Edge Network Authentication via Anonymous ID Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, user equipment (UE) faces challenges in securely authenticating and authorizing access to edge data networks, as existing methods are vulnerable to ID interception by malicious attackers, compromising user privacy.
Innovation Solution
The UE generates a first credential based on a second credential from the cellular network, creating a message authentication code with a count associated with an edge network client ID, and transmits this information to the edge data network, ensuring the edge enabler client ID is never shared outside the UE, while the network maps a public ID to the client ID within the mobile network operator's domain, preventing external interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE transmits the edge enabler client ID to the edge data network for authentication, then the authentication procedure can be completed, but the ID becomes vulnerable to interception by malicious attackers
Solution Approach 1:
The patent extracts the sensitive edge enabler client ID from the authentication message and replaces it with an anonymous identifier. The UE generates an anonymous ID that does not reveal the actual client ID, thereby removing the vulnerable element while maintaining authentication functionality through separate credential verification.
Solution Approach 2:
The patent introduces an intermediary mechanism where the UE acts as a mediator between the edge enabler client and the edge data network. The UE holds the actual client ID securely and only transmits derived credentials and anonymous identifiers, preventing direct exposure of the client ID while enabling authentication through intermediate credential verification.
2Reliability
If the UE shares the edge enabler client ID with the edge data network, then authentication can be established, but user privacy is compromised
Solution Approach 1:
The patent extracts and separates the identity information from the authentication process. The actual edge enabler client ID is kept confidential within the UE, while an anonymous identifier is used for communication. This extraction prevents privacy loss while maintaining the ability to establish authentication through credential verification alone.
Solution Approach 2:
The patent creates an anonymous copy or representation of the client ID that can be safely transmitted. Instead of sharing the real identifier, the UE generates and transmits an anonymous identifier that serves the same functional purpose for authentication routing without revealing the actual identity, thus preserving user privacy.
3Reliability
If the network stores and maps the edge enabler client ID, then authentication verification can be performed, but the stored ID becomes a target for attacks
Solution Approach 1:
The patent removes the sensitive client ID from the network storage and transmission paths. The edge data network stores and processes only anonymous identifiers and derived credentials, not the actual edge enabler client ID. This extraction eliminates the attack target while maintaining verification capability through the secure credential checking mechanism.
Solution Approach 2:
The patent introduces the UE as an intermediary that securely holds and manages the actual client ID. The network interacts only with anonymous identifiers and credentials, while the UE mediates the verification process by validating credentials against the stored client ID locally, preventing the network from becoming a target for ID-based attacks.
Data Source
AI summary
A user equipment (UE) may attempt to access an edge data network. The UE generates a first credential based on a second credential that was generated for a procedure between the UE and a network. The UE then generates an identifier corresponding to the first credential and generates a message authentication code based on the first credential and a count, wherein the count is associated with an identifier of an edge network client running on the UE. The UE then transmits an application registration request, message to a server associated with an edge data network, the application registration request message including the count, the message authentication code, the identifier corresponding to the first credential, and a public land mobile network identifier (PLMN ID) of the network. The UE then receives an authentication accept message or an authentication reject message from the server associated with the edge data network.


