Roaming WTRU Edge Authorization Using Validated Visiting Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in authorizing roaming wireless transmit/receive units (WTRUs) for edge applications, particularly in validating authorization tokens and determining network nodes for edge computing services, which can compromise user identity and network security.
Innovation Solution
A network node receives a message from a WTRU containing temporary public land mobile network information and an authorization token, determines the home public land mobile network and a second network node, generates a second authorization token associated with a Visited Network Edge Execution Service, and sends it to the WTRU, while ensuring the identity of the WTRU is obfuscated and validated through digital signatures or decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a WTRU roams to a visited network for edge applications, then service availability and user experience are improved, but security risks and identity exposure increase
Solution Approach 1:
The patent introduces a visited network edge computing service (V-ECS) as an intermediary between the roaming WTRU and the home network edge computing service (H-ECS). The V-ECS validates authorization tokens and coordinates with the H-ECS to provide services without directly exposing the WTRU's identity to the visited network, thus maintaining security while enabling service availability.
Solution Approach 2:
The authorization system is segmented into multiple components: the first authorization token generated by H-ECS for initial access, and the second authorization token generated by V-ECS for service-specific access. This segmentation allows different levels of authorization validation, improving security while maintaining service availability across network boundaries.
2Reliability
If authorization tokens are validated through multiple network nodes, then security is improved, but processing time and system complexity increase
Solution Approach 1:
The H-ECS performs preliminary authorization validation and generates the first authorization token before the WTRU actually accesses services in the visited network. This preliminary action reduces the complexity of real-time validation by pre-establishing trust relationships and authorization credentials.
Solution Approach 2:
The V-ECS validates the first authorization token and provides feedback to the H-ECS about the WTRU's authorization status. This feedback mechanism allows the system to maintain security through multiple validation points while managing complexity through structured information exchange between network nodes.
3Loss of information
If the first EEC ID obfuscates the WTRU identity, then privacy is improved, but the ability to determine the correct network node deteriorates
Solution Approach 1:
The V-ECS acts as an intermediary that receives the obfuscated first EEC ID from the roaming WTRU, validates it against the first authorization token, and then determines the corresponding second EEC ID by coordinating with the H-ECS. This intermediary approach protects WTRU identity while enabling correct network node determination through trusted validation.
Solution Approach 2:
The H-ECS performs preliminary binding between the obfuscated first EEC ID and the actual WTRU identity when generating the first authorization token. This preliminary action allows the V-ECS to later resolve the obfuscated ID to the correct network node without exposing the WTRU's true identity during the roaming process.
Data Source
AI summary
Systems, methods, and instrumentalities may be described herein for wireless transmit/receive units (WTRUs) to authorize roaming (e.g., authorize an EEC (Edge Enabler Client) in a roaming WTRLI by a V-ECS (Visiting Edge Configuration Server) token that may be generated by the H-ECS (Home Edge Configuration Server). A first message may be sent. The first message may indicate a request for an authorization token to be used in a visiting network. A second message may be sent. The second message may indicate authentication information. A third message may be sent. The third message may indicate an authorization token. The authorization token may be associated with the authentication information. A fourth message may be received. The fourth message may indicate a validation of the authorization token and may indicate an identity of a visiting network.


