Domain name lookup methods, systems, devices, communication equipment, and storage media

By switching to a third server in the local domain name system for a second recursive query, the problem of manual configuration required for traditional domain name query methods is solved, achieving automatic switching and improving the efficiency and reliability of domain name queries.

CN117135141BActive Publication Date: 2026-01-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311089486.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-28
Publication Date
2026-01-06
Estimated Expiration
2043-08-28

AI Technical Summary

Technical Problem

Traditional domain name lookup methods cannot automatically switch to a different lookup method after a domain name risk is detected, requiring manual configuration and resulting in unreliable domain name resolution.

Method used

After receiving a domain name query from the first server in the local domain name system, if the first recursive query fails, based on the pre-established binding relationship between the protected domain name and the security domain name, the system switches to initiating a second recursive query to the third server, and uses the result of the second recursive query as the query result of the protected domain name, thereby achieving automatic query switching.

Benefits of technology

It enables automatic switching of domain name queries, avoiding manual configuration and improving the efficiency and reliability of domain name queries and resolution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117135141B_ABST
    Figure CN117135141B_ABST
Patent Text Reader

Abstract

This application relates to a domain name query method, system, apparatus, communication device, storage medium, and computer program product. Applied to a local domain name system, the method includes: receiving a domain name query from a first server for a protected domain name; initiating a first recursive query to a second server; if the first recursive query fails, initiating a second recursive query to a third server based on a pre-established binding relationship between the protected domain name and the security domain name; and using the result of the second recursive query as the query result for the protected domain name; wherein the security domain name is a controllable domain name with a higher level than the protected domain name; and wherein both the second and third servers are deployed within a controllable network. This achieves automatic switching of query methods for domain name queries, avoids the need for manual query steps, improves the efficiency of domain name queries, and helps improve the reliability of domain name resolution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a domain name query method, system, device, communication equipment, storage medium, and computer program product. Background Technology

[0002] Internet services use domain name resolution as the first step in service access. If domain name resolution is incorrect or unavailable, it can severely impact these services. With the development of cybersecurity technology, to address domain name security issues, operators have begun offering domain name protection services. These services ensure rapid correction of domain names when services become unavailable due to hijacking or misoperation, using APIs (Application Programming Interfaces), WeChat, and other services.

[0003] In traditional technologies, when a domain name cannot yield results using conventional query methods, manual configuration is required, making it difficult to automatically switch query methods based on risk assessment. Therefore, there is an urgent need for a method that can automatically switch domain name query methods upon risk detection, without requiring manual domain name configuration again. Summary of the Invention

[0004] This application provides a domain name query method, system, device, communication equipment, storage medium, and computer program product, which can achieve the beneficial effect of automatically switching the domain name query method after domain name risk perception, without the need for manual domain name configuration again.

[0005] Firstly, this application provides a domain name query method applied to a local domain name system, the method comprising:

[0006] Receive a domain name query from the first server for the protected domain name, and initiate a first recursive query to the second server;

[0007] If the first recursive query fails, a second recursive query is initiated to the third server based on the pre-established binding relationship between the protected domain name and the security domain name, and the result of the second recursive query is used as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name;

[0008] Both the second server and the third server are deployed within a controllable network.

[0009] In one embodiment, the step of receiving a domain name query from the first server for the protected domain name and initiating a first recursive query to the second server includes:

[0010] The system receives a domain name query initiated by the first server using a relay domain name; the relay domain name includes the protected domain name.

[0011] Initiate the first recursive query to the second server using the aforementioned relay domain name;

[0012] In this context, the protected domain name in the transit domain name is located after the protected domain name.

[0013] In one embodiment, the step of initiating a second recursive query to a third server based on the pre-established binding relationship between the protected domain name and the security domain name includes:

[0014] Based on the pre-established binding relationship between the protected domain name and the security domain name, the second recursive query is initiated to the third server in the form of a security service subdomain.

[0015] In this context, the protected domain name is used as a subdomain, the security domain name is used as a parent domain, and the protected domain name is located before the security domain name.

[0016] In one embodiment, the method further includes:

[0017] Based on the lifetime of the security service subdomain in the third server, periodically check the flag field parameter of the file synchronization signal corresponding to the security service subdomain;

[0018] When the flag field parameter is the switching flag field parameter, resource record data synchronization is performed to form a binding relationship between the protected domain name and the protected domain name.

[0019] In one embodiment, the step of synchronizing resource record data to establish a binding relationship between the protected domain name and the protected domain name includes:

[0020] Read resource record data from the domain name configuration file of the security service subdomain;

[0021] Update the resource record data into the domain name configuration file of the transit domain name;

[0022] Update the flag field parameter of the file synchronization signal corresponding to the relay domain name to the immediate flag field parameter;

[0023] The immediate flag field parameter indicates that the binding relationship between the protected domain name and the protected domain name is complete.

[0024] In one embodiment, the second recursive query is executed based on the security service subdomain; in the security service subdomain, the protected domain is used as the subdomain, the security domain is used as the parent domain, and the protected domain is located before the security domain.

[0025] The step of using the result obtained from the second recursive query as the query result of the protected domain name includes:

[0026] The parsing result of the query result obtained from the second recursive query is written into the cache as the parsing result of the protected domain name.

[0027] Secondly, this application provides a domain name query system, including a local domain name system, a first server, a second server, and a third server; wherein the second server and the third server are both deployed within a controllable network;

[0028] The local domain name system receives a domain name query from the first server for the protected domain name and initiates a first recursive query to the second server;

[0029] If the first recursive query fails, the local domain name system initiates a second recursive query to the third server based on the pre-established binding relationship between the protected domain name and the security domain name, and uses the result of the second recursive query as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name.

[0030] In one embodiment, the second server executes the first recursive query based on the relay domain name;

[0031] The local domain name system is also used to receive domain name queries initiated by the first server in the form of relay domain names; the relay domain names include the protected domain name;

[0032] The local domain name system is also used to initiate the first recursive query to the second server using the relay domain name method;

[0033] In this context, the protected domain name in the transit domain name is located after the protected domain name.

[0034] In one embodiment, the third server executes the second recursive query based on the security service subdomain;

[0035] The local domain name system is also used to initiate the second recursive query to the third server in the form of a security service subdomain, based on the pre-established binding relationship between the protected domain name and the security domain name;

[0036] In this context, the protected domain name is used as a subdomain, the security domain name is used as a parent domain, and the protected domain name is located before the security domain name.

[0037] In one embodiment, the third server is used to receive the protected domain name input by the user, use the protected domain name as a subdomain and the security domain name as a parent domain name, and generate a security service subdomain that is located before the security domain name of the protected domain name;

[0038] The third server is also used to extend the flag field parameter of the file synchronization signal of the security service subdomain, and add a switching flag field parameter.

[0039] In one embodiment, the local domain name system is further configured to periodically check the flag field parameter of the file synchronization signal corresponding to the security service subdomain based on the lifetime of the security service subdomain in the third server; when the flag field parameter is detected to be a switching flag field parameter, the second server is driven to synchronize resource record data with the third server to form a binding relationship between the protected domain name and the security domain name.

[0040] In one embodiment, the local domain name system is also used for,

[0041] When the flag field parameter is detected to be a switching flag field parameter, resource record data is read from the domain name configuration file of the security service subdomain;

[0042] Update the resource record data into the domain name configuration file of the transit domain name;

[0043] Update the flag field parameter of the file synchronization signal corresponding to the relay domain name to the immediate flag field parameter;

[0044] The immediate flag field parameter indicates that the binding relationship between the protected domain name and the protected domain name is complete.

[0045] In one embodiment, the local domain name system is configured with a file synchronization record parameter monitoring module, and the flag field parameter monitored by the file synchronization record parameter monitoring module includes the switching flag field parameter;

[0046] The file synchronization record parameter monitoring module is used to drive the second server to synchronize the resource record data with the third server through the local domain name system when the flag field parameter of the file synchronization signal in the second server is the switching flag field parameter, thereby forming a binding relationship between the protected domain name and the protected domain name.

[0047] In one embodiment, the second server is further configured to maintain information synchronization between the second server and the third server upon receiving the resource record data from the third server;

[0048] The second server is also configured to transmit at least a portion of the data to the first server upon receiving a data request from the first server, and to maintain information synchronization with the first server.

[0049] In one embodiment, the first server is used to make data requests to the second server in order to maintain information synchronization with the second server.

[0050] In one embodiment, the second recursive query is executed based on the security service subdomain; in the security service subdomain, the protected domain is used as the subdomain, the security domain is used as the parent domain, and the protected domain is located before the security domain.

[0051] The local domain name system is also used to write the parsing result of the query result obtained from the second recursive query into the cache as the parsing result of the protected domain name.

[0052] Thirdly, this application provides a domain name query device applied to a local domain name system, the device comprising:

[0053] The first query module is used to receive domain name queries from the first server for the protected domain name and initiate a first recursive query to the second server.

[0054] The second query module is used to initiate a second recursive query to a third server based on the pre-established binding relationship between the protected domain name and the security domain name when the first recursive query fails, and to use the result of the second recursive query as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name.

[0055] Both the second server and the third server are deployed within a controllable network.

[0056] Fourthly, this application provides a communication device, including a transmitter, a receiver, a processor, and a memory, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0057] Receive a domain name query from the first server for the protected domain name, and initiate a first recursive query to the second server;

[0058] If the first recursive query fails, a second recursive query is initiated to the third server based on the pre-established binding relationship between the protected domain name and the security domain name, and the result of the second recursive query is used as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name;

[0059] Both the second server and the third server are deployed within a controllable network.

[0060] Fifthly, this application provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, performs the following steps:

[0061] Receive a domain name query from the first server for the protected domain name, and initiate a first recursive query to the second server;

[0062] If the first recursive query fails, a second recursive query is initiated to the third server based on the pre-established binding relationship between the protected domain name and the security domain name, and the result of the second recursive query is used as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name;

[0063] Both the second server and the third server are deployed within a controllable network.

[0064] Sixthly, this application provides a computer program product, including a computer program, which, when executed by a processor, performs the following steps:

[0065] Receive a domain name query from the first server for the protected domain name, and initiate a first recursive query to the second server;

[0066] If the first recursive query fails, a second recursive query is initiated to the third server based on the pre-established binding relationship between the protected domain name and the security domain name, and the result of the second recursive query is used as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name;

[0067] Both the second server and the third server are deployed within a controllable network.

[0068] The aforementioned domain name query method, system, device, communication equipment, storage medium, and computer program product, when the first recursive query to the second server fails, switch to a second recursive query to the third server based on the pre-established binding relationship between the protected domain name and the protected domain name. This allows the data information corresponding to the protected domain name to be retrieved from the third server, and the result of the second recursive query is used as the query result for the protected domain name. This achieves automatic switching of the domain name query method, avoids the need for manual assistance in the query process, improves the efficiency of domain name queries, and enhances the reliability of domain name resolution. Attached Figure Description

[0069] Figure 1 This is a schematic diagram of a domain name query system provided in an embodiment of this application;

[0070] Figure 2 An example of a subdomain for the security service provided in this application embodiment;

[0071] Figure 3 This is an example of a transit domain name provided in an embodiment of this application;

[0072] Figure 4 A schematic diagram of another domain name query system provided in this application embodiment;

[0073] Figure 5 A flowchart corresponding to the first embodiment of the domain name query method provided in this application;

[0074] Figure 6 A flowchart corresponding to the second embodiment of the domain name query method provided in this application;

[0075] Figure 7 A flowchart corresponding to the third embodiment of the domain name query method provided in this application;

[0076] Figure 8 A flowchart corresponding to the fourth embodiment of the domain name query method provided in this application;

[0077] Figure 9 A flowchart corresponding to the fifth embodiment of the domain name query method provided in this application;

[0078] Figure 10 A flowchart corresponding to the sixth embodiment of the domain name query method provided in this application;

[0079] Figure 11 A flowchart corresponding to the seventh embodiment of the domain name query method provided in this application;

[0080] Figure 12 A schematic diagram of a domain name query device provided in this application;

[0081] Figure 13 Another schematic diagram of the domain name query device provided in this application;

[0082] Figure 14 This is an internal structure diagram of a communication device provided in an embodiment of this application. Detailed Implementation

[0083] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0084] Traditional domain name protection technologies all require manual configuration of DNS (Domain Name System) caches after domain risk is detected. This might involve the domain owner promptly modifying the IP (Internet Protocol) configuration of network devices at the domain hosting provider, or modifying the Local DNS (local DNS system) configuration (usually indirectly through the ISP). The Local DNS then resolves recursive queries, directing them to the protection server. This makes automatic domain name protection difficult. Even when the risk is mitigated, existing domain name protection still requires manual configuration, hindering automatic switching based on the risk situation. Therefore, there is an urgent need for a method that can automatically switch domain query methods after domain risk is detected, without requiring further manual configuration.

[0085] This application provides a domain name query method, system, device, communication equipment, storage medium, and computer program product, which can achieve the beneficial effect of automatically switching the domain name query method after domain name risk perception, without the need for manual domain name configuration again.

[0086] It should be noted that the beneficial effects or technical problems solved by the embodiments of this application are not limited to this one, but may also be other implicit or related problems. For details, please refer to the description of the embodiments below.

[0087] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0088] Figure 1 This is a schematic diagram of a domain name query system provided in an embodiment of this application. Figure 1As shown, the system 100 includes a Local Domain Name System (DNS) 14, a first server (authoritative server) 11, a second server (authoritative sub-server) 12, and a third server (preservation authoritative server) 13. Data transmission between the Local Domain Name System 14 and the first server 11, second server 12, and third server 13 is conducted via a network. Data transmission also occurs between the first server 11 and the second server 12, and between the second server 12 and the third server 13.

[0089] Figure 2 For an example of a subdomain for the preservation service provided in this application embodiment, please refer to... Figure 1 , Figure 2 , Figure 1 , Figure 2 The following example illustrates the process using the protected domain name example.com and the security domain name dnsbak.cn. The third server 13 receives the protected domain name input by the user, uses the protected domain name as a subdomain and the security domain name as a parent domain name, and generates a security service subdomain where the protected domain name precedes the security domain name. The third server 13 is also used to extend the flag field parameter of the file synchronization signal of the security service subdomain by adding a switching flag field parameter. The second server 12 is also used to maintain information synchronization between the second server 12 and the third server 13 when receiving resource record data from the third server 13; enabling the transmission of information related to the protected domain name input by the user to the third server 13 from the third server 13 to the second server 12; the second server 12 is also used to transmit at least part of the data to the first server 11 when receiving a data request from the first server 11, maintaining information synchronization with the first server 11; specifically, when the second server 12 receives a data request from the first server 11, it synchronizes the information related to the protected domain name input by the user, stored in the second server 12, to the first server 11, so that the protected domain name updated by the user on the third server 13 can be updated to the first server 11 after passing through the second server 12. That is, the first server 11 is used to make data requests to the second server 12 to maintain information synchronization with the second server 12; so that the first server 11 can include the protected domain name input by the user. The domain name query system provided in this application can, when a user has a need, realize the transmission and update of the protected domain name entered by the user to the third server 13 through the second server 12 to the first server 11 when the user communicates with the third server 13, the second server 12, and the first server 11.

[0090] Furthermore, the third server 13 can update the protected domain name in the security sub-server within the third server based on the modified protected domain name submitted by the control device (not shown). The control device and the third server 13 are interconnected via a wireless or wired network connection. The control device can provide a user interface for domain name users to perform various interactive operations. Here, a domain name user refers to the owner of the domain name. In one practical application, the control device can display the user interface in the form of a WEB (World Wide Web) page, where domain name users can perform input, selection, and other interactive operations. Of course, the control device can also display the user interface in other forms, such as an APP (Application), which is not limited in this embodiment.

[0091] Based on the domain name query system 100 provided in this application, which includes the aforementioned local domain name system 14, first server 11, second server 12, and third server 13, an alternative implementation method is provided: the local domain name system 14 receives a domain name query from the first server 11 for the protected domain name and initiates a first recursive query to the second server 12; if the first recursive query fails, the local domain name system 14 initiates a second recursive query to the third server 13 based on the pre-established binding relationship between the protected domain name and the security domain name, and uses the result of the second recursive query as the query result for the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name.

[0092] Specifically, the local domain name system 14 receives a domain name query from the first server 11 for the protected domain name, and then initiates a first recursive query to the second server 12 to obtain the relevant query results of the protected domain name from the second server 12. If no relevant query results of the protected domain name are found from the authoritative sub-server 12, it indicates that the first recursive query has failed. In the case of failure of the first recursive query, the local domain name system 14 can switch to initiating a second recursive query to the third server 13 based on the pre-established binding relationship between the protected domain name and the security domain name. The third server 13 receives the protected domain name input by the user. Therefore, if no query results are obtained from the domain name query to the first server 11 and the first recursive query to the second server 12, the system can switch to querying the domain name to the third server 13 and use the result of the second recursive query as the query result of the protected domain name, and then write the query result into the cache.

[0093] It should be added that the domain name query system 100 provided in this application can optionally deploy the second server 12 and the third server 13 within a controllable network. This allows users to query the protected domain name on the third server 13 within the controllable network if the protected domain name cannot be found on the first server 11. This ensures the reliability of authoritative services for ordinary domain names (such as domain names registered abroad) and guarantees the reliability of domain name resolution in extreme cases. These extreme cases may include the first server 11 storing the protected domain name but not providing domain name information feedback to the local domain name system 14; or the corresponding protected domain name on the first server 11 being maliciously tampered with.

[0094] It should be added that, such as Figure 1 , Figure 2 As shown, the domain names on the first server 11 end in .com, and the domain names on the third server 13 end in .cn. .com is not a fully controllable top-level domain, and its domain name server IP (Internet Protocol) may reside on an unreliable network. This application provides the third server 13, deploying it within a controllable network, and requires it to use a controllable top-level domain, such as .cn. Then, by having the user input the protected domain name on the third server 13 and matching it with the protected domain names ending in .cn on the third server 13, the application obtains domain names ending in .cn that include the protected domain name, thus achieving domain name protection. Furthermore, the domain names on the second server 12 end in .com, and the second server 12 can also be deployed within a fully controllable network. Through the domain name query system 100 provided above, this application can achieve domain name protection without adjusting the deployment location of the servers corresponding to .com domain names.

[0095] Among them, any two parties transmitting data over the network can choose to connect via a mobile network, which can be any of the following: 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, or even new network standards that will emerge in the future.

[0096] Any one of the first server 11, the second server 12, and the third server 13 can be a conventional server, a cloud server, a cloud host, a virtual center, or other server equipment.

[0097] Figure 3 For an example of a relay domain name provided in the embodiments of this application, please refer to... Figures 1-3 In one embodiment, the second server 12 performs a first recursive query based on the relay domain name;

[0098] The local domain name system 14 is also used to receive domain name queries initiated by the first server 11 in the form of relay domain names; the relay domain names include protected domain names;

[0099] The local domain name system 14 is also used to initiate a first recursive query to the second server 12 via a relay domain name;

[0100] Among them, the protected domain name in the transit domain name is located after the protected domain name.

[0101] Specifically, in the 100 provided in this application, the second server 12 executes the first recursive query based on a relay domain name. The relay domain name includes a protected domain name and, in addition to the protected domain name, a security domain name. The protected domain name follows the security domain name in the relay domain name. The local domain name system 14 provided in this application can also be used to receive domain name queries initiated by the first server 11 using a relay domain name. Since the relay domain name is formed in the second server 12, the local domain name system 14 can initiate a first recursive query to the second server 12 using a relay domain name to query the relay domain name. When a corresponding relay domain name is found in the second server 12, the protected domain name in the relay domain name is the domain name that the local domain name system 14 wants to query. When a corresponding relay domain name is not found in the second server 12, the query fails.

[0102] This application is based on the second server 12, which includes a relay domain formed by the protected domain and the security domain, which are updated under specific circumstances. By initiating a first recursive query to the second server 12 using the relay domain, the application can query the protected domain if the relay domain includes the protected domain to be queried. This improves the query efficiency of the protected domain and avoids the inability to query the protected domain through other means if the protected domain cannot be found on the first server 11.

[0103] Please refer to Figures 1-3 In one embodiment, the third server 13 performs a second recursive query based on the security service subdomain;

[0104] The local domain name system 14 is also used to initiate a second recursive query to the third server 13 in the form of a security service subdomain, based on the pre-established binding relationship between the protected domain name and the security domain name;

[0105] In this system, the protected domain is the subdomain of the security service, and the security domain is the parent domain. The protected domain is located before the security domain.

[0106] It should be noted that the third server 13 provided in this application is used to store the security service subdomain. The security service subdomain includes the protected domain and the security domain. The protected domain in the security service subdomain is the subdomain and the security domain is the parent domain. That is, the protected domain in the security service subdomain is located before the security domain. Therefore, the third server 13 provided in this application can perform a second recursive query based on the security service subdomain to obtain the query information related to the protected domain written by the user in the third server 13 through the second recursive query.

[0107] Based on this, if the local domain name system 14 cannot find the corresponding transit domain name in the second server 12, the local domain name system 14 can also be used to switch the query direction to the third server 13 based on the pre-established binding relationship between the protected domain name and the security domain name, and initiate a second recursive query to the third server 13 in the form of a security service subdomain. The relevant information of the protected domain name to be queried can be obtained through the security service subdomain corresponding to the protected domain name to be queried, which is obtained through the second recursive query. The security service subdomain obtained by the second recursive query can be used as the query result of the protected domain name.

[0108] In other words, this application achieves automatic switching of domain name queries by switching the query method to execute a second recursive query when the first recursive query fails, that is, when the required protected domain name cannot be found in the first server 11 and the corresponding second server 12, or when the first server 11 and the corresponding second server 12 cannot provide the required protected domain name to the local domain name system 14. This allows the required protected domain name to be queried in the third server 13, avoiding the need for manual querying steps, improving the efficiency of domain name queries, and helping to improve the reliability of domain name resolution.

[0109] Please continue to refer to Figures 1-3 In one embodiment, the local domain name system 14 is also used to periodically check the flag field parameter of the file synchronization signal corresponding to the security service subdomain based on the lifetime of the security service subdomain in the third server 13; when the flag field parameter is detected to be a switching flag field parameter, the second server 12 is driven to synchronize the resource record data with the third server 13 to form a binding relationship between the protected domain name and the security domain name.

[0110] Specifically, this application also provides an alternative implementation method in which the local domain name system 14 is further used to periodically check the flag field parameter (Flags, flag Segment) of the file synchronization signal (CSYCN) corresponding to the security service subdomain based on the life-to-life of the security service subdomain in the third server 13. Here, this application does not specifically limit the periodic time; for example, it can choose to periodically check the flag field parameter of the file synchronization signal corresponding to the security service subdomain at an average of 3, 4, or 5 times during the life-to-life of the security service subdomain in the third server 13. When the local domain name system 14 detects that the flag field parameter is a switching flag field parameter, it indicates that the corresponding protected domain name has been updated by the user in the third server 13, and it is necessary to synchronize the information of this modified protected domain name to the second server 12. At this time, the second server 12 can be driven to synchronize resource record data with the third server 13 to form a binding relationship between the protected domain name and the security domain name in the second server 12, that is, to realize the update of the transit domain name in the second server 12.

[0111] The above steps enable the security service subdomains obtained after the user updates the protected domain in the third server 13 to be updated on the second server 12 on a regular basis. This allows the security service subdomains updated by the user in the third server 13 to be synchronized to the second server 12 on a regular basis, which is beneficial for the real-time update of the user's modified protected domain and improves the update efficiency of the user's modified protected domain.

[0112] Please continue to refer to Figures 1-3 In one embodiment, the local domain name system 14 is also used for,

[0113] When the flag field parameter is detected to be a switch flag field parameter, resource record data is read from the domain configuration file of the security service subdomain;

[0114] Update the resource record data into the domain configuration file of the transit domain;

[0115] Update the flag field parameter of the file synchronization signal corresponding to the relay domain name to the immediate flag field parameter;

[0116] The immediate flag field parameter indicates that the binding relationship between the protected domain name and the protected domain name is complete.

[0117] Specifically, the ontology domain name system provided in this application is also used to perform the following operations when the flag field parameter is detected to be the switching flag field parameter: read the corresponding resource record data from the domain name configuration file of the security service subdomain, and then update the read resource record data into the domain name configuration file of the transit domain, so as to realize the synchronization of the information of the security service subdomain updated by the user to the transit domain. In this way, the flag field parameter of the file synchronization signal corresponding to the transit domain can be updated to the immediate flag field parameter. When the flag field parameter of the file synchronization signal corresponding to the transit domain is updated to the immediate flag field parameter, it also indicates that the binding relationship between the protected domain name and the security domain name in the second server 12 is completed, so that the first server 11, which is connected to it, can know the message that the transit domain name in the second server 12 has been updated.

[0118] This application, through the above steps, enables the updating of the preservation service subdomain obtained after the user updates the protected domain name in the third server 13, and the updating in the second server 12. This allows the preservation service subdomain updated by the user in the third server 13 to be synchronized with the second server 12, ensuring the update of the user's modified protected domain name in the second server 12, which is connected to the third server 13. At the same time, it also enables the first server 11, which is connected to the second server 12, to know the completion of the binding relationship between the protected domain name and the preservation domain name in the relay threshold. This allows the first server 11 to promptly obtain and update the user-modified protected threshold in the second server 12, thereby improving the query efficiency of the local domain name system 14 for the target domain name and also facilitating the preservation of the target domain name.

[0119] Figure 4 This is a schematic diagram of another domain name query system provided in the embodiments of this application. Please continue to refer to it. Figures 1-4 In one embodiment, a file synchronization record parameter monitoring module 141 is configured on the local domain name system 14, and the flag field parameters monitored by the extended file synchronization record parameter monitoring module 141 include the switching flag field parameter.

[0120] The file synchronization record parameter monitoring module 141 is used to drive the second server 12 to synchronize resource record data with the third server 13 through the local domain name system 14 when the flag field parameter of the file synchronization signal in the second server 12 is detected to be the switching flag field parameter, thereby forming a binding relationship between the protected domain name and the protected domain name.

[0121] Specifically, this application also provides an alternative implementation method in which a CSYNC parameter monitoring module (file synchronization record parameter monitoring module 141) is deployed on the local domain name system 14, and the flag field parameters of the CSYNC parameter monitoring module are extended to include a switching flag field parameter, so that the CSYNC parameter monitoring module can be used to monitor the switching flag field parameter; specifically, the CSYNC parameter monitoring module is used to monitor the flag field parameters of the file synchronization signal in the second server 12. When the flag field parameter is detected to be a switching flag field parameter, the local domain name system 14 can drive the second server 12 to synchronize resource record data with the third server 13, so as to form a binding relationship between the protected domain name and the protected domain name in the second server 12, that is, to realize the update of the transit domain name in the second server 12.

[0122] By configuring a CSYNC parameter monitoring module on the local domain name system 14, the system monitors the switching flag field parameter of the file synchronization signal in the second server 12. Based on the monitoring results, a binding relationship is formed between the protected domain name and the security domain name. This enables the security service subdomain name updated by the user in the third server 13 to be synchronized to the second server 12 according to the switching flag field parameter in the second server 12. This facilitates the timely update of the user's modified protected domain name and improves the update efficiency of the user's modified protected domain name.

[0123] Please refer to Figures 1-3 In one embodiment, the second recursive query is executed based on the security service subdomain; in the security service subdomain, the protected domain is used as the subdomain and the security domain is used as the parent domain, with the protected domain preceding the security domain;

[0124] The local domain name system 14 is also used to write the resolution result of the query result obtained from the second recursive query into the cache as the resolution result of the protected domain name.

[0125] Specifically, this application also provides an alternative implementation method in which, after the second recursive query is executed based on the security service subdomain, the local domain name system 14 can write the resolution result of the query result obtained by the second recursive query as the resolution result of the protected domain name into the cache; wherein, the query result is specifically the security service subdomain that is located before the security domain name after the user-modified protected domain name. Since the security service subdomain includes the user-modified protected domain name, the user-modified protected domain name is the domain name that the local domain name system 14 wants to query. Therefore, by obtaining the security service subdomain, the corresponding protected domain name can be obtained from it.

[0126] Based on the above, the 100 provided in this application treats the protected domain name as a subdomain of a high-level, secure parent domain name (security domain name). When the protected domain name cannot be resolved through the first recursive query, the system switches to resolving the subdomain of the security service that matches the protected domain name, ensuring the reliability of domain name resolution in extreme cases. Furthermore, this application, by configuring a CSYNC parameter monitoring module in the local domain name system 14 and extending the DNS domain name resolution parameter CSYNC, achieves the association between low-level and high-level secure domain names, i.e., the association between the protected domain name and the security domain name, thus ensuring the security of the protected domain name. Moreover, by extending the DNS domain name resolution parameters, it also achieves automatic switching between the first and second recursive queries, enabling automatic domain name query switching and improving the efficiency of domain name queries.

[0127] It should be added that the flag field parameters involved in this application can be set to 0x000x01: "immediate" to indicate the immediate flag field parameter, and set to 0x000x04: "reverse" to indicate the toggle flag field.

[0128] One alternative implementation is that the domain name query system 100 provided in this application includes a security authority server (third server 13) responsible for maintaining the domain name data of the security service and for expanding the CSYNC data of the security service subdomains corresponding to the security domains. Furthermore, the Flags parameter can be expanded on the CSYNC format defined in RFC7477 so that the parameter at least includes 0x000x01: "immediate", i.e., the immediate flag field parameter, and 0x000x04: "reverse", i.e., the reverse flag field parameter. RFC7477 refers to child-to-parent synchronization in DNS. The standard [RFC7477] specifies an RRType (Resource Record Type) and a protocol to signal and synchronize changes to resource records such as NS from child to parent zones. NS (Name Server), i.e., the DNS NS record, is used for authorization, delegating downwards, and specifying which DNS server should resolve the domain name.

[0129] The authoritative sub-server (second server 12), also known as the relay domain name server, is responsible for maintaining and preserving the synchronization with the authoritative server (first server 11). Additionally, it can be expanded with a CSYNC monitoring module to periodically check the corresponding domain's CSYNC flags based on the domain's TTL time. When the flags show "0x000x04", DNS RRs (Resource Records) data synchronization is required. The DNS RRs data synchronization process involves the following steps: First, reading DNS data from the example.com.dnsbak.cn domain's Zone (configuration) file; second, updating the DNS data in the dnsbak.cn.example.com domain's Zone file; and third, updating the dnsbak.cn.example.com domain's CSYNC to 0x000x01.

[0130] The protected domain name authority server (first server 11) is used to monitor CSYNC. When the Flags show "0x000x01", DNS RRs data synchronization needs to be performed. DNS RRs data synchronization performs standard synchronization operations.

[0131] This invention also provides an automatic switching process for the protected domain name. To achieve automatic recursive query switching of the protected domain name, a "CSYNC extended parameter monitoring and resolution module" has been added to the Local DNS. The main functions of this module are as follows: it supports the resolution of extended CSYNC parameters; when the authoritative sub-server (relay domain name server) indicates 0x000x04: "reverse" for CSYNC, the Local DNS needs to form a binding relationship between the protected domain name and the protected domain name based on this parameter; when the authoritative server of the protected domain name cannot resolve it, the Local DNS queries the authoritative server of the protected domain name based on the binding relationship.

[0132] Figure 5 The flowchart corresponds to the first embodiment of the domain name query method provided in this application. Figure 6 The flowchart corresponding to the second embodiment of the domain name query method provided in this application can be found in conjunction with... Figures 1-4 Reference Figures 5-6 Based on the same inventive concept, this application also provides a domain name query method, which is adopted by the local domain name system 14, and the method includes the following steps:

[0133] Step 101: Receive the domain name query from the first server 11 for the protected domain name, and initiate the first recursive query to the second server 12.

[0134] Specifically, the domain name query method provided in this application includes at least steps 101 and 102. Step 101 is used to receive a domain name query from the first server 11 for the protected domain name, and then initiate a first recursive query to the second server 12 to obtain relevant query results for the protected domain name from the second server 12. If no relevant query results for the protected domain name are found from the authoritative sub-server, it indicates that the first recursive query has failed. Therefore, the domain name query method provided in this application can not only perform a domain name query from the first server 11 via step 100, but also initiate a first recursive query to the second server 12, increasing the number of domain name query methods and improving the efficiency of domain name query.

[0135] Step 102: If the first recursive query fails, based on the pre-established binding relationship between the protected domain name and the security domain name, a second recursive query is initiated to the third server 13, and the result of the second recursive query is used as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name.

[0136] Both the second server 12 and the third server 13 are deployed within a controllable network.

[0137] Following step 101, step 102 is executed. Specifically, if the first recursive query fails, based on the pre-established binding relationship between the protected domain name and the security domain name, a second recursive query is initiated to the third server 13. The third server 13 receives the protected domain name input by the user. Therefore, if no query result is obtained from the domain name query to the first server 11 and the first recursive query to the second server 12, the query can be switched to the third server 13, and the result obtained from the second recursive query is used as the query result for the protected domain name. This query result can then be written to the cache. The domain name query method provided in this application, when the protected domain name cannot obtain a query result through the first recursive query, switches to executing a second recursive query on the third server 13 to obtain the associated query result for the protected domain name in the third server 13, and then uses it as the query result for the protected domain name, ensuring reliable domain name resolution query in extreme cases. Extreme cases may include the first server 11 storing the protected domain name but not providing domain name information feedback to the local domain name system 14; or the corresponding protected domain name in the first server 11 being maliciously tampered with. It should be noted that this application only provides two examples of extreme cases, but this application is not limited to these. Problems where the local domain name system 14 cannot obtain the query results of the protected domain name from the first server 11 due to other reasons can also be classified as extreme cases.

[0138] It should be added that, in the 100 provided in this application, the second server 12 and the third server 13 can be deployed within a controllable network. This allows users to query the protected domain name on the third server 13 within the controllable network when the protected domain name cannot be found on the first server 11. This ensures the reliability of authoritative services for ordinary domain names (such as domain names registered abroad) and guarantees the reliability of domain name resolution in extreme cases. These extreme cases may include the first server 11 storing the protected domain name but not providing domain name information feedback to the local domain name system 14; or the corresponding protected domain name on the first server 11 being maliciously tampered with. It should be noted that this application only provides two examples of extreme cases, but it is not limited to these. Problems where the local domain name system 14 cannot obtain query results for the protected domain name from the first server 11 due to other reasons can also be classified as extreme cases.

[0139] Figure 7 The flowchart corresponding to the third embodiment of the domain name query method provided in this application can be found in conjunction with... Figures 1-4 Reference Figure 5 , Figure 7 In one embodiment, step 101 above, receiving a domain name query from the first server 11 for the protected domain name and initiating a first recursive query to the second server 12, includes:

[0140] Step 111: Receive a domain name query initiated by the first server 11 using a relay domain name; the relay domain name includes the protected domain name;

[0141] Step 112: Initiate the first recursive query to the second server 12 using the relay domain name method;

[0142] Among them, the protected domain name in the transit domain name is located after the protected domain name.

[0143] Specifically, since the second server 12 provided in this application executes the first recursive query based on a relay domain name, wherein the relay domain name includes the protected domain name and, in addition to the protected domain name, also includes the security domain name, and the protected domain name is located after the security domain name in the relay domain name, the above step 101 can specifically include steps 111 and 112. Step 111 is used to receive the domain name query initiated by the first server 11 using the relay domain name. Since the relay domain name is formed in the second server 12, step 112 can further execute the local domain name system 14 to initiate the first recursive query to the second server 12 using the relay domain name, so as to query the relay domain name in the second server 12. When the corresponding relay domain name is found in the second server 12, the protected domain name in the relay domain name is the domain name that the local domain name system 14 wants to query. When the corresponding relay domain name is not found in the second server 12, the query fails.

[0144] This application is based on the second server 12, which includes a relay domain formed by the protected domain and the security domain, which are updated under specific circumstances. By initiating a first recursive query to the second server 12 using the relay domain, the application can query the protected domain if the relay domain includes the protected domain to be queried. This improves the query efficiency of the protected domain and avoids the inability to query the protected domain through other means if the protected domain cannot be found on the first server 11.

[0145] Figure 8 The flowchart corresponding to the fourth embodiment of the domain name query method provided in this application can be found in conjunction with... Figures 1-4 Reference Figure 5 , Figure 8 In one embodiment, step 102, which includes initiating a second recursive query to the third server 13 based on the pre-established binding relationship between the protected domain name and the security domain name, includes:

[0146] Step 121: Based on the pre-established binding relationship between the protected domain name and the security domain name, initiate a second recursive query to the third server 13 in the form of a security service subdomain.

[0147] In this system, the protected domain is the subdomain of the security service, and the security domain is the parent domain. The protected domain is located before the security domain.

[0148] Specifically, since the third server 13 provided in this application is used to store the security service subdomain, which includes the protected domain and the security domain, with the protected domain as the subdomain and the security domain as the parent domain, meaning the protected domain precedes the security domain. Therefore, when initiating a second recursive query to the third server 13 based on the pre-established binding relationship between the protected domain and the security domain in step 102, specifically through step 121, a second recursive query is initiated to the third server 13 using the security service subdomain, based on the pre-established binding relationship between the protected domain and the security domain. This allows obtaining relevant information about the protected domain by including the security service subdomain corresponding to the protected domain to be queried. The security service subdomain obtained from the second recursive query can then be used as the query result for the protected domain.

[0149] In other words, this application achieves automatic switching of domain name queries by switching the query method to execute a second recursive query when the first recursive query fails, that is, when the required protected domain name cannot be found in the first server 11 and the corresponding second server 12, or when the first server 11 and the corresponding second server 12 cannot provide the required protected domain name to the local domain name system 14. This allows the required protected domain name to be queried in the third server 13, avoiding the need for manual querying steps, improving the efficiency of domain name queries, and helping to improve the reliability of domain name resolution.

[0150] Figure 9 The flowchart corresponding to the fifth embodiment of the domain name query method provided in this application can be found in conjunction with... Figures 1-4 Reference Figure 5 , Figure 9 In one embodiment, the domain name query method further includes:

[0151] Step 103: Based on the lifetime of the security service subdomain in the third server 13, periodically check the flag field parameter of the file synchronization signal corresponding to the security service subdomain;

[0152] Step 104: When the flag field parameter is the switch flag field parameter, perform resource record data synchronization to form a binding relationship between the protected domain name and the security domain name.

[0153] Specifically, the domain name query method provided in this application also includes steps 103 and 104. Step 103 is used to periodically check the flag field parameter of the file synchronization signal corresponding to the security service subdomain based on the lifespan of the security service subdomain in the third server 13. Here, this application does not specify the specific time for periodic checks. For example, the flag field parameter of the file synchronization signal corresponding to the security service subdomain can be checked periodically at 3, 4, or 5 times during the lifespan of the security service subdomain in the third server 13. Then, step 104 is used to detect that the flag field parameter is a switching flag field parameter in the local domain name system 14, which means that the corresponding protected domain name has been updated by the user in the third server 13. It is necessary to synchronize the information of this modified protected domain name to the second server 12. At this time, the second server 12 can be driven to synchronize the resource record data with the third server 13 to form a binding relationship between the protected domain name and the security domain name in the second server 12, that is, to realize the update of the transit domain name in the second server 12.

[0154] This application achieves, through the above steps, the preservation service subdomain obtained after the user updates the protected domain name in the third server 13, and updates it in the second server 12 on a regular basis. This allows the preservation service subdomain updated by the user in the third server 13 to be synchronized to the second server 12 on a regular basis, which is beneficial for the real-time update of the user's modified protected domain name and improves the update efficiency of the user's modified protected domain name.

[0155] Figure 10 The flowchart corresponding to the sixth embodiment of the domain name query method provided in this application can be found in conjunction with... Figures 1-4 Reference Figure 5 , Figure 10 In one embodiment, step 104, which includes synchronizing resource record data to form a binding relationship between the protected domain name and the security domain name, includes the following steps:

[0156] Step 141: Read resource record data from the domain name configuration file of the security service subdomain;

[0157] Step 142: Update the resource record data into the domain configuration file of the transit domain;

[0158] Step 143: Update the flag field parameter of the file synchronization signal corresponding to the relay domain name to the immediate flag field parameter;

[0159] The immediate flag field parameter indicates that the binding relationship between the protected domain name and the protected domain name is complete.

[0160] Specifically, in step 104, when the flag field parameter is the switching flag field parameter, steps 141-143 can be further executed. Step 141 is used to read the corresponding resource record data from the domain name configuration file of the security service subdomain, and then update the read resource record data into the domain name configuration file of the relay domain through step 141, so as to realize the synchronization of the information of the security service subdomain updated by the user to the relay domain. Then, the flag field parameter of the file synchronization signal corresponding to the relay domain can be updated to the immediate flag field parameter through step 143. When the flag field parameter of the file synchronization signal corresponding to the relay domain is updated to the immediate flag field parameter, it also indicates that the binding relationship between the protected domain name and the security domain name in the second server 12 is completed, so that the first server 11, which is connected to it, can know the message that the relay domain name in the second server 12 has been updated.

[0161] This application, through the above steps, enables the updating of the preservation service subdomain obtained after the user updates the protected domain name in the third server 13, and the updating in the second server 12. This allows the preservation service subdomain updated by the user in the third server 13 to be synchronized with the second server 12, ensuring the update of the user's modified protected domain name in the second server 12, which is connected to the third server 13. At the same time, it also enables the first server 11, which is connected to the second server 12, to know the completion of the binding relationship between the protected domain name and the preservation domain name in the relay threshold. This allows the first server 11 to promptly obtain and update the user-modified protected threshold in the second server 12, thereby improving the query efficiency of the local domain name system 14 for the target domain name and also facilitating the preservation of the target domain name.

[0162] Figure 11 The flowchart corresponding to the seventh embodiment of the domain name query method provided in this application can be found in conjunction with... Figures 1-4 Reference Figure 5 , Figure 11 In one embodiment, the second recursive query is executed based on the security service subdomain; in the security service subdomain, the protected domain is used as the subdomain and the security domain is used as the parent domain, with the protected domain preceding the security domain;

[0163] Step 102, which includes using the result of the second recursive query as the query result for the protected domain name, includes:

[0164] Step 122: The parsing result of the query result obtained from the second recursive query is written into the cache as the parsing result of the protected domain name.

[0165] Specifically, this application also provides an alternative implementation method in which, after the second recursive query is executed based on the security service subdomain, step 122 can be further executed to write the parsing result of the query result obtained by the second recursive query as the parsing result of the protected domain name into the cache; wherein, the query result is specifically the security service subdomain that is located before the security domain name after the user-modified protected domain name. Since the security service subdomain includes the user-modified protected domain name, the user-modified protected domain name is the domain name that the local domain name system 14 wants to query. Therefore, by obtaining the security service subdomain, the corresponding protected domain name can be obtained from it.

[0166] Based on the above, the domain name query method provided in this application treats the protected domain name as a subdomain of a high-level, secure parent domain name (security domain name). When the protected domain name cannot be resolved through the first recursive query, it switches to resolving the subdomain of the security service that matches the security domain name, thereby realizing automatic domain name switching query, which helps to improve the efficiency of domain name query and ensures the reliability of domain name resolution in extreme cases.

[0167] Figure 12 A schematic diagram of the domain name query device provided in this application is shown below. Figures 1-11 Reference Figure 12 Based on the same inventive concept, this application also provides a domain name query device 200, applied to a local domain name system 14, the device comprising:

[0168] The first query module 81 is used to receive the domain name query from the first server 11 for the protected domain name and to initiate the first recursive query to the second server 12;

[0169] The second query module 82 is used to initiate a second recursive query to the third server 13 based on the pre-established binding relationship between the protected domain name and the security domain name when the first recursive query fails, and to use the result of the second recursive query as the query result of the protected domain name; wherein, the security domain name is a controllable domain name, and its level is higher than that of the protected domain name.

[0170] Both the second server 12 and the third server 13 are deployed within a controllable network.

[0171] Specifically, this application also provides a domain name query device 200 applied to a local domain name system 14. This device includes a first query module 81 and a second query module 82. The first query module 81 receives a domain name query from a first server 11 for a protected domain name, and then initiates a first recursive query to a second server 12 to obtain relevant query results for the protected domain name from the second server 12. If no relevant query results for the protected domain name are found from the authoritative sub-server, the first recursive query fails. The second query module 82, in the event of a failed first recursive query, switches to initiating a second recursive query to a third server 13 based on a pre-established binding relationship between the protected domain name and the security domain name. The third server 13 receives the protected domain name input by the user. Therefore, if no query results are obtained from the first recursive query to the first server 11 and the first recursive query to the second server 12, the query can be switched to the third server 13, and the result of the second recursive query can be used as the query result for the protected domain name, which can then be written to a cache. The domain name query method provided in this application, when the protected domain name cannot obtain query results through the first recursive query, switches to executing a second recursive query on the third server 13 to obtain the associated query results for the protected domain name in the third server 13, and then uses these results as the query results for the protected domain name, ensuring reliable domain name resolution query in extreme cases. These extreme cases may include the first server 11 storing the protected domain name but not feeding back the domain name information to the local domain name system 14; or the corresponding protected domain name in the first server 11 being maliciously tampered with. It should be noted that this application only illustrates two examples of extreme cases here, but it is not limited to these. Problems where the local domain name system 14 cannot obtain query results for the protected domain name from the first server 11 due to other reasons can also be classified as extreme cases.

[0172] It should be added that, in the 100 provided in this application, the second server 12 and the third server 13 can be deployed within a controllable network. This allows users to query the protected domain name on the third server 13 within the controllable network when the protected domain name cannot be found on the first server 11. This ensures the reliability of authoritative services for ordinary domain names (such as domain names registered abroad) and guarantees the reliability of domain name resolution in extreme cases. These extreme cases may include the first server 11 storing the protected domain name but not providing domain name information feedback to the local domain name system 14; or the corresponding protected domain name on the first server 11 being maliciously tampered with. It should be noted that this application only provides two examples of extreme cases, but it is not limited to these. Problems where the local domain name system 14 cannot obtain query results for the protected domain name from the first server 11 due to other reasons can also be classified as extreme cases.

[0173] In one embodiment, the first query module 81's action of receiving a domain name query from the first server 11 for the protected domain name and initiating a first recursive query to the second server 12 includes: receiving a domain name query initiated by the first server 11 using a relay domain name through the first query module 81; the relay domain name includes the protected domain name; and initiating a first recursive query to the second server 12 using the relay domain name through the first query module 81; wherein the protected domain name in the relay domain name is located after the protected domain name. See details for further information. Figures 1-5 , Figure 7 and the above regarding Figures 1-5 , Figure 7 Explanation.

[0174] In one embodiment, the second query module 82 initiates a second recursive query to the third server 13 based on the pre-established binding relationship between the protected domain name and the security domain name. This includes: the second query module 82 initiates a second recursive query to the third server 13 using a security service subdomain based on the pre-established binding relationship between the protected domain name and the security domain name; wherein, in the security service subdomain, the protected domain name is the subdomain and the security domain name is the parent domain, with the protected domain name preceding the security domain name. See details for further information. Figures 1-5 , Figure 8 and the above regarding Figures 1-5 , Figure 8 Explanation.

[0175] Figure 13 Another schematic diagram of the domain name query device provided in this application is shown in conjunction with... Figures 1-11 Reference Figure 13In one embodiment, the domain name query device 200 further includes an inspection device 83 and a resource synchronization device 84: the inspection device 83 periodically checks the flag field parameter of the file synchronization signal corresponding to the security service subdomain based on the lifetime of the security service subdomain in the third server 13; the resource synchronization device 84 is used to synchronize resource record data when the flag field parameter is the switching flag field parameter, so as to form a binding relationship between the protected domain name and the security domain name.

[0176] In one embodiment, the resource synchronization device 84 performs resource record data synchronization to form a binding relationship between the protected domain name and the security domain name, including: reading resource record data from the domain name configuration file of the security service subdomain; updating the resource record data into the domain name configuration file of the transit domain name; and updating the flag field parameter of the file synchronization signal corresponding to the transit domain name to an immediate flag field parameter; wherein the immediate flag field parameter indicates that the binding relationship between the protected domain name and the security domain name is complete. See details for further information. Figures 1-5 , Figure 10 and the above regarding Figures 1-5 , Figure 7 Explanation.

[0177] In one embodiment, the third server 13 executes a second recursive query based on the security service subdomain; in the security service subdomain, the protected domain is used as the subdomain and the security domain is used as the parent domain, with the protected domain preceding the security domain; the second query module 82 executes the function of using the result of the second recursive query as the query result of the protected domain, including: writing the parsing result of the query result obtained from the second recursive query as the parsing result of the protected domain into the cache through the second query module 82. For details, please refer to... Figures 1-5 , Figure 11 and the above regarding Figures 1-5 , Figure 11 Explanation.

[0178] Figure 14 This application provides an internal structure diagram of a communication device according to an embodiment. In one embodiment, a communication device 400 is provided. The communication device 400 can be any server or local domain name system, and its internal structure diagram can be as follows. Figure 14As shown, the communication device 400 includes a processor, memory, input / output interfaces (I / O), a transmitter, and a receiver. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor of the communication device 400 provides computing and control capabilities. The memory of the communication device 400 includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The I / O interfaces of the communication device 400 are used for exchanging information between the processor and external devices. The communication interface of the communication device 400 is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements any domain name lookup method.

[0179] Those skilled in the art will understand that Figure 14 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the communication device 400 to which the present application is applied. The specific communication device 400 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0180] Based on the same inventive concept, this application also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the aforementioned domain name query method. The domain name query method is any of the domain name query methods mentioned in the embodiments of this application. For related embodiments, please refer to the above.

[0181] Based on the same inventive concept, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned domain name query method. The domain name query method is any of the domain name query methods mentioned in the embodiments of this application, and related embodiments can be found above.

[0182] It should be noted that the data involved in this application (including but not limited to data used for analysis, data stored, data displayed, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0183] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0184] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0185] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A domain name query method, characterized by, Applied to a local domain name system, the method comprises: receiving a domain name query for a protected domain name initiated by a first server in a transit domain name mode, initiating a first recursive query to a second server in the transit domain name mode; in the case of failure of the first recursive query, initiating a second recursive query to a third server in a security service subdomain name mode based on a pre-established binding relationship between the protected domain name and a security domain name, and taking the result of the second recursive query as the query result of the protected domain name; wherein the security domain name is a controllable domain name, and its level is higher than that of the protected domain name; wherein the second server and the third server are both deployed in a controllable network; wherein the protected domain name is included in the transit domain name, and the protected domain name in the transit domain name is located after the security domain name; the protected domain name in the security service subdomain name is a subdomain name, and the security domain name is a parent domain name, and the protected domain name is located before the security domain name.

2. The domain name query method of claim 1, wherein, The method further comprises: periodically checking a flag field parameter of a file synchronization signal corresponding to the security service subdomain name according to the survival time of the security service subdomain name in the third server; when the flag field parameter is a switching flag field parameter, performing resource record data synchronization to form the binding relationship between the protected domain name and the security domain name.

3. The domain name query method according to claim 2, wherein the resource record data synchronization to form the binding relationship between the protected domain name and the security domain name comprises: reading resource record data from a domain name configuration file of the security service subdomain name; updating the resource record data into a domain name configuration file of the transit domain name; updating the flag field parameter of the file synchronization signal corresponding to the transit domain name to an immediate flag field parameter; wherein the immediate flag field parameter indicates that the binding relationship between the protected domain name and the security domain name is completed.

4. The domain name query method according to claim 1, wherein the result of the second recursive query is taken as the query result of the protected domain name, comprising: writing the analysis result of the query result of the second recursive query into a cache as the analysis result of the protected domain name. The local domain name system, the first server, the second server and the third server are included; wherein the second server and the third server are both deployed in a controllable network; the local domain name system receives a domain name query for a protected domain name initiated by a first server in a transit domain name mode, initiates a first recursive query to a second server in the transit domain name mode; 5. A domain name query system, characterized by, in the case of failure of the first recursive query, the local domain name system initiates a second recursive query to a third server in a security service subdomain name mode based on a pre-established binding relationship between the protected domain name and a security domain name, and takes the result of the second recursive query as the query result of the protected domain name; wherein the security domain name is a controllable domain name, and its level is higher than that of the protected domain name; ​ ​ The transit domain name includes the protected domain name, and the protected domain name is located after the security domain name in the transit domain name; the protected domain name is used as a subdomain name, and the security domain name is used as a parent domain name in the security service subdomain name, and the protected domain name is located before the security domain name.

6. The domain name query system of claim 5, wherein, the third server is configured to receive the protected domain name input by a user, generate a security service subdomain name with the protected domain name as a subdomain name and the security domain name as a parent domain name, and generate the security service subdomain name with the protected domain name located before the security domain name; the third server is further configured to expand a flag field parameter of a file synchronization signal of the security service subdomain name, and add a switching flag field parameter.

7. The domain name query system of claim 5, wherein, the local domain name system is further configured to periodically check a flag field parameter of a file synchronization signal corresponding to the security service subdomain name according to a survival time of the security service subdomain name in the third server; and when the switching flag field parameter is monitored in the flag field parameter, drive the second server to synchronize resource record data between the second server and the third server to form a binding relationship between the protected domain name and the security domain name.

8. The domain name query system of claim 7, wherein, the local domain name system is further configured to, when the switching flag field parameter is monitored in the flag field parameter, read resource record data from a domain name configuration file of the security service subdomain name; update the resource record data into a domain name configuration file of the transit domain name; update a flag field parameter of a file synchronization signal corresponding to the transit domain name to an immediate flag field parameter; and the immediate flag field parameter indicates that the binding relationship between the protected domain name and the security domain name is completed.

9. The domain name query system of claim 7, wherein, a file synchronization record parameter monitoring module is configured on the local domain name system, and the flag field parameter monitored by the file synchronization record parameter monitoring module includes the switching flag field parameter; the file synchronization record parameter monitoring module is configured to, when the flag field parameter of the file synchronization signal in the second server is the switching flag field parameter, drive the second server to synchronize the resource record data between the second server and the third server through the local domain name system to form the binding relationship between the protected domain name and the security domain name.

10. The domain name query system of claim 9, wherein, the second server is further configured to maintain information synchronization between the second server and the third server when the resource record data of the third server is received; the second server is further configured to transmit at least part of data to the first server when the data request of the first server is received, and maintain information synchronization with the first server.

11. The domain name query system of claim 10, wherein, The first server is configured to make a data request to the second server to maintain information synchronization with the second server.

12. The domain name query system of claim 5, wherein, The local domain name system is further configured to write a resolution result of the query result obtained by the second recursive query into a cache as a resolution result of the protected domain name.

13. A domain name query apparatus, characterized by comprising: The apparatus is applied to a local domain name system, and the apparatus comprises: The first query module is configured to receive a domain name query for a protected domain name initiated by a first server in a transit domain name manner, and initiate a first recursive query in the transit domain name manner to a second server; The second query module is configured to, in a case where the first recursive query fails, initiate a second recursive query in a security service subdomain name manner to a third server based on a binding relationship between the protected domain name and a security domain name which is previously established, and take a result obtained by the second recursive query as a query result of the protected domain name; the security domain name is a controllable domain name, and the security domain name has a higher level than the protected domain name. The second server and the third server are both deployed in a controllable network. The transit domain name comprises the protected domain name, and the protected domain name is located behind the security domain name in the transit domain name; in the security service subdomain name, the protected domain name is a subdomain name, and the security domain name is a parent domain name, and the protected domain name is located before the security domain name.

14. A communication device, characterized by The apparatus comprises a transmitter, a receiver, a processor and a memory, the memory stores a computer program, and the processor implements the domain name query method of any one of claims 1-4 when executing the computer program.

15. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the domain name query method of any one of claims 1-4.

16. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the domain name query method of any one of claims 1-4.

Citation Information

Patent Citations

  • Recursive side domain name preservation method and system based on RPZ

    CN115174518A

  • Domain name resolution method and device, equipment and storage medium

    CN115643234A