Key identification for mobile edge computing functions
Various aspects of the present disclosure relate to key identification for mobile edge computing functions. An apparatus includes at least one memory and at least one processor that is configured to generate a unique key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service, derive a key for a network function based on a corresponding root key and the generated KSI, the KSI provided as input to a key derivation function (“KDF”), and transmit an application registration request message to the network function for establishing a secure connection to the network function using the key, the application registration request message comprising the KSI.
1 . A user equipment (“UE”) for wireless communication, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the UE to:
generate a unique key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service;
derive a key for a network function based on a corresponding root key and the unique KSI, the unique KSI provided as input to a key derivation function (“KDF”); and
transmit an application registration request message to the network function for establishing a secure connection to the network function using the key, the application registration request message comprising the unique KSI.
2 . The UE of claim 1 , wherein the network function comprises an edge configuration server (“ECS”), an edge enabler server (“EES”), an edge application server (“EAS”), or a combination thereof.
3 . The UE of claim 2 , wherein the unique KSI is used to derive keys for each of the ECS, the EES, and EAS network functions using the KDF.
4 . The UE of claim 2 , wherein the at least one processor is configured to cause the UE to generate different unique KSIs to derive keys for each of the ECS, the EES, and EAS network functions using the KDF.
5 . The UE of claim 2 , wherein the corresponding root key is for one of an access and mobility management function (“AMF”), the ECS, and or the EES.
6 . The UE of claim 1 , wherein the unique KSI is valid for one or more of a duration of the MEC service, until an access and mobility management function (“AMF”) key is refreshed, until the AMF is changed, or a combination thereof.
7 . The UE of claim 1 , wherein the unique KSI is permanently assigned to the MEC service.
8 . The UE of claim 1 , wherein the unique KSI is a value of a counter that is adjusted with each new generated unique KSI.
9 . The UE of claim 1 , wherein the unique KSI is a randomly generated number based in part on a number of available MEC services.
10 . The UE of claim 1 , wherein the unique KSI is a static value that is pre-configured for the MEC service.
11 . The UE of claim 1 , wherein the unique KSI is a character string derived from one of a name or a description of the MEC service.
12 . A network equipment for wireless communication, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the network equipment to:
receive a key request message from a first network function via a second network function, the key request message comprising an application request message and a key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service;
derive a key for the first network function using an access and mobility management function (“AMF”) key and the KSI as inputs to a key derivation function (“KDF”); and
transmit the key to the first network function, via the second network function.
13 . The network equipment of claim 12 , wherein the first network function comprises an edge configuration server (“ECS”) and the second network function comprises a network exposure function (“NEF”).
14 . A network equipment for wireless communication, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the network equipment to:
receive an application request message comprising a key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service and a request for access to the MEC service;
generate a key request message comprising the application request message and the KSI;
transmit the key request message to a first network function;
receive a key from the first network function in response to the request; and
associate the key with the MEC service of the application request message using the KSI.
15 . The network equipment of claim 14 , wherein the network equipment comprises an edge configuration server (“ECS”), an edge enabler server (“EES”), an edge application server (“EAS”), or a combination thereof, and the first network function comprises a corresponding network exposure function (“NEF”), an ECS, an EES, or a combination thereof.
16 . A method performed by a user equipment (“UE”), comprising:
generating a unique key set identifier (“KSI”) associated with a multi-access edge computing (“MEC”) service; and
deriving a key for a network function based on a corresponding root key and the unique KSI, the unique KSI provided as input to a key derivation function (“KDF”); and
transmitting an application registration request message to the network function for establishing a secure connection to the network function using the key, the application registration request message comprising the unique KSI.
17 . The method of claim 16 , wherein the network function comprises an edge configuration server (“ECS”), an edge enabler server (“EES”), an edge application server (“EAS”), or a combination thereof.
18 . The method of claim 17 , wherein the unique KSI is used to derive keys for each of the ECS, the EES, and EAS network functions using the KDF.
19 . The method of claim 17 , further comprising generating different unique KSIs to derive keys for each of the ECS, the EES, and EAS network functions using the KDF.
20 . The method of claim 17 , wherein the corresponding root key is for one of an access and mobility management function (“AMF”), the ECS, or the EES.