Wireless Network Trust Establishment Through Scalable Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in establishing trust among devices, particularly due to the difficulty in scaling remote attestation across various device types, software versions, and roaming scenarios, which can lead to compromised user equipments (UEs) launching attacks and spoofing device identities.

Innovation Solution

Implementing a security service device as a root of trust for attestation, providing scalable attestation across networks, and performing attestation in conjunction with authentication to reduce overhead and enhance trust establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote attestation is implemented across various device types and software versions, then trust establishment is improved, but device complexity and scaling difficulty increase

Engineering Contradiction:
Improvetrust establishmentVSAvoidscaling difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security service device is introduced as an intermediary between the wireless communication device and the network. This mediator handles the complex attestation verification process, receiving attestation information from devices, verifying it against security policies, and making authorization decisions. This transfers the complexity from individual devices to a centralized security service, enabling scalable trust establishment across diverse device types and software versions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive attestation verification is performed, then security against compromised UEs is improved, but attestation and verification overhead increases

Engineering Contradiction:
Improvesecurity against compromised UEsVSAvoidattestation and verification overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary attestation verification by checking whether attestation information satisfies predetermined appraisal conditions before full authentication. The security service device evaluates key characteristics and attributes in advance, making authorization decisions based on predefined security policies. This preliminary action reduces the overhead of comprehensive verification while maintaining security against compromised devices.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If attestation information is collected and verified, then trust establishment is improved, but information processing overhead increases

Engineering Contradiction:
Improvetrust establishmentVSAvoidinformation processing overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts and evaluates only the most critical characteristics and attributes from attestation information based on predetermined appraisal conditions. Rather than processing all available attestation data, the security service device identifies and verifies key security-relevant information, reducing information processing overhead while maintaining effective trust establishment.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250294361A1Trust establishment in wireless networks
Publication Date: 2025.09.18 QUALCOMM INC
  • US20250294361A1 patent drawing
  • US20250294361A1 patent drawing
  • US20250294361A1 patent drawing

AI summary

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a security service device may receive, from at least one of a device or a service, attestation information that includes verifiable information regarding a state of the device or a state of the service. The security service device may generate an attestation result indicating whether the attestation information satisfies an appraisal condition. The security service device may receive a request for the attestation result. The security service device may provide the attestation result in accordance with the request. Numerous other aspects are described.