The censorship-resistant GNS domain name system has received the status of a proposed standard.

The IETF (Internet Engineering Task Force), which is responsible for the development of internet protocols and architecture, has completed the formation of an RFC for the GNS (GNU Name System) domain name system, being developed by the GNUnet project as a fully decentralized and censorship-resistant alternative to DNS. The specification, published as RFC-9498, has achieved the status of 'Proposed Standard'. A fully compliant implementation of GNS, published under the RFC, is included in the GNUnet platform 0.20.0 and is additionally available in the GNUnet-Go codebase.

GNS can be used alongside DNS and applied in traditional applications such as web browsers. The integrity and immutability of records are ensured through the use of cryptographic mechanisms. Unlike DNS, which uses a tree hierarchy, GNS employs a directed graph. servers The name transformation is similar to DNS, but queries and responses are processed with privacy in mind — the node processing the request does not know to whom the response is given, and transit nodes and third-party observers cannot decrypt the queries and responses.

A DNS zone in GNS is defined using a combination of ECDSA public and private keys based on the Curve25519 elliptic curves. The use of Curve25519 is considered somewhat unusual, as other types of elliptic curves are typically used for ECDSA, and Curve25519 is usually paired with the Ed25519 digital signature algorithm, which is more modern, secure, and faster than ECDSA. From a cryptographic strength perspective, the choice of key size—32 bytes instead of the usual 64 bytes for Ed25519—also raises questions, as does the application of cascade symmetric encryption using AES and TwoFish in CFB mode.

This approach is explained by the need to implement hierarchical keys, allowing the use of a root public key to derive a child public key, utilizing the linearity property of the Curve25519 curve. This feature allows child public keys to be derived without knowledge of the private root keys. The technique is also used in Bitcoin. The 32-byte key size is chosen to ensure that the key fits within a single DNS record.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster