Content delivery network encryption
Abstract
A system and method for delivering content to end users encrypted within a content delivery network (CDN) for content originators is disclosed. CDNs transport content for content originators to end user systems in a largely opaque manner. Caches and origin servers in the CDN are used to store content. Some or all of the content is encrypted within the CDN. When universal resource indicators (URIs) are received from an end user system, the CDN can determine the key used to decrypt the content object within the CDN before delivery. Where there is a cache miss, an origin server can be queried for the content object, which is encrypted in the CDN.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A content delivery network (CDN) having a plurality of points of presence (POPs) distributed geographically, the CDN comprising:
a first key database, wherein:
the first key database is part of a first POP of the plurality of POPs; and
the first key database stores a first plurality of keys for decrypting content objects;
a first cache, wherein:
the first cache is part of the first POP; and
the first cache stores a first encrypted version of a content object;
a first edge server, wherein:
the first edge server is part of the first POP; and
the first edge server is configured to:
receive a first request for the content object, wherein the first request is generated by a first end-user system;
retrieve a first key of the first plurality of keys from the first key database;
decrypt at least a portion of the first encrypted version of the content object using the first key to create a first unencrypted object; and
initiate delivery of the first unencrypted object to the first end-user system over the Internet;
a second key database, wherein the second key database stores a second plurality of keys for decrypting content objects; a second cache, wherein the second cache stores a second encrypted version of the content object; a second edge server, the second edge server configured to:
receive a second request for the content object;
retrieve a second key, wherein:
the second key is retrieved from the second key database; and
the second key is one of the second plurality of keys;
decrypt at least a portion of the second encrypted version of the content object using the second key to create a second unencrypted object; and
initiate delivery of the second unencrypted object to a second end-user system over the Internet.
3 . The CDN as recited in claim 2 , wherein:
the second edge server is part of the first POP; and the second key database is part of the first POP.
4 . The CDN as recited in claim 2 , wherein the second edge server is part of a second POP of the plurality of POPs.
5 . The CDN as recited in claim 2 , wherein the second key database is part of a second POP of the plurality of POPS.
6 . The CDN as recited in claim 2 , wherein the first key database and/or the second key database are indexed by information derivable from information contained in a URI.
7 . The CDN as recited in claim 2 , further comprising a fingerprinting function that embeds a source Internet address into the content object.
8 . A method for protecting content within a content delivery network (CDN) having a plurality of points of presence (POPs) distributed geographically, the method comprising:
receiving a first request for a content object; locating a first encrypted version of the content object at a first edge server, wherein the first edge server is part of a first POP of the plurality of POPs; retrieving a first key for the first encrypted version of the content object, wherein the first key is located in a first key database; receiving a second request for the content object; locating a second encrypted version of the content object at a second edge server, wherein the second edge server is part of the CDN; retrieving a second key for the second encrypted version of the content object, wherein the second key is located in a second key database; and decrypting at least a portion of the first encrypted version of the content object with the first key to create a first unencrypted object; initiating delivery of the first unencrypted object to a first end-user system; decrypting at least a portion of the second encrypted version of the content object with the second key to create a second unencrypted object; and initiating delivery of the second unencrypted object to a second end-user system.
9 . The method for protecting content within the CDN as recited in claim 8 , wherein:
the second edge server is part of the first POP; and the second key database is part of the first POP.
10 . The method for protecting content within the CDN as recited in claim 8 , wherein;
the second edge server is part of a second POP of the plurality of POPs; and the second key database is part of the second POP.
11 . The method for protecting content within the CDN as recited in claim 2 , wherein the first key database and the second key database are part of the CDN.
12 . The method for protecting content within the CDN as recited in claim 8 , wherein:
the first key database is outside the CDN; and the first key is passed to the CDN using a secure channel.
13 . The method for protecting content within the CDN as recited in claim 8 , wherein the first request is received by the first edge server and the second request is received by the second edge server.
14 . The method for protecting content within the CDN as recited in claim 8 , wherein:
the first request includes a URI specifying the content object; and the first key is located by analyzing the URI.
15 . The method for protecting content within the CDN as recited in claim 14 , further comprising watermarking the content object with a fingerprint that allows determination of an IP address that the URI was requested from.
16 . The method for protecting content within the CDN as recited in claim 8 , wherein the first end-user system is the same as the second end-user system.
17 . A memory device having instructions for protecting content within a CDN having a plurality of points of presence (POPs) distributed geographically, that when executed, cause one or more processors to:
receive a first request for a content object; locate a first encrypted version of the content object at a first edge server, wherein the first edge server is part of a first POP of the plurality of POPs; retrieve a first key for the first encrypted version of the content object, wherein the first key is located in a first key database; receive a second request for the content object; locate a second encrypted version of the content object at a second edge server, wherein the second edge server is part of the CDN; retrieve a second key for the second encrypted version of the content object, wherein the second key is located in a second key database; and decrypt at least a portion of the first encrypted version of the content object with the first key to create a first unencrypted object; initiate delivery of the first unencrypted object to a first end-user system; decrypt at least a portion of the second encrypted version of the content object with the second key to create a second unencrypted object; and initiate delivery of the second unencrypted object to a second end-user system.
18 . The memory device having instructions for protecting content within the CDN as recited in claim 17 , wherein:
the second edge server is part of the first POP; and the second key database is part of the first POP.
19 . The memory device having instructions for protecting content within the CDN as recited in claim 17 , wherein:
the second edge server is part of a second POP of the plurality of POPs; and the second key database is part of the second POP.
20 . The memory device having instructions for protecting content within the CDN as recited in claim 17 , wherein:
the first request includes a URI specifying the content object; and the first key is located by analyzing the URI.
21 . The memory device having instructions for protecting content within the CDN as recited in claim 20 , wherein the instructions further cause the one or more processors to watermark the first unencrypted object and/or the second unencrypted object with a fingerprint that allows determination of an IP address that the URI was requested from.Join the waitlist — get patent alerts
Track US2014304507A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.