IP Library Granted Patent US 12,273,707
Granted Patent B2
US 12,273,707 · App. 17/555,196 · Granted Apr 8, 2025

Deriving a key based on an edge enabler client identifier

Inventors: Andreas Kunz (Ladenburg, DE); Sheeba Backia Mary Baskaran (Friedrichsdorf, DE)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04W12/041H04L9/0819H04L9/0866H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,707
App. No.
17/555,196
Granted
Apr 8, 2025
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for deriving a key based on an edge enabler client identifier. One method includes receiving, at a network function, a request message from an edge server function. The request message includes: an edge server identifier; and an edge enabler client identifier (EEC-ID), wherein the EEC-ID includes: an unencrypted EEC-ID; or an encrypted EEC-ID. The encrypted EEC-ID is encrypted with an authentication and key management (AKMA) key (K AKMA ). The method includes deriving a unique key (K AFEEC ) based on the edge server identifier and the EEC-ID. The method includes transmitting a response message to the edge server function. The response message includes: the K AFEEC ; and an unencrypted EEC-ID.

Claims (42)

1. A method of a network function, the method comprising:

receiving a request message from an edge server function, wherein the request message comprises: an edge server identifier and an edge enabler client identifier (EEC-ID), wherein the EEC-ID comprises an unencrypted EEC-ID or an encrypted EEC-ID, wherein the encrypted EEC-ID is encrypted with an authentication and key management (AKMA) key (K AKMA );

deriving an application specific key (K AF ) based on the edge server identifier;

authenticating the edge server function;

when the edge server function is authenticated, decrypting the EEC-ID and deriving a unique key (K AFEEC ) in an AKMA anchor function (AAnF) based on the K AF and the EEC-ID; and

transmitting a response message to the edge server function, wherein the response message comprises the K AFEEC and an unencrypted EEC-ID.

2. The method of claim 1 , wherein the network function comprises an AKMA anchor function.

3. The method of claim 1 , wherein the edge server function comprises an edge configuration server, an edge enabler server, or a combination thereof.

4. The method of claim 1 , wherein the edge server identifier comprises an edge configuration identifier, an edge enabler server identifier, or a combination thereof.

5. The method of claim 1 , wherein the request message further comprises an AKMA key identifier.

6. The method of claim 1 , further comprising, in response to the EEC-ID comprising the encrypted EEC-ID, decrypting the EEC-ID with the K AKMA .

7. The method of claim 6 , wherein decrypting the EEC-ID with the K AKMA comprises decrypting the EEC-ID in response to the EEC-ID being encrypted.

8. The method of claim 1 , wherein the response message further comprises a K AFEEC expiry time.

9. An apparatus for performing a network function, the apparatus comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the apparatus to:

receive a request message from an edge server function, wherein the request message comprises an edge server identifier and an edge enabler client identifier (EEC-ID), wherein the EEC-ID comprises an unencrypted EEC-ID or an encrypted EEC-ID, wherein the encrypted EEC-ID is encrypted with an authentication and key management (AKMA) key (K AKMA );

derive an application specific key (K AF ) based on the edge server identifier;

authenticate the edge server function;

when the edge server function is authenticated, decrypt the EEC-ID and derive a unique key (K AFEEC ) in an AKMA anchor function (AAnF) based on the K AF and the EEC-ID; and

transmit a response message to the edge server function, wherein the response message comprises the K AFEEC and an unencrypted EEC-ID.

10. The apparatus of claim 9 , wherein the network function comprises an AKMA anchor function.

11. The apparatus of claim 9 , wherein the edge server function comprises an edge configuration server, an edge enabler server, or a combination thereof.

12. The apparatus of claim 9 , wherein the edge server identifier comprises an edge configuration identifier, an edge enabler server identifier, or a combination thereof.

13. The apparatus of claim 9 , wherein the request message further comprises an AKMA key identifier.

14. The apparatus of claim 9 , wherein the at least one processor is configured to cause the apparatus to, in response to the EEC-ID comprising the encrypted EEC-ID, decrypt the EEC-ID with the K AKMA .

15. A user equipment (UE), comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the UE to:

transmit a request message to an edge server function, wherein the request message comprises an unencrypted EEC-ID or an encrypted EEC-ID, wherein the encrypted EEC-ID is encrypted with an authentication and key management (AKMA) key (K AKMA );

authenticate the edge server function;

when the edge server function is authenticated, decrypt the EEC-ID and derive a first unique key (K AFEEC ) based on an application specific key (K AF ) and an edge enabler client identifier (EEC-ID); and

receive a response message from the edge server function, wherein the response message comprises a second K AFEEC associated with the edge server function.

16. The UE of claim 15 , wherein the edge server function comprises an edge configuration server, an edge enabler server, or a combination thereof.

17. The UE of claim 15 , wherein the at least one processor is configured to cause the UE to compute the K AKMA .

18. The UE of claim 15 , wherein the at least one processor is configured to cause the UE to compute an AKMA key identifier.

19. A hardware processor for wireless communication, comprising:

at least one controller coupled with at least one memory and configured to cause the hardware processor to:

transmit a request message to an edge server function, wherein the request message comprises an unencrypted EEC-ID or an encrypted EEC-ID, wherein the encrypted EEC-ID is encrypted with an authentication and key management (AKMA) key (K AKMA );

authenticate the edge server function;

when the edge server function is authenticated, decrypt the EEC-ID and derive a first unique key (K AFEEC ) based on an application specific key (K AF ) and an edge enabler client identifier (EEC-ID); and

receive a response message from the edge server function, wherein the response message comprises a second K AFEEC used by the edge server function.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2022
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 061880/0110 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2022
From: KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (UNITED STATES) INC.
Reel/Frame 058623/0945 →
Continuity (1)
Related Publication 20230199483A1 · Jun 22, 2023
References Cited (12)
US 9088557B2 · Aoyagi · 2015 [cited by examiner]
US 20140351595A1 · Blom · 2014 [cited by examiner]
US 20230068196A1 · Sasi · 2023 [cited by examiner]
WO WO2021167399A1 · 2021 [cited by examiner]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enhancement of support for edge computing in the 5G Core (5GC) (Release 17)”, Dec. 3, 2021 (De… [cited by examiner]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security aspects of enhancement of support for enabling edge applications; Stage 2 (Release 17)”, 3GPP TS 33.558 V0.3… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (Release 1… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Access to network application functions using Hypertext Transfer Protocol … [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Generic Bootstrapping Architecture (GBA) (Release 17)”, 3GPP TS 33.220 V17… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture for enabling Edge Applications; (Release 17)”, 3GPP TS 23.558 V17.2.0, Dec. 2021, pp. 1-163. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enhancement of support for edge computing in the 5G Core (5GC) (Release 17)”, 3GPP TR 33… [cited by applicant]
PCT/IB2022/062260, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration”, International Searching Authority, Feb. 27, 2023,… [cited by applicant]