Radio communication exchange system, exchange, public key management device, mobile terminal and mobile terminal recognizing method
Abstract
[Task] Only a small number of authentication keys are required to be registered in mobile terminals that subscribe to multiple wireless communication exchange systems.
Solution.Register the public key ko1 of PS110 in the public key DB112 of the public key management device 100. Register the private key ks1 in PS110. When the PS110 moves to the service area of the wireless communication exchange system A, the exchange 103a requests the public key of the PS110 from the public key management device 100, and uses the received public key ko1 to perform authentication based on the public key cryptography. When the PS110 moves to the service area of the wireless communication exchange system B, the exchange 103b similarly uses the public key ko1 to perform authentication based on the public key cryptosystem. Further, the exchanges 103a and 103a may determine the authentication key unique to the wireless communication exchange system and notify the PS110 when the authentication is successful, and then perform the authentication of the PS110 using the original authentication key.
Term
Term ended
Projected expiry passed 7 October 2016, 10 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
11 claims: 10 independent, 1 dependent
- 1【特許請求の範囲】 【請求項1】複数の移動端末と、当該複数の移動端末の各々と無線回線で通信するための無線基地局と、当該無線基地局に接続される交換機とを備える無線通信交換システムにおいて、 前記複数の移動端末の各々の予め定められた識別情報に対応させて、予め定められた公開鍵を管理する公開鍵管理装置を有し、 前記交換機は、前記識別情報に対応する公開鍵を前記公開鍵管理装置に要求する公開鍵要求手段と、前記公開鍵管理装置から送信された公開鍵を受信する受信手段とを備え、 前記複数の移動端末の各々は、当該移動端末の前記公開鍵に対応する秘密鍵を記憶する秘密鍵記憶手段を備え、 前記交換機と前記複数の移動端末の各々との間で、前記識別情報に対応する公開鍵もしくは前記秘密鍵を用いた公開鍵暗号方法により暗号化もしくは復号化した情報を送受信し、前記交換機は、前記送受信した情報に基づいて、前記識別情報に対応する公開鍵と、前記複数の移動端末の各々に記憶されている秘密鍵との整合性を判断することにより、前記複数の移動端末の各々を認証することを特徴とする無線通信交換システム。
- 2【請求項2】請求項1において、前記交換機は、前記複数の移動端末の各々を認証するために、乱数を生成し、認証対象の移動端末に前記乱数を送信する認証手段をさらに備え、 前記複数の移動端末の各々は、前記秘密鍵記憶手段に記憶されている秘密鍵を用いて前記公開鍵暗号方法により前記送信された乱数を暗号化し、当該暗号化した乱数を演算結果として前記交換機に送信する処理手段をさらに備え、 前記認証手段は、前記認証対象の移動端末から送信され、暗号化された乱数を、当該認証対象の移動端末に対応する公開鍵を用いて前記公開鍵暗号方法により復号化し、当該復号化した乱数と、前記生成した乱数とが一致する場合に、当該認証対象の移動端末を認証することを特徴とする無線通信交換システム。
- 3【請求項3】請求項1において、前記交換機は、前記複数の移動端末の各々を認証するために、乱数を生成し、認証対象の移動端末に対応する公開鍵を用いて前記公開鍵暗号方法により前記乱数を暗号化し、当該暗号化した乱数を前記認証対象の移動端末に送信する認証手段をさらに備え、 前記複数の移動端末の各々は、前記秘密鍵記憶手段に記憶されている秘密鍵を用いて前記公開鍵暗号方法により前記送信された暗号化された乱数を復号化し、当該復号化した乱数を演算結果として前記交換機に送信する処理手段をさらに備え、 前記認証手段は、前記認証対象の移動端末から送信され、復号化された乱数と、前記生成した乱数とが一致する場合に、当該認証対象の移動端末を認証することを特徴とする無線通信交換システム。
- 4【請求項4】請求項3において、前記認証手段は、前記複数の移動端末ごとの乱数の暗号化を予め行い、当該暗号化された乱数を、当該複数の移動端末の識別情報に対応させて記憶する記憶手段を有することを特徴とする無線通信交換システム。
- 5【請求項5】請求項2または3において、前記認証手段は、前記移動端末の認証後、当該移動端末のための、予め定めた慣用暗号方法による独自鍵を生成し、当該独自鍵を当該移動端末の識別情報に対応させて記憶し、当該独自鍵を当該移動端末に対応する公開鍵を用いて前記公開鍵暗号方法により暗号化し、当該暗号化した独自鍵を当該移動端末にさらに送信し、それ以降の当該移動端末の認証を、当該独自鍵を用いて前記慣用暗号方法により当該移動端末と送受信することにより行い、 前記処理手段は、前記秘密鍵記憶手段に記憶されている秘密鍵を用いて前記公開鍵暗号方法により前記送信された暗号化された独自鍵を復号化し、当該復号化した独自鍵を前記秘密鍵記憶手段に記憶させ、前記交換機と送受信することにより、前記秘密鍵記憶手段に記憶されている独自鍵を用いて前記慣用暗号方法により当該移動端末が認証されるための演算をさらに行うことを特徴とする無線通信交換システム。
- 6【請求項6】請求項1において、前記交換機は、認証対象の移動端末のための、予め定めた慣用暗号方法による独自鍵を生成し、当該独自鍵を当該認証対象の移動端末に対応する公開鍵を用いて前記公開鍵暗号方法により暗号化し、当該暗号化した独自鍵と、生成した乱数とを当該認証対象の移動端末に送信する認証手段をさらに備え、 前記複数の移動端末の各々は、前記秘密鍵記憶手段に記憶されている秘密鍵を用いて前記公開鍵暗号方法により前記送信された暗号化された独自鍵を復号化し、当該復号化した独自鍵を用いて、前記慣用暗号方法により前記乱数を暗号化し、当該暗号化された乱数を演算結果として前記交換機に送信する処理手段をさらに備え、 前記認証手段は、前記認証対象の移動端末から送信され、暗号化された乱数と、前記生成した乱数を前記独自鍵を用いて前記慣用暗号方法により暗号化し、当該暗号化した乱数とが一致する場合に、当該移動端末を認証することを特徴とする無線通信交換システム。
- 7【請求項7】請求項1において、前記交換機は、前記受信手段により受信された、前記識別情報に対応する公開鍵を、当該識別情報に対応させて記憶する記憶手段をさらに有し、当該記憶手段を参照し、前記識別情報に対応する公開鍵を取得して前記認証を行うことを特徴とする無線通信交換システム。
- 8【請求項8】複数の移動端末の各々と無線回線で通信するための無線基地局に接続される交換機と、前記複数の移動端末の各々の予め定められた識別情報に対応させて、予め定められた公開鍵を管理する公開鍵管理装置とを備える無線通信交換システムにおける交換機であって、 前記複数の移動端末の各々の識別情報に対応する公開鍵を前記公開鍵管理装置に要求する公開鍵要求手段と、前記公開鍵管理装置から送信された公開鍵を受信する受信手段とを備え、 前記交換機と前記複数の移動端末の各々との間で、前記識別情報に対応する公開鍵もしくは前記秘密鍵を用いた公開鍵暗号方法により暗号化もしくは復号化した情報を送受信し、前記送受信した情報に基づいて、前記識別情報に対応する公開鍵と、前記複数の移動端末の各々に記憶されている秘密鍵との整合性を判断することにより、前記複数の移動端末の各々を認証することを特徴とする交換機。
- 9【請求項9】複数の移動端末の各々と無線回線で通信するための無線基地局に接続される交換機を備える無線通信交換システムにおける公開鍵管理装置であって、 前記複数の移動端末の各々の予め定められた識別情報に対応させて、予め定められた公開鍵を記憶する記憶手段と、 前記交換機から、前記複数の移動端末の各々の識別情報に対応する公開鍵を要求されたときに、前記記憶手段を検索し、当該識別情報に対応する公開鍵を取得し、当該取得した公開鍵を送信する送信手段とを有することを特徴とする公開鍵管理装置。
- 10【請求項10】複数の移動端末と、当該複数の移動端末の各々と無線回線で通信するための無線基地局と、当該無線基地局に接続される交換機とを備える無線通信交換システムにおける移動端末であって、 当該移動端末の前記公開鍵に対応する秘密鍵を記憶する秘密鍵記憶手段と、前記秘密鍵記憶手段に記憶されている秘密鍵を用いて予め定められた公開鍵暗号方法により当該移動端末が認証されるための演算を行う処理手段と、前記交換機と送受信する送受信手段とを備えることを特徴とする移動端末。
- 11【請求項11】複数の移動端末と、当該複数の移動端末の各々と無線回線で通信するための無線基地局と、当該無線基地局に接続される交換機と、前記複数の移動端末の各々の予め定められた識別情報に対応させて、予め定められた公開鍵を管理する公開鍵管理装置とを備える無線通信交換システムにおける移動端末認証方法であって、 前記識別情報に対応する公開鍵を前記公開鍵管理装置に要求し、 前記公開鍵管理装置から送信された公開鍵を受信し、前記交換機と前記複数の移動端末の各々との間で、前記識別情報に対応する公開鍵もしくは前記秘密鍵を用いた公開鍵暗号方法により暗号化もしくは復号化した情報を送受信し、 前記送受信した情報に基づいて、前記識別情報に対応する公開鍵と、前記複数の移動端末の各々に記憶されている秘密鍵との整合性を判断することにより、前記複数の移動端末の各々を認証することを特徴とする移動端末認証方法。
Independent claims11
155 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a method for authenticating a mobile terminal (subscriber terminal) in a wireless communication exchange system including a mobile terminal and an exchange to which a wireless base station for communicating with the mobile terminal via a wireless line is connected. The present invention relates to an authentication method when the terminal is a subscriber terminal of a plurality of wireless communication exchange systems.
【0002】
[Conventional technology]
Generally, as a mobile terminal, a simple mobile phone (personal handyphone system, hereinafter referred to as PHS) is known. PHS adopts the "Second Generation Cordless Telephone System Standard" (hereinafter referred to as RCRSTD-28) of the Radio System Development Center as a wireless protocol between wireless base stations and mobile terminals, and uses the same terminal outdoors. It has been developed with the goal of being able to be used as a cordless phone in homes and businesses as a mobile phone.
【0003】
Against this background, multiple inventions have been made regarding PHS. In the "telephone device equipped with a cordless handset" described in Japanese Patent Application Laid-Open No. 6-121370, the same mobile terminal is used under the control of a plurality of home wireless base stations (master units) or a plurality of private branch exchanges. Have an invention that is possible. Further, the "cordless telephone exchange device" described in JP-A-7-177562 and the "portable terminal accommodating method" described in JP-A-7-212826 are referred to as subscriber terminals of a public mobile communication network. For the case of using the above under the control of a private branch exchange, we have invented a public mobile communication service, that is, enabling location registration, outgoing calls, incoming calls, etc. to a public mobile communication network, not just as an extension telephone.
【0004】
In the "telephone device equipped with a cordless handset" described in Japanese Patent Application Laid-Open No. 6-121370 described above, the system ID registered in advance in the home master unit or the private branch exchange and the system ID registered in the mobile terminal are used. If they match, it is determined that the mobile terminal is a subscriber terminal of the home master unit or private branch exchange, and it is assumed that communication is permitted, and then the system ID of the home master unit or private branch exchange is held. It shows how to register a system ID on a mobile terminal that is not available. The system ID referred to here is the system call code shown in RCRSTD-28 described above.
【0005】
Further, in the "cordless telephone exchange device" described in JP-A-7-177562 described above, a public subscriber terminal moved under the private branch exchange is a terminal required for call control in a public network or a private branch exchange. It shows a method of providing public services to a public subscriber terminal via a private branch exchange by notifying the private branch exchange of the identification information.
【0006】
In the first embodiment of the "portable terminal accommodating method" described in Japanese Patent Application Laid-Open No. 7-212826 described above, even if the public subscription terminal is not registered for subscription to the private branch exchange in advance, it is public under the control of the private branch exchange. Shows how to get service. In this method, when the public subscriber terminal makes a location registration request for the first time under the control of the private branch exchange, the terminal identification information is registered in the private branch exchange, and the authentication algorithm and authentication previously determined between the public network and the public branch exchange are performed. Authentication is performed under the relay of the private branch exchange using the key, and then the location of the public subscriber terminal under the private branch exchange is registered in the public network database as location information. Even if the public subscriber terminal registered in this way makes a location registration request again due to the movement between radio base stations under the private branch exchange, only the location information under the control managed by the private branch exchange is updated and sent to the public network. Location registration is not performed. The terminal is authenticated when updating the location information under the private branch exchange or transmitting to the public network, depending on whether or not the terminal identification information transmitted by the terminal to the private branch exchange has already been registered in the private branch exchange.
【0007】
Further, in the second embodiment of the "portable terminal accommodating method" described in Japanese Patent Application Laid-Open No. 7-212826, a method in which a public subscriber terminal subscribes to a private branch exchange in advance and obtains a private telephone number. Is disclosed. In the second embodiment, even when the public subscriber terminal makes a location registration request for the first time under the control of the private branch exchange, the private branch exchange authenticates based on whether or not the terminal identification information has been registered in the private branch exchange. It is different from the example of. Subsequent update of the location information under the private branch exchange and authentication of the terminal when making a call to the public network, as in the first embodiment, the own terminal identification information transmitted by the terminal to the private branch exchange is already on the premises. This is done depending on whether or not it has been registered in the exchange.
【0008】
On the other hand, in the current public PHS, authentication that is always performed every time a subscriber terminal makes an outgoing call, an incoming call, location registration, etc. is performed by a method using a cryptographic algorithm based on a conventional cryptographic method (hereinafter referred to as an authentication algorithm). The security level is higher than that of the registration method in the invention described in JP-A-7-212826. In the current public PHS, first, a set of terminal identification information and an authentication key and an authentication algorithm are registered in advance in each of the subscriber terminal and the public network. Both the terminal identification information and the authentication key are different for each subscriber terminal. During operation, authentication is performed prior to setting up a communication connection between the mobile terminal and the switch, and the procedure is as follows. The public network generates random numbers and sends the generated random numbers to mobile terminals. The mobile terminal encrypts the received random number using the authentication algorithm and the authentication key registered in itself, and transmits the encryption result to the public network. The public network obtains an authentication key that the mobile terminal should have from the terminal identification information of the mobile terminal to be authenticated, and uses it to encrypt random numbers independently of the mobile terminal. The encryption result is compared with the encryption result received from the mobile terminal, and if they match, it is determined that the authentication keys are the same, and the authentication is successful. If there is a mismatch, authentication will fail and public services will not be provided to the mobile terminal.
【0009】
[Problems to be Solved by the Invention]
Such a conventional method has the following problems. When setting a connection between a mobile terminal and an exchange including a wireless line part for location registration, outgoing call, incoming call, etc., the mobile terminal uses an authentication algorithm and an authentication key determined in advance for each wireless communication exchange system. When authenticating that is a subscriber terminal, the terminal that is not originally subscribed (public subscriber terminal, premises terminal, etc.) is not equipped with the pre-determined authentication algorithm and authentication key, so authentication is performed. Can't.
【0010】
As a countermeasure, for a wireless communication exchange system to which the mobile terminal is not originally subscribed, a method of newly subscribing and registering the authentication algorithm and the authentication key of the contracted wireless communication exchange system in the mobile terminal can be considered. However, in this method, in order to store the authentication algorithm and the authentication key in the memory built in the terminal, when there are a plurality of wireless communication exchange systems that the mobile terminal wants to be able to use, the authentication algorithm and the authentication key are used for each wireless communication exchange system. Since they are different, the authentication algorithm and authentication key corresponding to each wireless communication exchange system must be stored. Therefore, a memory capacity proportional to the number of contracted wireless communication exchange systems is required.
【0011】
Further, as another measure, a method of sharing the authentication algorithm and the authentication key for each terminal in a plurality of wireless communication exchange systems can be considered. However, if it is simply standardized, the administrator of the wireless communication exchange system (for example, PBX) can know the key of each subscriber terminal, and in another wireless communication exchange system in which he / she is not the administrator, he / she is an individual of another person. By using the key of the subscriber terminal to falsely prove that it is a subscriber terminal, it becomes possible to illegally receive communication services.
【0012】
An object of the present invention is a wireless communication exchange system, an exchange, and a management system having a mobile terminal capable of subscribing to a plurality of wireless communication exchange systems, in which the number of authentication algorithms and authentication keys registered in the mobile terminal is reduced. The purpose is to provide a device, a mobile terminal, and a terminal authentication method thereof. Another object of the present invention is to provide a wireless communication exchange system that requires less increase in the memory capacity of a mobile terminal.
【0013】
[Means for solving problems]
In order to solve the above problems, the present invention includes a plurality of mobile terminals, a radio base station for communicating with each of the plurality of mobile terminals via a wireless line, and an exchange connected to the wireless base station. In the wireless communication exchange system, the wireless communication exchange system has a public key management device that manages a predetermined public key in correspondence with each predetermined identification information of the plurality of mobile terminals, and the exchange uses the identification information. Each of the plurality of mobile terminals includes a public key requesting means for requesting a corresponding public key from the public key management device and a receiving means for receiving the public key transmitted from the public key management device. A private key storage means for storing the private key corresponding to the public key of the terminal is provided, and the public key corresponding to the identification information or the private key is used between the exchange and each of the plurality of mobile terminals. Information encrypted or decrypted by a public key cryptosystem is transmitted and received, and the exchange stores the public key corresponding to the identification information and each of the plurality of mobile terminals based on the transmitted and received information. By determining the consistency with the private key, each of the plurality of mobile terminals is authenticated.
【0014】
In the present invention, the exchange retrieves the public key from the public key management device and authenticates the mobile terminal. Also, when a mobile terminal moves to the service area of another wireless communication exchange system, the same public key encryption method is used for the same mobile terminal using the same public key and private key. Authentication is done. In public key cryptography, a numerical value encrypted with one key can be decrypted with the other key only when the private key and the corresponding public key are combined. Since the administrator of the wireless communication exchange system cannot know the private key of the mobile terminal, the administrator cannot illegally use the mobile terminal by an individual in another wireless communication exchange system. Therefore, even when the mobile terminal subscribes to a plurality of wireless communication exchange systems, only one key (private key) and authentication algorithm (authentication algorithm by public key cryptography) stored in the mobile terminal can be used. In addition, since it is not necessary to store different authentication algorithms and private keys for each of the plurality of wireless communication exchange systems, the memory capacity of the mobile terminal can be reduced.
【0015】
As a specific solution, the exchange further includes an authentication means for generating a random number and transmitting the random number to the mobile terminal to be authenticated in order to authenticate each of the plurality of mobile terminals. Each of the mobile terminals encrypts the transmitted random number by the public key cryptography method using the private key stored in the private key storage means, and transmits the encrypted random number to the exchange as a calculation result. The authentication means further includes a processing means, and the authentication means decrypts an encrypted random number transmitted from the mobile terminal to be authenticated by the public key cryptography method using a public key corresponding to the mobile terminal to be authenticated. , When the decoded random number and the generated random number match, the mobile terminal to be authenticated can be authenticated.
【0016】
As another solution, the exchange generates a random number in order to authenticate each of the plurality of mobile terminals, and uses the public key corresponding to the mobile terminal to be authenticated by the public key cryptography method. An authentication means for encrypting the random number and transmitting the encrypted random number to the mobile terminal to be authenticated is further provided, and each of the plurality of mobile terminals uses a private key stored in the private key storage means. Further, a processing means for decrypting the transmitted encrypted random number by the public key cryptography method and transmitting the decrypted random number as a calculation result to the exchange is further provided, and the authentication means moves the authentication target. When the decrypted random number transmitted from the terminal and the generated random number match, the mobile terminal to be authenticated is authenticated.
【0017】
Further, since the authentication of the mobile terminal is performed at the time of location registration, outgoing call, and incoming call of the mobile terminal, the above-mentioned authentication is performed at the time of the first location registration when the mobile terminal moves to the wireless communication exchange system. And subsequent authentication may be performed using a conventional encryption method. In this case, after the mobile terminal is authenticated, the authentication means generates a unique key for the mobile terminal by a predetermined conventional encryption method, and makes the unique key correspond to the identification information of the mobile terminal. The unique key is encrypted by the public key cryptography method using the public key corresponding to the mobile terminal, the encrypted unique key is further transmitted to the mobile terminal, and the mobile terminal thereafter. Authentication is performed by transmitting and receiving to and from the mobile terminal by the conventional encryption method using the unique key, and the processing means uses the private key stored in the private key storage means by the public key cryptography method. The transmitted encrypted original key is decrypted, the decrypted original key is stored in the private key storage means, and the original key stored in the private key storage means is transmitted to and received from the exchange. Is used to further perform an operation for authenticating the mobile terminal by the conventional cryptosystem.
【0018】
Further, as a specific other solution using the public key cryptography method, the exchange generates a unique key by a predetermined conventional cryptography method for the mobile terminal to be authenticated, and uses the unique key. An authentication means is further provided in which the public key corresponding to the mobile terminal to be authenticated is encrypted by the public key cryptography method, and the encrypted original key and the generated random number are transmitted to the mobile terminal to be authenticated. Each of the plurality of mobile terminals decrypts the encrypted unique key transmitted by the public key cryptography method using the private key stored in the private key storage means, and the decrypted unique key. Further includes a processing means for encrypting the random number by the conventional encryption method and transmitting the encrypted random number to the exchange as a calculation result, and the authentication means is transmitted from the mobile terminal to be authenticated. , The encrypted random number and the generated random number may be encrypted by the conventional encryption method using the original key, and the mobile terminal may be authenticated when the encrypted random number matches. ..
【0019】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, the first embodiment of the present invention will be described in detail.
【0020】
FIG. 1 shows a schematic diagram of a wireless communication exchange system and a public key management device to which the first embodiment of the present invention is applied. In FIG. 1, the wireless communication exchange system includes a plurality of mobile terminals (hereinafter referred to as PS) 110 and a wireless base station (hereinafter referred to as CS) 109 for communicating with each of the plurality of mobile terminals via a wireless line. , A switch 103 connected to a radio base station. Further, the wireless communication exchange system further includes a public key management device 100 that manages a public key by a predetermined public key cryptosystem in correspondence with each predetermined identification information of a plurality of PS110s.
【0021】
The exchange 103 includes a layer 1 control unit 108 that controls layer 1 communication of the communication protocol, a layer 2 control unit 107 that controls communication of layer 2 of the communication protocol, and a call control unit that controls the connection between PS and PS. 106, the authentication processing unit 104 of the authentication means that authenticates PS110 by sending and receiving to and from PS110 by public key cryptography using the public key, the key DB111 that stores the public key for each PS110, and the public key management device 100. It is provided with a communication control unit 105 that controls communication with the user.
【0022】
The exchange 103 accommodates the PS110 via a plurality of CS109s connected by a telecommunication line, and controls communication between the PS and PS. The PS110-CS109 are connected by a wireless line that employs the RCRST D-28 protocol, as in the conventional example described above. The CS109 and PBX103 are connected by, for example, the TTC standard simplified mobile phone system public base station digital network interface (JT-Q931-b, JT-Q932-a). Further, the layer 1 control unit 108 of the exchange 103 controls the electrical characteristics of the communication line, and the layer 2 control unit 107 uses the communication means provided by the layer 1 control unit 108 to link the data to the CS109. To set. The call control unit 106 sets an end-to-end connection between PSs using the data link provided by the layer 2 control unit 107. The call control unit 106 also has a position management function for managing the position information of the PS110. The authentication processing unit 104 is provided with an authentication algorithm using a predetermined public key cryptography method, and when the exchange 103 communicates with the PS110, the PS110 is a subscriber terminal of this wireless communication exchange system according to an instruction from the call control unit 106. The authentication process is performed using the public key stored in the key DB111 and the public key cryptosystem. If the key DB 111 does not store the public key corresponding to PS110, the authentication processing unit 104 requests the public key management device 100 for the public key corresponding to PS110, and is transmitted from the public key management device 110. Receives the public key and stores the public key corresponding to PS110 in the key DB111. Further, as described in the third embodiment, the authentication processing unit 104 generates an authentication key corresponding to PS110 by the conventional key cryptography method unique to the wireless communication exchange system after the authentication by the public key cryptography method. , The generated original authentication key may be notified to the PS110 via the call control unit 106 and CS109, and then the authentication may be performed according to the original conventional key cryptography method. The authentication result in the authentication processing unit 104 is transmitted to the call control unit 106, and the call control unit 106 sends it to the call control unit 106. Based on this, set or release the connection with PS110. The communication control unit 105 is for the authentication processing unit 104 to communicate with the public key management device 100, and is connected to the communication control unit 102 of the public key management device 100 via a telecommunication line such as X25. The key DB 111 manages the public key of PS110 obtained from the public key management device 100 in correspondence with the predetermined identification information (hereinafter referred to as PSN) of PS. In addition, when the PS110 is authenticated not only by the public key cryptosystem but also by the conventional encryption method and the authentication key independently determined by the wireless communication exchange system, the authentication key independently determined is also used in the key DB111. To manage.
【0023】
Figure 2 shows the key table 900 stored in the key DB111. The key table 900 stores the PSN901, the public key 902, and the original authentication key 903 for each PS110 in association with each other. The PSN901 is assigned to each PS110 that visits the wireless communication exchange system. The public key 902 and the original authentication key 903 are stored in correspondence with the PSN 901.
【0024】
The public key management device 100 receives a request from the communication control unit 102 that controls communication with the exchange 103 and the authentication processing unit 104 of the exchange 103, searches the public key DB 112, and sends the public key of the PS 110 to the AP. It includes a (application) 101, a public key DB 112 that stores the public key for each PS 110, and an input unit 115 for inputting a PSN or the like.
【0025】
In response to a request from the authentication processing unit 104 of the exchange 103, the AP 101 of the public key management device 100 searches the public key DB 112, obtains the public key of the PS110, and requests the exchange 103 for the public key via the communication control unit 102. Send the key.
【0026】
Figure 3 shows the public key table 800 stored in the public key DB 112. The public key table 800 stores the PSN 801 and the corresponding public key 802. In the public key table 800, the PSN 801 and the public key 802 for the PS 110, which are connected to the public key management device 100 and are permitted to be used in all wireless communication exchange systems, are registered via the input unit 115. For example, when there are a plurality of wireless communication exchange systems, one PSN801 and a public key 802 are assigned to the PS110 that uses each wireless communication exchange system, and in each wireless communication exchange system, the public key management device 100 The public key 802 corresponding to PSN801 of PS110 can be obtained by making an inquiry to. The public key 802 is agreed in advance for each PS at the time of the first contract for the wireless communication exchange system.
【0027】
A block diagram of the PS110 configuration is shown in FIG. In FIG. 4, the PS110 is a connection between a layer 1 control unit 108 that controls layer 1 communication of a communication protocol, a layer 2 control unit 107 that controls communication of layer 2 of a communication protocol, and an exchange 103 or another PS. The mobile terminal uses the call control unit 106 that controls the protocol, the key DB151 of the private key storage means that stores the private key corresponding to the public key, and the public key encryption method using the private key stored in the key DB151. Authentication processing unit 154 that performs authentication processing for authentication, speaker 161 that outputs voice, 163 that inputs voice, display unit 163 that displays telephone number, etc., and key input that accepts input of telephone number, etc. It includes a unit 164 and a system management unit 160 that controls and manages the entire system.
【0028】
In the PS110, the private key corresponding to the registered public key 802 is registered in advance in the public key DB112. Figure 5 shows the terminal information table 1000 registered in the public key DB 112. The terminal information table 1000 stores the PSN1001 assigned to the PS110, the private key 1002, the original authentication key 1003, and the public key 1004 in association with each other. The PS110 is provided with an authentication algorithm using a predetermined public key cryptosystem, and when the exchange 103 requests authentication by the public key cryptosystem, the PS110 performs an authentication operation using the private key 1002 and the public key cryptosystem. The original authentication key 1003 is a unique authentication key that is stored and used when the conventional encryption method is used for the authentication of the PS110, and is uniquely assigned to the PS110 by the wireless communication exchange system in which the PS110 is located. The public key 1004 is required when the PS110 is also a subscriber terminal of the public mobile communication network, and is used for the authentication calculation when the public mobile communication network authenticates the PS110.
【0029】
Next, in the configuration shown in FIG. 1, a sequence in the case of performing location registration will be described with reference to FIG. FIG. 6 shows a signal sequence diagram when the PS110 registers a position with the switch 103 of the wireless communication exchange system. In the sequence shown in FIG. 6, when a location registration request is received from the terminal, the exchange 103 authenticates the terminal using the public key and accepts the location registration after the authentication.
【0030】
In FIG. 6, when the PS110 detects a movement between wireless communication exchange systems by receiving a radio signal periodically notified by the CS109, a location registration request message including its own PSN is transmitted to the exchange 103 via the CS109. To do. The exchange 103 searches the key table 900 in the key DB 111 and determines whether or not the PS 110 has been registered (step 201). If it is not registered, a public key request message including PSN is sent to the public key management device 100. Upon receiving the public key request message, the public key management device 100 searches the public key table 800 corresponding to the PSN included in the message (step 202). In step 203, if the search is successful, the public key management device 100 transmits the PSN and the public key 802 to the exchange 103 by the public key response message, and the exchange 103 registers the PSN and the public key in the key table 900 (step). 204). In step 205, a random number for authenticating the PS110 by a predetermined public key cryptosystem is generated, and this random number is transmitted to the PS110 via the CS109 by an authentication request message. When the PS110 receives the authentication request message, it encrypts this random number using the private key 1002 registered in the terminal information table 1000 according to a predetermined public key encryption method, and encrypts the authentication calculation result. (Step 206). The PS110 sets the authentication calculation result in the authentication response message and transmits it to the exchange 103. Upon receiving the authentication response message, the exchange 103 performs an authentication operation in order to decrypt the received authentication operation result using the public key 902 of the key table 900 (step 207). In public key cryptography, a numerical value encrypted with one key can be decrypted with the other key only when the private key and the corresponding public key are combined. Therefore, the private key 1002 stored in the PS110 and the public key 802 stored in the public key management device 100 correspond to each other by determining whether or not the result of the authentication operation in step 207 matches the random number generated in step 205. Whether or not to do You can check it, which allows you to authenticate your PS110. In step 208, when the authentication calculation result matches the original random number, the position information of PS110 is registered in the call control unit 106, and the location registration acceptance message is transmitted to PS110 via CS109. In step 208, if the authentication calculation result and the original random number do not match, the exchange 103 transmits a location registration refusal message to PS110 via CS109. Further, in step 203, if the public key of PS110 cannot be searched, it means that PS110 is not permitted to be used in the wireless communication exchange system, and the public key management device 100 sends a search failure message to the exchange 103. Then, the exchange 103 that receives this search failure message sends a location registration refusal message to the PS110. Further, in step 201, if the PSN and public key of PS110 have already been registered in the key table 900 in the exchange 103, the public key is not requested to the public key management device 100, and the process proceeds to the random number generation in step 205. ..
【0031】
In the above sequence, even when the mobile terminal moves to the service area of another wireless communication exchange system, the same public key and the private key are used for the same mobile terminal in the same manner. Authentication by cryptographic method is performed.
【0032】
As described above, according to the first embodiment of the present invention, authentication by a public key cryptosystem can be performed. Further, when a mobile terminal subscribes to a plurality of wireless communication exchange systems, it can be authenticated in the plurality of wireless communication exchange systems only by storing an algorithm and a private key by a public key cryptosystem. Since it is not necessary to store different authentication algorithms and private keys for each of the multiple wireless communication exchange systems, the memory capacity of the mobile terminal can be reduced.
【0033】
Next, a second embodiment will be described. In the second embodiment, the configurations and tables shown in FIGS. 1 to 5 are the same as those in the first embodiment, but the order of the authentication operations using the public key and the private key for the random numbers generated by the exchange 103 is It is different from the first embodiment.
【0034】
FIG. 7 shows a signal sequence when the PS110 registers a position in the exchange 103 of the wireless communication exchange system in the second embodiment. In FIG. 7, steps 301 to 305 are processed in the same manner as steps 201 to 205 of the signal sequence shown in FIG. Next, in the exchange 103, the random number is encrypted by the authentication operation using the public key (step 307), and the encrypted random number is transmitted to the PS110 via the CS109 by the authentication request message. When the PS110 receives the authentication request message, it authenticates and decrypts this encrypted random number using the private key 1002 registered in the terminal information table 1000 (step 306). The PS110 sets the decrypted random number as an authentication operation result in the authentication response message and transmits it to the exchange 103. Upon receiving the authentication response message, the exchange 103 determines whether or not the decrypted random number that is the result of the authentication operation matches the random number generated in step 305, and performs authentication (step 308). Other processing is performed in the same manner as in the first embodiment.
【0035】
As described above, the random number may be encrypted by the exchange, the random number may be decrypted by the mobile terminal, and the random number decoded by the exchange may be compared with the original random number.
【0036】
Further, in the second embodiment, the authentication operation by encrypting the random number by the exchange 103 may be performed in advance before starting the communication with the PS110, and the encrypted random number may be stored in a memory or the like. Good. In this case, FIG. 8 shows a signal sequence when the PS110 registers the location with the exchange 103 of the wireless communication exchange system. In the memory for storing the encrypted random numbers, the encrypted random numbers and the PSN are stored in correspondence with each other. For example, as shown in FIG. 9, the encrypted random numbers may be stored in the key table 900 described above in correspondence with the PSN 901.
【0037】
In FIG. 8, steps 1201 to 1204 are processed in the same manner as steps 301 to 304 of the signal sequence shown in FIG. Next, in step 1210, it is checked whether the encrypted random number obtained by encrypting the random number with the public key of PS110 is already stored in the key table 900, and if it is not stored, a random number is generated (step 1205) and the authentication operation is performed. (Step 1207), set the encrypted random number in the authentication request message, and send it to PS110. If the encrypted random number is stored in step 1210, the encrypted random number is read out, set in the authentication request message, and sent to the PS110. Further, after the authentication is successful in step 1208 and the location registration acceptance message is sent to the PS110, the exchange 103 generates another different random number to be used for authentication the next time it communicates with the PS110 (step 1211), and performs the authentication operation. Perform (step 1212) and store it in the encrypted random number area of the key table 900 in correspondence with PSN (step 1213).
【0038】
By storing the encrypted random numbers in advance in this way, it is not necessary to perform an authentication operation when performing authentication, so that authentication can be performed in a shorter time.
【0039】
In the first and second embodiments, the case where the PS110 is always authenticated by the public key cryptosystem has been described above.
【0040】
Next, as the third embodiment, when the PS110 first registers the location of the exchange 103, the public key cryptosystem is used for authentication, and the subsequent location registration, outgoing call, incoming call, etc. are authenticated by the conventional encryption method. The case of doing so will be described.
【0041】
FIG. 10 shows a signal sequence when the PS110 moves under the switch 103 and performs position registration for the first time in the third embodiment. In the third embodiment, the configurations and tables shown in FIGS. 1 to 5 are the same as those in the first embodiment. In this case, the authentication processing unit 104 of the exchange 103 defines a cryptographic algorithm based on a predetermined conventional encryption method and its own key generation method, and the authentication processing unit 154 of the PS110 defines it in advance. A cryptographic algorithm based on the conventional cryptographic method is specified.
【0042】
In FIG. 10, when the PS110 detects that the wireless communication exchange system has been moved by receiving the radio signal notified by the CS109, the PS110 sends a location registration request message including information indicating a unique key request and a PSN to the CS109. Is transmitted to the exchange 103 via. Upon receiving the location registration request message, the exchange 103 checks whether the PS is requesting a unique key (step 401). If the unique key is not requested, the unique key may already be registered, so the process proceeds to step 502 shown in FIG. 11 to be described later. If a unique key is requested, a public key request message including PSN is sent to the public key management device 100. Upon receiving the public key request message, the public key management device 100 searches the public key table 800 (step 402). When the public key 802 for the PSN of the PS110 can be searched (step 403), the public key searched by the public key response message is notified to the exchange 103. Upon receiving the public key response message, the exchange 103 detects the public key included in the public key response message and registers the detected public key in the key table 900 (step 404). The exchange 103 generates a random number used for authentication, and notifies the PS110 of the generated random number by an authentication request message (step 405). The PS110 uses the private key 1002 in the terminal information table 1000 to perform an authentication operation based on the public key cryptosystem (step 406). The PS110 notifies the exchange 103 of the authentication calculation result by an authentication response message. The exchange 103 performs an authentication calculation based on the public key cryptosystem using the public key 902 registered in the key table 900 for the authentication calculation result in the received authentication response message (step 407). It is checked whether the authentication calculation result and the original random number generated in step 405 match (step 408), and if they match, the authentication is successful. If they match, register the location information in the PS110 wireless communication exchange system (step 409), and then use the wireless communication for authentication by the conventional encryption method. A key unique to the exchange system is generated, registered in the key table 900, and encrypted with the public key 902 (step 410). The exchange 103 notifies the PS110 of the encryption key by the location registration acceptance message. The PS110 decrypts the encryption key in the received location registration acceptance message using the private key 1002, and registers the resulting unique authentication key in the terminal information table 1000 (step 411).
【0043】
On the other hand, if the PSN and public key of PS110 cannot be searched in step 403, the public key management device 100 notifies the exchange 103 of the search failure message. Upon receiving the search failure message, the exchange 103 sends a location registration refusal message to the PS110 via the CS109. Further, in step 408, if the authentication calculation result by the public key and the original random number do not match, the exchange 103 sends a location registration refusal message to the PS110.
【0044】
According to the sequence shown in FIG. 10, when the PS110 first registers the location with the exchange 103, it can be authenticated by the public key cryptosystem, and then the original key can be encrypted and sent.
【0045】
Next, the signal sequence when the PS110 performs location registration with the wireless communication exchange system according to the procedure shown in FIG. 10 and then authenticates with the conventional encryption method in the location registration accompanying movement within the same wireless communication exchange system. Will be described with reference to FIG. In FIG. 11, the PS110 transmits a location registration request message to the exchange 103 via the CS109. In this case, the location registration request message is a case where the unique key has already been registered. Therefore, unlike the case shown in FIG. 10, the information indicating the unique key request should not be included. Upon receiving the location registration request message, the exchange 103 checks whether the PS110 is requesting a unique key (step 501). If not, check if unique key 903 is registered in key table 900 (step 502). If it has already been registered, a random number used for authentication is generated, and the generated random number is set in the authentication request message and transmitted to the PS110 (step 505). In addition to the random number, the authentication request message includes information indicating that a unique authentication based on a conventional encryption method using a unique key is requested. When the PS110 receives the authentication request message, it recognizes that the original authentication is requested, and uses the original authentication key 1003 in the terminal information table 1000 to perform an authentication operation that encrypts the random number based on the conventional encryption method. (Step 506). The PS110 sets the authentication calculation result in the authentication response message and transmits it to the exchange 103. The exchange 103 uses the original authentication key 903 registered in the key table 900 for the random number generated in step 505 to perform an authentication operation based on the conventional encryption formula independently of the PS110 (step 507). The authentication calculation result is compared with the authentication calculation result received from the PS110 (step 508), and if they match, the location information of the PS110 in the wireless communication exchange system is registered (step 509), and the location registration acceptance message is sent to the PS110. Send to. In step 508, when the authentication calculation result of the exchange 103 and the authentication calculation result of the PS110 do not match. The exchange 103 sends a location registration refusal message to the PS110. Further, when the original key is requested in step 501 and when the original authentication key 903 of PS110 is not registered in the key table 900 in step 502, it is necessary to perform authentication based on the public key cryptosystem again. Therefore, authentication is performed according to the procedure shown in Fig. 10.
【0046】
As described above, according to the third embodiment, authentication is performed by the public key cryptosystem at the first location registration when moving to the wireless communication exchange system, and if successful, the original key is encrypted with the public key and converted into PS. You can notify. After that, it is possible to perform encryption by the conventional encryption method using the original key. In general, the processing time of encryption by the conventional encryption method is shorter than the processing time of encryption by the public key encryption method. Therefore, after the first authentication by the public key encryption method, the authentication process is performed by performing the encryption processing by the conventional encryption method. Time can be shortened. In this case, the encryption algorithm by the conventional encryption method is common to all wireless communication exchange systems, but the unique key can be different in each wireless communication exchange system. For this reason, the administrator of one wireless communication exchange system falsely proves that he / she is a subscriber terminal by using the key of another person's subscriber terminal as an individual in another wireless communication exchange system in which he / she is not the administrator, and illegally performs the communication service. I can't receive it.
【0047】
Next, in the third embodiment, a method in which authentication by the public key is omitted will be described with reference to FIGS. 12 and 13 as the fourth embodiment. In the fourth embodiment, the private key for decrypting the original key encrypted by the public key cryptosystem should have only the PS for which the authentication is successful, so the authentication with the public key is omitted.
【0048】
FIG. 12 shows a signal sequence when the PS110 moves under the switch 103 and performs position registration for the first time. In FIG. 12, the PS110 transmits a location registration request message including information indicating the unique key request and the PSN to the exchange 103 via the CS109. Upon receiving the location registration request message, the exchange 103 checks whether or not a unique key is requested (step 601). If the unique key is not requested, the unique key may already be registered, so the process proceeds to step 702 shown in FIG. 13 described later. If a unique key is requested, a public key request message is sent to the public key management device 100. The public key management device 100 searches the public key table 800 based on the PSN of the PS110 included in the public key request message (step 602). If the public key search is successful (step 603), the exchange 103 is notified of the searched public key by the public key response message. When the exchange 103 receives the public key response message, it detects the public key included in the public key response message, generates a unique key for PS110, and registers the detected public key and the generated unique key in the key table 900. At the same time, encrypt the unique key with the public key (step 610). The exchange 103 generates a random number for authentication (step 605), sets the generated random number and the encrypted unique key in the authentication request message, and transmits the random number to the PS110. When the PS110 receives the authentication request message, it decrypts the original key based on the public key cryptosystem using the private key 1002 in the terminal information table 1000 (step 611), and stores the result as the original authentication key 1003. Next, the PS110 performs an authentication operation on the random numbers based on the conventional encryption method using the original authentication key 1003 (step 606). The PS110 sets the authentication calculation result in the authentication response message and transmits it to the exchange 103. The exchange 103 performs an authentication operation on the random number generated in step 605 based on the conventional encryption method using the unique key for PS110 generated in step 610. 607). The exchange 103 compares the result with the authentication calculation result received from the PS110 by the authentication response message (step 608), and if they match, the location information in the wireless communication exchange system of the PS110 is registered and the location registration is accepted. Send a message to PS110.
【0049】
If the authentication calculation results do not match in step 608, the unique key is deleted from the key table 900 in step 612, and a location registration refusal message is transmitted to PS110. If the public key search of the PS110 fails in step 603, the public key management device 100 sends a search failure message to the exchange 103, and the exchange 103 sends a location registration refusal message to the PS110.
【0050】
According to the sequence shown in FIG. 12, when the PS110 first registers the location with the exchange 103, the original key is encrypted and sent by the public key encryption method, and the PS110 decrypts the random number sent from the exchange and sends the unique key. Authentication can be performed by encrypting with the conventional encryption method using the above, decrypting with the original key in the exchange, and comparing whether or not the decrypted random number matches the transmitted random number.
【0051】
Next, the signal sequence when the PS110 performs location registration with the wireless communication exchange system according to the procedure shown in FIG. 12 and then authenticates with the conventional encryption method in the location registration accompanying movement within the same wireless communication exchange system. Will be described with reference to FIG. In FIG. 13, when the location registration is required, the PS110 sends a location registration request message to the exchange 103, but since the unique key is already registered in the location registration request message, it is shown in FIG. Unlike the case, do not include information indicating a unique key request. Upon receiving the location registration request message, the exchange 103 checks whether the PS110 is requesting its own key (step 701). If not, search key table 900 to see if unique key 903 is registered (step 702). If it has already been registered, a random number for authentication is generated, and the generated random number is set in the authentication request message and sent to the PS110 (step 705). When the PS110 receives the authentication request message, it recognizes that the original authentication is requested, and uses the original authentication key 1003 in the terminal information table 1000 to perform an authentication operation based on the conventional encryption method for the random number (step). 706). The PS110 sets the authentication calculation result as an authentication response message to the exchange 103 and transmits the result. The exchange 103 performs an authentication operation based on the conventional encryption method independently of the PS110 using the original authentication key 903 in the key table 900 for the random number generated in step 705 (step 707). The calculation result is compared with the authentication calculation result in the authentication response message received from the PS110 (step 708), and if they match, the location information of the PS110 in the wireless communication exchange system is registered (step 709), and the location is registered. Send the reception message to PS110. If the calculation results do not match in step 708, the exchange 103 sends a location registration refusal message to the PS110. If the PS110's unique key is not registered in the key table 900 in step 702,
【0052】
As described above, according to the fourth embodiment, the authentication by the public key in the third embodiment can be omitted.
【0053】
Next, the state of management of public keys and unique keys in a plurality of wireless communication exchange systems will be described with reference to FIG. FIG. 14 shows a configuration diagram when a plurality of wireless communication exchange systems are connected to the public key management device 100 in the third and fourth embodiments of the present invention.
【0054】
In FIG. 14, the wireless communication exchange system A and the wireless communication exchange system B are connected to the public key management device 100. PSN1, which is its own PSN, and the private key Ks1 are stored in PS1, and when it is moved to the wireless communication exchange system, the unique key k1 or k1'of each wireless communication exchange system is stored. Further, Ko1 which is the public key of PS1 is stored in the public key DB112, and Ko1 is also stored in the key DB111 of the exchange by the above-mentioned public key request and response.
【0055】
In FIG. 14, when the PS1 moves into the service area of the wireless communication exchange system A configured by the exchange 103-a, the exchange 103-a retrieves the public key Ko1 of the PS1 from the public key management device 100, and the key DB111- Register in a and authenticate PS1. After successful authentication, the exchange 103-a generates k1 as the PS1's original authentication key, registers k1 in the key DB111-a, and notifies PS1 of k1 as well. After that, the PS1 stores the original authentication key k1 in the terminal information table 1000 unless it moves out of the service area of the exchange 103-a. When the need for PS1 authentication arises, the exchange 103-a authenticates using the original authentication key k1 without relying on the public key management device 100.
【0056】
Next, when PS1 moves into the service area of the wireless communication exchange system B configured by the exchange 103-b, the exchange 103-b retrieves the public key Ko1 of the PS1 from the public key management device 100 and transfers Ko1 to the key DB111-b. Register and authenticate PS1. After successful authentication, the exchange 103-b generates k1'as the PS1's original authentication key, registers k1' in the original authentication key DB111-b, and notifies PS1 of k1'. The PS1 stores k1'instead of the original authentication key k1 stored in the terminal information table 1000 until then, and continues to store it unless it moves out of the service area of the exchange 103-b. When the exchange 103-b needs to authenticate PS1, it authenticates using the original authentication key k1'without relying on the public key management device 100.
【0057】
Further, as shown in the first and second embodiments, when authentication is always performed by the public key cryptosystem without using the authentication based on the conventional cryptosystem, the original key k1 or k1 of the wireless communication exchange system is used. 'Does not need to be memorized, and authentication can always be performed using the pair of Ko1 and Ks1.
【0058】
According to the first to fourth embodiments described above, by retrieving the public key from the public key management means provided outside the wireless communication exchange system and authenticating the PS, the PS becomes a plurality of wireless communication exchange systems. Even if you subscribe, you only need one key (private key) to be stored in the PS. In addition, even in the method of assigning an authentication key unique to the wireless communication exchange system to the PS after authentication by the public key cryptosystem and then performing authentication with the authentication key, the wireless communication exchange system in which the private key and the self are located in the PS. All you have to do is memorize your own authentication key. Furthermore, since the administrator of the wireless communication exchange system cannot know the private key of the PS, the administrator cannot create a PS that can be illegally used in another wireless communication exchange system.
【0059】
[Effect of the invention]
According to the present invention, in a wireless communication exchange system including a mobile terminal capable of subscribing to a plurality of wireless communication exchange systems, the number of authentication keys registered in the mobile terminal can be reduced. Also, the increase in the memory capacity of the mobile terminal is smaller.
[Simple explanation of drawings]
[Figure 1]
It is a block diagram of the wireless communication exchange system and the public key management apparatus in embodiment of this invention.
[Figure 2]
It is explanatory drawing which shows the key table in embodiment of this invention.
[Fig. 3]
It is explanatory drawing which shows the public key table in embodiment of this invention.
[Fig. 4]
It is a block diagram of the mobile terminal in embodiment of this invention.
[Fig. 5]
It is explanatory drawing which shows the terminal information table in embodiment of this invention.
[Fig. 6]
It is explanatory drawing which shows the signal sequence in 1st Embodiment of this invention.
[Fig. 7]
It is explanatory drawing which shows the signal sequence in the 2nd Embodiment of this invention.
[Fig. 8]
It is explanatory drawing which shows the signal sequence in the case which the random number is encrypted with the public key in advance and is stored in the 2nd Embodiment of this invention.
[Fig. 9]
It is explanatory drawing which shows the key table in the 2nd Embodiment of this invention.
[Fig. 10]
It is explanatory drawing which shows the signal sequence in the 3rd Embodiment of this invention.
[Fig. 11]
It is explanatory drawing which shows the signal sequence when the PS authentication is performed by the original authentication key in the 3rd Embodiment of this invention.
[Fig. 12]
It is explanatory drawing which shows the signal sequence in 4th Embodiment of this invention.
[Fig. 13]
It is explanatory drawing which shows the signal sequence when the PS authentication is performed by the original authentication key in the 4th Embodiment of this invention.
[Fig. 14]
In the third and fourth embodiments of the present invention, it is a block diagram explanatory diagram in the case where a plurality of wireless communication exchange systems are connected to a public key management device.
[Explanation of symbols]
100 ... Public key management device, 112 ... Public key DB, 103 ... Exchange, 111 ... Key DB, 109 ... CS, 110 ... PS, 800 ... Public key table, 900 ... key table, 1000 ... terminal information table.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR100423153B1 | Cited by | Republic of Korea | Search report |
| JP2007104733A | Cited by | Japan | Search report |
| KR20010004469A | Cited by | Republic of Korea | Search report |
| US8756709B2 | Cited by | United States of America | Applicant |
| US7869601B2 | Cited by | United States of America | Applicant |
| JP2009124399A | Cited by | Japan | Examiner |
| US7672457B2 | Cited by | United States of America | Applicant |
2 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 26610596 | Japan | A | |
| JP19960266105 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JPH10112883AThis record | Japan | A | |
| US6134431A | United States of America | A |
Numbers
- Publication
- 10-112883
- Publication, DOCDB
- H10112883
- Publication, EPODOC
- JPH10112883
- Application
- 8266105
- Application, DOCDB
- 26610596
- Application, EPODOC
- JP19960266105
Titles2
- Japanese
- 【発明の名称】無線通信交換システム、交換機、公開鍵管理装置、移動端末および移動端末認証方法
- English
- INDUSTRIAL APPLICABILITY: Wireless communication exchange system, exchange, public key management device, mobile terminal and mobile terminal authentication method.
Classification
- CPC, 4
- H04W84/16
- H04L9/083
- H04L9/3271
- H04L2209/80
- IPC, 4
- H04L9 08
- H04L9 30
- H04L9 32
- H04W84 16