Edge Server Authentication Using TLS-Bound Access Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for Edge Enabler Clients (EECs) in 5G networks, such as AKMA and Transport Layer Security (TLS), are unsuitable for interfaces between EECs and various servers, leading to deployment challenges for edge computing solutions.
Innovation Solution
Implementing a token-based authentication system where clients and servers use initial and subsequent access tokens, authenticated via TLS with server certificates and IP address verification, to securely bind EEC and UE identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (AKMA, TLS) are used for EEC-server interfaces, then security can be provided, but deployment challenges arise and the methods are unsuitable for edge computing scenarios
Solution Approach 1:
The patent changes the authentication parameters from traditional AKMA/TLS methods to a token-based system using Edge Authentication Tokens (EAT) and Edge Authorization Tokens (EAToken). This parameter change makes the authentication method suitable for edge computing deployments while maintaining security, as tokens can be efficiently distributed and validated in distributed edge environments.
Solution Approach 2:
The patent introduces an Edge Enabler Server (EES) as an intermediary that mediates between the EEC and other edge services. The EES issues and manages authentication tokens, simplifying the deployment process by centralizing token management while enabling distributed edge computing operations without requiring complex point-to-point TLS configurations.
2Ease of operation
If EEC authentication is implemented without binding to UE identity, then deployment is simpler, but security is compromised as EEC may not be running on correct UE
Solution Approach 1:
The patent merges EEC authentication with UE identity verification by having the EES bind the EAT to the UE's permanent identifier (SUPI or GPSI). This combination ensures that only the legitimate UE can obtain and use the EAT, providing strong security guarantees while maintaining deployment simplicity through centralized token management.
Solution Approach 2:
The patent performs preliminary binding of the EAT to the UE identity during the authentication phase before the EEC accesses edge services. The EES verifies the UE's identity and binds the token in advance, ensuring that subsequent service access is securely authorized without requiring complex runtime verification mechanisms.
3Adaptability or versatility
If multiple authentication mechanisms are supported for different interfaces, then versatility is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal token-based authentication framework that can be applied across multiple edge computing interfaces (EEC-EES, EES-ECS, EAS-EES). The same EAT and EAToken mechanisms work for all these interfaces, providing multi-functionality without requiring separate authentication systems for each interface type.
Solution Approach 2:
The patent segments the authentication system into distinct functional components: EAT for EEC authentication with EES, EAToken for EES authorization with other services, and separate authentication flows for different interface types. This segmentation allows each component to be optimized independently while maintaining overall system versatility.
Data Source
AI summary
Embodiments include methods performed by a client in an edge data network. Such methods include obtaining an initial access token before accessing the edge data network. The initial access token is based on an identifier of the client. Such methods include establishing a first connection with a server of the edge data network based on transport layer security (TLS) and authenticating the server based on a server certificate received from the server via the first connection. Such methods include providing the initial access token to the server, via the first connection, for authentication of the client. Other embodiments include complementary methods performed by a server in an edge data network, as well as apparatus (e.g., user equipment and servers) configured to perform such methods.


