Mutualized oblivious DNS (μODNS): Hiding a tree in the wild forest
Abstract
Domain fit: AI-adjacent · Paper appears method- or tooling-adjacent to AI workflows with partial ecosystem coverage.
The traditional Domain Name System (DNS) lacks fundamental features of security and privacy in its design. As concerns of privacy increased on the Internet, security and privacy enhancements of DNS have been actively investigated and deployed. Specially for user's privacy in DNS queries, several relay-based anonymization schemes have been recently introduced, however, they are vulnerable to the collusion of a relay with a full-service resolver, i.e., identities of users cannot be hidden to the resolver. This paper introduces a new concept of a multiple-relay-based DNS for user anonymity in DNS queries, called the mutualized oblivious DNS ($μ$ODNS), by extending the concept of existing relay-based schemes. The $μ$ODNS introduces a small and reasonable assumption that each user has at least one trusted/dedicated relay in a network and mutually shares the dedicated one with others. The user just sets the dedicated one as his next-hop, first relay, conveying his queries to the resolver, and randomly chooses its $0$ or more subsequent relays shared by other entities. Under this small assumption, the user's identity is concealed to a target resolver in the $μ$ODNS even if a certain (unknown) subset of relays collude with the resolver. That is, in $μ$ODNS, users can preserve their privacy and anonymity just by paying a small cost of sharing its resource. Moreover, we present a PoC implementation of $μ$ODNS that is publicly available on the Internet. We also show that by measurement of round-trip-time for queries, and our PoC implementation of $μ$ODNS achieves the performance comparable to existing relay-based schemes.
Results and benchmarks
The traditional Domain Name System (DNS) lacks fundamental features of security and privacy in its design.
Benchmark evidence is limited
Evidence graph: 3 refs, 3 links.
Utility signals: depth 70/100, grounding 75/100, status medium.
Implementation
No direct implementation yet
Maintained implementation evidence is not confirmed for this paper yet.
Use the implementation status and reproduction sections for the current action plan.
No verified maintained repo yet
There is no verified maintained implementation yet. Use this baseline plan to decide whether to prototype now or defer.
- No maintained paper-verified implementation was found; start with the closest related repositories below.
- Compare repo methods against the paper equations/algorithm before trusting metrics.
- Create a minimal baseline implementation from the paper and use adjacent repos as references.
Time to first repro: a few days
junkurihara/doh-auth-proxy is the closest maintained adjacent implementation (Matches contextual method/domain keyword: relay). It is not paper-verified; validate algorithm and evaluation setup against the paper before trusting reported metrics. Community adoption signal: 38 GitHub stars.
- Adjacent implementations are not paper-verified
- Recommended repository is adjacent and not paper-verified.
- Adjacent implementation match confidence is low.
Reproduction readiness
No repo
No verified implementation available
- No maintained repository has been identified for this paper. Check adjacent implementations or HF artifacts below.
Hardware requirements
- Expect multi-day setup/compute for meaningful reproduction based on current guidance.
Validation caveat
Repositories and ecosystem
Closest related implementations
These are not paper-verified. Use them as reference points when no direct implementation is available.
- junkurihara/doh-auth-proxy Adjacent · Confidence: Low · 38 stars
Matches contextual method/domain keyword: relay
No additional verified repositories beyond the primary recommendation.
Hugging Face artifacts
No trustworthy direct or curated related Hugging Face artifacts were found yet. Use targeted searches to quickly locate candidate models, datasets, and demos.
Models
Datasets
Spaces
Tip: start with models, then check datasets and spaces if you need evaluation data or demos.
Research context
1
Citations
19
References
Tasks
Computer science, Relay, Resolver, Domain Name System, Context (archaeology), Anonymity, Computer network, Implementation
Methods
None detected
Domains
Computer security
Related papers
- Position Measurement in Industrial Drives by Means of Low-Cost Resolver-to-Digital ConverterSearch on Paper2Code
2007 · Semantic similarity
- Proposal of a New Affordable 2-Pole Resolver and Comparing Its Performance With Conventional Wound-Rotor and VR ResolversSearch on Paper2Code
2018 · Semantic similarity
- Experimental verification of the resolver dynamic model and control designsSearch on Paper2Code
2013 · Semantic similarity
- DSP-based 3D printed resolver-to-digital conversion systemSearch on Paper2Code
2015 · Semantic similarity
- A low cost resolver-to-digital converterSearch on Paper2Code
2002 · Semantic similarity
- Study on Rotor Position Detection of Motor Based on ResolverSearch on Paper2Code
2008 · Semantic similarity
Open this paper in HFEPX to review benchmark signals, evaluation modes, and human-feedback protocol context.
Open in HFEPXJump to Paper2Code search queries derived from this paper's research context.