Encryption without Centralization: Distributing DNS Queries Across Recursive Resolvers

PDF Paper Library link to paper

Authors

Austin Hounsel, Paul Schmitt, Kevin Borgolte, Nick Feamster

Publication

Proceedings of the 2021 Applied Networking Research Workshop (ANRW), July 2021

Extended abstract. Co-located with IETF 105.

Abstract

Emerging protocols such as DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) improve the privacy of DNS queries and responses. While this trend towards encryption is positive, deployment of these protocols has in some cases resulted in further centralization of the DNS, which introduces new challenges. In particular, centralization has consequences for performance, privacy, and availability; a potentially greater concern is that it has become more difficult to control the choice of DNS recursive resolver, particularly for IoT devices. Ultimately, the best strategy for selecting among one or more recursive resolvers may ultimately depend on circumstance, user, and even device. Accordingly, the DNS architecture must permit flexibility in allowing users, devices, and applications to specify these strategies. Towards this goal of increased de-centralization and improved flexibility, this paper presents the design and implementation of a refactored DNS resolver architecture that allows for de-centralized name resolution, preserving the benefits of encrypted DNS while satisfying other desirable properties, including performance and privacy.

BibTeX

@inproceedings{anrw2021-encryption-without-centralization,
  title     = {{Encryption without Centralization: Distributing DNS Queries Across Recursive Resolvers}},
  author    = {Hounsel, Austin and Schmitt, Paul and Borgolte, Kevin and Feamster, Nick},
  booktitle = {Proceedings of the 2021 Applied Networking Research Workshop (ANRW)},
  date      = {2021-07-24},
  doi       = {10.1145/3472305.3472318},
  editor    = {Lutu, Andra and Feamster, Nick},
  location  = {Online},
  publisher = {Association for Computing Machinery (ACM)},
  url       = {https://doi.org/10.1145/3472305.3472318}
}