Security Considerations for Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation
Cameron McGowan, James Liu, Sushmita Ruj · 2025
The Domain Name System (DNS) is one of the most widely used systems in the world, invoked every time anyone visits a website or connects to a server over the internet. DNS security extensions (DNSSEC) provide users with security that the websites they access are legitimate. However, the emerging threat of quantum computers requires new quantum-resistant techniques to maintain DNSSEC's security. Our paper addresses a memory exhaustion vulnerability in a recently proposed resource record fragmentation (ARRF) technique which efficiently provides a post-quantum (PQ) DNSSEC. In fixing this vulnerability with minimal performance penalties, we hope to bring ARRF closer to deployment in real-world environments.