IP Library Granted Patent US 10,817,424
Granted Patent B1
US 10,817,424 · App. 16/723,639 · Granted Oct 27, 2020

Using post-cache edge computing to re-populate dynamic content in cached content

Inventors: Aleksander Amrani (Lisbon, PT); Andrew Taylor Plunk (Austin, TX)
Assignee: CLOUDFLARE, INC.
G06F12/0813G06F12/0891H04L47/783G06F2212/622
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,817,424
App. No.
16/723,639
Granted
Oct 27, 2020
Kind
B1
Abstract

A method that receives, at a first compute server of a plurality of compute servers, a request from a client device, wherein the request is a request for a network resource. The method locates at least one content item in response to the request for the network resource, detects possible dynamic content in the at least one content item, compares a first dynamic value in a first copy of the at least one content item to a second dynamic value in a second copy of the at least one content item from an origin server, and stores the at least one content item in a local cache as a safe content item to be returned for subsequent requests of the at least one content item in response to the first dynamic value matching the second dynamic value.

Claims (56)

1. A method, comprising:

receiving, at a first compute server of a plurality of compute servers, a request from a client device, where the plurality of compute servers are part of a distributed cloud computing platform, and wherein the request is a request for a network resource composed of a plurality of content items;

executing, by a single process at the first compute server, a dynamic content manager, wherein the dynamic content manager is run in a one of a plurality of isolated execution environments;

locating at least one content item from the plurality of content items in response to the request for the network resource;

detecting possible dynamic content in the at least one content item;

comparing a first dynamic value in a first copy of the at least one content item to a second dynamic value in a second copy of the at least one content item from an origin server; and

storing the at least one content item in a local cache as a safe content item to be returned for subsequent requests of the at least one content item in response to the first dynamic value matching the second dynamic value.

2. The method of claim 1 , further comprising:

marking the first content item as safe in the local cache or in a tracking data structure in response to the first dynamic value matching the second dynamic value.

3. The method of claim 1 , further comprising:

requesting the second copy of the at least one content item from the origin server remote from the first compute server in response to detecting the possible dynamic content.

4. The method of claim 1 , wherein the first content item is located in the local cache, further comprising:

determining whether the at least one content item is marked as safe in the local cache or in a tracking data structure.

5. The method of claim 1 , further comprising:

determining whether the dynamic content can be replaced at the first compute server.

6. The method of claim 1 , wherein the first dynamic value is any one or more of a nonce, text string, image or a numeric value that changes in each response to a request for the content item from the origin server.

7. The method of claim 1 , further comprising:

marking the at least one content item as unsafe in the local cache or flushing the at least one content item from the local cache in response to confirming dynamic content is present in the at least one content item.

8. A non-transitory machine-readable storage medium of a first one of a plurality of compute servers that provides instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving, at a first compute server of a plurality of compute servers, a request from a client device, where the plurality of compute servers are part of a distributed cloud computing platform, and wherein the request is a request for a network resource composed of a plurality of content items;

executing, by a single process at the first compute server, a dynamic content manager, wherein the dynamic content manager is run in a one of a plurality of isolated execution environments;

locating at least one content item from the plurality of content items in response to the request for the network resource;

detecting possible dynamic content in the at least one content item;

comparing a first dynamic value in a first copy of the at least one content item to a second dynamic value in a second copy of the at least one content item from an origin server; and

storing the at least one content item in a local cache as a safe content item to be returned for subsequent requests of the at least one content item in response to the first dynamic value matching the second dynamic value.

9. The non-transitory machine-readable storage medium of claim 8 , further providing instructions comprising:

marking the first content item as safe in the local cache or in a tracking data structure in response to the first dynamic value matching the second dynamic value.

10. The non-transitory machine-readable storage medium of claim 8 , further providing instructions comprising:

requesting the second copy of the at least one content item from an origin server remote from the first compute server in response to detecting the possible dynamic content.

11. The non-transitory machine-readable storage medium of claim 8 , wherein the first content item is located in the local cache, the instructions further comprising:

determining whether the at least one content item is marked as safe in the local cache or in a tracking data structure.

12. The non-transitory machine-readable storage medium of claim 8 , further providing instructions comprising:

determining whether the dynamic content can be replaced at the first compute server.

13. The non-transitory machine-readable storage medium of claim 8 , wherein the first dynamic value is any one or more of a nonce, text string, image or a numeric value that changes in each response to a request for the content item from the origin server.

14. The non-transitory machine-readable storage medium of claim 8 , further providing instructions comprising:

marking the at least one content item as unsafe in the local cache or flushing the at least one content item from the local cache in response to confirming dynamic content is present in the at least one content item.

15. A compute server, comprising:

a set of one or more processors; and

a non-transitory machine-readable storage medium that provides instructions that, when executed by the set of processors, cause the set of processors to perform the following operations:

receiving, at a first compute server of a plurality of compute servers, a request from a client device, where the plurality of compute servers are part of a distributed cloud computing platform, and wherein the request is a request for a network resource composed of a plurality of content items;

executing, by a single process at the first compute server, a dynamic content manager, wherein the dynamic content manager is run in a one of a plurality of isolated execution environments;

locating at least one content item from the plurality of content items in response to the request for the network resource;

detecting possible dynamic content in the at least one content item;

comparing a first dynamic value in a first copy of the at least one content item to a second dynamic value in a second copy of the at least one content item from an origin server; and

storing the at least one content item in a local cache as a safe content item to be returned for subsequent requests of the at least one content item in response to the first dynamic value matching the second dynamic value.

16. The compute server of claim 15 , wherein the operations are further comprising:

marking the first content item as safe in the local cache or in a tracking data structure in response to the first dynamic value matching the second dynamic value.

17. The compute server of claim 15 , wherein the operations are further comprising:

requesting the second copy of the at least one content item from an origin server remote from the first compute server in response to detecting the possible dynamic content.

18. The compute server of claim 15 , wherein the operations are further comprising:

determining whether the at least one content item is marked as safe in the local cache or in a tracking data structure.

19. The compute server of claim 15 , wherein the operations are further comprising:

determining whether the dynamic content can be replaced at the first compute server.

20. The compute server of claim 15 , wherein the first dynamic value is any one or more of a nonce, text string, image or a numeric value that changes in each response to a request for the content item from the origin server.

21. The compute server of claim 15 , wherein the operations are further comprising:

marking the at least one content item as unsafe in the local cache or flushing the at least one content item from the local cache in response to confirming dynamic content is present in the at least one content item.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2019
From: AMRANI, ALEKSANDER; PLUNK, ANDREW TAYLOR
To: CLOUDFLARE, INC.
Reel/Frame 051348/0907 →
Cited By (4)
US 12,193,081 US 12,335,113 US 12,464,030 US 12,477,013