UPnP Control Point Connection Restriction via Configuration Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing UPnP technologies lack a method to restrict connections between devices on a network, leading to potential security and stability issues due to uncontrolled communication between appliances.

Innovation Solution

A UPnP control point and device with a configuration file that allows or denies connections using a firewall function, analyzing SSDP responses and advertisements to determine whether to establish or deny service connections based on predefined rules in the configuration file.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If UPnP devices automatically detect and connect to each other without configuration, then ease of operation is improved, but network security and stability deteriorate due to uncontrolled communication

Engineering Contradiction:
Improveautomatic device connectionVSAvoidnetwork security and stability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring allow/deny lists in configuration files before devices attempt to connect. The control point analyzes these configuration files in advance to determine which devices are permitted to communicate, establishing security rules beforehand rather than reacting to connection attempts. This resolves the contradiction by maintaining automatic connection capabilities while pre-establishing security controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - the configuration file analysis system that acts as a mediator between automatic connection requests and actual service establishment. The control point intercepts SSDP responses, analyzes them against configuration rules, and selectively permits or blocks connections based on predefined criteria. This intermediary layer enables both automatic operation and security control simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If connection restrictions are implemented using configuration files and analysis, then network security is improved, but device complexity increases due to additional control mechanisms

Engineering Contradiction:
Improvenetwork securityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling devices to automatically analyze configuration files and make connection decisions without requiring external security management. The control point autonomously parses configuration files, compares device identifiers against allow/deny lists, and determines connection permission status independently. This self-service approach improves security while avoiding the need for complex centralized security management systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent utilizes parameter changes by transforming raw SSDP responses into structured data that can be evaluated against configuration parameters. The control point extracts device identifiers from SSDP responses, compares them against predefined allow/deny lists in configuration files, and changes the connection state parameter based on this evaluation. This parameter-based approach provides security control through simple configurable parameters rather than complex control logic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8443123B2UPnP control point and UPnP device based on the UPnP network and connecting method using the same
Publication Date: 2013.05.14 KOREA INST OF SCI & TECH
  • US8443123B2 patent drawing
  • US8443123B2 patent drawing
  • US8443123B2 patent drawing

AI summary

Disclosed herein are a UPnP control point and a UPnP device based on the UPnP network and a connecting method using the same, in which a service connection is performed. The service connection is restrictedly performed using a configuration file defined to allow or deny a connection with a specific device on the UPnP network, so that only devices specified by a user can be connected.