The DNS to Reinforce the PKIX for IoT Backend Servers: Implementation and Evaluation - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2022

The DNS to Reinforce the PKIX for IoT Backend Servers: Implementation and Evaluation

Résumé

The current Public Key Infrastructure on the Internet depends on binding names to public keys via the digital X.509 certificates. These certificates are issued by certificate authorities (CAs), and only certificates verified by one of these CAs are accepted. This model requires TLS (Transport Layer Security) clients to store dozens of trusted CA certificates and has proved to lack immunity against security breaches. The Domain Name System (DNS) could reinforce and complement the functioning of CAs. The DNS-Based Authentication of Named Entities (DANE) protocol is designed to use DNS to bind certificates or keys to domain names by adding TLSA resource records (RRs) to zones. Verification is done by fetching the certificate's TLSA RR and matching it against it. DANE utilizes DNSSEC, which guarantees the integrity and authenticity of DNS responses. Besides TLS servers, TLS clients could also have TLSA RR and be verified via DANE, allowing mutual authentication between clients and servers. In this paper, we implement DANE and perform mutual authentication for IoT backend servers. Our use case is a mutual authentication process between LoRaWAN's Join and Network servers upon receiving a join request from a LoRaWAN enddevice. We study the latency introduced by mutual authentication via DANE and compare it to traditional CA.
Fichier principal
Vignette du fichier
WMNC2022.pdf (268.59 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03798669 , version 1 (05-10-2022)

Identifiants

  • HAL Id : hal-03798669 , version 1

Citer

Ibrahim Ayoub, Gaël Berthaud-Müller, Sandoche Balakrichenan, Kinda Khawam, Benoît Ampeau. The DNS to Reinforce the PKIX for IoT Backend Servers: Implementation and Evaluation. 14th IFIP Wireless and Mobile Networking Conference, Oct 2022, Tunis, Tunisia. ⟨hal-03798669⟩
74 Consultations
68 Téléchargements

Partager

Gmail Facebook X LinkedIn More