IP Library › Granted Patent US 12,267,676
Granted Patent B2
US 12,267,676 · App. 17/497,350 · Granted Apr 1, 2025

Methods and systems for authentication and establishment of secure connection for edge computing services

Inventors: Rajavelsamy Rajadurai (Karnataka, IN); Nishant Gupta (Karnataka, IN); Rohini Rajendran (Karnataka, IN); Nivedya Parambath Sasi (Karnataka, IN)
Assignee: Samsung Electronics Co., Ltd.
H04W12/068H04W12/041H04W12/0431H04W12/0433H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,676
App. No.
17/497,350
Granted
Apr 1, 2025
Kind
B2
Abstract

Methods and systems for authentication and establishment of secure connection for accessing edge computing services are provided. The method includes dynamically deriving a pre-shared key (PSK) and use the dynamically derived PSK for the authentication, while performing or before performing a secure connection establishment or while or before establishing a secure interface between a user equipment (UE), and a server, wherein the UE includes an Edge Enabler Client (EEC), and the server is an Edge Configuration Server (ECS). The method further includes deriving the PSK based on an Authentication and Key Management for Applications (AKMA) application key.

Claims (40)

1. A method performed by a user equipment (UE) for accessing an edge computing service, the method comprising:

performing a network access authentication procedure;

deriving an authentication and key management for applications (AKMA) key;

transmitting, to an edge configuration server (ECS), a provisioning request message including an identifier (ID) of the AKMA key;

receiving, from the ECS, a message related to authentication;

obtaining a pre-shared key (PSK); and

performing, with the ECS, an establishment procedure of a transport layer security (TLS) session with the PSK based on authentication for mutual authentication.

2. The method of claim 1 , wherein the UE includes an edge enabler client (EEC).

3. The method of claim 1 , wherein the network access authentication procedure is a primary network access procedure.

4. The method of claim 1 , wherein the ID of the AKMA key is used by the ECS for contacting an entity corresponding to an AKMA anchor function (AAnF) to obtain an edge configuration server specific key (K ECS ).

5. The method of claim 1 ,

wherein the PSK is derived as an output of a key derivation function (KDF), and

wherein inputs of the KDF include an edge configuration server specific key (K ECS ) and parameters including at least one of, a Function Code (FC) value, a Generic Public Subscription Identifier (GPSI), an edge enabler client (EEC) ID, an ECS ID, a text string like “PSK”, or a freshness parameter.

6. The method of claim 5 , wherein the freshness parameter is a counter value maintained by the EEC of the UE.

7. A User Equipment (UE) in an edge computing system comprising:

a memory; and

a controller coupled to the memory and configured to:

perform a network access authentication procedure,

derive an authentication and key management for applications (AKMA) key,

transmit, to an edge configuration server (ECS), a provisioning request message including an identifier (ID) of the AKMA key,

receive, from the ECS, a message related to authentication,

obtain a pre-shared key (PSK), and

perform, with the ECS, an establishment procedure of a transport layer security (TLS) session with the PSK based on authentication for mutual authentication.

8. An edge configuration server (ECS) in an edge computing system comprising:

a memory; and

a controller coupled to the memory configured to:

receive, from a user equipment (UE), a provisioning request message including an identifier (ID) of an authentication and key management for applications (AKMA) key,

obtain an edge configuration server specific key (K ECS ) by contacting an entity corresponding to an AKMA anchor function (AAnF) based on the ID of the AKMA key,

derive a pre-shared key (PSK) based on the edge configuration server specific key (K ECS ), and

perform, with the UE, an establishment procedure of a transport layer security (TLS) session with the PSK based on authentication for mutual authentication.

9. A method performed by an edge configuration server (ECS) for an edge computing service, the method comprising:

receiving, from a user equipment (UE), a provisioning request message including an identifier (ID) of an authentication and key management for applications (AKMA) key;

obtaining an edge configuration server specific key (K ECS ) by contacting an entity corresponding to an AKMA anchor function (AAnF) based on the ID of the AKMA key;

deriving a pre-shared key (PSK) based on the edge configuration server specific key (K ECS ); and

performing, with the UE, an establishment procedure of a transport layer security (TLS) session with the PSK based on authentication for mutual authentication.

10. The method of claim 9 , further comprising:

transmitting, to the entity corresponding to the AAnF, a key request; and

receiving, from the entity corresponding to the AAnF, a key response including the edge configuration server specific key (K ECS ),

wherein the edge configuration server specific key (K ECS ) corresponds to the ID of the AKMA key.

11. The method of claim 9 , wherein the ECS provides configuration information to the UE to connect with an edge application server (EAS) for accessing edge computing services.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2021
From: RAJADURAI, RAJAVELSAMY; GUPTA, NISHANT; RAJENDRAN, ROHINI; SASI, NIVEDYA PARAMBATH
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 057742/0385 →
Priority Claims (2)
IN 202041043965 · Oct 8, 2020 · national
IN 2020 41043965 · Oct 5, 2021 · national
Continuity (1)
Related Publication 20220116774A1 · Apr 14, 2022
References Cited (25)
US 20120297473A1 · Case · 2012 [cited by examiner]
US 20170103388A1 · Pillai · 2017 [cited by examiner]
US 20170272944A1 · Link, II · 2017 [cited by examiner]
US 20180123784A1 · Gehrmann · 2018 [cited by examiner]
US 20190156019A1 · Chen · 2019 [cited by examiner]
US 20190207759A1 · Chan · 2019 [cited by examiner]
US 20200050747A1 · Egner · 2020 [cited by examiner]
US 20210058780A1 · Yu · 2021 [cited by examiner]
US 20210373537A1 · Wei · 2021 [cited by examiner]
US 20210400475A1 · Lehtovirta · 2021 [cited by examiner]
US 20230026671A1 · Seed · 2023 [cited by examiner]
EP 3713152A1 · 2020 [cited by applicant]
WO 2019104124A1 · 2019 [cited by applicant]
WO WO2021167417A1 · 2021 [cited by examiner]
WO WO2021233208A1 · 2021 [cited by examiner]
Samsung, ‘Authentication/Authorization framework for Edge Enabler Client and Servers’, S3-202062, 3GPP TSG-SA3 Meeting #100e, e-meeting, section X.Y.Z.2; and figure X.Y.Z.2-1, Aug. 21, 2020. [cited by applicant]
Apple, ‘pCR: New solution on authentication based on 3GPP credentials’, S3-202151, 3GPP TSG-SA WG3 Meeting #100e, E-meeting, section 3, Aug. 25, 2020. [cited by applicant]
Catt, ‘Key issue on Authentication and Authorization’, S3-201672, 3GPP TSG-SA3 Meeting #100e, emeeting, section 4, Aug. 7, 2020. [cited by applicant]
Samsung, ‘Key issue on Authentication/Authorization of Edge Enabler Client’, S3-201969, 3GPP TSGSA3 Meeting #100e, e-meeting, section 3, Aug. 7, 2020. [cited by applicant]
International Search Report and Written Opinion dated Jan. 7, 2022, issued in International Patent Application No. PCT/KR2021/013932. [cited by applicant]
Indian Office Action dated Jun. 2, 2022, issued in Indan Patent Application No. 202041043965. [cited by applicant]
Samsung, Resolving editor's note on MAC-I calculation, S3-202621, 3GPP TSG-SA3 Meeting #100bis-e, e-meeting, Oct. 2, 2020, XP051937922. [cited by applicant]
3GPP TR 33.839 V0.1.0, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Security Aspects of Enhancement of Support for Edge Computing in 5GC, (Release 17), Sep. 14,… [cited by applicant]
Extended European Search Report dated Jan. 25, 2024, issued in European Patent Application No. 21878065.8. [cited by applicant]
Indian Hearing Notice dated May 1, 2024, issued in Indian Patent Application No. 202041043965. [cited by applicant]
Cited By (1)
US 12,549,365