Network node device, communication system, and communication method
By introducing network node devices into the 5G system, authentication requests can be received and processed, and other nodes can be asked through secret information about the existence of user information, which solves the problem of users accessing services across borders, and realizes the processing of dynamic user information and system flexibility.
Patent Information
- Application Number
- CN202280101922.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-22
- Publication Date
- 2025-06-24
AI Technical Summary
In 5G systems, the information registered by users in mobile networks cannot be accessed by application servers in other countries, resulting in the inability to log in and receive services.
A network node device is provided that can receive an authentication request from a terminal access application server, and by generating secret information to inquire about the existence of specific information, and determine the destination of sending the authentication request.
It realizes processing dynamic user information in 5G systems, allowing users to access services across borders, and improves the flexibility and user experience of the system.
Smart Images

Figure CN120202694A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technology for ID cooperation. Background Art
[0002] In 3GPP (registered trademark) (3rd Generation Partnership Project), research on a wireless communication method called 5G or NR (New Radio) has been carried out in order to further increase system capacity, further increase data transmission speed, and further reduce latency in the wireless section (hereinafter, this wireless communication method will be referred to as "5G" or "NR"). In 5G, various wireless technologies have been studied to meet the requirements of achieving a throughput of 10 Gbps or more and a latency in the wireless section of 1 ms or less.
[0003] In NR, a network architecture including a 5GC (5G Core Network) corresponding to the EPC (Evolved Packet Core), which is the core network in the LTE (Long Term Evolution) network architecture, and an NG-RAN (Next Generation-Radio Access Network) corresponding to the E-UTRAN (Evolved Universal Terrestrial Radio Access Network), which is the RAN (Radio Access Network) in the LTE network architecture, has been studied (for example, Non-Patent Document 1).
[0004] In addition, for example, an architecture in which a Northbound interface between the NEF (Network Exposure Function) and the AF (Application Function) in a 5G system is constituted by CAPIF (Common API Framework) has been studied (for example, Non-Patent Document 2, Non-Patent Document 3, and Non-Patent Document 4).
[0005] In addition, a technology for ID cooperation that can uniformly manage ID information registered scattered by each user at each site has attracted attention. In recent IT technologies, OpenID (registered trademark) Connect is usually used in ID cooperation.
[0006] Prior Art Documents
[0007] Non - Patent Literature
[0008] Non - Patent Literature 1: 3GPP TS23.501 V17.6.0 (2022 - 09)
[0009] Non - Patent Literature 2: 3GPP TS23.222 V17.7.0 (2022 - 09)
[0010] Non - Patent Literature 3: 3GPP TS 33.122 V17.0.0 (2022 - 03)
[0011] Non - Patent Literature 4: 3GPP TR 23.700 - 95 V1.5.0 (2022 - 09) Summary of the Invention
[0012] Problems to be Solved by the Invention
[0013] In a 5G system, in the case where technologies such as OpenID (registered trademark) Connect for ID cooperation are envisaged to be introduced, it is envisaged to use user information registered in a mobile network in the actions for ID cooperation.
[0014] Here, when a user (assumed to be User A) in the mobile network of a certain country (assumed to be Country A) accesses an application server (= RP (Relying Party)) in another country (assumed to be Country B), it is envisaged that the application server sends an authentication request to the mobile network of Country B.
[0015] However, since the user information of User A does not exist in the mobile network of Country B, processing such as login authorization for User A cannot be performed. In this case, User A cannot log in to the application server and cannot receive services.
[0016] The present invention has been completed in view of the above problems, and its object is to provide a network node device that receives an authentication request related to a specific user and a technology for grasping a mobile network in which information related to the specific user exists.
[0017] Means for Solving the Problems
[0018] According to the disclosed technology, a network node device is provided, which includes: a receiving unit that receives an authentication request from an application server that has received an access from a terminal;
[0019] a sending unit that uses a secret information generated based on specific information included in the authentication request to send an inquiry about the presence or absence of the specific information to another network node device; and
[0020] a control unit that determines a transmission destination of the authentication request based on a response to the inquiry.
[0021] Advantages of the Invention
[0022] According to the disclosed technology, a network node device for receiving an authentication request related to a specific user is provided, for a technology of a mobile network for grasping information related to the specific user. Brief Description of the Drawings
[0023] Figure 1 It is a diagram for explaining an example of a communication system.
[0024] Figure 2 It is a diagram for explaining an example of a communication system in a roaming environment.
[0025] Figure 3 It is a diagram showing an example of an API call.
[0026] Figure 4 It is a diagram showing an example of a communication system in an embodiment of the present invention.
[0027] Figure 5 It is a timing diagram of the first embodiment.
[0028] Figure 6 It is a timing diagram of the first embodiment.
[0029] Figure 7 It is a timing diagram of the first embodiment.
[0030] Figure 8 It is a timing diagram of the second embodiment.
[0031] Figure 9 It is a structural diagram of the third embodiment.
[0032] Figure 10 It is a timing diagram of the third embodiment.
[0033] Figure 11 It is a diagram showing an example of the functional structure of the authorization device 40 in an embodiment of the present invention.
[0034] Figure 12 It is a diagram showing an example of the functional structure of the data storage device 70 in an embodiment of the present invention.
[0035] Figure 13 It is a diagram showing an example of the hardware structure of the device in an embodiment of the present invention.
[0036] Figure 14 It is a diagram showing an example of the structure of the vehicle in an embodiment of the present invention. Detailed Description of the Invention
[0037] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In addition, the embodiments described below are merely examples, and the embodiments to which the present invention is applied are not limited to the following embodiments.
[0038] In the operation of the wireless communication system according to the embodiment of the present invention, existing technologies are appropriately used. Such existing technologies are, for example, existing LTE or existing NR (5G), but are not limited to existing LTE or existing NR.
[0039] In addition, in the present embodiment, as a mechanism for ID cooperation, OIDC (OpenID (registered trademark) Connect) is used. However, the use of OIDC is an example, and a mechanism other than OIDC may also be used as the mechanism for ID cooperation.
[0040] In addition, in the embodiment of the present invention, "configured" such as radio parameters may be pre-configured with predetermined values, or may be configured with radio parameters notified from a network node device or a terminal 20.
[0041] Figure 1 It is a diagram for explaining an example of a communication system. As Figure 1 shown, the communication system is composed of a UE as a terminal 20 and a plurality of network node devices. Hereinafter, it is assumed that one network node device corresponds to each function, but multiple functions may be implemented by one network node device, or one function may be implemented by multiple network node devices. In addition, "connection" described below may be a logical connection or a physical connection.
[0042] RAN (Radio Access Network) is a network node device having a radio access function, which may include a base station and is connected to a UE, an AMF (Access and Mobility Management Function), and a UPF (User plane function). The AMF is a network node device having functions such as a terminal with a RAN interface, a NAS (Non-Access Stratum) terminal, registration management, connection management, reachability management, and mobility management. The UPF is a network node device having functions such as an external PDU (Protocol Data Unit) session point for interconnecting with a DN (Data Network), routing and forwarding of packets, and QoS (Quality of Service) processing of the user plane. The UPF and the DN constitute a network slice. In the wireless communication network according to the embodiment of the present invention, a plurality of network slices are constructed.
[0043] The AMF is connected to the UE, RAN, SMF (Session Management function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (Network Repository Function), UDM (Unified Data Management), UDR (Unified Data Repository), AUSF (Authentication Server Function), PCF (Policy Control Function), and AF (Application Function). The AMF, SMF, NSSF, NEF, NRF, UDM, UDR, AUSF, PCF, and AF are interface-based on each service and are network node devices interconnected via Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nudr, Nausf, Npcf, and Naf.
[0044] The SMF is a network node device with functions such as session management, IP (Internet Protocol) address allocation and management for the UE, DHCP (Dynamic Host Configuration Protocol) function, ARP (Address Resolution Protocol) proxy, and roaming function. The NEF is a network node device with the function of notifying other NFs (Network Functions) of capabilities and events. The NSSF is a network node device with functions such as selecting the network slice to which the UE is connected, determining the permitted NSSAI (Network Slice Selection Assistance Information), determining the configured NSSAI, and determining the set of AMFs to which the UE is connected. The PCF is a network node device with the function of performing policy control of the network. The AF is a network node device with the function of controlling the application server. The NRF is a network node device with the function of discovering NF instances that provide services. The UDM is a network node device that manages subscriber data and authentication data, etc. Dynamic information corresponding to the connection status of the terminal 20, etc. is also stored (managed) in the UDM. The UDM is connected to the UDR (User Data Repository) that holds the data.
[0045] Figure 2 It is a diagram for explaining an example of a communication system in a roaming environment. As Figure 2 shown, the network consists of a UE as the terminal 20 and multiple network node devices. The SEPP is a non-transparent proxy for filtering control plane messages between PLMNs (Public Land Mobile Networks). Figure 2 The vSEPP shown is the SEPP in the visited network, and the hSEPP is the SEPP in the home network.
[0046] As Figure 2 shown, the UE is in a roaming environment connected to the RAN and the AMF in the VPLMN (Visited PLMN). The VPLMN and the HPLMN (Home PLMN) are connected via the vSEPP and the hSEPP. The UE can communicate with the UDM of the HPLMN via the AMF of the VPLMN, for example.
[0047] The operations in this embodiment can be carried out by Figure 1 、 Figure 2 any of the structures. Additionally, it can also be in Figure 1 、 Figure 2The operations in this embodiment are performed in a structure other than the shown structure. That is, it is assumed that the authorization device 40, user information disclosure device 50, data storage device 70, etc., described later are network node devices in 5GS, but this assumption is not limited thereto. The authorization device 40, user information disclosure device 50, etc. can also be devices in a communication system other than 5GS.
[0048] In the above-mentioned NEF, the CAPIF (Common API Framework) architecture can be applied to implement an API (Application Programming Interface) that can be called from the AF. The CAPIF architecture provides a mechanism to support the operation of service APIs. For example, it enables the API call initiator (invoker) to discover the service APIs provided by the API provider (provider) and perform communication using these service APIs.
[0049] In addition, the application server 60 of the API call initiator described below (hereinafter referred to as the application server 60) can also be configured in the above-mentioned AF, and the API providing function (AEF) can be configured in the NEF, but this is not limited thereto. The application server 60 and AEF can also be configured in any network node device respectively. In addition, the application server 60 can also be configured in a certain terminal or a certain base station. The application server 60 can also be referred to as an API call initiator (invoker).
[0050] In addition, the resource owner can be a network node device, a terminal 20, a base station, or a device other than these. In this embodiment, it is assumed that the terminal 20 is the resource owner.
[0051] Figure 3 This is a diagram showing an example of an API call. APIs are opened to the outside in the core network of 3GPP (registered trademark), and APIs can be called from a third-party application server 60 to network node devices.
[0052] As Figure 3 shown, the application of the API call initiator is registered with the CAPIF core device 30 in advance from the application server 60 using the CAPIF-API. In the CAPIF core device 30, the application is authenticated and authorized. In addition, as Figure 3 shown, the service API is opened to the authenticated and authorized application through the API providing function (API Exposing Function (API opening function), also recorded as AEF) 91, and the application of the API call initiator can utilize the functions of the API by calling this API.
[0053] The APF (API Publishing Function) 92 has a function of publishing the service API information of the API provider to the CAPIF core device 30. The AMF (API Management Function) 91 has various management functions associated with API calls.
[0054] In addition, by extending CAPIF, the terminal 20 (resource owner) can authorize an API call to the application server 60 via the authorization device 40. For example, the OAuth2.0 mechanism can be used to achieve authorization.
[0055] Hereinafter, the first embodiment, the second embodiment, and the third embodiment will be described. The first embodiment is the basic embodiment. The second embodiment and the third embodiment are respectively modified examples of the first embodiment. However, the second embodiment and the third embodiment can also be implemented independently of the first embodiment. In addition, the first embodiment, the second embodiment, and the third embodiment can be combined and implemented.
[0056] In addition, in the following description, unless otherwise specified, a "user" is a subject (typically a person) using a terminal, and a "terminal" is a device such as a smartphone. However, sometimes the "terminal" is also referred to as a "user".
[0057] (Regarding the problem of the first embodiment)
[0058] As described above, ID collaboration technology that can uniformly manage the ID information registered by users scattered by each site is attracting attention. In recent IT technologies, OpenID (registered trademark) Connect is usually used in ID collaboration.
[0059] However, in the 5GS (5G system), which is a communication system assumed to be used in this embodiment, neither ID collaboration nor OpenID (registered trademark) Connect is introduced.
[0060] Instead of introducing ID collaboration into 5GS, it is also possible to consider implementing ID collaboration at the application layer. However, in this case, in the user information collaboration that constitutes ID collaboration, it is easy to only process static user information.
[0061] On the other hand, by providing ID collaboration in 5GS, it is also possible to process dynamic user information that can be obtained from 5GS. As a result, the user can receive services that are more in line with their preferences or status from the logged-in application server 60.
[0062] Since OAuth2.0 is introduced in 5GS, by slightly expanding the CAPIF authorization function (authorization device 40) and the CAPIF core function (CAPIF core device 30), the authorization endpoint function of the OIDC (Open ID (registered trademark) Connect) OP (Open ID (registered trademark) Provider) and the token endpoint function of the OIDC OP can be respectively included. However, there is no function corresponding to the user information endpoint function of the OIDC OP in 5GS. Therefore, in the prior art, there is a problem that OIDC-based ID cooperation cannot be appropriately performed.
[0063] (Outline of the First Embodiment)
[0064] In this embodiment, regarding the communication system (presumed to be 5GS here), OIDC is introduced into the communication system so that ID cooperation including cooperation of dynamic user information can be provided.
[0065] Specifically, the authorization endpoint function of the OIDC OP is included in the CAPIF authorization function (referred to as the authorization device 40).
[0066] In addition, an interface with the authorization device 40 is set in the CAPIF core function (referred to as the CAPIF core device 30) so that an ID token can be generated. Therefore, the CAPIF core device 30 can execute the token endpoint function of the OIDC OP.
[0067] Furthermore, in the communication system, a user information disclosure device 50 as a "user information disclosure function" is newly introduced so that the user information endpoint function of the OIDC OP can be executed.
[0068] In OIDC, user information is sent from the OIDC OP to the OIDC RP (Relying Party). In this embodiment, the user information is set to information that gives characteristics to the identifier according to each user's identifier (that is, multiple identifiers corresponding to each SUPI (Subscription Permanent Identifier)). However, the user information is not limited to this, and user information independent of the identifier can also be used.
[0069] In this embodiment, the user information is any one or any combination or all of static information, dynamic information, and a URI for obtaining dynamic information. In the following embodiments, user information including these three is used.
[0070] The user information disclosure device 50 needs to obtain (generate) the disclosed user information. The method for obtaining the user information can be any method, but in this embodiment, the UDR (equivalent to the data storage device 70 described later) stores the information required for the user information disclosure device 50 to generate the user information.
[0071] More specifically, through offline input or using Nnef_UserInfoProvision, the following information (1) to (3) is stored in the corresponding area of the UDR.
[0072] (1) Static information
[0073] (2) Dynamic information to be obtained (information indicating the dynamic information to be obtained)
[0074] (3) URI sent to the OIDC RP for obtaining the dynamic information
[0075] Regarding the above (2), the user information disclosure device 50 can, for example, use the SUPI to access the UDM (equivalent to the data management device 80 described later), obtain the information indicating the current state of the user (for example, AMF registration information, etc.), and include this information (or a part of this information) as the dynamic information in the user information.
[0076] (System structure)
[0077] Figure 4 Shows a structural example of the communication system in the first embodiment. Figure 4 The structure shown basically also applies to the second embodiment and the third embodiment. However, in the third embodiment, it is envisaged that for each MNO (Mobile Network Operator), there is Figure 4 the structure shown. In addition, the MNO can also be referred to as "Mobile Network".
[0078] As Figure 4 shown, the communication system in this embodiment has a terminal 20 (the user's terminal 20), a CAPIF core device 30, an authorization device 40, a user information disclosure device 50, an application server 60, an information server 65, a data storage device 70, a data management device 80, and a NEF 90. In Figure 4 , each device can at least communicate with other devices connected by the lines shown in the figure.
[0079] In addition, in the present embodiment (the first to third embodiments), it is assumed that the data storage device 70 corresponds to the UDR and the data management device 80 corresponds to the UDM, but it is not limited thereto. Additionally, the "data storage device 70 and the data management device 80" may also be constituted by one device (which may also be referred to as a data storage device or a network node device). Furthermore, the "CAPIF core device 30 and the authorization device 40" may be one device. This one device may be referred to as a core device, an authorization device, or a network node device.
[0080] In addition, in the present embodiment, it is assumed that the terminal 20 has a browser, the device communicating with the terminal 20 has a Web server function, and the terminal 20 sends information as an HTTP request to other devices and receives information as an HTTP response from other devices. However, such an assumption is an example and is not limited to such an assumption.
[0081] In addition, in the following description, communication between the application server 60 and the authorization device 40 is performed through redirection via a terminal (browser), but this is an example. The system may also be configured to directly communicate between the application server 60 and the authorization device 40.
[0082] (First Embodiment: Setting of Dynamic Information)
[0083] Refer to Figure 5 A timing example for setting the above dynamic information will be described. Here, as an example, a case of setting via the NEF 90 is shown.
[0084] In the data storage device 70, through offline setting at the time of user subscription, "SUPI = a, [identifier: user information] = [a1: telephone number, email address]" is stored. This means that the SUPI of the user's terminal 20 is a, the identifier corresponding to SUPI = a is a1, and the user information corresponding to a1 is "telephone number, email address".
[0085] In S11 (step 11), the terminal 20 sends a user information addition request to the NEF 90. The user information addition request is, for example, an Nnef_UserInfoProvision request. The user information addition request here includes the following information.
[0086] "GPSI = A, additional information ([identifier: user information] = [a2: telephone number, email address, "in-use access confirmation", "in-use RAT confirmation", access confirmation URI, RAT confirmation URI])"
[0087] The above information is for adding the above user information with the identifier a2.
[0088] The NEF 90 makes an inquiry to the data management device 80 (S12), obtains the SUPI = a corresponding to the GPSI = A (S13), and thereby transforms the GPSI = A into the SUPI = a.
[0089] In S14, the NEF 90 writes the above additional information to the data of SUPI = a in the data storage device 70.
[0090] (First Embodiment: OIDC Process)
[0091] Refer to Figure 6 、 Figure 7 the flowchart of to explain the OIDC process in the first embodiment.
[0092] In S101, the terminal 20 accesses the application server 60 (= RP) and makes a login request. Since the application server 60 cannot directly process this login, the subsequent OIDC process is then executed.
[0093] In S102 - S103, the application server 60 sends an authentication request to the authorization device 40 via the browser of the terminal 20 (redirect).
[0094] In S104, the authorization device 40 authenticates the terminal 20 (or the user) via the browser in the terminal 20 or through a mechanism within 5GS, and obtains authorization from the user regarding "the application server 60 accessing user information". In this process, for example, an input screen is displayed through the browser in the terminal 20, and the user inputs information indicating authorization for "the application server 60 to access user information" from the input screen. The information indicating authorization (authorization promise information) is sent to the authorization device 40. For example, at this time, the user inputs the user identifier = a2 from the input screen. That is, in S104, the authorization device 40 obtains the user identifier = a2.
[0095] In addition, the above content of "authorization" is an example. "Authorization" can be authorization from the user regarding "the application server 60 using a specific API", or authorization for specific processing of the application server 60 other than these. The content of "authorization" is the same in the second and third embodiments.
[0096] In S105 - S106, the authorization device 40 sends an authorization code indicating that the user has authorized access to the user information to the application server 60 via the browser in the terminal 20.
[0097] In S107, the application server 60 prompts (sends) an authorization code to the CAPIF core device 30. In S108 to S109, the CAPIF core device 30 accesses the authorization device 40 to obtain information related to authentication (e.g., authentication execution time and authentication method). In S109, the authorization device 40 may notify the CAPIF core device 30 that the user identifier = a2.
[0098] In S110, the CAPIF core device 30 generates an ID token based on the information obtained from the authorization device 40. In addition, the CAPIF core device 30 generates an access token.
[0099] In Figure 7 S111, the CAPIF core device 30 sends the ID token and the access token to the application server 60. In S112, the application server 60 sends a user information request to the user information disclosure device 50. The user information request includes the user identifier = a2 and the access token. Additionally, the application server 60 may obtain the user identifier = a2 in S105 and S106, may obtain the user identifier = a2 in S111, or may obtain the user identifier = a2 at other timings. For example, the ID token in S111 may include the user identifier = a2.
[0100] In S113 to S114, the user information disclosure device 50 accesses the data storage device 70, obtains the information corresponding to the user identifier = a2, and confirms that the SUPI = a corresponds to the user identifier = a2.
[0101] The user information disclosure device 50 detects "in - use access confirmation" and "in - use RAT confirmation" in the information. Therefore, in S115 to S116, it makes an inquiry to the data management device 80 using the SUPI = a and obtains the in - use access mode of the terminal 20 (user) and "3GPP access" and "NR" as the in - use RAT.
[0102] In S117, the user information disclosure device 50 generates "phone number, email address, 'in - use access = 3GPP access', 'in - use RAT = NR', access confirmation URI, RAT confirmation URI" as user information and sends the user information to the application server 60.
[0103] In S118, the application server 60 allows the login of the user identifier = a2 based on the ID token received from the CAPIF core device 30 and provides services to the user (terminal 20) based on the user information.
[0104] Here, it is assumed that both the access confirmation URI and the RAT confirmation URI are URIs in the information server 65. In addition, the information server 65 can also be the data management device 80. In this case, the access confirmation URI and the RAT confirmation URI can also be URIs disclosed by the NEF 90. In S119, the application server 60 monitors the access confirmation URI and the RAT confirmation URI (i.e., the information server 65), and prepares for the status change of the terminal 20 corresponding to the user identifier = a2.
[0105] Through the technology of the first embodiment described above, OIDC can be implemented in 5GS. In addition, as user information in OIDC, dynamic information can be processed, so that the service can flexibly adapt to the situation of the terminal 20.
[0106] In addition, in the above example, as the dynamic information obtained by the communication system, the information of the accessed service in use and the RAT in use are obtained, but these are examples and are not limited thereto. For example, by using the positioning mechanism in the communication system, the location information of the terminal 20 can also be obtained as dynamic information.
[0107] (Problems of the Second Embodiment)
[0108] Next, the second embodiment will be described. First, the problems of the second embodiment will be described. In OIDC, the authorization endpoint of the OP finely controls the operation through the prompt parameter (prompt parameter) when authenticating the end user.
[0109] That is, there is the following description in the OIDC specification (OpenID Connect Core 1.0 incorporating errata set1). The following authorization server is equivalent to the authorization device 40. In addition, "none" can also be referred to as "no".
[0110] "○ The authorization server must attempt to authenticate the end user in the following cases.
[0111] · The end user has not been authenticated yet.
[0112] · The authentication request includes a prompt parameter with the value "login". In this case, even if the end user has been authenticated, the authorization server needs to re-authenticate the end user.
[0113] ○ In the following cases, the authorization server shall not interact with the end user.
[0114] · The authentication request includes a prompt parameter with the value "none". In this case, if the end user has not been authenticated or has not been authenticated silently, the authorization server must return an error.
[0115] In the authorization device 40, appropriately handling the case where "the authentication request includes a prompt parameter with the value 'none'" is important for making the user feel smooth transfer between applications.
[0116] In the second embodiment, the processing in the case where "the authentication request includes a prompt parameter with the value 'none'" will be mainly described. In addition, hereinafter, the authentication request where "the authentication request includes a prompt parameter with the value 'none'" may sometimes be referred to as a "silent authentication request".
[0117] (Summary of the second embodiment)
[0118] In the second embodiment, when the authorization device 40 receives a silent authentication request, it confirms that the terminal 20 (or the user, or both the terminal 20 and the user) is authenticated based on the result of 5GS authentication / the result of FIDO authentication. In addition, the authorization device 40 confirms whether to allow the terminal 20 (user) to automatically log in. When these confirmations are obtained, the authorization device 40 issues an authorization code to the application server 60.
[0119] In the second embodiment, during the registration process of registering with the communication system (here 5GS), the terminal 20 registers information on the terminal authenticator capability (such as FIDO) with the data management device 80. Additionally, FIDO is an abbreviation for Fast Identity Online. In FIDO authentication, high security can be achieved by performing authentication of the person in the local environment of the terminal 20 (such as biometric authentication) and authentication based on the public key authentication method.
[0120] In the second embodiment, in the case where "the authentication request includes a prompt parameter with the value 'none'" and "the user (terminal 20) has not been authenticated (at the application layer)", the authorization device 40 performs the following processing in the authentication phase and the login authorization phase. Additionally, the condition in the case where "the user (terminal 20) has not been authenticated (at the application layer)" may not be used.
[0121] [Authentication phase]
[0122] The authorization device 40 first confirms with the data management device 80 whether there is AMF registration information. The storage of the AMF registration information of the terminal 20 in the data management device 80 means that the terminal 20 is authenticated (authentication successful) in the communication system.
[0123] After that, as a confirmation of the result of authentication (e.g., biometric authentication) performed between the user and the terminal 20, the authorization device 40 performs the following (i) and (ii).
[0124] (i) When it is detected from the information on the terminal authenticator capability in the AMF registration information that the terminal 20 has the terminal authenticator capability, access the FIDO server. When there is stored custody information indicating that authentication has been performed, it is determined that the terminal 20 (and the user) is authenticated.
[0125] (ii) When there is no information on the terminal authenticator capability in the AMF registration information, or when it is detected from this information that the terminal 20 does not have the terminal authenticator capability, it is determined that the terminal 20 is authenticated.
[0126] [Login Authorization Phase]
[0127] The authorization device 40 confirms that there is information indicating permission for automatic login in the subscriber information of the data management device 80.
[0128] After the confirmation in the above authentication phase and login authorization phase, the authorization device 40 does not perform re - authentication at the application layer, but sends an authorization code to the application server 60. In addition, it is also possible not to perform the confirmation in the login authorization phase among the confirmation in the above authentication phase and the confirmation in the login authorization phase.
[0129] In addition, regarding the above (ii), when there is no terminal authenticator capability of the terminal 20, the authorization device 40 may also determine that the terminal 20 (or the user) is not authenticated and not issue an authorization code.
[0130] (Processing Steps of the Second Embodiment)
[0131] <Terminal Registration>
[0132] During its own registration process, the terminal 20 includes information on the terminal authenticator capability in the registration request. The AMF includes this information on the terminal authenticator capability when registering the terminal 20 with the data management device 80. That is, through the terminal registration process, information on the terminal authenticator capability of the terminal 20 is stored in the data management device 80. It is assumed that when the terminal 20 has the terminal authenticator capability, FIDO authentication in the terminal 20 can be performed, and when it does not have the terminal authenticator capability, FIDO authentication in the terminal 20 cannot be performed.
[0133] <OIDC Process>
[0134] Next, refer to Figure 8The timing diagram below illustrates the OIDC process. In the following timing, the FIDO server 100 is used. The FIDO server 100 can be a network node device in a communication system or a device outside the communication system. The FIDO server 100 can also be referred to as an authentication server.
[0135] In S201, the terminal 20 accesses the application server 60 (= RP) and makes a login request. Since the application server 60 cannot directly process this login, the subsequent OIDC process is then executed.
[0136] In S202 - S203, the application server 60 sends an authentication request to the authorization device 40 via the browser of the terminal 20. The authentication request includes the following parameters:
[0137] (a) The client_id parameter: has the identifier of the application server 60 as its value.
[0138] (b) The prompt parameter: the value "none".
[0139] (c) The login_hint parameter: has the user's email address as its value.
[0140] In addition, as described below, the above "user's email address" is used as the identification information of the terminal 20 (or the user). The "user's email address" is an example, and information other than the "user's email address" can also be used.
[0141] In S204 - S205, the authorization device 40 uses the user's email address to query the data storage device 70 and obtains SUPI = b.
[0142] In S206 - S207, the authorization device 40 obtains the AMF registration information (specific registration information) corresponding to SUPI = b from the data management device 80 and confirms that there is information about the terminal authenticator capabilities of the terminal 20 in this AMF registration information. If there is no AMF registration information corresponding to SUPI = b, an error is returned to the application server 60, for example.
[0143] In S208 - S209, the authorization device 40 accesses the FIDO server 100 and obtains information indicating the existence of authenticated custody information about the terminal 20. If there is no authenticated custody information, an error is returned to the application server 60, for example.
[0144] In S210 to S211, the authorization device 40 obtains the CAPIF usage setting information of the subscriber information with SUPI = b from the data management device 80, and in this CAPIF usage setting information, it is confirmed that the identifier of the application server 60 is included in the "allowed automatic login target client_id parameter". That is, it is confirmed that automatic login to the application server 60 is allowed.
[0145] In S212 to S213, the authorization device 40 does not perform authentication in the application layer, but sends an authorization code to the application server 60. The authentication in the application layer is, for example, the authentication and authorization process of S104 described in the first embodiment. The subsequent processing is the same as the processing from S107 in the first embodiment.
[0146] According to the second embodiment described above, when the authentication request includes a prompt parameter with a value of "none", an authorization code can be issued quickly without returning an error.
[0147] (System Structure in the Third Embodiment)
[0148] Next, the third embodiment will be described. In either the first embodiment or the second embodiment, it is assumed that the system structure and the operation of the system are implemented for each MNO. In addition, it is assumed that there is one or more MNOs in each region (for example, country).
[0149] In the third embodiment, MNO#A exists in country A, MNO#B exists in country B, and MNO#C exists in country C. In addition, the user's terminal 20A is in the network of MNO#A in country A, and the application server 60B that provides the application service to the terminal 20A exists in country B.
[0150] In this case, as Figure 9 shown, in addition to the above-mentioned terminal 20A and application server 60B, an authorization device 40, a CAPIF core device 30, a user information disclosure device 50, a data storage device 70, a data management device 80, etc. are also provided in each country (each MNO).
[0151] In addition, the authorization device 40 provided by MNO#A is labeled as authorization device 40A, the authorization device 40 provided by MNO#B is labeled as authorization device 40B, and the authorization device 40 provided by MNO#C is labeled as authorization device 40C. The same applies to other devices.
[0152] In each MNO, the operations of either the first embodiment or the second embodiment can also be implemented. Furthermore, in the third embodiment, as will be described later, an operation for solving the following problems can be performed.
[0153] (Problems in the Third Embodiment)
[0154] As Figure 9 shown, when the user's terminal 20A is under MNO#A in Country A and the application server 60B (RP) is in Country B, when performing the operations of the first or second embodiment, consider that the application server 60B sends an authentication request to the terminal 20A ( Figure 6 S102 of Figure 8 and S202 of
[0155] If the application server 60B only receives an IP packet requesting login from the terminal 20A, without performing special processing, it is impossible to know which country the terminal 20A is in. In addition, although the application server 60B in Country B goes through the terminal 20A under MNO#A in Country A, it is unnatural to trust MNO#A in Country A and send an authentication request to it. That is, as the application server 60B in Country B, if it sends an authentication request to an MNO, it will naturally send it to MNO#B in Country B.
[0156] Assume that when the application server 60B sends an authentication request related to the terminal 20A to the authorization device 40B of MNO#B, in subsequent processing, the authorization device 40B or the user information disclosure device 50B accesses the data storage device 70B to obtain the user information of the terminal 20A ( Figure 7 S113 and S114 of Figure 8 and S204 and S205 of
[0157] However, it is considered that the user information of the terminal A of MNO#A in Country A does not exist in the data storage device 70B of MNO#B (e.g., SUPI = b). When the user information of the terminal A does not exist in the data storage device 70B, the application server 60B cannot perform login permission for the terminal 20A, etc., and the terminal 20A cannot use the services of the application server 60B. In this case, the application server 60B may, for example, determine that it is best to use the OIDC service of an operator with global services.
[0158] In addition, in the solution to the above problem, from the perspective of personal information protection, the user information stored in the "data storage device 70 behind the user information disclosure device 50" should not be shared among MNOs. In addition, for an MNO that has not received an authentication request and for which there is no target user (target terminal), which user accessed which MNO should be kept secret.
[0159] (Summary of the Third Embodiment)
[0160] In order to solve the above problems, in the third embodiment, when the authorization device 40 of the MNO that has received the authentication request does not find the user (terminal 20) that is the object of authentication authorization within the mobile network of the MNO, it derives the hash value of the login_hint parameter and uses this hash value to query other collaborating MNOs.
[0161] The above-mentioned authorization device 40 that first receives the authentication request redirects the authentication request to the authorization device 40 of the MNO that has found the target user. Thereafter, in this MNO, the authentication authorization process continues.
[0162] (Processing steps of the third embodiment)
[0163] Hereinafter, the processing steps in the third embodiment will be described with reference to Figure 10 the timing diagram. As a prerequisite for the Figure 10 operation, MNO#A, MNO#B, and MNO#C collaborate with each other regarding OIDC.
[0164] Specifically, the authorization device 40 of each MNO has a function of querying whether there is user information using secret information in the network node devices (such as data storage device 70) of other MNOs. In addition, the network node device (such as data storage device 70) of each MNO has a function of confirming whether there is user information in response to the query of whether there is user information from the authorization device 40 of other MNOs and replying the confirmation result to the query source.
[0165] In the Figure 10 example, it is assumed that the user information of terminal 20A exists in MNO#A. However, other MNOs do not know that the user information of terminal 20A exists in MNO#A. In addition, the fact that the user information of terminal 20A exists in MNO#A is just an example. When the user information of terminal 20A exists in an MNO other than MNO#A, the operation can be performed in the same manner.
[0166] When the user information of terminal 20A exists in MNO#A, for example, through offline setting at the time of user subscription, "SUPI = a, [identifier: user information] = [a1: phone number, email address]" is stored in data storage device 70A.
[0167] In Figure 10 S301, the terminal 20A under MNO#A in country A accesses the application server 60B (= RP) in country B and makes a login request. Since the application server 60B cannot directly process this login, the subsequent OIDC process is executed.
[0168] In S302 - S303, the application server 60B sends an authentication request to the authorization device 40B of MNO#B via the browser of the terminal 20A. The authentication request includes a login_hint parameter. The value of the login_hint parameter is set to the email address of the user (terminal 20A) here.
[0169] In addition, in this embodiment, the login_hint parameter is used for the subsequent interrogation, but using the login_hint parameter for interrogation is just an example. Any information can be used for interrogation as long as it is the information included in the authentication request received from the application server 60B and can be used to confirm the existence of user information.
[0170] In S304, the authorization device 40B interrogates the data storage device 70B behind the user information disclosure device 50B in MNO#B using the value of the login_hint parameter. That is, the authorization device 40B asks the data storage device 70B whether there is an email address of the terminal 20A. In addition, since the interrogation here is a process within the same MNO, it is not necessary to use a hash value, but a hash value can also be used.
[0171] In this example, since there is no email address of the terminal 20A in the data storage device 70B, in S305, the data storage device 70B returns a response indicating no information to the authorization device 40B.
[0172] Assume that the authorization device 40B pre - maintains the interrogation destination (such as the address of the data storage device 70 of other mutually cooperative MNOs) when receiving a response indicating no information within its own MNO#B.
[0173] In S306, the authorization device 40B generates a hash value of the value of the login_hint parameter and uses this hash value to send an interrogation about the existence of information to the data storage device 70C of the mutually cooperative MNO#C. In addition, the hash value is an example of secret information. Any information can be used as secret information as long as it can be generated based on the value of the login_hint parameter and the original value cannot be known only through this information.
[0174] The data storage device 70C that receives the above interrogation, for example, generates hash values of each user information (here, email addresses) it holds, compares the hash values with the hash value included in the interrogation, and thereby determines whether there is user information with the same hash value as the hash value included in the interrogation. In this example, since there is no email address of the terminal 20A in the data storage device 70C, it is determined that there is no user information with the same hash value as the hash value included in the interrogation.
[0175] Therefore, in S307, the data storage device 70C returns a response indicating no information to the authorization device 40B.
[0176] Next, in S308, the authorization device 40B uses the hash value of the value of the login_hint parameter to send an inquiry about the presence or absence of information to the data storage device 70A of the cooperating MNO#A.
[0177] The data storage device 70A, for example, generates the hash value of each user information (here, the email address) it holds, and compares this hash value with the hash value included in the inquiry, thereby determining whether there is user information with the same hash value as the hash value included in the inquiry. In this example, the email address of the terminal 20A exists in the data storage device 70A.
[0178] Therefore, in S309, the data storage device 70A returns a response indicating there is information to the authorization device 40B. Thus, the authorization device 40B knows that the user information of the terminal 20A exists in the network of MNO#A.
[0179] Next, in S310 - S311, the authorization device 40B sends the authentication request received in S303 to the authorization device 40A of MNO#A.
[0180] Specifically, in this example, the authorization device 40B receives the authentication request as an HTTP request in S303. In S310, the authorization device 40B responds to the terminal 20A (browser) through an HTTP response for redirecting to the authorization device 40A of MNO#A, thereby sending the authentication request. The terminal 20A sends this authentication request to the authorization device 40A according to this redirection instruction.
[0181] The processing after S311 is, for example, the same as that of Figure 6 S104 - Figure 7 S119 in the first embodiment. However, here, Figure 6 , Figure 7 the application server 60 shown is the application server 60B, and other devices are devices in MNO#A.
[0182] In addition, the processing after S311 can also be the same as that of Figure 8 S204 and later in the second embodiment. In this case, Figure 8 the application server 60 shown is the application server 60B, and other devices are devices in MNO#A.
[0183] According to the third embodiment described above, it is possible to keep the user information registered in a certain MNO confidential from other MNOs, and the authorization device 40 of a certain MNO can know the presence or absence of user information in other MNOs. Thus, the user (terminal 20) can utilize the services of the application server 60 in a region outside the region (country, etc.) of the MNO where the user is located under ID cooperation.
[0184] In addition, in the third embodiment, the authentication device 40 that fails to find the user information in its own MNO queries the data storage device 70 of other MNOs, but this is just an example.
[0185] The authentication device 40 that fails to find the user information in its own MNO may also query the authorization device 40 of other MNOs. In this case, in the Figure 10 scenario described, the authorization device 40B that receives the no-information response in S305 queries the authorization device 40C of MNO#C using the hash value. The received authorization device 40C queries the data storage device 70C using the hash value, and the data storage device 70C returns the no-information response to the authorization device 40C, and the authorization device 40C returns the no-information response to the authorization device 40B.
[0186] Then, the authorization device 40B queries the authorization device 40A of MNO#A using the hash value. The received authorization device 40A queries the data storage device 70A using the hash value, and the data storage device 70A returns the yes-information response to the authorization device 40A, and the authorization device 40A returns the yes-information response to the authorization device 40B.
[0187] (Device Structure)
[0188] Next, a functional structure example of the authorization device 40 and the data storage device 70 that implement the processing and operations described above will be described.
[0189] <Authorization Device 40>
[0190] Figure 11 is a diagram showing an example of the functional structure of the authorization device 40. As Figure 11 shown, the authorization device 40 has a transmission unit 110, a reception unit 120, a setting unit 130, and a control unit 140. Figure 11 The functional structure shown is just an example. As long as the operations of the embodiments of the present invention can be implemented, the functional division and the names of the functional units can be arbitrary. In addition, Figure 4 each of the network node devices shown also has the Figure 11 structure shown.
[0191] The transmitting unit 110 includes a function of generating information to be transmitted to the terminal 20 or other network node devices and transmitting the information via wired or wireless means. The receiving unit 120 receives various information transmitted from the terminal 20 or other network node devices.
[0192] The setting unit 130 stores various setting information in the storage device and reads it from the storage device as needed.
[0193] The control unit 140 controls the entire device. The functional unit related to information transmission in the control unit 140 may be included in the transmitting unit 110, and the functional unit related to information reception in the control unit 140 may also be included in the receiving unit 120.
[0194] <Data storage device 70>
[0195] Figure 12 is a diagram showing an example of the functional structure of the data storage device 70. As Figure 12 shown, the data storage device 70 has a transmitting unit 210, a receiving unit 220, a setting unit 230, and a control unit 240. Figure 12 The functional structure shown is only an example. As long as the actions of the embodiments of the present invention can be implemented, the functional division and the names of the functional units can be arbitrary.
[0196] The transmitting unit 210 includes a function of generating information to be transmitted to the terminal 20 or other network node devices and transmitting the information via wired or wireless means. The receiving unit 220 receives various information transmitted from the terminal 20 or other network node devices.
[0197] The setting unit 230 stores various setting information in the storage device and reads it from the storage device as needed.
[0198] The control unit 240 controls the entire device. The functional unit related to information transmission in the control unit 240 may be included in the transmitting unit 210, and the functional unit related to information reception in the control unit 240 may also be included in the receiving unit 220.
[0199] According to the present embodiment, at least the following supplementary notes 1 to 3 are disclosed.
[0200] <Supplementary note 1>
[0201] (Supplementary note item 1)
[0202] A user information disclosure device, comprising: a receiving unit that receives a user information request including a user identifier from an application server authorized to perform a specific process;
[0203] a control unit that obtains information corresponding to the user identifier from a data storage device in a communication system; and
[0204] A sending unit that sends user information generated based on the information to the application server.
[0205] (Supplementary Note Item 2)
[0206] The user information disclosure device according to Supplementary Note Item 1, wherein the user information sent to the application server includes information on an access destination for monitoring the status of a terminal corresponding to the user identifier.
[0207] (Supplementary Note Item 3)
[0208] The user information disclosure device according to Supplementary Note Item 1 or 2, wherein the control unit obtains the dynamic information from a data management device that manages the dynamic information of the terminal, and includes the dynamic information in the user information.
[0209] (Supplementary Note Item 4)
[0210] The user information disclosure device according to Supplementary Note Item 3, wherein when the control unit detects the presence of specific information in the information obtained from the data storage device, the control unit accesses the data management device to obtain the dynamic information.
[0211] (Supplementary Note Item 5)
[0212] A communication system comprising: the user information disclosure device according to any one of Supplementary Note Items 1 to 4, and an authorization device that executes a process for authorizing the specific process for the application server.
[0213] (Supplementary Note Item 6)
[0214] A user information disclosure method executed by a user information disclosure device, comprising the following steps:
[0215] Receiving a user information request including a user identifier from an application server authorized to perform a specific process;
[0216] Obtaining information corresponding to the user identifier from a data storage device in a communication system; and
[0217] Sending user information generated based on the information to the application server.
[0218] According to any one of Supplementary Note Items 1 to 6, a technology is provided that can provide dynamic information to an application server in a mechanism for ID cooperation. According to Supplementary Note Item 2, the application server can continue to obtain the user's dynamic information after the user logs in. According to Supplementary Note Item 3, the application server can obtain the user's dynamic information when the user logs in. According to Supplementary Note Item 4, dynamic information can be obtained only when needed.
[0219] <Supplementary Note 2>
[0220] (Supplementary Note Item 1)
[0221] An authorization device, comprising:
[0222] A receiving unit that receives an authentication request from an application server that has received an access from a terminal;
[0223] A control unit that, when the authentication request includes a specific parameter, confirms whether specific registration information related to the terminal is stored in a network node device of a communication system used in the terminal, and determines whether the terminal is authenticated based on the confirmation result; and
[0224] A sending unit that, when the control unit determines that the terminal is at least authenticated, sends an authorization code to the application server.
[0225] (Supplementary Note Item 2)
[0226] The authorization device according to Supplementary Note Item 1, when the specific registration information is stored in the network node device, the control unit confirms whether the terminal has the terminal authenticator ability according to the specific registration information,
[0227] When the terminal has the terminal authenticator ability and there is custody information indicating that the terminal has been authenticated in the authentication server, it is determined that the terminal has been authenticated.
[0228] (Supplementary Note Item 3)
[0229] The authorization device according to Supplementary Note Item 1 or 2, the control unit confirms whether automatic login is allowed based on the subscriber information of the user of the terminal stored in the network node device,
[0230] When the control unit determines that the terminal is authenticated and it is confirmed that automatic login is allowed, the sending unit sends the authorization code to the application server.
[0231] (Supplementary Note Item 4)
[0232] The authorization device according to any one of Supplementary Note Items 1 to 3, wherein the specific parameter is a prompt parameter having a value of none.
[0233] (Supplementary Note Item 5)
[0234] A communication system, comprising the authorization device according to any one of Supplementary Note Items 1 to 4, and a user information disclosure device that sends user information to the application server that has received the authorization code from the authorization device.
[0235] (Supplementary Note Item 6)
[0236] An authorization method executed by an authorization device, wherein the authorization method has the following steps:
[0237] Receiving an authentication request from an application server that has received an access from a terminal;
[0238] In the case where a specific parameter is included in the authentication request, confirming whether specific registration information related to the terminal is stored in a network node device of a communication system used by the terminal, and determining whether the terminal is authenticated based on the confirmation result; and
[0239] In the case where it is at least determined that the terminal is authenticated, sending an authorization code to the application server.
[0240] According to any one of supplementary note items 1 to 6, a technique for appropriately processing in the case where an authorization device receives an authentication request including a specific parameter is provided. According to supplementary note item 2, appropriate processing corresponding to the presence or absence of a terminal authenticator capability can be performed. According to supplementary note item 3, appropriate processing corresponding to whether automatic login is allowed can be performed. According to supplementary note item 4, a specific parameter can be determined.
[0241] <Supplementary Note 3>
[0242] (Supplementary Note Item 1)
[0243] A network node device, which includes:
[0244] A receiving unit that receives an authentication request from an application server that has received an access from a terminal;
[0245] A sending unit that sends an inquiry about the presence or absence of the specific information to another network node device using a secret information generated based on the specific information included in the authentication request; and
[0246] A control unit that determines a sending destination of the authentication request based on a response to the inquiry.
[0247] (Supplementary Note Item 2)
[0248] The network node device according to supplementary note item 1, wherein a mobile network including the network node device is different from a mobile network including the other network node device.
[0249] (Supplementary Note Item 3)
[0250] A network node device, which includes:
[0251] A receiving unit that receives, from another network node device that has received an authentication request, an inquiry regarding the presence or absence of specific information including secret information, the secret information being generated based on the specific information included in the authentication request;
[0252] A control unit that uses the secret information to confirm the presence or absence of the specific information; and
[0253] A transmitting unit that transmits the result of the confirmation to the other network node device.
[0254] (Supplementary Note Item 4)
[0255] A communication system including a first network node device and a second network node device, wherein
[0256] the first network node device includes:
[0257] A receiving unit that receives an authentication request from an application server that has received an access from a terminal;
[0258] A transmitting unit that transmits, to the second network node device, an inquiry regarding the presence or absence of the specific information using secret information generated based on the specific information included in the authentication request; and
[0259] A control unit that determines the transmission destination of the authentication request based on a response to the inquiry,
[0260] the second network node device includes:
[0261] A receiving unit that receives the inquiry from the first network node device;
[0262] A control unit that uses the secret information to confirm the presence or absence of the specific information; and
[0263] A transmitting unit that transmits the result of the confirmation to the first network node device as the response.
[0264] (Supplementary Note Item 5)
[0265] A communication method performed by a network node device, the communication method including the steps of:
[0266] Receiving an authentication request from an application server that has received an access from a terminal;
[0267] Transmitting, to another network node device, an inquiry regarding the presence or absence of the specific information using secret information generated based on the specific information included in the authentication request; and
[0268] Determining the transmission destination of the authentication request based on a response to the inquiry.
[0269] According to any one of Supplementary Note Items 1 to 5, a network node device that receives an authentication request related to a specific user can grasp a mobile network in which information related to the specific user exists. According to Supplementary Note Item 2, for example, even when a terminal of an MNO in a certain country accesses an application server existing in another country, it is possible to use the service provided by the application server in cooperation with the ID.
[0270] (Hardware Structure)
[0271] The block diagrams used in the description of the above embodiment ( Figures 11 - 12 ) represent modules in terms of functions. These functional blocks (structural parts) are implemented by any combination of at least one of hardware and software. In addition, there is no particular limitation on the implementation method of each functional block. That is, each functional block can be implemented using a single device physically or logically combined, or two or more physically or logically separated devices can be directly or indirectly (e.g., using wired, wireless, etc.) connected and these multiple devices can be used for implementation. The functional block can also be implemented by combining software in the above single device or the above multiple devices.
[0272] Functions include judgment, decision-making, determination, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, solution, selection, selection, establishment, comparison, assumption, expectation, regarded as, broadcasting, notification, communication, forwarding, configuration, reconfiguration, allocation (allocating, mapping), assignment, etc., but are not limited to these. For example, a functional block (structural part) that enables transmission to function is called a transmitting unit or a transmitter. In short, as described above, there is no particular limitation on the implementation method.
[0273] For example, the base station 10, the terminal 20, etc. in an embodiment of the present disclosure can also function as a computer that performs the processing of the wireless communication method of the present disclosure. Figure 13 FIG. is an example of the hardware structure of the authorization device 40 and the data storage device 70 showing an embodiment of the present disclosure. The above authorization device 40 and data storage device 70 can also be configured to physically include a computer device such as a processor 1001, a storage device 1002, an auxiliary storage device 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, etc. In addition, network node devices other than the authorization device 40 and the data storage device 70 also haveFigure 13 The structure shown
[0274] In addition, in the following description, the term "device" may be replaced with "circuit", "equipment (device)", "unit", etc. The hardware structures of the base station 10 and the terminal 20 may be configured to include one or more of the devices shown in the figures, or may be configured not to include some of the devices.
[0275] Each function in the authorization device 40 and the data storage device 70 is implemented by the following method: a predetermined software (program) is read into hardware such as the processor 1001 and the storage device 1002, so that the processor 1001 performs operations and controls at least one of the communication of the communication device 1004 or the reading and writing of data in the storage device 1002 and the auxiliary storage device 1003.
[0276] The processor 1001, for example, operates an operating system to control the entire computer. The processor 1001 may also be composed of a central processing unit (CPU: Central Processing Unit) including an interface with peripheral devices, a control device, an arithmetic device, registers, etc. For example, the above control unit 140, control unit 240, etc. may also be implemented by the processor 1001.
[0277] In addition, the processor 1001 reads a program (program code), a software module, or data, etc. from at least one of the auxiliary storage device 1003 and the communication device 1004 into the storage device 1002, and performs various processes accordingly. As the program, a program that causes a computer to execute at least a part of the operations described in the above embodiments is used. For example, Figure 11 The control unit 140 of the authorization device 40 shown may also be implemented by a control program stored in the storage device 1002 and operating in the processor 1001. In addition, for example, Figure 12 The control unit 240 of the data storage device 70 shown may also be implemented by a control program stored in the storage device 1002 and operating in the processor 1001. Although it has been described that the above various processes are executed by one processor 1001, the above various processes may also be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may also be implemented by one or more chips. In addition, the program may also be sent from a network via a telecommunication line.
[0278] The storage device 1002 is a computer-readable recording medium, which may be constituted by at least one of, for example, a ROM (Read Only Memory), an EPROM (Erasable Programmable ROM), an EEPROM (Electrically Erasable Programmable ROM), a RAM (Random Access Memory), etc. The storage device 1002 may also be referred to as a register, a cache, a main memory (main storage device), etc. The storage device 1002 can store programs (program codes), software modules, etc. that can be executed to implement the communication method according to an embodiment of the present disclosure.
[0279] The auxiliary storage device 1003 is a computer-readable recording medium, which may be constituted by at least one of, for example, optical discs such as CD-ROMs (Compact Disc ROMs), hard disk drives, floppy disks, magneto-optical discs (e.g., compact discs, digital versatile discs, Blu-ray (registered trademark) discs, smart cards, flash memories (e.g., cards, sticks, key drives (Key drive)), Floppy (registered trademark) disks, magnetic stripes, etc. The above storage media may be, for example, databases, servers, and other appropriate media including at least one of the storage device 1002 and the auxiliary storage device 1003.
[0280] The communication device 1004 is hardware (a transceiver device) for communicating between computers via at least one of a wired network and a wireless network, and may also be referred to as a network device, a network controller, a network card, a communication module, etc., for example. The communication device 1004 may also be configured to include, for example, a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc. to implement at least one of frequency division duplex (FDD: Frequency Division Duplex) and time division duplex (TDD: Time Division Duplex). For example, a transceiver antenna, an amplifier unit, a transceiver unit, a transmission path interface, etc. may also be implemented by the communication device 1004. The transceiver unit may also be physically or logically separately implemented by a transmission unit and a reception unit.
[0281] The input device 1005 is an input device (e.g., a keyboard, a mouse, a microphone, a switch, a button, a sensor, etc.) that accepts input from the outside. The output device 1006 is an output device (e.g., a display, a speaker, an LED lamp, etc.) that performs output to the outside. In addition, the input device 1005 and the output device 1006 may also be integrally formed (e.g., a touch panel).
[0282] In addition, devices such as the processor 1001 and the storage device 1002 are connected by a bus 1007 for communicating information. The bus 1007 may be constituted by a single bus or may be constituted by different buses between devices.
[0283] In addition, the authorization device 40 and the data storage device 70 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a PLD (Programmable Logic Device), and an FPGA (Field Programmable Gate Array), or a part or all of the functional blocks may be implemented by this hardware. For example, the processor 1001 may also be implemented using at least one of these hardwares.
[0284] In addition, the vehicle 2001 may include the authorization device 40 or the data storage device 70. Figure 14 A structural example of the vehicle 2001 is shown. As Figure 14 shown, the vehicle 2001 has a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a gearshift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021 to 2029, an information service unit 2012, and a communication module 2013. The authorization device 40 or the data storage device 70 in each form / embodiment described in the present disclosure may be applied to a communication device mounted on the vehicle 2001, and may also be applied to the communication module 2013, for example.
[0285] The drive unit 2002 is constituted by, for example, an engine, a motor, or a hybrid of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also referred to as a steering disk) and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel operated by the user.
[0286] The electronic control unit 2010 is constituted by a microprocessor 2031, a memory (ROM, RAM) 2032, and a communication port (IO port) 2033. Signals from various sensors 2021 to 2029 provided in the vehicle 2001 are input to the electronic control unit 2010. The electronic control unit 2010 may also be referred to as an ECU (Electronic Control Unit).
[0287] As signals from various sensors 2021 to 2029, there are current signals from the current sensor 2021 that monitors the current of the motor, rotational speed signals of the front and rear wheels obtained by the rotational speed sensor 2022, air pressure signals of the front and rear wheels obtained by the air pressure sensor 2023, vehicle speed signals obtained by the vehicle speed sensor 2024, acceleration signals obtained by the acceleration sensor 2025, the stepping amount signal of the accelerator pedal obtained by the accelerator pedal sensor 2029, the stepping amount signal of the brake pedal obtained by the brake pedal sensor 2026, the operation signal of the shift lever obtained by the shift lever sensor 2027, detection signals for detecting obstacles, vehicles, pedestrians, etc. obtained by the object detection sensor 2028, and so on.
[0288] The information service unit 2012 is composed of various devices such as a car navigation system, an audio system, speakers, a television, a radio, etc. for providing (outputting) various information such as driving information, traffic information, and entertainment information, and one or more ECUs that control these devices. The information service unit 2012 uses the information obtained from external devices via the communication module 2013, etc., to provide various multimedia information and multimedia services to the passengers of the vehicle 2001. The information service unit 2012 may include input devices (such as keyboards, mice, microphones, switches, buttons, sensors, touch panels, etc.) that accept inputs from the outside, and may also include output devices (such as displays, speakers, LED lights, touch panels, etc.) that implement outputs to the outside.
[0289] The driving assistance system unit 2030 is composed of various devices such as millimeter-wave radars, LiDAR (Light Detection and Ranging), cameras, locators for positioning (such as GNSS, etc.), map information (such as high-precision (HD) maps, autonomous vehicle (AV) maps, etc.), gyroscopic systems (such as IMU (Inertial Measurement Unit), INS (Inertial Navigation System), etc.), AI (Artificial Intelligence) chips, AI processors, etc. for providing functions to prevent accidents in advance or reduce the driving load of the driver, and one or more ECUs that control these devices. In addition, the driving assistance system unit 2030 transmits and receives various information via the communication module 2013 to implement driving assistance functions or autonomous driving functions.
[0290] The communication module 2013 can communicate with the microprocessor 2031 and the components of the vehicle 2001 via a communication port. For example, the communication module 2013 exchanges data with the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, gear lever 2006, front wheels 2007, rear wheels 2008, axles 2009, the microprocessor 2031 and the memory (ROM, RAM) 2032 within the electronic control unit 2010, and the sensors 2021 - 2029 of the vehicle 2001 via the communication port 2033.
[0291] The communication module 2013 can be controlled by the microprocessor 2031 of the electronic control unit 2010 and is a communication device capable of communicating with external devices. For example, it exchanges various information with external devices via wireless communication. The communication module 2013 can be located inside or outside the electronic control unit 2010. External devices can be, for example, base stations, mobile stations, etc.
[0292] The communication module 2013 can also transmit at least one of the signals from the various sensors 2021 - 2028 input to the electronic control unit 2010, the information obtained based on these signals, and the information based on the input from the external (user) obtained via the information service unit 2012 to an external device via wireless communication. The electronic control unit 2010, the various sensors 2021 - 2028, the information service unit 2012, etc. can also be referred to as input units that receive input. For example, the PUSCH transmitted by the communication module 2013 can include the information based on the above input.
[0293] The communication module 2013 receives various information (traffic information, signal information, vehicle - to - vehicle information, etc.) sent from an external device and displays it on the information service unit 2012 of the vehicle 2001. The information service unit 2012 can also be referred to as an output unit that outputs information (for example, outputs information to devices such as a display and a speaker based on the PDSCH received by the communication module 2013 (or the data / information decoded from the PDSCH)). In addition, the communication module 2013 stores the various information received from the external device in the memory 2032 that can be utilized by the microprocessor 2031. The microprocessor 2031 can also control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, gear lever 2006, front wheels 2007, rear wheels 2008, axles 2009, sensors 2021 - 2029, etc. of the vehicle 2001 based on the information stored in the memory 2032.
[0294] (Supplement of the Embodiment)
[0295] As described above, the embodiments of the present invention have been described. However, the disclosed invention is not limited to such embodiments, and those skilled in the art should understand various variations, modifications, alternatives, substitutions, etc. Specific numerical examples have been used to facilitate the understanding of the invention, but these numerical values are only examples as long as not specifically indicated, and any appropriate arbitrary values can also be used. The item distinctions in the above description are not essential for the present invention. The matters described in two or more items can be combined as needed, or the matters described in one item can be applied to the matters described in another item (as long as there is no contradiction). The boundaries of the functional units or processing units in the functional block diagram do not necessarily correspond to the boundaries of physical components. The actions of multiple functional units can be performed by one physical component, or the action of one functional unit can be performed by multiple physical components. Regarding the processing steps described in the embodiments, the order of processing can be swapped without contradiction. For the sake of facilitating the description of processing, the authorization device 40 and the data storage device 70 are illustrated using functional block diagrams, but such devices can also be implemented by hardware, software, or a combination thereof. The software that operates according to the embodiments of the present invention through the processor of the base station 10 and the software that operates according to the embodiments of the present invention through the processor of the terminal 20 can also be stored in a random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, register, hard disk drive (HDD), removable disk, CD-ROM, database, server, and other appropriate arbitrary storage media, respectively.
[0296] In addition, the notification of information is not limited to the forms / embodiments described in the present disclosure, and other methods can also be used. For example, the notification of information can be implemented through physical layer signaling (e.g., DCI (Downlink Control Information), UCI (Uplink Control Information)), upper layer signaling (e.g., RRC (Radio Resource Control) signaling, MAC (Medium Access Control) signaling, broadcast information (MIB (Master Information Block), SIB (System Information Block)), other signals, or a combination thereof. In addition, RRC signaling can also be referred to as an RRC message. For example, it can be an RRC connection setup message, an RRC connection reconfiguration message, etc.
[0297] Each form / embodiment described in the present disclosure can also be applied to systems using at least one of LTE (Long Term Evolution), LTE-A (LTE-Advanced), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), 6G (6th generation mobile communication system), xG (xth generation mobile communication system) (x is an integer or a decimal, for example), FRA (Future Radio Access), NR (new Radio), New radio access (NX), Future generation radio access (FX), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, UWB (Ultra-WideBand), Bluetooth (registered trademark), other suitable systems, and next-generation systems extended, modified, created, or defined based on these systems. In addition, multiple systems can be combined (for example, a combination of at least one of LTE and LTE-A and 5G) and applied.
[0298] For the processing steps, timings, flows, etc. of each form / embodiment described in this specification, the order can be swapped without contradiction. For example, for the methods described in the present disclosure, the elements of various steps are presented in an exemplary order, but are not limited to the specific order presented.
[0299] In this specification, specific actions performed by the base station 10 are sometimes also performed by its upper node according to circumstances. In a network composed of one or more network nodes including the base station 10, it is obvious that various actions performed for communicating with the terminal 20 can be performed by at least one of the base station 10 and other network nodes other than the base station 10 (for example, MME or S-GW is considered, but not limited to these). In the above, the case where there is one other network node other than the base station 10 is illustrated, but the other network nodes can also be a combination of multiple other network nodes (for example, MME and S-GW).
[0300] The information or signals etc. described in this disclosure can be output from a higher layer (or a lower layer) to a lower layer (or a higher layer). It can also be input or output via multiple network nodes.
[0301] The information etc. input or output can be stored in a specific location (for example, a memory), or can be managed using a management table. The information etc. input or output can be rewritten, updated or appended. The information etc. output can also be deleted. The information etc. input can also be sent to other devices.
[0302] The determination in this disclosure can be made by a value represented by 1 bit (0 or 1), can also be made by a Boolean value (true or false), and can also be made by a numerical comparison (for example, comparison with a predetermined value).
[0303] For software, no matter it is called software, firmware, middleware, microcode, hardware description language, or by other names, it should be widely interpreted as referring to commands, command sets, code, code segments, program code, programs, subroutines, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, processes, functions, etc.
[0304] In addition, software, commands, information, etc. can also be transmitted and received via a transmission medium. For example, when using at least one of wired technologies (coaxial cables, fiber optic cables, twisted pairs, digital subscriber lines (DSL), etc.) and wireless technologies (infrared rays, microwaves, etc.) to send software from a web page, a server, or other remote sources, at least one of these wired technologies and wireless technologies is included in the definition of the transmission medium.
[0305] The information, signals, etc. described in the present disclosure can also be represented using any one of a variety of different technologies. For example, the data, commands, instructions (command), information, signals, bits, symbols, chips, etc. that may be involved in the overall description above can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination of these.
[0306] In addition, for the terms described in the present disclosure and the terms required to understand the present disclosure, they can also be replaced with terms having the same or similar meanings. For example, at least one of a channel and a symbol can also be a signal (signaling). In addition, a signal can also be a message. In addition, a component carrier (CC: Component Carrier) can also be referred to as a carrier frequency, a cell, a frequency carrier, etc.
[0307] The terms "system" and "network" used in the present disclosure can be used interchangeably.
[0308] In addition, the information, parameters, etc. described in the present disclosure can be represented using absolute values, relative values with respect to a predetermined value, or other corresponding information. For example, wireless resources can also be indicated using indexes.
[0309] The names used for the above parameters are non-restrictive names in any aspect. Furthermore, the mathematical expressions, etc. using these parameters are sometimes different from the content explicitly disclosed in the present disclosure. Various channels (e.g., PUCCH, PDCCH, etc.) and information elements can be identified by all appropriate names, so the various names assigned to these various channels and information elements are non-restrictive names in any aspect.
[0310] In the present disclosure, the terms "base station (BS: Base Station)", "radio base station", "base station", "fixed station", "NodeB", "eNodeB (eNB)", "gNodeB (gNB)", "access point", "transmission point", "reception point", "transmission / reception point", "cell", "sector", "cell group", "carrier", "component carrier", etc. can be used interchangeably. Sometimes, terms such as macro cell, small cell, femto cell, pico cell, etc. are also used to refer to the base station.
[0311] A base station can accommodate one or more (e.g., 3) cells. When the base station accommodates multiple cells, the overall coverage area of the base station can be divided into multiple smaller areas, and each smaller area can also provide communication services through a base station subsystem (e.g., a small indoor base station RRH: Remote Radio Head). Terms such as "cell" or "sector" refer to part or all of the coverage area of at least one of the base station and the base station subsystem that provides communication services within the coverage range.
[0312] In the present disclosure, the base station sending information to the terminal can also be replaced by the base station instructing the terminal to perform control / actions based on the information.
[0313] In the present disclosure, terms such as "mobile station (MS)", "user terminal", "terminal (UE: User Equipment)", and "terminal" can be used interchangeably.
[0314] For a mobile station, those skilled in the art sometimes also refer to it using the following terms: subscriber station, mobile unit, subscriber unit, radio unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other appropriate terms.
[0315] At least one of the base station and the mobile station may also be referred to as a transmitting device, a receiving device, a communication device, etc. Additionally, at least one of the base station and the mobile station may be a device mounted on a moving body, the moving body itself, etc. The moving body refers to an object that can move, and the moving speed can be arbitrary. Additionally, of course, the case where the moving body stops is also included. The moving body includes, for example, vehicles, transport vehicles, automobiles, motorcycles, bicycles, connected cars, shovelcars, bulldozers, wheel loaders, dump trucks, forklifts, trains, buses, rear cars, rickshaws, ships and other watercraft, airplanes, rockets, artificial satellites, drones (registered trademark), multicopters, quadcopters, balloons, and objects mounted on them, and is not limited thereto. Additionally, the moving body may be a moving body that autonomously travels based on an operation instruction. It can be a means of transportation (e.g., a car, an airplane, etc.), a moving body that moves in an unmanned manner (e.g., a drone, an autonomous vehicle, etc.), or a robot (humanoid or non-humanoid). Additionally, at least one of the base station and the mobile station also includes a device that does not necessarily move during a communication operation. For example, at least one of the base station and the mobile station may be an IoT (Internet of Things) device such as a sensor.
[0316] Furthermore, the base station in the present disclosure may also be replaced by a terminal. For example, a structure in which the communication between the base station and the terminal is replaced with the communication between multiple terminals 20 (e.g., it may also be referred to as D2D (Device-to-Device), V2X (Vehicle-to-Everything), etc.) can also apply each form / embodiment of the present disclosure. In this case, it may also be configured such that the terminal 20 has the functions of the above-described base station 10. Additionally, terms such as "uplink" and "downlink" may also be replaced with terms corresponding to the communication between terminals (e.g., "side"). For example, the uplink channel, the downlink channel, etc. may also be replaced with side channels.
[0317] Similarly, the terminal in the present disclosure may also be replaced by a base station. In this case, it may also be configured such that the base station has the functions of the above-described terminal.
[0318] The terms "determining" and "deciding" as used in this disclosure sometimes also encompass a variety of actions. For example, "determining" and "deciding" may include considering matters that have been judged, calculated, computed, processed, derived, investigated, looked up, searched, inquired (e.g., searched in a table, database, or other data structure), or ascertained as matters that have been "determined" or "decided". In addition, "determining" and "deciding" may include considering matters that have been received (e.g., receiving information), transmitted (e.g., transmitting information), input, output, accessed (e.g., accessing data in a memory) as matters that have been "determined" or "decided". Further, "determining" and "deciding" may include considering matters that have been resolved, selected, chosen, established, compared, etc. as matters that have been "determined" or "decided". That is, "determining" and "deciding" may include considering certain actions as matters that have been "determined" or "decided". In addition, "determining (deciding)" may also be replaced by "assuming", "expecting", "considering", etc.
[0319] The terms "connected" and "coupled" or any variations of these terms are intended to represent all direct or indirect connections or couplings between two or more elements, and may include cases where there is one or more intermediate elements between the two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be a physical coupling or connection, a logical coupling or connection, or a combination of these. For example, "access" may also be used to replace "connected". In the context of this disclosure, it can be considered that two elements are "connected" or "coupled" to each other using at least one of one or more wires, cables, and printed electrical connections, and, as some non-limiting and non-inclusive examples, using electromagnetic energy having wavelengths in the radio frequency range, microwave region, and optical (including both visible and invisible) region to "connect" or "couple" to each other.
[0320] The reference signal can be abbreviated as RS (Reference Signal), or can be called Pilot according to the applied standard.
[0321] In the present disclosure, the description such as "based on" does not mean "only based on" unless otherwise clearly described. In other words, the description "based on" means both "only based on" and "at least based on".
[0322] Any reference to the elements using the terms such as "first", "second", etc. used in the present disclosure does not entirely limit the number or order of these elements. These terms may be used in the present disclosure as a convenient method for distinguishing between two or more elements. Therefore, the reference to the first element and the second element does not mean that only two elements can be taken or that the first element must precede the second element in any form.
[0323] The "unit" in the structure of each of the above devices can also be replaced with "section", "circuit", "equipment", etc.
[0324] When the terms "include", "including" and their variants are used in the present disclosure, these terms mean inclusive in the same way as the term "comprising". And, the term "or" used in the present disclosure does not refer to exclusive or.
[0325] A radio frame can be composed of one or more frames in the time domain. In the time domain, each of the one or more frames can be called a subframe. A subframe can also be composed of one or more time slots in the time domain. A subframe can also have a fixed time length (e.g., 1 ms) independent of the numerology.
[0326] The numerology can be communication parameters applied to at least one of transmission and reception of a certain signal or channel. The numerology can represent, for example, at least one of subcarrier spacing (SCS: SubCarrier Spacing), bandwidth, symbol length, cyclic prefix length, transmission time interval (TTI: Transmission Time Interval), number of symbols per TTI, radio frame structure, specific filtering processing performed by the transceiver in the frequency domain, specific windowing processing performed by the transceiver in the time domain, etc.
[0327] A time slot can be composed of one or more symbols (such as OFDM (Orthogonal Frequency Division Multiplexing) symbols, SC-FDMA (Single Carrier Frequency Division Multiple Access) symbols, etc.) in the time domain. A time slot can be a time unit based on a parameter set.
[0328] A time slot can contain multiple mini-slots. Each mini-slot can be composed of one or more symbols in the time domain. In addition, a mini-slot can also be referred to as a sub-slot. A mini-slot can be composed of a smaller number of symbols than a time slot. The PDSCH (or PUSCH) transmitted in a time unit larger than a mini-slot can be referred to as PDSCH (or PUSCH) mapping type A. The PDSCH (or PUSCH) transmitted using a mini-slot can be referred to as PDSCH (or PUSCH) mapping type B.
[0329] A radio frame, a sub-frame, a time slot, a mini-slot, and a symbol all represent time units when transmitting signals. A radio frame, a sub-frame, a time slot, a mini-slot, and a symbol can be respectively referred to by corresponding other names.
[0330] For example, 1 sub-frame can be called a Transmission Time Interval (TTI), multiple consecutive sub-frames can also be called a TTI, and 1 time slot or 1 mini-slot can also be called a TTI. That is, at least one of the sub-frame and the TTI can be the sub-frame (1 ms) in the existing LTE, or a period shorter than 1 ms (for example, 1 - 13 symbols), or a period longer than 1 ms. In addition, the unit representing the TTI can also not be called a sub-frame, but be called a time slot, a mini-slot, etc. Moreover, 1 time slot can also be called a unit time. The unit time can vary for each cell according to the parameter set.
[0331] Here, the TTI is, for example, the minimum time unit for scheduling in wireless communication. For example, in the LTE system, the base station performs scheduling to allocate radio resources (such as the bandwidth and transmission power that can be used in each terminal 20) to each terminal 20 in units of TTI. In addition, the definition of the TTI is not limited to this.
[0332] The TTI can be the transmission time unit for data packets (transport blocks), code blocks, codewords, etc. after channel coding, or the processing unit for scheduling, link adaptation, etc. In addition, when the TTI is given, the actual time interval (such as the number of symbols) to which the transport block, code block, codeword, etc. are mapped can also be shorter than the TTI.
[0333] In addition, when one time slot or one mini time slot is referred to as a TTI, more than one TTI (i.e., more than one time slot or more than one mini time slot) can also be the minimum time unit for scheduling. In addition, the number of time slots (mini time slots) that make up the minimum time unit for scheduling can also be controlled.
[0334] A TTI with a time length of 1 ms is also referred to as a normal TTI (TTI in LTE Rel.8 - 12), normal TTI, long TTI, normal subframe, long subframe, time slot, etc. A TTI shorter than the normal TTI can also be referred to as a shortened TTI, short TTI, partial or fractional TTI, shortened subframe, short subframe, mini time slot, sub - time slot, time slot, etc.
[0335] In addition, for a long TTI (e.g., normal TTI, subframe, etc.), it can be understood as a TTI with a time length exceeding 1 ms, and for a short TTI (e.g., shortened TTI, etc.), it can be understood as a TTI with a TTI length less than that of the long TTI and not less than 1 ms.
[0336] A resource block (RB) is a resource allocation unit in the time domain and the frequency domain. In the frequency domain, it can contain one or more consecutive sub - carriers. The number of sub - carriers contained in an RB can be the same regardless of the parameter set, for example, it can be 12. The number of sub - carriers contained in an RB can also be determined according to the parameter set.
[0337] In addition, the time domain of an RB can contain one or more symbols, and can be the length of 1 time slot, 1 mini time slot, 1 subframe, or 1 TTI. One TTI, one subframe, etc. can each be composed of one or more resource blocks.
[0338] In addition, one or more RBs can also be referred to as physical resource blocks (PRB), sub - carrier groups (SCG), resource element groups (REG), PRB pairs, RB pairs, etc.
[0339] In addition, a resource block can be composed of one or more resource elements (RE). For example, one RE can be a radio resource area of one sub - carrier and one symbol.
[0340] A bandwidth part (BWP) (which may also be referred to as partial bandwidth, etc.) can also represent a subset of consecutive common resource blocks (RB) used for a certain parameter set in a certain carrier. Here, the common RB can be determined by the index of the RB based on the common reference point of the carrier. The PRB can be defined in a certain BWP and numbered within that BWP.
[0341] The BWP can include a BWP for uplink (UL BWP) and a BWP for downlink (DL BWP). One or more BWPs can be set for a UE within one carrier.
[0342] At least one of the set BWPs can be active, and it can be assumed that the UE does not transmit or receive a predetermined signal / channel outside the active BWP. In addition, in the present disclosure, terms such as "cell" and "carrier" can be replaced by "BWP".
[0343] The structures such as the above-mentioned radio frames, subframes, time slots, mini-slots, and symbols are merely examples. For example, the number of subframes included in a radio frame, the number of time slots per subframe or radio frame, the number of mini-slots included in a time slot, the number of symbols and RBs included in a time slot or mini-slot, the number of subcarriers included in an RB, and the number of symbols, symbol length, cyclic prefix (CP) length, etc. within a TTI can be changed in various ways.
[0344] In the present disclosure, for example, when articles are added through translation as in the case of a, an, and the in English, the present disclosure also includes the case where the noun following these articles is in the plural form.
[0345] In the present disclosure, the term "A and B are different" can mean "A and B are mutually different". In addition, this term can also mean "A and B are respectively different from C". Terms such as "separation" and "combination" can be interpreted in the same way as "different".
[0346] Each form / embodiment described in the present disclosure can be used alone, combined, or switched according to execution. In addition, the notification of predetermined information is not limited to being explicit (for example, the notification of "is X"), and can also be implicit (for example, without the notification of the predetermined information).
[0347] As described above, the present disclosure has been described in detail. However, for those skilled in the art, it should be clear that the present disclosure is not limited to the embodiments described in the present disclosure. The present disclosure can be implemented in the form of modifications and changes without departing from the gist and scope of the present disclosure determined by the claims. Therefore, the purpose of the description of the present disclosure is to illustrate, and it has no restrictive meaning for the present disclosure.
[0348] Reference Numeral Explanation
[0349] 20 Terminal
[0350] 30 CAPIF Core Device
[0351] 40 Authorization Device
[0352] 50 User Information Disclosure Device
[0353] 60 Application Server
[0354] 65 Information Server
[0355] 70 Data Storage Device
[0356] 80 Data Management Device
[0357] 90 NEF
[0358] 100 FIDO Server
[0359] 110 Transmitting Unit
[0360] 120 Receiving Unit
[0361] 130 Setting Unit
[0362] 140 Control Unit
[0363] 210 Transmitting Unit
[0364] 220 Receiving Unit
[0365] 230 Setting Unit
[0366] 240 Control Unit
[0367] 1001 Processor
[0368] 1002 Storage Device
[0369] 1003 Auxiliary Storage Device
[0370] 1004 Communication Device
[0371] 1005 Input Device
[0372] 1006 Output Device
[0373] 2001 Vehicle
[0374] 2002 Driving Unit
[0375] 2003 Steering Unit
[0376] 2004 Accelerator Pedal
[0377] 2005 Brake Pedal
[0378] 2006 Gear Lever
[0379] 2007 Front Wheel
[0380] 2008 Rear Wheel
[0381] 2009 Axle
[0382] 2010 Electronic Control Unit
[0383] 2012 Information Service Unit
[0384] 2013 Communication Module
[0385] 2021 Current Sensor
[0386] 2022 Rotational Speed Sensor
[0387] 2023 Air Pressure Sensor
[0388] 2024 Vehicle Speed Sensor
[0389] 2025 Acceleration Sensor
[0390] 2026 Brake Pedal Sensor
[0391] 2027 Gear Lever Sensor
[0392] 2028 Object Detection Sensor
[0393] 2029 Accelerator Pedal Sensor
[0394] 2030 Driving Assistance System Unit
[0395] 2031 Microprocessor
[0396] 2032 Memory (ROM, RAM)
[0397] 2033 Communication Port (IO Port)
Claims
1. A network node device, comprising: a receiving unit that receives an authentication request from an application server that has received an access from a terminal; a transmitting unit that uses a secret information generated based on specific information included in the authentication request to send an inquiry about the presence or absence of the specific information to another network node device; and a control unit that determines a transmission destination of the authentication request based on a response to the inquiry.
2. The network node device according to claim 1, wherein a mobile network having the network node device is different from a mobile network having the other network node device.
3. A network node device, comprising: a receiving unit that receives an inquiry about the presence or absence of specific information including secret information generated based on the specific information included in the authentication request from another network node device that has received the authentication request; a control unit that uses the secret information to confirm the presence or absence of the specific information; and a transmitting unit that sends the result of the confirmation to the other network node device.
4. A communication system including a first network node device and a second network node device, wherein, The first network node device has: a receiving unit that receives an authentication request from an application server that has received an access from a terminal; a transmitting unit that uses a secret information generated based on specific information included in the authentication request to send an inquiry about the presence or absence of the specific information to a second network node device; and a control unit that determines a transmission destination of the authentication request based on a response to the inquiry, The second network node device has: a receiving unit that receives the inquiry from the first network node device; a control unit that uses the secret information to confirm the presence or absence of the specific information; and a transmitting unit that sends the result of the confirmation to the first network node device as the response.
5. A communication method performed by a network node device, wherein, The communication method has the following steps: receiving an authentication request from an application server that has received an access from a terminal; using a secret information generated based on specific information included in the authentication request to send an inquiry about the presence or absence of the specific information to another network node device; and determining a transmission destination of the authentication request based on a response to the inquiry.