Certificate Checkin Service for Cloud Content Entitlement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack synchronization of authorization, authentication, and entitlement data between content providers and cloud providers, leading to improper entitlement and usage tracking of content within cloud networks, which hampers compliance with licensing agreements.

Innovation Solution

A network of certificate checkin services (CCSs) is deployed across the cloud provider network to synchronize entitlement and usage data, enabling proper authorization and tracking of content consumption, with CCSs communicating through a parent-child hierarchy to ensure data exchange between cloud segments and the content provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional systems are used without synchronization mechanisms, then system simplicity is maintained, but authorization and entitlement data become desynchronized between content providers and cloud providers, leading to compliance issues

Engineering Contradiction:
Improveauthorization data synchronizationVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A synchronization service is introduced as an intermediary component that receives authorization data from content providers and distributes it to cloud providers. This mediator handles the complexity of data synchronization, ensuring reliable entitlement data distribution without requiring direct complex integrations between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is divided into distinct functional components: content providers, cloud providers, and synchronization services. Each entity operates independently with well-defined interfaces, allowing the synchronization mechanism to be implemented as a separate modular service that can be maintained and updated without affecting the core operations of content or cloud providers.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If manual tracking of content usage is implemented, then basic entitlement verification is possible, but accurate real-time tracking and reporting of usage data across cloud networks cannot be achieved

Engineering Contradiction:
Improveusage data tracking accuracyVSAvoidcontent delivery efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The synchronization service implements a feedback mechanism where usage data is collected from cloud providers and automatically reported back to content providers. This closed-loop system ensures accurate tracking of content consumption while maintaining real-time visibility into entitlement compliance, eliminating the need for manual tracking processes.

Inventive Principle:
Principle #23Feedback

3Stability of the object's composition

If a centralized synchronization system is deployed, then data consistency is improved, but system vulnerability to single points of failure increases

Engineering Contradiction:
Improvedata consistencyVSAvoidsystem availability
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The synchronization service is deployed as a distributed system across multiple servers and data centers rather than a single centralized instance. This segmentation allows the system to maintain data consistency through replication while providing fault tolerance - if one synchronization node fails, other nodes continue to operate and maintain service availability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9338160B2Certificate checkin service
Publication Date: 2016.05.10 RED HAT INC
  • US9338160B2 patent drawing
  • US9338160B2 patent drawing
  • US9338160B2 patent drawing

AI summary

A method and system for a content provider to enable the consumption of content by properly entitled consumers (e.g., end-users, clients, customers) within a cloud provider network. A first certificate checkin service (CCS) executed by a processing device deployed in the cloud provider network receives a first set of usage data relating to content of a content provider consumed by a client of the cloud provider network. The first CCS provides the usage data to a communicatively coupled parent CCS. The first CCS provides the parent CCS with a request for entitlement data relating to the cloud provider, and stores the entitlement data received from the parent CCS. The entitlement data may be used by the first CCS to determine if the client is entitled to consume the content.