Authentication device, authentication system, and program

The authentication device with SIM-based wired communication relays user data to build cost-effective and flexible non-public 5G networks, addressing resource strain and cost challenges while ensuring secure and adaptable communication.

JP7776693B1Active Publication Date: 2025-11-26SOFTBANK CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025124340
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-11-26
Estimated Expiration
2045-07-24

AI Technical Summary

Technical Problem

Existing systems face challenges in building non-public 5G networks without straining radio resources, incurring high construction and management costs, and lacking flexibility in QoS control and secure communication management.

Method used

An authentication device equipped with a SIM acquires and relays user data via wired communication, utilizing existing infrastructure and remote management to offload wireless communication, enabling cost-effective and flexible non-public network construction.

Benefits of technology

The solution alleviates radio resource strain, reduces construction and management costs, and allows flexible QoS control and secure communication management for non-public networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007776693000001_ABST
    Figure 0007776693000001_ABST
Patent Text Reader

Abstract

Provided is an authentication device equipped with a SIM (Subscriber Identity Module), the authentication device comprising: an acquisition unit that acquires authentication information stored in a SIM equipped in a user terminal; an authentication unit that uses the authentication information of the user terminal to perform authentication processing for the user terminal to access the mobile communication network via a wireless communication connection between the authentication device and a mobile communication network supported by the SIM of the authentication device; and a relay unit that relays communication of user data between the user terminal and a communication target of the user terminal via a wired communication connection between the authentication device and the mobile communication network.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system and a program. [Background technology]

[0002] Patent Document 1 describes a technique for supporting non-3GPP route switching in a multi-access session scenario. [Prior art document] [Patent documents] [Patent Document 1] Special Publication No. 2025-510955 Summary of the Invention [Means for solving the problem]

[0003] According to one embodiment of the present invention, there is provided an authentication device equipped with a SIM (Subscriber Identity Module). The authentication device may include an acquisition unit that acquires authentication information stored in a SIM equipped in a user terminal. The authentication device may include an authentication unit that executes authentication processing for the user terminal to access the mobile communication network using the authentication information of the user terminal via a wireless communication connection between the authentication device and a mobile communication network supported by the SIM of the authentication device. The authentication device may include a relay unit that relays communication of user data between the user terminal and a communication target of the user terminal via a wired communication connection between the authentication device and the mobile communication network.

[0004] In the authentication device, the authentication unit may perform the authentication process to enable the user terminal equipped with the SIM that is not compatible with the mobile communication network to access the mobile communication network.

[0005] In any of the authentication devices, the acquisition unit may further acquire communication status information indicating the communication status of the communication of the user data between the user terminal and the communication target via the wired communication connection, and the authentication device may further include a judgment unit that judges whether the communication status indicated by the communication status information satisfies a predetermined communication status condition, and the relay unit may relay the communication of the user data between the user terminal and the communication target via the wired communication connection if the judgment unit judges that the communication status satisfies the communication status condition, and may relay the communication of the user data between the user terminal and the communication target via the wireless communication connection if the judgment unit judges that the communication status does not satisfy the communication status condition.

[0006] In any of the authentication devices, the relay unit may relay the communication of user data between each of the plurality of user terminals and the communication target of each of the plurality of user terminals via the wired communication connection, the acquisition unit may acquire the communication status information of each of the plurality of user terminals, and the determination unit may determine whether the communication status indicated by the communication status information of each of the plurality of user terminals satisfies the communication status condition, and the authentication device may further include a selection unit that, when there is a user terminal whose communication status is determined by the determination unit to not satisfy the communication status condition, selects from the plurality of user terminals a user terminal that switches from communication of the user data via the wired communication connection to communication of the user data via the wireless communication connection based on predetermined selection conditions, and the relay unit may relay the communication of user data between the user terminal selected by the selection unit and the communication target via the wireless communication connection.

[0007] Any of the authentication devices may include a Trusted WLAN Interworking Function (TWIF).

[0008] Any of the authentication devices may further include a communication unit that communicates with a management device of an MNO (Mobile Network Operator) that manages the authentication device via the wireless communication connection.

[0009] In any of the authentication devices, the communication unit may receive an OAM (Operations, Administration, and Maintenance) signal from the management device instructing the relaying of the user data communication between the user terminal and the communication target to be switched from relaying via the wired communication connection to relaying via the wireless communication connection, and the relay unit may switch the relaying of the user data communication between the user terminal and the communication target from relaying via the wired communication connection to relaying via the wireless communication connection based on the OAM signal.

[0010] In any of the authentication devices, the acquisition unit may acquire the authentication information of the user terminal by receiving the authentication information of the user terminal via an access point that is connected to the authentication device via wired communication.

[0011] In any of the authentication devices, the acquisition unit may acquire the authentication information of the user terminal by receiving the authentication information of the user terminal via a direct communication connection between the user terminal and the authentication device.

[0012] Any of the authentication devices may be Customer Premises Equipment (CPE).

[0013] According to one embodiment of the present invention, there is provided an authentication system. The authentication system may include any one of the authentication devices described above. The authentication system may include an access point connected to the authentication device via wired communication. The authentication device may obtain the authentication information of the user terminal by receiving the authentication information of the user terminal via the access point.

[0014] According to one embodiment of the present invention, there is provided a program that, when executed by a computer, causes the computer to function as any one of the authentication devices.

[0015] The above summary of the invention does not list all of the necessary features of the present invention, and subcombinations of these features may also constitute inventions. [Brief explanation of the drawings]

[0016] [Figure 1] 1 shows an example of a system configuration of a system 10. [Figure 2] 1 is an explanatory diagram for explaining an example in which communication of user data is executed between a user terminal 300 and a communication target 400 in a related system. [Figure 3] FIG. 10 is an explanatory diagram for explaining an example in which communication of user data is executed between a user terminal 300 and a communication target 400 in another related system. [Figure 4] FIG. 10 is an explanatory diagram for explaining an example in which communication of user data is executed between a user terminal 300 and a communication target 400 in another related system. [Figure 5] 1 is an explanatory diagram for explaining an example of a case where communication of user data is executed between a user terminal 300 and a communication target 400 in the system 10. FIG. [Figure 6] FIG. 2 is an explanatory diagram for explaining an example of a processing flow of the system 10. [Figure 7] 2 shows an example of a functional configuration of the authentication device 100. [Figure 8] 2 shows an example of a functional configuration of a management device 500. [Figure 9] 2 is an explanatory diagram illustrating an example of a processing flow of the authentication device 100. FIG. [Figure 10] FIG. 10 is an explanatory diagram illustrating another example of the processing flow of the authentication device 100. [Figure 11]1 shows an example of a hardware configuration of a computer 1200 that functions as the authentication device 100 or the management device 500. DETAILED DESCRIPTION OF THE INVENTION

[0017] In recent years, there has been active development of technologies for building non-public networks compliant with 5G communication systems, such as local 5G (5th Generation) and private 5G, which have characteristics such as enhanced Mobile Broadband (eMBB), Ultra Reliable and Low Latency Communications (URLLC), and massive Machine Type Communications (mMTC). The main advantages of non-public networks compliant with 5G communication systems include the ability to cover areas not covered by public 5G, more secure communication compared to communications using unlicensed bands and public 5G, and less susceptibility to the surrounding network environment compared to public 5G. Non-public networks compliant with 5G communication systems, which have the aforementioned advantages, are often deployed in work sites such as factories and warehouses. However, there are concerns that the radio resources of the 5G communication system will be constrained if the radio resources of the 5G communication system are allocated to all communications on non-public networks compliant with the 5G communication system. Furthermore, if MNOs are required to build new infrastructure to perform OAM of non-public networks that comply with 5G communication systems, the costs required for building and managing non-public networks that comply with 5G communication systems will increase.

[0018] The system according to the present embodiment employs, for example, a mechanism in which a SIM is installed in an authentication device that performs authentication processing for accessing a mobile communication network. The authentication device acquires authentication information stored in a SIM installed in a user terminal (UE), and performs authentication processing for the UE to access the mobile communication network using the acquired UE authentication information via a wireless communication connection between the authentication device and a mobile communication network supported by the SIM of the authentication device. If the authentication device succeeds in the authentication processing, the authentication device relays user data communication between the UE and its communication target via a wired communication connection between the authentication device and the mobile communication network. This allows user data communication between the UE and its communication target, among communications of a non-public network compliant with a mobile communication system, to be offloaded to a wired communication line. Therefore, the system according to the present embodiment can build a non-public network compliant with a mobile communication system while alleviating concerns about straining the radio resources of the mobile communication system. In particular, the system according to the present embodiment employs, for example, a mechanism in which an MNO remotely manages an authentication device that is a CPE and has a TWIF. The authentication device receives an OAM signal from a management device owned by the MNO via the wireless communication connection, and relays user data communication between the UE and the UE's communication target based on the received OAM signal. This allows the MNO to perform OAM of the authentication device using existing infrastructure, so the system according to this embodiment can realize the construction and management of a non-public network compliant with a mobile communication system at low cost.

[0019] The present invention will be described below through embodiments of the invention, but the following embodiments do not limit the scope of the invention as claimed. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention. In the drawings, the same reference numerals are used to designate the same or similar parts, and redundant explanations may be omitted.

[0020] 1 shows an example of a system configuration of a system 10. The system 10 may include an authentication device 100. The system 10 may include an access point 200. The system 10 may include a management device 500.

[0021] The system 10 may provide various services. For example, the system 10 provides various services to corporations such as companies and local governments. The system 10 may also provide various services to individuals.

[0022] The system 10 provides a service of constructing a non-public network that conforms to a mobile communication system, for example. Note that a non-public network that conforms to a mobile communication system may also be referred to as a non-public network.

[0023] The mobile communication system is, for example, a 5G communication system. The mobile communication system may be a 6G (6th Generation) communication system or later. The mobile communication system may be a 3G (3rd Generation) communication system. The mobile communication system may be an LTE (Long Term Evolution) communication system. Here, an example in which the mobile communication system is a 5G communication system will be mainly described.

[0024] The C-Plane (Control Plane) of the mobile communication network 20 conforming to the 5G communication system may include an AMF (Access and Mobility Management Function), an AUSF (Authentication Server Function), and an SMF (Session Management Function), etc. The U-Plane (User Plane) of the mobile communication network 20 conforming to the 5G communication system may include a UPF (User Plane Function), etc.

[0025] For example, the system 10 provides a service for building a private 5G network that complies with the 5G communication system. The private 5G network is a non-public network that uses radio resources of a 5G communication system owned by an MNO. The system 10 may also provide a service for building a local 5G network that complies with the 5G communication system. The local 5G network is a non-public network that uses radio resources of a 5G communication system that is independently owned by a company other than the MNO, a local government, or the like.

[0026] The system 10 may provide, for example, a service for managing a non-public network, a service for managing a private 5G network compliant with a 5G communication system, or a service for managing a local 5G network compliant with a 5G communication system.

[0027] The system 10 provides, for example, a service that supports authentication for the user terminal 300 to access the mobile communication network 20. The system 10 may be an example of an authentication system.

[0028] The mobile communication network 20 may conform to a mobile communication system. The mobile communication network 20 includes, for example, a core network. The mobile communication network 20 includes, for example, a Radio Access Network (RAN). The mobile communication network 20 may be an example of an infrastructure of an MNO.

[0029] The user terminal 300 may be any communication terminal that can accommodate the SIM 320. The user terminal 300 may be, for example, a mobile phone such as a smartphone. The user terminal 300 may be a tablet terminal. The user terminal 300 may be a wearable terminal. The user terminal 300 may be a PC such as a laptop PC (Personal Computer) or a desktop PC. The user terminal 300 may be an IoT (Internet of Things) terminal. The user terminal 300 may include anything that falls under the IoE (Internet of Everything) category.

[0030] The SIM 320 corresponds to, for example, the mobile communication network 20. In this case, the user terminal 300 can access the mobile communication network 20 via the wireless communication connection 322 and the router 35 by establishing a wireless communication connection 322 between the user terminal 300 and the wireless base station 30. Note that the wireless base station 30 and the router 35 may each be an example of infrastructure of the MNO.

[0031] The SIM 320 may not be compatible with the mobile communication network 20. In this case, the user terminal 300 cannot access the mobile communication network 20 by establishing a wireless communication connection between the user terminal 300 and the wireless base station 30.

[0032] The SIM 320 is, for example, a SIM card or an embedded SIM (eSIM).

[0033] The authentication device 100 may perform an authentication process, for example, to access the mobile communication network 20.

[0034] The authentication device 100 is, for example, a CPE. A CPE is a communication device used in a mobile communication service and installed in a facility or premises of a subscriber of the mobile communication service. The inside of a facility or premises of a subscriber of the mobile communication service may be referred to as a customer premises, and the outside of a facility or premises of a subscriber of the mobile communication service may be referred to as an outside customer premises.

[0035] 1 shows an example in which the authentication device 100 is installed inside a building 50. The inside of the building 50 may be an example of a customer premises.

[0036] The authentication device 100 is equipped with, for example, a SIM 120 that is compatible with the mobile communication network 20. The SIM 120 may be a SIM card or an eSIM.

[0037] The authentication device 100, for example, executes an authentication process for the authentication device 100 to access the mobile communication network 20. The authentication device 100, for example, executes an authentication process for the authentication device 100 to access the mobile communication network 20, using authentication information of the authentication device 100 stored in the SIM 120. Note that the authentication process executed by the authentication device to access the mobile communication network 20 may be referred to as a direct authentication process.

[0038] The authentication device 100 executes, for example, an authentication process for a user terminal 300 on a customer premises to access the mobile communication network 20. Note that the authentication process executed by the authentication device for the user terminal 300 to access the mobile communication network 20 may be referred to as a proxy authentication process.

[0039] The authentication device 100, for example, acquires authentication information of the customer premises user terminal 300 stored in the SIM 320, and executes proxy authentication processing for the customer premises user terminal 300 using the acquired authentication information of the customer premises user terminal 300. The authentication device 100 acquires the authentication information of the customer premises user terminal 300 by, for example, receiving the authentication information of the customer premises user terminal 300 transmitted by the customer premises user terminal 300 via an access point 200 that is wired communication connected to the authentication device 100. Details of the authentication device 100 executing proxy authentication processing for the user terminal 300 will be described later.

[0040] The authentication device 100 has, for example, TWIF, which is a function for interworking between a WLAN (Wireless LAN) such as Wi-Fi (registered trademark), Bluetooth (registered trademark), and Zigbee (registered trademark) and the mobile communication network 20. A user terminal 300 on a customer premises equipped with a SIM 320 that is not compatible with the mobile communication network 20 can access the mobile communication network 20 via the authentication device 100 having TWIF.

[0041] When the authentication device 100 has TWIF, the authentication device 100 may perform direct authentication processing of the authentication device 100 or proxy authentication processing of the user terminal 300 on the customer premises in accordance with EAP-AKA (Extensible Authentication Protocol - Authentication and Key Agreement). EAP-AKA is a protocol used for authentication and key management in the mobile communication network 20.

[0042] The access point 200 communicatively connects a wired LAN (Local Area Network) and a wireless LAN. The access point 200 relays communication between the wired LAN and the wireless LAN, for example. The access point 200 is, for example, a TNAP (Trusted Network Access Point).

[0043] The access point 200 relays, for example, communication of a user terminal 300 in a customer premises. The access point 200 relays, for example, communication between a user terminal 300 in a customer premises and the authentication device 100.

[0044] The access point 200 relays communications of the user terminal 300 at the customer premises, for example, by establishing a direct communication connection 242 between the user terminal 300 at the customer premises and the access point 200. The direct communication connection 242 may be compliant with a direct communication method such as a Wi-Fi communication method, a Bluetooth communication method, or a Zigbee communication method.

[0045] The access point 200 is, for example, a CPE. In FIG. 2, an example in which the access point 200 is installed inside a building 50 is shown.

[0046] 1 shows an example in which the authentication device 100 and the access point 200 are different devices. However, the authentication device 100 and the access point 200 may be the same device. That is, the authentication device 100 may establish a direct communication connection between the authentication device 100 and the user terminal 300 on the customer premises, and receive authentication information of the user terminal 300 on the customer premises transmitted by the user terminal 300 on the customer premises via the established direct communication connection.

[0047] For example, if the authentication device 100 succeeds in the proxy authentication process for the user terminal 300 within the customer premises, the user terminal 300 within the customer premises can access the mobile communication network 20 via the access point 200 and the authentication device 100. Therefore, if the user terminal 300 within the customer premises is equipped with a function for establishing a direct communication connection 242 with the access point 200 and a SIM 320, the user terminal 300 within the customer premises can access the mobile communication network 20 via the access point 200 and the authentication device 100 without performing complicated setting processes. Here, the user terminal 300 within the customer premises accessing the mobile communication network 20 via the authentication device 100 may mean that the user terminal 300 within the customer premises accesses a non-public network.

[0048] The authentication device 100 relays, for example, communication of user data between a user terminal 300 on the customer premises and a communication target 400 of the user terminal 300 on the customer premises. The communication is, for example, communication via a mobile communication network 20. The communication is, for example, communication via the mobile communication network 20 and the Internet 40.

[0049] The communication target 400 may be any communication terminal that can communicate with the user terminal 300. The communication target 400 may be, for example, a server such as a web server or an application server. The communication target 400 may be a mobile phone such as a smartphone. The communication target 400 may be a tablet terminal. The communication target 400 may be a wearable terminal. The communication target 400 may be a PC. The communication target 400 may be an IoT terminal. The communication target 400 may include anything that corresponds to IoE.

[0050] The management device 500 manages the management targets. For example, the management device 500 remotely manages the management targets.

[0051] The management of the managed object may include operation management of the managed object. The management of the managed object may include maintenance management of the managed object. The management of the managed object may include upkeep management of the managed object. The management of the managed object may include monitoring of the managed object.

[0052] The management object of the management device 500 is, for example, the authentication device 100. The management object of the management device 500 is, for example, the mobile communication network 20.

[0053] The management device 500 manages the managed objects by, for example, transmitting a control signal to the managed objects. The management device 500 manages the managed objects by, for example, transmitting an OAM signal to the managed objects.

[0054] The management device 500 is owned by, for example, an MNO. In this case, the MNO may manage the authentication device 100. The management device 500 may be an example of an infrastructure of the MNO.

[0055] 1 shows an example in which the management device 500 is one device, but the management device 500 may be made up of multiple devices.

[0056] 2 is an explanatory diagram illustrating an example of a case where communication of user data is executed between a user terminal 300 and a communication target 400 in an associated system. Here, the associated system is assumed to be a system associated with the system 10.

[0057] The access point 600 is a CPE that connects a wired LAN and a wireless LAN for communication, and relays communication between the wired LAN and the wireless LAN, for example.

[0058] The access point 600 is equipped with, for example, a SIM 620 that is compatible with the mobile communication network 20. The SIM 620 may be a SIM card or an eSIM.

[0059] The access point 600 performs, for example, an authentication process for the access point 600 to access the mobile communication network 20. The access point 600 performs the authentication process using, for example, authentication information of the access point 600 stored in the SIM 620.

[0060] The access point 600 relays communications of, for example, the user terminal 300 at the customer premises. The access point 600 relays communications of, for example, the user terminal 300 at the customer premises by establishing a direct communications connection 642 between the user terminal 300 at the customer premises and the access point 600.

[0061] The access point 600 relays, for example, communication between a user terminal 300 in a customer premises and the radio base station 30. The access point 600 relays, for example, communication between a user terminal 300 in a customer premises and the radio base station 30 by establishing a wireless communication connection 622 between the access point 600 and the radio base station 30.

[0062] The access point 600 may function as a fixed wireless access (FWA). If the mobile communication network 20 complies with the 5G communication system, the access point 600 may function as a 5G residential gateway (RG).

[0063] The user terminal 300 at the customer premises may access the mobile communication network 20 via the access point 600. Here, the user terminal 300 at the customer premises accessing the mobile communication network 20 via the access point 600 may mean that the user terminal 300 at the customer premises accesses a non-public network.

[0064] The user terminal 300 at the customer premises communicates user data with the communication target 400, for example, via the access point 600 and the infrastructure of the MNO. If the user terminal 300 at the customer premises is equipped with a SIM 320 compatible with the mobile communication network 20, the user terminal 300 at the customer premises may communicate user data with the communication target 400 via a wireless communication connection 322 between the user terminal 300 at the customer premises and the radio base station 30 and the infrastructure of the MNO.

[0065] According to the related system shown in Figure 2, an access point 600 equipped with a SIM 620 is installed at a customer premises, which allows the related system shown in Figure 2 to provide access to a non-public network to a user terminal 300 at the customer premises without wiring a fixed line to the customer premises.

[0066] On the other hand, it is desirable to be able to build a non-public network without straining the radio resources of the mobile communication system. However, in the related system shown in Fig. 2, the radio resources of the mobile communication system compete for communication between the user terminal 300 on the customer premises via the non-public network, the user terminal 300 on the customer premises via the wireless communication connection 322, and the user terminal 300 outside the customer premises via the wireless communication connection 322. Therefore, in the related system shown in Fig. 2, there is a concern that building a non-public network will strain the radio resources of the mobile communication system.

[0067] It is also desirable to be able to flexibly control communications via a non-public network in accordance with QoS (Quality of Service) requirements and the like that may be applied to a user terminal 300 within a customer premises that accesses the non-public network. However, in the related system shown in Fig. 2, the smallest unit to which QoS requirements and the like can be applied is the access point 600, and QoS requirements and the like cannot be applied to each user terminal 300 within a customer premises that accesses the non-public network. Therefore, in the related system shown in Fig. 2, it is not possible to flexibly control communications via a non-public network in accordance with QoS requirements and the like that may be applied to a user terminal 300 within a customer premises that accesses the non-public network.

[0068] 3 is an explanatory diagram for explaining an example of a case where communication of user data is executed between a user terminal 300 and a communication target 400 in another related system. Here, the following mainly explains the points that are different from the case where communication of user data is executed between a user terminal 300 and a communication target 400 in the aforementioned related system.

[0069] The authentication device 700 is an infrastructure of the MNO that executes proxy authentication processing for the user terminal 300 on the customer premises. The authentication device 700 includes, for example, TWIF.

[0070] The authentication device 700 is, for example, connected by wired communication to the mobile communication network 20. The authentication device 700 is, for example, connected by wired communication to the mobile communication network 20 via a wired communication line 732 that connects the authentication device 700 to the router 35 and the CPE switch 800 by wired communication.

[0071] The authentication device 700 acquires, for example, authentication information of the customer premises user terminal 300 stored in the SIM 320. The authentication device 700 acquires the authentication information of the customer premises user terminal 300 by receiving the authentication information of the customer premises user terminal 300 transmitted by the customer premises user terminal 300 via the access point 200, which is a TNAP, and the CPE switch 800. The authentication device 700 may perform proxy authentication processing of the customer premises user terminal 300 using the acquired authentication information of the customer premises user terminal 300 via a wired communication connection between the authentication device 700 and the mobile communication network 20.

[0072] For example, the communication between the authentication device 700 and the CPE switch 800 is secure communication. This communication is, for example, communication compliant with IPsec (Internet Protocol Security). IPsec is a protocol for performing encrypted communication in a TCP / IP network that may include the mobile communication network 20 and the Internet 40.

[0073] For example, if the authentication device 700 succeeds in the proxy authentication process for the user terminal 300 at the customer premises, the user terminal 300 at the customer premises accesses the mobile communication network 20 via the access point 200 and the CPE switch 800. Here, the user terminal 300 at the customer premises accessing the mobile communication network 20 via the access point 200 and the CPE switch 800 may mean that the user terminal 300 at the customer premises accesses a non-public network.

[0074] The user terminal 300 at the customer premises communicates user data with the communication target 400 via, for example, the access point 200, the CPE switch 800, and the infrastructure of the MNO. If the user terminal 300 at the customer premises is equipped with a SIM 320 compatible with the mobile communication network 20, the user terminal 300 at the customer premises may communicate user data with the communication target 400 via a wireless communication connection 322 between the user terminal 300 at the customer premises and the radio base station 30 and the infrastructure of the MNO.

[0075] The CPE switch 800 is a switch installed on the customer premises. The CPE switch 800 is, for example, connected to the access point 200 via wired communication. The CPE switch 800 is, for example, connected to the router 35 and the authentication device 700 via wired communication.

[0076] According to the related system shown in Fig. 3, a CPE switch 800 is installed on the customer premises, and then a wired communication line 732, which is a single fixed line that communicatively connects the CPE switch 800 and the authentication device 700, which is an MNO infrastructure, is laid on the customer premises. As a result, communication of the user terminal 300 on the customer premises via the non-public network is communication via the wired communication line 732, and therefore, by constructing a non-public network, the related system shown in Fig. 3 does not strain the wireless resources of the mobile communication system.

[0077] Furthermore, according to the related system shown in Fig. 3, the authentication device 700 executes proxy authentication processing for each user terminal 300 on the customer premises that accesses the non-public network. This allows QoS requirements and the like to be applied to each user terminal 300 on the customer premises that accesses the non-public network, so the related system shown in Fig. 3 can flexibly control communications via the non-public network in accordance with the QoS requirements and the like that may be applied to the user terminal 300 on the customer premises that accesses the non-public network.

[0078] On the other hand, it is desirable to be able to build and manage a non-public network at low cost. However, in the related system shown in FIG. 3, the MNO must newly install an authentication device 700 as part of the MNO's infrastructure. In particular, since the authentication device 700 must perform proxy authentication processing for each of multiple user terminals 300 that may be located at multiple customer premises, the performance requirements for the authentication device 700 are extremely strict. Therefore, since the MNO must newly install an authentication device 700 with strict performance requirements, the related system shown in FIG. 3 increases the cost of building and managing the non-public network. Furthermore, in the related system shown in FIG. 3, in order to ensure secure communication over the non-public network, communication between the authentication device 700 and the CPE switch 800 must comply with a secure protocol such as IPsec. As a result, the cost of maintaining secure communication between the authentication device 700 and the CPE switch 800 is high, and therefore the related system shown in FIG. 3 increases the cost of building and managing the non-public network.

[0079] 4 is an explanatory diagram for explaining an example of a case where communication of user data is executed between a user terminal 300 and a communication target 400 in another related system. Here, the differences from the case where communication of user data is executed between a user terminal 300 and a communication target 400 in the related system described above will be mainly explained.

[0080] The authentication device 900 is a CPE that executes proxy authentication processing for the user terminal 300 on the customer premises. The authentication device 900 includes, for example, TWIF.

[0081] The authentication device 900 is, for example, connected by wired communication to the mobile communication network 20. The authentication device 900 is, for example, connected by wired communication to the mobile communication network 20 via a wired communication line 932 that connects the authentication device 900 and the router 35 by wired communication. The wired communication connection between the authentication device 900 and the mobile communication network 20 includes, for example, the wired communication line 932.

[0082] The authentication device 900 acquires, for example, authentication information of the customer premises user terminal 300 stored in the SIM 320. The authentication device 900 acquires the authentication information of the customer premises user terminal 300 by receiving the authentication information of the customer premises user terminal 300 transmitted by the customer premises user terminal 300 via the access point 200 that is connected to the authentication device 900 by wired communication and is a TNAP.

[0083] The authentication device 900 performs proxy authentication processing for the customer premises user terminal 300 using authentication information of the customer premises user terminal 300, for example, via a wired communication connection between the authentication device 900 and the mobile communication network 20. If the authentication device 900 succeeds in the proxy authentication processing for the customer premises user terminal 300, the customer premises user terminal 300 may access the mobile communication network 20 via the access point 200 and the authentication device 900. Here, the customer premises user terminal 300 accessing the mobile communication network 20 via the authentication device 900 may mean that the customer premises user terminal 300 accesses a non-public network.

[0084] The user terminal 300 at the customer premises communicates user data with the communication target 400 via, for example, the access point 200, the authentication device 900, and the infrastructure of the MNO. When the user terminal 300 at the customer premises is equipped with a SIM 320 compatible with the mobile communication network 20, the user terminal 300 at the customer premises may communicate user data with the communication target 400 via a wireless communication connection 322 between the user terminal 300 at the customer premises and the radio base station 30 and the infrastructure of the MNO.

[0085] The authentication device 900 receives, for example, an OAM signal transmitted by the management device 500. The authentication device 900 receives, for example, the OAM signal transmitted by the management device 500 via a wired communication connection between the authentication device 900 and the mobile communication network 20.

[0086] According to the related system shown in Fig. 4, an authentication device 900 is installed on the customer premises, and then a wired communication line 932, which is a single fixed line that communicatively connects the authentication device 900 and the mobile communication network 20, is laid on the customer premises. As a result, communication of the user terminal 300 on the customer premises via the non-public network is via the wired communication line 932, and therefore, by constructing a non-public network, the related system shown in Fig. 4 does not strain the wireless resources of the mobile communication system.

[0087] According to the related system shown in Fig. 4, the authentication device 900 executes proxy authentication processing for each user terminal 300 on the customer premises that accesses the non-public network. This allows QoS requirements and the like to be applied to each user terminal 300 on the customer premises that accesses the non-public network, so the related system shown in Fig. 4 can flexibly control communications via the non-public network in accordance with the QoS requirements and the like that may be applied to the user terminal 300 on the customer premises that accesses the non-public network.

[0088] According to the related system shown in FIG. 4, since the authentication device 900 is installed on the customer premises, the MNO does not need to build a new infrastructure to build and manage a non-public network. Therefore, the MNO can build and manage a non-public network by utilizing existing infrastructure. Furthermore, since the authentication device 900 only needs to perform proxy authentication processing for each of the multiple user terminals 300 that may be present on a single customer premises, the performance requirements for the authentication device 900 are relaxed compared to the performance requirements for the authentication device 700. As a result, the costs required for installing and managing the authentication device 900 are lower than the costs required for installing and managing the authentication device 700.

[0089] Furthermore, according to the related system shown in Fig. 4, authentication device 900 can be remotely managed using management device 500. As a result, the cost required to maintain secure communications over a non-public network in the related system shown in Fig. 4 is lower than the cost required to maintain secure communications over a non-public network in the related system shown in Fig. 3.

[0090] On the other hand, when the MNO remotely manages the authentication device, it is desirable for the MNO's operations that the communication line (sometimes referred to as the "data communication line") used for communication of user data between the user terminal and the communication target via a non-public network be separated from the communication line (sometimes referred to as the "authentication communication line") used for communication for the authentication device to perform authentication processing and the communication line (sometimes referred to as the "management communication line") used for communication for the authentication device to be managed by the management device. However, in the related system shown in FIG. 4, the data communication line, authentication communication line, and management communication line all include wired communication line 932, so the data communication line is not separated from the authentication communication line and the management communication line. If the data communication line were to be separated from the authentication communication line and the management communication line in the related system shown in FIG. 4, two fixed lines would have to be installed in the customer premises: a dedicated fixed line for the data communication line and a fixed line for the authentication communication line and the management communication line. This reduces the flexibility in the location where the authentication device 900 can be installed on the customer premises, and increases the cost of installing the authentication device 900 on the customer premises, so the related system shown in Figure 4 increases the cost of building and managing a non-public network.

[0091] 5 is an explanatory diagram for explaining an example of a case where communication of user data is executed between the user terminal 300 and the communication target 400 in the system 10. Here, the differences from the case where communication of user data is executed between the user terminal 300 and the communication target 400 in the related system described above will be mainly explained.

[0092] The authentication device 100 is, for example, connected by wired communication to the mobile communication network 20. The authentication device 100 is, for example, connected by wired communication to the mobile communication network 20 via a wired communication line 132 that connects the authentication device 100 and the router 35 by wired communication. The wired communication connection between the authentication device 100 and the mobile communication network 20 includes, for example, the wired communication line 132.

[0093] The authentication device 100 is, for example, wirelessly connected to the mobile communication network 20. The authentication device 100 is, for example, wirelessly connected to the mobile communication network 20 via the wireless communication connection 122 by establishing the wireless communication connection 122 between the authentication device 100 and the wireless base station 30. The wireless communication connection between the authentication device 100 and the mobile communication network 20 includes, for example, the wireless communication connection 122.

[0094] The wireless communication connection 122 may constitute a Wireless Access Backhaul (WAB), which may be a connection between the RAN and the core network.

[0095] The authentication device 100, for example, executes proxy authentication processing for the user terminal 300 within the customer premises. The authentication device 100 executes proxy authentication processing for the user terminal 300 within the customer premises, for example, using authentication information for the user terminal 300 within the customer premises stored in the SIM 320 via a wireless communication connection between the authentication device 100 and the mobile communication network 20. If the authentication device 100 succeeds in the proxy authentication processing for the user terminal 300 within the customer premises, the user terminal 300 within the customer premises may access the mobile communication network 20 via the access point 200 and the authentication device 100.

[0096] The user terminal 300 at the customer premises communicates user data with the communication target 400 via, for example, the access point 200, the authentication device 100, and the infrastructure of the MNO. When the user terminal 300 at the customer premises is equipped with a SIM 320 compatible with the mobile communication network 20, the user terminal 300 at the customer premises may communicate user data with the communication target 400 via a wireless communication connection 322 between the user terminal 300 at the customer premises and the radio base station 30 and the infrastructure of the MNO.

[0097] For example, the authentication device 100 receives an OAM signal transmitted by the management device 500. For example, the authentication device 100 receives the OAM signal transmitted by the management device 500 via a wireless communication connection between the authentication device 100 and the mobile communication network 20.

[0098] According to the system 10 of this embodiment, the authentication device 100 is installed within the customer premises, and then a wired communication line 132, which is a single fixed line used for communication of user data between the user terminal 300 within the customer premises and the communication target 400 via a non-public network, is laid within the customer premises. As a result, communication of user data between the user terminal 300 within the customer premises and the communication target 400 via a non-public network is communication via a wired communication connection between the authentication device 100 and the mobile communication network 20, so the system 10 of this embodiment does not strain the wireless resources of the mobile communication system due to communication of user data between the user terminal 300 within the customer premises and the communication target 400.

[0099] According to the system 10 of this embodiment, the authentication device 100 executes proxy authentication processing for each user terminal 300 on the customer premises that accesses the non-public network. This allows QoS requirements and the like to be applied to each user terminal 300 on the customer premises that accesses the non-public network, so the system 10 of this embodiment can flexibly control communications via the non-public network in accordance with the QoS requirements and the like that may be applied to the user terminal 300 on the customer premises that accesses the non-public network.

[0100] According to the system 10 of this embodiment, since the authentication device 100 is installed on the customer premises, the MNO does not need to build a new infrastructure to build and manage a non-public network. Therefore, the MNO can build and manage a non-public network by utilizing existing infrastructure. Furthermore, since the authentication device 100 only needs to perform proxy authentication processing for each of the multiple user terminals 300 that may be present on a single customer premises, the performance requirements for the authentication device 100 are relaxed compared to the performance requirements for the authentication device 700. As a result, the costs required for installing and managing the authentication device 100 are lower than the costs required for installing and managing the authentication device 700.

[0101] According to the system 10 of this embodiment, the authentication device 100 can be remotely managed using the management device 500. As a result, the cost required to maintain secure communications over a non-public network in the system 10 of this embodiment is lower than the cost required to maintain secure communications over a non-public network in the related system shown in FIG.

[0102] Furthermore, in the system 10 according to the present embodiment, the data communication line is a communication line including a wired communication line 132, and the authentication communication line and the management communication line are communication lines including a wireless communication connection 122. Therefore, in the system 10 according to the present embodiment, the data communication line is separated from the authentication communication line and the management communication line. Therefore, by installing a SIM 120 in the authentication device 100, the system 10 according to the present embodiment can separate the data communication line from the authentication communication line and the management communication line simply by wiring a single fixed line to the customer premises. In addition, the amount of wireless resources of the mobile communication system allocated to communications via the authentication communication line and communications via the management communication line is relatively small. As a result, the system 10 according to the present embodiment alleviates concerns about strain on wireless resources of the mobile communication system due to communications via the communication line and communications via the management communication line, while providing greater flexibility in the installation location of the authentication device within the customer premises and reducing the cost of installing the authentication device within the customer premises compared to the related system shown in FIG. 4 .

[0103] As described above, the system 10 according to the present embodiment can realize the construction and management of a non-public network at low cost while alleviating concerns about the shortage of radio resources in a mobile communication system. As a result, the system 10 according to the present embodiment can contribute to the spread of non-public networks.

[0104] 6 is an explanatory diagram for explaining an example of the processing flow of the system 10. Here, the description will be given assuming that the authentication device 100 is in a start state where it is not directly executing the authentication process.

[0105] The authentication device 100 and the access point 200 may be installed at the customer premises. Also, a user terminal 300 may be located at the customer premises.

[0106] The mobile communication network 20 may be compliant with a 5G communication system. In this case, the MNO may have at least the AMF 21, the AUSF 23, the SMF 25, the radio base station 30, and the UPF 32 as the MNO infrastructure.

[0107] In step (sometimes abbreviated as S) 102, authentication device 100 and UPF 32 share the Internet Protocol (IP) address of authentication device 100 and the IP address of UPF 32. For example, an engineer of mobile communication network 20 registers the IP address of authentication device 100 in UPF 32, whereby authentication device 100 and UPF 32 share the IP address of authentication device 100 and the IP address of UPF 32. For example, a worker in charge of installing authentication device 100 registers the IP address of UPF 32 in authentication device 100, whereby authentication device 100 and UPF 32 share the IP address of authentication device 100 and the IP address of UPF 32. Authentication device 100 and UPF 32 may share the IP address of authentication device 100 and the IP address of UPF 32 in any other manner.

[0108] In S104, the authentication device 100 and the wireless base station 30 execute an establishment process to establish a wireless communication connection 122 between the authentication device 100 and the wireless base station 30. For example, in response to the completion of installation of the authentication device 100 in the customer premises and the start of power supply to the authentication device 100, the authentication device 100 and the wireless base station 30 execute an establishment process to establish the wireless communication connection 122.

[0109] In S106, in response to the completion of the establishment process of S104, the authentication device 100 and the AUSF23 execute direct authentication processing of the authentication device 100 via the AMF21 using the authentication information of the authentication device 100 stored in the SIM120. For example, the authentication device 100 and the AMF21 communicate to execute the authentication processing. For example, the authentication device 100 and the AMF21 communicate to execute the authentication processing via the N1 interface. For example, the authentication device 100 and the AMF21 communicate to execute the authentication processing via the N2 interface. For example, the AMF21 and the AUSF23 communicate to execute the authentication processing. For example, the AMF21 and the AUSF23 communicate to execute the authentication processing via the N12 interface. Here, the description will continue assuming that the direct authentication processing of the authentication device 100 has been successful.

[0110] In S108, in response to the success of the direct authentication process of the authentication device 100 in S106, the authentication device 100 executes a registration process to register the registration information of the authentication device 100 in the AMF 21. The authentication device 100 executes the registration process, for example, via the N1 interface. The authentication device 100 executes the registration process, for example, via the N2 interface. The registration information may include identification information of the registration target, location information of the registration target, etc.

[0111] In S110, in response to the completion of the registration process of the authentication device 100 in S108, the authentication device 100 and the SMF 25 execute a process to establish a PDU (Protocol Data Unit) session for the authentication device 100. The authentication device 100 and the SMF 25 execute a process to establish a PDU session, for example, via the N1 interface. The authentication device 100 and the SMF 25 execute a process to establish a PDU session, for example, via the N2 interface. The authentication device 100 and the SMF 25 execute a process to establish a PDU session, for example, via the N11 interface.

[0112] In response to completion of the process of establishing a PDU session of authentication device 100 in S110, in S112, a PDU session of authentication device 100 is established between authentication device 100 and UPF 32. The PDU session of authentication device 100 established in S112 may be a PDU session via a wireless communication connection between authentication device 100 and mobile communication network 20.

[0113] In S114, the user terminal 300 transmits the authentication information of the user terminal 300 stored in the SIM 320 to the access point 200. In S116, the authentication device 100 receives, from the access point 200, the authentication information of the user terminal 300 transmitted by the user terminal 300 in S114.

[0114] In S114, the user terminal 300 may further transmit registration information of the user terminal 300. In S116, the authentication device 100 may further receive, from the access point 200, the registration information of the user terminal 300 transmitted by the user terminal 300 in S114.

[0115] In S118, the authentication device 100 and the AUSF 23 execute proxy authentication processing for the user terminal 300 via the AMF 21, using the authentication information of the user terminal 300 received by the authentication device 100 in S116. The authentication device 100 and the AUSF 23 execute proxy authentication processing for the user terminal 300, for example, via the PDU session of the authentication device 100 established between the authentication device 100 and the UPF 32 in S112 and the AMF 21. Here, the description will continue assuming that the proxy authentication processing for the user terminal 300 has been successful.

[0116] In S120, in response to the success of the proxy authentication process of the user terminal 300 in S118, the authentication device 100 executes a registration process to register the registration information of the user terminal 300 in the AMF 21. The authentication device 100 executes the registration process to register the registration information of the user terminal 300 in the AMF 21, for example, via the PDU session of the authentication device 100 established between the authentication device 100 and the UPF 32 in S112.

[0117] In S122, in response to the completion of the registration process of the user terminal 300 in S120, the authentication device 100 and the SMF 25 execute the process of establishing a PDU session of the user terminal 300. For example, the authentication device 100 and the SMF 25 execute the process of establishing a PDU session of the user terminal 300 via the PDU session of the authentication device 100 established between the authentication device 100 and the UPF 32 in S112.

[0118] Upon completion of the process of establishing the PDU session of the user terminal 300 in S122, in S124, a PDU session of the user terminal 300 is established between the authentication device 100 and the UPF 32. The PDU session of the user terminal 300 established in S124 is a PDU session via a wired communication connection between the authentication device 100 and the mobile communication network 20. Thereafter, the user terminal 300 performs communication of user data with the communication target 400 via the access point 200, the authentication device 100, the wired communication line 132, the N3 interface, and the N6 interface.

[0119] 7 shows an example of the functional configuration of the authentication device 100. The authentication device 100 may include a storage unit 102, an acquisition unit 104, an establishment unit 106, an authentication unit 108, a registration unit 112, a relay unit 114, a determination unit 116, a selection unit 118, and a communication unit 124. Note that it is not essential that the authentication device 100 include all of these components.

[0120] The storage unit 102 stores various types of information. For example, the storage unit 102 stores registration information of the authentication device 100. For example, the storage unit 102 stores IP address information indicating the IP address of the authentication device 100. For example, the storage unit 102 stores IP address information indicating the IP address of the UPF 32.

[0121] The acquisition unit 104 acquires various information. The acquisition unit 104 acquires the various information by, for example, receiving the various information. The acquisition unit 104 receives the various information, for example, via the mobile communication network 20. The acquisition unit 104 receives the various information, for example, via the wireless communication connection 122. The acquisition unit 104 receives the various information, for example, via the wired communication line 132. The acquisition unit 104 receives the various information, for example, via the access point 200. The acquisition unit 104 receives the various information, for example, via the Internet 40. The acquisition unit 104 may acquire the various information by an input unit included in the authentication device 100 accepting input of the various information. The acquisition unit 104 may acquire the various information by a measurement unit included in the authentication device 100 measuring the various information. The acquisition unit 104 may store the acquired various information in the storage unit 102.

[0122] The acquisition unit 104 acquires various information from, for example, the access point 200. The acquisition unit 104 acquires various information from, for example, the user terminal 300. The acquisition unit 104 acquires various information from, for example, the communication target 400. The acquisition unit 104 may acquire various information from any other external device.

[0123] The acquiring unit 104 acquires, for example, authentication information stored in the SIM 320 installed in the user terminal 300. The acquiring unit 104 acquires the authentication information of the user terminal 300, for example, by receiving the authentication information of the user terminal 300 via the access point 200. The acquiring unit 104 acquires the authentication information of the user terminal 300, for example, by receiving the authentication information of the user terminal 300 via a direct communication connection between the user terminal 300 and the authentication device 100.

[0124] The establishing unit 106 executes the establishment process based on, for example, various pieces of information stored in the storage unit 102. The establishing unit 106 executes the establishment process based on, for example, various pieces of information acquired by the acquiring unit 104.

[0125] The establishing unit 106 executes, for example, an establishment process to establish a wireless communication connection 122 between the authentication device 100 and the wireless base station 30. Upon completion of the establishment process of the wireless communication connection 122, the establishing unit 106 may register, in the storage unit 102, base station information indicating the wireless base station 30 that has established the wireless communication connection 122 with the authentication device 100.

[0126] The authentication unit 108 performs authentication processing in accordance with, for example, EAP-AKA.

[0127] The authentication unit 108 executes the authentication process based on, for example, various pieces of information stored in the storage unit 102. The authentication unit 108 executes the authentication process based on, for example, various pieces of information acquired by the acquisition unit 104.

[0128] The authentication unit 108 performs authentication processing, for example, via a wireless communication connection between the authentication device 100 and the mobile communication network 20. The authentication unit 108 performs authentication processing of the authentication device 100, for example, via the wireless communication connection 122, the wireless base station 30, the router 35, and the mobile communication network 20.

[0129] The authentication unit 108 executes direct authentication processing of the authentication device 100, for example, by using authentication information of the authentication device 100 stored in the SIM 120. The authentication unit 108 executes direct authentication processing of the authentication device 100 by using the authentication information of the authentication device 100, for example, in response to completion of establishment processing of the wireless communication connection 122 by the establishment unit 106.

[0130] The registration unit 112 executes the registration process via a wireless communication connection between the authentication device 100 and the mobile communication network 20, for example.

[0131] The registration unit 112 executes the registration process based on, for example, various pieces of information stored in the storage unit 102. The registration unit 112 executes the registration process based on, for example, various pieces of information acquired by the acquisition unit 104.

[0132] The registration unit 112, for example, executes a registration process for registering registration information of the authentication device 100. The registration unit 112 executes the registration process for the registration information of the authentication device 100 in response to, for example, the authentication unit 108 succeeding in the direct authentication process of the authentication device 100.

[0133] The establishment unit 106, for example, executes a process for establishing a PDU session. The establishment unit 106, for example, executes a process for establishing a PDU session via a wireless communication connection between the authentication device 100 and the mobile communication network 20.

[0134] The establishment unit 106, for example, executes a process for establishing a PDU session of the authentication device 100. The establishment unit 106, for example, executes a process for establishing a PDU session of the authentication device 100 in response to completion of a process for registering the registration information of the authentication device 100 by the registration unit 112. The establishment unit 106 may register session information indicating the PDU session of the authentication device 100 in the storage unit 102 in response to completion of the process for establishing a PDU session of the authentication device 100.

[0135] The authentication unit 108, for example, executes proxy authentication processing for the user terminal 300. The authentication unit 108 executes proxy authentication processing for the user terminal 300, for example, using authentication information of the user terminal 300.

[0136] The authentication unit 108 executes proxy authentication processing for, for example, a user terminal 300 equipped with a SIM 320 that is not compatible with the mobile communication network 20. The authentication unit 108 executes proxy authentication processing for, for example, a user terminal 300 equipped with a SIM 320 that is compatible with the mobile communication network 20.

[0137] The acquiring unit 104 acquires, for example, the registration information of the user terminal 300. The acquiring unit 104 may acquire the registration information of the user terminal 300 in the same manner as when acquiring the authentication information of the user terminal 300.

[0138] The registration unit 112, for example, executes a registration process to register the registration information of the user terminal 300. The registration unit 112 executes the registration process of the registration information of the user terminal 300 in response to, for example, the authentication unit 108 succeeding in the proxy authentication process of the user terminal 300.

[0139] The establishment unit 106, for example, executes a process for establishing a PDU session for the user terminal 300. The establishment unit 106 executes a process for establishing a PDU session for the user terminal 300, for example, in response to completion of a process for registering the registration information of the user terminal 300 by the registration unit 112. In response to completion of a process for establishing a PDU session for the user terminal 300, the establishment unit 106 may register session information indicating the PDU session of the user terminal 300 in the storage unit 102.

[0140] The acquiring unit 104 acquires, for example, user data. The acquiring unit 104 acquires, for example, user data in the downlink (DL) direction. The acquiring unit 104 acquires, for example, user data in the DL direction by receiving the user data in the DL direction via a wired communication connection between the authentication device 100 and the mobile communication network 20. The acquiring unit 104 acquires, for example, user data in the uplink (UL) direction. The acquiring unit 104 may acquire the user data in the UL direction in the same manner as when acquiring authentication information of the user terminal 300.

[0141] The relay unit 114 relays communication. The relay unit 114 relays communication, for example, based on various information stored in the storage unit 102. The relay unit 114 relays communication, for example, based on various information acquired by the acquisition unit 104.

[0142] The relay unit 114 relays, for example, communication of user data between the user terminal 300 and the communication target 400. The relay unit 114 relays communication of user data between the user terminal 300 and the communication target 400, for example, in response to completion of establishment processing of a PDU session of the user terminal 300 by the establishment unit 106.

[0143] The relay unit 114 relays, for example, user data communication in the DL direction between the user terminal 300 and the communication target 400. The relay unit 114 relays, for example, user data communication in the UL direction between the user terminal 300 and the communication target 400.

[0144] The relay unit 114 relays the communication of user data between the user terminal 300 and the communication target 400, for example, via a wired communication connection between the authentication device 100 and the mobile communication network 20. The relay unit 114 may also relay the communication of user data between the user terminal 300 and the communication target 400 via a wireless communication connection between the authentication device 100 and the mobile communication network 20.

[0145] The relay unit 114 relays, for example, communication of user data between each of the plurality of user terminals 300 and each communication target 400 of the plurality of user terminals 300. The relay unit 114 relays, for example, communication of user data between each of the plurality of user terminals 300 and each communication target 400 of the plurality of user terminals 300 via a wired communication connection between the authentication device 100 and the mobile communication network 20. The relay unit 114 relays, for example, communication of user data between each of at least one user terminal 300 among the plurality of user terminals 300 and each communication target 400 of the at least one user terminal 300 via a wireless communication connection between the authentication device 100 and the mobile communication network 20.

[0146] The acquiring unit 104 acquires, for example, communication status information indicating the communication status of communication of user data between the user terminal 300 and the communication target 400. The acquiring unit 104 acquires, for example, communication status information indicating the communication status of communication of user data between each of the plurality of user terminals 300 and each of the communication targets 400 of the plurality of user terminals 300.

[0147] The communication status of the user data communication between the user terminal 300 and the communication target 400 is, for example, the communication status of the user data communication between the user terminal 300 and the communication target 400 via a wired communication connection between the authentication device 100 and the mobile communication network 20. Note that the user data communication between the user terminal 300 and the communication target 400 via the wired communication connection between the authentication device 100 and the mobile communication network 20 may be referred to as the user data communication on a wired communication path.

[0148] The communication status of the communication of user data between the user terminal 300 and the communication target 400 may be, for example, the communication status of the communication of user data between the user terminal 300 and the communication target 400 via a wireless communication connection between the authentication device 100 and the mobile communication network 20. Note that the communication of user data between the user terminal 300 and the communication target 400 via a wireless communication connection between the authentication device 100 and the mobile communication network 20 may be referred to as the communication of user data on a wireless communication path.

[0149] The communication status of the user data communication between the user terminal 300 and the communication target 400 includes, for example, the communication status of the user data communication in the DL direction between the user terminal 300 and the communication target 400. The communication status of the user data communication between the user terminal 300 and the communication target 400 includes, for example, the communication status of the user data communication in the UL direction between the user terminal 300 and the communication target 400. The communication status of the user data communication between the user terminal 300 and the communication target 400 includes, for example, both the communication status of the user data communication in the DL direction between the user terminal 300 and the communication target 400 and the communication status of the user data communication in the UL direction between the user terminal 300 and the communication target 400.

[0150] The communication status information includes, for example, SNR information indicating the SNR (Signal to Noise Ratio) of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, SINR information indicating the SINR (Signal to Interference and Noise Ratio) of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, TP information indicating the throughput (TP) of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, RTT information indicating the round trip time (RTT) of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, LAT information indicating the latency (LAT) of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, Jitter information indicating the jitter of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, PLR information indicating a packet loss rate (PLR) of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, RR information indicating a retransmission rate (RR) of packets of the user data communication between the user terminal 300 and the communication target 400. The communication status information includes, for example, PER information indicating a packet error rate (PER) of the user data communication between the user terminal 300 and the communication target 400.

[0151] The acquiring unit 104 acquires, for example, QoS requirement information indicating QoS requirements applied to user data communication between the user terminal 300 and the communication target 400. The QoS requirements are applied, for example, to user data communication in the DL direction between the user terminal 300 and the communication target 400. The QoS requirements are applied, for example, to user data communication in the UL direction between the user terminal 300 and the communication target 400. The QoS requirements are applied, for example, to both user data communication in the DL direction between the user terminal 300 and the communication target 400 and user data communication in the UL direction between the user terminal 300 and the communication target 400.

[0152] For example, the QoS requirements applied to user data communication in the DL direction between the user terminal 300 and the communication target 400 are the same as the QoS requirements applied to user data communication in the UL direction between the user terminal 300 and the communication target 400. For example, the QoS requirements applied to user data communication in the DL direction between the user terminal 300 and the communication target 400 are different from the QoS requirements applied to user data communication in the UL direction between the user terminal 300 and the communication target 400.

[0153] The QoS requirement includes, for example, an SNR requirement, which requires that the SNR of the user data communication between the user terminal 300 and the communication target 400 is higher than a predetermined SNR threshold.

[0154] The QoS requirement includes, for example, an SINR requirement, which requires that the SINR of the user data communication between the user terminal 300 and the communication target 400 is higher than a predetermined SINR threshold.

[0155] The QoS requirement includes, for example, a TP requirement, which requires that the TP of the user data communication between the user terminal 300 and the communication target 400 is greater than a predetermined TP threshold.

[0156] The QoS requirement includes, for example, an RTT requirement, which requires that the RTT of the communication of user data between the user terminal 300 and the communication target 400 is shorter than a predetermined RTT threshold.

[0157] The QoS requirement includes, for example, an LAT requirement, which is that the LAT of the user data communication between the user terminal 300 and the communication target 400 is shorter than a predetermined LAT threshold.

[0158] The QoS requirements include, for example, a jitter requirement, which requires that the jitter in the communication of user data between the user terminal 300 and the communication target 400 is smaller than a predetermined jitter threshold.

[0159] The QoS requirement includes, for example, a PLR requirement, which requires that the PLR ​​of the user data communication between the user terminal 300 and the communication target 400 is lower than a predetermined PLR threshold.

[0160] The QoS requirement includes, for example, an RR requirement, which is that the RR of the communication of user data between the user terminal 300 and the communication target 400 is lower than a predetermined RR threshold.

[0161] The QoS requirement includes, for example, a PER requirement, which requires that the PER of the communication of user data between the user terminal 300 and the communication target 400 is lower than a predetermined PER threshold.

[0162] The QoS requirement may include two or more of an SNR requirement, a SINR requirement, a TP requirement, an RTT requirement, a LAT requirement, a Jitter requirement, a PLR requirement, an RR requirement, and a PER requirement. In this case, the QoS requirement may include any combination of an SNR requirement, a SINR requirement, a TP requirement, an RTT requirement, a LAT requirement, a Jitter requirement, a PLR requirement, an RR requirement, and a PER requirement.

[0163] The determination unit 116 executes a determination process based on, for example, various pieces of information stored in the storage unit 102. The determination unit 116 executes a determination process based on, for example, various pieces of information acquired by the acquisition unit 104.

[0164] The determination unit 116 determines whether or not the communication status of the user data communication over the wired communication path, indicated by the communication status information of the user terminal 300, satisfies a predetermined communication status condition. The determination unit 116 determines whether or not the communication status of the user data communication over the wired communication path, indicated by the communication status information of each of the multiple user terminals 300, satisfies the communication status condition.

[0165] For example, when the determination unit 116 determines that the communication status of the user data communication on the wired communication path satisfies the communication status condition, the relay unit 114 relays the user data communication between the user terminal 300 and the communication target 400 via the wired communication connection between the authentication device 100 and the mobile communication network 20. On the other hand, when the determination unit 116 determines that the communication status does not satisfy the communication status condition, the relay unit 114 relays the user data communication between the user terminal 300 and the communication target 400 via the wireless communication connection between the authentication device 100 and the mobile communication network 20.

[0166] The communication status conditions include, for example, that the communication of user data in the DL direction between the user terminal 300 and the communication target 400 satisfies the QoS requirements applied to the communication of user data in the DL direction between the user terminal 300 and the communication target 400. The communication status conditions include, for example, that the communication of user data in the UL direction between the user terminal 300 and the communication target 400 satisfies the QoS requirements applied to the communication of user data in the UL direction between the user terminal 300 and the communication target 400. The communication status conditions include, for example, that the communication of user data in the DL direction between the user terminal 300 and the communication target 400 satisfies the QoS requirements applied to the communication of user data in the DL direction between the user terminal 300 and the communication target 400, and that the communication of user data in the UL direction between the user terminal 300 and the communication target 400 satisfies the QoS requirements applied to the communication of user data in the UL direction between the user terminal 300 and the communication target 400.

[0167] For example, when a user terminal 300 for user data communication via a wireless communication path exists and a user terminal 300 for which the determination unit 116 has determined that the communication status of the user data communication via a wired communication path does not satisfy the communication status condition does not exist during a predetermined determination period, the relay unit 114 switches the relay of the user data communication between the user terminal 300 and the communication target 400 from relay via a wireless communication connection between the authentication device 100 and the mobile communication network 20 to relay via a wired communication connection between the authentication device 100 and the mobile communication network 20. On the other hand, when a user terminal 300 for user data communication via a wireless communication path does not exist or a user terminal 300 for which the determination unit 116 has determined that the communication status of the user data communication via a wired communication path does not satisfy the communication status condition exists during the determination period, the relay unit 114 does not switch the relay of the user data communication between the user terminal 300 and the communication target 400.

[0168] The selection unit 118 selects the user terminal 300 for which the communication path is to be switched. The selection unit 118 selects, for example, two or more user terminals 300 for which the communication path is to be switched.

[0169] The selection unit 118 selects the user terminal 300 based on, for example, various pieces of information stored in the storage unit 102. The selection unit 118 selects the user terminal 300 based on, for example, various pieces of information acquired by the acquisition unit 104.

[0170] The selection unit 118 selects, for example, the user terminal 300 that switches from communicating user data via a wired communication path to communicating user data via a wireless communication path. The selection unit 118 may also select the user terminal 300 that switches from communicating user data via a wireless communication path to communicating user data via a wired communication path.

[0171] For example, when there is a user terminal 300 for which the determination unit 116 has determined that the communication status of user data communication over a wired communication path does not satisfy the communication status condition, the selection unit 118 selects, from the multiple user terminals 300, a user terminal 300 that switches from user data communication over a wired communication path to user data communication over a wireless communication path, based on a predetermined first selection condition. In this case, the relay unit 114 relays the user data communication between the user terminal 300 selected by the selection unit 118 and the communication target 400 via a wireless communication connection between the authentication device 100 and the mobile communication network 20. On the other hand, when there is no user terminal 300 for which the determination unit 116 has determined that the communication status does not satisfy the communication status condition, the selection unit 118 does not select a user terminal 300.

[0172] The first selection condition includes, for example, giving priority to selecting a user terminal 300 to which a QoS requirement is applied. The first selection condition includes, for example, giving priority to selecting a user terminal 300 to which a stricter QoS requirement is applied.

[0173] The first selection condition includes, for example, preferentially selecting a user terminal 300 having a higher SNR in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a higher SINR in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a higher TP in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a shorter RTT in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a shorter LAT in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having smaller jitter in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a lower PLR in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a lower RR of user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a lower PER of user data communication over a wired communication path.

[0174] The first selection condition includes, for example, giving priority to selecting a user terminal 300 to which no QoS requirement is applied. The first selection condition includes, for example, giving priority to selecting a user terminal 300 to which a more lenient QoS requirement is applied.

[0175] The first selection condition includes, for example, preferentially selecting a user terminal 300 having a lower SNR in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a lower SINR in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a lower TP in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a longer RTT in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a longer LAT in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having larger jitter in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a higher PLR in user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a higher RR for user data communication over a wired communication path. The first selection condition includes, for example, preferentially selecting a user terminal 300 having a higher PER for user data communication over a wired communication path.

[0176] For example, when there are two or more user terminals 300 communicating user data via a wireless communication path and there is no user terminal 300 for which the communication status of the user data communication via a wired communication path is determined by the determination unit 116 not to satisfy the communication status condition during the determination period, the selection unit 118 selects, from the two or more user terminals 300, a user terminal 300 for switching from communication of user data via a wireless communication path to communication of user data via a wired communication path, based on a predetermined second selection condition. In this case, the relay unit 114 relays the user data communication between the user terminal 300 selected by the selection unit 118 and the communication target 400 via the wired communication connection between the authentication device 100 and the mobile communication network 20. On the other hand, when there are two or more user terminals 300 communicating user data via a wireless communication path, or when there is a user terminal 300 for which the communication status is determined by the determination unit 116 not to satisfy the communication status condition during the determination period, the selection unit 118 does not select a user terminal 300.

[0177] The second selection condition includes, for example, giving higher priority to selecting a user terminal 300 to which a QoS requirement is applied. The second selection condition includes, for example, giving higher priority to selecting a user terminal 300 to which a stricter QoS requirement is applied.

[0178] The second selection condition includes, for example, preferentially selecting a user terminal 300 having a higher SNR for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a higher SINR for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a higher TP for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a shorter RTT for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a shorter LAT for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having smaller jitter for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a lower PLR for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a lower RR for user data communication on the wireless communication path. The second selection condition includes, for example, giving higher priority to selecting a user terminal 300 with a lower PER of user data communication on a wireless communication path.

[0179] The second selection condition includes, for example, giving preference to selecting a user terminal 300 to which no QoS requirement is applied, and giving preference to selecting a user terminal 300 to which a more lenient QoS requirement is applied.

[0180] The second selection condition includes, for example, preferentially selecting a user terminal 300 having a lower SNR for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a lower SINR for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a lower TP for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a longer RTT for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a longer LAT for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a larger Jitter for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a higher PLR for user data communication on the wireless communication path. The second selection condition includes, for example, preferentially selecting a user terminal 300 having a higher RR for user data communication on the wireless communication path. The second selection condition includes, for example, giving higher priority to selecting a user terminal 300 with a higher PER of user data communication on a wireless communication path.

[0181] The communication unit 124 communicates with the management device 500. The communication unit 124 communicates with the management device 500 via a wireless communication connection between the authentication device 100 and the mobile communication network 20, for example.

[0182] The communication unit 124 receives, for example, from the management device 500, an OAM signal instructing to switch the relay of the user data communication between the user terminal 300 and the communication target 400 from relay via the wired communication connection between the authentication device 100 and the mobile communication network 20 to relay via the wireless communication connection between the authentication device 100 and the mobile communication network 20. In this case, based on the OAM signal, the relay unit 114 switches the relay of the user data communication between the user terminal 300 and the communication target 400 from relay via the wired communication connection between the authentication device 100 and the mobile communication network 20 to relay via the wireless communication connection between the authentication device 100 and the mobile communication network 20. Note that this OAM signal may be referred to as a first OAM signal.

[0183] For example, the communication unit 124 receives an OAM signal from the management device 500 instructing to switch the relay of the user data communication between the user terminal 300 and the communication target 400 from relay via the wireless communication connection between the authentication device 100 and the mobile communication network 20 to relay via the wired communication connection between the authentication device 100 and the mobile communication network 20. In this case, based on the OAM signal, the relay unit 114 switches the relay of the user data communication between the user terminal 300 and the communication target 400 from relay via the wireless communication connection between the authentication device 100 and the mobile communication network 20 to relay via the wired communication connection between the authentication device 100 and the mobile communication network 20. Note that this OAM signal may be referred to as a second OAM signal.

[0184] 8 illustrates an example of the functional configuration of the management device 500. The management device 500 may include a storage unit 502, an acquisition unit 504, a determination unit 506, a generation unit 508, a selection unit 512, and a transmission unit 514. Note that it is not essential for the management device 500 to include all of these components.

[0185] The storage unit 502 stores various types of information, such as QoS requirement information of the user terminal 300.

[0186] The acquisition unit 504 acquires various types of information. The acquisition unit 504 acquires various types of information by, for example, receiving the various types of information. The acquisition unit 504 receives various types of information, for example, via the mobile communication network 20. The acquisition unit 504 receives various types of information, for example, via the wireless communication connection 122. The acquisition unit 504 receives various types of information, for example, via the wired communication line 132. The acquisition unit 504 receives various types of information, for example, via the access point 200. The acquisition unit 504 receives various types of information, for example, via the Internet 40. The acquisition unit 504 may acquire various types of information by an input unit included in the management device 500 accepting input of the various types of information. The management device 500 may acquire various types of information by a measurement unit included in the management device 500 measuring the various types of information. The acquisition unit 504 may store the acquired various types of information in the storage unit 502.

[0187] The acquisition unit 504 acquires various information from, for example, the authentication device 100. The acquisition unit 504 acquires various information from, for example, the access point 200. The acquisition unit 504 acquires various information from, for example, the user terminal 300. The acquisition unit 504 acquires various information from, for example, the communication target 400. The acquisition unit 504 may acquire various information from any other external device.

[0188] The acquiring unit 504 acquires, for example, communication status information indicating the communication status of user data communication between the user terminal 300 and the communication target 400. The acquiring unit 504 acquires, for example, resource status information indicating the resource status of radio resources of the mobile communication system to which the mobile communication network 20 conforms.

[0189] The determination unit 506 executes a determination process based on, for example, various pieces of information stored in the storage unit 502. The determination unit 506 executes a determination process based on, for example, various pieces of information acquired by the acquisition unit 504.

[0190] The determination unit 506 determines whether or not the communication status of user data communication over a wired communication path, indicated by the communication status information of the user terminal 300, satisfies a predetermined communication status condition. The determination unit 506 determines whether or not the communication status of user data communication over a wired communication path, indicated by the communication status information of each of the multiple user terminals 300, satisfies the communication status condition.

[0191] The determining unit 506 determines whether the resource status of the radio resource indicated by the resource status information satisfies a predetermined resource status condition, for example. The resource status condition includes whether the available resource amount of the radio resource is greater than a predetermined available resource amount threshold. The resource status condition includes whether the ratio of the available resource amount of the radio resource to the resource amount of the radio resource is higher than a predetermined ratio threshold.

[0192] The generating unit 508 generates various signals. For example, the generating unit 508 generates various signals based on various information stored in the storage unit 502. For example, the generating unit 508 generates various signals based on various information acquired by the acquiring unit 504.

[0193] The generating unit 508 generates, for example, a control signal, or an OAM signal.

[0194] The generating unit 508 generates, for example, a first OAM signal. For example, when the determining unit 506 determines that the communication status of user data communication on a wired communication path indicated by the communication status information of the user terminal 300 does not satisfy the communication status conditions, the generating unit 508 generates a first OAM signal that switches the communication path of the user terminal 300. On the other hand, when the determining unit 506 determines that the communication status satisfies the communication status conditions, the generating unit 508 does not generate the first OAM signal.

[0195] For example, when the determination unit 506 determines that the communication conditions do not satisfy the communication condition conditions and that the resource conditions of the radio resources indicated by the resource condition information satisfy the resource condition conditions, the generation unit 508 generates the first OAM signal. On the other hand, when the determination unit 506 determines that the communication conditions satisfy the communication condition conditions or when the determination unit 506 determines that the resource conditions do not satisfy the resource condition conditions, the generation unit 508 does not generate the first OAM signal.

[0196] The generating unit 508 generates, for example, a second OAM signal. For example, when a user terminal 300 communicating user data on the wireless communication path is present and the determining unit 506 determines that the resource status of the wireless resources indicated by the resource status information does not satisfy the resource status condition, the generating unit 508 generates the second OAM signal to switch the communication path of the user terminal 300 communicating user data on the wireless communication path. On the other hand, when a user terminal 300 communicating user data on the wireless communication path is not present or when the determining unit 506 determines that the resource status satisfies the resource status condition, the generating unit 508 does not generate the second OAM signal.

[0197] For example, when a user terminal 300 communicating user data via a wireless communication path exists and a user terminal 300 whose communication status for communicating user data via a wired communication path is determined by the determination unit 506 not to satisfy the communication status condition exists during a predetermined determination period, the generation unit 508 generates a second OAM signal to switch the communication path of the user terminal 300 communicating user data via a wireless communication path. On the other hand, when a user terminal 300 communicating user data via a wireless communication path is not present or when a user terminal 300 whose communication status is determined by the determination unit 506 not to satisfy the communication status condition exists during the determination period, the generation unit 508 does not generate the second OAM signal.

[0198] The selection unit 512 selects the user terminal 300 for which the communication path is to be switched. The selection unit 512 selects, for example, two or more user terminals 300 for which the communication path is to be switched.

[0199] The selection unit 512 selects the user terminal 300 for which the communication path is to be switched, for example, based on various information stored in the storage unit 502. The selection unit 512 selects the user terminal 300 for which the communication path is to be switched, for example, based on various information acquired by the acquisition unit 504.

[0200] For example, when there is a user terminal 300 for which the determination unit 506 has determined that the communication conditions of user data communication over a wired communication path do not satisfy the communication condition conditions, the selection unit 512 selects, from among the multiple user terminals 300, a user terminal 300 for switching from user data communication over a wired communication path to user data communication over a wireless communication path, based on a predetermined first selection condition. In this case, the generation unit 508 generates a first OAM signal for switching the communication path of the user terminal 300 selected by the selection unit 512. On the other hand, when there is no user terminal 300 for which the determination unit 506 has determined that the communication conditions do not satisfy the communication condition conditions, the selection unit 512 does not select a user terminal 300.

[0201] For example, when there is a user terminal 300 whose communication conditions are determined by the determination unit 506 not to satisfy the communication condition condition and when the determination unit 506 determines that the resource conditions of the radio resources indicated by the resource condition information satisfy the resource condition condition, the selection unit 512 selects, from the multiple user terminals 300, a user terminal 300 that switches from user data communication via a wired communication path to user data communication via a wireless communication path based on the first selection condition. In this case, the generation unit 508 generates a first OAM signal that switches the communication path of the user terminal 300 selected by the selection unit 512. On the other hand, when there is no user terminal 300 whose communication conditions are determined by the determination unit 506 not to satisfy the communication condition condition or when the determination unit 506 determines that the resource conditions do not satisfy the resource condition.

[0202] For example, when there are two or more user terminals 300 communicating user data via a wireless communication path and the determination unit 506 determines that the resource status of the wireless resources indicated by the resource status information does not satisfy the resource status condition, the selection unit 512 selects a user terminal 300 that switches from communicating user data via a wireless communication path to communicating user data via a wired communication path from among the two or more user terminals 300, based on a predetermined second selection condition. In this case, the generation unit 508 generates a second OAM signal that switches the communication path of the user terminal 300 selected by the selection unit 512. On the other hand, when there are two or more user terminals 300 communicating user data via a wireless communication path, or when the determination unit 506 determines that the resource status satisfies the resource status condition, the selection unit 512 does not select a user terminal 300.

[0203] For example, when there are two or more user terminals 300 communicating user data via a wireless communication path and there is no user terminal 300 for which the determination unit 506 has determined that the communication status of the user data communication via a wired communication path does not satisfy the communication status condition during the determination period, the selection unit 512 selects, from the two or more user terminals 300, a user terminal 300 for switching from communication of user data via a wireless communication path to communication of user data via a wired communication path based on the second selection condition. In this case, the generation unit 508 generates a second OAM signal for switching the communication path of the user terminal 300 selected by the selection unit 512. On the other hand, when there are two or more user terminals 300 communicating user data via a wireless communication path or when there is a user terminal 300 for which the determination unit 506 has determined that the communication status of the user data communication via a wired communication path does not satisfy the communication status condition during the determination period, the selection unit 512 does not select a user terminal 300.

[0204] The transmitting unit 514 transmits various types of information. For example, the transmitting unit 514 transmits the various types of information to the authentication device 100. The transmitting unit 514 may transmit the various types of information to any other external device.

[0205] The transmitting unit 514 transmits the various information via, for example, the mobile communication network 20. The transmitting unit 514 transmits the various information via, for example, the wireless communication connection 122. The transmitting unit 514 transmits the various information via, for example, the wired communication line 132. The transmitting unit 514 transmits the various information via, for example, the access point 200. The transmitting unit 514 may transmit the various information via the Internet 40.

[0206] The transmitting unit 514 transmits, for example, various signals generated by the generating unit 508. The transmitting unit 514 transmits, for example, a control signal generated by the generating unit 508. The transmitting unit 514 transmits, for example, an OAM signal generated by the generating unit 508. The transmitting unit 514 transmits, for example, a first OAM signal generated by the generating unit 508. The transmitting unit 514 transmits, for example, a second OAM signal generated by the generating unit 508.

[0207] 9 is an explanatory diagram illustrating an example of the flow of processing by the authentication device 100. Here, a state in which the authentication device 100 has not yet acquired communication status information of the user terminal 300 will be described as a starting state.

[0208] In S202, the acquisition unit 104 acquires communication status information for each of the multiple user terminals 300. In S204, the determination unit 116 determines whether the communication status of the communication of user data between the user terminal 300 and the communication target 400, indicated by the communication status information for one user terminal 300 among the communication status information for each of the multiple user terminals 300 acquired by the acquisition unit 104 in S202, satisfies a predetermined communication status condition. If the determination unit 116 determines that the communication status does not satisfy the communication status condition, the process proceeds to S206. If the determination unit 116 determines that the communication status satisfies the communication status condition, the process proceeds to S208.

[0209] In S206, if the communication status information of the one user terminal 300 acquired by the acquisition unit 104 in S202 indicates the communication status of user data communication over a wired communication path, the determination unit 116 counts the one user terminal 300. On the other hand, in S206, if the communication status information of the one user terminal 300 acquired by the acquisition unit 104 in S202 indicates the communication status of user data communication over a wireless communication path, the determination unit 116 does not count the one user terminal 300.

[0210] In S208, the determination unit 116 determines whether or not all of the communication status information for each of the multiple user terminals 300 acquired by the acquisition unit 104 in S204 has been determined. If the determination unit 116 determines that all of the communication status information for each of the multiple user terminals 300 has been determined, the process proceeds to S210. If the determination unit 116 determines that all of the communication status information for each of the multiple user terminals 300 has not been determined, the process returns to S204, and determines whether or not the communication status of the communication of user data between the user terminal 300 and the communication target 400, which is indicated by the communication status information of one undetermined user terminal 300, satisfies the communication status condition.

[0211] In S210, the determination unit 116 determines whether or not the UE counted in S206 exists. If the determination unit 116 determines that the UE counted in S206 exists, the process proceeds to S212. If the determination unit 116 determines that the UE counted in S206 does not exist, the process proceeds to S216.

[0212] In S212, the selection unit 118 selects, from the plurality of user terminals 300, a user terminal 300 that switches user data communication from a wired communication path to a wireless communication path, based on a predetermined first selection condition. The selection unit 118 selects, from the plurality of user terminals 300, the number of user terminals 300 counted by the determination unit 116 in S206, based on, for example, the first selection condition. For example, if the determination unit 116 counts three user terminals 300 in S206, the selection unit 118 selects three user terminals 300 based on the first selection condition. In S214, the relay unit 114 relays user data communication between the user terminal 300 selected by the selection unit 118 in S212 and the communication target 400 via a wireless communication connection between the authentication device 100 and the mobile communication network 20.

[0213] In S216, the determination unit 116 determines whether or not a user terminal 300 whose communication status of user data communication on a wired communication path is determined not to satisfy the communication status conditions exists during a predetermined determination period. If the determination unit 116 determines that a user terminal 300 whose communication status of user data communication on a wired communication path is determined not to satisfy the communication status conditions exists during the determination period, the process proceeds to S218. If the determination unit 116 determines that a user terminal 300 whose communication status of user data communication on a wired communication path is determined not to satisfy the communication status conditions exists during the determination period, the process proceeds to S222.

[0214] In S218, the determination unit 116 determines whether or not a user terminal 300 for communicating user data via the wireless communication path exists. If the determination unit 116 determines that a user terminal 300 for communicating user data via the wireless communication path exists, the process proceeds to S220. If the determination unit 116 determines that a user terminal 300 for communicating user data via the wireless communication path does not exist, the process proceeds to S222.

[0215] In S220, the relay unit 114 relays the user data communication between the user terminal 300, for which the communication status information acquired by the acquisition unit 104 in S202 indicates the communication status of the user data communication on the wireless communication path, and the communication target 400, via the wired communication connection between the authentication device 100 and the mobile communication network 20. If the determination unit 116 determines in S218 that there are two or more user terminals 300 communicating user data on the wireless communication path, the selection unit 118 may select, from the two or more user terminals 300, a user terminal 300 that switches from user data communication on the wireless communication path to user data communication on the wired communication path, based on a predetermined second selection condition. In this case, the relay unit 114 relays the user data communication between the user terminal 300 selected by the selection unit 118 and the communication target 400, via the wired communication connection between the authentication device 100 and the mobile communication network 20.

[0216] In S222, if the acquisition unit 104 has not acquired an end instruction, the process returns to S202 after resetting the count of the user terminal 300. In S222, if the acquisition unit 104 has acquired an end instruction, the process of the authentication device 100 then ends.

[0217] 10 is an explanatory diagram illustrating another example of the processing flow of authentication device 100. Here, the description will be given assuming that the state in which authentication device 100 is not receiving an OAM signal is the starting state.

[0218] In S302, the communication unit 124 receives an OAM signal from the management device 500 via the wireless communication connection between the authentication device 100 and the mobile communication network 20. Here, the description will continue assuming that the OAM signal is the first OAM signal or the second OAM signal.

[0219] In S304, the repeater unit 114 determines whether the OAM signal received by the communication unit 124 in S302 is a first OAM signal or a second OAM signal. If the repeater unit 114 determines that the OAM signal is a first OAM signal, the process proceeds to S306. If the repeater unit 114 determines that the OAM signal is a second OAM signal, the process proceeds to S308.

[0220] At S306, based on the first OAM signal received by the communication unit 124 at S302, the relay unit 114 switches the relay of the user data communication between the user terminal 300 and the communication target 400 from relaying via the wired communication connection between the authentication device 100 and the mobile communication network 20 to relaying via the wireless communication connection between the authentication device 100 and the mobile communication network 20. At S308, based on the second OAM signal received by the communication unit 124 at S302, the relay unit 114 switches the relay of the user data communication between the user terminal 300 and the communication target 400 from relaying via the wireless communication connection between the authentication device 100 and the mobile communication network 20 to relaying via the wired communication connection between the authentication device 100 and the mobile communication network 20.

[0221] In S310, if the acquisition unit 104 has not acquired an end instruction, the process returns to S302. In S312, if the acquisition unit 104 has acquired an end instruction, the process of the authentication device 100 then ends.

[0222] 11 schematically illustrates an example of the hardware configuration of a computer 1200 that functions as the authentication device 100 or the management device 500. A program installed on the computer 1200 can cause the computer 1200 to function as one or more "parts" of the device according to the present embodiment, or can cause the computer 1200 to perform operations associated with the device according to the present embodiment or one or more "parts," and / or can cause the computer 1200 to perform a process according to the present embodiment or steps of the process. Such a program can be executed by the CPU 1212 to cause the computer 1200 to perform specific operations associated with some or all of the blocks in the flowcharts and block diagrams described herein.

[0223] The computer 1200 according to this embodiment includes a CPU 1212, a RAM 1214, and a graphics controller 1216, which are interconnected by a host controller 1210. The computer 1200 also includes input / output units such as a communications interface 1222, a storage device 1224, a DVD drive 1226, and an IC card drive, which are connected to the host controller 1210 via an input / output controller 1220. The DVD drive 1226 may be a DVD-ROM drive, a DVD-RAM drive, or the like. The storage device 1224 may be a hard disk drive, a solid-state drive, or the like. The computer 1200 also includes a ROM 1230 and legacy input / output units such as a keyboard, which are connected to the input / output controller 1220 via an input / output chip 1240.

[0224] The CPU 1212 operates according to programs stored in the ROM 1230 and the RAM 1214, thereby controlling each unit. The graphics controller 1216 acquires image data generated by the CPU 1212 into a frame buffer or the like provided in the RAM 1214 or into the graphics controller itself, and causes the image data to be displayed on the display device 1218.

[0225] The communication interface 1222 communicates with other electronic devices via a network. The storage device 1224 stores programs and data used by the CPU 1212 in the computer 1200. The DVD drive 1226 reads programs or data from a DVD-ROM 1227 or the like and provides them to the storage device 1224. The IC card drive reads programs and data from an IC card and / or writes programs and data to an IC card.

[0226] The ROM 1230 stores therein a boot program or the like that is executed by the computer 1200 upon activation, and / or programs that depend on the hardware of the computer 1200. The input / output chip 1240 may also connect various input / output units to the input / output controller 1220 via a USB port, a parallel port, a serial port, a keyboard port, a mouse port, etc.

[0227] The programs are provided by a computer-readable storage medium such as a DVD-ROM 1227 or an IC card. The programs are read from the computer-readable storage medium, installed in the storage device 1224, RAM 1214, or ROM 1230, which are also examples of computer-readable storage media, and executed by the CPU 1212. Information processing described in these programs is read by the computer 1200, and causes cooperation between the programs and the various types of hardware resources described above. An apparatus or method may be configured by implementing operations or processing of information in accordance with the use of the computer 1200.

[0228] For example, when communication is performed between the computer 1200 and an external device, the CPU 1212 may execute a communication program loaded into the RAM 1214 and instruct the communication interface 1222 to perform communication processing based on the processing described in the communication program. Under the control of the CPU 1212, the communication interface 1222 reads transmission data stored in a transmission buffer area provided in the RAM 1214, the storage device 1224, the DVD-ROM 1227, or a recording medium such as an IC card, and transmits the read transmission data to the network, or writes reception data received from the network to a reception buffer area or the like provided on the recording medium.

[0229] Furthermore, the CPU 1212 may cause all or a necessary portion of a file or database stored in an external recording medium such as the storage device 1224, the DVD drive 1226 (DVD-ROM 1227), an IC card, etc. to be read into the RAM 1214, and may perform various types of processing on the data on the RAM 1214. The CPU 1212 may then write back the processed data to the external recording medium.

[0230] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and may undergo information processing. The CPU 1212 may perform various types of processing on data read from the RAM 1214, including various types of operations, information processing, conditional judgment, conditional branching, unconditional branching, information search / replacement, etc., as described throughout this disclosure and specified by the instruction sequences of the programs, and write the results back to the RAM 1214. The CPU 1212 may also search for information in a file, database, etc. on the recording medium. For example, if multiple entries, each having an attribute value of a first attribute associated with an attribute value of a second attribute, are stored on the recording medium, the CPU 1212 may search for an entry whose attribute value of the first attribute matches a specified condition from among the multiple entries, read the attribute value of the second attribute stored in the entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.

[0231] The above-described programs or software modules may be stored in a computer-readable storage medium on or near the computer 1200. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can also be used as a computer-readable storage medium, thereby providing the programs to the computer 1200 via the network.

[0232] The blocks in the flowcharts and block diagrams in the present embodiments may represent stages of a process in which an operation is performed or "parts" of an apparatus responsible for performing the operation. Particular stages and "parts" may be implemented by dedicated circuitry, programmable circuitry provided with computer-readable instructions stored on a computer-readable storage medium, and / or a processor provided with computer-readable instructions stored on a computer-readable storage medium. The dedicated circuitry may include digital and / or analog hardware circuits, including integrated circuits (ICs) and / or discrete circuits. The programmable circuitry may include reconfigurable hardware circuits, such as field programmable gate arrays (FPGAs) and programmable logic arrays (PLAs), including AND, OR, XOR, NAND, NOR, and other logical operations, flip-flops, registers, and memory elements.

[0233] A computer-readable medium may include any tangible device capable of storing instructions that are executed by a suitable device, such that the computer-readable medium having instructions stored thereon comprises an article of manufacture containing instructions that can be executed to create means for performing the operations specified in the flowcharts or block diagrams. Examples of computer-readable media may include electronic, magnetic, optical, electromagnetic, and semiconductor storage media. More specific examples of computer-readable media may include floppy disks, diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), Blu-ray disc, memory stick, integrated circuit card, and the like.

[0234] The computer readable instructions may include either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk®, JAVA®, C++, etc., and conventional procedural programming languages ​​such as the “C” programming language or similar programming languages.

[0235] The computer-readable instructions may be provided to a processor or programmable circuit of a programmable data processing device, such as a computer, locally or over a wide area network, such as a local area network or the Internet, and the computer-readable instructions may be executed to create means for performing the operations specified in the flowcharts or block diagrams. Here, the computer may be a personal computer (PC), a tablet computer, a smartphone, a workstation, a server computer, a general-purpose computer, a special-purpose computer, or the like, or may be a computer system in which multiple computers are connected. Such a computer system in which multiple computers are connected is also called a distributed computing system, and is a broad definition of computer. In a distributed computing system, the multiple computers collectively execute a program by each executing a portion of the program and passing data between the computers as needed during program execution.

[0236] Examples of processors include a computer processor, a central processing unit (CPU), a processing unit, a microprocessor, a digital signal processor, a controller, a microcontroller, etc. A computer may have one or more processors. In a multiprocessor system with multiple processors, each processor executes a portion of a program and passes data between processors as needed during program execution, allowing the multiple processors to collectively execute the program. For example, in multitasking, each of the multiple processors may execute a portion of each task in small chunks by switching tasks at time slice intervals. In this case, which portion of a program each processor executes changes dynamically. Which portion of a program each of the multiple processors executes may also be statically determined by multiprocessor-aware programming.

[0237] The present invention can contribute to the spread of non-public networks that comply with mobile communication systems, and can therefore contribute to the achievement of Goal 9 of the Sustainable Development Goals (SDGs), which is to "build inclusive and sustainable industrial bases, promote innovation and foster resilience."

[0238] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. It is clear from the claims that such modifications and improvements can also be included within the technical scope of the present invention.

[0239] It should be noted that the execution order of each process, such as operations, procedures, steps, and stages, in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not specifically stated as "before," "prior to," etc., and that the processes can be performed in any order unless the output of a previous process is used in a later process. Even if the operational flow in the claims, specifications, and drawings is described using "first," "next," etc. for convenience, this does not mean that the processes must be performed in this order. [Explanation of symbols]

[0240] 10 System, 20 Mobile communication network, 21 AMF, 23 AUSF, 25 SMF, 30 Wireless base station, 32 UPF, 35 Router, 40 Internet, 50 Building, 100 Authentication device, 102 Storage unit, 104 Acquisition unit, 106 Establishment unit, 108 Authentication unit, 112 Registration unit, 114 Relay unit, 116 Determination unit, 118 Selection unit, 120 SIM, 122 Wireless communication connection, 124 Communication unit, 132 Wired communication line, 200 Access point, 242 Direct communication connection, 300 User terminal, 320 SIM, 322 Wireless communication connection, 400 Communication target, 500 Management device, 502 Storage unit, 504 Acquisition unit, 506 Determination unit, 508 Generation unit, 512 Selection unit, 514 Transmission unit, 600 Access point, 620 SIM, 622 wireless communication connection, 642 direct communication connection, 700 authentication device, 732 wired communication line, 800 CPE switch, 900 authentication device, 932 wired communication line, 1200 computer, 1210 host controller, 1212 CPU, 1214 RAM, 1216 graphic controller, 1218 display device, 1220 input / output controller, 1222 communication interface, 1224 storage device, 1226 DVD drive, 1227 DVD-ROM, 1230 ROM, 1240 input / output chip

Claims

1. An authentication device equipped with a SIM (Subscriber Identity Module), an acquisition unit that acquires authentication information stored in a SIM installed in the user terminal; an authentication unit that executes authentication processing for the user terminal to access the mobile communication network using the authentication information of the user terminal via a wireless communication connection between the authentication device and the mobile communication network supported by the SIM of the authentication device; a relay unit that relays communication of user data between the user terminal and a communication target of the user terminal via a wired communication connection between the authentication device and the mobile communication network; Equipped with the authentication unit executes the authentication process for the user terminal equipped with the SIM that is not compatible with the mobile communication network to access the mobile communication network. Authentication device.

2. The authentication device described in claim 1, wherein the authentication device has a TWIF (Trusted WLAN Interworking Function).

3. An authentication device equipped with a SIM, an acquisition unit that acquires authentication information stored in a SIM installed in the user terminal; an authentication unit that executes authentication processing for the user terminal to access the mobile communication network using the authentication information of the user terminal via a wireless communication connection between the authentication device and the mobile communication network supported by the SIM of the authentication device; a relay unit that relays communication of user data between the user terminal and a communication target of the user terminal via a wired communication connection between the authentication device and the mobile communication network; Equipped with the acquiring unit further acquires communication status information indicating a communication status of communication of the user data between the user terminal and the communication target via the wired communication connection; The authentication device a determination unit that determines whether the communication status indicated by the communication status information satisfies a predetermined communication status condition; Furthermore, the relay unit relays the communication of the user data between the user terminal and the communication target via the wired communication connection when the determination unit determines that the communication situation satisfies the communication situation condition, and relays the communication of the user data between the user terminal and the communication target via the wireless communication connection when the determination unit determines that the communication situation does not satisfy the communication situation condition. Authentication device.

4. The determination unit determines whether or not the communication of the user data in a DL (Down Link) direction between the user terminal and the communication target satisfies QoS (Quality of Service) requirements applied to the communication of the user data in the DL direction between the user terminal and the communication target; the relay unit relays the user data communication between the user terminal and the communication target via the wired communication connection when the determination unit determines that the user data communication in the DL direction between the user terminal and the communication target satisfies the QoS requirements, and relays the user data communication between the user terminal and the communication target via the wireless communication connection when the determination unit determines that the user data communication in the DL direction between the user terminal and the communication target does not satisfy the QoS requirements. The authentication device according to claim 3 .

5. The determination unit determines whether or not the communication of the user data in an UL (Up Link) direction between the user terminal and the communication target satisfies QoS requirements applied to the communication of the user data in the UL direction between the user terminal and the communication target; the relay unit relays the user data communication between the user terminal and the communication target via the wired communication connection when the determination unit determines that the user data communication in the UL direction between the user terminal and the communication target satisfies the QoS requirements, and relays the user data communication between the user terminal and the communication target via the wireless communication connection when the determination unit determines that the user data communication in the UL direction between the user terminal and the communication target does not satisfy the QoS requirements. The authentication device according to claim 3 .

6. The determination unit determines whether or not the communication of the user data in the DL direction between the user terminal and the communication target satisfies the QoS requirements applicable to the communication of the user data in the DL direction between the user terminal and the communication target, and whether or not the communication of the user data in the UL direction between the user terminal and the communication target satisfies the QoS requirements applicable to the communication of the user data in the UL direction between the user terminal and the communication target; the relay unit relays the user data communication between the user terminal and the communication target via the wired communication connection when the determination unit determines that the user data communication in the DL direction between the user terminal and the communication target satisfies the QoS requirements and that the user data communication in the UL direction between the user terminal and the communication target satisfies the QoS requirements, and relays the user data communication between the user terminal and the communication target via the wireless communication connection when the determination unit determines that the user data communication in the DL direction between the user terminal and the communication target does not satisfy the QoS requirements or that the user data communication in the UL direction between the user terminal and the communication target does not satisfy the QoS requirements. The authentication device according to claim 3 .

7. the relay unit relays communication of the user data between each of the plurality of user terminals and the communication target of each of the plurality of user terminals via the wired communication connection; the acquisition unit acquires the communication status information of each of the plurality of user terminals; the determination unit determines whether the communication status indicated by the communication status information of each of the plurality of user terminals satisfies the communication status condition; The authentication device a selection unit that selects, from the plurality of user terminals, a user terminal that switches from communication of the user data via the wired communication connection to communication of the user data via the wireless communication connection based on a predetermined selection condition when there is a user terminal whose communication situation is determined by the determination unit to not satisfy the communication situation condition. Furthermore, the relay unit relays communication of the user data between the user terminal selected by the selection unit and the communication target via the wireless communication connection. The authentication device according to claim 3 .

8. An authentication device equipped with a SIM, an acquisition unit that acquires authentication information stored in a SIM installed in the user terminal; an authentication unit that executes authentication processing for the user terminal to access the mobile communication network using the authentication information of the user terminal via a wireless communication connection between the authentication device and the mobile communication network supported by the SIM of the authentication device; a relay unit that relays communication of user data between the user terminal and a communication target of the user terminal via a wired communication connection between the authentication device and the mobile communication network; a communication unit that communicates with a management device of an MNO (Mobile Network Operator) that manages the authentication device via the wireless communication connection; Equipped with the communication unit receives, from the management device, an OAM (Operations, Administration, and Maintenance) signal instructing to switch relay of the user data communication between the user terminal and the communication target from relay via the wired communication connection to relay via the wireless communication connection; the relay unit switches relay of the communication of the user data between the user terminal and the communication target from relay via the wired communication connection to relay via the wireless communication connection based on the OAM signal. Authentication device.

9. The authentication device according to claim 1 , wherein the acquisition unit acquires the authentication information of the user terminal by receiving the authentication information of the user terminal via an access point that is connected to the authentication device via wired communication.

10. The authentication device according to claim 1 , wherein the acquisition unit acquires the authentication information of the user terminal by receiving the authentication information of the user terminal via a direct communication connection between the user terminal and the authentication device.

11. The authentication device according to claim 1 , wherein the authentication device is a Customer Premises Equipment (CPE).

12. An authentication device equipped with a SIM, an acquisition unit that acquires authentication information stored in a SIM installed in the user terminal; an authentication unit that executes authentication processing for the user terminal to access the mobile communication network using the authentication information of the user terminal via a wireless communication connection between the authentication device and the mobile communication network supported by the SIM of the authentication device; a relay unit that relays communication of user data between the user terminal and a communication target of the user terminal via a wired communication connection between the authentication device and the mobile communication network; Equipped with the authentication device is communicatively connected to the mobile communication network via a wired communication line that connects the authentication device and a router that is an infrastructure of the MNO via a wired communication line, and a communication line that connects the router and the mobile communication network that is the infrastructure of the MNO within the infrastructure of the MNO via a wired communication line. Authentication device.

13. An authentication device according to any one of claims 1 to 8 and 12; an access point connected to the authentication device by wired communication; Equipped with the authentication device receives the authentication information of the user terminal via the access point, thereby acquiring the authentication information of the user terminal; Authentication system.

14. A program that, when executed by a computer, causes the computer to function as the authentication device according to any one of claims 1 to 8 and 12.

Citation Information

Patent Citations

  • Wireless system and wireless communication method

    JP2012147051A

  • Authentication method, access point, and program that allow wireless terminal of third party to connect to access point owned by user

    JP2017034690A