Zero Touch Network Device Provisioning via Centralized Database Lookup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices often require manual configuration and intervention for provisioning, which can lead to inefficiencies, increased deployment costs, and security risks due to misconfiguration or lack of specialized equipment at remote sites.

Innovation Solution

The implementation of Next Generation Zero Touch Provisioning (NexGen ZTP) technologies, including Expected Device Workflow, URL-Based Redirect Onboarding, and App-Assisted Onboarding, which enable network devices to programmatically configure themselves without requiring a built-in URL or extensive user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration is used for network devices, then users can control the setup process, but deployment time and costs increase due to required user intervention and specialized equipment

Engineering Contradiction:
Improveease of provisioningVSAvoiddeployment time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The network device automatically performs provisioning operations by executing a script obtained from a network management service without requiring user intervention. The device autonomously configures itself, obtains network credentials, and establishes connectivity, eliminating the need for manual configuration by specialized personnel.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network device is pre-configured with a public key and a uniform resource locator (URL) during manufacturing. These preliminary configurations enable the device to automatically authenticate with and download provisioning scripts from the network management service without requiring user setup or specialized equipment at the installation site.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration is performed, then complex networking expertise can be applied, but deployment complexity increases for both owner and provider

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device autonomously executes provisioning operations by automatically downloading and running a script from the network management service. This self-service approach eliminates human error in configuration while reducing the overall complexity of the provisioning process, as no specialized knowledge is required at the installation site.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A network management service acts as an intermediary between the device manufacturer and the deployed device. This service hosts provisioning scripts and credentials, enabling automatic configuration without requiring users to have networking expertise or providers to manually intervene in the setup process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If specialized equipment is provided at remote sites, then proper configuration can be achieved, but equipment costs and site requirements increase

Engineering Contradiction:
Improveprovisioning success rateVSAvoidsite equipment requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device automatically performs all provisioning operations using only its built-in capabilities and pre-configured information (public key and URL). No specialized equipment such as serial cables, SSH clients, or configuration laptops are required at the remote site, eliminating equipment costs while maintaining high provisioning success rates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The provisioning functionality is extracted from the installation site environment and embedded directly into the network device itself through pre-configured credentials and automated scripts. This eliminates the need for external specialized equipment at remote locations while ensuring reliable provisioning.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If DHCP and service discovery are unavailable, then network security can be maintained, but automatic network connectivity cannot be established

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network device is pre-configured with a public key during manufacturing. This preliminary security credential enables the device to authenticate with the network management service and obtain provisioning credentials through a secure key-exchange mechanism, eliminating the need for DHCP or service discovery while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A network management service acts as a secure intermediary that facilitates automatic network connectivity without requiring DHCP or service discovery. The service uses the device's pre-configured public key to establish secure communication channels and provide network credentials, enabling connectivity while maintaining security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250193072A1Next generation zero touch provisioning of network devices
Publication Date: 2025.06.12 ARISTA NETWORKS INC
  • US20250193072A1 patent drawing
  • US20250193072A1 patent drawing
  • US20250193072A1 patent drawing

AI summary

Next generation zero touch provisioning (NexGen ZTP) provides programmatic onboarding features that can benefit those who desire ZTP without requiring them to spend time and money to preprogram network devices with a designated URL for ZTP. Particularly, when a connection request is received from a network device, network device identification information contained in the connection request is used to search for a matching identifier stored in a centralized database. The centralized database stores historical transactions that record sales of network devices. If a matching identifier is found, an owner of the network device can be identified from a corresponding sales record using the matching identifier. Once the owner is identified, a tenant or suborganization of the owner is determined. The network device can then be directed to a configuration file or script corresponding to the tenant or suborganization for ZTP of the network device.