Wireless communication system and communication method

The wireless communication system uses encryption keys generated from unique information to securely relay communications between wireless stations in closed and Internet networks, addressing the inability of LTE terminals to encrypt voice data in existing systems.

JP2026017880APending Publication Date: 2026-02-05ICOM INC

Patent Information

Application Number
JP2024118925
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

The LTE communication terminal in existing systems is unable to encrypt voice data, preventing communication with devices connected to the Internet via a LAN.

Method used

A wireless communication system comprising a closed system in a closed network and a cloud system in an Internet network, with activation servers in both systems storing unique information and encryption key generation information, and using encryption keys to protect communication between wireless stations connected to either network.

Benefits of technology

Ensures secure communication relay between wireless stations connected to either a closed network or the Internet by using encryption keys generated based on unique information, thereby enabling safe communication across different network types.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026017880000001_ABST
    Figure 2026017880000001_ABST
Patent Text Reader

Abstract

To provide a radio communication system and a communication method capable of safely relaying communication between a radio station connected to the Internet network and a radio station connected to a closed network.SOLUTION: The closed area system 11 and the cloud system 21 included in the wireless communication system 1 include a closed area side gateway server 13 and a cloud side gateway server 22. When receiving an authentication request from a radio station 41,42, a closed area side gateway server 13 and a cloud side gateway server 22 store activation information including unique information of the radio station 41,42 and generation information of an encryption key in a storage device 27. Regardless of whether the wireless station 41,42 is connected to the closed network 10 or the Internet network 20, the communication between the wireless station 41,42 and the closed system 11 or the cloud system 21 is protected by the encryption key generated based on the generation information included in the activation information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a wireless communication system and a communication method. [Background technology]

[0002] In order for communication devices connected to different networks such as a LAN (Local Area Network) and a WAN (Wide Area Network) to communicate with each other, a gateway device is provided between the different networks. Patent Document 1 discloses an example of a communication device that communicates with other communication devices connected to different networks via a gateway device.

[0003] The voice communication system disclosed in Patent Document 1 includes a gateway device that connects a LAN and LTE (Long Term Evolution), a mobile phone communication network, and relays communication between a LAN communication terminal connected to the LAN and an LTE communication terminal connected to the LTE. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] International Publication No. 2017 / 006833 Summary of the Invention [Problem to be solved by the invention]

[0005] The LTE communication terminal disclosed in Patent Document 1 is capable of communicating with LAN communication terminals, but does not encrypt voice data and is therefore unable to communicate with communication terminals connected to the Internet via a LAN.

[0006] The present invention has been made in consideration of the above-mentioned circumstances, and an object of the present invention is to provide a wireless communication system and a communication method that can safely relay communications between a wireless station connected to an Internet network and a wireless station connected to a closed network. [Means for solving the problem]

[0007] In order to achieve the above object, a wireless communication system according to a first aspect of the present invention comprises a closed system provided in a closed network and a cloud system provided in an internet network, the closed system and the cloud system being connected to each other so as to be able to communicate with each other, The closed system comprises: a call control server that controls communications between a plurality of wireless stations, each of which is connected to either the closed network or the Internet; a closed-side activation server that, upon receiving an authentication request from a wireless station connected to the closed network, includes unique information for uniquely identifying the wireless station and encryption key generation information, stores activation information including the unique information and the encryption key generation information in a storage device provided in at least one of the closed system and the cloud system; The cloud system includes: a cloud-side activation server that, upon receiving an authentication request including the unique information and the generation information from the wireless station connected to the Internet network, stores activation information including the unique information and the generation information in the storage devices provided in the closed system and the cloud system, respectively; Regardless of whether the wireless station is connected to the closed network or the Internet network, communication between the wireless station, whose activation information is stored in the storage device, and the closed system or the cloud system is protected by an encryption key generated based on the generation information included in the activation information.

[0008] Preferably, the closed system further includes a closed-side gateway server that holds correspondence between the radio stations and the call control servers, and that, upon receiving an encrypted registration request or voice data from a radio station connected to the closed network, decrypts the registration request or the voice data using the encryption key generated based on the generation information included in the activation information of the radio station stored in the storage device, and transmits the decrypted registration request or the voice data to the call control server associated with the radio station, and, upon receiving a registration response or voice data from the call control server, encrypts the registration response or the voice data using the encryption key, and transmits the encrypted registration response or the voice data to the radio station.

[0009] Preferably, the cloud system further includes a cloud-side gateway server that maintains correspondence between the wireless stations and the call control servers, and that, upon receiving an encrypted registration request or voice data from a wireless station connected to the Internet network, decrypts the registration request or the voice data using the encryption key generated based on the generation information included in the activation information of the wireless station stored in the storage device, and transmits the decrypted registration request to the call control server associated with the wireless station, and, upon receiving a registration response or voice data addressed to the wireless station connected to the Internet network from the call control server, encrypts the registration response or the voice data using the encryption key, and transmits the encrypted registration response or the voice data to the wireless station.

[0010] Preferably, when the closed-side gateway server and the cloud-side gateway server receive the registration request or the voice data, if the generation information included in the activation information corresponding to the wireless station that is the sender is not stored in the closed-side gateway server and the cloud-side gateway server, the closed-side gateway server and the cloud-side gateway server each acquire the generation information included in the activation information of the wireless station from the storage device and store the acquired generation information in the closed-side gateway server and the cloud-side gateway server, the closed-side activation server instructs each of the closed-side gateway server and the cloud-side gateway server to delete the stored generation information every time the activation information is stored in the storage device; Each time the cloud-side activation server stores the activation information in the storage device, it instructs each of the closed-side gateway server and the cloud-side gateway server to erase the stored generation information.

[0011] Preferably, the cloud system further includes a cloud-side provisioning server that, when receiving an encrypted provisioning request from the wireless station connected to the closed network, decrypts the provisioning request with the encryption key generated based on the generation information included in the activation information of the wireless station stored in the storage device, encrypts a provisioning response including connection information for connecting to the closed-side gateway server with the encryption key, and transmits the encrypted provisioning response to the wireless station, and, when receiving an encrypted provisioning request from the wireless station connected to the Internet network, decrypts the provisioning request with the encryption key generated based on the generation information included in the activation information of the wireless station stored in the storage device, encrypts a provisioning response including connection information for connecting to the cloud-side gateway server with the encryption key, and transmits the encrypted provisioning response to the wireless station.

[0012] A communication method according to a second aspect of the present invention is a wireless communication system comprising a closed system provided in a closed network and a cloud system provided in an Internet network, the closed system and the cloud system being connected to each other so as to be able to communicate with each other, the closed system having a call control server that controls communication between a plurality of wireless stations, each of which is connected to either the closed network or the Internet network, and a closed-side activation server that receives, from the wireless stations connected to the closed network, an authentication request including unique information that uniquely identifies the wireless station and information for generating an encryption key, the cloud system having a cloud-side activation server that receives, from the wireless stations connected to the Internet network, an authentication request including the unique information and the generation information, the communication method being performed by the wireless communication system, The closed-side activation server performs a closed-side activation step of storing activation information including the unique information and the generation information in a storage device provided in at least one of the closed system and the cloud system when the authentication request is received from the wireless station connected to the closed network; The cloud-side activation server performs a cloud-side activation step of storing activation information including the unique information and the generation information in the storage device when the authentication request is received from the wireless station connected to the Internet network, Regardless of whether the wireless station is connected to the closed network or the Internet network, communication between the wireless station, whose activation information is stored in the storage device, and the closed system or the cloud system is protected by an encryption key generated based on the generation information included in the activation information. [Effects of the Invention]

[0013] The wireless communication system according to the present invention includes a closed-side activation server and a cloud-side activation server that, upon receiving an authentication request from a wireless station, stores activation information including wireless station-specific information and encryption key generation information in a storage device, and whether the wireless station is connected to a closed network or the Internet, communication between the wireless station and the closed system or the cloud system is protected by an encryption key generated based on the generation information included in the activation information. As a result, a wireless communication system and a communication method are obtained that can securely relay communications of wireless stations. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 is a block diagram showing a configuration of a wireless communication system according to a first embodiment; [Figure 2] FIG. 1 is a block diagram showing a configuration of a radio station according to a first embodiment. [Figure 3] A flowchart showing an example of a startup process performed by a wireless station according to the first embodiment. [Figure 4] FIG. 1 is a sequence diagram illustrating an example of activation processing performed by a wireless communication system according to a first embodiment. [Figure 5] FIG. 1 is a sequence diagram illustrating an example of a provisioning process performed by a wireless communication system according to a first embodiment. [Figure 6] FIG. 1 is a sequence diagram illustrating an example of a registration process performed by a wireless communication system according to a first embodiment. [Figure 7] FIG. 10 is a sequence diagram illustrating another example of the activation process performed by the wireless communication system according to the first embodiment. [Figure 8] FIG. 10 is a sequence diagram illustrating another example of the provisioning process performed by the wireless communication system according to the first embodiment. [Figure 9] FIG. 10 is a sequence diagram showing another example of the registration process performed by the wireless communication system according to the first embodiment. [Figure 10] FIG. 1 is a sequence diagram illustrating an example of a call establishment process performed by the wireless communication system according to the first embodiment. [Figure 11]A flowchart showing an example of a switching process performed by a wireless station according to the first embodiment. [Figure 12] FIG. 10 is a block diagram showing a configuration of a wireless communication system according to a second embodiment. [Figure 13] FIG. 10 is a sequence diagram illustrating an example of a registration process performed by a wireless communication system according to a second embodiment. [Figure 14] FIG. 1 is a block diagram showing a hardware configuration for realizing a closed system and a cloud system according to an embodiment. [Figure 15] FIG. 1 is a block diagram showing a modified example of a hardware configuration for realizing a closed system and a cloud system according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0015] A wireless communication system and a communication method according to an embodiment of the present invention will be described in detail below with reference to the drawings, in which the same or equivalent parts are designated by the same reference numerals.

[0016] (Embodiment 1) The wireless communication system 1 shown in Fig. 1 relays communications between wireless stations 41 and 42 connected to either a private network 10 or an Internet network 20. In the first embodiment, the wireless stations 41 and 42 are IP (Internet Protocol) transceivers that perform voice communications. The wireless stations 41 and 42 have the same configuration and function. In the example of Fig. 1, the wireless station 41 is connected to the private network 10 via a base station 31, and the wireless station 42 is connected to the Internet network 20 via a WLAN (Wireless Local Area Network) device 32. The WLAN device 32 is, for example, an access point device.

[0017] The wireless communication system 1 includes a closed system 11 provided in a closed network 10, and a cloud system 21 provided in an Internet network 20. The closed system 11 includes a call control server 12, a closed-side gateway server 13, a closed-side DNS (Domain Name System) server 14, a closed-side activation server 15, a router 16, and a storage device 17. The cloud system 21 includes a cloud-side gateway server 22, a cloud-side provisioning server 23, a cloud-side activation server 24, an endpoint device 25, a dedicated connection device 26, and a storage device 27.

[0018] The closed system 11 and the cloud system 21 are connected to each other by a dedicated line. The dedicated connection device 26 connects each of the cloud side devices included in the cloud system 21 to the closed side devices included in the closed system 11 and the closed network 10 by a dedicated line. The closed side devices are the components of the closed system 11 described above, specifically, the call control server 12, the closed side gateway server 13, the closed side DNS server 14, the closed side activation server 15, the router 16, and the storage device 17. The cloud side devices are the components of the cloud system 21, specifically, the cloud side gateway server 22, the cloud side provisioning server 23, the cloud side activation server 24, the endpoint device 25, the dedicated connection device 26, and the storage device 27. Note that the term "device" refers to not only physically existing devices but also virtual devices.

[0019] The closed system 11 includes any number of call control servers 12. Each call control server 12 controls communications between wireless stations 41 and 42, specifically, controls outgoing, incoming, and outgoing calls. Each wireless station 41 and 42 is associated with one of the call control servers 12.

[0020] The closed-side gateway server 13 holds a correspondence between the wireless station 41 and the call control server 12. As an example, the closed-side gateway server 13 holds a table that associates unique information that uniquely identifies the wireless station 41 with the address of the call control server 12. The unique information that uniquely identifies the wireless station 41 is, for example, an IMEI (International Mobile Equipment Identifier) ​​or an ICCID (Integrated Circuit Card Identifier), which is an identification number of a SIM (Subscriber Identity Module) card inserted in the wireless station 41.

[0021] When the closed-side gateway server 13 receives a registration request or voice data from a wireless station 41 connected to the closed network 10 via the router 16, it decrypts the received registration request or voice data and transmits it to the call control server 12 associated with the wireless station 41. When the closed-side gateway server 13 receives a registration response or voice data from the call control server 12, it encrypts the received registration response or voice data and transmits it to the destination wireless station 41 via the router 16.

[0022] The closed-side DNS server 14 performs name resolution for closed-side devices included in the closed system 11 and for cloud-side devices included in the cloud system 21. The closed-side devices that are the targets of name resolution by the closed-side DNS server 14 are, for example, the closed-side gateway server 13 and the closed-side activation server 15. The cloud-side devices that are the targets of name resolution by the closed-side DNS server 14 are, for example, the dedicated connection device 26.

[0023] In detail, when the closed-side DNS server 14 receives a name resolution request including a domain name of a closed-side device included in the closed system 11 or a cloud-side device included in the cloud system 21 from a wireless station 41 connected to the closed network 10, the closed-side DNS server 14 performs name resolution of the domain name included in the name resolution request and transmits a name resolution response including a corresponding address corresponding to the domain name to the wireless station 41.

[0024] When the closed-side activation server 15 receives an authentication request including the unique information of the wireless station 41 and the generation information of the encryption key from the wireless station 41 connected to the closed network 10, the closed-side activation server 15 stores the activation information including the unique information and the generation information in a storage device provided in at least one of the closed system 11 and the cloud system 21, for example, in the storage devices 17 and 27 provided in the closed system 11 and the cloud system 21, respectively. The generation information is, for example, a different hash value associated with each of the wireless stations 41 and 42.

[0025] The storage device 17 is a DB server, for example, a NoSQL server, that stores activation information.

[0026] The router 16 transmits data received from the cloud system 21 or the closed network 10 to a closed-side device included in the closed system 11 depending on the destination of the data. The router 16 transmits data received from a closed-side device to the cloud system 21 or the closed network 10 depending on the destination of the data.

[0027] The dedicated connection device 26 has, for example, a virtual interface that is connected via a dedicated line to the closed system 11 and the closed network 10. The dedicated connection device 26 transmits data received from the closed system 11 or the closed network 10 having the above configuration to a cloud-side device included in the cloud system 21 according to the type of the data.

[0028] In detail, data transmitted from a wireless station 41 connected to the closed network 10 or a closed-side device included in the closed system 11 reaches the dedicated connection device 26. The dedicated connection device 26 transfers the received data to a cloud-side device depending on the type of the data. For example, when the dedicated connection device 26 receives a provisioning request from the wireless station 41, it transfers the provisioning request to the cloud-side provisioning server 23 via a load balancing device (not shown). The dedicated connection device 26 transmits data received from a cloud-side device included in the cloud system 21 to the closed system 11 or the closed network 10 via a virtual interface depending on the destination of the data.

[0029] Endpoint device 25 has an interface connected to Internet network 20. Endpoint device 25 transmits data received from Internet network 20 to each device in cloud system 21. In particular, endpoint device 25 forwards various requests received from Internet network 20, specifically, activation requests, provisioning requests, and registration requests, to devices according to the request types, namely, cloud-side activation server 24, cloud-side provisioning server 23, and cloud-side gateway server 22. Endpoint device 25 also forwards data addressed to wireless station 42 received from each device in cloud system 21 to wireless station 42 via Internet network 20.

[0030] The cloud-side gateway server 22 holds a correspondence between the wireless station 42 and the call control server 12. As an example, the cloud-side gateway server 22 holds a table that associates unique information that uniquely identifies the wireless station 42 with the address of the call control server 12. The unique information that uniquely identifies the wireless station 42 is, for example, the IMEI, an ICCID that is the identification number of the SIM card inserted in the wireless station 42, or the like.

[0031] When the cloud-side gateway server 22 receives a registration request or voice data from a wireless station 42 connected to the Internet network 20, it decrypts the received registration request or voice data and transmits it to the call control server 12 associated with the wireless station 42. When the cloud-side gateway server 22 receives a registration response or voice data from the call control server 12, it encrypts the received registration response or voice data and transmits it to the wireless station 42 as the destination.

[0032] When the cloud-side provisioning server 23 receives a provisioning request from the wireless stations 41 and 42, it transmits a provisioning response including the domain name of the gateway server to the wireless stations 41 and 42.

[0033] When the cloud-side activation server 24 receives an authentication request from a wireless station 42 connected to the Internet network 20, the activation information including the wireless station 42's unique information and encryption key generation information is stored in a storage device provided in at least one of the closed system 11 and the cloud system 21, for example, in storage devices 17 and 27 provided in the closed system 11 and the cloud system 21, respectively.

[0034] The storage device 27 is a DB server, such as a NoSQL server, that stores activation information. As an example, the storage device 27 is a master DB, and the activation information stored in the storage device 27 is periodically updated in the storage device 17, which is a replica DB.

[0035] 2 shows the configuration of radio stations 41, 42 that communicate via the radio communication system 1 having the above configuration. The radio stations 41, 42 each include an LTE communication circuit 51, a WLAN communication circuit 52, a communication control circuit 53, a data processing circuit 54, an input circuit 55, and an output circuit 56. The LTE communication circuit 51 connects to the private network 10 and transmits and receives private network data that conforms to the communication standards of the private network 10. The WLAN communication circuit 52 connects to the Internet network 20 via the WLAN device 32 and transmits and receives communication data that conforms to the communication standards of the Internet network 20. The communication control circuit 53 controls the LTE communication circuit 51 and the WLAN communication circuit 52 to establish voice communication.

[0036] The data processing circuit 54 generates closed network data to be transmitted from the LTE communication circuit 51 or communication data to be transmitted from the WLAN communication circuit 52 from the transmission data generated by the input circuit 55. The data processing circuit 54 also generates received data from the closed network data received by the LTE communication circuit 51 or the communication data received by the WLAN communication circuit 52, and outputs the received data to the output circuit 56.

[0037] The input circuit 55 acquires audio from a microphone (not shown), performs signal processing such as AD (Analog-to-Digital) conversion, noise filtering, and amplification, generates data for transmission, and sends the generated data for transmission to the data processing circuit 54.

[0038] The output circuit 56 performs signal processing such as noise filtering, amplification, and DA (Digital-to-Analog) conversion on the received data acquired from the data processing circuit 54 to generate audio data, and outputs the generated audio data from a speaker (not shown). The output circuit 56 may also acquire processing results such as activation, provisioning, and registration from the data processing circuit 54 and display them on a screen (not shown).

[0039] When the wireless stations 41 and 42 having the above configuration start up, for example when the power is turned on, they start the startup process shown in Fig. 3. By performing the startup process, the wireless stations 41 and 42 can start voice communication.

[0040] The following describes the startup process performed by the wireless station 41 connected to the private network 10. The wireless station 41 performs activation, which is a setting when the wireless station 41 starts to be used (step S11).

[0041] Details of the activation process performed by the wireless station 41 are shown in Figure 4. The wireless station 41 transmits a name resolution request including the domain name of the closed-side activation server 15, which is the destination of the activation request, to the closed-side DNS server 14 (sequence Sq1). In detail, the wireless station 41 sets its own IP address as the source IP address and the IP address of the closed-side DNS server 14 as the destination IP address, and generates and transmits a name resolution request including the domain name of the closed-side activation server 15. It is assumed that the wireless station 41 holds the IP address of the closed-side DNS server 14 in advance. The name resolution request transmitted from the wireless station 41 reaches the closed-side DNS server 14 via the base station 31, the closed network 10, and the router 16.

[0042] When the closed-side DNS server 14 receives the name resolution request including the domain name of the closed-side activation server 15, it transmits a name resolution response including the address of the closed-side activation server 15 to the wireless station 41 (sequence Sq2). In detail, the closed-side DNS server 14 sets its own IP address as the source IP address and the source IP address of the name resolution request as the destination IP address, and generates and transmits the name resolution response including the address of the closed-side activation server 15. The name resolution response transmitted from the closed-side activation server 15 reaches the wireless station 41 via the router 16, the closed network 10, and the base station 31.

[0043] Upon receiving the name resolution response, the wireless station 41 transmits an activation request to the closed-side activation server 15 (sequence Sq3). Specifically, the wireless station 41 sets its own IP address as the source IP address and the address of the closed-side activation server 15 included in the name resolution response as the destination IP address, and then generates and transmits the activation request. The activation request transmitted from the wireless station 41 reaches the closed-side activation server 15 via the base station 31, the closed network 10, and the router 16.

[0044] Upon receiving the activation request, the closed-side activation server 15 transmits an activation response including the token to the wireless station 41 (sequence Sq4). Specifically, the closed-side activation server 15 sets its own IP address as the source IP address and sets the source IP address of the activation request, i.e., the IP address of the wireless station 41, as the destination IP address, generates and transmits an activation response including the token. The activation response transmitted from the closed-side activation server 15 reaches the wireless station 41 via the router 16, the private network 10, and the base station 31.

[0045] Upon receiving the activation response, the wireless station 41 extracts the token included in the activation response and transmits an authentication request including the wireless station 41's unique information, the token, and encryption key generation information to the closed-side activation server 15 (sequence Sq5). In detail, the wireless station 41 sets its own IP address as the source IP address and the address of the closed-side activation server 15 as the destination IP address, generates and transmits an authentication request including the wireless station 41's unique information, the token included in the activation response, and encryption key generation information.

[0046] Upon receiving the authentication request, the closed-side activation server 15 performs a parameter check based on the unique information and token of the wireless station 41 included in the authentication request to determine whether the authentication request is valid (sequence Sq6). If the closed-side activation server 15 determines that the authentication request is valid, it stores activation information including the unique information and generation information of the wireless station 41 in the storage device 27 (sequence Sq7).

[0047] As described above, when storage device 27 is the master DB and storage device 17 is the replica DB, if closed-side activation server 15 stores activation information only in storage device 27, the activation information will be stored in both storage devices 17 and 27. When the closed-side activation server 15 has completed storing the activation information, it instructs closed-side gateway server 13 and cloud-side gateway server 22 to erase the generated information (sequences Sq8 and Sq9).

[0048] When the closed-side gateway server 13 receives the instruction to delete the generated information, it deletes the generated information stored therein in order to perform the encryption or decryption process without delay (sequence Sq10). When the cloud-side gateway server 22 receives the instruction to delete the generated information, it deletes the generated information stored therein in order to perform the encryption or decryption process without delay (sequence Sq11). As a result, the generated information temporarily stored in the closed-side gateway server 13 and the cloud-side gateway server 22 is cleared.

[0049] Thereafter, the closed-side activation server 15 transmits an authentication response (sequence Sq12). Specifically, the closed-side activation server 15 sets its own IP address as the source IP address and sets the source IP address of the authentication request, i.e., the IP address of the wireless station 41, as the destination IP address, and generates and transmits the authentication response.

[0050] For example, if the storage device 27 cannot be accessed and the storage of the activation information is not completed normally, the closed-side activation server 15 does not send the authentication response of sequence Sq12, but instead sends an error notification, for example, a notification that the activation has been aborted, to the wireless station 41.

[0051] As shown in FIG. 3, when the activation process does not end normally (step S12; No), for example, when an error notification is received from the closed-side activation server 15, the wireless station 41 displays on the screen that an error has occurred (step S20).

[0052] When the activation process is completed successfully (step S12; Yes), specifically, when the wireless station 41 receives an authentication response from the closed-side activation server 15, the wireless station 41 performs a provisioning process to obtain connection information (step S13).

[0053] 5 shows details of the provisioning process performed by the wireless station 41. The wireless station 41 transmits a name resolution request including the domain name of the dedicated connection device 26 that is the destination of the provisioning request to the closed-side DNS server 14 (sequence Sq21).

[0054] When the closed-side DNS server 14 receives the name resolution request including the domain name of the cloud-side provisioning server 23, it transmits a name resolution response including the address of the dedicated connection device 26 to the wireless station 41 (sequence Sq22).

[0055] Upon receiving the name resolution response, the wireless station 41 transmits a provisioning request addressed to the cloud-side provisioning server 23, including the wireless station 41's unique information, to the dedicated connection device 26 (sequence Sq23). In detail, the wireless station 41 sets its own IP address as the source IP address and the address of the dedicated connection device 26 included in the name resolution response as the destination IP address, and generates and transmits a provisioning request including the wireless station 41's unique information. The wireless station 41 preferably encrypts the provisioning request with an encryption key generated based on the generation information, then encrypts the provisioning request with a public key, and transmits the encrypted provisioning request to the dedicated connection device 26. At this time, it is assumed that the wireless station 41 and the cloud-side provisioning server 23 hold information about a common public key.

[0056] Upon receiving the provisioning request, the dedicated connection device 26 transfers the provisioning request to the cloud-side provisioning server 23 (sequence Sq24). For example, the dedicated connection device 26 decrypts the provisioning request using the public key and transfers the decrypted provisioning request to the cloud-side provisioning server 23 via the load balancer. Note that the decryption using the public key may be performed in the load balancer. The provisioning request transmitted from the wireless station 41 reaches the cloud-side provisioning server 23 via the base station 31, the closed network 10, and the dedicated connection device 26.

[0057] Upon receiving the provisioning request, the cloud-side provisioning server 23 extracts the unique information of the wireless station 41 included in the provisioning request and transmits an activation information request to the storage device 27 to acquire activation information of the wireless station 41 (sequence Sq25). Upon receiving the activation information request, the storage device 27 transmits the activation information of the wireless station 41 to the cloud-side provisioning server 23 (sequence Sq26).

[0058] The cloud-side provisioning server 23 checks whether activation of the wireless station 41 has been performed normally based on the activation information acquired in sequence Sq26 (sequence Sq27). Specifically, the cloud-side provisioning server 23 generates an encryption key from the generation information included in the activation information and decrypts the provisioning request with the generated encryption key. If the provisioning request can be successfully decrypted, the activation information stored in the storage device 27 is correct, and therefore it can be considered that activation has been performed normally.

[0059] If the activation is successful, the cloud-side provisioning server 23 transmits a provisioning response addressed to the wireless station 41 to the dedicated connection device 26, the provisioning response including connection information for connecting to the closed-side gateway server 13 associated with the call control server 12 corresponding to the wireless station 41 (sequence Sq28). In detail, the cloud-side provisioning server 23 sets the IP address of its own device as the source IP address and sets the source IP address of the provisioning request, i.e., the IP address of the wireless station 41, as the destination IP address, and generates a provisioning response including the connection information.

[0060] Upon receiving the provisioning response, the dedicated connection device 26 transfers the provisioning response to the destination wireless station 41 (sequence Sq29). The dedicated connection device 26 preferably encrypts the provisioning response using a public key and transmits the encrypted provisioning response to the wireless station 41. The provisioning response transmitted from the cloud-side provisioning server 23 reaches the wireless station 41 via the dedicated connection device 26, the closed network 10, and the base station 31. The wireless station 41 decrypts the received provisioning response using the public key.

[0061] For example, if the cloud-side provisioning server 23 cannot access the storage device 27 and cannot acquire the activation information, the cloud-side provisioning server 23 does not transmit the provisioning response of sequence Sq28, but transmits an error notification addressed to the wireless station 41 to the dedicated connection device 26. Upon receiving the error notification, the dedicated connection device 26 forwards the error notification to the wireless station 41.

[0062] 3, when the provisioning process does not end normally (step S14; No), for example, when an error notification is received from the cloud-side provisioning server 23 or when the wireless station 41 cannot connect to the cloud-side provisioning server 23, the wireless station 41 determines whether or not previous information, which is connection information acquired when the previous startup process was performed, is available (step S15). If previous information is not available (step S15; No), the wireless station 41 displays on the screen that an error has occurred (step S20).

[0063] If the provisioning process did not end normally but previous information exists (step S14; No, step S15; Yes), or if the provisioning process ended normally (step S14; Yes), the wireless station 41 reflects the connection information or previous information acquired in step S13 as connection information in its own device (step S16).

[0064] Next, the wireless station 41 performs registration to store information about itself in the call control server 12 (step S17). Details of the registration process performed by the wireless station 41 are shown in Fig. 6. The wireless station 41 transmits a name resolution request including the domain name of the closed-side gateway server 13, which is the destination of the registration request, to the closed-side DNS server 14 (sequence Sq31).

[0065] When the closed-side DNS server 14 receives the name resolution request including the domain name of the closed-side gateway server 13, it transmits a name resolution response including the address of the closed-side gateway server 13 to the wireless station 41 (sequence Sq32).

[0066] Upon receiving the name resolution response, the wireless station 41 transmits a registration request to the closed-side gateway server 13 (sequence Sq33). Specifically, the wireless station 41 sets its own IP address as the source IP address and the address of the closed-side gateway server 13 included in the name resolution response as the destination IP address, and generates and transmits a registration request including the wireless station 41's unique information and encryption key generation information. The wireless station 41 encrypts the registration request using an encryption key that can be generated based on the generation information included in the registration request, and transmits the encrypted registration request. As an example, the registration request includes confidential data including unique information, such as the IMEI, and data encrypted with the encryption key. The registration request transmitted from the wireless station 41 reaches the closed-side gateway server 13 via the base station 31, the closed network 10, and the router 16.

[0067] Upon receiving the registration request, the closed-side gateway server 13 extracts the unique information of the wireless station 41 included in the registration request and transmits an activation information request to the storage device 27 to acquire activation information of the wireless station 41 (sequence Sq34). As an example, the closed-side gateway server 13 extracts the unique information of the wireless station 41 from the concealed data included in the registration request using a predetermined calculation method. Upon receiving the activation information request, the storage device 27 transmits the activation information of the wireless station 41 to the closed-side gateway server 13 (sequence Sq35).

[0068] The closed-side gateway server 13 stores the activation information acquired in sequence Sq35, specifically, the association between the unique information and the generation information of the wireless station 41. The closed-side gateway server 13 generates an encryption key from the generation information included in the activation information acquired in sequence Sq35, and decrypts the registration request with the generated encryption key (sequence Sq36).

[0069] The closed-side gateway server 13 transmits the decrypted registration request to the call control server 12 corresponding to the wireless station 41 (sequence Sq37). The closed-side gateway server 13 stores the source address of the registration request and the unique information of the wireless station 41 included in the registration request in association with each other.

[0070] Upon receiving the registration request, the call control server 12 transmits a registration response including the unique information of the wireless station 41 to the closed-area gateway server 13 that is the sender of the registration request (sequence Sq38).

[0071] Upon receiving the registration response, the closed-side gateway server 13 encrypts the registration response with the encryption key used for decryption in sequence Sq36 (sequence Sq39). The closed-side gateway server 13 transmits the encrypted registration response to the wireless station 41 (sequence Sq40). Specifically, the closed-side gateway server 13 sets the IP address of its own device as the source IP address and sets the IP address associated with the unique information of the wireless station 41 included in the registration response received from the call control server 12 as the destination IP address, and generates and transmits the registration response. The registration response transmitted from the closed-side gateway server 13 reaches the wireless station 41 via the router 16, the closed network 10, and the base station 31. The wireless station 41 decrypts the received registration response with an encryption key that can be generated based on the generation information included in the authentication request.

[0072] 3, when the registration process does not end normally (step S18; No), for example, when the radio station 41 does not receive a registration response from the closed-side gateway server 13 within a certain time, the radio station 41 displays on the screen a message indicating that an error has occurred (step S20). The certain time may be determined according to the time required for receiving a registration response after transmitting a registration request under normal circumstances, the length of an allowable downtime, etc.

[0073] When the registration process has been completed successfully (step S18; Yes), specifically, when the wireless station 41 has received a registration response from the closed-side gateway server 13, the wireless station 41 displays on the screen a message that the startup process has been completed successfully (step S19). When the process of displaying on the screen a message that the startup process has been completed successfully in step S19 is completed, the wireless station 41 becomes able to start voice communication. When steps S19 and S20 are completed, the wireless station 41 ends the startup process.

[0074] The startup process of the wireless station 42 is also the same as that shown in Fig. 3. The activation, provisioning, and registration processes performed by the wireless station 42 will be described in detail below.

[0075] 7 shows details of the activation process performed by the wireless station 42. The wireless station 42 sends a name resolution request including the domain name of endpoint device 25, which is the destination of the activation request, to an Internet DNS server on the Internet network 20 (not shown in FIG. 1) (sequence Sq41). Upon receiving the name resolution request including the domain name of endpoint device 25, the Internet DNS server sends a name resolution response including the address of endpoint device 25 to the wireless station 42 (sequence Sq42).

[0076] Upon receiving the name resolution response, wireless station 42 transmits an activation request to endpoint device 25 (sequence Sq43). In detail, wireless station 42 sets the IP address of its own device as the source IP address and sets the address of endpoint device 25 included in the name resolution response as the destination IP address, and generates and transmits the activation request.

[0077] Upon receiving the activation request, endpoint device 25 forwards the activation request to cloud-side activation server 24 (sequence Sq44). The activation request transmitted from wireless station 42 reaches cloud-side activation server 24 via WLAN device 32, Internet network 20, and endpoint device 25.

[0078] Upon receiving the activation request, cloud-side activation server 24 transmits an activation response addressed to wireless station 42 and including the token to endpoint device 25 (sequence Sq45). Specifically, cloud-side activation server 24 sets the IP address of its own device as the source IP address and sets the source IP address of the activation request, i.e., the IP address of wireless station 42, as the destination IP address, and generates and transmits the activation response including the token.

[0079] Upon receiving the activation response, endpoint device 25 forwards the activation response to the destination wireless station 42 (sequence Sq46). The activation response sent from cloud-side activation server 24 reaches wireless station 42 via endpoint device 25, Internet network 20, and WLAN device 32.

[0080] Upon receiving the activation response, the wireless station 42 extracts the token included in the activation response and transmits an authentication request including the unique information of the wireless station 42, the token, and encryption key generation information to the endpoint device 25 (sequence Sq47). In detail, the wireless station 42 sets its own IP address as the source IP address and the address of the endpoint device 25 as the destination IP address, and generates and transmits an authentication request including the unique information of the wireless station 42, the token included in the activation response, and encryption key generation information.

[0081] Upon receiving the authentication request, the endpoint device 25 transfers the authentication request to the cloud-side activation server 24 (sequence Sq48).

[0082] Upon receiving the authentication request, the cloud-side activation server 24 performs a parameter check based on the unique information and token of the wireless station 42 included in the authentication request to determine whether the authentication request is valid (sequence Sq49). If the cloud-side activation server 24 determines that the authentication request is valid, it stores activation information including the unique information and generation information of the wireless station 42 in the storage device 27 (sequence Sq50).

[0083] When the cloud-side activation server 24 has completed storing the activation information, it instructs the closed-side gateway server 13 and the cloud-side gateway server 22 to delete the generated information (sequences Sq51 and Sq52).

[0084] Upon receiving the instruction to delete the generated information, the closed-side gateway server 13 deletes the generated information stored therein in order to perform the encryption or decryption process without delay (sequence Sq53). Upon receiving the instruction to delete the generated information, the cloud-side gateway server 22 deletes the generated information stored therein in order to perform the encryption or decryption process without delay (sequence Sq54). As a result, the generated information temporarily stored in the closed-side gateway server 13 and the cloud-side gateway server 22 is cleared.

[0085] Thereafter, cloud-side activation server 24 transmits an authentication response (sequence Sq55). Specifically, cloud-side activation server 24 sets the IP address of its own device as the source IP address and sets the source IP address of the authentication request, i.e., the IP address of wireless station 42, as the destination IP address, and generates and transmits the authentication response.

[0086] Upon receiving the authentication response, the endpoint device 25 transfers the authentication response to the destination wireless station 42 (sequence Sq56).

[0087] If, for example, storage device 27 cannot be accessed and the storage of activation information does not end normally, cloud-side activation server 24 does not send the authentication response of sequence Sq55, but instead sends an error notification, for example, a notification that activation has been canceled, to endpoint device 25. Upon receiving the error notification, endpoint device 25 forwards the error notification to the destination wireless station 42.

[0088] 8 shows details of the provisioning process performed by the wireless station 42. The wireless station 42 transmits a name resolution request including the domain name of the endpoint device 25 that is the destination of the provisioning request to the Internet DNS server (sequence Sq61).

[0089] When the Internet DNS server receives the name resolution request including the domain name of the endpoint device 25, it transmits a name resolution response including the address of the endpoint device 25 to the wireless station 42 (sequence Sq62).

[0090] Upon receiving the name resolution response, the wireless station 42 transmits a provisioning request addressed to the cloud-side provisioning server 23, including the unique information of the wireless station 42, to the endpoint device 25 (sequence Sq63). In particular, the wireless station 42 sets its own IP address as the source IP address and the address of the endpoint device 25 included in the name resolution response as the destination IP address, and generates and transmits the provisioning request including the unique information of the wireless station 42. It is preferable that the wireless station 42 encrypts the unique information of the provisioning request with an encryption key generated based on the generation information, encrypts the provisioning request with a public key, and transmits the encrypted provisioning request to the endpoint device 25. At this time, it is assumed that the wireless station 42 and the cloud-side provisioning server 23 hold information about a common public key.

[0091] Upon receiving the provisioning request, the endpoint device 25 transfers the provisioning request to the cloud-side provisioning server 23 (sequence Sq64). The provisioning request transmitted from the wireless station 42 reaches the cloud-side provisioning server 23 via the WLAN device 32, the Internet network 20, and the endpoint device 25.

[0092] Upon receiving the provisioning request, the cloud-side provisioning server 23 extracts the unique information of the wireless station 42 included in the provisioning request and transmits an activation information request to the storage device 27 to acquire activation information of the wireless station 42 (sequence Sq65). Upon receiving the activation information request, the storage device 27 transmits the activation information of the wireless station 42 to the cloud-side provisioning server 23 (sequence Sq66).

[0093] The cloud-side provisioning server 23 checks whether activation of the wireless station 42 has been performed normally based on the activation information acquired in sequence Sq66 (sequence Sq67). Specifically, the cloud-side provisioning server 23 generates an encryption key from the generation information included in the activation information and decrypts the provisioning request with the generated encryption key. If the provisioning request can be successfully decrypted, the activation information stored in the storage device 27 is correct, and therefore activation can be considered to have been performed normally.

[0094] If the activation is successful, the cloud-side provisioning server 23 transmits a provisioning response addressed to the wireless station 42, including connection information for connecting to the call control server 12 corresponding to the wireless station 42, to the endpoint device 25 (sequence Sq68). In detail, the cloud-side provisioning server 23 sets the IP address of its own device as the source IP address and sets the source IP address of the provisioning request, i.e., the IP address of the wireless station 42, as the destination IP address, and generates and transmits the provisioning response including the connection information.

[0095] Upon receiving the provisioning response, the endpoint device 25 transfers the provisioning response to the destination wireless station 42 (sequence Sq69). The endpoint device 25 preferably encrypts the provisioning response using a public key and transmits the encrypted provisioning response to the wireless station 42. The provisioning response transmitted from the cloud-side provisioning server 23 reaches the wireless station 42 via the endpoint device 25, the Internet network 20, and the WLAN device 32. The wireless station 42 decrypts the received provisioning response.

[0096] For example, if the cloud-side provisioning server 23 cannot access the storage device 27 and cannot acquire the activation information, the cloud-side provisioning server 23 does not transmit the provisioning response of sequence Sq68, but transmits an error notification to the endpoint device 25. Upon receiving the error notification, the endpoint device 25 forwards the error notification to the wireless station 42.

[0097] 9 shows details of the registration process performed by wireless station 42. Wireless station 42 sends a name resolution request including the domain name of endpoint device 25, which is the destination of the registration request, to the Internet DNS server (sequence Sq71). Upon receiving the name resolution request including the domain name of endpoint device 25, the Internet DNS server sends a name resolution response including the address of endpoint device 25 to wireless station 42 (sequence Sq72).

[0098] Upon receiving the name resolution response, wireless station 42 transmits a registration request to endpoint device 25 (sequence Sq73). Specifically, wireless station 42 sets its own IP address as the source IP address and the address of endpoint device 25 included in the name resolution response as the destination IP address, and generates and transmits a registration request including the unique information of wireless station 42 and encryption key generation information. Wireless station 42 encrypts the registration request with an encryption key that can be generated based on the generation information included in the registration request, and transmits the encrypted registration request.

[0099] Upon receiving the registration request, endpoint device 25 forwards the registration request to cloud-side gateway server 22 (sequence Sq74). The registration request transmitted from wireless station 42 reaches cloud-side gateway server 22 via WLAN device 32, Internet network 20, and endpoint device 25.

[0100] Upon receiving the registration request, the cloud-side gateway server 22 extracts the unique information of the wireless station 42 included in the registration request and transmits an activation information request to the storage device 27 to acquire activation information of the wireless station 42 (sequence Sq75). Upon receiving the activation information request, the storage device 27 transmits the activation information of the wireless station 42 to the cloud-side gateway server 22 (sequence Sq76).

[0101] The cloud-side gateway server 22 stores the activation information acquired in sequence Sq76, specifically, the association between the unique information and the generation information of the wireless station 42. The cloud-side gateway server 22 generates an encryption key from the generation information included in the activation information acquired in sequence Sq76, and decrypts the registration request with the generated encryption key (sequence Sq77).

[0102] The cloud-side gateway server 22 generates a registration request addressed to the call control server 12 corresponding to the wireless station 42 from the decrypted registration request, and transmits the registration request to the dedicated connection device 26 (sequence Sq78). The cloud-side gateway server 22 associates the sender address of the registration request with the unique information of the wireless station 42 included in the registration request and stores the association information.

[0103] Upon receiving the registration request, the dedicated connection device 26 transfers the registration request to the call control server 12 (sequence Sq79). The registration request sent from the cloud-side gateway server 22 reaches the call control server 12 via the dedicated connection device 26 and the router 16.

[0104] Upon receiving the registration request, the call control server 12 transmits a registration response, including the unique information of the wireless station 42, addressed to the cloud-side gateway server 22 that is the sender of the registration request, to the dedicated connection device 26 (sequence Sq80).

[0105] Upon receiving the registration response, the dedicated connection device 26 transfers the registration response to the cloud-side gateway server 22 (sequence Sq81). The registration response sent from the call control server 12 reaches the cloud-side gateway server 22 via the router 16 and the dedicated connection device 26.

[0106] Upon receiving the registration response, the cloud-side gateway server 22 encrypts the registration response with the encryption key used for decryption in sequence Sq77 (sequence Sq82). The cloud-side gateway server 22 generates a registration response addressed to the wireless station 42 from the encrypted registration response and transmits the registration response to the endpoint device 25 (sequence Sq83). In detail, the cloud-side gateway server 22 sets the IP address of its own device as the source IP address and sets the IP address associated with the unique information of the wireless station 42 included in the registration response received from the call control server 12 as the destination IP address, and then generates and transmits the registration response.

[0107] Upon receiving the registration response, endpoint device 25 transfers the registration response to the destination wireless station 42 (sequence Sq84). The registration response sent from cloud-side gateway server 22 reaches wireless station 42 via endpoint device 25, Internet network 20, and WLAN device 32. Wireless station 42 decrypts the registration response using an encryption key that can be generated based on the generation information included in the authentication request.

[0108] When the startup processing of the wireless stations 41 and 42 is completed as described above, voice communication between the wireless stations 41 and 42 becomes possible. As an example, FIG. 10 shows an example in which the wireless station 41 requests a call with the wireless station 42. The wireless station 41 sends a call request specifying the wireless station 42 as the call destination, specifically, a call request including the ID of the wireless station 42 as the callee ID, to the closed-side gateway server 13 (sequence Sq91). Upon receiving the call request, the closed-side gateway server 13 extracts the unique information of the wireless station 41 included in the call request and decrypts the call request using the encryption key associated with the unique information of the wireless station 41 (sequence Sq92). The closed-side gateway server 13 transmits the decrypted call request to the call control server 12 (sequence Sq93).

[0109] The call control server 12 holds a correspondence between the call destination ID and the closed-side gateway server 13 or the cloud-side gateway server 22. Because the called wireless station 42 is connected to the Internet network 20, the wireless station 42 is associated with the cloud-side gateway server 22. Therefore, when the call control server 12 receives the above-mentioned call request, it transmits the call request addressed to the cloud-side gateway server 22 corresponding to the called wireless station 42 to the dedicated connection device 26 (sequence Sq94). The call request reaches the dedicated connection device 26 from the call control server 12 via the router 16. When the dedicated connection device 26 receives the call request, it transfers the call request to the cloud-side gateway server 22, which is the destination (sequence Sq95).

[0110] Upon receiving the call request, cloud-side gateway server 22 encrypts the call request addressed to wireless station 42 using an encryption key associated with the unique information of wireless station 42, the destination of the call (sequence Sq96). Cloud-side gateway server 22 transmits the encrypted call request to endpoint device 25 (sequence Sq97). Upon receiving the call request, endpoint device 25 transfers the call request to the destination wireless station 42 (sequence Sq98).

[0111] Upon receiving the call request, the wireless station 42 decrypts the received call request using an encryption key that can be generated based on the generation information included in the authentication request. The wireless station 42 generates a call response addressed to the wireless station 41 that sent the call request and transmits the call response to the endpoint device 25 (sequence Sq99). Upon receiving the call response, the endpoint device 25 transfers the call response to the cloud-side gateway server 22 (sequence Sq100). Upon receiving the call response, the cloud-side gateway server 22 decrypts the call response using an encryption key associated with the unique information of the wireless station 42 that sent the call request (sequence Sq101). The cloud-side gateway server 22 transmits the decrypted call response addressed to the wireless station 41 to the dedicated connection device 26 (sequence Sq102). Upon receiving the call response, the dedicated connection device 26 transfers the call response to the call control server 12 that is the destination (sequence Sq103).

[0112] When the call control server 12 receives the call response, it transmits the call response to the closed-side gateway server 13 associated with the destination wireless station 41 (sequence Sq104). When the closed-side gateway server 13 receives the call response, it encrypts the call response using an encryption key associated with the unique information of the destination wireless station 41 (sequence Sq105). The closed-side gateway server 13 transmits the encrypted call response to the destination wireless station 41 (sequence Sq106). The wireless station 41 decrypts the received call response using an encryption key that can be generated based on the generation information included in the authentication request. Establishing a call session as described above enables voice communication between the wireless stations 41 and 42. Voice data transfer is also performed in the same manner as in FIG. 10.

[0113] When the connection destination of the wireless stations 41, 42 is switched, the wireless stations 41, 42 perform the switching process of Fig. 11. For example, when the wireless station 41 performs the startup process shown in Fig. 3 and switches from a state in which it is connected to the private network 10 to a connection to the Internet network 20, the wireless station 41 performs the switching process of Fig. 11. The switching process of Fig. 11 is part of the startup process of Fig. 3, specifically, the process after the registration process. The processes of steps S17 to S20 are the same as the process of Fig. 3. Similarly, when the wireless station 42 performs the startup process shown in Fig. 3 and switches from a state in which it is connected to the Internet network 20 to a connection to the private network 10, the wireless station 42 performs the switching process of Fig. 11.

[0114] As described above, the wireless communication system 1 according to the first embodiment includes the closed-side activation server 15 and the cloud-side activation server 24, which, upon receiving an authentication request from the wireless stations 41 and 42, store activation information including the unique information of the wireless stations 41 and 42 and encryption key generation information in the storage device 27. Whether the wireless stations 41 and 42 are connected to the closed network 10 or the Internet 20, communication between the wireless stations 41 and 42 and the closed system 11 or the cloud system 21 is protected by an encryption key generated based on the generation information included in the activation information. As an example, data encrypted with the encryption key is transmitted and received, thereby encrypting and protecting communication between the wireless stations 41 and 42 and the closed system 11 or the cloud system 21. As a result, a wireless communication system and a communication method capable of securely relaying communication between the wireless stations 41 and 42 are obtained.

[0115] Furthermore, whether the wireless station 41 is connected to the closed network 10 or the Internet 20, the same encryption key associated with the unique information of the wireless station 41 is used to protect communications. Therefore, even if the wireless station 41 changes from being connected to the closed network 10 to being connected to the Internet 20, it is not necessary to perform the activation process and provisioning process again, and it is possible to smoothly switch the destination network. The same applies to the wireless station 42. This makes it possible to switch the destination network without interrupting the voice communications of the wireless stations 41 and 42.

[0116] When the wireless station 41 is connected to the Internet network 20, it operates in the same manner as the wireless station 42 described above. When the wireless station 42 is connected to the private network 10, it operates in the same manner as the wireless station 41 described above. As a result, the wireless stations 41 and 42 can connect to the call control server 12 and can perform voice communications with other wireless stations, regardless of whether they are connected to the private network 10 or the Internet network 20. In other words, the call control server 12 controls the voice communications of the associated wireless stations 41 and 42, regardless of whether they are connected to the private network 10 or the Internet network 20.

[0117] The wireless communication system 1 according to the first embodiment can be modified in various ways in addition to those described above. First, the closed system 11 may have any number of closed-side devices. Furthermore, the processing of each closed-side device may be distributed. As an example, the closed system 11 may have multiple closed-side gateway servers 13, and the processing performed by the closed-side gateway server 13 during registration may be load-distributed among the multiple closed-side gateway servers 13. The cloud system 21 may have any number of cloud-side devices. Furthermore, the processing of the cloud-side devices may be load-distributed. As an example, the cloud system 21 may have multiple cloud-side gateway servers 22, and the processing performed by the cloud-side gateway server 22 during registration may be load-distributed among the multiple cloud-side gateway servers 22.

[0118] Secondly, the closed-side activation server 15 may store the activation information in both the storage devices 27 and 17. Alternatively, the wireless communication system 1 may be provided with only the storage device 17.

[0119] Thirdly, the wireless stations 41 and 42 communicating via the wireless communication system 1 may perform the startup process shown in FIG. 3 not only at startup but also, for example, when no call has been made for a certain period of time.

[0120] (Embodiment 2) 12, the wireless communication system 2 according to the second embodiment includes a closed system 11a provided in a closed network 10a, a closed system 11b provided in a closed network 10b, and a cloud system 21.

[0121] The configuration of the closed systems 11a and 11b is the same as that of the closed system 11 included in the wireless communication system 1 according to embodiment 1. In detail, the closed system 11a includes a call control server 12a, a closed-side gateway server 13a, a closed-side DNS server 14a, a closed-side activation server 15a, a router 16a, and a storage device 17a. The closed system 11b includes a call control server 12b, a closed-side gateway server 13b, a closed-side DNS server 14b, a closed-side activation server 15b, a router 16b, and a storage device 17b.

[0122] The configuration of the cloud system 21 differs from that of the cloud system 21 provided in the wireless communication system 1 according to the first embodiment, and includes dedicated connection devices 26a and 26b corresponding to the closed systems 11a and 11b, respectively. In detail, the dedicated connection device 26a connects each of the cloud side devices included in the cloud system 21 to the closed side devices included in the closed system 11a and the closed network 10a via dedicated lines. The dedicated connection device 26b connects each of the cloud side devices included in the cloud system 21 to the closed side devices included in the closed system 11b and the closed network 10b via dedicated lines.

[0123] The wireless stations 41a, 41b, and 42 can perform voice communication with each other via the wireless communication system 2. The startup processing performed by the wireless stations 41a, 41b, and 42 is the same as that in the first embodiment. The wireless stations 41a and 41b are associated with the closed systems 11a and 11b, respectively. When the wireless station 41a cannot connect to the call control server 12a included in the closed system 11a, it connects to the call control server 12b included in the closed system 11b via the cloud system 21. Similarly, when the wireless station 41b cannot connect to the call control server 12b included in the closed system 11b, it connects to the call control server 12a included in the closed system 11a via the cloud system 21. The wireless station 42 preferentially connects to either the call control server 12a in the closed system 11a or the call control server 12b in the closed system 11b, and when it cannot connect to either the call control server 12a or the call control server 12b, it connects to the other of the call control servers 12a and 12b.

[0124] In detail, the wireless station 41a performs the activation process shown in Fig. 4 with the closed-side activation server 15a, performs the provisioning process shown in Fig. 5 with the cloud-side provisioning server 23, and performs the registration process shown in Fig. 6 with the call control server 12a via the closed-side gateway server 13a. When performing each of the activation, provisioning, and registration processes, the wireless station 41a requests name resolution from the closed-side DNS server 14a.

[0125] When the wireless station 41a performs the registration process shown in Fig. 6 and fails to receive a registration response from the closed-side gateway server 13a within a certain period of time, the wireless station 41a displays an error on the screen. Thereafter, the wireless station 41a performs registration process with the call control server 12b, as shown in Fig. 13. The wireless station 41a transmits a name resolution request including the domain name of the closed-side gateway server 13b, which is the destination of the registration request, to the closed-side DNS server 14a (sequence Sq111).

[0126] When the closed-side DNS server 14a receives the name resolution request including the domain name of the closed-side gateway server 13b, it transmits a name resolution response including the address of the dedicated connection device 26a to the wireless station 41 (sequence Sq112).

[0127] Upon receiving the name resolution response, the wireless station 41a transmits a registration request to the dedicated connection device 26a (sequence Sq113). Specifically, the wireless station 41a sets its own IP address as the source IP address and the address of the closed-side gateway server 13b included in the name resolution response as the destination IP address, and generates and transmits a registration request including the wireless station 41a's unique information and encryption key generation information. The wireless station 41a encrypts the registration request with an encryption key that can be generated based on the generation information included in the registration request, and transmits the encrypted registration request.

[0128] Upon receiving the registration request, dedicated connection device 26a transfers the registration request to dedicated connection device 26b (sequence Sq114). Upon receiving the registration request, dedicated connection device 26b transfers the registration request to closed-side gateway server 13b (sequence Sq115).

[0129] Upon receiving the registration request, the closed-side gateway server 13b extracts the unique information of the wireless station 41a contained in the registration request and transmits an activation information request for acquiring activation information of the wireless station 41a to the storage device 27 (sequence Sq116). Upon receiving the activation information request, the storage device 27 transmits the activation information of the wireless station 41a to the closed-side gateway server 13b (sequence Sq117).

[0130] The closed-side gateway server 13b stores the activation information acquired in sequence Sq117, specifically, the association between the unique information and the generation information of the wireless station 41. The closed-side gateway server 13b generates an encryption key from the generation information included in the activation information acquired in sequence Sq117, and decrypts the registration request with the generated encryption key (sequence Sq118).

[0131] The closed-side gateway server 13b transmits the decrypted registration request to the call control server 12b corresponding to the wireless station 41a (sequence Sq119). The closed-side gateway server 13b stores the source address of the registration request and the unique information of the wireless station 41a included in the registration request in association with each other.

[0132] Upon receiving the registration request, the call control server 12b transmits a registration response including the unique information of the wireless station 41a to the closed-area gateway server 13b that is the sender of the registration request (sequence Sq120).

[0133] Upon receiving the registration response, the closed-side gateway server 13b encrypts the registration response with the encryption key used for decryption in sequence Sq118 (sequence Sq121). The closed-side gateway server 13b transmits the encrypted registration response to the dedicated connection device 26b (sequence Sq122). In detail, the closed-side gateway server 13b sets the IP address of its own device as the source IP address and sets the IP address associated with the unique information of the wireless station 41a included in the registration response received from the call control server 12b as the destination IP address, and generates and transmits the registration response.

[0134] Upon receiving the registration response, dedicated connection device 26b transfers the registration response to dedicated connection device 26a (sequence Sq123). Upon receiving the registration response, dedicated connection device 26a transfers the registration response to wireless station 41a (sequence Sq124). Wireless station 41a decrypts the registration response using an encryption key that can be generated based on the generation information included in the authentication request.

[0135] As described above, when the radio station 41a is unable to perform the registration process with the call control server 12a, the radio station 41a can connect to the call control server 12b and establish voice communication by performing the registration process with the call control server 12b.

[0136] The same is true for the wireless station 41b. In detail, the wireless station 41b performs the activation process shown in Fig. 4 with the closed-side activation server 15b, performs the provisioning process shown in Fig. 5 with the cloud-side provisioning server 23, and performs the registration process shown in Fig. 6 with the call control server 12b via the closed-side gateway server 13b. When performing each of the activation, provisioning, and registration processes, the wireless station 41b requests name resolution from the closed-side DNS server 14b.

[0137] When the wireless station 41b performs the registration process shown in Fig. 6 and fails to receive a registration response from the closed-side gateway server 13b within a certain period of time, the wireless station 41b displays an error on its screen. Thereafter, the wireless station 41b performs registration process with the call control server 12a, as shown in Fig. 13. As a result, the wireless station 41b is able to connect to the call control server 12a and establish voice communication.

[0138] Furthermore, as in the first embodiment, when the radio station 42 performs the registration process shown in Fig. 9 with the call control server 12a, if it does not receive a registration response from the closed-side gateway server 13a within a certain period of time, it displays an error on the screen. Thereafter, the radio station 42 performs the registration process shown in Fig. 9 with the call control server 12b. By performing the registration process, the radio station 42 can connect to the call control server 12b and establish voice communication.

[0139] As described above, according to the wireless communication system 2 according to the second embodiment, when connection to one of the call control servers 12a and 12b is unavailable, voice communication can be performed by connecting to the other call control server 12a and 12b. In other words, when one of the call control servers 12a and 12b is unable to control communication between the wireless stations 41a, 41b, and 42, the other of the call control servers 12a and 12b controls communication between the wireless stations 41a, 41b, and 42. Therefore, the availability of the wireless communication system 2 is higher than that of the wireless communication system 1 according to the first embodiment.

[0140] Activation information including the unique information of the wireless stations 41a, 41b, and 42 and encryption key generation information is stored in the storage device 27 and can be read out from either the closed-side gateway servers 13a and 13b or the cloud-side gateway server 22. Therefore, regardless of whether the wireless stations 41a, 41b, and 42 are connected to the closed network 10a, 10b or the Internet network 20, communication between the wireless stations 41a, 41b, and 42 and the closed system 11 or the cloud system 21 is protected by an encryption key generated based on the generation information included in the activation information.

[0141] Furthermore, whether the wireless station 41a is connected to the private network 10a, 10b, or the Internet 20, the same encryption key associated with the unique information of the wireless station 41a is used to protect communications. Therefore, even if the wireless station 41a changes from being connected to the private network 10a to being connected to the private network 10b or the Internet 20, there is no need to perform the activation process and provisioning process again, and networks can be switched smoothly. The same applies to the wireless stations 41b and 42. This makes it possible to switch the network to which the wireless station 41a is connected without interrupting voice communications between the wireless stations 41a, 41b, and 42.

[0142] The wireless communication system 2 according to the second embodiment can be modified in various ways other than those described above. The number of closed systems is not limited to the above example, and may be any natural number equal to or greater than two.

[0143] The modifications described in the first embodiment can also be applied to the second embodiment. First, the number of closed side devices included in each of the closed systems 11a and 11b is arbitrary. The number of cloud side devices included in the cloud system 21 is arbitrary.

[0144] Second, the closed-side activation server 15 may store the activation information in each of the storage devices 27, 17a, and 17b. Alternatively, the wireless communication system 1 may be provided with only the storage device 17.

[0145] Thirdly, the wireless stations 41a, 41b, and 42 communicating via the wireless communication system 1 may perform the startup processing shown in FIG. 3 not only at startup but also, for example, when no calls have been made for a certain period of time.

[0146] An example of a hardware configuration for realizing the above-described wireless communication systems 1 and 2 is shown in Fig. 14. The closed side devices included in the closed systems 11, 11a, and 11b and the cloud side devices included in the cloud system 21 are realized by a processor 61, a memory 62, and an interface 63. The processor 61, the memory 62, and the interface 63 are connected to one another by a bus 60. The processor 61 includes any electronic circuit including a transistor, and is considered to be a circuit or a processor circuit.

[0147] For example, each function of the closed side devices of the closed systems 11, 11a, and 11b and the cloud side devices of the cloud system 21 is realized by software, firmware which is software built into electronic devices, or a combination of software and firmware. The software is written as a program and stored in the memory 62. The processor 61 executes the program stored in the memory 62 to realize the function of each of the above-mentioned parts. That is, the memory 62 stores programs for executing the processing of the closed side devices of the closed systems 11, 11a, and 11b and the cloud side devices of the cloud system 21.

[0148] The memory 62 includes, for example, non-volatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read-Only Memory), flash memory, EPROM (Erasable Programmable Read Only Memory), EEPROM (Electrically Erasable and Programmable Read-Only Memory), magnetic disk, flexible disk, optical disk, compact disk, mini disk, DVD (Digital Versatile Disc), etc.

[0149] For example, the interface 63 connects the closed systems 11, 11a, and 11b to the cloud system 21 or the wireless stations 41, 41a, and 41b, and connects the cloud system 21 to the wireless station 42, thereby establishing voice communication. The interface 63 has multiple types of interface modules as necessary.

[0150] 14 shows one processor 61 and one memory 62, the closed side devices of the closed systems 11, 11a, and 11b and the cloud side devices of the cloud system 21 may be realized by a plurality of processors 61 and a plurality of memories 62. In this case, the plurality of processors 61 and the plurality of memories 62 may work together to execute the functions of the devices of the closed systems 11, 11a, and 11b and the cloud system 21.

[0151] Each device of the closed systems 11, 11a, and 11b and the cloud system 21 may be realized by a processing circuit 71, as shown in Fig. 15. The processing circuit 71 is connected to other devices via an interface circuit 72.

[0152] When the processing circuit 71 is dedicated hardware, the processing circuit 71 includes, for example, a single circuit, a composite circuit, a processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The closed-side devices of the closed systems 11, 11a, and 11b and the cloud-side devices of the cloud system 21 may be realized by any number of processing circuits 71.

[0153] Some of the functions of the closed-side devices of the closed systems 11, 11a, and 11b and the cloud-side devices of the cloud system 21 may be realized by dedicated hardware, and other functions may be realized by software or firmware. For example, in the closed system 11, the call control server 12, the closed-side gateway server 13, the closed-side DNS server 14, and the closed-side activation server 15 may be realized by the processor 61 shown in Fig. 14 reading and executing programs stored in the memory 62, and the router 16 and the storage device 17 may be realized by the processing circuit 71 shown in Fig. 15.

[0154] Furthermore, the above-described hardware configuration and flowchart are merely examples and can be changed and modified as desired. [Explanation of symbols]

[0155] 1,2 Wireless communication systems 10,10a,10b closed network 11, 11a, 11b Closed System 12, 12a, 12b Call control server 13, 13a, 13b Closed gateway server 14, 14a, 14b Closed DNS server 15, 15a, 15b Closed-area activation server 16, 16a, 16b routers 17,17a,17b,27 Storage device 20 Internet Network 21 Cloud System 22 Cloud-side gateway server 23 Cloud-side provisioning server 24 Cloud-side activation server 25 Endpoint Devices 26, 26a, 26b dedicated connection devices 31 Base station 32 WLAN equipment 41,41a,41b,42 Radio station 51 LTE communication circuit 52 WLAN communication circuit 53 Communication control circuit 54 Data Processing Circuit 55 Input circuit 56 Output circuit 60 Bus 61 processors 62 memory 63 Interface 71 Processing circuit 72 Interface Circuit

Claims

1. A wireless communication system comprising: a closed system provided in a closed network; and a cloud system provided in an internet network, the closed system and the cloud system being connected to each other so as to be able to communicate with each other; The closed system comprises: a call control server that controls communications between a plurality of wireless stations, each of which is connected to either the closed network or the Internet; a closed-side activation server that, upon receiving an authentication request from a wireless station connected to the closed network, includes unique information for uniquely identifying the wireless station and encryption key generation information, stores activation information including the unique information and the encryption key generation information in a storage device provided in at least one of the closed system and the cloud system; The cloud system includes: a cloud-side activation server that, upon receiving an authentication request including the unique information and the generation information from the wireless station connected to the Internet network, stores activation information including the unique information and the generation information in the storage devices provided in the closed system and the cloud system, respectively; Regardless of whether the wireless station is connected to the closed network or the Internet network, communication between the wireless station, whose activation information is stored in the storage device, and the closed system or the cloud system is protected by an encryption key generated based on the generation information included in the activation information. Wireless communication system.

2. the closed system further comprises a closed-side gateway server that holds correspondence between the radio stations and the call control servers, and that, upon receiving an encrypted registration request or voice data from a radio station connected to the closed network, decrypts the registration request or the voice data using the encryption key generated based on the generation information included in the activation information of the radio station stored in the storage device, and transmits the decrypted registration request or the voice data to the call control server associated with the radio station, and, upon receiving a registration response or voice data from the call control server, encrypts the registration response or the voice data using the encryption key, and transmits the encrypted registration response or the voice data to the radio station.

10. The wireless communication system of claim 1.

3. the cloud system further comprises a cloud-side gateway server that holds correspondence between the wireless stations and the call control servers, that upon receiving an encrypted registration request or voice data from the wireless station connected to the Internet network, decrypts the registration request or the voice data using the encryption key generated based on the generation information included in the activation information of the wireless station stored in the storage device, and transmits the decrypted registration request to the call control server associated with the wireless station, and that upon receiving a registration response or voice data addressed to the wireless station connected to the Internet network from the call control server, encrypts the registration response or the voice data using the encryption key, and transmits the encrypted registration response or the voice data to the wireless station.

3. The wireless communication system according to claim 2.

4. When the closed-side gateway server and the cloud-side gateway server receive the registration request or the voice data, if the generation information included in the activation information corresponding to the wireless station that is the sender is not stored in the closed-side gateway server and the cloud-side gateway server, the closed-side gateway server and the cloud-side gateway server each acquire the generation information included in the activation information of the wireless station from the storage device and store the acquired generation information in the closed-side gateway server and the cloud-side gateway server, the closed-side activation server instructs each of the closed-side gateway server and the cloud-side gateway server to delete the stored generation information every time the activation information is stored in the storage device; the cloud-side activation server instructs each of the closed-side gateway server and the cloud-side gateway server to delete the stored generation information every time the activation information is stored in the storage device; 4. The wireless communication system according to claim 3.

5. the cloud system further comprises a cloud-side provisioning server that, when receiving an encrypted provisioning request from the wireless station connected to the closed network, decrypts the provisioning request with the encryption key generated based on the generation information included in the activation information of the wireless station stored in the storage device, encrypts a provisioning response including connection information for connecting to the closed-network gateway server with the encryption key, and transmits the encrypted provisioning response to the wireless station; and, when receiving an encrypted provisioning request from the wireless station connected to the Internet network, decrypts the provisioning request with the encryption key generated based on the generation information included in the activation information of the wireless station stored in the storage device, encrypts a provisioning response including connection information for connecting to the cloud-side gateway server with the encryption key, and transmits the encrypted provisioning response to the wireless station.

5. The wireless communication system according to claim 3 or 4.

6. A wireless communication system comprising a closed system provided in a closed network and a cloud system provided in an Internet network, the closed system and the cloud system being connected to each other so as to be able to communicate with each other, the closed system having a call control server that controls communication between a plurality of wireless stations, each of which is connected to either the closed network or the Internet network, and a closed-side activation server that receives, from the wireless stations connected to the closed network, an authentication request including unique information that uniquely identifies the wireless station and information for generating an encryption key, the cloud system having a cloud-side activation server that receives, from the wireless stations connected to the Internet network, an authentication request including the unique information and the generation information, the method comprising: The closed-side activation server performs a closed-side activation step of storing activation information including the unique information and the generation information in a storage device provided in at least one of the closed system and the cloud system when the authentication request is received from the wireless station connected to the closed network; The cloud-side activation server performs a cloud-side activation step of storing activation information including the unique information and the generation information in the storage device when the authentication request is received from the wireless station connected to the Internet network, Regardless of whether the wireless station is connected to the closed network or the Internet network, communication between the wireless station, whose activation information is stored in the storage device, and the closed system or the cloud system is protected by an encryption key generated based on the generation information included in the activation information. Communication method.

Citation Information

Patent Citations

  • Relay device, communication packet relay method, and sound communication system

    WO2017006833A1

Cited By

  • Thermoplastic resin composition, molded article and product

    DE112020003292B4