Have a personal or library account? Click to login
Analysis and Evaluation of Post-Quantum Cryptography for DNSSEC Cover

Analysis and Evaluation of Post-Quantum Cryptography for DNSSEC

By: Tomasz Nal and  Marcin Niemiec  
Open Access
|Dec 2025

Figures & Tables

Listing 1:

Configuration settings in pdns.conf file used by the authoritative nameservers to control cache usage.
Configuration settings in pdns.conf file used by the authoritative nameservers to control cache usage.

Listing 2:

Configuration settings in pdns.conf file used by the recursor to control cache usage.
Configuration settings in pdns.conf file used by the recursor to control cache usage.

Listing 3:

Key parts of the Bash script showing the overall flow of the experiments and data collection process.
Key parts of the Bash script showing the overall flow of the experiments and data collection process.

Figure 1.

Latency measured at the authoritative nameservers for FALCON-512 with A-type DNS queries.
Latency measured at the authoritative nameservers for FALCON-512 with A-type DNS queries.

Figure 2.

Latency measured at the authoritative nameservers for FALCON-512 with AAAA-type DNS queries.
Latency measured at the authoritative nameservers for FALCON-512 with AAAA-type DNS queries.

Figure 3.

Latency measured at the authoritative nameservers for ECDSA with A-type DNS queries.
Latency measured at the authoritative nameservers for ECDSA with A-type DNS queries.

Figure 4.

Latency measured at the authoritative nameservers for ECDSA with AAAA-type DNS queries.
Latency measured at the authoritative nameservers for ECDSA with AAAA-type DNS queries.

Figure 5.

Error rate measured at the authoritative nameservers for FALCON-512 with A-type DNS queries.
Error rate measured at the authoritative nameservers for FALCON-512 with A-type DNS queries.

Figure 6.

Error rate measured at the authoritative nameservers for FALCON-512 with AAAA-type DNS queries.
Error rate measured at the authoritative nameservers for FALCON-512 with AAAA-type DNS queries.

Figure 7.

Error rate with queries for non-existent domains.
Error rate with queries for non-existent domains.

Figure 8.

Latency measured at the authoritative nameservers for FALCON-512 with A-type DNS queries for non-existent domains.
Latency measured at the authoritative nameservers for FALCON-512 with A-type DNS queries for non-existent domains.

Figure 9.

Latency measured at the authoritative nameservers for ECDSA with A-type DNS queries for non-existent domains.
Latency measured at the authoritative nameservers for ECDSA with A-type DNS queries for non-existent domains.

Testbed zone configuration_

ZoneHostIPv4/IPv6
.s.root-servers.net.10.0.1.2 / fc01::2
pl.ns1.example.pl.10.0.1.3 / fc01::3
dnsseclab.pl.n21.dnsseclab.pl.10.0.1.4 / fc01::4
resolver-10.0.1.10 / fc01::10
resolver (dnssec)-10.0.1.11 / fc01::11

Hardware environment—the testbed is running inside Podman containers, on a virtual machine with Ubuntu Linux kernel 6_8_0-54-generic_

CoresNumber of CPUsRAM
11th Gen Intel(R) Core(TM) i7-1185G7 @ 3.00GHz48 GB

Testbed networking configuration_

DNS architectureImagePort
.pqc-auth-powerdns5302, tcp/udp
pl.pqc-auth-powerdns5303, tcp/udp
dnsseclab.pl.pqc-auth-powerdns5304, tcp/udp
resolverpqc-resolver-powerdns5311, tcp/udp
DOI: https://doi.org/10.2478/qic-2025-0025 | Journal eISSN: 3106-0544 | Journal ISSN: 1533-7146
Language: English
Page range: 438 - 452
Submitted on: Jun 11, 2025
|
Accepted on: Aug 24, 2025
|
Published on: Dec 31, 2025
In partnership with: Paradigm Publishing Services
Publication frequency: 1 issue per year

© 2025 Tomasz Nal, Marcin Niemiec, published by Cerebration Science Publishing Co., Limited
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.