US2014304507A1PendingUtilityA1

Content delivery network encryption

Assignee: LIMELIGHT NETWORKS INCPriority: Sep 19, 2008Filed: Mar 17, 2014Published: Oct 9, 2014
Est. expirySep 19, 2028(~2.2 yrs left)· nominal 20-yr term from priority
H04L 63/0428H04L 67/568G06F 21/6218H04L 63/06H04L 9/08H04L 63/10
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for delivering content to end users encrypted within a content delivery network (CDN) for content originators is disclosed. CDNs transport content for content originators to end user systems in a largely opaque manner. Caches and origin servers in the CDN are used to store content. Some or all of the content is encrypted within the CDN. When universal resource indicators (URIs) are received from an end user system, the CDN can determine the key used to decrypt the content object within the CDN before delivery. Where there is a cache miss, an origin server can be queried for the content object, which is encrypted in the CDN.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A content delivery network (CDN) having a plurality of points of presence (POPs) distributed geographically, the CDN comprising:
 a first key database, wherein:
 the first key database is part of a first POP of the plurality of POPs; and 
 the first key database stores a first plurality of keys for decrypting content objects; 
   a first cache, wherein:
 the first cache is part of the first POP; and 
 the first cache stores a first encrypted version of a content object; 
   a first edge server, wherein:
 the first edge server is part of the first POP; and 
 the first edge server is configured to:
 receive a first request for the content object, wherein the first request is generated by a first end-user system; 
 retrieve a first key of the first plurality of keys from the first key database; 
 decrypt at least a portion of the first encrypted version of the content object using the first key to create a first unencrypted object; and 
 initiate delivery of the first unencrypted object to the first end-user system over the Internet; 
 
   a second key database, wherein the second key database stores a second plurality of keys for decrypting content objects;   a second cache, wherein the second cache stores a second encrypted version of the content object;   a second edge server, the second edge server configured to:
 receive a second request for the content object; 
 retrieve a second key, wherein:
 the second key is retrieved from the second key database; and 
 the second key is one of the second plurality of keys; 
 
 decrypt at least a portion of the second encrypted version of the content object using the second key to create a second unencrypted object; and 
 initiate delivery of the second unencrypted object to a second end-user system over the Internet. 
   
     
     
         3 . The CDN as recited in  claim 2 , wherein:
 the second edge server is part of the first POP; and   the second key database is part of the first POP.   
     
     
         4 . The CDN as recited in  claim 2 , wherein the second edge server is part of a second POP of the plurality of POPs. 
     
     
         5 . The CDN as recited in  claim 2 , wherein the second key database is part of a second POP of the plurality of POPS. 
     
     
         6 . The CDN as recited in  claim 2 , wherein the first key database and/or the second key database are indexed by information derivable from information contained in a URI. 
     
     
         7 . The CDN as recited in  claim 2 , further comprising a fingerprinting function that embeds a source Internet address into the content object. 
     
     
         8 . A method for protecting content within a content delivery network (CDN) having a plurality of points of presence (POPs) distributed geographically, the method comprising:
 receiving a first request for a content object;   locating a first encrypted version of the content object at a first edge server, wherein the first edge server is part of a first POP of the plurality of POPs;   retrieving a first key for the first encrypted version of the content object, wherein the first key is located in a first key database;   receiving a second request for the content object;   locating a second encrypted version of the content object at a second edge server, wherein the second edge server is part of the CDN;   retrieving a second key for the second encrypted version of the content object, wherein the second key is located in a second key database; and   decrypting at least a portion of the first encrypted version of the content object with the first key to create a first unencrypted object;   initiating delivery of the first unencrypted object to a first end-user system;   decrypting at least a portion of the second encrypted version of the content object with the second key to create a second unencrypted object; and   initiating delivery of the second unencrypted object to a second end-user system.   
     
     
         9 . The method for protecting content within the CDN as recited in  claim 8 , wherein:
 the second edge server is part of the first POP; and   the second key database is part of the first POP.   
     
     
         10 . The method for protecting content within the CDN as recited in  claim 8 , wherein;
 the second edge server is part of a second POP of the plurality of POPs; and   the second key database is part of the second POP.   
     
     
         11 . The method for protecting content within the CDN as recited in  claim 2 , wherein the first key database and the second key database are part of the CDN. 
     
     
         12 . The method for protecting content within the CDN as recited in  claim 8 , wherein:
 the first key database is outside the CDN; and   the first key is passed to the CDN using a secure channel.   
     
     
         13 . The method for protecting content within the CDN as recited in  claim 8 , wherein the first request is received by the first edge server and the second request is received by the second edge server. 
     
     
         14 . The method for protecting content within the CDN as recited in  claim 8 , wherein:
 the first request includes a URI specifying the content object; and   the first key is located by analyzing the URI.   
     
     
         15 . The method for protecting content within the CDN as recited in  claim 14 , further comprising watermarking the content object with a fingerprint that allows determination of an IP address that the URI was requested from. 
     
     
         16 . The method for protecting content within the CDN as recited in  claim 8 , wherein the first end-user system is the same as the second end-user system. 
     
     
         17 . A memory device having instructions for protecting content within a CDN having a plurality of points of presence (POPs) distributed geographically, that when executed, cause one or more processors to:
 receive a first request for a content object;   locate a first encrypted version of the content object at a first edge server, wherein the first edge server is part of a first POP of the plurality of POPs;   retrieve a first key for the first encrypted version of the content object, wherein the first key is located in a first key database;   receive a second request for the content object;   locate a second encrypted version of the content object at a second edge server, wherein the second edge server is part of the CDN;   retrieve a second key for the second encrypted version of the content object, wherein the second key is located in a second key database; and   decrypt at least a portion of the first encrypted version of the content object with the first key to create a first unencrypted object;   initiate delivery of the first unencrypted object to a first end-user system;   decrypt at least a portion of the second encrypted version of the content object with the second key to create a second unencrypted object; and   initiate delivery of the second unencrypted object to a second end-user system.   
     
     
         18 . The memory device having instructions for protecting content within the CDN as recited in  claim 17 , wherein:
 the second edge server is part of the first POP; and   the second key database is part of the first POP.   
     
     
         19 . The memory device having instructions for protecting content within the CDN as recited in  claim 17 , wherein:
 the second edge server is part of a second POP of the plurality of POPs; and   the second key database is part of the second POP.   
     
     
         20 . The memory device having instructions for protecting content within the CDN as recited in  claim 17 , wherein:
 the first request includes a URI specifying the content object; and   the first key is located by analyzing the URI.   
     
     
         21 . The memory device having instructions for protecting content within the CDN as recited in  claim 20 , wherein the instructions further cause the one or more processors to watermark the first unencrypted object and/or the second unencrypted object with a fingerprint that allows determination of an IP address that the URI was requested from.

Join the waitlist — get patent alerts

Track US2014304507A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.