1
A Threshold Cryptographic Backend for DNSSEC
Francisco Cifuentes
francisco@niclabs.cl
A Threshold Cryptographic Backend for DNSSEC Francisco Cifuentes - - PowerPoint PPT Presentation
A Threshold Cryptographic Backend for DNSSEC Francisco Cifuentes francisco@niclabs.cl 1 Key Management Implementations Back to ICANN 40 2 Key Management Implementations Needs Zones need to be re-signed PKCS#11 periodically. Keys
1
Francisco Cifuentes
francisco@niclabs.cl
2
3
HSM
Needs
periodically.
Problems
PKCS#11
4
PKCS#11
Threshold Cryptographic Backend
Threshold Cryptographic backend
5
PKCS#11
Threshold Cryptographic Backend
6
Cryptographic backend
7
– Private key is split into shares and distributed
– The signing procedure is called in each of the
8
– A subset of nodes can fail and the signing
9
– Failures and attacks can be reduced
10
– No one holds the complete private key. – More than k nodes have to be endangered to
11
12
13
14
Francisco Cifuentes
francisco@niclabs.cl