Wireless communication system and terminal authentication method

A dual authentication system in wireless communication systems addresses single-process failure issues by implementing a secondary authentication method, ensuring continuous communication functionality.

JP7738490B2Active Publication Date: 2025-09-12MITSUBISHI ELECTRIC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022003643
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-01-13
Publication Date
2025-09-12
Estimated Expiration
2042-01-13

AI Technical Summary

Technical Problem

Existing wireless communication systems face issues where a single authentication process failure prevents the authentication of wireless communication terminals, leading to communication disruptions.

Method used

A wireless communication system with a dual authentication process, utilizing both an authentication server and an authentication configuration to ensure continuous authentication even when the primary process fails.

Benefits of technology

Ensures uninterrupted communication by enabling a secondary authentication mechanism when the primary authentication with the server is unavailable, preventing communication disruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007738490000001
    Figure 0007738490000001
  • Figure 0007738490000002
    Figure 0007738490000002
  • Figure 0007738490000003
    Figure 0007738490000003
Patent Text Reader

Abstract

To suppress the occurrence of a situation in which a wireless communication terminal cannot be authenticated.SOLUTION: A wireless communication system 1000 includes an authentication server 301 used to perform first authentication processing for authenticating a wireless communication terminal 101 using wireless communication. The wireless communication system 1000 has an authentication configuration having a function of performing second authentication processing for authenticating the wireless communication terminal 101. If there is occurring a special situation in which the first authentication processing using the authentication server 301 cannot be performed, the wireless communication system 1000 performs the second authentication processing for authenticating the wireless communication terminal 101 using the authentication configuration.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a wireless communication system and a terminal authentication method that perform processing for authenticating a wireless communication terminal. [Background technology]

[0002] Wireless communication terminals used in wireless communication systems that require confidentiality and high communication continuity are used by an unspecified number of people who are authorized to use the wireless communication terminals within an organization. Furthermore, wireless communication terminals may be used by different people on different days. Therefore, in such wireless communication systems, wireless communication terminals are authenticated in order to be used.

[0003] In the above-described usage environment of a wireless communication terminal, authentication of the wireless communication terminal is performed using, for example, cryptographic techniques using an authentication server that communicates with an authentication device. The authentication device is, for example, a device owned by each different user. The authentication device is also, for example, a device distributed to each user by an organization. The authentication server is, for example, installed at the organization's headquarters. The cryptographic techniques are, for example, private key cryptography, public key cryptography, etc.

[0004] The main functions of the wireless communication system are voice communication and data communication. Authentication of a wireless communication terminal is a process performed to enable the wireless communication terminal to use voice communication, for example.

[0005] Patent Document 1 discloses a configuration (hereinafter also referred to as "related configuration A") in which an authentication process is performed to authenticate a wireless terminal as a wireless communication terminal using an authentication server. The authentication process is performed using wireless communication. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Patent No. 4705944 Summary of the Invention [Problem to be solved by the invention]

[0007] In the related configuration A, the number of types of authentication processes for authenticating a wireless communication terminal is one. Therefore, if a situation arises in which one type of authentication process cannot be performed, there is a problem in that a situation arises in which the wireless communication terminal cannot be authenticated.

[0008] The present disclosure has been made to solve such problems, and aims to provide a wireless communication system etc. that can prevent situations from occurring in which authentication of a wireless communication terminal cannot be performed. [Means for solving the problem]

[0009] In order to achieve the above-mentioned object, a wireless communication system according to one embodiment of the present disclosure comprises a wireless communication terminal having the function of performing wireless communication, and an authentication server used to perform a first authentication process to authenticate the wireless communication terminal using wireless communication, wherein the wireless communication terminal is a device that, when authenticated, is capable of performing specific communication with a communication terminal with which the wireless communication terminal is to communicate, the wireless communication system has an authentication configuration having the function of performing a second authentication process to authenticate the wireless communication terminal, and when a special situation occurs in which the first authentication process using the authentication server cannot be performed, the wireless communication system uses the authentication configuration to perform the second authentication process to authenticate the wireless communication terminal. [Effects of the Invention]

[0010] According to the present disclosure, a wireless communication system includes an authentication server used to perform a first authentication process to authenticate a wireless communication terminal using wireless communication. The wireless communication system has an authentication configuration having a function of performing a second authentication process to authenticate the wireless communication terminal. When a special situation occurs in which the first authentication process using the authentication server cannot be performed, the wireless communication system performs the second authentication process to authenticate the wireless communication terminal using the authentication configuration.

[0011] This makes it possible to prevent situations in which authentication of a wireless communication terminal cannot be performed. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a diagram illustrating a configuration of a wireless communication system according to a first embodiment. [Figure 2] FIG. 10 is a diagram illustrating a normal authentication control process. [Figure 3] FIG. 2 is a block diagram showing the configuration of a wireless communication terminal. [Figure 4] FIG. 2 is a block diagram showing a configuration of an authentication device. [Figure 5] FIG. 2 is a diagram for explaining an authentication control process A according to the first embodiment. [Figure 6] FIG. 10 is a diagram illustrating a configuration of a wireless communication system according to a second embodiment. [Figure 7] 1 is a block diagram showing a characteristic functional configuration of a wireless communication system. [Figure 8] FIG. 1 is a diagram illustrating an example of a hardware configuration of a wireless communication system. [Figure 9] FIG. 10 is a diagram illustrating another example of the hardware configuration of a wireless communication system. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments will be described with reference to the drawings. In the following drawings, the same components are assigned the same reference numerals. The names and functions of components assigned the same reference numerals are the same. Therefore, detailed descriptions of some of the components assigned the same reference numerals may be omitted.

[0014] <First Embodiment> (composition) FIG. 1 is a diagram showing a configuration of a wireless communication system 1000 according to a first embodiment. The wireless communication system 1000 is a system capable of performing, for example, press-to-talk communication. The press-to-talk communication is, for example, voice communication performed from one wireless communication terminal to multiple other wireless communication terminals. Voice communication is communication for making a call using voice (hereinafter also referred to as a "voice call"). Furthermore, the wireless communication system 1000 is a system that performs wireless communication using a time division multiple access method (i.e., a TDMA method).

[0015] The wireless communication system 1000 is not limited to a system capable of performing press-to-talk communication. The wireless communication system 1000 may be, for example, a system capable of performing communication with a communication terminal located outside the wireless communication system 1000 (hereinafter also referred to as an "external communication terminal").

[0016] The main functions of the wireless communication system 1000 are wide-area communication and direct communication. Wide-area communication is communication carried out in a wide area. Wide-area communication is communication carried out using, for example, a base station device 501 described below. Wide-area communication includes voice communication and data communication. Hereinafter, voice communication as wide-area communication will also be referred to as "wide-area voice communication." Also, hereinafter, data communication as wide-area communication will also be referred to as "wide-area data communication."

[0017] Direct communication is communication that takes place directly between multiple wireless communication terminals. Direct communication is performed by wireless communication. Direct communication includes voice communication and data communication. Hereinafter, voice communication as a form of direct communication will also be referred to as "direct voice communication." Also, hereinafter, data communication as a form of direct communication will also be referred to as "direct data communication."

[0018] As shown in FIG. 1, the wireless communication system 1000 includes communication units M10, M20, and M30, a base station device 501, a headquarters device 401, and an authentication server 301.

[0019] The communication unit M10 includes a wireless communication terminal 101 and an authentication device 201. The wireless communication terminal 101 has a function of performing wireless communication. The wireless communication is, for example, short-distance wireless communication, long-distance wireless communication, etc. The short-distance wireless communication is, for example, communication using a wireless LAN (Local Area Network), Bluetooth, etc. "Bluetooth" is a registered trademark. The long-distance wireless communication is wireless communication performed over a long distance. The long distance is, for example, a distance ranging from 1 km to 10 km. In other words, the wireless communication terminal 101 has a function of performing short-distance wireless communication and long-distance wireless communication as wireless communication.

[0020] The communication unit M10 may be an integrated unit of the wireless communication terminal 101 and the authentication device 201.

[0021] Each of the communication units M20 and M30 has a function of performing wireless communication with the wireless communication terminal 101.

[0022] The communication unit M20 includes a wireless communication terminal 102 and an authentication device 202. The communication unit M30 includes a wireless communication terminal 103 and an authentication device 203. Each of the wireless communication terminal 102 and the wireless communication terminal 103 has a function of performing wireless communication with the wireless communication terminal 101.

[0023] The communication unit M20 may be an integrated unit of the wireless communication terminal 102 and the authentication device 202. The communication unit M30 may be an integrated unit of the wireless communication terminal 103 and the authentication device 203.

[0024] Each of the communication units M10, M20, and M30 is a unit that can be carried by a user. For example, the wireless communication terminal 101 and the authentication device 201 included in the communication unit M10 are carried by the user as a pair.

[0025] The wireless communication terminals 101, 102, and 103 have the same configuration. Hereinafter, each of the wireless communication terminals 101, 102, and 103 will also be referred to as a "wireless communication terminal M1." The wireless communication terminal M1 is, for example, a transceiver having a function for performing press-to-talk communication as voice communication. Note that the wireless communication terminal M1 is not limited to a transceiver. The wireless communication terminal M1 may be, for example, a mobile phone.

[0026] As an example, three wireless communication terminals M1 are included in the wireless communication system 1000. Note that the number of wireless communication terminals M1 included in the wireless communication system 1000 is not limited to three, and may be two or four or more.

[0027] Each of the authentication devices 201, 202, and 203 has the same configuration. Hereinafter, each of the authentication devices 201, 202, and 203 will also be referred to as an "authentication device M2." The authentication device M2 is, for example, a smartphone. The authentication device M2 has a function of performing wireless communication. Furthermore, the authentication device M2 performs processing related to authentication of the wireless communication terminal M1.

[0028] The wireless communication terminal M1 and authentication device M2 included in each of the communication units M10, M20, and M30 have the function of performing communication A with each other. Communication A is wireless communication or wired communication. Wireless communication, which is communication A, is, for example, communication using Bluetooth. Wired communication, which is communication A, is communication using a communication cable. For example, the wireless communication terminal 101 included in the communication unit M10 has the function of communicating with the authentication device 201.

[0029] The wireless communication system 1000 performs a process for authenticating the wireless communication terminal M1. Hereinafter, the process for authenticating the wireless communication terminal M1 using wireless communication is also referred to as "authentication process Pr1." The wireless communication is, for example, the aforementioned short-range wireless communication or long-range wireless communication. Hereinafter, the process for authenticating the wireless communication terminal M1, which is different from the authentication process Pr1, is also referred to as "authentication process Pr2."

[0030] The wireless communication system 1000 performs an authentication process Pr1 or an authentication process Pr2 depending on the status of the wireless communication system 1000. Hereinafter, a configuration having a function of performing the authentication process Pr2 will also be referred to as an "authentication configuration Ca." The wireless communication system 1000 has an authentication configuration Ca.

[0031] The authentication configuration Ca is configured to use multiple communication units. In this embodiment, the authentication configuration Ca is configured to use communication units M20 and M30. The number of communication units used in the authentication configuration Ca is not limited to two, and may be three or more.

[0032] Hereinafter, the state of the wireless communication terminal M1 in a situation where the wireless communication terminal M1 is authenticated by the authentication process Pr1 or Pr2 will also be referred to as the “authenticated state.” Also, below, the state of the wireless communication terminal M1 in a situation where the wireless communication terminal M1 is not authenticated by the authentication process Pr1 or Pr2 will also be referred to as the “non-authenticated state.”

[0033] The wireless communication terminal M1 has a function of performing wireless communication. The wireless communication terminal M1 also has a function of performing the wide area communication and direct communication described above. Specifically, the wireless communication terminal M1 has a function of performing the wide area voice communication, wide area data communication, direct voice communication, and direct data communication described above. Hereinafter, the function of the wireless communication terminal M1 to perform direct data communication with another wireless communication terminal M1 using wireless communication is also referred to as a "direct communication function." The wireless communication terminal M1 has a direct communication function.

[0034] The wireless communication terminal M1 in the authenticated state can perform wide-area voice communication, wide-area data communication, direct voice communication, and direct data communication. On the other hand, the wireless communication terminal M1 in the unauthenticated state can only perform direct data communication. In other words, the wireless communication terminal M1 in the unauthenticated state cannot perform wide-area voice communication, wide-area data communication, or direct voice communication.

[0035] In this embodiment, as an example, a process for authenticating the wireless communication terminal 101, which is the wireless communication terminal M1, will be described. Hereinafter, wide-area voice communication, wide-area data communication, and direct voice communication will also be collectively referred to as "specific communication" or "specific communication." Each of wide-area voice communication and wide-area data communication is wide-area communication. Therefore, wide-area communication is specific communication. The function of performing specific communication is a main function of the wireless communication terminal M1.

[0036] A wireless communication terminal 101 in an authenticated state can perform specific communication and direct data communication. That is, a wireless communication terminal 101 in an authenticated state can use specific communication and direct data communication. On the other hand, a wireless communication terminal 101 in an unauthenticated state can only perform direct data communication. That is, a wireless communication terminal 101 in an unauthenticated state can only use direct data communication.

[0037] Hereinafter, the terminal with which wireless communication terminal 101 communicates will also be referred to as "communication terminal A." Communication terminal A is, for example, both or one of wireless communication terminal 102 and wireless communication terminal 103. Note that communication terminal A may be, for example, an external communication terminal that is a communication terminal that exists outside wireless communication system 1000. Communication terminal A may also be communication unit M20, M30, etc.

[0038] When the wireless communication terminal 101 is authenticated by the authentication process Pr1 or the authentication process Pr2, the state of the wireless communication terminal 101 becomes an authenticated state. Therefore, when the wireless communication terminal 101 is authenticated, the wireless communication terminal 101 is a device that can perform the above-mentioned specific communication with the communication terminal A.

[0039] The authentication server 301 has a function of performing wireless communication. The authentication server 301 is used to perform authentication process Pr1, which will be described in detail later. The authentication process Pr1 is a process that uses the authentication server 301. Each of the authentication devices 201, 202, and 203 has a function of performing wireless communication with the authentication server 301.

[0040] The base station device 501 is a communication device provided in a base station. The base station device 501 is a wireless transceiver having a function of performing long-distance wireless communication as wireless communication. The base station device 501 is installed, for example, on a mountain or on the roof of a high-rise building. The base station device 501 has a function of performing wireless communication with the wireless communication terminal 101.

[0041] Hereinafter, the communication area of ​​the authentication server 301 will also be referred to as "area Ar3." Area Ar3 is an area in which the authentication server 301 can communicate wirelessly with the authentication device M2. For example, if the authentication device 201 exists in area Ar3 of the authentication server 301, the authentication server 301 can communicate wirelessly with the authentication device 201. FIG. 1 shows a state in which the authentication devices 201, 202, and 203 exist in area Ar3 of the authentication server 301.

[0042] In the following, the communication area of ​​the base station device 501 will also be referred to as "area Ar5." Area Ar5 is an area in which the base station device 501 can perform wireless communication with the wireless communication terminal M1. For example, if the wireless communication terminal 101 is present in area Ar5 of the base station device 501, the base station device 501 can perform wireless communication with the wireless communication terminal 101. FIG. 1 shows a state in which the wireless communication terminals 101, 102, and 103 are present in area Ar5 of the base station device 501. Area Ar3 of the authentication server 301 is smaller than area Ar5 of the base station device 501.

[0043] In the following, the communication area of ​​the wireless communication terminal M1 will also be referred to as "area Ar1." Area Ar1 of the wireless communication terminal M1 is smaller than area Ar5 of the base station device 501. Area Ar1 is also smaller than area Ar3 of the authentication server 301. Area Ar1 exists within area Ar5. Area Ar1 also exists within area Ar3.

[0044] Area Ar1 is an area in which wireless communication terminal M1 can communicate wirelessly with other wireless communication terminals M1. For example, if wireless communication terminal 102 exists in area Ar1 of wireless communication terminal 101, wireless communication terminal 101 can communicate wirelessly with wireless communication terminal 102.

[0045] The base station device 501 is also connected to the headquarters device 401 via a communication cable C1. The communication cable C1 is, for example, an optical fiber cable, a coaxial cable, or the like. The base station device 501 communicates with the headquarters device 401 via the communication cable C1. That is, the base station device 501 communicates with the headquarters device 401 via a wired connection.

[0046] The headquarters device 401 communicates with the base station device 501 via a communication cable C1. The headquarters device 401 has a function of performing specific communication support processing. The specific communication support processing is processing that enables the wireless communication terminal M1 in an authenticated state to perform wide-area communication, which is specific communication. As described above, wide-area communication is communication that is performed using the base station device 501.

[0047] The wide-area communication is, for example, a press-to-talk communication as a wide-area voice communication. Here, in order to explain a specific example of the specific communication response processing, it is assumed that the wireless communication terminal 101 in an authenticated state performs a press-to-talk communication as a wide-area voice communication with the wireless communication terminals 102 and 103 as communication terminal A present in area Ar5.

[0048] In this case, in the specific communication response process, the headquarters device 401 performs a communication control process. The communication control process is a process for enabling the wireless communication terminal 101 to perform press-to-talk communication with the wireless communication terminals 102 and 103. In the communication control process, for example, a determination of the priority of the communication performed by each of the wireless communication terminals 102 and 103, a transfer of voice data for performing press-to-talk communication, etc. are performed.

[0049] The wide-area communication is not limited to press-to-talk communication as wide-area voice communication, and may be, for example, communication between an authenticated wireless communication terminal M1 and a communication terminal A that is located in an area Ar5 of the base station device 501 outside the area Ar1 of the wireless communication terminal M1.

[0050] Here, to explain a specific example of specific communication response processing, it is assumed that a wireless communication terminal 101 in an authenticated state performs wide-area voice communication, which is wide-area communication, with a wireless communication terminal 102 as communication terminal A, which is located in an area outside the area Ar1 of the wireless communication terminal 101, within the area Ar5 of the base station device 501.

[0051] In this case, in the specific communication response processing, the headquarters device 401 performs processing to transmit voice data to the wireless communication terminal 102 using the base station device 501, so that the wireless communication terminal 101 in an authenticated state can perform wide-area voice communication with the wireless communication terminal 102 as communication terminal A.

[0052] Here, it is assumed that the wireless communication terminal 101 transmits voice data for wide-area voice communication with the wireless communication terminal 102 to the headquarters device 401 via the base station device 501. In this case, in the specific communication response process, the headquarters device 401 performs a process for transmitting the received voice data to the wireless communication terminal 102 via the base station device 501.

[0053] The wireless communication system 1000 may be configured such that the wireless communication terminal M1 in an authenticated state can communicate with a communication terminal A that exists outside the wireless communication system 1000 as an external communication terminal (hereinafter also referred to as an "external communication configuration").

[0054] In the external communication configuration, the headquarters device 401 is connected to an external network (not shown) via a communication cable (not shown). The external network is, for example, the Internet. The external network in the external communication configuration can communicate with, for example, a communication terminal A serving as an external communication terminal located outside the wireless communication system 1000.

[0055] The wide area communication in the external communication configuration is, for example, communication between the wireless communication terminal M1 in an authenticated state and a communication terminal A as an external communication terminal that communicates with an external network via the base station device 501 and the headquarters device 401.

[0056] Here, in the external communication configuration, it is assumed that the wireless communication terminal M1 in an authenticated state performs wide-area voice communication, which is wide-area communication, with, for example, a communication terminal A as an external communication terminal. In this case, in the specific communication response process, the headquarters device 401 performs a process to transmit to the communication terminal A voice data for the wireless communication terminal M1 in an authenticated state to perform wide-area voice communication with the communication terminal A as an external communication terminal.

[0057] When the headquarters device 401 performs the specific communication handling process, the wireless communication terminal M1 in the authenticated state can perform wide-area communication, which is specific communication, with the communication terminal A.

[0058] Hereinafter, a state in which the wireless communication system 1000 is operating normally will also be referred to as a "normal state." In the normal state, the authentication device 201 can communicate wirelessly with the authentication server 301. Hereinafter, the process for authenticating the wireless communication terminal M1 in the normal state will also be referred to as a "normal authentication control process." Also, in the normal authentication control process, a communication path for authenticating the wireless communication terminal 101, which uses the authentication device 201 and the authentication server 301, will also be referred to as a "normal authentication path."

[0059] (Normal authentication control process) Next, a normal authentication control process for authenticating the wireless communication terminal 101, which is the wireless communication terminal M1, will be described with reference to Fig. 2. Fig. 2 is a diagram for explaining the normal authentication control process.

[0060] Hereinafter, a signal for starting authentication processing will also be referred to as an "authentication start signal." Also, below, information identifying wireless communication terminal M1 will also be referred to as "ID information J1." For example, if wireless communication terminal M1 is wireless communication terminal 101, ID information J1 is information that identifies wireless communication terminal 101. Wireless communication terminal 101 holds ID information J1.

[0061] In the following, information identifying the authentication device M2 will also be referred to as "ID information J2." For example, if the authentication device M2 is the authentication device 201, the ID information J2 is information identifying the authentication device 201. The authentication device 201 holds the ID information J2. Each of the ID information J1 and the ID information J2 is expressed, for example, by numbers, alphabets, etc.

[0062] Here, a description will be given of normal authentication control processing using the wireless communication terminal 101, the authentication device 201, and the authentication server 301. The normal authentication control processing is performed, for example, when the wireless communication terminal 101 is powered on.

[0063] In short, in the normal authentication control process, the authentication device 201 and the authentication server 301 perform a process to authenticate the wireless communication terminal 101. Only when the wireless communication terminal 101 is authenticated can the wireless communication terminal 101 use the specific communication described above. Before the normal authentication control process is performed, the wireless communication terminal 101 is in an unauthenticated state.

[0064] When the wireless communication terminal 101 and the authentication device 201 are powered on and the wireless communication terminal 101 and the authentication device 201 are started up, a normal authentication control process is performed.

[0065] Specifically, in the normal authentication control process, first, the authentication device 201 transmits an authentication start signal to the wireless communication terminal 101. Upon receiving the authentication start signal, the wireless communication terminal 101 in an unauthenticated state generates plaintext based on the authentication start signal.

[0066] The plaintext generated by the wireless communication terminal 101 changes randomly each time the plaintext is generated. That is, the content of the plaintext generated by the wireless communication terminal 101 is different each time the plaintext is generated.

[0067] Hereinafter, a signal including encrypted plaintext will also be referred to as an "encrypted signal." Also, below, the plaintext generated by the wireless communication terminal 101 will also be referred to as "plaintext Na." Also, below, the plaintext Na generated by the wireless communication terminal 101 will also be referred to as "original data."

[0068] The wireless communication terminal 101 transmits plaintext Na, which is the original data, to the authentication device 201. As a result, the authentication device 201 receives plaintext Na, which is the original data, from the wireless communication terminal 101. The authentication device 201 holds the received plaintext Na, which is the original data.

[0069] Furthermore, the authentication device 201 performs encryption processing on the plaintext Na, which is the received original data, based on the ID information J2 and the ID information J1, to generate an encrypted signal including the encrypted plaintext Na. When the encrypted plaintext Na is decrypted, a decryption processing, which will be described later, is performed. Each of the encryption processing and the decryption processing is processing that uses, for example, a secret key cryptosystem or a public key cryptosystem.

[0070] Specifically, in the encryption process, for example, the authentication device 201 encrypts the plaintext Na using the ID information J2 and the ID information J1 as a key, and then generates an encrypted signal including the encrypted plaintext Na.

[0071] The process of encrypting the plaintext Na in the encryption process is not limited to the above process. In the encryption process, for example, the authentication device 201 may encrypt the plaintext Na using the ID information J2 as a key.

[0072] Next, in the normal authentication control process, the normal authentication process is performed by the wireless communication system 1000. The normal authentication process is authentication process Pr1. As described above, authentication process Pr1 is a process for authenticating the wireless communication terminal M1 using wireless communication. The normal authentication process, which is authentication process Pr1, is a process performed in a situation where the wireless communication terminal 101 can communicate with the authentication server 301 via the authentication device 201.

[0073] In the normal authentication process, which is the authentication process Pr1, the authentication device 201 transmits an encrypted signal to the authentication server 301 by wireless communication.

[0074] Upon receiving the encrypted signal, the authentication server 301 performs a decryption process to decrypt the encrypted plaintext Na. In the decryption process, a key for decrypting the encrypted plaintext Na is used.

[0075] Next, the authentication server 301 performs a re-encryption process on the decrypted plaintext Na. The re-encryption process is a process using a secret key cryptosystem or a public key cryptosystem. In the re-encryption process, the authentication server 301 re-encrypts the plaintext Na using a different key. This different key is a key different from the key used by the authentication device 201 in the encryption process.

[0076] Then, the authentication server 301 generates an encrypted signal including the plaintext Na encrypted by the re-encryption process. The authentication server 301 transmits the generated encrypted signal to the authentication device 201 by wireless communication. As a result, the authentication device 201 receives the encrypted signal.

[0077] The authentication device 201 performs a decryption process to decrypt the encrypted plaintext Na included in the encrypted signal received from the authentication server 301. In the decryption process, a key for decrypting the encrypted plaintext Na is used.

[0078] As a result, the authentication device 201 obtains the plaintext Na from the encrypted signal received from the authentication server 301. Next, the authentication device 201 performs a comparison authentication process.

[0079] In the following, the plaintext Na obtained by the authentication device 201 from the encrypted signal received from the authentication server 301 is also referred to as "comparison data."

[0080] Next, in the normal authentication process, a comparison authentication process is performed. In the comparison authentication process, the authentication device 201 compares the comparison data with the original data. Specifically, the authentication device 201 determines whether the plain text Na as the comparison data is the same as the plain text Na as the original data.

[0081] If the plaintext Na as comparison data is the same as the plaintext Na as original data, the authentication device 201 determines that the authentication is successful. On the other hand, if the plaintext Na as comparison data is different from the plaintext Na as original data, the authentication device 201 determines that the authentication is unsuccessful. Hereinafter, a situation in which the plaintext Na as comparison data is different from the plaintext Na as original data is also referred to as an "authentication failure situation."

[0082] An authentication failure situation occurs, for example, when the key used by the authentication device 201 in the decryption process is different from another key used by the authentication server 301 in the re-encryption process.

[0083] Moreover, the authentication failure state occurs, for example, when the wireless communication state is poor. The wireless communication state is, for example, the state of wireless communication performed between the authentication device 201 and the authentication server 301. The wireless communication state is, for example, the state of wireless communication performed between the wireless communication terminal 101 and the authentication device 201.

[0084] Furthermore, an authentication failure state occurs when, for example, a part of the plaintext Na, which is the original data, is not transmitted to the authentication server 301 due to poor wireless communication conditions.

[0085] Next, the authentication device 201 generates authentication result information indicating whether the specific communication can be used. If the authentication is determined to be successful, the authentication device 201 generates authentication result information to enable the wireless communication terminal 101 to use the specific communication. The authentication result information indicates "usable."

[0086] If the authentication is determined to be unsuccessful, the authentication device 201 generates authentication result information that does not permit the wireless communication terminal 101 to use the specific communication. The authentication result information indicates "unusable."

[0087] Next, the authentication device 201 transmits the generated authentication result information to the wireless communication terminal 101 in the unauthenticated state by using the direct communication function.

[0088] When the wireless communication terminal 101 receives authentication result information indicating "enabled," the state of the wireless communication terminal 101 is set to an authenticated state. This enables the wireless communication terminal 101 to use specific communication. Specifically, the wireless communication terminal 101 becomes able to perform specific communication with communication terminal A. The specific communication is wide-area voice communication, wide-area data communication, direct voice communication, etc.

[0089] This completes the normal authentication process, and the normal authentication control process ends.

[0090] (Configuration of wireless communication terminal) Next, the configuration of the wireless communication terminal M1 will be described with reference to Fig. 3. Fig. 3 is a block diagram showing the configuration of the wireless communication terminal M1. The wireless communication terminal M1 includes an antenna 602, a changeover switch 603, a modulation unit 604, a demodulation unit 605, an antenna 606, a changeover switch 607, a modulation unit 608, a demodulation unit 609, a control unit 610, a plaintext generation unit 611, a storage unit 612, and a voice processing unit 613.

[0091] The antenna 602, the changeover switch 603, the modulation unit 604, and the demodulation unit 605 are used when the wireless communication terminal M1 communicates with the base station device 501. Hereinafter, the process by which the wireless communication terminal M1 transmits a signal to the base station device 501 by wireless communication is also referred to as "transmission process Pks." The transmission process Pks is, for example, a process for transmitting a modulated signal to the base station device 501 using the antenna 602.

[0092] In the following description, the process by which the wireless communication terminal M1 receives a signal transmitted by the base station device 501 via wireless communication is also referred to as “reception process Pkr.” The reception process Pkr is, for example, a process for receiving the signal transmitted by the base station device 501 using the antenna 602.

[0093] The antenna 606, the selector switch 607, the modulator 608, and the demodulator 609 are used when the wireless communication terminal M1 communicates with the authentication device M2. Hereinafter, the process by which the wireless communication terminal M1 transmits a signal to the authentication device M2 by wireless communication will also be referred to as a "transmission process Pds." The transmission process Pds is, for example, a process of transmitting a modulated signal to the authentication device M2 using the antenna 606.

[0094] In the following description, the process by which the wireless communication terminal M1 receives a signal transmitted by the authentication device M2 via wireless communication is also referred to as a “reception process Pdr.” The reception process Pdr is, for example, a process for receiving a signal transmitted by the authentication device M2 using the antenna 606.

[0095] The control unit 610 controls each unit in the wireless communication terminal M1. The control unit 610 controls the changeover switch 603 and the changeover switch 607, for example.

[0096] Each of the changeover switches 603 and 607 has a function of changing a signal transmission path. To perform either a transmission process Pks or a reception process Pkr, the changeover switch 603 changes the signal transmission path in accordance with the control of the control unit 610. To perform either a transmission process Pds or a reception process Pdr, the changeover switch 607 changes the signal transmission path in accordance with the control of the control unit 610.

[0097] The modulation unit 604 and the modulation unit 608 have a function of modulating a signal. In the transmission process Pks described above, a process is performed to transmit the signal modulated by the modulation unit 604 to the base station apparatus 501. In the transmission process Pds described above, a process is performed to transmit the signal modulated by the modulation unit 608 to the authentication device M2.

[0098] The demodulation unit 605 and the demodulation unit 609 have the function of demodulating signals. The demodulation unit 605 demodulates the signal received by the reception processing Pkr. The demodulation unit 605 transmits the demodulated signal to the control unit 610. The demodulation unit 609 demodulates the signal received by the reception processing Pdr. The demodulation unit 609 transmits the demodulated signal to the control unit 610.

[0099] The plaintext generation unit 611 has a function of generating plaintext. The memory unit 612 has a function of storing information. The memory unit 612 stores ID information J1. The ID information J1 stored in the memory unit 612 is information that can be changed from outside the wireless communication terminal M1. The audio processing unit 613 performs predetermined processing on the audio data. The audio processing unit 613 performs, for example, encoding of the audio data and decoding of the encoded audio data.

[0100] The configuration of the wireless communication terminal M1 is not limited to the configuration in Fig. 3. For example, the wireless communication terminal M1 may be provided with a component k having the function of performing both the transmission processing Pks and the reception processing Pkr. The component k is composed of, for example, a changeover switch 603, a modulation unit 604, and a demodulation unit 605.

[0101] Also, for example, the control unit 610 of the wireless communication terminal M1 may be configured to have the functions of the changeover switch 603, the modulation unit 604, the demodulation unit 605, the changeover switch 607, the modulation unit 608, and the demodulation unit 609. In this configuration, the control unit 610 can perform transmission processing Pks, reception processing Pkr, transmission processing Pds, and reception processing Pdr. In addition, in this configuration, it is not necessary to provide the changeover switch 603, the modulation unit 604, the demodulation unit 605, the changeover switch 607, the modulation unit 608, and the demodulation unit 609.

[0102] (Configuring Authentication Devices) Next, the configuration of the authentication device M2 will be described with reference to Fig. 4. Fig. 4 is a block diagram showing the configuration of the authentication device M2. The authentication device M2 includes an antenna 702, a changeover switch 703, a modulation unit 704, a demodulation unit 705, an antenna 706, a changeover switch 707, a modulation unit 708, a demodulation unit 709, a control unit 710, an authentication encryption unit 711, an authentication decryption unit 712, an authentication verification unit 713, and a storage unit 714.

[0103] The antenna 702, the changeover switch 703, the modulator 704, and the demodulator 705 are used when the authentication device M2 communicates with the authentication server 301. Hereinafter, the process by which the authentication device M2 transmits a signal to the authentication server 301 via wireless communication is also referred to as a "transmission process Pns." The transmission process Pns is, for example, a process for transmitting a modulated signal to the authentication server 301 using the antenna 702.

[0104] In the following description, the process by which the authentication device M2 receives a signal transmitted by the authentication server 301 via wireless communication is also referred to as a “reception process Pnr.” The reception process Pnr is, for example, a process for receiving a signal transmitted by the authentication server 301 using the antenna 702.

[0105] The antenna 706, the selector switch 707, the modulator 708, and the demodulator 709 are used when the authentication device M2 communicates with the wireless communication terminal M1. Hereinafter, the process by which the authentication device M2 transmits a signal to the wireless communication terminal M1 via wireless communication will also be referred to as a "transmission process Pms." The transmission process Pms is, for example, a process for transmitting a modulated signal to the wireless communication terminal M1 using the antenna 706.

[0106] In the following description, the process by which the authentication device M2 receives a signal transmitted by the wireless communication terminal M1 via wireless communication is also referred to as a “reception process Pmr.” The reception process Pmr is, for example, a process for receiving a signal transmitted by the wireless communication terminal M1 using the antenna 706.

[0107] The control unit 710 controls each unit in the authentication device M2, for example, the changeover switch 703 and the changeover switch 707.

[0108] Each of the changeover switches 703 and 707 has a function of changing a signal transmission path. To perform either the transmission processing Pns or the reception processing Pnr, the changeover switch 703 changes the signal transmission path in accordance with the control of the control unit 710. To perform either the transmission processing Pms or the reception processing Pmr, the changeover switch 707 changes the signal transmission path in accordance with the control of the control unit 710.

[0109] The modulation unit 704 and the modulation unit 708 have the function of modulating signals. In the transmission processing Pns described above, processing is performed to transmit the signal modulated by the modulation unit 704 to the authentication server 301. In the transmission processing Pms described above, processing is performed to transmit the signal modulated by the modulation unit 708 to the wireless communication terminal M1.

[0110] The demodulation unit 705 and the demodulation unit 709 have the function of demodulating signals. The demodulation unit 705 demodulates the signal received by the reception processing Pnr. The demodulation unit 705 transmits the demodulated signal to the control unit 710. The demodulation unit 709 demodulates the signal received by the reception processing Pmr. The demodulation unit 709 transmits the demodulated signal to the control unit 710.

[0111] The authentication encryption unit 711 has a function of encrypting data, the details of which will be described later.

[0112] The authentication decryption unit 712 has a function of performing a process of decrypting encrypted data, the details of which will be described later.

[0113] The authentication verification unit 713 has a function of performing processing related to authentication of the wireless communication terminal M1, the details of which will be described later.

[0114] The storage unit 714 has a function of storing information. The storage unit 714 stores ID information J2 and an authentication key in advance. The key is information used, for example, in encryption and decryption processes performed in the process of authenticating the wireless communication terminal M1. The ID information J2 and the key stored in the storage unit 714 are information that can be changed from outside the authentication device M2. The number of keys stored in the storage unit 714 is one or more.

[0115] The configuration of the authentication device M2 is not limited to that shown in Fig. 4. For example, the authentication device M2 may be provided with a component n having the function of performing both the transmission process Pns and the reception process Pnr. The component n is composed of, for example, a changeover switch 703, a modulation unit 704, and a demodulation unit 705.

[0116] Also, for example, the control unit 710 of the authentication device M2 may be configured to have the functions of the changeover switch 703, modulation unit 704, demodulation unit 705, changeover switch 707, modulation unit 708, and demodulation unit 709. In this configuration, the control unit 710 can perform transmission processing Pns and reception processing Pnr, and transmission processing Pms and reception processing Pmr. In addition, in this configuration, it is not necessary to provide the changeover switch 703, modulation unit 704, demodulation unit 705, changeover switch 707, modulation unit 708, and demodulation unit 709.

[0117] (Operation of wireless communication system) Next, the operation of the wireless communication system will be described. Hereinafter, a situation in which the authentication device 201 cannot communicate wirelessly with the authentication server 301 will also be referred to as a "special situation." A special situation is a situation in which the above-mentioned normal authentication process, which is the authentication process Pr1, cannot be performed. A special situation is a situation in which authentication of the wireless communication terminal M1 cannot be performed using a normal authentication path. A special situation occurs, for example, when a malfunction occurs in the communication-related configuration of the authentication server 301.

[0118] The authentication device 201 has a function to detect the occurrence of a special situation (hereinafter also referred to as a "health check function"). The health check function is a function to detect the occurrence of a special situation based on, for example, a drop in the received electric field level. The received electric field level is the level of radio waves received by the authentication device 201 from the authentication server 301.

[0119] The health check function may also be a function that detects the occurrence of a special situation by using, for example, a watchdog timer to monitor whether the authentication device 201 is performing wireless communication.

[0120] Hereinafter, a process that can authenticate the wireless communication terminal M1 in an unauthenticated state in a special situation is also referred to as an "authentication control process A." The authentication control process A is performed by the wireless communication system 1000. Each of the encryption process and decryption process performed in the authentication control process A is a process that uses, for example, a secret key cryptosystem or a public key cryptosystem.

[0121] Next, the authentication control process A will be described with reference to Fig. 5. Fig. 5 is a diagram for explaining the authentication control process A according to the first embodiment. To make an example of the authentication control process A easier to understand, the authentication control process A will be described under the following premise Pm1.

[0122] In the premise Pm1, processing is performed to authenticate the wireless communication terminal 101 in an unauthenticated state. In addition, in the premise Pm1, the wireless communication terminal 101, which is the wireless communication terminal M1, communicates with the authentication device 201, which is the authentication device M2. In addition, in the premise Pm1, it is assumed, as an example, that data is transmitted and received reliably in the communication between the wireless communication terminal 101 and the authentication device 201.

[0123] Also, in the premise Pm1, a special situation occurs. Also, in the premise Pm1, the authentication device 201 detects the occurrence of the special situation. Also, in the premise Pm1, the authentication device 201 holds ID information J2 that identifies the authentication device 201.

[0124] Furthermore, under the premise Pm1, the wireless communication terminal 102 and the wireless communication terminal 103 are present in the area Ar1 of the wireless communication terminal 101 in the unauthenticated state. That is, under the premise Pm1, the wireless communication terminal 101 in the unauthenticated state can perform wireless communication with the wireless communication terminal 102 and the wireless communication terminal 103. Therefore, under the premise Pm1, the communication units M20 and M30 can perform wireless communication with the wireless communication terminal 101.

[0125] The authentication control process A is performed after communication between the wireless communication terminal 101 in the unauthenticated state and the authentication device 201 becomes possible.

[0126] In the authentication control process A in the premise Pm1, first, the authentication device 201 transmits an authentication start signal 801 including ID information J2 to the wireless communication terminal 101.

[0127] In response to reception of the authentication start signal 801 by the wireless communication terminal 101, the plaintext generation unit 611 generates plaintext Na. The plaintext Na is, for example, a nonce. Hereinafter, the plaintext Na generated by the plaintext generation unit 611 will also be referred to as "original data."

[0128] The wireless communication terminal 101 transmits to the authentication device 201 an authentication response signal 802 including the plaintext Na, which is the original data.

[0129] As a result, the authentication device 201 receives the authentication response signal 802 and holds the plain text Na, which is the original data, included in the authentication response signal 802. The plain text Na, which is the original data, is stored in the storage unit 714.

[0130] Next, the authentication device 201 performs encryption processing on the received plaintext Na based on the ID information J2 and the ID information J1, thereby generating an encrypted signal. The encrypted signal includes the encrypted plaintext Na.

[0131] Specifically, in the encryption process, for example, the authentication encryption unit 711 of the authentication device 201 encrypts the plaintext Na using the ID information J2 and the ID information J1 as a key, and then generates an encrypted signal including the encrypted plaintext Na.

[0132] The process of encrypting the plaintext Na in the encryption process is not limited to the above process. In the encryption process, for example, the authentication encryption unit 711 may encrypt the plaintext Na using the ID information J2 as a key.

[0133] Hereinafter, the process of authenticating the wireless communication terminal M1 in an unauthenticated state using the authentication configuration Ca will also be referred to as a "collective authentication process." The collective authentication process is a process performed using a plurality of other wireless communication terminals M1. In this embodiment, the authentication configuration Ca is a configuration using the communication units M20 and M30. Also, below, a signal transmitted by the authentication device 201 when a special situation occurs will also be referred to as a "collective authentication execution signal 803." The collective authentication execution signal 803 is a signal for causing the wireless communication system 1000 to perform the collective authentication process.

[0134] In premise Pm1, the authentication device 201 detects the occurrence of a special situation. When a special situation occurs, the authentication device 201 transmits an encrypted signal including the encrypted plaintext Na to the wireless communication terminal 101 as a collective authentication execution signal 803. When the collective authentication execution signal 803 is transmitted to the wireless communication terminal 101, the wireless communication system 1000 performs collective authentication processing instead of normal authentication processing.

[0135] The collective authentication process is a process that is performed when a special situation occurs. The collective authentication process is authentication process Pr2 for authenticating the wireless communication terminal M1 in an unauthenticated state. The collective authentication process, which is authentication process Pr2, is a process that is performed in a situation where multiple communication units can perform wireless communication with the wireless communication terminal 101. The collective authentication process in premise Pm1 is a process that is performed in a situation where communication units M20 and M30 can perform wireless communication with the wireless communication terminal 101.

[0136] In the authentication control process A under the premise Pm1, when a special situation occurs, the wireless communication system 1000 uses the above-described authentication configuration Ca to perform collective authentication processing to authenticate the wireless communication terminal 101. The authentication configuration Ca is a configuration that uses communication units M20 and M30.

[0137] In the collective authentication process, which is authentication process Pr2, the wireless communication terminal 101, which has received the collective authentication execution signal 803 including the encrypted plaintext Na, recognizes that a special situation has occurred. As described above, the special situation is a situation in which the authentication device 201 cannot communicate wirelessly with the authentication server 301.

[0138] Furthermore, the wireless communication terminal 101 obtains the encrypted plaintext Na from the collective authentication execution signal 803 .

[0139] Under the premise Pm1, data is transmitted and received reliably in the communication between the wireless communication terminal 101 and the authentication device 201. Therefore, the encrypted plaintext Na that the wireless communication terminal 101 acquires from the collective authentication execution signal 803 is the original data.

[0140] Next, the wireless communication terminal 101 generates a collective authentication request signal 804 including encrypted plaintext Na. Under premise Pm1, the encrypted plaintext Na included in the collective authentication request signal 804 is the original data. The wireless communication terminal 101 uses the direct communication function to transmit the collective authentication request signal 804 to the wireless communication terminal 102 and the wireless communication terminal 103 that are present in area Ar1 of the wireless communication terminal 101.

[0141] In the collective authentication process, when each of the wireless communication terminal 102 and the wireless communication terminal 103 receives the collective authentication request signal 804, an authentication response process is performed. The authentication response process is performed in each of the communication units M20 and M30.

[0142] The authentication response process performed by the communication unit M20 is the same as the authentication response process performed by the communication unit M30. Here, the authentication response process performed by the communication unit M20 including the wireless communication terminal 102 will be described.

[0143] In the authentication process performed by the communication unit M20, the wireless communication terminal 102 receives a collective authentication request signal 804 including the encrypted plaintext Na and generates a collective authentication implementation request signal 806 including the encrypted plaintext Na. The wireless communication terminal 102 transmits the collective authentication implementation request signal 806 including the encrypted plaintext Na to the authentication device 202, which is the wireless communication terminal M1.

[0144] Next, the authentication device 202 receives the collective authentication execution request signal 806 and obtains the encrypted plaintext Na from the collective authentication execution request signal 806 .

[0145] Next, the authentication device 202 performs a decryption process to decrypt the encrypted plaintext Na. In the decryption process, a key for decrypting the encrypted plaintext Na is used.

[0146] Next, the authentication device 202 performs a re-encryption process on the decrypted plaintext Na. The re-encryption process is a process using a secret key cryptosystem or a public key cryptosystem. In the re-encryption process, the authentication encryption unit 711 of the authentication device 202 re-encrypts the plaintext Na using a different key. This different key is different from the key used by the authentication encryption unit 711 of the authentication device 201 in the encryption process described above.

[0147] Then, the authentication encryption unit 711 generates a group authentication execution response signal 807 including the plaintext Na encrypted by the re-encryption process.

[0148] The authentication device 202 transmits a collective authentication implementation response signal 807 to the wireless communication terminal 102 .

[0149] Upon receiving the collective authentication implementation response signal 807, the wireless communication terminal 102 acquires the encrypted plaintext Na included in the collective authentication implementation response signal 807. Next, the wireless communication terminal 102 generates a collective authentication response signal 805 including the encrypted plaintext Na. Then, the wireless communication terminal 102 transmits the collective authentication response signal 805 to the wireless communication terminal 101 using the direct communication function. This completes the authentication response process performed by the communication unit M20.

[0150] Furthermore, the authentication response process performed by the communication unit M30 is performed in the same manner as the authentication response process performed by the communication unit M20. As a result, the wireless communication terminal 103 of the communication unit M30 transmits a collective authentication response signal 805 to the wireless communication terminal 101 using the direct communication function.

[0151] The wireless communication terminal 101 receives two collective authentication response signals 805 from the wireless communication terminal 102 and the wireless communication terminal 103, respectively.

[0152] Next, the wireless communication terminal 101 transmits the two collective authentication response signals 805 as two collective authentication review request signals 808 to the authentication device 201. One of the two collective authentication review request signals 808 is the collective authentication response signal 805 transmitted by the wireless communication terminal 102. The other of the two collective authentication review request signals 808 is the collective authentication response signal 805 transmitted by the wireless communication terminal 103.

[0153] In response to reception of the two group authentication review request signals 808 by the authentication device 201, the authentication decryption unit 712 performs a decryption process to decrypt the encrypted plaintext Na included in each of the two group authentication review request signals 808. In the decryption process, a key for decrypting the encrypted plaintext Na is used.

[0154] As a result, the authentication decryption unit 712 acquires the two plaintexts Na as decrypted data. Hereinafter, the plaintexts Na as decrypted data acquired by the authentication decryption unit 712 will also be referred to as "comparison data."

[0155] Next, the authentication decryption unit 712 transmits the two plaintexts Na as comparison data to the authentication verification unit 713.

[0156] Next, a comparison authentication process is performed in the group authentication process. In the comparison authentication process, the authentication verification unit 713 compares the comparison data with the original data. Specifically, the authentication verification unit 713 determines whether each of the two plaintexts Na as the comparison data is the same as the plaintext Na as the original data.

[0157] If each of the two plaintexts Na as comparison data is the same as the plaintext Na as original data, the authentication verification unit 713 determines that the authentication is successful. In this case, the wireless communication terminal 101 is authenticated. The authentication verification unit 713 also generates a collective authentication verification response signal 809 indicating "usable" as authentication result information.

[0158] If one or both of the two plaintexts Na as comparison data differ from the plaintext Na as original data, the authentication verification unit 713 determines that the authentication has failed. In this case, the wireless communication terminal 101 has not been authenticated. The authentication verification unit 713 also generates a collective authentication verification response signal 809 indicating "unusable" as authentication result information.

[0159] Hereinafter, a situation in which one or both of the two plaintexts Na as comparison data differ from the plaintext Na as original data will also be referred to as an "authentication impossible situation." An authentication impossible situation occurs, for example, when the wireless communication state is poor. The wireless communication state is, for example, the state of wireless communication performed between the wireless communication terminal 101 and the wireless communication terminal 102.

[0160] Furthermore, an authentication failure state occurs when, for example, in a state where wireless communication is in a poor state, part of the plaintext Na, which is the original data transmitted by the collective authentication request signal 804, is not transmitted to the wireless communication terminal 102.

[0161] Furthermore, the authentication failure state occurs, for example, in a state where signal interception fails. The signal interception failure state is, for example, a state where an unauthorized key is used in a situation where an unauthorized wireless communication terminal 102 is used to intercept a signal transmitted by the wireless communication terminal 101. The unauthorized wireless communication terminal 102 is a terminal having the same configuration as the authorized wireless communication terminal 102. The unauthorized wireless communication terminal 102 is also a terminal created by a malicious party. The unauthorized key is a key different from the authorized key used in the collective authentication process described above.

[0162] Next, the authentication device 201 transmits a collective authentication verification response signal 809 as authentication result information to the wireless communication terminal 101 by using the direct communication function.

[0163] If the collective authentication verification response signal 809 received by the wireless communication terminal 101 as authentication result information indicates "available", the control unit 610 sets the state of the wireless communication terminal 101 to an authenticated state.

[0164] This enables the wireless communication terminal 101 to use the specific communication described above. Specifically, the wireless communication terminal 101 can perform the specific communication described above with communication terminal A. The specific communication is wide-area voice communication, wide-area data communication, direct voice communication, etc.

[0165] When the wireless communication terminal 101 in the authenticated state performs wide-area voice communication, which is specific communication, with, for example, communication terminal A, the headquarters device 401 performs the specific communication response process described above. By performing the specific communication response process, the wireless communication terminal 101 in the authenticated state can perform wide-area voice communication, which is specific communication.

[0166] Furthermore, for example, when a wireless communication terminal 102 serving as communication terminal A exists in area Ar1 of a wireless communication terminal 101 in an authenticated state, the wireless communication terminal 101 can directly perform voice communication with the wireless communication terminal 102.

[0167] On the other hand, if the collective authentication verification response signal 809 received by the wireless communication terminal 101 as authentication result information indicates "unusable", the state of the wireless communication terminal 101 remains unauthenticated. That is, the wireless communication terminal 101 in the unauthenticated state cannot perform specific communications such as wide-area voice communication, wide-area data communication, and direct voice communication.

[0168] Thus, the comparison authentication process is completed, the collective authentication process is completed, and the authentication control process A is completed.

[0169] (summary) As described above, according to this embodiment, the wireless communication system 1000 includes the authentication server 301 that is used to perform a first authentication process to authenticate the wireless communication terminal 101 using wireless communication. The wireless communication system 1000 has an authentication configuration that has a function of performing a second authentication process to authenticate the wireless communication terminal 101. When a special situation occurs in which the first authentication process using the authentication server 301 cannot be performed, the wireless communication system 1000 performs the second authentication process to authenticate the wireless communication terminal 101 using the authentication configuration.

[0170] This makes it possible to prevent situations in which authentication of a wireless communication terminal cannot be performed.

[0171] Furthermore, according to this embodiment, when a special situation occurs in which the wireless communication terminal 101 cannot be authenticated using a normal authentication path, a collective authentication process is performed instead of the normal authentication process to authenticate the wireless communication terminal 101. The collective authentication process is performed by the wireless communication terminal 101 communicating with the wireless communication terminals 102 and 103 that are present in the area Ar1 of the wireless communication terminal 101 using a direct communication function.

[0172] This makes it possible to prevent situations where the wireless communication terminal 101 cannot be authenticated. Furthermore, by authenticating the wireless communication terminal 101, the wireless communication terminal 101 becomes able to perform specific communication. In other words, the wireless communication terminal 101 becomes available for use in the wireless communication system 1000. Furthermore, encrypted data is used in the collective authentication process.

[0173] Therefore, it is possible to realize a wireless communication system that has high confidentiality and high communication continuity, and also to realize continuous operation of the wireless communication system.

[0174] Hereinafter, in the collective authentication process of the authentication control process A, the number of other wireless communication terminals M1 used to authenticate the wireless communication terminal 101 is also referred to as the "number for authentication." In this embodiment, the collective authentication process has been described using the wireless communication terminals 102 and 103 as the other wireless communication terminals M1. That is, the collective authentication process has been described in a situation where the number for authentication is two. Note that the number for authentication is not limited to two, and may be three or more.

[0175] The authentication number may be stored as a parameter in a storage unit of the authentication device M2, and may be configured to be changeable from outside the authentication device M2.

[0176] In the related configuration A, authentication processing is performed by communicating between a wireless terminal as a wireless communication terminal and an authentication server. In the related configuration A, if the wireless terminal is unable to communicate with the authentication server, a situation occurs in which the wireless terminal cannot be authenticated. If the wireless terminal is not authenticated, the main functions of the wireless terminal cannot be used.

[0177] Therefore, the wireless communication system 1000 of this embodiment has a configuration for achieving the above-mentioned effects, and therefore, the wireless communication system 1000 of this embodiment can solve the above-mentioned problems.

[0178] <Embodiment 2> (composition) Hereinafter, a situation in which no other wireless communication terminal M1 exists in the area Ar1 of the wireless communication terminal M1 will also be referred to as a "terminal absent situation." In a wireless communication system, special situations and terminal absent situations may occur. As described above, a special situation is a situation in which the authentication device 201 cannot perform wireless communication with the authentication server 301. Even in a special situation or a terminal absent situation, a configuration is required that can authenticate the wireless communication terminal M1 and that allows the wireless communication system to continue operating.

[0179] The configuration of this embodiment is a configuration that can authenticate the wireless communication terminal M1 even in special situations and terminal-non-existent situations.

[0180] Fig. 6 is a diagram showing the configuration of a wireless communication system 1000A according to embodiment 2. Wireless communication system 1000A differs from wireless communication system 1000 in Fig. 1 in that it does not include communication units M20 and M30 and that headquarters device 401 is connected to authentication server 301 via a communication cable. Other configurations of wireless communication system 1000A are the same as those of wireless communication system 1000, and therefore detailed description thereof will not be repeated.

[0181] As described above, the wireless communication system 1000A does not include the communication units M20 and M30. That is, the wireless communication system 1000A does not include the wireless communication terminals 102 and 103 and the authentication devices 202 and 203. The wireless communication system 1000A is a wireless communication system in the above-described terminal-absent state.

[0182] The headquarters device 401 is connected to the authentication server 301 via a communication cable C2. The communication cable C2 is, for example, an optical fiber cable, a coaxial cable, or the like. The headquarters device 401 communicates with the authentication server 301 via the communication cable C2. In other words, the headquarters device 401 communicates with the authentication server 301 via a wired connection.

[0183] The base station device 501 communicates with the headquarters device 401 via a communication cable C1. Therefore, the base station device 501 can communicate with the authentication server 301 via the headquarters device 401.

[0184] With the above configuration, the wireless communication system 1000A is further provided with an authentication path using the headquarters device 401 and the authentication server 301. This authentication path is a communication path for authenticating the wireless communication terminal M1.

[0185] Hereinafter, the process for authenticating the wireless communication terminal M1, which is different from the above-described authentication process Pr1, will also be referred to as “authentication process Pr2b.” The authentication process Pr2b of this embodiment is different from the authentication process Pr2 of the first embodiment.

[0186] The wireless communication system 1000A performs an authentication process Pr1 or an authentication process Pr2b depending on the status of the wireless communication system 1000A. Hereinafter, a configuration having a function of performing the authentication process Pr2b will also be referred to as an "authentication configuration Cb." The wireless communication system 1000A has an authentication configuration Cb. The authentication configuration Cb is a configuration that uses an authentication server 301.

[0187] Hereinafter, the state of the wireless communication terminal M1 in a situation where the wireless communication terminal M1 is authenticated by the authentication process Pr1 or Pr2b will also be referred to as the “authenticated state.” Also, below, the state of the wireless communication terminal M1 in a situation where the wireless communication terminal M1 is not authenticated by the authentication process Pr1 or Pr2b will also be referred to as the “non-authenticated state.”

[0188] As described above, the wireless communication terminal M1 in the authenticated state in the first embodiment is capable of performing wide-area voice communication, wide-area data communication, direct voice communication, and direct data communication. On the other hand, the wireless communication terminal M1 in the unauthenticated state in the first embodiment is capable of performing only direct data communication. In other words, the wireless communication terminal M1 in the unauthenticated state in the first embodiment cannot perform wide-area voice communication, wide-area data communication, or direct voice communication.

[0189] In this embodiment, the wireless communication terminal M1 in the unauthenticated state can perform wide-area data communication in addition to direct data communication. Therefore, in this embodiment, wide-area voice communication and direct voice communication are specific communications. In this embodiment, the description will be given on the assumption that the wireless communication terminal M1 in the unauthenticated state can perform wide-area data communication.

[0190] In this embodiment, as an example, a process for authenticating the wireless communication terminal 101, which is the wireless communication terminal M1, will be described.

[0191] Hereinafter, the terminal with which wireless communication terminal 101 communicates is also referred to as "communication terminal A." Communication terminal A is, for example, wireless communication terminals 102 and 103 that are not included in wireless communication system 1000A. Note that communication terminal A may also be, for example, an external communication terminal that is a communication terminal that exists outside wireless communication system 1000A.

[0192] When the wireless communication terminal 101 is authenticated by the authentication process Pr1 or the authentication process Pr2b, the state of the wireless communication terminal 101 becomes an authenticated state. Therefore, when the wireless communication terminal 101 is authenticated, the wireless communication terminal 101 is a device that can perform the above-mentioned specific communication with the communication terminal A.

[0193] Hereinafter, the process capable of authenticating the wireless communication terminal M1 in an unauthenticated state in a special situation where the authentication device 201 cannot communicate wirelessly with the authentication server 301 is also referred to as "authentication control process B." The authentication control process B is performed by the wireless communication system 1000A. Each of the encryption process and decryption process described below performed in the authentication control process B is a process using, for example, a secret key cryptosystem or a public key cryptosystem.

[0194] (Operation of wireless communication system) Next, the authentication control process B performed by the wireless communication system 1000A will be described with reference to Fig. 6. To make an example of the authentication control process B easier to understand, the authentication control process B will be described under the following premise Pm2.

[0195] In premise Pm2, processing is performed to authenticate the wireless communication terminal 101 in an unauthenticated state. In premise Pm2, the wireless communication terminal 101, which is wireless communication terminal M1, communicates with an authentication device 201, which is authentication device M2. In addition, in premise Pm2, it is assumed, as an example, that data is transmitted and received reliably in communication between the wireless communication terminal 101 and the authentication device 201.

[0196] Also, in premise Pm2, authentication control process B is performed in the wireless communication system 1000A in a terminal-absent state. The terminal-absent state in premise Pm2 is a state in which the wireless communication terminals 102 and 103 as other wireless communication terminals M1 are not present in the area Ar1 of the wireless communication terminal 101. Also, in premise Pm2, a special state occurs. Also, in premise Pm2, the authentication device 201 detects the occurrence of the special state.

[0197] In addition, in premise Pm2, the authentication device 201 holds ID information J2 that identifies the authentication device 201.

[0198] Furthermore, in premise Pm2, the wireless communication terminal 101 is present in area Ar5 of the base station device 501. Therefore, in premise Pm2, the base station device 501 can perform wireless communication with the wireless communication terminal 101. That is, in premise Pm2, the wireless communication terminal 101 can communicate with the authentication server 301 via the base station device 501 and the headquarters device 401.

[0199] The authentication control process B is performed after communication between the wireless communication terminal 101 in the unauthenticated state and the authentication device 201 becomes possible.

[0200] In the authentication control process B under the premise Pm2, first, the authentication device 201 transmits an authentication start signal including ID information J2 to the wireless communication terminal 101.

[0201] In response to reception of the authentication start signal by the wireless communication terminal 101, the plaintext generation unit 611 generates plaintext Na, which is the original data.

[0202] The wireless communication terminal 101 transmits to the authentication device 201 an authentication response signal including the plaintext Na, which is the original data.

[0203] As a result, the authentication device 201 receives the authentication response signal and holds the plaintext Na, which is the original data included in the authentication response signal. The plaintext Na, which is the original data, is stored in the storage unit 714.

[0204] Next, encryption processing is performed. In the encryption processing, for example, the authentication encryption unit 711 of the authentication device 201 encrypts the plaintext Na using the ID information J2 and the ID information J1 as a key. Then, the authentication encryption unit 711 generates an encrypted signal including the encrypted plaintext Na.

[0205] The process of encrypting the plaintext Na in the encryption process is not limited to the above process. In the encryption process, for example, the authentication encryption unit 711 may encrypt the plaintext Na using the ID information J2 as a key.

[0206] Hereinafter, the process for authenticating the unauthenticated wireless communication terminal M1 using the authentication configuration Cb is also referred to as the "wired authentication process." As described above, the authentication configuration Cb is a configuration that uses the authentication server 301. Also, below, the signal transmitted by the authentication device 201 when a special situation occurs is also referred to as the "wired authentication execution signal." The wired authentication execution signal is a signal that causes the wireless communication system 1000A to perform the wired authentication process.

[0207] In premise Pm2, the authentication device 201 detects the occurrence of a special situation in which the authentication device 201 cannot communicate wirelessly with the authentication server 301. When a special situation occurs, the authentication device 201 transmits an encrypted signal including encrypted plaintext Na to the wireless communication terminal 101 as a wired authentication execution signal. When the wired authentication execution signal is transmitted to the wireless communication terminal 101, the wireless communication system 1000A performs wired-use authentication processing instead of normal authentication processing. That is, in authentication control processing B in premise Pm2, the wireless communication system 1000A performs wired-use authentication processing.

[0208] The wired use authentication process is a process that is performed when a special situation occurs. The wired use authentication process is authentication process Pr2b for authenticating the wireless communication terminal M1 in an unauthenticated state. The wired use authentication process, which is authentication process Pr2b, is a process that is performed when the wireless communication terminal 101 is able to communicate with the authentication server 301 via the base station device 501 and the headquarters device 401.

[0209] In the authentication control process B under the premise Pm2, if a special situation occurs, the wireless communication system 1000A uses the above-mentioned authentication configuration Cb to perform wired authentication processing to authenticate the wireless communication terminal 101. The authentication configuration Cb is a configuration that uses the authentication server 301.

[0210] In the wired authentication process Pr2b, the wireless communication terminal 101 receives a wired authentication execution signal including encrypted plaintext Na and recognizes that a special situation has occurred. The wireless communication terminal 101 also obtains the encrypted plaintext Na from the wired authentication execution signal.

[0211] As described above, under the premise Pm2, data is transmitted and received reliably in the communication between the wireless communication terminal 101 and the authentication device 201. Therefore, the encrypted plaintext Na that the wireless communication terminal 101 acquires from the wired authentication execution signal is the original data.

[0212] Next, the wireless communication terminal 101 generates a wired authentication request signal including the encrypted plaintext Na. The destination of the wired authentication request signal is set to the authentication server 301. In addition, the header of the wired authentication request signal contains, for example, a string "terminal authentication request." The string "terminal authentication request" is a string that requests the authentication server 301 to perform processing for authenticating the wireless communication terminal.

[0213] In premise Pm1, the encrypted plaintext Na included in the wired authentication request signal is the original data. The wireless communication terminal 101 transmits the wired authentication request signal to the authentication server 301 via the base station device 501 and the headquarters device 401. Specifically, the wireless communication terminal 101 transmits the wired authentication request signal to the base station device 501 by wireless communication. The base station device 501 transmits the wired authentication request signal to the headquarters device 401. The headquarters device 401 transmits the wired authentication request signal to the authentication server 301.

[0214] Upon receiving the wired authentication request signal including the encrypted plaintext Na, the authentication server 301 acquires the encrypted plaintext Na from the wired authentication request signal.

[0215] Next, the authentication server 301 performs a decryption process to decrypt the encrypted plaintext Na. In the decryption process, a key for decrypting the encrypted plaintext Na is used.

[0216] Next, the authentication server 301 performs a re-encryption process on the decrypted plaintext Na. The re-encryption process is a process using a secret key cryptosystem or a public key cryptosystem. In the re-encryption process, the authentication server 301 re-encrypts the plaintext Na using a different key. This different key is different from the key used by the authentication encryption unit 711 of the authentication device 201 in the encryption process.

[0217] The authentication server 301 then generates a wired authentication response signal including the plaintext Na encrypted by the re-encryption process. The destination of the wired authentication response signal is set to the authentication device 201.

[0218] The authentication server 301 transmits a wired authentication response signal to the authentication device 201 via the headquarters device 401, the base station device 501, and the wireless communication terminal 101. Specifically, the authentication server 301 transmits the wired authentication response signal to the headquarters device 401. The headquarters device 401 transmits the wired authentication response signal to the base station device 501. The base station device 501 transmits the wired authentication response signal to the wireless communication terminal 101 by wireless communication. The wireless communication terminal 101 transmits the wired authentication response signal to the authentication device 201.

[0219] The authentication device 201 performs a decryption process to decrypt the encrypted plaintext Na included in the received wired authentication response signal. In the decryption process, a key for decrypting the encrypted plaintext Na is used.

[0220] As a result, the authentication device 201 obtains the plaintext Na as decrypted data from the received wired authentication response signal. Next, the authentication device 201 performs a comparison authentication process.

[0221] In the following, the plaintext Na as decrypted data obtained by the authentication device 201 from the wired authentication response signal received from the authentication server 301 is also referred to as "comparison data."

[0222] Next, in the wired authentication process, a comparison authentication process is performed. In the comparison authentication process, the authentication verification unit 713 compares the comparison data with the original data. Specifically, the authentication verification unit 713 determines whether the plain text Na as the comparison data is the same as the plain text Na as the original data.

[0223] If the plain text Na as the comparison data is the same as the plain text Na as the original data, the authentication verification unit 713 determines that the authentication is successful. In this case, the wireless communication terminal 101 is authenticated. The authentication verification unit 713 also generates an authentication verification response signal indicating "usable" as authentication result information.

[0224] If the plaintext Na as the comparison data is different from the plaintext Na as the original data, the authentication verification unit 713 determines that the authentication has failed. In this case, the wireless communication terminal 101 has not been authenticated. The authentication verification unit 713 also generates an authentication verification response signal indicating "unusable" as authentication result information.

[0225] Hereinafter, a situation in which the plaintext Na as comparison data differs from the plaintext Na as original data will also be referred to as an "authentication impossible situation." The authentication impossible situation occurs, for example, when the wireless communication state is poor. The wireless communication state is, for example, the state of wireless communication performed between the wireless communication terminal 101 and the base station device 501.

[0226] In addition, an authentication failure state occurs when, for example, in a state where wireless communication conditions are poor, part of the plaintext Na, which is the original data transmitted by the above-mentioned wired authentication request signal, is not transmitted to the base station device 501.

[0227] Next, the authentication device 201 transmits an authentication verification response signal as authentication result information to the wireless communication terminal 101 using the direct communication function.

[0228] If the authentication verification response signal received by the wireless communication terminal 101 as authentication result information indicates "usable", the control unit 610 sets the state of the wireless communication terminal 101 to an authenticated state.

[0229] This allows the wireless communication terminal 101 to use the specific communication described above. Specifically, the wireless communication terminal 101 can perform the specific communication described above with the communication terminal A.

[0230] On the other hand, if the authentication verification response signal received by the wireless communication terminal 101 as authentication result information indicates "unusable", the state of the wireless communication terminal 101 remains in the unauthenticated state.

[0231] Thus, the comparison authentication process ends, the wired use authentication process ends, and the authentication control process B ends.

[0232] (summary) As described above, according to this embodiment, the headquarters device 401 communicates with the authentication server 301 via the communication cable C2. That is, the headquarters device 401 communicates with the authentication server 301 by wire. Furthermore, in special situations and terminal-absent situations, wired authentication processing is performed to authenticate the wireless communication terminal 101. The wired authentication processing is performed using a communication path as an authentication path that uses the base station device 501, the headquarters device 401, and the authentication server 301.

[0233] Therefore, even in a terminal absence situation where the wireless communication terminals 102 and 103 as other wireless communication terminals M1 are not present in the area Ar1 of the wireless communication terminal 101, it is possible to authenticate the wireless communication terminal 101. Therefore, continuous operation of the wireless communication system can be realized more reliably than in the first embodiment.

[0234] (Function block diagram) Hereinafter, the wireless communication system according to the present technology will also be referred to as a “wireless communication system Hs1.” The wireless communication system Hs1 is either the wireless communication system 1000 or the wireless communication system 1000A.

[0235] Fig. 7 is a block diagram showing a characteristic functional configuration of the wireless communication system Hs1, that is, Fig. 7 is a block diagram showing main functions related to the present technology among the functions of the wireless communication system Hs1.

[0236] The wireless communication system Hs1 functionally comprises a wireless communication terminal BL1 and an authentication server BL2. The wireless communication terminal BL1 has a function of performing wireless communication. The wireless communication terminal BL1 corresponds to the wireless communication terminal 101.

[0237] The authentication server BL2 is used to perform a first authentication process for authenticating the wireless communication terminal BL1 using wireless communication. The authentication server BL2 corresponds to the authentication server 301.

[0238] The wireless communication terminal BL1 is a device that, when authenticated, is able to perform specific communication with a communication terminal that is a communication target of the wireless communication terminal BL1.

[0239] The wireless communication system Hs1 has an authentication configuration having a function of performing a second authentication process for authenticating the wireless communication terminal BL1.

[0240] If a special situation occurs in which the first authentication process cannot be performed using the authentication server BL2, the wireless communication system Hs1 uses the authentication configuration to perform the second authentication process to authenticate the wireless communication terminal BL1.

[0241] (Example of hardware configuration for wireless communication system) Hereinafter, the main functions related to the present technology that the wireless communication system Hs1 has will also be referred to as “main functions.” The wireless communication system Hs1 has the main functions.

[0242] 8 and 9 are diagrams each showing an example of the hardware configuration of the wireless communication system Hs1. The main functions of the wireless communication system Hs1 are realized by, for example, one processing circuit 70 shown in FIG.

[0243] When a special situation occurs in which the first authentication process using the authentication server cannot be performed, the processing circuit 70 uses the authentication configuration to perform the second authentication process for authenticating the wireless communication terminal.

[0244] The processing circuit 70 may be dedicated hardware. Alternatively, the processing circuit 70 may be configured using a processor that executes a program stored in a memory. The processor may be, for example, a CPU (Central Processing Unit), a central processing unit, an arithmetic unit, a microprocessor, a microcomputer, or a DSP (Digital Signal Processor).

[0245] Hereinafter, a situation in which the processing circuitry 70 is dedicated hardware will also be referred to as "situation St1." Also, below, a situation in which the processing circuitry 70 is configured using a processor will also be referred to as "situation St2."

[0246] In situation St1, the processing circuit 70 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.

[0247] 9 is a diagram illustrating an example of a hardware configuration of a wireless communication system Hs1 in a situation St2 in which the processing circuit 70 is configured using a processor. The configuration in FIG. 9 is a configuration in which the processing circuit 70 in FIG. 8 is realized by a processor 71 and a memory 72.

[0248] In situation St2, the main functions of the wireless communication system Hs1 are realized by software A. Software A is software or firmware. Software A may also be configured as a combination of software and firmware. Software A is written as a program and stored in memory 72.

[0249] In addition, in the situation St2, the processor 71 reads out and executes a program stored in the memory 72, thereby realizing the main functions of the wireless communication system Hs1. That is, the memory 72 stores the following programs:

[0250] This program is a program for causing the processor 71 to execute a process for performing a second authentication process to authenticate a wireless communication terminal using an authentication configuration when a special situation occurs in which it is not possible to perform a first authentication process using an authentication server.

[0251] The program also causes a computer to execute processes performed by the main functions of the wireless communication system Hs1, methods for executing the processes, and the like.

[0252] Here, the memory 72 is, for example, a non-volatile or volatile semiconductor memory such as a random access memory (RAM), a read only memory (ROM), a flash memory, an EPROM, or an EEPROM. The memory 72 is also, for example, a magnetic disk, a flexible disk, an optical disk, a compact disk, a minidisk, a DVD, or the like. The memory 72 may also be any storage medium that will be used in the future.

[0253] As described above, the wireless communication system Hs1 can realize the above-mentioned functions by the hardware or software A.

[0254] The present technology may also be realized as a terminal authentication method in which the operations of characteristic components of the wireless communication system Hs1 are performed as steps, or as a program that causes a computer to execute each step included in such a terminal authentication method.

[0255] Furthermore, the present technology may be realized as a computer-readable recording medium storing such a program. Furthermore, the program may be distributed via a transmission medium such as the Internet. The terminal authentication method according to the present technology corresponds to, for example, the authentication control process A of the first embodiment or the authentication control process B of the second embodiment.

[0256] (Other variations) It should be noted that the embodiments can be freely combined, and each embodiment can be modified or omitted as appropriate.

[0257] For example, the wireless communication system 1000 or the wireless communication system 1000A does not need to include all of the components shown in the figure. That is, the wireless communication system 1000 or the wireless communication system 1000A only needs to include the minimum number of components that can achieve the effects of the present technology.

[0258] Furthermore, for example, the keys used in the encryption process and re-encryption process performed in each of the normal authentication process, the authentication control process A, and the authentication control process B may be the same key.

[0259] Furthermore, for example, the encryption process, decryption process, and re-encryption process performed in each of the normal authentication process, authentication control process A, and authentication control process B are not limited to processes using a secret key cryptosystem or a public key cryptosystem. For example, each of the encryption process, decryption process, and re-encryption process may be a process that does not use a key.

[0260] Furthermore, for example, the base station device 501 is not limited to a wireless transceiver having a function of performing long-distance wireless communication, and may be, for example, a wireless LAN router. [Explanation of symbols]

[0261] 70 processing circuit, 71 processor, 72 memory, 101, 102, 103, BL1, M1 wireless communication terminal, 201, 202, 203, M2 authentication device, 301, BL2 authentication server, 401 headquarters device, 501 base station device, 1000, 1000A, Hs1 wireless communication system, M10, M20, M30 communication unit.

Claims

1. 1. A wireless communication system, comprising: a wireless communication terminal having a function of performing wireless communication; an authentication server used to perform a first authentication process for authenticating the wireless communication terminal using wireless communication; the wireless communication terminal is a device that, when the wireless communication terminal is authenticated, is capable of performing specific communication with a communication terminal that is a communication target of the wireless communication terminal; the wireless communication system has an authentication configuration having a function of performing a second authentication process for authenticating the wireless communication terminal; when a special situation occurs in which the first authentication process using the authentication server cannot be performed, the wireless communication system performs the second authentication process to authenticate the wireless communication terminal using the authentication configuration; The wireless communication system includes: further comprising a plurality of communication units each having a function of wirelessly communicating with the wireless communication terminal; the authentication configuration is a configuration using the plurality of communication units, the second authentication process is performed in a situation where the plurality of communication units are able to wirelessly communicate with the wireless communication terminal, the second authentication process includes a plurality of determination processes based on a plurality of response signals from the plurality of communication units; Wireless communication system.

2. The wireless communication system includes: further comprising an authentication device having a function of wirelessly communicating with the authentication server; the wireless communication terminal has a function of communicating with the authentication device, the first authentication process is a process that is performed in a situation where the wireless communication terminal is able to communicate with the authentication server via the authentication device, The special situation is a situation in which the authentication device cannot wirelessly communicate with the authentication server.

10. The wireless communication system of claim 1.

3. A wireless communication system, a wireless communication terminal having a function of performing wireless communication; an authentication server used to perform a first authentication process for authenticating the wireless communication terminal using wireless communication; the wireless communication terminal is a device that, when the wireless communication terminal is authenticated, is capable of performing specific communication with a communication terminal that is a communication target of the wireless communication terminal; the wireless communication system has an authentication configuration having a function of performing a second authentication process for authenticating the wireless communication terminal; when a special situation occurs in which the first authentication process using the authentication server cannot be performed, the wireless communication system performs the second authentication process to authenticate the wireless communication terminal using the authentication configuration; The wireless communication system includes: a base station device that performs wireless communication with the wireless communication terminal; a headquarters device that communicates with the base station device via a first communication cable; the headquarters device communicates with the authentication server via a second communication cable; the authentication configuration is a configuration using the authentication server, the second authentication process is performed in a situation where the wireless communication terminal is able to communicate with the authentication server via the base station device and the headquarters device; Wireless communication system.

4. The wireless communication system comprises: further comprising an authentication device having a function of wirelessly communicating with the authentication server; the wireless communication terminal has a function of communicating with the authentication device, the first authentication process is a process that is performed in a situation where the wireless communication terminal is able to communicate with the authentication server via the authentication device, The special situation is a situation in which the authentication device cannot wirelessly communicate with the authentication server.

4. The wireless communication system according to claim 3.

5. A terminal authentication method performed by a wireless communication system, The wireless communication system includes: a wireless communication terminal having a function of performing wireless communication; an authentication server used to perform a first authentication process for authenticating the wireless communication terminal using wireless communication; the wireless communication terminal is a device that, when the wireless communication terminal is authenticated, is capable of performing specific communication with a communication terminal that is a communication target of the wireless communication terminal; the wireless communication system has an authentication configuration having a function of performing a second authentication process for authenticating the wireless communication terminal; In the terminal authentication method, when a special situation occurs in which the first authentication process using the authentication server cannot be performed, the wireless communication system performs the second authentication process to authenticate the wireless communication terminal using the authentication configuration; The wireless communication system includes: a base station device that performs wireless communication with the wireless communication terminal; a headquarters device that communicates with the base station device via a first communication cable; the headquarters device communicates with the authentication server via a second communication cable; the authentication configuration is a configuration using the authentication server, the second authentication process is performed in a situation where the wireless communication terminal is able to communicate with the authentication server via the base station device and the headquarters device; Device authentication method.

Citation Information

Patent Citations

  • Radio communication system, and, authentication method

    JP2009111734A

  • Network system

    JP2012138863A

  • User authorization method for core network system including authorization device and service device

    JP2020017032A

  • Information processing system, information processing apparatus, method, and program

    JP2021026327A

  • Wireless communication system and authentication method

    JP4705944B2