CDN Center Node Automatic HTTPS Certificate Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying HTTPS security acceleration functions in a content delivery network (CDN) is hindered by the complexity of obtaining certificates from Certificate Authorities, leading to delays in communication security implementation.

Innovation Solution

A center node in the CDN automatically generates and deploys digital certificates for service domain names, allowing for flexible configuration of certificate providing modes and back-to-source modes, enabling efficient deployment of HTTPS security acceleration without relying on user-provided certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user applies for a certificate from a Certificate Authority to deploy HTTPS security acceleration, then communication security is ensured, but the deployment process becomes complex and time-consuming

Engineering Contradiction:
Improvecommunication securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The CDN system performs self-service by automatically generating and deploying digital certificates for domain names without requiring users to manually apply for certificates from Certificate Authorities. The center node automatically generates certificates and configures them on edge nodes, eliminating the complex manual deployment process while ensuring communication security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-generating and pre-configuring digital certificates before the user needs to access the domain name. The center node automatically creates certificates and pushes them to edge nodes in advance, so that when a user accesses the domain, the HTTPS security acceleration is already in place without requiring manual certificate acquisition and configuration.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the user manually applies for and configures certificates in the CDN, then HTTPS security acceleration can be deployed, but the deployment time is delayed

Engineering Contradiction:
Improvecommunication securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The center node performs preliminary actions by automatically generating and configuring digital certificates before the user needs to access the domain name. The system pre-processes certificate generation and deployment, eliminating delays associated with manual certificate application and configuration processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The CDN system performs self-service by autonomously generating and deploying certificates without requiring user intervention. This automatic self-service approach eliminates the time losses associated with manual certificate application, verification, and configuration processes.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the CDN automatically generates and deploys certificates, then deployment time is reduced and ease of operation is improved, but the system complexity increases

Engineering Contradiction:
Improvedeployment easeVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The center node performs self-service by automatically generating and deploying digital certificates without requiring user intervention. This self-service mechanism simplifies the deployment process for users while the underlying system handles the complex certificate generation and configuration operations autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The center node acts as an intermediary between the user and the certificate authority functions. It absorbs the complexity of certificate generation and deployment operations, presenting a simple interface to users while handling the intricate system-level tasks behind the scenes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10873451B2Content delivery network processing method, content delivery network, device, and storage medium
Publication Date: 2020.12.22 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US10873451B2 patent drawing
  • US10873451B2 patent drawing
  • US10873451B2 patent drawing

AI summary

Content delivery systems and methods are provided. A center node may determine a service domain name to be processed. The center node may obtain configuration parameters corresponding to the service domain name. The center node may generate configuration items based on the obtained configuration parameters. The configuration items may cause a plurality of edge nodes to deploy Hypertext Transfer Protocol Secure (HTTPS) security acceleration for the service domain name. The center node may send, to the edge nodes in the CDN, the configuration items that are based on the corresponding configuration parameters. The configuration item may include comprise a digital certificate providing mode and a back-to-source mode of an origin site. A first configuration parameter may correspond to the digital certificate providing and a second configuration parameter may correspond to a back-to-source mode of the origin site.