CDN Orchestration Scripts with Trusted Execution and Verifiable Logs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content delivery networks face challenges in ensuring efficient and secure content transmission, particularly during network peak times and when network stability is compromised, with trust issues in script execution and execution logs being unverifiable.
Innovation Solution
A method and apparatus for data transmission in a content delivery network that involves generating a target orchestration script at a client device, executing it in a trusted execution environment of edge devices, and logging the execution results, ensuring secure and transparent execution and logging processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If content transmission is performed through traditional CDN methods, then content delivery speed is improved, but transmission security and reliability deteriorate during network peak times
Solution Approach 1:
The system segments the CDN infrastructure into multiple isolated execution environments (containers) deployed across different edge devices. Each orchestration script executes in its own isolated container with dedicated resources, preventing resource contention and security breaches from affecting other scripts or the core CDN system. This segmentation maintains high delivery speed while improving reliability during peak times.
Solution Approach 2:
The patent introduces an intermediary trusted execution environment that acts as a mediator between the untrusted orchestration scripts and the CDN system. The TEE verifies script integrity, isolates execution, and protects sensitive data, enabling secure content delivery without compromising speed. The intermediary layer ensures transmission security while maintaining the efficiency of content delivery.
2Device complexity
If orchestration scripts are executed in untrusted environments, then device complexity is reduced, but execution reliability and security deteriorate
Solution Approach 1:
The system implements a nested structure where isolated execution environments (containers) are nested within the trusted execution environment, which itself is nested within the edge devices. This multi-layered nesting provides progressive security and isolation while keeping each layer's complexity manageable. The TEE handles security-critical functions, containers manage script execution isolation, and edge devices provide hardware support, distributing complexity appropriately.
Solution Approach 2:
The patent changes the trust parameter of the execution environment by transitioning from untrusted traditional CDN execution to trusted execution environments with hardware-based security. This parameter change enables the system to execute complex orchestration scripts with high reliability and security without proportionally increasing device complexity, as the TEE abstracts away the complexity of security management.
3Speed
If execution logs are stored in traditional CDN log databases, then data access speed is improved, but log authenticity and verification reliability deteriorate
Solution Approach 1:
The system performs preliminary actions by generating cryptographic hash values of execution logs at the source (edge devices) and storing them in the log database along with the actual logs. This preliminary hashing enables fast verification of log authenticity without requiring complex verification processes later. The hash storage adds minimal overhead while ensuring log authenticity, and clients can quickly verify logs using the pre-computed hashes.
Solution Approach 2:
The patent implements a feedback mechanism where the system provides cryptographic verification data (hash values, digital signatures) along with execution logs to clients. Clients can verify log authenticity by checking these cryptographic proofs against the original execution context. This feedback loop ensures log authenticity while maintaining fast access speeds, as the verification process uses efficient cryptographic operations rather than complex validation.
Data Source
AI summary
Embodiments of the disclosure provide methods, apparatuses, an electronic device, and a computer-readable medium for data transmission in a content delivery network. The method includes: generating a target orchestration script, where the target orchestration script includes an instruction to be executed by the content delivery network; transmitting the target orchestration script to a server of the content delivery network; and obtaining, from the server, a first log of the target orchestration script executed in a corresponding trusted execution environment of a plurality of edge devices in the content delivery network. In this way, a user can ensure the security of a content transmission process when using a content delivery network service.


