Poster: Transport Security Orchestration Using DNS

Abstract

Communication networks enable the exchange of data with varying sensitivity, from non-sensitive public files to highly confidential healthcare or financial records. Cryptographic protection introduces significant computational and communication overhead. While lightweight ciphers have been proposed to reduce this burden, they compromise security and are unsuitable for sensitive data. We propose a system that enables adaptive security by embedding service sensitivity information in the Domain Name System (DNS), allowing peers to select appropriate cryptographic primitives based on data requirements. This approach ensures adequate protection while minimizing overhead. Additionally, it can be seamlessly integrated into existing networks without additional hardware. Initial results indicate improved throughput and reduced computational load on hosts.

Type
Publication
Proceedings of the 33rd IEEE International Conference on Network Protocols (ICNP '25)
Event
33rd IEEE International Conference on Network Protocols, Sep 22 - Sep 25, 2025, Seoul, South Korea
Placeholder Avatar
Sahi Islam
Dr. rer. nat. Jan Pennekamp
Dr. rer. nat. Jan Pennekamp
Postdoctoral Researcher
Klaus Wehrle
Klaus Wehrle
Head of Group