Ilmu Komputer & AI editorial
Enc53: DNSSEC-Anchored Stateless Tickets for Post-Quantum Authoritative DNS
The core problem
DNSSEC authenticates RRsets but provides neither endpoint authentication nor channel security. DNS-over-TLS (DoT) and DNS-over-QUIC (DoQ) were designed for the stub-to-resolver hop, where stable long-lived connections amortize expensive initial setup. The recursive-to-authoritative path inverts these dynamics: high fan-in and nonuniform per-resolver query frequency make long-lived, stateful connections costly and often infeasible. A survey of TLD and 2LD nameservers bounds connection lifetimes, with almost half of surveyed servers imposing limits even on non-idle connections.
Post-quantum (PQ) primitives sharpen the mismatch. An ML-DSA WebPKI certificate chain crosses TCP's initial window, and a cold PQ DoQ session may incur up to about the total bytes of the same query over UDP. The paper asks: can authoritative DNS obtain authenticated encryption without per-connection server state and without the byte and latency penalties of PQ ADoT/ADoQ? Enc53 answers by splitting DNS encryption into two phases: (1) a short-lived, DNSSEC-anchored, TLS-authenticated provisioning on the initial query, and (2) a steady state of 1-RTT AEAD-encrypted UDP DNS queries. The design is serv
Innovation
Steady-state Enc53 exchanges cost about 570 B, roughly a plain UDP query, and land within 1 ms of the unencrypted UDP baseline. Against resumed PQ-ADoT, Enc53 uses fewer bytes and lower latency; against resumed PQ-ADoQ, Enc53 uses fewer bytes at the same latency.
When evaluated against a root server query trace, Enc53 achieves compute efficiency over ADoT/ADoQ, memory efficiency over ADoT, and memory efficiency over ADoQ. The server-side stateless property is central: authoritative servers hold only a symmetric STEK, so memory does not scale with the number of active resolvers or connections.
Joint deployment with FN-DSA-512 PQ-DNSSEC keeps the combined Enc53-DNSSEC UDP datagram below the 1232 B buffer limit, indicating that authenticated, PQ-secure authoritative DNS can fit within conservative path MTU constraints without fragmentation.
Efficiency ratios (illustrative):
Why it matters
The results show that the recursive-to-authoritative path requires a different security and performance trade-off than the stub-to-resolver hop. DoT and DoQ assume long-lived connections that amortize setup; authoritative servers face high fan-in and nonuniform query frequency, and nearly half of surveyed TLD/2LD nameservers limit even non-idle connection lifetimes. Enc53's two-phase split aligns with these realities: expensive authentication happens once, and steady-state traffic returns to UDP-like efficiency.
Post-quantum primitives make the mismatch acute. ML-DSA certificate chains cross TCP's initial window, and cold PQ DoQ can cost up to about the bytes of a UDP query. By anchoring provisioning in DNSSEC and TLS and then using 1-RTT AEAD over UDP, Enc53 avoids repeated PQ handshakes and server-side session state. The 570 B steady-state exchange and sub-millisecond latency gap versus plain UDP indicate that authenticated encryption need not impose prohibitive overhead.
The server-side stateless design has operational implications: authoritative servers store only a symmetric STEK, yielding compute efficiency over ADoT/ADoQ and up to memory efficiency over ADoQ. The joint Enc53-DNSSEC datagram remaining below 1232 B with FN-DSA-512 suggests deployability under conservative MTU limits. Limitations include reliance on DNSSEC anchoring and ticket management at resolvers; future work may examine ticket revocation, key rotation, and behavior under adversarial conditions. Overall, Enc53 offers a practical path to post-quantum, authenticated authoritative DNS without abandoning UDP's efficiency.
Who should read this
Opening member content…