Zero-Knowledge Proof Authentication for 5G Edge Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G authentication methods are vulnerable to distributed denial-of-service (DDoS) attacks during primary and secondary authentication processes, which can compromise network security and integrity, especially in edge computing environments where IoT devices are involved.

Innovation Solution

Implementing a zero-knowledge proof (ZKP) authentication protocol, specifically the Partial-ID ZKP, that authenticates user equipment (UE) at the edge of the 5G network without revealing credentials, thereby preventing illegitimate devices from performing DDoS attacks by using a setup phase to generate and share partial credential keys between entities, ensuring secure access to service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication protocols (5G AKA, EAP-AKA') are used for primary authentication, then mutual authentication between UE and MNO core network is achieved, but the system becomes vulnerable to DDoS attacks during authentication processes

Engineering Contradiction:
Improveauthentication securityVSAvoidDDoS attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authentication at the network edge before traffic is forwarded to the core network. The edge authentication entity verifies UE credentials in advance, so that by the time authentication requests reach the core network, legitimate users are already verified and can be differentiated from attackers. This prevents DDoS attacks from overwhelming core network resources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication process into two independent stages: edge authentication (performed by access network entities) and core network authentication (performed by MNO core network entities). This segmentation allows the edge to handle initial verification, filtering out malicious traffic before it reaches the core network, thereby protecting against DDoS attacks while maintaining the integrity of the original authentication protocols.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If secondary authentication is performed for each service provider access, then service-specific authentication is achieved, but the frequency of authentication traffic increases DDoS attack risks on the core network

Engineering Contradiction:
Improveservice provider authenticationVSAvoidauthentication traffic volume
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs secondary authentication preliminarily at the edge network before traffic is forwarded to external DN-AAA servers. The edge authentication entity validates service-specific credentials in advance, filtering out malicious authentication requests. This reduces the volume of authentication traffic reaching the core network and external servers, mitigating DDoS risks while maintaining service-specific authentication capabilities.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication data is distributed among decentralized nodes at the network edge, then authentication can occur at the edge, but storing and distributing credentials becomes impractical and creates security breaches

Engineering Contradiction:
Improveedge authentication capabilityVSAvoidcredential secrecy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts only the necessary authentication information (identifiers and public keys) to the edge network entities, while keeping the complete credential secrets securely stored at the MNO core network. The edge authentication entities receive and verify authentication data without storing the actual credentials. This allows edge authentication to function while maintaining credential secrecy at the core network, avoiding security breaches.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If new network functions are introduced to relay secondary authentication, then DDoS protection is improved, but the device complexity and implementation difficulty increase

Engineering Contradiction:
ImproveDDoS mitigationVSAvoidnetwork function architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes existing edge network entities (access and mobility management functions, session management functions) perform authentication functions in addition to their existing roles. Rather than introducing dedicated new authentication relay nodes, these multi-functional entities handle both traffic management and authentication verification. This reduces device complexity and implementation difficulty while maintaining DDoS mitigation capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240171402A1Authentication methods using zero-knowledge proof algorithms for user equipment and nodes implementing the authentication methods
Publication Date: 2024.05.23 HUAWEI TECH CO LTD
  • US20240171402A1 patent drawing
  • US20240171402A1 patent drawing
  • US20240171402A1 patent drawing

AI summary

An authentication method for a target device, the method comprising authenticating, at an access network, a first identity of the target device for registering on the access network. In response to a successful authentication of the first identity by the access network, the method comprises executing, at the access network, a zero-knowledge proof (ZKP) protocol to authenticate a second identity of the target device for accessing a service provider; and, in response to a successful authentication of the second identity, granting, by the access network, access of the target device to the service provider.