Device Management Server Authentication for Fixed Wireless Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of complex communication networks, particularly in areas with initial 5G wireless deployment, is hindered by signal interference and variability due to high mm-wave frequencies, requiring secure and efficient methods for installing and optimizing fixed wireless access devices while maintaining security and reducing the time spent on finding optimal signal placements.

Innovation Solution

A system and method for authenticating and authorizing user devices to access fixed wireless access devices, utilizing a device management server to generate unique certificates and one-time passwords, ensuring secure access while allowing technicians to easily log in and monitor signal quality, thereby facilitating optimal placement of devices without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for device management, then ease of operation is maintained, but security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A device management server acts as an intermediary between technicians and fixed wireless access devices. The server handles certificate generation, authentication, and authorization processes, allowing technicians to access device configuration interfaces securely without complex manual authentication procedures. The server mediates the authentication by verifying credentials and managing security certificates automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual device installation and configuration is performed, then adaptability to different deployment scenarios is maintained, but time consumption increases

Engineering Contradiction:
Improveinstallation speedVSAvoiddeployment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Security certificates and authentication credentials are generated and configured in advance by the device management server before technicians arrive at deployment locations. Device profiles and configuration parameters are pre-prepared based on deployment scenarios. This preliminary setup reduces on-site configuration time and simplifies the installation process while maintaining adaptability to different scenarios.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service capabilities where devices automatically perform authentication and configuration tasks. Technicians simply need to present their credentials, and the device management server automatically handles certificate verification, device provisioning, and configuration deployment without requiring manual intervention for each step, thereby speeding up installation while managing complexity centrally.

Inventive Principle:
Principle #25Self-service

3Reliability

If security measures are strengthened for device access, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoiddevice access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device management server serves as a security intermediary that handles all authentication and authorization operations. Technicians interact with the server through standardized interfaces, and the server manages security certificates, validates credentials, and controls access to device configuration interfaces. This centralizes security management while providing a user-friendly access experience for technicians.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the device management server continuously monitors authentication status, device access requests, and security events. The server provides real-time feedback to technicians about authentication success, authorization levels, and device status, enabling secure access while maintaining operational efficiency through automated security verification and status reporting.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11444788B2Authentication and access control for device management and provisioning
Publication Date: 2022.09.13 VERIZON PATENT & LICENSING INC
  • US11444788B2 patent drawing
  • US11444788B2 patent drawing
  • US11444788B2 patent drawing

AI summary

A method or system for authentication and access control in for network device management is disclosed. The method or system may include establishing a communication channel between a user device and a network device and receiving, by the network device, a public-key certificate including a specified identity of the user device. The method or system may include determining whether the public-key certificate is valid against a root certificate stored in the network device, and determining an actual identity of the user device. The method or system may include indicating that the user device is authentic and authorized when the received public-key is valid against the root certificate and when the actual identity of the user device matches the specified identity in the public-key certificate.