Public network domain name shunting method and communication system

Through the DNS redirection and DNAT conversion of the uplink classifier user plane functional network element, the problem of public network service diversion errors caused by content distribution network service providers is solved, ensuring normal access to ordinary public network services.

CN120675969APending Publication Date: 2025-09-19CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510813070.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Because the content distribution network service provider returns the same IP address for the DNS resolution requests of the public network services diverted from the intranet and ordinary public network services, ordinary public network services cannot be accessed normally.

Method used

The DNS resolution request message is received by the user plane functional network element of the uplink classifier, and it is determined whether the target public network domain name meets the preset DNS redirection rules. It is redirected to the target intranet DNS server and DNAT conversion is performed based on the resolution result of the target intranet DNS server. The real IP address is replaced with a virtual IP address to ensure the accuracy of traffic diversion.

Benefits of technology

It achieves accurate distinction between intranet diversion domain name traffic and ordinary public network domain name traffic, avoids diversion errors, and ensures normal access to ordinary public network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675969A_ABST
    Figure CN120675969A_ABST
Patent Text Reader

Abstract

The invention discloses a public network domain name shunting method and a communication system. Comprising the steps that an uplink classifier user plane function network element receives a DNS analysis request message initiated by user equipment, the message comprises a public network domain name to be analyzed, and a target IP address of the message is a first IP address; whether the public network domain name meets a DNS redirection rule is judged, if yes, the request message is sent to an intranet DNS server corresponding to the public network domain name, and a DNS analysis response message fed back by the intranet DNS server is received; and converting the analysis result from the second IP address to a virtual IP address according to a target IP address conversion rule, and sending a DNS analysis response message of which the analysis result is the virtual IP address to the user equipment. According to the method and the device, the technical problem that the common public network service cannot be normally accessed due to the fact that the same IP address is returned to two DNS analysis requests of the public network service shunted by the internal network and the common public network service by a content distribution network service provider is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless communication technology, and more specifically, to a public network domain name diversion method and communication system. Background Art

[0002] ULCL (Uplink Classifier) ​​is one of the key features of UPF (User Plane Function) in the 5G Core (5G Core, 5GC). It analyzes parameters such as the IP quintuple (source IP, destination IP, protocol, source port, destination port) or DNN (Deep Neural Network) of the uplink data packet to direct specific traffic to different data networks (such as local edge computing nodes, the Internet, corporate intranet, etc.), rather than all traffic being processed by the central cloud. This enables seamless multi-domain (intranet domain, Internet domain) business, improves user experience and network efficiency, and is widely used in scenarios such as universities, the Industrial Internet, and the Internet of Vehicles.

[0003] However, when public network services diverted from the intranet share the same CDN (Content Delivery Network) provider with other ordinary public network services, a problem may arise: the CDN provider may return the same IP address for DNS requests for both domain names, resolving to the service address of the same CDN node. This can cause ordinary public network services to be mistakenly diverted to the intranet, hindering access to ordinary public network services and affecting users' normal business use.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The embodiments of the present application provide a public domain name diversion method and communication system to at least solve the technical problem that ordinary public network services cannot be accessed normally because the content distribution network service provider returns the same IP address for two DNS resolution requests for public network services diverted to the intranet and ordinary public network services.

[0006] According to one aspect of an embodiment of the present application, a public network domain name diversion method is provided, comprising: an uplink classifier user plane functional network element receives a DNS resolution request message initiated by a user device, wherein the DNS resolution request message carries at least a target public network domain name to be resolved, and the destination IP address of the DNS resolution request message is a first IP address of a public network DNS server; judging whether the target public network domain name satisfies a preset DNS redirection rule, and if the target public network domain name satisfies the DNS redirection rule, determining a target intranet DNS server corresponding to the target public network domain name according to the DNS redirection rule, wherein the DNS redirection rule defines multiple public network domain names to be redirected and each public network domain name An intranet DNS server for domain name redirection; sending a DNS resolution request message to a target intranet DNS server, and receiving a first DNS resolution response message fed back by the target intranet DNS server, wherein the first DNS resolution response message carries at least a second IP address obtained by the target intranet DNS server for resolving the target public domain name; converting the second IP address into a target virtual IP address according to a preset target IP address conversion rule, and sending a first DNS resolution response message whose resolution result is the target virtual IP address to a user device, wherein the target IP address conversion rule includes a mapping relationship between real IP addresses obtained by resolving multiple public domain names and preset virtual IP addresses.

[0007] Optionally, the DNS resolution response message also carries the third IP address of the target intranet DNS server, wherein the first DNS resolution response message whose resolution result is the target virtual IP address is sent to the user device, including: changing the source IP address of the DNS resolution response message from the third IP address to the first IP address; and sending the first DNS resolution response message whose source IP address is the first IP address and whose resolution result is the target virtual IP address to the user device.

[0008] Optionally, after sending a first DNS resolution response message whose source IP address is the first IP address and whose resolution result is the target virtual IP address to the user device, the method further includes: receiving a first service request message initiated by the user device, wherein the destination IP address of the first service request message is the target virtual IP address; converting the target virtual IP address into a second IP address according to a target IP address conversion rule, and sending the first service request message to the second IP address; receiving a first service response message fed back by the second IP address; converting the source IP address of the first service response message from the second IP address to the target virtual IP address using the target IP address conversion rule; and sending the first service response message whose source IP address is the target virtual IP address to the user device.

[0009] Optionally, the method also includes: when the target public domain name in the DNS resolution request message does not meet the DNS redirection rules, sending the DNS resolution request message to the public DNS server, and receiving a second DNS resolution response message fed back by the public DNS server, wherein the second DNS resolution response message carries at least a fourth IP address obtained by the public DNS server for resolving the target public domain name; and sending the second DNS resolution response message whose source IP address is the first IP address and whose resolution result is the fourth IP address to the user device.

[0010] Optionally, after sending a second DNS resolution response message whose source IP address is the first IP address and whose resolution result is the fourth IP address to the user device, the method also includes: receiving a second service request message initiated by the user device, wherein the destination IP address of the second service request message is the fourth IP address; sending the second service request message to the target website corresponding to the fourth IP address, and receiving a second service response message fed back by the target website; sending a second service response message whose source IP address is the fourth IP address to the user device.

[0011] Optionally, a request message initiated by a user equipment through a user plane of a general packet radio service tunneling protocol of an N3 interface is received, wherein the request message includes one of the following: a DNS resolution request message, a first service request message, and a second service request message; a response message is sent to the user equipment through the user plane of a general packet radio service tunneling protocol of an N3 interface, wherein the response message includes one of the following: a first DNS resolution response message, a second DNS resolution response message, a first service response message, and a second service response message.

[0012] Optionally, a request message is sent to a public network DNS server or a target intranet DNS server through the N6 interface, wherein the request message includes one of the following: a DNS resolution request message, a first service request message, and a second service response message; a response message fed back by the public network DNS server or the target intranet DNS server is received through the N6 interface, wherein the response message includes one of the following: a first DNS resolution response message, a second DNS resolution response message, a first service response message, and a second service response message.

[0013] According to another aspect of the embodiment of the present application, a communication system is also provided, which includes at least: a user device, an uplink classifier user plane functional network element, wherein the user device is used to send a DNS resolution request message to the uplink classifier user plane functional network element, wherein the DNS resolution request message carries at least the target public network domain name to be resolved, and the destination IP address of the DNS resolution request message is the first IP address of the public network DNS server; the uplink classifier user plane functional network element is used to determine whether the target public network domain name satisfies a preset DNS redirection rule, and when the target public network domain name satisfies the DNS redirection rule, determine the target intranet DNS server corresponding to the target public network domain name according to the DNS redirection rule, wherein the DNS redirection rule It defines multiple public domain names to be redirected and the intranet DNS server to which each public domain name is redirected; sends a DNS resolution request message to the target intranet DNS server, and receives a first DNS resolution response message fed back by the target intranet DNS server, wherein the first DNS resolution response message carries at least a second IP address obtained by the target intranet DNS server for resolving the target public domain name; converts the second IP address into a target virtual IP address according to a preset target IP address conversion rule, and sends the first DNS resolution response message with the resolution result being the target virtual IP address to the user device, wherein the target IP address conversion rule includes a mapping relationship between the real IP addresses obtained by resolving multiple public domain names and the preset virtual IP address.

[0014] Optionally, the user device is further used to send a first service request message to the uplink classifier user plane functional network element, wherein the destination IP address of the first service request message is the target virtual IP address; the uplink classifier user plane functional network element is further used to convert the target virtual IP address into a second IP address according to the target IP address conversion rule, and send the first service request message to the second IP address; receive a first service response message fed back by the second IP address; convert the source IP address of the first service response message from the second IP address to the target virtual IP address using the target IP address conversion rule; and send the first service response message whose source IP address is the target virtual IP address to the user device.

[0015] Optionally, the uplink classifier user plane functional network element is also used to send the DNS resolution request message to the public network DNS server when the target public network domain name in the DNS resolution request message does not meet the DNS redirection rules, and receive a second DNS resolution response message fed back by the public network DNS server, wherein the second DNS resolution response message carries at least the fourth IP address obtained by the public network DNS server for resolving the target public network domain name; and send the second DNS resolution response message whose source IP address is the first IP address and the resolution result is the fourth IP address to the user equipment.

[0016] Optionally, the user equipment is further used to send a second service request message to the uplink classifier user plane functional network element, wherein the destination IP address of the second service request message is a fourth IP address; the uplink classifier user plane functional network element is further used to send the second service request message to the fourth IP address and receive a second service response message fed back by the fourth IP address; and send the second service response message whose source IP address is the fourth IP address to the user equipment.

[0017] According to another aspect of an embodiment of the present application, a network device is further provided, comprising: a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the above-mentioned public domain name diversion method through the computer program.

[0018] In an embodiment of the present application, the user-side functional network element of the uplink classifier receives and analyzes the DNS resolution request message initiated by the user device, and determines whether the target public domain name requested for resolution complies with the preset DNS redirection rules; for requests that match the rules, it redirects them to the corresponding target intranet DNS server, and performs DNAT conversion based on the resolution result returned by the target intranet DNS server, so as to replace the real IP address obtained by resolving the DNS resolution response message with the corresponding target virtual IP address before sending it to the user device. This allows the user-side functional network element of the uplink classifier to accurately distinguish and control the traffic of the intranet diversion domain name and the ordinary public domain name based on the virtual IP address, avoiding the diversion misclassification caused by the shared content distribution network service provider, achieving the purpose of ensuring normal access to ordinary public network services, and thus solving the technical problem that the content distribution network service provider returns the same IP address for the two DNS resolution requests for the intranet diversion public network service and the ordinary public network service, resulting in the inability to access the ordinary public network service normally. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0020] Figure 1 is a schematic structural diagram of an optional communication system according to an embodiment of the present application;

[0021] Figure 2 This is a flow chart of an optional public domain name diversion method according to an embodiment of the present application;

[0022] Figure 3 This is a schematic diagram of an optional process of requesting a public network service according to an embodiment of the present application;

[0023] Figure 4This is a flowchart of another optional public network service request according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0025] It should be noted that the terms "first", "second", etc. in the specification, claims, and drawings of the present application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products, or devices.

[0026] In order to better understand the embodiments of the present application, some nouns or terms that appear in the description of the embodiments of the present application are first translated and explained as follows:

[0027] The User Plane Function (UPF) is a core network element in the user plane of the 5G core network, responsible for packet routing, forwarding, QoS (Quality of Service) policy enforcement, traffic monitoring, and lawful interception. Controlled by the Session Management Function (SMF) via the N4 interface, the UPF supports functions such as the Uplink Classifier (ULCL) and Branching Point, serving as a key anchor for Multi-access Edge Computing (MEC).

[0028] PSA0 UPF (PDU Session Anchor 0 UPF): This anchor point serves as the session anchor for user equipment (UE) accessing the internet. It is typically deployed in prefecture-level or provincial core networks. The PSA0 UPF connects to the ULCL UPF through the N9 interface and processes public network traffic that doesn't match local rules.

[0029] PSA1 UPF (PDU Session Anchor 1 UPF, secondary anchor point UPF): This is the PDU session anchor point for local network access. In ULCL traffic diversion scenarios, the PSA1 UPF is responsible for routing matching traffic to the enterprise intranet, collaborating with the primary anchor point, PSA0 UPF, to achieve dual-path transmission.

[0030] ULCL (Uplink Classifier): is used to forward uplink service data to different PDU (Protocol Data Unit) session anchors according to filter requirements, and aggregate downlink service data from multiple session anchors of a single user and encapsulate and transmit them.

[0031] DNS (Domain Name System): is a technology that maps domain names and IP (Internet Protocol Address) addresses to each other.

[0032] CDN (Content Delivery Network) is an intelligent virtual network built on the existing Internet by placing node servers throughout the network. Its goal is to avoid bottlenecks and links on the Internet that may affect data transmission speed and stability as much as possible, making content transmission faster and more stable.

[0033] DNAT (Destination Network Address Translation): This technology replaces the destination IP address of a data packet with another IP address. This conversion occurs when a data packet is sent from an external network to an internal network.

[0034] Public network: also known as extranet or wide area network, it is a remote network that connects local area networks or metropolitan area networks (MANs) in different regions, and it usually spans a large physical range.

[0035] Intranet: also known as local area network, it refers to a computer group composed of multiple interconnected computers in a certain area, generally within a radius of several thousand meters. Therefore, the intranet is a closed type.

[0036] Example 1

[0037] According to an embodiment of the present application, a communication system is provided. The structure of the communication system is as follows: Figure 1 As shown, it includes: user equipment (hereinafter referred to as "UE"), uplink classifier user plane function UCLC UPF network element, access and mobility management function (AMF) network element, session management function SMF network element, (radio) access network (RAN), Internet (including public network DNS server), and enterprise intranet (including intranet DNS server). Among them, the user equipment interacts with the AMF network element through the N1 interface; the AMF network element interacts with the SMF network element through the N11 interface and interacts with the (R)AN through the N2 interface; the (R)AN interacts with the uplink classifier user plane function network element through the N3 interface; the SMF network element interacts with the uplink classifier user plane function network element, the primary anchor point UPF, and the secondary anchor point UPF respectively through the N4 interface; the uplink classifier user plane function network element interacts with the primary anchor point UPF and the secondary anchor point UPF through the N9 interface; the primary anchor point UPF interacts with the public network through the N6 interface, and the secondary anchor point UPF interacts with the intranet through the N6 interface. It should be noted that the uplink classifier user plane function network element can be co-located with the primary anchor point UPF (PSA0 UPF) or with the secondary anchor point UPF (ie, PSA1 UPF).

[0038] As an optional implementation, the uplink classifier user plane functional network element can perform public network domain name diversion according to Figure 2 The process steps shown interact with the user device and include:

[0039] In step S2, the uplink classifier user plane functional network element first receives a DNS resolution request message initiated by the user equipment, wherein the DNS resolution request message carries at least the target public domain name to be resolved, and the destination IP address of the DNS resolution request message is the first IP address of the public DNS server.

[0040] In step S4, the upstream classifier user plane functional network element determines whether the target public domain name satisfies a preset DNS redirection rule. If the target public domain name satisfies the DNS redirection rule, the upstream classifier user plane functional network element determines a target intranet DNS server corresponding to the target public domain name based on the DNS redirection rule. The DNS redirection rule defines multiple public domain names to be redirected and the intranet DNS server to which each public domain name is redirected.

[0041] Step S6: Send the DNS resolution request message to the target intranet DNS server and receive a first DNS resolution response message fed back by the target intranet DNS server, wherein the first DNS resolution response message carries at least the second IP address obtained by the target intranet DNS server from resolving the target public domain name.

[0042] In step S8, the uplink classifier user plane functional network element converts the second IP address into a target virtual IP address according to a preset target IP address conversion rule, and sends a first DNS resolution response message containing the target virtual IP address as the resolution result to the user equipment. The target IP address conversion rule includes a mapping relationship between real IP addresses obtained by resolving multiple public domain names and a preset virtual IP address.

[0043] That is, the uplink classifier user plane functional network element receives and analyzes the DNS resolution request message initiated by the user device, and determines whether the target public domain name requested for resolution complies with the preset DNS redirection rules; for requests that match the rules, it redirects them to the corresponding target intranet DNS server, and performs DNAT conversion based on the resolution result returned by the target intranet DNS server, so as to replace the real IP address obtained by resolving the DNS resolution response message with the corresponding target virtual IP address, and then feeds it back to the user device. This allows the uplink classifier user plane functional network element to accurately distinguish and control the traffic of intranet diversion domain names and ordinary public domain names based on virtual IP addresses, avoiding the diversion misclassification caused by shared content distribution network service providers, achieving the purpose of ensuring normal access to ordinary public network services, and thus solving the technical problem that ordinary public network services cannot be accessed normally because the content distribution network service provider returns the same IP address for the two DNS resolution requests for the intranet diversion public network services and ordinary public network services.

[0044] The following will describe the detailed process of the public network domain name diversion method implemented on the uplink classifier user plane function UCLC UPF network element side with reference to a specific process interaction diagram.

[0045] First, the user equipment interacts with the access and mobility management function network element in the 5G network to complete the authentication and registration of the access network. Then the user equipment communicates with the session management function network element to establish one or more PDU (Packet Data Unit) sessions. In the UE's session activation response message, the core network (5G Core, 5GC) will carry the IP address of a public network DNS server itself (i.e., the first IP address). This is to ensure that the user equipment can independently resolve and access domain name resources on the Internet without relying on a specific target intranet DNS server or configuration, thereby enhancing the flexibility and autonomy of the user equipment in the network.

[0046] Next, the (R)AN encapsulates the DNS resolution request message (e.g., "abc.com") initiated by the user equipment into the GTP-U (GPRS Tunneling Protocol-User Plane) tunnel of the N3 interface and sends it to the Uplink Classifier User Plane Function (UCLC UPF) network element. The DNS resolution request message carries at least the target public domain name to be resolved (e.g., "abc.com"), and the destination IP address of the DNS resolution request message is the first IP address of the public DNS server.

[0047] Then, the uplink classifier user plane function network element determines whether the target public domain name meets the preset DNS redirection rules, where the DNS redirection rules are pre-configured by the core network network elements (i.e., UPF network elements and SMF network elements), and the DNS redirection rules specify a series of public domain names to be redirected and the intranet DNS server (also known as the "local DNS server") to which each public domain name is redirected.

[0048] When the target public network domain name meets the DNS redirection rule, the uplink classifier user plane function UCLC UPF network element is co-located with the auxiliary anchor point UPF, and each network element in the communication system can be Figure 3 The flowchart shown implements public network service requests based on public network domain name diversion, including:

[0049] Step S11 : The uplink classifier user plane function (UCLC) UPF network element determines a target intranet DNS server corresponding to a target public network domain name according to a DNS redirection rule.

[0050] Step S12: The Uplink Classifier User Plane Function (UCLC UPF) network element redirects the DNS resolution request message to the target intranet DNS server of the local network through the N6 interface.

[0051] In step S13, the uplink classifier user plane function (UCLC) UPF network element receives a first DNS resolution response message fed back by the target intranet DNS server. The first DNS resolution response message carries at least the second IP address obtained by the target intranet DNS server from resolving the target public domain name, and the third IP address of the target intranet DNS server itself. Therefore, the source IP address of the first DNS resolution response message is the third IP address.

[0052] In step S14, the uplink classifier user plane function UCLC UPF network element modifies the source IP address of the first DNS resolution response message from the third IP address to the first IP address, so as to avoid the user device not accepting or correctly processing the response message because the source IP address of the DNS resolution response message does not match the expectation, thereby eliminating potential compatibility and identification problems. At the same time, the uplink classifier user plane function UCLC UPF network element converts the resolution result from the second IP address to the target virtual IP address according to the preset target IP address conversion rule. Among them, the target IP address conversion rule (also known as the "DNS resolution replacement rule") includes the mapping relationship between the real IP address obtained by resolving multiple public domain names and the preset virtual IP address.

[0053] In step S15, the uplink classifier user plane function UCLC UPF network element encapsulates the first DNS resolution response message whose source IP address is the first IP address and whose resolution result is the target virtual IP address in the GTP-U tunnel of the N3 interface and sends it to the (R)AN, which then sends the first DNS resolution response message to the user equipment.

[0054] Step S16: (R)AN encapsulates the first service request message initiated by the user equipment into the GTP-U tunnel of the N3 interface and sends it to the uplink classifier user plane function UCLC UPF network element, wherein the destination IP address of the first service request message is the target virtual IP address.

[0055] Step S17: The uplink classifier user plane function (UCLC UPF) network element performs a decapsulation operation to restore the original service data message, and then determines the second IP address corresponding to the target virtual IP address according to the target IP address conversion rule.

[0056] Step S18, the uplink classifier user plane function UCLC UPF network element sends the first service request message to the Internet website corresponding to the second IP address through the N6 interface and the N9 interface in sequence, thereby achieving service access through the public network channel of the local network.

[0057] Step S19: The uplink classifier user plane function UCLC UPF network element receives the first service response message fed back by the Internet website corresponding to the second IP address through the N9 interface and the N6 interface in sequence.

[0058] In step S110, the uplink classifier user plane function UCLC UPF network element uses the target IP address conversion rule to convert the source IP address of the first service response message from the second IP address to the target virtual IP address, so that the source IP address of the first DNS resolution response message received by the user equipment is consistent with the destination IP address at the time of the request, thereby ensuring service continuity and the user's non-perceptual experience.

[0059] Step S111, the uplink classifier user plane function UCLC UPF network element encapsulates the first service response message whose source IP address is the target virtual IP address in the GTP-U tunnel of the N3 interface and sends it to the (R)AN, and the (R)AN then sends the first service response message to the user equipment.

[0060] In the case that the target public network domain name does not meet the DNS redirection rules, the uplink classifier user plane function UCLCUPF network element is co-located with the main anchor point UPF, and each network element in the communication system can be based on Figure 4 The flowchart shown implements a public network service request, including:

[0061] Step S21: The uplink classifier user plane function (UCLC UPF) network element sends a DNS resolution request message to a public network DNS server corresponding to the first IP address through the N6 interface.

[0062] Step S22: The uplink classifier user plane function (UCLC) UPF network element receives a second DNS resolution response message fed back by the public network DNS server, wherein the second DNS resolution response message carries at least a fourth IP address obtained by resolving the target public network domain name by the public network DNS server.

[0063] Step S23: The uplink classifier user plane function UCLC UPF network element records the correspondence between the target public network domain name and the fourth IP address.

[0064] In step S24, the uplink classifier user plane function UCLC UPF network element encapsulates the second DNS resolution response message whose source IP address is the first IP address and whose resolution result is the fourth IP address in the GTP-U tunnel of the N3 interface and sends it to the (R)AN, which then sends the second DNS resolution response message to the user equipment.

[0065] In step S25, the (R)AN encapsulates the second service request message initiated by the user equipment within the GTP-U tunnel of the N3 interface and sends it to the Uplink Classifier User Plane Function (UCLC) UPF network element. The first service request message carries at least the target public domain name corresponding to the public DNS server and the fourth IP address corresponding to the target public domain name.

[0066] Step S26: The uplink classifier user plane function (UCLC UPF) network element first performs a decapsulation operation to restore the original service data message.

[0067] Step S27: The uplink classifier user plane function (UCLC UPF) network element sends the second service request message to the Internet website corresponding to the fourth IP address through the N6 interface and the N9 interface in sequence, wherein the destination IP address of the second service request message is the fourth IP address.

[0068] Step S28: The uplink classifier user plane function (UCLC) UPF network element receives a second service response message fed back by the Internet website corresponding to the fourth IP address through the N9 interface and the N6 interface in sequence, wherein the source IP address of the second service response message is the fourth IP address.

[0069] In step S29, the uplink classifier user plane function UCLC UPF network element encapsulates the second service response message whose source IP address is the fourth IP address in the GTP-U tunnel of the N3 interface and sends it to the (R)AN. The (R)AN then sends the second service response message to the user equipment, thereby ensuring normal access to the DNS service.

[0070] Therefore, the communication system provided in the embodiment of the present application does not require major improvements to the core network architecture. It only needs to embed the logic of DNS hijacking and DNAT rule generation in the auxiliary anchor point UPF to achieve public domain name diversion, which greatly reduces the deployment cost and complexity, while improving the adaptability and efficiency of the network.

[0071] Example 2

[0072] According to an embodiment of the present application, a network device is also provided, which includes: a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the public domain name diversion method in Example 1 through the computer program.

[0073] Specifically, the computer program executes the following steps when it is running: the uplink classifier user plane functional network element receives the domain name system DNS resolution request message initiated by the user equipment, wherein the DNS resolution request message carries at least the target public network domain name to be resolved, and the destination IP address of the DNS resolution request message is the first IP address of the public network DNS server; it determines whether the target public network domain name meets the preset DNS redirection rule, and when the target public network domain name meets the DNS redirection rule, determines the target intranet DNS server corresponding to the target public network domain name according to the DNS redirection rule, wherein the DNS redirection rule defines multiple public network domain names to be redirected and the number of each public network domain name to be redirected. A directed intranet DNS server; sending a DNS resolution request message to a target intranet DNS server, and receiving a first DNS resolution response message fed back by the target intranet DNS server, wherein the first DNS resolution response message carries at least a second IP address obtained by the target intranet DNS server from resolving the target public domain name; converting the second IP address into a target virtual IP address according to a preset target IP address conversion rule, and sending a first DNS resolution response message whose resolution result is the target virtual IP address to a user device, wherein the target IP address conversion rule includes a mapping relationship between real IP addresses obtained from resolving multiple public domain names and a preset virtual IP address.

[0074] The serial numbers of the above embodiments are for description only and do not represent the advantages or disadvantages of the embodiments.

[0075] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0076] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0077] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected to achieve the purpose of the present embodiment according to actual needs.

[0078] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0079] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program code.

[0080] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for distributing public domain names, characterized in that: include: The uplink classifier user plane function network element receives a domain name system DNS resolution request message initiated by the user equipment, wherein the DNS resolution request message carries at least a target public network domain name to be resolved, and the destination IP address of the DNS resolution request message is the first IP address of the public network DNS server; Determine whether the target public domain name satisfies a preset DNS redirection rule, and if the target public domain name satisfies the DNS redirection rule, determine a target intranet DNS server corresponding to the target public domain name according to the DNS redirection rule, wherein the DNS redirection rule defines multiple public domain names to be redirected and the intranet DNS server to which each public domain name is redirected; Send the DNS resolution request message to the target intranet DNS server, and receive a first DNS resolution response message fed back by the target intranet DNS server, wherein the first DNS resolution response message carries at least the second IP address obtained by the target intranet DNS server from resolving the target public domain name; The second IP address is converted into a target virtual IP address according to a preset target IP address conversion rule, and the first DNS resolution response message whose resolution result is the target virtual IP address is sent to the user device, wherein the target IP address conversion rule includes a mapping relationship between the real IP addresses obtained by resolving multiple public domain names and the preset virtual IP address.

2. The method according to claim 1, characterized in that The DNS resolution response message further carries the third IP address of the target intranet DNS server, wherein sending the first DNS resolution response message whose resolution result is the target virtual IP address to the user equipment includes: Modify the source IP address of the DNS resolution response message from the third IP address to the first IP address; The first DNS resolution response message whose source IP address is the first IP address and whose resolution result is the target virtual IP address is sent to the user equipment.

3. The method according to claim 2, characterized in that After sending the first DNS resolution response message whose source IP address is the first IP address and whose resolution result is the target virtual IP address to the user equipment, the method further includes: receiving a first service request message initiated by the user equipment, wherein the destination IP address of the first service request message is the target virtual IP address; Convert the target virtual IP address to a second IP address according to the target IP address conversion rule, and send the first service request message to the second IP address; receiving a first service response message fed back by the second IP address; Converting the source IP address of the first service response message from the second IP address to the target virtual IP address using the target IP address conversion rule; The first service response message whose source IP address is the target virtual IP address is sent to the user equipment.

4. The method according to claim 1, wherein The method further comprises: If the target public domain name in the DNS resolution request message does not satisfy the DNS redirection rule, sending the DNS resolution request message to the public DNS server, and receiving a second DNS resolution response message fed back by the public DNS server, wherein the second DNS resolution response message carries at least a fourth IP address obtained by the public DNS server from resolving the target public domain name; The second DNS resolution response message whose source IP address is the first IP address and whose resolution result is the fourth IP address is sent to the user equipment.

5. The method according to claim 4, characterized in that After sending the second DNS resolution response message whose source IP address is the first IP address and whose resolution result is the fourth IP address to the user equipment, the method further includes: receiving a second service request message initiated by the user equipment, wherein the destination IP address of the second service request message is the fourth IP address; Sending the second service request message to the fourth IP address, and receiving the second service response message fed back by the fourth IP address; The second service response message whose source IP address is the fourth IP address is sent to the user equipment.

6. The method according to any one of claims 1 to 5, characterized in that receiving a request message initiated by the user equipment through the user plane of the general packet radio service tunneling protocol of the N3 interface, wherein the request message includes one of the following: a DNS resolution request message, a first service request message, and a second service request message; The user plane of the General Packet Radio Service Tunneling Protocol through the N3 interface sends a response message to the user equipment, wherein the response message includes one of the following: a first DNS resolution response message, a second DNS resolution response message, a first service response message, and a second service response message.

7. The method according to any one of claims 1 or 3, characterized in that Sending a request message to the public network DNS server or the target intranet DNS server through the N6 interface, wherein the request message includes one of the following: a DNS resolution request message, a first service request message, and a second service response message; A response message fed back by the public network DNS server or the target intranet DNS server is received through the N6 interface, wherein the response message includes one of the following: a first DNS resolution response message, a second DNS resolution response message, a first service response message, and a second service response message.

8. A communication system, characterized in that: The communication system at least includes: user equipment, uplink classifier user plane function network element, wherein, The user equipment is configured to send a DNS resolution request message to the uplink classifier user plane function network element, wherein the DNS resolution request message carries at least a target public network domain name to be resolved, and the destination IP address of the DNS resolution request message is a first IP address of a public network DNS server; The uplink classifier user plane functional network element is used to determine whether the target public domain name meets the preset DNS redirection rules, and if the target public domain name meets the DNS redirection rules, determine the target intranet DNS server corresponding to the target public domain name according to the DNS redirection rules, wherein the DNS redirection rules define multiple public domain names to be redirected and the intranet DNS server to which each public domain name is redirected; send the DNS resolution request message to the target intranet DNS server, and receive the first DNS resolution response message fed back by the target intranet DNS server, wherein the first DNS resolution response message carries at least the second IP address obtained by the target intranet DNS server for resolving the target public domain name; convert the second IP address into a target virtual IP address according to the preset target IP address conversion rule, and send the first DNS resolution response message with the resolution result of the target virtual IP address to the user device, wherein the target IP address conversion rule includes a mapping relationship between the real IP addresses obtained by resolving multiple public domain names and the preset virtual IP addresses.

9. The system according to claim 8, characterized in that The user equipment is further configured to send a first service request message to the uplink classifier user plane function network element, wherein the destination IP address of the first service request message is the target virtual IP address; The uplink classifier user plane functional network element is also used to convert the target virtual IP address into a second IP address according to the target IP address conversion rule, and send the first service request message to the second IP address; receive the first service response message fed back by the second IP address; use the target IP address conversion rule to convert the source IP address of the first service response message from the second IP address to the target virtual IP address; and send the first service response message with the source IP address being the target virtual IP address to the user device.

10. The system according to claim 8, wherein: The uplink classifier user plane functional network element is further used to send the DNS resolution request message to the public network DNS server and receive a second DNS resolution response message fed back by the public network DNS server when the target public network domain name in the DNS resolution request message does not meet the DNS redirection rule, wherein the second DNS resolution response message carries at least a fourth IP address obtained by the public network DNS server for resolving the target public network domain name; and send the second DNS resolution response message whose source IP address is the first IP address and whose resolution result is the fourth IP address to the user equipment.

11. The system according to claim 8, wherein: The user equipment is further configured to send a second service request message to the uplink classifier user plane function network element, wherein the destination IP address of the second service request message is the fourth IP address; The uplink classifier user plane functional network element is also used to send the second service request message to the fourth IP address and receive the second service response message fed back by the fourth IP address; and send the second service response message with the source IP address being the fourth IP address to the user equipment.

12. A network device, characterized in that: include: A memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the public domain name diversion method according to any one of claims 1 to 7 through the computer program.