EP2087699A2 - Markteinführung einer dnssec-basis - Google Patents
Markteinführung einer dnssec-basisInfo
- Publication number
- EP2087699A2 EP2087699A2 EP07866500A EP07866500A EP2087699A2 EP 2087699 A2 EP2087699 A2 EP 2087699A2 EP 07866500 A EP07866500 A EP 07866500A EP 07866500 A EP07866500 A EP 07866500A EP 2087699 A2 EP2087699 A2 EP 2087699A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- server
- security mechanisms
- dns
- request
- security
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 230000007246 mechanism Effects 0.000 claims abstract description 92
- 238000000034 method Methods 0.000 claims abstract description 22
- 230000005540 biological transmission Effects 0.000 claims abstract description 5
- 230000004044 response Effects 0.000 claims description 11
- 238000004590 computer program Methods 0.000 claims description 4
- 208000033748 Device issues Diseases 0.000 description 1
- 239000008186 active pharmaceutical agent Substances 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 230000015654 memory Effects 0.000 description 1
- 230000000750 progressive effect Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/168—Implementing security features at a particular protocol layer above the transport layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
- H04L67/1001—Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
- H04L67/1001—Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
- H04L67/1004—Server selection for load balancing
- H04L67/1023—Server selection for load balancing based on a hash applied to IP addresses or costs
Definitions
- the invention also relates to the first device and associated server devices and a computer program product implementing the access method.
- DNS Domain Name Service
- DNSSEC Secure DNS
- a malicious third party may, for example, intercept a DNS request for the IP address of a domain name corresponding, for example, to a banking site, and return to the requesting an IP address corresponding to a false site imitating the banking site and allowing to acquire the codes of access of the thus diverted customers.
- LlETF has therefore developed a secure version of the DNS standard, called DNSSEC, described in the TIETF, RFC4033, RFC 4034 and RFC 4035 documents.
- the DNSSEC protocol relies on several security mechanisms:
- NSEC2 makes it possible to classify the domain names as within a dictionary. Since there is an order, if the requested domain name is not between the expected names, it does not exist.
- the NSEC3 field has the same functions as the NSEC2 field, except that it does not return unencrypted data from the previous domain name and the next domain name. It returns a hash key of these names. This prevents the zone from being listed.
- a chain of trust mechanism This mechanism makes it possible to go from one level of the hierarchy of the DNS servers to a lower level without losing confidence.
- the DNS protocol includes some security mechanisms such as:
- An object of the invention is therefore a method of access by a first device to duplicate predetermined information in a plurality of server devices, each server device implementing a subset of security mechanisms of a predetermined set of security mechanisms so that to provide a predefined level of security of access to the predetermined information, said method comprising the steps of: a) transmission by the first device of at least one access request adapted to receive the list of security mechanisms tmpîtigés by the server devices, b) sending by the first device to at least one of said server devices a predetermined access to information request, said request using the security mechanisms implemented by the at least one of said server devices.
- Other characteristics and particular modes of realization are:
- step a) comprises emitting a directed access request to the central server device , which advantageously makes it possible to obtain with a single request the list of server devices and their security mechanisms.
- Ie central server device sends to the first device a sublist of said list, said sub-list having only references to the server devices having the predetermined information, which advantageously allows to limit the amount of information transferred.
- step a) consists in issuing a DNS request of type A in order to determine the IP address corresponding to a DNS address with the DNS server.
- highest-level DNS server and the highest-level DNS server response to this request is a NS-type DNS response that concatenates the DNSSEC security mechanism description fields implemented for each DNS server whose address is transmitted in the NS type response, which advantageously makes it possible to select the DNS server impimalant the selected mechanisms of the DNSSEC protocol.
- step a) consists of a DNS request to acquire the characteristics of an addressed server device to said server device, to which said server device responds by transmitting to the first device a field of description of the security mechanisms of the DNSSEC standard implemented by said server device, which advantageously makes it possible to know the DNSSEC security mechanisms implemented by the DNS server.
- Another object of the invention is a device for accessing predetermined information duplicated in several server devices, each server device impinging a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a level of security.
- predefined security access to predetermined information characterized in that it comprises: a) means for transmitting at least one access request adapted to receive the list of security mechanisms implemented by the server devices , b) means for transmitting to at least one of said server devices a predetermined access request to the information, said request using the security mechanisms implemented by the at least one of said server devices.
- Another object of the invention is a server device impregnating a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a predefined level of security of access to predetermined information, characterized in that 'it comprises : a) means for receiving at least one access request by a first device adapted to receive a list of the security mechanisms implemented by said server device, b) sending means in response to the access request la list of implemented security mechanisms, c) means for receiving a predetermined access request to the information transmitted by the first device, said request using the security mechanisms implemented by said server device.
- Another object of the invention relates to a system for accessing a predetermined information comprising an access device according to the invention and several server devices according to the invention.
- Another object of the invention is a computer program comprising program code instructions for performing the steps of the preceding method when said program is executed on a computer.
- FIG. 1 is a schematic view of an access system according to one embodiment of the invention.
- FIG. 2 is a schematic view of a first device of the system of FIG. 1;
- FIG. 3 is a schematic view of a server device of the system of FIG. 1;
- FIG. 4 is a flow chart of a first embodiment of the method according to the invention.
- FIG. 5 is a flow diagram of a second embodiment of the method according to the invention.
- FIG. 6 is a schematic view of a computer implementing a program implementing an embodiment of the method according to the invention.
- a first device 1 is connected via a data network 2 to server devices 3, 4, 5.
- the first device 1 is a DNS client, for example a recursive cache server
- the server devices 3, 4 and 5 are DNS servers.
- the DNS servers are organized into a hierarchy of servers corresponding to the hierarchy of domain names.
- the DNS server 3 is the authoritative server on the ".fr" zone
- the DNS server 4 is the authoritative server on the "francetelecom.fr” domain
- the DNS server 5 is the authoritative server on the domain
- the hierarchy between DNS servers is particularly illustrated during a traditional resolution of the domain name.
- the DNS client 1 wants to know the IP address of the address www.francetelecom.fr.
- the DNS client 1 sends a request concerning this domain to the root server (not shown). This returns the IP address of the authoritative DNS server to the ".fr" zone, namely the DNS server 3. The DNS client 1 then sends a request to resolve the domain www.francetelecom.fr to the DNS server 3 This returns the address! P of the authoritative DNS server for the domain "francetelecom.fr", ie the server 4. The DNS client 1 then sends a resolution request for www.francetelecom.fr to the DNS server. 4. This returns the IP address of the corresponding web server, the IP address that is transferred by the DNS client 1 to the HTTP client that issued the initial request so that it can query the web server.
- the first device 1 comprises, FIG. 2, means 10 of connection to the data network 2.
- H comprises means 12 for transmitting at least one access request adapted to receive a list of security mechanisms implemented by the server devices 3, 4, 5.
- the access request is such that it uses the implemented security mechanisms.
- the server devices 3, 4, 5 comprise, FIG. 3, means 20 for storing a predetermined information item. This is, for example, a database of information related to the DNS protocol.
- Access to this information is controlled by security mechanisms 22 defining a level of security of access to this information.
- the server devices 3, 4, 5 comprise means 24 for connection to the data network 2.
- Reception means 26 are connected to the connection means 24.
- the receiving means 26 are adapted to receive an access request from the first device 1.
- This access request includes a request for information on the list of implemented security mechanisms 22.
- the server device 3, 4, 5 comprises means 28 for sending the list of implemented security mechanisms 22.
- the server device 3, 4, 5 further comprises means 30 for receiving a request for access to the predetermined information, a request sent by the first device 1. This request uses the access security mechanisms 22 to access to information.
- step 40 the first device 1 sends at least one request to at least one of the server devices 3, 4, 5.
- step 42 each polled server device 3, 4, 5 responds by sending a list of implemented security mechanisms.
- the first device 1 selects one of the server devices 3, 4, 5 according to the security mechanisms implemented by it. For example, the first device 1 compares the list of security mechanisms implemented by each server device to a predetermined subset of security mechanisms.
- step 46 the first device issues a request for access to the information stored in the storage means. This request is intended for the server device 3 "4, 5 selected and respects the security mechanisms impiementés by this server device 3, 4, 5.
- step 48 the security mechanisms having been correctly activated, the server device 3, 4, 5 sends the first device 1 the requested information.
- one of the server devices 3, 4, 5, for example the server device 3, has a central server device role comprising a list referencing the server devices 4, 5 as well as the subset of the security mechanisms. impiementé by each server device 4, 5.
- step 50 the first device 1 then sends its request to the central server device 3.
- step 52 the response of the central device 3 includes a list of the server devices 4, 5 and the implemented security mechanisms.
- the list sent by the server device Central 3 only includes server devices containing the predetermined information.
- the first device 1 selects in step 54 a server device 4, 5 as indicated in the previous embodiment and then sends in step 56 the request for access to the predetermined information to the server device 4, 5 selected .
- the latter sends in step 58 the predetermined information to the first device 1.
- the SEC field is used during the resolution of the domain name so that the client can decide according to the security mechanisms from the knowledge of the server name the security parameters set up by the server.
- the SEC parameter refers only to security mechanisms related to a domain name.
- An HSEC Field contains the server security information. This field is used to characterize the security mechanisms associated with an IP address. This field also makes it possible to know the security mechanisms of a server simply from its domain name (ie its name), and not from the domain name that it administers (ie the part of the namespace that he administers). In fact the HSEC field makes it possible to give the security mechanisms linked to the machine, ie to an IP address.
- the SEC field consists of a certain number of bytes (2 for example). Each bit represents a mechanism. The bit is 1 if the mechanism is implanted and 0 otherwise.
- the SEC field is described, for example, as follows: "Bit 0: Authentication / Integrity (SIG)
- the SEC field has the value 0.
- the HSEC field is dedicated to hosting information related to the domain name.
- the HSEC field is hosted under the domain name of the server.
- the HSEC field then has the value of the SEC security parameter.
- the structure of the HSEC field is, for example, Textual representation on: owner class ttl HINFO cpu os
- the NS * field has the following schema:
- NSDNAME Domain name specifying a host that manages the DNS zone
- DNS file The structure of a DNS file is, for example, the following movie.edu. IN SOA terminator.movie.edu. al.rohocop.movie.edu. (1, order number
- a secure DNS resolution then comprises, in FIG. 5, at step 50 a type A request for resolution request to which the DNS server 3 responds to step 52 by an NS * field, that is to say a NS field concatenated with the SEC field containing the DNSSEC security mechanisms of the corresponding server.
- the DNS client 1 has the necessary information to choose in step 54 the DNS server having DNSSEC security mechanisms adapted to its needs.
- the DNS client 1 wants to know the security mechanisms implemented by a particular DNS server, FIG. 3, it sends at 40 an access request to the HSEC field of this server. This enables it to adapt its request for access to information according to the security mechanisms implemented without having to request all the information corresponding to all the DNS servers.
- the access method can be implemented by a computer program product downloadable from a communication network and / or recorded on a computer readable medium and / or executable by a processor as shown in FIG. 6 and comprising an arithmetic and logic unit CPU, different registers MO, M1, M2, M3 and RAM memories as well as I / O inputs / outputs.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
- Hardware Redundancy (AREA)
- Telephonic Communication Services (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0609987A FR2908540A1 (fr) | 2006-11-15 | 2006-11-15 | Deploiement de bases dnssec |
| PCT/FR2007/052256 WO2008059150A2 (fr) | 2006-11-15 | 2007-10-26 | Deploiement de base dnssec |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2087699A2 true EP2087699A2 (de) | 2009-08-12 |
Family
ID=38325377
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07866500A Withdrawn EP2087699A2 (de) | 2006-11-15 | 2007-10-26 | Markteinführung einer dnssec-basis |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20100049982A1 (de) |
| EP (1) | EP2087699A2 (de) |
| FR (1) | FR2908540A1 (de) |
| WO (1) | WO2008059150A2 (de) |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8935748B2 (en) * | 2007-10-31 | 2015-01-13 | Microsoft Corporation | Secure DNS query |
| US8429715B2 (en) * | 2008-08-08 | 2013-04-23 | Microsoft Corporation | Secure resource name resolution using a cache |
| US7917616B2 (en) | 2008-08-08 | 2011-03-29 | Microsoft Corporation | Secure resource name resolution |
| US8645700B2 (en) | 2011-04-29 | 2014-02-04 | Verisign, Inc. | DNSSEC inline signing |
| US9130917B2 (en) * | 2011-05-02 | 2015-09-08 | Verisign, Inc. | DNSSEC signing server |
| US10924452B1 (en) * | 2013-08-30 | 2021-02-16 | Amazon Technologies, Inc. | Auditing IP address assignments |
| US10050927B2 (en) * | 2015-01-27 | 2018-08-14 | Mastercard International Incorporated | Systems and methods for centralized domain name system administration |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6801998B1 (en) * | 1999-11-12 | 2004-10-05 | Sun Microsystems, Inc. | Method and apparatus for presenting anonymous group names |
| US6961783B1 (en) * | 2001-12-21 | 2005-11-01 | Networks Associates Technology, Inc. | DNS server access control system and method |
| GB2389431A (en) * | 2002-06-07 | 2003-12-10 | Hewlett Packard Co | An arrangement for delivering resources over a network in which a demand director server is aware of the content of resource servers |
| GB0216000D0 (en) * | 2002-07-10 | 2002-08-21 | Nokia Corp | A method for setting up a security association |
| US20070050507A1 (en) * | 2005-08-24 | 2007-03-01 | Nokia Corporation | Context discovery for DNS names |
-
2006
- 2006-11-15 FR FR0609987A patent/FR2908540A1/fr not_active Withdrawn
-
2007
- 2007-10-26 US US12/312,510 patent/US20100049982A1/en not_active Abandoned
- 2007-10-26 EP EP07866500A patent/EP2087699A2/de not_active Withdrawn
- 2007-10-26 WO PCT/FR2007/052256 patent/WO2008059150A2/fr not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2008059150A3 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2008059150A2 (fr) | 2008-05-22 |
| WO2008059150A3 (fr) | 2008-10-09 |
| US20100049982A1 (en) | 2010-02-25 |
| FR2908540A1 (fr) | 2008-05-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2087699A2 (de) | Markteinführung einer dnssec-basis | |
| JP4762347B2 (ja) | セキュア・ピアツーピア・キャッシュ共有 | |
| EP1974522B1 (de) | Server, Client und Verfahren zur Verwaltung von DNSSEC-Anforderungen | |
| CN102667749A (zh) | Dns应用服务器 | |
| US20110099621A1 (en) | Process for monitoring, filtering and caching internet connections | |
| EP3087718B1 (de) | Erhalten von daten zum anschluss an eine vorrichtung über ein netzwerk | |
| WO2013110884A1 (fr) | Systeme et procede de controle d'une requête dns | |
| EP1085725B1 (de) | Verfahren zur Kommunikation eines Benutzers mit mindestens einer Datenbank | |
| WO2018115647A1 (fr) | Validation de livraison de contenu et de verification d'une delegation de livraison d'un contenu | |
| Hudák | Analysis of DNS in cybersecurity | |
| FR3023098A1 (fr) | Procede et systeme de traitement d'une demande de resolution d'un nom d'un serveur, emise par une application cliente sur un reseau de communication. | |
| WO2023083772A1 (fr) | Procédés de contrôle et de transmission, et entités configurées pour mettre en œuvre ces procédés | |
| KR101645222B1 (ko) | 어드밴스드 도메인 네임 시스템 및 운용 방법 | |
| CA2433216A1 (fr) | Serveur d'annuaire reparti | |
| EP4024820B1 (de) | Verfahren zur konfiguration einer sicheren schnittstelle zwischen einem transportnetz und einem elementarnetz aus einer vielzahl von elementarnetzen, die über das transportnetz föderiert sind; zugehörige schnittstelle | |
| EP3476107B1 (de) | Verfahren und vorrichtung zur steuerung eines nach dem domänennamensystem(dns)-protokoll übertragenen datenstroms | |
| EP3820112A1 (de) | Konfiguraitonsverfahren für den zugriff auf einen internetdienst | |
| WO2010076536A2 (fr) | Procède de traitement de requêtes émises par un client | |
| EP1843518B1 (de) | Verfahren zum Schutz von Instant-Messaging-Adressen, zugehöriges System und Vorrichtungen | |
| FR3074386A1 (fr) | Gestion de l'acces a un serveur de contenus via a une passerelle | |
| EP4595408A1 (de) | Verfahren zur namensauflösung, kommunikation, nachrichtenverarbeitung und server, entsprechende client-vorrichtung und relaisknoten | |
| FR3107798A1 (fr) | Procédé de gestion d’une requête d’accès à un site internet depuis un dispositif d’accès | |
| Pais et al. | Providing Secure Access to Unsecure Web Services | |
| EP3643035A1 (de) | Verfahren zur steuerung des erhaltens, durch ein endgerät, einer konfigurationsdatei | |
| FR2788398A1 (fr) | Interfonctionnement de caches cooperants et caches repartis |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20090513 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20110110 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20130216 |