Trusted Entity for Secure Remote Multimedia Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current UPnP A/V service solutions face challenges in securely sharing multimedia content between remote home networks due to IP address conflicts and unsatisfactory authentication key management, particularly when connections involve different home networks.

Innovation Solution

A trusted entity located in an external network, accessible via access gateways, manages remote access rules to secure content sharing between remote networks, verifying user authorization and filtering access requests to ensure secure content exchange without direct access to content servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN technology is used to secure content exchanges between remote networks, then security is improved, but device complexity and performance issues increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted entity as an intermediary between remote networks to manage access control. This entity receives access requests, verifies authorization rules, and coordinates with control devices and gateways to enable secure content sharing without requiring full VPN infrastructure, thereby reducing complexity while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security functions by separating access control management (handled by the trusted entity) from content delivery (handled by gateways and control devices). This segmentation allows each component to perform its specific function efficiently, reducing overall system complexity compared to a monolithic VPN solution

Inventive Principle:
Principle #1Segmentation

2Reliability

If iMS identity mechanism is used to manage remote access rights, then authentication is improved, but adaptability is reduced as it is limited to iMS network connections

Engineering Contradiction:
ImproveauthenticationVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The trusted entity is designed to work with multiple network types and access methods (iMS networks, Internet connections, mobile networks, WiFi hotspots). It provides universal authentication and access control functionality across different network infrastructures, making the system adaptable to various connection scenarios while maintaining robust authentication

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If direct access between remote networks is enabled, then ease of operation is improved, but security risks increase due to IP address conflicts and authentication key management issues

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The trusted entity acts as a mediator that sits between remote networks, receiving access requests from users, verifying authorization rules, and coordinating with control devices. This intermediary approach maintains ease of operation for users while eliminating direct network exposure that causes security risks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the trusted entity receives access requests, verifies them against stored authorization rules, and provides appropriate responses. Control devices and gateways also participate in feedback loops to confirm authorization and manage content delivery, ensuring security while maintaining operational simplicity

Inventive Principle:
Principle #23Feedback

4Reliability

If a trusted entity with verification mechanism is introduced, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted entity is a centralized intermediary that consolidates verification logic and authorization rule storage. By centralizing these security functions in a single entity rather than distributing complexity across multiple devices, the overall system complexity is managed more effectively while maintaining strong security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted entity autonomously manages authorization rules and verification processes without requiring manual intervention for each access request. It automatically retrieves rules, verifies user authorization, and coordinates with other system components, reducing operational complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2514167B1Monitoring method and device
Publication Date: 2017.02.08 ORANGE SA
  • EP2514167B1 patent drawing
  • EP2514167B1 patent drawing

AI summary

The invention relates to a method which includes: a step of receiving a message (M1), transmitted by a user (T-B) of a first network, said message containing an access rule authorising a user of a second network to access at least one multimedia content indexed on a server (MS-B2) of the first network; a step of sending, to a trusted entity (PFS) managing the interface between the first network (NW-B) and second network (NW-A), a notification message (M2) containing a remote access rule (RAD) authorising said user of the second network to access multimedia content belonging to said user of the first network; and a step of controlling a gateway (HGW-B) of the first network (NW-B) by means of a local access rule configuring said gateway, such that the latter sends a catalogue of content which said user of the second network is authorised to access upon receiving an access request relating to said catalogue from said user of the second network via the trusted entity (PFS).