CDN Synthetic Record Domain Name Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In content delivery networks (CDNs), synthetic record domain names can be intercepted by illegal users, allowing them to forge legitimate domain name resolutions and certificates. This leads to security issues and inefficiencies, particularly due to the need for extensive whitelist configurations.
Innovation Solution
A domain name encryption method and apparatus are introduced for CDNs, which involve receiving an access request for an initial server, acquiring a synthetic record domain name for a target server, and encrypting this domain name to produce an encrypted synthetic record domain name. This encrypted domain name is then sent to the terminal, preventing unauthorized access and improving security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a whitelist mechanism is used to prevent illegal domain name resolution, then security is improved, but the number of whitelist segments increases due to discrete CDN edge node network segments, resulting in low efficiency
Solution Approach 1:
The patent changes the parameter of domain name from plain text to encrypted form. By encrypting the domain name, the system maintains security without requiring extensive whitelist configurations, thus resolving the contradiction between security and efficiency
Solution Approach 2:
The patent introduces an encryption intermediary layer between the domain name and the resolution process. The encrypted domain name acts as a mediator that prevents illegal access while allowing legitimate resolutions, eliminating the need for complex whitelist mechanisms
2Ease of operation
If synthetic record domain names are used in CDN systems, then domain name resolution functionality is improved, but security deteriorates because illegal users can intercept and forge domain name resolutions
Solution Approach 1:
The patent applies encryption to the synthetic record domain name, changing its parameter from readable to encrypted form. This maintains the functional benefits of synthetic records while preventing interception and forgery by illegal users
Solution Approach 2:
The patent converts the potential harm of synthetic record domain names being interceptable into a benefit by using encryption. The encryption itself becomes the protective mechanism that allows synthetic records to function securely
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
The present disclosure relates to a domain name encryption method, decryption method, and apparatus based on a content delivery network. The method comprises: receiving (S210) an access request for an initial server sent by a terminal; acquiring (S220), in a case that the initial server needs to be redirected to a target server, a synthetic record domain name of the target server, the synthetic record domain name carrying a domain name resolution result of the target server; and encrypting (S230) the synthetic record domain name to obtain an encrypted synthetic record domain name, and sending the encrypted synthetic record domain name to the terminal. By encrypting the synthetic record domain name, one can be prevented from knowing data information about the domain name resolution result in the synthetic record domain name, which can improve the security of the data, and can significantly improve the processing efficiency of the domain name.