WO2022037611A1 - Procédé et appareil d'accès au réseau, procédé et appareil de sélection de réseau, et dispositif de communication - Google Patents

Procédé et appareil d'accès au réseau, procédé et appareil de sélection de réseau, et dispositif de communication Download PDF

Info

Publication number
WO2022037611A1
WO2022037611A1 PCT/CN2021/113248 CN2021113248W WO2022037611A1 WO 2022037611 A1 WO2022037611 A1 WO 2022037611A1 CN 2021113248 W CN2021113248 W CN 2021113248W WO 2022037611 A1 WO2022037611 A1 WO 2022037611A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
plane type
certificate
terminal
information
Prior art date
Application number
PCT/CN2021/113248
Other languages
English (en)
Chinese (zh)
Inventor
柯小婉
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN202011281217.6A external-priority patent/CN114173333A/zh
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2022037611A1 publication Critical patent/WO2022037611A1/fr

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information

Definitions

  • the embodiments of the present application relate to the field of wireless communication technologies, and in particular, to a method, apparatus, and communication device for accessing a network and selecting a network.
  • the way for a terminal to access another network in order to download a certificate for accessing an independent non-public network may be a control plane type or a user plane type.
  • SNPN Seplace Non-public Network
  • the embodiments of the present application provide an access network, a method, an apparatus, and a communication device for network selection, which are used to solve the problem of how to support a terminal to determine a method for downloading a certificate.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a first communication device, including:
  • the first information is used to indicate at least one of the following: the key used for communication between the terminal and the first network can be derived according to the default certificate or the key used for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or the terminal does not Supports the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user The first access method of the face type;
  • the first operation includes any one of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a second communication device, including:
  • the second information includes at least one of the following: information on an access method requested by the terminal, type information on a certificate download method requested by the terminal, and capability information of the terminal;
  • the The fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, information about the preconfigured terminal access mode, and the preconfigured terminal Type information of the certificate download method;
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Sending type information of the determined certificate download method where the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Sending second indication information where the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key used for the communication between the terminal and the first network can be derived according to the default certificate, or the key used for the communication between the terminal and the first network cannot be derived according to the default certificate;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a third communication device, including:
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information, and second indication information ; wherein, the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type; the type information of the certificate download mode is used to Indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type; the first indication information is used to indicate one of the following: adopt the first access method of the control plane type, and not adopt the control plane type the first access mode; the second indication information is used to indicate one of the following: adopt the certificate download mode of the control plane type, and not adopt the certificate download mode of the control plane type;
  • the third operation includes:
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for network selection, which is applied to a fourth communication device, including:
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type or the network does not support the first access mode of the user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for network selection, which is applied to a fifth communication device, including:
  • the operation of network selection is performed
  • the fourth information includes at least one of the following: fourth indication information, capability information of the terminal, information of the access mode requested by the terminal, and type information of the certificate download mode requested by the terminal;
  • the fourth indication information is used to indicate any one of the following: the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type, or the network supports the certificate download method of the user plane type.
  • the certificate downloading method of the user plane type is not supported; the network supports the first access method of the control plane type, or the network does not support the first access method of the control plane type; the network supports the first access method of the user plane type, or the network The first access mode of the user plane type is not supported;
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate downloader of the user plane type or the terminal does not support The certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user plane The first access mode of the type; the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived for the terminal according to the default certificate a key for communication with the first network;
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download the certificate for accessing the second network, and the method for downloading the certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a first communication device, including:
  • a first execution module configured to execute a first operation according to the first information
  • the first information is used to indicate at least one of the following: the key used for communication between the terminal and the first network can be derived according to the default certificate or the key used for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or the terminal does not Supports the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user The first access method of the face type;
  • the first operation includes any one of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a second communication device, including:
  • a first obtaining module configured to obtain second information and/or fifth information;
  • the second information includes at least one of the following: information on the access mode requested by the terminal, type information on the certificate download mode requested by the terminal, capability information of the terminal;
  • the fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, and preconfigured terminal access mode information, the type information of the pre-configured terminal certificate download method;
  • a second execution module configured to execute a second operation according to the second information and/or the fifth information
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Sending type information of the determined certificate download method where the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Sending second indication information where the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived according to the default certificate or the key for communication between the terminal and the first network cannot be derived according to the default certificate;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a device for accessing a network, which is applied to a third communication device, including:
  • the second receiving module is configured to receive third information and/or an access acceptance message; wherein the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information and second indication information; wherein, the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type; the certificate The type information of the download method is used to indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type; the first indication information is used to indicate one of the following: the first access using the control plane type The first access method of the control plane type is not used; the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and do not use the certificate download method of the control plane type;
  • a third execution module configured to determine whether to execute the third operation according to the third information and/or the access acceptance message
  • the third operation includes:
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fourth communication device, including:
  • a third sending module configured to send or broadcast the fourth indication information
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type or the network does not support the first access mode of the user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fifth communication device, including:
  • a second obtaining module configured to obtain fourth indication information
  • a fourth execution module configured to execute an operation of network selection according to the fourth information
  • the fourth information includes at least one of the following: fourth indication information, capability information of the terminal, information of the access mode requested by the terminal, and type information of the certificate download mode requested by the terminal;
  • the fourth indication information is used to indicate any one of the following: the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type, or the network supports the certificate download method of the user plane type.
  • the certificate downloading method of the user plane type is not supported; the network supports the first access method of the control plane type, or the network does not support the first access method of the control plane type; the network supports the first access method of the user plane type, or the network The first access mode of the user plane type is not supported;
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate downloader of the user plane type or the terminal does not support The certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user plane The first access mode of the type; the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived for the terminal according to the default certificate a key for communication with the first network;
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a communication device, including a processor, a memory, and a computer program stored on the memory and executable on the processor, the computer program being executed by the processor
  • the steps of implementing the method for accessing a network provided by the first aspect or the steps of implementing the method for accessing a network provided by the second aspect, or the steps of implementing the method for accessing a network provided by the third aspect, or,
  • an embodiment of the present application provides a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, implements the access network provided in the first aspect
  • FIG. 1 is a schematic structural diagram of a wireless communication system according to an embodiment of the present application.
  • FIG. 2 is a schematic flowchart of a method for accessing a network according to an embodiment of the present application
  • FIG. 3 is a schematic flowchart of a method for accessing a network according to another embodiment of the present application.
  • FIG. 4 is a schematic flowchart of a method for accessing a network according to another embodiment of the present application.
  • FIG. 5 is a schematic flowchart of a method for network selection according to another embodiment of the present application.
  • FIG. 6 is a schematic flowchart of a method for network selection according to another embodiment of the present application.
  • FIG. 7 is a schematic flowchart of a method for accessing a network according to Embodiment 1 of the present application.
  • FIG. 8 is a schematic flowchart of a method for network selection in Embodiment 1 of the present application.
  • FIG. 9 is a schematic structural diagram of an apparatus for accessing a network provided by the present application.
  • FIG. 10 is a schematic structural diagram of another apparatus for accessing a network provided by this application.
  • FIG. 11 is a schematic structural diagram of another apparatus for accessing a network provided by this application.
  • FIG. 12 is a schematic structural diagram of an apparatus for network selection provided by the application.
  • FIG. 13 is a schematic structural diagram of another apparatus for network selection provided by the application.
  • FIG. 14 is a structural diagram of a communication device provided by this application.
  • first, second and the like in the description and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and "first”, “second” distinguishes Usually it is a class, and the number of objects is not limited.
  • the first object may be one or multiple.
  • “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the associated objects are in an "or” relationship.
  • FIG. 1 shows a block diagram of a wireless communication system to which the embodiments of the present application can be applied.
  • the wireless communication system includes a terminal 11 and a network-side device 12 .
  • the terminal 11 may include a relay supporting the terminal function and/or a terminal supporting the relay function.
  • the terminal 11 may also be referred to as a terminal device or a user terminal (User Equipment, UE), and the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), Laptop Computer (Laptop Computer) or notebook computer, Personal Digital Assistant (Personal Digital Assistant, PDA), Mobile Internet Device (Mobile Internet Device, MID), Handheld Computer, Netbook, Ultra Mobile Personal Computer ( Ultra-mobile personal computer (UMPC), Mobile Internet Device (MID), Wearable Device (Wearable Device) or Vehicle User Equipment (VUE), Pedestrian User Equipment (PUE) and other terminals Side devices, wearable devices include: bracelets, headphones, glasses, etc. It should be noted that, the embodiment of the present application does not limit the specific type of the terminal 11 .
  • the network side device 12 may be a base station or a core network, wherein the base station may be referred to as a Node B, an evolved Node B, an access point, a Base Transceiver Station (BTS), a radio base station, a radio transceiver, a basic service Set (Basic Service Set, BSS), Extended Service Set (Extended Service Set, ESS), Node B, Evolved Node B (eNB), Home Node B, Home Evolved Node B, WLAN Access Point, WiFi Node, Send Transmitting Receiving Point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms.
  • the base station in the NR system is taken as an example, but the specific type of the base station is not limited.
  • the communication device does not have a network certificate but needs to access the network.
  • the UE may not be able to access the SNPN yet. certificate and UE identity.
  • the UE may access a certain network (hereinafter referred to as the first network) and download the certificate for accessing the SNPN.
  • the first network may be the SNPN.
  • the way of accessing the first network in order to download the credentials for accessing the second network may be referred to as onboarding.
  • the first network and the second network may be the same network.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the method of downloading the certificate may include: 1) a control plane (Control Plane, CP) type certificate downloading method, in which the first network downloads the certificate from the certificate configuration server for the UE and sends it to the UE through control plane signaling; 2) the user In the certificate download mode of the user plane (UP) type, the terminal establishes a data channel to the first network, and downloads the certificate from the certificate configuration server through the data channel.
  • a control plane Control Plane, CP
  • UP user plane
  • the UE and the first network are required to have additional capabilities:
  • the first network can interact with the provisioning server (Provision Server), and download the certificate from the Provision Server on behalf of the UE, and the certificate is to be sent to the UE under the protection of the key of the default certificate, such as the certificate is included in the non-accessible certificate.
  • layer (Non-Access Stratum, NAS) message is sent to the UE; and the NAS message is encrypted and/or integrity protected.
  • the UE shall be able to support receiving certificates from NAS messages.
  • the certificate download method of the user plane type can be the default method:
  • the network may not need additional capabilities; the network only needs to configure a policy to restrict the established data channel (such as a PDU session (Session)) to only connect to the Provision Server.
  • a policy to restrict the established data channel (such as a PDU session (Session)) to only connect to the Provision Server.
  • the network may support the user plane type certificate download method by default.
  • the UE may support the certificate downloader of the control plane type and/or the certificate download method of the user plane type.
  • the UE when the UE indicates the first access mode, it may imply that the first access mode of the user plane type is supported, and/or, the system information block (SIB) of the network broadcasts the first access mode may imply support.
  • SIB system information block
  • the network can decide whether to adopt the first access method of the control plane type according to the capability of the certificate download method of the control plane type of the UE, and/or, the network can decide whether to use the certificate download method of its own control plane type and the policy configuration.
  • the first access mode of the control plane type is adopted.
  • the UE needs to obtain an indication of the control plane type certificate download mode from the network to decide whether to initiate a data channel (such as a PDU session) Create a download certificate. For example, when the instruction of the certificate download mode of the control plane type is not obtained, the first network is initiated to establish a data channel to download the certificate; when the instruction of the certificate download mode of the control plane type is obtained, the first network can download the certificate for the UE. .
  • a data channel such as a PDU session
  • obtaining may be understood as obtaining from configuration, receiving, receiving after request, obtaining through self-learning, deriving and obtaining according to unreceived information, or obtaining after processing according to received information. It is determined according to actual needs, which is not limited in this embodiment of the present application. For example, when a certain capability indication information sent by the device is not received, it can be deduced that the device does not support the capability.
  • the sending can include broadcasting, broadcasting in system messages, and returning after responding to the request.
  • the first network may include one of the following: a non-public network (eg, SNPN, or PNI-SNPN), or a public network (PLMN).
  • a non-public network eg, SNPN, or PNI-SNPN
  • PLMN public network
  • the second network may include one of the following: a non-public network (eg, SNPN, or PNI-SNPN), or a public network (PLMN).
  • a non-public network eg, SNPN, or PNI-SNPN
  • PLMN public network
  • the certificate download method of the control plane type is that the network element of the first network interacts with the certificate configuration server, and sends the certificate through control plane signaling (such as NAS signaling). way to the terminal.
  • control plane signaling such as NAS signaling
  • the user plane type certificate download method is that the terminal requests the first network to establish a data channel (such as a PDU session), and through the data channel, the terminal and the certificate configuration server interact to download the certificate. Way.
  • the interaction between the terminal and the certificate configuration server is user plane data for the first network, so it is called a user plane type certificate downloading method.
  • the user plane capability of the terminal includes at least one of the following: supporting the establishment of a data channel (such as a PDU session) requesting from the network, a function of session management, and the like.
  • a data channel such as a PDU session
  • the certificate for accessing the second network includes: a certificate of the second network.
  • the non-public network is an abbreviation of the non-public network.
  • a non-public network may be referred to as one of the following: a non-public communication network.
  • the non-public network may include at least one of the following deployment modes: a physical non-public network, a virtual non-public network, and a non-public network implemented on the public network.
  • the non-public network is a closed access group (Closed Access Group, CAG).
  • a CAG can consist of a group of terminals.
  • the non-public network service is an abbreviation for non-public network service.
  • Non-public network services may also be referred to as one of the following: non-public network network services, non-public communication services, non-public network communication services, non-public network network services, or other designations. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the non-public network is a closed access group, and in this case, the non-public network service is a network service of the closed access group.
  • the non-public network may include or be referred to as a private network.
  • a private network may be referred to as one of the following: a private communication network, a private network, a local area network (LAN), a private virtual network (PVN), an isolated communication network, a dedicated communication network, or other nomenclature. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the public network is an abbreviation of the public network.
  • the public network may be called one of the following: public communication network or other designation. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the authentication service includes an authentication server (such as a DCS, or a home AUSF) initiating an authentication request for the terminal.
  • the authentication service network element may be an authentication agent that provides an authentication service for the terminal.
  • the authentication service network element may include but is not limited to one of the following: AUSF, AAA proxy.
  • the communication device may include at least one of the following: a communication network element and a terminal.
  • the communication network elements may include at least one of the following: a core network network element and a wireless access network network element.
  • the core network element may include, but is not limited to, at least one of the following: core network equipment, core network nodes, core network functions, core network network elements, and mobility management entities (Mobility Management Entity, MME), Access Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Serving Gateway (serving GW, SGW), PDN Gateway ( PDN Gate Way, PDN gateway), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), GPRS service support node (Serving GPRS Support Node, SGSN), gateway GPRS Support Node (Gateway GPRS Support Node, GGSN), Unified Data Management (Unified Data Management, UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS) and Application Function (Application Function) , AF).
  • MME Mobility Management Entity
  • AMF Access Management Function
  • SMF Session Management Function
  • UPF User Plane Function
  • the RAN network element may include, but is not limited to, at least one of the following: a radio access network device, a radio access network node, a radio access network function, a radio access network unit, a 3GPP radio access network, a non- 3GPP Radio Access Network, Centralized Unit (CU), Distributed Unit (DU), Base Station, Evolved Node B (eNB), 5G Base Station (gNB), Radio Network Controller (Radio Network) Controller, RNC), base station (NodeB), non-3GPP interworking function (Non-3GPP Inter Working Function, N3IWF), access control (Access Controller, AC) node, access point (Access Point, AP) equipment or wireless local area network (Wireless Local Area Networks, WLAN) node, N3IWF.
  • a radio access network device a radio access network node, a radio access network function, a radio access network unit, a 3GPP radio access network, a non- 3GPP Radio Access Network, Centralized Unit (CU), Distributed Unit (DU),
  • an embodiment of the present application provides a method for accessing a network, which is applied to a first communication device;
  • the first communication device includes but is not limited to: UE; the method includes:
  • Step 21 Execute the first operation according to the first information.
  • the first information is used to indicate at least one of the following: the key for communication between the terminal and the first network can be derived according to the default certificate or the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or The terminal does not support the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the first access method of the user plane type.
  • the first access mode of the user plane type is supported.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , encryption key, and integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • the first operation includes any of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the terminal supports the first access mode of the user plane type, or it is determined that the terminal does not support the first access mode of the user plane type.
  • the above-mentioned process of performing the first operation according to the first information may include: when at least one of the following is satisfied, determining that the information of the access mode requested by the terminal is the first information of the user plane type.
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type
  • the first information indicates that the terminal has a user plane capability
  • the first information indicates that the terminal supports a user plane type certificate download mode
  • the first information indicates that the terminal supports the first access mode of the user plane type.
  • the above-mentioned process of performing the first operation according to the first information may include: when the first condition is satisfied, determining that the terminal does not support the certificate downloading method of the control plane type or determining that the terminal does not support the first method of the control plane type. access method.
  • the first condition includes at least one of the following:
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type.
  • the above-mentioned process of performing the first operation according to the first information may include:
  • the information determining the access mode requested by the terminal is the first access mode of the control plane type:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type
  • the first information indicates that a key for communication between the terminal and the first network can be derived according to the default certificate
  • the first information indicates that the terminal supports a certificate downloading method of a control plane type
  • the first information indicates that the terminal supports the first access mode of the control plane type.
  • the above-mentioned process of performing the first operation according to the first information may include: when the second condition is satisfied, determining that the terminal does not support the certificate downloading method of the user plane type or determining that the terminal does not support the first method of the user plane type. access method.
  • the second condition includes at least one of the following:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type.
  • the method may further include:
  • Sending second information includes at least one of the following: information of an access mode requested by the terminal, capability information of the terminal, and type information of a certificate download mode requested by the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the method may further include:
  • the third information and/or the access acceptance message it is determined whether to perform the third operation.
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information, and second indication information; wherein the first access mode
  • the type information of the certificate is used to indicate one of the following: the first access method of the control plane type, the first access method of the user plane type
  • the type information of the certificate download method is used to indicate one of the following: the certificate of the control plane type
  • the download method is the certificate download method of the user plane type
  • the first indication information is used to indicate one of the following: the first access method of the control plane type is adopted, and the first access method of the control plane type is not adopted
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type.
  • the access accept message is an access accept message obtained after the terminal accesses the first network, including but not limited to a registration accept message.
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network.
  • the above-mentioned determining whether to perform the third operation according to the third information may include: when the fifth condition is satisfied, performing the third operation.
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate download method of the control plane type is not adopted;
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the first access mode of the user plane type by default.
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the user plane type certificate download mode by default.
  • the above-mentioned determining whether to perform the third operation according to the third information may include: when the sixth condition is satisfied, not performing the third operation.
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate downloading method of a control plane type is adopted.
  • both the UE and the network support the first access mode of the user plane type or the certificate download mode of the user plane type by default, and can optionally support the first access mode of the control plane type or the first access mode of the control plane type. Certificate downloader.
  • the UE when the UE indicates the first access mode, it may imply that the first access mode of the user plane type is supported, and/or, the system information block (SIB) of the network broadcasts the first access mode may imply support.
  • SIB system information block
  • the network can decide whether to adopt the first access method of the control plane type according to the capability of the certificate download method of the control plane type of the UE, and/or, the network can decide whether to use the certificate download method of its own control plane type and the policy configuration.
  • the first access mode of the control plane type is adopted.
  • the terminal needs to obtain an indication of the control plane type certificate download method from the network to decide whether to initiate a data channel (such as a PDU session) Create a download certificate. For example, when the instruction of the certificate download mode of the control plane type is not obtained, the first network is initiated to establish a data channel to download the certificate; when the instruction of the certificate download mode of the control plane type is obtained, it can wait for the first network to download the certificate for the UE. .
  • an embodiment of the present application provides a method for accessing a network, which is applied to a second communication device;
  • the second communication device includes but is not limited to: a CN network element (such as an AMF);
  • the CN network element may is a communication device in the first network.
  • the method includes:
  • Step 31 Acquire second information and/or fifth information.
  • the second information includes at least one of the following: information of an access mode requested by the terminal, type information of a certificate download mode requested by the terminal, and capability information of the terminal.
  • the fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, and information about the preconfigured terminal access mode. Information, type information of the preconfigured terminal certificate download method.
  • the sixth communication device includes but is not limited to one of the following: AF, UDM, PCF, SMF, AUSF, DCS, and configuration server (eg PS).
  • the sixth communication device is a communication device in the certificate owner.
  • the configuration server configures a certificate for the terminal.
  • the DCS may verify and/or authenticate the terminal that accesses the network through the first access manner.
  • the type information of the terminal certificate download method requested by the sixth communication device includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the information about the terminal access mode requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the information of the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the preconfigured terminal certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the terminal certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the capability information of the terminal may be used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , an encryption key and/or an integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • the first access method of the control plane type or the certificate download method of the control plane type cannot be used, because the certificate There is no encryption or integrity protection in the control plane signaling, which is not secure enough.
  • the first access mode of the user plane type or the certificate download mode of the user plane type may be adopted. Because the user plane type can be encrypted at the application layer of the terminal and the configuration server that configures the certificate.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • Step 32 Perform a second operation according to the second information and/or the fifth information.
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Sending type information of the determined certificate download method where the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Second indication information is sent, where the second indication information is used to indicate one of the following: adopt the certificate download mode of the control plane type, and not adopt the certificate download mode of the control plane type.
  • performing the second operation according to the second information and/or the fifth information may include: when the third condition is satisfied, performing at least one of the following: determining that the type of the first access mode is a control plane type the first access mode, determine that the type of the certificate download mode is the certificate download mode of the control plane type, determine that the first indication information indicates that the first access mode of the control plane type is adopted, and determine that the second indication information indicates that the control plane type is adopted. How to download the certificate.
  • the third condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type;
  • the information about the terminal access mode requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a control plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the control plane type;
  • the information of the preconfigured terminal access mode includes one of the following: the first access mode, the first access mode of the control plane type;
  • the type information of the preconfigured terminal certificate download method includes: the certificate download method of the control plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the certificate download method of the control plane type, the terminal supports the first access method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal does not support the certificate download method of the user plane type.
  • the terminal In the first access mode, the terminal does not have the capability of the user plane, and the key used for the communication between the terminal and the first network can be derived according to the default certificate;
  • the first network supports a certificate download method of the control plane type
  • the first network supports the first access mode of the control plane type
  • the first network does not support the certificate download method of the user plane type
  • the first network does not support the first access mode of the user plane type.
  • performing the second operation according to the second information and/or the fifth information may include: when the fourth condition is satisfied, performing at least one of the following: determining that the type of the first access mode is a user plane type the first access mode, determine that the type of the certificate download mode is the user plane type of certificate download mode, determine that the first indication information indicates that the first access mode of the control plane type is not used, and determine that the second indication information indicates that the control plane is not used.
  • the type of certificate download method, the address information of the configuration server is sent to the terminal, the slice information is sent to the terminal, and the Data Network Name (DNN) is sent to the terminal.
  • DNN Data Network Name
  • the configuration server may be a server that configures a certificate for the terminal.
  • the address information of the configuration server may include information for indexing the address of the configuration server.
  • the slice information may be slice information used for establishing a channel for the user plane.
  • the slice information is slice information for the first access mode or slice information for the first access mode of the user plane type.
  • the DNN may be a DNN used to build a channel for the user plane.
  • the user plane channel may be a user plane channel for downloading certificates.
  • the DNN is a DNN for the first access mode or a DNN for the first access mode of the user plane type.
  • the fourth condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a user plane type;
  • the terminal access mode information requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the user plane type;
  • the information of the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the preconfigured terminal certificate download method includes: the certificate download method of the user plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the first access method of the user plane type, the terminal supports the certificate download method of the user plane type, the terminal does not support the certificate download method of the control plane type, and the terminal does not support the certificate download method of the control plane type.
  • the terminal In the first access mode, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived;
  • the first network supports a user plane type certificate download method
  • the first network supports the first access mode of the user plane type
  • the first network does not support the certificate download method of the control plane type
  • the first network does not support the first access mode of the control plane type.
  • the above operations of sending the first indication information and/or sending the second indication information may include:
  • the first indication information indicates that the first access mode of the control plane type is adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is adopted;
  • the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is not adopted.
  • the first network supports the first access mode of the user plane type or the certificate downloading mode of the user plane type by default; the first network can optionally support the first access mode of the control plane type or the certificate of the control plane type. Download method. At this time, the first indication information or the second indication information may be sent.
  • the first indication information may indicate that the control plane is used.
  • the first access mode of the plane type, and the second indication information may indicate that the certificate download mode of the control plane type is adopted.
  • the first indication information may indicate that the control is not used.
  • the first access mode of the plane type, and the second indication information may indicate that the certificate download mode of the control plane type is not adopted.
  • the first network may optionally support a first access manner of a user plane type and/or a first access manner of a control plane type.
  • the first network may optionally support a user plane type certificate download method and/or a control plane type certificate download method.
  • the determined type information of the first access mode may be sent, and the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type and/or, sending the determined type information of the certificate download method, and the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a third communication device;
  • the third communication device includes but is not limited to: UE; the method includes:
  • Step 41 Receive third information and/or access acceptance information.
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information, and second indication information; wherein the first access mode
  • the type information of the certificate is used to indicate one of the following: the first access method of the control plane type, the first access method of the user plane type
  • the type information of the certificate download method is used to indicate one of the following: the certificate of the control plane type
  • the download method is the certificate download method of the user plane type
  • the first indication information is used to indicate one of the following: the first access method of the control plane type is adopted, and the first access method of the control plane type is not adopted
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type.
  • only the access acceptance information may be received, and the third information may not be received.
  • the third information and the access acceptance information may be received.
  • only the third information may be received without the access acceptance information.
  • the access accept message is an access accept message obtained after the terminal accesses the first network, including but not limited to a registration accept message.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • Step 42 Determine whether to perform the third operation according to the third information and/or the access acceptance information.
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network.
  • the access acceptance information is information that the terminal is accepted by the first network.
  • the access acceptance information may be embodied by a registration acceptance message and a service acceptance message.
  • the above-mentioned determining whether to perform the third operation according to the third information and/or the access acceptance information may include: performing the third operation when the fifth condition is satisfied.
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate download method of the control plane type is not adopted;
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the first access mode of the user plane type by default.
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the user plane type certificate download mode by default.
  • the above-mentioned determining whether to perform the third operation according to the third information may include: when the sixth condition is satisfied, not performing the third operation.
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate downloading method of a control plane type is adopted.
  • the method may further include:
  • the second information includes at least one of the following: information of an access mode requested by the terminal, and capability information of the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , encryption key, and integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • an embodiment of the present application provides a method for network selection, which is applied to a fourth communication device; the fourth communication device includes but is not limited to: a RAN network element; the RAN network element may be in the first network RAN network element.
  • the method includes:
  • Step 51 Send or broadcast fourth indication information.
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type, or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type, or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type, or the network does not support the first access mode of the user plane type.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • the terminal can be supported to select a network that conforms to its own capability for access.
  • an embodiment of the present application further provides a method for network selection, which is applied to a fifth communication device;
  • the fifth communication device includes but is not limited to: UE; the method includes:
  • Step 61 Obtain fourth indication information.
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type, or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type, or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type, or the network does not support the first access mode of the user plane type.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • Step 62 According to the fourth information, the operation of network selection is performed.
  • the fourth information may include at least one of the following: fourth indication information, capability information of the terminal, information of an access mode requested by the terminal, and type information of a certificate download mode requested by the terminal.
  • the fourth communication device obtains at least one of the following items through configuration: information of an access mode requested by the terminal, and type information of a certificate download mode requested by the terminal.
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports a control plane type certificate download method or the terminal does not support a control plane type certificate download method; the terminal supports a user plane type certificate downloader or terminal; The certificate download method of the user plane type is not supported; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support The first access mode of the user plane type; the terminal has the ability of the user plane or the terminal does not have the ability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived according to the default certificate. A key used for communication between the terminal and the first network.
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , encryption key, and integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • the foregoing operation of performing network selection according to the fourth information may include at least one of the following:
  • a network is selected, and the fourth indication information of the selected network conforms to the type information of the certificate download mode requested by the terminal.
  • the fourth indication information of the selected network conforming to the terminal capability information may include at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network The first access mode of the user plane type is not supported; and the capability information of the terminal indicates any one of the following: the terminal supports the certificate download method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal supports the control plane type.
  • the first access mode of the plane type the terminal does not support the first access mode of the user plane type, the terminal does not have the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate.
  • the network only supports the certificate download method of the control plane type, only the terminals that support the certificate download method of the control plane type, or both the certificate download method of the control plane type and/or the user plane type are supported. terminal, the network will be selected.
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; The network supports the first access method of the user plane type; and the capability information of the terminal indicates at least one of the following: the terminal does not support the certificate download method of the control plane type, the terminal supports the certificate download method of the user plane type, and the terminal does not support the certificate download method of the user plane type.
  • the first access mode of the control plane type the terminal supports the first access mode of the user plane type, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived.
  • the network only supports the certificate download method of the user plane type, only the terminal that supports the certificate download method of the user plane type, or supports the certificate download method of the control plane type and/or the user plane type at the same time. terminal, the network will be selected.
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network supports the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network supports The first access mode of the user plane type.
  • both the control plane type certificate download method and/or the user plane type terminal support The network can be selected.
  • the capability information of the terminal indicates at least one of the following: the terminal supports a control plane type certificate download method, the terminal supports a user plane type certificate download method, the terminal supports a control plane type first access method, and the terminal supports a user plane type In the first access mode of the type, the terminal has the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate.
  • the selected network supports the control plane type certificate download method and/or supports the user plane type certificate download method. Download method.
  • the information that the fourth indication information of the selected network conforms to the access mode requested by the terminal may include at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network The first access mode of the user plane type is not supported; and the information of the access mode requested by the terminal includes any one of the following: the first access mode and the first access mode of the control plane type.
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; The network supports the first access mode of the user plane type; and the information of the access mode requested by the terminal includes any one of the following: the first access mode and the first access mode of the user plane type.
  • the type information that the fourth indication information of the selected network conforms to the certificate download mode requested by the terminal may include at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network The first access mode of the user plane type is not supported; and the type information of the certificate download mode requested by the terminal includes any one of the following: a certificate download mode of the control plane type.
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; The network supports the first access mode of the user plane type; and the type information of the certificate download mode requested by the terminal includes: the certificate download mode of the user plane type.
  • the foregoing operation of performing network selection according to the fourth information may include at least one of the following:
  • the selected network supports the control plane type certificate download method and/or supports the user plane type certificate download method Way;
  • the selected network supports at least the certificate download mode of the user plane type
  • the selected network supports the first access mode of the control plane type and/or supports the first access mode of the user plane type
  • the selected network supports at least the first access mode of the control plane type
  • the selected network supports at least the first access mode of the user plane type.
  • At least the certificate download methods supporting the control plane type include: a certificate downloading method supporting the control plane type, a certificate downloading method supporting the control plane type, and a certificate downloading method supporting the user plane type.
  • At least the certificate downloading methods supporting the user plane type include: a certificate downloading method supporting the user plane type, a certificate downloading method supporting the control plane type, and a certificate downloading method supporting the user plane type.
  • At least the first access mode supporting the control plane type includes: a first access mode supporting the control plane type, a first access mode supporting the control plane type, and a first access mode supporting the user plane type Way.
  • At least the first access mode supporting the user plane type includes: a first access mode supporting the user plane type, a first access mode supporting the control plane type, and a first access mode supporting the user plane type Way.
  • the terminal can be supported to select a network that conforms to its own capability for access.
  • the corresponding method for accessing the network may include:
  • Step 71 The UE sends a registration request message to the first network, where the registration request message includes second information, and the second information is as described in the embodiment of FIG. 2 .
  • Step 72 The CN network element in the first network, such as the AMF, performs a second operation according to the second information and/or the fifth information, such as sending a registration acceptance message to the UE. This second operation is described in the FIG. 3 embodiment.
  • the second information may include the control plane capability of the terminal, for example, the terminal supports the certificate downloading method of the control plane type, or the terminal does not support the certificate downloading method of the control plane type.
  • the registration acceptance message includes type information of the certificate download method, and the type information of the certificate download method is used to indicate the certificate download method of the control plane type or the certificate download method of the user plane type.
  • the registration acceptance message includes third information.
  • the third information is as described in the embodiment of FIG. 3 .
  • the registration acceptance message does not include the third information.
  • Step 73 The UE performs a third operation according to the third information and/or the registration acceptance message. This third operation is described in the FIG. 4 embodiment.
  • the UE may establish a PDU session according to the indication of the user plane type certificate download method or the absence of the control plane type certificate download method indication, and the PDU session is used to download the certificate for accessing the second network.
  • the corresponding network selection process may include:
  • Step 81 The RAN network element (eg, the RAN network element in the first network) broadcasts fourth indication information, where the fourth indication information is as described in the embodiment of FIG. 5 .
  • Step 82 The UE performs an operation of network selection according to the fourth information.
  • the fourth information may include at least one of the following: fourth indication information and capability information of the terminal.
  • the capability information of the terminal is described in the embodiment of FIG. 5 .
  • the SIB broadcast of the RAN network element supports a user plane type certificate download method and/or a control plane type certificate download method.
  • the UE performs network selection according to the SIB broadcast content and the capability information of its own terminal (as described in the embodiment of FIG. 6 ), such as the capability of the control plane type certificate download method and/or the capability of the user plane type certificate download method.
  • the operation is specifically described in the embodiment of FIG. 6 , which is not repeated here.
  • an embodiment of the present application provides a device for accessing a network, which is applied to a first communication device.
  • the device 90 for accessing the network includes:
  • a first execution module 91 configured to execute a first operation according to the first information
  • the first information is used to indicate at least one of the following: the key used for communication between the terminal and the first network can be derived according to the default certificate or the key used for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or the terminal does not Supports the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user The first access method of the face type;
  • the first operation includes any one of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the first execution module 91 is specifically configured to: when at least one of the following conditions is satisfied, determine that the information of the access mode requested by the terminal is the first access mode of the user plane type:
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type
  • the first information indicates that the terminal has a user plane capability
  • the first information indicates that the terminal supports a user plane type certificate download mode
  • the first information indicates that the terminal supports the first access mode of the user plane type.
  • the first execution module 91 is specifically configured to: when the first condition is met, determine that the terminal does not support the certificate downloading method of the control plane type or determine that the terminal does not support the first access method of the control plane type;
  • the first condition includes at least one of the following:
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type.
  • the first execution module 91 is specifically configured to: when at least one of the following conditions is satisfied, determine that the information of the access mode requested by the terminal is the first access mode of the control plane type:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type
  • the first information indicates that a key for communication between the terminal and the first network can be derived according to the default certificate
  • the first information indicates that the terminal supports a certificate downloading method of a control plane type
  • the first information indicates that the terminal supports the first access mode of the control plane type.
  • the first execution module 91 is specifically configured to: when the second condition is satisfied, determine that the terminal does not support the certificate download mode of the user plane type or determine that the terminal does not support the first access mode of the user plane type;
  • the second condition includes at least one of the following:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type.
  • the apparatus 90 for accessing the network further includes:
  • a first sending module for sending second information
  • the second information includes at least one of the following: information of an access mode requested by the terminal, capability information of the terminal, and type information of a certificate download mode requested by the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the apparatus 90 for accessing the network further includes:
  • a first receiving module configured to receive third information and/or an access acceptance message;
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information and second indication information;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type;
  • the certificate The type information of the download method is used to indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type;
  • the first indication information is used to indicate one of the following: the first access using the control plane type
  • the first access method of the control plane type is not used;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and do not use the certificate download method of the control plane type;
  • the first execution module 91 is further configured to: determine whether to execute the third operation according to the third information and/or the access acceptance message;
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network.
  • the first execution module 91 is specifically used for:
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate downloading method of the control plane type is not adopted;
  • the first execution module 91 is specifically used for:
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate download method of a control plane type is adopted.
  • the device 90 for accessing the network can implement each process implemented in the method embodiment shown in FIG. 2 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a second communication device.
  • the apparatus 100 for accessing a network includes:
  • the first obtaining module 101 is configured to obtain second information and/or fifth information; wherein, the second information includes at least one of the following: information of an access mode requested by the terminal, and type information of a certificate download mode requested by the terminal , terminal capability information; the fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, preconfigured terminal access mode information Information about the method and type information of the pre-configured terminal certificate download method;
  • a second execution module 102 configured to execute a second operation according to the second information and/or the fifth information
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Send the type information of the determined certificate download mode, and the type information of the certificate download mode is used to indicate one of the following: the certificate download mode of the control plane type, the certificate download mode of the user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Sending second indication information where the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived according to the default certificate or the key for communication between the terminal and the first network cannot be derived according to the default certificate;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download the certificate for accessing the second network, and the method for downloading the certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the second execution module 102 is specifically configured to:
  • the third condition When the third condition is satisfied, perform at least one of the following: determine that the type of the first access mode is the first access mode of the control plane type, determine that the type of the certificate download mode is the certificate download mode of the control plane type, determine The first indication information indicates that the first access mode of the control plane type is adopted, and it is determined that the second indication information indicates that the certificate download mode of the control plane type is adopted;
  • the third condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type;
  • the information about the terminal access mode requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a control plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the control plane type;
  • the information about the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a control plane type;
  • the type information of the preconfigured terminal certificate download mode includes: the certificate download mode of the control plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the certificate download method of the control plane type, the terminal supports the first access method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal does not support the certificate download method of the user plane type.
  • the terminal In the first access mode, the terminal does not have the capability of the user plane, and the key used for the communication between the terminal and the first network can be derived according to the default certificate;
  • the first network supports a certificate download method of the control plane type
  • the first network supports the first access mode of the control plane type
  • the first network does not support the certificate download method of the user plane type
  • the first network does not support the first access mode of the user plane type.
  • the second execution module 102 is specifically configured to:
  • the fourth condition When the fourth condition is satisfied, perform at least one of the following: determine that the type of the first access mode is the first access mode of the user plane type, determine that the type of the certificate download mode is the certificate download mode of the user plane type, determine The first indication information indicates that the first access mode of the control plane type is not adopted, and it is determined that the second indication information indicates that the certificate download mode of the control plane type is not adopted, and the address information of the configuration server is sent to the terminal, slice information is sent to the terminal, and the terminal is sent to the terminal. send DNN;
  • the fourth condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a user plane type;
  • the terminal access mode information requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the user plane type;
  • the information of the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the preconfigured terminal certificate download method includes: the certificate download method of the user plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the first access method of the user plane type, the terminal supports the certificate download method of the user plane type, the terminal does not support the certificate download method of the control plane type, and the terminal does not support the certificate download method of the control plane type.
  • the terminal In the first access mode, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived;
  • the first network supports a user plane type certificate download method
  • the first network supports the first access mode of the user plane type
  • the first network does not support the certificate download method of the control plane type
  • the first network does not support the first access mode of the control plane type.
  • the second execution module 102 is specifically configured to:
  • the first indication information indicates that the first access mode of the control plane type is adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is adopted;
  • the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is not adopted.
  • the apparatus 100 for accessing the network can implement each process implemented in the method embodiment shown in FIG. 3 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a third communication device.
  • the apparatus 110 for accessing a network includes:
  • the second receiving module 111 is configured to receive third information and/or an access acceptance message, wherein the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, 1 indication information and second indication information; wherein, the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type; the The type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type; the first indication information is used to indicate one of the following: adopt the first connection of the control plane type. The first access method of the control plane type is not used; the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • a third execution module 112 configured to determine whether to execute the third operation according to the third information and/or the access acceptance message
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the third execution module 112 is specifically configured to:
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate download method of the control plane type is not adopted;
  • the third execution module 112 is specifically configured to:
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate downloading method of a control plane type is adopted.
  • the apparatus 110 for accessing the network further includes:
  • the second sending module is configured to send second information; wherein, the second information includes at least one of the following: information of an access mode requested by the terminal, and capability information of the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate, or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the device 110 for accessing the network can implement each process implemented in the method embodiment shown in FIG. 4 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fourth communication device.
  • the apparatus 120 for network selection includes:
  • the third sending module 121 is configured to send or broadcast the fourth indication information
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type or the network does not support the first access mode of the user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the apparatus 120 for network selection can implement each process implemented in the method embodiment shown in FIG. 5 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fifth communication device.
  • the apparatus 130 for network selection includes:
  • the second obtaining module 131 is configured to obtain fourth indication information
  • a fourth execution module 132 configured to execute an operation of network selection according to the fourth information
  • the fourth information includes at least one of the following: fourth indication information, capability information of the terminal, information of the access mode requested by the terminal, and type information of the certificate download mode requested by the terminal;
  • the fourth indication information is used to indicate any one of the following: the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type, or the network supports the certificate download method of the user plane type.
  • the certificate downloading method of the user plane type is not supported; the network supports the first access method of the control plane type, or the network does not support the first access method of the control plane type; the network supports the first access method of the user plane type, or the network The first access mode of the user plane type is not supported;
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate downloader of the user plane type or the terminal does not support The certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user plane The first access mode of the type; the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived for the terminal according to the default certificate a key for communication with the first network;
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the fourth execution module 132 is specifically configured to execute at least one of the following:
  • a network is selected, and the fourth indication information of the selected network conforms to the type information of the certificate download mode requested by the terminal.
  • the fourth indication information of the selected network conforming to the terminal capability information includes at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, and the network does not support the certificate download method of the user plane type.
  • the first access mode of the user plane type; and the capability information of the terminal indicates any one of the following: the terminal supports the certificate download method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal supports the control plane type
  • the terminal does not support the first access mode of the user plane type, the terminal does not have the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate;
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; the network supports the first access mode of the user plane type; and the capability information of the terminal indicates at least one of the following: the terminal does not support the certificate download method of the control plane type, the terminal supports the certificate download method of the user plane type, and the terminal does not support the control plane
  • the first access mode of the type the terminal supports the first access mode of the user plane type, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived;
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network supports the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network supports the user plane type Type of first access method;
  • the capability information of the terminal indicates at least one of the following: the terminal supports a control plane type certificate download method, the terminal supports a user plane type certificate download method, the terminal supports a control plane type first access method, and the terminal supports a user plane type.
  • the terminal In the first access manner, the terminal has the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate.
  • the fourth execution module 132 is specifically used for at least one of the following:
  • the selected network supports a control plane type certificate download method and/or supports a user plane type certificate download method
  • the selected network supports at least the certificate download method of the control plane type
  • the selected network supports at least the certificate download mode of the user plane type
  • the selected network supports the first access mode of the control plane type and/or supports the user plane type the first access method
  • the selected network supports at least the first access mode of the control plane type
  • the selected network supports at least the first access mode of the user plane type.
  • the communication device 130 can implement the various processes implemented in the method embodiment shown in FIG. 6 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • FIG. 14 is a schematic structural diagram of another communication device provided by an embodiment of the present application.
  • the communication device 140 includes: a processor 141 , a memory 142 , and a memory 142 that is stored in the memory 142 and can be The computer program running on the processor, the various components in the communication device 140 are coupled together through the bus interface 143, and the computer program is executed by the processor 141.
  • Each process of the above, or each process implemented in the method embodiment shown in FIG. 6 above is implemented, and the same technical effect can be achieved. To avoid repetition, details are not repeated here.
  • Embodiments of the present application further provide a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, each process implemented in the method embodiment shown in FIG. 5 is implemented, Alternatively, each process implemented in the above method embodiment shown in FIG. 6 is implemented, or each process implemented in the above method embodiment shown in FIG. 7 is implemented, or each process implemented in the above method embodiment shown in FIG. 8 is implemented , or, each process implemented in the method embodiment shown in FIG. 9 is implemented, and the same technical effect can be achieved. To avoid repetition, details are not repeated here.
  • the computer-readable storage medium such as read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk, etc.
  • the method of the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is better implementation.
  • the technical solution of the present application can be embodied in the form of a software product in essence or in a part that contributes to the prior art, and the computer software product is stored in a storage medium (such as ROM/RAM, magnetic disk, CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) execute the methods described in the various embodiments of this application.
  • a storage medium such as ROM/RAM, magnetic disk, CD-ROM

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Les modes de réalisation de la présente demande concernent un procédé et un appareil d'accès au réseau, un procédé et un appareil de sélection de réseau, et un dispositif de communication. Le procédé d'accès au réseau comprend : l'exécution d'une première opération selon des premières informations, la première opération comprenant l'une quelconque des opérations suivantes : la détermination d'informations d'un mode d'accès demandé par un terminal, les informations du mode d'accès demandé par le terminal comprenant un de ce qui suit : un premier mode d'accès, un premier mode d'accès d'un type de plan de commande et un premier mode d'accès d'un type de plan d'utilisateur ; la détermination d'un mode de téléchargement de certificat d'un type de plan de commande pris en charge par le terminal, ou la détermination d'un mode de téléchargement de certificat d'un type de plan de commande non pris en charge par le terminal, et la détermination d'un mode de téléchargement de certificat d'un type de plan d'utilisateur pris en charge par le terminal ; et la détermination d'un premier mode d'accès d'un type de plan de commande pris en charge par le terminal, le premier mode d'accès comprenant un mode d'accès pour accéder à un premier réseau afin de télécharger un certificat pour accéder à un second réseau.
PCT/CN2021/113248 2020-08-19 2021-08-18 Procédé et appareil d'accès au réseau, procédé et appareil de sélection de réseau, et dispositif de communication WO2022037611A1 (fr)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CN202010839912.3 2020-08-19
CN202010839912 2020-08-19
CN202011281217.6 2020-11-16
CN202011281217.6A CN114173333A (zh) 2020-08-19 2020-11-16 接入网络、网络选择的方法、装置及通信设备

Publications (1)

Publication Number Publication Date
WO2022037611A1 true WO2022037611A1 (fr) 2022-02-24

Family

ID=80322564

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/113248 WO2022037611A1 (fr) 2020-08-19 2021-08-18 Procédé et appareil d'accès au réseau, procédé et appareil de sélection de réseau, et dispositif de communication

Country Status (1)

Country Link
WO (1) WO2022037611A1 (fr)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110753346A (zh) * 2019-10-30 2020-02-04 北京微智信业科技有限公司 移动通信专网密钥生成方法、装置及控制器
WO2020068765A1 (fr) * 2018-09-27 2020-04-02 Convida Wireless, Llc Réseaux locaux privés 3gpp
US20200245235A1 (en) * 2019-01-24 2020-07-30 Lg Electronics Inc. Method for selecting non-public network in wireless communication system and apparatus thereof

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020068765A1 (fr) * 2018-09-27 2020-04-02 Convida Wireless, Llc Réseaux locaux privés 3gpp
US20200245235A1 (en) * 2019-01-24 2020-07-30 Lg Electronics Inc. Method for selecting non-public network in wireless communication system and apparatus thereof
CN110753346A (zh) * 2019-10-30 2020-02-04 北京微智信业科技有限公司 移动通信专网密钥生成方法、装置及控制器

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhanced support of non-public networks (Release 17)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 23.700-07, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.4.0, 19 June 2020 (2020-06-19), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , pages 1 - 158, XP051924077 *
HUAWEI, HISILICON: "KI #4, Sol #27: update the UP or CP decision", 3GPP DRAFT; S2-2005624, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20200819 - 20200901, 13 August 2020 (2020-08-13), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051920436 *

Similar Documents

Publication Publication Date Title
US9526119B2 (en) Methods and apparatus for multiple data packet connections
WO2020224622A1 (fr) Procédé et dispositif de configuration d'informations
CN113260016B (zh) 多模终端接入控制方法、装置、电子设备及存储介质
WO2013016968A1 (fr) Procédé et système d'accès, et point d'accès intelligent mobile
US20220116769A1 (en) Notification in eap procedure
US12089177B2 (en) Registering with a mobile network through another mobile network
JP2021513825A (ja) Sscモードを決定するための方法および装置
CN115380622A (zh) 重定位接入网关
WO2023124457A1 (fr) Procédé et appareil de sélection de réseau
WO2018058365A1 (fr) Procédé d'autorisation d'accès au réseau, et dispositif et système associés
WO2020147833A1 (fr) Procédé pour prendre en charge une association d'ue, et dispositif de communication
CN114173333A (zh) 接入网络、网络选择的方法、装置及通信设备
CN115362754A (zh) 重定位接入网关
WO2022037611A1 (fr) Procédé et appareil d'accès au réseau, procédé et appareil de sélection de réseau, et dispositif de communication
CN114071465B (zh) 接入控制方法、装置及通信设备
WO2022048265A1 (fr) Procédé de détermination de clé de couche application, terminal, dispositif côté réseau et appareil
JP7572568B2 (ja) 情報処理方法、装置、通信機器及び可読記憶媒体
WO2022166892A1 (fr) Procédé et appareil de traitement d'informations, dispositif de communication et support de stockage lisible
WO2022022739A1 (fr) Procédé et appareil de commande d'accès, et dispositif de communication
US20230017260A1 (en) Access control method and communications device
WO2022022738A1 (fr) Procédé et appareil de configuration d'informations, et dispositif de communication
WO2021208857A1 (fr) Procédé de commande d'accès et dispositif de communication
WO2022021433A1 (fr) Procédé d'authentification d'accès à un dispositif, dispositif terminal et plateforme en nuage
CN113556746A (zh) 接入控制方法及通信设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21857703

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21857703

Country of ref document: EP

Kind code of ref document: A1