Skip to main navigation Skip to search Skip to main content

Evaluating Post-Quantum Cryptography in DNSSEC Signing for Top-Level Domain Operators

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

4 Downloads (Pure)

Abstract

Like all other digital systems, the Domain Name System (DNS) needs to remain secure, even when future quantum computers are built. This means that DNS operators need to understand the implications of replacing the currently deployed cryptographic algorithms of the DNS Security Extensions (DNSSEC) with post-quantum cryptography (PQC) ones, which are vastly different. We therefore empirically analyze the signing performance of promising PQC algorithms MAYO-2 and Falcon-512 from a DNS operator point of view, in terms of zone file size, signing time, and validation time, and compare them to currently deployed algorithms RSA-1280 and ECDSA-P256. In our experiments, we use a PQC-enhanced DNSSEC signer, the zone files of three country code Top-Level Domains (ccTLDs) of different sizes, and two different CPU models to measure the effects of CPU optimizations. We find that the DNSSEC signing performance of MAYO-2 is better than RSA-1280, while Falcon-512 performs similarly. The validation performance of MAYO-2 is better than ECDSA-P256 and comparable to RSA-1280, whereas Falcon-512 is 0.3 times slower than ECDSA-P256. These results suggest that DNSSEC signing with MAYO-2 and Falcon-512 is feasible for TLD operators. However, Falcon-512 generates larger signature size and MAYO-2 has larger public keys. These drawbacks should be studied further to assess their operational impact on the validation side, for example by studying the behavior of DNS resolvers with PQC algorithms.

Original languageEnglish
Title of host publicationTMA 2025
Subtitle of host publicationProceedings of the 9th Network Traffic Measurement and Analysis Conference
PublisherIEEE
Number of pages10
ISBN (Electronic)978-3-903176-74-4
ISBN (Print)979-8-3315-5505-4
DOIs
Publication statusPublished - 10 Jun 2025
Event9th Network Traffic Measurement and Analysis Conference, TMA 2025 - Aalborg University, Copenhagen, Denmark
Duration: 10 Jun 202513 Jun 2025
Conference number: 9
https://tma.ifip.org/2025/

Publication series

NameNetwork Traffic Measurement and Analysis Conference (TMA)
PublisherIEEE
Volume2025

Conference

Conference9th Network Traffic Measurement and Analysis Conference, TMA 2025
Abbreviated titleTMA 2025
Country/TerritoryDenmark
CityCopenhagen
Period10/06/2513/06/25
Internet address

Keywords

  • 2026 OA procedure
  • DNSSEC
  • measurements
  • post-quantum cryptography
  • DNS

Fingerprint

Dive into the research topics of 'Evaluating Post-Quantum Cryptography in DNSSEC Signing for Top-Level Domain Operators'. Together they form a unique fingerprint.

Cite this