Remote Access Point Self-Provisioning via Captive Portal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying remote access points to a large number of users and locations is inefficient due to the time and labor required for proper setup and authorization, as each point needs individual configuration and provisioning by an IT specialist.

Innovation Solution

A method where an un-provisioned remote access point automatically establishes a connection to a controller, receives provisioning parameters, and becomes authorized upon user verification through a secure captive portal, allowing for scalable and controlled deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning by IT specialists is used for each remote access point, then proper configuration and authorization is ensured, but time and labor requirements increase significantly

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The remote access point performs self-provisioning by automatically contacting the controller, retrieving its identifier from storage, and obtaining configuration parameters without human intervention. The device autonomously completes the provisioning workflow including authentication and parameter retrieval.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The identifier is pre-stored in the remote access point's non-volatile memory before deployment. This preliminary action enables the device to immediately identify itself and retrieve appropriate configuration parameters upon activation, eliminating the need for manual configuration setup.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual provisioning by IT specialists is used for each remote access point, then proper configuration and authorization is ensured, but deployment scalability is limited

Engineering Contradiction:
Improveconfiguration accuracyVSAvoiddeployment scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Each remote access point independently performs self-provisioning and self-authorization by contacting the controller and retrieving its identifier from stored memory. This eliminates the need for IT specialist involvement in each deployment, enabling scalable rollout to numerous locations simultaneously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The identifier is pre-loaded into the device's non-volatile memory during manufacturing, enabling automatic recognition and configuration retrieval upon first use. This preliminary configuration enables immediate autonomous operation and simplifies large-scale deployments.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If the remote access point stores and transmits its identifier automatically, then provisioning automation is achieved, but security risks may increase from unauthorized access

Engineering Contradiction:
Improveprovisioning automationVSAvoidsecurity risk
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The controller acts as a secure intermediary that receives the identifier from the remote access point, validates it against authorized devices, and conditionally provides configuration parameters. This mediation ensures that only authenticated devices receive full provisioning, preventing unauthorized network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback loop where the remote access point sends its identifier to the controller, receives validation feedback, and only upon successful authentication does the controller provide configuration parameters. This feedback mechanism ensures secure authorization before provisioning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8627423B2Authorizing remote access points
Publication Date: 2014.01.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8627423B2 patent drawing
  • US8627423B2 patent drawing

AI summary

Authorizing remote access points for use in a network: After the remote access point is provisioned to communicate securely to a controller using its TCP/IP address provided by a user, the remote access point is put into an un-authorized state by the controller pending further authorization. The user is presented with a secure captive portal page authenticating the end-user. User's authentication credentials are verified by the controller. After the remote access point has been authorized, the controller marks it verified as a fully functional node, and saves this state. The remote access point is provisioned with the current provisioning parameters for the remote access point as configured by the IT administrator for the end user, so that each remote access point can have unique per-user configuration applied.