Mobile Edge Identity Tokens for Secure Enterprise Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in coordinating identity management between operator-managed mobile edge platforms and external networks, particularly in enterprise settings, leading to inefficiencies in traffic routing and security risks due to indirect communication paths and potential exposure to security threats.

Innovation Solution

A token-based system is implemented to facilitate secure communication between a wireless transmit/receive unit (WTRU) and an enterprise network, enabling the mobile edge platform to set packet filters and route traffic based on per-session or per-WTRU identity, using a token generated by the operator-managed mobile edge platform to associate mobile and external network identities, thereby enhancing security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If indirect communication paths are used between WTRU and external network, then routing flexibility is improved, but security risks increase due to potential exposure to security threats

Engineering Contradiction:
Improverouting flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mobile edge platform as an intermediary component between the WTRU and external networks. This platform generates and manages tokens that enable secure indirect communication paths while maintaining security through controlled identity association. The intermediary structure allows routing flexibility through multiple network paths while the token-based security mechanism mitigates security risks by preventing direct exposure of sensitive identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If token-based identity association is implemented, then security is improved, but system complexity increases due to token generation and management mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile edge platform serves as a centralized intermediary that handles the complex token generation and management operations, rather than distributing this complexity across multiple devices. The platform generates tokens that associate mobile network identities with external network identities, providing security through a managed approach that centralizes the complexity in a dedicated security function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms security management from a static configuration approach to a dynamic parameter-based approach using tokens. The token contains encoded identity association parameters that can be generated, validated, and managed through standardized procedures, making the security mechanism more systematic and manageable despite the increased complexity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If per-session token negotiation is used, then security precision is improved, but processing time increases due to authentication overhead

Engineering Contradiction:
Improvesecurity precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements dynamic token negotiation that adapts to different session requirements. Tokens can be negotiated on a per-session basis when high security precision is needed, or reused across multiple sessions when appropriate, providing flexibility in balancing security precision against processing time based on the specific operational context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent allows for partial token negotiation where full per-session authentication is performed only when necessary for security precision, while accepting pre-negotiated or cached tokens for routine operations. This partial application of the authentication mechanism reduces processing time overhead while maintaining security precision where required.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12587847B2Enabling coordinated identity management between an operator-managed mobile-edge platform and an external network
Publication Date: 2026.03.24 INTERDIGITAL PATENT HOLDINGS INC
  • US12587847B2 patent drawing
  • US12587847B2 patent drawing
  • US12587847B2 patent drawing

AI summary

An edge processing platform in a communications network is configured to communicate with at least one edge application. The edge processing platform comprises at least one processor configured to receive a registration request, from the at least one edge application. The registration request is a request to register a token. The token represents a wireless transmit/receive unit (WTRU) and the token is used to associate at least one traffic filter to the token. The at least one processor is configured to register the token in response to the received registration request. The at least one processor is configured to activate, in response to registering the token, the at least one traffic filter based on the token for routing traffic for the WTRU between the communications network and a local network.