Network Access Device Primary Device Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access devices, such as routers, face security risks due to the ability of unauthorized users to access and modify network configuration information once the account and password are leaked.

Innovation Solution

An electronic device is introduced that manages network configuration information by designating primary devices with authority to process such information. The device receives requests from user devices, determines if they are primary devices, and either grants or denies access based on this designation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to remotely access and set network configuration information using account and password authentication, then network management convenience is improved, but security risks worsen because unauthorized users can access the network once credentials are leaked

Engineering Contradiction:
Improvenetwork management convenienceVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments user devices into different types (portable vs. fixed) and assigns different authorization levels. Portable user devices are restricted from accessing network configuration information, while fixed user devices are granted access rights. This segmentation resolves the contradiction by providing convenient remote management for authorized devices while preventing unauthorized access through the portable device restriction.

Inventive Principle:
Principle #1Segmentation

2Reliability

If account and password authentication is used for accessing router configuration interface, then initial security is improved, but security worsens because leaked credentials allow unauthorized users to change access passwords, restore factory settings, or modify parental control policies

Engineering Contradiction:
Improveinitial security protectionVSAvoidunauthorized access damage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-restricting access rights based on device type before any authentication occurs. Portable user devices are preemptively denied access to network configuration information, while fixed user devices are pre-approved. This preliminary authorization mechanism prevents unauthorized access even if credentials are leaked, as portable devices cannot access the configuration interface regardless of authentication status.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If all connected user devices are granted access to network configuration information, then ease of management is improved, but security worsens due to potential unauthorized modifications

Engineering Contradiction:
Improvemanagement accessibilityVSAvoidunauthorized configuration changes
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different access rights to different categories of user devices. Instead of uniform access policies, the system grants configuration access rights specifically to fixed user devices while restricting portable user devices. This localized authorization approach maintains ease of management for legitimate users while preventing unauthorized modifications from portable devices.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12301410B2Electronic device, method for electronic device, computer readable medium, and apparatus
Publication Date: 2025.05.13 ARRIS ENTERPRISES LLC
  • US12301410B2 patent drawing
  • US12301410B2 patent drawing
  • US12301410B2 patent drawing

AI summary

The present disclosure relates to an electronic device, a method for an electronic device, a computer readable medium, and an apparatus. An electronic device, comprises: a memory having instructions stored thereon; and a processor configured to execute the instructions stored on the memory, to cause the electronic device to perform at least the following: receiving a network configuration information processing request from a first user device for a network to which the first user device is connected; determining whether one or more user devices have been set as primary devices, the primary devices having authorities to process network configuration information; in response to determining that the one or more user devices have been set as primary devices: determining whether the first user device is one of the primary devices; in response to determining that the first user device is one of the primary devices, responding to the network configuration information processing request; and in response to determining that the first user device is not one of the primary devices, denying the network configuration information processing request; and in response to determining that no user device is set as a primary device: responding to the network configuration information processing request.