Segmented Content Encryption for Scalable CDN Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing content distribution networks face inefficiencies in encrypting media content, particularly in large networks where encrypting signals just prior to transmission is not scalable, and pre-encrypting content can be inflexible and computationally demanding, requiring periodic re-encryption due to key compromises.

Innovation Solution

Implementing a segmented content encryption system where a local site within the network, such as a headend, encrypts media content into segments, caching both encrypted and unencrypted portions with metadata, and transmitting these segments to consumer devices, reducing the burden on hubs and improving scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content is pre-encrypted at a centralized location for distribution, then security is improved, but device complexity and computational demand increase significantly

Engineering Contradiction:
Improvecontent securityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the content distribution network into multiple hierarchical levels (national site, regional sites, local sites, hubs) and segments the encryption function to be performed at distributed local sites rather than centralized. Each local site encrypts content independently using its own key, breaking the monolithic encryption system into smaller, manageable segments that reduce overall device complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If encryption is performed at each hub just prior to transmission, then adaptability is improved, but productivity decreases due to inefficiency in large networks

Engineering Contradiction:
Improveencryption flexibilityVSAvoidcontent distribution efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent performs encryption at local sites in advance of distribution to multiple hubs, rather than waiting until the last moment at each hub. This preliminary encryption action allows pre-encrypted content to be distributed efficiently to multiple hubs simultaneously, improving productivity while maintaining the flexibility to use different keys at different levels through the hierarchical key management system.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If periodic re-encryption is performed in response to key compromise, then reliability is maintained, but loss of time increases due to re-encryption requirements

Engineering Contradiction:
Improveencryption securityVSAvoidre-encryption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The hierarchical key structure segments the encryption keys into different levels (national site key, regional site keys, local site keys). If a key is compromised at one level, only the content encrypted with that specific key needs re-encryption, not all content in the entire network. This segmentation limits the scope of re-encryption operations, reducing time loss while maintaining security.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If content is encrypted with a single key throughout the distribution network, then device complexity is reduced, but adaptability decreases when key compromise occurs

Engineering Contradiction:
Improvekey management complexityVSAvoidresponse to key compromise
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a hierarchical dimension to key management, organizing keys in a tree structure with multiple levels (national site, regional sites, local sites) rather than using a single flat key. This dimensional change allows the system to maintain relatively simple key management at each level while gaining the adaptability to respond selectively to key compromises by affecting only the affected branch of the hierarchy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11863540B2Segmented encryption for content delivery
Publication Date: 2024.01.02 COMCAST CABLE COMM LLC
  • US11863540B2 patent drawing
  • US11863540B2 patent drawing
  • US11863540B2 patent drawing

AI summary

Techniques for encrypting content in a content distribution network are disclosed. The content distribution network may comprise a number of national and local sites, and a number of hubs at each local sites. A content segment encrypting device may be operative at a local site to encrypt and cache segments of content. The segment encrypting device may provide the segments to streaming devices that encode content for delivery downstream to network or user devices.