IP Library Granted Patent US 10,997,320
Granted Patent B1
US 10,997,320 · App. 15/884,751 · Granted May 4, 2021

Segment-based personalized cache architecture

Inventors: Akhil Aggrawal (Fremont, CA); Kalyan Ram Palagummi (Dublin, CA)
Assignee: EMC IP Holding Company LLC
G06F21/6263G06F9/45558H04L9/0816G06F21/31G06F21/335G06Q30/0255H04L9/083H04L9/32H04L63/0236H04L63/0428H04L63/08H04L63/102H04L63/1441H04L67/02H04L67/06H04L67/1008H04L67/1095H04L67/2814H04L67/2842H04L67/303
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,997,320
App. No.
15/884,751
Granted
May 4, 2021
Kind
B1
Abstract

Methods and apparatus are provided for delivering segment-based electronic content. One method for providing segment-based electronic content comprises: obtaining a request for the segment-based electronic content, wherein the request comprises an encrypted cookie previously provided to a device of a user associated with the request by an origin server using a handshake protocol, wherein the encrypted cookie comprises a fingerprint and a segment key identifying one of a plurality of predefined user segments of the user; processing the encrypted cookie to evaluate whether the user is authorized to access the segment-based electronic content based on the fingerprint; and providing the segment-based electronic content to the user of the one predefined user segment if the user is authorized.

Claims (46)

1. A method for providing segment-based electronic content, comprising:

obtaining, by at least one server of a content delivery network, said segment-based electronic content and an encrypted cookie from an origin server, wherein the encrypted cookie is generated by the origin server for a device of a user associated with an initial request for said segment-based electronic content, and wherein the encrypted cookie comprises (i) a fingerprint and (ii) a segment key identifying one of a plurality of predefined user segments of said user in a local cache of said at least one server of said content delivery network, wherein communications between the at least one server of said content delivery network and the origin server are encrypted using said fingerprint stored in said encrypted cookie and a shared secret key;

storing said segment-based electronic content in said local cache of said at least one server of said content delivery network;

obtaining, by said at least one server of said content delivery network, a further request for said segment-based electronic content wherein said further request comprises the encrypted cookie;

processing, by said at least one server of said content delivery network, said encrypted cookie of said further request to evaluate whether said user is authorized to access said segment-based electronic content based on said fingerprint;

in response to determining that said user is authorized, providing, by said at least one server of said content delivery network, said segment-based electronic content from said local cache to said user of said one predefined user segment without forwarding said further request to said origin server; and

in response to determining that said user is not authorized:

bypassing said local cache for said further request in response to a fingerprint, computed by the at least one server of said content delivery network, not matching the fingerprint in the encrypted cookie received with the further request; and

forwarding said further request to said origin server.

2. The method of claim 1 , further comprising the step of determining whether the user associated with said further request has been authenticated based on said encrypted cookie.

3. The method of claim 1 , further comprising the step of determining whether said segment-based electronic content is stored in said local cache.

4. The method of claim 1 , wherein said origin server generates said encrypted cookie a first time a user of said one predefined user segment provides said initial request for said segment-based electronic content, and wherein said segment-based electronic content is obtained from said origin server using a handshake protocol.

5. The method of claim 1 , further comprising the step of evaluating said further request against one or more time limit thresholds.

6. The method of claim 1 , wherein the fingerprint of the encrypted cookie is generated based on at least one of a hashed message authentication code and a secure hash algorithm.

7. A system for providing segment-based electronic content, comprising:

a non-transitory memory; and

at least one hardware processing device, coupled to the memory, operative to implement the following steps:

obtaining, by at least one server of a content delivery network, said segment-based electronic content and an encrypted cookie from an origin server, wherein the encrypted cookie is generated by the origin server for a device of a user associated with an initial request for said segment-based electronic content, and wherein the encrypted cookie comprises (i) a fingerprint and (ii) a segment key identifying one of a plurality of predefined user segments of said user in a local cache of said at least one server of said content delivery network, wherein communications between the at least one server of said content delivery network and the origin server are encrypted using said fingerprint stored in said encrypted cookie and a shared secret key;

storing said segment-based electronic content in said local cache of said at least one server of said content delivery network;

obtaining, by said at least one server of said content delivery network, a further request for said segment-based electronic content wherein said further request comprises the encrypted cookie;

processing, by said at least one server of said content delivery network, said encrypted cookie of said further request to evaluate whether said user is authorized to access said segment-based electronic content based on said fingerprint;

in response to determining that said user is authorized, providing, by said at least one server of said content delivery network, said segment-based electronic content from said local cache to said user of said one predefined user segment without forwarding said further request to said origin server; and

in response to determining that said user is not authorized:

bypassing said local cache for said further request in response to a fingerprint, computed by the at least one server of said content delivery network, not matching the fingerprint in the encrypted cookie received with the further request; and

forwarding said further request to said origin server.

8. The system of claim 7 , further comprising the step of determining whether the user associated with said further request has been authenticated based on said encrypted cookie.

9. The system of claim 7 , further comprising the step of determining whether said segment-based electronic content is stored in said local cache.

10. The system of claim 7 , wherein said origin server generates said encrypted cookie a first time a user of said one predefined user segment provides said initial request for said segment-based electronic content, and wherein said segment-based electronic content is obtained from said origin server using a handshake protocol.

11. The system of claim 7 , further comprising the step of evaluating said further request against one or more time limit thresholds.

12. The system of claim 7 , wherein the fingerprint of the encrypted cookie is generated based at least in part on a hashed message authentication code.

13. The system of claim 7 , wherein the fingerprint of the encrypted cookie is generated based at least in part on a secure hash algorithm.

14. A computer program product for providing segment-based electronic content, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one hardware processing device perform the following steps:

obtaining, by at least one server of a content delivery network, said segment-based electronic content and an encrypted cookie from an origin server, wherein the encrypted cookie is generated by the origin server for a device of a user associated with an initial request for said segment-based electronic content, and wherein the encrypted cookie comprises (i) a fingerprint and (ii) a segment key identifying one of a plurality of predefined user segments of said user in a local cache of said at least one server of said content delivery network, wherein communications between the at least one server of said content delivery network and the origin server are encrypted using said fingerprint stored in said encrypted cookie and a shared secret key;

storing said segment-based electronic content in said local cache of said at least one server of said content delivery network;

obtaining, by said at least one server of said content delivery network, a further request for said segment-based electronic content wherein said further request comprises the encrypted cookie;

processing, by said at least one server of said content delivery network, said encrypted cookie of said further request to evaluate whether said user is authorized to access said segment-based electronic content based on said fingerprint;

in response to determining that said user is authorized, providing, by said at least one server of said content delivery network, said segment-based electronic content from said local cache to said user of said one predefined user segment without forwarding said further request to said origin server; and

in response to determining that said user is not authorized:

bypassing said local cache for said further request in response to a fingerprint, computed by the at least one server of said content delivery network, not matching the fingerprint in the encrypted cookie received with the further request; and

forwarding said further request to said origin server.

15. The computer program product of claim 14 , further comprising the step of determining whether the user associated with said further request has been authenticated based on said encrypted cookie.

16. The computer program product of claim 14 , wherein said origin server generates said encrypted cookie a first time a user of said one predefined user segment provides said initial request for said segment-based electronic content, and wherein said segment-based electronic content is obtained from said origin server using a handshake protocol.

17. The computer program product of claim 14 , further comprising the step of evaluating said further request against one or more time limit thresholds.

18. The computer program product of claim 14 , further comprising the step of determining whether said segment-based electronic content is stored in said local cache.

19. The computer program product of claim 14 , wherein the fingerprint of the encrypted cookie is generated based at least in part on a hashed message authentication code.

20. The computer program product of claim 14 , wherein the fingerprint of the encrypted cookie is generated based at least in part on a secure hash algorithm.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2018
From: AGGRAWAL, AKHIL; PALAGUMMI, KALYAN RAM
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 044785/0107 →
Cited By (1)
US 12,273,352