Wireless devices, authentication servers, and programs
By integrating a SIM in wireless devices to manage line information and generate access tokens, the system addresses the challenge of determining service rights post-authentication, enhancing security and efficiency in mobile communication networks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- KDDI CORP
- Filing Date
- 2024-11-19
- Publication Date
- 2026-05-29
AI Technical Summary
Existing systems struggle to efficiently determine service usage rights of wireless devices (WDs) in mobile communication networks based on successful authentication by an authentication server, as SIMs, being tamper-resistant devices, are used as authenticators, complicating the process.
A wireless device equipped with a SIM that stores a secret key and profile information, performs communication processing, and transmits line information to an authentication server to obtain an access token, enabling the authentication server to verify successful authentication and determine service usage rights.
The authentication server can easily determine the service usage rights of the WD based on successful authentication, ensuring secure and efficient access to services while reducing the risk of information leakage.
Smart Images

Figure 2026088694000001_ABST
Abstract
Description
Technical Field
[0004] , , , , , ,
[0001] The present disclosure relates to an authentication technology for wireless devices in a mobile communication network.
Background Art
[0002] Non-Patent Document 1 discloses an authentication method also called FIDO (Fast Identity Online) authentication. According to Non-Patent Document 1, a secret key, also called a credential, is stored in an authenticator, and a public key corresponding to the secret key is stored in an authentication server. The authentication server transmits challenge data to the authenticator, and the authenticator generates a signature of the challenge data based on the stored secret key and transmits it to the authentication server. The authentication server verifies the signature with the stored public key to authenticate the authenticator, and thus authenticate the user using the authenticator. A so-called tamper-resistant device is used for the authenticator.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Wireless devices (WDs) that communicate via mobile communication networks are equipped with an integrated circuit called a subscriber identification module (SIM). The WD accesses the mobile communication network based on information stored in the SIM, which is also referred to as a profile. In the following description, the term SIM refers to a combination of removable SIM cards, embedded SIMs (eSIMs) that cannot be removed from the WD, and embedded general-purpose integrated circuit cards (eUICCs). The eUICC is an integrated circuit configured to allow remote rewriting of its profile. Because SIMs are tamper-resistant devices, they can be used as authenticators for authentication of WDs (or WD users) by an authentication server.
[0005] A working device (WD) can access application servers (ASs) on data networks (DNs) such as the Internet via a mobile communication network and utilize services provided by the AS. In the following, a service provider will be referred to as a "service provider" if they are a business that provides services using an AS. Examples of services provided by an AS include video streaming services, social networking services (SNS), and storage services.
[0006] A mobile communications network operator may, in addition to communications over the mobile communications network, provide subscribers with the right to use services provided by a designated service provider, based on a contract. For example, a mobile communications network operator may provide subscribers who have entered into a designated contract with the right to use a video streaming service provided by a designated service provider, in addition to a predetermined amount of data communications per month. The AS used by the designated service provider to provide the service is configured to determine what services it can provide to the accessing WD.
[0007] Therefore, it is preferable to enable the AS to easily determine the service usage rights of a WD based on whether the WD has been successfully authenticated by the authentication server. [Means for solving the problem]
[0008] According to one aspect of this disclosure, a wireless device for a mobile communication network includes an integrated circuit that stores a secret key, line information, and a profile for accessing the mobile communication network, and processing means for performing communication processing over the mobile communication network, wherein, during authentication by an authentication server, the device transmits the line information to the authentication server and obtains an access token associated with the line information. [Effects of the Invention]
[0009] According to this disclosure, the AS can easily determine the right to use the services that the WD possesses, depending on whether the authentication of the WD by the authentication server is successful. [Brief explanation of the drawing]
[0010] [Figure 1] An example system configuration diagram. [Figure 2] A sequence diagram of the process of registering a public key with the authentication server. [Figure 3] Sequence diagram of the authentication process for WD by the authentication server. [Figure 4] A sequence diagram showing the process when a Working Driver (WD) initiates the use of services provided by an AS (Assessment System). [Figure 5] Another sequence diagram of the process of registering a public key with the authentication server. [Figure 6] Another sequence diagram of the authentication process for WD by the authentication server. [Figure 7] A diagram showing an example of an authentication server configuration. [Modes for carrying out the invention]
[0011] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims, and not all combinations of features described in the embodiments are essential to the invention. Two or more features from the multiple features described in the embodiments may be arbitrarily combined. Furthermore, identical or similar configurations will be given the same reference numeral, and redundant descriptions will be omitted.
[0012] <First Embodiment> Figure 1 is a system configuration diagram used to describe the embodiment. WD1 includes a SIM 10 and a processing unit 11. WD1 may be a device that is intended for human operation, such as a smartphone or tablet, or a device that is not intended for human operation, such as a so-called IoT (Internet of Things) device.
[0013] SIM10 is a tamper-resistant integrated circuit that stores a profile file for accessing the mobile communication network 21. SIM10 also stores an identifier for SIM10 (SIM identifier) and a subscriber identifier. The SIM identifier is information for identifying individual SIM10s and may be, for example, an Integrated Circuit Card Identifier (ICCID) or an Embedded Identification Document (EID). The subscriber identifier is an identifier assigned by the operator of the mobile communication network 21 for each contract with a subscriber and may be, for example, an International Mobile Subscriber Identifier (IMSI). The subscriber identifier is also the identifier associated with the profile file for accessing the mobile communication network 21.
[0014] The processing unit 11 may include one or more processors, an integrated circuit that performs communication processing for accessing the mobile communication network 21, also known as a modem chip, a non-volatile memory device, and a volatile memory device. One or more processors execute an operating system (OS) and an application program (APP) stored in the non-volatile memory device.
[0015] The network 2 in FIG. 1 is a general term for the mobile communication network 21 and the DN 22 such as the Internet. The WD 1 can communicate with the authentication server 3 and the AS 5 connected to the DN 22 via the mobile communication network 21. The authentication server 3 and the AS 5 can also be referred to as devices within the DN 22. In FIG. 1, the authentication server 3 and the AS 5 are shown as devices within the DN 22, but one or both of the authentication server 3 and the AS 5 may be devices within the mobile communication network 21.
[0016] The mobile communication network 21 can be configured to determine the contract information of the WD 1 (or the user of the WD 1) based on, for example, the SIM identifier and / or the subscriber identifier. In the following description, the combination of the SIM identifier and the subscriber identifier is referred to as "line information". Note that a configuration using only the SIM identifier as the line information or a configuration using only the subscriber identifier as the line information may also be used.
[0017] The AS 5 is a device that provides a predetermined service. In the present embodiment, the AS 5 provides the service defined in the contract to the WD 1 of the user who has made a predetermined contract with the operator of the mobile communication network 21. The AS 5 is configured to use the line information to determine the usage right of the WD 1 when providing the service to the WD 1.
[0018] The authentication server 3 is a device that authenticates the WD 1 using the SIM 10 installed in the WD 1 as an authenticator. When the authentication of the WD 1 is successful, the authentication server 3 is configured to issue an access token to the WD 1. In order to enable authentication by the authentication server 3, the SIM 10 generates a secret key (credential) used for authentication by the authentication server 3 and a public key corresponding to the secret key. The public key generated by the SIM 10 is registered in the authentication server 3 in advance.
[0019] Figure 2 shows the sequence of the process of registering the public key in the authentication server 3. In S10, the processing unit 11 transmits a registration request to the authentication server 3. Note that the information for communicating with the authentication server 3 is stored in the processing unit 11 in advance. The registration request includes line information. In the present embodiment, the line information is a combination of a SIM identifier and a subscriber identifier. The authentication server 3 responds to the registration request and transmits challenge data to the processing unit 11 in S11. The challenge data can be random data.
[0020] In S12, the processing unit 11 outputs the challenge data to the SIM 10 and instructs the generation of a key. In S13, the SIM 10 generates a pair of a private key and a public key, and stores the private key in S14. The SIM 10 generates signature data of the challenge data based on the generated private key, and outputs the public key and the signature data to the processing unit 11 in S15. In S16, the processing unit 11 transmits the public key and the signature data to the authentication server 3. The authentication server 3 verifies the signature data with the public key. When the verification is successful, the authentication server 3 stores the public key in association with the line information received in S10 in S17, and notifies the processing unit 11 of the completion of registration in S18.
[0021] Figure 3 shows the sequence of the authentication process of the WD1 by the authentication server 3. In S20, the processing unit 11 transmits an authentication request to the authentication server 3. The authentication request includes line information. The authentication server 3 responds to the authentication request and transmits challenge data to the processing unit 11 in S21. The challenge data can be random data.
[0022] In S22, the processing unit 11 outputs challenge data to the SIM 10. The SIM 10 generates signature data for the challenge data based on the stored private key and outputs the signature data to the processing unit 11 in S23. In S24, the processing unit 11 sends the signature data to the authentication server 3. In S25, the authentication server 3 verifies the signature data using the public key associated with the line information received in S20. If the verification of the signature data is successful, the authentication server 3 determines that the authentication of WD1 is successful and sends an access token to the processing unit 11 in S26. In addition, in S27, the authentication server 3 stores the access token sent to the processing unit 11 in association with the line information received in S20. If the verification is unsuccessful, the processes in S26 and S27 are not performed, and instead, the authentication server 3 notifies the processing unit 11 that the authentication of WD1 was unsuccessful.
[0023] Figure 4 shows the sequence when WD accesses AS5 to receive services. Processing unit 11 sends a service request to AS5 in S30. The service request includes an access token. In response to the service request, AS5 sends an information request to authentication server 3 in S31. The information request includes an access token. In response to the information request, authentication server 3 sends the line information stored in association with the access token received along with the information request to AS5 in S32. In S33, AS5 performs a determination process to determine the service usage rights of WD1 based on the line information.
[0024] For example, AS5 has information in advance that shows the relationship between line information and service usage rights. In this case, AS5 can determine the usage rights that WD1 has based on the line information. AS5 can also obtain information necessary to determine the usage rights that WD1 has from a device, for example, by notifying a device within the mobile communication network 21 or a device operated by the operator of the mobile communication network 21 connected to DN22 of the line information. The information necessary to determine the usage rights that WD1 has may be information that indicates the usage rights that WD1 has, or it may be attribute information of WD1 or the user using WD1, such as the age of the user of WD1.
[0025] Furthermore, since the access token is used solely to identify the line information by the authentication server 3, the information indicated by the access token can be arbitrarily set by the authentication server 3.
[0026] As described above, upon successful authentication of WD1 by the authentication server 3, the authentication server 3 issues an access token and sends it to WD1, and stores the access token associated with WD1's line information. Therefore, when WD1 presents the access token to AS5, the authentication server 3 can provide AS5 with WD1's line information based on the access token. Thus, upon successful authentication of WD1 by the authentication server 3, AS5 can easily determine WD1's right to use the services.
[0027] <Second Embodiment> Next, the second embodiment will be described, focusing on the differences from the first embodiment. In the first embodiment, encrypted communication such as Hypertext Transfer Protocol Secure (HTTPS) may be used for communication between the processing unit 11 and the authentication server 3. Therefore, the line information transmitted to the authentication server 3 in S10 of Figure 2 and S20 of Figure 3 will be kept confidential even if eavesdropping occurs on the network 2. However, the line information transmitted to the authentication server 3 in S10 of Figure 2 and S20 of Figure 3 is information stored in the SIM 10. Therefore, in the sequences of Figures 2 and 3, the processing unit 11 needs to read the line information from the SIM 10.
[0028] In this case, if a malicious app is running in the processing unit 11, the line information may be misused. Therefore, in this embodiment, the SIM 10, rather than the processing unit 11, performs encrypted communication with the authentication server 3.
[0029] Figure 5 shows the sequence of operations for registering a public key with the authentication server 3 according to this embodiment. In S40, the processing unit 11 sends a registration instruction to the SIM 10. In response to the registration instruction from the processing unit 11, the SIM 10 communicates with the authentication server 3 in S41 and starts the communication key exchange process. The information for communicating with the authentication server 3 is stored in the SIM 10 in advance. Alternatively, the information for communicating with the authentication server 3 is notified by the processing unit 11 in S40.
[0030] The communication key exchange process could be, for example, a Transport Layer Security (TLS) handshake performed over HTTPS. Through the communication key exchange process, SIM10 and authentication server 3 generate a common encryption key (communication key) to be used for encrypting communication. After the communication key is generated, information sent and received between SIM10 and authentication server 3 is encrypted using the generated communication key. In S42, SIM10 sends a registration request including line information to authentication server 3. In response to the registration request, authentication server 3 sends challenge data to SIM10 in S43.
[0031] In S44, SIM10 generates a private key and a public key pair, and in S45 stores the private key. Based on the generated private key, SIM10 generates signature data for the challenge data, and in S46 sends the public key and signature data to the authentication server 3. The authentication server 3 verifies the signature data using the public key. If the verification is successful, in S47, the authentication server 3 stores the public key associated with the line information received in S42, and in S48 notifies SIM10 that registration is complete. In S49, SIM10 notifies the processing unit 11 that registration is complete.
[0032] In communication between SIM10 and authentication server 3, SIM10 performs processing at or above the Transmission Control Protocol (TCP) layer, while processing unit 11 performs processing at or below the Internet Protocol (IP) layer. In this case, TCP packets are sent and received between SIM10 and processing unit 11. Therefore, similar to network 2, processing unit 11 cannot decrypt the encrypted information sent and received between SIM10 and authentication server 3, thereby reducing the risk of leakage of line information.
[0033] Figure 6 shows the sequence of authentication processing according to this embodiment. In S50, the processing unit 11 sends an authentication instruction to the SIM 10. In response to the authentication instruction from the processing unit 11, the SIM 10 communicates with the authentication server 3 in S51 and starts the communication key exchange process. In S52, the SIM 10 sends an authentication request including line information to the authentication server 3. In response to the authentication request, the authentication server 3 sends challenge data to the SIM 10 in S53.
[0034] SIM10 generates signature data for the challenge data based on the stored private key and sends the signature data to the authentication server 3 in S54. In S55, the authentication server 3 verifies the signature data using the public key associated with the line information received in S52. If the verification of the signature data is successful, the authentication server 3 determines that the authentication of WD1 is successful and sends an access token to SIM10 in S56. In S57, SIM10 outputs the access token to the processing unit 11. In S58, the authentication server 3 stores the access token sent to SIM10 in association with the line information received in S52. The processing when the processing unit 11 uses the service provided by AS5 is the same as in the first embodiment.
[0035] The SIM10 has a processor and is configured to run simple applications such as applets. Therefore, it is possible to have the SIM10 perform processing that conforms to encrypted communication protocols such as HTTPS.
[0036] Furthermore, if WD1 is a device that is operated by a human, such as a smartphone, the trigger for the processing unit 11 to start the sequence in Figures 3 and 6 may be, for example, when the user of WD1 performs an operation to access AS5. In this case, the processing unit 11 starts the process in Figure 4 after obtaining an access token. The processing unit 11 may also start the sequence in Figures 3 and 6 as a trigger if it does not have a valid access token or if the access token has expired. In this case, the processing unit 11 may start the process in Figure 4 at a pre-programmed timing or at a timing when it becomes necessary to access AS5 due to a change in circumstances.
[0037] As described above, in this embodiment as well, AS5 can easily determine the service usage rights of WD1 based on the success of authentication of WD1 by the authentication server 3. Furthermore, in this embodiment, the risk of leakage of information stored in SIM10 can be reduced.
[0038] <Example configuration of authentication server 3> Figure 7 is a schematic diagram of the authentication server 3. The authentication server 3 includes, for example, one or more processors and one or more memory devices. The one or more memory devices may include volatile memory devices and non-volatile memory devices. Each functional block shown in Figure 7 can be realized by one or more processors executing computer programs stored in one or more memory devices.
[0039] Although the authentication server 3 in Figure 7 is a single device, the authentication server 3 may be implemented by multiple devices that can communicate with each other. Furthermore, Figure 7 shows only the functional blocks necessary for understanding this disclosure, and the authentication server 3 may have functional blocks other than those shown in Figure 7.
[0040] When the processing unit 31 obtains a public key from WD1 through the registration process described in Figures 2 and 5, it stores the public key in the storage unit 30, associating it with the circuit information of WD1. Furthermore, in response to receiving an authentication request containing circuit information from WD1, the processing unit 31 sends challenge data to WD1. Upon receiving signature data for the challenge data from WD1 in response to sending the challenge data, the processing unit 31 verifies the signature data based on the public key associated with the circuit information. If the verification of the signature data is successful, the processing unit 31 determines that authentication of WD1 is successful; if the verification of the signature data fails, it determines that authentication of WD1 is unsuccessful. Note that if the processing unit 31 cannot obtain the public key associated with the circuit information received with the authentication request from the storage unit 30, it may determine that authentication of WD1 is unsuccessful without sending challenge data to WD1.
[0041] If authentication of WD1 is successful, the token management unit 32 issues an access token and transmits it to WD1, and stores the access token issued to WD1 in the storage unit 30, associating it with the line information of WD1. Furthermore, if an access token is received from a device on the mobile communication network 21 or DN22, the token management unit 32 retrieves the line information associated with the access token received from the device from the storage unit 30 and transmits it to the device.
[0042] Furthermore, the Disclosure provides a program executable on one or more processors. The program, when executed on one or more processors of a device or apparatus, includes instructions that cause the device or apparatus to function, for example, as WD1 or authentication server 3. Furthermore, the Disclosure provides a non-temporary computer-readable storage medium containing the program. Furthermore, the Disclosure provides methods that WD1 or authentication server 3 execute for the processes illustrated in Figures 2 to 6. Furthermore, the Disclosure provides a program for causing a device having one or more processors to execute these methods, and a non-temporary computer-readable storage medium containing the program.
[0043] The invention is not limited to the embodiments described above, and various modifications and changes are possible within the scope of the gist of the invention.
[0044] With the above configuration, the AS can easily determine the right to use the services held by the WD based on whether the authentication server has successfully authenticated the WD. Therefore, it becomes possible to contribute to Goal 9 of the United Nations Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation." [Explanation of symbols]
[0045] 10: SIM, 11: Processing Unit
Claims
1. A wireless device for a mobile communication network, An integrated circuit that stores a private key, line information, and a profile for accessing the mobile communication network, Processing means for performing communication processing via the aforementioned mobile communication network, Equipped with, A wireless device that, during authentication by an authentication server, transmits the aforementioned line information to the authentication server and obtains an access token associated with the aforementioned line information.
2. The integrated circuit generates signature data for the challenge data received from the authentication server based on the secret key during authentication by the authentication server. The wireless device according to claim 1, wherein the signature data is transmitted to the authentication server.
3. The wireless device according to claim 1, wherein the processing means transmits the access token to the server when using a service provided by a server of the mobile communication network or a data network connected to the mobile communication network.
4. Before transmitting the aforementioned line information to the authentication server, the integrated circuit performs a key exchange process with the authentication server to generate a communication key for encrypting the communication. The wireless device according to claim 1, wherein the integrated circuit transmits the line information encrypted based on the communication key to the authentication server via the processing means.
5. In communication with the aforementioned authentication server, The wireless device according to claim 1, wherein the processing means performs processing at or below the Internet Protocol (IP) layer, and the integrated circuit performs processing at layers higher than the IP layer.
6. The wireless device according to claim 1, wherein the line information is an identifier of the integrated circuit, a subscriber identifier assigned to the profile by the operator of the mobile communication network, or a combination of the identifier of the integrated circuit and the subscriber identifier.
7. The identifier of the aforementioned integrated circuit is an integrated circuit card identifier (ICCID) or an embedded identification document (EID), The wireless device according to claim 6, wherein the subscriber identifier is an International Mobile Subscriber Identifier (IMSI).
8. A program that, when executed on one or more processors of a device having one or more processors, causes the device to function as a wireless device according to any one of claims 1 to 7.
9. Processing means for authenticating a wireless device in response to receiving an authentication request including line information from a wireless device of a mobile communication network, If the authentication of the wireless device is successful, a token management means transmits an access token to the wireless device and stores the access token in association with the line information, An authentication server equipped with this feature.
10. The authentication server according to claim 9, wherein the processing means transmits challenge data to the wireless device in response to receiving the authentication request, and when it receives signature data of the challenge data from the wireless device in response to transmitting the challenge data, it verifies the signature data based on the public key associated with the line information, and if the verification of the signature data is successful, it determines that the authentication of the wireless device has been successful.
11. The authentication server according to claim 9, wherein when the token management means receives the access token from a device of the mobile communication network or a data network connected to the mobile communication network, the token management means transmits the line information associated with the access token received from the device to the device.
12. The authentication server according to claim 9, wherein the line information is information stored in an integrated circuit implemented in the wireless device, which stores a profile for the wireless device to access the mobile communication network.
13. The authentication server according to claim 12, wherein the line information is an identifier of the integrated circuit, a subscriber identifier assigned to the profile by the operator of the mobile communication network, or a combination of the identifier of the integrated circuit and the subscriber identifier.
14. The identifier of the aforementioned integrated circuit is an integrated circuit card identifier (ICCID) or an embedded identification document (EID), The authentication server according to claim 13, wherein the subscriber identifier is an International Mobile Subscriber Identifier (IMSI).
15. A program that, when executed on one or more processors of a device having one or more processors, causes the device to function as an authentication server according to any one of claims 9 to 14.