Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS
Abstract
Domain fit: Niche / domain-specific · No strong AI-core implementation/artifact signals were detected from current providers.
The Internet’s Domain Name System (DNS) responds to client hostname queries with corresponding IP addresses and records. Traditional DNS is unencrypted and leaks user information to on-lookers. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting DNS messages from third parties. However, the small number of available public large-scale DoT and DoH resolvers has reinforced DNS privacy concerns, specifically that DNS operators could use query contents and client IP addresses to link activities with identities. Oblivious DNS over HTTPS (ODoH) safeguards against these problems. In this paper we implement and deploy interoperable instantiations of the protocol, construct a corresponding formal model and analysis, and evaluate the protocols’ performance with wide-scale measurements. Results suggest that ODoH is a practical privacy-enhancing replacement for DNS.
Results and benchmarks
The Internet’s Domain Name System (DNS) responds to client hostname queries with corresponding IP addresses and records.
Benchmark evidence is limited
Evidence graph: 2 refs, 1 links.
Utility signals: depth 65/100, grounding 58/100, status medium.
Implementation
No direct implementation yet
Maintained implementation evidence is not confirmed for this paper yet.
Use the implementation status and reproduction sections for the current action plan.
No verified maintained repo yet
There is no verified maintained implementation yet. Use this baseline plan to decide whether to prototype now or defer.
- No direct maintained implementation was found. Use the paper PDF and citation graph to design a baseline reproduction.
- Start from related paper: Experimental study of DNS performance.
- Track assumptions and missing details in an experiment log before coding.
Time to first repro: a few days
Recommendation evidence is currently too limited for a maintained-repo choice. Use Implementation Status and Reproduction Path for a practical baseline plan.
- Estimate is based on paper-only reproduction flow
Reproduction readiness
No repo
No verified implementation available
- No maintained repository has been identified for this paper. Check adjacent implementations or HF artifacts below.
Hardware requirements
- Expect multi-day setup/compute for meaningful reproduction based on current guidance.
Validation caveat
Hugging Face artifacts
No trustworthy direct or curated related Hugging Face artifacts were found yet. Use targeted searches to quickly locate candidate models, datasets, and demos.
Tip: start with models, then check datasets and spaces if you need evaluation data or demos.
Research context
31
Citations
40
References
Tasks
Domain Name System, Computer science, Round-robin DNS, The Internet, Name server, Protocol (science), Computer network, World Wide Web
Methods
None detected
Domains
Computer security, Artificial Intelligence
Related papers
- Experimental study of DNS performanceSearch on Paper2Code
2011 · Semantic similarity
- Using Recursive Name-Server to Resolve DNSSearch on Paper2Code
2011 · Semantic similarity
- Balancing the Load of the Servers in Different Places Based on DNSSearch on Paper2Code
2001 · Semantic similarity
- Foundation Techniques and Cooperation Test of Fault-tolerant Domain Name Servers for Internet Name ResolutionSearch on Paper2Code
2011 · Semantic similarity
- Benefit of third-party name server operations in DNS configurationSearch on Paper2Code
2022 · Semantic similarity
- Efficient load balancing for bursty demand in web based application services via domain name servicesSearch on Paper2Code
2010 · Semantic similarity
Jump to Paper2Code search queries derived from this paper's research context.