Privacy Envelopes for Content Routing in CDNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content delivery networks lack effective means for content providers to control routing and ensure privacy constraints, particularly in content-oriented networks, leading to potential breaches in anonymity, pseudonymity, non-chainability, and non-observability.

Innovation Solution

A method for disseminating and routing content in a content distribution network that involves creating privacy protection envelopes with routing and storage constraints, which are interpreted by network nodes to enforce the content provider's rules, ensuring that only authorized nodes handle and route the content according to specified privacy parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If content is routed through multiple nodes in a CDN, then content delivery efficiency is improved, but user privacy and anonymity are compromised

Engineering Contradiction:
Improvecontent delivery efficiencyVSAvoidprivacy breach
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces privacy-preserving intermediaries (anonymity relays, mixing networks, onion routing layers) that act as mediators between content requesters and CDN nodes. These intermediaries decouple the direct connection between users and content delivery infrastructure, allowing efficient content routing while preserving user anonymity and preventing privacy breaches through multiple layers of abstraction

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the content delivery process into distinct privacy-preserving stages: identity separation (decoupling user identity from content requests), request anonymization (separating request metadata from content payload), and selective disclosure (revealing only necessary information at each routing stage). This segmentation allows efficient content delivery while maintaining privacy at each stage

Inventive Principle:
Principle #1Segmentation

2Reliability

If routing is based on user identity and location, then content can be delivered to specific users, but anonymity and non-observability are lost

Engineering Contradiction:
Improvecontent delivery accuracyVSAvoidanonymity loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing context-dependent routing: content delivery accuracy is maintained at the content level (delivering specific content to authorized users) while anonymity is preserved at the user level (hiding user identity and location). Different routing attributes are optimized locally for their specific purposes rather than using a single global routing mechanism

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent transitions from traditional identity-based routing to content-based routing, adding a new dimension to the routing space. Instead of routing based on user identity (4D: source, destination, port, protocol), the system routes based on content characteristics and authorization tokens, enabling accurate content delivery while maintaining user anonymity through content-centric addressing

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Speed

If CDN nodes store content for caching, then content delivery speed is improved, but storage constraints and data protection are compromised

Engineering Contradiction:
Improvecontent delivery speedVSAvoiddata protection risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent changes the storage parameters from traditional caching (store content indefinitely or until eviction) to constrained storage (store content only for specified durations, locations, and purposes). Content is cached with time-to-live (TTL) constraints, geographic restrictions, and access policy attachments, allowing fast delivery while limiting data protection risks through parameter-based control

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements feedback mechanisms where CDN nodes continuously monitor storage compliance, access patterns, and policy violations. The system provides feedback to content providers about storage usage and compliance status, enabling dynamic adjustment of caching strategies to balance delivery speed with data protection requirements through closed-loop control

Inventive Principle:
Principle #23Feedback

4Reliability

If routing rules are enforced at each node, then privacy constraints are protected, but network complexity and processing overhead increase

Engineering Contradiction:
Improveprivacy constraint enforcementVSAvoidnode processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-attaching routing policies, authorization tokens, and privacy constraints to content packets at the source before injection into the CDN. Content providers sign content with cryptographic credentials and policy descriptors in advance, allowing CDN nodes to enforce privacy constraints through simple verification operations rather than complex decision-making, reducing node processing complexity while maintaining reliable enforcement

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2410710B1Routing method in a content-distribution network
Publication Date: 2014.03.19 ALCATEL LUCENT SA
  • EP2410710B1 patent drawingFigure 1~2

AI summary

A method for disseminating and routing content in a content distribution network that takes into account the privacy needs of the holders of personal information, this method comprising a step of association, by a provider application, of an envelope of rules for access to and retention of this content by the nodes of the network, a step of creation of privacy protection envelopes for the file segments corresponding to this content, said privacy protection envelopes containing the privacy constraints, including routing and storage constraints for these file segments, and a step of injection of these consecutive file segments for routing in the content distribution network.