WO2022037611A1 - 接入网络、网络选择的方法、装置及通信设备 - Google Patents

接入网络、网络选择的方法、装置及通信设备 Download PDF

Info

Publication number
WO2022037611A1
WO2022037611A1 PCT/CN2021/113248 CN2021113248W WO2022037611A1 WO 2022037611 A1 WO2022037611 A1 WO 2022037611A1 CN 2021113248 W CN2021113248 W CN 2021113248W WO 2022037611 A1 WO2022037611 A1 WO 2022037611A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
plane type
certificate
terminal
information
Prior art date
Application number
PCT/CN2021/113248
Other languages
English (en)
French (fr)
Inventor
柯小婉
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN202011281217.6A external-priority patent/CN114173333A/zh
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2022037611A1 publication Critical patent/WO2022037611A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information

Definitions

  • the embodiments of the present application relate to the field of wireless communication technologies, and in particular, to a method, apparatus, and communication device for accessing a network and selecting a network.
  • the way for a terminal to access another network in order to download a certificate for accessing an independent non-public network may be a control plane type or a user plane type.
  • SNPN Seplace Non-public Network
  • the embodiments of the present application provide an access network, a method, an apparatus, and a communication device for network selection, which are used to solve the problem of how to support a terminal to determine a method for downloading a certificate.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a first communication device, including:
  • the first information is used to indicate at least one of the following: the key used for communication between the terminal and the first network can be derived according to the default certificate or the key used for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or the terminal does not Supports the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user The first access method of the face type;
  • the first operation includes any one of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a second communication device, including:
  • the second information includes at least one of the following: information on an access method requested by the terminal, type information on a certificate download method requested by the terminal, and capability information of the terminal;
  • the The fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, information about the preconfigured terminal access mode, and the preconfigured terminal Type information of the certificate download method;
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Sending type information of the determined certificate download method where the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Sending second indication information where the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key used for the communication between the terminal and the first network can be derived according to the default certificate, or the key used for the communication between the terminal and the first network cannot be derived according to the default certificate;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a third communication device, including:
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information, and second indication information ; wherein, the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type; the type information of the certificate download mode is used to Indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type; the first indication information is used to indicate one of the following: adopt the first access method of the control plane type, and not adopt the control plane type the first access mode; the second indication information is used to indicate one of the following: adopt the certificate download mode of the control plane type, and not adopt the certificate download mode of the control plane type;
  • the third operation includes:
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for network selection, which is applied to a fourth communication device, including:
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type or the network does not support the first access mode of the user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a method for network selection, which is applied to a fifth communication device, including:
  • the operation of network selection is performed
  • the fourth information includes at least one of the following: fourth indication information, capability information of the terminal, information of the access mode requested by the terminal, and type information of the certificate download mode requested by the terminal;
  • the fourth indication information is used to indicate any one of the following: the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type, or the network supports the certificate download method of the user plane type.
  • the certificate downloading method of the user plane type is not supported; the network supports the first access method of the control plane type, or the network does not support the first access method of the control plane type; the network supports the first access method of the user plane type, or the network The first access mode of the user plane type is not supported;
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate downloader of the user plane type or the terminal does not support The certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user plane The first access mode of the type; the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived for the terminal according to the default certificate a key for communication with the first network;
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download the certificate for accessing the second network, and the method for downloading the certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a first communication device, including:
  • a first execution module configured to execute a first operation according to the first information
  • the first information is used to indicate at least one of the following: the key used for communication between the terminal and the first network can be derived according to the default certificate or the key used for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or the terminal does not Supports the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user The first access method of the face type;
  • the first operation includes any one of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a second communication device, including:
  • a first obtaining module configured to obtain second information and/or fifth information;
  • the second information includes at least one of the following: information on the access mode requested by the terminal, type information on the certificate download mode requested by the terminal, capability information of the terminal;
  • the fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, and preconfigured terminal access mode information, the type information of the pre-configured terminal certificate download method;
  • a second execution module configured to execute a second operation according to the second information and/or the fifth information
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Sending type information of the determined certificate download method where the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Sending second indication information where the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived according to the default certificate or the key for communication between the terminal and the first network cannot be derived according to the default certificate;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a device for accessing a network, which is applied to a third communication device, including:
  • the second receiving module is configured to receive third information and/or an access acceptance message; wherein the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information and second indication information; wherein, the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type; the certificate The type information of the download method is used to indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type; the first indication information is used to indicate one of the following: the first access using the control plane type The first access method of the control plane type is not used; the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and do not use the certificate download method of the control plane type;
  • a third execution module configured to determine whether to execute the third operation according to the third information and/or the access acceptance message
  • the third operation includes:
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fourth communication device, including:
  • a third sending module configured to send or broadcast the fourth indication information
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type or the network does not support the first access mode of the user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fifth communication device, including:
  • a second obtaining module configured to obtain fourth indication information
  • a fourth execution module configured to execute an operation of network selection according to the fourth information
  • the fourth information includes at least one of the following: fourth indication information, capability information of the terminal, information of the access mode requested by the terminal, and type information of the certificate download mode requested by the terminal;
  • the fourth indication information is used to indicate any one of the following: the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type, or the network supports the certificate download method of the user plane type.
  • the certificate downloading method of the user plane type is not supported; the network supports the first access method of the control plane type, or the network does not support the first access method of the control plane type; the network supports the first access method of the user plane type, or the network The first access mode of the user plane type is not supported;
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate downloader of the user plane type or the terminal does not support The certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user plane The first access mode of the type; the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived for the terminal according to the default certificate a key for communication with the first network;
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • an embodiment of the present application provides a communication device, including a processor, a memory, and a computer program stored on the memory and executable on the processor, the computer program being executed by the processor
  • the steps of implementing the method for accessing a network provided by the first aspect or the steps of implementing the method for accessing a network provided by the second aspect, or the steps of implementing the method for accessing a network provided by the third aspect, or,
  • an embodiment of the present application provides a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, implements the access network provided in the first aspect
  • FIG. 1 is a schematic structural diagram of a wireless communication system according to an embodiment of the present application.
  • FIG. 2 is a schematic flowchart of a method for accessing a network according to an embodiment of the present application
  • FIG. 3 is a schematic flowchart of a method for accessing a network according to another embodiment of the present application.
  • FIG. 4 is a schematic flowchart of a method for accessing a network according to another embodiment of the present application.
  • FIG. 5 is a schematic flowchart of a method for network selection according to another embodiment of the present application.
  • FIG. 6 is a schematic flowchart of a method for network selection according to another embodiment of the present application.
  • FIG. 7 is a schematic flowchart of a method for accessing a network according to Embodiment 1 of the present application.
  • FIG. 8 is a schematic flowchart of a method for network selection in Embodiment 1 of the present application.
  • FIG. 9 is a schematic structural diagram of an apparatus for accessing a network provided by the present application.
  • FIG. 10 is a schematic structural diagram of another apparatus for accessing a network provided by this application.
  • FIG. 11 is a schematic structural diagram of another apparatus for accessing a network provided by this application.
  • FIG. 12 is a schematic structural diagram of an apparatus for network selection provided by the application.
  • FIG. 13 is a schematic structural diagram of another apparatus for network selection provided by the application.
  • FIG. 14 is a structural diagram of a communication device provided by this application.
  • first, second and the like in the description and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the present application can be practiced in sequences other than those illustrated or described herein, and "first”, “second” distinguishes Usually it is a class, and the number of objects is not limited.
  • the first object may be one or multiple.
  • “and/or” in the description and claims indicates at least one of the connected objects, and the character “/" generally indicates that the associated objects are in an "or” relationship.
  • FIG. 1 shows a block diagram of a wireless communication system to which the embodiments of the present application can be applied.
  • the wireless communication system includes a terminal 11 and a network-side device 12 .
  • the terminal 11 may include a relay supporting the terminal function and/or a terminal supporting the relay function.
  • the terminal 11 may also be referred to as a terminal device or a user terminal (User Equipment, UE), and the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), Laptop Computer (Laptop Computer) or notebook computer, Personal Digital Assistant (Personal Digital Assistant, PDA), Mobile Internet Device (Mobile Internet Device, MID), Handheld Computer, Netbook, Ultra Mobile Personal Computer ( Ultra-mobile personal computer (UMPC), Mobile Internet Device (MID), Wearable Device (Wearable Device) or Vehicle User Equipment (VUE), Pedestrian User Equipment (PUE) and other terminals Side devices, wearable devices include: bracelets, headphones, glasses, etc. It should be noted that, the embodiment of the present application does not limit the specific type of the terminal 11 .
  • the network side device 12 may be a base station or a core network, wherein the base station may be referred to as a Node B, an evolved Node B, an access point, a Base Transceiver Station (BTS), a radio base station, a radio transceiver, a basic service Set (Basic Service Set, BSS), Extended Service Set (Extended Service Set, ESS), Node B, Evolved Node B (eNB), Home Node B, Home Evolved Node B, WLAN Access Point, WiFi Node, Send Transmitting Receiving Point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms.
  • the base station in the NR system is taken as an example, but the specific type of the base station is not limited.
  • the communication device does not have a network certificate but needs to access the network.
  • the UE may not be able to access the SNPN yet. certificate and UE identity.
  • the UE may access a certain network (hereinafter referred to as the first network) and download the certificate for accessing the SNPN.
  • the first network may be the SNPN.
  • the way of accessing the first network in order to download the credentials for accessing the second network may be referred to as onboarding.
  • the first network and the second network may be the same network.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the method of downloading the certificate may include: 1) a control plane (Control Plane, CP) type certificate downloading method, in which the first network downloads the certificate from the certificate configuration server for the UE and sends it to the UE through control plane signaling; 2) the user In the certificate download mode of the user plane (UP) type, the terminal establishes a data channel to the first network, and downloads the certificate from the certificate configuration server through the data channel.
  • a control plane Control Plane, CP
  • UP user plane
  • the UE and the first network are required to have additional capabilities:
  • the first network can interact with the provisioning server (Provision Server), and download the certificate from the Provision Server on behalf of the UE, and the certificate is to be sent to the UE under the protection of the key of the default certificate, such as the certificate is included in the non-accessible certificate.
  • layer (Non-Access Stratum, NAS) message is sent to the UE; and the NAS message is encrypted and/or integrity protected.
  • the UE shall be able to support receiving certificates from NAS messages.
  • the certificate download method of the user plane type can be the default method:
  • the network may not need additional capabilities; the network only needs to configure a policy to restrict the established data channel (such as a PDU session (Session)) to only connect to the Provision Server.
  • a policy to restrict the established data channel (such as a PDU session (Session)) to only connect to the Provision Server.
  • the network may support the user plane type certificate download method by default.
  • the UE may support the certificate downloader of the control plane type and/or the certificate download method of the user plane type.
  • the UE when the UE indicates the first access mode, it may imply that the first access mode of the user plane type is supported, and/or, the system information block (SIB) of the network broadcasts the first access mode may imply support.
  • SIB system information block
  • the network can decide whether to adopt the first access method of the control plane type according to the capability of the certificate download method of the control plane type of the UE, and/or, the network can decide whether to use the certificate download method of its own control plane type and the policy configuration.
  • the first access mode of the control plane type is adopted.
  • the UE needs to obtain an indication of the control plane type certificate download mode from the network to decide whether to initiate a data channel (such as a PDU session) Create a download certificate. For example, when the instruction of the certificate download mode of the control plane type is not obtained, the first network is initiated to establish a data channel to download the certificate; when the instruction of the certificate download mode of the control plane type is obtained, the first network can download the certificate for the UE. .
  • a data channel such as a PDU session
  • obtaining may be understood as obtaining from configuration, receiving, receiving after request, obtaining through self-learning, deriving and obtaining according to unreceived information, or obtaining after processing according to received information. It is determined according to actual needs, which is not limited in this embodiment of the present application. For example, when a certain capability indication information sent by the device is not received, it can be deduced that the device does not support the capability.
  • the sending can include broadcasting, broadcasting in system messages, and returning after responding to the request.
  • the first network may include one of the following: a non-public network (eg, SNPN, or PNI-SNPN), or a public network (PLMN).
  • a non-public network eg, SNPN, or PNI-SNPN
  • PLMN public network
  • the second network may include one of the following: a non-public network (eg, SNPN, or PNI-SNPN), or a public network (PLMN).
  • a non-public network eg, SNPN, or PNI-SNPN
  • PLMN public network
  • the certificate download method of the control plane type is that the network element of the first network interacts with the certificate configuration server, and sends the certificate through control plane signaling (such as NAS signaling). way to the terminal.
  • control plane signaling such as NAS signaling
  • the user plane type certificate download method is that the terminal requests the first network to establish a data channel (such as a PDU session), and through the data channel, the terminal and the certificate configuration server interact to download the certificate. Way.
  • the interaction between the terminal and the certificate configuration server is user plane data for the first network, so it is called a user plane type certificate downloading method.
  • the user plane capability of the terminal includes at least one of the following: supporting the establishment of a data channel (such as a PDU session) requesting from the network, a function of session management, and the like.
  • a data channel such as a PDU session
  • the certificate for accessing the second network includes: a certificate of the second network.
  • the non-public network is an abbreviation of the non-public network.
  • a non-public network may be referred to as one of the following: a non-public communication network.
  • the non-public network may include at least one of the following deployment modes: a physical non-public network, a virtual non-public network, and a non-public network implemented on the public network.
  • the non-public network is a closed access group (Closed Access Group, CAG).
  • a CAG can consist of a group of terminals.
  • the non-public network service is an abbreviation for non-public network service.
  • Non-public network services may also be referred to as one of the following: non-public network network services, non-public communication services, non-public network communication services, non-public network network services, or other designations. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the non-public network is a closed access group, and in this case, the non-public network service is a network service of the closed access group.
  • the non-public network may include or be referred to as a private network.
  • a private network may be referred to as one of the following: a private communication network, a private network, a local area network (LAN), a private virtual network (PVN), an isolated communication network, a dedicated communication network, or other nomenclature. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the public network is an abbreviation of the public network.
  • the public network may be called one of the following: public communication network or other designation. It should be noted that, in the embodiments of the present invention, the naming manner is not specifically limited.
  • the authentication service includes an authentication server (such as a DCS, or a home AUSF) initiating an authentication request for the terminal.
  • the authentication service network element may be an authentication agent that provides an authentication service for the terminal.
  • the authentication service network element may include but is not limited to one of the following: AUSF, AAA proxy.
  • the communication device may include at least one of the following: a communication network element and a terminal.
  • the communication network elements may include at least one of the following: a core network network element and a wireless access network network element.
  • the core network element may include, but is not limited to, at least one of the following: core network equipment, core network nodes, core network functions, core network network elements, and mobility management entities (Mobility Management Entity, MME), Access Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Serving Gateway (serving GW, SGW), PDN Gateway ( PDN Gate Way, PDN gateway), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), GPRS service support node (Serving GPRS Support Node, SGSN), gateway GPRS Support Node (Gateway GPRS Support Node, GGSN), Unified Data Management (Unified Data Management, UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS) and Application Function (Application Function) , AF).
  • MME Mobility Management Entity
  • AMF Access Management Function
  • SMF Session Management Function
  • UPF User Plane Function
  • the RAN network element may include, but is not limited to, at least one of the following: a radio access network device, a radio access network node, a radio access network function, a radio access network unit, a 3GPP radio access network, a non- 3GPP Radio Access Network, Centralized Unit (CU), Distributed Unit (DU), Base Station, Evolved Node B (eNB), 5G Base Station (gNB), Radio Network Controller (Radio Network) Controller, RNC), base station (NodeB), non-3GPP interworking function (Non-3GPP Inter Working Function, N3IWF), access control (Access Controller, AC) node, access point (Access Point, AP) equipment or wireless local area network (Wireless Local Area Networks, WLAN) node, N3IWF.
  • a radio access network device a radio access network node, a radio access network function, a radio access network unit, a 3GPP radio access network, a non- 3GPP Radio Access Network, Centralized Unit (CU), Distributed Unit (DU),
  • an embodiment of the present application provides a method for accessing a network, which is applied to a first communication device;
  • the first communication device includes but is not limited to: UE; the method includes:
  • Step 21 Execute the first operation according to the first information.
  • the first information is used to indicate at least one of the following: the key for communication between the terminal and the first network can be derived according to the default certificate or the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or The terminal does not support the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the first access method of the user plane type.
  • the first access mode of the user plane type is supported.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , encryption key, and integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • the first operation includes any of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the terminal supports the first access mode of the user plane type, or it is determined that the terminal does not support the first access mode of the user plane type.
  • the above-mentioned process of performing the first operation according to the first information may include: when at least one of the following is satisfied, determining that the information of the access mode requested by the terminal is the first information of the user plane type.
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type
  • the first information indicates that the terminal has a user plane capability
  • the first information indicates that the terminal supports a user plane type certificate download mode
  • the first information indicates that the terminal supports the first access mode of the user plane type.
  • the above-mentioned process of performing the first operation according to the first information may include: when the first condition is satisfied, determining that the terminal does not support the certificate downloading method of the control plane type or determining that the terminal does not support the first method of the control plane type. access method.
  • the first condition includes at least one of the following:
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type.
  • the above-mentioned process of performing the first operation according to the first information may include:
  • the information determining the access mode requested by the terminal is the first access mode of the control plane type:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type
  • the first information indicates that a key for communication between the terminal and the first network can be derived according to the default certificate
  • the first information indicates that the terminal supports a certificate downloading method of a control plane type
  • the first information indicates that the terminal supports the first access mode of the control plane type.
  • the above-mentioned process of performing the first operation according to the first information may include: when the second condition is satisfied, determining that the terminal does not support the certificate downloading method of the user plane type or determining that the terminal does not support the first method of the user plane type. access method.
  • the second condition includes at least one of the following:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type.
  • the method may further include:
  • Sending second information includes at least one of the following: information of an access mode requested by the terminal, capability information of the terminal, and type information of a certificate download mode requested by the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the method may further include:
  • the third information and/or the access acceptance message it is determined whether to perform the third operation.
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information, and second indication information; wherein the first access mode
  • the type information of the certificate is used to indicate one of the following: the first access method of the control plane type, the first access method of the user plane type
  • the type information of the certificate download method is used to indicate one of the following: the certificate of the control plane type
  • the download method is the certificate download method of the user plane type
  • the first indication information is used to indicate one of the following: the first access method of the control plane type is adopted, and the first access method of the control plane type is not adopted
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type.
  • the access accept message is an access accept message obtained after the terminal accesses the first network, including but not limited to a registration accept message.
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network.
  • the above-mentioned determining whether to perform the third operation according to the third information may include: when the fifth condition is satisfied, performing the third operation.
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate download method of the control plane type is not adopted;
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the first access mode of the user plane type by default.
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the user plane type certificate download mode by default.
  • the above-mentioned determining whether to perform the third operation according to the third information may include: when the sixth condition is satisfied, not performing the third operation.
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate downloading method of a control plane type is adopted.
  • both the UE and the network support the first access mode of the user plane type or the certificate download mode of the user plane type by default, and can optionally support the first access mode of the control plane type or the first access mode of the control plane type. Certificate downloader.
  • the UE when the UE indicates the first access mode, it may imply that the first access mode of the user plane type is supported, and/or, the system information block (SIB) of the network broadcasts the first access mode may imply support.
  • SIB system information block
  • the network can decide whether to adopt the first access method of the control plane type according to the capability of the certificate download method of the control plane type of the UE, and/or, the network can decide whether to use the certificate download method of its own control plane type and the policy configuration.
  • the first access mode of the control plane type is adopted.
  • the terminal needs to obtain an indication of the control plane type certificate download method from the network to decide whether to initiate a data channel (such as a PDU session) Create a download certificate. For example, when the instruction of the certificate download mode of the control plane type is not obtained, the first network is initiated to establish a data channel to download the certificate; when the instruction of the certificate download mode of the control plane type is obtained, it can wait for the first network to download the certificate for the UE. .
  • an embodiment of the present application provides a method for accessing a network, which is applied to a second communication device;
  • the second communication device includes but is not limited to: a CN network element (such as an AMF);
  • the CN network element may is a communication device in the first network.
  • the method includes:
  • Step 31 Acquire second information and/or fifth information.
  • the second information includes at least one of the following: information of an access mode requested by the terminal, type information of a certificate download mode requested by the terminal, and capability information of the terminal.
  • the fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, and information about the preconfigured terminal access mode. Information, type information of the preconfigured terminal certificate download method.
  • the sixth communication device includes but is not limited to one of the following: AF, UDM, PCF, SMF, AUSF, DCS, and configuration server (eg PS).
  • the sixth communication device is a communication device in the certificate owner.
  • the configuration server configures a certificate for the terminal.
  • the DCS may verify and/or authenticate the terminal that accesses the network through the first access manner.
  • the type information of the terminal certificate download method requested by the sixth communication device includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the information about the terminal access mode requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the information of the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the preconfigured terminal certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the terminal certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the capability information of the terminal may be used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , an encryption key and/or an integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • the first access method of the control plane type or the certificate download method of the control plane type cannot be used, because the certificate There is no encryption or integrity protection in the control plane signaling, which is not secure enough.
  • the first access mode of the user plane type or the certificate download mode of the user plane type may be adopted. Because the user plane type can be encrypted at the application layer of the terminal and the configuration server that configures the certificate.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • Step 32 Perform a second operation according to the second information and/or the fifth information.
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Sending type information of the determined certificate download method where the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Second indication information is sent, where the second indication information is used to indicate one of the following: adopt the certificate download mode of the control plane type, and not adopt the certificate download mode of the control plane type.
  • performing the second operation according to the second information and/or the fifth information may include: when the third condition is satisfied, performing at least one of the following: determining that the type of the first access mode is a control plane type the first access mode, determine that the type of the certificate download mode is the certificate download mode of the control plane type, determine that the first indication information indicates that the first access mode of the control plane type is adopted, and determine that the second indication information indicates that the control plane type is adopted. How to download the certificate.
  • the third condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type;
  • the information about the terminal access mode requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a control plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the control plane type;
  • the information of the preconfigured terminal access mode includes one of the following: the first access mode, the first access mode of the control plane type;
  • the type information of the preconfigured terminal certificate download method includes: the certificate download method of the control plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the certificate download method of the control plane type, the terminal supports the first access method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal does not support the certificate download method of the user plane type.
  • the terminal In the first access mode, the terminal does not have the capability of the user plane, and the key used for the communication between the terminal and the first network can be derived according to the default certificate;
  • the first network supports a certificate download method of the control plane type
  • the first network supports the first access mode of the control plane type
  • the first network does not support the certificate download method of the user plane type
  • the first network does not support the first access mode of the user plane type.
  • performing the second operation according to the second information and/or the fifth information may include: when the fourth condition is satisfied, performing at least one of the following: determining that the type of the first access mode is a user plane type the first access mode, determine that the type of the certificate download mode is the user plane type of certificate download mode, determine that the first indication information indicates that the first access mode of the control plane type is not used, and determine that the second indication information indicates that the control plane is not used.
  • the type of certificate download method, the address information of the configuration server is sent to the terminal, the slice information is sent to the terminal, and the Data Network Name (DNN) is sent to the terminal.
  • DNN Data Network Name
  • the configuration server may be a server that configures a certificate for the terminal.
  • the address information of the configuration server may include information for indexing the address of the configuration server.
  • the slice information may be slice information used for establishing a channel for the user plane.
  • the slice information is slice information for the first access mode or slice information for the first access mode of the user plane type.
  • the DNN may be a DNN used to build a channel for the user plane.
  • the user plane channel may be a user plane channel for downloading certificates.
  • the DNN is a DNN for the first access mode or a DNN for the first access mode of the user plane type.
  • the fourth condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a user plane type;
  • the terminal access mode information requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the user plane type;
  • the information of the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the preconfigured terminal certificate download method includes: the certificate download method of the user plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the first access method of the user plane type, the terminal supports the certificate download method of the user plane type, the terminal does not support the certificate download method of the control plane type, and the terminal does not support the certificate download method of the control plane type.
  • the terminal In the first access mode, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived;
  • the first network supports a user plane type certificate download method
  • the first network supports the first access mode of the user plane type
  • the first network does not support the certificate download method of the control plane type
  • the first network does not support the first access mode of the control plane type.
  • the above operations of sending the first indication information and/or sending the second indication information may include:
  • the first indication information indicates that the first access mode of the control plane type is adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is adopted;
  • the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is not adopted.
  • the first network supports the first access mode of the user plane type or the certificate downloading mode of the user plane type by default; the first network can optionally support the first access mode of the control plane type or the certificate of the control plane type. Download method. At this time, the first indication information or the second indication information may be sent.
  • the first indication information may indicate that the control plane is used.
  • the first access mode of the plane type, and the second indication information may indicate that the certificate download mode of the control plane type is adopted.
  • the first indication information may indicate that the control is not used.
  • the first access mode of the plane type, and the second indication information may indicate that the certificate download mode of the control plane type is not adopted.
  • the first network may optionally support a first access manner of a user plane type and/or a first access manner of a control plane type.
  • the first network may optionally support a user plane type certificate download method and/or a control plane type certificate download method.
  • the determined type information of the first access mode may be sent, and the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type and/or, sending the determined type information of the certificate download method, and the type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • an embodiment of the present application provides a method for accessing a network, which is applied to a third communication device;
  • the third communication device includes but is not limited to: UE; the method includes:
  • Step 41 Receive third information and/or access acceptance information.
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information, and second indication information; wherein the first access mode
  • the type information of the certificate is used to indicate one of the following: the first access method of the control plane type, the first access method of the user plane type
  • the type information of the certificate download method is used to indicate one of the following: the certificate of the control plane type
  • the download method is the certificate download method of the user plane type
  • the first indication information is used to indicate one of the following: the first access method of the control plane type is adopted, and the first access method of the control plane type is not adopted
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type.
  • only the access acceptance information may be received, and the third information may not be received.
  • the third information and the access acceptance information may be received.
  • only the third information may be received without the access acceptance information.
  • the access accept message is an access accept message obtained after the terminal accesses the first network, including but not limited to a registration accept message.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • Step 42 Determine whether to perform the third operation according to the third information and/or the access acceptance information.
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network.
  • the access acceptance information is information that the terminal is accepted by the first network.
  • the access acceptance information may be embodied by a registration acceptance message and a service acceptance message.
  • the above-mentioned determining whether to perform the third operation according to the third information and/or the access acceptance information may include: performing the third operation when the fifth condition is satisfied.
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate download method of the control plane type is not adopted;
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the first access mode of the user plane type by default.
  • the terminal and/or the first network when the terminal and/or the first network support the first access mode, the terminal and/or the first network may support the user plane type certificate download mode by default.
  • the above-mentioned determining whether to perform the third operation according to the third information may include: when the sixth condition is satisfied, not performing the third operation.
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate downloading method of a control plane type is adopted.
  • the method may further include:
  • the second information includes at least one of the following: information of an access mode requested by the terminal, and capability information of the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , encryption key, and integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • an embodiment of the present application provides a method for network selection, which is applied to a fourth communication device; the fourth communication device includes but is not limited to: a RAN network element; the RAN network element may be in the first network RAN network element.
  • the method includes:
  • Step 51 Send or broadcast fourth indication information.
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type, or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type, or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type, or the network does not support the first access mode of the user plane type.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • the terminal can be supported to select a network that conforms to its own capability for access.
  • an embodiment of the present application further provides a method for network selection, which is applied to a fifth communication device;
  • the fifth communication device includes but is not limited to: UE; the method includes:
  • Step 61 Obtain fourth indication information.
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type, or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type, or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type, or the network does not support the first access mode of the user plane type.
  • the first access manner includes: an access manner of accessing the first network in order to download a certificate for accessing the second network.
  • the first access mode of the control plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the control plane type.
  • the first access mode of the user plane type includes: an access mode for accessing the first network in order to download a certificate for accessing the second network, and downloading a certificate for accessing the second network
  • the method is the certificate download method of the user plane type.
  • the first network and the second network are the same network or different networks.
  • Step 62 According to the fourth information, the operation of network selection is performed.
  • the fourth information may include at least one of the following: fourth indication information, capability information of the terminal, information of an access mode requested by the terminal, and type information of a certificate download mode requested by the terminal.
  • the fourth communication device obtains at least one of the following items through configuration: information of an access mode requested by the terminal, and type information of a certificate download mode requested by the terminal.
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports a control plane type certificate download method or the terminal does not support a control plane type certificate download method; the terminal supports a user plane type certificate downloader or terminal; The certificate download method of the user plane type is not supported; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support The first access mode of the user plane type; the terminal has the ability of the user plane or the terminal does not have the ability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived according to the default certificate. A key used for communication between the terminal and the first network.
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type.
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type.
  • the above-mentioned key used for communication between the terminal and the first network includes but is not limited to at least one of the following: K SEAF , K AUSF , K AMF , encryption key, and integrity protection key.
  • the key used for the communication between the terminal and the first network may derive an encryption key and/or an integrity protection key for the communication data between the terminal and the first network.
  • the foregoing operation of performing network selection according to the fourth information may include at least one of the following:
  • a network is selected, and the fourth indication information of the selected network conforms to the type information of the certificate download mode requested by the terminal.
  • the fourth indication information of the selected network conforming to the terminal capability information may include at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network The first access mode of the user plane type is not supported; and the capability information of the terminal indicates any one of the following: the terminal supports the certificate download method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal supports the control plane type.
  • the first access mode of the plane type the terminal does not support the first access mode of the user plane type, the terminal does not have the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate.
  • the network only supports the certificate download method of the control plane type, only the terminals that support the certificate download method of the control plane type, or both the certificate download method of the control plane type and/or the user plane type are supported. terminal, the network will be selected.
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; The network supports the first access method of the user plane type; and the capability information of the terminal indicates at least one of the following: the terminal does not support the certificate download method of the control plane type, the terminal supports the certificate download method of the user plane type, and the terminal does not support the certificate download method of the user plane type.
  • the first access mode of the control plane type the terminal supports the first access mode of the user plane type, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived.
  • the network only supports the certificate download method of the user plane type, only the terminal that supports the certificate download method of the user plane type, or supports the certificate download method of the control plane type and/or the user plane type at the same time. terminal, the network will be selected.
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network supports the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network supports The first access mode of the user plane type.
  • both the control plane type certificate download method and/or the user plane type terminal support The network can be selected.
  • the capability information of the terminal indicates at least one of the following: the terminal supports a control plane type certificate download method, the terminal supports a user plane type certificate download method, the terminal supports a control plane type first access method, and the terminal supports a user plane type In the first access mode of the type, the terminal has the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate.
  • the selected network supports the control plane type certificate download method and/or supports the user plane type certificate download method. Download method.
  • the information that the fourth indication information of the selected network conforms to the access mode requested by the terminal may include at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network The first access mode of the user plane type is not supported; and the information of the access mode requested by the terminal includes any one of the following: the first access mode and the first access mode of the control plane type.
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; The network supports the first access mode of the user plane type; and the information of the access mode requested by the terminal includes any one of the following: the first access mode and the first access mode of the user plane type.
  • the type information that the fourth indication information of the selected network conforms to the certificate download mode requested by the terminal may include at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network The first access mode of the user plane type is not supported; and the type information of the certificate download mode requested by the terminal includes any one of the following: a certificate download mode of the control plane type.
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; The network supports the first access mode of the user plane type; and the type information of the certificate download mode requested by the terminal includes: the certificate download mode of the user plane type.
  • the foregoing operation of performing network selection according to the fourth information may include at least one of the following:
  • the selected network supports the control plane type certificate download method and/or supports the user plane type certificate download method Way;
  • the selected network supports at least the certificate download mode of the user plane type
  • the selected network supports the first access mode of the control plane type and/or supports the first access mode of the user plane type
  • the selected network supports at least the first access mode of the control plane type
  • the selected network supports at least the first access mode of the user plane type.
  • At least the certificate download methods supporting the control plane type include: a certificate downloading method supporting the control plane type, a certificate downloading method supporting the control plane type, and a certificate downloading method supporting the user plane type.
  • At least the certificate downloading methods supporting the user plane type include: a certificate downloading method supporting the user plane type, a certificate downloading method supporting the control plane type, and a certificate downloading method supporting the user plane type.
  • At least the first access mode supporting the control plane type includes: a first access mode supporting the control plane type, a first access mode supporting the control plane type, and a first access mode supporting the user plane type Way.
  • At least the first access mode supporting the user plane type includes: a first access mode supporting the user plane type, a first access mode supporting the control plane type, and a first access mode supporting the user plane type Way.
  • the terminal can be supported to select a network that conforms to its own capability for access.
  • the corresponding method for accessing the network may include:
  • Step 71 The UE sends a registration request message to the first network, where the registration request message includes second information, and the second information is as described in the embodiment of FIG. 2 .
  • Step 72 The CN network element in the first network, such as the AMF, performs a second operation according to the second information and/or the fifth information, such as sending a registration acceptance message to the UE. This second operation is described in the FIG. 3 embodiment.
  • the second information may include the control plane capability of the terminal, for example, the terminal supports the certificate downloading method of the control plane type, or the terminal does not support the certificate downloading method of the control plane type.
  • the registration acceptance message includes type information of the certificate download method, and the type information of the certificate download method is used to indicate the certificate download method of the control plane type or the certificate download method of the user plane type.
  • the registration acceptance message includes third information.
  • the third information is as described in the embodiment of FIG. 3 .
  • the registration acceptance message does not include the third information.
  • Step 73 The UE performs a third operation according to the third information and/or the registration acceptance message. This third operation is described in the FIG. 4 embodiment.
  • the UE may establish a PDU session according to the indication of the user plane type certificate download method or the absence of the control plane type certificate download method indication, and the PDU session is used to download the certificate for accessing the second network.
  • the corresponding network selection process may include:
  • Step 81 The RAN network element (eg, the RAN network element in the first network) broadcasts fourth indication information, where the fourth indication information is as described in the embodiment of FIG. 5 .
  • Step 82 The UE performs an operation of network selection according to the fourth information.
  • the fourth information may include at least one of the following: fourth indication information and capability information of the terminal.
  • the capability information of the terminal is described in the embodiment of FIG. 5 .
  • the SIB broadcast of the RAN network element supports a user plane type certificate download method and/or a control plane type certificate download method.
  • the UE performs network selection according to the SIB broadcast content and the capability information of its own terminal (as described in the embodiment of FIG. 6 ), such as the capability of the control plane type certificate download method and/or the capability of the user plane type certificate download method.
  • the operation is specifically described in the embodiment of FIG. 6 , which is not repeated here.
  • an embodiment of the present application provides a device for accessing a network, which is applied to a first communication device.
  • the device 90 for accessing the network includes:
  • a first execution module 91 configured to execute a first operation according to the first information
  • the first information is used to indicate at least one of the following: the key used for communication between the terminal and the first network can be derived according to the default certificate or the key used for communication between the terminal and the first network cannot be derived according to the default certificate
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate download method of the user plane type or the terminal does not Supports the certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user The first access method of the face type;
  • the first operation includes any one of the following:
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type entry method;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the first execution module 91 is specifically configured to: when at least one of the following conditions is satisfied, determine that the information of the access mode requested by the terminal is the first access mode of the user plane type:
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type
  • the first information indicates that the terminal has a user plane capability
  • the first information indicates that the terminal supports a user plane type certificate download mode
  • the first information indicates that the terminal supports the first access mode of the user plane type.
  • the first execution module 91 is specifically configured to: when the first condition is met, determine that the terminal does not support the certificate downloading method of the control plane type or determine that the terminal does not support the first access method of the control plane type;
  • the first condition includes at least one of the following:
  • the first information indicates that the key for communication between the terminal and the first network cannot be derived according to the default certificate
  • the first information indicates that the terminal does not support the certificate download mode of the control plane type
  • the first information indicates that the terminal does not support the first access mode of the control plane type.
  • the first execution module 91 is specifically configured to: when at least one of the following conditions is satisfied, determine that the information of the access mode requested by the terminal is the first access mode of the control plane type:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type
  • the first information indicates that a key for communication between the terminal and the first network can be derived according to the default certificate
  • the first information indicates that the terminal supports a certificate downloading method of a control plane type
  • the first information indicates that the terminal supports the first access mode of the control plane type.
  • the first execution module 91 is specifically configured to: when the second condition is satisfied, determine that the terminal does not support the certificate download mode of the user plane type or determine that the terminal does not support the first access mode of the user plane type;
  • the second condition includes at least one of the following:
  • the first information indicates that the terminal does not have the capability of the user plane
  • the first information indicates that the terminal does not support the certificate download mode of the user plane type
  • the first information indicates that the terminal does not support the first access mode of the user plane type.
  • the apparatus 90 for accessing the network further includes:
  • a first sending module for sending second information
  • the second information includes at least one of the following: information of an access mode requested by the terminal, capability information of the terminal, and type information of a certificate download mode requested by the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the apparatus 90 for accessing the network further includes:
  • a first receiving module configured to receive third information and/or an access acceptance message;
  • the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, first indication information and second indication information;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type;
  • the certificate The type information of the download method is used to indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type;
  • the first indication information is used to indicate one of the following: the first access using the control plane type
  • the first access method of the control plane type is not used;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and do not use the certificate download method of the control plane type;
  • the first execution module 91 is further configured to: determine whether to execute the third operation according to the third information and/or the access acceptance message;
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network.
  • the first execution module 91 is specifically used for:
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate downloading method of the control plane type is not adopted;
  • the first execution module 91 is specifically used for:
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate download method of a control plane type is adopted.
  • the device 90 for accessing the network can implement each process implemented in the method embodiment shown in FIG. 2 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a second communication device.
  • the apparatus 100 for accessing a network includes:
  • the first obtaining module 101 is configured to obtain second information and/or fifth information; wherein, the second information includes at least one of the following: information of an access mode requested by the terminal, and type information of a certificate download mode requested by the terminal , terminal capability information; the fifth information includes at least one of the following: information about the terminal access mode requested by the sixth communication device, type information of the terminal certificate download mode requested by the sixth communication device, preconfigured terminal access mode information Information about the method and type information of the pre-configured terminal certificate download method;
  • a second execution module 102 configured to execute a second operation according to the second information and/or the fifth information
  • the second operation includes at least one of the following:
  • the type of the first access mode includes one of the following: a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type of the certificate download method includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type ;
  • Send the type information of the determined certificate download mode, and the type information of the certificate download mode is used to indicate one of the following: the certificate download mode of the control plane type, the certificate download mode of the user plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • first indication information is used to indicate one of the following: adopt the first access mode of the control plane type, and not adopt the first access mode of the control plane type;
  • the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • Sending second indication information where the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived according to the default certificate or the key for communication between the terminal and the first network cannot be derived according to the default certificate;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download the certificate for accessing the second network, and the method for downloading the certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the second execution module 102 is specifically configured to:
  • the third condition When the third condition is satisfied, perform at least one of the following: determine that the type of the first access mode is the first access mode of the control plane type, determine that the type of the certificate download mode is the certificate download mode of the control plane type, determine The first indication information indicates that the first access mode of the control plane type is adopted, and it is determined that the second indication information indicates that the certificate download mode of the control plane type is adopted;
  • the third condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type;
  • the information about the terminal access mode requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a control plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the control plane type;
  • the information about the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a control plane type;
  • the type information of the preconfigured terminal certificate download mode includes: the certificate download mode of the control plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the certificate download method of the control plane type, the terminal supports the first access method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal does not support the certificate download method of the user plane type.
  • the terminal In the first access mode, the terminal does not have the capability of the user plane, and the key used for the communication between the terminal and the first network can be derived according to the default certificate;
  • the first network supports a certificate download method of the control plane type
  • the first network supports the first access mode of the control plane type
  • the first network does not support the certificate download method of the user plane type
  • the first network does not support the first access mode of the user plane type.
  • the second execution module 102 is specifically configured to:
  • the fourth condition When the fourth condition is satisfied, perform at least one of the following: determine that the type of the first access mode is the first access mode of the user plane type, determine that the type of the certificate download mode is the certificate download mode of the user plane type, determine The first indication information indicates that the first access mode of the control plane type is not adopted, and it is determined that the second indication information indicates that the certificate download mode of the control plane type is not adopted, and the address information of the configuration server is sent to the terminal, slice information is sent to the terminal, and the terminal is sent to the terminal. send DNN;
  • the fourth condition includes at least one of the following:
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a user plane type;
  • the terminal access mode information requested by the sixth communication device includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the terminal certificate download method requested by the sixth communication device includes: the certificate download method of the user plane type;
  • the information of the preconfigured terminal access mode includes one of the following: a first access mode, a first access mode of a user plane type;
  • the type information of the preconfigured terminal certificate download method includes: the certificate download method of the user plane type;
  • the capability information of the terminal indicates at least one of the following: the terminal supports the first access method of the user plane type, the terminal supports the certificate download method of the user plane type, the terminal does not support the certificate download method of the control plane type, and the terminal does not support the certificate download method of the control plane type.
  • the terminal In the first access mode, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived;
  • the first network supports a user plane type certificate download method
  • the first network supports the first access mode of the user plane type
  • the first network does not support the certificate download method of the control plane type
  • the first network does not support the first access mode of the control plane type.
  • the second execution module 102 is specifically configured to:
  • the first indication information indicates that the first access mode of the control plane type is adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is adopted;
  • the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the second indication information indicates that the certificate download mode of the control plane type is not adopted.
  • the apparatus 100 for accessing the network can implement each process implemented in the method embodiment shown in FIG. 3 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for accessing a network, which is applied to a third communication device.
  • the apparatus 110 for accessing a network includes:
  • the second receiving module 111 is configured to receive third information and/or an access acceptance message, wherein the third information includes at least one of the following: type information of the first access mode, type information of the certificate download mode, 1 indication information and second indication information; wherein, the type information of the first access mode is used to indicate one of the following: the first access mode of the control plane type, the first access mode of the user plane type; the The type information of the certificate download method is used to indicate one of the following: a certificate download method of a control plane type, a certificate download method of a user plane type; the first indication information is used to indicate one of the following: adopt the first connection of the control plane type. The first access method of the control plane type is not used; the second indication information is used to indicate one of the following: adopt the certificate download method of the control plane type, and not adopt the certificate download method of the control plane type;
  • a third execution module 112 configured to determine whether to execute the third operation according to the third information and/or the access acceptance message
  • the third operation includes: requesting the first network to establish a data channel, where the data channel is used to download a certificate for accessing the second network;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the third execution module 112 is specifically configured to:
  • the fifth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the user plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the user plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is not adopted;
  • the third information includes second indication information, and the second indication information indicates that the certificate download method of the control plane type is not adopted;
  • the third execution module 112 is specifically configured to:
  • the sixth condition includes at least one of the following:
  • the third information includes type information of the first access mode, and the type information of the first access mode indicates the first access mode of the control plane type;
  • the third information includes type information of the certificate download method, and the type information of the certificate download method indicates the certificate download method of the control plane type;
  • the third information includes first indication information, and the first indication information indicates that the first access mode of the control plane type is adopted;
  • the third information includes second indication information, and the second indication information indicates that a certificate downloading method of a control plane type is adopted.
  • the apparatus 110 for accessing the network further includes:
  • the second sending module is configured to send second information; wherein, the second information includes at least one of the following: information of an access mode requested by the terminal, and capability information of the terminal.
  • the access mode information requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the capability information of the terminal is used to indicate at least one of the following:
  • the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type;
  • the terminal supports the certificate download method of the user plane type or the terminal does not support the certificate download method of the user plane type;
  • the terminal supports the first access mode of the control plane type or the terminal does not support the first access mode of the control plane type;
  • the terminal supports the first access mode of the user plane type or the terminal does not support the first access mode of the user plane type;
  • the terminal has the capability of the user plane or the terminal does not have the capability of the user plane;
  • the key for communication between the terminal and the first network can be derived from the default certificate, or the key for communication between the terminal and the first network cannot be derived from the default certificate.
  • the device 110 for accessing the network can implement each process implemented in the method embodiment shown in FIG. 4 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fourth communication device.
  • the apparatus 120 for network selection includes:
  • the third sending module 121 is configured to send or broadcast the fourth indication information
  • the fourth indication information is used to indicate any of the following:
  • the network supports the certificate download method of the control plane type or the network does not support the certificate download method of the control plane type;
  • the network supports the certificate download method of the user plane type or the network does not support the certificate download method of the user plane type;
  • the network supports the first access mode of the control plane type or the network does not support the first access mode of the control plane type;
  • the network supports the first access mode of the user plane type or the network does not support the first access mode of the user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the apparatus 120 for network selection can implement each process implemented in the method embodiment shown in FIG. 5 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • an embodiment of the present application provides an apparatus for network selection, which is applied to a fifth communication device.
  • the apparatus 130 for network selection includes:
  • the second obtaining module 131 is configured to obtain fourth indication information
  • a fourth execution module 132 configured to execute an operation of network selection according to the fourth information
  • the fourth information includes at least one of the following: fourth indication information, capability information of the terminal, information of the access mode requested by the terminal, and type information of the certificate download mode requested by the terminal;
  • the fourth indication information is used to indicate any one of the following: the network supports the certificate download method of the control plane type, or the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type, or the network supports the certificate download method of the user plane type.
  • the certificate downloading method of the user plane type is not supported; the network supports the first access method of the control plane type, or the network does not support the first access method of the control plane type; the network supports the first access method of the user plane type, or the network The first access mode of the user plane type is not supported;
  • the capability information of the terminal is used to indicate at least one of the following: the terminal supports the certificate download method of the control plane type or the terminal does not support the certificate download method of the control plane type; the terminal supports the certificate downloader of the user plane type or the terminal does not support The certificate download method of the user plane type; the terminal supports the first access method of the control plane type or the terminal does not support the first access method of the control plane type; the terminal supports the first access method of the user plane type or the terminal does not support the user plane The first access mode of the type; the terminal has the capability of the user plane or the terminal does not have the capability of the user plane; the key used for the communication between the terminal and the first network can be derived according to the default certificate or cannot be derived for the terminal according to the default certificate a key for communication with the first network;
  • the information of the access mode requested by the terminal includes one of the following: a first access mode, a first access mode of a control plane type, and a first access mode of a user plane type;
  • the type information of the certificate download method requested by the terminal includes one of the following: a certificate download method of a control plane type, and a certificate download method of a user plane type;
  • the first access mode includes: an access mode for accessing the first network in order to download a certificate for accessing the second network;
  • the first access mode for the control plane type includes: in order to download a certificate for accessing the second network
  • the access method of accessing the certificate of the second network to access the first network, and the method of downloading the certificate for accessing the second network is the certificate downloading method of the control plane type;
  • the first access method of the user plane type The method includes: an access method for accessing the first network in order to download a certificate for accessing the second network, and the method for downloading a certificate for accessing the second network is a user plane type certificate downloading method;
  • the first A network and the second network are the same network or different networks.
  • the fourth execution module 132 is specifically configured to execute at least one of the following:
  • a network is selected, and the fourth indication information of the selected network conforms to the type information of the certificate download mode requested by the terminal.
  • the fourth indication information of the selected network conforming to the terminal capability information includes at least one of the following:
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network does not support the certificate download method of the user plane type, the network supports the first access method of the control plane type, and the network does not support the certificate download method of the user plane type.
  • the first access mode of the user plane type; and the capability information of the terminal indicates any one of the following: the terminal supports the certificate download method of the control plane type, the terminal does not support the certificate download method of the user plane type, and the terminal supports the control plane type
  • the terminal does not support the first access mode of the user plane type, the terminal does not have the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate;
  • the fourth indication information indicates any one of the following: the network does not support the certificate download method of the control plane type; the network supports the certificate download method of the user plane type; the network does not support the first access method of the control plane type; the network supports the first access mode of the user plane type; and the capability information of the terminal indicates at least one of the following: the terminal does not support the certificate download method of the control plane type, the terminal supports the certificate download method of the user plane type, and the terminal does not support the control plane
  • the first access mode of the type the terminal supports the first access mode of the user plane type, the terminal has the capability of the user plane, and according to the default certificate, the key used for the communication between the terminal and the first network cannot be derived;
  • the fourth indication information indicates any one of the following: the network supports the certificate download method of the control plane type, the network supports the certificate download method of the user plane type, the network supports the first access method of the control plane type, the network supports the user plane type Type of first access method;
  • the capability information of the terminal indicates at least one of the following: the terminal supports a control plane type certificate download method, the terminal supports a user plane type certificate download method, the terminal supports a control plane type first access method, and the terminal supports a user plane type.
  • the terminal In the first access manner, the terminal has the capability of the user plane, and can derive the key used for the communication between the terminal and the first network according to the default certificate.
  • the fourth execution module 132 is specifically used for at least one of the following:
  • the selected network supports a control plane type certificate download method and/or supports a user plane type certificate download method
  • the selected network supports at least the certificate download method of the control plane type
  • the selected network supports at least the certificate download mode of the user plane type
  • the selected network supports the first access mode of the control plane type and/or supports the user plane type the first access method
  • the selected network supports at least the first access mode of the control plane type
  • the selected network supports at least the first access mode of the user plane type.
  • the communication device 130 can implement the various processes implemented in the method embodiment shown in FIG. 6 of the present application, and achieve the same beneficial effects. To avoid repetition, details are not described here.
  • FIG. 14 is a schematic structural diagram of another communication device provided by an embodiment of the present application.
  • the communication device 140 includes: a processor 141 , a memory 142 , and a memory 142 that is stored in the memory 142 and can be The computer program running on the processor, the various components in the communication device 140 are coupled together through the bus interface 143, and the computer program is executed by the processor 141.
  • Each process of the above, or each process implemented in the method embodiment shown in FIG. 6 above is implemented, and the same technical effect can be achieved. To avoid repetition, details are not repeated here.
  • Embodiments of the present application further provide a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, each process implemented in the method embodiment shown in FIG. 5 is implemented, Alternatively, each process implemented in the above method embodiment shown in FIG. 6 is implemented, or each process implemented in the above method embodiment shown in FIG. 7 is implemented, or each process implemented in the above method embodiment shown in FIG. 8 is implemented , or, each process implemented in the method embodiment shown in FIG. 9 is implemented, and the same technical effect can be achieved. To avoid repetition, details are not repeated here.
  • the computer-readable storage medium such as read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk, etc.
  • the method of the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is better implementation.
  • the technical solution of the present application can be embodied in the form of a software product in essence or in a part that contributes to the prior art, and the computer software product is stored in a storage medium (such as ROM/RAM, magnetic disk, CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) execute the methods described in the various embodiments of this application.
  • a storage medium such as ROM/RAM, magnetic disk, CD-ROM

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例提供一种接入网络、网络选择的方法、装置及通信设备,该接入网络的方法包括:根据第一信息,执行第一操作;所述第一操作包括以下任意一项:确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,确定终端支持用户面类型的证书下载方式;确定终端支持控制面类型的第一接入方式;所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。

Description

接入网络、网络选择的方法、装置及通信设备
相关申请的交叉引用
本申请主张在2020年8月19日在中国提交的中国专利申请号No.202010839912.3的优先权,及主张在2020年11月16日在中国提交的中国专利申请号No.202011281217.6的优先权,其全部内容通过引用包含于此。
技术领域
本申请实施例涉及无线通信技术领域,尤其涉及一种接入网络、网络选择的方法、装置及通信设备。
背景技术
目前,终端为了下载用于接入独立非公用网络(Standalone Non-public Network,SNPN)的证书而接入另一网络的方式,可以是控制面类型,也可以是用户面类型。然而此情况下,目前却没有相关方法来支持终端确定证书下载的方式,比如是采用控制面类型还是采用用户面类型。
发明内容
本申请实施例提供一种接入网络、网络选择的方法、装置及通信设备,用于解决如何支持终端确定证书下载的方式的问题。
为了解决上述技术问题,本申请是这样实现的:
第一方面,本申请实施例提供了一种接入网络的方法,应用于第一通信设备,包括:
根据第一信息,执行第一操作;
其中,所述第一信息用于指示以下至少一项:根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;终端具有用户面的能力或终端不具有用户面的能力;终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方 式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
其中,所述第一操作包括以下任意一项:
确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
确定终端请求的证书下载方式的类型信息,其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,
确定终端支持用户面类型的证书下载方式,或确定终端不支持用户面类型的证书下载方式;
确定终端支持控制面类型的第一接入方式,或确定终端不支持控制面类型的第一接入方式;
确定终端支持用户面类型的第一接入方式,或确定终端不支持用户面类型的第一接入方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第二方面,本申请实施例提供了一种接入网络的方法,应用于第二通信设备,包括:
获取第二信息和/或第五信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息、终端的 能力信息;所述第五信息包括以下至少一项:第六通信设备请求的终端接入方式的信息、第六通信设备请求的终端证书下载方式的类型信息、预配置的终端接入方式的信息、预配置的终端证书下载方式的类型信息;
根据所述第二信息和/或第五信息,执行第二操作;
其中,所述第二操作包括以下至少一项:
确定第一接入方式的类型,所述第一接入方式的类型包括以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
确定证书下载方式的类型,所述证书下载方式的类型包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
执行所述确定类型的第一接入方式;
执行所述确定类型的证书下载方式;
发送所述确定的第一接入方式的类型信息,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
发送所述确定的证书下载方式的类型信息,所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
确定第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
发送第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
确定第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
发送第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
其中,所述终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下 载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥,或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第三方面,本申请实施例提供了一种接入网络的方法,应用于第三通信设备,包括:
接收第三信息和/或接入接受消息;其中,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
其中,所述第三操作包括:
向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第四方面,本申请实施例提供了一种网络选择的方法,应用于第四通信设备,包括:
发送或广播第四指示信息;
其中,所述第四指示信息用于指示以下任意一项:
网络支持控制面类型的证书下载方式或网络不支持控制面类型的证书下载方式;
网络支持用户面类型的证书下载方式或网络不支持用户面类型的证书下载方式;
网络支持控制面类型的第一接入方式或网络不支持控制面类型的第一接入方式;
网络支持用户面类型的第一接入方式或网络不支持用户面类型的第一接入方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第五方面,本申请实施例提供了一种网络选择的方法,应用于第五通信设备,包括:
获取第四指示信息;
根据第四信息,执行网络选择的操作;
其中,所述第四信息包括以下至少一项:第四指示信息、终端的能力信息、终端请求的接入方式的信息、终端请求的证书下载方式的类型信息;
其中,所述第四指示信息用于指示以下任意一项:网络支持控制面类型的证书下载方式,或网络不支持控制面类型的证书下载方式;网络支持用户面类型的证书下载方式,或网络不支持用户面类型的证书下载方式;网络支持控制面类型的第一接入方式,或网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式,或网络不支持用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;终端具有用户面的能力或终端不具有用户面的能力;根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式, 且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第六方面,本申请实施例提供了一种接入网络的装置,应用于第一通信设备,包括:
第一执行模块,用于根据第一信息,执行第一操作;
其中,所述第一信息用于指示以下至少一项:根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;终端具有用户面的能力或终端不具有用户面的能力;终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
其中,所述第一操作包括以下任意一项:
确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
确定终端请求的证书下载方式的类型信息,其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,
确定终端支持用户面类型的证书下载方式,或确定终端不支持用户面类型的证书下载方式;
确定终端支持控制面类型的第一接入方式,或确定终端不支持控制面类型的第一接入方式;
确定终端支持用户面类型的第一接入方式,或确定终端不支持用户面类型的第一接入方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接 入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第七方面,本申请实施例提供了一种接入网络的装置,应用于第二通信设备,包括:
第一获取模块,用于获取第二信息和/或第五信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息、终端的能力信息;所述第五信息包括以下至少一项:第六通信设备请求的终端接入方式的信息、第六通信设备请求的终端证书下载方式的类型信息、预配置的终端接入方式的信息、预配置的终端证书下载方式的类型信息;
第二执行模块,用于根据所述第二信息和/或第五信息,执行第二操作;
其中,所述第二操作包括以下至少一项:
确定第一接入方式的类型,所述第一接入方式的类型包括以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
确定证书下载方式的类型,所述证书下载方式的类型包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
执行所述确定类型的第一接入方式;
执行所述确定类型的证书下载方式;
发送所述确定的第一接入方式的类型信息,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
发送所述确定的证书下载方式的类型信息,所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
确定第一指示信息,所述第一指示信息用于指示以下之一:采用控制面 类型的第一接入方式,不采用控制面类型的第一接入方式;
发送第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
确定第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
发送第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
其中,所述终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第八方面,本申请实施例提供了一种接入网络的装置,应用于第三通信 设备,包括:
第二接收模块,用于接收第三信息和/或接入接受消息;其中,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
第三执行模块,用于根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
其中,所述第三操作包括:
向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第九方面,本申请实施例提供了一种网络选择的装置,应用于第四通信设备,包括:
第三发送模块,用于发送或广播第四指示信息;
其中,所述第四指示信息用于指示以下任意一项:
网络支持控制面类型的证书下载方式或网络不支持控制面类型的证书下载方式;
网络支持用户面类型的证书下载方式或网络不支持用户面类型的证书下 载方式;
网络支持控制面类型的第一接入方式或网络不支持控制面类型的第一接入方式;
网络支持用户面类型的第一接入方式或网络不支持用户面类型的第一接入方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第十方面,本申请实施例提供了一种网络选择的装置,应用于第五通信设备,包括:
第二获取模块,用于获取第四指示信息;
第四执行模块,用于根据第四信息,执行网络选择的操作;
其中,所述第四信息包括以下至少一项:第四指示信息、终端的能力信息、终端请求的接入方式的信息、终端请求的证书下载方式的类型信息;
其中,所述第四指示信息用于指示以下任意一项:网络支持控制面类型的证书下载方式,或网络不支持控制面类型的证书下载方式;网络支持用户面类型的证书下载方式,或网络不支持用户面类型的证书下载方式;网络支持控制面类型的第一接入方式,或网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式,或网络不支持用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;终 端具有用户面的能力或终端不具有用户面的能力;根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
第十一方面,本申请实施例提供了一种通信设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现第一方面提供的接入网络的方法的步骤,或者,实现第二方面提供的接入网络的方法的步骤,或者,实现第三方面提供的接入网络的方法的步骤,或者,实现第四方面提供的网络选择的方法的步骤,或者,实现第五方面提供的网络选择的方法的步骤。
第十二方面,本申请实施例提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时实现第一方面提供的接入网络的方法的步骤,或者,实现第二方面提供的接入网络的方法的步骤,或者,实现第三方面提供的接入网络的方法的步骤,或者,实现第四方面提供的网络选择的方法的步骤,或者,实现第五方面提供的网络选择的方法的步骤。
不难理解,通过本申请实施例,可以支持终端确定证书下载的方式,以及支持终端选择符合自身能力的网络进行接入。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本申请的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1为本申请实施例提供的一种无线通信***的架构示意图;
图2为本申请一实施例的接入网络的方法的流程示意图;
图3为本申请另一实施例的接入网络的方法的流程示意图;
图4为本申请又一实施例的接入网络的方法的流程示意图;
图5为本申请又一实施例的网络选择的方法的流程示意图;
图6为本申请又一实施例的网络选择的方法的流程示意图;
图7为本申请具体实施例1的接入网络的方法的流程示意图;
图8为本申请具体实施例1网络选择的方法的流程示意图;
图9为本申请提供的一种接入网络的装置的结构示意图;
图10为本申请提供的另一种接入网络的装置的结构示意图;
图11为本申请提供的另一种接入网络的装置的结构示意图;
图12为本申请提供的一种网络选择的装置的结构示意图;
图13为本申请提供的另一种网络选择的装置的结构示意图;
图14为本申请提供的一种通信设备的结构图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并 不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。
图1示出本申请实施例可应用的一种无线通信***的框图。无线通信***包括终端11和网络侧设备12。其中,终端11可以包括支持终端功能的中继和/或支持中继功能的终端,终端11也可以称作终端设备或者用户终端(User Equipment,UE),终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、移动上网装置(Mobile Internet Device,MID)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、可穿戴式设备(Wearable Device)或车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)等终端侧设备,可穿戴式设备包括:手环、耳机、眼镜等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以是基站或核心网,其中,基站可被称为节点B、演进节点B、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、B节点、演进型B节点(eNB)、家用B节点、家用演进型B节点、WLAN接入点、WiFi节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR***中的基站为例,但是并不限定基站的具体类型。
在一些通信场景中,存在通信设备没有网络的证书却需要接入网络的场景,例如:在独立非公用网络(Standalone Non-public Network,SNPN)部署时,UE可能还没有能够用于接入SNPN的证书和UE标识。比如工厂部署的SNPN和刚在市场上采购的终端,或者在演唱会现场部署的SNPN和观众的终端。
为了让这种类型的UE获取用于接入SNPN的证书和UE标识,UE可以接入某个网络(后续称为第一网络),下载用于接入SNPN的证书。第一网络 可以是所述SNPN。
为了下载用于接入第二网络的证书而接入第一网络的方式可以称为onboarding。第一网络和第二网络可以是同一个网络。
可选的,第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。
比如,下载证书的方式可包括:1)控制面(Control Plane,CP)类型的证书下载方式,第一网络为UE向证书配置服务器下载证书并通过控制面信令发送给UE方式;2)用户面(User Plane,UP)类型的证书下载方式,终端向第一网络建立数据通道,并通过所述数据通道向证书配置服务器下载证书的方式。
对于控制面类型的证书下载方式,需要UE和第一网络都有额外的能力:
1)第一网络能够与配置服务器(Provision Server)交互,代表UE向Provision Server下载证书,所述证书要在默认证书的密钥的保护下发送给UE,比如所述证书被包含在非接入层(Non-Access Stratum,NAS)消息中发送给UE;而所述NAS消息被加密和/或完整性保护。
2)UE和默认证书鉴权服务器(Default Credential Server,DCS)间要能够支持认证之余,还要支持导出用于UE与第一网络间通信的密钥,比如导出K SEAF。这样第一网络和UE就可以导出K SEAF用于加密和/或完整性保护,来保护NAS消息,否则不能采用控制面类型的证书下载方式。
3)UE要能够支持从NAS消息接收证书。
对于用户面类型的证书下载方式,该用户面类型的证书下载方式可以是默认方式:
1)网络可能不需要额外的能力;网络只需要配置策略,限制所述建立的数据通道(如PDU会话(Session))只能连接到Provision Server。
2)UE的与Provision Server间交互的能力可以自设置的,可以不需要告知网络,因为UE与第一网络间交互只要建立数据通道(PDU Session)。
可选的,网络可以默认支持用户面类型的证书下载方式。
可选的,UE可以支持所述控制面类型的证书下载方和/或用户面类型的证书下载方式。
可选的,当UE指示第一接入方式可以暗示支持用户面类型的第一接入方式,和/或,网络的***信息块(system information block,SIB)广播第一接入方式可以暗示支持用户面类型的第一接入方式。网络可以根据UE的控制面类型的证书下载方式的能力决定是否采用控制面类型的第一接入方式,和/或,网络可以根据自己的控制面类型的证书下载方式的能力以及策略配置决定是否采用控制面类型的第一接入方式。
可选的,对同时具有控制面类型的证书下载方式的能力和用户面方式的能力的UE,UE需要从网络获得控制面类型的证书下载方式的指示来决定是否发起数据通道(如PDU会话)建立下载证书。比如,当未获得控制面类型的证书下载方式的指示时,就向第一网络发起数据通道建立下载证书;当获得控制面类型的证书下载方式的指示,可以等着第一网络为UE下载证书。
本申请实施例中,可选的,获取可以理解为从配置获得、接收、通过请求后接收、通过自学习获取、根据未收到的信息推导获取或者是根据接收的信息处理后获得,具体可根据实际需要确定,本申请实施例对此不作限定。比如当未收到设备发送的某个能力指示信息时可推导出该设备不支持该能力。
可选的,发送可以包含广播,***消息中广播,响应请求后返回。
在本申请一种可选实施例中,第一网络可以包括以下之一:非公网(如SNPN,或PNI-SNPN),公网(PLMN)。
在本申请一种可选实施例中,第二网络可以包括以下之一:非公网(如SNPN,或PNI-SNPN),公网(PLMN)。
本申请一种可选实施例中,所述控制面类型的证书下载方式是第一网络的网元通过与证书配置服务器交互,并通过控制面信令(如NAS信令)将所述证书发送给终端的方式。
本申请一种可选实施例中,所述用户面类型的证书下载方式是终端请求第一网络建立数据通道(如PDU会话),通过所述数据通道,终端与证书的配置服务器交互下载证书的方式。终端与证书的配置服务器间交互对第一网络来说都是用户面数据,因此称为用户面类型的证书下载方式。
本申请一种可选实施例中,终端的用户面能力包括以下至少一项:支持向网络请求数据通道(如PDU会话)的建立、会话管理的功能等。
本申请一种可选实施例中,用于接入第二网络的证书包括:第二网络的证书。
在本申请一种实施例中,非公网是非公众网络的简称。非公众网络可以称为以下之一:非公众通信网络。非公网可以包括以下至少一种部署方式:物理的非公网、虚拟的非公网、实现在公网上的非公网。一种实施方式中,非公网为封闭访问组(Closed Access Group,CAG)。一个CAG可以由一组终端组成。
在本申请一种实施例中,非公网服务是非公众网络服务的简称。非公众网络服务也可以称为以下之一:非公众网络的网络服务、非公众通信服务、非公众网络通信服务、非公网的网络服务或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。一种实施方式中,非公网为封闭访问组,此时,非公网服务为封闭的访问组的网络服务。
在本申请一种实施例中,非公众网络可以包含或称为私有网络。私有网络可以称为以下之一:私有通信网络、私网、本地区域网络(LAN)、私有虚拟网络(PVN)、隔离的通信网络、专用的通信网络或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。
在本申请一种实施例中,公网是公众网络的简称。公众网络可以称为以下之一:公众通信网络或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。
本申请一种可选实施例中,鉴权服务包括鉴权服务器(如DCS,或归属AUSF)发起对终端的鉴权请求。鉴权服务网元可以是为终端提供鉴权服务的鉴权代理。可选的,所述鉴权服务网元可以包括但不限于以下之一:AUSF、AAA代理。
本申请一种可选实施例中,通信设备可以包括以下至少一项:通信网元和终端。
本申请一种实施例中,通信网元可以包括以下至少一项:核心网网元和无线接入网网元。
本申请实施例中,核心网网元(CN网元)可以包含但不限于如下至少一项:核心网设备、核心网节点、核心网功能、核心网网元、移动管理实体 (Mobility Management Entity,MME)、接入移动管理功能(Access Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、服务网关(serving GW,SGW)、PDN网关(PDN Gate Way,PDN网关)、策略控制功能(Policy Control Function、PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、GPRS服务支持节点(Serving GPRS Support Node,SGSN)、网关GPRS支持节点(Gateway GPRS Support Node,GGSN)、统一数据管理(Unified Data Management,UDM),统一数据存储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)和应用功能(Application Function,AF)。
本申请实施例中,RAN网元可以包含但不限于至少以下之一:无线接入网设备、无线接入网节点、无线接入网功能、无线接入网单元、3GPP无线接入网、非3GPP无线接入网、集中单元(Centralized Unit,CU)、分布单元(Distributed Unit,DU)、基站、演进型基站(evolved Node B,eNB)、5G基站(gNB)、无线网络控制器(Radio Network Controller,RNC)、基站(NodeB)、非3GPP互操作功能(Non-3GPP Inter Working Function,N3IWF)、接入控制(Access Controller,AC)节点、接入点(Access Point,AP)设备或无线局域网(Wireless Local Area Networks,WLAN)节点、N3IWF。
以下对本申请实施例进行详细说明。
请参考图2,本申请实施例提供了一种接入网络的方法,应用于第一通信设备;该第一通信设备包括但不限于:UE;所述方法包括:
步骤21:根据第一信息,执行第一操作。
可选的,所述第一信息用于指示以下至少一项:根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;终端具有用户面的能力或终端不具有用户面的能力;终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型 的第一接入方式。
可选的,上述用于终端与第一网络间通信的密钥包括但不限于以下至少一项:K SEAF,K AUSF,K AMF,加密密钥,完整性保护密钥。所述用于终端与第一网络间通信的密钥可以导出终端与第一网络间通信数据的加密密钥和/或完整性保护密钥。
可选的,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。
可选的,所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式。
可选的,所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
可选的,所述第一操作包括以下任意一项:
确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
确定终端请求的证书下载方式的类型信息,其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,
确定终端支持用户面类型的证书下载方式,或确定终端不支持用户面类型的证书下载方式;
确定终端支持控制面类型的第一接入方式,或确定终端不支持控制面类型的第一接入方式;
确定终端支持用户面类型的第一接入方式,或确定终端不支持用户面类型的第一接入方式。
本申请实施例中,可选的,上述根据第一信息,执行第一操作的过程可以包括:当满足以下至少一项的情况下,确定终端请求的接入方式的信息为用户面类型的第一接入方式:
所述第一信息指示根据默认证书不能够导出用于终端与第一网络间通信的密钥;
所述第一信息指示终端不支持控制面类型的证书下载方式;
所述第一信息指示终端不支持控制面类型的第一接入方式;
所述第一信息指示终端具有用户面的能力;
所述第一信息指示终端支持用户面类型的证书下载方式;
所述第一信息指示终端支持用户面类型的第一接入方式。
和/或,上述根据第一信息,执行第一操作的过程可以包括:当满足第一条件的情况下,确定终端不支持控制面类型的证书下载方式或确定终端不支持控制面类型的第一接入方式。
其中,所述第一条件包括以下至少一项:
所述第一信息指示根据默认证书不能够导出用于终端与第一网络间通信的密钥;
所述第一信息指示终端不支持控制面类型的证书下载方式;
所述第一信息指示终端不支持控制面类型的第一接入方式。
本申请实施例中,可选的,上述根据第一信息,执行第一操作的过程可以包括:
当满足以下至少一项的情况下,确定终端请求的接入方式的信息为控制面类型的第一接入方式:
所述第一信息指示终端不具有用户面的能力;
所述第一信息指示终端不支持用户面类型的证书下载方式;
所述第一信息指示终端不支持用户面类型的第一接入方式;
所述第一信息指示根据默认证书能够导出用于终端与第一网络间通信的密钥;
所述第一信息指示终端支持控制面类型的证书下载方式;
所述第一信息指示终端支持控制面类型的第一接入方式。
和/或,上述根据第一信息,执行第一操作的过程可以包括:当满足第二条件的情况下,确定终端不支持用户面类型的证书下载方式或确定终端不支持用户面类型的第一接入方式。
其中,所述第二条件包括以下至少一项:
所述第一信息指示终端不具有用户面的能力;
所述第一信息指示终端不支持用户面类型的证书下载方式;
所述第一信息指示终端不支持用户面类型的第一接入方式。
本申请实施例中,可选的,所述方法还可包括:
发送第二信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端的能力信息、终端请求的证书下载方式的类型信息。
可选的,所述终端请求的接入方式信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式。
可选的,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式。
可选的,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
进一步的,上述发送第二信息之后,所述方法还可包括:
接收第三信息和/或接入接受消息;
根据所述第三信息和/或接入接受消息,确定是否执行第三操作。
可选的,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式。
一种实施方式中,所述接入接受消息为终端接入第一网络后获得的接入接受消息,包括但不限于注册接受消息。
可选的,所述第三操作包括:向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书。
进一步的,上述根据第三信息确定是否执行第三操作可以包括:当满足第五条件的情况下,执行所述第三操作。
其中,所述第五条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示用户面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示用户面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示不采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示不采用控制面类型的证书下载方式;
仅收到接入接受信息,或未获取到所述第三信息。
一种实施方式中,当终端和/或第一网络支持第一接入方式的情况下,终端和/或第一网络可以默认支持用户面类型的第一接入方式。
一种实施方式中,当终端和/或第一网络支持第一接入方式的情况下,终端和/或第一网络可以默认支持用户面类型的证书下载方式。
进一步的,上述根据第三信息确定是否执行第三操作可以包括:当满足 第六条件的情况下,不执行所述第三操作。
其中,所述第六条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示控制面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示控制面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示采用控制面类型的证书下载方式。
一种可选的应用场景中,UE和网络都默认支持用户面类型的第一接入方式或用户面类型的证书下载方式,可选支持控制面类型的第一接入方式或控制面类型的证书下载方。
可选的,当UE指示第一接入方式可以暗示支持用户面类型的第一接入方式,和/或,网络的***信息块(system information block,SIB)广播第一接入方式可以暗示支持用户面类型的第一接入方式。网络可以根据UE的控制面类型的证书下载方式的能力决定是否采用控制面类型的第一接入方式,和/或,网络可以根据自己的控制面类型的证书下载方式的能力以及策略配置决定是否采用控制面类型的第一接入方式。
可选的,对同时具有控制面类型的证书下载方式的能力和用户面方式的能力的终端,终端需要从网络获得控制面类型的证书下载方式的指示来决定是否发起数据通道(如PDU会话)建立下载证书。比如,当未获得控制面类型的证书下载方式的指示时,就向第一网络发起数据通道建立下载证书;当获得控制面类型的证书下载方式的指示,可以等着第一网络为UE下载证书。
不难理解,通过本实施例,可以支持终端确定证书下载的方式。
请参考图3,本申请实施例提供了一种接入网络的方法,应用于第二通信设备;该第二通信设备包括但不限于:CN网元(如AMF);所述CN网元可以为第一网络中的通信设备。所述方法包括:
步骤31:获取第二信息和/或第五信息。
可选的,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息、终端的能力信息。
可选的,所述第五信息包括以下至少一项:第六通信设备请求的终端接入方式的信息、第六通信设备请求的终端证书下载方式的类型信息、预配置的终端接入方式的信息、预配置的终端证书下载方式的类型信息。
一种实施方式中,第六通信设备包括但不限于以下之一:AF,UDM,PCF,SMF,AUSF,DCS,配置服务器(如PS)。另一种实施方式中,第六通信设备是证书拥有者中的通信设备。一种实施方式中,所述配置服务器为终端配置证书。所述DCS可以对通过第一接入方式接入网络的终端进行验证和/或认证。
可选的,第六通信设备请求的终端证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式。
可选的,第六通信设备请求的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式。
可选的,预配置的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式。
可选的,预配置的终端证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式。
可选的,所述终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式。
可选的,所述终端请求的终端证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式。
可选的,所述终端的能力信息可以用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
可选的,上述用于终端与第一网络间通信的密钥包括但不限于以下至少一项:K SEAF,K AUSF,K AMF,加密密钥和/或完整性保护密钥。所述用于终端与第一网络间通信的密钥可以导出终端与第一网络间通信数据的加密密钥和/或完整性保护密钥。
不难理解,当根据默认证书不能够导出用于终端与第一网络间通信的密钥时,不能够采用控制面类型的第一接入方式或控制面类型的证书下载方式,因为所述证书在控制面信令中没有加密或者完整性保护,不够安全。而此时,可以采用用户面类型的第一接入方式或用户面类型的证书下载方式。因为用户面类型可以在终端和配置证书的配置服务器的应用层加密。
可选的,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。
可选的,所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式。
可选的,所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
步骤32:根据所述第二信息和/或第五信息,执行第二操作。
可选的,所述第二操作包括以下至少一项:
确定第一接入方式的类型,所述第一接入方式的类型包括以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
确定证书下载方式的类型,所述证书下载方式的类型包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
执行所述确定类型的第一接入方式;
执行所述确定类型的证书下载方式;
发送所述确定的第一接入方式的类型信息,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
发送所述确定的证书下载方式的类型信息,所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
确定第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
发送第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
确定第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
发送第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式。
可选的,上述根据第二信息和/或第五信息,执行第二操作可以包括:当满足第三条件的情况下,执行以下至少一项:确定第一接入方式的类型为控制面类型的第一接入方式,确定证书下载方式的类型为控制面类型的证书下载方式,确定第一指示信息指示采用控制面类型的第一接入方式,确定第二指示信息指示采用控制面类型的证书下载方式。
其中,所述第三条件包括以下至少一项:
终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
第六通信设备请求的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
第六通信设备请求的终端证书下载方式的类型信息包括:控制面类型的证书下载方式;
预配置的终端接入方式的信息包括以下之一:第一接入方式,控制面类 型的第一接入方式;
预配置的终端证书下载方式的类型信息包括:控制面类型的证书下载方式;
终端的能力信息指示以下至少一项:终端支持控制面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端不支持用户面类型的证书下载方式,终端不支持用户面类型的第一接入方式,终端不具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥;
第一网络支持控制面类型的证书下载方式;
第一网络支持控制面类型的第一接入方式;
第一网络不支持用户面类型的证书下载方式;
第一网络不支持用户面类型的第一接入方式。
可选的,上述根据第二信息和/或第五信息,执行第二操作可以包括:当满足第四条件的情况下,执行以下至少一项:确定第一接入方式的类型为用户面类型的第一接入方式,确定证书下载方式的类型为用户面类型的证书下载方式,确定第一指示信息指示不采用控制面类型的第一接入方式,确定第二指示信息指示不采用控制面类型的证书下载方式,向终端发送配置服务器的地址信息,向终端发送切片信息,向终端发送数据网络名称(Data Network Name,DNN)。
一种实施方式中,所述配置服务器可以是为终端配置证书的服务器。一种实施方式中,所述配置服务器的地址信息可以包括用于索引配置服务器地址的信息。
一种实施方式中,所述切片信息可以是用于建立用于用户面通道的切片信息。另一种实施方式中,所述切片信息是用于第一接入方式的切片信息或用于用户面类型的第一接入方式的切片信息。
所述DNN可以是用于建立用于用户面通道的DNN。所述用户面通道可以是用于下载证书的用户面的通道。另一种实施方式中,所述DNN是用于第一接入方式的DNN或用于用户面类型的第一接入方式的DNN。
其中,所述第四条件包括以下至少一项:
终端请求的接入方式信息包括以下之一:第一接入方式,用户面类型的 第一接入方式;
第六通信设备请求的终端接入方式信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
第六通信设备请求的终端证书下载方式的类型信息包括:用户面类型的证书下载方式;
预配置的终端接入方式的信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
预配置的终端证书下载方式的类型信息包括:用户面类型的证书下载方式;
终端的能力信息指示以下至少一项:终端支持用户面类型的第一接入方式,终端支持用户面类型的证书下载方式,终端不支持控制面类型的证书下载方式,终端不支持控制面类型的第一接入方式,终端具有用户面的能力,根据默认证书不能够导出用于终端与第一网络间通信的密钥;
第一网络支持用户面类型的证书下载方式;
第一网络支持用户面类型的第一接入方式;
第一网络不支持控制面类型的证书下载方式;
第一网络不支持控制面类型的第一接入方式。
可选的,上述发送第一指示信息和/或发送第二指示信息的操作可包括:
当确定第一接入方式的类型为控制面类型的第一接入方式,或确定证书下载方式的类型为控制面类型的证书下载方式的情况下,发送第一指示信息和/或发送第二指示信息;其中,所述第一指示信息指示采用控制面类型的第一接入方式;第二指示信息指示采用控制面类型的证书下载方式;
和/或,
当确定第一接入方式的类型为用户面类型的第一接入方式,或确定证书下载方式的类型为用户面类型的证书下载方式的情况下,发送第一指示信息和/或发送第二指示信息;其中,所述第一指示信息指示不采用控制面类型的第一接入方式;第二指示信息指示不采用控制面类型的证书下载方式。
一种实施方式中,第一网络默认支持用户面类型的第一接入方式或用户面类型的证书下载方式;第一网络可选支持控制面类型的第一接入方式或控 制面类型的证书下载方式。此时,可以发送第一指示信息或第二指示信息。
进一步的,当确定第一接入方式的类型为控制面类型的第一接入方式,或确定证书下载方式的类型为控制面类型的证书下载方式的情况下,第一指示信息可以指示采用控制面类型的第一接入方式,第二指示信息可以指示采用控制面类型的证书下载方式。
进一步的,当确定第一接入方式的类型为用户面类型的第一接入方式或确定证书下载方式的类型为用户面类型的证书下载方式的情况下,第一指示信息可以指示不采用控制面类型的第一接入方式,第二指示信息可以指示不采用控制面类型的证书下载方式。
另一种实施方式中,第一网络可选支持用户面类型的第一接入方式和/或控制面类型的第一接入方式。或者,第一网络可选支持用户面类型的证书下载方式和/或控制面类型的证书下载方式。此时,可以发送所述确定的第一接入方式的类型信息,且第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;和/或,发送所述确定的证书下载方式的类型信息,且证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式。
不难理解,通过本实施例,可以支持终端确定证书下载的方式。
请参考图4,本申请实施例提供了一种接入网络的方法,应用于第三通信设备;该第三通信设备包括但不限于:UE;所述方法包括:
步骤41:接收第三信息和/或接入接受信息。
可选的,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式。
一种实施方式中,可以仅接收到接入接受信息,而未接收到第三信息。 另一种实施方式中,可以接收到第三信息和接入接受信息。另一种实施方式中,可以仅接收到第三信息,而未接收到接入接受信息。
一种实施方式中,所述接入接受消息为终端接入第一网络后获得的接入接受消息,包括但不限于注册接受消息。
可选的,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。
可选的,所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式。
可选的,所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
步骤42:根据所述第三信息和/或接入接受信息,确定是否执行第三操作。
可选的,所述第三操作包括:向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书。
可选地,所述接入接受信息为终端被第一网络接受的信息。所述接入接受信息可以通过注册接受消息,服务接受消息体现。
进一步的,上述根据第三信息和/或接入接受信息确定是否执行第三操作可以包括:当满足第五条件的情况下,执行所述第三操作。
其中,所述第五条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示用户面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示用户面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示不采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示不采用控制面类型的证书下载方式;
仅接收到接入接受信息,和/或未接收到所述第三信息。
一种实施方式中,当终端和/或第一网络支持第一接入方式的情况下,终端和/或第一网络可以默认支持用户面类型的第一接入方式。
一种实施方式中,当终端和/或第一网络支持第一接入方式的情况下,终端和/或第一网络可以默认支持用户面类型的证书下载方式。
进一步的,上述根据第三信息确定是否执行第三操作可以包括:当满足第六条件的情况下,不执行所述第三操作。
其中,所述第六条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示控制面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示控制面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示采用控制面类型的证书下载方式。
本申请实施例中,可选的,上述接收第三信息之前,所述方法还可包括:
发送第二信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端的能力信息。
可选的,所述终端请求的接入方式信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式。
可选的,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接 入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
可选的,上述用于终端与第一网络间通信的密钥包括但不限于以下至少一项:K SEAF,K AUSF,K AMF,加密密钥,完整性保护密钥。所述用于终端与第一网络间通信的密钥可以导出终端与第一网络间通信数据的加密密钥和/或完整性保护密钥。
不难理解,通过本实施例,可以支持终端确定证书下载的方式。
请参考图5,本申请实施例提供了一种网络选择的方法,应用于第四通信设备;该第四通信设备包括但不限于:RAN网元;所述RAN网元可以是第一网络中的RAN网元。所述方法包括:
步骤51:发送或广播第四指示信息。
可选的,所述第四指示信息用于指示以下任意一项:
网络支持控制面类型的证书下载方式,或网络不支持控制面类型的证书下载方式;
网络支持用户面类型的证书下载方式,或网络不支持用户面类型的证书下载方式;
网络支持控制面类型的第一接入方式,或网络不支持控制面类型的第一接入方式;
网络支持用户面类型的第一接入方式,或网络不支持用户面类型的第一接入方式。
可选的,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。
可选的,所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式。
可选的,所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的 方式是用户面类型的证书下载方式。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
不难理解,通过本实施例,可以支持终端选择符合自身能力的网络进行接入。
请参考图6,本申请实施例还提供一种网络选择的方法,应用于第五通信设备;该第五通信设备包括但不限于:UE;所述方法包括:
步骤61:获取第四指示信息。
可选的,所述第四指示信息用于指示以下任意一项:
网络支持控制面类型的证书下载方式,或网络不支持控制面类型的证书下载方式;
网络支持用户面类型的证书下载方式,或网络不支持用户面类型的证书下载方式;
网络支持控制面类型的第一接入方式,或网络不支持控制面类型的第一接入方式;
网络支持用户面类型的第一接入方式,或网络不支持用户面类型的第一接入方式。
可选的,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式。
可选的,所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式。
可选的,所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式。
可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。
步骤62:根据第四信息,执行网络选择的操作。
可选的,所述第四信息可以包括以下至少一项:第四指示信息、终端的能力信息、终端请求的接入方式的信息、终端请求的证书下载方式的类型信息。
一种实施方式中,第四通信设备通过配置获得以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息。
可选的,所述终端的能力信息用于指示以下至少一项:终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;终端具有用户面的能力或终端不具有用户面的能力;根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
可选的,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式。
可选的,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式。
可选的,上述用于终端与第一网络间通信的密钥包括但不限于以下至少一项:K SEAF,K AUSF,K AMF,加密密钥,完整性保护密钥。所述用于终端与第一网络间通信的密钥可以导出终端与第一网络间通信数据的加密密钥和/或完整性保护密钥。
可选的,上述根据第四信息执行网络选择的操作可以包括以下至少一项:
选择网络,且所述选择的网络的第四指示信息符合终端的能力信息;
选择网络,且所述选择的网络的第四指示信息符合终端请求的接入方式的信息;
选择网络,且所述选择的网络的第四指示信息符合终端请求的证书下载方式的类型信息。
进一步的,所述选择的网络的第四指示信息符合终端能力信息可以包括以下至少一项:
1)所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络不支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络不支持用户面类型的第一接入方式;且,所述终 端的能力信息指示以下任意一项:终端支持控制面类型的证书下载方式,终端不支持用户面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端不支持用户面类型的第一接入方式,终端不具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥。
由此不难理解,当网络仅支持控制面类型的证书下载方式的情况下,只有支持控制面类型的证书下载方式的终端,或同时支持控制面类型的证书下载方式和/或支持用户面类型的终端,才会选择所述网络。
2)所述第四指示信息指示以下任意一项:网络不支持通过控制面类型的证书下载方式;网络支持通过用户面类型的证书下载方式;网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式;且,所述终端的能力信息指示以下至少一项:终端不支持控制面类型的证书下载方式,终端支持用户面类型的证书下载方式,终端不支持控制面类型的第一接入方式,终端支持用户面类型的第一接入方式,终端具有用户面的能力,根据默认证书不能够导出用于终端与第一网络间通信的密钥。
由此不难理解,当网络仅支持用户面类型的证书下载方式的情况下,只有支持用户面类型的证书下载方式的终端,或同时支持控制面类型的证书下载方式和/或支持用户面类型的终端,才会选择所述网络。
3)所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络支持用户面类型的第一接入方式。
由此不难理解,当网络同时支持控制面类型的证书下载方式和支持用户面类型的证书下载方式的情况下,对支持控制面类型的证书下载方式和/或支持用户面类型的终端,都可以选择所述网络。
4)所述终端的能力信息指示以下至少一项:终端支持控制面类型的证书下载方式,终端支持用户面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端支持用户面类型的第一接入方式,终端具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥。
由此不难理解,当终端同时支持控制面类型的证书下载方式和支持用户面类型的证书下载方式的情况下,选择的网络支持控制面类型的证书下载方 式和/或支持用户面类型的证书下载方式。
进一步的,所述选择的网络的第四指示信息符合终端请求的接入方式的信息可以包括以下至少一项:
1)所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络不支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络不支持用户面类型的第一接入方式;且,所述终端请求的接入方式的信息包括以下任意一项:第一接入方式、控制面类型的第一接入方式。
2)所述第四指示信息指示以下任意一项:网络不支持通过控制面类型的证书下载方式;网络支持通过用户面类型的证书下载方式;网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式;且,所述终端请求的接入方式的信息包括以下任意一项:第一接入方式、用户面类型的第一接入方式。
进一步的,所述选择的网络的第四指示信息符合终端请求的证书下载方式的类型信息可以包括以下至少一项:
1)所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络不支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络不支持用户面类型的第一接入方式;且,所述终端请求的证书下载方式的类型信息包括以下任意一项:控制面类型的证书下载方式。
2)所述第四指示信息指示以下任意一项:网络不支持通过控制面类型的证书下载方式;网络支持通过用户面类型的证书下载方式;网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式;且,所述终端请求的证书下载方式的类型信息包括:用户面类的证书下载方式。
可选的,上述根据第四信息执行网络选择的操作可包括以下至少一项:
(1)当终端同时支持控制面类型的证书下载方式和支持用户面类型的证书下载方式的情况下,所述选择的网络支持控制面类型的证书下载方式和/或支持用户面类型的证书下载方式;
(2)当终端仅支持控制面类型的证书下载方式的情况下,所述选择的网 络至少支持控制面类型的证书下载方式;
(3)当终端仅支持用户面类型的证书下载方式的情况下,所述选择的网络至少支持用户面类型的证书下载方式;
(4)当终端同时支持控制面类型的第一接入方式和支持用户面类型的第一接入方式的情况下,所述选择的网络支持控制面类型的第一接入方式和/或支持用户面类型的第一接入方式;
(5)当终端仅支持控制面类型的第一接入方式的情况下,所述选择的网络至少支持控制面类型的第一接入方式;
(6)当终端仅支持用户面类型的第一接入方式的情况下,所述选择的网络至少支持用户面类型的第一接入方式。
一种实施方式中,至少支持控制面类型的证书下载方式包括:支持控制面类型的证书下载方式,支持控制面类型的证书下载方式和支持用户面类型的证书下载方式。
一种实施方式中,至少支持用户面类型的证书下载方式包括:支持用户面类型的证书下载方式,支持控制面类型的证书下载方式和支持用户面类型的证书下载方式。
一种实施方式中,至少支持控制面类型的第一接入方式包括:支持控制面类型的第一接入方式,支持控制面类型的第一接入方式和支持用户面类型的第一接入方式。
一种实施方式中,至少支持用户面类型的第一接入方式包括:支持用户面类型的第一接入方式,支持控制面类型的第一接入方式和支持用户面类型的第一接入方式。
不难理解,通过本实施例,可以支持终端选择符合自身能力的网络进行接入。
下面结合具体实施例对本申请所提供的方法进行描述。
实施例1
本实施例1中,如图7所示,对应的接入网络的方法过程可以包括:
步骤71:UE向第一网络发起注册请求消息,所述注册请求消息中包含第二信息,该第二信息如图2实施例中所述。
步骤72:第一网络中的CN网元比如AMF根据所述第二信息和/或第五信息,执行第二操作,比如向UE发送注册接受消息。该第二操作如图3实施例中所述。
可选的,UE默认支持用户面类型的证书下载方式时,所述第二信息可以包括终端的控制面能力,比如终端支持控制面类型的证书下载方式,或终端不支持控制面类型的证书下载方式。所述注册接受消息中包括证书下载方式的类型信息,该证书下载方式的类型信息用于指示控制面类型的证书下载方式或用户面类型的证书下载方式。
一种实施方式中,所述注册接受消息中包括第三信息。该第三信息如图3实施例中所述。
另一种实施方式中,所述注册接受消息中不包括第三信息。
步骤73:UE根据第三信息和/或注册接受消息,执行第三操作。该第三操作如图4实施例中所述。
比如,UE可以根据用户面类型的证书下载方式的指示或没有控制面类型的证书下载方式的指示的情况,建立PDU会话,该PDU会话用于下载用于接入第二网络的证书。
实施例2
本实施例2中,如图8所示,对应的网络选择过程可以包括:
步骤81:RAN网元(如第一网络中的RAN网元)广播第四指示信息,该第四指示信息如图5实施例中所述。
步骤82:UE根据第四信息,执行网络选择的操作。可选的,该第四信息可以包括以下至少一项:第四指示信息和终端的能力信息。该终端的能力信息如图5实施例中所述。
比如,RAN网元的SIB广播支持用户面类型的证书下载方式和/或控制面类型的证书下载方式。UE根据SIB广播内容和自身具有的终端的能力信息(如图6实施例所述),比如控制面类型的证书下载方式的能力和/或用户面类型的证书下载方式的能力,进行网络选择的操作,具体如图6实施例所述,此处不再赘述。
请参考图9,本申请实施例提供了一种接入网络的装置,应用于第一通信 设备,如图9所示,该接入网络的装置90包括:
第一执行模块91,用于根据第一信息,执行第一操作;
其中,所述第一信息用于指示以下至少一项:根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;终端具有用户面的能力或终端不具有用户面的能力;终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
其中,所述第一操作包括以下任意一项:
确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
确定终端请求的证书下载方式的类型信息,其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,
确定终端支持用户面类型的证书下载方式,或确定终端不支持用户面类型的证书下载方式;
确定终端支持控制面类型的第一接入方式,或确定终端不支持控制面类型的第一接入方式;
确定终端支持用户面类型的第一接入方式,或确定终端不支持用户面类型的第一接入方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入 方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
可选的,所述第一执行模块91具体用于:当满足以下至少一项的情况下,确定终端请求的接入方式的信息为用户面类型的第一接入方式:
所述第一信息指示根据默认证书不能够导出用于终端与第一网络间通信的密钥;
所述第一信息指示终端不支持控制面类型的证书下载方式;
所述第一信息指示终端不支持控制面类型的第一接入方式;
所述第一信息指示终端具有用户面的能力;
所述第一信息指示终端支持用户面类型的证书下载方式;
所述第一信息指示终端支持用户面类型的第一接入方式。
和/或,所述第一执行模块91具体用于:当满足第一条件的情况下,确定终端不支持控制面类型的证书下载方式或确定终端不支持控制面类型的第一接入方式;
其中,所述第一条件包括以下至少一项:
所述第一信息指示根据默认证书不能够导出用于终端与第一网络间通信的密钥;
所述第一信息指示终端不支持控制面类型的证书下载方式;
所述第一信息指示终端不支持控制面类型的第一接入方式。
可选的,所述第一执行模块91具体用于:当满足以下至少一项的情况下,确定终端请求的接入方式的信息为控制面类型的第一接入方式:
所述第一信息指示终端不具有用户面的能力;
所述第一信息指示终端不支持用户面类型的证书下载方式;
所述第一信息指示终端不支持用户面类型的第一接入方式;
所述第一信息指示根据默认证书能够导出用于终端与第一网络间通信的密钥;
所述第一信息指示终端支持控制面类型的证书下载方式;
所述第一信息指示终端支持控制面类型的第一接入方式。
和/或,所述第一执行模块91具体用于:当满足第二条件的情况下,确定终端不支持用户面类型的证书下载方式或确定终端不支持用户面类型的第一接入方式;
其中,所述第二条件包括以下至少一项:
所述第一信息指示终端不具有用户面的能力;
所述第一信息指示终端不支持用户面类型的证书下载方式;
所述第一信息指示终端不支持用户面类型的第一接入方式。
可选的,所述接入网络的装置90还包括:
第一发送模块,用于发送第二信息;
其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端的能力信息、终端请求的证书下载方式的类型信息。
其中,所述终端请求的接入方式信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
其中,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
可选的,所述接入网络的装置90还包括:
第一接收模块,用于接收第三信息和/或接入接受消息;其中,所述第三 信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
所述第一执行模块91还用于:根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
其中,所述第三操作包括:向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书。
可选的,所述第一执行模块91具体用于:
当满足第五条件的情况下,执行所述第三操作;
其中,所述第五条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示用户面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示用户面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示不采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示不采用控制面类型的证书下载方式;
仅接收到接入接受信息,和/或未接收到所述第三信息。
可选的,所述第一执行模块91具体用于:
当满足第六条件的情况下,不执行所述第三操作;
其中,所述第六条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示控制面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示控制面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示采用控制面类型的证书下载方式。
本实施例中,接入网络的装置90能够实现本申请图2所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图10,本申请实施例提供了一种接入网络的装置,应用于第二通信设备,如图10所示,该接入网络的装置100包括:
第一获取模块101,用于获取第二信息和/或第五信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息、终端的能力信息;所述第五信息包括以下至少一项:第六通信设备请求的终端接入方式的信息、第六通信设备请求的终端证书下载方式的类型信息、预配置的终端接入方式的信息、预配置的终端证书下载方式的类型信息;
第二执行模块102,用于根据所述第二信息和/或第五信息,执行第二操作;
其中,所述第二操作包括以下至少一项:
确定第一接入方式的类型,所述第一接入方式的类型包括以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
确定证书下载方式的类型,所述证书下载方式的类型包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
执行所述确定类型的第一接入方式;
执行所述确定类型的证书下载方式;
发送所述确定的第一接入方式的类型信息,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
发送所述确定的证书下载方式的类型信息,所述证书下载方式的类型信 息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
确定第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
发送第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
确定第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
发送第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
其中,所述终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式, 且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
可选的,所述第二执行模块102具体用于:
当满足第三条件的情况下,执行以下至少一项:确定第一接入方式的类型为控制面类型的第一接入方式,确定证书下载方式的类型为控制面类型的证书下载方式,确定第一指示信息指示采用控制面类型的第一接入方式,确定第二指示信息指示采用控制面类型的证书下载方式;
其中,所述第三条件包括以下至少一项:
终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
第六通信设备请求的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
第六通信设备请求的终端证书下载方式的类型信息包括:控制面类型的证书下载方式;
预配置的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
预配置的终端证书下载方式的类型信息包括:控制面类型的证书下载方式;
终端的能力信息指示以下至少一项:终端支持控制面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端不支持用户面类型的证书下载方式,终端不支持用户面类型的第一接入方式,终端不具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥;
第一网络支持控制面类型的证书下载方式;
第一网络支持控制面类型的第一接入方式;
第一网络不支持用户面类型的证书下载方式;
第一网络不支持用户面类型的第一接入方式。
可选的,所述第二执行模块102具体用于:
当满足第四条件的情况下,执行以下至少一项:确定第一接入方式的类型为用户面类型的第一接入方式,确定证书下载方式的类型为用户面类型的 证书下载方式,确定第一指示信息指示不采用控制面类型的第一接入方式,确定第二指示信息指示不采用控制面类型的证书下载方式,向终端发送配置服务器的地址信息,向终端发送切片信息,向终端发送DNN;
其中,所述第四条件包括以下至少一项:
终端请求的接入方式信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
第六通信设备请求的终端接入方式信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
第六通信设备请求的终端证书下载方式的类型信息包括:用户面类型的证书下载方式;
预配置的终端接入方式的信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
预配置的终端证书下载方式的类型信息包括:用户面类型的证书下载方式;
终端的能力信息指示以下至少一项:终端支持用户面类型的第一接入方式,终端支持用户面类型的证书下载方式,终端不支持控制面类型的证书下载方式,终端不支持控制面类型的第一接入方式,终端具有用户面的能力,根据默认证书不能够导出用于终端与第一网络间通信的密钥;
第一网络支持用户面类型的证书下载方式;
第一网络支持用户面类型的第一接入方式;
第一网络不支持控制面类型的证书下载方式;
第一网络不支持控制面类型的第一接入方式。
可选的,所述第二执行模块102具体用于:
当确定第一接入方式的类型为控制面类型的第一接入方式,或确定证书下载方式的类型为控制面类型的证书下载方式的情况下,发送第一指示信息和/或发送第二指示信息;其中,所述第一指示信息指示采用控制面类型的第一接入方式;第二指示信息指示采用控制面类型的证书下载方式;
和/或,当确定第一接入方式的类型为用户面类型的第一接入方式,或确定证书下载方式的类型为用户面类型的证书下载方式的情况下,发送第一指 示信息和/或发送第二指示信息;其中,所述第一指示信息指示不采用控制面类型的第一接入方式;第二指示信息指示不采用控制面类型的证书下载方式。
本实施例中,接入网络的装置100能够实现本申请图3所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图11,本申请实施例提供了一种接入网络的装置,应用于第三通信设备,如图11所示,该接入网络的装置110包括:
第二接收模块111,用于接收第三信息和/或接入接受消息;其中,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
第三执行模块112,用于根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
其中,所述第三操作包括:向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
可选的,所述第三执行模块112具体用于:
当满足第五条件的情况下,执行所述第三操作;
其中,所述第五条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示用户面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示用户面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示不采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示不采用控制面类型的证书下载方式;
仅接收到所述接入接受信息,和/或未接收到所述第三信息。
可选的,所述第三执行模块112具体用于:
当满足第六条件的情况下,不执行所述第三操作;
其中,所述第六条件包括以下至少一项:
所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示控制面类型的第一接入方式;
所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示控制面类型的证书下载方式;
所述第三信息包括第一指示信息,且所述第一指示信息指示采用控制面类型的第一接入方式;
所述第三信息包括第二指示信息,且所述第二指示信息指示采用控制面类型的证书下载方式。
可选的,所述接入网络的装置110还包括:
第二发送模块,用于发送第二信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端的能力信息。
其中,所述终端请求的接入方式信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:
终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下 载方式;
终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
终端具有用户面的能力或终端不具有用户面的能力;
根据默认证书能够导出用于终端与第一网络间通信的密钥,或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
本实施例中,接入网络的装置110能够实现本申请图4所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图12,本申请实施例提供了一种网络选择的装置,应用于第四通信设备,如图12所示,该网络选择的装置120包括:
第三发送模块121,用于发送或广播第四指示信息;
其中,所述第四指示信息用于指示以下任意一项:
网络支持控制面类型的证书下载方式或网络不支持控制面类型的证书下载方式;
网络支持用户面类型的证书下载方式或网络不支持用户面类型的证书下载方式;
网络支持控制面类型的第一接入方式或网络不支持控制面类型的第一接入方式;
网络支持用户面类型的第一接入方式或网络不支持用户面类型的第一接入方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
本实施例中,网络选择的装置120能够实现本申请图5所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
请参考图13,本申请实施例提供了一种网络选择的装置,应用于第五通信设备,如图13所示,该网络选择的装置130包括:
第二获取模块131,用于获取第四指示信息;
第四执行模块132,用于根据第四信息,执行网络选择的操作;
其中,所述第四信息包括以下至少一项:第四指示信息、终端的能力信息、终端请求的接入方式的信息、终端请求的证书下载方式的类型信息;
其中,所述第四指示信息用于指示以下任意一项:网络支持控制面类型的证书下载方式,或网络不支持控制面类型的证书下载方式;网络支持用户面类型的证书下载方式,或网络不支持用户面类型的证书下载方式;网络支持控制面类型的第一接入方式,或网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式,或网络不支持用户面类型的第一接入方式;
其中,所述终端的能力信息用于指示以下至少一项:终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;终端具有用户面的能力或终端不具有用户面的能力;根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网 络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
可选的,所述第四执行模块132具体用于执行以下至少一项:
选择网络,且所述选择的网络的第四指示信息符合终端的能力信息;
选择网络,且所述选择的网络的第四指示信息符合终端请求的接入方式的信息;
选择网络,且所述选择的网络的第四指示信息符合终端请求的证书下载方式的类型信息。
可选的,所述选择的网络的第四指示信息符合终端能力信息包括以下至少一项:
所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络不支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络不支持用户面类型的第一接入方式;且,所述终端的能力信息指示以下任意一项:终端支持控制面类型的证书下载方式,终端不支持用户面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端不支持用户面类型的第一接入方式,终端不具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥;
所述第四指示信息指示以下任意一项:网络不支持通过控制面类型的证书下载方式;网络支持通过用户面类型的证书下载方式;网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式;且,所述终端的能力信息指示以下至少一项:终端不支持控制面类型的证书下载方式,终端支持用户面类型的证书下载方式,终端不支持控制面类型的第一接入方式,终端支持用户面类型的第一接入方式,终端具有用户面的能力,根据默认证书不能够导出用于终端与第一网络间通信的密钥;
所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络支持用户面类型的第一接入方式;
所述终端的能力信息指示以下至少一项:终端支持控制面类型的证书下载方式,终端支持用户面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端支持用户面类型的第一接入方式,终端具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥。
可选的,所述第四执行模块132具体用于以下至少一项:
当终端同时支持控制面类型的证书下载方式和支持用户面类型的证书下载方式的情况下,所述选择的网络支持控制面类型的证书下载方式和/或支持用户面类型的证书下载方式;
当终端仅支持控制面类型的证书下载方式的情况下,所述选择的网络至少支持控制面类型的证书下载方式;
当终端仅支持用户面类型的证书下载方式的情况下,所述选择的网络至少支持用户面类型的证书下载方式;
当终端同时支持控制面类型的第一接入方式和支持用户面类型的第一接入方式的情况下,所述选择的网络支持控制面类型的第一接入方式和/或支持用户面类型的第一接入方式;
当终端仅支持控制面类型的第一接入方式的情况下,所述选择的网络至少支持控制面类型的第一接入方式;
当终端仅支持用户面类型的第一接入方式的情况下,所述选择的网络至少支持用户面类型的第一接入方式。
本实施例中,通信设备130能够实现本申请图6所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。
参见图14,图14是本申请实施例提供的另一种通信设备的结构示意图,如图14所示,通信设备140包括:处理器141、存储器142及存储在所述存储器142上并可在所述处理器上运行的计算机程序,通信设备140中的各个组件通过总线接口143耦合在一起,所述计算机程序被所述处理器141执行时可实现上述图2所示方法实施例中实现的各个过程,或者,实现上述图3所示方法实施例中实现的各个过程,或者,实现上述图4所示方法实施例中实现的各个过程,或者,实现上述图5所示方法实施例中实现的各个过程,或者,实现上述图6所示方法实施例中实现的各个过程,且能达到相同的技 术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现上述图5所示方法实施例中实现的各个过程,或者,实现上述图6所示方法实施例中实现的各个过程,或者,实现上述图7所示方法实施例中实现的各个过程,或者,实现上述图8所示方法实施例中实现的各个过程,或者,实现上述图9所示方法实施例中实现的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。其中,所述的计算机可读存储介质,如只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (30)

  1. 一种接入网络的方法,应用于第一通信设备,包括:
    根据第一信息,执行第一操作;
    其中,所述第一信息用于指示以下至少一项:根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;终端具有用户面的能力或终端不具有用户面的能力;终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
    其中,所述第一操作包括以下任意一项:
    确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
    确定终端请求的证书下载方式的类型信息,其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
    确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,
    确定终端支持用户面类型的证书下载方式,或确定终端不支持用户面类型的证书下载方式;
    确定终端支持控制面类型的第一接入方式,或确定终端不支持控制面类型的第一接入方式;
    确定终端支持用户面类型的第一接入方式,或确定终端不支持用户面类型的第一接入方式;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用 于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  2. 根据权利要求1所述的方法,其中,所述根据第一信息,执行第一操作,包括:
    当满足以下至少一项的情况下,确定终端请求的接入方式的信息为用户面类型的第一接入方式:
    所述第一信息指示根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    所述第一信息指示终端不支持控制面类型的证书下载方式;
    所述第一信息指示终端不支持控制面类型的第一接入方式;
    所述第一信息指示终端具有用户面的能力;
    所述第一信息指示终端支持用户面类型的证书下载方式;
    所述第一信息指示终端支持用户面类型的第一接入方式;
    和/或,
    当满足第一条件的情况下,确定终端不支持控制面类型的证书下载方式或确定终端不支持控制面类型的第一接入方式;
    其中,所述第一条件包括以下至少一项:
    所述第一信息指示根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    所述第一信息指示终端不支持控制面类型的证书下载方式;
    所述第一信息指示终端不支持控制面类型的第一接入方式。
  3. 根据权利要求1所述的方法,其中,所述根据第一信息,执行第一操作,包括:
    当满足以下至少一项的情况下,确定终端请求的接入方式的信息为控制面类型的第一接入方式:
    所述第一信息指示终端不具有用户面的能力;
    所述第一信息指示终端不支持用户面类型的证书下载方式;
    所述第一信息指示终端不支持用户面类型的第一接入方式;
    所述第一信息指示根据默认证书能够导出用于终端与第一网络间通信的密钥;
    所述第一信息指示终端支持控制面类型的证书下载方式;
    所述第一信息指示终端支持控制面类型的第一接入方式;
    和/或,
    当满足第二条件的情况下,确定终端不支持用户面类型的证书下载方式或确定终端不支持用户面类型的第一接入方式;
    其中,所述第二条件包括以下至少一项:
    所述第一信息指示终端不具有用户面的能力;
    所述第一信息指示终端不支持用户面类型的证书下载方式;
    所述第一信息指示终端不支持用户面类型的第一接入方式。
  4. 根据权利要求1所述的方法,还包括:
    发送第二信息;
    其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端的能力信息、终端请求的证书下载方式的类型信息;
    其中,所述终端请求的接入方式信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
    其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
    其中,所述终端的能力信息用于指示以下至少一项:
    终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
    终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
    终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
    终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接 入方式;
    终端具有用户面的能力或终端不具有用户面的能力;
    根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
  5. 根据权利要求4所述的方法,其中,所述发送第二信息的步骤之后,所述方法还包括:
    接收第三信息和/或接入接受消息;其中,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
    其中,所述第三操作包括:
    向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书。
  6. 根据权利要求5所述的方法,其中,所述根据所述第三信息,确定是否执行第三操作包括:
    当满足第五条件的情况下,执行所述第三操作;
    其中,所述第五条件包括以下至少一项:
    所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示用户面类型的第一接入方式;
    所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示用户面类型的证书下载方式;
    所述第三信息包括第一指示信息,且所述第一指示信息指示不采用控制面类型的第一接入方式;
    所述第三信息包括第二指示信息,且所述第二指示信息指示不采用控制面类型的证书下载方式;
    仅接收到接入接受信息,和/或未接收到所述第三信息。
  7. 根据权利要求5所述的方法,其中,所述根据所述第三信息,确定是否执行第三操作包括:
    当满足第六条件的情况下,不执行所述第三操作;
    其中,所述第六条件包括以下至少一项:
    所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示控制面类型的第一接入方式;
    所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示控制面类型的证书下载方式;
    所述第三信息包括第一指示信息,且所述第一指示信息指示采用控制面类型的第一接入方式;
    所述第三信息包括第二指示信息,且所述第二指示信息指示采用控制面类型的证书下载方式。
  8. 一种接入网络的方法,应用于第二通信设备,包括:
    获取第二信息和/或第五信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息、终端的能力信息;所述第五信息包括以下至少一项:第六通信设备请求的终端接入方式的信息、第六通信设备请求的终端证书下载方式的类型信息、预配置的终端接入方式的信息、预配置的终端证书下载方式的类型信息;
    根据所述第二信息和/或第五信息,执行第二操作;
    其中,所述第二操作包括以下至少一项:
    确定第一接入方式的类型,所述第一接入方式的类型包括以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
    确定证书下载方式的类型,所述证书下载方式的类型包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
    执行所述确定类型的第一接入方式;
    执行所述确定类型的证书下载方式;
    发送所述确定的第一接入方式的类型信息,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
    发送所述确定的证书下载方式的类型信息,所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
    确定第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
    发送第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
    确定第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    发送第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    其中,所述终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式;
    其中,所述终端的能力信息用于指示以下至少一项:
    终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
    终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
    终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
    终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
    终端具有用户面的能力或终端不具有用户面的能力;
    根据默认证书能够导出用于终端与第一网络间通信的密钥,或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接 入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  9. 根据权利要求8所述的方法,其中,所述根据所述第二信息和/或第五信息,执行第二操作,包括:
    当满足第三条件的情况下,执行以下至少一项:确定第一接入方式的类型为控制面类型的第一接入方式,确定证书下载方式的类型为控制面类型的证书下载方式,确定第一指示信息指示采用控制面类型的第一接入方式,确定第二指示信息指示采用控制面类型的证书下载方式;
    其中,所述第三条件包括以下至少一项:
    终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
    第六通信设备请求的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
    第六通信设备请求的终端证书下载方式的类型信息包括:控制面类型的证书下载方式;
    预配置的终端接入方式的信息包括以下之一:第一接入方式,控制面类型的第一接入方式;
    预配置的终端证书下载方式的类型信息包括:控制面类型的证书下载方式;
    终端的能力信息指示以下至少一项:终端支持控制面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端不支持用户面类型的证书下载方式,终端不支持用户面类型的第一接入方式,终端不具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥;
    第一网络支持控制面类型的证书下载方式;
    第一网络支持控制面类型的第一接入方式;
    第一网络不支持用户面类型的证书下载方式;
    第一网络不支持用户面类型的第一接入方式。
  10. 根据权利要求8所述的方法,其中,所述根据所述第二信息和/或第五信息,执行第二操作,包括:
    当满足第四条件的情况下,执行以下至少一项:确定第一接入方式的类型为用户面类型的第一接入方式,确定证书下载方式的类型为用户面类型的证书下载方式,确定第一指示信息指示不采用控制面类型的第一接入方式,确定第二指示信息指示不采用控制面类型的证书下载方式,向终端发送配置服务器的地址信息,向终端发送切片信息,向终端发送数据网络名称DNN;
    其中,所述第四条件包括以下至少一项:
    终端请求的接入方式信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
    第六通信设备请求的终端接入方式信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
    第六通信设备请求的终端证书下载方式的类型信息包括:用户面类型的证书下载方式;
    预配置的终端接入方式的信息包括以下之一:第一接入方式,用户面类型的第一接入方式;
    预配置的终端证书下载方式的类型信息包括:用户面类型的证书下载方式;
    终端的能力信息指示以下至少一项:终端支持用户面类型的第一接入方式,终端支持用户面类型的证书下载方式,终端不支持控制面类型的证书下载方式,终端不支持控制面类型的第一接入方式,终端具有用户面的能力,根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    第一网络支持用户面类型的证书下载方式;
    第一网络支持用户面类型的第一接入方式;
    第一网络不支持控制面类型的证书下载方式;
    第一网络不支持控制面类型的第一接入方式。
  11. 根据权利要求8所述的方法,其中,所述发送第一指示信息和/或发 送第二指示信息的操作包括:
    当确定第一接入方式的类型为控制面类型的第一接入方式,或确定证书下载方式的类型为控制面类型的证书下载方式的情况下,发送第一指示信息和/或发送第二指示信息;其中,所述第一指示信息指示采用控制面类型的第一接入方式;第二指示信息指示采用控制面类型的证书下载方式;
    和/或,
    当确定第一接入方式的类型为用户面类型的第一接入方式,或确定证书下载方式的类型为用户面类型的证书下载方式的情况下,发送第一指示信息和/或发送第二指示信息;其中,所述第一指示信息指示不采用控制面类型的第一接入方式;第二指示信息指示不采用控制面类型的证书下载方式。
  12. 一种接入网络的方法,应用于第三通信设备,包括:
    接收第三信息和/或接入接受消息;其中,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
    其中,所述第三操作包括:向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述 第一网络和所述第二网络是同一个网络或者不同的网络。
  13. 根据权利要求12所述的方法,其中,所述根据所述第三信息和/或接入接受消息,确定是否执行第三操作包括:
    当满足第五条件的情况下,执行所述第三操作;
    其中,所述第五条件包括以下至少一项:
    所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示用户面类型的第一接入方式;
    所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示用户面类型的证书下载方式;
    所述第三信息包括第一指示信息,且所述第一指示信息指示不采用控制面类型的第一接入方式;
    所述第三信息包括第二指示信息,且所述第二指示信息指示不采用控制面类型的证书下载方式;
    仅接收到所述接入接受信息,和/或未接收到所述第三信息。
  14. 根据权利要求12所述的方法,其中,所述根据所述第三信息,确定是否执行第三操作包括:
    当满足第六条件的情况下,不执行所述第三操作;
    其中,所述第六条件包括以下至少一项:
    所述第三信息包括第一接入方式的类型信息,且所述第一接入方式的类型信息指示控制面类型的第一接入方式;
    所述第三信息包括证书下载方式的类型信息,且所述证书下载方式的类型信息指示控制面类型的证书下载方式;
    所述第三信息包括第一指示信息,且所述第一指示信息指示采用控制面类型的第一接入方式;
    所述第三信息包括第二指示信息,且所述第二指示信息指示采用控制面类型的证书下载方式。
  15. 根据权利要求12所述的方法,其中,所述接收第三信息的步骤之前,所述方法还包括:
    发送第二信息;
    其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端的能力信息;
    其中,所述终端请求的接入方式信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
    其中,所述终端的能力信息用于指示以下至少一项:
    终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;
    终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
    终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
    终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
    终端具有用户面的能力或终端不具有用户面的能力;
    根据默认证书能够导出用于终端与第一网络间通信的密钥,或根据默认证书不能够导出用于终端与第一网络间通信的密钥。
  16. 一种网络选择的方法,应用于第四通信设备,包括:
    发送或广播第四指示信息;
    其中,所述第四指示信息用于指示以下任意一项:
    网络支持控制面类型的证书下载方式或网络不支持控制面类型的证书下载方式;
    网络支持用户面类型的证书下载方式或网络不支持用户面类型的证书下载方式;
    网络支持控制面类型的第一接入方式或网络不支持控制面类型的第一接入方式;
    网络支持用户面类型的第一接入方式或网络不支持用户面类型的第一接入方式;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用 于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  17. 一种网络选择的方法,应用于第五通信设备,包括:
    获取第四指示信息;
    根据第四信息,执行网络选择的操作;
    其中,所述第四信息包括以下至少一项:第四指示信息、终端的能力信息、终端请求的接入方式的信息、终端请求的证书下载方式的类型信息;
    其中,所述第四指示信息用于指示以下任意一项:网络支持控制面类型的证书下载方式或网络不支持控制面类型的证书下载方式;网络支持用户面类型的证书下载方式或网络不支持用户面类型的证书下载方式;网络支持控制面类型的第一接入方式或网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式或网络不支持用户面类型的第一接入方式;
    其中,所述终端的能力信息用于指示以下至少一项:终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;终端具有用户面的能力或终端不具有用户面的能力;根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
    其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用 于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  18. 根据权利要求17所述的方法,其中,所述根据第四信息,执行网络选择的操作包括以下至少一项:
    选择网络,且所述选择的网络的第四指示信息符合终端的能力信息;
    选择网络,且所述选择的网络的第四指示信息符合终端请求的接入方式的信息;
    选择网络,且所述选择的网络的第四指示信息符合终端请求的证书下载方式的类型信息。
  19. 根据权利要求18所述的方法,其中,所述选择的网络的第四指示信息符合终端能力信息包括以下至少一项:
    所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书下载方式,网络不支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络不支持用户面类型的第一接入方式;且,所述终端的能力信息指示以下任意一项:终端支持控制面类型的证书下载方式,终端不支持用户面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端不支持用户面类型的第一接入方式,终端不具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥;
    所述第四指示信息指示以下任意一项:网络不支持通过控制面类型的证书下载方式;网络支持通过用户面类型的证书下载方式;网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式;且,所述终端的能力信息指示以下至少一项:终端不支持控制面类型的证书下载方式,终端支持用户面类型的证书下载方式,终端不支持控制面类型的第一接入方式,终端支持用户面类型的第一接入方式,终端具有用户面的能力,根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    所述第四指示信息指示以下任意一项:网络支持通过控制面类型的证书 下载方式,网络支持通过用户面类型的证书下载方式,网络支持控制面类型的第一接入方式,网络支持用户面类型的第一接入方式;
    所述终端的能力信息指示以下至少一项:终端支持控制面类型的证书下载方式,终端支持用户面类型的证书下载方式,终端支持控制面类型的第一接入方式,终端支持用户面类型的第一接入方式,终端具有用户面的能力,根据默认证书能够导出用于终端与第一网络间通信的密钥。
  20. 根据权利要求17所述的方法,其中,所述根据第四信息,执行网络选择的操作包括以下至少一项:
    当终端同时支持控制面类型的证书下载方式和支持用户面类型的证书下载方式的情况下,所述选择的网络支持控制面类型的证书下载方式和/或支持用户面类型的证书下载方式;
    当终端仅支持控制面类型的证书下载方式的情况下,所述选择的网络至少支持控制面类型的证书下载方式;
    当终端仅支持用户面类型的证书下载方式的情况下,所述选择的网络至少支持用户面类型的证书下载方式;
    当终端同时支持控制面类型的第一接入方式和支持用户面类型的第一接入方式的情况下,所述选择的网络支持控制面类型的第一接入方式和/或支持用户面类型的第一接入方式;
    当终端仅支持控制面类型的第一接入方式的情况下,所述选择的网络至少支持控制面类型的第一接入方式;
    当终端仅支持用户面类型的第一接入方式的情况下,所述选择的网络至少支持用户面类型的第一接入方式。
  21. 一种接入网络的装置,应用于第一通信设备,包括:
    第一执行模块,用于根据第一信息,执行第一操作;
    其中,所述第一信息用于指示以下至少一项:根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;终端具有用户面的能力或终端不具有用户面的能力;终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方 式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
    其中,所述第一操作包括以下任意一项:
    确定终端请求的接入方式的信息,其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
    确定终端请求的证书下载方式的类型信息,其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
    确定终端支持控制面类型的证书下载方式,或确定终端不支持控制面类型的证书下载方式,
    确定终端支持用户面类型的证书下载方式,或确定终端不支持用户面类型的证书下载方式;
    确定终端支持控制面类型的第一接入方式,或确定终端不支持控制面类型的第一接入方式;
    确定终端支持用户面类型的第一接入方式,或确定终端不支持用户面类型的第一接入方式;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  22. 一种接入网络的装置,应用于第二通信设备,包括:
    第一获取模块,用于获取第二信息和/或第五信息;其中,所述第二信息包括以下至少一项:终端请求的接入方式的信息、终端请求的证书下载方式的类型信息、终端的能力信息;所述第五信息包括以下至少一项:第六通信 设备请求的终端接入方式的信息、第六通信设备请求的终端证书下载方式的类型信息、预配置的终端接入方式的信息、预配置的终端证书下载方式的类型信息;
    第二执行模块,用于根据所述第二信息和/或第五信息,执行第二操作;
    其中,所述第二操作包括以下至少一项:
    确定第一接入方式的类型,所述第一接入方式的类型包括以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
    确定证书下载方式的类型,所述证书下载方式的类型包括以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
    执行所述确定类型的第一接入方式;
    执行所述确定类型的证书下载方式;
    发送所述确定的第一接入方式的类型信息,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;
    发送所述确定的证书下载方式的类型信息,所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;
    确定第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
    发送第一指示信息,所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;
    确定第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    发送第二指示信息,所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    其中,所述终端请求的接入方式信息包括以下之一:第一接入方式,控制面类型的第一接入方式,用户面类型的第一接入方式;
    其中,所述终端的能力信息用于指示以下至少一项:
    终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下 载方式;
    终端支持用户面类型的证书下载方式或终端不支持用户面类型的证书下载方式;
    终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;
    终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;
    终端具有用户面的能力或终端不具有用户面的能力;
    根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  23. 一种接入网络的装置,应用于第三通信设备,包括:
    第二接收模块,用于接收第三信息和/或接入接受消息;其中,所述第三信息包括以下至少一项:第一接入方式的类型信息、证书下载方式的类型信息、第一指示信息、第二指示信息;其中,所述第一接入方式的类型信息用于指示以下之一:控制面类型的第一接入方式,用户面类型的第一接入方式;所述证书下载方式的类型信息用于指示以下之一:控制面类型的证书下载方式,用户面类型的证书下载方式;所述第一指示信息用于指示以下之一:采用控制面类型的第一接入方式,不采用控制面类型的第一接入方式;所述第二指示信息用于指示以下之一:采用控制面类型的证书下载方式,不采用控制面类型的证书下载方式;
    第三执行模块,用于根据所述第三信息和/或接入接受消息,确定是否执行第三操作;
    其中,所述第三操作包括:
    向第一网络请求建立数据通道,所述数据通道用于下载用于接入第二网络的证书;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  24. 一种网络选择的装置,应用于第四通信设备,包括:
    第三发送模块,用于发送或广播第四指示信息;
    其中,所述第四指示信息用于指示以下任意一项:
    网络支持控制面类型的证书下载方式或网络不支持控制面类型的证书下载方式;
    网络支持用户面类型的证书下载方式或网络不支持用户面类型的证书下载方式;
    网络支持控制面类型的第一接入方式或网络不支持控制面类型的第一接入方式;
    网络支持用户面类型的第一接入方式或网络不支持用户面类型的第一接入方式;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  25. 一种网络选择的装置,应用于第五通信设备,包括:
    第二获取模块,用于获取第四指示信息;
    第四执行模块,用于根据第四信息,执行网络选择的操作;
    其中,所述第四信息包括以下至少一项:第四指示信息、终端的能力信息、终端请求的接入方式的信息、终端请求的证书下载方式的类型信息;
    其中,所述第四指示信息用于指示以下任意一项:网络支持控制面类型的证书下载方式,或网络不支持控制面类型的证书下载方式;网络支持用户面类型的证书下载方式,或网络不支持用户面类型的证书下载方式;网络支持控制面类型的第一接入方式,或网络不支持控制面类型的第一接入方式;网络支持用户面类型的第一接入方式,或网络不支持用户面类型的第一接入方式;
    其中,所述终端的能力信息用于指示以下至少一项:终端支持控制面类型的证书下载方式或终端不支持控制面类型的证书下载方式;终端支持用户面类型的证书下载方或终端不支持用户面类型的证书下载方式;终端支持控制面类型的第一接入方式或终端不支持控制面类型的第一接入方式;终端支持用户面类型的第一接入方式或终端不支持用户面类型的第一接入方式;终端具有用户面的能力或终端不具有用户面的能力;根据默认证书能够导出用于终端与第一网络间通信的密钥或根据默认证书不能够导出用于终端与第一网络间通信的密钥;
    其中,所述终端请求的接入方式的信息包括以下之一:第一接入方式、控制面类型的第一接入方式、用户面类型的第一接入方式;
    其中,所述终端请求的证书下载方式的类型信息包括以下之一:控制面类型的证书下载方式、用户面类型的证书下载方式;
    其中,所述第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式;所述控制面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是控制面类型的证书下载方式;所述用户面类型的第一接入方式包括:为了下载用于接入第二网络的证书而接入第一网络的接入方式,且下载用于接入第二网络的证书的方式是用户面类型的证书下载方式;所述第一网络和所述第二网络是同一个网络或者不同的网络。
  26. 一种通信设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如权利要求1至7中任一项所述的接入网络的方法的步骤,或者,实现如权利要求8至11中任一项所述的接入网络的方法的步骤,或者,实现如权利要求12至15中任一项所述的接入网络的方法的步骤,或者,实现如权利要求16所述的网络选择的方法的步骤,或者,实现如权利要求17至20中任一项所述的网络选择的方法的步骤。
  27. 一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求1至7中任一项所述的接入网络的方法的步骤,或者,实现如权利要求8至11中任一项所述的接入网络的方法的步骤,或者,实现如权利要求12至15中任一项所述的接入网络的方法的步骤,或者,实现如权利要求16所述的网络选择的方法的步骤,或者,实现如权利要求17至20中任一项所述的网络选择的方法的步骤。
  28. 一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如权利要求1至7中任一项所述的接入网络的方法的步骤,或者,实现如权利要求8至11中任一项所述的接入网络的方法的步骤,或者,实现如权利要求12至15中任一项所述的接入网络的方法的步骤,或者,实现如权利要求16所述的网络选择的方法的步骤,或者,实现如权利要求17至20中任一项所述的网络选择的方法的步骤。
  29. 一种程序产品,所述程序产品被至少一个处理器执行以实现如权利要求1至7中任一项所述的接入网络的方法的步骤,或者,实现如权利要求8至11中任一项所述的接入网络的方法的步骤,或者,实现如权利要求12至15中任一项所述的接入网络的方法的步骤,或者,实现如权利要求16所述的网络选择的方法的步骤,或者,实现如权利要求17至20中任一项所述的网络选择的方法的步骤。
  30. 一种通信设备,被配置成用于执行如权利要求1至7中任一项所述的接入网络的方法的步骤,或者,实现如权利要求8至11中任一项所述的接入网络的方法的步骤,或者,实现如权利要求12至15中任一项所述的接入 网络的方法的步骤,或者,实现如权利要求16所述的网络选择的方法的步骤,或者,实现如权利要求17至20中任一项所述的网络选择的方法的步骤。
PCT/CN2021/113248 2020-08-19 2021-08-18 接入网络、网络选择的方法、装置及通信设备 WO2022037611A1 (zh)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CN202010839912.3 2020-08-19
CN202010839912 2020-08-19
CN202011281217.6A CN114173333A (zh) 2020-08-19 2020-11-16 接入网络、网络选择的方法、装置及通信设备
CN202011281217.6 2020-11-16

Publications (1)

Publication Number Publication Date
WO2022037611A1 true WO2022037611A1 (zh) 2022-02-24

Family

ID=80322564

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/113248 WO2022037611A1 (zh) 2020-08-19 2021-08-18 接入网络、网络选择的方法、装置及通信设备

Country Status (1)

Country Link
WO (1) WO2022037611A1 (zh)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110753346A (zh) * 2019-10-30 2020-02-04 北京微智信业科技有限公司 移动通信专网密钥生成方法、装置及控制器
WO2020068765A1 (en) * 2018-09-27 2020-04-02 Convida Wireless, Llc 3gpp private lans
US20200245235A1 (en) * 2019-01-24 2020-07-30 Lg Electronics Inc. Method for selecting non-public network in wireless communication system and apparatus thereof

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020068765A1 (en) * 2018-09-27 2020-04-02 Convida Wireless, Llc 3gpp private lans
US20200245235A1 (en) * 2019-01-24 2020-07-30 Lg Electronics Inc. Method for selecting non-public network in wireless communication system and apparatus thereof
CN110753346A (zh) * 2019-10-30 2020-02-04 北京微智信业科技有限公司 移动通信专网密钥生成方法、装置及控制器

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhanced support of non-public networks (Release 17)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 23.700-07, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.4.0, 19 June 2020 (2020-06-19), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , pages 1 - 158, XP051924077 *
HUAWEI, HISILICON: "KI #4, Sol #27: update the UP or CP decision", 3GPP DRAFT; S2-2005624, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20200819 - 20200901, 13 August 2020 (2020-08-13), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051920436 *

Similar Documents

Publication Publication Date Title
US9526119B2 (en) Methods and apparatus for multiple data packet connections
WO2018161796A1 (zh) 多接入场景中的连接处理方法和装置
WO2020224622A1 (zh) 一种信息配置方法及装置
CN113260016B (zh) 多模终端接入控制方法、装置、电子设备及存储介质
WO2013016968A1 (zh) 一种接入方法、***及移动智能接入点
WO2018006306A1 (zh) 一种网络连接配置方法及装置
JP2021513825A (ja) Sscモードを決定するための方法および装置
CN115380622A (zh) 重定位接入网关
WO2023124457A1 (zh) 选择网络的方法和装置
WO2018058365A1 (zh) 一种网络接入授权方法、相关设备及***
WO2020147833A1 (zh) 支持ue关联的方法及通信设备
WO2018170703A1 (zh) 一种连接建立方法及装置
EP4055857A1 (en) Registering with a mobile network through another mobile network
US20220116769A1 (en) Notification in eap procedure
CN115362754A (zh) 重定位接入网关
WO2022037611A1 (zh) 接入网络、网络选择的方法、装置及通信设备
CN114173333A (zh) 接入网络、网络选择的方法、装置及通信设备
WO2017129101A1 (zh) 路由控制方法、装置及***
WO2022048265A1 (zh) 一种应用层密钥确定的方法、终端、网络侧设备及装置
CN114071465A (zh) 接入控制方法、装置及通信设备
WO2022166892A1 (zh) 信息处理方法、装置、通信设备及可读存储介质
WO2022022739A1 (zh) 接入控制方法、装置及通信设备
US20230017260A1 (en) Access control method and communications device
WO2022022738A1 (zh) 信息配置方法、装置及通信设备
WO2021208857A1 (zh) 接入控制方法及通信设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21857703

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21857703

Country of ref document: EP

Kind code of ref document: A1