Method, Router, Medium, and Device for Implementing Enhanced UPnP Subscriptions
Patent Information
- Application Number
- CN202010688094.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-16
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2040-07-16
AI Technical Summary
The lack of verification mechanism for delivering URLs in the UPnP protocol leads to data leakage and reflection amplification of TCP DDos attack risks. The existing verification methods based on source IP limit the flexibility of subscription functions, especially in the Internet and mobile user scenarios.
Set a whitelist in the router, and determine whether to accept subscription messages by verifying whether the IP address or domain name in the delivery URL is in the whitelist, thereby achieving a balance between security and flexibility of subscriptions.
Improves the security of UPnP subscriptions, prevents data leakage and DDos attacks, and expands the scope of subscription functions, including support for Internet and mobile users.
Smart Images

Figure CN114024695B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to network communication, and more particularly, to methods, routers, media, and devices for implementing enhanced UPnP subscriptions. Background Art
[0002] Universal Plug and Play (UPnP) technology defines a system architecture for the universal peer-to-peer network connection of all types of smart appliances, wireless devices, and personal computers.
[0003] The UPnP Device Architecture (UDA) is designed to support zero configuration, an "invisible" network connection process, and the automatic discovery of many types of devices provided by many vendors. Under UDA, a device can dynamically join the network, obtain an IP address, broadcast its capabilities, and learn of the existence and capabilities of other devices. Finally, the device can automatically and smoothly leave the network without leaving any unexpected problems.
[0004] UPnP devices can be implemented in any programming language or on any operating system. A UPnP device can be regarded as a container that contains services and is nested within a conventional device. That is, a device under UPnP should not be understood only as a device in the hardware sense, but should include service functions.
[0005] UDA defines two types of devices, controlled devices and control points. Controlled devices play the role of servers and respond to requests from control points. Both control points and controlled devices can be implemented on various platforms, including personal computers and embedded systems.
[0006] After a control point discovers a controlled device and obtains a description of the controlled device and its services, the control point is then ready for eventing. Eventing is associated with the control point sending actions to the controlled device to cause the controlled device to provide services. A UPnP service description includes a list of commands or actions that the service will respond to, as well as parameters or arguments for each action. The service description also includes a list of variables. These variables model the state of the service during operation and are described in terms of the data type, range, and event characteristics of the variables. When these variables change, the service publishes an update, and the control point can subscribe to receive this information.
[0007] A subscriber subscribes to the occurrence of an event of a service by sending a subscription message, which includes the URL (Uniform Resource Locator) of the publisher, the service identifier of the publisher, and the delivery URL of the event message. The URL of the publisher and the service identification number are, for example, from a previously received UPnP service description. If the subscription is accepted by the publisher, the publisher will respond with the unique identifier of the subscription and the duration of the subscription. The event message will be notified to the delivery URL. The UPnP protocol (e.g., UPnP TM Device Architecture 1.1, Section 4.1.2) provides the SUBSCRIBE method to provide this notification function.
[0008] Among them, the SUBSCRIBE method, along with the NT and CALLBACK header fields, is used to send a subscription message in the following format, that is, a subscription request.
[0009]
[0010] Among them, the "publisher path" in SUBSCRIBE, the "publisher host" and "publisher port" in HOST specify information related to the publisher, and the "delivery URL" in CALLBACK is the place where the event message will be sent.
[0011] However, there are no restrictions on the "delivery URL" in CALLBACK, that is, the "delivery URL" can be any web address (i.e., link). When accepting a subscription, the publisher does not perform any verification on the URL in CALLBACK.
[0012] This brings at least two security issues, including data exfiltration and reflected amplification TCP DDos (Distributed Denial-of-Service) attacks. Data exfiltration is more covert than data leakage. For example, when a hacker infiltrates a device within a local area network, they can use the SUBSCRIBE method to forge a subscription message and direct the event message of the publisher to the delivery URL that the hacker desires. Since the publisher does not verify any of the URLs in the "delivery URL", the event message will be sent to the "delivery URL" included in the CALLBACK, which may result in data exfiltration. Additionally, UPnP devices are easily exploited by hackers as the source of reflected amplification TCP DDos attacks, causing the network where the UPnP device is located to participate in the DDos attack. Summary of the Invention
[0013] According to a first aspect of the present disclosure, there is provided a method for implementing enhanced UPnP subscriptions, including, by a router supporting UPnP: receiving a subscription message for a subscription, where the subscription message specifies a delivery URL, and the delivery URL is the location to which the event message targeted by the subscription will be sent; verifying whether the IP address or domain name in the delivery URL is included in a whitelist based on the whitelist; and determining whether to reject the subscription message based on the verification result.
[0014] In some embodiments, the whitelist includes at least one of the following: IP addresses allowed to use the UPnP subscription function; and / or domain names allowed to use the UPnP subscription function.
[0015] In some embodiments, the IP addresses and domain names included in the whitelist can be public IPs and domain names, or proprietary IPs and domain names.
[0016] In some embodiments, the publisher indicated by the subscription message is the router. The method may further include: determining that the subscription is accepted in response to determining based on the verification result not to reject the subscription message.
[0017] In some embodiments, the method may further include: sending an initial event message to the delivery URL in response to the subscription being accepted.
[0018] In some embodiments, the method may further include: sending a subsequent event message to the delivery URL in response to an event occurring at the router during the duration of the subscription.
[0019] In some embodiments, the initial event message includes the name and initial value of an event variable that models the state of the router. Subsequent event messages include updated values of the event variable when an event occurs at the router.
[0020] In some embodiments, the state of the router includes at least one of the following: addition / removal of UPnP devices under the router; and / or the operating mode of UPnP devices under the router.
[0021] In some embodiments, the publisher indicated by the subscription message is a UPnP device under the router. The method may further include: in response to determining not to reject the subscription message based on the verification result, sending the verified subscription message to the UPnP device, where the UPnP device will send event messages to the delivery URL during the duration of the subscription.
[0022] In some embodiments, the method may further include: receiving a user configuration for the whitelist and storing the whitelist configured based on the user configuration.
[0023] In some embodiments, the method may further include: determining whether there is a whitelist or whether the whitelist is empty; in response to determining that there is a whitelist and the whitelist is empty, or determining that there is no whitelist, verifying whether the delivery URL is on the source IP; otherwise, verifying whether the IP address or domain name of the delivery URL is included in the whitelist based on the whitelist.
[0024] According to a second aspect of the present disclosure, there is provided a UPnP-enabled router including one or more processors and a memory coupled to the one or more processors. The memory stores computer-readable program instructions that, when executed by the one or more processors, cause the one or more processors to perform the method as described above.
[0025] According to a third aspect of the present disclosure, there is provided a modem including the router as described above.
[0026] According to a fourth aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer-readable program instructions that, when executed by a processor, cause the processor to perform the method as described above.
[0027] According to a fifth aspect of the present disclosure, there is provided a device for implementing enhanced UPnP subscriptions, including means for performing the operations of the method as described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 is a flowchart of an example method for implementing an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0029] Figure 2 It is a diagram of an example system that implements an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0030] Figure 3 It is a diagram of an example system that implements an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0031] Figure 4 A diagram showing an example system that implements an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0032] Figure 5 It is an example block diagram of an example electronic device according to an embodiment of the present disclosure. Detailed implementation
[0033] The following detailed description is made with reference to the accompanying drawings, and the following detailed description is provided to help a comprehensive understanding of various example embodiments of the present disclosure. The following description includes various details to help understanding, but these details are only considered as examples and are not intended to limit the present disclosure, which is defined by the appended claims and their equivalents. The words and phrases used in the following description are only for the purpose of clearly and consistently understanding the present disclosure. In addition, for the sake of clarity and conciseness, descriptions of well-known structures, functions, and configurations may be omitted. Those of ordinary skill in the art will recognize that various changes and modifications can be made to the examples described herein without departing from the spirit and scope of the present disclosure.
[0034] To fix the above two security issues, the latest UPnP provides an official solution, that is, only allowing the source IP to receive notifications. (For example, see https: / / github.com / miniupnp / miniupnp / blob / master / miniupnpd / u pnphttp.c#L671.) Specifically, when a subscription message is received, first verify whether the "delivery URL" in the CALLBACK is on the source IP that sent the subscription message. Only when it is verified that the "delivery URL" is on the source IP, the correct URL is extracted.
[0035] The solution has at least the following problems: UPnP devices are generally limited to a local area network (LAN), so their IP addresses are also limited to the LAN. Since the "delivery URL" is restricted to the source IP, URLs on any other IP address except the source IP cannot be used. This makes the subscription / notification function of UPnP have great limitations. For example, a system deployed on the Internet will not be able to use the subscription function, that is, it cannot directly receive event messages. For example, it is also difficult to extend the subscription function to mobile users because mobile agents generally use a gateway address, such as 192.168.0.1, and the gateway IP address generally cannot be used as the source IP. Therefore, a mobile device that establishes a communication channel with a mobile agent, such as a Customer Premise Equipment (CPE), cannot use the subscription function, and thus the relevant mobile terminal / user cannot receive event messages from the publisher.
[0036] The inventors of the present application conceived of setting up a whitelist in a router. By using the whitelist to verify subscription messages, both flexible subscription and high security can be achieved simultaneously.
[0037] Figure 1 It is a flowchart of an example method 100 for implementing an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0038] Method 100 is executed, for example, by a router that supports UPnP. As shown, method 100 includes step 101, where the router receives a subscription message for subscription, that is, a subscription request. The subscription message specifies a delivery URL, which is the location to which the event message targeted by this subscription will be sent.
[0039] The subscription message is constructed, for example, using the SUBSCRIBE method and the NT and CALLBACK header fields in accordance with the UPnP protocol as described above. The delivery URL is defined in the CALLBACK header field. The delivery URL is the location to which the event message targeted by this subscription will be sent.
[0040] In some embodiments, the subscription message can be sent by any UPnP device under this router.
[0041] In other embodiments, the subscription message can also be sent by a non-UPnP device (e.g., a device that does not support / enable UPnP) within the LAN.
[0042] In other words, the subscription message can come from any device within the local area network (or the IP corresponding to the device). However, the gateway IP (i.e., the router IP), such as 192.168.0.1, 192.168.1.1, 192.168.3.1, etc., generally does not serve as the IP address for sending the subscription message.
[0043] The delivery URL can be an HTTP URL over TCP (prefixed with "http: / / "). And the URL can be a complete URL and cannot be truncated.
[0044] As shown in the figure, method 100 further includes step 102, at which the router verifies whether the IP address or domain name in the delivery URL is included in the whitelist based on the whitelist. Method 100 further includes step 103, at which the router determines whether to reject the subscription message based on the verification result.
[0045] In the embodiments of the present disclosure, when the router receives a subscription message, it can extract the IP or domain name in the delivery URL and compare the extracted IP or domain name with the IP or domain name in the whitelist.
[0046] If the extracted IP or domain name exists in the whitelist, it indicates that the whitelist verification is successful, and the router will determine not to reject the subscription message and continue with subsequent operations. For example, in the case where the publisher targeted by the subscription is the router itself, the method may include: in response to determining not to reject the subscription message based on the verification result, determining that the subscription is accepted. After the subscription is received, the method may further include sending an initial event message to the delivery URL. Then, when an event occurs at the router during the duration of the subscription, the router may send a subsequent event message to the delivery URL. In the case where the publisher targeted by the subscription is a UPnP device under the router, the router may send the verified subscription message to the UPnP device. After the subscription is successful, the UPnP device will send event messages, including initial event messages and subsequent event messages, to the delivery URL during the duration of the subscription. The following will refer to Figure 2 and Figure 3 be described in more detail.
[0047] If the extracted IP or domain name does not exist in the whitelist, it indicates that the whitelist verification fails, and the router will reject the subscription message, and the subscription fails.
[0048] The whitelist is a list of IP addresses and / or domain names that are allowed to use the subscription function of UPnP. The whitelist can include at least one of the following: an IP address allowed to use the UPnP subscription function; and / or a domain name allowed to use the UPnP subscription function. The IP addresses or domain names included in the whitelist can be public IPs or domain names, or can be private IPs (i.e., local area network IPs) or domain names. In some embodiments, the whitelist includes, for example, at least two columns, namely the IP address and the corresponding domain name. That is, the whitelist can include the mapping of both. In some embodiments, it can also include only one of the IP address and the domain name. Those skilled in the art can set it according to needs.
[0049] In other words, the IP addresses and domain names included in the whitelist can be freely set by the user, without being limited to the local area network.
[0050] The user can, for example, set / configure the whitelist via various router setting interfaces, such as an App on a mobile phone or a setting web page, a setting web page on a computer, a cloud-based web page, etc. The router can receive the user configuration for the whitelist and store the whitelist configured based on the user configuration.
[0051] Compared with the method of verifying the delivery URL based on the source IP, the method of the embodiments of the present disclosure improves security by setting a whitelist at the router and performing whitelist verification for subscription messages. For example, it is difficult for hackers to obtain the whitelist in the router. Even if a hacker penetrates into a device within the local area network where the router is located and forges a subscription message, since the whitelist verification cannot pass at the router, the forged subscription message will be rejected, so it is difficult to cause data leakage. In addition, due to the whitelist verification, UPnP devices are not easily exploited by hackers as the source of a reflected amplification TCP DDos attack, avoiding making the network where the UPnP device is located participate in the DDos attack.
[0052] In addition, compared with the method of restricting the delivery URL to the source IP of the subscription message, the method of the embodiments of the present disclosure provides greater subscription flexibility. As long as the delivery URL is on an IP or domain name within the whitelist, the subscription function can be used, that is, the subscribed event message can be received. This means that any URL that passes the whitelist verification, whether it is on the Internet or within the local area network, can use the subscription function.
[0053] In addition, the whitelist can include the gateway IP. This means that subscription messages sent to the gateway IP can also pass the verification, so that the event messages of the publisher can be sent to the gateway IP. Further, the event messages can be sent to the mobile user via the communication channel established by the mobile agent and the CPE, enabling the mobile user to obtain relevant information and / or perform relevant configurations.
[0054] In some embodiments, before step 102, the method may further include determining whether there is a whitelist or whether the whitelist is empty. If it is determined that there is a whitelist and the whitelist is empty, or it is determined that there is no whitelist, the router checks whether the delivery URL in the subscription message is on the source IP to decide whether to reject the subscription message. If it is determined that there is a whitelist and the whitelist is not empty, the method proceeds to step 102.
[0055] Figure 2 FIG. is a diagram of an example system 200 implementing an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0056] As shown in the figure, the system 200 includes a device 210, a UPnP - enabled router 212, and a delivery destination 214.
[0057] The device 210 can be any device under the local area network corresponding to the router. The UPnP - enabled router 212, for example, connects multiple UPnP devices (not shown), and in the future, more UPnP devices will continuously connect to or disconnect from this router. When a UPnP device connects to or disconnects from this router (for example, a printer connects to or disconnects from the router), it can be considered that the router is undergoing eventing. When the state of a UPnP device itself connected to this router changes (for example, a printer changes from performing a printing service to having completed the printing service), it can cause an update of some information in the router, which can also be considered that the router is undergoing eventing.
[0058] If an interested system wants to know the presence and / or state changes of UPnP devices under this router, the UPnP subscription function can be used. For example, as shown in the figure, any device 210 within the local area network can send a subscription message to the router 212. The subscription message, for example, specifies the path, host number, and port of this router through the "publisher path" in SUBSCRIBE and the "publisher host" and "publisher port" in HOST to specify the publisher as this router 212. And the subscription message, for example, specifies the URL of the interested system as the delivery URL in the CALLBACK header.
[0059] The router 212 receives the subscription message and compares the IP or domain name in the delivery URL of the subscription message with the whitelist. If the IP or domain name in the delivery URL is included in the whitelist, the router 212 can accept the subscription, that is, the subscription is successful.
[0060] After that, the router 212 can send an event message to the delivery destination 214 indicated by the delivery URL. The router 212 can first send an initial event message after accepting the subscription. After that, when an event occurs at the router 212, the router 212 can send subsequent event messages in response thereto.
[0061] The initial event message can include the name and initial value of an event variable that models the state of the router 212. The subsequent event message can include the updated value of the event variable when the event occurs at the router. For example, the state of the router can include at least one of the following: the joining / leaving of UPnP devices under the router; and / or the working mode of UPnP devices under the router. For example, the joining / leaving of UPnP devices can cause a change in the state of the router, which can be considered an event occurring at the router 212, thus triggering the sending of an event message to inform the system of the delivery destination of the change. Similarly, when the working mode of a UPnP device changes, such as a printer changing from printing to standby or to a fault mode, it can also cause a change in the state of the router, thus triggering the sending of a corresponding event message, so that the system of the delivery destination learns of the change caused by the change in the working mode of the printer under the router.
[0062] Figure 3 FIG. is a diagram of an example system 300 that implements an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0063] As shown in the figure, the system 300 includes a device 310, a UPnP-enabled router 312, a UPnP device 313, and a delivery destination 314. Among them, the UPnP device 313 is a UPnP device connected to the router 312.
[0064] In some cases, when wanting to subscribe to events occurring in the UPnP device 313 under the router 312, the device 310 can send a subscription message. The subscription message can specify the path, host number, and port of the UPnP device 313 through the "publisher path" in the SUBSCRIBE method and the "publisher host" and "publisher port" in the HOST field to specify the publisher as the UPnP device 313. Similarly, the subscription message specifies the URL of the system as the delivery URL, for example, in the CALLBACK header.
[0065] The UPnP-enabled router 312 receives the subscription message and verifies it based on the whitelist stored therein, that is, compares the IP or domain name in the delivery URL with the IP or domain name in the whitelist. The verification method is similar to the method described for Figure 2 and will not be elaborated here.
[0066] If the whitelist verification is successful, the router 312 does not reject the subscription message and proceeds with subsequent operations, such as sending the verified subscription message to the UPnP device 313. The UPnP device 313 receives the subscription message. After accepting the subscription, the UPnP device 313 sends an event message to the delivery destination 314. In this case, the event message, whether it is an initial event message or a subsequent event message, contains the name and variable value of the evented variable that models the state of the UPnP device 313.
[0067] If the whitelist verification is not successful, the router 312 directly rejects the subscription message. The subscription message will not be forwarded to the UPnP device 313, and there will be no subsequent event message sent.
[0068] Figure 4 A diagram showing an example system 400 that implements an enhanced UPnP subscription function according to an embodiment of the present disclosure.
[0069] As shown in the figure, the system 400 includes a modem 402, and the modem 402 integrates a router 412 that supports UPnP. The router 412 is similar to the router described above with reference to Figures 1-3 The router 412 that supports UPnP can be implemented as a module or component integrated in the modem 402.
[0070] Optionally, the modem 402 can also integrate a mobile agent 404. The mobile agent 404 establishes a communication channel with a mobile terminal 408 through a mobile device such as a CPE (not shown), for example. The mobile agent 404 generally uses a gateway IP (i.e., the router IP), such as 192.168.0.1.
[0071] The device 410 and the UPnP device 412 are connected to the modem 402, and more specifically, to the router 412. The device 410 can be a non-UPnP device. Only one device 410 and one UPnP device 412 are shown in the figure, and those skilled in the art can understand that there can be multiple devices 410 and multiple UPnP devices 412.
[0072] Either the device 410 or the UPnP device 412 can send a subscription message to the router 412, and either the router 412 or the UPnP device 412 can act as the publisher of the subscription.
[0073] In some embodiments, the delivery URL in the subscription message may include the gateway IP, and the whitelist used by router 412 also includes the gateway IP. Accordingly, the subscription message will pass the whitelist verification at router 412. In the case where the subscription is accepted, the publisher (e.g., router 412 or UPnP device 412) may send an event message to the mobile agent, which sends it to the mobile user via the established communication channel. This can extend the subscription function to mobile users.
[0074] Figure 5 FIG. 4 is an example block diagram of an example electronic device 500 in accordance with an embodiment of the present disclosure.
[0075] The electronic device 500 may be used to implement various devices or components in various systems (e.g., systems 200, 300, 400) in accordance with embodiments of the present disclosure, such as one of the following: devices 210, 310, 410; UPnP devices 313, 413; UPnP-enabled routers 212, 312; and modems 402.
[0076] As Figure 5 shown, the electronic device includes a processing subsystem 510, a memory subsystem 512, and a networking subsystem 514. The processing subsystem 510 includes one or more components configured to perform computing operations. For example, the processing subsystem 510 may include one or more microprocessors, ASICs, microcontrollers, programmable logic devices, graphics processing units (GPUs), and / or one or more digital signal processors (DSPs).
[0077] The memory subsystem 512 includes one or more components for storing data and / or instructions for the processing subsystem 510 and the networking subsystem 514. For example, the memory subsystem 512 may include dynamic random access memory (DRAM), static random access memory (SRAM), and / or other types of memory (sometimes collectively or individually referred to as "computer-readable storage media"). In some embodiments, the instructions for the processing subsystem 510 in the memory subsystem 512 include: one or more program modules or instruction sets (such as program instructions 522 or operating system 524), which may be executed by the processing subsystem 510. Note that one or more computer programs may constitute a computer program mechanism. In addition, the instructions in the various modules in the memory subsystem 512 may be implemented in: high-level programming languages, object-oriented programming languages, and / or in assembly or machine language. In addition, the programming language may be compiled or interpreted, e.g., configurable or configured to (used interchangeably in this discussion) be executed by the processing subsystem 510.
[0078] Additionally, the memory subsystem 512 may include mechanisms for controlling access to the memory. In some embodiments, the memory subsystem 512 includes a memory hierarchy that includes one or more caches coupled to the memory in the electronic device 500. In some of these embodiments, one or more of the caches are located in the processing subsystem 510.
[0079] In some embodiments, the memory subsystem 512 is coupled to one or more high-capacity mass storage devices (not shown). For example, the memory subsystem 512 may be coupled to a magnetic drive or an optical drive, a solid-state drive, or another type of mass storage device. In these embodiments, the electronic device 500 may use the memory subsystem 512 as a fast-access store for frequently used data, while the mass storage device is used to store infrequently used data.
[0080] The networking subsystem 514 includes one or more devices configured to couple to a wired and / or wireless network and communicate over the wired and / or wireless network (i.e., to perform network operations), including: control logic 516, interface circuitry 518, and one or more antennas 520 (or antenna elements). (Although Figure 5 including one or more antennas 520, in some embodiments, the electronic device 500 includes one or more nodes, such as node 508, for example, pads, that may be coupled to the one or more antennas 520. Thus, the electronic device 500 may or may not include one or more antennas 520.) For example, the networking subsystem 514 may include a Bluetooth networking system, a cellular networking system (e.g., 3G / 4G / 5G networks, such as UMTS, LTE, etc.), a USB networking system, a networking system based on the standards described in IEEE 802.11 (e.g., a Wi-Fi networking system), an Ethernet networking system, and / or another networking system.
[0081] In some embodiments, a pattern shaper (such as a reflector) in one or more antennas 520 (or antenna elements) may be used to adapt or change the transmit antenna radiation pattern of the electronic device 500, and the one or more antennas 520 may be independently and selectively electrically coupled to ground to direct the transmit antenna radiation pattern in different directions. Thus, if the one or more antennas 520 include N antenna radiation pattern shapers, the one or more antennas 520 may have 2N different antenna radiation pattern configurations. More generally, a given antenna radiation pattern may include the amplitude and / or phase of a signal that specifies the direction of the main lobe or major lobe of the given antenna radiation pattern, as well as so-called "exclusion regions" or "exclusion zones" (sometimes referred to as "notches" or "nulls"). Note that the exclusion zone of a given antenna radiation pattern includes the low-intensity regions of the given antenna radiation pattern. Although the intensity is not necessarily zero in the exclusion zone, the intensity may be below a threshold, such as 4 dB or below the peak gain of the given antenna radiation pattern. Thus, a given antenna radiation pattern may include a local maximum of gain (e.g., a main beam) that points the maximum value in the direction of an electronic device of interest, and one or more local minima that reduce the gain in the directions of other electronic devices that are not of interest. In this way, a given antenna radiation pattern may be selected such that undesirable communications (such as communications with other electronic devices) are avoided to reduce or eliminate adverse effects, such as interference or crosstalk.
[0082] The networking subsystem 514 includes a processor, a controller, a radio / antenna, a socket / plug, and / or other devices for coupling to each supported network system, communicating on each supported network system, and processing data and events for each supported network system. Note that sometimes the mechanisms for coupling to the network for each network system, communicating on that network, and processing data and events on that network are collectively referred to as the "network interface" of the network system. Additionally, in some embodiments, a "network" or "connection" between electronic devices does not yet exist. Thus, the electronic device 500 may use the mechanisms in the networking subsystem 514 to perform simple wireless communication between electronic devices, e.g., sending frames and / or scanning for frames sent by other electronic devices.
[0083] Within the electronic device 500, the processing subsystem 510, the memory subsystem 512, and the networking subsystem 514 are coupled together using a bus 528. The bus 528 may include electrical, optical, and / or electro-optical connections that may be used by the subsystems to convey commands and data, etc. Although only one bus 528 is shown for clarity, different embodiments may include different numbers or configurations of electrical, optical, and / or electro-optical connections among the subsystems.
[0084] In some embodiments, the electronic device 500 includes a display subsystem 526 for displaying information on a display, which may include a display driver and a display, such as a liquid crystal display, a multi-touch screen, and the like.
[0085] The electronic device 500 can be (or can be included in) any electronic device having at least one network interface. For example, the electronic device 500 can be (or can include): a desktop computer, a laptop computer, a sub-notebook / netbook, a server, a computer, a mainframe computer, a cloud-based computer, a tablet computer, a smart phone, a cellular phone, a smart watch, a wearable device, a consumer electronic device, a portable computing device, an access point, a transceiver, a controller, a radio node, a router, a switch, a communication device, an access point, a test device, and / or other electronic devices.
[0086] Although specific components are used to describe the electronic device 500, in alternative embodiments, different components and / or subsystems may be present in the electronic device 500. For example, the electronic device 500 may include one or more additional processing subsystems, memory subsystems, networking subsystems, and / or display subsystems. Additionally, one or more of the subsystems may not be present in the electronic device 500. Further, in some embodiments, the electronic device 500 may include one or more additional subsystems not shown in Figure 5 In addition, although separate subsystems are shown in Figure 5 In some embodiments, some or all of a given subsystem or component may be integrated into one or more of other subsystems or components in the electronic device 500. For example, in some embodiments, the program instructions 522 are included in the operating system 524 and / or the control logic 516 is included in the interface circuit 518.
[0087] Moreover, any combination of analog and / or digital circuits can be used to implement the circuits and components in the electronic device 500, including: bipolar, PMOS, and / or NMOS gates or transistors. Further, the signals in these embodiments can include digital signals having approximately discrete values and / or analog signals having continuous values. Additionally, the components and circuits can be single-ended or differential, and the power supply can be single-polar or bipolar.
[0088] An integrated circuit (sometimes referred to as a "communication circuit" or "device for communication") can implement some or all of the functions of the networking subsystem 514. The integrated circuit can include hardware and / or software mechanisms that are used to transmit wireless signals from the electronic device 500 and receive signals at the electronic device 500 from other electronic devices. In addition to the mechanisms described herein, radio devices are generally known in the art and are not described in detail herein. Generally, the networking subsystem 514 and / or the integrated circuit can include any number of radio devices. Note that the radio devices in multiple radio embodiments operate in a manner similar to that of the described single radio embodiment.
[0089] In some embodiments, the networking subsystem 514 and / or the integrated circuit includes a configuration mechanism (such as one or more hardware and / or software mechanisms) that configures the radio to transmit and / or receive on a given communication channel (e.g., a given carrier frequency). For example, in some embodiments, the configuration mechanism can be used to switch the radio from monitoring and / or transmitting on a given communication channel to monitoring and / or transmitting on a different communication channel. (Note that "monitoring" as used herein includes receiving signals from other electronic devices and possibly performing one or more processing operations on the received signals)
[0090] Although the previous discussion uses Wi-Fi and / or Ethernet communication protocols as illustrative examples, in other embodiments, a variety of communication protocols can be used, and more generally, communication technologies can be used. Thus, communication technologies can be used in various network interfaces. In addition, although some of the operations in the foregoing embodiments are implemented in hardware or software, generally, the operations in the foregoing embodiments can be implemented in a variety of configurations and architectures. Thus, some or all of the operations in the foregoing embodiments can be performed in hardware, software, or both. For example, at least some of the operations in the communication technology can be implemented using program instructions 522, an operating system 524 (such as a driver for the interface circuit 518), or firmware in the interface circuit 518. Alternatively or additionally, at least some of the operations in the communication technology can be implemented in the physical layer, such as the hardware in the interface circuit 518.
[0091] The present disclosure can be implemented as any combination of a device, a system, an integrated circuit, and a computer program on a non-transitory computer-readable medium. One or more processors can be implemented as an integrated circuit (IC), an application-specific integrated circuit (ASIC), or a large-scale integrated circuit (LSI), a system LSI, a super LSI, or an ultra LSI component that executes some or all of the functions described in the present disclosure.
[0092] Software and computer programs (which may also be referred to as programs, software applications, applications, components, or code) include machine instructions for a programmable processor and can be implemented in a high-level procedural language, an object-oriented programming language, a functional programming language, a logic programming language, or an assembly language or machine language. The term "computer-readable storage medium" refers to any computer program product, apparatus, or device for providing machine instructions or data to a programmable data processor, such as a magnetic disk, an optical disk, a solid state storage device, a memory, and a programmable logic device (PLD), including a computer-readable medium that receives the machine instructions as a computer-readable signal.
[0093] By way of example, a computer-readable storage medium may include a dynamic random access memory (DRAM), a random access memory (RAM), a read only memory (ROM), an electrically erasable programmable read only memory (EEPROM), a compact disk read only memory (CD-ROM), or other optical disk storage device, a magnetic disk storage device, or other magnetic storage device, or any other medium that can be used to carry or store the desired computer-readable program code in the form of instructions or data structures and that is accessible by a general purpose or special purpose computer or a general purpose or special purpose processor. As used herein, a disk or disc includes a compact disc (CD), a laser disc, an optical disc, a digital versatile disc (DVD), a floppy disk, and a Blu-ray disc, where disks typically reproduce data magnetically and discs reproduce data optically by laser. Combinations of the above are also included within the scope of computer-readable media.
[0094] In addition, the above description provides examples and does not limit the scope, applicability, or configuration set forth in the claims. Changes may be made to the function and arrangement of the elements discussed without departing from the spirit and scope of the present disclosure. Various embodiments may omit, substitute, or add various processes or components as appropriate. For example, features described with respect to certain embodiments may be incorporated in other embodiments.
Claims
1. A method for implementing enhanced UPnP subscriptions, including, by a UPnP - enabled router: Receive a subscription message for subscription, where, The subscription message specifies a delivery Uniform Resource Locator (URL), where the delivery URL is the location to which the event message targeted by the subscription will be sent; Based on a whitelist, verify whether the IP address or domain name in the delivery URL is included in the whitelist, where verifying the whitelist includes: Determine whether there is a whitelist or whether the whitelist is empty, In response to determining that there is a whitelist and the whitelist is empty, or determining that there is no whitelist, verify whether the delivery URL is on the source IP; and Based on the verification result, determine whether to reject the subscription message.
2. The method according to claim 1, wherein The whitelist includes at least one of the following: IP addresses allowed to use the UPnP subscription function; and / or Domain names allowed to use the UPnP subscription function.
3. The method according to claim 2, wherein The IP addresses included in the whitelist are public IPs or private IPs, and the domain names included in the whitelist are public domain names or private domain names.
4. The method according to any one of claims 1-3, wherein, The publisher indicated by the subscription message is the router, and the method further includes: In response to determining not to reject the subscription message based on the verification result, determine that the subscription is accepted.
5. The method according to claim 4, further including: In response to the subscription being accepted, send an initial event message to the delivery URL.
6. The method according to claim 5, further including: In response to an event occurring at the router during the duration of the subscription, send a subsequent event message to the delivery URL.
7. The method according to claim 6, wherein The initial event message includes the name and initial value of an event - based variable that models the state of the router; The subsequent event message includes the updated value of the event - based variable when an event occurs at the router.
8. The method according to claim 7, wherein, The state of the router includes at least one of the following: The joining / leaving of UPnP devices under the router, and / or The working mode of UPnP devices under the router.
9. The method according to any one of claims 1-3, wherein The publisher indicated by the subscription message is a UPnP device under the router, and the method further includes: In response to determining not to reject the subscription message based on the verification result, send the verified subscription message to the UPnP device, where the UPnP device will send event messages to the delivery URL during the duration of the subscription.
10. The method according to any one of claims 1 - 3, further including: Receive a user configuration for the whitelist; And Store the whitelist configured based on the user configuration.
11. The method according to any one of claims 1-3, wherein, Verifying the whitelist includes: Based on the whitelist, verify whether the IP address or domain name in the delivery URL is included in the whitelist.
12. The method according to claim 1, wherein, The publisher indicated by the subscription message is a gateway IP, the whitelist includes the gateway IP, and the method includes: Establish a communication channel with the mobile terminal; In response to determining not to reject the subscription message based on the verification result, determine to accept the subscription; Send an initial event message to the mobile terminal via the communication channel.
13. A UPnP - enabled router, including: One or more processors, and A memory coupled to the one or more processors, the memory storing computer-readable program instructions that, when executed by the one or more processors, cause the one or more processors to perform the method according to any one of claims 1-12.
14. A modem comprising a UPnP-enabled router as claimed in claim 13.
15. The modem according to claim 14, wherein, The publisher indicated by the subscription message is the gateway IP, the whitelist includes the gateway IP, and the modem comprises: A mobile agent configured to: Establish a communication channel with a mobile terminal; Determine to accept the subscription in response to determining not to reject the subscription message based on the verification result; Send an initial event message to the mobile terminal.
16. A non-transitory computer-readable storage medium having stored thereon computer-readable program instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 1-12.
17. An apparatus for implementing enhanced UPnP subscriptions, comprising means for performing the operations of the method according to any one of claims 1-12.
Citation Information
Patent Citations
Method and apparatus for protecting personal information in a home network
US20100049965A1