IP Library Granted Patent US 10,582,000
Granted Patent B1
US 10,582,000 · App. 16/375,664 · Granted Mar 3, 2020

Using post-cache edge computing to re-populate nonce values in cached content

Inventor: Aleksander Amrani (Austin, TX)
Assignee: CLOUDFLARE, INC.
H04L67/2842G06F21/10H04L61/1511H04L67/02H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,582,000
App. No.
16/375,664
Granted
Mar 3, 2020
Kind
B1
Abstract

A compute server receives, at a first compute server of a plurality of compute servers, a request from a client device, where the plurality of compute servers are part of a distributed cloud computing platform, and wherein the request is a request for a network resource. The compute server executes, by a single process at the first compute server, a nonce generator, wherein the nonce generator is run in a one of a plurality of isolated execution environments, locates at least one content item in response to the request for the network resource, detects a first nonce value in the at least one content item, computes a second nonce value by the nonce generator, and replaces the first nonce value with the second nonce value in the content item.

Claims (47)

1. A method, comprising:

receiving, at a first compute server of a plurality of compute servers, a request from a client device, where the plurality of compute servers are part of a distributed cloud computing platform, and wherein the request is a request for a network resource;

executing, by a single process at the first compute server, a nonce generator, wherein the nonce generator is run in a one of a plurality of isolated execution environments;

locating at least one content item in response to the request for the network resource;

detecting a first nonce value in the at least one content item;

generating a second nonce value by the nonce generator, in response to detecting the first nonce value in the at least one content item; and

replacing the first nonce value with the second nonce value in the content item.

2. The method of claim 1 , wherein locating the at least one content item comprises:

retrieving the at least one content item from a cache local to the first compute server.

3. The method of claim 1 , wherein locating the at least one content item comprises:

requesting the at least one content item from an origin server remote from the first compute server.

4. The method of claim 1 , wherein executing the nonce generator causes at least one sub-request to be generated and transmitted to an origin server for the at least one content item.

5. The method of claim 1 , wherein the replacing the first nonce value further comprises:

determining whether to replace the first nonce value by a lookup of configuration information for the nonce generator that identifies nonce values to replace.

6. The method of claim 1 , wherein the plurality of isolated execution environments execute at the first compute server.

7. The method of claim 1 , wherein the nonce generator can be configured by a customer via a control server to identify nonce values to be replaced.

8. A non-transitory machine-readable storage medium of a first one of a plurality of compute servers that provides instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving, at a first compute server of a plurality of compute servers, a request from a client device, where the plurality of compute servers are part of a distributed cloud computing platform, and wherein the request is a request for a network resource;

executing, by a single process at the first compute server, a nonce generator, wherein the nonce generator is run in a one of a plurality of isolated execution environments;

locating at least one content item in response to the request for the network resource;

detecting a first nonce value in the at least one content item;

generating a second nonce value by the nonce generator, in response to detecting the first nonce value in the at least one content item; and

replacing the first nonce value with the second nonce value in the content item.

9. The non-transitory machine-readable storage medium of claim 8 , wherein locating the at least one content item comprises:

retrieving the at least one content item from a cache local to the first compute server.

10. The non-transitory machine-readable storage medium of claim 8 , wherein locating the at least one content item comprises:

requesting the at least one content item from an origin server remote from the first compute server.

11. The non-transitory machine-readable storage medium of claim 8 , wherein executing the nonce generator causes at least one sub-request to be generated and transmitted to an origin server for the at least one content item.

12. The non-transitory machine-readable storage medium of claim 8 , wherein the replacing the first nonce value further comprises:

determining whether to replace the first nonce value by a lookup of configuration information for the nonce generator that identifies nonce values to replace.

13. The non-transitory machine-readable storage medium of claim 8 , wherein the plurality of isolated execution environments execute at the first compute server.

14. The non-transitory machine-readable storage medium of claim 8 , wherein the nonce generator can be configured by a customer via a control server to identify nonce values to be replaced.

15. A compute server, comprising:

a set of one or more processors; and

a non-transitory machine-readable storage medium that provides instructions that, when executed by the set of processors, cause the set of processors to perform the following operations:

receive a request from a client device, wherein the request is a request for a network resource;

execute, by a single process at the set of one or more processors, a nonce generator, wherein the nonce generator is run in a one of a plurality of isolated execution environments;

locate at least one content item in response to the request for the network resource;

detect a first nonce value in the at least one content item;

generating a second nonce value by the nonce generator, in response to detecting the first nonce value in the at least one content item; and

replace the first nonce value with the second nonce value in the content item.

16. The compute server of claim 15 , wherein the operations further locate the at least one content item by retrieving the at least one content item from a cache local to the compute server.

17. The compute server of claim 15 , wherein the operations further locate the at least one content item by requesting the at least one content item from an origin server remote from the compute server.

18. The compute server of claim 15 , wherein the operations further execute the nonce generator to cause at least one sub-request to be generated and transmitted to an origin server for the at least one content item.

19. The compute server of claim 15 , wherein the operations further replace the first nonce value by determining whether to replace the first nonce value by a lookup of configuration information for the nonce generator that identifies nonce values to replace.

20. The compute server of claim 15 , wherein the set of one or more processors execute the plurality of isolated execution environments.

21. The compute server of claim 15 , wherein the nonce generator can be configured by a customer via a control server to identify nonce values to be replaced.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2019
From: AMRANI, ALEKSANDER
To: CLOUDFLARE, INC.
Reel/Frame 048798/0664 →