Domain name preservation method and system, and storage medium

By modifying the root point to the root server in the recursive server, and using the tamper-free authoritative domain data of the top-level domain server in the domain, the problem of authoritative domain name system being hijacked is solved, and the security and accuracy of domain name resolution are achieved.

WO2025160899A1PCT designated stage Publication Date: 2025-08-07PENG CHENG LAB
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/075283
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

The existing technology cannot effectively alleviate the risk of authoritative domain name systems being hijacked, especially by modifying authoritative domain server records in top-level domain servers for hijacking, resulting in the domain name resolution results being forged.

Method used

By modifying the root point of the recursive server to the root server of this domain, and in the recursive resolution process of the domain name, directly communicate with the top-level domain server of this domain to avoid direct connection with the top-level domain server, use the tampered authoritative domain data stored in the top-level domain server of this domain to obtain the correct authoritative domain server address.

Benefits of technology

It effectively avoids the risk of authoritative domain name systems being hijacked, ensures the accuracy and security of domain name resolution results, and prevents authoritative servers of top-level domain servers from being tampered with.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024075283_07082025_PF_FP_ABST
    Figure CN2024075283_07082025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of computers. Disclosed are a domain name preservation method and system, and a storage medium. The preservation method comprises: acquiring a domain name to be resolved, which is sent by a client; sending a first acquisition request to a local-domain root server on the basis of said domain name, such that the local-domain root server returns the address of a local-domain top-level domain server, which address is obtained in response to the first acquisition request; sending a second acquisition request to the local-domain top-level domain server on the basis of the address of the local-domain top-level domain server, such that the local-domain top-level domain server returns, on the basis of authoritative-domain data, the address of an authoritative domain server corresponding to said domain name; sending a sub-domain name query request to the authoritative domain server corresponding to said domain name, such that the authoritative domain server returns an address corresponding to said domain name, which address is obtained in response to the sub-domain name query request; and sending to the client the address corresponding to said domain name. The present application can alleviate the risk of an authoritative domain being hijacked.
Need to check novelty before this filing date? Find Prior Art

Description

Domain name preservation method, system and storage medium Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a domain name preservation method, system, and storage medium. Background Art

[0002] The Domain Name System (DNS), a distributed database that maps domain names to IP addresses, facilitates internet access and is a critical piece of internet infrastructure. However, the DNS also carries risks: if important domain name data within the DNS is tampered with, the websites associated with those domain names could be hijacked and redirected to other IP addresses, creating a hijacking risk.

[0003] In related technologies, if a domain name is hijacked, the authoritative domain is generally hijacked. The specific hijacking method is: by modifying the authoritative domain server record in the top-level domain server to point to a forged authoritative domain server, the purpose of forging the resolution result of any subdomain of the domain name is achieved. However, there is currently no technology that can fundamentally alleviate the risk of authoritative domains being hijacked. How to alleviate the risk of authoritative domains being hijacked is an issue that urgently needs to be discussed and resolved.

[0004] Summary of the Invention

[0005] The present application aims to solve at least one of the technical problems existing in the prior art. To this end, the present application proposes a domain name preservation method, system and storage medium that can mitigate the risk of authoritative domains being hijacked.

[0006] In order to solve the above technical problems, this application proposes the following technical solutions:

[0007] A first aspect of the present application provides a domain name preservation method, which is applied to a recursive server in a domain name preservation system. The domain name preservation system further includes a local root server and a local top-level domain server, and the local top-level domain server stores authoritative domain data, the authoritative domain data including a correspondence between a domain name and an address of an authoritative domain server. The preservation method includes:

[0008] Get the domain name to be resolved sent by the client;

[0009] Sending a first acquisition request to a local domain root server according to the domain name to be resolved, so that the local domain root server returns an address of a local domain top-level domain server obtained in response to the first acquisition request;

[0010] Sending a second acquisition request to the local top-level domain server according to the address of the local top-level domain server, so that the local top-level domain server returns the address of the authoritative domain server corresponding to the domain name to be resolved according to the authoritative domain data;

[0011] Sending a subdomain name query request to the authoritative domain server corresponding to the domain name to be resolved, so that the authoritative domain server returns the address corresponding to the domain name to be resolved obtained in response to the subdomain name query request;

[0012] The address corresponding to the domain name to be resolved is sent to the client.

[0013] The domain name preservation method according to the embodiment of the first aspect of the present application has at least the following beneficial effects: the present application modifies the root pointing of the recursive server to the root server of the local domain. In the domain name recursive resolution process, the recursive server directly sends a first acquisition request to the root server of the local domain after obtaining the domain name to be resolved sent by the client, and receives the address of the top-level domain server of the local domain returned by the root server of the local domain. Then, the recursive server can connect to the top-level domain server of the local domain according to the address of the top-level domain server of the local domain, and receive the address of the authoritative domain server corresponding to the domain name to be resolved returned by the top-level domain server of the local domain, without directly connecting to the top-level domain server, effectively avoiding the problem caused by tampering with the authoritative server of the top-level domain server when there is a risk of hijacking the authoritative domain, and alleviating the risk of hijacking the authoritative domain.

[0014] A second aspect of the present application provides a domain name preservation method, which is applied to a local top-level domain server in a domain name preservation system. The domain name preservation system also includes a recursive server, and the local top-level domain server stores authoritative domain data, wherein the authoritative domain data includes a correspondence between a domain name and an address of an authoritative domain server. The preservation method includes:

[0015] receiving a second acquisition request, wherein the second acquisition request is obtained by the recursive server according to the domain name to be resolved sent by the client;

[0016] The address of the authoritative domain server corresponding to the domain name to be resolved is returned to the recursive server according to the authoritative domain data, so that the recursive server sends a subdomain query request to the authoritative domain server corresponding to the domain name to be resolved.

[0017] According to some embodiments of the second aspect of the present application, the local top-level domain server includes a cache module, the authoritative domain data includes first authoritative domain data, the cache module stores the first authoritative domain data, and returning the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server based on the authoritative domain data includes:

[0018] Query the first authoritative domain data to see whether the address of the authoritative domain server corresponding to the domain name to be resolved exists in the first authoritative domain data. If the address of the authoritative domain server corresponding to the domain name to be resolved exists in the first authoritative domain data, output the address of the authoritative domain server corresponding to the domain name to be resolved.

[0019] According to some embodiments of the second aspect of the present application, the local top-level domain server further includes an authoritative domain preservation database, the authoritative domain data further includes second authoritative domain data, the authoritative domain preservation database stores the second authoritative domain data, and returning the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server based on the authoritative domain data further includes:

[0020] When the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the first authoritative domain data, query whether the address of the authoritative domain server corresponding to the domain name to be resolved exists in the second authoritative domain data; when the address of the authoritative domain server corresponding to the domain name to be resolved exists in the second authoritative domain data, output the address of the authoritative domain server corresponding to the domain name to be resolved, and update the address of the authoritative domain server corresponding to the domain name to be resolved to the first authoritative domain data.

[0021] According to some embodiments of the second aspect of the present application, the local top-level domain server further includes a proxy module, and the security method further includes:

[0022] When the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the authoritative domain data, the address of the authoritative domain server corresponding to the domain name to be resolved is obtained through the proxy module, the address of the authoritative domain server corresponding to the domain name to be resolved is output, and the address of the authoritative domain server corresponding to the domain name to be resolved is updated to the first authoritative domain data.

[0023] According to some embodiments of the second aspect of the present application, the proxy module is respectively in communication with the global root server and the top-level domain server, and obtaining the address of the authoritative domain server corresponding to the domain name to be resolved through the proxy module includes:

[0024] Sending a third acquisition request to the global root server, so that the global root server returns the address of the top-level domain server obtained in response to the third acquisition request;

[0025] A resolution request is sent to the top-level domain server according to the address of the top-level domain server, so that the top-level domain server returns the address of the authoritative domain server corresponding to the domain name to be resolved obtained in response to the resolution request.

[0026] According to some embodiments of the second aspect of the present application, the local top-level domain server further includes an authoritative domain data acquisition module, and the preservation method further includes:

[0027] The authoritative domain preservation data of all alliance members in the alliance blockchain is obtained through the authoritative domain data acquisition module, and the authoritative domain preservation data is updated as the second authoritative domain data into the authoritative domain preservation database, wherein the authoritative domain preservation data includes the correspondence between the domain name and the address of the authoritative domain server.

[0028] According to some embodiments of the second aspect of the present application, updating the authoritative domain preservation data as second authoritative domain data into the authoritative domain preservation database includes:

[0029] Obtaining the priority level of the authoritative domain preservation data;

[0030] The authoritative domain preservation data is updated into the authoritative domain preservation database as second authoritative domain data in order of priority from high to low.

[0031] According to some embodiments of the second aspect of the present application, the consortium blockchain is obtained by the following steps:

[0032] A consortium blockchain is constructed based on a private chain, wherein each consortium member in the consortium blockchain corresponds to a top-level domain server in the local domain.

[0033] According to some embodiments of the second aspect of the present application, before obtaining the authoritative domain preservation data of all alliance members in the alliance blockchain through the authoritative domain data acquisition module, the method further includes:

[0034] Receive the authoritative domain preservation data uploaded by the units belonging to the authoritative domain, review the authoritative domain preservation data uploaded by the units belonging to the authoritative domain, and report the updated authoritative domain preservation data to the alliance blockchain after passing the review.

[0035] A third embodiment of the present application provides a domain name preservation system, including:

[0036] at least one memory;

[0037] at least one processor;

[0038] at least one program;

[0039] The programs are stored in the memory, and the processor executes at least one of the programs to implement:

[0040] A domain name preservation method as described in any one of the first aspects of this application.

[0041] A fourth aspect of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer-executable signal, wherein the computer-executable signal is used to execute:

[0042] A domain name preservation method as described in any one of the first aspects of this application.

[0043] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become obvious from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Additional aspects and advantages of the present application will become apparent and readily understood from the following description of the embodiments with reference to the accompanying drawings, in which:

[0045] FIG1 is a main flow chart of a domain name preservation method provided by some embodiments of the present application in which the execution subject is a recursive server;

[0046] FIG2 is a main flow chart of a domain name preservation method provided by some embodiments of the present application, wherein the execution subject is a top-level domain server of the domain;

[0047] FIG3 is a flowchart of existing recursive domain name resolution provided by some embodiments of the present application;

[0048] FIG4 is a flow chart of a case where a hijacking risk occurs in an existing domain name system according to some embodiments of the present application;

[0049] FIG5 is a flow chart of the domain name preservation system of the present application provided in some embodiments of the present application when a hijacking risk occurs;

[0050] FIG6 is a flowchart of the workflow of the top-level domain server of the present application provided in some embodiments of the present application;

[0051] FIG7 is a sub-flowchart of a method for preserving a domain name whose execution subject is a top-level domain server of the domain provided in some embodiments of the present application;

[0052] FIG8 is a main flow chart of a domain name preservation method provided in some embodiments of the present application;

[0053] FIG9 is a sub-flowchart of a method for preserving a domain name whose execution subject is a top-level domain server of the domain, provided in another embodiment of the present application;

[0054] FIG10 is a module block diagram of a domain name preservation system provided in some embodiments of the present application. DETAILED DESCRIPTION

[0055] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0056] It should be noted that although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be performed in a different order than that shown in the flowcharts. Terms used in the specification, claims, and drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0057] In the description of this application, if there is a description of first or second, it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features.

[0058] In the description of this application, unless otherwise clearly defined, terms such as setting, installing, and connecting should be understood in a broad sense, and technicians in the relevant technical field can reasonably determine the specific meanings of the above terms in this application based on the specific content of the technical solution.

[0059] First, some terms used in this application are explained:

[0060] The Domain Name System (DNS) is an internet service. As a distributed database that maps domain names to IP addresses, it facilitates internet access. A user seeking domain name resolution first sends a request to a local domain name server. If the local server is able to resolve the domain, the result is obtained directly. Otherwise, the local server sends a request to a root domain name server. Based on the pointer returned by the root domain name server, the server queries the next-level domain name server, and so on, ultimately obtaining the IP address for the domain name being resolved.

[0061] Domain Name Structure: DNS servers on the Internet are arranged in a hierarchy. Based on the roles played by domain name servers at different levels, domain name servers can be divided into several different types. The following is an introduction to several types of domain name servers involved in this application:

[0062] Root domain name server: the highest level domain name server and the most important domain name server;

[0063] Top-level domain name servers: In DNS, they are responsible for managing the next level of domain names (second-level domain names) registered with the top-level domain name server. The names and IP addresses of all top-level domain name servers are registered with the root server, which means that the root domain name server knows the names and IP addresses of all top-level domain name servers;

[0064] Authoritative domain name server: An authoritative domain name server usually refers to a server that manages second-level, third-level, fourth-level and other domain names below the top-level domain name.

[0065] Currently, the domain name system, as a distributed database that maps domain names and IP addresses to each other, enables people to access the Internet more conveniently and is one of the important infrastructures of the Internet. However, the domain name system also has risks: once the important domain name data in the domain name system is tampered with, the website corresponding to the important domain name data will be hijacked to other IP addresses, that is, there is a risk of hijacking. In related technologies, if a domain name is hijacked, it is generally the authoritative domain that is hijacked. The specific hijacking method is: by modifying the authoritative domain server record in the top-level domain server to point to a forged authoritative domain server, in order to achieve the purpose of forging the resolution result of any subdomain of the domain name, but there is currently no technology that can fundamentally alleviate the risk of authoritative domains being hijacked. How to alleviate the risk of authoritative domains being hijacked is an issue that urgently needs to be discussed and resolved.

[0066] Based on this, the domain name preservation method of the present application can alleviate the risk of authoritative domains being hijacked.

[0067] Referring to Figure 1, in a first aspect, an embodiment of the present application provides a domain name preservation method, which is applied to a recursive server in a domain name preservation system. The domain name preservation system also includes a local root server and a local top-level domain server. The domain name preservation method includes but is not limited to steps S110, S120, S130, S140, and S150.

[0068] S110, obtaining the domain name to be resolved sent by the client;

[0069] S120: Send a first acquisition request to the root server of the local domain according to the domain name to be resolved, so that the root server of the local domain returns the address of the top-level domain server of the local domain obtained in response to the first acquisition request;

[0070] S130: Send a second acquisition request to the top-level domain server of the local domain according to the address of the top-level domain server of the local domain, so that the top-level domain server of the local domain returns the address of the authoritative domain server corresponding to the domain name to be resolved according to the authoritative domain data;

[0071] S140: Send a subdomain name query request to the authoritative domain server corresponding to the domain name to be resolved, so that the authoritative domain server returns the address corresponding to the domain name to be resolved obtained in response to the subdomain name query request;

[0072] S150: Send the address corresponding to the domain name to be resolved to the client.

[0073] It should be noted that this application modifies the root pointing of the recursive server to the root server of this domain. In the domain name recursive resolution process, the recursive server directly sends a first acquisition request to the root server of this domain after obtaining the domain name to be resolved sent by the client, and receives the address of the top-level domain server of this domain returned by the root server of this domain. Then, the recursive server can connect to the top-level domain server of this domain according to the address of the top-level domain server of this domain, and receive the address of the authoritative domain server corresponding to the domain name to be resolved returned by the top-level domain server of this domain, without the need to directly connect to the top-level domain server. This effectively avoids the problem caused by tampering with the authoritative server of the top-level domain server when there is a risk of hijacking the authoritative domain, and alleviates the risk of hijacking the authoritative domain.

[0074] Referring to Figure 3, the normal domain name recursive resolution process is explained here using cctv.com as an example: (1) The client initiates a domain name query request to the recursive server, and the domain name query request includes the domain name to be resolved, cctv.com; (2) If the recursive server has an IP address corresponding to cctv.com in its cache, the IP address of cctv.com is directly returned; if the recursive server does not have an IP address corresponding to cctv.com in its cache, it first queries the .com top-level domain server from the global root server; (3) After querying the .com top-level domain server, the recursive server queries the .com top-level domain server for the address of the authoritative domain server of cctv.com; (4) The recursive server queries the authoritative domain server of cctv.com for the IP address corresponding to cctv.com; (5) The recursive server returns the query result to the client, that is, returns the IP address corresponding to cctv.com.

[0075] Referring to Figure 4, cctv.com is used as an example to illustrate the domain name recursive resolution process in the case of hijacking risk: (1) The client initiates a domain name query request to the recursive server, and the domain name query request includes the domain name to be resolved, cctv.com; (2) If the recursive server has an IP address corresponding to cctv.com in its cache, the IP address of cctv.com is directly returned; if the recursive server does not have an IP address corresponding to cctv.com in its cache, it first queries the global root server for the .com top-level domain server; (3) After querying the .com top-level domain server, the recursive server queries the .com top-level domain server for the address of the authoritative domain server of cctv.com. Since the authoritative domain server of cctv.com in the .com top-level domain server has been tampered with, the address of the authoritative domain server of cctv.com queried at this time is forged; (4) The recursive server queries the fake cctv.com authoritative domain server for the IP address corresponding to cctv.com, and the fake cctv.com authoritative domain server returns the forged IP address of cctv.com.

[0076] In response to the risk of hijacking, the present application proposes a domain name preservation method, which is applied to a domain name preservation system. The domain name preservation system includes a recursive server, a local domain root server, and a local domain top-level domain server. Referring to Figure 5, it should be noted that the present application first modifies the root pointing of the recursive server to the local domain root server (the local domain root servers are all automatically controllable root servers), and then points the top-level domain server to which the domain name to be resolved in the root zone record of the local domain root server belongs to the local domain top-level domain server (for example: the address of the cctv.com authoritative domain server is managed by the .com top-level domain server, and the top-level domain server to which the domain name to be resolved in the root zone record of the local domain root server belongs is pointed to the local domain top-level domain server, that is, the top-level domain server to which .com belongs is modified to the address of the .com local domain top-level domain server).

[0077] For example, cctv.com is taken as an example to illustrate the domain name preservation method of the present application: first, the recursive server receives the domain name cctv.com to be resolved sent by the client. At this time, because the root of the recursive server has been modified to the root server of the domain, the recursive server directly sends a first acquisition request to the root server of the domain for the domain name cctv.com to be resolved. Furthermore, because the root of the recursive server has been modified to the root server of the domain, the root server of the domain will return the address of the top-level domain server of the .com domain in response to the first acquisition request. The recursive server will send a second acquisition request to the top-level domain server of the .com domain based on the address of the top-level domain server of the .com domain to query the address of the authoritative domain server of the domain to be resolved. There is no need to directly connect to the top-level domain server, which effectively avoids the problem caused by the tampering of the authoritative server of the top-level domain server when there is a risk of hijacking of the authoritative domain. Specifically, the .com domain top-level domain server internally stores authoritative domain data that cannot be tampered with. Therefore, when the .com domain top-level domain server receives the second acquisition request, it will return the correct address of the authoritative domain server of cctv.com based on the authoritative domain data, thereby achieving authoritative domain preservation and alleviating the risk of hijacking. Among them, the authoritative domain data includes the correspondence between the domain name and the address of the authoritative domain server.

[0078] Furthermore, after obtaining the correct address of the authoritative domain server for cctv.com, the recursive server can send a subdomain query request to the cctv.com authoritative domain server, so that the cctv.com authoritative domain server can query the IP address corresponding to the domain name to be resolved and finally return the IP address corresponding to the domain name to be resolved to the client. This application achieves authoritative domain preservation by modifying the recursive server root pointer, modifying the top-level domain record in the root zone file of the local root server, and deploying the local top-level domain server, thereby mitigating the risk of hijacking.

[0079] According to another embodiment of the present application, when the cctv.com authoritative domain server cannot query the IP address corresponding to the domain name to be resolved, it will directly return an "NXDOMAIN error" prompt to the client.

[0080] 2 , in a second aspect, an embodiment of the present application provides a domain name preservation method, which is applied to a local top-level domain server in a domain name preservation system. The domain name preservation system also includes a local root server and a local top-level domain server. The domain name preservation method includes but is not limited to steps S210 and S220.

[0081] S210: Receive a second acquisition request, where the second acquisition request is obtained by the recursive server according to the domain name to be resolved sent by the client;

[0082] S220: Return the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server according to the authoritative domain data, so that the recursive server sends a subdomain query request to the authoritative domain server corresponding to the domain name to be resolved.

[0083] Exemplarily, after receiving the second acquisition request sent by the client, the top-level domain server of the domain will internally perform a query operation to query the stored authoritative domain data, and return the address of the authoritative domain server corresponding to the resolved domain name to the recursive server, wherein the authoritative domain data includes the correspondence between the domain name and the address of the authoritative domain server. The step of "returning the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server based on the authoritative domain data" is described in detail below:

[0084] 6 , it can be understood that the top-level domain server of this domain includes a cache module, the authoritative domain data includes first authoritative domain data, the cache module stores the first authoritative domain data, and returns the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server based on the authoritative domain data, including: querying whether the address of the authoritative domain server corresponding to the domain name to be resolved exists in the first authoritative domain data, and when the address of the authoritative domain server corresponding to the domain name to be resolved exists in the first authoritative domain data, outputting the address of the authoritative domain server corresponding to the domain name to be resolved.

[0085] Exemplarily, the cache module stores all the domain names to be resolved that have been resolved by the top-level domain server of this domain in the past and the addresses of the authoritative domain servers corresponding to the domain names to be resolved, that is, the first authoritative domain data. When the top-level domain server of this domain receives a second acquisition request sent by the recursive server, requesting to obtain the address of the authoritative domain server of the domain name to be resolved abcd.com, and the top-level domain server of this domain has already resolved the address of the authoritative domain server of abcd.com before receiving the second acquisition request, then the first authoritative domain data stored in the cache module of the top-level domain server of this domain includes abcd.com and the address of the authoritative domain server of abcd.com. When the domain name to be resolved and the address of the authoritative domain server of the domain name to be resolved exist in the first authoritative data, the top-level domain server of this domain can directly return the address of the authoritative domain server of abcd.com to the recursive resolver.

[0086] 6 , it can be understood that the top-level domain server of this domain also includes an authoritative domain preservation database, the authoritative domain data also includes second authoritative domain data, the authoritative domain preservation database stores the second authoritative domain data, and returns the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server based on the authoritative domain data, and also includes: when the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the first authoritative domain data, querying whether the address of the authoritative domain server corresponding to the domain name to be resolved exists in the second authoritative domain data; when the address of the authoritative domain server corresponding to the domain name to be resolved exists in the second authoritative domain data, outputting the address of the authoritative domain server corresponding to the domain name to be resolved, and updating the address of the authoritative domain server corresponding to the domain name to be resolved to the first authoritative domain data.

[0087] It should be noted that the authoritative domain preservation database stores second authoritative domain data. The second authoritative domain data is the relatively important domain names defined by the operator and the addresses of the authoritative domain servers corresponding to the domain names. The priority of the second authoritative domain data is higher than that of ordinary domain names and the address data of the authoritative domain servers corresponding to ordinary domain names (that is, the address data of the authoritative domain servers not stored in the cache module and the authoritative domain preservation database).

[0088] For example, during the recursive resolution of a domain name to be resolved, if the address of the authoritative domain server of the domain name to be resolved does not exist in the cache module, it means that before receiving the second acquisition request, the top-level domain server of this domain has not resolved the address of the authoritative domain server of the current domain name to be resolved. At this time, the second authoritative domain data is first queried to see whether there is a domain name to be resolved and the address of the authoritative domain server of the domain name to be resolved. Taking abcd.com as an example, when the second authoritative domain data contains abcd.com and the address of the authoritative domain server of abcd.com, the address of the authoritative domain server of abcd.com is output. At the same time, in order to ensure that the address of the authoritative domain server of abcd.com is obtained more quickly in the event that abcd.com still needs to be resolved, the addresses of abcd.com and the authoritative domain server of abcd.com need to be stored in the cache module as the first authoritative domain data.

[0089] The above are the detailed steps of "returning the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server based on the authoritative domain data".

[0090] 6 , it can be understood that the top-level domain server of this domain further includes a proxy module, and the preservation method further includes: when the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the authoritative domain data, obtaining the address of the authoritative domain server corresponding to the domain name to be resolved through the proxy module, outputting the address of the authoritative domain server corresponding to the domain name to be resolved, and updating the address of the authoritative domain server corresponding to the domain name to be resolved to the first authoritative domain data.

[0091] It should be noted that the proxy module is communicated with the global root server and the top-level domain server respectively, and is used to connect the top-level domain server of the domain with the top-level domain server and the global root server.

[0092] For example, taking abcd.com as an example, when the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the authoritative domain data, it means that the address of the authoritative domain server corresponding to the domain name to be resolved abcd.com does not exist in the cache module and the authoritative domain preservation database. The address of the authoritative domain server for the domain name to be resolved abcd.com is not stored in the top-level domain server of the current domain. The priority of the address of the authoritative domain server of abcd.com is not high, so it is necessary to obtain the address of the authoritative domain server of abcd.com from the top-level domain server through the proxy module and output the address of the authoritative domain server of abcd.com. At the same time, in order to ensure that the address of the authoritative domain server of abcd.com is obtained more quickly in the future when abcd.com still needs to be resolved, it is also necessary to store the address of abcd.com and the authoritative domain server of abcd.com as the first authoritative domain data in the cache module.

[0093] It is understandable that when the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the authoritative domain data, the address of the authoritative domain server corresponding to the domain name to be resolved can also be obtained through the proxy module, the address of the authoritative domain server corresponding to the domain name to be resolved can be output, and finally the address of the authoritative domain server corresponding to the domain name to be resolved can be updated to the second authoritative domain data. Among them, the priority of the second authoritative domain data is lower than the priority of the first authoritative domain data. In the process of recursive resolution, the top-level domain server of this domain will first query whether the address of the authoritative domain server of the domain name to be resolved exists in the first authoritative domain data. Therefore, if the address of the authoritative domain server corresponding to the domain name to be resolved can be updated to the first authoritative domain data, there is no need to update the address of the authoritative domain server corresponding to the domain name to be resolved to the second authoritative domain data. However, if the address of the authoritative domain server corresponding to the domain name to be resolved cannot be updated to the first authoritative domain data, the address of the authoritative domain server corresponding to the domain name to be resolved can be updated to the second authoritative domain data.

[0094] 7 , a second embodiment of the present application provides a domain name preservation method, including but not limited to steps S310 and S320 .

[0095] S310, sending a third acquisition request to the global root server, so that the global root server returns the address of the top-level domain server obtained in response to the third acquisition request;

[0096] S320: Send a resolution request to the top-level domain server according to the address of the top-level domain server, so that the top-level domain server returns the address of the authoritative domain server corresponding to the domain name to be resolved obtained in response to the resolution request.

[0097] It should be noted that when the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the authoritative domain data, domain name resolution is performed according to the normal recursive domain name resolution process in Figure 3. However, in this step of the present application, the proxy module replaces the function of the recursive server in Figure 3. The proxy module first sends a third acquisition request to the global root server. After receiving the third acquisition request, the global root server returns the address of the top-level domain server for the domain name to be resolved to the proxy module. The proxy module then sends a resolution request to the top-level domain server corresponding to the domain name to be resolved, causing the top-level domain server to return the address of the authoritative domain server for the domain name to be resolved. It is understood that in the present application, the top-level domain server of the local domain can achieve a more comprehensive query of the address of the authoritative domain server through the internally configured proxy module.

[0098] 8 , the method for preserving a complete domain name in this application is described as follows:

[0099] (1) The client initiates a domain name query request to the recursive server, and the domain name query request includes the domain name to be resolved;

[0100] (2) For the domain name to be resolved, the recursive server directly sends a first acquisition request to the root server of the domain. The root server of the domain responds to the first acquisition request and returns the address of the top-level domain server of the domain.

[0101] (3) The recursive server sends a second acquisition request to the top-level domain server of the domain according to the address of the top-level domain server of the domain, in order to query the address of the authoritative domain server of the domain name to be resolved. This step specifically includes:

[0102] (3-1) When the cache module of the top-level domain server of the domain contains the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved, the address of the authoritative domain server of the domain name to be resolved is returned to the recursive server;

[0103] (3-2) When the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved do not exist in the cache module, query whether the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved exist in the authoritative domain preservation database of the top-level domain server of the domain; when the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved exist in the authoritative domain preservation database, return the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server, and update the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved as the first authoritative domain data into the cache module;

[0104] (3-3) When the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved do not exist in the authoritative domain preservation database, a third acquisition request is sent to the global root server through the proxy module of the top-level domain server of the domain, so that the global root server returns the address of the top-level domain server, and a resolution request is sent to the top-level domain server, so that the top-level domain server returns the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved, the address of the authoritative domain server corresponding to the domain name to be resolved is returned to the recursive server, and the domain name to be resolved and the address of the authoritative domain server corresponding to the domain name to be resolved are updated as the first authoritative domain data in the cache module;

[0105] (4) After querying the address of the authoritative domain server corresponding to the domain name to be resolved, send a subdomain query request to the authoritative domain server, so that the authoritative domain server returns the IP address corresponding to the domain name to be resolved in response to the subdomain query request;

[0106] (5) Return the IP address corresponding to the domain name to be resolved to the client.

[0107] The domain name preservation method of the present application can achieve the preservation of key authoritative domains, alleviating the hijacking risk of the authoritative domains.

[0108] It can be understood that the top-level domain server of this domain also includes an authoritative domain data acquisition module, and the preservation method also includes: obtaining the authoritative domain preservation data of all alliance members in the alliance blockchain through the authoritative domain data acquisition module, and updating the authoritative domain preservation data as the second authoritative domain data to the authoritative domain preservation database, wherein the authoritative domain preservation data includes the correspondence between the domain name and the address of the authoritative domain server.

[0109] Referring to FIG6 , it should be noted that the authoritative domain data acquisition module of the present application acquires the authoritative domain preservation data of all alliance members in the consortium blockchain at preset intervals, and upon acquiring the authoritative domain preservation data of all alliance members, updates it as second authoritative domain data into the authoritative domain preservation database. Specifically, the top-level domain server of this domain is a node in the consortium blockchain (i.e., the top-level domain server of this domain corresponds to a consortium member in the consortium blockchain). The consortium blockchain stores the authoritative domain preservation data reported by each node. The top-level domain server of this domain includes the authoritative domain data acquisition module and the authoritative domain preservation database. The authoritative domain preservation data in the authoritative domain preservation database all comes from the consortium blockchain.

[0110] It should be noted that this application can provide the resolution capability of the top-level domain server based on the cache module, the authoritative domain preservation database, the authoritative domain acquisition module and the proxy module while achieving the preservation of key authoritative domains.

[0111] 9 , a second embodiment of the present application provides a domain name preservation method, including but not limited to steps S410 and S420 .

[0112] S410, obtaining the priority level of the authority domain preservation data;

[0113] S420 , updating the authoritative domain preservation data as second authoritative domain data into the authoritative domain preservation database in descending order of priority of the authoritative domain preservation data.

[0114] Exemplarily, the top-level domain server of this domain stores the authoritative domain preservation data as the second authoritative domain data in the authoritative domain preservation database according to the priority level of the authoritative domain preservation data. For example: there are authoritative domain preservation data a, authoritative domain preservation data b and authoritative domain preservation data c first, and the priority of authoritative domain preservation data a is greater than the priority of authoritative domain preservation data b, and the priority of authoritative domain preservation data b is greater than the priority of authoritative domain preservation data c. Therefore, when updating the authoritative domain preservation data a, the authoritative domain preservation data b and the authoritative domain preservation data c to the authoritative domain preservation database, the authoritative domain preservation data a is first updated as the second authoritative domain data to the authoritative domain preservation database, and the authoritative domain preservation data b is second as the second authoritative domain data to the authoritative domain preservation database, and finally the authoritative domain preservation data c is updated as the second authoritative domain data to the authoritative domain preservation database.

[0115] It can be understood that the alliance blockchain is obtained by the following steps: building a alliance blockchain based on a private chain, wherein each alliance member in the alliance blockchain corresponds to a top-level domain server in the local domain.

[0116] It can be understood that before obtaining the authoritative domain preservation data of all alliance members in the alliance blockchain through the authoritative domain data acquisition module, it also includes: receiving the authoritative domain preservation data uploaded by the units to which the authoritative domain belongs, and reviewing the authoritative domain preservation data uploaded by the units to which the authoritative domain belongs, and reporting the updated authoritative domain preservation data to the alliance blockchain after passing the review.

[0117] Referring to Figure 6, it should be noted that in the alliance blockchain, the top-level domain servers of this domain are mainly divided according to national and regional standards, that is, a country / region is an alliance member in the alliance blockchain, and one alliance member corresponds to a top-level domain server of this domain.

[0118] As an example, the process of building a consortium blockchain is described here: first, a decentralized consortium blockchain is built based on the private chain in the blockchain, and each consortium member in the consortium blockchain corresponds to a local top-level domain server. After the consortium blockchain is built, the companies and units affiliated with the authoritative domain update the authoritative domain preservation data to the local top-level domain server. A dedicated review module in the local top-level domain server performs a security review on the authoritative domain preservation data in the local top-level domain server. After the security review of the authoritative domain preservation data is passed, the local top-level domain server reports the qualified authoritative domain preservation data to the consortium blockchain. At this time, all consortium members of the consortium blockchain (i.e., the local top-level domain servers) can obtain the authoritative domain preservation data from the consortium blockchain through the authoritative domain acquisition module and update the obtained authoritative domain preservation data as the second authoritative domain data into the authoritative domain preservation database. For example, if a company / unit in a certain country has authoritative domain preservation data for abcd.com and the address of the authoritative domain server corresponding to abcd.com, the company / unit needs to update the address of the authoritative domain server corresponding to abcd.com and abcd.com to the top-level domain server corresponding to the country, and the country's review agency will conduct a security review of the top-level domain server of the domain. After the security review of the address of the authoritative domain server corresponding to abcd.com and abcd.com passes, the top-level domain server of the domain in the country will report the address of the authoritative domain server corresponding to abcd.com and abcd.com to the alliance blockchain. After that, the top-level domain servers of other countries in the alliance blockchain can obtain the address of the authoritative domain server corresponding to abcd.com and abcd.com from the alliance blockchain through the authoritative domain acquisition module, and update the address of the authoritative domain server corresponding to abcd.com and abcd.com as the second authoritative data to the authoritative domain preservation database of the top-level domain server of the domain in the country.

[0119] In a third aspect, referring to FIG. 10 , an embodiment of the present application provides a domain name preservation system, including:

[0120] at least one memory 200;

[0121] at least one processor 100;

[0122] at least one program;

[0123] Programs are stored in the memory 200, and the processor 100 executes at least one program to implement:

[0124] A domain name preservation method as in any embodiment of the first aspect of the present application.

[0125] The processor 100 and the memory 200 may be connected via a bus or other means.

[0126] The memory 200 is a non-transitory readable storage medium that can be used to store non-transitory software instructions and non-transitory instructions. In addition, the memory 200 may include a high-speed random access memory 200, and may also include a non-transitory memory 200, such as at least one disk storage device 200, a flash memory device, or other non-transitory solid-state storage device 200. It is understood that the memory 200 optionally includes a memory 200 remotely located relative to the processor 100, and these remote memories 200 can be connected to the processor 100 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0127] The processor 100 executes non-transitory software instructions, commands, and signals stored in the memory 200, thereby performing various functional applications and data processing, thereby implementing the domain name preservation method of the first embodiment described above.

[0128] The non-transient software instructions and instructions required to implement the domain name preservation method of the above-mentioned embodiment are stored in the memory 200. When executed by the processor 100, the domain name preservation method of the first aspect embodiment of the present application is executed, for example, the method steps S110 to S150 in Figure 1, the method steps S210 to S220 in Figure 2, steps S310 to S320 in Figure 7, and steps S410 to S420 in Figure 9 described above are executed.

[0129] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer-executable signal, and the computer-executable signal is used to execute:

[0130] A method for preserving a domain name according to any embodiment of the first aspect of the application.

[0131] For example, the method steps S110 to S150 in FIG. 1 , the method steps S210 to S220 in FIG. 2 , the steps S310 to S320 in FIG. 7 , and the steps S410 to S420 in FIG. 9 described above are executed.

[0132] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected based on actual needs to achieve the objectives of this embodiment.

[0133] By the description of the above embodiments, it will be appreciated by those skilled in the art that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a readable medium, and the readable medium can include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As known to those skilled in the art, the term computer storage medium is included in any method or technology for storing information (such as a computer-readable signal, a data structure, an instruction module or other data) and is volatile and non-volatile, removable and non-removable. Computer storage media includes but is not limited to RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, magnetic tape, disk storage or other magnetic storage device, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable signals, data structures, instruction modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0134] The embodiments of the present application are described in detail above in conjunction with the accompanying drawings, but the present application is not limited to the above embodiments. Various changes can be made within the scope of knowledge possessed by ordinary technicians in the relevant technical field without departing from the purpose of the present application.

Claims

1. A domain name preservation method, characterized in that: A recursive server is used in a domain name preservation system, wherein the domain name preservation system further includes a local root server and a local top-level domain server, and the local top-level domain server stores authoritative domain data, wherein the authoritative domain data includes a correspondence between a domain name and an address of an authoritative domain server. The preservation method includes: Get the domain name to be resolved sent by the client; Sending a first acquisition request to a local domain root server according to the domain name to be resolved, so that the local domain root server returns an address of a local domain top-level domain server obtained in response to the first acquisition request; Sending a second acquisition request to the local top-level domain server according to the address of the local top-level domain server, so that the local top-level domain server returns the address of the authoritative domain server corresponding to the domain name to be resolved according to the authoritative domain data; Sending a subdomain name query request to the authoritative domain server corresponding to the domain name to be resolved, so that the authoritative domain server returns the address corresponding to the domain name to be resolved obtained in response to the subdomain name query request; The address corresponding to the domain name to be resolved is sent to the client.

2. A domain name preservation method, characterized in that: A local top-level domain server is applied to a domain name preservation system, wherein the domain name preservation system further includes a recursive server, and the local top-level domain server stores authoritative domain data, wherein the authoritative domain data includes a correspondence between a domain name and an address of an authoritative domain server. The preservation method includes: receiving a second acquisition request, wherein the second acquisition request is obtained by the recursive server according to the domain name to be resolved sent by the client; The address of the authoritative domain server corresponding to the domain name to be resolved is returned to the recursive server according to the authoritative domain data, so that the recursive server sends a subdomain query request to the authoritative domain server corresponding to the domain name to be resolved.

3. The domain name preservation method according to claim 2, characterized in that: The top-level domain server of the local domain includes a cache module, the authoritative domain data includes first authoritative domain data, the cache module stores the first authoritative domain data, and returning the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server according to the authoritative domain data includes: Query the first authoritative domain data to see whether the address of the authoritative domain server corresponding to the domain name to be resolved exists in the first authoritative domain data. If the address of the authoritative domain server corresponding to the domain name to be resolved exists in the first authoritative domain data, output the address of the authoritative domain server corresponding to the domain name to be resolved.

4. The domain name preservation method according to claim 3, characterized in that: The local top-level domain server further includes an authoritative domain preservation database, the authoritative domain data further includes second authoritative domain data, the authoritative domain preservation database stores the second authoritative domain data, and the returning the address of the authoritative domain server corresponding to the domain name to be resolved to the recursive server according to the authoritative domain data further includes: When the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the first authoritative domain data, query whether the address of the authoritative domain server corresponding to the domain name to be resolved exists in the second authoritative domain data; when the address of the authoritative domain server corresponding to the domain name to be resolved exists in the second authoritative domain data, output the address of the authoritative domain server corresponding to the domain name to be resolved, and update the address of the authoritative domain server corresponding to the domain name to be resolved to the first authoritative domain data.

5. The domain name preservation method according to claim 4, characterized in that: The local top-level domain server further includes a proxy module, and the security method further includes: When the address of the authoritative domain server corresponding to the domain name to be resolved does not exist in the authoritative domain data, the proxy The module obtains the address of the authoritative domain server corresponding to the domain name to be resolved, outputs the address of the authoritative domain server corresponding to the domain name to be resolved, and updates the address of the authoritative domain server corresponding to the domain name to be resolved into the first authoritative domain data.

6. The domain name preservation method according to claim 5, characterized in that: The proxy module is respectively connected to the global root server and the top-level domain server in communication, and obtaining the address of the authoritative domain server corresponding to the domain name to be resolved through the proxy module includes: Sending a third acquisition request to the global root server, so that the global root server returns the address of the top-level domain server obtained in response to the third acquisition request; A resolution request is sent to the top-level domain server according to the address of the top-level domain server, so that the top-level domain server returns the address of the authoritative domain server corresponding to the domain name to be resolved obtained in response to the resolution request.

7. The domain name preservation method according to claim 4, characterized in that: The local top-level domain server further includes an authoritative domain data acquisition module, and the preservation method further includes: The authoritative domain preservation data of all alliance members in the alliance blockchain is obtained through the authoritative domain data acquisition module, and the authoritative domain preservation data is updated as the second authoritative domain data into the authoritative domain preservation database, wherein the authoritative domain preservation data includes the correspondence between the domain name and the address of the authoritative domain server.

8. The domain name preservation method according to claim 7, characterized in that: The updating of the authoritative domain preservation data as second authoritative domain data into the authoritative domain preservation database includes: Obtaining the priority level of the authoritative domain preservation data; The authoritative domain preservation data is updated into the authoritative domain preservation database as second authoritative domain data in order of priority from high to low.

9. The domain name preservation method according to claim 7, characterized in that: The consortium blockchain is obtained by the following steps: A consortium blockchain is constructed based on a private chain, wherein each consortium member in the consortium blockchain corresponds to a top-level domain server in the local domain.

10. The domain name preservation method according to claim 9, characterized in that: Before obtaining the authoritative domain preservation data of all alliance members in the alliance blockchain through the authoritative domain data acquisition module, the method further includes: Receive the authoritative domain preservation data uploaded by the units belonging to the authoritative domain, review the authoritative domain preservation data uploaded by the units belonging to the authoritative domain, and report the updated authoritative domain preservation data to the alliance blockchain after passing the review.

11. A domain name preservation system, characterized in that: include: at least one memory; at least one processor; at least one program; The programs are stored in the memory, and the processor executes at least one of the programs to implement: A domain name preservation method according to any one of claims 1 to 10.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer-executable signal, wherein the computer-executable signal is used to execute: A domain name preservation method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • DNS method, DNS recursive server and DNS system

    CN105357328A

  • Domain name resolution method and device, electronic equipment and storage medium

    CN110474994A

  • Domain name management method, domain name resolution method and device

    CN112583946A

  • DNS network system, domain-name parsing method and system

    US20200084177A1