Prevention of unauthorized access via WI-FI sharing in WI-FI networks

The method and system for managing Wi-Fi sharing in networks address unauthorized access and bandwidth inefficiencies by detecting and verifying client device identifiers, enhancing security and performance.

WO2026160561A1PCT designated stage Publication Date: 2026-07-30SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2025-10-01
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Wi-Fi sharing in networks leads to unauthorized access and inefficient bandwidth management, posing security risks and degrading network performance due to lack of control over connected clients.

Method used

A method and system for managing internet access in hotspot networks by detecting and verifying identifiers of secondary and ternary client devices using a database, blocking unauthorized access, and dynamically allocating bandwidth.

Benefits of technology

Enhances network security by preventing unauthorized access and optimizing bandwidth usage, ensuring a robust and efficient network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025015682_30072026_PF_FP_ABST
    Figure KR2025015682_30072026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments herein relate to managing internet access in hotspot network. The method includes detecting, by a host device, a one or more identifiers associated with secondary client devices and ternary client devices accessing the internet using the Wi-Fi hotspot of the host device. The method further includes determining whether each of the one or more identifiers is the same as or different from a corresponding set of authorized identifiers stored in a database. The method also includes blocking internet access over Wi-Fi sharing of the secondary client device or the internet access to the ternary client device via the hotspot of the host device when identifiers of at least one ternary client device are different from the corresponding set of authorized identifiers. Additionally, the method includes maintaining internet access of secondary client device or ternary client device using the Wi-Fi hotspot when all identifiers match the corresponding set of authorized identifiers.
Need to check novelty before this filing date? Find Prior Art

Description

PREVENTION OF UNAUTHORIZED ACCESS VIA WI-FI SHARING IN WI-FI NETWORKS

[0001] The disclosure generally relates to Wi-Fi networks, and more particularly, relates to the prevention of unauthorized access via Wi-Fi sharing in Wi-Fi networks.

[0002] The proliferation of Wi-Fi technology has revolutionized the way devices connect to the internet, offering flexibility and convenience for users across various environments such as homes, offices, and public spaces. A Wi-Fi hotspot is a physical location or device that provides internet access to other devices via a wireless connection. Generally, a hotspot allows devices such as smartphones, tablets, and laptops to connect to the internet without relying on mobile data or a wired Ethernet connection. This capability has become important in our connected world, where constant and reliable internet access is often necessary.

[0003] Wi-Fi sharing is a process that enables one device (for example, a smartphone, tablet, or computer) to provide internet access to another device by sharing its Wi-Fi connection. This functionality is particularly useful in scenarios where a device with internet access can extend that connectivity to other devices that are not directly connected to the primary Wi-Fi network. However, while Wi-Fi sharing offers significant convenience, it also introduces several challenges and potential problems.

[0004] In modern hotspot networks, devices that are directly connected to the hotspot can inadvertently extend the network through Wi-Fi sharing. This can lead to unauthorized internet access, as additional devices can connect to the network without the knowledge or consent of the network administrator. Such unauthorized access poses significant security risks, as it can expose the network to malicious activities and unauthorized data usage.

[0005] Furthermore, Wi-Fi sharing can compromise network security by creating additional entry points that are not monitored or controlled by the primary Wi-Fi access point (AP). This lack of control over Wi-Fi access points and the connected clients can result in vulnerabilities that malicious actors can exploit to gain unauthorized access to sensitive information or disrupt network operations.

[0006] Another issue associated with Wi-Fi sharing is inefficient bandwidth management. When connected clients share the internet through Wi-Fi sharing connections without the AP's knowledge, it can lead to unregulated bandwidth usage. This unregulated usage can degrade the overall network performance, leading to slower internet speeds and reduced quality of service for the connected devices. The AP is unable to effectively allocate and manage bandwidth resources, resulting in an imbalanced and suboptimal network experience.

[0007] Existing techniques for managing Wi-Fi networks often lack the necessary controls to regulate Wi-Fi access points and the connected clients. These techniques typically do not provide the AP with full visibility and control over the clients that are sharing the internet connection. As a result, addressing the issues of unauthorized access, compromised security, and inefficient bandwidth management remains a complex task.

[0008] The information disclosed in this background of the disclosure section is only for enhancement of understanding of the general background of the disclosure and should not be taken as an acknowledgement or any form of suggestion that this information forms the prior art already known to a person skilled in the art.

[0009] Additional aspects will be set forth in part in the description which follows and, in part, will be apparent from the description, or may be learned by practice of the presented embodiments. According to an example embodiment of the disclosure, a method for managing an internet access in hotspot networks is provided. The method includes detecting by a host device a one or more identifiers associated with a secondary client device and a ternary client device accessing a internet using a hotspot of the host device. Further, the method includes determining by the host device whether each of the one or more identifiers is the same or different from a corresponding set of authorized identifiers stored in a database accessible to the host device. Further, the method includes blocking the internet access over Wi-Fi sharing of the secondary client device or the internet access to the ternary client device via the hotspot of the host device in response that any of the one or more identifiers of the at least one ternary client device are different from the corresponding set of authorized identifiers. Also, the method includes maintaining the internet access over Wi-Fi sharing of the secondary client device or the internet access to the at least one ternary client device via the hotspot of the host device in response that all the one or more identifiers are the same from the corresponding set of authorized identifiers.

[0010] According to an example embodiment of the disclosure, a host device for managing internet access in hotspot networks is provided. The host device includes memory storing instructions and at least one processor. The instructions, when executed by the at least one processor individually or collectively, cause the host device to detect one or more identifiers associated with the secondary client device and the ternary client device accessing a internet using a hotspot of the host device. Further, the instructions, when executed by the at least one processor individually or collectively, cause the host device to determine whether each of the one or more identifiers is the same or different from a corresponding set of authorized identifiers stored in a database accessible to the host device. Further, the instructions, when executed by the at least one processor individually or collectively, cause the host device to block the internet access over Wi-Fi sharing of the secondary client device or the internet access to the ternary client device via the hotspot of the host device in response that any of the one or more identifiers of the ternary client device are different from the corresponding set of authorized identifiers. Also, the instructions, when executed by the at least one processor individually or collectively, cause the host device to maintain the internet access over Wi-Fi sharing of the secondary client device or the internet access to the ternary client device via the hotspot of the host device in response that the one or more identifiers are the same from the corresponding set of authorized identifiers.

[0011] According to an example embodiment of the disclosure, a non-transitory computer-readable storage medium storing one or more programs comprising instructions is provided. The instructions, when executed by the processor individually or collectively, cause a host device to detect one or more identifiers associated with the secondary client device and the ternary client device accessing a internet using a hotspot of the host device. Further, the instructions, when executed by the at least one processor individually or collectively, cause the host device to determine whether each of the one or more identifiers is the same or different from a corresponding set of authorized identifiers stored in a database accessible to the host device. Further, the instructions, when executed by the at least one processor individually or collectively, cause the host device to block the internet access over Wi-Fi sharing of the secondary client device or the internet access to the ternary client device via the hotspot of the host device in response that any of the one or more identifiers of the ternary client device are different from the corresponding set of authorized identifiers. Also, the instructions, when executed by the at least one processor individually or collectively, cause the host device to maintain the internet access over Wi-Fi sharing of the secondary client device or the internet access to the ternary client device via the hotspot of the host device in response that the one or more identifiers are the same from the corresponding set of authorized identifiers.

[0012] To further clarify the advantages and features of the disclosure, a more particular description of various example embodiments illustrated in the appended drawings is provided. It is appreciated that these drawings depict example embodiments and are therefore not to be considered limiting its scope. The disclosure will be described and explained with additional specificity and detail with reference to the accompanying drawings.

[0013] The above and other features, aspects, and advantages of certain embodiments of the disclosure will be more apparent from the following detailed description, taken in conjunction with the accompanying drawings in which like characters represent like parts throughout the drawings, an in which:

[0014] Fig. 1a is a schematic diagram that illustrates unauthorized sharing of internet from a mobile device to a client device through Wi-Fi sharing according to related art.

[0015] Fig. 1b is a schematic diagram that illustrates unauthorized internet sharing from a Wi-Fi access point to a client device according to related art.

[0016] Fig. 2 is a schematic diagram that illustrates the working of NAT according to related art.

[0017] Fig. 3a is a schematic diagram that illustrates the feature of locking the network for internet access according to related art.

[0018] Fig. 3b is a schematic diagram that illustrates the feature of pausing the internet according to related art.

[0019] Fig. 3c is a schematic diagram that illustrates the feature of a block list according to related art.

[0020] Fig. 4a is a schematic diagram that illustrates a scenario of a client device indirectly accessing the internet according to related art.

[0021] Fig. 4b is a schematic diagram that illustrates a scenario of a blocked client device accessing the internet indirectly according to related art.

[0022] Fig. 5a and Fig. 5b illustrate a User Equipment for managing internet access in hotspot networks according to various embodiments disclosed herein.

[0023] Fig. 6a is a schematic diagram that illustrates a scenario of blocking egress traffic for an unauthorized client device according to various embodiments of the disclosure.

[0024] Fig. 6b is a schematic diagram that illustrates a scenario of blocking ingress traffic for an unauthorized client device according to various embodiments of the disclosure.

[0025] Fig. 7a and Fig. 7b are flow diagrams that illustrate a method of managing internet access in hotspot networks according to various embodiments of the disclosure.

[0026] Fig. 8 is a flow diagram that illustrates a method for managing internet access in hotspot networks according to various embodiments of the disclosure.

[0027] Fig. 9a is a schematic diagram that illustrates a scenario of blocking Wi-Fi sharing for the connected clients according to various embodiments of the disclosure.

[0028] Fig. 9b is a schematic diagram that illustrates a scenario of selectively allowing and blocking Wi-Fi sharing for connected clients according to various embodiments of the disclosure.

[0029] Fig. 9c is a schematic diagram that illustrates a scenario of selectively blocking and allowing internet access to indirectly connected clients according to various embodiments of the disclosure.

[0030] Fig. 9d is a schematic diagram that illustrates a scenario of selectively blocking and allowing internet access to indirectly connected clients' port address according to various embodiments of the disclosure.

[0031] Fig. 10 is a flow diagram that illustrates a method for detecting a NAT port using a classification ML model according to various embodiments of the disclosure.

[0032] Fig. 11a and Fig. 11b are schematic diagrams that illustrates a scenario of selectively blocking and allowing internet access to indirectly connected clients according to various embodiments of the disclosure.

[0033] Fig. 12a is a flow diagram that illustrates a method of authorizing whether a client device is connected to a hotspot according to various embodiments of the disclosure.

[0034] Fig. 12b is a flow diagram that illustrates a method of sharing the socket address of a connected client device according to various embodiments of the disclosure.

[0035] Fig. 12c is a flow diagram that illustrates a method of authorizing the socket address of the client device with an allowed list according to various embodiments of the disclosure.

[0036] Further, skilled artisans will appreciate that elements in the drawings are illustrated for simplicity and may not have necessarily been drawn to scale. For example, the flow charts illustrate the method in terms of the most prominent steps / operations involved to help improve understanding of aspects of the disclosure. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the embodiments of the disclosure so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0037] It should be understood at the outset that although illustrative implementations of the embodiments of the disclosure are illustrated below, the disclosure may be implemented using any number of techniques, whether currently known or in existence. The disclosure should in no way be limited to the illustrative implementations, drawings, and techniques illustrated below, including the design and implementation illustrated and described herein, but may be modified within the scope of the appended claims along with their full scope of equivalents.

[0038] The term "some" as used herein is defined as "none, or one, or more than one, or all." Accordingly, the terms "none," "one," "more than one," "more than one, but not all" or "all" would all fall under the definition of "some." The term "some embodiments" may refer to no embodiments, to one embodiment or to several embodiments or to all embodiments. Accordingly, the term "some embodiments" is defined as meaning "no embodiment, or one embodiment, or more than one embodiment, or all embodiments."

[0039] The terminology and structure employed herein is for describing, teaching, and illuminating some embodiments and their specific features and elements and does not limit, restrict, or reduce the spirit and scope of the claims or their equivalents.

[0040] More specifically, any terms used herein such as but not limited to "includes," "comprises," "has," "consists," and grammatical variants thereof do NOT specify an exact limitation or restriction and certainly do NOT exclude the possible addition of one or more features or elements, unless otherwise stated, and furthermore must NOT be taken to exclude the possible removal of one or more of the listed features and elements, unless otherwise stated with the limiting language "MUST comprise" or "NEEDS TO include."

[0041] Whether or not a certain feature or element was limited to being used only once, either way, it may still be referred to as "one or more features" or "one or more elements" or "at least one feature" or "at least one element." Furthermore, the use of the terms "one or more" or "at least one" feature or element does NOT preclude there being none of that feature or element, unless otherwise specified by limiting language such as "there NEEDS to be one or more . . ." or "one or more element is REQUIRED."

[0042] Unless otherwise defined, all terms, and especially any technical and / or scientific terms, used herein may be taken to have the same meaning as commonly understood by one having ordinary skill in the art.

[0043] It is to be understood that a singular form of a noun corresponding to an item may include one or more of the things, unless the relevant context clearly indicates otherwise. As used herein, each of such phrases as "A or B," "at least one of A and B," "at least one of A or B," "A, B, or C," "at least one of A, B, and C," and "at least one of A, B, or C," may include any one of, or all possible combinations of the items enumerated together in a corresponding one of the phrases. It is to be understood that if an element (e.g., a first element) is referred to, with or without the term "operatively" or "communicatively", as "coupled with," "coupled to," "connected with," or "connected to" another element (e.g., a second element), it means that the element may be coupled with the other element directly (e.g., wired), wirelessly, or via a third element.

[0044] Referring now to the drawings and more particularly to Figs. 1 through 12, where similar reference characters denote corresponding features throughout the figure, these are shown preferred embodiments.

[0045] Fig. 1a is a schematic diagram that illustrates unauthorized sharing of the internet from a mobile device to a client device through Wi-Fi sharing according to related art. Consider a scenario where a device A (101) is sharing internet access through a mobile hotspot to the device B (103). Further, the device B (103) shares the internet access with the device C (105) using Wi-Fi sharing. Thus, the device C (105) is indirectly using the internet access from device A (101). However, the device A (101) is not aware that the device C (105) is using internet access and also does not have control over the connected client devices that are using the Wi-Fi sharing feature.

[0046] In an example embodiment, the device A (107) (e.g. hard AP / router) may be a Wi-Fi access point or Wi-Fi router that is providing internet access to device B (103) as shown in Fig. 1b. Further, the device B (103) shares the internet access with the device C (105) using Wi-Fi sharing. Thus, the device C (105) is indirectly using the internet access from device A (107). However, the device A (101) is not aware that the device C (105) is using internet access and also does not have control over the connected client devices that are using the Wi-Fi sharing feature.

[0047] Fig. 2 is a schematic diagram that illustrates the working of network address translation (NAT) according to related art. NAT is defined as the process of mapping private internet protocol (IP) addresses to a single public IP address while information is being transferred via a router or NAT firewall. For example, consider a host A device (201) that sends some information towards a server S1 (205) through a router R1 (203). The router R1 (203) converts the private IP address of the host A device (201) into a public IP address before sending the information to the server S1 (205). Further, the server S1 (205) provides the requested information to the host A device (201) through the router R1 (203). The server S1 (205) sends the requested information to the router R1 (203) using the public address. Further, the router R1 (203) maps the public IP address to the private IP address for the host A device (201) for further sending the requested information.

[0048] There are different types of NAT, such as static NAT, dynamic NAT, and NAT with port address translation (PAT). The static NAT maps a private IP address for the network device (network device is interchangeably used as host A device) (201) to a single public IP address. This is called static translation because the mapping is not dynamic and does not change over time. Further, the dynamic NAT maps private IP addresses with a pool of public IP addresses on a first-come, first-served basis. Whenever a private network device needs to access the internet, an available public IP address from the pool is assigned. Thus, the dynamic NAT is secure and fast. However, a drawback of dynamic NAT is that the host device A (201) wait when the pool runs out of available public IP addresses.

[0049] The NAT with PAT is also referred to as network address port translation (NAPT). The NAPT allows several private network devices to share the same public IP address through multiple port numbers. A unique port number gets assigned to each device over a private network whenever they need to communicate over the internet. During the communication, the NAT router (203) translates the port number and the private IP address into a single port number and public IP address. As a result, multiple devices may communicate easily and fast over the internet by using a single public IP address.

[0050] The mapping process between private IP addresses and public IP addresses in NAT occurs through NAT tables. The NAT tables refer to data structures that are stored by the NAT router. When a private IP address requires access to the internet, it gets mapped to a public IP address to mask its identity over the internet. However, once the internet sends back the responses, the public IP address gets converted into a private IP address. An example of the NAT table is as shown in the table 1 below.

[0051] SourcePCIP AddressSourcePort numberWAN addressSource Port numberA192.168.1.10025 (SMTP)24.37.63.121024B192.168.1.10180 (HTTP)24.37.63.121025C192.168.1.10280 (HTTP)24.37.63.121026C192.168.1.10221 (FTP control)24.37.63.121027

[0052] Fig. 3a is a schematic diagram that illustrates a feature of a locking network for internet access according to related art. The Lock Network feature in a mobile device does not allow new devices to connect to the mobile hotspot other than those already connected. Users of the mobile device may secure the mobile hotspot by limiting the number of connected devices. This lock network feature is a control-based setting that enables users to easily lock the hotspot with the present set of connected devices for enhanced privacy and control.For example, at S301, the user of the mobile device may click on the lock hotspot option displayed on the mobile device. At S303, the user may confirm the locking of the mobile hotspot usage for new devices that are requesting to connect. Subsequently, at S305, the mobile device locks the mobile hotspot, preventing it from being shared with new devices that are requesting to connect. Finally, at S307, the mobile device may display the internet consumed by the connected devices through the mobile hotspot.

[0053] Fig. 3b is a schematic diagram that illustrates a feature of pause internet according to related art. The Pause Internet feature allows the hotspot user to pause the internet access of connected devices with the click of a button. The internet access of the connected devices may be paused after exceeding a specified data usage limit. For example, at S309, when the user has set the specified data usage limit to 18MB, the internet access of the connected device may be paused once the data usage exceeds 18MB.

[0054] Fig. 3c is a schematic diagram that illustrates a feature of the block list according to embodiments disclosed herein. The block list feature in mobile devices will block one or more other devices from connecting to the mobile hotspot or from accessing Wi-Fi internet. The mobile hotspot user may add the medium access control (MAC) address of the connected device to the block list, and the given device will not be able to connect to the mobile hotspot. For example, at 311, the mobile device detects the MAC address of the connected devices. Further, at 313 and 315, the user of the mobile device may add the MAC address of the connected devices to the block list to block internet access through the mobile hotspot. Thus, features such as the lock feature, pause feature, and block feature restrict internet access either by blocking the internet access or preventing the connected device from accessing the internet.

[0055] Fig. 4a is a schematic diagram illustrating a scenario of a client device indirectly accessing the internet according to related art. In this scenario, device A (101) shares internet access via a mobile hotspot with connected client device B (103) and other devices (111, 113). Device B (103), connected to hotspot of device A (101), uses Wi-Fi Sharing to share its connection with device C (105). Further, device B (103) allows device C (105) to connect to its hotspot and access the internet. Consequently, device C (105) uses the internet of device A (101) indirectly through device B (103). Device A (101) remains unaware of the indirect usage of its internet access and lacks control over the internet usage by the indirectly connected device C (105).

[0056] Fig. 4b is a schematic diagram illustrating a scenario of a blocked client device accessing the internet indirectly according to related art. In this scenario, device A (101) shares internet access via a mobile hotspot with connected client device B (103) and other devices (109, 111, 113). Device B (103), connected to device A (101) hotspot, uses Wi-Fi Sharing to share its connection with device C (105). Further, device B (103) allows device C (105) to connect to its hotspot and access the internet. Device C (105) is not part of the allowed device list or is on a blocked list, yet it is still able to use internet access from device A (101) indirectly through device B (103). Therefore, there is a need for managing authorized client access to provide internet access.

[0057] Fig. 5a is a block diagram of a system that illustrates managing internet access in networks according to embodiments disclosed herein. The system (500) may include one or more devices that are connected to each other. For example, the system (500) may be, but is not limited to, a multi-user environment, a wireless communication system, and a telecommunication system. The system may include a host device (501) that is connected to at least one secondary client device (503, 505). Further, the secondary client device (503) is connected with at least one ternary client device (507, 509, 511). The system (500) is connected in a multi-hop environment. The host device may be a user equipment device that provides internet access to at least one secondary client device (503, 505) and the ternary client device (507, 509, 511). For example, the host device (501) may be a mobile phone, a Wi-Fi access point, a Wi-Fi router, and the like. Similarly, at least one secondary client device (503, 505) and the ternary client device (507, 509, 511) may be, but are not limited to, mobile phones, laptops, desktops, IoT devices, and the like. The host device (501) blocks all the ternary client devices (507, 509, 511) or the selected ternary client devices (507, 509, 511) from accessing the Wi-Fi sharing from at least one secondary client device (503, 505).

[0058] In addition to blocking internet access, the host device (501) may also manage the quality of service (QoS) for the connected secondary and ternary client devices. This may include prioritizing certain types of internet traffic, such as video streaming or online gaming, to ensure a smooth and uninterrupted user experience. The host device (501) may dynamically allocate bandwidth based on the current network load and the specific requirements of each client device. For instance, if a secondary client device (503) is engaged in a video conference, the host device (501) may allocate more bandwidth to it while temporarily reducing the bandwidth for less critical activities on other devices. This dynamic management helps in maintaining an efficient and user-friendly network environment.

[0059] Moreover, the system (500) may incorporate security measures to protect the integrity and confidentiality of the data being transmitted. The host device (501) may implement encryption protocols to secure the communication between the devices. Further, it may monitor for any suspicious activities or unauthorized access attempts, ensuring that authenticated devices are allowed to connect to the network. The use of international mobile equipment identity (IMEI) numbers and NAT ports for selective blocking and allowing of internet access adds an extra layer of security, as it ensures that recognized devices may access the network. This is particularly important in environments where sensitive information is being transmitted, such as in corporate networks or smart home systems.

[0060] Further, the host device (501) selectively blocks and allows internet access to the ternary client devices (507, 509, 511) and port addresses of the ternary client devices (507, 509, 511). The selective blocking and allowing of internet access is performed by utilizing at least one of the hash IMEI number and pair of IMEI hash and NAT port. The pair of the IMEI hash and NAT port of at least one ternary client device (507, 509, 511) is shared by the secondary client device (503, 505) to the host device (501). This ensures that the host device (501) maintains control over the network, preventing unauthorized devices from gaining access and potentially compromising the network's security. By managing the internet access at multiple levels, the system (500) provides a robust solution for maintaining a secure and efficient network environment.

[0061] Fig. 5b illustrates host device for managing internet access in networks, according to embodiments disclosed herein. The host device (501) may include a processor (513), a memory (515), an I / O interface (517), and a Wi-Fi access controller (519). Furthermore, the processor (513) of the host device (501) communicates with the memory (515), the I / O interface (517), and the Wi-Fi access controller (519).

[0062] The processor (513) is configured to execute instructions stored in the memory (515) and to perform various processes. The processor (513) may include one or a plurality of processors, may be a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an artificial intelligence (AI) dedicated processor such as a neural processing unit (NPU). Furthermore, the multi-core processor 208 may include various processing circuitry and / or multiple processors. For example, as used herein, including the claims, the term "processor" may include various processing circuitry, including at least one processor, wherein one or more of at least one processor, individually and / or collectively in a distributed manner, may be configured to perform various functions described herein. As used herein, when "a processor", "at least one processor", and "one or more processors" are described as being configured to perform numerous functions, these terms cover situations, for example and without limitation, in which one processor performs some of recited functions and another processor(s) performs other of recited functions, and also situations in which a single processor may perform all recited functions. Additionally, the at least one processor may include a combination of processors performing various of the recited / disclosed functions, e.g., in a distributed manner. At least one processor may execute program instructions to achieve or perform various functions.

[0063] Furthermore, the memory (515) of the host device (501) may include storage locations that may be addressed through the processor (513). The memory (515) is not limited to volatile or non-volatile memory and may include one or more computer-readable storage media. Non-volatile storage elements such as magnetic hard disks, optical discs, floppy discs, flash memories, EPROM, or EEPROM memories may also be included in the memory (515). Further, the memory (515) of the host device (501) may store various information received from the one or more connected devices. The host device (501) stores the one or more information such as IP address, MAC address and socket address of the at least one client devices that are connected to the host device (501).

[0064] The I / O interface (517) transmits information between the memory (515) and external peripheral devices, which are input-output devices associated with the host device (501). The I / O interface (517) receives various information from the one or more client devices. This information may include, but is not limited to, IP address, MAC address and the socket address.

[0065] The Wi-Fi access controller (519) communicates with the I / O interface (517) and memory (515) for managing authorized client access to Wi-Fi hotspot hosted by host device. The Wi-Fi access controller (519) is an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.

[0066] The Wi-Fi access controller (519) of the host device (501) detects a one or more identifiers associated with secondary client devices (503, 505) and ternary client devices (507, 509, 511) accessing the internet using the Wi-Fi hotspot of the host device (501). It determines whether each of the identifiers is the same as or different from the corresponding set of authorized identifiers stored in a database accessible to the host device (501). When any of the one or more identifiers of the ternary client devices (507, 509, 511) are different from the corresponding set of authorized identifiers, the Wi-Fi access controller (519) blocks the internet access over Wi-Fi sharing for the secondary client devices (503, 505) or the internet access to the ternary client devices (507, 509, 511) via the hotspot of the host device (501). Further, the Wi-Fi access controller (519) maintains the internet access over Wi-Fi sharing for the secondary client devices (503, 505) or the internet access to the ternary client devices (507, 509, 511) using the Wi-Fi hotspot of the host device (501) when all the one or more identifiers match the corresponding set of authorized identifiers.

[0067] In an example embodiment, the socket address and hash of IMEI is used for verifying the legitimacy of the devices attempting to access the network. The Socket address may include an IP address and a port number. This combination of identifiers ensures a robust mechanism for verifying the legitimacy of the devices attempting to access the network. By cross-referencing these identifiers with the authorized set stored in the database, the Wi-Fi access controller (519) may effectively prevent unauthorized access, thereby enhancing the security of the network. The use of hash of IMEI numbers, which are unique to each mobile device, coupled with IP addresses and port numbers, provides a multi-layered approach to authentication that is difficult to bypass.

[0068] In an example embodiment, the authorized identifiers define permissible access parameters for the secondary client devices (503, 505) and the ternary client device (507, 509, 511) connecting to the hotspot. These parameters may include specific time frames during which access is allowed, bandwidth limitations, and priority levels for different types of data traffic. By defining these parameters, the Wi-Fi access controller (519) may manage network resources more efficiently, ensuring that applications receive the necessary bandwidth while preventing network congestion caused by non-essential traffic. This approach not only improves the overall performance of the network but also enhances the user experience by providing consistent and reliable internet access.

[0069] In an example embodiment, the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) are directly connected to the host device (501) using the Wi-Fi hotspot of the host device (501). Further, the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) are indirectly connected to the host device (501) by establishing a Wi-Fi connection between the ternary client devices (507, 509, 511) and the secondary client devices. Furthermore, the Wi-Fi access controller (519) connects the secondary client devices (503, 505) directly to the host device (501) using the hotspot feature of the host device (501), thereby enabling the ternary client devices (507, 509, 511) to access the network via the host device (501).

[0070] In an example embodiment, a method is provided to determine whether each of the identifiers is the same as or different from a corresponding set of authorized identifiers stored in a database accessible to the host device (501). The Wi-Fi access controller (519) identifies whether data traffic is ingress traffic or egress traffic. Further, the Wi-Fi access controller (519) assesses whether the source IP address in the ingress traffic or the destination IP address in the egress traffic differs from the corresponding set of authorized IP addresses stored in the database. The connected client device utilizes either dynamic NAT or static NAT. Furthermore, the Wi-Fi access controller (519) blocks internet access over Wi-Fi sharing for the secondary client device when the source IP address in the ingress traffic or the destination IP address in the egress traffic is different from the allowed IP address. Further, the Wi-Fi access controller (519) grants internet access over Wi-Fi sharing to the secondary client device when the source IP address in the ingress traffic or the destination IP address in the egress traffic matches the corresponding set of authorized IP addresses stored in the database.

[0071] In an example embodiment, the Wi-Fi access controller (519) determines whether the one or more identifiers is the same as or different from the corresponding set of authorized identifiers. This determination involves identifying whether the data traffic is egress traffic or ingress traffic. When the data traffic is egress traffic, the Wi-Fi access controller (519) modifies the TTL value to 1 or sets the hop limit to 1. The secondary client device (503, 505) employs NAT with port address translation (PAT). Further, when the data traffic is ingress traffic, the Wi-Fi access controller (519) uses a machine learning (ML) model to determine whether the port is the NAT port. The secondary client device (503, 505) continues to use NAT with PAT.

[0072] In an example embodiment, the Wi-Fi access controller (519) determines whether the port is the NAT port by extracting a flow-based feature of the data traffic. The flow-based feature may include, but is not limited to, network traffic data, data packet size, timing, and flow duration of the ingress data packets. Further, the Wi-Fi access controller (519) combines the flow-based features of the data traffic to identify traffic patterns associated with the NAT ports. The combined flow-based features are classified by the Wi-Fi access controller (519) into either the non-NAT port or the NAT port based on the combined flow-based features using the ML model.

[0073] In an example embodiment, the Wi-Fi access controller (519) determines whether the one or more identifiers is the same as or different from the corresponding set of authorized identifiers. The determination involves checking whether the MAC address of the secondary client device (503, 505) and the ternary client device (507, 509, 511) is different from the corresponding set of authorized MAC addresses stored in the database. Upon making this determination, the Wi-Fi access controller (519) blocks internet access over Wi-Fi sharing to the secondary client device (503, 505) or the ternary client device (507, 509, 511) if their MAC addresses are different from the authorized set. Further, the Wi-Fi access controller (519) provides internet access over Wi-Fi sharing to the secondary client device (503, 505) or the ternary client device (507, 509, 511) if their MAC addresses match the authorized set stored in the database.

[0074] In an example embodiment, the Wi-Fi access controller (519) determines whether each of the identifiers is the same as or different from the corresponding set of authorized identifiers. The Wi-Fi access controller (519) receives the IMEI hash value and NAT port number of the secondary client device (503, 505) and of the ternary client device. Further, the Wi-Fi access controller (519) determines whether the IMEI hash value and NAT port number of the secondary client device (503, 505) and of the ternary client device (507, 509, 511) are different from the corresponding set of authorized IMEI hash values and NAT port numbers stored in the database. Further, the Wi-Fi access controller (519) blocks the internet access over Wi-Fi sharing to the secondary client device (503, 505) or the internet access to the ternary client device when at least one of the IMEI hash values and NAT port numbers of the secondary client device (503, 505) and of the ternary client device (507, 509, 511) is different from the corresponding set of authorized IMEI hash values and NAT port numbers stored in the database. Further, in response to the determination, the Wi-Fi access controller (519) provides the internet access over Wi-Fi sharing to the secondary client device (503, 505) or the internet access to the ternary client device when the IMEI hash value and NAT port number of the secondary client device (503, 505) and the ternary client device (507, 509, 511) are not different from the corresponding set of authorized IMEI hash values and NAT port numbers stored in the database.

[0075] In an example embodiment to block the internet access over Wi-Fi sharing of the secondary client device (503, 505) or the internet access to the ternary client device (507, 509, 511), the Wi-Fi access controller (519) drops the plurality of data packets of the ternary client device when any of the one or more identifiers of the ternary client device (507, 509, 511) are different from the corresponding set of authorized identifiers. This ensures that unauthorized devices are not able to access the internet through the Wi-Fi network, thereby maintaining the security and integrity of the network. The dropping of data packets acts as a preventive measure to safeguard against potential security breaches and unauthorized access attempts.

[0076] In an example embodiment to maintain the access to the internet of Wi-Fi sharing, the Wi-Fi access controller (519) forwards the plurality of data packets of the ternary client device (507, 509, 511) to the secondary client device (503, 505) for providing the internet access over Wi-Fi sharing when all the one or more identifiers are the same as the corresponding set of authorized identifiers.

[0077] In an example embodiment, the one or more identifiers may include, but not be limited to, the socket address of a client device, the hash of the IMEI number of the client device, the MAC address of the client device, and the IP address of the client device. These identifiers serve as unique markers that help in distinguishing between authorized and unauthorized devices. The use of multiple identifiers enhances the security of the network by providing multiple layers of verification. By cross-referencing these identifiers with the authorized set stored in the database, the Wi-Fi access controller (519) may accurately determine the legitimacy of devices attempting to connect to the network. This multi-faceted approach to device verification ensures a robust and secure Wi-Fi sharing environment.

[0078] Fig. 6a is a schematic diagram illustrating a scenario of blocking egress traffic for an unauthorized client device according to embodiments disclosed herein. The disclosure blocks the internet connection for indirectly connected client devices or unauthorized client devices. Internet access may be blocked by obstructing at least one of egress traffic, ingress traffic, or both.

[0079] Egress traffic refers to the data that leaves the network and needs to be sent to an external destination. Similarly, ingress traffic is the data that enters the network from a device or external source into the local network, typically from the device to the router or access point. As shown in Fig. 6a, the egress traffic associated with the host device (501) moving from the network (e.g. internet) (601) towards the ternary client device (507) is blocked or dropped when the identifiers of the ternary client device (507) are not present in the set of authorized identifiers. For example, if the identifiers associated with the ternary client device (507) are not present in the set of authorized identifiers, the network (601) may block or drop the egress traffic transmitted to the ternary client device (507).

[0080] Similarly, as shown in Fig. 6b, internet access to the unauthorized client device may be blocked by obstructing the ingress traffic received from the unauthorized client device. For instance, if the identifiers associated with the ternary client device (507) are not present in the set of authorized identifiers, the ingress traffic received from the ternary client device (507) is blocked or dropped, resulting in the internet access to the ternary client device (507) being blocked.

[0081] Fig 7a is a flow diagram that illustrates a method for managing the authorized client access to the Wi-Fi hotspot hosted by the host device according to the embodiments disclosed herein. At operation 701, the method may include detecting the one or more identifiers associated with the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) accessing the internet using the Wi-Fi hotspot of the host device (501). At operation 703, the method may include determining whether each of the identifiers is the same or different from the corresponding set of authorized identifiers stored in a database accessible to the host device (501). At operation 705, the method may include blocking the internet access over Wi-Fi sharing of the secondary client devices (503, 505) or the internet access to the ternary client devices (507, 509, 511) via the hotspot of the host device (501) when any of the one or more identifiers of the ternary client devices (507, 509, 511) are different from the corresponding set of authorized identifiers. At operation 707, the method may include maintaining the access to the internet of Wi-Fi sharing of the secondary client devices (503, 505) or the internet access to the ternary client devices (507, 509, 511) using the Wi-Fi hotspot of the host device (501) when all the one or more identifiers are the same from the corresponding set of authorized identifiers.

[0082] Fig 7b is the flow diagram that illustrates the method of preventing unauthorized client access to the Wi-Fi hotspot hosted by the host device in each layer according to embodiments disclosed herein. The disclosure uses a multi-layered approach to block the unauthorized client sharing through network traffic by monitoring the data traffic and comparing the IP address in the egress traffic and ingress traffic. Further, MAC address filtering is performed for specific ternary client device (507, 509, 511) authorization and ensures designated devices may share the internet. Further, the blocking or allowing of the internet access to the indirectly connected client devices (507, 509, 511) (hereinafter indirectly connected client devices is interchangeably used as ternary client device) is enhanced by verifying the hash of IMEI and NAT port number matches with the allowed list of IMEI and port numbers. Thus, the proposed solution ensures secure and managed network extensions.

[0083] At operation 709, the method may include monitoring data traffic that is received from the one or more client devices. The one or more client devices may be the secondary client devices (503, 505) and the ternary client devices (507, 509, 511). At operation 711, the method may include determining whether the data traffic is the egress traffic or the ingress traffic. Further, determining whether the source IP address of the ternary client device (507, 509, 511) matches with the allowed IP list when the data traffic is the ingress traffic. Similarly, the method may include determining whether the destination IP address of the ternary client device (507, 509, 511) matches with the allowed IP list when the data traffic is the egress traffic. Further, the data traffic associated with the ternary client device (507, 509, 511) for which the source IP address or the destination IP address does not match with the allowed IP list is dropped or blocked.

[0084] At operation 713, the method may include determining whether the MAC address of the secondary client devices (503, 505) matches with the list of allowed MAC addresses. Further, the internet access over Wi-Fi sharing is provided to the secondary client devices (503, 505) for which the MAC address of the secondary client devices (503, 505) matches with the allowed MAC address list. At operation 715, the method may include authorizing the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) connected to the host device (501). The secondary client devices and the ternary client devices (507, 509, 511) are authorized by matching the hash of IMEI with the NAT port. Further, providing the internet access to the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) for which the hash of IMEI and NAT port match is found. Also, the method may include blocking the internet access to the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) for which the hash of IMEI and NAT port match is not found.

[0085] At operation 717, the method may include performing a port-based authorization of the ternary client devices (507, 509, 511) to selectively allow internet access. The port-based authorization of the ternary client devices (507, 509, 511) is performed by matching the NAT port of the ternary client devices (507, 509, 511) with the allowed NAT port list. Further, the method may include providing internet access to the ternary client devices (507, 509, 511) for which the NAT port is present in the allowed NAT port list. Also, the method may include blocking internet access to the ternary client devices (507, 509, 511) for which the NAT port is not present in the allowed NAT port list.

[0086] At operations 719 and 721, the method may include handling the egress traffic and the ingress traffic for providing internet access to the ternary client devices (507, 509, 511). The ingress traffic and the egress traffic are blocked when at least one IP address, MAC address, socket address, or NAT port of the ternary client devices (507, 509, 511) is not present in the allowed list of MAC addresses, IP addresses, socket addresses, and NAT ports.

[0087] This comprehensive solution ensures that authorized devices may access the network, thereby enhancing the security and integrity of the Wi-Fi hotspot provided by the host device (501). The multi-layered security checks, including IP address verification, MAC address filtering, hash of IMEI and NAT port matching, and port-based authorization, work in tandem to create a robust and secure network environment.

[0088] Fig. 8 is the flow diagram that illustrates the method for preventing unauthorized clients from accessing the Wi-Fi hotspot hosted by the host device according to embodiments disclosed herein. At operation 801, the method may include receiving by the host device (501) a plurality of data packets from at least one secondary client device (503, 505). At operation 803, the method may include determining by the host device (501) whether the socket address in the received data packets matches with the allowed list of socket addresses. The socket address may include the IP address and the port number.

[0089] The host device (501) determines whether the socket address of the ternary client device (507, 509, 511) matches the allowed list of socket addresses. This determination is performed by selectively blocking or allowing internet access to the indirectly connected clients (507, 509, 511), also referred to as ternary client devices, based on their hash of IMEI and NAT port.

[0090] For example, as illustrated in Fig. 9c, the host device (501) connects to secondary client devices (503, 505, 521). These connected client devices (503, 505, 521) share their corresponding tuple information, which may include the hash of IMEI number and NAT port, with the host device (501). Further, the connected client device (505) forwards the tuple information of its further connected client devices, or ternary connected client devices (507, 509), to the host device (501).

[0091] The host device (501) checks whether the NAT port of the client devices (503, 505, 521, 507, 509) is associated with the allowed IMEI list. Internet access is provided by the host device (501) to the connected client devices (503, 505, 521, 509) whose NAT port is associated with the allowed IMEI list. Further, the host device (501) blocks internet access to the client device (507) whose NAT port does not match the allowed IMEI list.

[0092] In an example embodiment, consider a scenario as shown in Fig. 11a where the host device (501) is connected with the secondary client devices (503, 505, 521, 523). The secondary connected client devices (503, 505, 521, 523) send the hash of the IMEI number to the host device (501). The hash of IMEI number serves as the unique identification for the secondary client devices (503, 505, 521, 523) in the hotspot network.

[0093] Further, consider the secondary connected client device (503) gets disconnected from the host device (501) and is connected to the client device (505) for accessing the internet. Further, another ternary client device (507) is connected to the secondary client device (505). Further as shown in Fig. 11b the secondary connected client devices (505, 521, 523) sends the hash IMEI number of the ternary client devices (503, 507) to the host device (501). Upon receiving the hash IMEI numbers, the host device (501) matches the received hash IMEI numbers of the client devices (503, 505, 507, 521, 523) with the allowed IMEI list. The host device (501) provides internet access to the client devices (503, 505, 521, 523) since the hash IMEI numbers match with the allowed IMEI list. Thus, even though the client device (503) is accessing the internet through the client device (523), the host device (501) provides internet access to the client device (503) through the client device (523) since the hash of the IMEI number of the client device (503) is in the allowed IMEI list. However, the host device (501) does not provide internet access to the client device (507) since the hash of IMEI number does not match with the allowed IMEI list. Thus, the host device (501) may selectively allow or selectively block internet access to the indirectly connected clients (503, 507) based on the hash of IMEI number and the port number of the corresponding client device.

[0094] In an example embodiment, the host device (501) determines whether the socket address included in the received data packets matches with an allowed list of socket addresses. This determination is performed by selectively blocking or allowing internet access to the indirectly connected clients (507, 509) based on their port addresses. The host device (501) checks if the port number included in the received data packets matches the allowed list of port numbers, which may be selected by users.

[0095] Further, the host device (501) selectively provides internet access over Wi-Fi sharing to some of the secondary connected client devices (503, 505) and the indirectly connected client devices (507, 509) based on the allowed list of port numbers. For example, as shown in Fig. 9d, the host device (501) is connected with secondary client devices (503, 505, 521), and ternary client devices (507, 509) are connected with the secondary client device (505). The secondary client devices (503, 505, 521) send their corresponding hash IMEI numbers along with port numbers to the host device (501). The secondary client device (505) also sends the hash of IMEI numbers and port numbers of its connected ternary client devices (507, 509) which is used by secondary client device (505) when using PAT for Wi-Fi sharing.

[0096] The host device (501) matches the hash of IMEI numbers with the allowed IMEI list and matches the port numbers with the allowed port list, which is selected by users for internet access provision. The host device (501) selectively provides internet access to the ternary client device through the Wi-Fi sharing of the secondary client device (505) if the hash of IMEI number matches the allowed IMEI list. The host device (501) also matches the port number (901, 903) of the ternary connected client device (509) with the allowed port list. Internet access is provided to port 1 (901) since it matches the allowed port list, while access is blocked to port 2 (903) due to no match in the allowed port list. Similarly, internet access is blocked to the ternary client device (507) through Wi-Fi sharing with the secondary client device (505) if the hash of IMEI number does not match the allowed IMEI list.

[0097] Thus, the host device (501) may selectively allow and block internet access over Wi-Fi sharing to the connected client devices (503, 505) based on the socket addresses of the secondary client devices (503, 505). The host device (501) may effectively control which secondary client devices (503, 505) may extend the network and determine which indirectly connected devices and applications may access the internet.

[0098] At operation 817, the host device (501) forwards the data packets to the secondary client devices (503, 505) when the socket address in the data packets matches the with the allowed socket address list at operation 803. Further, if the socket address in the data packets does not match with the allowed socket address list, at operation 805, the host device (501) determines whether the data traffic is egress traffic or ingress traffic.

[0099] If the data traffic is determined to be egress traffic, at operation 807, the method may include determining whether the destination MAC address included in the data packets of the egress traffic matches the allowed MAC address list. Further, if the data traffic is determined to be ingress traffic, at operation 809, the method may include determining whether the source MAC address included in the data packets of the ingress traffic matches the allowed MAC address list.

[0100] Furthermore, when the destination MAC address or the source MAC address is included in the allowed MAC address list, at operation 817, the host device forwards the data packets to the corresponding client devices for which the destination MAC address or the source MAC address matches the allowed MAC address list.

[0101] For example, consider a scenario as shown in Fig. 9bthe host device (501) is connected with the secondary client devices (503, 505, 521). Further, when the data packets are received from the secondary client devices (503,505, 521), the host device (501) determines whether the MAC address included in the received data packets matches with the allowed MAC address list. The allowed MAC address list may be selected and provided by the user. The allowed MAC address list is used to filter the egress traffic and ingress traffic and ensures that authorized devices that are having the MAC address for which is present in the MAC address list are allowed to extend the internet access over Wi-Fi sharing to the ternary client devices (507, 509,511). Further, the host device (501), forwards the data packets for which the MAC address matches with the allowed MAC address list. For example, MAC address included in the data packets received from the secondary client devices (503, 521) matches with the allowed MAC address list, the host device (501) forwards the data packets to the secondary client device (503, 521) hence the host device (501) allows the secondary client devices (503, 521) to provide the internet access over Wi-Fi sharing. However, the MAC address of the data packets received from the secondary client device (505) is not present in the allowed MAC address list and hence, the host device (501) does not forward the data packet to the secondary client device (505). Further, the data packets are verified based on the IP address, when the MAC address of the data packet does not match with the allowed MAC address list. Thus, the authorization of the secondary client devices (503, 505, 521) using the MAC address provides the user with flexible and granular control over their network, and enabling the users to manage permissions effectively and prevent unauthorized access.

[0102] When the destination MAC address or the source MAC address does not match with the allowed MAC address list and when the data traffic is the egress traffic, at operation 811, the host device (501) determines whether the destination IP address included in the data packets matches with the IP address of the connected client devices.

[0103] Also, when the destination MAC address or the source MAC address does not match with the allowed MAC address list and when the data traffic is the ingress traffic, at operation 813, the host device (501) determines whether the source IP address included in the data packets matches with the IP address of the connected client device.

[0104] Particularly, when the connected client devices (503, 505) are using dynamic NAT or static NAT, the host device (501) is aware of the IP address of the connected client devices. Thus, when the IP address included in the data packets does not match the IP address of the connected client devices, those data packets are dropped. Further, when the IP address included in the data packets matches with the IP address of the connected client devices (503, 505), those data packets are forwarded.

[0105] In an example embodiment, when the connected client devices use NAT with PAT at operation 815, and the destination IP address matches the IP address of the connected client devices (503, 505), the host device (501) modifies the TTL value to 1 or the hop limit to 1 to avoid internet access to further connected client devices (503, 505) from the connected client devices. Upon modifying at operation 817, the host device (501) forwards the data packets to the connected client devices (503, 505).

[0106] Further, at operation 819, when the destination IP address matches the IP address of the connected client devices (503, 505) and the data traffic is ingress traffic, the host device (501) performs hop count filtering. Further, at operation 821, the host device (501) detects whether the port of the connected client device (503, 505) is the NAT port using a pre-trained ML model. The ML model is pre-trained using several parameters such as TTL, hop count, port number, interval time for packet transmission and receiving bytes, and the like.

[0107] Based on the detection at operation 823, the host device (501) determines whether the port of the connected client device is the NAT port. Further, at operation 825, the host device (501) drops the data packets for which the port is the NAT port. Also, the host device (501) forwards the data packets to the connected client devices for which the port is not the NAT port.

[0108] Consider a scenario as shown in Fig. 9a and Fig. 9b, where the host device (501) is connected to the secondary client devices (503, 505, 521). Further, the host device (501) blocks the internet access over Wi-Fi sharing to all the directly connected clients devices (503, 505, 521) by monitoring the network traffic and detecting discrepancies using TTL modifications. Particularly, the host device (501) determines whether the data traffic is ingress traffic or egress traffic. Further, the host device (501) determines whether the source IP address included in the data packets is present in the allowed IP address list, when the data traffic is the ingress traffic. Similarly, the host device (501) determines whether the destination IP address included in the received data packets is present in the allowed IP address list, when the data traffic is the egress traffic. When the source IP address in the ingress traffic does not match with the allowed IP address list, the ML model detects whether the ports is the NAT port. Further, when the port is the NAT port the host device (501) drops the data packets associated with the NAT ports is dropped. Also, when the port is not the NAT port the host device (501) forwards the data packets that is not associated with the NAT ports.

[0109] Fig. 10 is a flow diagram that illustrates a method for detecting a NAT port using a classification ML model according to various embodiments of the disclosure. In an example embodiment, the host device (501) receives packets at operation 1001, and extracts at least one of a flow-based feature of the data traffic at operation 1003. The at least one flow-based feature comprises at least one of a network traffic data, data packet size, timing, and flow duration of an ingress data packets. The host device (501) combines the flow-based features of the data traffic to identify traffic patterns associated with the NAT ports at operation 1005, and classifies a combined flow-based features into at least one of a non-NAT port or NAT port based on combined flow-based features using the ML model (e.g. RF, SVM, KNN etc.) at operation 1009 and 1011.

[0110] In the egress traffic, the host device (501) modifies the TTL value to 1 and the hop limit to 1 for data packets whose IP addresses match the list of allowed IP addresses. When the IP addresses of the data packets do not match the list of allowed IP addresses, the corresponding data packets are dropped. This authorization performed based on the IP addresses ensures comprehensive control over network traffic, preventing unauthorized sharing and maintaining network integrity.

[0111] Fig. 12a is a flow diagram illustrating a method of authorizing whether a client device is connected to a hotspot according to embodiments disclosed herein. At operation 1201, the method may include connecting the secondary client devices (503, 505) and the ternary client devices (507, 509, 511) to the Wi-Fi network with a Wi-Fi hotspot device or the host device (501). At operation 1203, the method may include determining whether the host device (501) is a hotspot device. At operation 1205, the method may include transmitting the IMEI hash value by the secondary client devices (503, 505) to the host device (501) through network service discovery (NSD).

[0112] Fig. 12b is a flow diagram illustrating a method of sharing the socket address of a connected client device according to embodiments disclosed herein. At operation 1207, the method may include receiving the IMEI hash value by the host device (501) from the secondary client devices (503, 505). At operation 1209, the method may include determining whether the upstream is a Wi-Fi and the connected Wi-Fi network is of the hotspot. At operation 1211, the method may include transmitting a pair of the IMEI hash value, IP address, and the NAT port of ternary client devices (507, 509, 511) by the secondary client devices (503, 505) to the host device (501).

[0113] Fig. 12c is a flow diagram illustrating a method of authorizing the socket address of the client device with an allowed list according to embodiments disclosed herein. At operation 1213, the method may include receiving the pair of the IMEI hash value, IP address, and the NAT port by the host device (501) from the secondary client devices (503, 505). At operation 1215, the method may include determining whether the IMEI hash value matches with the allowed IMEI list. At operation 1217, the method may include adding the IP address and the NAT port of the secondary client devices (503, 505) to the allowed list when the IMEI hash value matches with the allowed IMEI list.

[0114] The various actions, acts, blocks, steps, operations, or the like in the Figs. 1-11 are performed in the order presented, in a different order, or simultaneously. Furthermore, in some embodiments, some of the actions, acts, blocks, steps, operations, or the like are omitted, added, modified, skipped, or the like without departing from the scope of the proposed method.

[0115] The foregoing description of the specific embodiments will fully reveal the general nature of the embodiments herein such that others can readily modify and / or adapt such specific embodiments for various applications without departing from the generic concept. Therefore, such adaptations and modifications are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Thus, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modifications within the scope of the embodiments as described herein.

Claims

1.A method for managing an internet access in hotspot networks, the method comprising:detecting, by a host device (501), one or more identifiers associated with at least one secondary client device (503, 505) and at least one ternary client device (507, 509, 511) accessing a internet using a hotspot of the host device (501);determining, by the host device (501), whether each of the one or more identifiers is same or different from a corresponding set of authorized identifiers stored in a database accessible to the host device (501);blocking, by the host device (501), the internet access over Wi-Fi sharing of the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511) via the hotspot of the host device (501) in response that the one or more identifiers of the ternary client device (507, 509, 511) are different from the corresponding set of authorized identifiers, andmaintaining, by the host device (501), the internet access over Wi-Fi sharing of the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511) via the hotspot of the host device (501) in response that the one or more identifiers are same from the corresponding set of authorized identifiers.2.The method as claimed in claim 1, wherein the one or more identifiers comprises at least one of a socket address of a client device, hash of international mobile equipment identity (IMEI) number of the client device, a medium access control (MAC) address of the client device, and an internet protocol (IP) address of the client device,wherein the socket address comprises an IP address and a port number.3.The method as claimed in claim 1, wherein the corresponding set of authorized identifiers is permissible access parameters for at least one secondary client device (503, 505) and at least one ternary client device (507, 509, 511) connecting to the hotspot.4.The method as claimed in claim 1, wherein the one secondary client device (503, 505) and at least one ternary client device (507, 509, 511) is one of:directly connected to the host device (501) using the Wi-Fi hotspot of the host device (501); orindirectly connected to the host device (501) by establishing a Wi-Fi connection between the at least one ternary client device (507, 509, 511) and the at least one secondary client device (503, 505) and connecting the at least one secondary client device directly to the host device (501) using the hotspot of the host device (501), to allow the ternary client device (507, 509, 511) to access the internet via the host device (501).5.The method as claimed in claim 1, wherein determining whether each of the one or more identifiers is same or different from a corresponding set of authorized identifiers stored in a database accessible to the host device (501) comprises:determining, by the host device (501), whether a data traffic is at least one of an ingress traffic or an egress traffic; anddetermining, by the host device (501), whether a source internet protocol (IP) address in the ingress traffic or a destination IP address in the egress traffic is different from the corresponding set of authorized IP address stored in a database, wherein the at least one secondary client device (503, 505) and at least one ternary client device (507, 509, 511) uses a dynamic network address translation (NAT) or static NAT.6.The method as claimed in claim 5, wherein blocking the internet access comprises:blocking, by the host device (501), the internet access over Wi-Fi sharing of the at least one secondary client device, in response that the source IP address in the ingress traffic or the destination IP address in the egress traffic is different from an allowed IP address, andwherein maintaining the internet access comprises:providing, by the host device (501), the internet access over Wi-Fi sharing to the at least one secondary client device (503, 505), in response that the source IP address in the ingress traffic or the destination IP address in the egress traffic is not different from the corresponding set of authorized IP address stored in the database.7.The method as claimed in claim 1, wherein determining whether each of the one or more identifiers is same or different from corresponding set of authorized identifiers stored in a database accessible to the host device (501) s comprises:determining, by the host device (501), whether a data traffic is at least one of an egress traffic or an ingress traffic;modifying, by the host device (501), TTL value to 1 or hop limit to 1, in response that the data traffic is egress traffic, wherein the at least one secondary client device (503, 505) uses network address translation (NAT) with port address translation (PAT); anddetermining, by the host device (501), whether a port is a NAT port using a machine learning (ML) model, in response that the data traffic is ingress traffic, wherein the at least one secondary client device (503, 505) uses the NAT with the PAT.8.The method as claimed in claim 7, wherein determining whether a port is a NAT port using a ML model comprises:extracting, by the host device (501), at least one of a flow-based feature of the data traffic, wherein the at least one flow-based feature comprises at least one of a network traffic data, data packet size, timing, and flow duration of an ingress data packets;combining, by the host device (501), the flow-based features of the data traffic to identify traffic patterns associated with the NAT ports; andclassifying, by the host device (501), a combined flow-based features into at least one of a non-NAT port or NAT port based on combined flow-based features using the ML model.9.The method as claimed in claim 1, wherein determining whether each of the one or more identifiers is same or different from the corresponding set of authorized identifiers stored in the database accessible to the host device (501) comprises:determining, by the host device (501), whether a medium access control (MAC) address of the least one secondary client device (503, 505) and the at least one ternary client device (507, 509, 511) is different from the corresponding set of authorized MAC address stored in the database.10.The method as claimed in claim 9, wherein blocking the internet access comprises:blocking, by the host device (501), the internet access over Wi-Fi sharing to the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511), in response that the MAC address of the secondary client device (503, 505) of the at least one ternary client device (507, 509, 511) is different from the corresponding set of authorized MAC address stored in the database, andwherein maintaining the internet access comprises:providing, by the host device (501), the internet access over the Wi-Fi sharing to the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511), in response that the MAC address of the secondary client device (503, 505) of the at least one ternary client device (507, 509, 511) is not different from the corresponding set of authorized MAC address stored in the database.11.The method as claimed in claim 1, wherein determining whether each of the one or more identifiers is same or different from the corresponding set of authorized identifiers stored in the database accessible to the host device (501) comprises:receiving, by the host device (501), at least one of international mobile equipment identity (IMEI) hash value and network address translation (NAT) port number of the at least one secondary client device (503, 505) and of the at least one ternary client device (507, 509, 511);determining, by the host device (501), whether at least one of the IMEI hash value and NAT port number of the at least secondary client device (503, 505) and the at least one ternary client device (507, 509, 511) is different from corresponding set of authorized IMEI hash value and NAT port number stored in the database.12.The method as claimed in claim 11, wherein blocking the internet access comprises:blocking, by the host device (501), the internet access over Wi-Fi sharing to the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511), in response that at least one of the IMEI hash value and NAT port number of the at least secondary client device (503, 505) and of the at least one ternary client device (507, 509, 511) is different from thecorresponding set of authorized IMEI hash value and NAT port number stored in the database, andwherein maintaining the internet access comprises:providing, by the host device (501), the internet access over Wi-Fi sharing to the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511), in response that at least one of the IMEI hash value and NAT port number of the at least one secondary client device (503, 505) and the at least one ternary client device (507, 509, 511) is not different from the corresponding set of authorized IMEI hash value and NAT port number stored in the database.13.The method as claimed in claim 1, wherein blocking the internet access over Wi-Fi sharing of the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511) via the hotspot of the host device (501) comprises:dropping, by the host device (501), a plurality of data packets of the at least one ternary client device (507, 509, 511), in response that any of the one or more identifiers of the at least one ternary client device (507, 509, 511) are different from the corresponding set of authorized identifiers.14.The method as claimed in claim 1, wherein the maintaining the internet access over Wi-Fi sharing of the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511) comprises:forwarding, by the host device (501), the plurality of data packets of the at least one ternary client device (507, 509, 511) to the at least one secondary client device (503, 505) for providing the internet access over Wi-Fi sharing, in response that the one or more identifiers are same from the corresponding set of authorized identifiers.15.A host device (501) for managing an internet access in hotspot networks, the host device (501) comprises:memory (515) storing instructions; andat least one processor (513),wherein the instructions, when executed by the at least one processor (513) individually or collectively, cause the host device (501) to:detect one or more identifiers associated with at least one secondary client device (503, 505) and at least one ternary client device (507, 509, 511) accessing a internet using a hotspot of the host device (501);determine whether each of the one or more identifiers is same or different from a corresponding set of authorized identifiers stored in a database accessible to the host device (501);block the internet access over Wi-Fi sharing of the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511) via the hotspot of the host device (501) in response that the one or more identifiers of the ternary client device (507, 509, 511) are different from the corresponding set of authorized identifiers, andmaintain the internet access over Wi-Fi sharing of the at least one secondary client device (503, 505) or the internet access to the at least one ternary client device (507, 509, 511) via the hotspot of the host device (501) in response that the one or more identifiers are same from the corresponding set of authorized identifiers.