Information Processing Method, Apparatus, Communication Device, and Readable Storage Medium

The terminal and network capability information are obtained through the network side equipment, the access policy is determined and the indication information is sent, which solves the problem that the terminal does not support or is not allowed in the independent non-public network, and realizes the effective network selection and certificate download process.

CN114885320BActive Publication Date: 2025-07-04VIVO MOBILE COMM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110164997.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-05
Publication Date
2025-07-04
Estimated Expiration
2041-02-05

AI Technical Summary

Technical Problem

When the terminal is connected to an independent non-public network, the existing technology cannot effectively solve the situation where the network does not support or is not allowed during the certificate download process, resulting in the terminal being unable to correctly select the network for certificate download.

Method used

The network side device obtains the capability information of the terminal and the network, determines whether to accept or refuse access, sends instructions to indicate that the certificate and contract mode are supported or not supported, and the terminal updates the network list according to the reasons for the rejection to avoid selecting the unsupported network again.

Benefits of technology

Ensure that the terminal can identify the support for certificate download, maintain appropriate network lists, and improve the success rate and efficiency of the certificate download process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114885320B_ABST
    Figure CN114885320B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides an information processing method, apparatus, communication device, and readable storage medium, which relate to the field of communication technologies. The specific implementation solution includes: obtaining first information; performing a first operation according to the first information; the first information includes at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the certificate requested by the terminal and / or the signing acquisition method; the first operation includes at least one of the following: determining to accept the access of the terminal, or determining to reject the access of the terminal; determining the reason for rejection; determining the value of the first indication information; including the first reason for rejection in a first message and sending the first message; including the first indication information in a second message and sending the second message; the first message is a message for rejecting the access of the terminal; the second message is a message for accepting the access of the terminal. Using the solution in the present application, it is convenient for the terminal to maintain the first list and network selection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communication technologies, and in particular, to an information processing method, apparatus, communication device, and readable storage medium. Background Art

[0002] Currently, in order for a terminal to download a certificate for accessing a Standalone Non-public Network (SNPN), it can access another network. A first list can be configured on the terminal, and the terminal can obtain certificates of other networks by accessing the networks in the first list. However, in some cases, the networks in the first list may not allow or support the certificate download type of the terminal. At this time, the first list needs to be operated to avoid selecting the corresponding network. Based on this, how to ensure the certificate download process of the terminal is an urgent problem to be solved currently. Summary of the Invention

[0003] Embodiments of the present application provide an information processing method, apparatus, communication device, and readable storage medium for solving the problem of how to ensure the certificate download process of the terminal.

[0004] In a first aspect, an information processing method is provided, which is applied to a network-side device and includes:

[0005] Obtain first information;

[0006] Perform a first operation according to the first information;

[0007] Wherein, the first information includes at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the certificate and / or subscription acquisition method requested by the terminal;

[0008] Wherein, the first operation includes at least one of the following:

[0009] Determine to accept the access of the terminal or determine to reject the access of the terminal;

[0010] Determine the reason for rejection;

[0011] Determine the value of the first indication information;

[0012] Include the first reason for rejection in the first message and send the first message;

[0013] Include the first indication information in the second message and send the second message;

[0014] Wherein, the first message is a message for rejecting the access of the terminal; the second message is a message for accepting the access of the terminal;

[0015] Wherein, the first indication information is used to indicate at least one of the following: support or not support configuring a certificate and / or signing; support or not support configuring a certificate and / or signing through the control plane; support or not support configuring a certificate and / or signing through the user plane;

[0016] Wherein, the first rejection reason is used to indicate at least one of the following: not allowing or not supporting the terminal to obtain a certificate and / or sign, not allowing or not supporting the terminal to obtain a certificate and / or sign through the control plane, not allowing or not supporting the terminal to obtain a certificate and / or sign through the user plane, the network does not allow the terminal to access, the SNPN does not allow, the PLMN does not allow;

[0017] Wherein, the capability information of the terminal includes at least one of the following: support or not support obtaining a certificate and / or signing, support or not support obtaining a certificate and / or signing through the control plane, support or not support obtaining a certificate and / or signing through the user plane;

[0018] The capability information of the first network and / or the capability information of the first server includes at least one of the following: support or not support configuring a certificate and / or signing, support or not support configuring a certificate and / or signing through the control plane, support or not support configuring a certificate and / or signing through the user plane;

[0019] The access type information of the terminal accessing the first network includes one of the following: the type of the first access method, the type of non-first access method;

[0020] The first access method includes at least one of the following: an access method for accessing the network to obtain a certificate and / or sign, an access method using a restricted access network, an access method using a default certificate to access the network;

[0021] The method for obtaining a certificate and / or signing requested by the terminal includes at least one of the following: obtaining a certificate and / or signing through the control plane, obtaining a certificate and / or signing through the user plane.

[0022] In a second aspect, an information processing method is provided, which is applied to a terminal and includes:

[0023] Performing a second operation;

[0024] Wherein, the second operation includes at least one of the following:

[0025] Determining to initiate deregistration from the first network, or determining not to initiate deregistration from the first network;

[0026] Initiating deregistration from the first network;

[0027] Removing the first network from the first list;

[0028] Move the first network into the second list;

[0029] Wherein, the first list includes any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the first list include at least one of the following: the terminal can access in a restricted manner, can enable the terminal to obtain a certificate and / or sign a contract, the terminal can access using a default certificate;

[0030] Alternatively, the first list includes at least one of the following: a list of networks that can be accessed in a restricted manner, a list of networks that can configure a certificate and / or sign a contract, a list of networks that can access using a default certificate;

[0031] Wherein, the second list includes any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the second list include at least one of the following: the terminal cannot access, cannot enable the terminal to obtain a certificate and / or sign a contract, the terminal cannot access using a default certificate;

[0032] Alternatively, the second list includes at least one of the following: a list of networks that cannot be accessed in a restricted manner, a list of networks that cannot configure a certificate and / or sign a contract, a list of networks that cannot access using a default certificate;

[0033] The network list includes one or more network objects, or, the network list includes identification information of one or more network objects;

[0034] The network object includes a network and / or a network group.

[0035] In a third aspect, an information processing device is provided, which is applied to a network-side device and includes:

[0036] An acquisition module, configured to acquire first information;

[0037] A first execution module, configured to perform a first operation according to the first information;

[0038] Wherein, the first information includes at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the certificate and / or contract acquisition method requested by the terminal;

[0039] Wherein, the first operation includes at least one of the following:

[0040] Determine to accept the terminal access, or determine to reject the terminal access;

[0041] Determine the reason for rejection;

[0042] Determine the value of the first indication information;

[0043] Include a first rejection reason in a first message and send the first message;

[0044] Include first indication information in a second message and send the second message;

[0045] Wherein, the first message is a message for rejecting the access of a terminal; the second message is a message for accepting the access of a terminal;

[0046] Wherein, the first indication information is used to indicate at least one of the following: supporting or not supporting the configuration of a certificate and / or subscription; supporting or not supporting the configuration of a certificate and / or subscription in a control plane manner; supporting or not supporting the configuration of a certificate and / or subscription in a user plane manner;

[0047] Wherein, the first rejection reason is used to indicate at least one of the following: not allowing or not supporting the terminal to obtain a certificate and / or subscription, not allowing or not supporting the terminal to obtain a certificate and / or subscription in a control plane manner, not allowing or not supporting the terminal to obtain a certificate and / or subscription in a user plane manner, the network does not allow the terminal to access, the SNPN does not allow, the PLMN does not allow;

[0048] Wherein, the capability information of the terminal includes at least one of the following: supporting or not supporting the obtaining of a certificate and / or subscription, supporting or not supporting the obtaining of a certificate and / or subscription in a control plane manner, supporting or not supporting the obtaining of a certificate and / or subscription in a user plane manner;

[0049] The capability information of the first network and / or the capability information of the first server includes at least one of the following: supporting or not supporting the configuration of a certificate and / or subscription, supporting or not supporting the configuration of a certificate and / or subscription in a control plane manner, supporting or not supporting the configuration of a certificate and / or subscription in a user plane manner;

[0050] The access type information of the terminal accessing the first network includes one of the following: the type of the first access mode, the type of a non-first access mode;

[0051] The first access mode includes at least one of the following: an access mode for accessing the network to obtain a certificate and / or subscription, an access mode for accessing a restricted access network, an access mode for accessing the network with a default certificate;

[0052] The certificate and / or subscription obtaining mode requested by the terminal includes at least one of the following: obtaining a certificate and / or subscription in a control plane manner, obtaining a certificate and / or subscription in a user plane manner.

[0053] Fourthly, an information processing device is provided, which is applied to a terminal and includes:

[0054] A second execution module, configured to execute a second operation;

[0055] Wherein, the second operation includes at least one of the following:

[0056] Determine to initiate deregistration from the first network, or determine not to initiate deregistration from the first network;

[0057] Initiate deregistration from the first network;

[0058] Remove the first network from the first list;

[0059] Move the first network into the second list;

[0060] Wherein, the first list includes any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the first list include at least one of the following: the terminal can access them in a restricted manner, can enable the terminal to obtain a certificate and / or sign a contract, the terminal can access using a default certificate;

[0061] Or, the first list includes at least one of the following: a list of networks that can be accessed in a restricted manner, a list of networks that can configure a certificate and / or sign a contract, a list of networks that can access using a default certificate;

[0062] Wherein, the second list includes any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the second list include at least one of the following: the terminal cannot access them, cannot enable the terminal to obtain a certificate and / or sign a contract, the terminal cannot access using a default certificate;

[0063] Or, the second list includes at least one of the following: a list of networks that cannot be accessed in a restricted manner, a list of networks that cannot configure a certificate and / or sign a contract, a list of networks that cannot access using a default certificate;

[0064] The network list includes one or more network objects, or, the network list includes identification information of one or more network objects;

[0065] The network object includes a network and / or a network group.

[0066] In a fifth aspect, an embodiment of the present application provides a communication device, including a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, it implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect.

[0067] In a sixth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect.

[0068] In a seventh aspect, a chip is provided, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is configured to run programs or instructions to implement the steps of the method described in the first aspect or the steps of the method described in the second aspect.

[0069] In the embodiments of the present application, by means of the operations performed by the network-side device, the terminal can be made to know whether its acquisition of a certificate and / or signing is supported or not, thereby facilitating the terminal to maintain the first list and network selection. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present application. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0071] Figure 1 is a schematic diagram of the architecture of a wireless communication system provided by an embodiment of the present application;

[0072] Figure 2 is a schematic flowchart of an information processing method according to an embodiment of the present application;

[0073] Figure 3 is a schematic flowchart of an information processing method according to another embodiment of the present application;

[0074] Figure 4 is a schematic flowchart of an information processing method for Application Scenario 1 according to an embodiment of the present application;

[0075] Figure 5 is a schematic flowchart of an information processing method for Application Scenario 2 according to an embodiment of the present application;

[0076] Figure 6 is a schematic diagram of the structure of an information processing device provided by the present application;

[0077] Figure 7 is a schematic diagram of the structure of another information processing device provided by the present application;

[0078] Figure 8 is a structural diagram of a communication device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0079] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without making creative efforts belong to the scope of protection of the present application.

[0080] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means an "or" relationship between the associated objects before and after.

[0081] Figure 1A block diagram of a wireless communication system to which embodiments of the present application can be applied is shown. The wireless communication system includes a terminal 11 and a network-side device 12. Among them, the terminal 11 may include a relay supporting terminal functions and / or a terminal supporting relay functions. The terminal 11 may also be referred to as a terminal device or a user terminal (User Equipment, UE). The terminal 11 may be a mobile phone, a tablet personal computer, a laptop computer or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a mobile Internet device (Mobile Internet Device, MID), a palm computer, a netbook, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a mobile Internet device (Mobile Internet Device, MID), a wearable device (Wearable Device) or a vehicle user equipment (Vehicle User Equipment, VUE), a pedestrian user equipment (Pedestrian User Equipment, PUE), etc. Terminal-side devices. Wearable devices include: bracelets, earphones, glasses, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 may be a base station or a core network. Among them, the base station may be referred to as a Node B, an evolved Node B, an access point, a base transceiver station (Base Transceiver Station, BTS), a radio base station, a radio transceiver, a basic service set (Basic Service Set, BSS), an extended service set (Extended Service Set, ESS), a B node, an evolved B node (eNB), a home B node, a home evolved B node, a WLAN access point, a WiFi node, a transmitting and receiving point (Transmitting Receiving Point, TRP) or some other suitable term in the art. As long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiments of the present application, only the base station in the NR system is taken as an example, but the specific type of the base station is not limited.

[0082] In an alternative embodiment of the present application, "able to" can represent at least one of the following: allow, support, tend to, have a preference for, have the ability. "Not able to" can represent at least one of the following: not allow, not support, not allow, not tend to, not have the ability.

[0083] In an alternative embodiment of the present application, obtaining or acquiring can be understood as obtaining from a configuration, receiving, receiving after a request, obtaining through self-learning, deriving and obtaining based on unreceived information, or obtaining after processing received information. Specifically, it can be determined according to actual needs, and the embodiments of the present application do not limit this. For example, when a certain capability indication information sent by a device is not received, it can be deduced that the device does not support this capability.

[0084] In an alternative embodiment of the present application, sending may include broadcasting, broadcasting in a system message, and returning after responding to a request.

[0085] In an alternative embodiment of the present application, non-public network is the abbreviation of non-public network. A non-public network can be referred to as one of the following: a non-public communication network. A non-public network may include at least one of the following deployment methods: a physical non-public network, a virtual non-public network, and a non-public network implemented on a public network. In one implementation, the non-public network is a Closed Access Group (CAG). A CAG can be composed of a group of terminals.

[0086] In an alternative embodiment of the present application, non-public network service is the abbreviation of non-public network service. A non-public network service can also be referred to as one of the following: a network service of a non-public network, a non-public communication service, a non-public network communication service, a network service of a non-public network, or other names. It should be noted that in the embodiments of the present application, the naming method is not specifically limited. In one implementation, the non-public network is a closed access group. At this time, the non-public network service is the network service of the closed access group.

[0087] In an alternative embodiment of the present application, a non-public network may include or be referred to as a private network. A private network can be referred to as one of the following: a private communication network, a private network, a local area network (LAN), a private virtual network (PVN), an isolated communication network, a dedicated communication network, or other names. It should be noted that in the embodiments of the present application, the naming method is not specifically limited.

[0088] In an alternative embodiment of the present application, a public network is the abbreviation of a public network. A public network can be referred to as one of the following: a public communication network or other names. It should be noted that in the embodiments of the present application, the naming method is not specifically limited.

[0089] In an alternative embodiment of the present application, a communication device may include at least one of the following: a communication network element and a terminal.

[0090] In an alternative embodiment of the present application, a communication network element may include at least one of the following: a core network element and a radio access network element.

[0091] In an alternative embodiment of the present application, the core network element (CN network element) may include, but is not limited to, at least one of the following: core network device, core network node, core network function, core network element, Mobility Management Entity (MME), Access Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), serving gateway (SGW), PDN gateway (PDN gateway), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Serving GPRS Support Node (SGSN), Gateway GPRS Support Node (GGSN), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), and Application Function (AF).

[0092] In an alternative embodiment of the present application, the RAN network element may include, but is not limited to, at least one of the following: radio access network device, radio access network node, radio access network function, radio access network unit, 3GPP radio access network, non-3GPP radio access network, Centralized Unit (CU), Distributed Unit (DU), base station, evolved Node B (eNB), 5G base station (gNB), Radio Network Controller (RNC), NodeB, Non-3GPP Inter Working Function (N3IWF), Access Controller (AC) node, Access Point (AP) device, or Wireless Local Area Networks (WLAN) node, N3IWF.

[0093] In some communication scenarios, there are scenarios where a terminal needs to access a network without a network certificate. For example, when deploying a Standalone Non-public Network (SNPN), a User Equipment (UE) may not yet have a certificate and a UE identifier for accessing the SNPN. For example, an SNPN deployed in a factory and a terminal just purchased on the market, or an SNPN deployed at a concert venue and the terminal of the audience.

[0094] In the related art, a terminal (such as a User Equipment (UE)) can access a Public Land Mobile Network (PLMN) or a Standalone Non-Public Network (SNPN) 1 to download a certificate of a first object (such as a certificate of SNPN2, or a certificate for secondary authentication and / or authorization). When the UE does not have a certificate of SNPN1 (such as a certificate for unrestricted access), if SNPN1 supports the function of a first access mode (such as onboarding), then SNPN1 can be called an onboarding SNPN (abbreviated as O-SNPN). The first access mode can be an access mode through a restricted access network and / or through the network to obtain a certificate of a first network. When accessing the Onboarding SNPN, the UE does not have a certificate of the O-SNPN (no certificate for unrestricted access), and uses a default certificate (Default credential, such as a certificate for restricted access) to access the O-SNPN, and an onboarding indication needs to be provided to illustrate the particularity of the registration type of the UE. Therefore, in the scenario of the O-SNPN, there are two functions:

[0095] (1) Default credential onboarding or accessing the network through a restricted access method;

[0096] (2) Configuring the certificate and / or subscription of the first object.

[0097] The cell of the O-SNPN can broadcast an onboarding indication for the UE to select the O-SNPN and obtain the certificate and / or subscription of the first object.

[0098] When downloading the SNPN2 certificate through the PLMN or SNPN3, since the UE has a certificate for accessing the PLMN or SNPN3 (such as a certificate for unrestricted access), in essence, the PLMN or SNPN3 may not support the function of (1), but only support the function of (2).

[0099] For the UE, if the UE wants to obtain the certificate and / or subscription of the first object (such as SNPN2), a first list is configured on the UE. The UE can access the network in the first list to obtain the certificate and / or subscription of the first object. The first list can be a mixed list composed of PLMN and / or SNPN type networks.

[0100] The terminal can select a network according to the first list.

[0101] In the embodiments of the present application, the following problems need to be solved:

[0102] Problem 1: In the scenario of O-SNPN, when the UE registers to the first network through the first access method (such as onboarding), when the first network does not allow or does not support the certificate download type of the UE (for example, the UE supports the control plane method and the network supports the user plane method; or the UE supports the user plane method and the network supports the control plane method), the registration should be rejected. For such a registration rejection received from the first network, the terminal needs to operate on the first list to avoid re-selection. However, the first list is not a conventional network list for registration. For example, the UE has a default credential but may have a list of multiple SNPNs it wants to download. There may be a first list for each first object (SNPN).

[0103] A solution is to remove the first network from the first list corresponding to the first object according to the first rejection reason. The first rejection reason can be an existing reason or a new reason value.

[0104] Problem 2: In the scenario of PLMN or SNPN3, since downloading the certificate of the first object may be only one of the purposes for the UE to register to the PLMN or SNPN3, that is, the registration type is not the first access method (such as onboarding), when the first network does not allow or does not support the certificate download type of the UE, the registration may still be accepted, but a first indication message is sent, such as indicating: does not support configuring the certificate and / or subscription through the control method, does not support configuring the certificate and / or subscription through the user plane method, or does not support configuring the certificate and / or subscription. After receiving this indication, the UE decides whether to register to the first network by itself, and instead selects another network to obtain the certificate and / or subscription; if the UE has other services besides obtaining the certificate and / or subscription, it can also choose not to register (detach) and continue to stay in the first network to perform other services. In addition, according to the first indication message, the UE can also remove the first network from the first list corresponding to the first object.

[0105] In an alternative embodiment of the present application, the first access method includes at least one of the following: an access method for accessing the network to obtain a certificate and / or for signing, an access method using a restricted access network, and an access method using a default certificate to access the network.

[0106] In one embodiment, the method of using a restricted access network to download a certificate for accessing a first object, or the method of accessing the network to download a certificate for accessing a first object, may be referred to as onboarding. When the first object includes a Network A, the first network and Network A may be the same network or different networks. The first network is the network accessed by the terminal, such as the currently accessed network.

[0107] In an alternative embodiment of the present application, the first server is a server for configuring a certificate and / or signing for the terminal with respect to a first object.

[0108] In an embodiment of the present application, configuring a certificate and / or signing includes at least one of the following: configuring a certificate and / or signing based on restricted access, and configuring a certificate and / or signing based on unrestricted access.

[0109] (1) Optionally, configuring a certificate and / or signing through a control plane includes at least one of the following: configuring a certificate and / or signing through a control plane based on restricted access, and configuring a certificate and / or signing through a control plane based on unrestricted access.

[0110] (2) Optionally, configuring a certificate and / or signing through a user plane includes at least one of the following: configuring a certificate and / or signing through a user plane based on restricted access, and configuring a certificate and / or signing through a user plane based on unrestricted access.

[0111] (3) Optionally, obtaining a certificate and / or signing includes: obtaining a certificate and / or signing based on restricted access, and obtaining a certificate and / or signing based on unrestricted access.

[0112] (4) Optionally, obtaining a certificate and / or signing through a control plane includes at least one of the following: obtaining a certificate and / or signing through a control plane based on restricted access, and obtaining a certificate and / or signing through a control plane based on unrestricted access;

[0113] (5) Optionally, obtaining a certificate and / or signing through a user plane includes at least one of the following: obtaining a certificate and / or signing through a user plane based on restricted access, and obtaining a certificate and / or signing through a user plane based on unrestricted access.

[0114] (6) Optionally, configuring a certificate and / or signing may include at least one of the following: configuring a certificate and / or signing through a control plane, and configuring a certificate and / or signing through a user plane.

[0115] Optionally, obtaining a certificate and / or signing may include at least one of the following: obtaining a certificate and / or signing through a control plane method, obtaining a certificate and / or signing through a user plane method.

[0116] Optionally, the certificate and / or signing includes at least one of the following: a certificate and / or signing of a first object, a certificate and / or signing for primary authentication and / or authorization, a certificate and / or signing for authorization, a certificate and / or signing for non-primary authentication, a certificate and / or signing for non-authorization;

[0117] Wherein, the first object includes at least one of the following: a network A, a first entity, a network accessed by a terminal, primary authentication and / or authorization, non-primary authentication and / or authorization;

[0118] The first entity includes one of the following: an entity in a data network, an entity outside the network to which the terminal belongs, an entity outside a first network; the first network is the network accessed by the terminal;

[0119] Network A is the same as or different from the first network.

[0120] In an optional embodiment of the present application, supporting the configuration of a certificate and / or signing is used to further indicate at least one of the following: supporting the configuration of a certificate and / or signing through a control plane method, supporting the configuration of a certificate and / or signing through a user plane method.

[0121] In an optional embodiment of the present application, not supporting the configuration of a certificate and / or signing is used to further indicate not supporting the configuration of a certificate and / or signing through a control plane method, not supporting the configuration of a certificate and / or signing through a user plane method.

[0122] In an optional embodiment of the present application, obtaining a certificate and / or signing is remotely obtaining a certificate and / or signing. For example, when a terminal accesses a first network to obtain a certificate and / or signing, the provider of the certificate and / or signing is the first entity. The first entity is an entity in a data network (DN) or an entity outside the network accessed by the terminal.

[0123] In an optional embodiment of the present application, the provider of the certificate and / or signing is one of the following: an entity outside the network in a first list, an entity outside the network accessed by the terminal, an entity in a data network (DN), an entity in another network. The entity in the data network may be an application server, a configuration server for the certificate and / or signing in the data network. The goal of the terminal accessing the network includes obtaining a certificate and / or signing.

[0124] In an alternative embodiment of the present application, the certificate and / or subscription is / are the certificate and / or subscription of the network accessed by the terminal. The certificate and / or subscription of the network accessed by the terminal includes at least one of the following: the certificate and / or subscription of the network for unrestricted access used by the terminal, and the certificate and / or subscription of the network for restricted access used by the terminal.

[0125] In an alternative embodiment of the present application, the certificate and / or subscription includes at least one of the following: the certificate and / or subscription for unrestricted access, the certificate and / or subscription for restricted access, the certificate and / or subscription for primary authentication and / or authorization, and the certificate and / or subscription for non-primary authentication and / or authorization. Primary authentication (such as Primary Authentication) may include: Authentication and Key Agreement (AKA), for example, 5th generation (5G) AKA, Extensible Authentication Protocol (EAP) AKA.

[0126] Non-primary authentication and / or authorization includes at least one of the following: secondary authentication / authorization, and network slice-specific authentication and authorization (NSSAA).

[0127] In one implementation, the terminal may use the certificate (such as the default certificate) and / or subscription for the restricted access network to access the first network, and then obtain the certificate and / or subscription for unrestricted access to the first object (including network A) through the first network. Network A may be the same as or different from the first network.

[0128] In an alternative embodiment of the present application, obtaining the certificate and / or subscription through the control plane manner, and / or configuring the certificate and / or subscription through the control plane manner includes at least one of the following: a first entity configures the certificate and / or subscription for the terminal through the control plane signaling of the network accessed by the terminal; the terminal obtains the certificate and / or subscription from the first entity through the control plane signaling of the network accessed by the terminal.

[0129] In an alternative embodiment of the present application, obtaining a certificate and / or subscription through the user plane, and / or configuring a certificate and / or subscription through the user plane includes at least one of the following: The terminal establishes a data channel in the accessed network, and through the data channel, obtains the certificate and / or subscription from a first entity; or the first entity configures the certificate and / or subscription for the terminal through the data channel established by the terminal in the accessed network.

[0130] In an alternative embodiment of the present application, the data channel includes at least one of the following: The data channel may include, but is not limited to, one of the following: PDU session, PDN connection, QoS flow, bearer, Internet Protocol Security (IPsec) channel. Among them, the bearer may be an Evolved Radio Access Bearer (E-RAB), a Radio Access Bearer (RAB), a Data Radio Bearer (DRB), a signalling radio bearer (SRB), etc.

[0131] In an alternative embodiment of the present application, the network that allows access using a default certificate includes that the terminal accesses a network that can obtain a restricted connection using the terminal identifier corresponding to the default certificate.

[0132] In an alternative embodiment of the present application, the default certificate includes a certificate for a restricted access mode.

[0133] In an alternative embodiment of the present application, restricted access and restricted connection have the same meaning and can be used interchangeably.

[0134] In one implementation, restricted access includes at least one of the following: Only allowing the establishment of a first data channel and not allowing the establishment of data channels other than the first data channel, only allowing the acquisition of a certificate and / or subscription and not allowing the acquisition of services other than the certificate and / or subscription. The first data channel is a data channel for acquiring a certificate and / or subscription.

[0135] In one implementation, a certificate and / or subscription of a first object can be obtained through restricted access.

[0136] In an alternative embodiment of the present application, restricted access includes restricted control plane access and / or restricted user plane access.

[0137] In an alternative embodiment of the present application, restricted connection includes restricted control plane connection and / or restricted user plane connection. A certificate and / or subscription can be obtained through the restricted connection.

[0138] In an optional embodiment of the present application, the networks that can be accessed using the default certificate include: accessing the network using the terminal identifier corresponding to the default certificate, and passing the authentication and / or authorization of the network through the default certificate.

[0139] In an optional embodiment of the present application, the networks in the first list include the networks mapped by the network groups in the first list. One network group can be mapped to one or more networks.

[0140] In an optional embodiment of the present application, the networks in the network list that can configure certificates and / or subscriptions include: the networks to which the terminal can be restricted to access and that can enable the terminal to obtain certificates and / or subscriptions.

[0141] In an optional embodiment of the present application, the characteristics of the networks in the first list include the networks to which access can be restricted and that can enable the terminal to obtain certificates and / or subscriptions.

[0142] In an optional embodiment of the present application, a subscription includes subscription data, such as slice information, DNN, etc.

[0143] In an optional embodiment of the present application, network A is used to generally refer to a network or to specifically refer to one or more networks.

[0144] In an optional embodiment of the present application, the network types of the networks in the first list, the second list, and / or network A include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.

[0145] In an optional embodiment of the present application, the certificate and / or subscription of the first object include: the certificate and / or subscription for accessing the first object. The certificate and / or subscription for accessing the first object include at least one of the following: the certificate and / or subscription for unrestricted access to the first object, the certificate and / or subscription for restricted access to the first object.

[0146] In an optional embodiment of the present application, the certificate and / or subscription of network A include: the certificate and / or subscription for accessing network A. The certificate and / or subscription for accessing network A include at least one of the following: the certificate and / or subscription for unrestricted access to network A, the certificate and / or subscription for restricted access to network A.

[0147] In an optional embodiment of the present application, configuring a certificate and / or subscription for the terminal includes enabling the terminal to obtain the certificate and / or subscription.

[0148] In an optional embodiment of the present application,

[0149] (1) Optionally, enabling the terminal to obtain a certificate and / or signature includes: configuring a certificate and / or signature for the terminal.

[0150] (2) Optionally, enabling the terminal to obtain a certificate and / or signature through the control plane includes: configuring a certificate and / or signature for the terminal through the control plane.

[0151] (3) Optionally, enabling the terminal to obtain a certificate and / or signature through the user plane includes: configuring a certificate and / or signature for the terminal through the user plane.

[0152] (4) Optionally, enabling the terminal to obtain a certificate and / or signature of a first object through the control plane includes: configuring a certificate and / or signature of the first object for the terminal through the control plane.

[0153] and / or

[0154] (5) Optionally, enabling the terminal to obtain a certificate and / or signature of a first object through the user plane includes: configuring a certificate and / or signature of the first object for the terminal through the user plane.

[0155] In an alternative embodiment of the present application,

[0156] (1) Optionally, configuring a certificate and / or signature for the terminal includes: enabling the terminal to obtain a certificate and / or signature.

[0157] (2) Optionally, configuring a certificate and / or signature for the terminal through the control plane includes: enabling the terminal to obtain a certificate and / or signature through the control plane.

[0158] (3) Optionally, configuring a certificate and / or signature for the terminal through the user plane includes: enabling the terminal to obtain a certificate and / or signature through the user plane.

[0159] (4) Optionally, configuring a certificate and / or signature of a first object for the terminal through the control plane includes: enabling the terminal to obtain a certificate and / or signature of the first object through the control plane.

[0160] and / or

[0161] (5) Optionally, configuring a certificate and / or signature of a first object for the terminal through the user plane includes: enabling the terminal to obtain a certificate and / or signature of the first object through the user plane. It is not difficult to understand that when the certificate and / or signature of the first network is provided by an entity outside the network accessed by the terminal, the configuring a certificate and / or signature for the terminal can be understood as enabling the terminal to obtain a certificate and / or signature of the first object through the user plane.

[0162] The information processing method of the embodiments of the present application is described below.

[0163] Please refer toFigure 2 , an embodiment of the present application provides an information processing method, which is applied to a network-side device; the network-side device includes, but is not limited to: a CN network element; the CN network element is, for example, an AMF, etc. As Figure 2 shown, the method includes:

[0164] Step 21: Obtain first information.

[0165] Optionally, the first information may include at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the certificate requested by the terminal, and / or the subscription acquisition method.

[0166] Among them, the capability information of the terminal may include at least one of the following: support or not support for obtaining a certificate and / or subscription, support or not support for obtaining a certificate and / or subscription through the control plane, support or not support for obtaining a certificate and / or subscription through the user plane.

[0167] The capability information of the first network and / or the capability information of the first server may include at least one of the following: support or not support for configuring a certificate and / or subscription, support or not support for configuring a certificate and / or subscription through the control plane, support or not support for configuring a certificate and / or subscription through the user plane.

[0168] The access type information of the terminal accessing the first network may include one of the following: the type of the first access method, the type of non-first access method.

[0169] The first access method may include at least one of the following: the access method for accessing the network to obtain a certificate and / or subscription, the access method for accessing a restricted access network, the access method for accessing the network with a default certificate.

[0170] The certificate requested by the terminal and / or the subscription acquisition method may include at least one of the following: obtaining a certificate and / or subscription through the control plane, obtaining a certificate and / or subscription through the user plane.

[0171] Step 22: Perform a first operation according to the first information.

[0172] Optionally, the first operation may include at least one of the following:

[0173] Determine to accept the terminal access (such as registration acceptance), or determine to reject the terminal access (such as registration rejection);

[0174] Determine the reason for rejection;

[0175] Determine the value of the first indication information;

[0176] Include a first rejection reason in the first message and send the first message;

[0177] Include first indication information in the second message and send the second message.

[0178] Among them, the first message is a message for rejecting the terminal access, such as a registration rejection message. The second message is a message for accepting the terminal access, such as a registration acceptance message.

[0179] Among them, the first indication information is used to indicate at least one of the following: support or not support configuring certificates and / or signing; support or not support configuring certificates and / or signing through the control plane; support or not support configuring certificates and / or signing through the user plane.

[0180] It can be understood that the support or not support here is a general reference. One is network support, and the other is to confirm support or not support after combining the capabilities of the network and the terminal.

[0181] Among them, the first rejection reason is used to indicate at least one of the following: not allowing or not supporting the terminal to obtain certificates and / or sign, not allowing or not supporting the terminal to obtain certificates and / or sign through the control plane, not allowing or not supporting the terminal to obtain certificates and / or sign through the user plane, the network does not allow the terminal to access, SNPN does not allow, PLMN does not allow.

[0182] In one implementation, the network in the network does not allow the terminal to access is the network that the terminal requests to access, that is, the first network.

[0183] In another implementation, the rejection reason that the network does not allow the terminal to access can be reflected as one of the following: PLMN not allowed, SNPN not allowed. For example, when the network type of the network that the terminal accesses is SNPN, SNPN not allowed or PLMN not allowed can be used to reflect that the network does not allow. Among them, the PLMN not allowed means that the network that the terminal requests to access rejects the terminal access. The SNPN not allowed means that the network type of the network that the terminal requests to access is SNPN and the network that the terminal requests to access rejects the terminal access. It should be noted that PLMN not allowed is an existing reason.

[0184] In the embodiments of the present application, the above-mentioned execution of the first operation may include:

[0185] When the first condition is satisfied, perform at least one of the following:

[0186] Determine to reject the terminal from accessing the first network;

[0187] Send the first reason for rejection;

[0188] Send a message for rejecting the terminal access;

[0189] Send a message for rejecting the terminal access, and the message for rejecting the terminal access includes the first reason for rejection.

[0190] Wherein, the first condition may include at least one of the following:

[0191] The access type (such as the registration type) of the terminal accessing the first network is: the type of the first access method (onboarding);

[0192] The terminal does not have a certificate and / or subscription for unrestricted access to the first network;

[0193] The certificate and / or subscription of the terminal accessing the first network is a certificate and / or subscription for a restricted access type, such as the default certificate type;

[0194] The terminal authentication and / or authorization fails and the terminal cannot access the first network;

[0195] The first network is one of the following: a public network (including PLMN, PNI NPN, etc.), a PLMN-type network.

[0196] Wherein, the first network may satisfy at least one of the following:

[0197] Does not support the acquisition method of the certificate and / or subscription supported or requested by the terminal;

[0198] Does not allow the acquisition method of the certificate and / or subscription supported or requested by the terminal;

[0199] Does not support the terminal to obtain the certificate and / or subscription of the first object through the first network;

[0200] Does not allow the terminal to obtain the certificate and / or subscription of the first object through the first network.

[0201] Optionally, the first object may include Network A. The first network and Network A are the same network or different networks.

[0202] In one implementation, the certificate and / or subscription for the restricted access type includes a default certificate. After authenticating and / or authorizing access to the first network through the default certificate, only restricted services can be obtained. For example, only a restricted data channel can be established, and the restricted data channel is only used to obtain the certificate and / or subscription of the first object.

[0203] In another implementation, the certificate and / or subscription is for a non-restricted service. When the terminal has the certificate and / or subscription, the terminal can obtain non-restricted services in the first network.

[0204] Optionally, the execution of the first operation may include:

[0205] When the second condition is met, perform at least one of the following:

[0206] Determine to accept the terminal's access to the first network;

[0207] Determine that the value of the first indication information is at least one of the following: does not support configuring the certificate and / or subscription, does not support configuring the certificate and / or subscription via the control plane, does not support configuring the certificate and / or subscription via the user plane;

[0208] Send a message for accepting the terminal's access;

[0209] Send a message for accepting the terminal's access, and the message for accepting the terminal's access contains the first indication information.

[0210] Wherein, the second condition may include at least one of the following:

[0211] The terminal access type (such as the registration type) is: a type other than the first access method (onboarding);

[0212] The terminal has a certificate and / or subscription for restricted access to the first network;

[0213] The terminal has a certificate and / or subscription for non-restricted access to the first network;

[0214] The terminal's authentication and / or authorization is passed and it can access the first network;

[0215] The first network allows or supports the first service, and the first service is a service other than obtaining the certificate and / or subscription of the first object through the first network.

[0216] The first network is one of the following: a non-public network, a network of the SNPN type.

[0217] Optionally, the first network and / or the first server meet at least one of the following:

[0218] Do not support the certificate and / or subscription acquisition method supported or requested by the terminal;

[0219] Do not allow the certificate and / or subscription acquisition method supported or requested by the terminal;

[0220] Do not support the terminal to obtain the certificate and / or subscription of the first object through the first network;

[0221] The terminal is not allowed to obtain the certificate and / or signature of the first object through the first network.

[0222] Optionally, the type of the non-first access method may include any one of the following: initial registration, mobile registration update, periodic registration update, and emergency registration.

[0223] Optionally, the way that the first network and / or the first server do not support the terminal to obtain the certificate and / or signature may include at least one of the following:

[0224] The terminal only supports or requests to obtain the certificate and / or signature through the control plane, and the first network and / or the first server only support to configure the certificate and / or signature through the user plane;

[0225] The terminal only supports or requests to obtain the certificate and / or signature through the control plane, and the first network and / or the first server do not support to configure the certificate and / or signature through the control plane;

[0226] The terminal only supports or requests to obtain the certificate and / or signature through the user plane, and the first network and / or the first server only support to configure the certificate and / or signature through the control plane;

[0227] The terminal only supports or requests to obtain the certificate and / or signature through the user plane, and the first network and / or the first server do not support to configure the certificate and / or signature through the user plane;

[0228] The first network and / or the first server do not support the terminal to obtain the certificate and / or signature.

[0229] Optionally, the way that the first network and / or the first server do not allow the terminal to obtain the certificate and / or signature may include at least one of the following:

[0230] The terminal only supports or requests to obtain the certificate and / or signature through the control plane, and the first network and / or the first server only allow to configure the certificate and / or signature through the user plane;

[0231] The terminal only supports or requests to obtain the certificate and / or signature through the control plane, and the first network and / or the first server do not allow to configure the certificate and / or signature through the control plane;

[0232] The terminal only supports or requests to obtain the certificate and / or signature through the user plane, and the first network and / or the first server only allow to configure the certificate and / or signature through the control plane;

[0233] The terminal only supports or requests to obtain the certificate and / or signature through the user plane, and the first network and / or the first server do not allow to configure the certificate and / or signature through the user plane;

[0234] The first network and / or the first server do not allow the terminal to obtain a certificate and / or sign a contract.

[0235] It is not difficult to understand that through this embodiment, by means of the operations performed by the network-side device, the terminal can be made to know whether its obtaining a certificate and / or signing a contract is supported or not, thus facilitating the terminal to maintain the first list and network selection.

[0236] Please refer to Figure 3 , this embodiment of the present application also provides an information processing method, which is applied to a terminal, as Figure 3 shown, the method includes:

[0237] Step 31: Perform a second operation.

[0238] Optionally, the second operation may include at least one of the following:

[0239] Determine to initiate deregistration from the first network, or determine not to initiate deregistration from the first network;

[0240] Initiate deregistration from the first network;

[0241] Remove the first network from the first list;

[0242] Move the first network into the second list.

[0243] Wherein, the first list may include any one of the following: one or more network objects, identification information of one or more network objects. The characteristics of the networks in the first list include at least one of the following: the terminal can access them in a restricted manner, can enable the terminal to obtain a certificate and / or sign a contract, and the terminal can access using a default certificate.

[0244] Or, the first list includes at least one of the following: a list of networks that can be accessed in a restricted manner, a list of networks that can configure a certificate and / or sign a contract, a list of networks that can access using a default certificate.

[0245] Wherein, the second list may include any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the second list include at least one of the following: the terminal cannot access them, cannot enable the terminal to obtain a certificate and / or sign a contract, and the terminal cannot access using a default certificate.

[0246] Or, the second list includes at least one of the following: a list of networks that cannot be accessed in a restricted manner, a list of networks that cannot configure a certificate and / or sign a contract, a list of networks that cannot access using a default certificate.

[0247] Optionally, the network list includes one or more network objects, or, the network list includes identification information of one or more network objects.

[0248] Optionally, the network object includes a network and / or a network group.

[0249] Optionally, the certificate and / or signature includes at least one of the following: the certificate and / or signature of the first object, the certificate and / or signature for primary authentication and / or authorization, the certificate and / or signature for authorization, the certificate and / or signature for non-primary authentication, the certificate and / or signature for non-authorization.

[0250] Wherein, the first object includes at least one of the following: Network A, the first entity, the network accessed by the terminal, primary authentication and / or authorization, non-primary authentication and / or authorization.

[0251] The first entity includes one of the following: an entity in the data network, an entity outside the network to which the terminal belongs, an entity outside the first network; the first network is the network accessed by the terminal.

[0252] In one implementation, Network A is the same as or different from the networks in the first list.

[0253] In one implementation, Network A is the same as or different from the networks in the second list.

[0254] Optionally, the obtaining of the certificate and / or signature includes at least one of the following: obtaining the certificate and / or signature through the control plane, obtaining the certificate and / or signature through the user plane.

[0255] Optionally, the network list capable of configuring the certificate and / or signature includes at least one of the following: the network list capable of configuring the certificate and / or signature through the control plane, the network list capable of configuring the certificate and / or signature through the user plane.

[0256] Optionally, enabling the terminal to obtain the certificate and / or signature includes at least one of the following: enabling the terminal to obtain the certificate and / or signature through the control plane, enabling the terminal to obtain the certificate and / or signature through the user plane.

[0257] In the embodiments of the present application, the first list is the first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different.

[0258] Optionally, the second list is the second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different.

[0259] Optionally, the network list capable of configuring the certificate and / or signature includes: the network list capable of configuring the certificate and / or signature of the first object.

[0260] Optionally, the network list that cannot configure a certificate and / or sign includes: a network list that cannot configure the certificate and / or sign of a first object.

[0261] Optionally, enabling the terminal to obtain a certificate and / or sign includes: enabling the terminal to obtain the certificate and / or sign of a first object.

[0262] Optionally, not enabling the terminal to obtain a certificate and / or sign includes: not enabling the terminal to obtain the certificate and / or sign of a first object.

[0263] Optionally, the first list corresponding to the first object includes: a first list corresponding to the first object in a control plane manner, and a first list corresponding to the first object in a user plane manner.

[0264] Wherein, the first list corresponding to the first object in a control plane manner and the first list corresponding to the first object in a user plane manner are the same or different.

[0265] The networks in the first list corresponding to the first object in a control plane manner include: networks that can enable the terminal to obtain the certificate and / or sign of the first object in a control plane manner.

[0266] The networks in the first list corresponding to the first object in a user plane manner include: networks that can enable the terminal to obtain the certificate and / or sign of the first object in a user plane manner.

[0267] Optionally, the second list corresponding to the first object includes: a second list corresponding to the first object in a control plane manner, and a second list corresponding to the first object in a user plane manner.

[0268] Wherein, the second list corresponding to the first object in a control plane manner and the second list corresponding to the first object in a user plane manner are the same or different.

[0269] The networks in the second list corresponding to the first object in a control plane manner include: networks that cannot enable the terminal to obtain the certificate and / or sign of the first object in a control plane manner.

[0270] The networks in the second list corresponding to the first object in a user plane manner include: networks that cannot enable the terminal to obtain the certificate and / or sign of the first object in a user plane manner.

[0271] Optionally, the network list that can configure the certificate and / or sign of the first object includes at least one of the following: a network list that can configure the certificate and / or sign of the first object in a control plane manner, and a network list that can configure the certificate and / or sign of the first object in a user plane manner.

[0272] Optionally, the network list that cannot configure the certificate and / or subscription of the first object includes at least one of the following: the network list that cannot configure the certificate and / or subscription of the first object through the control plane, and the network list that cannot configure the certificate and / or subscription of the first object through the user plane.

[0273] Optionally, enabling the terminal to obtain the certificate and / or subscription of the first object includes at least one of the following: enabling the terminal to obtain the certificate and / or subscription of the first object through the control plane, and enabling the terminal to obtain the certificate and / or subscription of the first object through the user plane.

[0274] Optionally, not enabling the terminal to obtain the certificate and / or subscription of the first object includes at least one of the following: not enabling the terminal to obtain the certificate and / or subscription of the first object through the control plane, and not enabling the terminal to obtain the certificate and / or subscription of the first object through the user plane.

[0275] In an embodiment of the present application, the above execution of the second operation may include:

[0276] In the case of satisfying the third condition, initiate deregistration to the first network.

[0277] Wherein, the third condition includes at least one of the following:

[0278] The purpose of the terminal accessing the first network is to obtain the certificate and / or subscription of the first object through the first network;

[0279] The access type of the terminal accessing the first network is: the type of the first access method (onboarding);

[0280] The terminal fails to obtain the certificate and / or subscription of the first object through the first network.

[0281] In one implementation, the purpose of the terminal accessing the first network is to obtain the certificate and / or subscription of the first object through the first network includes: the only purpose of the terminal accessing the first network is to obtain the certificate and / or subscription of the first object through the first network.

[0282] Optionally, the above execution of the second operation may include:

[0283] In the case of satisfying the fourth condition, determine not to initiate deregistration to the first network.

[0284] The purpose of the terminal accessing the first network is not only to obtain the certificate and / or subscription of the first object through the first network;

[0285] The access type of the terminal accessing the first network is: a type other than the first access method (onboarding);

[0286] The terminal fails to obtain the certificate and / or subscription of the first object through the first network.

[0287] Optionally, the execution of the second operation may include:

[0288] Removing the first network from the first list and / or moving it to the second list when the fifth condition is met.

[0289] Wherein, the fifth condition includes: the terminal fails to obtain the certificate and / or subscription of the first object through the first network.

[0290] In one implementation, the first list is the first list corresponding to the first object, and the second list is the second list of the first object.

[0291] Furthermore, the situation where the terminal fails to obtain the certificate and / or subscription of the first object through the first network may include at least one of the following:

[0292] Failing to obtain the network certificate and / or subscription of the first object through the control plane;

[0293] Failing to obtain the network certificate and / or subscription of the first object through the user plane;

[0294] The timer expires or the waiting time expires, and the certificate and / or subscription of the first object are not received from the control plane of the first network;

[0295] Failing to obtain the certificate and / or subscription of the first object through the user plane initiated;

[0296] The terminal only supports obtaining the certificate and / or subscription of the first object through the control plane, and the timer expires or the waiting time expires, and the second certificate and / or subscription are not received from the control plane of the first network;

[0297] The terminal only supports obtaining the certificate and / or subscription of the first object through the user plane, and the request for the second certificate and / or subscription through the user plane initiated fails;

[0298] The terminal supports obtaining the certificate and / or subscription of the first object through both the control plane and the user plane, and the timer expires or the waiting time expires, and the second certificate and / or subscription are not received from the control plane of the first network, and the attempt to obtain the certificate and / or subscription of the first object through the user plane fails;

[0299] The terminal supports obtaining the certificate and / or subscription through both the control plane and the user plane, and the attempt to obtain the certificate and / or subscription of the first object through the user plane fails.

[0300] In one implementation, after the terminal obtains the access success message, it starts a timer or begins to wait. After the timer expires or the waiting time elapses, if it does not receive the certificate and / or subscription of the first object from the control plane of the first network, it indicates one of the following: the failure to obtain the certificate and / or subscription of the first object through the control plane method, the first network does not support the terminal to obtain the certificate and / or subscription of the first object through the control plane method, or the first server does not support the terminal to obtain the certificate and / or subscription of the first object through the control plane method.

[0301] In one implementation, the terminal obtains the duration of a timer or the waiting time, and the timer or the waiting time is used to wait for receiving the certificate and / or subscription of the first object from the control plane of the first network. The duration of the timer or the waiting time can be pre-configured in the terminal or obtained from the first network.

[0302] Optionally, the failure to obtain the certificate and / or subscription of the first object through the user plane method includes at least one of the following: the failure to establish the data channel of the first network, the failure to obtain the certificate and / or subscription of the first object from the first server, the first network does not support the terminal to obtain the certificate and / or subscription of the first object through the user plane method, or the first server does not support the terminal to obtain the certificate and / or subscription of the first object through the user plane method.

[0303] Optionally, obtaining the certificate and / or subscription of the first object through the control plane method includes: the first server configures the certificate and / or subscription of the first object for the terminal through the control plane signaling of the first network, or the terminal obtains the certificate and / or subscription of the first object through the control plane of the first network. The first server can be used to configure the certificate and / or subscription of the first object for the terminal.

[0304] Optionally, obtaining the certificate and / or subscription of the first object through the user plane method includes: the terminal establishes the first data channel of the first network and requests the network certificate and / or subscription of the first object from the first server through the first data channel. The first server can be used to configure the certificate and / or subscription of the first object for the terminal.

[0305] In the embodiments of the present application, the above-mentioned execution of the second operation includes:

[0306] Obtaining the second information and, based on the second information, executing the second operation.

[0307] Wherein, the second information includes at least one of the following: an access rejection message, a first rejection reason, a first indication information; the first indication information is used to indicate at least one of the following: not supporting the terminal to obtain the certificate and / or subscription, not supporting the terminal to obtain the certificate and / or subscription through the control plane method, or not supporting the terminal to obtain the certificate and / or subscription through the user plane method.

[0308] The first rejection reason is used to indicate at least one of the following: the terminal is not allowed or not supported to obtain a certificate and / or sign a contract, the terminal is not allowed or not supported to obtain a certificate and / or sign a contract through the control plane, the terminal is not allowed or not supported to obtain a certificate and / or sign a contract through the user plane, the network does not allow the terminal to access, the SNPN does not allow, the PLMN does not allow.

[0309] It should be noted that the types of networks in the first indication information include: SNPN, NPN, etc. The network in the first indication information can be represented as network A. The network in the first indication information can be a general reference, and in some cases, it specifically refers to network A.

[0310] Optionally, the above execution of the second operation may include:

[0311] When the sixth condition is met, initiate deregistration to the first network.

[0312] Among them, the sixth condition includes at least one of the following:

[0313] The purpose of the terminal accessing the first network is to obtain the certificate and / or signature of the first object through the first network;

[0314] The access type of the terminal accessing the first network is: the type of the first access method (onboarding);

[0315] The first indication information indicates at least one of the following: does not support configuring a certificate and / or signing a contract, does not support configuring a certificate and / or signing a contract through the control plane, does not support configuring a certificate and / or signing a contract through the user plane;

[0316] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane;

[0317] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

[0318] Optionally, the above execution of the second operation may include:

[0319] When the seventh condition is met, determine not to initiate deregistration to the first network.

[0320] Among them, the seventh condition includes at least one of the following:

[0321] The purpose of the terminal accessing the first network is not only to obtain the certificate and / or signature of the first object through the first network;

[0322] The access type of the terminal accessing the first network is: the type of non-first access method (onboarding);

[0323] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract;

[0324] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane;

[0325] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

[0326] Optionally, the execution of the second operation may include:

[0327] When the eighth condition is met, remove the first network from the first list and / or move it into the second list.

[0328] Wherein, the eighth condition includes at least one of the following:

[0329] Obtain an access rejection message;

[0330] Obtain the first rejection reason, or obtain the first indication information;

[0331] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract;

[0332] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane;

[0333] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

[0334] Optionally, the execution of the second operation may include:

[0335] When the ninth condition is met, remove the first network from the first list of obtaining a certificate and / or signing a contract through the control plane, and / or move the first network into the second list of obtaining a certificate and / or signing a contract through the control plane.

[0336] Wherein, the ninth condition includes: the first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane.

[0337] Optionally, the execution of the second operation may include:

[0338] When the tenth condition is met, remove the first network from the first list of obtaining a certificate and / or signing a contract through the user plane, and / or move the first network into the second list of obtaining a certificate and / or signing a contract through the user plane.

[0339] Wherein, the tenth condition includes at least one of the following:

[0340] Obtain an access rejection message;

[0341] Obtain a first rejection reason, or obtain first indication information;

[0342] The first rejection reason indicates that the terminal is not allowed to obtain a certificate and / or sign a contract through the user plane;

[0343] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane.

[0344] In one implementation, the terminal supports both the control plane mode and the user plane mode. After the waiting timeout in the control plane mode, the terminal initiates a request for a certificate and / or signing in the user plane mode. It is not difficult to understand that in this case, if the request for a certificate and / or signing in the user plane mode fails, it means that both the control plane mode and the user plane mode have failed. At this time, it means that the certificate and / or signing cannot be obtained through the first network, and the first network can be registered and the first network can be removed from the first list.

[0345] It is not difficult to understand. Through this embodiment, the UE can be supported to maintain the first list and network selection.

[0346] Next, the method provided by the present application will be described in combination with specific application scenarios.

[0347] Application scenario 1

[0348] In this application scenario 1, the terminal is configured with a first list (such as a list mixed with O-SNPN and PLMN) corresponding to obtaining a certificate and / or signing of the A network (O-SNPN). As Figure 4 shown, the corresponding information processing process may include:

[0349] Step 01: The terminal UE sends a registration request to the CN network element (such as AMF) of the first network. The registration request includes first information. The first information is as described above and will not be elaborated here.

[0350] Step 02: The CN network element of the first network sends a registration acceptance message to the UE. The registration acceptance message includes first indication information. The first indication information is as described above and will not be elaborated here.

[0351] Step 03: The terminal decides whether to remove the first network (such as registering the first network) or stay in the first network to continue other services. Specifically, as Figure 3 described in the embodiment, it will not be elaborated here.

[0352] Step 04: The terminal deletes the first network from the first list. Specifically, asFigure 3 As described in the embodiments, it will not be elaborated here.

[0353] Application Scenario 2

[0354] In this Application Scenario 2, the terminal is configured to obtain the certificate of the first object (such as SO - SNPN) and / or sign the corresponding first list (such as a network list mixed with O - SNPN and PLMN). For example Figure 5 As shown, the corresponding information processing process may include:

[0355] Step 01: The terminal UE sends a registration request to the CN network element (such as AMF) of the first network. The registration request includes first information. The first information is as described above and will not be elaborated here.

[0356] Step 02: The CN network element of the first network sends a registration rejection message to the UE. The registration rejection message includes a first rejection reason. The first rejection reason is as Figure 2 described and will not be elaborated here.

[0357] Step 03: The terminal deletes the first network from the first list, specifically as Figure 3 described in the embodiments and will not be elaborated here.

[0358] Please refer to Figure 6 , an embodiment of the present application provides an information processing device, which is applied to a network - side device, such as Figure 6 as shown, the information processing device 60 includes:

[0359] An acquisition module 61, configured to acquire first information;

[0360] A first execution module 62, configured to perform a first operation according to the first information;

[0361] Wherein, the first information includes at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the certificate and / or subscription acquisition method requested by the terminal;

[0362] Wherein, the first operation includes at least one of the following:

[0363] Determine to accept the terminal access or determine to reject the terminal access;

[0364] Determine the rejection reason;

[0365] Determine the value of the first indication information;

[0366] Include the first rejection reason in the first message and send the first message;

[0367] Include first indication information in a second message and send the second message;

[0368] Wherein, the first message is a message for rejecting terminal access; the second message is a message for accepting terminal access;

[0369] Wherein, the first indication information is used to indicate at least one of the following: support or not support configuring certificates and / or signing; support or not support configuring certificates and / or signing through the control plane; support or not support configuring certificates and / or signing through the user plane;

[0370] Wherein, the first rejection reason is used to indicate at least one of the following: not allowing or not supporting the terminal to obtain certificates and / or sign, not allowing or not supporting the terminal to obtain certificates and / or sign through the control plane, not allowing or not supporting the terminal to obtain certificates and / or sign through the user plane, the network does not allow the terminal to access, the SNPN does not allow, the PLMN does not allow;

[0371] Wherein, the capability information of the terminal includes at least one of the following: support or not support obtaining certificates and / or signing, support or not support obtaining certificates and / or signing through the control plane, support or not support obtaining certificates and / or signing through the user plane;

[0372] The capability information of the first network and / or the capability information of the first server includes at least one of the following: support or not support configuring certificates and / or signing, support or not support configuring certificates and / or signing through the control plane, support or not support configuring certificates and / or signing through the user plane;

[0373] The access type information for the terminal to access the first network includes one of the following: the type of the first access method, the type of non-first access method;

[0374] The first access method includes at least one of the following: an access method for accessing the network to obtain certificates and / or sign, an access method for accessing a restricted access network, an access method for accessing the network with a default certificate;

[0375] The method for the terminal to request to obtain certificates and / or sign includes at least one of the following: obtaining certificates and / or signing through the control plane, obtaining certificates and / or signing through the user plane.

[0376] Optionally, the first execution module 62 is further configured to:

[0377] When a first condition is satisfied, perform at least one of the following:

[0378] Determine to reject the terminal from accessing the first network;

[0379] Send the first rejection reason;

[0380] Send a message for rejecting the access of the terminal;

[0381] Send a message for rejecting the access of the terminal, and the message for rejecting the access of the terminal contains the first rejection reason;

[0382] Wherein, the first condition includes at least one of the following:

[0383] The access type of the terminal accessing the first network is: the type of the first access method;

[0384] The terminal does not have a certificate and / or subscription for unrestricted access to the first network;

[0385] The certificate and / or subscription of the terminal accessing the first network is a certificate and / or subscription for a restricted access type;

[0386] The authentication and / or authorization of the terminal fails and it cannot access the first network;

[0387] The first network is one of the following: a public network, a network of the Public Land Mobile Network (PLMN) type;

[0388] Wherein, the first network satisfies at least one of the following:

[0389] Does not support the acquisition method of the certificate and / or subscription supported or requested by the terminal;

[0390] Does not allow the acquisition method of the certificate and / or subscription supported or requested by the terminal;

[0391] Does not support the terminal to obtain the certificate and / or subscription of the first object through the first network;

[0392] Does not allow the terminal to obtain the certificate and / or subscription of the first object through the first network.

[0393] Optionally, the first execution module 62 is further configured to:

[0394] When the second condition is satisfied, perform at least one of the following:

[0395] Determine to accept the access of the terminal to the first network;

[0396] Determine that the value of the first indication information is at least one of the following: does not support configuring the certificate and / or subscription, does not support configuring the certificate and / or subscription through the control plane, does not support configuring the certificate and / or subscription through the user plane;

[0397] Send a message for accepting the access of the terminal;

[0398] Send a message for accepting the access of the terminal, and the message for accepting the access of the terminal contains the first indication information;

[0399] Wherein, the second condition includes at least one of the following:

[0400] The terminal access type is: a type other than the first access method;

[0401] The terminal has a certificate and / or subscription for restricted access to the first network;

[0402] The terminal has a certificate and / or subscription for unrestricted access to the first network;

[0403] The terminal authentication and / or authorization is passed and it can access the first network;

[0404] The first network allows or supports the first service, and the first service is a service other than obtaining a certificate and / or subscription of the first object through the first network;

[0405] The first network is one of the following: a non-public network, a network of the SNPN type;

[0406] The first network and / or the first server satisfy at least one of the following:

[0407] Do not support the certificate and / or subscription acquisition method supported or requested by the terminal;

[0408] Do not allow the certificate and / or subscription acquisition method supported or requested by the terminal;

[0409] Do not support the terminal to obtain a certificate and / or subscription of the first object through the first network;

[0410] Do not allow the terminal to obtain a certificate and / or subscription of the first object through the first network.

[0411] Optionally, the type of the non-first access method includes any one of the following:

[0412] Initial registration, mobile registration update, periodic registration update, emergency registration.

[0413] Optionally, the first network and / or the first server do not support the certificate and / or subscription acquisition method supported or requested by the terminal, including at least one of the following:

[0414] The terminal only supports or requests to obtain a certificate and / or subscription through the control plane, and the first network and / or the first server only support configuring the certificate and / or subscription through the user plane;

[0415] The terminal only supports or requests to obtain a certificate and / or subscription through the control plane, and the first network and / or the first server do not support configuring the certificate and / or subscription through the control plane;

[0416] The terminal only supports or requests to obtain a certificate and / or sign a contract through the user plane, and the first network and / or the first server only support configuring the certificate and / or signing the contract through the control plane;

[0417] The terminal only supports or requests to obtain a certificate and / or sign a contract through the user plane, and the first network and / or the first server do not support configuring the certificate and / or signing the contract through the user plane;

[0418] The first network and / or the first server do not support the terminal to obtain a certificate and / or sign a contract.

[0419] Optionally, the first network and / or the first server do not allow the obtaining method of the certificate and / or signing the contract supported or requested by the terminal, including at least one of the following:

[0420] The terminal only supports or requests to obtain a certificate and / or sign a contract through the control plane, and the first network and / or the first server only allow configuring the certificate and / or signing the contract through the user plane;

[0421] The terminal only supports or requests to obtain a certificate and / or sign a contract through the control plane, and the first network and / or the first server do not allow configuring the certificate and / or signing the contract through the control plane;

[0422] The terminal only supports or requests to obtain a certificate and / or sign a contract through the user plane, and the first network and / or the first server only allow configuring the certificate and / or signing the contract through the control plane;

[0423] The terminal only supports or requests to obtain a certificate and / or sign a contract through the user plane, and the first network and / or the first server do not allow configuring the certificate and / or signing the contract through the user plane;

[0424] The first network and / or the first server do not allow the terminal to obtain a certificate and / or sign a contract.

[0425] In this embodiment, the information processing device 60 can implement each process implemented in the method embodiment of the present application Figure 2 and achieve the same beneficial effects. To avoid repetition, it will not be elaborated here.

[0426] Please refer to Figure 7 , the embodiment of the present application provides an information processing device, which is applied to a network-side device, such as Figure 7 shown, the information processing device 70 includes:

[0427] A second execution module 71, configured to execute a second operation;

[0428] Wherein, the second operation includes at least one of the following:

[0429] Determine to initiate deregistration from the first network, or determine not to initiate deregistration from the first network;

[0430] Initiate deregistration from the first network;

[0431] Remove the first network from the first list;

[0432] Move the first network to the second list;

[0433] Wherein, the first list includes any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the first list include at least one of the following: the terminal can access restrictedly, can enable the terminal to obtain a certificate and / or sign a contract, the terminal can access using a default certificate;

[0434] Or, the first list includes at least one of the following: a list of networks that can be access restrictedly, a list of networks that can configure a certificate and / or sign a contract, a list of networks that can access using a default certificate;

[0435] Wherein, the second list includes any one of the following: one or more network objects, identification information of one or more network objects; the characteristics of the networks in the second list include at least one of the following: the terminal cannot access, cannot enable the terminal to obtain a certificate and / or sign a contract, the terminal cannot access using a default certificate;

[0436] Or, the second list includes at least one of the following: a list of networks that cannot be access restrictedly, a list of networks that cannot configure a certificate and / or sign a contract, a list of networks that cannot access using a default certificate;

[0437] The network list includes one or more network objects, or the network list includes identification information of one or more network objects;

[0438] The network object includes a network and / or a network group.

[0439] Optionally, the second execution module 71 is further configured to:

[0440] Initiate deregistration from the first network when a third condition is met;

[0441] Wherein, the third condition includes at least one of the following:

[0442] The purpose of the terminal accessing the first network is to obtain a certificate and / or sign a contract for a first object through the first network;

[0443] The access type of the terminal accessing the first network is: the type of the first access method;

[0444] The terminal fails to obtain a certificate and / or sign a contract for a first object through the first network.

[0445] Optionally, the second execution module 71 is further configured to:

[0446] When a fourth condition is satisfied, determine not to initiate deregistration from the first network;

[0447] The purpose of the terminal accessing the first network is not only to obtain the certificate and / or signature of the first object through the first network;

[0448] The access type of the terminal accessing the first network is: a type other than the first access method;

[0449] The terminal fails to obtain the certificate and / or signature of the first object through the first network.

[0450] Optionally, the second execution module 71 is further configured to:

[0451] When a fifth condition is satisfied, remove the first network from the first list and / or move it to the second list;

[0452] Wherein, the fifth condition includes:

[0453] The terminal fails to obtain the certificate and / or signature of the first object through the first network.

[0454] Optionally, the situation that the terminal fails to obtain the certificate and / or signature of the first object through the first network includes at least one of the following:

[0455] Failing to obtain the network certificate and / or signature of the first object through the control plane method;

[0456] Failing to obtain the network certificate and / or signature of the first object through the user plane method;

[0457] The timer expires or the waiting time expires, and the certificate and / or signature of the first object are not received from the control plane of the first network;

[0458] Failing to initiate obtaining the certificate and / or signature of the first object through the user plane method;

[0459] The terminal only supports obtaining the certificate and / or signature of the first object through the control plane method, and the timer expires or the waiting time expires, and the second certificate and / or signature are not received from the control plane of the first network;

[0460] The terminal only supports obtaining the certificate and / or signature of the first object through the user plane method, and the initiation of obtaining the second certificate and / or signature through the user plane method fails;

[0461] The terminal supports obtaining the certificate and / or subscription of the first object through both the control plane method and the user plane method at the same time, and the timer expires or the waiting time expires, but the second certificate and / or subscription is not received from the control plane of the first network, and the attempt to obtain the certificate and / or subscription of the first object through the user plane method fails;

[0462] The terminal supports obtaining the certificate and / or subscription through both the control plane method and the user plane method at the same time, and the attempt to obtain the certificate and / or subscription of the first object through the user plane method fails.

[0463] Optionally, the second execution module 71 is further configured to:

[0464] Obtain second information, and perform the second operation according to the second information;

[0465] Wherein, the second information includes at least one of the following: an access rejection message, a first rejection reason, a first indication message; the first indication message is used to indicate at least one of the following: does not support the terminal to obtain the certificate and / or subscription, does not support the terminal to obtain the certificate and / or subscription through the control plane method, does not support the terminal to obtain the certificate and / or subscription through the user plane method;

[0466] The first rejection reason is used to indicate at least one of the following: does not allow or does not support the terminal to obtain the certificate and / or subscription, does not allow or does not support the terminal to obtain the certificate and / or subscription through the control plane method, does not allow or does not support the terminal to obtain the certificate and / or subscription through the user plane method, the network does not allow the terminal to access, SNPN does not allow, PLMN does not allow.

[0467] Optionally, the second execution module 71 is further configured to:

[0468] In the case where the sixth condition is satisfied, initiate deregistration with the first network;

[0469] Wherein, the sixth condition includes at least one of the following:

[0470] The purpose of the terminal accessing the first network is to obtain the certificate and / or subscription of the first object through the first network;

[0471] The access type of the terminal accessing the first network is: the type of the first access method;

[0472] The first indication message indicates at least one of the following: does not support configuring the certificate and / or subscription, does not support configuring the certificate and / or subscription through the control plane method, does not support configuring the certificate and / or subscription through the user plane method;

[0473] The first indication message indicates that the terminal is not supported to obtain the certificate and / or subscription through the control plane method, and the terminal only supports obtaining the certificate and / or subscription through the control plane method;

[0474] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

[0475] Optionally, the second execution module 71 is further configured to:

[0476] When the seventh condition is satisfied, determine not to initiate deregistration to the first network;

[0477] Wherein, the seventh condition includes at least one of the following:

[0478] The purpose of the terminal accessing the first network is not only to obtain a certificate and / or sign a contract of the first object through the first network;

[0479] The access type of the terminal accessing the first network is: a type other than the first access method;

[0480] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract;

[0481] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane;

[0482] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

[0483] Optionally, the second execution module 71 is further configured to:

[0484] When the eighth condition is satisfied, remove the first network from the first list and / or move it to the second list;

[0485] Wherein, the eighth condition includes at least one of the following:

[0486] Obtain an access rejection message;

[0487] Obtain the first rejection reason, or obtain the first indication information;

[0488] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract;

[0489] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane;

[0490] The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

[0491] Optionally, the second execution module 71 is further configured to:

[0492] When the ninth condition is satisfied, remove the first network from the first list of obtaining certificates and / or signing through the control plane, and / or move the first network to the second list of obtaining certificates and / or signing through the control plane;

[0493] Wherein, the ninth condition includes:

[0494] The first indication information indicates that the terminal is not supported to obtain certificates and / or sign through the control plane.

[0495] Optionally, the second execution module 71 is further configured to:

[0496] When the tenth condition is satisfied, remove the first network from the first list of obtaining certificates and / or signing through the user plane, and / or move the first network to the second list of obtaining certificates and / or signing through the user plane;

[0497] Wherein, the tenth condition includes at least one of the following:

[0498] Obtain an access rejection message;

[0499] Obtain a first rejection reason, or obtain a first indication information;

[0500] The first rejection reason indicates that the terminal is not allowed or not supported to obtain certificates and / or sign through the user plane;

[0501] The first indication information indicates that the terminal is not supported to obtain certificates and / or sign through the user plane.

[0502] In this embodiment, the information processing device 70 can implement each process implemented in the method embodiment of the present application Figure 3 and achieve the same beneficial effects. To avoid repetition, it will not be elaborated here.

[0503] Optionally, as Figure 8 shown, an embodiment of the present application further provides a communication device 80, including a processor 81, a memory 82, a program or instruction stored on the memory 82 and executable on the processor 81. For example, when the communication device 80 is a network-side device, when the program or instruction is executed by the processor 81, it implements each process of the method embodiment shown above Figure 2 and can achieve the same technical effects. When the communication device 80 is a network terminal, when the program or instruction is executed by the processor 81, it implements each process of the method embodiment shown above Figure 3 and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0504] The embodiments of the present application further provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the information processing method embodiment described above Figure 2 or Figure 3 shown, and can achieve the same technical effects. To avoid repetition, details are not described here again.

[0505] Wherein, the processor is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk or optical disc, etc.

[0506] The embodiments of the present application further provide a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a network-side device program or instruction to implement each process of the information processing method embodiment described above Figure 2 or Figure 3 shown, and can achieve the same technical effects. To avoid repetition, details are not described here again.

[0507] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip.

[0508] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0509] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0510] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. An information processing method, applied to a network-side device, characterized in that, including: obtaining first information; performing a first operation according to the first information; the first operation includes: sending a first message, the first message includes a first rejection reason, the first rejection reason is used to indicate that the standalone non-public network (SNPN) does not allow the terminal to access; wherein, the first information includes at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the certificate and / or subscription acquisition method requested by the terminal; wherein, the capability information of the terminal includes at least one of the following: support or not support for obtaining a certificate and / or subscription, support or not support for obtaining a certificate and / or subscription through the control plane, support or not support for obtaining a certificate and / or subscription through the user plane; the capability information of the first network and / or the capability information of the first server includes at least one of the following: support or not support for configuring a certificate and / or subscription, support or not support for configuring a certificate and / or subscription through the control plane, support or not support for configuring a certificate and / or subscription through the user plane; the access type information of the terminal accessing the first network includes one of the following: the type of the first access method, the type of non-first access method; the first access method includes at least one of the following: the access method for accessing the network to obtain a certificate and / or subscription, the access method using a restricted access network, the access method using a default certificate to access the network; the certificate and / or subscription acquisition method requested by the terminal includes at least one of the following: obtaining a certificate and / or subscription through the control plane, obtaining a certificate and / or subscription through the user plane; wherein, the first rejection reason is used for the terminal to move the first network into a second list, and the first network is an SNPN; wherein, the second list includes any one of the following: one or more network objects, the identification information of one or more network objects; the networks in the second list include any one of the following: the networks that the terminal cannot access, the networks that cannot enable the terminal to obtain a certificate and / or subscription, the networks that the terminal cannot access using a default certificate; the network object includes a network and / or a network group.

2. The method according to claim 1, wherein the first message is a message for rejecting the terminal access.

3. The method according to claim 1, the first operation further includes at least one of the following: determining to accept the terminal access, or determining to reject the terminal access; determining the rejection reason; determining the value of the first indication information; including the first indication information in a second message and sending the second message; Among them, the first indication information is used to indicate at least one of the following: support or not support for configuring a certificate and / or subscription; support or not support for configuring a certificate and / or subscription through the control plane; support or not support for configuring a certificate and / or subscription through the user plane.

4. The method according to claim 1 or 3, wherein the certificate and / or subscription includes at least one of the following: the certificate and / or subscription of the first object, the certificate and / or subscription for primary authentication and / or authorization, the certificate and / or subscription for authorization, the certificate and / or subscription for non-primary authentication, the certificate and / or subscription for non-authorization; Among them, the first object includes at least one of the following: A network, a first entity, the network accessed by the terminal, primary authentication and / or authorization, non-primary authentication and / or authorization; The first entity includes one of the following: an entity in the data network, an entity outside the network to which the terminal belongs, an entity outside the first network; the first network is the network accessed by the terminal; The A network is the same as or different from the first network; and / or The configuration certificate and / or subscription includes at least one of the following: configuration certificate and / or subscription based on restricted access, configuration certificate and / or subscription based on non-restricted access; and / or The configuration of the certificate and / or subscription by the control plane mode includes at least one of the following: configuration of the certificate and / or subscription by the control plane mode based on restricted access, configuration of the certificate and / or subscription by the control plane mode based on non-restricted access; and / or The configuration of the certificate and / or subscription by the user plane mode includes at least one of the following: configuration of the certificate and / or subscription by the user plane mode based on restricted access, configuration of the certificate and / or subscription by the user plane mode based on non-restricted access; and / or The obtaining of the certificate and / or subscription includes: obtaining the certificate and / or subscription based on restricted access, obtaining the certificate and / or subscription based on non-restricted access; and / or The obtaining of the certificate and / or subscription by the control plane mode includes at least one of the following: obtaining the certificate and / or subscription by the control plane mode based on restricted access, obtaining the certificate and / or subscription by the control plane mode based on non-restricted access; and / or The obtaining of the certificate and / or subscription by the user plane mode includes at least one of the following: obtaining the configured certificate and / or subscription by the user plane mode based on restricted access, obtaining the certificate and / or subscription by the user plane mode based on non-restricted access.

5. The method according to claim 2, wherein The sending of the first message includes: When a first condition is satisfied, sending a first message, where the first message contains a first rejection reason; Among them, the first condition includes at least one of the following: The access type of the terminal accessing the first network is: the type of the first access mode; The terminal does not have a certificate and / or subscription for non-restricted access to the first network; The certificate and / or subscription of the terminal accessing the first network is a certificate and / or subscription for the restricted access type; The terminal authentication and / or authorization fails and it cannot access the first network; The first network is one of the following: a public network, a network of the Public Land Mobile Network (PLMN) type; Among them, the first network satisfies at least one of the following: It does not support the obtaining method of the certificate and / or subscription supported or requested by the terminal; It does not allow the obtaining method of the certificate and / or subscription supported or requested by the terminal; It does not support the terminal to obtain the certificate and / or subscription of the first object through the first network; It does not allow the terminal to obtain the certificate and / or subscription of the first object through the first network.

6. The method according to claim 3, wherein When a second condition is satisfied, perform at least one of the following: Determine to accept the terminal to access the first network; Determine that the value of the first indication information is at least one of the following: does not support configuration of the certificate and / or subscription, does not support configuration of the certificate and / or subscription by the control plane mode, does not support configuration of the certificate and / or subscription by the user plane mode; Send a message for accepting terminal access; Send a message for accepting terminal access, and the message for accepting terminal access contains the first indication information; Wherein, the second condition includes at least one of the following: The terminal access type is: a type other than the first access method; The terminal has a certificate and / or subscription for restricted access to the first network; The terminal has a certificate and / or subscription for unrestricted access to the first network; The terminal authentication and / or authorization is passed and it can access the first network; The first network allows or supports the first service, and the first service is a service other than obtaining the certificate and / or subscription of the first object through the first network; The first network is one of the following: a non-public network, a network of the SNPN type; The first network and / or the first server satisfy at least one of the following: Do not support the certificate and / or subscription acquisition method supported or requested by the terminal; Do not allow the certificate and / or subscription acquisition method supported or requested by the terminal; Do not support the terminal to obtain the certificate and / or subscription of the first object through the first network; Do not allow the terminal to obtain the certificate and / or subscription of the first object through the first network.

7. The method according to claim 1 or 6, characterized in that, The type of the non-first access method includes any one of the following: Initial registration, mobile registration update, periodic registration update, emergency registration.

8. The method according to claim 6, characterized in that, The first network and / or the first server do not support the certificate and / or subscription acquisition method supported or requested by the terminal, including at least one of the following: The terminal only supports or requests to obtain the certificate and / or subscription through the control plane, and the first network and / or the first server only support configuring the certificate and / or subscription through the user plane; The terminal only supports or requests to obtain the certificate and / or subscription through the control plane, and the first network and / or the first server do not support configuring the certificate and / or subscription through the control plane; The terminal only supports or requests to obtain the certificate and / or subscription through the user plane, and the first network and / or the first server only support configuring the certificate and / or subscription through the control plane; The terminal only supports or requests to obtain the certificate and / or subscription through the user plane, and the first network and / or the first server do not support configuring the certificate and / or subscription through the user plane; The first network and / or the first server do not support the terminal to obtain the certificate and / or subscription.

9. The method according to claim 6, characterized in that The first network and / or the first server do not allow the certificate and / or subscription acquisition method supported or requested by the terminal, including at least one of the following: The terminal only supports or requests to obtain the certificate and / or subscription through the control plane, and the first network and / or the first server only allow configuring the certificate and / or subscription through the user plane; The terminal only supports or requests to obtain the certificate and / or subscription through the control plane, and the first network and / or the first server do not allow configuring the certificate and / or subscription through the control plane; The terminal only supports or requests to obtain the certificate and / or subscription through the user plane, and the first network and / or the first server only allow configuring the certificate and / or subscription through the control plane; The terminal only supports or requests to obtain the certificate and / or subscription through the user plane, and the first network and / or the first server do not allow configuring the certificate and / or subscription through the user plane; The first network and / or the first server do not allow the terminal to obtain a certificate and / or sign a contract.

10. An information processing method, applied to a terminal, characterized in that, Including: Obtain a first rejection reason, and perform a second operation according to the first rejection reason; wherein, the first rejection reason is used to indicate that the SNPN does not allow the terminal to access; Wherein, the second operation includes: Move the first network into a second list, where the first network is the SNPN; Wherein, the second list includes any one of the following: one or more network objects, identification information of one or more network objects; the networks in the second list include any one of the following: networks that the terminal cannot access, networks that cannot enable the terminal to obtain a certificate and / or sign a contract, networks that the terminal cannot access using a default certificate; The network object includes a network and / or a network group.

11. The method according to claim 10, wherein Wherein, The second operation further includes at least one of the following: Determine to initiate deregistration to the first network, or determine not to initiate deregistration to the first network; Initiate deregistration to the first network; Remove the first network from the first list; Wherein, the first list includes any one of the following: one or more network objects, identification information of one or more network objects; Wherein, the networks in the first list include any one of the following: networks that allow the terminal to access, networks that allow the terminal to obtain a certificate and / or sign a contract, networks that allow the terminal to access using a default certificate.

12. The method according to claim 11, wherein, The certificate and / or the contract include at least one of the following: a certificate and / or a contract of a first object, a certificate and / or a contract for primary authentication and / or authorization, a certificate and / or a contract for authorization, a certificate and / or a contract for non-primary authentication, a certificate and / or a contract for non-authorization; Wherein, the first object includes at least one of the following: Network A, a first entity, a network accessed by the terminal, primary authentication and / or authorization, non-primary authentication and / or authorization; The first entity includes one of the following: an entity in a data network, an entity outside the network to which the terminal belongs, an entity outside the first network; the first network is the network accessed by the terminal; Network A is the same as or different from the networks in the first list; And / or, Network A is the same as or different from the networks in the second list; And / or, The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through the control plane method, obtaining the certificate and / or the contract through the user plane method; And / or, The list of networks capable of configuring the certificate and / or the contract includes at least one of the following: a list of networks capable of configuring the certificate and / or the contract through the control plane method, a list of networks capable of configuring the certificate and / or the contract through the user plane method; And / or, The enabling of the terminal to obtain the certificate and / or the contract includes at least one of the following: enabling the terminal to obtain the certificate and / or the contract through the control plane method, enabling the terminal to obtain the certificate and / or the contract through the user plane method.

13. The method according to claim 11, wherein, The first list is the first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different; And / or, The second list is the second list corresponding to the first object, and the second lists corresponding to different first objects may be the same or different; and / or, The network list capable of configuring the certificate and / or signing includes: the network list capable of configuring the certificate and / or signing of the first object; and / or, The network list incapable of configuring the certificate and / or signing includes: the network list incapable of configuring the certificate and / or signing of the first object; and / or, Enabling the terminal to obtain the certificate and / or signing includes: enabling the terminal to obtain the certificate and / or signing of the first object; and / or, Incapable of enabling the terminal to obtain the certificate and / or signing includes: incapable of enabling the terminal to obtain the certificate and / or signing of the first object.

14. The method according to claim 13, wherein The first list corresponding to the first object includes: the first list corresponding to the first object in the control plane mode, and the first list corresponding to the first object in the user plane mode; Among them, the first list corresponding to the first object in the control plane mode and the first list corresponding to the first object in the user plane mode may be the same or different; The networks in the first list corresponding to the first object in the control plane mode include: the networks capable of enabling the terminal to obtain the certificate and / or signing of the first object in the control plane mode; The networks in the first list corresponding to the first object in the user plane mode include: the networks capable of enabling the terminal to obtain the certificate and / or signing of the first object in the user plane mode; and / or, The second list corresponding to the first object includes: the second list corresponding to the first object in the control plane mode, and the second list corresponding to the first object in the user plane mode; Among them, the second list corresponding to the first object in the control plane mode and the second list corresponding to the first object in the user plane mode may be the same or different; The networks in the second list corresponding to the first object in the control plane mode include: the networks incapable of enabling the terminal to obtain the certificate and / or signing of the first object in the control plane mode; The networks in the second list corresponding to the first object in the user plane mode include: the networks incapable of enabling the terminal to obtain the certificate and / or signing of the first object in the user plane mode; and / or, The network list capable of configuring the certificate and / or signing of the first object includes at least one of the following: the network list capable of configuring the certificate and / or signing of the first object in the control plane mode, and the network list capable of configuring the certificate and / or signing of the first object in the user plane mode; and / or, The network list incapable of configuring the certificate and / or signing of the first object includes at least one of the following: the network list incapable of configuring the certificate and / or signing of the first object in the control plane mode, and the network list incapable of configuring the certificate and / or signing of the first object in the user plane mode; and / or, Enabling the terminal to obtain the certificate and / or signing of the first object includes at least one of the following: enabling the terminal to obtain the certificate and / or signing of the first object in the control plane mode, and enabling the terminal to obtain the certificate and / or signing of the first object in the user plane mode; and / or, The inability to enable the terminal to obtain the certificate and / or signature of the first object includes at least one of the following: the inability to enable the terminal to obtain the certificate and / or signature of the first object through the control plane, and the inability to enable the terminal to obtain the certificate and / or signature of the first object through the user plane.

15. The method according to claim 11, wherein when a third condition is satisfied, deregistration is initiated to the first network; wherein the third condition includes at least one of the following: the purpose of the terminal accessing the first network is to obtain the certificate and / or signature of the first object through the first network; the access type of the terminal accessing the first network is: the type of the first access method; the terminal fails to obtain the certificate and / or signature of the first object through the first network; wherein the first access method includes at least one of the following: the access method for accessing the network to obtain the certificate and / or signature, the access method for accessing the restricted access network, and the access method for accessing the network with the default certificate.

16. The method according to claim 11, wherein when a fourth condition is satisfied, it is determined not to initiate deregistration to the first network; wherein the fourth condition includes at least one of the following: the purpose of the terminal accessing the first network is not only to obtain the certificate and / or signature of the first object through the first network; the access type of the terminal accessing the first network is: the type of non-first access method; the terminal fails to obtain the certificate and / or signature of the first object through the first network; wherein the first access method includes at least one of the following: the access method for accessing the network to obtain the certificate and / or signature, the access method for accessing the restricted access network, and the access method for accessing the network with the default certificate.

17. The method according to claim 10 or 11, wherein when a fifth condition is satisfied, the first network is removed from the first list and / or moved into the second list; wherein the fifth condition includes: the terminal fails to obtain the certificate and / or signature of the first object through the first network.

18. The method according to any one of claims 15 to 16, characterized in that, The failure of the terminal to obtain the certificate and / or signature of the first object through the first network includes at least one of the following: the failure to obtain the network certificate and / or signature of the first object through the control plane; the failure to obtain the network certificate and / or signature of the first object through the user plane; the timer expires or the waiting time expires, and the certificate and / or signature of the first object are not received from the control plane of the first network; the initiated attempt to obtain the certificate and / or signature of the first object through the user plane fails; the terminal only supports obtaining the certificate and / or signature of the first object through the control plane, and the timer expires or the waiting time expires, and the second certificate and / or signature are not received from the control plane of the first network; the terminal only supports obtaining the certificate and / or signature of the first object through the user plane, and the initiated request for the second certificate and / or signature through the user plane fails; The terminal supports obtaining the certificate and / or subscription of the first object through both the control plane and the user plane at the same time, and the timer expires or the waiting time expires, but the second certificate and / or subscription is not received from the control plane of the first network, and the attempt to obtain the certificate and / or subscription of the first object through the user plane fails; The terminal supports obtaining the certificate and / or subscription through both the control plane and the user plane at the same time, and the attempt to obtain the certificate and / or subscription of the first object through the user plane fails.

19. The method according to any one of claims 10 to 11 and 14, characterized in that, The execution of the second operation further includes: Obtaining second information and performing the second operation according to the second information; Wherein, the second information includes at least one of the following: an access rejection message, a first rejection reason, a first indication information; the first indication information is used to indicate at least one of the following: not supporting the terminal to obtain the certificate and / or subscription, not supporting the terminal to obtain the certificate and / or subscription through the control plane, not supporting the terminal to obtain the certificate and / or subscription through the user plane; The first rejection reason is used to indicate at least one of the following: not allowing or not supporting the terminal to obtain the certificate and / or subscription, not allowing or not supporting the terminal to obtain the certificate and / or subscription through the control plane, not allowing or not supporting the terminal to obtain the certificate and / or subscription through the user plane, the network does not allow the terminal to access, the SNPN does not allow, the PLMN does not allow.

20. The method according to claim 19, wherein In the case of meeting the sixth condition, initiate deregistration with the first network; Wherein, the sixth condition includes at least one of the following: The purpose of the terminal accessing the first network is to obtain the certificate and / or subscription of the first object through the first network; The access type of the terminal accessing the first network is: the type of the first access method; The first indication information indicates at least one of the following: not supporting configuring the certificate and / or subscription, not supporting configuring the certificate and / or subscription through the control plane, not supporting configuring the certificate and / or subscription through the user plane; The first indication information indicates that the terminal is not supported to obtain the certificate and / or subscription through the control plane, and the terminal only supports obtaining the certificate and / or subscription through the control plane; The first indication information indicates that the terminal is not supported to obtain the certificate and / or subscription through the user plane, and the terminal only supports obtaining the certificate and / or subscription through the user plane; Wherein, the first access method includes at least one of the following: the access method for accessing the network to obtain the certificate and / or subscription, the access method using a restricted access network, the access method using a default certificate to access the network.

21. The method according to claim 19, wherein In the case of meeting the seventh condition, determine not to initiate deregistration with the first network; Wherein, the seventh condition includes at least one of the following: The purpose of the terminal accessing the first network is not only to obtain the certificate and / or subscription of the first object through the first network; The access type of the terminal accessing the first network is: a type other than the first access method; The first indication information indicates that the terminal is not supported to obtain the certificate and / or subscription; The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane; The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane; Wherein, the first access mode includes at least one of the following: an access mode for accessing the network to obtain a certificate and / or sign a contract, an access mode using a restricted access network, and an access mode using a default certificate to access the network.

22. The method according to claim 19, wherein, When the eighth condition is met, remove the first network from the first list and / or move it into the second list; Wherein, the eighth condition includes at least one of the following: Obtain an access rejection message; Obtain a first rejection reason, or obtain a first indication information; The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract; The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane, and the terminal only supports obtaining a certificate and / or signing a contract through the control plane; The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane, and the terminal only supports obtaining a certificate and / or signing a contract through the user plane.

23. The method according to claim 19, wherein, When the ninth condition is met, remove the first network from the first list for obtaining a certificate and / or signing a contract through the control plane, and / or move the first network into the second list for obtaining a certificate and / or signing a contract through the control plane; Wherein, the ninth condition includes: The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the control plane.

24. The method according to claim 19, wherein, When the tenth condition is met, remove the first network from the first list for obtaining a certificate and / or signing a contract through the user plane, and / or move the first network into the second list for obtaining a certificate and / or signing a contract through the user plane; Wherein, the tenth condition includes at least one of the following: Obtain an access rejection message; Obtain a first rejection reason, or obtain a first indication information; The first rejection reason indicates that the terminal is not allowed or not supported to obtain a certificate and / or sign a contract through the user plane; The first indication information indicates that the terminal is not supported to obtain a certificate and / or sign a contract through the user plane.

25. The method according to claim 20, wherein, The configuration of the certificate and / or signing includes at least one of the following: configuring the certificate and / or signing based on restricted access, and configuring the certificate and / or signing based on unrestricted access; And / or, The configuration of the certificate and / or signing through the control plane includes at least one of the following: configuring the certificate and / or signing through the control plane based on restricted access, and configuring the certificate and / or signing through the control plane based on unrestricted access; And / or, Configuring a certificate and / or subscribing in the user plane mode includes at least one of the following: configuring a certificate and / or subscribing in the user plane mode based on restricted access, configuring a certificate and / or subscribing in the user plane mode based on unrestricted access; and / or, Obtaining a certificate and / or subscribing includes: obtaining a certificate and / or subscribing based on restricted access, obtaining a certificate and / or subscribing based on unrestricted access and / or, Obtaining a certificate and / or subscribing in the control plane mode includes at least one of the following: obtaining a certificate and / or subscribing in the control plane mode based on restricted access, obtaining a certificate and / or subscribing in the control plane mode based on unrestricted access; and / or, Obtaining a certificate and / or subscribing in the user plane mode includes at least one of the following: obtaining a configured certificate and / or subscribing in the user plane mode based on restricted access, obtaining a certificate and / or subscribing in the user plane mode based on unrestricted access.

26. An information processing apparatus, applied to a network-side device, characterized in that, Includes: An obtaining module, configured to obtain first information; A first execution module, configured to perform a first operation according to the first information; The first operation includes: sending a first message, where the first message contains a first rejection reason, and the first rejection reason is used to indicate that a Standalone Non-Public Network (SNPN) does not allow a terminal to access; Wherein, the first information includes at least one of the following: the capability information of the terminal, the capability information of the first network, the capability information of the first server, the access type information of the terminal accessing the first network, the method for obtaining a certificate and / or subscribing requested by the terminal; Wherein, the capability information of the terminal includes at least one of the following: supporting or not supporting obtaining a certificate and / or subscribing, supporting or not supporting obtaining a certificate and / or subscribing in the control plane mode, supporting or not supporting obtaining a certificate and / or subscribing in the user plane mode; The capability information of the first network and / or the capability information of the first server includes at least one of the following: supporting or not supporting configuring a certificate and / or subscribing, supporting or not supporting configuring a certificate and / or subscribing in the control plane mode, supporting or not supporting configuring a certificate and / or subscribing in the user plane mode; The access type information of the terminal accessing the first network includes one of the following: the type of the first access method, the type of a non-first access method; The first access method includes at least one of the following: an access method for accessing the network to obtain a certificate and / or subscribe, an access method for accessing the network using restricted access, an access method for accessing the network using a default certificate; The method for obtaining a certificate and / or subscribing requested by the terminal includes at least one of the following: obtaining a certificate and / or subscribing in the control plane mode, obtaining a certificate and / or subscribing in the user plane mode; Wherein, the first rejection reason is used for the terminal to move the first network into a second list, and the first network is an SNPN; Wherein, the second list includes any one of the following: one or more network objects, the identification information of one or more network objects; the networks in the second list include any one of the following: networks that the terminal cannot access, networks that cannot enable the terminal to obtain a certificate and / or subscribe, networks that the terminal cannot access using a default certificate; The network object includes a network and / or a network group.

27. An information processing apparatus, applied to a terminal, characterized in that, Includes: A second execution module, configured to obtain a first rejection reason and perform a second operation according to the first rejection reason, where the first rejection reason is used to indicate that the SNPN does not allow the terminal to access; Wherein, the second operation includes at least one of the following: Moving a first network into a second list, where the first network is the SNPN; Wherein, the second list includes any one of the following: one or more network objects, identification information of one or more network objects; the networks in the second list include any one of the following: networks that the terminal cannot access, networks that cannot enable the terminal to obtain a certificate and / or sign a contract, networks that the terminal cannot access using the default certificate; The network object includes a network and / or a network group.

28. A communication device, characterized in that, It includes a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, it implements the steps of the information processing method according to any one of claims 1 to 9, or implements the steps of the information processing method according to any one of claims 10 to 25.

29. A readable storage medium, characterized in that, A program or instruction is stored on the readable storage medium. When the program or instruction is executed by the processor, it implements the steps of the information processing method according to any one of claims 1 to 9, or implements the steps of the information processing method according to any one of claims 10 to 25.

Citation Information

Patent Citations

  • Network service control method and communication equipment

    CN110971641A