Information processing device and communication system

The communication system enhances security by authenticating and relaying vehicle communications through security devices, addressing resource limitations and insecure network challenges.

JP2025104447APending Publication Date: 2025-07-10TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023222258
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing communication systems in vehicles face challenges in ensuring security, particularly when using insecure networks like the Internet, and are limited by hardware resources, making it difficult to allocate sufficient resources for security processing.

Method used

A communication system with a storage unit for authentication data and a gateway that authenticates mobile communication terminals, relaying communications to security devices based on authentication information, ensuring secure communication even through insecure paths.

Benefits of technology

This configuration allows for robust authentication and secure communication by directing insecure network communications to security devices, maintaining security without overburdening limited vehicle hardware resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025104447000001_ABST
    Figure 2025104447000001_ABST
Patent Text Reader

Abstract

To improve security in communication.SOLUTION: An information processing device includes a storage unit that stores authentication data for authenticating a mobile communication terminal and a gateway that accommodates access from a first communication network, and is disposed within a communication system that authenticates a mobile communication terminal that is connected via the first communication network and the gateway using the authentication data. The information processing device further includes a control unit that relays communication from the mobile communication terminal to one or more security devices based on information related to the authentication.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to communication technology.

Background Art

[0002] There is a technology for dynamically selecting a communication method used by a mobile body. Regarding this, for example, Patent Document 1 discloses an in-vehicle terminal device that switches between narrowband communication and broadband communication according to the type of data to be transmitted and received.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] The present disclosure aims to improve security in communication.

Means for Solving the Problems

[0005] One aspect of an embodiment of the present disclosure is an information processing apparatus disposed in a communication system that has a storage unit for storing authentication data for authenticating a mobile communication terminal and a gateway for accommodating access from a first communication network, and authenticates a mobile communication terminal connected via the first communication network and the gateway using the authentication data, the information processing apparatus having a control unit that relays communication from the mobile communication terminal to one or more security devices based on information related to the authentication.

[0006] One aspect of an embodiment of the present disclosure is A communication system comprising: a storage unit for storing authentication data for authenticating a mobile communication terminal; a gateway for accommodating access from a first communication network; a control unit for authenticating a mobile communication terminal connected via the first communication network and the gateway using the authentication data, and for relaying communication from the mobile communication terminal to one or more security devices based on information regarding the authentication.

[0007] In another aspect, there is provided a program for causing a computer to execute a method executed by the above-described apparatus or system, or a computer-readable storage medium storing the program non-temporarily.

Advantages of the Invention

[0008] According to the present disclosure, security in communication can be improved.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Modes for Carrying Out the Invention

[0010] In recent years, the connectedness of automobiles has advanced, and the number of vehicles equipped with in-vehicle devices having a wireless communication function has increased. The in-vehicle device can provide various services to the vehicle occupants, for example, by communicating with a server device (such as an application server) via a cellular communication network.

[0011] The server device that serves as the communication destination of the in-vehicle device is not necessarily arranged in a network with security ensured. Therefore, it is preferable for the in-vehicle device to execute security-related services (for example, antivirus services, etc.).

[0012] In the future, when the processing amount by the in-vehicle device increases, it is assumed that more resources for security processing will be consumed. However, the processor of the in-vehicle device, unlike a general-purpose computer, often has limitations on available resources and it is difficult to allocate a large amount of resources for security. The communication system according to the present disclosure solves such problems.

[0013] The information processing apparatus according to the first aspect of the present disclosure is an information processing apparatus disposed in a communication system that has a storage unit for storing authentication data for authenticating a mobile communication terminal and a gateway for accommodating access from a first communication network, and authenticates the mobile communication terminal connected via the first communication network and the gateway using the authentication data, and has a control unit for relaying communication from the mobile communication terminal to one or more security devices based on the information related to the authentication.

[0014] The mobile communication terminal is typically an in-vehicle terminal mounted on a vehicle, but is not limited thereto. The gateway is a terminal device that accommodates access via a first communication network in the communication system. The first communication network may be an insecure network such as an IP communication network, for example. The information processing apparatus is disposed in a communication system that has a storage unit for storing authentication data and a gateway. In the communication system, a device for authenticating the mobile communication terminal may be disposed independently of the information processing apparatus, or the information processing apparatus may also serve as a device for authenticating the mobile communication terminal. The communication system authenticates the mobile communication terminal connected via the first communication network and the gateway.

[0015] The control unit relays the communication from the mobile communication terminal to one or more security devices based on the information related to authentication. The one or more security devices are typically devices that are arranged outside the communication system and provide antivirus services, malware countermeasure services, sandbox services, and the like.

[0016] When the mobile communication terminal is connected to the communication system through an insecure path, it is preferable to pass through a device that provides a security service at any point on the communication path. Therefore, the control unit relays the communication from the mobile communication terminal to one or more security devices based on the information related to authentication. The information related to authentication may include the identifier of the mobile communication terminal. For example, when the gateway accommodates access from a first communication network that is not secure, it is preferable to provide a service related to security for the mobile communication terminal that accesses through the gateway.

[0017] Note that the control unit may obtain association data that associates the mobile communication terminal with a security device that is the relay destination of the communication from the mobile communication terminal, and determine the security device that relays the communication from the mobile communication terminal based on the association data.

[0018] According to such a configuration, it is possible to allocate to each mobile communication terminal which of the plurality of security devices to transfer the communication to.

[0019] In addition, the control unit may relay the communication from the mobile communication terminal to the one or more security devices when the destination of the communication from the mobile communication terminal is not a device within the communication system.

[0020] The destination of communication from a mobile communication terminal may not be a device within the communication system. For example, the communication system may be connected to the Internet via a packet gateway (PGW) or the like. Since the Internet is generally not a secure network, when the destination of communication from the mobile communication terminal is the Internet, it is preferable to perform communication via a security device. On the other hand, when communicating with a device associated with the communication system, a security service can be executed in the device. Therefore, depending on the communication destination, it may be possible to switch whether to direct the communication to the security device or not.

[0021] Hereinafter, specific embodiments of the present disclosure will be described with reference to the drawings. The hardware configuration, module configuration, functional configuration, etc. described in each embodiment are not intended to limit the technical scope of the disclosure only to those, unless otherwise specified.

[0022] [Overview of the Network] The overview of the vehicle communication network according to the embodiment will be described with reference to FIG. 1. The vehicle communication network according to the present embodiment includes a DCM10 mounted on a vehicle 1, a communication device 11 connected to the DCM10, a communication system 2, a server device 3, and a security device 4. The communication system 2 is a network including a plurality of communication devices including an authentication device 20. The DCM10 and the communication system 2 are connected via a carrier network A or a carrier network B. Note that the vehicle 1, the server device 3, and the security device 4 included in the system may be plural.

[0023] Vehicle 1 is a connected vehicle capable of communicating with any server device via wireless communication. Vehicle 1 can provide various services by communicating with an external server device (for example, server device 3) via a wireless communication device DCM10. Examples of various services include, for example, a navigation service, a remote control (for example, remote air conditioning, etc.) service, an in-vehicle Wi-Fi (registered trademark) service, an emergency notification service, and the like. In addition to the illustrated devices, Vehicle 1 may have an in-vehicle terminal that provides these services.

[0024] DCM10 is a device that performs wireless communication with a predetermined network in order to connect a component (for example, an in-vehicle terminal) that Vehicle 1 has and server device 3. In the present embodiment, DCM10 is configured to be connectable to a predetermined cellular communication network. DCM10 is configured to have an eUICC (Embedded Universal Integrated Circuit Card) for identifying a user. The eUICC may be a physical SIM card or an eSIM or the like. Hereinafter, the eUICC that DCM10 has is referred to as the first SIM.

[0025] In the illustrated example, DCM10 is configured to be communicable with a carrier network A that constitutes a cellular communication network. The carrier network A includes a base station of the cellular communication network, a control device that manages mobile communication terminals, and the like.

[0026] In the present embodiment, the carrier network A is connected to a communication system 2. The communication system 2 is a network that connects the carrier network A and a PDN (Packet Data Network) such as the Internet. ork). While the carrier network A is a network operated by a communication carrier, the communication system 2 can be a system operated by a manufacturer of Vehicle 1 or the like. By connecting these to each other, for example, it becomes possible to provide a unique service for Vehicle 1 by the communication system 2.

[0027] In this embodiment, the carrier network A provides only communication lines, and the communication system 2 performs authentication of the DCM 10 and provision of services to the DCM 10. The DCM 10 has a first SIM in which profile information for receiving authentication by the communication system 2 is stored. The first SIM is issued by an operator (for example, a vehicle manufacturer) that operates the communication system 2. The communication system 2 includes an authentication device 20 for authenticating the DCM 10.

[0028] The DCM 10 is connected to the communication system 2 via the carrier network A, and receives authentication from the communication system 2 using the profile information stored in the first SIM. In this embodiment, the authentication device 20 included in the communication system 2 authenticates the DCM 10 based on the profile information possessed by the first SIM. The authenticated DCM 10 can communicate with a PDN (for example, the Internet) and can start communicating with the server device 3.

[0029] Note that, as shown in the figure, in a form in which the DCM 10 is directly connected to a cellular communication network (carrier network A), if a communication failure occurs in the carrier network A, the communication will be interrupted.

[0030] To address this, a technique has also been proposed in which a plurality of profile information is stored in the SIM and the network is switched according to the situation (for example, connected to another carrier network). However, even when such a configuration is adopted, it is not possible to cope with the generational change of cellular communication standards. For example, for legacy communication standards such as 3G, it is expected that the services will be sequentially stopped in the future. On the other hand, since automobiles are generally used over a long span of 10 years or more, it is assumed that communication devices such as the DCM installed at the time of manufacture will become unusable in the future. In order to change the carrier network, it is necessary to replace the SIM card and the communication module, which incurs a great deal of cost.

[0031] To address this, in this embodiment, the DCM 10 is configured to be able to externally connect to other communication devices, and when the carrier network A becomes unavailable, an alternative communication path is secured via the other communication device.

[0032] As shown in FIG. 1, the DCM 10 is configured to be able to externally connect the communication device 11. For example, the DCM 10 can connect the communication device 11 via an interface such as USB, and is configured to be able to transmit and receive data via the communication device 11. In other words, the DCM 10 is configured to support USB tethering. The communication device 11 is a device capable of performing wireless communication according to an arbitrary communication standard. For example, even when the service of the communication standard used by the DCM 10 ends, the DCM 10 can continue communication via the communication device 11.

[0033] The communication device 11 is a device having the same communication function as the DCM 10. The communication device 11 has a second SIM and can connect to the carrier network B based on the profile information stored in the second SIM.

[0034] The carrier network B is a cellular communication network independent of the carrier network A and the communication system 2. For example, the user of the vehicle 1 selects and subscribes to the carrier network B and prepares a communication device 11 corresponding to the subscription. Since the carrier network B is a network independent of the communication system 2, as it is, the carrier network B and the communication system 2 cannot be connected to each other. Therefore, in this embodiment, the DCM 10 connected to the carrier network B establishes an IPsec tunnel with the ePDG of the communication system 2, thereby connecting the communication system 2 via the carrier network B and the subsequent IP communication network.

[0035] Since the carrier network B is a network independent of the communication system 2, as it is, the carrier network B and the communication system 2 cannot be connected to each other. Therefore, in this embodiment, the DCM 10 connected to the carrier network B establishes an IPsec tunnel with the ePDG of the communication system 2, thereby connecting the communication system 2 via the carrier network B and the subsequent IP communication network.

[0036] The communication system 2 has a gateway (enhanced Packet Data Gateway, hereinafter referred to as ePDG) for accommodating access from an IP communication network. The ePDG is a gateway for accommodating Untrusted non-3GPP (registered trademark) wireless access. As a result, the communication system 2 can accept access via an IP communication network (via carrier network B) in addition to access via a wireless access network (carrier network A). Note that the IP communication network is typically the Internet, but it may be otherwise. As a result, the DCM10 connected to the carrier network B can communicate with the communication system 2 via a path through the IP communication network (Internet).

[0037] According to such a configuration, even when the carrier network A is not available, the user of the vehicle 1 can continue the communication between the DCM10 and the communication system 2 by any path.

[0038] [Overview of Authentication Process] When the DCM10 is connected to the communication system 2 via the carrier network A, the communication system 2 can confirm the validity of the DCM10 by using a SIM (first SIM) issued by itself. On the other hand, consider the case where the DCM10 is connected to the communication system 2 via the carrier network B. Since the carrier network B and the communication system 2 are independent of each other, the communication system 2 cannot trust the DCM10 as it is. This is because only authentication by the carrier network B (authentication using the second SIM) has been performed for the DCM10.

[0039] Therefore, in the present embodiment, the communication system 2 (authentication device 20) authenticates the DCM10 connected via the ePGD using the authentication information possessed by the first SIM in the same manner as when connected via the carrier network A. Thus, even if the communication path between the DCM10 and the communication system 2 changes, the communication system 2 can continue to perform robust authentication equivalent to cellular communication without changing the device configuration.

[0040] Here, the problems when connecting the DCM10 and the communication system 2 via the IP communication network will be described. Generally, the IP communication network typified by the Internet is not a secure network. For example, when the DCM10 is connected to the communication system 2 via the carrier network A, security services can be provided inside the carrier network A. However, when the DCM10 is connected to the communication system 2 via the ePDG, communication may be tampered with on the path, or harmful data (such as computer viruses) may be mixed in.

[0041] However, it is not realistic in terms of cost to execute security services in the DCM10 with hardware limitations. Therefore, in this embodiment, on the condition that "the DCM10 is connected to the communication system 2 via the ePDG and authenticated by the first SIM", the communication from the DCM10 is relayed to a predetermined security device 4. The security device 4 is a device arranged on the path between the communication system 2 and the server device 3. According to such a configuration, it becomes possible to direct the communication from the DCM10 connected by an insecure path to a device that provides security services, and thereby it becomes possible to enable the DCM10 to perform secure communication.

[0042] [Details of Network Configuration] FIG. 2 is a diagram showing in detail the components of each network described with reference to FIG. 1. In FIG. 2, among the components of each system, the components according to the first embodiment are extracted and shown, and the components of each system are not limited to those shown in FIG. 2.

[0043] ​The carrier network A is composed of a base station for cellular communication (hereinafter referred to as eNodeB), a control device (Mobile Management Entity, hereinafter MME) that manages mobile communication terminals including DCM10, and a gateway (Serving Gateway, hereinafter S-GW) that performs data relay. It is configured.

[0044] The communication system 2 is composed of a gateway (Packet Gateway, hereinafter P-GW) for connecting the EPC to the Internet and a device (hereinafter, PCRF) that performs network policy and charging management. Also, as described above, the communication system 2 is composed of a gateway (ePDG) that accommodates access from the IP communication network and an authentication device 20.

[0045] The authentication device 20 is also called an AAA (Authentication Authorization and Accounting) server and executes a process of authenticating mobile communication terminals including DCM10. The authentication device 20 has a function of performing authentication in place of the MME in a normal EPC. The authentication device 20 is connected to a database (Home Subscriber Server, hereinafter HSS) that manages subscriber information, and authenticates the mobile communication terminal based on the information stored in the database (authentication information corresponding to the first SIM). It also performs authentication. The authentication device 20 has a function of performing authentication in place of the MME in a normal EPC. The authentication device 20 is connected to a database (Home Subscriber Server, hereinafter HSS) that manages subscriber information, and authenticates the mobile communication terminal based on the information stored in the database (authentication information corresponding to the first SIM).

[0046] The carrier network B has a function of authenticating a mobile communication terminal (communication device 11) connected via a base station (eNodeB). Also, the carrier network B has a P-GW connected to an IP communication network (for example, the Internet). Thereby, the mobile communication terminal (communication device 11) connected to the carrier network B can communicate with the IP communication network.

[0047] When establishing a connection using its own wireless communication module, DCM10 sends a connection request to communication system 2 via carrier network A. At this time, DCM10 receives authentication from authentication device 20 using the authentication information included in the profile information (hereinafter referred to as the first profile) stored in the first SIM.

[0048] Also, when establishing a connection via communication device 11, DCM10 sends a connection request to communication system 2 with the ePDG of communication system 2 as the destination. As described above, since the ePDG is a gateway that accommodates access from the IP communication network, DCM10 can communicate with communication system 2 via the ePDG. At this time, DCM10 receives authentication from authentication device 20 using the authentication information included in the profile information (first profile) stored in the first SIM. That is, regardless of the path to communication system 2, DCM10 is configured to receive authentication from authentication device 20 using the same authentication information ( the authentication information included in the first profile).

[0049] The connection request is processed by authentication device 20 of communication system 2, and authentication is executed between DCM10 and authentication device 20. Authentication device 20 authenticates DCM10 based on the authentication information included in the first profile. When the authentication is completed, the path from DCM10 to the PDN is established, and DCM10 and server device 3 can communicate with each other.

[0050] In this embodiment, DCM10 receives authentication from authentication device 20 using the same authentication information (profile information) for both the path (the first path shown in FIG. 2) of directly connecting to communication system 2 via the cellular communication network and the path (the second path) of connecting to communication system 2 via the IP communication network using tethering. According to such a configuration, it becomes possible to additionally provide a path (the second path) via the IP communication network by making use of facilities for authentication in the cellular communication network, such as the first SIM and authentication device 20.

[0051] Furthermore, when the authentication device 20 "authenticates the DCM 10 connected via the ePDG", the communication from the DCM 10 is relayed to the security device 4. The fact that the DCM 10 is connected via the ePDG means that it is passing through an insecure network. Therefore, in such a case, the authentication device 20 relays the communication from the DCM 10 to a pre-specified security device 4.

[0052] Note that in the figure, there is one security device 4, but the security device 4 may be a plurality of devices that provide a plurality of security services. In this case, the authentication device 20 may determine which security device to relay the communication to for each connected DCM 10. Specific examples will be described later.

[0053] [Device Configuration] Next, the configuration of each device included in the system will be described. FIG. 3 is a diagram schematically showing an example of the configuration of the DCM 10 and the communication device 11 according to the present embodiment.

[0054] The DCM 10 can be configured as a computer having a processor (such as a CPU or GPU), a main storage device (such as a RAM or ROM), and an auxiliary storage device (such as an EPROM, a hard disk drive, or a removable medium). The auxiliary storage device stores an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions (software modules) that meet a predetermined purpose, as described later, can be realized. However, some or all of the functions may be realized as hardware modules by a hardware circuit such as an ASIC or FPGA.

[0055] The DCM 10 is configured to include a control unit 101, a storage unit 102, a wireless communication module 103, a CAN communication module 104, and an expansion interface 105.

[0056] The control unit 101 is an arithmetic unit that realizes various functions of the DCM 10 by executing a predetermined program. The control unit 101 can be realized by a hardware processor such as a CPU, for example. Also, the control unit 101 may be configured to include a RAM, a ROM (Read Only Memory), a cache memory, and the like.

[0057] In this embodiment, the control unit 101 included in the DCM 10 is configured to include a communication control unit 1011 as a software module. The software module may be realized by executing, by the control unit 101 (CPU), a program stored in the storage unit 102. Note that the information processing executed by the software module is synonymous with the information processing executed by the control unit 101 (CPU). The communication control unit 1011 establishes a network connection in response to a request from a vehicle component included in the vehicle 1. The communication control unit 1011 may be configured to be able to select a network to be used for the connection. For example, when a first SIM is inserted into the DCM 10, the DCM 10 can perform a network connection via a carrier network A. Also, when a communication device 11 having a second SIM is connected to the DCM 10, the DCM 10 can perform a network connection via a carrier network B. When a plurality of networks are available, the communication control unit 1011 may determine the network to be used for the connection based on the user's selection.

[0058] When performing a network connection via the carrier network A, the communication control unit 1011 receives authentication from the authentication device 20 using the profile information (first profile) stored in the first SIM.

[0059] When performing network connection via carrier network B, the communication control unit 1011 first executes a process of requesting the communication device 11 to connect to carrier network B. Second, after the communication device 11 connects to carrier network B, it interacts with the communication system 2 (authentication device 20) via carrier network B and executes a process of receiving authentication from the authentication device 20.

[0060] The storage unit 102 is a means for storing information and is composed of a storage medium such as a RAM, a magnetic disk, or a flash memory. The storage unit 102 stores programs executed by the control unit 101, data used by the programs, and the like.

[0061] The wireless communication module 103 is a communication device that performs wireless communication with a predetermined network. In the present embodiment, the wireless communication module 103 is configured to be capable of communicating with a predetermined cellular communication network (carrier network A). The wireless communication module 103 is configured to have a SIM card 103A. The SIM card 103A is the first SIM in FIG. 1. The SIM card 103A is configured as a microcomputer equipped with a CPU and a storage device. The SIM card 103A has information (PLMN information) for connecting to carrier network A and authentication information for receiving authentication from the communication system 2.

[0062] Also, the SIM card 103A (the first SIM) is configured to store a first profile that is SIM profile information. The first profile is a profile issued by an operator who manages the communication system 2. The first profile includes, for example, identification information such as IMSI (International Mobile Subscription Identity) and ICCID (Integrated Circuit Card ID), and authentication information (key information) for receiving SIM authentication including AKA authentication.

[0063] The CAN communication module 104 is a communication interface for connecting the DCM10 to the in-vehicle network of Vehicle 1. The CAN communication module 104 is, for example, a network interface that communicates according to the CAN (Controller Area Network) protocol. It may be configured to include a sub-board. The DCM10 can perform data communication with other components (such as in-vehicle terminals, etc.) of Vehicle 1 via the CAN communication module 104.

[0064] The extended interface 105 is an interface for mutually connecting the DCM10 and the communication device 11. The extended interface 105 is, for example, a USB interface. The DCM10 is configured to be connectable to the communication device 11 via, for example, a USB interface.

[0065] Next, the configuration of the communication device 11 will be described. The communication device 11 is configured to include a control unit 111, a storage unit 112, a wireless communication module 113, and an interface 114.

[0066] Similar to the control unit 101, the control unit 111 is an arithmetic unit that realizes various functions of the communication device 11 by executing a predetermined program. The control unit 111 can be realized by, for example, a hardware processor such as a CPU.

[0067] In this embodiment, the control unit 111 of the communication device 11 is configured to include a communication control unit 1111 as a software module. The software module may be realized by executing the program stored in the storage unit 112 by the control unit 111 (CPU). Note that the information processing executed by the software module is synonymous with the information processing executed by the control unit 111 (CPU).

[0068] In response to a request from the DCM 10, the communication control unit 1111 establishes a network connection. When there is a connection request from the DCM 10, the communication control unit 1111 makes a network connection via the carrier network B. At this time, the communication control unit 1111 receives authentication from a control device (MME) possessed by the carrier network B using the profile information (second profile) stored in the second SIM.

[0069] The storage unit 112 is a means for storing information and is composed of a storage medium such as a RAM, a magnetic disk, or a flash memory. In the storage unit 112, a program executed by the control unit 111, data used by the program, and the like are stored.

[0070] The wireless communication module 113 is a communication device that performs wireless communication with a predetermined network. In the present embodiment, the wireless communication module 113 is configured to be able to communicate with a predetermined cellular communication network (carrier network B). The wireless communication module 113 is configured to have a SIM card 113A. The SIM card 113A is the second SIM in FIG. 1. The SIM card 113A is configured as a microcomputer equipped with a CPU and a storage device. The SIM card 113A has information (PLMN information) for connecting to the carrier network B and authentication information for receiving authentication from the network. The second SIM may be a physical SIM card or an eSIM or the like.

[0071] Also, the SIM card 113A (second SIM) is configured to store a second profile that is SIM profile information. The second profile is a profile issued by a telecommunications carrier that manages the carrier network B. Similar to the first profile, the second profile is configured to include identification information such as an IMSI and an ICCID, and authentication information (key information) for receiving SIM authentication.

[0072] Interface 114 is an interface for mutually connecting DCM10 and communication device 11. Communication device 11 is configured to be connectable to DCM10 via an interface such as USB, for example.

[0073] Next, the configuration of authentication device 20 will be described. FIG. 4 is a diagram schematically showing an example of the configuration of authentication device 20 according to the present embodiment. Authentication device 20 is configured as a computer having a control unit 201, a storage unit 202, and a communication module 203.

[0074] Authentication device 20 can be configured as a computer having a processor (such as a CPU or GPU), a main storage device (such as a RAM or ROM), and an auxiliary storage device (such as an EPROM, a hard disk drive, or a removable medium). However, some or all of the functions (software modules) may be realized as hardware modules by a hardware circuit such as an ASIC or an FPGA, for example.

[0075] Control unit 201 is an arithmetic unit that realizes various functions (software modules) of authentication device 20 by executing a predetermined program. Control unit 201 can be realized by a hardware processor such as a CPU, for example.

[0076] In the present embodiment, control unit 201 included in authentication device 20 is configured to have two software modules: a terminal authentication unit 2011 and a security processing unit 2012. Each software module may be realized by executing a program stored in storage unit 202 by control unit 201 (CPU). Note that the information processing executed by the software module is synonymous with the information processing executed by control unit 201 (CPU).

[0077] Terminal authentication unit 2011 receives a request from DCM10 and executes a process of authenticating DCM10. The authentication process can be executed, for example, according to the following sequence defined by 3GPP. (1) Process of receiving an Attach Request from DCM10 (2) Process of sending a request (Authentication data Request) for obtaining authentication-related data to HS S (3) Process of obtaining authentication-related data (Authentication data response) from HSS (4) Process of sending a challenge (User Authentication Request) to DCM10 (5) Process of receiving a response (User Authentication Response) from DCM10 (6) Process of verifying the validity of DCM10 based on the response In addition, the terminal authentication unit 2011 may also execute processes necessary for registering DCM10 in the communication system 2.

[0078] The security processing unit 2012 performs processes for providing security services to DCM10 connected to the communication system 2. As described above, when DCM10 is connected to the communication system 2 via the ePDG, since it passes through an unsecured IP communication network, the security of communication is not guaranteed. Therefore, the security processing unit 2012 executes a process of relaying communication from DCM10 connected via the ePDG to the security device 4. As the security device 4, a device that monitors communication and detects or blocks harmful data can be exemplified.

[0079] In addition, when a plurality of devices are used as the security device 4, data associating the identifier of DCM10 (or the identifier of the first profile) with the identifier of the device to which the relay destination is (hereinafter, security setting data. An example of the "association data" in the present disclosure) may be used. Thereby, it becomes possible to provide different services for each subscriber. For example, it becomes possible to "provide an antivirus service for DCM10A and a sandbox service for DCM10B".

[0080] Figure 4 shows an example of security setting data. In the example of Figure 4, the identifier of the first profile, the necessity of the security service (security flag), and the identifier of the security device (security device ID) to which the data is transferred are associated. Note that the service provided to each DCM may be specified by the user of the DCM (that is, vehicle 1). For example, when the user subscribes to a communication service, the security service may be specified as an optional subscription, and based on this, the security setting data used by the authentication device 20 may be generated. Note that the security setting data may be stored in the authentication device 20 (storage unit 202), or may be stored in an external device that manages the communication contract, and the authentication device 20 may acquire it.

[0081] The storage unit 202 is a means for storing information, and is composed of a storage medium such as a RAM, a magnetic disk, or a flash memory. The storage unit 202 stores a program executed by the control unit 201, data used by the program, and the like.

[0082] The communication module 203 is a communication interface for connecting the authentication device 20 to the communication system 2. Data communication can be performed between the authentication device 20 and other devices arranged in the communication system 2 via the communication module 203.

[0083] [Flowchart] Next, the details of the process executed when the DCM 10 is connected to the communication system 2 will be described. Figure 6 is a flowchart of the process executed when the DCM 10 is connected to the communication system 2.

[0084] First, in step S11, the communication control unit 1011 of the DCM 10 determines the network to be used for connection. For example, when a valid first SIM is inserted into the DCM 10, the communication control unit 1011 can determine to perform the connection using the carrier network A shown in FIG. 1. Note that when a valid first SIM is not inserted into the DCM 10 or when the communication device 11 is connected to the DCM 10, the communication control unit 1011 may determine to perform network connection via the communication device 11 (carrier network B). Note that when multiple networks are available, it may be determined which network to use based on the selection made by the user.

[0085] Next, in step S12, the communication control unit 1011 determines whether the network to be used for connection is a direct connection via the cellular communication network or a connection via tethering. The direct connection via the cellular communication network is a form in which the DCM 10 uses the built-in wireless communication module 103 to connect to the communication system 2 via the carrier network A. The connection via tethering is a form in which the communication device 11 connected to the DCM 10 connects to the carrier network B, and the DCM 10 connects to the communication system 2 via the communication device 11 via the IP communication network.

[0086] When the network to be used for connection is a direct connection via the cellular communication network, the process transitions to step S13. When the network to be used for connection is a connection via tethering, the process transitions to step S14.

[0087] In step S13, the communication control unit 1011 sends an authentication request to the carrier network A, and the communication system 2 authenticates the DCM 10. In this step, the communication control unit 1011 transmits an authentication request to the carrier network A, for example, via the base station of the carrier network A. The authentication request may be data for starting the authentication procedure (e.g., an attach request defined by 3GPP), or may include physical data necessary for authentication. The authentication request reaches the communication system 2 via the carrier network A. For example, the MME of the carrier network A that has received the authentication request may transfer the authentication request to the authentication device 20 of the communication system 2. The MME of the carrier network A may transfer the authentication request to the authentication device 20 of the communication system 2.

[0088] Next, the authentication device 20 of the communication system 2 starts the authentication of the DCM10 according to the authentication request. For example, the authentication device 20 requests data for authentication (hereinafter referred to as authentication-related data) from the HSS of the communication system 2. The authentication device 20 authenticates the DCM10 using the received authentication-related data and the information recorded in the first SIM of the DCM10 (details will be described later). When the authentication device 20 successfully authenticates the DCM10, the communication system 2 establishes communication paths in the control plane and the user plane. As a result, the DCM10 becomes capable of communicating with the server device 3 via the P-GW of the communication system 2.

[0089] When the process transitions to step S14, the DCM10 instructs the communication device 11 to establish a network connection. In response, the communication device 11 starts a connection using the carrier network B. Specifically, the control unit 111 of the communication device 11 transmits an authentication request to the carrier network B via the base station of the carrier network B. The authentication request is received by the MME of the carrier network B, and the MME authenticates the communication device 11 based on the authentication-related data obtained from the HSS. The profile information stored in the second SIM is used for the authentication. When the authentication is completed, a communication path is established between the communication device 11 and the carrier network B, and as a result, the communication device 11 becomes capable of communicating with the IP communication network via the P-GW.

[0090] When the communication device 11 becomes capable of communicating with the IP communication network, in step S15, authentication is started between the DCM 10 and the communication system 2. In step S15, the DCM 10 transmits an authentication request to the communication system 2 via a path through the tethering destination carrier network (i.e., carrier network B). The authentication request reaches the communication system 2 via the IP communication network and the ePDG and is received by the authentication device 20.

[0091] Next, the authentication device 20 starts the authentication of the DCM 10 according to the received authentication request. The authentication procedure is the same as that described in step S13. That is, also in this step, the authentication of the DCM 10 is executed based on the profile information stored in the first SIM. When the authentication device 20 succeeds in authenticating the DCM 10, the communication system 2 establishes a communication path. As a result, the DCM 10 connected to the communication system 2 via the ePEG becomes capable of communicating with the server device 3 via the P-GW.

[0092] When the communication path of the DCM 10 is established in step S15, the process transitions to step S16. In step S16, the security processing unit 2012 determines a security device 4 that relays the communication from the DCM 10. In this step, for example, the security service to be provided to the target DCM 10 may be determined by referring to the security setting data. In subsequent communications, all data from the DCM 10 is transmitted to the destination server device 3 via the security device 4. Note that there may be a plurality of security devices 4 that relay the communication from the DCM 10.

[0093] Note that the process in step S16 may be executed only when the communication destination of the DCM 10 is a device on the Internet and the communication does not end within the communication system 2. This is because when the communication from the DCM 10 ends within the communication system 2, it may be considered that a certain level of security is ensured.

[0094] Return to step S13 and continue the explanation. When authentication is completed in step S13, the process transitions to step S17 to determine whether to use the security service. If the DCM 10 is connected to the communication system 2 via the cellular communication network, it can be said that the communication path up to the communication system 2 is secure. On the other hand, when the destination of the communication from the DCM 10 is a device on the Internet, since it passes through an insecure path, it may be better to provide a security service to the DCM 10. In such a case, the process transitions to step S16. If the security service is not used, the process ends.

[0095] As described above, the DCM 10 according to the present embodiment is configured to be able to connect the communication device 11, and can communicate with the communication system 2 via an arbitrary cellular communication network through the communication device 11. Further, the authentication device 20 in the communication system 2 relays the communication from the DCM 10 connected via the ePDG to a predetermined security device. Thereby, even when the DCM 10 accesses the communication system 2 via an insecure communication network, it becomes possible to provide a security service to the DCM 10.

[0096] Also, by using the security setting data, different security services can be provided for each subscriber.

[0097] (Modification example) The above embodiment is merely an example, and the present disclosure can be appropriately modified and implemented without departing from the gist thereof. For example, the processes and means described in the present disclosure can be freely combined and implemented as long as no technical contradiction occurs.

[0098] Also, in the description of the embodiment, as the standard of the cellular communication network, 4G (LTE - Advance Although (d) has been exemplified, communication standards such as 3G and 5G can also be adopted. In this case, the ePDG can be replaced with an N3IWF (non-3GPP Interworking Function) (in the case of 5G), a PDG (in the case of 3G), etc. Also, in the description of the embodiment, the DCM10 has been exemplified as a mobile communication terminal, but the mobile communication terminal may be an IoT terminal or the like.

[0099] Also, in the description of the embodiment, the DCM10 has been made connectable to the carrier network A, but the DCM10 does not necessarily have to have the wireless communication module 103 and may not have a function of connecting to the carrier network A either. That is, the DCM10 may be an essential configuration for performing communication via the communication device 11. Even in this case, the DCM10 receives authentication from the authentication device 20 using the profile information stored in the first SIM. In such a configuration, the first SIM is not used for connecting to the carrier network and is used only for authentication.

[0100] Also, in the description of the embodiment, an example of authenticating the DCM10 using the profile information stored in the SIM has been given, but the DCM10 may be authenticated by other methods. For example, the DCM10 may hold a pair of key information and an electronic certificate (issued by a certification authority, for example) for proving the authenticity of the key information in the storage unit 102. The authentication device 20 can also authenticate the DCM10 using such information. In any case, authentication is executed using the same authentication information regardless of the communication path.

[0101] Also, the processing described as being performed by one device may be executed in a distributed manner by a plurality of devices. Alternatively, the processing described as being performed by different devices may be executed by one device. In a computer system, it is flexibly changeable how each function is realized by what kind of hardware ware configuration (server configuration).

[0102] The present disclosure can also be realized by supplying a computer program that implements the functions described in the above embodiments to a computer and causing one or more processors included in the computer to read and execute the program. Such a computer program may be provided to the computer by a non-transitory computer-readable storage medium connectable to the system bus of the computer, or may be provided to the computer via a network. The non-transitory computer-readable storage medium includes, for example, any type of disk such as a magnetic disk (e.g., a floppy (registered trademark) disk, a hard disk drive (HDD), etc.), an optical disk (e.g., a CD-ROM, a DVD disk, a Blu-ray disk, etc.), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, and any type of medium suitable for storing electronic instructions.

Description of Reference Numerals

[0103] 1 ··· Vehicle 2 ··· Communication system 3 ··· Server device 4 ··· Security device 10 ··· DCM 11 ··· Communication device 20 ··· Authentication device

Claims

1. An information processing apparatus disposed in a communication system, comprising: a storage unit that stores authentication data for authenticating a mobile communication terminal; and a gateway that accommodates access from a first communication network, wherein the mobile communication terminal connected via the first communication network and the gateway is authenticated using the authentication data, and having a control unit that relays communication from the mobile communication terminal to one or more security devices based on information related to the authentication. Information processing apparatus.

2. The information related to the authentication includes an identifier of the mobile communication terminal. The information processing apparatus according to claim 1.

3. The control unit acquires association data associating the mobile communication terminal with a security device that is a relay destination of communication from the mobile communication terminal, and determines the security device that relays communication from the mobile communication terminal based on the association data. The information processing apparatus according to claim 2.

4. The control unit relays communication from the mobile communication terminal to the one or more security devices when a destination of communication from the mobile communication terminal is not a device within the communication system. The information processing apparatus according to claim 1.

5. A communication system, comprising: a storage unit that stores authentication data for authenticating a mobile communication terminal; a gateway that accommodates access from a first communication network; authenticating the mobile communication terminal connected via the first communication network and the gateway using the authentication data; relaying communication from the mobile communication terminal to one or more security devices based on information related to the authentication; and a control unit that executes the above. Communication system.

Citation Information

Patent Citations

  • On-vehicle communication device

    JP2016025505A