Application-Specific GPSI Authentication in 5G Edge Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, authenticating user equipment (UE) for Edge Computing applications is challenging due to the complexity of managing multiple generic public subscription identifiers (GPSIs) associated with a single UE subscription, which complicates the authentication process between UE and Edge Computing Servers.

Innovation Solution

The proposed solution involves using application-specific GPSIs and associated information to facilitate authentication, where the UE sends an application service request with an application-specific GPSI and app-info to the Application Function (AF), and the AF derives an application-specific key to authenticate the UE, ensuring that the GPSI used matches the one stored in the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple GPSIs are stored in association with a single UE subscription to support multiple services and applications, then service versatility is improved, but authentication complexity increases

Engineering Contradiction:
Improveservice versatilityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the single UE subscription into multiple application-specific GPSIs, where each GPSI is associated with specific application information (app-info). This allows the network to present different GPSIs to different applications based on their requirements, thereby maintaining service versatility while simplifying authentication for each individual application through dedicated identifiers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by associating specific attributes (app-info) with each GPSI, such that each identifier has specialized characteristics tailored to its intended application. This enables the network to select the appropriate GPSI with the correct attributes for each authentication request, improving versatility while keeping each authentication instance simple and focused.

Inventive Principle:
Principle #3Local quality

2Productivity

If application-specific GPSIs are used to simplify authentication, then authentication efficiency is improved, but identifier management complexity increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoididentifier management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces application information (app-info) as an intermediary that links the UE to the appropriate application-specific GPSI. The app-info contains attributes that enable the network to automatically determine which GPSI to use for a given application, thereby simplifying the authentication process while providing a systematic method for managing multiple identifiers through their associated attributes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If GPSI matching is performed to ensure correct authentication, then authentication accuracy is improved, but processing time increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-associating application information (app-info) with each GPSI during identifier creation. This pre-linking of attributes to identifiers enables the network to quickly match the appropriate GPSI to an application based on the app-info provided in authentication requests, thereby ensuring accurate authentication while minimizing processing time through efficient attribute-based matching.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240276217A1Application-specific GPSI retrieval
Publication Date: 2024.08.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240276217A1 patent drawing
  • US20240276217A1 patent drawing
  • US20240276217A1 patent drawing

AI summary

A method for a user equipment (UE) configured to communicate with an application function (AF) via a communication network is provided. The method comprises sending, to the AF, an application service request including: a second identifier (GPSI) specific to one or more applications, including an application associated with the UE and the AF; and information (app-info) associated with the second identifier and descriptive of the one or more applications. The method further comprises authenticating the AF based on an application-specific key (KAF) derived from a security key (KAKMA) associated with the UE; and receiving, from the AF, an application service response indicating whether the second identifier (GPSI) matches a corresponding second identifier (GPSI*) derived from the information associated with the second identifier.