Telecom Provisioning System Virtual Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current provisioning systems for telecommunications networks struggle to efficiently manage and automate the provisioning of services for virtual operators, leading to increased operational costs and complexity for network operators, while also compromising security and control over network resources.

Innovation Solution

A provisioning system that enables network operators to provide a unified platform for both their own and virtual operators, using a virtual network model to differentiate access and control, with an authenticated and authorized Application Program Interface (API) for virtual operators, allowing them to provision subscribers and activate services without direct access to physical network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a unified provisioning system is used for both network operators and virtual operators, then productivity and automation are improved, but security and control over network resources deteriorate

Engineering Contradiction:
Improveprovisioning automationVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The provisioning system is segmented into multiple virtual instances, each dedicated to a specific operator (network operator or virtual operator). Each virtual instance maintains independent configuration, access control policies, and operational parameters. This segmentation allows the system to provide automated provisioning services to multiple operators simultaneously while maintaining security boundaries and preventing unauthorized access to network resources through virtualization isolation mechanisms.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If virtual operators have direct access to physical network elements, then ease of operation is improved, but harmful factors and security risks increase

Engineering Contradiction:
Improveservice provisioning capabilityVSAvoidnetwork security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A virtualization layer is introduced as an intermediary between virtual operators and physical network elements. This virtualization layer provides abstracted access interfaces that enable virtual operators to provision and manage services without direct exposure to underlying physical infrastructure. The intermediary enforces access control policies, validates provisioning requests, and translates high-level service commands into appropriate network element operations, thereby maintaining security while preserving operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the provisioning system is customized for each operator, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveoperator-specific configurationVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The provisioning system is designed as a universal multi-functional platform that can serve multiple operators with different requirements through virtualization. A single unified system architecture provides core provisioning functionalities that can be dynamically configured and customized for each operator instance. The system maintains a common infrastructure while allowing operator-specific configurations, policies, and parameters to be defined within each virtual instance, thereby achieving adaptability without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9083599B2Method, system and computer program product for providing access policies for services
Publication Date: 2015.07.14 COMPTEL CORP
  • US9083599B2 patent drawing
  • US9083599B2 patent drawing
  • US9083599B2 patent drawing

AI summary

The invention relates to a method, system and computer program product for provisioning in a communications network. According to the method at least one request is received form a client system (11, 30) through an Application Program Interface (API, 12, 13) and Management User Interface (48, 49, 58, 59, 93) for defining measures relating to customers and/or services and/or network elements (18, 19, 20, 21, 72), each request is processed in functional layers (80, 81, 82, 83) of the provisioning system hosted by network operator (1, 2). Tasks are executed according to the results of the processing step, and the results are reported to the requesting entity. According to the invention service operators (3, 4) are allowed to use the provisioning system (15) through authenticated Application Program Interface (API, 40, 50) and authorization function (43, 53) after the provisioning rules processing (94) where the rights for the use of the network elements (18, 19, 20, 21, 72) are controlled by the network operator, whereby the network operator is able to present and utilize one physical network in many logical views, each representing the portion accessible for virtual operator, and in this way controllable by network operator with limitations, authentication and authorization rules.