IP Library Granted Patent US 11,627,135
Granted Patent B2
US 11,627,135 · App. 16/927,226 · Granted Apr 11, 2023

Method and system for delivering restricted-access resources using a content delivery network

Inventors: Yuanxun Gu (Munich, DE); Joerg Koenning (Munich, DE); Eduard-Andrei Boamba (Puchheim, DE); Ovidiu Boc (Munich, DE); Yevgen Borodkin (Munich, DE)
Assignee: SAP SE
H04L63/10H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,627,135
App. No.
16/927,226
Granted
Apr 11, 2023
Kind
B2
Abstract

A computer-implemented method for delivering restricted-access resources hosted on an origin server using a CDN comprising a plurality of CDN servers is provided. The method comprises receiving, by a CDN server from a client, a request for a restricted-access resource hosted on the origin server, wherein the request comprises a resource identifier of the restricted-access resource and an authentication token; and performing a delivery step comprising: creating, by the CDN server, a composite cache key comprising the resource identifier and at least part of the authentication token; comparing, by the CDN server, the composite cache key with one or more composite cache keys previously stored at the CDN server; if a match between the composite cache key and one of the previously stored composite cache keys is found, delivering, by the CDN server, a response associated to the composite cache key to the client; if no match between the composite cache key and one of the previously stored composite cache keys is found, performing a retrieval step comprising: forwarding, by the CDN server, the request to the origin server; checking, by the origin server, whether the authentication token allows access to the restricted-access resource; if the access is allowed: retrieving, by the origin server, the restricted-access resource; sending, by the origin server, a response comprising the restricted-access resource to the CDN server; if the access is not allowed: sending, by the origin server, a response comprising a refusal of the request to the CDN server; storing, by the CDN server, the response in association to the composite cache key; delivering, by the CDN server, the response to the client.

Claims (65)

1. A computer-implemented method for delivering restricted-access resources hosted on an origin server using a content delivery network (CDN) comprising a plurality of CDN servers, the method comprising:

receiving, by a CDN server from a client, a request for a restricted-access resource hosted on the origin server, wherein the request comprises a resource identifier of the restricted-access resource and an authentication token, the authentication token comprising one or more access credentials and expiration information; and

performing a delivery step comprising:

creating, by the CDN server, a composite cache key comprising the resource identifier and the one or more access credentials of the authentication token, the composite cache key excluding the expiration information of the authentication token;

comparing, by the CDN server, the composite cache key with one or more composite cache keys previously stored at the CDN server;

determining whether a match between the composite cache key and one of the previously stored composite cache keys is found, wherein

responsive to the match between the composite cache key and one of the previously stored composite cache keys being found, delivering, by the CDN server, a first response message associated with the composite cache key to the client; and

responsive to the match between the composite cache key and one of the previously stored composite cache keys is not being found, performing a retrieval step comprising:

forwarding, by the CDN server, the request to the origin server; and

checking, by the origin server, whether the authentication token allows access to the restricted-access resource;

responsive to determining that the access is allowed:

 retrieving, by the origin server, the restricted-access resource; and

 sending, by the origin server, a second response message comprising the restricted-access resource to the CDN server; and

responsive to determining that the access is not allowed, sending, by the origin server, a third response message comprising a refusal of the request to the CDN server;

storing, by the CDN server, in association to the composite cache key, the second response in response to determining that the access is allowed, or the third response message in response to determining that the access is not allowed; and

delivering, by the CDN server, the second response message or the third response message to the client.

2. The computer-implemented method of claim 1 , further comprising verifying, by the CDN server, the validity of the authentication token after receiving the request, and wherein the delivery step is only performed if the authentication token is valid.

3. The computer-implemented method of claim 2 , further comprising:

generating, by the origin server, the authentication token and sending the authentication token to the client; and

wherein verifying the validity of the authentication token comprises retrieving, by the CDN server, verification data from the origin server.

4. The computer-implemented method of claim 3 , further comprising storing, by the CDN server, the verification data.

5. The computer-implemented method of claim 4 , wherein:

the request is an hypertext transfer protocol request comprising a body and the composite cache key further comprises the body.

6. A computer program product comprising computer-readable instructions, which, when executed by a content delivery network (CDN) server, cause the CDN server to:

receive, from a client, a request for a restricted-access resource hosted on an origin server, wherein the request comprises a resource identifier of the restricted-access resource and an authentication token, the authentication token comprising one or more access credentials and expiration information; and

perform a delivery step comprising:

create a composite cache key comprising the resource identifier and the one or more access credentials of the authentication token, the composite cache key excluding the expiration information of the authentication token;

compare the composite cache key with one or more composite cache keys previously stored at the CDN server;

determine whether a match between the composite cache key and one of the previously stored composite cache keys is found, wherein

responsive to the match between the composite cache key and one of the previously stored composite cache keys being found, deliver a first response message associated with the composite cache key to the client; and

responsive to the match between the composite cache key and one of the previously stored composite cache keys not being found, forward the request to the origin server, where the origin server:

checks whether the authentication token allows access to the restricted-access resource;

responsive to determining that if the access is allowed:

 retrieves the restricted-access resource; and

 sends a second response message comprising the restricted-access resource to the CDN server; and

responsive to determining that if the access is not allowed, sends a third response message comprising a refusal of the request to the CDN server;

store, in association to the composite cache key, the second response in response to determining that the access is allowed, or the third response message in response to determining that the access is not allowed; and

deliver the second response message or the third response message to the client.

7. The computer program product of claim 6 , the computer-readable instructions, which, when executed by the CDN server, cause the CDN server to verify the validity of the authentication token after receiving the request, and wherein the delivery step is only performed if the authentication token is valid.

8. The computer program product of claim 7 , the computer-readable instructions, which, when executed by the CDN server, cause the CDN server to generate, by the origin server, the authentication token and sending the authentication token to the client; and

wherein verifying the validity of the authentication token comprises retrieving, by the CDN server, verification data from the origin server.

9. The computer program product of claim 8 , the computer-readable instructions, which, when executed by the CDN server, cause the CDN server to store the verification data.

10. The computer program product of claim 9 , wherein:

the request is an hypertext transfer protocol request comprising a body and the composite cache key further comprises the body.

11. A computing system for delivering restricted-access resources hosted on an origin server using a content delivery network (CDN), the computing system comprising the origin server, a plurality of CDN servers and at least one client, wherein:

a CDN server of the plurality of CDN servers is configured to receive a request for a restricted-access resource hosted on the origin server from the at least one client, wherein the request comprises a resource identifier of the restricted-access resource and an authentication token, the authentication token comprising one or more access credentials and expiration information; and

the computing system is configured to perform a delivery step comprising:

creating, by the CDN server, a composite cache key comprising the resource identifier and the one or more access credentials of the authentication token, the composite cache key excluding the expiration information of the authentication token;

comparing, by the CDN server, the composite cache key with one or more composite cache keys previously stored at the CDN server;

determining whether a match between the composite cache key and one of the previously stored composite cache keys is found, wherein

responsive to the match between the composite cache key and one of the previously stored composite cache keys being found, delivering, by the CDN server, a first response message associated with the composite cache key to the client; and

responsive to the match between the composite cache key and one of the previously stored composite cache keys not being found, performing a retrieval step comprising:

forwarding, by the CDN server, the request to the origin server;

checking, by the origin server, whether the authentication token allows access to the restricted-access resource;

responsive to determining that the access is allowed:

retrieving, by the origin server, the restricted-access resource; and

sending, by the origin server, a second response message comprising the restricted-access resource to the CDN server; and

responsive to determining that the access is not allowed, sending, by the origin server, a third response message comprising a refusal of the request to the CDN server;

storing, by the CDN server, in association to the composite cache key, the second response in response to determining that the access is allowed, or the third response message in response to determining that the access is not allowed; and

delivering, by the CDN server, the second response message or the third response message to the client.

12. The system of claim 11 , wherein the CDN server is further configured to verify the validity of the authentication token after receiving the request, and wherein the system is configured to perform the delivery step only if the authentication token is valid.

13. The system of claim 12 , wherein the origin server is further configured to generate the authentication token and send the authentication token to the client; and

wherein the CDN server is further configured to retrieve verification data from the origin server.

14. The system of claim 13 , wherein the CDN server is further configured to store the verification data.

15. The system of claim 14 , wherein the request is an hypertext transfer protocol request comprising a body and the composite cache key further comprises the body.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2020
From: GU, YUANXUN; KOENNING, JOERG; BOAMBA, EDWARD-ANDREI; BOC, OVIDIU; BORODKIN, YEVGEN
To: SAP SE
Reel/Frame 053191/0579 →
Priority Claims (1)
EP 20181032 · Jun 19, 2020 · regional
Continuity (1)
Related Publication 20210400047A1 · Dec 23, 2021