Network node, terminal, and communication method

By implementing a SIM-based authentication mechanism for terminals without authentication functions, the system ensures continuous wide-area wireless communication and reduces energy consumption, addressing the issue of battery depletion in terminals with dual functions.

WO2025203258A1PCT designated stage Publication Date: 2025-10-02NTT DOCOMO INC +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/012055
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-26
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In current wide-area mobile communication systems, terminals without authentication functions cannot properly perform wireless communication due to battery depletion in terminals with both authentication and communication functions, leading to communication disruptions and bottlenecks.

Method used

A network node and terminal configuration where a device with a SIM-based authentication function (authentication UE) takes over authentication for terminals lacking a SIM, establishing trust through near-field communication and confirming pairing with communication UEs, allowing them to connect to the 3GPP system as a single entity.

Benefits of technology

Enables terminals without authentication functions to perform wide-area wireless communication effectively, preventing communication disruptions and bottlenecks by ensuring continuous connectivity and reducing energy consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024012055_02102025_PF_FP_ABST
    Figure JP2024012055_02102025_PF_FP_ABST
Patent Text Reader

Abstract

This network node comprises: a reception unit that receives, via a second terminal, authentication information transmitted from a first terminal and possessing a key associated with hardware of the second terminal; and a control unit that confirms pairing between the first terminal and the second terminal on the basis of the authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

Network node, terminal, and communication method

[0001] The present invention relates to a network node, a terminal, and a communication method in a communication system.

[0002] The 3GPP (registered trademark) (3rd Generation Partnership Project) has introduced a wireless communication system called 5G or NR (New Radio) (hereinafter, the wireless communication system is referred to as "5G" or "NR") to achieve even larger system capacity, even faster data transmission speeds, and even shorter latency in wireless sections. In 5G, various wireless technologies have been introduced to meet the requirements of achieving a throughput of 10 Gbps or more while reducing latency in wireless sections to 1 ms or less. Furthermore, various network (NW) functions have been introduced and delivered (e.g., Non-Patent Document 1). Furthermore, 6G, a future communication system, is also being studied.

[0003] In current wide-area mobile communication systems such as 5G, terminals are authenticated in the network before they are connected to the network and allowed to perform wide-area wireless communication. For this reason, terminals are generally equipped with wide-area wireless communication functions and authentication functions.

[0004] In addition, a mechanism is provided that enables communication by tethering a terminal having communication and authentication functions (for example, a mobile router or smartphone, referred to as terminal 1) with a terminal that does not have a SIM (Subscriber Identity Module) (a terminal that does not have the above authentication function, referred to as terminal 2).

[0005] 3GPP TS 23.502 V18.3.0 (2023-09)

[0006] However, in the above-described tethering configuration, if the battery of terminal 1 runs out, terminal 2 using tethering will be unable to communicate even if the battery of terminal 2 has sufficient power. Terminal 1 may also become a bottleneck for communication with its subordinate terminals 2. In other words, the conventional technology has the problem that terminals without authentication functions cannot properly perform wide-area wireless communication.

[0007] The present invention has been made in view of the above points, and has an object to provide a technique that enables a terminal that does not have an authentication function to properly perform wide-area wireless communication.

[0008] According to the disclosed technology, there is provided a network node including: a receiving unit that receives authentication information transmitted from a first terminal, the authentication information having a key linked to hardware of a second terminal, via the second terminal; and a control unit that confirms pairing between the first terminal and the second terminal based on the authentication information.

[0009] According to the disclosed technology, a terminal that does not have an authentication function can appropriately perform wide-area wireless communication.

[0010] FIG. 1 is a diagram for explaining an example of a communication system. FIG. 1 is a diagram for explaining an example of a communication system in a roaming environment. FIG. 2 is a diagram for explaining an example of a system in which communication is performed using a dithering mechanism. FIG. 3 is a diagram for explaining an example of a system configuration in an embodiment of the present invention. FIG. 4 is a diagram for explaining an example of a system configuration in an embodiment of the present invention. FIG. 5 is a diagram for explaining an example of a system configuration in an embodiment of the present invention. FIG. 6 is a sequence chart for explaining operation of a system in an embodiment of the present invention. FIG. 7 is a diagram for explaining an example of a functional configuration of a network node 100 in an embodiment of the present invention. FIG. 8 is a diagram for explaining an example of a functional configuration of a terminal 20 in an embodiment of the present invention. FIG. 9 is a diagram for explaining an example of a hardware configuration of a terminal 20 and a network node 100 in an embodiment of the present invention. FIG. 10 is a diagram for explaining an example of a configuration of a vehicle 2001 in an embodiment of the present invention.

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Note that the embodiment described below is an example, and the embodiment to which the present invention is applied is not limited to the following embodiment.

[0012] In the operation of the wireless communication system according to the embodiment of the present invention, existing technologies are used as appropriate. However, the existing technologies include, but are not limited to, the existing LTE or the existing NR.

[0013] In the following, we will first explain an example of the configuration of a 5G core network, which is an example of a network (NW) in which wide-area wireless communication is performed in this embodiment, and then explain the configuration and operation related to this embodiment.

[0014] Fig. 1 is a diagram illustrating an example of a communication system corresponding to a core network. As shown in Fig. 1, this communication system is composed of a UE (terminal 20) and multiple network nodes. Hereinafter, it is assumed that one network node corresponds to each function, but multiple functions may be realized by one network node, or multiple network nodes may realize one function. Furthermore, the "connection" described below may be a logical connection or a physical connection.

[0015] An (R)AN (Radio) Access Network) is a network node having a radio access function, which may include a base station 10, and is connected to a UE 20, an AMF (Access and Mobility Management Function), and a UPF (User plane function). The AMF is a network node having functions such as terminating the RAN interface, terminating the NAS (Non-Access Stratum), registration management, connection management, reachability management, and mobility management. The UPF is a network node having functions such as a PDU (Protocol Data Unit) session point to the outside that interconnects with a DN (Data Network), packet routing and forwarding, and user plane QoS (Quality of Service) handling. The UPF and DN constitute a network slice.

[0016] The AMF is connected to the UE 20, (R)AN 10, SMF (Session Management function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (Network Repository Function), UDM (Unified Data Management), AUSF (Authentication Server Function), PCF (Policy Control Function), and AF (Application Function). The AMF, SMF, NSSF, NEF, NRF, UDM 40, AUSF 80, PCF, and AF are network nodes interconnected via interfaces based on their respective services, Namf, Nsmf, Nnssf, Nnef, Nnrf, Nudm, Nausf, Npcf, and Naf.

[0017] The SMF is a network node having functions such as session management, UE IP (Internet Protocol) address allocation and management, DHCP (Dynamic Host Configuration Protocol) function, ARP (Address Resolution Protocol) proxy, and roaming function. The NEF is a network node having a function of notifying other NFs (Network Functions) of capabilities and events. The NSSF is a network node having functions such as selecting a network slice to which the UE 20 connects, determining the allowed NSSAI (Network Slice Selection Assistance Information), determining the NSSAI to be set, and determining the AMF set to which the UE 20 connects. The PCF is a network node having a function of controlling network policies. The AF is a network node having a function of controlling application servers. The NRF is a network node having a function of discovering NF instances that provide services. The UDM is a network node that manages subscriber data and authentication data. The UDM is connected to a UDR (User Data Repository) that stores the data.

[0018] 2 is a diagram illustrating an example of a communication system in a roaming environment. As shown in FIG. 2, the network is made up of a UE, which is a terminal 20, and a plurality of network nodes.

[0019] The SEPP is a non-transparent proxy that filters control plane messages between PLMNs (Public Land Mobile Networks). The vSEPP shown in Figure 2 is a SEPP in a visited network, and the hSEPP is a SEPP in a home network.

[0020] As shown in Fig. 2, the UE 20 is in a roaming environment connected to an (R)AN and an AMF 30 in a Visited PLMN (VPLMN). The VPLMN and the Home PLMN (HPLMN) are connected via a vSEPP and an hSEPP. The UE 20 can communicate with the UDM of the HPLMN via the AMF of the VPLMN, for example.

[0021] (Problems) As mentioned above, in current wide-area mobile communication systems, terminals are authenticated in the network before they are connected to the network and allowed to perform wide-area wireless communication. For this reason, terminals are generally equipped with wide-area wireless communication functions and authentication functions.

[0022] In addition, a mechanism is provided that enables communication by tethering a terminal having communication and authentication functions (for example, a mobile router or smartphone, referred to as terminal 1) with a terminal that does not have a SIM (Subscriber Identity Module) (a terminal that does not have the above authentication function, referred to as terminal 2).

[0023] An example of a system in which communication is performed using this mechanism is shown in Figure 3. Figure 3 shows multiple terminals 2 communicating wirelessly using tethering from terminal 1, such as a smartphone or mobile router. However, if terminal 1's battery runs out, terminal 2 using tethering will be unable to communicate, even if the terminal 2 has sufficient battery power. Terminal 1 can also become a bottleneck in communication for the terminals 2 subordinate to it.

[0024] Since the terminal 1 is responsible for both the wide-area wireless communication function and the authentication function for the wide-area wireless communication, the connection configuration shown in FIG. 3 is unavoidable, which causes the above-mentioned problem.

[0025] In this embodiment, in order to solve the above-mentioned problem, a device having a SIM-based authentication function (referred to as an authentication UE 22) takes over authentication of a terminal not having a SIM (referred to as a communication UE 21). Near-field communication is performed between the authentication UE 22 and the communication UE 21, and they mutually trust each other.

[0026] The authentication UE 22 is a UE that has only the authentication function and does not have the wide-area wireless communication function among the functions of the terminal 1. However, like the terminal 1, the authentication UE 22 may have both the authentication function and the wide-area wireless communication function and not use the wide-area wireless communication function.

[0027] An example of a system configuration in this embodiment is shown in Fig. 4. There may be one or more communication UEs 21 for one authentication UE 22. The example of Fig. 4 shows a case where multiple communication UEs 21 are connected to one authentication UE 22. The communication UE 21 may be a terminal such as a smartphone, a PC, or a car (connected car).

[0028] Furthermore, as shown in FIG. 5, a plurality of authentication UEs 22 may be connected to one communication UE 21 .

[0029] In this system having an authentication UE 22 and a communication UE 21, a mechanism is provided for establishing trust between the authentication UE 22 and the communication UE 21, and the established trust relationship is proven to the 3GPP system, and the authentication UE 22 and the communication UE 21 are connected to the 3GPP system as a single entity.

[0030] With the technology according to the present embodiment, the authentication UE 22 only needs to perform proximity communication with the communication UE 21, which allows the authentication UE 22 to be made smaller and more energy-efficient. This reduces the possibility of communication being disabled due to a dead battery in the terminal with authentication functionality, as in the prior art. It also prevents the terminal with authentication functionality from becoming a bottleneck in communication.

[0031] The technology according to the present embodiment can be applied to various use cases. For example, by pairing a sharing car as a communication UE 21 with a ring device as an authentication UE 22, the sharing car can communicate as a terminal of a user who owns the ring device.

[0032] (System Configuration, Operation Example) An operation example will be described below. First, the configuration of a communication system that is the premise of this operation example is shown in Fig. 6. As shown in Fig. 6, this communication system includes a communication UE 21, an authentication UE 22, an access network function 30, an authentication function 40, and a GW (gateway) 50. The access network function 30, the authentication function 40, and the GW 50 are provided in a network 300.

[0033] Here, it is assumed that the communication UE 21 does not have a SIM, the authentication UE 22 has a SIM, and the authentication function 40 authenticates the pair of "communication UE 21 and authentication UE 22" (confirms pairing, which will be described later) using SIM information held by the authentication UE 22 and a key linked to the hardware of the communication UE 21. However, using SIM information for authentication is just one example, and an authentication method other than the authentication method using a SIM may also be used.

[0034] In this embodiment, it is assumed that the network 300 is a network defined by 3GPP (for example, a 5G core network). However, the network 300 is not limited to a network defined by 3GPP and may be any network.

[0035] The access network function 30 is, for example, a base station 10 (RAN). The authentication function 40 may be an existing network node (e.g., AUSF) defined by 3GPP that has been functionally extended so that it can perform the operations of this embodiment, or may be a new network node. The GW 50 is a network node that serves as a gateway between the network 300 and an external network (e.g., the Internet).

[0036] An example of the operation of the communication system according to this embodiment will be described with reference to the sequence diagram of FIG.

[0037] In S1, pairing for proximity communication (short-range communication) is performed between the authentication UE 22 and the communication UE 21. This enables communication between the authentication UE 22 and the communication UE 21.

[0038] The method of near field communication in this embodiment is not limited to a specific method, but for example, Bluetooth (registered trademark), infrared communication, wireless LAN, etc. can be used.

[0039] In this embodiment, it is assumed that the authentication UE 22 and the communication UE 21 communicate wirelessly, but the communication between the authentication UE 22 and the communication UE 21 is not limited to wireless communication. For example, the authentication UE 22 and the communication UE 21 may communicate by contacting each other, or by connecting the authentication UE 22 and the communication UE 21 with a cable.

[0040] In S2, the communication UE 21 and the authentication UE 22 mutually confirm the authenticity of each other. For example, the communication UE 21 acquires information unique to the authentication UE 22 (e.g., a serial number) from the authentication UE 22 and confirms whether the information is authentic. Similarly, the authentication UE 22 acquires information unique to the communication UE 21 (e.g., a serial number) from the communication UE 21 and confirms whether the information is authentic. The communication UE 21 may also acquire information on the SIM of the authentication UE 22 from the authentication UE 22 and confirm whether the information is authentic. The SIM may also be referred to as an authentication information storage function.

[0041] In S3, the authentication UE 22 requests the communication UE 21 to generate a key linked to the hardware of the communication UE 21. In S4, the communication UE 21 responds to the authentication UE 22 with the key (referred to as Kc) linked to the hardware of the communication UE 21.

[0042] The "key associated with hardware" may be any information associated with the hardware of the communication UE 21. For example, the "key associated with hardware" may be identification information (such as a number) that uniquely identifies the communication UE 21 as an object (hardware), or information obtained by converting (encrypting) the identification information.

[0043] Furthermore, the "key associated with the hardware" may be a private key written in a tamper-resistant area of ​​the communication UE 21 by the manufacturer of the communication UE 21 when the communication UE 21 is manufactured. The "key associated with the hardware" may be a signature generated using the private key (for example, a signature generated from the above-mentioned identification information). The "key associated with the hardware" may be a pair of the signature and the above-mentioned identification information.

[0044] In S5, the authentication UE 22 transmits authentication information linked to Kc to the communication UE 21. This authentication information includes information for authenticating the authentication UE 22 (e.g., SIM information of the authentication UE 22) and Kc. This authentication information is encrypted. The communication UE 21 holds the encrypted authentication information. Because the authentication information is encrypted, the communication UE 21 cannot view the authentication information (cannot know the contents of the authentication information).

[0045] Furthermore, the authentication information transmitted from the authenticating UE 22 may be a VC (Verifiable Credential). The VC is signed data that stores personal data and the like. The VC includes the DID (Decentralized Identifier) ​​of the issuer of the VC, and by referencing a distributed ledger in which the DID and the like are registered, the VC can be verified without inquiring about the issuer.

[0046] In S6, the communication UE 21 that has received the encrypted authentication information establishes an access network layer connection with the access network function 30. In S7, the communication UE 21 transmits the encrypted authentication information to the authentication function 40.

[0047] In S8, the authentication function 40 receives the encrypted authentication information, decrypts the encrypted authentication information, and uses the decrypted authentication information to confirm the pairing between the authentication UE 22 and the communication UE 21. By confirming the pairing, authentication of the "authentication UE 22 and the communication UE 21" is performed.

[0048] Specifically, for example, the authentication function 40 first authenticates the authentication UE 22 using the authentication information. The authentication of the authentication UE 22 can be performed using existing technology, for example, SIM information of the authentication UE 22 included in the authentication information. Alternatively, the authentication of the authentication UE 22 may be performed by verifying the above-mentioned VC.

[0049] If the authentication of the authentication UE 22 is successful, the authentication function 40 checks whether Kc included in the authentication information is valid. For example, if the authentication function 40 acquires hardware-unique identification information of the communication UE 21 based on Kc and checks that the identification information is valid, the authentication function 40 determines that Kc is valid and that the authentication UE 22 and the communication UE 21 are paired. This determination corresponds to determining that the authentication of the "authentication UE 22 and the communication UE 21" has been successful.

[0050] Note that whether the identification information of the communication UE 21 is valid or not may be confirmed by any method. For example, an external database may be queried, the identification information may be determined to be valid if the format of the identification information itself is correct, or the identification information may be queried from the communication UE 21 and the identification information acquired from the communication UE 21 may be compared with the identification information acquired based on Kc.

[0051] In S9, the authentication function 40 transmits the authentication result to the communication UE 21. In S10, the communication UE 21 transmits the authentication result to the authentication UE 22. Here, it is assumed that the authentication result is "authentication success."

[0052] In S11, the communication UE 21 establishes a communication path with the GW 50. This communication path is a communication path for the communication UE 21 to perform data communication. In addition, in S12, the authentication UE 22 establishes communication paths with the authentication function 40 and with the GW 50. Note that the authentication UE 22 may not establish a communication path with the GW 50. In S13, a control channel is established between the authentication UE 22 and the authentication function 40.

[0053] (Regarding Expiration Management of Authentication Information) The authentication function 40 performs expiration management of authentication information. For example, the authentication function 40 determines that the authentication information has expired when a predetermined period of time has elapsed since the successful authentication (confirmation of pairing) in S8. The predetermined period of time may be a predetermined period of time, or may be described in the authentication information created by the authentication UE 22.

[0054] The authentication function 40 can use the control channel to control the expiration of authentication information. For example, when the authentication function 40 detects that the authentication information has expired, it notifies the authentication UE 22 via the control channel that the authentication information has expired (the authentication has expired). Upon receiving this notification, the authentication UE 22 executes steps S3 to S5 again, and the communication UE 21 transmits new encrypted authentication information to the authentication function 40. Thereafter, the authentication function 40 performs authentication (confirms pairing). If the authentication is successful, a communication path and a control channel are established again.

[0055] Furthermore, when the control channel is active and the authentication function 40 determines that the authentication information has expired, the control channel may be deactivated. In this case, when the authenticating UE 22 detects that the control channel has become inactive, it determines that the authentication information has expired and executes the processes from S3 onwards again.

[0056] The authentication function 40 may also notify the authentication UE 22 of the time (timing) when the authentication information will expire via the control channel. When that time arrives, the authentication UE 22 determines that the authentication information has expired and executes the processes from S3 onwards again.

[0057] Furthermore, the authentication function 40 may invalidate authentication information held by a specific communication UE through, for example, a Network Exposure Function (NEF).

[0058] (Effects of the embodiment) The technology according to the embodiment enables a terminal (for example, the communication UE 21) that does not have an authentication function to appropriately perform wide-area wireless communication.

[0059] (Device Configuration) Next, a description will be given of an example of the functional configuration of the access network function 30, authentication function 40, GW 50, communication UE 21, and authentication UE 22, which perform the processes and operations described above. Hereinafter, network nodes such as the access network function 30, authentication function 40, and GW 50 will be collectively referred to as "network node 100." Furthermore, terminals such as the communication UE 21 and authentication UE 22 will be collectively referred to as "terminal 20."

[0060] <Network Node 100> FIG. 8 is a diagram showing an example of the functional configuration of the network node 100. As shown in FIG.

[0061] As shown in Fig. 8, the network node 100 includes a transmitting unit 110, a receiving unit 120, a setting unit 130, and a control unit 140. The functional configuration shown in Fig. 8 is merely an example. The names of the functional divisions and functional units may be any names as long as they can perform the operations according to the embodiment of the present invention.

[0062] The transmitter 110 has a function of generating a signal to be transmitted to the terminal 20 or another network node and transmitting the signal via a wired or wireless connection. The receiver 120 has a function of receiving various signals transmitted from the terminal 20 or another network node and acquiring, for example, information of a higher layer from the received signal. A communication unit including the transmitter 110 and the receiver 120 may be configured.

[0063] The setting unit 130 stores pre-set setting information and various setting information to be transmitted to the terminal 20 in a storage device, and reads out the information from the storage device as needed. The control unit 140 controls the network node 100. The function unit related to signal transmission in the control unit 140 may be included in the transmitting unit 110, and the function unit related to signal reception in the control unit 140 may be included in the receiving unit 120. The transmitting unit 110 and the receiving unit 120 may be called a transmitter and a receiver, respectively.

[0064] <Terminal 20> Fig. 9 is a diagram showing an example of the functional configuration of the terminal 20. As shown in Fig. 9, the terminal 20 has a transmitting unit 210, a receiving unit 220, a setting unit 230, and a control unit 240. The functional configuration shown in Fig. 9 is merely an example. The names of the functional divisions and functional units may be any as long as they can perform the operations related to the embodiment of the present invention.

[0065] The transmitter 210 creates a transmission signal from transmission data and transmits the transmission signal wirelessly. The receiver 220 receives various signals wirelessly and acquires higher layer signals from the received physical layer signals. In particular, in the communication UE 21, the receiver 220 has a function of receiving NR-PSS, NR-SSS, NR-PBCH, DL / UL control signals, reference signals, etc. transmitted from a network node. A communication unit including the transmitter 210 and the receiver 220 may be configured.

[0066] The setting unit 230 stores various setting information received from the network node by the receiving unit 220 in a storage device, and reads it out from the storage device as needed. The setting unit 230 also stores setting information that is set in advance.

[0067] The control unit 240 controls the terminal 20. The functional unit in the control unit 240 related to signal transmission may be included in the transmitting unit 210, and the functional unit in the control unit 240 related to signal reception may be included in the receiving unit 220. The transmitting unit 210 and the receiving unit 220 may be called a transmitter and a receiver, respectively.

[0068] (Hardware Configuration) The block diagrams (FIGS. 8 and 9) used to explain the above embodiments show functional blocks. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wires, wirelessly, etc.) and these multiple devices. The functional block may be realized by combining software with the single device or the multiple devices.

[0069] Functions include, but are not limited to, judgment, determination, assessment, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, resolution, selection, selection, establishment, comparison, assumption, expectation, consideration, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, and assignment. For example, a functional block (component) that performs transmission is called a transmitting unit or transmitter. As mentioned above, there are no particular limitations on how these functions are implemented.

[0070] For example, the network node 100 and the terminal 20 according to an embodiment of the present disclosure may function as a computer that performs processing of the communication method of the present disclosure. Fig. 10 is a diagram illustrating an example of the hardware configuration of the network node 100 and the terminal 20 according to an embodiment of the present disclosure. The network node 100 and the terminal 20 described above may be physically configured as a computer device including a processor 1001, a storage device 1002, an auxiliary storage device 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, etc.

[0071] In the following description, the term "apparatus" can be read as a circuit, a device, a unit, etc. The hardware configuration of the network node 100 and the terminal 20 may be configured to include one or more of the apparatuses shown in the figure, or may be configured to exclude some of the apparatuses.

[0072] Each function in the network node 100 and the terminal 20 is realized by loading specified software (programs) onto hardware such as the processor 1001, the memory device 1002, etc., so that the processor 1001 performs calculations, controls communication via the communication device 1004, and controls at least one of reading and writing data in the memory device 1002 and the auxiliary memory device 1003.

[0073] The processor 1001 controls the entire computer by running, for example, an operating system. The processor 1001 may be configured as a central processing unit (CPU) including an interface with peripheral devices, a control device, an arithmetic unit, a register, etc. For example, the above-mentioned control unit 140, control unit 240, etc. may be realized by the processor 1001.

[0074] Furthermore, the processor 1001 reads programs (program codes), software modules, data, etc. from at least one of the auxiliary storage device 1003 and the communication device 1004 into the storage device 1002 and executes various processes in accordance with the programs. The programs used are those that cause a computer to execute at least some of the operations described in the above-described embodiments. For example, the control unit 140 of the network node 100 shown in FIG. 8 may be implemented by a control program stored in the storage device 1002 and running on the processor 1001. Furthermore, for example, the control unit 240 of the terminal 20 shown in FIG. 9 may be implemented by a control program stored in the storage device 1002 and running on the processor 1001. While the above-described various processes have been described as being executed by one processor 1001, they may also be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may be implemented by one or more chips. The programs may also be transmitted from a network via a telecommunications line.

[0075] The storage device 1002 is a computer-readable recording medium and may be configured, for example, by at least one of a read-only memory (ROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a random access memory (RAM), etc. The storage device 1002 may also be called a register, a cache, a main memory, etc. The storage device 1002 can store executable programs (program codes), software modules, etc. for implementing a communication method according to an embodiment of the present disclosure.

[0076] The secondary storage device 1003 is a computer-readable recording medium, and may be, for example, at least one of an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disk, a digital versatile disk, a Blu-ray (registered trademark) disk), a smart card, a flash memory (e.g., a card, a stick, a key drive), a floppy (registered trademark) disk, a magnetic strip, etc. The above-mentioned storage medium may be, for example, a database, a server, or other appropriate medium including at least one of the storage device 1002 and the secondary storage device 1003.

[0077] The communication device 1004 is hardware (transmission / reception device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as, for example, a network device, a network controller, a network card, a communication module, etc. The communication device 1004 may be configured to include a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc. to realize at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, a transmission / reception antenna, an amplifier unit, a transmission / reception unit, a transmission path interface, etc. may be realized by the communication device 1004. The transmission / reception unit may be implemented as a transmission unit and a reception unit that are physically or logically separated.

[0078] The input device 1005 is an input device (e.g., a keyboard, a mouse, a microphone, a switch, a button, a sensor, etc.) that receives input from the outside. The output device 1006 is an output device (e.g., a display, a speaker, an LED lamp, etc.) that outputs to the outside. Note that the input device 1005 and the output device 1006 may be integrated into one device (e.g., a touch panel).

[0079] Furthermore, each device such as the processor 1001 and the storage device 1002 is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus, or may be configured using different buses between each device.

[0080] Furthermore, the network node 100 and the terminal 20 may be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA), and some or all of the functional blocks may be realized by the hardware. For example, the processor 1001 may be implemented using at least one of these pieces of hardware.

[0081] 11 shows an example configuration of a vehicle 2001. As shown in FIG. 11 , the vehicle 2001 includes a drive unit 2002, a steering unit 2003, an accelerator pedal 2004, a brake pedal 2005, a shift lever 2006, front wheels 2007, rear wheels 2008, an axle 2009, an electronic control unit 2010, various sensors 2021 to 2029, an information service unit 2012, and a communication module 2013. Each aspect / embodiment described in the present disclosure may be applied to a communication device mounted on the vehicle 2001, and may be applied to the communication module 2013, for example. For example, the network node 100 or the terminal 20 may be included in the communication module 2013.

[0082] The drive unit 2002 is configured, for example, by an engine, a motor, or a hybrid of an engine and a motor. The steering unit 2003 includes at least a steering wheel (also called a handle) and is configured to steer at least one of the front wheels and the rear wheels based on the operation of the steering wheel operated by the user.

[0083] The electronic control unit 2010 is composed of a microprocessor 2031, a memory (ROM, RAM) 2032, and a communication port (IO port) 2033. Signals are input to the electronic control unit 2010 from various sensors 2021 to 2029 provided in the vehicle 2001. The electronic control unit 2010 may also be called an ECU (Electronic Control Unit).

[0084] The signals from the various sensors 2021 to 2029 include a current signal from a current sensor 2021 that senses the current of the motor, a rotation speed signal of the front and rear wheels obtained by a rotation speed sensor 2022, an air pressure signal of the front and rear wheels obtained by an air pressure sensor 2023, a vehicle speed signal obtained by a vehicle speed sensor 2024, an acceleration signal obtained by an acceleration sensor 2025, an accelerator pedal depression amount signal obtained by an accelerator pedal sensor 2029, a brake pedal depression amount signal obtained by a brake pedal sensor 2026, a shift lever operation signal obtained by a shift lever sensor 2027, and a detection signal for detecting obstacles, vehicles, pedestrians, etc. obtained by an object detection sensor 2028.

[0085] The information service unit 2012 is composed of various devices, such as a car navigation system, an audio system, speakers, a television, and a radio, for providing (outputting) various types of information, such as driving information, traffic information, and entertainment information, and one or more ECUs for controlling these devices. The information service unit 2012 uses information acquired from external devices via the communication module 2013 or the like to provide various types of multimedia information and multimedia services to the occupants of the vehicle 2001. The information service unit 2012 may include input devices (e.g., a keyboard, a mouse, a microphone, a switch, a button, a sensor, a touch panel, etc.) that accept input from the outside, and may also include output devices (e.g., a display, a speaker, an LED lamp, a touch panel, etc.) that output information to the outside.

[0086] The driving assistance system unit 2030 is composed of various devices that provide functions for preventing accidents and reducing the driving burden on the driver, such as millimeter-wave radar, LiDAR (Light Detection and Ranging), cameras, positioning locators (e.g., GNSS, etc.), map information (e.g., high-definition (HD) maps, autonomous vehicle (AV) maps, etc.), gyro systems (e.g., IMU (Inertial Measurement Unit), INS (Inertial Navigation System), etc.), AI (Artificial Intelligence) chips, and AI processors, as well as one or more ECUs that control these devices. In addition, the driving assistance system unit 2030 transmits and receives various information via the communication module 2013 to realize the driving assistance function or the autonomous driving function.

[0087] The communication module 2013 can communicate with the microprocessor 2031 and components of the vehicle 2001 via the communication port. For example, the communication module 2013 transmits and receives data via the communication port 2033 to and from the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axle 2009, microprocessor 2031 and memory (ROM, RAM) 2032 in the electronic control unit 2010, and sensors 2021 to 29, which are provided in the vehicle 2001.

[0088] The communication module 2013 is a communication device that can be controlled by the microprocessor 2031 of the electronic control unit 2010 and can communicate with an external device. For example, it transmits and receives various information to and from the external device via wireless communication. The communication module 2013 may be located either inside or outside the electronic control unit 2010. The external device may be, for example, a base station, a terminal, a network node, or the like.

[0089] The communication module 2013 may transmit, via wireless communication, to an external device at least one of signals from the various sensors 2021-2028 input to the electronic control unit 2010, information obtained based on the signals, and information based on input from the outside (user) obtained via the information service unit 2012. The electronic control unit 2010, the various sensors 2021-2028, the information service unit 2012, etc. may be referred to as input units that accept input.

[0090] The communication module 2013 receives various information (traffic information, traffic signal information, vehicle-to-vehicle information, etc.) transmitted from external devices and displays it on an information service unit 2012 provided in the vehicle 2001. The information service unit 2012 may be called an output unit that outputs information (for example, outputs information to a device such as a display or speaker based on the PDSCH (or data / information decoded from the PDSCH) received by the communication module 2013). The communication module 2013 also stores the various information received from external devices in a memory 2032 that can be used by the microprocessor 2031. Based on the information stored in the memory 2032, the microprocessor 2031 may control the drive unit 2002, steering unit 2003, accelerator pedal 2004, brake pedal 2005, shift lever 2006, front wheels 2007, rear wheels 2008, axles 2009, sensors 2021 to 2029, etc. provided in the vehicle 2001.

[0091] Furthermore, when the communication module 2013 includes the network node 100 (or the terminal 20), the communication module 2013 can perform the operations of the network node 100 (or the terminal 20) described above.

[0092] This specification discloses at least the configurations described in the appendices below.

[0093] <Additional Notes> (Additional Item 1) A network node comprising: a receiving unit that receives, via a second terminal, authentication information transmitted from a first terminal, the authentication information having a key linked to hardware of the second terminal; and a control unit that confirms pairing between the first terminal and the second terminal based on the authentication information. (Additional Item 2) The network node according to Additional Item 1, wherein a control channel is established between the network node and the first terminal, and the control unit uses the control channel to perform control related to expiration of the authentication information. (Additional Item 3) The network node according to Additional Item 1, wherein a communication path for data communication with the second terminal is established when the control unit successfully confirms the pairing. (Additional Item 4) A terminal comprising: a control unit that performs pairing with a communication terminal and confirms the legitimacy of the communication terminal; a receiving unit that receives from the communication terminal a key linked to hardware of the communication terminal; and a transmitting unit that transmits encrypted authentication information having the key to the communication terminal. (Supplementary Item 5) A terminal comprising: a control unit that performs pairing with an authentication terminal and confirms the legitimacy of the authentication terminal; a transmission unit that transmits a key linked to hardware of the terminal to the authentication terminal; and a reception unit that receives encrypted authentication information having the key from the authentication terminal. (Supplementary Item 6) A communication method executed by a network node, comprising: receiving, via the second terminal, authentication information transmitted from a first terminal, the authentication information having the key linked to hardware of a second terminal; and confirming pairing between the first terminal and the second terminal based on the authentication information.

[0094] Any of Supplementary Items 1 to 6 provides a technique that enables a terminal without an authentication function to appropriately perform wide-area wireless communication. Supplementary Item 2 enables control over the expiration of authentication information. Supplementary Item 3 enables the second terminal to perform data communication based on confirmation of pairing.

[0095] (Supplementary Notes on the Embodiments) Although the embodiments of the present invention have been described above, the disclosed invention is not limited to such embodiments, and those skilled in the art will understand various modifications, alterations, alternatives, and substitutions. While specific numerical examples have been used to facilitate understanding of the invention, unless otherwise specified, these numerical values ​​are merely examples, and any appropriate values ​​may be used. The division of items in the above description is not essential to the present invention; matters described in two or more items may be used in combination as needed, and matters described in one item may apply to matters described in another item (as long as there is no contradiction). Boundaries between functional units or processing units in functional block diagrams do not necessarily correspond to boundaries between physical components. The operations of multiple functional units may be performed physically by a single component, or the operations of a single functional unit may be performed physically by multiple components. The order of processing procedures described in the embodiments may be reversed as long as there is no contradiction. For convenience of processing description, the network node 100 and the terminal 20 have been described using functional block diagrams. However, such devices may be realized by hardware, software, or a combination thereof. The software operated by the processor of the EES 30 in accordance with an embodiment of the present invention and the software operated by the processor of the terminal 20 in accordance with an embodiment of the present invention may each be stored in random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, registers, hard disk (HDD), removable disk, CD-ROM, database, server, or any other suitable storage medium.

[0096] Furthermore, the notification of information is not limited to the aspects / embodiments described in the present disclosure, and may be performed using other methods. For example, the notification of information may be performed by physical layer signaling (e.g., Downlink Control Information (DCI), Uplink Control Information (UCI)), higher layer signaling (e.g., Radio Resource Control (RRC) signaling, Medium Access Control (MAC) signaling), broadcast information (Master Information Block (MIB), System Information Block (SIB)), other signals, or a combination thereof. Furthermore, the RRC signaling may be referred to as an RRC message, and may be, for example, an RRC Connection Setup message, an RRC Connection Reconfiguration message, or the like.

[0097] Each aspect / embodiment described in the present disclosure may be implemented using any of the following standards: LTE (Long Term Evolution), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), 6th generation mobile communication system (6G), xth generation mobile communication system (xG) (xG (x is, for example, an integer or a decimal number)), FRA (Future Radio Access), NR (new Radio), New radio access (NX), Future generation radio access (FX), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.17 (WiMAX (registered trademark)), IEEE 802.19 (WiMAX (registered trademark)), IEEE 802.20 (WiMAX (registered trademark)), IEEE 802.21 (Wi-Fi (registered trademark)), IEEE 802.22 (WiMAX (registered trademark)), IEEE 802.23 (WiMAX (registered trademark)), IEEE 802.24 (WiMAX (registered trademark)), IEEE 802.25 (WiMAX (registered trademark)), IEEE 802.26 (WiMAX (registered trademark)), IEEE 802.27 (WiMAX (registered trademark)), IEEE 802.28 (WiMAX (registered trademark)), IEEE 802.29 (WiMAX (registered trademark)), IEEE 802.30 (WiMAX (registered trademark)), IEEE 802.31 (Wi-Fi (registered trademark)), IEEE 802.32 (WiMAX (registered trademark)), IEEE 802.33 (WiMAX (registered trademark)), IEEE 802.34 ( The present invention may be applied to at least one of systems using 802.20, UWB (Ultra-Wide Band), Bluetooth (registered trademark), or other suitable systems, and next-generation systems that are extended, modified, created, or defined based on these systems. The present invention may also be applied to a combination of multiple systems (e.g., a combination of LTE and / or LTE-A with 5G).

[0098] The order of the procedures, sequences, flowcharts, etc. of each aspect / embodiment described herein may be rearranged unless it is consistent. For example, the methods described in this disclosure present elements of various steps using an example order and are not limited to the particular order presented.

[0099] In this specification, a specific operation described as being performed by the base station 10 ((R)AN 10) may also be performed by its upper node in some cases. In a network consisting of one or more network nodes having a base station 10, it is clear that various operations performed for communication with a terminal 20 may be performed by at least one of the base station 10 and another network node other than the base station 10 (such as, but not limited to, an MME or an S-GW). Although the above example illustrates a case where there is one other network node other than the base station 10, the other network node may be a combination of multiple other network nodes (for example, an MME and an S-GW).

[0100] The information, signals, etc. described in the present disclosure may be output from a higher layer (or a lower layer) to a lower layer (or a higher layer), or may be input / output via multiple network nodes.

[0101] Input and output information may be stored in a specific location (for example, memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be transmitted to another device.

[0102] In the present disclosure, the determination may be made by a value represented by one bit (0 or 1), by a Boolean value (true or false), or by a comparison of numerical values ​​(e.g., comparison with a predetermined value).

[0103] Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc., whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.

[0104] Software, instructions, information, etc. may also be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then these wired and / or wireless technologies are included within the definition of transmission media.

[0105] The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.

[0106] Note that terms described in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings. For example, at least one of a channel and a symbol may be a signal (signaling). Furthermore, a signal may be a message. Furthermore, a component carrier (CC) may be called a carrier frequency, a cell, a frequency carrier, etc.

[0107] As used in this disclosure, the terms "system" and "network" are used interchangeably.

[0108] Furthermore, the information, parameters, etc. described in the present disclosure may be expressed using absolute values, may be expressed using relative values ​​from a predetermined value, or may be expressed using other corresponding information. For example, a radio resource may be indicated by an index.

[0109] The names used for the above-described parameters are not intended to be limiting in any way. Furthermore, the mathematical expressions using these parameters may differ from those explicitly disclosed in this disclosure. The various channels (e.g., PUCCH, PDCCH, etc.) and information elements may be identified by any suitable names, and therefore the various names assigned to these various channels and information elements are not intended to be limiting in any way.

[0110] In the present disclosure, terms such as "base station (BS)," "radio base station," "base station device," "fixed station," "NodeB," "eNodeB (eNB)," "gNodeB (gNB)," "access point," "transmission point," "reception point," "transmission / reception point," "cell," "sector," "cell group," "carrier," and "component carrier" may be used interchangeably. A base station may also be referred to by terms such as a macrocell, a small cell, a femtocell, and a picocell.

[0111] A base station can accommodate one or more (e.g., three) cells. When a base station accommodates multiple cells, the overall coverage area of ​​the base station can be partitioned into multiple smaller areas, and each smaller area can also be provided with communication services by a base station subsystem (e.g., a small indoor base station (RRH: Remote Radio Head)). The terms "cell" or "sector" refer to part or all of the coverage area of ​​a base station and / or base station subsystem that provides communication services within that coverage.

[0112] In the present disclosure, the base station transmitting information to a terminal may be interpreted as the base station instructing the terminal to control or operate based on the information.

[0113] In this disclosure, the terms "Mobile Station (MS)," "user terminal," "User Equipment (UE)," "terminal," and the like may be used interchangeably.

[0114] A mobile station may also be referred to by those skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or some other suitable terminology.

[0115] At least one of the base station and the mobile station (terminal 20) may be referred to as a transmitting device, a receiving device, a communication device, etc. At least one of the base station and the mobile station may be a device mounted on a mobile object, the mobile object itself, etc. The mobile object refers to a movable object, and may move at any speed. Naturally, this also includes cases where the mobile object is stationary. Examples of the mobile object include, but are not limited to, vehicles, transport vehicles, automobiles, motorcycles, bicycles, connected cars, excavators, bulldozers, wheel loaders, dump trucks, forklifts, trains, buses, handcars, rickshaws, ships and other watercraft, airplanes, rockets, satellites, drones (registered trademark), multicopters, quadcopters, balloons, and objects mounted thereon. The mobile object may also be a mobile object that travels autonomously based on an operational command. The mobile object may be a vehicle (e.g., a car, an airplane, etc.), an unmanned mobile object (e.g., a drone, an autonomous vehicle, etc.), or a robot (manned or unmanned). At least one of the base station and the mobile station may be a device that does not necessarily move during communication operations. For example, at least one of the base station and the mobile station may be an IoT (Internet of Things) device such as a sensor.

[0116] Furthermore, a base station in the present disclosure may be read as a user terminal. For example, the aspects / embodiments of the present disclosure may be applied to a configuration in which communication between a base station and a user terminal is replaced with communication between multiple terminals 20 (which may be called, for example, Device-to-Device (D2D) or Vehicle-to-Everything (V2X)). In this case, the terminal 20 may be configured to have the functions of the base station 10 described above. Furthermore, terms such as "uplink" and "downlink" may be read as terms corresponding to terminal-to-terminal communication (for example, "side"). For example, terms such as an uplink channel and a downlink channel may be read as a side channel.

[0117] Similarly, the user terminal in the present disclosure may be read as a base station, in which case the base station may be configured to have the functions of the user terminal described above.

[0118] As used in this disclosure, the terms "determining" and "determining" may encompass a wide variety of actions. "Determining" and "determining" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiring (e.g., searching in a table, database, or other data structure), ascertaining, and the like. "Determining" and "determining" may also include receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, accessing (e.g., accessing data in memory), and the like. Furthermore, "judgment" and "decision" can include regarding resolving, selecting, choosing, establishing, comparing, etc. as having been "judged" or "decided." In other words, "judgment" and "decision" can include regarding some action as having been "judged" or "decided." Furthermore, "judgment (decision)" can be interpreted as "assuming," "expecting," "considering," etc.

[0119] The terms "connected," "coupled," or any variation thereof, refer to any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be physical, logical, or a combination thereof. For example, "connected" may be read as "access." As used in this disclosure, two elements may be considered to be "connected" or "coupled" to each other using one or more wires, cables, and / or printed electrical connections, as well as electromagnetic energy having wavelengths in the radio frequency range, microwave range, and optical (both visible and invisible) range, as some non-limiting and non-exhaustive examples.

[0120] The reference signal may be abbreviated as RS (Reference Signal) or may be called a pilot depending on the applicable standard.

[0121] As used in this disclosure, the phrase "based on" does not mean "based only on," unless expressly stated otherwise. In other words, the phrase "based on" means both "based only on" and "based at least on."

[0122] As used in this disclosure, any reference to an element using a designation such as "first," "second," etc. does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Thus, a reference to a first and a second element does not imply that only two elements may be employed or that the first element must in some way precede the second element.

[0123] The "means" in the configuration of each of the above devices may be replaced with "part," "circuit," "device," etc.

[0124] When the terms "include," "including," and variations thereof are used in this disclosure, these terms are intended to be inclusive, similar to the term "comprising." Furthermore, when the term "or" is used in this disclosure, it is not intended to be an exclusive or.

[0125] In this disclosure, where articles are added by translation, such as a, an, and the in English, the disclosure may include that the nouns following these articles are in the plural form.

[0126] In the present disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "coupled" may also be interpreted in the same way as "different."

[0127] The aspects / embodiments described in this disclosure may be used alone, in combination, or switched depending on the implementation. Notification of predetermined information (e.g., notification that "X is true") is not limited to explicit notification, but may be implicit (e.g., not notifying the predetermined information).

[0128] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure.

[0129] 10 Base station ((R)AN) 20 Terminal (UE) 21 Communication UE 22 Authentication UE 30 Access network function 40 Authentication function 50 GW 100 Network node 110 Transmission unit 120 Reception unit 130 Setting unit 140 Control unit 210 Transmission unit 220 Reception unit 230 Setting unit 240 Control unit 300 Network 1001 Processor 1002 Storage device 1003 Auxiliary storage device 1004 Communication device 1005 Input device 1006 Output device

Claims

1. A network node comprising: a receiving unit that receives authentication information transmitted from a first terminal via a second terminal, the authentication information including a key associated with hardware of the second terminal; and a control unit that confirms pairing between the first terminal and the second terminal based on the authentication information.

2. The network node according to claim 1, wherein a control channel is established between the network node and the first terminal, and the control unit uses the control channel to perform control related to the expiration of the authentication information.

3. The network node according to claim 1, wherein a communication path for data communication of the second terminal is established when the control unit has successfully confirmed the pairing.

4. A terminal comprising: a control unit that performs pairing with a communication terminal and verifies the authenticity of the communication terminal; a receiving unit that receives a key associated with the hardware of the communication terminal from the communication terminal; and a transmitting unit that transmits encrypted authentication information having the key to the communication terminal.

5. A terminal comprising: a control unit that performs pairing with an authentication terminal and verifies the legitimacy of the authentication terminal; a transmission unit that transmits a key linked to the hardware of the terminal to the authentication terminal; and a reception unit that receives encrypted authentication information having the key from the authentication terminal.

6. A communication method executed by a network node, comprising: receiving, via a second terminal, authentication information transmitted from a first terminal, the authentication information including a key associated with hardware of the second terminal; and confirming pairing between the first terminal and the second terminal based on the authentication information.

Citation Information

Patent Citations

  • User authenticating method, service registering method, authentication card, recording medium recording service registration / User authentication program, authentication organization device, and service providing device

    JP2002042102A

  • Wireless communication system, information equipment, public line terminal, electronic identification card, pairing id setting method, storage medium, and program

    JP2003143326A

  • Non-3GPP device access to the core network

    JP2021536687A