IP Library Granted Patent US 9,390,289
Granted Patent B2
US 9,390,289 · App. 14/247,165 · Granted Jul 12, 2016

Secure collection synchronization using matched network names

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,390,289
App. No.
14/247,165
Granted
Jul 12, 2016
Kind
B2
Abstract

One embodiment provides a system that facilitates facilitate secure synchronization of manifests using exact network names. During operation, the system generates an interest of advertisement comprising a name of a content object of the system. This name represents a collection of objects of the system and includes a first hash that is based on a key of the system. The first hash corresponds to a respective content object hash of one or more segments of a manifest representing the collection of objects. The system also determines a request for the content object based on the name in an interest of data from a remote node.

Claims (44)

1. A computer-executable method, comprising:

generating, by a computing device, an advertisement of a collection of content objects stored at the computing device, wherein a name included in the advertisement is a hierarchically structured variable length identifier which comprises contiguous name components ordered from a most general level to a most specific level,

wherein a last component of the name for the advertisement is a first hash that is based on a key of the computing device,

wherein the first hash is a hash of one or more segments of a manifest representing the collection of content objects,

wherein a segment of a manifest is distinct from a content object associated with the collection; and

receiving a request for a content object associated with the collection based on a name of a received interest of data from a remote node, wherein the last component of the name of the received interest is the first hash.

2. The method of claim 1 , wherein the requested content object is a first segment of the manifest; and

wherein the requested content object comprises a second hash of a second segment of the manifest.

3. The method of claim 2 , further comprising electing, based on the advertisement, the manifest at the computing device from a plurality of manifests with a same manifest hash, wherein the plurality of manifests is distributed among a plurality of nodes.

4. The method of claim 1 , wherein the requested content object is a secure catalog at the computing device, wherein the secure catalog comprises the respective content object hash of the segments of the manifest, and wherein the first hash is a hash of the secure catalog.

5. The method of claim 4 , further comprising signing the secure catalog using the key of the computing device.

6. The method of claim 4 , further comprising electing, based on the advertisement, the secure catalog at the computing device from a plurality of secure catalogs with the same content object hash, wherein the plurality of secure catalogs is distributed among a plurality of nodes.

7. The method of claim 4 , wherein the secure catalog is distributed among a plurality of segments; and

wherein a content object of a first segment of the secure catalog includes a hash of a content object of a second segment of the secure catalog.

8. The method of claim 4 , further comprising generating a message comprising a segment of the manifest in response to an interest of data from a remote node for the segment, wherein the interest of data includes one of the content object hashes in the secure catalog.

9. The method of claim 1 , wherein the key of the computing device identifies the computing device as a trusted publisher.

10. A computer-executable method, comprising:

obtaining, by a computing device, a name included in an advertisement from a remote node, wherein the name represents a collection of objects at the remote node and is a hierarchically structured variable length identifier which comprises contiguous name components ordered from a most general level to a most specific level,

wherein a last name component of the name for the advertisement is a first hash that is based on a key of the remote node,

wherein the first hash is a hash of one or more segments of a manifest representing the collection of content objects,

wherein a segment of a manifest is distinct from a content object associated with the collection; and

generating for the remote node an interest of data comprising a request for the collection of content objects based on the name.

11. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method, the method comprising:

generating an advertisement of a collection of content objects stored at a local node, wherein a name included in the advertisement is a hierarchically structured variable length identifier which comprises contiguous name components ordered from a most general level to a most specific level,

wherein a last component of the name for the advertisement is a first hash that is based on a key of the local node,

wherein the first hash is a hash of one or more segments of a manifest representing the collection of content objects,

wherein a segment of a manifest is distinct from a content object associated with the collection; and

receiving a request for a first content object associated with the collection based on a name of a received interest of data from a remote node, wherein the last component of the name of the received interest is the first hash.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the requested content object is a first segment of the manifest; and

wherein the requested content object comprises a second hash of a second segment of the manifest.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the method further comprises electing, based on the advertisement, the manifest at the local node from a plurality of manifests with a same manifest hash, wherein the plurality of manifests is distributed among a plurality of nodes.

14. The non-transitory computer-readable storage medium of claim 11 , wherein the requested content object is a secure catalog at the local node, wherein the secure catalog comprises the respective content object hash of the segments of the manifest, and wherein the first hash is a hash of the secure catalog.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the method further comprises signing the secure catalog using the key of the local node.

16. The non-transitory computer-readable storage medium of claim 14 , wherein the method further comprises electing, based on the advertisement, the secure catalog at the local node from a plurality of secure catalogs with the same content object hash, wherein the plurality of secure catalogs is distributed among a plurality of nodes.

17. The non-transitory computer-readable storage medium of claim 14 , wherein the secure catalog is distributed among a plurality of segments; and

wherein a content object of a first segment of the secure catalog includes a hash of a content object of a second segment of the secure catalog.

18. The non-transitory computer-readable storage medium of claim 14 , wherein the method further comprises generating a message comprising a segment of the manifest in response to an interest of data from a remote node for the segment, wherein the interest of data includes one of the content object hashes in the secure catalog.

19. The non-transitory computer-readable storage medium of claim 11 , wherein the key of the local node identifies the local node as a trusted publisher.

20. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method, the method comprising:

obtaining a name included in an advertisement from a remote node, wherein the name represents a collection of objects at the remote node and is a hierarchically structured variable length identifier which comprises contiguous name components ordered from a most general level to a most specific level,

wherein a last name component of the name for the advertisement is a first hash that is based on a key of the remote node,

wherein the first hash is a hash of one or more segments of a manifest representing the collection of content objects,

wherein a segment of a manifest is distinct from a content object associated with the collection; and

generating for the remote node an interest of data comprising a request for the collection of content objects based on the name.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2017
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: CISCO SYSTEMS, INC.
Reel/Frame 041714/0373 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2017
From: CISCO SYSTEMS, INC.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 041715/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2014
From: MOSKO, MARC E.
To: PALO ALTO RESEARCH CENTER INCORPORATED
Reel/Frame 032651/0203 →