Network Access Control for Customer Premises Equipment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing provisioning processes for customer-premises equipment accessing networks are slow, cumbersome, and error-prone, limiting user flexibility, especially when moving or replacing equipment, as they require manual administrative actions and complex data entry.

Innovation Solution

A system and method that use a network interface to obtain equipment and line identifiers, search a trusted access database for a combination of these identifiers, and grant access to the network if valid credentials are found, or provide temporary access to submit credentials digitally, allowing automatic network access without manual provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning processes are used to register customer-premises equipment and grant network access, then network access control is achieved, but the process becomes slow, cumbersome, and error-prone

Engineering Contradiction:
Improvenetwork access control reliabilityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables customer-premises equipment to automatically register itself with the network access server by transmitting its identifier without human intervention. The server autonomously processes the registration, searches the database for valid credentials, and grants access automatically, eliminating the need for manual administrative actions while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (administrative personnel entering data, scheduling events) with an automated electronic system. The network access server automatically receives equipment identifiers, queries databases using electronic protocols, and processes authentication credentials through computerized workflows, substituting human manual operations with automated computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual provisioning processes are used to register customer-premises equipment, then network access is granted, but the process is cumbersome and error-prone due to manual actions

Engineering Contradiction:
Improveprovisioning accuracyVSAvoidprovisioning simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The customer-premises equipment performs self-registration by automatically transmitting its identifier to the network access server. The system autonomously completes the provisioning workflow including database queries and authentication verification, eliminating manual data entry and administrative interventions that cause errors and complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses the equipment identifier as a digital copy or representation of the physical device. This identifier serves as a unique key that automatically links the equipment to its authentication credentials in the database, replacing manual copying and entry of device information with automated identifier-based registration.

Inventive Principle:
Principle #26Copying

3Reliability

If traditional provisioning processes are used, then network access is controlled, but user flexibility is limited when moving or replacing equipment

Engineering Contradiction:
Improveaccess control securityVSAvoiduser mobility flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

When equipment moves to a new location or is replaced, it automatically re-registers with the network access server by transmitting its identifier. The server autonomously handles the re-provisioning process, maintaining secure access control while enabling users to freely move or replace equipment without administrative intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The provisioning system transitions from a static, pre-configured approach to a dynamic, on-demand registration process. Equipment can automatically register at any location or time by communicating its identifier to the server, which dynamically processes the registration and grants access based on real-time credential verification, enabling flexible user mobility.

Inventive Principle:
Principle #15Dynamics

4Productivity

If automated registration is implemented, then provisioning speed improves, but system complexity increases

Engineering Contradiction:
Improveprovisioning speedVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network access server performs multiple functions: it acts as an authentication server, a database management system, and an access control decision-maker. By consolidating these functions into a single multi-functional system, the patent achieves automated fast provisioning without requiring a complex distributed architecture of separate specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The equipment identifier serves as an intermediary that bridges the physical equipment and its digital authentication credentials in the database. This simple identifier mechanism enables automated registration and fast provisioning by providing a direct link between the device and its authorization information, avoiding complex identification and verification protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3790231B1Controlling network access of customer-premises equipment
Publication Date: 2023.03.15 KONINK KPN NV
  • EP3790231B1 patent drawingFigure 1
  • EP3790231B1 patent drawingFigure 2
  • EP3790231B1 patent drawingFigure 3

AI summary

A system and computer-implemented method are provided for controlling network access of customer-premises equipment which may be connected via a last mile access line to a transport network. The last mile access line may terminate at a line terminal in the transport network. Said controlling may comprise searching a trusted access database for an entry containing a combination of an equipment identifier and a line identifier. If the entry is found and if the entry contains a user identifier having user credentials which are valid according to an authorization database, the network access may be granted. If the entry is not found, temporary access may be granted to a private network which may enable a user identifier and user credentials to be digitally submitted. If the user credentials are valid according to the authorization database, the network access may be subsequently granted.