Patent · US2026107144A1 · A1 · US
Authentication Procedures for Edge Computing in Roaming Deployment Scenarios
- (11) Publication number
- US2026107144A1
- (21) Application number
- 19/116,315
- (22) Filing date
- 2022-09-29
- (43) Publication date
- 2026-04-16
- (52) CPC
- H04W Wireless communication networks: 12/069, 36/0038, 84/042
- (54) Title
- Authentication Procedures for Edge Computing in Roaming Deployment Scenarios
- (57) Abstract
An edge configuration server (ECS) is deployed in a home public land mobile network (HPLMN) of a user equipment (UE). The ECS receives an authentication verification message comprising at least an authorization parameter from a first network function, an identifier of a client running on the UE and an identifier corresponding to a first credential, retrieves the first credential using the identifier corresponding to the first credential, verifies the authorization parameter using the first credential and the identifier of the client running on the UE and transmits a response to the authentication verification message to the first network function.
- Full text
- View on Google Patents
Claims (1)
- A method performed by an edge configuration server (ECS) deployed in a home public land mobile network (HPLMN) of a user equipment (UE), the method comprising: receiving an authentication verification message comprising at least an authorization parameter from a first network function, an identifier of a client running on the UE and an identifier corresponding to a first credential; retrieving the first credential using the identifier corresponding to the first credential; verifying the authorization parameter using the first credential and the identifier of the client running on the UE; and transmitting a response to the authentication verification message to the first network function. 2. The method of claim 1, further comprising: receiving, prior to receiving the authentication verification message, a credential update message from a second network function of the HPLMN, the credential update message comprising at least the identifier of the client running on the UE, the first credential and the identifier corresponding to the first credential. 3. The method of claim 2, wherein the second network function is an authentication server function (AUSF) that generates the first credential and the identifier corresponding to the first credential based on a second credential generated for a primary authentication procedure. 4. The method of claim 3, wherein the second credential is K AUSF. 5. The method of claim 1, wherein the first network function is a network exposure function (NEF) deployed in a visited public land mobile network (VPLMN). 6. The method of claim 1, further comprising: transmitting, in response to receiving the authentication verification message, a credential update request to the first network function, the credential update request comprising at least the identifier of the client running on the UE, the first credential and the identifier corresponding to the first credential. 7. The method of claim 6, wherein the first network function is an authentication server function (AUSF) deployed in the HPLMN of the UE that generates the first credential and the identifier corresponding to the first credential based on a second credential generated for a primary authentication procedure, wherein the second credential is K AUSF. 8. The method of claim 1, further comprising: receiving, prior to receiving the authentication verification message, a credential update message from the first network function of the HPLMN, the credential update message comprising at least the identifier of the client running on the UE, the first credential and the identifier corresponding to the first credential. 9. The method of claim 8, wherein the first network function is an authentication server function (AUSF) that generates the first credential and the identifier corresponding to the first credential based on a second credential generated for a primary authentication procedure. 10. The method of claim 9, wherein the second credential is K AUSF. 11. The method of claim 1, wherein the UE is configured to use a local breakout (LBO) roaming architecture to access the ECS. 12. The method of claim 1, wherein the UE is configured to use a home routed roaming architecture to access the ECS. 13. The method of claim 1, wherein the response to the authentication verification message comprises at least the first credential and the identifier corresponding to the first credential. 14. A method performed by a first network function deployed in a home public deployed in a home public land mobile network (HPLMN) of a user equipment (UE), the method comprising: receiving an authentication verification message comprising at least an authorization parameter from a second network function, an identifier of a client running on the UE and an identifier corresponding to a first credential; retrieving the first credential using the identifier corresponding to the first credential; verifying the authorization parameter using the first credential and the identifier of the client running on the UE; and transmitting a response to the authentication verification message to the second network function. 15. The method of claim 14, wherein the second network function is a network exposure function (NEF) deployed in a visited public land mobile network (VPLMN) of the UE. 16. The method of claim 14, further comprising: transmitting an authentication update comprising at least an authentication result derived based on verifying the authorization parameter to an edge configuration server (ECS) deployed in the HPLMN of the UE. 17. The method of claim 16, wherein the authentication update further comprises an identifier of a client running on the UE and the first credential. 18. The method of claim 16, wherein the UE configured to use a home routed roaming architecture to access the ECS. 19. The method of claim 14, wherein the response to the authentication verification message comprises at least the first credential and the identifier corresponding to the first credential. 20. A method performed by a user equipment (UE), comprising: transmitting an application registration request to an edge configuration server (ECS) of a visited public land mobile network (VPLMN) comprising at least an edge enabler client ID, an authorization parameter and an identifier for a first credential; and establishing a transport layer security (TLS) security tunnel based on the first credential.
Record as JSON
{
"publication_number": "US2026107144A1",
"country": "US",
"kind": "A1",
"title": "Authentication Procedures for Edge Computing in Roaming Deployment Scenarios",
"abstract": "An edge configuration server (ECS) is deployed in a home public land mobile network (HPLMN) of a user equipment (UE). The ECS receives an authentication verification message comprising at least an authorization parameter from a first network function, an identifier of a client running on the UE and an identifier corresponding to a first credential, retrieves the first credential using the identifier corresponding to the first credential, verifies the authorization parameter using the first credential and the identifier of the client running on the UE and transmits a response to the authentication verification message to the first network function.",
"claims": [
"1. A method performed by an edge configuration server (ECS) deployed in a home public land mobile network (HPLMN) of a user equipment (UE), the method comprising: receiving an authentication verification message comprising at least an authorization parameter from a first network function, an identifier of a client running on the UE and an identifier corresponding to a first credential; retrieving the first credential using the identifier corresponding to the first credential; verifying the authorization parameter using the first credential and the identifier of the client running on the UE; and transmitting a response to the authentication verification message to the first network function. 2. The method of claim 1, further comprising: receiving, prior to receiving the authentication verification message, a credential update message from a second network function of the HPLMN, the credential update message comprising at least the identifier of the client running on the UE, the first credential and the identifier corresponding to the first credential. 3. The method of claim 2, wherein the second network function is an authentication server function (AUSF) that generates the first credential and the identifier corresponding to the first credential based on a second credential generated for a primary authentication procedure. 4. The method of claim 3, wherein the second credential is K AUSF. 5. The method of claim 1, wherein the first network function is a network exposure function (NEF) deployed in a visited public land mobile network (VPLMN). 6. The method of claim 1, further comprising: transmitting, in response to receiving the authentication verification message, a credential update request to the first network function, the credential update request comprising at least the identifier of the client running on the UE, the first credential and the identifier corresponding to the first credential. 7. The method of claim 6, wherein the first network function is an authentication server function (AUSF) deployed in the HPLMN of the UE that generates the first credential and the identifier corresponding to the first credential based on a second credential generated for a primary authentication procedure, wherein the second credential is K AUSF. 8. The method of claim 1, further comprising: receiving, prior to receiving the authentication verification message, a credential update message from the first network function of the HPLMN, the credential update message comprising at least the identifier of the client running on the UE, the first credential and the identifier corresponding to the first credential. 9. The method of claim 8, wherein the first network function is an authentication server function (AUSF) that generates the first credential and the identifier corresponding to the first credential based on a second credential generated for a primary authentication procedure. 10. The method of claim 9, wherein the second credential is K AUSF. 11. The method of claim 1, wherein the UE is configured to use a local breakout (LBO) roaming architecture to access the ECS. 12. The method of claim 1, wherein the UE is configured to use a home routed roaming architecture to access the ECS. 13. The method of claim 1, wherein the response to the authentication verification message comprises at least the first credential and the identifier corresponding to the first credential. 14. A method performed by a first network function deployed in a home public deployed in a home public land mobile network (HPLMN) of a user equipment (UE), the method comprising: receiving an authentication verification message comprising at least an authorization parameter from a second network function, an identifier of a client running on the UE and an identifier corresponding to a first credential; retrieving the first credential using the identifier corresponding to the first credential; verifying the authorization parameter using the first credential and the identifier of the client running on the UE; and transmitting a response to the authentication verification message to the second network function. 15. The method of claim 14, wherein the second network function is a network exposure function (NEF) deployed in a visited public land mobile network (VPLMN) of the UE. 16. The method of claim 14, further comprising: transmitting an authentication update comprising at least an authentication result derived based on verifying the authorization parameter to an edge configuration server (ECS) deployed in the HPLMN of the UE. 17. The method of claim 16, wherein the authentication update further comprises an identifier of a client running on the UE and the first credential. 18. The method of claim 16, wherein the UE configured to use a home routed roaming architecture to access the ECS. 19. The method of claim 14, wherein the response to the authentication verification message comprises at least the first credential and the identifier corresponding to the first credential. 20. A method performed by a user equipment (UE), comprising: transmitting an application registration request to an edge configuration server (ECS) of a visited public land mobile network (VPLMN) comprising at least an edge enabler client ID, an authorization parameter and an identifier for a first credential; and establishing a transport layer security (TLS) security tunnel based on the first credential."
],
"cpc": [
"H04W 12/069",
"H04W 36/0038",
"H04W 84/042"
],
"filing_date": "2022-09-29",
"publication_date": "2026-04-16",
"application_number": "US-202219116315-A"
}
Record 8 of 5,000 in Patents full text (MLC-0201). Request the full dataset.