Network node and communication method

The network node system addresses the challenge of controlling private keys and cryptographic primitives by using a Remote Attestation framework with advance information verification, ensuring secure and efficient transitions between cryptographic methods, thus maintaining communication integrity.

WO2025163920A1PCT designated stage Publication Date: 2025-08-07NTT DOCOMO INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/003596
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-02
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing technologies face challenges in properly controlling the use of private keys or cryptographic primitives, particularly with short-term certificates, as on-demand validation is not performed, leading to potential compromises that cannot be efficiently revoked or restricted, and this issue is exacerbated by the transition to Post-Quantum Cryptography.

Method used

A network node system utilizing a Remote Attestation framework where a Relying Party receives advance information from a Verifier to verify the validity of private keys or cryptographic primitives, allowing for controlled use and revocation or restriction without real-time communication, enabling efficient transitions between different cryptographic methods.

Benefits of technology

Enables appropriate control of private keys and cryptographic primitives, allowing for seamless transitions and minimizing service disruptions during cryptographic method changes, such as from TasC-PKI to PQC-PKI, by reducing verification traffic and ensuring secure communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024003596_07082025_PF_FP_ABST
    Figure JP2024003596_07082025_PF_FP_ABST
Patent Text Reader

Abstract

This network node comprises: a reception unit that receives identification information of a secret key or identification information of a cipher primitive from a first network node; a control unit that determines the validity of the secret key or the cipher primitive on the basis of prior information received from a second network node; and a transmission unit that transmits a determination result by the control unit to the first network node.
Need to check novelty before this filing date? Find Prior Art

Description

Network node and communication method

[0001] The present invention relates to a network node in a communication system and a communication method.

[0002] The 3GPP (registered trademark) (3rd Generation Partnership Project) is currently studying a wireless communication system called 5G or NR (New Radio) (hereinafter, the wireless communication system will be referred to as "5G" or "NR") to achieve even larger system capacity, even faster data transmission speeds, and even lower latency in wireless sections. Various wireless technologies are being studied for 5G to meet the requirements of achieving a throughput of 10 Gbps or more while reducing latency in wireless sections to 1 ms or less. Furthermore, 5G has introduced a core network called 5GC (5G Core Network) (see, for example, Non-Patent Document 1).

[0003] Encrypted communications using PKI (Public Key Infrastructure) and the like are commonly used to enhance communication security, not just for 5G. Certificates used in PKI and the like may be revoked before their expiration date for security reasons. Therefore, when using a certificate, it is necessary to check whether the certificate has been revoked. Known methods for this purpose include methods that perform on-demand certificate validity checks, such as OSCP (X.509 Internet Public Key Infrastructure Online Certificate Status Protocol).

[0004] In the method of checking the validity of certificates on demand, the traffic generated by this method may overwhelm the actual communication traffic. For this reason, consideration is being given to short-term certificates that do not check the validity of certificates on demand. Short-term certificates are certificates with a short expiration date.

[0005] 3GPP TS 23.501 V18.1.0(2023-03)

[0006] As described above, on-demand certificate validation is not performed for short-term certificates. Therefore, even if the private key or cryptographic primitives corresponding to a short-term certificate are compromised, it may not be possible to properly revoke or restrict the use of the private key or cryptographic primitives. Note that certificates other than short-term certificates may also encounter issues similar to those of short-term certificates if on-demand certificate validation is not performed.

[0007] The present invention has been made in view of the above points, and aims to provide a technique that enables appropriate control of the use of private keys or cryptographic primitives in a network node.

[0008] According to the disclosed technology, a network node is provided that includes: a receiving unit that receives identification information of a private key or identification information of a cryptographic primitive from a first network node; a control unit that determines the validity of the private key or the cryptographic primitive based on prior information received from a second network node; and a transmitting unit that transmits the determination result by the control unit to the first network node.

[0009] The disclosed technology provides a technology that enables appropriate control of the use of private keys or cryptographic primitives in a network node.

[0010] FIG. 1 is a diagram for explaining an example of a communication system. FIG. 2 is a diagram for explaining an example of a communication system in a roaming environment. FIG. 3 is a diagram for explaining an overview of an embodiment according to the present invention. FIG. 4 is a diagram for explaining processing procedures in the first to third embodiments. FIG. 5 is a diagram for explaining an example of switchback. FIG. 6 is a diagram for explaining an example of the functional configuration of a network node 100 in an embodiment of the present invention. FIG. 7 is a diagram for explaining an example of the functional configuration of a terminal 200 in an embodiment of the present invention. FIG. 8 is a diagram for explaining an example of the hardware configuration of a network node 100 and a terminal 200 in an embodiment of the present invention. FIG. 9 is a diagram for explaining an example of the configuration of a vehicle 2001 in an embodiment of the present invention.

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Note that the embodiment described below is an example, and the embodiment to which the present invention is applied is not limited to the following embodiment.

[0012] In the operation of the wireless communication system according to the embodiment of the present invention, an existing technology is used as appropriate. However, the existing technology is, for example, the existing LTE or NR, but is not limited to the existing LTE or NR.

[0013] In this embodiment, a technique for determining whether to use a private key or a cryptographic primitive corresponding to a short-term validity certificate in an environment where the certificate is used will be described.

[0014] Here, we will first explain a 5G communication system (network) as an example of a communication system in which encrypted communication using short-term validity certificates can be performed. FIG. 1 is a diagram for explaining this example of a communication system. As shown in FIG. 1, this communication system is composed of a terminal (UE) and multiple network nodes. Hereinafter, it is assumed that one network node corresponds to each function, but multiple functions may be realized by one network node, or multiple network nodes may realize one function. Furthermore, the "connection" described below may be a logical connection or a physical connection.

[0015] A Radio Access Network (RAN) is a network node having a radio access function, which may include a base station, and is connected to a UE, an Access and Mobility Management Function (AMF), and a User Plane Function (UPF). The AMF is a network node having functions such as terminating the RAN interface, terminating the Non-Access Stratum (NAS), registering management, connecting management, reachability management, and mobility management. The UPF is a network node having functions such as a Protocol Data Unit (PDU) session point to the outside that interconnects with a Data Network (DN), routing and forwarding packets, and handling user plane Quality of Service (QoS). The UPF and the DN constitute a network slice. In a wireless communication network according to an embodiment of the present invention, multiple network slices are constructed.

[0016] The AMF is connected to the UE, RAN, SMF (Session Management function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (Network Repository Function), UDM (Unified Data Management), AUSF (Authentication Server Function), PCF (Policy Control Function), and AF (Application Function). The AMF, SMF, NSSF, NEF, NRF, UDM, AUSF, PCF, and AF are network nodes interconnected via interfaces based on their respective services: Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.

[0017] The SMF is a network node that has functions such as session management, UE IP (Internet Protocol) address allocation and management, DHCP (Dynamic Host Configuration Protocol) function, ARP (Address Resolution Protocol) proxy, and roaming function. The NEF is a network node that has the function of notifying other NFs (Network Functions) of capabilities and events. The NSSF is a network node that has functions such as selecting a network slice to which a UE connects, determining the allowed NSSAI (Network Slice Selection Assistance Information), determining the NSSAI to be configured, and determining the AMF set to which the UE connects. The PCF is a network node that has the function of controlling network policies. The AF is a network node that has the function of controlling application servers. The NRF is a network node that has the function of discovering NF instances that provide services. The UDM is a network node that manages subscriber data and authentication data. The UDM is connected to a UDR (User Data Repository) that stores the data.

[0018] 2 is a diagram illustrating an example of a communication system in a roaming environment. As shown in FIG. 2, the network is made up of a UE and a plurality of network nodes.

[0019] The SEPP is a non-transparent proxy that filters control plane messages between PLMNs (Public Land Mobile Networks). The vSEPP shown in Figure 2 is a SEPP in a visited network, and the hSEPP is a SEPP in a home network.

[0020] As shown in Figure 2, a UE is in a roaming environment connected to a RAN and an AMF in a Visited PLMN (VPLMN). The VPLMN and a Home PLMN (HPLMN) are connected via a vSEPP and an hSEPP. The UE can communicate with a UDM in the HPLMN via the AMF in the VPLMN, for example.

[0021] (Regarding short-lived certificates and remote attestation) As mentioned above, methods such as OSCP that perform on-demand certificate validation may cause the traffic generated by such methods to overwhelm the actual communication traffic. For this reason, studies are underway to develop short-lived certificates that do not perform on-demand certificate validation (for example, E. Topalovic, B. Saeta, LS Huang, C. Jackson, and D. Boneh, "Towards Short-Lived Certificates," IEEE Oakland Web 2.0 Security and Privacy (W2SP 2012), May 2012, https: / / www.ieee-security.org / TC / W2SP / 2012 / papers / w2sp12-final9.pdf).

[0022] Meanwhile, with the advancement of cloud usage, Zero Trust Architecture (hereinafter referred to as ZTA) has been proposed for cloud security. Unlike traditional perimeter-based security, ZTA involves some form of verification / authentication for resources in cloud environments. For example, when using private keys, Remote Attestation is a typical method for verification / authentication. Remote Attestation is described, for example, in "Henk Birkholz, et al., 'Remote ATtestation procedures (RATS) Architecture,' RFC9334, January 2023."<https: / / datatracker.ietf.org / doc / html / rfc9334> " is disclosed in

[0023] Short-term certificates are not subject to on-demand certificate validation, so even if the private key or cryptographic primitives associated with a short-term certificate are compromised, the private key or cryptographic primitives may not be properly revoked or restricted.

[0024] In particular, in the anticipated future transition to cryptographic primitives that are resistant to quantum computers, it is important to respond to the compromise of cryptographic primitives, and it is necessary to respond efficiently while maintaining service continuity.

[0025] As mentioned above, the use of short-term certificates can reduce traffic on the OSCP. However, there is a problem in that it is not possible to properly control the use of private keys or cryptographic primitives when they are compromised.

[0026] For example, when migrating to PQC (Post-Quantum Cryptography), certificates for a PKI (hereinafter referred to as TasC-PKI) configured using a traditional cryptographic method (hereinafter referred to as TasC: Traditional asymmetric key Cipher) and certificates for a PKI (hereinafter referred to as PQC-PKI) configured using PQC must exist simultaneously on a terminal (e.g., a PC) in order to maintain service continuity.

[0027] When a terminal transitions from using a TasC-PKI certificate to using a PQC-PKI certificate, if a problem occurs in the PQC-PKI environment (e.g., a problem due to a compromise), it is necessary to quickly return to the TasC-PKI environment and minimize service interruptions. However, with conventional technologies, it is difficult to appropriately control such usage.

[0028] (Outline of the Embodiments) Below, first to third embodiments of the technology for solving the above problems will be described, but first an outline of the embodiments will be described. In the following description, "A / B" means "A or B" unless it is clear from the context that it has a different meaning. Furthermore, "A or B" includes only A, only B, and "A and B."

[0029] In this embodiment, it is assumed that communication is performed using short-term validity certificates in a communication system having multiple network nodes. Hereinafter, a "certificate" refers to a short-term validity certificate. However, the scope of application of the technology according to the present invention is not limited to short-term validity certificates. The technology according to the present invention can also be applied to certificates other than short-term validity certificates.

[0030] The network node may be a terminal, a server, a base station, or any other node.

[0031] Examples of communications using short-term validity certificates include the following (1) to (3).

[0032] (1) Network node A obtains a certificate for network node B, encrypts data using the public key included in the certificate, and sends the encrypted data to network node B, which decrypts the data using its own private key.

[0033] (2) Network node A signs data with its own private key and transmits the data and the signature to network node B. Network node B obtains the certificate of network node A and verifies the signature using the public key included in the certificate.

[0034] (3) Network node A obtains a certificate from network node B, verifies the authenticity of the certificate, and then shares a common key and performs encrypted communication between network node A and network node B using the common key.

[0035] In this embodiment, the private key / cryptographic primitives are verified using a Remote Attestation (RA) framework. The cryptographic primitives are, for example, information described in "Subject Public Key Info" in a certificate. Verifying the private key / cryptographic primitives associated with a certificate may also be expressed as verifying the certificate.

[0036] The above "verification" also includes checking whether the software is sound, whether it has been compromised, whether it can be used, whether it is valid or invalid, and the like.

[0037] Fig. 3 shows an example of the configuration of a verification system according to this embodiment. As shown in Fig. 3, this communication system includes an attester 10, a relying party 20, and a verifier 30. The attester 10, the relying party 20, and the verifier 30 are each connected to a network and are capable of communicating with other devices.

[0038] The Attester 10, the Relying Party 20, and the Verifier 30 are each a network node that includes a communication function. The Attester 10, the Relying Party 20, and the Verifier 30 may each be any network node, such as a terminal, a base station, a server, or a virtual machine on a cloud.

[0039] In a general RA framework, an Attester 10 is a device that wants to prove that it is a trustworthy device, a Relying Party 20 is a device that wants to confirm that the Attester 10 is a trustworthy device, and a Verifier 30 is a device that mediates the verification of trust between the Attester 10 and the Relying Party 20.

[0040] In a typical RA framework (e.g., background check model), the Attester 10 presents evidence that it is in a trustworthy environment to the Relying Party 20, and the Relying Party 20 presents the evidence received from the Attester 10 to the Verifier 30.

[0041] The Verifier 30 verifies the Evidence received from the Relying Party 20 and presents an Attestation result indicating that the Attester 10 that presented the Evidence is trustworthy to the Relying Party 20. The Relying Party 20 checks the Attestation result presented by the Verifier 30 and returns a result to the Attester 10.

[0042] In this embodiment, unlike the general RA framework described above, the Relying Party 20 does not perform the above-described real-time communication with the Verifier 30 (communication is suppressed), and the Relying Party 20 obtains in advance information necessary for verifying the private key / cryptographic primitives from the Verifier 30. This reduces the traffic between the Relying Party 20 and the Verifier 30.

[0043] Furthermore, the Relying Party 20 in this embodiment can make a judgment specific to the Attester 10 for each service or for each authentication domain such as PKI. For example, even if a cryptographic primitive in a certain certificate has been compromised, it is possible to make a judgment such as permitting the use of a private key for purposes other than encryption (e.g., pseudo-random number generation).

[0044] An overview of the operation of the verification system in this embodiment will be described with reference to Fig. 3. Here, it is assumed that the Relaying Party 20 has already received and stored advance information (advance instructions) from the Verifier 30.

[0045] In S1, the Attester 10 transmits "information about the private key or information about the cryptographic primitives" related to the certificate to be verified as Evidence to the Relaying party 20. In S2, the Relying Parity 20 performs verification by referring to the prior information from the Verifier 30. The verification result indicates, for example, whether the private key / cryptographic primitives can be used.

[0046] In S3, the Relying Parity 20 returns the verification result to the Attester 10. In S4, the Attester 10 determines whether to use the secret key / cryptographic primitive based on the received verification result.

[0047] The Relying Parity 20 and the Attester 10 may be configured as a single device (network node). In this case, the network node can determine by itself whether or not the private key / cryptographic primitive can be used, based on the prior information received from the Verifier 30.

[0048] Furthermore, in this embodiment, an example is described in which the technology according to the present invention is implemented within the framework of RA, but the technology according to the present invention can also be implemented without using RA.

[0049] Each embodiment will be described below.

[0050] First Embodiment First, the first embodiment will be described. In the case of short-term certificates assumed for use in each embodiment, on-demand certificate revocation checks are not performed. Therefore, problems may arise if a factor that is difficult to predict that could compromise a private key / cryptographic primitive occurs.

[0051] In addition, in consideration of the future transition to PQC, it is desirable to have a mechanism to transition currently used private keys / cryptographic primitives to a compromised state (a state of inhibited use) in order to inhibit their use even if they are currently secure.

[0052] The operation of the verification system according to the first embodiment for solving the above problem will be described with reference to FIG.

[0053] In S0, the Verifier 30 notifies the Relying Party 20 of the "identification information of the private key to be revoked / identification information of the cryptographic primitive to be revoked" as advance information. The reason for revoking the private key is, for example, a compromise such as key leakage / insufficient key length.

[0054] Furthermore, for example, in order to transition to PQC, advance information may be created to intentionally disable (or restrict the use of) a specific private key / specific cryptographic primitive.

[0055] The relying party 20 holds the prior information. By notifying the prior information, traffic relating to verification between the verifier 30 and the relying party 20 can be suppressed.

[0056] The prior information sent from the Verifier 30 to the Relying Party 20 may be updated periodically or whenever there is a change in the prior information.

[0057] In S1, the Attester 10 transmits, as Evidence, the "identification information of the private key / identification information of the cryptographic primitive" to be verified to the Relying Party 20. The identification information of the private key is, for example, the hash value of the private key. The identification information of the cryptographic primitive is, for example, an OID.

[0058] In S2, the Relying party 20 compares the received Evidence with the prior information to determine whether the private key / cryptographic primitive notified as Evidence should be invalidated. In S3, the Relying party 20 notifies the Attester 10 of the determination result (verification result) as "result."

[0059] If the Attester 10 receives a verification result indicating that the target private key / cryptographic primitive should be invalidated, in S4, the Attester 10 invalidates the private key / cryptographic primitive and will not use the private key / cryptographic primitive in the future.

[0060] In addition, the relying party 20 may notify the attester 10 of a result indicating that the private key / cryptographic primitive should be invalidated when it detects an event (such as a compromise) that requires the private key / cryptographic primitive to be invalidated, regardless of whether or not it has received evidence from the attester 10.

[0061] <Effects of First Embodiment> The technology according to the first embodiment makes it possible to confirm the validity of private keys / cryptographic primitives in an environment where short-term validity certificates are used (e.g., an mTLS (Mutual Transport Layer Security) environment) without performing on-demand revocation checking using OSCP or the like.

[0062] Furthermore, the technology according to the first embodiment makes it possible to invalidate a specific private key / specific cryptographic primitive in order to proceed with the transition to PQC, for example.

[0063] Second Embodiment In the second and third embodiments, it is assumed that TasC-PKI certificates and PQC-PKI certificates coexist in a communication system (verification system).

[0064] As described above, assume that in an environment where TasC-PKI certificates and PQC-PKI certificates coexist, the Attester 11 and the Attester 12 communicate using, for example, mTLS. In this case, for example, when the Attester 12 uses PQC-PKI, if the Attester 11 can use both PQC-PKI and TasC-PKI, there is a possibility that a session cannot be properly established using mTLS. Therefore, it is necessary to prevent the Attester 11 from using TasC-PKI.

[0065] Therefore, in the second embodiment, the Attester is restricted from using TasC-PKI.

[0066] The processing in the second embodiment will be described along the procedure shown in FIG.

[0067] In S0, the Verifier 30 notifies the Relying Party 20 of the "private key identification information / cryptographic primitive identification information" as advance information for restricting the use of TasC-PKI.

[0068] In S1, the Attester 10 transmits to the Relying party 20, as evidence, the "identification information of the private key / identification information of the cryptographic primitive" that the Attester wishes to verify.

[0069] In S2, the Relying party 20 compares the received Evidence with the prior information to determine whether or not to suppress the use of the private key / cryptographic primitive notified as Evidence. That is, if the private key / cryptographic primitive notified as Evidence corresponds to the TasC-PKI notified as prior information, the Relying party 20 determines that the use of the private key / cryptographic primitive notified as Evidence should be suppressed, and creates a result indicating "suppressed."

[0070] In S3, the relying party 20 notifies the attester 10 of the judgment result (verification result) as a result.

[0071] If the Attester 10 receives a verification result indicating that the use of the target private key / cryptographic primitive should be restricted, then in S4, the Attester 10 restricts the use of the private key / cryptographic primitive (i.e., the use of TasC-PKI).

[0072] In this embodiment, it is assumed that a short-term validity certificate is used as the TasC-PKI certificate. Therefore, by introducing PQC-PKI to an Attester before the TasC-PKI certificate expires, the Attester can perform mTLS communication with other Attesters using PQC after the TasC-PKI certificate expires.

[0073] Furthermore, by the above-described processing in the second embodiment, after PQC-PKI is introduced, even before the TasC-PKI certificate expires, the use of TasC-PKI can be suppressed and mTLS communication can be performed using PQC.

[0074] <Effects of the Second Embodiment> The technology according to the second embodiment can suppress the use of TasC-PKI in the Attester.

[0075] Third Embodiment Next, a third embodiment will be described. The situation in the third embodiment is assumed to be the situation after the use of TasC-PKI in the Attester 10 in the second embodiment has been restricted.

[0076] In the second embodiment, it is assumed that a problem occurs when the Attester 10 uses PQC-PKI after the Attester 10 has restricted use of TasC-PKI. In this case, it becomes necessary to switch back to TasC-PKI.

[0077] In the third embodiment, the above-described switchback is achieved by enabling TasC-PKI, which has been inhibited from being used. By enabling TasC-PKI, it becomes possible to establish a session using mTLS again using TasC-PKI.

[0078] The processing in the third embodiment will be described along the procedure shown in FIG.

[0079] In S0, the Verifier 30 notifies the Relying Party 20 of the "private key identification information / cryptographic primitive identification information" as advance information for lifting the restriction on use of TasC-PKI.

[0080] In S1, the Attester 10 transmits to the Relying party 20, as evidence, the "identification information of the private key / identification information of the cryptographic primitive" that the Attester wishes to verify.

[0081] In S2, the Relying party 20 compares the received Evidence with the prior information to determine whether or not to release the restriction on use of the private key / cryptographic primitive notified as Evidence. That is, if the private key / cryptographic primitive notified as Evidence corresponds to the TasC-PKI notified as the prior information for which the restriction on use should be released, the Relying party 20 determines that the restriction on use of the private key / cryptographic primitive notified as Evidence should be released, and creates a result indicating "release."

[0082] In S3, the relying party 20 notifies the attester 10 of the judgment result (verification result) as a result.

[0083] If the Attester 10 receives a verification result indicating that the restriction on the use of the target private key / cryptographic primitive should be lifted, in S4, the Attester 10 lifts the restriction on the use of the private key / cryptographic primitive (i.e., the restriction on the use of TasC-PKI).

[0084] Assume that the communication partner of the Attester 10 is the Attester 13. Here, for example, if the Attester 13 is an Attester that uses only TasC-PKI, the above procedure releases the restriction on the use of the private key / cryptographic primitives of TasC-PKI in the Attester 10, making it possible to use TasC-PKI in the mTLS session negotiation between the Attester 10 and the Attester 13, and switching back to the original state (proven state) is possible.

[0085] Another example of a situation in which switchback is performed is shown in Fig. 5. In the example of Fig. 5, first, Attester 11 and Attester 12 are communicating in TasC-PKI.

[0086] Subsequently, the TasC-PKI certificate (short-term certificate (SLC)) of the attester 11 is revoked. This revocation may occur because the validity period has expired, or may occur before the validity period has expired based on a result from the relying party 20.

[0087] When the TasC-PKI certificate of the attester 11 expires, communication is performed between the attester 11 and the attester 12 in accordance with the PQC-PKI.

[0088] If a problem subsequently occurs in communication using the PQC-PKI, reversion is performed using the process described in the third embodiment. That is, the relying party 20 notifies the relying party 20 from the verifier 30 of advance information corresponding to the TasC-PKI to be revoked, and the relying party 20 notifies the attester 11 of the revocation of the TasC-PKI as the verification result. This allows communication using the TasC-PKI between the attester 11 and the attester 12.

[0089] <Effects of the Technology According to the Third Embodiment> The technology according to the third embodiment makes it possible to release the restriction on the use of TasC-PKI in the Attester.

[0090] (Device Configuration) Next, an example of the functional configuration of the network node 100 (Attester 10, Relying party 20, Verifier 30, etc.) and the terminal 200 (Attester 10, Relying party 20, Verifier 30, etc.) that perform the processes and operations described above will be described. Note that the terminal is an example of a network node, but here it is assumed that the network node 100 is a network node other than the terminal 200.

[0091] <Network Node 100> Fig. 6 is a diagram showing an example of the functional configuration of the network node 100. As shown in Fig. 6, the network node 100 has a transmitting unit 110, a receiving unit 120, a setting unit 130, and a control unit 140. The functional configuration shown in Fig. 6 is merely an example. The names of the functional divisions and functional units may be any names as long as they can perform the operations related to the embodiment of the present invention.

[0092] The transmitter 110 has a function of generating a signal to be transmitted to the terminal 200 or a network node and transmitting the signal via a wired or wireless connection. The receiver 120 has a function of receiving various signals transmitted from the terminal 200 or a network node and acquiring, for example, information of a higher layer from the received signal. A communication unit including the transmitter 110 and the receiver 120 may be configured.

[0093] The setting unit 130 stores pre-set setting information and various setting information to be transmitted to the terminal 200 or the network node in a storage device, and reads out the information from the storage device as needed. The control unit 140 controls the network node 100. The function unit related to signal transmission in the control unit 140 may be included in the transmitting unit 110, and the function unit related to signal reception in the control unit 140 may be included in the receiving unit 120. The transmitting unit 110 and the receiving unit 120 may be called a transmitter and a receiver, respectively.

[0094] <Terminal 200> Fig. 7 is a diagram showing an example of the functional configuration of terminal 200. As shown in Fig. 7, terminal 200 has a transmitting unit 210, a receiving unit 220, a setting unit 230, and a control unit 240. The functional configuration shown in Fig. 20 is merely an example. The names of the functional divisions and functional units may be any as long as they can perform the operations related to the embodiment of the present invention.

[0095] The transmitter 210 creates a transmission signal from transmission data and transmits the transmission signal wirelessly. The receiver 220 receives various signals wirelessly and acquires higher layer signals from the received physical layer signals. The receiver 220 also has a function of receiving NR-PSS, NR-SSS, NR-PBCH, DL / UL control signals, reference signals, and the like transmitted from a network node. A communication unit including the transmitter 210 and the receiver 220 may be configured.

[0096] The setting unit 230 stores various setting information received from the network node by the receiving unit 220 in a storage device, and reads it out from the storage device as needed. The setting unit 230 also stores setting information that is set in advance.

[0097] The control unit 240 controls the terminal 200. The functional unit in the control unit 240 related to signal transmission may be included in the transmitting unit 210, and the functional unit in the control unit 240 related to signal reception may be included in the receiving unit 220. The transmitting unit 210 and the receiving unit 220 may be called a transmitter and a receiver, respectively.

[0098] (Hardware Configuration) The block diagrams (FIGS. 6 and 7) used to explain the above embodiments show functional blocks. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are connected directly or indirectly (for example, using wires, wirelessly, etc.) and these multiple devices. The functional block may be realized by combining software with the single device or the multiple devices.

[0099] Functions include, but are not limited to, judgment, determination, assessment, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, resolution, selection, selection, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, and assignment. For example, a functional block (component) that performs transmission is called a transmitting unit or transmitter. As mentioned above, there are no particular limitations on how these functions are implemented.

[0100] For example, the network node 100 and the terminal 200 according to an embodiment of the present disclosure may function as a computer that performs processing of the communication method of the present disclosure. Fig. 8 is a diagram illustrating an example of the hardware configuration of the network node 100 and the terminal 200 according to an embodiment of the present disclosure. The network node 100 and the terminal 200 described above may be physically configured as a computer device including a processor 1001, a storage device 1002, an auxiliary storage device 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, etc.

[0101] In the following description, the term "apparatus" can be read as a circuit, a device, a unit, etc. The hardware configuration of the network node 100 and the terminal 200 may be configured to include one or more of the apparatuses shown in the drawings, or may be configured to exclude some of the apparatuses.

[0102] Each function in the network node 100 and the terminal 200 is realized by loading specified software (programs) onto hardware such as the processor 1001, the memory device 1002, etc., so that the processor 1001 performs calculations, controls communication via the communication device 1004, and controls at least one of reading and writing data in the memory device 1002 and the auxiliary memory device 1003.

[0103] The processor 1001 controls the entire computer by running, for example, an operating system. The processor 1001 may be configured as a central processing unit (CPU) including an interface with peripheral devices, a control device, an arithmetic unit, a register, etc. For example, the above-mentioned control unit 140, control unit 240, etc. may be realized by the processor 1001.

[0104] Furthermore, the processor 1001 reads programs (program codes), software modules, data, etc. from at least one of the auxiliary storage device 1003 and the communication device 1004 into the storage device 1002 and executes various processes in accordance with the programs. The programs used are those that cause a computer to execute at least some of the operations described in the above-described embodiments. For example, the control unit 140 of the network node 100 shown in FIG. 6 may be implemented by a control program stored in the storage device 1002 and running on the processor 1001. Furthermore, for example, the control unit 240 of the terminal 200 shown in FIG. 7 may be implemented by a control program stored in the storage device 1002 and running on the processor 1001. While the above-described various processes have been described as being executed by one processor 1001, they may also be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may be implemented by one or more chips. The programs may also be transmitted from a network via a telecommunications line.

[0105] The storage device 1002 is a computer-readable recording medium and may be configured, for example, by at least one of a read-only memory (ROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a random access memory (RAM), etc. The storage device 1002 may also be called a register, a cache, a main memory, etc. The storage device 1002 can store executable programs (program codes), software modules, etc. for implementing a communication method according to an embodiment of the present disclosure.

[0106] The secondary storage device 1003 is a computer-readable recording medium, and may be, for example, at least one of an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disk, a digital versatile disk, a Blu-ray (registered trademark) disk), a smart card, a flash memory (e.g., a card, a stick, a key drive), a floppy (registered trademark) disk, a magnetic strip, etc. The above-mentioned storage medium may be, for example, a database, a server, or other appropriate medium including at least one of the storage device 1002 and the secondary storage device 1003.

[0107] The communication device 1004 is hardware (transmission / reception device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as, for example, a network device, a network controller, a network card, a communication module, etc. The communication device 1004 may be configured to include a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc. to realize at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, a transmission / reception antenna, an amplifier unit, a transmission / reception unit, a transmission path interface, etc. may be realized by the communication device 1004. The transmission / reception unit may be implemented as a transmission unit and a reception unit that are physically or logically separated.

[0108] The input device 1005 is an input device (e.g., a keyboard, a mouse, a microphone, a switch, a button, a sensor, etc.) that receives input from the outside. The output device 1006 is an output device (e.g., a display, a speaker, an LED lamp, etc.) that outputs to the outside. Note that the input device 1005 and the output device 1006 may be integrated into one device (e.g., a touch panel).

[0109] Furthermore, each device such as the processor 1001 and the storage device 1002 is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus, or may be configured using different buses between each device.

[0110] Furthermore, the network node 100 and the terminal 200 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA), and some or all of the functional blocks may be realized by the hardware. For example, the processor 1001 may be implemented using at least one of these pieces of hardware.

[0111] 9 shows an example configuration of a vehicle 2001. As shown in FIG. 9 , the vehicle 2001 includes a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a shift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021 to 2029, an information service unit 2012, and a communication module 2013. Each aspect / embodiment described in the present disclosure may be applied to a communication device mounted on the vehicle 2001, and may be applied to the communication module 2013, for example. For example, the network node 100 or the terminal 200 may be included in the communication module 2013.

[0112] The drive unit 2002 is configured, for example, by an engine, a motor, or a hybrid of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also called a handle) and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel operated by the user.

[0113] The electronic control unit 2010 is composed of a microprocessor 2031, a memory (ROM, RAM) 2032, and a communication port (IO port) 2033. Signals are input to the electronic control unit 2010 from various sensors 2021 to 2029 provided in the vehicle 2001. The electronic control unit 2010 may also be called an ECU (Electronic Control Unit).

[0114] The signals from the various sensors 2021 to 2029 include a current signal from a current sensor 2021 that senses the current of the motor, a rotation speed signal of the front and rear wheels obtained by a rotation speed sensor 2022, an air pressure signal of the front and rear wheels obtained by an air pressure sensor 2023, a vehicle speed signal obtained by a vehicle speed sensor 2024, an acceleration signal obtained by an acceleration sensor 2025, an accelerator pedal depression amount signal obtained by an accelerator pedal sensor 2029, a brake pedal depression amount signal obtained by a brake pedal sensor 2026, a shift lever operation signal obtained by a shift lever sensor 2027, and a detection signal for detecting obstacles, vehicles, pedestrians, etc. obtained by an object detection sensor 2028.

[0115] The information service unit 2012 is composed of various devices, such as a car navigation system, an audio system, speakers, a television, and a radio, for providing (outputting) various types of information, such as driving information, traffic information, and entertainment information, and one or more ECUs for controlling these devices. The information service unit 2012 uses information acquired from external devices via the communication module 2013 or the like to provide various types of multimedia information and multimedia services to the occupants of the vehicle 2001. The information service unit 2012 may include input devices (e.g., a keyboard, a mouse, a microphone, a switch, a button, a sensor, a touch panel, etc.) that accept input from the outside, and may also include output devices (e.g., a display, a speaker, an LED lamp, a touch panel, etc.) that output information to the outside.

[0116] The driving assistance system unit 2030 is composed of various devices that provide functions for preventing accidents and reducing the driving burden on the driver, such as millimeter-wave radar, LiDAR (Light Detection and Ranging), cameras, positioning locators (e.g., GNSS, etc.), map information (e.g., high-definition (HD) maps, autonomous vehicle (AV) maps, etc.), gyro systems (e.g., IMU (Inertial Measurement Unit), INS (Inertial Navigation System), etc.), AI (Artificial Intelligence) chips, and AI processors, as well as one or more ECUs that control these devices. In addition, the driving assistance system unit 2030 transmits and receives various information via the communication module 2013 to realize the driving assistance function or the autonomous driving function.

[0117] The communication module 2013 can communicate with the microprocessor 2031 and components of the vehicle 2001 via the communication port. For example, the communication module 2013 transmits and receives data via the communication port 2033 to and from the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axle 2009, microprocessor 2031 and memory (ROM, RAM) 2032 in the electronic control unit 2010, and sensors 2021 to 29, which are provided in the vehicle 2001.

[0118] The communication module 2013 is a communication device that can be controlled by the microprocessor 2031 of the electronic control unit 2010 and can communicate with an external device. For example, it transmits and receives various information to and from the external device via wireless communication. The communication module 2013 may be located either inside or outside the electronic control unit 2010. The external device may be, for example, a base station, a terminal, a network node, or the like.

[0119] The communication module 2013 may transmit, via wireless communication, to an external device at least one of signals from the various sensors 2021-2028 input to the electronic control unit 2010, information obtained based on the signals, and information based on input from the outside (user) obtained via the information service unit 2012. The electronic control unit 2010, the various sensors 2021-2028, the information service unit 2012, etc. may be referred to as input units that accept input.

[0120] The communication module 2013 receives various information (traffic information, traffic signal information, vehicle-to-vehicle information, etc.) transmitted from external devices and displays it on an information service unit 2012 provided in the vehicle 2001. The information service unit 2012 may be called an output unit that outputs information (for example, outputs information to a device such as a display or speaker based on the PDSCH (or data / information decoded from the PDSCH) received by the communication module 2013). The communication module 2013 also stores the various information received from external devices in a memory 2032 that can be used by the microprocessor 2031. Based on the information stored in the memory 2032, the microprocessor 2031 may control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axles 2009, sensors 2021 to 2029, etc. provided in the vehicle 2001.

[0121] Furthermore, when the communication module 2013 includes the network node 100 (or the terminal 200), the communication module 2013 can perform the operations of the network node 100 (or the terminal 200) described above.

[0122] This specification discloses at least the configurations described in the appendices below.

[0123] <Supplementary Notes> (Supplementary Item 1) A network node comprising: a receiver that receives identification information of a private key or identification information of a cryptographic primitive from a first network node; a controller that determines the validity of the private key or the cryptographic primitive based on prior information received from a second network node; and a transmitter that transmits the determination result by the controller to the first network node. (Supplementary Item 2) The network node according to Supplementary Item 1, wherein the private key or the cryptographic primitive is a private key or cryptographic primitive corresponding to a short-term validity certificate. (Supplementary Item 3) The network node according to Supplementary Item 1 or 2, wherein the prior information is identification information indicating a private key or cryptographic primitive to be revoked. (Supplementary Item 4) The network node according to any one of Supplementary Items 1 to 3, wherein the prior information is information corresponding to a specific public key cryptosystem whose usage restriction is to be released. (Supplementary Item 5) The network node according to any one of Supplementary Items 1 to 4, wherein the prior information is information corresponding to a specific public key cryptosystem whose usage restriction is to be released. (Supplementary clause 6) A communication method executed by a network node, comprising: a step of receiving identification information of a private key or identification information of a cryptographic primitive from a first network node; a judgment step of judging the validity of the private key or the cryptographic primitive based on prior information received from a second network node; and a step of transmitting the judgment result of the judgment step to the first network node.

[0124] Any of Supplementary Items 1 to 6 provides a technique that enables appropriate control of the use of private keys or cryptographic primitives in a network node. Supplementary Item 2 enables appropriate control of certificate use when using short-term validity certificates. Supplementary Item 3 enables prior information to be used to identify private keys or cryptographic primitives that should be appropriately revoked. Supplementary Item 4 enables the use of a specific public key cryptosystem to be restricted. Supplementary Item 5 enables the use of a specific public key cryptosystem that has been restricted to be resumed.

[0125] (Supplementary Notes on the Embodiments) Although the embodiments of the present invention have been described above, the disclosed invention is not limited to such embodiments, and those skilled in the art will understand various modifications, alterations, alternatives, and substitutions. While specific numerical examples have been used to facilitate understanding of the invention, unless otherwise specified, these numerical values ​​are merely examples, and any appropriate values ​​may be used. The division of items in the above description is not essential to the present invention. Two or more items may be combined as needed, and items described in one item may apply to items described in another item (as long as there is no contradiction). Boundaries between functional units or processing units in functional block diagrams do not necessarily correspond to physical component boundaries. The operations of multiple functional units may be physically performed by a single component, or the operations of a single functional unit may be physically performed by multiple components. The order of processing steps described in the embodiments may be reversed as long as there is no contradiction. For convenience of processing description, the network node 100 and the terminal 200 have been described using functional block diagrams. However, such devices may be implemented using hardware, software, or a combination thereof. The software operated by the processor of the network node 100 in accordance with an embodiment of the present invention and the software operated by the processor of the terminal 200 in accordance with an embodiment of the present invention may each be stored in random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, registers, hard disk (HDD), removable disk, CD-ROM, database, server or any other suitable storage medium.

[0126] Furthermore, the notification of information is not limited to the aspects / embodiments described in the present disclosure, and may be performed using other methods. For example, the notification of information may be performed by physical layer signaling (e.g., Downlink Control Information (DCI), Uplink Control Information (UCI)), higher layer signaling (e.g., Radio Resource Control (RRC) signaling, Medium Access Control (MAC) signaling), broadcast information (Master Information Block (MIB), System Information Block (SIB)), other signals, or a combination thereof. Furthermore, the RRC signaling may be referred to as an RRC message, and may be, for example, an RRC Connection Setup message, an RRC Connection Reconfiguration message, or the like.

[0127] Each aspect / embodiment described in the present disclosure may be implemented using any of the following standards: LTE (Long Term Evolution), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), 6th generation mobile communication system (6G), xth generation mobile communication system (xG) (xG (x is, for example, an integer or a decimal number)), FRA (Future Radio Access), NR (new Radio), New radio access (NX), Future generation radio access (FX), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.17 (WiMAX (registered trademark)), IEEE 802.19 (WiMAX (registered trademark)), IEEE 802.20 (WiMAX (registered trademark)), IEEE 802.21 (Wi-Fi (registered trademark)), IEEE 802.22 (WiMAX (registered trademark)), IEEE 802.23 (WiMAX (registered trademark)), IEEE 802.24 (WiMAX (registered trademark)), IEEE 802.25 (WiMAX (registered trademark)), IEEE 802.26 (WiMAX (registered trademark)), IEEE 802.27 (WiMAX (registered trademark)), IEEE 802.28 (WiMAX (registered trademark)), IEEE 802.29 (WiMAX (registered trademark)), IEEE 802.30 (WiMAX (registered trademark)), IEEE 802.31 (Wi-Fi (registered trademark)), IEEE 802.32 (WiMAX (registered trademark)), IEEE 802.33 (WiMAX (registered trademark)), IEEE 802.34 ( The present invention may be applied to at least one of systems using 802.20, UWB (Ultra-Wide Band), Bluetooth (registered trademark), or other suitable systems, and next-generation systems that are extended, modified, created, or defined based on these systems. The present invention may also be applied to a combination of multiple systems (e.g., a combination of LTE and / or LTE-A with 5G).

[0128] The order of the procedures, sequences, flowcharts, etc. of each aspect / embodiment described herein may be rearranged unless it is consistent. For example, the methods described in this disclosure present elements of various steps using an example order and are not limited to the particular order presented.

[0129] In this specification, a specific operation that is described as being performed by a base station may be performed by its upper node in some cases. In a network consisting of one or more network nodes having a base station, it is clear that various operations performed for communication with the terminal 200 may be performed by at least one of the base station and another network node other than the base station (for example, an MME or an S-GW, etc., but are not limited to these). Although the above example illustrates a case where there is one other network node other than the base station, the other network node may be a combination of multiple other network nodes (for example, an MME and an S-GW).

[0130] The information, signals, etc. described in the present disclosure may be output from a higher layer (or a lower layer) to a lower layer (or a higher layer), or may be input / output via multiple network nodes.

[0131] Input and output information may be stored in a specific location (for example, memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be transmitted to another device.

[0132] In the present disclosure, the determination may be made by a value represented by one bit (0 or 1), by a Boolean value (true or false), or by a comparison of numerical values ​​(e.g., comparison with a predetermined value).

[0133] Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc., whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.

[0134] Software, instructions, information, etc. may also be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then these wired and / or wireless technologies are included within the definition of transmission media.

[0135] The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.

[0136] Note that terms described in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings. For example, at least one of a channel and a symbol may be a signal (signaling). Furthermore, a signal may be a message. Furthermore, a component carrier (CC) may be called a carrier frequency, a cell, a frequency carrier, etc.

[0137] As used in this disclosure, the terms "system" and "network" are used interchangeably.

[0138] Furthermore, the information, parameters, etc. described in the present disclosure may be expressed using absolute values, may be expressed using relative values ​​from a predetermined value, or may be expressed using other corresponding information. For example, a radio resource may be indicated by an index.

[0139] The names used for the above-described parameters are not intended to be limiting in any way. Furthermore, the mathematical expressions using these parameters may differ from those explicitly disclosed in this disclosure. The various channels (e.g., PUCCH, PDCCH, etc.) and information elements may be identified by any suitable names, and therefore the various names assigned to these various channels and information elements are not intended to be limiting in any way.

[0140] In the present disclosure, terms such as "base station (BS)," "radio base station," "base station device," "fixed station," "NodeB," "eNodeB (eNB)," "gNodeB (gNB)," "access point," "transmission point," "reception point," "transmission / reception point," "cell," "sector," "cell group," "carrier," and "component carrier" may be used interchangeably. A base station may also be referred to by terms such as a macrocell, a small cell, a femtocell, and a picocell.

[0141] A base station can accommodate one or more (e.g., three) cells. When a base station accommodates multiple cells, the overall coverage area of ​​the base station can be partitioned into multiple smaller areas, and each smaller area can also be provided with communication services by a base station subsystem (e.g., a small indoor base station (RRH: Remote Radio Head)). The terms "cell" or "sector" refer to part or all of the coverage area of ​​a base station and / or base station subsystem that provides communication services within that coverage.

[0142] In the present disclosure, the base station transmitting information to a terminal may be interpreted as the base station instructing the terminal to control or operate based on the information.

[0143] In this disclosure, the terms "Mobile Station (MS)," "user terminal," "User Equipment (UE)," "terminal," and the like may be used interchangeably.

[0144] A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other suitable terminology.

[0145] Either the network node 100 or the terminal 200 may be referred to as a transmitting device, a receiving device, a communication device, or the like. Note that either the network node 100 or the terminal 200 may be a device mounted on a mobile object, the mobile object itself, or the like. The mobile object refers to a movable object, and may move at any speed. Naturally, this also includes cases where the mobile object is stationary. Examples of the mobile object include, but are not limited to, vehicles, transport vehicles, automobiles, motorcycles, bicycles, connected cars, excavators, bulldozers, wheel loaders, dump trucks, forklifts, trains, buses, handcarts, rickshaws, ships and other watercraft, airplanes, rockets, satellites, drones (registered trademark), multicopters, quadcopters, balloons, and objects mounted thereon. The mobile object may also be a mobile object that travels autonomously based on an operational command. Furthermore, the mobile object may be a vehicle (e.g., a car, an airplane, etc.), an unmanned mobile object (e.g., a drone, an autonomous vehicle, etc.), or a robot (manned or unmanned). Note that at least one of the base station and the mobile station may also include devices that do not necessarily move during communication operations. For example, at least one of the base station and the mobile station may be an IoT (Internet of Things) device such as a sensor.

[0146] Furthermore, a base station in the present disclosure may be read as a user terminal. For example, the aspects / embodiments of the present disclosure may be applied to a configuration in which communication between a base station and a user terminal is replaced with communication between multiple terminals 200 (which may be called, for example, Device-to-Device (D2D) or Vehicle-to-Everything (V2X)). In this case, the terminal 200 may be configured to have the functions of the base station described above. Furthermore, terms such as "uplink" and "downlink" may be read as terms corresponding to terminal-to-terminal communication (for example, "side"). For example, terms such as an uplink channel and a downlink channel may be read as a side channel.

[0147] Similarly, the user terminal in the present disclosure may be read as a base station, in which case the base station may be configured to have the functions of the user terminal described above.

[0148] As used in this disclosure, the terms "determining" and "determining" may encompass a wide variety of actions. "Determining" and "determining" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiring (e.g., searching in a table, database, or other data structure), ascertaining, and the like. "Determining" and "determining" may also include receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, accessing (e.g., accessing data in memory), and the like. Furthermore, "judgment" and "decision" can include regarding resolving, selecting, choosing, establishing, comparing, etc. as having been "judged" or "decided." In other words, "judgment" and "decision" can include regarding some action as having been "judged" or "decided." Furthermore, "judgment (decision)" can be interpreted as "assuming," "expecting," "considering," etc.

[0149] The terms "connected," "coupled," or any variation thereof, refer to any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be physical, logical, or a combination thereof. For example, "connected" may be read as "access." As used in this disclosure, two elements may be considered to be "connected" or "coupled" to each other using one or more wires, cables, and / or printed electrical connections, as well as electromagnetic energy having wavelengths in the radio frequency range, microwave range, and optical (both visible and invisible) range, as some non-limiting and non-exhaustive examples.

[0150] The reference signal may be abbreviated as RS (Reference Signal) or may be called a pilot depending on the applicable standard.

[0151] As used in this disclosure, the phrase "based on" does not mean "based only on," unless expressly stated otherwise. In other words, the phrase "based on" means both "based only on" and "based at least on."

[0152] As used in this disclosure, any reference to an element using a designation such as "first," "second," etc. does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Thus, a reference to a first and a second element does not imply that only two elements may be employed or that the first element must in some way precede the second element.

[0153] The "means" in the configuration of each of the above devices may be replaced with "part," "circuit," "device," etc.

[0154] When the terms "include," "including," and variations thereof are used in this disclosure, these terms are intended to be inclusive, similar to the term "comprising." Furthermore, when the term "or" is used in this disclosure, it is not intended to be an exclusive or.

[0155] In this disclosure, where articles are added by translation, such as a, an, and the in English, the disclosure may include that the nouns following these articles are in the plural form.

[0156] In the present disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "coupled" may also be interpreted in the same way as "different."

[0157] The aspects / embodiments described in this disclosure may be used alone, in combination, or switched depending on the implementation. Notification of predetermined information (e.g., notification that "X is true") is not limited to explicit notification, but may be implicit (e.g., not notifying the predetermined information).

[0158] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure.

[0159] 10 Attester 20 Relying party 30 Verifier 100 Network node 110 Transmitter 120 Receiver 130 Setting unit 140 Control unit 200 Terminal 210 Transmitter 220 Receiver 230 Setting unit 240 Control unit 1001 Processor 1002 Storage device 1003 Auxiliary storage device 1004 Communication device 1005 Input device 1006 Output device 2001 Vehicle 2002 Drive unit 2003 Steering unit 2004 Accelerator pedal 2005 Brake pedal 2006 Shift lever 2007 Front wheels 2008 Rear wheels 2009 Axle 2010 Electronic control unit 2012 Information service unit 2013 Communication module 2021 Current sensor 2022 Rotation speed sensor 2023 Air pressure sensor 2024 Vehicle speed sensor 2025 Acceleration sensor 2026 Brake pedal sensor 2027 Shift lever sensor 2028 Object detection sensor 2029 Accelerator pedal sensor 2030 Driving assistance system section 2031 Microprocessor 2032 Memory (ROM, RAM) 2033 Communication port (IO port)

Claims

1. A network node comprising: a receiver for receiving, from a first network node, identification information of a private key or identification information of a cryptographic primitive; a controller for determining the validity of the private key or the cryptographic primitive based on prior information received from a second network node; and a transmitter for transmitting the result of the determination made by the controller to the first network node.

2. The network node according to claim 1, wherein the private key or the cryptographic primitive is a private key or a cryptographic primitive corresponding to a short-term validity certificate.

3. The network node according to claim 1, wherein the prior information is identification information indicating a private key or a cryptographic primitive to be revoked.

4. The network node according to claim 1, wherein the prior information is information corresponding to a specific public key cryptosystem the use of which should be restricted.

5. The network node according to claim 1, wherein the advance information is information corresponding to a specific public key cryptosystem for which usage restriction is to be lifted.

6. A communication method executed by a network node, comprising: a step of receiving, from a first network node, an identification of a private key or an identification of a cryptographic primitive; a determination step of determining the validity of the private key or the cryptographic primitive based on prior information received from a second network node; and a step of transmitting the determination result of the determination step to the first network node.

Citation Information

Patent Citations

  • Method of verifying certificate, verification server, program, and storage medium

    JP2011193416A

  • Private key updating

    US20210135864A1