ENABLING COORDINATED IDENTITY MANAGEMENT BETWEEN AN OPERATOR-MANAGED MOBILE-EDGE PLATFORM AND AN EXTERNAL NETWORK
Approaches may be used for enabling coordinated identity management between an operator-managed mobile edge platform (MEP) and an external network. A token may be generated in the MEP that may associate a mobile network identity and an external network identity. The token may be negotiated on a per-session basis or on a per-wireless transmit/receive unit (WTRU) identity (WTRU-ID) basis. In an example method performed by a WTRU camped on a small cell network covered by the MEP, an enterprise bring your own device (BYOD) client (EBC) application may establish a secure link with an enterprise BYOD agent (EBA) application running on the MEP using an initial connection procedure. The EBC application may initiate an application-level authentication procedure with an enhanced evolved packet core (EPC) network. The EBC application may generate and provide a token to the EBA application via the established secure link.
1 - 22 . (canceled)
23 . An edge processing platform in a communications network, the edge processing platform comprising:
at least one application programming interface (API) configured to communicate with at least one edge application;
the at least one API configured to receive, from the at least one edge application, a token, wherein the token is used to associate Internet protocol (IP) traffic flows in the communications network to a wireless transmit/receive unit (WTRU) in a local network; and
a processor configured to set at least one packet filter based on the token for routing traffic for the WTRU between the communications network and the local network.
24 . The edge processing platform of claim 23 , wherein the token associates an identifier of the WTRU used in the communications network with a different identifier of the WTRU used in the local network.
25 . The edge processing platform of claim 24 , wherein the identifier of the WTRU used in the communications network is one of an International Mobile Subscriber Identity (IMSI) or a Temporary Mobile Subscriber Identity (TMSI).
26 . The edge processing platform of claim 24 , wherein the identifier of the WTRU used in the local network is a Mobile Station International Subscriber Directory Number (MSISDN).
27 . The edge processing platform of claim 24 , wherein the local network is an enterprise network and the identifier of the WTRU used in the local network is an enterprise identity.
28 . The edge processing platform of claim 23 , wherein the processor is further configured to perform authentication of the at least one edge processing application.
29 . The edge processing platform of claim 23 configured as a European Telecommunications Standards Institute (ETSI) Mobile Edge Computing (MEC) platform.
30 . A method performed by an edge processing platform in a communications network, the method comprising:
communicating with at least one edge application;
receiving, from the at least one edge application, a token, wherein the token is used to associate Internet protocol (IP) traffic flows in the communications network to a wireless transmit/receive unit (WTRU) in a local network; and
setting at least one packet filter based on the token for routing traffic for the WTRU between the communications network and the local network.
31 . The method of claim 30 , wherein the token associates an identifier of the WTRU used in the communications network with a different identifier of the WTRU used in the local network.
32 . The method of claim 31 , wherein the identifier of the WTRU used in the communications network is one of an International Mobile Subscriber Identity (IMSI) or a Temporary Mobile Subscriber Identity (TMSI).
33 . The method of claim 31 , wherein the identifier of the WTRU used in the local network is a Mobile Station International Subscriber Directory Number (MSISDN).
34 . The method of claim 31 , wherein the local network is an enterprise network and the identifier of the WTRU used in the local network is an enterprise identity.
35 . The method of claim 30 , further comprising:
performing authentication of the at least one edge processing application.
36 . The method of claim 30 configured as a European Telecommunications Standards Institute (ETSI) Mobile Edge Computing (MEC) platform.
37 . An edge application comprising:
at least one application programming interface (API) configured to communicate with an edge processing platform;
at least one interface configured to establish communications with a wireless transmit/receive unit (WTRU);
the at least one interface configured to receive a token, wherein the token is used to associate Internet protocol (IP) traffic flows in a communications network to the WTRU; and
the at least one API configured to provide the token to the edge processing platform.
38 . The edge application of claim 37 , wherein the token associates an identifier of the WTRU used in the communications network with a different identifier of the WTRU used in a local network.
39 . The edge application of claim 38 , wherein the identifier of the WTRU used in the communications network is one of an International Mobile Subscriber Identity (IMSI) or a Temporary Mobile Subscriber Identity (TMSI).
40 . The edge application of claim 38 , wherein the identifier of the WTRU used in the local network is a Mobile Station International Subscriber Directory Number (MSISDN).
41 . The edge application of claim 38 , wherein the local network is an enterprise network and the identifier of the WTRU used in the local network is an enterprise identity.
42 . The edge application of claim 37 , wherein the at least one API is further configured to perform authentication with the edge processing platform.