Online signing method, device and system
Through the access network equipment, the terminal equipment selects O-SNPN and terminal type information for online contracting according to its own type matching, solving the problem of misjudgment in the prior art and achieving higher accuracy and security.
Patent Information
- Application Number
- CN202010629029.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-02
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2040-07-02
AI Technical Summary
When terminal devices choose independent non-public networks (SNPNs) that can provide online contracting services, there are misjudgments and inaccuracies in the prior art, resulting in online contracting failure.
The access network device sends information indicating the supported O-SNPN and its corresponding terminal type. The terminal device selects O-SNPN according to its own type matching for online contracts, and uses the terminal type as stable information to improve selection accuracy.
Improve the accuracy of terminal equipment selection of O-SNPN, ensuring the success rate and security of the online contracting process.
Smart Images

Figure CN113965334B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this application relate to the field of communication technologies, and in particular, to an online subscription method, apparatus, and system. Background Art
[0002] In a communication system, before a terminal device accesses a standalone non-public network (SNPN), it needs to obtain the subscription information of the SNPN and the network credential of the SNPN. This SNPN can be referred to as a subscribed SNPN (S-SNPN).
[0003] Currently, the subscription information of the S-SNPN and the network credential of the S-SNPN are obtained through two subscription methods: offline subscription and online subscription (online-subscription or onboard). Taking the online subscription method as an example, this method may include: The terminal device can identify an onboard SNPN (O-SNPN), and send an access request carrying the certificate of the terminal device and the identifier (ID) of the terminal device to the access network device in the O-SNPN, requesting the O-SNPN to provide online subscription services. After receiving the access request, the access network device in the O-SNPN triggers the core network device in the O-SNPN to determine whether the certificate of the terminal device corresponds to the ID of the terminal device and is included in the default credential server (DCS). If it is included, the terminal device is allowed to access the O-SNPN. The core network device in the O-SNPN creates a session for the terminal device, and the terminal device obtains the subscription information of the S-SNPN and the network credential of the S-SNPN from the provisioning server (PS) through the session.
[0004] As can be seen from the above, the key step in online subscription is for the terminal device to select the SNPN that provides online subscription services for it. Therefore, how the terminal device selects the SNPN that can provide online subscription services for it becomes the primary problem to be solved. Summary of the Invention
[0005] Embodiments of this application provide an online subscription method, apparatus, and system to solve the problem of selecting the SNPN that can provide online subscription services for the terminal device.
[0006] To achieve the above objective, the embodiments of this application adopt the following technical solutions:
[0007] In a first aspect, an embodiment of the present application provides an online signing method, which may include: The terminal device receives, from the access network device, first information for indicating the O-SNPN supported by the access network device and second information for indicating the terminal type corresponding to the O-SNPN. When the terminal device belongs to the terminal type corresponding to the O-SNPN, the terminal device sends a first message to the access network device for requesting the access network device to provide an online signing service for the terminal device, thereby implementing the online signing of the terminal device. Based on the method described in the first aspect, the terminal device can, under the indication of the access network device, determine whether it belongs to the terminal type corresponding to the O-SNPN. If it belongs to the terminal type corresponding to the O-SNPN supported by the access network device, it determines to perform online signing through the O-SNPN supported by the access network device and requests the access network device to provide an online signing service for it. Compared with the O-SNPN ID pre-configured for the terminal device, the terminal type is a more stable information that does not change over time. Therefore, selecting the O-SNPN through the matching of the terminal type can improve the accuracy of the terminal device in selecting the O-SNPN.
[0008] In a possible design, the first information includes the identifier of the cell and a first indication information for indicating that the SNPN in the cell supports the online signing service. In this way, the O-SNPN supported by the access network device can be indicated at the cell granularity, that is, the O-SNPN corresponding to a certain cell is centrally indicated, reducing the signaling overhead.
[0009] In a possible design, the first information includes the identifier of the PLMN and a second indication information for indicating that the SNPN in the PLMN supports the online signing service. In this way, the O-SNPN supported by the access network device can be indicated at the PLMN granularity, that is, the O-SNPN corresponding to a certain PLMN is centrally indicated to the terminal device, reducing the signaling overhead.
[0010] In a possible design, the first information includes the identifier of the SNPN and a third indication information for indicating that the SNPN supports the online signing service. In this way, the O-SNPN can be indicated to the terminal device one by one, and the indication granularity is specific to a certain O-SNPN, with a finer granularity, which can provide a more flexible deployment.
[0011] In a possible design, the second information includes the identifier of the terminal type corresponding to the O-SNPN. When the identifier of the terminal type to which the terminal device belongs is included in the second information, it is determined that the terminal device belongs to the terminal type corresponding to the O-SNPN. In this way, the terminal device can match whether the identifier of its own terminal type is included in the second information to determine whether it belongs to the terminal type corresponding to the O-SNPN and whether it can perform online signing through the O-SNPN, simplifying the system design.
[0012] In a possible design, the terminal type to which the terminal device belongs is pre-configured; or, the terminal type to which the terminal device belongs is determined by the terminal device according to the certificate of the terminal device, and the certificate of the terminal device is pre-configured to the terminal device. In this way, the terminal type to which the terminal device belongs can be determined through pre-configuration or the correspondence between the certificate of the terminal device and the terminal type, and the method is flexible and diverse.
[0013] In a possible design, the O-SNPN supported by the access network device belongs to the O-SNPN that allows the terminal device to access. That is, when the terminal type of the terminal device belongs to the terminal type corresponding to the O-SNPN and the O-SNPN that allows the terminal device to access belongs to this O-SNPN, the O-SNPN that provides the online subscription service for the terminal device is determined. In this way, the O-SNPN is selected through multiple conditions, ensuring the accuracy of O-SNPN judgment.
[0014] In a possible design, the method further includes: the terminal device sends a second message to the access network device, and the second message carries the identifier of the terminal type selected by the terminal device, so that the access network device can find the DCS corresponding to the terminal type according to the identifier of the terminal type, and verify whether the ID of the terminal and the certificate of the terminal are included in the DCS, realizing the authentication and authorization of online subscription and providing security guarantee for online subscription.
[0015] In a second aspect, the present application provides a communication device, which can be a terminal device, a chip or a system-on-chip in the terminal device, can also be a module or unit in the terminal device for implementing the online subscription method described in the embodiments of the present application, or can be other modules or units capable of implementing the method on the terminal device side. The communication device can implement the functions executed by the terminal device in the above first aspect or each possible design. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one design, the communication device can include modules corresponding one by one to the methods / operations / steps / actions described in the first aspect, and the module can be a hardware circuit, software, or a combination of hardware circuit and software. In one design, the communication device can include: a receiving unit, a processing unit, and a sending unit.
[0016] The receiving unit is configured to receive, from the access network device, the first information for indicating the O-SNPN supported by the access network device and the second information for indicating the terminal type corresponding to the O-SNPN;
[0017] The processing unit is configured to determine that the terminal device belongs to the terminal type corresponding to the O-SNPN;
[0018] A sending unit, configured to send a first message to an access network device, where the first message is used to request the access network device to provide an online subscription service for a terminal device.
[0019] Based on the communication device described in the second aspect, under the indication of the access network device, it can be determined whether the terminal type to which the terminal device belongs belongs to the terminal type corresponding to the O-SNPN. If it belongs to the terminal type corresponding to the O-SNPN supported by the access network device, it is determined that the terminal device performs online subscription through the O-SNPN supported by the access network device, and a request is sent to the access network device to request the access network device to provide an online subscription service for it. Compared with the O-SNPN ID pre-configured for the terminal device, the terminal type is a more stable and time-invariant information. Therefore, selecting the O-SNPN through the matching of the terminal type can improve the accuracy of the terminal device in selecting the O-SNPN.
[0020] In a possible design, the first information includes an identifier of a cell and a first indication information for indicating that the SNPN in the cell supports the online subscription service. Alternatively, it includes an identifier of a PLMN and a second indication information for indicating that the SNPN in the PLMN supports the online subscription service. Alternatively, it includes an identifier of an SNPN and a third indication information for indicating that the SNPN supports the online subscription service, indicating the O-SNPN supported by the access network device based on the cell granularity or the PLMN granularity or the SNPN granularity. Specifically, the relevant description of the first information can be referred to in the possible design of the first aspect and will not be elaborated here.
[0021] In a possible design, the second information includes an identifier of the terminal type corresponding to the O-SNPN; the communication device further includes: a processing unit, configured to determine that the terminal device belongs to the terminal type corresponding to the O-SNPN when the identifier of the terminal type to which the terminal device belongs is included in the second information.
[0022] Based on this possible design, it can be determined whether the terminal device belongs to the terminal type corresponding to the O-SNPN and whether it can perform online subscription through the O-SNPN by matching whether the identifier of the terminal type of the terminal device is included in the second information, which simplifies the system design.
[0023] In a possible design, the terminal type to which the terminal device belongs is pre-configured; or, the terminal type to which the terminal device belongs is determined by the terminal device according to the certificate of the terminal device, and the certificate of the terminal device is pre-configured for the terminal device.
[0024] Based on this possible design, the terminal type to which the terminal device belongs can be determined through pre-configuration or the correspondence between the certificate of the terminal device and the terminal type, and the method is flexible and diverse.
[0025] In a possible design, the sending unit is further configured to send a second message to the access network device. The second message carries an identifier of the terminal type selected by the terminal device, so that the access network device can find the DCS corresponding to the terminal type according to the identifier of the terminal type, and verify whether the ID of the terminal and the certificate of the terminal are included in the DCS, implement the authentication and authorization of online signing, and provide security guarantee for online signing.
[0026] In a possible design, the O-SNPN supported by the access network device belongs to the O-SNPN that allows the terminal device to access. Based on this possible design, when the terminal type of the terminal device belongs to the terminal type corresponding to the O-SNPN, and the O-SNPN that allows the terminal device to access belongs to this O-SNPN, determine the O-SNPN that provides the online signing service for the terminal device. In this way, the O-SNPN is selected through multiple conditions to ensure the accuracy of O-SNPN judgment.
[0027] In a third aspect, a communication device is provided. The communication device can be a terminal device, a chip or a system-on-chip in the terminal device, or other modules or units that can implement the method on the terminal device side. The communication device can implement the functions performed by the terminal device in the first aspect or each possible design above. The functions can be implemented by hardware. In a possible design, the communication device may include: a processor and a communication interface. The processor can be used to support the communication device to implement the functions involved in the first aspect or any possible design of the first aspect above. For example, the processor is used to receive, through the communication interface, a first piece of information for indicating the O-SNPN supported by the access network device and a second piece of information for indicating the terminal type corresponding to the O-SNPN from the access network device; when the terminal device belongs to the terminal type corresponding to the O-SNPN, send a first message to the access network device. The first message is used to request the access network device to provide an online signing service for the terminal device. In another possible design, the communication device may further include a memory, and the memory is used to store computer instructions and / or data. When the communication device runs, the processor executes the computer instructions stored in the memory, so that the communication device executes the online signing method described in the first aspect or any possible design of the first aspect above. In the embodiments of the present application, the communication interface can be a transceiver, an interface circuit, a bus interface, a pin, or other devices that can implement the transceiver function.
[0028] In a fourth aspect, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When it runs on a computer, it enables the computer to execute the online signing method described in the first aspect or any possible design of the above aspect.
[0029] In a fifth aspect, there is provided a computer program product comprising instructions, which may include program instructions that, when the computer program product runs on a computer, cause the computer to execute the online signing method described in the first aspect above or any possible design of the above aspects.
[0030] In a sixth aspect, there is provided a chip system, which includes a processor and a communication interface. The chip system can be used to implement the functions executed by the terminal device in the first aspect above or any possible design of the first aspect. For example, the processor is configured to receive, through the communication interface, first information for indicating the O-SNPN supported by the access network device and second information for indicating the terminal type corresponding to the O-SNPN; when the terminal device belongs to the terminal type corresponding to the O-SNPN, send a first message to the access network device, where the first message is used to request the access network device to provide an online signing service for the terminal device. In a possible design, the chip system further includes a memory, which is used to store program instructions and / or data. When the chip system runs, the processor executes the program instructions stored in the memory, so that the chip system executes the online signing method described in the first aspect above or any possible design of the first aspect. The chip system may be composed of chips or may include chips and other discrete devices, without limitation.
[0031] In a seventh aspect, an embodiment of the present application further provides an online signing method, which may include: the access network device sends first information for indicating the O-SNPN supported by the access network device and second information for indicating the terminal type corresponding to the O-SNPN. When the terminal device belongs to the terminal type corresponding to the O-SNPN, the access network device receives a first message from the terminal device for requesting the access network device to provide an online signing service for the terminal device, so that the access network device responds to the first message and provides an online signing service for the terminal device.
[0032] Based on the method described in the seventh aspect, the access network device may indicate to the terminal device the O-SNPN supported by the access network device and the terminal type corresponding to the O-SNPN, so that the terminal device can, under the indication of the access network device, determine whether it belongs to the terminal type corresponding to the O-SNPN. If it belongs to the terminal type corresponding to the O-SNPN supported by the access network device, it determines to perform online signing through the O-SNPN supported by the access network device and sends a request message to the access network device to request the access network device to provide an online signing service for it. Compared with the pre-configured O-SNPN ID of the terminal device, the terminal type is a more stable and non-time-varying information. Therefore, selecting the O-SNPN through the matching of the terminal type can improve the accuracy of the terminal device in selecting the O-SNPN.
[0033] Among them, the relevant descriptions of the first information and the second information can be referred to in the first aspect or the possible designs of the first aspect, and will not be elaborated here.
[0034] In a possible design, the method further includes: the access network device obtains the identifier of the terminal type corresponding to the O-SNPN from the DCS connected to the O-SNPN. That is, the access network device can obtain the identifier of the terminal type corresponding to the O-SNPN by interacting with the DCS, which simplifies the system design.
[0035] In a possible design, the O-SNPN supported by the access network device belongs to the O-SNPN that allows the terminal device to access. That is, when the terminal type of the terminal device belongs to the terminal type corresponding to the O-SNPN, and the O-SNPN that allows the terminal device to access belongs to this O-SNPN, it is determined as the O-SNPN that provides the online subscription service for the terminal device. In this way, the O-SNPN is selected through multiple conditions, ensuring the accuracy of the O-SNPN judgment.
[0036] In a possible design, the method further includes: the access network device receives a second message from the terminal device, and the second message carries the identifier of the terminal type selected by the terminal device, so that the access network device can find the DCS corresponding to the terminal type according to the identifier of the terminal type, and verify whether the ID of the terminal and the certificate of the terminal are included in the DCS, realizing the authentication and authorization of the online subscription and providing security guarantee for the online subscription.
[0037] In an eighth aspect, the present application provides a communication device, which can be an access network device, a chip or a system-on-chip in the access network device, or a module or unit in the access network device for implementing the online subscription method described in the embodiments of the present application, or other modules or units capable of implementing the network-side method. The communication device can implement the functions performed by the access network device in the above seventh aspect or each possible design. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one design, the communication device can include modules corresponding one by one to the methods / operations / steps / actions described in the seventh aspect. The module can be a hardware circuit, software, or a combination of hardware circuit and software. In one design, the communication device can include: a sending unit, a receiving unit.
[0038] The sending unit is used to send the first information indicating the O-SNPN supported by the access network device and the second information indicating the terminal type corresponding to the O-SNPN;
[0039] A receiving unit, configured to receive, when the terminal device belongs to the terminal type corresponding to the O-SNPN, a first message from the terminal device for requesting the access network device to provide an online subscription service for the terminal device.
[0040] Based on the communication device described in the eighth aspect, it can indicate to the terminal device the O-SNPN supported by the access network device and the terminal type corresponding to the O-SNPN, so that the terminal device can, under the indication of the access network device, determine whether it belongs to the terminal type corresponding to the O-SNPN. If it belongs to the terminal type corresponding to the O-SNPN supported by the access network device, it determines to perform online subscription through the O-SNPN supported by the access network device, and sends a request to the communication device, requesting the access network device to provide an online subscription service for it. Compared with the pre-configured O-SNPN ID of the terminal device, the terminal type is a more stable and time-invariant information. Therefore, selecting the O-SNPN through the matching of the terminal type can improve the accuracy of the terminal device in selecting the O-SNPN.
[0041] In a possible design, the first information includes the identifier of the cell and the first indication information for indicating that the SNPN in the cell supports the online subscription service. Alternatively, it includes the identifier of the PLMN and the second indication information for indicating that the SNPN in the PLMN supports the online subscription service, or includes the identifier of the SNPN and the third indication information for indicating that the SNPN supports the online subscription service, and indicates the O-SNPN supported by the access network device based on the cell granularity or the PLMN granularity or the SNPN granularity. Specifically, the relevant description of the first information can be referred to in the possible design of the first aspect and will not be elaborated here.
[0042] In a possible design, the second information includes the identifier of the terminal type corresponding to the O-SNPN, so that after the terminal device receives the second information, when it determines that the identifier of the terminal type to which the terminal device belongs is included in the second information, it determines that the terminal device belongs to the terminal type corresponding to the O-SNPN, simplifying the system design.
[0043] In a possible design, the receiving unit is further configured to obtain the identifier of the terminal type corresponding to the O-SNPN from the default certificate server DCS, and the DCS is connected to the O-SNPN.
[0044] Based on this possible design, the receiving unit in the communication device can obtain the identifier of the terminal type corresponding to the O-SNPN by interacting with the DCS, simplifying the system design.
[0045] In a possible design, the receiving unit is further configured to receive a second message from a terminal device. The second message carries an identifier of the terminal type selected by the terminal device, so that the access network device can find the DCS corresponding to the terminal type according to the identifier of the terminal type, and verify whether the ID of the terminal and the certificate of the terminal are included in the DCS, implement the authentication and authorization of online signing, and provide security guarantee for online signing.
[0046] In a ninth aspect, a communication device is provided. The communication device may be an access network device, a chip or a system-on-chip in the access network device, or other modules or units capable of implementing network-side methods. The communication device can implement the functions performed by the access network device in the above seventh aspect or each possible design. The functions can be implemented by hardware. In a possible design, the communication device may include: a processor and a communication interface. The processor can be used to support the communication device to implement the functions involved in the above seventh aspect or any possible design of the seventh aspect. For example: the processor is used to send, through the communication interface, a first piece of information indicating the O-SNPN supported by the access network device and a second piece of information indicating the terminal type corresponding to the O-SNPN; when the terminal device belongs to the terminal type corresponding to the O-SNPN, receive a first message from the terminal device for requesting the access network device to provide an online signing service for the terminal device. In another possible design, the communication device may further include a memory, and the memory is used to store computer instructions and / or data. When the communication device runs, the processor executes the computer instructions stored in the memory, so that the communication device executes the online signing method described in the above seventh aspect or any possible design of the seventh aspect.
[0047] In a tenth aspect, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When it runs on a computer, it enables the computer to execute the online signing method described in the above seventh aspect or any possible design of the above aspect.
[0048] In an eleventh aspect, a computer program product containing instructions is provided. The computer program product may include program instructions. When the computer program product runs on a computer, it enables the computer to execute the online signing method described in the above seventh aspect or any possible design of the above aspect.
[0049] In a twelfth aspect, a chip system is provided. The chip system includes a processor and a communication interface, and can be used to implement the functions performed by the access network device in the above seventh aspect or any possible design of the seventh aspect. For example, the processor is used to send, through the communication interface, first information indicating the O-SNPN supported by the access network device and second information indicating the terminal type corresponding to the O-SNPN; when the terminal device belongs to the terminal type corresponding to the O-SNPN, receive a first message from the terminal device for requesting the access network device to provide an online subscription service for the terminal device. In a possible design, the chip system further includes a memory for storing program instructions and / or data. When the chip system runs, the processor executes the program instructions stored in the memory, so that the chip system executes the online subscription method described in the above seventh aspect or any possible design of the seventh aspect. The chip system may be composed of chips or may include chips and other discrete devices, without limitation.
[0050] In a thirteenth aspect, an embodiment of the present application further provides a communication system, which includes the communication device described in the second aspect or the third aspect, and the communication device described in the eighth aspect or the ninth aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 FIG. is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0052] Figure 2 FIG. is another schematic diagram of a system architecture provided by an embodiment of the present application;
[0053] Figure 3 FIG. is a schematic diagram of the composition of a communication device 300 provided by an embodiment of the present application;
[0054] Figure 4 FIG. is a flowchart of an online subscription method provided by an embodiment of the present application;
[0055] Figure 5a FIG. is a flowchart of an online subscription method provided by an embodiment of the present application;
[0056] Figure 5b FIG. is a flowchart of another online subscription method provided by an embodiment of the present application;
[0057] Figure 6 FIG. is a flowchart of another online subscription method provided by an embodiment of the present application;
[0058] Figure 7 FIG. is a schematic diagram of the composition of a communication device 70 provided by an embodiment of the present application;
[0059] Figure 8Schematic diagram of the composition of a communication device 80 provided by an embodiment of the present application;
[0060] Figure 9 Schematic diagram of the composition of a communication system provided by an embodiment of the present application. Detailed implementation manners
[0061] Before introducing the embodiments of the present application, some terms related to the embodiments of the present application are explained:
[0062] A non-public network (NPN), also known as a private network, refers to a network for non-public purposes. For example, an NPN can be an internal network built by an operator itself, or an internal network built by a third party, such as an internal network built by a factory, a school, or a business district. An NPN can be divided into two types: a standalone non-public network (SNPN) and a public network integrated NPN (PNI-NPN). Among them, a PNI-NPN depends on the functions of the public network. For example, a PNI-SNPN can be integrated into the public network. It should be noted that the public network described in the present application can refer to a public land mobile network (PLMN).
[0063] Among them, an SNPN does not depend on the functions of the public network. Each SNPN has an identifier (ID), such as an SNPN ID, and the SNPN is uniquely identified by the SNPN ID. The SNPN ID can be composed of a public land mobile network identity (PLMN ID) and a network identifier (NID). The PLMN ID can be used to indicate a certain PLMN. A PLMN can include one or more networks / subnets. The NID can be used to indicate a network / subnet under the PLMN. The terminal device can subscribe to one or more SNPNs as needed. If the terminal device wants to access an SNPN to which the terminal device has subscribed and the SNPN provides network services for the terminal device, the terminal device needs to have the subscription information of the SNPN and the network credential of the SNPN.
[0064] It should be noted that in this application, the SNPN that provides the online signing service can be referred to as the onboarding SNPN (O-SNPN), and the SNPN subscribed by the terminal device can be referred to as the subscribed SNPN (S-SNPN).
[0065] Exemplarily, the terminal device can obtain the subscription information of the SNPN and the network certificate of the SNPN through an off-line method or an online-subscription / onboarding method. Taking the case where the terminal device obtains the subscription information of the SNPN and the network certificate of the SNPN through the online signing method as an example, this method may include: the terminal device selects and connects to an SNPN that can provide the online signing service for the terminal device, and obtains the subscription information of the SNPN and the network certificate of the SNPN from a provisioning server (PS) through the SNPN. From the perspective of the online signing process, the key step of online signing is that the terminal device can select an SNPN that provides online services.
[0066] In one way, in the online signing method, the terminal device selects the O-SNPN that can provide the online signing service for itself through the following method: One or more SNPN IDs that can provide the online signing service for the terminal device are pre-configured for the terminal device. The access network device sends a broadcast message in the cell, and the broadcast message includes the SNPN ID that provides the online signing service. After the terminal device receives the broadcast message and finds that the SNPN ID in the broadcast message is the same as a certain SNPN ID pre-configured for itself, it accesses the SNPN identified by the SNPN ID. Among them, the SNPN ID pre-configured for the terminal device can be the ID corresponding to the O-SNPN that can be connected to the default credential server (DCS) storing the default credential of the terminal device.
[0067] Since the O-SNPN connected to the DCS changes over time, that is, the SNPN that can provide the online signing service for the terminal device changes. If the terminal device still selects the appropriate O-SNPN according to the pre-configured SNPN ID, misjudgment will occur, affecting the online signing of the terminal device.
[0068] For example, the DCS1 stores the certificates of terminal devices. In the initial state, assume that the O-SNPNs connected to the DCS1 include O-SNPN1, O-SNPN2, and O-SNPN3, and the SNPN IDs pre-configured for the terminal devices include {O-SNPN1, O-SNPN2, O-SNPN3}. If the terminal device detects that the broadcast message sent by the access network device includes {O-SNPN1}, it selects to perform online signing through O-SNPN1. As time goes by, the O-SNPNs connected to the DCS1 change to include O-SNPN4 and O-SNPN5. At this time, the access network device can send a broadcast message carrying {O-SNPN4} or {O-SNPN5}. When the terminal device detects the broadcast message carrying {O-SNPN4} or {O-SNPN5}, it cannot select a suitable O-SNPN based on the pre-configured SNPN IDs. However, there are actually O-SNPNs connected to the DCS1, which causes misjudgment and leads to the failure of online signing.
[0069] To solve the above technical problems, an embodiment of the present application provides an online signing method: The access network device sends information indicating the O-SNPNs it supports and information indicating the terminal types corresponding to the O-SNPNs. If the terminal device receives the information sent by the access network device and determines that it belongs to the terminal type corresponding to the O-SNPNs supported by the access network device, it determines to perform online signing through the O-SNPNs supported by the access network device and requests the access network device to provide it with online signing services. Since the terminal type does not change over time and is a more stable piece of information, selecting the O-SNPN through the matching of the terminal type can improve the accuracy of the terminal device in selecting the O-SNPN.
[0070] The following describes the online signing method provided by the embodiment of the present application with reference to the accompanying drawings of the specification.
[0071] The online signing method provided by the embodiment of the present application can be applied to Figure 1 the system shown in Figure 1 As shown, the system may include: multiple terminal devices, an access network device, a configuration server, S-SNPN, O-SNPN, and DCS. Among them, the access network device can cover one or more cells. A cell can include one or more PLMNs, and a PLMN can include one or more O-SNPNs. The configuration server can be deployed in a data network (DN).
[0072] Among them, the access network device is mainly used to implement at least one of the functions of resource scheduling, radio resource management, and radio access control of the terminal device. Specifically, the access network device may include any one of a base station, a wireless access point, a transmission receive point (TRP), a transmission point (TP), and some other access nodes. In the embodiments of the present application, the device for implementing the functions of the access network device may be the access network device; it may also be a device capable of supporting the access network device to implement this function, such as a chip system, and this device may be installed in the access network device or used in matching with the access network device. In the technical solution provided in the embodiments of the present application, taking the device for implementing the functions of the access network device as the access network device as an example, the technical solution provided in the embodiments of the present application is described.
[0073] The terminal device may be a terminal, a user equipment (UE), a mobile station (MS), or a mobile terminal (MT), etc. Specifically, the terminal device may be a mobile phone, a tablet computer, or a computer with a wireless transceiver function. It may also be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in remote medical treatment, a wireless terminal in a smart grid, a wireless terminal in a smart city, a smart home, or a vehicle-mounted terminal, etc. In the embodiments of the present application, the device for implementing the functions of the terminal device may be the terminal device, or it may also be a device capable of supporting the terminal device to implement this function, such as a chip system, and this device may be installed in the terminal device or used in matching with the terminal device. Below, taking the device for implementing the functions of the terminal device as the terminal device as an example, the online signing method provided in the embodiments of the present application is described.
[0074] Among them, the O-SNPN can be used to provide an online signing service for the terminal device.
[0075] Among them, the S-SNPN is called the SNPN owning the UE's subscription, that is, the SNPN to which the terminal device has subscribed but has not yet obtained its subscription information and network certificate.
[0076] Among them, the DCS contains the identifier (ID) of the terminal device that allows online signing and the UE credential of the terminal device. The UE credential of the terminal device can be the default UE credential. The UE credential of the terminal device can correspond to the terminal type of the terminal device. For example, the terminal type can be the device vendor (DV) service provider of the terminal device, and the UE credential of the terminal device corresponds to the DV of the terminal device. According to the UE credential of the terminal device, the DV of the terminal device can be determined. It should be noted that in this application, "network certificate" and "UE credential of the terminal device" are two different concepts. The network certificate can be used for the authentication and authorization of the S-SNPN, and the UE credential of the terminal device can be used for the authentication and authorization related to online signing by the O-SNPN.
[0077] Among them, the provisioning server (PS) can be used to authenticate the terminal device according to the UE credential of the terminal device. After successful authentication, the signing information, network certificate are extracted from the S-SNPN and sent to the terminal device.
[0078] It should be noted that Figure 1 is only an exemplary framework diagram, Figure 1 the number of nodes, the number of cells, and the state of the terminal included are not restricted. Except Figure 1 the functional nodes shown, other nodes can also be included, such as: core network devices, gateway devices, application servers, etc., without restriction. The access network device communicates with the core network device in a wired or wireless manner, such as communicating with each other through the next generation (NG) interface.
[0079] In addition, in this application, Figure 1 different terminal devices can belong to different terminal types or the same terminal type, without restriction. For example, different terminal devices can belong to different device vendors, or can belong to terminal devices of different batches and different product models produced by the same device vendor, without restriction. For example, terminal device 1 can be a terminal device produced by device vendor A, and terminal device 2 can be a terminal device produced by device vendor B, or terminal device 1 can be a terminal device of model A_1 produced by device vendor A, and terminal device 2 can be a terminal device of model A_2 produced by device vendor A.
[0080] Specifically, Figure 1The system shown can be a communication system in the 3rd generation partnership project (3GPP), for example, it can be a long term evolution (LTE) communication system, or a 4th generation (4G) communication system, or a 5th generation (5G) communication system or a new radio (NR) communication system, or it can also be a non-3GPP communication system, without limitation.
[0081] Taking Figure 1 the communication system shown as a 5G communication system as an example, as Figure 2 shown, the above O-SNPN may include a session management function (SMF), a user plane function (UPF), an access and mobility management function (AMF) in the 5G communication system, a policy control function (PCF) in the 5G communication system, a network slice selection function (NSSF) in the 5G communication system, a unified data management (UDM) in the 5G communication system, and an authentication server function (AUSF). Figure 1 The network element or entity corresponding to the access network device in Figure 2 can be a radio access network (RAN) in the 5G communication system. The S-SNPN may include a network exposure function (NEF) in the 5G communication system. As Figure 2 shown, each network element in the 5G communication system can be connected through a next generation (NG) interface, and the NG interface can be abbreviated as the N interface. Specifically, the N interface between network elements can be referred to Figure 2 shown, and will not be elaborated.
[0082] In specific implementation, Figure 1 each network element shown, such as a terminal device and an access network device, can adopt Figure 3 the composition structure shown or include Figure 3 the components shown. Figure 3FIG. 0 is a schematic structural diagram of a communication device 300 provided by an embodiment of the present application. When the communication device 300 has the functions of the terminal device described in the embodiment of the present application, the communication device 300 may be a terminal device, or a chip or a system-on-chip in the terminal device. When the communication device 300 has the functions of the access network device described in the embodiment of the present application, the communication device 300 may be an access network device, or a chip or a system-on-chip in the access network device.
[0083] As Figure 3 shown, the communication device 300 may include a processor 301, a communication line 302, and a communication interface 303. Further, the communication device 300 may also include a memory 304. Among them, the processor 301, the memory 304, and the communication interface 303 may be connected through the communication line 302.
[0084] Among them, the processor 301 may be a central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 301 may also be other devices with processing functions, such as circuits, devices, or software modules.
[0085] The communication line 302 is used to transmit information between the components included in the communication device 300.
[0086] The communication interface 303 is used to communicate with other devices or other communication networks. The other communication network may be an Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc. The communication interface 303 may be an interface circuit, a pin, a radio frequency module, a transceiver, or any device capable of implementing communication.
[0087] The memory 304 is used to store instructions. Among them, the instructions may be computer programs.
[0088] Among them, the memory 304 can be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions. It can also be a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage, magnetic disc storage media, or other magnetic storage devices. Optical disc storage includes compressed optical discs, laser discs, optical discs, digital versatile discs, or Blu-ray discs, etc.
[0089] It should be noted that the memory 304 can exist independently of the processor 301 or be integrated with the processor 301. The memory 304 can be used to store instructions, program codes, or some data, etc. The memory 304 can be located inside the communication device 300 or outside the communication device 300, without limitation. When the processor 301 executes the instructions stored in the memory 304, the online signing method provided in the following embodiments of the present application can be implemented.
[0090] In one example, the processor 301 can include one or more CPUs, such as Figure 3 CPU0 and CPU1 in
[0091] As an alternative implementation, the communication device 300 includes multiple processors. For example, in addition to Figure 3 the processor 301 in
[0092] As an alternative implementation, the communication device 300 further includes an output device 305 and an input device 306. Exemplarily, the input device 306 is a device such as a keyboard, a mouse, a microphone, or a joystick, and the output device 305 is a device such as a display screen or a speaker.
[0093] It should be noted that the communication device 300 can be a desktop computer, a portable computer, a network server, a mobile phone, a tablet computer, a wireless terminal, an embedded device, a chip system, or a device with a Figure 3 similar structure in Figure 3 In addition, the component structure shown in Figure 3 does not constitute a limitation on the communication device. Except for the components shown in
[0094] In the embodiments of the present application, the chip system may be composed of chips or may include chips and other discrete devices.
[0095] The online signing method provided by the embodiments of the present application will be described below. Among them, each device in the following embodiments may have Figure 3 the components shown. Among them, actions, terms, etc. involved between the embodiments of the present application can be referred to each other without limitation. The message names or parameter names in the messages exchanged between devices in the embodiments of the present application are only examples. In specific implementations, other names can also be used. For example, "support" in the embodiments of the present application can also be understood as "allowed", and "include" in the embodiments of the present application can also be understood as "carry", etc. It is uniformly stated here that the embodiments of the present application do not make specific limitations on this.
[0096] Figure 4 is a flowchart of an online signing method provided by an embodiment of the present application. As Figure 4 shown, the method includes:
[0097] Step 401: The access network device sends the first information and the second information.
[0098] Among them, the access network device may be the Figure 1 access network device in.
[0099] Among them, the first information may be used to indicate the O-SNPN supported by the access network device. The O-SNPN supported by the access network device may be connected to the DCS. Once there is an SNPN connected to the DCS in the SNPNs covered by the access network device, it is determined that the access network device supports O-SNPN.
[0100] Exemplarily, to improve the deployment flexibility of the SNPN, the SNPN supporting the online subscription service can be indicated at different granularities. For example, in the first method, taking the cell as the granularity, the first information can be used to indicate that the SNPN in a certain cell in the access network device supports the online subscription service. The first information can include the identifier of the cell and the first indication information, and the first indication information is used to indicate that the SNPN in the cell identified by the identifier of the cell supports the online subscription service. In the second method, taking the PLMN as the granularity, the first information can be used to indicate that the SNPN corresponding to a certain PLMN in the cell supports the online subscription service. The first information can include the PLMN ID and the second indication information, and the second indication information is used to indicate that the SNPN in the PLMN identified by the PLMN ID supports the online subscription service. In the third method, taking the O-SNPN as the granularity, the first information can be used to indicate that a specific SNPN supports the online subscription service. The first information can include the SNPN ID and the third indication information, and the third indication information is used to indicate that the SNPN identified by the SNPN ID supports the online subscription service. Specifically, the detailed descriptions of the first to the third methods can be referred to below.
[0101] It should be noted that in this application, a cell can refer to an area used to provide wireless communication services for a terminal device, and the access network device can provide wireless communication services for the terminal device in this area. An access network device can manage one or more cells. Each cell corresponds to a cell identifier (cell ID), and the cell is uniquely identified by the cell identifier. In addition, the first information can also be named the online subscription service indication information or the onboarding information or other names, which is not limited.
[0102] Among them, the second information can be used to indicate the terminal type (type or category) corresponding to the O-SNPN indicated by the first information, and the O-SNPN can provide an online subscription service for terminal devices belonging to this terminal type. Alternatively, the replacement description is that the second information can be used to indicate the terminal types supported by the online subscription service. The second information can include a list of terminal types, and the list of terminal types can include the identifiers (identifiers, IDs) of one or more terminal types supported by the online subscription service. In this application, the terminal type can be used to describe a class of terminals with the same or similar characteristics. For example, terminal devices can be divided into different terminal types according to the device providers of the terminal devices. Terminal devices belonging to the same terminal type come from the same device provider. Or, terminal devices can be divided into different terminal types according to the product models of the terminal devices. Terminal devices belonging to the same terminal type have the same product model, and one or more product models can correspond to one service provider. For example, the terminal types can include device provider A, device provider B, device provider C, etc., and the second information can include {DV A, DV B, DV C}; or, the terminal types can include product model A_1, product model A_2, product model B_1, product model B_2, product model C_1, product model C_2, and the second information can include {A_1, A_2, B_1, B_2, C_1, C_2}.
[0103] Exemplarily, the list of terminal types can be obtained by the access network device from the DCS connected to the O-SNPN. For example, the access network device can determine the SNPN connected to the DCS in the cell it covers, obtain the list of terminal types stored in the DCS from the DCS connected to this SNPN, encapsulate the indication information and the identifier in the first information, encapsulate the list of terminal types in the second information, and send the first information and the second information. In this application, the list of terminal types can be referred to as the list of terminal types supported by the DCS. Specifically, the process of the access network device obtaining the list of terminal types from the DCS can refer to the following Figure 5a Steps 404 to 406 shown.
[0104] For example, taking the terminal device as a UE and the identifier of the terminal type as the DV ID, the DCS stores the UE IDs of all UEs allowed for online subscription and the default UE credential. The DCS can obtain the DV IDs corresponding to all UEs based on the default UE credential. The DV IDs corresponding to all UEs form a list of DV IDs supported by the DCS. The DCS reports the list of DV IDs it supports to the core network (CN) device in the O-SNPN supported by the access network device. The CN device in the O-SNPN forwards the list of DV IDs to the access network device of the O-SNPN. After receiving the list of DV IDs, the access network device sends a first message and a second message including the list of DV IDs. Among them, the CN device can be Figure 2 the AUSF shown.
[0105] Among them, the first message can be carried and sent in the first system information block (SIB), and the second message can be carried and sent in the second SIB. The first SIB and the second SIB can be the same or different. For example, the first SIB can be SIB1, and the second SIB can be other SIBs, such as SIBX, etc. In this application, the SIB can be a public message in the cell and can be received by all terminal devices in the cell or can be received by a group of terminal devices in the cell. The SIB can be any of the following types of SIBs: SIB for indicating that the terminal device performs random access, SIB for assisting the terminal device in cell reselection, and SIB for carrying special messages such as security messages and emergency messages, etc.
[0106] Exemplarily, the access network device can periodically send / broadcast the first SIB carrying the first message and send the second SIB carrying the second message in one or more cells covered by the access network device according to a preset period. For example, assuming that the base station covers cell 1 and cell 2, the base station can send SIB1 for indicating the O-SNPN corresponding to cell 1 or the O-SNPN corresponding to the PLMN in cell 1 or a specific O-SNPN in cell 1 and SIB2 for indicating the terminal type corresponding to the O-SNPN in cell 1. The base station can send SIB1 for indicating the O-SNPN corresponding to cell 2 or the O-SNPN corresponding to the PLMN in cell 2 or a specific O-SNPN in cell 2 and SIB3 for indicating the terminal type corresponding to the O-SNPN in cell 2.
[0107] It should be noted that this application is not limited to indicating the O-SNPN supported by the access network device and the terminal type corresponding to the O-SNPN to the terminal device through the first information and the second information. It is also possible to indicate the O-SNPN supported by the access network device and the terminal type corresponding to the O-SNPN to the terminal device through one piece of information. For example, the access network device sending the first information and the second information can be replaced by the access network device sending one piece of information, and this information is used to indicate the O-SNPN supported by the access network device and the terminal type corresponding to the O-SNPN.
[0108] Step 402: The terminal device receives the first information and the second information from the access network device.
[0109] Exemplarily, taking the first information carried in the first SIB and the second information carried in the second SIB as an example, the terminal device receiving the first information and the second information from the access network device may include: the terminal device receives the first SIB from the access network device, obtains the first information from the first SIB, receives the second SIB, and obtains the second information from the second SIB.
[0110] Step 403: When the terminal device belongs to the terminal type indicated by the second information, the terminal device sends a first message to the access network device. Correspondingly, the access network device receives the first message.
[0111] Among them, the first message can be used to request the access network device to provide an online subscription service for the terminal device. The first message may include the cell identifier of the cell, and there is an O-SNPN in this cell that is supported by the access network device and corresponds to the terminal type of the terminal device. Specifically, the first message can be used to request access to the cell identified by the cell identifier, and provide an online subscription service for the terminal device through the O-SNPN in this cell. For example, the terminal device detects SIB1 and SIB2 in cell 1, and learns from SIB1 and SIB2 that the access network device supports O-SNPN, and the terminal type corresponding to the O-SNPN supported by the access network device includes the terminal type of the terminal device. Then, the terminal device carries the cell identifier of cell 1 in the first message and sends it to the access network device, requesting access to cell 1 and performing an online subscription through the O-SNPN in the cell.
[0112] In this application, the first message may be a Radio Resource Control Setup Request (RRC setup request) message or other types of messages. When the first message is an RRC setup request message, the first message may further include the cause of the RRC connection establishment, and the cause of the RRC connection establishment includes establishing an RRC connection to provide an online subscription service for the terminal device. For example, when the terminal device belongs to the terminal type indicated by the second information, the terminal device may send an RRC setup request message carrying {cause: onboarding} to the access network device.
[0113] Exemplarily, when the terminal device receives the first information, if it is determined according to the first information that the access network device supports O-SNPN, the terminal device detects and receives the second information corresponding to the first information, determines the terminal type corresponding to the O-SNPN according to the second information, and checks whether the terminal type corresponding to the O-SNPN includes the terminal type to which the terminal device belongs. If it includes, it is determined that the terminal device belongs to the terminal type indicated by the second information, and online subscription can be performed through the O-SNPN supported by the access network device. Otherwise, if it does not include, it is determined that the terminal does not belong to the terminal type indicated by the second information, and online subscription cannot be performed through the O-SNPN supported by the access network device, that is, there is no O-SNPN in the O-SNPN supported by the access network device that can provide online services for the terminal device.
[0114] Among them, the terminal type to which the terminal device belongs is pre-configured; or, the terminal type to which the terminal device belongs is determined by the terminal device according to the certificate of the terminal device, and the certificate of the terminal device is pre-configured for the terminal device. For example, assuming the terminal type is DV, there is a pre-configured corresponding relationship between the certificate of the terminal device and the DV ID of the terminal device, and the terminal device can determine the DV ID of the terminal device according to this corresponding relationship and the certificate of the terminal device.
[0115] For example, assume that the terminal type is DV, the identifier of the terminal type is DV ID, the terminal device 1 belongs to the device provider A, and the identifier of the terminal type of the terminal device 1 is DV A. If the second information includes {DV A, DV B, DV C}, and {DV A, DV B, DVC} corresponds to the O-SNPN supported by the base station 1, since DV A is included in {DV A, DV B, DV C}, it is determined that the terminal device 1 belongs to the terminal type indicated by the second information, and online subscription can be performed through the O-SNPN supported by the base station 1; if the second information includes {DVB, DV C}, since DV A is not included in {DV B, DV C}, it is determined that the terminal device 1 does not belong to the terminal type indicated by the second information, and online subscription cannot be performed through the O-SNPN supported by the base station 1.
[0116] It should be noted that, in order to improve the accuracy of the terminal device in selecting the O-SNPN, further, Figure 4 In the method shown, after determining that the terminal device belongs to the terminal type indicated by the second information and before sending the first message to the access network device, the terminal device also needs to determine whether the O-SNPN supported by the access network device belongs to the O-SNPNs allowed for the terminal device to access. If so, then send the first message to the access network device; otherwise, do not send the first message.
[0117] Among them, the O-SNPNs allowed for the terminal device to access can be pre-configured for the terminal device. The O-SNPNs allowed for the terminal device to access can be alternatively described as the pre-configured O-SNPNs that can support the online subscription of the terminal device. For example, assume that the O-SNPNs pre-configured for the terminal device include: {O-SNPN1, O-SNPN2, O-SNPN3}. If the terminal device learns from the first information and the second information that the O-SNPN supported by the access network device and corresponding to the terminal type of the terminal device is O-SNPN1, and O-SNPN1 is included in the O-SNPNs pre-configured for the terminal device, then it is determined that O-SNPN1 provides the online subscription service for the terminal device and send the first message. Otherwise, if the terminal device learns from the first information and the second information that the O-SNPN supported by the access network device and corresponding to the terminal type of the terminal device is O-SNPN4, and O-SNPN4 is not included in the O-SNPNs pre-configured for the terminal device, then do not send the first message.
[0118] In this way, when the terminal device belongs to the terminal type indicated by the second information and whether the O-SNPN supported by the access network device belongs to the O-SNPNs allowed for the terminal device to access, then send the first message to the access network device, improving the accuracy of selecting the O-SNPN during online subscription.
[0119] In Figure 4 In a possible implementation manner of the method shown, before performing Figure 4 the steps 401 to 403 shown, the access network device can obtain the list of terminal types from the DCS with reference to Figure 5a the steps 404 to 406 shown.
[0120] Step 404: The DCS determines the identifier of the terminal type to which the terminal device belongs according to the certificate of the terminal device stored locally.
[0121] Among them, the certificate of the terminal device can be assigned by the device provider, and the device provider stores the certificate of the terminal device corresponding to the ID of the terminal device on the DCS. The ID of the terminal device can be used to uniquely represent a terminal device, and the ID of the terminal device can also be assigned by the device provider.
[0122] It should be noted that in this application, the device provider can also be referred to as a device service provider or a device manufacturer, etc. The DCS can also be replaced by other devices that can store the certificates of the terminal devices, without limitation.
[0123] Among them, in one possible implementation, there is a corresponding mapping relationship between the certificate of the terminal device and the identifier of the terminal type to which the terminal device belongs. The DCS can determine the identifier of the terminal type to which the terminal device belongs according to this corresponding relationship. In another possible implementation, the certificate of the terminal device is composed of the identifier of the terminal type to which the terminal device belongs and other preset strings. For example, the identifier of the terminal type to which the terminal device belongs can be arranged on the left (or right) side of the preset string to combine to obtain the certificate of the terminal device. The DCS can extract the identifier of the terminal type from the certificate of the terminal device according to the position of the identifier of the terminal type. In yet another possible implementation, the certificate of the terminal device and the identifier of the terminal type to which the terminal device belongs satisfy a preset calculation rule. The DCS can calculate the certificate of the terminal device according to this preset calculation rule to obtain the identifier of the terminal type to which the terminal device belongs. For example, the identifier of the terminal type to which the terminal device belongs = f(certificate of the terminal device), and f() can be a preset calculation rule.
[0124] Step 405: The DCS includes the extracted identifier of the terminal type in the list of terminal types and sends the list of terminal types to the core network device (such as Figure 2 the AUSF shown) in the S-SNPN connected to the DCS. Correspondingly, the core network device receives the list of terminal types.
[0125] Step 406: The core network device sends the list of terminal types to the access network device. Correspondingly, the access network device receives the list of terminal types.
[0126] Furthermore, in the Figure 4 method shown, after receiving the first message, the access network device can provide an online subscription service for the terminal device according to the first message. Among them, the online subscription process can refer to Figure 5b Steps 407 to 410 shown.
[0127] Step 407: The access network device determines whether to allow the terminal device to access the O-SNPN supported by the access network device according to the first message. If allowed, the access network device sends a first response to the terminal device. If not allowed, the process ends.
[0128] Exemplarily, the access network device can determine whether there is sufficient radio resource for the online subscription service currently. If the access network device currently has sufficient radio resource for the online subscription service, it allows the terminal device to access the O-SNPN supported by the access network device; otherwise, it does not allow the terminal device to access the O-SNPN supported by the access network device.
[0129] Among them, the first response can correspond to the first message, and the first response can be used to indicate that the terminal device is allowed to access the O-SNPN supported by the access network device. When the first message is an RRC setup request message, the first response can be an RRC setup response.
[0130] Step 408: The terminal device receives the first response and sends a second message to the access network device.
[0131] Among them, the second message can be an RRC setup complete message, and the second message can include the identifier of the terminal type selected by the terminal device. The identifier of the terminal type selected by the terminal device is the identifier of the terminal type to which the terminal device belongs. For example, when the terminal type is DV, the second message can include the DV ID of the terminal device. It should be noted that in addition to including the identifier of the terminal type selected by the terminal device, the second message can also include other information such as the ID of the terminal device and the certificate of the terminal device, without limitation.
[0132] Step 409: The access network device receives the second message, determines the DCS corresponding to the terminal type selected by the terminal device according to the second message, and verifies the terminal device through interaction with the DCS. If the verification is successful, step 407 is executed; otherwise, if the verification fails, the process ends.
[0133] Among them, the access network device verifying the terminal device through interaction with the DCS can include: the access network device sends the ID of the terminal device and the certificate of the terminal device to the core network device in the O-SNPN connected to the DCS; the core network device in the O-SNPN receives the ID of the terminal device and the certificate of the terminal device, sends the identifier of the terminal type selected by the terminal device to the DCS for verification, and verifies whether the ID of the terminal device and the certificate of the terminal device are included in the DCS. If they are included, the verification is successful; otherwise, the verification fails.
[0134] Step 410: The core network device in O-SNPN triggers the session management network element to establish a session between the terminal device and the PS. The terminal device sends an authentication request carrying the terminal device's certificate to the PS through the session. The PS receives the authentication request and authenticates the terminal device according to the terminal device's certificate. After successful authentication, the PS extracts the contract information and the network certificate of the S-SNPN belonging to the terminal device from the S-SNPN, and sends them to the terminal device through the above session connection. At this point, the terminal device obtains the contract information and the network certificate of the S-SNPN and completes the online contract.
[0135] based on Figure 4 In the method shown, the access network device indicates to the terminal device that the access network device supports O-SNPN and the terminal type corresponding to the O-SNPN, so that the terminal device can determine whether it belongs to the terminal type corresponding to the O-SNPN. If it is determined that it belongs to the terminal type corresponding to the O-SNPN supported by the access network device, it is determined to perform online signing through the O-SNPN supported by the access network device, and request the access network device to provide it with online signing services. Compared with the O-SNPN ID, the terminal type is a more stable information that does not change over time. Therefore, selecting O-SNPN by matching the terminal type can improve the accuracy of the terminal device selecting O-SNPN.
[0136] exist Figure 4 In the method shown, when the O-SNPN supported by the access network device is indicated at the cell granularity, the first information may include the cell identifier and the first indication information. The first indication information may be named as onboarding-Info or other names without limitation. The first indication information may be used to indicate that the SNPN in the cell identified by the cell identifier supports the online contract service. Exemplarily, when the first indication information is the first value, it indicates that the SNPN in the cell identified by the cell identifier supports the online contract service; when the first indication information is the second value or is not the first value or the first information does not include the first indication information, it is used to indicate that there is no SNPN supporting the online contract service in the cell identified by the cell identifier.
[0137] Among them, the first value and the second value can be binary bit numbers "0", "1" or binary bit numbers "1", "0", or other symbols or numbers, etc. For example, the string "true" can be used to indicate that the SNPN in the cell supports online signing services, and the string "false" can be used to indicate that there is no SNPN in the cell that supports online signing services, etc., without restriction.
[0138] For example, assume that the first piece of information includes the following field 1: NPN identification information (NPN-IdentityInfo), and this field 1 includes {NPN identification list (npn-IdentityList), cell identity (cellIdentity), online subscription information (onboarding-Info)}. The cellIdentity is used to identify the cell. The value range of the npn-IdentityList is SIZE(1..maxNPN), and (1..maxNPN) indicates that the value range of NPN is from 1 to maxNPN. One or more NPNs can be selected from 1..maxNPN as the NPNs that support online subscription services in this cell. The value of onboarding-Info is {true}, indicating that all NPNs corresponding to the NPN identification list in this cell support online subscription services. After the terminal device monitors this field, it can determine whether the NPNs in the cell support online subscription services based on the cellIdentity and onboarding-Info. Conversely, if the value of onboarding-Info is {false} or onboarding-Info does not exist, it is determined that all NPNs corresponding to the NPN identification list in this cell do not support online subscription services. It should be noted that the following field 1 is only an exemplary field, and this field 1 can also carry other information, such as it can also carry the tracking area code (trackingAreaCode), RAN area code (RAN-AreaCode) (abbreviated as ranac), and cell reserved field for operator use (cellReservedForOperatorUse). The tracking area code can be used for core network paging, and ranac can be used for radio access network paging. The value range of cellReservedForOperatorUse includes: reserved and notReserved. When the value of cellReservedForOperatorUse is reserved, it means that ordinary terminal devices cannot access the cell, and only the operator's detection devices can access it.
[0139] Field 1:
[0140]
[0141]
[0142] Correspondingly, when indicating O-SNPN at the cell granularity, the terminal type indicated by the second information corresponding to the first information may be the terminal type corresponding to the cell, and the terminal devices belonging to this terminal type can perform online subscription through the O-SNPN in the cell. For example, taking the terminal type as DV and the identifier of the terminal type as DV ID, the second information may include the following field two, and this field two includes: onboarding-Info-list, onboarding-Info corresponding to each cell. The value of onboarding-Info-list is SIZE(1..N), indicating that there are N cells, and the SNPNs in these N cells support online subscription. Each cell corresponds to a cell index, and each cell index corresponds to a DV-ID-list. The onboarding-Info corresponding to each cell includes {cell-index, dV-ID-List}. The cell-index is used to indicate a certain cell among the N cells, and the DV-ID-list represents the list of identifiers of the device providers supported by the SNPN online subscription service in the cell corresponding to this cell index.
[0143] Field two:
[0144]
[0145] Similarly, in Figure 4 In the method shown, when indicating the O-SNPN supported by the access network device at the PLMN granularity, the first information may include the identifier of the PLMN and the second indication information. The second indication information can be named onboarding-Info or other names without limitation. The second indication information can be used to indicate that the SNPN in the PLMN identified by the identifier of the PLMN supports the online subscription service. Exemplarily, when the second indication information is the third value, it indicates that the SNPN in the PLMN identified by the identifier of the PLMN supports the online subscription service; when the second indication information is the fourth value or not the third value or the first information does not include the second indication information, it is used to indicate that there is no SNPN supporting the online subscription service in the PLMN identified by the identifier of the PLMN.
[0146] Among them, the relevant descriptions of the third value and the fourth value can refer to the above first value and second value, and will not be elaborated.
[0147] For example, assume that the first information includes the following field three: NPN-Identity. This field three includes CHOICE information: pni-npn and snpn-related information. Pni-npn includes {PLMN-Identity, cag-IdentityList}, and snpn-related information includes {PLMN-Identity, nid-List, onboarding-Info}. Plmn-Identity is used to identify the PLMN. The value range of nid-List is SIZE(1..maxNPN), where (1..maxNPN) indicates that the value range of NPN is from 1 to maxNPN. One or more NPNs can be selected from 1..maxNPN as the NPNs that support the online subscription service in this PLMN. The value of onboarding-Info is {true}, indicating that all NPNs corresponding to the NPN-Identity list in this PLMN support the online subscription service. After the terminal device monitors this field, it can determine whether the NPNs in the PLMN support the online subscription service based on plmn-Identity and onboarding-Info. Conversely, if the value of onboarding-Info is {false} or onboarding-Info does not exist, it is determined that all NPNs corresponding to the NPN-Identity list in this PLMN do not support the online subscription service. It should be noted that the following field three is only an exemplary field, and this field three can also carry other information without limitation.
[0148] Field three:
[0149]
[0150]
[0151] Correspondingly, when indicating the O-SNPN at the PLMN granularity, the terminal type indicated by the second information corresponding to the first information may be the terminal type corresponding to the PLMN, and the terminal devices belonging to this terminal type may perform online subscription through the O-SNPN in the PLMN. For example, taking the terminal type as DV and the identifier of the terminal type as DV ID as an example, the second information may include the following field four, and this field four includes: onboarding-Info-list, onboarding-Info corresponding to each PLMN. The value of onboarding-Info-list is SIZE(1..N), indicating that there are N PLMNs, and the SNPNs in these N PLMNs support online subscription. Each PLMN corresponds to a PLMN index, each PLMN index corresponds to a DV-ID-list, and the onboarding-Info corresponding to each PLMN includes {cell-index, dV-ID-List}. The cell-index is used to indicate a certain PLMN among the N PLMNs, and the DV-ID-list represents the list of identifiers of the device providers supported by the online subscription service of the SNPN in the PLMN corresponding to this PLMN index.
[0152] Field four:
[0153]
[0154] Similarly, in Figure 4 In the method shown, when indicating the O-SNPN supported by the access network device at the SNPN granularity, the first information may include the identifier of the SNPN and the third indication information. The third indication information may be named onboarding-Info or other names without limitation. The third indication information may be used to indicate that the SNPN identified by the identifier of the SNPN supports the online subscription service. Exemplarily, when the third indication information is the fifth value, it indicates that the SNPN identified by the identifier of the SNPN supports the online subscription service; when the third indication information is the sixth value or not the fifth value or the first information does not include the third indication information, it is used to indicate that the SNPN identified by the identifier of the SNPN does not support the online subscription service.
[0155] Among them, the relevant descriptions of the fifth value and the sixth value can refer to the above-mentioned first value and second value, and will not be elaborated here.
[0156] For example, assume that the first information includes the following field five: NPN-Identity, and this field five includes CHOICE information: pni-npn and snpn-r16 related information. pni-npn includes {plmn-Identity (PLMN identifier), cag-IdentityList (cell area identifier list)}. pni-npn is optional and can be included in field five or not. snpn-r16 includes {plmn-Identity (PLMN identifier), nid-List (network identifier list), onboarding-Info (online subscription information) corresponding to a network under the PLMN identified by nid}. plmn-Identity is used to identify the PLMN. The value range of nid-List is SIZE(1..maxNPN), and (1..maxNPN) means that the PLMN can include 1 to maxNPN networks, that is, it can include 1 to maxNPN SNPNs. Each SNPN corresponds to an onboarding-Info, and the onboarding-Info corresponding to each SNPN includes {nid, onboarding-Info}. The value of onboarding-Info is {true}, which is used to indicate that a specific SNPN identified by nid supports the online subscription service. Conversely, if the value of onboarding-Info is {false} or onboarding-Info does not exist, it is determined that a specific SNPN identified by nid does not support the online subscription service. It should be noted that the following field five is only an exemplary field, and this field five can also carry other information without limitation.
[0157] Field five:
[0158]
[0159] Correspondingly, when indicating an O-SNPN at the SNPN granularity, the terminal type indicated by the second information corresponding to the first information may be the terminal type corresponding to the SNPN, and the terminal devices belonging to this terminal type may perform online subscription through the SNPN. For example, taking the terminal type as DV and the identifier of the terminal type as DV ID, the second information may include the following field six, and this field six includes: onboarding-Info-list, onboarding-Info corresponding to each SNPN. The value of onboarding-Info-list is SIZE(1..N), indicating that there are N SNPNs, and the SNPNs among the N SNPNs support online subscription. Each SNPN corresponds to a DV-ID-list, and the onboarding-Info corresponding to each SNPN includes {plmn-Identity, nid, dV-ID-List}. plmn-Identity + nid can uniquely identify an SNPN, and DV-ID-list represents the list of identifiers of the device providers supported by this SNPN.
[0160] Field six:
[0161]
[0162] Taking the terminal type as DV and the terminal device as a brand mobile phone produced by mobile phone manufacturer A as an example, and the first information is carried in SIB1 and the second information is carried in SIBX, the above method will be illustrated by combining the application scenario of a user performing online subscription in a shopping mall: The shopping mall has built an SNPN, which is connected to the DCS of a certain mobile phone manufacturer A, and this SNPN can provide online subscription services for this brand of mobile phone. Then, the cell of this SNPN can broadcast information supporting online subscription for this brand of mobile phone, such as the first information and the second information. When this brand of mobile phone is initially started and finds that it can perform online subscription in this SNPN, it sends an access request to this SNPN and informs its manufacturer identifier. The SNPN reports the information of this device to the DCS of this mobile phone manufacturer, and the DCS performs device authentication. If the authentication passes, the online subscription process can be started. Specifically, this process can be referred to Figure 6 as shown.
[0163] Figure 6 is a flowchart of an online subscription method provided by an embodiment of this application. As Figure 6 shown, the method includes:
[0164] Step 601: The DCS stores the ID of the mobile phone and the certificate of the mobile phone, and obtains the DVID of the mobile phone according to the certificate of the mobile phone.
[0165] Among them, the DCS can be the DCS of a certain mobile phone manufacturer A, or the DCS can be a DCS shared by multiple mobile phone manufacturers, without limitation. The mobile phone manufacturer can assign an ID and a certificate to each mobile phone produced by itself, and pre-configure the ID of the mobile phone and the certificate of the mobile phone on the DCS. There is a corresponding relationship between the certificate of the mobile phone and the DV ID of the mobile phone, and the DV ID of the mobile phone is extracted from the certificate of the mobile phone.
[0166] Step 602: The DCS sends a DV list to the access network device through the core network element, and the DV list includes one or more DV IDs supported by the DCS.
[0167] Step 603: The access network device receives the DV list and sends SIB1 and SIBX.
[0168] Step 604: When the mobile phone is initially started, it detects SIB1 and SIBX, discovers that it can perform online signing at a certain SNPN supported by the access network device according to SIB1 and SIBX, and sends an RRC establishment request (RRC Setuprequest) message to the access network device.
[0169] Step 605: The access network device determines whether to allow the mobile phone to access the SNPN according to the RRC establishment request message. If allowed, step 606 is executed.
[0170] Exemplarily, if the access network device currently has sufficient radio resources for online signing services, the mobile phone is allowed to access the SNPN. Otherwise, the mobile phone is not allowed to access the SNPN.
[0171] Step 606: The access network device sends an RRC establishment (RRC Setup) response to the mobile phone. The RRC establishment response corresponds to the RRC establishment request message, and the RRC establishment response can be used to indicate that the mobile phone is allowed to access.
[0172] Step 607: The mobile phone receives the RRC establishment response and sends an RRC establishment complete ((RRC Setupcomplete) message to the access network device.
[0173] Among them, the RRC establishment complete message may include the DV ID selected by the mobile phone, and the identifier of the selected DV of the mobile phone is the identifier of the DV to which the mobile phone belongs; the RRC establishment complete message may also include other information such as the ID of the mobile phone and the certificate of the mobile phone;
[0174] Step 608: The access network device receives the RRC connection setup complete message, determines the DCS corresponding to the DV selected by the mobile phone according to the RRC connection setup complete message, and sends the ID of the mobile phone and the certificate of the mobile phone to the DCS for verification through the core network device in the O-SNPN connected to the DCS, and verifies whether the ID of the mobile phone and the certificate of the mobile phone are included in the DCS. If they are included, the verification is successful; otherwise, the verification fails.
[0175] Step 609: In the case of successful verification, the core network device in the O-SNPN triggers the session management network element to establish a session between the mobile phone and the PS. The mobile phone sends an authentication request carrying the certificate of the mobile phone to the PS through this session. The PS receives the authentication request and authenticates the mobile phone according to the certificate of the mobile phone. After successful authentication, the PS extracts the subscription information of the S-SNPN belonging to the mobile phone and the network certificate of the S-SNPN from the S-SNPN and sends them to the mobile phone through the above session connection.
[0176] So far, the mobile phone has obtained the subscription information of the S-SNPN and the network certificate of the S-SNPN, and completed the online subscription.
[0177] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between each node. It can be understood that in order to implement the above functions, each node, such as the access network device and the terminal device, includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, combined with the algorithm steps of each example described in the embodiments disclosed in this article, the method of the embodiment of the present application can be implemented in the form of hardware, software, or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0178] The embodiment of the present application can divide the functional modules of the access network device and the terminal device according to the above method examples. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. It should be noted that the division of modules in the embodiment of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation.
[0179] Figure 7The structure diagram of a communication device 70 is shown. The communication device 70 can be a terminal device, a chip in the terminal device, a system on a chip, or other devices that can implement the functions of the terminal device in the above method, etc. The communication device 70 can be used to execute the functions of the terminal device involved in the above method embodiments. As an implementable manner, Figure 7 The shown communication device 70 includes: a receiving unit 701, a processing unit 702, and a transmitting unit 703.
[0180] The receiving unit 701 is configured to receive a first piece of information and a second piece of information from an access network device. The first piece of information is used to indicate the online subscription independent non-public network O-SNPN supported by the access network device, and the second piece of information is used to indicate the terminal type corresponding to the O-SNPN. For example, the receiving unit 701 supports the communication device 70 to execute step 402.
[0181] The processing unit 702 is configured to determine that the terminal device belongs to the terminal type corresponding to the O-SNPN. For example, the processing unit 702 is used to support the communication device 70 to execute the action of determining whether the terminal device belongs to the terminal type corresponding to the O-SNPN in step 403.
[0182] The transmitting unit 703 is configured to send a first message to the access network device. The first message is used to request the access network device to provide an online subscription service for the terminal device. For example, the transmitting unit 703 supports the communication device 70 to execute step 403.
[0183] Specifically, all relevant contents of each step involved in the above Figures 4 - 6 shown method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here. The communication device 70 is used to execute Figures 4 - 6 the functions of the terminal device in the online subscription method shown in the shown method, so the same effects as the above online subscription method can be achieved.
[0184] As another implementable manner, Figure 7 the shown communication device 70 includes: a processing module and a communication module. The processing module is used to control and manage the actions of the communication device 70. For example, the processing module can integrate the functions of the processing unit 702 and can be used to support the communication device 70 to execute the action of determining whether the terminal device belongs to the terminal type corresponding to the O-SNPN and other processes of the technologies described in this article. The communication module can integrate the functions of the receiving unit 701 and the transmitting unit 703 and can be used to support the communication device 70 to execute step 402, step 403, and communicate with other network entities, such as communicating with Figure 1 the shown functional modules or network entities. The communication device 70 may further include a storage module for storing instructions and / or data. When the instructions are executed by the processing module, the processing module implements the above method on the terminal device side.
[0185] Among them, the processing module can be a processor, a controller, a module, or a circuit. It can implement or execute various exemplary logic blocks described in connection with the disclosure of this application. The communication module can be a transceiver circuit, a pin, an interface circuit, a bus interface, or a communication interface, etc. The storage module can be a memory. When the processing module is a processor, the communication module is a communication interface, and the storage module is a memory, the communication device 70 involved in the embodiments of this application can be Figure 3 the communication device shown.
[0186] Figure 8 The structural diagram of a communication device 80 is shown. The communication device 80 can be an access network device, a chip in the access network device, a system on a chip, or other devices that can implement the functions of the access network device in the above method, etc. The communication device 80 can be used to execute the functions of the access network device involved in the method embodiments above. As an implementable manner, Figure 8 the communication device 80 shown includes: a sending unit 801 and a receiving unit 802.
[0187] The sending unit 801 is used to send a first piece of information and a second piece of information. The first piece of information is used to indicate the online subscription independent non-public network O-SNPN supported by the access network device, and the second piece of information is used to indicate the terminal type corresponding to the O-SNPN. For example, the sending unit 801 can be used to support the communication device 80 to execute step 401.
[0188] The receiving unit 802 is used to receive a first message from the terminal device when the terminal device belongs to the terminal type corresponding to the O-SNPN. The first message is used to request the access network device to provide an online subscription service for the terminal device. For example, the receiving unit 802 can be used to support the communication device 80 to execute step 403.
[0189] Specifically, all relevant contents of each step involved in the above Figure 4 method embodiments can be cited in the function descriptions of the corresponding functional modules and will not be elaborated here. The communication device 80 is used to execute Figure 4 the functions of the access network device in the online subscription method shown in the method shown, and thus can achieve the same effects as the above online subscription method.
[0190] As another implementable manner, Figure 8The communication device 80 shown includes: a processing module and a communication module. The processing module is used to control and manage the operations of the communication device 80. For example, the processing module can integrate the functions of a processing unit and can be used to support the communication device 80 in performing operations other than the transmission and reception operations of the access network device described herein. The communication module can integrate the functions of a transmitting unit 801 and a receiving unit 802 and can be used to support the communication device 80 in performing step 401 and communicating with other network entities, such as communicating with Figure 1 the functional modules or network entities shown. The communication device 80 may further include a storage module for storing instructions and / or data of the communication device 80. When the instructions are executed by the processing module, the processing module can implement the method on the access network device side as described above.
[0191] Among them, the processing module can be a processor, a controller, a module, or a circuit. It can implement or execute various exemplary logic blocks described in connection with the disclosure of the present application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on. The communication module can be a transceiver circuit, a pin, an interface circuit, a bus interface, or a communication interface, etc. The storage module can be a memory. When the processing module is a processor, the communication module is a communication interface, and the storage module is a memory, the communication device 80 involved in the embodiments of the present application can be Figure 3 the communication device shown.
[0192] In the embodiments of the present application, the processor can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in connection with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor.
[0193] In the embodiments of the present application, the memory can be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), etc., and can also be a volatile memory, such as a random-access memory (RAM). The memory is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function for storing instructions and / or data.
[0194] Figure 9 This is a structural diagram of a communication system provided by an embodiment of the present application. As Figure 9 shown, the communication system may include: a terminal device 90 and an access network device 91. Among them, the terminal device 90 may have the functions of the above-mentioned communication device 70. The access network device 91 may have the functions of the above-mentioned communication device 80.
[0195] For example, the access network device 91 is used to send first information indicating the O-SNPN supported by the access network device 91 and second information indicating the terminal type corresponding to the O-SNPN;
[0196] The terminal device 90 is used to receive the first information and the second information from the access network device 91. When the terminal device 90 belongs to the terminal type corresponding to the O-SNPN, the terminal device 90 sends a first message to the access network device 91. The first message is used to request the access network device 91 to provide an online subscription service for the terminal device 90;
[0197] The access network device 91 is further used to receive the first message from the terminal device 90.
[0198] Specifically, the specific implementation process of the terminal device 90 may refer to the execution process of the terminal device in the above Figure 4 method embodiment, which will not be elaborated here. The specific implementation process of the access network device 91 may refer to the execution process of the access network device 91 in the above Figure 4 method embodiment, which will not be elaborated here.
[0199] An embodiment of the present application further provides a computer-readable storage medium. All or part of the processes in the above method embodiments may be completed by a computer program instructing relevant hardware. The program may be stored in the above computer-readable storage medium. When the program is executed, it may include the processes of the above method embodiments. The computer-readable storage medium may be the terminal device in any of the foregoing embodiments, such as: an internal storage unit including a data sending end and / or a data receiving end, such as a hard disk or memory of the terminal device. The above computer-readable storage medium may also be an external storage device of the above terminal device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the above terminal device. Further, the above computer-readable storage medium may also include both the internal storage unit of the above terminal device and the external storage device. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above terminal device. The above computer-readable storage medium may also be used to temporarily store data that has been output or will be output.
[0200] The embodiments of the present application also provide a computer instruction. All or part of the processes in the above method embodiments can be completed by a computer instruction to instruct related hardware (such as a computer, a processor, a network device, a terminal, etc.). This program can be stored in the above computer-readable storage medium.
[0201] The embodiments of the present application also provide a chip system. The chip system can be composed of chips, or can include chips and other discrete devices, without limitation. The chip system includes a processor and a communication interface. All or part of the processes in the above method embodiments can be completed by the chip system. For example, the chip system can be used to implement the functions performed by the terminal device in the above method embodiments, or implement the functions performed by the terminal device in the above method embodiments. Taking the chip system can be used to implement the functions performed by the terminal device in the above method embodiments as an example, the processor is used to receive, through the communication interface, the first information for indicating the O-SNPN supported by the access network device and the second information for indicating the terminal type corresponding to the O-SNPN from the access network device. When the terminal device belongs to the terminal type corresponding to the O-SNPN, the processor sends a first message for requesting the access network device to provide an online subscription service for the terminal device to the access network device. Taking the chip system can be used to implement the functions performed by the access network device in the above method embodiments as an example, the processor is used to send, through the communication interface, the first information for indicating the O-SNPN supported by the access network device and the second information for indicating the terminal type corresponding to the O-SNPN, and receive, through the communication interface, the first message sent by the terminal device.
[0202] In a possible design, the above chip system further includes a memory, and the memory is used to store program instructions and / or data. When the chip system runs, the processor executes the program instructions stored in the memory, so that the chip system executes the functions performed by the terminal device in the above method embodiments or executes the functions performed by the terminal device in the above method embodiments.
[0203] It should be noted that the terms "first" and "second" in the specification, claims and drawings of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.
[0204] It should be understood that in the embodiments of the present application, "at least one (item)" means one or more, "a plurality" means two or more, "at least two (items)" means two or three or more, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one)" or its similar expression below refers to any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple. It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A. For example, B can be determined according to A. It should also be understood that determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information. In addition, the "connection" that appears in the embodiments of the present application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices, and the embodiments of the present application do not make any limitations on this.
[0205] Unless otherwise specified, the "transmission" (transmit / transmission) that appears in the embodiments of the present application refers to two-way transmission, including the actions of sending and / or receiving. Specifically, the "transmission" in the embodiments of the present application includes the sending of data, the receiving of data, or the sending and receiving of data. Or rather, the data transmission here includes uplink and / or downlink data transmission. The data can include channels and / or signals. The uplink data transmission is the uplink channel and / or uplink signal transmission, and the downlink data transmission is the downlink channel and / or downlink signal transmission. The "network" and "system" that appear in the embodiments of the present application express the same concept, and the communication system is the communication network.
[0206] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0207] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.
[0208] The units described as separate components may or may not be physically separated. The components displayed as units can be one physical unit or multiple physical units, that is, they can be located in one place, or they can also be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0209] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0210] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to enable a device, such as a single-chip microcomputer, a chip, etc., or a processor to execute all or part of the steps of the methods described in each embodiment of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0211] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any change or replacement within the technical scope disclosed in this application should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claimed rights.
Claims
1. An online signing method, characterized in that, The method includes: The terminal device receives first information and second information from the access network device. The first information is used to indicate the online-signing-enabled standalone non-public network (O-SNPN) supported by the access network device, and the second information is used to indicate the terminal type corresponding to the O-SNPN. When the terminal device belongs to the terminal type corresponding to the O-SNPN, the terminal device sends a first message to the access network device. The first message is used to request the access network device to provide online-signing services for the terminal device.
2. The method according to claim 1, characterized in that, The first information includes an identifier of a cell and first indication information. The first indication information is used to indicate that the SNPN in the cell supports online-signing services.
3. The method according to claim 1, wherein The first information includes an identifier of a public land mobile network (PLMN) and second indication information. The second indication information is used to indicate that the SNPN in the PLMN supports online-signing services.
4. The method according to claim 1, wherein The first information includes an identifier of the SNPN and third indication information. The third indication information is used to indicate that the SNPN supports online-signing services.
5. The method according to any one of claims 1-4, characterized in that, The second information includes an identifier of the terminal type corresponding to the O-SNPN. The method further includes: When the identifier of the terminal type to which the terminal device belongs is included in the second information, it is determined that the terminal device belongs to the terminal type corresponding to the O-SNPN.
6. The method according to any one of claims 1-4, characterized in that The terminal type to which the terminal device belongs is pre-configured; or The terminal type to which the terminal device belongs is determined by the terminal device according to the certificate of the terminal device, and the certificate of the terminal device is pre-configured for the terminal device.
7. The method according to any one of claims 1-4, characterized in that The O-SNPN supported by the access network device belongs to the O-SNPNs allowed for the terminal device to access.
8. The method according to any one of claims 1-4, characterized in that, The method further includes: The terminal device sends a second message to the access network device. The second message carries the identifier of the terminal type selected by the terminal device.
9. An online signing method, characterized in that, The method includes: The access network device sends first information and second information. The first information is used to indicate the online-signing-enabled standalone non-public network (O-SNPN) supported by the access network device, and the second information is used to indicate the terminal type corresponding to the O-SNPN. When the terminal device belongs to the terminal type corresponding to the O-SNPN, the access network device receives a first message from the terminal device. The first message is used to request the access network device to provide online-signing services for the terminal device.
10. The method according to claim 9, characterized in that The first information includes an identifier of a cell and first indication information. The first indication information is used to indicate that the SNPN in the cell supports online-signing services.
11. The method according to claim 9, wherein The first information includes an identifier of a public land mobile network (PLMN) and second indication information. The second indication information is used to indicate that the SNPN in the PLMN supports online-signing services.
12. The method according to claim 9, wherein The first information includes an identifier of the SNPN and third indication information. The third indication information is used to indicate that the SNPN supports online-signing services.
13. The method according to any one of claims 9-12, characterized in that, The second information includes an identifier of the terminal type corresponding to the O-SNPN.
14. The method according to claim 13, wherein The method further includes: The access network device obtains the identifier of the terminal type corresponding to the O-SNPN from a default certificate server DCS, and the DCS is connected to the O-SNPN.
15. The method according to any one of claims 9-12, wherein The O-SNPN supported by the access network device belongs to the O-SNPNs that allow the terminal device to access.
16. The method according to any one of claims 9-12, characterized in that, The method further includes: The access network device receives a second message from the terminal device, and the second message carries an identifier of the terminal type selected by the terminal device.
17. A communication device, characterized in that, The communication device includes: A receiving unit, configured to receive first information and second information from an access network device, where the first information is used to indicate an online subscription independent non-public network O-SNPN supported by the access network device, and the second information is used to indicate the terminal type corresponding to the O-SNPN; A sending unit, configured to send a first message to the access network device when the terminal device belongs to the terminal type corresponding to the O-SNPN, where the first message is used to request the access network device to provide an online subscription service for the terminal device.
18. The communication device according to claim 17, characterized in that, The first information includes an identifier of a cell and a first indication information, and the first indication information is used to indicate that the SNPN in the cell supports an online subscription service.
19. The communication device according to claim 17, wherein The first information includes an identifier of a public land mobile network PLMN and a second indication information; the second indication information is used to indicate that the SNPN in the PLMN supports an online subscription service.
20. The communication device according to claim 17, characterized in that, The first information includes an identifier of the SNPN and a third indication information, and the third indication information is used to indicate that the SNPN supports an online subscription service.
21. The communication device according to any one of claims 17-20, characterized in that, The second information includes an identifier of the terminal type corresponding to the O-SNPN; the communication device further includes: A processing unit, configured to determine that the terminal device belongs to the terminal type corresponding to the O-SNPN when the identifier of the terminal type to which the terminal device belongs is included in the second information.
22. The communication device according to any one of claims 17-20, wherein The terminal type to which the terminal device belongs is pre-configured; or, The terminal type to which the terminal device belongs is determined by the terminal device according to the certificate of the terminal device, and the certificate of the terminal device is pre-configured for the terminal device.
23. The communication device according to any one of claims 17 - 20, characterized in that, The O-SNPN supported by the access network device belongs to the O-SNPNs that allow the communication device to access.
24. The communication device according to any one of claims 17-20, wherein The sending unit is further configured to send a second message to the access network device, and the second message carries an identifier of the communication device type selected by the communication device.
25. A communication device, characterized in that, The communication device includes: A sending unit, configured to send first information and second information, where the first information is used to indicate an online subscription independent non-public network O-SNPN supported by an access network device, and the second information is used to indicate the terminal type corresponding to the O-SNPN; A receiving unit, configured to receive, when the terminal device belongs to the terminal type corresponding to the O-SNPN, a first message from the terminal device, where the first message is used to request the access network device to provide an online subscription service for the terminal device.
26. The communication device according to claim 25, wherein The first information includes an identifier of a cell and first indication information, where the first indication information is used to indicate that the SNPN in the cell supports an online subscription service.
27. The communication device according to claim 25, wherein The first information includes an identifier of a public land mobile network (PLMN) and second indication information; the second indication information is used to indicate that the SNPN in the PLMN supports an online subscription service.
28. The communication device according to claim 25, wherein The first information includes an identifier of the SNPN and third indication information, where the third indication information is used to indicate that the SNPN supports an online subscription service.
29. The communication device according to any one of claims 25-28, characterized in that, The second information includes an identifier of the terminal type corresponding to the O-SNPN.
30. The communication device according to claim 29, wherein the receiving unit is further configured to obtain, from a default certificate server (DCS), an identifier of the terminal type corresponding to the O-SNPN, where the DCS is connected to the O-SNPN.
31. The communication device according to any one of claims 25-28, characterized in that, The O-SNPN supported by the access network device belongs to the O-SNPNs that allow the terminal device to access.
32. The communication device according to any one of claims 25-28, wherein the receiving unit is further configured to receive a second message from the terminal device, where the second message carries an identifier of the terminal type selected by the terminal device.
33. A communication system, characterized in that, The communication system includes: An access network device that sends first information and second information, where the first information is used to indicate an online subscription stand-alone non-public network (O-SNPN) supported by the access network device, and the second information is used to indicate the terminal type corresponding to the O-SNPN; A terminal device, configured to receive the first information and the second information from the access network device, and when the terminal device belongs to the terminal type corresponding to the O-SNPN, send a first message to the access network device, where the first message is used to request the access network device to provide an online subscription service for the terminal device; The access network device is further configured to receive the first message from the terminal device.
34. A communication device, characterized in that, The communication device includes a processor and a communication interface, where the processor and the communication interface are used to support the communication device to execute the online subscription method according to any one of claims 1-8 or the online subscription method according to any one of claims 9-16.
35. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions run on a computer, the computer is caused to execute the online subscription method according to any one of claims 1-8 or the online subscription method according to any one of claims 9-16.
Citation Information
Patent Citations
Mobile communication private network key generation method and device and controller
CN110753346A