Encrypted CDN Caching Without Sharing Decryption Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for integrating middle boxes into secure communications between user terminals and content providers fail to reduce latency and maintain security for encrypted internet traffic, as transparent caching cannot be applied to encrypted content, and businesses are reluctant to share cryptographic keys with untrusted networks like CDNs.
Innovation Solution
A method where a terminal, server, and middle box communicate using encrypted content and identifiers or pseudo-identifiers, with the server providing decryption keys exclusively to the terminal, ensuring the middle box remains unaware of the decryption keys, allowing caching and delivery of encrypted content from a network closer to the user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If transparent caching is used to replicate content inside operator networks, then bandwidth is saved and access delays are reduced, but encrypted content cannot be cached because the caching mechanism only works with unencrypted content
Solution Approach 1:
The patent creates encrypted copies of content at the middle box (CDN cache) that can be stored and retrieved without decryption. When a user requests content, the middle box serves the encrypted copy directly without needing to decrypt it, thus enabling caching of encrypted content while maintaining security.
Solution Approach 2:
The patent introduces a middle box as an intermediary between the user terminal and the content provider server. This middle box holds the encrypted content copies and facilitates direct retrieval, acting as a mediator that enables caching functionality for encrypted content without requiring the terminal or server to share decryption keys.
2Loss of time
If cryptographic keys are shared with CDNs to enable encrypted content caching, then latency is reduced through caching, but security is compromised because the CDN gains access to decryption keys
Solution Approach 1:
Instead of sharing decryption keys, the system creates and stores encrypted copies of content at the middle box. The terminal decrypts content locally using its own keys, while the middle box only handles encrypted data, eliminating the need for key sharing while enabling caching.
Solution Approach 2:
The patent separates the caching function from the decryption function. The middle box performs only caching of encrypted content, while the terminal performs decryption. This segmentation allows caching without key sharing, as the middle box never obtains decryption capabilities.
3Productivity
If businesses share customer data with untrusted networks like CDNs, then content delivery performance is improved, but confidentiality is compromised due to contractual, regulatory, or business considerations
Solution Approach 1:
The patent enables creation of encrypted content copies at the middle box that remain confidential. Businesses can leverage CDN infrastructure for performance improvement while maintaining confidentiality, as the middle box only stores and retrieves encrypted data without access to the actual content or decryption keys.
Solution Approach 2:
The encrypted content resides in an 'inert environment' at the middle box where it cannot be accessed or interpreted. The middle box handles only encrypted data, creating a secure environment that allows performance improvement without compromising confidentiality, similar to storing sensitive materials in a sealed, inaccessible container.
Data Source
AI summary
The disclosure describes methods and arrangements for caching encrypted content. Embodiments of the described inventions make use of a middle box to serve encrypted content rather than requiring a server to answer each request for content with a separate and distinct response, thereby allowing a network to operate effectively and efficiently even when serving encrypted content that looks different each time it is requested.


