Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon – CircleID
This is the fourth in a multi-part series on cryptography and the Domain Name System (DNS).
One of the "key" questions cryptographers have been asking for the past decade or more is what to do about the potential future development of a large-scale quantum computer.
If theory holds, a quantum computer could break established public-key algorithms including RSA and elliptic curve cryptography (ECC), building on Peter Shor's groundbreaking result from 1994.
This prospect has motivated research into new so-called "post-quantum" algorithms that are less vulnerable to quantum computing advances. These algorithms, once standardized, may well be added into the Domain Name System Security Extensions (DNSSEC) thus also adding another dimension to a cryptographer's perspective on the DNS.
(Caveat: Once again, the concepts I'm discussing in this post are topics we're studying in our long-term research program as we evaluate potential future applications of technology. They do not necessarily represent Verisign's plans or position on possible new products or services.)
The National Institute of Standards and Technology (NIST) started a Post-Quantum Cryptography project in 2016 to "specify one or more additional unclassified, publicly disclosed digital signature, public-key encryption, and key-establishment algorithms that are capable of protecting sensitive government information well into the foreseeable future, including after the advent of quantum computers."
Security protocols that NIST is targeting for these algorithms, according to its 2019 status report (Section 2.2.1), include: "Transport Layer Security (TLS), Secure Shell (SSH), Internet Key Exchange (IKE), Internet Protocol Security (IPsec), and Domain Name System Security Extensions (DNSSEC)."
The project is now in its third round, with seven finalists, including three digital signature algorithms, and eight alternates.
NIST's project timeline anticipates that the draft standards for the new post-quantum algorithms will be available between 2022 and 2024.
It will likely take several additional years for standards bodies such as the Internet Engineering Task (IETF) to incorporate the new algorithms into security protocols. Broad deployments of the upgraded protocols will likely take several years more.
Post-quantum algorithms can therefore be considered a long-term issue, not a near-term one. However, as with other long-term research, it's appropriate to draw attention to factors that need to be taken into account well ahead of time.
The three candidate digital signature algorithms in NIST's third round have one common characteristic: all of them have a key size or signature size (or both) that is much larger than for current algorithms.
Key and signature sizes are important operational considerations for DNSSEC because most of the DNS traffic exchanged with authoritative data servers is sent and received via the User Datagram Protocol (UDP), which has a limited response size.
Response size concerns were evident during the expansion of the root zone signing key (ZSK) from 1024-bit to 2048-bit RSA in 2016, and in the rollover of the root key signing key (KSK) in 2018. In the latter case, although the signature and key sizes didn't change, total response size was still an issue because responses during the rollover sometimes carried as many as four keys rather than the usual two.
Thanks to careful design and implementation, response sizes during these transitions generally stayed within typical UDP limits. Equally important, response sizes also appeared to have stayed within the Maximum Transmission Unit (MTU) of most networks involved, thereby also avoiding the risk of packet fragmentation. (You can check how well your network handles various DNSSEC response sizes with this tool developed by Verisign Labs.)
The larger sizes associated with certain post-quantum algorithms do not appear to be a significant issue either for TLS, according to one benchmarking study, or for public-key infrastructures, according to another report. However, a recently published study of post-quantum algorithms and DNSSEC observes that "DNSSEC is particularly challenging to transition" to the new algorithms.
Verisign Labs offers the following observations about DNSSEC-related queries that may help researchers to model DNSSEC impact:
A typical resolver that implements both DNSSEC validation and qname minimization will send a combination of queries to Verisign's root and top-level domain (TLD) servers.
Because the resolver is a validating resolver, these queries will all have the "DNSSEC OK" bit set, indicating that the resolver wants the DNSSEC signatures on the records.
The content of typical responses by Verisign's root and TLD servers to these queries are given in Table 1 below. (In the table,
For an A or NS query, the typical response, when the domain of interest exists, includes a referral to another name server. If the domain supports DNSSEC, the response also includes a set of Delegation Signer (DS) records providing the hashes of each of the referred zone's KSKs the next link in the DNSSEC trust chain. When the domain of interest doesn't exist, the response includes one or more Next Secure (NSEC) or Next Secure 3 (NSEC3) records.
Researchers can estimate the effect of post-quantum algorithms on response size by replacing the sizes of the various RSA keys and signatures with those for their post-quantum counterparts. As discussed above, it is important to keep in mind that the number of keys returned may be larger during key rollovers.
Most of the queries from qname-minimizing, validating resolvers to the root and TLD name servers will be for A or NS records (the choice depends on the implementation of qname minimization, and has recently trended toward A). The signature size for a post-quantum algorithm, which affects all DNSSEC-related responses, will therefore generally have a much larger impact on average response size than will the key size, which affects only the DNSKEY responses.
Post-quantum algorithms are among the newest developments in cryptography. They add another dimension to a cryptographer's perspective on the DNS because of the possibility that these algorithms, or other variants, may be added to DNSSEC in the long term.
In my next post, I'll make the case for why the oldest post-quantum algorithm, hash-based signatures, could be a particularly good match for DNSSEC. I'll also share the results of some research at Verisign Labs into how the large signature sizes of hash-based signatures could potentially be overcome.
Read the previous posts in this six-part blog series:
The rest is here:
Securing the DNS in a Post-Quantum World: New DNSSEC Algorithms on the Horizon - CircleID
- Prediction: This Quantum Computing Stock Will Surge in 2025 - Yahoo Finance - June 14th, 2025 [June 14th, 2025]
- How to capitalize on the red-hot quantum computing space, according to a veteran investor - CNBC - June 14th, 2025 [June 14th, 2025]
- Quantum Computing Stock Jumped 25% on WednesdayThese Are the Key Price Levels to Watch - Investopedia - June 14th, 2025 [June 14th, 2025]
- Prediction: This Quantum Computing Stock Will Surge in 2025 - The Motley Fool - June 14th, 2025 [June 14th, 2025]
- Why Quantum Computing Stock Is Skyrocketing This Week - The Motley Fool - June 14th, 2025 [June 14th, 2025]
- eleQtron and FMD Partner to Advance Scalable Quantum Chip Production in Europe - Quantum Computing Report - June 14th, 2025 [June 14th, 2025]
- Prediction: This Quantum Computing Stock Will Surge in 2025 - The Globe and Mail - June 14th, 2025 [June 14th, 2025]
- Why IONQ, RGTI and QBTS are Worth the Risk in Quantum Computing - TipRanks - June 14th, 2025 [June 14th, 2025]
- If I Could Own Only 1 Quantum Computing Stock, This Would Be It - The Motley Fool - June 14th, 2025 [June 14th, 2025]
- Senior Thesis Spotlight: A high-risk, but well-defined idea to advance quantum computing - Princeton University - June 14th, 2025 [June 14th, 2025]
- Prediction: This Quantum Computing Stock Will Surge in 2025 - MSN - June 14th, 2025 [June 14th, 2025]
- IonQ to buy Oxford Ionics for $1.08 billion to expand quantum computing research - Reuters - June 14th, 2025 [June 14th, 2025]
- IBM claims 'real world' edge in quantum computing race - Phys.org - June 14th, 2025 [June 14th, 2025]
- IonQ Announces Agreement to Acquire Oxford Ionics, Accelerating Path to Pioneering Breakthroughs in Quantum Computing - Business Wire - June 14th, 2025 [June 14th, 2025]
- Why Quantum Computing Stock Is Skyrocketing This Week - AOL.com - June 14th, 2025 [June 14th, 2025]
- Quantum-Computing Company with Bothell Site Announces Deal That Will 'Set a New Standard - 425business.com - June 14th, 2025 [June 14th, 2025]
- Quantum computing creates the fog and the lighthouse - cio.com - June 14th, 2025 [June 14th, 2025]
- The Quantum Computing Threat to Bitcoin Is Real -- and Coming Fast - The Motley Fool - June 14th, 2025 [June 14th, 2025]
- IBM just took a 'significant' step toward useful quantum computing - Yahoo Finance - June 10th, 2025 [June 10th, 2025]
- Is D-Wave Quantum a Better Quantum Computing Stock to Buy Than IonQ? - The Motley Fool - June 10th, 2025 [June 10th, 2025]
- IonQ buys UK quantum startup Oxford Ionics for more than $1 billion - CNBC - June 10th, 2025 [June 10th, 2025]
- The 2025 Tech Power Players in the quantum computing sector - The Boston Globe - June 10th, 2025 [June 10th, 2025]
- 3 Quantum Computing Stocks with Potential to Beat the Market 6/9/2025 - TipRanks - June 10th, 2025 [June 10th, 2025]
- Quantum Computing and its Impact on the Life Science Industry - Inside Global Tech - June 10th, 2025 [June 10th, 2025]
- IBM bets on novel error-correction for scalable quantum computing - Nextgov - June 10th, 2025 [June 10th, 2025]
- Vodafone Partners With ORCA Computing to Model Future Networks in Minutes Using Quantum technology - The Quantum Insider - June 10th, 2025 [June 10th, 2025]
- Vodafone Partners With ORCA Computing to Model Future Networks in Minutes Using Quantum Technology - Business Wire - June 10th, 2025 [June 10th, 2025]
- Want to Invest in Quantum Computing? 3 Stocks That Are Great Buys Right Now. - Nasdaq - June 10th, 2025 [June 10th, 2025]
- Should You Invest in Quantum Computing Stocks During the TACO Trade? - Yahoo Finance - June 10th, 2025 [June 10th, 2025]
- Quantum Computing: Journey from bits to qubits still has far to go - The Indian Express - June 10th, 2025 [June 10th, 2025]
- Quantum Computing Breakthrough: BTQ and QPerfect Join Forces to Create Unhackable Digital Transactions - Stock Titan - June 10th, 2025 [June 10th, 2025]
- Want to Invest in Quantum Computing? 3 Stocks That Are Great Buys Right Now. - MSN - June 10th, 2025 [June 10th, 2025]
- British quantum computing start-up spun out of Oxford University snapped up by US rival in 800m deal - MSN - June 10th, 2025 [June 10th, 2025]
- NVIDIA's quantum computing team forged: alliance between US and Taiwanese companies - TweakTown - June 10th, 2025 [June 10th, 2025]
- IonQ to buy Oxford Ionics for $1.08 billion to expand quantum computing research - Yahoo Finance - June 10th, 2025 [June 10th, 2025]
- Will IonQ's Big Move for Quantum Computing Open Door to All-Time High? - TheStreet Pro - June 10th, 2025 [June 10th, 2025]
- Should You Invest in Quantum Computing Stocks During the TACO Trade? - The Motley Fool - June 10th, 2025 [June 10th, 2025]
- D-Wave Quantum Stock Skyrockets on Real-World Computing Breakthroughs - Yahoo Finance - June 10th, 2025 [June 10th, 2025]
- 1 Quantum Computing Stock That Has Crushed the S&P 500 Index This Year -- Should Investors Jump Aboard or Run for the Hills? - Yahoo Finance - June 1st, 2025 [June 1st, 2025]
- Lockheed Martin (LMT) and IBM Show the Real-World Potential of Quantum Computing - TipRanks - June 1st, 2025 [June 1st, 2025]
- Analyst flags new quantum computing stocks to buy - TheStreet - June 1st, 2025 [June 1st, 2025]
- Certifying the unpredictable: a key step in quantum computing - anl.gov - June 1st, 2025 [June 1st, 2025]
- Quantum Computing (NASDAQ:QUBT) Trading Down 3.3% - Here's What Happened - MarketBeat - June 1st, 2025 [June 1st, 2025]
- Want to Invest in Quantum Computing? 4 Stocks That Are Great Buys Right Now - Nasdaq - June 1st, 2025 [June 1st, 2025]
- A.I. Drone Operations Flourishing as Global Quantum Computing Market Expected to Reach $5.3 Billion By 2029 - GlobeNewswire - June 1st, 2025 [June 1st, 2025]
- Quantum Computing: Coming to a Marketing Organization Near You - CMSWire.com - June 1st, 2025 [June 1st, 2025]
- 1 Quantum Computing Stock That Has Crushed the S&P 500 Index This Year -- Should Investors Jump Aboard or Run for the Hills? - The Motley Fool - June 1st, 2025 [June 1st, 2025]
- The Promise of Quantum Computing - The Motley Fool - June 1st, 2025 [June 1st, 2025]
- This Company's CEO Said It Wants to Become the Nvidia of Quantum Computing. Should You Buy the Stock Now? - The Motley Fool - June 1st, 2025 [June 1st, 2025]
- This Company's CEO Said It Wants to Become the Nvidia of Quantum Computing. Should You Buy the Stock Now? - Yahoo Finance - June 1st, 2025 [June 1st, 2025]
- The 7 Competitors Vying for the Ultimate Quantum Computing Architecture - HackerNoon - June 1st, 2025 [June 1st, 2025]
- Error Correction with Fewer Qubits Brings Practical Quantum Computing Closer - IoT World Today - June 1st, 2025 [June 1st, 2025]
- Nvidia in advanced talks to invest in PsiQuantum- a quantum computing company - report - Seeking Alpha - May 19th, 2025 [May 19th, 2025]
- Honeywell Just Got a $1 Billion Quantum Computing Boost. Should You Buy HON Stock Now? - The Globe and Mail - May 19th, 2025 [May 19th, 2025]
- How will quantum computing impact the hosting industry? - Cybernews - May 19th, 2025 [May 19th, 2025]
- Nvidia reportedly in advanced talks to back quantum computing firm PsiQuantum - Proactive financial news - May 19th, 2025 [May 19th, 2025]
- Bismuth's mask uncovered: Implications for quantum computing and spintronics materials - Phys.org - May 15th, 2025 [May 15th, 2025]
- Is NVIDIA (NVDA) the Best Quantum Computing Stock to Invest in Now? - Yahoo Finance - May 15th, 2025 [May 15th, 2025]
- How close is quantum computing to commercial reality? - Computer Weekly - May 15th, 2025 [May 15th, 2025]
- Quantum computing is still in its infancy, but researchers have high hopes - Technical.ly - May 15th, 2025 [May 15th, 2025]
- Quantum computing signals the coming of the API storm - Computer Weekly - May 15th, 2025 [May 15th, 2025]
- Quantinuum Scores a $1 Billion Deal in Qatar. Demand for Quantum Computing Grows Globally. - Barron's - May 15th, 2025 [May 15th, 2025]
- 7 Best Quantum Computing Stocks to Buy This May - 24/7 Wall St. - May 15th, 2025 [May 15th, 2025]
- Quantum Computing (QUBT) Projected to Post Quarterly Earnings on Thursday - MarketBeat - May 15th, 2025 [May 15th, 2025]
- Quantinuum and Al Rabban Capital Launch Joint Venture to Accelerate Quantum Computing Adoption in Qatar and the Region - PR Newswire - May 15th, 2025 [May 15th, 2025]
- Buy or Sell Quantum Computing (QUBT) Stock Ahead of Its Upcoming Earnings? - Forbes - May 15th, 2025 [May 15th, 2025]
- Silicon spin qubits gain ground as a leading candidate for quantum computing - Phys.org - May 15th, 2025 [May 15th, 2025]
- Quantum Computing (NASDAQ:QUBT) Trading 1.5% Higher - Here's What Happened - MarketBeat - May 15th, 2025 [May 15th, 2025]
- Particles can be measured jointly without bringing them togetheran advance for quantum communication and computing - Phys.org - May 15th, 2025 [May 15th, 2025]
- Tel Aviv startup pulls in $110 million to become the Microsoft of quantum computing - The Times of Israel - May 15th, 2025 [May 15th, 2025]
- Quantum Computing Inc. Hosts Ribbon-Cutting to Celebrate Grand Opening of Quantum Photonic Chip Foundry in Tempe, Arizona - Yahoo Finance - May 15th, 2025 [May 15th, 2025]
- Cells Might Be Doing Quantum Computing. Life on Earth Has Performed 10 Logical Operations - ZME Science - May 15th, 2025 [May 15th, 2025]
- How will quantum computing change the world? - Fox Business - May 10th, 2025 [May 10th, 2025]
- Whats next in computing is generative and quantum - IBM Research - May 10th, 2025 [May 10th, 2025]
- Quantum computing gets an error-correction boost from AI innovation - Network World - May 10th, 2025 [May 10th, 2025]
- D-Wave CEO explains where the US is falling behind the rest of the world on quantum computing - Sherwood News - May 10th, 2025 [May 10th, 2025]
- How will quantum computing change the world? - MSN - May 10th, 2025 [May 10th, 2025]
- Editorial: What will it take to realize the potential of quantum computing in chemistry? - C&EN - May 10th, 2025 [May 10th, 2025]
- A Strong Business CaseFor Quantum Computing: How Amazon (NASDAQ:AMZN) Is Taking It On - TipRanks - May 10th, 2025 [May 10th, 2025]
- News | Quantum computing provider teams up with electric utility for expansion in Tennessee - CoStar - May 10th, 2025 [May 10th, 2025]