Secure consensus generation with distributed DoH

AutorJeitner, P.; Shulman, H.; Waidner, M.
ArtConference Paper
AbstraktMany applications and protocols depend on the ability to generate a pool of servers to conduct majority-based consensus mechanisms and often this is done by doing plain DNS queries. A recent off-path attack [1] against NTP and security enhanced NTP with Chronos [2] showed that relying on DNS for generating the pool of NTP servers introduces a weak link. In this work, we propose a secure, backward-compatible address pool generation method using distributed DNS-over-HTTPS (DoH) resolvers which is aimed to prevent such attacks against server pool generation.
KonferenzInternational Conference on Dependable Systems and Networks (DSN) <50, 2020, Online>
ReferenzInstitute of Electrical and Electronics Engineers -IEEE-: DSN-S 2020 supplemental volume. 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks: Proceedings : 29 June-2 July 2020, Valencia, Spain. Piscataway, NJ: IEEE, 2020, pp. 41-42
SchlüsselISBN : 9781728172606