EP2087699A2 - Markteinführung einer dnssec-basis - Google Patents

Markteinführung einer dnssec-basis

Info

Publication number
EP2087699A2
EP2087699A2 EP07866500A EP07866500A EP2087699A2 EP 2087699 A2 EP2087699 A2 EP 2087699A2 EP 07866500 A EP07866500 A EP 07866500A EP 07866500 A EP07866500 A EP 07866500A EP 2087699 A2 EP2087699 A2 EP 2087699A2
Authority
EP
European Patent Office
Prior art keywords
server
security mechanisms
dns
request
security
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP07866500A
Other languages
English (en)
French (fr)
Inventor
Daniel Migault
Jean-Michel Combes
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Orange SA
Original Assignee
France Telecom SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by France Telecom SA filed Critical France Telecom SA
Publication of EP2087699A2 publication Critical patent/EP2087699A2/de
Withdrawn legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4505Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
    • H04L61/4511Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1001Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1001Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
    • H04L67/1004Server selection for load balancing
    • H04L67/1023Server selection for load balancing based on a hash applied to IP addresses or costs

Definitions

  • the invention also relates to the first device and associated server devices and a computer program product implementing the access method.
  • DNS Domain Name Service
  • DNSSEC Secure DNS
  • a malicious third party may, for example, intercept a DNS request for the IP address of a domain name corresponding, for example, to a banking site, and return to the requesting an IP address corresponding to a false site imitating the banking site and allowing to acquire the codes of access of the thus diverted customers.
  • LlETF has therefore developed a secure version of the DNS standard, called DNSSEC, described in the TIETF, RFC4033, RFC 4034 and RFC 4035 documents.
  • the DNSSEC protocol relies on several security mechanisms:
  • NSEC2 makes it possible to classify the domain names as within a dictionary. Since there is an order, if the requested domain name is not between the expected names, it does not exist.
  • the NSEC3 field has the same functions as the NSEC2 field, except that it does not return unencrypted data from the previous domain name and the next domain name. It returns a hash key of these names. This prevents the zone from being listed.
  • a chain of trust mechanism This mechanism makes it possible to go from one level of the hierarchy of the DNS servers to a lower level without losing confidence.
  • the DNS protocol includes some security mechanisms such as:
  • An object of the invention is therefore a method of access by a first device to duplicate predetermined information in a plurality of server devices, each server device implementing a subset of security mechanisms of a predetermined set of security mechanisms so that to provide a predefined level of security of access to the predetermined information, said method comprising the steps of: a) transmission by the first device of at least one access request adapted to receive the list of security mechanisms tmpîtigés by the server devices, b) sending by the first device to at least one of said server devices a predetermined access to information request, said request using the security mechanisms implemented by the at least one of said server devices.
  • Other characteristics and particular modes of realization are:
  • step a) comprises emitting a directed access request to the central server device , which advantageously makes it possible to obtain with a single request the list of server devices and their security mechanisms.
  • Ie central server device sends to the first device a sublist of said list, said sub-list having only references to the server devices having the predetermined information, which advantageously allows to limit the amount of information transferred.
  • step a) consists in issuing a DNS request of type A in order to determine the IP address corresponding to a DNS address with the DNS server.
  • highest-level DNS server and the highest-level DNS server response to this request is a NS-type DNS response that concatenates the DNSSEC security mechanism description fields implemented for each DNS server whose address is transmitted in the NS type response, which advantageously makes it possible to select the DNS server impimalant the selected mechanisms of the DNSSEC protocol.
  • step a) consists of a DNS request to acquire the characteristics of an addressed server device to said server device, to which said server device responds by transmitting to the first device a field of description of the security mechanisms of the DNSSEC standard implemented by said server device, which advantageously makes it possible to know the DNSSEC security mechanisms implemented by the DNS server.
  • Another object of the invention is a device for accessing predetermined information duplicated in several server devices, each server device impinging a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a level of security.
  • predefined security access to predetermined information characterized in that it comprises: a) means for transmitting at least one access request adapted to receive the list of security mechanisms implemented by the server devices , b) means for transmitting to at least one of said server devices a predetermined access request to the information, said request using the security mechanisms implemented by the at least one of said server devices.
  • Another object of the invention is a server device impregnating a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a predefined level of security of access to predetermined information, characterized in that 'it comprises : a) means for receiving at least one access request by a first device adapted to receive a list of the security mechanisms implemented by said server device, b) sending means in response to the access request la list of implemented security mechanisms, c) means for receiving a predetermined access request to the information transmitted by the first device, said request using the security mechanisms implemented by said server device.
  • Another object of the invention relates to a system for accessing a predetermined information comprising an access device according to the invention and several server devices according to the invention.
  • Another object of the invention is a computer program comprising program code instructions for performing the steps of the preceding method when said program is executed on a computer.
  • FIG. 1 is a schematic view of an access system according to one embodiment of the invention.
  • FIG. 2 is a schematic view of a first device of the system of FIG. 1;
  • FIG. 3 is a schematic view of a server device of the system of FIG. 1;
  • FIG. 4 is a flow chart of a first embodiment of the method according to the invention.
  • FIG. 5 is a flow diagram of a second embodiment of the method according to the invention.
  • FIG. 6 is a schematic view of a computer implementing a program implementing an embodiment of the method according to the invention.
  • a first device 1 is connected via a data network 2 to server devices 3, 4, 5.
  • the first device 1 is a DNS client, for example a recursive cache server
  • the server devices 3, 4 and 5 are DNS servers.
  • the DNS servers are organized into a hierarchy of servers corresponding to the hierarchy of domain names.
  • the DNS server 3 is the authoritative server on the ".fr" zone
  • the DNS server 4 is the authoritative server on the "francetelecom.fr” domain
  • the DNS server 5 is the authoritative server on the domain
  • the hierarchy between DNS servers is particularly illustrated during a traditional resolution of the domain name.
  • the DNS client 1 wants to know the IP address of the address www.francetelecom.fr.
  • the DNS client 1 sends a request concerning this domain to the root server (not shown). This returns the IP address of the authoritative DNS server to the ".fr" zone, namely the DNS server 3. The DNS client 1 then sends a request to resolve the domain www.francetelecom.fr to the DNS server 3 This returns the address! P of the authoritative DNS server for the domain "francetelecom.fr", ie the server 4. The DNS client 1 then sends a resolution request for www.francetelecom.fr to the DNS server. 4. This returns the IP address of the corresponding web server, the IP address that is transferred by the DNS client 1 to the HTTP client that issued the initial request so that it can query the web server.
  • the first device 1 comprises, FIG. 2, means 10 of connection to the data network 2.
  • H comprises means 12 for transmitting at least one access request adapted to receive a list of security mechanisms implemented by the server devices 3, 4, 5.
  • the access request is such that it uses the implemented security mechanisms.
  • the server devices 3, 4, 5 comprise, FIG. 3, means 20 for storing a predetermined information item. This is, for example, a database of information related to the DNS protocol.
  • Access to this information is controlled by security mechanisms 22 defining a level of security of access to this information.
  • the server devices 3, 4, 5 comprise means 24 for connection to the data network 2.
  • Reception means 26 are connected to the connection means 24.
  • the receiving means 26 are adapted to receive an access request from the first device 1.
  • This access request includes a request for information on the list of implemented security mechanisms 22.
  • the server device 3, 4, 5 comprises means 28 for sending the list of implemented security mechanisms 22.
  • the server device 3, 4, 5 further comprises means 30 for receiving a request for access to the predetermined information, a request sent by the first device 1. This request uses the access security mechanisms 22 to access to information.
  • step 40 the first device 1 sends at least one request to at least one of the server devices 3, 4, 5.
  • step 42 each polled server device 3, 4, 5 responds by sending a list of implemented security mechanisms.
  • the first device 1 selects one of the server devices 3, 4, 5 according to the security mechanisms implemented by it. For example, the first device 1 compares the list of security mechanisms implemented by each server device to a predetermined subset of security mechanisms.
  • step 46 the first device issues a request for access to the information stored in the storage means. This request is intended for the server device 3 "4, 5 selected and respects the security mechanisms impiementés by this server device 3, 4, 5.
  • step 48 the security mechanisms having been correctly activated, the server device 3, 4, 5 sends the first device 1 the requested information.
  • one of the server devices 3, 4, 5, for example the server device 3, has a central server device role comprising a list referencing the server devices 4, 5 as well as the subset of the security mechanisms. impiementé by each server device 4, 5.
  • step 50 the first device 1 then sends its request to the central server device 3.
  • step 52 the response of the central device 3 includes a list of the server devices 4, 5 and the implemented security mechanisms.
  • the list sent by the server device Central 3 only includes server devices containing the predetermined information.
  • the first device 1 selects in step 54 a server device 4, 5 as indicated in the previous embodiment and then sends in step 56 the request for access to the predetermined information to the server device 4, 5 selected .
  • the latter sends in step 58 the predetermined information to the first device 1.
  • the SEC field is used during the resolution of the domain name so that the client can decide according to the security mechanisms from the knowledge of the server name the security parameters set up by the server.
  • the SEC parameter refers only to security mechanisms related to a domain name.
  • An HSEC Field contains the server security information. This field is used to characterize the security mechanisms associated with an IP address. This field also makes it possible to know the security mechanisms of a server simply from its domain name (ie its name), and not from the domain name that it administers (ie the part of the namespace that he administers). In fact the HSEC field makes it possible to give the security mechanisms linked to the machine, ie to an IP address.
  • the SEC field consists of a certain number of bytes (2 for example). Each bit represents a mechanism. The bit is 1 if the mechanism is implanted and 0 otherwise.
  • the SEC field is described, for example, as follows: "Bit 0: Authentication / Integrity (SIG)
  • the SEC field has the value 0.
  • the HSEC field is dedicated to hosting information related to the domain name.
  • the HSEC field is hosted under the domain name of the server.
  • the HSEC field then has the value of the SEC security parameter.
  • the structure of the HSEC field is, for example, Textual representation on: owner class ttl HINFO cpu os
  • the NS * field has the following schema:
  • NSDNAME Domain name specifying a host that manages the DNS zone
  • DNS file The structure of a DNS file is, for example, the following movie.edu. IN SOA terminator.movie.edu. al.rohocop.movie.edu. (1, order number
  • a secure DNS resolution then comprises, in FIG. 5, at step 50 a type A request for resolution request to which the DNS server 3 responds to step 52 by an NS * field, that is to say a NS field concatenated with the SEC field containing the DNSSEC security mechanisms of the corresponding server.
  • the DNS client 1 has the necessary information to choose in step 54 the DNS server having DNSSEC security mechanisms adapted to its needs.
  • the DNS client 1 wants to know the security mechanisms implemented by a particular DNS server, FIG. 3, it sends at 40 an access request to the HSEC field of this server. This enables it to adapt its request for access to information according to the security mechanisms implemented without having to request all the information corresponding to all the DNS servers.
  • the access method can be implemented by a computer program product downloadable from a communication network and / or recorded on a computer readable medium and / or executable by a processor as shown in FIG. 6 and comprising an arithmetic and logic unit CPU, different registers MO, M1, M2, M3 and RAM memories as well as I / O inputs / outputs.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Hardware Redundancy (AREA)
  • Telephonic Communication Services (AREA)
EP07866500A 2006-11-15 2007-10-26 Markteinführung einer dnssec-basis Withdrawn EP2087699A2 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0609987A FR2908540A1 (fr) 2006-11-15 2006-11-15 Deploiement de bases dnssec
PCT/FR2007/052256 WO2008059150A2 (fr) 2006-11-15 2007-10-26 Deploiement de base dnssec

Publications (1)

Publication Number Publication Date
EP2087699A2 true EP2087699A2 (de) 2009-08-12

Family

ID=38325377

Family Applications (1)

Application Number Title Priority Date Filing Date
EP07866500A Withdrawn EP2087699A2 (de) 2006-11-15 2007-10-26 Markteinführung einer dnssec-basis

Country Status (4)

Country Link
US (1) US20100049982A1 (de)
EP (1) EP2087699A2 (de)
FR (1) FR2908540A1 (de)
WO (1) WO2008059150A2 (de)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8935748B2 (en) * 2007-10-31 2015-01-13 Microsoft Corporation Secure DNS query
US8429715B2 (en) * 2008-08-08 2013-04-23 Microsoft Corporation Secure resource name resolution using a cache
US7917616B2 (en) 2008-08-08 2011-03-29 Microsoft Corporation Secure resource name resolution
US8645700B2 (en) 2011-04-29 2014-02-04 Verisign, Inc. DNSSEC inline signing
US9130917B2 (en) * 2011-05-02 2015-09-08 Verisign, Inc. DNSSEC signing server
US10924452B1 (en) * 2013-08-30 2021-02-16 Amazon Technologies, Inc. Auditing IP address assignments
US10050927B2 (en) * 2015-01-27 2018-08-14 Mastercard International Incorporated Systems and methods for centralized domain name system administration

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6801998B1 (en) * 1999-11-12 2004-10-05 Sun Microsystems, Inc. Method and apparatus for presenting anonymous group names
US6961783B1 (en) * 2001-12-21 2005-11-01 Networks Associates Technology, Inc. DNS server access control system and method
GB2389431A (en) * 2002-06-07 2003-12-10 Hewlett Packard Co An arrangement for delivering resources over a network in which a demand director server is aware of the content of resource servers
GB0216000D0 (en) * 2002-07-10 2002-08-21 Nokia Corp A method for setting up a security association
US20070050507A1 (en) * 2005-08-24 2007-03-01 Nokia Corporation Context discovery for DNS names

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO2008059150A3 *

Also Published As

Publication number Publication date
WO2008059150A2 (fr) 2008-05-22
WO2008059150A3 (fr) 2008-10-09
US20100049982A1 (en) 2010-02-25
FR2908540A1 (fr) 2008-05-16

Similar Documents

Publication Publication Date Title
EP2087699A2 (de) Markteinführung einer dnssec-basis
JP4762347B2 (ja) セキュア・ピアツーピア・キャッシュ共有
EP1974522B1 (de) Server, Client und Verfahren zur Verwaltung von DNSSEC-Anforderungen
CN102667749A (zh) Dns应用服务器
US20110099621A1 (en) Process for monitoring, filtering and caching internet connections
EP3087718B1 (de) Erhalten von daten zum anschluss an eine vorrichtung über ein netzwerk
WO2013110884A1 (fr) Systeme et procede de controle d'une requête dns
EP1085725B1 (de) Verfahren zur Kommunikation eines Benutzers mit mindestens einer Datenbank
WO2018115647A1 (fr) Validation de livraison de contenu et de verification d'une delegation de livraison d'un contenu
Hudák Analysis of DNS in cybersecurity
FR3023098A1 (fr) Procede et systeme de traitement d'une demande de resolution d'un nom d'un serveur, emise par une application cliente sur un reseau de communication.
WO2023083772A1 (fr) Procédés de contrôle et de transmission, et entités configurées pour mettre en œuvre ces procédés
KR101645222B1 (ko) 어드밴스드 도메인 네임 시스템 및 운용 방법
CA2433216A1 (fr) Serveur d'annuaire reparti
EP4024820B1 (de) Verfahren zur konfiguration einer sicheren schnittstelle zwischen einem transportnetz und einem elementarnetz aus einer vielzahl von elementarnetzen, die über das transportnetz föderiert sind; zugehörige schnittstelle
EP3476107B1 (de) Verfahren und vorrichtung zur steuerung eines nach dem domänennamensystem(dns)-protokoll übertragenen datenstroms
EP3820112A1 (de) Konfiguraitonsverfahren für den zugriff auf einen internetdienst
WO2010076536A2 (fr) Procède de traitement de requêtes émises par un client
EP1843518B1 (de) Verfahren zum Schutz von Instant-Messaging-Adressen, zugehöriges System und Vorrichtungen
FR3074386A1 (fr) Gestion de l'acces a un serveur de contenus via a une passerelle
EP4595408A1 (de) Verfahren zur namensauflösung, kommunikation, nachrichtenverarbeitung und server, entsprechende client-vorrichtung und relaisknoten
FR3107798A1 (fr) Procédé de gestion d’une requête d’accès à un site internet depuis un dispositif d’accès
Pais et al. Providing Secure Access to Unsecure Web Services
EP3643035A1 (de) Verfahren zur steuerung des erhaltens, durch ein endgerät, einer konfigurationsdatei
FR2788398A1 (fr) Interfonctionnement de caches cooperants et caches repartis

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20090513

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR

DAX Request for extension of the european patent (deleted)
17Q First examination report despatched

Effective date: 20110110

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20130216