Proxy Server Secure Redirection for CDN Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data retrieval systems face challenges in securely redirecting requests from a Content Service Provider's default CDN to a Network Service Provider's chosen CDN without modifying the Content Service Provider's platform, particularly in ensuring secure access and preventing unauthorized use of prioritization and usage exemptions.
Innovation Solution
A method is implemented where the user terminal is configured to establish a mutually authenticated connection with a redirection server, allowing it to redirect data messages and manage secure media asset locators, ensuring only authorized users access the secondary content delivery platform, and using a proxy configuration to handle secure connections and signatures effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a proxy server is used to redirect requests from the Content Service Provider's default CDN to the Network Service Provider's chosen CDN, then network prioritization and usage exemptions can be achieved, but security risks arise from unauthorized access and potential abuse of these privileges
Solution Approach 1:
The patent introduces a proxy server as an intermediary component that sits between the user terminal and the content delivery networks. This proxy server mediates all requests, performing authentication, authorization, and redirection functions. The intermediary structure allows the system to maintain security controls while enabling network prioritization, as the proxy can verify user credentials and enforce access policies before allowing requests to proceed to the optimized CDN path.
Solution Approach 2:
The system performs preliminary authentication and authorization actions through the proxy server before actual content delivery occurs. The proxy server pre-validates user credentials, device identities, and request permissions, establishing security credentials in advance. This preliminary action ensures that only authorized users can access the prioritized network path, preventing unauthorized abuse while maintaining the productivity benefits of network optimization.
2Reliability
If the system implements strict authentication and authorization mechanisms to prevent unauthorized access, then security is improved, but system complexity increases due to multiple authentication layers and certificate management
Solution Approach 1:
The patent combines multiple authentication and authorization functions into a single integrated proxy server component. Rather than implementing separate authentication servers, authorization servers, and certificate management systems distributed throughout the network, all security-related functions are merged into the proxy server. This consolidation maintains robust security while reducing overall system complexity by eliminating redundant components and simplifying the architecture.
Solution Approach 2:
The proxy server is designed as a multi-functional universal component that handles authentication, authorization, certificate validation, request redirection, and security credential verification all in one place. This universal design allows the system to implement comprehensive security mechanisms without requiring multiple specialized components, thereby maintaining high security standards while avoiding the complexity that would arise from a distributed multi-component security architecture.
3Adaptability or versatility
If the Content Service Provider's platform is modified to support redirection to alternative CDNs, then flexibility and control over content delivery are improved, but the ease of operation deteriorates due to required platform modifications
Solution Approach 1:
The patent segments the content delivery system into distinct functional components: the Content Service Provider's original platform remains unchanged, while a separate proxy server handles all redirection and alternative CDN routing logic. This segmentation allows the Network Service Provider to implement flexible content delivery control through the proxy server without requiring any modifications to the Content Service Provider's platform, thereby maintaining ease of operation while achieving adaptability.
Solution Approach 2:
The proxy server acts as an intermediary layer that enables flexible content delivery control without touching the Content Service Provider's platform. All redirection logic, alternative CDN selection, and request routing occur at the proxy server level, which mediates between the user terminal and the content delivery infrastructure. This intermediary approach provides full adaptability for the Network Service Provider while keeping the original platform unchanged and easy to operate.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Data messages having secure data location addresses other than a predefined set are handled by a user terminal (14) in the normal way by setting up a secure tunnel (181) to a server specified in the data message (16). As this would' prevent any proxy server from performing any processing on the content of the data message, messages that require the proxy to perform process on the data messages are processed separately. Data messages (251) incorporating secure media access locators identifying a predefined set of known media servers are identified by a message processing function (41, 410, 44) and passed to a proxy server over a connection between the user terminal and the proxy which does not tunnel past the proxy server, such that the proxy server may generate a redirected media access locator for return to the user terminal (14).