论文标题
没有集中化的加密:在递归解析器上分发DNS查询
Encryption without Centralization: Distributing DNS Queries Across Recursive Resolvers
论文作者
论文摘要
新兴协议,例如DNS-Over-HTTP(DOH)和DNS-Over-TLS(DOT)改善了DNS查询和响应的隐私。尽管这种加密趋势是积极的,但在某些情况下,这些协议的部署导致了DNS的进一步集中化,这引入了新的挑战。特别是,集中化对绩效,隐私和可用性有后果;一个潜在的问题是,控制DNS递归解析器的选择变得越来越困难,尤其是对于物联网设备而言。最终,在一个或多个递归解析器之间选择的最佳策略最终可能取决于情况,用户甚至设备。因此,DNS体系结构必须允许允许用户,设备和应用程序指定这些策略的灵活性。为了增加偏心化和提高灵活性的目标,本文介绍了经过重构的DNS解析器体系结构的设计和实施,该架构允许偏心化名称分辨率,并保留了加密DNS的好处,同时满足了其他理想的属性,包括性能和隐私。
Emerging protocols such as DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) improve the privacy of DNS queries and responses. While this trend towards encryption is positive, deployment of these protocols has in some cases resulted in further centralization of the DNS, which introduces new challenges. In particular, centralization has consequences for performance, privacy, and availability; a potentially greater concern is that it has become more difficult to control the choice of DNS recursive resolver, particularly for IoT devices. Ultimately, the best strategy for selecting among one or more recursive resolvers may ultimately depend on circumstance, user, and even device. Accordingly, the DNS architecture must permit flexibility in allowing users, devices, and applications to specify these strategies. Towards this goal of increased de-centralization and improved flexibility, this paper presents the design and implementation of a refactored DNS resolver architecture that allows for de-centralized name resolution, preserving the benefits of encrypted DNS while satisfying other desirable properties, including performance and privacy.