A server selection method and device

The terminal device sends DNS encryption capability information to the first network element and selects a matching DNS server, which solves the problem of strong dependence on encryption DNS configuration in the prior art, and achieves more secure and stable network access.

CN114286335BActive Publication Date: 2025-06-17HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010979627.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-17
Publication Date
2025-06-17
Estimated Expiration
2040-09-17

AI Technical Summary

Technical Problem

When the existing mobile terminals turn on the encrypted DNS mechanism, they rely on user manual configuration, which leads to a long time for DNS resolution and slow Internet access, which may even lead to failure of DNS server authentication and inability to access the Internet.

Method used

A server selection method is provided, through the terminal device, the supported DNS encryption capability information is sent to the first network element, and the first network element selects a matching DNS server based on the information, and the terminal device can initiate a DNS query to the selected DNS server.

Benefits of technology

By automatically selecting the appropriate DNS server, the security and stability of the network are improved, the dependence of manual configuration of users is avoided, and the security and resolution of users' access to the Internet are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114286335B_ABST
    Figure CN114286335B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a server selection method and device, which relates to the field of wireless communication technologies and is used to select a suitable DNS server for a terminal device to provide a secure and stable network experience. In this method, the terminal device may send first information to a first network element. The terminal device may receive the address of the DNS server sent by the first network element. Among them, the DNS server may be determined by the first network element according to the first information. Based on the above solution, the first network element may select a DNS server that matches the DNS encryption capability according to the DNS encryption capability supported by the terminal device, and the terminal device may initiate a DNS query to the DNS server selected by the first network element. Since the selection of the DNS server does not depend on manual configuration by the user and is selected by the first network element according to the DNS encryption capability of the terminal device, it is more suitable for the terminal device and can provide a secure and stable network experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technologies, and in particular, to a server selection method and apparatus. Background Art

[0002] With the continuous growth of the number of mobile terminal users, the service functions supported by various mobile terminals are constantly increasing. For example, functions such as instant messaging tools, web browsing, and file downloading have gradually become the mainstream applications of mobile terminals, especially smart terminals. During the process of accessing the Internet, a mobile terminal needs to query the real Internet Protocol (IP) address of the domain name of the Uniform Resource Locator (URL) in order to send data packets. This operation needs to be completed by querying a Domain Name System (DNS) server.

[0003] DNS is a distributed host information database that provides mapping and conversion between domain names and IP addresses, and can resolve a domain name into the corresponding IP address through a DNS server. A user device can achieve access to a domain name through the domain name resolution service provided by DNS.

[0004] Traditional DNS queries and responses use the User Datagram Protocol (UDP) and the Transmission Control Protocol (TCP) for plaintext transmission, which poses risks such as network eavesdropping, DNS hijacking, and interference from intermediate devices. Encrypted DNS is a mechanism to achieve secure transmission and can ensure a secure network experience. DNS Secure Transmission Service can be applied to multiple scenarios such as mobile applications, browsers, operating systems, Internet of Things devices, and gateway routers. By sending DNS queries in an encrypted manner, the security, resolution stability, and privacy protection of user access to the Internet are enhanced.

[0005] However, currently, when a mobile terminal enables the encrypted DNS mechanism, it depends on manual configuration by the user. If the DNS encryption mode manually configured by the user is different from the DNS encryption mode providing services to the mobile terminal, it may lead to a longer DNS resolution time, slow Internet access, and even possible DNS server authentication failure and inability to access the Internet. Summary of the Invention

[0006] This application provides a server selection method and apparatus for selecting a suitable DNS server for a terminal device to provide a secure and stable network experience.

[0007] In a first aspect, an embodiment of the present application provides a server selection method. This method can be executed by a terminal device or by a chip similar to a terminal device. In this method, the terminal device can send first information to a first network element. Here, the first information can be used to indicate the domain name system (DNS) encryption capability supported by the terminal device. The DNS encryption capability supported by the terminal device can be the capability of the terminal device to encrypt DNS information. For example, it can include that the terminal device supports encrypting DNS information or the terminal device does not support encrypting DNS information. The terminal device can receive the address of the DNS server sent by the first network element. The DNS server can be determined by the first network element according to the first information.

[0008] Based on the above solution, the first network element can select a DNS server that matches the DNS encryption capability for the terminal device according to the DNS encryption capability supported by the terminal device. The terminal device can initiate a DNS query to the DNS server selected by the first network element. Since the selection of the DNS server does not depend on manual configuration by the user and is selected by the first network element according to the DNS encryption capability of the terminal device, it is more suitable for the terminal device and can provide a secure and stable network experience.

[0009] In a possible implementation, the terminal device can send second information to the first network element. The second information can be used to indicate the mode of DNS encrypted transmission adopted by the terminal device. The mode of DNS encrypted transmission can be the DNS encrypted transmission on mode or the DNS encrypted transmission off mode.

[0010] Based on the above solution, the first network element can also select a DNS server for the terminal device according to the mode of DNS encrypted transmission of the terminal device. The selected DNS server is suitable for the DNS encrypted transmission mode of the terminal device, which can improve the stability of the network.

[0011] In a possible implementation, the DNS encryption capability can include the supported DNS encryption protocol. The DNS encryption protocol can include at least one of the following: transport layer security protocol (TLS) or hypertext transfer protocol (HTTP).

[0012] Based on the above solution, the first network element can select a DNS server that supports HTTP or TLS for the terminal device, which matches the type of DNS encryption protocol supported by the terminal device, and can improve the security and stability of the network.

[0013] In a possible implementation, the terminal device may receive third information sent by the first network element. The third information here may be used to indicate that the encryption capability of the DNS server matches the DNS encryption capability supported by the terminal device indicated by the foregoing first information.

[0014] Based on the above solution, the terminal device may determine whether the DNS encryption capability of the DNS server selected by the first network element matches its own through the third information, and the terminal device may also determine whether to initiate a DNS query through the DNS server according to the third information.

[0015] In a possible implementation, the terminal device may receive fourth information sent by the first network element. The fourth information may be used to indicate the type of DNS encryption protocol that matches the DNS encryption capabilities supported by the DNS server and the terminal device. The terminal device may initiate a DNS query to the DNS server according to the type of DNS encryption protocol supported by the DNS server. Among them, the terminal device may support the type of DNS encryption protocol supported by the DNS server.

[0016] Based on the above solution, the terminal device may determine whether the DNS encryption protocol type of the DNS server selected by the first network element matches its own through the fourth information, and the terminal device may also determine whether to initiate a DNS query through the DNS server according to the fourth information.

[0017] In a second aspect, a method for selecting a server is provided. This method may be executed by the first network element provided in the embodiments of the present application. The first network element may be an edge configuration server, or may be a network element in the core network. For example, a session management function network element or a policy control function network element. In this method, the first network element may receive first information. The first information here may be used to determine the DNS encryption capability supported by the terminal device. The DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information. The first network element may determine a first DNS server that provides DNS queries for the terminal device according to the first information, and the first network element may send the address of the first DNS server.

[0018] Based on the above solution, the first network element may select a DNS server with a matching DNS encryption capability for the terminal device according to the DNS encryption capability supported by the terminal device, and the terminal device may initiate a DNS query to the DNS server selected by the first network element. Since the selection of the DNS server does not depend on manual configuration by the user and is selected by the first network element according to the DNS encryption capability of the terminal device, it is more suitable for the terminal device and can provide a secure and stable network experience.

[0019] In a possible implementation, the first network element may receive second information. The second information here may be used to indicate the DNS encryption transmission mode adopted by the terminal device. Among them, the DNS encryption transmission mode may be a DNS encryption transmission enabled mode or a DNS encryption transmission disabled mode. The first network element may determine a first DNS server that provides DNS queries for the terminal device according to the first information and the second information.

[0020] Based on the above solution, the first network element may also select a DNS server for the terminal device according to the DNS encryption transmission mode of the terminal device. The selected DNS server is suitable for the DNS encryption transmission mode of the terminal device, which can improve the stability of the network.

[0021] In a possible implementation, the DNS encryption capability includes supported DNS encryption protocols. Among them, the DNS encryption protocol may include at least one of the following: TLS or HTTP.

[0022] Based on the above solution, the first network element may select a DNS server that supports HTTP or TLS for the terminal device, which matches the type of DNS encryption protocol supported by the terminal device, and can improve the security and stability of the network.

[0023] In a possible implementation, the first network element may send third information. The third information may be used to indicate that the encryption capability of the DNS server matches the DNS encryption capability supported by the terminal device indicated by the first information.

[0024] Based on the above solution, the terminal device may determine whether the DNS encryption capability of the DNS server selected by the first network element matches itself through the third information.

[0025] In a possible implementation, the first network element may send fourth information. The fourth information here may be used to indicate the type of DNS encryption protocol that matches the DNS encryption capabilities supported by the DNS server and the terminal device.

[0026] Based on the above solution, the terminal device may determine whether the type of DNS encryption protocol of the DNS server selected by the first network element matches itself through the fourth information.

[0027] In a third aspect, a server selection method is provided. This method can be executed by a terminal device or a chip with similar terminal device functions. In this method, the terminal device can send the operating system identification information of the terminal device to a first network element. The operating system identification information can be used to determine the DNS encryption capability supported by the terminal device, and the DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information. The terminal device can receive the address of the DNS server sent by the first network element. The DNS server is determined by the first network element according to the operating system identification information.

[0028] Based on the above solution, the first network element can determine a DNS server for the terminal device according to the operating system identification information of the terminal device. Therefore, the selected DNS server is more suitable for the terminal device, and the stability of the network during DNS queries can be improved.

[0029] In a possible implementation, the DNS encryption capability can include the supported DNS encryption protocol, and the DNS encryption protocol can include at least one of the following: TLS or HTTP.

[0030] Based on the above solution, the first network element can select a DNS server that supports HTTP or TLS for the terminal device, which matches the type of DNS encryption protocol supported by the terminal device, and can improve the security and stability of the network.

[0031] In a fourth aspect, an embodiment of the present application provides a server selection method. This method can be executed by the first network element provided in the embodiment of the present application. The first network element can be an edge configuration server, or can be a network element in the core network. For example, a session management function network element or a policy control function network element. In this method, the first network element can receive the operating system identification information of the terminal device from the terminal device. The first network element is configured with a DNS encryption capability corresponding to the operating system identification information of the terminal device. The first network element can determine the DNS encryption capability supported by the terminal device according to the operating system identification information of the terminal device. The DNS encryption capability supported by the terminal device can be the capability of the terminal device to encrypt DNS information. The first network element can determine a first DNS server for providing DNS queries for the terminal device according to the DNS encryption capability supported by the terminal device, and can send the address of the first DNS server.

[0032] Based on the above solution, the first network element can determine a DNS server for the terminal device according to the operating system identification information of the terminal device. Therefore, the selected DNS server is more suitable for the terminal device, and the stability of the network during DNS queries can be improved.

[0033] In a possible implementation, the DNS encryption capability may include supported DNS encryption protocols, and the DNS encryption protocols may include at least one of the following: TLS or HTTP.

[0034] Based on the above solution, the first network element can select a DNS server that supports HTTP or TLS for the terminal device, which matches the type of DNS encryption protocol supported by the terminal device, and can improve the security and stability of the network.

[0035] In a fifth aspect, an embodiment of the present application provides a method for selecting a server. This method can be executed by a terminal device or a chip similar to the function of the terminal device. In this method, the terminal device can receive the encryption capability information of at least one DNS server from the first network element. The terminal device can determine a first DNS server from at least one DNS server according to the encryption capability information of at least one DNS server. Among them, the encryption capability of the first DNS server matches the encryption capability supported by the terminal device, and the DNS encryption capability supported by the terminal device is the ability of the terminal device to encrypt DNS information. The terminal device can initiate a DNS query to the first DNS server.

[0036] Based on the above solution, the terminal device can select a DNS server with a DNS encryption capability matching its own from at least one DNS server sent by the first network element to initiate a DNS query, improving the stability of the network during DNS query.

[0037] In a possible implementation, the DNS encryption capability may include supported DNS encryption protocols, and the DNS encryption protocols may include at least one of the following: TLS or HTTP.

[0038] Based on the above solution, the terminal device can select a DNS server that matches the type of DNS encryption protocol supported by itself from at least one DNS server, which can improve the security and stability of the network.

[0039] In a sixth aspect, a method for selecting a server is provided. This method can be executed by the first network element provided in the embodiment of the present application. The first network element may be an edge configuration server, or may be a network element in the core network. For example, a session management function network element or a policy control function network element. In this method, the first network element can determine the encryption capability information of at least one DNS server. Among them, the encryption capability information of at least one DNS server includes the ability of at least one DNS server to encrypt DNS information. The first network element can send the at least one DNS encryption capability to the terminal device.

[0040] Based on the above solution, the terminal device can select a DNS server with a DNS encryption capability matching itself from at least one DNS server sent by the first network element to initiate a DNS query, improving the network stability during DNS query.

[0041] In a possible implementation, the DNS encryption capability may include the supported DNS encryption protocol, and the DNS encryption protocol may include at least one of the following: TLS or HTTP.

[0042] Based on the above solution, the terminal device can select a DNS server matching the type of DNS encryption protocol supported by itself from at least one DNS server, which can improve the network security and stability.

[0043] In a seventh aspect, a server selection device is provided. The communication device may include each module / unit for executing the methods in the first aspect or any possible implementation of the first aspect, or may further include each module / unit for executing the methods in the second aspect or any possible implementation of the second aspect, or may further include each module / unit for executing the methods in the third aspect or any possible implementation of the third aspect, or may further include each module / unit for executing the methods in the fourth aspect or any possible implementation of the fourth aspect, or may further include each module / unit for executing the methods in the fifth aspect or any possible implementation of the fifth aspect, or may further include each module / unit for executing the methods in the sixth aspect or any possible implementation of the sixth aspect. For example, a communication unit and a processing unit.

[0044] In an eighth aspect, a communication device is provided. The communication device includes a processor and a memory. The memory is used to store computer execution instructions. When the controller runs, the processor executes the computer execution instructions in the memory to execute the operation steps of the methods in the first aspect or any possible implementation of the first aspect, or execute the operation steps of the methods in the second aspect or any possible implementation of the second aspect, or execute the operation steps of the methods in the third aspect or any possible implementation of the third aspect, or execute the operation steps of the methods in the fourth aspect or any possible implementation of the fourth aspect, or execute the operation steps of the methods in the fifth aspect or any possible implementation of the fifth aspect, or execute the operation steps of the methods in the sixth aspect or any possible implementation of the sixth aspect.

[0045] In a ninth aspect, the present application provides a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When it runs on a computer, it causes the computer to execute the methods in the above aspects.

[0046] In a tenth aspect, the present application provides a computer program product for storing instructions, which, when running on a computer, causes the computer to execute the methods in the above aspects.

[0047] In an eleventh aspect, the present application provides a communication system, which may include at least one network device. The at least one network device may be used to execute each step performed by the first network element above. Optionally, the communication system may further include at least one terminal device. The at least one terminal device may be used to execute each step performed by the terminal device above.

[0048] In addition, the beneficial effects of the seventh to eleventh aspects may be the same as those shown in the first to sixth aspects, which will not be elaborated here. Description of the Drawings

[0049] Figure 1 is one of the schematic diagrams of the communication system provided by the embodiment of the present application;

[0050] Figure 2 is one of the schematic diagrams of the communication system provided by the embodiment of the present application;

[0051] Figure 3 is one of the schematic diagrams of the communication system provided by the embodiment of the present application;

[0052] Figure 4 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0053] Figure 5 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0054] Figure 6 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0055] Figure 7 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0056] Figure 8 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0057] Figure 9 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0058] Figure 10 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0059] Figure 11 is one of the exemplary flowcharts of the server selection method provided by the embodiment of the present application;

[0060] Figure 12 One of the schematic diagrams of the server selection device provided by the embodiment of the present application;

[0061] Figure 13 One of the schematic diagrams of the terminal device provided by the embodiment of the present application;

[0062] Figure 14 One of the schematic diagrams of the server selection device provided by the embodiment of the present application;

[0063] Figure 15 The block diagram of the server selection device provided by the embodiment of the present application. Detailed implementation manners

[0064] Hereinafter, some terms in the embodiments of the present application are explained to facilitate the understanding of those skilled in the art.

[0065] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "Multiple" means two or more, and other quantifiers are similar. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, for elements where the singular forms "a", "an", and "the" appear, unless otherwise clearly specified in the context, they do not mean "one or only one", but mean "one or more than one". For example, "a device" means one or more such devices. Furthermore, "at least one of..." means one or any combination of the subsequent associated objects. For example, "at least one of A, B, and C" includes A, B, C, AB, AC, BC, or ABC.

[0066] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, Worldwide Interoperability for Microwave Access (WiMAX) communication systems, future 5th Generation (5G) systems, such as New Radio Access Technology (NR), and future communication systems, such as 6G systems, etc.

[0067] Aspects, embodiments or features of the present application will be presented in the context of a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in connection with the figures. In addition, combinations of these solutions may also be used.

[0068] The network architecture and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art will know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0069] To facilitate the understanding of the embodiments of the present application, first, a communication system shown in Figure 1 and Figure 2 will be used as an example to detail the communication system applicable to the embodiments of the present application. Figure 1 and Figure 2 show schematic diagrams of a communication system for a communication method applicable to the embodiments of the present application. As shown in Figure 1 and Figure 2 , the communication system 100 includes an Authentication Server Function (AUSF) network element, a network exposure function (NEF) network element, a policy control function (PCF) network element, a unified data management (UDM) network element, a Unified Data Repository (UDR), a Network Repository Function (NRF) network element, an application function (AF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, a radio access network (RAN), and a user plane function (UPF) network element. Among them, Figure 1 the interfaces between the network elements shown in Figure 2 are service-based interfaces, and

[0070] The functions of each network element or device in the communication system according to the embodiments of the present application are described in detail below:

[0071] The terminal device, also known as user equipment (UE), mobile station (MS), mobile terminal (MT), etc., is a device that provides voice and / or data connectivity to users. For example, the terminal device may include a handheld device with wireless connection capabilities, a vehicle-mounted device, etc. Specifically, it includes a device that provides voice to users, or a device that provides data connectivity to users, or a device that provides both voice and data connectivity to users. For example, it may include a handheld device with wireless connection capabilities, or a processing device connected to a wireless modem. The terminal can communicate with the core network via a radio access network (RAN), exchange voice or data with the RAN, or interact with the RAN for both voice and data. The terminal may include user equipment (UE), wireless terminal, mobile terminal, device-to-device (D2D) terminal, vehicle-to-everything (V2X) terminal, machine-to-machine / machine-type communications (M2M / MTC) terminal, Internet of Things (IoT) terminal, subscriber unit, subscriber station, mobile station, remote station, access point (AP), remote terminal, access terminal, user terminal, user agent, or user device, etc. For example, it may include a mobile phone (or "cellular" phone), a computer with a mobile terminal, a portable, pocket-sized, handheld, or computer-integrated mobile device, etc. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDA), etc. It also includes restricted devices, such as devices with low power consumption, or devices with limited storage capacity, or devices with limited computing capacity, etc.For example, it includes information sensing devices such as barcodes, radiofrequency identification (RFID), sensors, global positioning system (GPS), laser scanners, etc.

[0072] In the embodiments of the present application, the device for implementing the functions of a network device may be a network device or a device capable of supporting the network device to implement such functions, such as a chip system, and this device may be installed in the network device. In the technical solutions provided in the embodiments of the present application, taking the device for implementing the functions of a network device as a network device as an example, the technical solutions provided in the embodiments of the present application are described.

[0073] As an example rather than a limitation, in the embodiments of the present application, the terminal may also be a wearable device. Wearable devices can also be referred to as wearable intelligent devices or intelligent wearable devices, etc. It is a general term for devices developed by applying wearable technology to the intelligent design of daily wear, such as glasses, gloves, watches, clothing, shoes, etc. Wearable devices are portable devices that are directly worn on the body or integrated into the user's clothes or accessories. Wearable devices are not only a kind of hardware device, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable intelligent devices include those with complete functions and large sizes that can achieve complete or partial functions without relying on a smart phone, such as smart watches or smart glasses, etc., and those that only focus on a certain type of application function and need to cooperate with other devices such as smart phones, such as various smart bracelets for physical sign monitoring, smart helmets, smart jewelry, etc.

[0074] For various terminals introduced above, if they are located on a vehicle (for example, placed inside or installed inside the vehicle), they can all be considered in-vehicle terminals. In-vehicle terminals are also called on-board units (OBUs) for example.

[0075] In the embodiments of the present application, the device for implementing the functions of a terminal may be a terminal or a device capable of supporting the terminal to implement such functions, such as a chip system, and this device may be installed in the terminal. In the embodiments of the present application, the chip system may be composed of chips or may also include chips and other discrete devices. In the technical solutions provided in the embodiments of the present application, taking the device for implementing the functions of a terminal as a terminal as an example, the technical solutions provided in the embodiments of the present application are described.

[0076] Next, the Figure 1 and Figure 2 individual network elements are introduced.

[0077] The access and mobility management function network element AMF can be used to manage the access control and mobility of the terminal device. In practical applications, it includes the mobility management function in the mobility management entity (MME) in the network framework of Long-Term Evolution (LTE), and adds an access management function. Specifically, it can be responsible for the registration of the terminal device, mobility management, tracking area update process, reachability detection, selection of session management function network elements, mobile state transition management, etc. For example, in 5G, the core network access and mobility management function network element can be an AMF (access and mobility management function) network element, such as Figure 1 and Figure 2 shown, in future communications, such as 6G, the core network access and mobility management function network element can still be an AMF network element, or have other names, which are not limited in this application. When the core network access and mobility management function network element is an AMF network element, the AMF can provide Namf services.

[0078] The session management function network element SMF can be used to be responsible for the session management of the terminal device (including the establishment, modification, and release of sessions), selection and reselection of user plane function network elements, allocation of Internet Protocol (IP) addresses for the terminal device, Quality of Service (QoS) control, etc. For example, in 5G, the session management function network element can be an SMF (session management function) network element, such as Figure 1 and Figure 2 shown, in future communications, such as 6G, the session management function network element can still be an SMF network element, or have other names, which are not limited in this application. When the session management function network element is an SMF network element, the SMF can provide Nsmf services.

[0079] The policy control function network element PCF can be used to be responsible for policy control decisions, provide functions such as service data flow and application detection, gating, QoS, and flow-based charging control, etc. For example, in 5G, the policy control function network element can be a PCF (policy control function) network element, such as Figure 1 and Figure 2 shown, in future communications, such as 6G, the policy control function network element can still be a PCF network element, or have other names, which are not limited in this application. When the policy control function network element is a PCF network element, the PCF network element can provide Npcf services.

[0080] The Application Function network element AF mainly interacts with the core network of the 3rd generation partnership project (3GPP) to provide services, influencing service flow routing, access network capability opening, policy control, etc. For example, in 5G, the Application Function network element can be the AF network element, such as Figure 1 and Figure 2 As shown, in future communications such as 6G, the Application Function network element can still be the AF network element, or have other names, which are not limited in this application. When the Application Function network element is the AF network element, the AF network element can provide Naf services.

[0081] The Unified Data Management network element UDM can be used to manage the subscription data of the terminal device, registration information related to the terminal device, etc. For example, in 5G, the data management network element can be the Unified Data Management network element (UDM), such as Figure 1 and Figure 2 As shown, in future communications such as 6G, the data management network element can still be the UDM network element, or have other names, which are not limited in this application. When the data management network element is the UDM network element, the UDM network element can provide Nudm services.

[0082] The Network Exposure Function network element NEF can be used to enable 3GPP to securely provide network service capabilities to third-party AFs (such as Services Capability Server (SCS), Application Server (AS), etc.). For example, in 5G, the Network Exposure Function network element can be NEF, such as Figure 1 and Figure 2 As shown, in future communications such as 6G, the Network Exposure Function network element can still be the NEF network element, or have other names, which are not limited in this application. When the Network Exposure Function network element is NEF, NEF can provide Nnef services to other network function network elements.

[0083] Therefore, the Unified Data Repository network element UDR can be used to store and retrieve subscription data, policy data, common architecture data, etc.; for UDM, PCF, and NEF to obtain relevant data. UDR should be able to have different data access authentication mechanisms for different types of data such as subscription data and policy data to ensure the security of data access; UDR should be able to return a failure response with an appropriate cause value for illegal service-oriented operations or data access requests. For example, in 5G, the Unified Data Repository network element can be UDR, such as Figure 1and Figure 2 As shown in Figure 2 , in future communications such as 6G, the unified data repository functional network element may still be a UDR network element or have other names, which are not limited in this application.

[0084] The user plane function network element UPF can be used to interconnect a PDU session with a data network, perform packet routing and forwarding (for example, support forwarding traffic to a data network after an Uplink classifier, support a Branching point to support a multi-homed PDU session), perform packet detection, etc. For example, in 5G, the user plane function network element may be a UPF, for example Figure 1 and Figure 2 As shown in Figure 2 , in future communications such as 6G, the user plane function network element may still be a UPF network element or have other names, which are not limited in this application.

[0085] Refer to Figure 3 , Figure 3 Figure 3 is the system architecture applicable to the server selection method provided in the embodiments of this application. In this system, it may include a terminal device, a radio access network, a user plane function network element, and a DNS server. The terminal device can be communicatively connected to the radio access network. When the terminal device accesses a domain name, if the IP address corresponding to the domain name to be accessed does not exist in the cache record stored by the terminal device, the terminal device can initiate a domain name resolution request to the DNS server through the radio access network. The domain name resolution request can carry the domain name that the terminal device wants to access, and the DNS server returns the IP address corresponding to the domain name, and the terminal device can access the corresponding domain name through this IP address. And the DNS server here can be selected by the core network (such as the user plane function network element) for the terminal device.

[0086] Since traditional DNS queries and responses use the User Datagram Protocol (UDP) and the Transmission Control Protocol (TCP) for plaintext transmission, there are risks of network eavesdropping, DNS hijacking, and interference from intermediate devices. Encrypted DNS is a mechanism to achieve transmission security and can ensure network experience security. DNS Secure Transmission Service can be applied to multiple scenarios such as mobile applications, browsers, operating systems, Internet of Things devices, and gateway routers. By sending DNS queries in an encrypted manner, it enhances the security of user access to the Internet, parsing stability, and privacy protection.

[0087] When the current mobile terminal enables the encrypted DNS mechanism, it relies on manual configuration by the user. If the DNS encryption mode manually configured by the user is different from the DNS encryption mode provided for the mobile terminal, it may result in a longer DNS resolution time, slow Internet access, and even possible DNS server authentication failure and inability to access the Internet.

[0088] Based on the above requirements, an embodiment of the present application provides a server selection method. Refer to Figure 4 , which is an exemplary flowchart of the server selection method shown from the perspective of device interaction, and may include the following steps:

[0089] Step 401: The terminal device sends a first piece of information to the first network element, and the first network element receives the first piece of information.

[0090] The first piece of information here can be used to indicate the DNS encryption capabilities supported by the terminal device. Among them, the DNS encryption capabilities supported by the terminal device can be the capabilities of the terminal device to encrypt DNS information. For example, the terminal device supports encrypting DNS information, or the terminal device does not support encrypting DNS information. Optionally, the first piece of information can also indicate the DNS decryption capabilities of the terminal device. For example, the terminal device supports decrypting encrypted DNS information, or the terminal device does not support decrypting encrypted DNS information.

[0091] It should be noted that in the embodiment of the present application, the meaning of the terminal device encrypting DNS information refers to the terminal device encrypting DNS information; among them, the DNS information here can be the information included in the uplink DNS query message sent by the terminal device to the DNS server, which is not limited in the embodiment of the present application. For example, the DNS information can be the domain name requested by the terminal device to query, the source IP address of the terminal device, etc. included in the uplink DNS query message. It can be understood that the terminal device determines the DNS information and encrypts the DNS information before sending the uplink DNS query message.

[0092] It should be noted that in the embodiments of this application, the meaning of the terminal device decrypting the encrypted DNS information refers to the terminal device decrypting the DNS information. Herein, the encrypted DNS information may be the information included in the downlink DNS response message received by the terminal device from the DNS server, which is not limited in the embodiments of this application. For example, the encrypted DNS information may be the domain name requested by the terminal device included in the downlink DNS response message, the IP address of the application server corresponding to the domain name, and so on. It can be understood that the terminal device receives the downlink DNS response message, determines the encrypted DNS information included in the downlink DNS response message, and decrypts the encrypted DNS information. Additionally, it should be noted that the first information may be used to indicate the DNS encryption capability supported by the terminal device, or may be used by the first network element to determine the DNS encryption capability supported by the terminal device. Hereinafter, the first information will be explained in two cases respectively.

[0093] Case 1: The first information is used to indicate the DNS encryption capability supported by the terminal device.

[0094] In one implementation, the DNS encryption capability may be the capability of the terminal device to encrypt DNS information. Exemplarily, the capability of the terminal device to encrypt DNS information may be represented by the cell UE’s Encryption DNScapability. Optionally, the first information may further include the DNS encryption protocol supported by the terminal device. For example, if the first information indicates that the terminal device supports encrypting DNS information, the first information may further include the DNS encryption protocols available to the terminal device. Such as, the Transport Layer Security protocol and / or the Hypertext Transfer Protocol. The DNS encryption protocol supported by the terminal device here may refer to the protocol that the terminal device can adopt when encrypting DNS information, and the protocol through which the terminal device can decrypt the encrypted DNS information.

[0095] In another implementation, the DNS encryption capability may be the DNS encryption protocol supported by the terminal device. It can be understood that since the terminal device supports the DNS encryption protocol, then the terminal device has the capability to encrypt DNS information using the DNS encryption protocol. The DNS encryption protocol supported by the terminal device, for example, the Transport Layer Security protocol and / or the Hypertext Transfer Protocol. The DNS encryption protocol supported by the terminal device here may refer to the protocol that the terminal device can adopt when encrypting DNS information, and the protocol through which the terminal device can decrypt the encrypted DNS information. It should be noted that if the terminal device does not support the DNS encryption capability, then the first information that the terminal device can send to the first network element may be a null value, or the terminal device does not send the first information to the first network element (i.e., step 401 does not carry the first information), which is not limited in the embodiments of this application.

[0096] Optionally, the first information may also indicate the DNS encryption transmission mode adopted by the terminal device. For example, the terminal device supports encrypting DNS information, but the terminal device has not enabled the DNS encryption capability. In other words, the terminal device has disabled the capability to encrypt DNS information. Therefore, the terminal device cannot encrypt DNS information, nor can it decrypt encrypted DNS information. Or, the terminal device supports encrypting DNS information, and the terminal device has enabled the DNS encryption capability, that is, the terminal device has enabled the capability to encrypt DNS information. Therefore, the terminal device can encrypt DNS information and can also decrypt encrypted DNS information.

[0097] In another example, the terminal device may also send second information to the first network element. Here, the second information can be used to indicate the DNS encryption transmission mode adopted by the terminal device. For example, the terminal device has enabled the DNS encryption transmission mode, that is, the terminal device supports encrypting DNS information. Similarly, the terminal device also supports decrypting encrypted DNS information. Or, the terminal device has disabled the DNS encryption transmission mode, that is, the terminal device does not support encrypting DNS information. Similarly, the terminal device also does not support decrypting encrypted DNS information.

[0098] Case 2: The first information is used by the first network element to determine the DNS encryption capability supported by the terminal device.

[0099] The first information here may be the operating system identification information of the terminal device. For example, the international mobile equipment identity (IMEI). The IMEI is used to uniquely identify a device model, and the type of the terminal device (such as a smart phone, a feature phone, or a data card), the name of the operating system of the terminal device, the brand name of the terminal device, the model of the terminal device, etc. can be read. The first network element can determine the name of the operating system of the terminal device from the IMEI, and thus can determine the operating system identification of the terminal device. Or, the first information may also be the operating system identity (OS ID).

[0100] Step 402: The first network element determines a first DNS server for providing DNS queries for the terminal device according to the first information.

[0101] The first network element here can be a Session Management Function (SMF), a Policy Control Function (PCF), or it can also be an Edge Configuration Server. The Edge Configuration Server here can store mobile data network configuration information and send the mobile data network configuration information to an Edge Enabler Client, where the Edge Enabler Client is located on a terminal device and is used for the terminal device to discover the IP address of an edge application. The Edge Configuration Server can be deployed by an operator or a third party, and the embodiments of the present application do not make any limitations.

[0102] Among them, the first network element can determine the DNS encryption capability of the terminal device according to the first information, and then determine the first DNS server that provides DNS queries for the terminal device. It should be noted that due to the difference in the first information, the first network element determines the first DNS server in different ways, which will be specifically introduced below.

[0103] Method 1: The first information is used to indicate the DNS encryption capability supported by the terminal device.

[0104] One implementation method is that the first network element can locally configure or obtain from other network elements the DNS encryption capability corresponding to each DNS server deployed in the network. Among them, the DNS encryption capability corresponding to the DNS server can be the capability of the DNS server to encrypt DNS information and / or the capability of the DNS server to decrypt DNS information. For example, the DNS server supports encrypting DNS information, or the DNS server does not support encrypting DNS information. The DNS server supports decrypting encrypted DNS information, or the DNS server does not support decrypting encrypted DNS information. Exemplarily, the capability of the DNS server to encrypt DNS information can be represented by the cell DNS server’s Encryption DNS capability.

[0105] It should be noted that in the embodiments of the present application, the meaning of the DNS server encrypting DNS information refers to the DNS server encrypting DNS information; among them, the DNS information can be the information included in the downlink DNS response message sent by the DNS server to the terminal device, and the embodiments of the present application do not make any limitations. For example, the encrypted DNS information can be the domain name requested by the terminal device included in the downlink DNS response message, the IP address of the application server corresponding to the domain name, etc. It can be understood that the DNS server determines the DNS information, encrypts the DNS information, and then sends the downlink DNS response message to the terminal device.

[0106] It should be noted that in the embodiments of the present application, the meaning of the DNS server decrypting the encrypted DNS information refers to the DNS server decrypting the DNS information. Among them, the encrypted DNS information may be the information included in the upstream DNS query message, which is not limited in the embodiments of the present application. For example, the encrypted DNS information may be the domain name requested by the terminal device included in the upstream DNS query message, the source IP address of the terminal device, and so on. It can be understood that the DNS server receives the upstream DNS query message, determines the encrypted DNS information included in the upstream DNS query message, and decrypts the encrypted DNS information.

[0107] In addition, if the DNS server supports encrypting DNS information, the first network element may also indicate the type of DNS encryption protocol supported by the DNS server. Such as, the Transport Layer Security protocol and / or the Hypertext Transfer Protocol, etc.

[0108] The first network element may store the correspondence between the DNS encryption capabilities of each DNS server obtained and the type of DNS encryption protocol supported by the DNS server. For example, it may be as shown in Table 1-1.

[0109] Table 1-1

[0110] DNS Server DNS Server Address DNS Encryption Capability DNS Encryption Protocol Type DNS Server 1 Address 1 Not Supported / DNS Server 2 Address 2 Supported Hypertext Transfer Protocol HTTP DNS Server 3 Address 3 Supported Transport Layer Security Protocol TLS

[0111] It should be noted that if the DNS server does not support DNS encryption capabilities, then the type of DNS encryption protocol supported by the DNS server may be a null value, which is not limited in the present application.

[0112] In another implementation manner, the first network element may locally configure or obtain from other network elements the DNS encryption protocol corresponding to each DNS server deployed in the network. It can be understood that since the DNS server supports the DNS encryption protocol, then the DNS server has the ability to encrypt DNS information using the DNS encryption protocol. The DNS encryption protocols supported by the DNS server, for example, the Transport Layer Security protocol and / or the Hypertext Transfer Protocol.

[0113] The first network element may store the DNS server and the type of DNS encryption protocol it supports. For example, it may be as shown in Table 1-2.

[0114] Table 1-2

[0115] DNS Server DNS Server Address DNS Encryption Protocol Type DNS Server 1 Address 1 / DNS Server 2 Address 2 Hypertext Transfer Protocol HTTP DNS Server 3 Address 3 Transport Layer Security Protocol TLS

[0116] It should be noted that if the DNS server does not support DNS encryption capabilities, then the type of DNS encryption protocol supported by the DNS server may be a null value, which is not limited in the present application.

[0117] The first network element may determine a first DNS server that provides DNS queries for the terminal device according to the DNS encryption capability supported by the terminal device indicated by the first information. For example, if the first information indicates that the terminal device supports encrypting DNS information, the first network element may select a DNS server that supports encrypting DNS information for the terminal device according to Table 1-1. If the first information indicates that the terminal device does not support encrypting DNS information, or the terminal device does not send the first information to the first network element, the first network element may select a DNS server that does not support encrypting DNS information for the terminal device according to Table 1-1. Another example is that if the first information indicates that the terminal device supports encrypting DNS information and the terminal device enables the DNS encryption transmission mode, the first network element may select a DNS server that supports encrypting DNS information for the terminal device according to Table 1-1. Or, if the first information indicates that the terminal device supports encrypting DNS information and the terminal device disables the DNS encryption transmission mode, the first network element may determine a DNS server that does not support encrypting DNS information for the terminal device according to Table 1-1.

[0118] Alternatively, the first network element may determine a first DNS server that provides DNS queries for the terminal device according to the DNS encryption protocol type indicated by the first information. For example, if the first information indicates that the DNS encryption protocol type supported by the terminal device is HTTP, the first network element may determine DNS Server 2 as the first DNS server according to Table 1-2. If the DNS encryption protocol type indicated by the first information is empty, indicating that the terminal device does not support the DNS encryption capability, the first network element may determine DNS Server 1 as the first DNS server according to Table 1-2.

[0119] In one example, if the first information indicates that the terminal device supports encrypting DNS information and the first information further includes the DNS encryption protocol type supported by the terminal device, the first network element may select a DNS server with a matching DNS encryption protocol type for the terminal device according to the DNS encryption protocol type supported by the terminal device. For example, if the DNS encryption protocol type supported by the terminal device is the Hypertext Transfer Protocol, the first network element may determine a DNS server (DNS Server 2) that supports encrypting DNS information and has a DNS encryption protocol type of the Hypertext Transfer Protocol as the first DNS server according to Table 1-1. If the DNS encryption protocol type supported by the terminal device is the Transport Layer Security Protocol, the first network element may determine a DNS server (DNS Server 3) that supports encrypting DNS information and has a DNS encryption protocol type of the Transport Layer Security Protocol as the first DNS server according to Table 1-1.

[0120] For the method described in the above-mentioned first manner, the embodiments of this application adoptFigures 4 to 6 Describe in detail.

[0121] Taking the first network element as the SMF as an example, refer to Figure 5 , which is an exemplary flowchart for the interaction between the terminal device and the core network, and may include the following steps:

[0122] Step 501: The SMF obtains the DNS encryption capabilities of each DNS server and the corresponding DNS encryption protocol types.

[0123] Among them, the SMF can obtain the DNS encryption capabilities of each DNS server already deployed in the affiliated network and the corresponding DNS encryption protocol types. The way for the SMF to obtain the above information can be local configuration of the SMF or the SMF obtains it through other network elements, and the embodiments of the present application do not make limitations.

[0124] Optionally, the AF can send a request message to the UDR, and the request message carries application information. Here, the application information may include the deployment location of the application, the address of the DNS server for resolving the IP address of the application, as well as the encryption capabilities of the DNS server and the corresponding DNS encryption protocol types, and the UDR can store the application information.

[0125] Step 502: The UE triggers the PDU session establishment process, and the UE can send a PDU session establishment request message to the SMF.

[0126] Among them, the message may carry a PDU session ID and first information. The first information can be used to indicate the DNS encryption capabilities supported by the terminal device. Optionally, the first information may further include the DNS encryption protocol supported by the terminal device. The description of the first information can refer to the relevant description of Case 1 in the above step 401, and will not be elaborated here.

[0127] It should be noted that if the terminal device does not support encrypting DNS information, then the first information carried in step 502 can be a null value, or the terminal device may not send the first information to the SMF (that is, step 502 does not carry the first information), and the embodiments of the present application do not make limitations.

[0128] Optionally, the message may further include second information, and the second information can be used to indicate the DNS encryption transmission mode adopted by the terminal device. The description of the second information can refer to the relevant description of Case 1 in the above step 401, and will not be elaborated here.

[0129] Step 503: The SMF invokes the service operation Npcf_SMPolicyControl_Create of the PCF to request the PCF to generate policy and charging control rules (PCC rules) for this session.

[0130] Step 504: The PCF returns Npcf_SMPolicyControl_Control to the SMF, carrying the PCC rules.

[0131] The PCC rules here may contain application-related information. For example, the deployment location of the application, the address of the DNS server used to resolve the IP address of the application, and the encryption capability of the DNS server. Among them, the PCF can determine application-related information and information such as the DNS server corresponding to the IP address used to resolve the application from the application information stored in the UDR.

[0132] For the description of the encryption capability of the DNS server, reference can be made to the relevant description in Step 402 above, which will not be elaborated here.

[0133] Step 505: The SMF determines the first DNS server for the UE.

[0134] Among them, if the UE reports the first information, then the SMF can determine the first DNS server for the terminal device according to the first information reported by the UE and the application information contained in the PCC rules.

[0135] For example, if the UE supports encrypting DNS information and the DNS encryption transmission mode is enabled, the SMF can select a DNS server that also supports encrypting DNS information for the UE. If the first information also contains the DNS encryption protocol type supported by the UE, the SMF can also select a DNS server that matches the DNS encryption protocol type supported by the UE according to the DNS encryption protocol type supported by the UE.

[0136] Another example, if the UE supports DNS encryption and the DNS encryption transmission mode is disabled, the SMF can select a DNS server that does not support encrypting DNS information for the UE. Or, if the UE does not support encrypting DNS information, the SMF can also select a DNS server that does not support encrypting DNS information for the UE.

[0137] Optionally, the SMF may also determine a first DNS server for the UE based on the location information of the UE, as well as the application information included in the first information and the PCC rule. For example, the SMF may determine that, at the current location of the UE, a DNS server that can provide DNS queries and whose DNS encryption capability and DNS encryption protocol type match those supported by the UE is used as the first DNS server.

[0138] Step 506: The SMF returns a PDU session establishment accept message to the UE, and the address of the first DNS server selected by the SMF for the UE may be carried in this message.

[0139] In an example, the SMF may send third information to the terminal device. Here, the third information may be used to indicate that the DNS encryption capability of the first DNS server matches the DNS encryption capability supported by the terminal device indicated by the first information. For example, if the first information indicates that the terminal device supports encrypting DNS information, the third information indicates that the first DNS server supports encrypting DNS information. If the first information indicates that the terminal device does not support encrypting DNS information, the third information indicates that the first DNS server does not support encrypting DNS information.

[0140] Optionally, the third information may also be used to indicate that the DNS encryption capability of the DNS server sent by the SMF does not match the DNS encryption capability supported by the terminal device indicated by the first information. For example, the addresses of the DNS servers sent by the first network element to the terminal device include the address 1 of DNS server 1 and the address 2 of DNS server 2. The third information sent by the first network element to the terminal device indicates that DNS server 1 matches the DNS encryption capability of the terminal device, and DNS server 2 does not match the DNS encryption capability of the terminal device. Therefore, the terminal device may select DNS server 1 according to the third information and initiate a DNS query through address 1.

[0141] In another example, the SMF may also send fourth information to the terminal device. Here, the fourth information may be used to indicate the DNS encryption protocol type that matches the first DNS server and the terminal device. For example, if the terminal device supports encrypting DNS information and the supported DNS encryption protocol type is HTTP, the fourth information may be used to indicate that the first DNS server supports encrypting DNS information and the supported DNS encryption protocol type is HTTP.

[0142] Optionally, the fourth piece of information can also be used to indicate that the DNS encryption protocol types supported by the first DNS server sent by the SMF do not match the DNS encryption protocol type supported by the terminal device. For example, the addresses of the first DNS server sent by the SMF to the terminal device include the address 1 of DNS server 1 and the address 2 of DNS server 2. DNS server 1 supports encrypting DNS information, and the supported DNS encryption protocol type is HTTP. DNS server 2 supports encrypting DNS information, and the supported DNS encryption protocol type is TLS. The terminal device can select from DNS server 1 and DNS server 2 according to the DNS encryption protocol type it supports. For example, when the DNS encryption protocol type supported by the terminal device itself is HTTP, the terminal device can initiate a DNS query through address 1. If the DNS encryption protocol type supported by the terminal device itself is TLS, the terminal device can initiate a DNS query through address 2.

[0143] When the UE receives the address of the first DNS server from the network side through the process as Figure 8 shown, the UE can initiate a DNS query to the first DNS server. If the UE wishes to change the DNS encryption transmission mode, then the UE can initiate a PDU session modification process to report the updated DNS encryption capability, as Figure 6 shown, which can include the following processes:

[0144] Step 601: The UE updates its own DNS encryption capability.

[0145] Among them, the UE can update its own DNS encryption capability according to its preference. For example, a UE that did not previously enable the DNS encryption transmission mode can enable the DNS encryption transmission mode, thereby changing its DNS encryption capability to support encrypting DNS information. Or, a UE that has previously enabled the DNS encryption transmission mode can disable the DNS encryption transmission mode, thereby changing its DNS encryption capability to not support encrypting DNS information.

[0146] Step 602: The UE triggers a PDU session modification process and sends a PDU session modification request message to the SMF.

[0147] Among them, the PDU session ID and the updated first piece of information can be carried in this message. The first piece of information here can be used to indicate the DNS encryption capability of the UE. Optionally, the first piece of information can also include the DNS encryption protocol supported by the terminal device. For the description of the first piece of information, refer to the relevant description in Case 1 of Step 401 above, and the repeated parts will not be elaborated.

[0148] In addition, it should be noted that if the terminal device does not support encrypting DNS information, the first information carried in step 602 can be a null value, or the message in step 602 may not carry the first information, and the present application does not make specific limitations.

[0149] Optionally, the message may further include second information. The second information can be used to indicate the DNS encryption transmission mode adopted by the terminal device. The description of the second information can refer to the relevant description of case 1 in step 401 above, and will not be elaborated here.

[0150] Step 603: The SMF can select an updated first DNS server for the UE according to the location information of the UE, the updated first information, and the application information in the PCC rule.

[0151] Among them, the way for the SMF to select an updated first DNS server for the UE can be as Figure 4 、 Figure 5 shown in the relevant ways, and will not be elaborated here.

[0152] Step 604: The SMF sends a response (PDU session modification ACK) message of the PDU session modification request to the UE, carrying the address of the updated first DNS server.

[0153] After receiving the address of the updated first DNS server, the UE can initiate a DNS query to the first DNS server.

[0154] Method 2: The first information is the operating system identification information of the terminal device.

[0155] The first network element can locally configure or obtain from other network elements the DNS encryption capabilities corresponding to each DNS server. For example, the DNS server supports encrypting DNS information, or the DNS server does not support encrypting DNS information. In addition, if the DNS server supports encrypting DNS information, the first network element can also obtain the type of DNS encryption protocol supported by the DNS server. Such as, the Transport Layer Security protocol and / or the Hypertext Transfer Protocol, etc. The first network element can store the corresponding relationship between the DNS encryption capabilities of each DNS server and the supported DNS encryption protocol types as described above. For example, it can be as shown in Table 1-1 or Table 1-2.

[0156] The first network element can locally configure or obtain from other network elements the DNS encryption capabilities corresponding to each operating system identification, as well as the corresponding DNS encryption protocol types. The first network element can store the corresponding relationship between the operating system identification and the DNS encryption capabilities and DNS encryption protocol types as described above. As shown in Table 2-1.

[0157] Table 2-1

[0158]

[0159] In another implementation, the first network element can locally configure or obtain from other network elements the DNS encryption protocol corresponding to each operating system identifier. It can be understood that since the operating system represented by the operating system identifier supports the DNS encryption protocol, then this operating system has the ability to encrypt DNS information using this DNS encryption protocol. Among them, the DNS encryption protocol supported by the operating system can be the Transport Layer Security protocol and / or the Hypertext Transfer Protocol.

[0160] The first network element can store the correspondence between the operating system identifier and the type of supported DNS encryption protocol, as shown in Table 2-2.

[0161] Table 2-2

[0162] Operating System Identification DNS Encryption Protocol Type OS ID-1 Transport Layer Security Protocol TLS, Hypertext Transfer Protocol HTTP OS ID-2 /

[0163] The first network element can determine the DNS encryption capability of the terminal device according to the operating system identifier reported by the terminal device. For example, the first network element can determine the DNS encryption capability of the terminal device according to Table 2-1. For example, if the operating system identifier of the terminal device is OS ID-1, the first network element can determine that the terminal device supports encrypting DNS information. If the operating system identifier of the terminal device is OS ID-2, the first network element can determine that the terminal device does not support encrypting DNS information. Optionally, the first network element can also determine the first DNS server according to the type of DNS encryption protocol supported by the terminal device. For example, if the first network element determines according to the operating system identifier that the type of DNS encryption protocol supported by the terminal device is HTTP, the first network element can select a DNS server that supports the DNS encryption protocol type of HTTP as the first DNS server. Or, if the first network element determines according to the operating system identifier that the type of DNS encryption protocol supported by the terminal device is TLS, the first network element can select a DNS server that supports the DNS encryption protocol type of TLS as the first DNS server.

[0164] In another implementation manner, the first network element may determine the DNS encryption protocol type supported by the terminal device according to the operating system identifier reported by the terminal device. For example, the first network element may determine the DNS encryption protocol type corresponding to the operating system identifier through Table 2-1. For example, if the operating system identifier reported by the terminal device is OS ID-2, the first network element may determine that the DNS encryption protocol type supported by the terminal device is empty. Therefore, the first network element may select a DNS server that does not support encrypting DNS information as the first DNS server for the terminal device. If the operating system identifier reported by the terminal device is OS ID-1, the first network element may determine that the DNS encryption protocol types supported by the terminal device are HTTP and TLS. Therefore, the first network element may select a DNS server that supports the DNS encryption protocol types of HTTP and TLS as the first DNS server for the terminal device.

[0165] For the method described in the above-mentioned second manner, the embodiments of the present application adopt Figures 7 to 9 to describe in detail.

[0166] Taking the first network element as the SMF as an example, referring to Figure 7 , an exemplary flowchart for the interaction between the terminal device and the network side may include the following steps:

[0167] Step 701: The SMF configures the DNS encryption capabilities of each OS ID.

[0168] In a possible implementation manner, the SMF may also configure the DNS encryption capabilities of each DNS server deployed in the network. For example, the SMF may configure whether each DNS server can encrypt DNS information, and configure the DNS encryption protocol type used by the DNS server when encrypting DNS, such as HTTP or TLS.

[0169] Optionally, the AF may send a request message to the UDR, and the request message carries application information. The application information here may include the deployment location of the application. For example, the deployment location of the application may be identified by a data network access identity (DNAI). The application information may also include the DNS server address for resolving the IP address of the application. Optionally, the application information may also include the encryption capabilities of the DNS server, and the UDR may store this application information.

[0170] Step 702: The UE triggers a PDU session establishment process, and the UE sends a PDU session establishment request message to the SMF.

[0171] The PDU session ID and the OS ID corresponding to the UE are carried in this message.

[0172] Step 703: The SMF invokes the service operation Npcf_SMPolicyControl_Create of the PCF to request the PCF to generate a PCC rule for this session.

[0173] Step 704: The PCF returns Npcf_SMPolicyControl_Create to the SMF, carrying the PCC rule.

[0174] The PCC rule here may contain application-related information. For example, the deployment location of the application, the address of the DNS server used to resolve the IP address of the application, the DNS encryption capability of the DNS server, and the DNS encryption protocol type, etc. Among them, the PCF can determine the application-related information and information such as the DNS server used to resolve the IP address of the application from the application information stored in the UDR.

[0175] Step 705: The SMF selects a first DNS server for the UE based on the OS ID of the UE and the application information included in the PCF rule.

[0176] For example, the SMF can determine the DNS encryption capability of the UE according to the OS ID of the UE. If the UE supports encrypting DNS information, the SMF can select a DNS server that supports encrypting DNS information as the first DNS server for the UE according to the application information. Optionally, the SMF can also determine the first DNS server for the UE according to the DNS encryption protocol type supported by the UE. For example, if the DNS encryption protocol type supported by the UE is HTTP, the SMF can select a DNS server whose supported DNS encryption protocol type is HTTP as the first DNS server according to the application information. Or, if the DNS encryption protocol type supported by the UE is TLS, the SMF can select a DNS server whose supported DNS encryption protocol type is TLS as the first DNS server according to the application information. If the UE does not support encrypting DNS information, the SMF can select a DNS server that does not support encrypting DNS information as the first DNS server for the UE according to the application information.

[0177] Optionally, the SMF can determine the first DNS server for the UE according to the location information of the UE, the DNS encryption capability of the UE, and the application information. For example, the SMF can determine a DNS server that can provide DNS queries at the current location of the UE, and whose DNS encryption capability and DNS encryption protocol type match the DNS encryption capability and DNS encryption protocol type supported by the UE as the first DNS server.

[0178] Step 706: The SMF returns a PDU session establishment accept message to the UE, and the address of the first DNS server is carried in this message.

[0179] Above, through Figure 7 An exemplary flowchart showing the SMF obtaining the OS ID of the terminal device from the terminal device is shown.

[0180] Below, through Figure 8 An exemplary flowchart showing the SMF obtaining the OS ID of the terminal device from the PCF is shown, and the following steps may be included.

[0181] Step 801: The SMF configures the DNS encryption capability for each OS ID.

[0182] Optionally, the SMF may also configure the DNS encryption capability for each DNS server deployed in the network.

[0183] In an example, the AF may send a request message to the UDR, and application information is carried in this request message. The application information here may include the deployment location of the application. For example, the deployment location of the application may be identified by DNAI. The application information may also include the DNS server address for resolving the IP address of the application. Optionally, the application information may also include the DNS server encryption capability, and the UDR may store this application information.

[0184] Step 802: The AMF obtains the terminal device identifier of the UE.

[0185] Wherein, the terminal device identifier here may be the IMEI, or the terminal device identifier may also be the Permanent Equipment Identifier (PEI).

[0186] Step 803: The UE triggers a PDU session establishment process, and the UE sends a PDU session establishment request message to the SMF.

[0187] The PDU session ID may be included in this message.

[0188] Step 804: The SMF obtains the terminal device identifier of the UE from the AMF.

[0189] Step 805: The SMF invokes the service operation Npcf_SMPolicyControl_Create of the PCF, and requests the PCF to generate a PCC rule for this session.

[0190] Among them, the SMF can carry the terminal device identifier in this message and send it to the PCF.

[0191] Step 806: The PCF determines the OS ID according to the terminal device identifier corresponding to the UE.

[0192] The terminal device identifier of the UE here can be IMEI or PEI. The PCF can determine the operating system name of the UE according to the terminal device identifier of the UE, and then determine the OS ID of the UE.

[0193] Step 807: The PCF returns Npcf_SMPolicyControl_Create to the SMF, carrying the PCC rule and the OS ID.

[0194] The PCC rule here can contain application-related information. For example, the deployment location of the application, the address of the DNS server that resolves the IP address of the application, the DNS encryption capability of the DNS server, and the DNS encryption protocol type, etc.

[0195] Step 808: The SMF can determine the DNS encryption capability supported by the UE according to the OS ID, and determine the first DNS server for the terminal device according to the application information.

[0196] For example, the SMF can determine the DNS encryption capability of the UE according to the OS ID of the UE. If the UE supports encrypting DNS information, the SMF can select a DNS server that supports encrypting DNS information as the first DNS server according to the application information. Optionally, the SMF can also determine the first DNS server for the UE according to the DNS encryption protocol type supported by the UE. For example, if the DNS encryption protocol type supported by the UE is HTTP, the SMF can select a DNS server that supports the DNS encryption protocol type of HTTP as the first DNS server according to the application information. Or, if the DNS encryption protocol type supported by the UE is TLS, the SMF can select a DNS server that supports the DNS encryption protocol type of TLS as the first DNS server according to the application information. If the UE does not support encrypting DNS information, the SMF can select a DNS server that does not support encrypting DNS information as the first DNS server according to the application information.

[0197] Optionally, the SMF can determine the first DNS server for the UE according to the location information of the UE, the DNS encryption capability of the UE, and the application information. For example, the SMF can determine a DNS server that can provide DNS queries at the current location of the UE and whose DNS encryption capability and DNS encryption protocol type match as the first DNS server.

[0198] Step 809: The SMF returns a PDU session establishment accept message to the UE, and the address of the first DNS server is carried in this message.

[0199] Taking the first network element as the PCF as an example, refer to Figure 9 , an exemplary flowchart for configuring the DNS encryption capability corresponding to the OS ID for the PCF may include the following steps.

[0200] Step 901: The PCF configures the DNS encryption capability corresponding to each OS ID.

[0201] It should be understood that the PCF can also configure the type of DNS encryption protocol supported by each OS ID. Optionally, the PCF can also configure the DNS encryption capability of each DNS server deployed in the network.

[0202] In an example, the AF can send a request message to the UDR, and application information is carried in this request message. The application information here may include the deployment location of the application. For example, the deployment location of the application can be identified by the DNAI. The application information may also include the DNS server address for resolving the IP address of the application. Optionally, the application information may also include the encryption capability of the DNS server, and the UDR can store this application information.

[0203] Steps 902 - 906 are the same as Figure 8 the steps 802 - 806 shown.

[0204] Step 907: The PCF determines the first DNS server according to the DNS encryption capability of the UE and the application information.

[0205] Among them, for example, the PCF can determine the DNS encryption capability of the UE according to the OS ID of the UE. If the UE supports encrypting DNS information, the PCF can select a DNS server that supports encrypting DNS information for the UE as the first DNS server according to the application information. Optionally, the PCF can also determine the first DNS server for the UE according to the type of DNS encryption protocol supported by the UE. For example, if the type of DNS encryption protocol supported by the UE is HTTP, the PCF can select a DNS server that supports the DNS encryption protocol type of HTTP as the first DNS server according to the application information. Or, if the type of DNS encryption protocol supported by the UE is TLS, the PCF can select a DNS server that supports the DNS encryption protocol type of TLS as the first DNS server according to the application information. If the UE does not support encrypting DNS information, the PCF can select a DNS server that does not support encrypting DNS information for the UE as the first DNS server according to the application information.

[0206] Step 908: The PCF returns Npcf_SMPolicyControl_Create to the SMF, carrying the PCC rule.

[0207] The PCC rule here may contain application-related information. For example, the deployment location of the application, the address of the DNS server used to resolve the IP address of the application, the DNS encryption capability of the DNS server, and the DNS encryption protocol type, etc.

[0208] In an example, the message may also carry the DNS encryption capability of the UE and the address of the first DNS server determined by the PCF for the UE. Optionally, the message may also carry the DNS encryption capability of the first DNS server. For example, whether the first DNS server supports encrypting and decrypting DNS information, and the DNS encryption protocol type supported by the first DNS server, etc.

[0209] Step 909: The SMF returns a PDU session establishment accept message to the UE, and the address of the first DNS server is carried in this message.

[0210] In an example, after receiving the address of the first DNS server sent by the PCF, the SMF can determine whether the first DNS server can provide DSN queries for the UE based on the location information of the UE. For example, if the PCF sends multiple addresses of the first DNS server to the SMF, the SMF can determine one or more of the first DNS servers that can provide DNS queries for the UE at the current location of the UE. The SMF can carry the determined address(es) of one or more of the first DNS servers in the PDU session establishment accept message. If the PCF sends an address of a first DNS server to the SMF, the SMF can determine whether the first DSN server can provide DNS queries for the UE at the current location of the UE. If the first DNS server can provide DNS queries for the UE, the SMF can carry the address of the first DNS server in the PDU session establishment accept message. If the first DSN server cannot provide DNS queries for the UE, the SMF may not carry the address of the first DNS server in the PDU session establishment accept message.

[0211] In one example, a first network element (such as an SMF) may send fifth information to a terminal device. The fifth information here may be used to indicate the DNS encryption capabilities supported by the DNS server. For example, the fifth information may indicate that the DNS server supports encrypting DNS information, or may indicate that the DNS server does not support encrypting DNS information. For instance, the address of the DNS server sent by the first network element to the terminal device includes address 1 of DNS server 1. The first network element may send the fifth information to the terminal device, and the fifth information may indicate that DNS server 1 supports encrypting DNS information. The terminal device may also determine whether the DNS encryption capabilities of DNS server 1 match its own based on the fifth information. If the terminal device determines that the DNS encryption capabilities of DNS server 1 match its own, that is, it itself supports encrypting DNS information or has enabled the DNS encrypted transmission mode, the terminal device may initiate a DNS query through address 1. If the terminal device determines that the DNS encryption capabilities of DNS server 1 do not match its own, that is, it itself does not support encrypting DNS information or has disabled the DNS encrypted transmission mode, the terminal device may send its own DNS encryption capabilities to the network side and request an update of the DNS server address. Alternatively, the addresses of the DNS servers sent by the first network element include address 1 of DNS server 1 and address 2 of DNS server 2. The fifth information may indicate that DNS server 1 supports encrypting DNS information and DNS server 2 does not support encrypting DNS information. The terminal device may select a DNS server to initiate a DNS query based on its own DNS encryption capabilities and DNS encrypted transmission mode. For example, if the terminal device supports encrypting DNS information and the DNS encrypted transmission mode is enabled, the terminal device may initiate a DNS query to DNS server 1. If the terminal device does not support encrypting DNS information, or the DNS encrypted transmission mode is disabled, the terminal device may initiate a DNS query to DNS server 2.

[0212] In another example, a first network element (such as an SMF) may send sixth information to a terminal device. The sixth information may indicate the type of DNS encryption protocol supported by the DNS server. For example, the addresses of the DNS servers sent by the first network element to the terminal device include address 1 of DNS server 1 and address 2 of DNS server 2. The sixth information indicates that the type of DNS encryption protocol supported by DNS server 1 is HTTP, and the type of DNS encryption protocol supported by DNS server 2 is TLS. The terminal device may select a DNS server from them based on the type of DNS encryption protocol it supports. For example, if the type of DNS encryption protocol supported by the terminal device is HTTP, the terminal device may initiate a DNS query to DNS server 1. If the type of DNS encryption protocol supported by the terminal device is TLS, the terminal device may initiate a DNS query to DNS server 2.

[0213] Step 403: The first network element sends the address of the first DNS server, and the terminal device receives the address of the first DNS server.

[0214] The terminal device can initiate a DNS query to the first DNS server according to the received address of the first DNS server. Among them, if the first DNS server supports encrypting DNS information, the terminal device and the first DNS server can perform encrypted transmission of DNS information. Optionally, the protocol for encrypting DNS can be a protocol supported by both the terminal device and the first DNS server. If the first DNS server does not support encrypting DNS information, the terminal device and the first DNS server can not perform encrypted transmission of DNS information.

[0215] Based on the same inventive concept, an embodiment of the present application further provides a server selection method. Refer to Figure 10 , which is an exemplary flowchart of the server selection method shown from the perspective of device interaction, and may include the following steps:

[0216] Step 1001: The first network element determines the encryption capability information of at least one DNS server.

[0217] The first network element here may be a session management function network element SMF, a policy control function network element PCF, or an edge configuration server.

[0218] Among them, the first network element may determine at least one DNS server according to the application information. Optionally, the first network element may also determine at least one DNS server for the terminal device according to the location information of the terminal device. For example, the first network element may determine the DNS servers that can provide DNS queries for the terminal device at the current location of the terminal device.

[0219] The encryption capability information of the DNS server here may include the DNS encryption capability of each DNS server. The DNS encryption capability may include that the DNS server supports encrypting DNS information, or the DNS server does not support encrypting DNS information. Optionally, the encryption capability information may further include the type of DNS encryption protocol supported by each DNS server that supports encrypting DNS information. Such as, HTTP and / or TLS, etc.

[0220] It should be understood that the description of the DNS encryption capability and the DNS encryption protocol type of the DNS server can refer to the relevant description in the method embodiment as shown in Figure 4 , and will not be elaborated here.

[0221] Step 1002: The first network element sends the encryption capability information of at least one DNS server to the terminal device.

[0222] The encryption capability information here may include the DNS encryption capabilities of at least one DNS server determined by the first network element and the corresponding DNS encryption protocol types.

[0223] The first network element may also send the addresses of at least one DNS server to the terminal device. Among them, the first network element may send the addresses of at least one DNS server and the encryption capability information to the terminal device together, or may send the addresses of at least one DNS server and the encryption capability information to the terminal device separately.

[0224] Step 1003: The terminal device determines a first DNS server from at least one DNS server according to the encryption capability information of at least one DNS server.

[0225] The terminal device may select a DNS server from at least one DNS server to initiate a DNS query according to its own DNS encryption capability. For example, if the terminal device supports encrypting DNS information and the DNS encryption transmission mode is enabled, the terminal device may select a DNS server that supports encrypting DNS information from at least one DNS server to initiate a DNS query. Optionally, the terminal device may select a DNS server whose supported DNS encryption protocol type matches its own from the DNS servers that support encrypting DNS information. For example, if the DNS encryption protocol type supported by itself is TLS, the terminal device may select a DNS server whose supported DNS encryption protocol type is TLS to initiate a DNS query. If the DNS encryption protocol type supported by itself is HTTP, the terminal device may select a DNS server whose supported DNS encryption protocol type is HTTP to initiate a DNS query. Or, if the terminal device does not support encrypting DNS information, or the DNS encryption transmission mode is disabled, the terminal device may select a DNS server that does not support encrypting DNS information from at least one DNS server to initiate a DNS query.

[0226] The terminal device may also select a DNS server from at least one DNS server to initiate a DNS query according to its own preference. For example, when the terminal device determines that DNS information does not need to be encrypted, the terminal device may select a DNS server that does not support encrypting DNS information from at least one DNS server to initiate a DNS query. When the terminal device determines that DNS information needs to be encrypted, the terminal device may select a DNS server that supports encrypting DNS information from at least one DNS server to initiate a DNS query. Among them, the DNS encryption protocol type supported by the DNS server that supports encrypting DNS information is the same as the DNS encryption protocol type supported by itself.

[0227] If the terminal device receives only the address of one DNS server from the first network element and the encryption capability information of this DNS server does not match its own, the terminal device can decide on its own whether to use this DNS server to initiate a DNS query. For example, if the DNS encryption capability of the DNS server received by the terminal device is not to support encrypting DNS information, while the terminal device itself supports encrypting DNS information, then the terminal device can initiate a DNS query to this DNS server or send its own DNS encryption capability to the network side. Or, if the DNS encryption capability of the DNS server received by the terminal device is to support encrypting DNS information, while the terminal device itself does not support encrypting DNS information, then the terminal device can initiate a DNS query to this DNS server or send its own DNS encryption capability to the network side.

[0228] For another example, if the type of DNS encryption protocol supported by the DNS server received by the terminal device is different from the type of DNS encryption protocol supported by the terminal device itself, the terminal device can initiate a DNS query to this DNS server or send its own DNS encryption capability and the type of DNS encryption protocol supported to the network side.

[0229] Taking the first network element as the SMF network element as an example, referring to Figure 11 , an exemplary flowchart for the interaction between the terminal device and the network side may include the following steps:

[0230] Step 1101: The SMF configures the DNS encryption capability of each DNS server.

[0231] Among them, the SMF can configure the DNS encryption capability of each DNS server or the type of DNS encryption protocol supported by each DNS server.

[0232] Optionally, the AF can send a request message to the UDR, and the application information is carried in this request message. The application information here may include the deployment location of the application and the address of the DNS server used to resolve the IP address of this application. Optionally, the application information may further include the encryption capability of the DNS server, and the UDR can store this application information.

[0233] Step 1102: The UE triggers the PDU session establishment process, and the UE can send a PDU session establishment request message to the SMF.

[0234] The PDU session ID may be carried in this message.

[0235] Step 1103: The SMF invokes the service operation Npcf_SMPolicyControl_Create of the PCF to request the PCF to generate policy and charging control rules (PCC rules) for this session.

[0236] Step 1004: The PCF returns Npcf_SMPolicyControl_Control to the SMF, carrying the PCC rules.

[0237] The PCC rules here may contain application-related information. For example, the deployment location of the application, the address of the DNS server used to resolve the IP address of the application, the encryption capability of the DNS server, and the corresponding DNS encryption protocol type. Among them, the PCF can determine the above application-related information from the application information stored in the UDR.

[0238] Step 1105: The SMF determines the encryption capability information of at least one DNS server.

[0239] The SMF can determine at least one DNS server for the UE and the encryption capability information of at least one DNS server according to the application information. Optionally, the SMF can also determine at least one DNS server and the encryption capability information of at least one DNS server according to the location information and application information of the UE. For example, the SMF can determine at least one DNS server that can provide DNS queries for the UE at the current location of the UE, and the encryption capability information of the at least one DNS server.

[0240] It should be noted that if the DNS server does not support encrypting DNS information, the encryption capability information of the DNS server can be a null value, or the encryption capability information of the DNS server can be a unified identification information. The unified identification information here can indicate that DNS information encryption is not supported.

[0241] Step 1106: The SMF returns a PDU session establishment accept message to the UE, and the message may carry the encryption capability information of at least one DNS server.

[0242] Optionally, the message may also carry the addresses of at least one DNS server.

[0243] Step 1107: The terminal device selects a DNS server from at least one DNS server to initiate a DNS query.

[0244] Among them, for the method by which the terminal device selects a DNS server from at least one DNS server, reference can be made to the relevant description in the method embodiment as shown in Figure 8 below.

[0245] The method of the embodiment of the present application is introduced above. The devices in the embodiment of the present application will be introduced below. The method and the device are based on the same technical concept. Since the principles of the method and the device for solving problems are similar, the implementation of the device and the method can be referred to each other, and the repeated parts will not be elaborated.

[0246] Based on the same technical concept as the above communication method, as shown in Figure 12 below, a server selection device 1200 is provided. The device 1200 can perform each step executed by the terminal device in the above method. For the sake of avoiding repetition, it will not be elaborated here. The device 1200 includes: a communication unit 1210, a processing unit 1220. Optionally, it further includes a storage unit 1230; the processing unit 1220 can be respectively connected to the storage unit 1230 and the communication unit 1210, and the storage unit 1230 can also be connected to the communication unit 1210. Among them, the processing unit 1220 can be integrated with the storage unit 1230.

[0247] The storage unit 1230 is used to store computer programs;

[0248] Exemplarily, the processing unit 1220 is used to send a first piece of information to a first network element through the communication unit 1210. For the description of the first piece of information, reference can be made to the relevant description in the method embodiment as shown in Figure 4 below, and it will not be elaborated here. The processing unit 1220 is further used to receive the address of the DNS server sent by the first network element through the communication unit 1210. This DNS server is determined by the first network element according to the first piece of information.

[0249] In one design, the processing unit 1220 is further used to send a second piece of information through the communication unit 1210. Among them, for the description of the second piece of information, reference can be made to the relevant description in the method embodiment as shown in Figure 4 below, and it will not be elaborated here.

[0250] In one design, the processing unit 1220 is further used to receive a third piece of information sent by the first network element through the communication unit. Among them, for the description of the third piece of information, reference can be made to the relevant description in the method embodiment as shown in Figure 4 below, and it will not be elaborated here.

[0251] In one design, the processing unit 1220 is further used to receive a fourth piece of information sent by the first network element through the communication unit 1210. Among them, for the description of the fourth piece of information, reference can be made to the relevant description in the method embodiment as shown in Figure 4For the relevant descriptions in the method embodiments shown above, they will not be elaborated here. The processing unit 1220 is further configured to initiate a DNS query to the DNS server according to the type of DNS encryption protocol supported by the DNS server. Among them, the type of DNS encryption protocol supported by the DNS server supported by the device 1200.

[0252] Exemplarily, the processing unit 1220 is configured to send the operating system identification information of the device 1200 to the first network element through the communication unit 1210. Among them, the description of the operating system identification information can be referred to as Figure 4 shown in the relevant descriptions. The processing unit 1220 is further configured to receive the address of the DNS server from the first network element through the communication unit 1210. The DNS server here is determined by the first network element according to the operating system identification information.

[0253] Each step performed by the terminal device in the above method can also be implemented by a chip for the terminal device. Among them, the communication unit can be the input / output circuit or interface of the chip, and the processing unit can be a logic circuit. The logic circuit can process the data to be processed according to the steps described in the above method aspect to obtain the processed data. The data to be processed can be the data received by the input circuit / interface. The processed data can be the data obtained according to the data to be processed. The output circuit / interface is used to output the processed data.

[0254] The embodiment of the present application further provides a server selection device, which can be a terminal device or a circuit. This device can be used to perform the actions performed by the terminal device in the above method embodiment.

[0255] Figure 13 Shows a schematic structural diagram of a simplified terminal device. For the convenience of understanding and illustration, Figure 13 in which the terminal device takes a mobile phone as an example. As Figure 13 shown, the terminal device includes a processor, a memory, a radio frequency circuit, an antenna, and an input / output device. The processor is mainly used to process communication protocols and communication data, control the terminal device, execute software programs, process data of software programs, etc. The memory is mainly used to store software programs and data. The radio frequency circuit is mainly used for the conversion between baseband signals and radio frequency signals and the processing of radio frequency signals. The antenna is mainly used to receive and transmit radio frequency signals in the form of electromagnetic waves. The input / output device, such as a touch screen, a display screen, a keyboard, etc., is mainly used to receive data input by the user and output data to the user. It should be noted that some types of terminal devices may not have an input / output device.

[0256] When data needs to be sent, after the processor performs baseband processing on the data to be sent, it outputs a baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then sends the radio frequency signal outwards in the form of electromagnetic waves through the antenna. When data is sent to the terminal device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data. For ease of explanation, Figure 13 only one memory and one processor are shown. In an actual terminal device product, there may be one or more processors and one or more memories. The memory may also be referred to as a storage medium or a storage device, etc. The memory may be set independently of the processor or integrated with the processor. The embodiments of the present application do not limit this.

[0257] In the embodiments of the present application, the antenna and the radio frequency circuit with transceiver functions can be regarded as the communication unit of the terminal device, and the processor with processing functions can be regarded as the processing unit of the terminal device. As Figure 13 shown, the terminal device includes a communication unit 1310 and a processing unit 1320. The communication unit may also be referred to as a transceiver, a transceiver machine, a transceiver device, etc. The processing unit may also be referred to as a processor, a processing board, a processing module, a processing device, etc. Optionally, the devices in the communication unit 1310 for implementing the receiving function can be regarded as the receiving unit, and the devices in the communication unit 1310 for implementing the sending function can be regarded as the sending unit, that is, the communication unit 1310 includes a receiving unit and a sending unit. The communication unit is sometimes also referred to as a transceiver, a transceiver, or a transceiver circuit, etc. The receiving unit is sometimes also referred to as a receiver, a receiver, or a receiving circuit, etc. The sending unit is sometimes also referred to as a transmitter, a transmitter, or a transmitting circuit, etc.

[0258] It should be understood that the communication unit 1310 is used to perform the sending operation and the receiving operation on the terminal device side in the above method embodiments, and the processing unit 1320 is used to perform other operations on the terminal device except the transceiver operation in the above method embodiments.

[0259] For example, in one implementation, the communication unit 1310 is used to perform Figure 4 the receiving and / or sending operations on the terminal device side in steps 401 and 402 in

[0260] Based on the same technical concept as the above method, as Figure 14As shown, a server selection device 1400 is provided. The device 1400 can perform each step executed by the first network element in the above method. To avoid repetition, details are not described herein again. The device 1400 includes: a communication unit 1410, a processing unit 1420, and optionally, a storage unit 1430; the processing unit 1420 can be respectively connected to the storage unit 1430 and the communication unit 1410, and the storage unit 1430 can also be connected to the communication unit 1410. Among them, the processing unit 1420 can be integrated with the storage unit 1430.

[0261] The storage unit 1430 is used to store computer programs;

[0262] Exemplarily, the communication unit 1410 is used to receive first information. Among them, the description of the first information can refer to the relevant description in the method embodiment as shown in Figure 4 The processing unit 1420 is further used to determine a first DNS server for providing DNS queries for the terminal device according to the first information. The communication unit 1410 is further used to send the address of the first DNS server.

[0263] In one design, the communication unit 1410 is further used to receive second information. Among them, the description of the second information can refer to the relevant description in the method embodiment as shown in Figure 4 The processing unit 1410 is specifically used to determine a first DNS server for providing DNS queries for the terminal device according to the first information and the second information.

[0264] In one design, the communication unit 1410 is further used to send third information. Among them, the description of the third information can refer to the relevant description in the method embodiment as shown in Figure 4 and details are not described herein again.

[0265] In one design, the communication unit 1410 is further used to send fourth information. The fourth information here can refer to the relevant description in the method embodiment as shown in Figure 4 and details are not described herein again.

[0266] Exemplarily, the processing unit 1420 is used to determine encryption capability information of at least one DNS server. Among them, the encryption capability information of at least one DNS server can refer to the relevant description in the method embodiment as shown in Figure 4 The communication unit 1410 is used to send the encryption capability information of the at least one DNS server to the terminal device.

[0267] In the above method, each step executed by the first network element can also be implemented by a chip for the first network element. Among them, the communication unit can be the input / output circuit or interface of the chip, and the processing unit can be a logic circuit. The logic circuit can process the data to be processed according to the steps described in the above method aspect, and obtain the processed data. The data to be processed can be the data received by the input circuit / interface. The processed data can be the data obtained according to the data to be processed. The output circuit / interface is used to output the processed data.

[0268] As Figure 15 shown, the server selection device 1500 provided in the embodiment of the present application is used to implement the functions of the terminal device and the first network element in the above method. The device 1500 can be a terminal device, a first network element, or a chip for a terminal device or a first network element, or a device that can be used in matching with the terminal device and the first network element.

[0269] The device 1500 includes at least one processor 1520, which is used to implement the functions of the terminal device and the first network element in the method provided in the embodiment of the present application. The device 1500 may further include a communication interface 1510. In the embodiment of the present application, the communication interface can be a transceiver, a circuit, a bus, a module, or other types of communication interfaces, and is used to communicate with other devices through a transmission medium. For example, the communication interface 1510 is used for the units in the device 1500 to communicate with other devices. When the device 1500 is a terminal device, the processor 1520 can complete the functions of the processing unit 1220 as Figure 12 shown, and the communication interface 1510 can complete the functions of the communication unit 1210 as Figure 12 shown. When the device 1500 is a first network element, the processor 1520 can complete the functions of the processing unit 1420 as Figure 14 shown, and the communication interface 1510 can complete the functions of the communication unit 1410 as Figure 14 shown.

[0270] The device 1500 may further include at least one memory 1530, which is used to store program instructions and / or data. The memory 1530 is coupled to the processor 1520. The coupling in the embodiment of the present application is an indirect coupling or communication connection between devices, units, or modules, and can be electrical, mechanical, or other forms, and is used for information interaction between devices, units, or modules. The processor 1520 may cooperate with the memory 1530. The processor 1520 may execute the program instructions stored in the memory 1530. At least one of the at least one memory may be included in the processor.

[0271] In the embodiments of the present application, the specific connection medium between the communication interface 1510, the processor 1520, and the memory 1530 is not limited. In the embodiments of the present application Figure 15 it is shown that the memory 1530, the processor 1520, and the communication interface 1510 are connected through a bus 1540, and the bus is represented by a thick line in Figure 15 which. The connection manners between other components are only for illustrative purposes and are not to be taken as limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 15 it is only represented by a thick line in which, but it does not mean that there is only one bus or one type of bus.

[0272] As another form of this embodiment, a computer-readable storage medium is provided, on which instructions are stored, and when the instructions are executed, the methods on the terminal device side or the first network element side in the above method embodiments are executed.

[0273] As another form of this embodiment, a computer program product containing instructions is provided, and when the instructions are executed, the methods on the terminal device side or the first network element side in the above method embodiments are executed.

[0274] As another form of this embodiment, a communication system is provided, and the system may include at least one of the above terminal devices and at least one of the above first network elements.

[0275] It should be understood that the processor mentioned in the embodiments of the present invention may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0276] It should also be understood that the memory mentioned in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).

[0277] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) is integrated in the processor.

[0278] It should be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0279] It should be understood that in various embodiments of the present application, the magnitude of the sequence numbers of the above processes does not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0280] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans may use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.

[0281] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0282] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0283] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0284] In addition, the functional units in each embodiment of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0285] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0286] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A server selection method, characterized in that, include: The terminal device sends first information to the first network element; The first information is used to indicate the domain name system DNS encryption capability supported by the terminal device; The DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information; The terminal device receives the address of the DNS server sent by the first network element; the DNS server is determined by the first network element based on the first information.

2. The method according to claim 1, characterized in that, Also includes: The terminal device sends second information to the first network element, where the second information indicates a DNS encryption transmission mode adopted by the terminal device; The DNS encrypted transmission mode is a DNS encrypted transmission on mode or a DNS encrypted transmission off mode.

3. The method according to claim 1 or 2, characterized in that, The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security Protocol TLS; Hypertext Transfer Protocol HTTP.

4. The method according to claim 1 or 2, characterized in that, Also includes: The terminal device receives third information sent by the first network element, where the third information is used to indicate that the DNS encryption capability of the DNS server matches the DNS encryption capability supported by the terminal device indicated by the first information.

5. The method according to claim 1 or 2, characterized in that, Also includes: The terminal device receives fourth information sent by the first network element, where the fourth information is used to indicate a DNS encryption protocol type matched by a DNS encryption capability supported by the DNS server and the terminal device; The terminal device initiates a DNS query to the DNS server according to the DNS encryption protocol type supported by the DNS server; wherein the terminal device supports the DNS encryption protocol type supported by the DNS server.

6. A server selection method, characterized in that, include: The first network element receives the first information; The first information is used to determine the domain name system DNS encryption capability supported by the terminal device; The DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information; The first network element determines, according to the first information, a first DNS server that provides a DNS query for the terminal device; The first network element sends the address of the first DNS server.

7. The method according to claim 6, characterized in that, Also includes: The first network element receives second information; the second information indicates a DNS encrypted transmission mode adopted by the terminal device; the DNS encrypted transmission mode is a DNS encrypted transmission on mode or a DNS encrypted transmission off mode; The first network element determines, according to the first information, a first DNS server that provides a DNS query for the terminal device, including: The first network element determines a first DNS server that provides DNS queries for the terminal device based on the first information and the second information.

8. The method according to claim 6 or 7, characterized in that, The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security TLS protocol; Hypertext Transfer Protocol (HTTP).

9. The method according to claim 6 or 7, characterized in that, Also includes: The first network element sends third information, where the third information is used to indicate that the encryption capability of the DNS server matches the DNS encryption capability supported by the terminal device indicated by the first information.

10. The method according to claim 6 or 7, characterized in that, Also includes: The first network element sends fourth information, where the fourth information is used to indicate the DNS encryption protocol type that matches the DNS encryption capabilities supported by the DNS server and the terminal device.

11. A server selection method, characterized in that include: The terminal device sends the operating system identification information of the terminal device to the first network element; the operating system identification information is used to determine the domain name system DNS encryption capability supported by the terminal device; the DNS encryption capability supported by the terminal device is the ability of the terminal device to encrypt DNS information; The terminal device receives the address of the DNS server sent by the first network element; the DNS server is determined by the first network element according to the operating system identification information.

12. The method according to claim 11, characterized in that The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security TLS protocol; Hypertext Transfer Protocol HTTP protocol.

13. A server selection method, characterized in that include: The first network element receives operating system identification information of the terminal device from the terminal device; The first network element is configured with a domain name system DNS encryption capability corresponding to the operating system identification information of the terminal device, and the first network element determines the DNS encryption capability supported by the terminal device according to the operating system identification information of the terminal device; The DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information; The first network element determines, according to the DNS encryption capability supported by the terminal device, a first DNS server that provides a DNS query for the terminal device; The first network element sends the address of the first DNS server.

14. The method according to claim 13, characterized in that The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security TLS protocol; Hypertext Transfer Protocol HTTP protocol.

15. A server selection method, characterized in that include: The terminal device receives encryption capability information of at least one DNS server from the first network element; The at least one DNS server is determined by the first network element according to the location information of the terminal device and is a DNS server capable of providing services for the terminal device; The terminal device determines a first DNS server from the at least one DNS server according to the encryption capability information of the at least one DNS server, wherein the encryption capability of the first DNS server matches the encryption capability supported by the terminal device, and the DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information; The terminal device initiates a DNS query to the first DNS server.

16. The method according to claim 15, characterized in that The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security TLS protocol; Hypertext Transfer Protocol HTTP protocol.

17. A server selection method, characterized in that include: The first network element determines encryption capability information of at least one DNS server; The encryption capability information of the at least one DNS server includes the capability of the at least one DNS server to encrypt DNS information, and the at least one DNS server is determined by the first network element and is a DNS server capable of providing services to the terminal device; The first network element sends the encryption capability information of the at least one DNS server to the terminal device.

18. The method according to claim 17, characterized in that The encryption capability information further includes the DNS encryption protocols supported by the at least one DNS server, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP) protocol.

19. The method according to any one of claims 1, 2, 6, 7, 11 to 18, characterized in that The first network element is a session management function network element, or an edge configuration server, or a policy control function network element.

20. A server selection device, characterized in thatincluding: A processing unit and a communication unit Wherein, the processing unit is configured to send first information to the first network element through the communication unit; The first information is used to indicate the Domain Name System (DNS) encryption capability supported by the device; the DNS encryption capability supported by the device is the capability of the device to encrypt DNS information; The processing unit is further configured to receive, through the communication unit, the address of the DNS server sent by the first network element; the DNS server is determined by the first network element according to the first information.

21. The device according to claim 20, wherein, The processing unit is further configured to: Send second information through the communication unit, where the second information indicates the DNS encryption transmission mode adopted by the device; the DNS encryption transmission mode is a DNS encryption transmission on mode or a DNS encryption transmission off mode.

22. The device according to claim 20 or 21, wherein, The DNS encryption capability includes the supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP) protocol.

23. The device according to claim 20 or 21, wherein, The processing unit is further configured to: Receive, through the communication unit, third information sent by the first network element, where the third information is used to indicate that the DNS encryption capability of the DNS server matches the DNS encryption capability supported by the terminal device indicated by the first information.

24. The device according to claim 20 or 21, wherein, The processing unit is further configured to: Receive, through the communication unit, fourth information sent by the first network element, where the fourth information is used to indicate the DNS encryption protocol type that matches the DNS encryption capability of the DNS server and the Domain Name System (DNS) encryption capability supported by the device. The processing unit is further configured to: initiate a DNS query to the DNS server according to the DNS encryption protocol type supported by the DNS server; wherein, the device supports the DNS encryption protocol type supported by the DNS server.

25. A server selection device, wherein, including: A processing unit and a communication unit Wherein, the communication unit is configured to receive first information; The first information is used to determine the Domain Name System (DNS) encryption capability supported by the terminal device; the DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information; The processing unit is configured to determine, according to the first information, a first DNS server that provides DNS queries for the terminal device; The communication unit is further configured to send the address of the first DNS server.

26. The device according to claim 25, wherein, The communication unit is further configured to: Receive second information; the second information indicates the DNS encryption transmission mode adopted by the terminal device; the DNS encryption transmission mode is the DNS encryption transmission enabled mode or the DNS encryption transmission disabled mode; When determining, according to the first information, the first DNS server that provides DNS queries for the terminal device, the processing unit is specifically configured to: Determine, according to the first information and the second information, the first DNS server that provides DNS queries for the terminal device.

27. The device according to claim 25 or 26, wherein, The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP).

28. The device according to claim 25 or 26, wherein, The communication unit is further configured to: Send third information, where the third information is used to indicate that the DNS encryption capability of the DNS server matches the DNS encryption capability supported by the terminal device indicated by the first information.

29. The device according to claim 25 or 26, wherein, The communication unit is further configured to: Send fourth information, where the fourth information is used to indicate the type of DNS encryption protocol that matches the DNS encryption capabilities of the DNS server and the terminal device.

30. A server selection device, characterized in that, Comprises: A processing unit and a communication unit The processing unit is configured to send, through the communication unit, the operating system identification information of the device to a first network element; the operating system identification information is used to determine the DNS encryption capability supported by the device; the DNS encryption capability supported by the device is the capability of the device to encrypt DNS information; The processing unit is further configured to receive, through the communication unit, the address of the DNS server sent by the first network element; the DNS server is determined by the first network element according to the operating system identification information.

31. The device according to claim 30, characterized in that, The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP).

32. A server selection device, characterized in that, Comprises: A processing unit and a communication unit The communication unit is configured to receive the operating system identification information of the terminal device from the terminal device; The processing unit is configured with a DNS encryption capability corresponding to the operating system identification information of the terminal device, and the processing unit is configured to determine, according to the operating system identification information of the terminal device, the DNS encryption capability supported by the terminal device; the DNS encryption capability supported by the terminal device is the capability of the terminal device to encrypt DNS information; The processing unit is further configured to determine, according to the DNS encryption capability supported by the terminal device, the first DNS server that provides DNS queries for the terminal device; The communication unit is further configured to send the address of the first DNS server.

33. The device according to claim 32, characterized in that, The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP).

34. A server selection device, characterized in that, Comprises: A processing unit and a communication unit. The communication unit is configured to receive the encryption capability information of at least one DNS server from a first network element; The at least one DNS server is a DNS server determined by the first network element according to the location information of the device and capable of providing services to the device; The processing unit is configured to determine a first DNS server from the at least one DNS server according to the encryption capability information of the at least one DNS server, where the encryption capability of the first DNS server matches the encryption capability supported by the device, and the DNS encryption capability supported by the device is the capability of the device to encrypt DNS information; The processing unit is further configured to initiate a DNS query to the first DNS server.

35. The device according to claim 34, characterized in that, The DNS encryption capability includes supported DNS encryption protocols, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP) protocol.

36. A server selection device, characterized in that, Comprising: A processing unit and a communication unit The processing unit is configured to determine the encryption capability information of at least one DNS server; The encryption capability information of the at least one DNS server includes the capability of the at least one DNS server to encrypt DNS information, and the at least one DNS server is determined by the device and is a DNS server capable of providing services to the terminal device; The communication unit is configured to send the encryption capability information of the at least one DNS server to the terminal device.

37. The device according to claim 36, characterized in that, The encryption capability information further includes the DNS encryption protocols supported by the at least one DNS server, and the DNS encryption protocols include at least one of the following: Transport Layer Security (TLS) protocol; Hypertext Transfer Protocol (HTTP) protocol.

38. The device according to any one of claims 20, 21, 25, 26, 30 to 37, characterized in that, The first network element is a session management function network element or an edge configuration server or a policy control function network element.

39. A server selection device, characterized in that, Comprising: A processor and a memory The memory is configured to store computer programs or instructions; The processor is configured to execute the computer programs or instructions in the memory, so that the method described in any one of claims 1-5 is executed or the method described in any one of claims 6-10 or the method described in any one of claims 11-12 or the method described in any one of claims 13-14 or the method described in any one of claims 15-16 or the method described in any one of claims 17-19 is executed.

40. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are called by the computer, the computer is caused to execute the method described in any one of claims 1-5 or execute the method described in any one of claims 6-10 or execute the method described in any one of claims 11-12 or execute the method described in any one of claims 13-14 or execute the method described in any one of claims 15-16 or execute the method described in any one of claims 17-19.

Citation Information

Patent Citations

  • Method for hiding DNS domain name of server accessed by mobile phone APP

    CN111262881A