WO2022166891A1 - Method, apparatus, and device for supporting network selection, and readable storage medium - Google Patents

Method, apparatus, and device for supporting network selection, and readable storage medium Download PDF

Info

Publication number
WO2022166891A1
WO2022166891A1 PCT/CN2022/075020 CN2022075020W WO2022166891A1 WO 2022166891 A1 WO2022166891 A1 WO 2022166891A1 CN 2022075020 W CN2022075020 W CN 2022075020W WO 2022166891 A1 WO2022166891 A1 WO 2022166891A1
Authority
WO
WIPO (PCT)
Prior art keywords
list
network
certificate
certificates
subscriptions
Prior art date
Application number
PCT/CN2022/075020
Other languages
French (fr)
Chinese (zh)
Inventor
柯小婉
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2022166891A1 publication Critical patent/WO2022166891A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/02Access restriction performed under specific conditions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/18Selecting a network or a communication service

Definitions

  • the present application belongs to the field of communication technologies, and in particular relates to a method, apparatus, device and readable storage medium for supporting network selection.
  • a terminal for example, a user terminal (User Equipment, UE)
  • UE User Equipment
  • a terminal wishes to temporarily access the first network to obtain the certificate and/or subscription of the first object.
  • the problem of how to select the first network is an urgent problem to be solved.
  • Embodiments of the present application provide a method, apparatus, device, and readable storage medium for supporting network selection, so as to solve the problem of how to select a network for downloading a certificate and/or signing a subscription.
  • a method for supporting network selection executed by a first communication device, including:
  • first information includes: a first list, a second list and/or first indication information
  • the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
  • the first list includes at least one of the following:
  • the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
  • the first indication information is used to indicate at least one of the following:
  • a method for supporting network selection is provided, performed by a second communication device, including:
  • the first indication information is used to indicate at least one of the following:
  • a method for supporting network selection is provided, executed by a third communication device, including:
  • the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
  • the first list includes at least one of the following:
  • the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
  • an apparatus for supporting network selection is provided, which is executed by a first communication device, including:
  • a first obtaining module configured to obtain first information, where the first information includes: a first list, a second list and/or first indication information;
  • a selection module configured to select a network according to the first information
  • the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
  • the first list includes at least one of the following:
  • the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
  • the first indication information is used to indicate at least one of the following:
  • a fifth aspect provides an apparatus for supporting network selection, which is applied to a second communication device, including:
  • a first sending module configured to send the first indication information
  • the first indication information is used to indicate at least one of the following:
  • an apparatus for supporting network selection is provided, applied to a third communication device, including:
  • a second sending module configured to send the first list and/or the second list
  • the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
  • the first list includes at least one of the following:
  • the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
  • a terminal comprising: a processor, a memory, and a program stored on the memory and executable on the processor, the program being executed by the processor to implement the method described in the first aspect steps of the method described.
  • a network-side device including: a processor, a memory, and a program stored on the memory and executable on the processor, the program being executed by the processor to achieve the second The steps of the method of aspect or third aspect.
  • a readable storage medium is provided, and a program or an instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the steps of the above-mentioned method are implemented.
  • a computer program product is provided, the computer program product being stored in a non-volatile storage medium, the computer program product being executed by at least one processor to implement the steps of the method as described above.
  • a chip in an eleventh aspect, includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is configured to run a program or an instruction to implement the steps of the above method .
  • the first communication device is supported to confirm and select a network for downloading a certificate and/or signing a contract.
  • FIG. 1 is a schematic diagram of a wireless communication system to which an embodiment of the present application can be applied;
  • FIG. 4 is the third flowchart of the method for supporting network selection provided by an embodiment of the present application.
  • FIG. 5 is a fourth flowchart of a method for supporting network selection provided by an embodiment of the present application.
  • FIG. 6 is one of the schematic diagrams of the apparatus for supporting network selection provided by an embodiment of the present application.
  • FIG. 7 is a second schematic diagram of an apparatus for supporting network selection provided by an embodiment of the present application.
  • FIG. 8 is a third schematic diagram of an apparatus for supporting network selection provided by an embodiment of the present application.
  • FIG. 9 is a schematic diagram of a terminal provided by an embodiment of the present application.
  • FIG. 10 is a schematic diagram of a network side device according to an embodiment of the present application.
  • first, second and the like in the description and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and "first”, “second” distinguishes Usually it is a class, and the number of objects is not limited.
  • the first object may be one or multiple.
  • “and/or” in the description and claims refers to at least one of the connected objects, and the character “/" generally indicates that the contextual objects are in an "and/or” relationship.
  • LTE Long Term Evolution
  • LTE-Advanced LTE-Advanced
  • LTE-A Long Term Evolution
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency-Division Multiple Access
  • system and “network” in the embodiments of the present application are often used interchangeably, and the described technology can be used not only for the above-mentioned systems and radio technologies, but also for other systems and radio technologies.
  • NR New Radio
  • NR terminology is used in most of the following description, although these techniques are also applicable to applications other than NR system applications, such as 6th generation ( 6th Generation, 6G) communication system.
  • FIG. 1 shows a block diagram of a wireless communication system to which the embodiments of the present application can be applied.
  • the wireless communication system includes a terminal 11 and a network-side device 12 .
  • the terminal 11 may also be called a terminal device or a user terminal (User Equipment, UE), and the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital computer Assistant (Personal Digital Assistant, PDA), PDA, Netbook, Ultra-Mobile Personal Computer (UMPC), Mobile Internet Device (Mobile Internet Device, MID), Wearable Device (Wearable Device) or vehicle-mounted device (Vehicle User Equipment, VUE), pedestrian terminal (Pedestrian User Equipment, PUE) and other terminal-side devices, wearable devices include: bracelets, headphones, glasses, etc.
  • the network side device 12 may be a base station or a core network, wherein the base station may be referred to as a Node B, an evolved Node B, an access point, a Base Transceiver Station (BTS), a radio base station, a radio transceiver, a basic service Set (Basic Service Set, BSS), Extended Service Set (Extended Service Set, ESS), Node B, Evolved Node B (eNB), Home Node B, Home Evolved Node B, Wireless Local Area Networks (WLAN) ) access point, wireless fidelity (Wireless Fidelity, WiFi) node, transmitting and receiving point (Transmitting Receiving Point, TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to For specific technical terms, it should be noted that in the embodiments of this application, only the base station in the NR system is used as an example,
  • a terminal eg, UE
  • a terminal can access a public land mobile network (Public Land Mobile Network, PLMN) or an independent non-public network (Standalone Non-Public Network, SNPN) 1 to download the certificate of the first object (eg SNPN2 certificate, or, for secondary authentication and/or authorization).
  • PLMN Public Land Mobile Network
  • SNPN independent non-public network
  • the UE does not have a certificate of SNPN1 (such as a certificate for unrestricted access)
  • the SNPN1 supports the function of the first access mode (such as onboarding)
  • O-SNPN Onboarding SNPN for short
  • the first access manner may be an access manner in which the certificate of the first network is acquired through a restricted access network and/or through the network.
  • the UE When accessing the Onboarding SNPN, the UE does not have an O-SNPN certificate (no certificate for unrestricted access), and uses a default certificate (Default credential, such as a certificate for restricted access) to access O- SNPN, and an onboarding indication is to be provided to illustrate the specificity of the UE's registration type. Therefore, in the scenario of O-SNPN, it includes two functions:
  • the cell of the O-SNPN may broadcast an onboarding indication for the UE to select the O-SNPN and obtain the certificate and/or subscription of the first object.
  • the PLMN or SNPN3 may not support the function of (1), Instead, only the functions of (2) can be supported. Therefore, if the PLMN or SNPN3 wants to broadcast the capabilities of the network, it is not suitable to broadcast the indication information for indicating that onboarding is supported. Therefore, the following problems have to be solved.
  • Question 1 How does the UE access and select a network (such as PLMN and SNPN3) that already has the certificate and/or subscription for unrestricted access to download the certificate of the SNPN.
  • a network such as PLMN and SNPN3
  • the optional solution is as follows:
  • the network side does not broadcast the indication information to indicate that onboarding is supported, but broadcasts the first indication information, which can be used to indicate one of the following: the first indication information to support the configuration certificate and/or the subscription, and to support the unrestricted access based on the first indication information.
  • the first list is configured on the UE.
  • the UE can access the network in the first list to obtain the certificate and/or subscription of the first object, and the first list may be a PLMN and/or SNPN type network to form a mixed list.
  • the terminal may select a network according to the first list and the first indication information.
  • the first list may include at least one of the following:
  • configuring the certificate and/or subscription by means of the control plane includes obtaining the certificate and/or subscription of the network through control plane signaling. It is not difficult to understand that the terminal needs to have the ability to obtain the certificate and/or the subscription through the control plane, and the first network needs to have the ability to configure the certificate and/or the subscription through the control plane.
  • the first network is the network in the first list.
  • configuring the network list of the certificate and/or subscription in a user plane manner includes obtaining the certificate and/or subscription of the network through a data channel.
  • the terminal establishes a data channel in the first network, and the terminal connects to a configuration server in the data network through the data channel to obtain the certificate and/or contract of the first object. Therefore, the terminal needs to have the ability to obtain a certificate and/or a subscription through the user plane.
  • the terminal needs to obtain the address information of the configuration server from the first network (the first network is the network in the first list).
  • the first network needs to have a certificate configured in a user plane manner and/or a subscription to support this.
  • obtaining or obtaining may be understood as obtaining from configuration, receiving, receiving after request, obtaining through self-learning, deriving and obtaining according to unreceived information, or obtaining according to received
  • the information obtained after processing can be determined according to actual needs, which is not limited in this embodiment of the present application. For example, when a certain capability indication information sent by the device is not received, it can be deduced that the device does not support the capability.
  • the sending may include broadcasting, broadcasting in the system message, and returning after responding to the request.
  • able can represent at least one of the following: allow, support, inclination, and preferentially have ability.
  • Impossible can mean at least one of the following: not allowed, not supported, not allowed, not inclined, not capable.
  • the first access mode includes at least one of the following: an access mode for accessing a network for obtaining a certificate and/or signing a contract, using a restricted access network access mode, The access method of using the default certificate to access the network;
  • the manner of using a restricted access network for downloading the certificate for accessing the first object, or the manner of accessing the network for downloading the certificate for accessing the first object may be called onboarding.
  • the first object includes the A network
  • the first network and the A network may be the same network or different networks.
  • the first network is a network accessed by the terminal, such as a currently accessed network.
  • the first server is used to configure the terminal with the certificate of the first object and/or the server for signing up.
  • the supporting configuration of certificates and/or subscriptions is used to further indicate at least one of the following: supporting configuration of certificates and/or subscriptions by means of a control plane, supporting configuration of certificates by means of user planes and/or contract.
  • the configuration certificate and/or subscription not supported is used to further indicate that the configuration of the certificate and/or subscription by means of the control plane is not supported, and the configuration of the certificate and/or subscription by means of the user plane is not supported. or contract.
  • the obtaining of the certificate and/or the contract is to obtain the certificate and/or the contract remotely.
  • the The provider of the certificate and/or contract is the first entity.
  • the first entity is an entity in a data network (Data Network, DN) or an entity (entity) outside the network accessed by the terminal.
  • the provider of the certificate and/or subscription is one of the following: an entity outside the network in the first list, an entity outside the network accessed by the terminal, data Entities in the network (DN), entities in other networks.
  • the entity in the data network may be an application server, a certificate and/or a contracted configuration server in the data network.
  • the objectives of a terminal accessing the network include obtaining a certificate and/or signing up.
  • the certificate and/or subscription is the certificate and/or subscription of the network accessed by the terminal.
  • the certificate and/or subscription of the network accessed by the terminal includes at least one of the following: the certificate and/or subscription of the terminal for the unrestricted access network, the certificate and/or the subscription of the terminal for the restricted access network.
  • the certificate and/or subscription includes at least one of the following: a certificate and/or subscription for unrestricted access, a certificate and/or a subscription for restricted access or subscription, certificate and/or subscription for primary authentication and/or authorization, certificate and/or subscription for non-primary authentication and/or authorization.
  • Primary authentication (such as Primary Authentication) may include: Authentication and Key Agreement (AKA), for example, 5th generation (5G) AKA, an extensible authentication protocol (Extensible Authentication Protocol, EAP) AKA.
  • AKA Authentication and Key Agreement
  • 5G 5th generation
  • EAP extensible authentication protocol
  • non-primary authentication and/or authorization includes at least one of the following: secondary authentication and/or authorization (Secondary authentication/authorization), slice-related authentication and/or authorization (Network Slice-Specific Authentication and Authorization, NSSAA).
  • Secondary authentication and/or authorization Secondary authentication/authorization
  • slice-related authentication and/or authorization NSSAA
  • the terminal may use a certificate (such as a default certificate) for a restricted access network and/or subscribe to access the first network, and then obtain the unrestricted access to the first object (including network A) through the first network. Access-restricted credentials and/or subscriptions.
  • the A network is the same as or different from the first network.
  • obtaining the certificate and/or signing through the control plane and/or configuring the certificate and/or signing through the control plane includes at least one of the following: a first entity, accessing through a terminal The terminal obtains the certificate and/or the subscription from the first entity through the control plane signaling of the network accessed by the terminal;
  • obtaining a certificate and/or signing a contract through a user plane method and/or configuring a certificate and/or signing a contract through a user plane method includes at least one of the following: the terminal establishes data on the network accessed by the terminal The channel, through the data channel, obtains the certificate and/or the contract from the first entity; or the first entity configures the certificate and/or the contract for the terminal through the data channel established by the terminal in the access network.
  • the data channel includes at least one of the following: the data channel may include but is not limited to one of the following: a protocol data unit (Protocol Data Unit, PDU) session, a public data network (Public Data Network, PDN) connection, quality of service (Quality of Service, QoS) flow, bearer, Internet Protocol Security (Internet Protocol Security, IPsec) channel, wherein, the bearer can be an evolved radio access bearer (Evolved Radio Access Bearer, E- RAB), radio access bearer (Evolved Radio Access Bearer, RAB), data radio bearer (Data Radio Bearer, DRB), signaling radio bearer (signalling radio bearers, SRB) and so on.
  • E- RAB evolved radio access bearer
  • RAB radio access bearer
  • DRB Data Radio Bearer
  • SRB signaling radio bearer
  • the network that is allowed to access by using the default certificate includes that the terminal uses the terminal identifier corresponding to the default certificate to access the network that can obtain a restricted connection.
  • the default credentials include credentials for restricted access.
  • restricted access and restricted connection have the same meaning and can be used in combination.
  • the restricted access includes at least one of the following: only the first data channel is allowed to be established, the establishment of data channels other than the first data channel is not allowed, only the certificate and/or contract is allowed, and the Businesses other than getting a certificate and/or contracting.
  • the first data channel is used to obtain a certificate and/or a contracted data channel.
  • the certificate and/or subscription of the first object may be obtained through the restricted access.
  • the restricted access includes restricted control plane access and/or restricted user plane access.
  • the restricted connection includes a restricted control plane connection and/or a restricted user plane connection. Credentials and/or subscriptions may be obtained through the restricted connection.
  • the network that can be accessed by using the default certificate includes using the terminal identification corresponding to the default certificate to access the network and passing the authentication and/or authorization of the network through the default certificate.
  • the networks in the first list include networks mapped by the network group in the first list.
  • a netgroup can be mapped to one or more nets.
  • the network in the list of networks that can configure certificates and/or subscriptions includes that the first communication device can access restricted, and enables the first communication device Network to obtain a certificate and/or sign up.
  • the characteristics of the networks in the first list include that the first communication device can access restricted, and can enable the first communication device to obtain a certificate and/or contracted network.
  • the subscription includes subscription data (subscription data), such as slice information, a data network name (Data Network Name, DNN), and the like.
  • the A network is used to refer to a network in general, or to refer to one or more networks in particular.
  • the certificate and/or subscription of the first object includes a certificate and/or subscription for accessing the first object.
  • the credentials and/or subscriptions for accessing the first object include at least one of the following: credentials and/or subscriptions for unrestricted access to the first object, credentials and/or subscriptions for restricted access to the first object contract.
  • the certificate and/or subscription of the A network includes a certificate and/or a subscription for accessing the A network.
  • the certificate and/or subscription for accessing the A network includes at least one of the following: a certificate and/or subscription for unrestricted access to the A network, and a certificate and/or subscription for restricted access to the A network.
  • configuring a certificate and/or a subscription for the first communication device includes causing the first communication device to obtain a certificate and/or a subscription.
  • causing the first communication device to obtain a certificate and/or a subscription includes: configuring a certificate and/or a subscription for the first communication device.
  • causing the first communication device to obtain the certificate and/or the subscription through the control plane method includes: configuring the certificate and/or the subscription for the first communication device through the control plane method.
  • causing the first communication device to obtain the certificate and/or subscription through the user plane method includes: configuring the certificate and/or the subscription through the user plane method for the first communication device.
  • causing the first communication device to obtain the certificate and/or contract of the first object through a control plane method includes: configuring the first communication device through a control plane method with the certificate and/or the first object's certificate contract.
  • enabling the first communication device to obtain the first object's certificate and/or signing the contract through the user plane method includes: configuring the first object's certificate and/or the first object's certificate for the first communication device through the user plane method. contract.
  • configuring a certificate and/or signing a contract for the first communication device includes: causing the first communication device to obtain a certificate and/or signing a contract includes: .
  • configuring the certificate and/or signing the first communication device through the control plane method includes: causing the first communication device to obtain the certificate and/or signing the contract through the control plane method includes:
  • configuring the certificate and/or signing the first communication device through the user plane method includes: causing the first communication device to obtain the certificate and/or signing the contract through the user plane method includes:
  • configuring the certificate and/or subscription of the first object for the first communication device through the control plane method includes causing the first communication device to obtain the certificate and/or subscription of the first object through the control plane method .
  • configuring the certificate and/or signing of the first object for the first communication device through the user plane method includes: enabling the first communication device to obtain the certificate and/or the first object's certificate through the user plane method. contract. It is not difficult to understand that when the certificate and/or subscription of the first network is provided by an entity other than the network accessed by the terminal, the configuring the certificate and/or the subscription for the first communication device may be understood as making the first communication The communication device obtains the certificate and/or the subscription of the first object by means of the user plane.
  • an embodiment of the present application provides a method for supporting network selection, which is performed by a first communication device, where the first communication device includes but is not limited to a terminal (UE).
  • the specific steps include: step 201 and step 202 .
  • Step 201 Obtain first information, where the first information includes: a first list, a second list and/or first indication information;
  • Step 202 Select a network according to the first information
  • the first list includes one of the following:
  • the characteristics of the networks in the first list include at least one of the following:
  • the first communication device is capable of restricted access
  • the first communication device can access by using the default certificate
  • the characteristics of the networks in the first list include networks to which the first communication device can access restricted and enable the first communication device to obtain a certificate and/or a subscription.
  • the default credentials include credentials for the restricted access mode.
  • the first list includes at least one of the following:
  • the characteristics of the networks in the list of networks that can be configured with certificates and/or subscribed include one of the following: the first communication device is capable of restricted access and enables the first communication device to obtain a certificate and/or contract, the first communication device can access by using the default certificate.
  • the second list includes:
  • the characteristics of the networks in the second list include at least one of the following:
  • the first communication device cannot be accessed
  • the first communication device cannot be made to obtain a certificate and/or a contract
  • the second list includes at least one of the following:
  • the network list includes:
  • the network object includes a network and/or a network group
  • the first indication information is used to indicate at least one of the following:
  • the first communication device obtains the first list and/or the second list through pre-configuration. In another implementation manner, the first communication device obtains the first list and/or the second list from the accessed network or the first server.
  • the first server is a server that configures a certificate and/or a subscription for the first communication device.
  • the certificate and/or contract includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a contract for primary authentication and/or authorization , for certificates and/or signings other than primary authentication and/or authorization;
  • the non-primary authentication and/or authorization includes at least one of the following: secondary authentication and/or authorization (Secondary authentication/authorization), slice-related authentication and/or authorization (Network Slice-Specific Authentication and Authorization, NSSAA).
  • Secondary authentication and/or authorization Secondary authentication/authorization
  • slice-related authentication and/or authorization Network Slice-Specific Authentication and Authorization, NSSAA.
  • the first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
  • the first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
  • the A network is the same as or different from the network in the first list
  • the A network is the same as or different from the network in the second list;
  • the A network is the same as or different from the network accessed by the first communication device; and/or,
  • the obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
  • the list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
  • the characteristics of the networks in the list of networks that can configure certificates and/or subscriptions by means of the control plane include one of the following: the first communication device can have restricted access, and the first communication device can The certificate and/or the subscription is obtained by means of the control plane, and the first communication device can access by using the default certificate.
  • the characteristics of the networks in the list of networks that can be configured with certificates and/or subscriptions in a user plane manner include one of the following: the first communication device can have restricted access, and the first communication device can Obtaining the certificate and/or signing the contract through the user plane, the first communication device can access by using the default certificate.
  • enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or To sign a contract, the first communication device can obtain a certificate and/or a contract through a user plane method.
  • the certificate and/or subscription of the first object includes a certificate and/or subscription for accessing the first object.
  • the first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;
  • the second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;
  • the list of networks capable of configuring certificates and/or subscriptions includes: a list of networks capable of configuring certificates and/or subscriptions of the first object;
  • the list of networks for which the certificate and/or subscription cannot be configured includes: the list of networks for which the certificate and/or subscription of the first object cannot be configured;
  • the enabling of the first communication device to obtain the certificate and/or the contract includes: enabling the first communication device to obtain the certificate and/or the contract of the first object;
  • the inability to enable the first communication device to obtain the certificate and/or the contract includes: the inability to enable the first communication device to obtain the certificate and/or the contract of the first object.
  • the first list corresponding to the first object includes: a first list corresponding to the first object through the control plane, and the first object corresponding to the user the first list of face modes;
  • the first list corresponding to the first object through the control plane method and the first list through the user plane method corresponding to the first object are the same or different;
  • the network corresponding to the first object in the first list by means of the control plane includes a network capable of enabling the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
  • the network corresponding to the first object in the first list through the user plane method includes a network that enables the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
  • the second list corresponding to the first object includes: a second list corresponding to the first object through a control plane method, and a second list corresponding to the first object through a user plane method;
  • the second list corresponding to the first object through the control plane method and the second list corresponding to the first object through the user plane method are the same or different;
  • the networks in the second list by means of the control plane corresponding to the first object include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
  • the networks in the second list corresponding to the first object through the user plane method include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
  • the list of networks that can configure the certificate and/or subscription of the first object includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object through the control plane, and the certificate of the first object can be configured through the user plane. and/or a list of contracted networks;
  • the list of networks for which the certificate and/or subscription of the first object cannot be configured includes at least one of the following: a list of the subject's credentials and/or contracted networks;
  • the ability to enable the first communication device to obtain the certificate and/or the contract of the A object includes at least one of the following: enabling the first communication device to obtain the certificate and/or the contract of the first object by means of a control plane, enabling the first communication device to obtain the certificate and/or contract of the first object The first communication device obtains the certificate and/or the subscription of the first object by means of the user plane;
  • the inability to enable the first communication device to obtain the certificate and/or the contract of the A object includes at least one of the following: the first communication device cannot be enabled to obtain the certificate and/or the contract of the first object by means of the control plane; The first communication device is caused to obtain the certificate and/or subscription of the first object through the user plane.
  • the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: a public network, Non-public network, PLMN, non-independent non-public network (Public Network Integrated Non-Public Network, PNI-NPN), SNPN.
  • the obtaining the first indication information includes:
  • the first indication information is broadcast from the cell or received from the second communication device.
  • the method further includes:
  • the selecting a network according to the first information includes: selecting the first network when the first condition is satisfied;
  • the first condition includes at least one of the following:
  • the first network is a network in the first list
  • the first indication information is obtained from the first network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the first list includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object; a first list corresponding to the first object; the networks in the first list can enable the first communication device to obtain The certificate and/or subscription of the first object; the list of allowed networks corresponding to the certificate and/or subscription of the first object;
  • the first network has the highest priority in the first list
  • the first communication device is within the coverage of the first network or the first communication device can monitor the signal of the first network.
  • the selecting a network according to the first information includes:
  • the second network is selected
  • the second condition includes at least one of the following:
  • the second network is not a network in the second list
  • the first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the second list includes at least one of the following: a list of networks that cannot configure the certificate and/or subscription of the first object; a second list corresponding to the first object; the networks in the second list cannot enable the first communication
  • the device obtains the certificate and/or subscription of the first object; the list of disallowed networks corresponding to the certificate and/or subscription of the first object;
  • the first communication device is out of coverage of any network in the first list or the first communication device cannot monitor the signal of any network in the first list.
  • the networks in the first list are sorted by priority.
  • the selecting a network according to the first information includes:
  • the third condition includes at least one of the following:
  • the third network is a network in the first list
  • the first indication information is obtained from the third network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, a list of networks that can configure the certificate and/or subscription of the first object in a control plane manner; networks in the first list
  • the first communication device can be enabled to obtain the certificate and/or subscription of the first object through the control plane; the first communication device is within the coverage of the third network or the first communication device can monitor the signal of the third network ;
  • the fourth condition includes at least one of the following:
  • the fourth network is a network in the first list
  • the first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions, support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the first list includes at least one of the following: a first list corresponding to the first object through a user plane method, and a network list of certificates and/or subscriptions of the first object that can be configured through a user plane method; the first list The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane;
  • the first communication device is within the coverage of the fourth network or the first communication device can monitor the signal of the fourth network.
  • the first communication device is instructed to select a network for downloading the certificate and/or signing the contract through the first indication information.
  • the first communication device may select a network for downloading a certificate and/or signing a subscription according to the first information.
  • an embodiment of the present application provides a method for supporting network selection, which is performed by a second communication device, where the second communication device includes but is not limited to one of the following: a RAN network element, a CN network element (such as access and mobility Management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF)), the specific steps include:
  • Step 301 Send first indication information
  • the first indication information is used to indicate at least one of the following:
  • the first indication information is broadcast through a cell system message.
  • the second communication device is a communication device in the first network or the second network
  • the first communication device is instructed to select a network for downloading the certificate and/or signing the contract through the first indication information.
  • an embodiment of the present application provides a method for supporting network selection, which is performed by a third communication device, where the third communication device includes but is not limited to one of the following: a RAN network element, a CN network element (such as AMF, SMF),
  • the first server, the first entity, the specific steps include:
  • Step 401 Send the first list and/or the second list
  • the first list includes:
  • the first communication device is capable of restricted access
  • the first communication device can access by using the default certificate
  • the networks in the first list include networks to which the first communication device can access restricted and enable the first communication device to obtain a certificate and/or a subscription.
  • the first list includes at least one of the following:
  • the characteristics of the networks in the list of networks that can be configured with certificates and/or subscribed include one of the following: the first communication device is capable of restricted access and enables the first communication device to obtain a certificate and/or contract, the first communication device can access by using the default certificate.
  • the second list includes:
  • the first communication device cannot be accessed
  • the first communication device cannot be made to obtain a certificate and/or a contract
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or identification information of one or more network objects, and the network objects include networks and/or network groups.
  • the certificate and/or subscription includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a certificate for primary authentication and/or authorization Contracts, certificates and/or contracts for non-primary certification and/or authorization;
  • the first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
  • the first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
  • the A network is the same as or different from the network in the first list
  • the A network is the same as or different from the network in the second list.
  • the A network is the same as or different from the network accessed by the first communication device;
  • the obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
  • the list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
  • the characteristics of the networks in the list of networks that can configure certificates and/or subscriptions by means of the control plane include one of the following: the first communication device can have restricted access, and the first communication device can The certificate and/or the subscription is obtained by means of the control plane, and the first communication device can access by using the default certificate.
  • the characteristics of the networks in the list of networks that can be configured with certificates and/or subscriptions in a user plane manner include one of the following: the first communication device can have restricted access, and the first communication device can Obtaining the certificate and/or signing the contract through the user plane, the first communication device can access by using the default certificate.
  • enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate and/or signing a contract; A communication device obtains a certificate and/or a subscription through the user plane.
  • the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: a public network, Non-public network, PLMN, PNI NPN, SNPN.
  • the networks in the first list are sorted by priority.
  • the first communication device is instructed to select a network for downloading the certificate and/or signing the contract through the first list and/or the second list.
  • Step 1 Configure the terminal to obtain the first object (eg, SNPN2) certificate and/or the first list corresponding to the subscription (eg, a mixed network list of SNPN and PLMN).
  • the first object eg, SNPN2
  • the first list corresponding to the subscription eg, a mixed network list of SNPN and PLMN.
  • Step 2 Receive the first indication information sent by the second communication device (such as the RAN network element or the CN network element);
  • Step 3 Select a network according to the first list and the first indication information.
  • step 3 reference may be made to the description of the embodiment shown in FIG. 2 . ⁇ 1st>
  • an embodiment of the present application provides an apparatus for supporting network selection, which is applied to a first communication device.
  • the apparatus 600 includes:
  • a first obtaining module 601 configured to obtain first information, where the first information includes: a first list, a second list and/or first indication information;
  • a selection module 602 configured to select a network according to the first information
  • the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include the following At least one item: the first communication device is capable of restricted access, enabling the first communication device to obtain a certificate and/or signing a contract, and the first communication device can access by using a default certificate;
  • the first list includes at least one of the following:
  • the networks in the list of networks that can be configured with certificates and/or subscriptions include networks that the first communication device can access restricted and enable the first communication device to obtain certificates and/or subscriptions. network.
  • the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least the following: Item 1: the first communication device cannot be accessed, the first communication device cannot be made to obtain a certificate and/or a contract, and the first communication device cannot access using a default certificate;
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
  • the first indication information is used to indicate at least one of the following:
  • the first communication device obtains the first list and/or the second list through pre-configuration.
  • the credentials and/or subscriptions of the first object include credentials and/or subscriptions for accessing the first object.
  • the first communication device obtains the first list and/or the second list through pre-configuration.
  • the credentials and/or subscriptions of the first object include credentials and/or subscriptions for accessing the first object.
  • the certificate and/or contract includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a contract for primary authentication and/or authorization , for certificates and/or signings other than primary authentication and/or authorization;
  • the first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
  • the first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
  • the A network is the same as or different from the network in the first list
  • the A network is the same as or different from the network in the second list;
  • the A network is the same as or different from the network accessed by the first communication device;
  • the obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
  • the list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
  • Enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate and/or signing through a user plane way to obtain a certificate and/or contract.
  • the first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;
  • the second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;
  • the list of networks capable of configuring certificates and/or subscriptions includes: a list of networks capable of configuring certificates and/or subscriptions of the first object;
  • the list of networks for which the certificate and/or subscription cannot be configured includes: the list of networks for which the certificate and/or subscription of the first object cannot be configured;
  • the enabling of the first communication device to obtain the certificate and/or the contract includes: enabling the first communication device to obtain the certificate and/or the contract of the first object;
  • the inability to enable the first communication device to obtain the certificate and/or the contract includes: the inability to enable the first communication device to obtain the certificate and/or the contract of the first object.
  • the first list corresponding to the first object includes: a first list corresponding to the first object through the control plane, and the first object corresponding to the user the first list of face modes;
  • the first list corresponding to the first object through the control plane method and the first list through the user plane method corresponding to the first object are the same or different;
  • the networks in the first list by means of the control plane corresponding to the first object include: networks capable of enabling the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
  • the network corresponding to the first object in the first list through the user plane method includes: a network capable of enabling the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
  • the second list corresponding to the first object includes: a second list corresponding to the first object through a control plane method, and a second list corresponding to the first object through a user plane method;
  • the second list corresponding to the first object through the control plane method and the second list corresponding to the first object through the user plane method are the same or different;
  • the networks in the second list by means of the control plane corresponding to the first object include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
  • the networks in the second list corresponding to the first object through the user plane method include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
  • the list of networks that can configure the certificate and/or subscription of the first object includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object in a control plane mode, and a list of networks that can configure the certificate and/or subscription of the first object in a user plane mode. the certificate and/or contracted network list of the first object;
  • the list of networks for which the certificate and/or contract of the first object cannot be configured includes at least one of the following: the list of networks for which the certificate and/or the contract of the first object cannot be configured through the control plane, and the list of networks that cannot be configured through the user plane way to configure the certificate and/or contracted network list of the first object;
  • the enabling of the first communication device to obtain the certificate and/or the contract of the first object includes at least one of the following: enabling the first communication device to obtain the certificate and/or the contract of the first object by means of a control plane , enabling the first communication device to obtain the certificate and/or contract of the first object through the user plane;
  • the inability to enable the first communication device to obtain the first object's certificate and/or the contract includes at least one of the following: inability to enable the first communication device to obtain the first object's certificate and/or by means of the control plane or contract, the first communication device cannot obtain the certificate and/or contract of the first object through the user plane method.
  • the network types of the networks in the first list, the networks in the second list, and/or the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
  • the first obtaining module 601 is further configured to: broadcast from a cell or receive the first indication information from a second communication device.
  • the apparatus 600 further includes:
  • the second obtaining module is configured to obtain at least one of the following items by accessing the network in the first list:
  • the selection module 602 is further configured to:
  • the first network is selected
  • the first condition includes at least one of the following:
  • the first network is a network in the first list
  • the first indication information is obtained from the first network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the first list includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object; a first list corresponding to the first object; the networks in the first list can enable the first communication device to obtain The certificate and/or subscription of the first object; the list of allowed networks corresponding to the certificate and/or subscription of the first object;
  • the first network has the highest priority in the first list
  • the first communication device is within the coverage of the first network or the first communication device can monitor the signal of the first network.
  • the selection module 602 is further configured to:
  • the second network is selected
  • the second condition includes at least one of the following:
  • the second network is not a network in the second list
  • the first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the second list includes at least one of the following: a list of networks that cannot configure the certificate and/or subscription of the first object; a second list corresponding to the first object;
  • the first communication device obtains the certificate and/or subscription of the first object; the list of disallowed networks corresponding to the certificate and/or subscription of the first object;
  • the first communication device is out of coverage of any network in the first list or the first communication device cannot monitor the signal of any network in the first list.
  • the networks in the first list are sorted by priority.
  • the selection module 602 is further configured to:
  • the third condition includes at least one of the following:
  • the third network is a network in the first list
  • the first indication information is obtained from the third network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, and a network list of certificates and/or subscriptions of the first object that can be configured in a control plane manner; the first The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the control plane; the first communication device is within the coverage of the third network or the first communication device can monitor the signal to the third network;
  • the fourth condition includes at least one of the following:
  • the fourth network is a network in the first list
  • the first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions, support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
  • the terminal needs to obtain the certificate and/or contract of the first object
  • the first list includes at least one of the following: a first list corresponding to the first object through a user plane method, and a network list of certificates and/or subscriptions of the first object that can be configured through a user plane method; the first list The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane;
  • the first communication device is within the coverage of the fourth network or the first communication device can monitor the signal of the fourth network.
  • the apparatus provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 2 , and achieve the same technical effect. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for supporting network selection, which is applied to a second communication device.
  • the apparatus 700 includes:
  • a first sending module 701, configured to send first indication information
  • the first indication information is used to indicate at least one of the following:
  • the apparatus provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 3 , and achieve the same technical effect. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for supporting network selection, which is applied to a third communication device.
  • the apparatus 800 includes:
  • a second sending module 801, configured to send the first list and/or the second list
  • the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include the following At least one item: the first communication device is capable of restricted access, enabling the first communication device to obtain a certificate and/or sign a contract, and the first communication device can access by using a default certificate;
  • the networks in the first list include networks to which the first communication device can access restricted and enable the first communication device to obtain a certificate and/or a subscription.
  • the first list includes at least one of the following:
  • the networks in the list of networks that can be configured with certificates and/or subscriptions include networks that the first communication device can access restricted and enable the first communication device to obtain certificates and/or subscriptions. network.
  • the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least the following: Item 1: the first communication device cannot be accessed, the first communication device cannot be made to obtain a certificate and/or a contract, and the first communication device cannot access using a default certificate;
  • the second list includes at least one of the following:
  • the network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
  • the certificate and/or contract includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a contract for primary authentication and/or authorization , for certificates and/or signings other than primary authentication and/or authorization;
  • the first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
  • the first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
  • the A network is the same as or different from the network in the first list
  • the A network is the same as or different from the network in the second list.
  • the A network is the same as or different from the network accessed by the first communication device;
  • the obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
  • the list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
  • Enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate and/or signing through a user plane way to obtain a certificate and/or contract.
  • the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
  • the networks in the first list are sorted by priority.
  • the apparatus provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 4 , and achieve the same technical effect. To avoid repetition, details are not repeated here.
  • the apparatus provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 4 , and achieve the same technical effect. To avoid repetition, details are not repeated here.
  • FIG. 9 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.
  • the terminal 900 includes but is not limited to: a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user Input unit 907, interface unit 908, memory 909, processor 910 and other components.
  • the terminal 900 may also include a power source (such as a battery) for supplying power to various components, and the power source may be logically connected to the processor 910 through a power management system, so as to manage charging, discharging, and power consumption through the power management system management and other functions.
  • a power source such as a battery
  • the terminal structure shown in FIG. 9 does not constitute a limitation on the terminal, and the terminal may include more or less components than shown, or combine some components, or arrange different components, which will not be repeated here.
  • the input unit 904 may include a graphics processor (Graphics Processing Unit, GPU) 9041 and a microphone 9042. Such as camera) to obtain still pictures or video image data for processing.
  • the display unit 906 may include a display panel 9061, which may be configured in the form of a liquid crystal display, an organic light emitting diode, or the like.
  • the user input unit 907 includes a touch panel 9071 and other input devices 9072 .
  • the touch panel 9071 is also called a touch screen.
  • the touch panel 9071 may include two parts, a touch detection device and a touch controller.
  • Other input devices 9072 may include, but are not limited to, physical keyboards, function keys (such as volume control keys, switch keys, etc.), trackballs, mice, and joysticks, which will not be repeated here.
  • the radio frequency unit 901 receives the downlink data from the network side device, and then processes it to the processor 910; in addition, sends the uplink data to the network side device.
  • the radio frequency unit 901 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, and the like.
  • Memory 909 may be used to store software programs or instructions as well as various data.
  • the memory 909 may mainly include a storage program or instruction area and a storage data area, wherein the stored program or instruction area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.) and the like.
  • the memory 909 may include a high-speed random access memory, and may also include a non-volatile memory, wherein the non-volatile memory may be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM) , PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or flash memory.
  • ROM Read-Only Memory
  • PROM programmable read-only memory
  • PROM erasable programmable read-only memory
  • Erasable PROM Erasable PROM
  • EPROM electrically erasable programmable read-only memory
  • EEPROM electrically erasable programmable read-only memory
  • flash memory for example at least one magnetic disk storage device, flash memory device, or other non-volatile solid state storage device.
  • the processor 910 may include one or more processing units; optionally, the processor 910 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, application programs or instructions, etc., Modem processors mainly deal with wireless communications, such as baseband processors. It can be understood that, the above-mentioned modulation and demodulation processor may not be integrated into the processor 910.
  • the terminal provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 2 and achieve the same technical effect. To avoid repetition, details are not described here.
  • the network side device 1000 includes: an antenna 1001 , a radio frequency device 1002 , and a baseband device 1003 .
  • the antenna 1001 is connected to the radio frequency device 1002 .
  • the radio frequency device 1002 receives information through the antenna 1001, and sends the received information to the baseband device 1003 for processing.
  • the baseband device 1003 processes the information to be sent and sends it to the radio frequency device 1002
  • the radio frequency device 1002 processes the received information and sends it out through the antenna 1001 .
  • the above-mentioned frequency band processing apparatus may be located in the baseband apparatus 1003 , and the method performed by the network side device in the above embodiments may be implemented in the baseband apparatus 1003 .
  • the baseband apparatus 1003 includes a processor 1004 and a memory 1005 .
  • the baseband device 1003 may include, for example, at least one baseband board on which multiple chips are arranged, as shown in FIG. 10 , one of the chips is, for example, the processor 1004 , which is connected to the memory 1005 to call a program in the memory 1005 to execute
  • the network devices shown in the above method embodiments operate.
  • the baseband device 1003 may also include a network interface 1006 for exchanging information with the radio frequency device 1002, and the interface is, for example, a Common Public Radio Interface (CPRI for short).
  • CPRI Common Public Radio Interface
  • the network-side device in this embodiment of the present application further includes: an instruction or program stored in the memory 1005 and executable on the processor 1004, and the processor 1004 invokes the instruction or program in the memory 1005 to execute the instructions or programs shown in FIGS. 7-8.
  • the methods performed by each module are shown, and the same technical effect is achieved. In order to avoid repetition, it is not repeated here.
  • An embodiment of the present application further provides a program product, where the program product is stored in a non-volatile storage medium, and the program product is executed by at least one processor to implement the processing method as described in FIG. 2 to FIG. 4 .
  • An embodiment of the present application further provides a readable storage medium, where a program or an instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, each process of the method embodiment shown in FIG. 2 to FIG. 4 is implemented. , and can achieve the same technical effect, in order to avoid repetition, it is not repeated here.
  • the processor is the processor in the terminal described in the foregoing embodiment.
  • the readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, and the like.
  • An embodiment of the present application further provides a chip, where the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a network-side device program or instruction to implement the above-mentioned FIG. 2-
  • the chip includes a processor and a communication interface
  • the communication interface is coupled to the processor
  • the processor is used to run a network-side device program or instruction to implement the above-mentioned FIG. 2-
  • the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, a system-on-chip, a system-on-chip, or a system-on-a-chip, or the like.
  • the method of the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is better implementation.
  • the technical solution of the present application can be embodied in the form of a software product in essence or in a part that contributes to the prior art, and the computer software product is stored in a storage medium (such as ROM/RAM, magnetic disk, CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, or a network device, etc.) execute the methods described in the various embodiments of this application.
  • a storage medium such as ROM/RAM, magnetic disk, CD-ROM

Abstract

The present application discloses a method, apparatus, and device for supporting network selection, and a readable storage medium. The method comprises: acquiring first information, which comprises: a first list, a second list, and/or first indication information; and selecting a network on the basis of the first information.

Description

支持网络选择的方法、装置、设备及可读存储介质Method, apparatus, device and readable storage medium for supporting network selection
相关申请的交叉引用CROSS-REFERENCE TO RELATED APPLICATIONS
本申请主张在2021年02月05日在中国提交的中国专利申请No.202110164165.2的优先权,其全部内容通过引用包含于此。This application claims priority to Chinese Patent Application No. 202110164165.2 filed in China on Feb. 05, 2021, the entire contents of which are hereby incorporated by reference.
技术领域technical field
本申请属于通信技术领域,具体涉及一种支持网络选择的方法、装置、设备及可读存储介质。The present application belongs to the field of communication technologies, and in particular relates to a method, apparatus, device and readable storage medium for supporting network selection.
背景技术Background technique
终端(例如用户终端(User Equipment,UE))希望临时接入第一网络获得第一对象的证书和/或签约。如何选择第一网络的问题亟待解决的问题。A terminal (for example, a user terminal (User Equipment, UE)) wishes to temporarily access the first network to obtain the certificate and/or subscription of the first object. The problem of how to select the first network is an urgent problem to be solved.
发明内容SUMMARY OF THE INVENTION
本申请实施例提供一种支持网络选择的方法、装置、设备及可读存储介质,解决如何选择用于下载证书和/或签约的网络的问题。Embodiments of the present application provide a method, apparatus, device, and readable storage medium for supporting network selection, so as to solve the problem of how to select a network for downloading a certificate and/or signing a subscription.
第一方面,提供一种支持网络选择的方法,由第一通信设备执行,包括:In a first aspect, a method for supporting network selection is provided, executed by a first communication device, including:
获得第一信息,所述第一信息包括:第一列表,第二列表和/或第一指示信息;obtaining first information, where the first information includes: a first list, a second list and/or first indication information;
根据所述第一信息选择网络;selecting a network according to the first information;
其中,in,
所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,所述第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
能够被受限接入的网络列表;A list of networks that can be restricted access;
能够配置证书和/或签约的网络列表;A list of networks that can configure certificates and/or subscriptions;
能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
或者,第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
其中,所述网络列表包括一个或多个网络对象,或一个或多个网络对象的标识信息;所述网络对象包括网络和/或网络组;Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
所述第一指示信息用于指示以下至少一项:The first indication information is used to indicate at least one of the following:
支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
第二方面,提供一种支持网络选择的方法,由第二通信设备执行,包括:In a second aspect, a method for supporting network selection is provided, performed by a second communication device, including:
发送第一指示信息;sending first indication information;
其中,所述第一指示信息用于指示以下至少一项:Wherein, the first indication information is used to indicate at least one of the following:
支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
第三方面,提供一种支持网络选择的方法,由第三通信设备执行,包括:In a third aspect, a method for supporting network selection is provided, executed by a third communication device, including:
发送第一列表和/或第二列表;send the first list and/or the second list;
所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
能够被受限接入的网络列表,A list of networks that can be restricted to access,
能够配置证书和/或签约的网络列表,Ability to configure a list of certificates and/or signed networks,
能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
或者,所述第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
所述网络列表包括一个或多个网络对象,或所述网络列表包括一个或多个网络对象的标识信息,所述网络对象包括网络和/或网络组。The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
第四方面,提供一种支持网络选择的装置,应用第一通信设备执行,包括:In a fourth aspect, an apparatus for supporting network selection is provided, which is executed by a first communication device, including:
第一获取模块,用于获得第一信息,所述第一信息包括:第一列表,第二列表和/或第一指示信息;a first obtaining module, configured to obtain first information, where the first information includes: a first list, a second list and/or first indication information;
选择模块,用于根据所述第一信息选择网络;a selection module, configured to select a network according to the first information;
其中,in,
所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,所述第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
能够被受限接入的网络列表;A list of networks that can be restricted access;
能够配置证书和/或签约的网络列表;A list of networks that can configure certificates and/or subscriptions;
能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
或者,第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
其中,所述网络列表包括一个或多个网络对象,或一个或多个网络对象的标识信息;所述网络对象包括网络和/或网络组;Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
所述第一指示信息用于指示以下至少一项:The first indication information is used to indicate at least one of the following:
支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
第五方面,提供一种支持网络选择的装置,应用于第二通信设备,包括:A fifth aspect provides an apparatus for supporting network selection, which is applied to a second communication device, including:
第一发送模块,用于发送第一指示信息;a first sending module, configured to send the first indication information;
其中,所述第一指示信息用于指示以下至少一项:Wherein, the first indication information is used to indicate at least one of the following:
支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
第六方面,提供一种支持网络选择的装置,应用于第三通信设备,包括:In a sixth aspect, an apparatus for supporting network selection is provided, applied to a third communication device, including:
第二发送模块,用于发送第一列表和/或第二列表;a second sending module, configured to send the first list and/or the second list;
所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
能够被受限接入的网络列表,A list of networks that can be restricted to access,
能够配置证书和/或签约的网络列表,Ability to configure a list of certificates and/or signed networks,
能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
或者,所述第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
所述网络列表包括一个或多个网络对象,或所述网络列表包括一个或多个网络对象的标识信息,所述网络对象包括网络和/或网络组。The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
第七方面,提供一种终端,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如第一方面所述的方法的步骤。In a seventh aspect, a terminal is provided, comprising: a processor, a memory, and a program stored on the memory and executable on the processor, the program being executed by the processor to implement the method described in the first aspect steps of the method described.
第八方面,提供一种网络侧设备,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如第二方面或第三方面所述的方法的步骤。In an eighth aspect, a network-side device is provided, including: a processor, a memory, and a program stored on the memory and executable on the processor, the program being executed by the processor to achieve the second The steps of the method of aspect or third aspect.
第九方面,提供一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如上所述的方法的步骤。In a ninth aspect, a readable storage medium is provided, and a program or an instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the steps of the above-mentioned method are implemented.
第十方面,提供一种计算机程序产品,所述计算机程序产品被存储在非易失的存储介质中,所述计算机程序产品被至少一个处理器执行以实现如上所述的方法的步骤。In a tenth aspect, a computer program product is provided, the computer program product being stored in a non-volatile storage medium, the computer program product being executed by at least one processor to implement the steps of the method as described above.
第十一方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如上所述的方法的步骤。In an eleventh aspect, a chip is provided, the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is configured to run a program or an instruction to implement the steps of the above method .
在本申请实施例中,支持第一通信设备确认选择用于下载证书和/或签约的网络。In this embodiment of the present application, the first communication device is supported to confirm and select a network for downloading a certificate and/or signing a contract.
附图说明Description of drawings
图1是本申请实施例可应用的一种无线通信系统的示意图;FIG. 1 is a schematic diagram of a wireless communication system to which an embodiment of the present application can be applied;
图2是本申请实施例提供的支持网络选择的方法的流程图之一;2 is one of the flowcharts of the method for supporting network selection provided by an embodiment of the present application;
图3是本申请实施例提供的支持网络选择的方法的流程图之二;3 is the second flowchart of the method for supporting network selection provided by an embodiment of the present application;
图4是本申请实施例提供的支持网络选择的方法的流程图之三;FIG. 4 is the third flowchart of the method for supporting network selection provided by an embodiment of the present application;
图5是本申请实施例提供的支持网络选择的方法的流程图之四;FIG. 5 is a fourth flowchart of a method for supporting network selection provided by an embodiment of the present application;
图6是本申请实施例提供的支持网络选择的装置的示意图之一;6 is one of the schematic diagrams of the apparatus for supporting network selection provided by an embodiment of the present application;
图7是本申请实施例提供的支持网络选择的装置的示意图之二;7 is a second schematic diagram of an apparatus for supporting network selection provided by an embodiment of the present application;
图8是本申请实施例提供的支持网络选择的装置的示意图之三;8 is a third schematic diagram of an apparatus for supporting network selection provided by an embodiment of the present application;
图9是本申请实施例提供的终端的示意图;9 is a schematic diagram of a terminal provided by an embodiment of the present application;
图10是本申请实施例的网络侧设备的示意图。FIG. 10 is a schematic diagram of a network side device according to an embodiment of the present application.
具体实施方式Detailed ways
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of this application.
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“和/或”的关系。The terms "first", "second" and the like in the description and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and "first", "second" distinguishes Usually it is a class, and the number of objects is not limited. For example, the first object may be one or multiple. In addition, "and/or" in the description and claims refers to at least one of the connected objects, and the character "/" generally indicates that the contextual objects are in an "and/or" relationship.
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency-Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。然而,以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,尽管这些技术也可应用于NR系统应用以外的应用,如第6代(6th Generation,6G)通信系统。It is worth noting that the technologies described in the embodiments of this application are not limited to Long Term Evolution (LTE)/LTE-Advanced (LTE-Advanced, LTE-A) systems, and can also be used in other wireless communication systems, such as code Division Multiple Access (Code Division Multiple Access, CDMA), Time Division Multiple Access (Time Division Multiple Access, TDMA), Frequency Division Multiple Access (Frequency Division Multiple Access, FDMA), Orthogonal Frequency Division Multiple Access (Orthogonal Frequency Division Multiple Access, OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used not only for the above-mentioned systems and radio technologies, but also for other systems and radio technologies. However, the following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, although these techniques are also applicable to applications other than NR system applications, such as 6th generation ( 6th Generation, 6G) communication system.
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11也可以称作终端设备或者用 户终端(User Equipment,UE),终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(Ultra-Mobile Personal Computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、可穿戴式设备(Wearable Device)或车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)等终端侧设备,可穿戴式设备包括:手环、耳机、眼镜等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以是基站或核心网,其中,基站可被称为节点B、演进节点B、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、B节点、演进型B节点(eNB)、家用B节点、家用演进型B节点、无线局域网(Wireless Local Area Networks,WLAN)接入点、无线保真(Wireless Fidelity,WiFi)节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例,但是并不限定基站的具体类型。FIG. 1 shows a block diagram of a wireless communication system to which the embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network-side device 12 . The terminal 11 may also be called a terminal device or a user terminal (User Equipment, UE), and the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital computer Assistant (Personal Digital Assistant, PDA), PDA, Netbook, Ultra-Mobile Personal Computer (UMPC), Mobile Internet Device (Mobile Internet Device, MID), Wearable Device (Wearable Device) or vehicle-mounted device (Vehicle User Equipment, VUE), pedestrian terminal (Pedestrian User Equipment, PUE) and other terminal-side devices, wearable devices include: bracelets, headphones, glasses, etc. It should be noted that, the embodiment of the present application does not limit the specific type of the terminal 11 . The network side device 12 may be a base station or a core network, wherein the base station may be referred to as a Node B, an evolved Node B, an access point, a Base Transceiver Station (BTS), a radio base station, a radio transceiver, a basic service Set (Basic Service Set, BSS), Extended Service Set (Extended Service Set, ESS), Node B, Evolved Node B (eNB), Home Node B, Home Evolved Node B, Wireless Local Area Networks (WLAN) ) access point, wireless fidelity (Wireless Fidelity, WiFi) node, transmitting and receiving point (Transmitting Receiving Point, TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to For specific technical terms, it should be noted that in the embodiments of this application, only the base station in the NR system is used as an example, but the specific type of the base station is not limited.
在相关技术中,终端(例如UE)可以接入公共陆地移动网(Public Land Mobile Network,PLMN)或独立组网的非公共网络(Standalone Non-Public Network,SNPN)1来下载第一对象的证书(如SNPN2的证书,或,用于二次认证和/或授权的证书)。当UE没有SNPN1的证书(如用于非受限接入的证书)时,如果SNPN1支持第一接入方式(如onboarding)的功能,那么SNPN1可以称为Onboarding SNPN(简称O-SNPN)。第一接入方式可以是通过受限接入网络和/或通过所述网络获取第一网络的证书的接入方式。当接入Onboarding SNPN时,UE没有O-SNPN的证书(没有用于非受限接入的证书),用的是默认证书(Default credential,比如用于受限接入的证书)接入O-SNPN,并且要提供onboarding指示来说明UE的注册类型的特殊性。因此在O-SNPN的场景下,包括两个功能:In the related art, a terminal (eg, UE) can access a public land mobile network (Public Land Mobile Network, PLMN) or an independent non-public network (Standalone Non-Public Network, SNPN) 1 to download the certificate of the first object (eg SNPN2 certificate, or, for secondary authentication and/or authorization). When the UE does not have a certificate of SNPN1 (such as a certificate for unrestricted access), if the SNPN1 supports the function of the first access mode (such as onboarding), then the SNPN1 may be called an Onboarding SNPN (O-SNPN for short). The first access manner may be an access manner in which the certificate of the first network is acquired through a restricted access network and/or through the network. When accessing the Onboarding SNPN, the UE does not have an O-SNPN certificate (no certificate for unrestricted access), and uses a default certificate (Default credential, such as a certificate for restricted access) to access O- SNPN, and an onboarding indication is to be provided to illustrate the specificity of the UE's registration type. Therefore, in the scenario of O-SNPN, it includes two functions:
(1)默认证书入网(Default credential onboarding)或者是受限接入方式接入网络;(1) Default credential onboarding or restricted access to the network;
(2)配置第一对象的证书和/或签约。(2) Configure the certificate and/or contract of the first object.
O-SNPN的小区可以广播onboarding的指示用于UE选择O-SNPN并获取第一对象的证书和/或签约。The cell of the O-SNPN may broadcast an onboarding indication for the UE to select the O-SNPN and obtain the certificate and/or subscription of the first object.
当通过PLMN或SNPN3来下载SNPN2证书时,由于UE具有能够接入PLMN或SNPN3的证书(比如用于非受限接入的证书),所以本质上PLMN或SNPN3可以不支持(1)的功能,而可以仅支持(2)的功能。因此,PLMN或SNPN3如果要广播网络的能力,不适合广播用于指示支持onboarding的指示信息。因此还要解决以下问题。When the SNPN2 certificate is downloaded through the PLMN or SNPN3, since the UE has a certificate capable of accessing the PLMN or SNPN3 (such as a certificate for unrestricted access), essentially the PLMN or SNPN3 may not support the function of (1), Instead, only the functions of (2) can be supported. Therefore, if the PLMN or SNPN3 wants to broadcast the capabilities of the network, it is not suitable to broadcast the indication information for indicating that onboarding is supported. Therefore, the following problems have to be solved.
问题一:UE如何接入选择已经具有用于非受限接入的证书和/或签约的网络(如PLMN和SNPN3)来下载SNPN的证书。Question 1: How does the UE access and select a network (such as PLMN and SNPN3) that already has the certificate and/or subscription for unrestricted access to download the certificate of the SNPN.
为了支持选网的问题,在本申请一种可选实施例中,可选的解决的方案如下:In order to support the problem of network selection, in an optional embodiment of the present application, the optional solution is as follows:
网络侧不广播用于指示支持onboarding的指示信息,而是广播第一指示信息,可以用于指示以下之一:支持配置证书和/或签约的第一指示信息,支持基于非限制接入情况下配置证书和/或签约。The network side does not broadcast the indication information to indicate that onboarding is supported, but broadcasts the first indication information, which can be used to indicate one of the following: the first indication information to support the configuration certificate and/or the subscription, and to support the unrestricted access based on the first indication information. Configure certificates and/or sign up.
对UE而言,如果UE想获得第一对象(如SNPN2)的证书和/或签约,UE上配置第一列表。UE能接入所述第一列表中的网络获得第一对象的证书和/或签约,第一列表可以是PLMN和/或SNPN类型的网络构成混杂列表。For the UE, if the UE wants to obtain the certificate and/or subscription of the first object (eg SNPN2), the first list is configured on the UE. The UE can access the network in the first list to obtain the certificate and/or subscription of the first object, and the first list may be a PLMN and/or SNPN type network to form a mixed list.
终端可以根据第一列表和第一指示信息来进行选网。The terminal may select a network according to the first list and the first indication information.
一种实施实施方式中,第一列表可以包括以下至少一项:In one embodiment, the first list may include at least one of the following:
(1)通过控制面方式配置证书和/或签约的网络列表;(1) Configure the certificate and/or the contracted network list by means of the control plane;
可选地,通过控制面方式配置证书和/或签约包括通过控制面信令获得网络的证书和/或签约。不难理解,终端需要具有通过控制面方式获取证书和/或签约的能力,第一网络需要具有通过控制面方式配置证书和/或签约的能力。第一网络是第一列表中的网络。Optionally, configuring the certificate and/or subscription by means of the control plane includes obtaining the certificate and/or subscription of the network through control plane signaling. It is not difficult to understand that the terminal needs to have the ability to obtain the certificate and/or the subscription through the control plane, and the first network needs to have the ability to configure the certificate and/or the subscription through the control plane. The first network is the network in the first list.
(2)通过用户面方式配置证书和/或签约的网络列表。(2) Configure the certificate and/or subscribed network list through the user plane.
可选地,通过用户面方式配置证书和/或签约的网络列包括通过数据通道获得网络的证书和/或签约。比如,终端在第一网络建立数据通道,终端通过所述数据通道连接数据网络内的配置服务器,以获取第一对象的证书和/或签 约。所以,所述终端需要具有通过用户面方式获得证书和/或签约的能力。Optionally, configuring the network list of the certificate and/or subscription in a user plane manner includes obtaining the certificate and/or subscription of the network through a data channel. For example, the terminal establishes a data channel in the first network, and the terminal connects to a configuration server in the data network through the data channel to obtain the certificate and/or contract of the first object. Therefore, the terminal needs to have the ability to obtain a certificate and/or a subscription through the user plane.
一种实施方式中,终端需要从第一网络(第一网络为第一列表中的网络)获得配置服务器的地址信息。此时,需要第一网络具有通过用户面方式配置证书和/或签约才能支持。In an implementation manner, the terminal needs to obtain the address information of the configuration server from the first network (the first network is the network in the first list). In this case, the first network needs to have a certificate configured in a user plane manner and/or a subscription to support this.
在本申请一种可选实施例中,可选的,获得或获取可以理解为从配置获得、接收、通过请求后接收、通过自学习获取、根据未收到的信息推导获取或者是根据接收的信息处理后获得,具体可根据实际需要确定,本申请实施例对此不作限定。比如当未收到设备发送的某个能力指示信息时可推导出该设备不支持该能力。In an optional embodiment of the present application, optionally, obtaining or obtaining may be understood as obtaining from configuration, receiving, receiving after request, obtaining through self-learning, deriving and obtaining according to unreceived information, or obtaining according to received The information obtained after processing can be determined according to actual needs, which is not limited in this embodiment of the present application. For example, when a certain capability indication information sent by the device is not received, it can be deduced that the device does not support the capability.
在本发明的一种可选的实施例中,发送可以包含广播,系统消息中广播,响应请求后返回。In an optional embodiment of the present invention, the sending may include broadcasting, broadcasting in the system message, and returning after responding to the request.
在本发明的一种可选的实施例中,能够可以表示以下至少一项:允许,支持,倾向,优先具有能力。不能够可以表示以下至少一项:不允许,不支持,不允许,不倾向,不具有能力。In an optional embodiment of the present invention, able can represent at least one of the following: allow, support, inclination, and preferentially have ability. Impossible can mean at least one of the following: not allowed, not supported, not allowed, not inclined, not capable.
本申请一种可选实施例中,所述第一接入方式包括以下至少一项:为了获取证书和/或签约而接入网络的接入方式,采用受限接入网络的接入方式,采用默认证书接入网络的接入方式;In an optional embodiment of the present application, the first access mode includes at least one of the following: an access mode for accessing a network for obtaining a certificate and/or signing a contract, using a restricted access network access mode, The access method of using the default certificate to access the network;
一种实施方式中,为了下载用于接入第一对象的证书而采用受限接入网络的方式,或为了下载用于接入第一对象的证书而接入网络的方式可以称为onboarding。当第一对象包含A网络时,第一网络和A网络可以是同一个网络或不同的网络。所述第一网络为终端接入的网络,比如当前的接入的网络。In an implementation manner, the manner of using a restricted access network for downloading the certificate for accessing the first object, or the manner of accessing the network for downloading the certificate for accessing the first object may be called onboarding. When the first object includes the A network, the first network and the A network may be the same network or different networks. The first network is a network accessed by the terminal, such as a currently accessed network.
本申请一种可选实施例中,第一服务器用于为终端配置第一对象的证书和/或签约的服务器。In an optional embodiment of the present application, the first server is used to configure the terminal with the certificate of the first object and/or the server for signing up.
在本发明的一种可选的实施例中,所述支持配置证书和/或签约用于进一步指示以下至少一项:支持通过控制面方式配置证书和/或签约,支持通过用户面方式配置证书和/或签约。In an optional embodiment of the present invention, the supporting configuration of certificates and/or subscriptions is used to further indicate at least one of the following: supporting configuration of certificates and/or subscriptions by means of a control plane, supporting configuration of certificates by means of user planes and/or contract.
在本发明的一种可选的实施例中,所述不支持配置证书和/或签约用于进一步指示不支持通过控制面方式配置证书和/或签约,不支持通过用户面方式配置证书和/或签约。In an optional embodiment of the present invention, the configuration certificate and/or subscription not supported is used to further indicate that the configuration of the certificate and/or subscription by means of the control plane is not supported, and the configuration of the certificate and/or subscription by means of the user plane is not supported. or contract.
在本发明的一种可选的实施例中,所述获得证书和/或签约是远程获得证书和/或签约,比如,终端接入第一网络以获得证书和/或签约的情况下,所述证书和/或签约的提供方为第一实体。所述第一实体为数据网(Data Network,DN)中的实体或终端接入的网络之外的实体(entity)。In an optional embodiment of the present invention, the obtaining of the certificate and/or the contract is to obtain the certificate and/or the contract remotely. For example, when the terminal accesses the first network to obtain the certificate and/or the contract, the The provider of the certificate and/or contract is the first entity. The first entity is an entity in a data network (Data Network, DN) or an entity (entity) outside the network accessed by the terminal.
在本发明的一种可选的实施例中,所述证书和/或签约的提供方是以下之一:第一列表中的网络之外的实体,终端接入的网络之外的实体,数据网(DN)中的实体,其他网络中的实体。所述数据网中实体可以是应用服务器,数据网中的证书和/或签约的配置服务器。终端接入网络的目标包括获得证书和/或签约。In an optional embodiment of the present invention, the provider of the certificate and/or subscription is one of the following: an entity outside the network in the first list, an entity outside the network accessed by the terminal, data Entities in the network (DN), entities in other networks. The entity in the data network may be an application server, a certificate and/or a contracted configuration server in the data network. The objectives of a terminal accessing the network include obtaining a certificate and/or signing up.
在本发明的一种可选的实施例中,所述证书和/或签约为终端接入的网络的证书和/或签约。终端接入的网络的证书和/或签约包括以下至少一项:终端用于非受限接入的网络的证书和/或签约,终端用于受限接入的网络的证书和/或签约。In an optional embodiment of the present invention, the certificate and/or subscription is the certificate and/or subscription of the network accessed by the terminal. The certificate and/or subscription of the network accessed by the terminal includes at least one of the following: the certificate and/or subscription of the terminal for the unrestricted access network, the certificate and/or the subscription of the terminal for the restricted access network.
在本发明的一种可选的实施例中,所述证书和/或签约包括以下至少一项:用于非受限接入的证书和/或签约,用于受限接入的证书和/或签约,用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约。主认证(如主身份认证(Primary Authentication))可以包括:鉴权和密钥同意(Authentication and Key Agreement,AKA)比如,第五代通信技术(5th generation,5G)AKA,可扩展的身份验证协议(Extensible Authentication Protocol,EAP)AKA。In an optional embodiment of the present invention, the certificate and/or subscription includes at least one of the following: a certificate and/or subscription for unrestricted access, a certificate and/or a subscription for restricted access or subscription, certificate and/or subscription for primary authentication and/or authorization, certificate and/or subscription for non-primary authentication and/or authorization. Primary authentication (such as Primary Authentication) may include: Authentication and Key Agreement (AKA), for example, 5th generation (5G) AKA, an extensible authentication protocol (Extensible Authentication Protocol, EAP) AKA.
用于非主认证和/或授权包括以下至少一项:二次认证和/或授权(Secondary authentication/authorization),切片相关的认证和/或授权(Network Slice-Specific Authentication and Authorization,NSSAA)。For non-primary authentication and/or authorization, it includes at least one of the following: secondary authentication and/or authorization (Secondary authentication/authorization), slice-related authentication and/or authorization (Network Slice-Specific Authentication and Authorization, NSSAA).
一种实施方式中,终端可以采用用于受限接入网络的证书(如默认证书)和/或签约接入第一网络,然后通过第一网络获得第一对象(包括A网络)的非受限接入的证书和/或签约。A网络与第一网络相同或不同。In an implementation manner, the terminal may use a certificate (such as a default certificate) for a restricted access network and/or subscribe to access the first network, and then obtain the unrestricted access to the first object (including network A) through the first network. Access-restricted credentials and/or subscriptions. The A network is the same as or different from the first network.
在本发明的一种可选的实施例中,通过控制面方式获得证书和/或签约和/或通过控制面方式配置证书和/或签约包括以下至少一项:第一实体,通过终端接入的网络的控制面信令,向终端配置所述证书和/或签约;终端,通过终 端接入的网络的控制面信令,向第一实体获取所述证书和/或签约;In an optional embodiment of the present invention, obtaining the certificate and/or signing through the control plane and/or configuring the certificate and/or signing through the control plane includes at least one of the following: a first entity, accessing through a terminal The terminal obtains the certificate and/or the subscription from the first entity through the control plane signaling of the network accessed by the terminal;
在本发明的一种可选的实施例中,通过用户面方式获得证书和/或签约和/或通过用户面方式配置证书和/或签约包括以下至少一项:终端在接入的网络建立数据通道,通过所述数据通道,向第一实体获取所述证书和/或签约;或第一实体,通过终端在接入的网络建立的数据通道,向终端配置所述证书和/或签约。In an optional embodiment of the present invention, obtaining a certificate and/or signing a contract through a user plane method and/or configuring a certificate and/or signing a contract through a user plane method includes at least one of the following: the terminal establishes data on the network accessed by the terminal The channel, through the data channel, obtains the certificate and/or the contract from the first entity; or the first entity configures the certificate and/or the contract for the terminal through the data channel established by the terminal in the access network.
在本发明的一种可选的实施例中,数据通道包括以下至少一项:数据通道可以包括但不限于以下之一:协议数据单元(Protocol Data Unit,PDU)会话,公共数据网(Public Data Network,PDN)连接,服务质量(Quality of Service,QoS)流,承载,互联网安全协议(Internet Protocol Security,IPsec)通道,其中,承载可以是演进的无线接入承载(Evolved Radio Access Bearer,E-RAB)、无线接入承载(Evolved Radio Access Bearer,RAB)、数据无线承载(Data Radio Bearer,DRB)、信令无线承载(signalling radio bearers,SRB)等。In an optional embodiment of the present invention, the data channel includes at least one of the following: the data channel may include but is not limited to one of the following: a protocol data unit (Protocol Data Unit, PDU) session, a public data network (Public Data Network, PDN) connection, quality of service (Quality of Service, QoS) flow, bearer, Internet Protocol Security (Internet Protocol Security, IPsec) channel, wherein, the bearer can be an evolved radio access bearer (Evolved Radio Access Bearer, E- RAB), radio access bearer (Evolved Radio Access Bearer, RAB), data radio bearer (Data Radio Bearer, DRB), signaling radio bearer (signalling radio bearers, SRB) and so on.
在本发明的一种可选的实施例中,采用默认证书允许接入的网络包括,终端采用默认证书对应的终端标识接入能够获得受限连接的网络。In an optional embodiment of the present invention, the network that is allowed to access by using the default certificate includes that the terminal uses the terminal identifier corresponding to the default certificate to access the network that can obtain a restricted connection.
在本发明的一种可选的实施例中,默认证书包括用于受限接入方式的证书。In an optional embodiment of the present invention, the default credentials include credentials for restricted access.
在本发明的一种可选的实施例中,受限接入和受限连接是同一意义,可以混用。In an optional embodiment of the present invention, restricted access and restricted connection have the same meaning and can be used in combination.
一种实施方式中,所述受限接入包括以下至少一项:仅允许建立第一数据通道,不允许建立第一数据通道之外的数据通道,仅允许获取证书和/或签约,不允许获取证书和/或签约之外的业务。第一数据通道用于获取证书和/或签约的数据通道。In one embodiment, the restricted access includes at least one of the following: only the first data channel is allowed to be established, the establishment of data channels other than the first data channel is not allowed, only the certificate and/or contract is allowed, and the Businesses other than getting a certificate and/or contracting. The first data channel is used to obtain a certificate and/or a contracted data channel.
一种实施方式中,通过所述受限接入可以获得第一对象的证书和/或签约。In one embodiment, the certificate and/or subscription of the first object may be obtained through the restricted access.
在本发明的一种可选的实施例中,受限接入包括受限的控制面接入和/或受限的用户面接入。In an optional embodiment of the present invention, the restricted access includes restricted control plane access and/or restricted user plane access.
在本发明的一种可选的实施例中,受限连接包括受限的控制面连接和/或受限的用户面连接。通过所述受限连接可以获得证书和/或签约。In an optional embodiment of the present invention, the restricted connection includes a restricted control plane connection and/or a restricted user plane connection. Credentials and/or subscriptions may be obtained through the restricted connection.
在本发明的一种可选的实施例中,采用默认证书能够接入的网络包括采 用默认证书对应的终端标识接入网并通过默认证书能够通过网络的认证和/或授权。In an optional embodiment of the present invention, the network that can be accessed by using the default certificate includes using the terminal identification corresponding to the default certificate to access the network and passing the authentication and/or authorization of the network through the default certificate.
在本发明的一种可选的实施例中,第一列表中的网络包括第一列表中网络组映射的网络。一个网络组可以映射为一个或多个网络。In an optional embodiment of the present invention, the networks in the first list include networks mapped by the network group in the first list. A netgroup can be mapped to one or more nets.
在本发明的一种可选的实施例中,所述能够配置证书和/或签约的网络列表中的网络包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an optional embodiment of the present invention, the network in the list of networks that can configure certificates and/or subscriptions includes that the first communication device can access restricted, and enables the first communication device Network to obtain a certificate and/or sign up.
在本发明的一种可选的实施例中,所述第一列表中的网络的特征包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an optional embodiment of the present invention, the characteristics of the networks in the first list include that the first communication device can access restricted, and can enable the first communication device to obtain a certificate and/or contracted network.
在本发明的一种可选的实施例中,签约(suscription)包括签约数据(subcription data),比如切片信息,数据网络名(Data Network Name,DNN)等。In an optional embodiment of the present invention, the subscription (suscription) includes subscription data (subscription data), such as slice information, a data network name (Data Network Name, DNN), and the like.
在本发明的一种可选的实施例中,A网络用于泛指网络,或用于特指某一个或多个网络。In an optional embodiment of the present invention, the A network is used to refer to a network in general, or to refer to one or more networks in particular.
在本发明的一种可选的实施例中,所述第一对象的证书和/或签约包括用于接入第一对象的证书和/或签约。用于接入第一对象的证书和/或签约包括以下至少一项:用于非受限接入第一对象的证书和/或签约,用于受限接入第一对象的证书和/或签约。In an optional embodiment of the present invention, the certificate and/or subscription of the first object includes a certificate and/or subscription for accessing the first object. The credentials and/or subscriptions for accessing the first object include at least one of the following: credentials and/or subscriptions for unrestricted access to the first object, credentials and/or subscriptions for restricted access to the first object contract.
在本发明的一种可选的实施例中,所述A网络的证书和/或签约包括用于接入A网络的证书和/或签约。用于接入A网络的证书和/或签约包括以下至少一项:用于非受限接入A网络的证书和/或签约,用于受限接入A网络的证书和/或签约。In an optional embodiment of the present invention, the certificate and/or subscription of the A network includes a certificate and/or a subscription for accessing the A network. The certificate and/or subscription for accessing the A network includes at least one of the following: a certificate and/or subscription for unrestricted access to the A network, and a certificate and/or subscription for restricted access to the A network.
在本发明的一种可选的实施例中,为所述第一通信设备配置证书和/或签约包括使所述第一通信设备获得证书和/或签约。In an optional embodiment of the present invention, configuring a certificate and/or a subscription for the first communication device includes causing the first communication device to obtain a certificate and/or a subscription.
在本发明的一种可选的实施例中,In an optional embodiment of the present invention,
(1)可选地,使第一通信设备获得证书和/或签约包括:为所述第一通信设备配置证书和/或签约。(1) Optionally, causing the first communication device to obtain a certificate and/or a subscription includes: configuring a certificate and/or a subscription for the first communication device.
(2)可选地,使所述第一通信设备通过控制面方式获得证书和/或签约 包括:为所述第一通信设备通过控制面方式配置证书和/或签约。(2) Optionally, causing the first communication device to obtain the certificate and/or the subscription through the control plane method includes: configuring the certificate and/or the subscription for the first communication device through the control plane method.
(3)可选地,使所述第一通信设备通过用户面方式获得证书和/或签约包括:为所述第一通信设备通过用户面方式配置证书和/或签约。(3) Optionally, causing the first communication device to obtain the certificate and/or subscription through the user plane method includes: configuring the certificate and/or the subscription through the user plane method for the first communication device.
(4)可选地,使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约包括:为所述第一通信设备通过控制面方式配置第一对象的证书和/或签约。(4) Optionally, causing the first communication device to obtain the certificate and/or contract of the first object through a control plane method includes: configuring the first communication device through a control plane method with the certificate and/or the first object's certificate contract.
和/或and / or
(5)可选地,使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约包括:为所述第一通信设备通过用户面方式配置第一对象的证书和/或签约。(5) Optionally, enabling the first communication device to obtain the first object's certificate and/or signing the contract through the user plane method includes: configuring the first object's certificate and/or the first object's certificate for the first communication device through the user plane method. contract.
在本发明的一种可选的实施例中,In an optional embodiment of the present invention,
(1)可选地,为所述第一通信设备配置证书和/或签约包括:使第一通信设备获得证书和/或签约包括:。(1) Optionally, configuring a certificate and/or signing a contract for the first communication device includes: causing the first communication device to obtain a certificate and/or signing a contract includes: .
(2)可选地,为所述第一通信设备通过控制面方式配置证书和/或签约包括:使所述第一通信设备通过控制面方式获得证书和/或签约包括:。(2) Optionally, configuring the certificate and/or signing the first communication device through the control plane method includes: causing the first communication device to obtain the certificate and/or signing the contract through the control plane method includes:
(3)可选地,为所述第一通信设备通过用户面方式配置证书和/或签约包括:使所述第一通信设备通过用户面方式获得证书和/或签约包括:。(3) Optionally, configuring the certificate and/or signing the first communication device through the user plane method includes: causing the first communication device to obtain the certificate and/or signing the contract through the user plane method includes:
(4)可选地,为所述第一通信设备通过控制面方式配置第一对象的证书和/或签约包括使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约。(4) Optionally, configuring the certificate and/or subscription of the first object for the first communication device through the control plane method includes causing the first communication device to obtain the certificate and/or subscription of the first object through the control plane method .
和/或and / or
(5)可选地,为所述第一通信设备通过用户面方式配置第一对象的证书和/或签约包括:使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约。不难理解,当第一网络的证书和/或签约是终端接入的网络之外的实体提供的情况下,所述为第一通信设备配置证书和/或签约可以理解为使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约。(5) Optionally, configuring the certificate and/or signing of the first object for the first communication device through the user plane method includes: enabling the first communication device to obtain the certificate and/or the first object's certificate through the user plane method. contract. It is not difficult to understand that when the certificate and/or subscription of the first network is provided by an entity other than the network accessed by the terminal, the configuring the certificate and/or the subscription for the first communication device may be understood as making the first communication The communication device obtains the certificate and/or the subscription of the first object by means of the user plane.
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的一种支持网络选择的方法、装置、设备及可读存储介质进行详细地说明。A method, apparatus, device, and readable storage medium for supporting network selection provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings through some embodiments and application scenarios thereof.
<1st><1st>
参见图2,本申请实施例提供一种支持网络选择的方法,由第一通信设备执行,该第一通信设备包括但不限于终端(UE),具体步骤包括:步骤201和步骤202。Referring to FIG. 2 , an embodiment of the present application provides a method for supporting network selection, which is performed by a first communication device, where the first communication device includes but is not limited to a terminal (UE). The specific steps include: step 201 and step 202 .
步骤201:获得第一信息,所述第一信息包括:第一列表,第二列表和/或第一指示信息;Step 201: Obtain first information, where the first information includes: a first list, a second list and/or first indication information;
步骤202:根据所述第一信息,选择网络;Step 202: Select a network according to the first information;
在本发明的一种可选的实施例中,所述第一列表包括以下之一:In an optional embodiment of the present invention, the first list includes one of the following:
(1)一个或多个网络对象;(1) one or more network objects;
(2)一个或多个网络对象的标识信息;(2) Identification information of one or more network objects;
在本发明的一种可选的实施例中,所述第一列表中的网络的特征包括以下至少一项:In an optional embodiment of the present invention, the characteristics of the networks in the first list include at least one of the following:
(1)所述第一通信设备能够受限接入;(1) The first communication device is capable of restricted access;
(2)能够使所述第一通信设备获得证书和/或签约;(2) enabling the first communication device to obtain a certificate and/or to sign a contract;
(3)第一通信设备采用默认证书能够接入;(3) The first communication device can access by using the default certificate;
一种实施方式中,所述第一列表中的网络的特征包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an implementation manner, the characteristics of the networks in the first list include networks to which the first communication device can access restricted and enable the first communication device to obtain a certificate and/or a subscription.
一种实施方式中,默认证书包括用于受限接入方式的证书。In one embodiment, the default credentials include credentials for the restricted access mode.
在本发明的另一种可选的实施例中,第一列表包括以下至少一项:In another optional embodiment of the present invention, the first list includes at least one of the following:
(1)能够被受限接入的网络列表;(1) A list of networks that can be restricted to access;
(2)能够配置证书和/或签约的网络列表;(2) A list of networks that can configure certificates and/or subscriptions;
(3)能够采用默认证书接入的网络列表;(3) A list of networks that can be accessed using the default certificate;
一种实施方式中,所述能够配置证书和/或签约的网络列表中的网络的特征包括以下一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入。In an implementation manner, the characteristics of the networks in the list of networks that can be configured with certificates and/or subscribed include one of the following: the first communication device is capable of restricted access and enables the first communication device to obtain a certificate and/or contract, the first communication device can access by using the default certificate.
在本发明的一种可选的实施例中,所述第二列表包括:In an optional embodiment of the present invention, the second list includes:
(1)一个或多个网络对象;(1) one or more network objects;
(2)一个或多个网络对象的标识信息;(2) Identification information of one or more network objects;
在本发明的一种可选的实施例中,所述第二列表中的网络的特征包括以 下至少一项:In an optional embodiment of the present invention, the characteristics of the networks in the second list include at least one of the following:
(1)所述第一通信设备不能够接入;(1) The first communication device cannot be accessed;
(2)不能够使所述第一通信设备获得证书和/或签约;(2) The first communication device cannot be made to obtain a certificate and/or a contract;
(3)第一通信设备采用默认证书不能够接入;(3) The first communication device cannot access using the default certificate;
在本发明的另一种可选的实施例中,第二列表包括以下至少一项:In another optional embodiment of the present invention, the second list includes at least one of the following:
(1)不能够被受限接入的网络列表;(1) A list of networks that cannot be restricted to access;
(2)不能够配置证书和/或签约的网络列表;(2) The list of networks for which certificates and/or subscriptions cannot be configured;
(3)不能够采用默认证书接入的网络列表;(3) A list of networks that cannot be accessed using the default certificate;
其中,所述网络列表包括:Wherein, the network list includes:
(1)一个或多个网络对象;(1) one or more network objects;
(2)一个或多个网络对象的标识信息;(2) Identification information of one or more network objects;
其中,所述网络对象包括网络和/或网络组;Wherein, the network object includes a network and/or a network group;
所述第一指示信息用于指示以下至少一项:The first indication information is used to indicate at least one of the following:
(1)支持或不支持配置证书和/或签约;(1) Supports or does not support configuring certificates and/or signing;
(2)支持或不支持通过控制面方式配置证书和/或签约;(2) Support or not support the configuration of certificates and/or signing through the control plane;
(3)支持或不支持通过用户面方式配置证书和/或签约;(3) Support or not support the configuration of certificates and/or signing through the user plane;
(4)支持或不支持基于受限接入配置证书和/或签约;(4) Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
(5)支持或不支持基于受限接入通过控制面方式配置证书和/或签约;(5) Supports or does not support the configuration of certificates and/or subscriptions by means of the control plane based on restricted access;
(6)支持或不支持基于受限接入通过用户面方式配置证书和/或签约;(6) Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
(7)支持或不支持基于非受限接入配置证书和/或签约;(7) Support or not support the configuration of certificates and/or subscriptions based on unrestricted access;
(8)支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;(8) Supports or does not support the configuration of certificates and/or subscriptions based on unrestricted access by means of the control plane;
(9)支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。(9) Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on unrestricted access.
一种实施方式中,第一通信设备通过预配置获得第一列表和/或第二列表。另一种实施方式中,第一通信设备从接入的网络或第一服务器获得第一列表和/或第二列表。所述第一服务器是为第一通信设备配置证书和/或签约的服务器。In an implementation manner, the first communication device obtains the first list and/or the second list through pre-configuration. In another implementation manner, the first communication device obtains the first list and/or the second list from the accessed network or the first server. The first server is a server that configures a certificate and/or a subscription for the first communication device.
在本发明的一种可选的实施例中,所述证书和/或签约包括以下至少一项:第一对象的证书和/或签约;用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约;In an optional embodiment of the present invention, the certificate and/or contract includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a contract for primary authentication and/or authorization , for certificates and/or signings other than primary authentication and/or authorization;
一种实施方式中,用于非主认证和/或授权包括以下至少一项:二次认证和/或授权(Secondary authentication/authorization),切片相关的认证和/或授权(Network Slice-Specific Authentication and Authorization,NSSAA)。In one embodiment, the non-primary authentication and/or authorization includes at least one of the following: secondary authentication and/or authorization (Secondary authentication/authorization), slice-related authentication and/or authorization (Network Slice-Specific Authentication and Authorization, NSSAA).
其中,in,
所述第一对象包括以下至少一项:A网络,第一实体,第一通信设备接入的网络,主认证和/或授权,非主认证和/或授权;The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
所述第一实体包括以下之一:数据网中的实体、第一通信设备接入的网络之外的实体;The first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
其中,in,
所述A网络与所述第一列表中的网络相同或不同;The A network is the same as or different from the network in the first list;
和/或,and / or,
所述A网络与所述第二列表中的网络相同或不同;the A network is the same as or different from the network in the second list;
和/或,and / or,
所述A网络与所述第一通信设备接入的网络相同或不同;和/或,The A network is the same as or different from the network accessed by the first communication device; and/or,
所述获得证书和/或签约包括以下至少一项:通过控制面方式获得证书和/或签约,通过用户面方式获得证书和/或签约;The obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
和/或,and / or,
所述能够配置证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置证书和/或签约的网络列表,能够通过用户面方式配置证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
一种实施方式中,能够通过控制面方式配置证书和/或签约的网络列表中的网络的特征包括以下一项:所述第一通信设备能够受限接入,能够使所述第一通信设备通过控制面方式获得证书和/或签约,第一通信设备采用默认证书能够接入。In an implementation manner, the characteristics of the networks in the list of networks that can configure certificates and/or subscriptions by means of the control plane include one of the following: the first communication device can have restricted access, and the first communication device can The certificate and/or the subscription is obtained by means of the control plane, and the first communication device can access by using the default certificate.
一种实施方式中,能够通过用户面方式配置证书和/或签约的网络列表中的网络的特征包括以下一项:所述第一通信设备能够受限接入,能够使所述第一通信设备通过用户面方式获得证书和/或签约,第一通信设备采用默认证书能够接入。In an implementation manner, the characteristics of the networks in the list of networks that can be configured with certificates and/or subscriptions in a user plane manner include one of the following: the first communication device can have restricted access, and the first communication device can Obtaining the certificate and/or signing the contract through the user plane, the first communication device can access by using the default certificate.
在本发明的一种可选的实施例中,能够使所述第一通信设备获得证书和/ 或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得证书和/或签约,能够使所述第一通信设备通过用户面方式获得证书和/或签约。In an optional embodiment of the present invention, enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or To sign a contract, the first communication device can obtain a certificate and/or a contract through a user plane method.
在本发明的一种可选的实施例中,所述第一对象的证书和/或签约包括用于接入第一对象的证书和/或签约。In an optional embodiment of the present invention, the certificate and/or subscription of the first object includes a certificate and/or subscription for accessing the first object.
在本发明的一种可选的实施例中,所述第一列表为所述第一对象对应的第一列表,不同的所述第一对象对应的第一列表相同或不同;In an optional embodiment of the present invention, the first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;
和/或,and / or,
所述第二列表为所述第一对象对应的第二列表,不同的所述第一对象对应的第二列表相同或不同;The second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;
和/或,and / or,
能够配置证书和/或签约的网络列表包括:能够配置所述第一对象的证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes: a list of networks capable of configuring certificates and/or subscriptions of the first object;
和/或,and / or,
不能够配置证书和/或签约的网络列表包括:不能够配置所述第一对象的证书和/或签约的网络列表;The list of networks for which the certificate and/or subscription cannot be configured includes: the list of networks for which the certificate and/or subscription of the first object cannot be configured;
和/或,and / or,
能够使所述第一通信设备获得证书和/或签约包括:能够使所述第一通信设备获得所述第一对象的证书和/或签约;The enabling of the first communication device to obtain the certificate and/or the contract includes: enabling the first communication device to obtain the certificate and/or the contract of the first object;
和/或,and / or,
不能够使所述第一通信设备获得证书和/或签约包括:不能够使所述第一通信设备获得第一对象的证书和/或签约。The inability to enable the first communication device to obtain the certificate and/or the contract includes: the inability to enable the first communication device to obtain the certificate and/or the contract of the first object.
在本发明的一种可选的实施例中,所述第一对象对应的第一列表包括:所述第一对象对应的通过控制面方式的第一列表,所述第一对象对应的通过用户面方式的第一列表;In an optional embodiment of the present invention, the first list corresponding to the first object includes: a first list corresponding to the first object through the control plane, and the first object corresponding to the user the first list of face modes;
其中,in,
所述第一对象对应的通过控制面方式的第一列表和所述第一对象对应的通过用户面方式的第一列表相同或不同;The first list corresponding to the first object through the control plane method and the first list through the user plane method corresponding to the first object are the same or different;
所述第一对象对应的通过控制面方式的第一列表中的网络包括能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约的网络;The network corresponding to the first object in the first list by means of the control plane includes a network capable of enabling the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
所述第一对象对应的通过用户面方式的第一列表中的网络包括能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约的网络;The network corresponding to the first object in the first list through the user plane method includes a network that enables the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
和/或,and / or,
所述第一对象对应的第二列表包括:所述第一对象对应的通过控制面方式的第二列表,所述第一对象对应的通过用户面方式的第二列表;The second list corresponding to the first object includes: a second list corresponding to the first object through a control plane method, and a second list corresponding to the first object through a user plane method;
其中,in,
所述第一对象对应的通过控制面方式的第二列表和第一对象对应的通过用户面方式的第二列表相同或不同;The second list corresponding to the first object through the control plane method and the second list corresponding to the first object through the user plane method are the same or different;
所述第一对象对应的通过控制面方式的第二列表中的网络包括不能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约的网络;The networks in the second list by means of the control plane corresponding to the first object include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
所述第一对象对应的通过用户面方式的第二列表中的网络包括不能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约的网络;The networks in the second list corresponding to the first object through the user plane method include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
和/或,and / or,
能够配置第一对象的证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置第一对象的证书和/或签约的网络列表,能够通过用户面方式配置第一对象的证书和/或签约的网络列表;The list of networks that can configure the certificate and/or subscription of the first object includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object through the control plane, and the certificate of the first object can be configured through the user plane. and/or a list of contracted networks;
和/或,and / or,
不能够配置第一对象的证书和/或签约的网络列表包括以下至少一项:不能够通过控制面方式配置第一对象的证书和/或签约的网络列表,不能够通过用户面方式配置第一对象的证书和/或签约的网络列表;The list of networks for which the certificate and/or subscription of the first object cannot be configured includes at least one of the following: a list of the subject's credentials and/or contracted networks;
和/或,and / or,
能够使所述第一通信设备获得A对象的证书和/或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约,能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约;The ability to enable the first communication device to obtain the certificate and/or the contract of the A object includes at least one of the following: enabling the first communication device to obtain the certificate and/or the contract of the first object by means of a control plane, enabling the first communication device to obtain the certificate and/or contract of the first object The first communication device obtains the certificate and/or the subscription of the first object by means of the user plane;
和/或,and / or,
不能够使所述第一通信设备获得A对象的证书和/或签约包括以下至少一项:不能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约,不能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约。The inability to enable the first communication device to obtain the certificate and/or the contract of the A object includes at least one of the following: the first communication device cannot be enabled to obtain the certificate and/or the contract of the first object by means of the control plane; The first communication device is caused to obtain the certificate and/or subscription of the first object through the user plane.
在本发明的一种可选的实施例中,所述第一列表中网络的网络类型,第二列表中网络的网络类型,和/或A网络的网络类型包括以下至少一项:公网,非公网,PLMN,非独立的非公共网络(Public Network Integrated Non-Public Network,PNI-NPN),SNPN。In an optional embodiment of the present invention, the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: a public network, Non-public network, PLMN, non-independent non-public network (Public Network Integrated Non-Public Network, PNI-NPN), SNPN.
在本发明的一种可选的实施例中,所述获得第一指示信息,包括:In an optional embodiment of the present invention, the obtaining the first indication information includes:
从小区广播或从第二通信设备接收第一指示信息。The first indication information is broadcast from the cell or received from the second communication device.
在本发明的一种可选的实施例中,所述方法还包括:In an optional embodiment of the present invention, the method further includes:
通过接入所述第一列表中的网络,获得以下至少一项:Obtain at least one of the following by accessing the network in the first list:
(1)所述第一对象的证书和/或签约,(1) the certificate and/or contract of the first object,
(2)所述第一对象的标识信息;(2) identification information of the first object;
(3)所述第一对象对应的第一列表;(3) the first list corresponding to the first object;
(4)所述第一对象对应的第二列表;(4) the second list corresponding to the first object;
在本发明的一种可选的实施例中,所述根据所述第一信息,选择网络,包括:满足第一条件时,选择第一网络;In an optional embodiment of the present invention, the selecting a network according to the first information includes: selecting the first network when the first condition is satisfied;
其中,所述第一条件包括以下至少一项:Wherein, the first condition includes at least one of the following:
所述第一网络是所述第一列表中的网络;the first network is a network in the first list;
从所述第一网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the first network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第一列表包括以下至少一项:能够配置第一对象的证书和/或签约的网络列表;第一对象对应的第一列表;第一列表中的网络能够使所述第一通信设备获得第一对象的证书和/或签约;第一对象的证书和/或签约对应的允许的网络列表;The first list includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object; a first list corresponding to the first object; the networks in the first list can enable the first communication device to obtain The certificate and/or subscription of the first object; the list of allowed networks corresponding to the certificate and/or subscription of the first object;
所述第一网络在第一列表中优先级最高;The first network has the highest priority in the first list;
所述第一通信设备在第一网络的覆盖范围内或第一通信设备能够监测到第一网络的信号。The first communication device is within the coverage of the first network or the first communication device can monitor the signal of the first network.
在本发明的一种可选的实施例中,所述根据所述第一信息选择网络,包括:In an optional embodiment of the present invention, the selecting a network according to the first information includes:
满足第二条件时,选择第二网络;When the second condition is met, the second network is selected;
其中,所述第二条件包括以下至少一项:Wherein, the second condition includes at least one of the following:
所述第二网络不是所述第二列表中的网络;the second network is not a network in the second list;
从所述第二网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第二列表包括以下至少一项:不能够配置第一对象的证书和/或签约的网络列表;第一对象对应的第二列表;第二列表中的网络不能够使所述第一通信设备获得第一对象的证书和/或签约;第一对象的证书和/或签约对应的不允许的网络列表;The second list includes at least one of the following: a list of networks that cannot configure the certificate and/or subscription of the first object; a second list corresponding to the first object; the networks in the second list cannot enable the first communication The device obtains the certificate and/or subscription of the first object; the list of disallowed networks corresponding to the certificate and/or subscription of the first object;
所述第一通信设备在第一列表的任一网络的覆盖范围之外或第一通信设备不能够监测到第一列表中任一网络的信号。The first communication device is out of coverage of any network in the first list or the first communication device cannot monitor the signal of any network in the first list.
在本发明的一种可选的实施例中,所述第一列表中的网络按优先级别排序。In an optional embodiment of the present invention, the networks in the first list are sorted by priority.
在本发明的一种可选的实施例中,所述根据所述第一信息,选择网络,包括:In an optional embodiment of the present invention, the selecting a network according to the first information includes:
满足第三条件时,选择第三网络;When the third condition is met, select the third network;
其中,所述第三条件包括以下至少一项:Wherein, the third condition includes at least one of the following:
所述第三网络是所述第一列表中的网络;the third network is a network in the first list;
从所述第三网络获得第一指示信息,且所述第一指示信息指示以下至少 一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the third network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第一列表包括以下至少一项:第一对象对应的通过控制面方式的第一列表,能够通过控制面方式配置第一对象的证书和/或签约的网络列表;第一列表中的网络能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约;所述第一通信设备在第三网络的覆盖范围内或第一通信设备能够监测到第三网络的信号;The first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, a list of networks that can configure the certificate and/or subscription of the first object in a control plane manner; networks in the first list The first communication device can be enabled to obtain the certificate and/or subscription of the first object through the control plane; the first communication device is within the coverage of the third network or the first communication device can monitor the signal of the third network ;
和/或,and / or,
满足第四条件时,选择第四网络;When the fourth condition is met, select the fourth network;
其中,所述第四条件包括以下至少一项:Wherein, the fourth condition includes at least one of the following:
所述第四网络是所述第一列表中的网络;the fourth network is a network in the first list;
从所述第四网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约,支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions, support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第一列表包括以下至少一项:所述第一对象对应的通过用户面方式的第一列表,能够通过用户面方式配置第一对象的证书和/或签约的网络列表;所述第一列表中的网络能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约;The first list includes at least one of the following: a first list corresponding to the first object through a user plane method, and a network list of certificates and/or subscriptions of the first object that can be configured through a user plane method; the first list The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane;
所述第一通信设备在第四网络的覆盖范围内或第一通信设备能够监测到 第四网络的信号。The first communication device is within the coverage of the fourth network or the first communication device can monitor the signal of the fourth network.
在本申请实施例中,通过第一指示信息指示第一通信设备选择用于下载证书和/或签约的网络。In this embodiment of the present application, the first communication device is instructed to select a network for downloading the certificate and/or signing the contract through the first indication information.
在本申请实施例中,第一通信设备可以根据第一信息选择用于下载证书和/或签约的网络。In this embodiment of the present application, the first communication device may select a network for downloading a certificate and/or signing a subscription according to the first information.
参见图3,本申请实施例提供一种支持网络选择的方法,由第二通信设备执行,第二通信设备包括但不限于以下之一:RAN网元,CN网元(如接入和移动性管理功能(Access and Mobility Management Function,AMF),会话管理功能(Session Management Function,SMF)),具体步骤包括:Referring to FIG. 3 , an embodiment of the present application provides a method for supporting network selection, which is performed by a second communication device, where the second communication device includes but is not limited to one of the following: a RAN network element, a CN network element (such as access and mobility Management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF)), the specific steps include:
步骤301:发送第一指示信息;Step 301: Send first indication information;
其中,所述第一指示信息用于指示以下至少一项:Wherein, the first indication information is used to indicate at least one of the following:
(1)支持或不支持配置证书和/或签约;(1) Supports or does not support configuring certificates and/or signing;
(3)支持或不支持通过控制面方式配置证书和/或签约;(3) Support or not support the configuration of certificates and/or signing through the control plane;
(4)支持或不支持通过用户面方式配置证书和/或签约;(4) Support or not support the configuration of certificates and/or signing through the user plane;
(5)支持或不支持基于受限接入配置证书和/或签约;(5) Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
(6)支持或不支持基于受限接入通过控制面方式配置证书和/或签约;(6) Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
(7)支持或不支持基于受限接入通过用户面方式配置证书和/或签约;(7) Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
(8)支持或不支持基于非受限接入配置证书和/或签约;(8) Supports or does not support configuration of certificates and/or subscriptions based on unrestricted access;
(9)支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;(9) Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
(10)支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。(10) Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on unrestricted access.
一种实施方式中,通过小区系统消息广播所述第一指示信息。In an implementation manner, the first indication information is broadcast through a cell system message.
一种实施方式中,所述第二通信设备是第一网络或第二网络中的通信设备In an implementation manner, the second communication device is a communication device in the first network or the second network
在本申请实施例中,通过第一指示信息指示第一通信设备选择用于下载证书和/或签约的网络。In this embodiment of the present application, the first communication device is instructed to select a network for downloading the certificate and/or signing the contract through the first indication information.
参见图4,本申请实施例提供一种支持网络选择的方法,由第三通信设备执行,第三通信设备包括但不限于以下之一:RAN网元,CN网元(如AMF,SMF),第一服务器,第一实体,具体步骤包括:Referring to FIG. 4 , an embodiment of the present application provides a method for supporting network selection, which is performed by a third communication device, where the third communication device includes but is not limited to one of the following: a RAN network element, a CN network element (such as AMF, SMF), The first server, the first entity, the specific steps include:
步骤401:发送第一列表和/或第二列表;Step 401: Send the first list and/or the second list;
在本发明的一种可选的实施例中,所述第一列表包括:In an optional embodiment of the present invention, the first list includes:
(1)一个或多个网络对象;(1) one or more network objects;
(2)一个或多个网络对象的标识信息;(2) Identification information of one or more network objects;
所述第一列表中的网络的特征包括以下至少一项:The characteristics of the networks in the first list include at least one of the following:
(1)所述第一通信设备能够受限接入;(1) The first communication device is capable of restricted access;
(2)能够使所述第一通信设备获得证书和/或签约;(2) enabling the first communication device to obtain a certificate and/or sign a contract;
(3)第一通信设备采用默认证书能够接入;(3) The first communication device can access by using the default certificate;
一种实施方式中,所述第一列表中的网络包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an implementation manner, the networks in the first list include networks to which the first communication device can access restricted and enable the first communication device to obtain a certificate and/or a subscription.
在本发明的另一种可选的实施例中,第一列表包括以下至少一项:In another optional embodiment of the present invention, the first list includes at least one of the following:
(1)能够被受限接入的网络列表,(1) A list of networks that can be restricted to access,
(2)能够配置证书和/或签约的网络列表,(2) A list of networks capable of configuring certificates and/or subscriptions,
(3)能够采用默认证书接入的网络列表;(3) A list of networks that can be accessed using the default certificate;
一种实施方式中,所述能够配置证书和/或签约的网络列表中的网络的特征包括以下一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入。In an implementation manner, the characteristics of the networks in the list of networks that can be configured with certificates and/or subscribed include one of the following: the first communication device is capable of restricted access and enables the first communication device to obtain a certificate and/or contract, the first communication device can access by using the default certificate.
,在本发明的一种可选的实施例中,所述第二列表包括:, in an optional embodiment of the present invention, the second list includes:
(1)一个或多个网络对象;(1) one or more network objects;
(2)一个或多个网络对象的标识信息;(2) Identification information of one or more network objects;
所述第二列表中的网络的特征包括以下至少一项:The characteristics of the networks in the second list include at least one of the following:
(1)所述第一通信设备不能够接入;(1) The first communication device cannot be accessed;
(2)不能够使所述第一通信设备获得证书和/或签约;(2) The first communication device cannot be made to obtain a certificate and/or a contract;
(3)第一通信设备采用默认证书不能够接入;(3) The first communication device cannot access using the default certificate;
在本发明的另一种可选的实施例中,所述第二列表包括以下至少一项:In another optional embodiment of the present invention, the second list includes at least one of the following:
(1)不能够被受限接入的网络列表;(1) A list of networks that cannot be restricted to access;
(2)不能够配置证书和/或签约的网络列表;(2) The list of networks for which certificates and/or subscriptions cannot be configured;
(3)不能够采用默认证书接入的网络列表;(3) A list of networks that cannot be accessed using the default certificate;
其中,所述网络列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述网络对象包括网络和/或网络组。Wherein, the network list includes one or more network objects, or identification information of one or more network objects, and the network objects include networks and/or network groups.
在本发明的另一种可选的实施例中,所述证书和/或签约包括以下至少一项:第一对象的证书和/或签约;用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约;In another optional embodiment of the present invention, the certificate and/or subscription includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a certificate for primary authentication and/or authorization Contracts, certificates and/or contracts for non-primary certification and/or authorization;
其中,in,
所述第一对象包括以下至少一项:A网络,第一实体,第一通信设备接入的网络,主认证和/或授权,非主认证和/或授权;The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
所述第一实体包括以下之一:数据网中的实体、第一通信设备接入的网络之外的实体;The first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
所述A网络与所述第一列表中的网络相同或不同;The A network is the same as or different from the network in the first list;
和/或,and / or,
所述A网络与所述第二列表中的网络相同或不同。The A network is the same as or different from the network in the second list.
和/或,and / or,
所述A网络与所述第一通信设备接入的网络相同或不同;The A network is the same as or different from the network accessed by the first communication device;
和/或,and / or,
所述获得证书和/或签约包括以下至少一项:通过控制面方式获得证书和/或签约,通过用户面方式获得证书和/或签约;The obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
和/或,and / or,
所述能够配置证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置证书和/或签约的网络列表,能够通过用户面方式配置证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
一种实施方式中,能够通过控制面方式配置证书和/或签约的网络列表中的网络的特征包括以下一项:所述第一通信设备能够受限接入,能够使所述第一通信设备通过控制面方式获得证书和/或签约,第一通信设备采用默认证书能够接入。In an implementation manner, the characteristics of the networks in the list of networks that can configure certificates and/or subscriptions by means of the control plane include one of the following: the first communication device can have restricted access, and the first communication device can The certificate and/or the subscription is obtained by means of the control plane, and the first communication device can access by using the default certificate.
一种实施方式中,能够通过用户面方式配置证书和/或签约的网络列表中的网络的特征包括以下一项:所述第一通信设备能够受限接入,能够使所述第一通信设备通过用户面方式获得证书和/或签约,第一通信设备采用默认证书能够接入。In an implementation manner, the characteristics of the networks in the list of networks that can be configured with certificates and/or subscriptions in a user plane manner include one of the following: the first communication device can have restricted access, and the first communication device can Obtaining the certificate and/or signing the contract through the user plane, the first communication device can access by using the default certificate.
一种实施方式中,能够使所述第一通信设备获得证书和/或签约包括以下 至少一项:能够使所述第一通信设备通过控制面方式获得证书和/或签约,能够使所述第一通信设备通过用户面方式获得证书和/或签约。In an implementation manner, enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate and/or signing a contract; A communication device obtains a certificate and/or a subscription through the user plane.
在本发明的一种可选的实施例中,所述第一列表中网络的网络类型,第二列表中网络的网络类型,和/或A网络的网络类型包括以下至少一项:公网,非公网,PLMN,PNI NPN,SNPN。In an optional embodiment of the present invention, the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: a public network, Non-public network, PLMN, PNI NPN, SNPN.
在本发明的一种可选的实施例中,所述第一列表中的网络按优先级别排序。In an optional embodiment of the present invention, the networks in the first list are sorted by priority.
在本申请实施例中,通过第一列表和/或第二列表指示第一通信设备选择用于下载证书和/或签约的网络。In this embodiment of the present application, the first communication device is instructed to select a network for downloading the certificate and/or signing the contract through the first list and/or the second list.
参见图5,具体步骤如下Referring to Figure 5, the specific steps are as follows
步骤1:在终端上配置获取第一对象(如SNPN2)证书和/或签约对应的第一列表(比如SNPN和PLMN的混合的网络列表)。Step 1: Configure the terminal to obtain the first object (eg, SNPN2) certificate and/or the first list corresponding to the subscription (eg, a mixed network list of SNPN and PLMN).
步骤2:接收第二通信设备(比如RAN网元或CN网元)发送的第一指示信息;Step 2: Receive the first indication information sent by the second communication device (such as the RAN network element or the CN network element);
步骤3:根据第一列表和第一指示信息选择网络。Step 3: Select a network according to the first list and the first indication information.
可以理解的是,步骤3的实施方式可以参考如图2所示实施例的描述。<1st>It can be understood that, for the implementation of step 3, reference may be made to the description of the embodiment shown in FIG. 2 . <1st>
参见图6,本申请实施例提供一种支持网络选择的装置,应用于第一通信设备,该装置600包括:Referring to FIG. 6 , an embodiment of the present application provides an apparatus for supporting network selection, which is applied to a first communication device. The apparatus 600 includes:
第一获取模块601,用于获得第一信息,所述第一信息包括:第一列表,第二列表和/或第一指示信息;A first obtaining module 601, configured to obtain first information, where the first information includes: a first list, a second list and/or first indication information;
选择模块602,用于根据所述第一信息选择网络;a selection module 602, configured to select a network according to the first information;
在本发明的一种可选的实施例中,所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,所述第一通信设备采用默认证书能够接入;In an optional embodiment of the present invention, the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include the following At least one item: the first communication device is capable of restricted access, enabling the first communication device to obtain a certificate and/or signing a contract, and the first communication device can access by using a default certificate;
在本发明的另一种可选的实施例中,第一列表包括以下至少一项:In another optional embodiment of the present invention, the first list includes at least one of the following:
能够被受限接入的网络列表;A list of networks that can be restricted to access;
能够配置证书和/或签约的网络列表;A list of networks that can configure certificates and/or subscriptions;
能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
一种实施方式中,所述能够配置证书和/或签约的网络列表中的网络包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an implementation manner, the networks in the list of networks that can be configured with certificates and/or subscriptions include networks that the first communication device can access restricted and enable the first communication device to obtain certificates and/or subscriptions. network.
在本发明的一种可选的实施例中,所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;In an optional embodiment of the present invention, the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least the following: Item 1: the first communication device cannot be accessed, the first communication device cannot be made to obtain a certificate and/or a contract, and the first communication device cannot access using a default certificate;
在本发明的另一种可选的实施例中,第二列表包括以下至少一项:In another optional embodiment of the present invention, the second list includes at least one of the following:
不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
其中,所述网络列表包括一个或多个网络对象,或一个或多个网络对象的标识信息;所述网络对象包括网络和/或网络组;Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
所述第一指示信息用于指示以下至少一项:The first indication information is used to indicate at least one of the following:
支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
一种实施方式中,第一通信设备通过预配置获得第一列表和/或第二列表。In an implementation manner, the first communication device obtains the first list and/or the second list through pre-configuration.
所述第一对象的证书和/或签约包括用于接入第一对象的证书和/或签约。The credentials and/or subscriptions of the first object include credentials and/or subscriptions for accessing the first object.
一种实施方式中,第一通信设备通过预配置获得第一列表和/或第二列表。In an implementation manner, the first communication device obtains the first list and/or the second list through pre-configuration.
所述第一对象的证书和/或签约包括用于接入第一对象的证书和/或签约。The credentials and/or subscriptions of the first object include credentials and/or subscriptions for accessing the first object.
在本发明的一种可选的实施例中,所述证书和/或签约包括以下至少一项: 第一对象的证书和/或签约;用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约;In an optional embodiment of the present invention, the certificate and/or contract includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a contract for primary authentication and/or authorization , for certificates and/or signings other than primary authentication and/or authorization;
其中,in,
所述第一对象包括以下至少一项:A网络,第一实体,第一通信设备接入的网络,主认证和/或授权,非主认证和/或授权;The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
所述第一实体包括以下之一:数据网中的实体,所述第一通信设备接入的网络之外的实体;The first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
其中,所述A网络与所述第一列表中的网络相同或不同;Wherein, the A network is the same as or different from the network in the first list;
和/或,and / or,
所述A网络与所述第二列表中的网络相同或不同;the A network is the same as or different from the network in the second list;
和/或,and / or,
所述A网络与所述第一通信设备接入的网络相同或不同;The A network is the same as or different from the network accessed by the first communication device;
和/或,and / or,
所述获得证书和/或签约包括以下至少一项:通过控制面方式获得证书和/或签约,通过用户面方式获得证书和/或签约;The obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
和/或,and / or,
所述能够配置证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置证书和/或签约的网络列表,能够通过用户面方式配置证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
和/或,and / or,
能够使所述第一通信设备获得证书和/或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得证书和/或签约,能够使所述第一通信设备通过用户面方式获得证书和/或签约。Enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate and/or signing through a user plane way to obtain a certificate and/or contract.
在本发明的一种可选的实施例中,所述第一列表为所述第一对象对应的第一列表,不同的所述第一对象对应的第一列表相同或不同;In an optional embodiment of the present invention, the first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;
和/或,and / or,
所述第二列表为所述第一对象对应的第二列表,不同的所述第一对象对应的第二列表相同或不同;The second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;
和/或,and / or,
能够配置证书和/或签约的网络列表包括:能够配置所述第一对象的证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes: a list of networks capable of configuring certificates and/or subscriptions of the first object;
和/或,and / or,
不能够配置证书和/或签约的网络列表包括:不能够配置所述第一对象的证书和/或签约的网络列表;The list of networks for which the certificate and/or subscription cannot be configured includes: the list of networks for which the certificate and/or subscription of the first object cannot be configured;
和/或,and / or,
能够使所述第一通信设备获得证书和/或签约包括:能够使所述第一通信设备获得所述第一对象的证书和/或签约;The enabling of the first communication device to obtain the certificate and/or the contract includes: enabling the first communication device to obtain the certificate and/or the contract of the first object;
和/或,and / or,
不能够使所述第一通信设备获得证书和/或签约包括:不能够使所述第一通信设备获得所述第一对象的证书和/或签约。The inability to enable the first communication device to obtain the certificate and/or the contract includes: the inability to enable the first communication device to obtain the certificate and/or the contract of the first object.
在本发明的一种可选的实施例中,所述第一对象对应的第一列表包括:所述第一对象对应的通过控制面方式的第一列表,所述第一对象对应的通过用户面方式的第一列表;In an optional embodiment of the present invention, the first list corresponding to the first object includes: a first list corresponding to the first object through the control plane, and the first object corresponding to the user the first list of face modes;
其中,in,
所述第一对象对应的通过控制面方式的第一列表和所述第一对象对应的通过用户面方式的第一列表相同或不同;The first list corresponding to the first object through the control plane method and the first list through the user plane method corresponding to the first object are the same or different;
所述第一对象对应的通过控制面方式的第一列表中的网络包括:能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约的网络;The networks in the first list by means of the control plane corresponding to the first object include: networks capable of enabling the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
所述第一对象对应的通过用户面方式的第一列表中的网络包括:能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约的网络;The network corresponding to the first object in the first list through the user plane method includes: a network capable of enabling the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
和/或,and / or,
所述第一对象对应的第二列表包括:所述第一对象对应的通过控制面方式的第二列表,所述第一对象对应的通过用户面方式的第二列表;The second list corresponding to the first object includes: a second list corresponding to the first object through a control plane method, and a second list corresponding to the first object through a user plane method;
其中,in,
所述第一对象对应的通过控制面方式的第二列表和第一对象对应的通过用户面方式的第二列表相同或不同;The second list corresponding to the first object through the control plane method and the second list corresponding to the first object through the user plane method are the same or different;
所述第一对象对应的通过控制面方式的第二列表中的网络包括不能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约的网络;The networks in the second list by means of the control plane corresponding to the first object include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
所述第一对象对应的通过用户面方式的第二列表中的网络包括不能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约的网络;The networks in the second list corresponding to the first object through the user plane method include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
和/或,and / or,
能够配置所述第一对象的证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置所述第一对象的证书和/或签约的网络列表,能够通过用户面方式配置所述第一对象的证书和/或签约的网络列表;The list of networks that can configure the certificate and/or subscription of the first object includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object in a control plane mode, and a list of networks that can configure the certificate and/or subscription of the first object in a user plane mode. the certificate and/or contracted network list of the first object;
和/或,and / or,
不能够配置所述第一对象的证书和/或签约的网络列表包括以下至少一项:不能够通过控制面方式配置所述第一对象的证书和/或签约的网络列表,不能够通过用户面方式配置所述第一对象的证书和/或签约的网络列表;The list of networks for which the certificate and/or contract of the first object cannot be configured includes at least one of the following: the list of networks for which the certificate and/or the contract of the first object cannot be configured through the control plane, and the list of networks that cannot be configured through the user plane way to configure the certificate and/or contracted network list of the first object;
和/或,and / or,
能够使所述第一通信设备获得所述第一对象的证书和/或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得所述第一对象的证书和/或签约,能够使所述第一通信设备通过用户面方式获得所述第一对象的证书和/或签约;The enabling of the first communication device to obtain the certificate and/or the contract of the first object includes at least one of the following: enabling the first communication device to obtain the certificate and/or the contract of the first object by means of a control plane , enabling the first communication device to obtain the certificate and/or contract of the first object through the user plane;
和/或,and / or,
不能够使所述第一通信设备获得所述第一对象的证书和/或签约包括以下至少一项:不能够使所述第一通信设备通过控制面方式获得所述第一对象的证书和/或签约,不能够使所述第一通信设备通过用户面方式获得所述第一对象的证书和/或签约。The inability to enable the first communication device to obtain the first object's certificate and/or the contract includes at least one of the following: inability to enable the first communication device to obtain the first object's certificate and/or by means of the control plane or contract, the first communication device cannot obtain the certificate and/or contract of the first object through the user plane method.
在本发明的一种可选的实施例中,所述第一列表中网络,第二列表中网络,和/或A网络的网络类型包括以下至少一项:公网,非公网,PLMN,PNI NPN,SNPN。In an optional embodiment of the present invention, the network types of the networks in the first list, the networks in the second list, and/or the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
在本发明的一种可选的实施例中,第一获取模块601进一步用于:从小区广播或从第二通信设备接收第一指示信息。In an optional embodiment of the present invention, the first obtaining module 601 is further configured to: broadcast from a cell or receive the first indication information from a second communication device.
在本发明的一种可选的实施例中,所述装置600还包括:In an optional embodiment of the present invention, the apparatus 600 further includes:
第二获取模块,用于通过接入所述第一列表中的网络,获得以下至少一项:The second obtaining module is configured to obtain at least one of the following items by accessing the network in the first list:
所述第一对象的证书和/或签约,the certificate and/or contract of the first object,
所述第一对象的标识信息;identification information of the first object;
所述第一对象对应的第一列表;a first list corresponding to the first object;
所述第一对象对应的第二列表;a second list corresponding to the first object;
在本发明的一种可选的实施例中,选择模块602进一步用于:In an optional embodiment of the present invention, the selection module 602 is further configured to:
满足第一条件时,选择第一网络;When the first condition is met, the first network is selected;
其中,所述第一条件包括以下至少一项:Wherein, the first condition includes at least one of the following:
所述第一网络是所述第一列表中的网络;the first network is a network in the first list;
从所述第一网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the first network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第一列表包括以下至少一项:能够配置第一对象的证书和/或签约的网络列表;第一对象对应的第一列表;第一列表中的网络能够使所述第一通信设备获得第一对象的证书和/或签约;第一对象的证书和/或签约对应的允许的网络列表;The first list includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object; a first list corresponding to the first object; the networks in the first list can enable the first communication device to obtain The certificate and/or subscription of the first object; the list of allowed networks corresponding to the certificate and/or subscription of the first object;
所述第一网络在第一列表中优先级最高;The first network has the highest priority in the first list;
所述第一通信设备在第一网络的覆盖范围内或第一通信设备能够监测到第一网络的信号。The first communication device is within the coverage of the first network or the first communication device can monitor the signal of the first network.
在本发明的一种可选的实施例中,选择模块602进一步用于:In an optional embodiment of the present invention, the selection module 602 is further configured to:
满足第二条件时,选择第二网络;When the second condition is met, the second network is selected;
其中,所述第二条件包括以下至少一项:Wherein, the second condition includes at least one of the following:
所述第二网络不是所述第二列表中的网络;the second network is not a network in the second list;
从所述第二网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约; 支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得所述第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第二列表包括以下至少一项:不能够配置所述第一对象的证书和/或签约的网络列表;所述第一对象对应的第二列表;第二列表中的网络不能够使所述第一通信设备获得所述第一对象的证书和/或签约;所述第一对象的证书和/或签约对应的不允许的网络列表;The second list includes at least one of the following: a list of networks that cannot configure the certificate and/or subscription of the first object; a second list corresponding to the first object; The first communication device obtains the certificate and/or subscription of the first object; the list of disallowed networks corresponding to the certificate and/or subscription of the first object;
所述第一通信设备在第一列表的任一网络的覆盖范围之外或第一通信设备不能够监测到第一列表中任一网络的信号。The first communication device is out of coverage of any network in the first list or the first communication device cannot monitor the signal of any network in the first list.
在本发明的一种可选的实施例中,所述第一列表中的网络按优先级别排序。In an optional embodiment of the present invention, the networks in the first list are sorted by priority.
在本发明的一种可选的实施例中,选择模块602进一步用于:In an optional embodiment of the present invention, the selection module 602 is further configured to:
满足第三条件时,选择第三网络;When the third condition is met, select the third network;
其中,所述第三条件包括以下至少一项:Wherein, the third condition includes at least one of the following:
所述第三网络是所述第一列表中的网络;the third network is a network in the first list;
从所述第三网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the third network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得所述第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第一列表包括以下至少一项:所述第一对象对应的通过控制面方式的第一列表,能够通过控制面方式配置所述第一对象的证书和/或签约的网络列表;第一列表中的网络能够使所述第一通信设备通过控制面方式获得所述第一对象的证书和/或签约;所述第一通信设备在第三网络的覆盖范围内或 第一通信设备能够监测到第三网络的信号;The first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, and a network list of certificates and/or subscriptions of the first object that can be configured in a control plane manner; the first The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the control plane; the first communication device is within the coverage of the third network or the first communication device can monitor the signal to the third network;
和/或,and / or,
满足第四条件时,选择第四网络;When the fourth condition is met, select the fourth network;
其中,所述第四条件包括以下至少一项:Wherein, the fourth condition includes at least one of the following:
所述第四网络是所述第一列表中的网络;the fourth network is a network in the first list;
从所述第四网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约,支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions, support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
所述第一列表包括以下至少一项:所述第一对象对应的通过用户面方式的第一列表,能够通过用户面方式配置第一对象的证书和/或签约的网络列表;所述第一列表中的网络能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约;The first list includes at least one of the following: a first list corresponding to the first object through a user plane method, and a network list of certificates and/or subscriptions of the first object that can be configured through a user plane method; the first list The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane;
所述第一通信设备在第四网络的覆盖范围内或第一通信设备能够监测到第四网络的信号。The first communication device is within the coverage of the fourth network or the first communication device can monitor the signal of the fourth network.
本申请实施例提供的装置能够实现图2所示的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The apparatus provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 2 , and achieve the same technical effect. To avoid repetition, details are not described here.
参见图7,本申请实施例提供一种支持网络选择的装置,应用于第二通信设备,装置700包括:Referring to FIG. 7 , an embodiment of the present application provides an apparatus for supporting network selection, which is applied to a second communication device. The apparatus 700 includes:
第一发送模块701,用于发送第一指示信息;a first sending module 701, configured to send first indication information;
其中,所述第一指示信息用于指示以下至少一项:Wherein, the first indication information is used to indicate at least one of the following:
支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
本申请实施例提供的装置能够实现图3所示的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The apparatus provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 3 , and achieve the same technical effect. To avoid repetition, details are not described here.
参见图8,本申请实施例提供一种支持网络选择的装置,应用于第三通信设备,装置800包括:Referring to FIG. 8 , an embodiment of the present application provides an apparatus for supporting network selection, which is applied to a third communication device. The apparatus 800 includes:
第二发送模块801,用于发送第一列表和/或第二列表;A second sending module 801, configured to send the first list and/or the second list;
在本发明的一种可选的实施例中,所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入;In an optional embodiment of the present invention, the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include the following At least one item: the first communication device is capable of restricted access, enabling the first communication device to obtain a certificate and/or sign a contract, and the first communication device can access by using a default certificate;
一种实施方式中,所述第一列表中的网络包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an implementation manner, the networks in the first list include networks to which the first communication device can access restricted and enable the first communication device to obtain a certificate and/or a subscription.
在本发明的另一种可选的实施例中,第一列表包括以下至少一项:In another optional embodiment of the present invention, the first list includes at least one of the following:
能够被受限接入的网络列表,A list of networks that can be restricted to access,
能够配置证书和/或签约的网络列表,Ability to configure a list of certificates and/or signed networks,
能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
一种实施方式中,所述能够配置证书和/或签约的网络列表中的网络包括所述第一通信设备能够受限接入,并能够使所述第一通信设备获得证书和/或签约的网络。In an implementation manner, the networks in the list of networks that can be configured with certificates and/or subscriptions include networks that the first communication device can access restricted and enable the first communication device to obtain certificates and/or subscriptions. network.
在本发明的一种可选的实施例中,所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;In an optional embodiment of the present invention, the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least the following: Item 1: the first communication device cannot be accessed, the first communication device cannot be made to obtain a certificate and/or a contract, and the first communication device cannot access using a default certificate;
在本发明的另一种可选的实施例中,所述第二列表包括以下至少一项:In another optional embodiment of the present invention, the second list includes at least one of the following:
不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
所述网络列表包括一个或多个网络对象,或所述网络列表包括一个或多个网络对象的标识信息,所述网络对象包括网络和/或网络组。The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
在本发明的一种可选的实施例中,所述证书和/或签约包括以下至少一项:第一对象的证书和/或签约;用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约;In an optional embodiment of the present invention, the certificate and/or contract includes at least one of the following: a certificate and/or a contract for the first object; a certificate and/or a contract for primary authentication and/or authorization , for certificates and/or signings other than primary authentication and/or authorization;
其中,in,
所述第一对象包括以下至少一项:A网络,第一实体,第一通信设备接入的网络,主认证和/或授权,非主认证和/或授权;The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
所述第一实体包括以下之一:数据网中的实体、第一通信设备接入的网络之外的实体;The first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
所述A网络与所述第一列表中的网络相同或不同;The A network is the same as or different from the network in the first list;
和/或,and / or,
所述A网络与所述第二列表中的网络相同或不同。The A network is the same as or different from the network in the second list.
和/或,and / or,
所述A网络与所述第一通信设备接入的网络相同或不同;The A network is the same as or different from the network accessed by the first communication device;
和/或,and / or,
所述获得证书和/或签约包括以下至少一项:通过控制面方式获得证书和/或签约,通过用户面方式获得证书和/或签约;The obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
和/或,and / or,
所述能够配置证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置证书和/或签约的网络列表,能够通过用户面方式配置证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
和/或,and / or,
能够使所述第一通信设备获得证书和/或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得证书和/或签约,能够使所述第一通信设备通过用户面方式获得证书和/或签约。Enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate and/or signing through a user plane way to obtain a certificate and/or contract.
在本发明的一种可选的实施例中,所述第一列表中网络的网络类型,第 二列表中网络的网络类型,和/或所述A网络的网络类型包括以下至少一项:公网,非公网,PLMN,PNI NPN,SNPN。In an optional embodiment of the present invention, the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
在本发明的一种可选的实施例中,所述第一列表中的网络按优先级别排序。In an optional embodiment of the present invention, the networks in the first list are sorted by priority.
本申请实施例提供的装置能够实现图4所示的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The apparatus provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 4 , and achieve the same technical effect. To avoid repetition, details are not repeated here.
本申请实施例提供的装置能够实现图4所示的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The apparatus provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 4 , and achieve the same technical effect. To avoid repetition, details are not repeated here.
图9为实现本申请实施例的一种终端的硬件结构示意图,该终端900包括但不限于:射频单元901、网络模块902、音频输出单元903、输入单元904、传感器905、显示单元906、用户输入单元907、接口单元908、存储器909、以及处理器910等部件。FIG. 9 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application. The terminal 900 includes but is not limited to: a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user Input unit 907, interface unit 908, memory 909, processor 910 and other components.
本领域技术人员可以理解,终端900还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器910逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图9中示出的终端结构并不构成对终端的限定,终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。Those skilled in the art can understand that the terminal 900 may also include a power source (such as a battery) for supplying power to various components, and the power source may be logically connected to the processor 910 through a power management system, so as to manage charging, discharging, and power consumption through the power management system management and other functions. The terminal structure shown in FIG. 9 does not constitute a limitation on the terminal, and the terminal may include more or less components than shown, or combine some components, or arrange different components, which will not be repeated here.
应理解的是,本申请实施例中,输入单元904可以包括图形处理器(Graphics Processing Unit,GPU)9041和麦克风9042,图形处理器9041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元906可包括显示面板9061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板9061。用户输入单元907包括触控面板9071以及其他输入设备9072。触控面板9071,也称为触摸屏。触控面板9071可包括触摸检测装置和触摸控制器两个部分。其他输入设备9072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。It should be understood that, in this embodiment of the present application, the input unit 904 may include a graphics processor (Graphics Processing Unit, GPU) 9041 and a microphone 9042. Such as camera) to obtain still pictures or video image data for processing. The display unit 906 may include a display panel 9061, which may be configured in the form of a liquid crystal display, an organic light emitting diode, or the like. The user input unit 907 includes a touch panel 9071 and other input devices 9072 . The touch panel 9071 is also called a touch screen. The touch panel 9071 may include two parts, a touch detection device and a touch controller. Other input devices 9072 may include, but are not limited to, physical keyboards, function keys (such as volume control keys, switch keys, etc.), trackballs, mice, and joysticks, which will not be repeated here.
本申请实施例中,射频单元901将来自网络侧设备的下行数据接收后,给处理器910处理;另外,将上行的数据发送给网络侧设备。通常,射频单元901包括但不限于天线、至少一个放大器、收发信机、耦合器、低噪声放 大器、双工器等。In the embodiment of the present application, the radio frequency unit 901 receives the downlink data from the network side device, and then processes it to the processor 910; in addition, sends the uplink data to the network side device. Generally, the radio frequency unit 901 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, and the like.
存储器909可用于存储软件程序或指令以及各种数据。存储器909可主要包括存储程序或指令区和存储数据区,其中,存储程序或指令区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器909可以包括高速随机存取存储器,还可以包括非易失性存储器,其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。例如至少一个磁盘存储器件、闪存器件、或其他非易失性固态存储器件。 Memory 909 may be used to store software programs or instructions as well as various data. The memory 909 may mainly include a storage program or instruction area and a storage data area, wherein the stored program or instruction area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.) and the like. In addition, the memory 909 may include a high-speed random access memory, and may also include a non-volatile memory, wherein the non-volatile memory may be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM) , PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or flash memory. For example at least one magnetic disk storage device, flash memory device, or other non-volatile solid state storage device.
处理器910可包括一个或多个处理单元;可选的,处理器910可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、用户界面和应用程序或指令等,调制解调处理器主要处理无线通信,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器910中。The processor 910 may include one or more processing units; optionally, the processor 910 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, application programs or instructions, etc., Modem processors mainly deal with wireless communications, such as baseband processors. It can be understood that, the above-mentioned modulation and demodulation processor may not be integrated into the processor 910.
本申请实施例提供的终端能够实现图2所示的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The terminal provided in this embodiment of the present application can implement each process implemented by the method embodiment shown in FIG. 2 and achieve the same technical effect. To avoid repetition, details are not described here.
本申请实施例还提供了一种网络侧设备。如图10所示,该网络侧设备1000包括:天线1001、射频装置1002、基带装置1003。天线1001与射频装置1002连接。在上行方向上,射频装置1002通过天线1001接收信息,将接收的信息发送给基带装置1003进行处理。在下行方向上,基带装置1003对要发送的信息进行处理,并发送给射频装置1002,射频装置1002对收到的信息进行处理后经过天线1001发送出去。The embodiment of the present application also provides a network side device. As shown in FIG. 10 , the network side device 1000 includes: an antenna 1001 , a radio frequency device 1002 , and a baseband device 1003 . The antenna 1001 is connected to the radio frequency device 1002 . In the uplink direction, the radio frequency device 1002 receives information through the antenna 1001, and sends the received information to the baseband device 1003 for processing. In the downlink direction, the baseband device 1003 processes the information to be sent and sends it to the radio frequency device 1002 , and the radio frequency device 1002 processes the received information and sends it out through the antenna 1001 .
上述频带处理装置可以位于基带装置1003中,以上实施例中网络侧设备执行的方法可以在基带装置1003中实现,该基带装置1003包括处理器1004和存储器1005。The above-mentioned frequency band processing apparatus may be located in the baseband apparatus 1003 , and the method performed by the network side device in the above embodiments may be implemented in the baseband apparatus 1003 . The baseband apparatus 1003 includes a processor 1004 and a memory 1005 .
基带装置1003例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图10所示,其中一个芯片例如为处理器1004,与存储器1005连接,以调用存储器1005中的程序,执行以上方法实施例中所示的网络设备操作。The baseband device 1003 may include, for example, at least one baseband board on which multiple chips are arranged, as shown in FIG. 10 , one of the chips is, for example, the processor 1004 , which is connected to the memory 1005 to call a program in the memory 1005 to execute The network devices shown in the above method embodiments operate.
该基带装置1003还可以包括网络接口1006,用于与射频装置1002交互 信息,该接口例如为通用公共无线接口(Common Public Radio Interface,简称CPRI)。The baseband device 1003 may also include a network interface 1006 for exchanging information with the radio frequency device 1002, and the interface is, for example, a Common Public Radio Interface (CPRI for short).
具体地,本申请实施例的网络侧设备还包括:存储在存储器1005上并可在处理器1004上运行的指令或程序,处理器1004调用存储器1005中的指令或程序执行图7-图8所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。Specifically, the network-side device in this embodiment of the present application further includes: an instruction or program stored in the memory 1005 and executable on the processor 1004, and the processor 1004 invokes the instruction or program in the memory 1005 to execute the instructions or programs shown in FIGS. 7-8. The methods performed by each module are shown, and the same technical effect is achieved. In order to avoid repetition, it is not repeated here.
本申请实施例还提供一种程序产品,所述程序产品被存储在非易失的存储介质中,所述程序产品被至少一个处理器执行以实现如图2-图4所述的处理的方法的步骤。An embodiment of the present application further provides a program product, where the program product is stored in a non-volatile storage medium, and the program product is executed by at least one processor to implement the processing method as described in FIG. 2 to FIG. 4 . A step of.
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述图2-图4所示方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。An embodiment of the present application further provides a readable storage medium, where a program or an instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, each process of the method embodiment shown in FIG. 2 to FIG. 4 is implemented. , and can achieve the same technical effect, in order to avoid repetition, it is not repeated here.
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。Wherein, the processor is the processor in the terminal described in the foregoing embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, and the like.
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行网络侧设备程序或指令,实现上述图2-图4所示方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。An embodiment of the present application further provides a chip, where the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a network-side device program or instruction to implement the above-mentioned FIG. 2- The various processes of the method embodiment shown in FIG. 4 can achieve the same technical effect, and are not repeated here in order to avoid repetition.
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, a system-on-chip, a system-on-chip, or a system-on-a-chip, or the like.
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例 如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。It should be noted that, herein, the terms "comprising", "comprising" or any other variation thereof are intended to encompass non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements, It also includes other elements not expressly listed or inherent to such a process, method, article or apparatus. Without further limitation, an element qualified by the phrase "comprising a..." does not preclude the presence of additional identical elements in a process, method, article or apparatus that includes the element. Furthermore, it should be noted that the scope of the methods and apparatus in the embodiments of the present application is not limited to performing the functions in the order shown or discussed, but may also include performing the functions in a substantially simultaneous manner or in the reverse order depending on the functions involved. To perform functions, for example, the described methods may be performed in an order different from that described, and various steps may also be added, omitted, or combined. Additionally, features described with reference to some examples may be combined in other examples.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器或者网络设备等)执行本申请各个实施例所述的方法。From the description of the above embodiments, those skilled in the art can clearly understand that the method of the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is better implementation. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product in essence or in a part that contributes to the prior art, and the computer software product is stored in a storage medium (such as ROM/RAM, magnetic disk, CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, or a network device, etc.) execute the methods described in the various embodiments of this application.
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。The embodiments of the present application have been described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific embodiments, which are merely illustrative rather than restrictive. Under the inspiration of this application, without departing from the scope of protection of the purpose of this application and the claims, many forms can be made, which all fall within the protection of this application.

Claims (24)

  1. 一种支持网络选择的方法,由第一通信设备执行,包括:A method for supporting network selection, performed by a first communication device, comprising:
    获得第一信息,所述第一信息包括:第一列表,第二列表和/或第一指示信息;obtaining first information, where the first information includes: a first list, a second list and/or first indication information;
    根据所述第一信息选择网络;selecting a network according to the first information;
    其中,in,
    所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,所述第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
    或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
    能够被受限接入的网络列表;A list of networks that can be restricted to access;
    能够配置证书和/或签约的网络列表;A list of networks that can configure certificates and/or subscriptions;
    能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
    所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
    或者,第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
    不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
    不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
    不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
    其中,所述网络列表包括一个或多个网络对象,或一个或多个网络对象的标识信息;所述网络对象包括网络和/或网络组;Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
    所述第一指示信息用于指示以下至少一项:The first indication information is used to indicate at least one of the following:
    支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
    支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
    支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
    支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
    支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
    支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
    支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
    支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
    支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions via the user plane based on unrestricted access is supported or not.
  2. 根据权利要求1所述的方法,其中,所述证书和/或签约包括以下至少一项:第一对象的证书和/或签约;用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约;The method according to claim 1, wherein the certificate and/or subscription includes at least one of the following: a certificate and/or a subscription for the first object; a certificate and/or a subscription for primary authentication and/or authorization, using for certificates and/or contracts other than primary certification and/or authorization;
    其中,in,
    所述第一对象包括以下至少一项:A网络,第一实体,第一通信设备接入的网络,主认证和/或授权,非主认证和/或授权;The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
    所述第一实体包括以下之一:数据网中的实体,所述第一通信设备接入的网络之外的实体;The first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
    其中,in,
    所述A网络与所述第一列表中的网络相同或不同;The A network is the same as or different from the network in the first list;
    和/或,and / or,
    所述A网络与所述第二列表中的网络相同或不同;the A network is the same as or different from the network in the second list;
    和/或,and / or,
    所述A网络与所述第一通信设备接入的网络相同或不同;The A network is the same as or different from the network accessed by the first communication device;
    和/或,and / or,
    所述获得证书和/或签约包括以下至少一项:通过控制面方式获得证书和/或签约,通过用户面方式获得证书和/或签约;The obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
    和/或,and / or,
    所述能够配置证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置证书和/或签约的网络列表,能够通过用户面方式配置证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
    和/或,and / or,
    能够使所述第一通信设备获得证书和/或签约包括以下至少一项:能够使 所述第一通信设备通过控制面方式获得证书和/或签约,能够使所述第一通信设备通过用户面方式获得证书和/或签约。Enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate through a user plane way to obtain a certificate and/or contract.
  3. 根据权利要求2所述的方法,其中,The method of claim 2, wherein,
    所述第一列表为所述第一对象对应的第一列表,不同的所述第一对象对应的第一列表相同或不同;The first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;
    和/或,and / or,
    所述第二列表为所述第一对象对应的第二列表,不同的所述第一对象对应的第二列表相同或不同;The second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;
    和/或,and / or,
    能够配置证书和/或签约的网络列表包括:能够配置所述第一对象的证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes: a list of networks capable of configuring certificates and/or subscriptions of the first object;
    和/或,and / or,
    不能够配置证书和/或签约的网络列表包括:不能够配置所述第一对象的证书和/或签约的网络列表;The list of networks for which the certificate and/or subscription cannot be configured includes: the list of networks for which the certificate and/or subscription of the first object cannot be configured;
    和/或,and / or,
    能够使所述第一通信设备获得证书和/或签约包括:能够使所述第一通信设备获得所述第一对象的证书和/或签约;The enabling of the first communication device to obtain the certificate and/or the contract includes: enabling the first communication device to obtain the certificate and/or the contract of the first object;
    和/或,and / or,
    不能够使所述第一通信设备获得证书和/或签约包括:不能够使所述第一通信设备获得所述第一对象的证书和/或签约。The inability to enable the first communication device to obtain the certificate and/or the contract includes: the inability to enable the first communication device to obtain the certificate and/or the contract of the first object.
  4. 根据权利要求3所述的方法,其中,所述第一对象对应的第一列表包括:所述第一对象对应的通过控制面方式的第一列表,所述第一对象对应的通过用户面方式的第一列表;The method according to claim 3, wherein the first list corresponding to the first object comprises: a first list corresponding to the first object through a control plane method, and a user plane method corresponding to the first object the first list of;
    其中,in,
    所述第一对象对应的通过控制面方式的第一列表和所述第一对象对应的通过用户面方式的第一列表相同或不同;The first list corresponding to the first object through the control plane method and the first list corresponding to the first object through the user plane method are the same or different;
    所述第一对象对应的通过控制面方式的第一列表中的网络包括:能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约的网络;The networks in the first list by means of the control plane corresponding to the first object include: networks capable of enabling the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
    所述第一对象对应的通过用户面方式的第一列表中的网络包括:能够使 所述第一通信设备通过用户面方式获得第一对象的证书和/或签约的网络;The network in the first list corresponding to the first object through the user plane method includes: a network that enables the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
    和/或,and / or,
    所述第一对象对应的第二列表包括:所述第一对象对应的通过控制面方式的第二列表,所述第一对象对应的通过用户面方式的第二列表;The second list corresponding to the first object includes: a second list corresponding to the first object through a control plane method, and a second list corresponding to the first object through a user plane method;
    其中,in,
    所述第一对象对应的通过控制面方式的第二列表和第一对象对应的通过用户面方式的第二列表相同或不同;The second list corresponding to the first object through the control plane method and the second list corresponding to the first object through the user plane method are the same or different;
    所述第一对象对应的通过控制面方式的第二列表中的网络包括不能够使所述第一通信设备通过控制面方式获得第一对象的证书和/或签约的网络;The networks in the second list by means of the control plane corresponding to the first object include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object by means of the control plane;
    所述第一对象对应的通过用户面方式的第二列表中的网络包括不能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约的网络;The networks in the second list corresponding to the first object through the user plane method include networks that cannot enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane method;
    和/或,and / or,
    能够配置所述第一对象的证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置所述第一对象的证书和/或签约的网络列表,能够通过用户面方式配置所述第一对象的证书和/或签约的网络列表;The list of networks that can configure the certificate and/or subscription of the first object includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object in a control plane mode, and a list of networks that can configure the certificate and/or subscription of the first object in a user plane mode. the certificate and/or contracted network list of the first object;
    和/或,and / or,
    不能够配置所述第一对象的证书和/或签约的网络列表包括以下至少一项:不能够通过控制面方式配置所述第一对象的证书和/或签约的网络列表,不能够通过用户面方式配置所述第一对象的证书和/或签约的网络列表;The list of networks for which the certificate and/or contract of the first object cannot be configured includes at least one of the following: the list of networks for which the certificate and/or the contract of the first object cannot be configured through the control plane, and the list of networks that cannot be configured through the user plane way to configure the certificate and/or contracted network list of the first object;
    和/或,and / or,
    能够使所述第一通信设备获得所述第一对象的证书和/或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得所述第一对象的证书和/或签约,能够使所述第一通信设备通过用户面方式获得所述第一对象的证书和/或签约;The enabling of the first communication device to obtain the certificate and/or the contract of the first object includes at least one of the following: enabling the first communication device to obtain the certificate and/or the contract of the first object by means of a control plane , enabling the first communication device to obtain the certificate and/or contract of the first object through the user plane;
    和/或,and / or,
    不能够使所述第一通信设备获得所述第一对象的证书和/或签约包括以下至少一项:不能够使所述第一通信设备通过控制面方式获得所述第一对象的证书和/或签约,不能够使所述第一通信设备通过用户面方式获得所述第一对象的证书和/或签约。The inability to enable the first communication device to obtain the first object's certificate and/or the contract includes at least one of the following: inability to enable the first communication device to obtain the first object's certificate and/or by means of the control plane or contract, the first communication device cannot obtain the certificate and/or contract of the first object through the user plane method.
  5. 根据权利要求1或2所述的方法,其中,所述第一列表中网络,第二列表中网络,和/或A网络的网络类型包括以下至少一项:公网,非公网,PLMN,PNI NPN,SNPN。The method according to claim 1 or 2, wherein the network types of the network in the first list, the network in the second list, and/or the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
  6. 根据权利要求1所述的方法,其中,所述获得第一指示信息,包括:The method according to claim 1, wherein the obtaining the first indication information comprises:
    从小区广播或从第二通信设备接收第一指示信息。The first indication information is broadcast from the cell or received from the second communication device.
  7. 根据权利要求1所述的方法,其中,所述方法还包括:The method of claim 1, wherein the method further comprises:
    通过接入所述第一列表中的网络,获得以下至少一项:Obtain at least one of the following by accessing the network in the first list:
    所述第一对象的证书和/或签约,the certificate and/or contract of the first object,
    所述第一对象的标识信息;the identification information of the first object;
    所述第一对象对应的第一列表;a first list corresponding to the first object;
    所述第一对象对应的第二列表。the second list corresponding to the first object.
  8. 根据权利要求1至3任一所述的方法,其中,所述根据所述第一信息选择网络,包括:The method according to any one of claims 1 to 3, wherein the selecting a network according to the first information comprises:
    满足第一条件时,选择第一网络;When the first condition is met, the first network is selected;
    其中,所述第一条件包括以下至少一项:Wherein, the first condition includes at least one of the following:
    所述第一网络是所述第一列表中的网络;the first network is a network in the first list;
    从所述第一网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the first network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
    所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
    所述第一列表包括以下至少一项:能够配置第一对象的证书和/或签约的网络列表;第一对象对应的第一列表;第一列表中的网络能够使所述第一通信设备获得第一对象的证书和/或签约;第一对象的证书和/或签约对应的允许的网络列表;The first list includes at least one of the following: a list of networks that can configure the certificate and/or subscription of the first object; a first list corresponding to the first object; the networks in the first list can enable the first communication device to obtain The certificate and/or subscription of the first object; the list of allowed networks corresponding to the certificate and/or subscription of the first object;
    所述第一网络在第一列表中优先级最高;The first network has the highest priority in the first list;
    所述第一通信设备在第一网络的覆盖范围内或第一通信设备能够监测到第一网络的信号。The first communication device is within the coverage of the first network or the first communication device can monitor the signal of the first network.
  9. 根据权利要求1至4任一所述的方法,其中,所述根据所述第一信息,选择网络,包括:The method according to any one of claims 1 to 4, wherein the selecting a network according to the first information comprises:
    满足第二条件时,选择第二网络;When the second condition is met, the second network is selected;
    其中,所述第二条件包括以下至少一项:Wherein, the second condition includes at least one of the following:
    所述第二网络不是所述第二列表中的网络;the second network is not a network in the second list;
    从所述第二网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
    所述终端需要获得所述第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
    所述第二列表包括以下至少一项:不能够配置所述第一对象的证书和/或签约的网络列表;所述第一对象对应的第二列表;第二列表中的网络不能够使所述第一通信设备获得所述第一对象的证书和/或签约;所述第一对象的证书和/或签约对应的不允许的网络列表;The second list includes at least one of the following: a list of networks that cannot configure the certificate and/or subscription of the first object; a second list corresponding to the first object; The first communication device obtains the certificate and/or subscription of the first object; the list of disallowed networks corresponding to the certificate and/or subscription of the first object;
    所述第一通信设备在第一列表的任一网络的覆盖范围之外或第一通信设备不能够监测到第一列表中任一网络的信号。The first communication device is out of coverage of any network in the first list or the first communication device cannot monitor the signal of any network in the first list.
  10. 根据权利要求1所述的方法,其中,所述第一列表中的网络按优先级别排序。The method of claim 1, wherein the networks in the first list are ordered by priority.
  11. 根据权利要求2至4任一所述的方法,其中,所述根据所述第一信息选择网络,包括:The method according to any one of claims 2 to 4, wherein the selecting a network according to the first information comprises:
    满足第三条件时,选择第三网络;When the third condition is met, select the third network;
    其中,所述第三条件包括以下至少一项:Wherein, the third condition includes at least one of the following:
    所述第三网络是所述第一列表中的网络;the third network is a network in the first list;
    从所述第三网络获得第一指示信息,且所述第一指示信息指示以下至少 一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约;支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the third network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions; support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
    所述终端需要获得所述第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
    所述第一列表包括以下至少一项:所述第一对象对应的通过控制面方式的第一列表,能够通过控制面方式配置所述第一对象的证书和/或签约的网络列表;第一列表中的网络能够使所述第一通信设备通过控制面方式获得所述第一对象的证书和/或签约;所述第一通信设备在第三网络的覆盖范围内或第一通信设备能够监测到第三网络的信号;The first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, and a network list of certificates and/or subscriptions of the first object that can be configured in a control plane manner; the first The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the control plane; the first communication device is within the coverage of the third network or the first communication device can monitor the signal to the third network;
    和/或,and / or,
    满足第四条件时,选择第四网络;When the fourth condition is met, select the fourth network;
    其中,所述第四条件包括以下至少一项:Wherein, the fourth condition includes at least one of the following:
    所述第四网络是所述第一列表中的网络;the fourth network is a network in the first list;
    从所述第四网络获得第一指示信息,且所述第一指示信息指示以下至少一项:支持配置证书和/或签约;支持通过控制面方式配置证书和/或签约;支持通过用户面方式配置证书和/或签约,支持基于受限接入配置证书和/或签约;支持基于受限接入通过控制面方式配置证书和/或签约;支持基于受限接入通过用户面方式配置证书和/或签约;支持基于非受限接入配置证书和/或签约;支持基于非受限接入通过控制面方式配置证书和/或签约;支持基于非受限接入通过用户面方式配置证书和/或签约;The first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting the configuration of certificates and/or subscriptions; supporting the configuration of certificates and/or subscriptions by means of a control plane; supporting by means of user planes Configure certificates and/or subscriptions, support the configuration of certificates and/or subscriptions based on restricted access; support the configuration of certificates and/or subscriptions through the control plane based on restricted access; support the configuration of certificates and/or subscriptions through the user plane based on restricted access Supports configuration of certificates and/or subscriptions based on unrestricted access; supports configuration of certificates and/or subscriptions through control plane based on unrestricted access; supports configuration of certificates and/or subscriptions through user plane based on unrestricted access / or contract;
    所述终端需要获得第一对象的证书和/或签约;The terminal needs to obtain the certificate and/or contract of the first object;
    所述第一列表包括以下至少一项:所述第一对象对应的通过用户面方式的第一列表,能够通过用户面方式配置第一对象的证书和/或签约的网络列表;所述第一列表中的网络能够使所述第一通信设备通过用户面方式获得第一对象的证书和/或签约;The first list includes at least one of the following: a first list corresponding to the first object through a user plane method, and a network list of certificates and/or subscriptions of the first object that can be configured through a user plane method; the first list The networks in the list can enable the first communication device to obtain the certificate and/or subscription of the first object through the user plane;
    所述第一通信设备在第四网络的覆盖范围内或第一通信设备能够监测到 第四网络的信号。The first communication device is within the coverage of the fourth network or the first communication device can monitor the signal of the fourth network.
  12. 一种支持网络选择的方法,由第二通信设备执行,包括:A method of supporting network selection, performed by a second communication device, comprising:
    发送第一指示信息;sending first indication information;
    其中,所述第一指示信息用于指示以下至少一项:Wherein, the first indication information is used to indicate at least one of the following:
    支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
    支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
    支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
    支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
    支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
    支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
    支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
    支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
    支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
  13. 一种支持网络选择的方法,由第三通信设备执行,包括:A method of supporting network selection, performed by a third communication device, comprising:
    发送第一列表和/或第二列表;send the first list and/or the second list;
    所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
    或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
    能够被受限接入的网络列表,A list of networks that can be restricted to access,
    能够配置证书和/或签约的网络列表,Ability to configure a list of certificates and/or signed networks,
    能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
    所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
    或者,所述第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
    不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
    不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
    不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
    所述网络列表包括一个或多个网络对象,或所述网络列表包括一个或多个网络对象的标识信息,所述网络对象包括网络和/或网络组。The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
  14. 根据权利要求13所述的方法,其中,所述证书和/或签约包括以下至少一项:第一对象的证书和/或签约;用于主认证和/或授权的证书和/或签约,用于非主认证和/或授权的证书和/或签约;The method according to claim 13, wherein the certificate and/or subscription includes at least one of the following: a certificate and/or a subscription for the first object; a certificate and/or a subscription for primary authentication and/or authorization, using for certificates and/or contracts other than primary certification and/or authorization;
    其中,in,
    所述第一对象包括以下至少一项:A网络,第一实体,第一通信设备接入的网络,主认证和/或授权,非主认证和/或授权;The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and/or authorization, and non-primary authentication and/or authorization;
    所述第一实体包括以下之一:数据网中的实体、第一通信设备接入的网络之外的实体;The first entity includes one of the following: an entity in a data network, an entity outside the network accessed by the first communication device;
    所述A网络与所述第一列表中的网络相同或不同;The A network is the same as or different from the network in the first list;
    和/或,and / or,
    所述A网络与所述第二列表中的网络相同或不同;the A network is the same as or different from the network in the second list;
    和/或,and / or,
    所述A网络与所述第一通信设备接入的网络相同或不同;The A network is the same as or different from the network accessed by the first communication device;
    和/或,and / or,
    所述获得证书和/或签约包括以下至少一项:通过控制面方式获得证书和/或签约,通过用户面方式获得证书和/或签约;The obtaining of the certificate and/or signing includes at least one of the following: obtaining the certificate and/or signing through the control plane, and obtaining the certificate and/or signing through the user plane;
    和/或,and / or,
    所述能够配置证书和/或签约的网络列表包括以下至少一项:能够通过控制面方式配置证书和/或签约的网络列表,能够通过用户面方式配置证书和/或签约的网络列表;The list of networks capable of configuring certificates and/or subscriptions includes at least one of the following: a list of networks capable of configuring certificates and/or subscriptions in a control plane manner, and a list of networks capable of configuring certificates and/or subscriptions in a user plane manner;
    和/或,and / or,
    能够使所述第一通信设备获得证书和/或签约包括以下至少一项:能够使所述第一通信设备通过控制面方式获得证书和/或签约,能够使所述第一通信设备通过用户面方式获得证书和/或签约。Enabling the first communication device to obtain a certificate and/or signing a contract includes at least one of the following: enabling the first communication device to obtain a certificate and/or signing a contract through a control plane, enabling the first communication device to obtain a certificate through a user plane way to obtain a certificate and/or contract.
  15. 根据权利要求13或14所述的方法,其中,所述第一列表中网络的 网络类型,第二列表中网络的网络类型,和/或所述A网络的网络类型包括以下至少一项:公网,非公网,PLMN,PNI NPN,SNPN。The method according to claim 13 or 14, wherein the network type of the network in the first list, the network type of the network in the second list, and/or the network type of the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
  16. 根据权利要求13所述的方法,其中,所述第一列表中的网络按优先级别排序。14. The method of claim 13, wherein the networks in the first list are ordered by priority.
  17. 一种支持网络选择的装置,应用第一通信设备,包括:An apparatus for supporting network selection, using a first communication device, includes:
    第一获取模块,用于获得第一信息,所述第一信息包括:第一列表,第二列表和/或第一指示信息;a first obtaining module, configured to obtain first information, where the first information includes: a first list, a second list and/or first indication information;
    选择模块,用于根据所述第一信息选择网络;a selection module, configured to select a network according to the first information;
    其中,in,
    所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,所述第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
    或者,所述第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
    能够被受限接入的网络列表;A list of networks that can be restricted to access;
    能够配置证书和/或签约的网络列表;A list of networks that can configure certificates and/or subscriptions;
    能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
    所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
    或者,第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
    不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
    不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
    不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
    其中,所述网络列表包括一个或多个网络对象,或一个或多个网络对象的标识信息;所述网络对象包括网络和/或网络组;Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and/or network groups;
    所述第一指示信息用于指示以下至少一项:The first indication information is used to indicate at least one of the following:
    支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
    支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
    支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
    支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
    支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
    支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
    支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
    支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
    支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions through the user plane based on unrestricted access is supported or not.
  18. 一种支持网络选择的装置,应用于第二通信设备,包括:An apparatus for supporting network selection, applied to a second communication device, comprising:
    第一发送模块,用于发送第一指示信息;a first sending module, configured to send the first indication information;
    其中,所述第一指示信息用于指示以下至少一项:Wherein, the first indication information is used to indicate at least one of the following:
    支持或不支持配置证书和/或签约;Supports or does not support provisioning certificates and/or signing;
    支持或不支持通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the control plane;
    支持或不支持通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or signing through the user plane;
    支持或不支持基于受限接入配置证书和/或签约;Supports or does not support configuration of certificates and/or subscriptions based on restricted access;
    支持或不支持基于受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on restricted access;
    支持或不支持基于受限接入通过用户面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the user plane based on restricted access;
    支持或不支持基于非受限接入配置证书和/或签约;Supports or does not support provisioning credentials and/or subscriptions based on unrestricted access;
    支持或不支持基于非受限接入通过控制面方式配置证书和/或签约;Supports or does not support the configuration of certificates and/or subscriptions through the control plane based on unrestricted access;
    支持或不支持基于非受限接入通过用户面方式配置证书和/或签约。Configuration of certificates and/or subscriptions via the user plane based on unrestricted access is supported or not.
  19. 一种支持网络选择的装置,应用于第三通信设备,包括:A device for supporting network selection, applied to a third communication device, comprising:
    第二发送模块,用于发送第一列表和/或第二列表;a second sending module, configured to send the first list and/or the second list;
    所述第一列表包括:一个或多个网络对象,或一个或多个网络对象的标识信息,所述第一列表中的网络的特征包括以下至少一项:所述第一通信设备能够受限接入,能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书能够接入;The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be limited access, enabling the first communication device to obtain a certificate and/or to sign a contract, and the first communication device can access by using a default certificate;
    或者,第一列表包括以下至少一项:Alternatively, the first list includes at least one of the following:
    能够被受限接入的网络列表,A list of networks that can be restricted to access,
    能够配置证书和/或签约的网络列表,Ability to configure a list of certificates and/or signed networks,
    能够采用默认证书接入的网络列表;A list of networks that can be accessed using the default certificate;
    所述第二列表包括一个或多个网络对象,或一个或多个网络对象的标识信息,所述第二列表中的网络的特征包括以下至少一项:所述第一通信设备不能够接入,不能够使所述第一通信设备获得证书和/或签约,第一通信设备采用默认证书不能够接入;The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access , the first communication device cannot obtain a certificate and/or sign a contract, and the first communication device cannot access using the default certificate;
    或者,所述第二列表包括以下至少一项:Alternatively, the second list includes at least one of the following:
    不能够被受限接入的网络列表;A list of networks that cannot be restricted to access;
    不能够配置证书和/或签约的网络列表;inability to configure certificates and/or signed network lists;
    不能够采用默认证书接入的网络列表;A list of networks that cannot be accessed using the default certificate;
    所述网络列表包括一个或多个网络对象,或所述网络列表包括一个或多个网络对象的标识信息,所述网络对象包括网络和/或网络组。The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and/or network groups.
  20. 一种终端,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,其中,所述程序被所述处理器执行时实现如权利要求1至11中任一项所述的方法的步骤。A terminal, comprising: a processor, a memory, and a program stored on the memory and executable on the processor, wherein, when the program is executed by the processor, any one of claims 1 to 11 is implemented A step of the method.
  21. 一种网络侧设备,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,其中,所述程序被所述处理器执行时实现如权利要求12至16中任一项所述的方法的步骤。A network-side device, comprising: a processor, a memory, and a program stored on the memory and running on the processor, wherein, when the program is executed by the processor, the implementation of claims 12 to 16 The steps of any one of the methods.
  22. 一种可读存储介质,其中,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至16中任一项所述的方法的步骤。A readable storage medium, wherein a program or an instruction is stored on the readable storage medium, and the program or instruction implements the steps of the method according to any one of claims 1 to 16 when executed by a processor.
  23. 一种芯片,所述芯片包括处理器和通信接口,其中,所述通信接口和所述处理器耦合,所述处理器用于运行网络设备程序或指令,实现如权利要求1至11任一项所述的支持网络选择的方法的步骤,或者实现如权利要求12所述的支持网络选择的方法的步骤,或者实现如权利要求13至16任一项所述的支持网络选择的方法的步骤。A chip, the chip includes a processor and a communication interface, wherein the communication interface is coupled with the processor, and the processor is used to run a network device program or instruction to implement the method as claimed in any one of claims 1 to 11 The steps of the method for supporting network selection described above, or the steps for implementing the method for supporting network selection as claimed in claim 12, or the steps for implementing the method for supporting network selection as claimed in any one of claims 13 to 16.
  24. 一种计算机程序产品,所述计算机程序产品存储在非易失的存储介质中,其中,所述计算机程序产品被至少一个处理器执行以实现如权利要求1至11任一项所述的支持网络选择的方法的步骤,或者实现如权利要求12所述的支持网络选择的方法的步骤,或者实现如权利要求13至16任一项所 述的支持网络选择的方法的步骤。A computer program product, stored in a non-volatile storage medium, wherein the computer program product is executed by at least one processor to implement a support network as claimed in any one of claims 1 to 11 The steps of the method of selection, or the steps of implementing the method of supporting network selection as claimed in claim 12, or the steps of implementing the method of supporting network selection as claimed in any one of claims 13 to 16.
PCT/CN2022/075020 2021-02-05 2022-01-29 Method, apparatus, and device for supporting network selection, and readable storage medium WO2022166891A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110164165.2 2021-02-05
CN202110164165.2A CN114885321A (en) 2021-02-05 2021-02-05 Method, device and equipment for supporting network selection and readable storage medium

Publications (1)

Publication Number Publication Date
WO2022166891A1 true WO2022166891A1 (en) 2022-08-11

Family

ID=82667165

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/075020 WO2022166891A1 (en) 2021-02-05 2022-01-29 Method, apparatus, and device for supporting network selection, and readable storage medium

Country Status (2)

Country Link
CN (1) CN114885321A (en)
WO (1) WO2022166891A1 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110636506A (en) * 2018-06-22 2019-12-31 维沃移动通信有限公司 Network access method, terminal and network side network element
CN110971641A (en) * 2018-09-30 2020-04-07 维沃移动通信有限公司 Network service control method and communication equipment
US20200329422A1 (en) * 2019-08-05 2020-10-15 Intel Corporation Non-public networks support by ng radio access network (ng-ran)

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110636506A (en) * 2018-06-22 2019-12-31 维沃移动通信有限公司 Network access method, terminal and network side network element
CN110971641A (en) * 2018-09-30 2020-04-07 维沃移动通信有限公司 Network service control method and communication equipment
US20200329422A1 (en) * 2019-08-05 2020-10-15 Intel Corporation Non-public networks support by ng radio access network (ng-ran)

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
ANONYMOUS: "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhanced support of non-public networks (Release 17)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 23.700-07, no. V1.0.0, 9 September 2020 (2020-09-09), pages 1 - 215, XP051925989 *
ERICSSON: "UE onboarding", 3GPP DRAFT; R3-210638, vol. RAN WG3, 14 January 2021 (2021-01-14), pages 1 - 5, XP051973083 *

Also Published As

Publication number Publication date
CN114885321A (en) 2022-08-09

Similar Documents

Publication Publication Date Title
US10798647B2 (en) Network slice selection
US9386617B2 (en) Discovery and operation of hybrid wireless wide area and wireless local area networks
US11064422B2 (en) System and method for enabling subscriber-based policy decisions
US11910475B2 (en) Systems and methods for enabling efficient establishment of policy control associations
WO2022171086A1 (en) Information acquisition supporting method, apparatus, device, and readable storage medium
US20220272577A1 (en) Communication method and communication apparatus
WO2022095850A1 (en) Method and apparatus for establishing policy association, and terminal and network-side device
US9756536B2 (en) Method and apparatus for managing information in a communication system
JP6889740B2 (en) Network slice selection
WO2022166891A1 (en) Method, apparatus, and device for supporting network selection, and readable storage medium
WO2022057828A1 (en) Measurement method, measurement apparatus, terminal and network device
WO2022068903A1 (en) Network selection method and apparatus, information transmission method and apparatus, and information acquisition method and apparatus
US10264441B2 (en) Method and apparatus for performing discovery by device supporting Wi-Fi Direct in wireless communication system
CN112789896B (en) Method and device for switching transmission path
WO2023138525A1 (en) Network selection and access information transmission method and apparatus, network selection and access information obtaining method and apparatus, and related device
WO2022213981A1 (en) Information processing method and apparatus, and communication device
WO2022188754A1 (en) Method and apparatus which use unlicensed frequency band, and terminal and network-side device
WO2022206663A1 (en) Pdu session establishment method, related device and readable storage medium
WO2022156695A1 (en) Operation method and apparatus for leaving network, device, and readable storage medium
WO2022097290A1 (en) Terminal and communication system
WO2022166892A1 (en) Information processing method and apparatus, communication device, and readable storage medium
US20230217531A1 (en) Methods and apparatus for inactive state initial uplink transmission using pre-configured grant at a base station in wireless communication
AU2016102415A4 (en) Network slice selection

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22749170

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22749170

Country of ref document: EP

Kind code of ref document: A1