Dynamic PSK Derivation for Edge Computing Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing edge computing systems face challenges in establishing secure connections for accessing edge computing services due to inefficiencies in provisioning security credentials and the time required for secure connection establishment.
Innovation Solution
The proposed solution involves dynamically deriving a Pre-shared key (PSK) and using it for authentication and secure connection establishment between a User Equipment (UE) and an Edge Configuration Server (ECS) in an edge computing system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used for edge computing services, then security credentials can be provisioned, but the time required for secure connection establishment is excessive
Solution Approach 1:
The patent applies preliminary action by pre-provisioning security credentials (authentication credentials, encryption keys, and certificates) in the edge computing system before actual service access. The UE receives and stores these credentials in advance during initial system setup or registration, so that when secure connection establishment is needed, the credentials are already available locally, eliminating the time-consuming process of real-time credential provisioning and exchange.
2Loss of time
If security credentials are pre-provisioned in edge computing systems, then connection establishment time is reduced, but the complexity of credential management increases
Solution Approach 1:
The patent introduces an intermediary credential management entity that acts as a mediator between the UE and the edge computing services. This intermediary entity handles the complex tasks of credential generation, distribution, storage, and renewal automatically. The UE simply interacts with this intermediary to obtain credentials, while the intermediary manages the complexity of credential lifecycle operations, including secure storage, rotation, and revocation, thereby reducing the apparent complexity for end users.
Solution Approach 2:
The system implements self-service mechanisms where the UE automatically manages its own security credentials through local storage and usage. The credentials are provisioned once and then autonomously used for multiple connection establishments without requiring repeated external provisioning. The system includes automatic credential renewal and rotation capabilities, where the UE can independently refresh its credentials without manual intervention, reducing operational complexity over time.
Data Source
AI summary
Methods and systems for authentication and establishment of secure connection for accessing edge computing services are provided. The method includes dynamically deriving a pre-shared key (PSK) and use the dynamically derived PSK for the authentication, while performing or before performing a secure connection establishment or while or before establishing a secure interface between a user equipment (UE), and a server, wherein the UE includes an Edge Enabler Client (EEC), and the server is an Edge Configuration Server (ECS). The method further includes deriving the PSK based on an Authentication and Key Management for Applications (AKMA) application key.


