Information processing apparatus, communication method, and program
The information processing device with UICC card and dual connection capabilities addresses authentication and communication challenges in vehicles without cellular networks, ensuring secure and functional communication services through non-cellular networks.
Patent Information
- Application Number
- JP2024102030
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-25
- Publication Date
- 2026-01-14
AI Technical Summary
Existing communication systems in vehicles without cellular network capabilities face challenges in performing robust authentication and maintaining communication functionality, especially with the advent of new communication standards, limiting access to connected services.
An information processing device equipped with a UICC card for authentication data, wireless and wired connection capabilities, and a control unit to transmit data via non-cellular networks, enabling robust authentication and communication with a communication device using a non-cellular network.
Enables robust authentication and communication services in vehicles without cellular network capabilities, ensuring secure data transmission and access to connected services through non-cellular networks.
Smart Images

Figure 2026003913000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device, a communication method, and a program. [Background technology]
[0002] BACKGROUND ART Conventionally, there are communication devices equipped with a SIM card capable of storing a plurality of communication profiles (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180105 Summary of the Invention [Problem to be solved by the invention]
[0004] An object of the present disclosure is to provide an information processing device, a communication method, and a program that are capable of performing robust authentication during communication using a non-cellular network. [Means for solving the problem]
[0005] One aspect of the present disclosure is an information processing device capable of communicating with a communication device, the information processing device including a UICC (Universal Integrated Circuit Card) card that stores authentication data and a wireless connection with a non-cellular network. an information processing device including a wireless communication unit for performing wireless communication with the non-cellular network, a connector to which a wireless device used for wireless connection with the non-cellular network can be detached, and at least one of a communication unit for using a wired connection with the non-cellular network, and a control unit for transmitting the authentication data to the communication device via the non-cellular network after the information processing device is connected to the communication device via the non-cellular network using the wireless communication unit, the wireless device, or the communication unit.
[0006] According to one aspect of the present disclosure, there is provided an information processing device capable of communicating with a communication device, the information processing device having a UICC (Universal Integrated Circuit Card) card storing authentication data, A communication method that performs the following: by using either a wireless communication unit that establishes a wireless connection with a cellular network, a wireless device that is connected to a connector of the information processing device and is used for a wireless connection with the non-cellular network, or a communication unit that is used for a wired connection with the non-cellular network, the information processing device is connected to the communication device via the non-cellular network, and then transmitting the authentication data to the communication device via the non-cellular network.
[0007] Other aspects include a program for causing a computer to execute the above method, a computer-readable storage medium non-temporarily storing the program, or a mobile object equipped with an information processing device. [Effects of the Invention]
[0008] According to the present disclosure, robust authentication can be performed when communicating using a non-cellular network. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of a communication system according to an embodiment. [Figure 2] FIG. 2 is a diagram showing an example of the configuration of the in-vehicle device 10. As shown in FIG. [Figure 3] FIG. 3 shows an example of the configuration of the communication device 20. [Figure 4] FIG. 4 is a sequence diagram illustrating an example of the operation of the communication system. DETAILED DESCRIPTION OF THE INVENTION
[0010] Businesses (e.g., vehicle manufacturers, dealers, rental companies, etc.) involved in vehicles equipped with communication functions, such as connected cars and autonomous vehicles, may wish to collect data related to the vehicles (e.g., data related to vehicle operation and data related to vehicle communications). For this reason, it is considered that the business's communication devices (communication facilities) will receive predetermined data (IoT data) transmitted from devices installed in the vehicles via a network. Then, as a service provider, the business can provide services based on the analysis results of the IoT data to vehicle users, etc.
[0011] However, in vehicles that do not have a communication function, users cannot enjoy the above-mentioned services. Furthermore, even in vehicles that have a communication function, the communication function may become unavailable for various reasons, such as a change in the next generation of communication standards. In such cases, the services cannot be enjoyed. The communication system described below solves these problems.
[0012] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. The configurations of the following embodiments are examples, and the present disclosure is not limited to the configurations of the embodiments. FIG. 1 is a diagram showing an example of a communication system according to an embodiment. The communication system includes an in-vehicle device 10 mounted on a vehicle and a communication device 20. The in-vehicle device 10 may be a stationary type installed in the vehicle or a portable type.
[0013] The vehicle user can provide and receive predetermined services through communication between the in-vehicle device 10 and the communication device 20. The in-vehicle device 10 can provide and receive various services by communicating with a server device (e.g., server 51 or server 52) connected to the communication device 20. The various services include, for example, a navigation service, a remote control service (e.g., remote air conditioning), an in-vehicle Wi-Fi service, and an emergency call service.
[0014] The in-vehicle device 10 executes a predetermined application program (app) to acquire information about the vehicle from the in-vehicle device 10 itself or from an in-vehicle device other than the in-vehicle device 10 (for example, a car navigation device, a drive recorder, an ECU (Electronic Control Unit), etc.). (Data related to vehicle operation such as location, speed, etc.) can be collected.
[0015] Therefore, the in-vehicle device 10 connects to the communication device 20, enabling communication with the server device via the communication device 20. Data generated in the vehicle or the in-vehicle device 10 is sent to the communication device 20, and the communication device 20 sends the data to be transmitted to a predetermined destination (a communication partner, for example, the server 51 or 52). However, the destination of the data may be the communication device 20.
[0016] The in-vehicle device 10 uses an IP (Internet Protocol) network for communication with the communication device 20. As the IP network, for example, a public network such as the Internet 1 can be used. The IP network may be other than the Internet 1. As an access network to the Internet 1, for example, a cellular network 3, a wireless LAN (Local Area Network), a satellite communication network, or a wired LAN 15 can be used.
[0017] The communication device 20 is configured by one information processing device (computer) or a collection of two or more information processing devices connected via a network. The communication device 20 has an internal network configuration formed by a collection of core network components (network nodes, called network functions (NFs) in 5G) of a cellular network according to the use or function of the communication device 20. In the example shown in FIG. 1, the communication device 20 operates as a device including a gateway (GW) 21, an authentication unit 22, a routing unit 23, an accounting unit (log storage unit) 24, a control unit 25, and a storage unit 26.
[0018] The GW21 is connected to the in-vehicle device 10 via an access network and the Internet 1 (IP network). When the internal network configuration of the communication device 20 is a 5G core network (5GC), an N3IWF (non-3GPP Interworking Function) is disposed as the GW21. The N3IWF is a gateway for accommodating untrusted non-3GPP wireless access. When the internal network configuration of the communication device 20 is an LTE or 4G core network (EPC), an ePDG (enhanced Packet Data Gateway) is used as the GW21. An IPsec-based tunnel (called an IPsec tunnel or an SWu tunnel) is established between the in-vehicle device 10 and the GW21 as an encrypted line, and data transmitted from the in-vehicle device 10 is transmitted to the GW21 through the SWu tunnel.
[0019] When the in-vehicle device 10 accesses the communication device 20, the in-vehicle device 10 acquires SIM profile information (SIM information) stored in the SIM card 105 of the in-vehicle device 10 and transmits it as authentication data (control information) to the communication device 20. The authentication unit 22 can authenticate the in-vehicle device 10 having the SIM card 105 by using the SIM profile information of the SIM card 105 and the subscriber information stored in the storage unit 26. AKA (Authentication and Key Agreement) can be applied as an authentication method (authentication mechanism).
[0020] When the internal network configuration of the communication device 20 is 5GC, an AUSF (Authentication Server Function) may be used as the authentication unit 22, and a UDM (Unified Data Management) may be used as the storage unit 26. When the internal network configuration of the communication device 20 is EPC, AAA (Authentication, Authorization, Accounting) is used for this purpose, and the storage unit 26 However, the authentication unit 22 may also operate as an AMF in 5GC or an MME in EPC.
[0021] When the routing unit 23 receives a packet containing user data, it determines whether the destination IP address of the packet is registered in the routing table, and if not, it calculates the shortest route to the destination IP address, determines information indicating a route (output port) according to the shortest route, and registers the destination IP address and output port information in the routing table. In addition, the routing unit 23 transfers the packet whose destination IP address is registered in the routing table to the corresponding output port (destination).
[0022] When the internal network configuration of the communication device 20 is 5GC, a UPF (User Plane Function) is used as the routing unit 23, and when the internal network configuration of the communication device 20 is EPC, A P-GW (Packet data network GateWay) can be used as the unit 23. A GTPu tunnel is formed between the GW 21 and the routing unit 23 (UPF or P-GW), and the GW 21 sends the packet obtained by terminating the SWu tunnel to the routing unit 23 through the GTPu tunnel.
[0023] Furthermore, the routing unit 23 generates and outputs a CDR (Charge Data Record) used as charging information, and passes it to the charging unit 24. The CDR is communication log information (log information) that can include packet flow identification information (e.g., source / destination TCP port numbers, source / destination IP addresses), the start time and end time of the packet flow, the amount of data, and the like.
[0024] For example, when the internal network configuration of the communication device 20 is 5GC, a CHF (Charging Function) is used as the charging unit 24, and when the internal network configuration is EPC, a PCRF (Policy and Charging Rules Function) is used as the charging unit 24. The charging unit 24 uses the CDR to The usage fee for packet communication is calculated based on, for example, the amount of data in the packet and the fee plan. It is calculated according to the
[0025] The control unit 25 uses the CDR (log information) to generate information indicating an incentive that the business operator will give to the vehicle user.
[0026] 2 is a diagram showing an example of the configuration of the in-vehicle device 10. The in-vehicle device 10 includes a control unit (controller) 30 having a CPU 31 and a main memory device 32a, an auxiliary memory device 32b, a CAN communication module 34, and an expansion interface 35, all of which are interconnected via a bus 38. The in-vehicle device 10 also includes a SIM card 105, a card reader 106, an input device 36, a display 37, a wireless communication circuit 103, and a network interface card (NIC) 111.
[0027] The auxiliary storage device 32b is, for example, a hard disk drive (HDD), a solid state drive (SSD), or an EEPROM. The auxiliary storage device 32b stores, for example, an operating system (OS) and a plurality of types of application programs (apps). The apps include programs for implementing various functions such as a communication control program. The main storage device 32a is, for example, a random access memory (RAM), a read only memory (ROM), or a combination of a RAM and a ROM. The CPU 31 performs the operation of the in-vehicle device 10 by executing various programs stored in the main storage device 32a or the auxiliary storage device 32b.
[0028] The CAN communication module 34 is a communication interface for connecting the in-vehicle device 10 to an in-vehicle network (CAN (Controller Area Network)) of the vehicle. The communication module 34 may include, for example, a network interface board that communicates using the CAN protocol. The in-vehicle device 10 can perform data communication with other components (such as ECUs) of the vehicle via the CAN communication module 34.
[0029] The expansion interface 35 is an interface for interconnecting the in-vehicle device 10 and the communication device 10A or the USB dongle 13. The expansion interface 35 is, for example, a USB (Universal Serial Bus) interface and has a female connector (an example of a connector) to which a USB cable connected to the communication device 10A or a male connector of the USB dongle 13 can be detached. The communication device 10A is a smart device such as a smartphone or a cellular tablet terminal. The communication device 10A can be detachably attached to the expansion interface 35 via a USB cable connected to the connector. The USB dongle 13 is a cellular USB dongle compatible with the cellular network 3, but the in-vehicle device 10 may be connected to the Internet 1 using a Wi-Fi USB dongle or a satellite communication USB dongle.
[0030] The wireless communication circuit 103 can perform wireless communication with an external device (such as the communication device 10A) using a wireless communication method such as Bluetooth (registered trademark) or wireless LAN (including IEEE 802.11 series and Wi-Fi). The NIC 111 is used to connect to the wired LAN 15. The wired LAN 15 is connected to the Internet 1 via a connection device for the Internet 1, such as a broadband modem. As described above, the in-vehicle device 10 does not have a configuration for connecting to a cellular network such as the cellular network 3, and does not have a location registration function for the cellular network. However, the in-vehicle device 10 is configured to be able to connect to the cellular network 3 using the communication device 10A or a cellular USB dongle 13 and connect to the Internet 1 (communication device 20) through the cellular network 3. The in-vehicle device 10 can also connect to the Internet 1 via the wired LAN 15 or a satellite communication network (non-terrestrial network (NTN)) and communicate with the communication device 20. The connection mechanism to the wired LAN 15 may be optional.
[0031] The input device 36 is a key, a button, etc., and is used to input information. The display 37 is used to display (notify) information. The input device 36 may be a user interface displayed on the display 37. The input device 36 and the display 37 are optional and may be omitted.
[0032] The SIM card 105 is a UICC (Universal Integrated Circuit Card) and The SIM card 105 operates as a microcomputer having a PU and memory. The SIM card 105 stores profile information used for authentication. The profile information includes an identification number and key information. The identification number is, for example, an International Mobile Subscription Identity (IMSI), a Mobile Subscriber Integrated Services Digital Network Number (MSISDN), or an Integrated Circuit Card IDentity (ICCID). The key information is a shared secret key K value (Ki) and an operation code (OPc) used in AKA authentication.
[0033] The SIM card 105 is a SIM card issued by a business operator (e.g., a vehicle manufacturer) that provides services using the communication device 20. The SIM card 105 according to this embodiment is not intended to register the location of the on-vehicle device 10 in a predetermined cellular network or to establish a communication path (PDU session) within the cellular network, but is primarily intended to authenticate the on-vehicle device 10. For this reason, the SIM card 105 may have the same configuration as a normal SIM card, but may have functions related to processes other than those intended for authentication (e.g., location registration, establishment of a communication path within the cellular network) omitted.
[0034] The SIM card 105 includes profile information (identifier and key information) for performing authentication in the communication device 20. The identifier is, for example, a subscriber identification such as an International Mobile Subscriber Identity (IMSI) or a Subscription Permanent Identifier (SUPI). The identifier may be a card identifier such as an ICCID (Integrated Circuit Card ID), which is a SIM card serial number of up to 19 digits.
[0035] The IMSI is a maximum of 15 digits long, and is made up of a 3-digit MCC (Mobile Country Code), a 2-3 digit MNC, etc., in accordance with communication standards such as 3GPP (registered trademark) TS23.003. (Mobile Network Code: carrier number) and 9-10 digit MSIN (Mobile Subscription Number) The MCC and MNC constitute a PLMN-ID (Public Land Mobile Network-ID). However, since the SIM card 105 is not intended for location registration, a uniquely identifiable string of numbers created according to rules different from the communication standard may be used instead of the IMSI or ICCID. The string of numbers is configured to match the number of digits of the IMSI and ICCID. In this way, the profile information (authentication data) can include the IMSI, ICCID, or a uniquely identifiable identifier instead of the IMSI or ICCID.
[0036] In the example shown in Figure 2, an apparatus configuration is illustrated that includes a wireless communication circuit 103, an expansion interface 35 to which a USB dongle 13 can be attached or detached, and a NIC 111 that provides a wired connection to the Internet 1, but at least one of these is sufficient for communication with the communication device 20.
[0037] Fig. 3 shows an example of the configuration of an information processing device 20A that can be used as the communication device 20. The communication device 20 can be configured with one or more information processing devices 20A. In Fig. 3, the information processing device 20A includes a control unit (controller) 120, an auxiliary storage device 123, a communication interface (communication IF) 124, an input device 125, and a display 126, which are interconnected by a bus 127.
[0038] The control unit 120 includes a CPU 121 and a main storage device 122 connected to the CPU 121. The CPU 121 executes various programs stored in the main storage device 122 or the auxiliary storage device 123, thereby causing the communication device 20 to operate as a device including a GW 21, an authentication unit 22, a routing unit 23, an accounting unit (log storage unit) 24, a control unit 25, and a storage unit 26.
[0039] The communication interface (communication IF) 124 includes a communication interface circuit with the Internet 1 (IP network), and performs transmission and reception of control information and user data (packets), format (protocol) conversion, etc. The input device 125 is a button, key, touch panel, etc. used for inputting and setting information, etc. The display 126 is used to display information. The input device 125 and display 126 are optional.
[0040] The CPUs (processors) constituting the controllers 30 and 120 described above may be processors other than CPUs, such as DSPs and GPUs, or may be combined with CPUs. Furthermore, the processing or operations performed by the controllers 30 and 120 may be performed using semiconductor devices (hardware) such as FPGAs (Field Programmable Gate Arrays) or ASICs (Application Specific Integrated Circuits), or may be a combination of a processor and hardware, such as an SoC (System On a Chip). Each of the control unit (controller), FPGA, ASIC, and SoC is an example of a "circuitry."
[0041] FIG. 4 is a sequence diagram showing an example of operation in a communication system. <0> Then, the in-vehicle device 10 acquires the data to be transmitted. However, the timing of acquiring the data is an example, and the data can be transmitted and received at any appropriate timing.
[0042] Figure 4 <1> In the example, the controller 30 of the in-vehicle device 10 detects a trigger to start communication. The trigger may be reception of a communication request message from the in-vehicle device 10, detection of an instruction to start communication input from the input device 36, or detection by the controller 30 of the occurrence of some other event (such as storage of data to be transmitted in the auxiliary storage device 32b). The trigger can be set as appropriate. The data to be transmitted may be data received from the in-vehicle network or data generated in the in-vehicle device 10.
[0043] Figure 4 <2> In the example, the controller 30 connects to the Internet 1. For example, the controller 30 displays information on the display 37 prompting the operator of the in-vehicle device 10 to connect to the Internet 1, such as connecting to the communication device 10A, connecting the USB dongle 13 to the expansion interface 35, or connecting the NIC 111 to the wired LAN 15, thereby prompting the operator of the in-vehicle device 10 to connect to the Internet 1. The controller 30 performs a process of connecting to the Internet 1 using the communication device 10A, the USB dongle 13, the wired LAN 15, or the like that is connected wirelessly or physically to the in-vehicle device 10.
[0044] Figure 4 <3> In this example, the controller 30 establishes an encrypted communication path (IKE SA) called a security association (SA) with the GW 21 of the communication device 20. The IP address of the GW 21 is known to the in-vehicle device 10. Alternatively, the in-vehicle device 10 may determine the IP address of the GW 21 using a DNS system.
[0045] Figure 4 <4> In this example, authentication processing is performed between the in-vehicle device 10 and the communication device 20 using the profile information (authentication data) stored in the SIM card 105. The authentication processing can be performed, for example, by the following sequence. (1) The in-vehicle device 10 acquires the IMSI from the SIM card 105 and transmits a connection request including the IMSI to the GW 21. The GW 21 sends the connection request to the authentication unit 22. (2) The authentication unit 22 sends an authentication information request to the storage unit 26. (3) The storage unit 26 creates RAND, AUTN, and XRES using Ki and OPc corresponding to the IMSI, which are stored in advance, and a sequence number (SQN), etc. The SQN is incremented each time authentication is performed, and is updated synchronously between the in-vehicle device 10 and the communication device 20. RAND is a random number, and AUTN is a message authentication code for detecting tampering with the RAND. The SQN, the encryption key (Cipher Key: CK), and the message authentication code are used. The XRES is an expected value of the response from the SIM card 105. (4) The authentication unit 22 holds the XRES and transmits the AUTN and RAND. The CK and IK are held as a shared key for IPsec to be set with the in-vehicle device 10. The AUTN and RAND are received by the in-vehicle device 10 via the GW 21, and the in-vehicle device 10 sends the AUTN and RAND to the SIM card 105. (5) The SIM card 105 checks the SQN included in the AUTN against the SQN it holds. If the SQNs match, the network (communication device 20) is determined to be authentic. (6) If the network determines that the SIM card 105 is legitimate, the SIM card 105 combines the RAND with Ki and OPc stored in the SIM card 105 to calculate CK, IK, and RES (authentication response). (7) The values of CK, IK, and RES are passed from the SIM card 105 to the in-vehicle device 10, and the in-vehicle device 10 sends RES to the authentication unit 22. The values of CK and IK are held in the in-vehicle device 10 as a shared key for IPsec. (8) The authentication unit 22 compares RES with XRES and determines that the authentication is successful if the two match. Information indicating the authentication is successful is sent to the in-vehicle device 10.
[0046] Figure 4 <5> In this step, a tunnel is established based on IPsec. That is, using the shared keys CK and IK, an SWu tunnel is established between the in-vehicle device 10 and the GW 21, and a GTPu tunnel is established between the GW 21 and the routing unit 23. Note that the operation of the authentication unit 22 in the above steps (1) to (8) includes the operation as an AMF in a 5G system or an MME in LTE (4G).
[0047] Figure 4 <6> In this case, the in-vehicle device 10 generates a packet storing the data to be transmitted and transmits it to the GW 21 of the communication device 20 through the SWu tunnel (see FIG. 4). <7> The SWu tunnel is terminated at the GW 21, the SWu header is removed, and the original packet is obtained. The GW 21 adds a new header (referred to as a GTPu header) to the packet in order to transmit the packet through the GTPu tunnel established between the GW 21 and the routing unit 23.
[0048] The routing unit 23 performs termination processing of the GTPu tunnel (removal of the GTPu header, etc.) on the packet received from the GW 21, and obtains the original packet. The routing unit 23 performs routing on the original packet (see FIG. 4). <8> That is, if the destination IP address of the original packet (for example, the IP address of the server 51 or 52) is registered in the routing table, the routing unit 23 transfers the packet to the output port associated with that IP address (see FIG. 4). <9> On the other hand, if the IP address is not registered in the routing table, the system will use a method such as SPF (Shortest Path First) to The shortest route is searched using the above method, and the information of the output port corresponding to the shortest route is registered in the routing table in association with the IP address, and the packet is forwarded to the output port.
[0049] The routing unit 23 generates a CDR (Charging Data Record) including packet flow information including the source and destination IP addresses of the original packet, the source and destination TCP port numbers, the start and end times of the packet flow, the amount of data of the packet, etc. (see FIG. 4). <10> The CDR is passed to the billing unit 24, which calculates the usage fee using the CDR. Calculate.
[0050] If the user is willing to pay the fee for packet transmission from the in-vehicle device 10 to the communication device 20, the control unit 25 generates incentive information (see FIG. 5). <11> ). The determination of whether the user is responsible for the fee can be made, for example, by determining whether the value of a flag stored in the main storage device 122 or the auxiliary storage device 123 of the communication device 20 (for example, "1" = user responsible, "0" = someone other than the user (e.g., a carrier) responsible) is "1." Packet transmission can be managed, for example, for each TCP session (connection) established between the in-vehicle device 10 and the communication device 20. That is, a packet flow from the TCP handshake to the end of communication can be treated as one unit for setting a flag. For example, the communication device 20 can be configured to store a packet flow identified from a specific source and destination TCP port number and a source and destination IP address, and set a flag "1" for the packet flow when a specific packet flow is established with the in-vehicle device 10. Alternatively, when the in-vehicle device 10 detects the establishment of a specific packet flow with the communication device 20, a control signal for setting a flag "1" can be transmitted to the communication device 20, and the communication device 20 can set the flag "1" in accordance with the control signal. Furthermore, if the party responsible for the communication charges changes during the transmission of a large amount of data, the TCP session is temporarily terminated and a new TCP session (packet flow) is established. At this time, the communication device 20 determines whether the packet flow is the specific one described above or receives a control signal, and sets a flag "1" or "0" for the new TCP session (packet flow). can be done.
[0051] If the value of the flag is "1", that is, if the user of the vehicle bears the cost of transmitting packets to communication device 20, control unit 25 acquires a CDR from accounting unit 24 and generates incentive information for the user (information indicating user behavior) according to the amount of data indicated in the CDR. On the other hand, if the value of the flag is "0", that is, if a party other than the user of the vehicle (such as a business operator) bears the cost of transmitting packets to communication device 20, control unit 25 does not perform an operation to generate incentive information from accounting unit 24.
[0052] The content of the incentive information may be changed depending on the amount of data or may be fixed regardless of the amount of data. The content of the incentive is arbitrary and may include points that can be used to purchase products or receive services, coupons, gift certificates, cash back, or some other preferential treatment, but is not limited to these examples. In addition, instead of incentive information, information indicating an action other than the granting of an incentive may be generated.
[0053] The generated incentive information is stored in, for example, the storage unit 26 and is used as information indicating the basis for the business to give some kind of incentive to the user. For example, the incentive information is transmitted to the in-vehicle device 10 (see FIG. 4). <12> ), may be stored in the auxiliary storage device 32b and, if necessary, displayed on the display 37. However, the method of awarding the incentive is arbitrary.
[0054] In the embodiment, the in-vehicle device 10 (information processing device) includes a controller 30 (controller). The controller 30 has a SIM card 105 (UICC card as a storage unit) that stores authentication data. The in-vehicle device 10 (controller 30) also includes at least one of a wireless communication circuit 103 (wireless communication unit) that establishes a wireless connection with the Internet 1 (non-cellular network), an expansion interface 35 (connector) to which a USB dongle 13 (wireless device) used for the wireless connection with the Internet 1 can be attached / detached, and a NIC 111 (communication unit) that establishes a wired connection with the Internet 1. After connecting to the Internet 1 via the communication device 10A, the USB dongle 13, or the wired LAN 15, the in-vehicle device 10 (controller 30) acquires authentication data from the SIM card 105 and transmits the authentication data via the Internet 1. The authentication data is transmitted to the communication device 20 that performs authentication using the authentication data.
[0055] The in-vehicle device 10 can be connected to a vehicle (standalone) that does not have a communication function with the cellular network 3, thereby operating the vehicle as a connected car and receiving services from a service provider. When the in-vehicle device 10 starts communication with the communication device 20 via an IP network, which is a non-cellular network, a robust authentication process (AKA) can be performed. A vehicle is an example of a "mobile body." A "mobile body" can include smart devices other than vehicles. A "mobile body" corresponds to a data sender. The in-vehicle device 10 can perform robust authentication (AKA) when providing a communication function using a non-cellular network (Internet 1) to the mobile body. In addition, the communication infrastructure used for connection with the communication device 20 can be selected from the communication device 10A, the USB dongle 13, a wired LAN 15, etc.
[0056] In the embodiment, an example has been given in which the in-vehicle device 10 (information processing device) is connected to an in-vehicle device (data generating device) other than the in-vehicle device 10, such as an ECU, and is mounted (including electrically connected) on a vehicle (mobile body). However, the in-vehicle device 10 can be mounted on a mobile body other than a vehicle, such as an IoT device. The timing of mounting may be when the mobile body is manufactured or after the mobile body is manufactured (post-manufacturing). The in-vehicle device 10 is preferably portable, but does not necessarily have to be portable.
[0057] The in-vehicle device 10 can be used independently of a vehicle (mobile body). For example, a user-desired application may be installed in the auxiliary storage device 32b of the in-vehicle device 10, and packets may be transmitted from the in-vehicle device 10 to the communication device 20 by the application. The in-vehicle device 10 can also be connected to a device other than the above-described mobile body, such as a (standalone) computer (PC, etc.) that does not have a communication function, to enable the device to communicate with the communication device 20.
[0058] As in the illustrated embodiment, the authentication data may include SIM profile information stored on the SIM card 105. The authentication data may be a subscriber identifier (IMSI or SUPI), a card identifier (ICCID), or an identifier in lieu of a uniquely identifiable subscriber or card identifier.
[0059] Furthermore, the in-vehicle device 10 does not have a location registration mechanism for a cellular network using the SIM card 105 (UICC card). That is, the in-vehicle device 10 does not receive radio waves from base stations, connect to base stations (cells), or register its location in a cellular network. However, by performing authentication using AKA using the SIM card 105, mutual authentication between the in-vehicle device 10 and the communication device 20 can be performed while ensuring robust security.
[0060] Alternatively, the IMSI (Subscriber Identifier) or ICCID (Card Identifier) may be used as the authentication data. However, since location registration to the cellular network is not performed, a unique identifier that has the same size as the IMSI or ICCID but is different from the IMSI or ICCID can be used as the authentication data.
[0061] Furthermore, the in-vehicle device 10 may include a CAN communication module 34 (a connection mechanism with the vehicle (in-vehicle network)), and if authentication is successful, the in-vehicle device 10 may be able to transmit data received from the vehicle (sender) by the CAN communication module 34 to the communication device 20. That is, the in-vehicle device 10 (controller 30) may transmit data received from the vehicle that is the sender of the data to the communication device 20 after authentication is successful. The timing of receiving data from the sender may be before, during, or after authentication.
[0062] After the authentication is successful, the controller 30 of the in-vehicle device 10 connects the in-vehicle device 10 to the communication device An encrypted line (SWu tunnel) can be set between the communication device 20 and the communication device 20, and data can be transmitted to the communication device 20 using the SWu tunnel. This allows data to be transmitted to the communication device 20 in a state where security is ensured.
[0063] Furthermore, after successful authentication, when data is transmitted to the communication device 20 using the wireless communication circuit 103 (communication device 10A), the expansion interface 35 (USB dongle 13 or communication device 10A), the NIC 111 (wired LAN 15), or the like, the in-vehicle device 10 can receive, from the communication device 20, information indicating an incentive for a party that bears the charge for transmitting the data. For example, if the charge for transmitting packets from the in-vehicle device 10 to the communication device 20 is borne by the user of the vehicle, the communication device 20 can generate information indicating an incentive from the operator to the user according to the data volume of the packets and transmit the information to the in-vehicle device 10. This allows the user of the vehicle (in-vehicle device 10) to obtain information indicating the incentive provided by the operator. By providing the incentive to the user (the party that bears the charge for transmitting data (communication charges)), the party that bears the communication charges can be encouraged to enable the vehicle to communicate with the communication device 20 using the in-vehicle device 10.
[0064] The processes and means described in the present disclosure can be freely combined and implemented as long as no technical contradictions arise. Furthermore, processes described as being performed by one device may be shared and executed by multiple devices. Alternatively, processes described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration for implementing each function can be flexibly changed. The present disclosure can also be realized by providing a computer program that implements the functions described in the above embodiments to a computer, and having one or more processors of the computer read and execute the program. Such a computer program may be provided to the computer via a non-transitory computer-readable storage medium connectable to the computer's system bus, or via a network. [Explanation of symbols]
[0065] 1 Internet, 10 In-vehicle device, 10A, 20 Communication device, 13 USB dongle, 15 wired LAN, 21 gateway, 22 authentication unit, 23 routing unit, 24 accounting unit, 25 control unit, 26 storage unit, 30, 120 control unit
Claims
1. An information processing device capable of communicating with a communication device, a UICC (Universal Integrated Circuit Card) card storing authentication data used to authenticate the information processing device; at least one of a wireless communication unit used for wireless connection with a non-cellular network, a connector to which a wireless device used for wireless connection with the non-cellular network can be detachably attached, and a communication unit used for wired connection with the non-cellular network; a control unit that transmits the authentication data to the communication device via the non-cellular network after the information processing device is connected to the communication device via the non-cellular network by using the wireless communication unit, the wireless device, or the communication unit; An information processing device comprising:
2. The wireless communication unit is wirelessly connected to a wireless device that connects the information processing device to the non-cellular network via a cellular network. The information processing device according to claim 1 .
3. The wireless device that connects the information processing device to the non-cellular network via a cellular network is attached to the connector. The information processing device according to claim 1 .
4. The communication unit includes an interface circuit that connects the information processing device to the non-cellular network via a wired LAN. The information processing device according to claim 1 .
5. The authentication data includes SIM (Subscriber Identity Module) profile information. The information processing device according to claim 1 .
6. The authentication data is a subscriber identifier, a card identifier, or an identifier that is uniquely identifiable in place of the subscriber identifier or the card identifier. The information processing device according to claim 1 .
7. Does not have a location registration function to the cellular network using the UICC card The information processing device according to claim 1 .
8. Further including a connection mechanism with a data source; If the authentication is successful, the data received from the sender can be sent to the communication device. The information processing device according to claim 1.
9. After the authentication is successful, the control unit sets up an encrypted line between the information processing device and the communication device, and transmits data to the communication device using the encrypted line. The information processing device according to claim 1 .
10. When data is transmitted to the communication device using the wireless communication unit, the wireless device, or the communication unit after the authentication is successful, the information processing device receives, from the communication device, information indicating an incentive for a person who bears the fee for transmitting the data. The information processing device according to claim 1 .
11. A UICC (Universal Integrated Computer Card) capable of communicating with a communication device and storing authentication data used for authentication. an information processing device having a Personal Integrated Circuit Card (PEC) card, After the information processing device is connected to the communication device via the non-cellular network by using either a wireless communication unit used for wireless connection with a non-cellular network, a wireless device used for wireless connection with the non-cellular network attached to a connector of the information processing device, or a communication unit used for wired connection with the non-cellular network, the information processing device transmits the authentication data to the communication device via the non-cellular network. A communication method that performs the following:
12. The wireless communication unit is wirelessly connected to a wireless device that connects the information processing device to the non-cellular network via a cellular network. The communication method according to claim 11.
13. The wireless device attached to the connector connects the information processing device to the non-cellular network via a cellular network. The communication method according to claim 11.
14. The communication unit connects the information processing device to the non-cellular network via a wired LAN. The communication method according to claim 11.
15. The authentication data includes SIM (Subscriber Identity Module) profile information. The communication method according to claim 11.
16. The authentication data is a subscriber identifier, a card identifier, or an identifier that is uniquely identifiable in place of the subscriber identifier or the card identifier. The communication method according to claim 11.
17. The information processing device is an information processing device that does not have a location registration function to a cellular network using the UICC card. The communication method according to claim 11.
18. The information processing device further executes, after the authentication is successful, transmitting the data received from the data sender to the communication device. The communication method according to claim 11.
19. A computer of an information processing device that can communicate with a communication device and has a UICC (Universal Integrated Circuit Card) card that stores authentication data used for authentication, transmitting the authentication data to the communication device via the non-cellular network after the information processing device is connected to the communication device via the non-cellular network by using either a wireless communication unit for wirelessly connecting to a non-cellular network, a wireless device for wirelessly connecting to the non-cellular network, or a communication unit for wired connection to the non-cellular network, which is connected to a connector of the information processing device; A program that executes the following.
20. A mobile body equipped with an information processing device capable of communicating with a communication device, The information processing device includes: a UICC (Universal Integrated Circuit Card) card that stores authentication data used for authentication; At least one of a wireless communication unit for wirelessly connecting to a non-cellular network, a connector for detachably connecting a wireless device used for wirelessly connecting to the non-cellular network, and a communication unit for wired connection to the non-cellular network. At least one, a control unit that transmits the authentication data to the communication device via the non-cellular network after the information processing device is connected to the communication device via the non-cellular network by using the wireless communication unit, the wireless device, or the communication unit; After the authentication is successful, the information processing device is able to transmit data to the communication device. Mobile object.
Citation Information
Patent Citations
Communication apparatus, device, communication system, and application writing method
JP2022180105A