Network Access Device Primary Device Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access devices, such as routers, face security risks due to the ability of unauthorized users to access and modify network configuration information once the account and password are leaked.
Innovation Solution
An electronic device is introduced that manages network configuration information by designating primary devices with authority to process such information. The device receives requests from user devices, determines if they are primary devices, and either grants or denies access based on this designation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are allowed to remotely access and set network configuration information using account and password authentication, then network management convenience is improved, but security risks worsen because unauthorized users can access the network once credentials are leaked
Solution Approach 1:
The patent segments user devices into different types (portable vs. fixed) and assigns different authorization levels. Portable user devices are restricted from accessing network configuration information, while fixed user devices are granted access rights. This segmentation resolves the contradiction by providing convenient remote management for authorized devices while preventing unauthorized access through the portable device restriction.
2Reliability
If account and password authentication is used for accessing router configuration interface, then initial security is improved, but security worsens because leaked credentials allow unauthorized users to change access passwords, restore factory settings, or modify parental control policies
Solution Approach 1:
The patent implements preliminary action by pre-restricting access rights based on device type before any authentication occurs. Portable user devices are preemptively denied access to network configuration information, while fixed user devices are pre-approved. This preliminary authorization mechanism prevents unauthorized access even if credentials are leaked, as portable devices cannot access the configuration interface regardless of authentication status.
3Ease of operation
If all connected user devices are granted access to network configuration information, then ease of management is improved, but security worsens due to potential unauthorized modifications
Solution Approach 1:
The patent applies local quality by assigning different access rights to different categories of user devices. Instead of uniform access policies, the system grants configuration access rights specifically to fixed user devices while restricting portable user devices. This localized authorization approach maintains ease of management for legitimate users while preventing unauthorized modifications from portable devices.
Data Source
AI summary
The present disclosure relates to an electronic device, a method for an electronic device, a computer readable medium, and an apparatus. An electronic device, comprises: a memory having instructions stored thereon; and a processor configured to execute the instructions stored on the memory, to cause the electronic device to perform at least the following: receiving a network configuration information processing request from a first user device for a network to which the first user device is connected; determining whether one or more user devices have been set as primary devices, the primary devices having authorities to process network configuration information; in response to determining that the one or more user devices have been set as primary devices: determining whether the first user device is one of the primary devices; in response to determining that the first user device is one of the primary devices, responding to the network configuration information processing request; and in response to determining that the first user device is not one of the primary devices, denying the network configuration information processing request; and in response to determining that no user device is set as a primary device: responding to the network configuration information processing request.


