Provisioning remote access points
Abstract
Provisioning remote access points for use in a telecommunication network. A remote access point contains identity information established during manufacturing; this identity information may be in the nature of a digital certificate. The identity information is stored in the remote access point, and may be stored in a Trusted Platform Module if present. When the remote access node is powered up in unprovisioned state, outside the manufacturing environment, it attempts to establish an internet connection via a first wired interface, and queries a user for information representing the TCP/IP address of its controller via a second wired interface. Once an internet connection is present, and a TCP/IP address has been provided, the remote access point attempts to connect to the controller at that address. The controller may filter connection requests through a whitelist of approved remote access points. Once a connection is established, controller and access point exchange and verify each other's identities. This may be done through the exchange and verification of digital certificates. Provisioning information is downloaded from controller to remote access point and installed. This may be done via a tunnel such as an encrypted tunnel. Software updates may be applied. The provisioned remote access point is placed in operation.
Claims
exact text as granted — not AI-modified1 . A method of provisioning a remote access point having identity information stored in the remote access point memory, a first wired interface for connecting to the internet, and a second wired interface for connecting to a user computer, the method comprising:
establishing an internet connection on the first wired interface, accepting user input through the second wired interface, the user input representing a TCP/IP address, attempting to connect to a controller at the TCP/IP address via the internet connection on the first wired interface, exchanging and verifying identity information with the controller, downloading and installing configuration information from the controller, and placing the remote access node in operation.
2 . The method of claim 1 where the identity information contains the MAC address of at least the first wired interface.
3 . The method of claim 1 where the identity information is a digital certificate.
4 . The method of claim 1 where the controller maintains a whitelist of remote access points which are allowed to connect, and refusing connections from remote access points not on the whitelist.
5 . The method of claim 1 where the step of downloading and installing configuration information includes downloading and installing any software updates for the remote access point.
6 . The method of claim 1 where the step of downloading and installing configuration information is performed using a tunnel.
7 . The method of claim 6 where the tunnel is encrypted.
8 . The method of claim 6 where the tunnel is an IPsec tunnel.
9 . The method of claim 1 where the user input representing a TCI/IP address is a TCP/IP address.
10 . The method of claim 1 where the user input representing a TCI/IP address is a Fully Qualified Domain Name (FQDN),
11 . The method of claim 1 where the user input representing a TCI/IP address is a code representing a TCP/IP address.Join the waitlist — get patent alerts
Track US2010313262A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.