JP2004349902A - Mobile communication system, mobile communication terminal, personal information lock method used therefor and its program - Google Patents
Mobile communication system, mobile communication terminal, personal information lock method used therefor and its program Download PDFInfo
- Publication number
- JP2004349902A JP2004349902A JP2003142799A JP2003142799A JP2004349902A JP 2004349902 A JP2004349902 A JP 2004349902A JP 2003142799 A JP2003142799 A JP 2003142799A JP 2003142799 A JP2003142799 A JP 2003142799A JP 2004349902 A JP2004349902 A JP 2004349902A
- Authority
- JP
- Japan
- Prior art keywords
- personal information
- mobile communication
- communication terminal
- registration request
- message
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000010295 mobile communication Methods 0.000 title claims abstract description 320
- 238000000034 method Methods 0.000 title claims description 58
- 238000004891 communication Methods 0.000 claims abstract description 23
- 230000007704 transition Effects 0.000 claims abstract description 13
- 230000008569 process Effects 0.000 claims description 31
- 230000005540 biological transmission Effects 0.000 claims description 15
- 230000002401 inhibitory effect Effects 0.000 claims 1
- 230000004044 response Effects 0.000 description 94
- 238000010586 diagram Methods 0.000 description 20
- 238000012546 transfer Methods 0.000 description 19
- 230000006870 function Effects 0.000 description 18
- 238000012545 processing Methods 0.000 description 13
- 238000012790 confirmation Methods 0.000 description 3
- 238000007796 conventional method Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000004880 explosion Methods 0.000 description 1
- 239000002360 explosive Substances 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 230000002265 prevention Effects 0.000 description 1
- 230000009467 reduction Effects 0.000 description 1
- 230000001960 triggered effect Effects 0.000 description 1
Images
Landscapes
- Mobile Radio Communication Systems (AREA)
- Telephone Function (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
【0001】
【発明の属する技術分野】
本発明は移動通信システム、移動体通信端末及びそれらに用いる個人情報ロック方法並びにそのプログラムに関し、特に移動体通信端末に搭載された個人情報の漏洩防止に関する。
【0002】
【従来の技術】
1990年代中から始まる携帯電話加入者の爆発的な増加によって、2002年11月末現在、国内における携帯電話加入者は7280万を越える勢いとなっている。
【0003】
このような携帯電話機の爆発的な普及は、単なる音声通話に限らず、各種データ通信までをサポートするようなサービス内容の充実化が第一の理由であると考えられるが、それ以外にも加入者が使用する携帯電話機(以下、移動体通信端末とする)自体の機能充実化もそれに貢献していると考えられる。
【0004】
すなわち、移動体通信端末自体の機能充実化とは、音声通話やデータ通信といったメインサービス機能以外の加入者自身に有効となる各種付加機能(以下、ツールとする)の充実化である。
【0005】
現状、移動体通信端末に付加されるツールの一例としては、電話帳管理ツール、メールアドレス管理ツール、スケジュール管理ツール、送受信メール管理ツール等があるが、これらツールにて扱う情報としては、いわゆる個人情報と呼ばれるような第3者への公開を決して許さない非常に重要な情報が過半数を占めていると考えられる。
【0006】
ここで、移動体通信端末の紛失について考えると、各種移動体通信事業者においては加入者が移動体通信端末を紛失した場合、拾得した第3者の悪用及び乱用を防ぐために音声通話等のメインサービス機能を停止するサポートサービスが設定されている。
【0007】
また、移動体通信端末には個人情報閲覧を制限する機能(以下、シークレットモードとする)が組込まれており、予め加入者が移動体通信端末に登録する各種個人情報に対してシークレットモードを設定にしておくことで、紛失時にツールにて取扱われる重要な個人情報が拾得した第3者に閲覧されることを防止することができる。
【0008】
ところで、シークレットモードが設定された個人情報は、閲覧時にシークレットモード解除設定が当然必要となる。ここで、一例として、氏名と電話番号との2つの情報によって電話番号を管理する電話帳管理ツールについて説明する。
【0009】
加入者は任意の相手に通話をする際、電話帳管理ツールに登録されている通話相手の氏名を検索することで、その電話番号を取得することが可能であるが、電話帳管理ツールにシークレットモードが設定されている場合には暗証番号を入力してシークレットモードを解除することで、はじめて電話番号取得が可能となる。
【0010】
つまり、加入者が通話をしようとする場合には、電話帳管理ツールに対してシークレットモードが設定されていると、通話開始までの手順としてシークレットモード設定解除という手順が必要となり、通話手順の複雑化につながるため、実際のところ、移動体通信端末を使用する加入者にとってはシークレットモード設定というもの自体が非常に手間がかかるものと認識されている。
【0011】
また、現状、シークレットモード設定は電話番号1つ1つに対して行うことが通常となっている。これは電話帳管理ツールに登録する電話番号の1つ1つを異なる暗証番号にてシークレットモード設定が可能となることを意味し、セキュリティ性向上の意味があると考えられる。
【0012】
しかしながら、逆に、電話帳管理ツールに登録する電話番号が多ければ多いほどその設定に時間を要してしまうことになり、ましてや登録する電話番号一つ一つに異なる暗証番号を使用したのでは暗証番号の忘却によるシークレットモード解除不可の可能性も高まる。このようなことから、シークレットモード設定を使用する加入者は、暗証番号をすべて同一とする場合が比較的多いといわれている。
【0013】
上記のシークレットモード以外にも、加入者が他の電話機や端末等を用いて紛失した移動体通信端末にコマンド等を送信することで、キー操作や内部情報の閲覧を禁止する方法が提案されている(例えば、特許文献1〜7参照)。
【0014】
【特許文献1】
特開平9−182158号公報(第5〜7頁、図1,2)
【特許文献2】
特開2000−151798号公報(第6〜11頁、図1)
【特許文献3】
特開2000−253457号公報(第6,7頁、図1)
【特許文献4】
特開2001−230858号公報(第6〜8頁、図1〜3)
【特許文献5】
特開2002−77372号公報(第8〜11頁、図1,2)
【特許文献6】
特開2002−77433号公報(第4,5頁、図1,2)
【特許文献7】
特開2002−218048号公報(第4,5頁、図1,2)
【0015】
【発明が解決しようとする課題】
上述した従来の個人情報の漏洩防止方法では、上記のように、シークレットモード設定を行う場合、その設定手順及び閲覧時の解除手順の両方において手間を要してしまうと考えられる。そのため、現状では加入者の過半数が個人情報に対してのシークレットモード設定自体を行っておらず、移動体通信端末の紛失時にはそれを拾得した第3者が重要な個人情報を容易に閲覧できる状況となっている。
【0016】
このようなことから、近年、移動体通信端末ではその端末の紛失による個人情報の流出及び悪用による犯罪が増加傾向にあり、重大な問題として認識され始めている。
【0017】
上記のように、シークレットモード設定の使用率が非常に低く、なおかつ移動体通信端末紛失に関係する犯罪が増加傾向にあることを考慮すると、移動体通信端末で取り扱う個人情報は紛失してしまった後でも防御できるようにしなければならないと考えられる。
【0018】
また、上述した特許文献1〜7に記載された技術を用いたとしても、紛失した移動体通信端末が通話エリアの圏外にある場合に、キー操作や内部情報の閲覧を禁止することができないという問題がある。
【0019】
そこで、本発明の目的は上記の問題点を解消し、紛失した端末が通話エリアの圏外にある場合でも個人情報の防御を可能とし、個人情報流出及び悪用といった問題の軽減を図ることができる移動通信システム、移動体通信端末及びそれらに用いる個人情報ロック方法並びにそのプログラムを提供することにある。
【0020】
【課題を解決するための手段】
本発明による移動通信システムは、基地局に対して周期的に位置登録要求を送信しかつ使用者の個人情報を記憶する移動通信端末を含む移動通信システムであって、
前記基地局への位置登録要求が予め規定された回数だけ連続して不成功となった時に少なくとも前記個人情報の読み書きを抑止する個人情報保護モードへ遷移する手段を前記移動体通信端末に備えている。
【0021】
本発明による移動体通信端末は、基地局に対して周期的に位置登録要求を送信しかつ使用者の個人情報を記憶する移動通信端末であって、
前記基地局への位置登録要求が予め規定された回数だけ連続して不成功となった時に少なくとも前記個人情報の読み書きを抑止する個人情報保護モードへ遷移する手段を備えている。
【0022】
本発明による個人情報ロック方法は、基地局に対して周期的に位置登録要求を送信しかつ使用者の個人情報を記憶する移動通信端末を含む移動通信システムの個人情報ロック方法であって、前記移動体通信端末側に、前記基地局への位置登録要求が予め規定された回数だけ連続して不成功となったことを検出するステップと、前記位置登録要求が連続して不成功となったことが検出された時に少なくとも前記個人情報の読み書きを抑止する個人情報保護モードへ遷移するステップとを備えている。
【0023】
本発明による個人情報ロック方法のプログラムは、基地局に対して周期的に位置登録要求を送信しかつ使用者の個人情報を記憶する移動通信端末を含む移動通信システムの個人情報ロック方法のプログラムであって、前記移動体通信端末側のコンピュータに、前記基地局への位置登録要求が予め規定された回数だけ連続して不成功となったことを検出する処理と、前記位置登録要求が連続して不成功となったことが検出された時に少なくとも前記個人情報の読み書きを抑止する個人情報保護モードへ遷移する処理とを実行させている。
【0024】
すなわち、本発明の移動通信システムは、移動体通信端末を紛失し、その端末が基地局のサービスエリア(通話エリア)の圏外にある場合等において、移動体通信端末に登録されている各種個人情報がその端末を拾得した第3者に容易に閲覧されたり、悪用されたりすることを防止する機能を持つことを特徴としている。
【0025】
また、本発明の移動通信システムでは、紛失した移動体通信端末が基地局のサービスエリアの圏内にある場合、その端末に対してリモートに制御情報(以下、個人情報ロックメッセージとする)を送信することによって、移動体通信端末に登録されている各種個人情報を強制的にロックすることを特徴としている。
【0026】
さらに、本発明の移動通信システムでは、紛失した移動体通信端末に対して個人情報ロックメッセージを送信する方法として、移動体通信端末側からの受信要求を必要とせず、移動体通信端末の位置情報がネットワーク側にて把握しているという条件のみで、メッセージを送信可能なシステムを利用することを特徴としている。
【0027】
より具体的に説明すると、本発明の移動通信システムは、移動体通信端末と、基地局と、基地局制御装置と、移動通信交換局と、関門移動通信交換局と、ホームロケーションレジスタとから構成されている。
【0028】
ホームロケーションレジスタは在圏位置情報等の加入者データを管理する装置である。ここで、本発明ではある特定の加入者の移動体通信端末が紛失した場合、紛失状態にある移動体通信端末には持ち主である加入者の各種個人情報が登録されており、それらの情報が端末を拾得した第3者に閲覧される危険性がある。
【0029】
そこで、持ち主である加入者はこのような危険性を回避するために、紛失した移動体通信端末に対してリモートから個人情報ロックメッセージを送信する。ホームロケーションレジスタにてその在圏位置情報が把握されているという条件下において、移動体通信端末は個人情報ロックメッセージを受信する。この時、メッセージの受信可否は拾得した第3者の意思に一切依存せず、単にホームロケーションレジスタにて移動体通信端末の在圏位置情報が把握できているか否かにのみ依存するものとする。
【0030】
移動体通信端末は個人情報ロックメッセージを受信すると、アプリケーションプログラムにてそのメッセージの内容を判断し、移動体通信端末に登録されている各種個人情報をロックする。これによって、拾得した第3者の個人情報閲覧が不可能となる。
【0031】
しかしながら、移動体通信端末は紛失時に基地局のサービスエリアの圏外にある場合、ホームロケーションレジスタに対する移動体通信端末からの位置登録要求が届かず、ホームロケーションレジスタ上にて、紛失した移動通信端末の所在エリアが把握できない状況になるため、遠隔からリモートによって個人情報を保護する機能を利用することができない。
【0032】
そこで、本発明では、紛失した移動体通信端末が基地局のサービスエリアの圏外の環境下にある場合でも、紛失した移動体通信端末内の個人情報を保護するための方法として、予め規定された回数だけ連続して基地局への位置登録要求が不成功になった状態を契機として自動的に個人情報保護モードへ遷移する機能を移動体通信端末に持たせている。
【0033】
これによって、本発明では、紛失した端末が基地局のサービスエリアの圏外にある場合でも、個人情報の防御を可能とし、個人情報流出及び悪用といった問題の軽減を図ることが可能となる。
【0034】
上記のように、本発明では、各種個人情報に対して第3者の閲覧を不可にするためのシークレットモード設定が予めなされていない場合でも、紛失時に移動体通信端末に対してリモートから個人情報ロックメッセージを送信して各種個人情報の閲覧を不可にすることができるため、その端末を拾得した第3者によって持ち主の個人情報の閲覧及び個人情報の流出や悪用が行われるのを防止することが可能となる。
【0035】
つまり、本発明では、紛失した移動体通信端末に対してリモートから登録されている個人情報をロックする新システムを提案することで、移動体端末を紛失した後でも個人情報の防御を可能とし、個人情報の流出及び悪用といった問題の軽減を図ることが可能となる。
【0036】
【発明の実施の形態】
次に、本発明の一実施例について図面を参照して説明する。図1は本発明の一実施例による移動通信システムの構成を示すブロック図である。図1において、本発明の一実施例による移動通信システムは移動体通信端末1と、基地局2と、基地局制御装置3と、移動通信交換局4と、関門移動通信交換局5と、ホームロケーションレジスタ6とから構成されている。ホームロケーションレジスタ6は在圏位置情報等の加入者データを管理する装置である。
【0037】
ここで、本実施例ではある特定の加入者の移動体通信端末1が紛失し、紛失した移動体通信端末1が電波環境の悪い場所(基地局2のサービスエリア200の圏外に在中している)にあり、しかも遠隔からの個人情報ロックが不可能な場合に、移動体通信端末1の個人情報をロック可能とする方法を示している。この場合、紛失状態にある移動体通信端末1は持ち主である加入者の各種個人情報が登録されており、それらが拾得する第3者に閲覧される危険性があるものとする。
【0038】
持ち主である加入者はこのような危険性を回避するために紛失した移動体通信端末1に対してリモートから個人情報ロックメッセージを送信するが、移動体通信端末1が基地局2のサービスエリア200の圏外にあるため、この個人情報ロックメッセージを受信することができない。
【0039】
移動体通信端末1が基地局2のサービスエリア200の圏外にある場合には、移動体通信端末1から送信される位置登録要求が基地局2にて受信されることはなく、ホームロケーションレジスタ6まで到達することができない。
【0040】
このため、ホームロケーションレジスタ6における移動体通信端末1の位置情報の更新を行うことができない。すなわち、ホームロケーションレジスタ6上にて、紛失した移動通信端末1の所在エリアが把握できない状況になるため、遠隔からリモートによって個人情報を保護する機能を利用することができない。
【0041】
そこで、本実施例では、紛失した移動体通信端末1が基地局2のサービスエリア200の圏外の環境下にある場合でも、紛失した移動体通信端末1内の個人情報を保護するための方法として、予め規定された回数だけ連続して基地局2への位置登録要求が不成功になった状態を契機として自動的に個人情報保護モードへ遷移する機能を移動体通信端末1に持たせている。
【0042】
上記の位置登録要求は移動体通信端末1から周期的に送信されるが、移動体通信端末1が基地局2のサービスエリア200の圏外にある場合には、この周期的に送信される位置登録要求がホームロケーションレジスタ6に到達することが不可能となる。その結果、移動体通信端末1側においては位置登録応答を受信することはなく、位置登録要求すべてがタイムアウト(NG)になるはずである。
【0043】
そこで、移動体通信端末1においては個人情報保護モードへの遷移を判断する基準として位置登録要求の連続タイムアウト(NG)許容回数を予め規定しておく。この許容回数については移動体通信端末1の持ち主である加入者側及びサービス提供者側のどちらからでも設定可能なものとする。
【0044】
図2は図1の移動体通信端末1の構成を示すブロック図である。図2において、移動体通信端末1はアンテナ11と、無線回路部12と、信号処理部13と、制御回路部14と、記憶回路部15と、位置登録手段16と、位置登録タイムアウトカウンタ17と、個人情報ロック部18と、送受話器19と、表示部20と、キー操作部21とから構成されている。
【0045】
記憶回路部15は制御回路部14で実行されるプログラム(コンピュータで実行可能なプログラム)や移動体通信端末1の持ち主である加入者の各種個人情報(例えば、電話帳データ、メールアドレス、スケジュールデータ等)、及び位置登録要求の連続タイムアウト許容回数等を記憶している。
【0046】
位置登録手段16は位置登録要求を基地局2に周期的に送信し、位置登録タイムアウトカウンタ17は位置登録手段16からの位置登録要求に対する応答を受信せずにタイムアウトとなった回数をカウントする。
【0047】
個人情報ロック部18は制御回路部14が位置登録タイムアウトカウンタ17のカウント値が記憶回路部15の連続タイムアウト許容回数以上となったことを検出した時、記憶回路部15の各種個人情報の読出し書込みをロックするための個人情報保護モードに自端末を遷移させる。
【0048】
尚、移動体通信端末1においてはアンテナ11、無線回路部12、信号処理部13、送受話器19、表示部20、キー操作部21各々の動作は公知であるので、その説明を省略する。
【0049】
図3は本発明の一実施例による個人情報ロック及び解除に関する移動体通信端末1の状態遷移を示す図である。これら図1〜図3を参照して移動体通信端末1の個人情報保護モードへの遷移について説明する。
【0050】
まず、移動体通信端末1は位置未登録状態(記憶回路部15の個人情報未保護状態)A1にあるものとする。この場合、移動体通信端末1は位置登録手段16によって周期的に位置登録要求を送信する。
【0051】
移動体通信端末1は位置登録要求に対する位置登録応答を正常に受信し、ホームロケーションレジスタ6からの個人情報ロック指示がない場合(図3の301)、位置登録状態(記憶回路部15の個人情報未保護状態)A2に遷移する。また、移動体通信端末1はホームロケーションレジスタ6からの個人情報ロック指示がある場合(図3の302)、個人情報ロック部18による個人情報ロック処理(後述する)を実施することで、位置登録状態[記憶回路部15の個人情報ロック状態]A3に遷移する。
【0052】
一方、移動体通信端末1は基地局2のサービスエリア200の圏外にある場合、位置登録要求がホームロケーションレジスタ6に到着しないため、位置登録要求タイムアウト(NG)が発生する(図3の303)。この場合、移動体通信端末1の状態は位置未登録状態(記憶回路部15の個人情報未保護状態)A1から遷移することはない。
【0053】
この位置登録要求タイムアウト(NG)が連続して発生し、その回数が予め規定された位置登録要求連続タイムアウト(NG)許容回数を越えた場合(図3の304)、移動体通信端末1は個人情報ロック部18によって自動的に個人情報ロック処理を実施し、位置未登録状態(記憶回路部15の個人情報ロック状態)A4に遷移する。
【0054】
この位置未登録状態(記憶回路部15の個人情報ロック状態)A4にある移動体通信端末1が基地局2のサービスエリア200の圏内に移動し、位置登録要求が成功(OK)した場合(図3の305)、位置登録状態[記憶回路部15の個人情報ロック状態]A3に状態遷移する。
【0055】
位置未登録状態(記憶回路部15の個人情報ロック状態)A4にある移動体通信端末1が持ち主の手に戻った場合には、持ち主が設定した暗証番号を入力(個人情報保護解除指示)することで(図3の06)、移動体通信端末1が位置未登録状態(記憶回路部15の個人情報未保護状態)A1に状態遷移する。
【0056】
一方、位置登録要求が成功(OK)し、ホームロケーションレジスタ6の指示によって個人情報がロックされた位置登録状態[記憶回路部15の個人情報ロック状態]A3にある移動体通信端末1が持ち主の手に戻り、持ち主が設定した暗証番号を入力(個人情報保護解除指示)することで(図3の307)、移動体通信端末1は位置登録状態(記憶回路部15の個人情報未保護状態)A2に状態遷移する。
【0057】
位置登録状態(記憶回路部15の個人情報未保護状態)A2にある移動体通信端末1が基地局2のサービスエリア200の圏外に移動し、位置登録要求が不成功(NG)になる場合(図3の308)、移動体通信端末1は位置未登録状態(記憶回路部15の個人情報未保護状態)A1に再度、状態遷移する。
【0058】
上述したように、本実施例では移動体通信端末1の所在(基地局2のサービスエリア200の圏内か圏外か)、位置登録要求結果及び個人情報ロックの指示にしたがって状態遷移する4つのモードを設定することによって、移動体通信端末1の個人情報を電波環境に依存せずに保護することができる。
【0059】
図4は図1の移動体通信端末1の位置登録要求タイムアウト(NG)処理を示すフローチャートである。これら図1〜図4を参照して位置未登録状態(記憶回路部15の個人情報未保護状態)A1から位置未登録状態(記憶回路部15の個人情報ロック状態)A4に状態遷移する際の動作について説明する。尚、図4に示す処理は制御回路部14が記憶回路部15に格納されたプログラムを実行することで実現される。
【0060】
移動体通信端末1は位置登録要求タイムアウト(NG)処理を行う場合、まず自端末において既に記憶回路部15の個人情報がロックされているかどうかを確認する(図4ステップS1)。移動体通信端末1は既に記憶回路部15の個人情報がロック済みの場合、記憶回路部15の個人情報のロック処理を終了する。
【0061】
一方、移動体通信端末1は記憶回路部15の個人情報がロックされていない場合、前回の位置登録要求結果を確認する(図4ステップS2,S3)。この前回の位置登録要求結果としては、初期値、OK、タイムアウト(NG)の3つの値が設定されるものとする。
【0062】
移動体通信端末1はこの前回の位置登録要求結果の確認において設定されている値がOKの場合、次回の位置登録要求タイムアウト(NG)処理が起動した際の確認のため、今回の位置登録要求結果としてタイムアウト(NG)を設定する図4ステップS5)。
【0063】
移動体通信端末1は前回の位置登録要求結果が初期値もしくはタイムアウト(NG)の場合、次回の位置登録要求タイムアウト(NG)処理が起動した際の確認のため、今回の位置登録要求結果としてタイムアウト(NG)を設定し(図4ステップS4)、位置登録タイムアウトカウンタ17をカウントアップする(図4ステップS6)。
【0064】
次に、移動体通信端末1は位置登録タイムアウトカウンタ17のカウンタ値と所有者もしくはサービス提供者のいずれかにより設定された位置登録要求連続タイムアウト(NG)許容回数を比較し、位置登録要求の連続タイムアウト(NG)が許容回数をオーバしたかどうかを判断する(図4ステップS7)。
【0065】
移動体通信端末1は位置登録タイムアウトカウンタ17のカウンタ値が位置登録要求連続タイムアウト(NG)許容回数未満であれば、記憶回路部15の個人情報のロック処理を終了する。
【0066】
移動体通信端末1は位置登録タイムアウトカウンタ17のカウンタ値が位置登録要求連続タイムアウト(NG)許容回数をオーバしている場合(図4ステップS7)、個人情報ロック部18によって記憶回路部15の個人情報のロック処理を実施し(図4ステップS8)、位置登録要求連続タイムアウト(NG)カウンタ17及び位置登録要求結果(今回)を初期化する(図4ステップS9,S10)。
【0067】
図5は本発明の一実施例による位置登録応答受信処理を示すフローチャートである。これら図1〜図3と図5とを参照して本発明の一実施例において位置登録要求が成功する場合に必要となる処理について説明する。尚、図5に示す処理は制御回路部14が記憶回路部15に格納されたプログラムを実行することで実現される。
【0068】
移動体通信端末1は位置登録応答受信処理において、記憶回路部15の個人情報が既にロックされているかどうかを確認し(図5ステップS11)、記憶回路部15の個人情報が未ロックであれば、位置登録要求結果(前回)を確認する(図5ステップS12)。
【0069】
移動体通信端末1は位置登録要求結果(前回)が初期値もしくはOKと設定されている場合、次回の位置登録要求タイムアウト(NG)処理が起動した際の確認のため、今回の位置登録要求結果としてOKを設定する(図5ステップS14)。
【0070】
一方、移動体通信端末1は位置登録要求結果(前回)がタイムアウト(NG)の場合、次回の位置登録要求タイムアウト(NG)処理が起動した際の確認のため、今回の位置登録要求結果としてOKを設定した後(図5ステップS13)、位置登録要求連続タイムアウト(NG)カウンタ17を初期化する(図5ステップS15)。
【0071】
これはあくまでも位置登録要求が“連続して”タイムアウト(NG)する場合に限って記憶回路部15の個人情報をロックするためであり、例えば移動体通信端末1が紛失状態ではなく、持ち主とともに電波環境が頻繁に変化するような環境下を移動しているような場合において、持ち主の意図に反して移動体通信端末1が安易に個人情報ロック状態に遷移することを防ぐこととなる。
【0072】
このように、本実施例では、移動体通信端末1が紛失して基地局2のサービスエリア200の圏外にある場合、自動的に記憶回路部15の個人情報をロックすることができる。よって、本実施例では、紛失した移動体通信端末1が基地局2のサービスエリア200の圏外にある場合でも、記憶回路部15の個人情報の防御が可能となり、個人情報流出及び悪用といった問題の軽減を図ることができる。
【0073】
次に、本発明の一実施例における個人情報ロック部18による個人情報ロック処理について説明する。本実施例では紛失した移動体通信端末1が基地局2のサービスエリア200の圏外にある場合の処理について述べたが、基地局2のサービスエリア200の圏内にある場合には上述した従来の技術と同様に、移動体通信端末1の外部から記憶回路部15の個人情報をロックすることができる。この個人情報ロック部18による個人情報ロック処理について幾つかの処理例を以下に述べる。
【0074】
図6は本発明の一実施例による移動通信システムの構成を示すブロック図である。図6において、移動体通信端末1が基地局2のサービスエリア200の圏内にある以外は図1に示す移動通信システムと同様の構成となっている。尚、移動体通信端末1の内部構成は図2に示す通りである。
【0075】
ここで、本実施例ではある特定の加入者の移動体通信端末1が紛失した場合について考える。紛失状態にある移動体通信端末1の記憶回路部15には持ち主である加入者の各種個人情報が登録されており、その端末を拾得した第3者がそれらの情報を閲覧する危険性があるものとする。
【0076】
持ち主である加入者はこのような危険性を回避するために紛失した移動体通信端末1に対してリモートから個人情報ロックメッセージ101を送信する。ホームロケーションレジスタ6にてその在圏位置情報が把握されているという条件下において、移動体通信端末1は個人情報ロックメッセージ101を受信する。この時、個人情報ロックメッセージ101の受信可否は、端末を拾得した第3者の意思には一切依存せず、単にホームロケーションレジスタ6にて移動体通信端末1の在圏位置情報が把握できているか否かにのみ依存するものとする。
【0077】
個人情報ロックメッセージ101を受信した移動体通信端末1ではアプリケーションソフトウェアにてその個人情報ロックメッセージ101の内容を判断し、移動体通信端末1の記憶回路部15に登録されている各種個人情報をロックする。これによって、紛失した移動体通信端末1が基地局2のサービスエリア200の圏内にある場合でも、端末を拾得した第3者が記憶回路部15の個人情報を閲覧することが不可能となる。
【0078】
このように、本実施例では、記憶回路部15の各種個人情報に対して第3者の閲覧を不可にするためのシークレットモード設定が予めなされていない場合でも、紛失時に移動体通信端末1に対してリモートから個人情報ロックメッセージ101を送信することで、記憶回路部15の各種個人情報の閲覧を不可にすることができるため、端末を拾得した第3者による持ち主の個人情報の閲覧及び個人情報の流出や悪用といった問題を防止することができる。
【0079】
本実施例では、移動体通信端末1への個人情報ロックメッセージ101の送信方法として、移動体通信端末1側からの受信要求を必要とせず、ネットワーク側において移動体通信端末1の位置情報を把握している条件のみでメッセージを送信することができる通信システムを適用するが、例えばその通信システム例としてはショートメッセージサービスがある。
【0080】
図7は本発明の一実施例による移動通信システムにおけるショートメッセージサービスのネットワーク概要を示す図である。図7において、紛失した状態にある移動体通信端末1の移動体通信端末アプリケーション部(以下、アプリケーション部とする)15aには移動体通信端末識別用ID151と暗証番号152とが予め登録されているものとする。
【0081】
また、移動体通信端末1の移動体通信端末メモリ部(以下、メモリ部とする)15bには通常ショートメッセージ受信(保存)用メモリ領域153とは別に、個人情報ロックメッセージ受信(保存)用メモリ領域154が確保されているものとする。
【0082】
従来のショートメッセージサービスでは、ショートメッセージセンタ7と呼ばれるサーバにてショートメッセージの中継、転送、待機を行うことで、そのサービスを実現している。また、ショートメッセージを目的の相手に送信するためには一般加入電話及び公衆電話8といった固定網300を利用して送信する方法、PC(パーソナルコンピュータ)9からインタネットを利用して送信する方法、及び移動体通信端末10から移動網400を利用して送信する方法等がある。
【0083】
本実施例では、移動体通信端末1を紛失してしまった加入者が一般加入電話及び公衆電話8、PC9または移動体通信端末10のいずれかを利用して紛失した移動体通信端末1に対して個人情報ロックメッセージ101をショートメッセージ形式にて送信している。
【0084】
図8は本発明の一実施例による個人情報ロックメッセージの構成例を示す図である。図8において、個人情報ロックメッセージBはショートメッセージ形式にて送信される個人情報ロックメッセージ101であり、個人情報ロックメッセージ識別子(B1)と、移動体通信端末識別用ID(B2)と、暗証番号(B3)と、個人情報ロックメッセージ(応答)送付先電話番号(B4)とからなる。
【0085】
個人情報ロックメッセージ識別子(B1)は紛失した移動体通信端末1側にてこのショートメッセージを受信した場合にその内容が個人情報ロックメッセージBであることを識別するためのものである。
【0086】
また、移動体通信端末識別用ID(B2)と暗証番号(B3)とは移動体通信端末アプリケーション部15aにおける移動体通信端末識別用ID151及び暗証番号152とそれぞれ同一値とする。
【0087】
さらに、個人情報ロックメッセージ(応答)送付先電話番号(B4)は移動体通信端末1における個人情報ロック状況の応答を送信する先となる電話番号を記載する領域である。
【0088】
図9は図7のショートメッセージセンタ7のメモリ領域の構成例を示す図である。図9において、ショートメッセージセンタ7のショートメッセージセンタメモリ領域Cは通常のショートメッセージを待機させる通常ショートメッセージ待機用メモリ領域C1と、個人情報ロックメッセージの応答を保存する個人情報ロックメッセージ(応答)保存用メモリ領域C2とから構成されている。
【0089】
ショートメッセージセンタメモリ領域Cに保存された個人情報ロックメッセージBの応答は加入者からのアクセスに応じて音声ガイダンス形式にて通知するものとする。
【0090】
図10は本発明の一実施例による移動通信システムの動作を示すシーケンスチャートであり、図11は図7の移動体通信端末1のショートメッセージ受信処理を示すフローチャートであり、図12は図7のショートメッセージセンタ7への個人情報ロックメッセージの構成例を示す図であり、図13は図7のショートメッセージセンタ7の個人情報ロックメッセージ(応答)受信処理を示すフローチャートである。これら図7〜図13を参照して本発明の一実施例による移動通信システムの動作について説明する。
【0091】
紛失した移動体通信端末1に対して持ち主である加入者は、別の移動体通信端末10、PC9、一般加入電話及び公衆電話8のいずれかの手段によってショートメッセージを送信する(図10のa1)。このショートメッセージの内容は図8に示す個人情報ロックメッセージBとする。
【0092】
この時、送信する手段が別の移動体通信端末10である場合には、個人情報ロックメッセージBの応答を受信するために、応答送信先として自身の電話番号を個人情報ロックメッセージ(応答)送付先電話番号(B4)に設定できるものとする。それ以外のショートメッセージ送信手段においてはショートメッセージセンタ宛ての電話番号を個人情報ロックメッセージ(応答)送付先電話番号(B4)に設定する。
【0093】
ショートメッセージを受信したショートメッセージセンタ7は関門移動通信交換局5に対してショートメッセージ転送要求を指示する(図10のa2)。このショートメッセージ転送要求を受信した関門移動通信交換局5はホームロケーションレジスタ6に対してルーティング情報問い合わせを行う(図10のa3)。
【0094】
ホームロケーションレジスタ6はこの要求に対して移動体通信端末(紛失)1へのルーティング情報をルーティング情報応答にて関門移動通信交換局5に転送する(図10のa4)。移動体通信端末(紛失)1へのルーティング情報を把握した関門移動通信交換局5はこの情報を基に該当する移動通信交換局4に対してショートメッセージ転送要求にてショートメッセージを転送する(図10のa5)。
【0095】
移動通信交換局4にて受信されたショートメッセージはショートメッセージ転送要求に示すように基地局制御装置3及び基地局2を通じて移動体通信端末(紛失)1に転送される(図10のa6)。
【0096】
移動体通信端末(紛失)1は受信したショートメッセージに対して受信完了報告として移動通信交換局4に対してACKを送信する(図10のa7)。また、移動体通信端末(紛失)1にて受信されたショートメッセージはアプリケーション部のショートメッセージ受信処理にて内容が判断され、個人情報のロックを実行する(図10のa8)。
【0097】
移動体通信端末(紛失)1のアプリケーション部15aは受信したショートメッセージのメッセージ識別子を判断し(図11ステップS21)、メッセージ識別子が個人情報ロックメッセージ識別子(B1)以外の場合、メモリ部15bの通常ショートメッセージ受信(保存)用メモリ領域153にショートメッセージを保存し(図11ステップS30)、処理を終了する。
【0098】
一方、アプリケーション部15aはメッセージ識別子が個人情報ロックメッセージ識別子(B1)の場合、移動体通信端末識別用ID(B2)及び暗証番号(B3)が移動体通信端末(紛失)1にて認識している移動体通信端末識別用ID151及び暗証番号152と合致するかどうかの判定を行う(図11ステップS22,S23)。
【0099】
アプリケーション部15aはそれらが合致しない場合、個人情報ロック不可の応答としてショートメッセージの作成を行う(図11ステップS28)。また、アプリケーション部15aはそれらが合致した場合、個人情報ロックメッセージ受信(保存)用メモリ領域154にショートメッセージを保存し(図11ステップS24)、登録されている各種個人情報をすべてロックし、移動体通信端末1外部からの個人情報表示要求を一切拒否するものとする(図11ステップS25)。
【0100】
この時、アプリケーション部15aは各種個人情報ロックが正常に終了したかどうかの判断を行い(図11ステップS26)、正常終了すると、個人情報ロック正常終了の応答としてショートメッセージの作成を行う(図11ステップS27)。
【0101】
一方、アプリケーション部15aは各種個人情報のうち1つでもロック不可能となるような場合等、個人情報ロック不可の応答としてショートメッセージの作成を行う(図11ステップS28)。この作成される個人情報ロックメッセージ(応答)のショートメッセージ例を図12に示す。
【0102】
図12において、個人情報ロックメッセージ(応答)Dは個人情報ロックメッセージ識別子D1と、暗証番号D2と、個人情報ロック結果D3とから構成され、個人情報ロック結果D3には個人情報ロック正常終了の場合にOKが、個人情報ロック不可の場合にNGがそれぞれ設定される。
【0103】
移動体通信端末(紛失)1はメッセージ作成終了後、個人情報ロックメッセージ(応答)送付先電話番号(B4)を基に個人情報ロックメッセージ(応答)Dのショートメッセージを送信する(図11ステップS29)。
【0104】
この個人情報ロックメッセージ(応答)はショートメッセージ転送応答として移動体通信端末(紛失)1から移動通信交換局4に送信される(図10のa9)。これを受信した移動体通信交換局4は受信したショートメッセージに対して受信完了報告として移動体通信端末(紛失)1に対してACKを送信し(図10のa10)、関門移動通信交換局5に対してショートメッセージ転送応答にて、個人情報ロックメッセージ(応答)Dを転送する(図10のa11)。
【0105】
これを受信する関門移動通信交換局5はショートメッセージセンタ7に対してショートメッセージ転送応答にて、個人情報ロックメッセージ(応答)Dを転送する(図10のa12)。ショートメッセージセンタ7に受信された個人情報ロックメッセージ(応答)Dは個人情報ロックメッセージ(応答)受信処理にて処理される(図10のa13)。
【0106】
すなわち、ショートメッセージセンタ7はまず受信した個人情報ロックメッセージ(応答)Dの送信先を確認し(図13ステップS31)、送信先が自装置の場合、ショートメッセージセンタメモリ領域Cの個人情報ロックメッセージ(応答)保存用メモリC2に受信したメッセージを保存する(図13ステップS32)。ショートメッセージセンタ7は送信先が自装置以外(移動体通信端末10宛て)の場合、該当する送信先へ個人情報ロックメッセージ(応答)Dを転送する(図13ステップS33)。
【0107】
この個人情報ロックメッセージ(応答)Dはショートメッセージセンタ7から移動体通信端末10に転送される(図10のa14)。このショートメッセージが移動体通信端末10にて受信されることで、移動体通信端末(紛失)1の個人情報ロック結果が持ち主である加入者にて確認されることとなる。
【0108】
ところで、個人情報ロックメッセージ(応答)Dは移動体通信端末を通信手段とした場合のみ、ショートメッセージ形式にて受信可能であるが、通信手段をPC9や一般加入電話及び公衆電話8とした場合にはショートメッセージ受信が不可能であるため、個人情報ロック結果を確認することができない。
【0109】
しかしながら、PC9や一般加入電話及び公衆電話8から個人情報ロックメッセージを送信する場合、個人情報ロックメッセージ(応答)送付先電話番号(B4)にはショートメッセージセンタ7を指定することで、個人情報ロックメッセージ(応答)Dはショートメッセージセンタ7内の個人情報ロックメッセージ(応答)保存用メモリ領域C2に保存される。
【0110】
そこで、一般加入電話及び公衆電話8を利用してショートメッセージセンタ7にアクセスし、保存された個人情報ロックメッセージ(応答)Dを音声ガイダンス形式によって加入者に対して通知するシステムを考える。
【0111】
図14は図7のショートメッセージセンタ7に対する個人情報ロックメッセージ(応答)Dの確認動作を示すシーケンスチャートであり、図15は図7のショートメッセージセンタ7による検索処理を示すフローチャートである。これら図7と図14と図15とを参照してショートメッセージセンタ7に対する個人情報ロックメッセージ(応答)Dの確認動作について説明する。
【0112】
加入者は一般加入電話及び公衆電話8からショートメッセージセンタ7に対して個人情報ロックメッセージ(応答)問合せによってアクセスする(図14のb1)。ショートメッセージセンタ7はこの問合せに対して、移動体通信端末識別用ID入力要求を音声ガイダンス形式にて加入者に指示し(図14のb2)、移動体通信端末識別用ID入力応答によって移動体通信端末識別用IDが入力されるのを待つ(図14のb3)。
【0113】
この移動体通信端末識別用ID入力応答を受信した後、ショートメッセージセンタ7は暗証番号入力要求を音声ガイダンス形式にて加入者に指示する(図14のb4)。これに対して、加入者は暗証番号を暗証番号入力応答をショートメッセージセンタ7に通知する(図14のb5)。
【0114】
ショートメッセージセンタ7は移動体通信端末識別用ID入力応答及び暗証番号入力応答にて通知された2つの情報を基に個人情報ロックメッセージ(応答)保存用メモリC2の検索を実行する(図13のb6)(図15ステップS41)。
【0115】
ショートメッセージセンタ7は加入者から入力された移動体通信端末識別用ID及び暗証番号に合致する個人情報ロックメッセージ(応答)が存在しない場合(図15ステップS42)、音声ガイダンスの内容を『個人情報ロック未完了』とし(図15ステップS46)、個人情報ロック結果音声ガイダンスにて加入者に通知する(図13のb7)。
【0116】
一方、ショートメッセージセンタ7は加入者から入力された移動体通信端末識別用ID及び暗証番号に合致する個人情報ロックメッセージ(応答)が存在する場合(図15ステップS42)、個人情報ロックメッセージ(応答)のメッセージ内容を判断する(図15ステップS43)。
【0117】
ショートメッセージセンタ7はメッセージ内容が個人情報ロック正常終了であれば、音声ガイダンス内容を『個人情報ロック正常終了』とし(図15ステップS44)、メッセージ内容が個人情報ロックNGであれば、音声ガイダンス内容を『個人情報ロック不可』として(図15ステップS45)、個人情報ロック結果音声ガイダンスにて加入者に通知する(図13のb7)。
【0118】
上記の構成及び動作をショートメッセージセンタ7にて実現することで、加入者がショートメッセージ受信が不可能な通信手段を利用した場合でも個人情報ロック結果を確認することができる。
【0119】
また、移動体通信端末(紛失)1が電源OFF等の場合には、その在圏位置情報が不明になり、ホームロケーションレジスタ6にて管理するルーティング情報の更新が行われないため、ショートメッセージの受信、すなわち個人情報ロックメッセージの受信が不可能となる。このような状況を考慮して、個人情報ロックメッセージ(ショートメッセージ)の再送システムを考える。
【0120】
まず、紛失した移動体通信端末1側が個人情報ロックメッセージ受信不可能状態にあることをネットワーク側にて検出する方法と、その結果に基づいてショートメッセージセンタ7に対して待機メッセージ設定を実施するシステムとについて説明する。
【0121】
図16は本発明の一実施例による個人情報ロックメッセージ受信不可時の待機メッセージ設定動作を示すシーケンスチャートであり、図17は本発明の一実施例による個人情報ロックメッセージ(ショートメッセージ)再送動作を示すシーケンスチャートである。これら図7と図16と図17とを参照して紛失した移動体通信端末1側が個人情報ロックメッセージ受信不可能状態にある場合の動作について説明する。
【0122】
関門移動通信局5はショートメッセージセンタ7からの要求に応じてショートメッセージ転送要求によってショートメッセージ(個人情報ロックメッセージ)を移動通信交換局4に転送する(図16のc1)。この時、関門移動通信交換局5は移動体通信端末(紛失)1からのショートメッセージ転送応答を待つためのタイマを設定する(図16のc2)。
【0123】
ここで、移動体通信交換局4から基地局制御装置3及び基地局2を通してショートメッセージ転送要求にて移動体通信端末(紛失)1にショートメッセージが転送される(図16のc3)。移動体通信端末(紛失)1は電源OFF等によってショートメッセージ受信不可状態にあるため(図16のc4)、ショートメッセージ転送応答を送信せず、結果的にショートメッセージ転送応答待ちタイマがタイムアウトすることとなる(図16のc5)。
【0124】
この時、関門移動通信交換局5はホームロケーションレジスタ6に対して待機メッセージ情報設定要求を送信する(図16のc6)。この要求に対してホームロケーションレジスタ6は移動体通信端末(紛失)1宛てのショートメッセージが待機状態にあることを自身がもつ加入者情報に設定する(図16のc7)。
【0125】
その設定終了後、ホームロケーションレジスタ6から関門移動通信交換局5に対して待機メッセージ情報設定応答が転送される(図16のc8)。これを受信した関門移動通信交換局5はショートメッセージセンタ7に対して待機設定報告にて個人情報ロックメッセージが移動体通信端末(紛失)1にて受信されなかったことを通知する(図16のc9)。但し、ショートメッセージセンタ7においてはその報告を個人情報ロックメッセージ(応答)保存用メモリ領域C2に保存しないものとする。
【0126】
続いて、移動体通信端末(紛失)1の持ち主である加入者に対して個人情報ロックメッセージが待機状態になったことを認識させる方法について説明する。加入者が個人情報ロックメッセージを送信する手段として別の移動体通信端末10を利用する場合には、本来、移動体通信端末(紛失)1から送信されるはずの個人情報ロックメッセージ(応答)を受信しないことで、メッセージが待機状態になったことが認識可能と考えられる。
【0127】
一方、加入者が別の移動体通信端末10以外の通信手段を利用して個人情報ロックメッセージを送信する場合には、別途、ショートメッセージセンタ7へのアクセスによって『個人情報ロック未完了』の音声ガイダンスが通知されることから、上記と同様に、個人情報ロックメッセージの待機状態を認識することができると考えられる。
【0128】
また、個人情報ロックメッセージの再送について説明する。従来、ショートメッセージの再送は移動体通信端末(紛失)1の電源ON等による位置登録を契機に行われるため、本実施例では個人情報ロックメッセージの再送をショートメッセージの再送手順に準じて行うものとする。
【0129】
この場合、移動体通信端末(紛失)1とホームロケーションレジスタ6との間において位置登録(位置登録要求及び位置登録応答)が完了した後(図17のd1,d2)、ホームロケーションレジスタ6は位置登録を完了した移動体通信端末(紛失)1に対する待機メッセージ情報の設定有無を検索する(図17のd3)。
【0130】
待機メッセージ情報が設定されている場合には関門移動交換局5に対してショートメッセージ再送要求を送信し(図17のd4)、関門移動交換局5からショートメッセージセンタ7にショートメッセージ再送要求にて通知される(図17のd5)。
【0131】
ショートメッセージセンタ7はその要求を契機としてショートメッセージ転送要求を関門移動交換局5に通知してショートメッセージ再送が行われる(図17のd6)。尚、これ以降のシーケンスは上述した個人情報ロックメッセージ(ショートメッセージ)転送シーケンスと同様である。
【0132】
また、紛失した移動体通信端末1に対して個人情報がロックされた後、その解除方法としては、紛失した移動体通信端末1が持ち主である加入者の元に戻ってきた場合に、加入者の手によって暗証番号(152,B3)を移動体通信端末1に入力することでのみ解除可能とし、その他の通信手段を用いた遠隔操作にて個人情報ロックは一切解除できないものとすることで、個人情報の保護を一層強化することが可能と考えられる。
【0133】
本実施例では、個人情報ロックメッセージを送信するために利用する通信システムとして、移動体通信端末1側からの受信要求を必要とせず、ネットワーク側において移動体通信端末1の位置情報を把握している条件のみでメッセージを送信することができる通信システムが考えられる。そこで、このような通信システムの一例として位置登録について説明する。
【0134】
図18は本発明の一実施例による位置登録を利用した個人情報ロック動作を示すシーケンスチャートである。図7及び図18を参照して本発明の一実施例による位置登録を利用した個人情報ロック動作について説明する。
【0135】
移動体通信端末(紛失)1を紛失した加入者は予めサポートセンタ(図示せず)に問合せ、移動体通信端末1の紛失報告及び個人情報ロック要求を行う(図18のe1)。サポートセンタは加入者からの要求に応じてホームロケーションレジスタ6上の該当する移動体通信端末情報に個人情報ロック設定を行う(図18のe2)。尚、ホームロケーションレジスタ6にて管理する移動体通信端末情報としては『個人情報ロック設定』が新規に追加される必要がある。
【0136】
さらに、サポートセンタから関門移動通信交換局5を通じてホームロケーションレジスタ6に対して個人情報ロックの設定を行うためには、関門移動通信交換局5において個人情報ロック設定が認識できるような信号フォーマットを定義する必要がある。
【0137】
ホームロケーションレジスタ6に対する個人情報ロック設定の完了後、移動体通信端末(紛失)1から位置登録要求があると(図18のe3)、ホームロケーションレジスタ6は位置登録要求に応じて各種加入者情報の更新を行う。この時、該当する移動体通信端末情報内にサポートセンタからの要求による個人情報ロック設定があるかないかを確認する(図18のe4)。
【0138】
個人情報ロック設定ありの場合、ホームロケーションレジスタ6は個人情報ロック要求を含めて位置登録応答を移動体通信端末(紛失)1に送信する(図18のe5)。尚、ホームロケーションレジスタ6から送信される個人情報ロック要求込みの位置登録応答は移動体通信端末(紛失)1、基地局2、基地局制御装置3、移動通信交換局4にて認識される信号フォーマットを新規に定義する必要がある。
【0139】
図19は本発明の一実施例による個人情報ロック要求込みの位置登録応答の信号フォーマットを示す図である。図19において、個人情報ロック要求込みの位置登録応答の信号フォーマットE1は個人情報ロック要求フィールド有効フラグE2と、位置登録応答フィールドE3と、個人情報ロック要求フィールド4とからなる。
【0140】
個人情報ロック要求フィールド有効フラグE2は位置登録応答以外に個人情報ロック要求が含まれているかいないかを明確にするフラグであり、このフラグを参照することで、位置登録応答の中継点である基地局2、基地局制御装置3、移動通信交換局4のそれぞれが位置登録応答の内容に個人情報ロック要求が含まれるか否かを判断することが可能となり、個人情報ロック要求追加による位置登録応答の信号長変化に対応することができる。
【0141】
また、位置登録応答フィールドE3は通常の位置登録応答内容を設定するフィールドとして使用し、個人情報ロック要求フィールドE4は移動体通信端末(紛失)1における個人情報ロックの実行時に必要となる情報を設定するフィールドとする。この個人情報ロック要求フィールドE4に設定される内容としては、移動体通信端末識別用ID(E5)や暗証番号(E6)が考えられる。
【0142】
移動体通信端末(紛失)1では位置登録応答を受信すると、位置登録応答受信処理にて位置登録応答を処理する(図18のe6)。
【0143】
図20は図7の移動体通信端末(紛失)1による位置登録応答受信処理を示すフローチャートである。この図20を参照して移動体通信端末(紛失)1による位置登録応答受信処理について説明する。
【0144】
移動体通信端末(紛失)1は位置登録応答受信処理において、受信した位置登録応答から個人情報ロック要求フィールド有効フラグE2を判断する(図20ステップS51)。移動体通信端末(紛失)1は個人情報ロック要求が無効の場合、位置登録応答フィールドE3から位置登録応答内容を確認する(図20ステップS60)。
【0145】
一方、移動体通信端末(紛失)1は個人情報ロック要求が有効の場合、位置登録応答フィールドE3から位置登録応答内容を確認した後(図20ステップS52)、個人情報ロック要求フィールドE4内の移動体通信端末識別用ID(E5)及び暗証番号(E6)を取得し、自端末にて認識している移動体通信端末識別用ID151及び暗証番号152と合致するかどうかの判定を行う(図20ステップS53,S54)。
【0146】
移動体通信端末(紛失)1は合致しない場合、個人情報ロック不可として個人情報ロック完了報告を作成する(図20ステップS58)。一方、移動体通信端末(紛失)1は合致する場合、各種個人情報のロックを実行する(図20ステップS55)。この時、移動体通信端末(紛失)1は各種個人情報ロックが正常に終了したかどうかの判断も行う(図20ステップS56)。
【0147】
移動体通信端末(紛失)1は正常終了した場合、個人情報ロック正常終了として個人情報ロック完了報告を作成する(図20ステップS57)。一方、移動体通信端末(紛失)1は各種個人情報のうち1つでもロック不可能となるような場合等、個人情報ロック不可として個人情報ロック完了報告を作成する(図20ステップS58)。
【0148】
移動体通信端末(紛失)1は個人情報ロック完了報告の作成終了後、それをホームロケーションレジスタ6に対して送信する(図20ステップS59)。尚、この個人情報ロック完了報告送信は移動体通信端末(紛失)1からホームロケーションレジスタ6へと行われる(図18のe7)。
【0149】
個人情報ロック完了報告送信は基地局2、基地局制御装置3、移動通信交換局4を通過することから、個人情報ロック完了報告はこれらの装置にて認識される信号フォーマットとして定義される必要がある。
【0150】
図21は本発明の一実施例による個人情報ロック完了報告信号フォーマットを示す図である。図21において、個人情報ロック完了報告信号フォーマットF1は移動体通信端末識別用ID(F2)と、個人情報ロック完了報告内容(F3)とから構成されている。個人情報ロック完了報告内容(F3)には上述した個人情報ロック正常終了もしくは個人情報ロック不可のいずれかが設定されるものとする。
【0151】
ホームロケーションレジスタ6は個人情報ロック完了報告を受信すると、個人情報ロック完了報告内容を保存する(図18のe8)。この時、ホームロケーションレジスタ6はその内容の保存先として、新たに移動体通信端末情報内に『個人情報ロック結果』を追加することとする。
【0152】
一方、サポートセンタは定期的にホームロケーションレジスタ6にアクセスし、該当する移動体通信端末情報内の『個人情報ロック結果』を読出す(図18のe9)。サポートセンタは読出した『個人情報ロック結果』を判断し、加入者に対して個人情報ロックの正常終了もしくは不可を通知する(図18のe10)。上記の手順によって、位置登録を利用した移動体通信端末1の個人情報ロックが可能となる。
【0153】
本発明の一実施例では上記の処理によって個人情報のロックが行われるが、そのロックの対象として移動体通信端末1に登録される個人情報以外に移動体通信端末1の発信機能を抑制する機能もある。これは紛失した移動体通信端末1の個人情報ロックを行う際に、その移動体通信端末1から発信できる相手先電話番号を固定化するものであり、発信可能電話番号を持ち主である加入者の一般加入電話もしくは別移動体通信端末に設定することで、移動体通信端末1を拾得する第3者と持ち主との間での会話を実現することができる。
【0154】
図22は本発明の一実施例による移動体通信端末1の発信機能抑制動作を示すシーケンスチャートである。この図22を参照して本発明の一実施例による移動体通信端末1の発信機能抑制動作について説明する。
【0155】
この場合、加入者もしくはサポートセンタは移動体通信端末(紛失)1に個人情報ロック要求を送信する(図22のf1)。この時、個人情報ロック要求は個人情報ロックに必要な情報の他に発信可能電話番号をも含むものとする。
【0156】
移動体通信端末(紛失)1は個人情報ロック要求を受信すると、受信した情報を基に個人情報ロックを実行する(図22のf2)。また、移動体通信端末(紛失)1は発信可能電話番号を判断してその電話番号以外への発信を不可能とするための発信機能制限を実行する(図22のf3)。その後に、移動体通信端末(紛失)1は個人情報ロックと発信機能制限とを終了した段階にて、個人情報ロック応答を加入者もしくはサポートセンタに対して送信する(図22のf4)。
【0157】
これによって、移動体通信端末(紛失)1では拾得する第3者の個人情報閲覧不可及び発信の乱用防止を実現することができる。また、紛失した移動体通信端末1側から持ち主である加入者側という新たな発信経路を実現することができ、紛失した移動体通信端末1が持ち主の手元に戻る可能性が増加すると考えられる。
【0158】
このように、本実施例では、移動体通信端末1の紛失時に、移動体通信端末1が基地局2のサービスエリア200の圏外にあっても、移動体通信端末1の個人情報の防御を可能とし、個人情報流出及び悪用といった問題の軽減を図ることができるとともに、サービスエリア200の圏内にある移動体通信端末1側からの受信要求を必要とせず、ネットワーク側において移動体通信端末1の位置情報を把握している条件のみでメッセージを送信することができる。
【0159】
本実施例では、上記のショートメッセージサービスを利用してリモートから移動体通信端末1内部の個人情報をロックするメッセージを送信することによって、近年、問題となっている移動体通信端末1に登録される各種個人情報の第3者による閲覧及び流出を防止することができる。
【0160】
【発明の効果】
以上説明したように本発明は、上記のような構成及び動作とすることで、紛失した端末が通話エリアの圏外にある場合でも個人情報の防御を可能とし、個人情報流出及び悪用といった問題の軽減を図ることができるという効果が得られる。
【図面の簡単な説明】
【図1】本発明の一実施例による移動通信システムの構成を示すブロック図である。
【図2】図1の移動体通信端末の構成を示すブロック図である。
【図3】本発明の一実施例による個人情報ロック及び解除に関する移動体通信端末の状態遷移を示す図である。
【図4】図1の移動体通信端末の位置登録要求タイムアウト(NG)処理を示すフローチャートである。
【図5】本発明の一実施例による位置登録応答受信処理を示すフローチャートである。
【図6】本発明の一実施例による移動通信システムの構成を示すブロック図である。
【図7】本発明の一実施例による移動通信システムにおけるショートメッセージサービスのネットワーク概要を示す図である。
【図8】本発明の一実施例による個人情報ロックメッセージの構成例を示す図である。
【図9】図7のショートメッセージセンタのメモリ領域の構成例を示す図である。
【図10】本発明の一実施例による移動通信システムの動作を示すシーケンスチャートである。
【図11】図7の移動体通信端末のショートメッセージ受信処理を示すフローチャートである。
【図12】図7のショートメッセージセンタへの個人情報ロックメッセージの構成例を示す図である。
【図13】図7のショートメッセージセンタの個人情報ロックメッセージ(応答)受信処理を示すフローチャートである。
【図14】図7のショートメッセージセンタに対する個人情報ロックメッセージ(応答)Dの確認動作を示すシーケンスチャートである。
【図15】図7のショートメッセージセンタによる検索処理を示すフローチャートである。
【図16】本発明の一実施例による個人情報ロックメッセージ受信不可時の待機メッセージ設定動作を示すシーケンスチャートである。
【図17】本発明の一実施例による個人情報ロックメッセージ再送動作を示すシーケンスチャートである。
【図18】本発明の一実施例による位置登録を利用した個人情報ロック動作を示すシーケンスチャートである。
【図19】本発明の一実施例による個人情報ロック要求込みの位置登録応答の信号フォーマットを示す図である。
【図20】図7の移動体通信端末(紛失)による位置登録応答受信処理を示すフローチャートである。
【図21】本発明の一実施例による個人情報ロック完了報告信号フォーマットを示す図である。
【図22】本発明の一実施例による移動体通信端末の発信機能抑制動作を示すシーケンスチャートである。
【符号の説明】
1,10 移動体通信端末
2 基地局
3 基地局制御装置
4 移動通信交換局
5 関門移動通信交換局
6 ホームロケーションレジスタ
7 ショートメッセージセンタ
8 一般加入電話及び公衆電話
9 PC
11 アンテナ11
12 無線回路部
13 信号処理部
14 制御回路部
15 記憶回路部
15a 移動体通信端末アプリケーション部
15b 移動体通信端末メモリ部
16 位置登録手段
17 位置登録タイムアウトカウンタ
18 個人情報ロック部
19 送受話器
20 表示部
21 キー操作部
100 ネットワーク
151 移動体通信端末識別用ID
152 暗証番号
153 通常ショートメッセージ受信(保存)用メモリ領域
154 個人情報ロックメッセージ受信(保存)用メモリ領域
200 サービスエリア
300 固定網
400 移動網[0001]
TECHNICAL FIELD OF THE INVENTION
The present invention relates to a mobile communication system, a mobile communication terminal, a method for locking personal information used in the mobile communication terminal, and a program therefor, and more particularly, to prevention of leakage of personal information mounted on the mobile communication terminal.
[0002]
[Prior art]
As of the end of November 2002, the number of mobile phone subscribers in Japan has exceeded 72.8 million due to the explosion of mobile phone subscribers that began in the 1990s.
[0003]
The explosive spread of such mobile phones is considered to be primarily due to the enhancement of service content that supports not only voice calls but also various data communications. It is thought that the enhancement of the function of the mobile phone (hereinafter, referred to as a mobile communication terminal) used by the user has also contributed to this.
[0004]
That is, enhancement of the functions of the mobile communication terminal itself refers to enhancement of various additional functions (hereinafter, referred to as tools) effective for the subscriber itself other than the main service functions such as voice communication and data communication.
[0005]
At present, examples of tools added to mobile communication terminals include a telephone directory management tool, a mail address management tool, a schedule management tool, a transmission / reception mail management tool, and the like. It is thought that the majority of the information is very important information that is never allowed to be disclosed to third parties, which is called information.
[0006]
Here, considering the loss of mobile communication terminals, various mobile communication providers have been working to reduce the loss of a mobile communication terminal when a subscriber loses the mobile communication terminal. A support service that stops the service function is set.
[0007]
In addition, the mobile communication terminal has a built-in function to restrict browsing of personal information (hereinafter referred to as a secret mode), and a secret mode is set for various types of personal information registered in advance by the subscriber in the mobile communication terminal. By doing so, it is possible to prevent important personal information handled by the tool at the time of loss from being viewed by a third party who has found it.
[0008]
By the way, for the personal information for which the secret mode has been set, the secret mode release setting is naturally required at the time of browsing. Here, as an example, a telephone directory management tool that manages a telephone number based on two pieces of information, a name and a telephone number, will be described.
[0009]
When a subscriber talks to any party, the phone number can be obtained by searching for the name of the other party registered in the phonebook management tool. When the mode has been set, the secret number is input to release the secret mode, so that the telephone number can be obtained for the first time.
[0010]
In other words, when a subscriber tries to make a call, if the secret mode is set in the phonebook management tool, a procedure of releasing the secret mode setting as a procedure until the call starts is necessary, which complicates the call procedure. As a matter of fact, it is recognized that the secret mode setting itself is very troublesome for a subscriber using a mobile communication terminal.
[0011]
Further, at present, it is normal to set the secret mode for each telephone number. This means that each of the telephone numbers registered in the telephone directory management tool can be set in a secret mode with a different personal identification number, which is considered to have a meaning of improving security.
[0012]
However, conversely, the more phone numbers to be registered in the phonebook management tool, the longer it takes to set up the phone number. Even more, if different passwords are used for each registered phone number, The possibility that the secret mode cannot be canceled due to forgetting of the personal identification number increases. For this reason, it is said that subscribers who use the secret mode setting have relatively the same password in all cases.
[0013]
In addition to the above secret mode, a method has been proposed in which a subscriber transmits a command or the like to a lost mobile communication terminal using another telephone or terminal, etc., thereby prohibiting key operations and browsing of internal information. (For example, see
[0014]
[Patent Document 1]
JP-A-9-182158 (
[Patent Document 2]
JP-A-2000-151798 (
[Patent Document 3]
JP-A-2000-253457 (
[Patent Document 4]
JP-A-2001-230858 (
[Patent Document 5]
JP-A-2002-77372 (
[Patent Document 6]
JP-A-2002-77433 (
[Patent Document 7]
JP 2002-218048 A (
[0015]
[Problems to be solved by the invention]
In the above-described conventional method for preventing leakage of personal information, when setting the secret mode as described above, it is considered that both the setting procedure and the release procedure at the time of browsing require time and effort. Therefore, at present, the majority of the subscribers have not set the secret mode for personal information, and when a mobile communication terminal is lost, a third party who has found it can easily view important personal information. It has become.
[0016]
For these reasons, in recent years, mobile communication terminals have an increasing number of outflows of personal information due to loss of the terminals and crimes caused by abuse, and are beginning to be recognized as a serious problem.
[0017]
As described above, considering that the usage rate of the secret mode setting is extremely low and the crime related to the loss of the mobile communication terminal is increasing, the personal information handled by the mobile communication terminal has been lost. We need to be able to defend even later.
[0018]
Further, even if the techniques described in
[0019]
Accordingly, an object of the present invention is to solve the above-mentioned problems, to enable protection of personal information even when a lost terminal is out of the service area, and to reduce problems such as leakage and misuse of personal information. It is an object of the present invention to provide a communication system, a mobile communication terminal, a personal information locking method used for the same, and a program therefor.
[0020]
[Means for Solving the Problems]
A mobile communication system according to the present invention is a mobile communication system including a mobile communication terminal that periodically transmits a position registration request to a base station and stores personal information of a user,
The mobile communication terminal includes means for transitioning to a personal information protection mode in which at least the reading and writing of the personal information is suppressed when the position registration request to the base station is continuously unsuccessful for a predetermined number of times. I have.
[0021]
A mobile communication terminal according to the present invention is a mobile communication terminal that periodically transmits a position registration request to a base station and stores personal information of a user,
When the position registration request to the base station fails consecutively for a predetermined number of times, the mode is changed to a personal information protection mode for suppressing at least reading and writing of the personal information.
[0022]
A personal information locking method according to the present invention is a personal information locking method for a mobile communication system including a mobile communication terminal that periodically transmits a position registration request to a base station and stores a user's personal information, Detecting, on the mobile communication terminal side, that the position registration request to the base station has been continuously unsuccessfully performed a predetermined number of times, and the position registration request has been continuously unsuccessfully performed. And a step of transiting to a personal information protection mode in which reading and writing of the personal information is suppressed at least when this is detected.
[0023]
The personal information locking method program according to the present invention is a personal information locking method program for a mobile communication system including a mobile communication terminal that periodically transmits a position registration request to a base station and stores a user's personal information. The mobile communication terminal-side computer has a process of detecting that the location registration request to the base station has been continuously unsuccessfully performed a predetermined number of times. And a process for transiting to a personal information protection mode in which reading and writing of the personal information is suppressed at least when it is detected that the personal information is unsuccessful.
[0024]
That is, the mobile communication system according to the present invention can be used for various types of personal information registered in the mobile communication terminal when the mobile communication terminal is lost and the terminal is out of the service area (communication area) of the base station. Has a function of preventing a third party who has found the terminal from easily viewing or abusing the terminal.
[0025]
Further, in the mobile communication system of the present invention, when the lost mobile communication terminal is within the service area of the base station, control information (hereinafter referred to as a personal information lock message) is transmitted to the terminal remotely. Thus, various personal information registered in the mobile communication terminal is forcibly locked.
[0026]
Further, in the mobile communication system of the present invention, the method of transmitting the personal information lock message to the lost mobile communication terminal does not require a reception request from the mobile communication terminal side, and the position information of the mobile communication terminal is not required. Is characterized by using a system capable of transmitting a message only under the condition that the network side knows the message.
[0027]
More specifically, the mobile communication system of the present invention comprises a mobile communication terminal, a base station, a base station controller, a mobile communication switching center, a gateway mobile communication switching center, and a home location register. Have been.
[0028]
The home location register is a device that manages subscriber data such as location information. Here, in the present invention, when the mobile communication terminal of a specific subscriber is lost, various personal information of the owner who is the owner is registered in the mobile communication terminal in a lost state, and such information is registered. There is a risk of being viewed by a third party who has found the terminal.
[0029]
In order to avoid such a risk, the owner, the owner, remotely transmits a personal information lock message to the lost mobile communication terminal. The mobile communication terminal receives the personal information lock message under the condition that the home location register knows the location information. At this time, whether or not the message can be received does not depend on the intention of the third party who has found the message, but only depends on whether or not the location information of the mobile communication terminal can be grasped by the home location register. .
[0030]
When the mobile communication terminal receives the personal information lock message, the content of the message is determined by the application program, and various types of personal information registered in the mobile communication terminal are locked. This makes it impossible to view the personal information of the found third party.
[0031]
However, when the mobile communication terminal is out of the service area of the base station at the time of loss, the location registration request from the mobile communication terminal to the home location register does not arrive, and the lost mobile communication terminal is displayed on the home location register. Since the location area cannot be grasped, the function of protecting personal information remotely cannot be used.
[0032]
Therefore, in the present invention, even when the lost mobile communication terminal is in an environment outside the service area of the base station, a method for protecting personal information in the lost mobile communication terminal is defined in advance. The mobile communication terminal is provided with a function of automatically transiting to the personal information protection mode when a position registration request to the base station fails unsuccessfully consecutively.
[0033]
As a result, according to the present invention, even when the lost terminal is out of the service area of the base station, it is possible to protect personal information and reduce problems such as leakage and misuse of personal information.
[0034]
As described above, according to the present invention, even if a secret mode setting for disabling third-party browsing of various personal information has not been made in advance, when the personal information is lost, the personal information can be remotely transmitted to the mobile communication terminal. Since a lock message can be sent to prevent browsing of various personal information, it is possible to prevent a third party who has found the terminal from browsing the personal information of the owner and leaking or misusing the personal information. Becomes possible.
[0035]
In other words, the present invention proposes a new system that locks personal information registered remotely to a lost mobile communication terminal, thereby enabling protection of personal information even after the mobile terminal is lost. Problems such as leakage and misuse of personal information can be reduced.
[0036]
BEST MODE FOR CARRYING OUT THE INVENTION
Next, an embodiment of the present invention will be described with reference to the drawings. FIG. 1 is a block diagram showing a configuration of a mobile communication system according to one embodiment of the present invention. In FIG. 1, a mobile communication system according to one embodiment of the present invention includes a
[0037]
Here, in this embodiment, the
[0038]
In order to avoid such a danger, the owner of the owner transmits a personal information lock message to the lost
[0039]
When the
[0040]
Therefore, the location information of the
[0041]
Therefore, in the present embodiment, as a method for protecting personal information in the lost
[0042]
The above-mentioned location registration request is periodically transmitted from the
[0043]
Therefore, in
[0044]
FIG. 2 is a block diagram showing a configuration of the
[0045]
The
[0046]
The location registration unit 16 periodically transmits a location registration request to the
[0047]
When the
[0048]
In the
[0049]
FIG. 3 is a diagram showing a state transition of the
[0050]
First, it is assumed that the
[0051]
The
[0052]
On the other hand, when the
[0053]
If this location registration request timeout (NG) occurs continuously and the number of times exceeds a predetermined number of allowable location registration request timeouts (NG) (304 in FIG. 3), the
[0054]
When the
[0055]
When the
[0056]
On the other hand, the
[0057]
When the
[0058]
As described above, in the present embodiment, the four modes in which the state transitions according to the location of the mobile communication terminal 1 (whether or not within the
[0059]
FIG. 4 is a flowchart showing a location registration request timeout (NG) process of the
[0060]
When performing the location registration request time-out (NG) process, the
[0061]
On the other hand, when the personal information in the
[0062]
If the value set in the previous confirmation of the location registration request result is OK, the
[0063]
If the previous location registration request result is an initial value or a timeout (NG), the
[0064]
Next, the
[0065]
If the count value of the location
[0066]
When the count value of the location
[0067]
FIG. 5 is a flowchart showing a location registration response receiving process according to one embodiment of the present invention. With reference to FIGS. 1 to 3 and FIG. 5, a description will be given of a process required when a position registration request is successful in one embodiment of the present invention. Note that the processing illustrated in FIG. 5 is realized by the
[0068]
In the location registration response receiving process, the
[0069]
If the location registration request result (previous time) is set to the initial value or OK, the
[0070]
On the other hand, if the location registration request result (previous) is time-out (NG), the
[0071]
This is to lock the personal information in the
[0072]
As described above, in the present embodiment, when the
[0073]
Next, a personal information lock process by the personal
[0074]
FIG. 6 is a block diagram showing the configuration of the mobile communication system according to one embodiment of the present invention. 6, the configuration is the same as that of the mobile communication system shown in FIG. 1 except that the
[0075]
Here, in the present embodiment, a case where the
[0076]
In order to avoid such a danger, the subscriber as the owner transmits a personal information lock message 101 to the lost
[0077]
The
[0078]
As described above, in the present embodiment, even if the secret mode setting for disabling the third party from viewing various types of personal information in the
[0079]
In the present embodiment, as a method of transmitting the personal information lock message 101 to the
[0080]
FIG. 7 is a diagram showing a network overview of a short message service in a mobile communication system according to an embodiment of the present invention. In FIG. 7, a mobile communication terminal identification ID 151 and a
[0081]
The mobile communication terminal memory unit (hereinafter referred to as a memory unit) 15b of the
[0082]
In the conventional short message service, the service is realized by relaying, transferring, and waiting the short message in a server called a
[0083]
In this embodiment, the subscriber who has lost the
[0084]
FIG. 8 is a diagram showing a configuration example of a personal information lock message according to an embodiment of the present invention. In FIG. 8, a personal information lock message B is a personal information lock message 101 transmitted in a short message format, and includes a personal information lock message identifier (B1), a mobile communication terminal identification ID (B2), and a personal identification number. (B3) and a personal information lock message (response) destination telephone number (B4).
[0085]
The personal information lock message identifier (B1) is for identifying that the content is the personal information lock message B when the lost
[0086]
The mobile communication terminal identification ID (B2) and the password (B3) have the same values as the mobile communication terminal identification ID 151 and the
[0087]
Further, the personal information lock message (response) transmission destination telephone number (B4) is an area for describing a telephone number to which a response of the personal information lock status in the
[0088]
FIG. 9 is a diagram showing a configuration example of a memory area of the
[0089]
The response to the personal information lock message B stored in the short message center memory area C is to be notified in a voice guidance format in response to access from the subscriber.
[0090]
FIG. 10 is a sequence chart showing an operation of the mobile communication system according to one embodiment of the present invention, FIG. 11 is a flowchart showing a short message receiving process of the
[0091]
The subscriber who owns the lost
[0092]
At this time, if the transmitting means is another
[0093]
Upon receiving the short message, the
[0094]
In response to this request, the
[0095]
The short message received by the mobile
[0096]
The mobile communication terminal (lost) 1 transmits an ACK to the mobile
[0097]
The application unit 15a of the mobile communication terminal (lost) 1 determines the message identifier of the received short message (step S21 in FIG. 11), and when the message identifier is other than the personal information lock message identifier (B1), the normal operation of the memory unit 15b is performed. The short message is stored in the short message receiving (saving) memory area 153 (step S30 in FIG. 11), and the process is terminated.
[0098]
On the other hand, when the message identifier is the personal information lock message identifier (B1), the application unit 15a recognizes the mobile communication terminal identification ID (B2) and the personal identification number (B3) by the mobile communication terminal (lost) 1. It is determined whether the ID matches the mobile communication terminal identification ID 151 and the password 152 (steps S22 and S23 in FIG. 11).
[0099]
If they do not match, the application unit 15a creates a short message as a response indicating that personal information cannot be locked (step S28 in FIG. 11). If they match, the application unit 15a saves the short message in the memory area 154 for receiving (storing) the personal information lock message (step S24 in FIG. 11), locks all registered personal information, and moves the personal information. It is assumed that any personal information display request from outside the
[0100]
At this time, the application unit 15a determines whether or not various personal information locks have been completed normally (step S26 in FIG. 11). When the personal information lock has been completed normally, a short message is created as a response to the personal information lock normal completion (FIG. 11). Step S27).
[0101]
On the other hand, the application unit 15a creates a short message as a response indicating that personal information cannot be locked, for example, in a case where even one of various types of personal information cannot be locked (step S28 in FIG. 11). FIG. 12 shows an example of a short message of the created personal information lock message (response).
[0102]
In FIG. 12, a personal information lock message (response) D is composed of a personal information lock message identifier D1, a password D2, and a personal information lock result D3. OK is set, and NG is set when the personal information cannot be locked.
[0103]
After the completion of the message, the mobile communication terminal (lost) 1 transmits a short message of the personal information lock message (response) D based on the personal information lock message (response) destination telephone number (B4) (step S29 in FIG. 11). ).
[0104]
This personal information lock message (response) is transmitted from the mobile communication terminal (lost) 1 to the mobile
[0105]
Upon receiving this, the gateway mobile
[0106]
That is, the
[0107]
This personal information lock message (response) D is transferred from the
[0108]
By the way, the personal information lock message (response) D can be received in the form of a short message only when the mobile communication terminal is used as the communication means. However, when the communication means is the
[0109]
However, when the personal information lock message is transmitted from the
[0110]
Therefore, a system is considered in which the
[0111]
FIG. 14 is a sequence chart showing a confirmation operation of the personal information lock message (response) D to the
[0112]
The subscriber accesses the
[0113]
After receiving the mobile communication terminal identification ID input response, the
[0114]
The
[0115]
If there is no personal information lock message (response) matching the mobile communication terminal identification ID and the password input from the subscriber (step S42 in FIG. 15), the
[0116]
On the other hand, if there is a personal information lock message (response) that matches the mobile communication terminal identification ID and the password entered by the subscriber (step S42 in FIG. 15), the
[0117]
The
[0118]
By realizing the above configuration and operation in the
[0119]
When the mobile communication terminal (lost) 1 is powered off or the like, its location information becomes unknown, and the routing information managed by the
[0120]
First, a method for detecting on the network side that the lost
[0121]
FIG. 16 is a sequence chart showing a standby message setting operation when a personal information lock message cannot be received according to an embodiment of the present invention, and FIG. 17 shows a personal information lock message (short message) resending operation according to an embodiment of the present invention. It is a sequence chart shown. The operation in the case where the lost
[0122]
In response to a request from the
[0123]
Here, the short message is transferred from the mobile
[0124]
At this time, the gateway mobile
[0125]
After the setting is completed, a standby message information setting response is transferred from the
[0126]
Next, a method of making the subscriber who is the owner of the mobile communication terminal (lost) 1 recognize that the personal information lock message is in the standby state will be described. When the subscriber uses another
[0127]
On the other hand, when the subscriber transmits a personal information lock message using a communication means other than another
[0128]
Further, retransmission of the personal information lock message will be described. Conventionally, the retransmission of the short message is performed upon the position registration by turning on the power of the mobile communication terminal (lost) 1 or the like. In this embodiment, the retransmission of the personal information lock message is performed according to the retransmission procedure of the short message. And
[0129]
In this case, after the location registration (location registration request and location registration response) between the mobile communication terminal (lost) 1 and the
[0130]
If the standby message information is set, a short message retransmission request is transmitted to the gateway mobile switching center 5 (d4 in FIG. 17), and the short message retransmission request is sent from the gateway
[0131]
The
[0132]
Further, after the personal information is locked for the lost
[0133]
In the present embodiment, as a communication system used for transmitting a personal information lock message, a reception request from the
[0134]
FIG. 18 is a sequence chart showing a personal information lock operation using location registration according to one embodiment of the present invention. A personal information locking operation using location registration according to an embodiment of the present invention will be described with reference to FIGS.
[0135]
The subscriber who has lost the mobile communication terminal (lost) 1 inquires in advance to a support center (not shown), and reports the loss of the
[0136]
Further, in order to set the personal information lock from the support center to the
[0137]
After the personal information lock setting for the
[0138]
When the personal information lock is set, the
[0139]
FIG. 19 is a diagram showing a signal format of a position registration response including a personal information lock request according to one embodiment of the present invention. In FIG. 19, the signal format E1 of the position registration response including the personal information lock request includes a personal information lock request field valid flag E2, a position registration response field E3, and a personal information
[0140]
The personal information lock request field valid flag E2 is a flag for clarifying whether or not a personal information lock request is included in addition to the location registration response. By referring to this flag, the base station which is a relay point of the location registration response is referred to. Each of the
[0141]
The location registration response field E3 is used as a field for setting the content of a normal location registration response, and the personal information lock request field E4 is used to set information required when personal information lock is executed in the mobile communication terminal (lost) 1. Field. The contents set in the personal information lock request field E4 may be a mobile communication terminal identification ID (E5) or a password (E6).
[0142]
Upon receiving the location registration response, the mobile communication terminal (lost) 1 processes the location registration response in the location registration response receiving process (e6 in FIG. 18).
[0143]
FIG. 20 is a flowchart showing a location registration response receiving process by the mobile communication terminal (lost) 1 of FIG. With reference to FIG. 20, the location registration response receiving processing by mobile communication terminal (lost) 1 will be described.
[0144]
The mobile communication terminal (lost) 1 determines the personal information lock request field valid flag E2 from the received position registration response in the position registration response receiving process (step S51 in FIG. 20). If the personal information lock request is invalid, the mobile communication terminal (lost) 1 checks the content of the location registration response from the location registration response field E3 (step S60 in FIG. 20).
[0145]
On the other hand, when the personal information lock request is valid, the mobile communication terminal (lost) 1 checks the contents of the position registration response from the position registration response field E3 (step S52 in FIG. 20), and then moves in the personal information lock request field E4. The mobile communication terminal identification ID (E5) and the personal identification number (E6) are obtained, and it is determined whether or not they match the mobile communication terminal identification ID 151 and the
[0146]
If the mobile communication terminal (lost) 1 does not match, the personal information lock completion report is created with the personal information lock disabled (step S58 in FIG. 20). On the other hand, if the mobile communication terminal (lost) 1 matches, the personal communication terminal locks various personal information (step S55 in FIG. 20). At this time, the mobile communication terminal (lost) 1 also determines whether or not various personal information locks have been normally completed (step S56 in FIG. 20).
[0147]
When the mobile communication terminal (lost) 1 ends normally, the personal information lock completion report is created as the personal information lock normal end (step S57 in FIG. 20). On the other hand, when the mobile communication terminal (lost) 1 cannot lock any one of the various types of personal information, the personal information lock completion report is created (step S58 in FIG. 20).
[0148]
After completing the creation of the personal information lock completion report, the mobile communication terminal (lost) 1 transmits it to the home location register 6 (step S59 in FIG. 20). The personal information lock completion report is transmitted from the mobile communication terminal (lost) 1 to the home location register 6 (e7 in FIG. 18).
[0149]
Since the transmission of the personal information lock completion report passes through the
[0150]
FIG. 21 is a diagram illustrating a personal information lock completion report signal format according to an embodiment of the present invention. In FIG. 21, the personal information lock completion report signal format F1 is composed of a mobile communication terminal identification ID (F2) and a personal information lock completion report content (F3). In the personal information lock completion report content (F3), either the above-described normal termination of the personal information lock or the inability to lock the personal information is set.
[0151]
Upon receiving the personal information lock completion report, the
[0152]
On the other hand, the support center periodically accesses the
[0153]
In one embodiment of the present invention, the personal information is locked by the above processing, but a function of suppressing the transmission function of the
[0154]
FIG. 22 is a sequence chart showing the calling function suppressing operation of the
[0155]
In this case, the subscriber or the support center transmits a personal information lock request to the mobile communication terminal (lost) 1 (f1 in FIG. 22). At this time, the personal information lock request includes a callable telephone number in addition to the information necessary for the personal information lock.
[0156]
Upon receiving the personal information lock request, the mobile communication terminal (lost) 1 executes the personal information lock based on the received information (f2 in FIG. 22). In addition, the mobile communication terminal (lost) 1 determines a telephone number that can be called and executes a calling function restriction to disable calling other than the telephone number (f3 in FIG. 22). Thereafter, the mobile communication terminal (lost) 1 transmits a personal information lock response to the subscriber or the support center when the personal information lock and the transmission function restriction are completed (f4 in FIG. 22).
[0157]
As a result, the mobile communication terminal (lost) 1 can prevent a third party who can find the personal information from being browsed and prevent abuse of transmission. Further, it is possible to realize a new transmission path from the lost
[0158]
As described above, in the present embodiment, when the
[0159]
In the present embodiment, by transmitting a message for locking personal information inside the
[0160]
【The invention's effect】
As described above, the present invention adopts the above-described configuration and operation, thereby enabling protection of personal information even when a lost terminal is out of the service area, and reducing problems such as personal information leakage and misuse. Is obtained.
[Brief description of the drawings]
FIG. 1 is a block diagram showing a configuration of a mobile communication system according to one embodiment of the present invention.
FIG. 2 is a block diagram showing a configuration of the mobile communication terminal of FIG.
FIG. 3 is a diagram illustrating a state transition of a mobile communication terminal regarding personal information lock and release according to an embodiment of the present invention.
FIG. 4 is a flowchart showing a location registration request timeout (NG) process of the mobile communication terminal of FIG. 1;
FIG. 5 is a flowchart showing a location registration response receiving process according to one embodiment of the present invention.
FIG. 6 is a block diagram illustrating a configuration of a mobile communication system according to an embodiment of the present invention.
FIG. 7 is a diagram showing a network overview of a short message service in a mobile communication system according to an embodiment of the present invention.
FIG. 8 is a diagram showing a configuration example of a personal information lock message according to an embodiment of the present invention.
9 is a diagram illustrating a configuration example of a memory area of the short message center in FIG. 7;
FIG. 10 is a sequence chart showing an operation of the mobile communication system according to one embodiment of the present invention.
FIG. 11 is a flowchart showing a short message receiving process of the mobile communication terminal of FIG. 7;
12 is a diagram illustrating a configuration example of a personal information lock message to the short message center in FIG. 7;
FIG. 13 is a flowchart showing a personal information lock message (response) receiving process of the short message center of FIG. 7;
14 is a sequence chart showing an operation of confirming a personal information lock message (response) D to the short message center of FIG. 7;
FIG. 15 is a flowchart showing a search process by the short message center of FIG. 7;
FIG. 16 is a sequence chart showing a standby message setting operation when a personal information lock message cannot be received according to an embodiment of the present invention.
FIG. 17 is a sequence chart showing a personal information lock message retransmission operation according to an embodiment of the present invention.
FIG. 18 is a sequence chart showing a personal information lock operation using location registration according to one embodiment of the present invention.
FIG. 19 is a diagram showing a signal format of a location registration response including a personal information lock request according to an embodiment of the present invention.
20 is a flowchart showing a location registration response receiving process by the mobile communication terminal (lost) in FIG. 7;
FIG. 21 is a diagram illustrating a personal information lock completion report signal format according to an embodiment of the present invention.
FIG. 22 is a sequence chart showing a calling function suppressing operation of the mobile communication terminal according to one embodiment of the present invention.
[Explanation of symbols]
1,10 mobile communication terminals
2 base stations
3 Base station controller
4 Mobile switching center
5 Kanmon Mobile Switching Center
6 home location register
7 Short Message Center
8 General subscriber telephones and public telephones
9 PC
11
12 Radio circuit section
13 signal processing unit
14 Control circuit section
15 Memory circuit section
15a Mobile communication terminal application section
15b Mobile communication terminal memory unit
16 location registration means
17 Location registration timeout counter
18 Personal Information Lock Department
19 Handset
20 Display
21 Key operation section
100 networks
151 Mobile communication terminal identification ID
152 PIN
153 Memory area for normal short message reception (save)
154 Memory area for receiving (saving) personal information lock message
200 Service Area
300 fixed net
400 mobile network
Claims (10)
前記基地局への位置登録要求が予め規定された回数だけ連続して不成功となった時に少なくとも前記個人情報の読み書きを抑止する個人情報保護モードへ遷移する手段を前記移動体通信端末に有することを特徴とする移動通信システム。A mobile communication system including a mobile communication terminal that periodically transmits a position registration request to a base station and stores personal information of a user,
The mobile communication terminal having means for transitioning to a personal information protection mode for suppressing at least reading and writing of the personal information when the position registration request to the base station is continuously unsuccessful for a predetermined number of times. A mobile communication system characterized by the above-mentioned.
前記基地局への位置登録要求が予め規定された回数だけ連続して不成功となった時に少なくとも前記個人情報の読み書きを抑止する個人情報保護モードへ遷移する手段を有することを特徴とする移動体通信端末。A mobile communication terminal that periodically transmits a location registration request to a base station and stores personal information of a user,
A mobile unit characterized by comprising: means for transitioning to a personal information protection mode in which at least the reading and writing of the personal information is suppressed when the position registration request to the base station is continuously unsuccessful a predetermined number of times. Communication terminal.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2003142799A JP2004349902A (en) | 2003-05-21 | 2003-05-21 | Mobile communication system, mobile communication terminal, personal information lock method used therefor and its program |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2003142799A JP2004349902A (en) | 2003-05-21 | 2003-05-21 | Mobile communication system, mobile communication terminal, personal information lock method used therefor and its program |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| JP2004349902A true JP2004349902A (en) | 2004-12-09 |
Family
ID=33530760
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2003142799A Pending JP2004349902A (en) | 2003-05-21 | 2003-05-21 | Mobile communication system, mobile communication terminal, personal information lock method used therefor and its program |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JP2004349902A (en) |
Cited By (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2006174158A (en) * | 2004-12-16 | 2006-06-29 | Vodafone Kk | Data update method, management server, and mobile communication terminal |
| JP2006279770A (en) * | 2005-03-30 | 2006-10-12 | Nec Corp | Portable communication terminal, method for controlling the same and illegal terminal use prevention system |
| JP2006309489A (en) * | 2005-04-28 | 2006-11-09 | Nec Corp | System, server and terminal for settlement, value management unit, mobile communication terminal, settlement method and program |
| JP2007312218A (en) * | 2006-05-19 | 2007-11-29 | Willcom Inc | Wireless communication method, program, and wireless communication system for controlling terminal |
| JP2008085728A (en) * | 2006-09-28 | 2008-04-10 | Nec Corp | Portable wireless terminal and key lock setting releasing method |
| JP2008092294A (en) * | 2006-10-02 | 2008-04-17 | Ntt Docomo Inc | Mobile communication network system and mobile terminal device locking method |
| JP2009212886A (en) * | 2008-03-05 | 2009-09-17 | Nec Personal Products Co Ltd | Portable information terminal and method for controlling operation of the portable information terminal |
| JP2009232255A (en) * | 2008-03-24 | 2009-10-08 | Toshiba Corp | Portable communication terminal |
| JP2011139484A (en) * | 2005-08-12 | 2011-07-14 | Sii Ido Tsushin Kk | Remote locking system and communication terminal |
| CN102597960A (en) * | 2009-12-31 | 2012-07-18 | 富士通株式会社 | data protection device |
| US8326264B2 (en) | 2006-09-15 | 2012-12-04 | Ntt Docomo, Inc. | Mobile communication network system and locking method of a mobile terminal apparatus |
| KR101247654B1 (en) * | 2005-05-25 | 2013-04-01 | 훼리카네트워크스 카부시키가이샤 | Contactless IC chip, portable terminal, information processing method, and program |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001309431A (en) * | 2000-04-19 | 2001-11-02 | Sony Corp | Method of protecting data recorded in mobile terminal and mobile terminal data protection system |
| JP2002009934A (en) * | 2000-06-22 | 2002-01-11 | Toshiba Corp | Communication terminal and recording medium |
| JP2002142247A (en) * | 2000-11-02 | 2002-05-17 | Hitachi Ltd | Location registration control method and mobile station apparatus using the same |
-
2003
- 2003-05-21 JP JP2003142799A patent/JP2004349902A/en active Pending
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001309431A (en) * | 2000-04-19 | 2001-11-02 | Sony Corp | Method of protecting data recorded in mobile terminal and mobile terminal data protection system |
| JP2002009934A (en) * | 2000-06-22 | 2002-01-11 | Toshiba Corp | Communication terminal and recording medium |
| JP2002142247A (en) * | 2000-11-02 | 2002-05-17 | Hitachi Ltd | Location registration control method and mobile station apparatus using the same |
Cited By (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2006174158A (en) * | 2004-12-16 | 2006-06-29 | Vodafone Kk | Data update method, management server, and mobile communication terminal |
| JP2006279770A (en) * | 2005-03-30 | 2006-10-12 | Nec Corp | Portable communication terminal, method for controlling the same and illegal terminal use prevention system |
| JP2006309489A (en) * | 2005-04-28 | 2006-11-09 | Nec Corp | System, server and terminal for settlement, value management unit, mobile communication terminal, settlement method and program |
| KR101247654B1 (en) * | 2005-05-25 | 2013-04-01 | 훼리카네트워크스 카부시키가이샤 | Contactless IC chip, portable terminal, information processing method, and program |
| JP2011139484A (en) * | 2005-08-12 | 2011-07-14 | Sii Ido Tsushin Kk | Remote locking system and communication terminal |
| JP2007312218A (en) * | 2006-05-19 | 2007-11-29 | Willcom Inc | Wireless communication method, program, and wireless communication system for controlling terminal |
| US8326264B2 (en) | 2006-09-15 | 2012-12-04 | Ntt Docomo, Inc. | Mobile communication network system and locking method of a mobile terminal apparatus |
| JP2008085728A (en) * | 2006-09-28 | 2008-04-10 | Nec Corp | Portable wireless terminal and key lock setting releasing method |
| JP2008092294A (en) * | 2006-10-02 | 2008-04-17 | Ntt Docomo Inc | Mobile communication network system and mobile terminal device locking method |
| JP2009212886A (en) * | 2008-03-05 | 2009-09-17 | Nec Personal Products Co Ltd | Portable information terminal and method for controlling operation of the portable information terminal |
| JP2009232255A (en) * | 2008-03-24 | 2009-10-08 | Toshiba Corp | Portable communication terminal |
| CN102597960A (en) * | 2009-12-31 | 2012-07-18 | 富士通株式会社 | data protection device |
| JP2013516676A (en) * | 2009-12-31 | 2013-05-13 | 富士通株式会社 | Data protection device |
| US8745747B2 (en) | 2009-12-31 | 2014-06-03 | Fujitsu Limited | Data protecting device |
| CN102597960B (en) * | 2009-12-31 | 2016-02-17 | 富士通株式会社 | data protection device |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1589779A2 (en) | Function-limiting device and function-limiting method | |
| CN106559591B (en) | Method and device for calling mobile terminal based on call transfer | |
| JP2004349902A (en) | Mobile communication system, mobile communication terminal, personal information lock method used therefor and its program | |
| US20030013491A1 (en) | Portable terminal device having outgoing call control and personal data access control | |
| JP2012114906A (en) | Access point connection device and method thereof in portable terminal apparatus | |
| US5983093A (en) | Wireless terminal and wireless telecommunications system adapted to prevent the theft of wireless service | |
| JP4203738B2 (en) | Mobile phone with email and schedule function | |
| US20120108217A1 (en) | Communication terminal, telephone directory resistering method, and communication terminal handling method | |
| KR101626465B1 (en) | Apparatus and method for connecting the access point in portable communication system | |
| JP4736505B2 (en) | Mobile communication terminal, control method thereof, and terminal unauthorized use prevention system | |
| US8145755B2 (en) | Terminal, terminal management apparatus and method thereof for enabling management of terminals including based on association to each other | |
| JP2007318245A (en) | Cellular phone system, cellular phone terminal, personal information protecting method, personal information protecting program and program recording medium | |
| JP3353293B2 (en) | Mobile phone power-off notification system and method | |
| CN106341506A (en) | Dialing method for dialing equipment, dialing device, dialing equipment and communication system | |
| JPH11341151A (en) | Dial-up connection authentication system | |
| JP5316761B2 (en) | Method and apparatus for accommodating extension of cellular phone | |
| JP2004356685A (en) | Portable communication terminal and system for controlling portable communication terminal | |
| JP5478437B2 (en) | Server apparatus, terminal control system, and terminal control method | |
| JP4019059B2 (en) | Data line terminator with authentication function and authentication method in data communication | |
| JP5527214B2 (en) | Alternative processing determination method, alternative processing determination device, program, and mobile phone terminal | |
| JP3313662B2 (en) | Mobile terminal | |
| US20080205363A1 (en) | Method for operating a VoIP terminal device and a VoIP terminal device | |
| JP2006352739A (en) | Telephone call originating method, mobile telephone set and connection apparatus | |
| JP4800693B2 (en) | Wireless communication system and control program thereof | |
| JP2008245097A (en) | Extension telephone system and extension number retrieval method |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20060313 |
|
| A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20080123 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20080129 |
|
| A521 | Written amendment |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20080324 |
|
| A02 | Decision of refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A02 Effective date: 20080430 |