Domain name resolution method, system and apparatus for edge computing, and device and medium
By converting and sending domain name resolution requests to the authoritative domain name system in edge cloud computing scenarios, the problems of large DNS scale, high maintenance difficulty and high deployment cost in edge data centers are solved, and efficient and reliable domain name resolution services are achieved.
Patent Information
- Application Number
- PCT/CN2025/080399
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-21
- Filing Date
- 2025-03-04
- Publication Date
- 2025-09-25
AI Technical Summary
In the edge cloud computing scenario, the wide distribution of edge data centers leads to problems such as large DNS scale, high maintenance difficulty, and high deployment cost. In particular, small data centers have low DNS traffic and insufficient resources, making them unable to provide other cloud computing services.
The resolver in the first edge computer room converts the domain name resolution request into a second domain name resolution request, and sends it to the authoritative domain name system of the second edge computer room for resolution. The load balancing device is used to distribute the request and feedback of the domain name resolution result is achieved, thus avoiding the need to independently deploy a DNS system for each edge computer room.
It effectively reduces the scale of DNS, reduces maintenance difficulty and deployment costs, while ensuring the reliability and flexibility of domain name resolution, and adapts to the needs of edge cloud computing scenarios.
Smart Images

Figure CN2025080399_25092025_PF_FP_ABST
Abstract
Description
Domain name resolution method, system, device, equipment and medium for edge computing
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed on March 21, 2024, with application number 202410330082.X and invention name “Domain name resolution method, system, device, equipment and medium for edge computing”. The entire contents of that application are incorporated by reference into this application. Technical Field
[0003] The present disclosure relates to the field of edge cloud technology, and in particular to a domain name resolution method, system, device, equipment, and medium for edge computing. Background Art
[0004] Edge cloud computing is a new type of cloud computing scenario. In edge cloud computing, the cloud is typically deployed in edge data centers close to users, significantly different from the central data centers in traditional centralized cloud computing. While the central data centers in traditional centralized cloud computing are typically concentrated in a limited number of large data centers, edge data centers in edge cloud computing are typically highly dispersed, consisting of several widely distributed small data centers. Communication between these data centers is achieved through external networks, internal networks, dedicated lines, or VPNs (Virtual Private Networks). Summary of the Invention
[0005] In view of this, the present disclosure provides a domain name resolution method, system, apparatus, device and medium for edge computing.
[0006] In a first aspect, the present disclosure provides a domain name resolution method for edge computing, which is applied to a resolver. The domain name resolution method for edge computing includes:
[0007] Obtaining a first domain name resolution request forwarded by the virtual device through the network module, where the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is located in a first edge computer room;
[0008] Converting the first domain name resolution request into a second domain name resolution request, and sending the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is located in a second edge computer room;
[0009] Receive a resolution result of the second domain name resolution request from the authoritative domain name system, and forward the resolution result to the virtual device through the network module.
[0010] In a second aspect, the present disclosure provides a domain name resolution system for edge computing, the domain name resolution system for edge computing comprising:
[0011] Virtual device, used to send private network domain name resolution requests to the network module;
[0012] A network module, configured to convert the private network domain name resolution request into a first domain name resolution request, and to send the first domain name resolution request to a resolver;
[0013] a resolver, configured to convert the first domain name resolution request into a second domain name resolution request, and to send the second domain name resolution request to an authoritative domain name system; wherein the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is disposed in a first edge computer room;
[0014] The authoritative domain name system is used to resolve the second domain name resolution request to obtain a resolution result; the authoritative domain name system is also used to send the resolution result to the resolver; the authoritative domain name system is deployed on a second physical machine, and the second physical machine is set in a second edge computer room;
[0015] The parser is also used to forward the parsing results to the network module;
[0016] The network module is also used to forward the parsing results to the virtual device.
[0017] In a third aspect, the present disclosure provides a domain name resolution device for edge computing, the domain name resolution device for edge computing comprising:
[0018] an acquiring unit, configured to acquire a first domain name resolution request forwarded by the virtual device through the network module, wherein the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is disposed in a first edge computer room;
[0019] a conversion unit, configured to convert the first domain name resolution request into a second domain name resolution request, and to send the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is disposed in a second edge computer room;
[0020] The response unit is used to receive the resolution result of the authoritative domain name system for the second domain name resolution request, and to forward the resolution result to the virtual device through the network module.
[0021] In a fourth aspect, the present disclosure provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the domain name resolution method for edge computing of the above-mentioned first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0022] In a fifth aspect, the present disclosure provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the domain name resolution method for edge computing of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0024] FIG1 is a flow chart of a domain name resolution method for edge computing according to an embodiment of the present disclosure;
[0025] FIG2 is a flow chart of another domain name resolution method for edge computing according to an embodiment of the present disclosure;
[0026] FIG3 is a flow chart of another domain name resolution method for edge computing according to an embodiment of the present disclosure;
[0027] FIG4 is a schematic diagram of an arrangement of virtual devices according to an embodiment of the present disclosure;
[0028] FIG5 is a schematic diagram illustrating an implementation principle of a domain name resolution method for edge computing according to an embodiment of the present disclosure;
[0029] FIG6 is a schematic diagram of the structure of a virtual extended LAN message according to an embodiment of the present disclosure;
[0030] FIG7 is a schematic diagram of the structure of a message constructed based on the extended domain name resolution protocol;
[0031] FIG8 is a schematic diagram of the structure of an extended domain name resolution message according to an embodiment of the present disclosure;
[0032] 9 is a schematic diagram illustrating the implementation principle of the edge private network domain name system console issuing configuration information according to an embodiment of the present disclosure;
[0033] FIG10 is a structural block diagram of a domain name resolution device for edge computing according to an embodiment of the present disclosure;
[0034] FIG11 is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0035] To make the purpose, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present disclosure.
[0036] The edge cloud computing scenario is a new type of cloud computing scenario. The cloud in the edge cloud computing scenario is usually sunk to the edge computer room close to the user side, which is quite different from the central computer room in the traditional central cloud computing scenario. The central computer room in the traditional central cloud computing scenario is usually concentrated in a limited number of large computer rooms, while the edge computer rooms in the edge cloud computing scenario are usually very discrete, specifically including several widely distributed small computer rooms. The interconnection between different edge computer rooms can be achieved through the external network or the internal network or a dedicated line or a VPN (Virtual Private Network) to open up the communication connection between different edge computer rooms. In the related technology, the method of deploying DNS (Domain Name System) in the central computer room can be used to deploy DNS for the edge computer room. However, the edge computer rooms are widely distributed. The solution of deploying a set of DNS for each edge computer room will result in a very large scale of DNS, high maintenance difficulty and high deployment cost.
[0037] In cloud computing scenarios, a virtual private cloud (VPC) can be used to represent the dynamic configuration of cloud computing resources. A VPC is generally an on-cloud network and can be implemented using VXLAN (Virtual eXtensible Local Area Network), while the off-cloud network generally refers to the underlying physical machine network. Users can create different VPCs to isolate the intranets of different tenants, thereby preventing interference between virtual devices and other resources of different tenants. Virtual devices in cloud computing scenarios (such as virtual machines or containers) are often the source of DNS resolution requests. These virtual device resources are typically virtualized on physical machines, and virtual devices under different VPCs can be created on a single physical machine.
[0038] Cloud computing scenarios primarily include central cloud computing and edge cloud computing. In traditional central cloud computing scenarios, DNS resolution services within the central data center allow each tenant to customize domain name resolution to prevent interference and isolate tenants. For example, Private Zones or Private DNS can be used to implement tenant isolation. Both approaches utilize tenant isolation services deployed in the cloud, with each central data center equipped with a DNS cluster. By combining physical resources with network virtualization, resolution isolation is achieved at the software level. However, implementing these solutions in edge cloud computing requires deploying a private DNS cluster in each data center, resulting in a large DNS footprint and inconvenient maintenance. Furthermore, some small data centers have very low DNS traffic, making deploying a separate DNS cluster for each data center prohibitively expensive and cost-effective. Furthermore, some edge data centers are very small, with only a single physical server. This can result in the physical servers in these edge data centers being used solely for DNS resolution services and unable to provide other cloud computing services. Therefore, if the DNS deployment solution of the central computer room is directly applied to the edge computer room, the small edge computer room may not have enough resources to deploy DNS. Even if all edge computer rooms have sufficient resources for deploying DNS, it will lead to problems such as very large DNS scale and very high deployment costs.
[0039] According to an embodiment of the present disclosure, an embodiment of a domain name resolution method for edge computing is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0040] In this embodiment, a domain name resolution method for edge computing is provided, which can be applied to a resolver. FIG1 is a flow chart of the domain name resolution method for edge computing according to an embodiment of the present disclosure. As shown in FIG1 , the process includes the following steps:
[0041] Step S101: obtaining a first domain name resolution request forwarded by a virtual device through a network module, wherein the virtual device, the network module and the resolver are all deployed on a first physical machine, and the first physical machine is set in a first edge computer room.
[0042] Among them, the first edge computer room in this embodiment is an edge computer room in an edge computing scenario. The virtual device includes at least one of a virtual machine and a container. The following implementation method is explained based on the implementation of the virtual device as a virtual machine. The implementation of the virtual device as a container is similar.
[0043] In some optional implementations, the network module is a network connection component, and the network module can be, for example, a virtual switch (vSwitch). In this embodiment, the cloud network and the cloud network can be connected through the vSwitch, and the DNS data packets sent from the virtual device can be forwarded to the resolver. The resolver (Resolver) in this embodiment is specifically a resolution node, which generally belongs to a component of DNS recursive iteration. It can divert DNS requests, forward the intranet tenant domain name to the authoritative DNS, and forward the recursive resolution request of the external network to the external network (Internet). Of course, the DNS resolution request can also be cached. The content cached by the resolver (Resolver) can be distinguished by VNI (VXLAN Network ID, virtual extended local area network identifier).
[0044] As shown in Figure 4, a first physical machine A and a first physical machine B are shown. Virtual machines 01, 02, 03, and a network module M (vSwitch) can be deployed on the first physical machine A, and virtual machines 04, 05, and a network module N (vSwitch) can be deployed on the first physical machine B.
[0045] For example, a user can create VPC1 and VPC2. VPC1 includes VMs 02, 03, and 04, while VPC2 includes VMs 01 and 05. VMs 01, 02, and 03 communicate with each other and external devices via network module M (vSwitch). VMs 04 and 05 communicate with each other and external devices via network module N (vSwitch). Network modules M (vSwitch) and N (vSwitch) communicate with each other. VPCs can be sold as independent units and provided to users. Different VPCs are isolated from each other and do not interfere with each other.
[0046] As shown in FIG5 , in some embodiments, a first physical machine A and a first physical machine B are deployed in a first edge computer room X. Virtual machines 01, 02, and 03, a network module M (vSwitch), and a resolver P (Resolver) can be deployed on first physical machine A. Virtual machines 04, 05, and 06, a network module N (vSwitch), and a resolver Q (Resolver) can be deployed on first physical machine B. Virtual machines 01, 02, and 03 are each connected to the network module M (vSwitch), which is in turn connected to the resolver P (Resolver). Virtual machines 04, 05, and 06 are each connected to the network module N (vSwitch), which is in turn connected to the resolver Q (Resolver). Optionally, each virtual machine can point to a virtual resolver address, which can be the same globally and essentially represents the resolver on the physical machine. In this embodiment, the Resolver software can be deployed separately on each first physical machine in the first edge computer room. The Resolver software does not need to occupy an independent physical machine / virtual machine, thereby greatly saving the physical cost of the DNS. The deployment cost of the DNS does not increase linearly with the increase in the scale of the edge computer room. It can be seen that this embodiment greatly reduces the deployment cost of the DNS.
[0047] In this embodiment, the virtual device sends a private network DNS resolution request (private network domain name resolution request) to the network module, and the network module converts the private network DNS resolution request into a first domain name resolution request; for example, at least one virtual machine among virtual machines 01, 02, and 03 sends a private network DNS resolution request to the network module M (vSwitch), or at least one virtual machine among virtual machines 04, 05, and 06 sends a private network DNS resolution request to the network module N (vSwitch). The network module M (vSwitch) or the network module N (vSwitch) can convert the received private network domain name resolution request into a first domain name resolution request, and send the first domain name resolution request to the corresponding resolver.
[0048] In some optional embodiments, before obtaining the first domain name resolution request forwarded by the virtual device through the network module, the domain name resolution method also includes: obtaining configuration information issued by the edge private network domain name system console, the configuration information is used to characterize the resolution rules for the target domain name resolution request, and the target domain name resolution request includes the first domain name resolution request.
[0049] Among them, the resolution rules for the target domain name resolution request indicate that some pre-configured target domain names can be resolved through authoritative DNS, while for domain names that are not within the target domain name range, they can be transferred to the external network for recursive iterative resolution.
[0050] As shown in Figure 9, the edge private network domain name system console receives user configuration related information, which includes configuration information and DNS resolution rule information. The edge private network domain name system console is used to configure the resolver's (Resolver) resolution rules for target domain name resolution requests, and to configure authoritative DNS resolution rules. Specifically, the resolver (Resolver) obtains the configuration information of the edge private network domain name system console, and then can perceive which domain names need to be forwarded to the authoritative DNS for resolution; for domain names that cannot be resolved, the resolver (Resolver) goes to the external network and performs recursive iterative resolution. The authoritative DNS resolves the received domain name resolution request based on the DNS resolution rule information issued by the edge private network domain name system console.
[0051] The disclosed embodiment adopts the method of sending configuration information from the edge private network domain name system console to the resolver, so that the resolver can accurately perceive which domain name resolution requests can be sent to the authoritative DNS for resolution, and which domain name resolution requests cannot be resolved by the authoritative DNS and can only be sent to the external network for iterative resolution. The process of receiving user-configured configuration information and sending and taking effect through the edge private network domain name system console can effectively improve the reliability and flexibility of the domain name resolution process.
[0052] Step S102: convert the first domain name resolution request into a second domain name resolution request, and send the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is set in a second edge computer room.
[0053] The authoritative domain name system deployed on the second physical machine can provide domain name resolution resources for the virtual devices on the first physical machine. The domain name resolution resources are specifically provided as shared resources to the virtual machines deployed in the first edge computer room.
[0054] The second edge computer room in this embodiment is an edge computer room in an edge computing scenario. The second edge computer room and the first edge computer room are two independent computer rooms, and the second physical machine in the second edge computer room is communicatively connected to the first physical machine in the first edge computer room. The communication between the first edge computer room and the second edge computer room can be a dedicated line or an extranet communication method. For example, if there is a VPN in the extranet, the first edge computer room and the second edge computer room can be connected through the VPN. Moreover, this embodiment can also encrypt the communication data message, and the encryption method can be selected from related technologies. The authoritative domain name system in this embodiment is the authoritative DNS. The authoritative domain name system is a server responsible for private network domain name resolution.
[0055] In some optional implementations, the second edge computer room is, for example, a central computer room in a central cloud computing scenario. In this embodiment, the second edge computer room is a computer room with high stability. Optionally, the authoritative domain name system in the second edge computer room can reuse the private network authoritative DNS resources of the central computer room.
[0056] In some optional implementations, the number of the second edge computer rooms is at least two, and may include, for example, the second edge computer room Y and the second edge computer room Z shown in FIG5 .
[0057] The disclosed embodiment improves the reliability of responses to domain name resolution requests through at least two second edge computer rooms. Even if an unexpected failure occurs in one of the second edge computer rooms, authoritative DNS resources can still be provided by the second edge computer room that has not failed, thereby ensuring business continuity and reliability.
[0058] As shown in FIG5 , the resolver in this embodiment may be, for example, a resolver P (Resolver) or a resolver Q (Resolver). The resolver P (Resolver) is used to convert the first domain name resolution request sent by the network module M (vSwitch, virtual switch) into a second domain name resolution request, and the resolver Q (Resolver) is used to convert the first domain name resolution request sent by the network module N (vSwitch) into a second domain name resolution request. Next, the resolver P (Resolver) or the resolver Q (Resolver) is used to send the second domain name resolution request to the corresponding authoritative DNS. The authoritative DNS may include, for example, authoritative DNS 11, authoritative DNS 12, and authoritative DNS 13 deployed in the second edge computer room Y, and / or authoritative DNS 14, authoritative DNS 15, and authoritative DNS 16 deployed in the second edge computer room Z. Thus, the resolver in this embodiment can connect the virtual network and the physical network, and use the physical network to carry DNS data and interact with the authoritative DNS.
[0059] In some optional implementations, sending the second domain name resolution request to the authoritative domain name system includes: sending the second domain name resolution request to a load balancing device, the load balancing device being configured to distribute the second domain name resolution request to the authoritative domain name system.
[0060] In this embodiment, the access to the authoritative domain name system can be handled by a load balancing device, and the external network IP (Internet Protocol) of the load balancing device can publish an Anycast address (the same IP), so that disaster recovery and local access can be achieved.
[0061] As shown in Figure 5, for the process in which the resolver P (Resolver) or the resolver Q (Resolver) sends the second domain name resolution request to the corresponding authoritative DNS, this embodiment can divert multiple second domain name resolution requests through the load balancing device R (LB, Load Balance) or the load balancing device S (LB) to distribute the second domain name resolution request to the corresponding authoritative DNS, such as any one of DNS11, authoritative DNS12, authoritative DNS13, authoritative DNS14, authoritative DNS15, and authoritative DNS16. The load balancing device in this embodiment can be deployed on a third physical machine in the second edge computer room, and the third physical machine is the same as or different from the second physical machine. The specific process of distributing multiple second domain name resolution requests to the authoritative DNS through load balancing can be selected from the relevant scheme and will not be repeated here.
[0062] The embodiment of the present disclosure adopts a load balancing device to distribute the second domain name resolution requests. Even in the face of a large number of high-concurrency second domain name resolution requests, it is still possible to reasonably adjust the load of each authoritative DNS and make full use of the authoritative DNS resources to ensure the high availability of the authoritative DNS.
[0063] In some optional implementations, when the resolver in this embodiment sends the second domain name resolution request to the corresponding authoritative DNS, the second domain name resolution request can be forwarded through the network address translation device (NAT) shown in Figure 5, so that the second domain name resolution request is first sent to the load balancing device, and then the load balancing device distributes the second domain name resolution request to the corresponding authoritative DNS.
[0064] Step S103: receiving a resolution result of the second domain name resolution request from the authoritative domain name system, and forwarding the resolution result to the virtual device through the network module.
[0065] In this embodiment, the authoritative domain name system can resolve the received second domain name resolution request to obtain a resolution result; wherein, the authoritative domain name system can resolve the VNI from the second domain name resolution request, and perform tenant-isolated domain name resolution based on the VNI, and the resolution result can be a DNS data packet.
[0066] In some optional implementations, while converting the first domain name resolution request into the second domain name resolution request, the domain name resolution method further includes: retaining a session connection between the resolver and the network module.
[0067] Specifically, this embodiment retains the session connection between the resolver and the network module by storing the five-tuple data in the first domain name resolution request, so that when responding to the first domain name resolution request, the original session connection can be found by receiving the five-tuple data of the message.
[0068] In some optional implementations, forwarding the parsing result to the virtual device through the network module includes: forwarding the parsing result to the virtual device through the network module based on a session connection between the parser and the network module.
[0069] The session connection between the resolver and the network module can be achieved by obtaining the five-tuple data in the pre-stored first domain name resolution request.
[0070] This embodiment feeds back the resolution result by retaining the existing session connection, thereby improving communication efficiency and ensuring that the response result is accurately sent to the virtual machine that issued the corresponding private network domain name resolution request.
[0071] The domain name resolution method for edge computing provided in this embodiment is specifically a private network DNS implementation method applied in edge computing scenarios. This embodiment uses a resolver on a first physical machine deployed in a first edge computer room to convert a first domain name resolution request forwarded by a virtual device through a network module, and sends the converted second domain name resolution request to an authoritative domain name system on a second physical machine deployed in a second edge computer room for resolution, and sends the resolution result fed back by the authoritative domain name system to the virtual device. It can be seen that in the domain name resolution solution provided by this embodiment, on the basis of realizing the domain name resolution function, the authoritative domain name system and the virtual device resources are deployed separately, avoiding the situation of deploying a domain name system for each edge computer room separately, and effectively overcoming the problems of large scale, high maintenance difficulty and high deployment cost of the domain name system in the edge cloud computing scenario in the related technologies. Compared with the related technologies, this embodiment can greatly reduce the scale of the domain name system in the edge cloud computing scenario, reduce the maintenance difficulty and reduce the deployment cost.
[0072] In this embodiment, a domain name resolution method for edge computing is provided, which can be applied to a resolver. FIG2 is a flow chart of the domain name resolution method for edge computing according to an embodiment of the present disclosure. As shown in FIG2 , the process includes the following steps:
[0073] Step S201: Obtain a first domain name resolution request forwarded by a virtual device via a network module, wherein the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is located in a first edge computer room. The first domain name resolution request is a Virtual Extended Local Area Network (VXLAN) message.
[0074] In some optional implementations, the network module is a virtual switch (vSwitch), which is used to encapsulate the domain name resolution message sent by the virtual device into a virtual extended local area network (VXLAN) message. The domain name resolution message is a private network domain name resolution request.
[0075] The virtual machine switch in this embodiment can encapsulate the domain name resolution message through a custom protocol or an extended domain name resolution protocol to obtain a virtual extended local area network message, and the virtual extended local area network message is the first domain name resolution request.
[0076] 6 , taking the encapsulation of the domain name resolution message by the extended domain name resolution protocol as an example, the structure of the obtained virtual extended local area network message includes: an outer Ethernet header (Outer Ethernet header), an outer Internet Protocol header (Outer IP header), an outer user datagram protocol header (Outer UDP header), a virtual extended local area network header (VXLAN header), an inner Ethernet header (Inner Ethernet header), an inner Internet Protocol header (Inner IP header), and a domain name resolution payload (DNS Payload); wherein, the virtual extended local area network header (VXLAN header) includes a flag (Flags), a first reserved unused bit (Reserved), a virtual extended local area network identifier (VNI), and a second reserved unused bit (Reserved). The length of the first reserved unused bit (Reserved) may be greater than the length of the second reserved unused bit (Reserved). The functions of each part in the structure of the virtual extended local area network message can be referred to the EDNS protocol and will not be repeated here.
[0077] The network module implemented by vSwitch in this embodiment supports the configuration of more virtual devices and has the advantages of strong scalability, high performance and low cost, so that the solution of this embodiment can better adapt to the private network DNS resolution of edge cloud computing scenarios.
[0078] Step S202: convert the first domain name resolution request into a second domain name resolution request, and send the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is set in a second edge computer room.
[0079] Specifically, the above step S202 includes:
[0080] Step S2021: parse the VELAN message to obtain the outer network information, the VELAN identifier, and the message payload information.
[0081] As shown in FIG6 , the outer network information includes an outer Ethernet header and an outer Internet Protocol header, and the message payload information includes a domain name resolution payload (DNS Payload).
[0082] The virtual extended local area network identifier in this embodiment represents an ID (Identity Document) that can be used to implement tenant isolation. Different virtual extended local area network identifiers may correspond to different tenants. The virtual extended local area network identifier is specifically a VNI (VXLAN Network ID).
[0083] The resolver in this embodiment parses and strips the VXLAN header and the inner header to obtain the VNI in the message, and then inserts it into the EDNS field of the DNS message (the virtual extended LAN message in this embodiment). The specific arrangement can use the Option Code reserved by the EDNS protocol. Combined with the structural diagram of the message constructed based on the extended domain name resolution protocol shown in Figure 7, the message structure includes a transaction identifier (Transaction ID), flags, number of questions (Questions), number of answer resource records (Answer RRs), number of authoritative name server records (Authority RRs), number of additional resource records (Additional RRs), query questions (Queries), number of answers (Answers), and authoritative name server zone (Authoritative nameservers), extended return status code (EXTENDED-RCODE), version (VERSION), option code (OPTION-CODE), option length (OPTION-LENGTH), option data (OPTION-DATA). The option data of this embodiment is specifically VNI&IDC (virtual extended LAN identifier and computer room coding information). The additional information (Additional records) includes option code (OPTION-CODE), option length (OPTION-LENGTH) and option data (OPTION-DATA).
[0084] Step S2022: Generate a second domain name resolution request based on the external network information, the virtual extended local area network identifier, and the message payload information.
[0085] Specifically, in this embodiment, relevant information such as the outer network information, the virtual extended local area network identifier, and the message payload information may be encapsulated into a message representing the second domain name resolution request.
[0086] Step S203: Receive the resolution result of the second domain name resolution request from the authoritative domain name system and forward the resolution result to the virtual device via the network module. For details, please refer to step S103 of the embodiment shown in FIG1 , which will not be described in detail here.
[0087] The domain name resolution method provided in this embodiment can parse the VNI from the virtual extended LAN message, and implement a tenant-isolated domain name resolution process. By requiring each domain name resolution rule to specify the VNI, the domain name configurations of different VNIs can be independent and non-conflicting, thereby achieving the purpose of private network domain name resolution.
[0088] In this embodiment, a domain name resolution method for edge computing is provided, which can be applied to a resolver. FIG3 is a flow chart of the domain name resolution method for edge computing according to an embodiment of the present disclosure. As shown in FIG3 , the process includes the following steps:
[0089] In step S301, a first domain name resolution request is obtained, which is forwarded by the virtual device via the network module. The virtual device, the network module, and the resolver are all deployed on a first physical machine, which is located in a first edge computer room. For details, please refer to step S201 of the embodiment shown in FIG2 , and will not be repeated here.
[0090] Step S302: convert the first domain name resolution request into a second domain name resolution request, and send the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is set in a second edge computer room.
[0091] Specifically, the above step S302 includes:
[0092] Step S3021: parse the VELAN message to obtain the outer network information, VELAN identifier, and message payload information. For details, please refer to step S2021 of the embodiment shown in FIG2 , which will not be described in detail here.
[0093] Step S3022: Generate a second domain name resolution request based on the external network information, the virtual extended local area network identifier, and the message payload information.
[0094] Specifically, the above step S3022 includes:
[0095] Step S30221: Obtain the computer room coding information corresponding to the first domain name resolution request.
[0096] The room coding information is, for example, a room ID, specifically a first edge room ID. In this embodiment, the room coding information can be configured on the resolver, that is, the room ID information is configured on the resolver. The room ID is used to distinguish different first edge rooms.
[0097] Step S30222: Generate a second domain name resolution request using the outer network information, the virtual extended local area network identifier, the message payload information, and the computer room code information.
[0098] 8 , this embodiment may encapsulate the outer network information, the virtual extended LAN identifier, the message payload information, and the computer room code information into a message representing the second domain name resolution request. The outer network information may include an outer Ethernet header and an outer IP header, and the virtual extended LAN identifier and the message payload information are encapsulated in an extended domain name resolution payload (DNS Payload with EDNS).
[0099] The domain name resolution method for edge computing provided in this embodiment further distinguishes different second domain name resolution requests through the computer room coding information. Even when the virtual extended LAN identifier is the same, different second domain name resolution requests can still be distinguished, thereby achieving better tenant isolation effect in the domain name resolution process.
[0100] In some optional implementations, the above-mentioned step S30222 includes: based on the extended domain name resolution protocol, encapsulating the outer network information, virtual extended LAN identifier, message payload information and computer room coding information into an extended domain name resolution message, and the second domain name resolution request is an extended domain name resolution message.
[0101] In this embodiment, the extended domain name resolution protocol is the EDNS (Extension Mechanisms for DNS) protocol. By encapsulating external network information, virtual extended local area network identifiers, message payload information, and computer room code information through the EDNS protocol, a larger DNS message size can be provided, and support for expanded functions and options can be provided. Furthermore, messages encapsulated based on the EDNS protocol can improve communication efficiency between the resolver and the authoritative DNS, reducing DNS query latency.
[0102] Step S303: receiving a resolution result of the second domain name resolution request from the authoritative domain name system, and forwarding the resolution result to the virtual device through the network module.
[0103] Specifically, after the authoritative domain name system receives the extended domain name resolution message, it performs tenant isolation domain name resolution through VNI&IDC (virtual extended LAN identifier and computer room coding information); the resolution result is responded to the Resolver of the corresponding first physical machine as a DNS data packet. The Resolver can find the original session connection by receiving the five-tuple data of the message, thereby obtaining the address of the inner part to be encapsulated, and then encapsulates the DNS data packet with a VXLAN header to form a new VXLAN (virtual extended LAN) data packet, among which the source address and target address in the header of the response message used as the resolution result are swapped, and finally the message is sent to the virtual machine that issued the domain name resolution request through the virtual switch (vSwitch).
[0104] It should be understood that in the edge computing scenario, the physical machines set up in the edge computer room specifically involved in the present disclosure, such as but not limited to the aforementioned first physical machine and second physical machine, can all be understood as an edge computing node.
[0105] As shown in Figure 5, a domain name resolution system for edge computing is provided in this embodiment. The domain name resolution system for edge computing includes but is not limited to virtual devices, network modules, resolvers, and authoritative domain name systems.
[0106] A virtual device used to send private network domain name resolution requests to the network module.
[0107] The network module is used to convert the private network domain name resolution request into a first domain name resolution request, and to send the first domain name resolution request to the resolver.
[0108] A resolver converts a first domain name resolution request into a second domain name resolution request, and is used to send the second domain name resolution request to an authoritative domain name system; wherein the virtual device, the network module and the resolver are all deployed on a first physical machine, and the first physical machine is set in a first edge computer room.
[0109] The authoritative domain name system is used to resolve the second domain name resolution request to obtain a resolution result; the authoritative domain name system is also used to send the resolution result to the resolver; the authoritative domain name system is deployed on the second physical machine, and the second physical machine is set in the second edge computer room.
[0110] The parser is also used to forward the parsing results to the network module.
[0111] The network module is also used to forward the parsing results to the virtual device.
[0112] This embodiment provides a distributed private network DNS system suitable for edge computing scenarios, which can be distributedly deployed in discrete edge computer rooms, solving the problem of complex DNS deployment in edge computing scenarios. At the same time, the architecture of the domain name resolution system provided by this embodiment does not require an independent deployment of a DNS system in each edge computer room. Therefore, on the basis of realizing the domain name resolution function, the authoritative domain name system and the virtual device resources are deployed separately, avoiding the situation of deploying a domain name system for each edge computer room separately, overcoming the problems of large scale, high maintenance difficulty and high deployment cost of the domain name system in the edge cloud computing scenario in the related technology. The domain name resolution architecture for edge computing provided by the present embodiment is applied to the private network DNS in the edge computing scenario, and provides a full set of DNS solutions. It can also solve the tenant isolation problem of DNS resolution in the edge computing scenario. The domain name resolution system for edge computing provided by this embodiment has a wide range of applications and can greatly reduce the DNS resource consumption in the edge computing environment.
[0113] In some optional implementations, the first domain name resolution request is a virtual extended local area network message.
[0114] Specifically, the resolver is used to parse the outer network information, virtual extended LAN identifier and message payload information from the virtual extended LAN message, and to generate a second domain name resolution request based on the outer network information, virtual extended LAN identifier and message payload information.
[0115] In some optional implementations, the resolver is specifically used to obtain the computer room coding information corresponding to the first domain name resolution request; the resolver is specifically used to generate a second domain name resolution request using outer network information, virtual extended LAN identifier, message payload information and computer room coding information.
[0116] In some optional implementations, the resolver is specifically used to encapsulate outer network information, virtual extended LAN identifier, message payload information and computer room coding information into an extended domain name resolution message based on the extended domain name resolution protocol, and the second domain name resolution request is an extended domain name resolution message.
[0117] In some optional implementations, the network module is a virtual switch, and the virtual switch is used to encapsulate the domain name resolution message sent by the virtual device into a virtual extended local area network message.
[0118] In some optional implementations, the parser is specifically used to retain the session connection between the parser and the network module, and to forward the parsing result to the virtual device through the network module based on the session connection between the parser and the network module.
[0119] In some optional implementations, the resolver is further used to obtain configuration information issued by the edge private network domain name system console, where the configuration information is used to characterize the resolution rules for the target domain name resolution request, where the target domain name resolution request includes the first domain name resolution request.
[0120] In some optional embodiments, the domain name resolution system for edge computing also includes a load balancer; the resolver is specifically used to send the second domain name resolution request to the load balancing device, and the load balancing device is used to distribute the second domain name resolution request to the authoritative domain name system.
[0121] In some optional implementations, the number of the second edge computer rooms is at least two.
[0122] The detailed implementation methods of the components included in the domain name resolution system, such as virtual devices, network modules, resolvers, and authoritative domain name systems, have been described in detail in the aforementioned embodiments and will not be repeated here.
[0123] In this embodiment, a domain name resolution device for edge computing is also provided, which is used to implement the above-mentioned embodiments and preferred implementation methods. The details that have been described will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and conceivable.
[0124] This embodiment provides a domain name resolution device for edge computing, as shown in FIG10 , including:
[0125] The acquisition unit 1001 is used to acquire a first domain name resolution request forwarded by the virtual device through the network module. The virtual device, the network module and the resolver are all deployed on a first physical machine, and the first physical machine is set in a first edge computer room.
[0126] The conversion unit 1002 is used to convert the first domain name resolution request into a second domain name resolution request, and to send the second domain name resolution request to the authoritative domain name system, which is deployed on a second physical machine, and the second physical machine is set in a second edge computer room.
[0127] The responding unit 1003 is configured to receive a resolution result of the authoritative domain name system for the second domain name resolution request, and to forward the resolution result to the virtual device via the network module.
[0128] In some optional implementations, the first domain name resolution request is a virtual extended local area network message.
[0129] The conversion unit 1002 includes:
[0130] The parsing subunit is used to parse the virtual extended local area network message to obtain the outer network information, the virtual extended local area network identifier and the message payload information.
[0131] The generating subunit is used to generate a second domain name resolution request based on the outer network information, the virtual extended local area network identifier and the message payload information.
[0132] In some optional embodiments, the generating subunit includes:
[0133] The acquisition subunit is used to obtain the computer room coding information corresponding to the first domain name resolution request.
[0134] A subunit is created for generating a second domain name resolution request using the outer network information, the virtual extended local area network identifier, the message payload information, and the computer room coding information.
[0135] In some optional embodiments, a subunit is created, specifically used to encapsulate outer network information, virtual extended LAN identifier, message payload information and computer room coding information into an extended domain name resolution message based on the extended domain name resolution protocol, and the second domain name resolution request is an extended domain name resolution message.
[0136] In some optional implementations, the network module is a virtual switch, and the virtual switch is used to encapsulate the domain name resolution message sent by the virtual device into a virtual extended local area network message.
[0137] In some optional implementations, the domain name resolution device for edge computing further includes a session retention unit.
[0138] The session preserving unit is used to preserve the session connection between the resolver and the network module while converting the first domain name resolution request into the second domain name resolution request.
[0139] The responding unit 1003 is specifically configured to forward the parsing result to the virtual device through the network module based on the session connection between the parser and the network module.
[0140] In some optional implementations, the domain name resolution device for edge computing further includes a configuration acquisition unit.
[0141] The configuration acquisition unit is used to acquire configuration information sent by the edge private network domain name system console, where the configuration information is used to represent a resolution rule for a target domain name resolution request, where the target domain name resolution request includes a first domain name resolution request.
[0142] In some optional implementations, the conversion unit 1002 is specifically configured to send the second domain name resolution request to a load balancing device, and the load balancing device is configured to distribute the second domain name resolution request to an authoritative domain name system.
[0143] In some optional implementations, the number of the second edge computer rooms is at least two.
[0144] The further functional description of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0145] The domain name resolution device for edge computing in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0146] An embodiment of the present disclosure also provides a computer device having the domain name resolution device for edge computing shown in FIG10 above.
[0147] Please refer to Figure 11, which is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present disclosure. As shown in Figure 11, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 11 takes a processor 10 as an example.
[0148] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0149] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.
[0150] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0151] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0152] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0153] The embodiments of the present disclosure also provide a computer-readable storage medium. The above-mentioned method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0154] Although the embodiments of the present disclosure have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A domain name resolution method for edge computing, applied to a resolver, comprising: Obtaining a first domain name resolution request forwarded by a virtual device through a network module, wherein the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is disposed in a first edge computer room; Converting the first domain name resolution request into a second domain name resolution request, and sending the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is located in a second edge computer room; Receive a resolution result of the authoritative domain name system for the second domain name resolution request, and forward the resolution result to the virtual device through the network module.
2. The method according to claim 1, wherein the first domain name resolution request is a virtual extended local area network message; and converting the first domain name resolution request into a second domain name resolution request comprises: Parsing the outer network information, the virtual extended local area network identifier and the message payload information from the virtual extended local area network message; The second domain name resolution request is generated based on the outer network information, the virtual extended local area network identifier and the message payload information.
3. The method according to claim 2, wherein generating the second domain name resolution request based on the outer network information, the virtual extended local area network identifier, and the message payload information comprises: Obtaining computer room code information corresponding to the first domain name resolution request; The second domain name resolution request is generated by using the outer network information, the virtual extended local area network identifier, the message payload information and the computer room code information.
4. The method according to claim 3, wherein generating the second domain name resolution request by using the outer network information, the virtual extended local area network identifier, the message payload information, and the computer room code information comprises: Based on the extended domain name resolution protocol, the outer network information, the virtual extended LAN identifier, the message payload information and the computer room code information are encapsulated into an extended domain name resolution message, and the second domain name resolution request is the extended domain name resolution message.
5. The method according to claim 2, wherein: The network module is a virtual switch, and the virtual switch is used to encapsulate the domain name resolution message sent by the virtual device into the virtual extended local area network message.
6. The method according to any one of claims 1 to 5, wherein While converting the first domain name resolution request into a second domain name resolution request, the method further includes: retaining a session connection between the resolver and the network module; The forwarding the parsing result to the virtual device through the network module includes: forwarding the parsing result to the virtual device through the network module based on a session connection between the parser and the network module.
7. The method according to any one of claims 1 to 5, wherein before obtaining the first domain name resolution request forwarded by the virtual device through the network module, the method further comprises: Configuration information sent by an edge private network domain name system console is obtained, where the configuration information is used to represent a resolution rule for a target domain name resolution request, where the target domain name resolution request includes the first domain name resolution request.
8. The method according to any one of claims 1 to 5, wherein sending the second domain name resolution request to an authoritative domain name system comprises: The second domain name resolution request is sent to a load balancing device, and the load balancing device is used to distribute the second domain name resolution request to the authoritative domain name system.
9. The method according to any one of claims 1 to 5, wherein The number of the second edge computer rooms is at least two.
10. A domain name resolution system for edge computing, comprising: Virtual device, used to send private network domain name resolution requests to the network module; The network module is configured to convert the private network domain name resolution request into a first domain name resolution request, and to send the first domain name resolution request to the resolver; The resolver converts the first domain name resolution request into a second domain name resolution request, and is used to send the second domain name resolution request to an authoritative domain name system; wherein the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is set in a first edge computer room; The authoritative domain name system is configured to resolve the second domain name resolution request to obtain a resolution result; the authoritative domain name system is further configured to send the resolution result to the resolver; the authoritative domain name system is deployed on a second physical machine, and the second physical machine is located in a second edge computer room; The parser is further configured to forward the parsing result to the network module; The network module is further configured to forward the analysis result to the virtual device.
11. A domain name resolution device for edge computing, comprising: an acquiring unit, configured to acquire a first domain name resolution request forwarded by a virtual device through a network module, wherein the virtual device, the network module, and the resolver are all deployed on a first physical machine, and the first physical machine is disposed in a first edge computer room; a conversion unit, configured to convert the first domain name resolution request into a second domain name resolution request, and to send the second domain name resolution request to an authoritative domain name system, where the authoritative domain name system is deployed on a second physical machine, and the second physical machine is disposed in a second edge computer room; The response unit is configured to receive a resolution result of the authoritative domain name system for the second domain name resolution request, and to forward the resolution result to the virtual device through the network module.
12. A computer device comprising: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the domain name resolution method for edge computing according to any one of claims 1 to 9 by executing the computer instructions.
13. A computer-readable storage medium having computer instructions stored thereon, wherein the computer instructions are used to enable a computer to execute the domain name resolution method for edge computing according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method and device of forwarding data packet
CN107317752A
Domain name resolution method and domain name resolution system
CN112738296A
Method for supporting VPC private domain name resolution by DNS
CN115604223A
Domain name resolution method, system and device for edge computing, equipment and medium
CN117938808A
Domain name system-over-hypertext transfer protocol secure with edge cloud or content delivery network localization
WO2021014204A1