Date Added: May 2011
Internet Service Providers' DNS traffic can be up to 120000 queries per second and increases around 8% every month. DNSSEC is expected to replace DNS and brings new challenge to naming resolution with heavy signature check. This paper provides an architecture, where incoming DNS traffic is split according to the DNS query rather than to its IP ad-dress, in order to minimize the number of signature checks. To split DNS traffic among the different nodes of the plat-form, k-means clustering algorithms are considered.