Cloud-Based Network Access Device Ownership Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network access devices such as routers, switches, and modems lack secure management tools for transferring ownership and control, making them vulnerable to unauthorized access when moved from one user or network to another.

Innovation Solution

A cloud-based system method that initiates a registration change for network access devices by receiving authorization from the current owner and a physical reset indication, allowing secure dissociation and transfer of ownership, ensuring only one valid owner at a time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network access devices are made interchangeable and readily transferable between networks, then ease of operation and adaptability improve, but security and vulnerability to unauthorized access worsen

Engineering Contradiction:
Improvetransferability of network access deviceVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary registration of the network access device with the cloud system before transfer occurs. The current owner's device is pre-associated with the NAD in the cloud database, and preliminary authorization tokens are established. This preliminary binding ensures that only authorized transfer requests are processed, preventing unauthorized access while enabling legitimate transfers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cloud system acts as an intermediary between the current owner, new owner, and network access device. It mediates the transfer process by verifying authorization tokens, managing registration changes, and coordinating the dissociation/association process. This intermediary role ensures secure handoff without requiring direct trust between parties, resolving the security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network access devices allow easy transfer between users, then ease of operation improves, but reliability and secure management worsen

Engineering Contradiction:
Improveownership transfer processVSAvoidsecure management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The current owner can initiate and complete the transfer process themselves through the cloud system using their authorized device. The system provides self-service capabilities where the owner generates authorization tokens, initiates transfer requests, and confirms ownership changes without requiring administrator intervention or complex procedures. This maintains ease of operation while the cloud system ensures reliability through automated verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cloud system provides continuous feedback during the transfer process, notifying the current owner of transfer requests, confirming authorization token validity, and verifying successful completion. This feedback mechanism ensures the current owner is aware of and controls each step, maintaining reliability while keeping the process simple and transparent for the user.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If network access devices are registered with a cloud system for security, then security improves, but device complexity and management overhead worsen

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidregistration and transfer management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The complex security management functions are extracted from the network access device itself and placed in the cloud system. The NAD only needs to perform simple operations like generating authorization tokens and communicating registration status, while the cloud system handles complex tasks such as verifying device authenticity, managing owner registrations, validating transfer requests, and maintaining security policies. This extraction reduces device complexity while maintaining strong security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud system provides universal security management services that handle multiple functions: initial device registration, owner authorization, transfer management, and security policy enforcement. By consolidating these diverse functions into a single multi-functional cloud platform, the system avoids duplicating complex security mechanisms in each device, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11886594B2Secure transfer of registered network access devices
Publication Date: 2024.01.30 NETGEAR INC
  • US11886594B2 patent drawing
  • US11886594B2 patent drawing
  • US11886594B2 patent drawing

AI summary

The disclosed method is performed by a cloud system for changing a registration of a network access device. The method includes initiating a change of a registration of a network access device. The registration is stored at a cloud system and indicates ownership of the network access device by a first user. The method further includes receiving an authorization from the first user to dissociate the ownership of the network access device by the first user, and receiving an indication of a physical reset occurring locally at the network access device. The physical reset allows the first user to dissociate the ownership of the network access device. The method further includes, upon receiving both the authorization by the first user and the indication of the physical reset, releasing the ownership by the first user of the network access device at the cloud system.