Edge Enabler Client Identification Authentication Key Collision
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Authentication and Key Management for Applications (AKMA) procedure in edge computing networks faces a key collision issue due to multiple edge enabler clients (EECs) instantiated by a user equipment (UE) sharing the same key (KAKMA).
Innovation Solution
The proposed solution involves using a unique edge enabler client identification (EEC ID) as part of the AKMA procedure for authenticating EECs. This EEC ID is used to generate a unique key (KEDGE) for each EEC, preventing key collisions and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AKMA procedure is used for EEC authentication, then authentication can be performed, but key collision occurs because multiple EECs share the same KAKMA
Solution Approach 1:
The patent segments the authentication process by introducing a unique EEC ID for each edge enabler client. Instead of using a single shared KAKMA for all EECs, each EEC is assigned a distinct identifier (EEC ID) that is used to generate individual authentication credentials. This segmentation resolves the key collision problem by ensuring that each EEC has its own unique authentication key derived from its specific EEC ID, while still utilizing the AKMA framework.
2Adaptability or versatility
If multiple EECs are instantiated by a UE, then edge computing services can be accessed, but security is compromised due to shared authentication keys
Solution Approach 1:
The patent applies local quality by making each EEC's authentication credentials unique to that specific client instance. The EEC ID serves as a local identifier that is specific to each EEC, and authentication keys are derived locally based on this unique identifier. This ensures that while multiple EECs can coexist (adaptability), each maintains its own security context (local quality), preventing cross-EEC authentication attacks and ensuring that compromise of one EEC does not affect others.
Data Source
AI summary
An edge enabler server of an edge data network is configured to receive a verification request comprising an edge enabler client identification (EEC ID), wherein the EEC ID uniquely identifies an edge enabler client (EEC), determine whether the EEC ID is an authorized EEC ID and provide a verification response based on whether the EEC ID is authorized.


