Secure Content Delivery via Split Streams and Untrusted Caches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network caching techniques are inefficient due to the inability to utilize near-edge caches for protected content, as they lack user authorization management and integrity assurance, leading to resource wastage and limited implementation of Content Delivery Networks (CDNs).
Innovation Solution
A method that splits content into protected and unprotected streams, allowing the unprotected streams to be cached throughout the network, with the protected stream ensuring authorization and integrity via a secure path, while the unprotected stream can be delivered over unsecure paths, enabling extensive caching and efficient resource use.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If content is cached in near-edge caches throughout the network, then network resource efficiency is improved, but content protection from unauthorized access deteriorates
Solution Approach 1:
The patent divides content into multiple segments or chunks, where each segment is individually cached and distributed across the network. The content owner maintains control by managing the segments separately, allowing caching efficiency while preserving protection capabilities through selective segment delivery and verification.
Solution Approach 2:
The patent introduces an intermediary mechanism (such as a trusted proxy or verification system) that mediates between the content owner and the untrusted near-edge caches. This intermediary enables the use of unprotected caches while maintaining content protection through verification and controlled access.
2Reliability
If Content Delivery Networks with surrogates are used to protect and cache content, then content protection is improved, but system complexity deteriorates
Solution Approach 1:
The patent extracts the authorization and verification functions from the complex CDN surrogate system and implements them directly at the content owner and user endpoints. This eliminates the need for intermediary surrogates, reducing system complexity while maintaining protection capabilities.
Solution Approach 2:
The patent enables the content owner and users to perform authorization and verification themselves through cryptographic mechanisms, eliminating the need for complex intermediary surrogate systems. The content owner directly manages access control, and users self-verify their authorization credentials.
3Productivity
If simple lightly managed caches are placed at network edges, then network resource efficiency is improved, but trust relationship with content owners deteriorates
Solution Approach 1:
The patent replaces the mechanical trust relationship (requiring trusted hardware or software in caches) with cryptographic verification mechanisms. Untrusted caches can store and deliver content segments, but the content owner verifies authorization and integrity through cryptographic proofs, eliminating the need for trust in the cache infrastructure.
Data Source
AI summary
A user apparatus configured to request and receive data divided into chunks from a content source over a network, the apparatus comprising: a network module configured to establish a secure path to the content source and to establish an unsecure path to the content source; a determination module configured to determine that a next chunk of data is required and to determine whether the next chunk of data is protected; and a request module configured to request and receive the next chunk of data, wherein the next chunk of data is requested and received via the unsecure path if or when the next chunk of data is unprotected.


