6–7 Feb 2025 Workshop
Atlanta Marriott Marquis
America/New_York timezone

New Method for Signing Wildcard Responses in Compact Denial of Existence

7 Feb 2025, 14:35
25m
Imperial Salon B ( Atlanta Marriott Marquis)

Imperial Salon B

Atlanta Marriott Marquis

265 Peachtree Center Ave NE Atlanta GA 30303 United States
In-Person Standard Presentation Main Session OARC 44 Day 2

Speaker

Liang Zhu (Microsoft)

Description

DNSSEC online signing is computationally expensive. In general, DNSSEC signature cache can reduce the overhead of generating signature on the fly. However, signature caching will not be effective for responses of wildcard record in current Compact Denial of Existence implementations, because query names can be unique and valid with wildcard expansion. In this talk, we present a new method of signing wildcard response for Compact Denial of Existence, by using a fabricated NSEC record which is smaller than the real NSEC range but is still large enough to cover a set of non-existent records. We show that this type of wildcard response can improve the signature cache hit ratio for some DNS zones, reducing query latency and improve server performance. We verify that this new type of wildcard responses is compatible with DNS protocol and is accepted by common DNS recursive implementations like BIND and Unbound.

Talk duration 20 Minutes (+5 for Q&A)

Primary author

Liang Zhu (Microsoft)

Presentation materials