Edge Network Authentication Credential Pre-generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication procedures for user equipment (UE) accessing edge data networks are inefficient, lacking a streamlined method for verifying credentials and authorization parameters in multi-access edge computing (MEC) environments, which hinders seamless connectivity and data processing.

Innovation Solution

A method involving the generation of a first credential based on a second credential, with an identifier received from a server, followed by retrieval and verification of a multi-access edge computing (MEC) authorization parameter, and transmission of an authentication verification response to ensure secure access to edge data networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication procedures are used for UE accessing edge data networks, then security is maintained through multiple verification steps, but authentication time and processing latency increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network component pre-generates credentials and authorization parameters during the initial authentication phase between UE and cellular network. These credentials are then reused in subsequent edge data network access requests, eliminating the need for repeated full authentication cycles and reducing authentication time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A network component acts as an intermediary that generates and manages credentials, serving as a trusted mediator between the UE and edge data network. This intermediary verifies authorization parameters and transmits authentication responses, streamlining the authentication process while maintaining security through centralized credential management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple credentials and authorization parameters are verified for secure edge network access, then authentication reliability is improved, but the complexity of the authentication procedure increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication and authorization verification steps into a single streamlined process. The network component integrates credential verification, authorization parameter validation, and authentication response transmission into one unified operation, reducing procedural complexity while maintaining comprehensive security checks

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network component performs multiple functions within a single authentication mechanism: it generates credentials, verifies authorization parameters, and transmits authentication responses. This multi-functional approach consolidates complex authentication procedures into a universal process that maintains reliability without increasing operational complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If credential generation and verification processes are streamlined for faster edge network access, then authentication speed is improved, but security verification thoroughness may be compromised

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity verification thoroughness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

Comprehensive security verification is performed in advance during the initial credential generation phase between UE and cellular network. The network component pre-validates authorization parameters and generates secure credentials beforehand, enabling fast authentication subsequent access without compromising verification thoroughness

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network component serves as a security intermediary that performs thorough verification of authorization parameters while maintaining fast authentication. It validates credentials against stored information and ensures security requirements are met before transmitting authentication responses, balancing speed with comprehensive security checks

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11968530B2Network authentication for user equipment access to an edge data network
Publication Date: 2024.04.23 APPLE INC
  • US11968530B2 patent drawing
  • US11968530B2 patent drawing
  • US11968530B2 patent drawing

AI summary

A network may authenticate a user equipment (UE) to access an edge data network. The network generates a first credential based on a second credential, the second credential generated for a procedure between the UE and a cellular network corresponding to the network component, receives an identifier associated with the first credential from a further network component in response to the UE transmitting an application registration request to a server associated with an edge data network and retrieves the first credential based on the identifier. The network also receives a multi-access edge computing (MEC) authorization parameter, verifies the MEC authorization parameter and transmits an authentication verification response to a second network component.