Roaming DNS Resolution for Unauthorized Domain Name Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a mobile communication network, when a terminal roams within a visited PLMN where certain domain names are not authorized for service offloading, the terminal may experience limited quality of service due to inability to access application servers corresponding to these unauthorized domain names.
Innovation Solution
A communication method and apparatus that enables a network element to provide information about the terminal's home network to a DNS server, allowing the DNS server to determine and provide the address of application servers corresponding to unauthorized domain names, thereby enabling the terminal to access these servers and improve communication quality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the visited network restricts access to application servers for unauthorized domain names, then network security and policy compliance are improved, but service quality and user experience deteriorate
Solution Approach 1:
The DNS server acts as an intermediary between the terminal and application servers. When a terminal queries a domain name, the DNS server receives the query, determines whether the domain name is authorized in the visited network, and if unauthorized, redirects the query to obtain the terminal's home network information and resolves the domain name accordingly. This intermediary mechanism enables service continuity while maintaining network security policies.
2Productivity
If the terminal accesses application servers in the home network during roaming, then service quality is improved, but network complexity and signaling overhead increase
Solution Approach 1:
The system changes the resolution parameter of domain names based on the terminal's location and authorization status. When a domain name is unauthorized in the visited network, the DNS server modifies the resolution process by incorporating the terminal's home network information to obtain the appropriate application server address. This parameter change enables seamless service without requiring terminal-side complexity.
Data Source
Figure 1
Figure 1A
Figure 2
AI summary
This application provides a communication method and a communication apparatus. The method includes: A first network element receives a first query message from a terminal, where the first query message includes information about a first domain name, the first domain name is not authorized in a visited network of the terminal, and the first network element is a network element in the visited network of the terminal; the first network element sends a second query message to a domain name system server based on the first query message, where the second query message includes the information about the first domain name and information about a home network of the terminal, and the information about the home network is used to determine an address of an application server; and the first network element receives the address of the application server from the DNS server. This can avoid a problem that the terminal cannot access a service corresponding to a domain name because the domain name is not authorized in the visited network, and improve quality of a communication service of the terminal.