Boot Agent Zero-Touch Network Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring network devices, such as routers or switches, in complex secure corporate networks often requires trained IT staff and is cumbersome, especially for remote locations, as existing methods lack a straightforward, automated process for provisioning these devices.

Innovation Solution

A system and method that enables zero-touch provisioning of network devices by loading a boot agent, which allows them to connect to a cloud-based provisioning engine, using USB keys or internet connections, and employs Java applets and scripts to automate configuration, determining internet connectivity, and establishing secure tunnels for full provisioning without on-site IT expertise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional manual configuration methods are used for network devices, then configuration accuracy and security can be ensured, but the complexity of operation increases and requires trained IT staff

Engineering Contradiction:
Improveconfiguration processVSAvoidprovisioning system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The network device automatically performs provisioning tasks through a boot agent that contacts the provisioning engine. The device self-configures by receiving configuration files and executing them without requiring manual intervention from IT staff, thereby improving ease of operation while the provisioning engine handles the complexity in the background

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A cloud-based provisioning engine acts as an intermediary between the network device and the configuration management system. This intermediary automates the provisioning process by receiving requests from the boot agent, generating appropriate configuration files, and delivering them to the device, thus simplifying operations while managing system complexity centrally

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated provisioning is implemented, then productivity and ease of operation improve, but reliability and security may be compromised

Engineering Contradiction:
Improveprovisioning speedVSAvoidconfiguration security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The provisioning system implements feedback mechanisms where the boot agent reports device status and configuration needs to the provisioning engine. The engine processes this feedback, generates appropriate secure configurations, and verifies successful deployment. This closed-loop feedback ensures automated provisioning maintains security through verified, controlled configuration delivery

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Security configurations and authentication mechanisms are established in advance as part of the automated provisioning process. The boot agent and provisioning engine pre-configure secure communication channels, encryption, and access controls before the device goes live, ensuring security is built-in from the start rather than added later

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If remote provisioning is enabled, then ease of operation for remote locations improves, but the need for initial setup and connectivity becomes a barrier

Engineering Contradiction:
Improveremote deploymentVSAvoidinitial setup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring the boot agent on the network device before deployment. The device is pre-programmed with the provisioning engine's address and basic connectivity parameters, so upon power-up, it can immediately initiate the automated provisioning process without requiring on-site configuration or waiting for IT staff arrival

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9760528B1Methods and systems for creating a network
Publication Date: 2017.09.12 GLUWARE IP LLC
  • US9760528B1 patent drawing
  • US9760528B1 patent drawing
  • US9760528B1 patent drawing

AI summary

Systems and methods described herein may perform processing associated with loading, with a boot agent injection module in communication with a processor; a boot agent into a memory of a network device comprising a processor; and perform processing associated with using the boot agent to configure, with the network device, the network device to connect to a remote computer.