Content Delivery Address Validation Against Fraudulent Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing content delivery systems are vulnerable to fraudulent substitution of delivery servers due to insecure domain name resolution servers, leading to the delivery of unwanted or malicious content.

Innovation Solution

A method and device for validating the delivery server address received by the client terminal using information from the content provider's server to verify the authenticity of the delivery server, comparing the received address with an authentic address to ensure secure content delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If content delivery is delegated through domain name resolution servers, then delivery flexibility and scalability are improved, but security and reliability deteriorate due to vulnerable DNS servers and cache poisoning attacks

Engineering Contradiction:
Improvedelivery flexibilityVSAvoiddelivery security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary validation of the delivery server address by comparing it with an authentic address obtained from the content provider's server before the client terminal accepts the content. This preliminary check prevents fraudulent content delivery by verifying the address authenticity in advance, resolving the security issue while maintaining the delegated delivery structure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary verification mechanism where the client terminal acts as a mediator between the delivery server and content acceptance. The terminal validates the delivery server address against authentic information from the content provider, creating a security layer that doesn't interfere with the delegated delivery architecture but ensures reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple delegations are used in content delivery, then system scalability and load distribution are improved, but the complexity of verifying authentic delivery servers increases

Engineering Contradiction:
Improvesystem scalabilityVSAvoidverification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The client terminal performs self-service validation by autonomously comparing the received delivery server address with authentic information obtained from the content provider's server. This self-validation mechanism simplifies the overall verification process despite multiple delegations, as each terminal independently verifies authenticity without requiring complex centralized verification infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the verification parameter from complex multi-level delegation tracking to a simple address comparison parameter. By focusing validation on comparing the received address with authentic address information from the content provider, the system maintains scalability through multiple delegations while reducing verification complexity to a straightforward parameter check.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If domain name resolution servers are used for address translation, then ease of content access is improved, but vulnerability to cache poisoning and fraudulent substitution increases

Engineering Contradiction:
Improvecontent access easeVSAvoidfraudulent substitution risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by preemptively validating the delivery server address against authentic information from the content provider before the client terminal accesses content. This counteracts the fraudulent substitution risk introduced by vulnerable domain name resolution servers, allowing easy access through DNS while neutralizing the security threat through prior validation.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The invention implements a feedback mechanism where the client terminal receives authentic delivery server address information from the content provider's server and uses this feedback to validate the address obtained through domain name resolution. This feedback loop ensures that even if DNS servers are compromised, the client can detect and reject fraudulent addresses, maintaining both ease of access and security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3560163B1Validation of content delivery and verification of a delegation of delivery of a content
Publication Date: 2025.07.30 ORANGE SA
  • EP3560163B1 patent drawingFigure 1~4
  • EP3560163B1 patent drawingFigure 2a
  • EP3560163B1 patent drawingFigure 2b

AI summary

The invention relates to methods for validating delivery of content and verifying a delegation of delivery of a content, and corresponding devices and computer program products. A method is proposed for validating a delivery of a content to a client terminal (UA). Such a method comprises a step (S210b) of receiving, by the client terminal (UA), an address, referred to as the received address, in response to a request (S210a) sent to an address server (LDNS, DNS) in order to obtain an address of a delivery server (uCDN) of said content, the request comprising a piece of information relating to said delivery server. Such a method further comprises receiving (S2302b), by the client terminal (UA), a piece of information relating to an authentic address associated with the delivery server, the information being sent by a server (CSP) of the content supplier, and determining (S230) the validity of the received address with respect to the authentic address on the basis of the information relating to the authentic address.