A message processing method and device
By using a data encryption key to encrypt and authenticate DNS request and response messages between the DNS client and server, security risks in DNS message processing are resolved, and data transmission security and integrity are achieved.
Patent Information
- Application Number
- CN202510372128.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-03-26
AI Technical Summary
DNS message processing has security vulnerabilities, especially in local area network environments where it is susceptible to DNS spoofing and man-in-the-middle attacks.
By using data encryption keys to encrypt and authenticate DNS request and response messages between the DNS client and server, and by utilizing key indexes for key association storage and retrieval, the security of data transmission is ensured.
It improves the security of DNS message processing, prevents data tampering and attacks, and ensures data integrity and client authentication.
Smart Images

Figure CN120128410B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network communication, and particularly relates to a message processing method and device. BACKGROUND
[0002] DNS (Domain Name System) is a system for converting domain names (such as example.com) into machine-readable IP addresses (such as 192.0.2.1). It is one of the key infrastructures of the Internet, allowing users to access websites and other online resources through easily memorable names.
[0003] In a local area network environment, DNS may have security risks due to DNS spoofing or man-in-the-middle attacks.
[0004] How to improve the security of DNS message processing has become a technical problem to be solved. SUMMARY
[0005] The present disclosure provides a message processing method and device to solve the problem of low security of DNS message processing in the prior art.
[0006] According to a first aspect of an embodiment of the present disclosure, a message processing method is provided, applied to a DNS client, and the method comprises:
[0007] The request data of the DNS request message is encrypted and authenticated using the stored data encryption key, and the key index is carried in the processed DNS request message and sent to the DNS server, so that the DNS server queries the associated data encryption key according to the key index carried in the received DNS request message, and decrypts and authenticates the request data of the received DNS request message according to the queried data encryption key; the data encryption key is obtained by the DNS client from the DNS server and is stored in association with the key index;
[0008] The DNS response message sent by the DNS server is received, the associated data encryption key is queried according to the key index carried in the DNS response message, and the response data of the DNS response message is decrypted and authenticated according to the queried data encryption key; wherein the DNS response message is sent by the DNS server in the case that the request data of the received DNS request message is authenticated, the response data of the DNS response message is generated by the DNS server according to the request data, and the generated response data is encrypted and authenticated using the data encryption key.
[0009] According to a second aspect of the embodiments of the present disclosure, a message processing method is provided, applied to a DNS server, and the method comprises:
[0010] receiving a DNS request message sent by the DNS client, querying a data encryption key associated with the key index according to the key index carried in the DNS request message, and decrypting and authenticating the request data of the DNS request message according to the queried data encryption key; wherein the DNS request message is sent by the DNS client after the request data of the DNS request message is encrypted and authenticated by the data encryption key, and the processed DNS request message carries the key index;
[0011] In the case that the request data of the received DNS request message is authenticated, the response data is generated according to the decrypted request data, the generated response data is encrypted and authenticated by the data encryption key, and the processed response data is carried in the DNS response message and sent to the DNS client, so that the DNS client queries the data encryption key associated with the key index according to the key index carried in the DNS response message, and decrypts and authenticates the response data of the DNS response message according to the queried data encryption key.
[0012] According to a third aspect of the embodiments of the present disclosure, a message processing device is provided, deployed in a domain name system (DNS) device, and the device comprises:
[0013] a processing unit, configured to encrypt and authenticate the request data of the DNS request message by using the stored data encryption key; the data encryption key is obtained by the DNS client from the DNS server and is stored in association with the key index;
[0014] a communication unit, configured to send the key index in the processed DNS request message to the DNS server, so that the DNS server queries the data encryption key associated with the key index according to the key index carried in the received DNS request message, and decrypts and authenticates the request data of the received DNS request message according to the queried data encryption key;
[0015] The communication unit is also configured to receive a DNS response message sent by the DNS server; wherein the DNS response message is sent by the DNS server in the case that the request data of the received DNS request message is authenticated, the response data of the DNS response message is generated by the DNS server according to the request data, and the generated response data is encrypted and authenticated by the data encryption key to obtain;
[0016] The processing unit is further configured to query an associated data encryption key according to the key index carried in the DNS response message, and decrypt and authenticate the response data of the DNS response message according to the queried data encryption key.
[0017] According to a fourth aspect of the embodiments of the present disclosure, a message processing apparatus is provided, which is deployed on a domain name system (DNS) server, and the apparatus comprises:
[0018] The communication unit is configured to receive a DNS request message sent by a DNS client.
[0019] The processing unit is configured to query an associated data encryption key according to a key index carried in the DNS request message, and decrypt and authenticate the request data of the DNS request message according to the queried data encryption key, wherein the DNS request message is sent by the DNS client after encryption and authentication processing of the request data of the DNS request message by using the data encryption key, and the processed DNS request message carries the key index.
[0020] The processing unit is further configured to generate response data according to the decrypted request data, and perform encryption and authentication processing of the generated response data by using the data encryption key, in the case that the request data of the received DNS request message is authenticated.
[0021] The communication unit is further configured to carry the processed response data in a DNS response message and send the DNS response message to the DNS client, so that the DNS client queries an associated data encryption key according to a key index carried in the DNS response message, and decrypts and authenticates the response data of the DNS response message according to the queried data encryption key.
[0022] By means of the technical solution of the present disclosure, the DNS client stores the data encryption key and the key index in association by obtaining the data encryption key from the DNS server; the DNS server can also store the data encryption key and the key index sent by the DNS client in association after determining the data encryption key of the DNS client; the DNS client can encrypt and authenticate the request data of the DNS request message by using the obtained data encryption key, and send the key index in the processed DNS request message to the DNS server; the DNS server can query the associated data encryption key according to the key index in the DNS request message, decrypt and authenticate the request data in the DNS request message by using the data encryption key, and generate response data and encrypt and authenticate the response data by using the data encryption key in the case of passing the authentication, and send the key index and the processed response data in the DNS response message to the DNS client; the DNS client can query the associated data encryption key according to the key index carried in the DNS response message after receiving the DNS response message sent by the DNS server, and decrypt and authenticate the response data in the DNS response message according to the queried data encryption key, thereby improving the security of the DNS message processing. BRIEF DESCRIPTION OF DRAWINGS
[0023] Figure 1 is a message processing method flow diagram provided by the DNS client side of the present disclosure embodiment;
[0024] Figure 2 is a message processing method flow diagram provided by the DNS server side of the present disclosure embodiment;
[0025] Figure 3 is a message processing method flow diagram provided by the present disclosure embodiment;
[0026] Figure 4 is a structure diagram of a message processing device provided by the DNS client side of the present disclosure embodiment;
[0027] Figure 5 is a structure diagram of a message processing device provided by the DNS server side of the present disclosure embodiment. DETAILED DESCRIPTION
[0028] In order to make the person skilled in the art better understand the technical solutions in the present disclosure embodiment, the following first explains some terms related to the present disclosure embodiment.
[0029] 1. DNS spoofing (DNS Spoofing): malicious attackers can pretend to be a real DNS server and give incorrect IP addresses, thereby leading users to a fake or malicious website.
[0030] 2. Man-in-the-Middle (MITM): Attackers can intercept and modify DNS query responses, tampering with the target users access.
[0031] The basic working principle of DNS is briefly described below.
[0032] The basic working principle of DNS includes:
[0033] Domain name resolution: After the user inputs the domain name, the client (usually a browser) queries the corresponding IP address through the DNS resolver.
[0034] Recursive query: The resolver may contact multiple DNS servers, starting from the root DNS server, and asking level by level until the IP address of the domain name is obtained.
[0035] Caching: In order to reduce query time and server load, DNS resolution results are usually cached locally and on ISP DNS servers for a period of time.
[0036] In order to make the above-mentioned purposes, features and advantages of the embodiments of the present disclosure more obvious and easy to understand, the technical solutions in the embodiments of the present disclosure will be further described in detail below with reference to the drawings.
[0037] Please refer to Figure 1 , a flowchart of a packet processing method provided by the embodiments of the present disclosure, wherein the packet processing method can be applied to a DNS client. As Figure 1 shown, the packet processing method can include the following steps:
[0038] Step 101, encrypt and authenticate the request data of the DNS request packet using the stored data encryption key, and send the key index in the processed DNS request packet to the DNS server, so that the DNS server queries the associated data encryption key according to the key index carried in the received DNS request packet, and decrypts and authenticates the request data of the received DNS request packet according to the queried data encryption key; The data encryption key is obtained by the DNS client from the DNS server and is stored in association with the key index.
[0039] For example, the case where the DNS client sends the DNS request packet can include but is not limited to: the DNS client first accesses the specified domain name, the DNS client local cache of the resolved domain name and IP address is invalid, the IP address of the domain name changes, etc.
[0040] In the embodiments of the present disclosure, in order to avoid the request data from being attacked, the DNS client can encrypt and authenticate the request data of the DNS request message by using the obtained data encryption key.
[0041] The authentication processing of the DNS client on the request data of the DNS request message can include: generating a check code (which can be referred to as a first check code) by using the data encryption key according to the request data of the DNS request message, and the first check code can be used to check the integrity of the request data of the DNS request message.
[0042] The DNS client can encrypt the request data and the first check code by using the data encryption key.
[0043] For example, the related processing of the DNS server when receiving the DNS request message can refer to the related description of the method flow shown in Figure 2 The embodiments of the present disclosure do not repeat the related description of the method flow shown in
[0044] Step 102, receiving the DNS response message sent by the DNS server, querying the associated data encryption key according to the key index carried in the DNS response message, and decrypting and authenticating the response data of the DNS response message according to the queried data encryption key; wherein the DNS response message is sent by the DNS server under the condition that the request data of the received DNS request message is authenticated, the response data of the DNS response message is generated by the DNS server according to the request data, and the generated response data is encrypted and authenticated by using the data encryption key.
[0045] In the embodiments of the present disclosure, the related processing of the DNS server sending the DNS response message to the DNS client can refer to the related description of the method flow shown in Figure 2 The embodiments of the present disclosure do not repeat the related description of the method flow shown in
[0046] In the embodiments of the present disclosure, when the DNS client receives the DNS response message sent by the DNS server, the DNS client can obtain the key index carried in the DNS response message, query the associated data encryption key according to the obtained key index, and decrypt and authenticate the response data of the DNS response message according to the queried data encryption key.
[0047] For example, the DNS client can decrypt the response data of the DNS response message by using the data encryption key to obtain the decrypted response data, and the integrity check code (which can be referred to as a second check code) of the response data (which is generated by the DNS server and encrypted together with the response data).
[0048] The DNS client can generate a check code (which can be referred to as a third check code, used for checking the integrity of the response data) according to the decrypted response data, using the data encryption key, and compare the third check code with the integrity check code (i.e., the second check code) of the decrypted response data. If they are consistent, it indicates that the response data integrity check is passed, and the response data is not tampered with; otherwise, it is determined that the response data integrity check is not passed, and the response data is tampered with.
[0049] It should be noted that, in the process of interaction between the DNS client and the DNS server, for the same type of data (for example, request data or response data), the algorithm used by the DNS client side for check code generation of the data is consistent with the algorithm used by the DNS server side for check code generation of the data.
[0050] In addition, the message of the interaction between the DNS client and the DNS server can be sent through the UDP 53 port, reducing the delay of message sending, being compatible with the original DNS message processing, and reducing the modification of the client.
[0051] In some embodiments, the data encryption key is obtained by the following method:
[0052] The first message is sent to the DNS server, the first message is used to request to obtain the data encryption key, and the first message carries the key index, so that the DNS server stores the key index and the data encryption key in association after determining the data encryption key of the DNS client;
[0053] The response message of the first message sent by the DNS server is received, the data encryption key carried in the response message is obtained, and the data encryption key and the key index are stored in association.
[0054] In the embodiments of the present disclosure, in order to improve the security of the DNS message (including DNS request message, DNS response message, etc.) processing, the DNS client can first obtain the data encryption key from the DNS server before processing the DNS message, and the data encryption key is used to encrypt the related message content in the DNS message.
[0055] The DNS client can send a message (which can be referred to as a first message) to the DNS server to request to obtain the data encryption key; wherein the first message carries a key index.
[0056] For example, the key index can be generated by the DNS client and sent to the DNS server in the first message, used for associated maintenance of the data encryption key obtained by the DNS client.
[0057] For example, the key index can be generated by the DNS client in a random manner (e.g., a random number generated by the DNS client).
[0058] In a case where the DNS server receives the first message sent by the DNS client, the DNS server can perform data encryption key determination processing for the DNS client.
[0059] In a case where the data encryption key for the DNS client is determined, on one hand, the DNS server can store the key index and the data encryption key in association; on the other hand, the DNS server can send the determined data encryption key to the DNS client through a response message (a response message of the first message, which can be referred to as a first response message).
[0060] In the embodiments of the present disclosure, in a case where the DNS client receives the first response message sent by the DNS server, the DNS client can obtain the data encryption key carried in the first response message and store the data encryption key and the key index in association.
[0061] In one example, in order to ensure the security of the data encryption key obtaining processing, the key index in the first message and the data encryption key in the first response message can be encrypted by a key agreed between the DNS client and the DNS server.
[0062] For example, the DNS client can encrypt the key index in the first message by using the agreed key; in a case where the DNS server receives the first message, the DNS server can decrypt the encrypted key index by using the agreed key to obtain the decrypted key index.
[0063] For example, the DNS server can encrypt the data encryption key in the first message by using the agreed key; in a case where the DNS client receives the first response message, the DNS client can decrypt the encrypted data encryption key by using the agreed key to obtain the decrypted data encryption key.
[0064] In some embodiments, the above sending of the first message to the DNS server can include:
[0065] The identity authentication information is encrypted and authenticated by using the pre-shared key, and a registration request message carrying the processed identity authentication information, the registration ID, and the key index is sent to the DNS server, so that the DNS server queries the associated pre-shared key according to the registration ID carried in the received registration request message, and decrypts and authenticates the identity authentication information in the received registration request message according to the queried pre-shared key; wherein the DNS server stores an association relationship between the registration ID and the pre-shared key;
[0066] The DNS client receives the data encryption key acquisition response message sent by the DNS server, acquires the data encryption key carried in the data encryption key acquisition response message, and stores the data encryption key and the key index in association, which can include:
[0067] The DNS client receives the registration success response message sent by the DNS server; the registration success response message carries the data encryption key encrypted and authenticated by the pre-shared key, and the data encryption key is generated by the DNS server when the identity authentication information in the received registration request message is authenticated successfully;
[0068] The DNS client decrypts and authenticates the data encryption key in the registration success response message by using the pre-shared key, and stores the decrypted data encryption key and the key index in association when the authentication is successful.
[0069] For example, the DNS client can acquire the data encryption key from the DNS server during the registration process.
[0070] For example, the DNS client can register with the DNS server when it first accesses the local area network, and acquire the data encryption key from the DNS server during the registration process.
[0071] For example, the DNS client can acquire the pre-shared key (such as the key agreed between the DNS client and the DNS server as described above) and the registration ID by using an offline method before registering with the DNS server.
[0072] For example, the DNS client can acquire the pre-shared key and the registration ID by using an offline method (such as through a USB flash disk) during startup.
[0073] The registration ID is used to identify the identity of the DNS client during the registration process, and the DNS server can maintain the pre-shared key of the DNS client according to the registration ID.
[0074] For example, the DNS client can encrypt and authenticate the identity authentication information by using the pre-shared key.
[0075] In one example, the identity authentication information can include but is not limited to the registration ID, the key index, and other identity authentication information.
[0076] The other identity authentication information can include but is not limited to the IP address of the DNS client and / or the IP address of the DNS server.
[0077] The DNS client can encrypt and authenticate the identity authentication information by using the pre-shared key to obtain the processed identity authentication information.
[0078] For example, the DNS client can generate an identity authentication information integrity check code (which can be referred to as a fourth check code) according to the identity authentication information by using the pre-shared key, and can encrypt the identity authentication information and the fourth check code together by using the pre-shared key.
[0079] The DNS client can send a registration request message (that is, the first message can be a registration request message) carrying the processed identity authentication information, the registration ID, and the key index to the DNS server.
[0080] For example, the related processing of the DNS server when receiving the registration request message sent by the DNS client, and the related processing of the DNS server sending a registration success response message to the DNS client can be referred to the related description in the method flow shown in Figure 2 The embodiments of the present disclosure will not be described here.
[0081] When receiving the registration success response message (that is, the response message of the first message can be a registration success response message) sent by the DNS server, the DNS client can decrypt and authenticate the data encryption key in the registration success response message by using the pre-shared key, and store the decrypted data encryption key and the key index in association with each other when the authentication is successful.
[0082] For example, the DNS client can decrypt the data encryption key in the registration success response message by using the pre-shared key to obtain the decrypted data encryption key and an integrity check code of the data encryption key (which can be referred to as a fifth check code, generated by the DNS server and encrypted together with the data encryption key).
[0083] The DNS client can generate a check code (which can be referred to as a sixth check code, used to check the integrity of the data encryption key) according to the decrypted data encryption key by using the pre-shared key, and compare the fifth check code and the sixth check code. If they are consistent, it means that the data encryption key integrity check is passed, and the data encryption key is not tampered with; otherwise, it is determined that the data encryption key integrity check is not passed, and the data encryption key is tampered with.
[0084] The DNS client can store the decrypted data encryption key and the key index in association with each other when the authentication of the decrypted data encryption key is successful.
[0085] In some embodiments, the data encryption key carried in the response message of the first message can include:
[0086] Obtain the data encryption key and the key lifetime carried in the response message.
[0087] The sending of the first message to the DNS server can include:
[0088] The first message is sent to the DNS server in a case where the DNS client first connects to the local area network or the DNS client determines that the current data encryption key is expired.
[0089] To improve the security of the data encryption key and further improve the security of the DNS message processing, the DNS server can set a lifetime for the data encryption key generated for the DNS client.
[0090] For any data encryption key, in a case where the data encryption key is expired (the data encryption key exists for more than the lifetime), the data encryption key is invalid, and the DNS client needs to obtain the data encryption key from the DNS server again.
[0091] Correspondingly, the DNS client can send the first message to the DNS server in a case where the DNS client first connects to the local area network or the DNS client determines that the current data encryption key is expired, to obtain the data encryption key.
[0092] In a case where the DNS server determines that the data encryption key needs to be generated for the DNS client, for example, in a case where the DNS server authenticates the identity of the DNS client successfully, in the process of generating the data encryption key, the DNS server can also determine the key lifetime of the data encryption key, and carry the data encryption key and the key lifetime in the response message (such as a registration success response message) of the first message and send them to the DNS client.
[0093] In one example, in a case where the DNS client determines that the current data encryption key is expired, a new key index can be generated, and the newly generated key index can be carried in the data encryption key obtaining request message to obtain a new data encryption key corresponding to the newly generated key index from the DNS server.
[0094] Please refer to Figure 2 A flowchart of a message processing method provided by the embodiments of the present disclosure is shown, wherein the message processing method can be applied to the DNS server. As shown in Figure 2 The message processing method can include the following steps:
[0095] Step 201, receiving a DNS request message sent by a DNS client, querying a data encryption key associated with a key index carried in the DNS request message, and decrypting and authenticating request data of the DNS request message according to the queried data encryption key; wherein the DNS request message is sent by the DNS client after the request data of the DNS request message is encrypted and authenticated by the data encryption key, and the processed DNS request message carries the key index.
[0096] In the embodiment of the present disclosure, the specific implementation of the DNS client sending the DNS request message to the DNS server can be referred to the related description in the method flow shown in Figure 1 The specific implementation of the DNS client sending the DNS request message to the DNS server can be referred to the related description in the method flow shown in
[0097] When the DNS server receives the DNS request message, the DNS server can query the data encryption key associated with the key index carried in the DNS request message, and decrypt and authenticate the request data (encrypted by the data encryption key by the DNS client) of the DNS request message according to the queried data encryption key.
[0098] For example, the DNS server can decrypt the request data of the DNS request message by using the queried data encryption key to obtain the decrypted request data and the integrity check code (such as the first check code) of the request data.
[0099] The DNS server can generate a check code (which can be referred to as a seventh check code) according to the decrypted request data by using the queried data encryption key, and compare the seventh check code with the integrity check code (such as the first check code) of the decrypted request data. If they are consistent, it means that the request data integrity check is passed, and the request data is not tampered with; otherwise, it is determined that the request data integrity check is not passed, and the request data is tampered with.
[0100] Step 202, in the case that the request data of the received DNS request message is authenticated, generating response data according to the decrypted request data, encrypting and authenticating the generated response data by using the data encryption key, and sending the processed response data in a DNS response message to the DNS client, so that the DNS client queries the data encryption key associated with the key index carried in the DNS response message, and decrypts and authenticates the response data of the DNS response message according to the queried data encryption key.
[0101] In the embodiment of the present disclosure, in the case that the request data of the received DNS request message is authenticated by the DNS server, the DNS server can generate response data according to the decrypted request data.
[0102] For example, the decrypted request data can include a domain name to be queried, and the DNS server can determine an IP address corresponding to the domain name to be queried by querying external DNS or data in a local cache, and generate response data according to the queried IP address.
[0103] The DNS server can encrypt and authenticate the generated response data by using a data encryption key of the DNS client sending the DNS request, and send the processed response data to the DNS client sending the DNS request in a DNS response message.
[0104] The authentication processing of the response data by the DNS server can include: generating a check code (such as the second check code described above) by using the data encryption key according to the response data, which can be used to check the integrity of the response data of the DNS response message.
[0105] The specific processing flow of the DNS client when receiving the DNS response message can be referred to the related description in the method flow shown in Figure 1 The embodiments of the present disclosure will not be repeated here.
[0106] In some embodiments, the message processing method can further include:
[0107] Receiving a first message sent by the DNS client; the first message is used to request to obtain a data encryption key, and the first message carries a key index;
[0108] Obtaining the key index carried in the first message, and in the case of determining the data encryption key of the DNS client, associatively storing the key index and the data encryption key, and sending a response message carrying the data encryption key to the DNS client.
[0109] In the embodiments of the present disclosure, the specific implementation of the DNS client sending the first message to the DNS server can be referred to the related description in the method flow shown in Figure 1 The embodiments of the present disclosure will not be repeated here.
[0110] For example, when the DNS server receives the first message sent by the DNS client, it can determine whether to generate a data encryption key for the DNS client.
[0111] For example, the DNS server can authenticate the identity of the DNS client, and in the case of passing the authentication, determine to generate a data encryption key for the DNS client.
[0112] In a case where the DNS determines the data encryption key of the DNS client, the DNS can store the key index carried in the first message in association with the data encryption key, and send a response message carrying the data encryption key to the DNS client.
[0113] The related processing in a case where the DNS client receives the response message of the first message can be referred to the related description of the method flow shown in Figure 1 The related description of the method flow shown in
[0114] In some embodiments, receiving the first message sent by the DNS client can include:
[0115] receiving a registration request message sent by the DNS client; the registration request message carries the processed identity authentication information, the registration ID, and the key index, the processed identity authentication information is obtained by encrypting and authenticating the identity authentication information by the DNS client using the pre-shared key; the DNS server stores an association between the registration ID and the pre-shared key;
[0116] querying the associated pre-shared key according to the registration ID carried in the registration request message, and decrypting and authenticating the identity authentication information in the received registration request message according to the queried pre-shared key.
[0117] The above sending of the response message carrying the data encryption key to the DNS client can include:
[0118] sending a registration success response message carrying the data encryption key to the DNS client.
[0119] For example, the DNS client can obtain the data encryption key from the DNS server in the process of registering with the DNS server.
[0120] The specific implementation of the DNS client sending the registration request message to the DNS server can be referred to the related description of the method flow shown in Figure 1 The related description of the method flow shown in
[0121] In a case where the DNS server receives the registration request message, the DNS server can query the associated pre-shared key according to the registration ID carried in the registration request message, and decrypt and authenticate the identity authentication information in the received registration request message according to the queried pre-shared key.
[0122] The DNS server can decrypt the identity authentication information (identity authentication information encrypted and authenticated by the DNS client) carried in the registration request message by using the pre-shared key, to obtain decrypted identity authentication information and an integrity check code (such as the fourth check code) of the identity authentication information, which is used to check the integrity of the identity authentication information.
[0123] The DNS server can generate a check code (which can be referred to as an eighth check code, used to check the integrity of the identity authentication information) by using the pre-shared key according to the decrypted identity authentication information, and compare the fourth check code and the eighth check code. If the two check codes are consistent, it indicates that the identity authentication information integrity check is passed, and the identity authentication information is not tampered with. Otherwise, it is determined that the identity authentication information integrity check is not passed, and the identity authentication information is tampered with.
[0124] It should be noted that in the case where the DNS server obtains the decrypted identity authentication information in the manner described above, the DNS server can also compare the registration ID included in the decrypted identity authentication information with the registration ID carried in the registration request message. If the two are inconsistent, it can also be determined that the identity authentication information authentication is not passed.
[0125] In addition, in the case where the identity authentication information also includes the IP address of the DNS server, the DNS server can also compare the IP address of the DNS server included in the decrypted identity authentication information with the IP address of the DNS server itself in the case where the decrypted identity authentication information is obtained. If the two are inconsistent, it can also be determined that the identity authentication information authentication is not passed.
[0126] In the case where the identity authentication information also includes the IP address of the DNS client, the DNS server can also compare the IP address of the DNS client included in the decrypted identity authentication information with the IP address of the DNS client sending the registration request in the case where the decrypted identity authentication information is obtained. If the two are inconsistent, it can also be determined that the identity authentication information authentication is not passed.
[0127] It can be seen that, in the case where the identity authentication information also includes the IP address of the DNS client, Figure 1 and Figure 2In the method flow shown, the DNS client obtains a data encryption key from the DNS server and stores the data encryption key in association with a key index; the DNS server, after determining the data encryption key of the DNS client, can also store the data encryption key in association with the key index sent by the DNS client; the DNS client can encrypt and authenticate the request data of the DNS request message using the obtained data encryption key, and send the key index in the processed DNS request message to the DNS server; the DNS server can query the associated data encryption key according to the key index in the DNS request message, decrypt and authenticate the request data in the DNS request message using the data encryption key, and generate response data in the case of authentication passing, encrypt and authenticate the response data using the data encryption key, and send the key index and the processed response data in the DNS response message to the DNS client; in the case that the DNS client receives the DNS response message sent by the DNS server, the DNS client can query the associated data encryption key according to the key index carried in the DNS response message, and decrypt and authenticate the response data in the DNS response message according to the queried data encryption key, thereby improving the security of DNS message processing.
[0128] In order for those skilled in the art to better understand the technical solutions provided by the embodiments of the present disclosure, the technical solutions provided by the embodiments of the present disclosure will be described in detail below in combination with specific application scenarios.
[0129] In this embodiment, pre-shared key and symmetric algorithm key technology are used in combination for identity authentication, key agreement, etc., to reduce deployment complexity and reduce the pressure on the DNS server.
[0130] The message processing scheme provided by the embodiments of the present disclosure will be described in detail below.
[0131] I. Architecture design
[0132] 1.1, Encrypt DNS request and DNS response: prevent DNS hijacking, sniffing and man-in-the-middle attack.
[0133] 1.2, Identity verification and integrity protection: ensure the integrity of the request and verify the identity of the DNS client.
[0134] 1.3, Do not use certificates and asymmetric key pairs for client identity authentication, use lightweight identity authentication methods such as pre-shared keys.
[0135] 1.4, Use UDP port 53: support message transmission based on UDP 53, the DNS request message remains the same format as the traditional DNS, but both sending and receiving need to be encrypted and authenticated.
[0136] 1.5. with index (i.e. the key index mentioned above): the index of the plaintext field in the DNS encrypted packet header, used to identify the security parameters of the session.
[0137] II. Key components
[0138] 2.1. KDS (Key / DNS Server, i.e. the DNS server mentioned above):
[0139] 2.1.1. both as a DNS server and responsible for managing and distributing session keys;
[0140] 2.1.2. establish a secure association with the client through a lightweight key agreement mechanism, i.e. the association of client identity information and server locally stored key information;
[0141] 2.1.3. adopt a lightweight identity authentication scheme based on pre-shared key (PSK).
[0142] 2.2. DNS client:
[0143] 2.2.1. both a DNS request initiator and a member controlled by the key server.
[0144] 2.2.2. After successful registration of the client, the KDS issues a session key (i.e. the data encryption key mentioned above), which is used for subsequent encryption and authentication of DNS requests.
[0145] 2.2.3. The encrypted and authenticated DNS request is sent through the UDP 53 port, with an index identifier in the data packet.
[0146] III. Core process
[0147] As shown in Figure 3 , the core process of message processing in the embodiments of the present application can include:
[0148] 3.1. System initialization
[0149] 3.1.1. KDS (Key Server + DNS Server) startup:
[0150] 3.1.1.1. KDS listens to the UDP 53 port, and session key negotiation, DNS response, etc. are performed using this port; generate session keys (also known as DNS encryption keys (DEK), and the session keys are updated periodically.
[0151] 3.1.1.2. KDS distributes the identifier (registration ID) and pre-shared key (PSK) of each DNS client.
[0152] 3.2, Client registration.
[0153] 3.2.1, The DNS client (such as a PC (network camera), an IoT (Internet of Things) device, etc.) establishes a connection with the KDS at startup, obtains a registration ID and a pre-shared key through offline takeout, etc. In the case of first connecting to a local area network, it is registered with the configured KDS server.
[0154] For example, the client initiates a registration request, and the client locally generates an index. The request content contains device index / IP / device ID / KDS IP, etc. identity authentication information. The identity authentication information is encrypted and authenticated using the pre-shared key using the AES-256-GCM algorithm, and the processed identity authentication information is carried in the registration request message and sent to the KDS server through UDP destination port 53.
[0155] The registration request message can carry the plaintext of the registration ID.
[0156] 3.2.2, The KDS queries the pre-shared key according to the registration ID carried in the registration request message, and decrypts and authenticates the processed identity authentication information according to the queried pre-shared key.
[0157] For example, the registration request message can also carry the plaintext of the index, for example, after the UDP header. After the KDS decrypts the processed identity information using the pre-shared key, it can also compare the decrypted index with the plaintext index carried in the message, compare the decrypted registration ID with the plaintext registration ID carried in the message, compare the decrypted KDS IP with the IP of the KDS itself, and compare the decrypted client IP with the IP of the DNS client sending the registration request message. If any of them is inconsistent, it is determined that the authentication fails; if they are all consistent and the checksum authentication passes, it is determined that the client authentication passes.
[0158] In the case where the client authentication passes, the KDS locally generates a DEK and the corresponding survival time, and sends it to the client after encryption and authentication using the pre-shared key.
[0159] For example, the DEK and the corresponding index will be updated after a certain period of time (for example, every 1 hour or every 1 day), and the DEK will not be available after the expiration.
[0160] 3.3, Encryption and identity authentication process of DNS request.
[0161] 3.3.1, The DNS client initiates a request:
[0162] 3.3.1.1. The DNS client generates a DNS request (e.g. IP query for "www.example.com").
[0163] 3.3.1.2. The request data (including the domain name of the query, etc.) is AES-GCM encrypted and authenticated using the DEK.
[0164] 3.3.1.3. The index is inserted into the header of the DNS request packet.
[0165] 3.3.1.4. The encrypted and authenticated DNS request packet is sent to the KDS using UDP port 53.
[0166] 3.4. The KDS decrypts and verifies the DNS request packet.
[0167] 3.4.1. Upon receiving the DNS request packet, the KDS finds the corresponding DEK based on the index in the packet header.
[0168] 3.4.2. The request data is decrypted using the DEK, and the query data of the DNS request is extracted.
[0169] 3.4.3. The integrity of the data is verified to ensure that the data has not been tampered with.
[0170] 3.5. The KDS processes the DNS request.
[0171] 3.5.1. The KDS queries external DNS or cached data for the IP address of "www.example.com".
[0172] 3.5.2. The KDS generates response data (e.g. IP address 192.168.1.100).
[0173] 3.5.3. The KDS encrypts and authenticates the response data using the DEK, and encapsulates the processed response data into a DNS response packet with the index identifier, and sends it to the DNS client via UDP port 53.
[0174] 3.6. The DNS client decrypts and verifies the DNS response packet.
[0175] 3.6.1. Upon receiving the DNS response packet, the DNS client queries the corresponding DEK using the index.
[0176] 3.6.2. The response data in the DNS response packet is decrypted using the DEK, and the integrity of the response data is verified (e.g. HMAC verification).
[0177] 3.6.3. If the verification is successful, the client passes the IP address to the local application (e.g. web browser).
[0178] IV. Packet format
[0179] In this embodiment, the packet format of the DNS request packet and the DNS response packet can include:
[0180] UDP Header (UDP header): Destination port 53, length and checksum normal filling;
[0181] INDEX: A 32-bit identifier for identifying the ID of DEK.
[0182] Encrypted DNSData: Encrypted DNS query / response data, encrypted with AES-GCM, with data integrity check code.
[0183] V. Security mechanism
[0184] Confidentiality: Use AES-GCM to encrypt data.
[0185] Identity authentication: Use pre-shared key, pre-shared key is assigned uniquely according to the registration ID of each device.
[0186] Data integrity: Use AES-GCM for integrity check.
[0187] Man-in-the-middle attack: Because of the dynamic binding of DEK and index, the man-in-the-middle cannot tamper or replay data.
[0188] Data minimization: No certificate is used, reducing data transmission overhead.
[0189] VI. Security analysis
[0190] DNS hijacking: DNS request packet and DNS response packet are encrypted, and the attacker cannot hijack the request.
[0191] DNS tampering: AES-GCM encryption and HMAC check, tampered DNS response packet will be discarded.
[0192] Man-in-the-middle attack: protected by PSK, INDEX and DEK, the attacker cannot insert false DNS data.
[0193] VII. Key parameter configuration
[0194] DEK: Session key (AES-256), for example, 256-bit key.
[0195] INDEX: Security parameter index, i.e. key index, for example, 32-bit integer.
[0196] Encryption algorithm: data encryption, such as AES-GCM algorithm (AES-256).
[0197] HMAC algorithm: integrity check, such as AES-GCM (AES-256).
[0198] Eight, implementation scheme.
[0199] 8.1, lightweight PSK authentication: using registration ID and pre-shared key (PSK) to authenticate client and server identity.
[0200] 8.2, encryption and decryption: data encryption using AES-GCM algorithm, and integrity verification after decryption.
[0201] 8.3, dynamic DEK and INDEX binding: DEK (session key) is updated regularly, and INDEX is used for quick query of corresponding DEK.
[0202] See Figure 4 , a structural schematic diagram of a packet processing device provided by the embodiment of the disclosure, wherein the packet processing device can be deployed in a DNS client, such as Figure 4 , the packet processing device can include:
[0203] The processing unit 410 is configured to encrypt and authenticate the request data of the DNS request packet by using the stored data encryption key; the data encryption key is obtained by the DNS client from the DNS server and is stored in association with a key index;
[0204] The communication unit 420 is configured to send the key index in the processed DNS request packet to the DNS server, so that the DNS server queries the associated data encryption key according to the key index carried in the received DNS request packet, and decrypts and authenticates the request data of the received DNS request packet according to the queried data encryption key;
[0205] The communication unit 420 is also configured to receive the DNS response packet sent by the DNS server; wherein the DNS response packet is sent by the DNS server in the case that the request data of the received DNS request packet is authenticated, and the response data of the DNS response packet is generated by the DNS server according to the request data, and the generated response data is encrypted and authenticated by using the data encryption key to obtain;
[0206] The processing unit 410 is further configured to query a data encryption key associated with the key index according to the key index carried in the DNS response message, and decrypt and authenticate the response data of the DNS response message according to the queried data encryption key.
[0207] In some embodiments, the communication unit 420 acquires the data encryption key by:
[0208] sending a first message to the DNS server, the first message being used to request the data encryption key, and the first message carrying the key index, so that the DNS server stores the key index and the data encryption key in association with each other after determining the data encryption key of the DNS client;
[0209] receiving a response message of the first message sent by the DNS server, acquiring the data encryption key carried in the response message, and storing the data encryption key and the key index in association with each other. In some embodiments, the processing unit 410 is further configured to encrypt and authenticate the identity authentication information by using the pre-shared key.
[0210] The communication unit 420 is specifically configured to send a registration request message carrying the processed identity authentication information, a registration ID, and the key index to the DNS server, so that the DNS server queries a pre-shared key associated with the registration ID according to the registration ID carried in the received registration request message, and decrypts and authenticates the identity authentication information in the received registration request message according to the queried pre-shared key; wherein the DNS server stores an association relationship between the registration ID and the pre-shared key.
[0211] The communication unit 420 is further configured to receive a registration success response message sent by the DNS server; decrypt and authenticate the data encryption key in the registration success response message by using the pre-shared key, and store the decrypted data encryption key and the key index in association with each other in the case of successful authentication; wherein the registration success response message carries the data encryption key processed by encryption and authentication by using the pre-shared key, and the data encryption key is generated by the DNS server in the case of successful authentication of the identity authentication information in the received registration request message.
[0212] In some embodiments, the identity authentication information includes the registration ID, the key index, and other identity authentication information, the other identity authentication information includes an IP address of the DNS client and / or an IP address of the DNS server; and the pre-shared key and the registration ID are acquired by the DNS client in an offline manner.
[0213] In some embodiments, the communication unit 420 is specifically configured to acquire the data encryption key and the key lifetime carried in the response message of the first message.
[0214] The communication unit 420 is specifically configured to send a first message to the DNS server when the DNS client connects to the local area network for the first time, or when the DNS client determines that the current data encryption key is expired.
[0215] Please refer to Figure 5 A structure diagram of a message processing device provided by the embodiments of the present disclosure is shown in FIG. 5, wherein the message processing device can be deployed in a DNS server, such as Figure 5 As shown in FIG. 5, the message processing device can include:
[0216] The communication unit 510 is configured to receive a DNS request message sent by a DNS client; the processing unit 520 is configured to query an associated data encryption key according to a key index carried in the DNS request message, and decrypt and authenticate request data of the DNS request message according to the queried data encryption key; wherein the DNS request message is sent by the DNS client after encryption and authentication processing of request data of the DNS request message by using the data encryption key, and the processed DNS request message carries the key index;
[0217] The processing unit 520 is further configured to generate response data according to the decrypted request data when the authentication of the request data of the received DNS request message is passed, and perform encryption and authentication processing on the generated response data by using the data encryption key.
[0218] The communication unit 510 is further configured to carry the processed response data in a DNS response message and send it to the DNS client, so that the DNS client queries an associated data encryption key according to a key index carried in the DNS response message, and decrypts and authenticates response data of the DNS response message according to the queried data encryption key.
[0219] In some embodiments, the communication unit 510 is further configured to receive a first message sent by the DNS client; the first message is used to request to acquire the data encryption key, and the first message carries a key index.
[0220] The processing unit 520 is further configured to acquire the key index carried in the first message, and store the key index and the data encryption key in association when it is determined that the data encryption key of the DNS client is acquired.
[0221] The communication unit 510 is further configured to send a response message carrying the data encryption key to the DNS client.
[0222] In some embodiments, the communication unit 510 is specifically configured to receive a registration request message sent by the DNS client, wherein the registration request message carries processed identity authentication information, a registration ID, and the key index, the processed identity authentication information being obtained by the DNS client through encryption and authentication processing of identity authentication information using a pre-shared key; the DNS server stores an association between the registration ID and the pre-shared key.
[0223] The processing unit 530 is further configured to query the pre-shared key associated with the registration ID according to the registration ID carried in the registration request message, and decrypt and authenticate the identity authentication information in the received registration request message according to the queried pre-shared key.
[0224] The communication unit 510 is further configured to send a registration success response message carrying the data encryption key to the DNS client.
[0225] In some embodiments, the identity authentication information includes the registration ID, the key index, and other identity authentication information, the other identity authentication information including an IP address of the DNS client and / or an IP address of the DNS server; the pre-shared key and the registration ID are obtained by the DNS client through an offline manner.
Claims
1. A message processing method, characterized in that, Applied to Domain Name System (DNS) clients, the method includes: The DNS request message data is encrypted and authenticated using a stored data encryption key. The key index is then carried in the processed DNS request message and sent to the DNS server. The DNS server then uses the key index carried in the received DNS request message to query the associated data encryption key and decrypts and authenticates the received DNS request message data based on the queried data encryption key. The data encryption key is obtained by the DNS client from the DNS server and stored in association with the key index. The system receives a DNS response message sent by the DNS server, queries the associated data encryption key based on the key index carried in the DNS response message, and decrypts and authenticates the response data of the DNS response message based on the queried data encryption key. The DNS response message is sent by the DNS server after successfully authenticating the request data of a received DNS request message. The response data of the DNS response message is generated by the DNS server based on the request data, and the generated response data is encrypted and authenticated using the data encryption key. The data encryption key is obtained in the following way: A first message is sent to the DNS server. The first message is used to request the data encryption key and carries the key index, so that the DNS server, after determining the data encryption key of the DNS client, associates and stores the key index with the data encryption key. Receive a response message to the first message sent by the DNS server, obtain the data encryption key carried in the response message, and associate and store the data encryption key with the key index; Sending the first message to the DNS server includes: The authentication information is encrypted and authenticated using a pre-shared key, and a registration request message carrying the processed authentication information, registration ID, and key index is sent to the DNS server. This allows the DNS server to query the associated pre-shared key based on the registration ID carried in the received registration request message, and to decrypt and authenticate the authentication information in the received registration request message based on the queried pre-shared key. The DNS server stores the association between the registration ID and the pre-shared key.
2. The method according to claim 1, characterized in that, The step of receiving a response message to the first message sent by the DNS server, obtaining the data encryption key carried in the response message, and associating and storing the data encryption key with the key index includes: The DNS server receives a registration success response message; wherein the registration success response message carries a data encryption key that has been encrypted and authenticated using the pre-shared key, and the data encryption key is generated by the DNS server when the identity authentication information in the received registration request message is successfully authenticated; The data encryption key in the registration success response message is decrypted and authenticated using the pre-shared key, and if the authentication is successful, the decrypted data encryption key is associated with and stored with the key index.
3. The method according to claim 1, characterized in that, The authentication information includes the registration ID, the key index, and other authentication information, including the IP address of the DNS client and / or the IP address of the DNS server; the pre-shared key and the registration ID are obtained by the DNS client offline.
4. The method according to claim 1, characterized in that, Obtaining the data encryption key carried in the response message includes: Obtain the data encryption key and key lifetime carried in the response message; Sending the first message to the DNS server includes: When the DNS client first connects to the local area network, or when the DNS client determines that the current data encryption key has expired, it sends a first message to the DNS server.
5. A message processing method, characterized in that, Applied to the Domain Name System (DNS) server, the method includes: The system receives a DNS request message sent by a DNS client, queries the associated data encryption key based on the key index carried in the DNS request message, and decrypts and authenticates the request data of the DNS request message based on the queried data encryption key; wherein the DNS request message is sent by the DNS client after encrypting and authenticating the request data of the DNS request message using the data encryption key, and the processed DNS request message carries the key index; If the request data of the received DNS request message is successfully authenticated, response data is generated based on the decrypted request data. The generated response data is then encrypted and authenticated using the data encryption key. The processed response data is then carried in a DNS response message and sent to the DNS client. This allows the DNS client to query the associated data encryption key based on the key index carried in the DNS response message, and to decrypt and authenticate the response data of the DNS response message based on the queried data encryption key. The method further includes: Receive a first message sent by the DNS client; the first message is used to request the data encryption key, and the first message carries a key index; Obtain the key index carried in the first message; if the data encryption key of the DNS client is determined, associate and store the key index with the data encryption key, and send a response message carrying the data encryption key to the DNS client. Receive the first message sent by the DNS client, including: The DNS server receives a registration request message sent by a DNS client; wherein the registration request message carries processed authentication information, a registration ID, and the key index; the processed authentication information is obtained by the DNS client through encryption and authentication using a pre-shared key; and the DNS server stores the association between the registration ID and the pre-shared key. The associated pre-shared key is queried based on the registration ID carried in the registration request message, and the identity authentication information in the received registration request message is decrypted and authenticated based on the queried pre-shared key.
6. The method according to claim 5, characterized in that, Sending a response message carrying the data encryption key to the DNS client includes: Send a registration success response message carrying the data encryption key to the DNS client.
7. The method according to claim 5, characterized in that, The authentication information includes the registration ID, the key index, and other authentication information, including the IP address of the DNS client and / or the IP address of the DNS server; the pre-shared key and the registration ID are obtained by the DNS client offline.
8. A message processing apparatus, characterized in that, Deployed in a Domain Name System (DNS) client, the device includes: The processing unit is used to encrypt and authenticate the request data of the DNS request message using the stored data encryption key; the data encryption key is obtained by the DNS client from the DNS server and stored in association with the key index; The communication unit is used to send the key index in the processed DNS request message to the DNS server, so that the DNS server can query the associated data encryption key according to the key index carried in the received DNS request message, and decrypt and authenticate the request data of the received DNS request message according to the queried data encryption key. The communication unit is further configured to receive a DNS response message sent by the DNS server; wherein the DNS response message is sent by the DNS server after the request data of the received DNS request message has been authenticated, and the response data of the DNS response message is generated by the DNS server based on the request data, and the generated response data is encrypted and authenticated using the data encryption key. The processing unit is further configured to query the associated data encryption key based on the key index carried in the DNS response message, and decrypt and authenticate the response data of the DNS response message based on the queried data encryption key; The communication unit is further configured to send a first message to a DNS server, the first message being used to request the data encryption key, and the first message carrying the key index, so that the DNS server, having determined the data encryption key of the DNS client, associates and stores the key index with the data encryption key; and receives a response message to the first message sent by the DNS server, obtains the data encryption key carried in the response message, and associates and stores the data encryption key with the key index. The communication unit is specifically used to encrypt and authenticate identity authentication information using a pre-shared key, and send a registration request message carrying the processed identity authentication information, registration ID, and key index to the DNS server, so that the DNS server queries the associated pre-shared key based on the registration ID carried in the received registration request message, and decrypts and authenticates the identity authentication information in the received registration request message based on the queried pre-shared key; wherein, the DNS server stores the association relationship between the registration ID and the pre-shared key.
9. A message processing apparatus, characterized in that, Deployed on a Domain Name System (DNS) server, the device includes: The communication unit is used to receive DNS request messages sent by DNS clients; The processing unit is configured to query the associated data encryption key based on the key index carried in the DNS request message, and decrypt and authenticate the request data of the DNS request message based on the queried data encryption key; wherein the DNS request message is sent by the DNS client after encrypting and authenticating the request data of the DNS request message using the data encryption key, and the processed DNS request message carries the key index. The processing unit is further configured to, upon successful authentication of the request data in the received DNS request message, generate response data based on the decrypted request data, and encrypt and authenticate the generated response data using the data encryption key. The communication unit is further configured to send the processed response data in a DNS response message to the DNS client, so that the DNS client can query the associated data encryption key based on the key index carried in the DNS response message, and decrypt and authenticate the response data of the DNS response message based on the queried data encryption key; The communication unit is further configured to receive a first message sent by the DNS client; the first message is used to request the data encryption key, and the first message carries a key index; the key index carried in the first message is obtained, and if the data encryption key of the DNS client is determined, the key index is associated with the data encryption key and stored, and a response message carrying the data encryption key is sent to the DNS client. The communication unit is specifically used to receive a registration request message sent by a DNS client; wherein the registration request message carries processed authentication information, a registration ID, and the key index, the processed authentication information being obtained by the DNS client through encryption and authentication using a pre-shared key; the DNS server stores the association between the registration ID and the pre-shared key; it queries the associated pre-shared key based on the registration ID carried in the registration request message, and decrypts and authenticates the authentication information in the received registration request message based on the queried pre-shared key.
Citation Information
Patent Citations
Session encryption method and device, equipment and storage medium
CN114143108A
Secret key authentication method and device and electronic equipment
CN119545349A