Validating edge computing devices using verification of network identifiers
Techniques are provided for validating edge computing devices using verification of network identifiers. One method comprises obtaining an ownership voucher for an edge device, wherein the ownership voucher comprises credentials of the edge device, wherein the edge device comprises an integrated circuit used by the edge device to access a network, such as a mobile network, and wherein the ownership voucher further comprises: (i) an identifier of the integrated circuit used to access the network and/or (ii) an identifier of the network; verifying, by a provider of the network: (i) the identifier of the integrated circuit and/or (ii) the identifier of the network; and automatically enabling the edge device to access the network based on a result of the verifying. The ownership voucher may comprise an identifier of a subscriber of the network and the provider of the network may verify the identifier of the subscriber of the network.
1 . A method, comprising:
obtaining at least a portion of at least one cryptographically attested digital document for at least one edge device, wherein the at least one cryptographically attested digital document comprises one or more credentials of the at least one edge device, wherein the at least one edge device comprises at least one integrated circuit used by the at least one edge device to access at least one network, wherein the at least one edge device is onboarded to an edge infrastructure management platform, and wherein the at least one cryptographically attested digital document is updated during an onboarding of the at least one edge device to further comprise one or more of: (i) at least one identifier of the at least one integrated circuit used to access the at least one network, obtained from a provider of the at least one network during the onboarding, and (ii) at least one identifier of the at least one network, obtained from the provider of the at least one network during the onboarding;
verifying, by at least one processing device of the provider of the at least one network, one or more of: (i) the at least one identifier of the at least one integrated circuit and (ii) the at least one identifier of the at least one network; and
automatically enabling the at least one edge device to access the at least one network based at least in part on a result of the verifying;
wherein the method is performed by at least one processing device comprising a processor coupled to a memory.
2 . The method of claim 1 , wherein the at least one cryptographically attested digital document further comprises at least one identifier of at least one subscriber of the at least one network and wherein the verifying, by the at least one processing device of the provider of the at least one network, comprises verifying the at least one identifier of at least one subscriber of the at least one network.
3 . The method of claim 1 , wherein the at least one integrated circuit comprises one or more of a subscriber identity module, a universal integrated circuit card and an embedded universal integrated circuit card.
4 . The method of claim 1 , wherein an entity associated with the at least one edge device updates the at least one cryptographically attested digital document with the one or more of: (i) the at least one identifier of the at least one integrated circuit and (ii) the at least one identifier of the at least one network.
5 . The method of claim 1 , wherein the at least one cryptographically attested digital document comprises an ownership voucher.
6 . The method of claim 1 , wherein the one or more credentials of the at least one edge device comprise one or more keys.
7 . The method of claim 6 , wherein the one or more keys comprise at least an asymmetric public key of a public-private key pair.
8 . An apparatus, comprising:
at least one processing device comprising a processor coupled to a memory;
the at least one processing device being configured to implement the following steps:
obtaining at least a portion of at least one cryptographically attested digital document for at least one edge device, wherein the at least one cryptographically attested digital document comprises one or more credentials of the at least one edge device, wherein the at least one edge device comprises at least one integrated circuit used by the at least one edge device to access at least one network, wherein the at least one edge device is onboarded to an edge infrastructure management platform, and wherein the at least one cryptographically attested digital document is updated during an onboarding of the at least one edge device to further comprise one or more of: (i) at least one identifier of the at least one integrated circuit used to access the at least one network, obtained from a provider of the at least one network during the onboarding, and (ii) at least one identifier of the at least one network, obtained from the provider of the at least one network during the onboarding;
verifying, by at least one processing device of the provider of the at least one network, one or more of: (i) the at least one identifier of the at least one integrated circuit and (ii) the at least one identifier of the at least one network; and
automatically enabling the at least one edge device to access the at least one network based at least in part on a result of the verifying.
9 . The apparatus of claim 8 , wherein the at least one cryptographically attested digital document further comprises at least one identifier of at least one subscriber of the at least one network and wherein the verifying, by the at least one processing device of the provider of the at least one network, comprises verifying the at least one identifier of at least one subscriber of the at least one network.
10 . The apparatus of claim 8 , wherein the at least one integrated circuit comprises one or more of a subscriber identity module, a universal integrated circuit card and an embedded universal integrated circuit card.
11 . The apparatus of claim 8 , wherein an entity associated with the at least one edge device updates the at least one cryptographically attested digital document with the one or more of: (i) the at least one identifier of the at least one integrated circuit and (ii) the at least one identifier of the at least one network.
12 . The apparatus of claim 8 , wherein the one or more credentials of the at least one edge device comprise one or more keys, and wherein the one or more keys comprise at least an asymmetric public key of a public-private key pair.
13 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:
obtaining at least a portion of at least one cryptographically attested digital document for at least one edge device, wherein the at least one cryptographically attested digital document comprises one or more credentials of the at least one edge device, wherein the at least one edge device comprises at least one integrated circuit used by the at least one edge device to access at least one network, wherein the at least one edge device is onboarded to an edge infrastructure management platform, and wherein the at least one cryptographically attested digital document is updated during an onboarding of the at least one edge device to further comprise one or more of: (i) at least one identifier of the at least one integrated circuit used to access the at least one network, obtained from a provider of the at least one network during the onboarding, and (ii) at least one identifier of the at least one network, obtained from the provider of the at least one network during the onboarding;
verifying, by at least one processing device of the provider of the at least one network, one or more of: (i) the at least one identifier of the at least one integrated circuit and (ii) the at least one identifier of the at least one network; and
automatically enabling the at least one edge device to access the at least one network based at least in part on a result of the verifying.
14 . The non-transitory processor-readable storage medium of claim 13 , wherein the at least one cryptographically attested digital document further comprises at least one identifier of at least one subscriber of the at least one network and wherein the verifying, by the at least one processing device of the provider of the at least one network, comprises verifying the at least one identifier of at least one subscriber of the at least one network.
15 . The non-transitory processor-readable storage medium of claim 13 , wherein the at least one integrated circuit comprises one or more of a subscriber identity module, a universal integrated circuit card and an embedded universal integrated circuit card.
16 . The non-transitory processor-readable storage medium of claim 13 , wherein an entity associated with the at least one edge device updates the at least one cryptographically attested digital document with the one or more of: (i) the at least one identifier of the at least one integrated circuit and (ii) the at least one identifier of the at least one network.
17 . The non-transitory processor-readable storage medium of claim 13 , wherein the one or more credentials of the at least one edge device comprise one or more keys.
18 . The non-transitory processor-readable storage medium of claim 17 , wherein the one or more keys comprise at least an asymmetric public key of a public-private key pair.
19 . The non-transitory processor-readable storage medium of claim 13 , wherein the at least one cryptographically attested digital document comprises an ownership voucher.
20 . The apparatus of claim 8 , wherein the at least one cryptographically attested digital document comprises an ownership voucher.