IP Library Granted Patent US 9,317,677
Granted Patent B1
US 9,317,677 · App. 13/902,535 · Granted Apr 19, 2016

Access control for content delivery networks

Inventors: Robert Benjamin Scott (San Francisco, CA); Arthur Kopatsy (San Francisco, CA); Ned Todd Birdwell Rockson (San Francisco, CA)
Assignee: Inkling Systems, Inc.
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,317,677
App. No.
13/902,535
Granted
Apr 19, 2016
Kind
B1
Abstract

Content items are distributed to a content delivery network using identifiers that expresses relationships between the content items and at least one associated content element. When making requests to content delivery network, a requesting Web browser may thus specify the content items according to uniform resource locators that include credentials that allow the content delivery network to verify that the browser is authorized to receive the content items. These uniform resource locators may uniquely associate the content items with the associated content element and the requesting browser in a cryptographically secure manner.

Claims (15)

1. A computer-implemented method, comprising

distributing, from an origin server, a plurality of content items to a server in a content delivery network, the content items each being identified in a manner that expresses relationships between a respective one of the content items and an associated content element, wherein the content element and the respective one of the content items represent a portion of an electronic content work such as an electronic book, magazine, or article, and

providing a requesting Web browser associated with a client computer a request signature that is based on a client identifier, a content element identifier, and trusted credentials to be used by the server in the content delivery network for verifying that the browser is authorized to receive the content items and the associated content element, wherein the credentials comprise a request signature that uniquely associates the requesting browser with the content elements,

wherein during loading of the content element from the server in the content delivery network, the requesting Web browser specifies, for each respective one of the content items, uniform resource locators that include bindings that uniquely associate the content items with the associated content element in a cryptographically secure manner, comprising: the content element identifier; a unique identifier for the respective access-restricted content item that is based on an identifier for the content element, an asset identifier for the respective access-restricted content item, and the trusted credentials; the request signature; and the content item identifier.

2. A computer-implemented method, comprising:

receiving, at a server of a content delivery network (CDN), a resource request from a requesting browser associated with a client, the resource request identifying a content element that comprises content items, wherein the content element and the content items represent a portion of an electronic content work such as an electronic book, magazine, or article, a plurality of which content items are access-restricted content items, the access-restricted content items each having an associated unique identifier, wherein the unique identifier for each respective access-restricted content item is based on an identifier for the content element, an asset identifier for the respective access-restricted content item, and the common trusted credentials known to an origin server and the CDN server, wherein the credentials comprise a request signature that uniquely associates the requesting browser with the content elements;

determining, by the server and without contacting the origin server for the content element, whether the client is authorized to receive the access-restricted content items;

and, if so, returning the access-restricted content items to the client, otherwise, not returning the access-restricted content items to the client,

wherein the determination is made according to subsequent resource requests from the client for each respective access-restricted content item and said subsequent resource requests use a uniform resource locator formatted to express a binding between each respective access-restricted content item and the content element in a manner that facilitates validation of the client's authorization to receive the respective access-restricted content item according to common trusted credentials within each of said subsequent resource requests, wherein the binding uniquely associates each respective content item with the associated content element in a cryptographically secure manner.

3. A content delivery network (CDN) server, comprising:

an interface configured to receive a resource request from a browser associated with a client, the resource request identifying a content element that comprises content items, wherein the content element and the content items represent a portion of an electronic content work such as an electronic book, magazine, or article, a plurality of which content items are access-restricted content items, the access-restricted content items each having an associated unique identifier wherein the unique identifier for each respective access-restricted content item is based on an identifier for the content element, an asset identifier for the respective access-restricted content item, and the common trusted credentials known to an origin server and the CDN server, wherein the credentials comprise a request signature that uniquely associates the requesting browser with the content elements;

a processor configured to determine, without contacting the origin server for the content element, whether the client is authorized to receive the access-restricted content items;

and, if so, to effect a return of the access-restricted content items to the client, otherwise, to not effect the return of the access-restricted content items to the client,

wherein the determination is made according to subsequent resource requests received from the client for each respective access-restricted content item, and said subsequent resource requests use a uniform resource locator formatted to express bindings between each respective access-restricted content items and the content element in a manner that facilitates validation of the client's authorization to receive the respective access-restricted content item according to common trusted credentials within each of said subsequent resource requests, wherein the bindings uniquely associate the content items with the associated content element in a cryptographically secure manner.

4. The server of claim 3 wherein the resource request includes an identifier for the content element as well as the unique identifier for each respective access-restricted content item based on an identifier for the content element, an asset identifier for the respective access-restricted content item, and the common trusted credentials.

Assignments (11)
SECURITY INTEREST Recorded May 12, 2025
From: TURNING TECH INTERMEDIATE, INC.; TURNING ACQUISITION, INC.; ECHO 360, INC.; ECHO 360 HOLDINGS, INC.; ECHO 360 CONTINUING EDUCATION, LLC; TURNING TECH LLC; TURNING TECH HOLDINGS, LLC; TURNING TECHNOLOGIES, LLC; RESPONSE TOOLS, LLC; INKLING SYSTEMS, INC.; SPEAKWORKS, INC.; RESPONSIVE INNOVATIONS, LLC
To: ADVANTAGE CAPITAL MANAGEMENT LLC
Reel/Frame 071276/0781 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: INKLING SYSTEMS, INC.; INK MIDCO LLC
Reel/Frame 067285/0617 →
SECURITY INTEREST Recorded May 1, 2024
From: ECHO 360, INC.; ECHO 360 CONTINUING EDUCATION, LLC; ECHO 360 HOLDINGS, INC.; TURNING ACQUISITION, INC.; TURNING TECH INTERMEDIATE, INC.; TURNING TECH LLC; TURNING TECH HOLDINGS, LLC; TURNING TECHNOLOGIES, LLC; RESPONSIVE INNOVATIONS, LLC; RESPONSE TOOLS, LLC; INKLING SYSTEMS, INC.
To: ADVANTAGE CAPITAL MANAGEMENT LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 067289/0001 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 16, 2018
From: SILICON VALLEY BANK
To: INKLING SYSTEMS, INC.
Reel/Frame 045612/0869 →
RELEASE OF SECURITY INTEREST Recorded Mar 16, 2018
From: TRIPLEPOINT CAPITAL LLC
To: INKLING SYSTEMS, INC.
Reel/Frame 045611/0800 →
PATENT SECURITY AGREEMENT Recorded Mar 6, 2018
From: INKLING SYSTEMS, INC.; INK MIDCO LLC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 045506/0160 →
RELEASE OF SECURITY INTEREST Recorded Feb 15, 2018
From: SILICON VALLEY BANK
To: INKLING SYSTEMS, INC.
Reel/Frame 045347/0274 →
RELEASE OF SECURITY INTEREST Recorded Feb 15, 2018
From: TRIPLEPOINT CAPITAL LLC
To: INKLING SYSTEMS, INC.
Reel/Frame 045346/0794 →
SECURITY INTEREST Recorded Dec 12, 2016
From: INKLING SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040714/0268 →
SECURITY INTEREST Recorded Apr 1, 2016
From: INKLING SYSTEMS, INC.
To: TRIPLEPOINT CAPITAL LLC
Reel/Frame 038329/0545 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2013
From: SCOTT, ROBERT BENJAMIN; KOPATSY, ARTHUR; BIRDWELL ROCKSON, NED TODD
To: INKLING SYSTEMS, INC.
Reel/Frame 030485/0306 →