UPnP Telephony Session Authority Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
UPnP telephony services lack appropriate authority management, allowing unauthorized users to end or shift phone calls, and existing Device Protection standards are inadequate for telephony services, as they fail to clearly distinguish between executable and non-executable actions.
Innovation Solution
A method and apparatus that manage phone calls by setting user authority within the UPnP telephony server, performing user authentication, and transferring role and user ID information to control points to ensure only authorized users can manage sessions and perform actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If UPnP telephony service allows any control point to manage sessions, then ease of operation is improved, but security deteriorates as unauthorized users can end or shift calls
Solution Approach 1:
The patent applies local quality by assigning different authority levels to different control points based on their relationship to the session. The session owner (initiator) receives full management authority, while other control points receive limited or no authority. This differentiated authority model allows the system to maintain ease of operation for authorized users while preventing unauthorized access, resolving the contradiction between operational ease and security.
2Reliability
If Device Protection standard is applied to UPnP telephony, then security is improved, but adaptability deteriorates as it fails to distinguish telephony-specific actions
Solution Approach 1:
The patent changes the parameter of authority management from a generic device-level approach to a session-specific approach with differentiated authority levels. By introducing session-owner-specific authority and action-type-specific authority levels (full management authority, partial authority, no authority), the system adapts the Device Protection concept to telephony-specific requirements, maintaining both security and adaptability.
3Reliability
If user authority management is implemented, then security is improved, but device complexity increases due to authentication processes
Solution Approach 1:
The patent applies preliminary action by establishing user authority and session ownership at the moment of session initiation. The telephony server automatically identifies the session owner and assigns appropriate authority levels before any session management actions occur. This preliminary establishment of authority eliminates the need for complex authentication checks during each session management operation, reducing overall system complexity while maintaining security.
Data Source
AI summary
A method of giving a monopoly of a call in a call transmission/reception system using UPnP (Universal Plug and Play) includes a telephony server setting a user's authority to manage a session when the telephony server generates the session; the telephony server performing a user authentication when the telephony server receives a call for an action for managing the session from a control point; and the control point performing the action for managing the session if a user of the control point has an authority to manage the session as the result of authentication.


