Universal Plug and Play Registrar Access Control Setup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Universal Plug and Play networks lack user-friendly solutions for defining access control rules, requiring users to manually configure shared keys or enter PIN codes, leading to a cumbersome and error-prone experience, especially in home environments where no trusted authorities exist.
Innovation Solution
A registrar device and method that determines device access, executes a configuration protocol to share unique configuration keys, and provides a credential service for delegating access control credentials, allowing users to easily manage privileged services and control points within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Universal Plug and Play security standard is implemented for device authentication and access control, then security for device authentication and command authorization is improved, but user operation complexity increases due to requiring users to read and compare full length hashes
Solution Approach 1:
The patent introduces a simplified authentication mechanism where the security console automatically generates and displays a simplified verification code instead of requiring users to manually read and compare full-length public key hashes. This intermediary simplification layer maintains security while making the operation user-friendly.
Solution Approach 2:
The patent changes the parameter of authentication verification from full-length hash values to simplified verification codes. This parameter transformation maintains the security function while significantly improving ease of operation for average consumers.
2Reliability
If manual configuration of shared keys or PIN codes is required for access control, then access control for privileged services is achieved, but device complexity and setup time increase
Solution Approach 1:
The patent implements a self-service authentication mechanism where the security console automatically manages the authentication process. When a device joins the network, the system automatically generates verification codes and manages access control rights without requiring manual configuration by the user, thereby reducing configuration complexity while maintaining secure access control.
Solution Approach 2:
The patent performs preliminary authentication setup automatically when a device joins the network. The security console pre-generates verification codes and establishes access control relationships before the user needs to access privileged services, eliminating the need for manual configuration steps.
3Ease of operation
If USB cable connection is used to avoid reading and comparing full length hashes, then ease of operation is improved, but device complexity and setup requirements increase
Solution Approach 1:
The patent replaces the mechanical USB cable connection method with a wireless authentication mechanism. Instead of requiring physical cable connections between devices, the system uses automated verification codes displayed on screens, eliminating the need for physical connections while maintaining ease of operation.
Data Source
AI summary
A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.


