Secondary CDN Delegation Proof for Encrypted Content Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In content distribution networks, the continuity of security is interrupted when a cache server delegates content delivery to a secondary server that lacks the necessary cryptographic material, preventing an encrypted connection from being established between the client terminal and the secondary server.

Innovation Solution

A method of requesting proof of delegation is implemented, where the secondary delivery server obtains the cryptographic material by sending a signature to the content server, which responds with an encryption key, allowing the establishment of an encrypted connection perceived as being with the original content server, and includes a challenge file to test the secondary server's delivery capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a cache server delegates content delivery to a secondary server, then content delivery flexibility and scalability are improved, but security continuity is interrupted because the secondary server lacks cryptographic material

Engineering Contradiction:
Improvecontent delivery flexibilityVSAvoidsecurity continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a delegation proof mechanism as an intermediary that bridges the content server and secondary delivery server. The content server issues a delegation proof to the secondary server, which contains cryptographic material that enables the secondary server to establish encrypted connections with clients. This intermediary mechanism allows security continuity without requiring a direct relationship between the content server and secondary server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the cryptographic material into different components: the delegation proof (issued by content server to secondary server) and the encryption key (used by secondary server with client). This segmentation allows the secondary server to obtain necessary cryptographic credentials without having direct access to all cryptographic material, maintaining security while enabling delegated delivery.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a secondary delivery server establishes an encrypted connection with the client terminal, then security is maintained, but the client terminal cannot verify the server's identity as being from the original content server's domain

Engineering Contradiction:
Improveencryption securityVSAvoidserver identity verification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a copying mechanism where the secondary server obtains a delegation proof that contains cryptographic material copied from the content server's credentials. The secondary server uses this copied cryptographic material to establish encrypted connections, and the connection appears to the client as if it were established with a server from the original domain, maintaining identity verification while enabling delegated delivery.

Inventive Principle:
Principle #26Copying

3Manufacturing precision

If the content server verifies the secondary server's delivery capabilities through challenge files, then delivery quality is ensured, but additional communication steps and time are required

Engineering Contradiction:
Improvedelivery capability verificationVSAvoidverification time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the content server issue a delegation proof to the secondary server before actual content delivery begins. The delegation proof process includes capability verification through challenge files, but this verification happens in advance, allowing the secondary server to be pre-approved and ready for immediate content delivery without repeated verification delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3568966B1Methods and devices for delegation of distribution of encrypted content
Publication Date: 2022.11.23 ORANGE SA
  • EP3568966B1 patent drawingFigure 1~4
  • EP3568966B1 patent drawingFigure 2

AI summary

The invention relates to a method for requesting proof of delegation for the delivery of content to a client terminal (UA) via an encrypted connection, the content being referenced on a server (CSP) called a content server, to which the client terminal has emitted a request (E01) to obtain the content, the content server having delegated the delivery of said content to a server called a primary delivery server (uCDN), the method being implemented by a delivery server called a secondary delivery server (dCDN), to which the primary delivery server has delegated the delivery of said content, said method comprising the following steps: reception (G01) of a request to establish an encrypted connection, from the client terminal, comprising an identifier of the content server; emission (G03) of a request for proof of delegation of delivery, addressed to the content server; reception (G06) of a message from the content server, comprising an encryption key; emission (G07) of a response for establishing an encrypted connection, addressed to the client terminal; establishing (G09) the encrypted connection with the client terminal by means of the encryption key.