Type-Based Authentication for Edge Enabler Client
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for Edge Enabler Client (EEC) authentication in 5G networks face difficulties due to reliance on identifier-based authentication, which adds complexity and is not suitable for interfaces between EEC and various servers in the Edge network.
Innovation Solution
The proposed solution involves obtaining initial and subsequent access credentials based on indications of legitimacy and client type, rather than solely on the EEC identifier. These credentials are validated using Transport Layer Security (TLS) connections and server certificates, simplifying the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identifier-based authentication is used for EEC authentication, then authentication can be performed, but the authentication process becomes complex and is not suitable for interfaces between EEC and various servers
Solution Approach 1:
The patent extracts the EEC identifier from the authentication process and replaces it with a simplified credential-based mechanism. The EEC obtains credentials from an edge computing service provider and presents these credentials to servers for authentication, removing the need for servers to directly verify EEC identifiers and reducing authentication complexity.
Solution Approach 2:
The patent introduces an edge computing service provider as an intermediary that issues credentials to the EEC. This intermediary acts as a trusted third party that simplifies the authentication process by providing pre-validated credentials, eliminating the need for complex identifier verification between the EEC and multiple servers.
2Loss of information
If EEC identifier is used for authentication, then the server can identify the client, but the authentication process requires additional complexity in validating the identifier
Solution Approach 1:
The patent uses credentials that contain or represent the EEC identifier information in a simplified form. Instead of directly validating complex EEC identifiers, the server validates the credential presented by the EEC, which has already been verified by the edge computing service provider, thus preserving identification capability while reducing validation complexity.
3Reliability
If TLS connection with certificate validation is implemented, then secure communication is established, but the initial setup becomes more complex
Solution Approach 1:
The patent implements TLS certificate validation during the initial connection establishment between the EEC and the server. By performing security setup at the beginning, the system ensures secure communication for all subsequent interactions without requiring repeated security negotiations, thus balancing security requirements with operational simplicity.
Data Source
AI summary
Embodiments of the present disclosure include methods for a client in an edge data network. Such methods include obtaining an initial access credential before accessing the edge data network. The initial access credential includes or is based on one or more of the following: an indication that the client is a legitimate client, and a client type associated with the client. Such methods include establishing a first connection with a server of the edge data network based on transport layer security (TLS); authenticating the server via the first connection based on a server certificate; and providing the initial access credential to the server, via the first connection, for authentication of the client. Other embodiments include complementary methods for a server and for a credential provider, as well as UEs, network nodes, and/or computing systems configured to perform such methods.


