Group security in machine type communication
Abstract
Problem to be solved.To solve the problem that if a related secure communication method is applied to a system which includes a plurality of the MTC (Machine Type Communication) devices, traffic in a network would increase in proportion to the number of MTC devices.
Solution.A communication apparatus which is connected to a network and a plurality of communication terminals, includes: group information sending means for sending group information which is received from the network; access control means for 1) receiving a reply from the communication terminal which responded to the group information and 2) sending the reply to the network; and temporary identifier and group key sending means for sending a temporary identifier and a group key to the communication terminal which responded to the group information, when the communication apparatus received the temporary identifier and the group key from the network.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
23 claims: 4 independent, 19 dependent
- 1A communication device connected to a network and a plurality of communication terminals, which receives a response from a group information transmitting means for transmitting group information received from the network and the communication terminal that responds to the group information, and transmits the response. An access control means for transmitting to the network and a temporary identifier for transmitting the temporary identifier and the group key to the communication terminal that responds to the group information when the communication device receives the temporary identifier and the group key from the network. And a communication device including a group key transmission means. 網と複数の通信端末に接続された通信機器であって、 前記網から受信したグループ情報を送信するグループ情報送信手段と、 前記グループ情報に応答した前記通信端末から応答を受信し、その応答を前記網に送信するアクセス制御手段と、 前記通信機器が前記網から仮識別子及びグループキーを受信したとき、前記グループ情報に応答した前記通信端末に、前記仮識別子及び前記グループキーを送信する仮識別子及びグループキー送信手段とを備える通信機器。
- 6A plurality of communication terminals, a network, and a communication device that relays communication between the plurality of communication terminals and the network are provided, and the communication device receives group information from the network and the plurality of communication terminals. A communication system characterized in that the group information is transmitted to the communication system, and a temporary identifier and a group key are transmitted to the communication terminal that responds to the group information. 複数の通信端末と、 網と、 前記複数の通信端末と前記網との間の通信を中継する通信機器とを備え、 前記通信機器は、前記網からグループ情報を受信し、前記複数の通信端末に前記グループ情報を送信し、そして、前記グループ情報に応答した前記通信端末に、仮識別子及びグループキーを送信することを特徴とする通信システム。
- 13In a communication method executed between a network and a plurality of communication terminals, group information is received from the network, the group information is transmitted to the plurality of communication terminals, and a response to the group information is received from the communication terminal. A communication method including transmitting a temporary identifier and a group key to the communication terminal that responds to the group information. 網と複数の通信端末との間で実行される通信方法において、 前記網からグループ情報を受信し、 前記複数の通信端末に前記グループ情報を送信し、 前記通信端末から前記グループ情報に対する応答を受信し、 前記グループ情報に応答した前記通信端末に、仮識別子及びグループキーを送信することを含む通信方法。
- 19Group information transmission processing for transmitting group information received from the network, access control processing for receiving a response from the communication terminal that responded to the group information and transmitting the response to the network, and a temporary identifier and a temporary identifier from the network. A storage medium for storing a communication program including the temporary identifier, a temporary identifier for transmitting the group key, and a group key transmission process in the communication terminal that responds to the group information when the group key is received. 前記網から受信したグループ情報を送信するグループ情報送信処理と、 前記グループ情報に応答した前記通信端末から応答を受信し、その応答を前記網に送信するアクセス制御処理と、 前記網から仮識別子及びグループキーを受信したとき、前記グループ情報に応答した前記通信端末に、前記仮識別子及び前記グループキーを送信する仮識別子及びグループキー送信処理とを含む通信プログラムを格納するための記憶媒体。
Independent claims4
169 paragraphs, as filed
The present invention provides a safety solution for group-based machine-type communication (MTC) disclosed in Non-Patent Documents 1 and 2. The present invention is intended to reduce signaling between MTC devices and networks and to establish efficient and secure communication between group-based MTC devices and networks.
MTC communications are attracting attention both technically / academically and industrially. According to the current 3GPP (3rd Generation Partnership Project) specifications, MTC devices within the same area and / or having the same MTC feature attributes and / or belonging to the same MTC user are grouped together and networked as a unit. Can communicate with.
However, from a security point of view, it has not yet been described how MTC devices belonging to a group establish secure communication with the network, including authentication and key assignment for the devices. Also, how MTC devices establish secure communication with the network when joining a new group has not yet been described.
Patent Document 1 discloses a method for establishing such secure communication between communication devices. In Patent Document 1, when a distribution server that distributes data receives a distribution request from another server (request server), the distribution server sends a security request to the request server. The request server configures the security settings and sends information about the security settings. The distribution server checks the security settings of the request server, and if there is no problem with the security settings received, sends the requested data to the request server.
Further, related techniques are disclosed in Patent Documents 2, 3 and 4 as follows.
Patent Document 2 discloses a method of generating a formal identifier (ID) for a new wireless communication device that does not conflict with the identifier of another wireless communication device by using a hash function.
A method of communicating between communication devices is disclosed in Patent Document 3. One-to-one or one-to-many communication is performed between devices set as the same group.
Patent Document 4 discloses that an integrated entity integrates messages received from a plurality of entities and sends the integrated message to its destination.
Patent Document 5 discloses an M2M (machine to machine, mobile to machine, machine to mobile) module connected to a network.
<p num="0010"><patcit num="1"><text>Japanese Unexamined Patent Publication No. 2008-257340</text></patcit><patcit num="2"><text>International Patent Publication WO 2007/072814</text></patcit><patcit num="3"><text>Japanese Unexamined Patent Publication No. 2006-081184</text></patcit><patcit num="4"><text>JP-A-2007-089156</text></patcit><patcit num="5"><text>Special Table 2008-543137</text></patcit></p>
<p num="0011"><nplcit num="1"><text>TS 22.368 Service requirements for Machine-Type Communications (MTC); Stage 1 (Release 10)</text></nplcit><nplcit num="2"><text>TS 23.888 System Improvements for Machine-Type Communications (Release 10)</text></nplcit><nplcit num="3"><text>TS 33.401 3GPP System Architecture Evolution (SAE); Security architecture (Release 9)</text></nplcit></p>
<p num="0012"> However, Patent Document 1 discloses secure communication between a single communication device, that is, one-to-one communication. Therefore, if the secure communication method disclosed in Patent Document 1 is applied to the system assumed in Non-Patent Document 1 including a plurality of MTC devices, the traffic in the network is proportional to the number of MTC devices. Increase. This is because communication is carried out between each single MTC device and the network.</p>
<p num="0013"> There are two main practical situations to consider. One is that a group is created before the start of communication, and the group ID (grID) is shared between the MTC device belonging to the group and the network. For the device, the grID is embedded in the USIM (Universal Subscriber Identity Module) card. This is introduced in Invention 1.</p><p num="0014"> The other situation is for MTC equipment to join an existing group. Net has no prior knowledge of this MTC device. However, an MTC device that meets the requirements for a group of networks can be required to join that group. Contrary to Invention 1, the network and MTC device cannot reach an agreement in advance. The solution is proposed in Invention 2. It is optional for the gateway to have a UICC (Universal Integrated Circuit Card). When the MTC device acts as a gateway, it will have a UICC.</p><p num="0015"> A typical object of the present invention is to provide a storage medium for storing a communication device, a communication system, a communication method, and a communication program capable of solving the above-mentioned problems.</p><p num="0016"> A communication device, which is a typical embodiment of the present invention, is a group information transmitting means that is connected to a network and a plurality of communication terminals and transmits group information received from the network, and a response from the communication terminal that responds to the group information. When the access control means that receives and transmits the response to the network and the communication device receives the temporary identifier and the group key from the network, the communication terminal that responds to the group information receives the temporary identifier and the said. Includes a temporary identifier for transmitting the group key and a means for transmitting the group key.</p><p num="0017"> A communication system, which is a typical embodiment of the present invention, includes a plurality of communication terminals, a network, and a communication device that relays communication between the plurality of communication terminals and the network, and the communication device is transmitted from the network. The group information is received, the group information is transmitted to the plurality of communication terminals, and the temporary identifier and the group key are transmitted to the communication terminals that respond to the group information.</p><p num="0018"> A communication method which is a typical form of the present invention and is executed between a network and a plurality of communication terminals receives group information from the network and causes the group information to the plurality of communication terminals. Is transmitted, a response to the group information is received from the communication terminal, and a temporary identifier and a group key are transmitted to the communication terminal that responds to the group information.</p><p num="0019"> The storage medium for storing the communication program, which is a typical form of the present invention, receives a group information transmission process for transmitting group information received from the network and a response from the communication terminal that responds to the group information. An access control process for transmitting the response to the network, and a temporary identifier for transmitting the temporary identifier and the group key to the communication terminal that responded to the group information when the temporary identifier and the group key are received from the network. And group key transmission processing.</p>
<p num="0020"> According to the present invention, the traffic between the MTC device and the network can be reduced, and secure communication between the MTC device and the network based on the group is established.</p>
<figref num="1">FIG. 1 is a block diagram for Invention 1.</figref><figref num="2">FIG. 2 is a block diagram for Invention 2.</figref><figref num="3">FIG. 3 is a message sequence chart between the MTC device, the gateway, and the core network in Invention 1.</figref><figref num="4">FIG. 4 is a message sequence chart between the MTC device, the gateway, and the core network in Invention 2.</figref><figref num="5">FIG. 5 is a block diagram showing a configuration of a communication device according to the first typical embodiment.</figref><figref num="6">FIG. 6 is a flowchart showing the operation in the first typical embodiment.</figref><figref num="7">FIG. 7 is a block diagram showing a configuration of a communication system according to a second typical embodiment.</figref><figref num="8">FIG. 8 is a block diagram showing a gateway configuration in the second typical embodiment.</figref><figref num="9">FIG. 9 is a block diagram showing a configuration of an MTC device according to a second typical embodiment.</figref><figref num="10">FIG. 10 is a block diagram showing the configuration of the core network in the second typical embodiment.</figref><figref num="11">FIG. 11 is a flowchart showing the operation in the second typical embodiment.</figref><figref num="12">FIG. 12 is a flowchart showing the operation in the third typical embodiment.</figref>
[Invention 1] An object of the present invention is achieved by using a gateway for security management for a group-optimized MTC device. The main role of the gateway is to establish secure communication between the MTC device and the core network, distribute the group key (grKey) to the MTC device to unicast the temporary ID, and execute access control. The temporary ID is generated arbitrarily.
For the present invention, some assumptions are made as follows.
1. The gateway and core network (CN) have established secure communication.
2. A group is created in advance by the decision of the network.
3. The unique group ID is known by all MTC devices in the group and is retrieved from the network by the gateway before any communication is initiated.
4. Authentication between the gateway with UICC and the network, and between the MTC device and the network follows the 3GPP standard AKA (Authentication and Key Agreement).
5. Each gateway can manage one or more groups.
The present invention includes the following steps.
1. The gateway broadcasts the grID and sets the timer. The MTC device responds to the gateway with a grID that matches what it holds.
2. The gateway sends a concatenated attach request message to the network for the MTC device that responded before the timer expired.
3. Access control against the MTC list for MTC devices that responded to the broadcast is performed by (1) gateway only, (2) network only, and (3) or both gateway and network.
4. The AKA procedure for the MTC device is performed so that all messages from the MTC device are collected at the gateway and sent to the network in a concatenated message. Similarly, the message sent from the network is a concatenated message, and the gateway distributes it to each MTC device.
5. After the AKA procedure is successful, the Security Mode Command (SMC) procedure is performed as a 3GPP standard [3] procedure. From there, a complete and confidential key is generated and activated for communication between the MTC device and the network.
6. The gateway receives the grKey from the network after secure communication is established between them and before the gateway distributes it to the MTC device. The gateway can optionally generate the grKey itself.
7. The network creates a unique temporary ID (tempID) for each MTC device that the MTC device can exclusively recognize and communicate with. The network sends its tempID to the gateway, which unicasts the tempID to each MTC device. The gateway can optionally create a tempID for the MTC device. In this case, the gateway sends its tempID to the network.
FIG. 3 is a message sequence chart between the MTC device, the gateway, and the core network in Invention 1.
In step 10, the gateway and core network authenticate each other and establish a secure channel.
In step 12, the network sends the grID, gwID, grKey, group features and MTC list to the gateway. The grKey can be optionally generated by the gateway.
In step 14, the gateway broadcasts the grID along with the characteristics of the group and fires a timer to wait for the MTC device to respond.
In step 16, an MTC device accumulating grIDs and features that match the broadcast responds to the broadcast.
In step 18, the gateway performs access control for the MTC device that responded to the broadcast by comparing the received grID against the MTC list. When the timer expires, any response from the MTC device is discarded. If the network controls access, the access control here is optional.
In step 20, the gateway sends a concatenated attach request message that includes all attach request messages from the MTC device.
In step 22, the network performs access control against the MTC list. This procedure is optional if the gateway controls access and the network trusts it.
In step 24, the network performs the MTC device authentication procedure, and then in step 26, performs the security mode command (SMC) procedure.
In step 28, the network (or optionally the gateway) generates a unique temporary ID for each MTC device. If the network generates tempIDs, send them to the gateway with an attach permission message. If the gateway generates tempIDs, in step 32, they are notified to the network.
In step 30, the gateway unicasts tempID and distributes grKey to the MTC device.
[Invention 2] An object of the present invention is achieved by a method in which the network broadcasts the feature requirements of the group, as the network does not have prior knowledge of the MTC devices that should exist within the group. MTC devices that meet those feature requirements are individually certified by the network (requiring participation in the group).
Assumptions 1, 4, and 5 of Invention 1 apply here, and for the present invention, some other assumptions are made as follows.
1. The network and MTC equipment do not have any prior knowledge of each other.
2. Mutual authentication and identification assignment between the network and MTC equipment follows the 3GPP standard procedure.
The present invention includes the following steps.
1. The network broadcasts the characteristics of the group.
2. An MTC device that meets its characteristics may respond, for example, by sending an attach request to join the group.
3. The network performs authentication and access control for MTC equipment.
4. The network generates tempID and sends it to the MTC device.
5. The network informs the gateway which MTC device will join the group by sending the MTC device identification to the gateway.
6. TempID generation is optionally done by the gateway, and if so, the network sends the MTC device's IMSI (International Mobile Subscriber Identity) to the gateway. After generating the tempID, the gateway sends it to the network.
7. The gateway distributes the grKey to the MTC device.
FIG. 4 is a message sequence chart between the MTC device, the gateway, and the core network in Invention 2.
In step 10, the gateway and core network authenticate each other and establish a secure channel.
In step 12, the network broadcasts the group features and activates a timer to wait for the MTC device to respond.
In step 14, the feature-matched MTC device can respond by sending a request to join the group.
In step 16, the network performs access control against the MTC list. When the timer expires, any response from the MTC device is discarded.
In step 18, the network performs an authentication procedure for the MTC device in response to the broadcast, and then performs an SMC procedure.
In step 20, the network generates a unique tempID for each MTC device.
In step 22, the network sends its tempID to the MTC device in an attach acceptance message.
In step 24, the network displays the tempID of the successfully authenticated MTC device on the gateway.
In step 28, the gateway can distribute grKey to the MTC device and optionally unicast the tempID that can be generated in step 26 to the MTC device. If the gateway generates tempIDs, they will be sent to the network.
According to the embodiments described above, sending a concatenated message between the gateway and the network reduces signaling and provides efficiency, especially when the group size grows significantly. Using gateways for group security management prevents further attacks on the network. It provides the group with the flexibility to have new members. Access control and tempID generation locally executed by the gateway can also reduce the load on the network.
Hereinafter, typical embodiments of the present invention will be described in detail with reference to the accompanying drawings.
<First typical embodiment> (Structure of the first typical embodiment) FIG. 5 shows the configuration of the communication device 1000. According to FIG. 5, the communication device is connected to the communication terminal 1101 and the network 1100. Although only one communication terminal 1101 is shown in FIG. 5, there may be one or more communication terminals.
According to FIG. 5, the communication device 1000 includes a group information transmission unit 1001, an access control unit 1002, and a temporary identifier and a group key transmission unit 1003. Each of them is connected to the communication terminal 1101 and the network 1100.
(Operation of the first typical embodiment) FIG. 6 shows the operation by the communication device 1000.
First, the group information transmission unit 1001 transmits the group information received from the network 1100 to the communication terminal 1101 (S1001).
The access control unit 1002 then sends a response to network 1100 (S1002). The response is a response received by the access control unit 1002 from the communication terminal 1101 as a response to the group information transmitted in step S1001.
Finally, when the temporary identifier and group key transmission unit 1003 receives the temporary identifier from the network 1100, the temporary identifier and group key transmission unit 1003 transmits the temporary identifier and group key to the communication terminal 1101 that responds to the group information ( S1003).
(Effects of the first representative embodiment) According to the first typical embodiment described above, the communication device 1000 transmits a response to the network 1100 to notify the response from the communication terminal 1101, and the communication device 1000 also responds to the group information to the communication terminal 1101. Send the temporary identifier and group key to.
Therefore, according to the first typical embodiment, the traffic can be reduced and the secure communication with the network can be established.
<Second typical embodiment> (Structure of the second typical embodiment) FIG. 7 shows the configuration of the system of the second typical embodiment of the present invention. According to FIG. 7, the system includes a gateway 100, a core network 110, an MTC device 120, an MTC device 130 and an MTC device 140.
The core network 110 is connected to the MTC devices 120 to 140 via the gateway 100. Since the MTC devices 120 to 140 have the same configuration, only the MTC device 120 will be described in detail for the sake of simplicity, and the other two description will be omitted below.
FIG. 8 shows the configuration of the gateway 100. According to FIG. 8, the gateway 100 includes a group information transmission unit 101, an access control unit 102, a tempID transmission unit 103, and a storage unit 104. Further, the gateway 100 includes an authentication unit 105, an interface (I / F) 106 and an interface (I / F) 107.
The group information transmission unit 101 receives the group information, gwID (gateway ID), grKey (group key) and MTC list from the core network 110 via the I / F 107, and stores the received group information in the storage unit 104. accumulate. Further, the group information transmission unit 101 transmits / broadcasts the received group information to the MTC device via the I / F 106.
Group information includes information such as grID and group characteristics. The grID is an identifier indicating which group the MTC device belongs to. The group feature may be the MTC feature described in the background art. As described in the background art, MTC devices with the same grID or the same group characteristics may be in the same group.
The grKey is a set of complete and confidential keys held by each group. MTC devices in the same group have the same grKey. The grKey is used for communication between the MTC device and the gateway 100. The grKey may be updated (and possibly periodic) when there are members (MTC devices) leaving the group.
The MTC list is a list of MTC devices held by the core network 110. Access control for MTC equipment can be performed according to the MTC list. If the core network 110 can send the MTC list to the gateway 100, the gateway 100 may perform access control.
The access control unit 102 receives a response from the MTC device that has responded to the group information transmitted by the group information transmission unit 101. The access control unit 102 executes access control for the responding MTC device by comparing the received response with the MTC list. It is explained that multiple MTC devices responded to the group information, but this applies mutatis mutandis when there is only one MTC device. Further, the access control unit 102 transmits the response received from the MTC device to the core network 110 via the I / F 107. When a plurality of MTC devices respond to the group information, the access control unit concatenates the responses and sends the concatenated message to the core network 110.
The tempID transmission unit 103 receives the tempID generated by the core network 110 via the I / F 107. Further, the tempID transmission unit 103 transmits / broadcasts the received tempID to the MTC device that responds to the group information transmitted by the group information transmission unit 101.
The storage unit 104 stores the group information transmitted from the core network 110.
The authentication unit 105 performs authentication between the MTC device and the core network.
The I / F 106 and I / F 107 relay all communication between the MTC device and the gateway 100, and communication between the gateway 100 and the core network 110, respectively.
FIG. 9 shows the configuration of the MTC device 120. As described above, since the MTC devices 130 and 140 have the same configuration as the MTC device 120, the description of the MTC devices 130 and 140 will be omitted.
According to FIG. 9, the MTC device 120 includes a collation unit 121, a response unit 122, an authentication unit 123 and an I / F 124.
The collation unit 121 receives the group information transmitted from the gateway 100. Further, the collation unit 121 determines whether or not the received group information matches the group information of the MTC device 120. Specifically, if the collation unit 121 receives the grID "A", the collation unit 121 determines whether the MTC device 120 itself has the grID "A".
Then, if the received group information matches the group information of the MTC device 120, the response unit 122 transmits a response to the gateway 100. Then, if the received group information does not match the group information of the MTC device 120, the response unit 122 does not transmit the response.
Authentication unit 123 performs authentication between the MTC device 120 and the gateway 100 / core network 110.
The I / F 124 relays all communication between the MTC device 120 and the gateway 100.
FIG. 10 shows the configuration of the core network 110. According to FIG. 10, the core network 110 includes a group information transmission unit 111, an access control unit 112, a tempID generation unit 113, a storage unit 114, an authentication unit 115, and an I / F 116.
The group information transmission unit 111 transmits the group information, gwID, grKey, group characteristics, and MTC list to the gateway 100.
The storage unit 114 stores the group information, gwID, grKey, group features and MTC list to be transmitted.
The access control unit 112 performs access control for the responding MTC device by comparing it with the MTC list stored in the storage unit 114. If the gateway 100 executes access control and the core network 110 trusts the access control performed by the gateway 100, the access control performed by the access control unit 112 may be omitted.
The tempID generation unit 113 generates a unique tempID for each MTC device that responds to the group information. Optionally, gateway 100 may generate tempID. If core network 110 generates tempID, that tempID is sent to gateway 100 with an attach acceptance message. Then, if the gateway 100 generates a tempID, the gateway 100 informs the core network 110 that the tempID has been generated while the gateway 100 is transmitting the tempID to the MTC device.
In addition, tempID generation unit 113 may generate grKey for each group.
The authentication unit 115 performs authentication between the core network 110 and the MTC device via the gateway 100.
The I / F 116 relays all communication between the gateway 100 and each unit of the core network 110.
(Operation of the second typical embodiment) FIG. 11 shows the operation of the second typical embodiment. For example, suppose both MTC devices 120 and 130 have grID "A".
First, the authentication unit 105 of the gateway 100 and the authentication unit 115 of the core network 110 execute mutual authentication with each other (S101). When the authentication is completed, a secure channel for secure communication is established between the gateway 100 and the core network 110.
Next, the group information transmission unit 111 transmits the group information, gwID, grKey, and MTC list to the gateway 100 (S102). For example, the group information transmission unit 111 assumes that grID "A" is transmitted as group information.
Then, the group information transmission unit 101 of the gateway 100 receives the group information, gwID, grKey, and MTC list from the core network 110. The group information transmission unit 101 stores the received information in the storage unit 104. Next, the group information transmission unit 101 transmits or broadcasts the received group information to the MTC device (S103).
The collation unit 121 of the MTC device 120 receives the group information transmitted by the step S103. Then, the collation unit 121 determines whether or not the received group information matches the group information of the MTC device 120 (S104).
Then, if the received group information matches the group information of the MTC device 120, the response unit 122 transmits a response to the gateway 100 (S105).
Then, if the received group information does not match the group information of the MTC device 120, the response unit 122 does not send a response, and the operation ends (S104: "NO").
After step S105, the access control unit 102 receives a response from the MTC device. In this case, the received grID "A" matches both grIDs "A", so that the MTC devices 120 and 130 respond to the gateway 100. Then, the access control unit 102 transmits the concatenated message created by concatenating the response or the response from the MTC device.
Access control is performed using the MTC list, which is performed by access control unit 102 of gateway 100 (S106). As described above, the access control may be executed by the access control unit 112 of the core network 110.
The access control unit 102 of the gateway 100 may wait for a predetermined period of time to send a response to the core network 110 because other MTC devices may respond to the group information as well.
Then, after the access control unit 112 receives the response or the concatenation message, the authentication unit 115 starts executing the authentication of the responding MTC device (S106). The authentication in step S106 is performed between the authentication unit 115 of the core network 110, the authentication unit 105 of the gateway 100, and the authentication unit 123 of the MTC device 120.
The tempID generation unit 113 then generates a unique tempID for each MTC device that responded to gateway 100 in step S105 (S107). For example, tempID generation unit 113 generates two unique tempIDs for each of the MTC devices 120 and 130.
Then, the tempID generation unit 113 of the core network 110 transmits the tempID generated in step S107 and the grKey for each group of the MTC devices to the gateway 100. The tempID and grKey are sent as a concatenated message. The tempID transmission unit 103 receives the concatenated message transmitted from the core network 110. Then, the tempID transmission unit 103 transmits or broadcasts the received tempID and grKey to the MTC device (S108).
After step S108, the authentication unit 123 of the MTC device 120 receives the tempID and grKey sent from the gateway 100.
(Effects of the second representative embodiment) According to the second typical embodiment described above, the gateway 100 sends a concatenation message to the core network 110 to notify the response by the MTC device, and the gateway 100 also sends the tempID and tempID in the concatenation message. Send grKey to the MTC device that responded to the group information.
Therefore, according to the second representative embodiment, in the system of the second representative embodiment, the traffic between the MTC device and the network can be reduced, and secure communication between them can be performed. Can be established.
Further, according to the second representative embodiment, the gateway 100 transmits a concatenated message created by concatenating the responses from the MTC device in response to the group information to the core network 110.
By sending a concatenated message rather than sending a response from the MTC device, traffic can be reduced in the system of the second typical embodiment. Traffic reduction is more effective, especially as the size of the group of MTC devices increases.
<Third typical embodiment> The configuration of the third representative embodiment is the same as that of the second representative embodiment. Therefore, the description of the configuration of the third typical embodiment will be omitted. The differences between the third representative embodiment and the second representative embodiment are explained as follows.
In a third representative embodiment, the core network 110 shall have no prior knowledge of the MTC device requiring participation in the group. The core network 110 transmits the characteristics of the group to the MTC device, and the MTC device satisfying the received characteristics responds and is individually authenticated by the core network 110.
FIG. 12 shows the operation of the third typical embodiment. For example, assume that both MTC devices 120 and 130 have feature "B".
First, the authentication unit 105 of the gateway 100 and the authentication unit 115 of the core network 110 perform authentication with each other to establish secure communication between them (S201).
Next, the group information transmission unit 111 of the core network 110 transmits or broadcasts the group features to the MTC device (S202). In step S202, gateway 100 may receive group features from core network 110. In this case, the group information transmission unit 101 transmits or broadcasts the received group information to the MTC device.
The collation unit 121 of the MTC device 120 receives the group feature transmitted in step S202. Then, the collation unit 121 determines whether or not the received group information matches the group characteristics of the MTC device 120 (S203).
Then, if the received group feature matches the group information of the MTC device 120, the response unit 122 transmits a request to join the group to the core network 110 (S204).
In step S204, the request from the MTC device may be sent directly to the core network 110, or the request may pass through the gateway 100. In the latter case, the access control unit 102 receives the request from the MTC device. Then, the access control unit 102 transmits a concatenated message created by concatenating the requests received from the MTC device. Since there is no difference in both cases except that the gateway 100 relays the request in the latter case, the latter case will be described below.
Then, if the received group feature does not match the group feature of the MTC device 120, the response unit 122 does not send the request and terminates the operation (S203: "NO").
After step S204, the access control unit 102 of gateway 100 receives the request. In this case, the MTC devices 120 and 130 transmit the group participation request to the gateway 100 because the received group feature "B" matches the feature "B" of both. Then, the access control unit 102 transmits the concatenated message created by concatenating the request or the request from the MTC device.
Access control is performed using the MTC list, which is performed by the access control unit 112 of the core network 110 (S205). The access control in step S205 may be performed by the access control unit 102 of the gateway 100. The access control unit 112 may also perform SMC between the core network 110 and the MTC device.
The access control unit 112 of the core network 110 may wait for a predetermined period of time to start executing authentication with the MTC device because other MTC devices may make a request as well.
When the access control unit 112 receives the concatenation message or the predetermined period expires, the authentication unit 115 starts executing the authentication of the MTC device that sent the request.
The tempID generation unit 113 then generates a unique tempID for each MTC device that requested joining the group in step S204 (S206). TempID generation unit 113 may also generate grKeys for each group if grKeys have not yet been generated.
Then, the tempID generation unit 113 transmits the tempID generated in step S206 and the grKey for each group of the MTC devices to the gateway 100. The tempID and grKey are sent as a concatenated message. The tempID transmission unit 103 receives the concatenated message transmitted from the core network 110. Then, the tempID transmission unit 103 transmits or broadcasts the received tempID and grKey to the MTC device (S207). The tempID generation unit 113 may broadcast tempID and grKey directly to the MTC device.
(Effects of the second representative embodiment) According to the second typical embodiment described above, the gateway 100 sends a concatenation message to the core network 110 to notify the response by the MTC device, and the gateway 100 also sends the tempID and tempID in the concatenation message. Send grKey to the MTC device that responded to the group information.
Therefore, according to the third representative embodiment, in the system of the third typical embodiment, the traffic between the MTC device and the network can be reduced, and secure communication between them can be performed. Can be established.
Further, according to a third typical embodiment, the gateway 100 transmits a concatenated message created by concatenating the responses from the MTC device in response to the group information to the core network 110.
By sending a concatenated message instead of sending a response from the MTC device, traffic can be reduced in the system of the third typical embodiment. Traffic reduction is more effective, especially as the size of the group of MTC devices increases.
Furthermore, according to a third representative embodiment, it is possible to authenticate the MTC device without any prior knowledge of the MTC device that the core network 110 should be in the same group.
Although the present invention has been shown and described in particular with reference to representative embodiments thereof, the present invention is not limited to those embodiments. It is understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the intent and scope of the invention as defined by the claims. To.
For example, the operations of each of the representative embodiments described above (operations shown in flowcharts and sequence charts) can be performed by hardware, software or a combined configuration of software and hardware.
When a process is executed by software, a program recording the sequence of the process may be embedded in the memory of a computer equipped with dedicated hardware and executed. It may also be possible for the program to be embedded and executed in a general purpose computer capable of performing various processes.
For example, the program can be pre-recorded on a hard disk as a storage medium and a ROM (read-only memory). In addition, the program can be stored in a removable storage medium such as a CD-ROM (compact disk read-only memory), MO (magneto-optical) disk, DVD (digital multipurpose disk), magnetic disk, or semiconductor memory. , Temporarily or permanently can be accumulated (recorded). Such removable storage media can be supplied as so-called packaged software.
In addition, the program may be incorporated by reading from a removable storage medium as described above, and the program is also otherwise transferred wirelessly from the download site to the computer. It may also be possible. The program may also be wired to the computer via a network such as a LAN (Local Area Network) and the Internet. The computer can receive the transferred program and embed the program in a storage medium such as an internal hard disk.
Furthermore, the system described in the typical embodiment described above can also have a structure of a logical combination of a plurality of devices or a configuration in which the functions of the devices are mixed.
This application claims priority on the basis of Japanese Application Application No. 2010-176115 filed on August 5, 2010, and incorporates all of its disclosures herein.
Some or all of the above representative embodiments may also be described as, but not limited to, the following appendices.
(Appendix 1) A communication device connected to a network and multiple communication terminals. A group information transmitting means for transmitting group information received from the network and An access control means that receives a response from the communication terminal that responds to the group information and transmits the response to the network. When the communication device receives the temporary identifier and the group key from the network, the temporary identifier and the group key transmitting means for transmitting the temporary identifier and the group key to the communication terminal that responds to the group information. Communication equipment equipped with.
(Appendix 2) The communication device according to Appendix 1, wherein when the communication device receives the response from the communication terminal, the access control means concatenates the responses and transmits the concatenated response to the network.
(Appendix 3) When the communication device receives the response from the communication terminal, the access control means determines that the group information transmitted to the communication terminal matches the group information held by the communication terminal, and responds. A communication device according to Appendix 1 or 2, characterized in that access control to the communication terminal is executed.
(Appendix 4) When the access control means determines that the group information to the communication terminal matches the group information held by the communication terminal, the access control means authenticates between the communication terminal and the network. Communication equipment according to Appendix 3, which is characterized by the execution of.
(Appendix 5) The group information is a communication device according to any one of Supplementary Provisions 1 to 4, wherein the group information includes at least one of a group identifier and information on the characteristics of a communication terminal.
(Appendix 6) With multiple communication terminals With the net A communication device that relays communication between the plurality of communication terminals and the network. With The communication device receives group information from the network, transmits the group information to the plurality of communication terminals, and transmits a temporary identifier and a group key to the communication terminals that respond to the group information. Characterized communication system.
(Appendix 7) The communication device is A group information transmitting means for transmitting group information received from the network and An access control means that receives a response from the communication terminal that responds to the group information and transmits the response to the network. When the communication device receives the temporary identifier and the group key from the network, the temporary identifier and the group key transmitting means for transmitting the temporary identifier and the group key to the communication terminal that responds to the group information. A communication system according to Appendix 6, which is characterized by being provided with.
(Appendix 8) A communication system according to Appendix 6 or 7, wherein when the communication device receives the response from the communication terminal, the access control means concatenates the responses and transmits the concatenated response to the network.
(Appendix 9) When the communication device receives the response from the communication terminal, the access control means determines that the group information transmitted to the communication terminal matches the group information held by the communication terminal, and responds. A communication system according to any one of Supplementary note 6 to 8, characterized in that access control to the communication terminal is executed.
(Appendix 10) When the access control means determines that the group information transmitted to the communication terminal matches the group information held by the communication terminal, the access control means between the communication terminal and the network. A communication system according to Appendix 9, which is characterized by performing authentication.
(Appendix 11) The communication terminal is A determination means for determining whether or not the group information received from the communication device matches the group information held by the communication terminal. A response means that responds to the communication device when the group information received from the communication device matches the group information held by the communication terminal. A communication system according to any one of the appendices 6 to 10, characterized in that.
(Appendix 12) The communication system according to any one of the appendices 6 to 11, wherein the group information includes at least one of a group identifier and information on the characteristics of a communication terminal.
(Appendix 13) In the communication method executed between the network and multiple communication terminals, Receive group information from the network The group information is transmitted to the plurality of communication terminals, A response to the group information is received from the communication terminal, A temporary identifier and a group key are transmitted to the communication terminal that responds to the group information. Communication method including that.
(Appendix 14) The group information received from the network is transmitted, A response is received from the communication terminal that responds to the group information, Send the response to the network and When the temporary identifier and the group key are received from the network, the temporary identifier and the group key are transmitted to the communication terminal that responds to the group information. The communication method according to Appendix 13, which further includes the above.
(Appendix 15) When the response is received from the communication terminal, the response is concatenated and the concatenated response is transmitted to the network. A communication method according to Appendix 13 or 14, characterized in that the above is further included.
(Appendix 16) When the response is received from the communication terminal, it is determined that the group information transmitted to the communication terminal matches the group information held by the communication terminal. Execute access control for the communication terminal that responded A communication method according to any one of Supplementary note 13 to 15, further comprising:
(Appendix 17) When the access control means determines that the group information transmitted to the communication terminal matches the group information held by the communication terminal, authentication between the communication terminal and the network is executed. A communication method according to Appendix 16, which further includes the above.
(Appendix 18) The communication method according to any one of Supplementary Provisions 13 to 17, wherein the group information includes at least one of a group identifier and information on the characteristics of the communication terminal.
(Appendix 19) Group information transmission process that transmits group information received from the network, An access control process that receives a response from the communication terminal that responds to the group information and transmits the response to the network. When the temporary identifier and the group key are received from the network, the temporary identifier and the group key transmission process for transmitting the temporary identifier and the group key to the communication terminal that responds to the group information. A storage medium for storing communication programs including.
(Appendix 20) When the response is received from the communication terminal, the access control process concatenates the responses and transmits the concatenated response to the network. A storage medium for storing the communication program according to Appendix 19, which is characterized in that.
(Appendix 21) When the response is received from the communication terminal, the access control process determines that the group information transmitted to the communication terminal matches the group information held by the communication terminal, and responds to the communication terminal. Perform access control for A storage medium for storing the communication program according to Appendix 19 or 20, characterized in that.
(Appendix 22) When the access control process determines that the group information transmitted to the communication terminal matches the group information held by the communication terminal, the access control process authenticates between the communication terminal and the network. To run A storage medium for storing the communication program according to Appendix 21, which is characterized in that.
(Appendix 23) The group information includes at least one of the group identifier and the information on the characteristics of the communication terminal. A storage medium for storing a communication program according to any one of the appendices 19 to 22, characterized in that.
100 gateways 101, 111, 1001 Group information transmission unit 102, 112, 1002 Access control unit 103, 113 tempID transmission unit 104, 114 storage unit 105, 115, 123 certification unit 106, 107, 116, 124 I / F (interface) 110 core net 120, 130, 140 MTC equipment 121 Collation unit 122 Relay unit 1000 communication equipment 1003 Temporary identifier and group key transmission unit 1100 net 1101 communication terminal
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2001078259A | Cites | Japan | Search report |
| JP2002111679A | Cites | Japan | Search report |
| JP2002111679A | Cites | Japan | Examiner |
| JP2003513537A | Cites | Japan | Examiner |
| JP2003513537A | Cites | Japan | Search report |
| JP2004166190A | Cites | Japan | Search report |
| JP2004166190A | Cites | Japan | Examiner |
| JP2007036541A | Cites | Japan | Search report |
| JP2007089156A | Cites | Japan | Examiner |
| JP2007089156A | Cites | Japan | Search report |
| WO2008072691A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2009042518A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2009042518A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2009042518A2 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JP2009124464A | Cites | Japan | Search report |
| JP2009124464A | Cites | Japan | Examiner |
| US6813714B1 | Cites | United States of America | Search report |
| US6813714B1 | Cites | United States of America | Examiner |
| US6813714B1 | Cites | United States of America | Search report |
| US7234058B1 | Cites | United States of America | Search report |
| US7234058B1 | Cites | United States of America | Search report |
| US7234058B1 | Cites | United States of America | Examiner |
7 priority claims, no other members on record
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 2010176115 | Japan | A | |
| 2010176115 | Japan | A | |
| 2010176115 | Japan | – | |
| 2015004993 | Japan | A | |
| 2010176115 | – | – | – |
| JP20100176115 | – | – | – |
| JP20150004993 | – | – | – |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written measure of dismissal of application [lapsed due to lack of payment]LapsedA045 | A045 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Request for written amendment filedA521 | A521 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2015065701
- Publication, DOCDB
- 2015065701
- Publication, EPODOC
- JP2015065701
- Application
- 4993
- Application, DOCDB
- 2015004993
- Application, EPODOC
- JP20150004993
Titles2
- Japanese
- マシンタイプ通信におけるグループセキュリティ
- English
- Group security in machine type communication
Classification
- CPC, 13
- H04L63/065
- H04L61/00
- H04L9/0833
- H04L9/0819
- H04W4/08
- H04L9/083
- H04W4/70
- H04L29/12207
- H04L61/50
- H04L61/20
- H04L9/08
- H04L63/062
- H04L63/067
- IPC, 4
- H04W28 08
- H04W4 08
- H04W12 04
- H04W4 70