Method for connecting user equipment and h(e)nb, method for authenticating user equipment, mobile telecommunication system, h (e)nb, and core network
Abstract
Problem to be solved.To provide a means for performing an authentication process when connecting a wireless base station device and a user device, and a means for setting and managing a wireless base station device with security.
Solution.In a mobile communication system including a core network, a user device, and H (e) NB and Node B which are connected to the core network and communicate with each other and wirelessly communicate with the user device, H (e). ) After the NB connects to the core network, the subscriber identifier of the user device that first makes the connection request is used as the owner identifier, and is stored in the core network in association with the H (e) NB identifier of the H (e) NB. Let me. Further, the user device corresponding to the owner identifier stores an access control list including the subscriber identifier of the user device that is allowed to connect to the H (e) NB in the core network. The core network authenticates the connection request to the H (e) NB of the user device based on the access control list. [Selection diagram] Fig. 2

Term
1.8 yearsto projected expiry
Projected expiry 25 July 2028, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
28 claims: 8 independent, 20 dependent
- 1ユーザ装置とH(e)NBとコア・ネットワークとを有する移動体通信システムにおける前記ユーザ装置と前記H(e)NBとを無線通信で接続する方法であって、 前記H(e)NBが、前記ユーザ装置を識別する加入者識別子を含む接続要求情報をコア・ネットワークに送信する過程と、 前記コア・ネットワークが、受信した前記接続要求情報に基づいて、予め記憶されているアクセス制御リストを参照して前記ユーザ装置を前記H(e)NBに接続するか否かを判定する過程と、 を有することを特徴とするユーザ装置とH(e)NBとの接続方法。
- 2前記接続要求情報は、前記H(e)NBに予め付与されたH(e)NB識別子を含む ことを特徴とする請求項1に記載のユーザ装置とH(e)NBとの接続方法。
- 3前記コア・ネットワークは、前記H(e)NBに予め付与されたH(e)NB識別子と、該H(e)NBに割当てられたIPアドレス情報とが対応付けられたセキュリティアソシエーション情報を記憶し、 前記接続要求情報は、前記IPアドレス情報を含む ことを特徴とする請求項1に記載のユーザ装置とH(e)NBとの接続方法。
- 4前記アクセス制御リストは、前記H(e)NBの前記H(e)NB識別子が該H(e)NBに接続を許された前記ユーザ装置の前記加入者識別子に対応付けられた情報を含む ことを特徴とする請求項2又は請求項3に記載のユーザ装置とH(e)NBとの接続方法。
- 5前記ユーザ装置が、該ユーザ装置の前記加入者識別子を含み、接続の要求を示す端末接続要求情報を、接続を要求する前記H(e)NBに送信する過程を有する ことを特徴とする請求項4に記載のユーザ装置とH(e)NBとの接続方法。
- 6前記コア・ネットワークが、前記H(e)NBから前記接続要求情報を受信すると、予め記憶している認証情報を参照して、該H(e)NBを接続するか否かを判定する過程を有し、 前記認証情報は、前記コア・ネットワークに接続することを許された前記H(e)NBの前記H(e)NB識別子を含む情報である ことを特徴とする請求項5に記載のユーザ装置とH(e)NBとの接続方法。
- 7前記コア・ネットワークが、前記H(e)NBごとにオーナー識別子としての前記加入者識別子と、前記認証情報に含まれる前記H(e)NB識別子とを対応付けて記憶して前記認証情報を更新する過程を有し、 前記オーナー識別子として前記認証情報に記憶された前記加入者識別子は、前記H(e)NBが最初に受信した前記端末接続要求情報に含まれる前記加入者識別子であり、 前記アクセス制御リストに含まれる前記H(e)NB識別子と前記加入者識別子とが対応付けられた情報は、前記オーナー識別子に対応する前記ユーザ装置を用いて定められた情報である ことを特徴とする請求項6記載のユーザ装置とH(e)NBとの接続方法。
- 8前記オーナー識別子に対応する前記ユーザ装置が、前記アクセス制御リストに前記加入者識別子を記憶させる際に、 該加入者識別子に対応する前記ユーザ装置が、前記アクセス制御リストに記憶されることを加入者に通知する情報を出力する過程と、 前記ユーザ装置が、前記加入者の操作により入力される該加入者識別子が前記アクセス制御リストに記憶されることを承諾するか否かを示す情報を含む応答情報を、前記コア・ネットワークに送信する過程と、 前記コア・ネットワークは、前記応答情報に含まれる情報に基づいて前記アクセス制御リストに前記加入者識別子を記憶する過程と を有することを特徴とする請求項7に記載のユーザ装置とH(e)NBとの接続方法。
- 9前記移動体通信システムは、更に、(e)NodeBを有し、 前記ユーザ装置が前記(e)NodeBから前記H(e)NBに接続を変更するハンドオーバーを行う際、 前記ユーザ装置が、一定時間間隔ごとに、前記(e)NodeB又は前記H(e)NBから受信する電波についての受信信号レポートを接続している前記(e)NodeB又は前記H(e)NBに送信する過程と、 前記(e)NodeB又は前記H(e)NBが、受信した前記受信信号レポートに基づいて、前記H(e)NBへの接続を変更するハンドオーバー要求情報を前記コア・ネットワークに送信する過程と、 前記コア・ネットワークが、前記ハンドオーバー要求情報に対して前記アクセス制御リストに基づいて接続の認証処理を行い、認証処理の結果に基づいてハンドオーバーを行わせるハンドオーバー指示情報を前記ユーザ装置に送信する過程と、 前記ユーザ装置が、前記ハンドオーバー指示情報に基づいて接続を変更する過程と を有することを特徴とする請求項8に記載のユーザ装置とH(e)NBとの接続方法。
- 10前記移動体通信システムは、更に、(e)NodeBを有し、 前記ユーザ装置が前記(e)NodeBから前記H(e)NBに接続を変更するハンドオーバーを行う際、 前記H(e)NBが、該H(e)NBの前記H(e)NB識別子又は該H(e)NBの非公開加入者グループ名を送信する過程と、 前記ユーザ装置が、前記H(e)NBから受信した前記H(e)NB識別子又は非公開加入者グループ名に基づいて、該H(e)NBに接続を変更する過程と を有することを特徴とする請求項8に記載のユーザ装置とH(e)NBの接続方法。
- 11前記端末接続要求情報は、前記ユーザ装置が記憶するトークンを含み、 前記コア・ネットワークが、記憶する前記アクセス制御リストに基づいて、前記H(e)NBごとに異なる前記トークンを生成し、生成した該トークンを該トークンに対応する前記H(e)NB及び該H(e)NBに接続を許された前記ユーザ装置に送信して記憶させる過程と、 前記H(e)NBが、記憶している前記トークンと、受信した前記端末接続要求情報に含まれる前記トークンとが一致しているか否かにより該端末接続要求情報に対する認証処理を行う過程と を有することを特徴とする請求項9又は請求項10に記載のユーザ装置とH(e)NBとの接続方法。
- 12前記オーナー識別子に対応する前記ユーザ装置に記憶される前記トークンと、それ以外の前記ユーザ装置に記憶される前記トークンとは、異なり、 前記H(e)NBは、前記オーナー識別子に対応する前記ユーザ装置と、それ以外の前記ユーザ装置と、それぞれの認証処理に用いる2つの前記トークンを記憶する ことを特徴とする請求項11に記載のユーザ装置とH(e)NBとの接続方法。
- 13前記端末接続要求情報は、前記ユーザ装置が記憶するトークンを含み、 前記コア・ネットワークが、記憶する前記アクセス制御リストに基づいて、前記ユーザ装置ごとに異なる前記トークンを生成し、生成した該トークンを該トークンに対応する前記ユーザ装置及び前記ユーザ装置が接続を許された前記H(e)NBに送信して記憶させる過程と、 前記H(e)NBは、記憶している前記トークンと、受信した前記端末接続要求情報に含まれる前記トークンとが一致しているか否かにより該端末接続要求情報に対する認証処理を行う過程と を有することを特徴とする請求項9又は請求項10に記載のユーザ装置とH(e)NBとの接続方法。
- 14前記移動体通信システムは、更に、移動局管理装置を備え、 前記移動局管理装置が、前記H(e)NBが送信する情報を受信し、受信した情報を前記コア・ネットワークに送信して中継する過程 を有することを特徴とする請求項2から請求項13のいずれか1項に記載のユーザ装置とH(e)NBとの接続方法。
- 15無線基地局とネットワークを有する通信システムにおいて、ユーザ装置の認証方法であって、 前記無線基地局と前記ネットワークとの間でセキュリティ保護された接続を形成し、 前記無線基地局に接続している前記ユーザ装置と前記ネットワーク間の通信を許可し、 前記無線基地局を介して前記ユーザ装置と前記ネットワークとの間の通信を開始する ことを特徴とするユーザ装置の認証方法。
- 16前記ネットワークは、前記ユーザ装置がオーナーであるかどうかを検証し、 前記ユーザがオーナーである場合、前記無線基地局を介して前記ユーザ装置と前記ネットワークとの間でさらなる通信を許可する ことを特徴とする請求項15に記載のユーザ装置の認証方法。
- 17前記ネットワークは、前記ユーザ装置がオーナーであるかどうかを検証し、 前記ユーザがオーナーである場合、前記ネットワークから前記無線基地局にアクセス制御リストを維持するかどうかを通知する ことを特徴とする請求項15に記載のユーザ装置の認証方法。
- 18前記無線基地局は、H(e)NBである ことを特徴とする請求項15から請求項17のいずれか1項に記載のユーザ装置の認証方法。
- 19前記ネットワークは、コア・ネットワークである ことを特徴とする請求項15から請求項18のいずれか1項に記載のユーザ装置の認証方法。
- 20ユーザ装置とH(e)NBとコア・ネットワークとを有する移動体通信システムにおけるH(e)NBであって、 前記ユーザ装置を識別する加入者識別子を含む接続要求情報をコア・ネットワークに送信する ことを特徴とするH(e)NB。
- 21前記接続要求情報は、予め付与されるH(e)NB識別子を含む ことを特徴とする請求項20に記載のH(e)NB。
- 22前記接続要求情報は、前記コア・ネットワークにより割当てられたIPアドレス情報を含む ことを特徴とする請求項20に記載のH(e)NB。
- 23前記ユーザ装置の前記加入者識別子を含み、該ユーザ装置からの接続の要求を示す端末接続要求情報を該ユーザ装置から受信する基地局通信部と、 前記H(e)NB識別子が記憶されている識別子記憶部と、 前記接続要求情報を生成して前記コア・ネットワークに送信する基地局制御部と を備え、 前記接続要求情報に含まれる前記加入者識別子は、前記ユーザ装置から受信した前記端末接続要求情報に含まれる前記加入者識別子である ことを特徴とする請求項21に記載のH(e)NB。
- 24前記ユーザ装置の前記加入者識別子を含み、該ユーザ装置からの接続の要求を示す端末接続要求情報を該ユーザ装置から受信する基地局通信部と、 前記IPアドレス情報及び予め付与されるH(e)NB識別子が記憶されている識別子記憶部と、 前記接続要求情報を生成して前記コア・ネットワークに送信する基地局制御部と を備え、 前記接続要求情報に含まれる前記加入者識別子は、前記ユーザ装置から受信した前記端末接続要求情報に含まれる前記加入者識別子である ことを特徴とする請求項22に記載のH(e)NB。
- 25ユーザ装置とH(e)NBとコア・ネットワークとを有する移動体通信システムにおけるコア・ネットワークであって、 前記ユーザ装置を識別する加入者識別子と前記H(e)NBに予め付与されるH(e)NB識別子とを含み、前記H(e)NBから受信した接続要求情報に基づいて、予め記憶されているアクセス制御リストを参照して前記ユーザ装置を前記H(e)NBに接続するか否かを判定する ことを特徴とするコア・ネットワーク。
- 26前記アクセス制御リストは、前記H(e)NBの前記H(e)NB識別子と、該H(e)NBに接続を許された前記ユーザ装置の前記加入者識別子とが対応付けられた情報を含む ことを特徴とする請求項25に記載のコア・ネットワーク。
- 27前記アクセス制御リストを記憶するアクセス制御リスト部と、 前記接続要求情報に基づいて、前記アクセス制御リストを参照して前記ユーザ装置を前記H(e)NBに接続するか否かを判定する認証制御部と、 を備え、 前記接続要求情報は、該情報に含まれる前記加入者識別子に対応した前記ユーザ装置が、該情報に含まれる前記H(e)NB識別子に対応する前記H(e)NBへの接続を要求することを示す情報である ことを特徴とする請求項26に記載のコア・ネットワーク。
- 28ユーザ装置とH(e)NBとコア・ネットワークとを有する移動体通信システムであって、 前記ユーザ装置は、 自端末を識別する加入者識別子が記憶されている加入者識別子記憶部と、 前記加入者識別子を含み、前記H(e)NBへの接続を要求する端末接続要求情報を生成して出力する端末制御部と、 前記端末制御部から入力された前記端末接続要求情報を、接続を要求する前記H(e)NBに送信する端末通信部と、 を備え、 前記H(e)NBは、 前記ユーザ装置から前記端末接続要求情報を受信する基地局通信部と、 予め付与されたH(e)NB識別子が記憶されている識別子記憶部と、 前記端末接続要求情報に含まれる前記加入者識別子を含み、前記加入者識別子に対応する前記ユーザ装置からの接続の要求を示す接続要求情報を生成して前記コア・ネットワークに送信する基地局制御部と、 を備え、 前記コア・ネットワークは、 前記H(e)NBに対して接続が許された前記ユーザ装置の前記加入者識別子と、該H(e)NBの前記H(e)NB識別子とが対応付けられた情報が記憶されているアクセス制御リスト部と、 前記H(e)NBから受信した前記接続要求情報に含まれる前記加入者識別子に対応するユーザ装置を、該接続要求情報に含まれる前記H(e)NB識別子に対応する前記H(e)NBに接続するか否かを前記アクセス制御リスト部に記憶されている情報に基づき判定する認証制御部と、 を備える ことを特徴とする移動体通信システム。
Independent claims28
131 paragraphs, as filed
The present invention relates to a connection method of a user device to a communication network via a radio base station device, particularly a connection method that maintains security.
In recent years, in wired data communication, technological development has been remarkable, networks based on IP (Internet Protocol) technology have become widespread, and communication speed is high and inexpensive communication is provided. However, in wireless communication using user equipment (UE; User Equipment) in mobile communication, for example, mobile phones and personal digital assistants, communication by IP technology is not as widespread as wired data communication. ..
By the way, in mobile communication, by installing a small wireless base station device that covers a range of several meters to several tens of meters (Femto Cell) in a home or SOHO (Small Office Home Office), etc. There is a technology that provides high-speed and inexpensive communication to user equipment. Here, the small radio base station device is a radio base station device that provides mobile communication to a user device, and is one of the radio base station devices having a small radio wave output and a communicable range of several meters to several tens of meters. A small wireless base station device is a form of technology that narrows the communicable range and reduces the number of connected user devices to allocate a wide band to the connected user devices to provide high-speed and inexpensive communication. It is a device to have. In addition, the small wireless base station device communicates with the core network (CN: Core Network), which is a wired communication network, via a fixed telephone line or the Internet, for example, by DSL (Digital Subscriber Line). Connected by wire as provided by.
The use of femtocells using such a small wireless base station device is advantageous not only for subscribers but also for operators that provide mobile communications. For example, until now, in order to make a wide range a communicable range, it has been necessary to install a large number of wireless base station devices that can accommodate many user devices. Moreover, since such a wireless base station is expensive, the financial burden on the operator who installs it is large. On the other hand, since the small wireless base station device is inexpensive, it can be sold or rented to the subscriber, and the burden on the operator can be reduced. Further, since the subscriber installs the small radio base station device, the small radio base station device can be accurately installed in a place where there is a demand for mobile communication.
In addition, such a small radio base station device is 3GPP (3).<sup>rd</sup> In the Generation Partnership Project (CSG), Home Node B (H NB) and Home E Node B (H (e)) provide communication to the Closed Subscriber Group (CSG). ) NB; Home evolved Node B) has been proposed (Non-Patent Document 1).<nplcit num="1"><text>3GPP TS 22.011 V8.3.0 (2008-03) Technical Specification 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Service accessibility (Release 8)</text></nplcit>
<p> However, when the small wireless base station equipment installed by the subscriber is connected to the core network via a fixed telephone line or the Internet, the mobile communication provider manages the small wireless base station equipment. Therefore, an unauthorized connection of a small wireless base station device, an incorrect connection of a small wireless base station device, an illegal connection of a user device to a small wireless base station device, an incorrect connection of a user device, etc. are performed. There is a possibility that there is a problem.</p><p> Therefore, an object of the present invention is a means for performing authentication processing when connecting a small wireless base station device and when connecting a user device to a wired communication network in order to prevent unauthorized use and misuse, and a small size that secures security. The purpose is to provide a means for setting and managing a radio base station device.</p>
<p> In order to solve the above problems, the present invention presents a method of wirelessly connecting the user device and the H (e) NB in a mobile communication system having a user device, an H (e) NB, and a core network. Based on the process in which the H (e) NB transmits the connection request information including the subscriber identifier that identifies the user device to the core network, and the connection request information received by the core network. The user device and H (e) are characterized by having a process of determining whether or not to connect the user device to the H (e) NB by referring to an access control list stored in advance. This is the connection method with NB.</p><p> Further, the present invention is a method for authenticating a user device in a communication system having a radio base station and a network, in which a secure connection is formed between the radio base station and the network, and the radio base station is described. A method for authenticating a user device, characterized in that communication between the user device and the network connected to the user device is permitted, and communication between the user device and the network is started via the radio base station. is there.</p><p> Further, the present invention is H (e) NB in a mobile communication system having a user device, H (e) NB, and a core network, and provides connection request information including a subscriber identifier that identifies the user device. It is an H (e) NB characterized by transmitting to the core network.</p><p> Further, the present invention is a core network in a mobile communication system having a user device, an H (e) NB, and a core network, and the subscriber identifier that identifies the user device and the H (e) NB are used. Based on the connection request information received from the H (e) NB, including the H (e) NB identifier given in advance, the user device is referred to the H (e) by referring to the access control list stored in advance. ) A core network characterized by determining whether or not to connect to an NB.</p><p> Further, the present invention is a mobile communication system having a user device, an H (e) NB, and a core network, and the user device is a subscriber identifier in which a subscriber identifier that identifies a local terminal is stored. A storage unit, a terminal control unit that includes the subscriber identifier and generates and outputs terminal connection request information requesting connection to the H (e) NB, and the terminal connection request input from the terminal control unit. The H (e) NB includes a terminal communication unit that transmits information to the H (e) NB requesting a connection, and the H (e) NB has a base station communication unit that receives the terminal connection request information from the user device in advance. A connection request from the user device including the identifier storage unit in which the assigned H (e) NB identifier is stored and the subscriber identifier included in the terminal connection request information, and corresponding to the subscriber identifier. The core network includes the base station control unit that generates the connection request information shown and transmits the connection request information to the core network, and the core network is the subscription of the user apparatus that is allowed to connect to the H (e) NB. The access control list unit that stores the information associated with the person identifier and the H (e) NB identifier of the H (e) NB, and the connection request information received from the H (e) NB Whether or not to connect the user device corresponding to the included subscriber identifier to the H (e) NB corresponding to the H (e) NB identifier included in the connection request information is stored in the access control list unit. It is a mobile communication system including an authentication control unit that determines based on the information provided.</p>
<p> According to the present invention, in mobile communication via a wireless base station device, unauthorized use and misuse can be prevented by using an access control list in which user devices permitted to be connected are registered for each wireless base station device. It is possible to ensure the security for this.</p>
The outline of the present invention is shown. FIG. 1 is a diagram showing an outline of the present invention. Secure Closed Subscriber Group Creation About registration: When a user (subscriber) registers for a connection to H (e) NB, the operator who provides mobile communication is 1. H (e) NB identifier and 2. Subscriber's. Record the identifier.
Solution as a message sequence, 1. The H (e) NB authenticates the mobile communication provider (operator) to the Core Network when power is supplied and connected to the network. 2. A protected connection is established between the core network and H (e) N. 3. The core network records that the connection is the first connection by H (e) NB. 4. Users connecting to H (e) NB are allowed to communicate with the core network (Access Control List; If ACL) is on the core network and the access control list is on H (e) NB, the owner has not yet been set). This communication includes the identifier of the H (e) NB added by the H (e) NB. The core network checks to see if the user is the owner. 5. If the user is the owner The core network notifies the H (e) NB that access control list maintenance may be performed, or the core network is after the UE (User Equipment) H (e) NB. Allow communication. 6. The UE may initiate communication and add members to the access control list. To add a private subscriber group to the access control list, the owner either launches the software and adds the private subscriber group member, or the owner opens a web page and adds the private subscriber group member. .. 7. Upon receiving the access control list, the core network adds the received list to the access control list. If the access control list is provided in H (e) NB, the access control list is also recorded in H (e) NB. 8. When a new device is connected to H (e) NB, If an access control list is provided in H (e) NB, H (e) NB confirms it. If the access control list is provided in the core network, the core network confirms it. Allow subsequent access only if the UE is in the access control list.
The details are shown below. A means for ensuring security for preventing unauthorized use and misuse when connecting a user device to a wireless base station device according to an embodiment of the present invention will be described with reference to the drawings. In this embodiment, an example in which Home Evolved Node B (H (e) NB; Home Evolved Node B) (hereinafter referred to as H (e) NB) is applied to the radio base station apparatus is used. explain.
(First Embodiment) FIG. 2 is a schematic block diagram showing the mobile communication system 1 according to the first embodiment. As shown in the figure, the mobile communication system 1 includes a core network (CN) 10 and a home evolved node B (H (e) NB; Home Evolved Node B) 20 (hereinafter, H (e)). NB20), User Equipment (UE; User Equipment) 30-1, 30-2, ..., 30-n, Radio Base Station Equipment (NodeB) 40 (hereinafter referred to as NodeB40), Radio Network Control Device (RNC) It has a Radio Network Controller) 50 and a radio base station device (e-node B ((e) Node B; evolved Node B)) 70 (hereinafter referred to as (e) Node B70). The user devices 30-1, ..., 30-n have the same configuration, and hereinafter, any or all of the user devices 30-1, ..., and the user devices 30-n are represented. When shown as, it is referred to as a user device 30. In addition, H (e) NB20 is managed by the subscriber purchasing or renting from a business operator that provides mobile communication.
The core network 10 is a core part of a mobile communication system that provides mobile communication. Further, the core network 10 connects based on the information on whether or not the user device 30 is allowed to connect to the H (e) NB 20 in response to the request to connect to the H (e) NB 20 of the user device 30. Performs an authentication process that determines whether or not to approve. The H (e) NB20 communicates with the core network 10 via a telephone public line, the Internet, etc., relays transmission / reception data to / from the core network 10 to the user device 30, and requests a connection of the user device 30. Performs authentication processing for. By connecting to the H (e) NB 20, the user device 30 makes a voice call or data communication with another user device 30 or the like via the H (e) NB 20 and the core network 10. The user device 30 is, for example, a terminal such as a mobile phone or a mobile information terminal. The NodeB40 is connected to the core network 10 by a dedicated line via the wireless network control device 50, and relays transmission / reception data with the core network 10 and requests a handover to the user device 30. (e) NodeB70 is connected to the core network 10 and relays transmission / reception data to / from the core network 10 and makes a handover request to the user device 30.
FIG. 3 is a schematic block diagram showing the configurations of the core network 10, the H (e) NB20, and the user apparatus 30. Hereinafter, each functional block will be described with reference to FIGS. 3, 4 and 5.
The core network 10 includes an authentication control unit (AuC) 101, an authentication information storage unit (AuC DB) 102, an access control list storage unit (ACL DB) 103, and a security gateway (AuC DB). It is equipped with a SeGW (Security Gateway) 104, a communication network 105, and a subscriber identifier storage (Subscriber DB) 106. In addition, the core network 10 is managed and operated by a business operator that provides mobile communication. The authentication control unit 101, the authentication information storage unit 102, the access control list storage unit 103, and the subscriber identifier storage unit 106 may be configured by one server device. Further, the authentication control unit 101, the authentication information storage unit 102, the access control list storage unit 103, and the subscriber identifier storage unit 106 may be configured by different server devices connected via the communication network 105.
In the core network 10, the authentication control unit 101 reads out the information stored in the authentication information storage unit 102 and the access control list storage unit 103 in response to a request such as a connection from the H (e) NB 20 and the user device 30. , Allow the user device 30 to connect to the H (e) NB 20 based on the information. Further, the authentication control unit 101 updates the authentication information stored in the authentication information storage unit 102 and the access control list stored in the access control list storage unit 103.
Authentication information is stored in the authentication information storage unit 102. Here, the authentication information is managed by a relational database. FIG. 4 is a schematic diagram showing a data structure and a data example included in the authentication information. As shown in the figure, the authentication information is, for example, two-dimensional tabular data consisting of rows and columns, and manages H (e) NB identifier (H (e) NB ID) and H (e) NB 20. Owner identifier (Owner ID) that identifies the owner (administrator), unconnected information (H (e) NB's first It has a column for each item of attach). Each row of credentials exists for each H (e) NB20. The H (e) NB identifier is an identifier that uniquely identifies H (e) NB20. Further, the H (e) NB identifier includes information that can be distinguished from NodeB40 and (e) NodeB70 that provide mobile communication to the user device 30. For example, when the H (e) NB identifier is composed of a plurality of bit strings, the first few bits can be distinguished by including a unique bit string different from the identifiers of NodeB40 and (e) NodeB70. It is possible to distinguish between (e) NB20, NodeB40, and (e) NodeB70. The owner identifier is a subscriber identifier that uniquely identifies the subscriber who manages the connection of H (e) NB20. The unconnected information is information indicating the history of connection of H (e) NB20 to the core network 10. If it has never been connected, it is "unconnected" (No), and if it is connected, it is "already connected". "(No) is memorized. It is information indicating whether or not it has been done. In addition, the authentication information includes in advance the H (e) NB identifiers of all the H (e) NB 20s that are allowed to connect to the core network 10. Further, in the initial state, all the owner identifiers are in the unregistered state, and the unconnected information is in the "not connected" (Yes) state.
The access control list storage unit 103 stores the access control list, and the access control list is managed by a relational database. FIG. 5 is a schematic diagram showing a data structure included in the access control list and a data example. As shown, an access control list is, for example, two-dimensional tabular data consisting of rows and columns, a closed subscriber group name (CSG Name; Closed Subscriber Group Name), and an H (e) NB identifier (. It has columns for each item of H (e) NB's ID), owner identifier, and member list. Each row in the access control list exists for each private subscriber group.
The private subscriber group is a group of subscribers who are authorized to connect to the core network 10 via the defined H (e) NB20. The "private subscriber group name" is a name that uniquely identifies the private subscriber group. The H (e) NB identifier is the H (e) NB identifier of the H (e) NB 20 owned by the private subscriber group. The "owner identifier" is a subscriber identifier of a subscriber who has the authority to manage a private subscriber group, for example, the authority to add and delete subscribers. The "member list" is a list of subscriber identifiers that can connect to the H (e) NB20 corresponding to the private subscriber group. If the private subscriber group has only one H (e) NB20, the H (e) NB identifier may be used for the private subscriber group name.
The security gateway 104 is provided between the communication network 105 and the H (e) NB20, and communicates with the H (e) NB20. Further, when the security gateway 104 communicates with the H (e) NB20, the security gateway 104 individually establishes a communication line connection with the H (e) NB20 using a generally known secure channel to provide communication information. Prevent leakage and eavesdropping. For example, the security gateway 104 can be used for encryption of communication information by IPsec (Security Architecture for Internet Protocol), PKI (Public Key Infrastructure), H (e) NB20 and core network 10. Use tunneling technology to establish a virtual direct line between the two.
The communication network 105 connects a plurality of security gateways 104 and provides a communication line. The subscriber identifier storage unit 106 stores the subscriber identifier. The user device 30 having the subscriber identifier stored in the subscriber identifier storage unit 106 can be connected to the core network 10.
The H (e) NB 20 includes an identifier storage unit (Authentication module) 201, an access list storage unit 202, a base station control unit 203, a base station communication unit 204, and an antenna 205. In addition, the H (e) NB20 is connected to the core network 10 via a public line, the Internet, etc., and communicates between the user device 30 owned by the subscribers of the private subscriber group and the core network 10. Has the function to provide.
In the H (e) NB 20, the identifier storage unit 201 stores the H (e) NB identifier that uniquely identifies the H (e) NB 20. The identifier storage unit 201 may be fixed inside the H (e) NB20, or may be a removable IC card or the like. Further, the H (e) NB identifier may be stored in the identifier storage unit 201 in advance, and when the H (e) NB 20 is connected to the core network 10, mobile communication is provided by the operation of the subscriber. The H (e) NB identifier may be stored in the identifier storage unit 201 by downloading the H (e) NB identifier from the operator via the core network 10. Further, the H (e) NB identifier is stored by writing the H (e) NB identifier in the identifier storage unit 201 by the operation of the operator when the operator providing the mobile communication sells or rents the H (e) NB20. You may let me.
In the access list storage unit 202, the private subscriber group name and the owner identifier stored in association with the H (e) NB identifier of the own device among the access control lists stored in the access control list storage unit 103. And a copy of the member list is stored. Further, the access list storage unit 202 stores a token used for the authentication process for the connection between the H (e) NB 20 and the user device 30.
The base station control unit 203 communicates with the core network 10 and processes a connection request from the user device 30 and the like.
The base station communication unit 204 has a generally known function of performing wireless communication via the antenna 205, or UTRAN (UMTS Terrestrial Radio Access Network; UMTS terrestrial radio access network) or E-UTRN (Evolved UTRAN; development). It has a function to perform wireless communication compatible with the standard of the type UMTS terrestrial radio access network), and performs wireless communication with the user device 30.
The user device 30 includes a subscriber identifier storage unit (USIM; Universal Subscriber Identity Module) 301, a terminal communication unit 302, a terminal control unit 303, a terminal input / output unit 304, and an antenna 305.
In the user device 30, the subscriber identifier storage unit 301 contains a subscriber identifier that uniquely identifies the user device 30, and information used for the authentication process, for example, a private subscriber group name or H (e) that is allowed to be connected. ) The H (e) NB identifier of NB20 is stored. Further, the subscriber identifier storage unit 301 stores a token used for the authentication process for the connection between the H (e) NB 20 and the user device 30. The subscriber identifier storage unit 301 may be fixed to the user device 30, or may be a removable IC card or the like.
The terminal communication unit 302 has a generally known function of performing wireless communication via the antenna 305, or a function of performing wireless communication compatible with the UTRAN or E-UTRN standard, and has H (e). Wireless communication with NB20.
The terminal control unit 303 processes the connection to the H (e) NB20 and sets the private subscriber group.
When the terminal input / output unit 304 receives the input operated by the subscriber, the terminal input / output unit 304 outputs the input to the terminal control unit 303. Further, the terminal input / output unit 304 outputs the information input from the terminal control unit 303 to make the subscriber recognize it. For example, the terminal input / output unit 304 has a display screen for displaying text and a plurality of input buttons for allowing a subscriber to input.
FIG. 6 is a sequence diagram of the process of registering the H (e) NB20 to the core network 10, the process of initial connection of the H (e) NB20, and the process of creating a private subscriber group. Hereinafter, the processing of the mobile communication system 1 will be described with reference to the drawings.
(H (e) NB20 registration process) First, when the H (e) NB 20 is connected to the core network 10 via a public line, the Internet, or the like, the base station control unit 203 reads the H (e) NB identifier from the identifier storage unit 201 and reads it out. Generate an initial connection request including the H (e) NB identifier and the request for secure channel setting (step S101).
The base station control unit 203 transmits the generated initial connection request to the security gateway 104 of the core network 10 (step S102).
When the security gateway 104 receives the initial connection request from the H (e) NB 20, the security gateway 104 outputs the received initial connection request to the authentication control unit 101 via the communication network 105. The authentication control unit 101 detects that the H (e) NB identifier included in the initial connection request is stored in the authentication information storage unit 102, and the unconnected information associated with the H (e) NB identifier. Detects if is not connected (Yes). Further, when the authentication control unit 101 reads that the H (e) NB identifier is stored in the authentication information storage unit 102 and the unconnected information is not connected from the authentication information storage unit 102, the H (e) Write the existing connection (No) to the unconnected information associated with the NB identifier, and update the authentication information. In addition, when the input H (e) NB identifier is not stored in the authentication information storage unit 102, or the unconnected information associated with the input H (e) NB identifier has already been stored in the authentication control unit 101. In the case of connection (No), the initial connection request is regarded as an invalid request and the process is terminated.
Subsequently, the authentication control unit 101 generates key information used for the secure channel, and outputs the initial connection instruction information including the secure channel setting instruction, the H (e) NB identifier, and the generated key information to the security gateway 104. When the security gateway 104 receives the initial connection instruction information from the authentication control unit 101, it sets a secure channel with the H (e) NB 20 indicated by the H (e) NB identifier included in the initial connection instruction information. After that, the security gateway 104 communicates with the H (e) NB20 via the secure channel set as the H (e) NB20 by using the key information included in the initial connection instruction information (step S103).
Next, the security gateway 104 transmits information indicating the completion of processing of the initial connection request to the base station control unit 203 of H (e) NB20 (step S104).
When the base station control unit 203 receives the information indicating the completion of processing of the initial connection request from the security gateway 104, the base station control unit 203 sets a secure channel with the security gateway 104 and generates key information used for communication via the secure channel. (Step S105). After that, the base station control unit 203 uses the generated key information to communicate with the core network 10 via the secure channel set up with the security gateway 104.
As described above, the H (e) NB20 is registered in the core network 10 and is connected by setting the secure channel. The authentication information storage unit 102 stores the identifier of H (e) NB20 that is allowed to be connected in advance. Further, the authentication control unit 101 determines whether or not to approve the connection request based on whether or not the H (e) NB identifier of the H (e) NB 20 requesting the connection is stored in the authentication information storage unit 102. Perform the specified authentication process. As a result, it is possible to prevent unauthorized connection and incorrect connection of the H (e) NB20 to the core network 10. When the connection to the core network 10 is completed, the H (e) NB 20 is in a state where only the information requiring the authentication process from the user device 30 can be relayed to the core network 10.
(Processing of initial connection of H (e) NB20) After the registration of H (e) NB20 is completed, the user device 30 inputs a request to connect to H (e) NB20 to the terminal input / output unit 304 by the operation of the subscriber in order to communicate with the core network 10. To. The terminal input / output unit 304 outputs the input request to the terminal control unit 303. The terminal control unit 303 generates terminal connection request information requesting connection to H (e) NB20 (step S111). Here, the terminal connection request information is information including a subscriber identifier read from the subscriber identifier storage unit 301 by the terminal control unit 303 and a request for connecting to the core network 10.
The terminal control unit 303 transmits the generated terminal connection request information to the H (e) NB 20 through the terminal communication unit 302 (step S112).
When the base station communication unit 204 receives the terminal connection request information from the user device 30, it outputs the terminal connection request information to the base station control unit 203. When the terminal connection request information is input, the base station control unit 203 generates the connection request information indicating the connection request from the user device 30 (step S113). Here, the connection request information is information including the received terminal connection request information and the H (e) NB identifier read from the identifier storage unit 201. That is, the connection request information is information including a request for connecting the user device 30 to the H (e) NB 20, a subscriber identifier, and an H (e) NB identifier.
The base station control unit 203 transmits the generated connection request information to the core network 10 (step S114).
When the security gateway 104 receives the connection request information from the H (e) NB 20, the security gateway 104 outputs the received connection request information to the authentication control unit 101 via the communication network 105. When the authentication control unit 101 receives the connection request information from the security gateway 104, whether or not the authentication control unit 101 approves the connection request based on whether or not the subscriber identifier included in the connection request information is stored in the subscriber identifier storage unit 106. Perform the authentication process to determine. Further, the authentication control unit 101 detects that the subscriber identifier is stored in the subscriber identifier storage unit 106, and further, the owner identifier corresponding to the H (e) NB identifier included in the connection request information is not registered. When it is detected that the state is, the subscriber identifier is written and stored in the authentication information storage unit 102 as the owner identifier. In addition, the authentication control unit 101 generates owner registration instruction information (step S115).
Here, the owner registration instruction information includes information indicating that the connection corresponding to the connection request information is permitted, the subscriber identifier of the user device 30 that requested the connection, and H (H (e) NB20 of the connection requested H (e) NB20. e) Information including the NB identifier. If the subscriber identifier included in the connection request information is not stored in the subscriber identifier storage unit 106, the initial connection process of the H (e) NB 20 is terminated as an invalid connection request.
The authentication control unit 101 transmits the generated owner registration instruction information to the base station control unit 203 of the H (e) NB 20 via the security gateway 104 (step S116).
When the base station control unit 203 receives the owner registration instruction information from the core network 10, the base station control unit 203 writes and stores the subscriber identifier included in the owner registration instruction information as the owner identifier in the access list storage unit 202 (step S117).
Further, the base station control unit 203 transmits the owner registration instruction information to the user device 30 corresponding to the subscriber identifier included in the received owner registration instruction information via the base station communication unit 204 (step S118).
When the terminal communication unit 302 receives the owner registration instruction information from the H (e) NB20, the terminal input / output unit 304 tells the terminal input / output unit 304 the owner of the H (e) NB20 corresponding to the H (e) NB identifier included in the owner registration instruction information. Notify the subscriber by outputting the fact that it has been registered in. In addition, the terminal communication unit 302 generates information prompting the setting of a private subscriber group, which is a group of user devices 30 that can be connected to the owner H (e) NB 20, and causes the terminal input / output unit 304 to set. Output and prompt the subscriber to input. Here, the setting of the private subscriber group is the setting of the private subscriber group name and the subscriber identifier of the subscriber who is a member of the private subscriber group, that is, the member list.
The terminal control unit 303 generates CSG setting request information when the private subscriber group name and the member list are input via the terminal input / output unit 304 by the operation of the subscriber (step S121). Here, the CSG setting request information includes the private subscriber group name, the H (e) NB identifier of the H (e) NB20 to be set, the subscriber identifier stored in the subscriber identifier storage unit 301, and the member list. , And information including a request for CSG settings.
Further, the terminal control unit 303 transmits the generated CSG setting request information to the H (e) NB 20 via the terminal communication unit 302 (step S122).
When the base station communication unit 204 receives the CSG setting request information from the user device 30, the base station communication unit 204 outputs the received CSG setting request information to the base station control unit 203. When the CSG setting request information is input, the base station control unit 203 accesses the private subscriber group name, H (e) NB identifier, owner identifier, and member list included in the input CSG setting request information. It is written to the list storage unit 202 and stored (step S123).
Further, the base station control unit 203 transmits the input CSG setting request information to the security gateway 104 of the core network 10 (step S124).
When the security gateway 104 receives the CSG setting request information, it outputs the received CSG setting request information to the authentication control unit 101. When the CSG setting request information is input, the authentication control unit 101 associates the private subscriber group name, H (e) NB identifier, owner identifier, and member list included in the input CSG setting request information with each other. , Write to the access control list storage unit 103 and store it (step S125).
By the above process, the owner of H (e) NB20 is set. In addition, the private subscriber group provided by H (e) NB20 is set. In this way, the owner of H (e) NB20 is set, and the subscriber identifier of the owner who can set the private subscriber group is registered. By setting the private subscriber group only for this owner, only the user device 30 to which the owner allows connection is registered in the access control list. Although it was transmitted from the user device 30 to the core network 10 via H (e) NB20, an interface such as a web page is prepared via the Internet or the like, and the subscriber operates to connect to the Internet or the like. The computer may be made to send the CSG setting request information to the core network 10.
(Connection processing of user device 30) FIG. 7 is a sequence diagram of a process in which the user device 30 connects to the core network 10 via the H (e) NB 20.
First, in the user device 30, the terminal control unit 303 generates terminal connection request information when a connection request to the core network 10 is input via the terminal input / output unit 304 by the operation of the subscriber (step). S201).
Subsequently, the user apparatus 30 transmits the generated terminal connection request information to the H (e) NB 20 (step S202).
When the base station control unit 203 receives the terminal connection request information from the user device 30 via the base station communication unit 204, the base station control unit 203 generates the connection request information (step S203).
The base station control unit 203 transmits the generated connection request information to the core network 10 (step S204).
The authentication control unit 101 receives the connection request information from the H (e) NB 20 via the security gateway 104. Further, the authentication control unit 101 approves the connection request based on whether or not the H (e) NB identifier and the subscriber identifier included in the connection request information are stored in association with the access control list storage unit 103. Performs authentication processing to determine whether or not. The authentication process reads the member list corresponding to the H (e) NB identifier included in the connection request information, and detects whether or not the read member list includes the subscriber identifier included in the connection request information. Will be done. When the authentication control unit 101 detects that the H (e) NB identifier and the subscriber identifier included in the connection request information are stored in association with each other, the authentication control unit 101 permits the connection request. Further, when the authentication control unit 101 detects that the H (e) NB identifier and the subscriber identifier included in the connection request information are not stored in association with each other, the authentication control unit 101 rejects the connection request. In addition, the authentication control unit 101 generates connection response information for notifying the result of the connection request (step S205).
Further, the authentication control unit 101 transmits the generated connection response information to the H (e) NB 20 via the security gateway 104 (step S206).
When the base station control unit 203 receives the connection response information from the core network 10, it transmits the received connection response information to the user apparatus 30 indicated by the subscriber identifier included in the received connection response information, and the user apparatus. Notify the result of 30 terminal connection request information (step S207).
By the above-mentioned process, the core network 10 performs an authentication process for determining whether or not to accept the terminal connection request from the user device 30 to the H (e) NB 20. When the terminal connection request is approved, the H (e) NB20 relays the transmitted / received data between the user device 30 and the core network 10, and the user device 30 relays the transmission / reception data through the H (e) NB20 to the core network. Connect to 10 and communicate. Only the user device 30 registered in the access control list is allowed to connect to the H (e) NB20 to prevent unauthorized access to the H (e) NB20 and incorrect access to the H (e) NB20. Is possible.
The H (e) NB 20 may perform the authentication process using the member list stored in the access list storage unit 202 without transmitting the terminal connection request information to the core network 10. In that case, the base station control unit 203 performs the authentication process based on whether or not the subscriber identifier included in the received terminal connection request information is included in the member list stored in the access list storage unit 202. It will be. At this time, the base station control unit 203 permits the connection request if the subscriber identifier included in the received terminal connection request information is included in the member list, and rejects the connection request if it is not included.
Next, connection processing of different user devices 30 will be described. Here, the security gateway 104 sets a secure channel with H (e) NB20 using IPsec. The core network 10 includes a security association database (not shown). Security association information is stored in advance in the security association storage unit. Here, the security association information includes the IP address information indicating the IP (Internet Protocol) address assigned to the H (e) NB30 associated with the H (e) NB identifier, and the encryption algorithm used in the secure channel. Information including the key information used in the secure channel. The identifier storage unit 201 further stores the IP address information assigned by the security gateway 104 when the secure channel is set.
FIG. 8 is a sequence diagram of a process of connecting the user device 30 to the core network 10 via the H (e) NB 20. First, in the user device 30, the communication control unit 303 generates terminal connection request information when a connection request to the core network 10 is input via the terminal input / output unit 304 by the operation of the subscriber (step). S251). Subsequently, the user apparatus 30 transmits the generated terminal connection request information to the H (e) NB 20 (step S252).
When the base station control unit 203 receives the terminal connection request information from the user device 30 via the base station communication unit 204, the base station control unit 203 generates the connection request information (step S253). Here, the connection request information includes the received terminal connection request information and the IP address information stored in the identifier storage unit 201. The base station control unit 203 transmits the generated connection request information to the core network 10 (step S254). When the security gateway 104 receives the connection request information from the H (e) NB 20, the security gateway 104 reads the H (e) NB identifier corresponding to the key information of the secure channel from the security association storage unit. The security gateway 104 outputs the received connection request information and the read H (e) NB identifier to the authentication control unit 101 (step S255).
The authentication control unit 101 stores whether or not the subscriber identifier included in the connection request information received from the security gateway 104 and the received H (e) NB identifier are stored in association with the access control list storage unit 103. The authentication process that determines whether or not to accept the connection request is performed based on the above. When the authentication control unit 101 detects that the received H (e) NB identifier and the subscriber identifier are associated and stored, the connection request is permitted. Further, when the authentication control unit 101 detects that the received H (e) NB identifier and the subscriber identifier are not stored in association with each other, the authentication control unit 101 rejects the connection request. In addition, the authentication control unit 101 generates connection response information for notifying the result of the connection request (step S256). Further, the authentication control unit 101 transmits the generated connection response information to the H (e) NB 20 via the security gateway 104 (step S257). When the base station control unit 203 receives the connection response information from the core network 10, it transmits the received connection response information to the user apparatus 30 indicated by the subscriber identifier included in the received connection response information, and the user apparatus. Notify the result of 30 terminal connection request information (step S258).
By the above-mentioned process, the core network 10 performs an authentication process for determining whether or not to accept the terminal connection request from the user device 30 to the H (e) NB 20. When the terminal connection request is approved, the H (e) NB20 relays the transmitted / received data between the user device 30 and the core network 10, and the user device 30 relays the transmission / reception data through the H (e) NB20 to the core network. Connect to 10 and communicate. Only the user device 30 registered in the access control list is allowed to connect to the H (e) NB20 to prevent unauthorized access to the H (e) NB20 and incorrect access to the H (e) NB20. Is possible. Further, since the H (e) NB identifier is not transmitted / received between the H (e) NB 20 and the core network 10, it is possible to prevent leakage or eavesdropping of the H (e) NB identifier.
In step S255, the security gateway 104 may read the H (e) NB identifier corresponding to the key information of the secure channel from the security association storage unit only when the received communication packet is the connection request information. Good.
(Member list change process) FIG. 9 is a sequence diagram of the process of adding the subscriber identifier to the member list of the private subscriber group. The user device 30 owned by the owner subscriber of the private subscriber group is designated as the owner user device (Owner UE) 30-O, and the user device 30 owned by the subscriber newly added to the member list is referred to as the member user device (Member UE). ) 30-M will be explained.
First, in the owner-user device 30-O, the terminal control unit 303 controls the subscriber identifier of the newly added subscriber and the private subscription to which the subscriber is added via the terminal input / output unit 304 by the operation of the owner subscriber. Person group name and H (e) NB identifier are entered. In addition, the terminal control unit 303 generates member list change request information including the input subscriber identifier, private subscriber group name, and H (e) NB identifier (step S301).
Next, in the owner-user apparatus 30-O, the terminal control unit 303 transfers the generated member list change request information and the subscriber identifier read from the subscriber identifier storage unit 301 via the terminal communication unit 302 to H ( e) Send to NB20 (step S302).
The base station control unit 203 receives the member list change request information and the subscriber identifier from the owner-user device 30-O via the base station communication unit 204. Further, the base station control unit 203 transmits the received member list change request information and the subscriber identifier to the core network 10 (step S303).
When the authentication control unit 101 receives the member list change request information via the security gateway 104, the authentication control unit 101 generates member addition confirmation information (step S304). Here, the member addition confirmation information includes a confirmation message prompting an answer as to whether or not to join the private subscriber group corresponding to the private subscriber group name included in the received member list change request, and the subscription of the target to be added. Information including a person identifier, a private subscriber group name of the private subscriber group, and an H (e) NB identifier.
The authentication control unit 101 transmits the generated member addition confirmation information to H (e) NB20 (step S305).
When the base station control unit 203 receives the member addition confirmation information from the core network 10, the base station control unit 203 transmits the received member addition confirmation information to the member user apparatus 30-M having the subscriber identifier included in the received member addition confirmation information. (Step S306).
In the member user apparatus 30-M, when the terminal control unit 303 receives the member addition confirmation information via the terminal communication unit 302, the terminal control unit 303 outputs a confirmation message included in the received member addition confirmation information to the terminal input / output unit 304. .. The terminal input / output unit 304 outputs the input confirmation message and answers to the subscriber whether or not to join the private subscriber group, that is, the subscriber identifier of the subscriber is a member of the private subscriber group. Prompt an answer, whether or not you agree to be remembered in the list. In the member user apparatus 30-M, the terminal control unit 303 inputs the response information as to whether or not to join the private subscriber group via the terminal input / output unit 304 by the operation of the subscriber. When the response information is input, the terminal communication unit 302 generates the member addition response information (step S307). Here, the member additional response information includes the subscriber identifier stored in the subscriber identifier storage unit 301, the response information as to whether or not to join the private subscriber group, and the private member group. Information including the subscriber group name and the H (e) NB identifier. When the response information is "participation", the terminal control unit 303 writes and stores the private subscriber group name and the H (e) NB identifier included in the member addition confirmation information in the subscriber identifier storage unit 301. ..
The base station control unit 203 receives the member additional response information from the member user apparatus 30-M via the base station communication unit 204. When the response information included in the received member addition response information is "participation", the base station control unit 203 joins the member list stored in the access list storage unit 202 in the received member addition response information. Write and store the person identifier (step S309). If the response information included in the received member addition response information is "non-participation", the member list change process is terminated.
Further, the base station control unit 203 transmits the received member additional response information to the core network 10 (step S310).
The authentication control unit 101 receives the member addition response information from the H (e) NB 20 via the security gateway 104. When the response information included in the received member addition response information is "participation", the authentication control unit 101 writes the subscriber identifier to be added to the access control list storage unit 103, and corresponds to the member addition response information. Add to the member list of private subscriber group names and H (e) NB identifiers. In addition, the authentication control unit 101 generates member addition completion information (step S311). Here, the member addition completion information includes information indicating that the change process of the member list of the private subscriber group is completed, the response information from the member user device 30-M, and the owner of the private subscriber group to be changed. Information including a subscriber identifier.
The authentication control unit 101 transmits the generated member addition completion information to the H (e) NB 20 via the security gateway 104 (step S312).
When the base station control unit 203 receives the member addition completion information from the core network 10, it transmits the received member addition completion information to the user device 30 indicated by the subscriber identifier included in the received member addition completion information (the received member addition completion information). Step S313).
When the terminal control unit 303 receives the member addition completion information from the H (e) NB20 in the owner-user device 30-O, the terminal control unit 303 outputs the response information included in the received member addition completion information to the terminal input / output unit 304. The terminal input / output unit 304 outputs the response information input from the terminal control unit 303, and notifies the subscriber of the result of the member list change process (step S314).
By the above process, the user apparatus 30 adds a new subscriber to the member list stored in the core network 10 and the H (e) NB 20 by the operation of the owner's subscriber. Moreover, although the additional process has been described, the same applies to the process of deleting a subscriber from the member list. Only the owner can change the member list of the private subscriber group, and the user device 30 of the owner receives the result of the change to change the member list of the private subscriber group unintentionally by the owner. This can be prevented, and it is possible to prevent an unauthorized connection of the user device 30 to the H (e) NB20 and an incorrect connection of the user device 30 to the H (e) NB20. If the H (e) NB 20 does not have the access list storage unit 202, the operation of step S309 is not performed.
(Handover processing) FIG. 10 is a sequence diagram showing a handover process in which the connection of the user device 30 is changed from (e) Node70 to H (e) NB20. It is assumed that the user device 30 is connected to (e) NodeB70 for communication, but also receives radio waves from H (e) NB20.
In a state where the user device 30 is connected to (e) Node B70 and is communicating, the terminal communication unit 302 creates a received signal report showing the state of the radio waves received at regular time intervals (step S401). Here, the received signal report contains information indicating the communication status such as the radio wave strength and signal error rate of each received radio wave, the identifier of each radio base station transmitting the radio wave, and the private subscriber group. Information including the name and the subscriber identifier of the own terminal.
The terminal communication unit 302 transmits the generated received signal report to (e) NodeB70 (step S402).
(e) NodeB70 detects whether or not the received signal report received from the user apparatus 30 includes the H (e) NB identifier of H (e) NB20. (e) When NodeB70 detects that the H (e) NB identifier is included, it generates handover request information (step S403). Here, the handover request information includes the H (e) NB identifier, the subscriber identifier, and the private subscriber group name included in the received signal report, and the H of the user device 30 corresponding to the subscriber identifier. (e) Information including information indicating a handover request for changing the connection to H (e) NB20 corresponding to the NB identifier.
(e) NodeB70 transmits the generated handover request information to the core network 10 via the wireless network control device 50 (step S404).
The authentication control unit 101 receives the handover request information from (e) NodeB70 via the wireless network control device 50 and the security gateway 104. Whether or not the authentication control unit 101 stores the H (e) NB identifier, the subscriber identifier, and the private subscriber group name included in the received handover request information in the access control list storage unit 103 in association with each other. The authentication process is performed based on the information. When the authentication control unit 101 detects and permits that the H (e) NB identifier and the subscriber identifier included in the received handover request information are stored in association with the access control list storage unit 103, the hand The connection change due to the over is recognized and the handover instruction information is generated (step S405). When the authentication control unit 101 detects that the H (e) NB identifier and the subscriber identifier included in the handover request information are associated and are not stored in the access control list storage unit 103, the handover is rejected. And the process ends. Here, the handover instruction information is information including a subscriber identifier of the user device 30 to be handover, an H (e) NB identifier of the handover destination of the user device 30, and a handover instruction. ..
The authentication control unit 101 transmits the generated handover instruction information to (e) NodeB70 via the security gateway 104 and the wireless network control device 50 (step S406).
(e) NodeB70 receives the handover instruction information from the core network 10 via the wireless network control device 50. (e) NodeB70 transmits the received handover instruction information to the user apparatus 30 indicated by the subscriber identifier included in the received handover instruction information (step S407).
When the terminal control unit 303 receives the handover instruction information from (e) NodeB70 via the terminal communication unit 302, the terminal control unit 303 generates terminal connection request information (step S408).
The terminal control unit 303 transmits the generated terminal connection request information to the H (e) NB20 indicated by the H (e) NB identifier included in the received handover instruction information (step S409).
Subsequent processes of steps S410 to S414 are the same as steps S203 to S207 of the connection process of the user apparatus 30 shown in FIG. 7, and thus the description thereof will be omitted. By the process described above, the user apparatus 30 performs a handover for changing the connection from the connected (e) Node B70 to H (e) NB 20 and an authentication process at the time of the handover. When communication with H (e) NB20 is possible, by changing the connection destination of the user device 30 to H (e) NB20, it becomes possible to select high-speed and inexpensive communication.
If the name of the private subscriber group of the handover source (e) NodeB70 and the name of the private subscriber group of the handover destination H (e) NB20 match, (e) NodeB70 is the handover destination. The handover instruction information including the H (e) NB identifier of the H (e) NB 20 of the above may be generated and transmitted to the user apparatus 30. Further, although the handover from (e) Node B70 to H (e) NB20 has been described, the handover from H (e) NB20 to another H (e) NB20 is also performed in the same manner. In that case, the H (e) NB20 capable of high-speed communication is selected based on the information indicating the communication status included in the received signal report.
Further, when the base station communication unit 204 transmits the H (e) NB identifier of its own device at regular time intervals, the terminal control unit 303 uses the received H (e) NB identifier as the subscriber identifier storage unit 301. When it is detected that it is stored in, the handover may be performed to the H (e) NB20 indicated by the received H (e) NB identifier. At this time, the user device 30 performs the operation of step S408, and thereafter, the mobile communication system 1 performs the operations of step S409 and subsequent steps. Further, when the base station communication unit 204 transmits the private subscriber group name of the private subscriber group to which the own device belongs at regular time intervals, the terminal control unit 303 receives the private subscriber group. When the name is stored in the subscriber identifier storage unit 301, the handover may be performed to the H (e) NB20 of the private subscriber group. At this time, the user device 30 performs the operation of step S408, and thereafter, the mobile communication system 1 performs the operations of step S409 and subsequent steps.
(Authentication process using token) FIG. 11 is a sequence diagram showing an authentication process between the H (e) NB 20 and the user device 30 using the token. It is assumed that the process of creating a private subscriber group shown in FIG. 6 has been completed. Further, the H (e) NB20 transmits the H (e) NB identifier of its own device, and the user device 30 sends the H (e) NB identifier of the H (e) NB20 that transmits the connection request to the connection request. It is assumed that it has been acquired before sending.
In the core network 10, the authentication control unit 101 generates a token for each private subscriber group stored in the authentication information storage unit 102 (step S501). This token is generated so that the information contained in the token is unique. For example, a token is a number that is randomly generated and omits duplicate numbers.
The authentication control unit 101 transmits the generated token to the H (e) NB 20 via the security gateway 104 (step S502).
When the base station control unit 203 receives the token from the core network 10, it writes the received token to the access list storage unit 202 and stores it (step S503).
Further, the base station control unit 203 transmits the received token to all the user devices 30 indicated by the subscriber identifiers included in the member list stored in the access list storage unit 202 (step S504).
When the terminal control unit 303 receives a token from the H (e) NB 20 via the terminal communication unit 302, the terminal control unit 303 stores the received token in the subscriber identifier storage unit 301 (step S505).
Next, in the user device 30, the terminal control unit 303 generates terminal connection request information when a connection request to the core network 10 is input via the terminal input / output unit 304 by the operation of the subscriber ( Step S511). Here, the terminal request information is information including a subscriber identifier and a token read from the subscriber identifier storage unit 301 by the terminal control unit 303 and a request for connecting to the core network 10.
The terminal control unit 303 transmits the generated terminal connection request information to the H (e) NB 20 via the terminal communication unit 302 (step S512).
When the base station control unit 203 receives the terminal connection request information from the user device 30, it reads out the token stored in the access list storage unit 202 and determines whether or not the token matches the token included in the received terminal connection request information. Authentication processing is performed by detecting. When the base station control unit 203 detects a match between the two tokens, it permits the connection request, and when it detects a mismatch between the two tokens, it rejects the connection request. Further, the base station control unit 203 generates terminal connection response information including the result of the authentication process for the terminal connection request information (step S513).
The base station control unit 203 transmits the generated terminal connection response information to the user device 30 and notifies the result (step S514).
As described above, the H (e) NB 20 uses the token to perform the authentication process for the connection request from the user device 30. The authentication process using the token is performed by using the token that has been transmitted to and stored in the user device 30 in advance, so that the connection request from the user device 30 that has falsified or forged the subscriber identifier can be rejected. It is possible to maintain security.
Whenever the member list shown in FIG. 9 is changed, the authentication control unit 101 regenerates the token and H (e) corresponding to the private subscriber group whose member list is changed. The newly generated token is transmitted to the NB 20 and the user device 30. Further, not only for the authentication process for the connection request from the user device 30, but also for the authentication process for the owner of the private subscriber group, the authentication control unit 101 generates a token and sets the H (e) NB20. , The generated token may be transmitted to the user device 30 indicated by the owner identifier of the access control list. Further, the authentication control unit 101 may generate a token for each subscriber identifier. In that case, the base station control unit 203 stores the token for each user device 30 permitted to connect to its own device in the access list storage unit 202. As a result, the process of deleting the subscriber identifier from the member list of the private subscriber group can be performed by deleting the token corresponding to the subscriber identifier from the access list storage unit 202. As a result, it is possible to reduce the amount of communication between the H (e) NB20 and the core network 10 for deletion.
When the mobile communication system 1 has a plurality of H (e) NB20s, in step S502, the authentication control unit 101 transmits a different token for each H (e) NB20. Further, in step S511, as the token included in the terminal connection request information generated by the terminal control unit 303, the token corresponding to the destination H (e) NB20 is selected. Here, the terminal control unit 303 selects the token using the H (e) NB identifier received from the H (e) NB 20 by the terminal communication unit 302.
As described above, in the first embodiment, the access control list storage unit 103 of the core network 10 stores the subscriber identifiers to which the connection is permitted for each H (e) NB identifier of the H (e) NB 20. It was configured. Further, the H (e) NB 20 is configured to transmit to the core network 10 by adding the H (e) NB identifier to the transmission request when transmitting the connection request of the user device 30 to the core network 10. .. As a result, the authentication control unit 101 sends the access control list storage unit 103 the authentication process for the request that the user device 30 indicated by the subscriber identifier connects to the H (e) NB 20 indicated by the H (e) NB identifier. This can be done by querying the stored access control list. As a result, the setting of the private subscriber group of the H (e) NB (radio base station device) 20, the connection of the user device 30 to the H (e) NB20, and the handover to the H (e) NB20 are performed. It will be possible to do it securely. Further, by performing the authentication process using the token, it is possible to reduce the communication for the authentication process to the core network 10.
In the mobile communication system 1 of the first embodiment, the H (e) NB20 is owned and managed by the subscriber, but may be managed by a business operator that provides mobile communication. Further, in the mobile communication system 1, the configuration of one H (e) NB20 has been described with reference to FIGS. 2 and 3, but there may be a plurality of H (e) NB20s.
In the mobile communication system 1 according to the first embodiment, the member list may not be stored in the access list storage unit 202. In that case, the authentication process for the connection request will be performed on the core network 10.
(Second Embodiment) FIG. 12 is a schematic view showing the configuration of the mobile communication system 2 according to the second embodiment. The mobile communication system 2 includes a core network 10a, a mobile management Entity (MME) 60 (hereinafter referred to as MME60), and a Home Evolved Node B (H (e) NB; Home Evolved Node B). 20a (hereinafter referred to as H (e) NB20a), wireless base station equipment (NodeB) 40 (hereinafter referred to as NodeB40), wireless network controller (RNC; Radio Network Controller) 50, user equipment (UE; User Equipment) 30 -1, 30-2, ..., 30-n, radio base station equipment (e-node B ((e) NodeB; evolved Node) B)) 70 (hereinafter referred to as (e) Node B70). The user devices 30-1, ..., 30-n have the same configuration, and hereinafter, any or all of the user devices 30-1, ..., and the user devices 30-n are represented. When shown as, it is referred to as a user device 30. Further, since the user device 30, NodeB40, (e) NodeB70 and the wireless network control device 50 have the same configuration as the mobile communication system 1 of the first embodiment, they are described with the same reference numerals 40 and 50. Omit.
As shown in the figure, the MME60 is connected between the core network 10a and the H (e) NB20a, and relays communication data performed between the core network 10a and the H (e) NB20a. Further, the user device 30 connects to the core network 10a by transmitting and receiving to and from the H (e) NB20a. The core network 10a is a core part of the mobile communication system 2 that provides mobile communication. Further, the core network 10a connects based on the information on whether or not the user device 30 is allowed to connect to the H (e) NB20a in response to the request for connecting to the H (e) NB20a of the user device 30. Performs an authentication process that determines whether or not to approve. The H (e) NB20a is connected to the core network 10a via a public line, the Internet, etc., and provides communication between the user device 30 owned by the subscribers of the private subscriber group and the core network 10a. Has a function.
Next, FIG. 13 is a sequence diagram of processing in the second embodiment. First, when the H (e) NB20a is connected to the core network 10a via a public line or the Internet, it sends an initial connection request including an H (e) NB identifier that uniquely identifies its own device to the MME60. Send to core network 10a via (steps S601, S602). When the core network 10a receives the initial connection request from the H (e) NB20a, the core network 10a establishes a secure channel with the H (e) NB20a and generates key information. After that, the core network 10a communicates with the H (e) NB20a using the secure channel set (step S603).
The core network 10a transmits the information indicating that the secure channel has been set to the H (e) NB20a via the MME60 (step S604). When the H (e) NB20a receives the information indicating that the secure channel has been set from the core network 10a, the H (e) NB20a sets the secure channel for the core network 10a and generates the key information (step S605).
After the H (e) NB20a is connected to the core network 10a, the user apparatus 30 transmits the terminal connection request information requesting the connection to the H (e) NB20 to the H (e) NB20a (steps S611, S612). .. Here, the terminal connection request information is information including a subscriber identifier that uniquely identifies the user device 30 and information that requests the H (e) NB20a to connect.
When the H (e) NB20a receives the terminal connection request information from the user apparatus 30, it transmits the connection request information including the H (e) NB identifier to the core network 10a via the MME60 (steps S613 and S614). .. When the core network 10a receives the connection request information received from the H (e) NB20a via the MME60, it determines whether or not to allow the connection for the connection requested by the received connection request information (step S615). .. Further, the core network 10a includes information indicating that the connection is approved for the connection request information, the H (e) NB identifier of the H (e) NB 20a, and the subscriber identifier of the user device 30. Send the owner registration instruction information to MME60 (step S616).
When the MME60 receives the owner registration instruction information from the core network 10a, the MME60 stores the H (e) NB identifier and the subscriber identifier included in the received owner registration instruction information in association with each other (step S617). Further, the MME60 transmits the received owner registration instruction information to the H (e) NB20a (step S618).
When the H (e) NB20a receives the owner registration instruction information from the MME60, the H (e) NB20a stores the subscriber identifier included in the received owner registration instruction information as the owner identifier indicating the owner of the own device (step S619). Further, the H (e) NB20a transmits the received owner registration instruction information to the user apparatus 30 (step S620).
When the user device 30 receives the owner registration instruction information from the H (e) NB20a, it notifies the subscriber that it has been registered as the owner of the H (e) NB20a, and connects to the H (e) NB20a. Prompt to set up a closed subscriber group (CSG), which is a group of 30 user devices that can be used.
The user device 30 generates CSG setting request information when the private subscriber group name and the subscriber identifier (member list) of the private subscriber group are input by the operation of the subscriber registered as the owner. The generated CSG configuration request information is transmitted to the core network 10a via H (e) NB20a and MME60 (steps S621 and S622). Here, the CSG setting request information includes the name of the private subscriber group corresponding to the private subscriber group, the subscriber identifier that allows connection, and H (e) NB20a of H (e) NB20a corresponding to the private subscriber group. e) Information including the NB identifier and the owner identifier.
The core network 10a receives the CSG setting request information and associates the private subscriber group name, the subscriber identifier that allows connection, the H (e) NB identifier, and the owner identifier included in the received CSG setting request information. Store as an access control list (step S623). The core network 10a performs an authentication process for a request to connect to the H (e) NB20a of the user device 30 based on the stored access control list.
As described above, in the second embodiment, the core network 10a has a configuration in which the H (e) NB identifier of the H (e) NB 20a and the subscriber identifier that is allowed to be connected are stored in association with each other. Further, the H (e) NB 20a is configured to transmit the connection request of the user apparatus 30 to the core network 10a by adding the H (e) NB identifier to the transmission request when transmitting the connection request to the core network 10a. As a result, the core network 10a performs the authentication process for the request for the user device 30 indicated by the subscriber identifier to connect to the H (e) NB 20a indicated by the H (e) NB identifier, with the subscriber identifier and H (e). This can be performed based on whether or not the NB identifier is stored in association with the NB identifier. As a result, the user device 30 can be securely connected to the H (e) NB20a.
Authentication control unit 101, authentication information storage unit 102, access control list storage unit 103, security gateway 104, subscriber identifier storage unit 106, base station control unit 203, terminal control unit 303, H (e) NB20a, core The network 10a may have a computer system inside. In that case, the process of the above-mentioned initial connection process of H (e) NB20, connection process of user device 30, member list change process, handover process, and authentication process using tokens is read by a computer in the form of a program. It is stored in a possible recording medium, and the above processing is performed by reading and executing this program by a computer. Here, the computer-readable recording medium refers to a magnetic disk, a magneto-optical disk, a CD-ROM, a DVD-ROM, a semiconductor memory, or the like. Further, this computer program may be distributed to a computer via a communication line, and the computer receiving the distribution may execute the program.
<figref num="1">It is the schematic which shows the outline of this invention.</figref><figref num="2">It is a schematic diagram which shows the structure of the mobile communication system in 1st Embodiment.</figref><figref num="3">It is the schematic which shows the structure of the core network, H (e) NB, and the user apparatus in 1st Embodiment.</figref><figref num="4">This is the authentication information stored in the authentication information storage unit in the first embodiment.</figref><figref num="5">This is an access control list stored in the access control list storage unit according to the first embodiment.</figref><figref num="6">It is a sequence diagram which shows the registration process of H (e) NB in the core network in 1st Embodiment.</figref><figref num="7">It is a sequence diagram of the connection process of the user apparatus in 1st Embodiment.</figref><figref num="8">It is a sequence diagram of the connection process of the user apparatus in 1st Embodiment.</figref><figref num="9">It is a sequence diagram of the member list change processing in 1st Embodiment.</figref><figref num="10">It is a sequence diagram of the handover processing in the 1st Embodiment.</figref><figref num="11">It is a sequence diagram of the authentication process using the token in the 1st embodiment.</figref><figref num="12">It is the schematic which showed the structure of the mobile communication system in 2nd Embodiment.</figref><figref num="13">It is a sequence diagram which showed the operation of the mobile communication system in 2nd Embodiment.</figref>
Code description
10 ... Core network 101 ... Authentication control unit, 102 ... Authentication information storage unit, 103 ... Access control list storage unit 104 ... Security Gateway, 105 ... Communication Network 106 ... Subscriber identifier storage 20 ... H (e) NB 201 ... identifier storage, 202 ... access list storage, 203 ... base station control 204 ... Base station communication department, 205 ... Antenna 30, 30-1, 30-2, 30-n ... user equipment 30-O ... owner user device, 30-M ... member user device 301 ... Subscriber identifier storage unit, 302 ... Terminal communication unit, 303 ... Terminal control unit 304 ... Terminal input / output, 305 ... Antenna 40 ... NodeB 50 ... Wireless network controller 10a ... core network 20a ... H (e) NB 60 ... MME 70 ... (e) NodeB
14 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2015524627A | Cited by | Japan | Examiner |
| US9756029B2 | Cited by | United States of America | Applicant |
| JP2013135279A | Cited by | Japan | Search report |
3 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2008192343 | Japan | A | |
| JP20080192343 | – | – | – |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| WO2010010800A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2010010800A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP2011139113AThis record | Japan | A |
Numbers
- Publication
- 2011139113
- Publication, DOCDB
- 2011139113
- Publication, EPODOC
- JP2011139113
- Application
- 192343
- Application, DOCDB
- 2008192343
- Application, EPODOC
- JP20080192343
Titles2
- Japanese
- ユーザ装置とH(e)NBとの接続方法、ユーザ装置の認証方法、移動体通信システム、H(e)NB及びコア・ネットワーク
- English
- How to connect user equipment to H (e) NB, how to authenticate user equipment, mobile communication system, H (e) NB and core network
Classification
- CPC, 8
- H04W12/08
- H04L63/101
- H04L63/104
- H04L63/107
- H04W48/02
- H04W84/045
- H04W12/06
- H04W12/72
- IPC, 2
- H04W12 06
- H04W8 20