Method and device for evaluating query quality of encrypted DNS (Domain Name Server) server in mobile scene
By using DNS over UDP, DNS over HTTPS, and DNS over TLS protocols on mobile devices to assemble, send, and parse DNS query packets, the performance and security evaluation issues of encrypted DNS protocols in mobile scenarios are solved, and real-time monitoring and improvement of network reliability and security are achieved.
Patent Information
- Application Number
- CN202410240150.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-04
- Publication Date
- 2025-09-05
AI Technical Summary
In mobile scenarios, existing technologies are unable to effectively monitor and evaluate the performance and security of encrypted DNS protocols, resulting in the inability to timely improve the reliability and security of mobile Internet networks.
A method for evaluating the quality of encrypted DNS server queries in mobile scenarios was developed. Based on the Android platform, DNS query data packets were assembled and tested using the DNS over UDP, DNS over HTTPS, and DNS over TLS protocols. The test data was recorded and uploaded to a cloud server for real-time monitoring and evaluation.
It enables monitoring of the performance differences between unencrypted and encrypted DNS protocols on mobile devices, helping users choose the appropriate DNS protocol and improving network usage experience and security.
Smart Images

Figure CN120602365A_ABST
Abstract
Description
Technical Field
[0001] This patent application belongs to the field of mobile scenario monitoring and evaluation technology, and more specifically, relates to a method and device for evaluating the quality of encrypted DNS server queries in mobile scenarios. Background Art
[0002] The Domain Name System (DNS) is an important part of the Internet. It maps Internet Protocol (IP) addresses that are difficult to remember to domain names that are easy to remember, helping people access Internet services conveniently and quickly. A large number of network services rely on domain name services to operate.
[0003] DNS, DoH (DNS over HTTPS), and DoT (DNS over TLS) are three common protocols used to transmit domain name system queries and responses. When properly configured and used, they can improve network throughput and performance. Among them, DNS is the most commonly used protocol. Similar DNS measurement schemes are:
[0004] (1) DNS Jumper: Query the DNS records of a specific domain name and support querying multiple types of DNS records;
[0005] (2) DNS Benchmark: Tests multiple DNS servers to help users compare the performance of different DNS servers;
[0006] (3) DNSDetective: Helps users diagnose DNS problems on the network. It can detect the DNS records of a domain name, view the query time of a domain name, and check the availability of the DNS server.
[0007] Since data communication in the DNS protocol uses plain text communication, the security of the above-mentioned DNS-based measurement solution is difficult to guarantee.
[0008] Based on the DNS protocol, DoH and DoT encrypt plaintext data and use encrypted data for communication, ensuring the security of DNS protocol communication, but at the same time incurring performance losses. The DoH protocol encrypts DNS data based on the HTTPS protocol, while the DoT protocol encrypts DNS data based on the TLS protocol. HTTPS and TLS are both commonly used internet encrypted communication protocols.
[0009] However, due to the technical complexity of these protocols, existing DNS measurements in mobile scenarios do not support the use of encrypted DNS protocols such as DoT and DoH. They are also unable to extract deep information from the network during the test process, and cannot help users monitor and evaluate the performance differences between encrypted and unencrypted DNS protocols in real time.
[0010] Therefore, under the current circumstances, it is difficult for managers to accurately monitor and evaluate mobile users, and they are unable to promptly discover their performance and security issues in mobile scenarios, and thus are unable to promptly improve the reliability and security of mobile Internet networks. Summary of the Invention
[0011] The technical problem to be solved by the present invention is to provide a method and device for evaluating the quality of encrypted DNS server queries in mobile scenarios, which can measure the test data of unencrypted DNS protocols and encrypted DNS protocols during the communication process on mobile devices, and provide real-time monitoring for mobile users.
[0012] In order to solve the above problems, the technical solution adopted by the present invention is:
[0013] The encrypted DNS server query quality assessment method in mobile scenarios is based on the Android platform and is characterized by comprising the following steps:
[0014] S1. Assembling a DNS query data packet to be sent based on DNS query elements, where the DNS query elements include but are not limited to the DNS server address, the domain name to be queried, and the query type;
[0015] S2, using multiple different DNS protocols to send DNS query packets and receive DNS response packets;
[0016] S3, parse the DNS response data packet and record the test data;
[0017] S4. The test data is converted into a test file and uploaded to the cloud server.
[0018] Furthermore, in S1, the DNS server address includes the custom DNS server address and the default DNS server address. This is used to determine whether the user needs a custom DNS server. In S1, the DNS query data packet includes the following elements:
[0019] Transaction ID: The ID of the DNS message. The value of this field is the same for the request message and the corresponding response message. It can be used to distinguish which request the DNS response message responds to.
[0020] Flags: Flags field in the DNS message;
[0021] Question count: the number of DNS query requests;
[0022] Number of answer resource records: the number of DNS responses;
[0023] Authoritative name server count: the number of authoritative name servers, corresponding to the number of IP addresses;
[0024] Additional resource records: the number of additional records;
[0025] Query question area: contains three fields: query name, query type, and query class.
[0026] Query name: includes the domain name or IP address to be queried; usually it is the domain name to be queried, sometimes it is the IP address for reverse query;
[0027] Query type: The resource type requested by the DNS query, including A type and AAAA type. A type indicates that the corresponding IPv4 address is obtained from the domain name, and AAAA type indicates that the corresponding IPv6 address is obtained from the domain name. Usually the query type is A type;
[0028] Query type: Address type, which is an Internet address and has a value of 1.
[0029] Furthermore, in S1, the DNS query data packet also includes an answer area, an authoritative name server area, and an additional information area. The above three areas are all recorded in a resource record format, and the resource record format specifically includes:
[0030] Domain name: the domain name of the DNS request;
[0031] Type: The type of resource record, which is the same as the value of the query type in the query question area;
[0032] Class: Address type, same as the value of the query class in the query question area;
[0033] Time to Live: In seconds, it represents the life cycle of a resource record. It is generally used when the address resolution program determines the time to save and use cached data after retrieving the resource record. It can also indicate the stability of the resource record. The longer the time, the more stable the resource record.
[0034] Resource data length: the length of resource data;
[0035] Resource data: represents the data of related resource records returned according to the query segment requirements;
[0036] Furthermore, in S2, three different DNS protocols, DNS over UDP, DNS over HTTPS (DoH), and DNS over TLS (DoT), are used to test domain names. The sending processes of the three DNS protocols are as follows:
[0037] DNS over UDP protocol: Uses UDP protocol to send data to the DNS server. The data content is the constructed DNS data query packet.
[0038] DNS over HTTPS (DoH) protocol: uses the HTTPS protocol to send data to the DNS server. The DoH protocol can use both GET and POST methods. When using the POST method, the DNS query message is included in the message body of the HTTP request; when using the GET method, the only variable "dns" is assigned to the DNS data query packet encoded using base64url;
[0039] DNS over TLS (DoT) protocol: Uses the TLS protocol to establish a connection to the DNS server. This protocol is different from the DNS over UDP protocol and the DNS over HTTPS (DoH) protocol in sending data packets. The query packet of the DNS over TLS (DoT) protocol must add two bytes of data representing the length of the query packet to its header before sending the query packet; the response packet of the DNS over TLS (DoT) must first remove the two bytes of data representing the length of the response packet in the header before parsing the response packet.
[0040] Furthermore, in S3, when "recording corresponding test data", when using each DNS protocol, the relevant test data saved is as follows:
[0041] DNS server communication query time: Query Time;
[0042] DNS record lifetime: Time To Live;
[0043] DNS query IP result: IP Result;
[0044] Device current signal type: Signal;
[0045] The current signal strength of the device: Signal Strength;
[0046] The geographical location of the device: Location;
[0047] The speed of the device: Speed;
[0048] The default DNS server address of the network where the device is located: Default DNS Host;
[0049] Query time for communicating with the default DNS server: Default DNS Query Time.
[0050] Furthermore, when calculating the query time of DNS server communication, the method used is:
[0051] The DNS server is accessed multiple times, the average query time is calculated, and then all relevant test data from the test process is saved and uploaded to the cloud server. In the cloud, the response delay of the encrypted server is compared and analyzed with the response delay of the non-encrypted DNS server. The service quality of the encrypted DNS server is evaluated by comparing it with the service quality of the non-encrypted DNS server.
[0052] Furthermore, a device for evaluating the quality of encrypted DNS server queries in a mobile scenario is disclosed, which is used to implement the above method. The device includes:
[0053] A DNS query data packet assembly module, used to implement step S1;
[0054] A sending and receiving module, used to implement step S2;
[0055] DNS resolution module, used to implement step S3;
[0056] The summary upload module is used to implement step S4.
[0057] Due to the adoption of the above technical solution, the beneficial effects achieved by the present invention are:
[0058] This invention is developed based on the Android platform and supports DNS, DoT, and DoH protocols. At the same time, it can extract deep network information such as query time and packet loss rate during the mobile scene measurement process. It can help users monitor and evaluate the performance differences caused by using different DNS protocols, thereby helping users choose different DNS protocols and improve the network usage experience.
[0059] At the same time, the present invention also supports custom DNS servers, which can help users test and detect the performance indicators of communication requests made to different DNS servers with different DNS protocols, and help users choose appropriate DNS servers and DNS communication protocols. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 It is a system flow chart of the present invention.
[0061] Figure 2 This is a structural diagram of the DNS query data packet in the present invention.
[0062] Figure 3 This is a format diagram of the resource record format in the present invention. DETAILED DESCRIPTION
[0063] The present invention is further described in detail below with reference to the embodiments.
[0064] In view of the problems mentioned in the background, the problem that the present invention aims to solve is: the DNS encryption protocol can encrypt users' daily DNS traffic and effectively protect users' traffic information, but it also produces corresponding performance losses. The present invention provides real-time monitoring for mobile users by measuring the test data of the unencrypted DNS protocol and the encrypted DNS protocol during the communication process on mobile devices, which is used to evaluate and improve the performance and security of mobile Internet networks, thereby improving the reliability and security of mobile Internet networks. Through the present invention, mobile users can monitor and evaluate the performance indicators and connection delays of the unencrypted DNS protocol and the encrypted DNS protocol during the communication process in real time, thereby improving the security and reliability of mobile Internet networks.
[0065] A method for evaluating the quality of encrypted DNS server queries in a mobile scenario includes the following steps:
[0066] S1. Assemble the DNS query data packet to be sent based on the DNS query elements. The DNS query elements include but are not limited to the DNS server address, the domain name to be queried, and the query type. The DNS server address includes the custom DNS server address and the default DNS server address. This is used to determine whether the user needs a custom DNS server.
[0067] S2, using multiple different DNS protocols to send DNS query packets and receive DNS response packets;
[0068] S3, parse the DNS response data packet and record the test data;
[0069] S4. The test data is converted into a test file and uploaded to the cloud server.
[0070] The present invention is developed based on the Android platform, and the main test steps are: assembling DNS query data packets, using multiple different DNS protocols to send DNS query packets and receive DNS response data packets, parsing DNS response packets and recording corresponding test data.
[0071] The specific process is as follows Figure 1 After the program starts, it determines whether the user needs to customize the DNS server. If the user customizes the DNS server, the user needs to enter the DNS server address and perform the subsequent server domain name test. If the user uses the default DNS server for testing, the subsequent server domain name test is performed.
[0072] When testing a server domain name, you need to first determine whether the domain name to be tested has been tested. If the test is completed, the test data will be written to a file and the test file will be uploaded to the cloud server. If the domain name to be tested has not been tested, the corresponding thread will be created in the background according to the protocol:
[0073] Create a thread, use the DNS protocol to send DNS query requests to the server, and record relevant test data;
[0074] Create a thread, use the DoH protocol to send DNS query requests to the server, and record relevant test data;
[0075] Create a thread, use the DoT protocol to send DNS query requests to the server, and record relevant test data.
[0076] The above-mentioned relevant test data is written into the file and returns to the previous process until the test of the domain name to be tested is completed.
[0077] (1) Assembling DNS query data packets
[0078] First, construct a DNS query data packet as needed, including the necessary query information. According to the RFC1035 document, the structure of the DNS query data packet is as follows: Figure 2 As shown:
[0079] Transaction ID: This field is used to identify the DNS message ID. This field is the same for both the request message and the corresponding response message. This field allows you to distinguish which request the DNS response message is responding to.
[0080] Flags: Flags field in the DNS message.
[0081] Question Count: The number of DNS query requests.
[0082] Answer resource records: The number of DNS responses.
[0083] Authoritative Name Server Count: The number of authoritative name servers.
[0084] Additional resource records: The number of additional records (the number of IP addresses corresponding to the authoritative name servers).
[0085] Query Question section: This section contains three fields:
[0086] (1) Query name: usually the domain name to be queried, sometimes also the IP address, used for reverse query;
[0087] (2) Query type: The resource type requested by the DNS query. Usually the query type is A, which means obtaining the corresponding IPv4 address from the domain name, and AAAA, which means obtaining the corresponding IPv6 address from the domain name. Usually the query type is A.
[0088] Query type: Address type, usually an Internet address, with a value of 1.
[0089] Answer question zone field, authoritative name server zone field, additional information zone field. These three fields all use a format called resource record, the format is as follows Figure 3 shown.
[0090] Domain name: The domain name of the DNS request.
[0091] Type: The type of resource record, which is the same as the query type value in the question section.
[0092] Class: Address type, same as the query class value in the question section.
[0093] Lifetime: Measured in seconds, it represents the lifecycle of a resource record. It is generally used to determine how long to save and use cached data after the address resolution program retrieves the resource record. It also indicates the stability of the resource record. The longer the time, the more stable the resource record.
[0094] Resource data length: the length of the resource data.
[0095] Resource data: refers to the data of related resource records returned according to the query segment requirements.
[0096] In this step, the DNS query data packet to be sent is assembled according to information such as the DNS server address, the domain name to be queried, and the query type.
[0097] (2) Sending query packets and receiving DNS response packets
[0098] Use three different DNS protocols: DNS over UDP, DNS over HTTPS (DoH), and DNS over TLS (DoT) to send DNS query packets to the target DNS server, wait for the arrival of response packets, and receive DNS response packets.
[0099] The sending process of the three DNS protocols is as follows:
[0100] 1) DNS over UDP protocol: Use the UDP protocol to send data to the DNS server. The data content is the constructed DNS data query packet.
[0101] 2) DNS over HTTPS (DoH) protocol: This protocol uses the HTTPS protocol to send data to a DNS server. DoH can use both GET and POST methods. When using the POST method, the DNS query message is included in the message body of the HTTP request. When using the GET method, the unique variable "dns" is assigned the DNS query data packet encoded using base64 URL.
[0102] 3) DNS over TLS (DoT) protocol: Uses the TLS protocol to establish a connection to the DNS server. This protocol is different from the DNS over UDP protocol and the DNS over HTTPS (DoH) protocol in sending data packets. The query packet of the DNS over TLS (DoT) protocol must add two bytes of data representing the length of the query packet to its header before sending the query packet; the response packet of the DNS over TLS (DoT) protocol must first remove the two bytes of data representing the length of the response packet in the header before parsing the response packet.
[0103] (3) Parse the DNS corresponding package and record the corresponding test data
[0104] During the period from the start of sending the DNS query data packet to the completion of receiving the DNS response data packet, the network communication related test information is recorded.
[0105] Finally, according to the received DNS response data packet, the corresponding data is parsed and the parsed related records are saved.
[0106] When recording the corresponding test data, when using each DNS protocol, the relevant data saved is as follows:
[0107] 1) DNS server communication query time: Query Time;
[0108] 2) DNS record lifetime: Time To Live;
[0109] 3) IP result of DNS query: IP Result;
[0110] 4) Device current signal type: Signal;
[0111] 5) Current signal strength of the device: Signal Strength;
[0112] 6) Geographic location of the device: Location;
[0113] 7) Device movement speed: Speed;
[0114] 8) The default DNS server address of the network where the device is located: Default DNS Host;
[0115] 9) Query time for communicating with the default DNS server: Default DNS Query Time.
[0116] Query time is calculated by accessing the DNS server multiple times and calculating the average query time. All relevant test data is then saved and uploaded to a cloud server. In the cloud, the response latency of the encrypted server is compared and analyzed with that of the non-encrypted DNS server. The service quality of the encrypted DNS server is evaluated by comparing it with the non-encrypted DNS server.
[0117] In addition, the present invention also discloses a device for evaluating the quality of encrypted DNS server queries in a mobile scenario, which is used to implement the above method and is characterized by comprising:
[0118] The DNS query data packet assembly module is used to assemble the DNS query data packet to be sent according to the DNS query elements. The DNS query elements include but are not limited to the DNS server address, the domain name to be queried, and the query type.
[0119] The sending and receiving modules are used to send DNS query packets and receive DNS response packets using a variety of different DNS protocols. These can be three different DNS protocols: DNS, DoH, and DoT.
[0120] DNS parsing module, used to parse DNS response data packets and record test data.
[0121] The summary upload module is used to form test files from test data and upload them to the cloud server.
[0122] For example, in the cloud, the response delay of the encrypted server will be compared and analyzed with the response delay of the non-encrypted DNS server. When evaluating the service quality of the encrypted DNS server by comparing it with the service quality of the non-encrypted DNS server, Python language will be used for data analysis. The control variable method will be used to analyze and compare indicators such as the response delay of the encrypted server and the non-encrypted server, and then a CDF graph and histogram will be drawn to display them.
[0123] In summary, the present invention can utilize mobile devices to communicate with different DNS servers using different DNS protocols, helping users to comprehensively detect the performance differences between different DNS solutions in mobile scenarios and helping mobile users choose the optimal encrypted DNS solution.
Claims
1. The quality assessment method of encrypted DNS server query in mobile scenarios, based on the Android platform, is characterized by The steps include: S1. Assembling a DNS query data packet to be sent based on DNS query elements, where the DNS query elements include but are not limited to the DNS server address, the domain name to be queried, and the query type; S2, using multiple different DNS protocols to send DNS query packets and receive DNS response packets; S3, parse the DNS response data packet and record the test data; S4. The test data is converted into a test file and uploaded to the cloud server.
2. The method for evaluating the quality of encrypted DNS server queries in mobile scenarios according to claim 1, wherein: In S1, the DNS server address includes the custom DNS server address and the default DNS server address.
3. The method for evaluating the quality of encrypted DNS server queries in mobile scenarios according to claim 1, wherein: In S1, the DNS query packet includes the following elements: Transaction ID: the ID of the DNS message; Flags: Flags field in the DNS message; Question count: the number of DNS query requests; Number of answer resource records: the number of DNS responses; Authoritative name server count: the number of authoritative name servers, corresponding to the number of IP addresses; Additional resource records: the number of additional records; Query question area: contains three fields: query name, query type, and query class. Query name: includes the domain name or IP address to be queried; Usually the domain name to be queried, sometimes it is an IP address for reverse query; Query type: The resource type of the DNS query request, including A type and AAAA type. A type indicates that the corresponding IPv4 address is obtained from the domain name, and AAAA type indicates that the corresponding IPv6 address is obtained from the domain name. Query type: Address type, which is an Internet address and has a value of 1.
4. The method for evaluating the quality of encrypted DNS server queries in mobile scenarios according to claim 3, wherein: In S1, the DNS query data packet also includes an answer area, an authoritative name server area, and an additional information area. The above three areas are all recorded in the resource record format. The resource record format specifically includes: Domain name: the domain name of the DNS request; Type: The type of resource record, which is the same as the value of the query type in the query question area; Class: Address type, same as the value of the query class in the query question area; Lifetime: In seconds, it indicates the life cycle of the resource record; Resource data length: the length of resource data; Resource data: refers to the data of related resource records returned according to the query segment requirements.
5. The method for evaluating the quality of encrypted DNS server queries in mobile scenarios according to claim 1, wherein: In S2, three different DNS protocols, DNS over UDP, DNS over HTTPS, and DNS over TLS, are used to test domain names. The sending processes of the three different DNS protocols are as follows: DNS over UDP protocol: Uses UDP protocol to send data to the DNS server. The data content is the constructed DNS data query packet. DNS over HTTPS protocol: Use the HTTPS protocol to send data to the DNS server. This protocol can use both GET and POST methods. When using the POST method, the DNS query message is included in the message body of the HTTP request; when using the GET method, the only variable "dns" is assigned to the DNS data query packet encoded using base64url. DNS over TLS protocol: Uses the TLS protocol to establish a connection to the DNS server. This protocol is different from the DNS over UDP protocol and the DNS over HTTPS protocol in sending data packets. The query packet of the DNS over TLS protocol must add two bytes of data representing the query packet length to its header before sending the query packet. The DNS over TLS response packet must first remove the two bytes representing the response packet length in the header before parsing the response packet.
6. The method for evaluating the quality of encrypted DNS server queries in mobile scenarios according to claim 1, wherein: In S3, when "Record corresponding test data" is selected, the relevant test data saved when using each DNS protocol is as follows: DNS server communication query time: Query Time; DNS record lifetime: Time To Live; DNS query IP result: IP Result; Device current signal type: Signal; The current signal strength of the device: Signal Strength; The geographical location of the device: Location; The speed of the device: Speed; The default DNS server address of the network where the device is located: Default DNS Host; Query time for communicating with the default DNS server: Default DNS Query Time.
7. The method for evaluating the quality of encrypted DNS server queries in mobile scenarios according to claim 6, wherein: The query time for DNS server communication is calculated using the following method: The DNS server is accessed multiple times, the average query time is calculated, and then all relevant test data from the test process is saved and uploaded to the cloud server. In the cloud, the response delay of the encrypted server is compared and analyzed with the response delay of the non-encrypted DNS server. The service quality of the encrypted DNS server is evaluated by comparing it with the service quality of the non-encrypted DNS server.
8. A device for evaluating the quality of encrypted DNS server queries in a mobile scenario, for implementing the method according to any one of claims 1 to 7, characterized in that include: A DNS query data packet assembly module, used to implement step S1; A sending and receiving module, used to implement step S2; DNS resolution module, used to implement step S3; The summary upload module is used to implement step S4.