CN110061838A - A kind of the decentralization storage system and its realization, information retrieval method of DNS resource record - Google Patents

A kind of the decentralization storage system and its realization, information retrieval method of DNS resource record Download PDF

Info

Publication number
CN110061838A
CN110061838A CN201910350269.5A CN201910350269A CN110061838A CN 110061838 A CN110061838 A CN 110061838A CN 201910350269 A CN201910350269 A CN 201910350269A CN 110061838 A CN110061838 A CN 110061838A
Authority
CN
China
Prior art keywords
dns
record
information
contract
resource record
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201910350269.5A
Other languages
Chinese (zh)
Other versions
CN110061838B (en
Inventor
胡宁
王文通
刘亚萍
吴纯青
张硕
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangzhou University
Original Assignee
Guangzhou University
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Guangzhou University filed Critical Guangzhou University
Priority to CN201910350269.5A priority Critical patent/CN110061838B/en
Publication of CN110061838A publication Critical patent/CN110061838A/en
Application granted granted Critical
Publication of CN110061838B publication Critical patent/CN110061838B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/10File systems; File servers
    • G06F16/13File access structures, e.g. distributed indices
    • G06F16/137Hash-based
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4505Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
    • H04L61/4511Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1097Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Mining & Analysis (AREA)
  • Databases & Information Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)

Abstract

The invention discloses a kind of decentralization storage system of DNS resource record and its realizations, information retrieval method, the system includes: accumulation layer on chain, utilizes key DNS resource record and DNS resource record of tracing to the source in intelligent contract storage DNS resource record, index external storage;Accumulation layer under chain stores DNS resource record using IPFS, and the cryptographic Hash of the Hash Round Robin data partition of identity and record information is stored in block chain, it is ensured that the authenticity and integrity of resource record by the Hash Round Robin data partition of the corresponding identity of each IPFS node;Client layer includes DNS administrator and DNS user, the former is responsible for DNS database information registering and update, synchronous DNS critical data is into external storage, and relevant information is written in block using intelligent contract, the latter passes through the corresponding resource record of DNS client nslookup, and the record in block chain and external storage is inquired, verify the authenticity and integrity of record.

Description

A kind of the decentralization storage system and its realization, information retrieval of DNS resource record Method
Technical field
The present invention relates to block chain technical field, more particularly in the going of a kind of DNS resource record based on alliance's chain Heart storage system and its realization, information retrieval method.
Background technique
The architecture of current DNS (Domain Name System, domain name system) system is a kind of level of centralization Structure, control centre of the DNS root server as entire DNS system are responsible for DNS global administration and parsing, the solution of all domain names Analysis and verifying require the participation of DNS root server, and on the one hand this architecture increases the processing load of root server, another There are Single Point of Faliure hidden danger for aspect.When root server is inaccessible or breaks down, it will lead to entire internet domain name system System paralysis.
There is also unilateral control hidden danger for the DNS system of existing centralization hierarchical structure.Current 13 root services have 10 positions In the U.S., 2 are located at Europe, and 1 is located at Japan, and the distribution of dns server and number are seriously unbalanced, lead to cyberspace master There are serious unilateral control phenomenons for power, mainly include two aspect: one is to domain name deorienting risk.It only need to be in root server The top level domain record of particular country is deleted, and refuse offer to realize to the domain name registration of the country.Second is that refusal is visited Ask risk.In root server and its mirror image server, refuse the analysis request from a state top level domain.In root service Also the access strategy to certain domain name and its subset can be set in device, to destroy the network sovereignty that the domain name corresponds to tissue.
DNS security solution based on PKI (Public Key Infrastructure, Public Key Infrastructure) It is difficult to widespread deployment.The DNS security enhancing proposed at present or alternative solution are mostly based on digital signature and PKI infrastructure, and This kind of scheme needs to modify DNS Protocol, can not keep being compatible with traditional DNS system, and therefore, it is difficult to large scale deployments, such as: mesh Preceding 89% top level domain server disposition DNSSEC (Domain Name System Security Extensions, DNS Security extension), but second level domain deployment rate is only 3%, this makes DNSSEC be difficult to play a role in practical applications.This Outside, inherently there is unilateral control problem in PKI infrastructure, it is difficult to dispose in the world.
In conclusion since the excessively apparent centralization of DNS system is characterized in that DNS system security risk is caused to be difficult to eradicate Major reason, for this purpose, DNS decentralization becomes an important developing direction.Therefore, the present invention intends not changing DNS In the case where agreement, the storage of DNS resource record, retrieval and the verification method of a kind of decentralization are proposed.
Summary of the invention
In order to overcome the deficiencies of the above existing technologies, it is gone purpose of the present invention is to provide a kind of DNS resource record Centralization storage system and its realization, information retrieval method using alliance's chain decentralization, the storage of data distribution formula, can not usurp Change, collective maintenance the characteristics of, realize based on alliance's chain DNS resource record decentralization storage and retrieval purpose, do not changing Under the premise of becoming DNS Protocol, DNS resource record is prevented to be maliciously tampered and forge, improves DNS system analysis and verification efficiency.
In order to achieve the above object, the present invention proposes a kind of decentralization storage system of DNS resource record, comprising:
Accumulation layer on chain, using intelligent contract storage DNS resource record, index external storage in DNS resource record and It traces to the source DNS resource record;
Accumulation layer under chain stores DNS resource record, the Hash of the corresponding identity of each IPFS node using IPFS Address, by the Hash Round Robin data partition of identity and record information cryptographic Hash be stored in block chain, it is ensured that resource record it is true Property and integrality;
Client layer, including DNS administrator and DNS user, DNS administrator are responsible for DNS database information registering and update, together DNS critical data is walked into external storage, and using intelligent contract by DNS registration information, more new information, record cryptographic Hash, In signing messages, external storage chained address write-in block;DNS user passes through the corresponding resource note of DNS client nslookup Record, and further inquire the record in block chain and external storage according to the corresponding address of domain name, verify the authenticity of record And integrality.
Preferably, the cryptographic Hash of domain-name information, resource record are signed using intelligent contract, are updated by accumulation layer on the chain Information, external storage link, public key information are written in block, and ensure each node in block chain network using common recognition algorithm Recording for middle storage is identical, provides authenticity and integrity for resource record and guarantees, the block link layer is also used to index outside Key DNS resource record in storage, chained address and the record being recorded in keystone resources using intelligent contract in external storage Cryptographic Hash storage within a block, block chain and external storage are associated, block is suitable according to the time in the block chain Sequence is stored, and storage resource is recorded in the more new record information of address in external storage, resource record in each block, with It is traced to the source the historical information of certain domain name by the block chain.
Preferably, the intelligent contract include common recognition contract, relational contracts, ownership contract, historical record contract and Service contract, will be in DNS hierarchical relationship, resource record, history more new information write area block chain by five kinds of contracts.
Preferably, the common recognition contract is responsible for user's registration information write-in, and the relational contracts are responsible for storing DNS level pass System, the ownership contract are responsible for recording the specifying information of name server institute management domain name, and the historical record contract is responsible for By in the DNS zone file update information write-in block chain comprising DNS resource record, the service contract is responsible for recording domain name The service log of server.
Preferably, for each node in the block chain after common recognition negotiating algorithm is consistent, block chain network is added in authorization, The common recognition contract registers customers as information write-in block chain.
In order to achieve the above objectives, the present invention also provides a kind of implementation method of DNS resource record decentralization storage system, Include the following steps:
Step S1 constructs block chain network by the way of alliance's chain, using intelligent contract to the registration Shen of register node Come in row processing, and by common recognition algorithm it is authorized after be added into the block chain network, will include DNS by intelligent contract The DNS zone file of resource record is written in the block chain network, take on chain/chain under the mode that combines be managed, Partial data is stored in external storage under chain, is grounded the file cryptographic Hash of domain name resources record, outer chains on chain Location, the public key information for verifying external data are stored in block chain, guarantee the authenticity of DNS data and complete by block chain Property, while utilizing the memory space of external storage system extension block chain;
Step S2 is stored, and will when data update under the synchronous chain of the resource record that will be updated by server node The chained address of domain name configuration file, the cryptographic Hash of record, status information are sent to service contract, more using service contract storage New domain-name information, and history contract is generated, record the state of update and the content of update.
Preferably, step S1 further comprises:
Register node proposes application for registration to block chain network;
Common recognition contract pushes messages to ballot tank node, is confirmed;
Tank node of voting checks whether domain-name information is legal and unregistered, if domain name is legal and unregistered, returns to registration Success, otherwise returns to registration failure;
The common recognition contract processing voting results create relational contracts if voting results are legal, otherwise abandon registration letter Breath;
Registration message is transmitted to relational contracts by common recognition contract;
Registration message is given to by relational contracts sends out server node corresponding;
Parent server node is agreed to authorize the node, and application information and itself signature are sent to relational contracts;
Relational contracts are compiled registration information and authorization server signature, and create service contract;
The information write service contract that relational contracts will have been registered;
The address of service contract returns to register node, and register node carries out domain-name information operation using service contract.
Preferably, the method also includes:
In the incipient stage of system, the common recognition contract is sky, and start node is added as needed in temporary control and education person's node, After there are enough complete nodes to be added, allow to remove temporary control and education person, consensus process is held according to common recognition algorithm Row.
In order to achieve the above objectives, the present invention also provides a kind of decentralization search method of DNS resource record, including it is as follows Step:
Step S1, end subscriber initiate inquiry request when retrieving domain-name information, to trusted servers;
Step S2, the trusted servers search caching, the service contract hair if caching is not hit, into block chain Inquiry request is played, service contract records the corresponding server of each domain name and external linkage address;
Step S3, the service contract is by the external address of the corresponding zone file of the domain name retrieved and records cryptographic Hash Return to trusted servers;
Step S4 after the trusted servers receive external linkage address, inquires external zone file record, and calculates outer Portion's record Hash and service contract return recording Hash are made comparisons, to prevent external record to be tampered, if two cryptographic Hash results Identical, the information retrieved is returned to end subscriber by trusted servers.
Preferably, the method also includes:
Search result is verified, by the verification mode of DNS centralization, switchs to distributed validation mode, passes through block The verifying of DNS resource record is become searching the account book of collective's maintenance by chain technology, is looked into using signature mechanism and hash algorithm guarantee The mode recorded on chain is looked for guarantee the authenticity and integrity of record.
Compared with prior art, the invention proposes a kind of decentralization storage system of DNS resource record and its realization, Information retrieval method, by intelligent contract will DNS zone file be written ether mill block chain in, take on chain/chain under combine Mode be managed, partial data is stored in external storage under chain, on chain by domain name resources record (RR) text Part cryptographic Hash, external linkage address, verify external data public key information be stored in block chain, pass through block chain guarantee DNS The authenticity and integrity of resource record, while using the memory space of external storage system extension block chain, improve system Scalability, the present invention realize verifying domain name while retrieving domain name, compared to DNSSEC after obtaining search result again into The mode of row domain name verifying, shortens verifying path and process, promotes verification efficiency.
Detailed description of the invention
Fig. 1 is the structural schematic diagram of DNS resource record decentralization proposed by the present invention storage, retrieval and verification method;
Fig. 2 is the schematic diagram of intelligent contract in the specific embodiment of the invention;
Fig. 3 is the step flow chart of the implementation method of DNS resource record decentralization storage system proposed by the present invention;
Fig. 4 is the network diagram of alliance's chain in the specific embodiment of the invention;
Fig. 5 is the process schematic of specific embodiment of the invention interior joint addition;
Fig. 6 is the flow chart of common recognition algorithm in the specific embodiment of the invention;
Fig. 7 is the flow chart of data updating process in the specific embodiment of the invention;
Fig. 8 is the step flow chart of DNS resource record decentralization information retrieval method proposed by the present invention;
Fig. 9 is data retrieval process schematic diagram in the specific embodiment of the invention;
Figure 10 is the retrieval of DNS resource record and the verification process schematic diagram in the specific embodiment of the invention based on block chain;
Figure 11 is that code key updates flow diagram in the specific embodiment of the invention;
Figure 12 is resource record retrieval and verification process schematic diagram in the specific embodiment of the invention.
Specific embodiment
Below by way of specific specific example and embodiments of the present invention are described with reference to the drawings, those skilled in the art can Further advantage and effect of the invention are understood by content disclosed in the present specification.The present invention also can be by other different specific Example is implemented or is applied, and details in this specification can also be based on different perspectives and applications, without departing substantially from the present invention Spirit under carry out it is various modification and change.
Fig. 1 is the structural schematic diagram of the decentralization storage system of DNS resource record proposed by the present invention.As shown in Figure 1, The decentralization storage system of the DNS resource record, comprising:
Accumulation layer 10 on chain, for storing DNS resource record, key DNS resource record and tracing back in index external storage Source DNS resource record.Specifically, on chain accumulation layer 10 using intelligent contract by the cryptographic Hash of domain-name information, resource record signature, More new information, external storage link, public key information are written in block, and ensure each of block chain network using common recognition algorithm Recording for storing in node is identical, provides authenticity and integrity for resource record and guarantees, the block link layer 10 is also used to rope Draw DNS resource record in external storage, i.e., using intelligent contract by keystone resources be recorded in chained address in external storage and Record cryptographic Hash storage within a block, block chain and external storage are associated, due in block chain block be all by It is stored according to time sequencing, the update of storage resource is recorded in external storage in each block address, resource record is remembered It records information, therefore can be traced to the source the historical information of certain domain name by block chain 10.
Accumulation layer 20 under chain, for being responsible for storage DNS resource record.In the specific embodiment of the invention, accumulation layer under chain 20 use IPFS (Inter Planetary File System, interspace file system) external storage system, and IPFS can be saved often The record information that secondary DNS administrator submits, the Hash Round Robin data partition of the corresponding identity of each IPFS, by the Hash of identity The cryptographic Hash of address and record information is stored in block chain, it is ensured that the authenticity and integrity of resource record.
Client layer 30 mainly includes two kinds of users: DNS administrator and search user, wherein DNS administrator is responsible for DNS number According to library information registering and update, synchronous DNS critical data utilizes intelligent contract by DNS registration information, more into external storage New information, the cryptographic Hash of record, signing messages, external storage chained address are written in block;DNS user then utilizes DNS client The corresponding resource record of nslookup is held, to the IP address retrieved, inquires the record in block chain and external storage, verifying note The authenticity and integrity of record.
In order to facilitate in DNS resource record write-in block chain, the present invention constructs 5 kinds of intelligent contracts, comprising: common recognition contract (Consensus Contract, CC), relational contracts (Relationship Contract, RC), ownership contract (Ownership Contract, OC) (not shown), historical record contract (History Contract, HC), service are closed About (Service Contract, SC).DNS hierarchical relationship, resource record, history more new information are written by this 5 kinds of contracts In block chain.In order to keep the contract between node mutually indepedent, contract, which only passes through generated contract, to be created.Specifically, Intelligence contract used by block link layer 10 is as shown in Fig. 2, the intelligence contract is as follows:
(1) know together contract (CC): common recognition contract is responsible for user's registration information write-in, and common recognition each field meanings of contract are as follows:
Ethereum Addr: the ether mill address that authorized user is added
Reponsible Domain: it is responsible for the name space of management
User Type: user type, including inquiry user, application for domain names person
RC Addr: it is responsible for the contract address of storage tier relationship
For each node in block chain after common recognition negotiating algorithm is consistent, block chain network is added in authorization, and common recognition contract will It appeals information and block chain is written.
For user registration course, common recognition and about CC prevent attacker for verifying whether register node is repeated registration Carry out malice rush-register.In order to construct the hierarchical relationship between dns server, parent server passes through relational contracts RC storage authorization Lower level servers, the address of relational contracts are stored in the common recognition contract of register node, and new registration node passes through common recognition algorithm warp It is added after authorization, prevents newly added node from constituting a threat to system.It should be noted that in the incipient stage of system, common recognition and about CC It will be sky.Therefore, temporary control and education person's node will need to add start node, such as using top level domain server node as starting Node is added.After there are enough complete nodes to be added, allow to remove temporary control and education person, consensus process is according to altogether Know algorithm to execute.
2) relational contracts (RC): relational contracts are responsible for storing DNS hierarchical relationship, and each field meanings of relational contracts are as follows:
Ethereum Addr: the next stage server ether mill address of authorization
Reponsible Domain: the responsible name space of the next stage server of authorization
IP: the IP address of server
Level: server tier
HC Addr: relational contracts address
Server Signature: Information Signature
For the name space that server authorization goes out, in order to record hierarchical relationship, parent server is closed in common recognition and about CC The name space, IP and associated ether mill address information of the name server management of authorization are stored in the relational contracts RC of connection. The name space of parent server authorization has multiple, and relational contracts are responsible for recording each authority record.Each authorization is taken Business device information, can all be recorded in sequentially in time in block chain, so as to subsequent lookup and trace to the source.
3) ownership contract (OC): ownership contract is responsible for recording the specifying information of name server institute management domain name, institute Each field meanings of contract of having the right are as follows:
Ethereum Addr: resource record manager's address information
Domain Name: it is responsible for the domain name of management
IP Addr: the corresponding IP address of domain name
External Link: the link of resource record external storage
Hash: the Hash of resource record
HC Addr: the address of historical record contract
Due to the limited storage space of each block, if complete resource record information is stored in block chain, meeting It increases the length of block chain rapidly, is not easy to manage and maintain.Therefore, for convenience of domain name address information is quickly searched, each Domain name and address are directly stored in block, other resource records are stored in external storage.The chained address of external storage saves In External Link field.To prevent external resource record malice from distorting, the cryptographic Hash of resource record is stored in Hash word Section.DNS resource record information meeting real-time update passes through building historical record contract and stores more new information.Historical record contract Address is stored in ownership contract.
Complete DNS resource is stored in IPFS, and each domain name configuration (zone) file corresponds to a node ID in IPFS, This node ID is immutable, and only dns server administrator possesses, and is responsible for updating DNS domain name configuration (zone) file.It updates Block chain will be written by historical record contract in domain name configuration (zone) file afterwards.
4) historical record contract (HC): historical record contract is responsible for DNS zone file update information block chain is written In, each field concrete meaning of historical record contract is as follows:
Ethereum Addr:zone file management person address
New_Hash: zone file Hash after update
Condition: state, addition, are deleted at modification
IPFS ID: mark of the user in IPFS
To the change information of zone file, the information after change is written by block chain by historical record contract, for every The information of secondary change saves the copy submitted every time in external IPFS, while the Hash of record is stored in block chain, it is ensured that The zone the file information submitted every time is not tampered, and can be traced to the source zone the file information by block chain and external IP FS.
5) service contract (SC) (not shown): it is responsible for the service log of record name server, each word of service contract Section concrete meaning is as follows:
Ethereum Addr:zone file management person address
Service Record: service log
Condition: state, addition, are deleted at modification
IPFS ID: mark of the user in IPFS
DNS zone file is written in the block chain of ether mill that is, the present invention passes through intelligent contract, take on chain/ The mode combined under chain is managed.Partial data is stored in external storage under chain, remembers domain name resources on chain Record the file cryptographic Hash of (RR), external linkage address, the public key information for verifying external data are stored in block chain, pass through block Chain guarantees the authenticity and integrity of DNS data, while using the memory space of external storage system extension block chain, improving system Unite scalability, the present invention realizes verifying domain name while retrieving domain name, compared to DNSSEC after obtaining search result again The mode for carrying out domain name verifying shortens verifying path and process, promotes verification efficiency.
Fig. 3 is a kind of step flow chart of the implementation method of the decentralization storage system of DNS resource record of the present invention.Such as Shown in Fig. 3, a kind of implementation method of the decentralization storage system of DNS resource record of the present invention includes the following steps:
Step S1 constructs block chain network by the way of alliance's chain, using intelligent contract to the registration Shen of register node Row processing that come in, is added into the block chain network, and the block link network is written in DNS zone file by intelligent contract In network, take on chain/chain under the mode that combines be managed, partial data is stored in external storage under chain, in chain On the domain name resources record file cryptographic Hash of (RR), external linkage address, the public key information for verifying external data be stored in area In block chain, guarantee the authenticity and integrity of DNS data by block chain, while utilizing external storage system extension block chain Memory space.
In the specific embodiment of the invention, the intelligence contract includes common recognition and about CC, relational contracts RC, ownership contract OC, historical record and about HC and service contract SC.The block chain network is constructed by the way of alliance's chain, server node The chain network that coalizes is authorized, the network diagram of alliance's chain is as shown in Figure 4.It is assumed that the server node of the system of addition is Ethereum client and create the address Ethereum through installation, node adding procedure as shown in figure 5, specifically, step S1's Node adding procedure is as follows:
1) register node proposes application for registration into block chain network, including the address Ethereum, domain-name information, institute Belong to server tier, identity information;
2) common recognition contract pushes messages to ballot tank node, is confirmed;
3) ballot tank node checks whether domain-name information is legal and unregistered, if domain name is legal and unregistered, returns to note Volume success, otherwise returns to registration failure;
4) common recognition contract processing voting results create relational contracts if voting results are legal, otherwise abandon registration letter Breath;
5) registration message is transmitted to relational contracts by common recognition contract;
6) registration message is given to by relational contracts sends out server node corresponding;
7) parent server node is agreed to authorize the node, and application information and itself signature are sent to relational contracts;
8) relational contracts are compiled registration information and authorization server signature, and create service contract;
9) the information write service contract that relational contracts will have been registered;
10) address of service contract returns to register node, and register node carries out domain-name information operation using service contract.
As it can be seen that whether common recognition and about CC verifying register node are repeated registration for user registration course, attacker is prevented Malice rush-register is carried out, in order to construct the hierarchical relationship between dns server, parent server passes through under relational contracts storage authorization Grade server, the address of relational contracts is stored in the common recognition contract of register node.New registration node is by common recognition algorithm through awarding It is added after power, prevents newly added node from constituting a threat to system.It should be noted that common recognition and about CC will in the incipient stage of system For sky, therefore, temporary control and education person's node will need to add start node, such as add top level domain server node as starting Ingress.After there are enough complete nodes to be added, allow to remove temporary control and education person, consensus process is according to common recognition Algorithm executes.
Illustrate common recognition algorithm employed in the specific embodiment of the invention (i.e. the common recognition process of data update) below:
1) algorithm idea
In view of PBFT (common recognition algorithm) limitation of the algorithm in terms of network bandwidth and node communication mode, in conjunction with block The characteristics of chain, PBFT algorithm do not require each message first to sequence sequence, and each node need to only complete the verifying and confirmation of message, will 3 broadcasting process of PBFT are reduced to 2 times, reduce the communication overhead of network.
2) symbol indicates
If the number of nodes for participating in common recognition in system is N, patient maximum malicious node number is f, then N must satisfy formula N >=3f+1, common recognition node participates in accounting procedure in system, and ordinary node can see common recognition process, but and be not involved in.It participates in altogether The node of knowledge is divided into two types: host node m, from node s.For the authenticity and integrity for guaranteeing message, message transmitting process In, by the way of signature, if function σ is signature function, msg is the message to be sent, and hash is hash function, then signature value Sig is expressed as
Sigmsg=σ (hash (msg))
Required data acquisition system is denoted as view v during every wheel common recognition, and set is numbered from 0, if current Set is not reached common understanding, then needs to enter next set, until reaching common understanding.The node that common recognition process participates in also is compiled Number, every wheel selects a node as host node, other nodes are used as from node.
Assuming that participating in the node original state having the same of common recognition when initial, i.e. original block height h, a upper block are breathed out It is uncommon, version number is consistent.Initial views number and master node number relationship is as shown in formula (1)
If not common recognition node receives Transaction Information, then message is forwarded.Common recognition node, which initiates common recognition by host node, asks It asks, sub- common recognition node receives transaction message, then verifies the correctness of message, the information is saved if correct after message is verified, Common recognition confirmation broadcast is sent, view update information is otherwise broadcasted.After common recognition process, Transaction Information is deleted, updates view With block height, it is prepared to enter into the new stage, specifically, the process for algorithm of knowing together is as shown in Figure 6.The common recognition algorithm mainly wraps Containing two aspects:
A. host node broadcast common recognition request
The term of office of host node be time t, host node m to other common recognition node broadcasts know together motion message
{ConsensusRequest,h,v,m,Block,SigBlock}
Wherein ConsensusRequest represents type of message as common recognition request, and h is current block height, v active view Number, m master node number, the Block block that interior transaction is constituted for a period of time, SigBlockFor block information signature.
B. child node is known together confirmation stage
After each common recognition process child node receives the broadcast message of host node, the correctness of message is successively verified, if disappearing Breath is correct, then broadcasts common recognition confirmation message:
<ConsensusConfirm,h,v,s,SigBlock>
Wherein ConsensusConfirm represents type of message as common recognition request, and h is current block height, v active view Number, s child node number, SigBlockFor block signature.
After each common recognition node receives broadcast message, following process is executed, judges the correctness of message:
A. judge whether the format of message is correct, including type of message, current block height, master node number, signature are It is no correct, view update process is carried out if incorrect;
B. judge the correctness traded in current block, include whether to have existed, whether the verifying script traded correct, Whether include repeat business, step d is gone to if incorrect;
C. in the case where step a and b are verified, then each transaction is legal in the block;
D. broadcast view replaces message;
If the message received is incorrect, view replacement message is broadcasted.If each common recognition node receives at least 2f altogether After the common recognition confirmation message for knowing node, then prove that the block is arrived most of nodes and received in network, i.e., common recognition is reached, by the area Block is added in block chain, and broadcasts the block.
Common recognition request message or child node broadcast view update are broadcasted not in stipulated time t when host node breaks down Message does not obtain 2f node confirmation, then can execute view update operation, and renewal process is as follows:
A. view is increased into v=v+1 first
B. child node sends replacement view message
<ViewChange,h,v,s,v′,Sigmsg>
Wherein ViewChange represents type of message as view update, and h is current block height, v active view number, s Child node number, the new view number of v ', SigmsgFor information signature
It is v ' by view update if it is more than 2f that c. common recognition node, which receives view update number of broadcast message, host node updates For m=m+1, start new common recognition process.
If d. received view update message count does not arrive 2f, continued to execute back to step a.
B. the setting of host node term of office time t
The network fluctuation between master node network is unstable or common recognition node, may arrive causes frequent view to be replaced, and disappears Consume Internet resources.In order to avoid frequently triggering view because of network fluctuation with changing, the time t of host node work should be with view more New index increases, and when view, which takes place frequently, to be updated, illustrates that network fluctuates, it should increase time t.If time t meets as follows Function,
T (k)=2kT, k=0,1,2 ...
Function T increases with view update number index, can make to avoid frequently view replacement caused by due to network fluctuation At the waste of Internet resources.
Step S2, when data update, under the synchronous chain of resource record that server node will update in storage, and by domain The chained address of name configuration (zone) file, cryptographic Hash, the status information of record are sent to service contract, are deposited using service contract The domain-name information updated is stored up, and generates history contract, records the state of update and the content of update.In the specific embodiment of the invention In, it is assumed that more new domain name configuration (zone) file server node in systems complete registration, server node The resource record that database management component will update is synchronized under chain in storage, and chain of the zone file in IPFS is grounded Location, the cryptographic Hash of record, status information are sent to service contract, it should be noted that, storage uses database, cloud storage under chain Same function can be equally completed, even if original data also remain to using IPFS in the case where data file is deleted Enough access, and IPFS has the characteristics that decentralization, the domain-name information that service contract storage updates, and generates history contract, comes Record the content of the state and update that update.
Specifically, as shown in fig. 7, data updating process is as follows:
(1) server node database management component generates more new record;
(2) database management component will update recording synchronism to external IP FS system, and generate external storage link and note Record cryptographic Hash;
(3) chained address, the cryptographic Hash of record, status information are sent to service contract by server node;
(4) service contract records updated domain-name information, and generates history contract;
(5) more new record, status information are sent to history contract by service contract;
(6) history contract will more new record, status information write-in block chain.
Fig. 8 is a kind of step flow chart of the decentralization information retrieval method of DNS resource record of the present invention.In the present invention In, block chain network is responsible for the index of storage record, and provides guarantee to the authenticity and integrity of record.In block chain network It is responsible for the write-in and reading of record by contract, and contract is created by already existing contract, it is ensured that contract creation and data pass Safety during defeated.Inter-trust domain is made of local network or server node trusty, and end subscriber passes through trusted Server retrieve domain-name information.Complete domain name configuration (zone) file is stored in external storage, the link of external storage Address and record Hash are stored in block chain.As shown in figure 8, a kind of decentralization information inspection of DNS resource record of the present invention Suo Fangfa includes the following steps:
Step S601, end subscriber initiate inquiry request when retrieving domain-name information, to trusted servers;
Step S602, trusted servers search caching, if caching is not hit, the service contract into block chain is initiated Inquiry request, service contract record the corresponding server of each domain name and external linkage address;
Step S603, service contract return the external address of the corresponding zone file of the domain name retrieved and record cryptographic Hash Back to trusted servers;
Step S604 after trusted servers receive external linkage address, inquires external zone file record, and calculate outside Record Hash and service contract return recording Hash are made comparisons, to prevent external record to be tampered, if two cryptographic Hash result phases Together, the information retrieved is returned to end subscriber by trusted servers.
Specifically, as shown in figure 9, information retrieval process is as follows:
(1) end subscriber initiates inquiry request
(2) trusted servers search local cache record, and the service contract initiation if not hitting into block chain is looked into Ask request
(3) service contract inquiry storage record, if being stored in the record of the domain name, inquiry content is corresponding IP address, Then IP address is returned, if inquiry content is other records, returns to the external storage address of zone file;
(4) trusted servers receive service contract and return the result, if user query content is the corresponding IP address of domain name, IP address is returned, if other records, server searches external storage
(5) trusted servers search external storage;
(6) Hash and service contract return recording Hash for calculating external zone file are made comparisons, will if the two is identical External file is not tampered with, retrieval respective resources record;
(7) query result is returned.
Preferably, the information retrieval method further includes following steps:
Search result is verified.In the present invention, by the verification mode of DNS centralization, switch to distributed validation side The verifying of DNS resource record is become searching the account book of collective's maintenance that is, by block chain technology by formula, using signature mechanism with Hash algorithm guarantees to search the authenticity and integrity that the mode recorded on chain guarantees record.
Figure 10 is the retrieval of DNS resource record and the verification process schematic diagram in the specific embodiment of the invention based on block chain. Specifically, the present invention verifies the DNS system based on block chain, and each zone file of DNS is stored in external data base, Zone file signature, external index, public key information are stored in block chain, using the decentralization of block chain, collective's maintenance, are not easy The characteristics of distorting provides the authenticity and integrity protection of zone file, to verify the authenticity of the address www.aa.com record For, only needing 2 inquiries, i.e. inquiry block chain obtains external linkage address, and inquiry external linkage address obtains address record, And 1 Hash operation is carried out, the authenticity and integrity of 1 cryptographic calculation verifying zone file.
1) identity binding
Record in block chain can be arrived by the Nodes Retrieval in all block chains, if directly and domain by the public key of user Name information binding, the identity information and public key information of the node can be revealed.For this purpose, the present invention is in order to solve code key and identity information Under conditions of binding while protecting privacy of user, the code key of user is designed using the process of Figure 11.
By publication, the public key in block chain carries out authenticity and integrity verifying, the private key of offline storage for the update of data It is responsible for public key in more new block chain.User is locally generated a pair of offline secret key pair, and online code key is by offline private key and previous step The online public key generated is generated with function F, as shown in formula (2).
(skn,pkn)=F (skf,pkn-1), (2)
When user's more new information, it is responsible for signature with public key, it is ensured that the code key of identity information and real Identity Association letter Manner of breathing separation.
When server sends key information into block chain, server sends code key and registers broadcast message:
<key_register, id, values=(pk, σ)>
It is code key registration that wherein key_register, which is type of message, and id is identity, and σ=sig (sk, id), σ are to use Signature of the private key sk to identity id, it was demonstrated that the node possesses public key pk corresponding private key sk.
2) code key updates
The update of online public key is by sending new, old public key to block chain, and the mode of attaching signature is completed.Pass through number Signature, new public key are generated by the holder of the corresponding private key of old public key, it is ensured that the sender of message is the owner of old public key.
Server sends code key and updates broadcast message: < key_update, id, values=(pkold,pknew,σ1,σ2)>
It is that code key updates that wherein key_update, which is type of message, and id is identity, σ 1=sig (skold,(id, pknew)), σ 1 is with old code key signature to the signature of identity and new public key, this proves that the node possesses old public key pkoldIt is right The private key sk answeredold, and pknewFor the corresponding new public key of node i d.σ 2=sig (sknew, id), σ 2 is with new private key sknewIt is right The signature of identity id, it was demonstrated that the node possesses new public key pknewCorresponding new private key sknew
3) verification process
A. code key updates verifying
After each accounting nodes receive code key update request, following verifying is done:
Judge that id is identified whether and pk in block chainoldCorresponding id matches;
Whether signature sigma 1 is correct;
Whether signature sigma 2 is correct.
If wherein there is an authentication failed, the transaction is abandoned, the message is otherwise packaged into block, is broadcasted to the message Confirmation.
B. resource record retrieval and verifying
The authentication domain retrieving of resource record is as shown in figure 12.It is not recorded if domain name D summarizes in block chain, return does not have There is record, retrieving terminates, if there is retrieval to record in block chain, threaded file is retrieved first, and do following verifying:
A judges whether the cryptographic Hash that file is saved in block chain is identical as the file value in external memory
Whether b judges the signature in block chain, and identical with signature value of the public key in block chain to external file
If c the two has a Xiang Butong, mistake is returned, otherwise returns to correct query result.
In conclusion the present invention a kind of the decentralization storage system and its realization, information retrieval method of DNS resource record DNS zone file is written in the block chain of ether mill by intelligent contract, take on chain/chain under the mode that combines carry out pipe Partial data, is stored in external storage by reason under chain, by the file cryptographic Hash of domain name resources record (RR), outside on chain Chained address, verify external data public key information be stored in block chain, by block chain guarantee DNS data authenticity and Integrality, while using the memory space of external storage system extension block chain, the system expandability is improved, the present invention realizes Verifying domain name while retrieving domain name, carries out the mode of domain name verifying compared to DNSSEC again after obtaining search result, contracts Short verifying path and process promote verification efficiency.
Compared with prior art, the present invention has the advantage that
1) can incremental deployment can be with DNS system compatible without changing DNS Protocol;
2) DNS zone file decentralization storage and management, using alliance's chain thought and intelligent contract technology by DNS Zone file and alliance's chain combination, using block chain go center, distributed management, collective safeguard the characteristics of, guarantee DNS zone The safe and reliable and decentralization of file stores;
3) the decentralization retrieval and verifying of domain-name information is known together mechanism and signature mechanism using block chain decentralization, The correctness for guaranteeing search result completes domain name verifying while domain name retrieval.
The above-described embodiments merely illustrate the principles and effects of the present invention, and is not intended to limit the present invention.Any Without departing from the spirit and scope of the present invention, modifications and changes are made to the above embodiments by field technical staff.Therefore, The scope of the present invention, should be as listed in the claims.

Claims (10)

1. a kind of decentralization storage system of DNS resource record, comprising:
Accumulation layer on chain using DNS resource record in intelligent contract storage DNS resource record, index external storage and is traced to the source DNS resource record;
Accumulation layer under chain stores DNS resource record using IPFS, and each IPFS node is with corresponding to the Hash of an identity The cryptographic Hash of the Hash Round Robin data partition of identity and record information is stored in block chain, it is ensured that the authenticity of resource record by location And integrality;
Client layer, including DNS administrator and DNS user, DNS administrator are responsible for DNS database information registering and update, synchronous DNS critical data utilizes intelligent contract by DNS registration information, more new information, the cryptographic Hash of record, label into external storage In name information, external storage chained address write-in block;DNS user passes through the corresponding resource record of DNS client nslookup, And further according to the corresponding address of domain name, inquire the record in block chain and external storage, verify record authenticity and Integrality.
2. a kind of decentralization storage system of DNS resource record as described in claim 1, it is characterised in that: on the chain Cryptographic Hash that domain name resources records by accumulation layer using intelligent contract, resource record signature, more new information, external storage link, Public key information is written in block, and identical using common recognition algorithm recording of ensuring to store in each node in block chain network, Authenticity and integrity being provided for resource record to guarantee, the block link layer is also used to index DNS resource record in external storage, The cryptographic Hash of chained address and record using intelligent contract by resource record in external storage stores within a block, by area Block chain and external storage are associated, and block is stored sequentially in time in the block chain, and money is stored in each block Address of the source record in external storage, resource record more new record information, to be traced to the source certain domain name by the block chain Historical information.
3. a kind of decentralization storage system of DNS resource record as claimed in claim 2, it is characterised in that: the intelligence Contract includes but is not limited to know together contract, relational contracts, ownership contract, historical record contract and service contract, by this Five kinds of contracts will be in DNS hierarchical relationship, resource record, history more new information write area block chain.
4. a kind of decentralization storage system of DNS resource record as claimed in claim 3, it is characterised in that: the common recognition Contract is responsible for user's registration information write-in, and the relational contracts are responsible for storing DNS hierarchical relationship, and the ownership contract is responsible for note The specifying information of name server institute management domain name is recorded, the historical record contract is responsible for writing DNS zone file update information Enter in block chain, the service contract is responsible for recording the service log of name server.
5. a kind of decentralization storage system of DNS resource record as claimed in claim 4, it is characterised in that: the block Each node in chain is after common recognition negotiating algorithm is consistent, and block chain network is added in authorization, and the common recognition contract registers customers as Block chain is written in information.
6. a kind of implementation method of the decentralization storage system of DNS resource record, includes the following steps:
Step S1 constructs block chain network by the way of alliance's chain, using intelligent contract to the application for registration of register node into Row processing, and by common recognition algorithm it is authorized after be added into the block chain network, will include DNS resource by intelligent contract The DNS zone file of record is written in the block chain network, take on chain/chain under the mode that combines be managed, in chain It is lower that partial data is stored in external storage, on chain by domain name resources record file cryptographic Hash, external linkage address, test The public key information of card external data is stored in block chain, guarantees the authenticity and integrity of DNS data by block chain, simultaneously Utilize the memory space of external storage system extension block chain;
Step S2 is stored under the synchronous chain of the resource record that will be updated by server node when data update, and by domain name The chained address of configuration file, the cryptographic Hash of record, status information are sent to service contract, are updated using service contract storage Domain-name information, and history contract is generated, record the state of update and the content of update.
7. a kind of implementation method of the decentralization storage system of DNS resource record as claimed in claim 6, feature exist In step S1 further comprises:
Register node proposes application for registration to block chain network;
Common recognition contract pushes messages to ballot tank node, is confirmed;
Tank node of voting checks whether domain-name information is legal and unregistered, if domain name is legal and unregistered, return is succeeded in registration, Otherwise registration failure is returned;
The common recognition contract processing voting results create relational contracts, otherwise abandon registration information if voting results are legal;
Registration message is transmitted to relational contracts by common recognition contract;
Registration message is given to by relational contracts sends out server node corresponding;
Parent server node is agreed to authorize the node, and application information and itself signature are sent to relational contracts;
Relational contracts are compiled registration information and authorization server signature, and create service contract;
The information write service contract that relational contracts will have been registered;
The address of service contract returns to register node, and register node carries out domain-name information operation using service contract.
8. a kind of implementation method of the decentralization storage system of DNS resource record as claimed in claim 7, feature exist In, the method also includes:
In the incipient stage of system, the common recognition contract is sky, and start node is added as needed in temporary control and education person's node, once After there are enough complete nodes to be added, allow to remove temporary control and education person, consensus process is executed according to common recognition algorithm.
9. a kind of decentralization information retrieval method of DNS resource record, includes the following steps:
Step S1, end subscriber initiate inquiry request when retrieving domain-name information, to trusted servers;
Step S2, the trusted servers search caching, if caching is not hit, the service contract initiation into block chain is looked into Request is ask, service contract records the corresponding server of each domain name and external linkage address;
Step S3, the service contract return to the external address of the corresponding zone file of the domain name retrieved and record cryptographic Hash To trusted servers;
Step S4 after the trusted servers receive external linkage address, inquires external zone file record, and calculate external note Record Hash and service contract return recording Hash are made comparisons, to prevent external record to be tampered, if two cryptographic Hash results are identical, The information retrieved is returned to end subscriber by trusted servers.
10. a kind of decentralization information retrieval method of DNS resource record as claimed in claim 9, which is characterized in that described Method further include:
Search result is verified, by the verification mode of DNS centralization, switchs to distributed validation mode, passes through block chain skill The verifying of DNS resource record is become searching the account book of collective's maintenance by art, guarantees to search chain using signature mechanism and hash algorithm The mode of upper record guarantees the authenticity and integrity of record.
CN201910350269.5A 2019-04-28 2019-04-28 Decentralized storage system for DNS resource records and implementation method thereof Active CN110061838B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910350269.5A CN110061838B (en) 2019-04-28 2019-04-28 Decentralized storage system for DNS resource records and implementation method thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910350269.5A CN110061838B (en) 2019-04-28 2019-04-28 Decentralized storage system for DNS resource records and implementation method thereof

Publications (2)

Publication Number Publication Date
CN110061838A true CN110061838A (en) 2019-07-26
CN110061838B CN110061838B (en) 2022-07-19

Family

ID=67321357

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910350269.5A Active CN110061838B (en) 2019-04-28 2019-04-28 Decentralized storage system for DNS resource records and implementation method thereof

Country Status (1)

Country Link
CN (1) CN110061838B (en)

Cited By (58)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110492997A (en) * 2019-08-09 2019-11-22 华南理工大学 A kind of encryption system based on super account book, method, apparatus and storage medium
CN110737668A (en) * 2019-12-17 2020-01-31 腾讯科技(深圳)有限公司 Data storage method, data reading method, related device and medium
CN110880966A (en) * 2019-11-22 2020-03-13 哈尔滨工业大学 Domain name resolution system building and domain name query method
CN111031076A (en) * 2020-03-06 2020-04-17 南京畅洋科技有限公司 Internet of things block chain consensus method based on timing mechanism
CN111031086A (en) * 2019-10-08 2020-04-17 安徽华博胜讯信息科技股份有限公司 Block chain data storage method and system
CN111061698A (en) * 2019-12-30 2020-04-24 语联网(武汉)信息技术有限公司 Storage method and device of Ether house contract data
CN111144578A (en) * 2019-12-27 2020-05-12 创新奇智(重庆)科技有限公司 Artificial intelligence model management system and management method under distributed environment
CN111177277A (en) * 2020-04-10 2020-05-19 支付宝(杭州)信息技术有限公司 Data storage method, transaction storage method and device
CN111200642A (en) * 2019-12-26 2020-05-26 下一代互联网关键技术和评测北京市工程研究中心有限公司 Authoritative DNS server information distribution method and system
CN111210223A (en) * 2019-12-17 2020-05-29 广东文储区块链科技有限公司 Method and system for clearing block chain of decentralized storage area
CN111310238A (en) * 2020-02-12 2020-06-19 腾讯科技(深圳)有限公司 File management method and device
CN111343267A (en) * 2020-02-24 2020-06-26 深圳木成林科技有限公司 Configuration management method and system
CN111373402A (en) * 2019-11-08 2020-07-03 支付宝(杭州)信息技术有限公司 Lightweight decentralized application platform
CN111448565A (en) * 2020-02-14 2020-07-24 支付宝(杭州)信息技术有限公司 Data authorization based on decentralized identity
CN111445245A (en) * 2020-03-27 2020-07-24 北京瑞卓喜投科技发展有限公司 Certificate index updating method and device for security type general certificate
CN111460489A (en) * 2019-12-09 2020-07-28 重庆锐云科技有限公司 Client persistent storage method based on IPFS (Internet protocol file system) block chain
CN111835884A (en) * 2020-07-13 2020-10-27 北京好扑信息科技有限公司 Virtual address generation method for block chain
CN111858627A (en) * 2020-06-24 2020-10-30 南京信息职业技术学院 Academic degree and academic calendar query system and method based on block chain
CN111885212A (en) * 2020-06-03 2020-11-03 山东伏羲智库互联网研究院 Domain name storage method and device
CN111901447A (en) * 2020-05-27 2020-11-06 伏羲科技(菏泽)有限公司 Domain name data management method, device, equipment and storage medium
CN111936995A (en) * 2020-06-08 2020-11-13 支付宝实验室(新加坡)有限公司 Distributed storage of customs clearance data
CN112187900A (en) * 2020-09-18 2021-01-05 中国科学院计算技术研究所 DNS data updating method and system based on block chain shared cache
CN112214456A (en) * 2020-11-05 2021-01-12 深圳市瀚兰区块链地产有限公司 House property data processing method and device and electronic equipment
CN112241435A (en) * 2020-10-23 2021-01-19 山西特信环宇信息技术有限公司 Cone block chain storage system and consensus storage method
CN112256662A (en) * 2020-10-22 2021-01-22 安徽农业大学 Storage and tracing method, device, equipment and storage medium for agricultural product information block chain
CN112286881A (en) * 2020-10-28 2021-01-29 金蝶云科技有限公司 Document authentication and tracing method and device
CN112437089A (en) * 2020-11-26 2021-03-02 交控科技股份有限公司 Train control system key management method and device based on block chain
CN112468603A (en) * 2019-09-06 2021-03-09 傲为信息技术(江苏)有限公司 Domain name query system and method based on block chain
WO2021042784A1 (en) * 2019-09-06 2021-03-11 南京瑞祥信息技术有限公司 Domain name management system employing blockchain
CN112529581A (en) * 2020-12-23 2021-03-19 广州大学 Domain name data storage system based on block chain and data transaction implementation method thereof
CN112637330A (en) * 2020-12-22 2021-04-09 山东大学 Block chain large file copy address selection method, system, equipment and storage medium
WO2021071421A1 (en) * 2019-10-10 2021-04-15 Standard Chartered Bank (Singapore) Limited Methods, systems, and devices for managing digital assets
CN112686673A (en) * 2020-12-18 2021-04-20 上海黑犇互联网科技有限公司 Article traceability system based on IPFS and ETH
CN112702390A (en) * 2020-12-07 2021-04-23 北京大学 Block chain-based networking method and device for intelligent contract resources
CN112818038A (en) * 2021-02-02 2021-05-18 山东伏羲智库互联网研究院 Data management method based on combination of block chain and IPFS (Internet protocol file system) and related equipment
CN112822279A (en) * 2021-01-13 2021-05-18 精英数智科技股份有限公司 Monitoring method and device based on intelligent sensing and trusted storage
CN112948847A (en) * 2021-02-02 2021-06-11 山东伏羲智库互联网研究院 Data sharing system based on block chain and data correctness verification method
CN113067836A (en) * 2021-04-20 2021-07-02 哈尔滨工业大学 Intelligent contract system based on decentralized DNS root zone management
CN113064898A (en) * 2021-04-06 2021-07-02 北京瑞卓喜投科技发展有限公司 Retrieval method and device based on miniature index of contract on chain and electronic equipment
CN113064886A (en) * 2021-03-04 2021-07-02 广州中国科学院计算机网络信息中心 Method for storing and managing identification resources
CN113064876A (en) * 2021-03-25 2021-07-02 芝麻链(北京)科技有限公司 IPFS file processing method
CN113098941A (en) * 2021-03-25 2021-07-09 浙江大学 Virtual reality content distributed management method and system based on integral excitation
CN113127811A (en) * 2021-03-09 2021-07-16 西北大学 Cultural relic digital resource safety sharing method, cultural relic digital resource safety sharing system and information data processing terminal
CN113157698A (en) * 2021-04-23 2021-07-23 上海和数软件有限公司 Data query verification method and system based on block chain technology
CN113312640A (en) * 2021-05-31 2021-08-27 天津理工大学 Software data integrity multi-party consensus method based on trusted computing
CN113422767A (en) * 2021-06-21 2021-09-21 哈尔滨工业大学 Domain name registration management method and system based on block chain
CN113538149A (en) * 2021-07-28 2021-10-22 浙江数秦科技有限公司 Multisource data fusion platform based on block chain
CN113608703A (en) * 2021-08-24 2021-11-05 上海点融信息科技有限责任公司 Data processing method and device
CN113657899A (en) * 2021-10-19 2021-11-16 支付宝(杭州)信息技术有限公司 Method, device and system for transferring property right
CN114117545A (en) * 2021-11-08 2022-03-01 重庆邮电大学 Tamper-proof electronic certification system and implementation method thereof
CN114185997A (en) * 2022-02-17 2022-03-15 天津眧合数字科技有限公司 Pet information credible storage system based on block chain
US20220103370A1 (en) * 2020-09-25 2022-03-31 Wickr Inc. Decentralized system for securely resolving domain names
CN114629631A (en) * 2021-07-21 2022-06-14 国网河南省电力公司信息通信公司 Data credible interaction method and system based on alliance chain and electronic equipment
CN114666277A (en) * 2022-05-05 2022-06-24 中国互联网络信息中心 Data processing method and device based on domain name
CN115150355A (en) * 2021-03-15 2022-10-04 正链科技(深圳)有限公司 Method for realizing distributed domain name
CN115174385A (en) * 2022-06-15 2022-10-11 桂林电子科技大学 Industrial Internet of things equipment firmware software updating method based on block chain
KR20220150728A (en) * 2021-05-04 2022-11-11 계명대학교 산학협력단 Method and apparatus for providing lightweight blockchain using external strorage and pbft consensus algorithm
CN115567550A (en) * 2022-09-22 2023-01-03 北京工业大学 File information data storage method based on block chain and national cryptographic algorithm

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106910051A (en) * 2017-01-11 2017-06-30 中国互联网络信息中心 A kind of DNS resource record notarization method and system based on alliance's chain
CN107273410A (en) * 2017-05-03 2017-10-20 上海点融信息科技有限责任公司 Distributed storage based on block chain
CN107563905A (en) * 2017-07-20 2018-01-09 西安电子科技大学 A kind of academic platform service system and method for building up based on block chain
CN107613041A (en) * 2017-09-22 2018-01-19 中国互联网络信息中心 DNS management system, domain name management method and domain name analytic method based on block chain
CN108023894A (en) * 2017-12-18 2018-05-11 苏州优千网络科技有限公司 Visa information system and its processing method based on block chain
WO2018213880A1 (en) * 2017-05-22 2018-11-29 Haventec Pty Ltd System for blockchain based domain name and ip number register
CN109034833A (en) * 2018-06-16 2018-12-18 复旦大学 A kind of product back-tracing information management system and method based on block chain
CN109327562A (en) * 2018-12-10 2019-02-12 中共中央办公厅电子科技学院 Domain name storage system and method based on block chain
CN109491968A (en) * 2018-11-13 2019-03-19 浙江鲸腾网络科技有限公司 A kind of document handling method, device, equipment and computer readable storage medium

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106910051A (en) * 2017-01-11 2017-06-30 中国互联网络信息中心 A kind of DNS resource record notarization method and system based on alliance's chain
CN107273410A (en) * 2017-05-03 2017-10-20 上海点融信息科技有限责任公司 Distributed storage based on block chain
WO2018213880A1 (en) * 2017-05-22 2018-11-29 Haventec Pty Ltd System for blockchain based domain name and ip number register
CN107563905A (en) * 2017-07-20 2018-01-09 西安电子科技大学 A kind of academic platform service system and method for building up based on block chain
CN107613041A (en) * 2017-09-22 2018-01-19 中国互联网络信息中心 DNS management system, domain name management method and domain name analytic method based on block chain
CN108023894A (en) * 2017-12-18 2018-05-11 苏州优千网络科技有限公司 Visa information system and its processing method based on block chain
CN109034833A (en) * 2018-06-16 2018-12-18 复旦大学 A kind of product back-tracing information management system and method based on block chain
CN109491968A (en) * 2018-11-13 2019-03-19 浙江鲸腾网络科技有限公司 A kind of document handling method, device, equipment and computer readable storage medium
CN109327562A (en) * 2018-12-10 2019-02-12 中共中央办公厅电子科技学院 Domain name storage system and method based on block chain

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
WENTONG WANG等: "《BlockZone: A Blockchain-Based DNS Storage and Retrieval Scheme》", 《INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND SECURITY》 *
XIANGUI WANG等: "《ConsortiumDNS: A Distributed Domain Name Service Based on Conssortium Chain》", 《2017 IEEE 19TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS》 *
王文通: "《基于区块链的DNS系统设计与实现》", 《中国优秀硕士学位论文全文数据库信息科技辑》 *

Cited By (92)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110492997A (en) * 2019-08-09 2019-11-22 华南理工大学 A kind of encryption system based on super account book, method, apparatus and storage medium
CN110492997B (en) * 2019-08-09 2020-12-01 华南理工大学 Encryption system, method, device and storage medium based on super account book
CN112468603A (en) * 2019-09-06 2021-03-09 傲为信息技术(江苏)有限公司 Domain name query system and method based on block chain
WO2021042784A1 (en) * 2019-09-06 2021-03-11 南京瑞祥信息技术有限公司 Domain name management system employing blockchain
WO2021042788A1 (en) * 2019-09-06 2021-03-11 南京瑞祥信息技术有限公司 Blockchain-based domain name query system and method
CN111031086A (en) * 2019-10-08 2020-04-17 安徽华博胜讯信息科技股份有限公司 Block chain data storage method and system
WO2021071421A1 (en) * 2019-10-10 2021-04-15 Standard Chartered Bank (Singapore) Limited Methods, systems, and devices for managing digital assets
US11164186B2 (en) 2019-10-10 2021-11-02 Standard Chartered Bank (Singapore) Limited Methods, systems, and devices for managing digital assets
CN111373402A (en) * 2019-11-08 2020-07-03 支付宝(杭州)信息技术有限公司 Lightweight decentralized application platform
US11429617B2 (en) 2019-11-08 2022-08-30 Alipay (Hangzhou) Information Technology Co., Ltd. System and method for blockchain-based data synchronization
CN110880966A (en) * 2019-11-22 2020-03-13 哈尔滨工业大学 Domain name resolution system building and domain name query method
CN110880966B (en) * 2019-11-22 2022-05-06 哈尔滨工业大学 Domain name resolution system building and domain name query method
CN111460489A (en) * 2019-12-09 2020-07-28 重庆锐云科技有限公司 Client persistent storage method based on IPFS (Internet protocol file system) block chain
CN111210223A (en) * 2019-12-17 2020-05-29 广东文储区块链科技有限公司 Method and system for clearing block chain of decentralized storage area
CN110737668A (en) * 2019-12-17 2020-01-31 腾讯科技(深圳)有限公司 Data storage method, data reading method, related device and medium
CN111200642B (en) * 2019-12-26 2022-08-23 下一代互联网关键技术和评测北京市工程研究中心有限公司 Authoritative DNS server information distribution method and system
CN111200642A (en) * 2019-12-26 2020-05-26 下一代互联网关键技术和评测北京市工程研究中心有限公司 Authoritative DNS server information distribution method and system
CN111144578B (en) * 2019-12-27 2023-07-28 创新奇智(重庆)科技有限公司 Artificial intelligence model management system and management method in distributed environment
CN111144578A (en) * 2019-12-27 2020-05-12 创新奇智(重庆)科技有限公司 Artificial intelligence model management system and management method under distributed environment
CN111061698B (en) * 2019-12-30 2023-09-05 语联网(武汉)信息技术有限公司 Method and device for storing Ethernet contract data
CN111061698A (en) * 2019-12-30 2020-04-24 语联网(武汉)信息技术有限公司 Storage method and device of Ether house contract data
CN111310238A (en) * 2020-02-12 2020-06-19 腾讯科技(深圳)有限公司 File management method and device
CN111310238B (en) * 2020-02-12 2024-05-14 腾讯科技(深圳)有限公司 File management method and device
CN111448565A (en) * 2020-02-14 2020-07-24 支付宝(杭州)信息技术有限公司 Data authorization based on decentralized identity
CN111448565B (en) * 2020-02-14 2024-04-05 支付宝(杭州)信息技术有限公司 Data authorization based on decentralised identification
CN111343267B (en) * 2020-02-24 2022-08-12 深圳木成林科技有限公司 Configuration management method and system
CN111343267A (en) * 2020-02-24 2020-06-26 深圳木成林科技有限公司 Configuration management method and system
CN111031076A (en) * 2020-03-06 2020-04-17 南京畅洋科技有限公司 Internet of things block chain consensus method based on timing mechanism
CN111445245A (en) * 2020-03-27 2020-07-24 北京瑞卓喜投科技发展有限公司 Certificate index updating method and device for security type general certificate
CN111177277A (en) * 2020-04-10 2020-05-19 支付宝(杭州)信息技术有限公司 Data storage method, transaction storage method and device
CN111901447B (en) * 2020-05-27 2022-09-20 伏羲科技(菏泽)有限公司 Domain name data management method, device, equipment and storage medium
CN111901447A (en) * 2020-05-27 2020-11-06 伏羲科技(菏泽)有限公司 Domain name data management method, device, equipment and storage medium
CN111885212A (en) * 2020-06-03 2020-11-03 山东伏羲智库互联网研究院 Domain name storage method and device
CN111885212B (en) * 2020-06-03 2023-05-30 山东伏羲智库互联网研究院 Domain name storage method and device
CN111936995A (en) * 2020-06-08 2020-11-13 支付宝实验室(新加坡)有限公司 Distributed storage of customs clearance data
CN111858627B (en) * 2020-06-24 2024-05-31 南京信息职业技术学院 System and method for inquiring academic calendar based on blockchain
CN111858627A (en) * 2020-06-24 2020-10-30 南京信息职业技术学院 Academic degree and academic calendar query system and method based on block chain
CN111835884B (en) * 2020-07-13 2022-11-04 北京好扑信息科技有限公司 Virtual address generation method for block chain
CN111835884A (en) * 2020-07-13 2020-10-27 北京好扑信息科技有限公司 Virtual address generation method for block chain
CN112187900B (en) * 2020-09-18 2022-03-01 中国科学院计算技术研究所 DNS data updating method and system based on block chain shared cache
CN112187900A (en) * 2020-09-18 2021-01-05 中国科学院计算技术研究所 DNS data updating method and system based on block chain shared cache
US11757652B2 (en) * 2020-09-25 2023-09-12 Wickr Inc. Decentralized system for securely resolving domain names
US20220103370A1 (en) * 2020-09-25 2022-03-31 Wickr Inc. Decentralized system for securely resolving domain names
CN112256662A (en) * 2020-10-22 2021-01-22 安徽农业大学 Storage and tracing method, device, equipment and storage medium for agricultural product information block chain
CN112241435A (en) * 2020-10-23 2021-01-19 山西特信环宇信息技术有限公司 Cone block chain storage system and consensus storage method
CN112286881B (en) * 2020-10-28 2024-04-05 金蝶云科技有限公司 Document authentication tracing method and device
CN112286881A (en) * 2020-10-28 2021-01-29 金蝶云科技有限公司 Document authentication and tracing method and device
CN112214456A (en) * 2020-11-05 2021-01-12 深圳市瀚兰区块链地产有限公司 House property data processing method and device and electronic equipment
CN112214456B (en) * 2020-11-05 2022-05-10 深圳市瀚兰区块链地产有限公司 House property data processing method and device and electronic equipment
CN112437089A (en) * 2020-11-26 2021-03-02 交控科技股份有限公司 Train control system key management method and device based on block chain
CN112702390B (en) * 2020-12-07 2022-04-15 北京大学 Block chain-based networking method and device for intelligent contract resources
CN112702390A (en) * 2020-12-07 2021-04-23 北京大学 Block chain-based networking method and device for intelligent contract resources
CN112686673A (en) * 2020-12-18 2021-04-20 上海黑犇互联网科技有限公司 Article traceability system based on IPFS and ETH
CN112637330A (en) * 2020-12-22 2021-04-09 山东大学 Block chain large file copy address selection method, system, equipment and storage medium
CN112529581A (en) * 2020-12-23 2021-03-19 广州大学 Domain name data storage system based on block chain and data transaction implementation method thereof
CN112822279A (en) * 2021-01-13 2021-05-18 精英数智科技股份有限公司 Monitoring method and device based on intelligent sensing and trusted storage
CN112818038A (en) * 2021-02-02 2021-05-18 山东伏羲智库互联网研究院 Data management method based on combination of block chain and IPFS (Internet protocol file system) and related equipment
CN112948847A (en) * 2021-02-02 2021-06-11 山东伏羲智库互联网研究院 Data sharing system based on block chain and data correctness verification method
CN112948847B (en) * 2021-02-02 2024-05-10 山东伏羲智库互联网研究院 Block chain-based data sharing system and data correctness verification method
CN113064886A (en) * 2021-03-04 2021-07-02 广州中国科学院计算机网络信息中心 Method for storing and managing identification resources
CN113064886B (en) * 2021-03-04 2023-08-29 广州中国科学院计算机网络信息中心 Method for storing and marking management of identification resource
CN113127811B (en) * 2021-03-09 2024-03-19 西北大学 Cultural relic digital resource safe sharing method, system and information data processing terminal
CN113127811A (en) * 2021-03-09 2021-07-16 西北大学 Cultural relic digital resource safety sharing method, cultural relic digital resource safety sharing system and information data processing terminal
CN115150355A (en) * 2021-03-15 2022-10-04 正链科技(深圳)有限公司 Method for realizing distributed domain name
CN113064876B (en) * 2021-03-25 2024-06-04 北京知料科技有限公司 IPFS file processing method
CN113064876A (en) * 2021-03-25 2021-07-02 芝麻链(北京)科技有限公司 IPFS file processing method
CN113098941A (en) * 2021-03-25 2021-07-09 浙江大学 Virtual reality content distributed management method and system based on integral excitation
CN113064898A (en) * 2021-04-06 2021-07-02 北京瑞卓喜投科技发展有限公司 Retrieval method and device based on miniature index of contract on chain and electronic equipment
CN113067836A (en) * 2021-04-20 2021-07-02 哈尔滨工业大学 Intelligent contract system based on decentralized DNS root zone management
CN113067836B (en) * 2021-04-20 2022-04-19 哈尔滨工业大学 Intelligent contract system based on decentralized DNS root zone management
CN113157698A (en) * 2021-04-23 2021-07-23 上海和数软件有限公司 Data query verification method and system based on block chain technology
KR20220150728A (en) * 2021-05-04 2022-11-11 계명대학교 산학협력단 Method and apparatus for providing lightweight blockchain using external strorage and pbft consensus algorithm
KR102650336B1 (en) 2021-05-04 2024-03-22 계명대학교 산학협력단 Method and apparatus for providing lightweight blockchain using external strorage and pbft consensus algorithm
CN113312640A (en) * 2021-05-31 2021-08-27 天津理工大学 Software data integrity multi-party consensus method based on trusted computing
CN113312640B (en) * 2021-05-31 2022-05-24 天津理工大学 Software data integrity multi-party consensus method based on trusted computing
CN113422767A (en) * 2021-06-21 2021-09-21 哈尔滨工业大学 Domain name registration management method and system based on block chain
CN114629631A (en) * 2021-07-21 2022-06-14 国网河南省电力公司信息通信公司 Data credible interaction method and system based on alliance chain and electronic equipment
CN114629631B (en) * 2021-07-21 2024-01-09 国网河南省电力公司信息通信公司 Data trusted interaction method and system based on alliance chain and electronic equipment
CN113538149A (en) * 2021-07-28 2021-10-22 浙江数秦科技有限公司 Multisource data fusion platform based on block chain
CN113538149B (en) * 2021-07-28 2024-02-27 浙江数秦科技有限公司 Multi-source data fusion platform based on block chain
CN113608703B (en) * 2021-08-24 2024-06-07 上海点融信息科技有限责任公司 Data processing method and device
CN113608703A (en) * 2021-08-24 2021-11-05 上海点融信息科技有限责任公司 Data processing method and device
CN113657899A (en) * 2021-10-19 2021-11-16 支付宝(杭州)信息技术有限公司 Method, device and system for transferring property right
CN114117545A (en) * 2021-11-08 2022-03-01 重庆邮电大学 Tamper-proof electronic certification system and implementation method thereof
CN114185997A (en) * 2022-02-17 2022-03-15 天津眧合数字科技有限公司 Pet information credible storage system based on block chain
CN114185997B (en) * 2022-02-17 2022-05-13 天津眧合数字科技有限公司 Pet information credible storage system based on block chain
CN114666277A (en) * 2022-05-05 2022-06-24 中国互联网络信息中心 Data processing method and device based on domain name
CN114666277B (en) * 2022-05-05 2023-10-24 中国互联网络信息中心 Domain name based data processing method and device
CN115174385A (en) * 2022-06-15 2022-10-11 桂林电子科技大学 Industrial Internet of things equipment firmware software updating method based on block chain
CN115174385B (en) * 2022-06-15 2024-04-02 桂林电子科技大学 Firmware software updating method for industrial Internet of things equipment based on blockchain
CN115567550A (en) * 2022-09-22 2023-01-03 北京工业大学 File information data storage method based on block chain and national cryptographic algorithm
CN115567550B (en) * 2022-09-22 2024-06-21 北京工业大学 File information data storage method based on blockchain and cryptographic algorithm

Also Published As

Publication number Publication date
CN110061838B (en) 2022-07-19

Similar Documents

Publication Publication Date Title
CN110061838A (en) A kind of the decentralization storage system and its realization, information retrieval method of DNS resource record
US11831772B2 (en) Blockchain multi-party shared-governance-based system for maintaining domain name information
CN108124502B (en) Top-level domain name management method and system based on alliance chain
CN107613041B (en) Domain name management system, domain name management method and domain name resolution method based on block chain
CN108064444B (en) Domain name resolution system based on block chain
CN110945853B (en) Method for generating and managing multimode identification network based on alliance chain voting consensus algorithm
US11930113B2 (en) Blockchain hybrid consensus-based system for maintaining domain name information
CN112311530B (en) Block chain-based alliance trust distributed identity certificate management authentication method
CN109327562B (en) Domain name storage system and method based on block chain
US11368450B2 (en) Method for bidirectional authorization of blockchain-based resource public key infrastructure
CN102045413B (en) DHT expanded DNS mapping system and method for realizing DNS security
KR101330392B1 (en) Network nodes and methods for data authorization in distributed storage networks
Ooi et al. Managing trust in peer-to-peer systems using reputation-based techniques
US11521205B2 (en) Method for certificate transaction validation of blockchain-based resource public key infrastructure
CN108366137A (en) The method and root DNS that domain name is handled based on block chain
CN108366138A (en) Domain name operating method, system and electronic equipment
CN111031010B (en) Certificate transaction warning method of resource public key infrastructure based on block chain
CN106790296A (en) Domain name records verification method and device
CN112116349B (en) High-throughput-rate-oriented random consensus method and device for drawing account book
JP2006236349A5 (en)
JP2006236349A (en) Peer-to-peer network information
CN110868446A (en) Back IP main power network system architecture
CN112039837B (en) Electronic evidence preservation method based on block chain and secret sharing
CN117407437A (en) Block chain-based data processing method, equipment and readable storage medium
CN107659574A (en) A kind of data access control system

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant