Attribute-based credentials for resource access
Various aspects of the present disclosure relate to attribute-based credentials for resource access. An apparatus, such as a UE, generates one or more credentials comprising one or more first public keys and one or more attributes associated with a service request. The apparatus communicates a credential issuance request comprising at least a portion of the one or more credentials, and receives, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request.
1 . A user equipment (UE) for wireless communication, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the UE to:
generate a first set of credentials comprising one or more first public keys and one or more attributes associated with a service request;
communicate a credential issuance request comprising at least a portion of the first set of credentials;
receive, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request;
generate the one or more encrypted root keys and the one or more encrypted subscription identities; and
generate a second set of credentials to include the one or more encrypted root keys and the one or more encrypted subscription identities.
2 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to one or more of:
generate the one or more first public keys based at least in part on a number of the first set of credentials; or
generate the one or more first public keys based at least in part on a number of the one or more attributes to be bound to an instance of the one or more first public keys.
3 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to generate the one or more encrypted root keys and the one or more encrypted subscription identities using a second public key.
4 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to generate a third set of credentials to include at least one of one or more pseudonyms, a device identity associated with the UE, a network type associated with the service request, a network name associated with the service request, or revocation information associated with the first set of credentials.
5 . The UE of claim 4 , wherein the third set of credentials include proof information for a private key of the UE and a random number, the random number used to compute the proof information for the private key.
6 . The UE of claim 1 , wherein the one or more encrypted subscription identities comprise one or more encrypted subscription permanent identifiers (SUPIs).
7 . The UE of claim 1 , wherein the credential issuance request further comprises revocation information associated with the first set of credentials.
8 . The UE of claim 1 , wherein the first set of credentials do not include the one or more encrypted root keys or the one or more encrypted subscription identities.
9 . The UE of claim 1 , wherein the service request comprises a request for access to a wireless communication network.
10 . A processor for wireless communication, comprising:
at least one controller coupled with at least one memory and configured to cause the processor to:
generate a first set of credentials comprising one or more first public keys and one or more attributes associated with a service request for a user equipment (UE);
communicate a credential issuance request comprising at least a portion of the first set of credentials;
receive, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys, and one or more encrypted subscription identities associated with the service request;
generate the one or more encrypted root keys and the one or more encrypted subscription identities; and
generate a second set of credentials to include the one or more encrypted root keys and the one or more encrypted subscription identities.
11 . The processor of claim 10 , wherein the at least one controller is configured to cause the processor to generate a third set of credentials to include at least one of one or more pseudonyms, a device identity associated with the UE, a network type associated with the service request, a network name associated with the service request, or revocation information associated with the first set of credentials.
12 . The processor of claim 10 , wherein the credential issuance request further comprises revocation information associated with the first set of credentials.
13 . The processor of claim 10 , wherein the first set of credentials do not include the one or more encrypted root keys or the one or more encrypted subscription identities.
14 . A network equipment for wireless communication, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the network equipment to:
receive a key generation request associated with a service request by a user equipment (UE), the key generation request comprising one or more first public keys associated with the UE and one or more one or more second public keys;
generate a root key and a subscription identity associated with the service request;
encrypt the root key and the subscription identity using the one or more first public keys and one or more second public keys to generate an encrypted root key and an encrypted subscription identity;
communicate a key generation response comprising the encrypted root key and the encrypted subscription identity;
receive the encrypted root key and the encrypted subscription identity; and
receive one or more credentials to include the encrypted root key and the encrypted subscription identity.
15 . The network equipment of claim 14 , wherein the at least one processor is configured to cause the network equipment to one or more of:
separately encrypt the root key and the subscription identity using the one or more first public keys and one or more second public keys; or
encrypt the root key and the subscription identity together using the one or more first public keys and one or more second public keys.
16 . The network equipment of claim 14 , wherein the at least one processor is configured to cause the network equipment to sign the encrypted root key and the encrypted subscription identity with the one or more second public keys.
17 . The network equipment of claim 14 , wherein the key generation response further comprises revocation information for a credential associated with the service request.
18 . A method performed by a user equipment (UE), the method comprising:
generating a first set of credentials comprising one or more first public keys and one or more attributes associated with a service request;
communicating a credential issuance request comprising at least a portion of the first set of credentials;
receiving, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys, and one or more encrypted subscription identities associated with the service request;
generating the one or more encrypted root keys and the one or more encrypted subscription identities; and
generating a second set of credentials to include the one or more encrypted root keys and the one or more encrypted subscription identities.
19 . The method of claim 18 , further comprising:
generating the one or more first public keys based at least in part on a number of the first set of credentials; or
generating the one or more first public keys based at least in part on a number of the one or more attributes to be bound to an instance of the one or more first public keys.
20 . The method of claim 18 , further comprising:
generating the one or more encrypted root keys and the one or more encrypted subscription identities using a second public key.