Edge Computing Authentication via UDM Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing edge computing systems are vulnerable to denial of service attacks due to inadequate authentication and authorization processes, particularly when any client can request edge computing service authorization, leading to potential service disruptions.

Innovation Solution

An information processing method that involves obtaining and verifying authentication information for terminals through a unified data management entity (UDM) and edge computing authorization, ensuring that only authenticated terminals receive edge computing services, thereby reducing the risk of denial of service attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If any client can request edge computing service authorization from the edge enabler server, then service accessibility is improved, but the system becomes vulnerable to denial of service attacks

Engineering Contradiction:
Improveservice accessibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary authentication of the terminal before allowing it to access the edge enabler server. The authentication server authenticates the terminal in advance, and only authenticated terminals are allowed to request edge computing services. This preliminary action prevents unauthorized clients from launching denial of service attacks while maintaining service accessibility for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the terminal and the edge enabler server. This intermediary component verifies the terminal's identity and authentication status before allowing access to edge computing services. The authentication server acts as a mediator that protects the edge enabler server from direct exposure to unauthenticated clients, thereby preventing denial of service attacks while maintaining service accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and authorization processes are implemented, then system security is improved, but the complexity of the authentication architecture increases

Engineering Contradiction:
Improvesystem securityVSAvoidauthentication architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism that serves multiple functions: it authenticates terminals, verifies authentication status, and controls access to edge computing services. By designing the authentication server to handle these multiple functions, the patent reduces the need for separate dedicated components for each function, thereby improving security without proportionally increasing architectural complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a self-service authentication mechanism where terminals present their authentication status to the edge enabler server, and the server automatically verifies it against the authentication server. This self-service approach eliminates the need for complex manual authentication flows and reduces architectural complexity by allowing the system to automatically manage authentication states.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If authentication information is obtained from UDM, then authorization accuracy is improved, but the data management complexity increases

Engineering Contradiction:
Improveauthorization accuracyVSAvoiddata management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces the UDM (Unified Data Management) entity as an intermediary that centrally manages authentication information. Instead of each network element maintaining its own authentication data, the UDM serves as a centralized mediator that provides authentication information to authorized network elements. This approach improves authorization accuracy by having a single source of truth while managing data complexity through centralized organization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal data management approach where the UDM handles multiple data management functions including authentication information storage, retrieval, and updates. By consolidating these functions into a single multi-functional entity, the patent improves authorization accuracy across all scenarios while managing data complexity through unified management rather than distributed management of multiple data sources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12262448B2Information processing method, information processing device and computer readable storage medium
Publication Date: 2025.03.25 DATANG MOBILE COMM EQUIP CO LTD
  • US12262448B2 patent drawing
  • US12262448B2 patent drawing
  • US12262448B2 patent drawing

AI summary

The present disclosure provides an information processing method, an information processing device and a computer-readable storage medium, which relate to the field of communication technology to improve the security of edge computing services. The method includes: obtaining first authentication information for a terminal; and in the case of determining that authentication of the terminal is successful according to the first authentication information, sending information of a second network element to the terminal, so that the terminal obtains information of a target network element from the second network element, the information of the target network element is sent by the second network element to the terminal when edge computing authorization information of the terminal is verified, and the target network element is used to provide an edge computing service for the terminal.