WO2022022739A1 - 接入控制方法、装置及通信设备 - Google Patents

接入控制方法、装置及通信设备 Download PDF

Info

Publication number
WO2022022739A1
WO2022022739A1 PCT/CN2021/110015 CN2021110015W WO2022022739A1 WO 2022022739 A1 WO2022022739 A1 WO 2022022739A1 CN 2021110015 W CN2021110015 W CN 2021110015W WO 2022022739 A1 WO2022022739 A1 WO 2022022739A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
type
information
terminal
identifier
Prior art date
Application number
PCT/CN2021/110015
Other languages
English (en)
French (fr)
Inventor
柯小婉
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN202110369540.7A external-priority patent/CN114071465A/zh
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Priority to EP21851111.1A priority Critical patent/EP4192064A4/en
Priority to KR1020237006765A priority patent/KR20230043969A/ko
Priority to JP2023503412A priority patent/JP7509991B2/ja
Publication of WO2022022739A1 publication Critical patent/WO2022022739A1/zh
Priority to US18/104,061 priority patent/US20230179597A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0884Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/105Multiple levels of security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/72Subscriber identity

Definitions

  • the embodiments of the present application relate to the field of communication technologies, and in particular, to an access control method, apparatus, and communication device.
  • a terminal needs to pass the authentication of the default certificate authentication server. Certification.
  • the authentication service function Authentication Server Function, AUSF
  • AUSF Authentication Server Function
  • Embodiments of the present application provide an access control method, apparatus, and communication device, which are used to solve the problem of how to select an authentication service network element.
  • an embodiment of the present application provides an access control method, which is applied to a first communication device, including:
  • first information and/or second information wherein, the first information includes at least one of the following: indication information of the first access mode, routing indication of the first type, and network identifier of the first type; the first information
  • the second information includes at least one of the following: a first-type network identifier, a first-type routing indication, a first-type group identifier, and terminal identification information;
  • the first operation includes at least one of the following:
  • the authentication service network element requesting to discover the authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, the information of the service provider and/or the indication information of the first access mode;
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode that does not have access to the first network
  • the access mode of accessing the first network with the certificate, the access mode that can only use restricted services, and the certificate of the terminal accessing the first network is the default certificate;
  • the first network and the second network are the same network or different networks
  • the first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals in the first access mode, and an authentication service network element for providing authentication services for terminals with default certificates. right service network element;
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the first type of routing indication includes: a routing indication for a first access mode
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • an embodiment of the present application provides an access control method, which is applied to a second communication device, including:
  • the first information includes at least one of the following: indication information of the first access mode, route indication of the first type, network identification of the first type, and identification information of the terminal;
  • the first type of routing indication includes: a routing indication for a first access mode
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the first network and the second network are the same network or different networks
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • an embodiment of the present application provides an access control method, which is applied to a third communication device, including:
  • the third information includes at least one of the following: a first type of group identifier, information of an authentication provider, a first type of routing indication, and a first type of network identifier , Indication information of the first access mode;
  • the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information includes at least one of the following: routing instructions supported by the authentication service network element, authentication The network ID of the network to which the service NE belongs, the group ID to which the authentication service NE belongs, the access mode supported by the authentication service NE, the authentication service type supported by the authentication service NE, and the authentication supported by the authentication service NE information of the provider and the authentication provider capable of authenticating the terminal with the default certificate;
  • the third operation includes at least one of the following:
  • the type of authentication service supported by the authentication service network element includes supporting the provision of authentication service to a terminal with a default certificate
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the first network and the second network are the same network or different networks
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the first type of routing indication includes: a routing indication for a first access mode
  • the first type of network identifier includes: a network identifier for the first access mode.
  • an embodiment of the present application provides an access control method, which is applied to a fourth communication device, including:
  • the fourth information is used to indicate the attribution information of the authentication service network element;
  • the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, and the network identifier of the network to which the authentication service network element belongs. , the group ID to which the authentication service NE belongs, the access mode supported by the authentication service NE, the authentication service type supported by the authentication service NE, the information of the authentication provider supported by the authentication service NE, and the authentication Providers are able to authenticate endpoints with default certificates;
  • the route indication supported by the authentication service network element is the route indication of the first type
  • the network identifier of the network to which the authentication service network element belongs is the first type of network identifier
  • the group identifier to which the authentication service network element belongs is a group identifier of the first type
  • the access mode supported by the authentication service network element includes a first access mode
  • the authentication service types supported by the authentication service network element include supporting the provision of authentication services to terminals with default certificates;
  • the first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and an access mode for accessing the first network without a certificate capable of accessing the first network
  • the access method of the network the access method that can only use restricted services
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the first type of network identifier includes: a network identifier for the first access mode.
  • an embodiment of the present application provides an access control apparatus, which is applied to a first communication device, including:
  • a first obtaining module configured to obtain first information and/or second information; wherein, the first information includes at least one of the following: indication information of the first access mode, route indication of the first type, and route indication of the first type
  • the second information includes at least one of the following: a first type of network identification, a first type of routing indication, a first type of group identification, and terminal identification information;
  • a first execution module configured to execute a first operation according to the first information and/or the second information
  • the first operation includes at least one of the following:
  • the authentication service network element requesting to discover the authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, the information of the service provider and/or the indication information of the first access mode;
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode that does not have access to the first network
  • the access mode of accessing the first network with the certificate, the access mode that can only use restricted services, and the certificate of the terminal accessing the first network is the default certificate;
  • the first network and the second network are the same network or different networks
  • the first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals in the first access mode, and an authentication service network element for providing authentication services for terminals with default certificates. right service network element;
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the first type of routing indication includes: a routing indication for a first access mode
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • an embodiment of the present application provides an access control apparatus, which is applied to a second communication device, including:
  • a first sending module configured to send the first information
  • the first information includes at least one of the following: indication information of the first access mode, route indication of the first type, network identification of the first type, and identification information of the terminal;
  • the first type of routing indication includes: a routing indication for a first access mode
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the first network and the second network are the same network or different networks
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • an embodiment of the present application provides an access control device, which is applied to a third communication device, including:
  • a second obtaining module configured to obtain third information and/or fourth information; wherein the third information includes at least one of the following: a first type of group identifier, a first type of routing indication, a first type of network Identification, information of the authentication provider, and indication information of the first access mode; the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information includes at least one of the following: the authentication service network element Supported routing instructions, network ID of the network to which the authentication service NE belongs, group ID to which the authentication service NE belongs, access mode supported by the authentication service NE, authentication service type supported by the authentication service NE, information of the authentication provider supported by the authorization service network element and the authentication provider can authenticate the terminal with the default certificate;
  • a second execution module configured to execute a third operation according to the third information and/or the fourth information
  • the third operation includes at least one of the following:
  • the type of authentication service supported by the authentication service network element includes supporting the provision of authentication service to a terminal with a default certificate
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode of accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the first network and the second network are the same network or different networks
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the first type of routing indication includes: a routing indication for a first access mode
  • the first type of network identifier includes: a network identifier for the first access mode.
  • an embodiment of the present application provides an access control apparatus, which is applied to a fourth communication device, including:
  • a second sending module configured to send fourth information
  • the fourth information is used to indicate the attribution information of the authentication service network element;
  • the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, and the network identifier of the network to which the authentication service network element belongs. , the group ID to which the authentication service NE belongs, the access mode supported by the authentication service NE, the authentication service type supported by the authentication service NE, the information of the authentication provider supported by the authentication service NE, and the authentication Providers are able to authenticate endpoints with default certificates;
  • the route indication supported by the authentication service network element is the route indication of the first type
  • the network identifier of the network to which the authentication service network element belongs is the first type of network identifier
  • the group identifier to which the authentication service network element belongs is a group identifier of the first type
  • the access mode supported by the authentication service network element includes a first access mode
  • the authentication service types supported by the authentication service network element include supporting the provision of authentication services to terminals with default certificates;
  • the first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and an access mode for accessing the first network without a certificate capable of accessing the first network
  • the access method of the network the access method that can only use restricted services
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the first type of network identifier includes: a network identifier for the first access mode.
  • an embodiment of the present application provides an access control method, which is applied to a fifth communication device, including:
  • the fifth operation includes at least one of the following:
  • the fifth condition includes at least one of the following: the terminal is in the first access mode;
  • the fifth information includes at least one of the following: the user identifier of the terminal, the MNC in the terminal user identifier, the MCC in the terminal user identifier, the information in the realm in the terminal user identifier, the first network identifier NID in the terminal user identifier, and the terminal user identifier. medium network ID.
  • an embodiment of the present application provides an access control apparatus, which is applied to a second communication device, including:
  • a third execution module configured to execute the fifth operation when the fifth condition is satisfied
  • the fifth operation includes at least one of the following:
  • the fifth condition includes at least one of the following: the terminal is in the first access mode;
  • the fifth information includes at least one of the following: a user identifier of the terminal, network identifier information in the terminal user identifier, and information in realm in the terminal user identifier.
  • an embodiment of the present application provides a communication device, including a processor, a memory, and a computer program stored on the memory and executable on the processor, where the computer program is executed by the processor can implement the steps of the access control method provided by the first aspect, or implement the steps of the access control method provided by the second aspect, or implement the steps of the access control method provided by the third aspect, or implement the fourth aspect.
  • an embodiment of the present application provides a readable storage medium, where a program or an instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the interface provided by the first aspect can be implemented.
  • the steps of the access control method, or the steps of implementing the access control method provided by the second aspect, or the steps of implementing the access control method provided by the third aspect, or the steps of implementing the access control method provided by the fourth aspect or, implement the steps of the access control method provided by the ninth aspect.
  • the selection of the authentication service network element can be supported in the above scenario that the terminal accesses the first network in the first access manner.
  • FIG. 1A is a schematic structural diagram of a wireless communication system according to an embodiment of the present application.
  • FIG. 1B is a schematic diagram of the relationship between network elements in the first access mode in this application.
  • FIG. 2 is a schematic flowchart of an access control method according to an embodiment of the present application
  • FIG. 3 is a schematic flowchart of an access control method according to another embodiment of the present application.
  • FIG. 4 is a schematic flowchart of an access control method according to another embodiment of the present application.
  • FIG. 5 is a schematic flowchart of an access control method according to another embodiment of the present application.
  • FIG. 6 is a flowchart of an indication process of service authentication in application scenario 1 of an embodiment of the present application.
  • FIG. 7 is a flowchart of a service selection process in application scenario 2 of an embodiment of the present application.
  • FIG. 8 is a flowchart of a service selection process of application scenario 3 of an embodiment of the present application.
  • FIG. 9 is a structural diagram of an access control apparatus according to an embodiment of the present application.
  • FIG. 10 is a structural diagram of another access control apparatus according to an embodiment of the present application.
  • FIG. 11 is a structural diagram of another access control apparatus according to an embodiment of the application.
  • FIG. 12 is a structural diagram of another access control apparatus according to an embodiment of the application.
  • FIG. 13 is a structural diagram of a communication device according to an embodiment of the application.
  • first, second and the like in the description and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and "first”, “second” distinguishes Usually it is a class, and the number of objects is not limited.
  • the first object may be one or multiple.
  • “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the associated objects are in an "or” relationship.
  • FIG. 1A shows a block diagram of a wireless communication system to which embodiments of the present application can be applied.
  • the wireless communication system includes a terminal 11 and a network-side device 12 .
  • the terminal 11 may include a relay supporting the terminal function and/or a terminal supporting the relay function.
  • the terminal 11 may also be referred to as a terminal device or a user terminal (User Equipment, UE), and the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), Laptop Computer (Laptop Computer) or notebook computer, Personal Digital Assistant (Personal Digital Assistant, PDA), Mobile Internet Device (Mobile Internet Device, MID), Handheld Computer, Netbook, Ultra Mobile Personal Computer ( Ultra-mobile personal computer (UMPC), Mobile Internet Device (MID), Wearable Device (Wearable Device) or Vehicle User Equipment (VUE), Pedestrian User Equipment (PUE) and other terminals Side devices, wearable devices include: bracelets, headphones, glasses, etc. It should be noted that, the embodiment of the present application does not limit the specific type of the terminal 11 .
  • the network side device 12 may be a base station or a core network, wherein the base station may be referred to as a Node B, an evolved Node B, an access point, a Base Transceiver Station (BTS), a radio base station, a radio transceiver, a basic service Set (Basic Service Set, BSS), Extended Service Set (Extended Service Set, ESS), Node B, Evolved Node B (eNB), Home Node B, Home Evolved Node B, WLAN Access Point, WiFi Node, Send Transmitting Receiving Point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms.
  • the base station in the NR system is taken as an example, but the specific type of the base station is not limited.
  • the communication device does not have a network certificate but needs to access the network.
  • the UE may not be able to access the SNPN yet. certificate and UE identity.
  • the UE may access a certain network (hereinafter referred to as the first network) and download the certificate for accessing the SNPN.
  • the first network For example, the UE accesses the first network, establishes a data channel, connects to the configuration server through the data channel, downloads the SNPN certificate from the configuration server, or the UE accesses the first network, and the control network element of the first network replaces the UE with the configuration server. Download the SNPN certificate.
  • the way of accessing the first network in order to download the credentials for accessing the second network may be referred to as onboarding.
  • the first network and the second network may be the same network.
  • the first network When the UE does not have the certificate of the first network, the first network needs to authenticate the UE before it can download the certificate for the UE or establish a data channel for downloading the certificate.
  • the UE may have a default certificate.
  • the first network may request a default certificate authentication server (DCS Default Credential Server) to authenticate the UE with the default certificate.
  • DCS can directly authenticate the UE or request other entities to authenticate the UE.
  • This type of authentication is analogous to the UE's roaming access to other networks' authentication but is different from the UE's roaming authentication.
  • the Access and Mobility Management Function (AMF) of the network accessed by the UE selects the authentication server (Home-Authentication Server Function, home AUSF) of the UE's home network for the UE, and The home AUSF is requested to authenticate the UE.
  • AMF Access and Mobility Management Function
  • home AUSF Home-Authentication Server Function
  • the AMF of the first network can select for the UE an authentication proxy server (for example, an Authentication Server Function (AUSF), or an AAA (Authentication Authorization Accounting Server) server proxy), and the authentication proxy server requests the default authentication server (Default Credential Server, DCS) in another network to authenticate the UE.
  • an authentication proxy server for example, an Authentication Server Function (AUSF), or an AAA (Authentication Authorization Accounting Server) server proxy
  • the authentication proxy server requests the default authentication server (Default Credential Server, DCS) in another network to authenticate the UE.
  • the DCS may be the home AUSF of the UE's home network.
  • NRF saves the relationship of network elements and can be called to query network elements.
  • a UE with a Public Land Mobile Network (PLMN) certificate can: 1) roam to access other PLMN networks through the PLMN certificate, 2) access the SNPN through the PLMN certificate, and 3) can also onboard to the first network for default Certificate authentication.
  • PLMN Public Land Mobile Network
  • the AMF of the UE's access network contacts the AUSF of the UE's home network.
  • the AMF of the UE's access network contacts the authentication proxy server (eg, AUSF, or AAA server proxy) of the access network, and the authentication proxy server contacts the UE's home AUSF.
  • the authentication proxy server eg, AUSF, or AAA server proxy
  • the authentication structure of mode 1) or the authentication structure of mode 3) may be adopted.
  • the current AUSF selection for AMF connection is that AMF selects according to the Home Network Identifier (Home Network Identifier) in the Subscription Permanent Identifier (SUPI) provided by the UE or the AUSF Group ID (Group ID) associated with the SUPI of.
  • the AMF of the first network needs to select the AUSF in the first network for the UE, and the AUSF then selects the AUSF of the UE's home location for the UE.
  • the AUSF of the first network has nothing to do with the UE and has nothing to do with the SUPI of the UE. How to differentiate UEs of different access types and select different AUSFs becomes a problem that needs to be solved.
  • obtaining may be understood as obtaining from configuration, receiving, receiving after request, obtaining through self-learning, deriving and obtaining according to unreceived information, or obtaining after processing according to received information. It is determined according to actual needs, which is not limited in this embodiment of the present application. For example, when a certain capability indication information sent by the device is not received, it can be deduced that the device does not support the capability.
  • the sending can include broadcasting, broadcasting in system messages, and returning after responding to the request.
  • the non-public network is an abbreviation of the non-public network.
  • a non-public network may be referred to as one of the following: a non-public communication network.
  • the non-public network may include at least one of the following deployment modes: a physical non-public network, a virtual non-public network, and a non-public network implemented on the public network.
  • the non-public network is a closed access group (Closed Access Group, CAG).
  • a CAG can consist of a group of terminals.
  • the non-public network service is an abbreviation for non-public network service.
  • Non-public network services may also be referred to as one of the following: non-public network network services, non-public communication services, non-public network communication services, non-public network network services, or other designations. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the non-public network is a closed access group, and in this case, the non-public network service is a network service of the closed access group.
  • the non-public network may include or be referred to as a private network.
  • a private network may be referred to as one of the following: a private communication network, a private network, a local area network (LAN), a private virtual network (PVN), an isolated communication network, a dedicated communication network, or other nomenclature. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the public network is an abbreviation of the public network.
  • the public network may be called one of the following: public communication network or other designation. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the authentication service includes initiating an authentication request for the terminal to an authentication server (eg, DCS, or home AUSF).
  • the authentication service network element may be an authentication agent that provides an authentication service for the terminal.
  • the authentication service network element may include but is not limited to one of the following: AUSF, AAA proxy.
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the access mode for accessing the first network with the certificate capable of accessing the first network, the access mode for using only restricted services, and the certificate for the terminal to access the first network are the default certificates.
  • that the certificate for the terminal to access the first network is a default certificate means that when the terminal accesses the first network, the certificate corresponding to the identity of the terminal provided to the first network is the default certificate. In one embodiment, the default certificate is not the certificate of the first network.
  • the first network and the second network are the same network or different networks.
  • the network type of the first network may include but is not limited to one of the following: a public network (such as PLMN), an independent non-public network (such as NPN), and a non-public network integrated with the public network (eg PNI NPN).
  • a public network such as PLMN
  • NPN independent non-public network
  • PNI NPN non-public network integrated with the public network
  • not having a certificate capable of accessing the first network includes not having a certificate capable of accessing an unrestricted service of the first network.
  • the terminal directly has the certificate of the B network, and it can be considered that the terminal has the certificate to be able to access the B network.
  • It has a certificate that can access B's network, that is, A's certificate.
  • the terminal of the service provider A and the terminal of the B network access the B network, and it can be considered that the access is an unrestricted service.
  • the certificate of C that the terminal has can help the B network request the C network.
  • the authentication server authenticates the terminal.
  • the certificate of C that the terminal has is not the certificate that can access the B network, but the certificate that the B network can verify the terminal, which is generally called a default certificate.
  • the terminal of the service provider C accesses the network of B, and it can be considered that the access is restricted service.
  • the authentication provider is a provider that can verify a terminal with a default certificate. In an embodiment, the authentication provider does not include the terminal's home network in the roaming scenario.
  • the information of the authentication provider of the terminal includes at least one of the following: a network identifier of the network corresponding to the default certificate of the terminal, a network identifier in the identifier of the terminal corresponding to the default certificate of the terminal, and a network identifier of the terminal corresponding to the default certificate of the terminal.
  • the certificate of the terminal corresponds to the identity of the terminal.
  • the information of the authentication provider of the terminal may be included in the identity of the terminal.
  • the first identifier of the terminal includes one of the following: a terminal identifier corresponding to a default certificate of the terminal, or a terminal identifier of the terminal in the DCS.
  • the identifier of the home network of the terminal is the identifier of the network in the identifiers of the terminal corresponding to the default certificate of the terminal.
  • the home network identifier of the terminal is the identifier of the authentication provider network.
  • the DCS is a device in the authentication provider of the terminal.
  • the first identifier of the terminal is the terminal identifier of the terminal in the home network.
  • the index information of the certificate verifier or the index information of the DCS is the identifier of the home network of the terminal by default.
  • the home network may be a network corresponding to the default certificate of the terminal.
  • the home AUSF is the AUSF in the home network.
  • the home NRF is the NRF in the home network.
  • Other home network elements are network elements in the home network.
  • the first type of network identifier includes the first type of home network identifier.
  • the home network identifier for the first access mode includes the home network identifier for the first access mode.
  • the first type of home network identifier includes: a home network identifier used for the first access mode.
  • the network identifier of the first type may be one of the following: the network identifier of the authentication provider, the network identifier corresponding to the default certificate of the terminal, and one of the identifiers of the terminal corresponding to the default certificate of the terminal. network identity.
  • the communication device may include at least one of the following: a communication network element and a terminal.
  • the communication network elements may include at least one of the following: a core network network element and a wireless access network network element.
  • the core network element may include, but is not limited to, at least one of the following: core network equipment, core network nodes, core network functions, core network network elements, and mobility management entities (Mobility Management Entity, MME), access mobility management function (Access Management Function, AMF), network storage function (Network Repository Function, NRF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), service Gateway (serving GW, SGW), PDN Gateway (PDN Gate Way), Policy Control Function (Policy Control Function, PCF), Policy and Charging Rules Function (Policy and Charging Rules Function, PCRF), GPRS Serving Support Node (Serving GPRS Support Node, SGSN), Gateway GPRS Support Node (GGSN), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server, HSS) and Application Function (AF).
  • MME Mobility Management Entity
  • MME Mobility Management Entity
  • Access Management Function Access Management Function
  • NRF Network Repository Function
  • an embodiment of the present application provides an access control method, which is applied to a first communication device; the first communication device includes an AMF.
  • the first communication device is a communication device in the first network. As shown in Figure 2, the method includes:
  • Step 21 Acquire the first information and/or the second information.
  • the first information includes, but is not limited to, at least one of the following: indication information of the first access mode, route indication of the first type, and network identifier of the first type.
  • the second information includes, but is not limited to, at least one of the following: a first-type routing indication, a first-type network identifier, a first-type group identifier, and terminal identification information.
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to the terminal in the first access mode.
  • the network identifier of the first type includes: a network identifier used for the first access mode.
  • the first type of route indication includes: a route indication for the first access mode.
  • the first information may be received and acquired from the terminal.
  • the above-mentioned first information may be included in the identification of the terminal (such as SUCI, or SUPI, etc.) for transmission.
  • the second information may be obtained by local configuration of the first communication device.
  • the identification information of the terminal may include at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal.
  • the first identification of the terminal includes information of the authentication provider of the terminal.
  • the authentication provider is a provider capable of verifying a terminal with a default certificate, or a provider capable of authenticating the terminal (eg, the home network of the terminal, the network corresponding to the default certificate of the terminal). In one embodiment, the authentication provider does not include the terminal's home network in the roaming scenario
  • the information of the authentication provider of the terminal includes at least one of the following: the network identifier of the network corresponding to the default certificate of the terminal, the network identifier in the identifier of the terminal corresponding to the default certificate of the terminal, the network identifier of the home network of the terminal, the default certificate verification The index information of the provider and the index information of the DCS. Not difficult to understand.
  • the certificate of the terminal corresponds to the identity of the terminal.
  • the information of the authentication provider of the terminal may be included in the identity of the terminal.
  • the first identifier of the terminal includes one of the following: a terminal identifier corresponding to a default certificate of the terminal, or a terminal identifier of the terminal in the DCS.
  • the DCS is a device in the authentication provider of the terminal.
  • the first identifier of the terminal is the terminal identifier of the terminal in the home network.
  • the index information of the certificate verifier or the index information of the DCS is the identifier of the home network of the terminal by default.
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of the authentication provider of the terminal, the network identifier of the first type and/or the routing indication of the first type.
  • the network identification of the first type and/or the routing indication of the first type can be determined.
  • the first identification of the terminal and the network identification of the first type may be sent.
  • the first identification of the terminal and the routing indication of the first type may be sent.
  • the first identification of the terminal and the second identification of the terminal may be sent.
  • the third identifier of the terminal may be sent.
  • Step 22 Perform a first operation according to the first information and/or the second information.
  • the first operation may include at least one of the following:
  • the first type of group identifier the first type of routing indication, the first type of network identifier, the information of the service provider and/or the indication information of the first access mode, request to discover the authentication service network element.
  • the indication information of the first access mode may be used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode that does not have access to the first network
  • the access mode for accessing the first network with a certificate of a network, the access mode for using only restricted services, and the certificate for the terminal to access the first network are the default certificates.
  • the first network and the second network are the same network or different networks.
  • the indication information of the first access mode includes the first registration type.
  • the first registration type can be used to indicate at least one of the following: registering a registration method for accessing the first network in order to download a certificate for accessing the second network, registering the first network without a certificate capable of accessing the first network How the network is registered.
  • the above-mentioned certificate for being able to access the first network includes a certificate for being able to access an unrestricted service of the first network.
  • the above-mentioned not having the certificate for being able to access the first network includes not having the certificate for being able to access the unrestricted service of the first network.
  • the terminal directly has the certificate of the B network, and it can be considered that the terminal has the certificate to be able to access the B network.
  • It has a certificate that can access B's network, that is, A's certificate.
  • the terminal of the service provider A and the terminal of the B network access the B network, and it can be considered that the access is an unrestricted service.
  • the certificate of C that the terminal has can help the B network request the C network.
  • the authentication server authenticates the terminal.
  • the certificate of C that the terminal has is not the certificate that can access the B network, but the certificate that the B network can verify the terminal, which is generally called a default certificate.
  • the terminal of the service provider C accesses the network of B, and it can be considered that the access is restricted service.
  • the above-mentioned first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals in the first access mode, and an authentication service network element for providing authentication services for terminals with default certificates. authentication service network element.
  • the authentication service includes initiating an authentication request for the terminal to an authentication server (eg, DCS, or home AUSF).
  • an authentication server eg, DCS, or home AUSF.
  • the above-mentioned request to discover the authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier or the indication information of the first access mode may include at least one of the following: item:
  • the first type of route indication is sent to the first target end, where the first type of route indication is used for the first target end to find an authentication service network element matching the first type of route indication.
  • the first target terminal may include: a network element device responsible for querying network elements in the network, such as a network repository function (Network Repository Function, NRF).
  • NRF Network Repository Function
  • the authentication service network element may include but is not limited to one of the following: AUSF, AAA proxy.
  • the authentication service network element may be an authentication proxy that provides authentication services for the terminal.
  • the NRF may be requested to discover the AUSF through the AUSF group identifier dedicated to the first access mode.
  • the obtaining of the first information may include: obtaining the first information from the terminal.
  • the obtaining of the second information may include: obtaining the second information according to a configuration on the first communication device.
  • obtaining the first information and/or the second information above may include at least one of the following:
  • the first type of group identifier, the first type of routing indication or the first type of network identifier is acquired.
  • performing the first operation may include:
  • the routing indication of the first type and/or the network identifier of the first type it is requested to discover the authentication service network element.
  • obtaining the first information and/or the second information above may include at least one of the following:
  • performing the first operation may include:
  • the discovery of the authentication service network element is requested.
  • the above-mentioned first operation further includes at least one of the following:
  • the third identifier of the terminal derive the first identifier of the terminal
  • the first identification of the terminal is sent to the first authentication service network element or the discovered authentication service network element.
  • the selection of the authentication service network element can be supported in the above scenario that the terminal accesses the first network in the first access manner.
  • an embodiment of the present application provides an access control method, which is applied to a second communication device; the second communication device includes a UE. As shown in Figure 3, the method includes:
  • Step 31 Send the first information.
  • the first information packet may include at least one of the following: indication information of the first access mode, routing indication of the first type, network identification of the first type, and identification information of the terminal.
  • the first type of routing indication includes: routing indication for the first access mode.
  • the first type of network identifier includes: a network identifier for the first access mode.
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode in which only restricted services can be used, and the certificate for the terminal to access the first network are the default certificates.
  • the first network and the second network are the same network or different networks.
  • the first information is sent to the first network accessed by the terminal.
  • the manner in which the terminal accesses the first network is the first access manner.
  • the above-mentioned first information may be included in the identifier of the terminal (such as SUCI, or SUPI, etc.) for transmission.
  • the foregoing sending the first information may include: sending the first information when the first condition is satisfied.
  • the first condition may include at least one of the following:
  • the purpose of the second communication device accessing the first network is to download a certificate for accessing the second network
  • the second communication device does not have a certificate capable of accessing the first network
  • the access of the second communication device to the first network can only use restricted services.
  • the first network and the second network are the same network or different networks.
  • the network identifier for the first access mode is sent through the user permanent identifier SUPI of the terminal.
  • the fact that the second communication device does not have a certificate capable of accessing the first network includes: the second communication device does not have a certificate of the first network or the second communication device does not have a service provider capable of accessing the first network certificate.
  • the above-mentioned certificate for being able to access the first network may include a certificate for being able to access unrestricted services of the first network.
  • the above-mentioned not having the certificate for being able to access the first network includes not having the certificate for being able to access the unrestricted service of the first network.
  • the terminal directly has the certificate of the B network, and it can be considered that the terminal has the certificate to be able to access the B network.
  • It has a certificate that can access B's network, that is, A's certificate.
  • the terminal of the service provider A and the terminal of the B network access the B network, and it can be considered that the access is an unrestricted service.
  • the certificate of C that the terminal has can help the B network request the C network.
  • the authentication server authenticates the terminal.
  • the certificate of C that the terminal has is not the certificate that can access the B network, but the certificate that the B network can verify the terminal, which is generally called a default certificate.
  • the terminal of the service provider C accesses the network of B, and it can be considered that the access is restricted service.
  • the identification information of the terminal may include at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal.
  • the first identification of the terminal includes information of the authentication provider of the terminal.
  • the authentication provider is a provider capable of authenticating a terminal with a default certificate, or a provider capable of authenticating the terminal (such as the terminal's home network).
  • the information of the authentication provider of the terminal includes at least one of the following: the network identifier of the network corresponding to the default certificate of the terminal, the network identifier in the identifier of the terminal corresponding to the default certificate of the terminal, the network identifier of the home network of the terminal, the default certificate verification The index information of the provider and the index information of the DCS.
  • the information of the authentication provider of the terminal may be included in the identity of the terminal.
  • the certificate of the terminal corresponds to the identity of the terminal.
  • the first identifier of the terminal includes one of the following: a terminal identifier corresponding to a default certificate of the terminal, or a terminal identifier of the terminal in the DCS.
  • the DCS is a device in the authentication provider of the terminal.
  • the first identifier of the terminal is the terminal identifier of the terminal in the home network.
  • the index information of the certificate verifier or the index information of the DCS is the identifier of the home network of the terminal by default.
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of the authentication provider of the terminal, the network identifier of the first type and/or the routing indication of the first type.
  • the network identification of the first type and/or the routing indication of the first type can be determined.
  • the first identification of the terminal and the network identification of the first type may be sent.
  • the first identifier of the terminal and the routing indication of the first type may be sent.
  • the first identification of the terminal and the second identification of the terminal may be sent.
  • the third identification of the terminal may be sent.
  • the method may further include at least one of the following:
  • the second identification of the terminal that is, setting the routing indication in the identification of the terminal to the routing indication of the first type and/or setting the home network identification in the identification of the terminal to the network identification of the first type;
  • the third identification of the terminal is generated, that is, the network identification of the first type is added to the identification of the terminal and/or the routing indication of the first type is added to the identification of the terminal.
  • the operation of generating the second identification of the terminal and/or generating the third identification of the terminal is performed under the condition that the first condition is satisfied.
  • the first condition is as described above and will not be repeated here.
  • the selection of the authentication service network element can be supported.
  • an embodiment of the present application provides an access control method, which is applied to a third communication device; the third communication device includes an NRF.
  • the third communication device is a communication device in the first network. As shown in Figure 4, the method includes:
  • Step 41 Acquire third information and/or fourth information.
  • the third information may include at least one of the following: a first-type group identifier, a first-type routing indication, a first-type network identifier, information on the authentication provider, and an indication of the first access mode information.
  • the fourth information is used to indicate attribution information of the authentication service network element.
  • the fourth information may include at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, and a network identifier supported by the authentication service network element.
  • the access mode, the authentication service type supported by the authentication service network element, the information of the authentication provider supported by the authentication service network element, and the authentication provider can authenticate the terminal with the default certificate.
  • the indication information of the first access mode may be used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode that does not have access to the first network
  • the access mode of accessing the first network with a certificate of a network, the access mode of only being able to use restricted services, and the certificate of the terminal accessing the first network are the default certificates.
  • the first network and the second network are the same network or different networks.
  • the first type of route indication includes: a route indication for the first access mode.
  • the restricted service includes a service for downloading a certificate capable of accessing the network.
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to the terminal in the first access mode.
  • the third information may be obtained from the AMF.
  • the fourth information that is, the attribution information of the authentication service network element
  • the authentication service network element eg, AUSF or AAA proxy
  • Step 42 Perform a third operation according to the third information and/or the fourth information.
  • the third operation may include at least one of the following:
  • the type of authentication service supported by the authentication service network element includes supporting the provision of authentication service to a terminal with a default certificate.
  • the discovered authentication service network element is sent to the second target end.
  • the second target terminal includes: AMF.
  • the third information is received from the second target.
  • the authentication service network element may include one of the following: AUSF, AAA proxy.
  • the authentication service network element matching the third information is the first authentication service network element.
  • the first authentication service network element includes: an authentication service network element configured to provide an authentication service to the terminal in the first access mode.
  • the first type of group identifier includes one of the following: AUSF Group ID, AAA proxy group ID.
  • the NRF may be requested to discover the AUSF.
  • the discovered authentication service network element when the third information includes the indication information of the first access mode, the discovered authentication service network element The supported access mode is the first access mode; or, when the third information includes a route indication of the first type, the route indication supported by the discovered authentication service network element is the route of the first type or, when the third information includes the network identifier of the first type, the network identifier of the network to which the discovered authentication service network element belongs is the network identifier of the first type; or, when the third information When the information includes the first type of group identifier, the group identifier to which the discovered authentication service network element belongs is the first type of group identifier; or, when the third information includes the information of the authentication provider, the The authentication provider information supported by the discovered authentication service network element includes the authentication provider information in the third information.
  • the discovered authentication service network element satisfies at least one of the following:
  • the route indication supported by the discovered authentication service network element is the route indication of the first type
  • the network identifier of the network to which the discovered authentication service network element belongs is the first type of network identifier
  • the group identifier to which the discovered authentication service network element belongs is the group identifier of the first type
  • the access mode supported by the discovered authentication service network element is the first access mode
  • the authentication service type supported by the discovered authentication service network element is to support providing an authentication service to a terminal with a default certificate.
  • the selection of the authentication service network element can be supported in the above scenario that the terminal accesses the first network in the first access manner.
  • an embodiment of the present application provides an access control method, which is applied to a fourth communication device; the fourth communication device includes an AUSF.
  • the fourth communication device is a communication device in the first network. As shown in Figure 5, the method includes:
  • Step 51 Send fourth information.
  • the fourth information is used to indicate the attribution information of the authentication service network element.
  • the fourth information may include at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, and a network identifier supported by the authentication service network element.
  • the access mode, the authentication service type supported by the authentication service network element, the information of the authentication provider supported by the authentication service network element, and the authentication provider can authenticate the terminal with the default certificate.
  • the route indication supported by the authentication service network element is the route indication of the first type.
  • the network identifier of the network to which the authentication service network element belongs is the network identifier of the first type.
  • the group identifier to which the authentication service network element belongs is a group identifier of the first type.
  • the access mode supported by the authentication service network element includes the first access mode.
  • the type of authentication service supported by the authentication service network element includes supporting the provision of authentication service (for example, as an authentication proxy) for a terminal with a default certificate.
  • the first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and an access mode for accessing the first network without a certificate capable of accessing the first network
  • the access mode of the network, the access mode in which only restricted services can be used, and the certificate for the terminal to access the first network are the default certificates.
  • the group identifier of the first type includes: the group identifier of the authentication service network element used to provide the authentication service to the terminal in the first access mode.
  • the first type of route indication of the first type includes: route indication for the first access mode.
  • the first type of network identifier includes: a network identifier for the first access mode.
  • the above-mentioned sending the fourth information may include: when the second condition is satisfied, sending the fourth information; wherein, the second condition includes: the authentication service network element is used for the first The terminal in the access mode provides the authentication service network element of the authentication service.
  • the selection of the authentication service network element can be supported in the above scenario that the terminal accesses the first network in the first access manner.
  • An embodiment of the present application provides an access control method, which is applied to a fifth communication device; the fourth communication device includes at least one of the following: AMF, AUSF, and UDM.
  • the fifth communication device is a communication device in the first network. The method includes:
  • the fifth operation includes at least one of the following:
  • the fifth condition includes at least one of the following: the terminal is in the first access mode;
  • the fifth information includes at least one of the following: a user identifier of the terminal, network identifier information in the terminal user identifier, and information in realm in the terminal user identifier.
  • a terminal that accesses the network through a non-first access manner it is a default operation to select a network device for the terminal according to the information in the user identity of the terminal. Therefore, an exceptional operation needs to be performed for a terminal that accesses the network through a non-first access method.
  • the network identification information in the terminal user identification includes at least one of the following: MNC in the terminal user identification, MCC in the terminal user identification, and network identification NID in the terminal user identification.
  • the method further includes: obtaining first information, where the first information includes at least one of the following: a first access mode The indication information, the first type of routing indication, the first type of network identification; the second information includes at least one of the following: the first type of network identification, the first type of routing indication, the first type of group identification, Identification information of the terminal; among them,
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the first type of routing indication includes: a routing indication for a first access mode
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • the network element includes at least one of the following: a core network network element, an authentication service function AUSF, a unified data management UDM, and a unified data storage UDR.
  • the network element may be a network device.
  • the indication process of service authentication may include:
  • Step 61 The authentication service network element for providing the authentication service to the terminal in the first access mode (the AUSF is used as an example to be described later) initiates a registration request to the NRF, such as Nnrf_NF Management_NF Register.
  • the NRF such as Nnrf_NF Management_NF Register.
  • the registration request includes fourth information, where the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information may include at least one of the following: a network identifier of the network to which the authentication service network element belongs. , the group ID to which the authentication service network element belongs, and the access mode supported by the authentication service network element.
  • the authentication service network element when the network identifier of the network to which the authentication service network element belongs is the first type of home network identifier, it can be indicated that the authentication service network element is used to provide authentication for the terminal in the first access mode. Serve.
  • the authentication service network element when the group identifier to which the authentication service network element belongs is the first type of group identifier, it can be indicated that the authentication service network element is used to provide authentication services to terminals in the first access mode.
  • the UE registers with the first network, and the registration type is the first access mode.
  • the first network needs to request the DCS to authenticate the UE.
  • the AMF, NRF, and AUSF are communication devices in the first network
  • the home NRF and the home AUSF are devices in the UE's home network
  • the home AUSF is an embodiment of DCS.
  • the process of selecting an AUSF may include:
  • Step 71 The UE initiates a registration request to the AMF, wherein the registration type of the registration request is the indication information of the first access mode (eg, the first registration type).
  • Step 72 The AMF performs an AUSF selection operation according to the indication information of the first access mode (such as the first registration type) provided by the UE, including at least one of the following:
  • the AUSF needs to provide the access mode supported by the NRF, such as the first access mode, when registering with the NRF.
  • the network identifier of the network to which the network element providing the authentication service belongs should be the network identifier of the first access mode. For example, a network identifier dedicated to the first access mode.
  • the AUSF supporting the first access mode needs to correspondingly provide the network ID of the first access mode with the group ID to which the authentication network element belongs when registering with the NRF.
  • the group identifier of the authentication service network element dedicated to the first access mode For example, the group identifier of the authentication service network element dedicated to the first access mode.
  • Step 73 The NRF performs a third operation according to the acquired third information and/or the fourth information.
  • the third information may include at least one of the following: a first type of group identifier, a first type of network identifier, and indication information of the first access mode.
  • the fourth information is used to indicate the attribution information of the authentication service network element.
  • the fourth information may include at least one of the following: the network identifier of the network to which the authentication service network element belongs, the group identifier to which the authentication service network element belongs, and the access mode supported by the authentication service network element.
  • the third operation includes at least one of the following:
  • the AUSF will be used as an example in the following
  • Step 74 The AMF sends a UE authentication request, such as Nausf_UEAuthentication_Authenticate Request, to the AUSF.
  • a UE authentication request such as Nausf_UEAuthentication_Authenticate Request
  • the request may include the first identifier of the terminal (the real first SUCI or the first SUPI of the UE).
  • Steps 75 to 78 The AUSF discovers the home AUSF through the NRF and the home NRF according to the first identity of the terminal, or the home network identity in the first UE identity, or the AUSF group identity corresponding to the first UE identity.
  • the AUSF sends a network function discovery request, such as Nnrf_NF Discovery_Request, to the NRF.
  • the discovery request may include one of the following: the first identification of the terminal, the home network identification Home Network ID of the terminal, the AUSF group identification related to the first identification of the terminal, and the like.
  • the NRF sends a network function discovery request, such as Nnrf_NF Discovery_Request, to the home NRF.
  • the discovery request may include the first identifier of the terminal, or the home network identifier in the first UE identifier, or the AUSF group identifier corresponding to the first UE identifier, and the like.
  • step 77 the home NRF returns a network function discovery response, such as Nnrf_NF Discovery_Response, to the NRF.
  • a network function discovery response such as Nnrf_NF Discovery_Response
  • step 78 the NRF returns a network function discovery response, such as Nnrf_NF Discovery_Response, to the AUSF.
  • Step 79 The AUSF initiates a UE authentication request to the home AUSF, such as Nausf_UE Authentication_Authenticate Request.
  • the request includes the generated second SUCI or first SUPI, SN-name, indication information of the first access mode, and the like.
  • the home AUSF may initiate an authentication procedure to the UE.
  • the UE registers with the first network and provides identification information of the terminal.
  • the first network needs to request the DCS to authenticate the UE.
  • the AMF, NRF, and AUSF are communication devices in the first network
  • the home NRF and the home AUSF are devices in the UE's home network
  • the home AUSF is an embodiment of DCS.
  • the process of selecting an AUSF may include:
  • Step 81 The UE initiates a registration request to the AMF.
  • the registration request includes the first information.
  • the identification information of the terminal may include at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of the authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of the authentication provider of the terminal, the first type of network identifier and/or the first type of routing indication.
  • the AMF may perform: deriving the first type of network identifier and/or the first type of routing indication according to the second identifier of the terminal or the third identifier of the terminal;
  • the network identifier of the first type is a specific value dedicated to the first access mode, such as 111.
  • the first type of routing indication is a specific value dedicated to the first access mode.
  • the registration request includes a first identification of the terminal and a first type of network identification.
  • the registration request includes the first identifier of the terminal and the second identifier of the terminal.
  • the registration request includes the third identifier of the terminal.
  • the DCS index information includes the real Home Network ID of the SUPI of the UE.
  • Step 82 The AMF sends a network function discovery request, such as Nnrf_NF Discovery_Request, to the NRF, that is, requests the NRF to query the AUSF according to the home network identifier of the first access mode to obtain the AUSF.
  • a network function discovery request such as Nnrf_NF Discovery_Request
  • the request includes the Home Network ID and/or Group ID of the AUSF.
  • Step 83 The NRF returns the discovered authentication service network element, that is, the AUSF, to the AMF.
  • Step 84 The AMF sends a UE authentication request, such as Nausf_UEAuthentication_Authenticate Request, to the AUSF.
  • a UE authentication request such as Nausf_UEAuthentication_Authenticate Request
  • AMF can perform at least one of the following:
  • the first identification of the terminal is sent to the first authentication service network element or the discovered authentication service network element.
  • Steps 85 to 89 the same as steps 75 to 79 in the second application scenario, and will not be repeated here.
  • an embodiment of the present application provides an access control apparatus, which is applied to a first communication device.
  • the access control apparatus 90 includes:
  • the first obtaining module 91 is configured to obtain first information and/or second information; wherein, the first information includes at least one of the following: indication information of the first access mode, route indication of the first type, first A type of network identifier; the second information includes at least one of the following: a first type of network identifier, a first type of routing indication, a first type of group identifier, and terminal identification information;
  • a first execution module 92 configured to execute a first operation according to the first information and/or the second information
  • the first operation includes at least one of the following:
  • the authentication service network element requesting to discover the authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, the information of the service provider and/or the indication information of the first access mode;
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode that does not have access to the first network
  • the access mode of accessing the first network with the certificate, the access mode that can only use restricted services, and the certificate of the terminal accessing the first network is the default certificate;
  • the first network and the second network are the same network or different networks
  • the first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals in the first access mode, and an authentication service network element for providing authentication services for terminals with default certificates. right service network element;
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the first type of routing indication includes: a routing indication for a first access mode
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • the first execution module 92 is further configured to execute at least one of the following:
  • the first type of route indication is sent to the first target end, where the first type of route indication is used for the first target end to find an authentication service network element matching the first type of route indication.
  • the first obtaining module 91 is specifically configured to: obtain the first information from the terminal.
  • the first obtaining module 91 is specifically configured to: obtain the second information according to the configuration on the first communication device.
  • the first obtaining module 91 is specifically used for at least one of the following:
  • the first communication device obtain the first type of group identifier, the first type of routing indication or the first type of network identifier;
  • performing the first operation according to the first information and/or the second information includes at least one of the following:
  • the routing indication of the first type and/or the network identifier of the first type it is requested to discover the authentication service network element.
  • the first obtaining module 91 is specifically used for at least one of the following:
  • performing the first operation according to the first information and/or the second information includes at least one of the following:
  • the discovery of the authentication service network element is requested.
  • the first operation further includes at least one of the following:
  • the first identification of the terminal is sent to the first authentication service network element or the discovered authentication service network element.
  • the access control apparatus 90 can implement each process implemented in the method embodiment shown in FIG. 2 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not repeated here.
  • an embodiment of the present application provides an access control apparatus, which is applied to a second communication device.
  • the access control apparatus 100 includes:
  • a first sending module 101 configured to send first information
  • the first information includes at least one of the following: indication information of the first access mode, route indication of the first type, network identification of the first type, and identification information of the terminal;
  • the first type of routing indication includes: a routing indication for a first access mode
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the first network and the second network are the same network or different networks
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • the first sending module 101 is specifically configured to: send the first information when the first condition is satisfied;
  • the first condition includes at least one of the following:
  • the purpose of the second communication device accessing the first network is to download a certificate for accessing the second network
  • the second communication device does not have a certificate capable of accessing the first network
  • the access of the second communication device to the first network can only use restricted services.
  • the access control apparatus 100 further includes:
  • a generating module for generating a second identification of the terminal, setting the routing indication in the identification of the terminal as the routing indication of the first type and/or setting the home network identification in the identification of the terminal as the network identification of the first type; and /or
  • a third identification of the terminal is generated, the network identification of the first type is added to the identification of the terminal and/or the routing indication of the first type is added to the identification of the terminal.
  • the access control apparatus 100 can implement each process implemented in the method embodiment shown in FIG. 3 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an access control apparatus, which is applied to a second communication device.
  • the access control apparatus 110 includes:
  • the second obtaining module 111 is configured to obtain third information and/or fourth information; wherein, the third information includes at least one of the following: a first type of group identifier, a first type of routing indication, a first type of The network identifier, the information of the authentication provider, and the indication information of the first access mode; the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information includes at least one of the following: an authentication service network The routing indication supported by the element, the network identifier of the network to which the authentication service NE belongs, the group identifier to which the authentication service NE belongs, the access mode supported by the authentication service NE, the authentication service type supported by the authentication service NE, Information of the authentication provider supported by the authentication service network element and the authentication provider can authenticate the terminal with the default certificate;
  • a second execution module 112 configured to execute a third operation according to the third information and/or the fourth information
  • the third operation includes at least one of the following:
  • the type of authentication service supported by the authentication service network element includes supporting the provision of authentication service to a terminal with a default certificate
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the first network and the second network are the same network or different networks
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the first type of routing indication includes: a routing indication for a first access mode
  • the first type of network identifier includes: a network identifier for the first access mode.
  • the access mode supported by the discovered authentication service network element is the first access mode
  • the routing indication supported by the discovered authentication service network element is a routing indication of the first type
  • the network identifier of the network to which the discovered authentication service network element belongs is the network identifier of the first type
  • the group identifier to which the discovered authentication service network element belongs is the first type of group identifier.
  • the authentication provider information supported by the discovered authentication service network element includes the information of the authentication provider in the third information
  • the discovered authentication service network element satisfies at least one of the following:
  • the route indication supported by the discovered authentication service network element is the route indication of the first type
  • the network identifier of the network to which the discovered authentication service network element belongs is the first type of network identifier
  • the group identifier to which the discovered authentication service network element belongs is the group identifier of the first type
  • the access mode supported by the discovered authentication service network element is the first access mode
  • the authentication service type supported by the discovered authentication service network element is to support providing an authentication service to a terminal with a default certificate.
  • the access control apparatus 110 can implement each process implemented in the method embodiment shown in FIG. 4 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an access control apparatus, which is applied to a second communication device.
  • the access control apparatus 120 includes:
  • a second sending module 121 configured to send fourth information
  • the fourth information is used to indicate the attribution information of the authentication service network element;
  • the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, and the network identifier of the network to which the authentication service network element belongs. , the group ID to which the authentication service NE belongs, the access mode supported by the authentication service NE, the authentication service type supported by the authentication service NE, the information of the authentication provider supported by the authentication service NE, and the authentication Providers are able to authenticate endpoints with default certificates;
  • the route indication supported by the authentication service network element is the route indication of the first type
  • the network identifier of the network to which the authentication service network element belongs is the first type of network identifier
  • the group identifier to which the authentication service network element belongs is a group identifier of the first type
  • the access mode supported by the authentication service network element includes a first access mode
  • the authentication service types supported by the authentication service network element include supporting the provision of authentication services to terminals with default certificates;
  • the first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and an access mode for accessing the first network without a certificate capable of accessing the first network
  • the access mode of the network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network is the default certificate;
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the first type of network identifier includes: a network identifier for the first access mode.
  • the second sending module 121 is further configured to: send the fourth information when the second condition is satisfied;
  • the second condition includes: the authentication service network element is an authentication service network element for providing authentication services to the terminal in the first access mode.
  • the access control apparatus 120 can implement each process implemented in the method embodiment shown in FIG. 5 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • the present application also provides an access control apparatus, which is applied to the fifth communication device, including:
  • a third execution module configured to execute the fifth operation when the fifth condition is satisfied
  • the fifth operation includes at least one of the following:
  • the fifth condition includes at least one of the following: the terminal is in the first access mode;
  • the fifth information includes at least one of the following: a user identifier of the terminal, network identifier information in the terminal user identifier, and information in realm in the terminal user identifier.
  • the network identification information in the terminal user identification includes at least one of the following: MNC in the terminal user identification, MCC in the terminal user identification, and network identification NID in the terminal user identification.
  • the device further includes:
  • a third obtaining module configured to obtain first information, where the first information includes at least one of the following: indication information of the first access mode, route indication of the first type, and network identifier of the first type; the second The information includes at least one of the following: a first-type network identifier, a first-type routing indication, a first-type group identifier, and terminal identification information; wherein,
  • the indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, and a certificate that is not capable of accessing the first network
  • the access mode for accessing the first network, the access mode that can only use restricted services, and the certificate for the terminal to access the first network are the default certificates;
  • the group identifier of the first type includes: a group identifier of an authentication service network element used to provide an authentication service to a terminal in the first access mode;
  • the network identifier of the first type includes: a network identifier for the first access mode
  • the first type of routing indication includes: a routing indication for a first access mode
  • the identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;
  • the first identification of the terminal includes information of an authentication provider of the terminal;
  • the second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication
  • the third identifier of the terminal includes information of an authentication provider of the terminal, a network identifier of the first type, and/or a routing indication of the first type.
  • the device further includes:
  • a determination module configured to determine that the fifth condition is satisfied according to the first information.
  • the network element includes at least one of the following: core network element, AUSF, UDM and UDR.
  • the network element may be a network device.
  • FIG. 13 is a schematic structural diagram of another communication device provided by an embodiment of the present application.
  • the communication device 130 includes: a processor 131 , a memory 132 , and a memory 132 stored on the memory 132 and available in the The computer program running on the processor, the various components in the communication device 130 are coupled together through the bus interface 133, and the computer program is executed by the processor 131.
  • Embodiments of the present application further provide a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, each process implemented in the method embodiment shown in FIG. 2 above is implemented, Alternatively, implement each process implemented in the above method embodiment shown in FIG. 3 , or implement each process implemented in the above method embodiment shown in FIG. 4 , or implement each process implemented in the above method embodiment shown in FIG. 5 . , and can achieve the same technical effect, in order to avoid repetition, it is not repeated here.
  • the computer-readable storage medium such as read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Power Engineering (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本申请实施例提供一种接入控制方法、装置及通信设备。该接入控制方法包括:获取第一信息和/或第二信息;该第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;该第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;根据第一信息和/或第二信息,执行第一操作;该第一操作包括以下至少一项:选择第一鉴权服务网元;确定第一类型的组标识,确定第一类型的路由指示或者确定第一类型的网络标识。

Description

接入控制方法、装置及通信设备
相关申请的交叉引用
本申请主张在2020年7月31日在中国提交的中国专利申请号No.202010762196.3的优先权,及主张在2021年4月6日在中国提交的中国专利申请号No.202110369540.7的优先权,其全部内容通过引用包含于此。
技术领域
本申请实施例涉及通信技术领域,尤其涉及一种接入控制方法、装置及通信设备。
背景技术
目前,终端为了下载用于接入独立非公用网络(Standalone Non-public Network,SNPN)的证书而接入另一网络(此方式可称为onboarding)的过程中,需要通过默认证书鉴权服务器的认证。然而,此时该另一网络的鉴权服务功能(Authentication Server Function,AUSF)可能与终端无关,与终端的签约永久标识无关。此情况下,如何选择鉴权服务网元是急需要解决的问题。
发明内容
本申请实施例提供一种接入控制方法、装置及通信设备,用于解决如何选择鉴权服务网元的问题。
为了解决上述技术问题,本申请是这样实现的:
第一方面,本申请实施例提供了一种接入控制方法,应用于第一通信设备,包括:
获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;
根据所述第一信息和/或所述第二信息,执行第一操作;
其中,所述第一操作包括以下至少一项:
选择第一鉴权服务网元;
确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;
根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;
其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或者不同的网络;
其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
第二方面,本申请实施例提供了一种接入控制方法,应用于第二通信设备,包括:
发送第一信息;
其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或不同的网络;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
第三方面,本申请实施例提供了一种接入控制方法,应用于第三通信设备,包括:
获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、认证提供方的信息、第一类型的路由指示、第一类型的网络标识、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
根据所述第三信息和/或所述第四信息,执行第三操作;
其中,所述第三操作包括以下至少一项:
发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息 与所述第三信息相匹配;
发送所述发现的鉴权服务网元;
其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或不同的网络;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
第四方面,本申请实施例提供了一种接入控制方法,应用于第四通信设备,包括:
发送第四信息;
其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;
所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;
所述鉴权服务网元所属的组标识为第一类型的组标识;
所述鉴权服务网元支持的接入方式包括第一接入方式;
所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一 网络的接入方式、仅能够使用受限服务的接入方式;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
第五方面,本申请实施例提供了一种接入控制装置,应用于第一通信设备,包括:
第一获取模块,用于获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;
第一执行模块,用于根据所述第一信息和/或所述第二信息,执行第一操作;
其中,所述第一操作包括以下至少一项:
选择第一鉴权服务网元;
确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;
根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;
其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或者不同的网络;
其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
第六方面,本申请实施例提供了一种接入控制装置,应用于第二通信设备,包括:
第一发送模块,用于发送第一信息;
其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或不同的网络;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
第七方面,本申请实施例提供了一种接入控制装置,应用于第三通信设 备,包括:
第二获取模块,用于获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
第二执行模块,用于根据所述第三信息和/或所述第四信息,执行第三操作;
其中,所述第三操作包括以下至少一项:
发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;
发送所述发现的鉴权服务网元;
其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或不同的网络;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
第八方面,本申请实施例提供了一种接入控制装置,应用于第四通信设备,包括:
第二发送模块,用于发送第四信息;
其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;
所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;
所述鉴权服务网元所属的组标识为第一类型的组标识;
所述鉴权服务网元支持的接入方式包括第一接入方式;
所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
第九方面,本申请实施例提供了一种接入控制方法,应用于第五通信设备,包括:
在满足第五条件的情况下,执行第五操作;
所述第五操作包括以下至少一项:
不使用第五信息为终端选择网元;
其中,
所述第五条件包括以下至少一项:所述终端为第一接入方式;
所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中MNC,终端用户标识中MCC,终端用户标识中realm中的信息,终端用户标识中第一网络标识NID,终端用户标识中网络标识。
第十方面,本申请实施例提供了一种接入控制装置,应用于第二通信设备,包括:
第三执行模块,用于在满足第五条件的情况下,执行第五操作;
所述第五操作包括以下至少一项:
不使用第五信息为终端选择网元;
其中,
所述第五条件包括以下至少一项:所述终端为第一接入方式;
所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。
第十方面,本申请实施例提供了一种通信设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时可实现第一方面提供的接入控制方法的步骤,或者,实现第二方面提供的接入控制方法的步骤,或者,实现第三方面提供的接入控制方法的步骤,或者,实现第四方面提供的接入控制方法的步骤,或者,实现第九方面提供的接入控制方法的步骤。
第一方面,本申请实施例提供了一种可读存储介质,所述可读存储介质上存储有程序或指令,所述程序或指令被处理器执行时实现如可实现第一方面提供的接入控制方法的步骤,或者,实现第二方面提供的接入控制方法的步骤,或者,实现第三方面提供的接入控制方法的步骤,或者,实现第四方面提供的接入控制方法的步骤,或者,实现第九方面提供的接入控制方法的步骤。
不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本申请的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1A为本申请实施例提供的一种无线通信系统的架构示意图;
图1B为本申请中第一接入方式下网元间的关系示意图;
图2为本申请一实施例的接入控制方法的流程示意图;
图3为本申请另一实施例的接入控制方法的流程示意图;
图4为本申请又一实施例的接入控制方法的流程示意图;
图5为本申请又一实施例的接入控制方法的流程示意图;
图6为本申请实施例的应用场景1的服务鉴权的指示过程的流程图;
图7为本申请实施例的应用场景2的服务选择过程的流程图;
图8为本申请实施例的应用场景3的服务选择过程的流程图;
图9为本申请实施例的一种接入控制装置的结构图;
图10为本申请实施例的另一种接入控制装置的结构图;
图11为本申请实施例的另一种接入控制装置的结构图;
图12为本申请实施例的另一种接入控制装置的结构图;
图13为本申请实施例的一种通信设备的结构图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。
图1A示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以包括支持终端功能的中继和/或支持中继功能的终端,终端11也可以称作终端设备或者用户终端 (User Equipment,UE),终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、移动上网装置(Mobile Internet Device,MID)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、可穿戴式设备(Wearable Device)或车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)等终端侧设备,可穿戴式设备包括:手环、耳机、眼镜等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以是基站或核心网,其中,基站可被称为节点B、演进节点B、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、B节点、演进型B节点(eNB)、家用B节点、家用演进型B节点、WLAN接入点、WiFi节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例,但是并不限定基站的具体类型。
在一些通信场景中,存在通信设备没有网络的证书却需要接入网络的场景,例如:在独立非公用网络(Standalone Non-public Network,SNPN)部署时,UE可能还没有能够用于接入SNPN的证书和UE标识。比如工厂部署的SNPN和刚在市场上采购的终端,或者在演唱会现场部署的SNPN和观众的终端。
为了让这种类型的UE获取用于接入SNPN的证书和UE标识,UE可以接入某个网络(后续称为第一网络),下载用于接入SNPN的证书。比如UE接入第一网络,建立一条数据通道,并通过所述数据通道连接配置服务器,从配置服务器下载SNPN的证书或者UE接入第一网络,第一网络的控制网元代替UE向配置服务器下载SNPN的证书。
为了下载用于接入第二网络的证书而接入第一网络的方式可以称为onboarding。第一网络和第二网络可以是同一个网络。
当UE没有第一网络的证书的情况下,第一网络需要对UE进行认证才 可以为UE下载证书或者是建立用于下载证书的数据通道。UE上可能具有默认证书,此时,第一网络可以请求默认证书鉴权服务器(DCS Default Credential Server)对具有默认证书的UE进行认证。DCS可以直接认证UE或者或请求其他实体对UE进行认证。
这种类型的认证类比UE在漫游接入其他网络的认证但又不同于UE漫游认证。
-在漫游的情况下,UE访问的网络的接入和移动性管理功能(Access and Mobility Management Function,AMF)为UE选择UE归属网络的鉴权服务器(Home-Authentication Server Function,归属AUSF),并请求归属AUSF对UE进行认证。
-在onboarding方式下,如图1B所示,第一网络的AMF可以为UE选择UE访问的第一网络下的认证代理服务器(比如,鉴权服务器功能(Authentication Server Function,AUSF),或者AAA(Authentication Authorization Accounting Server)服务器代理),并由认证代理服务器来请求另一网络中默认鉴权服务器(Default Credential Server,DCS)对UE进行认证。当UE具有的默认证书是通信网络(如3GPP的网络)的证书时,DCS可以是UE归属网络的归属AUSF。NRF保存有网元的关系,可以被调用进行网元的查询。
具有公共陆地移动网(Public Land Mobile Network,PLMN)证书的UE可以:1)通过PLMN证书漫游接入其他PLMN网络,2)通过PLMN证书接入SNPN,3)还可以onboarding到第一网络进行默认证书认证。其中,对于方式1),UE接入网络的AMF与UE归属网络的AUSF联系。对于方式3),UE接入网络的AMF与接入网络的认证代理服务器(如AUSF,或AAA服务器代理)联系,所述认证代理服务器与UE归属AUSF联系。对于方式2),可能采用方式1)的认证结构也可能采用方式3)的认证结构。
为了支持方式3)的认证结构,还要解决如下问题:
问题1:目前的AMF连接的AUSF选择是,AMF根据UE提供的签约永久标识(Subscription Permanent Identifier,SUPI)中的归属网络标识(Home Network Identifier)或者SUPI关联的AUSF组标识(Group ID)进行选择的。 但是在onboarding的架构中,第一网络的AMF需为UE选择第一网络中的AUSF,AUSF再为UE选择UE归属地的AUSF。第一网络的AUSF与UE无关,与UE的SUPI无关。如何区分不同接入类型的UE选择不同的AUSF成为一个需要解决的问题。
本申请实施例中,可选的,获取可以理解为从配置获得、接收、通过请求后接收、通过自学习获取、根据未收到的信息推导获取或者是根据接收的信息处理后获得,具体可根据实际需要确定,本申请实施例对此不作限定。比如当未收到设备发送的某个能力指示信息时可推导出该设备不支持该能力。
可选的,发送可以包含广播,系统消息中广播,响应请求后返回。
在本申请一种实施例中,非公网是非公众网络的简称。非公众网络可以称为以下之一:非公众通信网络。非公网可以包括以下至少一种部署方式:物理的非公网、虚拟的非公网、实现在公网上的非公网。一种实施方式中,非公网为封闭访问组(Closed Access Group,CAG)。一个CAG可以由一组终端组成。
在本申请一种实施例中,非公网服务是非公众网络服务的简称。非公众网络服务也可以称为以下之一:非公众网络的网络服务、非公众通信服务、非公众网络通信服务、非公网的网络服务或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。一种实施方式中,非公网为封闭访问组,此时,非公网服务为封闭的访问组的网络服务。
在本申请一种实施例中,非公众网络可以包含或称为私有网络。私有网络可以称为以下之一:私有通信网络、私网、本地区域网络(LAN)、私有虚拟网络(Private Virtual Network,PVN)、隔离的通信网络、专用的通信网络或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。
在本申请一种实施例中,公网是公众网络的简称。公众网络可以称为以下之一:公众通信网络或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。
本申请一种可选实施例中,鉴权服务包括向鉴权服务器(如DCS,或归属AUSF)发起对终端的鉴权请求。鉴权服务网元可以是为终端提供鉴权服务的鉴权代理。可选的,所述鉴权服务网元可以包括但不限于以下之一:AUSF、 AAA代理。
本申请一种可选实施例中,第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。
本申请一种可选实施例中,所述终端接入第一网络的证书为默认证书是指终端接入第一网络时,向第一网络提供的终端的标识对应的证书为默认证书。一种实施方式中,所述默认证书不是第一网络的证书。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
本申请一种可选实施例中,所述第一网络的网络类型可以包括但不限于以下之一:公网(如PLMN),独立非公网(如NPN),公网集成的非公网(如PNI NPN)。
本申请一种可选实施例中,不具有能够接入第一网络的证书包括不具有能够访问第一网络的非受限服务的证书。
1)一种实施方式中,终端直接具有B网络的证书,可以认为终端具有能够接入B网络的证书。
2)另一种实施方式中,服务提供方A(包括A网络)与B网络间存在允许A的终端接入B网络享受网络服务的协议(如漫游协议),此时,可以认为A的终端具有能够接入B网络的证书,即A的证书。此中,服务提供方A的终端和B网络的终端接入B网络,可以认为访问的是非受限服务。
3)另一种实施方式中,服务提供方C(包括C网络)的终端为了下载接入B网络的证书而接入B网络的方式中,终端具有的C的证书能够帮助B网络请求C中的鉴权服务器验证终端。此时终端具有的C的证书并不是能够接入B网络的证书,而是B网络能够验证终端的证书,一般称为默认证书。此中,服务提供方C的终端接入B网络,可以认为访问的是受限服务。
本申请一种可选实施例中,认证提供方为能够对具有默认证书的终端进行验证的提供方。一种实施方式中,所述认证提供方不包括漫游场景中的终端归属网络。
本申请一种可选实施例中,所述终端的认证提供方的信息包括以下至少 一项:终端的默认证书对应网络的网络标识,终端的默认证书对应的终端的标识中的网络标识,终端的归属网络的网络标识,默认证书验证提供方的索引信息,DCS的索引信息。不难理解。终端的证书与终端的标识对应。所述终端的认证提供方的信息可以包含在终端的标识中。
本申请一种可选实施例中,所述终端的第一标识包括以下之一:终端的默认证书对应的终端标识,或者终端在DCS中的终端标识。
一种实施方式中,所述终端的归属网络的标识为终端的默认证书对应的终端的标识中的网络的标识。另一种实施方式中,所述终端的归属网络标识为验证提供方网络的标识。
可选的,DCS是终端的认证提供方中的设备。当DCS包括终端归属的AUSF时,所述终端的第一标识为终端在归属网络中的终端标识。此时,默认证书验证方的索引信息或DCS的索引信息为终端的归属网络的标识。
本申请一种可选实施例中,所述归属网络可以为终端的默认证书对应的网络。一种实施方式中,归属AUSF为归属网络中的AUSF。归属NRF为归属网络中的NRF。其他归属网元为归属网络中的网元。
本申请一种可选实施例中,第一类型的网络标识包括第一类型的归属网络标识。用于第一接入方式的归属网络标识包括用于第一接入方式的归属网络标识。第一类型的归属网络标识包括:用于第一接入方式的归属网络标识。
本申请一种另可选实施例中,第一类型的网络标识可以是以下之一:认证提供方的网络标识,终端的默认证书对应的网络标识,终端的默认证书对应的终端的标识中的网络标识。
本申请一种可选实施例中,通信设备可以包括以下至少一项:通信网元和终端。
本申请一种实施例中,通信网元可以包括以下至少一项:核心网网元和无线接入网网元。
本申请实施例中,核心网网元(CN网元)可以包含但不限于如下至少一项:核心网设备、核心网节点、核心网功能、核心网网元、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access Management Function,AMF)、网络存储功能(Network Repository Function,NRF)、会话 管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、服务网关(serving GW,SGW)、PDN网关(PDN Gate Way)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、GPRS服务支持节点(Serving GPRS Support Node,SGSN)、网关GPRS支持节点(Gateway GPRS Support Node,GGSN)、统一数据管理(Unified Data Management,UDM),统一数据存储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)和应用功能(Application Function,AF)。
以下对本申请实施例的接入控制方法进行说明。
请参考图2,本申请实施例提供了一种接入控制方法,应用于第一通信设备;该第一通信设备包括AMF。可选的,该第一通信设备为第一网络中的通信设备。如图2所示,所述方法包括:
步骤21:获取第一信息和/或第二信息。
其中,所述第一信息包括但不限于以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识。所述第二信息包括但不限于以下至少一项:第一类型的路由指示、第一类型的网络标识、第一类型的组标识、终端的标识信息。
可选的,所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识。
可选的,所述第一类型的网络标识包括:用于第一接入方式的网络标识。
可选的,所述第一类型的路由指示包括:用于第一接入方式的路由指示。
一种实施方式中,可以从终端接收获取第一信息。上述的第一信息可以包含在终端的标识(如SUCI,或SUPI等)中进行发送。
另一种实施方式中,可以第一通信设备本地配置获取第二信息。
所述终端的标识信息可以包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识。
1)所述终端的第一标识包含终端的认证提供方的信息。所述认证提供方为能够对具有默认证书的终端进行验证的提供方,或者是能够认证终端的提供方(如终端的归属网络,终端的默认证书对应的网络)。一种实施方式中, 所述认证提供方不包括漫游场景中的终端归属网络
所述终端的认证提供方的信息包括以下至少一项:终端的默认证书对应网络的网络标识,终端的默认证书对应的终端的标识中的网络标识,终端的归属网络的网络标识,默认证书验证提供方的索引信息,DCS的索引信息。不难理解。终端的证书与终端的标识对应。所述终端的认证提供方的信息可以包含在终端的标识中。
所述终端的第一标识包括以下之一:终端的默认证书对应的终端标识,或者终端在DCS中的终端标识。
可选的,DCS是终端的认证提供方中的设备。当DCS包括终端归属的AUSF时,所述终端的第一标识为终端在归属网络中的终端标识。此时,默认证书验证方的索引信息或DCS的索引信息为终端的归属网络的标识。
2)所述终端的第二标识包含第一类型的网络标识和/或第一类型的路由指示;
3)所述终端的第三标识中包含终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
不难理解,根据终端的第二标识或根据终端的第三标识,可以确定第一类型的网络标识和/或第一类型的路由指示。
1)一种实施方式中,可发送终端的第一标识和第一类型的网络标识。
2)另一种实施方式中,可发送终端的第一标识和第一类型的路由指示。
3)另一种实施方式中,可发送终端的第一标识和终端的第二标识。
4)另一种实施方式中,可发送终端的第三标识。
步骤22:根据第一信息和/或第二信息,执行第一操作。
其中,所述第一操作可以包括以下至少一项:
选择第一鉴权服务网元;
确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;
根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元。
可选的,所述第一接入方式的指示信息可用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
一种实施方式中,第一接入方式的指示信息包括第一注册类型。而第一注册类型可以用于指示以下至少一项:为了下载用于接入第二网络的证书而注册接入第一网络的注册方式、不具有能够接入第一网络的证书而注册第一网络的注册方式。
可选的,上述能够接入第一网络的证书包括能够访问第一网络的非受限服务的证书。上述不具有能够接入第一网络的证书包括不具有能够访问第一网络的非受限服务的证书。
1)一种实施方式中,终端直接具有B网络的证书,可以认为终端具有能够接入B网络的证书。
2)另一种实施方式中,服务提供方A(包括A网络)与B网络间存在允许A的终端接入B网络享受网络服务的协议(如漫游协议),此时,可以认为A的终端具有能够接入B网络的证书,即A的证书。此中,服务提供方A的终端和B网络的终端接入B网络,可以认为访问的是非受限服务。
3)另一种实施方式中,服务提供方C(包括C网络)的终端为了下载接入B网络的证书而接入B网络的方式中,终端具有的C的证书能够帮助B网络请求C中的鉴权服务器验证终端。此时终端具有的C的证书并不是能够接入B网络的证书,而是B网络能够验证终端的证书,一般称为默认证书。此中,服务提供方C的终端接入B网络,可以认为访问的是受限服务。
可选的,上述的第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元。
一种实施方式中,所述鉴权服务包括向鉴权服务器(如DCS,或归属AUSF)发起对终端的鉴权请求。
本申请实施例中,上述根据第一类型的组标识、第一类型的路由指示、 第一类型的网络标识或第一接入方式的指示信息,请求发现鉴权服务网元可包括以下至少一项:
向第一目标端发送所述第一类型的组标识,所述第一类型的组标识用于所述第一目标端发现匹配所述第一类型的组标识的鉴权服务网元;
向第一目标端发送所述第一接入方式的指示信息,所述第一接入方式的指示信息用于所述第一目标端发现匹配所述第一接入方式的指示信息的鉴权服务网元;
向第一目标端发送所述第一类型的路由指示,所述第一类型的路由指示用于所述第一目标端发现匹配所述第一类型的路由指示的鉴权服务网元。
向第一目标端发送所述第一类型的网络标识,所述第一类型的网络标识用于所述第一目标端发现匹配所述第一类型的网络标识的鉴权服务网元。
可选的,所述第一目标端可以包括:负责查询网络中网元的网元设备,比如网络存储库功能(Network Repository Function,NRF)。
可选的,所述鉴权服务网元可以包括但不限于以下之一:AUSF、AAA代理。一种实施方式中,鉴权服务网元可以是为终端提供鉴权服务的鉴权代理。
一种实施方式中,可以通过专用于第一接入方式的AUSF组标识向NRF请求发现AUSF。
可选的,上述获取第一信息可包括:从终端获取第一信息。和/或,上述获取第二信息可包括:根据第一通信设备上的配置,获取第二信息。
可选的,上述获取第一信息和/或第二信息可以包括以下至少一项:
从终端获取第一接入方式的指示信息;
根据第一通信设备上的配置,获取第一类型的组标识、第一类型的路由指示或者第一类型的网络标识。
进一步的,上述根据第一信息和/或第二信息,执行第一操作可以包括:
根据所述第一接入方式的指示信息,确定第一类型的组标识、第一类型的路由指示或第一类型的网络标识;
根据所述第一类型的组标识、第一类型的路由指示和/或第一类型的网络标识,请求发现鉴权服务网元。
可选的,上述获取第一信息和/或第二信息可以包括以下至少一项:
从终端获取第一类型的网络标识和/或第一类型的路由指示,
根据第一通信设备上的配置,获取第一类型的组标识;
进一步的,上述根据第一信息和/或第二信息,执行第一操作可以包括:
根据所述第一类型的网络标识和/或第一类型的路由指示,确定第一类型的组标识;
根据所述第一类型的组标识,请求发现鉴权服务网元。
可选的,上述的第一操作还包括以下至少一项:
接收请求发现的鉴权服务网元;
根据终端的第二标识或终端的第三标识导出第一类型的网络标识和/或第一类型的路由指示;
不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;
根据终端的第三标识,导出终端的第一标识;
向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第一标识。
不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。
请参考图3,本申请实施例提供了一种接入控制方法,应用于第二通信设备;该第二通信设备包括UE。如图3所示,所述方法包括:
步骤31:发送第一信息。
其中,所述第一信息包可以包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息。
所述第一类型的路由指示包括:用于第一接入方式的路由指示。
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。
所述第一网络和所述第二网络是同一个网络或不同的网络。
可选的,向终端接入的第一网络发送所述第一信息。终端接入第一网络的方式为第一接入方式。上述的第一信息可以包含在终端的标识(如SUCI, 或SUPI等)中进行发送。
可选的,上述发送第一信息可以包括:在满足第一条件的情况下,发送所述第一信息。其中,所述第一条件可以包括以下至少一项:
第二通信设备接入第一网络的目是为了下载用于接入第二网络的证书;
第二通信设备不具有能够接入第一网络的证书;
第二通信设备接入第一网络仅能够使用受限服务。
所述第一网络和所述第二网络是同一个网络或不同的网络。
一种实施方式中,所述用于第一接入方式的网络标识是通过终端的用户永久标识SUPI发送的。
需指出的,所述第二通信设备不具有能够接入第一网络的证书包括:第二通信设备不具有第一网络的证书或者第二通信设备不具有能够接入第一网络的服务提供方的证书。
上述能够接入第一网络的证书可以包括能够访问第一网络的非受限服务的证书。上述不具有能够接入第一网络的证书包括不具有能够访问第一网络的非受限服务的证书。
1)一种实施方式中,终端直接具有B网络的证书,可以认为终端具有能够接入B网络的证书。
2)另一种实施方式中,服务提供方A(包括A网络)与B网络间存在允许A的终端接入B网络享受网络服务的协议(如漫游协议),此时,可以认为A的终端具有能够接入B网络的证书,即A的证书。此中,服务提供方A的终端和B网络的终端接入B网络,可以认为访问的是非受限服务。
3)另一种实施方式中,服务提供方C(包括C网络)的终端为了下载接入B网络的证书而接入B网络的方式中,终端具有的C的证书能够帮助B网络请求C中的鉴权服务器验证终端。此时终端具有的C的证书并不是能够接入B网络的证书,而是B网络能够验证终端的证书,一般称为默认证书。此中,服务提供方C的终端接入B网络,可以认为访问的是受限服务。
可选的,所述终端的标识信息可以包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识。
1)所述终端的第一标识包含终端的认证提供方的信息。所述认证提供方 为能够对具有默认证书的终端进行验证的提供方,或者是能够认证终端的提供方(如终端的归属网络)。
所述终端的认证提供方的信息包括以下至少一项:终端的默认证书对应网络的网络标识,终端的默认证书对应的终端的标识中的网络标识,终端的归属网络的网络标识,默认证书验证提供方的索引信息,DCS的索引信息。所述终端的认证提供方的信息可以包含在终端的标识中。
不难理解。终端的证书与终端的标识对应。所述终端的第一标识包括以下之一:终端的默认证书对应的终端标识,或者终端在DCS中的终端标识。
可选的,DCS是终端的认证提供方中的设备。当DCS包括终端归属的AUSF时,所述终端的第一标识为终端在归属网络中的终端标识。此时,默认证书验证方的索引信息或DCS的索引信息为终端的归属网络的标识。
2)所述终端的第二标识包含第一类型的网络标识和/或第一类型的路由指示;
3)所述终端的第三标识中包含终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
不难理解,根据终端的第二标识或根据终端的第三标识,可以确定第一类型的网络标识和/或第一类型的路由指示。
1)一种实施方式中,可发送终端的第一标识和第一类型的网络标识。
2)另一种实施方式中,可以发送终端的第一标识和第一类型的路由指示。
3)另一种实施方式中,可以发送终端的第一标识和终端的第二标识。
4)另一种实施方式中,可以发送终端的第三标识。
可选的,在发送第一信息的步骤之前,所述方法还可包括以下至少一项:
生成终端的第二标识,即将终端的标识中的路由指示设置为第一类型的路由指示和/或将终端的标识中的归属网络标识设置为第一类型的网络标识;
生成终端的第三标识,即将第一类型的网络标识添加到终端的标识中和/或将第一类型的路由指示添加到终端的标识中。
一种实施方式中,所述生成终端的第二标识和/或生成终端的第三标识的操作是在满足第一条件的情况下执行的。第一条件如上所述,此处不再赘述。
不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一 网络的场景下,,支持对鉴权服务网元的选择。
请参考图4,本申请实施例提供了一种接入控制方法,应用于第三通信设备;该第三通信设备包括NRF。可选地,该第三通信设备为第一网络中的通信设备。如图4所示,所述方法包括:
步骤41:获取第三信息和/或第四信息。
可选的,所述第三信息可以包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息。
可选的,所述第四信息用于指示鉴权服务网元的归属信息。所述第四信息可以包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证。
可选的,所述第一接入方式的指示信息可用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。
可选的,所述第一网络和所述第二网络是同一个网络或不同的网络。
可选的,所述第一类型的路由指示包括:用于第一接入方式的路由指示。
一种实施方式中,所述受限服务包括下载能够接入网络的证书的服务。
可选的,所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识。
一种实施方式中,可以从AMF获取第三信息。
另一种实施方式中,可以从鉴权服务网元(如AUSF或AAA代理)获取第四信息,即鉴权服务网元的归属信息。
步骤42:根据第三信息和/或第四信息,执行第三操作。
其中,所述第三操作可以包括以下至少一项:
发现匹配所述第三信息的鉴权服务网元,即所述鉴权服务网元的第四信息与所述第三信息相匹配;
发送所述发现的鉴权服务网元。
其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务。
一种实施方式中,向第二目标端发送所述发现的鉴权服务网元。所述的第二目标端包括:AMF。一种实施方式中,从第二目标端接收所述第三信息。
可选的,鉴权服务网元可以包括以下之一:AUSF,AAA代理。
一种实施方式中,匹配第三信息的鉴权服务网元为第一鉴权服务网元。所述第一鉴权服务网元包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。
一种实施方式中,所述第一类型的组标识包括以下之一:AUSF Group ID、AAA代理group ID。
一种实施方式中,可以向NRF请求发现AUSF。
可选的,在发现匹配所述第三信息的鉴权服务网元的操作中,当所述第三信息包括第一接入方式的指示信息的情况下,所述发现的鉴权服务网元支持的接入方式为第一接入方式;或者,当所述第三信息包括第一类型的路由指示的情况下,所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;或者,当所述第三信息包括第一类型的网络标识的情况下,所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;或者,当所述第三信息包括第一类型的组标识的情况下,所述发现的鉴权服务网元所属的组标识为第一类型的组标识;或者,当所述第三信息包括认证提供方的信息,所述发现的鉴权服务网元支持的认证提供方信息包括所述第三信息中的认证提供方的信息。
或者,所述发现的鉴权服务网元满足至少以下一项:
所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;
所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;
所述发现的鉴权服务网元所属的组标识为第一类型的组标识;
所述发现的鉴权服务网元支持的接入方式为第一接入方式;
所述发现的鉴权服务网元支持的鉴权服务类型为支持对具有默认证书的终端提供鉴权服务。
不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。
请参考图5,本申请实施例提供了一种接入控制方法,应用于第四通信设备;该第四通信设备包括AUSF。可选地,该第四通信设备为第一网络中的通信设备。如图5所示,所述方法包括:
步骤51:发送第四信息。
其中,所述第四信息用于指示鉴权服务网元的归属信息。所述第四信息可以包括以下至少一项:鉴权服务网元支持的路由指示,鉴权服务网元所属网络的网络标识,鉴权服务网元所属的组标识,鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证。
其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示。
所述鉴权服务网元所属网络的网络标识为第一类型的网络标识。
所述鉴权服务网元所属的组标识为第一类型的组标识。
所述鉴权服务网元支持的接入方式包括第一接入方式。
所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务(比如作为鉴权代理)。
所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识。
所述第一类型的第一类型的路由指示包括:用于第一接入方式的路由指示。
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
可选的,上述发送第四信息可以包括:在满足第二条件的情况下,发送所述第四信息;其中,所述第二条件包括:所述鉴权服务网元为用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。
不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。
本申请实施例提供了一种接入控制方法,应用于第五通信设备;该第四通信设备包括以下至少一项:AMF,AUSF,UDM。可选地,该第五通信设备为第一网络中的通信设备。所述方法包括:
在满足第五条件的情况下,执行第五操作;
所述第五操作包括以下至少一项:
不使用第五信息为终端选择网元;
其中,
所述第五条件包括以下至少一项:所述终端为第一接入方式;
所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。
一种实施方式中,对通过非第一接入方式接入网络的终端,根据终端的用户标识中的信息来为终端选择网络设备是默认操作。因此对通过非第一接入方式接入网络的终端,需要执行例外操作。
其中,所述终端用户标识中网络标识信息包括以下至少一项;终端用户标识中MNC,终端用户标识中MCC,终端用户标识中网络标识NID。
可选地,所述在满足第五条件的情况下,执行第五操作的步骤之前,所述方法还包括:获得第一信息,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;其中,
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
可选地,所述获得第一信息的步骤之后,根据第一信息确定满足第五条件。
可选地,所述网元包括以下至少一项:核心网网元,鉴权服务功能AUSF,统一数据管理UDM,统一数据存储UDR。
一种实施方式中,所述网元可以是网络设备。
下面结合具体应用场景对本申请实施例提供的方法进行描述。
应用场景一
本应用场景一中,如图6所示,服务鉴权的指示过程可包括:
步骤61:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元(后续以AUSF作为实例说明)向NRF发起注册请求,比如Nnrf_NF Management_NF Register。
可选的,该注册请求中包括第四信息,该第四信息用于指示鉴权服务网元的归属信息,该第四信息可以包括以下至少一项:鉴权服务网元所属网络的网络标识,鉴权服务网元所属的组标识,鉴权服务网元支持的接入方式。
一种实施方式中,通过鉴权服务网元所属网络的网络标识是第一类型的归属的网络标识的情况下,可说明鉴权服务网元用于对第一接入方式的终端提供鉴权服务。
另一种实施方式中,通过鉴权服务网元所属的组标识是第一类型的组标识的情况下,可说明鉴权服务网元用于对第一接入方式的终端提供鉴权服务。
应用场景二
本应用场景二中,UE注册第一网络,所述注册类型是第一接入方式。第 一网络需要请求DCS对UE进行认证。AMF,NRF,AUSF为第一网络中的通信设备,归属NRF和归属AUSF为UE归属网络中的设备,所述归属AUSF为DCS的一种实施例。如图7所示,选择AUSF的过程可包括:
步骤71:UE向AMF发起注册请求,其中,该注册请求的注册类型为第一接入方式的指示信息(如第一注册类型)。
步骤72:AMF根据UE提供的第一接入方式的指示信息(如第一注册类型),执行AUSF的选择操作,包括以下至少一项:
(1)选择本地配置的用于第一接入方式的AUSF;
(2)选择本地配置的用于第一接入方式的AUSF的组标识(AUSF Group ID),并根据该AUSF组标识向NRF请求发现AUSF;
(3)通过网络功能发现请求,比如Nnrf_NF Discovery_Request,向NRF发送第一接入方式的指示信息,用于请求发现支持第一接入方式的AUSF;
不难理解,在此之前,AUSF注册NRF时要对应提供其支持的接入方式,如第一接入方式。
(4)通过网络功能发现请求,比如Nnrf_NF Discovery_Request,向NRF发送第一类型的网络标识(Home Network ID);
不难理解,在此之前,支持第一接入方式的AUSF注册NRF时要对应提供鉴权服务网元所属网络的网络标识为第一接入方式的网络标识。比如专用于第一接入方式的网络标识。
(5)通过网络功能发现请求,比如Nnrf_NF Discovery_Request,向NRF发送第一类型的组标识;
不难理解,在此之前,支持第一接入方式的AUSF注册NRF时要对应提供鉴权网元所属的组标识为第一接入方式的网络标识。比如专用于第一接入方式的鉴权服务网元的组标识。
步骤73:NRF根据获取的第三信息和/或第四信息,执行第三操作。
其中,所述第三信息可包括以下至少一项:第一类型的组标识、第一类型的网络标识、第一接入方式的指示信息。所述第四信息用于指示鉴权服务网元的归属信息。所述第四信息可包括以下至少一项:鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式。
其中,所述第三操作包括以下至少一项:
发现匹配所述第三信息的鉴权服务网元(后续以AUSF示例说明);
向AMF发送所述发现的鉴权服务网元。
步骤74:AMF向AUSF发送UE认证请求,比如Nausf_UEAuthentication_Authenticate Request。其中,该请求中可包括终端的第一标识(UE真实的第一SUCI或者第一SUPI)。
步骤75至步骤78:AUSF根据终端的第一标识、或第一UE标识中的归属网络标识,或第一UE标识对应AUSF组标识等,通过NRF和归属NRF发现归属AUSF。
具体的,步骤75中,AUSF向NRF发送网络功能发现请求,比如Nnrf_NF Discovery_Request。其中,该发现请求中可包括以下之一:终端的第一标识、终端的归属网络标识Home Network ID、与终端的第一标识相关的AUSF组标识等。
步骤76中,NRF向归属NRF发送网络功能发现请求,比如Nnrf_NF Discovery_Request。其中,该发现请求中可包括终端的第一标识、或第一UE标识中的归属网络标识,或第一UE标识对应AUSF组标识AUSF组标识等。
步骤77中,归属NRF向NRF返回网络功能发现响应,比如Nnrf_NF Discovery_Response。
步骤78中,NRF向AUSF返回网络功能发现响应,比如Nnrf_NF Discovery_Response。
步骤79:AUSF向归属AUSF发起UE认证请求,比如Nausf_UE Authentication_Authenticate Request。其中,该请求中包括生成的第二SUCI或者第一SUPI、SN-name、第一接入方式的指示信息等。
之后,归属AUSF可以向UE发起认证过程。
应用场景三
本应用场景三中,UE注册第一网络,提供终端的标识信息。第一网络需要请求DCS对UE进行认证。AMF,NRF,AUSF为第一网络中的通信设备,归属NRF和归属AUSF为UE归属网络中的设备,所述归属AUSF为DCS的一种实施例。如图8所示,选择AUSF的过程可包括:
步骤81:UE向AMF发起注册请求。可选地,该注册请求中包含第一信息。示例性地,比如终端的标识信息。
所述终端的标识信息可以包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包含终端的认证提供方的信息;
所述终端的第二标识包含第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包含终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
AMF可以执行:根据终端的第二标识或终端的第三标识,导出第一类型的网络标识和/或第一类型的路由指示;
所述第一类型的网络标识是专用于第一接入方式的特定取值,如111。
所述第一类型的路由指示是专用于第一接入方式的特定取值。
1)一种实施方式中,所述注册请求中包含终端的第一标识和第一类型的网络标识。
2)另一种实施方式中,所述注册请求中包含终端的第一标识和终端的第二标识。
3)另一种实施方式中,所述注册请求中包含终端的第三标识。
当终端的第一标识(SUPI或SUPI)指示的是PLMN或SNPN的签约时,所述DCS索引信息中包含UE的SUPI真正的Home Network ID。
步骤82:AMF向NRF发送网络功能发现请求比如Nnrf_NF Discovery_Request,即根据第一接入方式的归属网络标识向NRF请求查询AUSF,获取AUSF。
可选地,该请求中包含AUSF的Home Network ID和/或Group ID。
步骤83:NRF向AMF返回发送的发现的鉴权服务网元即AUSF。
步骤84:AMF向AUSF发送UE认证请求,比如Nausf_UEAuthentication_Authenticate Request。
可选的,AMF可以执行以下至少一项:
不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;
根据终端的第三标识导出终端的第一标识;
向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第一标识。
步骤85至步骤89:同应用场景二中的步骤75至79,此处不再赘述。
请参考图9,本申请实施例提供了一种接入控制装置,应用于第一通信设备,如图9所示,该接入控制装置90包括:
第一获取模块91,用于获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;
第一执行模块92,用于根据所述第一信息和/或所述第二信息,执行第一操作;
其中,所述第一操作包括以下至少一项:
选择第一鉴权服务网元;
确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;
根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;
其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或者不同的网络;
其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
可选的,所述第一执行模块92还用于执行以下至少一项:
向第一目标端发送所述第一类型的组标识,所述第一类型的组标识用于所述第一目标端发现匹配所述第一类型的组标识的鉴权服务网元;
向第一目标端发送所述第一接入方式的指示信息,所述第一接入方式的指示信息用于所述第一目标端发现匹配所述第一接入方式的指示信息的鉴权服务网元;
向第一目标端发送所述第一类型的路由指示,所述第一类型的路由指示用于所述第一目标端发现匹配所述第一类型的路由指示的鉴权服务网元。
向第一目标端发送所述第一类型的网络标识,所述第一类型的网络标识用于所述第一目标端发现匹配所述第一类型的网络标识的鉴权服务网元。
可选的,所述第一获取模块91具体用于:从终端获取第一信息。
可选的,所述第一获取模块91具体用于:根据第一通信设备上的配置,获取第二信息。
可选的,所述第一获取模块91具体用于以下至少一项:
从终端获取第一接入方式的指示信息;
根据第一通信设备上的配置,获取第一类型的组标识、第一类型的路由指示或者第一类型的网络标识;
其中,所述根据所述第一信息和/或所述第二信息,执行第一操作包括以下至少一项:
根据所述第一接入方式的指示信息,确定第一类型的组标识、第一类型的路由指示或第一类型的网络标识;
根据所述第一类型的组标识、第一类型的路由指示和/或第一类型的网络标识,请求发现鉴权服务网元。
可选的,所述第一获取模块91具体用于以下至少一项:
从终端获取第一类型的网络标识和/或第一类型的路由指示,
根据第一通信设备上的配置,获取第一类型的组标识;
其中,所述根据所述第一信息和/或所述第二信息,执行第一操作包括以下至少一项:
根据所述第一类型的网络标识和/或第一类型的路由指示,确定第一类型的组标识;
根据所述第一类型的组标识,请求发现鉴权服务网元。
可选的,所述第一操作还包括以下至少一项:
接收请求发现的鉴权服务网元;
根据所述终端的第二标识或终端的第三标识,导出第一类型的网络标识和/或第一类型的路由指示;
不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;
根据所述终端的第三标识,导出终端的第一标识;
向所述第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第一标识。
本实施例中,接入控制装置90能够实现本申请图2所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图10,本申请实施例提供了一种接入控制装置,应用于第二通信设备,如图10所示,该接入控制装置100包括:
第一发送模块101,用于发送第一信息;
其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的 证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或不同的网络;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
可选的,所述第一发送模块101具体用于:在满足第一条件的情况下,发送所述第一信息;
其中,所述第一条件包括以下至少一项:
第二通信设备接入第一网络的目是为了下载用于接入第二网络的证书;
第二通信设备不具有能够接入第一网络的证书;
第二通信设备接入第一网络仅能够使用受限服务。
可选的,该接入控制装置100还包括:
生成模块,用于生成终端的第二标识,将终端的标识中的路由指示设置为第一类型的路由指示和/或将终端的标识中的归属网络标识设置为第一类型的网络标识;和/或
生成终端的第三标识,将第一类型的网络标识添加到终端的标识中和/或将第一类型的路由指示添加到终端的标识中。
本实施例中,接入控制装置100能够实现本申请图3所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图11,本申请实施例提供了一种接入控制装置,应用于第二通信设备,如图11所示,该接入控制装置110包括:
第二获取模块111,用于获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息;所述第四信 息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
第二执行模块112,用于根据所述第三信息和/或所述第四信息,执行第三操作;
其中,所述第三操作包括以下至少一项:
发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;
发送所述发现的鉴权服务网元;
其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一网络和所述第二网络是同一个网络或不同的网络;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
可选的,在发现匹配所述第三信息的鉴权服务网元的操作中,
当所述第三信息包括第一接入方式的指示信息的情况下,所述发现的鉴权服务网元支持的接入方式为第一接入方式;
或者,当所述第三信息包括第一类型的路由指示的情况下,所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;
或者,当所述第三信息包括第一类型的网络标识的情况下,所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;
或者,当所述第三信息包括第一类型的组标识的情况下,所述发现的鉴权服务网元所属的组标识为第一类型的组标识。
或者,当所述第三信息包括认证提供方的信息,所述发现的鉴权服务网元支持的认证提供方信息包括所述第三信息中的认证提供方的信息;
或者,所述发现的鉴权服务网元满足至少以下一项:
所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;
所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;
所述发现的鉴权服务网元所属的组标识为第一类型的组标识;
所述发现的鉴权服务网元支持的接入方式为第一接入方式;
所述发现的鉴权服务网元支持的鉴权服务类型为支持对具有默认证书的终端提供鉴权服务。
本实施例中,接入控制装置110能够实现本申请图4所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图12,本申请实施例提供了一种接入控制装置,应用于第二通信设备,如图12所示,该接入控制装置120包括:
第二发送模块121,用于发送第四信息;
其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;
所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;
所述鉴权服务网元所属的组标识为第一类型的组标识;
所述鉴权服务网元支持的接入方式包括第一接入方式;
所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一 网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识。
可选的,所述第二发送模块121还用于:在满足第二条件的情况下,发送所述第四信息;
其中,所述第二条件包括:所述鉴权服务网元为用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。
本实施例中,接入控制装置120能够实现本申请图5所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
本申请还提供一种接入控制装置,应用于第五通信设备,包括:
第三执行模块,用于在满足第五条件的情况下,执行第五操作;
所述第五操作包括以下至少一项:
不使用第五信息为终端选择网元;
其中,
所述第五条件包括以下至少一项:所述终端为第一接入方式;
所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。
一种实施方式中,对通过非第一接入方式接入网络的终端,根据终端的用户标识中的信息来为终端选择网络设备是默认操作。因此对通过非第一接入方式接入网络的终端,需要执行例外操作。
其中,所述终端用户标识中网络标识信息包括以下至少一项;终端用户标识中MNC,终端用户标识中MCC,终端用户标识中网络标识NID。
可选地,所述装置还包括:
第三获取模块,用于获得第一信息,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;其中,
所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
所述第一类型的网络标识包括:用于第一接入方式的网络标识;
所述第一类型的路由指示包括:用于第一接入方式的路由指示;
所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
所述终端的第一标识包括终端的认证提供方的信息;
所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
可选地,所述装置还包括:
确定模块,用于根据第一信息确定满足第五条件。
可选地,所述网元包括以下至少一项:核心网网元,AUSF,UDM和UDR。
一种实施方式中,所述网元可以是网络设备。
参见图13,图13是本申请实施例提供的另一种通信设备的结构示意图,如图13所示,通信设备130包括:处理器131、存储器132及存储在所述存储器132上并可在所述处理器上运行的计算机程序,通信设备130中的各个组件通过总线接口133耦合在一起,所述计算机程序被所述处理器131执行时可实现上述图2所示方法实施例中实现的各个过程,或者,实现上述图3所示方法实施例中实现的各个过程,或者,实现上述图4所示方法实施例中实现的各个过程,或者,实现上述图5所示方法实施例中实现的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现上述图2所示方 法实施例中实现的各个过程,或者,实现上述图3所示方法实施例中实现的各个过程,或者,实现上述图4所示方法实施例中实现的各个过程,或者,实现上述图5所示方法实施例中实现的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。其中,所述的计算机可读存储介质,如只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (29)

  1. 一种接入控制方法,应用于第一通信设备,包括:
    获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;
    根据所述第一信息和/或所述第二信息,执行第一操作;
    其中,所述第一操作包括以下至少一项:
    选择第一鉴权服务网元;
    确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;
    根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;
    其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一网络和所述第二网络是同一个网络或者不同的网络;
    其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
    所述终端的第一标识包括终端的认证提供方的信息;
    所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
    所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
  2. 根据权利要求1所述的方法,其中,所述根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识或第一接入方式的指示信息,请求发现鉴权服务网元包括以下至少一项:
    向第一目标端发送所述第一类型的组标识,所述第一类型的组标识用于所述第一目标端发现匹配所述第一类型的组标识的鉴权服务网元;
    向第一目标端发送所述第一接入方式的指示信息,所述第一接入方式的指示信息用于所述第一目标端发现匹配所述第一接入方式的指示信息的鉴权服务网元;
    向第一目标端发送所述第一类型的路由指示,所述第一类型的路由指示用于所述第一目标端发现匹配所述第一类型的路由指示的鉴权服务网元;
    向第一目标端发送所述第一类型的网络标识,所述第一类型的网络标识用于所述第一目标端发现匹配所述第一类型的网络标识的鉴权服务网元。
  3. 根据权利要求1所述的方法,其中,
    所述获取第一信息包括:从终端获取第一信息;
    和/或,
    所述获取第二信息包括:根据第一通信设备上的配置,获取第二信息。
  4. 根据权利要求1所述的方法,其中,所述获取第一信息和/或第二信息包括以下至少一项:
    从终端获取第一接入方式的指示信息;
    根据第一通信设备上的配置,获取第一类型的组标识、第一类型的路由指示或者第一类型的网络标识;
    其中,所述根据所述第一信息和/或所述第二信息,执行第一操作包括以下至少一项:
    根据所述第一接入方式的指示信息,确定第一类型的组标识、第一类型 的路由指示或第一类型的网络标识;
    根据所述第一类型的组标识、第一类型的路由指示和/或第一类型的网络标识,请求发现鉴权服务网元。
  5. 根据权利要求1所述的方法,其中,所述获取第一信息和/或第二信息包括以下至少一项:
    从终端获取第一类型的网络标识和/或第一类型的路由指示;
    根据第一通信设备上的配置,获取第一类型的组标识;
    其中,所述根据所述第一信息和/或所述第二信息,执行第一操作包括以下至少一项:
    根据所述第一类型的网络标识和/或第一类型的路由指示,确定第一类型的组标识;
    根据所述第一类型的组标识,请求发现鉴权服务网元。
  6. 根据权利要求1所述的方法,其中,所述第一操作还包括以下至少一项:
    接收请求发现的鉴权服务网元;
    根据所述终端的第二标识或终端的第三标识,导出第一类型的网络标识和/或第一类型的路由指示;
    不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;
    根据所述终端的第三标识,导出终端的第一标识;
    向所述第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第一标识。
  7. 一种接入控制方法,应用于第二通信设备,包括:
    发送第一信息;
    其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识;
    所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的 证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一网络和所述第二网络是同一个网络或不同的网络;
    所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
    所述终端的第一标识包括终端的认证提供方的信息;
    所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
    所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
  8. 根据权利要求7所述的方法,其中,所述发送第一信息包括:
    在满足第一条件的情况下,发送所述第一信息;
    其中,所述第一条件包括以下至少一项:
    第二通信设备接入第一网络的目是为了下载用于接入第二网络的证书;
    第二通信设备不具有能够接入第一网络的证书;
    第二通信设备接入第一网络仅能够使用受限服务。
  9. 根据权利要求7所述的方法,其中,所述发送第一信息的步骤之前,所述方法还包括以下至少一项:
    生成终端的第二标识,将终端的标识中的路由指示设置为第一类型的路由指示和/或将终端的标识中的归属网络标识设置为第一类型的网络标识;
    生成终端的第三标识,将第一类型的网络标识添加到终端的标识中和/或将第一类型的路由指示添加到终端的标识中。
  10. 一种接入控制方法,应用于第三通信设备,包括:
    获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网 元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
    根据所述第三信息和/或所述第四信息,执行第三操作;
    其中,所述第三操作包括以下至少一项:
    发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;
    发送所述发现的鉴权服务网元;
    其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
    所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一网络和所述第二网络是同一个网络或不同的网络;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识。
  11. 根据权利要求10所述的方法,其中,在发现匹配所述第三信息的鉴权服务网元的操作中,
    当所述第三信息包括第一接入方式的指示信息的情况下,所述发现的鉴权服务网元支持的接入方式为第一接入方式;
    或者,当所述第三信息包括第一类型的路由指示的情况下,所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;
    或者,当所述第三信息包括第一类型的网络标识的情况下,所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;
    或者,当所述第三信息包括第一类型的组标识的情况下,所述发现的鉴权服务网元所属的组标识为第一类型的组标识;
    或者,当所述第三信息包括认证提供方的信息,所述发现的鉴权服务网 元支持的认证提供方信息包括所述第三信息中的认证提供方的信息;
    或者,所述发现的鉴权服务网元满足至少以下一项:
    所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;
    所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;
    所述发现的鉴权服务网元所属的组标识为第一类型的组标识;
    所述发现的鉴权服务网元支持的接入方式为第一接入方式;
    所述发现的鉴权服务网元支持的鉴权服务类型为支持对具有默认证书的终端提供鉴权服务。
  12. 一种接入控制方法,应用于第四通信设备,包括:
    发送第四信息;
    其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
    其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;
    所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;
    所述鉴权服务网元所属的组标识为第一类型的组标识;
    所述鉴权服务网元支持的接入方式包括第一接入方式;
    所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
    所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识。
  13. 根据权利要求12所述的方法,其中,所述发送第四信息包括:
    在满足第二条件的情况下,发送所述第四信息;
    其中,所述第二条件包括:所述鉴权服务网元为用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。
  14. 一种接入控制方法,应用于第五通信设备,包括:
    在满足第五条件的情况下,执行第五操作;
    所述第五操作包括以下至少一项:
    不使用第五信息为终端选择网元;
    其中,
    所述第五条件包括以下至少一项:所述终端为第一接入方式;
    所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。
  15. 根据权利要求14所述的方法,其中,所述在满足第五条件的情况下,执行第五操作的步骤之前,所述方法还包括:获得第一信息,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;其中,
    所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
    所述终端的第一标识包括终端的认证提供方的信息;
    所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
    所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
  16. 根据权利要求14所述的方法,其中,所述获得第一信息的步骤之后,
    根据第一信息确定满足第五条件。
  17. 根据权利要求14所述的方法,其中,所述网元包括以下至少一项:核心网网元,鉴权服务功能AUSF,统一数据管理UDM,统一数据存储UDR。
  18. 一种接入控制装置,应用于第一通信设备,包括:
    第一获取模块,用于获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;
    第一执行模块,用于根据所述第一信息和/或所述第二信息,执行第一操作;
    其中,所述第一操作包括以下至少一项:
    选择第一鉴权服务网元;
    确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;
    根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;
    其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一网络和所述第二网络是同一个网络或者不同的网络;
    其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务 的鉴权服务网元的组标识;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
    所述终端的第一标识包括终端的认证提供方的信息;
    所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
    所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
  19. 一种接入控制装置,应用于第二通信设备,包括:
    第一发送模块,用于发送第一信息;
    其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识;
    所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一网络和所述第二网络是同一个网络或不同的网络;
    所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
    所述终端的第一标识包括终端的认证提供方的信息;
    所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
    所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
  20. 一种接入控制装置,应用于第三通信设备,包括:
    第二获取模块,用于获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
    第二执行模块,用于根据所述第三信息和/或所述第四信息,执行第三操作;
    其中,所述第三操作包括以下至少一项:
    发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;
    发送所述发现的鉴权服务网元;
    其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
    所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一网络和所述第二网络是同一个网络或不同的网络;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识。
  21. 一种接入控制装置,应用于第四通信设备,包括:
    第二发送模块,用于发送第四信息;
    其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络 的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;
    其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;
    所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;
    所述鉴权服务网元所属的组标识为第一类型的组标识;
    所述鉴权服务网元支持的接入方式包括第一接入方式;
    所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;
    所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识。
  22. 一种接入控制装置,应用于第五通信设备,包括:
    第三执行模块,用于在满足第五条件的情况下,执行第五操作;
    所述第五操作包括以下至少一项:
    不使用第五信息为终端选择网元;
    其中,
    所述第五条件包括以下至少一项:所述终端为第一接入方式;
    所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。
  23. 根据权利要求22所述的装置,还包括:
    第三获取模块,用于获得第一信息,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;其中,
    所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接 入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;
    所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;
    所述第一类型的网络标识包括:用于第一接入方式的网络标识;
    所述第一类型的路由指示包括:用于第一接入方式的路由指示;
    所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;
    所述终端的第一标识包括终端的认证提供方的信息;
    所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;
    所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。
  24. 根据权利要求22所述的装置,还包括:
    确定模块,用于根据第一信息确定满足第五条件。
  25. 根据权利要求22所述的装置,其中,所述网元包括以下至少一项:核心网网元,AUSF,UDM和UDR。
  26. 一种通信设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如权利要求1至6中任一项所述的接入控制方法的步骤,或者,实现如权利要求7至9中任一项所述的接入控制方法的步骤,或者,实现如权利要求10或11所述的接入控制方法的步骤,或者,实现如权利要求12或13所述的接入控制方法的步骤,或者,实现如权利要求14至17任一项所述的接入控制方法的步骤。
  27. 一种可读存储介质,所述可读存储介质上存储有程序或指令,所述程序或指令被处理器执行时实现如权利要求1至6中任一项所述的接入控制方法的步骤,或者,实现如权利要求7至9中任一项所述的接入控制方法的步骤,或者,实现如权利要求10或11所述的接入控制方法的步骤,或者, 实现如权利要求12或13所述的接入控制方法的步骤,或者,实现如权利要求14至17任一项所述的接入控制方法的步骤。
  28. 一种计算机程序产品,所述计算机程序产品被至少一个处理器执行以实现如权利要求1至6中任一项所述的接入控制方法的步骤,或者,实现如权利要求7至9中任一项所述的接入控制方法的步骤,或者,实现如权利要求10或11所述的接入控制方法的步骤,或者,实现如权利要求12或13所述的接入控制方法的步骤,或者,实现如权利要求14至17任一项所述的接入控制方法的步骤。
  29. 一种通信设备,被配置成用于执行如权利要求1至6中任一项所述的接入控制方法的步骤,或者,实现如权利要求7至9中任一项所述的接入控制方法的步骤,或者,实现如权利要求10或11所述的接入控制方法的步骤,或者,实现如权利要求12或13所述的接入控制方法的步骤,或者,实现如权利要求14至17任一项所述的接入控制方法的步骤。
PCT/CN2021/110015 2020-07-31 2021-08-02 接入控制方法、装置及通信设备 WO2022022739A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP21851111.1A EP4192064A4 (en) 2020-07-31 2021-08-02 ACCESS CONTROL METHOD AND DEVICE AND COMMUNICATION DEVICE
KR1020237006765A KR20230043969A (ko) 2020-07-31 2021-08-02 접속 제어 방법, 장치 및 통신기기
JP2023503412A JP7509991B2 (ja) 2020-07-31 2021-08-02 アクセス制御方法、装置及び通信機器
US18/104,061 US20230179597A1 (en) 2020-07-31 2023-01-31 Access control method, access control apparatus, and communications device

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CN202010762196.3 2020-07-31
CN202010762196 2020-07-31
CN202110369540.7 2021-04-06
CN202110369540.7A CN114071465A (zh) 2020-07-31 2021-04-06 接入控制方法、装置及通信设备

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US18/104,061 Continuation US20230179597A1 (en) 2020-07-31 2023-01-31 Access control method, access control apparatus, and communications device

Publications (1)

Publication Number Publication Date
WO2022022739A1 true WO2022022739A1 (zh) 2022-02-03

Family

ID=80037599

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/110015 WO2022022739A1 (zh) 2020-07-31 2021-08-02 接入控制方法、装置及通信设备

Country Status (5)

Country Link
US (1) US20230179597A1 (zh)
EP (1) EP4192064A4 (zh)
JP (1) JP7509991B2 (zh)
KR (1) KR20230043969A (zh)
WO (1) WO2022022739A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140273958A1 (en) * 2013-03-15 2014-09-18 Alcatel-Lucent Usa Inc. Method of providing user equipment with access to a network and a network configured to provide access to the user equipment
CN107211272A (zh) * 2014-11-12 2017-09-26 诺基亚通信公司 方法、装置和系统
CN109413646A (zh) * 2017-08-16 2019-03-01 华为技术有限公司 安全接入方法、设备及系统
CN110636506A (zh) * 2018-06-22 2019-12-31 维沃移动通信有限公司 网络接入方法、终端及网络侧网元

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10313997B2 (en) * 2017-02-06 2019-06-04 Industrial Technology Research Institute User equipment registration method for network slice selection and network controller and network communication system using the same
JP2020194988A (ja) * 2017-08-14 2020-12-03 株式会社Nttドコモ 通信制御方法および通信システム
WO2020098974A1 (en) * 2018-11-14 2020-05-22 Telefonaktiebolaget Lm Ericsson (Publ) Methods and apparatuses for network function selection in 5g for a user

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140273958A1 (en) * 2013-03-15 2014-09-18 Alcatel-Lucent Usa Inc. Method of providing user equipment with access to a network and a network configured to provide access to the user equipment
CN107211272A (zh) * 2014-11-12 2017-09-26 诺基亚通信公司 方法、装置和系统
CN109413646A (zh) * 2017-08-16 2019-03-01 华为技术有限公司 安全接入方法、设备及系统
CN110636506A (zh) * 2018-06-22 2019-12-31 维沃移动通信有限公司 网络接入方法、终端及网络侧网元

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
HUAWEI, HISILICON,: "Alternative 3GPP Credentials based on Identity-based Cryptography", 3GPP DRAFT; S3-161365_PCR_ALTERNATIVE_3GPP_CREDENTIALS_BASED_ON_IDENTITY_BASED_CRYPTOGRAPHY, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. San Diego; 20160725 - 20160729, 20 September 2016 (2016-09-20), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051170323 *
See also references of EP4192064A4 *

Also Published As

Publication number Publication date
EP4192064A4 (en) 2024-01-17
JP2023535386A (ja) 2023-08-17
US20230179597A1 (en) 2023-06-08
KR20230043969A (ko) 2023-03-31
EP4192064A1 (en) 2023-06-07
JP7509991B2 (ja) 2024-07-02

Similar Documents

Publication Publication Date Title
US9526119B2 (en) Methods and apparatus for multiple data packet connections
WO2013160673A1 (en) Content control in telecommunications networks
WO2014089754A1 (zh) 接入控制方法、基站、用户设备和移动管理实体
WO2018058680A1 (zh) 一种本地业务授权方法及相关设备
WO2009152676A1 (zh) Aaa服务器、p-gw、pcrf、用户设备标识的获取方法和系统
US11997751B2 (en) Method for supporting UE association and communications device
WO2021218878A1 (zh) 切片认证方法及装置
WO2023124457A1 (zh) 选择网络的方法和装置
WO2018058365A1 (zh) 一种网络接入授权方法、相关设备及系统
EP3335394A1 (en) Method and apparatus for extensible authentication protocol
WO2022062929A1 (zh) 一种会话建立方法及装置
WO2016183745A1 (zh) 用于建立连接的方法和设备
WO2020208294A1 (en) Establishing secure communication paths to multipath connection server with initial connection over public network
WO2020208295A1 (en) Establishing secure communication paths to multipath connection server with initial connection over private network
CN114071465A (zh) 接入控制方法、装置及通信设备
WO2022022739A1 (zh) 接入控制方法、装置及通信设备
WO2017129101A1 (zh) 路由控制方法、装置及系统
CN114173333A (zh) 接入网络、网络选择的方法、装置及通信设备
WO2021208857A1 (zh) 接入控制方法及通信设备
WO2022037611A1 (zh) 接入网络、网络选择的方法、装置及通信设备
WO2022022738A1 (zh) 信息配置方法、装置及通信设备
US20230017260A1 (en) Access control method and communications device
CN113556746A (zh) 接入控制方法及通信设备
WO2022166892A1 (zh) 信息处理方法、装置、通信设备及可读存储介质
WO2023040728A1 (zh) 一种网元的选择方法、通信装置及通信系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21851111

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2023503412

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 202317009765

Country of ref document: IN

ENP Entry into the national phase

Ref document number: 20237006765

Country of ref document: KR

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 2021851111

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2021851111

Country of ref document: EP

Effective date: 20230228

NENP Non-entry into the national phase

Ref country code: DE