Network Equipment Onboarding via Challenge-Response Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for onboarding network equipment in managed networks are costly, cumbersome, and inefficient, particularly in unsecured or public networks, and often require pre-configured hardware or software, which limits their suitability and security.

Innovation Solution

The implementation of an onboarding process using a challenge-response method that authenticates network equipment without requiring special hardware or software, allowing standard devices to be onboarded by issuing a configuration change challenge and detecting its implementation, ensuring secure identification and integration into the network management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional onboarding methods use pre-configured hardware or software, then authentication security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network equipment performs self-configuration by automatically implementing the challenge requested by the onboarding controller without requiring pre-configured hardware or software. The device configures itself based on the challenge parameters received during the onboarding process, eliminating the need for complex pre-provisioning while maintaining security through the challenge-response authentication mechanism.

Inventive Principle:
Principle #25Self-service

2Reliability

If conventional onboarding methods require dedicated hardware, then authentication reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The onboarding solution works with standard network equipment that does not require dedicated authentication hardware. The challenge-response mechanism can be implemented using the equipment's existing configuration capabilities, making the authentication process universally applicable to various network devices without requiring special hardware components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If conventional onboarding methods use manual configuration, then measurement precision is improved, but productivity deteriorates

Engineering Contradiction:
Improveidentification accuracyVSAvoidonboarding efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The onboarding controller sends a challenge that includes configuration parameters in advance, allowing the network equipment to pre-configure itself before formal authentication. This preliminary configuration action enables automatic identification and authentication without requiring manual intervention during the actual onboarding process, thereby improving productivity while maintaining identification accuracy.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If conventional onboarding methods require pre-configuration, then security is improved, but adaptability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The onboarding process uses dynamic challenge-response authentication where the challenge parameters are generated and processed in real-time during the onboarding event. The network equipment configures itself dynamically based on the received challenge without requiring static pre-configuration, enabling the system to adapt to different devices and scenarios while maintaining security through the dynamic authentication mechanism.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11888834B2Methods and systems for onboarding network equipment
Publication Date: 2024.01.30 INTERDIGITAL CE PATENT HOLDINGS SAS
  • US11888834B2 patent drawing
  • US11888834B2 patent drawing
  • US11888834B2 patent drawing

AI summary

Methods are systems are provided for onboarding network equipment to managed networks. An onboarding controller of a managed network may generate a challenge for network equipment to be onboarded into the managed network, and may send the challenge to a communication device different from the equipment network. The challenge may include information relating to a configuration change to be made to the network equipment. Further, the challenge is sent over a connection that is different than a connection used in communicating with the network equipment. The onboarding controller may verify, based on handling of the configuration change, an identity and/or a network location of the network equipment. Handling the configuration change may include applying the configuration change.