{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:EHWKV26L4TWSL3CTOXJ2X4SB7J","short_pith_number":"pith:EHWKV26L","schema_version":"1.0","canonical_sha256":"21ecaaebcbe4ed25ec5375d3abf241fa76cf366b48217972ee739687fda4b3a7","source":{"kind":"arxiv","id":"2211.14196","version":1},"attestation_state":"computed","paper":{"title":"Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Douglas Stebila, Jason Goertzen","submitted_at":"2022-11-25T15:54:50Z","abstract_excerpt":"The Domain Name System Security Extensions (DNSSEC) provide authentication of DNS responses using digital signatures. DNS operates primarily over UDP, which leads to several constraints: notably, packets should be at most 1232 bytes long to avoid problems during transmission. Larger DNS responses either need to be fragmented into several UDP responses or the request would need to be repeated over TCP, neither of which is sufficiently reliable in today's DNS ecosystem. While RSA or elliptic curve digital signatures are sufficiently small to avoid this problem, even for DNSSEC packets containing"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2211.14196","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2022-11-25T15:54:50Z","cross_cats_sorted":[],"title_canon_sha256":"8163a70da76f34a9bc0bed6181860becd32f52e62709fe75f96725a554253216","abstract_canon_sha256":"aa3cfc06ccdd18310fb3313a32e8f23651cae6cd5e5b5363100070f217e251cc"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:19:30.413481Z","signature_b64":"9FZju9u3xlmSnufW0zjiu1wZ5TQc7QEN8p7DmNFwJZYyTJ3Gdh6q5IqdoBw0OPHm6U0QL8bsC3rmOH29GYuaCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"21ecaaebcbe4ed25ec5375d3abf241fa76cf366b48217972ee739687fda4b3a7","last_reissued_at":"2026-07-05T05:19:30.412954Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:19:30.412954Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Post-Quantum Signatures in DNSSEC via Request-Based Fragmentation","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Douglas Stebila, Jason Goertzen","submitted_at":"2022-11-25T15:54:50Z","abstract_excerpt":"The Domain Name System Security Extensions (DNSSEC) provide authentication of DNS responses using digital signatures. DNS operates primarily over UDP, which leads to several constraints: notably, packets should be at most 1232 bytes long to avoid problems during transmission. Larger DNS responses either need to be fragmented into several UDP responses or the request would need to be repeated over TCP, neither of which is sufficiently reliable in today's DNS ecosystem. While RSA or elliptic curve digital signatures are sufficiently small to avoid this problem, even for DNSSEC packets containing"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2211.14196","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2211.14196/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2211.14196","created_at":"2026-07-05T05:19:30.413019+00:00"},{"alias_kind":"arxiv_version","alias_value":"2211.14196v1","created_at":"2026-07-05T05:19:30.413019+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2211.14196","created_at":"2026-07-05T05:19:30.413019+00:00"},{"alias_kind":"pith_short_12","alias_value":"EHWKV26L4TWS","created_at":"2026-07-05T05:19:30.413019+00:00"},{"alias_kind":"pith_short_16","alias_value":"EHWKV26L4TWSL3CT","created_at":"2026-07-05T05:19:30.413019+00:00"},{"alias_kind":"pith_short_8","alias_value":"EHWKV26L","created_at":"2026-07-05T05:19:30.413019+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.02314","citing_title":"Discovering Agents for Discovery: The Case for DNS","ref_index":10,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J","json":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J.json","graph_json":"https://pith.science/api/pith-number/EHWKV26L4TWSL3CTOXJ2X4SB7J/graph.json","events_json":"https://pith.science/api/pith-number/EHWKV26L4TWSL3CTOXJ2X4SB7J/events.json","paper":"https://pith.science/paper/EHWKV26L"},"agent_actions":{"view_html":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J","download_json":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J.json","view_paper":"https://pith.science/paper/EHWKV26L","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2211.14196&json=true","fetch_graph":"https://pith.science/api/pith-number/EHWKV26L4TWSL3CTOXJ2X4SB7J/graph.json","fetch_events":"https://pith.science/api/pith-number/EHWKV26L4TWSL3CTOXJ2X4SB7J/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J/action/storage_attestation","attest_author":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J/action/author_attestation","sign_citation":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J/action/citation_signature","submit_replication":"https://pith.science/pith/EHWKV26L4TWSL3CTOXJ2X4SB7J/action/replication_record"}},"created_at":"2026-07-05T05:19:30.413019+00:00","updated_at":"2026-07-05T05:19:30.413019+00:00"}