| Abstract [eng] |
The Domain Name System Security Extensions (DNSSEC) provide the cryptographic foundation for DNS data integrity and origin authentication. Cryptographically relevant quantum computers (CRQCs) threaten this foundation, since RSA and ECDSA, the signature schemes underlying DNSSEC, are susceptible to polynomial time attacks via Shor’s algorithm. NIST-standardized post-quantum cryptography (PQC) signatures structurally exceed the 1232-byte UDP payload limit of DNS, and no existing proposal simultaneously resolves all transport, security, and operational constraints. Following PRISMA 2020 guidelines, this paper systematically reviews 27 peer-reviewed works published between 2020 and 2025, providing the first unified analytical framework for post-quantum DNSSEC research across five dimensions: transport constraints, cryptographic agility, denial-of-service resilience, operational deployment, and standardization readiness. Three findings emerge. First, every NIST-standardized PQC scheme is structurally incompatible with UDP transport in non-minimal DNSSEC responses. Second, analytical modeling predicts that the DNSKEY-RRSIG validation product scales quadratically in the number of coexisting signature algorithms, and that the interaction of KeyTrap with PQC validation overhead compounds denial-of-service severity super-linearly. This prediction is formalized as a testable hypothesis pending experimental characterization, while the algorithm agility mechanism enabling PQC deployment simultaneously enables downgrade attacks. Third, the architecture of signature-based DNSSEC lacks retroactive protection against key compromise, which is the signature-domain equivalent of forward secrecy. No security proof exists for hybrid dual-signature constructions owing to IND-CMP composition problems. We identify five previously unaddressed research gaps and present a prioritized three-phase roadmap through 2029. Post-quantum DNSSEC constitutes a protocol-redesign problem, not an algorithm-substitution problem. |