Virtual UPnP Node Gateway for Secure Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current UPnP systems lack support for both mobility and security, particularly in scenarios where devices and control points move between IP networks, as existing mobility support architectures do not consider security aspects.

Innovation Solution

A gateway system that creates virtual UPnP nodes for remote devices and control points, enabling them to connect securely to the network by forwarding messages and storing security information, such as ACLs and certificates, to authenticate and authorize interactions within the UPnP network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobility support is added to UPnP systems to allow devices to move between IP networks, then adaptability is improved, but security is worsened because existing mobility architectures do not consider security aspects

Engineering Contradiction:
Improvemobility supportVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a gateway as an intermediary component that mediates between mobile UPnP devices and the UPnP network. The gateway creates virtual UPnP nodes for remote devices, forwards messages between them, and stores security information including ACLs and certificates. This intermediary approach enables mobility while maintaining security by centralizing security management and authentication processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protocols are enforced for mobile UPnP nodes, then security is improved, but message traffic increases due to authentication and authorization overhead

Engineering Contradiction:
ImprovesecurityVSAvoidmessage traffic
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by pre-configuring security information including ACLs (Access Control Lists) and certificates in the virtual UPnP nodes before mobile devices attempt to access the network. The gateway stores these security credentials in advance, so when a mobile device connects, authentication and authorization can proceed efficiently without generating excessive message traffic during the actual access operation.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If virtual UPnP nodes are created for remote devices, then mobility support is improved, but device complexity increases due to additional security management components

Engineering Contradiction:
Improvemobility supportVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway is designed as a universal multi-functional component that handles multiple tasks: creating virtual UPnP nodes, forwarding messages, storing security information, managing ACLs, and validating certificates. By consolidating these diverse functions into a single gateway entity, the patent avoids distributing complex security management logic across multiple components, thereby reducing overall system complexity while maintaining mobility support.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2153599B1Methods and arrangements for security support for universal plug and play system
Publication Date: 2019.10.16 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2153599B1 patent drawingFigure 1
  • EP2153599B1 patent drawingFigure 2
  • EP2153599B1 patent drawingFigure 3~4

AI summary

The present invention relates to a nodes and methods for use in a Universal Plug and Play (UPnP) system (201) to provide support for both UPnP security and mobility of security aware UPnP nodes. A gateway (20) is arranged to provide remote access to a UPnP network (10) to remote UPnP nodes (24, 25) via the gateway. The gateway comprises means (26) for creating a virtual UPnP node (24a, 25a) for emulating internal presence of a remote UPnP node on the UPnP network. The virtual UPnP node is arranged to obtain and store security information associated with the remote UPnP node. The securit y informatio n specifies how the remote UPnP node is authorized to interact with other UPnP nodes in the UPnP network. The security information may be used to filter messages from the UPnP network to the remote UPnP node.