M2M Service Subscription Resource Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In M2M communication systems, there is a need for improved access control to ensure that only authorized M2M entities can access specific resources, as current systems may inadvertently provide unintended privileges to M2M service providers.

Innovation Solution

A method and apparatus for authenticating requests in a wireless communication system, where an M2M device receives a request for a specific operation, searches for an M2M service subscription resource using security association credentials, and determines authorization using an access control policy resource, allowing or denying access based on the device's permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an M2M entity controls access rights to resources, then authorized entities can access resources, but unintended privileges may be provided to specific M2M entities

Engineering Contradiction:
Improveaccess control accuracyVSAvoidunintended privileges
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments access control into two distinct levels: service subscription level (controlling which services an M2M entity can access) and resource level (controlling specific operations on specific resources). This segmentation prevents unintended privileges by ensuring that access rights are granular and precisely defined at each level, rather than providing broad, potentially unintended access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different access control policies to be applied to different resources and service subscriptions. Each resource can have its own access control policy that specifies exactly which M2M entities can perform which operations, ensuring that privileges are localized and precise rather than generalized.

Inventive Principle:
Principle #3Local quality

2Productivity

If traditional authentication methods are used, then M2M entities can access services, but authentication efficiency is insufficient

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidaccess control security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary action by establishing service subscription relationships and associating M2M entity identifiers with service subscriptions in advance. During authentication, the system quickly retrieves pre-established service subscription information using the M2M entity identifier as a key, avoiding the need for complex real-time verification and thus improving authentication efficiency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10182351B2Method for service subscription resource-based authentication in wireless communication system
Publication Date: 2019.01.15 LG ELECTRONICS INC
  • US10182351B2 patent drawing
  • US10182351B2 patent drawing
  • US10182351B2 patent drawing

AI summary

The present invention relates to a method for authorizing a specific operation of a specific resource in a wireless communication system, and comprises receiving, from a requesting M2M device, a request for a specific operation of a specific resource, the operation request including an identifier of the requesting M2M device and the identifier being associated with an M2M service subscription resource derived using a credential of the requesting M2M device; searching the M2M service subscription resource using the identifier, and determining whether the requesting M2M device is authorized for a type of the specific resource using the M2M service subscription resource.