Verification information generation method and related device

By jointly signing the RPKI resource certificate and DNSSEC key of the target domain name to generate a joint certificate, and caching it in the recursive server, the problem of poor compatibility between DNSSEC and RPKI is solved, thereby improving security and efficiency and enhancing the defense capabilities of the domain name system.

CN121333688APending Publication Date: 2026-01-13CHINA INTERNET NETWORK INFORMATION CENTER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511488778.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-17
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

The poor compatibility between DNSSEC and RPKI leads to low verification efficiency, an inability to effectively defend against cross-layer attacks, and a lack of unified and trusted guarantees for the mapping relationship between domain names and IP addresses.

Method used

By jointly signing the RPKI resource certificate and DNSSEC key of the target domain name, a combined certificate is generated, and the verified combined certificate is cached in the recursive server, thus realizing the binding of trusted information between the routing layer and the domain name resolution layer.

Benefits of technology

It improves the security and reliability of domain name queries, avoids the performance overhead caused by repeated chained verification, enhances verification efficiency and security, and strengthens the domain name system's ability to resist route hijacking and DNS cache poisoning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333688A_ABST
    Figure CN121333688A_ABST
Patent Text Reader

Abstract

The invention discloses a verification information generation method and a related device, and the method achieves the credible information binding of a routing layer and a domain name resolution layer through the joint signature of an RPKI resource certificate of a target domain name and a DNSSEC key and the generation of a joint certificate. Therefore, the problems that in the prior art, RPKI and DNSSEC are independently verified, so that cross-layer attacks cannot be effectively defended, and the mapping relation between the domain name and the IP address lacks unified credible guarantee are solved. The verified joint certificate is cached in the recursive server, so that the verification result can be ensured to have IP address attribution legality and domain name ownership authenticity at the same time, the security and credibility of domain name query are remarkably improved, performance consumption caused by repeated chain verification is avoided, and the efficiency of domain name query is improved. The verification results of the two verification links are displayed through one joint certificate, so that the security and the efficiency are improved together, and an effective technical support is provided for enhancing the domain name system to resist routing hijacking and DNS cache poisoning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method and apparatus for generating verification information. Background Technology

[0002] With the continuous development of internet technology, the digital economy is developing rapidly. The Domain Name System (DNS) and routing systems, as core components of internet infrastructure, play a vital supporting role in the current and future development of the digital economy, forming the cornerstone of my country's information society. However, they also face multiple security threats due to design flaws and protocol vulnerabilities.

[0003] Currently, Domain Name System Security Extensions (DNSSEC) serves as a key protection measure, effectively enhancing the security level of the DNS system. Resource Public Key Infrastructure (RPKI) technology is a widely recognized and implemented security technology in the industry, and is currently the most likely mechanism for enhancing routing security to be widely adopted.

[0004] However, despite the gradual promotion of protection technologies such as DNSSEC and RPKI, the poor compatibility between the two still restricts the improvement of the overall security level, and the verification efficiency is low due to the need for multi-path verification. Summary of the Invention

[0005] To address the aforementioned issues, this application provides a method and related apparatus for generating verification information, which improves the compatibility of DNSSEC and RPKI and enhances verification efficiency.

[0006] Based on this, the following technical solution is disclosed in this application:

[0007] In a first aspect, embodiments of this application provide a method for generating verification information, the method comprising:

[0008] Obtain the Domain Name System Security Extension (RPKI) resource certificate and the DNSSEC key of the target domain name. The RPKI resource certificate is used to identify the Internet Protocol (IP) address ownership of the target domain name, and the DNSSEC key is used to identify the domain name ownership of the target domain name.

[0009] The RPKI resource certificate of the target domain name and the DNESEC key of the target domain name are jointly signed to generate a joint certificate for the target domain name;

[0010] If the RPKI resource certificate and the DNESEC key of the target domain are verified, the combined certificate of the target domain is stored in the cache of the recursive server so as to provide verification information for query requests for the target domain.

[0011] Optionally, if the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name pass verification, the combined certificate of the target domain name is stored in the cache corresponding to the recursive server, including:

[0012] The RPKI resource certificate chain is verified based on the RPKI resource certificate of the target domain name, and the DNSSEC signature chain is verified based on the DNSSEC key of the target domain name to obtain the verification result for the federated certificate.

[0013] Determine the target membership degree corresponding to the verification result, wherein the target membership degree is used to reflect the degree of deviation between the verification result and the ideal result;

[0014] Based on the target membership, a target response strategy is determined from multiple pending response strategies, and the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name are verified through the target response strategy. The pending response strategy is used to adjust the verification method.

[0015] If the RPKI resource certificate and the DNESEC key of the target domain name are verified, the combined certificate of the target domain name is stored in the cache corresponding to the recursive server.

[0016] Optionally, determining the target response strategy from multiple pending response strategies based on the target membership degree includes:

[0017] If the deviation of the target membership degree indicator is less than or equal to the first threshold, then log it.

[0018] If the deviation of the target membership degree indicator is greater than the first threshold and less than or equal to the second threshold, then a secondary verification is triggered, wherein the second threshold is greater than the first threshold;

[0019] If the deviation of the target membership indicator is greater than the second threshold, the cache corresponding to the recursive server is isolated and an alarm message is generated.

[0020] Optionally, the method further includes:

[0021] The RPKI resource certificate chain is verified based on the RPKI resource certificate of the target domain name to obtain a first verification score. The first verification score is used to indicate the verification progress of the RPKI resource certificate chain.

[0022] The DNSSEC signature chain is verified based on the DNESEC key of the target domain name to obtain a second verification score, which is used to indicate the verification progress of the DNSSEC signature chain.

[0023] Based on the first verification score and the second verification score, determine the first weight and the second weight;

[0024] Based on the first weight and the second weight, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

[0025] Optionally, the method further includes:

[0026] Obtain network status information, which includes a first network quality indicator for the verification node in the RPKI resource certificate chain and a second network quality indicator for the verification node in the DNSSEC signature chain.

[0027] Based on the network state information, the first weight and the second weight are corrected to obtain the first corrected weight and the second corrected weight.

[0028] Based on the first correction weight and the second correction weight, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

[0029] Optionally, the combined certificate for the target domain name includes the RPKI resource certificate, the DNSSEC public key, the RIR issuance signature, the domain registry signature, and the certificate validity period.

[0030] Secondly, embodiments of this application provide a verification information generation apparatus, the apparatus comprising:

[0031] The acquisition unit is used to acquire the Domain Name System Security Extension (RPKI) resource certificate of the target domain name and the DNSSEC key of the target domain name. The RPKI resource certificate is used to identify the Internet Protocol IP address ownership of the target domain name, and the DNSSEC key is used to identify the domain name ownership of the target domain name.

[0032] The verification unit is used to jointly sign the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name to generate a joint certificate for the target domain name;

[0033] The storage unit is configured to store the combined certificate of the target domain name in the cache corresponding to the recursive server if the RPKI resource certificate and the DNESEC key of the target domain name are verified, so as to provide verification information for query requests for the target domain name.

[0034] Thirdly, embodiments of this application provide a computer device, the computer device including a processor and a memory:

[0035] The memory is used to store computer programs and to transfer the computer programs to the processor;

[0036] The processor is configured to execute the method described in the first aspect above according to the computer program.

[0037] Fourthly, embodiments of this application provide a computer-readable storage medium for storing a computer program for performing the method described in the first aspect above.

[0038] Fifthly, embodiments of this application provide a computer program product including a computer program, which, when run on a computer device, causes the computer device to perform the method described in the first aspect above.

[0039] As can be seen from the above technical solutions, this application has at least the following beneficial effects:

[0040] By jointly signing the RPKI resource certificate and DNSSEC key of the target domain name to generate a combined certificate, trusted information binding between the routing layer and the domain name resolution layer is achieved. This solves the problems in existing technologies where independent verification by RPKI and DNSSEC leads to ineffective defense against cross-layer attacks and a lack of unified trusted assurance for the mapping relationship between domain names and IP addresses. By caching the verified combined certificate in the recursive server, not only can the verification result be ensured to simultaneously possess the legitimacy of IP address ownership and the authenticity of domain name ownership, significantly improving the security and trustworthiness of domain name queries, but it also avoids the performance overhead caused by repeated chain verification. That is, by displaying the verification results of two verification chains through a single combined certificate, both security and efficiency are improved, providing effective technical support for enhancing the domain name system's resistance to route hijacking and DNS cache poisoning. Attached Figure Description

[0041] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 A flowchart illustrating a verification information generation method provided in an embodiment of this application;

[0043] Figure 2 A diagram illustrating a joint authentication model architecture is provided for an embodiment of this application.

[0044] Figure 3 This is a flowchart illustrating a resource binding layer provided in an embodiment of this application.

[0045] Figure 4 This application provides a schematic flowchart of a joint verification layer.

[0046] Figure 5 This is a flowchart illustrating a dynamic strategy layer provided in an embodiment of this application;

[0047] Figure 6 This is a schematic diagram illustrating an application scenario of a verification information generation method provided in an embodiment of this application.

[0048] Figure 7 This is a schematic diagram of the structure of a verification information generation device provided in an embodiment of this application;

[0049] Figure 8 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0050] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.

[0051] The DNS protocol, in its early design, lacked a security verification mechanism, making it a prime target for attackers. For example, DNS hijacking can redirect users to phishing websites by tampering with resolution results. DNS cache poisoning can pollute local resolution records to expand the attack surface. Distributed Denial of Service (DDoS) attacks can use massive query requests to paralyze authoritative servers. Currently, DNSSEC, a security extension of the Domain Name System, serves as a key protection measure, effectively improving the security level of the DNS system. Routing systems rely on network layer protocols to dynamically select data packet transmission paths; their core value lies in ensuring the flexibility and efficiency of network topology and communication. The global internet relies on the Border Gateway Protocol (BGP) to exchange routing information across autonomous systems, but the BGP protocol, based on a trust model, lacks verification of the authenticity of route advertisements, leading to frequent route hijacking incidents. Currently, RPKI technology is a widely recognized and implemented security technology, and is the most likely mechanism for enhancing routing security to be widely adopted at present. Although protection technologies such as DNSSEC and RPKI have been gradually promoted, their poor compatibility still restricts the overall improvement of security levels. In addition, DNSSEC and RPKI perform verification based on their own independent trust chains. DNSSEC needs to verify the multi-level signature chain from the root zone to the target domain name in sequence, while RPKI needs to verify the resource certificate chain step by step. When the two are used together, they must complete the complete verification process of the two verification chains before the final verification result can be obtained. This not only increases the verification latency and computational overhead, but also leads to low overall verification efficiency.

[0052] Based on this, this application provides a verification result generation method and related apparatus. By jointly signing the RPKI resource certificate and DNSSEC key of the target domain name and generating a joint certificate, the trusted information binding between the routing layer and the domain name resolution layer is realized. This solves the problems in the prior art where independent verification by RPKI and DNSSEC leads to ineffective defense against cross-layer attacks and a lack of unified trusted protection for the mapping relationship between domain names and IP addresses. By caching the verified joint certificate in the recursive server, not only can the verification result be ensured to simultaneously possess the legitimacy of IP address ownership and the authenticity of domain name ownership, significantly improving the security and trustworthiness of domain name queries, but it also avoids the performance overhead caused by repeated chain verification. That is, by displaying the verification results of two verification links through a single joint certificate, both security and efficiency are improved, providing effective technical support for enhancing the domain name system's resistance to route hijacking and DNS cache poisoning.

[0053] The verification information generation method provided in this application can be applied to computer devices capable of generating verification information, such as terminal devices and servers. Specifically, terminal devices can be desktop computers, laptops, mobile phones, and tablets; servers can be independent physical servers, server clusters composed of multiple physical servers, or distributed systems. Terminal devices and servers can be directly or indirectly connected via wired or wireless communication, and this application does not impose any restrictions on this connection.

[0054] All data collected in this application (such as RPKI resource certificates and DNESEC keys) are collected with the consent and authorization of the data subject (such as users, organizations, or enterprises), and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.

[0055] See Figure 1 This figure is a schematic flowchart of the verification information generation method provided in an embodiment of this application. For ease of description, the following embodiment uses a server as the execution subject of the verification information generation method. Figure 1 As shown, the verification information generation method includes S101-S103.

[0056] S101: Obtain the Domain Name System Security Extension (RPKI) resource certificate and the Domain Name System Security Extension (DNESEC) key for the target domain.

[0057] The target domain name is a specific type of domain name. The RPKI resource certificate identifies the Internet Protocol (IP) address of the target domain name, and the DNSSEC key identifies the domain name ownership. These are explained in detail below.

[0058] An RPKI (Resource Public Key Infrastructure) certificate is a digital certificate used to verify the legitimacy of network routing information. It proves which Autonomous System (AS) a given IP address or IP prefix belongs to. In other words, an RPKI certificate indicates who should use or announce a particular IP address, thus preventing malicious or erroneous route announcements. For example, if an IP address should belong to AS A but is incorrectly announced by someone else through the routing system, an RPKI certificate can identify and prevent this route hijacking.

[0059] A DNSSEC key (Domain Name System Security Extensions Key) is a key used by DNSSEC to digitally sign domain name resolution records, proving that the data corresponding to a domain name has not been tampered with. It demonstrates the ownership of the domain and the authenticity of the DNS resolution results. For example, when a user visits www.example.com, the DNSSEC key can be used to verify that the returned IP address resolution result indeed comes from a trusted domain owner, and not a fake address forged by an attacker.

[0060] S102: Jointly sign the RPKI resource certificate of the target domain and the DNESEC key of the target domain to generate a joint certificate for the target domain.

[0061] Joint signature is a method of integrating multiple independent digital signature information into a single security credential. In the application embodiment, the same certificate can be signed by a trusted authority of the routing system (such as a RIR) and a domain name system authority (such as a domain name registry), thereby making the certificate trusted by both the routing system and the DNS system.

[0062] The Joint Certificate (JC) proposed in this application is a novel certificate format that integrates information from RPKI resource certificates and DNSSEC keys, and includes dual signatures. The Joint Certificate not only proves that the IP address corresponding to the domain name has legitimate network resource ownership, but also proves that the ownership of the domain name is genuine and trustworthy. This allows the recursive server to simultaneously verify the trustworthiness of the route and the authenticity of the domain name based on a single Joint Certificate when a user accesses the target domain name. This avoids the overhead of multiple verifications caused by separately executing the RPKI resource certificate chain and the DNSSEC signature chain in existing technologies. It not only improves the security and integrity of the verification process but also significantly reduces the latency and efficiency of the verification process, providing support for fast and secure domain name resolution.

[0063] As one possible implementation, federated certificates can be signed using the Elliptic Curve Digital Signature Algorithm (ECDSA).

[0064] In one possible implementation, the combined certificate for the target domain name includes an RPKI resource certificate, a DNSSEC public key, an RIR issuance signature, a domain registry signature, and a certificate validity period.

[0065] For example, the format of a federated certificate is as follows:

[0066] JointCertificate ::= SEQUENCE {

[0067] rpkiCert RPKICertificate,

[0068] dnssecKey DNSKEY,

[0069] dualSignature SEQUENCE {

[0070] rirSig BIT STRING,

[0071] registrarSig BIT STRING

[0072] },

[0073] validity ValidityPeriod

[0074] }

[0075] Among them, rpkiCert is the RPKI resource certificate (which may include IP prefix and ASN), dnssecKey is the DNSSEC public key, rirSig is the RIR issuance signature, registrarSig is the domain registry signature, and validity is the certificate validity period.

[0076] S103: If the RPKI resource certificate and the DNESEC key of the target domain are verified, the combined certificate of the target domain is stored in the cache of the recursive server so as to provide verification information for query requests for the target domain.

[0077] A recursive server is a query processing node in the DNS resolution system. It receives domain name resolution requests initiated by users and queries the root server, top-level domain server, and authoritative server in sequence, and finally returns the resolution result to the user. The resolution result may include verification information for the domain name (such as a federated certificate).

[0078] The cache is an area within the recursive server used to store parsing results or verification data, accelerating the processing of subsequent identical query requests and reducing redundant queries and calculations. In this embodiment, the cache is used to store verified federated certificates.

[0079] The server can verify the IP address ownership of the target domain name by accessing the RPKI system associated with it. For example, it can check whether 203.0.113.5 is owned by a legitimate network operator (such as AS12345). If the RPKI verification passes, it means that the IP address ownership is legitimate. The recursive server verifies the ownership of the target domain name (such as example.com) through DNSSEC and verifies the signature records of the domain name resolution.

[0080] The server can use the DNSSEC public key to verify the DNS records (such as A records, MX records, etc.) of the domain name to ensure that they have not been tampered with. If the DNSSEC verification passes, it means that the domain name resolution result is genuine and reliable.

[0081] like Figure 2 As shown in the embodiments of this application, a federated authentication model is also proposed, including a resource binding layer, a federated verification layer, and a dynamic policy layer. The resource binding layer implements federated authentication of RPKI resource certificates and DNSSEC signatures, the federated verification layer verifies the JC certificate generated by the resource binding layer, and the dynamic policy layer implements real-time blocking of cross-layer attacks. If a high risk is detected, temporary cache isolation or cross-layer alarm linkage is triggered.

[0082] like Figure 3 As shown below, the working principle of the resource binding layer is explained:

[0083] 1. Obtain the authoritative server route source signature record (RPKI resource certificate) from the RPKI database through the route information signature acquisition module.

[0084] 2. Obtain DNSSEC signature records (DNSSEC signatures) from the Domain Name System (domain root servers, top-level domain authoritative servers) through the DNSSEC signature acquisition module.

[0085] 3. Generate a joint verification certificate by routing source signature records and DNSSEC signature records through the signature module.

[0086] Fourth, store the generated joint verification certificate through the certificate storage module.

[0087] As can be seen from the above technical solution, by jointly signing the RPKI resource certificate and DNSSEC key of the target domain name and generating a combined certificate, trusted information binding between the routing layer and the domain name resolution layer is achieved. This solves the problems in existing technologies where independent verification by RPKI and DNSSEC leads to ineffective defense against cross-layer attacks and a lack of unified trusted assurance for the mapping relationship between domain names and IP addresses. By caching the verified combined certificate in the recursive server, not only can the verification result be ensured to simultaneously possess the legitimacy of IP address ownership and the authenticity of domain name ownership, significantly improving the security and trustworthiness of domain name queries, but it also avoids the performance overhead caused by repeated chain verification. That is, by displaying the verification results of two verification chains through a single combined certificate, both security and efficiency are improved, providing effective technical support for enhancing the domain name system's resistance to route hijacking and DNS cache poisoning.

[0088] In one possible implementation, the nodes corresponding to the RPKI resource certificate chain are verified based on the target domain's RPKI resource certificate, and the nodes corresponding to the DNSSEC signature chain are verified based on the target domain's DNSSEC key, resulting in a verification result for the federated certificate. Then, the target membership degree corresponding to the verification result is determined. Based on the target membership degree, a target response policy is determined from multiple pending response policies, and the target response policy is used to verify the target domain's RPKI resource certificate and target domain's DNSSEC key. The pending response policy is used to adjust the verification method. If the target domain's RPKI resource certificate and target domain's DNSSEC key pass verification, the federated certificate of the target domain is stored in the cache corresponding to the recursive server.

[0089] In the verification process of RPKI and DNSSEC, verification does not only look at the trustworthiness of a single resource certificate or a single signature, but requires verification along a hierarchical verification chain. For example, DNSSEC verifies from the root zone (.) to the top-level domain (e.g., .cn), and then to the specific domain name (e.g., example.cn). RPKI, on the other hand, needs to verify certificates from the Regional Internet Registry (RIR) down to the local network operator.

[0090] The RPKI resource certificate chain is a verification chain that inherits from resource certificates issued by higher-level authorities (such as APNIC or the China Internet Network Information Center) and ultimately points to the IP address resources owned by a certain Autonomous System (AS). Each level needs to verify the validity of the signature to ensure that the IP address ownership is genuine and trustworthy.

[0091] The DNSSEC signature chain ensures that domain name resolution records have not been tampered with. It verifies the signature records of top-level domain servers (such as .cn) and then to specific authoritative DNS servers from the root server, thereby realizing the verification of domain name legitimacy.

[0092] Membership degree, derived from extension cloud theory, is a metric used to measure the degree of deviation of a system's state from its normal state. Membership degree values ​​typically range from 0 to 1. For example, a membership degree closer to 1 indicates a more reliable verification result, while a membership degree closer to 0 suggests potential anomalies or attacks. In this embodiment, the target membership degree reflects the degree of deviation between the verification result and the ideal result. The ideal result can be an empirical value determined based on historical data, or it can refer to the complete verification of the RPKI resource certificate chain and DNSSEC signature chain corresponding to the target domain name, the trustworthiness of all nodes in the verification path, and the absence of any abnormal risks, thus indicating that the correspondence between the target domain name and its corresponding IP address is secure, reliable, and has not been tampered with.

[0093] A pending response strategy is a set of optional security policies used during joint verification to determine how to proceed with the verification process when risks, uncertainties, or deviations from ideal conditions are found in the verification results. Pending response strategies are not fixed in execution; instead, the most suitable response method is dynamically selected based on the target's membership degree. The target response strategy is at least one of the multiple pending response strategies corresponding to the target's membership degree.

[0094] Therefore, by introducing a membership-driven dynamic verification mechanism, not only can the joint verification of the RPKI resource certificate chain and the DNSSEC signature chain be completed, but the verification strategy can also be dynamically adjusted according to the actual verification results during the verification process. This effectively improves the system's ability to identify abnormal domain name resolution behavior and its attack protection capabilities. Compared with the existing technology that only performs single verification based on fixed rules, this method calculates the target membership degree of the verification result to achieve a quantitative assessment of the verification credibility. Furthermore, it flexibly selects the target response strategy based on multiple pending response strategies, making the verification process adaptive and capable of differentiated responses, thus improving the verification processing capabilities in high-concurrency resolution scenarios.

[0095] In one possible implementation, if the deviation of the target membership indicator is less than or equal to a first threshold, a log is recorded. If the deviation of the target membership indicator is greater than the first threshold but less than or equal to a second threshold, secondary verification is triggered, where the second threshold is greater than the first threshold. If the deviation of the target membership indicator is greater than the second threshold, the cache corresponding to the recursive server is isolated, and an alarm message is generated.

[0096] The first threshold and the second threshold are two benchmark values ​​used to determine the risk level. The first threshold is used to identify minor risks, and the second threshold is used to identify severe risks.

[0097] As one possible implementation, during the process of triggering secondary verification, the server will perform a more stringent verification process again, such as re-verifying the RPKI certificate chain or DNSSEC signature chain, or performing cross-verification to confirm authenticity.

[0098] Cache isolation is used to indicate that potentially corrupted federated certificate caches in the current recursive server should be isolated separately and no longer used for subsequent queries, in order to prevent the spread of abnormal verification results and ensure the overall security of the system.

[0099] Therefore, by introducing a hierarchical response mechanism based on target membership, the verification results of different risk levels can be processed differently during the joint verification process, achieving a dynamic balance between security and availability. Specifically, when the target membership deviation is low, only logs are recorded to avoid impacting normal business operations. When the target membership is in the medium-risk range, secondary verification is triggered to improve the rigor of the verification and prevent potential attacks from bypassing the initial verification. When the target membership deviation exceeds the high-risk threshold, cache isolation is immediately implemented and alarm information is generated, thus blocking risky links in the early stages of an attack. Compared to traditional static single verification strategies, this hierarchical response mechanism can automatically adjust the verification strategy according to risk, achieving precise defense against complex attack behaviors such as cache poisoning and route hijacking, significantly improving the system's security robustness and anomaly self-recovery capabilities.

[0100] In one possible implementation, each node in the RPKI resource certificate chain can be verified based on the RPKI resource certificate of the target domain name to obtain a first verification score, which is used to indicate the verification progress of the RPKI resource certificate chain.

[0101] The DNSSEC signature chain is verified using the DNESEC key of the target domain name to obtain a second verification score, which is used to indicate the verification progress of the DNSSEC signature chain.

[0102] The first weight and the second weight are determined based on the first verification score and the second verification score.

[0103] Based on the first and second weights, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

[0104] In other words, higher weights can be assigned to verification chains with slower verification progress, thereby allocating more verification computing resources.

[0105] Therefore, the computational resources for the two verification processes can be adaptively scheduled based on the real-time verification progress of the RPKI resource certificate chain and the DNSSEC signature chain, avoiding the problem of verification delays or wasted computational resources in a certain verification chain due to fixed resource allocation. By determining the first weight and second weight based on the first verification score and the second verification score respectively, and dynamically adjusting resource allocation accordingly, not only is the execution efficiency of joint verification improved and the overall verification latency shortened, but performance bottlenecks that may occur during the verification process are also avoided. This ensures the integrity of verification while improving the system's throughput and high-concurrency processing performance.

[0106] In one possible implementation, network state information can be obtained. Based on the network state information, the first weight and the second weight are adjusted to obtain a first adjusted weight and a second adjusted weight. Based on the first adjusted weight and the second adjusted weight, the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain are adjusted.

[0107] Network status information is a data set describing the current network operating status and reflecting network transmission quality. It typically includes metrics such as delay, packet loss rate, bandwidth availability, and jitter. Network status information includes a first network quality metric for verification nodes in the RPKI resource certificate chain and a second network quality metric for verification nodes in the DNSSEC signature chain.

[0108] The first network quality metric could be the link quality during RPKI authentication when communicating with the RPKI certificate store or RIR server. The second network quality metric could be the link quality during DNSSEC authentication when communicating with the DNS authority server.

[0109] The first corrected weight is the weight obtained after correcting the first weight, and the second corrected weight is the weight obtained after correcting the second weight.

[0110] In other words, the lag in verification progress may be due to poor network conditions. In this case, it is not necessary to allocate more verification resources to meet the needs of verification progress. The weights can be adjusted according to the network condition information to match the actual network condition and improve the adaptability of the allocation of verification computing resources to the actual network condition.

[0111] In one possible implementation, the verification result can be determined in the following way:

[0112] The system obtains the number of nodes that passed the RPKI resource certificate chain and the number of nodes that passed the DNSSEC signature chain, and determines the third verification score for the RPKI resource certificate chain and the fourth verification score for the DNSSEC signature chain, respectively. The verification result is determined based on these scores. A higher number of passing nodes results in a higher verification score. A third verification score exceeding a third threshold indicates a successful verification chain, and a fourth verification score exceeding a fourth threshold indicates a successful verification chain. The third and fourth verification scores can be adaptively adjusted based on network status information to improve the robustness of the verification. For example, when the network status information indicates a poor network condition, the threshold for the corresponding verification chain is lowered.

[0113] like Figure 4As shown, the working principle of the aforementioned joint verification layer is as follows:

[0114] The joint verification layer performs parallel verification of RPKI and DNSSEC, and dynamically adjusts the weights based on network status. The verification results are then passed to the dynamic policy layer for threat analysis and subsequent operations. This dynamic weight adjustment achieves three-dimensional coordination of Resource Authentication (RPKI), Authentication (DNSSEC), and network status awareness.

[0115] 1. Verify the RPKI certificate chain and DNSSEC signature chain in parallel using a lightweight verification protocol.

[0116] 2. Domain name queries are scored using a dynamic weighting algorithm, including the verification score of the RPKI certificate chain, the verification score of the DNSSEC signature chain, and the network score.

[0117] 3. Pass the verification results to the dynamic strategy layer via REST API.

[0118] like Figure 5 As shown, the working principle of the aforementioned dynamic strategy layer for volume is as follows:

[0119] The dynamic strategy layer is used to dynamically adjust the verification strategy. The overall workflow is as follows: Figure 4 As shown, its working principle is as follows:

[0120] 1. Obtain the verification result from the federated verification layer via the REST API;

[0121] II. Calculate the membership function value of the Tuoyun theory based on the verification results;

[0122] Third, the verification strategy is dynamically adjusted through a dynamic strategy engine and membership function values.

[0123] like Figure 6 As shown in the illustration, this application provides a verification system. The system comprises a recursive layer, a joint verification layer, and a dynamic policy layer, and interacts with external systems to generate and provide verification information for a target domain name. The system receives a domain name query request (e.g., querying the target domain name) with EDNS extended fields from the user and completes joint verification through the following functional modules:

[0124] (1) Recursive layer

[0125] The recursive layer includes a JC cache, which stores the federated certificate (JC) generated through federated authentication. When subsequent query requests for the same target domain arrive, the recursive layer can directly return the authentication result from the cache, improving authentication efficiency.

[0126] (2) Joint verification layer

[0127] The joint verification layer is used to perform joint verification of the target domain name using RPKI and DNSSEC, and includes two core verification modules:

[0128] The DNSSEC verification module (e.g., verification based on the DNSSEC key of the target domain name) is used to verify the legitimacy and integrity of domain name resolution records.

[0129] The RPKI verification module (e.g., verifying based on the RPKI resource certificate of the target domain) is used to verify the legitimacy of the routing source of the IP address corresponding to the target domain.

[0130] The network status monitoring module (e.g., acquiring network status information) is used to monitor and verify link quality indicators such as latency and packet loss.

[0131] A dynamic weighting algorithm is used to adaptively allocate verification resources based on verification results and network status information.

[0132] (3) Dynamic strategy layer

[0133] The dynamic strategy layer receives verification results from the joint verification layer and performs risk analysis and strategy management. The dynamic strategy layer includes a dynamic strategy engine, which calculates the target membership degree of the verification results and adjusts the strategy. Threat intelligence integration is used to obtain verification scores (verification results) and perform related processing.

[0134] (4) External system layer

[0135] The verification system interacts with external system layers, including the Domain Name System (DNS) and RPKI system, and synchronizes them via a certificate synchronization protocol.

[0136] See Figure 7 , Figure 7 A verification information generation apparatus 700 provided in this application embodiment includes:

[0137] The acquisition unit 701 is used to acquire the Domain Name System Security Extension (RPKI) resource certificate of the target domain name and the DNSSEC key of the target domain name. The RPKI resource certificate is used to identify the Internet Protocol IP address ownership of the target domain name, and the DNSSEC key is used to identify the domain name ownership of the target domain name.

[0138] Verification unit 702 is used to jointly sign the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name to generate a joint certificate for the target domain name;

[0139] Storage unit 703 is used to store the combined certificate of the target domain name in the cache corresponding to the recursive server if the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name are verified, so as to provide verification information for query requests for the target domain name.

[0140] Optionally, the storage unit 703 is specifically used for:

[0141] The RPKI resource certificate chain is verified based on the RPKI resource certificate of the target domain name, and the DNSSEC signature chain is verified based on the DNSSEC key of the target domain name to obtain the verification result for the federated certificate.

[0142] Determine the target membership degree corresponding to the verification result, wherein the target membership degree is used to reflect the degree of deviation between the verification result and the ideal result;

[0143] Based on the target membership, a target response strategy is determined from multiple pending response strategies, and the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name are verified through the target response strategy. The pending response strategy is used to adjust the verification method.

[0144] If the RPKI resource certificate and the DNESEC key of the target domain name are verified, the combined certificate of the target domain name is stored in the cache corresponding to the recursive server.

[0145] Optionally, the storage unit 703 is specifically used for:

[0146] If the deviation of the target membership degree indicator is less than or equal to the first threshold, then log it.

[0147] If the deviation of the target membership degree indicator is greater than the first threshold and less than or equal to the second threshold, then a secondary verification is triggered, wherein the second threshold is greater than the first threshold;

[0148] If the deviation of the target membership indicator is greater than the second threshold, the cache corresponding to the recursive server is isolated and an alarm message is generated.

[0149] Optionally, the device 700 further includes a resource allocation unit for:

[0150] The RPKI resource certificate chain is verified based on the RPKI resource certificate of the target domain name to obtain a first verification score. The first verification score is used to indicate the verification progress of the RPKI resource certificate chain.

[0151] The DNSSEC signature chain is verified based on the DNESEC key of the target domain name to obtain a second verification score, which is used to indicate the verification progress of the DNSSEC signature chain.

[0152] Based on the first verification score and the second verification score, determine the first weight and the second weight;

[0153] Based on the first weight and the second weight, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

[0154] Optionally, the device 700 further includes a weight correction unit, used for:

[0155] Obtain network status information, which includes a first network quality indicator for the verification node in the RPKI resource certificate chain and a second network quality indicator for the verification node in the DNSSEC signature chain.

[0156] Based on the network state information, the first weight and the second weight are corrected to obtain the first corrected weight and the second corrected weight.

[0157] Based on the first correction weight and the second correction weight, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

[0158] Optionally, the combined certificate for the target domain name includes the RPKI resource certificate, the DNSSEC public key, the RIR issuance signature, the domain registry signature, and the certificate validity period.

[0159] See Figure 8 This application also provides a computer device, which includes a memory 801 and a processor 802.

[0160] The memory is used to store computer programs and to transfer the computer programs to the processor;

[0161] The processor is used to execute the method of the above method embodiment according to the computer program.

[0162] This application also provides a computer-readable storage medium, characterized in that the computer-readable storage medium is used to store a computer program, the computer program being used to execute the method of the above-described method embodiments.

[0163] This application also provides a computer program product including a computer program, which, when run on a computer device, causes the computer device to perform the method described in the above method embodiments.

[0164] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.

[0165] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0166] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0167] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0168] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0169] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for generating verification information, characterized in that, The method includes: Obtain the Domain Name System Security Extension (RPKI) resource certificate and the DNSSEC key of the target domain name. The RPKI resource certificate is used to identify the Internet Protocol (IP) address ownership of the target domain name, and the DNSSEC key is used to identify the domain name ownership of the target domain name. The RPKI resource certificate of the target domain name and the DNESEC key of the target domain name are jointly signed to generate a joint certificate for the target domain name; If the RPKI resource certificate and the DNESEC key of the target domain are verified, the combined certificate of the target domain is stored in the cache of the recursive server so as to provide verification information for query requests for the target domain.

2. The method according to claim 1, characterized in that, If the RPKI resource certificate and the DNESEC key of the target domain name are verified, the combined certificate of the target domain name is stored in the cache corresponding to the recursive server, including: The RPKI resource certificate chain is verified based on the RPKI resource certificate of the target domain name, and the DNSSEC signature chain is verified based on the DNSSEC key of the target domain name to obtain the verification result for the federated certificate. Determine the target membership degree corresponding to the verification result, wherein the target membership degree is used to reflect the degree of deviation between the verification result and the ideal result; Based on the target membership, a target response strategy is determined from multiple pending response strategies, and the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name are verified through the target response strategy. The pending response strategy is used to adjust the verification method. If the RPKI resource certificate and the DNESEC key of the target domain name are verified, the combined certificate of the target domain name is stored in the cache corresponding to the recursive server.

3. The method according to claim 2, characterized in that, The step of determining the target response strategy from multiple pending response strategies based on the target membership degree includes: If the deviation of the target membership degree indicator is less than or equal to the first threshold, then log it. If the deviation of the target membership degree indicator is greater than the first threshold and less than or equal to the second threshold, then a secondary verification is triggered, wherein the second threshold is greater than the first threshold; If the deviation of the target membership indicator is greater than the second threshold, the cache corresponding to the recursive server is isolated and an alarm message is generated.

4. The method according to claim 1, characterized in that, The method further includes: The RPKI resource certificate chain is verified based on the RPKI resource certificate of the target domain name to obtain a first verification score. The first verification score is used to indicate the verification progress of the RPKI resource certificate chain. The DNSSEC signature chain is verified based on the DNESEC key of the target domain name to obtain a second verification score, which is used to indicate the verification progress of the DNSSEC signature chain. Based on the first verification score and the second verification score, determine the first weight and the second weight; Based on the first weight and the second weight, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

5. The method according to claim 4, characterized in that, The method further includes: Obtain network status information, which includes a first network quality indicator for the verification node in the RPKI resource certificate chain and a second network quality indicator for the verification node in the DNSSEC signature chain. Based on the network state information, the first weight and the second weight are corrected to obtain the first corrected weight and the second corrected weight. Based on the first correction weight and the second correction weight, adjust the verification computation resources for the RPKI resource certificate chain and the verification computation resources for the DNSSEC signature chain.

6. The method according to claim 1, characterized in that, The combined certificate for the target domain name includes the RPKI resource certificate, the DNSSEC public key, the RIR issuance signature, the domain registry signature, and the certificate validity period.

7. A verification information generation device, characterized in that, The device includes: The acquisition unit is used to acquire the Domain Name System Security Extension (RPKI) resource certificate of the target domain name and the DNSSEC key of the target domain name. The RPKI resource certificate is used to identify the Internet Protocol IP address ownership of the target domain name, and the DNSSEC key is used to identify the domain name ownership of the target domain name. The verification unit is used to jointly sign the RPKI resource certificate of the target domain name and the DNESEC key of the target domain name to generate a joint certificate for the target domain name; The storage unit is configured to store the combined certificate of the target domain name in the cache corresponding to the recursive server if the RPKI resource certificate and the DNESEC key of the target domain name are verified, so as to provide verification information for query requests for the target domain name.

8. A computer device, characterized in that, The computer device includes a processor and memory: The memory is used to store computer programs and to transfer the computer programs to the processor; The processor is configured to perform the method according to any one of claims 1-6 according to the computer program.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program for performing the method according to any one of claims 1-6.

10. A computer program product comprising a computer program, characterized in that, When it is run on a computer device, it causes the computer device to perform the method described in any one of claims 1-6.