Method and apparatus for secure content delivery from a telecommunication network cache

US10367906B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10367906-B2
Application numberUS-201515544779-A
CountryUS
Kind codeB2
Filing dateFeb 2, 2015
Priority dateFeb 2, 2015
Publication dateJul 30, 2019
Grant dateJul 30, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

According to one aspect, the teachings herein disclose a method and apparatus for a providing content over a secure connection to a subscriber device, where the content is advantageously securely delivered from a cache local to the telecommunication network. Such operation is based on intercepting a secure connection request from the subscriber device and establishing a corresponding secure session between the subscriber device and a local network data center, rather than the remote content provider targeted by the request.

First claim

Opening claim text (preview).

What claimed is: 1. A method of providing content over a secure connection to a subscriber device of a telecommunication network comprising: receiving a secure connection request from the subscriber device, said secure connection request being received at a first communication interface of a network data center that is internal to the telecommunication network and being directed to an external network address associated with an external content provider that is external to the telecommunication network; determining whether or not the external content provider is registered for secure-content caching in the network data center; and responsive to determining that the external content provider is registered: establishing a secure session between the network data center and the subscriber device, including establishing a session key for encrypting communications over the secure session; determining whether the content targeted by the secure connection request is available from a content cache of the network data center; responsive to determining that the content targeted by the secure connection request is available from the content cache, delivering the content targeted by the secure connection request from the content cache to the subscriber device using the secure session; and responsive to determining that the content targeted by the secure connection request is not available from the content cache: initiating a takeover of the secure session by the external content provider by forwarding session information towards the external content provider via a second communication interface of the network data center, said session information including the session key, a network address of the subscriber device, and identification of the content targeted by the secure connection request; and instructing the telecommunication network to forward all subsequent session messages from the subscriber device for the secure session towards the external content provider rather than towards the network data center. 2. The method of claim 1 , wherein receiving the secure connection request from the subscriber device comprises receiving the secure connection request as forwarded from a serving packet gateway of the telecommunication network, and wherein the network data center communicates with the serving packet gateway via the first communication interface. 3. The method of claim 2 , wherein instructing the telecommunication network to forward all subsequent session messages from the subscriber device for the secure session towards the external content provider rather than towards the network data center comprises sending control signaling to the serving packet gateway via the first communication interface. 4. The method of claim 1 , wherein the external content provider comprises an external content delivery network that is accessible via one or more external packet data networks, and wherein initiating the takeover of the secure session by the external content provider comprises initiating a communication with the external content delivery network via the second communication interface. 5. The method of claim 1 , wherein initiating the takeover of the secure session by the external content provider comprises transferring a protocol endpoint established at the network data center for the secure session to the external content provider. 6. The method of claim 5 , wherein transferring the protocol endpoint comprises performing a Transfer Control Protocol Connection Passing, TCPCP, operation, to pass a TCP endpoint from the network data center to the external content provider, or transferring a Transport Layer Security, TLS, protocol endpoint from the network data center to the external content provider. 7. The method of claim 1 , wherein determining whether or not the external content provider is registered for secure-content caching in the network data center comprises accessing a registration data store in the network data center to determine whether the registration data store contains registration information corresponding to domain name information conveyed in the secure connection request. 8. The method of claim 1 , wherein determining whether the content targeted by the secure connection request is available from the content cache of the network data center comprises accessing a content-listing data store in the network data center to determine whether the content-listing data store contains listing information corresponding to a content identifier conveyed in the secure connection request. 9. A network data center configured for operation in a telecommunication network and further configured for providing content over a secure connection to a subscriber device of the telecommunication network, said network data center comprising at least one network node that comprises: a first communication interface configured to receive a secure connection request from the subscriber device, said secure connection request being directed to an external network address associated with an external content provider that is external to the telecommunication network; and processing circuitry configured to determine whether or not the external content provider is registered for secure-content caching in the network data center; and responsive to determining that the external content provider is registered: establish a secure session between the network data center and the subscriber device, including establishing a session key for encrypting communications over the secure session; determine whether the content targeted by the secure connection request is available from a content cache of the network data center; responsive to determining that the content targeted by the secure connection request is available from the content cache, deliver the content targeted by the secure connection request from the content cache to the subscriber device using the secure session; and responsive to determining that the content targeted by the secure connection request is not available from the content cache: initiate a takeover of the secure session by the external content provider by forwarding session information towards the external content provider via a second communication interface of the network data center, said session information including the session key, a network address of the subscriber device, and identification of the content targeted by the secure connection request; and instruct the telecommunication network to forward all subsequent session messages from the subscriber device for the secure session towards the external content provider rather than towards the network data center. 10. The network data center of claim 9 , wherein the first communication interface is configured to receive the secure connection request as forwarded from a serving packet gateway of the telecommunication network. 11. The network data center of claim 10 , wherein the processing circuitry is configured to instruct the telecommunication network to forward all subsequent session messages from the subscriber device for the secure session towards the external content provider by sending control signaling to the serving packet gateway via the first communication interface. 12. The network data center of claim 9 , wherein the external content provider comprises an external content delivery network that is accessible via one or more external packet data networks, and wherein the processing circuitry is configured to initiate the takeover of the secure session by the external content provider by initiating a communication with the external content delivery network via the second communication interface. 13.

Assignees

Inventors

Classifications

  • Connection setup · CPC title

  • Electricity · mapped topic

  • Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use · CPC title

  • Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP] · CPC title

  • intercepting packet switched data communications, e.g. Web, Internet or IMS communications · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10367906B2 cover?
According to one aspect, the teachings herein disclose a method and apparatus for a providing content over a secure connection to a subscriber device, where the content is advantageously securely delivered from a cache local to the telecommunication network. Such operation is based on intercepting a secure connection request from the subscriber device and establishing a corresponding secure ses…
Who is the assignee on this patent?
Zhu Zhongwen, Pourzandi Makan, Ericsson Telefon Ab L M
What technology area does this patent fall under?
Primary CPC classification H04L67/2842. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 30 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).