Factory Device Provisioning Portal for Secure Network Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The provisioning of factory devices in enterprise network systems is challenging due to their diversity, specific configurations, and the need for secure, efficient, and automated management, as conventional mobile device management systems are inadequate for factory environments.

Innovation Solution

The implementation of a Factory Device Provisioning (FDP) system comprising an FDP portal and module, which interacts with an Enterprise Device Management (EDM) module to request and retrieve device information, generate device-configuring information, and facilitate enrollment of factory devices into the enterprise network, providing granular control and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual provisioning processes are used for factory devices, then flexibility and control are maintained, but provisioning speed and efficiency deteriorate

Engineering Contradiction:
Improveprovisioning controlVSAvoidprovisioning speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system enables self-service provisioning where factory devices automatically register themselves with the enterprise network. The device performs self-enrollment by communicating its identity and capabilities to the network, which automatically provisions it with appropriate policies and configurations, eliminating the need for manual intervention while maintaining security and control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary provisioning actions by pre-configuring device profiles, access policies, and security parameters before the device actually connects to the network. This allows the device to be rapidly integrated upon connection, as the provisioning work has already been prepared in advance based on device type and factory requirements.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If conventional mobile device management systems are used, then general-purpose management is achieved, but factory-specific configuration requirements and security needs are not met

Engineering Contradiction:
Improvedevice management coverageVSAvoidfactory-specific configuration reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies local quality by implementing factory-specific provisioning policies and configurations tailored to different device types, locations, and use cases within the enterprise network. Each factory or department can have customized security parameters, access controls, and operational profiles that match their specific requirements, rather than applying uniform generic settings.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary provisioning layer between conventional mobile device management and factory-specific requirements. This intermediary translates general device management capabilities into factory-appropriate configurations, acting as a mediator that adapts standard protocols and policies to meet specialized industrial needs while maintaining compatibility with existing systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated provisioning is implemented, then provisioning speed and efficiency are improved, but system complexity and security requirements increase

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidprovisioning system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the provisioning process into distinct modular components: device identification, authentication, profile selection, policy application, and network integration. Each segment handles a specific aspect of provisioning independently, which reduces overall system complexity by breaking down the automated process into manageable, well-defined stages that can be implemented and maintained separately.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11604453B2Methods and systems for provisioning factory devices within enterprise network systems
Publication Date: 2023.03.14 THE BOEING CO
  • US11604453B2 patent drawing
  • US11604453B2 patent drawing
  • US11604453B2 patent drawing

AI summary

Described are new methods and systems for provisioning factory devices in enterprise network systems using specially configured Factory Device Provisioning (FDP) portals, FDP modules, which is used for supporting various operations of the FDP portals, and enterprise device management (EDM) modules. In some examples, an EDM module stores a device-information set (e.g., an asset tag), while an FDP module stores a device-location list and a device profile, corresponding to a certain factory device. An FDP portal allows a user, through a user interface provided by the DRP portal, to retrieve and review this information without directly interacting with the EDM module. The FDP portal then allows the user to initiate a device enrollment request for the factory device. The FDP module generates a device-configuring information, which is presented by the FDP portal and used for connecting the factory device to the enterprise network system.