Home Network Secure Admission via Pre-Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current home network secure admission methods are prone to resource waste and low security due to the potential for illegal joining of malicious devices, as they require complex user operations and lengthy pairing windows.

Innovation Solution

A method where the domain master node sends prompt information to the user, allowing for a simple authorization operation, such as a key press or one-click authorization on a terminal, to enable pairing without requiring additional devices, thereby authorizing new devices before the pairing window opens, reducing unauthorized access and shortening the pairing window duration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a pairing window is opened to allow new devices to join the domain, then device access flexibility is improved, but security deteriorates due to potential illegal joining by malicious devices

Engineering Contradiction:
Improvedevice access flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication and authorization actions before opening the pairing window. The domain master node authenticates the new device and obtains authorization information in advance, so that when the pairing window opens, only authorized devices can join. This prevents malicious devices from exploiting the pairing window for illegal access while maintaining flexibility for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If a lengthy pairing window is provided for device joining, then ease of operation is improved, but resource waste increases due to extended vulnerability period

Engineering Contradiction:
Improvepairing operation convenienceVSAvoidresource waste
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The system completes authentication and authorization actions before the pairing window opens, so the pairing window itself can be kept short. Since the new device is already authenticated and authorized in advance, the pairing window only needs to be open briefly for the actual pairing, reducing the period of vulnerability and resource consumption while maintaining operational convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces the traditional mechanical approach of keeping a long pairing window open with an information-based approach using domain name system (DNS) authorization. Instead of relying on a prolonged time window, the system uses pre-obtained authorization information and DNS records to enable quick, secure pairing, thereby reducing the pairing window duration and associated resource waste.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If complex user operations are required for secure admission, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service authentication where the new device automatically performs authentication with the domain master node and obtains authorization information without requiring complex user operations. The user simply needs to confirm the device joining through a simplified interface, while the complex authentication and authorization processes are handled automatically by the system itself, maintaining security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3739817B1Network security access method and home network device
Publication Date: 2023.06.21 HUAWEI TECH CO LTD
  • EP3739817B1 patent drawingFigure 1
  • EP3739817B1 patent drawingFigure 2
  • EP3739817B1 patent drawingFigure 3

AI summary

A network secure admission method and a home network device are disclosed. When the network secure admission method is applied, and when determining that there is a home network device that needs to join a domain for pairing, a home network device used as a domain master node sends prompt information to a user. The user performs an authorization operation according to the prompt information sent by the domain master node. The domain master node receives the authorization operation of the user, enables a pairing window when determining that the authorization operation of the user is received, and sends, within an effective period of the pairing window, indication information used to indicate that the device is allowed to join the domain for pairing. After receiving the indication information sent by the domain master node, the device that needs to join the domain for pairing may initiate a registration request, to complete a secure admission process. According to embodiments of this application, the user performs the authorization operation according to the prompt information, and the user does not need to use a device such as a television or a computer to cooperate the operation, so that paring networking of a home network is friendlier to the user, and an operation is more convenient.