IP Library Granted Patent US 12,615,510
Granted Patent B2
US 12,615,510 · App. 18/029,341 · Granted Apr 28, 2026

Key-based authentication for a mobile edge computing network

Inventors: Andreas Kunz (Ladenburg, DE); Sheeba Bakia Mary Baskaran (Friedrichsdorf, DE); Tingfang Tang (Beijing, CN)
Assignee: Lenovo (Beijing) Limited
H04W12/041H04L9/0861H04L9/14H04W12/069H04W12/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,510
App. No.
18/029,341
Granted
Apr 28, 2026
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for key-based authentication for a mobile edge computing network. One method ( 800 ) includes deriving ( 805 ), at a user equipment, a first network key after authentication with a network function of a wireless core network, deriving ( 810 ) a second network key based on the first network key, the second network key for a first network function of a mobile edge computing network, sending ( 815 ) a registration request message to the first network function of the mobile edge computing network, the registration request message integrity protected with the second network key, receiving ( 820 ) a registration response message from the first network function, and, in response to verifying the integrity of the registration response message using the second network key, establishing ( 825 ) a secure communication with the first network function of the mobile edge computing network based on the second network key.

Claims (48)

1 . A user equipment (UE), comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the UE to:

derive a first network key after authentication with a network function of a wireless core network;

derive a second network key based on the first network key, the second network key for a first network function of a mobile edge computing network;

send a registration request message to the first network function of the mobile edge computing network, wherein the registration request message is integrity protected with the second network key;

receive a registration response message from the first network function of the mobile edge computing network; and

in response to verifying an integrity of the registration response message using the second network key, establish a secure communication with the first network function of the mobile edge computing network based on the second network key.

2 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to:

derive a third network key based on the second network key, the third network key for a second network function of the mobile edge computing network, the second network function of the mobile edge computing network different from the first network function of the mobile edge computing network;

send a registration request message to the second network function of the mobile edge computing network, wherein the registration request message is integrity protected with the third network key;

receive a registration response message from the second network function of the mobile edge computing network; and

in response to verifying the integrity of the registration response message using the third network key, establish a secure communication with the second network function of the mobile edge computing network based on the third network key.

3 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to send, to the network function of the wireless core network, an indication that the UE is capable of communicating with the mobile edge computing network.

4 . The apparatus UE of claim 1 , wherein the at least one processor is configured to cause the UE to send, to the network function of the wireless core network, an identifier for the UE in a registration request message for the wireless core network.

5 . The UE of claim 1 , wherein the second network key for the first network function of the mobile edge computing network is derived using at least the first network key and a key distinguisher flag, the key distinguisher flag indicating which network key to derive for a network function of the mobile edge computing network.

6 . The UE of claim 5 , wherein the key distinguisher flag specifies a network key for one of an edge configuration server (“ECS”) function, an edge enabler server (“EES”) server, and an edge application server (“EAS”) function of the mobile edge computing network.

7 . The UE of claim 1 , wherein the first network key comprises a network key associated with an Access and Mobility Management Function (“AMF”) of the wireless core network.

8 . A network equipment (NE), comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the NE to:

receive, at a first network function of a mobile edge computing network, a network key request from a second network function of the mobile edge computing network, the network key request comprising a registration request message for a user equipment (UE) that is integrity protected with a first network key;

derive, at the first network function, the first network key based on a previously derived second network key associated with the first network function;

verify an integrity of the registration request message using the first network key; and

send a key response message to the second network function that comprises an indication of verification of the integrity of the registration request message and the first network key.

9 . The NE of claim 8 , wherein the first network key is derived based on the previously derived second network key associated with the first network function and a key distinguisher flag, the key distinguisher flag indicating which network key to derive for a network function of the mobile edge computing network.

10 . The NE of claim 8 , wherein the at least one processor is configured to cause the NE to:

receive the registration request message from the UE at the second network function, the registration request message comprising an identifier for the UE that is used to determine a network function for authenticating the UE; and

send the network key request, including the registration request message, to the first network function.

11 . The NE of claim 10 , wherein the identifier for the UE comprises at least one of a fifth generation (5G) Globally Unique Temporary UE Identity, a Subscription Concealed Identifier, an error correction code (ECC) identifier (ID), an external ID, and an internet protocol (IP) address.

12 . The NE of claim 8 , wherein the first network function comprises an edge configuration server (“ECS”) and the second network function comprises an edge enabler server (“EES”), the first network key comprising a network key for the EES and the second network key comprising a network key for the ECS.

13 . The NE of claim 8 , wherein the first network function comprises an edge enabler server (“EES”) and the second network function comprises an edge application server (“EAS”), the first network key comprising a network key for the EAS and the second network key comprising a network key for the EES.

14 . The NE of claim 8 , wherein the at least one processor is configured to cause the NE to:

receive the key response message from the first network function at the second network function;

send a registration response message to the UE from the second network function that includes the indication of integrity verification of the registration request message, wherein the registration response message is integrity protected with the first network key; and

establish a secure communication between the second network function and the UE using the first network key.

15 . A network equipment (NE), comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the NE to:

receive, at a network function of a wireless core network, a registration request message from a user equipment (UE), the registration request message comprising at least one of an identifier for the UE and an indication that the UE is capable of communicating with a mobile edge computing network;

derive a second network key for a first network function of a mobile edge computing network based on a first network key associated with the network function of the wireless core network;

receive an authentication request message for the UE from the first network function of the mobile edge computing network, the authentication request message integrity protected with the second network key; and

in response to verifying an integrity of the authentication request message using the second network key, send an authentication response message to the first network function of the mobile edge computing network that indicates that the UE is authenticated for communicating with the mobile edge computing network.

16 . The NE of claim 15 , wherein the authentication response message to the first network function of the mobile edge computing network further comprises the second network key.

17 . The NE of claim 15 , wherein the network function of the wireless core network comprises an Access and Mobility Management Function (“AMF”).

18 . The NE of claim 15 , wherein the second network key is derived using at least the first network key associated with network function of the wireless core network and a key distinguisher flag, the key distinguisher flag indicating which network key to derive for a network function of the mobile edge computing network.

19 . The NE of claim 15 , wherein the identifier for the UE comprises at least one of a fifth generation (5G) Globally Unique Temporary UE Identity, a Subscription Concealed Identifier, an error correction code (ECC) identifier (ID), an external ID, and an internet protocol (IP) address.

20 . The NE of claim 15 , wherein the at least one processor is configured to cause the NE to send the network key request to a network function within a wireless core network where the UE is authenticated and registered.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2023
From: KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY; TANG, TINGFANG
To: LENOVO (BEIJING) LIMITED
Reel/Frame 063161/0539 →
Continuity (1)
Related Publication 20230388788A1 · Nov 30, 2023
References Cited (14)
US 20140006786A1 · Campagna et al. · 2014 [cited by applicant]
US 20150281188A1 · Sakemi · 2015 [cited by examiner]
US 20170300978A1 · Narasimhan · 2017 [cited by examiner]
US 20200280559A1 · Wu · 2020 [cited by examiner]
CA 3019276A1 · 2017 [cited by examiner]
CA 3053316A1 · 2018 [cited by examiner]
CN 108173882A · 2018 [cited by applicant]
CN 108781366A · 2018 [cited by applicant]
International Searching Authority, “Written Opinion of the International Searching Authority,” PCT/CN2020/119365, Jun. 21, 2021, pp. 1-4. [cited by applicant]
Jia, Xiaoying et al. “A Provacably Secure and Efficient Identity-Based Anonymous Authentication Scheme for Mobile Edge Computing”, IEEE Systems Journal, vol. 14, No. 1, Mar. 31, 2020 (Mar. 31, 2020), pp. 1-12. [cited by applicant]
Samsung, “Authentication/Authorization framework for Edge Enabler Client and Servers”, 3GPP TSG-SA3 Meeting #100e S3-202062, Aug. 17-28, 2020, pp. 1-3. [cited by applicant]
Apple, “pCR: New solution on authentication based on 3GPP credentials”, 3GPP TSG-SA WG3 Meeting #100e S3-202151, Aug. 17-28, 2020, pp. 1-3. [cited by applicant]
Lenovo et al., “Authentication and Authorization with the Edge Data Network”, 3GPP TSG-SA3 Meeting #100bis-e S3-202605, Oct. 12-16, 2020, pp. 1-3. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Security Aspects of Enhancement of Support for Edge Computing in 5GC (Release 17)”, 3GPP TR 33.839 V0.1.0, A… [cited by applicant]