Content Delivery Address Validation Against Fraudulent Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing content delivery systems are vulnerable to fraudulent substitution of delivery servers due to insecure domain name resolution servers, leading to the delivery of unwanted or malicious content.
Innovation Solution
A method and device for validating the delivery server address received by the client terminal using information from the content provider's server to verify the authenticity of the delivery server, comparing the received address with an authentic address to ensure secure content delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If content delivery is delegated through domain name resolution servers, then delivery flexibility and scalability are improved, but security and reliability deteriorate due to vulnerable DNS servers and cache poisoning attacks
Solution Approach 1:
The system performs preliminary validation of the delivery server address by comparing it with an authentic address obtained from the content provider's server before the client terminal accepts the content. This preliminary check prevents fraudulent content delivery by verifying the address authenticity in advance, resolving the security issue while maintaining the delegated delivery structure.
Solution Approach 2:
The invention introduces an intermediary verification mechanism where the client terminal acts as a mediator between the delivery server and content acceptance. The terminal validates the delivery server address against authentic information from the content provider, creating a security layer that doesn't interfere with the delegated delivery architecture but ensures reliability.
2Productivity
If multiple delegations are used in content delivery, then system scalability and load distribution are improved, but the complexity of verifying authentic delivery servers increases
Solution Approach 1:
The client terminal performs self-service validation by autonomously comparing the received delivery server address with authentic information obtained from the content provider's server. This self-validation mechanism simplifies the overall verification process despite multiple delegations, as each terminal independently verifies authenticity without requiring complex centralized verification infrastructure.
Solution Approach 2:
The system changes the verification parameter from complex multi-level delegation tracking to a simple address comparison parameter. By focusing validation on comparing the received address with authentic address information from the content provider, the system maintains scalability through multiple delegations while reducing verification complexity to a straightforward parameter check.
3Ease of operation
If domain name resolution servers are used for address translation, then ease of content access is improved, but vulnerability to cache poisoning and fraudulent substitution increases
Solution Approach 1:
The system applies preliminary anti-action by preemptively validating the delivery server address against authentic information from the content provider before the client terminal accesses content. This counteracts the fraudulent substitution risk introduced by vulnerable domain name resolution servers, allowing easy access through DNS while neutralizing the security threat through prior validation.
Solution Approach 2:
The invention implements a feedback mechanism where the client terminal receives authentic delivery server address information from the content provider's server and uses this feedback to validate the address obtained through domain name resolution. This feedback loop ensures that even if DNS servers are compromised, the client can detect and reject fraudulent addresses, maintaining both ease of access and security.
Data Source
Figure 1~4
Figure 2a
Figure 2b
AI summary
The invention relates to methods for validating delivery of content and verifying a delegation of delivery of a content, and corresponding devices and computer program products. A method is proposed for validating a delivery of a content to a client terminal (UA). Such a method comprises a step (S210b) of receiving, by the client terminal (UA), an address, referred to as the received address, in response to a request (S210a) sent to an address server (LDNS, DNS) in order to obtain an address of a delivery server (uCDN) of said content, the request comprising a piece of information relating to said delivery server. Such a method further comprises receiving (S2302b), by the client terminal (UA), a piece of information relating to an authentic address associated with the delivery server, the information being sent by a server (CSP) of the content supplier, and determining (S230) the validity of the received address with respect to the authentic address on the basis of the information relating to the authentic address.