针对现行域名解析系统存在各种性能和安全上的问题(例如,查询延迟、更新延迟、易受DoS攻击等),提出了一种新型的、可增量部署的、和现行DNS兼容的、具有更好性能的域名解析服务模型。此服务模型基于云技术,利用云及其网络架构来发布DNS记录,响应用户的域名解析请求,提供域名解析服务。在此服务模型中,云的节点服务器实现了域名解析器和权威域名服务器的功能,域名的权威DNS记录被发布到各节点服务器,DNS查询结果直接由节点服务器返回给用户(现行的DNS则需要访问多级域名服务器来完成对域名解析器中未缓存的DNS记录的解析)。理论分析和实验证明,此服务模型与现行的各种域名解析服务相比,其DNS查询延迟、更新延迟、故障应变能力、可靠性等各方面性能都有显著提高。
The current DNS had various performance and security problems, such as query delay, update latency, vulner- able to DoS attacks etc. Focuses on those problems, a novel, incremental deployable, compatible, and more effective do- main name resolving service model was proposed. The service model was cloud sourcing, by using the cloud and its branch network worldwide to distribute DNS records, response DNS queries, and provide domain name resolved service. In this service model, the cloud edge servers function as local resolvers and authoritative nameservers, and authoritative DNS records were distributed to the edge servers, which directly responsed users' DNS queries (if the queried record was not cached at local resolver, current DNS needed to access several nameservers in multi-level hierarchy). Compared with current domain name resolving services, the analysis and experiments prove that the service model show advantages in query latency, update latency, resiliency, and reliability etc.