Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon – CircleID
This is the fourth in a multi-part series on cryptography and the Domain Name System (DNS).
One of the "key" questions cryptographers have been asking for the past decade or more is what to do about the potential future development of a large-scale quantum computer.
If theory holds, a quantum computer could break established public-key algorithms including RSA and elliptic curve cryptography (ECC), building on Peter Shor's groundbreaking result from 1994.
This prospect has motivated research into new so-called "post-quantum" algorithms that are less vulnerable to quantum computing advances. These algorithms, once standardized, may well be added into the Domain Name System Security Extensions (DNSSEC) thus also adding another dimension to a cryptographer's perspective on the DNS.
(Caveat: Once again, the concepts I'm discussing in this post are topics we're studying in our long-term research program as we evaluate potential future applications of technology. They do not necessarily represent Verisign's plans or position on possible new products or services.)
The National Institute of Standards and Technology (NIST) started a Post-Quantum Cryptography project in 2016 to "specify one or more additional unclassified, publicly disclosed digital signature, public-key encryption, and key-establishment algorithms that are capable of protecting sensitive government information well into the foreseeable future, including after the advent of quantum computers."
Security protocols that NIST is targeting for these algorithms, according to its 2019 status report (Section 2.2.1), include: "Transport Layer Security (TLS), Secure Shell (SSH), Internet Key Exchange (IKE), Internet Protocol Security (IPsec), and Domain Name System Security Extensions (DNSSEC)."
The project is now in its third round, with seven finalists, including three digital signature algorithms, and eight alternates.
NIST's project timeline anticipates that the draft standards for the new post-quantum algorithms will be available between 2022 and 2024.
It will likely take several additional years for standards bodies such as the Internet Engineering Task (IETF) to incorporate the new algorithms into security protocols. Broad deployments of the upgraded protocols will likely take several years more.
Post-quantum algorithms can therefore be considered a long-term issue, not a near-term one. However, as with other long-term research, it's appropriate to draw attention to factors that need to be taken into account well ahead of time.
The three candidate digital signature algorithms in NIST's third round have one common characteristic: all of them have a key size or signature size (or both) that is much larger than for current algorithms.
Key and signature sizes are important operational considerations for DNSSEC because most of the DNS traffic exchanged with authoritative data servers is sent and received via the User Datagram Protocol (UDP), which has a limited response size.
Response size concerns were evident during the expansion of the root zone signing key (ZSK) from 1024-bit to 2048-bit RSA in 2016, and in the rollover of the root key signing key (KSK) in 2018. In the latter case, although the signature and key sizes didn't change, total response size was still an issue because responses during the rollover sometimes carried as many as four keys rather than the usual two.
Thanks to careful design and implementation, response sizes during these transitions generally stayed within typical UDP limits. Equally important, response sizes also appeared to have stayed within the Maximum Transmission Unit (MTU) of most networks involved, thereby also avoiding the risk of packet fragmentation. (You can check how well your network handles various DNSSEC response sizes with this tool developed by Verisign Labs.)
The larger sizes associated with certain post-quantum algorithms do not appear to be a significant issue either for TLS, according to one benchmarking study, or for public-key infrastructures, according to another report. However, a recently published study of post-quantum algorithms and DNSSEC observes that "DNSSEC is particularly challenging to transition" to the new algorithms.
Verisign Labs offers the following observations about DNSSEC-related queries that may help researchers to model DNSSEC impact:
A typical resolver that implements both DNSSEC validation and qname minimization will send a combination of queries to Verisign's root and top-level domain (TLD) servers.
Because the resolver is a validating resolver, these queries will all have the "DNSSEC OK" bit set, indicating that the resolver wants the DNSSEC signatures on the records.
The content of typical responses by Verisign's root and TLD servers to these queries are given in Table 1 below. (In the table,
For an A or NS query, the typical response, when the domain of interest exists, includes a referral to another name server. If the domain supports DNSSEC, the response also includes a set of Delegation Signer (DS) records providing the hashes of each of the referred zone's KSKs the next link in the DNSSEC trust chain. When the domain of interest doesn't exist, the response includes one or more Next Secure (NSEC) or Next Secure 3 (NSEC3) records.
Researchers can estimate the effect of post-quantum algorithms on response size by replacing the sizes of the various RSA keys and signatures with those for their post-quantum counterparts. As discussed above, it is important to keep in mind that the number of keys returned may be larger during key rollovers.
Most of the queries from qname-minimizing, validating resolvers to the root and TLD name servers will be for A or NS records (the choice depends on the implementation of qname minimization, and has recently trended toward A). The signature size for a post-quantum algorithm, which affects all DNSSEC-related responses, will therefore generally have a much larger impact on average response size than will the key size, which affects only the DNSKEY responses.
Post-quantum algorithms are among the newest developments in cryptography. They add another dimension to a cryptographer's perspective on the DNS because of the possibility that these algorithms, or other variants, may be added to DNSSEC in the long term.
In my next post, I'll make the case for why the oldest post-quantum algorithm, hash-based signatures, could be a particularly good match for DNSSEC. I'll also share the results of some research at Verisign Labs into how the large signature sizes of hash-based signatures could potentially be overcome.
Read the previous posts in this six-part blog series:
The rest is here:
Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon - CircleID
- Turkey Launches First 5-Qubit Quantum Computer, Called QuanT, Marking National Technology Breakthrough for the Country - Quantum Computing Report - November 23rd, 2024 [November 23rd, 2024]
- Toshiba and RIKEN Achieve 99.90% Fidelity with Double-Transmon Coupler for Superconducting Quantum Computers - Quantum Computing Report - November 23rd, 2024 [November 23rd, 2024]
- IBM and Pasqal to Advance Quantum-Centric Supercomputing with a Unified Framework - Quantum Computing Report - November 23rd, 2024 [November 23rd, 2024]
- Up 43% Today, This Quantum Computing Stock Has More Than Tripled In November - Barchart - November 21st, 2024 [November 21st, 2024]
- Quantum computing making leap from theoretical to practical - Hamburg Invest - November 21st, 2024 [November 21st, 2024]
- Google Unveils AlphaQubit: AI-Driven Breakthrough in Quantum Error Correction - Quantum Computing Report - November 21st, 2024 [November 21st, 2024]
- Lightsynq Comes Out of Stealth with $18 Million in Series A Funding to Scale Quantum Computing - The Quantum Insider - November 21st, 2024 [November 21st, 2024]
- How Clean Does a Quantum Computing Test Facility Need to Be? - HPCwire - November 21st, 2024 [November 21st, 2024]
- Alice & Bob Launch Dynamiqs: A GPU-Accelerated Library for High-Speed Quantum Simulations - Quantum Computing Report - November 21st, 2024 [November 21st, 2024]
- Microsoft and Atom Computing Are Taking Orders for a Fault Tolerant Quantum Computer with 1K (Physical) / 50 (Logical) Qubits for Delivery Next Year -... - November 21st, 2024 [November 21st, 2024]
- Nurturing The Emerging Ecosystem Of Industry-Academia Collaboration In Quantum Computing - NDTV Profit - November 21st, 2024 [November 21st, 2024]
- Microsoft and Atom Computing leap ahead on the quantum frontier with logical qubits - GeekWire - November 21st, 2024 [November 21st, 2024]
- Quantum Computing and the Evolving Cyber Threat Landscape - The Soufan Center - November 16th, 2024 [November 16th, 2024]
- What is quantum computing and how might it impact financial services? - Lloyds Banking Group - November 16th, 2024 [November 16th, 2024]
- Quantum Computing to sell 16M shares at $2.50 in registered direct offering - TipRanks - November 16th, 2024 [November 16th, 2024]
- How 'clean' does a quantum computing test facility need to be? - Phys.org - November 14th, 2024 [November 14th, 2024]
- Quantum Computing Shares Are Up By More Than 70%: Here's What You Need To Know - Benzinga - November 14th, 2024 [November 14th, 2024]
- In step forward for quantum computing hardware, IU physicist uncovers novel behavior in quantum-driven superconductors - IU Newsroom - November 14th, 2024 [November 14th, 2024]
- Closing in on quantum computing with error mitigation - ComputerWeekly.com - November 14th, 2024 [November 14th, 2024]
- IQM unveils roadmap focused on fault-tolerant quantum computing by 2030 - Scientific Computing World - November 14th, 2024 [November 14th, 2024]
- Quantum Computing is Coming - Is the Insurance Industry Ready? - - Insurance Edge - November 14th, 2024 [November 14th, 2024]
- Could Diamonds Unlock Improved Qubits for Quantum Computing? - Securities.io - November 14th, 2024 [November 14th, 2024]
- Enterprise Quantum Computing Market on Track for 29.7% CAGR | Key Growth Drivers and Future Opportunities - openPR - November 14th, 2024 [November 14th, 2024]
- Equal1s Quantum Computing Breakthough with Arm Technology - Arm Newsroom - November 14th, 2024 [November 14th, 2024]
- Quantum Algorithms Institute Partners with AbaQus and InvestDEFY to Enhance Financial Forecasting with Quantum Computing - Quantum Computing Report - November 14th, 2024 [November 14th, 2024]
- SemiQon and SDT Partner to Scale Quantum Computing with Silicon-Based QPUs - Quantum Computing Report - November 14th, 2024 [November 14th, 2024]
- The CIO's quantum leap into the cloud: Integrating quantum computing into cloud infrastructure - ITPro - November 14th, 2024 [November 14th, 2024]
- Massachusetts Invests $5 Million in New Quantum Computing Facility in Holyoke - This Week In Worcester - November 14th, 2024 [November 14th, 2024]
- Hamad Bin Khalifa University and Quantinuum Partner to Advance Quantum Computing in Qatar - The Quantum Insider - November 14th, 2024 [November 14th, 2024]
- Hamad Bin Khalifa University Partners with Quantinuum to Boost Quantum Computing Research in Qatar - Quantum Computing Report - November 14th, 2024 [November 14th, 2024]
- Singtel Expands Quantum-Safe Network with Palo Alto Networks and Fortinet Integration - Quantum Computing Report - November 14th, 2024 [November 14th, 2024]
- Quantum Computing Company to Part With General Counsel - Law.com - November 12th, 2024 [November 12th, 2024]
- Researchers from the University of Sydney demonstrate more effieicnt quantum error correction - Scientific Computing World - November 12th, 2024 [November 12th, 2024]
- Quantum computing will be the next big tech trend to have a major impact on marketing, says Citi CMO Alex Craddock - Business Insider - November 10th, 2024 [November 10th, 2024]
- A Look At The Official Opening of UKs National Quantum Computing Centre - The Quantum Insider - November 10th, 2024 [November 10th, 2024]
- IonQ Partners with imec to Advance Quantum Computing with Photonic Integrated Circuits and Chip-Scale Ion Traps - Quantum Computing Report - November 10th, 2024 [November 10th, 2024]
- BTQ Technologies and Macquarie University Partner to Drive Quantum Computing and Secure Communications - Quantum Computing Report - November 10th, 2024 [November 10th, 2024]
- IonQ to Acquire the Assets of Qubitekk to Strengthen Its Position in Quantum Networking Technology - Quantum Computing Report - November 10th, 2024 [November 10th, 2024]
- From nuclear to quantum computing, how Big Tech intends to power AI's insatiable thirst for energy - CNBC - November 10th, 2024 [November 10th, 2024]
- Quantum Computing and Critical Infrastructure - The Quantum Insider - October 16th, 2024 [October 16th, 2024]
- A Superconducting Waltz: Elia Strambini on the Quantum Future of Computing - The Quantum Insider - October 16th, 2024 [October 16th, 2024]
- Quantum computing and photonics discovery potentially shrinks critical parts by 1,000 times - Phys.org - October 16th, 2024 [October 16th, 2024]
- Nu Quantum Announces the Qubit-Photon Interface for Modular and Scalable Distributed Quantum Computing - The Quantum Insider - October 16th, 2024 [October 16th, 2024]
- How to Invest in Quantum Computing Companies (Updated 2024) - Investing News Network - October 16th, 2024 [October 16th, 2024]
- IBM pitches camp in Germany to prepare Quantum Computing for the real world - diginomica - October 16th, 2024 [October 16th, 2024]
- Purifications, Fidelity & the Future of Computing - The Quantum Insider - October 16th, 2024 [October 16th, 2024]
- Making quantum computing more accessible and applicable to real-world challenges - Scientific Computing World - October 16th, 2024 [October 16th, 2024]
- The future of quantum computing and cybersecurity in telecommunications - Telefnica - October 16th, 2024 [October 16th, 2024]
- Chinese Quantum Computing Threat Highlights Urgency for Quantum eMotion's Quantum Security Solutions - Newsfile - October 16th, 2024 [October 16th, 2024]
- Qunova Computing Achieves Chemical Accuracy in Quantum Chemistry Simulations with Innovative Hardware-Agnostic Algorithm on NISQ Devices - Quantum... - October 16th, 2024 [October 16th, 2024]
- Quantum Computing Transformed by Breakthrough Photonic Technology - SciTechDaily - October 12th, 2024 [October 12th, 2024]
- How Is Quantum Computing Being Used in Healthcare? - HealthTech Magazine - October 12th, 2024 [October 12th, 2024]
- IBM Quantum Roadmap Guide -- Scaling And Expanding The Usefulness of Quantum Computing - The Quantum Insider - October 12th, 2024 [October 12th, 2024]
- Toyota and Xanadu Partner to Bring Quantum Computing to Advanced Materials Science and Sensing Applications - The Quantum Insider - October 12th, 2024 [October 12th, 2024]
- 'Invisibility' and quantum computing tipped for physics Nobel - Yahoo! Voices - October 12th, 2024 [October 12th, 2024]
- Airbus Selects Multiverse Computing to Build Quantum-inspired Gesture Recognition Software For Fighter Pilots - The Quantum Insider - October 12th, 2024 [October 12th, 2024]
- From Legacy to Innovation: Banks' Path to Cloud, AI, and Quantum Computing - Finextra - October 12th, 2024 [October 12th, 2024]
- IBM Executive Stories: Bringing Useful Quantum Computing to the World - IBM - October 7th, 2024 [October 7th, 2024]
- Quantum Computing Market to Soar to $7.1B by 2031 with 30.7% CAGR - openPR - October 7th, 2024 [October 7th, 2024]
- Quantum Computing Market Is Going to Boom | Major Giants IBM, Google, Rigetti, Microsoft, Intel - openPR - October 7th, 2024 [October 7th, 2024]
- Will IBM's Focus on Quantum Computing Propel the Stock? - Yahoo Finance - October 7th, 2024 [October 7th, 2024]
- Nu Quantums Platform For Networking Quantum Computers Hosted at The UK's National Quantum Computing Centre - The Quantum Insider - October 7th, 2024 [October 7th, 2024]
- Quantum Computing for Real-world Applications with Professor Naoki Yamamoto of Keio University - The Quantum Insider - October 7th, 2024 [October 7th, 2024]
- University of Queensland (UQ) is Receiving $29 million AUD ($19.7M USD) in Funding for Quantum Research and Scholarships - Quantum Computing Report - October 7th, 2024 [October 7th, 2024]
- History of quantum computing: 12 key moments that shaped the future of computers - Livescience.com - October 3rd, 2024 [October 3rd, 2024]
- Quantum Sensors: Atom Interferometry. Part 3: Space is the Place - Quantum Computing Report - October 3rd, 2024 [October 3rd, 2024]
- D-Wave and Japan Tobacco Collaborate on a Quantum AI-Driven Drug Discovery Proof-of-Concept - Quantum Computing Report - October 3rd, 2024 [October 3rd, 2024]
- March-Ins on Quantum Computing is the Newest of Threats to Free Enterprise - ShortGo - October 3rd, 2024 [October 3rd, 2024]
- Quantum computing and the future of cryptography: Understanding the imminent threat - Backend News - October 3rd, 2024 [October 3rd, 2024]
- Quantum for AI: Weather Forecasting. Are we There Yet? - Quantum Computing Report - September 28th, 2024 [September 28th, 2024]
- US Implements Controls on Quantum Computing and other Technologies - HPCwire - September 28th, 2024 [September 28th, 2024]
- IBM opens its quantum-computing stack to third parties - Ars Technica - September 28th, 2024 [September 28th, 2024]
- G7 cyber group warns financial sector to prep for quantum computing risks - The Record from Recorded Future News - September 28th, 2024 [September 28th, 2024]
- IonQ Signs a $54.5 Million Contract with AFRL for Research in Both Quantum Computing and Quantum Networking - Quantum Computing Report - September 28th, 2024 [September 28th, 2024]
- Quantum computing what you need to know - Information Age - September 28th, 2024 [September 28th, 2024]
- AI and Quantum Computing Form Strong Bond to Power Materials Discovery Innovation -- SandboxAQ, EY Researchers Report - The Quantum Insider - September 28th, 2024 [September 28th, 2024]
- University of Iowa Technology Institute researcher secures nearly $1 million grant to advance quantum computing - Corridor Business - September 28th, 2024 [September 28th, 2024]
- Quantum Computing vs. Blockchain: Will It Break the System? - CCN.com - September 28th, 2024 [September 28th, 2024]
- The Pervasiveness of Machine Learning in Quantum Technology - Quantum Computing Report - September 28th, 2024 [September 28th, 2024]
- BlueQubit Launches Plugin for Pennylane to Enable Quantum Simulations on BlueQubits Platform - Quantum Computing Report - September 28th, 2024 [September 28th, 2024]