Edge Client-Server Authentication Using Token-Bound TLS in 5G

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for Edge Enabler Clients (EECs) in 5G networks, such as AKMA and transport layer security (TLS), are unsuitable for interfaces between EECs and various servers, leading to deployment challenges for edge computing solutions.

Innovation Solution

Implement methods for clients and servers in edge data networks that involve obtaining initial access tokens based on client identifiers, establishing TLS connections, and authenticating servers with certificates, while also using ECSP-provided tokens for mutual authentication, and binding EEC and UE identities through IP address matching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If AKMA and TLS authentication methods are used for EECs in 5G networks, then existing authentication protocols are maintained, but they are unsuitable for interfaces between EECs and servers, causing deployment challenges

Engineering Contradiction:
Improveauthentication method suitabilityVSAvoiddeployment success
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the authentication parameters by introducing a new token-based mechanism where the EEC receives a token from the ECS, uses it to obtain a certificate from the CA, and presents both to the EES for mutual authentication. This parameter change enables authentication to work across EEC-server interfaces while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary authentication flow involving the ECS and CA as mediators between the EEC and EES. The ECS issues tokens and the CA issues certificates, creating a mediated authentication chain that enables EECs to authenticate to various servers without direct peer-to-peer authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mutual authentication with tokens and certificates is implemented, then security is improved, but authentication complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct phases: initial authentication with the ECS to obtain a token, certificate acquisition from the CA, and final mutual authentication with the EES. This segmentation allows each component to handle a specific part of authentication, reducing overall complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by having the EEC first authenticate with the ECS and obtain a token before attempting to connect to the EES. The certificate is also obtained in advance from the CA. These preliminary actions prepare the EEC with the necessary credentials for subsequent authentication, streamlining the overall process.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If EEC and UE identities are bound through IP address matching, then identity verification is improved, but network configuration complexity increases

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidnetwork configuration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service identity binding where the network automatically matches the EEC's IP address with the UE's identifier without requiring manual configuration. The ECS and EES automatically perform this matching using the token and certificate information, eliminating the need for complex network-side configuration while ensuring accurate identity verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260095764A1Authentication and Authorization of Servers and Clients in Edge Computing
Publication Date: 2026.04.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20260095764A1 patent drawing
  • US20260095764A1 patent drawing
  • US20260095764A1 patent drawing

AI summary

Embodiments include methods performed by a client in an edge data network. Such methods include obtaining an initial access token before accessing the edge data network. The initial access token is based on an identifier of the client. Such methods include establishing a first connection with a server of the edge data network based on transport layer security (TLS) and authenticating the server based on a server certificate received from the server via the first connection. Such methods include providing the initial access token to the server, via the first connection, for authentication of the client and subsequently receiving a second access token from the server via the first connection. The second access token is based on the identifier of the client. Other embodiments include complementary methods performed by a server in an edge data network, as well as apparatus (e.g., user equipment and servers) configured to perform such methods.