RHINE: Robust and High-performance Internet Naming with E2E Authenticity
Huayi Duan, Rubén Fischer, Jie Lou, Si Liu, David A. Basin, Adrian Perrig
Abstract
The variety and severity of recent DNS-based attacks underscore the importance of a secure naming system. Although DNSSEC provides data authenticity in theory, practical deployments unfortunately are fragile, costly, and typically lacks end-to-end (E2E) guarantees. This motivates us to rethink authentication in DNS fundamentally and introduce RHINE, a secure-by-design Internet naming system.
RHINE offloads the authentication of zone delegation to an end-entity PKI and tames the operational complexity in an offline manner, allowing the efficient E2E authentication of zone data during online name resolution. With a novel logging mechanism, Delegation Transparency, RHINE achieves a highly robust trust model that can tolerate the compromise of all but one trusted entities and, for the first time, counters threats from superordinate zones. We formally verify RHINE's security properties using the Tamarin prover. We also demonstrate its practicality and performance advantages with a prototype implementation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9be7e1ee-1ffd-4456-b8be-342f20d6d5c9Cited by top-tier papers3
- A Formal Framework for End-to-End DNS ResolutionSi Liu, Huayi Duan, Lukas Heimes, Marco Bearzi et al.SIGCOMM 2023 · 11 citations
- PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery NetworksShihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu et al.NSDI 2025 · 2 citations
- NOPE: Strengthening domain authentication with succinct proofsZachary DeStefano, Jeff J. Ma, Joseph Bonneau, Michael WalfishSOSP 2024 · 2 citations
Builds on19
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi et al.USENIX Security 2017 · 163 citations
- A Longitudinal, End-to-End View of the DNSSEC EcosystemTaejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran, David R. Choffnes et al.USENIX Security 2017 · 125 citations
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann et al.CCS 2018 · 71 citations
- Transparency Logs via Append-Only Authenticated DictionariesAlin Tomescu, Vivek Bhupatiraju, Dimitrios Papadopoulos, Charalampos Papamanthou et al.CCS 2019 · 69 citations
Related papers
- Under the Hood of DANE Mismanagement in SMTPHyeonmin Lee, Md. Ishtiaq Ashiq, Moritz Müller, Roland van Rijswijk-Deij et al.USENIX Security 2022
- Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNSTaejoong Chung, Dave Levin, Protick BhowmickSIGCOMM 2025 · 2 citations
- Your Shield is My Sword: A Persistent Denial-of-Service Attack via the Reuse of Unvalidated Caches in DNSSEC ValidationShuhan Zhang, Shuai Wang, Li Chen, Dan Li et al.USENIX Security 2025
- A Longitudinal and Comprehensive Study of the DANE Ecosystem in EmailHyeonmin Lee, Aniketh Gireesh, Roland van Rijswijk-Deij, Taekyoung Kwon et al.USENIX Security 2020
- Robust or Risky: Measurement and Analysis of Domain Resolution DependencyShuhan Zhang, Shuai Wang, Dan LiINFOCOM 2024 · 3 citations
