Attribute-Based Credentials for Wireless Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems lack solutions for enabling attribute-based credentials (ABCs) to facilitate access to wireless communication networks, particularly for UEs that are not subscribed to the network, and there are no defined processes for UEs to utilize ABCs for network registration and access.
Innovation Solution
UEs generate or receive credentials including encrypted root keys and subscription identities using public keys, which are signed by an issuer, allowing them to authenticate and access wireless communication networks without a subscription, using an ABC framework that includes entities like issuers, verifiers, and revocation authorities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional subscription-based access control is used, then network security and management are simplified, but access flexibility and user autonomy are reduced
Solution Approach 1:
The patent introduces an attribute-based credential system as an intermediary layer between users and network access control. Credentials issued by a trusted authority contain encrypted attributes that mediate the authentication process, allowing flexible access without direct subscription management complexity at the network side.
Solution Approach 2:
The system changes the access control parameters from traditional subscription-based models to attribute-based models. By encrypting attributes such as location, time, and service type within credentials, the system enables flexible access control while maintaining security, resolving the contradiction between adaptability and complexity.
2Adaptability or versatility
If attribute-based credentials are implemented for non-subscribed UEs, then access flexibility is improved, but authentication security and system reliability are challenged
Solution Approach 1:
The system performs preliminary action by having a trusted authority pre-issue credentials containing encrypted attributes before the UE attempts network access. This advance preparation ensures that when access is needed, the authentication can proceed securely without real-time trust establishment, thereby maintaining reliability while enabling flexibility.
Solution Approach 2:
The patent uses cryptographic copying by encrypting attributes within credentials that can be copied and presented by UEs. The encrypted attributes act as verified copies of user information that can be shared without revealing the underlying data, maintaining security while enabling flexible access for non-subscribed users.
3Measurement precision
If encrypted credentials with multiple attributes are generated, then access control precision is improved, but computational complexity and processing time are increased
Solution Approach 1:
The credential structure is segmented into multiple encrypted attributes (location, time, service type, etc.), each independently encrypted and verifiable. This segmentation allows the system to achieve precise access control by evaluating individual attributes without processing the entire credential set, reducing computational complexity while maintaining precision.
Solution Approach 2:
The system extracts only the necessary encrypted attributes from the credential for each specific access decision. Rather than processing all attributes, the network can selectively extract and verify only the relevant attributes needed for the current access request, thereby reducing computational overhead while maintaining precise access control where needed.
Data Source
AI summary
Various aspects of the present disclosure relate to attribute-based credentials for resource access. An apparatus, such as a UE, generates one or more credentials comprising one or more first public keys and one or more attributes associated with a service request. The apparatus communicates a credential issuance request comprising at least a portion of the one or more credentials, and receives, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request.


