Home Network Access Authorization via Proxy Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access systems for home networks face security risks due to temporary accounts being easily leaked, inconvenient management, and complexity in setting user access authorities, particularly for temporary authorizations.

Innovation Solution

A system and method utilizing an authorizing proxy device to forward access request information and authorization information, implementing one-time and temporal authorization for home network access, which simplifies and secures the authorization process by eliminating the need for account and password settings for visitors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If temporary accounts are created for remote access, then access convenience is improved, but security risks increase due to account leakage

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authorization function from the accessed device and relocates it to an independent authorization device. This separation allows the accessed device to maintain security while the authorization device handles temporary account creation and management, reducing security risks associated with temporary accounts on the accessed device itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authorization device as an intermediary between the accessing device and the accessed device. This intermediary handles the temporary authorization process, acting as a secure mediator that grants time-limited access without compromising the security of the accessed device or creating vulnerable temporary accounts on it.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed access authority settings are configured for each user, then access control precision is improved, but management complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization where access authorities are not statically configured but dynamically granted and revoked by the authorization device. This allows precise access control to be applied on-demand based on specific access requests, eliminating the need for complex pre-configuration of detailed user permissions while maintaining precision when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of authorization from static user-specific permissions to dynamic time-limited authorization tokens. The authorization device can dynamically adjust authorization parameters (time limit, scope, authority level) based on the specific access request, providing precise control without complex management overhead.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If user-level access authorities are pre-configured, then access security is improved, but the authorization process becomes more complicated

Engineering Contradiction:
Improveaccess securityVSAvoidauthorization process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary configuration of the authorization device with security policies and authority definitions, but leaves the specific authorization decisions to be made dynamically at access time. This preliminary setup ensures security requirements are met while keeping the actual authorization process simple and flexible for each access request.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2053779B1A system and method for authenticating the accessing request for the home network
Publication Date: 2016.11.09 HUAWEI TECH CO LTD
  • EP2053779B1 patent drawingFigure 1~2

AI summary

A system and method for authorizing an access request for a home network. The system includes: at least one accessed device, at least an authorizing device and at least an authorizing proxy server, wherein a connection request managing module is provided in the accessed device, the authorizing proxy server includes an access request information forwarding module, an authorizing information forwarding module and an authorizing mode managing module. The method includes: the authorizing proxy server receives an access request information of an accessing device that is acquired and transmitted by the accessed device; the authorizing proxy server forwards the received access request information to the authorizing device; after receiving the authorized information of the authorizing device, the authorizing proxy server feedbacks the authorized information to the accessed device; the authorized information is the information that is sent to the authorizing proxy server after the authorizing device determines the authorization according to the received access request information.