Edge Server Authentication Using TLS-Bound Access Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for Edge Enabler Clients (EECs) in 5G networks, such as AKMA and Transport Layer Security (TLS), are unsuitable for interfaces between EECs and various servers, leading to deployment challenges for edge computing solutions.

Innovation Solution

Implementing a token-based authentication system where clients and servers use initial and subsequent access tokens, authenticated via TLS with server certificates and IP address verification, to securely bind EEC and UE identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (AKMA, TLS) are used for EEC-server interfaces, then security can be provided, but deployment challenges arise and the methods are unsuitable for edge computing scenarios

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment suitability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the authentication parameters from traditional AKMA/TLS methods to a token-based system using Edge Authentication Tokens (EAT) and Edge Authorization Tokens (EAToken). This parameter change makes the authentication method suitable for edge computing deployments while maintaining security, as tokens can be efficiently distributed and validated in distributed edge environments.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an Edge Enabler Server (EES) as an intermediary that mediates between the EEC and other edge services. The EES issues and manages authentication tokens, simplifying the deployment process by centralizing token management while enabling distributed edge computing operations without requiring complex point-to-point TLS configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If EEC authentication is implemented without binding to UE identity, then deployment is simpler, but security is compromised as EEC may not be running on correct UE

Engineering Contradiction:
Improvedeployment simplicityVSAvoididentity binding security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges EEC authentication with UE identity verification by having the EES bind the EAT to the UE's permanent identifier (SUPI or GPSI). This combination ensures that only the legitimate UE can obtain and use the EAT, providing strong security guarantees while maintaining deployment simplicity through centralized token management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary binding of the EAT to the UE identity during the authentication phase before the EEC accesses edge services. The EES verifies the UE's identity and binds the token in advance, ensuring that subsequent service access is securely authorized without requiring complex runtime verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple authentication mechanisms are supported for different interfaces, then versatility is improved, but system complexity increases

Engineering Contradiction:
Improveinterface compatibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal token-based authentication framework that can be applied across multiple edge computing interfaces (EEC-EES, EES-ECS, EAS-EES). The same EAT and EAToken mechanisms work for all these interfaces, providing multi-functionality without requiring separate authentication systems for each interface type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the authentication system into distinct functional components: EAT for EEC authentication with EES, EAToken for EES authorization with other services, and separate authentication flows for different interface types. This segmentation allows each component to be optimized independently while maintaining overall system versatility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12513521B2Authentication and authorization of servers and clients in edge computing
Publication Date: 2025.12.30 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12513521B2 patent drawing
  • US12513521B2 patent drawing
  • US12513521B2 patent drawing

AI summary

Embodiments include methods performed by a client in an edge data network. Such methods include obtaining an initial access token before accessing the edge data network. The initial access token is based on an identifier of the client. Such methods include establishing a first connection with a server of the edge data network based on transport layer security (TLS) and authenticating the server based on a server certificate received from the server via the first connection. Such methods include providing the initial access token to the server, via the first connection, for authentication of the client. Other embodiments include complementary methods performed by a server in an edge data network, as well as apparatus (e.g., user equipment and servers) configured to perform such methods.