IP Library Granted Patent US 8,200,958
Granted Patent B2
US 8,200,958 · App. 12/573,542 · Granted Jun 12, 2012

Content delivery network encryption

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,200,958
App. No.
12/573,542
Granted
Jun 12, 2012
Kind
B2
Abstract

A system and method for delivering content to end users encrypted within a content delivery network (CDN) for content originators is disclosed. CDNs transport content for content originators to end user systems in a largely opaque manner. Caches and origin servers in the CDN are used to store content. Some or all of the content is encrypted within the CDN. When universal resource indicators (URIs) are received from an end user system, the CDN can determine the key used to decrypt the content object within the CDN before delivery. Where there is a cache miss, an origin server can be queried for the content object, which is encrypted in the CDN.

Claims (105)

1. A method for protecting content within a content delivery network (CDN) that delivers content for content originators, method comprising:

receiving a URI specifying a content object;

analyzing the URI to determine if the content object is protected with encryption within the CDN;

searching for the content object within the CDN;

requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

analyzing the URI to find a key from a plurality of keys;

retrieving the key for the content object;

encrypting the content object with the key to create an encrypted content object;

caching the encrypted content object in the CDN;

decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

watermarking the content object with a fingerprint that allows determination of an IP address that the URI was requested from.

2. The method for protecting content within the CDN that delivers content for content originators as recited in claim 1 , further comprising decrypting the content object received from the origin server using an origin key different from the key.

3. A method for protecting content within a CDN that delivers content for content originators, the method comprising:

receiving a URI specifying a content object;

analyzing the URI to determine if the content object is protected with encryption within the CDN;

searching for the content object within the CDN;

requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

analyzing the URI to find a key from a plurality of keys;

retrieving the key for the content object;

encrypting the content object with the key to create an encrypted content object;

caching the encrypted content object in the CDN;

decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

watermarking the content object to create a watermarked content object, wherein a source Internet address of the URI is embedded in watermarked content object.

4. A method for protecting content within a CDN that delivers content for content originators, the method comprising:

receiving a URI specifying a content object;

analyzing the URI to determine if the content object is protected with encryption within the CDN;

searching for the content object within the CDN;

requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

analyzing the URI to find a key from a plurality of keys;

retrieving the key for the content object;

encrypting the content object with the key to create an encrypted content object;

caching the encrypted content object in the CDN;

decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

fingerprinting the content object to create a fingerprinted content object, wherein a source Internet address of the URI and/or information from the URI is embedded in fingerprinted content object.

5. The method for protecting content within the CDN delivering for content originators as recited in claim 4 , wherein the origin server is outside the CDN.

6. A method for protecting content within a CDN the CDN that delivers content for content originators, the method comprising:

receiving a URI specifying a content object;

analyzing the URI to determine if the content object is protected with encryption within the CDN;

searching for the content object within the CDN;

requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

analyzing the URI to find a key from a plurality of keys;

retrieving the key for the content object;

encrypting the content object with the key to create an encrypted content object;

caching the encrypted content object in the CDN;

decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

watermarking the content object with a fingerprint that allows determination of an account that the URI came, wherein the fingerprint is derived from information in the URI.

7. A CDN for delivering content to end users encrypted within the CDN for content originators, the CDN comprising:

a key database comprising a plurality of keys, wherein:

the plurality of keys are indexed by information derivable from URI information, and

a key is determined from the plurality of keys by analysis of a URI from an end user system;

an interface to the Internet, wherein the interface requests the content object from an origin server;

an edge server comprising a content database for caching content, wherein:

the CDN requests content from origin servers when not cached in the CDN

the edge server receives the URI specifying a content object,

the edge server analyzes the URI to determine if the content object is protected with encryption within the CDN,

the edge server stores the content object in the content database, and

the edge server decrypts the content object or a portion thereof with the key before delivery to an end user; and

a fingerprinting function that embeds a source Internet address of the URI and/or information from the URI into the content object.

8. The CDN for delivering content to end users encrypted within the CDN for content originators as recited in claim 7 , wherein the key is unique to the edge server being different from keys used by a remainder of edge servers in the CDN.

9. The CDN for delivering content to end users encrypted within the CDN for content originators as recited in claim 7 , wherein the key is unique to a content originator supplying the content object being different from keys used by a remainder of content originators using the CDN.

10. A CDN for delivering to end users encrypted within the CDN for content originators, the CDN comprising:

means for receiving a URI specifying a content object;

means for analyzing the URI to determine if the content object is protected with encryption within the CDN;

means for searching for the content object within the CDN;

means for requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

means for analyzing the URI to find a key from a plurality of keys;

means for retrieving the key for the content object;

means for encrypting the content object with the key to create an encrypted content object;

means for caching the encrypted content object in the CDN;

means for decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

means for watermarking the content object with a fingerprint that allows determination of an IP address that the URI was requested from.

11. The CDN for delivering content to end users encrypted within the CDN for content originators as recited in claim 10 , further comprising means for decrypting the content object received from the origin server using an origin key different from the key.

12. A CDN for delivering to end users encrypted within the CDN for content originators, the CDN comprising:

means for receiving a URI specifying a content object;

means for analyzing the URI to determine if the content object is protected with encryption within the CDN;

means for searching for the content object within the CDN;

means for requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

means for analyzing the URI to find a key from a plurality of keys;

means for retrieving the key for the content object;

means for encrypting the content object with the key to create an encrypted content object;

means for caching the encrypted content object in the CDN;

means for decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

means for watermarking the content object to create a watermarked content object, wherein a source Internet address of the URI is embedded in watermarked content object.

13. A CDN for delivering to end users encrypted within the CDN for content originators, the CDN comprising:

means for receiving a URI specifying a content object;

means for analyzing the URI to determine if the content object is protected with encryption within the CDN;

means for searching for the content object within the CDN;

means for requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

means for analyzing the URI to find a key from a plurality of keys;

means for retrieving the key for the content object;

means for encrypting the content object with the key to create an encrypted content object;

means for caching the encrypted content object in the CDN;

means for decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

means for fingerprinting the content object to create a fingerprinted content object, wherein a source Internet address of the URI and/or information from the URI is embedded in fingerprinted content object.

14. A CDN for delivering to end users encrypted within the CDN for content originators, the CDN comprising:

means for receiving a URI specifying a content object;

means for analyzing the URI to determine if the content object is protected with encryption within the CDN;

means for searching for the content object within the CDN;

means for requesting the content object from an origin server when the content object cannot find the content object cached within the CDN;

means for analyzing the URI to find a key from a plurality of keys;

means for retrieving the key for the content object;

means for encrypting the content object with the key to create an encrypted content object;

means for caching the encrypted content object in the CDN;

means for decrypting the encrypted content object or a portion thereof with the key as the content object is passed to an end user computer; and

means for watermarking the content object with a fingerprint that allows determination of an account that the URI came, wherein the fingerprint is derived from information in the URI.

Assignments (7)
RELEASE OF PATENT SECURITY AGREEMENT [RECORDED AT REEL/FRAME 065597/0406] Recorded Jul 9, 2025
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: UPLYNK, INC. (F/K/A EDGIO, INC.)
Reel/Frame 071875/0105 →
RELEASE OF PATENT SECURITY AGREEMENT [RECORDED AT REEL/FRAME 065597/0212] Recorded Jul 3, 2025
From: LYNROCK LAKE MASTER FUND LP
To: UPLYNK, INC. (F/K/A EDGIO, INC.); MOJO MERGER SUB, LLC
Reel/Frame 071817/0877 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2025
From: EDGIO, INC.
To: DRNC HOLDINGS, INC.
Reel/Frame 070071/0327 →
CHANGE OF NAME Recorded Sep 9, 2024
From: LIMELIGHT NETWORKS, INC.
To: EDGIO, INC.
Reel/Frame 068898/0281 →
PATENT SECURITY AGREEMENT Recorded Nov 15, 2023
From: EDGIO, INC.; MOJO MERGER SUB, LLC
To: LYNROCK LAKE MASTER FUND LP [LYNROCK LAKE PARTNERS LLC, ITS GENERAL PARTNER]
Reel/Frame 065597/0212 →
PATENT SECURITY AGREEMENT Recorded Nov 15, 2023
From: EDGIO, INC.; MOJO MERGER SUB, LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065597/0406 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2009
From: COPPOLA, PETER; WHITE, WILLIAM P.; MONSON, TAMARA
To: LIMELIGHT NETWORKS, INC.
Reel/Frame 023444/0337 →