EdgeLocker Secure Content Caching via Pre-positioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In content delivery networks (CDNs), customers are hesitant to share their private TLS keys with service providers and require secure data transmission without decryption, ensuring data authenticity and confidentiality.

Innovation Solution

Implementing an EdgeLocker in the edge network that caches only encrypted content objects, leveraging bulk encryption from the TLS layer without managing encryption keys, and using a multi-layered edge network architecture to maintain secure content delivery and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted content is cached in the edge network, then data confidentiality is improved, but content delivery performance deteriorates due to encryption overhead

Engineering Contradiction:
Improvedata confidentialityVSAvoidcontent delivery performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent pre-positions encrypted content objects in the edge network before customer requests arrive. This preliminary caching of encrypted content eliminates the need for real-time decryption and re-encryption operations, thereby maintaining data confidentiality while improving content delivery performance by reducing encryption overhead during actual content retrieval

Inventive Principle:
Principle #10Preliminary action

2Speed

If TLS termination is performed at the CDN edge, then content delivery speed is improved, but key security deteriorates due to private key exposure

Engineering Contradiction:
Improvecontent delivery speedVSAvoidkey security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent extracts the private key management function from the CDN edge infrastructure. By using customer-provided encryption keys that are never stored or managed by the CDN service provider, the system enables TLS termination at the edge for improved content delivery speed while simultaneously protecting key security by eliminating private key exposure risks in the CDN environment

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If secure content caching is implemented without key management, then data authenticity is improved, but device complexity increases due to multi-layered architecture

Engineering Contradiction:
Improvedata authenticityVSAvoidedge network architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal encryption approach where a single encryption key management mechanism serves multiple security functions simultaneously. The customer-provided encryption keys enable the system to achieve both data confidentiality and data authenticity without requiring separate key management systems, thereby reducing overall device complexity despite the multi-layered edge network architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11671413B2Caching content securely within an edge environment, with pre-positioning
Publication Date: 2023.06.06 AKAMAI TECHNOLOGIES INC
  • US11671413B2 patent drawing
  • US11671413B2 patent drawing
  • US11671413B2 patent drawing

AI summary

A technique to cache content securely within edge network environments, even within portions of that network that might be considered less secure than what a customer desires, while still providing the acceleration and off-loading benefits of the edge network. The approach ensures that customer confidential data (whether content, keys, etc.) are not exposed either in transit or at rest. In this approach, only encrypted copies of the customer's content objects are maintained within the portion of the edge network, but without any need to manage the encryption keys. To take full advantage of the secure content caching technique, preferably the encrypted content (or portions thereof) are pre-positioned within the edge network portion to improve performance of secure content delivery from the environment.