CDN Orchestration Scripts with Trusted Execution and Verifiable Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content delivery networks face challenges in ensuring efficient and secure content transmission, particularly during network peak times and when network stability is compromised, with trust issues in script execution and execution logs being unverifiable.

Innovation Solution

A method and apparatus for data transmission in a content delivery network that involves generating a target orchestration script at a client device, executing it in a trusted execution environment of edge devices, and logging the execution results, ensuring secure and transparent execution and logging processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If content transmission is performed through traditional CDN methods, then content delivery speed is improved, but transmission security and reliability deteriorate during network peak times

Engineering Contradiction:
Improvecontent delivery speedVSAvoidtransmission security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments the CDN infrastructure into multiple isolated execution environments (containers) deployed across different edge devices. Each orchestration script executes in its own isolated container with dedicated resources, preventing resource contention and security breaches from affecting other scripts or the core CDN system. This segmentation maintains high delivery speed while improving reliability during peak times.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary trusted execution environment that acts as a mediator between the untrusted orchestration scripts and the CDN system. The TEE verifies script integrity, isolates execution, and protects sensitive data, enabling secure content delivery without compromising speed. The intermediary layer ensures transmission security while maintaining the efficiency of content delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If orchestration scripts are executed in untrusted environments, then device complexity is reduced, but execution reliability and security deteriorate

Engineering Contradiction:
Improveexecution environment complexityVSAvoidexecution reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system implements a nested structure where isolated execution environments (containers) are nested within the trusted execution environment, which itself is nested within the edge devices. This multi-layered nesting provides progressive security and isolation while keeping each layer's complexity manageable. The TEE handles security-critical functions, containers manage script execution isolation, and edge devices provide hardware support, distributing complexity appropriately.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent changes the trust parameter of the execution environment by transitioning from untrusted traditional CDN execution to trusted execution environments with hardware-based security. This parameter change enables the system to execute complex orchestration scripts with high reliability and security without proportionally increasing device complexity, as the TEE abstracts away the complexity of security management.

Inventive Principle:
Principle #35Parameter changes

3Speed

If execution logs are stored in traditional CDN log databases, then data access speed is improved, but log authenticity and verification reliability deteriorate

Engineering Contradiction:
Improvedata access speedVSAvoidlog authenticity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary actions by generating cryptographic hash values of execution logs at the source (edge devices) and storing them in the log database along with the actual logs. This preliminary hashing enables fast verification of log authenticity without requiring complex verification processes later. The hash storage adds minimal overhead while ensuring log authenticity, and clients can quickly verify logs using the pre-computed hashes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the system provides cryptographic verification data (hash values, digital signatures) along with execution logs to clients. Clients can verify log authenticity by checking these cryptographic proofs against the original execution context. This feedback loop ensures log authenticity while maintaining fast access speeds, as the verification process uses efficient cryptographic operations rather than complex validation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250298885A1Method, apparatus, device and medium for data transmission in content delivery network
Publication Date: 2025.09.25 BEIJING VOLCANO ENGINE TECH CO LTD
  • US20250298885A1 patent drawing
  • US20250298885A1 patent drawing
  • US20250298885A1 patent drawing

AI summary

Embodiments of the disclosure provide methods, apparatuses, an electronic device, and a computer-readable medium for data transmission in a content delivery network. The method includes: generating a target orchestration script, where the target orchestration script includes an instruction to be executed by the content delivery network; transmitting the target orchestration script to a server of the content delivery network; and obtaining, from the server, a first log of the target orchestration script executed in a corresponding trusted execution environment of a plurality of edge devices in the content delivery network. In this way, a user can ensure the security of a content transmission process when using a content delivery network service.