Communication network node, user apparatus, communication network, and method
Decentralized identifiers and distributed ledgers improve the flexibility and security of MaaS roaming services by enabling secure, convenient access across multiple providers, addressing the limitations of centralized systems in MaaS solutions.
Patent Information
- Application Number
- JP2025060503
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2020-01-27
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-08
AI Technical Summary
Existing Mobility as a Service (MaaS) solutions lack flexibility in roaming services, leading to inconvenient and expensive ticketing processes for travelers without service subscriptions, and rely heavily on centralized identifiers that compromise privacy and security.
Implementing decentralized identifiers and distributed ledgers, such as blockchain technology, to manage traveler credentials and enable seamless roaming mobility services across multiple providers, ensuring privacy and security through self-sovereign identities.
Enhances the flexibility and security of roaming mobility services by reducing dependency on centralized entities, minimizing personal data transmission, and providing secure, convenient access to mobility services across different regions and providers.
Smart Images

Figure 2025102900000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to communication network nodes, user equipment, communication networks, and methods.
Background Art
[0002] Generally, it is known to distribute ledgers on entities that record digital transactions, such as multiple nodes like electronic devices, servers, etc. The distributed ledger can be based on known blockchain technology, based on which, for example, the well-known cryptocurrency Bitcoin is based, but also well-known projects such as the Ethereum project are based. Generally, the distributed ledger may be implemented with other technologies other than blockchain technology, and examples of distributed ledger projects not based on blockchain are BigchainDB and IOTA. For example, IOTA is a cryptocurrency that uses a linked list.
[0003] Also, Mobility as a Service (MaaS) is known, and a user or traveler (passenger) uses Mobility as a Service (MaaS) without, for example, renting a car or the like. Mobility as a Service can combine public (e.g., trains, buses, etc.) and private (e.g., car sharing, bike sharing, etc.) transportation services from related operators or providers.
[0004] Known MaaS solutions typically include a central unified gateway where travel or trips are planned and reserved, and users can pay with a single account.
[0005] Technologies exist for providing distributed ledgers and Mobility as a Service (MaaS), but generally, it is desirable to provide communication network nodes, user equipment, communication networks, and methods for providing Mobility as a Service (MaaS).
Summary of the Invention
[0006] According to a first aspect, the present disclosure provides a communication network node comprising a circuit configured to request a home mobility service provider to permit a roaming mobility service for a traveler (passenger) located in a mobility service area of a roaming mobility service provider.
[0007] According to a second aspect, the present disclosure provides a method for controlling a communication network node, the method including the step of requesting a home mobility service provider to permit a roaming mobility service for a traveler located in a mobility service area of a roaming mobility service provider.
[0008] According to a third aspect, the present disclosure provides a communication network node comprising a circuit configured to request a distributed database to provide a traveler's credential, where the credential is generated based on a distributed identifier of the traveler, and the distributed identifier is generated based on a request of a user equipment to the distributed database so that the traveler can use a mobility service of a roaming mobility service provider.
[0009] According to a fourth aspect, the present disclosure provides a user equipment comprising a circuit comprising a circuit configured to issue generation of a distributed identifier of a traveler and receive a traveler's credential so that the traveler can use a mobility service of a roaming mobility service provider, where the credential is generated based on a request of a home mobility service provider to a distributed database and based on the distributed identifier.
[0010] According to a fifth aspect, the present disclosure provides a communication network for providing a distributed ledger including a plurality of network nodes for authenticating a traveler to a roaming mobility service provider having a circuit, the circuit being Based on the request of the user equipment, provide a distributed identifier of the traveler in the distributed database, and based on the request of the home mobility service provider and based on the distributed identifier, provide the traveler's proof of credit in the distributed database, and configure to send the proof of credit to the user equipment so that the traveler can use the mobility service of the roaming mobility service provider.
[0011] According to a sixth aspect, the present disclosure provides a method for controlling a communication network for providing a distributed ledger including a plurality of network nodes for authenticating a traveler to a roaming mobility service provider. This method includes: Providing a distributed identifier of the traveler in the distributed database based on the request of the user equipment; providing the traveler's proof of credit in the distributed database based on the request of the home mobility service provider and based on the distributed identifier; and sending the proof of credit to the user equipment so that the traveler can use the mobility service of the roaming mobility service provider.
[0012] According to a seventh aspect, the present disclosure provides a user equipment comprising a circuit configured to send a proof of credit of a traveler, receive a token, and decrypt the token for authenticating the traveler to a roaming mobility service provider so that the traveler can use the mobility service of the roaming mobility service provider, wherein the proof of credit is generated based on the request of the home mobility service provider to the distributed database and based on the distributed identifier of the traveler, and the token is based on the encryption of the distributed identifier.
[0013] According to an eighth aspect, the present disclosure provides a communication network for providing a distributed ledger including a plurality of network nodes for authenticating a traveler to a roaming mobility service provider including a circuit. This circuit is configured to decrypt a token provided to authenticate a traveler to a roaming mobility service provider such that the traveler can use the mobility services of the roaming mobility service provider, where the token is based on the encryption of the traveler's decentralized identifier.
[0014] According to a ninth aspect, the present disclosure provides a communication network node comprising a circuit configured to enable a traveler to use the mobility services of a roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and a home mobility service provider, where the proof of credit is generated based on a request of the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier.
[0015] According to a tenth aspect, the present disclosure provides a communication network node comprising a circuit configured to store a plurality of proofs of credit of a traveler and transmit at least one of the plurality of proofs of credit to a user equipment such that the traveler can use the mobility services of a roaming mobility service provider. Here, the plurality of proofs of credit are generated based on a request of the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier.
[0016] According to an eleventh aspect, the present disclosure provides a method of controlling a communication network node including storing a plurality of proofs of credit of a traveler and transmitting at least one of the plurality of proofs of credit to a user equipment such that the traveler can use the mobility services of a roaming mobility service provider. Here, the plurality of proofs of credit are generated based on a request of the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier.
[0017] Further embodiments are set forth in the dependent claims, the following description, and the drawings.
Brief Description of the Drawings
[0018] Embodiments of the present invention are described by way of example with reference to the accompanying drawings.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Modes for Carrying Out the Invention
[0019] Before describing the embodiments in detail with reference to FIG. 2, a general description will be given.
[0020] As described at the beginning, generally, Mobility as a Service (MaaS) is known. Roaming mobility services are usually provided by a single mobility service provider. However, it has been recognized that by dispersing mobility services across multiple ledgers, it is desirable to enhance the flexibility of roaming mobility services.
[0021] Furthermore, it has been recognized that for travelers in foreign mobility service areas without service subscriptions, an improvement in convenience is desired. In such cases, travelers usually need to purchase separate tickets that are time-consuming and expensive.
[0022] Therefore, it has generally been recognized that it is desirable to provide roaming for Mobility as a Service.
[0023] It has been further recognized that decentralized identifiers and sovereign identities may further enhance security for personal data in such roaming services, for example.
[0024] In contrast, in some embodiments, social login that is convenient for the user may be utilized. However, it has been recognized that social login depends too strongly on one account, and thus, if the user temporarily or permanently disables the account, the user (i.e., the traveler) may no longer be able to use the services assigned to that account. Furthermore, while the user's personal data may be restricted by such accounting, in some countries where roaming services are used, the personal data may not be protected by the government or the like, so it has been recognized that it is desirable to reduce the amount of personal data transmitted.
[0025] Furthermore, from a privacy perspective, a social network service provider may indirectly know the user activities of a mobility provider's service.
[0026] Therefore, as discussed, it is recognized that decentralized identifiers may have the potential to reduce dependencies on such entities.
[0027] Furthermore, decentralized identifiers can meet requirements such as user control of digital IDs, privacy, personal data management, and vendor lock-in.
[0028] Furthermore, decentralized identifiers enable the provision of roaming mobility services that span different countries, borders, regions, and cities of mobility service providers.
[0029] The following provides definitions of some terms, which may be applicable in some embodiments (without limiting the present disclosure to the definitions provided below). These definitions are merely examples provided to enhance the understanding of the present disclosure, and since the technical fields of MaaS and decentralized ledgers are very dynamic and the definitions may change in the future, they are only provided as such.
[0030] The term "decentralized ledger" is known from Wikipedia, which defines it as "a consensus of replicated, shared, and synchronized digital data that is geographically distributed across multiple sites, countries, or institutions, and there is no central administrator or centralized data storage."
[0031] The decentralized ledger and its special example, namely blockchain technology, will be further described below. More generally, the term "decentralized ledger" is used as a type of database that shares digital records with multiple nodes of a network. Distributed ledgers may be composed of a peer-to-peer network. Digitally recorded data may include a kind of information to prove its consistency from the previously recorded data on the same database.
[0032] Distributed ledgers can be made public and accessible to anyone, but in principle, they can also be made non-public, and only authorized users can access them. A group of authorized entities, nodes, persons, operators, providers, etc., may also be called a "consortium" as further explained below. Also, it is possible to distinguish access permissions to the ledger data for each hierarchical user.
[0033] Distributed ledgers can use mechanisms known from blockchain technologies such as those used for Bitcoin. Such mechanisms include discovery methods, consensus mechanisms, mechanisms for maintaining data consistency, etc. The consensus mechanism ensures that all nodes or a certain number of nodes, generally electronic devices, having a copy of the distributed ledger reach a consensus on the content of the distributed ledger. There are many consensus mechanisms, including what is called a kind of cryptographic puzzle, for example, the so-called proof-of-work mechanism that ensures that old blocks of the blockchain cannot be (easily) changed. For example, the proof-of-work is used in the mining process of the Bitcoin blockchain.
[0034] In a distributed ledger or blockchain, an approval process called the mining process, which creates a consensus on data updates on the blockchain in participating nodes, can achieve the irreversibility of the sequence of transactions recorded on the blockchain by including the previously recorded data in the approval data. Such a mining process implements a distributed time - stamp server for new transaction blocks. In Bitcoin (and thus, in some embodiments), the mining process is based on the SHA256 hash function. While the input to the hash function is determined by the current block of the blockchain and the new block of transactions to be added to the blockchain, the nodes of the blockchain participating in the mining process search for a hash output with a predefined property.
[0035] The proof - of - work calculation based on the hash function may not be useful in itself, except that it is required to implement the irreversibility of the distributed ledger.
[0036] Furthermore, in general, it is known to use blockchains to store various data. For example, images, videos, measurements, and text files can be recorded on the blockchain in the form of transactions.
[0037] The term "Mobility as a Service (MaaS)" describes the shift away from individually - owned modes of transportation towards mobility solutions that are consumed as a service. This is made possible by combining transportation services from public and private transportation providers through an integrated gateway that allows users to create and manage trips and pay with a single account. Users can pay per trip or can pay a monthly fee for a limited distance. The key concept behind MaaS is to provide travelers with mobility solutions based on their travel needs. " is typically known from Wikipedia, which defines it as.
[0038] The term "mobility service provider" is the name for an umbrella of any type of service provider for MaaS. In some embodiments, a mobility service provider is typically a transportation agency such as a railway company, bus / coach, tram and taxi, carsharing, ridesharing, bikesharing, etc. Among mobility service providers, there are those that do not provide actual means of transportation, but may provide only reservation / arrangement comparable to that of a travel agency or an online reservation site.
[0039] The term "traveler (passenger)" refers to a person who has entered into a service contract with a home mobility service provider, i.e., a customer of a home mobility service provider (defined below).
[0040] "Mobility service provider" (also referred to as "MaaS service provider") is a superordinate term for the terms "home mobility service provider" and "roaming mobility service provider" (defined below), and refers to an operator, society, enterprise, etc. that provides mobility services in a specific mobility service area (e.g., town, country, region, airline route, waterway).
[0041] The term "home mobility service provider" means a mobility service provider that is located or operated in a fixed area (e.g., country, city), and may be a mobility service provider with which a traveler has a contract for, e.g., a pass, ticket, subscription, etc. This provider may also be, in some embodiments, a plurality of service providers.
[0042] The term "roaming mobility service provider" refers to another mobility service provider with which a traveler does not have a direct contract, membership, etc. Accordingly, a traveler may use the mobility services of a roaming mobility service provider, but the process of purchasing a pass, ticket, or using the mobility services of a roaming mobility service provider may be processed through the home mobility service provider.
[0043] The term "user" refers to a traveler who intends to use a roaming mobility service provider.
[0044] The term "user" may also mean a traveler's terminal device (e.g., a smartphone).
[0045] The term "user agent" means software, applications, etc. executed on a traveler's terminal device (or user equipment), which is configured to process DID (see below), credential (see below), etc. For example, a MaaS application (e.g., from a mobility service provider) may function as a user agent.
[0046] A decentralized identifier (DID) resolver can refer to a server (or other information system) that searches for a DID document for a response to a verification (authentication) via a DID (see below).
[0047] A credential can refer to evidence of a situation, right, membership, etc. approved by an issuer, a MaaS provider, etc. For example, a user can prove a MaaS subscription membership (e.g., of a home mobility service provider) (e.g., to a roaming mobility service provider).
[0048] In some embodiments, the term "public-key cryptography" is understood, as defined even on Wikipedia (https: / / en.wikipedia.org / wiki / Public-key_cryptography), to be "any cryptographic system that uses a widely disseminated public key and a secret key known only to the owner, a pair of keys." This achieves two functions: authentication, where the holder of the paired secret key confirms sending a message, and encryption, where only the holder of the paired secret key can decrypt a message encrypted with the public key. "On the other hand, two of the most well-known uses of public-key cryptography are public-key encryption, where a message is encrypted with the recipient's public key. The message cannot be decrypted by anyone who does not have the matching secret key and, thus, is presumed to be anyone other than the owner of that key and the person associated with the public key. This is used in attempts to ensure confidentiality." "Also, a digital signature where a message is signed with the sender's secret key can be verified by anyone who has access to the sender's public key. This verification proves that the sender likely had access to the secret key and, thus, is likely the person associated with that public key. This also guarantees that the message has not been tampered with because the signature is mathematically bound to the message it was originally created for. Also, any verification of another message, no matter how similar it may seem to the original message, will fail."
[0049] The term "personal data" can be understood in some embodiments as having the following meaning (see exemplary https: / / gdpr-info.eu / art-4-gdpr / ). "(1) 'Personal data' means any information relating to an identified or identifiable natural person ('data subject'). An identifiable natural person can be identified directly or indirectly, in particular by reference to an identifier such as the natural person's name, identification number, location data, online identifier, or identifiers of physical, physiological, mental, economic, cultural, or social identity."
[0050] In certain embodiments, the acronym AAA may refer to "authentication, authorization, accounting" in a computer network or network service, as is generally known as a security framework for information and communication technology (ICT).
[0051] Authentication refers to checking whether a user (or, in the context of the present disclosure, a traveler) is a legitimate user of a network, network service, or system. For example, a MaaS service provider (e.g., a mobility service provider, a transportation operator) can check the identification of a user / traveler and the status of service subscription when the user / traveler attempts to use the MaaS service.
[0052] Authorization (approval) means verifying the specific service (or services) that an authenticated user / traveler is permitted to use. For example, a MaaS service provider can check the user's contract type and service type and determine the services permitted for the user / traveler. For example, a user / traveler may be permitted to use train services but not taxi services, and the use of a train may be permitted while the use of a taxi may be denied.
[0053] Accounting refers to the recording of the actions of users and the services they use (e.g., the duration of service use, the frequency of service use, etc.). For example, when a traveler uses MaaS services such as making a reservation or boarding a vehicle, the traveler can record this information.
[0054] In some embodiments, authorization frameworks such as OAuth, Oauth 2.0, etc. can be utilized, because they are known from Internet Engineering Task Force (IETF) Request for Comments (RFC) 6749.
[0055] Such an authorization framework may be used in third - party applications. For example, an application on a terminal device (e.g., a smartphone) can reuse a social network service (SNS) account for third - party server access. Next, the authorization server can perform the authorization on behalf of the third party and provide a token, whereby the (client) application can access the data protected by the provided token, as further discussed with reference to FIG. 1 showing the simplified OAuth 2.0 protocol. For details, refer to the domain of https: / / tools.ietf.org / html / rfc6749.
[0056] At the top of FIG. 1, the connection of end - user 1 using client - application 2 is depicted, and the client - application accesses the authorization server 3.
[0057] At the bottom of FIG. 1, the authorization method 4 is depicted. Client - application 5 (which may be the same as client - application 2) inquires of the resource owner 7 (e.g., end - user 1) in 6 for permission to reuse the account.
[0058] In 8, the resource owner 7 enables reuse in 9 such that the client - application 5 provides authorization permission to the authorization server 10 where the SNS account is stored.
[0059] In 11, the authorization server sends an access token for access to the third - party server 12, which is a resource server storing the protected data.
[0060] Client - application 5 requests the data protected by the access token received from the third - party server 12 in 13.
[0061] At 14, the third - party server 12 sends the requested data to the client application 5.
[0062] Such a method is also called social login, as described in FIG. 1 (see also https: / / en.wikipedia.org / wiki(Social_login)). Social login can provide authorization for third - party services using a common SNS account.
[0063] Some embodiments relate to a communication network node having a circuit configured to request a home mobility service provider in order to enable a roaming mobility service for a traveler located in a mobility service area of a roaming mobility service provider.
[0064] The communication network node may be a computer, a server, a terminal device, etc. Further, a plurality of such components (e.g., several servers that can be connected to a terminal device, etc.) may be assumed.
[0065] A request may be issued in response to the detection of a traveler within the mobility service area of the roaming mobility service provider.
[0066] Here, further explanation will be given with reference to FIG. 2.
[0067] FIG. 2 shows a roaming mobility service method 20 according to the present disclosure.
[0068] At 22, the home mobility service provider 21 sends support information for the roaming mobility service to the traveler 23 for the preparation of the roaming mobility service. The support information includes, in this embodiment, the name of the roaming mobility service provider 24 and the mobility service area of the roaming mobility service provider 24.
[0069] For the detection of the roaming mobility service, the sensor 25 (e.g., GNSS sensor) of the mobile phone of traveler 23 detects at 26 that traveler 23 enters a predetermined area (e.g., via geofencing).
[0070] Furthermore, at 27, traveler 23 selects a roaming mobility service with a user interface of the mobile phone on which the corresponding application is displayed.
[0071] At 28, the application on the mobile phone causes the roaming mobility service provider 24 to request the roaming mobility service.
[0072] For the authentication / authorization of the user to use the mobility service of the roaming mobility service provider 24, at 29, the roaming mobility service provider 24 sends a request to the home mobility service provider 21 to confirm the subscription of traveler 23's service in the home mobility service provider 21.
[0073] Then, the home mobility service provider 21 checks whether the user account of traveler 23 exists, thereby checking the authentication at 30.
[0074] Furthermore, the home mobility service provider 21 checks the permitted services of the roaming mobility service, thereby checking the approval at 31.
[0075] At 32, the home mobility service provider 21 sends the permitted mobility service of traveler 23 to the roaming mobility service provider 24.
[0076] At 33, the roaming mobility service provider 24 transmits to the traveler 23 that roaming has been approved, and at 34, the roaming mobility service provider 24 starts the roaming service according to the received result.
[0077] The detection may be based on at least one of a Mobile Country Code (MCC), geofencing, an external trigger, and a reservation history.
[0078] The MCC can be provided, for example, by a mobile phone network and can indicate the country or region where a terminal device (e.g., a mobile phone) can be located. Such a mobile network can transmit (or broadcast) the MCC, and when the terminal device is in an operating state, the terminal device may be configured to receive the MCC and identify the country where it is located.
[0079] The terminal device may be configured to detect, based on the received MCC, that the user (e.g., the owner of the terminal device) is in a country different from their home country. A related MaaS client application (e.g., of the local mobility service provider of the current country) may be launched on the terminal device, and the terminal device may be configured to notify the mobility service provider, thereby requesting the roaming mobility service of the local mobility service provider so that the local mobility service provider becomes the user's roaming mobility service provider.
[0080] Geofencing may be based on the positioning function of the terminal device. In one embodiment, the terminal device may use a Global Navigation Satellite System (GNSS) and may be configured to determine the user's location thereby.
[0081] A home mobility service provider can provide a geographical location information database to a terminal device, where such a database can include an authorized roaming service area. When the user (or the terminal device) is in the authorized roaming service area, the terminal device can trigger the startup of the relevant MaaS application as described above.
[0082] External triggers can refer to beacon signals such as Bluetooth® beacons, Bluetooth Low Energy (BLE)® beacons, and Near Field Communication (NFC) signals.
[0083] For example, the trigger point may be provided at a boarding gate, a railway station, a national gateway, a region, a zone, etc., and the trigger point may be configured to emit one or more beacon signals without limiting the present disclosure to the above beacon signals (for example, a Wi-Fi signal can also be considered sufficient).
[0084] When the traveler (user) is close enough to the trigger point and the traveler's terminal device can receive the beacon signal, the terminal device can be configured to determine a country, a region, an area, etc. based on the beacon signal.
[0085] Alternatively or additionally, the terminal device may be configured to request further information. For example, the terminal device may send a message (e.g., an SMS) requesting a roaming mobility service provider. Such an embodiment may be assumed when the energy of the received beacon signal is below a predetermined threshold, when the amount of information in the beacon is limited, etc.
[0086] Reservation history may be used to track a traveler's previous reservations. For example, a roaming mobility service provider may store a traveler's travel records (e.g., air travel for going overseas). For example, a traveler may make reservations for flights, train trips, etc. with a roaming mobility service provider. The roaming mobility service provider can store this reservation as a reservation record within an application on the traveler's terminal device. At the date and time of the reserved trip, the application may initiate the roaming mobility service.
[0087] It has been recognized that social login is applicable to MaaS roaming services.
[0088] Therefore, in some embodiments, the circuit is further configured to perform a social login to the roaming mobility service provider.
[0089] However, in some embodiments, social login may not be suitable for MaaS services. For example, social login may depend on identifiers provided by a particular company, and as a result, the company may be able to know (directly or indirectly) each traveler's request to use the MaaS service. Therefore, for privacy reasons and from the perspective of the MaaS service provider, access to travel records may need to be restricted for third parties.
[0090] Therefore, it has been recognized that it is possible to control MaaS identifiers by individual decentralized issuers.
[0091] Therefore, in some embodiments, the identifier is a decentralized identifier.
[0092] A decentralized identifier (DID) can provide a decentralized public key infrastructure (DPKI). The definition of DID can be found, for example, by the Centralized Global Unique ID World Wide Web Consortium (W3C) (see also https: / / w3c-ccg.github.io / did-primer / and / or https: / / query.prod.cms.rt.microsoft.com / cms / api / am / binary / RE2DjfY).
[0093] In some embodiments, such decentralized identifiers are used for the verification, identification, authorization, and authentication of travelers to mobility service providers.
[0094] A DID can be used, for example, to provide self-sovereign identifiers, and thus, in some embodiments, the identifier is a self-sovereign identifier.
[0095] SSI can be defined as a portable digital identifier of duration that does not depend on any centralized authority, which may further meet the requirements of persistence, global resolvability, cryptographic verifiability, and decentralization (see also https: / / w3c-ccg.github.io / did-primer / ).
[0096] Thus, traditional identifiers may be provided by a centralized entity or institution (e.g., government) and SNS service providers, but in the case of SSI, such authority is not required.
[0097] Common SSI specifications such as Hyperledger Indy may be used and applied to the MaaS roaming service according to the present disclosure.
[0098] Figure 3 shows a method 40 for authenticating a traveler 23 for using the mobility service of a roaming mobility service provider 24.
[0099] For the preparation of a decentralized identifier (DID), a user agent 41 (e.g., provided by a traveler's mobile phone application) issues the creation of a DID at 42 together with a decentralized system 43 (i.e., a decentralized database, e.g., a blockchain, a decentralized ledger system). The DID is, in this embodiment, a unique number (in other embodiments, a traveler's global unique address) such that the information necessary to authenticate the traveler is minimized.
[0100] At 44, the DID is created by the user agent 41, and at 45, the DID is stored by the user agent 41.
[0101] At 46, a DID document is sent to a DID resolver 47.
[0102] And a credential is prepared by the home mobility service provider 21.
[0103] At 48, the user agent notifies the home mobility service provider 21 about the DID.
[0104] At 49, the home mobility service provider 21 requests the issuance of a credential based on the DID (in other embodiments, the issuer of the credential may be different from the home mobility service provider 21). This request is sent to the decentralized system 43.
[0105] At 50, the decentralized system 43 issues a credential signed with the DID to prove that the traveler is a subscriber of the mobility service of the home mobility service provider 21. Thus, both the DID and the credential are stored in the decentralized system 43.
[0106] The signature is, in this embodiment, executed via the hashing of the DID and successive public key encryption based on the generated hash.
[0107] The credit certificate is sent to the home mobility service provider 21 at 51, and the credit certificate is sent to the user agent 41 at 52.
[0108] Some embodiments relate to a communication network node having circuitry configured to require a distributed database to provide a traveler's credit certificate, the credit certificate being generated based on a traveler's distributed identifier, the distributed identifier being generated based on a request of a user device to the distributed database to enable the traveler to use the mobility services of a roaming mobility service provider.
[0109] With respect to FIG. 3, the communication network node may be controlled by the home mobility service provider 21.
[0110] Some embodiments relate to a user device comprising circuitry configured to issue the generation of a traveler's distributed identifier and to receive a traveler's credit certificate to enable the traveler to use the mobility services of a roaming mobility service provider, the credit certificate being generated based on a request of a home mobility service provider to a distributed database and based on the distributed identifier.
[0111] The user device (e.g., smartphone, smartwatch, etc.) may be configured to execute an application, thereby providing the functionality of the user agent 41 in FIG. 3.
[0112] Some embodiments provide a decentralized identifier of a traveler in a decentralized database based on a request of a user device, provide a traveler's credential in the decentralized database based on a request of a home mobility service provider and based on the decentralized identifier, and transmit the credential to the user device so that the traveler can use the mobility service of a roaming mobility service provider. A communication network is provided for a decentralized ledger having a plurality of network nodes for authenticating travelers for a roaming mobility service provider.
[0113] The communication network may include, for example, a plurality of servers, computers, user devices, etc., as discussed with respect to FIG. 3.
[0114] Some embodiments relate to a method for controlling a communication network for providing a decentralized ledger having a plurality of network nodes for authenticating travelers for a roaming mobility service provider, and this method, as discussed herein, includes providing a decentralized identifier of a traveler in a decentralized database based on a request of a user device, providing a traveler's credential in the decentralized database based on a request of a home mobility service provider and based on the decentralized identifier, and transmitting the credential to the user device so that the traveler can use the mobility service of a roaming mobility service provider.
[0115] It should be noted that the embodiments of the present disclosure generally also relate to the methods executed by respective circuits, controls, network nodes, etc., and those skilled in the art can define each of the methods corresponding to each of such embodiments.
[0116] FIG. 4 shows a further method 60 for authenticating a traveler based on a DID-based credential. Method 60 may be executed after method 40 of FIG. 3 or may be regarded as a stand-alone method.
[0117] At 61, the user agent 41 detects the entrance to the mobility service area of the roaming mobility service provider 24 so that roaming is initiated.
[0118] At 62, the user agent 41 sends a credential to the roaming mobility service provider 24 that triggers an authentication process.
[0119] The roaming mobility service provider sends the credential with a DID signature to the DID resolver 47 (server).
[0120] The DID resolver 47 sends a DID document to the roaming mobility service provider. In addition to a single DID, the DID document includes, at 63, the user's public key for performing public key encryption of the DID to generate a token. The terminal for validating the roaming mobility service provider can store the DID and the public key after the initial process (i.e., when such method 60 is executed for the first time). If the DID and the public key are stored, repeated execution of this process can be omitted at a later stage of executing method 60 without limiting the present disclosure in that regard. The stored data (i.e., the DID and / or the public key) may be valid for a predetermined time (e.g., one day). Generally, the DID and the public key are valid at different or the same times. Thereby, an offline operation (e.g., an operation without a network connection) may be possible, which may be assumed when the remaining processing does not necessarily require a network connection.
[0121] As is generally known in public key cryptography, a private key is required to decrypt a token. The private key is stored in the user agent 41.
[0122] The token (or challenge token) is sent to the user agent 41 at 64, and at 65, the user agent decrypts the token with the private key.
[0123] The decrypted result is then sent to the roaming mobility service provider 24 at 66, and the roaming mobility service provider recognizes at 67 that the user is an authenticated user for using the mobility service of the roaming mobility service provider 24 by the fact that the decrypted token is the same token as the one generated.
[0124] Accordingly, some embodiments receive a traveler's credential (this credential is generated based on a request of the home mobility service provider to a distributed database and based on the traveler's distributed identifier,) receive a distributed identifier in response to sending the credential to the database, and relate to a communication network node having a circuit configured to authenticate a traveler based on the distributed identifier so that the traveler can use the mobility service of the roaming mobility service provider.
[0125] Such a network node may be controlled by a roaming mobility service provider, as discussed with reference to FIG. 4, for example.
[0126] In some embodiments, the verification is token-based, as discussed herein.
[0127] In one embodiment, the token is generated based on public key encryption of the distributed identifier, as discussed herein.
[0128] Note that the present disclosure is not limited to public key cryptography, as any other type of symmetric or asymmetric cryptography may also be envisioned by those skilled in the art.
[0129] Some embodiments relate to a method of controlling a communication network node, the method comprising receiving a traveler's credential, the credential being generated based on a request from a home mobility service provider to a distributed database and based on a traveler's distributed identifier, receiving a distributed identifier in response to transmitting the credential to the database, and authenticating the traveler based on the distributed identifier such that the traveler can use the mobility services of a roaming mobility service provider.
[0130] Some embodiments relate to a user device having a circuit configured to transmit a traveler's credential, the credential being generated based on a request from a home mobility service provider to a distributed database and based on a traveler's distributed identifier, receive a token, the token being based on an encryption of the distributed identifier, and decrypt the token for use in authenticating the traveler to a roaming mobility service provider such that the traveler can use the mobility services of the roaming mobility service provider.
[0131] Such a user device can be realized by, for example, a smartphone or the like that functions as a user agent as discussed with respect to FIG. 4.
[0132] Some embodiments relate to a communication network for providing a distributed ledger having a plurality of network nodes for authenticating a traveler to a roaming mobility service provider having a circuit, as also discussed herein with respect to FIG. 4. This circuit provides a token, (the token being based on the encryption of a traveler's decentralized identifier,) and is configured to decrypt a token for authenticating the traveler to a roaming mobility service provider so that the traveler can use the mobility services of the roaming mobility service provider.
[0133] In some embodiments, the decentralized ledger is blockchain-based, as discussed herein.
[0134] Some embodiments relate to a method of controlling a communication network for providing a decentralized ledger having a plurality of network nodes for authenticating a traveler to a roaming mobility service provider, as discussed herein, The method includes providing a token, (the token being based on the encryption of a traveler's decentralized identifier,) and decrypting a token for authenticating the traveler to a roaming mobility service provider so that the traveler can use the mobility services of the roaming mobility service provider.
[0135] In some embodiments, a single authentication may not be considered sufficient to enable a traveler to use roaming mobility services.
[0136] Accordingly, additional traveler authorization is envisioned for security and / or safety reasons. For example, this can be compared to passport control at an airport. Checking a passport may be sufficient for traveler authentication. However, a valid visa may be required to permit the traveler to enter the country.
[0137] Similarly, according to the present disclosure, in some embodiments, an approval is performed.
[0138] In some embodiments, there is a mutual agreement between the home mobility service provider and the roaming mobility service provider to enable a traveler to use the mobility services of the roaming mobility service provider. This mutual agreement includes the assumption that the traveler will present the home mobility service provider's credentials to prove having a mobility service subscription. In this embodiment, the traveler already has a DID.
[0139] The credentials may include the issuer (home mobility service provider), the service provider (roaming mobility service provider or transportation service provider), service information (e.g., permitted services (e.g., public transportation in zones 1 - 3)), validity information (e.g., timestamp of the issue date, expiration period, expiration date, PKI (public key infrastructure) information (e.g., signature)).
[0140] Figure 5 shows a method 70 for authenticating a traveler having a single mobility service credential under a mutual agreement.
[0141] At 71, the home mobility service provider 21 issues a credential for the home mobility service and sends it to the user agent 41. The credential can be used by the roaming mobility service provider under the mutual agreement.
[0142] At 72, the user agent 41 (e.g., a mobility service application on a smartphone) detects the entrance to the roaming mobility service area (i.e., the mobility service area of a mobility service provider other than the traveler's home mobility service provider 21) and starts roaming.
[0143] The user agent 41 sends the credential to the roaming mobility service provider 24 at 73.
[0144] At 74, as described above, the traveler is authenticated.
[0145] At 75, permission is executed as follows.
[0146] First, the roaming mobility service provider 24 verifies the credentials and validity based on the electronic signature from the home mobility service provider 21. Second, the roaming mobility service provider 24 reads the service conditions provided by the credentials, and third, enables the traveler to use the mobility services of the roaming mobility service provider according to the conditions of the credentials.
[0147] Accordingly, some embodiments relate to a communication network node configured to enable a traveler to use the mobility services of a roaming mobility service provider based on the traveler's credentials and based on the mutual agreement between the roaming mobility service provider and the home mobility service provider, as discussed with respect to FIG. 5, The credentials are generated based on a request from the home mobility service provider to a distributed database and based on the traveler's distributed identifier.
[0148] In some embodiments, the network node may be controlled according to a roaming mobility user service provider.
[0149] Some embodiments relate to a method of controlling a communication network node, including steps to enable a traveler to use the mobility services of a roaming mobility service provider based on the traveler's credentials and based on the mutual agreement between the roaming mobility service provider and the home mobility service provider, as discussed herein. The credential is generated based on a request from a home mobility service provider to a distributed database and based on the traveler's distributed identifier.
[0150] However, the present disclosure is not limited to authentication according to FIG. 5, and mutual credentials, that is, mutual mobility service agreements are assumed. Each credential may be based on specific requirements.
[0151] For example, between different mobility service providers, service levels, conditions, etc. may be different. For example, a traveler may use the full services of a home mobility user service provider, but may not use the full services of a roaming mobility service provider. Furthermore, different transportation operators may be assigned to a roaming mobility service provider (such as taxis or trains), and a traveler may only use one of them. Therefore, individual credentials may be required for each operator.
[0152] For example, transportation operator A (railway company) may require credential A with vehicle usage conditions, and transportation operator B (taxi company) may require credential B with taxi usage conditions.
[0153] The credential may include the following information. Issuer (e.g., home mobility service provider, service provider, transportation operator), service information (e.g., service type (e.g., taxi, railway), service permission (e.g., within 10 times with taxi, 4 times per railway ticket)), validity information (e.g., timestamp of issue date, validity period, expiration date, PKI information (e.g., digital signature)).
[0154] FIG. 6 shows a method 80 for further explaining a case of multiple credentials for authenticating a traveler.
[0155] Based on the traveler's request to use the mobility service of the roaming mobility service provider issued to the home mobility service provider, the home mobility service provider sends a letter of credit for roaming mobility service provider A 24a and a letter of credit for roaming mobility service provider B 24b to the user agent 41.
[0156] At 82, the user agent sends the letter of credit to an Identity Hub 83 (e.g., a server, storage).
[0157] At 84, roaming detection is performed by the user agent 41 as discussed herein. The result of the roaming detection is that the traveler intends to use the mobility service of roaming mobility service provider A 24a.
[0158] Based on the roaming detection, at 85, the user agent 41 requests the corresponding letter of credit from the identity hub 83, and at 86, the identity hub 83 sends the letter of credit A to the user agent 41.
[0159] At 87, the user agent 41 displays / sends the relevant letter of credit to the roaming mobility service provider A 24a to authenticate the traveler occurring at 88.
[0160] For approval, at 89, the roaming mobility service provider A 24a verifies the letter of credit using a distributed system (e.g., blockchain). Further, the roaming mobility service provider A 24a confirms the permission of the mobility service. In some embodiments, the permission history (or remaining permission changes) may be recorded in a user agent, a distributed ledger, a distributed system, etc. For example, the user agent may have a secure memory that is not easily writable / updatable without access rights or permissions. The user agent can be set to check the remaining permissions when a user (i.e., traveler) requests a permission-based mobility service (or transport service). Further, such a mechanism may be applied to related services such as recording travel mileage and recording estimated CO2 emissions based on the type of mobility service (e.g., train, airplane, etc.).
[0161] Receiving the roaming service at 90, the traveler can start the roaming service.
[0162] Accordingly, some embodiments relate to a communication network node comprising a circuit configured to store multiple credentials of a traveler, (the multiple credentials are generated based on a request from a home mobility service provider to a distributed database and based on a distributed identifier of the traveler,) and to transmit at least one of the multiple credentials to a user device so that the traveler can use the mobility service of a roaming mobility service provider.
[0163] The network node may be configured or controlled by an identity hub as discussed with respect to FIG. 6.
[0164] Some embodiments relate to a method of controlling a communication network node as discussed herein, the method comprising storing a plurality of traveler credentials, (the plurality of credentials are generated based on a request from a home mobility service provider to a decentralized database and based on a traveler's decentralized identifier,) and transmitting at least one of the plurality of credentials to a user device so that the traveler can use the mobility services of a roaming mobility service provider.
[0165] This method may be performed by a server, computer, etc., such as the identity hub discussed with reference to FIG. 6.
[0166] Hereinafter, the blockchain and its general data structure will be described with reference to FIG. 7. The features of the blockchain of this embodiment are network / topology, consensus algorithm, hash function, participation authentication, scalability / block structure, and performance.
[0167] FIG. 7 shows the general structure of a blockchain 100. The blockchain 100 includes a chain of a plurality of data blocks 101a, 101b, and 101c, where block 101b is the current block (block #N), block 101a is the previous block (block #N - 1), and block 101c is the future or subsequent block (block #N + 1). Each block includes the result of the hash function of the previous block, the main data structure, the input value to the hash function of the current block, and the result of the hash function, and the hash function result of the current block (101b) is always used as the input to the next block (101c).
[0168] Also, each block includes a nonce (Number used once, a disposable number used only once), which is a one-time random number for secure blockchain processing and can prevent a reflection attack (replay attack). For example, if an attacker copies previously transmitted data and reuses the copied data for spoofing, the recipient can detect the spoofed communication because the next data must be used with a different "nonce." This random number is sometimes called a "nonce" in cryptocurrency.
[0169] Furthermore, a time stamp may be inserted into each of blocks 101a, 101b, and 101c. The blockchain 100 is an example of a distributed ledger that can be used, for example, to provide MaaS in some embodiments.
[0170] FIG. 8 shows the input and output of a hash function used for the blockchain 100 of FIG. 7, for example.
[0171] In general, a hash function is any function that can be used to map input data to output data with a specific algorithm. The size of the input data is large and varies, while conversely, the output of the data is compact and can have a fixed size. Known (and well-known) algorithms used for hashing in some blockchain embodiments are secure hash algorithms (SHA) designed by the U.S. National Security Agency (e.g., SHA-2, SHA-256).
[0172] The input to the hash function is the previous hash output, the nonce, and the body of the data within the current block (e.g., block 101b of FIG. 7). The output of the hash function is a unique response value to the input values. If someone tries to tamper with the body of the data, the output of the hash function will become inconsistent.
[0173] Embodiments of the distributed ledger (blockchain) in the present disclosure can implement a consensus protocol or algorithm. For example, in some embodiments, Byzantine Fault Tolerance (BFT) is used in the consensus protocol, which has a recovery function against database spoofing and hardware failures.
[0174] A well-known consensus algorithm implemented in some embodiments is the so-called Practical Byzantine Fault Tolerance (PBFT).
[0175] In some embodiments, a permissioned blockchain is used, and a relatively small number of permissioned blockchain nodes are responsible for consensus (block verification).
[0176] Figure 9 illustrates the PBFT process 110.
[0177] The leader node (also called a non-approved peer) requests in step 111 that other nodes verify the blockchain. In step 112, each requested node (approved peer) uses a hash function to confirm the validity of the blockchain and shows the result to other nodes in step 113. In step 114, when one node receives validity results from multiple other peers and receives results more valid than a predetermined criterion, it confirms the consensus of the blockchain. If there is a consensus, in step 115, that node writes / ends the blockchain. The leader peer checks the overall progress of the validity confirmation in other nodes and ends the blockchain procedure in step 116.
[0178] For resilience, the total number of nodes exceeds 3f + 1 in some embodiments, where f is the number of tolerated faulty nodes. For example, when f = 1, there are a total of 4 nodes. When f = 3, there are a total of 10 nodes, and there are other cases as well.
[0179] In some embodiments, PBFT has a permissioned blockchain for the mobility service blockchain as described herein and provides at least partially the following features.
[0180] Regarding security, in some embodiments, PBFT provides a slight risk of a 51% attack, which is common to cryptocurrencies as the permission of the peers responsible for consensus must be trusted. Regarding privacy, (due to the permission-based blockchain and the end users not having permission to access the entire blockchain), only the mobility service providers can process the entire blockchain at the (peer) nodes, so the end users cannot access the entire blockchain. Regarding performance, the processing time for consensus is very short in some embodiments due to the small number of high-performance peers. Regarding flexibility, the block size and format of the blockchain are flexible in some embodiments compared to public blockchains.
[0181] Hereinafter, an embodiment of the general-purpose computer 130 will be described with reference to FIG. 10. The computer 130 is implemented to be able to basically function as any type of network device, for example, a network node, an identity hub, a part of a distributed database, a base station or a new radio base station, a transmission and reception point, or a communication device such as a user device, a (terminal) terminal device. The computer has constituent elements 131 to 141 that can form a circuit such as any one of the circuits of the network device and the communication device as described herein.
[0182] Embodiments that execute the methods described herein using software, firmware, programs, etc. are then installed on the computer 130 configured to suit the specific embodiments.
[0183] The computer 130 has a CPU 131 (Central Processing Unit), and the CPU 131 can execute various types of procedures and methods described herein according to programs stored, for example, in a read-only memory (ROM) 132, stored in a storage 137, loaded into a random access memory (RAM) 133, and stored in a recording medium (media) 140 inserted into respective drives 139.
[0184] The CPU 131, ROM 132, and RAM 133 are connected by a bus 141, and this bus 141 is connected to an input / output interface 134. The numbers of CPUs, memories, and storages are merely illustrative, and those skilled in the art will understand that the computer 130 can be adapted and configured to meet specific requirements that arise when functioning as a base station or as a user equipment (end terminal).
[0185] Connected to the input / output interface 134 are several components such as an input section 135, an output section 136, a storage 137, a communication interface 138, and a drive 139 into which a recording medium 140 (such as a CD, digital video disk, compact flash (registered trademark) memory, etc.) can be inserted.
[0186] In addition to or instead of the storage 137, the hardware may have a secure memory for storing credentials. Special software having the right to access the secure memory can change the content of the secure memory. For example, the process of reading / writing / updating the credentials may be protected by software (execution) (either the same software or different software). Therefore, risks of forging a letter of credit (or any other content of the secure memory), such as malicious software, accidental updates / deletions (due to software errors, defects, or malfunctions), etc., are prevented. Such secure hardware / software may be referred to as a trusted execution environment (TEE) or a root of trust.
[0187] The input unit 135 can be a pointer device (such as a mouse, a graphics tablet, etc.), a keyboard, a microphone, a camera, a touch screen, or the like.
[0188] The output unit 136 can have a display (such as a liquid crystal display, a cathode ray tube display, a light emitting diode display, etc.), a speaker, or the like.
[0189] The storage 137 can have a hard disk, a solid state drive, or the like.
[0190] The communication interface 138 is configured to communicate via, for example, a local area network (LAN), a wireless local area network (WLAN), a mobile telecommunication system (such as GSM, UMTS, LTE, NR, etc.), Bluetooth (registered trademark), infrared rays, or the like.
[0191] It should be noted that the above description relates only to the configuration example of the computer 130. Alternative configurations may be implemented using additional or other sensors, storage devices, interfaces, etc. For example, the communication interface 138 may support other radio access technologies other than the mentioned UMTS, LTE, and NR.
[0192] When the computer 130 functions as a base station, the communication interface 138 can further have respective air interfaces (e.g., providing E-UTRA protocols OFDMA (downlink) and SC-FDMA (uplink)), and network interfaces (e.g., implementing protocols such as S1-AP, GTPU, S1-MME, X2-AP). Furthermore, the computer 130 may have one or more antennas and / or antenna arrays. The present disclosure is not limited to any particularity of such protocols.
[0193] Embodiments of the user equipment UE 150 and eNB 155 (or NR eNB / gNB), and the communication path 154 between the UE 150 and the eNB 155, used to implement embodiments of the present disclosure, will be described with reference to FIG. 11. The UE 150 is an example of a communication device, and the eNB is an example of a base station (e.g., a network device), but the present disclosure is not limited in this regard.
[0194] The UE 150 has a transmitter 151, a receiver 152, and a controller 153. Generally, the technical functionality of the transmitter 151, the receiver 152, and the controller 153 is known to those skilled in the art, and thus, a more detailed description thereof will be omitted.
[0195] The eNB 155 has a transmitter 156, a receiver 157, and a controller 158. Again, generally, the functionality of the transmitter 156, the receiver 157, and the controller 158 is known to those skilled in the art, and therefore, a more detailed description thereof will be omitted.
[0196] The communication path 154 has an uplink path 154a from the UE 150 to the eNB 155 and a downlink path 154b from the eNB 155 to the UE 150.
[0197] During operation, the controller 153 of the UE 150 controls the receiver 152 to receive a downlink signal via the downlink path 154b, and the controller 153 controls the transmitter 151 to transmit an uplink signal via the uplink path 154a.
[0198] Similarly, during operation, the controller 158 of the eNB 155 controls the transmitter 156 to transmit a downlink signal via the downlink path 154b, and the controller 158 controls the receiver 157 to receive an uplink signal via the uplink path 154a.
[0199] In some embodiments, the methods described herein are also implemented as a computer program that causes a computer and / or a processor and / or a circuit to execute the methods when executed on a computer and / or a processor and / or a circuit. In some embodiments, there is also provided a non-transitory computer-readable recording medium storing a computer program product that causes the method described herein to be executed when executed by the above-described processor.
[0200] It should be understood that embodiments of the present invention describe a method with an exemplary ordering of method steps. However, the specific ordering of method steps is provided for illustrative purposes only and should not be construed as binding. For example, the ordering of 22 and 26 in the embodiment of FIG. 2 may be exchanged. Also, the order of 45 and 46 in the embodiment of FIG. 3 may be exchanged. Further, the ordering of 82 and 84 in the embodiment of FIG. 6 may be exchanged. Other changes in the order of method steps will be apparent to those skilled in the art.
[0201] Note that the division of UE 150 into units 151 to 153 is possible only for illustrative purposes, and the present disclosure is not limited to a specific division of functions in specific units. For example, control XY can be realized by respective programmed processors, field programmable gate arrays, etc.
[0202] All units and entities described in this specification and claimed in the appended patent claims are implemented, unless otherwise specified, as integrated circuit logic on a chip, and the functions provided by such units and entities are implemented by software, unless otherwise specified.
[0203] As long as the above-described embodiments of the present disclosure are implemented, at least in part, using a software-controlled data processing apparatus, it is understood that a computer program providing such software control, and a transmission, storage, or other medium on which such a computer program is provided, are contemplated as aspects of the present disclosure.
[0204] Note that the present technology may be configured as follows. (1) A communication network node comprising a circuit configured to request a home mobility service provider to permit a roaming mobility service for a traveler located in a mobility service area of a roaming mobility service provider. The communication network node. (2) The request is based on detection of a traveler within the mobility service area of the roaming mobility service provider. The communication network node according to (1). (3) The detection is based on at least one of a mobility country code, geofencing, an external trigger, and a reservation history. (2) The communication network node according to (2). (4) The circuit is further configured to perform social login to the roaming mobility service provider. The communication network node according to any one of (1) to (3). (5) The permission for the roaming mobility service is based on an identifier. The communication network node according to any one of (1) to (4). (6) The identifier is a decentralized identifier. The communication network node according to (5). (7) The identifier is a self-sovereign identifier. The communication network node according to (5) or (6). (8) A method for controlling a communication network node, comprising: requesting a home mobility service provider to permit a roaming mobility service for a traveler located in a mobility service area of a roaming mobility service provider. Method. (9) Further comprising the step of performing social login to the roaming mobility service provider. The method according to (8). (10) A communication network node comprising a circuit configured to request a decentralized database to provide a traveler's credit proof, wherein the credit proof is generated based on a decentralized identifier of the traveler, and the decentralized identifier is generated based on a request of a user device to the decentralized database so that the traveler can use the mobility service of the roaming mobility service provider. Communication network node. (11) The decentralized database is based on a decentralized ledger. The communication network node according to (10). (12) The decentralized ledger is a blockchain. The communication network node according to (11). (13) Issue the generation of a traveler's decentralized identifier and, Receive the traveler's proof of credit so that the traveler can use the mobility services of the roaming mobility service provider A user equipment comprising a circuit configured to: The proof of credit is generated based on a request from a home mobility service provider to a decentralized database and based on the decentralized identifier User equipment. (14) The decentralized database is based on a decentralized ledger The user equipment according to (13). (15) The decentralized ledger is a blockchain The user equipment according to (14). (16) A communication network for providing a decentralized ledger having a plurality of network nodes for authenticating a traveler to a roaming mobility service provider, the circuit being: Provide a traveler's decentralized identifier in a decentralized database based on a request from a user equipment, Based on a request from a home mobility service provider and based on the decentralized identifier, provide a traveler's proof of credit in the decentralized database and, Send the proof of credit to the user equipment so that the traveler can use the mobility services of the roaming mobility service provider Is configured as Communication network. (17) The decentralized database is based on a decentralized ledger The communication network according to (16). (18) The decentralized ledger is a blockchain The communication network according to (17). (19) A method for controlling a communication network for providing a decentralized ledger having a plurality of network nodes for authenticating a traveler to a roaming mobility service provider, the method comprising: providing a distributed identifier of a traveler in a distributed database based on a request of a user device; providing a traveler's credential in the distributed database based on a request of a home mobility service provider and based on the distributed identifier; transmitting the credential to the user device so that the traveler can use a mobility service of a roaming mobility service provider. A method. (20) receiving a traveler's credential, receiving a distributed identifier in response to transmitting the credential to a database, and authenticating the traveler based on the distributed identifier so that the traveler can use a mobility service of a roaming mobility service provider; a circuit configured to; wherein the credential is generated based on a request of a home mobility service provider to a distributed database and based on the distributed identifier of the traveler; A communication network node. (21) wherein the authentication is token-based; The communication network node according to (20). (22) wherein the token is based on public key encryption of the distributed identifier; The communication network node according to (21). (23) transmitting a traveler's credential, receiving a token, a circuit configured to decrypt the token for authenticating the traveler to a roaming mobility service provider so that the traveler can use a mobility service of the roaming mobility service provider; wherein the credential is generated based on a request of a home mobility service provider to a distributed database and based on the distributed identifier of the traveler; The token is based on the encryption of the decentralized identifier User equipment (24) The encryption is public key encryption The user equipment according to (23) (25) A communication network for providing a decentralized ledger having a plurality of network nodes for authenticating a traveler to a roaming mobility service provider including a circuit, the circuit being configured to provide a token configured to decrypt the token for authenticating the traveler to the roaming mobility service provider so that the traveler can use the mobility service of the roaming mobility service provider The token is based on the encryption of the traveler's decentralized identifier Communication network (26) The decentralized ledger is based on a blockchain The communication network according to (25) (27) A communication network node comprising a circuit configured to enable a traveler to use the mobility service of the roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and the home mobility service provider, wherein the proof of credit is generated based on a request of the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier Communication network node (28) A method of controlling a communication network node, comprising the step of enabling a traveler to use the mobility service of the roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and the home mobility service provider The credit credentials are generated based on the request of the home mobility service provider to the distributed database and based on the traveler's distributed identifier. Method. (29) Store multiple credit credentials of a traveler and, Send at least one of the multiple credit credentials to a user device so that the traveler can use the mobility services of a roaming mobility service provider. A communication network node comprising a circuit configured to: The multiple credit credentials are generated based on the request of the home mobility service provider to the distributed database and based on the traveler's distributed identifier. Communication network node. (30) A step of storing multiple credit credentials of a traveler, A step of sending at least one of the multiple credit credentials to a user device so that the traveler can use the mobility services of a roaming mobility service provider, and A method of controlling a communication network node including: The multiple credit credentials are generated based on the request of the home mobility service provider to the distributed database and based on the traveler's distributed identifier. Method.
Claims
1. A communication network node comprising a circuit configured to request a distributed database to provide a traveler's credit proof, wherein the credit proof is generated based on a traveler's distributed identifier, and the distributed identifier is generated based on a request from a user device to the distributed database so that the traveler can use the mobility services of a roaming mobility service provider Communication network node.
2. The communication network node according to claim 1, wherein the distributed database is based on a distributed ledger. The communication network node according to claim 1.
3. The communication network node according to claim 1, wherein the distributed ledger is a blockchain. The communication network node according to claim 1.
4. A user device comprising a circuit configured to issue the generation of a traveler's distributed identifier and receive a traveler's credit proof so that the traveler can use the mobility services of a roaming mobility service provider, wherein the credit proof is generated based on a request from a home mobility service provider to the distributed database and based on the distributed identifier User device.
5. The user device according to claim 4, wherein the distributed database is based on a distributed ledger. The user device according to claim 4.
6. The user device according to claim 5, wherein the distributed ledger is a blockchain. The user device according to claim 5.
7. A communication network for providing a distributed ledger having a plurality of network nodes for authenticating a traveler to a roaming mobility service provider, the circuit being configured to provide a traveler's distributed identifier in a distributed database based on a request from a user device, provide a traveler's credit proof in the distributed database based on a request from a home mobility service provider and based on the distributed identifier, and send the credit proof to the user device so that the traveler can use the mobility services of the roaming mobility service provider Communication network.
8. The communication network according to claim 7, wherein the distributed database is based on a distributed ledger. The communication network according to claim 7.
9. The communication network according to claim 7, wherein the distributed ledger is a blockchain. The communication network according to claim 7.
10. A plurality of networks for authenticating a traveler to a roaming mobility service provider A method for controlling a communication network for providing a distributed ledger having work nodes, comprising: providing a distributed identifier of a traveler in a distributed database based on a request of a user device; step; providing a traveler's credit certificate in the distributed database based on a request of a home mobility service provider and based on the distributed identifier; step; sending the credit certificate to the user device so that the traveler can use the mobility service of the roaming mobility service provider. Method.
11. Receiving a traveler's credit certificate, receiving a distributed identifier in response to sending the credit certificate to a database, and authenticating the traveler based on the distributed identifier so that the traveler can use the mobility service of the roaming mobility service provider. A communication network node configured as such, wherein the credit certificate is generated based on a request of a home mobility service provider to a distributed database and based on the distributed identifier of the traveler. Communication network node.
12. The authentication according to claim 11, wherein the authentication is token-based. Communication network node.
13. The token according to claim 12, wherein the token is based on public key encryption of the distributed identifier. Communication network node.
14. Sending a traveler's credit certificate, receiving a token, comprising a circuit configured to decrypt the token for authenticating the traveler to the roaming mobility service provider so that the traveler can use the mobility service of the roaming mobility service provider, wherein the credit certificate is generated based on a request of a home mobility service provider to a distributed database and based on the distributed identifier of the traveler, wherein the token is based on encryption of the distributed identifier. User equipment.
15. The encryption according to claim 14, wherein the encryption is public key encryption. User equipment.
16. A communication network for providing a distributed ledger comprising a plurality of network nodes for authenticating a traveler to a roaming mobility service provider including a circuit, wherein the circuit provides a token, The traveler can use the mobility service of the roaming mobility service provider, and is configured to decrypt the token for authenticating the traveler to the roaming mobility service provider. The token is based on the encryption of the traveler's decentralized identifier in a communication network. For the traveler to be able to use the mobility service of the roaming mobility service provider, the token for authenticating the traveler to the roaming mobility service provider is configured to be decrypted. The token is based on the encryption of the traveler's decentralized identifier in a communication network. The token is based on the encryption of the traveler's decentralized identifier in a communication network. Communication network.
17. The decentralized ledger is based on a blockchain. The communication network according to claim 16. The communication network according to claim 16.
18. A communication network node comprising a circuit configured to enable a traveler to use the mobility service of a roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and the home mobility service provider. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. The communication network node is configured to enable a traveler to use the mobility service of a roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and the home mobility service provider. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. Communication network node.
19. A method of controlling a communication network node, including the step of enabling a traveler to use the mobility service of a roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and the home mobility service provider. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. The method includes the step of enabling a traveler to use the mobility service of a roaming mobility service provider based on the traveler's proof of credit and based on a mutual agreement between the roaming mobility service provider and the home mobility service provider. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. Method. The proof of credit is generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. Method.
20. A communication network node comprising a circuit configured to store a plurality of proofs of credit of a traveler and transmit at least one of the plurality of proofs of credit to a user device so that the traveler can use the mobility service of a roaming mobility service provider. The plurality of proofs of credit are generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. The plurality of proofs of credit are generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. Transmit The communication network node is configured to store a plurality of proofs of credit of a traveler and transmit at least one of the plurality of proofs of credit to a user device so that the traveler can use the mobility service of a roaming mobility service provider. The plurality of proofs of credit are generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. The plurality of proofs of credit are generated based on a request from the home mobility service provider to a decentralized database and based on the traveler's decentralized identifier. Communication network node.
21. A step of storing a plurality of proofs of credit of a traveler. A step of enabling a traveler to use the mobility service of a roaming mobility service provider. To enable use, at least one of the plurality of credentials is transmitted to a user device The step of A method of controlling a communication network node, comprising: The plurality of credentials are generated based on a home mobility service provider request to a distributed database and based on a traveler's distributed identifier Method
Citation Information
Patent Citations
System for verification of pseudonymous credentials for digital identities with managed access to personal data on trust networks
US20190333054A1
User authentication using connection information provided by a blockchain network
WO2019086127A1