RWTH Aachen University
Transport Security Orchestration Using DNS
Pages
3
Time to read
10 mins
Publication
Language
English
Pages
3
Time to read
10 mins
Publication
Language
English
This document is a technical report that presents a system for adaptive transport security orchestration utilizing the Domain Name System (DNS). The proposed system aims to enhance the security of data transmission across communication networks by embedding service sensitivity information within the DNS. This allows clients to select appropriate cryptographic primitives based on the sensitivity of the data being exchanged. The report discusses the limitations of current security practices, which often apply a uniform level of security regardless of data sensitivity, leading to unnecessary computational overhead. The authors propose a new DNS record type, SEC, to capture security requirements for different services, facilitating centralized management of security policies. Initial evaluations indicate that this approach can reduce computational load on hosts and minimize communication overhead for non-sensitive data. The report outlines future work, including the implementation of the SEC record and further assessments of the design's impact on resource-constrained hardware.