Confidence-Based Network Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for connecting computing devices to secure networks often require user intervention and lack efficient automated processes for authorizing new devices, which can lead to security vulnerabilities and increased user effort.

Innovation Solution

A confidence-based authorization process that uses a series of phases to assess the likelihood of a device's authorization through a confidence score, allowing automated connection without user input by comparing device-specific data against predefined thresholds, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automated connection processes are implemented, then user effort is reduced, but security risks increase due to potential unauthorized access

Engineering Contradiction:
Improveuser effortVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by collecting device data, generating confidence scores, and establishing authorization criteria before the actual connection is made. This advance assessment ensures security validation occurs automatically without requiring user intervention during the connection moment, thus reducing user effort while maintaining security through pre-validated authorization.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual authorization processes are used, then security is maintained through user control, but user effort and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by enabling devices to automatically authenticate themselves through confidence score evaluation. The network system autonomously assesses device credibility, compares confidence scores against thresholds, and grants or denies access without requiring user intervention. This self-authorized process maintains security through automated validation while eliminating time-consuming manual authorization steps.

Inventive Principle:
Principle #25Self-service

3Reliability

If confidence score thresholds are set high, then security is improved by preventing unauthorized access, but device connectivity is reduced

Engineering Contradiction:
ImprovesecurityVSAvoiddevice connectivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies dynamics by making confidence score thresholds adjustable and adaptable rather than fixed. Thresholds can be dynamically configured based on network security requirements, device types, and environmental contexts. This dynamic approach allows the system to optimize the balance between security and connectivity by raising thresholds when security is prioritized and lowering them when device integration is the goal, thus preventing unauthorized access while maintaining productive connectivity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12262204B1Confidence based network provisioning of devices
Publication Date: 2025.03.25 AMAZON TECH INC
  • US12262204B1 patent drawing
  • US12262204B1 patent drawing
  • US12262204B1 patent drawing

AI summary

Techniques for establishing a data connection are described. In an example, a computer system receives, from a second device of a computer network, first data associated with a first device and second data associated with the second device. The first device is not connected to the computer network. The computer system determines third data generated by one or more devices other than the first device and the second device and associated with at least one of: the first device, the second device, a user account, or the computer network. The computer system generates, based on the first data, the second data, and the third data, a confidence score indicating a likelihood of a user authorization to connect the first device to the computer network. The computer system sends, to the second device based on the confidence score, instructions associated with connecting the first device to the computer network.