Universal Plug and Play Registrar Access Control Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Universal Plug and Play networks lack user-friendly solutions for defining access control rules, requiring users to manually configure shared keys or enter PIN codes, leading to a cumbersome and error-prone experience, especially in home environments where no trusted authorities exist.

Innovation Solution

A registrar device and method that determines device access, executes a configuration protocol to share unique configuration keys, and provides a credential service for delegating access control credentials, allowing users to easily manage privileged services and control points within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Universal Plug and Play security standard is implemented for device authentication and access control, then security for device authentication and command authorization is improved, but user operation complexity increases due to requiring users to read and compare full length hashes

Engineering Contradiction:
Improvedevice authentication securityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a simplified authentication mechanism where the security console automatically generates and displays a simplified verification code instead of requiring users to manually read and compare full-length public key hashes. This intermediary simplification layer maintains security while making the operation user-friendly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of authentication verification from full-length hash values to simplified verification codes. This parameter transformation maintains the security function while significantly improving ease of operation for average consumers.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual configuration of shared keys or PIN codes is required for access control, then access control for privileged services is achieved, but device complexity and setup time increase

Engineering Contradiction:
Improveaccess control for privileged servicesVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service authentication mechanism where the security console automatically manages the authentication process. When a device joins the network, the system automatically generates verification codes and manages access control rights without requiring manual configuration by the user, thereby reducing configuration complexity while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary authentication setup automatically when a device joins the network. The security console pre-generates verification codes and establishes access control relationships before the user needs to access privileged services, eliminating the need for manual configuration steps.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If USB cable connection is used to avoid reading and comparing full length hashes, then ease of operation is improved, but device complexity and setup requirements increase

Engineering Contradiction:
Improveauthentication simplicityVSAvoidphysical connection requirement
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical USB cable connection method with a wireless authentication mechanism. Instead of requiring physical cable connections between devices, the system uses automated verification codes displayed on screens, eliminating the need for physical connections while maintaining ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11153081B2System for user-friendly access control setup using a protected setup
Publication Date: 2021.10.19 HFI INNOVATION INC
  • US11153081B2 patent drawing
  • US11153081B2 patent drawing
  • US11153081B2 patent drawing

AI summary

A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.