UPnP Software Management via Authentication Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the current UPnP security architecture, service providers cannot control the management operations of software installed on UPnP devices by users, as users with administrator rights can manage software modules installed by service providers.

Innovation Solution

A method where a communication device verifies that second authentication information matches first authentication information before executing software management commands, ensuring that only the service provider can manage software installed by them on the communication device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the user with administrator right manages the UPnP device, then the user can perform any operation including managing software modules, but the service provider cannot control the management operation on software installed by the service provider

Engineering Contradiction:
Improveuser's ability to manage softwareVSAvoidservice provider's control over installed software
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the administrator rights by creating different types of administrators: device-level administrators (users) and software-level administrators (service providers). The software module includes a dedicated service provider administrator account with restricted rights that only allow management of that specific software module, while excluding access to other software modules and device-level operations. This segmentation resolves the contradiction by allowing users to manage device-level software while preserving service provider control over their installed modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing different permission levels for different administrative contexts. The service provider administrator account has specialized rights that are locally optimized for managing only the specific software module it installed, rather than having universal administrator rights. This localized permission structure enables the service provider to maintain control over their software while allowing users to manage other aspects of the device.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If the UPnP device allows any user with administrator right to manage all software, then operational flexibility is improved, but security control over service provider software deteriorates

Engineering Contradiction:
Improvesoftware management flexibilityVSAvoidunauthorized modification of service provider software
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments administrative rights into device-level and software-level categories. When a service provider installs software, a service provider administrator account is created with rights segmented to only that specific software module. This segmentation prevents users from unauthorizedly modifying service provider software while still allowing them to manage other software and device functions, thus maintaining both flexibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service provider administrator account acts as an intermediary between the service provider and the UPnP device's software management system. This intermediary account enables the service provider to maintain control over their installed software without requiring the user to have unrestricted administrator rights, thereby preventing unauthorized modifications while preserving user flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If the service provider installs software remotely via CP on gateway, then installation control is improved, but management control over installed software deteriorates

Engineering Contradiction:
Improveremote software installationVSAvoidservice provider's management control
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent implements preliminary action by automatically creating a service provider administrator account with specific management rights at the time of software installation. When the service provider remotely installs software via the CP on the gateway, the system proactively configures the appropriate administrative credentials and permission structures, ensuring that the service provider maintains management control without requiring subsequent manual configuration or additional authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2590354B1Method, apparatus and system for software management
Publication Date: 2019.09.25 HUAWEI DEVICE (SHENZHEN) CO LTD
  • EP2590354B1 patent drawingFigure 1
  • EP2590354B1 patent drawingFigure 2
  • EP2590354B1 patent drawingFigure 3

AI summary

Disclosed in the present invention are a method, apparatus and system for software management, relating to the technical field of communications, and allowing software installed on a UPnP device by a service provider to be managed only by that service provider. The method comprises: receiving a software installation command sent by a first control device, installing software according to the software installation command and storing a first authentication information required during management of the software; receiving a software management command sent by a second control device, and acquiring a second authentication information corresponding to the software management command, which command is used in managing the software; when the second authentication information is consistent with the first authentication information, executing the software management command. In embodiments of the present invention, after a service provider has installed software on a communication device, it is possible to allow only that service provider to manage the software that service provider has installed, and the user is unable to manage the software installed on the communication device by that service provider.