I. IMPORTANT LANDMARK EVENTS
A. DNS “Execution Day”
Knowledge of obsolescent, wrong, or inappropriate methods to conduct software work around is required when we need to go on DNS software updating or programming. Some workarounds pertain to DNS software have made it a deeper and refined situation for the US to control and inaugurate Domain Name System, unavoidably there are functional declination and an increase in unpredictable errors and safety risks. Consequently, reinforcement in Domain Name System becomes inevitable.
The Internet Engineering Task Force (IETF) proposed the implementation of DNS Domain Name System Extension Mechanism (EDNS) in 1999. In March 2016, the US Department of Commerce’s National Telecommunications and Information Administration (NTIA), Internet Corporation for Assigned Names and Numbers (ICANN) and VeriSign, a company that provides intelligent information infrastructure services which was established in the United States, led to the completion of the domain name root zone key (KSK) replacement plan as domain name root zone managers.
On October 12, 2018, ICANN finished the first global domain name root zone key (KSK) rollover in the history of the Internet and announced there will be rollover every year. Professionals claimed that KSK is a unified “re-keying”, followed by “DNS Execution Day” being unified “lock and hinge updating”, they interlock with each other, laying codes systematically.
In May 2018, the Internet’s worldwide regional regulatory agencies (RIR) announced officially that February 1, 2019would be the “DNS Flag Day”. According to the official notifications from regional Internet authorities and the joint alert of the Internet community, non-compliant domain name servers will identified as “Dead” from the “Execution Day” and beyond, which will make inroads on the access of related websites.
Domain name servers are mainly authoritative domain name servers and recursive domain name servers oriented. Compliance is a “workaround” to dispense with or delete DNS software by updating software version, and to identify or support the Domain Name System Extension Mechanism (EDNS) by Software Defined Interconnection (SDN). EDNS is implemented by the standard RFC 6891 released by the Internet Engineering Task Force (IETF) in 2013.
The application of DNS protocols on the Internet has a history of more than 30 years. It is the first time in the history of the Internet of the “Execution Day” to maintain DNS protocols and update DNS software versions together globally, indicating the DNS into a new beginning, a new phase, and a new generation in control community. The Asia Pacific Network Information Center (APNIC) state: “We hope that all operators of authoritative DNSSEC (DNS Security Extension) servers will be able to successfully update their DNS system software and seamlessly transfer to the next 30 years of DNS era.”
The London School of Economics and Political Science (LSE) published an article entitled “China and the Domain Name System” in March 2009stating,“In terms of Information and Communication Technology (ICT), DNS is an ‘inherently political’ technology. Because of its ability to allocate, store, and resolve Internet addresses, it is undoubtedly an important fountain of political power; and DNS is mainly for the assurance of the latent capacity to conduct successful communication between standardized technologies and system and the avoidance of duplicate allocation of a same network address. ‘Inherently political’ technologies also characterized by the high concentration of DNS technology itself. Therefore, these who possess the centralized technology of DNS will seize the power and dominance in cyberspace.”
B. To dispense with the “next Internet IPNG”
The United States has released a series of planned preparations and foreshadows for the implementation of the “next 30-year DNS era”, including the deployment of “recognition” for the Internet development.
1). To Abandon IPv6 as “next generation Internet protocols”, this lasts for nearly 20 years
On July 14, 2017, the US Internet Engineering Task Force (IETF) released Document RFC 8200, announcing the latest official standard for the sixth edition of the Internet Protocol (IPv6) (Code: STD 86).The Document RFC 2460 (the draft IPv6 specification) proposed in December 1998 and the “Next Generation Internet Protocol IPNG” which was originally for the transition to IPv6 abandoned and removed.
The US Internet Regional Working Group pointed out: “In the past few years, the widespread implementation of new data protection regulations around the world is beginning to make inroads on technology companies and consumers worldwide, resulting the change to bad practices of some formerly established best methods required by IETF procedures and regulations.”That is to say, the dramatic changes in the global network application environment have caused dramatic changes in the network technology frames and user needs, “which led to the inevitability and necessity of abolishing drafts (protocols) and transitional measures (plans) with IPv6 in the “next generation of Internet ”, showing that the Document RFC No. 8200 is based not only on the objective summary and generalization of the history and status of the Internet but the adherence to the principle of “US first” and the maintenance of “the supremacy of US interests”, the aim of cyberspace strategy and the security bottom line.
In the United States, the transition to IPv6 proposed with a pretext of the “insufficient number of IPv4 addresses”; the “IPv6 draft specification” and “next generation Internet IPNG” transition plan now abandoned based on the same principles. The reason being not simply in the design of network technology architecture; nor in the strategic error of network deployment, but a major deployment to deepen and refine the US network hegemony, and a fundamental decision to reaffirm the “inherently political” trait of the Internet.
Correspondingly, the KSK and DNS Domain Name System Extension Mechanism (EDNS), which controls the DNS Domain Name System Security Extension (DNSSEC), are the premise and the foundation for establishing and consolidating the core role and status of DNS in the “next generation Internet “.
2). The release of three basic principles advocated by IETF intellectual property rights
In May 2017, the US Internet Engineering Task Force (IETF) issued the official document RFC8179 (BCP79), the “Intellectual Property Rights in IETF Technology”, providing three basic principles in handling Internet intellectual property problems and discarding document RFC3979 and RFC4879. TheRFC8179 document stipulates:
a) The IETF will make no determination about the validity of any particular IPR claim.
b) The IETF, following normal processes, can decide to use technology for which IPR disclosures been made if it decides that such a use is warranted.
c) In order for a working group and the rest of the IETF have the information needed to make an informed decision about the use of particular technology. All those contributing to the working group’s discussions must disclose the existence of any IPR the Contributor or any other IETF Participant believes Covers or may ultimately cover the technology under discussion. This applies to both Contributors and other Participants, and applies whether they contribute in person, via email, or by other means. The requirement applies to all IPR of the Participant, the Participant’s employer, sponsor, or others represented by the Participant that reasonably and personally known to the Participant. No patent search is required.
That is to say, “The Internet is mine, and the rules are made by me.” IETF is legitimate to choose technology that has not intellectual property rights claimed yet, or freely licensed intellectual property technology; IETF can adopt any technology with no promise of any technology license. Indicating that technology adopted by the IETF in Internet engineering applications is free from the restriction of intellectual property rights and ownership owners. It only determined by the IETF whether the technology adopted by the Internet is “compliant”; technology and any application of intellectual property rights are invalid and non-compliant without the consent of the IETF, and the IETF will not admit it. It is commonplace for the IETF to enforce the utterance of security technology in its technical specifications. The release of the three principles of intellectual property rights is only a public announcement of the “removing the burning brands from under the boiling cauldron”, “overweening” and “getting my own way” strategies.
Until November 2018, the US Patent and Trademark Office (USPTO) granted 19,296 patents for IPv6 related technologies, and the European Patent Office (EPO) granted 2,180. The abrogation of IETF for IPv6 as the “Next Generation Internet Protocol” and its decision to implement a global “DNS Execution Day” and the practice of arbitrarily shutting down the best servers of other countries (such as Iraq and Libya, disconnecting the network and services. No matter how powerful the intellectual property rights are, no matter who grants intellectual property rights to them and who’s intellectual property rights are, the three principles of intellectual property rights of IETF, the US civil society organization, are placed on the authority of the government to protect intellectual property rights and the authority of the regulatory agencies. They are absolute dominate and the only “compliance” to the Internet.
The principle of “US priority” and “US interest first” and the bottom line always placed beyond everything else, too is the cyberspace hegemony to maintain the Internet “one network for all” policy.
II. LEGAL COMPETITION FOR DATA SOVEREIGNTY
The three basic dimensions that make up cyberspace are the infrastructure-centered physical dimension, the data-centric information dimension, and the cognitive dimension centered on human behavior. For more than half a century, irreversible evolution have taken place, from industrialization to socialization, from commercialization to customization, and the quality-quantity evolution from technology-driven to data-driven, especially the dominance and influence of marginal politic power have become increasingly prominent.
The United Nations Internet Governance (IGF) organization has approved the Global Internet and Jurisdiction Policy Network (I&J) as an “open forum” with more than 200 key entities from different stakeholders around the world participated, including governments and networks enterprises, technical groups, civil organizations, academic institutions and international institutions (for some reason, no Chinese organization participated), with the focus of research and discussion being “the jurisdiction of data” for three consecutive I & J annual meetings (including the upcoming annual meeting in June 2019).
In October 2015, the European Court of Justice (ECJ) made a landmark ruling that overturned the “safe harbor “mechanism proposed by the European Commission at the beginning of this century and has utilized by more than 4,000 companies, including IBM, Google and Ericsson. According to the European Court of Justice, the “safe harbor” mechanism does not provide adequate protection for the personal data of EU citizens, because the United States often violates the privacy protection measures established by the mechanism in the name of national security, public interest and law enforcement needs.
UK is the one with the highest penetration rate of the Internet economy in the G20 countries. The goal of the UK government is to make UK the safest country to conduct online business activities, and the government holds that the level and duration of protection for personal data should be improve simultaneously when the amount of personal data is keeping increased by the development of digital economy. On August 7, 2017, the UK Department of Digital, Cultural Media and Sports issued a report titled “New Data Protection Act: Our Reforms”, which passed the new Data Protection Law to update and enforce the personal data protection in the digital economy era and to replace the 1998 Data Protection Act.
The General Data Protection Regulations (GDPR) adopted by the European Parliament came into effect on May 25, 2018. The regulation extends the data protection from subordinates to owners, refines the classification of personal private data, clarifies the “consent” requirements of the data subject, and guarantees the individual’s access to the data, the right to restrict processing and the right to refuse data using, and “portable rights” (obtaining a copy of personal data processing), “erasing rights” (also known as the right to be forgotten). Severe high-limit penalties have been imposed for data managers and processors who violate the law to negate data owner rights, to restrict data processing, to interrupt data transmission or to prohibit data access.
Trump is in a tit for tat, and signed the Clarify Lawful Overseas Use of Data (CLOUD) on March 23, 2018; two months in advance of the European Union, requiring the US Federal Bureau of Investigation (FBI) and other law enforcement agencies have the right to get access to Internet data worldwide. The bill holds that timely access to electronic data provided by communication service providers is the key to the US governments for protecting public safety and combating major crimes, including terrorism; the communication service providers that regulate, control or own such data should subject to the US law. The bill also allows other countries to store personal data of non-US citizens in the United States. According to professionals, the bill gives US law enforcement agencies infinite priority for administrating any data controlled by the service provider, regardless of where the data is stored and where it created.
In other words, the Clarify Lawful Overseas Use of Data holds that the US government, USA companies and institutions are legal and legitimate in accessing any data in the world to be prosecuted and punished against the EU General Data Protection Regulations..
The year 2018, it called the “first world data protection year”.
Undoubtedly, the protection of data sovereignty and security has risen to the battle for national sovereignty and security. What we have seen is still the battle for cyberspace data that dominated by “US priority”, “US interest first”. “DNS Execution Day” indicates that the cyberspace data battle has penetrated into the control and command system of the Internet in all directions.
Nomine, one of the world’s three largest network information centers, is one of the world’s first professional CCTLD (Country Code Top Level Domain) operators. The UK’s. UK domain name management and registration agency founded in May 1996. Nomine believes that DNS plays a vital role in every network – it sets the technical standard for translating human-readable domain names into machine-aware Internet Protocol (IP) addresses.
In other words, DNS is the underlying backbone platform of network data operations, applications, services, and security. The dispute between data sovereignty and security must first involve the dispute over the control, command, standard, and initiative and discourse power of the DNS.
The “DNS Execution Day” is the inevitable result of data sovereignty competition. The United States yields none in cyberspace data, not only in technology but also in the performance and implementation at the legal level.
III. CHINA’S NETWORK DATA HAS MAJOR SECURITY RISKS
A. Servers generally hosted outside the country
When observing reversely, China is obviously lagging behind in maintaining data sovereignty and security, protecting data, paying attention to and using data. In the form of insufficient emphasis on law, owner management, and governance of data, many institutions and officials who rely on data and contact with data all day are ignorant of the principles, bottom lines, key points, methods, and approaches of data protection. They are politically confused; formality adhered, technically exaggerated, and lazy in management.
According to National Information Center’s continuous real-time monitoring based on DNS open source information, there is a top-down tendency in China’s party and government organs, state-owned enterprises, well-known websites (service providers) and other servers with their servers indirectly or directly hosted outside the country. In recent years, there is a large number of data leakages in citizens’ personal data, corporate data, national data, and other data involving important economic, political, social, cultural, military and other sensitive industries. Some enterprises provide exclusive services of domestic servers hosting to overseas, and Content Delivery Network (CDN) services, without any scruples and hesitation.
In 2017, China ranked first in the top 10 countries of data leaking. The main member including Baidu with 2 billion user phone numbers, names and addresses; Notecase’s 1.222 billion email addresses and user passwords sold on the Internet; Shanghai Chonju’s 268 million email addresses and phone numbers; Ten cent’s 130 million Email address and user password sold on the network and the like. So far, how do did they reflect and rectify, and how did the government regulatory department investigate and handle with they remain unknown. However, the online articles that disclosed the truth of the leaked data were quickly delete, and the websites that published the articles were under great pressure. Not only are the rights of the individuals and units that have leaked data at least not respected and protected, but the national data security issue is actually “turned to domestic sales” after being discovered and alerted by the outside world. It is really a strange thing.
On October 11, 2018, Wiki Leaks published Amazon’s “highly confidential” internal file “Amazon Atlas.” The document lists the address and operational details of more than 100 Amazon data centers in 15 cities across nine countries, among them nine data centers are in China with six in Beijing. In 2013, Amazon signed a contract with the US Central Intelligence Agency (CIA) to build a “cloud” for intelligence agencies to integrate and provide information classified as “top secret”. Amazon also operates a special Gov Cloud area (government cloud) for the US government. Amazon’s government cloud center in China is located in Ningxia Province. Many local development zones and high-tech zones have numbly invited Amazon to set up data centers in the region to publicize and provide “business” training for free servers hosting.
On November 20, 2017, Amazon publicly announced that it would provide a “cloud” service to the CIA and its intelligence system (IC) members, known as the “Amazon Secret Service” (AWS Secret Region). Amazon called the service “the first and the only commercial cloud providing the government with a comprehensive data classification service, including non-confidential, sensitive, confidential, top secret data”. Amazon is the only company required to certify confidential data in the “cloud”. The Net Ease mail server hosted on Amazon’s AWS service platform.
The server is hosted outside the country, on Amazon,, meaning that the path and system relying on the DNS domain name address translation and resolution depend ocean penetrate (leap) China’s “firewall”, with no need to go through the “mirror” in China (With no traces left).It avoid the various monitoring and supervision in China, and the big data managed by the host can be selectively filtered and then “pushed” back to the “Cloud” operated b China.
B. Revolving Doors Abound
In the early years, some college elites in the United States changed their status and became national politicians. Some senior generals retired as multinational entrepreneurs or scientific research leaders. They considered the “revolving doors” of identity conversion, which provided the possibility for the realization of the American dream.
Over the years, the concept and manipulation of the “revolving door” has applied to the Internet. Based on the situational awareness of DNS real-time monitoring, the “revolving door” problem found in the servers and “cloud” centers of publicly known websites.
The “vest effect” led by the domestic company and jointly produces the data flow to the outside is called the “inner revolving door”, otherwise it is called the “outer revolving door”. The original source data conducted in China hosted overseas, and the data pushed from overseas is the data being filtered (backup), and cached domestic. Data leakage or malicious utilization are only in the moment of “revolving door”, and we are often asking and arguing for whether the data is leaked, how much data leaked, “towing the library” or “collision library”…..
Please note that in recent years, the US Department of Justice, the Federal Bureau of Investigation, and other public evidences of criminal prosecution of Chinese citizens (including my national security officials, international students, researchers, entrepreneurs and the like) are mainly obtain through the “revolving door”-- Open source data, information, and intelligence.
The CDN Cache Server is an important technical model supporting “revolving doors”. It is the source to provide data (content) to the territory, and also the node that receives data (content) from outside the country. Its open custom port potentially interacts with other countries. Network intrusions and attacks often utilize custom port penetration.
Among Ten cent’s 16 mail servers (IPv4 addresses), 12 of them belong to Los Angeles, with an autonomous system AS 7939, the owner being owner Hurricane Electric (HE, Hurricane Electronics); and the rest 4 in Shenzhen, with an autonomous system AS 132203/132591, with the owner being Ten cent itself. All servers have a “revolving door” function.
Apple has four major domain names in China. The “Guizhou-Cloud Big Data” page is www.colasoft.com.cnicloud.com.cn, and the other three addresses displayed on Apple’s official website. The “Canonical Name” of “Guizhou-Cloud Big Data” is www.icloud.com.cn.edgekey.net, the website in China is 47.96.193.19 (www.icloud.com.cn), and the owner is AS37963 (Alibaba Cloud). The IPv4 address 104.100.56.123 mapped to the IPv4 address 23.38.201.117, and the owner is Akamai Corporation of the United States (a service provider with more than one-third of the CDN market in the world). The function of “Guizhou-Cloud Big Data” and the “revolving door” is very obvious and typical, and may involve deeper and broader cyberspace sovereignty and security issues.
The alias of China Railway 12306’s main website is www.12306.cn.lxdns.com, the website in China is 58.216.109.187, the owner is AS4134 (China Telecom), and the five DNSs bound to the alias are all in the United States (AS54994).It is a typical DNS-based content push network (DN-CDN); the domain name of the customer service center dynamic.12306.cn is hosted by the host’s IP address 210.61.207.156 (AS3462), the territory is actually Taiwan (Taipei) and the owner is incredibly the official network operator of Taiwan, Data Communication Business Group.
TABLE I.
SOME OF CHINA RAILWAY’S SUB DOMAIN HOSTED IN TAIWAN [210.61.207.156]
| Sub-domain name (alias) | Standardize domain name | IP address visible in the territory (A record) | Business (reference) |
|---|---|---|---|
| dynamic.12306.cn | dynamic.12306.cn.lxdns.com | 110.18.246.12 | customer service |
| ad.12306.cn | ad.12306.cn.wscdns.com | 110.18.246.12 | advertisement |
| travel.12306.cn | travel.12306.cn.wsglb0.com | 110.18.246.12 | go out |
| hotel.12306.cn | hotel.12306.cn.wsglb0.com | 110.18.246.12 | hotel |
| wifi.12306.cn | wifi.12306.cn.wsglb0.com | 110.18.246.12 | Radio communication |
| test.wifi.12306.cn | test.wifi.12306.cn.wscdns.com | 110.18.246.12 | test |
| eximages.12306.cn | eximages.12306.cn.wsglb0.com | 110.18.246.12 | picture |
| epay.12306.cn | epay.12306.cn.lxdns.com | 110.18.246.12 | electronic payment |
| expay.12306.cn | expay.12306.cn.wsglb0.com | 110.18.246.12 | |
| epay-hy.12306.cn | epay-hy.12306.cn.lxdns.com | 110.18.246.12 | |
| exservice.12306.cn | exservice.12306.cn.wsglb0.com | 110.18.246.12 | |
| hyfw.12306.cn | hyfw.12306.cn.lxdns.com | 110.18.246.12 |
| Sub-domain name (alias) | Standardize domain name | IP address visible in the territory (A record) | Business (reference) |
|---|---|---|---|
| cx.12306.cn | cx.12306.cn.wsglb0.com | 110.18.246.11 | Member Services |
| video.12306.cn | video.12306.cn.lxdns.com | 110.18.246.11 | video |



