UPnP Telephony Session Authority Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

UPnP telephony services lack appropriate authority management, allowing unauthorized users to end or shift phone calls, and existing Device Protection standards are inadequate for telephony services, as they fail to clearly distinguish between executable and non-executable actions.

Innovation Solution

A method and apparatus that manage phone calls by setting user authority within the UPnP telephony server, performing user authentication, and transferring role and user ID information to control points to ensure only authorized users can manage sessions and perform actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If UPnP telephony service allows any control point to manage sessions, then ease of operation is improved, but security deteriorates as unauthorized users can end or shift calls

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning different authority levels to different control points based on their relationship to the session. The session owner (initiator) receives full management authority, while other control points receive limited or no authority. This differentiated authority model allows the system to maintain ease of operation for authorized users while preventing unauthorized access, resolving the contradiction between operational ease and security.

Inventive Principle:
Principle #3Local quality

2Reliability

If Device Protection standard is applied to UPnP telephony, then security is improved, but adaptability deteriorates as it fails to distinguish telephony-specific actions

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter of authority management from a generic device-level approach to a session-specific approach with differentiated authority levels. By introducing session-owner-specific authority and action-type-specific authority levels (full management authority, partial authority, no authority), the system adapts the Device Protection concept to telephony-specific requirements, maintaining both security and adaptability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If user authority management is implemented, then security is improved, but device complexity increases due to authentication processes

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing user authority and session ownership at the moment of session initiation. The telephony server automatically identifies the session owner and assigns appropriate authority levels before any session management actions occur. This preliminary establishment of authority eliminates the need for complex authentication checks during each session management operation, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10623197B2Method and apparatus for giving monopoly of call in call transmission/reception system using UPnP
Publication Date: 2020.04.14 SAMSUNG ELECTRONICS CO LTD
  • US10623197B2 patent drawing
  • US10623197B2 patent drawing
  • US10623197B2 patent drawing

AI summary

A method of giving a monopoly of a call in a call transmission/reception system using UPnP (Universal Plug and Play) includes a telephony server setting a user's authority to manage a session when the telephony server generates the session; the telephony server performing a user authentication when the telephony server receives a call for an action for managing the session from a control point; and the control point performing the action for managing the session if a user of the control point has an authority to manage the session as the result of authentication.