System for distributing content in a network federation, distribution method and computer program product therefor

DE602022017274T2Active Publication Date: 2025-07-09THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602022017274
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-12-30
Filing Date
2022-12-28
Publication Date
2025-07-09
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

Existing CDN solutions are not adaptable to military federated networks due to issues such as network instability, constrained bandwidth, high latency, specific configuration requirements, user mobility, and operational constraints, which are not addressed by conventional CDN systems designed for fixed infrastructure networks.

Method used

A system and method for dynamically optimizing content dissemination in a federated network using a Federated Mission Content Delivery (FMCD) module that manages CDN servers across multiple networks, considering user needs and operational constraints, and ensures secure and optimized routing and access paths.

Benefits of technology

The system effectively positions and routes content across a federated network, ensuring secure and efficient delivery while adhering to military-specific constraints like Red/Black network separation, interoperability, and fluctuating bandwidth, thereby optimizing network utilization and user access.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the dissemination of content in a federation of networks.

[0002] For civilian uses, we know the concept of content delivery network, or CDN. It is a set of servers in an infrastructure network, including an origin server and a set of mirror servers, which are located at different locations on the infrastructure network. A copy of the content placed on the origin server is transmitted to one or more mirror servers so that it is stored as close as possible to the actual users of this content. This is intended to limit flows on the infrastructure network and reduce the latency between the request for content by a user and its reception by this user.

[0003] A request for access to content, issued by a user, must be redirected to the mirror server on which this content is actually copied. This redirection is based on the request-routing mechanism implemented by a domain name server - DNS (Domain Name System) dedicated to the CDN network. The access request is transmitted to the DNS server, which returns the IP address of the mirror server where the content subject to the access request is stored.

[0004] Currently, CDN solutions, such as the one described in WO 2013 / 049079 A2, are designed to operate on fixed networks such as infrastructure networks, where issues of instability, constrained bandwidth, high latency, specific configuration, naming, user mobility and prioritization or preemption of flows do not exist.

[0005] Such a CDN solution is therefore not transposable to military uses where all or part of these problems are encountered.

[0006] Indeed, for military uses, the dissemination of content must satisfy a certain number of specific constraints, which derive from the fact that military networks are federated networks, whose capacities are reduced and whose topology evolves rapidly over time and the operational situation.

[0007] For example, a first constraint is to respect the separation of networks according to their level of security. This is NATO's concept of Red / Black networks.

[0008] A second constraint is to respect the interoperability requirements between federated networks, in particular the interoperability requirements specified in the NATO Federated Mission Networking (FMN) environment.

[0009] A third constraint is to take into account capacities (notably bandwidth) which fluctuate over time.

[0010] A fourth constraint is to take into account the operational situation.

[0011] Document US 2021 / 271565 A1 presents a system for managing the backup of data of an application.

[0012] The purpose of the present invention is to solve this problem of dissemination of content within the framework of a military federated network.

[0013] For this purpose, the invention relates to a system for disseminating content in a federation of networks, a method for disseminating content, and a computer program product according to the appended claims.

[0014] The invention and its advantages will be better understood upon reading the detailed description which follows of a particular embodiment, given solely as a non-limiting example, this description being made with reference to the appended drawings in which: [ Fig 1 ] [ Fig 2 ] There Figure 1 is a schematic representation of an embodiment of a network federation integrating a content dissemination system according to the invention; and, [Fig 3] The Figure 2 is a block representation of an embodiment of the content dissemination method according to the invention.

[0015] The present invention makes it possible to dynamically optimize not only the positioning of content on a network federation comprising a plurality of CDN servers, which constitute a CDN component of the network federation, but also the routing path of a copy of content from an origin server to a mirror server of the CDN component (and preferably the securing of this copying path and / or the prioritization of the flow during the transfer of the content from the origin server to the mirror server), as well as, advantageously, the access path allowing a user to access content copied in a mirror server (and preferably the securing of this access path to this content and / or the definition of access rules to this content by the user). General infrastructure

[0016] Referring to the Figure 1, an infrastructure 1 comprises a first network 100 on the one hand and second and third networks 200 and 300 on the other hand, intended to be federated through an underlying network 20.

[0017] The underlying network 20 is a wide area network (WAN). The underlying network 20 implements, for example, satellite links.

[0018] The first network 100 is preferably a reception network temporarily deployed behind the theater of operations. It comprises, for example: a first host network 120, which comprises a gateway, a PGW gateway 124, with the underlying network 20, and various equipment, bearing the general reference 126 on the Figure 1 ; a first private network constituting a data center or SDDC (“Softwaredefined data center”) 130, which is a secure network comprising a large number of virtual machines VM, five of which are represented on the Figure 1. They respectively bear the references 132a, 132b, 132c, 132c and 132e; a first firewall FW (“Firewall”) 140 constituting an interface between the first host network 120 and the first SDDC 130, on the one hand, and the underlying network 20, on the other hand.

[0019] The first network 100 further comprises an orchestration system 150 comprising a plurality of controllers and a service orchestrator 151 supervising the plurality of controllers.

[0020] The plurality of controllers comprises a second network controller 156, a security controller 152 and an information technology system (IT) controller 154. This distribution is carried out according to the three critical dimensions of a network configuration.

[0021] The network controller 156 controls the machines of the first host network 120 to configure them according to network commands received from the service orchestrator 151. This involves, for example, configuring the routing of a certain type of data flow of an identified user to ensure a certain bandwidth.

[0022] The information system controller - IT 154 controls the machines of the first SDDC 130 to configure them according to application commands received from the service orchestrator 151. This involves, for example, instantiating a particular application according to an identified user need, reserving a certain memory and computing resource of a VM of the first SDDC 130 for the execution of this application, possibly decommissioning this application when it is no longer used or when the operational situation requires it.

[0023] The security controller 152 controls the first firewall 140, to configure it according to security commands received from the service orchestrator 151. This involves, for example, filtering the circulation of data of an authenticated user according to his privileges, stored in a subscriber profile of this user.

[0024] More generally, the first service orchestrator 151 allows, through the controllers, the allocation of available physical and / or virtual resources of the first network 100 according to the needs of the users.

[0025] Physical resources include, for example, SDDC compute capacity, SDDC working memory capacity, network bandwidth capacity, firewall Network Address Translation (NAT) capacity, etc.

[0026] Virtual resources include, for example, virtualized bricks, each corresponding to an application enabling specific processing to be carried out on specific data, such as, for example, a deep packet inspection (DPI) application by the firewall, an image processing application by the SDDC, or a data flow compression application by the host network.

[0027] The second network 200 is preferably a local area network (LAN) constituting a border network or “tactical bubble”. It is embedded, for example, in a second armoured vehicle, the users of this network being infantrymen operating in a second zone of the theatre of operations. It comprises, for example: a second radio network 210, notably integrating a plurality of access points or eNB (“e-Node B” in 4G) 212. On the Figure 1two eNBs are represented and referenced 212a and 212b. An eNB allows a user equipment - UE, such as the UE 202 or the UE 203, to connect, by means of a radio link, to the second network 200; a second host network 220, or core network - EPC ("Evolved Packet Core"). Schematically, the second host network 220 comprises a gateway SGW221 with the second radio network 210, a gateway PGW 224 with the underlying network 20, and various equipment, such as an MME ("Mobility Management Entity") unit 226; a second SDDC network 230 which is a secure network comprising a small number of virtual machines VM, only one of which is represented on the Figure 1 . It is referenced by the number 232; a second firewall FW 240 constituting an interface between the second host network 220 and the second SDDC 230, on the one hand, and the underlying network 20, on the other hand.

[0028] The second network 200 further comprises a second orchestration system 250 comprising a plurality of controllers and a second service orchestrator 251 supervising the plurality of controllers.

[0029] The plurality of controllers includes a second network controller 256, a second security controller 252, and a second information system controller - IT 254.

[0030] The second orchestration system 250 is similar to the first orchestration system 150.

[0031] Similarly, the third network 300 is preferably a local area network (LAN) constituting a border network or “tactical bubble”. It is embedded, for example, in a second armored vehicle, the users of this local network being infantrymen operating in a second zone of the theater of operations. It comprises, for example: a third radio network 310, notably integrating a plurality of access points or eNB (“e-Node B” in 4G) 312. On the Figure 1 two eNBs are represented and referenced 312a and 312b. An eNB allows a user equipment - UE, such as the UE 302 by means of a radio link, to the third network 300; a third host network 320, or core network - EPC ("Evolved Packet Core"). Schematically, the third host network 320 comprises an SGW gateway 321 with the third radio network 310, a PGW gateway 324 with the underlying network 20, and various equipment, such as an MME ("Mobility Management Entity") unit 326; a third SDDC network 330 which is a secure network comprising a small number of virtual machines VM, only one of which is represented on the Figure 1. It is referenced by the number 332; a third firewall FW 340 constituting an interface between the third host network 320 and the third SDDC 230, on the one hand, and the underlying network 20, on the other hand.

[0032] The third network 200 further comprises a third orchestration system 350 comprising a third plurality of controllers and a third service orchestrator 351 supervising the third plurality of controllers.

[0033] The third plurality of controllers comprises a third network controller 356, a third security controller 352 and a third IT controller 354. This distribution is carried out according to the three critical dimensions of a network configuration.

[0034] The third orchestration system 350 is similar to the first and second orchestration systems 150 and 250.

[0035] In a federated network, one of the orchestration systems acts as the master and the other(s) as the slave. This is relevant to the operation of a federated network and is outside the scope of the present invention. In particular, how to choose the master orchestration system is outside the scope of this document.

[0036] The master orchestration system communicates with the slave orchestration systems to obtain information about the networks controlled by the latter and to request these slave orchestration systems to configure the networks that they control. Thus, the master orchestration system is able to determine the configuration that the network federation must adopt at each moment and is able to deploy this configuration in the network federation either directly or through the slave orchestration systems.

[0037] In the following, the presence of these slave orchestration systems is omitted to simplify the description and the focus is on the master orchestration system.

[0038] In the following, the orchestration system 150 acts as the master orchestration system. System according to the invention

[0039] The content dissemination system according to the invention comprises a plurality of CDN (“Content Delivery Network”) servers.

[0040] The plurality of CDN servers are federated network servers.

[0041] The plurality of CDN servers together constitute a federated CDN network.

[0042] CDN servers are, for example, VMs in the federated network.

[0043] For example on the Figure 1 , the federated CDN network comprises VMs 132a and 132d of the first network 100, VM 232 of the second network 200, and VM 332 of the third network 300.

[0044] Since this is an embodiment involving VMs, at a time when using the infrastructure 1, a VM can be configured to play the role of CDN server and integrate the federated CDN network, or on the contrary a VM can be deconditioned to stop playing the role of CDN server and leave the federated CDN network.

[0045] The content dissemination system according to the invention comprises, associated with each orchestration system, a control module or FMCD module (for Federated Mission Content Delivery module or module - "Federated Mission Content Delivery" in English) in the following.

[0046] For example, the FMCD module of an orchestration system is executed by the corresponding service orchestrator. Let, for the embodiment shown in the Figure 1, a first FMCD module 160 is executed by the first orchestration system 151, a second FMCD module 260 is executed by the second orchestration system 251, and a third FMCD module is executed by the third orchestration system 351.

[0047] It is the FMCD module associated with the master orchestration system that is running at the current time to manage the entire CDN service offered by the network federation.

[0048] In the configuration of the Figure 1 , the first orchestration system 150 is chosen as master, so it is the FMCD module 160 which is executed.

[0049] The FMCD 160 module communicates with other FMCD modules in the network federation to exchange information, such as subscription profiles.

[0050] The FMCD 160 module is capable of controlling the various CDN servers of infrastructure 1 while taking into account user needs and operational constraints.

[0051] The FMCD module is preferably standard so that the decision algorithms it executes are the same regardless of the networks actually federated. All messages and expectations required to implement the federated CDN network also conform to a standard format. This meets the interoperability requirement of the NATO FMN standard.

[0052] The FMCD module implements different algorithms, including a positioning algorithm and a decision algorithm.

[0053] Each algorithm can be executed at each occurrence of a particular event detected on the federated networks, i.e. a change in the value of an input variable of the FMCD module. This allows outputs to be calculated dynamically.

[0054] The FMCD module is capable of running an algorithm for positioning CDN servers across the network federation.

[0055] The positioning algorithm is, for example, based on a calculation of weights.

[0056] It leads to a deployment of the CDN service in the network federation in order to optimize the use of the network federation.

[0057] The FMCD 160 module is thus able to determine the VM(s) (and more generally any machine) eligible as CDN servers in order to define the federated CDN network at the current time. To do this, the FMCD 160 module takes into account, for example: the location of subscribers, the capacities of each VM (in terms of computing capacities - CPU, memory, etc.), and / or, the criticality of each VM depending on the operational situation (this being for example known to the master orchestration system by an entry of adapted information by an operator piloting the orchestration system ("Floor control").

[0058] The FMCD module is able to identify the best mirror CDN server for storing a particular content deposited on an origin CDN server of the federated CDN network. To do this, the FMCD 160 module takes into account, for example: resources available on the CDN servers of the federated CDN network (storage capacity, number of accesses, etc.) allowing content to be hosted, and / or, available network capacities allowing content to be routed from the original CDN server to a potential mirror CDN server, knowing that the master orchestration system has knowledge of all the flows associated with each of the security levels circulating on the network federation.

[0059] The FMCD module is able to identify an optimal route (or routing path) for the replication of content from the origin CDN server to a selected mirror CDN server. To do this, the FMCD 160 module takes into account, for example: operational risks that could degrade the routing service in order to guarantee the continuity of replication (such as available bandwidth on the links between the network federation equipment, availability of the network federation equipment, etc.), and / or security criteria (availability, integrity, confidentiality) in order to determine the safest route, limiting, for example, distributed denial of service attacks - DDoS.

[0060] In a particularly advantageous embodiment, the FMCD module is capable of cooperating with advanced FW 140, 240, 340 firewall modules, such as for example those conforming to the dynamic network identity allocation module - MADIR described in patent application FR 20 09408.

[0061] This is an access control module suitable for controlling user access to network resources. Such a module includes, for example, in addition to a firewall, a DNS Proxy, a DNS ("Domain Name System"), an authorization and authentication module - AAA, a control block, and a cyber defense network block of the NMCD type ("Network Management Cyber ​​Defense"), preferably compliant with the NATO FMN standard.

[0062] The FMCD 160 module then preferably has two interfaces with each of the firewall modules of the network federation: a first interface to provide the list of name resolutions of deployed CDN servers for a list of authorized users; a second interface to provide specific routes between a particular deployed CDN server and each relevant subscriber.

[0063] The FMCD module is then able to control each user's access to content.

[0064] This is achieved using MADIR. The FMCD module adds a list of per-user name resolutions to the MADIR module.

[0065] To do this, the FMCD 160 module takes into account, for example, a subscriber profile (signed subscription, access rights, prioritization, etc.) of each user in order to offer controlled access to each user.

[0066] The FMCD module is also able to identify a secure access route (or path) to access content hosted by a mirror CDN server for each user. Secure access routes differ from one user to another, for example, depending on the security level of the route, the type of information to be circulated along the route, the cost of using the route, etc.

[0067] This is achieved through MADIR. The FMCD module adds a list of routes per user to the MADIR module.

[0068] To do this, the FMCD 160 module takes into account, for example, the subscriber profile (signed subscription, access rights, prioritization, etc.) and the CDN server hosting the content, but also: available network capabilities allowing a user to access the mirror CDN server storing the content, knowing that the master orchestration system has knowledge of all the flows associated with each security level circulating on the network federation, and / or operational risks that could interrupt a user's access to the content stored in the CDN server.

[0069] An FMCD module, such as the module 160, therefore saves a subscriber profile for each user authorized to access content on the network federation. Advantageously, at a given time, an FMCD module only stores the profiles of users actually connected to the corresponding network. This is particularly true for edge networks. An FMCD module can request the necessary information from the FMCD module of the master orchestration system to update the user profiles that it stores. The master orchestration system can be backed by a BSS (“Business Support System”) system grouping together all the subscriber profiles of users authorized to connect to the network federation. Operating method

[0070] As illustrated on the Figure 2, the implementation of the method 400 makes it possible to provide a CDN service on the network federation resulting from the association of the first, second and third networks 100, 200 and 300.

[0071] The orchestration system 150 is for example chosen as the master orchestration system of the network federation.

[0072] At each time of execution of the method 400, different metrics relating to the network dimension, the IT dimension and the security dimension are available at the level of each local orchestration system 150, 250 and 350 of each network 100, 200 and 300. These metrics are repatriated to the master orchestration system, which consequently has a vision of the entire network federation.

[0073] Preferably, a pilot operator can provide input data describing the operational situation. Alternatively, sensors or devices deployed in the field can be used to define the current operational situation.

[0074] In step 401, the orchestration system 150 executes the positioning algorithm of the FMCD module 160 so as to determine the VM(s) (and more generally any machine) eligible as CDN servers in order to define the federated CDN network at the current time.

[0075] The defined CDN network groups together a set of VMs that can act as a CDN server at a given time. For example, it is composed of VMs 132a and 132d of the first network 100, VM 232 of the second network 200 and VM 332 of the third network 300.

[0076] The following steps of the method 400 correspond to the dissemination of content in the previously defined federated CDN network.

[0077] In a step 402, a content publisher deposits a content file on a CDN server, which therefore constitutes the origin CDN server. For example, the origin CDN server is the CDN server closest to the publisher's access point to the network federation. For example, the user of the UE 302 deposits content of the image type on the CDN server 332. The origin CDN server 332 informs the local orchestration system 350 on which it depends that new content has been deposited and the type of this content. This information is transmitted back to the master orchestration system 150.

[0078] In a third step 403, the FMCD module 160 of the orchestration system 150 identifies the CDN servers of the federated CDN network which constitute candidate mirror CDN servers for the content. A list of candidate mirror CDN servers is produced.

[0079] In a fourth step 404, the FMCD module 160 of the master orchestration system 150, based on the metrics and the list of candidate mirror CDN servers, determines a list of mirror CDN servers capable of receiving a copy of the content file. Advantageously, this determination is made based on the network's ability to route the content file from the original CDN server to a candidate mirror CDN server, for example by performing a pre-calculation of a route to each of the candidate mirror CDN servers.

[0080] An allocation is calculated against the various candidate mirror CDN servers and, for each candidate mirror CDN, the number of users subscribed to the nearest.

[0081] An allocation takes the form, for example, of a vector associated with the content that indicates whether or not a candidate mirror CDN server should be considered a mirror CDN server for that content.

[0082] The problem is called the "knapsac" problem. There are several known algorithms for solving this problem with optimal solutions. The weights are input values ​​to the problem, and the output is an allocation.

[0083] Weights that represent the state of each candidate mirror CDN server (disk, CPU for encoding the content file, and / or network load).

[0084] We also know whether a user is interested in the type of content that has just been posted, for example, from that user's subscriber profile.

[0085] At the end of step 404, the list of mirror CDN servers to which to send a copy of the content is determined.

[0086] The next 405 step is to optimize delivery paths for the content file from the original CDN server to each of the mirror CDN servers.

[0087] The FMCD module 160 of the master orchestration system 150 calculates the optimal paths between the original CDN server and the mirror CDN servers taking into account constraints of security, bandwidth, availability of the nodes of the network federation, etc.

[0088] The optimal path calculation can be achieved by implementing the procedure of patent application FR No. 20 13990.

[0089] Alternatively, it is possible to jointly optimize the mirror CDN servers and the associated routing paths, but this calculation is more complex.

[0090] At step 406, the master orchestration system 150 controls the various controllers to configure the network federation and prepare calculated routing paths for routing the content file from the original CDN server to the mirror CDN servers.

[0091] Then, in step 407, the master orchestration system 150 informs the origin CDN server to synchronize the content with the remote mirror CDN servers. The content is then routed to each of the mirror CDN servers using the routing paths configured for this purpose in the network federation.

[0092] The master orchestration system 150 also informs the network federation DNS servers to direct a user's request to the appropriate mirror CDN server.

[0093] Finally, step 408 corresponds to a user accessing content deposited on a mirror CDN server.

[0094] Advantageously, this access is done securely. For example, in step 406, the master orchestrator 150 controls one or more network devices (FW firewall type, or advanced firewall of the MADIR module type, etc.) to set up access rules per user.

[0095] Advantageously, again, in step 405, the FMCD module 160 calculates an access path for each user to the content deposited on a particular mirror CDN server. The output of this calculation can take the form of a vector comprising different attributes, such as for example: the IP address of the target mirror CDN server storing the content, the definition of several access paths through the network federation allowing access to the target mirror CDN server, each path being a function of a user subscriber profile. Then, in step 406, the master orchestrator 150 controls one or more network devices to configure the network federation and prepare the calculated access paths for routing the content file from the mirror CDN server to a user. Variants and Advantages

[0096] Alternatively, a user's subscriber profile includes a list of content types that interest that user. When new content is uploaded to the federated CDN network, the master orchestration server 150 is capable of sending a notification to each of the users whose subscriber profile indicates that they are interested in that content type. This notification includes, for example, a link pointing directly to the mirror CDN server suitable for that user.

[0097] Thus, the FMCD module 160 is executed to determine how to deploy the FMCD service on the network federation: positioning of the CDN servers, but also determination of the mirror servers for a type of content deposited on an origin server, determination of the routing paths of the contents from one CDN server to another, and, advantageously, definition of the rules for user access to a type of content on the mirror CDN servers and determination of the access paths for each type of content for each user.

[0098] Those skilled in the art will note that the present invention makes it possible to meet the constraints associated with military use of a CDN service on a federated network.

Claims

1. A system for disseminating content in a network federation, including: - a plurality of content servers (132a, 132d, 232, 332) distributed in the plurality of networks (100, 200, 300) making up the network federation, each content server defining a content storage space in one particular location of the network federation; - a master orchestration system (150) of the network federation, comprising a control module (160), the control module making it possible to optimize, based on a subscriber profile of a user seeking to access a particular content, the choice of a mirror content server of the plurality of content servers for the storage of a copy of a particular content deposited on an original content server of the plurality of content servers, as well as the choice of an optimal routing path on the network federation allowing the copy of the content to be transmitted from the original server to the mirror content server, as well as an access path allowing the user to access the copy of the particular content deposited on the chosen mirror server, the master orchestration system being adapted to inform the original content server to synchronize the particular content with the chosen mirror content server and to configure the network federation so that the routing of the copy of the particular content is performed along the chosen routing path, such that the user accesses the copy of the particular content deposited on the chosen mirror content server by connecting to the chosen mirror content server by the chosen access path.

2. The system according to claim 1, wherein the control module (160) is able to determine the network federation equipment eligible as content servers of the plurality of content servers.

3. The system according to claim 1 or claim 2, wherein the control module (160) optimizes the choice of a mirror content server based on the resources available on the content servers of the plurality of content servers for hosting the particular content, and / or the available network capabilities allowing the particular content to be routed from the original content server to a candidate mirror content server.

4. The system according to any one of claims 1 to 3, wherein the control module (160) optimizes the choice of the routing path based on security constraints associated with the particular content, available bandwidth on the links between the equipment items of the network federation, and / or availability of the equipment items of the network federation.

5. The system according to any one of claims 1 to 4, wherein the control module (160) determines access rules to content copied to the chosen mirror content server for each user based on a subscriber profile of each user.

6. The system according to any one of claims 1 to 5, wherein the control module (160) optimizes the choice of an access path to a content copied to the chosen mirror content server for each user based on a subscriber profile of each user.

7. A method (400) for disseminating content implemented in a network federation including a content dissemination system according to any one of the preceding claims, characterized in that it includes the steps of: - depositing a particular content on an original content server of the plurality of content servers; - optimizing the choice, by the master orchestration system, based on a subscriber profile of a user seeking to access the particular content, of a mirror content server among the plurality of content servers and a routing path of a copy of the particular content from the original content server to the chosen mirror content server, as well as an access path allowing the user to access the copy of the particular content deposited on the chosen mirror server; - informing, by the master orchestration system, the original content server to synchronize the particular content with the chosen mirror content server and configuring, by the master orchestration system, the network federation so that the routing of the copy of the particular content is carried out according to the chosen routing path; and - accessing, by the user, the copy of the particular content deposited on the chosen mirror content server by the chosen access path.

8. The method (400) according to claim 7, further comprising the steps of: - determining the equipment items of the network federation eligible as content servers of the plurality of content servers of the content dissemination system; and choosing a mirror content server from the plurality of content servers consists in: - identifying the content servers that make up candidate mirror content servers for the particular content; and - determining, among the candidate mirror content servers, the mirror content server able to receive a copy of the particular content.

9. The method according to claim 7 or claim 8, further including a step consisting in defining access rules to the copy of the particular content deposited on the chosen mirror content server for the user.

10. The method according to any one of claims 7 to 9, further including a step consisting in calculating an access path to the copy of the particular content deposited on the chosen mirror content server for the user.

11. A computer program product including software instructions which, when they are executed by a master orchestration system of a content dissemination system according to any one of claims 1 to 6, makes it possible to implement certain steps of a method for disseminating content according to any one of claims 7 to 10.