AKMA and GBA Negotiation for 5G Edge Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication mechanisms for Edge Enabler Client (EEC) in 5G networks, such as AKMA and GBA, do not enable application servers to determine whether a User Equipment's (UE) Home Public Land Mobile Network (HPLMN) supports AKMA, GBA, or both, leading to ambiguity and incompatibility in edge computing deployments.
Innovation Solution
A negotiation mechanism is introduced where the UE sends a message with pre-shared key (PSK) identity hints and security key identifiers to the edge data network server, allowing the server to determine supported authentication procedures and establish secure connections using TLS certificates when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication mechanisms (AKMA/GBA) are used without negotiation, then authentication can be performed, but the server cannot determine HPLMN support status leading to ambiguity and incompatibility
Solution Approach 1:
The patent applies preliminary action by having the UE send PSK identity hints and security key identifiers to the server before actual authentication takes place. This advance information exchange enables the server to determine HPLMN support status for AKMA and GBA, allowing proper authentication procedure selection without ambiguity.
Solution Approach 2:
The patent uses PSK identity hints as an intermediary mechanism that carries information about HPLMN support status. These hints act as a mediator between the UE's authentication capabilities and the server's authentication procedure selection, enabling the server to make informed decisions about which authentication method to use.
2Adaptability or versatility
If multiple authentication procedures are supported, then versatility is improved, but negotiation complexity increases
Solution Approach 1:
The patent segments the authentication negotiation by separating different authentication procedures (AKMA and GBA) into distinct, identifiable components. Each procedure has its own PSK identity hint and security key identifier, allowing the server to evaluate and select appropriate procedures independently based on HPLMN support status without complex interdependencies.
Solution Approach 2:
The patent uses parameter changes by encoding HPLMN support information for different authentication procedures into PSK identity hints. The server changes its authentication procedure selection based on these parameters, enabling versatile support for multiple procedures while keeping the negotiation mechanism relatively simple through structured parameter exchange.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Embodiments include methods performed by a user equipment (UE) configured with a client for an edge data network. Such methods include sending, to a server in the edge data network, a first message that includes one of the following contents: at least one pre-shared key (PSK) identity hint that is supported by the UE and the UE's home public land mobile network (HPLMN), and one or more security key identifiers corresponding to respective one or more of a plurality of authentication procedures supported by at least the HPLMN; an indication of the UE's HPLMN; all valid PSK identity hints, and the one or more security key identifiers; or all valid PSK identity hints, and the indication of the HPLMN. Such methods also include receiving from the server a second message that includes one of the following contents: all valid PSK identity hints; or a PSK identity hint that is supported by at least the UE's HPLMN.