Domain name verification method and device and storage medium
By analyzing domain name registration information, historical verification data and DNS resolution records, dynamically selecting the best verification service nodes and methods, and using multi-node verification, solving the problem of vulnerability in traditional domain name verification and achieving more reliable and secure domain name verification.
Patent Information
- Application Number
- CN202511014996.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-07-23
AI Technical Summary
Traditional domain name verification methods rely on fixed means and are susceptible to improper information storage or cyber attacks, resulting in low reliability.
By analyzing domain name registration information, historical verification data and DNS resolution records, dynamically select the best verification service node and verification method, and use multi-node verification to prevent misjudgment caused by single point of failure or network attacks.
It improves the reliability and security of domain name verification, ensures the stability and accuracy of the verification process, and reduces misjudgments caused by network problems.
Smart Images

Figure CN120528895A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of digital information transmission, and in particular to a domain name verification method, device, and storage medium. Background Art
[0002] In today's era of rapid digital development, the Internet has become an indispensable part of people's lives and work. Domain names are key identifiers of the Internet, and the reliability and security of their verification are related to the stability and credibility of network communications.
[0003] Traditional domain name verification methods have many drawbacks and mainly rely on fixed verification methods, such as simply checking the domain name registration information. This method is extremely vulnerable to improper information storage or network attacks. Once the relevant information is illegally tampered with or stolen, it may lead to low reliability of domain name verification. Summary of the Invention
[0004] The main purpose of this application is to provide a domain name verification method, device and storage medium, aiming to solve the technical problem of low reliability of domain name verification.
[0005] To achieve the above objectives, this application proposes a domain name verification method, which includes: Determining a data processing result of the domain name based on the domain name related information, the domain name related information including at least one of domain name registration information, historical verification data, and DNS resolution records, the data processing result including a risk assessment result and a policy assessment result; Determining, based on the data processing result, a verification service node corresponding to the domain name and a domain name verification method, wherein the verification service node is used to execute the domain name verification method; Obtain a single-node verification result returned by each verification service node when executing the domain name verification method, and determine a target verification result of the domain name based on the single-node verification result.
[0006] In one embodiment, the step of obtaining the single-node verification result returned by each verification service node when executing the domain name verification method includes: Determine a target verification path according to the verification service node and the domain name verification method, where the target verification path is a path between the verification service node and a server corresponding to the domain name verification method; The single-node verification result is obtained based on the target verification path.
[0007] In one embodiment, the step of determining a target verification path according to the verification service node and the domain name verification method includes: Determining a candidate verification path according to the verification service node and the domain name verification method; Obtaining a real-time network status of each candidate verification path, wherein the real-time network status includes at least one of bandwidth, delay, and packet loss rate; Determining a comprehensive score of each candidate verification path based on the real-time network status; Among the candidate verification paths, the target verification path corresponding to the domain name is determined according to the comprehensive score.
[0008] In one embodiment, the verification service node is obtained through the following steps: Determine a candidate service node according to the data processing result; Obtaining a service indicator of each candidate service node, where the service indicator includes at least one of performance, reliability, and coverage; A verification service node is determined from the candidate service nodes according to the service indicator, attribute information of the domain name and user requirements, wherein the attribute information of the domain name includes geographical distribution and / or business type.
[0009] In one embodiment, the domain name verification method is obtained by the following steps: Determining a dynamic verification level based on the user's security requirements and the data processing results; The authentication mode of the authentication service node is determined according to the dynamic authentication level.
[0010] In one embodiment, the step of determining the verification mode of the verification service node according to the dynamic verification level includes: When the dynamic verification level is lower than the preset level threshold, the verification method of the first risk level is adopted; When the dynamic verification level is greater than or equal to the preset level threshold, a second risk level verification method is adopted, and the first risk level is lower than the second risk level.
[0011] In one embodiment, the step of determining the data processing result of the domain name based on the domain name related information includes: Extracting key features of the domain name related information, the key features including at least one of domain name registration duration, DNS resolution stability, and historical verification success rate; Determining a weight parameter corresponding to the key feature, where the weight parameter is generated based on the degree of influence of the key feature on the domain name; The data processing result of the domain name is determined according to the key feature and the weight parameter.
[0012] In one embodiment, the method further comprises: Determining the validity period of the domain name based on the frequency of changes in the domain name and the historical verification data; Determining the verification frequency of the domain name based on the validity period and importance of the domain name; Based on the verification frequency, the step of determining the data processing result of the domain name according to the domain name related information and related steps are performed.
[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes a domain name verification device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the computer program is configured to implement the steps of the domain name verification method described above.
[0014] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by the processor, the steps of the domain name verification method described above are implemented.
[0015] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the domain name verification method described above.
[0016] One or more technical solutions proposed in this application have at least the following technical effects: By analyzing multi-dimensional information such as domain name registration information, historical verification data, and DNS resolution records, we can more comprehensively assess the risk status of the domain name and the corresponding verification strategy of the domain name. Based on the data processing results, we can dynamically select the best domain name verification service node and verification method to ensure the security and reliability of the verification process. Simultaneous verification of multiple nodes can effectively prevent misjudgments caused by single point failures or network attacks, thereby improving the reliability of domain name verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0018] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0019] Figure 1 A flowchart of the first embodiment of the domain name verification method for this application is provided; Figure 2 A flowchart of the second embodiment of the domain name verification method of this application is provided; Figure 3 A flowchart of the third embodiment of the domain name verification method of this application is provided; Figure 4 A flowchart of the fourth embodiment of the domain name verification method of this application is provided; Figure 5 A flowchart of the fifth embodiment of the domain name verification method of this application is provided; Figure 6 A flowchart of the sixth embodiment of the domain name verification method of this application is provided; Figure 7 This is a schematic diagram of the device structure of the hardware operating environment involved in the domain name verification method in the embodiment of the present application.
[0020] The purpose, features and advantages of this application will be further explained with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION
[0021] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0022] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0023] The main solution of the embodiment of the present application is: determining the data processing result of the domain name based on the domain name related information, the domain name related information includes at least one of the domain name registration information, historical verification data and DNS resolution records, and the data processing result includes the risk assessment result and the policy assessment result; determining the verification service node and the domain name verification method corresponding to the domain name based on the data processing result, the verification service node is used to execute the domain name verification method; obtaining the single-node verification result returned by each verification service node when executing the domain name verification method, and determining the target verification result of the domain name based on the single-node verification result.
[0024] In this embodiment, for ease of description, the following description is made with the domain name verification device as the execution entity.
[0025] Since traditional domain name verification methods mainly rely on fixed verification methods, such as simply checking domain name registration information, this method is extremely vulnerable to improper information storage or network attacks. Once the relevant information is illegally tampered with or stolen, it may lead to low reliability of domain name verification.
[0026] This application provides a solution that, by analyzing multi-dimensional information such as domain name registration information, historical verification data, and DNS resolution records, can more comprehensively assess the risk status of a domain name and the corresponding verification strategy for the domain name. Based on the data processing results, the optimal domain name verification service node and verification method are dynamically selected to ensure the security and reliability of the verification process. Simultaneous verification of multiple nodes can effectively prevent misjudgments caused by single point failures or network attacks, thereby improving the reliability of domain name verification.
[0027] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, mobile phone, etc., or an electronic device capable of performing the above functions, a domain name verification device, etc. The following uses the domain name verification device as an example to illustrate this embodiment and the following embodiments.
[0028] Based on this, the embodiment of the present application provides a domain name verification method, referring to Figure 1 , Figure 1 This is a flowchart of the first embodiment of the domain name verification method of this application.
[0029] In this embodiment, the domain name verification method includes steps S10 to S30: Step S10: determining a data processing result of the domain name based on the domain name related information, wherein the domain name related information includes at least one of domain name registration information, historical verification data, and DNS resolution records, and the data processing result includes a risk assessment result and a policy assessment result.
[0030] Optionally, domain name related information includes domain name registration information, historical verification data and DNS (Domain Name System) resolution records, as well as domain name filing information, domain name SSL (Secure Sockets Layer) certificate information, domain name traffic information, etc. Domain name related information is not limited to the above information.
[0031] Domain name related information can be uniformly stored in the database for standardized processing.
[0032] In this embodiment, the domain name registration information is detailed information related to the registered domain name. Optionally, the domain name registration information includes information about the domain name itself, registrant information, registration service agency information, domain name server information, domain name status information, registration time, expiration time, etc.
[0033] Historical verification data refers to various records generated during previous domain name verification processes, including the time, method, results, and related details of the verification. Optionally, historical verification data includes previous verification records, exception records, and domain name status change records. Previous verification records include the time of each domain name verification, the verification method used, and whether the verification passed or failed. Exception records detail the reasons for domain name verification failures or exceptions, such as inaccurate verification information, DNS resolution anomalies, or email hijacking. Domain name status change records record changes in the domain name's status, such as the time and reason for the status change.
[0034] DNS resolution records are records generated by a DNS server when resolving a domain name into an IP (Internet Protocol) address or other resource records. These records store various configuration information for the domain name. Optionally, a DNS resolution record includes at least one or more of the following: an A record (Address Record), used to map a domain name to an IPv4 (Internet Protocol version 4) address; an AAAA record (IPv6 Address Record), used to map a domain name to an IPv6 (Internet Protocol version 6) address; an MX record (Mail Exchange Record), used to specify the mail server that receives email; a CNAME record (Canonical Name Record), used to map one domain alias to another; an NS record (Name Server Record), used to specify the authoritative DNS server for a domain name; and a TXT record (Text Record), used to store text information and often used to verify domain ownership or store Sender Policy Framework (SPF) records. PTR records (Pointer Records) are used for reverse DNS lookups, mapping IP (Internet Protocol) addresses to domain names. SRV records (Service Records) specify the server address and port number for a specific service.
[0035] Optionally, a comprehensive assessment model is constructed using a machine learning algorithm, such as a decision tree or neural network. The processed domain name information from multiple sources is input into the comprehensive assessment model, which processes the domain name and outputs a data processing result.
[0036] By comprehensively considering domain name registration information, historical verification data, and DNS resolution records, it can comprehensively assess the risk status of domain names and promptly detect anomalies and potential threats, such as whether the domain name has been maliciously registered or whether there is DNS hijacking, thereby effectively identifying high-risk domain names and preventing users from suffering from security threats such as online fraud and data leakage.
[0037] Optionally, the data processing results include risk assessment results and policy assessment results. Optionally, the risk assessment results include whether the domain name poses a risk, the risk level, the risk value, whether it is a malicious domain name, etc. Optionally, the policy assessment results include policy selection for the verification service node and / or domain name verification method, including how to select the verification service node, such as how to select a specific region. The policy assessment results may also include how to select the domain name verification method that the verification service node can execute, such as whether the verification service node supports domain name verification method A and domain name verification method B, and whether to select either domain name verification method A or domain name verification method B.
[0038] In an optional embodiment, the validity period of the domain name is determined based on the frequency of changes in the domain name and the historical verification data; the verification frequency of the domain name is determined based on the validity period and importance of the domain name; and based on the verification frequency, the step of determining the data processing result of the domain name based on the domain name related information and related steps are executed.
[0039] The frequency of domain name changes can reflect its activity and any anomalies. Frequent changes in a domain, such as frequent changes in IP addresses or registration information, may indicate instability or potential malicious activity. Combined with historical verification data, the domain's history can be traced, including any past violations or tampering. These combined factors make the process of determining domain name expiration more comprehensive and scientific, enabling more accurate judgment of domain validity and avoiding incorrectly validating expired or potentially risky domains.
[0040] For highly important domain names, a higher verification frequency can be set to promptly detect potential issues, such as attacks or tampering with key corporate domain names. For less important domain names, the verification frequency can be appropriately reduced to optimize management resources. Alternatively, importance can be determined by domain type. This automated management mechanism effectively reduces manual intervention and management costs, while improving efficiency and ensuring timely and accurate processing of domain name information.
[0041] Accurately determining domain name expiration dates and appropriate verification frequencies can prevent malicious domain name exploitation. For example, malicious users may exploit vulnerabilities in domain name expiration dates to carry out attacks. Strictly controlling domain name expiration dates and verification frequencies allows for timely detection and action on these malicious domains, protecting network users. Furthermore, proper management of legitimate domain names can enhance network stability and reduce network failures and security vulnerabilities caused by domain name issues.
[0042] Step S20: determining the verification service node and domain name verification method corresponding to the domain name according to the data processing result, and the verification service node is used to execute the domain name verification method.
[0043] Optionally, when the data processing result includes a risk assessment result, the risk assessment result includes a risk level, and different risk levels correspond to different numbers of verification service nodes. For example, a low risk level corresponds to one verification service node, a medium risk level corresponds to two verification service nodes, and a high risk level corresponds to three domain name verification service nodes.
[0044] Optionally, when the data processing result includes a policy evaluation result, the target region is determined based on the region where the domain name server is located, and the verification service node in the target region is selected. Optionally, when the data processing result includes a policy evaluation result, the type of verification service node is selected based on the type of the domain name.
[0045] In this embodiment, different domain name verification service nodes may use different domain name verification methods. For example, domain name verification node A may use domain name verification methods a and b, and domain name verification node B may use domain name verification methods a, b, and c.
[0046] Optionally, the domain name verification method can be selected by the user.
[0047] Optionally, based on the data processing results, the verification service node corresponding to the domain name and the domain name verification method are determined, the domain name verification method is output on the management interface, and the domain name verification method selected by the user is obtained based on the management interface as the final domain name verification method.
[0048] Domain name verification options include DNS verification, email verification, and file verification. DNS verification uses DNS records to prove domain control. Email verification confirms domain ownership by sending a verification email to the email address associated with the domain. During domain registration or domain-related operations, an email containing a verification link or code is sent to the email address provided in the domain registration information. The domain owner must log in to that email address and click the verification link or enter the verification code to complete the verification process. This verification method leverages the association between the email address and the domain name, assuming that users with access to the email address associated with the domain are the legitimate owners of the domain. Email verification is commonly used by domain registrars to confirm domain registration information and by some network services for preliminary verification of domain owner identity. File verification involves uploading a specific verification file to the website's root directory to verify the domain name. When verifying a domain name, the domain verification device provides a verification file containing a specific file name and content. The domain owner must upload this file to the website's root directory. This method is often used in scenarios where access to website content is restricted. For example, some website management tools or services use file verification to confirm domain ownership when linking to a domain name.
[0049] Step S30: Obtain the single-node verification result returned by each verification service node when executing the domain name verification method, and determine the target verification result of the domain name according to the single-node verification result.
[0050] Optionally, the target verification result includes domain control rights, success, or failure. This allows domain administrators and users to quickly understand the security status of a domain and take appropriate measures, such as further investigation or access restriction on high-risk domains. This improves domain management decision-making efficiency. This ensures that only verified domains are trusted and accessible, blocking the spread of malicious domains, reducing the risk of cyberattacks, and protecting the network assets of users and enterprises.
[0051] Optionally, a target verification result of the domain name is determined based on each single node verification result and a weight parameter, where the weight parameter is a preset parameter.
[0052] Optionally, the node weight of the verification service node is determined based on the reliability of the verification service node in executing the domain name verification method in historical verification data; and the target verification result is determined based on the node weight and the single-node verification result. For example, if the single-node verification result of verification service node A is a successful verification, and the single-node verification result of verification service node B is a failed verification, and the node weight of verification service node A is greater than the node weight of verification service node B, then the target verification result is a successful verification.
[0053] Optionally, after step S10, the method further includes: using the target verification result of the domain name as historical verification data; and storing the historical verification data in the blockchain. Optionally, in response to a user's query operation on the blockchain, the historical verification data of the domain name is output.
[0054] It's important to note that blockchains are tamper-proof. Storing domain name verification data on the blockchain ensures that, once written, it's difficult to maliciously alter. This provides a highly trusted data environment for domain name verification, as any unauthorized modifications will be detected by the blockchain's verification mechanisms. For example, for critical, high-value domain names, storing their verification data on the blockchain prevents competitors or malicious attackers from interfering with the validity of the domain name by tampering with historical data.
[0055] By allowing users to query historical domain name verification data on the blockchain, data transparency is achieved. Users can clearly understand all verification records of a domain name from registration to the present, including verification time and results. This is extremely helpful for domain name transactions and management. This verification information is transparent, allowing domain name owners to know whether their domain has any illegal verification records.
[0056] This embodiment proposes an innovative verification mechanism, which transforms the previous one-time verification in the industry into decision-making verification after comprehensive analysis. The comprehensive analysis combines multi-dimensional information, such as registration information, historical data, real-time data, etc., making domain name verification more reliable, safer, more efficient, and more transparent.
[0057] In the technical solution of this embodiment, by analyzing multi-dimensional information such as domain name registration information, historical verification data, and DNS resolution records, the risk status of the domain name and the verification strategy corresponding to the domain name can be more comprehensively evaluated. The optimal domain name verification service node and verification method are dynamically selected based on the data processing results to ensure the security and reliability of the verification process. The simultaneous verification of multiple nodes can effectively prevent misjudgments caused by single point failures or network attacks, thereby improving the reliability of domain name verification.
[0058] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment can be referred to the above introduction and will not be described in detail later. Figure 2 , step S30 includes: Step S31, determining a target verification path according to the verification service node and the domain name verification method, wherein the target verification path is a path between the verification service node and a server corresponding to the domain name verification method; Step S32: Acquire the single-node verification result based on the target verification path.
[0059] In this embodiment, candidate verification paths are those that support both the verification service node and the domain name verification method. Optionally, a comprehensive score is determined for each candidate verification path based on at least one of bandwidth, latency, and packet loss rate and their corresponding weights. Target verification paths with high comprehensive scores are selected to achieve a stable and fast verification path for domain name verification, thereby improving the efficiency and reliability of domain name verification.
[0060] Optionally, a network path evaluation model is established to calculate the comprehensive score of the verification paths from different domain name verification service nodes to the DNS server to which the domain name belongs, based on real-time network conditions. Target verification paths with high comprehensive scores are selected to obtain a stable and fast verification path for domain name verification, thereby improving the efficiency and reliability of domain name verification.
[0061] In an optional embodiment, step S31 includes: determining candidate verification paths based on the verification service node and domain name verification method; obtaining the real-time network status of each candidate verification path, the real-time network status including at least one of bandwidth, delay, and packet loss rate; determining the comprehensive score of each candidate verification path based on the real-time network status; and determining the target verification path corresponding to the domain name in each candidate verification path based on the comprehensive score.
[0062] By considering the verification service node and domain name verification method to determine candidate verification paths, we can explore multiple possible path options for domain name verification. Among the many candidate paths, determining the target verification path based on real-time network status can avoid sending verification requests to paths with poor network conditions. For example, if a path has low bandwidth, high latency, or a high packet loss rate, selecting such a path for domain name verification may result in slow verification or even failure. This approach prioritizes paths with good network conditions for verification, improving overall domain name verification efficiency and reducing verification time.
[0063] Real-time network status information is acquired and used to determine the target verification path, reducing the risk of domain name verification failures due to network failures or instability. For example, in the event of network congestion or node failures, the verification process can automatically switch to a verification path with better network conditions, ensuring a smooth domain name verification process. This makes the domain name verification service more reliable and reduces domain name verification errors or failures due to network issues. For paths with good network conditions, the verification request load can be appropriately increased; for paths with poor network conditions, the number of verification requests can be reduced to avoid wasting network resources. For example, for paths with ample bandwidth and low latency, more domain name verification requests can be allocated to them, fully utilizing their favorable network conditions and thus optimizing network resource allocation.
[0064] Optionally, the number of target verification paths is determined based on the data processing result. Optionally, when the risk level is less than a preset level threshold, a first number of target verification paths is used; when the risk level is greater than or equal to the preset level threshold, a second number of target verification paths is used, and the first number is less than the second number.
[0065] Optionally, when there are more than or equal to two target verification paths, a path verification result is obtained based on each target verification path, and a single-node verification result is determined according to the path verification result.
[0066] Optionally, the risk level is determined based on the data processing results, and the verification ratio is determined based on the risk level. When the consistency rate of the path verification results is greater than or equal to the verification ratio, the single-node verification result of the domain name is determined based on the path verification results with the largest proportion. When the consistency rate of the path verification results is less than the verification ratio, verification is determined to have failed. For example, if target verification path 1 is successfully verified, target verification path 2 is successfully verified, and target verification path 3 is unsuccessful, the consistency rate of the path verification results is 2 / 3, and the verification ratio is 1 / 2, then the path verification result with the largest proportion is successfully verified, and the single-node verification result is successfully verified.
[0067] Optionally, when the risk value in the data processing result is greater than a preset first risk threshold, the verification ratio is the preset first ratio. When the risk value in the data processing result is less than the preset first risk threshold and greater than a preset second risk threshold, the verification ratio is the preset second ratio. When the risk value in the data processing result is less than the preset second ratio, the verification ratio is a preset third ratio, wherein the third ratio is less than the second ratio, and the second ratio is less than the first ratio. Exemplarily, when the risk value in the data processing result is greater than 7.0, 100% path result consistency is required; when the risk value is less than 4.0, 70% path result consistency is required; for other risk values, 85% path result consistency is required.
[0068] Obtaining single-node verification results based on the target verification path avoids wasting verification resources on multiple unrelated nodes or paths. Verification service nodes can directly send verification requests to the server corresponding to the verification method being used, reducing unnecessary data transmission and processing steps. For example, for DNS-based domain name verification, verification requests are sent directly to the appropriate DNS server for verification, rather than transferring data back and forth between multiple different types of servers. This shortens verification time and improves verification efficiency.
[0069] In the technical solution of this embodiment, by clearly defining the target verification path—that is, the path from the verification service node to the server corresponding to the domain name verification method—the domain name verification process is made more precise. This ensures that the verification process is directly targeted at the verification method being used, reduces interference from irrelevant factors, improves the targeted nature of the verification, and enables more accurate determination of domain name validity.
[0070] Based on any of the above embodiments of the present application, in the third embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 3 , step S20 includes: Step S21, determining a candidate service node according to the data processing result; Step S22: obtaining a service indicator of each candidate service node, wherein the service indicator includes at least one of performance, reliability, and coverage; Step S23: determining a verification service node from the candidate service nodes according to the service index, attribute information of the domain name, and user requirements, wherein the attribute information of the domain name includes geographical distribution and / or business type.
[0071] Optionally, according to the risk level in the data processing result, a candidate service node corresponding to the risk level is determined.
[0072] Optionally, based on the selection strategy in the data processing results, candidate service nodes that meet the selection strategy are determined. Optionally, for domain names targeting global users, priority is given to verification service nodes with extensive global node coverage; for domain names in specific industries, verification service nodes with industry-specific verification capabilities are selected to improve verification efficiency and reliability.
[0073] In this embodiment, performance metrics measure the speed and efficiency with which a service node processes requests and completes tasks. Optionally, performance metrics include latency or response time, throughput, processing time, resource utilization, and the like. Reliability metrics measure the service node's ability to consistently, stably, and accurately provide the promised service. Optionally, reliability metrics include availability, failure rate, mean time between failures, mean time to repair, data consistency or correctness, and fault tolerance. Coverage metrics measure the service accessibility and breadth of a service node's services across geographic regions, network access points, or target user groups. Optionally, coverage metrics include geographic coverage, network coverage or access points, latency coverage, target user coverage, and service range.
[0074] Real-time evaluation of candidate service nodes based on performance, reliability, coverage, and other metrics. The most appropriate verification service node is selected based on domain name attributes, such as geographic distribution and business type, and user needs. Selecting verification service nodes based on user needs provides users with more targeted and efficient domain name verification services, reducing user wait times and the probability of verification failures, thereby improving user satisfaction. Verification service nodes are precisely matched based on domain name attributes such as geographic distribution and business type. For example, for domain names with a large number of users in a specific region or a specific business type, nodes close to the user base and familiar with the business can be assigned to reduce latency, improve response speed, and make the service more tailored to the actual scenario.
[0075] In the technical solution of this embodiment, the verification service node is determined by comprehensively considering service indicators, domain name attributes and user needs, and the node that best meets the requirements in terms of performance, reliability and coverage can be selected, thereby improving the verification quality and efficiency, ensuring that the verification process is stable and reliable, and meeting the personalized needs of users.
[0076] Based on any of the above embodiments of the present application, in the fourth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 4 , step S20 includes: Step S24, determining a dynamic verification level based on the user's security requirements and the data processing results; Step S25: Determine the verification method of the verification service node according to the dynamic verification level.
[0077] Taking into account the different security needs of different users, we provide users with clear and tailored verification services. For ordinary users with lower security needs, we adopt a relatively simple verification method to reduce the tedious operations during the verification process, improve verification efficiency, enable users to quickly complete domain name verification, and enhance the user experience.
[0078] Dynamically adjusting verification levels based on user security needs and data processing results ensures stricter verification for domain names with high security requirements. For example, for domain names involving financial transactions, processing sensitive user information, or other areas with extremely high security requirements, where the risk level of the data processing results exceeds the preset level, a higher dynamic verification level will be assigned, effectively preventing security threats such as domain name theft and malicious exploitation.
[0079] Verification levels are dynamically adjusted based on data processing results and user security needs. For lower-risk domains, a basic verification level is used to reduce verification steps and resource consumption. For high-risk domains or domains involving important businesses, the verification level is increased, with the addition of multi-dimensional dynamic domain name verification steps, such as extended identity verification, to ensure reliability and security.
[0080] In an optional embodiment, when the dynamic verification level is less than the preset level threshold, the first risk level verification method is adopted; when the dynamic verification level is greater than or equal to the preset level threshold, the second risk level verification method is adopted, and the first risk level is lower than the second risk level.
[0081] Optionally, verification methods for the first risk level include DNS verification, email verification, and file verification, and verification methods for the second risk level include verification of corporate information, physical address, legal qualifications, etc., in order to apply for an OV SSL certificate (Organization Validation SSL Certificate) or an EV SSL certificate (Extended Validation SSL Certificate).
[0082] In one embodiment, enterprise information is automatically verified according to the rules and algorithms of the multi-factor dynamic verification mechanism. After the enterprise information is verified, a verification token can be automatically generated, which can be integrated into the automatic deployment service and integrated into the certificate application process through the token mechanism.
[0083] Optionally, if a corporate domain name wants to apply for an OV SSL certificate, after sending a request to this system, when the target verification result is successful, that is, after the domain name control verification is completed, the legitimacy of the corporate information, physical address, legal qualifications and other entities will be automatically verified. After the verification, a verification token can be automatically generated, and the token can be used to apply for an OV SSL certificate. This extended verification token generation mechanism is also part of the multi-dimensional verification method, which is applied to the automated process of domain name certificates to promote the automation of certificate issuance.
[0084] Optionally, if a corporate domain name wishes to apply for an EV SSL certificate, after submitting a request to this system, upon receiving a successful verification result, i.e., completing domain control verification, the system automatically verifies the legitimacy of the corporate information, physical address, legal qualifications, and other entities. Upon successful verification, a verification token is automatically generated, which can be used to apply for an EV SSL certificate. This verification method is part of a multi-dimensional verification approach, applied to the automated process of domain name certificates, facilitating the automation of certificate issuance.
[0085] The above extended verification method generates a verification token after completion. This mechanism is integrated into the automated process, bringing business innovation to the verification automation solution.
[0086] Optionally, when the dynamic verification level is less than a preset level threshold, a first number of verification methods is adopted; when the dynamic verification level is greater than or equal to the preset level threshold, a second number of verification methods is adopted, and the first data is less than the second number.
[0087] In this embodiment, dynamic verification level determination allows for the rational allocation of verification service node resources. High-security verification requests are assigned to verification service nodes with higher security capabilities and resources, employing complex verification methods. Low-security requests are assigned to corresponding ordinary nodes, avoiding excessive resource usage and improving overall system resource utilization efficiency.
[0088] Based on any of the above embodiments of the present application, in the fifth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 5 , step S10 includes: Step S11, extracting key features of the domain name related information, wherein the key features include at least one of domain name registration duration, DNS resolution stability, and historical verification success rate; Step S12, determining a weight parameter corresponding to the key feature, wherein the weight parameter is generated by the degree of influence of the key feature on the domain name; Step S13: determining the data processing result of the domain name according to the key feature and the weight parameter.
[0089] There's a correlation between domain name registration duration and risk. When a domain name is registered within the appropriate timeframe, the risk is low; when it's outside the appropriate timeframe, the risk is high. For example, newly registered domains lack a track record and trustworthiness, making them vulnerable to short-term malicious activity. These domains can be frequently used for attacks within a short period of time before being quickly discarded. If long-registered domains are poorly managed, they can become forgotten or neglected, leading to outdated or unupdated security configurations, which can increase the risk of attack.
[0090] DNS resolution stability refers to the reliability and consistency of a domain name's DNS resolution process over a period of time, reflecting the stability and availability of the DNS server when processing domain name resolution requests. DNS resolution stability can also include resolution success rate, resolution latency, and resolution consistency. If a domain name has a low DNS resolution success rate, high resolution latency, or inconsistent resolution results, it may indicate technical issues or a high risk of attack.
[0091] The historical verification success rate refers to the ratio of successful domain verification attempts to the total number of verification attempts in the past, reflecting the historical performance and reliability of domain verification. Optionally, the historical verification success rate includes the verification pass rate, reasons for verification failures, and verification frequency. A low verification pass rate or frequent verification failures may indicate poor domain management or potential security risks.
[0092] Optionally, based on the degree of influence of different key features on the authenticity and security of the domain name, weight parameters corresponding to the key features are set using a method such as the analytic hierarchy process. The data processing result of the domain name is determined based on the weighted sum of the key features and the weight parameters.
[0093] By evaluating domain names using key features, particularly factors like domain registration age, DNS resolution stability, and historical verification success rates, we can more accurately assess the security of domain names. For example, domain names with longer registration periods may be more reliable, as malicious domain owners may be less inclined to register domains for extended periods to engage in illegal activities. Frequent DNS resolution instability may indicate a risk of domain name tampering or use in attacks, such as domain hijacking. A low historical verification success rate may indicate past verification issues, potentially leading to abuse or misconfiguration. By combining these key features, we can effectively distinguish legitimate from malicious domain names, improving the reliability of domain name security assessments.
[0094] By determining weight parameters corresponding to key features, the impact of each key feature on a domain name can be quantified. This allows for targeted data processing of domain names based on different business needs and security policies. In the financial sector, cybersecurity protection can assign a relatively high weight to domain name registration duration, as financial transactions involve the security of significant funds. Domain names registered for a long period of time and operating stably are likely to be more trustworthy. In content distribution network services, DNS resolution stability may be more important to ensure fast and stable user access to content. This approach allows for domain name data processing results that better meet the needs of different application scenarios.
[0095] After determining the domain name data processing results, domain names with different risk levels can be categorized and managed. Low-risk domain names can be prioritized for critical business or high-value network applications; potentially risky domain names can be restricted or further verified to optimize the overall domain name resource allocation strategy.
[0096] In this embodiment, an intelligent comprehensive analysis and decision-making engine is integrated, including intelligent selection of network routes for domain name services that need to be verified, and consideration of the system status of the verification service node itself, such as task volume, network status, system processing capabilities, etc., as well as comprehensive analysis and decision-making based on verification frequency, which greatly improves the verification efficiency and security.
[0097] In the technical solution of this embodiment, by extracting key features to evaluate domain names, the security or risk level of the domain name can be more accurately determined. The data processing results of the domain name are determined based on the key features and weight parameters, thereby improving the comprehensiveness of domain name management.
[0098] Based on any of the above embodiments of the present application, in the sixth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 6 . The first step is to collect relevant data from multiple channels such as authoritative domain name registration agencies, SSL certificate issuing authorities, DNS resolution servers, and user behavior monitoring systems. The second step is to clean, analyze and process the collected data, extract key features, and combine machine learning algorithms to perform user behavior analysis and anomaly detection. The third step is to comprehensively evaluate the verification status of the domain name based on the rules and algorithms of the multi-factor dynamic verification mechanism, and make corresponding verification decisions, including the validity period of the verification data, select a multi-dimensional verification system to simultaneously check the domain name resolution results through multiple independent optimal network nodes around the world, and finally determine the verification results in combination with the verification strategy. The fourth step is to automatically verify and obtain the company's information. The verification results can be integrated into the automatic management platform in the form of tokens, which is responsible for the verification and issuance of OV SSL or EV SSL certificates. Finally, the verification results will be stored on the blockchain, and the domain name verification status will be displayed through a visual interface, and feedback and early warning information will be sent to the domain name owner and security agency.
[0099] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the domain name verification method of this application. More simple transformations based on this technical concept are all within the scope of protection of this application.
[0100] The present application provides a domain name verification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the domain name verification method in the above-mentioned embodiment 1.
[0101] Reference below Figure 7, which shows a schematic diagram of the structure of a domain name verification device suitable for implementing embodiments of the present application. The domain name verification device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, personal digital assistants (PDAs), tablet computers (PADs), portable multimedia players (PMPs), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The domain name verification device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0102] like Figure 7 As shown, the domain name verification device may include a processing device 1001 (e.g., a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the domain name verification device. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems may be connected to I / O interface 1006: input device 1007, such as a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output device 1008, such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003, such as a magnetic tape or hard disk; and communication device 1009. The communication device 1009 can allow the domain name verification device to communicate with other devices wirelessly or wired to exchange data. Although the figure shows a domain name verification device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or have alternatively.
[0103] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0104] The domain name verification device provided in this application utilizes the domain name verification method described in the aforementioned embodiment to address the technical issue of low domain name verification reliability. Compared to the prior art, the domain name verification device provided in this application achieves the same beneficial effects as the domain name verification method described in the aforementioned embodiment. Other technical features of the domain name verification device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0105] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0106] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0107] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, and the computer-readable program instructions are used to execute the domain name verification method in the above-mentioned embodiment.
[0108] The computer-readable storage medium provided herein may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including, but not limited to, wires, optical cables, radio frequency (RF), etc., or any suitable combination thereof.
[0109] The computer-readable storage medium may be included in the domain name verification device; or it may exist independently without being assembled into the domain name verification device.
[0110] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the domain name verification device, the domain name verification device can: by analyzing multi-dimensional information such as domain name registration information, historical verification data, and DNS resolution records, more comprehensively assess the risk status of the domain name and the verification strategy corresponding to the domain name, dynamically select the optimal domain name verification service node and verification method based on the data processing results, and ensure the security and reliability of the verification process. The simultaneous verification of multiple nodes can effectively prevent misjudgments caused by single point failures or network attacks, thereby improving the reliability of domain name verification.
[0111] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0112] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0113] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0114] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned domain name verification method, thereby resolving the technical issue of low domain name verification reliability. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are similar to those of the domain name verification method provided in the aforementioned embodiments and are not further elaborated here.
[0115] The present application also provides a computer program product, comprising a computer program, which implements the steps of the domain name verification method as described above when executed by a processor.
[0116] The computer program product provided in this application can solve the technical problem of low reliability of domain name verification. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the domain name verification method provided in the above embodiment, and will not be repeated here.
[0117] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A domain name verification method, characterized in that: The domain name verification method includes: Determining a data processing result of the domain name based on the domain name related information, the domain name related information including at least one of domain name registration information, historical verification data, and DNS resolution records, the data processing result including a risk assessment result and a policy assessment result; Determine, based on the data processing result, a verification service node corresponding to the domain name and a domain name verification method, wherein the verification service node is used to execute the domain name verification method; Obtain a single-node verification result returned by each verification service node when executing the domain name verification method, and determine a target verification result of the domain name based on the single-node verification result.
2. The domain name verification method according to claim 1, wherein: The step of obtaining the single-node verification result returned by each verification service node executing the domain name verification method includes: Determine a target verification path according to the verification service node and the domain name verification method, where the target verification path is a path between the verification service node and a server corresponding to the domain name verification method; The single-node verification result is obtained based on the target verification path.
3. The domain name verification method according to claim 2, wherein: The step of determining a target verification path according to the verification service node and the domain name verification method includes: Determining a candidate verification path according to the verification service node and the domain name verification method; Obtaining a real-time network status of each candidate verification path, wherein the real-time network status includes at least one of bandwidth, delay, and packet loss rate; Determining a comprehensive score of each candidate verification path based on the real-time network status; Among the candidate verification paths, the target verification path corresponding to the domain name is determined according to the comprehensive score.
4. The domain name verification method according to claim 1, wherein: The verification service node is obtained through the following steps: Determine a candidate service node according to the data processing result; Obtaining a service indicator of each candidate service node, where the service indicator includes at least one of performance, reliability, and coverage; A verification service node is determined from the candidate service nodes according to the service indicator, attribute information of the domain name and user requirements, wherein the attribute information of the domain name includes geographical distribution and / or business type.
5. The domain name verification method according to claim 1, wherein: The domain name verification method is obtained through the following steps: Determining a dynamic verification level based on the user's security requirements and the data processing results; The authentication mode of the authentication service node is determined according to the dynamic authentication level.
6. The domain name verification method according to claim 5, wherein: The step of determining the verification mode of the verification service node according to the dynamic verification level includes: When the dynamic verification level is lower than the preset level threshold, the verification method of the first risk level is adopted; When the dynamic verification level is greater than or equal to the preset level threshold, a second risk level verification method is adopted, and the first risk level is lower than the second risk level.
7. The domain name verification method according to claim 1, wherein: The step of determining the data processing result of the domain name according to the domain name related information includes: Extracting key features of the domain name related information, the key features including at least one of domain name registration duration, DNS resolution stability, and historical verification success rate; Determining a weight parameter corresponding to the key feature, where the weight parameter is generated based on the degree of influence of the key feature on the domain name; The data processing result of the domain name is determined according to the key feature and the weight parameter.
8. The domain name verification method according to claim 1, wherein: The method further comprises: Determining the validity period of the domain name based on the frequency of changes in the domain name and the historical verification data; Determining the verification frequency of the domain name based on the validity period and importance of the domain name; Based on the verification frequency, the step of determining the data processing result of the domain name according to the domain name related information and related steps are performed.
9. A domain name verification device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the domain name verification method according to any one of claims 1 to 8.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the domain name verification method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Domain name data processing method and device, server and storage medium
CN113742783A
Phishing security verification method, system and device and storage medium
CN119094186A
Certificate issuing method, apparatus and system, storage medium, and computer program product
WO2025015988A1
Cited By
Terminal protection system and method for domain name hijacking prevention
CN121173551A