Remote Access Point Self-Provisioning via Captive Portal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deploying remote access points to a large number of users and locations is inefficient due to the time and labor required for proper setup and authorization, as each point needs individual configuration and provisioning by an IT specialist.
Innovation Solution
A method where an un-provisioned remote access point automatically establishes a connection to a controller, receives provisioning parameters, and becomes authorized upon user verification through a secure captive portal, allowing for scalable and controlled deployment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual provisioning by IT specialists is used for each remote access point, then proper configuration and authorization is ensured, but time and labor requirements increase significantly
Solution Approach 1:
The remote access point performs self-provisioning by automatically contacting the controller, retrieving its identifier from storage, and obtaining configuration parameters without human intervention. The device autonomously completes the provisioning workflow including authentication and parameter retrieval.
Solution Approach 2:
The identifier is pre-stored in the remote access point's non-volatile memory before deployment. This preliminary action enables the device to immediately identify itself and retrieve appropriate configuration parameters upon activation, eliminating the need for manual configuration setup.
2Reliability
If manual provisioning by IT specialists is used for each remote access point, then proper configuration and authorization is ensured, but deployment scalability is limited
Solution Approach 1:
Each remote access point independently performs self-provisioning and self-authorization by contacting the controller and retrieving its identifier from stored memory. This eliminates the need for IT specialist involvement in each deployment, enabling scalable rollout to numerous locations simultaneously.
Solution Approach 2:
The identifier is pre-loaded into the device's non-volatile memory during manufacturing, enabling automatic recognition and configuration retrieval upon first use. This preliminary configuration enables immediate autonomous operation and simplifies large-scale deployments.
3Extent of automation
If the remote access point stores and transmits its identifier automatically, then provisioning automation is achieved, but security risks may increase from unauthorized access
Solution Approach 1:
The controller acts as a secure intermediary that receives the identifier from the remote access point, validates it against authorized devices, and conditionally provides configuration parameters. This mediation ensures that only authenticated devices receive full provisioning, preventing unauthorized network access.
Solution Approach 2:
The system implements a feedback loop where the remote access point sends its identifier to the controller, receives validation feedback, and only upon successful authentication does the controller provide configuration parameters. This feedback mechanism ensures secure authorization before provisioning.
Data Source
AI summary
Authorizing remote access points for use in a network: After the remote access point is provisioned to communicate securely to a controller using its TCP/IP address provided by a user, the remote access point is put into an un-authorized state by the controller pending further authorization. The user is presented with a secure captive portal page authenticating the end-user. User's authentication credentials are verified by the controller. After the remote access point has been authorized, the controller marks it verified as a fully functional node, and saves this state. The remote access point is provisioned with the current provisioning parameters for the remote access point as configured by the IT administrator for the end user, so that each remote access point can have unique per-user configuration applied.

