Network node, terminal, and communication method
By employing autonomous identity management and verifiable authentication information technology in the communication system, and using electronic signatures and private key signatures for secure self-authentication, the problems of user information leakage and impersonation risks in SMS authentication are solved, achieving secure user authentication and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NTT DOCOMO INC
- Filing Date
- 2023-11-01
- Publication Date
- 2026-05-29
AI Technical Summary
Existing SMS authentication methods pose a risk of user personal information leakage and cannot effectively prevent malicious third parties from impersonating service providers for authentication.
Employing autonomous identity management (SSI) and verifiable authentication information (VC) technologies, secure personal authentication is achieved through information exchange between network nodes and terminals, utilizing the electronic signature of the telecommunications operator and the user's private key signature, thus avoiding the direct disclosure of the user's phone number.
It enables secure personal authentication in communication systems, prevents the leakage of user phone numbers, reduces the risk of malicious third-party impersonation, and improves authentication security and privacy protection.
Smart Images

Figure CN122122955A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to network nodes, terminals, and communication methods in communication systems. Background Technology
[0002] Within the 3GPP (3rd Generation Partnership Project), research was conducted on a wireless communication method known as 5G or NR (New Radio) to further increase system capacity, accelerate data transmission speeds, and reduce latency in the radio space. In 5G, various wireless technologies were researched to meet the requirements of achieving throughput of over 10Gbps and achieving latency of less than 1ms in the radio space.
[0003] In NR, network architectures including 5GC (5G Core Network) corresponding to the core network EPC (Evolved Packet Core) in the LTE (Long Term Evolution) network architecture and NG-RAN (Next Generation-Radio Access Network) corresponding to the RAN (Radio Access Network) E-UTRAN (Evolved Universal Terrestrial Radio Access Network) in the LTE network architecture were studied (e.g., non-patent literature 1).
[0004] In addition, in recent years, as a new form of identity management in the network, research is being conducted on the concept and implementation technologies (W3C Decentralized Identifiers (DID), W3C Verifiable Credentials (VC), etc.) of self-sovereign identity (SSI), which allows users to manage their own identifiers or identities and control the destination without relying on centralized identity providers (ID providers).
[0005] Existing technical documents
[0006] Non-patent literature
[0007] Non-patent document 1: 3GPP TS 23.501 V18.2.2 (2023-07) Summary of the Invention
[0008] The problem that the invention aims to solve
[0009] Currently, SMS (Short Message Service) authentication is used as a method of personal authentication when using the service. SMS authentication includes the following: authentication of the person who has signed up for the line (the person whose identity has been verified by the telecommunications operator) or their related personnel, and authentication of the terminal with a SIM card activated and associated with the phone number.
[0010] However, SMS authentication requires notifying the service provider of the user's phone number as personal information, which raises security concerns such as the risk of the service provider leaking the user's personal information.
[0011] The present invention was made in view of the above-mentioned problems, and its purpose is to perform secure personal authentication in a communication system.
[0012] Methods for solving problems
[0013] According to the disclosed technology, a network node is provided, comprising: a sending unit that sends first authentication information used in the authentication of a user with a line contract to the user's terminal; a receiving unit that receives a message sending request from a service provider's network node, including second authentication information sent by the terminal and a token generated by the service provider's network node; and a control unit that determines the user and the user's phone number based on the first authentication information and the second authentication information, wherein the sending unit uses the phone number to send a message containing the token to the terminal.
[0014] Invention Effects
[0015] Based on publicly available technology, it is possible to perform secure personal authentication in communication systems. Attached Figure Description
[0016] Figure 1 This is a diagram used to illustrate an example of a communication system.
[0017] Figure 2 This is a diagram used to illustrate an example of a communication system in a roaming environment.
[0018] Figure 3 This is a timing diagram illustrating an example of the SMS authentication method in an embodiment of the present invention.
[0019] Figure 4 This is a timing diagram illustrating an example of a first authentication method using VC in an embodiment of the present invention.
[0020] Figure 5 This is a timing diagram illustrating an example of a second authentication method using VC in an embodiment of the present invention.
[0021] Figure 6 This is a diagram comparing the authentication methods in embodiments of the present invention.
[0022] Figure 7 This is a diagram illustrating an example of the functional structure of a base station 10 and a network node 30 in an embodiment of the present invention.
[0023] Figure 8 The figure shows an example of the functional structure of terminal 20 in an embodiment of the present invention.
[0024] Figure 9 This is a diagram illustrating an example of the hardware structure of the base station 10, terminal 20, and network node 30 in an embodiment of the present invention.
[0025] Figure 10 This is a diagram illustrating an example of the structure of a vehicle 2001 according to an embodiment of the present invention. Detailed Implementation
[0026] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. Furthermore, the embodiments described below are merely examples, and the application of the present invention is not limited to the embodiments described below.
[0027] In the operation of the wireless communication system according to embodiments of the present invention, existing technologies are appropriately used. These existing technologies include, for example, existing LTE, but are not limited to, existing LTE. Furthermore, unless otherwise stated, the term "LTE" as used herein has a broad meaning that includes LTE-Advanced and subsequent modes (e.g., NR) or wireless LAN (Local Area Network).
[0028] Furthermore, in embodiments of the present invention, the "configuration" of wireless parameters, etc., can be a predetermined value that has been pre-configured, or it can be wireless parameters that have been set and notified from network node 30 or terminal 20.
[0029] Figure 1 This is a diagram used to illustrate an example of a communication system. For example... Figure 1 As shown, the communication system consists of a UE (User Equipment) as terminal 20 and multiple network nodes 30. Hereinafter, it is assumed that there is one network node 30 corresponding to each function; however, multiple functions can be implemented by one network node 30, or one function can be implemented by multiple network nodes 30. Furthermore, the term "connection" as used below can refer to either a logical connection or a physical connection.
[0030] The RAN (Radio Access Network) is a network node 30 with radio access capabilities, which may include a base station 10 and connect to the UE, AMF (Access and Mobility Management Function), and UPF (User Plane Function). The AMF is a network node 30 with functions such as RAN interface termination, NAS (Non-Access Stratum) termination, registration management, connection management, reachability management, and mobility management. The UPF is a network node 30 with functions such as PDU (Protocol Data Unit) session points interconnected with the DN (Data Network), packet routing and forwarding, and QoS (Quality of Service) processing for the user plane. The UPF and DN constitute a network slice. In the wireless communication network of this embodiment, multiple network slices are constructed.
[0031] The AMF connects with the UE, RAN, SMF (Session Management function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (Network Repository Function), UDM (Unified Data Management), ASF (Authentication Server Function), PCF (Policy Control Function), and AF (Application Function). AMF, SMF, NSSF, NEF, NRF, UDM, ASF, PCF, and AF are interconnected network nodes 30 via their respective service-based interfaces Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.
[0032] The SMF (Service Provider Function) is a network node 30 with functions such as session management, UE IP (Internet Protocol) address allocation and management, DHCP (Dynamic Host Configuration Protocol) functionality, ARP (Address Resolution Protocol) proxy, and roaming capabilities. The NEF (Network Function Provider Function) is a network node 30 with the ability to notify other NFs (Network Functions) and handle events. The NSSF (Network Slice Selection Assistance Information) is a network node 30 with functions such as selecting the network slice to which the UE connects, determining the allowed NSSAI (Network Slice Selection Assistance Information), determining the configured NSSAI, and determining the set of AMFs to which the UE connects. The PCF (Public Network Function Provider Function) is a network node 30 with the function of controlling network policies. The AF (Application Provider Function) is a network node 30 with the function of controlling application servers. The NRF (Network Provider Function) is a network node 30 with the function of discovering NF instances that provide services. The UDM (User Data Repository) is a network node 30 that manages subscriber data and authentication data. The UDM is connected to the UDR (User Data Repository) that maintains this data. Alternatively, a UDM can also have ARPF (Authentication Credential Repository and Processing Function) and SIDF (Subscription Identifier De-concealing Function). ARPF handles the processing and management of authentication information, while SIDF decrypts encrypted identification information. Alternatively, the UDM can also perform these functions by connecting to other network nodes that have ARPF or SIDF.
[0033] Figure 2 This is a diagram illustrating an example of a communication system in a roaming environment. For example... Figure 2 As shown, the network consists of a UE (User Equipment) as terminal 20 and multiple network nodes 30. Hereinafter, it is assumed that each function corresponds to one network node 30; however, multiple functions can be implemented by one network node 30, or one function can be implemented by multiple network nodes 30. Furthermore, the term "connection" as used below can refer to either a logical connection or a physical connection.
[0034] The RAN is a network node 30 with wireless access capabilities, connected to the UE, AMF, and UPF. The AMF is a network node 30 with functions such as RAN interface termination, NAS termination, registration management, connection management, reachability management, and mobility management. The UPF is a network node 30 interconnected with the DN, with functions such as external PDU session points, packet routing and forwarding, and user plane QoS processing. The UPF and DN constitute a network slice. In the wireless communication network of this embodiment, multiple network slices are constructed.
[0035] AMF connects to UE, RAN, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, AF, and SEPP (Security Edge Protection Proxy). AMF, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, and AF are network nodes 30 interconnected via their respective service-based interfaces Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.
[0036] The SMF (Service Provider Function) is a network node 30 with functions such as session management, UE IP address allocation and management, DHCP, ARP proxy, and roaming. The NEF (Network Provider Function) is a network node 30 with the ability to notify other NFs and handle events. The NSSF (Network Provider Function) is a network node 30 with functions such as selecting the network slice the UE connects to, determining the allowed NSSAI (Network Service Access Point), determining the configured NSSAI, and determining the set of AMFs the UE connects to. The PCF (Network Service Function) is a network node 30 with the function of performing network policy control. The AF (Application Provider Function) is a network node 30 with the function of controlling application servers. The NRF (Network Provider Function) is a network node 30 with the function of discovering NF instances that provide services. The SEPP (Secure Provider Proxy) is a non-transparent proxy used to filter control plane messages between PLMNs (Public Land Mobile Networks). Figure 2 The vSEPP shown is the SEPP in the visited network, and the hSEPP is the SEPP in the home network.
[0037] like Figure 2 As shown, the UE is in a roaming environment within the VPLMN (Visited PLMN) connected to the RAN and AMF. The VPLMN and HPLMN (Home PLMN) are connected via vSEPP and hSEPP. For example, the UE can communicate with the HPLMN's UDM via the VPLMN's AMF.
[0038] (Example 1)
[0039] In Example 1, a method for secure self-authentication in a communication system is described.
[0040] (SMS authentication method)
[0041] Among services on the network, SMS (Short Message Service) authentication is used as a method for performing personal authentication. SMS authentication includes the following: authentication of the person who has signed up for the line (the person whose identity has been verified by the telecommunications operator) or their related personnel, and authentication of the terminal with a SIM card activated and associated with the phone number.
[0042] Figure 3 This is a timing diagram illustrating an example of the SMS authentication method in an embodiment of the present invention. In this timing diagram, processing is performed between the terminal 20 owned by the user performing personal authentication, the authentication processing device (network node 30A) performing the processing related to personal authentication managed by the service provider, and the authentication processing device (network node 30B) performing the processing related to personal authentication managed by the telecommunications operator. Hereinafter, [further details will be provided]. Figure 3 The process of each step is explained.
[0043] Step S301: Terminal 20 sends a service access permission request to network node 30A.
[0044] Step S302: Network node 30A sends a telephone number input request to terminal 20.
[0045] Step S303: Terminal 20 sends a telephone number input response containing the telephone number of terminal 20 to network node 30A.
[0046] Step S304: Network node 30A sends a token input request to terminal 20. Based on the received request, terminal 20 displays text such as "Please enter the password received via SMS" on its screen.
[0047] Step S305: Network node 30A generates a token (e.g., a 6-digit random number) and sends the phone number of terminal 20 received in step S303 and the generated token to the phone number of network node 30B via SMS (i.e., sends a short message (SM) containing the phone number and the token).
[0048] Step S306: Network node 30B sends the token received in step S305 to the telephone number of terminal 20 via SMS (i.e., sends an SMS containing the token). Terminal 20 displays the received token on its screen.
[0049] Step S307: Terminal 20 accepts the user's operation of entering a token. Then, terminal 20 sends a token input response containing the token entered by the user to network node 30A. Network node 30A performs user authentication by confirming whether the received token matches the token sent in step S305.
[0050] Step S308: If the user's authentication is successful in step S307, then network node 30A sends a service access permission response to terminal 20.
[0051] The SMS authentication method described above allows for the verification of a user's identity by confirming the device associated with their phone number. However, this method exposes the user's phone number to the service provider. Furthermore, there is a possibility that a malicious third party could impersonate the service provider and perform the SMS authentication on their behalf.
[0052] (The first authentication method using VC)
[0053] This section explains authentication methods that utilize verifiable authentication information (VC) based on Self-Sovereign Identity (SSI) and SSI technologies (W3C Decentralized Identifiers (DID), W3C Verifiable Credentials (VC), etc.). In SSI, there are three parties: the Holder, who manages and maintains their digital identity; the Issuer, who issues attribute and qualification certificates (VC) after verifying the Holder's attribute information (name, age, address, etc.) and qualification information (employee of a company, member of a service, etc.); and the Verifier, who verifies the Holder's attributes and qualifications by requesting and receiving the required attribute and qualification certificates (VC) for services, and makes judgments regarding service provision.
[0054] Figure 4 This is a timing diagram illustrating an example of a first authentication method using VC according to an embodiment of the present invention. In this authentication method, VC is used instead of SMS to confirm that the user owns a line contract. In this timing diagram, processing is performed between the terminal 20 owned by the user performing personal authentication, the authentication processing device (network node 30A) performing the processing related to personal authentication managed by the service provider, and the authentication processing device (network node 30B) performing the processing related to personal authentication managed by the telecommunications operator. Hereinafter, [further details will be provided]. Figure 4 The process of each step is explained.
[0055] Step S401: Terminal 20 sends a Line VC issuance request to network node 30B. The Line VC is authentication information used in the authentication of users of Terminal 20 who own a Line contract.
[0056] Step S402: Network node 30B generates a line VC containing user-related information (e.g., user ID) and assigns the line VC a digital signature from the communication operator using the operator's private key. Additionally, network node 30B may include user-owned information (e.g., information related to the DID signed with the user's private key) pre-obtained from the user in the line VC. Network node 30B sends a line VC issuance response, including the line VC with the communication operator's digital signature, to terminal 20.
[0057] Step S403: Terminal 20 sends a service license request to network node 30A.
[0058] Step S404: Network node 30A sends a line VC prompt request to terminal 20.
[0059] Steps S405 and S406 are optional processes that the user can choose to perform as needed.
[0060] Step S405: Terminal 20 sends a one-time line VC issuance request to network node 30B, containing the line VC received in step S402. The one-time line VC is a line VC with a usage limit or usage period. Network node 30B confirms that the received line VC is issued to terminal 20.
[0061] Step S406: Network node 30B generates a one-time line VC and assigns the one-time line VC an electronic signature of the communication operator using the communication operator's private key. Network node 30B sends a one-time line VC issuance response containing the one-time line VC with the electronic signature of the communication operator to terminal 20.
[0062] Step S407: Terminal 20 uses the user's private key to assign the user's electronic signature to the line VC received in step S402. Then, terminal 20 sends the line VC containing the communication operator's electronic signature and the user's electronic signature to network node 30A. In the case of executing steps S405 and S406, a one-time line VC is used instead of the original line VC in the processing of step S407. Furthermore, terminal 20 sets a limit on the number of uses or an expiration period for the one-time line VC.
[0063] Network node 30A verifies the legitimacy of the received line VC. Here, the line VC issued to terminal 20 by network node 30B (the telecommunications operator), acting as the issuer, is provided to network node 30A (the service provider), acting as the verifier. Therefore, network node 30A can verify the legitimacy of the line VC by confirming whether the line VC received from terminal 20 matches the provided line VC. Furthermore, this line VC is an anonymized information that cannot be used by any third party other than the issuer and verifier to determine the user's identity.
[0064] In addition, network node 30A uses the public key of the telecommunications operator to verify the legitimacy of the electronic signature of the telecommunications operator assigned to the received line VC.
[0065] In addition, network node 30A uses the user's public key to verify the legitimacy of the user's electronic signature assigned to the received line VC.
[0066] Network node 30A performs user authentication by verifying the legitimacy of the line VC, the legitimacy of the electronic signatures of the communication operator and the user, and, in the case of using a one-time line VC, verifying the usage limit or validity period (whether the usage limit or validity period has been exceeded).
[0067] Step S408: If the user's authentication is successful in step S407, then network node 30A sends a line VC prompt request to terminal 20.
[0068] In the first authentication method using VC shown above, the user's phone number can be prevented from being disclosed to the service provider, but it cannot verify that the user owns the terminal associated with the phone number.
[0069] (Using VC's second authentication method)
[0070] The second authentication method using VC is explained below. In this second authentication method, a mechanism is used to electronically verify personally associated attribute information such as VC, achieving the same level of self-authentication as SMS authentication without requiring the user to provide a phone number to the service provider. Figure 5 This is a timing diagram illustrating an example of a second authentication method using VC according to an embodiment of the present invention. In this authentication method, SMS and VC are used to verify that the user owns a line contract. In this timing diagram, processing is performed between the terminal 20 owned by the user performing personal authentication, the authentication processing device (network node 30A) performing the processing related to personal authentication managed by the service provider, and the authentication processing device (network node 30B) performing the processing related to personal authentication managed by the telecommunications operator. Hereinafter, [further details will be provided]. Figure 5 The process of each step is explained.
[0071] Processing of steps S501 to S503 Figure 4 The processing of steps S401 to S403 is the same.
[0072] Step S504: In addition to the line VC prompt request and phone number input request, network node 30A also sends a message containing the service provider's electronic signature and / or Decentralized Identifiers (DIDs) to terminal 20. Terminal 20 can also verify the legitimacy of the service provider's electronic signature contained in the received message. Based on the received message, terminal 20 displays text such as "Line VC prompt or please enter phone number" on its screen.
[0073] Steps S505 and S506 are optional processes that the user can choose to execute as needed. Figure 4 The processing of each step S405 and step S406 is the same.
[0074] Step S507: Terminal 20 accepts the user's operation of indicating line VC prompt (Scenario A) or indicating telephone number input response and sends the operation (Scenario B).
[0075] In scenario A, terminal 20 generates a message that appends the service provider's electronic signature and / or distributed identifier received in step S504 to the line VC received in step S502, and assigns an electronic signature to the message using the user's private key. Then, terminal 20 sends this message containing the communication operator's electronic signature, the user's electronic signature, and the service provider's electronic signature to network node 30A. Here, when executing steps S505 and S506, a one-time line VC received in step S506 is used instead of the original line VC. Furthermore, terminal 20 sets a limit on the number of uses or a validity period for the one-time line VC.
[0076] In scenario B, terminal 20 accepts the user's input of a phone number and sends a phone number input response containing the input phone number to network node 30A.
[0077] Step S508: Network node 30A sends a token input request to terminal 20. Additionally, network node 30A generates a token (e.g., a 6-bit random number).
[0078] In the following steps S509 to S511, in step S507, if the terminal 20 sends a (one-time) line VC to the network node 30A (case A), steps S509 and S510 are executed; if a telephone number input response is sent (case B), step S511 is executed.
[0079] Step S509: Network node 30A sends an SMS transmission request to network node 30B. The request message contains a token, a (one-time) line VC, the user's electronic signature, and the service provider's electronic signature and / or distributed identifier.
[0080] Step S510: Network node 30B determines the user of terminal 20 by confirming that the (one-time) line VC sent to terminal 20 is consistent with the (one-time) line VC received from terminal 20.
[0081] Then, network node 30B determines the phone number of terminal 20 based on the identified user. For example, network node 30B determines the phone number of terminal 20 by referring to the joiner data of the identified user.
[0082] Additionally, network node 30B uses the user's public key to verify the legitimacy of the user's electronic signature received in step S509. Alternatively, the legitimacy of the user can also be verified based on whether the line VC has been granted information that only the user can know (such as session binding).
[0083] In addition, network node 30B uses the service provider's public key to verify the legitimacy of the service provider's electronic signature and / or uses a distributed identifier to verify the legitimacy of the service provider.
[0084] In addition, when network node 30B receives a one-time line VC, it confirms the legitimacy of the one-time line VC by checking the usage limit or validity period set for the one-time line VC (whether the usage limit or validity period has been exceeded).
[0085] If network node 30B cannot determine the user (e.g., inconsistent line VC, improper electronic signatures of the communication operator, user, and service provider, improper duration of the one-time line VC), it sends a response to network node 30A indicating that the user determination has failed, thus ending the authentication process involved in this sequence diagram.
[0086] Step S511: Network node 30A sends the phone number of terminal 20 received in step S507 and the token generated in step S508 to the phone number of network node 30B via SMS (i.e., sends an SMS containing the phone number and the token).
[0087] Step S512: Network node 30B sends the token received in step S509 or S511 to the telephone number of terminal 20 via SMS (i.e., sends an SMS containing the token). Terminal 20 displays the received token on its screen.
[0088] Step S513: Terminal 20 accepts the user's operation of entering a token. Then, terminal 20 sends a token input response containing the token entered by the user to network node 30A. Network node 30A performs user authentication by confirming whether the received token matches the token sent in step S509 or S511.
[0089] Step S514: If the user's authentication is successful in step S513, then network node 30A sends a service access permission response to terminal 20.
[0090] In the second authentication method using VC shown above (case A of step S507), personal authentication can be performed without disclosing the user's phone number to the service provider.
[0091] In addition, in the second authentication method, by including useful additional information attached to the line contract (such as the term of the line contract) in the line VC, it is possible to perform personal authentication that also takes into account the additional information.
[0092] Furthermore, in the second authentication method, when the service provider sends a line VC prompt request and a phone number input request to the user, additional information appended with the service provider's electronic signature and / or distributed identifier is sent. This allows the telecommunications operator to verify the legitimacy of the service provider and prevents malicious third parties from sending messages to users via SMS on behalf of the service provider (i.e., binding the service provider as an SMS sender).
[0093] In addition, in this embodiment, for the purpose of granting service access permission, in addition to sending tokens via SMS, other information (such as notifications related to service access) can also be sent via SMS. The validity period of a one-time line VC can also be set to be longer for the purpose of sending such information. Alternatively, by setting the validity period of a one-time line VC to be short, or limiting the number of uses (e.g., limiting it to only once), even if the line VC is leaked from the service provider, and subsequently the service provider's private key is leaked, the possibility of a malicious third party being able to send SMS can be reduced.
[0094] In addition, in this embodiment, the telephone number is used as an identifier (ID) issued by the telecommunications operator to the user and as a locator, but it is not limited to the telephone number; an email address or other similar identifier can also be used.
[0095] Furthermore, while this embodiment uses electronic identifiers (IDs) and locators, they can also be applied to addresses, etc. The telecommunications operator possesses information related to the user's address based on contract information. For example, if a service provider wants to deliver documents such as contracts to a user instead of tokens, the service provider mails a document containing information (such as a QR code) related to the (one-time) line VC obtained from the user to the telecommunications operator. The telecommunications operator then mails the received document to the user's address. For example, the telecommunications operator's network node 30 analyzes the QR code read by a scanner to obtain information related to the line VC, identifies the user based on the obtained information, and determines the user's address based on the identified user's contract information. Thus, the user can receive documents from the service provider without providing their address.
[0096] (Comparison of authentication methods)
[0097] Figure 6 This is a diagram comparing the authentication methods in embodiments of the present invention. For example... Figure 6 As shown, regarding "proving ownership of the terminal associated with the phone number," SMS authentication is not feasible, but the first and second authentication methods using VC are feasible. Regarding "proving ownership of the terminal associated with the phone number," SMS authentication (sending a token to the terminal via SMS) and the second authentication method are feasible, but the first authentication method is not feasible. Regarding "considering user convenience," SMS authentication cannot select authentication information other than a token, nor can it set the number of times or the duration of authentication information can be used, therefore it is not feasible. However, the first and second authentication methods using VC are feasible. Regarding "preventing SMS proxy execution," SMS authentication is not possible, but the first and second authentication methods using VC can be used (because third parties cannot obtain VC, this can be prevented). Furthermore, the second authentication method can be prevented by using the telecommunications operator's electronic signature.
[0098] According to the above embodiments, secure personal authentication can be performed in the communication system. Furthermore, personal authentication that proves ownership of a terminal associated with a phone number can be performed without disclosing the user's phone number to the service provider.
[0099] (Device structure)
[0100] Next, an example of the functional structure of the base station 10, network node 30, and terminal 20 performing the processes and actions described above will be explained. The base station 10, network node 30, and terminal 20 include the functions implemented in the above embodiments. However, the base station 10, network node 30, and terminal 20 may each possess only a portion of the functions described in the embodiments.
[0101] <Base station 10 and network node 30>
[0102] Figure 7 This is a diagram illustrating an example of the functional structure of base station 10 and network node 30. (See diagram for example.) Figure 7 As shown, the base station 10 has a transmitting unit 110, a receiving unit 120, a setting unit 130 and a control unit 140. Figure 7 The functional structure shown is only one example. The functional distinctions and names of the functional units can be arbitrary, as long as the operations of the embodiments of the present invention can be implemented. Furthermore, network node 30 can have the same functional structure as base station 10. Additionally, network nodes 30 with multiple different functions in the system architecture can also be composed of multiple network nodes 30 separated by function.
[0103] The transmitting unit 110 includes the function of generating a signal to be transmitted to the terminal 20 or other network node 30 and transmitting the signal via wired or wireless means. The receiving unit 120 includes the function of receiving various signals transmitted from the terminal 20 or other network node 30 and obtaining, for example, higher-level information from the received signals. A communication unit including the transmitting unit 110 and the receiving unit 120 may also be configured.
[0104] The setting unit 130 stores the preset setting information and various setting information sent to the terminal 20 into the storage device, and reads them from the storage device as needed.
[0105] As described in the embodiment, the control unit 140 performs processing related to user authentication, etc. Additionally, the control unit 140 performs processing related to communication with the terminal 20. Alternatively, the signal transmission-related functions of the control unit 140 may be included in the transmitting unit 110, and the signal reception-related functions of the control unit 140 may be included in the receiving unit 120.
[0106] Terminal 20
[0107] Figure 8 This is a diagram illustrating an example of the functional structure of terminal 20. (As shown...) Figure 8 As shown, the terminal 20 includes a transmitting unit 210, a receiving unit 220, a setting unit 230, and a control unit 240. Figure 8 The functional structure shown is only one example. The functional distinctions and names of the functional units can be arbitrary, as long as the operations of the embodiments of the present invention can be implemented. Furthermore, the communication device that becomes the resource holder 20 can also have the same functional structure as the terminal 20.
[0108] The transmitting unit 210 generates a transmission signal based on the transmission data and transmits the signal wirelessly. The receiving unit 220 wirelessly receives various signals and extracts higher-layer signals from the received physical layer signals. Furthermore, the receiving unit 220 has the function of receiving control signals, reference signals, etc., transmitted from the network node 30. A communication unit including the transmitting unit 210 and the receiving unit 220 may also be configured.
[0109] The setting unit 230 stores various setting information received by the receiving unit 220 from the network node 30 in a storage device, and reads it from the storage device as needed. In addition, the setting unit 230 also stores preset setting information.
[0110] As described in the embodiment, the control unit 240 performs processing related to user authentication, etc. Alternatively, the signal transmission-related functions of the control unit 240 may be included in the transmitting unit 210, and the signal reception-related functions of the control unit 240 may be included in the receiving unit 220.
[0111] (Hardware structure)
[0112] The block diagrams used in the description of the above embodiments ( Figure 7 and Figure 8 The diagram illustrates blocks organized by function. These functional blocks (components) are implemented through any combination of at least one of hardware and software. Furthermore, there are no particular limitations on the implementation method of each functional block. That is, each functional block can be implemented using a single device that is physically or logically combined, or by directly or indirectly (e.g., using wired, wireless, etc.) connecting two or more physically or logically separate devices. Functional blocks can also be implemented by combining software within the aforementioned single or multiple devices.
[0113] The functions include judgment, decision, determination, calculation, calculation, processing, derivation, investigation, search, confirmation, receiving, sending, output, access, resolution, selection, selection, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, and assigning, but are not limited to these. For example, the functional block (structural part) that performs the sending function is called the transmitting unit or transmitter. In short, as mentioned above, there are no particular limitations on the implementation method.
[0114] For example, in one embodiment of this disclosure, the base station 10, network node 30, terminal 20, etc., can also function as a computer for processing the wireless communication method of this disclosure. Figure 9 This diagram illustrates an example of the hardware structure of a base station 10 and a terminal 20 according to one embodiment of the present disclosure. The network node 30 may have the same hardware structure as the base station 10. The base station 10 and terminal 20 may also be configured as a computer device that physically includes a processor 1001, a storage device 1002, an auxiliary storage device 1003, a communication device 1004, an input device 1005, an output device 1006, and a bus 1007, etc.
[0115] Furthermore, in the following description, the term "device" can be replaced with "circuit," "device," "unit," etc. The hardware structure of base station 10 and terminal 20 can be configured to include one or more of the devices shown in the figures, or it can be configured to not include any of them.
[0116] The functions of base station 10 and terminal 20 are implemented by reading predetermined software (program) into hardware such as processor 1001 and storage device 1002, so that processor 1001 performs calculations and controls the communication of communication device 1004 or controls at least one of reading and writing data in storage device 1002 and auxiliary storage device 1003.
[0117] The processor 1001 controls the computer as a whole by instructing the operating system to operate. The processor 1001 may also be a central processing unit (CPU) that includes interfaces with peripheral devices, control units, arithmetic units, registers, etc. For example, the control unit 140 and control unit 240 described above can also be implemented using the processor 1001.
[0118] Furthermore, the processor 1001 reads programs (program code), software modules, or data from at least one of the auxiliary storage devices 1003 and communication devices 1004, and performs various processes accordingly. As a program, a program is used that causes the computer to perform at least a portion of the actions described in the above embodiments. For example, Figure 7 The control unit 140 of the base station 10 shown can also be implemented by a control program stored in the storage device 1002 and operated in the processor 1001. And, for example, Figure 8The control unit 240 of the terminal 20 shown can also be implemented by a control program stored in the storage device 1002 and operated in the processor 1001. Although it has been described that the various processes described above are executed by one processor 1001, the various processes described above can also be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 can also be implemented by more than one chip. In addition, the program can also be sent from the network via a telecommunications line.
[0119] Storage device 1002 is a computer-readable recording medium, and may be composed of at least one of ROM (Read Only Memory), EPROM (Erasable Programmable ROM), EEPROM (Electrically Erasable Programmable ROM), RAM (Random Access Memory), etc. Storage device 1002 may also be referred to as a register, cache, main memory (main storage device), etc. Storage device 1002 can store programs (program code), software modules, etc., that are executable for implementing the communication method according to one embodiment of this disclosure.
[0120] The auxiliary storage device 1003 is a computer-readable recording medium, such as at least one of the following: CD-ROM (CompactDisc ROM) or other optical discs, hard disks, floppy disks, magneto-optical discs (e.g., compact discs, digital multifunction discs, Blu-ray discs), smart cards, flash memory (e.g., cards, sticks, key drives), floppy disks, magnetic stripes, etc. The aforementioned storage medium may, for example, be a database, server, or other suitable media that includes at least one of the storage device 1002 and the auxiliary storage device 1003.
[0121] The communication device 1004 is hardware (transceiver) used for communication between computers via at least one of a wired network and a wireless network. It may also be referred to as a network device, network controller, network interface card (NIC), communication module, etc. The communication device 1004 may, for example, be configured to include a high-frequency switch, duplexer, filter, frequency synthesizer, etc., to implement at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, transceiver antennas, amplifiers, transceiver units, transmission path interfaces, etc., can also be implemented using the communication device 1004. The transceiver unit may also be physically or logically separated into a transmitting unit and a receiving unit.
[0122] Input device 1005 is an input device that accepts input from external sources (e.g., keyboard, mouse, microphone, switch, button, sensor, etc.). Output device 1006 is an output device that performs output to external sources (e.g., display, speaker, LED, etc.). Alternatively, input device 1005 and output device 1006 can also be integrated (e.g., a touch panel).
[0123] Furthermore, the processor 1001 and storage device 1002, among other devices, are connected via a bus 1007 for communicating information. The bus 1007 can be configured using a single bus or different buses can be used between each device.
[0124] Furthermore, the base station 10 and the terminal 20 can be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a PLD (Programmable Logic Device), or a FPGA (Field Programmable Gate Array), and can also use this hardware to implement part or all of the functional blocks. For example, the processor 1001 can also be implemented using at least one of these hardware components.
[0125] Figure 10 An example of the structure of vehicle 2001 is shown. For example... Figure 10 As shown, the vehicle 2001 includes a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a gearshift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021-2029, an information service unit 2012, and a communication module 2013. The various forms / implementations described in this disclosure can also be applied to communication devices mounted on the vehicle 2001, for example, to the communication module 2013.
[0126] The drive unit 2002 may be composed, for example, an engine, a motor, or a hybrid power system of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also called a steering wheel) and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel operated by the user.
[0127] The electronic control unit 2010 consists of a microprocessor 2031, a memory (ROM, RAM) 2032, and a communication port (I / O port) 2033. Signals from various sensors 2021 to 2029 of the vehicle 2001 are input to the electronic control unit 2010. The electronic control unit 2010 can also be referred to as an ECU (Electronic Control Unit).
[0128] The signals from various sensors 2021 to 2029 include current signals from current sensor 2021 that monitors the current of the motor, speed signals of the front and rear wheels obtained by speed sensor 2022, air pressure signals of the front and rear wheels obtained by air pressure sensor 2023, vehicle speed signals obtained by vehicle speed sensor 2024, acceleration signals obtained by acceleration sensor 2025, accelerator pedal depress signal obtained by accelerator pedal sensor 2029, brake pedal depress signal obtained by brake pedal sensor 2026, gear lever operation signal obtained by gear lever sensor 2027, and detection signals obtained by object detection sensor 2028 for detecting obstacles, vehicles, pedestrians, etc.
[0129] The Information Service Unit 2012 comprises various devices such as a car navigation system, audio system, speakers, television, and radio, used to provide (output) various information such as driving information, traffic information, and entertainment information, and one or more ECUs that control these devices. The Information Service Unit 2012 uses information obtained from external devices via a communication module 2013, etc., to provide various multimedia information and multimedia services to the occupants of the vehicle 2001. The Information Service Unit 2012 may include input devices that accept input from external sources (such as keyboards, mice, microphones, switches, buttons, sensors, touch panels, etc.), and may also include output devices that perform output to external sources (such as displays, speakers, LED lights, touch panels, etc.).
[0130] The Driver Assistance System 2030 comprises various devices used to prevent accidents or reduce driver workload, such as millimeter-wave radar, LiDAR (Light Detection and Ranging), cameras, positioning devices (e.g., GNSS), map information (e.g., high-definition (HD) maps, autonomous vehicle (AV) maps), gyroscope systems (e.g., IMU (Inertial Measurement Unit), INS (Inertial Navigation System)), AI (Artificial Intelligence) chips, and AI processors, as well as one or more ECUs that control these devices. Furthermore, the Driver Assistance System 2030 transmits and receives various information via the communication module 2013 to achieve driver assistance or autonomous driving functions.
[0131] The communication module 2013 can communicate with the microprocessor 2031 and the components of the vehicle 2001 via the communication port. For example, the communication module 2013 can send and receive data with the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, gear shift lever 2006, front wheel 2007, rear wheel 2008, axle 2009, microprocessor 2031 in the electronic control unit 2010, memory (ROM, RAM) 2032, and sensors 2021 to 29 in the vehicle 2001 via the communication port 2033.
[0132] The communication module 2013, controlled by the microprocessor 2031 of the electronic control unit 2010, is a communication device capable of communicating with external devices. For example, it can transmit and receive various types of information with external devices via wireless communication. The communication module 2013 can be located inside or outside the electronic control unit 2010. External devices can be, for example, base stations, mobile stations, etc.
[0133] The communication module 2013 can also wirelessly transmit at least one of the signals input to the electronic control unit 2010 from the various sensors 2021-2028 described above, the information obtained based on those signals, and the information obtained via the information service unit 2012 based on input from an external source (user) to an external device. The electronic control unit 2010, the various sensors 2021-2028, and the information service unit 2012 can also be referred to as input units that receive input. For example, the PUSCH transmitted by the communication module 2013 can contain information based on the aforementioned inputs.
[0134] The communication module 2013 receives various information (traffic information, signal information, vehicle-to-vehicle information, etc.) sent from external devices and displays it on the information service unit 2012 of the vehicle 2001. The information service unit 2012 can also be referred to as an output unit for outputting information (for example, outputting information to devices such as displays and speakers based on the PDSCH received by the communication module 2013 (or data / information decoded from the PDSCH). In addition, the communication module 2013 stores the various information received from external devices in a memory 2032 available to the microprocessor 2031. The microprocessor 2031 can also control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, gear lever 2006, front wheels 2007, rear wheels 2008, axles 2009, sensors 2021 to 2029, etc., of the vehicle 2001 based on the information stored in the memory 2032.
[0135] (Summary of implementation methods)
[0136] As described above, according to an embodiment of the present invention, a network node is provided, comprising: a sending unit that sends first authentication information used in the authentication of a user with a line contract to the user's terminal; a receiving unit that receives a message sending request from a service provider's network node, including second authentication information sent by the terminal and a token generated by the service provider's network node; and a control unit that determines the user and the user's phone number based on the first authentication information and the second authentication information, wherein the sending unit uses the phone number to send a message containing the token to the terminal.
[0137] Based on the above structure, secure personal authentication can be performed in the communication system.
[0138] The message sending request may also include an electronic signature of the network node of the service provider assigned the second authentication information. The control unit verifies the legitimacy of the service provider based on the electronic signature.
[0139] Based on the above structure, secure personal authentication can be performed in the communication system.
[0140] The message sending request may also include the distributed identifier of the service provider, and the control unit confirms the legitimacy of the service provider based on the distributed identifier.
[0141] Based on the above structure, secure personal authentication can be performed in the communication system.
[0142] The sending unit can send third authentication information, which sets the number of uses or the validity period, to the user's terminal and is used in the user's authentication. The receiving unit receives a message sending request from the service provider's network node, which includes fourth authentication information set by the user for the number of uses or the validity period and a token generated by the service provider's network node. The control unit determines the user and the user's phone number based on the third authentication information and the fourth authentication information.
[0143] Based on the above structure, secure personal authentication can be performed in the communication system.
[0144] The first authentication information may include information that only the user possesses.
[0145] Based on the above structure, secure personal authentication can be performed in the communication system.
[0146] Furthermore, according to an embodiment of the present invention, a terminal is provided, comprising: a receiving unit that receives authentication information used in the authentication of a user with a line contract from a network node of a telecommunications operator; and a sending unit that sends the authentication information to a network node of a service provider, wherein the receiving unit receives a message containing a token generated by the network node of the telecommunications operator, and the sending unit sends the token to the network node of the service provider.
[0147] Based on the above structure, secure personal authentication can be performed in the communication system.
[0148] Furthermore, according to an embodiment of the present invention, a communication method is provided, which is executed by a network node, the communication method comprising the following steps: sending first authentication information used in the authentication of a user with a line contract to the user's terminal; receiving a message sending request from a service provider's network node, including second authentication information sent by the terminal and a token generated by the service provider's network node; determining the user and the user's phone number based on the first authentication information and the second authentication information; and sending a message containing the token to the terminal using the phone number.
[0149] Based on the above structure, secure personal authentication can be performed in the communication system.
[0150] (Supplement to the implementation method)
[0151] The embodiments of the present invention have been described above, but the disclosed invention is not limited to such embodiments. Those skilled in the art should understand various modifications, alterations, substitutions, and replacements. Specific numerical examples have been used to facilitate understanding of the invention, but unless otherwise specified, these values are merely examples, and any appropriate values may be used. The distinctions between items in the above description are not essential to the present invention. Items described in two or more items may be combined as needed, and items described in one item may be applied to items described in another item (as long as there is no contradiction). The boundaries of functional units or processing units in the functional block diagram do not necessarily correspond to the boundaries of physical components. Multiple functional units may be operated by a single physical component, or a single functional unit may be operated by multiple physical components. Regarding the processing described in the embodiments, the order of processing may be interchanged unless there is a contradiction. For ease of explanation, a functional block diagram is used to illustrate the base station 10 and terminal 20, but such a device may also be implemented by hardware, software, or a combination thereof. The software operating according to the embodiments of the present invention via the processor of the base station 10 and the software operating according to the embodiments of the present invention via the processor of the terminal 20 may also be stored in random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, register, hard disk (HDD), removable disk, CD-ROM, database, server and other suitable storage media, respectively.
[0152] Furthermore, the notification of information is not limited to the forms / implementations described in this disclosure, and other methods may also be used. For example, information notification may be implemented through physical layer signaling (e.g., DCI (Downlink Control Information), UCI (Uplink Control Information)), higher layer signaling (e.g., RRC (Radio Resource Control) signaling, MAC (Medium Access Control) signaling), broadcast information (MIB (Master Information Block), SIB (System Information Block)), other signals, or combinations thereof. In addition, RRC signaling may also be referred to as an RRC message, for example, an RRC connection setup message, an RRC connection reconfiguration message, etc.
[0153] The various forms / implementations described in this disclosure can also be applied to systems utilizing LTE (Long Term Evolution), LTE-A (LTE-Advanced), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), 6th generation mobile communication system (6G), xth generation mobile communication system (xG) (xG (x is, for example, an integer or a decimal)), FRA (Future Radio Access), NR (new Radio), New radio access (NX), Future generation radio access (FX), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE The system may include at least one of 802.20, UWB (Ultra-Wideband), Bluetooth (registered trademark), other suitable systems, and next-generation systems based on, modified, created, or defined by these systems. Furthermore, multiple systems may be combined (e.g., a combination of at least one of LTE and LTE-A with 5G, etc.).
[0154] The processing procedures, timing, and flow of the various forms / implementations described in this specification may be rearranged in order, provided there is no contradiction. For example, the elements of various steps are indicated using an illustrative order for the methods described in this disclosure, but are not limited to the specific order indicated.
[0155] In this specification, certain actions performed by base station 10 may sometimes also be performed by its upper node, depending on the circumstances. In a network consisting of one or more network nodes having base station 10, it is obvious that various actions performed to communicate with terminal 20 can be performed by at least one of base station 10 and other network nodes besides base station 10 (e.g., considering MME or S-GW, but not limited to these). The above example illustrates the case where there is only one other network node besides base station 10, but other network nodes can also be a combination of multiple other network nodes (e.g., MME and S-GW).
[0156] The information or signals described in this disclosure can be output from a higher (or lower) layer to a lower (or higher) layer. They can also be input or output via multiple network nodes.
[0157] Input or output information can be stored in a specific location (e.g., memory) or managed using a management table. Input or output information can be overwritten, updated, or appended. Output information can also be deleted. Input information can also be sent to other devices.
[0158] The determination in this disclosure can be made by a value represented by 1 bit (0 or 1), by a Boolean value (Boolean: true or false), or by a comparison of numerical values (e.g., a comparison with a predetermined value).
[0159] Software, whether called software, firmware, middleware, microcode, hardware description language, or by other names, should be broadly interpreted as referring to commands, command sets, code, code segments, program code, programs, subroutines, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc.
[0160] In addition, software, commands, information, etc., can be sent and received via a transmission medium. For example, when software is sent from a webpage, server, or other remote source using at least one of wired technologies (coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL) etc.) and wireless technologies (infrared, microwave, etc.), at least one of these wired and wireless technologies is included within the definition of a transmission medium.
[0161] The information, signals, etc., described in this disclosure can also be represented using any of a variety of different technologies. For example, the data, commands, instructions, information, signals, bits, symbols, chips, etc., that may be involved in the above description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or photons, or any combination of these.
[0162] Furthermore, the terms used in this disclosure and those necessary for understanding this disclosure may be replaced with terms that have the same or similar meanings. For example, at least one of the channel and symbol may also be a signal (signaling). Additionally, a signal may also be a message. Furthermore, a component carrier (CC) may also be referred to as carrier frequency, cell, frequency carrier, etc.
[0163] The terms “system” and “network” as used in this disclosure are used interchangeably.
[0164] Furthermore, the information, parameters, etc., described in this disclosure can be represented using absolute values, relative values to predetermined values, or other corresponding information. For example, wireless resources can be indicated using indexes.
[0165] The names used for the above parameters are non-limiting in any respect. Furthermore, the formulas, etc., using these parameters sometimes differ from those explicitly disclosed in this disclosure. Various channels (e.g., PUCCH, PDCCH, etc.) and information elements can be identified by all appropriate names, therefore the various names assigned to these channels and information elements are non-limiting in any respect.
[0166] In this disclosure, the terms "base station (BS)," "wireless base station," "base station device," "fixed station," "NodeB," "eNodeB (eNB)," "gNodeB (gNB)," "access point," "transmission point," "reception point," "transmission / reception point," "cell," "sector," "cell group," "carrier," and "component carrier" are used interchangeably. Sometimes, terms such as macro cell, small cell, femtocell, and picocell are also used to refer to base stations.
[0167] A base station can accommodate one or more (e.g., three) cells. When a base station accommodates multiple cells, its coverage area can be divided into several smaller areas, each of which can provide communication services through a base station subsystem (e.g., a small indoor base station RRH: Remote Radio Head). Terms such as "cell" or "sector" refer to a portion or all of the coverage area of at least one of the base station and base station subsystem providing communication services within that coverage area.
[0168] In this disclosure, the base station sending information to the terminal can also be replaced by the base station instructing the terminal on information-based control / actions.
[0169] In this disclosure, the terms "Mobile Station (MS)," "User Terminal (user terminal)," "User Equipment (UE)," and "Terminal" can be used interchangeably.
[0170] For mobile stations, those skilled in the art sometimes also use the following terms: subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handheld device, user agent, mobile client, client, or some other appropriate terms.
[0171] At least one of the base station and mobile station can also be referred to as a transmitting device, receiving device, communication device, etc. Furthermore, at least one of the base station and mobile station can also be a device mounted on a mobile body, the mobile body itself, etc. The mobile body refers to a movable object with an arbitrary speed of movement. It also includes situations where the mobile body is stationary. Examples of mobile bodies include, but are not limited to, vehicles, transport vehicles, automobiles, motorcycles, bicycles, connected cars, excavators, bulldozers, wheel loaders, dump trucks, forklifts, trains, buses, rear cars, rickshaws, ships (ships and other watercraft), airplanes, rockets, artificial satellites, Drone (registered trademark), multi-rotor helicopters, quadcopter helicopters, balloons, and objects mounted on them. Additionally, the mobile body can also be a mobile body that moves autonomously based on operating commands. It can be a means of transportation (e.g., car, airplane), a mobile body that moves unmanned (e.g., drone, autonomous vehicle), or a robot (humanized or unmanned). Furthermore, at least one of the base station and mobile station also includes devices that do not necessarily move during communication operations. For example, at least one of the base station and the mobile station can be an IoT (Internet of Things) device such as a sensor.
[0172] Furthermore, the base station in this disclosure can also be replaced by a user terminal. For example, the communication between the base station and the user terminal can be replaced by communication between multiple terminals 20 (e.g., D2D (Device-to-Device), V2X (Vehicle-to-Everything), etc.), and various forms / implementations of this disclosure can also be applied. In this case, the terminal 20 can also be configured to have the functions of the base station 10 described above. In addition, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "side"). For example, uplink channel, downlink channel, etc. can also be replaced with side channel.
[0173] Similarly, the user terminal in this disclosure can also be replaced by a base station. In this case, the base station can also be configured to have the functions of the aforementioned user terminal.
[0174] The terms "determining" and "determining" as used in this disclosure sometimes encompass a variety of actions. For example, "determining" or "determining" may include actions such as judging, calculating, computing, processing, deriving, investigating, searching (e.g., searching in a table, database, or other data structure), and ascertaining, which are considered as actions of "determining" or "determining." Furthermore, "determining" or "determining" may include actions such as receiving (e.g., receiving information), transmitting (e.g., sending information), inputting, outputting, and accessing (e.g., accessing data in memory), which are considered as actions of "determining" or "determining." Moreover, "determining" or "determining" may include actions such as resolving, selecting, choosing, establishing, and comparing, which are considered as actions of "determining" or "determining." That is, "judgment" and "decision" can include matters that are considered as having been "judged" or "decided". In addition, "judgment (decision)" can also be replaced by "assuming", "expecting", "considering", etc.
[0175] The terms “connected,” “coupled,” or any variations thereof are intended to indicate any direct or indirect connection or combination between two or more elements, including cases where there is one or more intermediate elements between the two elements that are “connected” or “coupled.” The combination or connection between elements can be physical, logical, or a combination of these. For example, “access” can be used instead of “connected.” In the context of this disclosure, it can be understood that two elements are “connected” or “coupled” to each other using at least one of one or more wires, cables, and printed electrical connections, and, as some non-limiting and non-inclusive examples, using electromagnetic energy with wavelengths in the wireless frequency domain, microwave region, and light (including both visible and invisible regions) to “connect” or “couple” to each other.
[0176] The reference signal can be simply called RS (Reference Signal), or, depending on the standard applied, pilot.
[0177] As used in this disclosure, the word "based on" does not mean "based on only" unless otherwise expressly stated. In other words, the word "based on" means both "based on only" and "based on at least".
[0178] Any reference to elements using the designations "first," "second," etc., as used in this disclosure does not necessarily limit the number or order of these elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Therefore, reference to a first element and a second element does not imply that only two elements can be used, or that in any form the first element must precede the second element.
[0179] Alternatively, the "unit" in the structure of the above devices can be replaced with "section", "circuit", "equipment", etc.
[0180] When the terms "include," "including," and their variations are used in this disclosure, these terms, like the term "comprising," imply inclusion. Furthermore, the term "or" as used in this disclosure does not refer to XOR.
[0181] In this disclosure, for example, in cases where articles are added through translation, such as in English (e.g., a, an, and the), this disclosure may also include cases where the noun following these articles is in a plural form.
[0182] In this disclosure, the phrase "A and B are different" can mean "A and B are not the same." Furthermore, this phrase can also mean "A and B are each different from C." Terms such as "separate" and "combined" can also be interpreted in the same way as "different."
[0183] The various forms / implementations described in this disclosure can be used individually or in combination, and can be switched depending on the execution. Furthermore, the notification of predetermined information (e.g., a "It is X" notification) is not limited to being explicit, but can also be implicit (e.g., not being notified of the predetermined information).
[0184] The present disclosure has been described in detail above, but it will be clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented as modifications and variations without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the present disclosure is for illustrative purposes only and is not intended to be limiting.
[0185] Label Explanation
[0186] 10 base stations
[0187] 110 Dispatch Department
[0188] 120 Receiving Department
[0189] 130 Setting Department
[0190] 140 Control Department
[0191] 20 terminals
[0192] 210 Sending Department
[0193] 220 Receiving Department
[0194] 230 Setting Department
[0195] 240 Control Department
[0196] 30 network nodes
[0197] 1001 processor
[0198] 1002 Storage device
[0199] 1003 Auxiliary storage device
[0200] 1004 Communication device
[0201] 1005 Input Device
[0202] 1006 Output Device
[0203] Vehicle 2001
[0204] 2002 Drive Unit
[0205] 2003 Steering Unit
[0206] 2004 Accelerator Pedal
[0207] 2005 Brake Pedal
[0208] 2006 gearshift lever
[0209] 2007 front wheel
[0210] 2008 rear wheel
[0211] 2009 axle
[0212] 2010 Electronic Control Department
[0213] 2012 Information Service Department
[0214] 2013 Communication Module
[0215] 2021 Current Sensor
[0216] 2022 Speed Sensor
[0217] 2023 Barometric Pressure Sensor
[0218] 2024 vehicle speed sensor
[0219] 2025 Accelerometer
[0220] 2026 Brake Pedal Sensor
[0221] 2027 Gearshift sensor
[0222] 2028 Object Detection Sensor
[0223] 2029 Accelerator Pedal Sensor
[0224] 2030 Driver Assistance Systems Department
[0225] 2031 microprocessor
[0226] 2032 Memory (ROM, RAM)
[0227] 2033 Communication Port (IO Port)
Claims
1. A network node having: The sending unit sends the first authentication information used in the authentication of users who have a line contract to the user's terminal; The receiving unit receives a message sending request from the service provider's network node, which includes the second authentication information sent by the terminal and the token generated by the service provider's network node. as well as The control unit determines the user and the user's phone number based on the first authentication information and the second authentication information. The sending unit uses the telephone number to send a message containing the token to the terminal.
2. The network node according to claim 1, wherein, The message sending request also includes an electronic signature of the network node of the service provider assigned to the second authentication information. The control unit verifies the legitimacy of the service provider based on the electronic signature.
3. The network node according to claim 1, wherein, The message sending request also includes the service provider's distributed identifier. The control unit uses the distributed identifier to verify whether the service provider is legitimate.
4. The network node according to claim 1, wherein, The sending unit sends third authentication information, which specifies the number of uses or the validity period, to the user's terminal for use in the user's authentication. The receiving unit receives a message sending request from the service provider's network node, which includes fourth authentication information (set by the user for the number of uses or validity period) and a token generated by the service provider's network node. The control unit determines the user and the user's phone number based on the third authentication information and the fourth authentication information.
5. The network node according to claim 1, wherein, The first authentication information includes information that only the user possesses.
6. A terminal having: The receiving unit receives authentication information used in the authentication of users with line contracts from the network nodes of the telecommunications operator; and The sending unit sends the authentication information to the service provider's network nodes. The receiving unit receives a message containing a token generated by the network node of the service provider from the network node of the communication operator. The sending unit sends the token to the network node of the service provider.
7. A communication method performed by a network node, the communication method comprising the following steps: The first authentication information used in the authentication of users who have a line contract will be sent to the user's terminal; Receive a message sending request from the service provider's network node, which includes the second authentication information sent by the terminal and the token generated by the service provider's network node. Based on the first authentication information and the second authentication information, the user and the user's phone number are determined; as well as Using the phone number, a message containing the token is sent to the terminal.