Home Network Access Authorization via Proxy Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote access systems for home networks face security risks due to temporary accounts being easily leaked, inconvenient management, and complexity in setting user access authorities, particularly for temporary authorizations.
Innovation Solution
A system and method utilizing an authorizing proxy device to forward access request information and authorization information, implementing one-time and temporal authorization for home network access, which simplifies and secures the authorization process by eliminating the need for account and password settings for visitors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If temporary accounts are created for remote access, then access convenience is improved, but security risks increase due to account leakage
Solution Approach 1:
The patent extracts the authorization function from the accessed device and relocates it to an independent authorization device. This separation allows the accessed device to maintain security while the authorization device handles temporary account creation and management, reducing security risks associated with temporary accounts on the accessed device itself.
Solution Approach 2:
The patent introduces an authorization device as an intermediary between the accessing device and the accessed device. This intermediary handles the temporary authorization process, acting as a secure mediator that grants time-limited access without compromising the security of the accessed device or creating vulnerable temporary accounts on it.
2Measurement precision
If detailed access authority settings are configured for each user, then access control precision is improved, but management complexity increases
Solution Approach 1:
The patent implements dynamic authorization where access authorities are not statically configured but dynamically granted and revoked by the authorization device. This allows precise access control to be applied on-demand based on specific access requests, eliminating the need for complex pre-configuration of detailed user permissions while maintaining precision when needed.
Solution Approach 2:
The patent changes the parameter of authorization from static user-specific permissions to dynamic time-limited authorization tokens. The authorization device can dynamically adjust authorization parameters (time limit, scope, authority level) based on the specific access request, providing precise control without complex management overhead.
3Reliability
If user-level access authorities are pre-configured, then access security is improved, but the authorization process becomes more complicated
Solution Approach 1:
The patent implements preliminary configuration of the authorization device with security policies and authority definitions, but leaves the specific authorization decisions to be made dynamically at access time. This preliminary setup ensures security requirements are met while keeping the actual authorization process simple and flexible for each access request.
Data Source
Figure 1~2
AI summary
A system and method for authorizing an access request for a home network. The system includes: at least one accessed device, at least an authorizing device and at least an authorizing proxy server, wherein a connection request managing module is provided in the accessed device, the authorizing proxy server includes an access request information forwarding module, an authorizing information forwarding module and an authorizing mode managing module. The method includes: the authorizing proxy server receives an access request information of an accessing device that is acquired and transmitted by the accessed device; the authorizing proxy server forwards the received access request information to the authorizing device; after receiving the authorized information of the authorizing device, the authorizing proxy server feedbacks the authorized information to the accessed device; the authorized information is the information that is sent to the authorizing proxy server after the authorizing device determines the authorization according to the received access request information.