CDN Access Control via Cryptographic URL Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content delivery networks (CDNs) lack fine-grained access control over individual content items, forcing content providers to either overload their origin servers or duplicate content, which is inefficient in terms of storage and development.

Innovation Solution

Content items are distributed from an origin server to a CDN using identifiers that express relationships between items and associated content elements, with credentials provided to the browser for authentication, allowing the CDN to verify user access through cryptographically secure uniform resource locators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If content providers use CDN resources to deliver content, then content delivery speed and user experience improve, but fine-grained access control over individual content items deteriorates

Engineering Contradiction:
Improvecontent delivery speedVSAvoidfine-grained access control
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The patent segments access control from the content element level to the individual content item level. Each content item within a content element can now have its own access credentials and permissions, allowing the CDN to deliver content efficiently while maintaining granular control over what specific items users can access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces credentials as an intermediary mechanism that bridges the CDN's content delivery capability with fine-grained access control requirements. These credentials associate specific user identifiers with permitted content items, enabling the CDN to verify and enforce access permissions without sacrificing delivery performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If content providers maintain fine-grained access control at origin servers, then access security improves, but server load and processing requirements worsen

Engineering Contradiction:
Improveaccess securityVSAvoidserver load
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts the access control verification function from the origin server and relocates it to the CDN edge servers. By pre-configuring credentials and associations between user identifiers and content items at the origin, the heavy lifting of access verification is performed at the CDN, significantly reducing the load on origin servers while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary action by pre-establishing credential associations between user identifiers and permitted content items before content delivery requests occur. This preconfiguration allows CDN servers to perform rapid credential verification without requiring real-time communication with origin servers, thereby reducing server load while maintaining access security.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If content providers duplicate content items for different access control scenarios, then access control flexibility improves, but storage efficiency and development complexity worsen

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidstorage efficiency
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements universality by creating a single content item that can serve multiple access control scenarios through the credential mechanism. Instead of duplicating content for different permission sets, the same content item can be accessed by different users or systems with appropriate credentials that define their specific access rights, thereby improving storage efficiency while maintaining access control flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9317677B1Access control for content delivery networks
Publication Date: 2016.04.19 INKLING SYST
  • US9317677B1 patent drawing
  • US9317677B1 patent drawing
  • US9317677B1 patent drawing

AI summary

Content items are distributed to a content delivery network using identifiers that expresses relationships between the content items and at least one associated content element. When making requests to content delivery network, a requesting Web browser may thus specify the content items according to uniform resource locators that include credentials that allow the content delivery network to verify that the browser is authorized to receive the content items. These uniform resource locators may uniquely associate the content items with the associated content element and the requesting browser in a cryptographically secure manner.