Key-based authentication for a mobile edge computing network
Apparatuses, methods, and systems are disclosed for key-based authentication for a mobile edge computing network. One method ( 800 ) includes deriving ( 805 ), at a user equipment, a first network key after authentication with a network function of a wireless core network, deriving ( 810 ) a second network key based on the first network key, the second network key for a first network function of a mobile edge computing network, sending ( 815 ) a registration request message to the first network function of the mobile edge computing network, the registration request message integrity protected with the second network key, receiving ( 820 ) a registration response message from the first network function, and, in response to verifying the integrity of the registration response message using the second network key, establishing ( 825 ) a secure communication with the first network function of the mobile edge computing network based on the second network key.
1 . A user equipment (UE), comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the UE to:
derive a first network key after authentication with a network function of a wireless core network;
derive a second network key based on the first network key, the second network key for a first network function of a mobile edge computing network;
send a registration request message to the first network function of the mobile edge computing network, wherein the registration request message is integrity protected with the second network key;
receive a registration response message from the first network function of the mobile edge computing network; and
in response to verifying an integrity of the registration response message using the second network key, establish a secure communication with the first network function of the mobile edge computing network based on the second network key.
2 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to:
derive a third network key based on the second network key, the third network key for a second network function of the mobile edge computing network, the second network function of the mobile edge computing network different from the first network function of the mobile edge computing network;
send a registration request message to the second network function of the mobile edge computing network, wherein the registration request message is integrity protected with the third network key;
receive a registration response message from the second network function of the mobile edge computing network; and
in response to verifying the integrity of the registration response message using the third network key, establish a secure communication with the second network function of the mobile edge computing network based on the third network key.
3 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to send, to the network function of the wireless core network, an indication that the UE is capable of communicating with the mobile edge computing network.
4 . The apparatus UE of claim 1 , wherein the at least one processor is configured to cause the UE to send, to the network function of the wireless core network, an identifier for the UE in a registration request message for the wireless core network.
5 . The UE of claim 1 , wherein the second network key for the first network function of the mobile edge computing network is derived using at least the first network key and a key distinguisher flag, the key distinguisher flag indicating which network key to derive for a network function of the mobile edge computing network.
6 . The UE of claim 5 , wherein the key distinguisher flag specifies a network key for one of an edge configuration server (“ECS”) function, an edge enabler server (“EES”) server, and an edge application server (“EAS”) function of the mobile edge computing network.
7 . The UE of claim 1 , wherein the first network key comprises a network key associated with an Access and Mobility Management Function (“AMF”) of the wireless core network.
8 . A network equipment (NE), comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the NE to:
receive, at a first network function of a mobile edge computing network, a network key request from a second network function of the mobile edge computing network, the network key request comprising a registration request message for a user equipment (UE) that is integrity protected with a first network key;
derive, at the first network function, the first network key based on a previously derived second network key associated with the first network function;
verify an integrity of the registration request message using the first network key; and
send a key response message to the second network function that comprises an indication of verification of the integrity of the registration request message and the first network key.
9 . The NE of claim 8 , wherein the first network key is derived based on the previously derived second network key associated with the first network function and a key distinguisher flag, the key distinguisher flag indicating which network key to derive for a network function of the mobile edge computing network.
10 . The NE of claim 8 , wherein the at least one processor is configured to cause the NE to:
receive the registration request message from the UE at the second network function, the registration request message comprising an identifier for the UE that is used to determine a network function for authenticating the UE; and
send the network key request, including the registration request message, to the first network function.
11 . The NE of claim 10 , wherein the identifier for the UE comprises at least one of a fifth generation (5G) Globally Unique Temporary UE Identity, a Subscription Concealed Identifier, an error correction code (ECC) identifier (ID), an external ID, and an internet protocol (IP) address.
12 . The NE of claim 8 , wherein the first network function comprises an edge configuration server (“ECS”) and the second network function comprises an edge enabler server (“EES”), the first network key comprising a network key for the EES and the second network key comprising a network key for the ECS.
13 . The NE of claim 8 , wherein the first network function comprises an edge enabler server (“EES”) and the second network function comprises an edge application server (“EAS”), the first network key comprising a network key for the EAS and the second network key comprising a network key for the EES.
14 . The NE of claim 8 , wherein the at least one processor is configured to cause the NE to:
receive the key response message from the first network function at the second network function;
send a registration response message to the UE from the second network function that includes the indication of integrity verification of the registration request message, wherein the registration response message is integrity protected with the first network key; and
establish a secure communication between the second network function and the UE using the first network key.
15 . A network equipment (NE), comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the NE to:
receive, at a network function of a wireless core network, a registration request message from a user equipment (UE), the registration request message comprising at least one of an identifier for the UE and an indication that the UE is capable of communicating with a mobile edge computing network;
derive a second network key for a first network function of a mobile edge computing network based on a first network key associated with the network function of the wireless core network;
receive an authentication request message for the UE from the first network function of the mobile edge computing network, the authentication request message integrity protected with the second network key; and
in response to verifying an integrity of the authentication request message using the second network key, send an authentication response message to the first network function of the mobile edge computing network that indicates that the UE is authenticated for communicating with the mobile edge computing network.
16 . The NE of claim 15 , wherein the authentication response message to the first network function of the mobile edge computing network further comprises the second network key.
17 . The NE of claim 15 , wherein the network function of the wireless core network comprises an Access and Mobility Management Function (“AMF”).
18 . The NE of claim 15 , wherein the second network key is derived using at least the first network key associated with network function of the wireless core network and a key distinguisher flag, the key distinguisher flag indicating which network key to derive for a network function of the mobile edge computing network.
19 . The NE of claim 15 , wherein the identifier for the UE comprises at least one of a fifth generation (5G) Globally Unique Temporary UE Identity, a Subscription Concealed Identifier, an error correction code (ECC) identifier (ID), an external ID, and an internet protocol (IP) address.
20 . The NE of claim 15 , wherein the at least one processor is configured to cause the NE to send the network key request to a network function within a wireless core network where the UE is authenticated and registered.