Type-Based Authentication for Edge Enabler Client

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for Edge Enabler Client (EEC) authentication in 5G networks face difficulties due to reliance on identifier-based authentication, which adds complexity and is not suitable for interfaces between EEC and various servers in the Edge network.

Innovation Solution

The proposed solution involves obtaining initial and subsequent access credentials based on indications of legitimacy and client type, rather than solely on the EEC identifier. These credentials are validated using Transport Layer Security (TLS) connections and server certificates, simplifying the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identifier-based authentication is used for EEC authentication, then authentication can be performed, but the authentication process becomes complex and is not suitable for interfaces between EEC and various servers

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the EEC identifier from the authentication process and replaces it with a simplified credential-based mechanism. The EEC obtains credentials from an edge computing service provider and presents these credentials to servers for authentication, removing the need for servers to directly verify EEC identifiers and reducing authentication complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an edge computing service provider as an intermediary that issues credentials to the EEC. This intermediary acts as a trusted third party that simplifies the authentication process by providing pre-validated credentials, eliminating the need for complex identifier verification between the EEC and multiple servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If EEC identifier is used for authentication, then the server can identify the client, but the authentication process requires additional complexity in validating the identifier

Engineering Contradiction:
Improveclient identification capabilityVSAvoidvalidation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent uses credentials that contain or represent the EEC identifier information in a simplified form. Instead of directly validating complex EEC identifiers, the server validates the credential presented by the EEC, which has already been verified by the edge computing service provider, thus preserving identification capability while reducing validation complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If TLS connection with certificate validation is implemented, then secure communication is established, but the initial setup becomes more complex

Engineering Contradiction:
Improvecommunication securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements TLS certificate validation during the initial connection establishment between the EEC and the server. By performing security setup at the beginning, the system ensures secure communication for all subsequent interactions without requiring repeated security negotiations, thus balancing security requirements with operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250047659A1Type-Based Authentication of Edge Enabler Client (EEC)
Publication Date: 2025.02.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250047659A1 patent drawing
  • US20250047659A1 patent drawing
  • US20250047659A1 patent drawing

AI summary

Embodiments of the present disclosure include methods for a client in an edge data network. Such methods include obtaining an initial access credential before accessing the edge data network. The initial access credential includes or is based on one or more of the following: an indication that the client is a legitimate client, and a client type associated with the client. Such methods include establishing a first connection with a server of the edge data network based on transport layer security (TLS); authenticating the server via the first connection based on a server certificate; and providing the initial access credential to the server, via the first connection, for authentication of the client. Other embodiments include complementary methods for a server and for a credential provider, as well as UEs, network nodes, and/or computing systems configured to perform such methods.