Edge Computing Authentication Method Selection for 5G Subscribers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in providing secure and efficient authentication for mobile edge computing services, particularly in differentiating edge computing services for various subscribers and ensuring authorized access in a 5G environment.

Innovation Solution

The solution involves an apparatus and method for performing authentication procedures in a wireless communication system, where user equipment (UE) transmits information to a server, which determines an appropriate authentication method based on the received message, and subsequently grants authority for edge computing services using an authentication code, enabling differentiated edge computing services without additional subscriber information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a unified authentication method is used for all subscribers, then the authentication process is simple, but differentiated edge computing services cannot be provided for various subscribers

Engineering Contradiction:
ImproveDifferentiated edge computing servicesVSAvoidAuthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication method dynamically adapts based on subscriber identity and service requirements. The system selects different authentication methods (first or second method) depending on the subscriber type and edge computing service being accessed, rather than using a static unified approach. This enables differentiated services while maintaining operational simplicity through automated method selection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (method selection, security context requirements) based on subscriber characteristics and service type. By varying authentication parameters rather than structure, the system provides differentiated services without increasing overall system complexity.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If additional subscriber information is collected for differentiated services, then service differentiation is enabled, but the authentication process becomes more complex and information requirements increase

Engineering Contradiction:
ImproveDifferentiated edge computing servicesVSAvoidSubscriber information requirements
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The authentication system uses universal subscriber information (identity, security context) that serves multiple functions. The same information base supports both unified authentication and differentiated service provision, eliminating the need for additional subscriber-specific information while enabling service differentiation through intelligent processing of existing data.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically determines the appropriate authentication method and selects necessary information requirements based on subscriber identity and service type. This self-determination eliminates manual configuration and reduces information requirements by only collecting what is necessary for the specific authentication scenario.

Inventive Principle:
Principle #25Self-service

3Productivity

If security context is shared between core network and edge computing nodes, then authentication efficiency is improved, but security risks may increase

Engineering Contradiction:
ImproveAuthentication efficiencyVSAvoidAuthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security context is segmented and selectively shared only with authenticated edge computing nodes that have established trust relationships. Rather than universal sharing, the system divides security context distribution based on node authentication status and service requirements, improving efficiency for authorized nodes while maintaining security through controlled distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The core network acts as an intermediary that controls and manages security context distribution. It mediates between security requirements and authentication efficiency by selectively providing security context to edge computing nodes based on their authentication status, thus balancing security and efficiency without direct peer-to-peer sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3967067B1Apparatus and method for providing mobile edge computing services in wireless communication system
Publication Date: 2024.08.07 SAMSUNG ELECTRONICS CO LTD
  • EP3967067B1 patent drawingFigure 1
  • EP3967067B1 patent drawingFigure 2~3
  • EP3967067B1 patent drawingFigure 4~5

AI summary

The disclosure relates to a 5th generation (5G) or pre-5G communication system for supporting a data transmission rate higher than that of a 4th generation (4G) system, such as long-term evolution (LTE). The disclosure relates to authentication and authorization for edge computing applications, and an operation method of a user equipment (UE) in a wireless communication system. The method may include transmitting, to a server, a first message including at least one of information related to the UE or a type of user agent, performing an authentication procedure for an edge computing service according to an authentication method determined based on the first message, receiving a second message indicating authority granted to the edge computing service, based on an authentication code generated by the server according to the performed authentication procedure, and using the edge computing service in a range corresponding to the granted authority.