Provisioning Device for Secure Network Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in securely managing access to networks, particularly in setting up and maintaining secure network connections for user equipment (UE) that lack proper credentials or information to access endpoints within a network, while also needing to limit access to maintain network security.

Innovation Solution

A system where a user equipment (UE) accesses a provisioning device to obtain network access data, using provisioning network configuration data to establish a VPN tunnel, which then enables access to a primary network by obtaining primary network configuration data, allowing secure access while maintaining network security through validation and credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network administrators limit access to maintain network security, then network security is improved, but it becomes difficult for users to set up and communicate with new networks

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork setup difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a provisioning device as an intermediary between the user equipment and the secure network. This provisioning device facilitates the enrollment process by providing network access data and credentials to authorized devices, thereby maintaining network security while enabling legitimate users to connect easily without directly exposing the secure network to unauthorized access attempts

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a user equipment accesses a provisioning device to obtain network access data, then ease of network enrollment is improved, but network complexity increases

Engineering Contradiction:
Improvenetwork enrollment simplicityVSAvoidprovisioning system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the network access system into distinct functional components: user equipment, provisioning device, and secure network. The provisioning device is further divided into components that handle identification data reception, validation, and network access data generation. This segmentation allows each component to perform its specific function independently, simplifying the overall system architecture and making the enrollment process more manageable despite the added complexity of the provisioning layer

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11968181B2Secure network enrollment
Publication Date: 2024.04.23 OCEUS NETWORKS LLC
  • US11968181B2 patent drawing
  • US11968181B2 patent drawing
  • US11968181B2 patent drawing

AI summary

A UE communicates with a network gateway to access a provisioning device via a provisioning network. The provisioning device uses identification data of the UE to authenticate the UE for a primary network, and provides primary network configuration data to the UE. Using the primary network configuration data, the UE communicates with the network gateway to access the primary network. The primary network configuration data can include data to enable the UE to establish communications with one or more private networks accessible via the primary network.