Network Access Control for Customer Premises Equipment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing provisioning processes for customer-premises equipment accessing networks are slow, cumbersome, and error-prone, limiting user flexibility, especially when moving or replacing equipment, as they require manual administrative actions and complex data entry.
Innovation Solution
A system and method that use a network interface to obtain equipment and line identifiers, search a trusted access database for a combination of these identifiers, and grant access to the network if valid credentials are found, or provide temporary access to submit credentials digitally, allowing automatic network access without manual provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual provisioning processes are used to register customer-premises equipment and grant network access, then network access control is achieved, but the process becomes slow, cumbersome, and error-prone
Solution Approach 1:
The system enables customer-premises equipment to automatically register itself with the network access server by transmitting its identifier without human intervention. The server autonomously processes the registration, searches the database for valid credentials, and grants access automatically, eliminating the need for manual administrative actions while maintaining secure access control.
Solution Approach 2:
The patent replaces manual mechanical processes (administrative personnel entering data, scheduling events) with an automated electronic system. The network access server automatically receives equipment identifiers, queries databases using electronic protocols, and processes authentication credentials through computerized workflows, substituting human manual operations with automated computational processes.
2Reliability
If manual provisioning processes are used to register customer-premises equipment, then network access is granted, but the process is cumbersome and error-prone due to manual actions
Solution Approach 1:
The customer-premises equipment performs self-registration by automatically transmitting its identifier to the network access server. The system autonomously completes the provisioning workflow including database queries and authentication verification, eliminating manual data entry and administrative interventions that cause errors and complexity.
Solution Approach 2:
The system uses the equipment identifier as a digital copy or representation of the physical device. This identifier serves as a unique key that automatically links the equipment to its authentication credentials in the database, replacing manual copying and entry of device information with automated identifier-based registration.
3Reliability
If traditional provisioning processes are used, then network access is controlled, but user flexibility is limited when moving or replacing equipment
Solution Approach 1:
When equipment moves to a new location or is replaced, it automatically re-registers with the network access server by transmitting its identifier. The server autonomously handles the re-provisioning process, maintaining secure access control while enabling users to freely move or replace equipment without administrative intervention.
Solution Approach 2:
The provisioning system transitions from a static, pre-configured approach to a dynamic, on-demand registration process. Equipment can automatically register at any location or time by communicating its identifier to the server, which dynamically processes the registration and grants access based on real-time credential verification, enabling flexible user mobility.
4Productivity
If automated registration is implemented, then provisioning speed improves, but system complexity increases
Solution Approach 1:
The network access server performs multiple functions: it acts as an authentication server, a database management system, and an access control decision-maker. By consolidating these functions into a single multi-functional system, the patent achieves automated fast provisioning without requiring a complex distributed architecture of separate specialized components.
Solution Approach 2:
The equipment identifier serves as an intermediary that bridges the physical equipment and its digital authentication credentials in the database. This simple identifier mechanism enables automated registration and fast provisioning by providing a direct link between the device and its authorization information, avoiding complex identification and verification protocols.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and computer-implemented method are provided for controlling network access of customer-premises equipment which may be connected via a last mile access line to a transport network. The last mile access line may terminate at a line terminal in the transport network. Said controlling may comprise searching a trusted access database for an entry containing a combination of an equipment identifier and a line identifier. If the entry is found and if the entry contains a user identifier having user credentials which are valid according to an authorization database, the network access may be granted. If the entry is not found, temporary access may be granted to a private network which may enable a user identifier and user credentials to be digitally submitted. If the user credentials are valid according to the authorization database, the network access may be subsequently granted.