Web-based authoritative domain name service management and control method
By building an authoritative web-based domain name service management system, administrator operations are simplified and domain name data changes are automatically processed, which solves the problems of inefficiency and error-prone in traditional methods, and improves the controllability and stability of domain name services.
Patent Information
- Application Number
- CN202510243388.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-30
AI Technical Summary
The traditional authoritative domain name service control methods are inefficient and error-prone, which is difficult to meet the ever-changing domain name service needs, and has high requirements for administrator technical level, which affects the stability of domain name resolution services.
Build an authoritative domain name service management system based on the web, and use the front-end management view subsystem of the domain name service and the back-end model control subsystem, provide a web interface for domain name data management and control, simplify administrator operations, automate the processing of domain name data changes and loading, and reduce manual intervention.
It improves the controllability of authoritative domain name services, reduces the error rate, improves the user experience, and maintains the stability and efficiency of domain name resolution services.
Smart Images

Figure CN120075191A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network technology, and in particular to a web-based authoritative domain name service management and control method. Background Art
[0002] The Domain Name System (DNS) provides domain name resolution services. Its main function is to map network domain name resolution to network addresses (IP addresses). Network domain names must meet the standard domain name specifications (single-level domain names cannot exceed 63 characters, the total length of domain names cannot exceed 254 characters, and special characters are not allowed). IP addresses comply with unicast IP address specifications. As a key basic network service in the network infrastructure, the domain name system is an important support for the normal operation of most network services and applications.
[0003] The domain name system mainly consists of two parts: authoritative domain name service and recursive domain name service. The authoritative domain name service builds a unified hierarchical and hierarchical authorized naming system through a tree structure, which is composed of root domain names, top-level domain names, second-level and lower authoritative domain names from top to bottom; the recursive domain name service is the entrance to the entire domain name space, and provides users with the mapping relationship between domain names and IP addresses through top-down query of authoritative domain names. Correspondingly, the management of domain name data adopts a domain-based and hierarchical management and maintenance mechanism. Each domain name is mainly managed by the authoritative domain name server of the area to which it belongs. Each subdomain needs to apply for registration with its parent domain, and a dependency relationship is formed between domain names and regional servers.
[0004] When resolving a domain name, the client usually initiates a query to a recursive server. The recursive server queries the cache content. If the domain name matches completely, it directly returns the mapping relationship between the domain name and the IP address. Otherwise, it uses a method similar to the longest suffix match to find and determine the starting authoritative server list for the domain name query, and sends a domain name resolution request to one of the server addresses based on information such as the round-trip delay. If there is no match in the cache, a domain name query request is initiated to the root server address based on the round-trip delay, and the network routes it to a root server corresponding to the address. The recursive server then gradually issues query requests based on the returned clue information. After the recursive server finally obtains the correspondence between the domain name and the IP address, it returns it to the client.
[0005] At present, the authoritative domain name service software used in the domain name system is mainly ISC (Internet Systems Consortium) BIND (Berkeley Internet Name Domain) software and NLnet Labs NSD (Name Server Daemon) software. Statistical analysis in recent years shows that in the international Internet, almost all root domain name servers use BIND software. In top-level domain name servers, the usage rates of BIND and NSD account for about 59% and 36% respectively. In the second-level and lower authoritative domain name servers, BIND accounts for about 83%. In China's domain name resolution system, BIND software occupies a dominant position, and its share in key authoritative domain name servers reaches about 93%.
[0006] When the above authoritative domain name service software is used to provide authoritative domain name services, the authoritative domain name service software mainly obtains the jurisdiction of the area and the corresponding area file list through the configuration file when it is started, and then loads the content in the area file to provide domain name resolution services. Since domain name data often needs to be constantly changed during network operation, the authoritative domain name service software needs to constantly monitor the reload and other control commands from the administrator to load the newly modified configuration files and the content of the area files. Domain name service control operations are relatively cumbersome. Taking the modification of a domain name data (mainly including the domain name and the corresponding IP address) as an example, the typical steps of traditional authoritative domain name service control include: (1) The administrator logs in to the authoritative domain name server through SSH or other methods; (2) The administrator finds the zone file corresponding to the domain name in the file directory; (3) The administrator uses an editor such as vi to open the corresponding zone file, finds the corresponding domain name resource record, modifies it, and saves the zone file after modification; (4) The administrator uses a zone check tool (such as BIND's named-checkzone) to check whether the zone file content is correct. If an error is reported, go to step (3), otherwise go to step (5); (5) The administrator uses a reload command (such as BIND's rndc reload) to let the authoritative domain name service software perform a reload operation. If the administrator mistakenly enters incorrect domain name data in the zone file (for example, using illegal domain name characters or incorrect IP address), forgets to use the zone check tool to check, and directly calls the reload command, it may cause the domain name resolution service software to fail to provide services normally, affecting the stability of the authoritative domain name service.
[0007] As the scale of the network expands and the amount of domain name data under management continues to increase, traditional authoritative domain name service management methods have poor user experience, low efficiency, and are prone to errors. They also require a high level of technical skills from domain name administrators and are difficult to meet the ever-changing needs of domain name service management. Summary of the invention
[0008] The technical problem to be solved by the present invention is to provide a web-based authoritative domain name service control method, which improves the manageability and controllability of the authoritative domain name service, improves the stability of the authoritative domain name service, improves efficiency, reduces the error rate, and enhances the user experience.
[0009] The technical solution of the present invention is as follows:
[0010] First step, construct a web-based authoritative domain name service management system. The web-based authoritative domain name service management system consists of a domain name service front-end management view subsystem, a domain name service back-end model control subsystem, and a file system, and externally connects to the authoritative domain name service software. The domain name service front-end management view subsystem, the domain name service back-end model control subsystem, the file system, and the authoritative domain name service software generally run on the same server.
[0011] The domain name service front-end management view subsystem is connected to the domain name service back-end model control subsystem, provides a web interface for the administrator, receives the login credentials, operation types, operation commands, and operation data provided by the administrator, and sends the login credentials, operation types, operation commands, and operation data to the domain name service back-end model control subsystem; the operation types are divided into zone management operation types, domain name data management operation types, data backup and recovery operation types, and log management operation types, and the operation commands and operation data are divided according to different operation types. The domain name service front-end management view subsystem consists of an administrator login unit, an instruction dispatching unit, a domain name zone management unit, a domain name data management unit, a data backup and recovery management unit, and a log management unit.
[0012] The domain name service back-end model control subsystem is connected to the domain name service front-end management view subsystem, the file system, and the authoritative domain name service software, and consists of an administrator authentication unit, a domain name zone processing unit, a domain name data processing unit, a data backup and recovery processing unit, and a log processing unit. It receives the operation commands and operation data from the domain name service front-end management view subsystem, changes the zone file and configuration file of the authoritative domain name service software according to the operation commands and operation data, and changes the archived file and key operation log file of the file system. If the zone file and configuration file of the authoritative domain name service software change, the domain name service back-end model control subsystem also sends a reload command to the authoritative domain name service software, and the authoritative domain name service of the authoritative domain name service software executes the reload command to reload the zone file and configuration file, and records the running log during the reload process into the system running log file of the authoritative domain name service software.
[0013] The file system is connected to the domain name service backend model control subsystem. The file system contains an authentication data file, a key operation log file, and an archive file. Each line of the authentication data file contains a username and the password corresponding to that username. Each line of the key operation log file contains an operation command, the time when the operation command was executed, the client IP, the username, and the operation data. The archive file is a compressed package, and each compressed package contains the zone file and configuration file of the authoritative domain name service software.
[0014] The authoritative domain name service software is connected to the domain name service backend model control subsystem. The authoritative domain name service software is the traditional authoritative domain name service software BIND or NSD. Both the authoritative domain name service software BIND and NSD have functional modules for implementing the authoritative domain name service (abbreviated as the authoritative domain name service module), and contain a zone file, a configuration file, and a system operation log file.
[0015] The administrator login unit is connected to the administrator authentication unit, receives the login credentials of the web-based authoritative domain name service management system from the administrator, and sends the login credentials to the administrator authentication unit. The administrator authentication unit determines whether the login credentials are valid. If the login credentials are valid, the administrator authentication unit returns the authoritative domain name service control homepage to the administrator login unit. After receiving the authoritative domain name service control homepage, the administrator login unit sends an authentication passed signal to the instruction dispatching unit, allowing the instruction dispatching unit to receive the operation type, operation command, and operation data sent by the administrator. If the login credentials are invalid, the administrator authentication unit returns an authentication failed status code to the administrator login unit. After receiving the authentication failed status code, the administrator login unit sends an authentication failed signal to the instruction dispatching unit, not allowing the instruction dispatching unit to receive the operation type, operation command, and operation data sent by the administrator.
[0016] The instruction dispatching unit is connected to the administrator login unit, the domain name zone management unit, the domain name data management unit, the domain name backup and recovery management unit, and the log management unit. If it receives an authentication passed signal from the administrator login unit, the instruction dispatching unit receives the operation type, operation command, and operation data sent by the administrator. If the operation type is the zone management operation type, the instruction dispatching unit sends the domain name zone addition, deletion, configuration, and query operation commands and operation data to the domain name zone management unit of the domain name service front-end management view subsystem. If the operation type is the domain name data management operation type, the instruction dispatching unit sends the domain name data addition, deletion, modification, and query operation commands and operation data to the domain name data management unit. If the operation type is the data backup and recovery operation type, the instruction dispatching unit sends the data backup and data recovery operation commands to the domain name backup and recovery management unit. If the operation type is the log management operation type, the instruction dispatching unit sends the key operation log and system operation log operation commands to the log management unit.
[0017] The domain name area management unit is connected to the instruction dispatching unit and the domain name area processing unit. The domain name area management unit receives commands and operation data for adding, deleting, configuring, and querying domain name areas from the instruction dispatching unit, sends the operation commands and operation data to the domain name area processing unit, receives area list data from the domain name area processing unit, and displays the area list data.
[0018] The domain name data management unit is connected to the instruction dispatching unit and the domain name data processing unit. The domain name data management unit receives commands and operation data for adding, deleting, modifying, and querying domain name data from the instruction dispatching unit, sends the operation commands and operation data to the domain name data processing unit, receives domain name data list data from the domain name data processing unit, and displays the domain name data list data.
[0019] The domain name backup and recovery management unit is connected to the instruction dispatching unit and the domain name backup and recovery processing unit. The domain name backup and recovery management unit receives commands and operation data for data backup and data recovery from the instruction dispatching unit, sends the operation commands and operation data to the data backup and recovery processing unit, receives archived file list data from the data backup and recovery processing unit, and displays the archived file list data.
[0020] The log management unit is connected to the instruction dispatching unit and the log processing unit. The log management unit receives commands and operation data for key operation logs and system operation logs from the instruction dispatching unit, sends the operation commands and operation data to the log processing unit, receives key operation log or system operation log data from the log processing unit, and displays the key operation log or system operation log.
[0021] The administrator authentication unit is connected to the administrator login unit and the file system. The administrator authentication unit receives login credentials from the administrator login unit, obtains login credentials from the authentication data file in the file system, authenticates the login credentials obtained from the authentication data file and the login credentials sent by the administrator login unit according to the web user authentication mechanism (such as username / password, digital certificate, etc.). If the authentication is successful, the administrator authentication unit sends the authoritative domain name service control homepage to the administrator login unit; if the authentication fails, the administrator authentication unit sends a status code indicating failed authentication to the administrator login unit. At the same time, the administrator authentication unit records the timestamp, client IP address, user information, and key operation information of the authentication result in the key operation log file of the file system.
[0022] The domain name zone processing unit is connected to the domain name zone management unit, the file system, and the authoritative domain name service software. The domain name zone processing unit receives commands and operation data for adding, deleting, configuring, and querying domain name zones from the domain name zone management unit. If the domain name zone processing unit receives an operation command for adding a domain name zone, it adds the operation data to the configuration file of the authoritative domain name service software, records the domain name zone addition operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and reads the zone list data after the addition operation data from the configuration file of the authoritative domain name service software. If the domain name zone processing unit receives an operation command for deleting a domain name zone, it deletes the operation data from the configuration file of the authoritative domain name service software, records the domain name zone deletion operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and reads the zone list data after the deletion operation data from the configuration file of the authoritative domain name service software. If the domain name zone processing unit receives an operation command for configuring a domain name zone, it configures the domain name cache time to the operation data value in the zone file of the authoritative domain name service software, records the domain name zone configuration operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends an "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and receives a configuration success status code from the authoritative service software. If the domain name zone processing unit receives an operation command for querying a domain name zone, it reads the zone list data corresponding to the query operation data from the configuration file of the authoritative domain name service software and sends the zone list data to the domain name zone management unit.
[0023] The domain name data processing unit is connected to the domain name data management unit, the file system, and the authoritative domain name service software. The domain name data processing unit receives commands and operation data for adding, deleting, modifying, and querying domain name data from the domain name data management unit. If the domain name data processing unit receives a domain name addition operation command, it adds the operation data to the zone file of the authoritative domain name service software, records the domain name addition operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the notification authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the addition operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; if the domain name data processing unit receives a domain name deletion operation command, it deletes the operation data from the zone file of the authoritative domain name service software, records the domain name deletion operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the deletion operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; if the domain name data processing unit receives a domain name modification operation command, it modifies the operation data in the zone file of the authoritative domain name service software, records the domain name modification operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the modification operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; if the domain name data processing unit receives a domain name query operation command, it queries the operation data in the zone file of the authoritative domain name service software, reads the domain name list data corresponding to the query operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit.
[0024] The domain name backup and recovery processing unit is connected to the domain name backup and recovery management unit, the file system, and the authoritative domain name service software. The domain name backup and recovery processing unit receives data backup, data recovery operation commands, and operation data from the domain name backup and recovery management unit. If the domain name backup and recovery processing unit receives a data backup operation command, it generates an archived file named after the operation data in the file system and sends the file system archived file list data to the domain name backup and recovery management unit. If the domain name backup and recovery processing unit receives a data recovery operation command, it restores the archived file named after the operation data in the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and obtains the file system archived file list data for the domain name backup and recovery management unit.
[0025] The log processing unit is connected to the log management unit, the authoritative domain name service software, and the file system. The log processing unit receives critical operation logs, system operation log operation commands, and operation data from the log management unit. If the log processing unit receives critical operation log operation commands and operation data, the log processing unit returns the critical operation log data in the critical operation log file in the file system to the log management unit. If the log processing unit receives system operation log operation commands and operation data, the log processing unit sends the system operation log data in the system operation log file of the authoritative domain name service software to the log management unit.
[0026] The authoritative domain name service software is connected to the domain name zone processing unit, the domain name data processing unit, and the domain name backup and recovery unit. If it receives a "Execute Reload Command" message sent by the domain name zone processing unit, the domain name data processing unit, and the domain name backup and recovery processing unit, the authoritative domain name service module of the authoritative domain name service software reloads the configuration file and zone file of the authoritative domain name service software, and records the logs during the reload operation in the system operation log file of the authoritative domain name service software.
[0027] Second, the administrator login unit and the administrator authentication unit cooperate with each other to complete the administrator authentication login. The administrator authentication login adopts a web user authentication mechanism (such as username / password, digital certificate mechanism, etc.). The method is as follows:
[0028] 2.1 Start the authoritative domain name service software, start the web-based authoritative domain name service management system, open the browser, enter the access address of the domain name service front-end management view subsystem, and the domain name service front-end management view subsystem starts to work.
[0029] 2.2 The administrator login unit receives the login credentials submitted by the administrator, and sends the administrator login credentials to the administrator authentication unit. The administrator authentication unit receives the login credentials from the administrator login unit, obtains the login credentials from the authentication data file in the file system, and authenticates the login credentials obtained from the authentication data file and the login credentials received from the administrator login unit according to the web user authentication mechanism (such as username / password, digital certificate, etc.); if the two login credentials are the same, the authentication is passed, and the authoritative domain name service control homepage is sent to the administrator login unit, and go to 2.3; if the authentication fails, the authentication failure status code is sent to the administrator login unit, and go to 2.2;
[0030] 2.3 The administrator login unit receives the authoritative domain name service control homepage, and sends the "authentication passed" signal to the instruction dispatching unit; at the same time, the administrator authentication unit records the timestamp, client IP address, user information, and authentication result key operation information into the key operation log file in the file system, and go to the third step.
[0031] In the third step, the instruction dispatching unit determines whether it has received the "authentication passed" signal from the administrator login unit. If it has received the "authentication passed" signal, it receives the operation type, operation command, and operation data from the administrator, and go to the fourth step; if it has not received the "authentication passed" signal, it goes back to the third step and continues to wait.
[0032] In the fourth step, the instruction dispatching unit sends the operation type, operation command, and operation data to the domain area management unit, domain data management unit, domain backup and recovery management unit, and log management unit respectively according to the operation type received from the administrator. The domain area management unit, domain data management unit, domain backup and recovery management unit, and log management unit perform authoritative domain name service management operation processing according to the received operation type, operation command, and operation data respectively. The method is as follows:
[0033] If the operation type received by the instruction dispatching unit from the administrator is the area management operation type, it sends the operation command and operation data to the domain area management unit, and go to 4.1; if the operation type received by the instruction dispatching unit from the administrator is the domain data management operation type, it sends the operation command and operation data to the domain data management unit, and go to 4.2; if the operation type received by the instruction dispatching unit from the administrator is the data backup and recovery operation type, it sends the operation command and operation data to the domain backup and recovery management unit, and go to 4.3; if the operation type received by the instruction dispatching unit from the administrator is the log management operation type, it sends the operation command and operation data to the log management unit, and go to 4.4:
[0034] 4.1 At this time, the instruction dispatching unit receives the area management operation type from the administrator. If the operation command is to add a domain name area, go to 4.1.1; if the operation command is to delete a domain name area, go to 4.1.2; if the operation command is a configuration command, go to 4.1.3; if the operation command is to query a domain name area, go to 4.1.4.
[0035] 4.1.1 The domain name area management unit receives the operation command to add a domain name area from the instruction dispatching unit, and the operation data is the area name to be added. It verifies whether the length of the area name characters and labels conforms to the standard domain name specification. If it conforms, go to 4.1.1.1; if it does not conform, go to 4.1.1.2.
[0036] 4.1.1.1 At this time, the length of the characters and labels of the added area name conforms to the standard area name specification. The domain name area management unit sends the operation command to add a domain name area and the operation data (the added area name) to the domain name area processing unit; the domain name area processing unit receives the area addition operation command and operation data from the domain name area management unit, adds the operation data (the added area name) and the file path mapping content named after the area name to the configuration file of the authoritative domain name service software, sends the "Execute reload command" message to the authoritative domain name service software, and the authoritative domain name service module of the authoritative domain name service software performs the reload operation. The authoritative domain name service module of the authoritative domain name service software records the logs during the reload operation into the system operation log file of the authoritative domain name service software. The domain name area processing unit records the domain name area addition operation command, operation data (the added area name), timestamp, client IP address, and user information into the key operation log file of the file system, reads the area list data after adding the area name from the configuration file of the authoritative domain name service software, and sends the area list data to the domain name area management unit. The domain name area management unit receives the area list data and displays the area list data in the area list of the domain name area management operation page, and go to the fourth step.
[0037] 4.1.1.2 At this time, the length of the characters and labels of the added area name does not conform to the standard area name specification. The administrator is prompted to modify the area name on the domain name area operation page, and go to 4.1.1.
[0038] 4.1.2 The domain name area management unit receives a domain name area deletion operation command from the instruction dispatching unit, and the operation data is the area name to be deleted. The domain name area management unit sends the domain name area deletion operation command and the operation data (deleted area name) to the domain name area processing unit; the domain name area processing unit receives the area deletion operation command from the domain name area management unit, deletes the operation data (deleted area name) and the file path mapping content named after the area name in the configuration file of the authoritative domain name service software, and sends the "Execute reload command" message to the authoritative domain name service software; the authoritative domain name service module of the authoritative domain name service software performs a reload operation and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name area processing unit records the domain name area deletion operation command, the operation data (deleted area name), the timestamp, the client IP address, and the user information into the file system key operation log file, reads the area list data after deleting the area name from the configuration file of the authoritative domain name service software, and sends the area list data to the domain name area management unit. The domain name area management unit receives the area list data, displays the area list data in the area list of the domain name area management operation page, and proceeds to the fourth step.
[0039] 4.1.3 The domain name area management unit receives a configuration area operation command from the instruction dispatching unit, and the operation data (area name and configuration data). The domain name area management unit verifies the legality of the configuration data. For the domain name cache time TTL in the configuration data, it verifies whether the TTL is a non - negative number and within a reasonable range (not greater than 30 * 24 * 60 * 60 seconds). If the TTL is a non - negative number and within the reasonable range, go to 4.1.3.1; if the TTL is negative or not within the reasonable range, go to 4.1.3.2.
[0040] 4.1.3.1 The domain name zone management unit sends the configuration zone operation command and operation data (zone name and configuration data) to the domain name zone processing unit. The domain name zone processing unit receives the zone configuration operation command and operation data (zone name and configuration data) from the domain name zone management unit, modifies the domain name cache time field in the zone file corresponding to the authoritative domain name service software zone name. The domain name zone processing unit sends the "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs the reload operation and records the logs during the reload operation into the system operation log file of the authoritative domain name service software. Then the domain name zone processing unit records the configuration zone operation command, operation data (zone name and configuration data), timestamp, client IP address, and user information into the file system key operation log file. The domain name zone processing unit returns the configured status code to the domain name zone management unit. The domain name zone management unit receives the configured status code sent by the domain name zone processing unit, prompts the administrator on the domain name zone management operation page that the configuration is successful, and proceeds to the fourth step.
[0041] 4.1.3.2 Prompt the administrator on the domain name zone operation page to modify the domain name cache time TTL again, and proceed to 4.1.3.
[0042] 4.1.4 The domain name zone management unit receives the query zone operation command from the instruction dispatching unit. The domain name zone management unit sends the query zone operation command and operation data to the domain name zone processing unit. The domain name zone processing unit queries and obtains the corresponding zone name list data from the configuration file. If the zone name exists in the configuration file, proceed to 4.1.4.1; if the zone name does not exist in the configuration file, proceed to 4.1.4.2.
[0043] 4.1.4.1 The domain name zone processing unit queries and obtains the corresponding zone list data from the configuration file and returns it to the domain name zone management unit. The domain name zone management unit receives the zone list data and displays the zone list data in the zone list on the domain name zone management operation page, and proceeds to the fourth step.
[0044] 4.1.4.2 The domain name zone processing unit returns empty data to the domain name zone management unit. The domain name zone management unit prompts the administrator that the queried zone name does not exist and proceeds to 4.1.4.
[0045] 4.2 At this time, the operation type received by the instruction dispatching unit from the administrator is domain name data management operation. It sends the operation command and operation data to the domain name data management unit. If the operation command is domain name data addition, proceed to 4.2.1; if the operation command is domain name data deletion, proceed to 4.2.2; if the operation command is domain name data modification, proceed to 4.2.3; if the operation command is domain name data query, proceed to 4.2.4.
[0046] 4.2.1 The domain name data management unit receives a domain name data addition operation command and operation data from the instruction dispatch unit. The operation data is the domain name to be added and the input IP address. The domain name data management unit first verifies the legality of the added domain name in the operation data, checking whether the domain name characters and label lengths conform to the standard domain name specification; then it verifies whether the input IP address in the operation data conforms to the unicast IP address specification requirements. If the IP address meets the requirements, go to 4.2.1.1; if the IP address does not meet the requirements, go to 4.2.1.2.
[0047] 4.2.1.1 The domain name data management unit sends the domain name data addition operation command and operation data (the regional name to which the domain name belongs, the added domain name, and the input IP address) to the domain name data processing unit. The domain name data processing unit adds data (the added domain name and the input IP address) to the zone file corresponding to the authoritative domain name service software's regional name, and sends an "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name data processing unit records the domain name data addition operation command, the added domain name and the input IP address in the operation data, the timestamp, the client IP address, and the user information into the file system key operation log file, and reads the domain name list data after adding the domain name from the zone file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data and displays the domain name list data in the domain name list on the domain name data management operation page, and go to the fourth step.
[0048] 4.2.1.2 Prompt the administrator to modify the IP address again on the domain name data management operation page, and go to 4.2.1.
[0049] 4.2.2 The domain name data management unit receives a domain name data deletion operation command and operation data from the instruction dispatching unit. The operation data is the regional name to which the domain name belongs and the domain name to be deleted. The domain name data management unit sends the domain name data deletion operation command and operation data (the regional name to which the domain name belongs and the domain name to be deleted) to the domain name data processing unit. The domain name data processing unit deletes the domain name data in the regional file corresponding to the regional name, and sends the message of "Execute the reload command" to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and regional file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name data processing unit records the domain name data deletion operation command, the domain name to be deleted in the operation data, the timestamp, the client IP address, and the user information into the file system key operation log file, and reads the domain name list data after deleting the domain name from the regional file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data, displays the domain name list data in the domain name list on the domain name data management operation page, and proceeds to the fourth step.
[0050] 4.2.3 The domain name data management unit receives a domain name data modification operation command and operation data from the instruction dispatching unit. The operation data is the domain name (a domain name that must exist in the regional file) and the IP address. The domain name data management unit verifies whether the IP address in the operation data meets the requirements of the unicast IP address specification. If the IP address meets the requirements, proceed to 4.2.3.1; if the IP address does not meet the requirements, proceed to 4.2.3.2.
[0051] 4.2.3.1 The domain name data management unit sends the domain name data modification operation command and operation data (the regional name to which the domain name belongs, the modified domain name, and the IP address) to the domain name data processing unit. The domain name data processing unit modifies the IP address in the regional file corresponding to the regional name of the authoritative domain name service software, and sends the message of "Execute the reload command" to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and regional file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name data processing unit records the domain name data modification operation command, the operation data (the modified domain name and the IP address), the timestamp, the client IP address, and the user information into the file system key operation log file, and reads the domain name list data after modifying the domain name from the regional file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data, displays the domain name list data in the domain name list on the domain name data management operation page, and proceeds to the fourth step.
[0052] 4.2.3.2 Prompt the administrator to modify the IP address again on the domain name data management operation page, and go to 4.2.3.
[0053] 4.2.4 The domain name data management unit receives a domain name data query operation command and operation data from the instruction dispatching unit. The operation data is the domain name to be queried. The domain name data management unit sends the domain name data query operation command and operation data (the queried domain name) to the domain name data processing unit. If the queried domain name exists in the domain name zone file corresponding to the domain name queried by the authoritative domain name service software, send the queried domain name and IP address to the domain name data management unit, and go to 4.2.4.1. If the queried domain name does not exist in the domain name zone file corresponding to the domain name queried by the authoritative domain name service software, return an empty string to the domain name data management unit, and go to 4.2.4.2.
[0054] 4.2.4.1 The domain name data management unit receives the domain name list data and displays the domain name list data in the domain name list on the domain name data management operation page, and go to the fourth step.
[0055] 4.2.4.2 The domain name data management unit receives an empty string, prompts the administrator on the page that the queried domain name does not exist, and go to 4.2.4.
[0056] 4.3 At this time, the operation type received by the instruction dispatching unit from the administrator is data backup and recovery. If the operation command is data backup, go to 4.3.1; if the operation command is data recovery, go to 4.3.2.
[0057] 4.3.1 The domain name backup and recovery management unit receives a data backup operation command and operation data from the instruction dispatching unit. The operation data is the name of the file generated by packaging and archiving the authoritative domain name service software configuration file and zone file. The domain name backup and recovery management unit sends the data backup operation command and operation data to the domain name backup and recovery processing unit. The domain name backup and recovery processing unit packages and archives the authoritative domain name service software configuration file and zone file and names it as the file name specified by the operation data. After the packaging and archiving is completed, send the archived file list data to the domain name backup and recovery management unit. The domain name backup and recovery processing unit records the data backup operation command, operation data (the name of the file generated by packaging and archiving the authoritative domain name service software configuration file and zone file), timestamp, client IP address, and user information into the file system key operation log file. The domain name backup and recovery management unit receives the archived file list data and displays the archived file list data in the archived file list on the domain name backup and recovery management operation page, and go to the fourth step.
[0058] 4.3.2 The domain name backup and recovery management unit receives a data recovery operation command and operation data from the instruction dispatching unit. The operation data is the name of the archived file to be recovered. The domain name backup and recovery management unit sends the data recovery operation command and operation data to the domain name backup and recovery processing unit. The domain name backup and recovery processing unit uses the archived file corresponding to the name of the recovered archived file to overwrite the configuration file and zone file used by the authoritative domain name service software. After the overwriting is completed, the domain name backup and recovery processing unit sends the "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software. Then the domain name backup and recovery processing unit records the data recovery operation command, operation data (name of the recovered archived file), timestamp, client IP address, and user information into the file system key operation log file. The domain name backup and recovery processing unit reads the archived file list and sends the archived file list data to the domain name backup and recovery management unit. The domain name backup and recovery management unit receives the domain name list data and displays the archived file list data in the archived file list on the domain name backup and recovery management operation page, then proceeds to the fourth step.
[0059] 4.4 The instruction dispatching unit receives the log management operation type from the administrator. If the operation command is the key operation log command, proceed to 4.4.1; if the operation command is the system operation log command, proceed to 4.4.2.
[0060] 4.4.1 The log management unit receives the key operation log operation command and operation data (with a null value) from the instruction dispatching unit. The log management unit sends the key operation log operation command and operation data to the log processing unit. After receiving the key operation log operation command, the log processing unit obtains the data in the file system key operation log file and sends the data in the key operation log file to the log management unit. The log management unit receives the key operation log data and displays the key operation log data in the log data area on the log management operation page, then proceeds to the fourth step.
[0061] 4.4.2 The log management unit receives the system operation log operation command and operation data from the instruction dispatching unit. The log management unit sends the system operation log operation command and operation data to the log processing unit. After receiving the system operation log operation command, the log processing unit obtains the data of the system operation log file of the authoritative domain name service software and sends the data in the system operation log file to the log management unit. The log management unit receives the data in the system operation log file and displays the data in the log management unit, then proceeds to the fourth step.
[0062] A web-based authoritative domain name service control method aims to improve the manageability and controllability of authoritative domain name services. The monitored object, the authoritative domain name service, is always running unless the server shuts down or an error occurs, in which case the authoritative domain name service will stop. Therefore, as long as the authoritative domain name service is running, the present invention will work in a loop and will not end (unless there is a power outage or a fault).
[0063] The following technical effects can be achieved by adopting the present invention:
[0064] (1) Improve the manageability and controllability of authoritative domain name services:
[0065] Taking the modification of a domain name data (modifying the IP address corresponding to the domain name) as an example, the typical steps of traditional authoritative domain name service control are as follows: ① The administrator logs in to the authoritative domain name server through methods such as SSH; ② The administrator finds the zone file corresponding to the domain name in the file directory; ③ The administrator uses an editor such as vi to open the corresponding zone file, locates the corresponding domain name resource record, modifies it, and saves the zone file after modification; ④ The administrator uses a zone check tool (such as named-checkzone of BIND) to check whether the content of the zone file is correct. If an error is reported, go to step ③, otherwise go to step ⑤; ⑤ The administrator uses a reload command (such as rndc reload of BIND) to let the domain name service software perform a reload operation. However, the present invention realizes the domain name data modification operation through step 4.2.3. All operations are completed by the domain name data management unit and the data processing unit. The administrator only needs to provide operation data (the zone name to which the domain name belongs, the domain name, and the IP address corresponding to the domain name) to modify the domain name resource record, without the need for the administrator to execute ①②③ as in the traditional authoritative domain name service control method, which simplifies the steps, reduces the requirements for the administrator's business ability, and at the same time displays the domain name zone data and domain name resource records managed by the traditional authoritative domain name service software through the zone list and domain name list data respectively for centralized management. Compared with the traditional authoritative domain name service control, the manageability and controllability of the authoritative domain name service are improved.
[0066] (2) Reduce the error rate and improve the user experience:
[0067] Taking the addition of a domain name data (adding a domain name and its corresponding IP address) as an example, the typical steps for traditional authoritative domain name service management and control are as follows: ① The administrator logs in to the authoritative domain name server through methods such as SSH; ② The administrator finds the zone file corresponding to the domain name in the file directory; ③ The administrator uses an editor such as vi to open the corresponding zone file, adds the domain name data at the last line of the zone file, and saves the zone file after adding; ④ The administrator uses a zone check tool (such as named-checkzone in BIND) to check whether the content of the zone file is correct. If an error is reported, go back to step ③, otherwise go to step ⑤; ⑤ The administrator uses a reload command (such as rndc reload in BIND) to let the domain name service software perform a reload operation. The filling of domain name data requires a high technical level from the domain name administrator and is prone to repeated errors. The present invention realizes domain name service management and control through step 4.2.1. The domain name data management unit will perform a legality verification on the added domain name and its corresponding IP address. If it is illegal, the domain name data management operation page will prompt the administrator to modify the domain name or its corresponding IP. The user can directly modify the domain name and its corresponding IP on the domain name data management operation page. If it is legal, the domain name data management unit will send the zone name to which the domain name belongs, the added domain name, and its corresponding IP to the domain name data processing unit. Compared with traditional domain name service management and control, step ④ does not need to be executed separately, and it is ensured that the data sent to the domain name data management unit must be legal, reducing the error rate and improving the user experience compared with traditional authoritative domain name service management and control.
[0068] (3) Improve the stability of the authoritative domain name service and improve the usage efficiency.
[0069] For traditional authoritative domain name service software, the administrator needs to open zone files one by one. When the data volume is relatively large, the viewing efficiency of the administrator becomes much lower. Without modifying the code of the authoritative domain name service software, the present invention places the domain name zone management and domain name data management on the home page of the authoritative domain name service management and control, making the display of the domain name zone and domain name data more intuitive, improving the usage efficiency. At the same time, after the authoritative domain name service module of the authoritative domain name service software is started, when performing steps 4.1, 4.2, and 4.3 on the home page of the authoritative domain name service management and control, it is possible to implement web-based authoritative domain name service management without stopping the existing authoritative domain name service module, improving the stability of the authoritative domain name service. Brief Description of the Drawings
[0070] Figure 1 is the overall flowchart of the present invention;
[0071] Figure 2 is the logical structure diagram of the web-based authoritative domain name service management system constructed in the first step of the present invention;
[0072] Figure 3 It is the display of the data list of the regional name area added in the fourth step of the present invention;
[0073] Figure 4 It is the error regional name prompt diagram added in the fourth step of the present invention;
[0074] Figure 5 It is the display of the data list of the regional name area deleted in the fourth step of the present invention;
[0075] Figure 6 It is the success result diagram of the domain name area configuration in the fourth step of the present invention;
[0076] Figure 7 It is the error prompt diagram for incorrect input of the domain name cache time in the fourth step of the present invention;
[0077] Figure 8 It is the display of the data list of the regional name area queried in the fourth step of the present invention;
[0078] Figure 9 It is the effect diagram of the prompt for non - existence of the queried regional name in the fourth step of the present invention;
[0079] Figure 10 It is the display of the data list of the domain name data added in the fourth step of the present invention;
[0080] Figure 11 It is the error prompt diagram for the domain name IP address added in the fourth step of the present invention;
[0081] Figure 12 It is the error prompt diagram for the domain name added in the fourth step of the present invention;
[0082] Figure 13 It is the error prompt diagram for both the domain name and the IP address added in the fourth step of the present invention;
[0083] Figure 14 It is the display of the data list of the domain name list deleted in the fourth step of the present invention;
[0084] Figure 15 It is the display of the data list of the domain name list modified in the fourth step of the present invention;
[0085] Figure 16 It is the display of the data list of the domain name list queried in the fourth step of the present invention;
[0086] Figure 17 It is the display of the data list of the data backup archive files in the fourth step of the present invention;
[0087] Figure 18 It is the display of the data list of the data recovery archive files in the fourth step of the present invention;
[0088] Figure 19 It is the display of the key operation log data in the fourth step of the present invention. Detailed implementation mode
[0089] As Figure 1 shown, the present invention includes the following steps:
[0090] In the first step, a web-based authoritative domain name service management system is constructed by the following method:
[0091] The logical structure diagram of the web-based authoritative domain name service management system is as Figure 2 shown, and it consists of a domain name service front-end management view subsystem, a domain name service back-end model control subsystem, and a file system, and is externally connected to the authoritative domain name service software. The domain name service front-end management view subsystem, the domain name service back-end model control subsystem, the file system, and the authoritative domain name service software are installed on the same server.
[0092] The domain name service front-end management view subsystem is connected to the domain name service back-end model control subsystem, provides a web interface for the administrator, receives the login credentials, operation type, operation command, and operation data provided by the administrator, and sends the login credentials, operation type, operation command, and operation data to the domain name service back-end model control subsystem; the operation type is divided into area management operation type, domain name data management operation type, data backup and recovery operation type, and log management operation type, and the operation command and operation data are divided according to different operation types. The domain name service front-end management view subsystem consists of an administrator login unit, an instruction dispatching unit, a domain name area management unit, a domain name data management unit, a data backup and recovery management unit, and a log management unit.
[0093] The domain name service back-end model control subsystem is connected to the domain name service front-end management view subsystem, the file system, and the authoritative domain name service software, and consists of an administrator authentication unit, a domain name area processing unit, a domain name data processing unit, a data backup and recovery processing unit, and a log processing unit. It receives the operation command and operation data from the domain name service front-end management view subsystem, changes the zone file and configuration file of the authoritative domain name service software according to the operation command and operation data, and changes the archived file and key operation log file of the file system. If the zone file and configuration file of the authoritative domain name service software change, the domain name service back-end model control subsystem also sends a reload command to the authoritative domain name service software, and the authoritative domain name service of the authoritative domain name service software executes the reload command to reload the zone file and configuration file, and records the running log during the reload process into the system running log file of the authoritative domain name service software.
[0094] The file system is connected to the domain name service backend model control subsystem. The file system contains an authentication data file, a key operation log file, and an archive file. Each line of the authentication data file contains a username and the password corresponding to that username. Each line of the key operation log file contains an operation command, the time when the operation command was executed, the client IP, the username, and the operation data. The archive file is a compressed package, and each compressed package contains the zone file and configuration file of the authoritative domain name service software.
[0095] The authoritative domain name service software is connected to the domain name service backend model control subsystem. The authoritative domain name service software is the traditional authoritative domain name service software BIND or NSD. Both the authoritative domain name service software BIND and NSD have functional modules for implementing authoritative domain name services (referred to as authoritative domain name service modules), and contain zone files, configuration files, and system operation log files.
[0096] The administrator login unit is connected to the administrator authentication unit, receives the login credentials of the web-based authoritative domain name service management system from the administrator, and sends the login credentials to the administrator authentication unit. The administrator authentication unit determines whether the login credentials are valid. If the login credentials are valid, the administrator authentication unit returns the authoritative domain name service control homepage to the administrator login unit. After receiving the authoritative domain name service control homepage, the administrator login unit sends an authentication passed signal to the instruction dispatching unit, allowing the instruction dispatching unit to receive the operation type, operation command, and operation data sent by the administrator. If the login credentials are invalid, the administrator authentication unit returns an authentication failed status code to the administrator login unit. After receiving the authentication failed status code, the administrator login unit sends an authentication failed signal to the instruction dispatching unit, not allowing the instruction dispatching unit to receive the operation type, operation command, and operation data sent by the administrator.
[0097] The instruction dispatching unit is connected to the administrator login unit, the domain name zone management unit, the domain name data management unit, the domain name backup and recovery management unit, and the log management unit. If it receives an authentication passed signal from the administrator login unit, the instruction dispatching unit receives the operation type, operation command, and operation data sent by the administrator. If the operation type is the zone management operation type, the instruction dispatching unit sends the domain name zone addition, deletion, configuration, and query operation commands and operation data to the domain name zone management unit of the domain name service front-end management view subsystem. If the operation type is the domain name data management operation type, the instruction dispatching unit sends the domain name data addition, deletion, modification, and query operation commands and operation data to the domain name data management unit. If the operation type is the data backup and recovery operation type, the instruction dispatching unit sends the data backup and data recovery operation commands to the domain name backup and recovery management unit. If the operation type is the log management operation type, the instruction dispatching unit sends the key operation log and system operation log operation commands to the log management unit.
[0098] The domain name area management unit is connected to the instruction dispatching unit and the domain name area processing unit. The domain name area management unit receives commands and operation data for adding, deleting, configuring, and querying domain name areas from the instruction dispatching unit, sends the operation commands and data to the domain name area processing unit, receives area list data from the domain name area processing unit, and displays the area list data.
[0099] The domain name data management unit is connected to the instruction dispatching unit and the domain name data processing unit. The domain name data management unit receives commands and operation data for adding, deleting, modifying, and querying domain name data from the instruction dispatching unit, sends the operation commands and data to the domain name data processing unit, receives domain name data list data from the domain name data processing unit, and displays the domain name data list data.
[0100] The domain name backup and recovery management unit is connected to the instruction dispatching unit and the domain name backup and recovery processing unit. The domain name backup and recovery management unit receives commands and operation data for data backup and recovery from the instruction dispatching unit, sends the operation commands and data to the data backup and recovery processing unit, receives archived file list data from the data backup and recovery processing unit, and displays the archived file list data.
[0101] The log management unit is connected to the instruction dispatching unit and the log processing unit. The log management unit receives commands and operation data for key operation logs and system operation logs from the instruction dispatching unit, sends the operation commands and data to the log processing unit, receives key operation log or system operation log data from the log processing unit, and displays the key operation log or system operation log.
[0102] The administrator authentication unit is connected to the administrator login unit and the file system. The administrator authentication unit receives login credentials from the administrator login unit, obtains login credentials from the authentication data file in the file system, authenticates the login credentials obtained from the authentication data file and the login credentials sent by the administrator login unit according to the web user authentication mechanism (such as username / password, digital certificate, etc.). If the authentication is successful, the administrator authentication unit sends the authoritative domain name service control homepage to the administrator login unit; if the authentication fails, the administrator authentication unit sends a status code indicating authentication failure to the administrator login unit, and at the same time, the administrator authentication unit records the timestamp, client IP address, user information, and key operation information of the authentication result in the key operation log file of the file system.
[0103] The domain name zone processing unit is connected to the domain name zone management unit, the file system, and the authoritative domain name service software. The domain name zone processing unit receives commands and operation data for adding, deleting, configuring, and querying domain name zones from the domain name zone management unit. If the domain name zone processing unit receives an operation command for adding a domain name zone, it adds the operation data to the configuration file of the authoritative domain name service software, records the domain name zone addition operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and reads the zone list data after the addition operation data from the configuration file of the authoritative domain name service software. If the domain name zone processing unit receives an operation command for deleting a domain name zone, it deletes the operation data from the configuration file of the authoritative domain name service software, records the domain name zone deletion operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and reads the zone list data after the deletion operation data from the configuration file of the authoritative domain name service software. If the domain name zone processing unit receives an operation command for configuring a domain name zone, it configures the domain name cache time to the operation data value in the zone file of the authoritative domain name service software, records the domain name zone configuration operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends an "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and receives a configuration success status code from the authoritative service software. If the domain name zone processing unit receives an operation command for querying a domain name zone, it reads the zone list data corresponding to the query operation data from the configuration file of the authoritative domain name service software and sends the zone list data to the domain name zone management unit.
[0104] The domain name data processing unit is connected to the domain name data management unit, the file system, and the authoritative domain name service software. The domain name data processing unit receives commands and operation data for adding, deleting, modifying, and querying domain name data from the domain name data management unit. If the domain name data processing unit receives a domain name addition operation command, it adds the operation data to the zone file of the authoritative domain name service software, records the domain name addition operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the notification authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the addition operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; if the domain name data processing unit receives a domain name deletion operation command, it deletes the operation data from the zone file of the authoritative domain name service software, records the domain name deletion operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the deletion operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; if the domain name data processing unit receives a domain name modification operation command, it modifies the operation data in the zone file of the authoritative domain name service software, records the domain name modification operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the modification operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; if the domain name data processing unit receives a domain name query operation command, it queries the operation data in the zone file of the authoritative domain name service software, reads the domain name list data corresponding to the query operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit.
[0105] The domain name backup and recovery processing unit is connected to the domain name backup and recovery management unit, the file system, and the authoritative domain name service software. The domain name backup and recovery processing unit receives data backup, data recovery operation commands, and operation data from the domain name backup and recovery management unit. If the domain name backup and recovery processing unit receives a data backup operation command, it generates an archived file named after the operation data in the file system and sends the file system archived file list data to the domain name backup and recovery management unit. If the domain name backup and recovery processing unit receives a data recovery operation command, it restores the archived file named after the operation data in the file system, sends a "Execute Reload Command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and obtains the file system archived file list data for the domain name backup and recovery management unit.
[0106] The log processing unit is connected to the log management unit, the authoritative domain name service software, and the file system. The log processing unit receives critical operation logs, system operation log operation commands, and operation data from the log management unit. If the log processing unit receives critical operation log operation commands and operation data, it returns the critical operation log data in the critical operation log file in the file system to the log management unit. If the log processing unit receives system operation log operation commands and operation data, it sends the system operation log data in the system operation log file of the authoritative domain name service software to the log management unit.
[0107] The authoritative domain name service software is connected to the domain name zone processing unit, the domain name data processing unit, and the domain name backup and recovery unit. If it receives a "Execute Reload Command" message sent by the domain name zone processing unit, the domain name data processing unit, and the domain name backup and recovery processing unit, the authoritative domain name service module of the authoritative domain name service software reloads the configuration file and zone file of the authoritative domain name service software and records the logs during the reload operation in the system operation log file of the authoritative domain name service software.
[0108] Second, the administrator login unit and the administrator authentication unit cooperate with each other to complete the administrator authentication login. The administrator authentication login adopts a web user authentication mechanism (such as username / password, digital certificate mechanism, etc.). The method is as follows:
[0109] 2.1 Start the authoritative domain name service software, start the web-based authoritative domain name service management system, open the browser, enter the access address of the domain name service front-end management view subsystem, and the domain name service front-end management view subsystem starts to work.
[0110] 2.2 The administrator inputs the administrator login credentials on the login page of the front-end management view subsystem of the domain name service. The administrator login unit receives the login credentials submitted by the administrator, sends the administrator login credentials to the administrator authentication unit. The administrator authentication unit receives the login credentials from the administrator login unit, obtains the login credentials from the authentication data file in the file system, and authenticates the login credentials obtained from the authentication data file and the login credentials received from the administrator login unit according to the web user authentication mechanism (such as username / password, digital certificate, etc.); if the two login credentials are the same, the authentication is passed, and the authoritative domain name service control homepage is sent to the administrator login unit, and go to 2.3; if the authentication fails, the authentication failure status code is sent to the administrator login unit, and go to 2.2;
[0111] 2.3 The administrator login unit receives the authoritative domain name service control homepage, and the front-end management view subsystem of the domain name service displays the authoritative domain name service control homepage, and sends the "authentication passed" signal to the instruction dispatching unit; at the same time, the administrator authentication unit records the timestamp, client IP address, user information, and authentication result key operation information into the key operation log file in the file system.
[0112] In the third step, the instruction dispatching unit determines whether it has received the "authentication passed" signal from the administrator login unit. If it has received the "authentication passed" signal, the administrator operates on the authoritative domain name service control homepage to determine the operation type, operation command, and operation data. The instruction dispatching unit receives the operation type, operation command, and operation data from the administrator, and go to the fourth step; if it has not received the "authentication passed" signal, then go back to the third step and continue to wait.
[0113] In the fourth step, the instruction dispatching unit sends the operation type, operation command, and operation data to the domain name area management unit, domain name data management unit, domain name backup and recovery management unit, and log management unit respectively according to the operation type received from the administrator. The domain name area management unit, domain name data management unit, domain name backup and recovery management unit, and log management unit perform authoritative domain name service management operation processing according to the received operation type, operation command, and operation data respectively. The method is as follows:
[0114] If the operation type received by the instruction dispatching unit from the administrator is the area management operation type, the operation command and operation data are sent to the domain name area management unit, and go to 4.1; if the operation type received by the instruction dispatching unit from the administrator is the domain name data management operation type, the operation command and operation data are sent to the domain name data management unit, and go to 4.2; if the operation type received by the instruction dispatching unit from the administrator is the data backup and recovery operation type, the operation command and operation data are sent to the domain name backup and recovery management unit, and go to 4.3; if the operation type received by the instruction dispatching unit from the administrator is the log management operation type, the operation command and operation data are sent to the log management unit, and go to 4.4:
[0115] 4.1 The administrator selects the domain name area management unit on the authoritative domain name service control homepage. The authoritative domain name service control homepage switches to the domain name area management operation page. The instruction dispatching unit receives the area management operation type from the administrator. If the operation command is to add a domain name area, go to 4.1.1; if the operation command is to delete a domain name area, go to 4.1.2; if the operation command is a configuration command, go to 4.1.3; if the operation command is to query a domain name area, go to 4.1.4.
[0116] 4.1.1 The administrator clicks the add domain name area button on the domain name area management operation page, and an input box will appear. Enter the name of the area to be added, and verify whether the length of the area name string and label conforms to the standard domain name specification. If the name of the area to be added is m and it conforms to the standard domain name specification, go to 4.1.1.1; if the name of the area to be added is @m and it does not conform to the standard domain name specification, go to 4.1.1.2.
[0117] 4.1.1.1 The added area name m conforms to the standard area name specification. The domain name area management unit sends the domain name area addition operation command and operation data (the added area name m) to the domain name area processing unit; the domain name area processing unit receives the area addition operation command and operation data from the domain name area management unit, adds the operation data (the added area name m) and the file path mapping content named after the area name to the configuration file of the authoritative domain name service software, and sends the "execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs the reload operation. The authoritative domain name service module of the authoritative domain name service software records the logs during the reload operation into the system operation log file of the authoritative domain name service software. The domain name area processing unit records the domain name area addition operation command, operation data (the added area name m), timestamp, client IP address, and user information into the file system key operation log file, reads the area list data after adding the area name from the configuration file of the authoritative domain name service software, and sends the area list data to the domain name area management unit. The domain name area management unit receives the area list data and displays the area list data on the domain name area management operation page. The display result of the area list data is as Figure 3 shown Figure 3 In it, area a and n are the area names that existed in the configuration file of the authoritative domain name service software before adding the area name, and m is the newly added area name in the configuration file of the authoritative domain name service software. Go to the fourth step.
[0118] 4.1.1.2 The added area name @m does not conform to the standard domain name specification. As Figure 4 shown, prompt the administrator to modify the area name on the domain name area operation page, and go to 4.1.1.
[0119] 4.1.2 The administrator clicks the area deletion button in the row where the area name n is located in the area list on the domain name area management operation page area. The domain name area management unit receives the domain name area deletion operation command from the instruction dispatching unit. The operation data is the deleted area name n. The domain name area management unit sends the domain name area deletion operation command and the operation data (the deleted area name n) to the domain name area processing unit. The domain name area processing unit receives the area deletion operation command sent by the domain name area management unit, deletes the operation data (the deleted area name n) and the file path mapping content named after the area name in the configuration file of the authoritative domain name service software, and sends the "Execute reload command" message to the authoritative domain name service software; the authoritative domain name service module of the authoritative domain name service software performs the reload operation and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name area processing unit records the domain name area deletion operation command, the operation data (the deleted area name n), the timestamp, the client IP address, and the user information into the file system key operation log file, reads the area list data after deleting the area name from the configuration file of the authoritative domain name service software, and sends the area list data to the domain name area management unit. The domain name area management unit receives the area list data and displays the area list data in the area list on the domain name area management operation page. The display result of the area list data is as Figure 5 shown, which is all the area names in the configuration file of the authoritative domain name service software after deleting the area name n. Go to step 4.
[0120] 4.1.3 The administrator clicks the area configuration button in the row where the area name m is located in the area list on the domain name area management operation page, and an input box will appear for entering configuration data (in seconds). The domain name area management unit verifies the legality of the operation data. For the domain name cache time TTL in the configuration data, it verifies whether the TTL is a non - negative number and within a reasonable range (not greater than 30 * 24 * 60 * 60 seconds). If the entered configuration data is 10, which meets the requirements of the domain name cache time, go to 4.1.3.1. If the entered configuration data is 2592005, which does not meet the requirements of the domain name cache time, go to 4.1.3.2.
[0121] 4.1.3.1 The domain name area management unit sends the configuration area operation command and operation data (area name m and configuration data 10) to the domain name area processing unit. The domain name area processing unit receives the area configuration operation command and operation data (area name m and configuration data 10) from the domain name area management unit, modifies the domain name cache time field in the area file corresponding to the area name m of the authoritative domain name service software. The domain name area processing unit sends the "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs the reload operation and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name area processing unit records the configuration area operation command, operation data (area name m and configuration data 10), timestamp, client IP address, and user information into the file system key operation log file. The domain name area processing unit returns the configured status code to the domain name area management unit. After receiving the configured status code, the domain name area management unit displays the prompt information as shown in Figure 6 to prompt the administrator that the configuration is successful and proceed to the fourth step.
[0122] 4.1.3.2 As shown in Figure 7 , prompt the administrator to modify the domain name cache time again on the domain name area operation page and proceed to 4.1.3.
[0123] 4.1.4 The administrator enters the area name to be queried on the domain name area management operation page. The domain name area management unit receives the query area operation command from the instruction dispatching unit. The domain name area management unit sends the query area operation command and operation data (the queried area name) to the domain name area processing unit. The domain name area processing unit queries and obtains the corresponding area name list data from the configuration file. If the queried area name is m and the area name m exists in the configuration file, proceed to 4.1.4.1; if the queried area name is k and the area name k does not exist in the configuration file, proceed to 4.1.4.2.
[0124] 4.1.4.1 The domain name area processing unit queries and obtains the corresponding area name list data from the configuration file and returns it to the domain name area management unit. After receiving the area list data, the domain name area management unit, as shown in Figure 8 , displays the queried area name information in the area list on the domain name area operation page and proceeds to the fourth step.
[0125] 4.1.4.2 The domain name area processing unit returns empty data to the domain name area management unit. After receiving the empty data, the domain name area management unit, as shown in Figure 9 , prompts that the area name k does not exist on the domain name area operation page and proceeds to 4.1.4.
[0126] 4.2 The administrator selects the domain name data management unit on the authoritative domain name service control homepage. The authoritative domain name service control homepage switches to the domain name data management operation page. The instruction dispatching unit receives the domain name data management operation type from the administrator and sends the operation command and operation data to the domain name data management unit. The domain name data management unit receives the operation command and operation data from the instruction dispatching unit. If the operation command is domain name data addition, go to 4.2.1; if the operation command is domain name data deletion, go to 4.2.2; if the operation command is domain name data modification, go to 4.2.3; if the operation command is domain name data query, go to 4.2.4.
[0127] 4.2.1 The administrator clicks the domain name addition button on the domain name data management operation page, adds a domain name resource record in area m, enters the domain name in the domain name input box, and enters the IP address in the IP address box. If the domain name entered in the domain name input box is www.m. (complies with the standard domain name specification) and the entered IP is 8.8.8.8 (complies with the unicast IP address specification requirements), go to 4.2.1.1; if the domain name entered in the domain name input box is www.m. (complies with the standard domain name specification) and the entered IP address is 255.255.255.0 (does not comply with the unicast IP address specification requirements), go to 4.2.1.2; if the domain name entered in the domain name input box is @www.m. (does not comply with the standard domain name specification) and the entered IP address is 8.8.8.8 (complies with the unicast IP address specification requirements), go to 4.2.1.3; if the domain name entered in the domain name input box is @www.m and the entered IP is 255.255.255.0 (does not comply with the unicast IP address specification requirements), go to 4.2.1.4.
[0128] 4.2.1.1 The domain name data management unit receives a domain name data addition operation command from the instruction dispatch unit. The operation data is the domain name www.m. and the IP address 8.8.8.8. The domain name data management unit sends the domain name data addition operation command and the operation data (the domain name zone name m to which the domain name belongs, the added domain name www.m., and the IP address 8.8.8.8) to the domain name data processing unit. The domain name data processing unit adds the data (the domain name www.m. and the IP address 8.8.8.8) to the zone file corresponding to the zone name m of the authoritative domain name service software, and sends a "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name data processing unit records the domain name data addition operation command, the operation data (the added domain name and the input IP address), the timestamp, the client IP address, and the user information into the file system key operation log file, and reads the domain name list data after adding the domain name from the zone file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data. As Figure 10 shown, the domain name list data is displayed in the domain name list on the domain name data management operation page, and proceed to the fourth step.
[0129] 4.2.1.2 As Figure 11 shown, the administrator is prompted on the domain name data management operation page that the IP address does not meet the requirements of the unicast IP address specification, and proceed to 4.2.1.
[0130] 4.2.1.3 As Figure 12 shown, the administrator is prompted on the domain name data management operation page that the domain name does not meet the standard domain name specification, and proceed to 4.2.1.
[0131] 4.2.1.4 As Figure 13 shown, the administrator is prompted on the domain name data management operation page that the domain name does not meet the standard domain name specification and the IP address does not meet the requirements of the unicast IP address specification, and proceed to 4.2.1.
[0132] 4.2.2 The administrator clicks the "Delete Domain Name" button on the domain name resource record "aaa.m." in the domain name data list in the domain name data management operation page area m. The domain name data management unit receives a domain name data deletion operation command from the instruction dispatching unit. The operation data is the area name to which the domain name belongs and the domain name to be deleted. The domain name data management unit sends the domain name data deletion operation command and the operation data (the area name m to which the domain name belongs and the domain name aaa.m. to be deleted) to the domain name data processing unit. The domain name data processing unit deletes the domain name data in the zone file corresponding to the area name m, sends a "Execute Reload Command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name data processing unit records the domain name data deletion operation command, operation data (the domain name www.m. to be deleted), timestamp, client IP address, and user information into the file system key operation log file, and reads the domain name list data after deleting the domain name from the zone file of the authoritative domain name service software and sends it to the domain name data management unit; the domain name data management unit receives the domain name list data, as Figure 14 shown, displays the domain name list data after deleting the domain name www.m. in the domain name list on the domain name data management operation page, and proceeds to step 4.
[0133] 4.2.3 The administrator clicks the "Modify Domain Name" button on the domain name resource record "bbb.m." in the domain name data list in the domain name data management operation page area m. At this time, the domain name data management unit receives a domain name data modification operation command from the instruction dispatching unit. The operation data is the area name m, the domain name bbb.m., and the IP address 9.9.9.9 corresponding to the domain name bbb.m. (changing the IP address 12.12.12.12 to 9.9.9.9), and proceeds to 4.2.3.1.
[0134] 4.2.3.1 The domain name data management unit sends the domain name data modification operation command and operation data (zone name m, domain name bbb.m., and IP address 9.9.9.9) to the domain name data processing unit. The domain name data processing unit modifies the IP address corresponding to the domain name bbb.m. from 12.12.12.12 to 9.9.9.9 in the zone file corresponding to the zone name m of the authoritative domain name service software, and sends the "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name data processing unit records the domain name data modification operation command, operation data (modified domain name and IP address), timestamp, client IP address, and user information into the file system key operation log file, and reads the domain name list data after modifying the domain name from the zone file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data, as Figure 15 shown, displays the domain name list data after modifying the data on the domain name data management operation page, and proceeds to the fourth step.
[0135] 4.2.4 The administrator queries the domain name www.m. in the zone name m on the domain name data management operation page. The domain name data management unit receives the domain name data query operation command from the instruction dispatching unit, and the operation data is the queried domain name and zone name m. The domain name data management unit sends the domain name data query operation command and operation data (queried domain name and zone name m) to the domain name data processing unit, and sends the queried domain name list data to the domain name data management unit. The domain name data management unit receives the domain name list data, as Figure 16 shown, displays the queried domain name list data on the domain name data management operation page, and proceeds to the fourth step.
[0136] 4.3 The administrator selects the domain name backup and recovery management unit on the authoritative domain name service control homepage, and the authoritative domain name service control homepage switches to the domain name backup and recovery management operation page. The instruction dispatching unit receives the data backup and recovery operation type from the administrator, and the domain name area management unit receives the operation command and operation data from the instruction dispatching unit. If the operation command is data backup, go to 4.3.1; if the operation command is data recovery, go to 4.3.2.
[0137] 4.3.1 The administrator clicks the data backup button on the domain name backup and recovery management operation page, enters the file name k generated by archiving in the pop-up input box. The domain name backup and recovery management unit receives a data backup operation command from the instruction dispatching unit, and the operation data is the file name k of the file generated by packing and archiving the authoritative domain name service software configuration file and the zone file. The domain name backup and recovery management unit sends the data backup operation command and the operation data k to the domain name backup and recovery processing unit. The domain name backup and recovery processing unit packs and archives the authoritative domain name service software configuration file and the zone file, and names it the file name k specified by the operation data. After the packing and archiving is completed, it returns the archived file list data to the domain name backup and recovery management unit. The domain name backup and recovery processing unit records the data backup operation command, the operation data (the file name of the file generated by packing and archiving the authoritative domain name service software configuration file and the zone file), the timestamp, the client IP address, and the user information into the file system key operation log file. The domain name backup and recovery processing unit reads the archived file list and sends the archived file list data to the domain name backup and recovery management unit. The domain name backup and recovery management unit displays all existing archived file data in the archived file list data. The domain name backup and recovery management unit receives the domain name list data, as Figure 17 shown, the archived file list on the domain name backup and recovery management operation page displays the archived file list data, go to step 4.
[0138] 4.3.2 The administrator clicks the recovery button on the archived file name f line in the archived file list on the domain name backup and recovery management operation page. The domain name backup and recovery management unit receives a data recovery operation command from the instruction dispatching unit, and the operation data is the file name f of the archived file to be recovered. The domain name backup and recovery management unit sends the data recovery operation command and the operation data to the domain name backup and recovery processing unit. The domain name backup and recovery processing unit uses the archived file corresponding to the recovered archived file name to overwrite the configuration file and the zone file used by the authoritative domain name service software. After the overwrite is completed, it sends the "Execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software performs a reload operation to load the configuration file and the zone file of the authoritative domain name service software. The authoritative domain name service of the authoritative domain name service software records the logs during the reload operation into the system operation log file of the authoritative domain name service software; then the domain name backup and recovery processing unit records the data recovery operation command, the operation data (the file name of the recovered archived file), the timestamp, the client IP address, and the user information into the file system key operation log file. The domain name backup and recovery processing unit reads the archived file list and sends the archived file list data to the domain name backup and recovery management unit. The domain name backup and recovery management unit receives the domain name list data, as Figure 18 shown, the archived file list on the domain name backup and recovery management operation page displays the archived file list data, go to step 4.
[0139] 4.4 The administrator selects the log management unit on the authoritative domain name service control homepage, and the authoritative domain name service control homepage switches to the log management operation page. The instruction dispatching unit receives the log management operation type from the administrator. The log management unit receives the operation command and operation data (with a null value) from the instruction dispatching unit. If the operation command is the critical operation log command, go to 4.4.1; if the operation command is the system operation log command, go to 4.4.2.
[0140] 4.4.1 The administrator clicks the critical operation log button on the log management operation page. The log management unit receives the critical operation log operation command and operation data (an empty string) from the instruction dispatching unit. The log management unit sends the critical operation log operation command and operation data to the log processing unit. After receiving the critical operation log operation command, the log processing unit obtains the data in the critical operation log file of the file system and sends the data in the critical operation log file to the log management unit. After receiving the critical operation log data, the log management unit, as Figure 19 shown, displays the critical operation log data in the log data area of the log management operation page and goes to the fourth step.
[0141] 4.4.2 The administrator clicks the system operation log button on the log management operation page. The log management unit receives the critical operation log operation command and operation data (an empty string) from the instruction dispatching unit and also receives the system operation log operation command and operation data from the instruction dispatching unit. The log management unit sends the system operation log operation command and operation data to the log processing unit. After receiving the system operation log operation command, the log processing unit obtains the system operation log file data of the authoritative domain name service software and sends the data in the system operation log file to the log management unit. After receiving the system operation log file data, the log management unit displays the system operation log file data in the log management operation log data area. The data mainly includes the startup, shutdown, and reloading record information of the area file and configuration file of the authoritative domain name service software, and then goes to the fourth step.
Claims
1. A web-based authoritative domain name service management and control method, characterized in that The following steps are involved: The first step is to build a web-based authoritative domain name service management system. The web-based authoritative domain name service management system consists of a domain name service front-end management view subsystem, a domain name service back-end model control subsystem, and a file system, and is connected to the authoritative domain name service software. The domain name service front-end management view subsystem is connected to the domain name service back-end model control subsystem, provides a web interface to the administrator, receives the login credentials, operation type, operation command and operation data provided by the administrator, and sends the login credentials, operation type, operation command and operation data to the domain name service back-end model control subsystem; the operation type is divided into regional management operation type, domain name data management operation type, data backup and recovery operation type, log management operation type, and the operation command and operation data are divided according to different operation types; The domain name service front-end management view subsystem consists of an administrator login unit, a command dispatch unit, a domain name area management unit, a domain name data management unit, a data backup and recovery management unit, and a log management unit; The domain name service backend model control subsystem is connected to the domain name service frontend management view subsystem, the file system, and the authoritative domain name service software, and is composed of an administrator authentication unit, a domain name area processing unit, a domain name data processing unit, a data backup and recovery processing unit, and a log processing unit. It receives operation commands and operation data from the domain name service frontend management view subsystem, changes the area files and configuration files of the authoritative domain name service software according to the operation commands and operation data, and changes the archive files and key operation log files of the file system. If the area files and configuration files of the authoritative domain name service software are changed, the domain name service backend model control subsystem also sends a reload command to the authoritative domain name service software, and the authoritative domain name service of the authoritative domain name service software executes the reload command to reload the area files and configuration files, and records the operation logs during the reloading process into the system operation log files of the authoritative domain name service software; The file system is connected to the domain name service backend model control subsystem. The file system contains authentication data files, key operation log files, and archive files. Each line of the authentication data file contains a user name and the password corresponding to the user name. Each line of the key operation log file contains the operation command, the time when the operation command is executed, the client IP, the user name, and the operation data. The archive file is a compressed package, and each compressed package contains the regional file and configuration file of the authoritative domain name service software. The authoritative domain name service software is connected to the domain name service backend model control subsystem. The authoritative domain name service software is the authoritative domain name service software BIND or NSD. Both BIND and NSD have an authoritative domain name service module and include zone files, configuration files, and system operation log files. The administrator login unit is connected to the administrator authentication unit, receives the login credentials of the web-based authoritative domain name service management system from the administrator, and sends the login credentials to the administrator authentication unit; the administrator authentication unit determines whether the login credentials are valid, and if the login credentials are valid, the administrator authentication unit returns the authoritative domain name service management and control homepage to the administrator login unit. After receiving the authoritative domain name service management and control homepage, the administrator login unit sends an authentication pass signal to the instruction dispatching unit, allowing the instruction dispatching unit to receive the operation type, operation command and operation data sent by the administrator; If the login credentials are invalid, the administrator authentication unit returns an authentication failure status code to the administrator login unit. After receiving the authentication failure status code, the administrator login unit sends an authentication failure signal to the instruction dispatch unit, and does not allow the instruction dispatch unit to receive the operation type, operation command and operation data sent by the administrator; The instruction dispatching unit is connected to the administrator login unit, the domain name area management unit, the domain name data management unit, the domain name backup and recovery management unit, and the log management unit. If the authentication pass signal is received from the administrator login unit, the instruction dispatching unit receives the operation type, operation command and operation data sent by the administrator; if the operation type is the area management operation type, the instruction dispatching unit sends the domain name area addition, deletion, configuration, query operation command and operation data to the domain name area management unit of the domain name service front-end management view subsystem; if the operation type is the domain name data management operation type, the instruction dispatching unit sends the domain name data addition, deletion, modification, query operation command and operation data to the domain name data management unit; if the operation type is the data backup and recovery operation type, the instruction dispatching unit sends the data backup and data recovery operation command to the domain name backup and recovery management unit; If the operation type is a log management operation type, the instruction dispatching unit sends the key operation log and system operation log operation commands to the log management unit. The domain name zone management unit is connected to the instruction dispatching unit and the domain name zone processing unit. The domain name zone management unit receives domain name zone addition, deletion, configuration, and query operation commands and operation data from the instruction dispatching unit, sends the operation commands and operation data to the domain name zone processing unit, receives zone list data from the domain name zone processing unit, and displays the zone list data. The domain name data management unit is connected to the instruction dispatching unit and the domain name data processing unit. The domain name data management unit receives domain name data addition, deletion, modification, and query operation commands and operation data from the instruction dispatching unit, sends the operation commands and operation data to the domain name data processing unit, receives domain name data list data from the domain name data processing unit, and displays the domain name data list data; The domain name backup and recovery management unit is connected to the instruction dispatching unit and the domain name backup and recovery processing unit. The domain name backup and recovery management unit receives data backup and data recovery operation commands and operation data from the instruction dispatching unit, sends the operation commands and operation data to the data backup and recovery processing unit, receives archive file list data from the data backup and recovery processing unit, and displays the archive file list data. The log management unit is connected to the instruction dispatching unit and the log processing unit. The log management unit receives key operation logs and system operation log operation commands and operation data from the instruction dispatching unit, sends the operation commands and operation data to the log processing unit, receives key operation logs or system operation log data from the log processing unit, and displays the key operation logs or system operation logs. The administrator authentication unit is connected to the administrator login unit and the file system; the administrator authentication unit receives the login credentials from the administrator login unit, obtains the login credentials from the authentication data file of the file system, and authenticates the login credentials obtained from the authentication data file and the login credentials sent by the administrator login unit according to the web user authentication mechanism. If the authentication is successful, the administrator authentication unit sends the authoritative domain name service control homepage to the administrator login unit; If the authentication fails, the administrator authentication unit sends an authentication failure status code to the administrator login unit, and the administrator authentication unit records the timestamp, client IP address, user information, and authentication result key operation information into the key operation log file of the file system; The domain name zone processing unit is connected to the domain name zone management unit, the file system, and the authoritative domain name service software. The domain name zone processing unit receives domain name zone addition, deletion, configuration, query operation commands and operation data from the domain name zone management unit. If the domain name zone processing unit receives a domain name zone adding operation command, the operation data is added to the configuration file of the authoritative domain name service software, and the domain name zone adding operation command, operation data, timestamp, client IP address, and user information are recorded in the key operation log file of the file system, and an "execute reload command" message is sent to the authoritative domain name service software to notify the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and read the zone list data after the adding operation data from the configuration file of the authoritative domain name service software; If the domain name zone processing unit receives a domain name zone deletion operation command, the operation data is deleted in the configuration file of the authoritative domain name service software, the domain name zone deletion operation command, the operation data, the timestamp, the client IP address, and the user information are recorded in the key operation log file of the file system, and an "execute reload command" message is sent to the authoritative domain name service software to notify the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and the zone file of the authoritative domain name service software, and read the zone list data after the deletion operation data from the configuration file of the authoritative domain name service software; If the domain name zone processing unit receives a domain name zone configuration operation command, the domain name cache time is configured as the operation data value in the zone file of the authoritative domain name service software, the domain name zone configuration operation command, the operation data, the timestamp, the client IP address, and the user information are recorded in the key operation log file of the file system, and an "execute reload command" message is sent to the authoritative domain name service software to notify the authoritative domain name service module of the authoritative domain name service software to reload the authoritative domain name service software configuration file and the zone file, and a configuration success status code is received from the authoritative service software; If the domain name zone processing unit receives the domain name zone query operation command, it reads the zone list data corresponding to the query operation data from the authoritative domain name service software configuration file, and sends the zone list data to the domain name zone management unit; The domain name data processing unit is connected to the domain name data management unit, the file system, and the authoritative domain name service software. The domain name data processing unit receives domain name data addition, deletion, modification, query operation commands and operation data from the domain name data management unit. If the domain name data processing unit receives the domain name data adding operation command, the operation data is added to the zone file of the authoritative domain name service software, the domain name data adding operation command, the operation data, the timestamp, the client IP address, and the user information are recorded in the key operation log file of the file system, and an "execute reload command" message is sent to notify the authoritative domain name service software, notifying the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reading the domain name list data after the adding operation data from the zone file of the authoritative domain name service software, and sending the domain name list data to the domain name data management unit; If the domain name data processing unit receives a domain name deletion operation command, it deletes the operation data in the zone file of the authoritative domain name service software, records the domain name data deletion operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends an "execute reload command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, reads the domain name list data after the deletion operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; If the domain name data processing unit receives a domain name modification operation command, it modifies the operation data in the zone file of the authoritative domain name service software, records the domain name data modification operation command, operation data, timestamp, client IP address, and user information in the key operation log file of the file system, sends an "execute reload command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the authoritative domain name service software configuration file and zone file, reads the domain name list data after the modification operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; If the domain name data processing unit receives the domain name query operation command, it queries the operation data in the zone file of the authoritative domain name service software, reads the domain name list data corresponding to the query operation data from the zone file of the authoritative domain name service software, and sends the domain name list data to the domain name data management unit; The domain name backup and recovery processing unit is connected to the domain name backup and recovery management unit, the file system, and the authoritative domain name service software. The domain name backup and recovery processing unit receives data backup, data recovery operation commands and operation data from the domain name backup and recovery management unit. If the domain name backup and recovery processing unit receives the data backup operation command, it generates an archive file named after the operation data in the file system, and sends the file system archive file list data to the domain name backup and recovery management unit; If the domain name backup and recovery processing unit receives the data recovery operation command, it recovers the archived file named with the operation data in the file system, sends an "execute reload command" message to the authoritative domain name service software, notifies the authoritative domain name service module of the authoritative domain name service software to reload the configuration file and zone file of the authoritative domain name service software, and obtains the archived file list data of the file system to the domain name backup and recovery management unit; The log processing unit is connected to the log management unit, the authoritative domain name service software, and the file system. The log processing unit receives key operation logs, system operation log operation commands, and operation data from the log management unit. If the log processing unit receives the key operation log operation command and operation data, the log processing unit returns the key operation log data in the key operation log file in the file system to the log management unit; If the log processing unit receives the system operation log operation command and operation data, the log processing unit sends the system operation log data in the system operation log file of the authoritative domain name service software to the log management unit; The authoritative domain name service software is connected to the domain name zone processing unit, the domain name data processing unit, and the domain name backup and recovery unit. If an "execute reload command" message is received from the domain name zone processing unit, the domain name data processing unit, and the domain name backup and recovery processing unit, the authoritative domain name service module of the authoritative domain name service software reloads the configuration file and zone file of the authoritative domain name service software, and records the log of the reloading operation process into the system operation log file of the authoritative domain name service software; In the second step, the administrator login unit and the administrator authentication unit cooperate with each other to complete the administrator authentication login. The administrator authentication login adopts the web user authentication mechanism, and the method is: 2.1 Start the authoritative domain name service software, start the web-based authoritative domain name service management system, open the browser, enter the access address of the domain name service front-end management view subsystem, and the domain name service front-end management view subsystem starts working; 2.2 The administrator login unit receives the login credentials submitted by the administrator, and sends the administrator login credentials to the administrator authentication unit. The administrator authentication unit receives the login credentials from the administrator login unit, obtains the login credentials from the authentication data file of the file system, and authenticates the login credentials obtained from the authentication data file and the login credentials received from the administrator login unit according to the web user authentication mechanism; if the two login credentials are the same, the authentication is passed, and the authoritative domain name service control homepage is sent to the administrator login unit, and then go to 2.3; If the authentication fails, the authentication failure status code is sent to the administrator login unit, and go to 2.2; 2.3 The administrator login unit receives the authoritative domain name service control homepage and sends the "authentication passed" signal to the instruction dispatch unit; at the same time, the administrator authentication unit records the timestamp, client IP address, user information, and authentication result key operation information into the key operation log file of the file system, and then goes to the third step; In the third step, the instruction dispatching unit determines whether an "authentication passed" signal is received from the administrator login unit. If an "authentication passed" signal is received, the instruction dispatching unit receives the operation type, operation command and operation data from the administrator and proceeds to the fourth step. If the "Authentication Passed" signal is not received, go to step 3 and continue waiting; In the fourth step, the instruction dispatching unit sends the operation type, operation command and operation data to the domain name zone management unit, the domain name data management unit, the domain name backup and recovery management unit and the log management unit respectively according to the operation type received from the administrator. The domain name zone management unit, the domain name data management unit, the domain name backup and recovery management unit and the log management unit respectively perform authoritative domain name service management operation processing according to the received operation type, operation command and operation data. The method is: If the operation type received by the instruction dispatching unit from the administrator is a zone management operation type, the operation command and operation data are sent to the domain name zone management unit, and the process goes to 4.1; if the operation type received by the instruction dispatching unit from the administrator is a domain name data management operation type, the operation command and operation data are sent to the domain name data management unit, and the process goes to 4.2; if the operation type received by the instruction dispatching unit from the administrator is a data backup and recovery operation type, the operation command and operation data are sent to the domain name backup and recovery management unit, and the process goes to 4.3; if the operation type received by the instruction dispatching unit from the administrator is a log management operation type, the operation command and operation data are sent to the log management unit, and the process goes to 4.4: 4.1 At this time, the instruction dispatching unit receives the zone management operation type from the administrator. If the operation command is to add a domain name zone, go to 4.1.1; if the operation command is to delete a domain name zone, go to 4.1.2; if the operation command is a configuration command, go to 4.1.3; if the operation command is to query a domain name zone, go to 4.1.4; 4.1.1 The domain name zone management unit receives a domain name zone addition operation command from the instruction dispatching unit. The operation data is the zone name to be added. The unit verifies whether the zone name characters and label length meet the standard domain name specifications. If they meet, the unit goes to 4.1.1.
1. If not, the unit goes to 4.1.1.
2. 4.1.1.1 At this time, the characters and label length of the added zone name meet the standard zone name specification, and the domain name zone management unit sends the domain name zone addition operation command and operation data, i.e. the added zone name, to the domain name zone processing unit; The domain name zone processing unit receives the zone adding operation command and operation data from the domain name zone management unit, adds the operation data and the file path mapping content named with the zone name in the configuration file of the authoritative domain name service software, sends the "execute reload command" message to the authoritative domain name service software, and the authoritative domain name service module of the authoritative domain name service software executes the reload operation. The authoritative domain name service module of the authoritative domain name service software records the log of the reload operation process into the system operation log file of the authoritative domain name service software. The domain name zone processing unit records the domain name zone adding operation command, operation data, timestamp, client IP address, and user information into the key operation log file of the file system, and reads the zone list data after adding the zone name from the configuration file of the authoritative domain name service software, and sends the zone list data to the domain name zone management unit. The domain name zone management unit receives the zone list data, and displays the zone list data in the zone list of the domain name zone management operation page, and then goes to the fourth step; 4.1.1.2 At this time, the characters and label length of the added zone name do not meet the standard zone name specifications. The administrator is prompted to modify the zone name on the domain name zone operation page and go to 4.1.1; 4.1.2 The domain name zone management unit receives a domain name zone deletion operation command from the instruction dispatching unit, and the operation data is the name of the zone to be deleted. The domain name zone management unit sends the domain name zone deletion operation command and the operation data, i.e., the name of the zone to be deleted, to the domain name zone processing unit; The domain name zone processing unit receives the zone deletion operation command from the domain name zone management unit, deletes the operation data and the file path mapping content named with the zone name in the configuration file of the authoritative domain name service software, and sends an "execute reload command" message to the authoritative domain name service software; the authoritative domain name service module of the authoritative domain name service software executes the reload operation, and records the log of the reload operation process into the system operation log file of the authoritative domain name service software; Then the domain name zone processing unit records the domain name zone deletion operation command, operation data, timestamp, client IP address, and user information into the key operation log file of the file system, and reads the zone list data after deleting the zone name from the configuration file of the authoritative domain name service software, and sends the zone list data to the domain name zone management unit. The domain name zone management unit receives the zone list data, and displays the zone list data in the zone list of the domain name zone management operation page, and then goes to step 4; 4.1.3 The domain name zone management unit receives the configuration zone operation command from the instruction dispatching unit. The operation data is the zone name and configuration data. The domain name zone management unit verifies the legitimacy of the configuration data. For the domain name cache time TTL in the configuration data, it verifies whether TTL is a non-negative number and is within a reasonable range. If TTL is a non-negative number and is within a reasonable range, go to 4.1.3.
1. If TTL is negative or is not within a reasonable range, go to 4.1.3.
2. 4.1.3.1 The domain name zone management unit sends the zone configuration operation command and operation data, i.e., the zone name and configuration data, to the domain name zone processing unit; The domain name zone processing unit receives the zone configuration operation command and operation data from the domain name zone management unit, modifies the domain name cache time field in the zone file corresponding to the zone name of the authoritative domain name service software, and sends an "execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software executes the reload operation and records the log of the reload operation process into the system operation log file of the authoritative domain name service software; Then the domain name zone processing unit records the configuration zone operation command, operation data, timestamp, client IP address, and user information into the key operation log file of the file system. The domain name zone processing unit returns the configured status code to the domain name zone management unit. The domain name zone management unit receives the configured status code sent by the domain name zone processing unit, and prompts the administrator on the domain name zone management operation page that the configuration has been successful, and then goes to step 4. 4.1.3.2 On the domain name zone operation page, the administrator is prompted to re-modify the domain name cache time TTL, and go to 4.1.3; 4.1.4 The domain name zone management unit receives the query zone operation command from the instruction dispatching unit, and sends the query zone operation command and operation data to the domain name zone processing unit. The domain name zone processing unit queries and obtains the corresponding zone name list data from the configuration file. If the zone name exists in the configuration file, go to 4.1.4.1; if the zone name does not exist in the configuration file, go to 4.1.4.2; 4.1.4.1 The domain name zone processing unit queries and obtains the corresponding zone list data from the configuration file and returns it to the domain name zone management unit. The domain name zone management unit receives the zone list data and displays the zone list data in the zone list on the domain name zone management operation page, and then goes to step 4; 4.1.4.2 The domain name zone processing unit returns empty data to the domain name zone management unit. The domain name zone management unit prompts the administrator that the zone name queried does not exist, and then go to 4.1.4; 4.2 At this time, the instruction dispatching unit receives the domain name data management operation type from the administrator, and sends the operation command and operation data to the domain name data management unit. If the operation command is to add domain name data, go to 4.2.1; if the operation command is to delete domain name data, go to 4.2.2; if the operation command is to modify domain name data, go to 4.2.3; if the operation command is to query domain name data, go to 4.2.4; 4.2.1 The domain name data management unit receives the domain name data addition operation command and operation data from the instruction dispatch unit. The operation data is the domain name to be added and the input IP address. The domain name data management unit first verifies the legitimacy of the domain name added in the operation data, and verifies whether the domain name characters and label length meet the standard domain name specifications; then verifies whether the IP address input in the operation data meets the unicast IP address specification requirements. If the IP address meets the requirements, go to 4.2.1.
1. If the IP address does not meet the requirements, go to 4.2.1.
2. 4.2.1.1 The domain name data management unit sends the domain name data addition operation command and operation data, i.e., the zone name to which the domain name belongs, the added domain name and the input IP address, to the domain name data processing unit. The domain name data processing unit adds data, i.e., the added domain name and the input IP address, to the zone file corresponding to the zone name of the authoritative domain name service software, and sends the "execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software executes the reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the log of the reload operation process into the system operation log file of the authoritative domain name service software; Then the domain name data processing unit records the domain name data adding operation command, the domain name added in the operation data and the input IP address, timestamp, client IP address, and user information into the key operation log file of the file system, and reads the domain name list data after the domain name is added from the zone file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data, displays the domain name list data in the domain name list on the domain name data management operation page, and then goes to step 4; 4.2.1.2 The administrator will be prompted to modify the IP address again on the domain name data management operation page, go to 4.2.1; 4.2.2 The domain name data management unit receives the domain name data deletion operation command and operation data from the instruction dispatching unit, the operation data being the zone name to which the domain name belongs and the domain name to be deleted, and the domain name data management unit sends the domain name data deletion operation command and operation data, namely the zone name to which the domain name belongs and the domain name to be deleted, to the domain name data processing unit; The domain name data processing unit deletes the domain name data in the zone file corresponding to the zone name, and sends an "execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software executes the reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the log of the reload operation process into the system operation log file of the authoritative domain name service software; Then the domain name data processing unit records the domain name data deletion operation command, the domain name to be deleted in the operation data, the timestamp, the client IP address, and the user information into the key operation log file of the file system, and reads the domain name list data after the domain name is deleted from the zone file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data, displays the domain name list data in the domain name list on the domain name data management operation page, and then goes to step 4; 4.2.3 The domain name data management unit receives the domain name data modification operation command and operation data from the instruction dispatching unit. The operation data is the domain name and IP address. The domain name data management unit verifies whether the IP address in the operation data complies with the unicast IP address specification requirements. If the IP address complies, go to 4.2.3.1; if the IP address does not comply, go to 4.2.3.
2. 4.2.3.1 The domain name data management unit sends the domain name data modification operation command and operation data, i.e., the zone name to which the domain name belongs, the modified domain name and the IP address, to the domain name data processing unit; The domain name data processing unit modifies the IP address in the zone file corresponding to the zone name of the authoritative domain name service software, and sends an "execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software executes the reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the log of the reload operation process into the system operation log file of the authoritative domain name service software; Then the domain name data processing unit records the domain name data modification operation command, the modified domain name and IP address in the operation data, the timestamp, the client IP address, and the user information into the key operation log file of the file system, and reads the domain name list data after the modified domain name from the zone file of the authoritative domain name service software and sends it to the domain name data management unit. The domain name data management unit receives the domain name list data, displays the domain name list data in the domain name list on the domain name data management operation page, and then goes to step 4; 4.2.3.2 The administrator is prompted to modify the IP address again on the domain name data management operation page, and go to 4.2.3; 4.2.4 The domain name data management unit receives the domain name data query operation command and operation data from the instruction dispatch unit, the operation data being the queried domain name, and sends the domain name data query operation command and operation data, i.e., the queried domain name, to the domain name data processing unit. If the queried domain name exists in the domain name zone file corresponding to the queried domain name of the authoritative domain name service software, the queried domain name and IP address are sent to the domain name data management unit, and the process goes to 4.2.4.
1. If the queried domain name does not exist in the domain name zone file corresponding to the queried domain name of the authoritative domain name service software, an empty string is returned to the domain name data management unit, and the process goes to 4.2.4.
2. 4.2.4.1 The domain name data management unit receives the domain name list data, and displays the domain name list data in the domain name list on the domain name data management operation page, and then goes to step 4; 4.2.4.2 The domain name data management unit receives an empty string, and the administrator is prompted on the page that the domain name being queried does not exist. Go to 4.2.4; 4.3 At this time, the instruction dispatching unit receives the data backup and recovery operation type from the administrator. If the operation command is data backup, go to 4.3.1; if the operation command is data recovery, go to 4.3.2; 4.3.1 The domain name backup and recovery management unit receives the data backup operation command and operation data from the instruction dispatching unit. The operation data is the name of the file generated by packaging and archiving the authoritative domain name service software configuration file and the zone file; The domain name backup and recovery management unit sends the data backup operation command and the operation data to the domain name backup and recovery processing unit. The domain name backup and recovery processing unit packages and archives the authoritative domain name service software configuration file and the zone file, and names them as the file name specified by the operation data. After the packaging and archiving is completed, the archive file list data is sent to the domain name backup and recovery management unit. The domain name backup and recovery processing unit records the name, timestamp, client IP address, and user information of the file generated by the data backup operation command and the operation data, i.e., the authoritative domain name service software configuration file and the zone file, in the key operation log file of the file system. The domain name backup and recovery management unit receives the archive file list data, and displays the archive file list data in the archive file list on the domain name backup and recovery management operation page, and then goes to step 4. 4.3.2 The domain name backup and recovery management unit receives the data recovery operation command and operation data from the instruction dispatching unit, where the operation data is the name of the restored archive file; The domain name backup and recovery management unit sends the data recovery operation command and operation data to the domain name backup and recovery processing unit. The domain name backup and recovery processing unit uses the archive file corresponding to the restored archive file name to overwrite the configuration file and zone file used by the authoritative domain name service software. After the overwriting is completed, the domain name backup and recovery processing unit sends an "execute reload command" message to the authoritative domain name service software. The authoritative domain name service module of the authoritative domain name service software executes the reload operation, loads the configuration file and zone file of the authoritative domain name service software, and records the log of the reload operation process into the system operation log file of the authoritative domain name service software; Then the domain name backup and recovery processing unit records the data recovery operation command, the operation data, i.e., the name of the restored archive file, the timestamp, the client IP address, and the user information into the key operation log file of the file system. The domain name backup and recovery processing unit reads the archive file list and sends the archive file list data to the domain name backup and recovery management unit. The domain name backup and recovery management unit receives the domain name list data and displays the archive file list data in the archive file list on the domain name backup and recovery management operation page, and then goes to step 4. 4.4 The command dispatching unit receives the log management operation type from the administrator. If the operation command is a key operation log command, go to 4.4.1; if the operation command is a system operation log command, go to 4.4.2; 4.4.1 The log management unit receives the key operation log operation command and the operation data with a value of null from the instruction dispatch unit; the log management unit sends the key operation log operation command and the operation data to the log processing unit. After receiving the key operation log operation command, the log processing unit obtains the data in the key operation log file of the file system and sends the data in the key operation log file to the log management unit. The log management unit receives the key operation log data and displays the key operation log data in the log data area of the log management operation page, and then goes to step 4. 4.4.2 The log management unit receives the system operation log operation command and operation data from the instruction dispatching unit; the log management unit sends the system operation log operation command and operation data to the log processing unit. After receiving the system operation log operation command, the log processing unit obtains the system operation log file data of the authoritative domain name service software, and sends the data in the system operation log file to the log management unit. The log management unit receives the data in the system operation log file, displays the data in the log management unit, and then goes to the fourth step.
2. A web-based authoritative domain name service management and control method as claimed in claim 1, characterized in that The domain name service front-end management view subsystem, domain name service back-end model control subsystem, file system, and authoritative domain name service software run on the same server.
3. A web-based authoritative domain name service management and control method as claimed in claim 1, characterized in that The web user authentication mechanism described in the second step refers to any one of a username, password, or digital certificate mechanism.
4. A web-based authoritative domain name service management and control method as claimed in claim 1, characterized in that The reasonable range mentioned in step 4.1.3 means that TTL is no greater than 30*24*60*60 seconds.