Information processing device, communication method, and program

The information processing device in vehicles uses external communication devices to maintain connectivity by accessing cellular networks with SIM profile information, addressing the challenge of evolving standards without hardware updates, ensuring continuous service.

JP2025161545APending Publication Date: 2025-10-24TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024064831
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-12
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

Existing vehicles equipped with built-in communication modules face challenges as communication standards evolve over time, necessitating costly replacements due to changes in cellular networks, disrupting service continuity.

Method used

An information processing device that uses externally connected communication devices, such as a USB interface, to access a cellular network via stored SIM profile information, allowing authentication with a first communication system without a built-in cellular module, enabling seamless transition through network changes.

Benefits of technology

Ensures continued access to communication systems by replacing communication devices, maintaining authentication without updating the vehicle's hardware, thus minimizing service disruption and cost during infrastructure changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025161545000001_ABST
    Figure 2025161545000001_ABST
Patent Text Reader

Abstract

To improve the communication availability.SOLUTION: An information processing device includes a storage unit that stores first authentication data for receiving authentication from a first communication system, a communication interface that can access a predetermined cellular network and that connects to a communication device having second authentication data, and a control unit, and when the communication device connects to the cellular network using the second authentication data, the control unit accesses the first communication system via the communication device and the cellular network and receives authentication from the first communication system using the first authentication data.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to communications technology. [Background technology]

[0002] Vehicles that communicate using cellular networks are becoming more common. In this regard, for example, Patent Document 1 discloses an invention relating to a vehicle equipped with a data communication module. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2023-124635 Summary of the Invention [Problem to be solved by the invention]

[0004] The present disclosure aims to improve communication availability. [Means for solving the problem]

[0005] One aspect of the present disclosure is An information processing device having a memory unit that stores first authentication data for receiving authentication from a first communication system, a communication interface that can access a predetermined cellular network and is used to connect to a communication device having second authentication data, and a control unit that, when the communication device connects to the cellular network using the second authentication data, accesses the first communication system via the communication device and the cellular network and receives authentication from the first communication system using the first authentication data.

[0006] One aspect of the present disclosure is A communication method executed by an information processing device that can access a specified cellular network and has a communication interface for connecting to a communication device having second authentication data, the communication method including: acquiring first authentication data for receiving authentication from a first communication system from a storage unit; when the communication device connects to the cellular network using the second authentication data, accessing the first communication system via the communication device and the cellular network; and receiving authentication from the first communication system using the first authentication data.

[0007] One aspect of the present disclosure is a storage unit that stores SIM profile information for receiving authentication from a first communication system that authenticates a user terminal using the SIM profile information; An information processing device having a communication interface for connecting to a communication device that can access a first network, and a control unit that, when the communication device is connected to the first network, accesses the first communication system via the communication device and the first network and is authenticated by the first communication system using the SIM profile information.

[0008] Another aspect of the present invention is a program for causing a computer to execute the above-described method, or a computer-readable storage medium that non-transitory stores the program. [Effects of the Invention]

[0009] According to the present disclosure, it is possible to improve the availability of communications. [Brief explanation of the drawings]

[0010] [Figure 1] 1 is a schematic diagram of a vehicle communication network according to a first embodiment; [Figure 2] A more detailed diagram of the network configuration shown in Figure 1. [Figure 3] FIG. 2 is a hardware configuration diagram of the in-vehicle device 10. [Figure 4] FIG. 2 is a hardware configuration diagram of the communication device 11. [Figure 5] FIG. 2 is a hardware configuration diagram of the authentication device 20. [Figure 6] FIG. 2 is a software configuration diagram of the in-vehicle device 10. [Figure 7] FIG. 2 is a diagram illustrating the software configuration of the communication device 11. [Figure 8] FIG. 2 is a diagram illustrating the software configuration of the authentication device 20. [Figure 9] 6 is a flowchart of a process in which the in-vehicle device 10 connects to the communication system 2. [Figure 10] 10 is a flowchart of authentication processing executed by the authentication device 20. [Figure 11] FIG. 10 is a schematic diagram of a vehicle communication network according to a modified example of the first embodiment. [Figure 12] FIG. 10 is a schematic diagram of a vehicle communication network according to a second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] In recent years, as automobiles have become more connected, the number of vehicles equipped with communication devices has increased. The communication devices installed in the vehicles can provide various services to the vehicle occupants by communicating with server devices (such as application servers) via, for example, a cellular network.

[0012] A typical in-vehicle communication device has a built-in communication module that complies with a specific communication standard, and it is not easy to change the communication standard.

[0013] However, because automobiles are generally used for long periods of time, such as 10 years or more, it is possible that the communication standards assumed at the time of vehicle manufacture may become unusable due to a change in communication standards, etc. To address this, the built-in communication modules would need to be replaced, which would incur significant costs. The communication system according to the present disclosure solves this problem.

[0014] An information processing device according to a first aspect of the present disclosure includes a memory unit that stores first authentication data for receiving authentication from a first communication system, a communication interface that can access a predetermined cellular network and that is for connecting to a communication device having second authentication data, and a control unit that, when the communication device connects to the cellular network using the second authentication data, accesses the first communication system via the communication device and the cellular network and receives authentication from the first communication system using the first authentication data.

[0015] The information processing device according to the present disclosure is typically a computer mounted on a mobile object such as an automobile, etc. The information processing device is configured to be connectable to a communication device. The communication device is a device for accessing a cellular network, and is, for example, an external communication module that is inserted into a USB interface of a personal computer. The connection may be via a wired interface or via a wireless interface. The communication device may connect to the cellular network using, for example, a SIM profile (second authentication data) stored in a SIM card. The information processing device is connected to the first communication system via the communication device, and is then authenticated by the first communication system using the first authentication data.

[0016] The first authentication data is typically a predetermined communication system equivalent to the second authentication data. For example, the first authentication data may be SIM profile information.

[0017] In this way, the information processing device according to the present disclosure has a feature that it accesses the first communication system via an externally connected communication device rather than via a built-in communication module, and that it stores data (e.g., a SIM profile) for receiving authentication from the first communication system. The information processing device does not necessarily need to have a module for cellular communication (a cellular module).

[0018] With this configuration, even if a cellular network is replaced with a new generation and a previously used communication service is terminated, the user of the device can continue to access the first communication system by simply replacing the communication device. Furthermore, the user can continue to receive authentication from the first communication system using the same authentication data before and after the replacement. In other words, even if the status of the communication infrastructure changes during the service provision period, the service can be continued by minimizing the impact.

[0019] The storage unit does not necessarily have to be a built-in storage device. For example, the storage unit may be an internal storage that stores data such as a SIM profile, or may be a medium that can be inserted from outside the device, such as a SIM card.

[0020] The first communication system may be a system that authenticates a user terminal using SIM profile information held by an eUICC. For example, the first communication system may be a system that authenticates a user terminal using an authentication function in a cellular network, such as a Home Subscriber Server (HSS) or an Authentication Server Function (AUSF). In this case, the first authentication data is the SIM profile information.

[0021] The first communication system may also be a communication system connected to the cellular network via an untrusted network. For example, the first communication system and the cellular network may be connected via an untrusted network such as the Internet, and even in this case, the first communication system can verify the authenticity of the user device by using the first authentication data.

[0022] Specific embodiments of the present disclosure will be described below with reference to the accompanying drawings. Unless otherwise specified, the hardware configuration, module configuration, functional configuration, etc. described in each embodiment are not intended to limit the technical scope of the disclosure to those configurations.

[0023] (First embodiment) [Network Overview] An overview of a vehicle communication network according to a first embodiment will be described with reference to Fig. 1. The vehicle communication network according to this embodiment includes an on-board device 10 mounted on a vehicle 1, a communication device 11 connectable to the on-board device 10, and a communication system 2. The on-board device 10 and the communication system 2 are connected via a carrier network. The communication system 2 is a network including multiple communication devices, including an authentication device 20. Note that the vehicle communication network may include multiple vehicles 1.

[0024] The vehicle 1 is a connected vehicle that has the function of providing predetermined services by communicating with the communication system 2. The vehicle 1 can provide various services by communicating with a server device connected to the communication system 2. The various services include, for example, a navigation service, a remote control service (e.g., remote air conditioning), an in-vehicle W Examples of such services include i-Fi services, emergency call services, etc. These services may be provided by the in-vehicle device 10 or by other in-vehicle computers.

[0025] The in-vehicle device 10 is a device that mediates communication between components of the vehicle 1 and the communication system 2. The in-vehicle device 10 does not have a communication module for wireless communication, and establishes a communication path to the communication system 2 using a communication device 11 connected to the in-vehicle device 10.

[0026] 1, the in-vehicle device 10 is configured to be connectable to a communication device 11. For example, the in-vehicle device 10 is configured to be connectable to the communication device 11 via an interface such as a USB, and to be able to transmit and receive data via the communication device 11. In other words, the in-vehicle device 10 is configured to be able to perform tethering using the communication device 11. The communication device 11 is a device that can be connected to any cellular network.

[0027] The communication device 11 has a second SIM and can connect to the carrier network A by using profile information stored in the second SIM. For example, the user of the vehicle 1 enters into a contract with a business operator that provides communication services through the carrier network A, and is issued a second SIM by the business operator.

[0028] Carrier network A includes base stations of a cellular network, control devices that manage user equipment (hereinafter referred to as UE), etc. In this embodiment, carrier network A is connected to an IP communication network (such as the Internet). While carrier network A is a communication system operated by a mobile communications carrier, communication system 2 can be a communication system operated by the manufacturer of vehicle 1. By interconnecting these, it becomes possible, for example, to provide a service unique to vehicle 1 via communication system 2.

[0029] Since carrier network A is a network independent of communication system 2, carrier network A and communication system 2 cannot be connected to each other as is. For this reason, in this embodiment, a gateway (non-3GPP Interworking Function, hereinafter referred to as N3IWF) for accommodating access from an IP communication network is placed in communication system 2. N3IWF is a gateway for accommodating untrusted non-3GPP wireless access. This allows communication system 2 to accept access via an IP communication network (via carrier network A). The IP communication network is typically the Internet, but may be something else.

[0030] In this embodiment, the in-vehicle device 10 connected to the carrier network A can connect to the communication system 2 via the carrier network A and a subsequent IP communication network by establishing an IPsec tunnel with the N3IWF of the communication system 2. This allows the in-vehicle device 10 connected to the carrier network A to communicate with the communication system 2 via a route that goes through an IP communication network (such as the Internet).

[0031] In this embodiment, the carrier network A provides only a communication line, and the communication system 2 authenticates the in-vehicle device 10 and provides services to the in-vehicle device 10. The configuration of the communication system 2 is similar to the core network of the carrier network A, but differs from the core network provided by a mobile communication carrier that has been assigned a frequency and provides services over its own line in that the communication system 2 does not have a function to connect to a user device via a radio access network (RAN) or a function to manage the movement and handover of the user device. The communication system 2 uses the authentication device 20 to authenticate the user device (vehicle-mounted It has the function of authenticating the device 10). Therefore, the in-vehicle device 10 has a first SIM that stores profile information for authentication by the communication system 2. The first SIM is a SIM issued by a business operator (for example, a vehicle manufacturer) that operates the communication system 2. The first SIM may be a physical SIM card, an eSIM, or the like.

[0032] The in-vehicle device 10 connects to the communication system 2 via the carrier network A and is authenticated by the communication system 2 using the profile information stored in the first SIM. In this embodiment, the authentication device 20 included in the communication system 2 authenticates the in-vehicle device 10 based on the profile information included in the first SIM.

[0033] If the in-vehicle device 10 has a communication module and the communication system 2 has a wireless access network, the communication system 2 can accept and authenticate the connection of the in-vehicle device 10 using a first SIM issued by the operator (e.g., a vehicle manufacturer) that operates the system.

[0034] However, in this embodiment, the in-vehicle device 10 does not have a communication module, and instead uses the communication device 11 to connect to the communication system 2 via a route via the carrier network A. In this case, only authentication by the carrier network A (authentication using the second SIM) is performed, and the route passes through an untrusted network, so the communication system 2 cannot trust the in-vehicle device 10 as it is. Furthermore, since the communication system 2 is operated by a different carrier, the authentication result of the in-vehicle device 10 cannot be shared between the communication system 2 and the carrier network A.

[0035] Therefore, in this embodiment, the communication system 2 (authentication device 20) authenticates the in-vehicle device 10 connected via the N3IWF using the authentication information held by the first SIM. A SIM card typically has two types of information: information for connecting to a wireless access network provided by a cellular network, and information for receiving authentication from the cellular network. In contrast, in this embodiment, the communication system 2, which does not have a wireless access network, authenticates the in-vehicle device 10 using only the latter information.

[0036] As a result, even if the communication line between the in-vehicle device 10 and the communication system 2 is changed, the communication system 2 can continue to perform robust authentication equivalent to cellular communication without changing the device configuration. Furthermore, even if a service of a cellular network that the user of the in-vehicle device 10 has previously used (for example, a 5G service) is terminated, the user can secure a communication path to the communication system 2 by replacing the communication device 11. Even in this case, only the cellular network to be used changes, and the method by which the communication system 2 authenticates the user device does not change, so the user can continue to receive the service without updating the in-vehicle device 10.

[0037] [Network configuration details] Fig. 2 is a diagram showing in detail the components of each network described with reference to Fig. 1. Note that Fig. 2 shows only the components related to the first embodiment among the components of each system, and the components of each system are not limited to those shown in Fig. 2.

[0038] In this embodiment, the carrier network A is a 5G standard communication system. The carrier network A includes a radio access network (hereinafter, referred to as RAN), a session management function (hereinafter, referred to as SMF) for managing sessions of communication terminals including the in-vehicle device 10, Access and Mobility Management Function (hereinafter referred to as AM) F), a function that relays data in the user plane (User Plane Function, hereinafter referred to as UP F). Carrier network A also includes a function for user authentication (Authentication Server Function, hereinafter referred to as AUSF), a function for acquiring subscriber information (Unified Data Management, hereinafter referred to as UDM), etc. Each function is called a "device." It can also be read as:

[0039] The communication system 2 is also a 5G standard communication system. The communication system 2 is configured to include a gateway (N3IWF) that accommodates access from an IP communication network, an authentication device 20, and a UPF that serves as a gateway for connecting to an external network.

[0040] The authentication device 20 executes a process for authenticating user terminals such as the in-vehicle device 10. The authentication device 20 is a device that supports AMF and AUSF in the 5G system. The authentication device 20 is connected to the UDM and authenticates the user device based on information stored in a database (subscriber information corresponding to the first SIM).

[0041] As described above, carrier network A has a function of authenticating a user device (communication device 11) connected via a base station. In addition, carrier network A has a UPF connected to an IP communication network (e.g., the Internet). This allows the user device (communication device 11) connected to carrier network A to communicate with the IP communication network. When establishing a network connection via the communication device 11, the in-vehicle device 10 transmits a connection request to the communication system 2, addressed to the N3IWF included in the communication system 2. As described above, the N3IWF is a gateway that accommodates access from an IP communication network, and therefore the in-vehicle device 10 can communicate with the communication system 2 via the N3IWF.

[0042] At this time, the in-vehicle device 10 is authenticated by the authentication device 20 using the authentication information included in the profile information stored in the first SIM. The connection request is processed by the authentication device 20 included in the communication system 2, and authentication is performed between the in-vehicle device 10 and the authentication device 20. The authentication device 20 authenticates the in-vehicle device 10 based on authentication information included in the first SIM. When the authentication is complete, a communication path is established between the in-vehicle device 10 and the communication system 2, and the communication system 2 becomes able to provide services to the in-vehicle device 10.

[0043] The server device that provides the service to the in-vehicle device 10 may be located within the communication system 2, or may be located outside the communication system 2 as shown in FIG. In the description of the embodiment, the wide area network between carrier network A and communication system 2 is referred to as the "IP communication network" and the wide area network connected to the outside of communication system 2 is referred to as the "external network", but both may be the same network (e.g., the Internet).

[0044] [Hardware configuration] Next, the hardware configuration of each device constituting the system will be described. Fig. 3 is a diagram showing a schematic diagram of an example of the hardware configuration of the in-vehicle device 10 according to this embodiment.

[0045] The in-vehicle device 10 can be configured as a computer having a processor (CPU, GPU, etc.), a main memory (RAM, ROM, etc.), and an auxiliary memory (EPROM, hard disk drive, removable media, etc.). The software stores an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, it is possible to realize various functions (software modules) that meet specific purposes, as described below. However, some or all of the functions may be realized as hardware modules using hardware circuits such as ASICs and FPGAs.

[0046] The in-vehicle device 10 includes a control unit 101, a storage unit 102, a SIM card 103, a CAN communication module 104, and an expansion interface 105.

[0047] The control unit 101 is a computing unit that executes predetermined programs to realize various functions of the in-vehicle device 10. The control unit 101 can be realized by, for example, a hardware processor such as a CPU. The control unit 101 may also be configured to include a RAM, a ROM (Read Only Memory), a cache memory, and the like.

[0048] The storage unit 102 is a means for storing information, and is configured with storage media such as RAM, a magnetic disk, a flash memory, etc. The storage unit 102 stores programs executed by the control unit 101, data used by the programs, etc.

[0049] The SIM card 103 includes an eUICC (embedded The SIM card 103 is a SIM card (SIM universal integrated circuit card). The SIM card 103 is the first SIM in FIG. 1. The SIM card 103 is configured as a microcomputer equipped with a CPU and a storage device, and is connected to the in-vehicle device 10 via a SIM card slot. The SIM card 103 has authentication information for receiving authentication from the communication system 2. In this embodiment, the first SIM is a physical SIM card, but the first SIM may also be an eSIM.

[0050] The CAN communication module 104 is a communication interface for connecting the on-board device 10 to an in-vehicle network of the vehicle 1. The CAN communication module 104 is a network interface that performs communication using, for example, a CAN (Controller Area Network) protocol. The in-vehicle device 10 can perform data communication with other components of the vehicle 1 via the CAN communication module 104.

[0051] The expansion interface 105 is an interface for connecting the in-vehicle device 10 and the communication device 11 to each other. The expansion interface 105 is, for example, a USB interface. The in-vehicle device 10 is configured to be connectable to the communication device 11 via, for example, the USB interface. Note that the expansion interface may also be an interface that connects the in-vehicle device 10 and the communication device 11 via a wireless communication interface.

[0052] Next, a description will be given of the hardware configuration of the communication device 11. Fig. 4 is a diagram schematically showing an example of the hardware configuration of the communication device 11 according to this embodiment.

[0053] The communication device 11 includes a control unit 111 , a storage unit 112 , a wireless communication module 113 , and an interface 114 .

[0054] Similar to the control unit 101, the control unit 111 is a calculation unit that executes a predetermined program to realize various functions of the communication device 11. The control unit 111 can be realized by, for example, a hardware processor such as a CPU.

[0055] The storage unit 112 is a means for storing information, and is configured with a storage medium such as a RAM, a magnetic disk, or a flash memory. The program, the data used by the program, etc. are stored.

[0056] The wireless communication module 113 is a communication device that performs wireless communication with a predetermined network. In this embodiment, the wireless communication module 113 is configured to be able to communicate with a predetermined cellular network (carrier network A). The wireless communication module 113 may be an integrated circuit (cellular module) for performing cellular communication. The wireless communication module 113 is configured to have a SIM card 113A. The SIM card 113A is the second SIM in FIG. 1. The SIM card 113A is configured as a microcomputer equipped with a CPU and a storage device. The SIM card 113A has information (PLMN information) for connecting to carrier network A and authentication information for receiving authentication from the network. The second SIM may be a physical SIM card, an eSIM, or the like.

[0057] The interface 114 is an interface corresponding to the extension interface 105, and is an interface for mutually connecting the in-vehicle device 10 and the communication device 11. The communication device 11 is configured to be connectable to the in-vehicle device 10 via an interface such as a USB.

[0058] Next, a description will be given of the hardware configuration of the authentication device 20. Fig. 5 is a diagram showing a schematic example of the hardware configuration of the authentication device 20 according to this embodiment. The authentication device 20 is configured as a computer having a control unit 201 , a storage unit 202 , and a communication module 203 .

[0059] The authentication device 20 can be configured as a computer having a processor (CPU, GPU, etc.), a main memory device (RAM, ROM, etc.), and an auxiliary memory device (EPROM, hard disk drive, removable media, etc.). However, some or all of the functions (software modules) may be realized as hardware modules using hardware circuits such as ASIC, FPGA, etc.

[0060] The control unit 201 is a computing unit that executes a predetermined program to realize various functions (software modules) of the authentication device 20. The control unit 201 can be realized by, for example, a hardware processor such as a CPU.

[0061] The storage unit 202 is a means for storing information, and is configured with storage media such as RAM, a magnetic disk, a flash memory, etc. The storage unit 202 stores programs executed by the control unit 201, data used by the programs, etc.

[0062] The communication module 203 is a communication interface for connecting the authentication device 20 to the communication system 2. The communication module 203 can realize data communication between the authentication device 20 and other devices arranged in the communication system 2.

[0063] [Software configuration] Next, the software configuration of each device constituting the system will be described. Fig. 6 is a diagram showing a schematic software configuration of the in-vehicle device 10 according to this embodiment.

[0064] In this embodiment, the control unit 101 of the in-vehicle device 10 is configured to have a software module of a communication control unit 1011. The software module may be realized by the control unit 101 (CPU) executing a program stored in the storage unit 102. Note that the information processing executed by the software module is synonymous with the information processing executed by the control unit 101 (CPU).

[0065] Furthermore, the SIM card 103 (first SIM) is configured to store a first profile, which is SIM profile information. The first profile is a profile issued by a carrier that manages the communication system 2. The first profile includes, for example, identification information such as an International Mobile Subscription Identity (IMSI) and an Integrated Circuit Card ID (ICCID), and authentication information (key information) for undergoing SIM authentication such as AKA authentication. Note that if the first SIM is an eSIM, the first profile may be stored in the storage unit 102.

[0066] The communication control unit 1011 establishes a network connection in response to a request from a vehicle component of the vehicle 1. When a communication device 11 having a second SIM is connected to the in-vehicle device 10, the in-vehicle device 10 instructs the communication device 11 to establish a network connection via the carrier network A. Note that when multiple communication devices 11 are available, the communication control unit 1011 may determine the communication device to be used for the connection based on a user selection.

[0067] After the communication device 11 establishes a connection to the carrier network A, the communication control unit 1011 interacts with the communication system 2 (authentication device 20) via the carrier network A and receives authentication from the authentication device 20 using the profile information (first profile) stored in the first SIM. Any authentication procedure used in a 5G system can be used.

[0068] Next, a description will be given of the software configuration of the communication device 11. Fig. 7 is a diagram schematically showing the software configuration of the communication device 11 according to this embodiment.

[0069] In this embodiment, the control unit 111 of the communication device 11 is configured to have a software module of a communication control unit 1111. The software module may be realized by the control unit 111 (CPU) executing a program stored in the storage unit 112. Note that the information processing executed by the software module is synonymous with the information processing executed by the control unit 111 (CPU).

[0070] Furthermore, SIM card 113A (second SIM) built into wireless communication module 113 is configured to store a second profile, which is SIM profile information. The second profile is a profile issued by a telecommunications carrier that manages carrier network A. Like the first profile, the second profile includes identification information such as IMSI and ICCID, and authentication information (key information) for undergoing SIM authentication.

[0071] The communication control unit 1111 establishes a network connection in response to a request from the in-vehicle device 10. When a connection request is received from the in-vehicle device 10, the communication control unit 1111 establishes a network connection via the carrier network A. At this time, the communication control unit 1111 is authenticated by a control device (AUSF) of the carrier network A using profile information (second profile) stored in the second SIM.

[0072] Next, a description will be given of the software configuration of the authentication device 20. Fig. 8 is a diagram showing a schematic diagram of the software configuration of the authentication device 20 according to this embodiment.

[0073] In this embodiment, the control unit 201 of the authentication device 20 is configured to have a software module of a terminal authentication unit 2011. The software module may be realized by the control unit 201 (CPU) executing a program stored in the storage unit 202. The information processing executed by the software module is synonymous with the information processing executed by the control unit 201 (CPU).

[0074] Upon receiving a request from the in-vehicle device 10, the terminal authentication unit 2011 executes a process for authenticating the in-vehicle device 10. The authentication process can be executed, for example, according to the following sequence defined by 3GPP (registered trademark). (1) Processing for receiving a registration request from the in-vehicle device 10 (2) Sending a request to the UDM to obtain authentication-related data (3) The process of obtaining authentication-related data (e.g., Authentication Vector) from the UDM. (4) Processing for sending a challenge (Authentication Request) to the in-vehicle device 10 (5) Processing for receiving a response (Authentication Response) from the in-vehicle device 10 (6) Processing for verifying the validity of the in-vehicle device 10 based on the response

[0075] In addition, the terminal authentication unit 2011 may also execute processes required to register the in-vehicle device 10 in the communication system 2. Furthermore, if the authentication device 20 also serves as an AMF in a 5G system, the authentication device 20 may have a software module that performs predetermined processing for managing communications or user devices other than the authentication processing described above.

[0076] [flowchart] Next, a detailed description will be given of the process executed when the in-vehicle device 10 connects to the communication system 2. FIG.

[0077] First, in step S11, the in-vehicle device 10 instructs the communication device 11 to establish a network connection. In response to this, the communication device 11 starts a connection using the carrier network A. Specifically, the control unit 111 of the communication device 11 transmits an authentication request to the carrier network A via a base station of the carrier network A. The authentication request is received by the AMF of the carrier network A, and the AMF and AUSF authenticate the communication device 11 based on authentication-related data acquired from the UDM. For this authentication, profile information stored in the second SIM is used. When the authentication is completed, a communication path is established between the communication device 11 and the carrier network A, which enables the communication device 11 to communicate with the IP communication network via the UPF.

[0078] When the communication device 11 becomes able to communicate with the IP communication network, authentication is initiated between the in-vehicle device 10 and the communication system 2 in step S12. In step S12, the in-vehicle device 10 establishes an IPsec tunnel to the N3IWF via a route via the carrier network of the tethering destination (i.e., carrier network A), and then transmits an authentication request to the communication system 2. The authentication request reaches the communication system 2 via the IP communication network and the N3IWF, and is received by the authentication device 20.

[0079] Next, in accordance with the received authentication request, the authentication device 20 starts authentication of the in-vehicle device 10. In this step, authentication of the in-vehicle device 10 is executed based on the profile information stored in the first SIM. If the authentication device 20 succeeds in authenticating the in-vehicle device 10, the communication system 2 establishes a communication path. As a result, the in-vehicle device 10 connected to the communication system 2 via the N3IWF becomes capable of communicating with any server device connected to the communication system 2. The establishment of the communication path and the relay of data using the communication path may be performed by the authentication device 20 or by another device included in the communication system 2.

[0080] In addition, when a communication path is not established, the communication system 2 does not relay communication. As a result, for example, communication from an unauthenticated in-vehicle device 10 to a server device is blocked by the communication system 2.

[0081] Next, authentication-related processing executed by the authentication device 20 will be described. 10 is a flowchart of the process executed by the authentication device 20 in step S12. The process shown in the figure is started when the authentication device 20 (terminal authentication unit 2011) receives an authentication request transmitted from the in-vehicle device 10.

[0082] First, in step S21, the terminal authentication unit 2011 acquires authentication-related data. The authentication-related data is data used to authenticate the in-vehicle device 10. Examples of the authentication-related data include a challenge to be sent to the user device (on-board device 10), an authentication token, and an expected response value from the user device (on-board device 10). The authentication-related data is generated based on information provided by the UDM (for example, an Authentication Vector). It may be generated by the terminal authentication unit 2011. Alternatively, the terminal authentication unit 2011 may obtain the authentication-related data from the UDM. The authentication-related data listed in this example is for AKA authentication, which is a challenge-response authentication method for authenticating a device using a SIM card.

[0083] In step S22, the terminal authentication unit 2011 authenticates the in-vehicle device 10 based on the authentication-related data. When performing AKA authentication, the authentication device 20 transmits a challenge to the in-vehicle device 10, and the in-vehicle device 10 generates a response in response to the challenge. The response is generated based on authentication information (secret key) included in the profile information stored in the first SIM. If the generated response matches the one calculated based on the authentication-related data, it can be considered that the authentication of the in-vehicle device 10 has been successful.

[0084] In this example, AKA authentication is used as an example of a method for authenticating the in-vehicle device 10, but authentication may be performed by any other method as long as it is a method for performing authentication based on information stored in a SIM card.

[0085] As described above, the in-vehicle device 10 according to the first embodiment is configured to be connectable to the communication device 11, and can communicate with the communication system 2 via any cellular network via the communication device 11. This makes it possible to secure a communication path and perform communication without incorporating a wireless communication module in the in-vehicle device 10.

[0086] Furthermore, the in-vehicle device 10 according to the first embodiment receives authentication from the communication system 2 using the profile information stored in the first SIM, regardless of the network via which the in-vehicle device 10 passes. In other words, the first SIM held by the in-vehicle device 10 is not used for connecting to a cellular network, but is used only for authentication.

[0087] With this configuration, even if a generational change of the cellular network occurs, the device user can continue to access the communication system 2 simply by replacing the communication device. Furthermore, the user can continue to receive authentication from the communication system 2 using the same authentication data before and after the replacement. In other words, even if the status of the communication infrastructure changes during the service provision period, the service can be continued by minimizing the impact.

[0088] (Modification 1 of the first embodiment) In the first embodiment, a communication system is configured by connecting a communication device 11 to an in-vehicle device 10. A communication path up to 2 was established by tethering. On the other hand, multiple communication paths may be set by tethering.

[0089] FIG. 11 is a diagram showing an outline of a vehicle communication network in this modification. The in-vehicle device 10 may be configured to be connectable to another communication device 11A in addition to the communication device 11 described in the first embodiment. The communication device 11A is configured to have a SIM card (third SIM) for connecting to a carrier network B. The communication device 11 and the communication device 11A may be connectable at the same time. In this modification, the in-vehicle device 10 can select the device to be used for communication from the communication device 11 and the communication device 11A. When the communication device 11 is selected as the device to be used for communication, the communication is performed via the carrier network A. When the communication device 11A is selected as the device to be used for communication, the communication is performed via the carrier network B. If there are multiple communication paths via tethering, the communication control unit 1011 may determine which communication path to use, for example, before executing step S11.

[0090] Regardless of which communication path is used, the in-vehicle device 10 receives authentication from the authentication device 20 using the profile information stored in the first SIM. With this configuration, communication paths can be freely added without changing the configuration in which authentication is performed using the first SIM.

[0091] (Modification 2 of the first embodiment) In the first embodiment, a configuration has been exemplified in which the communication device 11 connected to the carrier network A accesses the communication system 2 via an untrusted network (IP communication network). However, it is not necessary for an untrusted network to exist between the communication device 11 and the communication system 2. For example, a reliable closed network may be connected to the carrier network A, and the communication device 11 may access the communication system 2 via the network. Even in this case, the in-vehicle device 10 can be authenticated by the communication system 2 by using the profile information stored in the first SIM, as in the first embodiment.

[0092] (Second embodiment) In the first embodiment, a configuration has been exemplified in which the communication device 11, which has a built-in wireless communication module for performing cellular communication, accesses the communication system 2 via the carrier network A. However, the communication device 11 does not necessarily need to perform communication via the cellular network.

[0093] 12 is a diagram showing an outline of a vehicle communication network in the second embodiment. The communication device 11B in this embodiment is a client device (wireless LAN adapter) for connecting to a wireless LAN access point. Unlike the first embodiment, the communication device 11B does not have a SIM card for a cellular network.

[0094] In this embodiment, the communication device 11B is configured to be connectable to an access point 3 that provides access to an IP communication network. The access point 3 is a device that has the function of accepting a wireless connection from a client device and providing access to the IP communication network. The access point 3 may be a device that functions both as a wireless router device and an optical line termination device (ONU).

[0095] In this embodiment, the communication device 11B accesses the access point 3, and thereby a path from the communication device 11B to the IP communication network is established. The in-vehicle device 10 can access the IP communication network using the communication device 11B as a gateway. Similarly to the first embodiment, the in-vehicle device 10 can connect to the communication system 2 by establishing an IPsec tunnel with the N3IWF of the communication system 2. In this way, the communication device according to the present disclosure may access an IP communication network using a communication medium other than a cellular network.

[0096] (Variation) The above-described embodiment is merely an example, and the present disclosure can be modified and implemented as appropriate within the scope that does not deviate from the gist of the disclosure. For example, the processes and means described in this disclosure can be freely combined and implemented as long as no technical contradiction occurs.

[0097] In addition, in the description of the embodiment, 5G is used as an example of a cellular network standard, but 4G (LTE-Advanced) or the like can also be adopted as a communication standard. In this case, the N3IWF can be replaced with an ePDG (enhanced Packet Data Gateway) or the like. Furthermore, in the description of the embodiment, the in-vehicle device 10 is exemplified as the user device, but the user device may be an IoT terminal or the like.

[0098] Furthermore, in the description of the embodiment, an example has been given in which the on-board device 10 is authenticated using profile information stored in a SIM, but the on-board device 10 may be authenticated using other methods. For example, the on-board device 10 may store in the storage unit 102 a pair of key information and an electronic certificate (e.g., issued by a certificate authority) for verifying the authenticity of the key information. The authentication device 20 can also authenticate the on-board device 10 using such information. In either case, authentication is performed using the same authentication information regardless of the communication path.

[0099] Furthermore, although the embodiments have been described with reference to an example in which a communication path is established by USB tethering, the communication path may be established by Wi-Fi tethering. In this case, the in-vehicle device 10 may be configured to be wirelessly connectable to a smartphone or the like owned by the user of the vehicle 1. In this case, the illustrated communication device 11 (or communication device 11A) is replaced with the smartphone or the like.

[0100] Furthermore, a process described as being performed by one device may be shared and executed by multiple devices. Alternatively, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is realized can be flexibly changed.

[0101] The present disclosure can also be realized by providing a computer program implementing the functions described in the above embodiments to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer via a non-transitory computer-readable storage medium connectable to the computer's system bus or via a network. Examples of non-transitory computer-readable storage media include any type of disk, such as a magnetic disk (e.g., a floppy disk, a hard disk drive (HDD), etc.), an optical disk (e.g., a CD-ROM, a DVD disk, a Blu-ray disk), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, or any type of medium suitable for storing electronic instructions. [Explanation of symbols]

[0102] 1. Vehicle 2. Communication Systems 10...In-vehicle equipment 11. Communication equipment 20 Authentication device

Claims

1. a storage unit that stores first authentication data for receiving authentication from the first communication system; a communication interface for connecting to a communication device that can access a predetermined cellular network and has second authentication data; a control unit that, when the communication device connects to the cellular network using the second authentication data, accesses the first communication system via the communication device and the cellular network and is authenticated by the first communication system using the first authentication data; An information processing device having the above.

2. the first and second authentication data are both SIM profile information; The information processing device according to claim 1 .

3. the first communication system is a system that authenticates a user terminal by using SIM profile information held by an eUICC; the storage unit stores SIM profile information as the first authentication data; The information processing device according to claim 1 .

4. the first communication system is a system that authenticates a user terminal using an authentication function in a cellular network, the storage unit stores SIM profile information as the first authentication data; The information processing device according to claim 1 .

5. the first communication system is a communication system connected to the cellular network via an untrusted network; The information processing device according to claim 2 .

6. does not have a cellular module for accessing the cellular network; The information processing device according to claim 1 .

7. A communication method executed by an information processing device that can access a predetermined cellular network and has a communication interface for connecting to a communication device having second authentication data, the method comprising: acquiring, from a storage unit, first authentication data for receiving authentication from a first communication system; accessing the first communication system via the communication device and the cellular network when the communication device connects to the cellular network using the second authentication data; receiving authentication from the first communications system using the first authentication data; A communication method, including:

8. the first and second authentication data are both SIM profile information; The communication method according to claim 7.

9. the first communication system is a system that authenticates a user terminal by using SIM profile information held by an eUICC; the storage unit stores SIM profile information as the first authentication data; The communication method according to claim 7.

10. the first communication system is a system that authenticates a user terminal using an authentication function in a cellular network, the storage unit stores SIM profile information as the first authentication data; The communication method according to claim 7.

11. the first communication system is a communication system connected to the cellular network via an untrusted network; The communication method according to claim 8.

12. does not have a cellular module for accessing the cellular network; The communication method according to claim 7.

13. A program for causing a computer to execute the communication method according to any one of claims 7 to 12.

14. a storage unit that stores SIM profile information for receiving authentication from a first communication system that authenticates a user terminal using the SIM profile information; a communication interface for connecting to a communication device that can access the first network; a control unit that, when the communication device is connected to the first network, accesses the first communication system via the communication device and the first network and receives authentication from the first communication system using the SIM profile information; An information processing device having the above.

Citation Information

Patent Citations

  • Information processing device and information processing method

    JP2023124635A