Information processing device and system

The eUICC system allows electronic certificates to be rewritten, ensuring accurate owner identification and reducing communication costs by updating authentication information, addressing the challenge of identifying the current owner and providing tailored services.

JP2026091903APending Publication Date: 2026-06-04TOYOTA JIDOSHA KK

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2026-03-19
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing systems fail to accurately identify the current owner of an information processing device, such as a vehicle, due to electronic certificates proving ownership being stored in secure storage areas that cannot be overwritten, leading to service providers unable to provide tailored services after a change in ownership.

Method used

An eUICC is used to store electronic certificates that can be rewritten, allowing service providers to authenticate and identify the current owner by obtaining digital certificates from a certification authority, and updating authentication information and profiles as ownership changes.

Benefits of technology

Enables service providers to correctly identify the current owner of the information processing device, allowing for tailored services and avoiding communication costs for the new owner, while maintaining security and enabling communication from factory shipment to purchase.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026091903000001_ABST
    Figure 2026091903000001_ABST
Patent Text Reader

Abstract

The server providing the specified service makes it possible to identify the current owner of the information processing device. [Solution] The information processing device comprises an eUICC that holds first profile information used for connecting to a first communication system, and a control unit that performs connecting to the first communication system using the first profile information. The control unit performs the following: obtains a first digital certificate from a predetermined certification authority that proves that the first authentication information used for authentication by the first server belongs to the first owner; stores the first authentication information and the first digital certificate in the eUICC; and performs authentication by the first server using the first authentication information and the first digital certificate. A default profile is stored in the eUICC, and while the information processing device is sold new or used, the information processing device connects to the first communication system using the default profile.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0003]

[0001] The present disclosure relates to wireless communication in which a SIM is used in a terminal.

Background Art

[0002] An Operational Profile including settings for connecting to a first wireless communication network, a Bootstrap Profile for connecting to a second wireless communication network, and an applet are held in a UICC, and when the applet detects a loss of operational connectivity with the first wireless communication network while connecting the first wireless communication network using the Operational Profile, it connects to the second wireless communication network using the Bootstrap Profile and re - establishes wireless communication with the host device. (For example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] One aspect of the disclosure aims to provide an information processing apparatus, method, and system that enable a server providing a predetermined service to identify the current owner of the information processing apparatus.

Means for Solving the Problems

[0005] One aspect of the present disclosure is an eUICC (Embedded Universal Integrated Circuit Card) that is used for connection to a first communication system and holds first profile information associated with a first owner of an information processing apparatus, A control unit that performs the operation of connecting to the first communication system using the first profile information, Equipped with, The control unit, Obtaining a first digital certificate from a designated certification authority that proves that the first authentication information corresponding to the first profile information, used for authentication by a first server trusted by the first communication system, belongs to the first owner, The first authentication information and the first digital certificate are stored in the eUICC, Authentication by the first server using the first authentication information and the first digital certificate, To further execute, It is an information processing device.

[0006] Another aspect of this disclosure is, A computer equipped with an eUICC (Embedded Universal Integrated Circuit Card) used to connect to a first communication system and holding first profile information associated with the first owner of the information processing device, Connecting to the first communication system using the first profile information, The first authentication information corresponding to the first profile information, used for authentication by the first server trusted by the first communication system, belongs to the first owner. Obtaining a first digital certificate from a designated certification authority to prove that, The first authentication information and the first digital certificate are stored in the eUICC, Authentication by the first server using the first authentication information and the first digital certificate, This is a way to further implement it.

[0007] Another aspect of this disclosure is, eUICC, which can store multiple profile information used for connecting to a communication network, A control unit that enables one of the plurality of profile information and uses the enabled profile information to connect to the communication network, An information processing device comprising, The aforementioned eUICC, at the time of factory shipment of the information processing device, holds default profile information that is used to connect to the first communication system and is configured to charge communication fees to a predetermined carrier. The control unit, At the time of factory shipment of the information processing device, the default profile information is enabled, and the device connects to the first communication system using the default profile information. When first profile information corresponding to the first owner of the information processing device is stored in the eUICC, the default profile information is disabled, the first profile information is enabled, and the first communication system is connected using the first profile information. It is an information processing device. [Effects of the Invention]

[0008] According to one aspect of this disclosure, a server providing a predetermined service can identify the current owner of an information processing device. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 shows an example of service provision to a vehicle according to the first embodiment. [Figure 2] Figure 2 shows an example of the hardware configuration of the DCM. [Figure 3] Figure 3 shows an example of the DCM's functional configuration. [Figure 4] Figure 4 shows an example of the hardware configuration of an information processing device. [Figure 5] Figure 5 shows an example of the functional configuration of HSS. [Figure 6] Figure 6 shows an example of the information held in the subscriber information database. [Figure 7] FIG. 7 is a diagram showing an example of information held in the terminal connection information database. [Figure 8] FIG. 8 is a diagram showing an example of the functional configuration of the server. [Figure 9] FIG. 9 is an example of a flowchart of the download process of profile information executed by the DCM. [Figure 10] FIG. 10 is an example of a flowchart of the process of activating or deactivating a profile executed by the DCM. [Figure 11] FIG. 11 is an example of a flowchart of the process of acquiring an identity certificate executed by the DCM. [Figure 12] FIG. 12 is a diagram showing an example of a sequence of processes from when the DCM acquires an owner profile until connecting to the communication system. [Figure 13] FIG. 13 is a diagram showing an example of a sequence of processes from when the DCM acquires an identity certificate until accessing the server. [Figure 14] FIG. 14 is a diagram showing an example of the transition of profile information used in a vehicle.

BEST MODE FOR CARRYING OUT THE INVENTION

[0010] When purchasing a vehicle, in order to confirm the identity of the new owner of the vehicle, submission of a seal certificate or the like is required. Instead of a seal certificate, it is also possible to use an electronic certificate of the My Number card. Based on such identity documents, through examination by a predetermined certification authority (CA: Certificate Authority or Certification Authority), the vehicle and the owner are associated, and an electronic certificate indicating that the owner of the vehicle is genuine is issued. The electronic certificate is stored, for example, in an in-vehicle device mounted on a vehicle having a communication function such as a connected car, and is used for authentication by the electronic certificate when receiving services for the vehicle.

[0011] Electronic certificates proving vehicle ownership are often stored in the secure storage area of ​​the vehicle's onboard system, and in such cases, they cannot be overwritten. Vehicles can change ownership, for example, when they are sold secondhand. However, because the electronic certificate proving ownership stored in the secure storage area of ​​the onboard system cannot be overwritten, even if the vehicle's ownership changes, the electronic certificate remains that of the original owner. As a result, service providers for vehicles could not identify the current owner even if the vehicle's ownership had changed from the original owner, and therefore could not provide services tailored to the current owner.

[0012] In one aspect of this disclosure, in view of the above-mentioned problems, an electronic certificate proving the owner's identity is stored within the eUICC of the information processing device. This makes it possible to rewrite the electronic certificate of identity verification, and enables service providers who perform authentication using the electronic certificate to identify the current owner of the information processing device.

[0013] More specifically, one aspect of the present disclosure is an information processing device comprising: an eUICC used for connecting to a first communication system and holding first profile information associated with a first owner of the information processing device; and a control unit that performs connecting to the first communication system using the first profile information. The control unit obtains a first digital certificate from a predetermined certification authority that proves that the first authentication information corresponding to the first profile information belongs to the first owner and is used for authentication by a first server trusted by the first communication system. The control unit stores the first authentication information and the first digital certificate in the eUICC. The control unit uses the first authentication information and the first digital certificate to be authenticated by the first server.

[0014] Information processing devices include, for example, in-vehicle devices mounted in vehicles, smartphones, tablet terminals, wearable devices, IoT terminals, and terminals capable of wireless communication based on mobile communication systems. In-vehicle devices include, for example, DCMs (Data Communication Modules) and car navigation systems. These include control devices, drive recorders, and ECUs (Electronic Control Units). The control unit includes, for example, processors such as a CPU (Central Processing Unit), a DSP (Digital Signal Processor), and a data communication processor, as well as circuits such as an FPGA (Field-Programmable Gate Array).

[0015] The first communication system is a wireless communication system that requires the terminal to be equipped with an eUICC, such as 4G (LTE-Advanced), 5G, 6G and later mobile communication systems, and 3G. The eUICC may be in chip form or card form. The authentication information is, for example, key information such as a public key. The first server trusted by the first communication system may be a server within the first communication system or a server outside the first communication system. The first communication system may be a system managed by the manufacturer of the information processing device or the device in which the information processing device is installed, or it may be a communication system of a carrier that issues profile information held in the eUICC.

[0016] Since the first profile information corresponds to the first owner, the profile information also changes when the owner of the information processing device changes. Since the first authentication information corresponds to the first profile information, the authentication information also changes when the profile information changes. Since the first digital certificate is issued for the first authentication information, the digital certificate also changes when the authentication information changes. In other words, when the owner changes, the digital certificate also changes. In one aspect of this disclosure, by storing the owner's digital certificate for identity verification in a data-rewritable eUICC, the digital certificate can be rewritten, for example, in conjunction with a change in the owner of the information processing device. This allows a service provider that performs authentication using the digital certificate for identity verification to correctly identify the current owner of the information processing device.

[0017] In one aspect of this disclosure, the information processing device may further maintain an applet that generates first authentication information using first profile information as a key. The control unit may activate the applet to generate the first authentication information. This requires that the digital certificate for identity verification be updated in conjunction with changes in profile information. In addition to changes in the owner of the information processing device, the first authentication information can also be updated when profile information is updated, for example, due to a vulnerability issue, thereby maintaining security.

[0018] Furthermore, the control unit may obtain the first profile information and applet from a second server that manages the profile information, and store the first profile information and applet in eUICC. The second server is, for example, an SM-DP+ (Subscription Manager Data Preparation +) server if the first communication system is an LTE (Long Term Evolution) compatible system. This makes it possible to rewrite the applet remotely, just like the profile information.

[0019] Furthermore, if the applet is updated, the control unit may obtain at least the updated applet from the second server and store it in the eUICC. The control unit may then launch the updated applet to generate new first authentication information, obtain a digital certificate from a predetermined Certificate Authority (CA) for the newly generated first authentication information, and store the newly generated first authentication information and the newly obtained digital certificate in the eUICC. This allows the first authentication information and digital certificate to be updated by updating the applet, for example, by updating the algorithm for generating the first authentication information, if the vulnerability of the digital certificate weakens.

[0020] In one aspect of this disclosure, the control unit may, when it enables the second profile information associated with the second owner, which is newly stored in the eUICC, obtain a second digital certificate from a predetermined certification authority that proves the second authentication information corresponding to the second profile information belongs to the second owner. The control unit may store the second authentication information and the second digital certificate in the eUICC and use the second authentication information and the second digital certificate to obtain authentication from the first server. At this time, the first profile information and the first digital certificate are invalidated or deleted. This prevents the first server from confusing the first owner (previous owner) with the second owner (current owner) when, for example, the owner of the information processing device changes from the first owner to the second owner.

[0021] In connected cars and other vehicles with communication capabilities, various data such as vehicle status and driving data are collected by the vehicle manufacturer. However, a vehicle only becomes capable of communication after it has been purchased and a contract with the purchaser (owner) for a carrier network has been established. Since the vehicle is not capable of communication between the time it leaves the factory and the time it is purchased, it is not possible to collect information about that vehicle during that period.

[0022] One aspect of this disclosure, in view of the above-mentioned problems, is to store default profile information in the eUICC of the information processing device so that the information processing device is able to communicate from the time it leaves the factory. This allows the information processing device to be able to communicate from the time it leaves the factory until it is purchased, and for example, manufacturers of information processing devices or devices equipped with information processing devices can collect information from the information processing device from the time it leaves the factory until it is purchased.

[0023] More specifically, one aspect of this disclosure is an information processing device comprising: an eUICC capable of holding multiple profile information used for connecting to a communication network; and a control unit that enables one of the multiple profile information and uses the enabled profile information to connect to the communication network. The eUICC holds default profile information used for connecting to a first communication system when the information processing device is shipped from the factory. The control unit enables the default profile information when the information processing device is shipped from the factory and uses the default profile information to connect to the first communication system. When first profile information corresponding to a first owner of the information processing device is stored in the eUICC, the control unit disables the default profile information, enables the first profile information, and uses the first profile information to connect to the first communication system.

[0024] The information processing device is, for example, an in-vehicle device mounted in a vehicle, a smartphone, a tablet terminal, a wearable terminal, an IoT terminal, and a terminal capable of wireless communication based on a mobile communication system. The in-vehicle device is, for example, a DCM, a car navigation system, a drive recorder, and an ECU. The control unit is, for example, a processor such as a CPU, a DSP, and a data communication processor, and a circuit such as an FPGA. The first communication system is, for example, a wireless communication system that requires the terminal to be equipped with an eUICC, such as a mobile communication system of 4G, 5G, 6G or later, and 3G. The first communication system may be a system managed by the manufacturer of the information processing device or the device on which the information processing device is installed, or it may be a communication system of a carrier that issues profile information held in the eUICC.

[0025] According to one aspect of this disclosure, the information processing device can be connected to a first communication system by default profile information from the time it leaves the factory until it is purchased and an owner is determined. This allows the first communication system to collect information about the information processing device even during the time it leaves the factory until it is purchased.

[0026] In one aspect of this disclosure, the default profile information may be configured to charge a predetermined carrier for communication fees. In the default profile information, the predetermined carrier configured as the billing destination is a carrier that collects information about the information processing device. The predetermined carrier is, for example, the administrator of the first communication system (the manufacturer of the information processing device, the manufacturer of equipment such as vehicles that are equipped with the information processing device, and the carrier that issues the profile information), and a carrier that requests the administrator of the first communication system to collect information about the information processing device.

[0027] According to one aspect of this disclosure, the communication charges for communications made by connecting to the first communication system using the default profile information from the time of factory shipment until purchase are not charged to the owner, thus avoiding the burden of communication costs on the owner. Furthermore, once the owner of the information processing device is determined, the default profile information is invalidated, so the designated business operator is not required to bear any communication costs after the owner is determined.

[0028] In one aspect of this disclosure, when a designated used goods dealer sells the information processing device secondhand, the control unit disables or deletes the first profile information and sets the default profile The file information may be enabled, and the system may connect to the first communication system using the default profile information. This allows the information processing device to remain communicative and collect information about it, even while it is being sold secondhand.

[0029] Another aspect of this disclosure is a system comprising the information processing device and a third server that holds information indicating whether the profile information used by the information processing device to connect to the first communication system is default profile information. If the first communication system is a 4G-compatible system, for example, the third server is an HSS (Home Subscriber Server).

[0030] According to one aspect of this disclosure, it is possible to determine whether or not the information processing device is for sale based on information indicating whether or not the profile information used to connect to the first communication network held by the third server is a default file.

[0031] This disclosure can also be identified in other aspects as a method by which a computer performs processing of the information processing apparatus, a program for causing a computer to perform processing of the information processing apparatus, and a computer-readable recording medium on which the program is recorded.

[0032] Embodiments of this disclosure will be described below with reference to the drawings. The configurations of the following embodiments are illustrative, and this disclosure is not limited to the configurations of these embodiments.

[0033] <First Embodiment> Figure 1 shows an example of service provision to a vehicle 10 according to the first embodiment. In the first embodiment, the communication system 2 is a system managed by the manufacturer of the vehicle 10. The communication system 2 collects information related to the communication of the vehicle 10 and controls the communication of the vehicle 10. The communication system 2 also enhances the security of the vehicle 10 by routing the vehicle 10's communication through the communication system 2 before sending it to an external network such as the Internet. The communication system 2 also provides the vehicle 10 with services such as vehicle status monitoring, navigation services, and emergency call services. Server 4 is a server trusted by the communication system 2 and provides these services to the vehicle 10. In Figure 1, Server 4 is located outside the communication system 2, but it may be located inside the communication system 2.

[0034] Vehicle 10 is a connected car and is equipped with a DCM 1 that handles communication functions. In the first embodiment, the manufacturer of vehicle 10, which is the administrator of the communication system 2, does not own the communication infrastructure. Therefore, the owner of vehicle 10 contracts with a communication carrier and connects to the communication system 2 through the communication carrier network. In addition, DCM 1 can communicate using communication methods other than mobile communication methods, such as WiFi communication. For example, DCM 1 can connect to the internet using WiFi as the access network. When using WiFi as the access network, DCM 1 can connect to the internet even without being connected to the communication system 2. However, in this case, it cannot receive services from the communication system 2. On the other hand, even when using WiFi as the access network, DCM 1 can connect to the communication system 2 and connect to the internet via the communication system 2, depending on the settings. However, in the first embodiment, the connection of DCM 1 to the communication system 2 when using WiFi as the access network is not described.

[0035] Communication system 2, SM-DP+ 3, server 4, and certification authority 5 are each connected to a public network such as the Internet and can communicate with each other. Vehicle 10 is connected to a public network such as the Internet, for example, via a WiFi network, and communicates with SM-DP+ 3 and server 5. It is possible to connect to 4 and the certification authority 5.

[0036] The communication system 2 includes an HSS 21 and an AAA (Authentication Authorization Accounting) 22. However, Figure 1 shows only the components according to the first embodiment. The components of the communication system 2 are not limited to those shown in Figure 1. The HSS 21 holds information about subscribers connected to the communication system 2. The subscriber information held by the HSS 21 includes, for example, identification information of the owner of the vehicle 10, identification information of the vehicle 10 (DCM 1), authentication information used for authentication of the DCM 1, and identification information of the profile information used for authentication.

[0037] AAA 22 authenticates DCM 1 using information about DCM 1 held in HSS 21, employing a predetermined authentication method. The authentication method employed by AAA 22 is, for example, AKA (Authentication and Key Agreement) authentication, which is used in carrier network authentication. However, the authentication method employed by AAA 22 is not limited to AKA authentication; a communication system 2's own authentication method may also be adopted.

[0038] SM-DP+ 3 manages profile information. SM-DP+ 3 stores profile information issued by communication system 2 about subscribers (in the first embodiment, the owner of vehicle 10) who have entered into a service subscription agreement with communication system 2. SM-DP+ 3 also provides profile information corresponding to the owner of vehicle 10 in response to requests from DCM 1. SM-DP+ 3 is managed, for example, by the same administrator as the administrator of communication system 2.

[0039] Certification Authority 5 is a system that verifies the authenticity of the owner of Vehicle 10 and issues an electronic certificate that proves the authentication information used by Vehicle 10 belongs to that person. Certification Authority 5 is a system managed by a trusted third-party organization. Hereinafter, the electronic certificate that proves the authentication information used by Vehicle 10 belongs to that person will simply be referred to as the "identity verification certificate."

[0040] DCM 1 is equipped with an eSIM and connects to the communication system 2 using the profile information stored in the eSIM. In the first embodiment, since DCM 1 is installed in the vehicle 10, the purchaser of the vehicle 10, the owner of the vehicle 10, the owner of DCM 1, and the subscriber of the communication system 2 are the same person.

[0041] In the first embodiment, the eSIM of DCM 1 stores default profile information used for connecting to the communication system 2. The default profile information is downloaded from SM-DP+ 3 via WiFi or the like by the manufacturer's staff at the time of factory shipment, stored in the eSIM, and activated. The default profile information is profile information set to correspond to the communication system 2. That is, while DCM 1 is connected to the communication system 2 using the default profile information, it is indicated that the owner of the vehicle 10 is the communication system 2, i.e., that the vehicle 10 is not owned by a specific individual and is for sale. Because the default profile information is held in the eSIM of DCM 1, DCM 1 is able to connect to and communicate with the communication system 2 from the time of factory shipment. Furthermore, the communication system 2 can obtain information about DCM 1 from the time of factory shipment of DCM 1, and can, for example, monitor the status of the vehicle 10 even while it is for sale. Hereinafter, the default profile information will simply be referred to as the default profile.

[0042] In the first embodiment, the process from the purchase of the vehicle 10 to receiving services provided by the communication system 2 for the owner of the vehicle 10 is as follows:

[0043] (1) When the purchase contract for vehicle 10 is concluded, the new owner will submit documents such as a seal certificate and other identification documents, as well as a parking certificate. In addition, a contract to subscribe to the services of communication system 2 will be made in conjunction with the purchase contract for vehicle 10. Based on the contents of the purchase contract for vehicle 10 and the contract to subscribe to the services of communication system 2, information about the owner will be registered in communication system 2.

[0044] The owner information registered in the communication system 2 includes, for example, the owner's personal information such as name, address, gender, date of birth, and identification documents, information about the purchased vehicle, and subscriber information for the communication system 2 service. Information about the purchased vehicle includes, for example, the vehicle's make, model, information on the license plate, and garage location. Subscriber information for the communication system 2 service includes, for example, the owner's identification information (IMSI), DCM 1 identification information (IMEI), profile information, and setting information such as the service plan contract details and payment method. Subscriber information for the communication system 2 service is stored in HSS 21. The owner's personal information and vehicle information may be stored in HSS 21 or in a database different from HSS 21.

[0045] The subscription contract for the communication system 2 service may be made at the same time as the purchase contract for vehicle 10, or at a later time. Once the subscription contract for the communication system 2 service is concluded, the communication system 2 issues profile information corresponding to the owner based on the subscriber information, and this profile information is registered in SM-DP+ 3. In addition, information on identity verification documents (seal certificate, identity verification document with facial image, My Number Card) is transmitted from the communication system 2 to the certification authority 5, and the certification authority 5 performs an identity verification review of the owner of vehicle 10, and the information linking the owner of vehicle 10 to vehicle 10 (DCM 1) is registered in the certification authority 5.

[0046] (2) The owner of vehicle 10 operates DCM 1 to download profile information corresponding to the owner of vehicle 10 from SM-DP+ 3. Note that the download of profile information may be performed, for example, via WiFi, or, in the first embodiment, since DCM 1 is connected to communication system 2 using the default profile, it may be performed via communication system 2. The profile information corresponding to the owner of vehicle 10 is stored in the eSIM of DCM 1. Hereinafter, the profile information corresponding to the owner of vehicle 10 will simply be referred to as the owner profile.

[0047] For example, when the owner profile is activated by the owner of vehicle 10, the default profile is deactivated. Subsequently, a connection is re-established between DCM 1 and communication system 2, with the owner of vehicle 10 as the subscriber to the communication system 2's service. During this process, DCM 1 is authenticated by AAA 22 using the owner profile information. AAA 22 authenticates the owner of vehicle 10 using the subscriber information corresponding to the owner of vehicle 10 stored in HSS 21. As a result, HSS 21 records that DCM 1 is connected to communication system 2 using the owner profile. From this point onward, DCM 1 can connect to the internet via communication system 2.

[0048] (3) When the owner of the vehicle 10 receives a service from the server 4 as one of the services of the communication system 2, the DCM 1 is authenticated by the server 4. The DCM 1 generates authentication information for this purpose. In the first embodiment, the DCM 1 generates the authentication information using the owner profile as the key. The authentication method adopted by the server 4 is, for example, TLS (Transport Layer Security) authentication. The authentication information is, for example, the public key and private key used in TLS authentication.

[0049] (4) DCM 1 requests Certification Authority 5 to issue an identity verification certificate that proves it is the owner of vehicle 10. Certification Authority 5 already has the association between vehicle 10 (DCM 1) and its owner registered, so Certification Authority 5 issues the identity verification certificate based on this. Since the identity verification certificate is created based on identity verification documents, it strongly proves the authenticity of the person. DCM 1 obtains the identity verification certificate from Certification Authority 5 and stores it in the eSIM, along with the authentication information, linked to the owner profile. The authentication information sent to Certification Authority 5 for which the identity verification certificate is issued is, for example, the public key used in TLS authentication. The eSIM stores the TLS public key and private key.

[0050] (5) DCM 1 accesses server 4 via communication system 2, sends the identity verification certificate stored in the eSIM to server 4, and receives authentication from server 4. If authentication is successful, DCM 1 will then be able to receive services from server 4.

[0051] In the first embodiment, authentication information used for authentication with server 4 is generated using the owner profile information of vehicle 10 as the key. Furthermore, the identity verification certificate for said authentication information is stored in the eSIM and is therefore rewritable. As a result, for example, if the owner of vehicle 10 changes and the activated owner profile is changed, the identity verification certificate used for authentication with server 4 will also change. This allows server 4 to identify the current owner of vehicle 10 from the identity verification certificate used for authentication with DCM 1, even if the owner of vehicle 10 has changed.

[0052] There are two main ways to connect DCM 1 to communication system 2 via the carrier network. The first is if communication system 2 is an MVNO (Mobile Virtual Network Operator) Furthermore, it has a billing function for connection to communication system 2, and DCM 1 connects using the carrier network with which it has a contract with communication system 2 as an MVNO. In this case, settings regarding billing for communication charges are made in the default profile and owner profile within the eSIM. For example, the default profile is set to the administrator of communication system 2 (manufacturer of vehicle 10) as the recipient of the billing for communication charges, while the owner profile is set to the owner of vehicle 10.

[0053] Another method is that communication system 2 is not an MVNO and does not have a billing function for connections to communication system 2, and DCM 1 connects to the gateway (ePDG) within communication system 2 via an IPsec tunnel on the carrier network. In this case, DCM DCM 1 is equipped with another SIM (hereinafter referred to as the second SIM) to connect to the carrier network, and the owner of vehicle 10 is required to enter into a contract with the carrier network separately from the communication system 2. For authentication in establishing the connection between DCM 1 and the carrier network, profile information used for connecting to the carrier network, which is stored in the second SIM, is used. The default profile or owner profile in the eSIM is used for authentication in establishing the connection with the communication system 2 after the connection between DCM 1 and the carrier network has been established. In this case, DCM 1 does not have any special contract between the carrier network used to connect to the communication system 2 and the communication system 2, and the owner of vehicle 10 can freely choose the carrier network. In addition, the default profile and owner profile in the eSIM do not contain any settings regarding the billing of communication charges. The second SIM may be an eSIM or a card-type SIM. In the following explanation, we will assume that the second SIM is an eSIM.

[0054] For example, DCM 1 stores a default profile in the eSIM when the vehicle 10 is shipped from the factory, and stores profile information used to connect to the carrier network specified by the manufacturer of the vehicle 10 in the second SIM. This profile information includes the destination for billing communication charges. For example, the administrator of communication system 2 (the manufacturer of vehicle 10) is set. When vehicle 10 is purchased, as described above, the owner profile is stored in the eSIM, and profile information used to connect to the carrier network selected by the owner is stored in the second SIM. In this profile information, the owner of vehicle 10 is set as the recipient of the billing for communication charges.

[0055] In the first embodiment, regardless of the method of connecting DCM 1 and communication system 2 via the carrier network, communication charges incurred while connected to communication system 2 using the default profile are charged to the administrator of communication system 2 (the manufacturer of vehicle 10).

[0056] Figure 2 shows an example of the hardware configuration of DCM 1. DCM 1 includes a CPU 101, memory 102, auxiliary storage device 103, first communication unit 104A, second communication unit 104B, and eUICC 105 as its hardware configuration. The auxiliary storage device 103 is, for example, an HDD (Hard Disk Drive) and an SSD (Solid State Drive). Programs held in the auxiliary storage device 103 include, for example, an OS (Operation System), a communication control program, and several other programs. The communication control program is a program that connects to the communication system 2 using profile information in the eUICC 105. Memory 102 includes, for example, semiconductor memory such as ROM (Read Only Memory) and RAM (Random Access Memory). Memory 102 and auxiliary storage device 103 are examples of computer-readable recording media.

[0057] The CPU 101 performs various processes by loading the OS and various other programs stored in the auxiliary storage device 103 into memory 102 and executing them. There may be more than one 101; the CPU 101 is an example of a "control unit".

[0058] In the first embodiment, the first communication unit 104A communicates with an external device based on a 4G mobile communication system. If the communication system 2 is a system that supports 5G or 6G or later mobile communication systems, the first communication unit 104A will also support the mobile communication system supported by the communication system 2. The second communication unit 104B performs wireless communication based on a system different from the mobile communication system. The second communication unit 104B supports wireless communication systems such as WiFi and Bluetooth®.

[0059] In the first embodiment, the eUICC 105 is a chip-type eUICC. However, it is not limited to this, and the eUICC 105 may be a card-type card that can be inserted into and removed from the DCM 1. In this case, the DCM 1 is equipped with an eSIM card slot, reader, and writer. In Figure 2, the eUICC 105 is assumed to be a chip-type embedded in the DCM 1.

[0060] The eUICC 105 comprises a CPU 105-1, memory 105-2, and auxiliary storage device 105-3. The CPU 105-1 and memory 105-2 are the same as those of the CPU 101 and memory 102, respectively. The auxiliary storage device 105-3 is, for example, flash memory or EEPROM. The auxiliary storage device 105-3 stores, for example, the eUICC OS, a program for downloading profile information, a program for managing profile information, and so on.

[0061] Note that the hardware configuration of DCM 1 is not limited to the configuration shown in Figure 2. For example, in addition to the eUICC 105, it may also include a device equivalent to a SIM. The device equivalent to a SIM is, for example, a SIM slot and SIM card reader for an eUICC or a card-type removable UICC SIM card.

[0062] Figure 3 shows an example of the functional configuration of DCM 1. DCM 1 comprises a communication control unit 11, an LPAd 12, and a service control unit 16. The communication control unit 11 controls the connection between DCM 1 and the communication system 2 using profile information held and activated in the eUICC 105. Details of the processing performed by the communication control unit 11 will be described later.

[0063] The service control unit 16 controls the reception of services from the communication system 2, including the services of server 4. Specifically, the service control unit 16 performs authentication with server 4 and processes related to the services.

[0064] LPAd 12 manages the profile information stored in eUICC 105. In other words, processing from DCM 1 to eUICC 105 is performed via LPAd 12. More specifically, LPAd 12 downloads profile information from SM-DP+ 3 according to user instructions and transfers the downloaded profile information to eUICC 105. LPAd 12 also receives user instructions to enable, disable, or delete profile information stored in eUICC 105 and transfers these instructions to eUICC 105. LPAd 12 also queries SM-DP+ 3 for events such as profile information updates. Furthermore, when the communication control unit 11 and service control unit 16 access information stored in eUICC 105, this access is also performed via LPAd 12.

[0065] The eUICC 105 has the following functional configuration: ISD-R (Issuance Security Domain Root It includes 13, an ISD-P (Issure Security Domain Profile) for the default profile 14, and an ISD-P 15 for the owner profile. These functional configurations are achieved by the CPU 105-1 executing a program stored in the auxiliary storage device 105-3.

[0066] ISD-R 13 is the interface with LPAd 12. ISD-R 13 receives the downloaded profile information from LPAd 12 and installs the profile information. Secure communication is used between 13 and SM-DP+ 3. Furthermore, ISD-R 13 enables, disables, or deletes the corresponding profile information according to instructions received from LPAd 12.

[0067] ISD-P is the area that stores profile information. An ISD-P is generated for each profile. Profile information is downloaded from SM-DP+ 3 as packaged data along with the applet, OTA (Over The Air) function control program, and program that controls access to the wireless communication network, as described later. The packaged data containing profile information will be referred to as the profile package below. The profile package includes an encrypted part that stores the profile information, etc., and a part that stores the ISD-P creation procedure. Based on the ISD-P creation procedure described in the profile package, the ISD-R 13 creates the ISD-P. The eUICC OS decrypts the encrypted part of the profile package and expands the profile information, etc., into the ISD-P. Hereinafter, the ISD-P may also be referred to as the profile. Furthermore, activating the profile information indicates activating the ISD-P.

[0068] The ISD-P 14 for the default profile is created at the factory when the default profile package is downloaded and installed from SM-DP+ 3. The ISD-P 15 for the owner profile is created when the owner of vehicle 10 downloads and installs the owner profile package from SM-DP+ 3. It is created when installed.

[0069] The ISD-P 15 for the owner profile stores profile information 151, an authentication information generation applet 152, authentication information 153, and an identity verification certificate 154. Profile information 151 is the owner profile for vehicle 10. Profile information 151 includes, for example, the IMSI (International Mobile Subscription Identity), which is the individual identification number of DCM 1, the ICCID (Integrated Circuit Card ID), which is the identification information of the owner profile of vehicle 10, and authentication information used for authentication of communication system 2. The authentication information used for authentication of communication system 2 is, for example, the public key and private key of AKA authentication.

[0070] The authentication information generation applet 152 is a program that generates authentication information 153 using profile information 151 as the key. Authentication information 153 is, for example, the public key and private key used in TLS authentication adopted by server 4. The identity verification certificate 154 is an electronic certificate issued by the certification authority 5 for the authentication information 153. If the authentication information 153 includes a public key and a private key, the identity verification certificate 154 is an electronic certificate for that public key. The public key and private key together are also called key information. Note that in Figure 3, the components of the first embodiment are extracted and shown, and the components included in the owner profile ISD-P 15 are not limited to the components shown in Figure 3.

[0071] The ISD-P 14 for the default profile stores, for example, default profile information. This default profile information includes, for example, the IMSI, which is the individual identification number of DCM 1, the ICCID, which is the identification information of the default profile, and authentication information used for authentication of the communication system 2. Note that the IMSI and ICCID are different values ​​for the ISD-P 14 for the default profile and the ISD-P 15 for the owner profile. If it is desired that the vehicle 10 will continue to receive services from the server 4 even while on sale, the ISD-P 14 for the default profile may store authentication information used for authentication of the server 4 and an electronic certificate that proves that the authentication information belongs to the administrator of the communication system 2 (the manufacturer of the vehicle 10). If the authentication information is generated by an applet, the applet may also be stored in the ISD-P 14 for the default profile. The authentication information generation algorithm of the applet may be the same as or different from that of the authentication information generation applet 152. However, the format of the generated authentication information is the same regardless of the generation algorithm.

[0072] Note that the functional configuration of DCM 1 shown in Figure 3 is just one example, and the functional configuration of DCM 1 is not limited to the example shown in Figure 3.

[0073] Figure 4 shows an example of the hardware configuration of the information processing device 6. The information processing device 6 is an example of a device that operates as either the HSS 21, AAA 22, SM-DP+ 3, or server 4. The information processing device 6 is, for example, a computer or device dedicated to the HSS 21, AAA 22, SM-DP+ 3, or server 4.

[0074] The information processing device 6 includes, as a hardware configuration, a processor 601, memory 602, auxiliary storage device 603, and a communication unit 604. The processor 601, memory 602, auxiliary storage device 603, and communication unit 604 are electrically connected by a bus. Memory 602 and auxiliary storage device 603 are the same as memory 102 and auxiliary storage device 103, respectively. The auxiliary storage device 603 contains HSS 21 and AAA, which are handled by the information processing device 6. This unit contains programs to implement one of the following operations: 22, SM-DP+ 3, or Server 4.

[0075] The processor 601 performs various processes by loading the OS and various other programs stored in the auxiliary storage device 603 into the memory 602 and executing them. The processor 601 can be, for example, a CPU, a DSP, and a GPU (Graphics Processing Unit). Furthermore, the processor 601 is not limited to one, but may be provided in multiple units. If multiple processors are provided, each of the multiple processors 601 may be a different type of processor.

[0076] The communication unit 604 is, for example, a NIC (Network Interface Card), an optical line interface, etc. The communication unit 604 may also be, for example, a wireless communication circuit connected to a wireless network such as a wireless LAN. The hardware configuration of the information processing device 6 is not limited to that shown in Figure 4.

[0077] Figure 5 shows an example of the functional configuration of HSS 21. The HSS 21 includes a control unit 211, a subscriber information DB 212, and a terminal connection information DB 213. For example, in response to a request from AAA 22, the HSS 21 reads data from the subscriber information DB 212 or the terminal connection information DB 213, or writes data to the subscriber information DB 212 or the terminal connection information DB 213.

[0078] The subscriber information DB 212 stores subscriber information. The terminal connection information DB 213 stores information about terminals connected to the communication system 2. Note that the functional configuration of HSS 21 is not limited to that shown in Figure 5.

[0079] Figure 6 shows an example of the information held in the subscriber information DB 212. One record in the subscriber information DB 212 shown in Figure 6 includes the fields for subscriber ID, vehicle ID, SIM ID, profile ID, matching ID, default, authentication information, and configuration information.

[0080] The Subscriber ID field stores, for example, the IMSI that communication system 2 assigns to subscribers of communication system 2's services. In the first embodiment, the subscriber is the administrator of communication system 2 in the default profile, and the owner of vehicle 10 (the subscriber of communication system 2's services) in the owner profile.

[0081] The vehicle ID field stores the IMEI (International Mobile Equipment Identity), which is the identification information for the DCM 1 assigned by the DCM 1 manufacturer. The manufacturer of vehicle 10 and the manufacturer of DCM 1 may be different. The SIM ID field stores the EID (Embedded Identity Document), which is the identification number of the SIM assigned to eUICC or UICC.

[0082] The Profile ID field stores the ICCID, which is the identifier for the profile information. The Matching ID field stores the Matching ID assigned to the profile information. The Matching ID is the identifier used to identify the profile package in SM-DP+ 3. The Default field stores information indicating whether the profile information is the default profile. This information may be a flag, for example. The Authentication Information field stores the authentication information used to authenticate the DCM 1. For example, if the authentication method adopted by AAA 22 is AKA authentication, the Authentication Information field stores the public key and private key corresponding to the DCM 1.

[0083] The settings information field stores the settings configured for that profile. For example, the profile settings include, for instance, the contract details with the subscriber and policy information. If communication system 2 is an MVNO, the settings also store the billing destination and billing rules for communication charges. In the case of the default profile, the billing destination for communication charges is the administrator of communication system 2 (the manufacturer of vehicle 10). In the case of the owner's profile, the billing destination for communication charges is the owner of vehicle 10.

[0084] The information stored in the subscriber information DB 212 is, for example, entered from the operator terminal of the communication system 2. Note that the information stored in the subscriber information DB 212 is not limited to the example shown in Figure 6.

[0085] Figure 7 shows an example of the information held in the terminal connection information DB 213. The terminal connection information DB 213 stores information about the connection of DCM 1 that is connected to the communication system 2. One record in the terminal connection information DB 213 shown in Figure 7 includes the fields for subscriber ID, vehicle ID, authentication date and time, and profile ID.

[0086] The Subscriber ID and Vehicle ID fields store the IMSI and IMEI, respectively, similar to the Subscriber ID and Vehicle ID fields in the Subscriber Information DB 212. The Authentication Date and Time field stores the date and time when the relevant DCM 1 was authenticated by AAA 22. The Profile ID field stores the identification information (ICCID) of the profile information used for authentication by AAA 22. Records in the Terminal Connection Information DB 213 are generated when DCM 1 newly connects to the communication system 2 and deleted when communication with that DCM 1 is terminated.

[0087] If the ICCID in the Profile ID field of a record in the Terminal Connection Information DB 213 indicates that it is the default profile in the Subscriber Information DB 212, it can be determined that the vehicle in question is currently for sale as a new or used vehicle. Note that the information held in the Terminal Connection Information DB 213 is not limited to that shown in Figure 7. In the first embodiment, an example was shown in which the Subscriber Information DB 212 manages information that does not change according to the connection status of DCM 1, and the Terminal Connection Information DB 213 manages information that changes dynamically according to the connection status of DCM 1, but this is not limited to this. The information held in the Subscriber Information DB 212 and the information held in the Terminal Connection Information DB 213 may be managed as a single database in an integrated state.

[0088] Figure 8 shows an example of the functional configuration of Server 4. Server 4 comprises an authentication unit 41, a service provision unit 42, and a user information DB 43. The authentication unit 41 authenticates DCM 1 using a predetermined authentication method (e.g., TLS authentication). The authentication unit 41... By receiving the identity verification certificate 154 from 1, access to the authentication unit 41 is permitted. The service provision unit 42 performs processing related to the service according to DCM 1.

[0089] The user information database 43 stores information about users of the services provided by server 4. This user information includes, for example, user identification information, authentication information used to authenticate the user, user personal information, and service details corresponding to the user's personal information. For example, the subscriber identification information (IMSI) in communication system 2 is used as the user identification information.

[0090] The identity verification certificate 154 is for authentication information generated using profile information. The profile information includes identification information (IMSI) that can identify the owner of vehicle 10. The service provision unit 42 can identify the owner of vehicle 10 using the identity verification certificate 154 used for authentication and can provide services according to the attributes of the owner of vehicle 10. For example, if the user information DB 43 contains personal information of the user, Some of the information held may be reused from the database held by communication system 2. Note that the functional configuration of server 4 is not limited to that shown in Figure 8.

[0091] <Processing flow> Figure 9 is an example of a flowchart for the profile information download process performed by DCM 1. The process shown in Figure 9 is repeatedly executed while DCM 1 is running. The entity executing the process shown in Figure 9 is the CPU 101 of DCM 1, but for convenience, the explanation will focus on the functional components. The same applies to the flowcharts from Figure 9 onward.

[0092] In OP101, LPAd 12 determines whether a user operation requesting profile acquisition has been entered. For example, when a contract is made to subscribe to the services of communication system 2, a QR code (registered trademark) containing an activation code for downloading the owner profile from communication system 2 is notified to DCM 1. The method of notifying the QR code may be, for example, by printing it on paper, by having the user access a predetermined URL, or by sending it to the vehicle owner's smartphone via email, etc. If the QR code is notified on paper or on the vehicle owner's smartphone, for example, the vehicle owner may input a user operation requesting profile acquisition to DCM 1 by reading the QR code with an in-vehicle camera, etc., installed in vehicle 10 and connected to DCM 1. If the QR code is notified as digital data (for example, image data, etc.) by accessing a predetermined URL, DCM 1 may input a user operation requesting profile acquisition to DCM 1 by reading the data of the QR code. The activation code will also be entered along with the request. Note that the user action to request profile acquisition is not limited to using a QR code.

[0093] If a user action requesting profile retrieval is entered (OP101:YES), the process proceeds to OP102. If no user action requesting profile retrieval is entered (OP101:NO), the process proceeds to OP105.

[0094] In OP102, LPAd 12 sends a profile request to SM-DP+ 3 to request the acquisition of profile information. If a QR code is used, an activation code is also sent along with the profile request. The activation code includes, for example, the address of SM-DP+ 3 and the matching ID.

[0095] In OP103, LPAd 12 downloads the profile package from SM-DP+ 3. In OP104, LPAd 12 transfers the downloaded profile package to ISD-R 13. After that, the process shown in Figure 9 is completed.

[0096] In OP105, LPAd 12 determines whether there are any updates to the profile information held in the owner profile ISD-P 15. Profile information updates occur, for example, when a vulnerability is found in the authentication information or authentication information 153 contained in profile information 151, or when the algorithm of the authentication information generation applet 152 is updated. Furthermore, profile information updates are detected by ISD-R 13, and LPAd This is notified to 12. If there are updates to the profile information held in the owner profile ISD-P 15 (OP105:YES), the process proceeds to OP101.

[0097] Note that profile information updates are performed on a package-by-package basis. Therefore, a profile package containing the updated profile information is downloaded from SM-DP+ 3, and a new ISD-P corresponding to the updated profile information is created. The ISD-P corresponding to the profile information is deactivated when the ISD-P corresponding to the updated profile information is activated. Therefore, the matching ID of the profile package will change from the one before the update. The matching ID of the profile package containing the updated profile information is obtained from SM-DP+ 3, for example, by ISD-R 13 along with the detection of the profile information update. However, the updating of profile information is not limited to being performed on a package-by-package basis, but may also be performed on a profile information unit or applet-by-applet basis when an update has occurred. When the profile information is updated on a profile information unit or applet-by-applet basis, the updated profile information or applet may be downloaded from SM-DP+ 3 and stored in the corresponding ISD-P. Note that the profile information download process is not limited to the process shown in Figure 9 and can be modified as appropriate depending on the embodiment.

[0098] Figure 10 is an example flowchart of the process of enabling or disabling a profile, which is performed by DCM 1. The process shown in Figure 10 is repeatedly executed at predetermined intervals while DCM 1 is running.

[0099] In OP201, LPAd 12 determines whether a user action to activate a profile has been entered. Note that the user action to activate or deactivate a profile is entered, for example, from the menu screen related to the SIM. If a user action to activate a profile has been entered (OP201: YES), the process proceeds to OP202. In OP202, LPAd 12 notifies ISD-R 13 of the instruction to activate the profile, and ISD-R 13 deactivates the currently activated profile if there is one. If there is no currently activated profile, the process in OP202 is skipped. In OP203, ISD-R 13 activates the profile (ISD-P) that was specified for activation.

[0100] If no user action to activate the profile is entered (OP201:NO), the process proceeds to OP204. In OP204, LPAd 12 determines whether or not a user action to deactivate the profile has been entered. If a user action to deactivate the profile has been entered (OP204:YES), the process proceeds to OP205. If neither a user action to activate nor deactivate the profile has been entered (OP204:NO), the process shown in Figure 10 ends. In OP205, LPAd 12 notifies ISD-R 13 of the instruction to deactivate the profile, and ISD-R 13 deactivates the profile (ISD-P) that was specified for deactivation.

[0101] In OP206, if there is a change in the enabled or disabled profiles, LPAd 12 notifies the communication control unit 11 of the change in the enabled profiles or the deactivation of all profiles. If there is a change in the enabled profiles, the communication control unit 11 reconnects the communication to the communication system 2 using the newly enabled profile information. If the profile information is deactivated and there are no enabled profiles, the communication with the communication system 2 is disconnected. After that, the process shown in Figure 10 is completed.

[0102] For example, when vehicle 10 is shipped from the factory, a staff member inputs the operation to activate the default profile (OP201:YES), and the default profile is activated (OP203). For example, when vehicle 10 is purchased and the new owner downloads the owner profile from SM-DP+ 3 in preparation for connecting DCM 1 to communication system 2, the owner of vehicle 10 inputs the user operation to activate the owner profile (OP201:YES). In this case, since the default profile is already activated, the default profile is deactivated (OP202), and then the owner profile is activated. The rofile is enabled (OP203).

[0103] For example, when vehicle 10 is sold by its owner to a used car dealer and put on the market as a used car, the owner of vehicle 10 or a staff member of the used car dealer will input a user operation to activate the default profile in order to deactivate the owner profile (OP201:YES). In this case, the activated owner profile will first be deactivated (OP202), and then the default profile will be activated (OP203). When the owner profile is deactivated, the authentication information 153 and identity verification document 154 in the owner profile ISD-P 15 will also be deactivated.

[0104] Note that the process of enabling or deactivating a profile is not limited to the example shown in Figure 10. Furthermore, if vehicle 10 is sold by the owner to a used car dealer, the owner profile may be deleted from eUICC 105.

[0105] Figure 11 is an example of a flowchart for the process of obtaining the identity verification certificate 154 executed by DCM 1. The process shown in Figure 11 is initiated, for example, when the service control unit 16 accesses the server 4, if the identity verification certificate 154 is not stored in the owner profile ISD-P 15, or if the identity verification certificate 154 in the owner profile ISD-P 15 has expired, after obtaining permission from the user to obtain the identity verification certificate 154. The owner profile ISD-P 15 may not contain the identity verification certificate 154 if, for example, no access to the server 4 has been made since the owner profile was downloaded from SM-DP+ 3, or since the owner profile was updated.

[0106] In OP301, the service control unit 16 requests LPAd 12 to generate authentication information 153 using the authentication information generation applet 152. In OP302, LPAd 12 activates the authentication information generation applet 152 via ISD-R 13, generates authentication information 153, and the service control unit 16 obtains the authentication information 153. In OP303, the service control unit 16 sends a request to the certification authority 5 for the issuance of an electronic certificate for the authentication information 153. Along with this request, part (e.g., the public key) or all of the authentication information 153 is also sent.

[0107] In OP304, the service control unit 16 obtains an identity verification certificate 154 from the certification authority 5. In OP305, the service control unit 16 stores the authentication information 153 and the identity verification certificate 154 in the owner profile ISD-P 15. After that, the process shown in Figure 11 is completed. The service control unit 16 sends the identity verification certificate 154 to the server 4 and performs authentication processing with the server 4 using the authentication information 153, and starts using the server 4's services. Note that the process of obtaining the identity verification certificate 154 is not limited to the example shown in Figure 11.

[0108] Figure 12 shows an example of the processing sequence from when DCM 1 obtains the owner profile until it connects to communication system 2. The processing sequence shown in Figure 12 assumes that the default profile is stored in eUICC 105 and that the default profile is enabled.

[0109] In S11, DCM 1 receives user input from the owner of vehicle 10 requesting an owner profile (Figure 9, OP101: YES). In S12, DCM 1 sends a profile request to SM-DP+ 3 (Figure 9, OP102). In S13, DCM 1 downloads the owner profile package from SM-DP+ 3 (Figure 9, OP103). Communication between DCM 1 and SM-DP+ 3 in S12 and S13 is performed, for example, via WiFi. In S14, DCM 1, Transfer the downloaded owner profile package to eUICC 105 (Figure 9, OP104). In S15, ISD-R 13 in eUICC 105 creates an ISD-P 15 for the owner profile from the owner profile package, and the owner profile is installed.

[0110] In S21, the owner of vehicle 10 inputs a user action to activate the owner profile to DCM 1 (OP201:YES). In S22, DCM 1 sends an eUICC ISD-R 13 in 105 is instructed to activate the owner profile. In S23, the currently active default profile is deactivated (OP202), and then the owner profile is activated (OP204). In S24, DCM 1 is notified that the new owner profile has been activated (OP206).

[0111] In S25, DCM 1 uses the owner profile information to perform the procedure for establishing a connection to communication system 2. During the series of steps in AAA 22, authentication is performed between DCM 1 and HSS 21 using the owner profile information (AKA authentication). Once communication is established between DCM 1 and communication system 2, DCM 1 can communicate with external networks such as the Internet via communication system 2.

[0112] Figure 13 shows an example of the sequence of processes from when DCM 1 obtains the identity verification certificate 154 until it accesses server 4. As a prerequisite for the sequence of processes shown in Figure 13, for example, the sequence shown in Figure 12 has been executed, and DCM 1 has already connected to communication system 2 using the owner profile.

[0113] In S31, DCM 1 receives user input from the user (for example, the owner of vehicle 10) requesting the acquisition of identity verification certificate 154 (Figure 11, OP301). For example, if the user inputs a user operation to start the service of server 4, and the identity verification certificate 154 is not held in eUICC 105, a message requesting permission to acquire the identity verification certificate 154 is output, and if the user grants permission, the user operation requesting the acquisition of identity verification certificate 154 is input.

[0114] In S32, DCM 1 instructs the ISD-R 13 of eUICC 105 to generate authentication information 153. In S33, the authentication information generation applet 152 of eUICC 105 generates authentication information 153 using profile information 151. In S34, DCM 1 obtains ISD-R 13 through the ISD-R 13 of eUICC 105 (Figure 11, OP302). In S35, DCM 1 sends a request to the Certificate Authority 5 for the issuance of an electronic certificate for authentication information 153, along with the authentication information 153 (e.g., public key) (Figure 11, OP303). In S36, the Certificate Authority 5 issues an identity verification certificate 154. In S37, DCM 1 receives the identity verification certificate 154 from the Certificate Authority 5 (Figure 11, OP304). In S38, DCM 1 transfers the identity verification certificate 154 to eUICC 105. In S39, the ISD-R 13 of eUICC 105 stores the identity verification certificate 154 and authentication information 153 in the owner profile ISD-P 15 (Figure 11, OP305).

[0115] In S41, DCM 1 reads the identity verification certificate 154 from eUICC 105. In S42, DCM 1 sends an authentication request and the identity verification certificate 154 to Server 4. Subsequently, DCM 1 performs authentication processing with Server 4 using authentication information 153 (for example, TLS authentication). In S44, Server 4 authenticates DCM 1 and then begins providing services to DCM 1. Server 4 identifies the current owner of Vehicle 10 from the identity verification certificate 154 and can provide services according to the attributes of the owner of Vehicle 10, for example.

[0116] Figure 14 shows an example of the evolution of profile information used in vehicle 10. At the time of factory shipment, the default profile is stored and activated in eUICC 105. From the time of factory shipment until the contract for service subscription to communication system 2 is signed, the default profile remains activated, and DCM 1 connects to communication system 2 using the default profile. The HSS 21 of communication system 2 registers the default profile information (see, for example, Figure 6).

[0117] When a subscription agreement for the communication system 2 service is concluded, the owner A profile is downloaded and activated. This disables the default profile. From the time of the subscription agreement for the communication system 2 service until the sale, DCM 1 connects to the communication system 2 using the owner A profile. After the owner A profile is activated, the identity verification certificate 154 is also obtained. The communication system 2's HSS 21 registers the owner A information and the owner A profile information (see, for example, Figure 6). The default profile information remains in the HSS 21.

[0118] When vehicle 10 is sold to a used car dealer, the default profile is activated and the profile for owner A is deactivated. Simultaneously, the identity verification document 154 within the owner profile ISD-P 15 is also deactivated. Furthermore, the contract between the owner of vehicle 10 and the communication system 2 service is terminated, and therefore, the information of owner A and the owner A profile information are deleted from the communication system 2's HSS 21. From then until vehicle 10 is purchased and a new owner enters into a service contract with the communication system 2, DCM 1 connects to the communication system 2 using the default profile.

[0119] When vehicle 10 is repurchased and a new contract for the communication system 2 service is concluded for the new buyer B, a profile for owner B is downloaded and activated, and the default profile is deactivated. From then on, DCM 1 connects to communication system 2 using the owner B profile. After the owner B profile is activated, an identity verification document 154 corresponding to the owner B profile is also obtained. The HSS 21 of communication system 2 registers the owner B information and the owner B profile information (see, for example, Figure 6).

[0120] <Effects of the First Embodiment> In the first embodiment, the identity verification certificate 154 is generated from the profile information 151 and stored in the owner profile ISD-P 15. As shown in Figure 14, both the owner profile information and the owner profile ISD-P 15 change along with the change in the owner of the vehicle 10. The server 4, which performs authentication using the identity verification certificate 154, can identify the new owner from the identity verification certificate 154 even if the owner of the vehicle 10 changes. This allows the server 4 to provide services according to, for example, the attributes of the current owner of the vehicle 10.

[0121] Furthermore, in the first embodiment, as shown in Figure 14, the DCM 1 can connect to the communication system 2 using a default profile even when it is not owned by a specific individual, i.e., while it is being sold as a new or used vehicle. This allows the communication system 2 to collect and control information related to the vehicle 10's communication even while the vehicle 10 is being sold as a new or used vehicle.

[0122] Furthermore, in the first embodiment, in addition to a change in ownership, the owner profile is updated for reasons such as the detection of vulnerabilities in the identity verification certificate 154 or the owner profile, and the identity verification certificate 154 is also updated. This covers vulnerabilities in the identity verification certificate 154 and the owner profile, thereby enhancing security.

[0123] <Other variations> The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence.

[0124] In the first embodiment, the communication system 2 is assumed to be a system compatible with 4G. However, it is not limited to this, and the communication system 2 may be a system compatible with 5G, 3G, and 6G and later mobile communication systems. If the communication system 2 is 5G compatible, the communication system 2 may, for example, use UDM (Unified Data Management) instead of HSS. It is equipped with.

[0125] In the first embodiment, the communication system 2 was described as a system managed by the manufacturer of the vehicle 10, and was used as an example to collect and control information related to the communication of the vehicle 10. However, the application of the technology described in the first embodiment is not limited to the vehicle 10 and the communication system 2. For example, it can also be applied to communication terminals such as smartphones or IoT terminals and their manufacturer's communication system. Furthermore, the administrator of the communication system 2 can receive a request from a third party to collect information on the communication of subscribers to the communication system 2's service, and collect information on the communication of terminals connected to the communication system 2 and provide it to the third party. In this case, the third party will be the recipient of the billing for communication charges when the default profile is used.

[0126] The processes and methods described in this disclosure can be freely combined and implemented, provided that no technical inconsistencies arise.

[0127] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is implemented can be flexibly changed.

[0128] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, any type of disk such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, and any type of medium suitable for storing electronic instructions. [Explanation of Symbols]

[0129] 1. DCM 2. Communication System 3··SM-DP+ 4. Server 5. Certification Authority 6. Information Processing Device 10. Vehicles 11. Communications Control Unit 12··LPAd 13··ISD-R 14. ISD-P for default profile 15. Owner Profile ISD-P 16. Service Control Unit 21··HSS 22··AAA 41. Authentication Department 42. Service Provision Department 43. User Information Database 101··CPU 102...memory 103...Auxiliary storage device 104A...1st Communication Department 104B ··2nd Communications Department 105··eUICC 151. Profile Information 152. Authentication Information Generator Applet 153. Authentication Information 154. Identity Verification Document 211. Control Unit 212·Subscriber information DB 213 Terminal Connection Information Database

Claims

1. An eUICC (Embedded Universal Integrated Circuit Card) capable of storing multiple profile information used for connecting to a communication network, A control unit that enables one of the plurality of profile information and uses the enabled profile information to connect to the communication network, An information processing device comprising, The eUICC, at the time of factory shipment of the information processing device, holds default profile information used for connecting to the first communication system. The control unit, At the time of factory shipment of the information processing device, the default profile information is enabled, and the device connects to the first communication system using the default profile information. When first profile information corresponding to the first owner of the information processing device is stored in the eUICC, the default profile information is disabled, the first profile information is enabled, and the first communication system is connected using the first profile information. Information processing device.

2. The aforementioned default profile information is set to charge communication fees to a designated carrier. The information processing apparatus according to claim 1.

3. The control unit, when a designated used goods dealer sells the information processing device secondhand, disables or deletes the first profile information, enables the default profile information, and connects to the first communication system using the default profile information. The information processing apparatus according to claim 1.

4. The control unit, Obtaining a first digital certificate from a predetermined certification authority that proves that the first authentication information corresponding to the first profile information, used for authentication by a first server trusted by the first communication system, belongs to the first owner, The first authentication information and the first digital certificate are stored in the eUICC, Authentication by the first server using the first authentication information and the first digital certificate, To further execute, The information processing apparatus according to claim 1.

5. An information processing device according to any one of claims 1 to 4, A third server that holds information indicating whether the profile information used in the connection of the information processing device to the first communication system is the default profile information, A system equipped with these features.