A domain name resolution method, system and computer device on a trusted device

By deploying the DNS service on the SPU device and modifying the IP and port information, the problem of the SPU device being unable to communicate with the remote service is solved, secure domain name resolution and network access are achieved, and the security of information interaction is improved.

CN119544662BActive Publication Date: 2025-10-10SHENZHEN QIANGJI COMPUTING TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411503175.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-25
Publication Date
2025-10-10
Estimated Expiration
2044-10-25

AI Technical Summary

Technical Problem

In the existing technology, SPU devices cannot communicate with remote services, and gateway services such as Nginx do not provide domain name resolution functions, resulting in login information and communication information between the device and the platform being easily stolen, affecting the security of information interaction.

Method used

Deploy the DNS service on the SPU device, obtain the host IP and port information, add it to the whitelist, modify it to the virtual IP and local port information, establish a connection between the DNS service in the SPU and the DNS service in the host, and resolve the remote domain name through the host's DNS service.

Benefits of technology

This enables secure access to external networks in a network-free environment within the SPU, improving the centralization and security of domain name resolution configuration and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544662B_ABST
    Figure CN119544662B_ABST
Patent Text Reader

Abstract

The application discloses a domain name resolution method and system on a trusted device and computer equipment, and the method comprises the following steps: obtaining host IP information and host port information, and adding the host IP information and the host port information into a white list of an SPU; running a DNS service in the SPU; when an application accesses a host, modifying the host IP information and the host port information into virtual IP information and local port information of the SPU respectively, and establishing a connection between the DNS service in the SPU and a DNS service in the host; sending a domain name resolution request from the DNS service of the SPU to the DNS service of the host, and then to a domain name server of a remote LAN to complete the resolution. The application can modify target address information into specified address information, and support the SPU to access an external network in a network-free environment in the SPU by cooperating with a network forwarding program, so that the application program in the SPU is allowed to use the DNS service configured by a host computer, and thus the configuration and management of the domain name resolution are more centralized and safe.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication computing, in particular to a domain name resolution method and system on a trusted device and a computer device. BACKGROUND

[0002] As a physically isolated environment, the SPU (confidential computing coprocessor) has its own operating system, memory and CPU computing resources inside the environment, but has no physical network card, and data cannot flow out from the SPU end. In order to enable the services in the SPU to communicate with the remote services, a gateway service is needed to forward network traffic to the pcie channel. The mainstream gateway services on the market, such as Nginx, do not provide similar functions.

[0003] Therefore, the prior art still needs to be improved and improved. SUMMARY

[0004] The technical problem to be solved by the present application is to provide a domain name resolution method and system on a trusted device and a computer device to solve the problem that the security mechanism provided by the platform in the prior art cannot meet the commercial demand, which easily leads to the login information and communication information between the device and the platform being easily stolen, affecting the security of information interaction.

[0005] In order to solve the above technical problems, the technical scheme adopted by the present application is as follows:

[0006] In a first aspect, the present application provides a domain name resolution method on a trusted device, wherein the method comprises:

[0007] Obtain host IP information and host port information, and add the host IP information and the host port information to the white list of the SPU;

[0008] Run the DNS service in the SPU, and when an application accesses a host, modify the host IP information and the host port information to virtual IP information of the SPU and local port information respectively, and establish a connection between the DNS service in the SPU and the DNS service in the host;

[0009] Obtain a domain name resolution request, send the domain name resolution request from the DNS service of the SPU to the DNS service of the host, and then to the domain name server of the remote local area network to complete the resolution.

[0010] In one implementation, the adding of the host IP information and the host port information to the white list of the SPU comprises:

[0011] Adding a dnsmasq configuration in the SPU and the host, and restarting the dnsmasq configuration service;

[0012] Modify the iptables settings of the SPU and add the host IP information and the host port information to the whitelist of the SPU.

[0013] In one implementation, the DNS service of the SPU is deployed on the virtual IP information, and the DNS service of the host is deployed on the host IP information.

[0014] In one implementation, after a connection is established between the DNS service in the SPU and the DNS service in the host, the DNS service in the SPU uses the host IP information as one of the domain name servers.

[0015] In one implementation, the application of the SPU is deployed in a container, and the domain name server of the container configures the virtual IP information as the domain name server of the container.

[0016] In one implementation, the network environment of the SPU includes: a network on which a user container runs, a network on which a dind container runs, and a virtual network of the SPU.

[0017] In a second aspect, an embodiment of the present invention further provides a domain name resolution system on a trusted device, wherein the system includes:

[0018] A whitelist setting module is used to obtain host IP information and host port information, and add the host IP information and the host port information to the whitelist of the SPU;

[0019] An address information modification module is configured to run the DNS service in the SPU, and when an application accesses a host, modify the host IP information and the host port information to the virtual IP information and local port information of the SPU, respectively, and establish a connection between the DNS service in the SPU and the DNS service in the host;

[0020] The domain name resolution module is used to obtain a domain name resolution request, send the domain name resolution request from the DNS service of the SPU to the DNS service of the host, and then send it to the domain name server of the remote local area network to complete the resolution.

[0021] In one implementation, the whitelist setting module includes:

[0022] The dnsmasq configuration unit is used to add dnsmasq configuration to the SPU and host, and restart the dnsmasq configuration service;

[0023] The iptables setting unit is used to modify the iptables setting of the SPU and add the host IP information and the host port information to the whitelist of the SPU.

[0024] In a third aspect, an embodiment of the present invention further provides a computer device, wherein the computer device includes a memory, a processor, and a domain name resolution program on a trusted device stored in the memory and runnable on the processor. When the processor executes the domain name resolution program on the trusted device, the steps of the domain name resolution method on the trusted device of any one of the above-mentioned schemes are implemented.

[0025] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein a domain name resolution program on a trusted device is stored on the computer-readable storage medium. When the domain name resolution program on the trusted device is executed by a processor, the steps of the domain name resolution method on the trusted device described in any one of the above-mentioned schemes are implemented.

[0026] Beneficial effects: Compared with the prior art, the present invention provides a domain name resolution method on a trusted device. The present invention first obtains the host IP information and the host port information, and adds the host IP information and the host port information to the whitelist of the SPU. Then, the DNS service in the SPU is run. When the application accesses the host, the host IP information and the host port information are modified to the virtual IP information and local port information of the SPU respectively, and a connection is established between the DNS service in the SPU and the DNS service in the host. Finally, a domain name resolution request is obtained, and the domain name resolution request is sent from the DNS service of the SPU to the DNS service of the host, and then sent to the domain name server of the remote LAN to complete the resolution. The present invention can support access to the external network in an environment without a network in the SPU by modifying the target address information to the specified address information, cooperating with the network forwarding program, and allowing the application in the SPU to use the DNS service configured by the host, thereby making the configuration and management of domain name resolution more centralized and secure. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 The present invention provides a flowchart of a preferred embodiment of a domain name resolution method on a trusted device.

[0028] Figure 2 This is a diagram of an application scenario of the domain name resolution method on a trusted device provided by an embodiment of the present invention.

[0029] Figure 3 A schematic diagram of the architecture of a domain name resolution system on a trusted device provided by an embodiment of the present invention.

[0030] Figure 4 This is a functional block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0031] For the purposes of the present application, the technical solutions and effects, the following will be further described in detail with reference to the drawings and examples. It should be understood that the specific examples described herein are only used to explain the present application, and are not intended to limit the present application.

[0032] The flowchart shown in the drawings is only an example and does not necessarily include all contents and operations or steps, nor does it necessarily execute in the order described. For example, some operations or steps can be further divided, combined or partially merged, so the actual execution order can be changed according to the actual situation.

[0033] It should be understood that the terms used in the present application specification herein are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the present application specification and the appended claims, unless otherwise clear from the context, the singular forms "a", "an" and "the" are intended to include the plural forms.

[0034] It should be understood that in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the terms "first", "second" and the like are used to distinguish the same or similar items with basically the same function and effect. For example, the first control information and the second control information are only used to distinguish different control information, and do not limit the order.

[0035] Those skilled in the art can understand that the terms "first", "second" and the like do not limit the quantity and execution order, and the terms "first", "second" and the like do not necessarily mean different.

[0036] It should also be understood that the term "and / or" used in the present application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes these combinations.

[0037] To solve the problems in the prior art, the embodiment provides a domain name resolution method on a trusted device. In specific application, the domain name resolution method on the trusted device first acquires host IP information and host port information, and adds the host IP information and the host port information to a white list of an SPU. Then, the DNS service in the SPU is run, and when an application accesses a host, the host IP information and the host port information are modified into virtual IP information of the SPU and local port information respectively, and a connection between the DNS service in the SPU and the DNS service in the host is established. Finally, a domain name resolution request is acquired, the domain name resolution request is sent from the DNS service of the SPU to the DNS service of the host, and then to a domain name server of a remote local area network to complete resolution. The domain name resolution method on the trusted device can support access to an external network in an environment without a network in the SPU by modifying target address information into specified address information in cooperation with a network forwarding program, and allows an application program in the SPU to use the DNS service configured by a host, so that the configuration and management of domain name resolution are more centralized and secure.

[0038] The domain name resolution method on the trusted device can be applied to a terminal, and the domain name resolution method on the trusted device can be executed by the terminal or a server, or executed by the terminal and the server in cooperation.

[0039] The terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, an Internet of Things device, and a portable wearable device. The Internet of Things device can be a smart speaker, a smart television, a smart air conditioner, a smart vehicle device, and the like. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, and the like.

[0040] The server can be a standalone physical server, or a service node in a blockchain system, and the service nodes in the blockchain system form a point-to-point network.

[0041] In addition, the server can be a server cluster composed of multiple physical servers, and can be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks (CDN), and big data and artificial intelligence platforms.

[0042] The domain name resolution method on the trusted device, as shown in Figure 1 The domain name resolution method on the trusted device includes the following steps:

[0043] In step S100, host IP information and host port information are acquired, and the host IP information and the host port information are added to a white list of an SPU.

[0044] The nodes and inter-node of the SPU can only communicate through IP and port. In the environment of cluster deployment, domain name support dynamic addressing and other functions are often needed to be configured. The prior art cannot support the dynamic addressing function based on domain name. Therefore, the embodiment sets the DNS configured by the host to allow the application program in the SPU to use the DNS configured by the host, and cooperates with the network forwarding program to realize the access to the external network in the SPU without network environment. Specifically, as shown in Figure 2 The embodiment deploys the dnsmasq service on the SPU and the host. The DNS service of the SPU is deployed on the IP 10.234.233.232 of the virtual network card. The DNS service of the host is deployed on the IP of the host. The dnsmasq is a lightweight tool for providing network infrastructure for small networks, which includes DNS, DHCP, router advertisement and network boot service. It is designed to be light and resource-consuming, suitable for running on resource-limited routers and firewalls, and is widely used in network sharing of smart phones and portable hotspots, and virtual network support in virtualization framework. The dnsmasq supports full IPv6 and provides local DNS server function, can forward all types of queries to the upstream recursive DNS server, and cache common record types. The network environment of the SPU includes:

[0045] 1. 172.17.0.x: network running by the user container;

[0046] 2. 172.x.0.2: network running by the dind container, used for isolating resources and setting iptables rules;

[0047] 3. 10.234.233.232: virtual network on the SPU, used for application to access the service on the SPU.

[0048] According to the above design, the embodiment uses the dnsmasq to run a DNS service in the SPU. The dnsmasq is configured as follows:

[0049] #spu

[0050] interface=tunspu

[0051] cache-size=1000

[0052] bind-interface server=192.168.209.35

[0053] #host

[0054] interface=enp5s0

[0055] cache-size=1000

[0056] bind-interfaces

[0057] #Forward DNS requests to systemd-resolved

[0058] server=127.0.0.53

[0059] The embodiment pre-acquires host IP information and host port information, and adds the host IP information and the host port information to the whitelist of the SPU. In order to enable the container to access the DNS service, the host port needs to be added to the iptables rule of the SPU. Specifically, the embodiment installs and adds the dnsmasq configuration in the SPU and the host, and restarts the dnsmasq configuration service. Then, the iptables setting of the SPU is modified, and the host IP information and the host port information are added to the whitelist of the SPU. At the same time, the network service of the SPU listens to a random local port information locally, and the local port information is also written into the whitelist.

[0060] Step S200, running the DNS service in the SPU, when the application accesses the host, modifying the host IP information and the host port information into the virtual IP information and the local port information of the SPU respectively, establishing the connection between the DNS service in the SPU and the DNS service in the host.

[0061] Specifically, when the application initiates connection by calling the Connect system call, the driver loaded in the SPU can hijack the input parameters of the connect function, and the main function of the connect function is to initiate a connection request to the server, and the input parameters include the host IP information and the host port information of the connection. After the SPU driver hijacks the input parameters, the host IP information and the host port information of the input parameters are modified into the virtual IP information and the local port information of the SPU. In this way, the user's application can establish a connection with the port of the SPU network service, but from the application, it seems to establish a connection with the service of the host, and the host is connected with the remote service, so the application can be connected with the remote service.

[0062] Step S300, acquiring a domain name resolution request, sending the domain name resolution request from the DNS service of the SPU to the DNS service of the host, and then to the domain name server of the remote local area network to complete the resolution.

[0063] Because the SPU application in this embodiment is deployed in a container, the container's domain name server configures the virtual IP address information as the container's domain name server. Once the DNS service within the SPU is connected to the host's DNS service, domain name resolution requests in the container can be sent through the SPU's DNS service to the host's DNS service, and then to the domain name server on the remote LAN for resolution and return. This shows that the SPU in this embodiment can leverage the host's network card to implement domain name resolution. This makes the configuration and management of domain name resolution more centralized and secure.

[0064] Based on the above embodiments, the present invention also provides a domain name resolution system on a trusted device, such as Figure 3 As shown in , the system includes: a whitelist setting module 10, an address information modification module 20, and a domain name resolution module 30. Specifically, the whitelist setting module 10 is used to obtain host IP information and host port information, and add the host IP information and the host port information to the whitelist of the SPU. The address information modification module 20 is used to run the DNS service in the SPU. When an application accesses the host, the host IP information and the host port information are modified to the virtual IP information and local port information of the SPU, respectively, to establish a connection between the DNS service in the SPU and the DNS service in the host. The domain name resolution module 30 is used to obtain a domain name resolution request, send the domain name resolution request from the DNS service of the SPU to the DNS service of the host, and then send it to the domain name server of the remote local area network to complete the resolution.

[0065] In one implementation, the whitelist setting module includes:

[0066] The dnsmasq configuration unit is used to add dnsmasq configuration to the SPU and host, and restart the dnsmasq configuration service;

[0067] The iptables setting unit is used to modify the iptables setting of the SPU and add the host IP information and the host port information to the whitelist of the SPU.

[0068] In one implementation, the DNS service of the SPU is deployed on the virtual IP information, and the DNS service of the host is deployed on the host IP information.

[0069] In one implementation, after a connection is established between the DNS service in the SPU and the DNS service in the host, the DNS service in the SPU uses the host IP information as one of the domain name servers.

[0070] In an implementation manner, the application of the SPU is deployed in a container, and a domain name server of the container configures virtual IP information as the domain name server of the container.

[0071] In an implementation manner, the network environment of the SPU includes a network in which a user container runs, a network in which a dind container runs, and a virtual network of the SPU.

[0072] The working principles of the various modules in the domain name resolution system on the trusted device of the embodiment are the same as the principles of the various steps in the method embodiments, which are not described herein again.

[0073] The various modules in the domain name resolution apparatus on the trusted device can be all or part of software, hardware, and combinations thereof. The various modules can be embedded in or independent of a processor in a computer device in a hardware form, or can be stored in a memory in a computer device in a software form, so as to be called and executed by a processor to perform the operations corresponding to the various modules.

[0074] In some embodiments, a computer device can be provided, which can be a terminal, and an internal structure diagram thereof can be as shown in Figure 4 The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to perform wired or wireless communication with external terminals, and the wireless communication can be implemented through WIFI, mobile cellular network, NFC (near field communication), or other technologies. The computer program is executed by the processor to implement a domain name resolution method on a trusted device. The display unit of the computer device is configured to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or can be a key, a trackball, or a touchpad arranged on the shell of the computer device. In addition, the input device can be an external keyboard, a touchpad, or a mouse, etc.

[0075] Those skilled in the art can understand that, Figure 4The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0076] In some embodiments, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:

[0077] Obtain host IP information and host port information, and add the host IP information and the host port information to the SPU whitelist;

[0078] Running the DNS service in the SPU, and when an application accesses a host, modifying the host IP information and the host port information to the virtual IP information and local port information of the SPU, respectively, and establishing a connection between the DNS service in the SPU and the DNS service in the host;

[0079] Obtain a domain name resolution request, send the domain name resolution request from the DNS service of the SPU to the DNS service of the host, and then send it to the domain name server of the remote local area network to complete the resolution.

[0080] It should be noted that the user information (including but not limited to user device function information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0081] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0082] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0083] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A domain name resolution method on a trusted device, characterized in that: The method comprises: Obtain the host IP information and host port information, and add the host IP information and the host port information to the whitelist of the confidential computing coprocessor. At the same time, the network service of the confidential computing coprocessor will monitor a random local port information locally and write the monitored local port information into the whitelist. Run the DNS service in the confidential computing coprocessor, and when the application accesses the host, modify the host IP information and the host port information to the virtual IP information and local port information of the confidential computing coprocessor, respectively, and establish a connection between the DNS service in the confidential computing coprocessor and the DNS service in the host; Obtain a domain name resolution request, send the domain name resolution request from the DNS service of the confidential computing coprocessor to the DNS service of the host, and then send it to the domain name server of the remote local area network to complete the resolution; Adding the host IP information and the host port information to a whitelist of a confidential computing coprocessor includes: Add dnsmasq configuration to the confidential computing coprocessor and host, and restart the dnsmasq configuration service; Modify the iptables settings of the confidential computing coprocessor and add the host IP information and the host port information to the whitelist of the confidential computing coprocessor; The DNS service of the confidential computing coprocessor is deployed on the virtual IP information, and the DNS service of the host is deployed on the host IP information; When the application accesses the host, the host IP information and the host port information are modified to the virtual IP information and local port information of the confidential computing coprocessor, respectively, and a connection is established between the DNS service in the confidential computing coprocessor and the DNS service in the host, including: When an application calls the Connect system call to initiate a connection, the driver loaded into the confidential computing coprocessor can hijack the input parameters of the connect function. The main function of the connect function is to initiate a connection request to the server. The input parameters include the host IP information and host port information of the connection. After hijacking the input parameters, the confidential computing coprocessor driver modifies the host IP information and host port information into the virtual IP information and local port information of the confidential computing coprocessor. The application of the confidential computing coprocessor is deployed in a container, and the domain name server of the container configures the virtual IP information as the domain name server of the container; When the DNS service in the confidential computing coprocessor is connected to the DNS service in the host, the domain name resolution request in the container is sent to the DNS service of the host through the DNS service of the confidential computing coprocessor, and then sent to the domain name server in the remote local area network to complete the resolution and return.

2. The domain name resolution method on a trusted device according to claim 1, characterized in that: When a connection is established between the DNS service in the confidential computing coprocessor and the DNS service in the host, the DNS service in the confidential computing coprocessor uses the host IP information as one of the domain name servers.

3. The domain name resolution method on a trusted device according to claim 1, characterized in that: The network environment of the confidential computing coprocessor includes: the network running the user container, the network running the dind container, and the virtual network of the confidential computing coprocessor.

4. A domain name resolution system on a trusted device, characterized in that: The system is used to implement the steps of the domain name resolution method on a trusted device according to any one of claims 1 to 3, and the system includes: A whitelist setting module, configured to obtain host IP information and host port information, and add the host IP information and the host port information to a whitelist of a confidential computing coprocessor; An address information modification module is used to run the DNS service in the confidential computing coprocessor, and when an application accesses a host, the host IP information and the host port information are modified to the virtual IP information and local port information of the confidential computing coprocessor, respectively, to establish a connection between the DNS service in the confidential computing coprocessor and the DNS service in the host; The domain name resolution module is used to obtain a domain name resolution request, send the domain name resolution request from the DNS service of the confidential computing coprocessor to the DNS service of the host, and then send it to the domain name server of the remote local area network to complete the resolution.

5. The domain name resolution system on a trusted device according to claim 4, characterized in that: The whitelist setting module includes: The dnsmasq configuration unit is used to add dnsmasq configuration to the confidential computing coprocessor and host, and restart the dnsmasq configuration service; The iptables setting unit is used to modify the iptables settings of the confidential computing coprocessor and add the host IP information and the host port information to the whitelist of the confidential computing coprocessor.

6. A computer device, characterized in that: The computer device includes a memory, a processor, and a domain name resolution program on a trusted device stored in the memory and capable of running on the processor. When the processor executes the domain name resolution program on the trusted device, the steps of the domain name resolution method on a trusted device as described in any one of claims 1 to 3 are implemented.

7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a domain name resolution program on a trusted device. When the domain name resolution program on the trusted device is executed by a processor, the steps of the domain name resolution method on a trusted device according to any one of claims 1 to 3 are implemented.

Citation Information

Patent Citations

  • Network request proxy method and device, equipment and storage medium

    CN114745434A