Proxy Server Media Asset Redirection Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data retrieval systems face challenges in securely redirecting media asset requests from a Content Service Provider's default CDN to a Network Service Provider's chosen CDN without modifying the Content Service Provider's platform, particularly in ensuring secure access and preventing unauthorized use of network prioritization and usage exemptions.

Innovation Solution

A system that uses a proxy redirection server with mutual authentication and a user terminal configured to transmit authentication certificates, ensuring that only authorized user terminals can access the redirected CDN, and includes a process to generate new media asset locators with enhanced security features like timestamps and IP address restrictions, allowing the Network Service Provider to control access and maintain security without modifying the Content Service Provider's platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a proxy server is used to redirect media asset requests from a Content Service Provider's default CDN to a Network Service Provider's chosen CDN, then the Network Service Provider can control access and prioritize content delivery, but security risks increase due to potential unauthorized access and misuse of network prioritization

Engineering Contradiction:
Improveability to redirect to different CDNVSAvoidsecurity of access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a proxy server as an intermediary between the user terminal and the CDN. This proxy server receives media asset requests, validates authentication certificates, and forwards authorized requests to the appropriate CDN. The intermediary structure enables the Network Service Provider to control and monitor traffic while maintaining security through certificate validation, thus resolving the contradiction between adaptability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by requiring user terminals to present authentication certificates before the proxy server forwards requests to the CDN. The proxy server validates these certificates in advance, ensuring that only authorized users can access the CDN and utilize network prioritization. This preliminary security check prevents unauthorized access while maintaining the ability to redirect to different CDNs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication certificates are required for accessing the redirected CDN, then unauthorized access is prevented, but the complexity of the access process increases

Engineering Contradiction:
Improvesecurity of access controlVSAvoidcomplexity of access process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the user terminal automatically manages authentication certificates and presents them to the proxy server without requiring manual user intervention. The terminal handles the complexity of certificate validation and authentication protocols automatically, reducing the perceived complexity for end users while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If the proxy server validates authentication certificates for each request, then security is maintained, but the processing time and system overhead increase

Engineering Contradiction:
Improvesecurity validationVSAvoidrequest processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The proxy server performs authentication certificate validation in advance, before forwarding the request to the CDN. By validating certificates preliminarily, the system ensures security requirements are met upfront, allowing subsequent request processing to proceed more efficiently without repeated validation overhead for each CDN interaction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9380028B2Proxy server operation
Publication Date: 2016.06.28 BRITISH TELECOM PLC
  • US9380028B2 patent drawing
  • US9380028B2 patent drawing
  • US9380028B2 patent drawing

AI summary

Data messages having secure data location addresses other than a predefined set are handled by a user terminal (14) in the normal way by setting up a secure tunnel (181) to a server specified in the data message (16). As this would prevent any proxy server from performing any processing on the content of the data message, messages that require the proxy to perform process on the data messages are processed separately. Data messages (251) incorporating secure media access locators identifying a predefined set of known media servers are identified by a message processing function (41, 410, 44) and passed to a proxy server over a connection between the user terminal and the proxy which does not tunnel past the proxy server, such that the proxy server may generate a redirected media access locator for return to the user terminal (14).