Feeds

DNS Rootservers go international

Anycast anywhere

  • alert
  • submit to reddit

Intelligent flash storage arrays

For the first time in Internet history there are more DNS rootservers outside the United States than within, following this week's launch in Frankfurt of an anycast "instance" of RIPE NCC-managed K root server.

The K-root DNS server is one of the 13 official DNS rootservers which answer lookups for domain names all over the world. It is operated by RIPE NCC, the organization in charge of IP adress allocation throughout Europe, the Middle East and parts of Africa, and is sitting at the London Internet Exchange.

Of the original 13 rootservers only three
were outside the US, which fuelled criticism of US centrism in Internet management.

"The launch of the K anycast instance will make the German Internet Community more independent and the DNS in general more reliable," said Denic CEO Sabine Dolderer. The registry for .de-adresses co-sponsered
the new server together with the German ISP association ECO.

According to Axel Pawlik, CEO of RIPE NCC, the anycast system will for example help to mitigate DDoS-attacks on the thirteen root servers. RIPE NCC technicians were among the pioneers of the anycast concept for the root servers. So far they brought instances of the K server that sits at the London Internet Exchange (LINX) to their headquarters in Amsterdam and to Frankfurt. Until the end of the year there will be up to ten identical servers in all of Europe.

The anycast systems makes the central zone files of the original root server available under the same IP adress on different machines in different locations. The spreading of the servers across the net make it more difficult to attack them and lower the response times for local communities.

"We talk about milliseconds," says Dolderer. Most users would not notice the change, and only traceroutes would show that request are now answered by the Frankfurt server. But tests at the anycast instance of the F root server in Dubai resulted in a drop from 130 to 30 milliseconds.

The operators of F, the Internet Software Consortium, so far have spread most rapidly over the globe. F root servers already have been installed in Ottawa, Madrid, Hong Kong, Rome, Auckland, Sao Paulo, Beijing, Seoul, Moscow, Taipei, Dubai, Paris and Singapore.

"It happens that our offers for a K instance were answered by 'oh, we already have F'," says Pawlik. But there was no race between root server operators. Up to now, five of them already joined the anycast effort and more will join, said Pawlik. "The more instances of the root servers the better", he says.

Some-well connected places house the slaves of several root servers. London for example has the K root and also hosts instances of I and J.

Now with the K instance at the Frankfurt German Internet Exchange (DeCIX) there are 24 root server locations outside, compared to 23 in the US. Not counted in are instances of root servers organized by local communities like the N-IX Internet Exchange at Nuremberg, Germany. The N-IX is anycasting root
servers of ICANN, the NASA and WIDE in Japan.

"Technically this changes the concentration," says Dolderer. "But the political problem is still there."

What information is fed into the system has to be decided by the Internet Corporation for Assigned Names and Numbers ICANN) and be propagated through the master, the A root server in Dulles. Everyone of the other 12 root servers are the so-called slaves and so are their new "children". And master A is under the oversight of the US Department of Commerce. ®

Internet Security Threat Report 2014

More from The Register

next story
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Lords take revenge on REVENGE PORN publishers
Jilted Johns and Jennies with busy fingers face two years inside
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Yes, yes, Steve Jobs. Look what I'VE done for you lately – Tim Cook
New iPhone biz baron points to Apple's (his) greatest successes
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.