Authentication System, Connected Car, and Authentication Method

The authentication system for connected cars uses wireless broadcast communication and cellular networks to securely associate and authenticate terminals with cars, addressing the security vulnerabilities of conventional methods and enhancing authentication strength and efficiency.

JP7717665B2Active Publication Date: 2025-08-04KDDI CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022111722
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-12
Publication Date
2025-08-04
Estimated Expiration
2042-07-12

AI Technical Summary

Technical Problem

Conventional authentication methods for IoT devices, such as connected cars, are insufficiently secure and prone to phishing attacks, lacking robust two-way authentication mechanisms.

Method used

An authentication system involving a connected car, a terminal, a server, and an authentication device, utilizing wireless broadcast communication and cellular networks to securely associate and authenticate terminals with connected cars using identifiers like IMSI and MSISDN, enabling two-way authentication with reduced operational complexity.

Benefits of technology

Enhances the security of terminal authentication for connected cars by providing strong two-way authentication, reducing the risk of phishing and improving operational efficiency through simplified and secure access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007717665000001
    Figure 0007717665000001
  • Figure 0007717665000002
    Figure 0007717665000002
  • Figure 0007717665000003
    Figure 0007717665000003
Patent Text Reader

Abstract

To provide an authentication system that can more safely authenticate a terminal when connected car services are provided to the terminal.SOLUTION: A connected car 30 includes an authentication value receiving unit 31 that receives an authentication value transmitted from a server 10 that provides services to a terminal 40 to an authentication device 20, by scanning wireless broadcast communication from the authentication device 20 to peripheral devices, and an identifier transmitting unit 32 that transmits its own IMSI together with the received authentication value to the server 10. The server 10 causes the terminal 40, which has been linked to an IMSI in advance, to transmit authentication value authentication information linked to the authentication value as authentication information for accessing the server 10.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system that authenticates a terminal and provides services for IoT devices.

Background Art

[0002] Conventionally, various Web services for IoT devices have been provided and can be used by authenticating the user's terminal. For example, in Patent Document 1, as a method for sharing the key of car sharing, a technique for remotely operating a key box in a car from a paired smartphone has been proposed.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, authentication for IoT devices is a one-way method and can be divided into two types: like a USB key used to authenticate an IoT device for a PC or the like, or like a wireless router that enables the use of an IoT device by entering a unique number of the IoT device into a PC or the like for pairing. In either case, the strength of authenticating the terminal is not sufficient, and in the conventional authentication system, there has always been a threat of phishing when using the service.

[0005] An object of the present invention is to provide an authentication system that can more securely authenticate a terminal when providing services of a connected car as an IoT device to the terminal.

Means for Solving the Problems

[0006] The authentication system according to the present invention includes a connected car, a terminal, a server that provides services related to the connected car to the terminal, and an authentication device. The server includes a terminal registration unit that registers by associating an identifier of the terminal and an identifier of the connected car, an authentication value transmission unit that transmits an authentication value to the authentication device, an identifier reception unit that receives the identifier of the connected car together with the authentication value received by the connected car via the authentication device from the connected car, an authentication information transmission unit that acquires the identifier of the terminal associated with the received identifier of the connected car and transmits authentication value authentication information associated with the authentication value to the terminal, and a terminal authentication unit that authenticates access from the terminal using the authentication value authentication information. The authentication device includes an authentication value transfer unit that transfers the authentication value received from the server to peripheral devices by wireless broadcast communication. The connected car includes an authentication value reception unit that scans the wireless broadcast communication and receives the authentication value, and an identifier transmission unit that transmits the identifier of the connected car together with the received authentication value to the server. The terminal includes an authentication information reception unit that receives the authentication value authentication information from the server, and a server access unit that accesses the server using the received authentication value authentication information.

[0007] The identifier of the connected car may be an IMSI, and the identifier of the terminal may be an MSISDN.

[0008] The authentication device may be the terminal.

[0009] The authentication value reception unit may receive the authentication value from the authentication device by a Bluetooth beacon.

[0010] The connected car according to the present invention includes an authentication value receiving unit that receives an authentication value transmitted from an authentication device to a peripheral device by scanning a wireless broadcast communication from the authentication device to the peripheral device, from a server that provides a service to a terminal, and an identifier transmitting unit that transmits its own identifier to the server together with the received authentication value. In the server, authentication value authentication information associated with the authentication value is transmitted to the terminal associated with the identifier in advance as authentication information for accessing the server.

[0011] The authentication method according to the present invention is an authentication system including a connected car, a terminal, a server that provides a service related to the connected car to the terminal, and an authentication device. The terminal registration step of registering the identifier of the terminal and the identifier of the connected car associated with each other by the server, the authentication value transmission step of transmitting an authentication value from the server to the authentication device, and the connected car scans a wireless broadcast communication from the authentication device to a peripheral device, thereby receiving the authentication value, an authentication value receiving step, an identifier transmitting step of transmitting the identifier of the connected car together with the received authentication value to the server, an authentication information transmitting step of obtaining the identifier of the terminal associated with the identifier of the connected car received by the server and transmitting the authentication value authentication information associated with the authentication value to the terminal, and a terminal authentication step of authenticating, by the server, access to the server using the authentication value authentication information received by the terminal.

Advantages of the Invention

[0012] According to the present invention, when providing a service of a connected car as an IoT device to a terminal, the terminal can be authenticated more securely.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Embodiments for Carrying Out the Invention

[0014] Hereinafter, Embodiments 1 and 2 of the present invention will be described by way of example. In any of the embodiments, a connected car capable of communicating with a server via a cellular line is used. The user (for example, the owner) of the connected car has a terminal (UE) such as a smartphone, and it is assumed that two communication line contracts are concluded regarding the terminal and the connected car.

[0015] The connected car continuously collects Bluetooth beacons and notifies the server, and the server transmits authentication information to a terminal registered in advance in association with the connected car that has received the beacon. Thereby, the server authenticates the terminal multiply using two communication lines, and provides a service safely with few operations.

[0016] [First Embodiment] In this embodiment, an authentication system provided with an authentication device different from the terminal of the user of the connected car will be described.

[0017] FIG. 1 is a diagram showing the functional configuration of the authentication system 1 in this embodiment. The authentication system 1 includes a server 10, an authentication device 20, a connected car 30, and a terminal 40.

[0018] The server 10 is an information processing device provided with a communication device and the like in addition to a control unit and a storage unit, and provides services related to the connected car 30 to the terminal 40. The control unit of server 10 includes a terminal registration unit 11, an authentication value transmission unit 12, an identifier reception unit 13, an authentication information transmission unit 14, and a terminal authentication unit 15. These functional units are realized by the control unit executing software stored in the storage unit.

[0019] The terminal registration unit 11 registers by associating the MSISDN as the identifier of the terminal 40 and the IMSI as the identifier of the connected car, that is, stores it in the storage unit. Note that the MSISDN is the phone number of the terminal 40, and the IMSI is the unique number recorded in the SIM / eSIM used by the connected car 30.

[0020] The authentication value transmission unit 12 transmits an authentication value (one-time password) to the authentication device 20.

[0021] The identifier reception unit 13 receives the IMSI of the connected car 30 from the connected car 30 together with the authentication value received by the connected car 30 via the authentication device 20.

[0022] The authentication information transmission unit 14 acquires the MSISDN of the terminal 40 associated with the received IMSI of the connected car 30, and transmits the authentication value authentication information associated with the authentication value to the terminal 40.

[0023] Here, the authentication value authentication information is data associated with the authentication value, such as the authentication value with a signature attached. The authentication value authentication information may be, for example, one in which the authentication value is stored in the body part (e.g., sub) of a JSON Web Token (JWT).

[0024] The terminal authentication unit 15 authenticates the access from the terminal 40 using the authentication value authentication information by comparing it with the authentication value.

[0025] The authentication device 20 is a device equipped with an authentication value transfer unit 21, is communicatively connected to the server 10, and is further capable of wireless broadcast communication to peripheral devices. The authentication value transfer unit 21 transfers the authentication value received from the server 10 to the peripheral devices by wireless broadcast communication. Specifically, for example, the authentication value is sent by a Bluetooth beacon.

[0026] The connected car 30 includes an authentication value reception unit 31 and an identifier transmission unit 32. The authentication value reception unit 31 scans the wireless broadcast communication from the authentication device 20 and receives the authentication value. The identifier transmission unit 32 transmits the IMSI of the connected car 30 to the server 10 via the cellular network together with the received authentication value.

[0027] The terminal 40 is a mobile terminal such as a smartphone, and includes an authentication information reception unit 41 and a server access unit 42. The authentication information reception unit 41 receives the authentication value authentication information from the server 10. The server access unit 42 accesses the server 10 using the received authentication value authentication information and uses a predetermined service.

[0028] For example, when the authentication device 20 is a beacon terminal such as a drive-through store, by causing the user's terminal 40 to place an order or the like using the authentication value authentication information, it can be more strongly authenticated that the user is actually at the location, at least that the user's car is at the location. Therefore, in the conventional method that does not go through the connected car, there were inconveniences such as unauthorized orders from unauthenticated terminals being possible or the process of identity verification for authentication being time-consuming. In this embodiment, the terminal 40 can be authenticated more safely and simply. Furthermore, since settlement is also possible by using the line contract of the connected car 30 specified by the IMSI and actually present at the location, the security is improved.

[0029] FIG. 2 is a sequence diagram showing the processing procedure of the authentication method in this embodiment. In step S1, the terminal 40 registers the association between the MSISDN of the terminal 40 and the IMSI of the connected car with the server 10.

[0030] Note that this registration process is performed in advance prior to the subsequent authentication procedure. Currently, the communication line is mainly based on a subscription contract, and it is considered that a similar contract is also made for the line used by the connected car 30 such as an autonomous vehicle. At this time, since the operator who concludes the line contract needs the user's contact information, it is very likely that the operator will request the user's phone number, that is, the MSISDN. In this case, the prior association registration is completed at the time of purchase / contract of the connected car 30.

[0031] In step S2, the server 10 sends an authentication value to the authentication device 20. In step S3, the authentication device 20 sends out the authentication value by means of a Bluetooth beacon, and the connected car 30 receives the authentication value by scanning the Bluetooth beacon.

[0032] In step S4, the connected car 30 sends the received authentication value together with the IMSI of the connected car 30 to the server 10. At this time, the connected car 30 sends all the received values of the Bluetooth beacon to the server 10 using carrier communication such as LTE. However, the same value may be omitted.

[0033] In step S5, the server 10 acquires the MSISDN of the terminal 40 associated with the received IMSI of the connected car, and sends the authentication value authentication information associated with the authentication value to the acquired MSISDN.

[0034] In step S6, the terminal 40 accesses the server 10 using the received authentication value authentication information, and after the server 10 authenticates the validity of the authentication value authentication information, the terminal 40 uses the service.

[0035] [Second Embodiment] In this embodiment, an authentication system will be described in which the terminal of the user of the connected car is also an authentication device.

[0036] FIG. 3 is a diagram showing the functional configuration of the authentication system 2 in this embodiment. The authentication system 1 includes a server 10, a connected car 30, and a terminal 40 (authentication device).

[0037] In this embodiment, a terminal 40 such as a smartphone is also used as the authentication device 20 of the first embodiment. That is, the terminal 40 further includes an authentication value transfer unit 21 in addition to an authentication information receiving unit 41 and a server access unit 42.

[0038] FIG. 4 is a sequence diagram showing the processing procedure of the authentication method in this embodiment. In step S11, the terminal 40 registers the association between the MSISDN of the terminal 40 and the IMSI of the connected car with the server 10.

[0039] In step S12, the server 10 transmits an authentication value to the terminal 40. In step S13, the terminal 40 sends out the authentication value by means of a Bluetooth beacon, and the connected car 30 receives the authentication value by scanning the Bluetooth beacon.

[0040] In step S14, the connected car 30 transmits the received authentication value together with the IMSI of the connected car 30 to the server 10. In step S15, the server 10 acquires the MSISDN of the terminal 40 associated with the received IMSI of the connected car, and transmits the authentication value authentication information associated with the authentication value to the acquired MSISDN.

[0041] In step S16, the terminal 40 accesses the server 10 using the received authentication value authentication information, and after the validity of the authentication value authentication information is authenticated by the server 10, the service is used.

[0042] Through this procedure, the server 10 can confirm that the terminal 40 is a terminal with a specific MSISDN and is near the connected car 30 having an IMSI line associated with this MSISDN, and allows only the subscriber on the car side to log in. Furthermore, the server 10 and the terminal 40 can confirm that the authentication value included in the authentication value authentication information is not an authentication value illegally transmitted to the connected car 30 by checking whether the authentication value is the one they themselves transmitted.

[0043] As a result, when the terminal 40 uses the service using the authentication value authentication information, it can be seen that the connected car 30 is nearby, the line subscriber is also the user of the terminal 40 and is trying to use the service of the connected car 30, so an effect similar to two-factor authentication can be obtained. Also, for the connected car 30, the pre-associated subscriber (terminal 40) is nearby and the authentication operation is performed. Therefore, the terminal 40 and the connected car 30 mutually use each other for two-factor authentication, the possibility of phishing for each other is very low, and it becomes possible to receive services regarding the IDs (MSISDN and IMSI) of both parties.

[0044] As described above, according to the foregoing embodiment, by performing authentication among three points (server 10, connected car 30, terminal 40) using the communication path of the connected car 30 through the procedure via the connected car 30, it can be used for two-way authentication with a single authentication procedure, and the labor of operation is reduced.

[0045] Here, the amount of data that can be notified by a Bluetooth beacon is only 27 bytes for the initial one and 251 bytes even for the latest one, and furthermore, since it is unidirectional and communication using public-key cryptography such as SSL cannot be performed, it has conventionally been used only for advertising purposes such as notifying the location of a store. On one hand, communication between the server 10 and the connected car 30 is performed via a carrier line such as LTE that is only available to the contractor. Therefore, if an identifier of the connected car 30 with a sufficient data length that is not externally exposed is used, it can have the same strength as a token. Also, although a Bluetooth beacon that can be easily eavesdropped is used between the authentication device and the connected car 30, the data sent is a one-time authentication value, and it is impossible to find out which terminal 40 it is for even if intercepted.

[0046] In this way, among IoT devices, devices such as autonomous vehicles that are expected to have a carrier line are considered to be difficult to implement complex functions like other IoT devices, but secure authentication becomes possible by utilizing the characteristic that the communication path is restricted.

[0047] In the above-described embodiment, a Bluetooth beacon is used to notify the authentication value from the authentication device to the connected car 30. However, the notification means is not limited to this, and for example, Bluetooth GATT communication may be used. By using wireless broadcast communication that does not require a pairing operation, the authentication value can be easily notified only at a proximity where a reception radio wave intensity of a certain level or more is obtained.

[0048] Note that according to the above-described embodiment, for example, since the authentication strength for IoT devices can be improved, it becomes possible to contribute to Goal 9 of the Sustainable Development Goals (SDGs) led by the United Nations, "Build resilient infrastructure, promote sustainable industrialization, and foster innovation."

[0049] As described above, the embodiments of the present invention have been explained, but the present invention is not limited to the above-described embodiments. Also, the effects described in the above-described embodiments are merely an enumeration of the most suitable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.

[0050] The authentication method by the authentication system (1 or 2) is realized by software. When it is realized by software, the program constituting this software is installed in an information processing apparatus (computer). Further, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a Web service via a network without being downloaded.

Explanation of Signs

[0051] 1, 2 Authentication system 10 Server 11 Terminal registration unit 12 Authentication value transmission unit 13 Identifier reception unit 14 Authentication information transmission unit 15 Terminal authentication unit 20 Authentication device 21 Authentication value transfer unit 30 Connected car 31 Authentication value reception unit 32 Identifier transmission unit 40 Terminal 41 Authentication information reception unit 42 Server access unit

Claims

1. A connected car, a terminal, a server that provides services related to the connected car to the terminal, and an authentication device, comprising: The server includes: A terminal registration unit that registers by associating an identifier of the terminal and an identifier of the connected car; An authentication value transmission unit that transmits an authentication value to the authentication device; An identifier reception unit that receives, from the connected car, the identifier of the connected car together with the authentication value received by the connected car via the authentication device; An authentication information transmission unit that acquires the identifier of the terminal associated with the received identifier of the connected car and transmits authentication value authentication information associated with the authentication value to the terminal; A terminal authentication unit that authenticates access from the terminal using the authentication value authentication information; The authentication device includes: An authentication value transfer unit that transfers the authentication value received from the server to peripheral devices by wireless broadcast communication; The connected car includes: An authentication value reception unit that scans the wireless broadcast communication and receives the authentication value; An identifier transmission unit that transmits the identifier of the connected car together with the received authentication value to the server; The terminal includes: An authentication information reception unit that receives the authentication value authentication information from the server; A server access unit that accesses the server using the received authentication value authentication information. An authentication system.

2. The identifier of the connected car is an IMSI, The authentication system according to claim 1, wherein the identifier of the terminal is an MSISDN.

3. The authentication system according to claim 1 or claim 2, wherein the authentication device is the terminal.

4. The authentication system according to claim 1 or claim 2, wherein the authentication value reception unit receives the authentication value from the authentication device by a Bluetooth beacon.

5. In an authentication system including a connected car, a terminal, a server that provides services related to the connected car to the terminal, and an authentication device, A terminal registration step in which the server registers by associating an identifier of the terminal and an identifier of the connected car; An authentication value transmission step of transmitting an authentication value from the server to the authentication device; An authentication value reception step in which the connected car receives the authentication value by scanning wireless broadcast communication from the authentication device to peripheral devices; An identifier transmission step of transmitting the identifier of the connected car together with the authentication value received by the connected car to the server; An authentication information transmission step of obtaining the identifier of the terminal associated with the identifier of the connected car received by the server and transmitting the authentication value authentication information associated with the authentication value to the terminal; A terminal authentication step in which the server authenticates access to the server by the terminal using the authentication value authentication information received by the terminal. The authentication method includes these steps.

Citation Information

Patent Citations

  • In-vehicle device control system

    JP2014215705A

  • System and method for managing vehicle

    JP2016206813A

  • A method of signing up a user for a service that controls at least one vehicle function on a user terminal

    JP2018508858A

  • Authentication system

    JP2021124845A