A Space-Ground Integrated Intelligent DNS Query and Routing Protocol

By combining multidimensional perception and deep reinforcement learning models with hierarchical DNS caching, post-quantum cryptography, and blockchain technology, the problems of high latency, poor security, and easy node failure in DNS queries in the integrated space-ground network are solved, realizing low-latency, high-reliability, and secure DNS query services, and ensuring node survivability in extreme environments.

CN122420199APending Publication Date: 2026-07-17GUANGDONG BOYIDA INTELLIGENT PARKING EQUIP CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG BOYIDA INTELLIGENT PARKING EQUIP CO LTD
Filing Date
2026-04-24
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies cannot provide low-latency, highly reliable, and highly secure DNS query services in integrated space-ground networks. Furthermore, traditional solutions are prone to routing node failures in extreme space environments, are costly, and cannot cope with multiple failures.

Method used

Employing multidimensional perception, deep reinforcement learning models, hierarchical DNS caching, post-quantum cryptography and blockchain technology, and graceful degradation survival guarantee technology, an intelligent DNS query routing protocol is implemented. Combining real-time network status and user needs, it provides end-to-end encryption and signature, dynamically switches paths, and optimizes resource utilization.

Benefits of technology

It enables global, dynamic, and intelligent selection of DNS query paths in complex integrated space-ground networks, ensuring user experience continuity, providing future security capabilities, efficiently utilizing network resources, and maintaining core functions in the event of hardware failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122420199A_ABST
    Figure CN122420199A_ABST
Patent Text Reader

Abstract

This invention discloses an integrated space-ground intelligent DNS query routing protocol and system, belonging to the field of communications. The protocol includes: a multi-dimensional perception step, collecting real-time information on user, network, and satellite service requirements; an intelligent resolution step, dynamically selecting pure space-based, pure ground-based, or space-ground collaborative resolution paths through a deep reinforcement learning model; a caching collaboration step, scheduling hierarchical caching and collaborative queries involving satellite L1, gateway station L2, and ground L3; a routing decision step, calculating specific routes based on a weighted and minimized approach considering latency, energy consumption, and security risks; an adaptive switching step, achieving seamless switching of query sessions based on a predictive model; a security enhancement step, integrating post-quantum encryption, quantum key distribution, and blockchain verification; and a graceful degradation survival guarantee step, ensuring the survivability of routing nodes in extreme space environments through state monitoring and thermal reconfiguration. This solves the problems of high latency and low reliability in DNS queries across heterogeneous space-ground networks, achieving high-performance and high-security root resolution services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a space-ground integrated intelligent DNS query routing protocol, applicable to space-ground integrated information networks including low-Earth orbit satellite constellations, high-Earth orbit satellites, and terrestrial networks. Background Technology

[0002] The Domain Name System (DNS) is a critical infrastructure of the internet, responsible for translating human-readable domain names into machine-readable IP addresses. Traditional DNS services rely heavily on terrestrial infrastructure, with its root service and recursive resolution service provided through anycast nodes globally. However, this architecture has inherent flaws: First, in remote areas (such as oceans, deserts, and airspace), users are far from the ground root servers or recursive resolvers, resulting in DNS query delays of up to hundreds of milliseconds, which seriously affects the internet access experience.

[0003] Secondly, terrestrial DNS infrastructure is vulnerable to natural disasters, conflicts, or large-scale cyberattacks, lacking sufficient resilience.

[0004] With the rapid development of low-Earth orbit broadband satellite constellations, integrated space-ground networks have become an inevitable trend. However, directly applying terrestrial DNS protocols to space-based networks faces severe challenges: dynamic changes in satellite network topology, asymmetric latency in satellite-to-ground links, limited computing and storage resources for satellite nodes, and escalating security threats to space links.

[0005] While there is research on satellite network routing optimization or DNS caching in existing technologies, there is a lack of a complete end-to-end DNS query routing protocol that can intelligently adapt to the dynamic characteristics of heterogeneous terrestrial and satellite networks and comprehensively consider performance, energy consumption, and security.

[0006] Furthermore, existing technologies generally overlook the survivability of space-based routing nodes in extreme space environments: micrometeoroid impacts, space debris collisions, and extreme thermal stress can lead to localized failures of routing nodes. Traditional solutions rely on hardware redundancy, but this approach is costly, heavy, and cannot cope with simultaneous failures at multiple points. Summary of the Invention

[0007] The purpose of this invention is to overcome the shortcomings of the prior art and provide an integrated terrestrial and satellite intelligent DNS query routing protocol, which aims to provide users of integrated terrestrial and satellite networks with low latency, high reliability, and high security DNS query services.

[0008] To achieve the above objectives, the present invention adopts the following technical solution: A space-ground integrated intelligent DNS query and routing protocol, characterized by comprising the following steps: Multi-dimensional sensing steps: Real-time sensing and collection of user terminal location and mobility information, access type and link quality information of currently available networks, real-time topology and ephemeris prediction information of satellite constellations, and service level requirement information of DNS queries initiated by users; Intelligent resolution steps: Multidimensional sensing information is input into a pre-trained deep reinforcement learning model, which outputs the optimal DNS resolution path type; the resolution path type includes pure space-based resolution path, pure ground-based resolution path, and space-ground collaborative resolution path; Cache coordination steps: Based on the selected resolution path, queries or cache updates are performed in the hierarchical DNS caches deployed on satellite nodes and ground gateways; the hierarchical DNS caches include hotspot caches deployed on low-Earth orbit satellites, regional caches deployed on high-Earth orbit satellites or ground gateway stations, and global caches deployed on ground root / top-level domain servers; Routing decision and execution steps: Based on the selected resolution path type, combined with the real-time network load, end-to-end latency requirements, and query security level, the specific query packet forwarding path is calculated through a multi-objective optimization function, and the routing is executed; Adaptive switching steps: Continuously monitor network status and predict user mobility. When it is predicted that the performance of the current resolution path will not meet the quality of service requirements or will be interrupted, seamlessly switch the ongoing DNS query session to a new optimal path. Security enhancement steps: Throughout the DNS query process, a post-quantum cryptography algorithm is integrated to encrypt and sign query requests and responses end-to-end, and blockchain technology is used to store and verify update operations of key root zones and top-level domain cache records. Graceful degradation survival assurance steps: The system collects temperature, power consumption and health status data of routing nodes, cache nodes and security nodes in real time through the status monitoring unit, re-plans the calculation task path for overheated components using a GPU-based parallel shortest path algorithm, and adjusts the heat dissipation power of components around the damaged area through a MEMS variable thermal resistance structure, so that the system can maintain core functions in the event of hardware failure.

[0009] The beneficial effects of this invention are as follows: (1) Global intelligent optimization: Through a deep reinforcement learning model, global, dynamic and intelligent selection of DNS query paths is realized in a complex integrated space-ground network environment; (2) Ultimate user experience: Through a predictive seamless switching mechanism, the continuity of DNS query sessions is guaranteed for users during high-speed movement or drastic network changes; (3) Intrinsic security: By integrating post-quantum cryptography and blockchain technology, it provides future-oriented security capabilities for the next generation of DNS; (4) Efficient use of resources: Through hierarchical caching with space-ground coordination and multi-objective optimization that takes energy consumption into account, precise scheduling of network resources is achieved; (5) Routing node survivability guarantee: By integrating graceful degradation survivability guarantee technology, millisecond-level hot control reconstruction of routing nodes is achieved. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a schematic diagram of the system architecture described in this invention; Figure 2 This is a general flowchart of the protocol described in this invention; Figure 3 This is a detailed flowchart of the intelligent parsing steps in this invention; Figure 4 This is a schematic diagram of the adaptive switching step in this invention; Figure 5 This is a flowchart of the graceful degradation survival assurance steps in this invention; Figure 6 This is a schematic diagram of the pre-reconstruction model in this invention; Figure 7 This is a schematic diagram of the three-dimensional temperature field map of the routing node and the pre-reconstruction trigger in this invention. Detailed Implementation

[0012] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments.

[0013] like Figure 1 As shown, this system operates within an integrated space-ground network comprised of a low-Earth orbit satellite constellation, high-Earth orbit satellites, ground gateway stations, terrestrial internet, and user terminals. The system includes the following functional modules: a multi-dimensional sensing module, an intelligent parsing module, a cache management module, a routing decision module, a handover control module, a security protection module, and a graceful degradation survival assurance module.

[0014] like Figure 2As shown, the workflow of this protocol is as follows: The user terminal initiates a DNS query; the multi-dimensional perception module collects terminal information, link quality, satellite topology, and service level requirements; the intelligent resolution module calls the deep reinforcement learning model to output path type decisions; the routing decision module calculates the optimal forwarding path; the DNS query packet is forwarded along the path, and the caching coordination module plays a role in the process; the handover control module runs continuously, predicts the network status, and achieves seamless handover; the security enhancement module is implemented throughout; and the graceful degradation survival guarantee module runs in parallel, continuously monitoring the health status of routing nodes.

[0015] Example 1: Secure and smooth transition of root zone key rolling

[0016] Scenario: The Internet Corporation for Assigned Names and Numbers (ICANN) performs a scheduled rolling update of the root zone key signing key (KSK).

[0017] Implementation process: ICANN distributes the root zone file signed with the new KSK to trusted ground anchor stations around the world; the system, based on multi-dimensional sensing information, uses a deep reinforcement learning model to decide on the "space-based collaborative path" for update broadcasting; hotspot cache nodes prioritize caching the new KSK; the multi-objective optimization function prioritizes the transmission of update data through low-latency and high-reliability paths; the update data is encrypted with post-quantum cryptography, transmitted through a quantum key distribution channel, and the update record is written to the blockchain.

[0018] Technical effect: The Tianji Root Service System can quickly complete authoritative and consistent updates of KSKs worldwide.

[0019] Example 2: Seamless service relay in response to satellite node mobility

[0020] Scenario: A passenger plane flying across the Pacific Ocean needs to continuously perform DNS queries, and the satellite providing root resolution services is about to leave the airspace due to orbital motion.

[0021] Implementation process: The switching control module predicts user trajectories and satellite coverage changes based on a predictive model, and detects that the currently serving satellite is about to leave; within the window before the link is predicted to be interrupted, the DNS query session state is synchronized to the target satellite; after the target satellite completes the state synchronization, it immediately takes over the aircraft's root resolution requests.

[0022] Technical effect: Switching jitter is in the millisecond range, significantly improving service availability, and users are completely unaware of it.

[0023] Example 3: Identifying and Isolating Intermittent Byzantine Nodes

[0024] Scenario: Due to long-term space radiation, the satellite node experiences memory bit flipping, which manifests as intermittent Byzantine faults.

[0025] Implementation process: In multiple rounds of consensus and query response, the system recorded that the behavior of the nodes began to deviate significantly from the high-reputation node cluster; the reputation value triggered a multiplicative penalty after the erroneous behavior, and plummeted to below the isolation threshold; the system excluded the node from the consensus group candidate list and downgraded it to a regular node that can only provide read-only query services.

[0026] Technical effect: It achieves gradual suppression and even automatic isolation of Byzantine nodes without manual intervention.

[0027] Example 4: Providing low-latency root resolution for remote areas

[0028] Scenario: A research vessel conducting marine scientific research in the heart of the South Pacific needs to transmit its research data back to a domestic server in real time. This region is far from any ground root server mirror.

[0029] Implementation process: The research vessel establishes a link directly with the satellites covering the airspace via its onboard satellite communication terminal; the distributed root service instance on the satellite directly queries the latest root region image stored locally and agreed upon by consensus.

[0030] Technical results: Significantly reduced latency and greatly improved performance.

[0031] Example 5: Verification of Space-Based Platform for Graceful Degradation Survival Assurance

[0032] This embodiment is used to verify the performance of graceful degradation survival assurance steps on a space-based satellite platform.

[0033] like Figure 5 As shown, the graceful degradation survival assurance module runs on the space-based routing node to simulate a multi-point failure scenario caused by micrometeoroid impact.

[0034] The status monitoring unit collects the temperature of each computing unit of the routing node in real time at a high sampling rate, forming a data structure such as... Figure 7 The three-dimensional temperature field map shown.

[0035] The thermal control path planning unit employs a GPU-based parallel shortest path algorithm to replan the computational task path for overheated components. The new path satisfies the following conditions: connecting the heat sink unit with all healthy components, ensuring that the computational load on each edge does not exceed a preset percentage of its maximum capacity, and ensuring that the temperature difference between adjacent components does not exceed a preset threshold.

[0036] The local thermal control unit adjusts the heat dissipation power of the components surrounding the damaged area through a MEMS variable thermal resistance structure.

[0037] The pre-reconfiguration unit predicts high-failure-risk areas based on a hybrid neural network model. The model takes historical temperature fluctuations, vibration characteristics, cumulative operating time, and query load change rate as input, and outputs a predicted failure probability. Pre-reconfiguration is triggered when the predicted probability exceeds a preset threshold, allowing for advance planning of alternative computation paths.

[0038] The performance evaluation unit calculates temperature uniformity and heat dissipation efficiency indicators to determine whether a secondary reconstruction is triggered.

[0039] Test results show that this graceful degradation survival assurance step can achieve millisecond-level thermal control reconstruction in multi-point failure scenarios, effectively maintaining the heat dissipation capacity and service continuity of routing nodes.

[0040] Example 6: Resource Cooperative Scheduling under Multiple Priority Tasks

[0041] This embodiment is used to verify the ability to dynamically allocate and reconfigure resources based on the priority instructions of the upper-layer system.

[0042] In a spatial event, multiple routing nodes overheated simultaneously. Node A was currently processing a sovereign root query (highest priority), node B was processing a regular domain name query (medium priority), and node C was processing cache data synchronization (low priority).

[0043] The intelligent resolution module sends priority instructions to the graceful degradation survival assurance module; the graceful degradation survival assurance module dynamically allocates reconstruction resources according to the priority instructions to ensure that high-priority nodes complete hot control reconstruction first; the reconstruction of each node is carried out in parallel, and high-priority nodes complete reconstruction in the shortest time, successfully maintaining the sovereign root query service.

[0044] This embodiment verifies that the graceful degradation survival assurance steps can dynamically allocate reconstruction resources according to task priority, ensuring that the survival of critical nodes is guaranteed first.

[0045] Example 7: Coordination of Threat Awareness and Graceful Degradation for Routing Nodes

[0046] This embodiment is used to verify the collaborative operation of the routing node threat perception coordination module and the graceful degradation survival assurance module.

[0047] In a DDoS attack scenario, malicious attackers launch a massive DNS query flood attack against routing nodes.

[0048] The routing node threat perception and coordination module runs a lightweight AI model to detect in real time a surge in DNS query traffic and an abnormal increase in CPU utilization. The module automatically triggers rate limiting rules to filter malicious traffic. At the same time, it notifies the graceful degradation survival protection module that the node's CPU is overloaded and its temperature is rising rapidly due to the attack. The graceful degradation module marks the node as high priority, plans alternative computing paths in advance, and initiates the pre-reconstruction process.

[0049] Technical effect: Threat perception and graceful degradation work together to achieve dual protection of active defense and passive heat dissipation during an attack.

[0050] Industrial applicability

[0051] This invention provides a space-ground integrated intelligent DNS query and routing protocol and system with broad industrial applicability. The protocol is based on mature deep reinforcement learning, graph theory, and optimization theory, and can be implemented on FPGAs, GPUs, or dedicated ASICs. The multi-dimensional perception module can be implemented using a high-speed ADC in collaboration with an FPGA; the intelligent resolution module can deploy a deep reinforcement learning model using an inference engine; the thermal control path planning unit of the graceful degradation survivability assurance module can use a GPU parallel computing architecture, and the pre-reconstruction unit can be deployed using a hybrid neural network model. Hardware-in-the-loop simulations have verified that the system is fully functional and can be directly applied to the routing nodes of a space-based root service system, providing survivability assurance in extreme space environments.

Claims

1. A space-ground integrated intelligent DNS query and routing protocol, characterized in that, Includes the following steps: Multi-dimensional sensing steps: Real-time sensing and collection of spatiotemporal information of user terminals, network access information, satellite constellation topology and ephemeris information, and service demand information of DNS queries; Intelligent resolution steps: The multidimensional sensing information is input into a pre-trained deep reinforcement learning model, which dynamically determines the optimal DNS resolution path type. The path types include pure space-based resolution path, pure ground-based resolution path, and space-ground collaborative resolution path. Cache coordination steps: Based on the resolution path type of the decision, schedule the hierarchical DNS cache deployed on satellite nodes and ground gateways for querying and response. The hierarchical cache includes satellite hotspot cache, regional cache and ground global cache. Routing decision and execution steps: Based on the parsed path type, combined with real-time network status and security constraints, the specific query packet forwarding path is calculated through a multi-objective optimization function, and the routing is executed; Adaptive switching steps: Continuously monitor and predict network status and user mobility, and seamlessly switch ongoing DNS query sessions to alternative paths when path performance degradation or impending interruption is detected. Security enhancement steps: Throughout the query process, a post-quantum cryptographic algorithm is integrated to encrypt and sign the query data, and blockchain is used to store and verify updates to critical DNS cache records; Graceful degradation survival assurance steps: The system collects temperature, power consumption and health status data of routing nodes, cache nodes and security nodes in real time through the status monitoring unit, re-plans the calculation task path for overheated components using a GPU-based parallel shortest path algorithm, and adjusts the heat dissipation power of components around the damaged area through a MEMS variable thermal resistance structure, so that the system can maintain core functions in the event of hardware failure.

2. The protocol according to claim 1, characterized in that, In the intelligent parsing step, the deep reinforcement learning model adopts a neural network based on the attention mechanism; its state space includes dynamic network topology, link quality, cache state and query load; its action space is the selection of the three parsing path types; its reward function integrates the reciprocal of query latency, query success rate, path energy consumption and security risk value calculated based on node reputation value.

3. The protocol according to claim 1, characterized in that, In the cache collaboration step, the satellite hotspot cache is deployed on low-Earth orbit satellites to store hotspot domain name records based on spatiotemporal locality prediction; the regional cache is deployed on high-Earth orbit satellites or ground gateway stations to store regional top-level domain and authoritative domain records; the ground global cache is located on ground root and top-level domain servers; and the caches at all levels perform data preheating and consistency maintenance through a collaboration strategy based on access prediction models.

4. The protocol according to claim 1, characterized in that, In the routing decision and execution steps, the objective of the multi-objective optimization function is to minimize the weighted sum of latency, energy consumption, and security risk values, where the security risk values ​​are calculated based on the dynamic reputation values ​​of nodes in the path, and the weight coefficients are dynamically adjusted according to the service level requirements queried by the user.

5. The protocol according to claim 1, characterized in that, In the adaptive switching step, the switching is triggered based on a predictive model of changes in user movement trajectory and satellite coverage. Before the service link quality is predicted to be lower than the threshold, the session status of the DNS query is synchronized to the target satellite node in advance, so as to realize the pre-switching and seamless continuation of the query path.

6. The protocol according to claim 1, characterized in that, The security enhancement steps specifically include: End-to-end encryption of DNS over HTTPS or DNS over TLS queries is performed using lattice-based post-quantum cryptography algorithms; A quantum-secure channel is established between satellite nodes equipped with quantum key distribution payloads for transmitting DNS-sensitive data; The rolling record of the root zone key signing key and its distribution verification hash in the satellite cache are written into the permissioned blockchain network for global verification and auditing.

7. The protocol according to claim 1, characterized in that, The graceful degradation survival assurance steps also include: predicting high failure risk areas based on a hybrid neural network model, with input features including at least one of historical temperature fluctuations, vibration characteristics, cumulative working time, and query load change rate, and outputting a failure probability prediction value. When the predicted probability exceeds a preset threshold, pre-reconstruction is triggered to plan backup computing paths in advance.

8. The protocol according to claim 1, characterized in that, The graceful degradation survival guarantee steps also include: dynamically allocating reconstruction resources according to the priority instructions of the upper layer system. When a routing node is overheated, if the node is currently processing a high-priority query, its heat dissipation reconstruction will be prioritized.

9. The protocol according to claim 1, characterized in that, In the graceful degradation survival guarantee step, the GPU-based parallel shortest path algorithm performs path planning, and the computational task path generated by the path planning satisfies: Path integrity constraint: The new path connects the heat sink unit to all healthy components; Traffic capacity constraint: The computational load on each edge shall not exceed a preset percentage of its maximum capacity. Temperature gradient constraint: The temperature difference between adjacent components after reconstruction shall not exceed a preset threshold.

10. The protocol according to claim 1, characterized in that, The status monitoring unit is also configured to: collect temperature data of each computing unit of the routing node in real time, generate a three-dimensional temperature field map of the routing node based on the collected data, and use the three-dimensional temperature field map as the input feature of the pre-reconstruction unit.

11. The protocol according to claim 1, characterized in that, It also includes a routing node threat awareness and coordination module, which is configured to run a lightweight AI model to continuously monitor the DNS query traffic, resource consumption, and routing table changes of the routing nodes. When an anomaly matching the characteristics of a DDoS attack is detected, it can automatically trigger local defense rules and notify the graceful degradation survival assurance steps to prioritize the heat dissipation reconstruction of the attacked node.

12. A space-ground integrated intelligent DNS system for implementing the protocol of any one of claims 1 to 11, characterized in that, include: A multi-dimensional sensing module, configured to collect real-time status information of users, networks, and satellites; The intelligent parsing module has a built-in deep reinforcement learning engine and is configured to make path type decisions. The cache management module configures a hierarchical DNS caching system for managing the space-air-ground collaboration. The routing decision module is configured to run multi-objective optimization algorithms and generate specific routes. Switch control modules to configure seamless switching for predicting network changes and managing query sessions; The security protection module is configured to provide post-quantum encryption and blockchain verification services; Graceful degradation survivability protection module, integrated into the routing node, includes: The status monitoring subunit is used to collect real-time data on the temperature, power consumption, and health status of the routing nodes. The thermal control path planning subunit uses a GPU-based parallel shortest path algorithm to replan the computation task path for overheated components; The local thermal control subunit adjusts the heat dissipation power of the components surrounding the damaged area through a MEMS variable thermal resistance structure. The pre-reconfigurable sub-unit is used to predict high-failure-risk areas and plan backup paths in advance. The performance evaluation sub-unit is used to evaluate the temperature uniformity and heat dissipation efficiency after reconstruction and to trigger a secondary reconstruction.

13. The system according to claim 12, characterized in that, The graceful degradation survival protection module receives priority instructions from the intelligent resolution module, and prioritizes the hot control reconstruction of the core routing node when a routing node fails.

14. A computing device comprising a memory and a processor, the memory storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the protocol as described in any one of claims 1 to 11.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the protocol as described in any one of claims 1 to 11.