M2M Service Subscription Resource Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In M2M communication systems, there is a need for improved access control to ensure that only authorized M2M entities can access specific resources, as current systems may inadvertently provide unintended privileges to M2M service providers.
Innovation Solution
A method and apparatus for authenticating requests in a wireless communication system, where an M2M device receives a request for a specific operation, searches for an M2M service subscription resource using security association credentials, and determines authorization using an access control policy resource, allowing or denying access based on the device's permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an M2M entity controls access rights to resources, then authorized entities can access resources, but unintended privileges may be provided to specific M2M entities
Solution Approach 1:
The patent segments access control into two distinct levels: service subscription level (controlling which services an M2M entity can access) and resource level (controlling specific operations on specific resources). This segmentation prevents unintended privileges by ensuring that access rights are granular and precisely defined at each level, rather than providing broad, potentially unintended access.
Solution Approach 2:
The patent implements local quality by allowing different access control policies to be applied to different resources and service subscriptions. Each resource can have its own access control policy that specifies exactly which M2M entities can perform which operations, ensuring that privileges are localized and precise rather than generalized.
2Productivity
If traditional authentication methods are used, then M2M entities can access services, but authentication efficiency is insufficient
Solution Approach 1:
The patent performs preliminary action by establishing service subscription relationships and associating M2M entity identifiers with service subscriptions in advance. During authentication, the system quickly retrieves pre-established service subscription information using the M2M entity identifier as a key, avoiding the need for complex real-time verification and thus improving authentication efficiency while maintaining security.
Data Source
AI summary
The present invention relates to a method for authorizing a specific operation of a specific resource in a wireless communication system, and comprises receiving, from a requesting M2M device, a request for a specific operation of a specific resource, the operation request including an identifier of the requesting M2M device and the identifier being associated with an M2M service subscription resource derived using a credential of the requesting M2M device; searching the M2M service subscription resource using the identifier, and determining whether the requesting M2M device is authorized for a type of the specific resource using the M2M service subscription resource.


