Dynamic PSK Derivation for Edge Computing Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge computing systems face challenges in establishing secure connections for accessing edge computing services due to inefficiencies in provisioning security credentials and the time required for secure connection establishment.

Innovation Solution

The proposed solution involves dynamically deriving a Pre-shared key (PSK) and using it for authentication and secure connection establishment between a User Equipment (UE) and an Edge Configuration Server (ECS) in an edge computing system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for edge computing services, then security credentials can be provisioned, but the time required for secure connection establishment is excessive

Engineering Contradiction:
Improvesecurity credential provisioningVSAvoidsecure connection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-provisioning security credentials (authentication credentials, encryption keys, and certificates) in the edge computing system before actual service access. The UE receives and stores these credentials in advance during initial system setup or registration, so that when secure connection establishment is needed, the credentials are already available locally, eliminating the time-consuming process of real-time credential provisioning and exchange.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If security credentials are pre-provisioned in edge computing systems, then connection establishment time is reduced, but the complexity of credential management increases

Engineering Contradiction:
Improvesecure connection establishment timeVSAvoidcredential provisioning system
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary credential management entity that acts as a mediator between the UE and the edge computing services. This intermediary entity handles the complex tasks of credential generation, distribution, storage, and renewal automatically. The UE simply interacts with this intermediary to obtain credentials, while the intermediary manages the complexity of credential lifecycle operations, including secure storage, rotation, and revocation, thereby reducing the apparent complexity for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service mechanisms where the UE automatically manages its own security credentials through local storage and usage. The credentials are provisioned once and then autonomously used for multiple connection establishments without requiring repeated external provisioning. The system includes automatic credential renewal and rotation capabilities, where the UE can independently refresh its credentials without manual intervention, reducing operational complexity over time.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12267676B2Methods and systems for authentication and establishment of secure connection for edge computing services
Publication Date: 2025.04.01 SAMSUNG ELECTRONICS CO LTD
  • US12267676B2 patent drawing
  • US12267676B2 patent drawing
  • US12267676B2 patent drawing

AI summary

Methods and systems for authentication and establishment of secure connection for accessing edge computing services are provided. The method includes dynamically deriving a pre-shared key (PSK) and use the dynamically derived PSK for the authentication, while performing or before performing a secure connection establishment or while or before establishing a secure interface between a user equipment (UE), and a server, wherein the UE includes an Edge Enabler Client (EEC), and the server is an Edge Configuration Server (ECS). The method further includes deriving the PSK based on an Authentication and Key Management for Applications (AKMA) application key.