Telecom Provisioning System Virtual Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current provisioning systems for telecommunications networks struggle to efficiently manage and automate the provisioning of services for virtual operators, leading to increased operational costs and complexity for network operators, while also compromising security and control over network resources.
Innovation Solution
A provisioning system that enables network operators to provide a unified platform for both their own and virtual operators, using a virtual network model to differentiate access and control, with an authenticated and authorized Application Program Interface (API) for virtual operators, allowing them to provision subscribers and activate services without direct access to physical network elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a unified provisioning system is used for both network operators and virtual operators, then productivity and automation are improved, but security and control over network resources deteriorate
Solution Approach 1:
The provisioning system is segmented into multiple virtual instances, each dedicated to a specific operator (network operator or virtual operator). Each virtual instance maintains independent configuration, access control policies, and operational parameters. This segmentation allows the system to provide automated provisioning services to multiple operators simultaneously while maintaining security boundaries and preventing unauthorized access to network resources through virtualization isolation mechanisms.
2Ease of operation
If virtual operators have direct access to physical network elements, then ease of operation is improved, but harmful factors and security risks increase
Solution Approach 1:
A virtualization layer is introduced as an intermediary between virtual operators and physical network elements. This virtualization layer provides abstracted access interfaces that enable virtual operators to provision and manage services without direct exposure to underlying physical infrastructure. The intermediary enforces access control policies, validates provisioning requests, and translates high-level service commands into appropriate network element operations, thereby maintaining security while preserving operational ease.
3Adaptability or versatility
If the provisioning system is customized for each operator, then adaptability is improved, but device complexity increases
Solution Approach 1:
The provisioning system is designed as a universal multi-functional platform that can serve multiple operators with different requirements through virtualization. A single unified system architecture provides core provisioning functionalities that can be dynamically configured and customized for each operator instance. The system maintains a common infrastructure while allowing operator-specific configurations, policies, and parameters to be defined within each virtual instance, thereby achieving adaptability without proportionally increasing overall system complexity.
Data Source
AI summary
The invention relates to a method, system and computer program product for provisioning in a communications network. According to the method at least one request is received form a client system (11, 30) through an Application Program Interface (API, 12, 13) and Management User Interface (48, 49, 58, 59, 93) for defining measures relating to customers and/or services and/or network elements (18, 19, 20, 21, 72), each request is processed in functional layers (80, 81, 82, 83) of the provisioning system hosted by network operator (1, 2). Tasks are executed according to the results of the processing step, and the results are reported to the requesting entity. According to the invention service operators (3, 4) are allowed to use the provisioning system (15) through authenticated Application Program Interface (API, 40, 50) and authorization function (43, 53) after the provisioning rules processing (94) where the rights for the use of the network elements (18, 19, 20, 21, 72) are controlled by the network operator, whereby the network operator is able to present and utilize one physical network in many logical views, each representing the portion accessible for virtual operator, and in this way controllable by network operator with limitations, authentication and authorization rules.


