WO2020136857A1 - 認証装置、システム、認証方法及びプログラム - Google Patents

認証装置、システム、認証方法及びプログラム Download PDF

Info

Publication number
WO2020136857A1
WO2020136857A1 PCT/JP2018/048402 JP2018048402W WO2020136857A1 WO 2020136857 A1 WO2020136857 A1 WO 2020136857A1 JP 2018048402 W JP2018048402 W JP 2018048402W WO 2020136857 A1 WO2020136857 A1 WO 2020136857A1
Authority
WO
WIPO (PCT)
Prior art keywords
decryption key
information
key information
authentication
decryption
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2018/048402
Other languages
English (en)
French (fr)
Inventor
昌博 佐田
孝則 滝井
忠良 櫻井
洋平 白川
大輔 三平
司 菅
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
SoftBank Corp
BB Backbone Corp
Original Assignee
SoftBank Corp
BB Backbone Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by SoftBank Corp, BB Backbone Corp filed Critical SoftBank Corp
Priority to PCT/JP2018/048402 priority Critical patent/WO2020136857A1/ja
Priority to JP2019555515A priority patent/JP6763096B1/ja
Publication of WO2020136857A1 publication Critical patent/WO2020136857A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present invention relates to an authentication device, a system, an authentication method and a program.
  • Patent Document 1 Japanese Patent Laid-Open No. 2013-168035
  • -It is desirable to provide a technology that can reduce the possibility of leaking SIM information.
  • an authentication device has a first storage area in which the first decryption key information is stored in a format that cannot be referenced from the outside, and a second storage area for storing the second decryption key information input from the outside.
  • a key information storage unit may be provided.
  • the authentication device may include a decryption key generation unit that generates a decryption key based on the first decryption key information stored in the first storage area and the second decryption key information stored in the second storage area. ..
  • the authentication device may include a decryption unit that decrypts the encrypted information using the decryption key.
  • the authentication device may include an authentication unit that receives an authentication request of the mobile terminal and authenticates the SIM based on the SIM information of the SIM of the mobile terminal included in the authentication request and the information decrypted by the decryption unit. ..
  • the authentication device may include a second decryption key information receiving unit that receives the second decryption key information from the outside and stores the second decryption key information in the second storage area.
  • the second decryption key information receiving unit may receive the second decryption key information transmitted via the Internet.
  • the first decryption key information may have a larger data amount than the second decryption key information.
  • the first decryption key information may have a smaller data amount than the second decryption key information.
  • the authentication device is a subscriber information storage unit that stores a plurality of subscriber information, and each of the plurality of subscriber information includes a subscriber identification number and key information unique to each SIM.
  • An information storage unit may be provided, the SIM information may include the subscriber identification number, and the authentication unit may include the subscriber identification number included in the SIM information and the subscriber identification number in the subscriber information storage unit.
  • the SIM may be authenticated based on the key information stored in association with the number and the information decrypted by the decryption unit.
  • the subscriber identification number may be IMSI (International Mobile Subscriber Identity), and the key information may be a K value.
  • a system including the authentication device and a management device that manages the authentication device.
  • the management device may include a first decryption key information receiving unit that receives the first decryption key information from the outside, and the storage control unit may include the first decryption key received by the first decryption key information receiving unit.
  • Information may be stored in the first storage area.
  • an authentication method has a first storage area in which the first decryption key information is stored in a format that cannot be referenced from the outside, and a second storage area for storing second decryption key information input from the outside. It may be executed by an authentication device having a key information storage unit.
  • the authentication method may include a decryption key generation step of generating a decryption key based on the first decryption key information stored in the first storage area and the second decryption key information stored in the second storage area. ..
  • the authentication method may comprise a decryption step of decrypting the encrypted information with the decryption key.
  • the authentication method may include an authentication step of accepting an authentication request of the mobile terminal and authenticating the SIM based on the SIM information of the SIM of the mobile terminal included in the authentication request and the information decrypted by the decryption unit. ..
  • a program has a key having a first storage area in which the first decryption key information is stored in a format that cannot be referenced from the outside and a second storage area for storing the second decryption key information input from the outside.
  • a decryption key generating step of generating a decryption key in a computer having an information storage unit based on the first decryption key information stored in the first storage area and the second decryption key information stored in the second storage area. May be executed.
  • the program may cause the computer to execute a decryption step of decrypting the encrypted information using the decryption key.
  • the program receives an authentication request of the mobile terminal to the computer, and performs an authentication step of authenticating the SIM based on the SIM information of the SIM of the mobile terminal included in the authentication request and the information decrypted by the decryption unit. You can let it run.
  • FIG. 1 schematically shows an example of the functional configuration of the AuC device 100.
  • 1 schematically shows an example of the configuration of the key information storage unit 102.
  • An example of the flow of processing by the AuC device 100 is schematically shown.
  • An example of the decryption key 610, the decryption key 620, and the decryption key 630 is schematically shown.
  • Another example of the decryption key 610, the decryption key 620, and the decryption key 630 is schematically shown.
  • An example of a functional configuration of the AuC vendor device 300 is schematically shown.
  • 1 schematically shows an example of a hardware configuration of a computer 1200 that functions as the AuC device 100.
  • FIG. 1 is an explanatory diagram for explaining a service realized by using the AuC device 100 according to this embodiment.
  • the AuC device 100 is an example of an authentication device.
  • This service provides a mechanism by which a mobile communication network can be configured inside the enterprise 50 or the like.
  • a carrier 20 as a telecommunications carrier provides a so-called core network in a mobile communication network to a PBX (Private Branch eXchanger) vendor 40, and the PBX vendor 40 provides the core network to a company 50 to provide a service.
  • PBX Primary Branch eXchanger
  • the mobile terminal 52 in the company 50 can perform wireless communication via the core network in the company 50 by the service.
  • the mobile terminal 52 is, for example, a mobile phone such as a smartphone.
  • the mobile terminal 52 may be a tablet terminal, a PC (Personal Computer), or the like. It is not limited to the mobile terminal 52 that enjoys the service.
  • a so-called IoT (Internet of Thing) terminal in the company 50 may execute wireless communication via the core network in the company 50.
  • the core network may be configured by one device or may be configured by a plurality of devices.
  • the device When the core network is configured by one device, the device is HSS, MME (Mobility Management Entity), PCRF (Policy and Charging Rule Function), SGW (Serving Gateway), and PGW (Packet gateway Data) function. You can do it.
  • the device may further function as an IMS (IP Multimedia Subsystem).
  • the core network may be composed of MME devices, HSS devices, PCRF devices, SGW devices, and PGW devices.
  • the core network may be configured by IMS devices in addition to these devices.
  • the AuC device 100 is a device having an AuC function, and when the core network is configured by one device, the AuC device 100 may be the one device. That is, the AuC device 100 may function as a core network.
  • the AuC device 100 may be an HSS device that constitutes the core network.
  • the AuC device 100 functions as a core network will be mainly described as an example.
  • the SIM of the mobile terminal 52 is authenticated using the authentication information stored in the SIM of the mobile terminal 52 and the authentication information stored in the HSS.
  • the raw value of the authentication information is strictly managed by the carrier 20, and it is premised that the raw value of the authentication information does not leak to the outside.
  • the service provider in this embodiment is the PBX vendor 40 and the AuC device 100 is located in the company 50, the premise is not established. If the authentication information is leaked, a clone SIM that can be used in the company 50 may be generated and the wireless communication service of the company 50 may be illegally used.
  • the service according to this embodiment provides a mechanism for suppressing the leakage of authentication information.
  • the carrier 20 divides the decryption key for decrypting the encrypted authentication information into the first decryption key information and the second decryption key information, and the first decryption key information is the AuC device 100.
  • the second decryption key information to the PBX vendor 40. Both the first decryption key information and the second decryption key information are information that together can generate a decryption key, and only one of them cannot generate a decryption key.
  • the carrier 20 uses the carrier device 200 to transmit the first decryption key information to the AuC vendor device 300 of the AuC vendor 30, for example.
  • the carrier device 200 transmits the first decryption key information to the AuC vendor device 300 via the network 80, for example.
  • the network 80 includes, for example, the Internet.
  • the AuC vendor 30 stores the first decryption key information in the AuC device 100.
  • the AuC vendor 30 causes the AuC vendor device 300 to store the first decryption key information received from the carrier device 200 in the AuC device 100, for example.
  • the AuC vendor device 300 transmits, for example, the first decryption key information to the AuC device 100 via the network 32 and stores the first decryption key information.
  • the network 32 may be a LAN (Local Area Network) included in the AuC vendor 30.
  • the AuC vendor device 300 may be directly connected to the AuC device 100.
  • the AuC device 100 that stores the first decryption key information is sold from the AuC vendor 30 to the PBX vendor 40, for example, and is placed in the company 50.
  • the carrier 20 uses the carrier device 200 to transmit the second decryption key information to the PBX vendor device 400 of the PBX vendor 40, for example.
  • the carrier device 200 transmits the second decryption key information to the PBX vendor device 400 via the network 80, for example.
  • the PBX vendor 40 uses the PBX vendor device 400 to transmit the second decryption key information to the AuC device 100.
  • the PBX vendor device 400 transmits the second decryption key information to the AuC device 100 arranged in the company 50 via the network 80, for example.
  • the AuC device 100 generates a decryption key from the stored first decryption key information and the second decryption key information received from the PBX vendor device 400. Then, when the AuC device 100 receives the encrypted authentication information, the AuC device 100 acquires the authentication information by decrypting it using the generated decryption key.
  • the first decryption key information received by the AuC vendor device 300 from the carrier device 200 may be manually stored in the AuC device 100 by the operator of the AuC vendor 30.
  • the AuC vendor 30 may provide the carrier 20 with a mechanism capable of writing data to the AuC device 100, and the carrier 20 may use the mechanism to write the first decryption key information in the AuC device 100. ..
  • FIG. 2 schematically shows an example of a service flow realized by using the AuC device 100 according to this embodiment.
  • the carrier 20 encrypts the first authentication information used for SIM authentication, divides the decryption key for decrypting the encrypted first authentication information into two, and defines them as KeyA and KeyB.
  • the state will be described as a start state.
  • the decryption key may be the same as the encryption key for encrypting the first authentication information.
  • the carrier 20 encrypts the first authentication information by using the first authentication information key and divides the first authentication information key into two.
  • the decryption key may be different from the encryption key that encrypts the first authentication information.
  • the carrier 20 encrypts the first authentication information by using the encryption key for the first authentication information, and the first authentication information different from the encryption key for the first authentication information is used.
  • the decryption key for use is divided into two.
  • a case where the encryption key and the decryption key are the same will be mainly described as an example.
  • the first authentication information includes, for example, various parameters used when performing SIM authentication.
  • the first authentication information includes OP, c, r, etc. defined in 3GPP (3rd Generation Partnership Project).
  • the first authentication information may further include a key for the second authentication information.
  • the second authentication information is used when performing SIM authentication.
  • the second authentication information may be information unique to each SIM.
  • the second authentication information is a K value that is key information unique to each SIM.
  • the key for the second authentication information may be a key for encrypting and decrypting the second authentication information.
  • the K value encrypted using the key for the second authentication information may be described as eKI.
  • step (step may be abbreviated as S) 102 the carrier device 200 transmits KeyA to the AuC vendor device 300.
  • KeyA is an example of first decryption key information.
  • the carrier device 200 transmits KeyB to the PBX vendor device 400.
  • KeyB is an example of second decryption key information.
  • the AuC vendor device 300 stores the KeyA received at S102 in the AuC device 100 in a format that cannot be referenced from the outside.
  • the PBX vendor apparatus 400 transmits the KeyB received in S104 to the AuC apparatus 100.
  • the AuC device 100 generates a decryption key based on KeyA and KeyB.
  • the carrier 20 provides the SIM manufactured by the SIM vendor to the PBX vendor 40, and the carrier device 200 encrypts the first authentication information and the SIM information including the eKI and the IMSI.
  • the first authentication information may be stored in the SIM provided by the carrier 20 to the PBX vendor 40.
  • the term "provide” as used herein is a concept that includes lending, transfer, and other rentals.
  • the carrier 20 notifies the SIM vendor of the first authentication information, and causes the SIM vendor to manufacture the SIM storing the first authentication information.
  • the carrier 20 notifies the SIM vendor of the first authentication information by a specific method that does not leak outside.
  • the SIM vendor writes the first authentication information in the SIM in a format that cannot be referenced from the outside.
  • the PBX vendor device 400 transmits the encrypted information to the AuC device 100.
  • the AuC device 100 uses the decryption key generated in S110 to decrypt the encrypted information received in S114.
  • the PBX vendor device 400 transmits the SIM information received in S112 to the AuC device 100.
  • the subscriber information is registered in the AuC device 100.
  • the AuC device 100 obtains the K value acquired by decrypting the eKI included in the SIM information received in S118 using the key for the second authentication information included in the authentication information decrypted in S116. , And the IMSI included in the SIM information are registered in association with each other.
  • the flow of services shown in Fig. 2 is an example, and the order of each step may be different.
  • the order in which the carrier device 200 transmits KeyA and KeyB may be reversed.
  • the carrier device 200 may not transmit the encrypted information and the SIM information to the PBX vendor device 400 at the same time, but may transmit them at different times.
  • the AuC device 100 may not transmit the encrypted information and the SIM information to the AuC device 100 at different times, but may transmit them at the same time.
  • FIG. 3 schematically shows an example of the functional configuration of the AuC device 100.
  • the AuC device 100 includes a key information storage unit 102, a decryption key information reception unit 110, a decryption key generation unit 112, an encryption information reception unit 114, a decryption unit 116, a subscriber information acquisition unit 118, a subscriber information storage unit 120, and authentication.
  • a request receiving unit 122 and an authentication unit 124 are provided.
  • the key information storage unit 102 stores a first decryption key information in a format that cannot be referenced from the outside, and a second storage area for storing the second decryption key information input from the outside. Have and.
  • the storage of the first decryption key information in the first storage area is performed by the AuC vendor device 300, for example.
  • the storage of the first decryption key information in the first storage area may be performed by the operator of the AuC vendor 30.
  • the storage of the first decryption key information in the first storage area may be performed by the carrier 20 by using a mechanism provided to the carrier 20 by the AuC vendor 30 and capable of writing data to the AuC device 100. ..
  • the second storage area may be an area predetermined as an area for storing the second decryption key information.
  • the decryption key information receiving unit 110 receives the second decryption key information.
  • the decryption key information receiving unit 110 may receive the second decryption key information from the outside.
  • the decryption key information receiving unit 110 receives the second decryption key information from the PBX vendor device 400 via the network 80, for example.
  • the decryption key information receiving unit 110 stores the received second decryption key information in the second storage area of the key information storage unit 102.
  • the decryption key generation unit 112 generates a decryption key based on the first decryption key information and the second decryption key information stored in the key information storage unit 102. Any method can be adopted as the method of dividing the decryption key into the first decryption key information and the second decryption key information and the method of generating the decryption key based on the first decryption key information and the second decryption key information. For example, the decryption key is generated by dividing the decryption key into the first half and the second half, and combining the first half and the second half.
  • the decryption key is divided based on a predetermined rule, and the decryption key generation unit 112 refers to the rule and generates a decryption key from the first decryption key information and the second decryption key information.
  • the amount of data may differ between the first decryption key information and the second decryption key information.
  • the first decryption key information may have a larger data amount than the second decryption key information
  • the second decryption key information may have a smaller data amount than the first decryption key information.
  • the first decryption key information may have a smaller data amount than the second decryption key information
  • the second decryption key information may have a larger data amount than the first decryption key information. Accordingly, as compared with the case where the data amount of the first decryption key information and the data amount of the second decryption key information are the same, for example, the first decryption written in the plurality of AuC devices 100 in the AuC vendor 30. The amount of key information data can be reduced, and the communication load and processing load in the AuC vendor 30 can be reduced.
  • the encrypted information receiving unit 114 receives the encrypted information.
  • the encrypted information receiving unit 114 receives the encrypted information from the PBX vendor device 400, for example.
  • the decryption unit 116 decrypts the encrypted information received by the encrypted information receiving unit 114, using the decryption key generated by the decryption key generating unit 112.
  • the decrypted information is authentication information.
  • the authentication information may be the first authentication information described above.
  • the subscriber information acquisition unit 118 acquires a plurality of subscriber information.
  • the subscriber information acquisition unit 118 includes, for example, the IMSI included in the SIM information received from the PBX vendor device 400 and the second authentication included in the authentication information decrypted by the decryption unit 116 with the eKI included in the SIM information.
  • the K value decrypted by using the key for use information is acquired.
  • the subscriber information storage unit 120 stores the subscriber information acquired by the subscriber information acquisition unit 118.
  • the subscriber information storage unit 120 stores the K value and the IMSI in association with each other.
  • the authentication request receiving unit 122 receives the authentication request of the mobile terminal 52.
  • the authentication request includes SIM information of the SIM of the mobile terminal 52.
  • the SIM information of the mobile terminal 52 may include the IMSI of the mobile terminal 52.
  • the authentication unit 124 receives the authentication request received by the authentication request receiving unit 122.
  • the authentication unit 124 based on the IMSI included in the authentication request, the K value stored in the subscriber information storage unit 120 in association with the IMSI, and the authentication information decrypted by the decryption unit 116,
  • the SIM of the mobile terminal 52 is authenticated.
  • FIG. 4 schematically shows an example of the configuration of the key information storage unit 102.
  • the key information storage unit 102 has a storage area 104 in which the first decryption key information is stored in a format that cannot be referenced from the outside, and a storage area 106 for storing the second decryption key information input from the outside.
  • the storage area 104 is an example of a first storage area.
  • the storage area 106 is an example of a second storage area.
  • FIG. 5 schematically shows an example of the flow of processing by the AuC device 100.
  • the flow of SIM authentication processing of the mobile terminal 52 by the AuC device 100 arranged in a certain company 50 will be schematically described.
  • the subscriber information acquisition unit 118 acquires the subscriber information assigned to the company 50 in which the AuC device 100 is arranged, and stores it in the subscriber information storage unit 120.
  • the authentication request receiving unit 122 receives the authentication request for the mobile terminal 52 in the company 50.
  • the authentication unit 124 receives the authentication request received by the authentication request receiving unit 122.
  • the authentication unit 124 reads the K value corresponding to the IMSI included in the authentication request from the subscriber information storage unit 120. In step S208, the authentication unit 124 generates a random number RAND, and uses the RAND and K value and the authentication information decrypted by the decryption unit 116 to generate an expected response.
  • the authentication unit 124 sends a RAND to the mobile terminal 52.
  • the SIM of the mobile terminal 52 receives the RAND.
  • the SIM uses the received RAND and the stored K value and authentication information to generate response information and sends it to the AuC device 100.
  • the authentication unit 124 receives the response information transmitted by the mobile terminal 52.
  • SIM authentication is performed by comparing the expected response generated in S208 with the response information received in S212.
  • the authentication unit 124 May send the expected response generated in S208 and RAND to the MME. Then, the MME may authenticate the SIM by transmitting RAND to the mobile terminal 52 and comparing the response information transmitted by the mobile terminal 52 and the expected response.
  • FIG. 6 schematically shows an example of a decryption key prepared in the carrier 20.
  • the carrier 20 may prepare different decryption keys for each of the PBX vendors 40.
  • FIG. 6 illustrates a decryption key 610 for the PBX vendor a company 41, a decryption key 620 for the PBX vendor b company 42, and a decryption key 630 for the PBX vendor c company 43.
  • the first decryption key information of the decryption key 610, the decryption key 620, and the decryption key 630 is common to the KeyA 650, and the second decryption key information is different from each other.
  • the second decryption key information in the decryption key 610 is KeyBa 612
  • the second decryption key information in the decryption key 620 is KeyBb 622
  • the second decryption key information in the decryption key 630 is KeyBc632.
  • FIG. 7 schematically shows another example of the decryption key prepared in the carrier 20.
  • FIG. 6 differences from FIG. 6 will be mainly described.
  • the decryption key 610, the decryption key 620, and the decryption key 630 have different first decryption key information and second decryption key information.
  • the first decryption key information in the decryption key 610 is KeyAa 651, and the second decryption key information is KeyBa 612.
  • the first decryption key information in the decryption key 620 is KeyAb652, and the second decryption key information is KeyBb622.
  • the first decryption key information in the decryption key 630 is KeyAc653, and the second decryption key information is KeyBc632.
  • the first decryption key information is also different for each of the plurality of PBX vendors 40, so that the first decryption key information is compared with the case where the first decryption key information common to the plurality of PBX vendors 40 is used. If it leaks, the range of influence can be narrowed.
  • FIG. 8 schematically shows an example of the functional configuration of the AuC vendor device 300.
  • the AuC vendor device 300 includes a decryption key information acquisition unit 302, a decryption key information storage unit 304, and a storage control unit 306.
  • the decryption key information acquisition unit 302 acquires the first decryption key information.
  • the decryption key information acquisition unit 302 receives the first decryption key information from the carrier device 200, for example.
  • the decryption key information acquisition unit 302 also acquires the first decryption key information input by the operator of the AuC vendor 30, for example. Further, the decryption key information acquisition unit 302 provides, for example, a mechanism capable of writing data to the AuC device 100 from the outside, and acquires the first decryption key information input via the mechanism.
  • the decryption key information storage unit 304 stores the first decryption key information acquired by the decryption key information acquisition unit 302.
  • the storage control unit 306 causes the AuC device 100 to store the first decryption key information stored in the decryption key information storage unit 304 in a format that cannot be referenced from the outside.
  • the storage control unit 306 stores the first decryption key information in the AuC device 100 being manufactured, for example.
  • the storage control unit 306 stores the first decryption key information in the AuC device 100 before shipment, for example, after the manufacturing is completed.
  • FIG. 9 schematically shows an example of the hardware configuration of a computer 1200 that functions as the AuC device 100.
  • the program installed in the computer 1200 causes the computer 1200 to function as one or more “units” of the apparatus according to the present embodiment, or causes the computer 1200 to perform an operation associated with the apparatus according to the present embodiment or Multiple “units” may be executed, and/or computer 1200 may execute processes according to embodiments of the present invention or stages of such processes.
  • Such programs may be executed by CPU 1212 to cause computer 1200 to perform certain operations associated with some or all of the blocks in the flowcharts and block diagrams described herein.
  • the computer 1200 includes a CPU 1212, a RAM 1214, and a graphic controller 1216, which are interconnected by a host controller 1210.
  • the computer 1200 also includes an input/output unit such as a communication interface 1222, a storage device 1224, a DVD drive 1226, and an IC card drive, which are connected to the host controller 1210 via the input/output controller 1220.
  • the DVD drive 1226 may be a DVD-ROM drive, a DVD-RAM drive, or the like.
  • the storage device 1224 may be a hard disk drive, a solid state drive, or the like.
  • Computer 1200 also includes ROM 1230 and legacy input/output units such as a keyboard, which are connected to input/output controller 1220 via input/output chip 1240.
  • the CPU 1212 operates according to a program stored in the ROM 1230 and the RAM 1214 to control each unit.
  • the graphic controller 1216 obtains image data generated by the CPU 1212 in a frame buffer provided in the RAM 1214 or the like, and causes the image data to be displayed on the display device 1218.
  • the communication interface 1222 communicates with other electronic devices via the network.
  • the storage device 1224 stores programs and data used by the CPU 1212 in the computer 1200.
  • the DVD drive 1226 reads a program or data from the DVD-ROM 1227 or the like and provides it to the storage device 1224.
  • the IC card drive reads programs and data from the IC card and/or writes programs and data to the IC card.
  • the ROM 1230 stores therein a boot program or the like executed by the computer 1200 at the time of activation, and/or a program dependent on the hardware of the computer 1200.
  • the I/O chip 1240 may also connect various I/O units to the I/O controller 1220 via USB ports, parallel ports, serial ports, keyboard ports, mouse ports, etc.
  • the program is provided by a computer-readable storage medium such as a DVD-ROM 1227 or an IC card.
  • the program is read from the computer-readable storage medium, installed in the storage device 1224, the RAM 1214, or the ROM 1230 that is also an example of the computer-readable storage medium, and executed by the CPU 1212.
  • the information processing described in these programs is read by the computer 1200, and brings about the cooperation between a program and the above-mentioned various types of hardware resources.
  • An apparatus or method may be configured by implementing the operation or processing of information according to the use of the computer 1200.
  • the CPU 1212 executes the communication program loaded in the RAM 1214, and performs the communication process on the communication interface 1222 based on the process described in the communication program. You may order.
  • the communication interface 1222 reads the transmission data stored in the transmission buffer area provided in the recording medium such as the RAM 1214, the storage device 1224, the DVD-ROM 1227, or the IC card under the control of the CPU 1212, and the read transmission is performed.
  • the data is transmitted to the network, or the received data received from the network is written in the reception buffer area provided on the recording medium.
  • the CPU 1212 causes the RAM 1214 to read all or necessary portions of files or databases stored in an external recording medium such as the storage device 1224, the DVD drive 1226 (DVD-ROM 1227), and an IC card, and the like. May perform various types of processing on the data. CPU 1212 may then write back the processed data to an external storage medium.
  • an external recording medium such as the storage device 1224, the DVD drive 1226 (DVD-ROM 1227), and an IC card, and the like. May perform various types of processing on the data.
  • CPU 1212 may then write back the processed data to an external storage medium.
  • the CPU 1212 may retrieve data read from the RAM 1214 for various types of operations, information processing, conditional judgment, conditional branching, unconditional branching, and information described elsewhere in this disclosure and specified by a program instruction sequence. Various types of processing may be performed, including /replacement, etc., and the result is written back to RAM 1214. Further, the CPU 1212 may search for information in files, databases, etc. in the recording medium. For example, when a plurality of entries each having the attribute value of the first attribute associated with the attribute value of the second attribute are stored in the recording medium, the CPU 1212 selects the first entry from the plurality of entries. Search the entry whose attribute value of the attribute of the specified attribute matches the specified condition, read the attribute value of the second attribute stored in the entry, and use it as the first attribute that satisfies the predetermined condition. The attribute value of the associated second attribute may be obtained.
  • the programs or software modules described above may be stored in a computer-readable storage medium on or near the computer 1200.
  • a recording medium such as a hard disk or a RAM provided in a server system connected to a dedicated communication network or the Internet can be used as a computer-readable storage medium, whereby the program can be stored in the computer 1200 via the network.
  • the blocks in the flowcharts and block diagrams in the present embodiment may represent a "stage" of a process in which an operation is executed or a "unit" of a device that has a role of executing the operation.
  • Specific steps and “parts” are provided along with dedicated circuitry, programmable circuitry provided with computer readable instructions stored on a computer readable storage medium, and/or computer readable instructions stored on a computer readable storage medium. It may be implemented by the processor.
  • Dedicated circuits may include digital and/or analog hardware circuits, and may include integrated circuits (ICs) and/or discrete circuits.
  • Programmable circuits include, for example, field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), and the like, logical product, logical sum, exclusive logical sum, negative logical product, negative logical sum, and other logical operations. , Reconfigurable hardware circuits, including flip-flops, registers, and memory elements.
  • FPGAs field programmable gate arrays
  • PLAs programmable logic arrays
  • Reconfigurable hardware circuits including flip-flops, registers, and memory elements.
  • Computer readable storage media may include any tangible device capable of storing instructions executed by a suitable device, such that a computer readable storage medium having instructions stored therein is a flowchart or block diagram. A product will be provided that includes instructions that can be executed to create means for performing the specified operations. Examples of computer readable storage media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, and the like. More specific examples of the computer readable storage medium include a floppy disk, a diskette, a hard disk, a random access memory (RAM), a read only memory (ROM), and an erasable programmable read only memory (EPROM or flash memory).
  • RAM random access memory
  • ROM read only memory
  • EPROM erasable programmable read only memory
  • EEPROM Electrically erasable programmable read only memory
  • SRAM static random access memory
  • CD-ROM compact disc read only memory
  • DVD digital versatile disc
  • Blu-ray registered trademark
  • Computer readable instructions include assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state setting data, or object oriented programming such as Smalltalk, JAVA, C++, etc. Language, and any source code or object code written in any combination of one or more programming languages, including conventional procedural programming languages such as the "C" programming language or similar programming languages. Good.
  • Computer readable instructions are instructions for a general purpose computer, special purpose computer, or processor of another programmable data processing device, or programmable circuit, to generate means for performing the operations specified in a flowchart or block diagram.
  • a general purpose computer, a special purpose computer, or other programmable data processing locally or via a wide area network (WAN) such as a local area network (LAN), the Internet, etc., to execute the computer readable instructions. It may be provided in the processor of the device or in a programmable circuit. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, and the like.
  • the mobile communication network supported by the core network may be, for example, a 3G (3rd Generation) network, a 5G (5th Generation) network, or a mobile communication network after 5G.
  • the AuC device 100 may be an HLR (Home Location Register) device.
  • the AuC device 100 may be a UDM (Unified Data Management) device.
  • the AuC device 100 according to this embodiment may be applied to LTE over Wi-Fi (registered trademark).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部と、第1記憶領域に記憶されている第1復号鍵情報と、第2記憶領域に記憶された第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成部と、復号鍵を用いて、暗号化された情報を復号化する復号部と、携帯端末の認証要求を受け付け、認証要求に含まれる携帯端末のSIMのSIM情報と、復号部によって復号化された情報とに基づいて、SIMの認証を行う認証部とを備える認証装置を提供する。

Description

認証装置、システム、認証方法及びプログラム
 本発明は、認証装置、システム、認証方法及びプログラムに関する。
 SIM(Subscriber Identity Module)に記憶された鍵情報と、HSS(Home Subscriber Server)上に保存された鍵情報とを用いてSIMの認証を行う仕組みが知られていた(例えば、特許文献1参照)。
 [先行技術文献]
 [特許文献]
 [特許文献1]特開2013-168035号公報
解決しようとする課題
 SIMの情報が漏えいする可能性を低減可能な技術を提供することが望ましい。
一般的開示
 本発明の第1の態様によれば、認証装置が提供される。認証装置は、第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部を備えてよい。認証装置は、第1記憶領域に記憶されている第1復号鍵情報と、第2記憶領域に記憶された第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成部を備えてよい。認証装置は、復号鍵を用いて、暗号化された情報を復号化する復号部を備えてよい。認証装置は、携帯端末の認証要求を受け付け、認証要求に含まれる携帯端末のSIMのSIM情報と、復号部によって復号化された情報とに基づいて、SIMの認証を行う認証部を備えてよい。
 上記認証装置は、上記第2復号鍵情報を外部から受信して上記第2記憶領域に記憶する第2復号鍵情報受信部を備えてよい。上記第2復号鍵情報受信部は、インターネットを介して送信された上記第2復号鍵情報を受信してよい。上記第1復号鍵情報は、上記第2復号鍵情報よりもデータ量が多くてよい。上記第1復号鍵情報は、上記第2復号鍵情報よりもデータ量が少なくてよい。
 上記認証装置は、複数の加入者情報を記憶する加入者情報記憶部であって、上記複数の加入者情報のそれぞれは、加入者識別番号と、SIM毎に固有の鍵情報とを含む加入者情報記憶部を備えてよく、上記SIM情報は上記加入者識別番号を含んでよく、上記認証部は、上記SIM情報に含まれる加入者識別番号と、上記加入者情報記憶部に当該加入者識別番号と対応付けて記憶されている鍵情報と、上記復号部によって復号化された情報とに基づいて、上記SIMの認証を行ってよい。上記加入者識別番号は、IMSI(International Mobile Subscriber Identity)であってよく、上記鍵情報は、K値であってよい。
 本発明の第2の態様によれば、上記認証装置と、上記認証装置を管理する管理装置とを備えるシステムが提供される。上記管理装置は、上記第1復号鍵情報を外部から受信する第1復号鍵情報受信部を備えてよく、上記記憶制御部は、上記第1復号鍵情報受信部が受信した上記第1復号鍵情報を上記第1記憶領域に記憶させてよい。
 本発明の第3の態様によれば、認証方法が提供される。認証方法は、第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部を有する認証装置により実行されてよい。認証方法は、第1記憶領域に記憶されている第1復号鍵情報と、第2記憶領域に記憶された第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成段階を備えてよい。認証方法は、復号鍵を用いて、暗号化された情報を復号化する復号段階を備えてよい。認証方法は、携帯端末の認証要求を受け付け、認証要求に含まれる携帯端末のSIMのSIM情報と、復号部によって復号化された情報とに基づいて、SIMの認証を行う認証段階を備えてよい。
 本発明の第4の態様によれば、プログラムが提供される。プログラムは、第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部を有するコンピュータに、第1記憶領域に記憶されている第1復号鍵情報と、第2記憶領域に記憶された第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成段階を実行させてよい。プログラムは、上記コンピュータに、復号鍵を用いて、暗号化された情報を復号化する復号段階を実行させてよい。プログラムは、上記コンピュータに、携帯端末の認証要求を受け付け、認証要求に含まれる携帯端末のSIMのSIM情報と、復号部によって復号化された情報とに基づいて、SIMの認証を行う認証段階を実行させてよい。
 なお、上記の発明の概要は、本発明の必要な特徴の全てを列挙したものではない。また、これらの特徴群のサブコンビネーションもまた、発明となりうる。
本実施形態に係るAuC(Authentication Centre)装置100を用いることによって実現されるサービスを説明するための説明図である。 本実施形態に係るAuC装置100を用いることによって実現されるサービスの流れの一例を概略的に示す。 AuC装置100の機能構成の一例を概略的に示す。 鍵情報記憶部102の構成の一例を概略的に示す。 AuC装置100による処理の流れの一例を概略的に示す。 復号鍵610、復号鍵620及び復号鍵630の一例を概略的に示す。 復号鍵610、復号鍵620及び復号鍵630の他の一例を概略的に示す。 AuCベンダ装置300の機能構成の一例を概略的に示す。 AuC装置100として機能するコンピュータ1200のハードウェア構成の一例を概略的に示す。
 以下、発明の実施の形態を通じて本発明を説明するが、以下の実施形態は請求の範囲にかかる発明を限定するものではない。また、実施形態の中で説明されている特徴の組み合わせの全てが発明の解決手段に必須であるとは限らない。
 図1は、本実施形態に係るAuC装置100を用いることによって実現されるサービスを説明するための説明図である。AuC装置100は、認証装置の一例である。本サービスは、企業50等の内部で移動体通信ネットワークを構成できるような仕組みを提供する。
 ここでは、通信事業者であるキャリア20が、移動体通信ネットワークにおけるいわゆるコアネットワークをPBX(Private Branch eXchanger)ベンダ40に提供し、PBXベンダ40が、コアネットワークを企業50に提供することによってサービスが実現される場合を例に挙げて説明する。企業50内の携帯端末52は、当該サービスによって、企業50内のコアネットワークを介して、無線通信を実行することができる。
 携帯端末52は、例えば、スマートフォン等の携帯電話である。携帯端末52は、タブレット端末及びPC(Personal Computer)等であってもよい。当該サービスを享受するのは、携帯端末52に限らない。例えば、企業50内のいわゆるIoT(Internet of Thing)端末が、企業50内のコアネットワークを介して、無線通信を実行してもよい。
 ここでは、移動体通信ネットワークがLTE(Long Term Evolution)ネットワークである場合を主に例に挙げて説明する。コアネットワークは、1つの装置によって構成されてもよく、また、複数の装置によって構成されてもよい。
 コアネットワークが1つの装置によって構成される場合、当該装置は、HSS、MME(Mobility Management Entity)、PCRF(Policy and Charging Rule Function)、SGW(Serving Gateway)、及びPGW(Packet Data Network Gateway)として機能してよい。当該装置は、さらにIMS(IP Multimedia Subsystem)として機能してもよい。
 コアネットワークが複数の装置によって構成される場合、コアネットワークは、MMEの装置、HSSの装置、PCRFの装置、SGWの装置、及びPGWの装置から構成されてよい。コアネットワークは、これらの装置に加えてさらにIMSの装置から構成されてもよい。
 本実施形態に係るAuC装置100は、AuCの機能を有する装置であり、コアネットワークが1つの装置によって構成される場合、AuC装置100は、当該1つの装置であってよい。すなわち、AuC装置100がコアネットワークとして機能してよい。コアネットワークが複数の装置によって構成される場合、AuC装置100は、コアネットワークを構成するHSSの装置であってよい。ここでは、AuC装置100がコアネットワークとして機能する場合を主に例に挙げて説明する。
 移動体通信ネットワークでは、携帯端末52のSIMに記憶されている認証用情報と、HSSに記憶されている認証用情報とを用いて、携帯端末52のSIMの認証が行われる。キャリア20が提供するいわゆる一般的な移動体通信ネットワークにおいては、認証用情報の生値がキャリア20によって厳重に管理されており、認証用情報の生値が外部に漏れないことを前提としている。しかし、本実施形態におけるサービスの提供主体はPBXベンダ40であり、AuC装置100は企業50内に配置されるので、その前提は成り立たないことになる。認証用情報が漏えいしてしまうと、企業50内で使用可能なクローンSIMが生成されて、企業50の無線通信サービスを不正規に利用されてしまい得る。
 本実施形態に係るサービスでは、認証用情報の漏えいを抑止する仕組みが提供される。本実施形態において、キャリア20は、暗号化された認証用情報を復号化するための復号鍵を第1復号鍵情報と第2復号鍵情報とに分割し、第1復号鍵情報をAuC装置100のベンダであるAuCベンダ30に提供し、第2復号鍵情報をPBXベンダ40に提供する。第1復号鍵情報及び第2復号鍵情報は、両方がそろって復号鍵を生成できる情報であり、いずれか一方のみでは復号鍵を生成することができない情報である。
 キャリア20は、例えば、キャリア装置200を用いて、AuCベンダ30のAuCベンダ装置300に第1復号鍵情報を送信する。キャリア装置200は、例えば、ネットワーク80を介して、第1復号鍵情報をAuCベンダ装置300に送信する。ネットワーク80は、例えば、インターネットを含む。
 AuCベンダ30は、第1復号鍵情報をAuC装置100に記憶させる。AuCベンダ30は、例えば、AuCベンダ装置300に、キャリア装置200から受信した第1復号鍵情報を、AuC装置100に記憶させる。AuCベンダ装置300は、例えば、ネットワーク32を介して第1復号鍵情報をAuC装置100に送信し、記憶させる。ネットワーク32は、AuCベンダ30が有するLAN(Local Area Network)等であってよい。AuCベンダ装置300は、AuC装置100に直接接続されてもよい。第1復号鍵情報を記憶したAuC装置100は、例えば、AuCベンダ30からPBXベンダ40に販売され、企業50内に配置される。
 キャリア20は、例えば、キャリア装置200を用いて、PBXベンダ40のPBXベンダ装置400に第2復号鍵情報を送信する。キャリア装置200は、例えば、ネットワーク80を介して、第2復号鍵情報をPBXベンダ装置400に送信する。
 PBXベンダ40は、PBXベンダ装置400を用いて、第2復号鍵情報をAuC装置100に送信する。PBXベンダ装置400は、例えば、ネットワーク80を介して、第2復号鍵情報を企業50内に配置されたAuC装置100に送信する。
 AuC装置100は、記憶している第1復号鍵情報と、PBXベンダ装置400から受信した第2復号鍵情報とから、復号鍵を生成する。そして、AuC装置100は、暗号化された認証用情報を受信した場合に、生成した復号鍵を用いて復号化することによって、認証用情報を取得する。
 このように、復号鍵を2つの鍵情報に分割して、AuCベンダ30及びPBXベンダ40のそれぞれに送信する構成とすることにより、仮に一方の鍵情報が、AuCベンダ30又はPBXベンダ40内で漏えいしたり、ネットワーク80上で漏えいしたりした場合であっても、復号鍵を生成できないようにすることができる。これにより、復号鍵が漏えいし、暗号化された認証用情報が復号化されて漏えいしてしまうリスクを低減することができる。
 なお、第1復号鍵情報をAuC装置100に記憶させる方法として、さまざまな方法を採用し得る。例えば、AuCベンダ装置300がキャリア装置200から受信した第1復号鍵情報を、AuCベンダ30のオペレータが手作業でAuC装置100に記憶させてもよい。また、例えば、AuCベンダ30が、データをAuC装置100に書き込み可能な仕組みをキャリア20に提供し、キャリア20が、当該仕組みを利用して、AuC装置100に第1復号鍵情報を書き込んでもよい。
 図2は、本実施形態に係るAuC装置100を用いることによって実現されるサービスの流れの一例を概略的に示す。ここでは、キャリア20が、SIM認証に用いる第1の認証用情報を暗号化し、暗号化した第1の認証用情報を復号化するための復号鍵を2つに分割してKeyA及びKeyBとした状態を開始状態として説明する。
 なお、当該復号鍵は、第1の認証用情報を暗号化するための暗号鍵と同一であってよい。この場合、キャリア20は、第1の認証用情報用の鍵を用いて第1の認証用情報を暗号化し、第1の認証用情報用の鍵を2つに分割する。また、当該復号鍵は、第1の認証用情報を暗号化する暗号鍵と異なってもよい。この場合、キャリア20は、第1の認証用情報用の暗号鍵を用いて第1の認証用情報を暗号化し、第1の認証用情報用の暗号鍵とは異なる、第1の認証用情報用の復号鍵を2つに分割する。ここでは、暗号鍵と復号鍵とが同一である場合を主に例に挙げて説明する。
 第1の認証用情報は、例えば、SIM認証を行うときに用いられる各種パラメータを含む。具体例として、第1の認証用情報は、3GPP(3rd Generation Partnership Project)において定義されているOP、c、r等を含む。第1の認証用情報は、さらに、第2の認証用情報用の鍵を含んでよい。第2の認証用情報は、SIM認証を行うときに用いられる。第2の認証用情報は、SIM毎に固有の情報であってよい。具体例として、第2の認証用情報は、SIM毎に固有の鍵情報であるK値である。第2の認証用情報用の鍵は、第2の認証用情報を暗号化及び復号化するための鍵であってよい。第2の認証用情報用の鍵を用いて暗号化されたK値をeKIと記載する場合がある。
 ステップ(ステップをSと省略して記載する場合がある。)102では、キャリア装置200が、KeyAをAuCベンダ装置300に送信する。KeyAは、第1復号鍵情報の一例である。S104では、キャリア装置200が、KeyBをPBXベンダ装置400に送信する。KeyBは、第2復号鍵情報の一例である。
 S106では、AuCベンダ装置300が、S102において受信したKeyAを、外部から参照不可能な形式でAuC装置100に記憶させる。S108では、PBXベンダ装置400が、S104において受信したKeyBを、AuC装置100に送信する。S110では、AuC装置100が、KeyAとKeyBとに基づいて復号鍵を生成する。
 S112では、キャリア20が、SIMベンダによって製造されたSIMをPBXベンダ40に提供し、キャリア装置200が、第1の認証用情報を暗号化した暗号化情報と、eKI及びIMSIを含むSIM情報とをPBXベンダ40に送信する。当該第1の認証用情報は、キャリア20がPBXベンダ40に提供したSIMに記憶されているものであってよい。なお、ここでいう提供とは、貸与、譲渡、その他レンタルを内包する概念である。
 キャリア20は、例えば、第1の認証用情報をSIMベンダに通知して、第1の認証用情報を記憶したSIMを、SIMベンダに製造させる。キャリア20は、外部に漏れることのない特定の方法で、第1の認証用情報をSIMベンダに通知する。SIMベンダは、外部から参照不可能な形式で第1の認証用情報をSIMに書き込む。
 S114では、PBXベンダ装置400が、暗号化情報をAuC装置100に送信する。S116では、AuC装置100が、S110において生成した復号鍵を用いて、S114において受信した暗号化情報を復号化する。
 S118では、PBXベンダ装置400が、S112において受信したSIM情報をAuC装置100に送信する。S120では、AuC装置100に、加入者情報を登録する。AuC装置100は、S118において受信したSIM情報に含まれるeKIを、S116において復号化した認証用情報に含まれる第2の認証用情報用の鍵を用いて復号化することによって取得したK値と、SIM情報に含まれるIMSIとを対応付けて登録する。
 図2に示すサービスの流れは一例であって、各ステップの順番は異なってもよい。例えば、キャリア装置200がKeyA及びKeyBを送信する順番は逆でもよい。また、例えば、キャリア装置200が暗号化情報及びSIM情報を同時期にPBXベンダ装置400に送信するのではなく、異なる時期に送信してもよい。また、例えば、AuC装置100が暗号化情報とSIM情報とを異なる時期にAuC装置100に送信するのではなく、同時期に送信してもよい。
 図3は、AuC装置100の機能構成の一例を概略的に示す。AuC装置100は、鍵情報記憶部102、復号鍵情報受信部110、復号鍵生成部112、暗号化情報受信部114、復号部116、加入者情報取得部118、加入者情報記憶部120、認証要求受信部122、及び認証部124を備える。
 鍵情報記憶部102は、第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する。第1復号鍵情報の第1記憶領域への記憶は、例えば、AuCベンダ装置300によって行われる。第1復号鍵情報の第1記憶領域への記憶は、AuCベンダ30のオペレータによって行われてもよい。第1復号鍵情報の第1記憶領域への記憶は、AuCベンダ30によってキャリア20に提供された、データをAuC装置100に書き込み可能な仕組みを利用することによって、キャリア20によって行われてもよい。第2記憶領域は、第2復号鍵情報を記憶する領域として予め定められた領域であってよい。
 復号鍵情報受信部110は、第2復号鍵情報を受信する。復号鍵情報受信部110は、外部から第2復号鍵情報を受信してよい。復号鍵情報受信部110は、例えば、PBXベンダ装置400からネットワーク80を介して第2復号鍵情報を受信する。復号鍵情報受信部110は、受信した第2復号鍵情報を、鍵情報記憶部102の第2記憶領域に記憶する。
 復号鍵生成部112は、鍵情報記憶部102に記憶されている第1復号鍵情報と第2復号鍵情報とに基づいて復号鍵を生成する。復号鍵を第1復号鍵情報及び第2復号鍵情報に分割する方法及び第1復号鍵情報及び第2復号鍵情報に基づいて復号鍵を生成する方法としては、任意の方法を採用し得る。例えば、復号鍵を前半と後半とに分割し、当該前半と当該後半とを結合することによって復号鍵が生成される。また、例えば、予め定められた規則に基づいて復号鍵を分割し、復号鍵生成部112は、当該規則を参照して、第1復号鍵情報及び第2復号鍵情報から復号鍵を生成する。
 第1復号鍵情報と第2復号鍵情報とは、データ量が異なってもよい。例えば、第1復号鍵情報は第2復号鍵情報よりもデータ量が多く、第2復号鍵情報は第1復号鍵情報よりもデータ量が少なくてよい。これにより、第1復号鍵情報のデータ量と第2復号鍵情報のデータ量とを同じにする場合と比較して、キャリア装置200からPBXベンダ装置400、及びPBXベンダ装置400からAuC装置100に対して送信される鍵情報のデータ量を低減することができる。
 また、例えば、第1復号鍵情報は第2復号鍵情報よりもデータ量が少なく、第2復号鍵情報は第1復号鍵情報よりもデータ量が多くてよい。これにより、第1復号鍵情報のデータ量と第2復号鍵情報のデータ量とを同じにする場合と比較して、例えば、AuCベンダ30内において、複数のAuC装置100に書き込まれる第1復号鍵情報のデータ量を低減することができ、AuCベンダ30内における通信負荷、処理負荷を低減することができる。
 暗号化情報受信部114は、暗号化情報を受信する。暗号化情報受信部114は、例えば、PBXベンダ装置400から暗号化情報を受信する。
 復号部116は、暗号化情報受信部114が受信した暗号化情報を、復号鍵生成部112によって生成された復号鍵を用いて復号化する。復号化された情報は、認証用情報である。当該認証用情報は、上述の第1の認証用情報であってよい。
 加入者情報取得部118は、複数の加入者情報を取得する。加入者情報取得部118は、例えば、PBXベンダ装置400から受信したSIM情報に含まれるIMSIと、SIM情報に含まれるeKIを復号部116によって復号化された認証用情報に含まれる第2の認証用情報用の鍵を用いて復号化したK値とを取得する。
 加入者情報記憶部120は、加入者情報取得部118が取得した加入者情報を記憶する。加入者情報記憶部120は、K値とIMSIとを対応付けて記憶する。
 認証要求受信部122は、携帯端末52の認証要求を受信する。認証要求には、携帯端末52のSIMのSIM情報が含まれる。携帯端末52のSIM情報には、携帯端末52のIMSIが含まれてよい。
 認証部124は、認証要求受信部122が受信した認証要求を受け付ける。認証部124は、認証要求に含まれるIMSIと、加入者情報記憶部120に当該IMSIと対応付けて記憶されているK値と、復号部116によって復号化された認証用情報とに基づいて、携帯端末52のSIMを認証する。
 図4は、鍵情報記憶部102の構成の一例を概略的に示す。鍵情報記憶部102は、第1復号鍵情報を外部から参照不可能な形式で記憶している記憶領域104と、外部から入力された第2復号鍵情報を記憶するための記憶領域106とを有する。記憶領域104は、第1記憶領域の一例である。記憶領域106は第2記憶領域の一例である。
 図5は、AuC装置100による処理の流れの一例を概略的に示す。ここでは、ある企業50内に配置されたAuC装置100による、携帯端末52のSIMの認証処理の流れを概略的に説明する。
 S202では、AuC装置100が配置された企業50に対して割り当てられた加入者情報を加入者情報取得部118が取得して、加入者情報記憶部120に記憶する。S204では、認証要求受信部122が、企業50内の携帯端末52の認証要求を受信する。認証部124は、認証要求受信部122が受信した認証要求を受け付ける。
 S206では、認証部124が、認証要求に含まれるIMSIに対応するK値を加入者情報記憶部120から読み出す。S208では、認証部124が、乱数であるRANDを発生し、RAND及びK値と、復号部116によって復号化された認証用情報とを用いて、想定応答を生成する。
 S210では、認証部124が、携帯端末52にRANDを送信する。携帯端末52のSIMは、当該RANDを受信する。SIMは、受信したRANDと、記憶しているK値及び認証用情報とを用いて、応答情報を生成し、AuC装置100に送信する。
 S212では、認証部124が、携帯端末52によって送信された応答情報を受信する。S214では、S208において生成した想定応答と、S212において受信した応答情報とを比較することにより、SIMの認証を行う。
 なお、ここでは、AuC装置100がコアネットワーク全体の役割を果たす場合を例に挙げて説明したが、コアネットワークが複数の装置によって構成され、AuC装置100がHSSの装置である場合、認証部124は、S208において生成した想定応答と、RANDとを、MMEに送信してよい。そして、MMEが、携帯端末52にRANDを送信し、携帯端末52によって送信された応答情報と、想定応答とを比較することによって、SIMの認証を行ってよい。
 図6は、キャリア20において準備される復号鍵の一例を概略的に示す。キャリア20は、複数のPBXベンダ40毎に異なる復号鍵を準備してよい。図6では、PBXベンダであるa社41用の復号鍵610、PBXベンダであるb社42用の復号鍵620、PBXベンダであるc社43用の復号鍵630を例示している。
 復号鍵610、復号鍵620、及び復号鍵630は、第1復号鍵情報がKeyA650で共通であり、第2復号鍵情報が互いに異なる。復号鍵610における第2復号鍵情報はKeyBa612であり、復号鍵620における第2復号鍵情報はKeyBb622であり、復号鍵630における第2復号鍵情報はKeyBc632である。
 このように、複数のPBXベンダ40毎に異なる復号鍵を準備することによって、複数のPBXベンダ40で共通の復号鍵を用いる場合と比較して、いずれかの復号鍵が漏えいしてしまった場合に影響の及ぶ範囲を狭くすることができる。
 図7は、キャリア20において準備される復号鍵の他の一例を概略的に示す。ここでは、図6とは異なる点を主に説明する。
 図7に示す例において、復号鍵610、復号鍵620、及び復号鍵630は、第1復号鍵情報も、第2復号鍵情報も互いに異なる。復号鍵610における第1復号鍵情報はKeyAa651であり、第2復号鍵情報はKeyBa612である。復号鍵620における第1復号鍵情報はKeyAb652であり、第2復号鍵情報はKeyBb622である。復号鍵630における第1復号鍵情報はKeyAc653であり、第2復号鍵情報はKeyBc632である。
 このように、第1復号鍵情報についても、複数のPBXベンダ40毎に異ならせることによって、複数のPBXベンダ40で共通の第1復号鍵情報を用いる場合と比較して、第1復号鍵情報が漏えいしてしまった場合に影響が及ぶ範囲を狭くすることができる。
 図8は、AuCベンダ装置300の機能構成の一例を概略的に示す。AuCベンダ装置300は、復号鍵情報取得部302、復号鍵情報記憶部304、及び記憶制御部306を備える。
 復号鍵情報取得部302は、第1復号鍵情報を取得する。復号鍵情報取得部302は、例えば、キャリア装置200から第1復号鍵情報を受信する。また、復号鍵情報取得部302は、例えば、AuCベンダ30のオペレータによって入力された第1復号鍵情報を取得する。また、復号鍵情報取得部302は、例えば、外部からデータをAuC装置100に書き込み可能な仕組を提供し、当該仕組を介して入力された第1復号鍵情報を取得する。復号鍵情報記憶部304は、復号鍵情報取得部302が取得した第1復号鍵情報を記憶する。
 記憶制御部306は、復号鍵情報記憶部304に記憶されている第1復号鍵情報を外部から参照不可能な形式でAuC装置100に記憶させる。記憶制御部306は、例えば、製造中のAuC装置100に第1復号鍵情報を記憶させる。また、記憶制御部306は、例えば、製造完了後、出荷前のAuC装置100に第1復号鍵情報を記憶させる。
 図9は、AuC装置100として機能するコンピュータ1200のハードウェア構成の一例を概略的に示す。コンピュータ1200にインストールされたプログラムは、コンピュータ1200を、本実施形態に係る装置の1又は複数の「部」として機能させ、又はコンピュータ1200に、本実施形態に係る装置に関連付けられるオペレーション又は当該1又は複数の「部」を実行させることができ、及び/又はコンピュータ1200に、本発明の実施形態に係るプロセス又は当該プロセスの段階を実行させることができる。そのようなプログラムは、コンピュータ1200に、本明細書に記載のフローチャート及びブロック図のブロックのうちのいくつか又はすべてに関連付けられた特定のオペレーションを実行させるべく、CPU1212によって実行されてよい。
 本実施形態によるコンピュータ1200は、CPU1212、RAM1214、及びグラフィックコントローラ1216を含み、それらはホストコントローラ1210によって相互に接続されている。コンピュータ1200はまた、通信インタフェース1222、記憶装置1224、DVDドライブ1226、及びICカードドライブのような入出力ユニットを含み、それらは入出力コントローラ1220を介してホストコントローラ1210に接続されている。DVDドライブ1226は、DVD-ROMドライブ及びDVD-RAMドライブ等であってよい。記憶装置1224は、ハードディスクドライブ及びソリッドステートドライブ等であってよい。コンピュータ1200はまた、ROM1230及びキーボードのようなレガシの入出力ユニットを含み、それらは入出力チップ1240を介して入出力コントローラ1220に接続されている。
 CPU1212は、ROM1230及びRAM1214内に記憶されたプログラムに従い動作し、それにより各ユニットを制御する。グラフィックコントローラ1216は、RAM1214内に提供されるフレームバッファ等又はそれ自体の中に、CPU1212によって生成されるイメージデータを取得し、イメージデータがディスプレイデバイス1218上に表示されるようにする。
 通信インタフェース1222は、ネットワークを介して他の電子デバイスと通信する。記憶装置1224は、コンピュータ1200内のCPU1212によって使用されるプログラム及びデータを記憶する。DVDドライブ1226は、プログラム又はデータをDVD-ROM1227等から読み取り、記憶装置1224に提供する。ICカードドライブは、プログラム及びデータをICカードから読み取り、及び/又はプログラム及びデータをICカードに書き込む。
 ROM1230はその中に、アクティブ化時にコンピュータ1200によって実行されるブートプログラム等、及び/又はコンピュータ1200のハードウェアに依存するプログラムを記憶する。入出力チップ1240はまた、様々な入出力ユニットをUSBポート、パラレルポート、シリアルポート、キーボードポート、マウスポート等を介して、入出力コントローラ1220に接続してよい。
 プログラムは、DVD-ROM1227又はICカードのようなコンピュータ可読記憶媒体によって提供される。プログラムは、コンピュータ可読記憶媒体から読み取られ、コンピュータ可読記憶媒体の例でもある記憶装置1224、RAM1214、又はROM1230にインストールされ、CPU1212によって実行される。これらのプログラム内に記述される情報処理は、コンピュータ1200に読み取られ、プログラムと、上記様々なタイプのハードウェアリソースとの間の連携をもたらす。装置又は方法が、コンピュータ1200の使用に従い情報のオペレーション又は処理を実現することによって構成されてよい。
 例えば、通信がコンピュータ1200及び外部デバイス間で実行される場合、CPU1212は、RAM1214にロードされた通信プログラムを実行し、通信プログラムに記述された処理に基づいて、通信インタフェース1222に対し、通信処理を命令してよい。通信インタフェース1222は、CPU1212の制御の下、RAM1214、記憶装置1224、DVD-ROM1227、又はICカードのような記録媒体内に提供される送信バッファ領域に記憶された送信データを読み取り、読み取られた送信データをネットワークに送信し、又はネットワークから受信した受信データを記録媒体上に提供される受信バッファ領域等に書き込む。
 また、CPU1212は、記憶装置1224、DVDドライブ1226(DVD-ROM1227)、ICカード等のような外部記録媒体に記憶されたファイル又はデータベースの全部又は必要な部分がRAM1214に読み取られるようにし、RAM1214上のデータに対し様々なタイプの処理を実行してよい。CPU1212は次に、処理されたデータを外部記録媒体にライトバックしてよい。
 様々なタイプのプログラム、データ、テーブル、及びデータベースのような様々なタイプの情報が記録媒体に記憶され、情報処理を受けてよい。CPU1212は、RAM1214から読み取られたデータに対し、本開示の随所に記載され、プログラムの命令シーケンスによって指定される様々なタイプのオペレーション、情報処理、条件判断、条件分岐、無条件分岐、情報の検索/置換等を含む、様々なタイプの処理を実行してよく、結果をRAM1214に対しライトバックする。また、CPU1212は、記録媒体内のファイル、データベース等における情報を検索してよい。例えば、各々が第2の属性の属性値に関連付けられた第1の属性の属性値を有する複数のエントリが記録媒体内に記憶される場合、CPU1212は、当該複数のエントリの中から、第1の属性の属性値が指定されている条件に一致するエントリを検索し、当該エントリ内に記憶された第2の属性の属性値を読み取り、それにより予め定められた条件を満たす第1の属性に関連付けられた第2の属性の属性値を取得してよい。
 上で説明したプログラム又はソフトウエアモジュールは、コンピュータ1200上又はコンピュータ1200近傍のコンピュータ可読記憶媒体に記憶されてよい。また、専用通信ネットワーク又はインターネットに接続されたサーバシステム内に提供されるハードディスク又はRAMのような記録媒体が、コンピュータ可読記憶媒体として使用可能であり、それによりプログラムを、ネットワークを介してコンピュータ1200に提供する。
 本実施形態におけるフローチャート及びブロック図におけるブロックは、オペレーションが実行されるプロセスの段階又はオペレーションを実行する役割を持つ装置の「部」を表わしてよい。特定の段階及び「部」が、専用回路、コンピュータ可読記憶媒体上に記憶されるコンピュータ可読命令と共に供給されるプログラマブル回路、及び/又はコンピュータ可読記憶媒体上に記憶されるコンピュータ可読命令と共に供給されるプロセッサによって実装されてよい。専用回路は、デジタル及び/又はアナログハードウェア回路を含んでよく、集積回路(IC)及び/又はディスクリート回路を含んでよい。プログラマブル回路は、例えば、フィールドプログラマブルゲートアレイ(FPGA)、及びプログラマブルロジックアレイ(PLA)等のような、論理積、論理和、排他的論理和、否定論理積、否定論理和、及び他の論理演算、フリップフロップ、レジスタ、並びにメモリエレメントを含む、再構成可能なハードウェア回路を含んでよい。
 コンピュータ可読記憶媒体は、適切なデバイスによって実行される命令を記憶可能な任意の有形なデバイスを含んでよく、その結果、そこに記憶される命令を有するコンピュータ可読記憶媒体は、フローチャート又はブロック図で指定されたオペレーションを実行するための手段を作成すべく実行され得る命令を含む、製品を備えることになる。コンピュータ可読記憶媒体の例としては、電子記憶媒体、磁気記憶媒体、光記憶媒体、電磁記憶媒体、半導体記憶媒体等が含まれてよい。コンピュータ可読記憶媒体のより具体的な例としては、フロッピー(登録商標)ディスク、ディスケット、ハードディスク、ランダムアクセスメモリ(RAM)、リードオンリメモリ(ROM)、消去可能プログラマブルリードオンリメモリ(EPROM又はフラッシュメモリ)、電気的消去可能プログラマブルリードオンリメモリ(EEPROM)、静的ランダムアクセスメモリ(SRAM)、コンパクトディスクリードオンリメモリ(CD-ROM)、デジタル多用途ディスク(DVD)、ブルーレイ(登録商標)ディスク、メモリスティック、集積回路カード等が含まれてよい。
 コンピュータ可読命令は、アセンブラ命令、命令セットアーキテクチャ(ISA)命令、マシン命令、マシン依存命令、マイクロコード、ファームウェア命令、状態設定データ、又はSmalltalk、JAVA(登録商標)、C++等のようなオブジェクト指向プログラミング言語、及び「C」プログラミング言語又は同様のプログラミング言語のような従来の手続型プログラミング言語を含む、1又は複数のプログラミング言語の任意の組み合わせで記述されたソースコード又はオブジェクトコードのいずれかを含んでよい。
 コンピュータ可読命令は、汎用コンピュータ、特殊目的のコンピュータ、若しくは他のプログラム可能なデータ処理装置のプロセッサ、又はプログラマブル回路が、フローチャート又はブロック図で指定されたオペレーションを実行するための手段を生成するために当該コンピュータ可読命令を実行すべく、ローカルに又はローカルエリアネットワーク(LAN)、インターネット等のようなワイドエリアネットワーク(WAN)を介して、汎用コンピュータ、特殊目的のコンピュータ、若しくは他のプログラム可能なデータ処理装置のプロセッサ、又はプログラマブル回路に提供されてよい。プロセッサの例としては、コンピュータプロセッサ、処理ユニット、マイクロプロセッサ、デジタル信号プロセッサ、コントローラ、マイクロコントローラ等を含む。
 上記実施形態では、移動体通信ネットワークがLTEネットワークである場合を主に例に挙げて説明したが、これに限らない。コアネットワークが対応する移動体通信ネットワークは、例えば、3G(3rd Generation)ネットワーク、5G(5th Generation)ネットワーク、及び5Gより後の移動体通信ネットワークであってもよい。コアネットワークが3Gネットワークに対応する場合であって、コアネットワークが複数の装置によって構成される場合、AuC装置100は、HLR(Home Location Register)の装置であってよい。コアネットワークが5Gネットワークに対応する場合であって、コアネットワークが複数の装置によって構成される場合、AuC装置100は、UDM(Unified Data Management)の装置であってよい。また、本実施形態に係るAuC装置100は、LTE over Wi-Fi(登録商標)に適用されてもよい。
 以上、本発明を実施の形態を用いて説明したが、本発明の技術的範囲は上記実施の形態に記載の範囲には限定されない。上記実施の形態に、多様な変更又は改良を加えることが可能であることが当業者に明らかである。その様な変更又は改良を加えた形態も本発明の技術的範囲に含まれ得ることが、請求の範囲の記載から明らかである。
 請求の範囲、明細書、及び図面中において示した装置、システム、プログラム、及び方法における動作、手順、ステップ、及び段階などの各処理の実行順序は、特段「より前に」、「先立って」などと明示しておらず、また、前の処理の出力を後の処理で用いるのでない限り、任意の順序で実現しうることに留意すべきである。請求の範囲、明細書、及び図面中の動作フローに関して、便宜上「まず、」、「次に、」などを用いて説明したとしても、この順で実施することが必須であることを意味するものではない。
20 キャリア
30 AuCベンダ
32 ネットワーク
40 PBXベンダ
41 a社
42 b社
43 c社
50 企業
52 携帯端末
80 ネットワーク
100 AuC装置
102 鍵情報記憶部
104 記憶領域
106 記憶領域
110 復号鍵情報受信部
112 復号鍵生成部
114 暗号化情報受信部
116 復号部
118 加入者情報取得部
120 加入者情報記憶部
122 認証要求受信部
124 認証部
200 キャリア装置
300 AuCベンダ装置
302 復号鍵情報取得部
304 復号鍵情報記憶部
306 記憶制御部
400 PBXベンダ装置
610 復号鍵
612 KeyBa
620 復号鍵
622 KeyBb
630 復号鍵
632 KeyBc
650 KeyA
651 KeyAa
652 KeyAb
653 KeyAc
1200 コンピュータ
1210 ホストコントローラ
1212 CPU
1214 RAM
1216 グラフィックコントローラ
1218 ディスプレイデバイス
1220 入出力コントローラ
1222 通信インタフェース
1224 記憶装置
1226 DVDドライブ
1227 DVD-ROM
1230 ROM
1240 入出力チップ

Claims (11)

  1.  第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部と、
     前記第1記憶領域に記憶されている前記第1復号鍵情報と、前記第2記憶領域に記憶された前記第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成部と、
     前記復号鍵を用いて、暗号化された情報を復号化する復号部と、
     携帯端末の認証要求を受け付け、前記認証要求に含まれる前記携帯端末のSIM(Subscriber Identity Module)のSIM情報と、前記復号部によって復号化された情報とに基づいて、前記SIMの認証を行う認証部と
     を備える認証装置。
  2.  前記第2復号鍵情報を外部から受信して前記第2記憶領域に記憶する第2復号鍵情報受信部
     を備える、請求項1に記載の認証装置。
  3.  前記第2復号鍵情報受信部は、インターネットを介して送信された前記第2復号鍵情報を受信する、請求項2に記載の認証装置。
  4.  前記第1復号鍵情報は、前記第2復号鍵情報よりもデータ量が多い、請求項1から3のいずれか一項に記載の認証装置。
  5.  前記第1復号鍵情報は、前記第2復号鍵情報よりもデータ量が少ない、請求項1から3のいずれか一項に記載の認証装置。
  6.  複数の加入者情報を記憶する加入者情報記憶部であって、前記複数の加入者情報のそれぞれは、加入者識別番号と、SIM毎に固有の鍵情報とを含む加入者情報記憶部
     を備え、
     前記SIM情報は前記加入者識別番号を含み、
     前記認証部は、前記SIM情報に含まれる加入者識別番号と、前記加入者情報記憶部に当該加入者識別番号と対応付けて記憶されている鍵情報と、前記復号部によって復号化された情報とに基づいて、前記SIMの認証を行う、請求項1から5のいずれか一項に記載の認証装置。
  7.  前記加入者識別番号は、IMSI(International Mobile Subscriber Identity)であり、
     前記鍵情報は、K値である、
     請求項6に記載の認証装置。
  8.  請求項1から7のいずれか一項に記載の認証装置と、
     前記認証装置を管理する管理装置であって、前記認証装置の前記第1記憶領域に前記第1復号鍵情報を記憶させる記憶制御部を有する管理装置と
     を備えるシステム。
  9.  前記管理装置は、
     前記第1復号鍵情報を外部から受信する第1復号鍵情報受信部
     を備え、
     前記記憶制御部は、前記第1復号鍵情報受信部が受信した前記第1復号鍵情報を前記第1記憶領域に記憶させる、請求項8に記載のシステム。
  10.  第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部を有する認証装置により実行される、
     前記第1記憶領域に記憶されている前記第1復号鍵情報と、前記第2記憶領域に記憶された前記第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成段階と、
     前記復号鍵を用いて、暗号化された情報を復号化する復号段階と、
     携帯端末の認証要求を受け付け、前記認証要求に含まれる前記携帯端末のSIMのSIM情報と、前記復号段階において復号化された情報とに基づいて、前記SIMの認証を行う認証段階と
     を備える認証方法。
  11.  第1復号鍵情報を外部から参照不可能な形式で記憶している第1記憶領域と、外部から入力された第2復号鍵情報を記憶するための第2記憶領域とを有する鍵情報記憶部を有するコンピュータに、
     前記第1記憶領域に記憶されている前記第1復号鍵情報と、前記第2記憶領域に記憶された前記第2復号鍵情報とに基づいて復号鍵を生成する復号鍵生成段階、
     前記復号鍵を用いて、暗号化された情報を復号化する復号段階、及び
     携帯端末の認証要求を受け付け、前記認証要求に含まれる前記携帯端末のSIMのSIM情報と、前記復号段階において復号化された情報とに基づいて、前記SIMの認証を行う認証段階
     を実行させるためのプログラム。
PCT/JP2018/048402 2018-12-28 2018-12-28 認証装置、システム、認証方法及びプログラム Ceased WO2020136857A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/JP2018/048402 WO2020136857A1 (ja) 2018-12-28 2018-12-28 認証装置、システム、認証方法及びプログラム
JP2019555515A JP6763096B1 (ja) 2018-12-28 2018-12-28 システム

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2018/048402 WO2020136857A1 (ja) 2018-12-28 2018-12-28 認証装置、システム、認証方法及びプログラム

Publications (1)

Publication Number Publication Date
WO2020136857A1 true WO2020136857A1 (ja) 2020-07-02

Family

ID=71126183

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2018/048402 Ceased WO2020136857A1 (ja) 2018-12-28 2018-12-28 認証装置、システム、認証方法及びプログラム

Country Status (2)

Country Link
JP (1) JP6763096B1 (ja)
WO (1) WO2020136857A1 (ja)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPWO2020188988A1 (ja) * 2019-03-20 2020-09-24

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH11298470A (ja) * 1998-04-16 1999-10-29 Hitachi Ltd 鍵の配布方法およびシステム
JP2001177642A (ja) * 1999-12-14 2001-06-29 Nec Commun Syst Ltd 交換機保守インターフェイスシステム
JP2005020608A (ja) * 2003-06-27 2005-01-20 Canon Inc コンテンツ配信システム
JP2015530802A (ja) * 2012-08-14 2015-10-15 クアルコム,インコーポレイテッド 動的hplmn構成のための方法、システムおよびデバイス

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH11298470A (ja) * 1998-04-16 1999-10-29 Hitachi Ltd 鍵の配布方法およびシステム
JP2001177642A (ja) * 1999-12-14 2001-06-29 Nec Commun Syst Ltd 交換機保守インターフェイスシステム
JP2005020608A (ja) * 2003-06-27 2005-01-20 Canon Inc コンテンツ配信システム
JP2015530802A (ja) * 2012-08-14 2015-10-15 クアルコム,インコーポレイテッド 動的hplmn構成のための方法、システムおよびデバイス

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPWO2020188988A1 (ja) * 2019-03-20 2020-09-24
JP7231010B2 (ja) 2019-03-20 2023-03-01 日本電気株式会社 制御装置、無線通信システム、制御方法及びプログラム
US12200483B2 (en) 2019-03-20 2025-01-14 Nec Corporation Control apparatus, radio communication system, control method, and recording medium having recorded program

Also Published As

Publication number Publication date
JPWO2020136857A1 (ja) 2021-02-15
JP6763096B1 (ja) 2020-09-30

Similar Documents

Publication Publication Date Title
US12137173B2 (en) Mutually authenticated ECDHE key exchange for a device and a network using multiple PKI key pairs
US12051064B2 (en) Transaction messaging
US11544677B2 (en) Methods and systems for facilitating microservices for cryptographic operations
CN113572715B (zh) 基于区块链的数据传输方法和系统
US10250613B2 (en) Data access method based on cloud computing platform, and user terminal
CN110169102B (zh) 隐私保护的方法及设备
US20120303310A1 (en) Systems and Methods for Providing Test Keys to Mobile Devices
CN104205891A (zh) 虚拟sim卡云平台
US11227041B2 (en) Identification service based authorization
CN113849847A (zh) 用于对敏感数据进行加密和解密的方法、设备和介质
US12200483B2 (en) Control apparatus, radio communication system, control method, and recording medium having recorded program
CN107609410B (zh) 基于HOOK的Android系统数据保护方法、终端设备及存储介质
CN104246784A (zh) 用于保护和安全地传输媒体内容的方法、设备和系统
CN110598429A (zh) 数据加密存储和读取的方法、终端设备及存储介质
WO2020073712A1 (zh) 一种移动终端中共享安全应用的方法及移动终端
CN111190974A (zh) 可验证声明的转发、获取方法、装置及设备
CN108713200B (zh) 用于将订阅加载到移动终端设备的嵌入式安全元件中的方法
JP6763096B1 (ja) システム
CN115361202A (zh) 区块链跨链方法、装置、存储介质及电子设备
CN112953893B (zh) 基于隐私保护的身份验证方法、装置、设备及系统
US12505076B2 (en) Method for using an ORAM database by a terminal equipment, corresponding computer program product and device
US20220174490A1 (en) System, method, storage medium and equipment for mobile network access
TW202415032A (zh) 一種資料共用系統、方法、裝置、設備及介質
CN114638685A (zh) 一种风险识别方法、装置及设备
CN106209381A (zh) 一种照片加解密方法及其系统

Legal Events

Date Code Title Description
ENP Entry into the national phase

Ref document number: 2019555515

Country of ref document: JP

Kind code of ref document: A

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18944306

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18944306

Country of ref document: EP

Kind code of ref document: A1