Journal of Frontiers of Computer Science and Technology ›› 2025, Vol. 19 ›› Issue (10): 2587-2614.DOI: 10.3778/j.issn.1673-9418.2504048

• Frontiers·Surveys • Previous Articles     Next Articles

Research Progress on Blockchain-Based DNS Security Enhancement Technology

NI Xueli, WANG Qun, MA Zhuo   

  1. 1. Department of Computer Information and Cybersecurity, Jiangsu Police Institute, Nanjing 210031, China
    2. Jiangsu Electronic Data Forensics and Analysis Engineering Research Center, Nanjing 210031, China
    3. School of Computer Science, School of Cyber Science and Engineering, Nanjing University of Information Science and Technology, Nanjing 210044, China
  • Online:2025-10-01 Published:2025-09-30

DNS安全增强及区块链技术的应用研究进展

倪雪莉,王群,马卓   

  1. 1. 江苏警官学院 计算机信息与网络安全系,南京 210031
    2. 江苏省电子数据取证分析工程研究中心,南京 210031
    3. 南京信息工程大学 计算机学院、网络空间安全学院,南京 210044

Abstract: Due to insufficient security considerations in its initial design, the domain name system (DNS) now faces increasingly complex and challenging security threats. Blockchain technology, with its unique characteristics of decentralization, tamper-resistance, traceability and transparency, provides a novel approach to addressing these security threats. Based on the systematic analysis of DNS vulnerabilities and security threats, this paper summarizes existing DNS security enhancement technologies, and emphasizes the unique functional and technical advantages of blockchain in improving DNS security and reconstructing its security framework. Firstly, this paper provides an overview of the working mechanism of DNS, analyzes the specific manifestations and root causes of DNS vulnerability, and summarizes typical DNS attack methods and detection techniques. Secondly, the research results of traditional DNS security enhancement technologies are systematically summarized from three aspects: architecture, protocol and implementation process. Thirdly, the application of blockchain in DNS security protection is divided into two types: DNS security enhancement technologies integrated with blockchain and blockchain based DNS security solutions, and their implementation methods and technical paths are detailed with representative examples. Finally, this paper points out the unresolved issues of blockchain DNS, such as the trade-off between decentralization and efficiency, the conflict between immutability and compliance, and the balance between security and user experience, and prospects for the possible future research hotspots and directions of DNS security enhancement.

Key words: DNS security, DNS vulnerability, blockchain technology, DNS security enhancement

摘要: 因设计之初对安全性考虑的缺失,致使当今的DNS面临日益复杂和极具挑战性的安全问题,而区块链技术的应用,以其独有的去中心化、防篡改、可溯源、公开透明等特征,为解决当前DNS面临的安全威胁提供了一种崭新的思路。在系统分析DNS脆弱性和安全威胁的基础上,对DNS安全增强技术进行了系统梳理与剖析,强调了区块链在增强DNS系统安全性以及重构DNS安全体系中发挥的独特功能和技术优势。概述了DNS的工作机制,分析了DNS安全脆弱性的具体表现和产生根源,总结了典型DNS攻击方式与检测方法;围绕体系结构、协议和实现过程三个维度分别对传统DNS安全增强技术的研究成果进行了对比分析;将区块链在DNS安全防护中的应用界定为融入区块链的DNS安全增强技术和基于区块链的DNS安全方案两种类型,以代表性示例分别分析了各区块链安全方案的实现方法和技术路径,并进行了分析与比较;总结并提出了区块链DNS目前仍然存在的去中心化与效率、不可篡改与合规、安全与用户体验等悬而未决的问题,且对DNS安全增强未来可能的研究热点和方向进行了展望。

关键词: DNS安全, DNS脆弱性, 区块链技术, DNS安全增强