EdgeLocker Secure Content Caching via Pre-positioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In content delivery networks (CDNs), customers are hesitant to share their private TLS keys with service providers and require secure data transmission without decryption, ensuring data authenticity and confidentiality.
Innovation Solution
Implementing an EdgeLocker in the edge network that caches only encrypted content objects, leveraging bulk encryption from the TLS layer without managing encryption keys, and using a multi-layered edge network architecture to maintain secure content delivery and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted content is cached in the edge network, then data confidentiality is improved, but content delivery performance deteriorates due to encryption overhead
Solution Approach 1:
The patent pre-positions encrypted content objects in the edge network before customer requests arrive. This preliminary caching of encrypted content eliminates the need for real-time decryption and re-encryption operations, thereby maintaining data confidentiality while improving content delivery performance by reducing encryption overhead during actual content retrieval
2Speed
If TLS termination is performed at the CDN edge, then content delivery speed is improved, but key security deteriorates due to private key exposure
Solution Approach 1:
The patent extracts the private key management function from the CDN edge infrastructure. By using customer-provided encryption keys that are never stored or managed by the CDN service provider, the system enables TLS termination at the edge for improved content delivery speed while simultaneously protecting key security by eliminating private key exposure risks in the CDN environment
3Reliability
If secure content caching is implemented without key management, then data authenticity is improved, but device complexity increases due to multi-layered architecture
Solution Approach 1:
The patent implements a universal encryption approach where a single encryption key management mechanism serves multiple security functions simultaneously. The customer-provided encryption keys enable the system to achieve both data confidentiality and data authenticity without requiring separate key management systems, thereby reducing overall device complexity despite the multi-layered edge network architecture
Data Source
AI summary
A technique to cache content securely within edge network environments, even within portions of that network that might be considered less secure than what a customer desires, while still providing the acceleration and off-loading benefits of the edge network. The approach ensures that customer confidential data (whether content, keys, etc.) are not exposed either in transit or at rest. In this approach, only encrypted copies of the customer's content objects are maintained within the portion of the edge network, but without any need to manage the encryption keys. To take full advantage of the secure content caching technique, preferably the encrypted content (or portions thereof) are pre-positioned within the edge network portion to improve performance of secure content delivery from the environment.


