Domain name data processing method and device, server and storage medium
By introducing blockchain technology into the domain name system, and verifying and storing query records according to users' security requirements, the security issues of centralized caching mechanisms are solved, achieving higher domain name data credibility and user security.
Patent Information
- Application Number
- CN202010460770.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-27
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2040-05-27
AI Technical Summary
In the existing domain name system, the caching mechanism is centralized and lacks data protection mechanisms, resulting in poor trustworthiness of DNS resources, making them susceptible to malicious tampering and affecting user experience.
By using blockchain technology for domain name data caching and querying, the verification method is determined according to the user's security requirements, and the query records are stored in the domain name blockchain. The distributed nature and security properties of blockchain are used to improve the credibility and tamper resistance of the data.
It improves the accuracy and adaptability of domain name verification, reduces the possibility of data tampering, and enhances the security of users' online access and the credibility of query records.
Smart Images

Figure CN113742783B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of domain name maintenance and query, and particularly relates to a domain name data processing method and device, a server and a storage medium. BACKGROUND
[0002] The domain name system (DNS) is a database for mapping domain names and IP addresses, and is an important Internet infrastructure resource.
[0003] The existing domain name resource caching mechanism is a centralized caching mechanism, that is, a single data point such as a DNS server initiates caching and single-point verification and authorization, and there is no sufficient data protection mechanism, the data caching security is poor, and the possibility of malicious tampering is relatively large, which leads to poor credibility of the queried DNS resource, and brings a poor user experience. SUMMARY
[0004] The embodiments of the present application provide a domain name data processing method and device, a server and a storage medium, which perform data caching and query based on a blockchain, and improve the security and credibility of domain name data.
[0005] In a first aspect, the embodiments of the present application provide a domain name data processing method, which comprises:
[0006] obtaining a user-inputted domain name to be queried and a security requirement level of the user;
[0007] obtaining a query record of the domain name to be queried;
[0008] determining a verification mode of the query record according to the security requirement level of the user;
[0009] verifying the query record based on the verification mode, and caching the query record in a domain name blockchain if the verification is passed.
[0010] The obtaining of the security requirement level of the user comprises:
[0011] determining the security requirement level of the user according to a network environment of the user and / or a type of the domain name to be queried.
[0012] Optionally, the determining of the verification mode of the query record according to the security requirement level of the user comprises:
[0013] obtaining a correspondence table of the security requirement level and the verification mode;
[0014] determining the verification mode of the query record according to the security requirement level and the correspondence table.
[0015] Optionally, the domain name blockchain comprises at least two domain name management nodes, and the caching of the query record into the domain name blockchain comprises:
[0016] The current domain name management node initiates the query record caching, and obtains verification results of the query record caching by each domain name management node;
[0017] The current domain name management node determines whether the query record caching is qualified according to the verification results of the query record caching by each domain name management node;
[0018] If qualified, the query record is cached into the domain name blockchain.
[0019] Optionally, the current domain name management node determines whether the query record caching is qualified according to the verification results of the query record caching by each domain name management node, comprising:
[0020] The current domain name management node receives the verification results of the query record caching by each domain name management node, wherein the verification results comprise two kinds of verification pass and verification fail;
[0021] According to a comparison result of a ratio of the verification pass in the verification results and a preset threshold, it is determined whether the query record caching is qualified.
[0022] In a second aspect, the application further provides a domain name data processing method, comprising:
[0023] Obtaining a user inputted domain name to be queried;
[0024] Judging whether a query record of the domain name to be queried exists in a domain name blockchain, wherein a caching method of the query record is the domain name data processing method provided in the first aspect;
[0025] If the query record exists, the query record is returned.
[0026] In a third aspect, the application further provides a domain name data processing device, comprising:
[0027] A first domain name obtaining module is configured to obtain a user inputted domain name to be queried and a security requirement level of the user;
[0028] A query record obtaining module is configured to obtain a query record of the domain name to be queried;
[0029] A verification mode determining module is configured to determine a verification mode of the query record according to the security requirement level of the user;
[0030] The query record caching module is configured to verify the query record based on the verification mode, and cache the query record in the domain name blockchain if the verification is passed.
[0031] Optionally, the first domain name obtaining module comprises:
[0032] The first domain name obtaining unit is configured to obtain a domain name to be queried input by a user.
[0033] The security requirement level determining unit is configured to determine a security requirement level of the user according to a network environment of the user and / or a type of the domain name to be queried.
[0034] Optionally, the verification mode determining module is specifically configured to:
[0035] obtain a correspondence table between the security requirement level and the verification mode.
[0036] determine the verification mode of the query record according to the security requirement level and the correspondence table.
[0037] Optionally, the domain name blockchain comprises at least two domain name management nodes, and the query record caching module comprises:
[0038] The verification result obtaining unit is configured to initiate, by a current domain name management node, caching of a query record, and obtain verification results of the query record caching by each domain name management node.
[0039] The cache eligibility determining unit is configured to determine, by the current domain name management node, whether the query record caching is eligible according to the verification results of the query record caching by each domain name management node.
[0040] The query record caching unit is configured to cache the query record in the domain name blockchain if the query record caching is eligible.
[0041] Optionally, the cache eligibility determining unit is specifically configured to:
[0042] the current domain name management node receives the verification results of the query record caching by each domain name management node, wherein the verification results comprise two types of verification passed and verification not passed.
[0043] determine whether the query record caching is eligible according to a comparison result of a ratio of the verification passed in the verification results and a preset threshold.
[0044] In a fourth aspect, the application further provides a domain name data processing apparatus, which comprises:
[0045] The second domain name obtaining module is configured to obtain a domain name to be queried input by a user.
[0046] The query record judgment module is configured to judge whether the query record of the domain name to be queried exists in the domain name block chain, wherein the cache method of the query record is the domain name data processing method provided by the first aspect of the application.
[0047] The query returning module is configured to return the query record if the query record of the domain name to be queried exists.
[0048] In a fifth aspect, the application further provides a domain name server, comprising a memory, a processor and a computer program.
[0049] The computer program is stored in the memory and is configured to be executed by the processor to implement the domain name data processing method provided by any of the embodiments of the application.
[0050] In a sixth aspect, the application further provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the domain name data processing method provided by any of the embodiments of the application.
[0051] The domain name data processing method, device, server and storage medium provided by the embodiments of the application determine the verification mode of the query record of the domain name to be queried according to the domain name to be queried input by the user and the security requirement level of the user, and perform security verification on the query record based on the verification mode, and cache the query record in the block chain if the verification is passed, thereby determining the corresponding verification mode based on the security requirement level required by the user himself, improving the accuracy and adaptability of domain name verification, storing the query record in the block chain, effectively reducing the possibility of data tampering, and improving the credibility of the query record and the security of the user's online. BRIEF DESCRIPTION OF DRAWINGS
[0052] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the application and, together with the specification, serve to explain the principles of the application.
[0053] Figure 1 An application scenario diagram of the domain name data processing method provided by the embodiments of the application;
[0054] Figure 2 A flowchart of the domain name data processing method provided by one of the embodiments of the application;
[0055] Figure 3 A flowchart of the domain name data processing method provided by another embodiment;
[0056] Figure 4 A flowchart of the domain name data processing method provided by another embodiment;
[0057] Figure 5 A structural schematic diagram of a domain name data processing apparatus provided by an embodiment of the present application is shown in the figure.
[0058] Figure 6 A structural schematic diagram of a domain name data processing apparatus provided by another embodiment of the present application is shown in the figure.
[0059] Figure 7 A structural schematic diagram of a domain name data processing apparatus provided by an embodiment of the present application is shown in the figure.
[0060] Figure 8 A structural schematic diagram of a domain name server provided by an embodiment of the present application is shown in the figure.
[0061] The specific embodiments of the present application have been shown in the above figures, and will be described in more detail hereinafter. These figures and the following description are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application for those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0062] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The same numbers are used in different drawings to represent the same or similar elements. The following detailed description is not intended to limit the scope of the present application, but rather to explain the embodiments of the present application as set out in the appended claims.
[0063] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments. The embodiments of the present application will be described below with reference to the drawings.
[0064] The application scenarios of the embodiments of the present application will be explained below:
[0065] Figure 1 An application scenario diagram of a domain name data processing method provided by an embodiment of the present application is shown in the figure. Figure 1 As shown in the figure, a target user inputs a domain name (Domain Name) through a related application or webpage of a user terminal, a DNS server or domain name server performs domain name resolution according to the domain name input by the user, obtains the corresponding IP address, and returns the IP address to the user terminal, so that the user can access the related webpage according to the IP address.
[0066] The main technical scheme of the domain name data processing method provided in the application is: determining the verification mode of the query record of the domain name according to the security requirement level of the user, and storing the query record of the domain name based on the blockchain after the security verification is passed, thereby improving the credibility of the query record and the security of the user accessing the webpage.
[0067] The blockchain is a distributed database, which has three main characteristics: first, the data structure is saved by using a hash algorithm, which improves the traceability of the data; second, multiple nodes participate in the system operation, which embodies the distributed feature and realizes decentralization or weak centralization; third, the consistency of the saved data is agreed through a certain protocol or algorithm, which is the consensus algorithm, and effectively prevents the data in the blockchain from being maliciously tampered with.
[0068] Recursive server: the recursive DNS server is used for querying and caching DNS resource records. The recursive DNS server independently maintains and caches the DNS resource records, and if the cached resource records have not expired, the cached resource records are directly returned when the user queries again without querying.
[0069] Since the recursive DNS server does not have sufficient protection mechanism for the cached resource records, the data may be maliciously tampered with. The blockchain technology is introduced in the application to solve the security problem of the recursive server by using the security properties of the blockchain.
[0070] Figure 2 The flowchart of the domain name data processing method provided in an embodiment of the application can be executed by a server, such as a DNS server or a domain name server. As shown in Figure 2 The domain name data processing method provided in the embodiment includes the following steps:
[0071] Step S101, obtaining a to-be-queried domain name input by a user and a security requirement level of the user.
[0072] The to-be-queried domain name is a domain name input by the user, and the related DNS server, such as the recursive server or the authoritative server, needs to determine the IP address corresponding to the to-be-queried domain name through domain name resolution. The security requirement level represents the security requirement of the user for the domain name resource record or the query record, and the higher the level is, the higher the security requirement is.
[0073] Domain name is usually composed of a string of names separated by points, the name of a computer or computer group on the Internet, because IP address has the disadvantage of inconvenient to remember and can not show the name and nature of address organization, people designed domain name, and through the domain name system (DNS, Domain Name System) to map domain name and IP address, so that people more convenient access to the Internet, without having to remember the IP address string that can be directly read by the machine.
[0074] Specifically, the user can input or select its security requirements level, or use the system default security requirements level, such as the default highest security requirements level.
[0075] Step S102, obtaining the query record of the domain name to be queried.
[0076] The query record can also be referred to as DNS resource record, which can include the IP address corresponding to the query domain name.
[0077] Specifically, the query record includes one or more of A record (host record, Address Record), NS record (domain name server record, Name Server Record), SOA record (start of authority record, Start of Authority Record), MX record (mail exchange record, Mail Exchanger Record), Cname record (alias record, Canonical NAME Record), SRV record (server resource record, Server Resource Record) and PTR record (pointer record, Pointer Record). Among them, A record is the most widely used DNS resource record, the basic role of A record is to explain what the IP address corresponding to a domain name is, which is the corresponding relationship between domain name and IP address; NS record and SOA record are two indispensable records in DNS resource record, NS record is used to explain which DNS server is responsible for domain name resolution, SOA record explains which is the master server in the DNS server responsible for domain name resolution; MX record is used to specify the mail server responsible for processing mail sent to the recipient domain name; Cname record allows multiple domain names to be mapped to the same computer; SRV record records the mapping relationship between computer and its provided service; PTR record is the reverse record of A record, which is used to parse IP address to domain name.
[0078] Usually, after the user inputs the domain name to be queried, the DNS server will return the corresponding DNS resource record (query record) according to the domain name to be queried, so that the user can access the web page corresponding to the domain name to be queried according to the DNS resource record.
[0079] Further, the query record of the domain name to be queried can be obtained based on a recursive server or an authoritative server.
[0080] In order to improve the security of user network access, the DNS resource record needs to be verified before being sent to the user.
[0081] In step S103, the verification mode of the query record is determined according to the security requirement level of the user.
[0082] The verification mode can be one or more of verification to an authoritative server, verification to an organization, and verification to a domain name holder.
[0083] Specifically, a trust degree can be set for each verification mode, wherein the trust degree corresponds to the security requirement level of the user, and the higher the security requirement level of the user is, the higher the trust degree of the verification mode required is. Furthermore, the verification mode of the query record can be determined according to the security requirement level of the user and the trust degree of the verification mode.
[0084] In step S104, the query record is verified based on the verification mode, and if the verification is passed, the query record is cached in the domain name blockchain.
[0085] The domain name blockchain refers to a blockchain for storing query records, and can also store domain names to be queried, so that when the domain name to be queried is queried again, the query record of the domain name to be queried stored in the blockchain can be directly returned.
[0086] Specifically, after the verification is passed, the query record is sent to the user.
[0087] Specifically, the domain name blockchain stores the query record and the domain name to be queried based on a hash algorithm, and the stored data is copied and distributed to each node of the blockchain. Based on the distributed characteristics of the blockchain, decentralization is realized, the efficiency of data access is improved, and the security and tamper resistance of data storage are improved.
[0088] The domain name data processing method provided in the embodiment determines the verification mode of the query record of the domain name to be queried according to the domain name to be queried input by the user and the security requirement level of the user, and performs security verification on the query record based on the verification mode. If the verification is passed, the query record is cached in the blockchain. The corresponding verification mode is determined based on the security requirement level of the user, the accuracy and adaptability of domain name verification are improved, the query record is stored in the blockchain, the possibility of data tampering is effectively reduced, and the credibility of the query record and the security of user network access are improved.
[0089] Figure 3A flowchart of a domain name data processing method provided for another embodiment of the present application is shown in Figure 3 As shown in the embodiment provided in the flowchart of the domain name data processing method provided in the embodiment shown in Figure 2 The domain name data processing method provided in the embodiment includes the following steps based on the domain name data processing method provided in the embodiment shown in
[0090] Step S201: Obtain a user-inputted domain name to be queried.
[0091] Step S202: Obtain a query record of the domain name to be queried.
[0092] Step S203: Determine a security requirement level of the user according to a network environment of the user and / or a type of the domain name to be queried.
[0093] The type of the domain name to be queried can include a shopping type, a payment type, an entertainment type, a social type, etc., and different types have different security performance requirements. The network environment includes a type of the Internet connected by the user, such as a public network or a private network, a trusted network or a newly-joined network, and can also include an online mode, a connection state, etc.
[0094] For example, if the network connected by the user is a public network and the domain name to be queried is a payment type domain name, the security requirement level of the user is relatively high; and if the network connected by the user is a trusted network and the domain name to be queried is a reading type domain name, the security requirement level of the user can be relatively low.
[0095] Specifically, a corresponding relationship between the network environment and the security requirement level can be established in advance, and then the security requirement level of the user is determined according to the corresponding relationship and the network environment of the user.
[0096] Specifically, a corresponding relationship between the type of the domain name to be queried and the security requirement level can be established in advance, and then the security requirement level of the user is determined according to the corresponding relationship and the type of the domain name to be queried.
[0097] Further, a corresponding relationship between the network environment, the type of the domain name to be queried and the security requirement level can be established in advance, and then the security requirement level of the user is determined according to the corresponding relationship and the network environment and the type of the domain name to be queried.
[0098] Step S204: Obtain a corresponding relationship table between the security requirement level and a verification mode.
[0099] Specifically, different security requirement levels correspond to different verification modes, and the higher the security requirement level is, the more rigorous and complex the verification mode is.
[0100] Further, a trust degree or a trust level can be set for each verification manner, such as a trust degree of 0.8 and a trust level of three for verification to an authoritative certification, a trust degree of 0.7 and a trust level of two for verification to an organization certification, a trust degree of 0.6 and a trust level of two for verification to a domain name holder certification, a trust degree of 1 and a trust level of seven for verification to the authoritative certification, the organization certification and the domain name holder certification, a trust degree of 0.95 and a trust level of six for verification to the authoritative certification and the organization certification, a trust degree of 0.92 and a trust level of five for verification to the authoritative certification and the domain name holder certification, and a trust degree of 0.9 and a trust level of four for verification to the organization certification and the domain name holder certification. Among them, the higher the trust degree or the higher the trust level, the more reliable the verification result corresponding to the verification manner. Of course, other verification manners and other trust degrees or trust levels for each verification manner can also be used.
[0101] For example, the correspondence between the security requirement level and the verification manner can be that when the security requirement level is one, the trust degree of the verification manner is required to be greater than 0.5; when the security requirement level is two, the trust degree of the verification manner is required to be greater than 0.6; when the security requirement level is three, the trust degree of the verification manner is required to be greater than 0.7; when the security requirement level is four, the trust degree of the verification manner is required to be greater than 0.8; when the security requirement level is five, the trust degree of the verification manner is required to be greater than 0.9; when the security requirement level is six, the trust degree of the verification manner is required to be greater than 0.92; and when the security requirement level is seven, the trust degree of the verification manner is required to be greater than 0.95. Thus, according to the requirement of the security requirement level on the trust degree, a set of verification manners that can be used is screened out, and one of them is selected for verification.
[0102] In step S205, the verification manner of the query record is determined according to the security requirement level and the correspondence table.
[0103] In step S206, the query record is verified based on the verification manner.
[0104] In step S207, if the verification is passed, the current domain name management node initiates the query record cache and obtains the verification results of the query record cache of each domain name management node.
[0105] Specifically, the domain name blockchain includes at least two domain name management nodes, and the current domain name management node is one of the nodes. For the domain name blockchain, when the current domain name management node performs the query record cache, each node of the domain name blockchain needs to verify the query record cache action, including verifying the query record and verifying whether the current domain name management node has the data cache permission.
[0106] Step S208, the current domain name management node determines whether the query record cache is qualified according to the verification results of the query record cache by the respective domain name management nodes.
[0107] Optionally, the current domain name management node determines whether the query record cache is qualified according to the verification results of the query record cache by the respective domain name management nodes, including:
[0108] The current domain name management node receives the verification results of the query record cache by the respective domain name management nodes, wherein the verification results include two kinds of verification pass and verification fail; and determines whether the query record cache is qualified according to a comparison result of a ratio of verification pass in the verification results and a preset threshold.
[0109] Specifically, the preset threshold can be 0.5, 0.6, 0.7 or other values.
[0110] Step S209, if qualified, the query record is cached in the domain name blockchain.
[0111] The domain name blockchain includes at least two domain name management nodes, and the current domain name management node is one of the nodes in the domain name blockchain.
[0112] Specifically, caching the query record in the domain name blockchain mainly includes the following steps: creating data shards, dividing the monitoring data into smaller fragments to obtain respective data shards; encrypting the respective data shards; generating a hash value for each data shard; copying each data shard and distributing the copied data shards.
[0113] Further, the method further includes:
[0114] When the query record is unqualified, the current domain name management node is deleted, and a new domain name management node is added.
[0115] In this embodiment, the security requirement level of the user is determined according to the network environment of the user and the type of the domain name to be queried, the verification mode of the query record of the domain name to be queried input by the user is determined according to the level, and the query record is securely verified based on the verification mode. After the verification is passed, the query record is stored in the blockchain, which realizes automatic determination of the security requirement level of the user based on the network environment and the input domain name, determines the corresponding verification mode based on the level, improves the accuracy and adaptability of domain name verification, stores the query record in the blockchain, effectively reduces the possibility of data tampering, and improves the credibility of the query record and the security of the user's online.
[0116] Figure 4is a flowchart of a domain name data processing method provided by another embodiment of the present application. The domain name data processing method can be executed by a client, such as a smart terminal, a tablet computer, a computer, etc. As shown in Figure 4 , the domain name data processing method includes the following steps:
[0117] In step S401, a user-inputted domain name to be queried is acquired.
[0118] In step S402, it is determined whether there is a query record of the domain name to be queried in a domain name blockchain.
[0119] In the embodiment shown in Figure 2 or Figure 3 , the query record caching method of the present application is provided in the domain name data processing method.
[0120] In step S403, if there is, the query record is returned.
[0121] Further, if there is a query record of the domain name to be queried in the domain name blockchain, the security requirement level of a user is acquired. If the query record meets the security requirement level of the user, the query record is returned. If not, the acquisition, verification and storage of the query record are performed again according to the security requirement level of the user and the domain name to be queried. The specific steps are similar to those mentioned in Figure 2 and Figure 3 , and thus will not be described here.
[0122] Figure 5 As shown in Figure 5 , the domain name data processing device provided by the present application includes a first domain name acquisition module 510, a query record acquisition module 520, a verification mode determination module 530 and a query record caching module 540.
[0123] The first domain name acquisition module 510 is configured to acquire a user-inputted domain name to be queried and a security requirement level of the user. The query record acquisition module 520 is configured to acquire a query record of the domain name to be queried. The verification mode determination module 530 is configured to determine a verification mode of the query record according to the security requirement level of the user. The query record caching module 540 is configured to verify the query record based on the verification mode, and cache the query record in a domain name blockchain if the verification is passed.
[0124] Optionally, the first domain name acquisition module 510 includes:
[0125] The first domain name acquisition unit is configured to acquire a domain name to be queried input by a user.
[0126] Optionally, the verification mode determination module 530 is specifically configured to:
[0127] acquire a correspondence table of the security requirement level and the verification mode; and determine the verification mode of the query record according to the security requirement level and the correspondence table.
[0128] Optionally, the domain name blockchain includes at least two domain name management nodes, and the query record cache module 540 includes:
[0129] The verification result acquisition unit is configured to initiate, by a current domain name management node, a query record cache, and acquire verification results of the query record cache by each domain name management node; the cache eligibility determination unit is configured to determine, by the current domain name management node, whether the query record cache is eligible according to the verification results of the query record cache by each domain name management node; and the query record cache unit is configured to cache the query record in the domain name blockchain if the query record cache is eligible.
[0130] Optionally, the cache eligibility determination unit is specifically configured to:
[0131] The current domain name management node receives the verification results of the query record cache by each domain name management node, wherein the verification results include two types of verification pass and verification fail; and the cache eligibility determination unit determines whether the query record cache is eligible according to a comparison result of a ratio of the verification pass in the verification results and a preset threshold.
[0132] Figure 6 A structural schematic diagram of a domain name data processing apparatus is provided for another embodiment of the present application, as shown in the figure, the domain name data processing apparatus includes a domain name service platform 610, a write-in mechanism module 620 and a blockchain 630. Figure 6
[0133] The domain name service platform 610 is configured to receive a domain name to be queried input by a user, and perform a query according to the domain name to be queried to generate a query record; the write-in mechanism module 620 is configured to determine a trust degree required by the query record according to a security requirement of the user for data, determine a write-in mechanism of the query record according to the trust degree, and perform a security verification on the query record according to the write-in mechanism; and the blockchain 630 is configured to write the query record in the blockchain if the security verification of the query record is passed.
[0134] Specifically, the user can query the domain name through the client app or webpage, that is, the user inputs the domain name to be queried in the client app or webpage for query, and the client app or webpage sends the domain name to be queried submitted by the user to the domain name service platform 610 for query. The domain name service platform 610 can query the DNS resource record of the domain name to the recursive server or the authoritative service. The authenticated DNS resource record (query record) is written into the blockchain 630 through the writing mechanism module 620, and the blockchain 630 is also used to send the query record to the user, thereby ensuring the security of the query result obtained by the user.
[0135] Further, when other users, such as user A, query the domain name to be queried again, if the query record of the domain name to be queried saved in the blockchain 630 meets the security requirement of user A for data, the query record in the blockchain 630 is directly returned, and if not, the query record needs to be verified and cached again based on the domain name service platform 610, the writing mechanism module 620 and the blockchain 630 according to the security requirement of user A for data, thereby ensuring the credibility of the returned query record.
[0136] Figure 7 The structure diagram of the domain name data processing apparatus provided by an embodiment of the present application is shown in Figure 7 The domain name data processing apparatus includes a second domain name acquisition module 710, a query record judgment module 720 and a query return module 730.
[0137] The second domain name acquisition module 710 is configured to acquire the domain name to be queried input by the user. The query record judgment module 720 is configured to judge whether the query record of the domain name to be queried exists in the domain name blockchain, wherein the cache method of the query record is the domain name data processing method provided by the first aspect of the present application. The query return module 730 is configured to return the query record if the query record of the domain name to be queried exists.
[0138] Further, the query return module 730 is specifically configured to acquire the security requirement level of the user if the query record of the domain name to be queried exists in the domain name blockchain, and return the query record if the query record meets the security requirement level of the user.
[0139] Further, the domain name data processing apparatus further includes:
[0140] The query verification module is configured to reacquire, verify and store the query record according to the security requirement level of the user and the domain name to be queried if the query record does not meet the security requirement level of the user, and the specific steps are similar to those mentioned in Figure 2 and Figure 3 and will not be described here again.
[0141] The domain name data processing apparatus provided by the embodiment can execute the technical solutions of the method embodiments as shown in the method embodiments, and the implementation principles and technical effects are similar, which will not be repeated here. Figures 2-4
[0142] Figure 8 The schematic diagram of the domain name server provided by one embodiment of the present application is shown in FIG. 8, and the domain name server provided by the embodiment includes a memory 810, a processor 820 and a computer program. Figure 8
[0143] The computer program is stored in the memory 810 and is configured to be executed by the processor 820 to implement the domain name data processing method provided by any one of the embodiments corresponding to the present application. Figures 2-4
[0144] The memory 810 and the processor 820 are connected through a bus 830.
[0145] The related description can be understood by referring to the related description and effects of the steps in Figures 2-4 , which will not be repeated here.
[0146] One embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the domain name data processing method provided by any one of the embodiments corresponding to the present application. Figures 2-4
[0147] The computer readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk and an optical data storage device, etc.
[0148] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are only schematic. The division of the modules is only a logical function division. There can be another division manner in actual implementation, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the modules shown or discussed can be indirect coupling or communication connection through some interfaces, devices or modules, and can be electrical, mechanical or in other forms.
[0149] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the specification and examples be considered as exemplary only, with a true scope and spirit of the application being indicated by the following claims.
[0150] It is to be understood that the application is not limited to the precise construction herein disclosed and shown in the drawings, and that various changes in shape, size and arrangements of parts can be made without departing from the scope of the application. The scope of the application is limited only by the claims that follow.
Claims
1. A method for processing domain name data, characterized in that, The method includes: Obtain the domain name to be queried input by the user, and determine the user's security requirement level based on the type of the domain name to be queried and the user's network environment; Obtain the query records for the domain name to be queried; The verification method for the query records is determined based on the user's security requirement level. The query record is verified based on the verification method. If the verification is successful, the query record is cached in the domain name blockchain, wherein the domain name blockchain includes at least two domain name management nodes. The step of caching the query record in the domain name blockchain includes: The current domain management node initiates a query record cache and obtains the verification results of each domain management node for the query record cache; The current domain name management node determines whether the query record cache is qualified based on the verification results of the query record cache by each domain name management node; If the query is successful, the query record will be cached in the domain name blockchain. If it is not qualified, the current domain name management node will be deleted and a new domain name management node will be added.
2. The method according to claim 1, characterized in that, The step of determining the verification method for the query record based on the user's security requirement level includes: Obtain the correspondence table between the security requirement level and the verification method; Based on the security requirement level and the corresponding relationship table, determine the verification method for the query record.
3. The method according to claim 2, characterized in that, The current domain name management node determines whether the query record cache is qualified based on the verification results of the query record cache by each domain name management node, including: The current domain name management node receives the verification results of the cached query records from each domain name management node, wherein the verification results include two types: verification passed and verification failed. Based on the comparison between the percentage of verified records that passed the verification and the preset threshold, it is determined whether the query record cache is qualified.
4. A method for processing domain name data, characterized in that, The method includes: Get the domain name to be queried by the user; Determine whether a query record for the domain name to be queried exists in the domain name blockchain, wherein the caching method for the query record is the domain name data processing method according to any one of claims 1-3; If it exists, return the queried record.
5. A domain name data processing apparatus, characterized in that, The device includes: The first domain name acquisition module is used to acquire the domain name to be queried input by the user, and determine the user's security requirement level based on the type of the domain name to be queried and the user's network environment. The query record acquisition module is used to acquire the query records of the domain name to be queried; The verification method determination module is used to determine the verification method for the query record based on the user's security requirement level. The query record caching module is used to verify the query record based on the verification method. If the verification is successful, the query record is cached in the domain name blockchain, wherein the domain name blockchain includes at least two domain name management nodes. The query record caching module is also used to initiate query record caching by the current domain name management node and obtain the verification results of each domain name management node for the query record cache; the current domain name management node determines whether the query record cache is qualified based on the verification results of each domain name management node for the query record cache; if qualified, the query record is cached in the domain name blockchain; if unqualified, the current domain name management node is deleted and a new domain name management node is added.
6. A domain name data processing apparatus, characterized in that, The device includes: The second domain name acquisition module is used to obtain the domain name to be queried by the user; The query record determination module is used to determine whether there is a query record for the domain name to be queried in the domain name blockchain, wherein the caching method for the query record is the domain name data processing method according to any one of claims 1-3; The query return module is used to return the query record if a query record for the domain name to be queried exists.
7. A domain name server, characterized in that, include: Memory, processor, and computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the domain name data processing method as described in any one of claims 1-3.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the domain name data processing method as described in any one of claims 1 to 3.
9. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the method for processing domain name data as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Query request service method for DNS (Domain Name System) recursive server
CN103685168A
NDN security authentication method based on DANE
CN104410635A