Edge controller, source server controller and method for operating in content delivery network system

By introducing edge controllers and source server controllers into the CDN system, and using encryption keys to encrypt and manage content data, the inefficiency and security problems of the CDN system when processing private and secure sensitive information is solved, and efficient and secure information processing and transmission are achieved.

CN120113191APending Publication Date: 2025-06-06HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101391.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-17
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Typical content distribution network (CDN) systems have inefficient problems when handling private and secure sensitive information, and are vulnerable to attacks such as malware, rogue administrators and side channel observers, resulting in information disclosure and privacy leakage.

Method used

By introducing edge controllers and source server controllers in the CDN system, the content data is encrypted using a pre-shared key (PSK) and a group access key (GAK), and the sensitivity and cache mode of the content data are determined based on the HTTP cache control attributes to ensure the security of the content data during transmission and storage.

Benefits of technology

It realizes efficient processing of private and secure sensitive information, enhances the security and reliability of CDN systems, reduces the risks of information leakage and IP theft, and reduces the cost and complexity of IT infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120113191A_ABST
    Figure CN120113191A_ABST
Patent Text Reader

Abstract

An edge controller is configured to operate in a CDN system including one or more CDN components, where the edge controller is configured to receive a request for content data from the client. The edge controller is to determine that the content data is sensitive and to be securely cached. In response, the edge controller is configured to determine that the client is authenticated and, in response, provide the sensitive content data to the client wherein the content data is provided in encrypted form based on a pre-shared key generated by a source server, the edge controller is further to receive a group access key from a client as part of the request for content data, the group access key indicating an instance of the content data. The disclosed CDN system efficiently processes private and security sensitive information by using the source server and the edge controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to the field of data distribution; and more particularly, to an edge controller for operating in a content distribution network (CDN) system, a method for use in the edge controller, an origin server controller for operating in the CDN system, and a method for use in the origin server controller. Background Art

[0002] A typical content distribution network (CDN) system is a geographically distributed network of proxy servers and their data centers. The goal of a CDN system is to provide high availability by distributing services spatially relative to end users. Since typical CDN systems support basic security protections, it is recommended that content owners do not cache security-sensitive or private content at the edge of a typical CDN system. Technical challenges such as high complexity, cross-geographic distribution, and fragmented reality make the CDN edge often vulnerable to information disclosure, privacy leakage, and Internet protocol (IP) theft caused by malware running on infected servers, rogue administrators, side-channel observers, etc. Therefore, a typical CDN system is required not to cache private information at the CDN edge. Therefore, the inherent performance and reliability of a typical CDN system are partially utilized, while providing technical solutions with high security and privacy requirements (for example, in healthcare, enterprises or government organizations, etc.).

[0003] Currently, certain methods have been developed to improve the performance of typical CDN systems, for example, CDN systems are customized for proprietary use cases and content types and rely on dedicated communication channels, site monitoring, etc. The above technical solutions usually increase the typical CDN system, resulting in increased cost and complexity of IT infrastructure. Thereafter, several CDN systems were integrated to achieve comprehensive and efficient sharing of all types of content (including privacy and security sensitive content), but such integration is complex and expensive. Therefore, there is a technical problem of inefficient handling of private and security sensitive information in typical CDN systems.

[0004] Therefore, in light of the above discussion, there is a need to overcome the above-mentioned shortcomings associated with conventional ways of handling privacy and security sensitive information in typical CDN systems. Summary of the invention

[0005] The present invention provides an edge controller for operating in a content distribution network (CDN) system, a method for use in the edge controller, an origin server controller for operating in the CDN system, and a method for use in the origin server controller. The present invention provides a technical solution that solves the problem of inefficient processing of private and security-sensitive information in typical CDN systems. The purpose of the present invention is to provide a technical solution that at least partially overcomes the problems encountered in the prior art and provides an improved edge controller for operating in a content distribution network (CDN) system, an improved method for use in the improved edge controller, an improved origin server controller for operating in the CDN system, and an improved method for use in the improved origin server controller.

[0006] The objects of the invention are achieved by the solutions presented in the attached independent claims. Advantageous embodiments of the invention are further defined in the dependent claims.

[0007] In one aspect, an edge controller is provided for operating in a CDN system including one or more CDN components, wherein the edge controller is used to receive a request for content data from the client. The edge controller is also used to determine that the content data is sensitive and will be securely cached. In response, the edge controller is also used to determine that the client is authenticated, and in response, provide the sensitive content data to the client, wherein the content data is provided in encrypted form based on a pre-shared key (PSK) generated by an origin server and unknown to the one or more CDN components, wherein the edge controller is also used to: receive a group access key (GAK) from the client as part of the request for content data, wherein the GAK indicates an instance of the content data; provide the GAK as part of the request for content data to the origin server, wherein the edge controller is characterized in that it is used to determine that the content data is sensitive and will be securely cached based on an HTTP cache control attribute, and the HTTP cache control attribute indicates that the content data is sensitive and will be securely cached.

[0008] The disclosed CDN system efficiently handles private and security-sensitive information by offloading the protection (e.g., encryption and decryption) of the content data to the origin server and the edge controller. The content data is encrypted using an encryption key (i.e., PSK), and therefore, the disclosed CDN system shows enhanced reliability and traffic savings. The PSK refers to a symmetric key that is pre-shared between the client and the origin server and is not accessible to the CDN machine. In addition, the content data is only shared with authentic and authorized clients in an encrypted form. In addition, the client's content data access rights are managed by using the GAK. This leads to improved maintenance of private and security-sensitive information in the disclosed CDN system.

[0009] According to one implementation, the edge controller is also used to determine that the content data is not stored in the local cache memory, and in response request the content data from the source server, wherein the content data is received in an encrypted form based on the PSK, and the encrypted content data is stored in the local cache memory.

[0010] By storing the content data in encrypted form in the local cache memory, enhanced security of the content data is achieved.

[0011] In another implementation, the edge controller is further configured to determine that the age of the GAK exceeds a key threshold age, and in response delete the content data.

[0012] The GAK is created within a limited period of time (ie, life cycle) to reduce the chances of stealing the content data.

[0013] In another implementation, the edge controller is further configured to update the content stored in the local cache memory.

[0014] The content data is updated after the encryption key is updated to facilitate maintenance of the content data.

[0015] In another implementation, the edge controller is further configured to reauthorize the delineation segment.

[0016] After the encryption key is updated, the client will be re-authorized to improve the security and reliability of the content data.

[0017] In another implementation, the edge controller is further configured to receive a request for the sensitive content data from a second client, determine that the client is not authorized, and initiate an authorization process for the second client in response.

[0018] When it is determined that the client is not authorized, an access authorization process for the second client is initiated, thereby improving the reliability of the CDN system.

[0019] In another aspect, the present invention provides a method for an edge controller, the edge controller being configured to operate in a CDN system including one or more CDN components. The method includes receiving a request for content data from the client, and determining that the content data is sensitive and will be securely cached. In response, the method also includes determining that the client is authenticated, and in response providing the sensitive content data to the client, wherein the content data is provided in encrypted form based on a pre-shared key generated by an origin server and unknown to the one or more CDN components, wherein the method is characterized in that the method also includes determining that the content data is sensitive and will be securely cached based on an HTTP cache control attribute, the HTTP cache control attribute indicating that the content data is sensitive and will be securely cached.

[0020] The method realizes all the advantages and technical features of the edge controller of the present invention.

[0021] In yet another aspect, the present invention provides a computer program product comprising program instructions for performing a method when the program instructions are executed by one or more processors in a CDN system.

[0022] The computer (eg, a processor of a device or system) realizes all the advantages and effects of the method after executing the method.

[0023] In yet another aspect, the present invention provides an origin server controller for operating in a CDN system including one or more CDN components, wherein the origin server controller is further used to retrieve a pre-shared encryption key (PSK). The origin server controller is further used to retrieve a group access encryption key (GAK), wherein the GAK is unknown to the one or more CDN components; receiving an authentication request from a client. The origin server controller is further used to initiate an authentication process for the client, determine that the authentication process is successful, and in response, provide the PSK and the GAK to the client. The origin server controller is further used to receive a request for content data from the edge controller, determine that the requested content data is sensitive, and in response, determine an instance of the requested content data based on the GAK. The origin server controller is further used to encrypt the content data using the PSK and provide the encrypted data to the edge controller, the encrypted data indicating that the data is sensitive.

[0024] The content data is encrypted using the PSK that is unknown to the one or more CDN components of the CDN system, thereby improving the security and reliability of the content data. The PSK and GAK are only shared with authenticated and authorized users as part of the authentication process. In addition, the edge controller is used to provide the requested content only to authorized users who prove their access rights using the GAK assigned to the specific instance of the content data. In addition, unauthorized users are forwarded to the origin server controller for further authentication, thereby enhancing the performance of the CDN system.

[0025] In one implementation, the source server controller is further configured to generate the encryption key for a group of users.

[0026] In another implementation, the source server controller is further configured to generate the encryption key for a type of content.

[0027] Different types of content data use different encryption keys, and the access and lifecycle of encryption keys are managed.

[0028] In another implementation, the origin server controller is further configured to indicate that the data is sensitive by setting an HTTP cache control attribute.

[0029] In another implementation, the encryption key is known only to the source server controller and authenticated clients.

[0030] Only the source server controller and the authenticated client know the encryption key, thereby enhancing the security of the content data.

[0031] In yet another aspect, the present invention provides a method for an edge controller, the edge controller being used to operate in a CDN system including one or more CDN components. The method includes: retrieving a pre-shared encryption key (PSK); retrieving a group access encryption key (GAK), wherein the GAK is unknown to the one or more CDN components. The method also includes: receiving an authentication request from a client; initiating an authentication process for the client. The method also includes: determining that the authentication process is successful, and providing the GAK and the PSK to the client in response, and receiving a request for content data from the edge controller. The method also includes: determining that the requested content data is sensitive, and in response determining an instance of the requested content data based on the GAK; encrypting the content data using the PSK; and providing the encrypted data to the edge controller, the encrypted data indicating that the data is sensitive.

[0032] The method realizes all the advantages and technical features of the source server controller of the present invention.

[0033] In yet another aspect, the present invention provides a computer program product comprising program instructions for performing a method when the program instructions are executed by one or more processors in a CDN system.

[0034] The computer (eg, a processor of a device or system) realizes all the advantages and effects of the method after executing the method.

[0035] It should be understood that all the above implementations can be combined together.

[0036] It should be noted that all devices, elements, circuits, units and modules described in this application can be implemented in software elements or hardware elements or any type of combination thereof. The steps performed by the various entities described in this application and the functions to be performed by the various entities described are intended to refer to the various entities for performing the various steps and functions. Even in the description of the following specific embodiments, the specific functions or steps to be performed by the external entity are not reflected in the description of the specific detailed elements of the entity performing the specific steps or functions, the technician should be aware that these methods and functions can be implemented in the corresponding software or hardware elements, or in any combination of such elements. It is understandable that the features of the present invention are easy to combine in various combinations without departing from the scope of the present invention defined by the appended claims.

[0037] Other aspects, advantages, features and objects of the present invention will be apparent from the accompanying drawings and detailed description of illustrative embodiments interpreted in conjunction with the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The above summary of the invention and the following detailed description of illustrative embodiments may be better understood when read in conjunction with the accompanying drawings. In order to illustrate the present invention, exemplary structures of the present invention are shown in the accompanying drawings. However, the present invention is not limited to the specific methods and means disclosed herein. In addition, it will be appreciated by those skilled in the art that the accompanying drawings are not drawn to scale. Where possible, identical elements are represented by identical numerals.

[0039] The following is a description of the embodiments of the present invention by way of example only and in conjunction with the following drawings.

[0040] Figure 1 An environment diagram in which an edge controller is used to operate in a content distribution network (CDN) system provided by an embodiment of the present invention;

[0041] Figure 2 A block diagram of various exemplary components of an edge controller provided for embodiments of the present invention;

[0042] Figure 3 The access flow of content data in a CDN system including an edge controller and an origin server controller provided by an embodiment of the present invention is described;

[0043] Figure 4 A block diagram of various exemplary components of a source server controller provided for an embodiment of the present invention;

[0044] Figure 5 A flow chart of a method for an edge controller running in a CDN system provided by an embodiment of the present invention;

[0045] Fig. 6A and Figure 6B The overall flowchart is a method for an origin server controller running in a CDN system provided by an embodiment of the present invention;

[0046] Figure 7 An operational flow chart describing the delivery flow of content data in a CDN system provided by an embodiment of the present invention;

[0047] Figure 8 An operational flow chart describing group sharing, content refresh, and security considerations in a CDN system is provided for an embodiment of the present invention.

[0048] In the drawings, underlined numbers are used to indicate the item in which the underlined number is located or the item adjacent to the underlined number. Non-underlined numbers are associated with the item identified by the line linking the non-underlined number to the item. When a number is not underlined but has an associated arrow, the non-underlined number is used to identify the general item to which the arrow points. DETAILED DESCRIPTION

[0049] The following detailed description describes embodiments of the invention and ways in which these embodiments may be implemented. Although some embodiments of the invention have been disclosed, those skilled in the art will recognize that other embodiments may be implemented to implement or practice the invention.

[0050] Figure 1 An environment diagram in which an edge controller is used to operate in a content distribution network (CDN) system is provided for an embodiment of the present invention. Figure 1 , shows an environment diagram 100 in which an edge controller 102 is configured to operate in a CDN system 104 including one or more CDN components 106. Also shown are a client 108, an origin server 110, and a second client 112. The CDN system 104 also includes a processor 114 and a memory 116.

[0051] The CDN system 104 may include appropriate logic, circuitry, and / or interfaces for handling content transfer from the origin server 110 to the client 108 and the second client 112 after authenticating each of the client 108 and the second client 112. Alternatively, the CDN system 104 is a strategically placed system for providing cached versions of static content from the origin servers to users, such as the client 108. The static content may include images, JavaScript, HTML, and downloadable content.

[0052] The origin server 110 may also be referred to as a content owner or an origin server controller. Each of the client 108 and the second client 112 may also be referred to as an end user or consumer of the content data.

[0053] The processor 114 may include appropriate logic, circuits, and / or interfaces for executing instructions stored in the memory 116. Examples of the processor 114 may include, but are not limited to, a general-purpose processor, a controller, a microcontroller, a microprocessor, a complex instruction set computing (CISC) processor, an application-specific integrated circuit (ASIC) processor, a reduced instruction set computing (RISC) processor, a very long instruction word (VLIW) processor, a data processing unit, and other processors or control circuits. In addition, depending on the application scenario, the processor 114 may refer to one or more separate processors.

[0054] The memory 116 may include suitable logic, circuitry, and / or interfaces for storing data and instructions executable by the processor 114. Implementation examples of the memory 116 may include, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Random Access Memory (RAM), a Read-Only Memory (ROM), a Hard Disk Drive (HDD), a flash memory, a Solid-State Drive (SSD), or a CPU cache memory. The memory 116 may store an operating system or other program products (including one or more operating algorithms) to run the CDN system 104.

[0055] In operation, the edge controller 102 is configured to operate in a CDN system 104 including one or more CDN components 106, wherein the edge controller 102 is configured to receive requests for content data from clients 108. The edge controller 102 is configured to support secure caching of private and no-storage content at the edge of the CDN system 104 to achieve efficient processing of private and security-required information while meeting security restrictions. "Private" content can be defined as data content that can only be cached by the browser of the client 108. "No-storage" content can be defined as data content that is always returned by the origin server 110 and is not cached anywhere else. The client 108 is configured to access the content data by executing a request to the edge controller 102.

[0056] The edge controller 102 is further configured to determine that the content data is sensitive and is to be securely cached, and in response determine that the client 108 is authenticated, and in response provide the sensitive content data to the client 108, wherein the content data is provided in an encrypted form based on a pre-shared key (PSK) generated by the origin server 110 and unknown to the one or more CDN components 106. Upon receiving a request from the client 108, the edge controller 102 is configured to determine whether the content data is sensitive. In this case, if the content data is sensitive, the edge controller 102 is further configured to determine whether the client 108 is authentic. After determining the authenticity of the client 108, the edge controller 102 is configured to provide the content data in an encrypted form only to authentic and authorized users (e.g., the client 108). The content data is encrypted using the PSK generated by the origin server 110. The PSK is not accessible to the one or more CDN components 106.

[0057] The edge controller 102 is further configured to: receive a group access key (GAK) as part of a request for content data from the client 108, wherein the GAK indicates an instance of the content data; and provide the GAK as part of the request for content data to the origin server 110, wherein the edge controller 102 is characterized in that it is configured to determine that the content data is sensitive and will be securely cached based on an HTTP cache control attribute, wherein the HTTP cache control attribute indicates that the content data is sensitive and will be securely cached. An authorized user (i.e., the client 108) uses the GAK assigned to a specific instance of the content data to prove its access rights. The edge controller 102 is configured to receive the GAK, which indicates the instance of the content data as part of the request for content data completed by the client 108. Thereafter, the edge controller 102 is configured to provide the GAK as part of the request for content data to the origin server 110. In addition, the edge controller 102 is configured to determine that the content data is securely cached based on the HTTP cache control attribute. The use of the HTTP cache control attribute indicates that the content data is securely cacheable and facilitates caching of recently uncacheable private and no-storage content in an enhanced security manner.

[0058] According to one embodiment, the edge controller 102 is further configured to determine that the content data is not stored in the local cache memory, and in response request the content data from the source server 110, wherein the content data is received in an encrypted form based on the PSK, and the encrypted content data is stored in the local cache memory. In one implementation, the edge controller 102 checks whether the requested content data is available in the local cache memory. In the case where the content data is not stored in the local cache memory, the edge controller 102 requests the content data from the source server 110. The source server 110 provides the content data in an encrypted form by using the PSK. The encrypted content data is stored in the local cache memory.

[0059] According to one embodiment, the edge controller 102 is further configured to determine that the age of the GAK exceeds a key threshold age and delete the content data in response. The origin server 110 is configured to create the GAK within a limited time period so that an attacker will have a limited time window to steal information from the client 108.

[0060] According to one embodiment, the edge controller 102 is also used to update the content stored in the local cache memory. Similar to the GAK, the source server 110 is used to generate the PSK within a limited time period (e.g., 1 minute to 1 hour) so that if an attacker is managed to steal the PSK from the client 108, other instances of the content data will not be opened, and there is a limited time window for publishing appropriate content stolen from the local cache memory. In the scenario where a new PSK and GAK are issued, the source server 110 is used to re-encrypt the content data using the new PSK, so that the content data (with the old uniform resource locator (URL)) cannot be accessed within a predefined time. Therefore, the content data is updated to the local cache memory.

[0061] According to one embodiment, the edge controller 102 is further configured to re-authorize the client 108. In the scenario of updating the PSK and GAK, the client 108 is configured to perform a key update request. In addition, the edge controller 102 is configured to re-authenticate the client 108.

[0062] According to one embodiment, the edge controller 102 is also used to receive a request for sensitive content data from the second client 112, and determine that the client is not authorized, and in response initiate an authorization process for the second client 112. Similar to the authorization of the client 108, the edge controller 102 is used to determine whether the second client 112 is authorized when receiving a request for sensitive content data from the second client 112. In the case that the second client 112 is not authorized, the edge controller 102 is used to initiate an access authorization process for the second client 112 by using the origin server 110.

[0063] Thus, the CDN system 104 efficiently handles private and security-sensitive information by using the edge controller 102 and the origin server 110. Caching security-sensitive and private content data through a general CDN (e.g., CDN system 104) helps users (e.g., clients 108) get rid of proprietary technology solutions used in addition to the CDN system 104 (e.g., Zoom, WhatsApp, site mirroring, etc.) and switch to existing "regular" CDN services. Therefore, in regulated enterprises (e.g., healthcare, government, military, etc.), simplification and cost reduction of IT infrastructure design, content management and maintenance can be achieved. In addition, sensitive content providers (e.g., distance education companies, ML federated learning services, etc.) require a large amount of content sharing and related content volume.

[0064] Figure 2 A block diagram of various exemplary components of an edge controller provided by an embodiment of the present invention. Figure 1 Component Description Figure 2 . refer to Figure 2 , showing the description ( Figure 1 2 is a block diagram 200 of an edge controller 102. The edge controller 102 includes a business logic (BL) 202, a client adapter 204, a local cache memory 206, and a processor 208. The business logic 202 includes a content access manager (CAM) 210 and a lifecycle manager 212. In addition, the edge controller 102 may optionally include a secure content memory 214.

[0065] The edge controller 102 is operable to provide content data only to authorized users (i.e., clients 108) in response to receiving a request for content data from the client 108. The request for content data is authenticated after receiving the GAK as part of the request from the client 108. The origin server 110 provides the GAK to the client 108. The cached copy is only provided to the user (i.e., client 108) that has the most recent GAK pointing to the currently cached content.

[0066] The business logic 202 may include suitable logic, circuitry, and / or interfaces that may be operable to efficiently manage the exchange of content data between the local cache memory 206 and the client 108 .

[0067] The client adapter 204 may comprise appropriate logic, circuitry, and / or interfaces that act as a class that implements the interface and forwards calls to HTTP clients that do not implement the interface.

[0068] The local cache memory 206 may include appropriate logic, circuitry, and / or interfaces for storing data and instructions executable by the processor 208. Implementation examples of the local cache memory 206 may include, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Random Access Memory (RAM), a Read Only Memory (ROM), a Hard Disk Drive (HDD), a Flash memory, a Solid-State Drive (SSD), or a CPU cache memory. The local cache memory 206 may store an operating system or other program product (including one or more operating algorithms) to operate the edge controller 102. In one implementation, the local cache memory 206 may be part of the secure content memory 214.

[0069] The processor 208 may include appropriate logic, circuits and / or interfaces for executing instructions stored in the memory 206. Examples of the processor 208 may include, but are not limited to, a general purpose processor, a controller, a microcontroller, a microprocessor, a complex instruction set computing (CISC) processor, an application-specific integrated circuit (ASIC) processor, a reduced instruction set computing (RISC) processor, a very long instruction word (VLIW) processor, a data processing unit, and other processors or control circuits. In addition, depending on the application scenario, the processor 208 may refer to one or more separate processors.

[0070] The content access manager 210 is used to check whether the request for content data contains the authentication token provided by the origin server 110 during the authentication process. If the access of the relevant client (i.e., the client 108) to the specified content is granted, the CAM 210 is used to return the specified content to the authorized user (i.e., the client 108). Otherwise, the CAM 210 is used to forward the request to the origin server 110 for re-authentication.

[0071] Lifecycle manager 212 is used to reliably erase unused content data from local cache storage 206 based on tokens invalidated by origin server 110 .

[0072] The edge controller 102 may implement the secure content memory 214 as a secure vault or an SGX protected storage area to enhance protection of secure content at rest.

[0073] Figure 3 The access flow of content data in a CDN system including an edge controller and an origin server controller provided by an embodiment of the present invention is described. Figure 1 and Figure 2 Component Description Figure 3 . refer to Figure 3 , shows an access flow 300 of content data requested by a client 108. Further shown are one or more CDN components 304, an origin server controller 306, an access controller 308, ( Figure 1 The CDN system 302 of the edge controller 102 and the local cache memory 206 of the edge controller 102.

[0074] CDN system 302 and one or more CDN components 304 correspond to CDN system 104 and one or more CDN components 106, respectively. Origin server controller 306 corresponds to ( Figure 1 ) source server 110.

[0075] In operation, the origin server controller 306 is configured to operate in a CDN system 302 including one or more CDN components 304, wherein the origin server controller 306 is further configured to retrieve a pre-shared encryption key (PSK) and retrieve a group access encryption key (GAK), wherein the GAK is unknown to the one or more CDN components 304. In other words, the origin server controller 306 is configured to perform group key management and encryption of content data using the PSK. In addition, the origin server controller 306 is configured to modify the access control flow to provide additional attributes to the client (e.g., the client 108) for use by the edge in authorization and content selection.

[0076] The source server controller 306 is also used to receive an authentication request from the client 108 and initiate an authentication process for the client 108. In the access flow 300 of content data, the operation indicated by sequence number 1 indicates that the source server controller 306 receives an authentication request from the client 108 and initiates an authentication process for the client 108 by using the access controller 308.

[0077] The origin server controller 306 is also used to determine that the authentication process is successful and, in response, provide the PSK and GAK to the client 108. In the content data access flow 300, the authentication process of the client 108 is determined to be successful, and then the origin server controller 306 is used to provide the client 108 with the PSK and GAK.

[0078] The source server controller 306 is also used to receive a request for content data from the edge controller 102, and determine that the requested content data is sensitive, and in response, determine an instance of the requested content data based on the GAK. In the access flow 300 of the content data, in the operation indicated by sequence number 2, the edge controller 102 is used to receive a request for content data from the client 108. In addition, the edge controller 102 is used to authenticate the client 108. In the case of a real and authorized user (i.e., the client 108), the operation indicated by sequence number 3 is performed. In the case of an unauthenticated and unauthorized user, the edge controller 102 can be used to reject and redirect the request for content data. Thereafter, in the access flow 300 of the content data, in the operation indicated by sequence number 3, the edge controller 102 is used to forward the request of the client 108 to the source server controller 306. The source server controller 306 is used to determine that the requested content data includes privacy and security requirement information. In response to determining the sensitivity of the requested content data, the source server controller 306 is used to determine the GAK indicating the instance of the requested content data.

[0079] The source server controller 306 is also used to encrypt the content data using the PSK and provide the encrypted data to the edge controller 102, wherein the encrypted data indicates that the data is sensitive. In the access flow 300 of the content data, in the operation indicated by sequence number 4, the source server controller 306 is used to encrypt the content data using the PSK. Thereafter, the encrypted content data is provided to the local cache memory 206 of the edge controller 102, wherein the encrypted content data is provided to the edge controller 102. In the access flow 300 of the content data, in the operation indicated by sequence number 5, the encrypted content data is provided from the local cache memory 206 to the client 108. In the access flow 300 of the content data, the client 108 is used to decrypt the content data using the PSK indicated by sequence number 6.

[0080] According to one embodiment, the source server controller 306 is further configured to generate encryption keys for a group of users. In one implementation, the source server controller 306 is configured to generate encryption keys (ie, pre-shared encryption keys (PSK)) by a group of users.

[0081] According to one embodiment, the source server controller 306 is further configured to generate an encryption key for a content type. The source server controller 306 is configured to generate an encryption key according to the type of content data, for example, different encryption keys are generated for images and HTML pages.

[0082] According to one embodiment, the origin server controller 306 is further configured to indicate that the data is sensitive by setting an HTTP cache control attribute. The origin server controller 306 is configured to indicate that the data is sensitive by using an HTTP cache control attribute that facilitates caching of non-cacheable private and no-storage content in a special manner.

[0083] According to one embodiment, the encryption key is known only to the origin server and the authenticated client.The encryption key (ie, PSK) is known only to the origin server controller 306 and the authenticated client (eg, client 108).

[0084] Therefore, the protection of content data (i.e., encryption / decryption) is offloaded to the origin server controller 306 (i.e., the content owner) and the client's browser (i.e., the client 108). And, the CDN system 302 is used to handle only the transmission of content data. The origin server controller 306 and the client 108 can trust the CDN system 302 through the content disclosure capabilities of the CDN system 302, which eliminates all traditional technical challenges of the reliability and inefficient utilization of inherent performance of traditional CDN systems. Appropriate content is encrypted by using a PSK that is unknown to one or more CDN components 304 of the CDN system 302. The PSK and GAK are shared only with authenticated and authorized users as part of the authentication process. In addition, the edge controller 102 is used to provide requested content only to authorized users who prove their access rights using the GAK assigned to a specific instance of the content data. In addition, unauthorized users are forwarded to the origin server controller 306 for further authentication.

[0085] Figure 4 A block diagram of various exemplary components of a source server controller provided for an embodiment of the present invention. Figure 1 , Figure 2 and Figure 3 The component description Figure 4 . refer to Figure 4 , showing the source server controller 306 ( Figure 3 4, the origin server controller includes business logic (BL) 402, web front end 404, content storage 406, and processor 408. Business logic 402 includes content protection engine 410 and key manager 412. Access controller 414 connected to origin server controller 306 is also shown.

[0086] The business logic 402 may include appropriate logic, circuitry, and / or interfaces for authenticating a request for content data from a client (e.g., client 108), and after authentication, providing the client 108 with an access token (AT) and an unlocking key for further access to secure content.

[0087] The web front end 404 may comprise suitable logic, circuitry, and / or interfaces to act as an interface that the client 108 sees or interacts with when communicating with the origin server controller 306 .

[0088] The origin server controller 306 is used for group key management and content data encryption suitable for secure cacheable content data.

[0089] The content memory 406 may include appropriate logic, circuits, and / or interfaces for storing content data and instructions executable by the processor 408. In one implementation, the content memory 406 may include a memory for storing data and instructions executable by the processor 408. Implementation examples of the memory may include, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Random Access Memory (RAM), a Read-Only Memory (ROM), a Hard Disk Drive (HDD), a Flash memory, a Solid-State Drive (SSD), or a CPU cache memory. The memory may store an operating system or other program products (including one or more operating algorithms) to operate the source server controller 306.

[0090] Processor 408 may include appropriate logic, circuits, and / or interfaces for executing instructions stored in content memory 406. Examples of processor 408 may include, but are not limited to, general purpose processors, controllers, microcontrollers, microprocessors, complex instruction set computing (CISC) processors, application-specific integrated circuit (ASIC) processors, reduced instruction set computing (RISC) processors, very long instruction word (VLIW) processors, data processing units, and other processors or control circuits. In addition, processor 408 may refer to one or more separate processors depending on the application scenario.

[0091] The content protection engine 410 may comprise suitable logic, circuitry, and / or interfaces that may be operable to enhance handling of secure cacheable content and secure code review (SCR) content when requested from the edge controller 102. The content protection engine 410 may also be referred to as a content protection manager.

[0092] Key manager 412 may include appropriate logic, circuits and / or interfaces for encrypting secure cacheable content and SCR content using PSK and GAK. In addition, key manager 412 is responsible for creating and updating keys for content data encryption for each group of users and content.

[0093] In one implementation, the edge controller 102 and the origin server controller 306 may be communicatively coupled to each other and may operate as a device having the functionality of both the edge controller 102 and the origin server controller 306 .

[0094] Figure 5 A flowchart of a method for an edge controller running in a CDN system provided by an embodiment of the present invention. Figure 1 , Figure 2 , Figure 3 and Figure 4 The component description Figure 5 . refer to Figure 5 , showing that in the edge controller 102 ( Figure 1 The method 500 is used in the edge controller 102, wherein the edge controller is used to run in the CDN system 104. The method 500 includes steps 502 to 508. The method 500 is performed by the edge controller 102.

[0095] A method 500 for use in an edge controller 102 configured to operate in a CDN system 104 including one or more CDN components 106 is provided.

[0096] In step 502, method 500 includes receiving a request for content data from client 108. The request for content data is received from client 108 to perform authentication of the request and client 108 by receiving a group access key (GAK) from client 108 as part of the request for content data.

[0097] In step 504, the method 500 also includes determining that the content data is sensitive and is to be securely cached. After receiving the request from the client 108, it is determined whether the content data is sensitive.

[0098] In step 506, in response to step 504, method 500 further includes determining that client 108 is authenticated. If the data is sensitive, the authenticity of client 108 is checked.

[0099] In step 508, in response to step 506, the method 500 further includes providing the sensitive content data to the client 108, wherein the content data is provided in an encrypted form based on a pre-shared key generated by the origin server 110 and unknown to one or more CDN components 106, wherein the method 500 is characterized in that it also includes determining that the content data is sensitive and will be securely cached based on an HTTP cache control attribute, wherein the HTTP cache control attribute indicates that the content data is sensitive and will be securely cached. After checking the authenticity of the client 108, the sensitive content data is provided to the client 108 in an encrypted form. The encryption of the content data is performed by using a pre-shared key (PSK) created and shared by the origin server controller 306. The PSK is unknown to one or more CDN elements 304. At the same time, the content data is securely cached based on the HTTP cache control attribute. The use of the HTTP cache control attribute indicates that the content data is securely cacheable and facilitates caching of recently uncacheable private and no-storage content in an enhanced secure manner.

[0100] Steps 502 to 508 are merely illustrative, and other alternatives may be provided in which one or more steps are added, one or more steps are deleted, or one or more steps are provided in a different order without departing from the scope of the claims herein.

[0101] In one aspect, a computer program product is provided, including program instructions, which when executed by one or more processors (e.g., processor 114) in CDN system 104 are used to perform method 500. In another aspect, a computer system is provided, including one or more processors (e.g., processor 114) in CDN system 104 and one or more memories (e.g., memory 116), wherein the one or more memories (i.e., memory 116) store program instructions, which when executed by one or more processors (e.g., processor 114) in CDN system 104 cause one or more processors (e.g., processor 114) in CDN system 104 to perform method 500. In yet another aspect, the present invention provides a non-transitory computer-readable medium having computer-implemented instructions stored thereon, which when executed by a computer cause the computer to perform the operations of method 500.

[0102] Fig. 6A and Figure 6B The overall flow chart of the method for the source server controller running in the CDN system provided by the embodiment of the present invention. Figure 1 , Figure 2 , Figure 3 , Figure 4 and Figure 5 The component description Fig. 6A and Figure 6B . refer to Fig. 6A and Figure 6B , showing that in the source server controller 306 ( Figure 3 and Figure 4 The method 600 used in the CDN system 104 is used to execute the source server controller in the CDN system 104. The method 600 includes steps 602 to 616 (steps 602 to 610 are in Fig. 6A As shown in FIG. 6 , steps 612 to 616 are performed in Figure 6B ). Steps 610 and 614 include sub-steps 610A and 614A, 614B, respectively. Method 600 is executed by source server controller 306.

[0103] A method 600 for use in an origin server controller 306 for operation in a CDN system 302 including one or more CDN components 304 is provided.

[0104] In step 602, method 600 includes retrieving a pre-shared encryption key (PSK). The PSK is used for encryption of content data.

[0105] In step 604, the method 600 further includes retrieving a Group Access encryption Key (GAK), wherein the GAK is unknown to one or more CDN components 304. The GAK is used for initial authentication of the client 108.

[0106] In step 606, the method 600 further includes receiving an authentication request from the client 108. An authentication request for the content data is received from the client 108.

[0107] In step 608 , the method 600 further includes initiating an authentication process for the client 108 . After receiving the authentication request for the content data, the source server controller 306 is used to initiate an authentication process for the client 108 by using the access controller 308 .

[0108] In step 610, method 600 also includes determining that the authentication process is successful.

[0109] In sub-step 610A, responsive to step 610, method 600 further includes providing the GAK and PSK to the client 108. Following authentication and authorization of the client 108, the PSK and GAK are shared with the client 108 in order to decrypt the content data.

[0110] In step 612, the method 600 further includes receiving a request for content data from the edge controller 102. The origin server controller 306 is configured to receive the request for content data from the edge controller 102.

[0111] At step 614, method 600 includes determining that the requested data is sensitive. Additionally, origin server controller 306 is operable to determine whether the requested data is sensitive.

[0112] In sub-step 614A, in response to step 614, method 600 further includes determining an instance of the requested content data based on the GAK. In the event that the requested data is determined to be sensitive data, origin server controller 306 is configured to determine a GAK indicating the instance of the requested content data.

[0113] In sub-step 614B, in response to step 614, method 600 further includes encrypting the content data using the PSK. The source server controller 306 is further configured to encrypt the content data using the PSK.

[0114] In step 616, the method 600 further includes providing the encrypted data to the edge controller 102, wherein the encrypted data indicates that the data is sensitive. The source server controller 306 is configured to provide the encrypted data to the edge controller 102, and the edge controller 102 provides the encrypted data to the client 108. And, the client 108 decrypts the encrypted data by using the PSK and the GAK.

[0115] Steps 602 to 616 are merely illustrative, and other alternatives may be provided in which one or more steps are added, one or more steps are deleted, or one or more steps are provided in a different order without departing from the scope of the claims herein.

[0116] In one aspect, a computer program product is provided, including program instructions, which when executed by one or more processors (e.g., processor 114) in CDN system 302 are used to perform method 600. In another aspect, a computer system is provided, including one or more processors (e.g., processor 114) and one or more memories (e.g., memory 116) in CDN system 302, wherein the one or more memories (i.e., memory 116) store program instructions, which when executed by one or more processors (e.g., processor 114) in CDN system 302, cause one or more processors (e.g., processor 114) in CDN system 302 to perform method 600. In yet another aspect, the present invention provides a non-transitory computer-readable medium having computer-implemented instructions stored thereon, which when executed by a computer cause the computer to perform the operations of method 600.

[0117] Figure 7 The present invention provides an operational flow chart describing the delivery flow of content data in a CDN system. Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Fig. 6A and Figure 6B Component Description Figure 7 . refer to Figure 7 , an operational flow chart 700 including operations 704 to 746 is shown. In the operational flow chart 700, a client 108, an edge controller 102, an origin server controller 306, and an identity and access manager (IAM) 702 are shown.

[0118] The IAM 702 may comprise suitable logic, circuitry, and / or interfaces that may be operable to identify a client (or end-user) and facilitate access to secure cacheable data.

[0119] In operation 704 , business logic 402 of origin server controller 306 is used to receive an authentication request from client 108 .

[0120] In operation 706, the IAM 702 is used to receive an authentication request from the client 108 from the business logic 402. After receiving the request, the IAM 702 processes the request and identifies the client 108 and facilitates limited access to the client's 108 content data.

[0121] In operation 708 , IAM 702 is used to provide information regarding the identification and authentication of client 108 to business logic 402 .

[0122] In operation 710 , business logic 402 is used to create an access token and an unlocking key and provide the access token and the unlocking key to key manager 412 .

[0123] In operation 712 , the key manager 412 is used to authenticate the client 108 and provide the created access token and unlocking keys (ie, PSK and GAK) for accessing the content data.

[0124] In operation 714 , the content access manager 210 of the edge controller 102 is operable to receive a request for content data from the client 108 .

[0125] In operation 716, the content access manager 210 determines whether the content data is safely cacheable.

[0126] In operation 718 , if the content data is not safely cacheable, the content data is stored in the local cache memory 206 of the edge controller 102 .

[0127] In operation 720, the non-secure cacheable content data is provided to the client 108, the content data is rendered in the client 108, and the operational flow is terminated.

[0128] In operation 722, if the content data is securely cacheable, the content access manager 210 is used to perform a valid AT cache check request for the existence of fresh content using a key corresponding to the provided valid access token (AT).

[0129] In operation 724, if the content request does not include an AT or the AT is invalid, the client 108 is redirected to the authentication site and the operational flow is aborted.

[0130] In operation 726 , in the case of securely cacheable content data, the CAM 210 is used to check whether such data exists in the local cache memory 206 of the edge controller 102 .

[0131] In operation 728 , if the content data exists in the local cache memory 206 , the content data is provided to the CAM 210 of the edge controller 102 in operation 730 .

[0132] In operation 732 , the CAM 210 of the edge controller 102 is used to provide content data to the client 108 .

[0133] In operation 734, if the content data is not present in the local cache memory 206, the content protection engine 410 of the origin server controller 306 is queried to provide such content.

[0134] In operation 736, the key manager 412 is used to manage and distribute encryption keys of content data.

[0135] In operation 738 , the key manager 412 is used to provide the encryption key to the content protection engine 410 of the origin server controller 306 .

[0136] In operation 740, the content protection engine 410 of the origin server controller 306 is used to encrypt the content data using the encryption key.

[0137] In operation 742 , the CAM 210 is operable to receive encrypted content data from the content protection engine 410 of the origin server controller 306 .

[0138] In operation 744 , the encrypted content data is stored in the local cache memory 206 of the edge controller 102 .

[0139] In operation 746 , the local cache memory 206 of the edge controller 102 is used to provide the encrypted content data to the client 108 , wherein the client decrypts the content data using the lock key shared by the key manager 412 of the origin server controller 306 during initial authentication.

[0140] Figure 8 An operational flow chart describing group sharing, content refresh, and security considerations in a CDN system provided for an embodiment of the present invention. Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Fig. 6A , Figure 6B and Figure 7 Component Description Figure 8 . refer to Figure 8, an operational flow chart 800 including operations 802 to 836 is shown.

[0141] In operation 802 , the CAM 210 of the edge controller 102 is used to receive a request for content data from the client 108 .

[0142] In operation 804 , the CAM 210 of the edge controller 102 is used to authenticate the client 108 .

[0143] In operation 806 , the CAM 210 of the edge controller 102 is used to check whether the content data is sensitive and is to be securely cached.

[0144] In operation 808 , in the case of sensitive content data, the content data is checked in the local cache memory 206 .

[0145] In operation 810, the content data is provided to the client 108, and the client 108 decrypts the content data using the PSK. Thereafter, the operational flow terminates.

[0146] Secure cacheable content is always encrypted when in transition or at rest in a CDN system (e.g., CDN system 302). The CDN edge does not have the keys required for decryption at any time, so even if the content data is accessed, such as by a rogue administrator, the content data cannot be exposed. Encryption is performed only by the origin server controller 306 using the PSK, which is a symmetric key used to lock and unlock content data. The PSK is provided to the client 108 during its initial authentication.

[0147] In operation 812, a PSK is created for each content instance and its lifetime is limited (e.g., a preconfigured 1 minute to 1 hour) so that an attacker who manages to steal the PSK from the client 108 will not be able to open other instances of the content data and has a limited time window for disclosing appropriate content stolen from the local cache memory 206.

[0148] In operation 814, if the time period of the PSK expires, the content data is deleted.

[0149] In operation 816 , the CAM 210 of the edge controller 102 is used to mark the GAK as obsolete.

[0150] In operation 818, the content protection engine 410 of the origin server controller 306 is operable to receive a request to refresh the PSK.

[0151] In operation 820 , the key manager 412 of the origin server controller 306 is operable to receive a request to refresh the PSK from the content protection engine 410 .

[0152] In operation 822, the content protection engine 410 of the origin server controller 306 is used to re-encrypt the content data using the refreshed PSK. Alternatively, the origin server controller 306 is used to perform content re-encryption using the refreshed PSK (or new key) and then redistribute the key as needed.

[0153] In operation 824, the content protection engine 410 of the origin server controller 306 is used to re-encrypt the uniform resource locator (URL) of the content data. After the URL of the content data is re-encrypted, the client 108 needs to perform a re-key request for each content request. In addition, the content data with the old URL will not be accessible for a predefined period of time (e.g., hours), and the content data will be automatically processed by the edge cache.

[0154] In operation 826 , the local cache memory 206 is used to update the page and content data.

[0155] In operation 828 , the CAM 210 of the edge controller 102 is used to authenticate the client 108 based on the GAK.

[0156] In operation 830 , the CAM 210 of the edge controller 102 is used to share the new PSK and GAK with the client 108 .

[0157] In operation 832 , business logic 402 of origin server controller 306 is used to reauthenticate client 108 .

[0158] In operation 834 , the business logic 402 of the source server controller 306 is used to share the new PSK and GAK (ie, the refreshed PSK and GAK) with the key manager 412 .

[0159] In operation 836, the key manager 412 of the source server controller 306 is used to share the new PSK and GAK with the client 108. Thereafter, the operational flow terminates.

[0160] Without departing from the scope of the invention as defined by the appended claims, the embodiments of the invention described above may be modified. Expressions such as "including", "comprising", "combining", "having", "being" used to describe and advocate the present invention should be considered to be interpreted in a non-exclusive manner, that is, allowing items, parts or elements that are not clearly described to appear. References to the singular should also be interpreted as being related to the plural. The word "exemplary" used herein means "as an example, instance or illustration". Any embodiment described as "exemplary" is not necessarily interpreted as taking precedence over or being superior to other embodiments and / or does not exclude the features of combining other embodiments. The word "optionally" used herein means "provided in some embodiments and not provided in other embodiments". It should be understood that certain features of the present invention described in the context of a single embodiment for the sake of clarity may also be provided in a single embodiment by combination. On the contrary, the various features of the present invention described in the context of a single embodiment for the sake of clarity may also be provided individually or by any suitable combination or as any other described embodiment of the present invention.

Claims

1. An edge controller (102), It is characterized in that The edge controller (102) is configured to operate in a CDN system (104) including one or more CDN components (106), wherein: receiving a request for content data from the client (108); Determine that the content data is sensitive and will be securely cached, and in response Determining that the client (108) is authenticated, and in response Providing the sensitive content data to the client (108), wherein the content data is provided in encrypted form based on a pre-shared key (PSK) generated by the origin server (110) and unknown to the one or more CDN components (106), wherein the edge controller (102) is further configured to: Receiving a Group Access Key (GAK) from the client (108) as part of the request for content data, wherein the GAK indicates an instance of the content data; providing the GAK to the source server (110) as part of the request for content data, wherein the edge controller (102) is characterized by being used to determine that the content data is sensitive and is to be securely cached based on an HTTP cache control attribute, wherein the HTTP cache control attribute indicates that the content data is sensitive and is to be securely cached.

2. The edge controller (102) according to claim 1, It is characterized in that The edge controller (102) is also used for: determining that the content data is not stored in a local cache memory (206), and in response requesting the content data from the origin server (110), wherein the content data is received in an encrypted form based on the PSK; The encrypted content data is stored in the local cache memory (206).

3. The edge controller (102) according to claim 2, It is characterized in that The edge controller (102) is further configured to determine that the age of the GAK exceeds a key threshold age, and in response delete the content data.

4. The edge controller (102) according to claim 3, It is characterized in that The edge controller (102) is further configured to update the content stored in the local cache memory (206).

5. The edge controller (102) according to claim 3 or 4, It is characterized in that The edge controller (102) is also used for: The client is reauthorized (108).

6. The edge controller (102) according to any one of the preceding claims, It is characterized in that The edge controller (102) is also used for: receiving a request for the sensitive content data from a second client (112); A determination is made that the client is not authorized, and in response an authorization process is initiated for the second client (112).

7. A method (500) for an edge controller (102), It is characterized in that The edge controller (102) is configured to operate in a CDN system (104) including one or more CDN components (106), and the method (500) includes: receiving a request for content data from the client (108); Determine that the content data is sensitive and will be securely cached, and in response Determining that the client (108) is authenticated, and in response The sensitive content data is provided to the client (108), wherein the content data is provided in an encrypted form based on a pre-shared key generated by the origin server (110) and unknown to one or more CDN components (106), wherein the method (500) is characterized by further comprising determining that the content data is sensitive and is to be securely cached based on an HTTP cache control attribute, wherein the HTTP cache control attribute indicates that the content data is sensitive and is to be securely cached.

8. A computer program product, It is characterized in that The method comprises program instructions for performing the method (500) according to claim 7 when the program instructions are executed by one or more processors in the CDN system (104).

9. An origin server controller (306), It is characterized in that The source server controller (306) is configured to be operated in a CDN system (302) including one or more CDN components (304), the source server controller (306) further configured to: Retrieve the Pre-Shared encryption Key (PSK); retrieving a Group Access Encryption Key (GAK), wherein the GAK is unknown to the one or more CDN components (304); receiving an authentication request from a client (108); Initiating an authentication process for the client (108); Determine that the authentication process is successful, and in response Providing the PSK and the GAK to the client (108); Receiving a request for content data from an edge controller (102) according to any one of the preceding claims; Determine that the content data of the request is sensitive, and in response determining an instance of the requested content data based on the GAK; Encrypting the content data using the PSK; The encrypted data is provided to the edge controller (102), the encrypted data indicating that the data is sensitive.

10. The source server controller (306) according to claim 9, It is characterized in that The source server controller (306) is also used to generate the encryption key for a group of users.

11. The source server controller (306) according to claim 9 or 10, It is characterized in that The origin server controller (306) is further configured to generate the encryption key for a type of content.

12. The origin server controller (306) according to any one of claims 9 to 11, It is characterized in that The origin server controller (306) is further configured to indicate that the data is sensitive by setting an HTTP cache control attribute.

13. The origin server controller (306) according to any one of claims 9 to 12, It is characterized in that The encryption key is known only to the origin server controller (306) and authenticated clients.

14. A method (600) for an origin server controller (306), It is characterized in that The origin server controller (306) is configured to operate in a CDN system (302) including one or more CDN components (304), and the method (600) includes: Retrieve the Pre-Shared encryption Key (PSK); retrieving a Group Access Encryption Key (GAK), wherein the GAK is unknown to the one or more CDN components (304); receiving an authentication request from a client (108); Initiating an authentication process for the client (108); Determine that the authentication process is successful, and in response Providing the GAK and the PSK to the client (108); receiving a request for content data from an edge controller (102); Determines that the requested data is sensitive, and in response determining an instance of the requested content data based on the GAK; Encrypting the content data using the PSK; The encrypted data is provided to the edge controller (102), the encrypted data indicating that the data is sensitive.

15. A computer program product, It is characterized in that The method comprises program instructions for performing the method (600) according to claim 14 when the program instructions are executed by one or more processors in the CDN system (302).