IP Library › Granted Patent US 11,716,621
Granted Patent B2
US 11,716,621 · App. 17/328,453 · Granted Aug 1, 2023

Apparatus and method for providing mobile edge computing services in wireless communication system

Inventors: Jicheol Lee (Suwon-si, KR); Sunghoon Kim (Suwon-si, KR); Sangsoo Jeong (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
H04W12/068H04L9/3242H04L63/0838H04W12/08H04W12/30H04W12/63H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,716,621
App. No.
17/328,453
Granted
Aug 1, 2023
Kind
B2
Abstract

The disclosure relates to a 5 th generation (5G) or pre-5G communication system for supporting a data transmission rate higher than that of a 4 th generation (4G) system, such as long-term evolution (LTE). The disclosure relates to authentication and authorization for edge computing applications, and an operation method of a user equipment (UE) in a wireless communication system. The method may include transmitting, to a server, a first message including at least one of information related to the UE or a type of user agent, performing an authentication procedure for an edge computing service according to an authentication method determined based on the first message, receiving a second message indicating authority granted to the edge computing service, based on an authentication code generated by the server according to the performed authentication procedure, and using the edge computing service in a range corresponding to the granted authority.

Claims (72)

1. A method performed by a user equipment (UE) in a wireless communication system, the method comprising:

performing an authentication procedure to access the wireless communication system;

obtaining an authentication and key management for application (AKMA) key for an edge computing service after the authentication procedure;

transmitting, to an edge server, a request message for requesting authorization for using the edge computing service, wherein the request message includes a AKMA key ID (identifier) corresponding to the AKMA key;

receiving, from the edge server, a response message indicating authority granted to the edge computing service, wherein the response message includes an access token for using the edge computing service corresponding to the AKMA key ID; and

managing the edge computing service by using the access token.

2. The method of claim 1 , wherein the authentication procedure is performed based on at least one of: authentication method based on a universal subscriber identity module (USIM) credential, an authentication method based on a user portal, authentication method based on a credential generated using information related to the UE, or authentication method based on transmission of a one-time password (OTP).

3. The method of claim 1 , wherein, in case that the authentication procedure is performed based on a universal subscriber identity module (USIM) credential, the performing of the authentication procedure comprises:

receiving, from the edge server, a message including random number information and an authentication token necessary for the UE to perform an authentication procedure; and

identifying whether or not the authentication token included in the received message matches an authentication token generated by the UE.

4. The method of claim 1 ,

wherein, in case that the authentication procedure is performed based on a user portal, the performing of the authentication procedure comprises:

displaying a screen for inputting authentication credential information, based on a message for inputting the authentication credential information received from the edge server;

detecting an input of the authentication credential information; and

transmitting the authentication credential information to the edge server, and

wherein the authentication credential information comprises at least one of a user identification (ID) or a password.

5. The method of claim 1 , wherein, in case that the authentication procedure is performed based on a credential generated using information related to the UE, the performing of the authentication procedure comprises:

receiving, from the edge server, a request message comprising random number information generated by the edge server;

generating a message authentication code (MAC), based on at least one piece of the random number information included in the received request message or the information related to the UE;

transmitting a response message including the MAC to the edge server; and

receiving an authentication code from the edge server, based on verification of the MAC included in the response message.

6. The method of claim 1 , wherein, in case that the authentication procedure is performed based on a transmission of a one-time password (OTP), the performing of the authentication procedure comprises:

receiving an OTP from the edge server;

receiving, from the edge server, a request message comprising random number information generated by the edge server;

generating a message authentication code (MAC), based on at least one of piece of the random number information included in the received request message, a value of the received OTP, or the information related to the UE;

transmitting a response message including the MAC to the edge server; and

receiving the authentication code from the edge server, based on verification of the MAC included in the response message.

7. The method of claim 1 , wherein the access token is encrypted based on the AKMA ID.

8. A method performed by an edge server for authorization for an edge computing service, the method comprising:

receiving, from a user equipment (UE), a request message for requesting authorization for using the edge computing service, wherein the request message includes an authentication and key management for application (AKMA) key ID (identifier) corresponding to the AKMA key;

transmitting, to the UE, a response message indicating authority granted to the edge computing service, wherein the response message includes an access token for using the edge computing service,

wherein the edge computing service corresponding to the access token is managed by the UE.

9. The method of claim 8 , wherein the access token is encrypted based on the AKMA ID.

10. A user equipment (UE) device in a wireless communication system, the device comprising:

at least one transceiver; and

at least one processor operably coupled with the at least one transceiver,

wherein the at least one processor is configured to:

perform an authentication procedure to access the wireless communication system,

obtain an authentication and key management for application (AKMA) key for an edge computing service after the authentication procedure,

transmit, to an edge server, a request message for requesting authorization for using the edge computing service, wherein the request message includes a AKMA key ID (identifier) corresponding to the AKMA key,

receive, from the edge server, a response message indicating authority granted to the edge computing service, wherein the response message includes an access token for using the edge computing service corresponding to the AKMA key ID, and

manage the edge computing service by using the access token.

11. The device of claim 10 , wherein the authentication procedure is performed based on at least one of: an authentication method based on a universal subscriber identity module (USIM) credential, an authentication method based on a user portal, an authentication method based on a credential generated using information related to the UE, or an authentication method based on transmission of a one-time password (OTP).

12. The device of claim 10 , wherein, in case that the authentication procedure is performed based on a first message corresponds to an authentication method based on a universal subscriber identity module (USIM) credential, the at least one processor is further configured to:

receive, from the edge server, a message including random number information and an authentication token necessary for the UE to perform an authentication procedure, and

identify whether or not the authentication token in the received message matches an authentication token generated by the UE.

13. The device of claim 11 ,

wherein, in case that the authentication procedure is performed based on a first message corresponds to an authentication method using a user portal, the at least one processor is further configured to:

display a screen for inputting authentication credential information, based on a message for inputting the authentication credential information received from the edge server,

detect an input of the authentication credential information, and

transmit the authentication credential information to the edge server, and

wherein the authentication credential information comprises at least one of a user identification (ID) or a password.

14. The device of claim 11 , wherein, in case that the authentication procedure is performed based on a first message corresponds to an authentication method based on a credential generated using the information related to the UE, the at least one processor is further configured to:

receive, from the edge server, a request message comprising random number information generated by the edge server,

generate a message authentication code (MAC), based on at least one piece of the random number information included in the received request message or the information related to the UE,

transmit a response message including the MAC to the edge server, and

receive an authentication code from the edge server, based on verification of the MAC included in the response message.

15. The device of claim 10 , wherein, in case that the authentication procedure is performed based on a first message corresponds to an authentication method based on transmission of a one-time password (OTP), the at least one processor is further configured to:

receive an OTP from the edge server,

receive, from the edge server, a request message comprising random number information generated by the edge server,

generate a message authentication code (MAC), based on at least one piece of the random number information included in the received request message, a value of the received OTP, or the information related to the UE,

transmit a response message including the MAC to the edge server, and

receive the authentication code from the edge server, based on verification of the MAC included in the response message.

16. The device of claim 10 , wherein the access token is encrypted based on the AKMA ID.

17. An edge server for authorization for an edge computing service, the edge server comprising:

at least one transceiver; and

at least one processor operably coupled with the at least one transceiver,

wherein the at least one processor is configured to:

receive, from a user equipment (UE), a request message for requesting authorization for using the edge computing service, wherein the request message includes an authentication and key management for application (AKMA) key ID (identifier) corresponding to the AKMA key,

transmit, to the UE, a response message indicating authority granted to the edge computing service, wherein the response message includes an access token for using the edge computing service,

wherein the edge computing service corresponding to the access token is managed by the UE.

18. The edge server of claim 17 , wherein the access token is encrypted based on the AKMA ID.

Priority Claims (2)
KR 10-2020-0043419 · Apr 9, 2020 · national
KR 10-2020-0052917 · Apr 29, 2020 · national
Continuity (3)
Continuation 16870078 · May 8, 2020
Provisional Application 62845426 · May 9, 2019
Related Publication 20210282012A1 · Sep 9, 2021
Cited By (1)
US 12,262,448