Token Authentication for Localized Content Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content delivery networks (CDNs) face performance challenges due to the inability to deeply penetrate user networks and the need to synergize CDN and service provider resources, while ensuring secure access restrictions are maintained across networks.

Innovation Solution

A multi-phase token-based authentication scheme is implemented to securely redirect content requests from a CDN to secondary networks, ensuring access restrictions are enforced at both the CDN and secondary networks through the use of first and second encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If CDN redirects content requests to secondary networks for localized delivery, then content delivery performance is improved, but securing access restrictions across networks becomes more complex

Engineering Contradiction:
Improvecontent delivery performanceVSAvoidauthentication scheme complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The authentication scheme is segmented into multiple phases, with each phase handling specific authentication tasks at different network boundaries. The first phase authenticates at the CDN level using first encryption keys, while the second phase authenticates at the secondary network level using second encryption keys. This segmentation allows complex security requirements to be broken down into manageable, modular components that can be implemented independently at each network layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Encryption keys serve as intermediaries that facilitate secure communication and authentication between the CDN, secondary networks, and content consumers. The first encryption keys enable authentication between the CDN and content consumers, while the second encryption keys enable authentication between the CDN and secondary networks. These intermediary keys allow the system to maintain security restrictions without requiring direct trust relationships between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If CDN leverages secondary network resources, then resource utilization is optimized, but maintaining access restrictions across networks becomes more difficult

Engineering Contradiction:
Improveresource utilizationVSAvoidaccess restriction enforcement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication actions before content is delivered to secondary networks. The CDN authenticates content consumers using first encryption keys before redirecting requests to secondary networks. This preliminary authentication ensures that only authorized consumers can access content through secondary networks, maintaining access restrictions while enabling resource optimization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The multi-phase authentication scheme implements feedback mechanisms where authentication results from the first phase inform the second phase. The CDN uses authentication outcomes from initial verification to determine appropriate secondary network routing and authentication requirements. This feedback loop ensures that access restrictions are dynamically enforced based on authenticated consumer credentials throughout the content delivery process.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9699165B2Providing localized content delivery with remote token authentication
Publication Date: 2017.07.04 DRNC HOLDINGS INC
  • US9699165B2 patent drawing
  • US9699165B2 patent drawing
  • US9699165B2 patent drawing

AI summary

Some embodiments set forth systems and methods enabling a first network to use the resources of various second networks in order to localize delivery of the first network content from the various second networks in a secure manner. Some embodiments provide a token-based authentication scheme to ensure that any configured content access restrictions are effectuated at the first network and any of the second networks providing localized content delivery for the first network. The scheme involves a two phase user authentication, wherein the user is separately authenticated at the first network and the redirected to second network using either the same or different set of access restrictions. The first network exchanges a first encryption key with content providers for encrypting/decrypting the first access restriction and a second encryption key with a second network for encrypting/decrypting the second access restriction.