Domain name resource transmission method, device, computer equipment and readable storage medium

By dividing the domain name resources into multiple file fragments and generating identification password signatures, combined with parallel transmission of multiple transmission channels, the problems of low serial transmission efficiency and insufficient security in the prior art are solved, and efficient and secure domain name resource transmission is achieved.

CN119402301BActive Publication Date: 2025-05-06PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510006422.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-05-06
Estimated Expiration
2045-01-03

AI Technical Summary

Technical Problem

The prior art only supports serial transmission when handling multi-transmission tasks, resulting in the inadequate utilization of system resources, reducing the efficiency of domain name resource transmission, and the serial transmission channel is easily hijacked, reducing the security of transmission.

Method used

A domain name resource transmission method is proposed. By obtaining the domain name resources to be transmitted, it is divided into multiple file fragments to be transmitted, and a identification password signature is generated for each fragment, which is encapsulated into a transmission task. The target transmission channel is determined according to the domain name level, and transmitted in parallel through multiple channels, the receiving node verifies the signature and updates the storage area.

Benefits of technology

It improves the efficiency and security of domain name resource transmission, makes full use of system resources through parallel transmission tasks, increases the difficulty of attacks, and provides higher-level encryption protection for high-level domain name resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402301B_ABST
    Figure CN119402301B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a domain name resource transmission method, device, computer equipment and readable storage medium. The method includes: obtaining a domain name resource to be transmitted; dividing the domain name resource to be transmitted into multiple file segments to be transmitted according to the domain name type, and generating corresponding identification cryptographic signatures; encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task; according to the domain name level corresponding to each transmission task, determining the target transmission channel corresponding to each transmission task from multiple transmission channels; transmitting the corresponding multiple transmission tasks to the corresponding receiving nodes through multiple target transmission channels, so that the receiving node verifies the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending node, and updates the target domain name resource in the corresponding storage area according to the verification results obtained by the verification. In this way, the efficiency and security of domain name resource transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of Internet data transmission, and in particular to a domain name resource transmission method, device, computer equipment and readable storage medium. Background Art

[0002] The Domain Name System (DNS) is a distributed database used to map domain names and Internet Protocol addresses to each other, allowing users to access websites and network services by entering easy-to-remember domain names, ensuring the convenience of Internet operation and communication.

[0003] However, without the consent or legal authorization of the domain name owner, the domain name registry, domain name registrar or any person or organization with access to and control of the domain name system may arbitrarily cancel, delete or modify the domain name resources. These actions may have serious impacts on the domain name owner, including but not limited to service interruption, infringement of rights and interests, and resource loss. Therefore, in order to prevent the above risks, the participants of the domain name system need to establish a safe and reliable domain name exchange channel to ensure the integrity and security of domain name resource data.

[0004] In the related art, when processing multiple transmission tasks, the system only supports serial transmission, that is, only one task can be processed at a time. However, during the transmission process through serial transmission, on the one hand, while waiting for the current task to be completed, other parts of the system may be idle, resulting in insufficient utilization of system resources, thereby reducing the efficiency of domain name resource transmission; on the other hand, if the serial transmission channel is hijacked, the attacker can intercept or tamper with all data transmitted through the channel, resulting in reduced transmission security. Summary of the invention

[0005] The main purpose of the embodiments of the present application is to propose a domain name resource transmission method, apparatus, computer equipment and readable storage medium, which can improve the efficiency and security of domain name resource transmission.

[0006] To achieve the above-mentioned purpose, a first aspect of an embodiment of the present application proposes a domain name resource transmission method, which is applied to a sending node. The method includes:

[0007] Get the domain name resources to be transferred;

[0008] Dividing the domain name resource to be transmitted into a plurality of file segments to be transmitted according to the domain name type, and generating a corresponding identification cryptographic signature for each file segment to be transmitted;

[0009] Encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task;

[0010] According to the domain name level corresponding to each transmission task, a target transmission channel corresponding to each transmission task is determined from multiple transmission channels; different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level;

[0011] The corresponding multiple transmission tasks are respectively transmitted to the corresponding receiving nodes through multiple target transmission channels, so that the receiving nodes verify the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending nodes, and update the target domain name resources in the corresponding storage area according to the verification results.

[0012] Accordingly, a second aspect of an embodiment of the present application proposes a domain name resource transmission device, which is applied to a sending node, and the device includes:

[0013] An acquisition module is used to acquire domain name resources to be transferred;

[0014] A generating module, used to divide the domain name resource to be transmitted into a plurality of file segments to be transmitted according to the domain name type, and generate a corresponding identification cryptographic signature for each file segment to be transmitted;

[0015] An encapsulation module, used for encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task;

[0016] A determination module, used to determine the target transmission channel corresponding to each transmission task from multiple transmission channels according to the domain name level corresponding to each transmission task; wherein different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level;

[0017] A transmission module is used to transmit corresponding multiple transmission tasks to corresponding receiving nodes through multiple target transmission channels, so that the receiving node verifies multiple identification cryptographic signatures in the multiple transmission tasks in sequence according to the identification information shared by the sending node, and updates the target domain name resources in the corresponding storage area according to the verification results obtained.

[0018] In some implementations, the domain name resource transmission device further includes an allocation module, which is used to:

[0019] For each transmission task in each target transmission channel, obtaining a sub-resource allocation index of each transmission task;

[0020] Determining a channel resource allocation index of each target transmission channel according to a sum of multiple sub-resource allocation indexes corresponding to multiple transmission tasks transmitted by each target transmission channel;

[0021] Determining a total resource allocation index according to the sum of multiple channel resource allocation indexes corresponding to the multiple target transmission channels respectively;

[0022] For each target transmission channel, determining the allocated resources of each target transmission channel based on the ratio of the corresponding channel resource allocation index to the total resource allocation index;

[0023] Based on the allocated resources, computing resources are allocated to each target transmission channel.

[0024] In some embodiments, the allocation module is further used to:

[0025] For each transmission task in each target transmission channel, obtaining a preset task weight, a data volume value, and a preset number of retransmissions for each transmission task;

[0026] Determining a data gain of each transmission task according to the number of retransmissions and the task weight;

[0027] The sub-resource allocation index of each transmission task is determined according to the product of the task weight, the data volume value and the data gain.

[0028] In some embodiments, the allocation module is further used to:

[0029] When all the transmission tasks assigned to any one of the first transmission channels have been transmitted, determining a first resource allocation amount released by the first transmission channel;

[0030] According to the channel resource allocation index of at least one second transmission channel that is currently transmitting the transmission task, the first resource allocation amount is allocated to the at least one second transmission channel to obtain a target transmission channel with an updated resource allocation amount.

[0031] In some implementations, the acquisition module is further used to:

[0032] Obtain the full data corresponding to the previous historical transmission time and the initial transmission data corresponding to the current time;

[0033] Taking a data snapshot of the initial transmission data to obtain a snapshot copy corresponding to the initial transmission data;

[0034] Dividing the snapshot copy into a plurality of to-be-verified file fragments according to the domain name type, and performing incremental verification on the plurality of to-be-verified file fragments according to the full data to obtain a verification result;

[0035] According to the verification result, the domain name resource to be transmitted is determined from the initial transmission data.

[0036] In some embodiments, the generating module is further used to:

[0037] Get randomly generated random parameters;

[0038] Generate corresponding system parameters and master keys based on the random parameters through a key generation center; wherein the system parameters are shared parameters of the current sending node among multiple transmission nodes, and the master key is encrypted and stored in the key generation center;

[0039] Obtaining preset identification information, and generating a corresponding target private key according to the identification information, the system parameters and the master key;

[0040] According to each file segment to be transmitted, the system parameters and the target private key, a corresponding identification cryptographic signature is generated for each file segment to be transmitted.

[0041] In some embodiments, the packaging module is further used for:

[0042] Obtaining the data volume value of each file segment to be transmitted;

[0043] Comparing the data volume value with a preset load threshold to obtain a comparison result;

[0044] When the comparison result indicates that the data volume value is greater than the load threshold, the corresponding file fragments to be transmitted are divided into a plurality of file groups to be transmitted according to the alphabetical order of the domain names;

[0045] The multiple files to be transmitted are grouped and encapsulated with the identification cryptographic signature to form a transmission task corresponding to each file segment to be transmitted.

[0046] In some implementations, the determining module is further configured to:

[0047] Calibrate the domain name level of each transmission task according to a pre-calibrated rule to obtain a plurality of transmission tasks associated with different domain name levels;

[0048] According to the multiple transmission tasks associated with different domain name levels, a target transmission channel corresponding to each transmission task is determined from multiple transmission channels.

[0049] Accordingly, a third aspect of an embodiment of the present application proposes a domain name resource transmission method, which is applied to a receiving node. The method includes:

[0050] Acquire multiple transmission tasks corresponding to the transmission of the sending node through multiple target transmission channels;

[0051] According to the identification information shared by the sending node, the multiple identification cryptographic signatures in the multiple transmission tasks are sequentially verified, and the target domain name resource in the corresponding storage area is updated according to the verification result obtained by the verification;

[0052] The target transmission channel corresponding to each transmission task is determined by the sending node from multiple transmission channels according to the domain name level corresponding to each transmission task; the transmission task is obtained by the sending node by encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature; the identification cryptographic signature corresponding to each file segment to be transmitted is obtained by the sending node through the domain name resource to be transmitted, and the domain name resource to be transmitted is divided into multiple file segments to be transmitted according to the domain name type and then generated;

[0053] Among them, different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level.

[0054] Correspondingly, the fourth aspect of the embodiments of the present application proposes a computer device, which includes a memory and a processor, the memory stores a computer program, and the processor implements the domain name resource transmission method described in the embodiment of the first aspect of the present application, or any one of the embodiments of the third aspect of the present application when executing the computer program.

[0055] Correspondingly, the fifth aspect of the embodiments of the present application proposes a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the domain name resource transmission method described in any one of the embodiments of the first aspect of the present application or the third aspect of the present application.

[0056] The embodiment of the present application obtains a domain name resource to be transmitted; divides the domain name resource to be transmitted into multiple file segments to be transmitted according to the domain name type, and generates a corresponding identification cryptographic signature for each file segment to be transmitted; encapsulates each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task; determines a target transmission channel corresponding to each transmission task from multiple transmission channels according to the domain name level corresponding to each transmission task; different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level; transmits the corresponding multiple transmission tasks to the corresponding receiving nodes through the multiple target transmission channels, so that the receiving nodes can verify the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending node, and update the target domain name resources in the corresponding storage area according to the verification results obtained. In this way, multiple transmission channels can be used to allow the simultaneous processing of transmission tasks of multiple different domain name levels, thereby improving the efficiency of system resource transmission; and by building multiple transmission channels, it is more difficult for the attacker to hijack all transmission channels and crack the full resource records, thereby greatly improving the security of the system transmission process. At the same time, each transmission channel supports transmission protocols with different encryption levels, which can enable transmission tasks with high domain name levels to be fully encrypted and protected, further improving the security of the system transmission process. In summary, this application can improve the efficiency and security of domain name resource transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 It is a schematic diagram of the architecture of the domain name resource transmission system provided in an embodiment of the present application;

[0058] Figure 2 is a flowchart of a domain name resource transmission method provided in an embodiment of the present application;

[0059] Figure 3 This is an example diagram of splitting domain name resources to be transmitted provided in an embodiment of the present application;

[0060] Figure 4 This is a flowchart of encryption of file segments to be transmitted provided by an embodiment of the present application;

[0061] Figure 5 This is an example diagram of grouping file fragments to be transmitted provided by an embodiment of the present application;

[0062] Figure 6 This is an example diagram of reallocating released resources provided by an embodiment of the present application;

[0063] Figure 7 is a flowchart of a domain name resource transmission method applied to a receiving node provided in an embodiment of the present application;

[0064] Figure 8 It is an overall flow chart of the domain name resource transmission method provided in the embodiment of the present application;

[0065] Fig. 9 It is a functional module diagram of a domain name resource transmission device provided in an embodiment of the present application;

[0066] Fig.10 It is a schematic diagram of the hardware structure of the computer device provided in the embodiment of the present application. DETAILED DESCRIPTION

[0067] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0068] It should be noted that, although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first", "second", etc. in the specification, claims and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0069] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.

[0070] The Domain Name System (DNS) is a distributed database used to map domain names and Internet Protocol addresses to each other, allowing users to access websites and network services by entering easy-to-remember domain names, ensuring the convenience of Internet operation and communication.

[0071] However, without the consent or legal authorization of the domain name owner, the domain name registry, domain name registrar or any person or organization with access to and control of the domain name system may arbitrarily cancel, delete or modify the domain name resources. These actions may have serious impacts on the domain name owner, including but not limited to service interruption, infringement of rights and interests, and resource loss. Therefore, in order to prevent the above risks, the participants of the domain name system need to establish a safe and reliable domain name exchange channel to ensure the integrity and security of domain name resource data.

[0072] In the related art, when processing multiple transmission tasks, the system only supports serial transmission, that is, only one task can be processed at a time. However, during the transmission process through serial transmission, on the one hand, while waiting for the current task to be completed, other parts of the system may be idle, resulting in insufficient utilization of system resources, thereby reducing the efficiency of domain name resource transmission; on the other hand, if the serial transmission channel is hijacked, the attacker can intercept or tamper with all data transmitted through the channel, resulting in reduced transmission security.

[0073] Based on this, the embodiments of the present application provide a domain name resource transmission method, apparatus, computer equipment and readable storage medium, which can improve the efficiency and security of domain name resource transmission.

[0074] The domain name resource transmission method, apparatus, computer device and readable storage medium provided in the embodiments of the present application are specifically described through the following embodiments. First, the domain name resource transmission system in the embodiments of the present application is described.

[0075] Please refer to Figure 1 In some implementations, an embodiment of the present application provides a domain name resource transmission system, including a sending node 11, a scheduler 12 and a receiving node 13.

[0076] Exemplarily, the sending node can be any server or computer device that needs to publish or update domain name resource data, such as the main server of the corporate headquarters, etc. The sending node can prepare the data file of the domain name resource to be transmitted, and perform necessary preprocessing, such as adding domain name level labels, sorting according to top-level domain information, splitting files, and generating identification cryptographic signatures, etc., and upload the processed file blocks and their identification cryptographic signatures to the scheduler for subsequent transmission.

[0077] In some embodiments, the scheduler can be a centralized management component that can be installed on a computer device, which can be a management node of a server, a data center, or a cloud platform. The scheduler can start multiple transmission channels between the sending node and the receiving node, and is responsible for collecting and managing the transmission tasks of at least one sending node, and performs internal grouping of the transmission tasks according to the received transmission tasks, and then, according to the domain name level of the transmission task, the transmission task is assigned to the corresponding transmission channel for transmission. In some embodiments, the scheduler can also be installed inside the sending node, which is determined according to the actual situation.

[0078] In addition, the scheduler can also be responsible for detecting the operating status of each transmission channel, dynamically adjusting resource allocation, and ensuring high utilization of the system.

[0079] Furthermore, the receiving node can be the party corresponding to the sending node, and the roles of the sending node and the receiving node can be interchangeable. The receiving node can be any server or computer device that can receive domain name resource data updates. For example, the receiving node can be a data center with one or more servers. After receiving the file, the receiver will verify the correctness and integrity of the transmission task through the identification information corresponding to the transmission task, that is, check the signature to confirm that the file has not been tampered with, and update the target domain name resource in the storage area corresponding to the file.

[0080] Next, combine Figure 1 , the domain name resource transmission process is introduced. Exemplarily, the sending node can divide the domain name resource 1 to be transmitted with a domain name level of 1 into file segments to be transmitted (abbreviated as files in the figure) 1-1, file segments to be transmitted 1-2, and file segments to be transmitted 1-3; divide the domain name resource 2 to be transmitted with a domain name level of 2 into file segments to be transmitted 2-1 and file segments to be transmitted 2-2; divide the domain name resource 3 to be transmitted with a domain name level of 3 into file segments to be transmitted 3-1 and file segments to be transmitted 3-2, and after encapsulating each file to be transmitted into a transmission task (abbreviated as files in the figure), upload it to the scheduler together with the corresponding identification password signature. The scheduler can internally group a large amount of files to be transmitted, and transmit them to the corresponding receiving node through multiple pre-opened transmission channels of different domain name levels. After the receiving node verifies the transmission task, it updates the target domain name resource in the corresponding storage area.

[0081] The domain name resource transmission method in the embodiment of the present application can be illustrated by the following embodiment.

[0082] It should be noted that in each specific implementation of the present application, when it comes to the need to perform relevant processing based on data related to user identity or characteristics such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiment of the present application needs to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for enabling the normal operation of the embodiment of the present application will be obtained.

[0083] In the embodiment of the present application, the domain name resource transmission device will be described from the perspective of the domain name resource transmission device, which can be specifically integrated into a computer device. Figure 2 , Figure 2This is a flowchart of the steps of the domain name resource transmission method provided in an embodiment of the present application. The domain name resource transmission method is applied to a sending node. In the embodiment of the present application, a domain name resource transmission device is specifically integrated in a terminal or a server as an example. When the processor on the terminal or the server executes the program instructions corresponding to the domain name resource transmission method, the specific process is as follows:

[0084] Step 101: Obtain the domain name resource to be transmitted.

[0085] In some implementations, in order to prepare and identify data that needs to be transmitted and updated in the network, domain name resources to be transmitted may be obtained to ensure that the domain name system can operate securely, stably, and efficiently.

[0086] The domain name resource to be transmitted may be a set of domain name related data synchronized or updated between a sending node (such as a domain name server or a data center) and a receiving node. The domain name resource to be transmitted includes information on mapping domain names to Internet Protocol addresses, allowing users to access websites and network services through easy-to-remember domain names.

[0087] Exemplarily, both the sending node and the receiving node may be network nodes.

[0088] Furthermore, the domain name resources to be transferred include, but are not limited to, root zone data, important domain name data, Internet Protocol address resource records (providing a mapping relationship between domain names and IPv4 addresses or IPv6 addresses), domain name registration information, and other auxiliary resource records.

[0089] In some implementations, a snapshot of the domain name resource data at the current moment can be taken to obtain a consistent state point, and then the snapshot is compared with the full data at the previous historical transmission moment to determine the changed data, and the changed data is used as the domain name resource to be transmitted.

[0090] In some implementations, the entire file corresponding to the changed data may also be transmitted as the domain name resource to be transmitted. Furthermore, the domain name resource to be transmitted may also be a newly generated file or a file specified by a technician. The embodiments of the present application do not limit the specific method of obtaining the domain name resource to be transmitted.

[0091] The above method helps to ensure the interoperability between different systems and devices, facilitates the synchronization and update of data between different nodes, and also facilitates the subsequent division and transmission of domain name resources to be transmitted.

[0092] In some implementations, in order to reduce unnecessary data transmission and improve transmission efficiency, a snapshot of the initial transmission data may be taken and an incremental check may be performed to identify data that has changed since the last transmission, so that only the changed portion is transmitted to reduce bandwidth usage and optimize resource allocation. For example, step 101 may include:

[0093] (101.1) Obtain the full data corresponding to the previous historical transmission time and the initial transmission data corresponding to the current time;

[0094] (101.2) Taking a data snapshot of the initial transmission data, obtaining a snapshot copy corresponding to the initial transmission data;

[0095] (101.3) Divide the snapshot copy into multiple file shards to be verified according to the domain name type, and perform incremental verification on the multiple file shards to be verified based on the full data to obtain the verification results;

[0096] (101.4) Based on the verification result, determine the domain name resource to be transferred from the initial transmission data.

[0097] Among them, the full data can be a complete set of all domain name resources at the historical transmission time (that is, when the previous successful transmission was completed), which includes all known domain names and their related records, and has been verified and confirmed.

[0098] The initial transmission data may refer to the new version of domain name resource data that needs to be transmitted at the current moment, and the initial transmission data may include a newly added, modified or deleted domain name and its corresponding resource record.

[0099] The snapshot copy may be an instant capture of the state of the initial transmission data at the current moment, and is used to capture all information in the current state.

[0100] The file shards to be verified may be obtained by dividing the snapshot copy into multiple small parts according to certain rules (for example, by domain name type or other classification standards), and each part is called a "file shard".

[0101] The verification result may be a result obtained by comparing the difference between the full data and each file segment to be verified. The verification result may be used to indicate the data that has changed in the file segment to be verified, and may provide a basis for determining the content that needs to be transmitted in the end.

[0102] For example, if sending node A completed the last successful domain name resource data synchronization on January 1, 2024, and on January 2, 2024, sending node A has new domain name resource updates and needs to be sent to other data centers, then January 1, 2024 is the migration history transmission time, and the corresponding domain name resource data is the full data. January 2, 2024 is the current time, and the domain name resource data corresponding to the current time is the initial transmission data.

[0103] Furthermore, in order to ensure that the verification result is not affected by changes in the initial transmission data during the comparison process, the initial transmission data can be copied from the main database or data storage system to obtain a snapshot copy corresponding to the initial transmission data, so as to perform accurate incremental analysis based on the snapshot copy. For example, the sending node A will take a snapshot of the initial transmission data to obtain a snapshot copy, for example, the snapshot copy contains 50,000 domain names and their related records.

[0104] Furthermore, in order to improve the efficiency of comparison and transmission, the snapshot copy can be divided into multiple file fragments to be verified for parallel processing. For example, the snapshot copy can be divided into non-overlapping fragments according to the domain name type (i.e., top-level domains of different importance) or other logical classification methods. For example, ".com", ".net", ".org" and other domain name types correspond to different domain name types, so the snapshot copy can be fragmented according to the domain name types such as ".com", ".net", ".org", etc., to obtain multiple file fragments to be verified.

[0105] Furthermore, the domain name information of each file segment to be verified can be compared with the information of the same domain name type in the full data segment by segment to obtain the verification result. For example, the verification result can determine that 1,000 domain names have been changed in the ".com" segment, and 500 domain names have been added or modified in the ".net" segment, and there are no changes in other segments.

[0106] Furthermore, the changed domain name resources can be determined based on the verification results, and the changed domain name resources can be determined as domain name resources to be transmitted. For example, using the above example, the sending node A can determine that the 1000 updated domain names in the ".com" segment and the 500 newly added or modified domain names in the ".net" segment need to be transmitted as domain name resources to be transmitted, without having to transmit the unchanged segments again.

[0107] By performing incremental verification on the data, domain name resources that have changed since the last transmission can be identified, reducing unnecessary data transmission, reducing network load, and improving transmission speed and system responsiveness.

[0108] Step 102: divide the domain name resource to be transmitted into a plurality of file segments to be transmitted according to the domain name type, and generate a corresponding identification cryptographic signature for each file segment to be transmitted.

[0109] In some embodiments, in order to ensure the security, accuracy and efficiency of data transmission, the domain name resources to be transmitted can be divided into multiple file segments to be transmitted according to the domain name type (such as the top-level domain), and a corresponding identification cryptographic signature is generated for each file segment to be transmitted, so as to improve the security of transmission while realizing parallel processing to shorten the overall transmission time.

[0110] The domain name type may be a part of the domain name structure, such as a top-level domain (TLD) type, which is the rightmost part of each domain name in the domain name resource to be transferred, and provides important classification information of the domain name.

[0111] The file fragments to be transferred can be the entire domain name resource to be transferred divided into several small parts according to specific rules (such as domain name type, domain name level, etc.). The file fragments to be transferred can include a group of related domain names and their resource records (such as A / AAAA, NS, etc.), and each file fragment to be transferred can be processed and transferred independently.

[0112] The identification cryptographic signature can be a digital signature generated by the identity-based cryptography (IBC) identification cryptography technology. Each file segment to be transmitted corresponds to a unique identification cryptographic signature to ensure its integrity and authenticity of the source. Alternatively, the identification cryptographic signature can also be a digital signature generated based on a public key infrastructure.

[0113] Please refer to Figure 3 For example, the sending node can divide the domain name resources to be transmitted according to the domain name type (or other logical classification standards) of the domain name. For example, all domain names ending with ".ac", ".bid", and ".cn" are divided into the same file segment to be transmitted; all domain names ending with ".edu" and ".gov" are divided into the same file segment to be transmitted; all domain names ending with ".net" are divided into the same file segment to be transmitted, and so on. By dividing the domain name resources to be transmitted into multiple file segments to be transmitted, it is possible to allow file segments to be transmitted of different domain name levels to be transmitted through different transmission channels, thereby improving the efficiency and security of transmission.

[0114] Furthermore, when the domain name resources to be transmitted are divided according to the domain name type, it is detected that the number of domain names in the file shards to be transmitted is too large and exceeds the quantity threshold, for example, more than 200 domain names. Then, the current file shards to be transmitted can be further divided until the number of domain names contained in each of the last file shards to be transmitted does not exceed the quantity threshold.

[0115] In some implementations, identity-based cryptography (IBC) identification cryptography technology may be used to generate an identification cryptographic signature corresponding to each file segment to be transmitted, so as to simplify the key management and distribution process and improve the usability of the system.

[0116] In some implementations, an identification cryptographic signature corresponding to each file segment to be transmitted may also be generated based on a public key infrastructure. For example, a sending node may apply to a certificate authority for a pair of asymmetric keys, namely a public key and a private key, and obtain a corresponding digital certificate, which binds the identity information of the sending node to the public key. For each file segment to be transmitted, the sending node may use its own private key to sign it. The signing process may include using a hash function to calculate a message digest of the file segment to be transmitted, and encrypting the message digest with a private key to form an identification cryptographic signature of each file segment to be transmitted.

[0117] By dividing the domain name resources to be transmitted into multiple file segments to be transmitted according to the domain name type, and generating a corresponding identification cryptographic signature for each file segment to be transmitted, efficient, secure and accurate data transmission is achieved.

[0118] In some implementations, in order to improve the security and efficiency of data transmission and simplify the key management process, an identification cryptographic signature corresponding to each file segment to be transmitted may be generated by IBC identification cryptography technology, thereby eliminating the need to pre-distribute public keys and reducing the complexity of key management while ensuring the uniqueness of the identification cryptographic signature. The "generating a corresponding identification cryptographic signature for each file segment to be transmitted" in step 102 includes:

[0119] (102.1) Obtain randomly generated random parameters;

[0120] (102.2) Generate corresponding system parameters and master keys based on random parameters through the key generation center; wherein the system parameters are shared parameters of the current sending node among multiple transmission nodes, and the master key is encrypted and stored in the key generation center;

[0121] (102.3) Obtaining preset identification information, and generating a corresponding target private key based on the identification information, system parameters and master key;

[0122] (102.4) Generate a corresponding identification cryptographic signature for each file segment to be transferred based on each file segment to be transferred, the system parameters and the target private key.

[0123] The random parameter may be a unique and unpredictable value or string generated for each sending node. The random parameter is used to ensure that each key generation process is independent, ensuring the security and anti-attack capability of the system.

[0124] Among them, the Key Generation Center (KGC) can be a trusted third-party organization responsible for generating and managing the encryption parameters and target private keys of the system.

[0125] The system parameters may be mathematical parameters disclosed by the sending node to all other communication nodes, and all nodes participating in the communication share the sending node system parameters, for example, the system parameters are shared between the sending node and the receiving node.

[0126] The master key may be a core key generated by a key generation center and kept strictly confidential. The master key is the basis for generating the target private key of the sending node.

[0127] The identification information may be a unique identifier of the sending node, such as an email address, a user name, a domain name of the sending node, etc. In the IBC system, the identification information may be directly used as a public key.

[0128] The target private key may be a private key of each sending node generated according to the identification information, system parameters and the master key. Each sending node has a unique identification information, so each sending node will generate a corresponding target private key.

[0129] Please refer to Figure 4 , exemplarily, the sending node can generate a unique random parameter as a security parameter, and the random parameter can be used to ensure that each signing process is independent and unpredictable. Furthermore, node A (i.e., the sending node) can send the random parameter k to the key generation center (KGC). KGC uses the random parameter k to generate the corresponding system parameters and master key of node A. The system parameters are public and can be shared by all communication nodes, while the master key is kept separately by KGC and is not disclosed to the outside.

[0130] Furthermore, node A has a unique identification information (eg, the Internet Protocol address of node A). Node A can generate a target private key through the identification information, the system parameters received from the KGC, and the master key to sign the file segments to be transmitted.

[0131] Furthermore, for each file segment to be transferred, the sending node will generate an identification cryptographic signature for it. Specifically, node A can generate the identification cryptographic signature by using the file segment to be transferred, system parameters, and the target private key. For example, if the file segment to be transferred contains the DNS record of the domain name example.com, node A will use these records of the file segment to be transferred, combined with the system parameters and the target private key, to generate the identification cryptographic signature S.

[0132] Furthermore, after the receiving node receives the corresponding file segment, it can verify the identification cryptographic signature through the identification information and system parameters of the sending node. Successful verification means that the received file segment has not been tampered with and comes from the sending node.

[0133] By generating a unique identification cryptographic signature for each file segment to be transmitted, the integrity and source verification of the data can be ensured. This application adopts a signing and verification process based on IBC identification cryptographic technology, without the need for traditional certificate authorities and public key infrastructure, simplifying the process of establishing secure communications while maintaining a high level of security.

[0134] Step 103: encapsulate each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task.

[0135] In some embodiments, in order to ensure the integrity, security and manageability of data transmission, each file segment to be transmitted and its corresponding identification cryptographic signature can be encapsulated into a transmission task for transmission, so that while transmitting in the network, the recipient can independently verify the source and integrity of each file segment to be transmitted.

[0136] The transmission task may be to package each file segment to be transmitted and its corresponding identification cryptographic signature into an independent task unit during the domain name resource data exchange process.

[0137] Exemplarily, a standardized task format can be first designed to encapsulate the file segments to be transmitted and the identification cryptographic signatures, and each file segment to be transmitted and its corresponding identification cryptographic signature can be packaged together into a task unit in a task format (such as JSON format) through a scheduler to form a complete transmission task.

[0138] By encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task, the receiving node can independently verify the source and integrity of each segment. In addition, encapsulation into independent transmission tasks allows the system to manage the transmission process more effectively, such as facilitating the implementation of error recovery and retransmission mechanisms, ensuring the safe and efficient transmission of critical data.

[0139] In some implementations, in order to avoid a single transmission task being too large and to achieve load balancing, after uploading the file segments to be transmitted to the scheduler, the scheduler can divide the file segments to be transmitted with a larger data volume into multiple file groups to be transmitted and then encapsulate them to obtain a transmission task, so as to improve the transmission efficiency; and, by dividing into multiple file groups to be transmitted, when a problem occurs in the transmission of a certain file group to be transmitted, the group can be retransmitted separately without having to restart the transmission of the entire transmission task, thereby improving the overall transmission speed. For example, step 103 may include:

[0140] (103.1) Obtaining the data volume value of each file segment to be transferred;

[0141] (103.2) Compare the data volume value with a preset load threshold to obtain a comparison result;

[0142] (103.3) When the comparison result indicates that the data volume value is greater than the load threshold, the corresponding file fragment to be transmitted is divided into multiple file groups to be transmitted according to the alphabetical order of the domain names;

[0143] (103.4) Grouping multiple files to be transmitted and encapsulating them with identification cryptographic signatures into transmission tasks corresponding to each file segment to be transmitted.

[0144] The data volume value may be the actual size of each file segment to be transferred, which may be measured in bytes. The data volume value is used to reflect the amount of space occupied by the file segment to be transferred during storage or transmission, which may be obtained by calculation or by directly reading the information provided by the file system.

[0145] The load threshold may be a pre-set standard value used to determine whether a single file segment to be transmitted is too large, thereby determining whether it needs to be further split to optimize transmission efficiency and resource allocation. The load threshold may be flexibly determined based on factors such as the actual system performance, network bandwidth, and expected transmission time.

[0146] The comparison result may be a conclusion drawn based on the comparison between the data volume value and the load threshold. If the data volume value is greater than the load threshold, it means that the file segment to be transmitted is too large, which may affect the transmission efficiency or cause resource overload; otherwise, it is considered that the file segment to be transmitted is moderate and can be directly processed without additional operations.

[0147] Among them, the multiple file groups to be transmitted can be divided into several smaller file sets according to the alphabetical order of the top-level domain in the domain name when the data volume value of a single file segment to be transmitted exceeds a preset load threshold.

[0148] For example, if a file segment to be transferred, file_chunk_1, has a data volume value of 500MB, and the preset load threshold is 300MB, the comparison result is obtained after comparison, and the data volume value of the file segment to be transferred is greater than the load threshold, so it is necessary to sort it according to the top-level domain name in the domain name to further divide it.

[0149] Furthermore, if file_chunk_1 contains data from the top-level domains of ".com", ".net", and ".org", it can be divided into three new file groups to be transferred: File Group 1: contains all domain name resources under ".com"; File Group 2: contains all domain name resources under ".net"; File Group 3: contains all domain name resources under ".org". Afterwards, these three file groups to be transferred can be packaged together with the identification password signature into a transfer task and uploaded to the scheduler for the next transfer arrangement, which not only helps to improve the transmission efficiency, but also ensures the security and consistency of the data.

[0150] Please refer to Figure 5 In some implementations, the file fragments to be transmitted may also be grouped according to the domain name letters. For example, the file fragments to be transmitted include domain name letters of top-level domains starting with a, b, c, and d. When the data volume value of the file fragments to be transmitted is greater than the load threshold, since the number of domain name resources of the top-level domain starting with c far exceeds that of other domain names, the sending node will adaptively adjust the splitting strategy and divide the domain name resources starting with c into one or more new file groups to be transmitted.

[0151] In some implementations, the file segments to be transmitted may be grouped and then packaged together with the identification cryptographic signature to obtain a transmission task, and the transmission task may be uploaded to the scheduler; or, the file segments to be transmitted may be uploaded to the scheduler for grouping and then packaged together with the identification cryptographic signature to obtain a transmission task. In some implementations, both the sending node and the scheduler have the function of grouping and packaging the file segments to be transmitted.

[0152] In some implementations, after dividing into multiple file groups to be transmitted, the multiple file groups to be transmitted may be marked, and each file group to be transmitted may be separately packaged with an identification cryptographic signature to obtain corresponding multiple transmission tasks, so as to transmit the multiple transmission tasks separately. The embodiments of the present application do not impose too many restrictions on this.

[0153] Through the above method, the system can adapt to different network conditions and data loads, and when problems occur during the transmission process, it can quickly locate and retransmit the problematic packets separately, rather than the entire file fragment to be transmitted, thereby improving the efficiency and reliability of data during transmission.

[0154] Step 104, according to the domain name level corresponding to each transmission task, determine the target transmission channel corresponding to each transmission task from multiple transmission channels; wherein different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level.

[0155] In some embodiments, in order to achieve refined management and optimization of domain name resource data transmission, the target transmission channel can be determined from multiple transmission channels according to the domain name level corresponding to each transmission task, so as to reduce congestion and delays in the transmission process while ensuring that domain names of different importance levels correspond to transmission channels of different encryption levels, thereby ensuring that key domain name resources can receive a higher level of security protection.

[0156] The domain name level can be an assessment of the importance of each domain name resource data to be transmitted. For example, the domain name level can include three levels, specifically level 1 (corresponding to general transmission tasks), which can be transmitted in general and encrypted; level 2 (corresponding to important transmission tasks), which must be transmitted encrypted. Level 3 (corresponding to particularly important transmission tasks) requires encryption and expedited transmission, which occupies the highest system resources. The domain name level determines the priority and security requirements of the transmission task during the transmission process, ensuring that important domain name resources can be more securely protected and more efficiently processed.

[0157] The target transmission channel may be the most suitable channel selected from a plurality of available transmission channels for each transmission task. Different target transmission channels have different characteristics, such as transmission speed, security, etc.

[0158] The transmission protocol may be a set of rules and standards for transmitting data on a network. The transmission channel of the present application supports three main transmission protocols, each of which corresponds to a different transmission channel and provides different levels of security.

[0159] The encryption level can be: The encryption level refers to the level of security protection provided by the transmission channel, which is specifically manifested in the encryption strength and technology used in the transmission process. The encryption level is positively correlated with the domain name level, that is, the more important the domain name resource is, the higher the encryption level is.

[0160] Exemplarily, multiple transmission channels can support multiple main transmission protocols respectively, each transmission protocol corresponds to a different transmission channel and provides different degrees of security. For example, the transmission channel can specifically include:

[0161] The transmission channel that supports the Remote Sync (RSYNC) protocol is suitable for transmission tasks with a domain level of 1. It can transmit transmission tasks that do not require encryption. It has the characteristics of easy construction, fast transmission speed, and low resource usage. When building a transmission channel that supports the RSYNC protocol, you can install the RSYNC software between the sending node and the receiving node, configure RSYNC to specify the source directory (files on the sending node) and the target directory (files on the receiving node). RSYNC can be configured to perform secure remote synchronization through the Secure Shell (SSH) protocol to quickly achieve synchronous transmission of files.

[0162] The Transport Layer Security (TLS) encrypted channel built based on Nginx (a high-performance HTTP and reverse proxy server) is suitable for transmission tasks at domain level 1 and 2 (lower domain level), providing basic encrypted transmission to ensure the security of file transmission, and the key file is exchanged during the transmission process. Furthermore, when building a TLS encrypted channel based on Nginx, you can install and configure the Nginx server or Nginx software in the sending node and the receiving node, and enable the TLS module. You need to obtain and install TLS certificates (which can be self-signed or issued by a certificate authority), and then configure Nginx to use these certificates. In this way, HyperText Transfer Protocol (HTTP) requests through the Nginx server will be carried out through an encrypted secure HyperText Transfer Protocol (HTTPS) channel.

[0163] The TLS encrypted channel built based on stunnel (a software tool for providing secure data transmission in the network) is suitable for tasks with domain level 3 (the highest domain level), providing the highest level of encryption protection, and can also be used to transmit tasks with domain level 2 when idle. Specifically, when building a TLS encrypted channel based on stunnel, you can install the stunnel software on the sending node and the receiving node, and configure stunnel to specify which types of network traffic need to be encrypted and how to communicate with the Secure Sockets Layer (SSL) / TLS server.

[0164] In some implementations, the above are just examples of how to build a transmission channel that supports the RSYNC protocol, a TLS encrypted channel based on Nginx, and a TLS encrypted channel based on stunnel. In actual applications, different building schemes can be selected to build a transmission channel that supports the RSYNC protocol, a TLS encrypted channel based on Nginx, and a TLS encrypted channel based on stunnel. Without violating the concept of the present application, any building method can be selected, and the present application does not make specific limitations on this.

[0165] In some implementations, at the start of each transmission task, the scheduler may call an application programming interface (API) to open multiple transmission channels, and the scheduler allocates transmission tasks to each transmission channel.

[0166] Exemplarily, the domain name level corresponding to each transmission task can be determined according to the task type corresponding to each transmission task, and the target transmission channel corresponding to the domain name level of each transmission task can be determined from multiple transmission channels. For example, if the task type of transmission task C is a domain name record involving critical infrastructure, then transmission task C can be assigned to domain name level 3, and if the domain name level of the transmission task corresponding to transmission channel 3 is also 3, then the transmission task can be assigned to transmission channel 3 for transmission.

[0167] By setting the encryption level of each transmission channel to match the domain name level of the transmission task, a higher level of protection can be provided for key domain name resources, ensuring the security of data transmission.

[0168] In some implementations, in order to achieve refined management of domain name resource data transmission, each transmission task may be calibrated with a domain name level, and corresponding target transmission channels may be determined for transmission tasks of different domain name levels, so as to perform hierarchical transmission of transmission tasks and improve transmission efficiency and security. For example, step 104 may include:

[0169] (104.1) Calibrate the domain name level of each transmission task according to a pre-calibrated rule to obtain multiple transmission tasks associated with different domain name levels;

[0170] (104.2) According to a plurality of transmission tasks associated with different domain name levels, a target transmission channel corresponding to each transmission task is determined from a plurality of transmission channels.

[0171] Among them, the pre-calibration rules can be pre-set standards and processes for evaluating and determining the importance level of the domain name resources contained in each file segment to be transferred (i.e., transfer task). By applying the pre-calibration rules, each transfer task can be associated with a specific domain name level, thereby ensuring that subsequent processing can take appropriate measures based on its importance.

[0172] Exemplarily, domain name levels can be divided into multiple levels, such as level 3, level 4, etc. Taking the domain name level divided into 3 levels as an example, level 1 can correspond to ordinary domain name resources, such as domain name data related to non-critical business; level 2 can correspond to important domain name resources, such as resources with certain data value; level 3 can correspond to particularly important domain name resources, involving core data.

[0173] In some implementations, the domain name resources in each transmission task are evaluated according to preset standards to determine the corresponding domain name level. For example, the domain name level of domain name categories a1 and a2 can be set to level 1, the domain name level corresponding to domain name categories b1, b2 and b3 can be set to level 2, and the domain name level corresponding to domain name category c1 can be set to level 2. Further, the domain name level of the transmission task can be identified by a technician, or an automated script can be written or a tool can be used for identification, and the embodiments of the present application do not specifically limit this.

[0174] In some implementations, after determining the domain name level of each transmission task, the level information of the transmission task may be marked to quickly identify and classify the transmission task in subsequent processing.

[0175] Furthermore, the most suitable target transmission channel can be selected for each transmission task according to the pre-calibrated domain name level. Specifically, the domain name levels applicable to different transmission channels can be defined by pre-setting a mapping table or a configuration file.

[0176] Furthermore, according to multiple transmission tasks associated with different domain name levels, a transmission channel applicable to the domain name level corresponding to each transmission task can be selected as the target transmission channel of the transmission task. For example, a level 1 transmission task can choose to use a transmission channel that does not use encryption or uses basic encryption, a level 2 transmission task can use a transmission channel that provides basic encryption, and a level 3 transmission task must use a transmission channel that provides advanced encryption, etc. Furthermore, the scheduler can transmit the corresponding transmission task through the selected target transmission channel.

[0177] For example, the domain name level of task_1 is level 1, the domain name level of task_2 is level 2, and the domain name level of task_3 is level 3. For task_1, you can choose the RSYNC protocol or the basic encrypted TLS channel built by Nginx. For task_2, you should choose the basic encrypted TLS channel built by Nginx. For task_3, you need to use the advanced encrypted TLS channel built based on stunnel.

[0178] Through the above method, not only can the most appropriate transmission method be selected according to the importance of domain name resources, but also the security and efficiency of the transmission process can be ensured. It is particularly suitable for application scenarios that require frequent synchronization of a large number of domain name resources and have high requirements for security and efficiency.

[0179] Step 105, respectively transmit the corresponding multiple transmission tasks to the corresponding receiving nodes through multiple target transmission channels, so that the receiving nodes verify the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending nodes, and update the target domain name resources in the corresponding storage area according to the verification results obtained.

[0180] In some implementations, in order to improve the efficiency and security of domain name resource data transmission, multiple target transmission channels may be used to process different transmission tasks in parallel, so as to achieve load balancing and fault isolation while improving transmission efficiency.

[0181] The receiving node may be a server or device that is responsible for receiving transmission tasks from the sending node during the data transmission process.

[0182] The storage area can be a physical or logical location set up on the receiving node specifically for storing and managing domain name resources, and can be any form of data storage solution such as a local disk, a distributed file system, or a database.

[0183] The target domain name resource may be a specific domain name that needs to be updated or synchronized and its associated resource records (such as A / AAAA, NS, etc.). The target domain name resource determines how Internet users access specific services or websites.

[0184] For example, when the domain name resource to be transmitted is divided into multiple file fragments to be transmitted, the file fragments can be labeled in sequence, for example 1-1, 1-2, 1-3, and 1-1, 1-2, 1-3 can be merged in sequence, so that the complete domain name resource to be transmitted can be obtained quickly and accurately.

[0185] Furthermore, the receiving node can start multiple daemons, each of which is responsible for only one transmission channel, and the receiving node controls the receiving process through the daemon. Specifically, after each daemon receives the corresponding transmission task, it can verify the identification cryptographic signature in each transmission task through the system parameters shared by the sending node and the identification information (that is, the public key) of the sending node, and merge the verified transmission tasks according to the pre-marked numbers, for example, 1-1, 1-2, and 1-3 are merged in order to obtain a complete domain name resource.

[0186] Exemplarily, if the verification of the identification cryptographic signature fails, the receiving node will discard the transmission task and send an error signal to the sending node through the transmission channel, requesting the transmission task to be resent. After receiving the transmission error signal, the sending node will check the number of retransmissions of the transmission task. If the number of retransmissions of the transmission task does not exceed the preset number of retransmissions, for example, it does not exceed 3 times, then the transmission task can continue to be retransmitted through the transmission channel.

[0187] Once all transfer tasks are successfully received and verified, the receiving node will update its domain name resource records in the corresponding storage area and may store these updated records in the file repository to complete a transfer task.

[0188] In some implementations, it is not necessary to wait until all transmission tasks are successfully received and verified, and it is sufficient that the received transmission tasks can be synthesized into a complete domain name resource. For example, when transmitting transmission tasks 1-1, 1-2, 1-3 corresponding to domain name resource 1 to be transmitted, and transmission tasks 2-1, 2-2, 2-3 corresponding to domain name resource 2 to be transmitted, if the receiving node verifies all transmission tasks 2-1, 2-2, 2-3 corresponding to domain name resource 2 to be transmitted, and merges them to obtain domain name resource 2, then the corresponding storage area can be updated according to domain name resource 2, without waiting for all transmission tasks of domain name resource 1 to be transmitted to be verified and then updated together.

[0189] The embodiment of the present application obtains a domain name resource to be transmitted; divides the domain name resource to be transmitted into multiple file segments to be transmitted according to the domain name type, and generates a corresponding identification cryptographic signature for each file segment to be transmitted; encapsulates each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task; determines a target transmission channel corresponding to each transmission task from multiple transmission channels according to the domain name level corresponding to each transmission task; different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level; transmits the corresponding multiple transmission tasks to the corresponding receiving nodes through the multiple target transmission channels, so that the receiving nodes can verify the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending node, and update the target domain name resources in the corresponding storage area according to the verification results obtained. In this way, multiple transmission channels can be used to allow the simultaneous processing of transmission tasks of multiple different domain name levels, thereby improving the efficiency of system resource transmission; and by building multiple transmission channels, it is more difficult for the attacker to hijack all transmission channels and crack the full resource records, thereby greatly improving the security of the system transmission process. At the same time, each transmission channel supports transmission protocols with different encryption levels, which can enable transmission tasks with high domain name levels to be fully encrypted and protected, further improving the security of the system transmission process. In summary, this application can improve the efficiency and security of domain name resource transmission.

[0190] In some implementations, in order to finely manage the resource allocation of the transmission channel and optimize the efficiency and performance of the domain name resource data exchange, the computing resources of each transmission channel can be reasonably allocated according to the ratio of the resource allocation index of each transmission channel to the total resource allocation index, ensuring that the key transmission tasks are given sufficient resources to be completed first, while balancing the load of each transmission channel, avoiding resource waste, and improving the overall transmission performance and response speed. For example, before step 105, it can also include:

[0191] (A.1) for each transmission task in each target transmission channel, obtaining a sub-resource allocation index of each transmission task;

[0192] (A.2) determining a channel resource allocation index for each target transmission channel according to a sum of multiple sub-resource allocation indexes corresponding to multiple transmission tasks transmitted by each target transmission channel;

[0193] (A.3) determining a total resource allocation index according to the sum of multiple channel resource allocation indices corresponding to the multiple target transmission channels;

[0194] (A.4) for each target transmission channel, determining the allocated resources of each target transmission channel based on the ratio of the corresponding channel resource allocation index to the total resource allocation index;

[0195] (A.5) Based on the allocated resources, the computing resources of each target transmission channel are allocated.

[0196] The sub-resource allocation index may be a resource requirement indicator for measuring each transmission task in resource allocation in a target transmission channel.

[0197] The channel resource allocation index may be the sum of the sub-resource allocation indexes of all transmission tasks in each target transmission channel, that is, the total resource demand index of the target transmission channel in resource allocation.

[0198] The total resource allocation index may be the sum of channel resource allocation indexes of all target transmission channels.

[0199] The allocated resources may be the product of the ratio of the channel resource allocation index of each target transmission channel to the total resource allocation index and the available computing resources of the system, that is, the allocated resources that should be allocated to each target transmission channel.

[0200] In some implementations, the allocated resources for each target transmission channel The formula for making the allocation is as follows:

[0201] ( Transmission channel x) (1)

[0202] in, is the sub-resource allocation index of the j-th transmission task in the target transmission channel x; is the channel resource allocation index of the target transmission channel x; It is the sum of the channel resource allocation indexes of all target transmission channels, where N means there are N target transmission channels in total; is the task weight, is the data volume value, The number of retransmissions.

[0203] Specifically, the task weight is used to reflect the importance and priority of the transmission task. The higher the task weight, the higher the priority of the corresponding transmission task in resource allocation. The data volume value reflects the amount of data required to be transmitted by the transmission task. The larger the data volume value, the more resources the transmission task requires. The more retransmissions, the more important the transmission task. The calculated gain factor is used to comprehensively consider the impact of task weight and number of retransmissions. When the task weight and number of retransmissions are large, the gain factor will also be large, which means that the transmission task has a higher priority in resource allocation.

[0204] For example, if there are two target transmission channels, there are three transmission tasks T1, T2, and T3 in target transmission channel 1, and transmission tasks S1, S2, and S3 in target transmission channel 2. Taking the channel resource allocation index of target transmission channel 1 as an example, if the task weight of transmission task T1 is 0.9, the data volume value is 1,048,576 bytes, and the number of retransmissions is 5; the task weight of transmission task T2 is 0.5, the data volume value is 524,288 bytes, and the number of retransmissions is 2; the task weight of transmission task T1 is 0.7, the data volume value is 2,097,152 bytes, and the number of retransmissions is 3. Substituting the relevant data of T1, T2, and T3 into formula (1), it can be calculated that the sub-resource allocation index of T1 is 1,347,456, the sub-resource allocation index of T2 is 288,352, and the sub-resource allocation index of T3 is 1,807,760.

[0205] Furthermore, the channel resource allocation index of the target transmission channel 1 can be calculated as 2,097,152+1,347,456+1,807,760=3,443,568 through the sub-resource allocation indexes corresponding to T1, T2, and T3 respectively.

[0206] Exemplarily, if the channel resource allocation index of the target transmission channel 2 is 5,312,510, the total resource allocation index is 3,443,568+5,312,510=8,756,078.

[0207] Furthermore, for the target transmission channel 1, the ratio of the corresponding channel resource allocation index to the total resource allocation index is 3,443,568 / 8,756,078. By multiplying the ratio by the available computing resources of the system, the allocated resources that should be allocated to the target transmission channel 1 can be obtained.

[0208] It should be noted that the above is only a calculation example provided for easy understanding of the allocation resources of each target transmission channel. The data may vary in actual situations. Please refer to the above process for specific calculations, which will not be described in detail here.

[0209] Through the above methods, the system can efficiently and dynamically allocate computing resources according to the specific needs of each transmission task, ensuring maximum resource utilization and optimization of transmission efficiency, and achieving efficient resource management and task scheduling.

[0210] In some implementations, in order for the system to fully understand the characteristics and requirements of each transmission task and provide accurate basic data for subsequent resource allocation, (A.1) may include:

[0211] (A.1.1) For each transmission task in each target transmission channel, obtain a preset task weight, data volume value, and preset number of retransmissions for each transmission task;

[0212] (A.1.2) Determine the data gain of each transmission task based on the number of retransmissions and the task weight;

[0213] (A.1.3) Determine the sub-resource allocation index of each corresponding transmission task according to the product of the task weight, the data volume value and the data gain.

[0214] The task weight may be the importance or priority of each transmission task.

[0215] The data volume value may be the data volume of each transmission task. It reflects the amount of data required to be transmitted for the transmission task, and can be expressed in units such as bytes (B), kilobytes (KB), and megabytes (MB). The larger the data volume value, the more resources are required for the transmission task.

[0216] The number of retransmissions can be a preset number of retransmissions, that is, the number of times the system will try to retransmit if the transmission fails during the transmission process. The number of retransmissions is used to reflect the reliability requirements of the transmission task. The more retransmissions, the higher the reliability requirements of the task.

[0217] The data gain may be a value calculated based on the number of retransmissions and the task weight, and the data gain is used to reflect the comprehensive impact of the importance of the transmission task in the transmission process and the reliability requirement.

[0218] In some implementations, sub-resource allocation index = ;

[0219] in, is the task weight, is the data volume value, is the number of retransmissions; is the data gain.

[0220] Specifically, the data volume value of each transmission task can be determined based on the file size of the transmission task, and then a task weight is assigned to each transmission task to determine the relative importance of the corresponding transmission task. The task weight can be set by a technician or by other means, such as a machine learning model. The task weight of each transmission task is set using the same standard. Furthermore, the number of retransmissions for each transmission task can be determined. The number of retransmissions can be set based on historical data or the task characteristics of the transmission task. The number of retransmissions for each transmission task is set using the same standard.

[0221] Furthermore, we can use the formula Calculate the data gain, and multiply the data volume value, task weight and data gain to obtain the sub-resource allocation index corresponding to each transmission task.

[0222] Through the above methods, tasks with high priority, large data volume or high reliability requirements can obtain more resource support to ensure their smooth completion. At the same time, low-priority tasks can also receive appropriate attention to ensure the efficient operation of the overall system.

[0223] In some implementations, in order to achieve dynamic adjustment and optimization of resource allocation and ensure that network resources can be flexibly allocated according to actual transmission requirements and task completion, when a transmission channel completes all allocated transmission tasks, its resources can be released and reallocated to other channels that are transmitting or waiting for transmission to avoid idleness and waste of resources. For example, the domain name resource transmission method may also include:

[0224] (B.1) when any first transmission channel has completed the transmission of all the assigned transmission tasks, determining the first resource allocation amount released by the first transmission channel;

[0225] (B.2) Allocate the first resource allocation amount to at least one second transmission channel according to the channel resource allocation index of at least one second transmission channel currently transmitting the transmission task, and obtain a target transmission channel with an updated resource allocation amount.

[0226] The first transmission channel may be a target transmission channel that has completed all its assigned transmission tasks. The first transmission channel no longer requires additional computing resources to process the current task list, and thus previously allocated resources may be released.

[0227] The first resource allocation amount may be the amount of computing resources released by the first transmission channel after the first transmission channel completes all transmission tasks. The first resource allocation amount includes but is not limited to central processing unit (CPU) time, memory space, network bandwidth, etc.

[0228] The second transmission channel may be one or more transmission channels that are currently still processing transmission tasks. The second transmission channel has not yet completed all of its assigned transmission tasks and still needs computing resources to continue processing the remaining transmission tasks.

[0229] In some implementations, the second transmission channel may receive the first resource allocation amount released from the first transmission channel to accelerate the task processing process and improve the efficiency of task transmission.

[0230] Please refer to Figure 6For example, if there are 4 transmission channels between the sending node and the receiving node, among which, transmission channel 1 has transmission task 1 and transmission task 7, the allocated resources obtained by transmission channel 1 are 10% of the system available resources; transmission channel 2 has transmission task 2, transmission task 5 and transmission task 8, and the allocated resources obtained by transmission channel 2 are 30% of the system available resources; transmission channel 3 has transmission task 3, transmission task 6 and transmission task 9, and the allocated resources obtained by transmission channel 3 are 20% of the system available resources; transmission channel 4 has transmission task 4, and the allocated resources obtained by transmission channel 4 are 40% of the system available resources.

[0231] Further, if the transmission of transmission channel 4 is completed, transmission channel 4 is used as the first transmission channel, and transmission channel 1, transmission channel 2, and transmission channel 3 are used as the second transmission channel. Then, the updated total resource allocation index can be recalculated according to the channel resource allocation indexes of the remaining transmission channels 1, 2, and 3. And according to the ratio of transmission channel 1, transmission channel 2, and transmission channel 3 to the total resource allocation index, they are multiplied by the first resource allocation amount released by transmission channel 4, respectively, to obtain the newly allocated system resources for transmission channel 1, transmission channel 2, and transmission channel 3. For example, the newly allocated resources obtained by transmission channel 1 are 20% of the available system resources, the newly allocated resources obtained by transmission channel 2 are 50% of the available system resources, and the newly allocated resources obtained by transmission channel 3 are 30% of the available system resources. Finally, the resource allocation amounts of transmission channel 1, transmission channel 2, and transmission channel 3 can be updated again according to the increased allocated system resources.

[0232] Through the above methods, the system can more effectively respond to changes in transmission tasks, such as task completion, the addition of new tasks, or the adjustment of transmission priorities, thereby improving the overall transmission efficiency and system performance to ensure that critical tasks obtain the necessary resources and guarantee their transmission quality. At the same time, resources can be reasonably allocated for non-critical tasks to achieve fair allocation and optimized use of resources.

[0233] See also Figure 7 , Figure 7 This is a flowchart of the steps of the domain name resource transmission method provided in an embodiment of the present application. The domain name resource transmission method is applied to a receiving node. In the embodiment of the present application, a domain name resource transmission device is specifically integrated on a computer device as an example. When a processor on the computer device executes a program instruction corresponding to the domain name resource transmission method, the specific process is as follows:

[0234] Step 201, obtaining multiple transmission tasks corresponding to transmissions of a sending node through multiple target transmission channels;

[0235] Step 202, based on the identification information shared by the sending node, multiple identification cryptographic signatures in multiple transmission tasks are sequentially verified, and the target domain name resource in the corresponding storage area is updated based on the verification result obtained;

[0236] The target transmission channel corresponding to each transmission task is determined by the sending node from multiple transmission channels according to the domain name level corresponding to each transmission task; the transmission task is obtained by the sending node by encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature; the identification cryptographic signature corresponding to each file segment to be transmitted is obtained by the sending node through the domain name resource to be transmitted, and the domain name resource to be transmitted is divided into multiple file segments to be transmitted according to the domain name type and then generated;

[0237] Among them, different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level.

[0238] The embodiment of the present application obtains multiple transmission tasks corresponding to the transmission of the sending node through multiple target transmission channels; according to the identification information shared by the sending node, the multiple identification cryptographic signatures in the multiple transmission tasks are verified in turn, and the target domain name resources of the corresponding storage area are updated according to the verification results; wherein, the target transmission channel corresponding to each transmission task is determined by the sending node from the multiple transmission channels according to the domain name level corresponding to each transmission task; the transmission task is obtained by the sending node by encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature; the identification cryptographic signature corresponding to each file segment to be transmitted is obtained by the sending node through the domain name resource to be transmitted, and the domain name resource to be transmitted is divided into multiple file segments to be transmitted according to the domain name type and then generated; wherein different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level. In this way, multiple transmission channels can be used to allow the simultaneous processing of transmission tasks of multiple different domain name levels, thereby improving the efficiency of system resource transmission; and by building multiple transmission channels, it is more difficult for the attacker to hijack all transmission channels and crack the full resource records, thereby greatly improving the security of the system transmission process. At the same time, each transmission channel supports transmission protocols with different encryption levels, which can enable transmission tasks with high domain name levels to be fully encrypted and protected, further improving the security of the system transmission process. In summary, this application can improve the efficiency and security of domain name resource transmission.

[0239] The specific implementation of the data migration method applied to the receiving node is basically the same as the specific implementation of the domain name resource transmission applied to the sending node mentioned above, and will not be repeated here.

[0240] Please refer to Figure 8In some embodiments, the following will be combined with Figure 8 The overall technical scheme of the present application is introduced. Exemplarily, the sending node first publishes the domain name resources to be transmitted, and sorts them and divides the file segments to be transmitted to ensure that each file segment to be transmitted is arranged in order according to the domain name type. Further, each file segment to be transmitted can be electronically signed to obtain a corresponding identification password signature to ensure the integrity of the data and the verifiability of the source. Further, the data can be analyzed by the scheduler, and a transmission channel matching the domain name level can be requested and started, and a suitable transmission channel can be specified for each file segment to be transmitted according to the domain name level of each file segment to be transmitted. Different transmission channels may support different transmission protocols and encryption levels to adapt to domain name resources of different levels. Further, the encapsulated transmission task and identification password signature can be transmitted to the receiving node through the opened transmission channel. The receiving node detects the transmission channel message through different daemons and receives the transmission tasks transmitted from different transmission channels. After receiving the corresponding transmission task, the receiving node can verify each received transmission task and check whether the identification password signature matches to ensure that the data has not been tampered with. After verification, each transmission task is aggregated into a complete domain name resource file in the correct order, and the receiving node stores the aggregated domain name resource file in the historical record to complete a complete transmission task.

[0241] See also Fig. 9 The embodiment of the present application further provides a domain name resource transmission device, which is applied to a sending node and can implement the above domain name resource transmission method. The domain name resource transmission device includes:

[0242] An acquisition module 91 is used to acquire a domain name resource to be transmitted;

[0243] A generating module 92, configured to divide the domain name resource to be transmitted into a plurality of file segments to be transmitted according to the domain name type, and to generate a corresponding identification cryptographic signature for each file segment to be transmitted;

[0244] The encapsulation module 93 is used to encapsulate each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task;

[0245] A determination module 94 is used to determine the target transmission channel corresponding to each transmission task from multiple transmission channels according to the domain name level corresponding to each transmission task; wherein different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level;

[0246] The transmission module 95 is used to transmit the corresponding multiple transmission tasks to the corresponding receiving nodes through multiple target transmission channels, so that the receiving nodes can verify the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending nodes, and update the target domain name resources in the corresponding storage area according to the verification results obtained.

[0247] The specific implementation of the domain name resource transmission device is basically the same as the specific implementation of the domain name resource transmission method described above, and will not be repeated here. On the premise of meeting the requirements of the embodiment of this application, the domain name resource transmission device can also be provided with other functional modules to implement the domain name resource transmission method in the above embodiment.

[0248] The embodiment of the present application also provides a computer device, the computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the above domain name resource transmission method when executing the computer program. The computer device can be any intelligent terminal including a tablet computer, a car computer, etc.

[0249] See also Fig.10 , Fig.10 The hardware structure of a computer device according to another embodiment is shown, and the computer device includes:

[0250] The processor 1001 may be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;

[0251] The memory 1002 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1002 can store an operating system and other application programs. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 1002, and the processor 1001 calls and executes the domain name resource transmission method of the embodiment of this application;

[0252] Input / output interface 1003, used to implement information input and output;

[0253] Communication interface 1004, used to realize communication interaction between the device and other devices, which can be realized through wired mode (such as USB, network cable, etc.) or wireless mode (such as mobile network, WIFI, Bluetooth, etc.);

[0254] A bus 1005 , which transmits information between various components of the device (e.g., the processor 1001 , the memory 1002 , the input / output interface 1003 , and the communication interface 1004 );

[0255] The processor 1001 , the memory 1002 , the input / output interface 1003 and the communication interface 1004 are connected to each other in communication within the device via the bus 1005 .

[0256] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned domain name resource transmission method is implemented.

[0257] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0258] The embodiments described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0259] Those skilled in the art will appreciate that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0260] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0261] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.

[0262] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0263] It should be understood that in the present application, "at least one (item)" and "several" refer to one or more, and "plurality" refers to two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0264] In the several embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely schematic. For example, the division of the above units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0265] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0266] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0267] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including multiple instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store programs.

[0268] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.

Claims

1. A domain name resource transmission method, characterized in that: Applied to a sending node, the method comprises: Get the domain name resources to be transferred; Dividing the domain name resource to be transmitted into a plurality of file segments to be transmitted according to the domain name type, and generating a corresponding identification cryptographic signature for each file segment to be transmitted; Encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task; According to the domain name level corresponding to each transmission task, a target transmission channel corresponding to each transmission task is determined from multiple transmission channels; different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level; For each transmission task in each target transmission channel, obtain the sub-resource allocation index of each transmission task; determine the channel resource allocation index of each target transmission channel according to the sum of multiple sub-resource allocation indexes corresponding to multiple transmission tasks transmitted by each target transmission channel; determine the total resource allocation index according to the sum of multiple channel resource allocation indexes corresponding to multiple target transmission channels respectively; for each target transmission channel, determine the allocated resources of each target transmission channel based on the ratio of the corresponding channel resource allocation index to the total resource allocation index; and allocate computing resources for each target transmission channel based on the allocated resources; The corresponding multiple transmission tasks are respectively transmitted to the corresponding receiving nodes through multiple target transmission channels, so that the receiving nodes verify the multiple identification cryptographic signatures in the multiple transmission tasks in turn according to the identification information shared by the sending nodes, and update the target domain name resources in the corresponding storage area according to the verification results.

2. The method for transmitting domain name resources according to claim 1, characterized in that: The acquiring, for each transmission task in each target transmission channel, a sub-resource allocation index of each transmission task includes: For each transmission task in each target transmission channel, obtaining a preset task weight, a data volume value, and a preset number of retransmissions for each transmission task; Determining a data gain of each transmission task according to the number of retransmissions and the task weight; The sub-resource allocation index of each transmission task is determined according to the product of the task weight, the data volume value and the data gain.

3. The domain name resource transmission method according to claim 1, characterized in that: The method further comprises: When all the transmission tasks assigned to any one of the first transmission channels have been transmitted, determining a first resource allocation amount released by the first transmission channel; According to the channel resource allocation index of at least one second transmission channel that is currently transmitting the transmission task, the first resource allocation amount is allocated to the at least one second transmission channel to obtain a target transmission channel with an updated resource allocation amount.

4. The domain name resource transmission method according to claim 1, characterized in that: The obtaining of the domain name resource to be transferred includes: Obtain the full data corresponding to the previous historical transmission time and the initial transmission data corresponding to the current time; Taking a data snapshot of the initial transmission data to obtain a snapshot copy corresponding to the initial transmission data; Dividing the snapshot copy into a plurality of to-be-verified file fragments according to the domain name type, and performing incremental verification on the plurality of to-be-verified file fragments according to the full data to obtain a verification result; According to the verification result, the domain name resource to be transmitted is determined from the initial transmission data.

5. The domain name resource transmission method according to claim 1, characterized in that: The generating of a corresponding identification cryptographic signature for each file segment to be transmitted includes: Get randomly generated random parameters; Generate corresponding system parameters and master keys based on the random parameters through a key generation center; wherein the system parameters are shared parameters of the current sending node among multiple transmission nodes, and the master key is encrypted and stored in the key generation center; Obtaining preset identification information, and generating a corresponding target private key according to the identification information, the system parameters and the master key; According to each file segment to be transmitted, the system parameters and the target private key, a corresponding identification cryptographic signature is generated for each file segment to be transmitted.

6. The domain name resource transmission method according to claim 1, characterized in that: The step of encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task includes: Obtaining the data volume value of each file segment to be transmitted; Comparing the data volume value with a preset load threshold to obtain a comparison result; When the comparison result indicates that the data volume value is greater than the load threshold, the corresponding file fragments to be transmitted are divided into a plurality of file groups to be transmitted according to the alphabetical order of the domain names; The multiple files to be transmitted are grouped and encapsulated with the identification cryptographic signature to form a transmission task corresponding to each file segment to be transmitted.

7. The domain name resource transmission method according to claim 1, characterized in that: The step of determining the target transmission channel corresponding to each transmission task from a plurality of transmission channels according to the domain name level corresponding to each transmission task includes: Calibrate the domain name level of each transmission task according to a pre-calibrated rule to obtain a plurality of transmission tasks associated with different domain name levels; According to the multiple transmission tasks associated with different domain name levels, a target transmission channel corresponding to each transmission task is determined from multiple transmission channels.

8. A domain name resource transmission method, characterized in that: Applied to a receiving node, the method comprises: Acquire multiple transmission tasks corresponding to the transmission of the sending node through multiple target transmission channels; According to the identification information shared by the sending node, the multiple identification cryptographic signatures in the multiple transmission tasks are sequentially verified, and the target domain name resource in the corresponding storage area is updated according to the verification result obtained by the verification; The target transmission channel corresponding to each transmission task is determined by the sending node from multiple transmission channels according to the domain name level corresponding to each transmission task; the transmission task is obtained by the sending node encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature; the identification cryptographic signature corresponding to each file segment to be transmitted is generated by obtaining the domain name resource to be transmitted through the sending node, and dividing the domain name resource to be transmitted into multiple file segments to be transmitted according to the domain name type; Among them, the computing resources of each target transmission channel are allocated by the sending node based on the allocated resources; the allocated resources of each target transmission channel are determined by the sending node for each target transmission channel based on the ratio of the corresponding channel resource allocation index to the total resource allocation index; the total resource allocation index is determined by the sending node according to the sum of multiple channel resource allocation indexes corresponding to multiple target transmission channels respectively; the channel resource allocation index of each target transmission channel is determined by the sending node according to the sum of multiple sub-resource allocation indexes corresponding to multiple transmission tasks transmitted by each target transmission channel; the sub-resource allocation index of each transmission task is obtained by the sending node for each transmission task in each target transmission channel; Among them, different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level.

9. A domain name resource transmission device, characterized in that: Applied to a sending node, the device comprises: An acquisition module is used to acquire domain name resources to be transferred; A generating module, used to divide the domain name resource to be transmitted into a plurality of file segments to be transmitted according to the domain name type, and generate a corresponding identification cryptographic signature for each file segment to be transmitted; An encapsulation module, used for encapsulating each file segment to be transmitted and the corresponding identification cryptographic signature into a transmission task; A determination module, used to determine the target transmission channel corresponding to each transmission task from multiple transmission channels according to the domain name level corresponding to each transmission task; wherein different transmission channels support different transmission protocols, and the encryption level of the transmission protocol supported by each transmission channel is positively correlated with the corresponding domain name level; A transmission module, used for obtaining, for each transmission task in each target transmission channel, a sub-resource allocation index of each transmission task; determining, according to the sum of multiple sub-resource allocation indices corresponding to multiple transmission tasks transmitted by each target transmission channel, a channel resource allocation index of each target transmission channel; determining, according to the sum of multiple channel resource allocation indices corresponding to multiple target transmission channels, a total resource allocation index; for each target transmission channel, determining, based on the ratio of the corresponding channel resource allocation index to the total resource allocation index, the allocated resources of each target transmission channel; allocating computing resources for each target transmission channel based on the allocated resources; transmitting, through multiple target transmission channels, the corresponding multiple transmission tasks to the corresponding receiving nodes, so that the receiving nodes sequentially verify, according to the identification information shared by the sending nodes, the multiple identification cryptographic signatures in the multiple transmission tasks, and update the target domain name resources of the corresponding storage area according to the verification results obtained.

10. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the domain name resource transmission method according to any one of claims 1 to 8 when executing the computer program.

11. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the domain name resource transmission method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Information security interaction method and device based on big data, electronic equipment and storage

    CN115941352A

  • Domain name resource data publishing method, domain name system, device and storage medium

    CN118041550A