Sign In to Follow Application
View All Documents & Correspondence

Communication System Communication Terminal Authentication Method And Non Transitory Computer Readable Medium Storing Program For Same

Abstract: The purpose of the present invention is to provide a communication system capable of suppressing the authentication processing load on the network side when the number of communication terminals using the network has increased. The communication system of the present invention comprises a representative communication terminal (20) belonging to a communication group (10) that comprises a plurality of communication terminals dependent communication terminals (30) (32) that are different from the representative communication terminal (20) and that belong to the communication group (10) and a node device (40) that performs call processing control related to the plurality of communication terminals belonging to the communication group (10). The representative communication terminal (20) and dependent communication terminals (30) (32) have common key information and common SIM information. The representative communication terminal (20) transmits a portion of information included in authentication information transmitted from the node device (40) to the dependent communication terminals (30) (32) and executes an authentication process for the dependent communication terminals (30) (32) using the key information and the authentication information.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
14 August 2017
Publication Number
46/2017
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
Parent Application

Applicants

NEC CORPORATION
7 1 Shiba 5 chome Minato ku Tokyo 1088001

Inventors

1. ZHANG Xiaowei
c/o NEC Corporation 7 1 Shiba 5 chome Minato ku Tokyo 1088001
2. PRASAD Anand Raghawa
c/o NEC Corporation 7 1 Shiba 5 chome Minato ku Tokyo 1088001

Specification

Technical field
[0001]
 The present invention is a communication system, a communication terminal, relates to an authentication method and a program, for example, a communication system that performs authentication using the key information, communication terminal, relates to an authentication method, and a program.
Background technique
[0002]
 In recent years, mobile phones and smart phones have spread rapidly, there is a case where one person holds a plurality of mobile phone or the like. In the future, in addition to holding a person, an increase in the M2M (Machine to Machine) terminal for autonomously communicate with another communication device is predicted. M2M terminal, in 3GPP (3rd Generation Partnership Project) is referred to as MTC (Machine Type Communication) terminal, or the like. M2M terminal, for example, be a vending machine equipped with a communication function, may be a sensor device or the like having a communication function. Moreover, M2M terminal, like the mobile phone or the like, when the authentication process and the like for performing communication using the network needs to be performed. Also, in addition to the increase of the M2M terminal, the future, an increase of wearable terminals, spread of network appliances in the home are also expected. Wearable terminal, it may be considered to possess a number of terminal alone. In addition, as the network home appliances, for example, air conditioning, robot vacuum cleaner or a refrigerator, and the like.
[0003]
 Non-Patent Document 1, the authentication process flow is disclosed in the case of using the network as defined in 3GPP.
CITATION
Non-Patent Document
[0004]
Non-patent Document 1: 3GPP TS 33.401 V12.13.0,6 Chapter and Chapter 7 (2014-12)
Summary of the Invention
Problems that the Invention is to Solve
[0005]
 Future, M2M terminal is expected to increase rapidly. Therefore, all M2M terminals, when executing the authentication process disclosed in Non-Patent Document 1 has a problem that the load of the authentication processing in the network side is increased.
[0006]
 An object of the present invention, when the communication terminal using the network is increased, the communication system, a communication terminal capable of suppressing the load on the network side authentication processing is to provide an authentication method, and a program.
Means for Solving the Problems
[0007]
 Communication system according to a first aspect of the present invention, a representative communication terminal belonging to the communication group constituted by a plurality of communication terminals belonging to the communication group, and subordinate communication terminal different from the representative communication terminal, the communication group and a node apparatus for performing call processing control regarding the plurality of communication terminals belonging to the representative communication terminal and the slave communication terminal, have a common key information and common SIM information, the representative communication terminal, the node a part of the information included in the authentication information transmitted from the device transmits to the slave communication terminal, said dependent information set in the response message from the communication terminal, using the key information and the authentication information, and it executes the authentication process of the subordinate communication terminal.
[0008]
 Communication terminal according to the second aspect of the present invention is a communication terminal belonging to the communication group constituted by a plurality of communication terminals belonging to the communication group, and device communication unit that communicates with slave communication terminals, the communication a network communication unit that communicates with the node apparatus for performing call processing control regarding the plurality of communication terminals belonging to the group, a storage unit for storing common key information and the subordinate communication terminals, the authentication information transmitted from the node device transmitted to the slave communication terminal, said dependent information set in the response message from the communication terminal, using the key information and the authentication information, which includes an authentication unit which performs authentication processing of the slave communication terminals it is.
[0009]
 Authentication method according to the third aspect of the present invention is an authentication method executed in the representative communication terminal belonging to the communication group including the representative communication terminal and the subordinate communication terminals, the representative communication terminal and dependent belonging to the communication group sending a portion of the information included in the authentication information transmitted from the node apparatus for performing call processing control in the communication terminal to the slave communication terminal, and information set in the response message from the slave communication terminal, wherein the authentication information When, and executes authentication processing of the slave communication terminal using a common key information and common SIM information stored in the representative communication terminal and the slave communication terminal.
[0010]
 Program according to a fourth aspect of the present invention is a program to be executed by the representative communication terminal and the subordinate communication representative communication terminal a is a computer belonging to a communication group including the terminal, the representative communication terminal and dependent belonging to the communication group sending a portion of the information included in the authentication information transmitted from the node apparatus for performing call processing control in the communication terminal to the slave communication terminal, and information set in the response message from the slave communication terminal, wherein the authentication information If it is intended to execute to perform the authentication processing of the slave communication terminal using a common key information and common SIM information stored in the representative communication terminal and the slave communication terminal to the computer.
Effect of the Invention
[0011]
 The present invention, when the communication terminal using the network is increased, the communication system, a communication terminal capable of suppressing the load on the network side authentication processing, it is possible to provide an authentication method, and a program.
BRIEF DESCRIPTION OF THE DRAWINGS
[0012]
FIG. 1 is a configuration diagram of a communication system in the first embodiment.
FIG. 2 is a block diagram of a master device according to the second embodiment.
3 is a configuration diagram of a MME according to the second embodiment.
4 is a diagram showing the flow of authentication processing of the second device in the master device according to the second embodiment.
5 is a diagram showing the flow of authentication processing in the communication system according to the second embodiment.
6 is a diagram showing the flow of authentication processing in the communication system according to the second embodiment.
7 is a configuration diagram of a MME according to the third embodiment.
8 is a diagram showing a flow of authentication processing in the communication system according to the third embodiment.
9 is a diagram showing a flow of authentication processing in the communication system according to the third embodiment.
DESCRIPTION OF THE INVENTION
[0013]
 (Embodiment 1)
 Hereinafter, with reference to the drawings will be described embodiments of the present invention. First, a configuration example of a communication system according to a first embodiment of the present invention will be described with reference to FIG. Communication system of FIG. 1 has a typical communication terminal 20, the dependent communication terminals 30-32, the base station 45 and, the node device 40. Representative communication terminal 20 and dependent communication terminals 30-32 form a communication group 10. Communication group 10 is a group formed by a plurality of communication terminals. Terminals forming a communication group 10, for example, a plurality of wearable devices worn, networked appliances such installed in the home, the sensor and the meters in the building, familial and communication terminals in one group, maker it may be a vending machine or the like to manage.
[0014]
 Representative communication terminal 20 and dependent communication terminals 30-32, for example, may be a computer device or the like having a smartphone or communication function. In addition, representative communication terminal 20 may be a mobile router. Representative communication terminal 20 communicates with the node apparatus 40 via the base station 45. The representative communication terminal 20 may be connected to the base station 45 by wire or wireless, it may be connected to the base station 45 via the network. Further, the representative communication terminal 20 may be connected to the subordinate communication terminals 30-32 by wire or wireless, may be connected to the subordinate communication terminals 30-32 via the network.
[0015]
 Node device 40 performs call processing control for a plurality of communication terminals belonging to the communication group 10. Call processing control, for example, routing at the representative communication terminal 20 and dependent communication terminal 30 to the mobile network of data transmitted and received in 32, or may be an authentication processing of the representative communication terminal 20. Node device 40 may be, for example, a MME (Mobility Management Entity) or SGSN (Serving GPRS Support Node) or the like which is defined as an apparatus for carrying out the call processing control in 3GPP.
[0016]
 Representative communication terminal 20 and dependent communication terminals 30-32, have a common key information and common SIM (Subscriber Identity Module) information. The key information may be, for example, information used to generate the encryption key or secret key or the like. Representative communication terminal 20 and dependent communication terminals 30-32, for example, key information may be set during manufacture of the terminal. Or, representative to the communication terminal 20 and dependent communication terminals 30-32, not via the network, the key information through the information recording medium or the like may be set. Or, the representative communication terminal 20 and dependent communication terminals 30-32 may acquire the key information via a communication path robust security have reliability is ensured.
[0017]
 Representative communication terminal 20 receives the authentication information transmitted from the node device 40. Further, the representative communication terminal 20 transmits a portion of the information included in the received authentication information to the slave communication terminals 30-32. For example, the authentication information, the representative communication terminal 20 and dependent communication terminals 30-32 may be information used to determine whether to allow belonging to the communication group 10.
[0018]
 The representative communication terminal 20 subordinate information set in the response message from the communication terminal, using the authentication information transmitted from the key information and the node device 40 performs authentication processing of the slave communication terminals 30-32. For example, the representative communication terminal 20, as an authentication process, dependent communication terminals 30-32 may be determined whether it is possible to implement the service provided to the communication group 10.
[0019]
 As described above, by using the communication system of FIG. 1, the dependent communication terminals 30-32 may be executed an authentication process between the representative communication terminal 20, the authentication processing between the node device 40 there is no need to run. In other words, the node device 40 may be only executing the authentication process with the representative communication terminal 20 belonging to the communication group 10, there is no need to perform an authentication process and dependent communication terminals 30-32. Therefore, the node device 40, as compared with the case of executing an authentication process for a representative communication terminal 20 and dependent communication terminals 30-32, it is possible to reduce the burden related to authentication processing.
[0020]
 (Second Embodiment)
 Subsequently, configuration example of a master device 50 according to the second embodiment of the present invention will be described with reference to FIG. Master device 50 corresponds to the representative communication terminal 20 of FIG. 1. Master device 50, for example, may be referred to as a parent device or a parent device or the like. Further, in the present embodiment, illustrating a device corresponding to the subordinate communication terminals 30-32 in FIG. 1 as a second device. Second device, for example, may be referred to as a slave unit or slave device. Moreover, describing a device corresponding to the node device 40 of FIG. 1 as MME 60.
[0021]
 A master device 50, and the plurality of second devices, receives a service using the communication group 10. Service using the communication group 10, for example, may be a broadcasting service to the communication group 10 in. That is, a plurality of devices belonging to the communication group 10 can receive the same information simultaneously. Or, in the communication group 10 belongs smartphones and wearable devices such that the user holds the same information to the smart phone and the wearable device such as may be transmitted. Or, when a plurality of second devices are in a location remote from the master device 50 belongs to the communication group 10, the same information to the communication group 10 and the plurality of second devices may be transmitted.
[0022]
 Master device 50 includes a network communication unit 51, the authentication information storage unit 52, SIM (Subscriber Identity Module) information storage unit 53, and an authentication unit 54 and the device communication unit 55.
[0023]
 Master device 50, in the case of such as smart phones and mobile router, the network communication unit 51 performs wireless communication with a base station constituting a mobile network. The base station may be, for example, eNB (evolved Node B), etc. are defined in 3GPP. Or, the base station may be a base station corresponding to the radio communication system called a so-called 2G or 3G. Incidentally, the master device 50, in the case of such fixed wireless router, may communicate with a base station and a wired. Network communication unit 51 transmits a control signal to the MME60 like through the eNB. The network communication unit 51 via the eNB, receives a control signal transmitted from the like MME 60.
[0024]
 Network communication unit 51 transmits, for example, information about the authentication of the communication group 10 to MME 60. Information about the authentication of the communication group 10, for example, may be information identifying the communication group 10. Furthermore, the information relating to the authentication of the communication group 10 may include identification information of all the second devices belonging to the communication group 10.
[0025]
 Network communication unit 51 is, for example, the authentication vector used in the communication group 10 (hereinafter, referred to as group AV (Group Authentication Vector)) to be received from the MME. group AV, for example, to be utilized in the communication group 10, it may be information indicating the predetermined random number. The network communication unit 51 outputs the group AV received the authentication information storage section 52.
[0026]
 Authentication information storage unit 52 stores a group AV output from the network communication unit 51. Authentication information storage unit 52 may be an internal memory provided in the master device 50 may be an external storage device or the like which is mounted on the master device 50.
[0027]
 SIM information storage unit 53, SIM information used in common in the master device 50 and second device belonging to the communication group 10 stores (hereinafter, Group SIM, referred to). In the communication group 10 to the Group SIM commonly used, for example, it may include identification information for identifying the communication group 10. Moreover, SIM information storage unit 53, key information used in common in the master device 50 and second device belonging to the communication group 10 (hereinafter, key information K, hereinafter) is also held.
[0028]
 In the authentication information storage unit 52 is, for example, Group SIM and the key information K may be set during manufacture of the master device 50. Or, in the authentication information storage section 52, without going through the network, Group SIM and the key information K via an information recording medium or the like may be set. Or, the authentication information storage section 52 has a reliability, may acquire the Group SIM and the key information K via a communication path robust security is ensured. Also second device, like the master device 50 Group SIM and the key information K is set.
[0029]
 Authentication unit 54, Group SIM stored in the SIM information storage unit 53, using the Group AV stored in the key information K and the authentication information storage section 52, it generates the key information Kasme. Further, the authentication unit 54 performs an operation defined in advance using the Group SIM, key information K and Group AV, holds the operation result. Predetermined operation, for example, XOR may be (Exclusive OR or Exclusive disjunction) operation or the like.
[0030]
 The device communication unit 55 communicates with the plurality of second devices. The device communication unit 55 utilizes, for example, wireless LAN (Local Area Network) using a communication may be in communication with the second device, Bluetooth (registered trademark), a short-range wireless communication such as NFC (Near Field Communication) it may communicate with the second device to. Or, the device communication unit 55 may communicate with second device located far via the mobile network. Device communication unit 55, when using the mobile network, the same functional blocks as the network communication unit 51 and the device communication unit 55 may be a device or a circuit or the like.
[0031]
 The device communication unit 55, the plurality of second devices, transmits a Group AV stored in the authentication information storage section 52. Second device receiving the Group AV, as in the processing in the authentication unit 54, and generates and predetermined operation key information Kasme.
[0032]
 Authentication unit 54 via the device communication unit 55, the calculation result in each of the second device, the holding and the operation result has been that determine whether or not to coincide, the second device may belong to a communication group 10 It determines whether or not to permit.
[0033]
 Next, an example of the configuration of the MME60 according to a second embodiment of the present invention will be described with reference to FIG. MME60 includes a communication unit 61 and the authentication information storage section 62.
[0034]
 Authentication information storage unit 62 stores a Group AV of each communication group. The communication unit 61 communicates with the master device 50 via the eNB. The communication unit 61 from the master device 50, when information for identifying the communication group is transmitted, extracts the Group AV associated with the communication group received from the authentication information storing section 62. The communication unit 61 transmits the extracted Group AV to the master device 50.
[0035]
 Subsequently, with reference to FIG. 4, description will be given of a flow of authentication processing second device in the master device 50. First, the network communication unit 51 receives the Group AV from MME 60 (S11). Next, the authentication unit 54, Group SIM, generates key information Kasme using the key information K and Group AV (S12). Next, the authentication unit 54 performs an operation defined in advance using the Group SIM, key information K and Group AV (S13).
[0036]
 The device communication unit 55, among the plurality of information included in the Group AV transmitted from MME 60, and transmits the information except the XRES (Expected Response) to the plurality of second devices (S14). The device communication unit 55, the second device, Group SIM, receives the result of the operations carried out by using the information except the XRES among a plurality of information contained in the key information K and Group AV (S15).
[0037]
 Next, the authentication unit 54 determines the calculation results of calculation performed in step S13, whether the operation result and received from the second device in step S15 match (S16). Authentication unit 54, when judging that calculation result matches, permits the second device belongs to the communication group 10 (S17). Authentication unit 54, when the result is determined not to match, does not allow the second device belongs to the communication group 10 (S18). In other words, the master device 50 does not send the XRES sent to the second device from the MME 60, by comparing the RES received from the second device, and XRES which has been held, to authenticate the second device.
[0038]
 Subsequently, the flow of authentication processing according to the second embodiment of the present invention will be described with reference to FIG. First, the master device 50, between the MME 60, performs an authentication process for using the mobile network. That is, the master device 50, before performing the authentication process for utilizing the communication group, it executes an authentication process for performing normal communication through the mobile network. Normal communication is a communication other than the communication related to the service using the communication group 10. For example, normal communications, the master device 50, by using the mobile network may be a communication performed by specifying a communication terminal as a destination, the master device 50 may be a communication performed is specified as the destination .
[0039]
 In the master device 50 and MME 60 Prefecture, in order to perform an authentication process for performing normal communication through the mobile network, MME 60 sends the Authentication Request message through the eNB to the master device 50 (S21). In the following description, the communication between the MME60 and master device 50, and is performed via the eNB. MME60 the authentication vector transmitting the Authentication Request message set (hereinafter, referred to as AV).
[0040]
 Next, the master device 50 is received AV, performs an operation defined in advance using the SIM and the key information K1, the Authentication Response message set the operation result of performing transmission to MME 60 (S22). Here, SIM, unlike Group SIM, a SIM used in normal communication without using the communication group 10. Further, the key information K1, unlike the key information K, which is the key information used in the normal communication without using the communication group 10.
[0041]
 MME60 uses the calculation result sent from the master device 50, and a result of calculation in its own device, performs an authentication process related to the master device 50.
[0042]
 Next, the master device 50 in order to perform an authentication process regarding the communication group 10, the MME 60, and transmits the Group Authentication Request message (S23). Master device 50, for example, sets the information for identifying the communication group 10 to Group Authentication Request message. Furthermore, the master device 50, the identification information of all the second devices belonging to the communication group 10 may be set to Group Authentication Request message.
[0043]
 Next, MME 60 transmits a Group Authentication Response message set for Group AV associated with communication group 10 which is the master device 50 belongs to the master device 50 (S24).
[0044]
 Next, the master device 50 transmits Authentication Request message set information except the XRES among a plurality of information contained in the Group AV transmitted from MME60 to the second device (S25). If there are multiple second devices, the master device 50 transmits Authentication Request message for each second device.
[0045]
 Next, the second device transmits a Authentication Response message set the operation result using the information except the XRES among a plurality of information contained in the Group AV to the master device 50 (S26). Master device 50, when the authentication using the calculation result transmitted from the second device, sends a Group Authentication Confirmation message set the authentication result to the MME 60 (S27). MME60 by receiving the Group Authentication Confirmation message can recognize the second device belonging to the communication group 10.
[0046]
 Next, the second device and the master device 50 generates a Group Session Key Canada for use in communication using the communication group 10 (S28, S29).
[0047]
 Also, the flow of authentication processing in FIG. 5, can be applied in a 3G system using the W-CDMA. In this case, as shown in FIG. 6, eNB may be replaced by RNC (Radio Network Controller), MME may be replaced by a SGSN. Also, RNC may be replaced by an access point to perform wireless LAN communication. Step S121 ~ S129 in FIG. 6 is omitted steps S21 ~ S29 in detail because it is similar description of FIG.
[0048]
 As described above, by using the communication system according to a second embodiment of the present invention, each of the second device, not to perform an authentication process and MME60 or SGSN. Therefore, MME 60 or the SGSN, as compared with the case of performing the authentication process and all the second devices, the burden of the authentication process in the MME 60 or SGSN is reduced.
[0049]
 Further, the master device 50 and second device belonging to the communication group 10, the SIM and the key information K1 used in normal communication different from the communication using the communication group 10 separately, using the Group SIM and the key information K. Therefore, the key information Kasme generated using the SIM and key information used in the normal communication, the key information Kasme generated using the Group SIM and the key information K is different. This, in a case where the key information Kasme generated using the SIM and key information used in normal communication is also updated, the key information Kasme generated using the Group SIM and the key information K is not updated it may be. In other words, the key information Kasme generated using the Group SIM and the key information K is not affected by that key information Kasme generated using the SIM and key information used in normal communication is changed.
[0050]
 (Third Embodiment)
 Subsequently, an example of the configuration of the MME70 according to the third embodiment of the present invention will be described with reference to FIG. MME 60 in Figure 3, which had been stored Group AV in the authentication information storage section 62, MME 70 in FIG. 7, in terms of obtaining a Group AV from another device different from the MME 60. Specifically, MME 70 may be obtained from HSS (Home Subscriber Server), which is defined as a node that manages subscriber data in 3GPP the Group AV.
[0051]
 Next, a configuration example of the MME 70. MME70 includes a communication unit 71 and the authentication information obtaining unit 72. Communication unit 71, a detailed description thereof will be omitted since it is similar to the communication unit 61 in the MME 60.
[0052]
 Authentication information acquiring unit 72 acquires the Group AV from another device such as HSS. Authentication information acquiring unit 72 outputs the acquired Group AV to the communication unit 71.
[0053]
 Subsequently, the flow of authentication processing according to the third embodiment of the present invention will be described with reference to FIG. Step S31 ~ S33 is a detailed description thereof will be omitted because it is similar to that of steps S21 ~ S23 of FIG. 5.
[0054]
 MME70 receives the Group Authentication Request message in step S33, in order to obtain the Group AV regarding the communication group 10 which is the master device 50 belongs, to the HSS, and transmits the authentication information Request message (S34).
[0055]
 Next, HSS transmits the authentication information Response message set for Group AV relating to the communication group 10 (S35). Step S36 ~ S41 is a detailed description thereof will be omitted because it is similar to that of steps S24 ~ S29 of FIG. 5.
[0056]
 Also, the flow of authentication processing in FIG. 8, can be applied in a 3G system using the W-CDMA. In this case, as shown in FIG. 9, eNB may be replaced by RNC (Radio Network Controller), MME may be replaced by a SGSN, even the HSS replaced by HLR (Home Location Register) good. Also, RNC may be replaced by an access point to perform wireless LAN communication. Step S131 ~ S141 in FIG. 9 is omitted the steps S31 ~ S41 in detail because it is similar description of FIG.
[0057]
 As described above, by using the communication system according to the third embodiment, MME 70 which performs call processing control, there is no need to store the Group AV, the memory capacity for storing the Group AV it can be reduced.
[0058]
 It is also possible to perform the operation that combines the first and second embodiments. For example, MME 70, when performing initial authentication to a communication group 10 acquires Group AV from HSS, the acquired Group AV may be stored in the own device. Next, from the master device 50, when receiving the set of information regarding the communication group 10 Group Authentication Request message, it may send a Group AV are stored in the own device to the master device 50. That, MME 70, when transmitting Group AV that is not stored in the own device to the master device 50, when acquired the Group AV from HSS, may transmit the Group AV are stored in the own device, stores sending a Group AV it is the master device 50.
[0059]
 In the embodiment described above, the invention has been described as a hardware configuration, the present invention is not limited thereto. The present invention is a process in the master device 50 can also be implemented by executing a computer program to CPU (Central Processing Unit).
[0060]
 In the above example, the program may be stored using a non-transitory computer readable media of various types (non-transitory computer readable medium), it can be supplied to the computer. Non-transitory computer readable media include with various types of entities (tangible storage medium). Examples of non-transitory computer readable media include magnetic storage media (such as floppy disks, magnetic tape, hard disk drive), magneto-optical recording medium (e.g. optical disk), CD-ROM (Read Only Memory), CD-R, CD-R / W, a semiconductor memory (e.g., a mask ROM, PROM (Programmable ROM), EPROM (Erasable PROM), flash ROM, RAM (Random Access memory)) includes a. The program may be provided to a computer using a temporary computer readable media of various types (transitory computer readable medium). Examples of transitory computer readable media include electric signals, optical signals, and electromagnetic waves. Transitory computer readable media, wired communication path such as electrical wires and optical fibers, or via a wireless communication path can provide the program to a computer.
[0061]
 The present invention is not limited to the above embodiments, but can be appropriately changed without departing from the spirit.
[0062]
 Although the present invention has been described with reference to the embodiments, the present invention is not limited by the foregoing. Configuration and details of the present invention, it is possible to make various modifications that those skilled in the art can understand within the scope of the invention.
[0063]
 This application claims priority based on Japanese Patent Application No. 2015-027355, filed on February 16, 2015, the entire disclosure of which is incorporated herein.
DESCRIPTION OF SYMBOLS
[0064]
 10 communication group
 20 representative communication terminal
 30 subordinate communication terminals
 31 subordinate communication terminals
 32 subordinate communication terminal
 40 node device
 45 base station
 50 master
 51 network communication unit
 52 the authentication information storing section
 53 SIM information storage unit
 54 authenticating unit
 55 device communication unit
 60 MME
 61 communication unit
 62 the authentication information storing section
 70 MME
 71 communication unit
 72 the authentication information acquiring section

The scope of the claims
[Claim 1]
 And representative communication terminal belonging to the communication group constituted by a plurality of communication terminals,
 belonging to the communication group, and subordinate communication terminal different from the representative communication terminal,
 performs the call processing control regarding the plurality of communication terminals belonging to the communication group It includes a node device, a
 said representative communication terminal and the slave communication terminal,
 have a common key information and common SIM information,
 the representative communication terminal,
 one included in the authentication information transmitted from the node device information part transmitted to the slave communication terminal, the dependent set information in the response message from the communication terminal, the key information, using the SIM information and the authentication information, executes authentication processing of the slave communication terminals to, communication system.
[Claim 2]
 The representative communication terminal
 in the slave communication terminal, and the operation result produced by the calculation by the key information and predetermined by using the authentication information is executed in its own device, the key information and the authentication executes an authentication process of the subordinate communication terminal using a calculation result generated a result of executing the operation using the information, the communication system according to claim 1.
[Claim 3]
 The representative communication terminal,
 transmits the identification information of the communication group to the node device, receives the authentication information associated with the communication group from said node device, the communication system according to claim 1 or 2.
[Claim 4]
 The representative communication terminal and the slave communication terminal,
 the SIM information, the authentication information and by using the key information to generate Kasme information used in the communication group, according to any one of claims 1 to 3 communication system.
[Claim 5]
 Said node apparatus,
 when receiving the identification information of the communication group from the representative communication terminal, previously held to have said authentication information associated with the communication group or, associated with the communication group obtained from other node devices transmitting the valley authentication information to the representative communication terminal, a communication system according to any one of claims 1 to 4.
[Claim 6]
 A communication terminal belonging to the communication group constituted by a plurality of communication terminals,
 belonging to the communication group, and device communication means for communicating with slave communication terminals,
 the call processing control regarding the plurality of communication terminals belonging to the communication group network communication means for communicating with a node apparatus that performs,
 storage means for storing common key information and the slave communication terminal,
 and transmits the authentication information transmitted from the node device to the slave communication terminal, from the slave communication terminal information set in the response message, the key information and by using the authentication information, the communication terminal and an authentication means for executing authentication processing of the slave communication terminal.
[Claim 7]
 It said authentication means,
 in the subordinate communication terminals, the calculation result produced by the calculation by the key information and predetermined by using the authentication information is executed in its own device, the key information and the authentication information It executes an authentication process of the subordinate communication terminal using a calculation result generated a result of executing the operation using a communication terminal according to claim 6.
[8.]
 Wherein the storage unit,
 has a common SIM information,
 the authentication means,
 the SIM information, by using the authentication information and the key information, to generate the Kasme information used in the communication group, according to claim 6 or 7 communication terminal according to.
[Claim 9]
 An authentication method executed in the representative communication terminals belonging to the representative communication terminal and a communication group including the subordinate communication terminal,
 transmitted from the node apparatus which performs call processing control of the representative communication terminal and the subordinate communication terminal belonging to said communication group transmitting the portion of the information included in the authentication information to the slave communication terminal,
 and information set in the response message from the slave communication terminal, and the authentication information, the representative communication terminal and the storage in the dependent communication terminal It executes an authentication process of the subordinate communication terminal using a common key information and common SIM information, the being, the authentication method.
[Claim 10]
 A program to be executed by the representative communication terminal and the subordinate communication are representative communication terminal computer belonging to the communication group including the terminal,
 transmitted from the node apparatus which performs call processing control of the representative communication terminal and the subordinate communication terminal belonging to said communication group by transmitting the part of the information included in the authentication information to the slave communication terminal,
 and information set in the response message from the slave communication terminal, and the authentication information, in the representative communication terminal and the slave communication terminal common key information and common SIM information and non-transitory computer readable medium storing a program for executing to perform the authentication process of the subordinate communication terminal to the computer using a stored.

Documents

Application Documents

# Name Date
1 201717028888-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [14-08-2017(online)].pdf 2017-08-14
2 201717028888-STATEMENT OF UNDERTAKING (FORM 3) [14-08-2017(online)].pdf 2017-08-14
3 201717028888-REQUEST FOR EXAMINATION (FORM-18) [14-08-2017(online)].pdf 2017-08-14
4 201717028888-PROOF OF RIGHT [14-08-2017(online)].pdf 2017-08-14
5 201717028888-PRIORITY DOCUMENTS [14-08-2017(online)].pdf 2017-08-14
6 201717028888-POWER OF AUTHORITY [14-08-2017(online)].pdf 2017-08-14
7 201717028888-FORM 18 [14-08-2017(online)].pdf 2017-08-14
8 201717028888-FORM 1 [14-08-2017(online)].pdf 2017-08-14
9 201717028888-DRAWINGS [14-08-2017(online)].pdf 2017-08-14
10 201717028888-DECLARATION OF INVENTORSHIP (FORM 5) [14-08-2017(online)].pdf 2017-08-14
11 201717028888-COMPLETE SPECIFICATION [14-08-2017(online)].pdf 2017-08-14
12 201717028888.pdf 2017-08-17
13 201717028888-Power of Attorney-170817.pdf 2017-08-23
14 201717028888-OTHERS-170817.pdf 2017-08-23
15 201717028888-OTHERS-170817--.pdf 2017-08-23
16 201717028888-Correspondence-170817.pdf 2017-08-23
17 201717028888-Verified English translation (MANDATORY) [25-08-2017(online)].pdf 2017-08-25
18 201717028888-Proof of Right (MANDATORY) [25-08-2017(online)].pdf 2017-08-25
19 201717028888-OTHERS-010917.pdf 2017-09-05
20 201717028888-OTHERS-010917-.pdf 2017-09-05
21 201717028888-OTHERS-010917--.pdf 2017-09-05
22 201717028888-Correspondence-010917.pdf 2017-09-05
23 201717028888-FORM 3 [05-02-2018(online)].pdf 2018-02-05
24 201717028888-FER.pdf 2020-05-15

Search Strategy

1 searchstrategy201717028888_19-12-2019.pdf