Feeds

DNS Rootservers go international

Anycast anywhere

  • alert
  • submit to reddit

Remote control for virtualized desktops

For the first time in Internet history there are more DNS rootservers outside the United States than within, following this week's launch in Frankfurt of an anycast "instance" of RIPE NCC-managed K root server.

The K-root DNS server is one of the 13 official DNS rootservers which answer lookups for domain names all over the world. It is operated by RIPE NCC, the organization in charge of IP adress allocation throughout Europe, the Middle East and parts of Africa, and is sitting at the London Internet Exchange.

Of the original 13 rootservers only three
were outside the US, which fuelled criticism of US centrism in Internet management.

"The launch of the K anycast instance will make the German Internet Community more independent and the DNS in general more reliable," said Denic CEO Sabine Dolderer. The registry for .de-adresses co-sponsered
the new server together with the German ISP association ECO.

According to Axel Pawlik, CEO of RIPE NCC, the anycast system will for example help to mitigate DDoS-attacks on the thirteen root servers. RIPE NCC technicians were among the pioneers of the anycast concept for the root servers. So far they brought instances of the K server that sits at the London Internet Exchange (LINX) to their headquarters in Amsterdam and to Frankfurt. Until the end of the year there will be up to ten identical servers in all of Europe.

The anycast systems makes the central zone files of the original root server available under the same IP adress on different machines in different locations. The spreading of the servers across the net make it more difficult to attack them and lower the response times for local communities.

"We talk about milliseconds," says Dolderer. Most users would not notice the change, and only traceroutes would show that request are now answered by the Frankfurt server. But tests at the anycast instance of the F root server in Dubai resulted in a drop from 130 to 30 milliseconds.

The operators of F, the Internet Software Consortium, so far have spread most rapidly over the globe. F root servers already have been installed in Ottawa, Madrid, Hong Kong, Rome, Auckland, Sao Paulo, Beijing, Seoul, Moscow, Taipei, Dubai, Paris and Singapore.

"It happens that our offers for a K instance were answered by 'oh, we already have F'," says Pawlik. But there was no race between root server operators. Up to now, five of them already joined the anycast effort and more will join, said Pawlik. "The more instances of the root servers the better", he says.

Some-well connected places house the slaves of several root servers. London for example has the K root and also hosts instances of I and J.

Now with the K instance at the Frankfurt German Internet Exchange (DeCIX) there are 24 root server locations outside, compared to 23 in the US. Not counted in are instances of root servers organized by local communities like the N-IX Internet Exchange at Nuremberg, Germany. The N-IX is anycasting root
servers of ICANN, the NASA and WIDE in Japan.

"Technically this changes the concentration," says Dolderer. "But the political problem is still there."

What information is fed into the system has to be decided by the Internet Corporation for Assigned Names and Numbers ICANN) and be propagated through the master, the A root server in Dulles. Everyone of the other 12 root servers are the so-called slaves and so are their new "children". And master A is under the oversight of the US Department of Commerce. ®

Internet Security Threat Report 2014

More from The Register

next story
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
I'll be back (and forward): Hollywood's time travel tribulations
Quick, call the Time Cops to sort out this paradox!
NSA mass spying reform KILLED by US Senators
Democrats needed just TWO more votes to keep alive bill reining in some surveillance
prev story

Whitepapers

10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.