Edge Client-Server Authentication Using Token-Bound TLS in 5G
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for Edge Enabler Clients (EECs) in 5G networks, such as AKMA and transport layer security (TLS), are unsuitable for interfaces between EECs and various servers, leading to deployment challenges for edge computing solutions.
Innovation Solution
Implement methods for clients and servers in edge data networks that involve obtaining initial access tokens based on client identifiers, establishing TLS connections, and authenticating servers with certificates, while also using ECSP-provided tokens for mutual authentication, and binding EEC and UE identities through IP address matching.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If AKMA and TLS authentication methods are used for EECs in 5G networks, then existing authentication protocols are maintained, but they are unsuitable for interfaces between EECs and servers, causing deployment challenges
Solution Approach 1:
The patent changes the authentication parameters by introducing a new token-based mechanism where the EEC receives a token from the ECS, uses it to obtain a certificate from the CA, and presents both to the EES for mutual authentication. This parameter change enables authentication to work across EEC-server interfaces while maintaining security.
Solution Approach 2:
The patent introduces an intermediary authentication flow involving the ECS and CA as mediators between the EEC and EES. The ECS issues tokens and the CA issues certificates, creating a mediated authentication chain that enables EECs to authenticate to various servers without direct peer-to-peer authentication.
2Reliability
If mutual authentication with tokens and certificates is implemented, then security is improved, but authentication complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct phases: initial authentication with the ECS to obtain a token, certificate acquisition from the CA, and final mutual authentication with the EES. This segmentation allows each component to handle a specific part of authentication, reducing overall complexity while maintaining security.
Solution Approach 2:
The patent performs preliminary actions by having the EEC first authenticate with the ECS and obtain a token before attempting to connect to the EES. The certificate is also obtained in advance from the CA. These preliminary actions prepare the EEC with the necessary credentials for subsequent authentication, streamlining the overall process.
3Measurement precision
If EEC and UE identities are bound through IP address matching, then identity verification is improved, but network configuration complexity increases
Solution Approach 1:
The patent implements self-service identity binding where the network automatically matches the EEC's IP address with the UE's identifier without requiring manual configuration. The ECS and EES automatically perform this matching using the token and certificate information, eliminating the need for complex network-side configuration while ensuring accurate identity verification.
Data Source
AI summary
Embodiments include methods performed by a client in an edge data network. Such methods include obtaining an initial access token before accessing the edge data network. The initial access token is based on an identifier of the client. Such methods include establishing a first connection with a server of the edge data network based on transport layer security (TLS) and authenticating the server based on a server certificate received from the server via the first connection. Such methods include providing the initial access token to the server, via the first connection, for authentication of the client and subsequently receiving a second access token from the server via the first connection. The second access token is based on the identifier of the client. Other embodiments include complementary methods performed by a server in an edge data network, as well as apparatus (e.g., user equipment and servers) configured to perform such methods.


