Encrypted CDN Caching Without Sharing Decryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for integrating middle boxes into secure communications between user terminals and content providers fail to reduce latency and maintain security for encrypted internet traffic, as transparent caching cannot be applied to encrypted content, and businesses are reluctant to share cryptographic keys with untrusted networks like CDNs.

Innovation Solution

A method where a terminal, server, and middle box communicate using encrypted content and identifiers or pseudo-identifiers, with the server providing decryption keys exclusively to the terminal, ensuring the middle box remains unaware of the decryption keys, allowing caching and delivery of encrypted content from a network closer to the user.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If transparent caching is used to replicate content inside operator networks, then bandwidth is saved and access delays are reduced, but encrypted content cannot be cached because the caching mechanism only works with unencrypted content

Engineering Contradiction:
Improveaccess delaysVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent creates encrypted copies of content at the middle box (CDN cache) that can be stored and retrieved without decryption. When a user requests content, the middle box serves the encrypted copy directly without needing to decrypt it, thus enabling caching of encrypted content while maintaining security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a middle box as an intermediary between the user terminal and the content provider server. This middle box holds the encrypted content copies and facilitates direct retrieval, acting as a mediator that enables caching functionality for encrypted content without requiring the terminal or server to share decryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If cryptographic keys are shared with CDNs to enable encrypted content caching, then latency is reduced through caching, but security is compromised because the CDN gains access to decryption keys

Engineering Contradiction:
ImprovelatencyVSAvoidsecurity risk
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

Instead of sharing decryption keys, the system creates and stores encrypted copies of content at the middle box. The terminal decrypts content locally using its own keys, while the middle box only handles encrypted data, eliminating the need for key sharing while enabling caching.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent separates the caching function from the decryption function. The middle box performs only caching of encrypted content, while the terminal performs decryption. This segmentation allows caching without key sharing, as the middle box never obtains decryption capabilities.

Inventive Principle:
Principle #1Segmentation

3Productivity

If businesses share customer data with untrusted networks like CDNs, then content delivery performance is improved, but confidentiality is compromised due to contractual, regulatory, or business considerations

Engineering Contradiction:
Improvecontent delivery performanceVSAvoidconfidentiality
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent enables creation of encrypted content copies at the middle box that remain confidential. Businesses can leverage CDN infrastructure for performance improvement while maintaining confidentiality, as the middle box only stores and retrieves encrypted data without access to the actual content or decryption keys.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The encrypted content resides in an 'inert environment' at the middle box where it cannot be accessed or interpreted. The middle box handles only encrypted data, creating a secure environment that allows performance improvement without compromising confidentiality, similar to storing sensitive materials in a sealed, inaccessible container.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS20250373425A1Caching encrypted content in an oblivious content distribution network, and system, compter-readable medium, and terminal for the same
Publication Date: 2025.12.04 VERIFIED IO LTD
  • US20250373425A1 patent drawing
  • US20250373425A1 patent drawing
  • US20250373425A1 patent drawing

AI summary

The disclosure describes methods and arrangements for caching encrypted content. Embodiments of the described inventions make use of a middle box to serve encrypted content rather than requiring a server to answer each request for content with a separate and distinct response, thereby allowing a network to operate effectively and efficiently even when serving encrypted content that looks different each time it is requested.