Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon – CircleID
This is the fourth in a multi-part series on cryptography and the Domain Name System (DNS).
One of the "key" questions cryptographers have been asking for the past decade or more is what to do about the potential future development of a large-scale quantum computer.
If theory holds, a quantum computer could break established public-key algorithms including RSA and elliptic curve cryptography (ECC), building on Peter Shor's groundbreaking result from 1994.
This prospect has motivated research into new so-called "post-quantum" algorithms that are less vulnerable to quantum computing advances. These algorithms, once standardized, may well be added into the Domain Name System Security Extensions (DNSSEC) thus also adding another dimension to a cryptographer's perspective on the DNS.
(Caveat: Once again, the concepts I'm discussing in this post are topics we're studying in our long-term research program as we evaluate potential future applications of technology. They do not necessarily represent Verisign's plans or position on possible new products or services.)
The National Institute of Standards and Technology (NIST) started a Post-Quantum Cryptography project in 2016 to "specify one or more additional unclassified, publicly disclosed digital signature, public-key encryption, and key-establishment algorithms that are capable of protecting sensitive government information well into the foreseeable future, including after the advent of quantum computers."
Security protocols that NIST is targeting for these algorithms, according to its 2019 status report (Section 2.2.1), include: "Transport Layer Security (TLS), Secure Shell (SSH), Internet Key Exchange (IKE), Internet Protocol Security (IPsec), and Domain Name System Security Extensions (DNSSEC)."
The project is now in its third round, with seven finalists, including three digital signature algorithms, and eight alternates.
NIST's project timeline anticipates that the draft standards for the new post-quantum algorithms will be available between 2022 and 2024.
It will likely take several additional years for standards bodies such as the Internet Engineering Task (IETF) to incorporate the new algorithms into security protocols. Broad deployments of the upgraded protocols will likely take several years more.
Post-quantum algorithms can therefore be considered a long-term issue, not a near-term one. However, as with other long-term research, it's appropriate to draw attention to factors that need to be taken into account well ahead of time.
The three candidate digital signature algorithms in NIST's third round have one common characteristic: all of them have a key size or signature size (or both) that is much larger than for current algorithms.
Key and signature sizes are important operational considerations for DNSSEC because most of the DNS traffic exchanged with authoritative data servers is sent and received via the User Datagram Protocol (UDP), which has a limited response size.
Response size concerns were evident during the expansion of the root zone signing key (ZSK) from 1024-bit to 2048-bit RSA in 2016, and in the rollover of the root key signing key (KSK) in 2018. In the latter case, although the signature and key sizes didn't change, total response size was still an issue because responses during the rollover sometimes carried as many as four keys rather than the usual two.
Thanks to careful design and implementation, response sizes during these transitions generally stayed within typical UDP limits. Equally important, response sizes also appeared to have stayed within the Maximum Transmission Unit (MTU) of most networks involved, thereby also avoiding the risk of packet fragmentation. (You can check how well your network handles various DNSSEC response sizes with this tool developed by Verisign Labs.)
The larger sizes associated with certain post-quantum algorithms do not appear to be a significant issue either for TLS, according to one benchmarking study, or for public-key infrastructures, according to another report. However, a recently published study of post-quantum algorithms and DNSSEC observes that "DNSSEC is particularly challenging to transition" to the new algorithms.
Verisign Labs offers the following observations about DNSSEC-related queries that may help researchers to model DNSSEC impact:
A typical resolver that implements both DNSSEC validation and qname minimization will send a combination of queries to Verisign's root and top-level domain (TLD) servers.
Because the resolver is a validating resolver, these queries will all have the "DNSSEC OK" bit set, indicating that the resolver wants the DNSSEC signatures on the records.
The content of typical responses by Verisign's root and TLD servers to these queries are given in Table 1 below. (In the table,
For an A or NS query, the typical response, when the domain of interest exists, includes a referral to another name server. If the domain supports DNSSEC, the response also includes a set of Delegation Signer (DS) records providing the hashes of each of the referred zone's KSKs the next link in the DNSSEC trust chain. When the domain of interest doesn't exist, the response includes one or more Next Secure (NSEC) or Next Secure 3 (NSEC3) records.
Researchers can estimate the effect of post-quantum algorithms on response size by replacing the sizes of the various RSA keys and signatures with those for their post-quantum counterparts. As discussed above, it is important to keep in mind that the number of keys returned may be larger during key rollovers.
Most of the queries from qname-minimizing, validating resolvers to the root and TLD name servers will be for A or NS records (the choice depends on the implementation of qname minimization, and has recently trended toward A). The signature size for a post-quantum algorithm, which affects all DNSSEC-related responses, will therefore generally have a much larger impact on average response size than will the key size, which affects only the DNSKEY responses.
Post-quantum algorithms are among the newest developments in cryptography. They add another dimension to a cryptographer's perspective on the DNS because of the possibility that these algorithms, or other variants, may be added to DNSSEC in the long term.
In my next post, I'll make the case for why the oldest post-quantum algorithm, hash-based signatures, could be a particularly good match for DNSSEC. I'll also share the results of some research at Verisign Labs into how the large signature sizes of hash-based signatures could potentially be overcome.
Read the previous posts in this six-part blog series:
The rest is here:
Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon - CircleID
- Prediction: This Stock Will Be the Biggest Quantum Computing Winner of 2025 - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Schrdinger's Cat breakthrough could usher in the 'Holy Grail' of quantum computing, making them error-proof - Livescience.com - January 19th, 2025 [January 19th, 2025]
- Here's Some Reassuring News for Anyone Invested in Quantum Computing Stocks - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- What is the future of quantum computing going to look like? - opinion - The Jerusalem Post - January 19th, 2025 [January 19th, 2025]
- What Is Quantum Computing? And Should You Be Investing In It? - Investor's Business Daily - January 19th, 2025 [January 19th, 2025]
- 2 Quantum Computing Stocks That Could Be a Once-in-a-Lifetime Opportunity - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Quantum Computing vs. Traditional AI: Which Tech Stocks Are Must-Haves in 2025? - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Should You Buy Quantum Computing Stock While It's Below $15? - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Why Quantum Computing Stock IonQ Surged Higher This Week - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Why Rigetti Computing, IonQ, D-Wave Quantum, and Quantum Computing Stocks All Exploded Higher on Wednesday - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Miami University and Cleveland Clinic announce partnership to advance education in quantum computing - The Miami Student - January 19th, 2025 [January 19th, 2025]
- Interested in Quantum Computing? You Might Want to Hear What Nvidia's CEO Just Said About It - The Motley Fool - January 19th, 2025 [January 19th, 2025]
- Quantum-computing stocks could be rich takeover targets. Heres what to know. - MarketWatch - January 19th, 2025 [January 19th, 2025]
- D-Wave and Quantum Computing Stocks Are on the Rise. What You Should Know. - Barron's - January 19th, 2025 [January 19th, 2025]
- Jim Cramer Eyes Quantum Computing Stocks Like Rigetti, Warns Against Super Micro Computer: 'They Are Trying So Hard To Walk It Up Now' - Yahoo Finance - January 19th, 2025 [January 19th, 2025]
- Here's Some Reassuring News for Anyone Invested in Quantum Computing Stocks - MSN - January 19th, 2025 [January 19th, 2025]
- Quantum Computing vs. Traditional AI: Which Tech Stocks Are Must-Haves in 2025? - MSN - January 19th, 2025 [January 19th, 2025]
- The Blockchain Industry Cant Afford Complacency in Preparing for Quantum Computing - Blockhead - January 19th, 2025 [January 19th, 2025]
- Rigetti and D-Wave: Top Analyst Chooses the Best Quantum Computing Stocks to Buy - TipRanks - January 19th, 2025 [January 19th, 2025]
- Quantum Computing: The Next Big Thing? Investors Are Watching Closely! - Jomfruland.net - January 19th, 2025 [January 19th, 2025]
- Quantum Computing in Healthcare Overview and Leading Players: - openPR - January 19th, 2025 [January 19th, 2025]
- Interested in quantum computing investments? Hear what Nvidia's CEO just said about it - USA TODAY - January 19th, 2025 [January 19th, 2025]
- Quantum Computing: The Next Big Thing or Just Hype? - Jomfruland.net - January 19th, 2025 [January 19th, 2025]
- Miami University and Cleveland Clinic Announce Partnership to Advance Education in Quantum Computing - Cleveland Clinic Newsroom - January 15th, 2025 [January 15th, 2025]
- Quantum computing stocks rebound after massive sell-off as industry exec says opportunity is 'real' - Yahoo Finance - January 15th, 2025 [January 15th, 2025]
- D-Wave Partners with Carahsoft to Provide Quantum Computing Solutions for the Public Sector - The Quantum Insider - January 15th, 2025 [January 15th, 2025]
- Miami University And Cleveland Clinic Announce Partnership to Launch Specialized Quantum Computing Degree Program - The Quantum Insider - January 15th, 2025 [January 15th, 2025]
- Quantum computing stocks soar after Nvidia and Meta CEOs tanked them - Yahoo Finance - January 15th, 2025 [January 15th, 2025]
- Are Quantum Computing Stocks a Buy in January? - The Motley Fool - January 15th, 2025 [January 15th, 2025]
- Jim Cramer Eyes Quantum Computing Stocks Like Rigetti, Warns Against Super Micro Computer: 'They Are Trying So Hard To Walk It Up Now' - Benzinga - January 15th, 2025 [January 15th, 2025]
- Quantum Computing Stocks Roar Back to Life. Time to Buy? - 24/7 Wall St. - January 15th, 2025 [January 15th, 2025]
- What's Going On With Quantum Computing Stock Today? - Benzinga - January 15th, 2025 [January 15th, 2025]
- D-Wave Partners with Carahsoft to Bring Quantum Computing to U.S. Government Agencies - StockTitan - January 15th, 2025 [January 15th, 2025]
- Quantum computing applications are 'real today': D-Wave CEO - Yahoo Finance - January 15th, 2025 [January 15th, 2025]
- Nvidia's Jensen Huang and Meta's Mark Zuckerberg Pour Cold Water on Quantum Computing Hype. Here's 1 Stock to Buy Anyway. - The Motley Fool - January 15th, 2025 [January 15th, 2025]
- Mark Zuckerberg joined Nvidia's CEO in doubting quantum computing and the stocks plunge again - Quartz - January 15th, 2025 [January 15th, 2025]
- Why Shares of Quantum Computing Stocks D-Wave Quantum, Quantum Computing, and Rigetti Computing Were Plunging Again Today - The Motley Fool - January 15th, 2025 [January 15th, 2025]
- Expert: The Nvidia-Driven Selloff in Quantum Computing Stocks Is a Reason to Double Down on These 4 Names - Barchart - January 15th, 2025 [January 15th, 2025]
- Quantum Computing Stocks Collapse: Here's Why - The Motley Fool - January 15th, 2025 [January 15th, 2025]
- NVIDIA Announces First-Ever Quantum Day At GTC 2025, Days After Jensen Huang Said Quantum Computing Is 20 Years Away - Benzinga - January 15th, 2025 [January 15th, 2025]
- SAP CEO Sees Huge Quantum Computing Impact In 3 To 4 Years - Investor's Business Daily - January 15th, 2025 [January 15th, 2025]
- MIT sets world record with 99.998% fidelity in quantum computing breakthrough - Interesting Engineering - January 15th, 2025 [January 15th, 2025]
- Quantum Computing Stocks Jump On D-Wave, Carahsoft Partnership - Yahoo! Voices - January 15th, 2025 [January 15th, 2025]
- IonQ and Rigetti: Top Analyst Chooses the Best Quantum Computing Stocks to Buy - TipRanks - January 15th, 2025 [January 15th, 2025]
- Scientists Create Split-Electrons, Unlocking the Future of Quantum Computing - SciTechDaily - January 15th, 2025 [January 15th, 2025]
- Quantum Computing Can Be Brought to the Masses, if It Is Decentralized - CCN.com - January 9th, 2025 [January 9th, 2025]
- Why Quantum Computing Specialist IonQ (IONQ) May Have Reached The End Of The Road - Barchart - January 9th, 2025 [January 9th, 2025]
- Nvidia CEO Jensen Huang just tanked quantum-computing stocks after saying their most exciting developments are more than a decade away - Fortune - January 9th, 2025 [January 9th, 2025]
- Quantum Computing Stocks Sink as Nvidia CEO Says Tech Is 15 to 30 Years Away - Investopedia - January 9th, 2025 [January 9th, 2025]
- Why Quantum Computing Stocks Rigetti Computing, Quantum Computing, and D-Wave Computing All Plunged Today - The Motley Fool - January 9th, 2025 [January 9th, 2025]
- Quantum Computing Stocks Crashed -- Here's Why - The Motley Fool - January 9th, 2025 [January 9th, 2025]
- Nvidia CEO Jen-Hsun Huang's simple reminder that useful quantum computing is a long way off has somehow caused industry stocks to plummet - PC Gamer - January 9th, 2025 [January 9th, 2025]
- How Quantum Computing Could Advance One Health - Impakter - January 9th, 2025 [January 9th, 2025]
- Quantum computing stocks are having a rough start to 2025: IonQ, D-Wave, Rigetti tank after Nvidia CEO predicts 20-year horizon - Fast Company - January 9th, 2025 [January 9th, 2025]
- Quantum Computing, Inc. Announces Private Placement of Common Stock for Proceeds of $100 Million - Yahoo Finance - January 9th, 2025 [January 9th, 2025]
- 2025 will see huge advances in quantum computing. So what is a quantum chip and how does it work? - The Conversation - January 9th, 2025 [January 9th, 2025]
- Nvidia CEO Jensen Huang just tanked quantum-computing stocks after saying their most exciting developments are more than a decade away - AOL - January 9th, 2025 [January 9th, 2025]
- Collaboration to explore the use of graphene technology in quantum computing - The Manufacturer - January 9th, 2025 [January 9th, 2025]
- Quantum computing stocks tumble after Nvidia boss Jensen Huang says the tech is still 20 years away - Markets Insider - January 9th, 2025 [January 9th, 2025]
- Want to Buy a Quantum Computing Stock in 2025? You Might Consider This Quantum Computing ETF. - The Motley Fool - January 9th, 2025 [January 9th, 2025]
- Ride the Quantum Computing Wave with These 2 Stocks: RGTI, QBTS - Yahoo Finance - January 9th, 2025 [January 9th, 2025]
- Shaping the Future of Quantum Computing in the United Arab Emirates (UAE) - Quantum Computing Report - January 9th, 2025 [January 9th, 2025]
- How Nvidia CEO Jensen Huang's one sentence wiped out $8 billion in market cap of quantum computing compan - The Times of India - January 9th, 2025 [January 9th, 2025]
- Will This Quantum Computing Stock Be a Must-Own in 2025? - The Motley Fool - January 9th, 2025 [January 9th, 2025]
- Quantum-computing stocks tumble on Nvidia CEOs comment that theyre decades away from being very useful - Sherwood News - January 9th, 2025 [January 9th, 2025]
- Analyzing Quantum Computing Has Been The Most Challenging Project In My Career (NASDAQ:QUBT) - Seeking Alpha - January 3rd, 2025 [January 3rd, 2025]
- Norma and Mabel Quantum Partner to Launch Integrated Quantum Computing System in Korea - Quantum Computing Report - January 3rd, 2025 [January 3rd, 2025]
- How Microsoft and Partners are Shaping the Future of Quantum Computing - The Quantum Insider - January 3rd, 2025 [January 3rd, 2025]
- One Quantum Computing ETF to Buy Hand Over Fist as Googles Willow Supercharges the Market - Barchart - January 3rd, 2025 [January 3rd, 2025]
- MicroCloud Hologram Inc. Develops Semiconductor Quantum Dot Hole Spin Qubit Technology, Advancing the Frontiers of Quantum Computing - Yahoo Finance - January 3rd, 2025 [January 3rd, 2025]
- Quantum Applications in the Automotive Industry - Quantum Computing Report - January 3rd, 2025 [January 3rd, 2025]
- Jim Cramer Warns 'Day Is Not Near Enough To Justify The Current Valuations' Of Quantum Computing, Nuclear Power Stocks - Benzinga - January 3rd, 2025 [January 3rd, 2025]
- MicroCloud Hologram's Stock Surges 31% on Quantum Computing Breakthrough: What This Means for the Future of Tech - The Africa Logistics - January 3rd, 2025 [January 3rd, 2025]
- Quantum Computing Stocks Like Rigetti Computing Are Soaring And This ETF Lets Investors Participate In The Boom Story - Benzinga - January 3rd, 2025 [January 3rd, 2025]
- Future Industry Growth Of Commercial Quantum Computing - openPR - January 3rd, 2025 [January 3rd, 2025]
- GCAN to Explore Strategic Alternatives in Artificial Intelligence and Quantum Computing - GlobeNewswire - January 3rd, 2025 [January 3rd, 2025]
- Jim Cramer talks being cautious with nuclear power and quantum computing stocks - MSN - January 3rd, 2025 [January 3rd, 2025]
- Quantum Computing Is Finally Here. But What Is It? - Bloomberg - December 27th, 2024 [December 27th, 2024]
- Should You Buy Quantum Computing Stocks in 2025? - The Motley Fool - December 27th, 2024 [December 27th, 2024]
- Rigetti Stock Doubles in Days: Here's the Quantum Computing Stock's Next Target - Money Morning - December 27th, 2024 [December 27th, 2024]