Base Server Secure Remote Network Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for initial provisioning of computer network infrastructure at remote sites are inefficient, requiring physical presence of network engineers, incurring significant costs and logistical challenges due to travel and equipment transportation, and lacking secure remote configuration capabilities.

Innovation Solution

A base server with secure hardware features and management software enables automatic and secure connection between central and remote sites, allowing for remote provisioning of network elements through protocols like Dynamic Host Configuration Protocol and Zero Touch Provisioning, using a VPN tunnel for secure communication and orchestration, even in untrusted environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network engineers travel to remote sites for physical provisioning, then secure configuration can be performed, but travel costs and logistical complexity increase significantly

Engineering Contradiction:
Improvesecure configurationVSAvoidlogistical complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A base server is deployed at the remote site to act as an intermediary between field technicians and the central management network. The base server establishes a secure connection to the central site and enables remote engineers to provision network elements automatically, eliminating the need for engineers to travel to remote locations while maintaining secure configuration capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The base server enables automatic provisioning of network elements without requiring manual configuration by field technicians. The system self-provisions network elements by downloading configurations from the central management network through the base server, reducing the need for human presence at remote sites.

Inventive Principle:
Principle #25Self-service

2Productivity

If network engineers are transported to site during turn up, then infrastructure can be provisioned, but personnel and travel costs increase

Engineering Contradiction:
Improveinfrastructure provisioningVSAvoidpersonnel costs
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The base server enables network elements to self-provision by automatically downloading configurations and firmware from the central management network. This eliminates the need for field technicians to be physically present at remote sites during infrastructure deployment, significantly reducing personnel and travel costs while maintaining provisioning productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of field technicians physically configuring network equipment is replaced by an automated electronic provisioning system. The base server communicates with network elements via network protocols to automatically apply configurations, replacing the need for human technicians to manually configure each device.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of time

If pre-fabricated equipment is shipped to site, then deployment time is reduced, but equipment transportation and setup complexity increase

Engineering Contradiction:
Improvedeployment timeVSAvoidequipment transportation
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

Network element configurations, firmware images, and provisioning instructions are prepared and stored at the central management network in advance. The base server retrieves these pre-prepared resources and automatically applies them to network elements upon arrival at the remote site, eliminating the need to transport and manually assemble pre-fabricated equipment while reducing deployment time.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If secure connection is established between central and remote site, then remote provisioning becomes possible, but security risks from faulty configuration or buggy firmware increase

Engineering Contradiction:
Improveremote provisioningVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The base server implements verification mechanisms to confirm that network elements have correctly received and applied configurations and firmware updates from the central management network. The system monitors provisioning status and provides feedback to ensure that security-critical parameters are correctly configured, reducing the risk of faulty configurations or buggy firmware.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The base server acts as a secure intermediary between the central management network and remote network elements. It establishes authenticated and encrypted connections to both the central site and network elements, ensuring that configuration data is transmitted securely and that only authorized devices can receive provisioning instructions, thereby mitigating security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10938855B1Systems and methods for automatically and securely provisioning remote computer network infrastructure
Publication Date: 2021.03.02 DIGI INTERNATIONAL
  • US10938855B1 patent drawing
  • US10938855B1 patent drawing
  • US10938855B1 patent drawing

AI summary

Systems and methods for computer network infrastructure provisioning are provided. In one illustrative implementation, a base server is sent to and physically installed at a remote site by field technicians, the base server automatically and securely connects back to a central site, and then becomes the platform to logically provision all other network elements to start a remote network infrastructure, wherein this process may be accomplished without intervention by network engineers at the remote site. The connection and communication between the central and remote site can be implemented over various networks, such as over the Internet, over a private IP network, over a cellular network, and/or other networks. According to implementations herein, the base server can ensure physical and logical integrity even if the environment or the chain of custody of the equipment involved is not trusted.