Inter-Operator Edge Access via Network-Assisted Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless networks face challenges in securely and efficiently enabling User Equipment (UE) to access edge computing devices from different network operators, lacking a seamless and authorized access mechanism.
Innovation Solution
A network-assisted authentication and authorization mechanism is implemented, allowing UEs to request and establish communication sessions with edge computing devices of other networks through core network elements, using protocols like PDU sessions and GTP tunnels, with authorization and usage tracking by the home network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If UEs are allowed to access edge computing devices from different network operators, then service availability and adaptability are improved, but network security and access control become more complex
Solution Approach 1:
The patent introduces a network-assisted authentication mechanism where the serving network acts as an intermediary between the UE and the home network. The serving network forwards authentication requests and receives authorization responses, enabling secure cross-network access without direct UE-home network communication. This intermediary approach maintains security while enabling service availability across different operators.
2Reliability
If a network-assisted authentication mechanism is implemented, then access security is improved, but signaling overhead and system complexity increase
Solution Approach 1:
The patent leverages existing multi-functional network elements (AMF, SMF, UPF) to perform authentication and authorization functions. These elements already handle session management and mobility, so adding authentication capabilities reuses existing infrastructure rather than introducing new dedicated components. This universal approach improves security while minimizing additional system complexity.
3Adaptability or versatility
If UEs can establish sessions with edge computing devices on other networks, then service access capability is improved, but resource management and tracking become more difficult
Solution Approach 1:
The patent implements a feedback mechanism where the serving network continuously monitors and tracks UE sessions with edge computing devices. The network receives authorization responses from the home network and maintains session state information, enabling real-time resource management and tracking. This feedback loop allows complex cross-network resource management while enabling service access capability.
Data Source
AI summary
A device of a first network, to which a User Equipment (“UE”) is wirelessly connected, may receive, a request to access a service provided by a second network. The device may establish, based on the request, a user plane connection between the first network and the second network while the UE remains wirelessly connected to the first network. The first network may receive, from the UE, traffic that is associated with the service, and may output the received traffic to the second network via the user plane connection. The first and second networks may communicate via a connection, such as a tunnel, via respective User Plane Functions (“UPFs”) of the first and second networks. The UPFs may communicate via an N9 interface. The service may be provided by an edge computing device of the second network.


