Hierarchical Database Architecture for Enterprise Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing MNO subscription model is not viable for managing access to enterprise wireless networks due to factors such as smaller user bases, varying enterprise sizes, and the need for customized access and policies, which poses challenges in credential management, storage, and scalability.

Innovation Solution

A multi-tenancy tiered CUPS architecture that allows individual enterprises to manage credentials and policies through a centralized cloud-based orchestration network (O-NET), enabling efficient distribution and reuse of credentials across multiple enterprise networks, with a hierarchical database structure for quick access and caching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized database is used for credential storage in enterprise networks, then access control and management are simplified, but scalability and performance degrade due to single points of failure and access bottlenecks

Engineering Contradiction:
Improvecredential managementVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized credential database into multiple distributed database instances across different network locations. Each database instance stores a portion of the credential data, eliminating the single point of failure and allowing the system to scale horizontally by adding more database nodes as needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a hierarchical database architecture where local enterprise databases are nested within a broader cloud-based credential management system. The local databases provide fast access for immediate credential verification, while the cloud-based system provides centralized coordination and synchronization, creating a nested structure that combines local autonomy with global management.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of operation

If credentials are stored in a single centralized location, then management is simplified, but access performance and speed degrade due to network latency and bottlenecks

Engineering Contradiction:
Improvecredential managementVSAvoidaccess speed
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent places credential database copies at multiple strategic locations including local enterprise networks and cloud data centers. This allows credential verification to occur locally or at nearby data centers rather than requiring all access to traverse to a single centralized location, significantly reducing network latency and improving access speed while maintaining centralized management capabilities.

Inventive Principle:
Principle #3Local quality

3Extent of automation

If a single enterprise manages all credentials, then policy control is centralized, but adaptability to different enterprise sizes and needs decreases

Engineering Contradiction:
Improvepolicy managementVSAvoidenterprise customization
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic credential management system where policies and database configurations can be automatically adjusted based on enterprise size, security requirements, and operational needs. The system can dynamically provision new database instances, adjust replication factors, and modify access policies without manual intervention, allowing it to adapt to varying enterprise requirements while maintaining centralized orchestration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11838984B2Hierarchical database architecture for subscriber credential management in enterprise networks
Publication Date: 2023.12.05 CELONA INC
  • US11838984B2 patent drawing
  • US11838984B2 patent drawing
  • US11838984B2 patent drawing

AI summary

A credential management system for enterprise networks (ENs) that allows credential storage in different levels and enables individual enterprises to manage the sets of credentials for the SIM cards used in their respective networks. Central management of credentials is provided by a remote cloud-based, centralized orchestration network (O-Net) that receives SIM cards from a SIM Provisioning Platform (SPP) and distributes the credentials to the ENs, which store the credentials in an enterprise global database and assign the SIM cards to the UEs. The credentials can be associated with specific policies and user groups so that the enterprise can control the type and quality of access allowed to UEs. Each EN may have a plurality of campus locations and at each location, a local credential database may be provided to act as a cache for quick efficient access to credentials by the UEs.