Security Policy Activation Key for Remote Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Setting up a newly deployed network security device in a network can be complex, especially for less sophisticated users, as it requires selecting and configuring a security policy, which is often done remotely and involves authentication through a security policy activation key.

Innovation Solution

A system with a processor and memory that prepares user interfaces for displaying security policy selection and configuration details, generating a security policy activation key for authentication, and updating the interface to include this key for downloading and installing the security policy on the device, facilitating remote setup and configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policy configuration is performed remotely with authentication, then security is improved, but setup complexity increases for less sophisticated users

Engineering Contradiction:
ImprovesecurityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a channel partner as an intermediary that pre-configures security policies and generates activation keys on behalf of end users. This mediator handles the complex authentication and policy selection processes, allowing less sophisticated users to simply enter a pre-provisioned activation key without understanding the underlying security configuration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary configuration actions by pre-provisioning security policies and generating activation keys before the end user receives the device. The channel partner completes the complex security policy selection and authentication setup in advance, so that the end user only needs to perform a simple key entry operation during device initialization.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If security policy selection is automated remotely, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvesetup simplicityVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a channel partner as an intermediary that pre-configures security policies and generates activation keys on behalf of end users. This mediator handles the complex authentication and policy selection processes, allowing less sophisticated users to simply enter a pre-provisioned activation key without understanding the underlying security configuration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service deployment where the security device automatically retrieves and applies the pre-configured security policy using the activation key. The device autonomously completes the policy installation without requiring manual configuration or deep user understanding of security settings, thereby simplifying the user experience while managing complexity through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10666683B2User interface for low-touch security policy provisioning
Publication Date: 2020.05.26 CISCO TECHNOLOGY INC
  • US10666683B2 patent drawing
  • US10666683B2 patent drawing
  • US10666683B2 patent drawing

AI summary

In one embodiment, a system includes a processor, and a memory to store data used by the processor, the processor being operative to prepare a first user interface including a security policy selection section, interpret user input data to include performing at least one security policy selection action in the security policy selection section yielding selection of a first security policy for a first device, and update the first user interface yielding an updated first user interface including the first security policy, and a first security policy activation key for inputting into a second user interface to be generated when the first device is installed, the first security policy activation key being associated with providing authentication for downloading the first security policy to the first device.