Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon – CircleID
This is the fourth in a multi-part series on cryptography and the Domain Name System (DNS).
One of the "key" questions cryptographers have been asking for the past decade or more is what to do about the potential future development of a large-scale quantum computer.
If theory holds, a quantum computer could break established public-key algorithms including RSA and elliptic curve cryptography (ECC), building on Peter Shor's groundbreaking result from 1994.
This prospect has motivated research into new so-called "post-quantum" algorithms that are less vulnerable to quantum computing advances. These algorithms, once standardized, may well be added into the Domain Name System Security Extensions (DNSSEC) thus also adding another dimension to a cryptographer's perspective on the DNS.
(Caveat: Once again, the concepts I'm discussing in this post are topics we're studying in our long-term research program as we evaluate potential future applications of technology. They do not necessarily represent Verisign's plans or position on possible new products or services.)
The National Institute of Standards and Technology (NIST) started a Post-Quantum Cryptography project in 2016 to "specify one or more additional unclassified, publicly disclosed digital signature, public-key encryption, and key-establishment algorithms that are capable of protecting sensitive government information well into the foreseeable future, including after the advent of quantum computers."
Security protocols that NIST is targeting for these algorithms, according to its 2019 status report (Section 2.2.1), include: "Transport Layer Security (TLS), Secure Shell (SSH), Internet Key Exchange (IKE), Internet Protocol Security (IPsec), and Domain Name System Security Extensions (DNSSEC)."
The project is now in its third round, with seven finalists, including three digital signature algorithms, and eight alternates.
NIST's project timeline anticipates that the draft standards for the new post-quantum algorithms will be available between 2022 and 2024.
It will likely take several additional years for standards bodies such as the Internet Engineering Task (IETF) to incorporate the new algorithms into security protocols. Broad deployments of the upgraded protocols will likely take several years more.
Post-quantum algorithms can therefore be considered a long-term issue, not a near-term one. However, as with other long-term research, it's appropriate to draw attention to factors that need to be taken into account well ahead of time.
The three candidate digital signature algorithms in NIST's third round have one common characteristic: all of them have a key size or signature size (or both) that is much larger than for current algorithms.
Key and signature sizes are important operational considerations for DNSSEC because most of the DNS traffic exchanged with authoritative data servers is sent and received via the User Datagram Protocol (UDP), which has a limited response size.
Response size concerns were evident during the expansion of the root zone signing key (ZSK) from 1024-bit to 2048-bit RSA in 2016, and in the rollover of the root key signing key (KSK) in 2018. In the latter case, although the signature and key sizes didn't change, total response size was still an issue because responses during the rollover sometimes carried as many as four keys rather than the usual two.
Thanks to careful design and implementation, response sizes during these transitions generally stayed within typical UDP limits. Equally important, response sizes also appeared to have stayed within the Maximum Transmission Unit (MTU) of most networks involved, thereby also avoiding the risk of packet fragmentation. (You can check how well your network handles various DNSSEC response sizes with this tool developed by Verisign Labs.)
The larger sizes associated with certain post-quantum algorithms do not appear to be a significant issue either for TLS, according to one benchmarking study, or for public-key infrastructures, according to another report. However, a recently published study of post-quantum algorithms and DNSSEC observes that "DNSSEC is particularly challenging to transition" to the new algorithms.
Verisign Labs offers the following observations about DNSSEC-related queries that may help researchers to model DNSSEC impact:
A typical resolver that implements both DNSSEC validation and qname minimization will send a combination of queries to Verisign's root and top-level domain (TLD) servers.
Because the resolver is a validating resolver, these queries will all have the "DNSSEC OK" bit set, indicating that the resolver wants the DNSSEC signatures on the records.
The content of typical responses by Verisign's root and TLD servers to these queries are given in Table 1 below. (In the table,
For an A or NS query, the typical response, when the domain of interest exists, includes a referral to another name server. If the domain supports DNSSEC, the response also includes a set of Delegation Signer (DS) records providing the hashes of each of the referred zone's KSKs the next link in the DNSSEC trust chain. When the domain of interest doesn't exist, the response includes one or more Next Secure (NSEC) or Next Secure 3 (NSEC3) records.
Researchers can estimate the effect of post-quantum algorithms on response size by replacing the sizes of the various RSA keys and signatures with those for their post-quantum counterparts. As discussed above, it is important to keep in mind that the number of keys returned may be larger during key rollovers.
Most of the queries from qname-minimizing, validating resolvers to the root and TLD name servers will be for A or NS records (the choice depends on the implementation of qname minimization, and has recently trended toward A). The signature size for a post-quantum algorithm, which affects all DNSSEC-related responses, will therefore generally have a much larger impact on average response size than will the key size, which affects only the DNSKEY responses.
Post-quantum algorithms are among the newest developments in cryptography. They add another dimension to a cryptographer's perspective on the DNS because of the possibility that these algorithms, or other variants, may be added to DNSSEC in the long term.
In my next post, I'll make the case for why the oldest post-quantum algorithm, hash-based signatures, could be a particularly good match for DNSSEC. I'll also share the results of some research at Verisign Labs into how the large signature sizes of hash-based signatures could potentially be overcome.
Read the previous posts in this six-part blog series:
The rest is here:
Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon - CircleID
- Google, Microsoft and IBM are bullish on quantum computing. Are the chips of the future for real? - CNBC - April 8th, 2025 [April 8th, 2025]
- Levi & Korsinsky Notifies Shareholders of Quantum Computing Inc.(QUBT) of a Class Action Lawsuit and an Upcoming Deadline - PR Newswire - April 8th, 2025 [April 8th, 2025]
- Cleveland Clinic and CAS to Leverage Quantum Computing and AI in Drug Discovery Effort - HPCwire - April 8th, 2025 [April 8th, 2025]
- How Quantum Computing and Advanced AI Are Redefining the Boundaries of Human Thought - Built In - April 8th, 2025 [April 8th, 2025]
- Bitcoin Developer Proposes Hard Fork to Protect BTC From Quantum Computing Threats - CoinDesk - April 8th, 2025 [April 8th, 2025]
- QUBT INVESTOR ALERT: Bronstein, Gewirtz and Grossman, LLC Announces that Quantum Computing Inc. Investors with Substantial Losses Have Opportunity to... - April 8th, 2025 [April 8th, 2025]
- Quantum Computing Inc. Class Action: The Gross Law Firm Reminds Quantum Computing Inc. Investors of the Pending Class Action Lawsuit with a Lead... - April 8th, 2025 [April 8th, 2025]
- QUBT Investors Have Opportunity to Lead Quantum Computing Inc. Securities Fraud Lawsuit with the Schall Law Firm - PR Newswire - April 8th, 2025 [April 8th, 2025]
- Americans once again make headlines in computing with the discovery of a quantum highway that raises great hopes. - Farmingdale Observer - April 8th, 2025 [April 8th, 2025]
- Three Canadian companies vying for U.S. quantum computing funding as race to develop technology heats up - The Globe and Mail - April 3rd, 2025 [April 3rd, 2025]
- What will quantum computing actually look like? - Defense One - April 3rd, 2025 [April 3rd, 2025]
- Are businesses ready for the disruption of quantum computing? - Kyndryl - April 3rd, 2025 [April 3rd, 2025]
- Rigetti Computing Selected to Participate in DARPAs Quantum Benchmarking Initiative - GlobeNewswire - April 3rd, 2025 [April 3rd, 2025]
- IonQ Selected by DARPA for Quantum Benchmarking Initiative (QBI) to Advance Quantum Computing - Business Wire - April 3rd, 2025 [April 3rd, 2025]
- Atom Computing selected by DARPA to explore near-term utility-scale quantum computing with neutral atoms - PR Newswire - April 3rd, 2025 [April 3rd, 2025]
- Advanced quantum computing could transform particle physics research - Digital Watch Observatory - April 3rd, 2025 [April 3rd, 2025]
- IonQ in focus as DARPA picks it for quantum computing initiative (IONQ:NYSE) - Seeking Alpha - April 3rd, 2025 [April 3rd, 2025]
- Shareholders that lost money on Quantum Computing Inc.(QUBT) should contact The Gross Law Firm about pending Class Action - QUBT - PR Newswire - April 3rd, 2025 [April 3rd, 2025]
- Top benefits and advantages of quantum computing - TechTarget - April 3rd, 2025 [April 3rd, 2025]
- Quantum Computing Breakthrough: Photon Router Transforms Microwave Qubits into Light Pulses - The Debrief - April 3rd, 2025 [April 3rd, 2025]
- Quantum Computing Inc. Secures Quantum Photonic Vibrometer Order with Delft University of Technology - PR Newswire - April 3rd, 2025 [April 3rd, 2025]
- Rigetti Computing Has Room to Grow. Why the CEO Is Tempering Expectations for Quantum. - Barron's - April 3rd, 2025 [April 3rd, 2025]
- Cautious Optimism: Evaluating Alphabets Position in the Nascent Quantum Computing Market - TipRanks - April 3rd, 2025 [April 3rd, 2025]
- D-Wave Stock Slips. Why Nvidias Quantum Computing Event Hurt the Shares. - Barron's - March 22nd, 2025 [March 22nd, 2025]
- Nvidia Is Going Big on Quantum Computing, and It Isnt Going It Alone - Barron's - March 22nd, 2025 [March 22nd, 2025]
- 6 Top Quantum Computing Stocks to Buy in 2025 - The Motley Fool - March 22nd, 2025 [March 22nd, 2025]
- Recommended Reading Evaluating the Performance of Quantum Process Units at Large Width and Depth - Quantum Computing Report - March 22nd, 2025 [March 22nd, 2025]
- When will quantum computing be available? It depends - TechTarget - March 22nd, 2025 [March 22nd, 2025]
- Quantum-computing stocks fall again as Jensen Huang and other CEOs temper expectations around the bleeding-edge tech: Not good enough yet for... - March 22nd, 2025 [March 22nd, 2025]
- Is quantum computing the future of tech and where to find investment opportunities By Investing.com - Investing.com - March 22nd, 2025 [March 22nd, 2025]
- Jensen Huang backpedals on remarks that sent quantum computing stocks spiraling - TechSpot - March 22nd, 2025 [March 22nd, 2025]
- D-Wave Introduces Quantum Blockchain Architecture, Featuring Enhanced Security and Efficiency over Classical Computing - Business Wire - March 22nd, 2025 [March 22nd, 2025]
- Nvidia CEO Jensen Huang says he was wrong about quantum computing. But he might be right - Quartz - March 22nd, 2025 [March 22nd, 2025]
- Nvidia will build accelerated quantum computing research center - VentureBeat - March 22nd, 2025 [March 22nd, 2025]
- Quantum Computing Stocks Jump Ahead Of Nvidia GTC Conference Next Week - Investor's Business Daily - March 18th, 2025 [March 18th, 2025]
- 5 wild things quantum computing could unlock now that Big Tech believes a breakthrough is within reach - Business Insider - March 18th, 2025 [March 18th, 2025]
- Want to Invest in Quantum Computing? 3 Stocks That Are Great Buys Right Now. - The Motley Fool - March 18th, 2025 [March 18th, 2025]
- How Quantum Computing And The Metaverse Will Transform Your Career - Forbes - March 18th, 2025 [March 18th, 2025]
- QUBT INVESTOR ALERT: Bronstein, Gewirtz and Grossman, LLC Announces that Quantum Computing Inc. Shareholders Have Opportunity to Lead Class Action... - March 18th, 2025 [March 18th, 2025]
- Cloudflare is already selling security tools for the quantum computing era - Quartz - March 18th, 2025 [March 18th, 2025]
- Norma and Neowiz Partner to Explore Quantum Computing and AI for Game Development - The Quantum Insider - March 18th, 2025 [March 18th, 2025]
- China to spend $55 billion on R&D in 2025 Semiconductor, AI and quantum computing fields to benefit - Tom's Hardware - March 18th, 2025 [March 18th, 2025]
- D-Wave Quantum leads massive rally in quantum computing stocks as its revenue outlook goes parabolic - Sherwood News - March 18th, 2025 [March 18th, 2025]
- Arqit leads quantum computing stocks higher ahead of Nvidia's GTC event - Seeking Alpha - March 18th, 2025 [March 18th, 2025]
- Quantum Computing (QUBT) to Release Earnings on Thursday - MarketBeat - March 18th, 2025 [March 18th, 2025]
- Nvidia's Jensen Huang to unveil cutting-edge AI and quantum computing processors - Firstpost - March 18th, 2025 [March 18th, 2025]
- Quantum Computing Just Took Another Giant Leap--What It Means for Investors - PR Newswire - March 18th, 2025 [March 18th, 2025]
- 4 Quantum Computing Stocks On Watch Today As GTC 2025 Kicks Off - Barchart - March 18th, 2025 [March 18th, 2025]
- The Gross Law Firm Reminds Quantum Computing Inc. Investors of the Pending Class Action Lawsuit with a Lead Plaintiff Deadline of April 28, 2025 -... - March 18th, 2025 [March 18th, 2025]
- Quantum Computing Market Size to Grow Worth USD 888.5 Million at - openPR - March 18th, 2025 [March 18th, 2025]
- China to spend $55 billion on R&D in 2025 Semiconductor, AI and quantum computing fields to benefit - MSN - March 18th, 2025 [March 18th, 2025]
- Nvidia GTC And Quantum Computing Drivers Of The Stock Market, Trump Put Fails But May Not Be Dead - Benzinga - March 18th, 2025 [March 18th, 2025]
- Google, Microsoft, and others are racing to crack open quantum computing. Here's how their breakthroughs stack up. - Business Insider - March 9th, 2025 [March 9th, 2025]
- Could Investing in This Quantum Computing Stock Be Like Buying Nvidia Prior to the Dawn of the Artificial Intelligence (AI) Revolution? - Yahoo... - March 9th, 2025 [March 9th, 2025]
- Inside The Quantum Computing Crash Triggered By Nvidia CEO And What His Upcoming 'Quantum Day' May Bring - Investor's Business Daily - March 9th, 2025 [March 9th, 2025]
- Rigetti Earnings Reveal the Risks and Rewards of Quantum Computing - Barron's - March 9th, 2025 [March 9th, 2025]
- 'Nanodot' control could fine-tune light for sharper displays and quantum computing - Phys.org - March 9th, 2025 [March 9th, 2025]
- 3 Quantum Computing Stocks to Buy on the Dip - 24/7 Wall St. - March 9th, 2025 [March 9th, 2025]
- How quantum computing is shaping the future of tech - Yahoo Finance - March 9th, 2025 [March 9th, 2025]
- AIST Strengthens Quantum Collaboration with ORCA Computing and Universal Quantum - Quantum Computing Report - March 9th, 2025 [March 9th, 2025]
- Microsofts Quantum Computing Breakthrough, Explained - The Dispatch - March 5th, 2025 [March 5th, 2025]
- Quantum Computing Startup Says Its Already Making Millions of Light-Powered Chips - Singularity Hub - March 5th, 2025 [March 5th, 2025]
- Quantum computing is creating the future heres how - USC Dornsife College of Letters, Arts and Sciences - March 5th, 2025 [March 5th, 2025]
- Why We Dont Have Real Quantum Computing Yet - Forbes - March 5th, 2025 [March 5th, 2025]
- QunaSys Joins 19.95M ($20.91M USD) EU Project to Advance Sustainable Battery Innovation with Quantum Computing - Quantum Computing Report - March 5th, 2025 [March 5th, 2025]
- Alice & Bob to Host Fault-Tolerant Quantum Computing Workshop with CEA - HPCwire - March 5th, 2025 [March 5th, 2025]
- Rigetti partners with Quanta to boost superconducting quantum computing development - DatacenterDynamics - March 5th, 2025 [March 5th, 2025]
- Quantum Computing Inc. Class Action Alert: Wolf Haldenstein Adler Freeman & Herz LLP reminds investors that a securities class action lawsuit has... - March 5th, 2025 [March 5th, 2025]
- Quantum computing startup says its already making millions of light-powered chips - StartupNews.fyi - March 5th, 2025 [March 5th, 2025]
- A quantum computing startup says it is already making millions of light-powered chips - Phys.org - March 3rd, 2025 [March 3rd, 2025]
- Superconducting Quantum Computing Beyond 100 Qubits - Physics - March 3rd, 2025 [March 3rd, 2025]
- How IBM CEO Arvind Krishna Is Thinking About AI and Quantum Computing - TIME - March 3rd, 2025 [March 3rd, 2025]
- Webinar | 27 March 2025 | Quantum computing: The future of finance are you ready for Q-Day? - FinTech Futures - March 3rd, 2025 [March 3rd, 2025]
- 3 Quantum Computing Stocks To Buy As Microsoft Announces Major Breakthrough - Barchart - March 3rd, 2025 [March 3rd, 2025]
- WT 360: Inside the governments quantum computing push - Washington Technology - March 3rd, 2025 [March 3rd, 2025]
- INVESTOR ALERT: Pomerantz Law Firm Announces the Filing of a Class Action Against Quantum Computing Inc. and Certain Officers - QUBT - PR Newswire - March 3rd, 2025 [March 3rd, 2025]
- Amazon unveils Ocelot, its first quantum computing chip - The Guardian - March 3rd, 2025 [March 3rd, 2025]
- Industry Weighs in on AWS Quantum Computing Chip - IoT World Today - March 3rd, 2025 [March 3rd, 2025]
- Startup PsiQuantum says it is making millions of quantum computing chips - Yahoo - March 1st, 2025 [March 1st, 2025]
- IonQs Earnings Hit the Stock. Quantum Computing Rivals D-Wave and Rigetti Are Down Too. - Barron's - March 1st, 2025 [March 1st, 2025]