Systems and methods for connecting customer premises equipment

By establishing a secure connection with the production environment through the VPN tunnel of the pre-registered server on the CPE, the secure connection problem of remote CPE under third-party networks is solved, and simple, fast and secure global expansion and multi-device installation are achieved.

JP2025528070APending Publication Date: 2025-08-26SOLAR TURBINES INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025505756
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-09
Filing Date
2023-07-21
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

In the prior art, the secure connection and configuration process of remote client devices (CPEs) is complicated, especially in a third-party network environment, it is difficult to establish connections with company servers efficiently and securely.

Method used

By pre-installing the pre-registration server on the CPE, using the VPN tunnel between the handshake package and the pre-registration server, authenticating and parameter exchange, establishing a secure connection, and finally establishing a secure VPN tunnel with the production environment.

Benefits of technology

It realizes simple, fast and secure connection to CPE in a third-party network environment, supports global expansion, ensures high security, supports simultaneous installation of multiple devices, and achieves zero-touch configuration when hardware replacement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025528070000001_ABST
    Figure 2025528070000001_ABST
Patent Text Reader

Abstract

Systems and methods for connecting customer premises equipment A system and method are disclosed for automatically and securely connecting a customer premises equipment (CPE) (102) to a central production environment (110). The method includes automatically sending a handshake message from the CPE (102) to a central pre-registration server (106), establishing a generic VPN tunnel (113) between the CPE (102) and a remote server, obtaining one or more parameters from the CPE and establishing a pre-registration tunnel (114), validating the CPE (102) using the one or more parameters, and establishing the production tunnel (113) between the CPE (102) and the production environment (110).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD Embodiments described herein relate generally to configuring remote equipment, and more particularly to automatically and securely connecting customer premises equipment over third party networks.

[0002] Some companies / entities need to distribute Customer Premises Equipment (CPE) to remotely located customers (e.g., by mailing the CPE or by sending a technician to install the CPE) and then securely connect the CPE to the company servers / network, for example, to configure / maintain / update / instruct / test the CPE. The company always needs to connect to the CPE using one or more third-party networks (e.g., using the Internet).

[0003] U.S. Patent No. 10,069,802 describes a method for securely configuring a CPE in a network including a configuration server, a DHCP server, and the CPE. The method includes receiving a request from the CPE to lease an Internet Protocol (IP) address to the CPE, embedding a portion of the CPE's Media Access Control (MAC) address into the IP address, authenticating the CPE, and providing the CPE with a configuration. The method also includes generating an encryption key using characteristic attributes of the CPE to establish a secure connection.

[0004] The present disclosure is directed to overcoming one or more problems discovered by the inventors. Summary of the Invention

[0005] In one embodiment, a method for connecting a customer premises equipment (CPE) to a production environment is disclosed, the method including: sending a handshake packet from the CPE to a pre-registration server over a third-party network, determining via the pre-registration server that the handshake packet is authentic, obtaining an identification parameter from the CPE, establishing a pre-registration tunnel between the CPE and a remote portion of a headquarters data center, validating the CPE using the identification parameter, and, in response to the validation, establishing a secure connection between the CPE and the production environment.

[0006] In one embodiment, a system for connecting to a CPE through a third-party network is disclosed, including a pre-registration server configured to receive a generic VPN tunnel initiation request from the CPE, authenticate the generic VPN tunnel initiation request, establish a first generic VPN tunnel to the CPE, obtain one or more parameters from the CPE using a protected communication channel in the generic VPN tunnel, pre-register the CPE establishing a second CPE ad-hoc pre-registration tunnel, and establish a third VPN tunnel between the CPE and a production server.

[0007] In one embodiment, a method for authenticating a CPE is disclosed, the method including receiving a handshake packet from the CPE, verifying the handshake packet, and, in response to at least the verification, establishing a generic VPN tunnel to the CPE, obtaining one or more CPE parameters using a protected communication channel in the generic VPN tunnel, and verifying that the CPE is authentic based on the one or more CPE parameters and establishing a pre-registration tunnel. [Brief explanation of the drawings]

[0008] The details of embodiments of the present disclosure, both as to their structure and operation, may be gleaned in part by study of the accompanying drawings, in which like reference numerals refer to like parts.

[0009] [Figure 1] 1 illustrates a production system according to an embodiment. [Figure 2] 1 illustrates an exemplary processing system in which one or more of the processes described herein may be performed, according to an embodiment. [Figure 3] 2 shows a flow diagram of a method for automatically connecting a CPE to a production environment in the system of FIG. 1. [Figure 4] 2 shows a flow diagram of a method for authenticating and connecting to a CPE in the system of FIG. 1. DETAILED DESCRIPTION OF THE INVENTION

[0010] The detailed description set forth below with reference to the accompanying drawings illustrates various embodiments and does not represent the only embodiments in which the present disclosure may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of the embodiments. However, it will be apparent to those skilled in the art that embodiments of the present invention may be practiced without these specific details. In some instances, well-known structures and components are shown in simplified form for the sake of simplicity.

[0011] For clarity and ease of illustration, some surfaces and details may be omitted in the description and figures. It should also be understood that, as used herein, terms such as "side," "top," "bottom," "front," "rear," "above," "below," etc. are used for convenience of understanding to convey the relative positions of various parts to one another and do not imply any particular orientation of those parts in absolute terms (e.g., with respect to the external environment or the ground).

[0012] The following embodiments describe a system and method for automatically connecting to customer premises equipment that provides simple and fast customer network configuration, is widely and easily scalable worldwide, eliminates the need to initiate connections to CPEs from outside the customer premises network (which may be prohibited by customer premises network security), provides a high level of security, supports the latest security protocols, supports simultaneous and multiple installations of equipment on the same customer network, and allows zero-touch configuration in the field in the event of hardware replacement.

[0013] FIG. 1 illustrates a production system including data transmission according to an exemplary embodiment.

[0014] The CPE 102 may be a network-connected device (e.g., a router or gateway) that interfaces / connects with on-site production or data collection equipment 112 (e.g., turbines, sensors, etc.). The CPE 102 is provided (e.g., leased or sold) by an entity (e.g., a company / business) to a customer. The CPE is installed at the customer's premises by a technician (e.g., a company employee) who collects (manually or automatically) one or more parameters of the CPE 102. After installation, the company has several ways to identify and authenticate the CPE 102 using the installation parameters. For example, upon installation, the technician may note the time / date of installation and the CPE's expected IP address. The CPE may also be manufactured or pre-installed with additional identification features, such as a device serial number. Finally, in an exemplary embodiment, the CPE 102 is pre-programmed to automatically attempt to establish a generic VPN tunnel to the company pre-registration server 106 by continuously sending a predetermined handshake message to the pre-registration server's 106 public IP address.

[0015] The network 104 may include the Internet, and the CPE 102 may communicate with the pre-registration server 106 over the Internet using standard transmission protocols such as Hypertext Transfer Protocol (HTTP), HTTP Secure (HTTPS), File Transfer Protocol (FTP), FTP Secure (FTPS), and Secure Shell FTP (SFTP), as well as proprietary protocols. The network(s) 104 may further include a customer premises intranet, a customer premises local area network(s), an LTE / 4G / 5G network, etc. Although the CPE 102 is shown as connected to the pre-registration server 106 through a single set of network(s) 104, it should be understood that the CPE 102 may be connected to various systems through a different set of one or more networks.

[0016] The company's headquarters data center may include a pre-registration server 106, a production server 108, and a production environment 110. In an exemplary embodiment, the pre-registration server 106 may be a dedicated server with a defined pre-registration server IP address. While a single pre-registration server 106 is discussed, the pre-registration server 106 may include one or more servers that host and / or execute one or more pre-registration server functions, processes, methods, and / or software modules described herein. The pre-registration server 106 may include or be communicatively connected to a server application and / or one or more databases. A generic VPN tunnel 113 (initiated by the CPE 102) may be formed between the CPE 102 and the pre-registration server. A pre-registration tunnel 114 may be formed between the CPE 102 and the pre-registration server 106.

[0017] A user terminal 118 at the headquarters data center is communicatively connected to the pre-registration server 106 and the production server 108 and may be used by a user / engineer to access both.

[0018] The production server 108 may be a dedicated server with a defined production server IP address. In one embodiment, the production server 108 is connected to a production environment 110 or a portion thereof. The production environment 110 may be multiple servers and / or cloud instances that aggregate and analyze data collected from multiple customer facilities (including remote facilities 112). For example, the production environment 110 may collect and analyze various sensor data from any remote facilities (e.g., turbines) that belong to or are serviced by a company / enterprise. A production tunnel 116 may be formed between the CPE 102 and the production server 108. The production tunnel 116 may be used to transmit inter-site production data between the remote facilities 112 and the headquarters production environment 110.

[0019] 2 is a block diagram illustrating an exemplary wired or wireless system 200 that may be used in connection with various embodiments described herein. For example, system 200 may be used as or in combination with one or more of the functions, processes, or methods described herein (e.g., to store and / or execute implementing software) and may represent components of CPE 102, pre-registration server 106, production server 108, user equipment / terminal 118, and / or other processing devices described herein. System 200 may be a server or any conventional personal computer, or any other processor-enabled device capable of wired or wireless data communication. Other computer systems and / or architectures may also be used, as will be apparent to those skilled in the art.

[0020] System 200 preferably includes one or more processors 210. Processor(s) 210 may include a central processing unit (CPU). Additional processors may be provided, such as graphics processing units (GPUs), auxiliary processors for managing input / output, auxiliary processors for performing floating-point mathematical operations, dedicated microprocessors (e.g., digital signal processors) having architectures suitable for fast execution of signal processing algorithms, processors subordinate to the main processing system (e.g., back-end processors), additional microprocessors or controllers for dual or multiprocessor systems, and / or coprocessors. Such auxiliary processors may be discrete processors or may be integrated with processor 210. Processors that may be used with system 200 include processors available from Intel Corporation of Santa Clara, California (e.g., Pentium®, Core™, etc.). (商標) any of the processors available from Advanced Micro Devices, Incorporated (AMD) of Santa Clara, California; any of the processors available from Apple Inc. of Cupertino (e.g., A series, M series, etc.); any of the processors available from Samsung Electronics Co., Ltd. of Seoul, Korea (e.g., Exynos (登録商標) ), or any of the processors available from NXP Semiconductors NV of Eindhoven, The Netherlands.

[0021] Processor 210 is preferably connected to communication bus 205. Communication bus 205 may include a data channel for facilitating information transfer between storage and other peripheral components of system 200. Additionally, communication bus 205 provides a set of signals used for communication with processor 210 and may include a data bus, an address bus, and / or a control bus (not shown). Communication bus 205 may include any standard or non-standard bus architecture, such as, for example, Industry Standard Architecture (ISA), Extended Industry Standard Architecture (EISA), MicroChannel Architecture (MCA), Peripheral Component Interconnect (PCI) local bus, a bus architecture conforming to standards promulgated by the Institute of Electrical and Electronics Engineers (IEEE), etc.

[0022] System 200 preferably includes main memory 215 and may also include secondary memory 220. Main memory 215 provides storage of instructions and data for programs executing on processor 210, such as any of the software described herein. It should be understood that the programs stored in memory and executed by processor 210 may be written and / or compiled according to any suitable language, including, but not limited to, C / C++, Java, JavaScript, Perl, Visual Basic, .NET, etc. Main memory 215 is typically semiconductor-based memory, such as dynamic random access memory (DRAM) and / or static random access memory (SRAM). Other semiconductor-based memory types include, for example, synchronous dynamic random access memory (SDRAM), Rambus dynamic random access memory (RDRAM), and ferroelectric random access memory (FRAM), including read-only memory (ROM).

[0023] Secondary memory 220 is a non-transitory computer-readable medium on which computer-executable code (e.g., any of the software disclosed herein) and / or other data is stored. Computer software or data stored in secondary memory 220 is read into main memory 215 for execution by processor 210. Secondary memory 220 may include semiconductor-based memory such as, for example, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable read-only memory (EEPROM), and flash memory (a block-oriented memory similar to EEPROM). Secondary memory 220 may optionally include internal media 225 and / or removable media 230. Removable media 230 may be read from and / or written to in any known manner. Removable storage media 230 may be, for example, a magnetic tape drive, a compact disc (CD) drive, a digital versatile disc (DVD) drive, other optical drives, a flash memory drive, etc.

[0024] In an embodiment, I / O interface 235 provides an interface between one or more components of system 200 and one or more input and / or output devices. Input devices include, for example, but are not limited to, sensors, keyboards, touchscreens or other touch-sensitive devices, cameras, biometric sensors, computer mice, trackballs, and / or pen-based pointing devices. Output devices include, for example, but are not limited to, other processing devices, cathode ray tubes (CRTs), plasma displays, light-emitting diode (LED) displays, liquid crystal displays (LCDs), printers, vacuum fluorescent displays (VFDs), surface-conduction electron-emitter displays (SEDs), and / or field-emission displays (FEDs). In some cases, input and output devices may be combined, such as in the case of touch-panel displays (e.g., in a display console or in a smartphone, tablet computer, or other mobile device).

[0025] System 200 may include a communications interface 240. Communications interface 240 allows software and data to be transferred between system 200 and an external device (e.g., a printer), a network (e.g., network(s) 104), or other information source. For example, computer software or executable code may be transferred to system 200 from a network server (e.g., pre-registration server 106 or production server 108) via communications interface 240. Communications interface 240 may include, for example, a built-in network adapter, a network interface card (NIC), a PC Memory Card International Association (PCMCIA) network card, a card bus network adapter, a wireless network adapter, a universal serial bus (USB) network adapter, a modem, a wireless data card, a communications port, an infrared interface, IEEE 1394 FireWire, and any other device capable of interfacing system 200 with a network (e.g., network(s) 104) or another computing device. Communications interface 240 preferably implements industry-promulgated protocol standards such as the Ethernet IEEE 802 standard, Fibre Channel, Digital Subscriber Line (DSL), Asynchronous Digital Subscriber Line (ADSL), Frame Relay, Asynchronous Transfer Mode (ATM), Integrated Services Digital Network (ISDN), Personal Communications Services (PCS), Transmission Control Protocol / Internet Protocol (TCP / IP), Serial Line Internet Protocol / Point-to-Point Protocol (SLIP / PPP), etc., but may also implement customized or non-standard interface protocols.

[0026] The software and data transferred via communications interface 240 are generally in the form of electrical communications signals 255. These signals 255 may be provided to communications interface 240 via communications channel 250. In embodiments, communications channel 250 may be a wired or wireless network (e.g., network(s) 104), or any of a variety of other communications links. Communications channel 250 carries signals 255 and may be implemented using a variety of wired or wireless communications means, including wire or cable, optical fiber, conventional telephone lines, cellular phone links, wireless data communications links, radio frequency (“RF”) links, or infrared links, to name a few.

[0027] Computer-executable code (e.g., computer programs such as the disclosed software) is stored in main memory 215 and / or secondary memory 220. Computer-executable code may also be received via communications interface 240 and stored in main memory 215 and / or secondary memory 220. Such computer programs, when executed, enable system 200 to perform various functions of the disclosed embodiments described elsewhere herein.

[0028] As used herein, the term "computer-readable medium" refers to any non-transitory computer-readable storage medium used to provide computer-executable code and / or other data to or within system 200. Such media include, for example, main memory 215, secondary memory 220 (including internal memory 225 and / or removable media 230), external storage medium 245, and any peripheral devices (including a network information server or other network device) communicatively coupled to communication interface 240. These non-transitory computer-readable media are means for providing software and / or other data to system 200.

[0029] System 200 may also include any wireless communication components that facilitate wireless communication over a voice network and / or a data network (e.g., network 104). The wireless communication components include an antenna system 270, a radio system 265, and a baseband system 260. The baseband system 260 is communicatively coupled to the processor(s) 210. In system 200, radio frequency (RF) signals are transmitted and received wirelessly by the antenna system 270 under the direction of the radio system 265.

[0030] Figure 3 is a flow diagram of a method from the perspective of a CPE 102 for automatically connecting the CPE 102 to a corporate production environment 110. The method of Figure 3 may be implemented in the system of Figure 1. The functions / processes described in Figure 3 may be implemented as software modules in the CPE 102 using one or more portions of the system described in Figure 2.

[0031] In step 302, the CPE 102 is installed in the remote environment. The CPE 102 is installed as part of a broader project to collect and transmit data between the remote production environment 112 and the central data center production environment 110. In an exemplary embodiment, a field technician is physically present on-site to install the CPE 102 and connect the CPE to the network 104. In one embodiment, the installation may be performed synchronously with the central data center worker / technician receiving identification parameters for the installation. The identification parameters are recorded / transmitted at this time as the CPE 102's expected identification parameters. The installed CPE 102 automatically includes several identification parameters, such as the device serial number and public key(s). The field technician also collects other identification parameters during installation, such as the CPE 102 configuration IP and default gateway, the CPE 102 source public IP, and the date and time of installation. In one embodiment, an expected registration date / time is included in the identification. The expected date / time may be determined by the field technician based, for example, on the CPE's location, a predetermined schedule, etc. In one embodiment, some or all of the identification parameters may be automatically transmitted to a central data center.

[0032] In step 304, the CPE 102 is connected to the network(s) 104 through which the CPE 102 may reach the headquarters data center.

[0033] In step 306, the CPE 102 announces itself by sending a handshake packet to a central location (e.g., the pre-registration public server 106). In an exemplary embodiment, the CPE 102 is pre-programmed to send handshake messages in an expected protocol to the public IP address of the pre-registration server 106. The CPE 102 (i) has the ability to send traffic over the Internet and (ii) continues to send handshake messages indefinitely (e.g., periodically or on a schedule) unless it receives an appropriate response from the pre-registration server 106. In an exemplary embodiment, the handshake message includes an encrypted virtual private network (VPN) initiation request. In one example, the VPN initiation request is a WireGuard initiation request, although other general-purpose VPN protocols may be used. A cryptographic key set is pre-programmed / pre-installed on the CPE.

[0034] In step 308, the CPE 102 receives a response to the handshake message from the central office (e.g., the pre-registration server 106). In one embodiment, the response includes the creation of a generic VPN tunnel 113, as initiated by the CPE.

[0035] In step 310, the CPE 102 receives a Secure Shell (SSH) session initiation within the generic VPN tunnel 113. In step 312, the CPE 102 sends a response to the SSH session.

[0036] In steps 314-320, the CPE 102 receives a request for identification parameters (step 314) and transmits the identification parameters within the SSH session (step 316). In step 316, the CPE 102 transmits its identification parameters, including, for example, the device serial number, the device configuration IP and default gateway, the device source public IP, and the CPE installation / registration date and time. After transmitting the identification parameters, the CPE 102 waits until the headquarters data center validates the CPE 102, and in step 318, the CPE receives the ad hoc pre-registration tunnel 114 configuration parameters from the pre-registration server 106. In step 320, the CPE establishes the ad hoc pre-registration tunnel 114.

[0037] After final / manual verification, in step 322, the company headquarters data center server (e.g., pre-registration server 106, production server 108, etc.) creates the final production tunnel 116 from the CPE 102 to the headquarters production server 108. After establishing the production tunnel 116, the CPE 102 may transmit the remote production data (e.g., turbine data) to the production environment 110.

[0038] Figure 4 is a flow diagram of the method of Figure 3 from a central perspective. The process of Figure 4 may be implemented within the production system of Figure 1. The functions / processes described in Figure 4 may be implemented at least in part as software modules (e.g., pre-registration server 106, production server 108, etc.) using one or more portions of the system described in Figure 2.

[0039] In step 402, the pre-registration server 106 is ready and waiting to receive a handshake message / packet.

[0040] In step 404, the pre-registration server 106 receives a handshake packet from the CPE 102. In one embodiment, the handshake packet includes a VPN initiation request that is verified with the expected key.

[0041] In steps 406-410, the pre-registration server 106 performs initial verification steps of the handshake packet. Steps 406-410 represent the first authentication step in the method of FIG. 4. In step 406, the pre-registration server 106 determines that the handshake message is not part of an existing flow. If the handshake message is part of an existing flow, pre-registration does not perform any further steps and defaults to waiting (step 402). In step 408, if the handshake message is from a new CPE, the pre-registration server 106 determines whether the message contains a proper VPN initiation request (e.g., a WireGuard initiation request). If the packet does not contain an initiation request, the pre-registration server 106 returns to waiting. In step 410, the pre-registration server 106 determines whether the public CPE encryption key matches the expected encryption key. If the keys do not match, the pre-registration server returns to step 402. If the keys match, the process proceeds to step 412.

[0042] If the handshake message is verified, steps 412 and 414 are executed. In step 412, the pre-registration server 106 responds to the handshake message. In step 414, the pre-registration server 106 establishes a generic VPN tunnel 113 to the CPE 102 based on the VPN initiation request.

[0043] In step 416 , the pre-registration server 106 opens an SSH session to the CPE 102 over the generic VPN tunnel 113 .

[0044] In step 417, the pre-registration server 106 receives the appropriate response from the CPE. At this point, the device / CPE 102 is verified as a genuine CPE. This is the second authentication step in the method of FIG. 4.

[0045] In step 418, the pre-registration server 106 retrieves the CPE identification parameters from the CPE 102 using the SSH session. In one embodiment, the pre-registration server 106 sends a request to the CPE 102 and receives the parameters in response to the request. The identification parameters may include one or more of the device serial number, the device configuration IP and default gateway, the device source public IP, and the installation and / or registration date and time.

[0046] In step 422, the pre-registration server 106 pre-registers the CPE 102 (sends ad-hoc tunnel parameters to the CPE, establishes the pre-registration tunnel, and inserts the CPE into the pre-registration queue). In an exemplary embodiment, the pre-registration server 106 also sends a command to the CPE 102, for example, to show a notification / message on the display of the CPE 102 (e.g., to inform the user that the device is being pre-registered). In step 422, the CPE 102 waits in the pre-registration queue until the final verification and pre-registration server 106 process is complete.

[0047] In step 424, a final verification of the CPE 102 is performed. The final verification is the third authentication step of the method of FIG. 4. The final verification involves verifying at least a portion of the identification parameters received from the CPE 102 (e.g., collected during installation of the CPE or known from the manufacturer) within expected identification parameters. The identification parameters used in the final verification step may include one or all of the CPE's public IP address, installation or registration date and time, etc. In one embodiment, the registration date and / or time received from the CPE is compared to the current date / time. In another example, the installation date / time received from the CPE is compared to the current date / time and is verified if the current date / time is within a specific time frame from the installation date / time. For example, the registration process may be expected to occur within a specific period of time (e.g., one month, one year, etc.) after CPE installation.

[0048] If the CPE 102 passes final verification in step 426, the process proceeds to connecting the CPE to the production server (step 428) and the CPE is removed from the pre-registration queue (step 429). Alternatively, if the CPE 102 does not pass final verification, the CPE 102 is removed from the pre-registration queue and, optionally, placed on a block list in step 427.

[0049] The tunnel 116 established between the CPE 102 and the headquarters data center production server 108 in step 428 is a secured VPN tunnel 116 that may be used by the CPE 102 to transmit production data from the remote production environment 112 to the headquarters production environment 110 and vice versa. The secured VPN tunnel may be used by the production server 108 to securely collect data from the remote environment 112, send instructions to the remote environment 112, and configure the CPE 102.

[0050] In an exemplary embodiment, final verification 426 is a manual verification process performed by an engineer / worker at the headquarters center, for example, via user terminal 118 (FIG. 1). In some embodiments, a worker must manually check that the identification parameters received from the CPE during the pre-registration process match the expected identification parameters (e.g., collected by a technician during CPE installation and / or determined for the CPE during manufacturing / pre-programming). In alternative embodiments, some or all of the final verification is performed automatically via one or more software modules (e.g., within system 200).

[0051] 3 and 4 are shown with a particular arrangement and order of sub-processes, the processes may be implemented with fewer, more, or different sub-processes and with a different arrangement and / or order of the sub-processes. It should be understood that any sub-process that is not dependent on the completion of another sub-process may be performed before, after, or in parallel with other independent sub-processes, even if the sub-processes are described or shown in a particular order.

[0052] It is understood that the benefits and advantages described above may relate to one embodiment or to several embodiments. It is intended that aspects described in connection with one embodiment can be used with other embodiments. Any description related to one embodiment applies to like features of other embodiments, and elements of multiple embodiments can be combined to form other embodiments. The multiple embodiments are not limited to those that solve any or all of the stated problems or have the stated benefits and advantages.

[0053] The foregoing detailed description is merely exemplary in nature and is not intended to limit the invention or its application and uses. The described embodiments are not limited to use in combination with a particular type of processing system or machine. Thus, while the present embodiments are shown and described as being implemented in a particular processing system for convenience of explanation, it will be understood that they can be implemented in various other types of processing systems and machines. Furthermore, there is no intention to be bound by any theory presented in any preceding section. It will also be understood that the description may include exaggerated dimensions and graphic representations to better illustrate indicated referenced items and are not to be considered limiting unless so expressly stated.

Claims

1. A method for connecting a customer premises equipment (CPE) (102) to a production environment (110), comprising: sending a handshake packet from said CPE (102) to a pre-registration server (106) via a third party network (104); determining, via the pre-registration server (106), that the handshake packet is valid; obtaining an identification parameter from said CPE (102); Establishing a pre-registered tunnel between said CPE (102) and a remote portion of a headquarters data center; validating said CPE (102) using said identification parameters; and in response to the validation, establishing a secure connection (116) between the CPE (102) and the production environment (110).

2. The method of claim 1 , wherein transmitting the handshake packets comprises continuously transmitting the handshake packets.

3. 2. The method of claim 1, wherein transmitting the handshake packets includes automatically transmitting the handshake packets to a public IP address pre-programmed on the CPE.

4. The method of claim 1 , wherein determining that the handshake packet is valid includes at least verifying the handshake packet with an expected key.

5. The method of claim 1 , wherein determining that the handshake packet is valid includes at least determining that the handshake packet includes a VPN initiation request.

6. The method of claim 1 , wherein determining that the handshake packet is valid includes at least determining that the handshake packet is not part of an existing flow.

7. 2. The method of claim 1, further comprising, prior to establishing the pre-registration tunnel, establishing a generic VPN tunnel and opening a Secure Shell (SSH) session to the CPE to retrieve CPE identification parameters and send ad-hoc parameters to set up the pre-registration tunnel.

8. 2. The method of claim 1, wherein verifying the CPE includes making at least some of the identification parameters viewable to a user at the headquarters data center; and receiving manual verification of the CPE from the user.

9. The method of claim 1 , wherein validating the CPE includes automatically comparing at least some of the identification parameters to one or more expected parameters.

10. The method of claim 1 , wherein the identification parameters include one or more of a unique serial number, a public IP address, and a registration time.

11. The method of claim 10 , further comprising placing the CPE in a pre-registration queue before validating the CPE.

12. The method of claim 11 , further comprising determining that the CPE is available for pre-registration before placing the CPE in the pre-registration queue.

13. 1. A system for connecting to a CPE (102) through a third party network (104), the system comprising: receiving a general VPN tunnel initiation request from the CPE (102); Authenticating the general VPN tunnel initiation request; Establishing a first generic VPN tunnel (113) to said CPE (102); obtaining one or more parameters from the CPE (102) using a secured communication channel within the generic VPN tunnel; pre-registering said CPE (102) to establish a second CPE ad-hoc pre-registration tunnel (114); and The system includes a pre-registration server (106) configured to establish a third VPN tunnel (116) between the CPE (102) and a production server (108).

14. 14. The system of claim 13, wherein the first generic VPN tunnel (113) and the second CPE ad-hoc pre-registration tunnel (114) are between the CPE (102) and a remote server, the remote server being remote from the production server (108).

15. 14. The system of claim 13, wherein pre-registering the CPE based on the one or more parameters comprises: determining that the unique serial number of the CPE is not in a database of registered devices; and pre-registering the CPE based on at least the determination.