Roaming DNS Query Routing for Unauthorized Domain Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In HR roaming scenarios, terminals may experience limited quality of service due to unauthorized domain names not being offloaded to local data networks in the visited PLMN, preventing access to corresponding application servers.

Innovation Solution

A communication method and apparatus that utilizes a network element to provide information about the terminal's home network to a DNS server when querying unauthorized domain names, enabling the DNS server to determine and provide the address of the application server, allowing the terminal to access and utilize the service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the HPLMN authorizes services corresponding to domain names to be offloaded to a local data network in the VPLMN, then the terminal can access application servers in the VPLMN, but the terminal cannot access application servers for domain names that are not authorized

Engineering Contradiction:
Improveaccess to application serversVSAvoidservice quality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The V-EASDF network element acts as an intermediary between the terminal and the DNS server. When the terminal queries an unauthorized domain name, the V-EASDF element intercepts the query, determines it is unauthorized, and then forwards it to the DNS server with additional home network information. This intermediary mechanism enables the system to maintain authorization control while still allowing access to unauthorized domain names through proper routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of DNS query processing by modifying how unauthorized domain names are handled. Instead of simply blocking queries for unauthorized domain names, the system changes the query parameters to include home network information and routes these queries to the appropriate DNS server, which then returns the correct application server address.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the terminal queries DNS for unauthorized domain names in the VPLMN, then the terminal should be able to access application servers, but the current authorization mechanism blocks such access

Engineering Contradiction:
Improveservice accessibilityVSAvoidnetwork configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The V-EASDF network element performs self-service by automatically determining whether a domain name is authorized based on its own configuration, and autonomously deciding how to route DNS queries. When an unauthorized domain name is detected, the element automatically adds home network information and forwards the query to the DNS server without requiring manual intervention or complex configuration changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring the V-EASDF network element with authorization information about which domain names can be offloaded to the VPLMN. This preliminary configuration allows the element to immediately recognize unauthorized domain names and handle them appropriately without requiring real-time analysis or complex decision-making processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260032099A1Communication method and communication apparatus
Publication Date: 2026.01.29 HUAWEI TECH CO LTD
  • US20260032099A1 patent drawing
  • US20260032099A1 patent drawing
  • US20260032099A1 patent drawing

AI summary

This application provides a communication method and a communication apparatus. The method includes: A first network element receives a first query message from a terminal, where the first query message includes information about a first domain name, the first domain name is not authorized in a visited network of the terminal, and the first network element is a network element in the visited network of the terminal; the first network element sends a second query message to a domain name system server based on the first query message, where the second query message includes the information about the first domain name and information about a home network of the terminal, and the information about the home network is used to determine an address of an application server; and the first network element receives the address of the application server from the DNS server.