DoH-based network access method and device, computer equipment and storage medium

By using DoH technology to send requests to multiple service providers in parallel, selecting the fastest resolution results and performing necessary proxy and cache adjustments, the DNS hijacking problem caused by the lack of encryption protection in traditional DNS queries is solved, and more efficient and secure network access is achieved.

CN120238320APending Publication Date: 2025-07-01BEIJING SHANGYI HEART TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311830819.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Traditional DNS queries lack encryption protection, resulting in DNS hijacking problems and threats to users' privacy and security.

Method used

Using the DoH-based network access method, DNS resolution requests are sent to multiple DoH service providers in parallel, the service provider with the shortest resolution time is selected to return the resolution results, and proxy configuration and cache pool adjustments are performed if necessary.

Benefits of technology

It effectively avoids DNS hijacking, improves the security and efficiency of network access, ensures user privacy and security, and optimizes network transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238320A_ABST
    Figure CN120238320A_ABST
Patent Text Reader

Abstract

The invention discloses a DoH-based network access method and device, computer equipment and a storage medium, and the method comprises the steps: receiving a DoH analysis request transmitted by a user side, and transmitting the DoH analysis request to each DoH service provider in parallel for analysis; the analysis time for each DoH service provider to return the analysis result is counted, and the target DoH service provider corresponding to the shortest analysis time is obtained; when the analysis time of the target DoH service provider is less than or equal to preset analysis time, sending an analysis result of the target DoH service provider to the user side; according to the invention, the security and efficiency of user network access can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission technology, and in particular to a DoH-based network access method, device, computer equipment and storage medium. Background Art

[0002] DNS (Domain Name System) is a way for a user to enter a recognizable URL in a browser, and the system will find the corresponding IP address in a very short time. During the URL resolution process, DNS accesses various name servers and obtains the digital address corresponding to the URL stored in these name servers. Up to now, DNS has been developed for decades, and although it is widely used, it rarely attracts people's attention to its security.

[0003] From a security perspective, requests are usually transmitted without any encryption, and DNS that can be read by anyone is actually unsafe. This means that cybercriminals can easily use their own servers to intercept the victim's DNS and redirect the user's request to phishing websites that distribute malware or place a large number of advertisements on normal websites to attract users. This behavior is called DNS hijacking.

[0004] Due to the existence of DNS hijacking, users' privacy and security are threatened. Traditional DNS queries lack encryption protection, making it easy for cyber criminals to steal users' personal information or tamper with users' network behavior. In addition, DNS hijacking may also cause users to be unable to access the websites they requested, thus affecting their normal work and daily life.

[0005] Therefore, how to ensure the security of DNS has become a technical problem that needs to be solved urgently by those skilled in the art. Summary of the invention

[0006] The purpose of the present invention is to provide a network access method, device, computer equipment and storage medium based on DoH, which can improve the security and efficiency of user network access.

[0007] According to one aspect of the present invention, a DoH-based network access method is provided, the method comprising the following steps:

[0008] Receive a DoH resolution request sent by the user end, and send the DoH resolution request in parallel to each DoH service provider for resolution;

[0009] Count the resolution time of each DoH service provider returning the resolution result, and obtain the target DoH service provider with the shortest resolution time.

[0010] When the parsing time of the target DoH service provider is less than or equal to the preset parsing time, send the parsing result of the target DoH service provider to the client.

[0011] Optionally, after receiving the DoH parsing request sent by the client, the method further includes:

[0012] Obtain the target domain name from the DoH parsing request;

[0013] When there is corresponding proxy configuration information for the target domain name, obtain the proxy server address corresponding to the target domain name according to the proxy configuration information;

[0014] Send the DoH parsing request to the proxy server corresponding to the proxy server address to proxy the DoH parsing request through the proxy server.

[0015] Optionally, after sending the parsing result of the target DoH service provider to the client when the parsing time of the target DoH service provider is less than or equal to the preset parsing time, the method further includes:

[0016] When the parsing time of the target DoH service provider is greater than the preset parsing time, send the DoH parsing request to the local DNS server for parsing;

[0017] Obtain the local parsing result of the local DNS server and return the local parsing result to the client.

[0018] Optionally, after sending the parsing result of the target DoH service provider to the client when the parsing time of the target DoH service provider is less than or equal to the preset parsing time, the method further includes:

[0019] Count the number of requests for DoH parsing requests received within a preset time period;

[0020] Adjust the capacity of the service provider cache pool according to the preset cache pool capacity adjustment rule based on the number of requests;

[0021] Cache the parsing result corresponding to the DoH parsing request into the service provider cache pool.

[0022] Optionally, sending the parsing result of the target DoH service provider to the client includes:

[0023] Obtain the data compression algorithm supported by the client, and compress the parsing result according to the data compression algorithm to obtain a parsing result compression package;

[0024] Obtain a target connection corresponding to the parsed result compressed package from the service provider cache pool, and transmit the parsed result compressed package to the client through the target connection.

[0025] To achieve the above object, the present invention further provides a device for a network access method based on DoH. The device specifically includes the following components:

[0026] A receiving module, configured to receive a DoH parsing request sent by a client, and send the DoH parsing request in parallel to each DoH service provider for parsing;

[0027] A statistics module, configured to count the parsing time of the parsing results returned by each DoH service provider, and obtain a target DoH service provider corresponding to the shortest parsing time;

[0028] A sending module, configured to send the parsing result of the target DoH service provider to the client when the parsing time of the target DoH service provider is less than or equal to a preset parsing time.

[0029] Optionally, the device further includes:

[0030] Obtain a target domain name from the DoH parsing request;

[0031] When there is corresponding proxy configuration information for the target domain name, obtain the proxy server address corresponding to the target domain name according to the proxy configuration information;

[0032] Send the DoH parsing request to a proxy server corresponding to the proxy server address, so as to proxy the DoH parsing request through the proxy server.

[0033] Optionally, the device further includes:

[0034] When the parsing time of the target DoH service provider is greater than the preset parsing time, send the DoH parsing request to a local DNS server for parsing;

[0035] Obtain the local parsing result of the local DNS server, and return the local parsing result to the client.

[0036] To achieve the above object, the present invention further provides a computer device, which specifically includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the above-described network access method based on DoH are implemented.

[0037] To achieve the above object, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-described DoH-based network access method are implemented.

[0038] The DoH-based network access method, device, computer device and storage medium provided by the present invention parallelly send the DoH parsing requests sent by the user side to each preset DoH service provider for parsing, and obtain the parsing result returned by the DoH service provider that meets the return condition and has the shortest parsing time, and send the parsing result to the user side. By using the DoH technology, the network hijacking problem that occurs in traditional DNS access is avoided, ensuring the security and reliability of the access request. Since multiple DoH service providers are set at the same time and the fastest parsing result is obtained from them, the efficiency of parsing the user side access request is improved, and it can also avoid the impact on the normal access when a single DoH service provider is unavailable, improving the network request speed and bringing a more efficient network experience to users, and improving the network transmission efficiency. In addition, by compressing and encrypting the transmission of the parsing result and increasing the cache pool capacity, the transmission traffic is saved, saving traffic resources for both the user side and the server. At the same time, the proxy function is pre-configured in the database. After receiving the DoH parsing request, it is determined whether to enable the proxy server by comparing the proxy configuration information in the database. If there is matching proxy configuration information, the corresponding proxy server is enabled to proxy the network access. The proxy automation function is realized, and there is no need for the user to manually enable the proxy function every time they access, bringing a better access experience to the user. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0040] Figure 1 An optional flowchart of the DoH-based network access method provided for Example 1;

[0041] Figure 2 An optional structural composition diagram of the DoH-based network access device provided for Example 2;

[0042] Figure 3 An optional hardware architecture diagram of the computer device provided for Example 3. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] Embodiment 1

[0045] The embodiment of the present invention provides a network access method based on DoH, as Figure 1 shown, the method specifically includes the following steps:

[0046] Step S101: Receive the DoH resolution request sent by the client and send the DoH resolution request to each DoH service provider in parallel for resolution.

[0047] Among them, the DoH (DNS over HTTPS) is a feasible alternative technology for DNS based on HTTPS. DNS (Domain Name System) is a way that when a user enters a recognizable website address in a browser, the system will find the corresponding IP address in a very short time. From a security perspective, DNS, which is usually not encrypted during request transmission and can be read by anyone, allows cybercriminals to easily use their own servers to intercept the victim's DNS and redirect the user's request to a phishing website. These websites release malware or display a large number of advertisements on normal websites to attract users. This behavior is called DNS hijacking. To solve the DNS hijacking problem, this embodiment introduces a feasible alternative to DNS based on HTTPS and a technical solution for network access using DoH technology. DoH is a technology that encrypts DNS queries through the HTTPS protocol. It uses SSL / TLS encryption to protect DNS queries and responses, making it impossible for cybercriminals to easily intercept and tamper with the user's DNS queries.

[0048] By using DoH technology, the user's DNS queries will be encrypted and transmitted through the HTTPS protocol, thereby increasing security. In this way, even if cybercriminals attempt to intercept the user's DNS queries, they cannot read or tamper with the content of the queries. In addition, DoH also provides better privacy protection because the user's DNS queries and responses will be encrypted, thus preventing possible eavesdropping and surveillance.

[0049] In addition, although mainstream servers already support setting a single DoH service provider for network access resolution, when faced with a huge number of resolution requests, a single DoH service provider may encounter problems such as excessive access volume, limited nodes, and slow return of resolution results, which may cause abnormal network access. Therefore, in this embodiment, multiple DoH service providers are set, and DoH resolution requests are sent to each DoH service provider in parallel to jointly resolve the DoH resolution requests, avoiding the technical problem of limited nodes of a single DoH service provider.

[0050] Preferably, the number of DoH service providers is 4.

[0051] Step S102: Statistically analyze the resolution time for each DoH service provider to return the resolution result, and obtain the target DoH service provider corresponding to the shortest resolution time.

[0052] Among them, the resolution time refers to the time taken from sending the DoH resolution request to returning the resolution result. Since different DoH service providers have different return times for different DoH resolution requests, and the server performance and network latency of different DoH service providers vary, the DoH service provider with the fastest resolution speed is obtained to improve the resolution efficiency.

[0053] Step S103: When the resolution time of the target DoH service provider is less than or equal to the preset resolution time, send the resolution result of the target DoH service provider to the client.

[0054] Among them, when the resolution time of the DoH service provider meets the preset resolution time, the resolution result of the target DoH service provider with the fastest resolution speed is used as the resolution result returned to the client.

[0055] In this embodiment, by taking the DNS resolution request sent by the client as a DoH resolution request and sending it to each DoH service provider in parallel, each DoH service provider resolves the DoH resolution request, and the resolution result of the target DoH service provider with the fastest resolution speed and whose resolution time meets the preset resolution time is returned to the client. Using the DoH technology, the DNS resolution problem is solved at the technical level, avoiding the occurrence of DNS hijacking. By parallelly resolving the DoH resolution requests through multiple DoH service providers, the network request speed is increased, providing a more efficient network experience for users and improving the network transmission efficiency.

[0056] Specifically, after receiving the DoH resolution request sent by the client, the method further includes:

[0057] Step A1: Obtain the target domain name from the DoH resolution request.

[0058] Step A2: When there is corresponding proxy configuration information for the target domain name, obtain the proxy server address corresponding to the target domain name according to the proxy configuration information.

[0059] Step A3: Send the DoH resolution request to the proxy server corresponding to the proxy server address, so as to proxy the DoH resolution request through the proxy server.

[0060] Among them, there are many situations where a proxy needs to be applied for access in the DoH resolution request sent by the client. Therefore, before the DoH service provider resolves the DoH resolution request, it is necessary to determine whether the domain name included in the DoH resolution request needs to apply a proxy for subsequent access.

[0061] In this embodiment, the proxy configuration information is stored in the database in advance. After receiving the DoH resolution request, it is determined whether to enable the proxy server by comparing the proxy configuration information in the database. If there is matching proxy configuration information, the corresponding proxy server is enabled to proxy the network access. The proxy automation function is realized, and there is no need for the user to manually enable the proxy function every time they access.

[0062] Further, after sending the resolution result of the target DoH service provider to the client when the resolution time of the target DoH service provider is less than or equal to the preset resolution time, the method further includes:

[0063] Step B1: When the resolution time of the target DoH service provider is greater than the preset resolution time, send the DoH resolution request to the local DNS server for resolution.

[0064] Among them, when the resolution time of the target DoH service provider is greater than the preset resolution time, it means that the resolution times of all DoH service providers do not meet the preset resolution time. To avoid the access experience of the client, at this time, the DoH resolution request is sent to the local DNS server for resolution, so as to avoid the situation where DNS resolution cannot be performed because all DoH services are unavailable.

[0065] Step B2: Obtain the local resolution result of the local DNS server and return the local resolution result to the client.

[0066] Even further, after sending the resolution result of the target DoH service provider to the client when the resolution time of the target DoH service provider is less than or equal to the preset resolution time, the method further includes:

[0067] Step C1: Count the number of requests of the DoH resolution requests received within a preset time period.

[0068] Step C2: According to the preset cache pool capacity adjustment rule, adjust the capacity of the service provider cache pool based on the number of requests.

[0069] Among them, when the number of DoH parsing requests increases, the capacity of the service provider cache pool can be expanded, connections can be established in advance in the cache pool, and connections can be obtained from the cache pool when needed, avoiding establishing new connections every time a connection is required. After using the connection, the connection can be returned to the cache pool for other requests to use. Due to the expansion of the cache pool capacity, frequent establishment of new connections is avoided, consuming a large amount of traffic.

[0070] Step C3: Cache the parsing result corresponding to the DoH parsing request in the service provider cache pool.

[0071] Among them, the service provider cache pool can not only cache connections, but also cache the parsing results corresponding to DoH parsing requests, improving the parsing speed of repeated access DoH parsing requests and improving access efficiency.

[0072] In addition, sending the parsing result of the target DoH service provider to the client includes:

[0073] Step D1: Obtain the data compression algorithm supported by the client, and compress the parsing result according to the data compression algorithm to obtain a parsing result compressed package.

[0074] Among them, in the HTTPS protocol, data compression, transmission efficiency improvement, and data security protection can be achieved by encoding the content.

[0075] Preferably, the data compression algorithm includes: Gzip algorithm or Deflate algorithm. By setting the Accept-Encoding header field, the data encoding method that the client can understand is informed to the server. For example, if the client includes "Accept-Encoding: gzip, deflate" in its request header, it means that the client can accept data compressed using the Gzip algorithm or the Deflate algorithm. By setting Content-Encoding: This header field is used to inform the client of the encoding method adopted by the server for the response content. For example, if the server chooses to compress the response content using the Gzip algorithm, it can include "Content-Encoding: gzip" in the response header.

[0076] Step D2: Obtain the target connection corresponding to the parsing result compressed package from the service provider cache pool, and transmit the parsing result compressed package to the client through the target connection.

[0077] After transmitting the parsed result compressed package to the client through the target connection, the method further includes:

[0078] Obtain a decoding algorithm corresponding to the data compression algorithm, and decode the parsed result compressed package through the decoding algorithm to obtain the original parsed result.

[0079] Furthermore, the method further includes:

[0080] Set a timeout for the connections in the service provider cache pool. When the idle time of a connection exceeds the timeout, close the connection;

[0081] Send a heartbeat packet to the connections in the service provider cache pool according to a preset heartbeat period. When there is a connection for which the heartbeat packet sending fails, perform a re-establishment operation on the connection;

[0082] Check the connections in the service provider cache pool according to a set check period, and delete invalid connections and connections that have not been used for a preset time.

[0083] In this embodiment, after compressing the parsed result using a compression algorithm and then transmitting it, the amount of data transmitted over the network can be significantly reduced, improving the content transmission speed. At the same time, the compression algorithm accompanied by an encryption mechanism can prevent unauthorized third parties from seeing the content of the document, providing data security.

[0084] In this embodiment, the DoH parsing requests sent by the client are sent in parallel to each preset DoH service provider for parsing, and the parsed result returned by the DoH service provider that meets the return conditions and has the shortest parsing time is obtained and sent to the client. Through the DoH technology, the network hijacking problem that occurs in traditional DNS access is avoided, ensuring the security and reliability of the access request. Since multiple DoH service providers are set at the same time and the fastest parsed result is obtained from them, the efficiency of parsing the client access request is improved, and it can also avoid affecting the normal access when a single DoH service provider is unavailable, improving the network request speed and bringing a more efficient network experience to users, and improving the network transmission efficiency. In addition, by compressing and encrypting the transmission of the parsed result, increasing the cache pool capacity, the transmission traffic is saved, saving traffic resources for both the client and the server. At the same time, the proxy function is pre-configured in the database. After receiving a DoH parsing request, it is determined whether to enable the proxy server by comparing the proxy configuration information in the database. If there is matching proxy configuration information, the corresponding proxy server is enabled to proxy the network access. The proxy automation function is realized, and there is no need for the user to manually enable the proxy function every time they access, bringing a better access experience to the user.

[0085] Embodiment 2

[0086] Based on the DoH-based network access method provided in the above Embodiment 1, a DoH-based network access device is provided in this embodiment. Specifically, Figure 2 The optional structural block diagram of the DoH-based network access device is shown. The DoH-based network access device is divided into one or more program modules. One or more program modules are stored in a storage medium and executed by one or more processors to complete the present invention. The program modules referred to in the present invention refer to a series of computer program instruction segments that can complete specific functions. They are more suitable for describing the execution process of the DoH-based network access device in the storage medium than the program itself. The following description will specifically introduce the functions of each program module in this embodiment.

[0087] As Figure 2 shown, the DoH-based network access device specifically includes the following components:

[0088] A receiving module 201, configured to receive a DoH resolution request sent by a user terminal and send the DoH resolution request to each DoH service provider in parallel for resolution;

[0089] A statistical module 202, configured to count the resolution time of the resolution results returned by each DoH service provider and obtain the target DoH service provider corresponding to the shortest resolution time;

[0090] A sending module 203, configured to send the resolution result of the target DoH service provider to the user terminal when the resolution time of the target DoH service provider is less than or equal to a preset resolution time.

[0091] Specifically, the receiving module 201 is further configured to:

[0092] Obtain a target domain name from the DoH resolution request;

[0093] When there is corresponding proxy configuration information for the target domain name, obtain the proxy server address corresponding to the target domain name according to the proxy configuration information;

[0094] Send the DoH resolution request to the proxy server corresponding to the proxy server address to proxy the DoH resolution request through the proxy server.

[0095] Further, the sending module 203 is further configured to:

[0096] When the resolution time of the target DoH service provider is greater than the preset resolution time, send the DoH resolution request to the local DNS server for resolution;

[0097] Obtain the local resolution result of the local DNS server and return the local resolution result to the client.

[0098] Furthermore, the sending module 203 is further configured to:

[0099] Count the number of requests for DoH resolution received within a preset time period;

[0100] Adjust the capacity of the service provider cache pool according to the preset cache pool capacity adjustment rule based on the number of requests;

[0101] Cache the resolution result corresponding to the DoH resolution request into the service provider cache pool.

[0102] In addition, the sending module 203 is further configured to:

[0103] Obtain the data compression algorithm supported by the client, and compress the resolution result according to the data compression algorithm to obtain a compressed packet of the resolution result;

[0104] Obtain a target connection corresponding to the compressed packet of the resolution result from the service provider cache pool, and transmit the compressed packet of the resolution result to the client through the target connection.

[0105] Embodiment III

[0106] This embodiment also provides a computer device, such as a smart phone, a tablet computer, a notebook computer, a desktop computer, a rack server, a blade server, a tower server or a cabinet server (including an independent server, or a server cluster composed of multiple servers) that can execute programs. As Figure 3 shown, the computer device 30 of this embodiment at least includes, but is not limited to, a memory 301 and a processor 302 that can communicate with each other through a system bus. It should be noted that, Figure 3 Only the computer device 30 with components 301-302 is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be alternatively implemented.

[0107] In this embodiment, the memory 301 (i.e., the readable storage medium) includes flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 301 may be an internal storage unit of the computer device 30, such as the hard disk or memory of the computer device 30. In other embodiments, the memory 301 may also be an external storage device of the computer device 30, such as a plug-in hard disk equipped on the computer device 30, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Of course, the memory 301 may also include both the internal storage unit and the external storage device of the computer device 30. In this embodiment, the memory 301 is generally used to store the operating system and various application software installed on the computer device 30. In addition, the memory 301 may also be used to temporarily store various data that have been output or will be output.

[0108] In some embodiments, the processor 302 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 302 is generally used to control the overall operation of the computer device 30.

[0109] Specifically, in this embodiment, the processor 302 is used to execute the program of the DoH-based network access method stored in the memory 301. When the program of the DoH-based network access method is executed, the following steps are implemented:

[0110] Receive the DoH resolution request sent by the client, and send the DoH resolution request in parallel to each DoH service provider for resolution;

[0111] Statistically analyze the resolution time of the resolution results returned by each DoH service provider, and obtain the target DoH service provider corresponding to the shortest resolution time;

[0112] When the resolution time of the target DoH service provider is less than or equal to the preset resolution time, send the resolution result of the target DoH service provider to the client.

[0113] For the specific implementation process of the above method steps, reference can be made to Embodiment 1, and this embodiment will not be repeated here.

[0114] Embodiment 4

[0115] This embodiment also provides a computer-readable storage medium, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, server, App application store, etc., on which a computer program is stored. When the computer program is executed by a processor, the following method steps are implemented:

[0116] Receive a DoH resolution request sent by the user terminal, and send the DoH resolution request in parallel to each DoH service provider for resolution;

[0117] Statistically analyze the resolution time of the resolution results returned by each DoH service provider, and obtain the target DoH service provider corresponding to the shortest resolution time;

[0118] When the resolution time of the target DoH service provider is less than or equal to the preset resolution time, send the resolution result of the target DoH service provider to the user terminal.

[0119] For the specific implementation process of the above method steps, reference can be made to Embodiment 1, and this embodiment will not be repeated here.

[0120] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including that element.

[0121] The serial numbers of the above embodiments of the present invention are only for description and do not represent the superiority or inferiority of the embodiments.

[0122] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0123] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. A network access method based on DoH, characterized in that, The method includes: Receiving a DoH resolution request sent by a client, and sending the DoH resolution request in parallel to each DoH service provider for resolution; Counting the resolution time for each DoH service provider to return a resolution result, and obtaining the target DoH service provider corresponding to the shortest resolution time; When the resolution time of the target DoH service provider is less than or equal to a preset resolution time, sending the resolution result of the target DoH service provider to the client.

2. The network access method based on DoH according to claim 1, wherein After receiving the DoH resolution request sent by the client, the method further includes: Obtaining a target domain name from the DoH resolution request; When there is corresponding proxy configuration information for the target domain name, obtaining the proxy server address corresponding to the target domain name according to the proxy configuration information; Sending the DoH resolution request to the proxy server corresponding to the proxy server address, so as to proxy the DoH resolution request through the proxy server.

3. The method for network access based on DoH according to claim 1, wherein After sending the resolution result of the target DoH service provider to the client when the resolution time of the target DoH service provider is less than or equal to the preset resolution time, the method further includes: When the resolution time of the target DoH service provider is greater than the preset resolution time, sending the DoH resolution request to the local DNS server for resolution; Obtaining the local resolution result of the local DNS server, and returning the local resolution result to the client.

4. The method for network access based on DoH according to claim 1, wherein After sending the resolution result of the target DoH service provider to the client when the resolution time of the target DoH service provider is less than or equal to the preset resolution time, the method further includes: Counting the number of requests for DoH resolution requests received within a preset time period; Adjusting the capacity of the service provider cache pool according to the preset cache pool capacity adjustment rule based on the number of requests; Caching the resolution result corresponding to the DoH resolution request in the service provider cache pool.

5. The network access method based on DoH according to claim 4, wherein, Sending the resolution result of the target DoH service provider to the client includes: Obtaining the data compression algorithm supported by the client, and compressing the resolution result according to the data compression algorithm to obtain a resolution result compressed package; Obtaining a target connection corresponding to the resolution result compressed package from the service provider cache pool, and transmitting the resolution result compressed package to the client through the target connection.

6. A network access device based on DoH, characterized in that, The device includes: A receiving module, configured to receive a DoH resolution request sent by a client, and send the DoH resolution request in parallel to each DoH service provider for resolution; A statistics module, configured to count the resolution time for each DoH service provider to return a resolution result, and obtain the target DoH service provider corresponding to the shortest resolution time; A sending module, configured to send the resolution result of the target DoH service provider to the client when the resolution time of the target DoH service provider is less than or equal to a preset resolution time.

7. The network access device based on DoH according to claim 6, wherein The device further includes: Obtaining a target domain name from the DoH resolution request; When there is corresponding proxy configuration information for the target domain name, obtaining the proxy server address corresponding to the target domain name according to the proxy configuration information; Send the DoH resolution request to a proxy server corresponding to the proxy server address, so as to proxy the DoH resolution request through the proxy server.

8. The network access device based on DoH according to claim 6, wherein The device further includes: When the resolution time of the target DoH service provider is greater than a preset resolution time, send the DoH resolution request to a local DNS server for resolution; Obtain a local resolution result of the local DNS server, and return the local resolution result to the client.

9. A computer device, the computer device comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 5 when executing the computer program.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program, when executed by the processor, implements the steps of the method according to any one of claims 1 to 5.