Edge Computing Authentication via UDM Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing edge computing systems are vulnerable to denial of service attacks due to inadequate authentication and authorization processes, particularly when any client can request edge computing service authorization, leading to potential service disruptions.
Innovation Solution
An information processing method that involves obtaining and verifying authentication information for terminals through a unified data management entity (UDM) and edge computing authorization, ensuring that only authenticated terminals receive edge computing services, thereby reducing the risk of denial of service attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If any client can request edge computing service authorization from the edge enabler server, then service accessibility is improved, but the system becomes vulnerable to denial of service attacks
Solution Approach 1:
The patent implements preliminary authentication of the terminal before allowing it to access the edge enabler server. The authentication server authenticates the terminal in advance, and only authenticated terminals are allowed to request edge computing services. This preliminary action prevents unauthorized clients from launching denial of service attacks while maintaining service accessibility for legitimate users.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the terminal and the edge enabler server. This intermediary component verifies the terminal's identity and authentication status before allowing access to edge computing services. The authentication server acts as a mediator that protects the edge enabler server from direct exposure to unauthenticated clients, thereby preventing denial of service attacks while maintaining service accessibility.
2Reliability
If authentication and authorization processes are implemented, then system security is improved, but the complexity of the authentication architecture increases
Solution Approach 1:
The patent implements a universal authentication mechanism that serves multiple functions: it authenticates terminals, verifies authentication status, and controls access to edge computing services. By designing the authentication server to handle these multiple functions, the patent reduces the need for separate dedicated components for each function, thereby improving security without proportionally increasing architectural complexity.
Solution Approach 2:
The patent implements a self-service authentication mechanism where terminals present their authentication status to the edge enabler server, and the server automatically verifies it against the authentication server. This self-service approach eliminates the need for complex manual authentication flows and reduces architectural complexity by allowing the system to automatically manage authentication states.
3Measurement precision
If authentication information is obtained from UDM, then authorization accuracy is improved, but the data management complexity increases
Solution Approach 1:
The patent introduces the UDM (Unified Data Management) entity as an intermediary that centrally manages authentication information. Instead of each network element maintaining its own authentication data, the UDM serves as a centralized mediator that provides authentication information to authorized network elements. This approach improves authorization accuracy by having a single source of truth while managing data complexity through centralized organization.
Solution Approach 2:
The patent implements a universal data management approach where the UDM handles multiple data management functions including authentication information storage, retrieval, and updates. By consolidating these functions into a single multi-functional entity, the patent improves authorization accuracy across all scenarios while managing data complexity through unified management rather than distributed management of multiple data sources.
Data Source
AI summary
The present disclosure provides an information processing method, an information processing device and a computer-readable storage medium, which relate to the field of communication technology to improve the security of edge computing services. The method includes: obtaining first authentication information for a terminal; and in the case of determining that authentication of the terminal is successful according to the first authentication information, sending information of a second network element to the terminal, so that the terminal obtains information of a target network element from the second network element, the information of the target network element is sent by the second network element to the terminal when edge computing authorization information of the terminal is verified, and the target network element is used to provide an edge computing service for the terminal.


