Content Management Device for ICN Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ubiquitous caching in Information-Centric Networking (ICN) poses challenges in controlling access to content, allowing unauthorized access and preventing content owners from tracking user identities and content usage due to the decentralized nature of content storage and retrieval.

Innovation Solution

A content management device generates and encrypts records of content with encryption credentials, allowing authorized access while disguising content names and tracking user information, and provides encrypted content through network devices closer to users for reduced latency and resource utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If ubiquitous caching is implemented in ICN, then content delivery speed is improved, but content security and access control deteriorate

Engineering Contradiction:
Improvecontent delivery speedVSAvoidcontent security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments content into multiple encrypted portions and distributes them across different cache nodes. Each node stores only a fragment, requiring reconstruction of the complete content for access. This segmentation prevents any single node from having full content, thereby maintaining security while enabling fast distributed delivery.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary content management device that mediates between users and cache nodes. This intermediary verifies user credentials, manages encryption keys, and controls content distribution policies, thereby maintaining security oversight while allowing rapid content retrieval from distributed caches.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If content is cached at multiple network devices, then access latency is reduced, but tracking user identity and content usage becomes difficult

Engineering Contradiction:
Improveaccess latencyVSAvoiduser tracking information
Core Design Contradiction:
Loss of timeVSLoss of information

Solution Approach 1:

The patent performs preliminary authentication and credential verification at the content management device before content is distributed to caches. User identities and usage permissions are established in advance, allowing subsequent fast content delivery without compromising tracking capabilities. The intermediary maintains user profiles and access histories for future reference.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where cache nodes report content access events back to the content management device. This feedback loop maintains user tracking information and usage statistics while allowing the bulk content transfer to occur rapidly from local caches, thus preserving monitoring capabilities without sacrificing speed.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If encryption is applied to content records, then unauthorized access is prevented, but processing and retrieval complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidprocessing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent changes the encryption parameter structure by using symmetric encryption for content portions with keys managed by an intermediary device. This approach maintains strong security protection while reducing processing complexity compared to asymmetric encryption, as symmetric operations are computationally lighter and can be performed efficiently at cache nodes during rapid retrieval operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11153282B2Controlling access to content in a network
Publication Date: 2021.10.19 VERIZON PATENT & LICENSING INC
  • US11153282B2 patent drawing
  • US11153282B2 patent drawing
  • US11153282B2 patent drawing

AI summary

A device can receive a first communication from a user device. The first communication can includes a request for content. The device can generate a record of content. The record of content includes a reference associated with the content and one or more encryption credentials associated with the content. The device can encrypt the record of content, to form an encrypted record of content, based on receiving the first communication. The device can provide the encrypted record of content to the user device based on receiving the first communication. The device can receive a second communication from the user device based on providing the encrypted record of content. The device can provide the content to the user device based on receiving the second communication.