Communication method, communication system, security control device, terminal device, and program
The communication system addresses the issue of variable 5G security by using a security control device to verify and enhance security functions, ensuring secure connections in 5G systems.
Patent Information
- Application Number
- JP2024026463
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-26
- Publication Date
- 2025-09-05
AI Technical Summary
In 5G communication systems, the integrity verification of user traffic is not a mandatory function, leading to potential tampering of user data, and existing security functions may not meet the strength required by standards like WPA3 Enterprise mode, with no way for user terminals to ascertain the security capabilities of connected systems.
A communication method and system that includes a security control device to check the security requirements of a terminal device against the capabilities of a base station, initiating additional security functions if necessary to ensure secure communication.
Ensures secure communication by enabling the terminal device to establish secure connections even when the base station does not meet the required security standards, using a security control device to verify and enhance security functions as needed.
Smart Images

Figure 2025129676000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to communication technology, and more particularly to communication technology that enables a communication system including a base station and a user terminal device to provide a communication service with a security level required by the user terminal device, regardless of the security function support status of the base station or the location where the communication service is used by the user terminal device. [Background technology]
[0002] 5G (5th generation mobile communication system) is a communication system that can realize communication characterized by high speed, large capacity, low latency, and multiple connections, and has been used for many purposes in recent years. 5G is a communication system that uses a mobile communication network, and security specifications have been defined (see Non-Patent Document 1). In a communication system that complies with the 5G standard, the communication control device (5G core device), base station, etc. that constitute the system must satisfy the 5G security specifications. [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] 3GPP, TS 33.501 Security architecture and procedures for 5G system (Release 17). [Non-patent document 2] David Rupprecht, et., al., IMP4GT: IMPersonation Attacks in 4G NeTworks, NDSS 2022. Summary of the Invention [Problem to be solved by the invention]
[0004] However, in the 5G security specifications (specifications defined in Non-Patent Document 1), integrity verification of user traffic (user plane) is not a required function but an optional one. In other words, even base stations and communication devices that comply with the 5G specifications may not have the function to verify the integrity of user traffic. As such, even base stations and communication devices that comply with the 5G specifications may have different security functions, such as not supporting the integrity verification function for user traffic. Therefore, depending on the user's location, if the base stations installed in the vicinity of that location do not support the integrity verification function, the integrity of the user's traffic cannot be guaranteed. For example, the attack method described in Non-Patent Document 2 allows tampering with user traffic by acting as an intermediary between the user's communication terminal and the base station when the integrity verification of user traffic is not enabled.
[0005] If a base station or communication device that complies with the 5G specifications does not support an integrity verification function for user traffic, the traffic may be tampered with by the attack method described in Non-Patent Document 2.
[0006] Furthermore, even if security strength beyond that specified in the 5G specifications is required, it is highly unlikely that base stations will provide security functions that exceed the specifications. For example, the 5G specifications stipulate that the encryption algorithm used to encrypt communications must have 128-bit security (a key length of 128 bits). Meanwhile, the Wi-Fi security specification, WPA3, stipulates the use of an encryption algorithm with 192-bit security (a key length of 192 bits) in Enterprise mode. In a 5G environment, it will be difficult to enjoy security strength equivalent to that of WPA3 Enterprise mode.
[0007] One possible solution when there are concerns about the security functions of the communication system is to use the VPN function (VPN: Virtual Private Network) of the user's communication terminal. However, with 5G, there is currently no way for an application installed on a user's communication terminal to ascertain the security functions provided by the 5G system to which the user is connected. Therefore, in order to realize a method in 5G for using the VPN function of a user's communication terminal when there are concerns about the security functions of the communication system, the 5G communication module equipped in the communication terminal needs to be equipped with a new function that provides information about the security functions provided by the 5G system to the application. Therefore, it is difficult to newly equip communication terminals and 5G communication modules already on the market with the above function and realize the above method (a method for using the VPN function of a user's communication terminal when there are concerns about the security functions of the communication system).
[0008] Furthermore, there are no specifications for the interface that allows the communications module within the communications terminal to provide the above information (information about the security functions provided by the connected 5G system) to applications, and so it will be necessary for a standardization organization to formulate a standard specification, or for specifications to be formulated and agreed upon by both the communications terminal development vendor and the communications module development vendor.
[0009] Therefore, in view of the above problems, the present invention aims to realize a communication system, a communication method, a security control device, a terminal device, and a program that realize the security function required by a communication terminal and enable secure communication in a communication system (e.g., a 5G communication system) even if the security function required by the communication terminal cannot be provided at the current location of the communication terminal. [Means for solving the problem]
[0010] In order to solve the above problems, a representative example (one aspect) of the invention disclosed in this application is a communication method executed in a communication system including a terminal device, a base station capable of communicating with the terminal device and also capable of communicating with a communication device installed in a core network, a communication control device installed in the core network, capable of acquiring information on security functions that can be provided by the base station, and capable of communicating with the base station and an external data network, a security control device, and a security communication device installed in the core network, capable of performing secure communication with the terminal device and also capable of communicating with an external data network. The communication method includes a first step and a second step.
[0011] In the first step, the security control device (1) receiving, from a base station, security requirements of a terminal device requesting connection to the base station; (2) Obtaining base station security function information, which is information about security functions that can be provided by the base station, from the communication control device; (3) Checking the security requirements against the base station security function information, and determining whether the base station can achieve secure communication that satisfies the security requirements; (4) If the determination process determines that the base station cannot achieve secure communication that meets the security requirements, the base station transmits to the base station determination process result data, which is data including the results of the determination process, or a second security function usage notification, which is a notification requesting the terminal device to use the second security function.
[0012] In the second step, the terminal device: (1) receiving, via the base station, the determination processing result data or the second security function usage notification from the security control device; (2) If the judgment processing result data indicates that secure communication that satisfies the security requirements cannot be achieved, or if a second security function usage notification is received, a process that realizes the second security function is initiated, and a process that establishes a secure communication connection that satisfies the security requirements with the security communication device is performed. [Effects of the Invention]
[0013] According to the present invention, in a communication system (e.g., a 5G communication system), even if the security function required by a communication terminal cannot be provided at the current location of the communication terminal, it is possible to realize a communication system, a communication method, a security control device, a terminal device, and a program that realize the security function required by the communication terminal and enable secure communication. [Brief explanation of the drawings]
[0014] [Figure 1] 1 is a schematic configuration diagram of a communication system 1000 according to a first embodiment. [Figure 2] 1 is a schematic configuration diagram of a terminal device 1 according to a first embodiment. [Figure 3] FIG. 2 is a schematic configuration diagram of a base station 2 according to the first embodiment. [Figure 4] FIG. 2 is a schematic configuration diagram of a communication control device 3 according to the first embodiment. [Figure 5] 1 is a schematic configuration diagram of a security control device 4 according to a first embodiment. [Figure 6] FIG. 3 is a sequence diagram of processing executed in the communication system 1000. [Figure 7] FIG. 3 is a sequence diagram of processing executed in the communication system 1000. [Figure 8] FIG. 10 is a schematic configuration diagram of a communication system 1000A according to a first modified example of the first embodiment. [Figure 9] FIG. 10 is a sequence diagram of processing executed in a communication system 1000A. [Figure 10] FIG. 10 is a schematic configuration diagram of a communication system 2000 according to a second embodiment. [Figure 11]FIG. 10 is a schematic configuration diagram of a base station 2A according to a second embodiment. [Figure 12] FIG. 10 is a schematic configuration diagram of a communication control device 3A according to a second embodiment. [Figure 13] FIG. 3 is a sequence diagram of processing executed in the communication system 1000. [Figure 14] FIG. 3 is a sequence diagram of processing executed in the communication system 1000. [Figure 15] FIG. 10 is a schematic configuration diagram of a communication system 2000A according to a first modified example of the second embodiment. [Figure 16] FIG. 10 is a sequence diagram of processing executed in a communication system 2000A. [Figure 17] FIG. 10 is a sequence diagram of processing executed in a communication system 2000A. [Figure 18] FIG. 10 is a sequence diagram of processing executed in a communication system 2000A. [Figure 19] A diagram showing the CPU bus configuration. DETAILED DESCRIPTION OF THE INVENTION
[0015] [First embodiment] The first embodiment will be described below with reference to the drawings.
[0016] <1.1: Communication system configuration> FIG. 1 is a schematic configuration diagram of a communication system 1000 according to the first embodiment.
[0017] FIG. 2 is a schematic configuration diagram of the terminal device 1 according to the first embodiment.
[0018] FIG. 3 is a schematic configuration diagram of the base station 2 according to the first embodiment.
[0019] FIG. 4 is a schematic configuration diagram of the communication control device 3 according to the first embodiment.
[0020] FIG. 5 is a schematic configuration diagram of the security control device 4 according to the first embodiment.
[0021] 1, the communication system 1000 includes one or more terminal devices 1, a base station 2 installed in, for example, a RAN (Radio Access Network), a communication control device 3 installed in, for example, a switching center Cntr1, a security control device 4, and a security communication device 5. The communication control device 3 is connected to a data network DataNW (for example, the Internet) and can communicate with communication devices (for example, servers, routers, gateways, etc.) connected to the data network DataNW.
[0022] In FIG. 1, the RAN includes one base station 2, but is not limited to this and may include multiple base stations (for example, one or more aggregation base stations and one or more distributed base stations connected to each of the aggregation base stations).
[0023] Furthermore, the communication control device 3 and the base station 2 of the RAN may be connected via a network (not shown) (for example, a mobile phone communication network (for example, a 4G / LTE communication network or a 5G communication network (5G: fifth generation mobile communication system))). Furthermore, the communication control device 3 and the security control device 4 may be connected via a network (not shown) (for example, a core network (for example, a 5G core network)), or may be directly connected. Furthermore, the communication control device 3 and the security communication device 5 may be connected via a network (not shown) (for example, a core network (for example, a 5G core network)). Furthermore, when connecting the communication devices via a network, a gateway device, a router, or the like may be installed at a predetermined position in the network to enable communication.
[0024] (1.1.1: Terminal Device Configuration) 1 and 2, the terminal device 1 includes a control unit 11, a storage unit 12, a data communication processing unit 13, a terminal-side communication interface 14, and a bus Bus 1. The control unit 11, the storage unit 12, and the data communication processing unit 13 are connected to the bus Bus 1, and can transmit and receive data, commands, control signals, etc., via the bus Bus 1.
[0025] The control unit 11 is a functional unit that controls each functional unit of the terminal device 1, and is realized by, for example, a processor or a CPU. The control unit 11 is connected to a bus Bus1, and can transmit and receive data, commands, and / or control signals, etc., with the storage unit 12 and the data communication processing unit 13 via the bus Bus1. Note that some or all of the control unit 11, the storage unit 12, and / or the data communication processing unit 13 may be directly connected without going through a bus, and transmit and receive data, commands, and / or control signals, etc.
[0026] The storage unit 12 is a functional unit (storage device) that can store data and the like, and stores security function modules.
[0027] The data communication processing unit 13 receives data output from each functional unit of the terminal device 1 via the bus Bus1. The data communication processing unit 13 performs predetermined data communication processing on the received data (for example, converting the data into a format that can be transmitted to the RAN (base station 2)). The data communication processing unit 13 then outputs the data acquired through the above-mentioned data communication processing to the terminal-side communication interface 14. The data communication processing unit 13 also receives data output from the terminal-side communication interface 14 and performs predetermined data communication processing on the data (for example, analyzing the header of an IP packet, acquiring predetermined data from received data, etc.). The data communication processing unit 13 then outputs the data acquired through the data communication processing to a predetermined functional unit via the bus Bus1.
[0028] The terminal-side communication interface 14 is a communication interface for performing data communication with devices within the RAN (e.g., the base station 2) and the like. The terminal-side communication interface 14 performs RF processing, data conversion processing, etc. on data received from the outside (RAN) to convert the data received from the outside (RAN) into data in a format that can be processed by the data communication processing unit 13, and outputs the converted data to the data communication processing unit 13. In addition, the terminal-side communication interface 14 performs RF processing, data conversion processing, etc. on data to be transmitted from the terminal device 1 to the outside (RAN) (data output from the data communication processing unit 13), to convert the data output from the data communication processing unit 13 into data (signals) in a format that can be transmitted to the outside (RAN), and transmits the converted data (signals) to the outside (RAN (e.g., the base station 2)).
[0029] (1.1.2: Base Station Configuration) The base station 2 is a device (communication base station) installed in the RAN and capable of communicating with the terminal device 1 (one or more terminal devices) by, for example, wireless communication. The base station 2 is also communicably connected to the communication control device 3 via, for example, a wired line.
[0030] For example, as shown in Figure 3, the base station 2 includes a first communication interface 21, a base station C-plane signal processing unit 22, a base station U-plane signal processing unit 23, a memory unit 24, a second communication interface 25, and a bus Bus2. As shown in Figure 3, the base station C-plane signal processing unit 22, the base station U-plane signal processing unit 23, and the memory unit 24 are connected to the bus Bus2, and can transmit and receive data, commands, and / or signals (control signals, etc.) via the bus Bus2. Note that some or all of the base station C-plane signal processing unit 22, the base station U-plane signal processing unit 23, and the memory unit 24 may be directly connected without going through a bus, and transmit and receive data, commands, and / or control signals, etc.
[0031] The first communication interface 21 is an interface for communicating with the terminal device 1 (one or more terminal devices) via wireless communication. The first communication interface 21 performs RF processing, data conversion processing, etc. on data received from the outside (e.g., the terminal device 1) to acquire C-plane data and / or U-plane data from the data (received signal) received from the outside (e.g., the terminal device 1), and outputs the acquired C-plane data (data for the control plane) to the C-plane signal processing unit 22 for the base station, and also outputs the acquired U-plane data (data for the user plane) to the U-plane signal processing unit 23 for the base station. The first communication interface 21 also inputs the C-plane data output from the C-plane signal processing unit 22 for the base station and the U-plane data output from the U-plane signal processing unit 23 for the base station. Then, the first communication interface 21 performs RF processing, data conversion processing, etc. on the input C-plane data and / or U-plane data to convert the input C-plane data and / or U-plane data into data (signals) in a format that can be transmitted to the outside (e.g., terminal device 1), and transmits the converted data (signals) to the outside (e.g., terminal device 1).
[0032] "C-plane" stands for Control plane, and refers to the data, signals, procedures, or mechanisms that control communications in a communications system (e.g., a wireless communications system). "U-plane" stands for User plane, and refers to the data, procedures, or mechanisms that users send and receive in a communications system (e.g., a wireless communications system).
[0033] The C-plane signal processing unit 22 for the base station is a functional unit that performs signal processing on C-plane data. In addition, the C-plane signal processing unit 22 for the base station performs processing for transmitting and receiving C-plane data with the communication control device 3 via the second communication interface 25, and / or processing using C-plane data (C-plane signal processing for the base station (on the communication control device side)). In addition, the C-plane signal processing unit 22 for the base station performs processing for transmitting and receiving C-plane data with one or more terminal devices (e.g., terminal device 1) via the first communication interface 21, and / or processing using C-plane data (C-plane signal processing for the base station (on the terminal device side)).
[0034] In addition, the C-plane signal processing unit 22 for the base station outputs data acquired by the C-plane signal processing for the base station that needs to be stored and maintained in the base station 2 to the memory unit 24 via the bus Bus2, and stores the data in the memory unit 24.
[0035] The U-plane signal processing unit 23 for the base station is a functional unit that performs signal processing on U-plane data. The U-plane signal processing unit 23 for the base station also performs processing for transmitting and receiving U-plane data with the communication control device 3 via the second communication interface 25, and / or processing using the U-plane data (U-plane signal processing for the base station (on the communication control device side)). The U-plane signal processing unit 23 for the base station also performs processing for transmitting and receiving U-plane data with one or more terminal devices (e.g., terminal device 1) via wireless communication, for example, and / or processing using the U-plane data (U-plane signal processing for the base station (on the terminal device side)).
[0036] In addition, the U-plane signal processing unit 23 for the base station outputs data acquired by the U-plane signal processing for the base station that needs to be stored and maintained in the base station 2 to the memory unit 24 via the bus Bus2, and stores the data in the memory unit 24.
[0037] The storage unit 24 is a functional unit that stores data. The storage unit 24 is connected to the bus Bus2, and performs data write processing and / or data read processing based on commands from each functional unit of the base station 2.
[0038] The second communication interface 25 is a communication interface for transmitting and receiving data to and from the communication control device 3 (a device of a core network (e.g., a 5G core device)). Also, as shown in FIG. 3, the second communication interface 25 is connected to the C-plane signal processing unit 22 for the base station and the U-plane signal processing unit 23 for the base station.
[0039] The second communication interface 25 outputs C-plane data received from the communication control device 3 to the C-plane signal processing unit 22 for the base station, and also inputs C-plane data output from the C-plane signal processing unit 22 for the base station and transmits the U-plane data to the outside (communication control device 3).
[0040] In addition, the second communication interface 25 outputs U-plane data received from the communication control device 3 to the U-plane signal processing unit 23 for the base station, and also inputs U-plane data output from the U-plane signal processing unit 23 for the base station and transmits the U-plane data to the outside (communication control device 3).
[0041] (1.1.3: Configuration of communication control device) The communication control device 3 is, for example, a device (e.g., a 5G core device) installed in a switching center Cntr1 (e.g., a switching center that connects a 5G (fifth generation mobile communication system) transmission network with an external network (e.g., the Internet) and performs communication), and is communicatively connected to a data network DataNW and a RAN (e.g., one or more base stations (e.g., base station 2) within the RAN). The communication control device 3 has a function of controlling communication between the data network DataNW, the RAN, and / or terminal devices.
[0042] Furthermore, the communication control device 3 is communicably connected to the security control device 4 and the security communication device 5 via, for example, a wired line (or a wireless line).
[0043] As shown in Fig. 4, the communication control device 3 includes a third communication interface 31, a C-plane signal processing unit 32, a U-plane signal processing unit 33, a memory unit 34, a data communication processing unit 35, a fourth communication interface 36, and a bus Bus3. As shown in Fig. 3, the C-plane signal processing unit 32, the U-plane signal processing unit 33, the memory unit 34, and the data communication processing unit 35 are connected to the bus Bus3, and can transmit and receive data, commands, and / or signals (control signals, etc.) via the bus Bus3. Note that some or all of the C-plane signal processing unit 32, the U-plane signal processing unit 33, the memory unit 34, and the data communication processing unit 35 may be directly connected without using a bus, and transmit and receive data, commands, and / or control signals, etc.
[0044] The third communication interface 31 is a communication interface for transmitting and receiving data to and from the RAN (a device within the RAN (e.g., a base station 2)). Also, as shown in FIG. 4, the third communication interface 31 is connected to a C-plane signal processing unit 32 and a U-plane signal processing unit 33.
[0045] The third communication interface 31 outputs C-plane data received from the outside (RAN) to the C-plane signal processing unit 32, and also inputs C-plane data output from the C-plane signal processing unit 32 and transmits the U-plane data to the outside (RAN).
[0046] In addition, the third communication interface 31 outputs U-plane data received from the outside (RAN) to the U-plane signal processing unit 33, and also inputs U-plane data output from the U-plane signal processing unit 33 and transmits the U-plane data to the outside (RAN).
[0047] The C-plane signal processing unit 32 performs processing (C-plane signal processing) for transmitting and receiving C-plane data with the RAN via the third communication interface 31.
[0048] The C-plane signal processing unit 32 also receives input of data necessary for C-plane control from the data communication processing unit 35. The C-plane signal processing unit 32 also outputs to the data communication processing unit 35 data acquired by C-plane signal processing and necessary for data communication processing by the data communication processing unit 35.
[0049] In addition, the C-plane signal processing unit 32 outputs data acquired by C-plane signal processing that needs to be stored and held in the communication control device 3 to the memory unit 34 via the bus Bus3, and stores the data in the memory unit 34.
[0050] The U-plane signal processing unit 33 performs processing (U-plane signal processing) for transmitting and receiving U-plane data with the RAN via the third communication interface 31.
[0051] Furthermore, the U-plane signal processing unit 33 receives data necessary for performing U-plane signal processing via the fourth communication interface 36, the data communication processing unit 35, and the bus Bus 3. The U-plane signal processing unit 33 then performs predetermined U-plane signal processing on the received data.
[0052] Furthermore, the U-plane signal processing unit 33 outputs to the data communication processing unit 35 the data acquired by the U-plane signal processing and necessary for the data communication processing by the data communication processing unit 35 .
[0053] In addition, the U-plane signal processing unit 33 outputs data acquired by U-plane signal processing that needs to be stored and held in the communication control device 3 to the memory unit 34 via the bus Bus3, and stores the data in the memory unit 34.
[0054] The storage unit 34 is a functional unit that stores data. The storage unit 34 is connected to the bus Bus 3, and performs data write processing and / or data read processing based on commands from each functional unit of the communication control device 3.
[0055] The data communication processing unit 35 inputs data output from the fourth communication interface 36 and performs predetermined data communication processing on the data (for example, IP packet header analysis processing, processing to acquire predetermined data from received data, etc.). The data communication processing unit 35 outputs data acquired by the data communication processing that is necessary for C-plane signal processing to the C-plane signal processing unit 32 via the bus Bus3, and also outputs data acquired by the data communication processing that is necessary for U-plane signal processing to the U-plane signal processing unit 33 via the bus Bus3. In addition, the data communication processing unit 35 converts data input from each functional unit of the communication control device 3 via the bus Bus3 into data in a format that can be transmitted to the outside (security control device 4, data network DataNW, or security communication device 5) via the fourth communication interface 36, and outputs the data to the fourth communication interface 36. In addition, the data communication processing unit 35 outputs data acquired by the data communication processing that needs to be stored and held in the communication control device 3 to the memory unit 34 via the bus Bus3, and stores the data in the memory unit 34.
[0056] The fourth communication interface 36 is a communication interface for transmitting and receiving data with a communication device connected to the data network DataNW, and is also a communication interface for transmitting and receiving data with the security control device 4 and / or the security communication device 5 via a wired or wireless line. In addition, the fourth communication interface 36 is connected to the data communication processing unit 35 as shown in FIG.
[0057] The fourth communication interface 36 converts data received from the outside (the data network DataNW, the security control device 4, and / or the security communication device 5, etc.) into data in a format that can be processed by the data communication processing unit 11, and outputs the converted data to the data communication processing unit 35. In addition, the fourth communication interface 36 converts data (data output from the data communication processing unit 35) to be transmitted from the communication control device 3 to the outside (the data network DataNW, the security control device 4, and / or the security communication device 5, etc.) into data (signals) in a format that can be transmitted to the outside (the data network DataNW, the security control device 4, and / or the security communication device 5, etc.), and transmits the converted data (signals) to the outside (the data network DataNW, the security control device 4, and / or the security communication device 5, etc.).
[0058] (1.1.4: Security control device configuration) The security control device 4 is communicably connected to the communication control device 3 via, for example, a wired line (or a wireless line).
[0059] 5, the security control device 4 includes a fifth communication interface 41, a security control processing unit 42, a storage unit 43, and a bus 4. Note that some or all of the fifth communication interface 41, the security control processing unit 42, and the storage unit 43 may be directly connected without using a bus to transmit and receive data, commands, and / or control signals.
[0060] The fifth communication interface 41 is a communication interface for transmitting and receiving data to and from an external device (for example, the communication control device 3) via a wired or wireless line. The fifth communication interface 41 is connected to the bus Bus4 as shown in Fig. 5, and transmits and receives data, commands, and / or control signals, etc. to and from each functional unit of the security control device 4 via the bus Bus4.
[0061] The security control processing unit 42 receives data transmitted from the communication control device 3 via the fifth communication interface 41 and the bus Bus 4, and performs security control processing on the data. The security control processing unit 42 also outputs data including the results of the security control processing to the fifth communication interface 41 via the bus Bus 4. The security control processing unit 42 also outputs data acquired by the security control processing that needs to be stored and held in the security control device 4 to the memory unit 43 via the bus Bus 4, and stores the data in the memory unit 43.
[0062] The storage unit 43 is a functional unit that stores data. The storage unit 43 is connected to the bus Bus 4, and performs data writing and / or data reading processes based on commands from each functional unit of the security control device 4.
[0063] (1.1.5: Security communication devices) The security communication device 5 is a communication device (for example, a VPN server, a secure server, a VPN router, a secure router, a UTM device (UTM: Unified Threat Management), etc.) for realizing secure communication (secure communication). The security communication device 5 is installed, for example, in the exchange Cntr1 (or in the core network), and is communicatively connected to the communication control device 3 via a wired or wireless line. The security communication device 5 is also a device that can communicate with communication devices connected to the data network DataNW via the data network Data.
[0064] <1.2: Operation of the communication system> The operation of communication system 1000 configured as above will be described below.
[0065] 6 and 7 are sequence diagrams of the processes executed in the communication system 1000. FIG.
[0066] The operation of the communication system 1000 will be described below with reference to the sequence diagrams of FIGS.
[0067] (Step S1): In step S1, a process of transmitting a connection request Req_connect (including information related to security requirements of the terminal device 1) is executed from the terminal device 1 to the base station 2 and the communication control device 3. Specifically, the following process is executed.
[0068] The control unit 11 of the terminal device 1 generates data (signal) requesting the establishment of a wireless communication session (for example, a PDU session (PDU: Protocol Data Unit)) between the terminal device 1 and the communication control device 3. At this time, the control unit 11 includes information on the security requirements of the terminal device 1 in the data. Then, the control unit 11 outputs the generated data (signal) to the data communication processing unit 13. The data communication processing unit 13 performs a predetermined data communication process (for example, a process of converting the data into a format that can be transmitted to the RAN (base station 2)) on the data input from the control unit 11. Then, the data communication processing unit 13 outputs the data acquired by the above data communication process to the terminal-side communication interface 14. Then, the terminal-side communication interface 14 transmits the data input from the data communication processing unit 13 (a connection request including information on the security requirements of the terminal device 1) to the base station 2 as a connection request Req_connect.
[0069] The base station 2 receives the connection request Req_connect sent from the terminal device 1 via the first communication interface 21, processes the received connection request Req_connect via the base station side C-plane signal processing unit 22 so that it is forwarded to the communication control device 3, and sends (forwards) the connection request Req_connect to the communication control device 3 via the second communication interface 25.
[0070] The communication control device 3 receives, via the third communication interface 31, the connection request Req_connect transmitted from the terminal device 1 and forwarded from the base station 2.
[0071] (Step S2): In step S2, a process for establishing a wireless communication session (for example, a PDU session) is executed. Specifically, the following process is executed.
[0072] The communication control device 3 acquires data (C-plane data) used for C-plane signal processing from the received connection request Req_connect via the third communication interface 31, and outputs the acquired data to the C-plane signal processing unit 32. Then, based on the data (connection request Req_connect) input from the third communication interface 31, the C-plane signal processing unit 32 and the U-plane signal processing unit 33 start processing to establish a wireless communication session (e.g., a PDU session) between the terminal device 1, the base station 2, and the communication control device 3. Note that the procedure for establishing a wireless communication session (e.g., a PDU session) between the terminal device 1, the base station 2, and the communication control device can be realized, for example, by the procedure of Document A below. <Reference A> 3GPP TS 23.502 Procedures for the 5G System (5GS); Stage 2 (Release 17) The communication control device 3, the base station 2, and the terminal device 1, for example, perform the procedure of the above-mentioned document A to establish a wireless communication session (for example, a PDU session) between the terminal device 1, the base station 2, and the communication control device 3.
[0073] (Step S3): In step S3, a process of notifying that a wireless communication session (for example, a PDU session) has been established is executed. Specifically, the following process is executed.
[0074] In step S2, when a wireless communication session (e.g., a PDU session) based on a connection request Req_connect from the terminal device 1 is established, the communication control device 3 generates a signal Res_completed notifying that the wireless communication session (e.g., a PDU session) has been established, and transmits the signal Res_completed to the base station 2.
[0075] The base station 2 receives the signal Res_completed transmitted from the communication control device 3, and transmits (transfers) the received signal Res_completed to the terminal device 1.
[0076] The terminal device 1 receives the signal Res_completed transmitted from the base station 2 and recognizes that a wireless communication session (for example, a PDU session) based on the connection request Req_connect transmitted by the terminal device 1 has been established.
[0077] After this, communication between the terminal device 1, the base station 2, and the communication control device 3 becomes possible through a wireless communication session (for example, a PDU session).
[0078] (Step S4): In step S4, the security function checking process data D_secure_ref is transmitted from the communication control device 3 to the security control device 4. Specifically, the following process is executed.
[0079] The communication control device 3 acquires information about the security requirements of the terminal device 1 included in the received connection request Req_connect from the connection request Req_connect via the third communication interface 31. The communication control device 3 also acquires information about the security functions of the base station 2 to which the terminal device 1 is connected. Note that the information about the security functions of the base stations (including base station 2) accessible to the communication control device 3 can be acquired by, for example, communication between the communication control device 3 and the base station (including base station 2) accessible to the communication control device 3. Alternatively, the information about the security functions of the base stations (including base station 2) accessible to the communication control device 3 is assumed to be stored in advance in the storage unit 34 of the communication control device 3.
[0080] The communication control device 3 converts data including (1) information about the security requirements of the terminal device 1 and (2) information about the security functions of the base station 2 to which the terminal device 1 is connected, into data in a format that can be transmitted to the security control device 4 via the fourth communication interface 36, using the data communication processing unit 35, and outputs the data to the fourth communication interface 36. Then, the fourth communication interface 36 transmits the data input from the data communication processing unit 35 (data including (1) information about the security requirements of the terminal device 1 and (2) information about the security functions of the base station 2 to which the terminal device 1 is connected) to the security control device 4 as data D_secure_ref.
[0081] The security control device 4 receives the data D_secure_ref sent from the communication control device 3 through the fifth communication interface 41.
[0082] (Step S5): In step S5, a security function verification process is executed. Specifically, the following process is executed.
[0083] The security control device 4 outputs the data D_secure_ref received by the fifth communication interface 41 to the security control processing unit 42 via the bus Bus4.
[0084] The security control processing unit 42 acquires (1) information on the security requirements of the terminal device 1 and (2) information on the security functions of the base station 2 to which the terminal device 1 is connected from the data D_secure_ref input from the fifth communication interface 41, and executes security function checking processing using (1) the information on the security requirements of the terminal device 1 and (2) the information on the security functions of the base station 2 to which the terminal device 1 is connected. Specifically, the security control processing unit 42 acquires the security level (security strength) required by the terminal device 1 from the information on the security requirements of the terminal device 1, and acquires information on the security functions that can be realized by the base station 2 from the information on the security functions of the base station 2 to which the terminal device 1 is connected. The security control processing unit 42 then determines whether the base station 2 to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) required by the terminal device 1. Then, it acquires the determination result (result of the security function checking processing).
[0085] For example, if the security level (security strength) requested by terminal device 1 is a security level (security strength) that guarantees 192-bit security (security with a key length of 192 bits during encryption) and the upper limit of the security level (security strength) that can be achieved by base station 2 to which terminal device 1 is connected is 128-bit security (security with a key length of 128 bits during encryption), security control processing unit 42 performs security function matching processing and obtains, as security function matching processing result data, data indicating that base station 2 to which terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by terminal device 1, or data for sending a notification (second security function usage notification) to terminal device 1 requesting the use of a second security function (another security function).
[0086] On the other hand, if the security level (security strength) requested by the terminal device 1 is a security level (security strength) that guarantees 128-bit security (security with a key length of 128 bits during encryption) and the upper limit of the security level (security strength) that can be achieved by the base station 2 to which the terminal device 1 is connected is 128-bit security (security with a key length of 128 bits during encryption), the security control processing unit 42 performs security function matching processing and obtains, as security function matching processing result data, data indicating that the base station 2 to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1.
[0087] (Step S6): In step S6, a process is executed to transmit the security function checking process result data from the security control device 4 to the terminal device 1. Specifically, the following process is executed.
[0088] The security control device 4 transmits the security function matching process result data acquired by the security function matching process as data Result_secure_ref to the communication control device 3. The communication control device 3 transmits (transfers) the security function matching process result data Result_secure_ref received from the security control device 4 to the base station 2. The base station 2 transmits (transfers) the security function matching process result data received from the communication control device 3 to the terminal device 1. Then, the terminal device 1 receives the security function matching process result data Result_secure_ref transmitted from the base station 2.
[0089] <A: When the base station 2 to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1> (Step S7): In step S7, security function activation processing is executed. Specifically, the following processing is executed. Here, it is assumed that the security function verification processing result data Result_secure_ref is data indicating that the base station 2 to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1.
[0090] The terminal device 1 analyzes the security function matching process result data Result_secure_ref received from the base station 2 by the control unit 11, and recognizes that the base station 2 to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1 (or recognizes that the data Result_secure_ref is a notification (second security function usage notification) requesting the terminal device 1 to use a second security function (another security function)).The control unit 11 then reads out a security function module stored in the memory unit 12, and performs a process using the security function module, thereby performing a security function activation process. Specifically, the terminal device 1 starts a process to establish a secure session between the terminal device 1 and the security communication device 5. The information required to establish a secure session between the terminal device 1 and the security communication device 5, and the information required to use the security communication device 5, are either (1) stored in advance in the memory unit 12 of the terminal device 1 (or the information is stored in a SIM (Subscriber Identity Module) card that can be read by the terminal device 1 (the data on the SIM card is assumed to be readable by the terminal device 1)), or (2) can be acquired by the terminal device 1, for example, by transmitting a profile via OTA (Over The Air) (transmitting a profile from an external device to the terminal device 1).
[0091] Furthermore, the security function module may be software (for example, a program), or may be software implemented by middleware or an OS. Furthermore, the security function module may be implemented in part or in whole by software and / or hardware.
[0092] (Step S8): In step S8, a process for establishing a secure session between the terminal device 1 and the security communication device 5 (between the terminal device 1, the base station 2, the communication control device 3, and the security communication device 5) is executed.
[0093] (1) For example, when the security communication device 5 is an SSL-VPN server, the following processing is executed. The terminal device 1 makes a TCP / IP connection to the security communication device 5 (SSL-VPN server), and the terminal device 1 establishes a TCP / IP connection with the security communication device 5 (SSL-VPN server). Then, the terminal device 1 executes negotiation with the security communication device 5 (SSL-VPN server) using the SSL protocol (SSL: Secure Sockets Layer), server authentication processing, etc., to establish a VPN session (secure session) between the terminal device 1 and the security communication device 5 (SSL-VPN server). Note that the processing on the terminal device 1 side of the above processing can be realized by processing using a security function module held by the terminal device 1.
[0094] (2) For example, when the security communication device 5 is an IPsec-VPN server, the following processing is executed. The terminal device 1 establishes an IP connection with the security communication device 5 (IPsec-VPN server), and further executes IKE SA (Internet Key Exchange, SA: Security Association) establishment processing (including specification of the encryption algorithm to be used, key exchange processing, etc.), and establishes an SA (Security Association) (secure session (secure session for IPsec communication)) between the terminal device 1 and the security communication device 5 (IPsec-VPN server). Note that the processing on the terminal device 1 side of the above processing can be realized by processing using a security function module held by the terminal device 1.
[0095] (3) Furthermore, for example, if the security communication device 5 is a secure communication device capable of performing IPsec communication, the following processing is executed. The terminal device 1 establishes an IP connection with the security communication device 5 (IPsec communication device), and further executes IKE SA (Internet Key Exchange, SA: Security Association) establishment processing (including specification of the encryption algorithm to be used, key exchange processing, etc.), and establishes an SA (Security Association) (secure session (secure session for IPsec communication)) between the terminal device 1 and the security communication device 5 (IPsec communication device). Note that the processing on the terminal device 1 side of the above processing can be realized by processing using a security function module held by the terminal device 1.
[0096] (Step S9): In step S9, communication is performed using a secure session.
[0097] (1) If the security communication device 5 is an SSL-VPN server, the terminal device 1 uses the secure session (VPN session) established in step S8 between the terminal device 1 and the security communication device 5 to perform secure communication, for example, with a communication device connected to the data network DataNW via the security communication device (SSL-VPN server).
[0098] (2) If the security communication device 5 is an IPsec-VPN server, the terminal device 1 uses the secure session (secure session for IPsec communication (IPsec-VPN session)) between the terminal device 1 and the security communication device 5 established in step S8 to perform secure communication, for example, with a communication device connected to the data network DataNW via the security communication device (IPsec-VPN server).
[0099] (3) If the security communication device 5 is a secure communication device (IPsec communication device) capable of performing IPsec communication, the terminal device 1 uses the secure session (secure session for IPsec communication) established in step S8 between the terminal device 1 and the security communication device 5 to perform secure communication, for example, with a communication device connected to the data network DataNW via the security communication device (VPN server).
[0100] <B: Case where the base station 2 to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1> The above describes the operation of the communication system 1000 when the security function matching process result data Result_secure_ref in step S7 is data indicating that the base station 2 to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1, but below, the operation of the communication system 1000 will be described with reference to the sequence diagram in Fig. 7 when the security function matching process result data Result_secure_ref is data indicating that the base station 2 to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1. Note that the operations in steps S1 to S6 are the same as those described above.
[0101] (Step S7A): In step S7A, processing is executed to establish a secure connection between the terminal device 1 and the base station 2. Specifically, the following processing is executed.
[0102] The terminal device 1 analyzes the security function matching process result data Result_secure_ref received from the base station 2 by means of the control unit 11, and recognizes that the base station 2 to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1. Then, the terminal device 1 performs a process to establish a secure connection with the base station 2. For example, the terminal device 1 performs a process to establish an RRC connection (RRC: Radio Resource Control) with the base station 2 by the procedure described in the following document B. <Reference B> 3GPP, TS 33.501 Security architecture and procedures for 5G system (Release 17) In addition, in step S2, when the process of establishing a wireless communication session (e.g., a PDU session) is performed, the process of establishing an RRC connection between the terminal device 1 and the base station 2 is also performed, and if the RRC connection has already been established between the terminal device 1 and the base station 2, the process of step S7A is omitted.
[0103] (Step S8A): In step S8A, the secure connection established between the terminal device 1 and the base station 2 and the wireless communication session (e.g., a PDU session) established between the terminal device 1, the base station 2, and the communication control device 3 are utilized to communicate, via the communication control device 3, with, for example, a communication device connected to the data network DataNW (communication that satisfies the security level (strength) requested by the terminal device 1).
[0104] <Summary> As described above, in the communication system 1000, whether or not communication at the security level requested by the terminal device 1 is possible can be determined by the security function matching process (matching the security level requested by the terminal device 1 with the security function of the connected base station) performed by the security control device 4. Then, in the communication system 1000, if it is determined that communication at the security level requested by the terminal device 1 is not possible, the terminal device 1 executes security function activation process, for example, to establish a secure session with a security communication device installed in the core network, and secure communication can be realized through the secure session.
[0105] Therefore, in the communication system 1000, even if the security function required by the terminal device 1 cannot be provided at the current location of the terminal device 1, the security function required by the terminal device 1 can be realized, thereby enabling secure communication. By using the communication system 1000 having the above functions, it is possible to prevent a decrease in the security level of the communication service provided due to differences in the support status for security functions of the base stations in the communication system 1000, and to provide a (wireless) communication service with a uniform security level (a (wireless) communication service with a predetermined security level guaranteed) regardless of the environment or location of the user receiving the communication service via the terminal device (communication terminal).
[0106] Furthermore, in the communication system 1000, the above functions can be realized by processing using the security control device 4, making it possible to maintain the security level of wireless communication services without requiring changes to the specifications used in current wireless communication systems or changes to the hardware of the communication device.
[0107] Although the above description is directed to a case where there is one base station in the RAN, the present invention is not limited to this, and multiple base stations may be installed in the RAN. In this case, in the communication system 1000, the security control device 4 may perform a security function matching process (a process of matching the security level required by the terminal device 1 with the security function of the base station to which the terminal device 1 is connected) for all base stations accessible by the terminal device 1, and perform the same process as described above. Furthermore, if there is a base station that can achieve the security level required by the terminal device 1, the security control device 4 may control the terminal device 1 to access that base station and establish a communication session.
[0108] Furthermore, in the communication system 1000, even if the terminal device 1 moves and a base station handover occurs, by performing the security function matching process on the base station to which the handover is made as described above, the communication system 1000 can realize the security functions required by the terminal device 1, enabling secure communication, even if the terminal device 1 moves (regardless of the location of the terminal device 1).
[0109] <First Modification> Next, a first modified example of the first embodiment will be described. Note that the same parts as those in the above embodiment are given the same reference numerals, and detailed description thereof will be omitted.
[0110] FIG. 8 is a schematic configuration diagram of a communication system 1000A according to a first modified example of the first embodiment.
[0111] FIG. 9 is a sequence diagram of the processing executed in the communication system 1000A.
[0112] In a communication system 1000A according to a first modification of the first embodiment, a second base station 20 is further installed in the RAN, as shown in Fig. 8. The second base station 20 is capable of wireless communication with the terminal device 1 and is connected to the communication control device 3 so as to be able to communicate with it.
[0113] For example, when the terminal device 1 moves from within the wireless communication range of the base station 2 to within the wireless communication range of the second base station 20, a handover process is executed in the communication system 1000A, and the communication destination of the terminal device 1 is changed from the base station 2 to the second base station 20. In this modification, the operation of the communication system 1000A when the terminal device 1 moves from within the wireless communication range of the base station 2 to within the wireless communication range of the second base station 20, the handover process is executed, and the communication destination of the terminal device 1 is changed from the base station 2 to the second base station 20 will be described with reference to the sequence diagram of FIG.
[0114] (Steps S1 to S9): The processing from steps S1 to S9 is the same as the processing from steps S1 to S9 in the first embodiment.
[0115] (Step S10): In step S10, a wireless communication session establishment process is executed. Specifically, the following process is executed. It is assumed that, prior to step S10, the terminal device 1 moves from within the wireless communication range of the base station 2 into the wireless communication range of the second base station 20, and a handover process is executed in the communication system 1000A.
[0116] The terminal device 1, the second base station 20, and the communication control device 3 perform processing to establish a wireless communication session among the terminal device 1, the second base station 20, and the communication control device 3. As a result, a wireless communication session is established among the terminal device 1, the second base station 20, and the communication control device 3.
[0117] (Step S11): In step S11, the terminal device 1 recognizes that it established a secure session (e.g., a VPN session) with the security communication device 5 before the handover process and is communicating via the secure session, so it continues to use the secure session (e.g., a VPN session) with the security communication device 5 and communicates, for example, with a communication device connected to the data network DataNW via the secure session (e.g., a VPN session) (the secure session between the terminal device 1 and the security communication device 5).
[0118] In this way, in the communication system 1000A of this modification, if a secure session (for example, a VPN session) has already been established between the terminal device 1 and the security communication device 5, the security function matching process is not performed and the already established secure session (for example, a VPN session) continues to be used even when the base station accessed by the terminal device 1 is changed. As a result, in the communication system 1000A of this modification, even when the access destination of the terminal device 1 is changed due to handover process or the like, it is possible to reduce the processing load and communication volume for performing secure communication.
[0119] [Second embodiment] Next, a second embodiment will be described. Note that the same parts as those in the above embodiment are given the same reference numerals and detailed description will be omitted.
[0120] FIG. 10 is a schematic configuration diagram of a communication system 2000 according to the second embodiment.
[0121] FIG. 11 is a schematic configuration diagram of a base station 2A according to the second embodiment.
[0122] FIG. 12 is a schematic configuration diagram of a communication control device 3A according to the second embodiment.
[0123] <2.1: Communication system configuration> 10, in the communication system 2000 of the second embodiment, the security control device 4 and the security communication device 5, which were connected to the communication control device 3 in the communication system 1000 of the first embodiment, are connected to a base station 2A in the RAN. This is a difference from the first embodiment.
[0124] As shown in FIG. 10, a communication system 2000 of the second embodiment has a configuration in which the base station 2 is replaced with a base station 2A, and the communication control device 3 is replaced with a communication control device 3A.
[0125] As shown in FIG. 11, the base station 2A has a configuration in which the second communication interface 25 in the base station 2 of the first embodiment is replaced with a second communication interface 25A.
[0126] The second communication interface 25A has the same configuration and functions as the second communication interface 25 of the first embodiment, and is also a communication interface for communicating with the security control device 4 and the security communication device 5 via a wired or wireless line.
[0127] As shown in FIG. 12, the communication control device 3A has a configuration in which the fourth communication interface 36 in the communication control device 3 of the first embodiment is replaced with a fourth communication interface 36A.
[0128] The fourth communication interface 36A has the same configuration and functions as the fourth communication interface 36 of the first embodiment, but the communication destination is the data network DataNW.
[0129] <2.2: Operation of the communication system> The operation of communication system 2000 configured as above will now be described.
[0130] 13 and 14 are sequence diagrams of the processes executed in the communication system 2000. FIG.
[0131] The operation of communication system 2000 will be described below with reference to the sequence diagrams of FIGS.
[0132] (Steps S1 to S3): The processing in steps S1 to S3 is the same as that in steps S1 to S3 in the first embodiment.
[0133] (Step S4A): In step S4A, the security function checking process data D_secure_ref is transmitted from the base station 2A to the security control device 4. Specifically, the following process is executed.
[0134] The base station 2A acquires information about the security requirements of the terminal device 1 included in the connection request Req_connect received from the terminal device 1 via the first communication interface 21. The base station 2A also acquires information about the security functions of the base station 2A to which the terminal device 1 is connected. It is assumed that the information about the security functions of the base station 2A is stored in the storage unit 24, or that the base station 2A can acquire information about the security functions of base stations (including the base station 2A) accessible to the communication control device 3A by communicating with the communication control device 3A.
[0135] The base station 2A transmits data including (1) information regarding the security requirements of the terminal device 1 and (2) information regarding the security functions of the base station 2A to which the terminal device 1 is connected as data D_secure_ref to the security control device 4 via the second communication interface 25A.
[0136] The security control device 4 receives, via the fifth communication interface 41, the data D_secure_ref transmitted from the base station 2A.
[0137] (Step S5A): In step S5A, the same process as in step S5 of the first embodiment is executed. Note that in step S5A, the data D_secure_ref is transmitted from the base station 2A, and the security control device 4 performs security function verification processing using the data D_secure_ref received from the base station 2A.
[0138] (Step S6A): In step S6A, a process is executed to transmit the security function checking process result data from the security control device 4 to the terminal device 1. Specifically, the following process is executed.
[0139] The security control device 4 transmits the security function matching process result data acquired by the security function matching process as data Result_secure_ref to the base station 2A. The base station 2A transmits (transfers) the security function matching process result data received from the security control device 4 to the terminal device 1. Then, the terminal device 1 receives the security function matching process result data Result_secure_ref transmitted from the base station 2A.
[0140] <A: When the base station 2A to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1> (Step S7): In step S7, a security function activation process is executed. If the security function verification process result data Result_secure_ref is data indicating that the base station 2A to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1 (or if the data Result_secure_ref is a notification (second security function usage notification) requesting the terminal device 1 to use a second security function (another security function), a process similar to step S7 in the first embodiment is executed in step S7.
[0141] (Steps S8 and S9): In the above case, the same processes as those in the first embodiment are executed in steps S8 and S9.
[0142] <B: Case where the base station 2A to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1> If the security function matching process result data Result_secure_ref indicates that the base station 2A to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1, in steps S7A and S8A, the communication system 2000 performs processes similar to steps S7A and S8A of the first embodiment (see Figure 14).
[0143] As described above, by performing the above processing in the communication system 2000, similarly to the communication system 1000 of the first embodiment, even if the security function requested by the terminal device 1 cannot be provided at the current location of the terminal device 1, the security function requested by the terminal device 1 can be realized and secure communication can be achieved. Furthermore, since the communication system 2000 has a configuration in which the security control device 4 is connected to the base station 2A in the RAN, communication for performing security function matching processing can be performed within the RAN, and the traffic load on the communication control device 3A can be reduced.
[0144] <First Modification> Next, a first modified example of the second embodiment will be described. Note that the same parts as those in the above embodiment (including the modified example) are given the same reference numerals, and detailed description thereof will be omitted.
[0145] FIG. 15 is a schematic configuration diagram of a communication system 2000A according to a first modified example of the second embodiment.
[0146] 16 to 18 are sequence diagrams of the processes executed in communication system 2000A.
[0147] In a communication system 2000A according to a first modification of the second embodiment, as shown in FIG. 15, a second base station 20A is further installed in the RAN.
[0148] The second base station 20A is capable of wireless communication with the terminal device 1, and is communicatively connected to the communication control device 3. The second base station 20A is also communicatively connected to the security control device 4. As shown in FIG. 15, the second base station 20A is also communicatively connected to the second security control device 5A.
[0149] The second security controller 5A has the same configuration and functions as the security controller 5.
[0150] As shown in FIG. 15, the security control device 4 is communicably connected to the base station 2A and the second base station 20A.
[0151] For example, when the terminal device 1 moves from the wireless communication range of the base station 2A into the wireless communication range of the second base station 20A, a handover process is executed in the communication system 2000A, and the communication destination of the terminal device 1 is changed from the base station 2A to the second base station 20A. In this modification, the operation of the communication system 1000A when the terminal device 1 moves from the wireless communication range of the base station 2A into the wireless communication range of the second base station 20A, the handover process is executed, and the communication destination of the terminal device 1 is changed from the base station 2A to the second base station 20A will be described with reference to the sequence diagrams of FIGS.
[0152] (Steps S1 to S3, S4A to S6A, S7 to S9): The processes of steps S1 to S3, S4A to S6A, and S7 to S9 are the same as the processes of steps S1 to S3, S4A to S6A, and S7 to S9 in the second embodiment.
[0153] (Step SA10): In step SA10, a process of canceling the secure session is executed. Specifically, the terminal device 1 and the security communication device 5 execute a process of canceling the secure session (for example, a VPN session) that has been established between the terminal device 1 and the security communication device 5, and cancel the secure session (for example, a VPN session). It is assumed that after step S9, the terminal device 1 moves from the wireless communication range of the base station 2A to the wireless communication range of the second base station 20A, and a handover process is executed in the communication system 2000A.
[0154] (Steps SA11 to SA13): In steps SA11 to SA13, processing similar to steps S1 to S3 in the second embodiment is executed. Note that in steps S1 to S3 in the second embodiment, the terminal device 1, the base station 2A, and the communication control device 3 execute transmission and reception processing of a connection request Req_connect, processing to establish a wireless communication session, and processing to transmit and receive a signal Res_completed, but in steps SA11 to SA13, the terminal device 1, the second base station 20A, and the communication control device 3 execute transmission and reception processing of a connection request Req_connect, processing to establish a wireless communication session, and processing to transmit and receive a signal Res_completed. Then, through the above processing, a wireless communication session is established between the terminal device 1, the second base station 20A, and the communication control device 3.
[0155] (Steps SA14 to SA16): In steps SA14 to SA16, the same processes as in steps S4A to S6A in the second embodiment are executed. Note that in steps S4A to S6A in the second embodiment, the processes executed by the base station 2A are executed by the second base station 20A in steps SA14 to SA16.
[0156] <A: When the second base station 20A to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1> (Steps SA17~SA19): If the second base station 20A to which the terminal device 1 is connected cannot achieve security (secure communication) at the security level (security strength) requested by the terminal device 1, the communication system 2000A executes processes similar to steps S7 to S9 of the second embodiment in steps SA17 to SA19. Note that the processes executed by the base station 2A in steps S7 to S9 of the second embodiment are executed by the second base station 20A in steps SA17 to SA19.
[0157] <B: Case where the second base station 20A to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1> (Steps SA20, SA21): If the second base station 20A to which the terminal device 1 is connected can achieve security (secure communication) at the security level (security strength) requested by the terminal device 1, steps SA20 and SA21 execute the same processes as steps S7A and S8A of the second embodiment. This enables communication through a wireless communication session established between the terminal device 1, the second base station, and the communication control device 3 (a secure session has been established between the terminal device 1 and the second base station 20A). Note that the processes executed by the base station 2A in steps S7A and S8A of the second embodiment are executed by the second base station 20A in steps SA20 and SA21.
[0158] As described above, in the communication system 2000A of this modification, when the base station accessed by the terminal device 1 is changed due to handover processing or the like, the secure session established via the source base station (base station 2A) needs to be released and the destination base station (second base station 20A) needs to perform security function verification processing, but if the destination base station (second base station 20A) can achieve security (secure communication) at the security level (security strength) required by the terminal device 1, there is no need to establish a new secure session with the second security communication device 5A. Therefore, in the above case, the communication system 2000A of this modification can reduce the communication load and improve communication efficiency.
[0159] [Other embodiments] In the communication systems 1000, 2000, terminal devices 1, base stations 2, 2A, communication control devices 3, 3A, and / or security control devices 4 described in the above embodiments, each block may be individually integrated into a single chip using a semiconductor device such as an LSI, or may be integrated into a single chip to include some or all of the blocks.
[0160] Although we have referred to it as an LSI here, it may also be called an IC, system LSI, super LSI, or ultra LSI depending on the level of integration.
[0161] Furthermore, the method of integration is not limited to LSI, but may be realized by dedicated circuits or general-purpose processors. It is also possible to use FPGAs (Field Programmable Gate Arrays), which can be programmed after the LSI is manufactured, or reconfigurable processors, which allow the connections and settings of circuit cells inside the LSI to be reconfigured.
[0162] Furthermore, part or all of the processing of each functional block in each of the above embodiments may be realized by a program. And part or all of the processing of each functional block in each of the above embodiments is performed by a central processing unit (CPU) in a computer. Furthermore, the programs for performing each processing are stored in a storage device such as a hard disk or ROM, and are executed in the ROM or by being read into the RAM.
[0163] Furthermore, each process in the above-described embodiments may be realized by hardware, or by software (including cases where it is realized together with an OS (operating system), middleware, or a predetermined library). Furthermore, it may be realized by a combination of software and hardware.
[0164] For example, when each functional unit of the above embodiment is realized by software, each functional unit may be realized by software processing using the hardware configuration shown in FIG. 19 (for example, a hardware configuration in which a CPU, GPU, ROM, RAM, input unit, output unit, etc. are connected via a bus).
[0165] Furthermore, when each functional unit of the above embodiment is realized by software, the software may be realized using a single computer having the hardware configuration shown in Figure 19, or may be realized by distributed processing using multiple computers.
[0166] Furthermore, the execution order of the processing method in the above embodiment is not necessarily limited to the description of the above embodiment, and the execution order can be changed within the scope of the gist of the invention. Furthermore, in the processing method in the above embodiment, some steps may be executed in parallel with other steps within the scope of the gist of the invention.
[0167] The scope of the present invention includes a computer program for causing a computer to execute the above-described method and a computer-readable recording medium having the program recorded thereon, including, for example, a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a large-capacity DVD, a next-generation DVD, and a semiconductor memory.
[0168] The computer program is not limited to one recorded on the recording medium, but may be one transmitted via a telecommunications line, a wireless or wired communication line, a network such as the Internet, or the like.
[0169] The specific configuration of the present invention is not limited to the above-described embodiment, and various changes and modifications are possible without departing from the gist of the invention.
[0170] [Note] The present invention can also be expressed as follows.
[0171] A first invention is a communication method executed in a communication system including a terminal device, a base station capable of communicating with the terminal device and with a communication device installed in a core network, a communication control device installed in the core network, capable of acquiring information on security functions that can be provided by the base station, and capable of communicating with the base station and an external data network, a security control device, and a security communication device installed in the core network, capable of securely communicating with the terminal device and capable of communicating with the external data network. The communication method includes a first step and a second step.
[0172] In the first step, the security control device (1) receiving, from a base station, security requirements of a terminal device requesting connection to the base station; (2) Obtaining base station security function information, which is information about security functions that can be provided by the base station, from the communication control device; (3) Checking the security requirements against the base station security function information, and determining whether the base station can achieve secure communication that satisfies the security requirements; (4) If the determination process determines that the base station cannot achieve secure communication that meets the security requirements, the base station transmits to the base station determination process result data, which is data including the results of the determination process, or a second security function usage notification, which is a notification requesting the terminal device to use the second security function.
[0173] In the second step, the terminal device: (1) receiving, via the base station, the determination processing result data or the second security function usage notification from the security control device; (2) If the judgment processing result data indicates that secure communication that satisfies the security requirements cannot be achieved, or if a second security function usage notification is received, a process that realizes the second security function is initiated, and a process that establishes a secure communication connection that satisfies the security requirements with the security communication device is performed.
[0174] In this communication method, whether or not communication at the security level required by the terminal device can be performed can be determined by the security control device performing security function matching processing (matching the security level required by the terminal device with the security function of the connected base station). In this communication method, if it is determined that communication at the security level required by the terminal device cannot be performed, the terminal device performs security function activation processing, for example, to establish a secure session with a security communication device installed in the core network, and secure communication can be realized through the secure session.
[0175] Therefore, with this communication method, even if the security function required by the terminal device cannot be provided at the current location of the terminal device, the security function required by the terminal device can be realized, enabling secure communication.
[0176] The "process of comparing the security requirements with the base station security capability information and determining whether the base station can achieve secure communication that satisfies the security requirements" may be performed based on, for example, the encryption method, encryption algorithm, the length (bit length) of the key used for encryption, the authentication method, algorithm, etc. In other words, the process of comparing the security requirements with the base station security capability information and the process of determining whether the base station can achieve secure communication that satisfies the security requirements may be performed taking into consideration, for example, the encryption method, encryption algorithm, the length (bit length) of the key used for encryption, the authentication method, algorithm, etc.
[0177] The second invention is the first invention, which is a communication method executed in a communication system further including a second base station capable of communicating with a terminal device and with a communication device installed in a core network.
[0178] The communication method further includes a third step in which, when the communication destination of the terminal device is switched from the base station to a second base station and a secure communication connection has been established between the terminal device and the security communication device, the second base station maintains the secure communication connection between the terminal device and the security communication device, and the terminal device communicates via the secure communication connection via the second base station.
[0179] As a result, in this communication method, when the communication destination of a terminal device is changed, for example, by handover processing, etc., and a secure communication connection has already been established between the terminal device and the security communication device by the base station from which the switching originates, the second base station to which the switching is made maintains the secure communication connection, and the terminal device can communicate via the secure communication connection via the second base station.
[0180] Therefore, with this communication method, even when the communication destination of the terminal device is changed due to handover processing or the like, it is possible to reduce the processing load and communication volume required for secure communication.
[0181] A third invention is a communication method executed in a communication system including a terminal device, a base station capable of communicating with the terminal device and with communication devices installed in a core network and capable of acquiring information on security functions that can be provided by the base station, a communication control device installed in the core network and capable of communicating with the base station and an external data network, a security control device, and a security communication device installed in the core network, capable of securely communicating with the terminal device and capable of communicating with the external data network. The communication method includes a first step and a second step.
[0182] In the first step, the security control device (1) receiving, from a base station, security requirements of a terminal device requesting connection to the base station; (2) Obtaining base station security function information from the base station, which is information about security functions that can be provided by the base station; (3) Checking the security requirements against the base station security function information, and determining whether the base station can achieve secure communication that satisfies the security requirements; (4) If the determination process determines that the base station cannot achieve secure communication that meets the security requirements, the base station transmits to the base station determination process result data, which is data including the results of the determination process, or a second security function usage notification, which is a notification requesting the terminal device to use the second security function.
[0183] In the second step, the terminal device: (1) receiving, via the base station, the determination processing result data or the second security function usage notification from the security control device; (2) If the judgment processing result data indicates that secure communication that satisfies the security requirements cannot be achieved, or if a second security function usage notification is received, a process that realizes the second security function is initiated, and a process that establishes a secure communication connection that satisfies the security requirements with the security communication device is performed.
[0184] In this communication method, whether or not communication at the security level required by the terminal device can be performed can be determined by the security control device performing security function matching processing (matching the security level required by the terminal device with the security function of the connected base station). In this communication method, if it is determined that communication at the security level required by the terminal device cannot be performed, the terminal device performs security function activation processing, for example, to establish a secure session with a security communication device installed in the core network, and secure communication can be realized through the secure session.
[0185] Therefore, with this communication method, even if the security function required by the terminal device cannot be provided at the current location of the terminal device, the security function required by the terminal device can be realized, enabling secure communication.
[0186] A fourth invention is a communication system including a security control device and a terminal device.
[0187] The security control device is (1) receiving, from a base station capable of communicating with the terminal device, security requirements of the terminal device requesting connection to the base station; (2) Acquire base station security function information, which is information about security functions that can be provided by the base station, from a communication control device or base station that can communicate with the base station and an external data network and can acquire information about security functions that can be provided by the base station; (3) Checking the security requirements against the base station security function information, and determining whether the base station can achieve secure communication that satisfies the security requirements; (4) If the determination process determines that the base station cannot achieve secure communication that meets the security requirements, the base station transmits a second security function usage notification to the base station, which is a notification requesting the terminal device to use the second security function.
[0188] The terminal device (1) receiving a second security function usage notification from the security control device via the base station; (2) Based on the notification of use of the second security function, a process for realizing the second security function is initiated, and a secure communication connection that meets the security requirements is established with a security communication device that is capable of communicating with an external data network and performing secure communication with the communication device.
[0189] In this communication system, whether or not communication at the security level required by the terminal device can be performed can be determined by the security control device performing security function matching processing (matching the security level required by the terminal device with the security function of the connected base station). In this communication system, if it is determined that communication at the security level required by the terminal device cannot be performed, the terminal device performs security function activation processing, for example, to establish a secure session with a security communication device installed in the core network, and secure communication can be realized through the secure session.
[0190] Therefore, in this communication system, even if the security function required by the terminal device cannot be provided at the current location of the terminal device, the security function required by the terminal device can be realized, enabling secure communication.
[0191] A fifth aspect of the present invention is a security control device used in the communication system of the fourth aspect of the present invention.
[0192] This makes it possible to realize a security control device used in a communication system, which is the fourth aspect of the present invention.
[0193] A sixth aspect of the present invention is a terminal device used in the communication system of the fourth aspect of the present invention.
[0194] This makes it possible to realize a terminal device used in a communication system, which is the fourth invention.
[0195] A seventh aspect of the present invention is a program for causing a computer to execute the communication method of the first or third aspect of the present invention.
[0196] This makes it possible to realize a program for causing a computer to execute a communication method that has the same effects as the first or third invention. [Explanation of symbols]
[0197] 1000, 2000 communication systems 1. Terminal equipment 2, 2A base station 3, 3A communication control device 4 Security control device 5. Security communication equipment
Claims
1. A terminal device; a base station capable of communicating with the terminal device and with a communication device installed in a core network; a communication control device that is installed within the core network, that can acquire information on security functions that can be provided by the base station, and that can communicate with the base station and an external data network; a security control device; a security communication device that is installed within the core network, that can perform secure communication with the terminal device, and that can communicate with the external data network; A communication method performed in a communication system comprising: The security control device receiving, from the base station, security requirements of a terminal device requesting connection to the base station; acquiring base station security function information, which is information about security functions that can be provided by the base station, from the communication control device; comparing the security requirements with the base station security function information, and determining whether the base station can realize secure communication that satisfies the security requirements; a first step of transmitting, to the base station, determination process result data, which is data including a result of the determination process, or a second security function usage notification, which is a notification requesting the terminal device to use a second security function, when the determination process determines that the base station cannot realize secure communication that satisfies the security requirements; The terminal device, receiving the determination process result data or the second security function usage notification from the security control device via the base station; a second step of starting a process for realizing a second security function and establishing a secure communication connection that satisfies the security requirements with the security communication device when the determination process result data indicates that the secure communication that satisfies the security requirements cannot be realized or when the second security function usage notification has been received; A communication method comprising:
2. A communication method executed in the communication system further including a second base station capable of communicating with the terminal device and a communication device installed in a core network, When the communication destination of the terminal device is switched from the base station to the second base station and a secure communication connection is established between the terminal device and the security communication device, the second base station maintains a secure communication connection between the terminal device and the security communication device; a third step in which the terminal device performs communication using the secure communication connection via the second base station; Further provided with The communication method according to claim 1 .
3. A terminal device; a base station that can communicate with the terminal device and with a communication device installed in a core network, and that can acquire information about security functions that can be provided by the base station; a communication control device that is installed within the core network and is capable of communicating with the base station and an external data network; a security control device; a security communication device that is installed within the core network, that can perform secure communication with the terminal device, and that can communicate with the external data network; A communication method performed in a communication system comprising: The security control device receiving, from the base station, security requirements of a terminal device requesting connection to the base station; acquires, from the base station, base station security function information, which is information about security functions that can be provided by the base station; comparing the security requirements with the base station security function information, and determining whether the base station can realize secure communication that satisfies the security requirements; a first step of transmitting, to the base station, determination process result data, which is data including a result of the determination process, or a second security function usage notification, which is a notification requesting the terminal device to use a second security function, when the determination process determines that the base station cannot realize secure communication that satisfies the security requirements; The terminal device, receiving the determination process result data or the second security function usage notification from the security control device via the base station; a second step of starting a process for realizing a second security function and establishing a secure communication connection that satisfies the security requirements with the security communication device when the determination process result data indicates that the secure communication that satisfies the security requirements cannot be realized or when the second security function usage notification has been received; A communication method comprising:
4. receiving, from a base station capable of communicating with a terminal device, security requirements of the terminal device requesting connection to the base station; acquires base station security function information, which is information about security functions that can be provided by the base station, from a communication control device or the base station that is capable of communicating with the base station and an external data network and that can acquire information about security functions that can be provided by the base station; comparing the security requirements with the base station security function information, and determining whether the base station can realize secure communication that satisfies the security requirements; a security control device that transmits, to the base station, a second security function usage notification that requests the terminal device to use a second security function when the base station determines that the base station cannot realize secure communication that satisfies the security requirements by the determination process; and receiving the second security function usage notification from the security control device via the base station; a terminal device that starts a process for realizing a second security function based on the second security function usage notification and establishes a secure communication connection that satisfies the security requirements with a security communication device that is capable of communicating with the external data network and performing secure communication with the communication device; A communication system comprising:
5. The security control device used in the communication system according to claim 4.
6. The terminal device used in the communication system according to claim 4.
7. A program for causing a computer to execute the communication method according to claim 1 or 3.