Zero-Knowledge Proof Authentication for 5G Edge Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G authentication methods are vulnerable to distributed denial-of-service (DDoS) attacks during primary and secondary authentication processes, which can compromise network security and integrity, especially in edge computing environments where IoT devices are involved.
Innovation Solution
Implementing a zero-knowledge proof (ZKP) authentication protocol, specifically the Partial-ID ZKP, that authenticates user equipment (UE) at the edge of the 5G network without revealing credentials, thereby preventing illegitimate devices from performing DDoS attacks by using a setup phase to generate and share partial credential keys between entities, ensuring secure access to service providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication protocols (5G AKA, EAP-AKA') are used for primary authentication, then mutual authentication between UE and MNO core network is achieved, but the system becomes vulnerable to DDoS attacks during authentication processes
Solution Approach 1:
The patent applies preliminary action by performing authentication at the network edge before traffic is forwarded to the core network. The edge authentication entity verifies UE credentials in advance, so that by the time authentication requests reach the core network, legitimate users are already verified and can be differentiated from attackers. This prevents DDoS attacks from overwhelming core network resources.
Solution Approach 2:
The patent segments the authentication process into two independent stages: edge authentication (performed by access network entities) and core network authentication (performed by MNO core network entities). This segmentation allows the edge to handle initial verification, filtering out malicious traffic before it reaches the core network, thereby protecting against DDoS attacks while maintaining the integrity of the original authentication protocols.
2Adaptability or versatility
If secondary authentication is performed for each service provider access, then service-specific authentication is achieved, but the frequency of authentication traffic increases DDoS attack risks on the core network
Solution Approach 1:
The patent performs secondary authentication preliminarily at the edge network before traffic is forwarded to external DN-AAA servers. The edge authentication entity validates service-specific credentials in advance, filtering out malicious authentication requests. This reduces the volume of authentication traffic reaching the core network and external servers, mitigating DDoS risks while maintaining service-specific authentication capabilities.
3Ease of operation
If authentication data is distributed among decentralized nodes at the network edge, then authentication can occur at the edge, but storing and distributing credentials becomes impractical and creates security breaches
Solution Approach 1:
The patent extracts only the necessary authentication information (identifiers and public keys) to the edge network entities, while keeping the complete credential secrets securely stored at the MNO core network. The edge authentication entities receive and verify authentication data without storing the actual credentials. This allows edge authentication to function while maintaining credential secrecy at the core network, avoiding security breaches.
4Reliability
If new network functions are introduced to relay secondary authentication, then DDoS protection is improved, but the device complexity and implementation difficulty increase
Solution Approach 1:
The patent makes existing edge network entities (access and mobility management functions, session management functions) perform authentication functions in addition to their existing roles. Rather than introducing dedicated new authentication relay nodes, these multi-functional entities handle both traffic management and authentication verification. This reduces device complexity and implementation difficulty while maintaining DDoS mitigation capabilities.
Data Source
AI summary
An authentication method for a target device, the method comprising authenticating, at an access network, a first identity of the target device for registering on the access network. In response to a successful authentication of the first identity by the access network, the method comprises executing, at the access network, a zero-knowledge proof (ZKP) protocol to authenticate a second identity of the target device for accessing a service provider; and, in response to a successful authentication of the second identity, granting, by the access network, access of the target device to the service provider.


