IP Library Granted Patent US 12,382,284
Granted Patent B2
US 12,382,284 · App. 17/593,460 · Granted Aug 5, 2025

User equipment authentication and authorization procedure for edge data network

Inventors: Shu Guo (Beijing, CN); Dawei Zhang (Saratoga, CA); Fangli Xu (Beijing, CN); Haijing Hu (Los Gatos, CA); Huarui Liang (Beijing, CN); Mona Agnel (Guildford, GB); Ralf Rossbach (Munich, DE); Sudeep Manithara Vamanan (Nuremberg, DE); Xiangying Yang (Cupertino, CA); Yuqin Chen (Beijing, CN)
Assignee: Apple Inc.
H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,382,284
App. No.
17/593,460
Granted
Aug 5, 2025
Kind
B2
Abstract

A user equipment (UE) may attempt to access an edge data network. The UE generates a first credential based on a second credential, the second credential generated for a procedure between the UE and a cellular network, generating an identifier corresponding to the first credential, and generates a multi-access edge computing (MEC) authorization parameter. The UE then transmits an application registration request message to a server associated with an edge data network, the application registration request message including an indication of the first credential, the identifier corresponding to the first credential and the first authorization parameter. The UE then receives an authentication accept message or an authentication reject message from the server associated with the edge data network.

Claims (32)

1. A method, comprising:

at a user equipment (UE):

generating a first credential based on a second credential, the second credential generated for a primary authentication procedure between the UE and a cellular network, wherein the second credential is an Authentication Server Function (AUSF) key (K AUSF );

generating an identifier corresponding to the first credential, said identifier uniquely identifying the first credential;

calculating a multi-access edge computing (MEC) authorization parameter using the first credential and a second identifier, the second identifier being a globally unique value associated with an edge enabler client (EEC) running on the UE;

transmitting an application registration request message to a server associated with an edge data network, the application registration request message including the second identifier, the second identifier corresponding to the first credential and the MEC authorization parameter; and

receiving an authentication accept message or an authentication reject message from the server associated with the edge data network, wherein the authentication accept message or the authentication rejection message is based on a validation of the MEC authorization parameter.

2. The method of claim 1 , wherein the primary authentication procedure includes an authentication server function (AUSF).

3. The method of claim 1 , wherein the first credential is further based on an identifier associated with the UE or other shared information between the UE and the cellular network.

4. The method of claim 3 , wherein the identifier associated with the UE is one of a subscription permanent identifier (SUPI) or a generic public subscription identifier (GPSI).

5. The method of claim 1 , wherein the server associated with the edge data network is an edge configuration server (ECS).

6. The method of claim 1 , wherein the server associated with the edge data network transmits the authentication accept message-based on a second MEC authorization parameter, generated from information in the request message, matching the MEC authorization parameter.

7. The method of claim 1 , wherein the first credential is based on a key derivation function (KDF) and wherein the MEC authorization parameter is generated based on a hashing function.

8. A user equipment (UE), comprising:

a processor configured to perform operations comprising:

generating a first credential based on a second credential, the second credential generated for a primary authentication procedure between the UE and a cellular network, wherein the second credential is an Authentication Server Function (AUSF) key (K AUSF );

generating an identifier corresponding to the first credential, said identifier uniquely identifying the first credential;

calculating a multi-access edge computing (MEC) authorization parameter using the first credential and a second identifier, the second identifier being a globally unique value associated with an edge enabler client (EEC) running on the UE;

generating an application registration request message to a server associated with an edge data network, the application registration request message including the second identifier, the second identifier corresponding to the first credential and the MEC authorization parameter; and

receiving an authentication accept message or an authentication reject message from the server associated with the edge data network, based on the MEC authorization parameter being verified, wherein the authentication accept message is transmitted when a second MEC authorization parameter, generated from information in the request message, matches the MEC authorization parameter; and

a transceiver communicatively connected to the processor.

9. The UE of claim 8 , wherein the first credential is further based on an identifier associated with the UE or other shared information between the UE and the cellular network.

10. The UE of claim 8 , wherein the server associated with the edge data network is an edge configuration server (ECS).

11. A non-transitory computer readable storage media having instructions stored thereon that, when executed by a baseband processor of a user equipment (UE), result in operations comprising:

generating a first credential based on a second credential, the second credential generated for a procedure between a UE and a cellular network;

generating an identifier corresponding to the first credential, said identifier uniquely identifying the first credential;

calculating a multi-access edge computing (MEC) authorization parameter using the first credential and a second identifier, the second identifier being a globally unique value associated with an edge enabler client (EEC) running on the UE;

generating an application registration request message to a server associated with an edge data network, the application registration request message including the second identifier, the second identifier corresponding to the first credential and the MEC authorization parameter; and

receiving at least one of: an authentication accept message and an authentication reject message from the server associated with the edge data network, wherein the authentication accept message is received when a second MEC authorization parameter, generated from information in the request message, matches the MEC authorization parameter.

12. The non-transitory computer readable storage media of claim 11 , wherein the second credential is generated for a primary authentication procedure includes an authentication server function (AUSF) and the second credential is K AUSF .

13. The non-transitory computer readable storage media of claim 11 , wherein the first credential is further based on an identifier associated with the UE or other shared information between the UE and the cellular network.

14. The non-transitory computer readable storage media of claim 11 , wherein the server associated with the edge data network is an edge configuration server (ECS).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2021
From: GUO, SHU; ZHANG, DAWEI; XU, FANGLI; HU, HAIJING; LIANG, HUARUI; AGNEL, MONA; ROSSBACH, RALF; VAMANAN, SUDEEP MANITHARA; YANG, XIANGYING; CHEN, YUQIN
To: APPLE INC.
Reel/Frame 058203/0064 →
Continuity (1)
Related Publication 20220303767A1 · Sep 22, 2022
References Cited (38)
US 10499304B1 · Stauffer et al. · 2019 [cited by applicant]
US 10932108B1 · Balmakhtar et al. · 2021 [cited by applicant]
US 11889308B2 · Guo · 2024 [cited by examiner]
US 20180192390A1 · Li et al. · 2018 [cited by applicant]
US 20180192471A1 · Li et al. · 2018 [cited by applicant]
US 20190075116A1 · Nishi · 2019 [cited by applicant]
US 20200068391A1 · Liu et al. · 2020 [cited by applicant]
US 20200296653A1 · Huang · 2020 [cited by applicant]
US 20200344604A1 · He · 2020 [cited by examiner]
US 20200359218A1 · Lee · 2020 [cited by examiner]
US 20200389531A1 · Lee et al. · 2020 [cited by applicant]
US 20210307089A1 · Kim et al. · 2021 [cited by applicant]
US 20210409942A1 · De Kievit · 2021 [cited by examiner]
US 20220060325A1 · Castellanos Zamora et al. · 2022 [cited by applicant]
US 20220201093A1 · Gupta · 2022 [cited by examiner]
US 20220272651A1 · Chun · 2022 [cited by applicant]
US 20230068196A1 · Sasi et al. · 2023 [cited by applicant]
US 20230070253A1 · Rajadurai · 2023 [cited by examiner]
CN 107770815 · 2018 [cited by applicant]
CN 108810026 · 2018 [cited by applicant]
CN 109861828 · 2019 [cited by applicant]
CN 110291803 · 2019 [cited by applicant]
CN 110366269 · 2019 [cited by applicant]
CN 110995418 · 2020 [cited by applicant]
CN 111052849 · 2020 [cited by applicant]
CN 111355745 · 2020 [cited by applicant]
KR 20200007754 · 2020 [cited by applicant]
WO 2019118964 · 2019 [cited by applicant]
WO 2019122495 · 2019 [cited by applicant]
WO 2019126931 · 2019 [cited by applicant]
WO 2019170047 · 2019 [cited by applicant]
WO 2020005925 · 2020 [cited by applicant]
WO 2020013677 · 2020 [cited by applicant]
WO 2021167417 · 2021 [cited by applicant]
Zhang et al., “Towards secure 5G networks: A Survey”, Computer Networks, vol. 162, Jul. 31, 2019, 22 sheets. [cited by applicant]
3rd Generation Partnership Project; “Technical Specification Group Services and System Aspects; Architecture for enabling Edge Applications; (Release 17)”; 3GPP TS 23.558 V0.3.0, Jun. 30, 2020; 70 sheets. [cited by applicant]
3rd Generation Partnership Project, “Technical Specification Group Services and System Aspects; Study on application architecture for enabling Edge Applications; (Release 17)”; 3GPP TR 23.758 V17.0.0; Dec. 31, 2019; 113… [cited by applicant]
Ericsson, “Edge Application Server Discovery and selection using DNS”, 3GPP TSG-SA/WG2 Meeting #136-AH, S2-2000196, Jan. 7, 2020, 4 sheets. [cited by applicant]