TWI568215B - Methods for handling requests between different resource record types and systems thereof - Google Patents
Methods for handling requests between different resource record types and systems thereof Download PDFInfo
- Publication number
- TWI568215B TWI568215B TW101116777A TW101116777A TWI568215B TW I568215 B TWI568215 B TW I568215B TW 101116777 A TW101116777 A TW 101116777A TW 101116777 A TW101116777 A TW 101116777A TW I568215 B TWI568215 B TW I568215B
- Authority
- TW
- Taiwan
- Prior art keywords
- resource record
- ipv6
- signature
- traffic management
- management device
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims description 30
- 230000004044 response Effects 0.000 claims description 48
- 238000012545 processing Methods 0.000 claims description 17
- 238000012795 verification Methods 0.000 claims description 16
- 238000007726 management method Methods 0.000 description 107
- 238000004891 communication Methods 0.000 description 18
- 230000001360 synchronised effect Effects 0.000 description 8
- 238000005516 engineering process Methods 0.000 description 6
- 230000008569 process Effects 0.000 description 6
- 239000000835 fiber Substances 0.000 description 4
- 230000003068 static effect Effects 0.000 description 4
- 238000012546 transfer Methods 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 239000003795 chemical substances by application Substances 0.000 description 3
- 230000006870 function Effects 0.000 description 3
- 230000007246 mechanism Effects 0.000 description 3
- 230000005540 biological transmission Effects 0.000 description 2
- 230000015572 biosynthetic process Effects 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 238000009434 installation Methods 0.000 description 2
- 238000013507 mapping Methods 0.000 description 2
- 239000000203 mixture Substances 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 230000003287 optical effect Effects 0.000 description 2
- 230000002093 peripheral effect Effects 0.000 description 2
- 238000003786 synthesis reaction Methods 0.000 description 2
- 230000001133 acceleration Effects 0.000 description 1
- 230000004075 alteration Effects 0.000 description 1
- 238000004458 analytical method Methods 0.000 description 1
- 238000003491 array Methods 0.000 description 1
- 239000002131 composite material Substances 0.000 description 1
- 235000014510 cooky Nutrition 0.000 description 1
- 230000009977 dual effect Effects 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 239000004744 fabric Substances 0.000 description 1
- 230000006855 networking Effects 0.000 description 1
- 230000010076 replication Effects 0.000 description 1
- 230000002441 reversible effect Effects 0.000 description 1
- 239000007787 solid Substances 0.000 description 1
- 230000002194 synthesizing effect Effects 0.000 description 1
- 238000013519 translation Methods 0.000 description 1
- 230000005641 tunneling Effects 0.000 description 1
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
Description
本技術大體涉及網路通信,尤其是處理不同資源記錄類型之間的請求的系統和方法。 The present technology generally relates to network communications, and more particularly to systems and methods for processing requests between different resource record types.
電腦網路(比如,網際網路)正在緩慢而吃力地從網際網路協議第4版(IPv4)轉換到網際網路協議第6版(IPv6):緩慢是由於如果所有的網路設備均部署IPv6,部署IPv6才是最有用的(“網路效應”),吃力是由於需要更新軟體和/或硬體。一個示例方案為DNS64,其為把在IPv4中使用的A記錄合成為在IPv6中使用的AAAA資源記錄(或,4-A記錄)的示例性機制。但是,如果請求AAAA資源位址的DNS客戶端和DNS伺服器之間的DNS64軟體已經進行了AAAA資源記錄的合成但是不能對合成的AAAA資源記錄簽名,下游驗證器會將合成的AAAA資源記錄類型標記為無效,這是由於傳統的技術不能驗證合成的AAAA資源記錄所造成。當轉換到IPv6時(針對的是源自A響應的AAAA響應,該A響應為不同於該AAAA響應的資源記錄類型),與IPv4A資源記錄類型相關的原始資源記錄簽名(RRSIG)變成無效。因此,DNS64的傳統實現方式破壞了域名系統安全擴展(DNSSEC)。遺憾的是,使用傳統技術會獲得未通過驗證的AAAA資源記錄響應,這對請求該資源記錄的客戶端設備構成安全威脅,並造成 其DNSSEC不能實現。 Computer networks (such as the Internet) are slowly and steadily switching from Internet Protocol version 4 (IPv4) to Internet Protocol version 6 (IPv6): slow because if all network devices are deployed IPv6, IPv6 deployment is the most useful ("network effect"), the difficulty is due to the need to update software and / or hardware. One example solution is DNS64, which is an exemplary mechanism for synthesizing A records used in IPv4 into AAAA resource records (or 4-A records) used in IPv6. However, if the DNS64 software between the DNS client requesting the AAAA resource address and the DNS server has already synthesized the AAAA resource record but cannot sign the synthesized AAAA resource record, the downstream authenticator will synthesize the AAAA resource record type. Marked as invalid because traditional techniques cannot verify synthetic AAAA resource records. When transitioning to IPv6 (for an AAAA response originating from an A response, which is a different resource record type than the AAAA response), the original resource record signature (RRSIG) associated with the IPv4A resource record type becomes invalid. Therefore, the traditional implementation of DNS64 undermines the Domain Name System Security Extension (DNSSEC). Unfortunately, using traditional techniques results in an unverified AAAA resource record response, which poses a security threat to the client device requesting the resource record and causes Its DNSSEC cannot be implemented.
本技術的一個示例為一種處理不同資源記錄類型之間的請求之方法。該方法包括在流量管理設備處根據客戶端設備的請求從一個或多個伺服器設備接收第一資源記錄類型。該流量管理設備驗證該第一資源記錄類型,並在驗證後創建對應於該第一資源記錄類型的第二資源記錄類型。在該流量管理設備對第二資源記錄類型簽名,從而為該客戶端設備的該請求提供服務。 One example of the present technology is a method of processing requests between different resource record types. The method includes receiving, at a traffic management device, a first resource record type from one or more server devices in accordance with a request by a client device. The traffic management device verifies the first resource record type and creates a second resource record type corresponding to the first resource record type after verification. The traffic management device signs the second resource record type to service the request of the client device.
另一示例為儲存用於處理不同資源記錄類型之間的請求的指令的電腦可讀媒體,當被至少一處理器執行時,使該處理器進行一系列步驟。該步驟包括在流量管理設備根據客戶端設備的請求從一個或多個伺服器設備接收第一資源記錄類型。另外,該步驟包括在該流量管理設備驗證該第一資源記錄類型,並在驗證後創建對應於該第一資源記錄類型的第二資源記錄類型;在該流量管理設備對該第二資源記錄類型簽名,從而為該客戶端設備的請求提供服務。 Another example is a computer readable medium storing instructions for processing requests between different resource record types that, when executed by at least one processor, cause the processor to perform a series of steps. The step includes receiving, by the traffic management device, a first resource record type from one or more server devices in response to a request by the client device. In addition, the step includes: verifying, by the traffic management device, the first resource record type, and after the verifying, creating a second resource record type corresponding to the first resource record type; and the traffic management device is configured to the second resource record type Signature to service the request of the client device.
另一示例為流量管理設備,其包括用於執行一個或多個流量管理應用程式的一個或多個處理器;通過一匯流排與該一個或多個處理器連接的記憶體;以及與該一個或多個處理器和記憶體連接之網路介面控制器,其經配置以接收來自一網路所涉及執行多個流量管理應用程式的數據封包且處理不同資源記錄類型之間請求的。在該示例中,該 一個或多個處理器中至少一者經配置以執行該記憶體中所儲存的程式指令,且具有邏輯的該網路介面控制器進一步經配置以實施下述:根據客戶端設備的請求在流量管理設備處接收來自一個或多個伺服器設備的第一資源記錄類型。前述實施包含在流量管理設備處驗證第一資源記錄類型;及在驗證後創建對應於第一資源記錄類型的第二資源記錄類型。對該第二資源記錄類型簽名從而為客戶端設備的請求提供服務。 Another example is a traffic management device that includes one or more processors for executing one or more traffic management applications; a memory coupled to the one or more processors via a bus; and the one Or a plurality of processor and memory connected network interface controllers configured to receive data packets from a network involved in executing a plurality of traffic management applications and to process requests between different resource record types. In this example, the At least one of the one or more processors is configured to execute program instructions stored in the memory, and the network interface controller having logic is further configured to implement the following: traffic in response to a request by the client device The management device receives the first resource record type from one or more server devices. The foregoing implementation includes verifying the first resource record type at the traffic management device; and creating a second resource record type corresponding to the first resource record type after verification. The second resource record type is signed to service the request of the client device.
這些示例給安全處理請求和動態實時或「即時」地把請求從一種資源記錄類型轉換成另一種類型帶來諸多好處。僅作為示例,所揭示技術能給DNS64實時動態部署DNSSEC代理,從而在IPv4和IPv6環境之間維持完整的信任關係或信任鏈。即使當AAAA記錄通過DNS64設備(比如,流量管理設備)合成時,仍然維持了信任鏈,因為該合成的AAAA記錄是通過在該合成發生的DNS64設備處附上簽名來驗證的。因此,當請求的資源記錄類型未從伺服器未獲得時,對該合成或創建的示例性資源記錄類型的AAAA資源記錄進行的驗證使該請求的響應有效,從而滿足響應設備(比如,伺服器)的DNSSEC。需要指出,儘管在上述示例中對AAAA和A資源記錄類型進行了討論,但是該技術也適用於其他類型的資源記錄,包括但不限於安德魯檔案系統數據庫(AFSDB)記錄、規範名稱(CNAME)記錄、主機信息(HINFO)記錄、整合服務數位網路(ISDN)記錄、位置(LOC)記錄、郵件交換(MX)記錄、郵件群 組(MG)記錄、郵箱(MB)記錄、郵箱信息(MINFO)記錄、郵箱重命名(MR)記錄、名稱伺服器(NS)記錄、網路服務存取協議(NSAP)記錄、公鑰(KEY)記錄、負責人(RP)記錄、反向查詢指針(PTR)記錄、路徑方向(RT)記錄、起始授權機構(SOA)記錄、文字(TXT)記錄、公認服務(WKS)記錄、X.400位址映射(PX)記錄、X25位址映射(X25)記錄等。結合附圖,上述或其他優點、方面和特徵在下面的詳細說明中會更加清晰。結合附圖對非限制性和非窮盡的示例進行說明。因此,下面的附圖和說明為說明性的,而非限定性或限制性的。 These examples provide a number of benefits for securely processing requests and dynamically converting requests from one resource record type to another in real time or "on the fly". By way of example only, the disclosed technology can dynamically deploy DNSSEC proxy to DNS64 in real time to maintain a complete trust relationship or chain of trust between the IPv4 and IPv6 environments. Even when the AAAA record is synthesized by a DNS64 device (for example, a traffic management device), the chain of trust is maintained because the synthesized AAAA record is verified by attaching a signature to the DNS64 device in which the synthesis occurs. Therefore, when the requested resource record type is not obtained from the server, the verification of the synthesized or created exemplary resource record type AAAA resource record validates the response of the request, thereby satisfying the response device (eg, the server) ) DNSSEC. It should be noted that although the AAAA and A resource record types are discussed in the above example, the technique is also applicable to other types of resource records, including but not limited to Andrew File System Database (AFSDB) records, canonical name (CNAME) records. Host information (HINFO) records, integrated services digital network (ISDN) records, location (LOC) records, mail exchange (MX) records, mail groups Group (MG) record, mailbox (MB) record, mailbox information (MINFO) record, mailbox rename (MR) record, name server (NS) record, network service access protocol (NSAP) record, public key (KEY Records, Responsible Person (RP) records, Reverse Query Point (PTR) records, Path Direction (RT) records, Start of Authority (SOA) records, Text (TXT) records, Accepted Services (WKS) records, X. 400 address mapping (PX) records, X25 address mapping (X25) records, and so on. The above and other advantages, aspects and features will become more apparent from the following detailed description. Non-limiting and non-exhaustive examples are described in conjunction with the drawings. The following drawings and description are to be regarded as illustrative and not restrict
所揭示技術中的多個示例使流量管理設備110能夠處理來自客戶端設備的第一資源記錄類型的請求,並基於來自伺服器設備的不同或第二資源記錄類型的響應為這些請求提供服務。比如,在IPv6單一環境中運行的客戶端設備需要與在IPv4單一環境中運行的伺服器通信。流量管理設備110驗證其自身合成或從伺服器接收的響應來回應請求。在一個示例中,流量管理設備110驗證IPv6客戶端設備的AAAA資源記錄類型,當存在來自伺服器的IPv4 A資源記錄類型響應時,在流量管理設備110創建AAAA資源記錄類型,使得合成的AAAA資源記錄類型對應於流量管理設備110接收的A資源記錄類型。 A number of examples in the disclosed technology enable the traffic management device 110 to process requests for the first resource record type from the client device and service these requests based on responses from different or second resource record types of the server device. For example, a client device running in a single IPv6 environment needs to communicate with a server running in a single IPv4 environment. Traffic management device 110 verifies its own composition or response received from the server to respond to the request. In one example, the traffic management device 110 verifies the AAAA resource record type of the IPv6 client device, and when there is an IPv4 A resource record type response from the server, creates an AAAA resource record type at the traffic management device 110, such that the synthesized AAAA resource The record type corresponds to the A resource record type received by the traffic management device 110.
參照圖1,示出了示例性網路系統100,其包括用於處 理不同資源記錄類型之間請求的流量管理設備110。僅作為示例,網路112可根據本示例中基於超文字傳輸協議(HTTP)的應用、各種意見請求(RFC)文件指南或通用網際網路檔案系統(CIFS)或網路檔案系統(NFS)協議來接收請求並提供響應,當然本申請所討論的原理不限於這些示例,還可包括其他應用協議和其他類型的請求(比如,基於檔案傳輸協議(FTP)的請求)。該示例性網路系統100可包括一系列的一個或多個客戶端設備,比如,客戶端電腦104(1)到104(n)。客戶端電腦104(1)到104(n)通過包含負載均衡設備106(1)到106(n)的多個負載均衡設備106與流量管理設備110連接,每個負載均衡設備具有一個基於資源記錄類型格式的唯一的網路位址(比如唯一的128位元IPv6位址)。流量管理設備110設置在伺服器102(1)到102(n)和客戶端設備104(1)到104(n)之間來提供從網路112到區域網路(LAN)114的一個或多個通信信道,當然也可在沒有網路112和/或區域網路114的網路系統100的各設備之間直接建立其他通信信道。為清晰和簡要,在圖1中示出了兩個伺服器設備102(1)和102(n),但是應理解:任意數量的伺服器設備可使用於該示例性網路系統100。同理,在圖1中示出三個客戶端設備104(1),104(2),104(n)和一個流量管理設備110,但是任意數量的客戶端設備和流量管理設備也均可使用於該示例性網路系統100。儘管示出的是網路112和區域網路114,但是也可使用其他數量和類型的網路。省略號和符號 “n”分別表示數量不限定的伺服器設備和客戶端設備。 Referring to Figure 1, an exemplary network system 100 is illustrated that includes A traffic management device 110 that requests between different resource record types. By way of example only, network 112 may be based on Hypertext Transfer Protocol (HTTP) based applications, various opinion request (RFC) file guides, or the Common Internet File System (CIFS) or Network File System (NFS) protocol in this example. To receive requests and provide responses, of course, the principles discussed herein are not limited to these examples, but may include other application protocols and other types of requests (eg, File Transfer Protocol (FTP) based requests). The exemplary network system 100 can include a series of one or more client devices, such as client computers 104(1) through 104(n). Client computers 104(1) through 104(n) are coupled to traffic management device 110 by a plurality of load balancing devices 106 including load balancing devices 106(1) through 106(n), each having a resource based record A unique network address in the type format (such as a unique 128-bit IPv6 address). The traffic management device 110 is disposed between the servers 102(1) through 102(n) and the client devices 104(1) through 104(n) to provide one or more of the slave network 112 to the local area network (LAN) 114. Communication channels, of course, may also establish other communication channels directly between devices of network system 100 without network 112 and/or regional network 114. For clarity and brevity, two server devices 102(1) and 102(n) are shown in FIG. 1, but it should be understood that any number of server devices may be used with the exemplary network system 100. Similarly, three client devices 104(1), 104(2), 104(n) and one traffic management device 110 are shown in FIG. 1, but any number of client devices and traffic management devices can also be used. In the exemplary network system 100. Although network 112 and area network 114 are shown, other numbers and types of networks may be used. Ellipsis and symbol "n" denotes an unlimited number of server devices and client devices, respectively.
伺服器102(1)到102(n)(也稱為伺服器設備102(1)到102(n))包括一個或多個能運行一個或多個基於Web的應用程式的伺服器電腦或設備,其可由網路112中的網路設備,比如,客戶端電腦104(1)到104(n),經由多個負載均衡器106和流量管理設備110進行訪問,並可提供代表所請求資源的其他數據,比如域名服務和區域、對應於URL請求的特殊Web頁面、實體對象的圖像和其他任意對象,來響應請求,當然,伺服器102(1)到102(n)還可進行其他任務並提供其他類型的資源。在該示例中,伺服器102(1)到102(n)中的至少一個為滿足客戶端電腦104(1)到104(n)各種請求的IPv4單一設備。或者或通常來說,伺服器102(1)到102(n)可以是一組提供與客戶端電腦104(1)到104(n)所請求和處理的資源記錄類型不同的資源記錄響應的設備。需要指出的是,儘管在圖1的網路系統100中只示出了兩個伺服器102(1)和102(n),其他數量和類型的伺服器也可與流量管理設備110連接。同樣設想到:伺服器102(1)到102(n)中一者或多者可以是網路流量管理設備(比如流量管理設備110)管理的集群伺服器。 Servers 102(1) through 102(n) (also referred to as server devices 102(1) through 102(n)) include one or more server computers or devices capable of running one or more web-based applications It may be accessed by network devices in network 112, such as client computers 104(1) through 104(n), via multiple load balancers 106 and traffic management device 110, and may provide representation of the requested resources. Other data, such as domain name services and zones, special web pages corresponding to URL requests, images of entity objects, and any other objects, respond to requests. Of course, servers 102(1) through 102(n) can perform other tasks. And provide other types of resources. In this example, at least one of the servers 102(1) through 102(n) is an IPv4 single device that satisfies various requests from the client computers 104(1) through 104(n). Alternatively or in general, servers 102(1) through 102(n) may be a set of devices that provide different resource record responses than the resource record types requested and processed by client computers 104(1) through 104(n). . It should be noted that although only two servers 102(1) and 102(n) are shown in the network system 100 of FIG. 1, other numbers and types of servers may be coupled to the traffic management device 110. It is also contemplated that one or more of servers 102(1) through 102(n) may be a cluster server managed by a network traffic management device, such as traffic management device 110.
該示例中的客戶端電腦104(1)到104(n)(也可稱為客戶端設備104(1)到104(n),客戶端計算設備104(1)到104(n),客戶端104(1)到104(n)以及客戶端計算系統104(1)到104(n))可運行比如Web瀏覽器 等介面應用程式,這些介面應用程式能夠提供介面,以通過一個或多個與網路112相連的負載均衡設備和/或通過流量管理設備110向基於Web伺服器的不同應用程式請求(包括IPv6請求)及發送數據。一系列網路應用程式能在可傳輸客戶端電腦104(1)到104(n)請求的數據的伺服器102(1)到102(n)上運行。伺服器102(1)到102(n)能提供數據或接收數據來響應來自客戶端電腦104(1)到104(n)的針對伺服器102(1)到102(n)上的各個應用程式的請求。比如,可根據傳輸控制協議(TCP)將數據封包從發出請求的客戶端電腦104(1)到104(n)發送到伺服器102(1)到102(n)來發送數據,當然也可使用其他協議(比如,FTP)。可理解的是,伺服器102(1)到102(n)可以是硬體或在硬體上執行並且由硬體支持的軟體,或可代表具有多個伺服器的系統,其可包括內部或外部網路。伺服器102(1)到102(n)可以是具有將一個或多個網址區域托管(hosting)的域名系統(DNS)能力的域名伺服器。 Client computers 104(1) through 104(n) in this example (also referred to as client devices 104(1) through 104(n), client computing devices 104(1) through 104(n), clients 104(1) through 104(n) and client computing systems 104(1) through 104(n) can run, for example, a web browser Interface applications that provide an interface to request (including IPv6 requests) to different web server-based applications via one or more load balancing devices connected to network 112 and/or through traffic management device 110 ) and send data. A series of web applications can run on servers 102(1) through 102(n) that can transmit data requested by client computers 104(1) through 104(n). Servers 102(1) through 102(n) can provide data or receive data in response to respective applications from clients 102(1) through 104(n) for servers 102(1) through 102(n) Request. For example, data packets may be sent from the requesting client computers 104(1) through 104(n) to the servers 102(1) through 102(n) according to the Transmission Control Protocol (TCP) to transmit data, although of course Other protocols (for example, FTP). It will be appreciated that the servers 102(1) through 102(n) may be hardware or hardware implemented on hardware and supported by hardware, or may represent a system having multiple servers, which may include internal or External network. Servers 102(1) through 102(n) may be domain name servers having Domain Name System (DNS) capabilities that host one or more URL regions.
通常,比如客戶端電腦104(1)到104(n)等客戶端設備可包括實際上能與另一計算設備相連的任意計算設備以發送和接收信息,包括基於Web的信息。如圖1所示,這組設備可包括通常使用有線(和/或無線)通信媒體連接的設備,比如,個人電腦(比如,臺式機、筆記本)、移動和/或智能手機等。比如,客戶端設備104(2)為除了音頻功能還具有網路功能的移動電話設備或智能手機。在該示例中,客戶端設備可運行瀏覽器和其他類型的應用程式 (、比如,基於web的應用程式),這些應用程式能夠提供介面,通過網路112向基於伺服器的不同應用程式提出一個或多個請求,當然,客戶端電腦104(1)到104(n)還可請求其他類型的網路應用程式和資源(比如,URL)。客戶端電腦104(1)到104(n)可用於通過各種類型的流量管理設備(比如,路由器、負載均衡器、應用程式遞送控制器等)向伺服器102(1)到102(n)提出IPv6 AAAA資源記錄類型請求。 In general, client devices, such as client computers 104(1) through 104(n), can include any computing device that can actually be connected to another computing device to send and receive information, including web-based information. As shown in FIG. 1, the set of devices may include devices that are typically connected using wired (and/or wireless) communication media, such as personal computers (eg, desktops, notebooks), mobile and/or smart phones, and the like. For example, the client device 104(2) is a mobile phone device or smart phone that has a network function in addition to an audio function. In this example, the client device can run browsers and other types of applications. (For example, web-based applications), these applications can provide an interface to make one or more requests to different server-based applications over the network 112, of course, client computers 104(1) through 104(n). You can also request other types of web applications and resources (such as URLs). Client computers 104(1) through 104(n) may be used to present to servers 102(1) through 102(n) through various types of traffic management devices (eg, routers, load balancers, application delivery controllers, etc.) IPv6 AAAA resource record type request.
如將在下文討論,客戶端電腦104(1)到104(n)可通過多個負載均衡設備106提交請求,該負載均衡設備106將該請求轉發給本地或全局流量管理設備110來進行分析。在一示例中,負載均衡設備106(1)到106(n)為NAT64設備,當然如本領域的技術人員在閱讀本文件後能想到的,還可使用具有網路位址轉換(NAT)能力和/或其他能力的其他類型的負載均衡器。在有些示例中,流量管理設備110可以是多個負載均衡設備106的一部分。 As will be discussed below, client computers 104(1) through 104(n) may submit requests through a plurality of load balancing devices 106 that forward the request to local or global traffic management device 110 for analysis. In an example, load balancing devices 106(1) through 106(n) are NAT64 devices, although network address translation (NAT) capabilities may also be used, as will be appreciated by those skilled in the art after reading this document. And/or other types of load balancers of other capabilities. In some examples, traffic management device 110 can be part of multiple load balancing devices 106.
一系列基於Web和/或其他類型的保護和未保護的網路應用程式能在用以允許傳輸客戶端電腦104(1)到104(n)所請求的數據的伺服器102(1)到102(n)上運行。客戶端電腦104(1)到104(n)可進一步用於通過多個負載均衡設備106、本地域名伺服器(LDNS),或使用比如安全套接層(SSL)、網際網路協議安全(IPSec)、傳輸層安全(TLS)等方式直接與流量管理設備110和/或伺服器102(1)到102(n)安全通信。 A series of web-based and/or other types of protected and unprotected web applications can be used in servers 102(1)-102 to allow transmission of data requested by client computers 104(1) through 104(n). Run on (n). Client computers 104(1) through 104(n) may be further used to pass multiple load balancing devices 106, local domain name servers (LDNS), or use, for example, Secure Sockets Layer (SSL), Internet Protocol Security (IPSec) Modes such as Transport Layer Security (TLS) are in direct communication with traffic management device 110 and/or servers 102(1) through 102(n).
在該示例中,網路112包括具有客戶端電腦104(1)到104(n)的公共存取網路,比如網際網路,當然網路112還可包括具有其他設備的其他類型的專用和公共網路。本示例中,比如來自客戶端電腦104(1)到104(n)的請求和來自伺服器102(1)到102(n)的響應之通信是根據標準網路協議(比如,HTTP和TCP/IP協議)通過網路112進行的,但是本申請討論的原理並不限於該示例,還可包括其他協議(比如,FTP)。另外,網路112可包括區域網路(LAN)、廣域網路(WAN)、直接連接、其他類型和數量的網路類型及其任意組合。在一組互聯的區域網路或其他網路上(包括基於不同架構和協議的網路),路由器、交換器、集線器、閘道器、橋接器、縱橫式交換器(crossbar)以及其他中間網路設備可用作區域網路和其他網路內及其之間的鏈路以使消息和其他數據可發送自及發送給網路設備。另外,區域網路和其他網路內及其之間的通信鏈路通常包括雙絞線(比如,乙太網路)、同軸電纜、類比電話線、包括T1、T2、T3和T4的全部專用或部分專用數位線路、整合服務數位網路(ISDN)、數位用戶線路(DSL)、包括衛星線路的無線鏈路、光纖以及其他相關領域的技術人員已知的通信鏈路。通常,網路112包括可使數據在客戶端電腦104(1)到104(n)、伺服器102(1)到102(n)和流量管理設備110之間傳輸的任意通信媒體和方法,這裏所提供的這些設備僅是示例性的。 In this example, network 112 includes a public access network having client computers 104(1) through 104(n), such as the Internet, although network 112 may also include other types of dedicated and other devices. Public network. In this example, communications such as requests from client computers 104(1) through 104(n) and responses from servers 102(1) through 102(n) are based on standard network protocols (eg, HTTP and TCP/). The IP protocol is performed over the network 112, but the principles discussed herein are not limited to this example, and may include other protocols (e.g., FTP). In addition, network 112 can include a local area network (LAN), a wide area network (WAN), a direct connection, other types and numbers of network types, and any combination thereof. Routers, switches, hubs, gateways, bridges, crossbars, and other intermediate networks on a set of interconnected regional or other networks (including networks based on different architectures and protocols) Devices can be used as links within and between regional networks and other networks to enable messages and other data to be sent and sent to network devices. In addition, communication links within and between regional networks and other networks typically include twisted pair (eg, Ethernet), coaxial cable, analog telephone lines, and all dedicated to T1, T2, T3, and T4. Or part of a dedicated digital line, Integrated Services Digital Network (ISDN), Digital Subscriber Line (DSL), wireless links including satellite lines, fiber optics, and communication links known to those skilled in the relevant arts. In general, network 112 includes any communication medium and method that enables data to be transferred between client computers 104(1) through 104(n), servers 102(1) through 102(n), and traffic management device 110, here The devices provided are merely exemplary.
在該示例中,每個伺服器102(1)到102(n)、流量 管理設備110、負載均衡設備106和客戶端電腦104(1)到104(n)可包括通過匯流排或其他鏈路連接在一起的中央處理器(CPU)、控制器或處理器、記憶體以及介面系統,當然,也可使用其他數量和類型的每個該組件以及該組件的其他配置和位置。由於這些設備對於相關領域的技術人員來說是已知的,因此這裏不再詳述。 In this example, each server 102(1) to 102(n), traffic The management device 110, the load balancing device 106, and the client computers 104(1) through 104(n) may include a central processing unit (CPU), a controller or processor, a memory, and the like, connected together by a bus or other link. The interface system, of course, can also use other quantities and types of each of the components as well as other configurations and locations of the components. Since these devices are known to those skilled in the relevant art, they will not be described in detail herein.
另外,可用兩個或多個計算系統或設備代替網路系統100中的任意一個系統。因此,根據情况,還可實現雲端計算和/或分散式處理的原理和優點,比如,冗餘、複製、虛擬化等,從而增加網路系統100的設備和系統的穩健性和性能。網路系統100還可在這樣一種電腦系統上實現,該電腦系統拓展到使用了任意合適的介面機制和通信技術,比如,包括任何合適形式的電信(比如:聲音、調制解調器等)、公共交換電話網路(PSTN),封包數據網路(PDN)、網際網路、企業內部網路及其組合等的整個網路環境。 Additionally, any one of the network systems 100 can be replaced with two or more computing systems or devices. Thus, depending on the circumstances, the principles and advantages of cloud computing and/or decentralized processing, such as redundancy, replication, virtualization, etc., may also be implemented to increase the robustness and performance of the devices and systems of network system 100. Network system 100 can also be implemented on a computer system that is extended to use any suitable interface mechanism and communication technology, including, for example, any suitable form of telecommunications (eg, voice, modem, etc.), public switched telephone. The entire network environment of the network (PSTN), packet data network (PDN), internet, intranet, and combinations thereof.
僅作為示例而非限制,區域網路114包括具有與一個或多個伺服器102(1)到102(n)連接的流量管理設備110的專用區域網路,當然區域網路114還可包括具有其他設備的其他類型的專用和公共網路。除了相關領域的技術人員所理解的,已經對包括區域網路之網路連同網路112進行了說明,這裏不再贅述。 By way of example and not limitation, the local area network 114 includes a private area network having a traffic management device 110 coupled to one or more servers 102(1) through 102(n), although the regional network 114 may also include Other types of private and public networks for other devices. The network including the regional network has been described in connection with the network 112, as will be understood by those skilled in the relevant art, and will not be described herein.
如圖1的網路系統100的示例環境所示,流量管理設備110可如圖1所示設置在通過區域網路114連接的網路112和伺服器102(1)到102(n)之間。另或者,流量管 理設備110為處於網路112周邊的多個負載均衡設備106的一部分並且與區域網路114和/或伺服器102(1)到102(n)連接。再者,網路系統100可以其他方式設置,具有其他數量和類型的設備。另外,流量管理設備110通過一個或多個網路通信鏈路和中間網路設備(比如,路由器、交換器、閘道器、集線器、縱橫式交換矩陣以及其他設備)與網路112連接。應理解的是,圖1所示的設備和特殊配置僅作為示例而非限制。除了單個流量管理設備110,根據具體應用,還可有其他流量管理設備與該流量管理設備110串聯和/或並聯,從而形成集群,圖1所示的單個流量管理設備110僅作為示例而非限制。 As shown in the example environment of network system 100 of FIG. 1, traffic management device 110 can be disposed between network 112 and servers 102(1) through 102(n) connected by area network 114 as shown in FIG. . Alternatively, the flow tube The device 110 is part of a plurality of load balancing devices 106 that are peripheral to the network 112 and is connected to the regional network 114 and/or the servers 102(1) through 102(n). Moreover, network system 100 can be configured in other ways, with other numbers and types of devices. In addition, traffic management device 110 is coupled to network 112 via one or more network communication links and intermediate network devices (e.g., routers, switches, gateways, hubs, crossbar switch fabrics, and other devices). It should be understood that the device and special configuration shown in FIG. 1 are by way of example only and not limitation. In addition to a single traffic management device 110, other traffic management devices may be in series and/or in parallel with the traffic management device 110 depending on the particular application to form a cluster. The single traffic management device 110 shown in FIG. 1 is by way of example only and not limitation. .
通常,流量管理設備110管理來自/至這些示例中位於客戶端電腦104(1)到104(n)和區域網路114內一個或多個伺服器102(1)到102(n)之間的網路112的網路通信,這些網路通信包括一個或多個客戶端請求和伺服器響應。比如,這些請求可指定給一個或多個伺服器102(1)到102(n),且如上述可採取來自網路112、通過一個或多個中間網路設備和/或中間網路、直到最終到達流量管理設備110的一個或多個TCP/IP數據封包的形式。當在客戶端電腦104(1)到104(n)發起時,這些請求為第一資源記錄類型格式(比如,IPv6 4-A資源記錄類型請求或查詢),且由提供不同類型的資源記錄格式(比如,IPv4 A資源記錄類型響應)響應的伺服器102(1)到102(n)提供服務。 In general, traffic management device 110 manages from/to these instances between client computers 104(1) through 104(n) and regional network 114 within one or more servers 102(1) through 102(n). Network communication of network 112, which includes one or more client requests and server responses. For example, these requests may be assigned to one or more servers 102(1) through 102(n) and may be taken from network 112, through one or more intermediate network devices, and/or intermediate networks, as described above, until The form of one or more TCP/IP data packets that ultimately arrive at the traffic management device 110. When initiated by client computers 104(1) through 104(n), these requests are in the first resource record type format (eg, IPv6 4-A resource record type request or query) and are provided by different types of resource record formats. The servers 102(1) through 102(n) responding (eg, IPv4 A resource record type response) provide services.
在一示例中,流量管理設備110配置為全局伺服器負 載均衡設備以基於服務政策、數據中心條件、網路條件、用戶位置和應用性能分配終端用戶應用請求,這樣,客戶端電腦104(1)到104(n)的每個請求自動指向將一個或多個伺服器102(1)到102(n)設為主機的最近或性能最好的數據中心。在該示例中,流量管理設備110具有全局伺服器負載均衡能力,而在其他示例中,流量管理設備110可以是接收來自與區域網路114連接的全局伺服器負載均衡(GSLB)設備的響應的本地流量管理設備。僅作為示例,這種全局負載均衡設備可以是由華盛頓州西雅圖的F5網路公司提供的BIG-IP®全局流量管理器TM。另外,需要注意的是,儘管所示流量管理設備110獨立於多個負載均衡設備106,但是,在有些示例中,流量管理設備110本身可以是該多個負載均衡設備106中的一個。 In an example, traffic management device 110 is configured as a global server load balancing device to allocate end user application requests based on service policies, data center conditions, network conditions, user location, and application performance, such that client computer 104(1) Each request to 104(n) automatically points to the nearest or best performing data center that has one or more of the servers 102(1) through 102(n) set to the host. In this example, traffic management device 110 has global server load balancing capabilities, while in other examples, traffic management device 110 may be receiving responses from a Global Server Load Balancing (GSLB) device connected to regional network 114. Local traffic management device. For example only, the global load balancing device may be provided by the state of Washington in Seattle Internet company F5 BIG-IP ® Global Traffic Manager TM. Additionally, it should be noted that although the traffic management device 110 is shown as being separate from the plurality of load balancing devices 106, in some examples, the traffic management device 110 itself may be one of the plurality of load balancing devices 106.
此外,結合圖2和圖3進行詳述,流量管理設備110用於處理不同資源記錄類型之間的請求(比如,針對來自伺服器102(1)到102(n)的IPv4 A資源記錄的IPv6 4-A請求)。根據例如結合圖2和圖3進一步描述的系統和步驟,在任何情况下,流量管理設備110可通過執行多種涉及安全或非安全網路通信(比如,負載均衡、存取控制、VPN托管、網路流量加速、加密、解密、訊錄(cookie)和密鑰管理)的網路流量管理相關的功能以及提供驗證的域名服務來管理網路通信。 Furthermore, as detailed in connection with Figures 2 and 3, traffic management device 110 is configured to process requests between different resource record types (e.g., IPv6 for IPv4 A resource records from servers 102(1) through 102(n). 4-A request). In any case, the traffic management device 110 can perform a variety of security or non-secure network communications (eg, load balancing, access control, VPN hosting, networking, in accordance with, for example, systems and steps further described in conjunction with FIGS. 2 and 3. Network traffic management related functions such as traffic acceleration, encryption, decryption, cookies, and key management, and a domain name service that provides authentication to manage network communications.
參照圖2,示出了示例性的流量管理設備110。流量管理設備110內包括經由橋接器25與主機系統18連接以及 與輸入-輸出(I/O)設備30連接的系統匯流排26(也稱為匯流排26)。在該示例中,示出的單個I/O設備30表示與匯流排26相連的任意數量的I/O設備。在一示例中,橋接器25通過主機輸入輸出(I/O)端口29進一步與主機處理器20連接。主機處理器20可進一步通過快取記憶體21、主機記憶體22(通過記憶體端口53)和CPU匯流排202與網路介面控制器24連接。如上述,在主機處理器20中包括主機I/O端口29、記憶體端口53和主處理器(未單獨示出)。在該示例中,主機系統18包括儲存有演算法和指令/代碼的驗證模組208,從而通過給合成的資源記錄類型(比如,合成的IPv6 AAAA資源記錄類型)附上資源記錄簽名(RRSIG)來對在流量管理設備110創建的資源記錄進行驗證和簽名。需要注意的是,驗證模組208可用作硬體邏輯電路或邏輯電路與其上執行代碼的組合。另外,儘管示出的驗證模組208為單個模組/模塊,但是其功能可在流量管理設備110的各種組件之間以分布方式實現。此外,驗證模組208可為能通過標準介面端口與流量管理設備110直接連接的獨立設備。 Referring to Figure 2, an exemplary traffic management device 110 is shown. The flow management device 110 includes a connection to the host system 18 via a bridge 25 and A system bus 26 (also referred to as bus 26) that is coupled to an input-output (I/O) device 30. In this example, a single I/O device 30 is shown to represent any number of I/O devices connected to bus bar 26. In an example, bridge 25 is further coupled to host processor 20 via a host input/output (I/O) port 29. The host processor 20 can be further coupled to the network interface controller 24 via the cache memory 21, the host memory 22 (via the memory port 53), and the CPU bus 202. As described above, the host processor 20 includes a host I/O port 29, a memory port 53, and a main processor (not separately shown). In this example, host system 18 includes a verification module 208 that stores algorithms and instructions/codes to attach a resource record signature (RRSIG) to a synthesized resource record type (eg, a synthetic IPv6 AAAA resource record type). The resource records created at the traffic management device 110 are verified and signed. It should be noted that the verification module 208 can be used as a combination of a hardware logic circuit or a logic circuit and execution code thereon. Additionally, although the illustrated verification module 208 is a single module/module, its functionality can be implemented in a distributed manner between the various components of the traffic management device 110. In addition, the verification module 208 can be a standalone device that can be directly connected to the traffic management device 110 via a standard interface port.
在一示例中,流量管理設備110可包括具有下列任一組件配置特徵的主機處理器20:響應並處理從主機記憶體22獲取的指令的電腦可讀媒體和邏輯電路;微處理器單元,比如,由位於加利福尼亞州聖克拉拉(Santa Clara)的英特爾公司、位於伊利諾伊州紹姆堡(Schaumburg)的摩托羅拉公司、位於加利福尼亞聖克拉拉的全美達公司製造 的微處理器;RS/6000處理器,比如,由位於紐約州阿蒙克市(Armonk)的國際商業機器公司(IBM)製造的RS/6000處理器;處理器,比如,由位於加利福尼亞州桑尼維爾(Sunnyvale)的超微半導體公司(AMD)製造的處理器;或能執行本申請該的系統和方法的邏輯電路的其他任意組合。主機處理器20的其他示例可包括下列任意組合:微處理器、微控制器、單核中央處理器、雙核中央處理器或多核中央處理器。 In an example, traffic management device 110 can include host processor 20 having any of the following component configuration features: computer readable media and logic circuitry responsive to and processing instructions retrieved from host memory 22; Manufactured by Intel Corporation of Santa Clara, Calif., Motorola, Inc., Schaumburg, Ill., and Transmeta, Inc., Santa Clara, California Microprocessor; RS/6000 processor, for example, an RS/6000 processor manufactured by International Business Machines Corporation (IBM) in Armonk, NY; processor, for example, by San Francisco, California A processor manufactured by AMD, of Sunnyvale; or any other combination of logic circuits capable of performing the systems and methods of the present application. Other examples of host processor 20 may include any combination of the following: a microprocessor, a microcontroller, a single core central processing unit, a dual core central processing unit, or a multi-core central processing unit.
流量管理設備110的示例包括由位於華盛頓州西雅圖的F5網路公司提供的BIG-IP®產品系列的一個或多個應用遞送控制器設備,當然也可使用其他類型的流量管理設備。在示例性結構和/或設置中,流量管理設備110可包括通過次級匯流排(也稱為後部匯流排)與快取記憶體21通信的主機處理器20,而流量管理設備110的另一示例包括通過系統匯流排26與快取記憶體21連接的主機處理器20。在有些實施例中,主機處理器20還可使用本地系統匯流排26以與多個類型的I/O設備30連接。在有些示例中,本地系統匯流排26可以是下列任意類型的匯流排:視頻電子標準協會局部(VESA VL)匯流排、工業標準架構(ISA)匯流排、擴展工業標準架構(EISA)匯流排、微通道架構(MCA)匯流排、周邊部件互連(PCI)匯流排、PCI-X匯流排、PCI-Express匯流排、或NuBus。流量管理設備110的其他示例配置包括通過先進圖形端口(AGP)與主機處理器20連接的I/O設備30(其為視頻顯示器,未單獨示出)。 另外,流量管理設備110的其他形式包括通過下列一個或多個連接與I/O設備30相連的主機處理器20:HyperTransport(快速傳輸)、Rapid I/O(高速輸入/輸出)或InfiniBand(無限帶寬)。流量管理設備110的其他示例包括通信連接,其中,主機處理器20通過本地互聯匯流排與一個I/O設備30連接,通過直接連接與第二I/O設備(未單獨示出)連接。如上述,在有些示例中,流量管理設備110包括主機記憶體22和快取記憶體21中的其中一個。在有些示例中,快取記憶體21可以是下列任意類型的記憶體:靜態隨機存取記憶體(SRAM)、叢發或同步叢發隨機存取記憶體(BSRAM)、或增强動態隨機存取記憶體(EDRAM)。流量管理設備110的其他示例包括快取記憶體21和主機記憶體22,其可以是下列任意類型的記憶體:靜態隨機存取記憶體、叢發靜態隨機存取記憶體或同步叢發靜態隨機存取記憶體、動態隨機存取記憶體、快速頁面模式動態隨機存取記憶體、增强動態隨機存取記憶體、擴展數據輸出隨機存取記憶體、擴展數據輸出動態隨機存取記憶體、叢發擴展數據輸出動態隨機存取記憶體、增强動態隨機存取記憶體、同步動態隨機存取記憶體、JEDECSRAM(固態技術協會SRAM)、PCIOO SDRAM、雙倍數據速率同步動態隨機存取記憶體、增强同步動態隨機存取記憶體、同步鏈接動態隨機存取記憶體、直接Rambus動態隨機存取記憶體、鐵電性隨機記憶體(FRAM)或能執行本申請該系統和方法的其他任意類型的記憶體設備。 Examples of traffic management device 110 includes a BIG-IP ® product family offered by Seattle, Washington F5's application delivery network company or more controller devices, of course, also possible to use other types of traffic management equipment. In an exemplary configuration and/or arrangement, traffic management device 110 may include host processor 20 in communication with cache memory 21 via a secondary bus (also referred to as a rear bus), while another of traffic management device 110 The example includes a host processor 20 connected to the cache memory 21 through a system bus 26. In some embodiments, host processor 20 may also use local system bus 26 to interface with multiple types of I/O devices 30. In some examples, local system bus 26 can be any of the following types of bus bars: Video Electronics Standards Association Partial (VESA VL) bus, Industry Standard Architecture (ISA) bus, Extended Industry Standard Architecture (EISA) bus, Micro Channel Architecture (MCA) Bus, Peripheral Component Interconnect (PCI) Bus, PCI-X Bus, PCI-Express Bus, or NuBus. Other example configurations of traffic management device 110 include I/O device 30 (which is a video display, not separately shown) connected to host processor 20 via an advanced graphics port (AGP). Additionally, other forms of traffic management device 110 include host processor 20 coupled to I/O device 30 via one or more of the following: HyperTransport, Rapid I/O, or InfiniBand (unlimited) bandwidth). Other examples of traffic management device 110 include communication connections in which host processor 20 is coupled to one I/O device 30 via a local interconnect bus, and to a second I/O device (not shown separately) through a direct connection. As described above, in some examples, the traffic management device 110 includes one of the host memory 22 and the cache memory 21. In some examples, the cache 21 can be any of the following types of memory: static random access memory (SRAM), burst or synchronous burst random access memory (BSRAM), or enhanced dynamic random access. Memory (EDRAM). Other examples of the traffic management device 110 include the cache memory 21 and the host memory 22, which may be any of the following types of memory: static random access memory, burst static random access memory, or synchronous burst static random. Access memory, dynamic random access memory, fast page mode dynamic random access memory, enhanced dynamic random access memory, extended data output random access memory, extended data output dynamic random access memory, plex Extended data output dynamic random access memory, enhanced dynamic random access memory, synchronous dynamic random access memory, JEDECSRAM (Solid State Technology Association SRAM), PCIOO SDRAM, double data rate synchronous dynamic random access memory, Enhanced Synchronous Dynamic Random Access Memory, Synchronous Linked Dynamic Random Access Memory, Direct Rambus Dynamic Random Access Memory, Ferroelectric Random Memory (FRAM), or any other type of system capable of performing the system and method of the present application Memory device.
在有些實施例中,主機記憶體22和/或快取記憶體21可包括一個或多個能儲存數據並允許主機處理器20能直接訪問任意儲存位置的記憶體設備。數據可儲存在通過網路介面控制器24的一個或多個輸入輸出端口連接的流量管理設備110的內部或外部的本地數據庫中。流量管理設備110的其他示例包括能通過下列其中一個來訪問主機記憶體22的主機處理器20:系統匯流排26、記憶體端口53、或使主機處理器20能訪問主機記憶體22的其他任意連接、匯流排或端口。 In some embodiments, host memory 22 and/or cache memory 21 may include one or more memory devices capable of storing data and allowing host processor 20 to directly access any storage location. The data may be stored in a local database internal or external to the traffic management device 110 connected through one or more input and output ports of the network interface controller 24. Other examples of traffic management device 110 include host processor 20 that can access host memory 22 by one of: system bus 26, memory port 53, or any other device that enables host processor 20 to access host memory 22. Connection, bus, or port.
流量管理設備110的一個示例支持下列任意一種安裝設備:ZIP軟碟、CD-ROM驅動器、CD-R/RW驅動器、DVD-ROM驅動器、USB設備、可啟動媒體、用於比如GNU/Linux分布(比如,KNOPPIX®)的可啟動光碟、硬碟驅動器或適合安裝應用程式或軟體的其他任意設備。在有些示例中,應用程式可包括客戶端代理程式或客戶端代理程式的任意部分。流量管理設備110還可包括儲存設備(未單獨示出),其可以是一個或多個硬碟驅動器或獨立冗餘磁碟陣列(RAID),其中該儲存設備用於儲存操作系統、軟體、應用程式或客戶端代理程式的至少一部分。流量管理設備110的另一示例包括用作儲存設備的安裝設備。 An example of the traffic management device 110 supports any of the following installation devices: a ZIP floppy disk, a CD-ROM drive, a CD-R/RW drive, a DVD-ROM drive, a USB device, bootable media, for distribution such as GNU/Linux ( For example, KNOPPIX ® can be a bootable CD, a hard drive, or any other device suitable for installing an application or software. In some examples, an application can include any part of a client agent or a client agent. The traffic management device 110 may also include a storage device (not separately shown), which may be one or more hard disk drives or a separate redundant disk array (RAID), where the storage device is used to store operating systems, software, applications At least part of a program or client agent. Another example of the traffic management device 110 includes a mounting device that serves as a storage device.
此外,流量管理設備110可包括網路介面控制器24,從而通過網路介面控制器24內的輸入-輸出端口、以多種連接方式,包括但不限於標準電話線、區域網路或廣域網路(比如,802.11、T1、T3、56 kb、X.25、SNA、DECNET)、 寬帶連接(比如,ISDN、訊框中繼、異步傳輸模式、千兆乙太網路、Ethernet-over-SONET)、無線連接、光纖連接或任意和所有上述連接的組合,與區域網路、廣域網路或網際網路連接。還可使用多種通信協議(比如,TCP/IP、IPX、SPX、NetBIOS、乙太網路、ARCNET、同步光纖網路(SONET)、同步數位體系(SDH)、光纖分布式數據介面(FDDI)、RS232、RS485、IEEE 802.11、IEEE 802.11a、IEEE 802.11b、IEEE 802.11g、CDMA、GSM、WiMax和直接異步連接)建立連接。流量管理設備110的一種形式是包括網路介面控制器24,用於通過任意類型和/或形式的閘道器或隧道協議(比如,安全套接層(SSL)或傳輸層安全(TLS),或位於佛羅里達州勞德達爾堡的思杰(Citrix)系統公司的思杰閘道器協議)與其他計算設備通信。網路介面控制器24的形式可包括下列任意一種:內置網路適配器、網路介面卡、PCMCIA網路卡、外接卡匯流排網路適配器、無線網路適配器、USB網路適配器、調制解調器、或其他任意適合把流量管理設備110與能進行通信和執行本申請該的方法和系統的網路相連接的設備。 In addition, the traffic management device 110 can include a network interface controller 24 for accessing the input-output ports within the network interface controller 24 in a variety of ways including, but not limited to, standard telephone lines, regional networks, or wide area networks ( For example, 802.11, T1, T3, 56 kb, X.25, SNA, DECNET), Broadband connection (eg, ISDN, frame relay, asynchronous transfer mode, Gigabit Ethernet, Ethernet-over-SONET), wireless connection, fiber connection or any combination of all and above, and regional network, wide area network Road or internet connection. Multiple communication protocols are also available (eg, TCP/IP, IPX, SPX, NetBIOS, Ethernet, ARCNET, Synchronous Optical Network (SONET), Synchronous Digital Hierarchy (SDH), Fiber Distributed Data Interface (FDDI), Connections are established for RS232, RS485, IEEE 802.11, IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, CDMA, GSM, WiMax, and direct asynchronous connections. One form of traffic management device 110 includes a network interface controller 24 for use by any type and/or form of gateway or tunneling protocol (eg, Secure Sockets Layer (SSL) or Transport Layer Security (TLS), or The Citrix Gateway Protocol of Citrix Systems, Inc., located in Fort Lauderdale, Fla., communicates with other computing devices. The network interface controller 24 may be in the form of any of the following: a built-in network adapter, a network interface card, a PCMCIA network card, an external card bus network adapter, a wireless network adapter, a USB network adapter, a modem, or Any other device suitable for connecting the traffic management device 110 to a network capable of communicating and performing the methods and systems of the present application.
在多個示例中,流量管理設備110可包括下列任意一種I/O設備:鍵盤、定點設備、滑鼠、基於手勢的遙控設備、生物統計設備、音頻設備、觸控板、光學筆、軌跡球、麥克風、視頻顯示器、揚聲器、或其他任意能執行本申請該的方法和系統的輸入/輸出設備。在有些示例中,主機I/O端口29可與多個I/O設備30相連從而控制一個或多個I/O 設備30。I/O設備30的一些示例為可用於儲存或提供安裝媒體,其他示例則為可提供通用串行匯流排(USB)介面來接收USB儲存設備,比如,Twintech Industry公司所製造的設備的USB快閃記憶體線路。I/O設備30的其他示例可以是位於系統匯流排26和外部通信匯流排之間的橋接器25,該外部通信匯流排比如為:USB匯流排、蘋果桌面(Apple Desktop)匯流排、RS-232串行連接、小型電腦系統介面(SCSI)匯流排、FireWire(火線)匯流排、FireWire 800匯流排、乙太網路匯流排、AppleTalk匯流排、千兆乙太網路匯流排、異步傳輸模式匯流排、HIPPI(高性能並行介面)匯流排、超HIPPI匯流排、SerialPlus匯流排、SCI/LAMP匯流排、光纖通道匯流排、或串聯附接小型電腦系統介面匯流排。根據有些示例,流量管理設備110包括集成為主機系統18一部分的驗證模組208,從而通過比如公鑰密碼術來實施各種對流量管理設備110創建的資源記錄類型(比如,AAAA資源記錄)進行簽名的示例性功能。 In various examples, the traffic management device 110 can include any of the following I/O devices: a keyboard, a pointing device, a mouse, a gesture-based remote control device, a biometric device, an audio device, a trackpad, an optical pen, a trackball , a microphone, a video display, a speaker, or any other input/output device capable of performing the methods and systems of the present application. In some examples, host I/O port 29 can be connected to multiple I/O devices 30 to control one or more I/Os. Device 30. Some examples of I/O device 30 may be used to store or provide installation media, and other examples may provide a universal serial bus (USB) interface to receive USB storage devices, such as USB for devices manufactured by Twintech Industry. Flash memory line. Other examples of the I/O device 30 may be a bridge 25 located between the system bus 26 and an external communication bus, such as a USB bus, an Apple Desktop bus, and an RS- 232 serial connection, small computer system interface (SCSI) bus, FireWire bus, FireWire 800 bus, Ethernet bus, AppleTalk bus, Gigabit Ethernet bus, asynchronous transfer mode Bus, HIPPI (High Performance Parallel Interface) Bus, Super HIPPI Bus, SerialPlus Bus, SCI/LAMP Bus, Fibre Channel Bus, or Serial Attached Small Computer System Interface Bus. According to some examples, the traffic management device 110 includes an authentication module 208 integrated as part of the host system 18 to implement various signatures of resource record types (eg, AAAA resource records) created by the traffic management device 110 by, for example, public key cryptography. Exemplary features.
因此,流量管理設備110的組件包括一個或多個執行一個或多個流量管理應用程式的處理器(比如,主機處理器20)、通過匯流排與一個或多個處理器連接的記憶體(比如,快取記憶體21和/或主機記憶體22)、與一個或多個處理器和主機記憶體22連接並且用於接收來自網路的涉及執行流量管理應用程式的數據封包並處理來自客戶端電腦104(1)到104(n)的第一資源記錄類型的請求的網路介面控制器24,其中伺服器102(1)到102(n)通過第二或 不同資源記錄類型的響應為這些請求提供服務。在該示例中,該一個或多個處理器中的至少一個用於執行儲存在記憶體(比如,快取記憶體21和/或主機記憶體22)內的程式指令,包含邏輯的網路介面控制器24能進一步用於根據客戶端設備的請求在流量管理設備接收來自一個或多個伺服器設備的第一資源記錄類型。該實施過程包括在該流量管理設備驗證該第一資源記錄類型,並在該驗證後創建對應於該第一資源記錄類型的第二資源記錄類型。在該流量管理設備對第二資源記錄類型簽名(比如,通過驗證模組208),從而為來自該客戶端設備的請求提供服務。 Accordingly, components of traffic management device 110 include one or more processors (eg, host processor 20) executing one or more traffic management applications, and memory coupled to one or more processors via busbars (eg, , cache memory 21 and/or host memory 22), coupled to one or more processors and host memory 22, and for receiving data packets from the network involved in executing the traffic management application and processing from the client The requested network interface controller 24 of the first resource record type of the computers 104(1) through 104(n), wherein the servers 102(1) through 102(n) pass the second or Responses to different resource record types serve these requests. In this example, at least one of the one or more processors is configured to execute program instructions stored in a memory (eg, cache 21 and/or host memory 22), including a logical network interface The controller 24 can be further configured to receive, at the request of the client device, a first resource record type from the one or more server devices at the traffic management device. The implementation process includes verifying the first resource record type at the traffic management device, and creating a second resource record type corresponding to the first resource record type after the verifying. The traffic management device signs the second resource record type (eg, via the verification module 208) to service the request from the client device.
下面分別結合圖1和圖2連同圖3所示的流程圖300,對使用比如圖1和圖2所示的流量管理設備110來處理不同資源記錄類型之間請求(比如,給DNS64提供DNSSEC代理)的示例過程的步驟進行說明。流程圖300表示在比如流量管理設備110處動態實時處理不同資源記錄類型之間請求的示例性機器可讀指令。在該示例中,該機器可讀指令包括由例如主機系統18內的(a)處理器(比如,主機處理器20)、(b)控制器和/或(c)一個或多個合適的處理設備執行的演算法。該演算法可在儲存於有形電腦可讀媒體(比如,快閃記憶體、CD-ROM、軟碟、硬碟驅動器、數位視頻(多功能)光碟(DVD)或其他儲存設備的軟體中執行,但是本領域的技術人員可容易意識到,整個演算法和/或其中一部分演算法可不由處理器而是由設備執行,和/或以已知的方式在固件或專用硬體中執行(比如,可由 特定應用積體電路(ASIC)、可編程邏輯設備(PLD)、現場可編程邏輯設備(FPLD)、現場可編程門陣列(FPGA)、離散邏輯等執行)。比如,流量管理設備110的至少一部分組件可由軟體、硬體和/或固件執行。同樣,圖3流程圖300的步驟所表示的一些或所有機器可讀指令可通過利用比如由系統管理員操作的命令行介面(CLI)提示窗口在流量管理設備110手動執行。另外,儘管結合流程圖300對示例性演算法進行了說明,但是本領域的技術人員會容易意識到還可使用許多其他方法來執行該示例性機器可讀指令。比如,流程圖300中之方塊的執行順序可以變化,和/或一些方塊可以變化、去掉或組合。 In the following, in conjunction with FIG. 1 and FIG. 2 together with the flowchart 300 shown in FIG. 3, a request between different resource record types is processed using the traffic management device 110 such as shown in FIGS. 1 and 2 (eg, providing a DNSSEC proxy to the DNS 64). The steps of the example process are explained. Flowchart 300 represents exemplary machine readable instructions for dynamically real-time processing of requests between different resource record types, such as at traffic management device 110. In this example, the machine readable instructions include, by, for example, (a) a processor (eg, host processor 20), (b) a controller, and/or (c) one or more suitable processes within host system 18. The algorithm executed by the device. The algorithm can be executed in software stored on a tangible computer readable medium such as a flash memory, CD-ROM, floppy disk, hard disk drive, digital video (multi-function) compact disc (DVD) or other storage device. However, those skilled in the art will readily appreciate that the entire algorithm and/or a portion of the algorithms may be executed by the device rather than by the processor, and/or executed in firmware or dedicated hardware in a known manner (eg, Can be Application-specific integrated circuits (ASICs), programmable logic devices (PLDs), field programmable logic devices (FPLDs), field programmable gate arrays (FPGAs), discrete logic, etc.). For example, at least a portion of the components of traffic management device 110 can be executed by software, hardware, and/or firmware. Likewise, some or all of the machine readable instructions represented by the steps of flowchart 300 of FIG. 3 may be manually executed at traffic management device 110 by utilizing a command line interface (CLI) prompt window, such as operated by a system administrator. Additionally, although the exemplary algorithms have been described in connection with flowchart 300, those skilled in the art will readily appreciate that many other methods can also be used to execute the example machine readable instructions. For example, the order of execution of the blocks in flowchart 300 can vary, and/or some blocks can be varied, removed, or combined.
參照圖3,在流程圖300的步驟302中,流量管理設備110接收來自其中一個客戶端電腦104(1)到104(n)的請求。通常,客戶端電腦104(1)到104(n)的請求的資源記錄類型不同於一個或多個伺服器102(1)到102(n)為響應該請求而提供的資源記錄類型。在一示例中,客戶端電腦104(1)到104(n)的請求是針對IPv4設備(比如,一個或多個伺服器102(1)到102(n))提供的資源(也稱為“A”記錄,其為32位元IPv4位址)的128位元IPv6請求或查詢(也稱為4A或“AAAA”請求或查詢)。由於IPv6 AAAA和IPv4 A資源記錄請求/查詢的各個標準格式對於本領域的技術人員來說是已知的,因此這裏不再詳述。另外,可使用其他類型的資源記錄,並且所討論的IPv4和IPv6資源記錄僅為示例而非限制。 Referring to Figure 3, in step 302 of flowchart 300, traffic management device 110 receives a request from one of client computers 104(1) through 104(n). In general, the requested resource record type of client computers 104(1) through 104(n) is different from the resource record type provided by one or more servers 102(1) through 102(n) in response to the request. In an example, the requests from client computers 104(1) through 104(n) are resources provided for IPv4 devices (eg, one or more servers 102(1) through 102(n)) (also referred to as " A "record, which is a 32-bit IPv4 address" 128-bit IPv6 request or query (also known as a 4A or "AAAA" request or query). Since the various standard formats of IPv6 AAAA and IPv4 A resource record requests/queries are known to those skilled in the art, they are not described in detail herein. In addition, other types of resource records can be used, and the IPv4 and IPv6 resource records in question are merely examples and are not limiting.
在步驟304中,流量管理設備110在移除位元和/或標頭後將接收的比如AAAA資源記錄格式的IPv6請求轉發給伺服器102(1)到102(n)中的一個,從而把該請求轉換為伺服器102(1)到102(n)能識別之對於A資源記錄的IPv4請求。所移除的位元和/或標頭可至少部分地為形成IPv6位址的96位元前置的一部分。由於伺服器102(1)到102(n)不能識別IPv6位址格式並且伺服器在IPv4網路環境中,因此移除前置位元有助於把客戶端電腦104(1)到104(n)的請求指向合適的一個或多個伺服器102(1)到102(n)。 In step 304, the traffic management device 110 forwards the received IPv6 request, such as the AAAA resource record format, to one of the servers 102(1) through 102(n) after removing the bit and/or the header, thereby The request translates to an IPv4 request that can be identified by the servers 102(1) through 102(n) for the A resource record. The removed bits and/or headers may be at least partially part of a 96-bit preamble that forms an IPv6 address. Since the servers 102(1) through 102(n) cannot recognize the IPv6 address format and the server is in an IPv4 network environment, removing the preamble helps to bring the client computers 104(1) through 104(n). The request is directed to the appropriate one or more servers 102(1) through 102(n).
在步驟306中,流量管理設備110接收來自其中一個伺服器102(1)到102(n)的響應以及與該響應相關的資源記錄簽名(RRSIG)。該接收的響應為簽名而經受驗證,比如用來確定其來自伺服器102(1)到102(n)之間的可信資源。可使用比如流量管理設備110中驗證模組208實施的公鑰密碼術機制來進行驗證,當然也可使用其他技術來進行驗證。 In step 306, traffic management device 110 receives a response from one of servers 102(1) through 102(n) and a resource record signature (RRSIG) associated with the response. The received response is verified for signature, such as to determine its trusted resources from servers 102(1) through 102(n). Verification can be performed using, for example, a public key cryptography mechanism implemented by the verification module 208 in the traffic management device 110, although other techniques can be used for verification.
在步驟308中,流量管理設備110確定接收的響應的資源記錄類型是否與客戶端設備請求的資源記錄類型相同。當接收的響應的資源記錄類型與所請求的資源記錄類型相同時則執行步驟314,該步驟中,流量管理設備110在驗證後將該接收的響應轉發給客戶端電腦104(1)到104(n)中發出請求的電腦。比如,如果該接收的響應為IPv6 AAAA類型響應,則流量管理設備110直接將該響應轉發給 客戶端電腦104(1)到104(n)中發出請求的電腦。 In step 308, the traffic management device 110 determines whether the resource record type of the received response is the same as the resource record type requested by the client device. When the resource record type of the received response is the same as the requested resource record type, step 314 is performed, in which the traffic management device 110 forwards the received response to the client computers 104(1) to 104 after verification ( n) The computer that made the request. For example, if the received response is an IPv6 AAAA type response, the traffic management device 110 directly forwards the response to The requesting computer is in the client computers 104(1) through 104(n).
但是,在步驟310中,當該響應包括一個或多個不同資源記錄類型格式(比如,IPv4格式或A資源記錄)的位址記錄時,流量管理設備110創建與接收的資源記錄類型對應而與請求的資源記錄類型格式(比如,其中帶有IPv4 A資源記錄網路位址的IPv6 AAAA資源記錄類型)匹配或對應的新資源記錄類型。 However, in step 310, when the response includes an address record of one or more different resource record type formats (eg, IPv4 format or A resource record), the traffic management device 110 creates a correspondence with the received resource record type. The requested resource record type format (for example, the IPv6 AAAA resource record type with the IPv4 A resource record network address) matches or corresponds to the new resource record type.
然後,執行步驟312,在該步驟中,流量管理設備110根據DNSSEC對包含上述新資源記錄類型的新建響應(比如,合成的AAAA資源記錄)進行簽名。在該情况下,當流量管理設備110為該新建IPv6 AAAA資源記錄類型響應動態實時地(或“即時”)附上新簽名(比如,新RRSIG)時,對應於IPv4 A資源記錄類型響應的舊簽名由於不再有效,而被該流量管理設備丟棄。僅作為示例,如上述,對合成的資源記錄的簽名可由驗證模組208使用流量管理設備110內(比如,主機記憶體22內)儲存的密鑰來實施,當然,也可使用其他技術進行簽名。因此,簽名的AAA資源記錄儘管是在流量管理設備110合成的,但是在到達客戶端設備中發出請求的設備前保持了DNSSEC所要求的信任鏈並且不會被其他下游驗證器拒絕為無效。 Then, step 312 is performed, in which the traffic management device 110 signs a new response (eg, a synthesized AAAA resource record) containing the new resource record type described above according to DNSSEC. In this case, when the traffic management device 110 attaches a new signature (eg, a new RRSIG) to the newly created IPv6 AAAA resource record type response in real time (or "instant"), the old response corresponding to the IPv4 A resource record type response The signature is discarded by the traffic management device because it is no longer valid. By way of example only, as described above, the signature of the synthesized resource record may be implemented by the verification module 208 using a key stored within the traffic management device 110 (e.g., within the host memory 22). Of course, other techniques may also be used for signing. . Thus, the signed AAA resource record, although synthesized at the traffic management device 110, maintains the chain of trust required by DNSSEC before reaching the requesting device in the client device and is not rejected by other downstream validators.
在步驟314中,該簽名的合成AAAA資源記錄作為響應轉發給客戶端電腦104(1)到104(n)中發出請求的電腦。需要指出的是,儘管在該示例中,IPv6 AAAA資源記錄稱為客戶端電腦104(1)到104(n)請求的資源記錄類 型,但是本申請揭示的示例對於其他資源記錄類型同樣有效,只要伺服器102(1)到102(n)提供的響應與這樣一種資源記錄的類型不同即可,該資源記錄需要經過驗證或需要通過合成而轉換成與客戶端電腦104(1)到104(n)所請求的資源記錄類型相同,然後比如通過在流量管理設備110附上簽名而被驗證。 In step 314, the signed composite AAAA resource record is forwarded in response to the requesting computer in client computers 104(1) through 104(n). It should be noted that although in this example, the IPv6 AAAA resource record is referred to as the resource record class requested by the client computers 104(1) through 104(n). Type, but the examples disclosed herein are equally valid for other resource record types, as long as the responses provided by servers 102(1) through 102(n) are different from the type of such resource record, the resource record needs to be verified or needed The composition is converted to the same type of resource record as requested by the client computers 104(1) through 104(n) by synthesis, and then verified, for example, by attaching a signature to the traffic management device 110.
通過對基本概念的說明,對於本領域的技術人員來說,顯而易見的是,上述詳細揭示內容僅作為示例而非限制。儘管在本申請中未詳細闡述,但是本領域的技術人員可進行各種變化、改進和修改。實現提供安全應用遞送的方法和步驟的順序也可以改變。另外,除了網路112和區域網路114,還可有多個網路與接收或發送網路數據封包的流量管理設備110相連。這些變化、改進和修改是本揭示內容所建議的,並且在示例的精神和範圍內。另外,所列出的處理部件的順序或次序、或數字、字母或其他標識的使用並不用於把主張的步驟和方法限於任何順序,除非已在申請專利範圍中指定。 It will be apparent to those skilled in the art <RTIgt; </ RTI> <RTIgt; </ RTI> <RTIgt; Various changes, modifications, and alterations can be made by those skilled in the art, although not described in detail herein. The order in which the methods and steps for providing secure application delivery can also be changed. Additionally, in addition to the network 112 and the regional network 114, there may be multiple networks connected to the traffic management device 110 that receives or transmits network data packets. These variations, improvements, and modifications are suggested by the present disclosure and are within the spirit and scope of the examples. In addition, the order or sequence of processing components, or the use of numbers, letters or other identifiers, is not intended to limit the claimed steps and methods to any order unless specified in the scope of the claims.
18‧‧‧主機系統 18‧‧‧Host system
20‧‧‧主機處理器 20‧‧‧Host processor
21‧‧‧快取憶體 21‧‧‧Recalling
22‧‧‧主機記憶體 22‧‧‧Host memory
24‧‧‧網路介面控制器 24‧‧‧Network Interface Controller
25‧‧‧橋接器 25‧‧‧ Bridge
26‧‧‧系統匯流排 26‧‧‧System Bus
29‧‧‧主機輸入輸出(I/O)端口 29‧‧‧Host Input/Output (I/O) Port
30‧‧‧輸入-輸出(I/O)設備 30‧‧‧Input-Output (I/O) Equipment
53‧‧‧記憶體端口 53‧‧‧ memory port
100‧‧‧網路系統 100‧‧‧Network System
102(1)-102(n)‧‧‧伺服器設備 102(1)-102(n)‧‧‧Server equipment
104(1)-104(n)‧‧‧客戶端電腦/設備 104(1)-104(n)‧‧‧Client Computer/Equipment
106(1)-106(n)‧‧‧負載均衡設備 106(1)-106(n)‧‧‧ Load balancing equipment
110‧‧‧流量管理設備 110‧‧‧Traffic management equipment
114‧‧‧區域網路(LAN) 114‧‧‧Regional Network (LAN)
202‧‧‧CPU匯流排 202‧‧‧CPU bus
208‧‧‧驗證模組 208‧‧‧ verification module
圖1為使用流量管理設備處理不同資源記錄類型之間的請求的示例性網路系統環境的示意圖;圖2為圖1所示示例性網路環境中流量管理設備的部分示意和功能方塊圖;以及圖3為處理不同資源記錄類型之間的請求的示例性步 驟和方法的流程圖。 1 is a schematic diagram of an exemplary network system environment for processing requests between different resource record types using a traffic management device; FIG. 2 is a partial schematic and functional block diagram of a traffic management device in the exemplary network environment of FIG. And Figure 3 is an exemplary step of processing requests between different resource record types Flow chart of the method and method.
100‧‧‧網路系統 100‧‧‧Network System
102(1)-102(n)‧‧‧伺服器設備 102(1)-102(n)‧‧‧Server equipment
104(1)-104(n)‧‧‧客戶端電腦/設備 104(1)-104(n)‧‧‧Client Computer/Equipment
106(1)-106(n)‧‧‧負載均衡設備 106(1)-106(n)‧‧‧ Load balancing equipment
110‧‧‧流量管理設備 110‧‧‧Traffic management equipment
114‧‧‧區域網路(LAN) 114‧‧‧Regional Network (LAN)
Claims (12)
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201120434308.9U CN202524399U (en) | 2010-11-04 | 2011-11-04 | Flow management device |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| TW201320654A TW201320654A (en) | 2013-05-16 |
| TWI568215B true TWI568215B (en) | 2017-01-21 |
Family
ID=48874578
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| TW101116777A TWI568215B (en) | 2011-11-04 | 2012-05-10 | Methods for handling requests between different resource record types and systems thereof |
Country Status (1)
| Country | Link |
|---|---|
| TW (1) | TWI568215B (en) |
-
2012
- 2012-05-10 TW TW101116777A patent/TWI568215B/en not_active IP Right Cessation
Non-Patent Citations (1)
| Title |
|---|
| K. Tsuchiya, H. Higuchi, Y. Atarashi, "Dual Stack Hosts using the "Bump-In-the-Stack" Technique (BIS)", RFC 2767, Feb. 2000. R. Arends, R. Austein, M. Larson, D. Massey, S. Rose, "Resource Records for the DNS Security Extensions", RFC 4034, Mar. 2005. R. Arends, R. Austein, M. Larson, D. Massey, S. Rose, " DNS Security Introduction and Requirements", RFC 4033, Mar. 2005. * |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201320654A (en) | 2013-05-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9106699B2 (en) | Methods for handling requests between different resource record types and systems thereof | |
| USRE47019E1 (en) | Methods for DNSSEC proxying and deployment amelioration and systems thereof | |
| EP3607732B1 (en) | Systems and methods for securely and transparently proxying saas applications through a cloud-hosted or on-premise network gateway for enhanced security and visibility | |
| US10484336B2 (en) | Systems and methods for a unique mechanism of providing ‘clientless SSLVPN’ access to a variety of web-applications through a SSLVPN gateway | |
| CN103314566B (en) | Systems and methods for managing domain name system security (DNSSEC) | |
| CN107771320B (en) | System and method for improving the security of Secure Sockets Layer (SSL) communications | |
| US9270646B2 (en) | Systems and methods for generating a DNS query to improve resistance against a DNS attack | |
| US10375155B1 (en) | System and method for achieving hardware acceleration for asymmetric flow connections | |
| CN105279216B (en) | A system for distributing unnamed objects using self-certifying names | |
| US9843554B2 (en) | Methods for dynamic DNS implementation and systems thereof | |
| US11824829B2 (en) | Methods and systems for domain name data networking | |
| CN109983752A (en) | Network address with NS grades of information of encoding D | |
| CN105721418B (en) | A low-cost method and system for authentication and signature delegation in a content-centric network | |
| CN105229996A (en) | For reducing the system and method for the Denial of Service attack to next safety records dynamically generated | |
| US10097521B2 (en) | Transparent encryption in a content centric network | |
| CN106790296B (en) | Domain name record verification method and device | |
| US11122083B1 (en) | Methods for managing network connections based on DNS data and network policies and devices thereof | |
| US9609017B1 (en) | Methods for preventing a distributed denial service attack and devices thereof | |
| TW201320654A (en) | Methods for handling requests between different resource record types and systems thereof | |
| Valkola | Improvements to DNS privacy and integrity | |
| Amir et al. | A new look at the old domain name system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| MM4A | Annulment or lapse of patent due to non-payment of fees |