Dynamic EHN Provisioning via Quarantine Zone

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in provisioning portable electronic devices to connect and utilize small-scale enterprise-hosted networks, such as those using Long Term Evolution (LTE), especially in self-service Bring Your Own Device scenarios, where entities struggle to onboard devices without issuing SIMs and provide customized services.

Innovation Solution

A communication technique that allows portable electronic devices to discover and connect to an enterprise-hosted network (EHN) using a quarantine zone, providing valid credentials, and receiving provisioning information to customize applications for venue-specific access, enabling secure and dynamic configuration for value-added services like customized phone numbers and remote check-in.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If portable electronic devices connect directly to enterprise-hosted networks, then network access is enabled, but security risks increase due to untrusted devices

Engineering Contradiction:
Improvenetwork accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network access process is segmented into distinct phases: initial connection phase and trusted access phase. During initial connection, devices connect through restricted access points with limited privileges. After authentication and provisioning, devices transition to the trusted phase with full network access. This segmentation allows secure onboarding while maintaining network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A provisioning server acts as an intermediary between portable devices and the enterprise network. The server mediates the authentication process, validates device credentials, and distributes provisioning information. This intermediary layer enables secure device verification without requiring direct trust between devices and network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If entities issue SIM cards for device provisioning, then network connectivity is ensured, but device complexity and provisioning cost increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidprovisioning process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Portable devices perform self-provisioning by automatically discovering enterprise networks, initiating authentication sequences, and receiving provisioning information without manual intervention. The device autonomously completes the onboarding process by storing credentials and configuring network parameters, eliminating the need for SIM card distribution and manual provisioning by entity personnel.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The provisioning system supports multiple device types and network access methods through a universal provisioning protocol. Instead of requiring device-specific SIM cards, the system uses a standardized authentication and provisioning mechanism that works across diverse portable devices, simplifying the provisioning process while ensuring reliable network connectivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If application customization for venue-specific services is implemented, then service quality improves, but provisioning time and complexity increase

Engineering Contradiction:
Improveservice customizationVSAvoidprovisioning time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Enterprise networks pre-configure provisioning information templates for common venue-specific services before devices connect. When a device provisions, it automatically receives and applies these pre-prepared configurations for services like voice exchanges and check-in systems. This preliminary preparation enables rapid service customization without requiring time-consuming manual configuration during the provisioning process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Devices automatically receive and apply provisioning information for customized services without user intervention. The provisioning server pushes service-specific configurations to devices, which then self-configure to enable venue-specific functionalities. This automated process delivers customized services quickly while minimizing provisioning time and complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11503017B2EHN venue-specific application provisioning
Publication Date: 2022.11.15 OUTDOOR WIRELESS NETWORKS LLC
  • US11503017B2 patent drawing
  • US11503017B2 patent drawing
  • US11503017B2 patent drawing

AI summary

In order to leverage an enterprise-hosted network (EHN) associated with an entity, a communication technique may dynamically customize an application on a portable electronic device. In particular, the portable electronic device may discover and then may connect to the EHN using a quarantine zone that restricts access to the EHN. After providing valid credentials to establish a level of trust with the EHN, the portable electronic device may receive a request for authentication and authorization information. In response to the request, the portable electronic device may provide a credential to the EHN. Next, the portable electronic device may receive provisioning information that customizes the application on the portable electronic device to a venue associated with the entity. The provisioning information may include a connection setting associated with the application on the portable electronic device, which allows the portable electronic device to connect to the EHN outside of the quarantine zone.