Virtual Device Filtering for UPnP Remote Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access services based on Universal Plug and Play (UPnP) protocols do not effectively restrict the disclosure of information about home network devices, potentially compromising security by revealing sensitive details to external networks.

Innovation Solution

A filtering method and apparatus that dynamically generates a virtual device description, allowing users to control the disclosure of information about embedded devices or services within a UPnP RA service session, using a Uniform Resource Locator (URL) to manage and restrict access to device descriptions, and employing Network Address Translation (NAT) to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote access service is enabled to allow external networks to access home network devices, then accessibility and convenience are improved, but security and information disclosure control deteriorate

Engineering Contradiction:
Improveremote access accessibilityVSAvoidinformation disclosure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtual device as an intermediary between external networks and actual home network devices. The virtual device receives and processes access requests from external networks, then selectively forwards them to appropriate internal devices. This mediator architecture allows remote access functionality while preventing direct exposure of internal device information, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual device that is a simplified copy or representation of the actual home network devices. This virtual device contains only the necessary interface elements and information needed for remote access, while the complete and sensitive information about actual devices remains protected inside the home network. The copy enables external access without revealing the full details of the original devices.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If complete device information is disclosed to external networks for full functionality, then service capability is improved, but security and user control deteriorate

Engineering Contradiction:
Improveservice capabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by making different parts of the device information have different disclosure characteristics. The virtual device contains selected portions of device information that are appropriate for external access, while complete and sensitive information remains localized within the home network. This selective information distribution allows the external network to access sufficient functionality without obtaining all device details, resolving the contradiction between service capability and security control.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If all home network devices are exposed to external networks for comprehensive access, then accessibility is improved, but security risks and unauthorized access potential worsen

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The virtual device serves as a mandatory intermediary layer between external networks and all home network devices. All access requests must pass through the virtual device, which validates and filters them before forwarding to internal devices. This intermediary architecture maintains accessibility while preventing unauthorized access attempts from reaching actual devices directly, thus resolving the contradiction between accessibility and security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the device information and access interfaces into two distinct layers: the virtual device layer exposed to external networks and the actual device layer kept within the home network. This segmentation allows external networks to interact with the virtual device for necessary functionality while the actual devices remain protected behind the segmentation boundary, reducing unauthorized access risks while maintaining accessibility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10404485B2Method and apparatus for restricting disclosure of network information during remote access service
Publication Date: 2019.09.03 SAMSUNG ELECTRONICS CO LTD
  • US10404485B2 patent drawing
  • US10404485B2 patent drawing
  • US10404485B2 patent drawing

AI summary

A method and apparatus for restricting disclosure of information about a network device during a Remote Access (RA) service are provided, in which a virtual device is activated by an RA service device, a device or service for which information is to be disclosed to an external network is determined from among devices discovered by the RA service device and registered as an embedded device or service of the virtual device, a device description of the virtual device including the embedded device or service is dynamically generated, a Uniform Resource Locator (URL) of the RA service device, from which the device description of the virtual device is acquired, is generated and opened to a device of the other party which has remotely accessed the RA service device, and the device description of the virtual device is provided, upon receipt of a request for the device description of the virtual device through the URL.