Method and related device for probing encrypted dns recursive server

By scanning the set of Internet Protocol IP addresses and iteratively expanding certificate information, the problem of limited coverage and low efficiency of encrypted DNS recursive server detection in existing technologies is solved, achieving efficient and widespread server discovery and IPv6 compatibility.

CN122419982APending Publication Date: 2026-07-17CHINA INTERNET NETWORK INFORMATION CENTER

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA INTERNET NETWORK INFORMATION CENTER
Filing Date
2026-06-12
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies have limited coverage and low detection efficiency when detecting encrypted DNS recursive servers that support encryption protocols across the entire network.

Method used

By scanning the set of Internet Protocol IP addresses, candidate encrypted DNS recursive servers are selected, a secure connection is established to obtain certificate information, the DNS recursive resolution service is verified, and the certificate domain name is used for iterative expansion to implement a two-level filtering mechanism to improve detection efficiency.

Benefits of technology

It expands the coverage of encrypted DNS recursive servers, improves detection efficiency, breaks through the scanning blind spots hidden by firewalls, is compatible with IPv6 networks, reduces resource waste, and improves hit rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419982A_ABST
    Figure CN122419982A_ABST
Patent Text Reader

Abstract

本申请公开了一种加密DNS递归服务器探测方法及相关装置。该方法包括:对IP地址集扫描,筛选出支持加密协议的第一候选加密DNS递归服务器;建立安全连接时获取其证书信息;通过该连接验证其DNS递归解析服务,通过后记入有效集合;从有效服务器的证书中提取域名信息;查询该域名得到至少一个第二候选加密DNS递归服务器;将第二候选作为第一候选,重复上述连接、验证、提取和查询步骤,直至满足结束条件。本方案利用证书域名作为线索,扩展覆盖范围;结合两级过滤和定向探测,在复用连接数据基础上进行迭代扩展,大幅提升了探测效率和准确性。
Need to check novelty before this filing date? Find Prior Art