2021
DOI: 10.2478/popets-2021-0085
|View full text |Cite
|
Sign up to set email alerts
|

Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS

Abstract: The Internet’s Domain Name System (DNS) responds to client hostname queries with corresponding IP addresses and records. Traditional DNS is unencrypted and leaks user information to on-lookers. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting DNS messages from third parties. However, the small number of available public large-scale DoT and DoH resolvers has reinforced DNS privacy concerns, specifically that DNS operators could use … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
14
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 18 publications
(15 citation statements)
references
References 37 publications
0
14
0
Order By: Relevance
“…Although ODNS took an elegant approach compatible with the standard Do53, it involves a large round-trip-time (RTT) since all queries must be forwarded to the ODNS resolver, i.e., an authoritative server. Oblivious DNS over HTTPS (ODoH) [21,25] has been designed by simplifying the architecture and omitting the compatibility with Do53, and realizes a performance comparable to the standard DoH. ODoH introduces a relay called oblivious proxy that just relays encrypted queries and responses between a user and a target resolver.…”
Section: Anonymized/oblivious Dns Protocolsmentioning
confidence: 99%
See 4 more Smart Citations
“…Although ODNS took an elegant approach compatible with the standard Do53, it involves a large round-trip-time (RTT) since all queries must be forwarded to the ODNS resolver, i.e., an authoritative server. Oblivious DNS over HTTPS (ODoH) [21,25] has been designed by simplifying the architecture and omitting the compatibility with Do53, and realizes a performance comparable to the standard DoH. ODoH introduces a relay called oblivious proxy that just relays encrypted queries and responses between a user and a target resolver.…”
Section: Anonymized/oblivious Dns Protocolsmentioning
confidence: 99%
“…Unlike ODNS, these schemes directly introduce intermediate relays dedicated to the schemes between users and encryption-enabled resolvers and omit the compatibility with Do53. This simplification in the architecture results in their good performance comparable to standard encrypted DNS schemes [25].…”
Section: Introductionmentioning
confidence: 99%
See 3 more Smart Citations