Communication system, control method for same, and program
Patent Information
- Application Number
- PCT/JP2026/010853
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2026-03-18
- Publication Date
- 2026-10-01
Smart Images

Figure JP2026010853_01102026_PF_FP_ABST
Abstract
Description
Communication System, Control Method therefor, and Program
[0001] The present invention relates to a communication system, a control method therefor, and a program.
[0002] A mobile communication network provides user equipment with a service of communicating with an external network. Patent Document 1 describes transferring data transmitted by user equipment to a server corresponding to a destination network.
[0003] International Publication No. 2017 / 056201
[0004] A communication carrier may restrict communication by user equipment depending on the subscriber's situation. Some aspects of the present invention aim to provide a technique for enabling restriction of communication of user equipment as intended.
[0005] According to some embodiments, there is provided a communication system comprising: specifying means for specifying a subscriber whose communication is prohibited; and transmitting means for transmitting, to user equipment equipped with the subscriber identification module of the subscriber, one or more messages for configuring the subscriber identification module such that the user equipment fails to unlock the subscriber identification module.
[0006] According to some embodiments, communication of user equipment can be restricted as intended.
[0007] Other features and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings. In the accompanying drawings, the same or similar configurations are denoted by the same reference numerals.
[0008] The attached drawings are included in the specification and constitute a part thereof, illustrating embodiments of the present invention and are used to explain the principles of the present invention together with the description thereof. Block diagram illustrating an example of the configuration of a mobile communication network according to some embodiments. Block diagram illustrating an example of the hardware configuration of a computer according to some embodiments. Block diagram illustrating an example of the configuration of a UE according to some embodiments. Diagram illustrating an example of connection permission information according to some embodiments. Flow diagram illustrating an example of the operation of a communication system according to some embodiments. Sequence Block diagram illustrating an example of the configuration of a P-GW according to some embodiments.
[0009] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims, and not all combinations of features described in the embodiments are essential to the invention. Two or more of the features described in the embodiments may be combined in any way. Furthermore, identical or similar configurations will be given the same reference numeral, and redundant descriptions will be omitted.
[0010] Referring to Figure 1, the configuration of a mobile communication network 100 according to some embodiments of the present invention will be described. Figure 1 describes a mobile communication network compliant with LTE (Long Term Evolution). The present invention is also applicable to mobile communication networks compliant with 3G, 5G, or other standards. The mobile communication network 100 provides communication services to user equipment (UE) 130. The mobile communication network 100 may consist of a communication system 110 and a communication system 120. Any component included in the mobile communication network 100 can be an entity that processes communication related to the UE 130.
[0011] Communication system 110 may include an eNB (evolved Node B) 111, an S-GW (Serving Gateway) 112, an MSC (Mobile Switching Center) 113, and an MME (Mobility Management Entity) 114. Communication system 120 may include a P-GW (Packet data network Gateway) 121, an HSS / HLR (Home Subscriber Server / Home Location Register) 124, a session manager 125, a GMSC (Gateway Mobile Switching Center) 126, an USDD (Unstructured Supplementary Service Data) gateway 127, and an SMSC (Short Message Service Center) 128. In the example in Figure 1, communication system 110 is provided by an MNO (Mobile Network Operator), and communication system 120 is provided by an MVNO (Mobile Virtual Network Operator). Alternatively, both communication system 110 and communication system 120 may be provided by an MNO. The P-GW 121 and session manager 125 may be built by the MVNO itself, or they may be built and operated by an MVNE (Mobile Virtual Network Enabler) at the request of the MVNO. The S-GW 112 may be included in the communication system 120 provided by the MVNO instead of being included in the communication system 110 provided by the MNO.
[0012] UE130 is a device that can use communication services provided by the mobile communication network 100. UE130 may be, for example, a mobile phone, a personal computer, a sensor, an actuator, etc. In particular, UE130 may be an IoT (Internet of Things) device that performs M2M (machine to machine) communication. UE130 has a SIM 131. SIM 131 is an integrated circuit that stores data and programs used for communication with the mobile communication network 100. SIM 131 may be an eSIM (Embedded SIM) or a physical SIM. SIM 131 stores an IMSI (International Mobile Subscriber Identity) assigned by the operator of the communication system 120. IMSI is an example of subscriber identification information uniquely assigned for each subscription contract. SIM 131 may store only one IMSI or multiple IMSIs. When SIM 131 stores multiple IMSIs, UE 130 may select one of the multiple IMSIs to communicate with the mobile communication network 100 or another mobile communication network. The multiple IMSIs may be stored in physically different SIMs or in the same SIM.
[0013] The mobile communication network 100 provides packet communication functionality between the UE 130 and the external network 140. A packet is a data unit transmitted and received at the network layer according to IP (Internet Protocol), such as an IP datagram, an Ethernet frame, or an arbitrary protocol data unit.
[0014] eNB111 connects UE130 to S-GW112 and forwards packets between UE130 and S-GW112. In this specification, entities of the mobile communication network 100 (e.g., eNB111, S-GW112, P-GW121, etc.) may add / modify / delete parts of packets (e.g., headers) or split or combine packets when forwarding packets. Thus, packet forwarding may be transmitting the received packet as is, or transmitting a new packet based on at least a part of the received packet. eNB111 further provides UE130 with radio resource management functions, mobility management functions, scheduling functions, etc. eNB111 connects UE130 to MSC113 and forwards data between UE130 and MSC113. The data forwarded between UE130 and MSC113 may include voice data, messages, etc.
[0015] The HSS / HLR124 manages subscriber information for the mobile communication network 100. For example, the HSS / HLR124 stores subscriber location information, service subscription information, authentication information, etc., and performs operations such as adding, changing, and deleting this information.
[0016] S-GW112 provides the function of routing packets to or from UE130. S-GW112 is equivalent to the SGSN (Serving GPRS Support Node) in a 3G network.
[0017] The P-GW121 has the function of providing the UE130 with access to the external network 140. The P-GW121 is a gateway device that functions as an endpoint of the core network included in the mobile communication network 100. The external network 140 is a network different from the mobile communication network 100. The external network 140 may include a public network such as the internet, or it may include a private network provided by an individual company. The P-GW121 corresponds to the GGSN (Gateway GPRS Support Node) of a 3G network, and the SMF (Session Management Function) and UPF (User Plane Function) of a 5G network.
[0018] Packets from eNB111 to P-GW121 are forwarded in an encapsulated state through a tunnel established according to the GTP (GPRS Tunneling Protocol) (GTP tunnel). Other Layer 2 (L2) tunnels may be used instead of the GTP tunnel.
[0019] The P-GW 121 may consist of one or more Tier 1 servers 122 and one or more Tier 2 servers 123. In the example in Figure 1, the P-GW 121 consists of multiple Tier 1 servers 122 and multiple Tier 2 servers 123. The Tier 1 servers 122 are connected to the S-GW 112. The Tier 1 servers 122 receive packets transmitted by the UE 130 and forwarded by the S-GW 112. The Tier 1 servers 122 forward these packets to one or more Tier 2 servers 123. The Tier 1 servers 122 also forward packets received by one of the Tier 2 servers 123 from the external network 140 to the S-GW 112.
[0020] Tier 2 server 123 receives packets forwarded from Tier 1 server. Tier 2 server 123 may forward these packets to the external network 140. As described later, any of the Tier 2 servers 123 may discard at least some of the packets forwarded from Tier 1 server 122. Tier 2 server 123 may provide various services to communication by UE 130. For example, Tier 2 server 123 may function as a NAT (Network Address Translation) that performs processing at the network layer, or as a proxy that performs processing at the application layer. Furthermore, Tier 2 server 123 may perform image / video processing, credential assignment processing, etc., on behalf of UE 130.
[0021] The maximum number of servers that can be simultaneously connected to the S-GW112 as a P-GW121 is determined by the MNO. In this embodiment, by separating the P-GW121 into a server that exchanges packets (data) with the S-GW112 (Tier 1 server 122) and a server that provides access to the external network 140 and various additional services (Tier 2 server 123), the number of Tier 2 servers 123 can be increased beyond the maximum number of connections set by the MNO.
[0022] The session manager 125 is a server for controlling the operation of the P-GW 121. The session manager 125 may also be called a control server. For example, the session manager 125 may select the Tier 2 server 123 to which the Tier 1 server 122 forwards packets.
[0023] MSC113 is a switching center that sets up and opens communication paths with UE130. MSC113 forwards data received from UE130 to GMSC126 and SMSC128. For example, MSC113 may forward SMS messages sent by UE130 to SMSC128. MSC113 may forward USDD messages sent by UE130 to GMSC126.
[0024] MME114 is an entity that handles the location information, paging, movement control, bearer establishment and deletion of UE130. MME114 may authenticate UE130 based on authentication information notified by HSS / HLR124.
[0025] GMSC 126 is a switching center that interconnects with telephone networks and other mobile communication networks. GMSC 126 may forward the USDD messages received from UE 130 via MSC 113 to USDD gateway 127. USDD gateway 127 may send these USDD messages directly to the external network 140, or it may send them to the external network 140 through an application server that processes the USDD messages.
[0026] SMSC 128 is a switching center that sends and receives SMS messages. SMSC 128 may forward SMS messages received from UE 130 via MSC 113 to SMSCs of other mobile communication networks, or send them to destination UE 130s connected to the mobile communication network 100. Furthermore, SMSC 128 may send SMS messages received from SMSCs of other mobile communication networks to destination UE 130s connected to the mobile communication network 100.
[0027] Next, with reference to Figure 2, an example of the hardware configuration of a computer 200 according to one embodiment will be described. The computer 200 may be used to implement any of the components of the mobile communication network 100. Each component of the mobile communication network 100 may be implemented on one computer 200, or it may be implemented in a distributed manner across multiple computers 200. Alternatively, two or more components of the mobile communication network 100 may be implemented on one computer 200.
[0028] Computer 200 may be located in an on-premises environment. Alternatively, or in addition to this, the cloud may be composed of multiple computers 200, and any component of the mobile communication network 100 may be implemented by a virtual machine of the cloud (i.e., as an instance of the cloud). The cloud may be a public cloud such as AWS (Amazon Web Services) or a private cloud built for a single company. If the cloud is a public cloud, one or more Tier 1 servers 122 and one or more Tier 2 servers 123 may belong to a virtual private network on the cloud. For example, if the cloud is AWS, a virtual private network may be built using the VPC (Virtual Private Cloud) function.
[0029] By building P-GW121 on the cloud, the performance of P-GW121 can be changed at the appropriate time according to the processing status of P-GW121. Changing the performance of P-GW121 can be achieved by replacing one server with another server (a server with higher or lower processing power than the original server) (so-called scale-up / scale-down), or by changing the number of servers (so-called scale-out / scale-in).
[0030] The computer 200 may have the hardware shown in Figure 2. The processor 201 controls the overall operation of the computer 200. The processor 201 may consist of, for example, a CPU (Central Processing Unit). The processor 201 may be a single processor or a collection of multiple processors connected to each other in a communicative manner.
[0031] Memory 202 stores programs and data used for processing by the computer 200. Memory 202 may be configured, for example, as a combination of RAM (Random Access Memory) and ROM (Read Only Memory). The operation of each component of the mobile communication network 100 may be performed by the processor 201 executing programs loaded into memory 202. Alternatively, at least part of the operation of each component of the mobile communication network 100 may be performed by a dedicated integrated circuit such as an ASIC (Application Specific Integrated Circuit).
[0032] The input device 203 is a device for obtaining instructions from the user of the computer 200. The input device 203 may consist of one or more combinations of, for example, a keyboard, buttons, a touchpad, and a microphone. The display device 204 is a device for visually presenting information to the user of the computer 200. The display device 204 may be a dot-matrix display, such as a liquid crystal display. The input device 203 and the display device 204 may be located outside the computer. In this case, the computer 200 may have an interface for communicating with the external input device 203 and the display device 204.
[0033] The communication device 205 is a device for communicating with devices outside the computer 200. When the computer 200 performs wired communication, the communication device 205 may be a NIC (Network Interface Card) having a connector for connecting a cable. When the computer 200 performs wireless communication, the communication device 205 may be a wireless communication module including an antenna and a baseband processing circuit.
[0034] The secondary storage device 206 is a device for non-volatilely storing programs and data used in the processing of the computer 200. The secondary storage device 206 is composed of, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive).
[0035] Next, with reference to Figure 3, a specific example of the configuration of UE130 will be described. In addition to the SIM131, UE130 includes a processor 301, memory 302, application 303, and communication module 304. The processor 301 controls the overall operation of UE130. The processor 301 may be configured by, for example, a CPU. The processor 301 may be a single processor or a collection of multiple processors connected to each other in a communicative manner.
[0036] Memory 302 stores programs and data used for processing the UE 130. Memory 302 may be configured, for example, as a combination of RAM and ROM. The operation of the UE 130 may be performed by the processor 301 executing a program loaded into memory 302. Alternatively, at least part of the operation of the UE 130 may be performed by a dedicated integrated circuit such as an ASIC.
[0037] Application 303 performs processing specific to UE130. Application 303 is executed by processor 301 on memory 302. Communication module 304 communicates with mobile communication network 100 in response to requests from application 303.
[0038] The SIM 131 comprises a processor 311, a memory 312, and an application 313. The processor 311 and memory 312 are the same as those of the processor 301 and memory 302, except that they are used for processing the SIM 131. The memory 312 stores information used for communication, such as subscriber information, encryption keys, and telephone numbers.
[0039] Application 313 performs processing specific to SIM 131. Application 313 is executed by processor 301 on memory 312. Application 313 may be able to execute commands of a toolkit conforming to some standard (for example, the card application toolkit specified in ETSI TS 102 223). Application 313 may include a remote file management (RFM) application. The RFM application is a standard application implemented by the SIM vendor within the SIM operating system to handle standard file systems related to OTA. Application 313 may include an applet for processing OTA messages to trigger the initialization of communication using SIM 131.
[0040] An example of communication permission information 400 will be described with reference to Figure 4. Communication permission information 400 may also refer to information relating to permission for communication using the mobile communication network 100 by the UE 130. In Figure 4, communication permission information 400 is managed in a table format. Alternatively, communication permission information 400 may be managed in other formats. Communication permission information 400 may be managed, for example, by a session manager 125. Specifically, the storage unit of the session manager 125 (the memory 202 or secondary storage device 206 of the computer 200 that constitutes the session manager 125) may store the communication permission information 400.
[0041] The communication permission information 400 has an entry for each subscriber of the mobile communication network 100. Each entry in the communication permission information 400 represents the settings for an individual subscriber. Column 401 of the communication permission information 400 shows the identification information of each subscriber, i.e., subscriber identification information. The subscriber identification information used in the mobile communication network 100 can be any information that uniquely identifies a subscriber, and in the example in Figure 4, IMSI is used as an example of subscriber identification information. Column 401 may include other subscriber identification information such as SUPI (Subscription Permanent Identifier), ICCID, or MSISDN (Mobile Station International Subscriber Directory Number) in place of or in addition to IMSI. For example, column 401 may include both IMSI and MSISDN as subscriber identification information. If column 401 contains multiple types of subscriber identification information, column 401 may be divided into multiple columns. Furthermore, if the UE130 identification information (e.g., the IMEI (International Mobile Equipment Identifier)) is associated with a subscriber, the UE130 identification information may be used as subscriber identification information.
[0042] Column 402 of the communication permission information 400 indicates whether communication using the mobile communication network 100 is permitted or prohibited for each subscriber. For example, communication by UE 130 may be prohibited by the communication carrier if UE 130 has used up the communication capacity stipulated in the contract, the contract period for the communication service has expired, there are outstanding payments for the communication service, or UE 130, including SIM 131, has been stolen or lost.
[0043] In the example of FIG. 4, the session manager 125 uses communication permission information 400 to manage subscriber identification information that is subject to communication restrictions. The session manager 125 may provide an API (Application Programming Interface) for editing the communication permission information 400. Through this API, an external entity (for example, an administrator of a telecommunications carrier or a program of a billing server) may be allowed to edit the communication permission information 400. For example, an external entity may instruct the session manager 125 to edit the communication permission information 400 (for example, delete an entry, add an entry, or change each item of an entry).
[0044] Next, an example of a control method for the communication system 120 will be described with reference to FIG. 5. The method of FIG. 5 is executed for each subscriber whose communication using the mobile communication network 100 is permitted. In the following description of FIG. 5, a subscriber to be processed is simply referred to as a subscriber. Further, a UE 130 equipped with a SIM 131 of the subscriber to be processed is simply referred to as the subscriber's UE 130.
[0045] In S501, the session manager 125 determines whether communication by the subscriber has been prohibited. If it is determined that communication by the subscriber is prohibited ("YES" in S501), the session manager 125 transitions the process to S502, and otherwise ("NO" in S501), repeats S501. For example, the session manager 125 may determine that communication is prohibited in response to the communication permission information 400 being edited by an external entity and communication being set to prohibited for specific subscriber identification information. In addition or alternatively, the session manager 125 may determine that communication is prohibited when the UE 130 uses up the communication capacity specified in the contract, the contract period of the communication service expires, or the fee for the communication service is unpaid.
[0046] In S502, the session manager 125 notifies the subscriber UE 130 that the connection is prohibited. For example, this notification may be made by rejecting the C-plane session creation request with a permanent cause. If the UE 130 can process this response correctly, the UE 130 will no longer attempt to connect to the mobile communication network 100. However, some UE 130s may still attempt to connect to the mobile communication network 100.
[0047] Therefore, in S503, the session manager 125 determines whether the UE 130 is still trying to connect to the mobile communication network 100. If the session manager 125 determines that the UE 130 is still trying to connect to the mobile communication network 100 (YES in S503), it proceeds to S504; otherwise (NO in S503), it repeats S503. For example, the session manager 125 may determine that the UE 130 is still trying to connect to the mobile communication network 100 based on having received a session creation request from the communication system 110 for the subscriber's UE 130.
[0048] In S504, the session manager 125 configures the subscriber's SIM 131 via OTA (Over The Air) such that the UE 130 (specifically, the communication module 304 thereof) fails to unlock the SIM 131. In a state where protection by a PIN (Personal Identification Number) is enabled (that is, a PIN Enabled state), the SIM 131 requests the communication module 304 to input the PIN when starting to use the SIM 131. On the other hand, in a state where protection by the PIN is disabled (that is, a PIN Disabled state), the SIM 131 does not request the communication module 304 to input the PIN. The SIM 131 transitions to a PIN locked state in response to incorrect PINs being consecutively input a predetermined number of times while the protection is enabled. The PIN locked state of the SIM 131 is canceled by inputting a PUK (PIN Unblocking Key, which is also called Personal Unblocking Key or Personal Unlock Code). The SIM 131 makes the PIN locked state unrecoverable in response to incorrect PUKs being consecutively input a predetermined number of times while the SIM 131 is in the PIN locked state. A specific example of the method for configuring the SIM 131 such that the UE 130 fails to unlock the SIM 131 will be described later. If unlocking of the SIM 131 fails, the communication module 304 cannot acquire information necessary for communication from the SIM 131, and therefore the UE 130 stops attempting to connect to the mobile communication network 100. However, the session manager 125 may fail to configure the SIM 131 in this manner.
[0049] Therefore, in S505, the session manager 125 makes the same determination as in S503. If the session manager 125 determines that the UE 130 is still trying to connect to the mobile communication network 100, in S506, it prohibits the forwarding of packets from the subscriber's UE 130 to the external network 140. Details of how to prohibit the forwarding of packets to the external network 140 will be described later. The process in S506 makes it possible to suppress excessive communication from the UE 130 on the C plane (signaling data path) while prohibiting communication from the UE 130 on the U plane. If communication on the U plane (user data path) becomes impossible, the UE 130 may stop trying to connect to the mobile communication network 100. However, some UE 130s may still try to connect to the mobile communication network 100.
[0050] Therefore, in S507, the session manager 125 makes the same determination as in S503. If the session manager 125 determines that the UE 130 is still trying to connect to the mobile communication network 100, in S508 it analyzes the content of the connection attempt from the subscriber's UE 130 (Ping or DNS query) and simulates a successful response.
[0051] One example of simulating a response is to redirect traffic from UE130 to a simulated local endpoint capable of responding, which is built within the mobile communication network 100. Determining the type of traffic can be done by checking the protocol or by processing all requests to a specific port. For Ping responses, the communication system 120 redirects all ICMP requests, regardless of the port, to the local endpoint. For DNS queries, the communication system 120 redirects requests to the UDP / TCP port (port number 53); for SIP traffic, to the UDP / TCP port (port number 5060); and for HTTP requests, to the TCP ports (port numbers 80 and 8080) or their secure versions (port numbers 853, 5061, and 443, respectively) to the endpoint. The type of response can be changed by separating local endpoints by protocol and port. For example, the communication system 120 might respond with 200 OK for HTTP requests and the same local IP address for all DNS queries.
[0052] In the method shown in Figure 5, communication by UE130 is prohibited by processes S502, S504, S506, and S508. Alternatively, at least one of processes S502, S504, S506, and S508 may be omitted. For example, the session manager 125 may execute process S504 without executing process S502. Also, processes S502, S504, S506, and S508 may be performed in an order other than that shown in Figure 5.
[0053] Next, with reference to Figure 6, a specific example of how to configure SIM 131 so that UE 130 fails to unlock SIM 131 in S504 of Figure 5 will be described. In the method of Figure 6, session manager 125 configures SIM 131 so that UE 130 fails to unlock SIM 131 by sending a single message to UE 130. The message sent from session manager 125 to UE 130 may be an SMS message, a USDD message, or any other message. In the process of Figure 6, unless otherwise explained, the later of two consecutive operations may be executed in accordance with the earlier operation. Assume that at the time of execution of Figure 6, PIN protection of SIM 131 is disabled. That is, SIM 131 does not request PIN input from communication module 304.
[0054] In S601, application 303 requests communication module 304 to initiate communication. In S602, communication module 304 requests SIM 131 to perform a communication initialization operation in order to initiate communication with communication system 110. In S603, SIM 131 performs the communication initialization operation. In S604, SIM 131 passes the information generated by the initialization operation in S604 (for example, an encryption key used for communication with communication system 110) to communication module 304.
[0055] In S605, the communication module 304 uses the information obtained in S604 to request a connection from the communication system 110. In S606, the communication system 110 queries the HSS / HLR 124 to determine whether it is permitted to establish a connection to the SIM 131 of the UE 130, which was requested to connect in S605. In S607, the HSS / HLR 124 responds to the query in S606. In this example, it is assumed that it is permitted to establish a connection to the SIM 131 of the UE 130. In S608, the communication system 110 grants the communication module 304 permission to connect. This enables the communication module 304 to communicate through the mobile communication network 100.
[0056] Suppose that communication via SIM 131 is subsequently prohibited. In this case, at S609, the session manager 125 sends a message to the UE 130 (specifically, its communication module 304) via the communication system 110 to enable PIN protection for SIM 131. This message may be an SMS message, a USDD message, or any other message. The recipient of this message is the identification information of the SIM 131 whose communication is prohibited (for example, its phone number).
[0057] In S610, the communication module 304 requests the SIM 131 to enable PIN protection. For example, the communication module 304 requests the RFM application of the SIM 131 to execute a command to enable PIN protection. In S611, the SIM 131 (for example, its application 313) enables PIN protection in response to the request in S610. In S612, the SIM 131 returns the result of the processing in S610 to the communication module 304. In S613, the communication module 304 sends a message containing the result of the processing obtained in S612 to the session manager 125 via the communication system 110. This message may be an SMS message, a USDD message, or any other message.
[0058] In S614, the session manager 125 sends a message to the UE 130 (specifically, its communication module 304) via the communication system 110 to initialize communication for the SIM 131. This message may be an SMS message, a USDD message, or any other message. The recipient of this message is the identification information of the SIM 131 whose communication is prohibited (e.g., a phone number).
[0059] In S615, the communication module 304 requests the SIM 131 to initialize the communication. For example, the communication module 304 requests the toolkit of application 313 on the SIM 131 to execute a command to initialize the communication. In S616, the SIM 131 (for example, its application 313) performs the initialization in response to the request in S615. In S617, the SIM 131 returns the result of the processing in S616 to the communication module 304. In S618, the communication module 304 sends a message containing the result of the processing obtained in S617 to the session manager 125 through the communication system 110. This message may be an SMS message, a USDD message, or any other message.
[0060] In S619, SIM 131 requests communication module 304 to perform the communication initialization operation again. In S620, communication module 304 requests SIM 131 to perform the communication initialization operation. In S621, because PIN protection is enabled, SIM 131 requests communication module 304 to attempt to unlock SIM 131 (i.e., to input a PIN). However, communication module 304 cannot input a PIN and therefore cannot perform any further processing. Also, if communication module 304 fails to unlock SIM 131 multiple times in a row, SIM 131 changes to a PIN locked state (a state where a PIN cannot be input, but can be resolved by inputting PUK).
[0061] As described above, in the method shown in Figure 6, the session manager 125 configures the SIM 131 so that the UE 130 fails to unlock it by sending a message to the UE 130 in S609 to enable PIN protection for the SIM 131. Enabling PIN protection for the SIM 131 causes the communication module 304 to be requested to unlock the SIM 131. However, since the application 303 does not know the PIN of the SIM 131 or is not configured to provide the PIN, the UE 130 fails to unlock the SIM 131. Therefore, the UE 130 stops making connection requests to the communication system 110. In addition, the session manager 125 sends a message to the UE 130 in S614 to cause the UE 130 to perform communication initialization. As a result, the communication module 304 is immediately unable to communicate with the communication system 110.
[0062] Next, with reference to Figure 7, a specific example of another method of configuring SIM 131 so that UE 130 fails to unlock SIM 131 in S504 of Figure 5 will be described. In the method of Figure 7, session manager 125 configures SIM 131 so that UE 130 fails to unlock SIM 131 by sending a series of messages to UE 130. The messages sent from session manager 125 to UE 130 may be SMS messages, USDD messages, or other messages. In the process of Figure 7, unless otherwise explained, the later operation of two consecutive operations may be executed in accordance with the earlier operation. At the time of execution of Figure 7, PIN protection of SIM 131 is enabled, and application 303 is able to provide the PIN of SIM 131 to communication module 304.
[0063] The processing in S601 to S608 is the same as described in Figure 6. However, since PIN protection of SIM 131 is enabled, in S602, the communication module 304 inputs a PIN to SIM 131.
[0064] Suppose communication via SIM 131 is subsequently prohibited. Therefore, at S701, the session manager 125 sends a message to the UE 130 (specifically, its communication module 304) via the communication system 110 requesting a change in the PIN of SIM 131. This message may be an SMS message, a USDD message, or any other message. The recipient of this message is the identification information (e.g., the phone number) of the SIM 131 whose communication is prohibited. The message requesting a PIN change includes the current PIN and the new PIN. The current PIN may be the same as, or different from, the PIN actually set on, SIM 131.
[0065] In S702, the communication module 304 requests the SIM 131 to change its PIN. For example, the communication module 304 requests the RFM application of the SIM 131 to execute a command to change its PIN. In S703, the SIM 131 (for example, its application 313) updates its PIN with the new PIN included in the request if the current PIN included in the request matches its own PIN, in response to the request in S702. The SIM 131 (for example, its application 313) returns an error if the current PIN included in the request does not match its own PIN. In S704, the SIM 131 returns the result of the processing in S704 to the communication module 304. In S705, the communication module 304 sends a message containing the result of the processing obtained in S704 to the session manager 125 through the communication system 110. This message may be an SMS message, a USD message, or any other type of message.
[0066] Subsequently, the session manager 125 repeats the process from S701 to S705 three times. In a total of four repetitions, the current PIN included in the message requesting a PIN change may all be the same. Therefore, even if the PIN change is successful in the first message, subsequent repetitions will fail to change the PIN consecutively. As a result, the SIM 131 enters a PIN lock state.
[0067] The session manager 125 may, after changing the SIM 131 to a PIN-locked state, prevent the SIM 131 from recovering its PIN-locked state by failing to input a PUK a predetermined number of times consecutively. As a result, even if the communication module 304 is configured to resolve the PIN-locked state by inputting a PUK to the SIM 131, the PIN-locked state cannot be resolved, and therefore the communication module 304 fails to unlock the SIM 131.
[0068] Subsequently, the same processing as in S614 to S619 is performed. In S706, the communication module 304 requests the SIM 131 to perform a communication initialization operation. However, since the SIM 131 is in a PIN lock state, in S707, the SIM 131 returns a PIN input failure. Thus, the communication module 304 fails to unlock and cannot perform any further processing.
[0069] As described above, in the method shown in Figure 7, the session manager 125 configures the SIM 130 so that it fails to unlock the SIM 130 by sending multiple messages from S701 to the UE 130 requesting a change in the PIN of the SIM 131. In addition, at S614, the session manager 125 sends a message to the UE 130 to initiate the initialization of the communication. As a result, the communication module 304 is immediately unable to communicate with the communication system 110.
[0070] In step S504 of Figure 5, the session manager 125 may perform only one of the methods shown in Figure 6 or Figure 7. Alternatively, in step S504 of Figure 5, the session manager 125 may perform the method shown in Figure 6 and, if the UE 130 is unable to configure the SIM 131 to fail to unlock it (for example, if PIN protection for the SIM 131 has already been enabled), then perform the method shown in Figure 7.
[0071] Next, with reference to Figure 8, a specific example of a method for prohibiting packet forwarding to the external network 140 in S506 of Figure 5 will be described. In Figure 8, for the sake of simplicity, the case in which the P-GW 121 includes one Tier 1 server 122 will be described. If the P-GW 121 includes multiple Tier 1 servers 122, each of the multiple Tier 1 servers 122 may perform the following operations. The P-GW 121 includes two Tier 2 servers 123 (Figure 1), namely a forwarding server 123a and a blocking server 123b.
[0072] For subscribers whose communication is permitted, the Tier 1 server 122 forwards packets sent from the subscriber's UE 130 to the forwarding server 123a. The forwarding server 123a then forwards packets forwarded from the Tier 1 server 122 to the external network 140.
[0073] For subscribers whose communication is prohibited, the Tier 1 server 122 forwards packets sent from the subscriber's UE 130 to the blocking server 123b. The blocking server 123b discards the packets forwarded from the Tier 1 server 122 without forwarding them to the external network 140. In this way, the blocking server 123b blocks the communication of the UE 130. The blocking server 123b may also discard packets using the firewall function of the OS (Operating System, for example, Linux®).
[0074] The session manager 125 can prevent packets from subscribers whose communication is prohibited (UE 130) from being forwarded to the external network 140 by setting the forwarding destination of packets from the Tier 1 server 122 to the blocking server 123b.
[0075] The invention is not limited to the embodiments described above, and various modifications and changes are possible within the scope of the gist of the invention.
[0076] This application claims priority based on Japanese Patent Application No. 2025-053693, filed on 27 March 2025, and all of its contents are incorporated herein by reference.
Claims
1. A communication system comprising: identification means for identifying a subscriber whose communication is prohibited; and transmission means for transmitting one or more messages to a user device equipped with the subscriber's subscriber identification module to configure the subscriber identification module to fail to unlock the subscriber identification module.
2. The communication system according to claim 1, wherein the one or more messages include a message for enabling protection by the PIN (Personal Identification Number) of the subscriber identification module.
3. The communication system according to claim 2, wherein the transmitting means further transmits a message to the user device causing the user device to attempt to unlock the subscriber identification module after transmitting one or more messages.
4. The communication system according to any one of claims 1 to 3, wherein the one or more messages include a plurality of messages each requesting a change in the PIN of the subscriber identification module.
5. The communication system according to claim 4, wherein the transmitting means further transmits a message to the user device causing the user device to attempt to unlock the subscriber identification module after transmitting the one or more messages.
6. The communication system according to any one of claims 1 to 5, wherein the one or more messages include SMS messages or USDD messages.
7. The communication system according to any one of claims 1 to 6, wherein the one or more messages represent commands to an application operating on the subscriber identification module.
8. The communication system according to any one of claims 1 to 7, wherein the transmitting means further transmits a message to the user device notifying it of the prohibition of communication before transmitting the one or more messages.
9. A program for causing one or more computers to function as means of the communication system described in any one of claims 1 to 8.
10. A control method for a communication system, comprising the steps of: identifying a subscriber from whom communication is prohibited; and transmitting one or more messages to a user device equipped with the subscriber's subscriber identification module to configure the subscriber identification module to fail to unlock the subscriber identification module.