The certificate revocation lists at access points of a wireless access
network can be reduced. In one embodiment, an Internet Service Provider
("ISP") connected to the wireless access network can receive a
subscription request from a user terminal capable of accessing the ISP
using the wireless access network. When the ISP assigns a subscription
identifier to the user terminal, it also provides a service certificate
signed by a certificate authority including the subscription identifier.
In addition, the ISP also provides the user terminal one or more session
certificates to be used to access the wireless access network, where the
session certificates having a shorter validity period than the service
certificate.