HTTP Streaming Security Framework via Client Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content delivery networks face challenges in securely delivering high-definition video content to a broad audience across various runtime environments and mobile devices, while preventing unauthorized access, due to the complexity and cost of maintaining dedicated platforms and the need for compatibility with traditional broadcast TV standards.

Innovation Solution

A method and system for authenticating client devices through a program executed by the client, which inspects and encodes client information into a token using a hash algorithm, allowing authorized access to streaming content while preventing unauthorized access by comparing the token with a known client identifier or list of recognized clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dedicated platforms are used to support delivery of content for multiple third party runtime environments, then content delivery capability is improved, but device complexity and implementation cost increase

Engineering Contradiction:
Improvecontent delivery capabilityVSAvoidplatform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal content delivery platform that can deliver content to multiple runtime environments (Flash, Silverlight, iPhone, etc.) through a single HTTP-based architecture. The system uses a common authentication mechanism and content delivery infrastructure that adapts to different client types without requiring separate dedicated platforms for each runtime environment, thereby achieving multi-functionality while reducing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication mechanisms are implemented to prevent unauthorized access, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements authentication by changing parameters within the existing HTTP protocol framework rather than introducing a completely new authentication system. The mechanism uses HTTP headers and query parameters to传递 authentication tokens, and the authentication logic is integrated into the existing content delivery workflow. This approach provides security while minimizing additional system complexity by leveraging existing protocol capabilities.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If content is delivered to mobile devices and various runtime environments, then adaptability is improved, but maintaining compatibility with traditional broadcast TV standards becomes more difficult

Engineering Contradiction:
Improvecross-platform compatibilityVSAvoidcompatibility maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an HTTP-based content delivery platform as an intermediary layer between the content source and various client devices (mobile devices, Flash players, Silverlight players, etc.). This intermediary handles format conversion, protocol adaptation, and authentication, allowing content to be delivered to diverse platforms while maintaining a single standardized interface. The intermediary absorbs the complexity of compatibility maintenance rather than requiring each client to handle multiple format conversions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9485238B2Security framework for HTTP streaming architecture
Publication Date: 2016.11.01 AKAMAI TECHNOLOGIES INC
  • US9485238B2 patent drawing
  • US9485238B2 patent drawing
  • US9485238B2 patent drawing

AI summary

Methods and apparatus for preventing unauthorized access to online content, including in particular streaming video and other media, are provided. In various embodiments, techniques are provided to authorize users and to authenticate clients (e.g., client media players) to a content delivery system. The content delivery system may comprise a content delivery network with one or more content or “edge” servers therein. The requesting client is sent a program at the time of content delivery. The program may be embedded in the content stream, or sent outside of the stream. The program contains instructions that are executed by the client and cause it to return identifying information to the content delivery system, which can then determine whether the client player is recognized and, if so, authorized to view the content. Unrecognized and/or altered players may be prevented from viewing the content.