Provisioning Flow Anomaly Detection Across Multi-Layer Network Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunications networks face challenges in detecting and locating provisioning failures across multiple layers and elements due to the lack of a global view, leading to increased customer care calls and network congestion, especially with diverse service brands and growing subscriber bases.

Innovation Solution

Implementing a network system with a billing system, network provisioning engine, and anomaly detection application that captures provisioning logs to train a probability density model for real-time anomaly detection, correlating anomalies across end-to-end provisioning flows using machine learning to identify error sources quickly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional provisioning monitoring is used without a global view, then device complexity is reduced, but anomaly detection precision deteriorates

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the complex provisioning network into multiple layers (network element layer, provisioning layer, segment layer) and components (provisioning flow elements). Each layer is monitored independently for basic metrics, while the ML model correlates anomalies across layers. This segmentation allows precise anomaly detection without requiring a single monolithic system to process all data centrally, thus maintaining detection precision while managing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary anomaly detection system that sits between the provisioning network elements and the core network. This intermediary captures provisioning logs, trains ML models, and correlates anomalies across different layers. By placing this intermediary layer, the system achieves global view anomaly detection precision without requiring complete reconfiguration of the entire network, thus improving detection while adding controlled complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive provisioning logs are captured across all layers, then anomaly detection precision is improved, but loss of time increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidtraining time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously capturing and storing provisioning logs from all layers in advance. The ML model is trained on this pre-captured historical data, so when anomalies need to be detected in real-time, the training work is already completed. This preliminary data collection and model training approach allows comprehensive anomaly detection precision without incurring time delays during actual anomaly detection events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous provisioning log capture across all network layers, maintaining an ongoing record of provisioning operations. This continuous data collection ensures that the ML model always has fresh training data and can detect anomalies immediately when they occur. The continuous action of log capture eliminates gaps in monitoring while the automated ML processing ensures timely anomaly detection without manual intervention delays.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If multiple provisioning flow elements are monitored simultaneously, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveprovisioning throughputVSAvoidmonitoring system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal anomaly detection framework that can monitor multiple provisioning flow elements (network elements, provisioning flows, segment layer elements) simultaneously through a single standardized interface. The ML model is designed to handle diverse provisioning data types uniformly, allowing the system to scale monitoring across multiple elements without proportionally increasing complexity. This multi-functionality enables high provisioning throughput while keeping the monitoring system complexity manageable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adds a new dimension to monitoring by implementing multi-layer correlation (network element layer, provisioning layer, segment layer) rather than monitoring elements in isolation. This dimensional approach allows the system to detect anomalies across multiple provisioning flow elements simultaneously by correlating data across layers. The ML model processes multi-dimensional provisioning data, enabling comprehensive monitoring of multiple elements without linearly increasing system complexity, thus improving provisioning throughput.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20260019349A1Efficient Anomaly Workflow Detection for End-to-end Provisioning Systems
Publication Date: 2026.01.15 T MOBILE INNOVATIONS LLC
  • US20260019349A1 patent drawing
  • US20260019349A1 patent drawing
  • US20260019349A1 patent drawing

AI summary

A method implemented in a network system to provide anomaly detection simultaneously across elements along end-to-end provisioning flows. The method includes receiving a provisioning log captured from provisioning flows over a predefined period, wherein the provisioning log comprises operations and responses associated with provisioning flow elements comprising transaction types, subscriber segments, network provisioning catalogs (NPCs), and network elements (NEs); determining, based on the provisioning log, metrics, each indicating a success rate for a respective one of the provisioning flow elements; determining a machine learning (ML) model to approximate a probability density of the metrics; determining an anomaly at one or more of the provisioning flow elements based on the ML model; and triggering an action address to the detected anomaly.