arrow
Return

A Privacy-Preserving Full DNS over HTTPS Architecture via Compatible NS Record Based Information Sharing

delete2026-02-01
delete0
PRE
AI
S
Satoru Sunahara *
Y
Yong Jin
K
Katsuyoshi Iida
N
Nariyoshi Yamai
Y
Yoshiaki Takai
DOI:10.23919/transcom.2025CEP0007delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The encryption of DNS communication for privacy protection has been gaining much attraction in recent years. The IETF has standardized protocols for discovering the encryption method of DNS communication between DNS full-service resolvers and authoritative DNS servers through RFCs 9461 and 9539. However, RFC 9461 has a limitation in that the SVCB records required to discover the encryption protocols supported by authoritative DNS servers must be resolved in plaintext. On the other hand, RFC 9539 generates unnecessary traffic by attempting encrypted communication even with authoritative DNS servers that do not support encryption protocols. Moreover, when both plaintext and encrypted communication are used to maintain compatibility, there is a risk of privacy information leakage. To address this issue, we propose and evaluate a new approach in which the parent authoritative DNS server indicates the encryption protocols supported by the child authoritative DNS server in the NS records during the zone delegation without violating the conventional DNS name resolution. The contributions of this paper can be summarized as i) Design and implement a privacy-preserving full DNS over HTTPS (DoH) architecture. ii) Propose NS record based information sharing to provide a compatibility with existing DNS architecture. iii) The functionality and performance of the proposed method are evaluated using the prototype system. iv) A discussion is provided on the proposed method and further enhancements for DNS privacy protection. Through the evaluations of the prototype system, we confirmed that the proposed architecture outperforms the existing approach using SVCB records to discover the encryption protocols supported by the authoritative DNS servers.
Keywords:
DNS
DNS over HTTPS
DoH
privacy
institutional privacy
Full-DoH
authoritative DNS encryption
protocol discovery

Journal

I
IEICE Transactions on Communications
IF:
0.6
Papers:
193
Citations:
1.2K

Organization

T
tokyo university of agriculture & technology
Scholars:
325
Papers: 152
Citations: 0
C
chitose institute science & technology
Scholars:
8
Papers: 5
Citations: 0
I
institute of science tokyo
Scholars:
3.3K
Papers: 1.2K
Citations: 0
H
hokkaido university
Scholars:
5.1K
Papers: 1.8K
Citations: 0
researcher View more organizations