Method, device, equipment and readable storage medium supporting network selection

By providing network feature list and indication information, the terminal device can effectively select the network for certificate download, solving the problem of certificate acquisition when selecting a network, and achieving flexible and efficient network access.

CN114885321BActive Publication Date: 2025-06-06VIVO MOBILE COMM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110164165.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-05
Publication Date
2025-06-06
Estimated Expiration
2041-02-05

AI Technical Summary

Technical Problem

When the terminal device selects a network, it is difficult to determine how to access a network with certificates for unrestricted access to download certificates for other networks.

Method used

By obtaining information containing the list of network features and indication information, the terminal device can select a suitable network based on this information for certificate download. Specifically, the list includes a network capable of restricted access, configuring certificates and/or contracts, and accessing with default certificates, and the indication information indicates supported configuration methods.

Benefits of technology

It realizes the flexibility and efficiency of terminal devices when selecting networks, ensuring that the devices can access correctly and obtain the required certificates and contracts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114885321B_ABST
    Figure CN114885321B_ABST
Patent Text Reader

Abstract

The present application discloses a method, apparatus, device and readable storage medium for supporting network selection, the method comprising: obtaining first information, the first information comprising: a first list, a second list and / or first indication information; selecting a network according to the first information. In an embodiment of the present application, the first communication device can select a network for downloading a certificate and / or signing a contract according to the first information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of communication technology, and specifically relates to a method, apparatus, device and readable storage medium for supporting network selection. Background Art

[0002] A terminal (eg, a user equipment (UE)) wishes to temporarily access a first network to obtain a certificate and / or a contract with a first object. How to select the first network is an urgent problem to be solved. Summary of the invention

[0003] The embodiments of the present application provide a method, apparatus, device and readable storage medium for supporting network selection, which solve the problem of how to select a network for downloading a certificate and / or signing a contract.

[0004] In a first aspect, a method for supporting network selection is provided, which is performed by a first communication device and includes:

[0005] Obtaining first information, wherein the first information includes: a first list, a second list and / or first indication information;

[0006] selecting a network according to the first information;

[0007] in,

[0008] The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be accessed with limited access, the first communication device can obtain a certificate and / or sign a contract, and the first communication device can access using a default certificate;

[0009] Alternatively, the first list includes at least one of the following:

[0010] List of networks that can be restricted from access;

[0011] Ability to configure certificates and / or signed network lists;

[0012] List of networks that can be accessed using default credentials;

[0013] The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access, the first communication device cannot obtain a certificate and / or sign a contract, and the first communication device cannot access using a default certificate;

[0014] Alternatively, the second list includes at least one of the following:

[0015] List of networks that cannot be restricted from access;

[0016] Inability to configure certificates and / or signed network lists;

[0017] List of networks that cannot be accessed using default certificates;

[0018] Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and / or network groups;

[0019] The first indication information is used to indicate at least one of the following:

[0020] Support or not support provisioning certificates and / or signing;

[0021] Support or not support configuration of certificates and / or contracts via the control plane;

[0022] Support or not support configuration of certificates and / or signing via user plane;

[0023] Support or not support configuration of certificates and / or contracts based on restricted access;

[0024] Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0025] Support or not support configuration of certificates and / or contracts through user plane based on restricted access;

[0026] Support or not support provisioning of certificates and / or contracts based on unrestricted access;

[0027] Support or not support configuration of certificates and / or contracts via control plane based on unrestricted access;

[0028] Support or not support configuration of certificates and / or subscriptions through the user plane based on unrestricted access.

[0029] In a second aspect, a method for supporting network selection is provided, which is performed by a second communication device and includes:

[0030] Sending first instruction information;

[0031] The first indication information is used to indicate at least one of the following:

[0032] Support or not support provisioning certificates and / or signing;

[0033] Support or not support configuration of certificates and / or contracts via the control plane;

[0034] Support or not support configuration of certificates and / or signing via user plane;

[0035] Support or not support configuration of certificates and / or contracts based on restricted access;

[0036] Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0037] Support or not support configuration of certificates and / or contracts through user plane based on restricted access;

[0038] Support or not support provisioning of certificates and / or contracts based on unrestricted access;

[0039] Support or not support configuration of certificates and / or contracts via control plane based on unrestricted access;

[0040] Support or not support configuration of certificates and / or subscriptions through the user plane based on unrestricted access.

[0041] According to a third aspect, a method for supporting network selection is provided, which is performed by a third communication device and includes:

[0042] sending the first list and / or the second list;

[0043] The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be accessed with limited access, the first communication device can obtain a certificate and / or sign a contract, and the first communication device can access using a default certificate;

[0044] Alternatively, the first list includes at least one of the following:

[0045] A list of networks that can be restricted from access.

[0046] Ability to configure certificates and / or signed network lists,

[0047] List of networks that can be accessed using default credentials;

[0048] The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access, the first communication device cannot obtain a certificate and / or sign a contract, and the first communication device cannot access using a default certificate;

[0049] Alternatively, the second list includes at least one of the following:

[0050] List of networks that cannot be restricted from access;

[0051] Inability to configure certificates and / or signed network lists;

[0052] List of networks that cannot be accessed using default certificates;

[0053] The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and / or network groups.

[0054] In a fourth aspect, a device for supporting network selection is provided, which is executed by a first communication device and includes:

[0055] A first acquisition module, configured to obtain first information, wherein the first information includes: a first list, a second list and / or first indication information;

[0056] A selection module, configured to select a network according to the first information;

[0057] in,

[0058] The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be accessed with limited access, the first communication device can obtain a certificate and / or sign a contract, and the first communication device can access using a default certificate;

[0059] Alternatively, the first list includes at least one of the following:

[0060] List of networks that can be restricted from access;

[0061] Ability to configure certificates and / or signed network lists;

[0062] List of networks that can be accessed using default credentials;

[0063] The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access, the first communication device cannot obtain a certificate and / or sign a contract, and the first communication device cannot access using a default certificate;

[0064] Alternatively, the second list includes at least one of the following:

[0065] List of networks that cannot be restricted from access;

[0066] Inability to configure certificates and / or signed network lists;

[0067] List of networks that cannot be accessed using default certificates;

[0068] Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and / or network groups;

[0069] The first indication information is used to indicate at least one of the following:

[0070] Support or not support provisioning certificates and / or signing;

[0071] Support or not support configuration of certificates and / or contracts via the control plane;

[0072] Support or not support configuration of certificates and / or signing via user plane;

[0073] Support or not support configuration of certificates and / or contracts based on restricted access;

[0074] Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0075] Support or not support configuration of certificates and / or contracts through user plane based on restricted access;

[0076] Support or not support provisioning of certificates and / or contracts based on unrestricted access;

[0077] Support or not support configuration of certificates and / or contracts via control plane based on unrestricted access;

[0078] Support or not support configuration of certificates and / or subscriptions through the user plane based on unrestricted access.

[0079] In a fifth aspect, a device for supporting network selection is provided, which is applied to a second communication device, including:

[0080] A first sending module, used for sending first indication information;

[0081] The first indication information is used to indicate at least one of the following:

[0082] Support or not support provisioning certificates and / or signing;

[0083] Support or not support configuration of certificates and / or contracts via the control plane;

[0084] Support or not support configuration of certificates and / or signing via user plane;

[0085] Support or not support configuration of certificates and / or contracts based on restricted access;

[0086] Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0087] Support or not support configuration of certificates and / or contracts through user plane based on restricted access;

[0088] Support or not support provisioning of certificates and / or contracts based on unrestricted access;

[0089] Support or not support configuration of certificates and / or contracts via control plane based on unrestricted access;

[0090] Support or not support configuration of certificates and / or subscriptions through the user plane based on unrestricted access.

[0091] In a sixth aspect, a device for supporting network selection is provided, which is applied to a third communication device, including:

[0092] A second sending module, used for sending the first list and / or the second list;

[0093] The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be accessed with limited access, the first communication device can obtain a certificate and / or sign a contract, and the first communication device can access using a default certificate;

[0094] Alternatively, the first list includes at least one of the following:

[0095] A list of networks that can be restricted from access.

[0096] Ability to configure certificates and / or signed network lists,

[0097] List of networks that can be accessed using default credentials;

[0098] The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access, the first communication device cannot obtain a certificate and / or sign a contract, and the first communication device cannot access using a default certificate;

[0099] Alternatively, the second list includes at least one of the following:

[0100] List of networks that cannot be restricted from access;

[0101] Inability to configure certificates and / or signed network lists;

[0102] List of networks that cannot be accessed using default certificates;

[0103] The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and / or network groups.

[0104] In a seventh aspect, a terminal is provided, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the method described in the first aspect.

[0105] In an eighth aspect, a network side device is provided, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the method described in the second aspect or the third aspect are implemented.

[0106] In a ninth aspect, a readable storage medium is provided, on which a program or instruction is stored, and the program or instruction, when executed by a processor, implements the steps of the method described above.

[0107] In a tenth aspect, a program product is provided, wherein the program product is stored in a non-volatile storage medium and is executed by at least one processor to implement the steps of the method described above.

[0108] In an eleventh aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps of the method described above.

[0109] In the embodiment of the present application, the first communication device is supported to confirm the selection of a network for downloading a certificate and / or signing a contract. BRIEF DESCRIPTION OF THE DRAWINGS

[0110] Figure 1 is a schematic diagram of a wireless communication system to which the embodiments of the present application can be applied;

[0111] Figure 2 This is one of the flow charts of the method for supporting network selection provided in an embodiment of the present application;

[0112] Figure 3 This is the second flowchart of the method for supporting network selection provided in an embodiment of the present application;

[0113] Figure 4 This is the third flowchart of the method for supporting network selection provided in an embodiment of the present application;

[0114] Figure 5 This is the fourth flowchart of the method for supporting network selection provided in an embodiment of the present application;

[0115] Figure 6 It is one of the schematic diagrams of the device supporting network selection provided in the embodiment of the present application;

[0116] Figure 7 This is the second schematic diagram of the device supporting network selection provided in the embodiment of the present application;

[0117] Figure 8 This is a third schematic diagram of a device for supporting network selection provided in an embodiment of the present application;

[0118] Fig. 9 is a schematic diagram of a terminal provided in an embodiment of the present application;

[0119] Fig.10 It is a schematic diagram of a network side device of an embodiment of the present application. DETAILED DESCRIPTION

[0120] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0121] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first" and "second" are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "and / or" relationship.

[0122] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used for the systems and radio technologies mentioned above as well as for other systems and radio technologies. However, the following description describes a New Radio (NR) system for illustrative purposes, and the NR terminology is used in most of the following descriptions, although these technologies can also be applied to applications other than NR system applications, such as the 6th generation (6 th Generation, 6G) communication system.

[0123] Figure 1A block diagram of a wireless communication system applicable to an embodiment of the present application is shown. The wireless communication system includes a terminal 11 and a network side device 12. Among them, the terminal 11 can also be called a terminal device or a user terminal (User Equipment, UE), and the terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a handheld computer, a netbook, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a mobile Internet device (Mobile Internet Device, MID), a wearable device (Wearable Device) or a vehicle-mounted device (Vehicle User Equipment, VUE), a pedestrian terminal (Pedestrian User Equipment, PUE) and other terminal side devices, and the wearable device includes: a bracelet, a headset, glasses, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 can be a base station or a core network, wherein the base station can be referred to as a node B, an evolved node B, an access point, a base transceiver station (Base Transceiver Station, BTS), a radio base station, a radio transceiver, a basic service set (Basic Service Set, BSS), an extended service set (Extended Service Set, ESS), a B node, an evolved B node (eNB), a home B node, a home evolved B node, a WLAN access point, a WiFi node, a transmitting and receiving point (Transmitting Receiving Point, TRP) or some other suitable term in the field. As long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is taken as an example, but the specific type of the base station is not limited.

[0124] In the related art, a terminal (e.g., a user equipment (UE)) can access a public land mobile network (PLMN) or a standalone non-public network (SNPN) 1 to download a certificate of a first object (e.g., a certificate of SNPN2, or a certificate for secondary authentication and / or authorization). When the UE does not have a certificate of SNPN1 (e.g., a certificate for unrestricted access), if SNPN1 supports the function of a first access method (e.g., onboarding), then SNPN1 can be called an onboarding SNPN (O-SNPN for short). The first access method may be an access method for obtaining a certificate of the first network through a restricted access network and / or through the network. When accessing the Onboarding SNPN, the UE does not have a certificate of the O-SNPN (no certificate for unrestricted access), and uses a default certificate (e.g., a certificate for restricted access) to access the O-SNPN, and an onboarding indication is provided to illustrate the particularity of the UE's registration type. Therefore, in the scenario of O-SNPN, two functions are included:

[0125] (1) Default credential onboarding or restricted access to the network;

[0126] (2) Configuring the certificate and / or signing of the first object.

[0127] The cell of the O-SNPN may broadcast an onboarding indication for the UE to select the O-SNPN and obtain the certificate and / or subscription of the first object.

[0128] When downloading the SNPN2 certificate through the PLMN or SNPN3, since the UE has a certificate that can access the PLMN or SNPN3 (such as a certificate for unrestricted access), the PLMN or SNPN3 may not support the function (1) in essence, but may only support the function (2). Therefore, if the PLMN or SNPN3 is to broadcast the capabilities of the network, it is not suitable to broadcast the indication information for indicating support for onboarding. Therefore, the following problem needs to be solved.

[0129] Problem 1: How does the UE access and select a network that already has a certificate and / or subscription for unrestricted access (such as PLMN and SNPN3) to download the certificate of the SNPN.

[0130] In order to support the problem of network selection, in an optional embodiment of the present application, the optional solution is as follows:

[0131] The network side does not broadcast the indication information used to indicate support for onboarding, but broadcasts the first indication information, which can be used to indicate one of the following: the first indication information for supporting configuration of certificates and / or contracts, and supporting configuration of certificates and / or contracts based on unrestricted access.

[0132] For the UE, if the UE wants to obtain the certificate and / or subscription of the first object (such as SNPN2), the first list is configured on the UE. The UE can access the network in the first list to obtain the certificate and / or subscription of the first object. The first list can be a mixed list of networks of PLMN and / or SNPN type.

[0133] The terminal can select a network according to the first list and the first indication information.

[0134] In one implementation manner, the first list may include at least one of the following:

[0135] (1) Configure the certificate and / or contracted network list through the control plane;

[0136] Optionally, configuring the certificate and / or contract in a control plane manner includes obtaining the certificate and / or contract of the network through control plane signaling. It is not difficult to understand that the terminal needs to have the ability to obtain the certificate and / or contract in a control plane manner, and the first network needs to have the ability to configure the certificate and / or contract in a control plane manner. The first network is a network in the first list.

[0137] (2) Configure the certificate and / or contracted network list through the user plane.

[0138] Optionally, configuring the network column of the certificate and / or contract through the user plane includes obtaining the network certificate and / or contract through the data channel. For example, the terminal establishes a data channel in the first network, and the terminal connects to the configuration server in the data network through the data channel to obtain the certificate and / or contract of the first object. Therefore, the terminal needs to have the ability to obtain the certificate and / or contract through the user plane.

[0139] In one implementation, the terminal needs to obtain the address information of the configuration server from the first network (the first network is a network in the first list). At this time, the first network needs to have a configuration certificate and / or contract in a user plane manner to support it.

[0140] In an optional embodiment of the present application, optionally, obtaining or acquiring can be understood as obtaining from configuration, receiving, receiving after request, obtaining through self-learning, obtaining by deduction based on information not received, or obtaining after processing received information, which can be determined according to actual needs, and the embodiment of the present application does not limit this. For example, when a certain capability indication information sent by a device is not received, it can be inferred that the device does not support the capability.

[0141] In an optional embodiment of the present invention, sending may include broadcasting, broadcasting in a system message, and returning after responding to a request.

[0142] In an optional embodiment of the present invention, "can" may represent at least one of the following: allow, support, inclination, and priority to have the ability. "cannot" may represent at least one of the following: not allow, not support, not allow, not inclination, and not having the ability.

[0143] In an optional embodiment of the present application, the first access method includes at least one of the following: an access method for accessing a network in order to obtain a certificate and / or sign a contract, an access method using a restricted access network, and an access method for accessing a network using a default certificate;

[0144] In one implementation, a method of using a restricted access network in order to download a certificate for accessing a first object, or a method of accessing a network in order to download a certificate for accessing a first object may be referred to as onboarding. When the first object includes a network A, the first network and the network A may be the same network or different networks. The first network is a network accessed by the terminal, such as a currently accessed network.

[0145] In an optional embodiment of the present application, the first server is used to configure a certificate and / or a signed server of the first object for the terminal.

[0146] In an optional embodiment of the present invention, the support for configuring certificates and / or contracts is used to further indicate at least one of the following: supporting configuring certificates and / or contracts via a control plane, and supporting configuring certificates and / or contracts via a user plane.

[0147] In an optional embodiment of the present invention, the non-support of certificate and / or subscription configuration is used to further indicate that certificate and / or subscription configuration via the control plane is not supported, and certificate and / or subscription configuration via the user plane is not supported.

[0148] In an optional embodiment of the present invention, the obtaining of the certificate and / or the contract is remotely obtaining the certificate and / or the contract, for example, when the terminal accesses the first network to obtain the certificate and / or the contract, the provider of the certificate and / or the contract is a first entity. The first entity is an entity in a data network (DN) or an entity outside the network accessed by the terminal.

[0149] In an optional embodiment of the present invention, the provider of the certificate and / or contract is one of the following: an entity outside the network in the first list, an entity outside the network accessed by the terminal, an entity in a data network (DN), and an entity in other networks. The entity in the data network may be an application server, a configuration server for the certificate and / or contract in the data network. The goal of the terminal accessing the network includes obtaining a certificate and / or contract.

[0150] In an optional embodiment of the present invention, the certificate and / or contract is a certificate and / or contract of a network accessed by the terminal. The certificate and / or contract of the network accessed by the terminal includes at least one of the following: a certificate and / or contract of a network used by the terminal for unrestricted access, and a certificate and / or contract of a network used by the terminal for restricted access.

[0151] In an optional embodiment of the present invention, the certificate and / or contract includes at least one of the following: a certificate and / or contract for unrestricted access, a certificate and / or contract for restricted access, a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization. Primary authentication (such as primary authentication (Primary Authentication)) may include: Authentication and Key Agreement (AKA) (for example, fifth generation communication technology (5th generation, 5G) AKA, Extensible Authentication Protocol (EAP) AKA).

[0152] Used for non-primary authentication and / or authorization includes at least one of the following: secondary authentication and / or authorization (Secondary authentication / authorization), slice-related authentication and / or authorization (NSSAA Network Slice-Specific Authentication and Authorization).

[0153] In one implementation, the terminal may access the first network using a certificate (such as a default certificate) and / or a subscription for a restricted access network, and then obtain a certificate and / or a subscription for unrestricted access to the first object (including the A network) through the first network. The A network is the same as or different from the first network.

[0154] In an optional embodiment of the present invention, obtaining a certificate and / or a contract by means of a control plane and / or configuring a certificate and / or a contract by means of a control plane includes at least one of the following: the first entity configures the certificate and / or the contract to the terminal by means of control plane signaling of a network accessed by the terminal; the terminal obtains the certificate and / or the contract from the first entity by means of control plane signaling of the network accessed by the terminal;

[0155] In an optional embodiment of the present invention, obtaining a certificate and / or a contract via a user plane and / or configuring a certificate and / or a contract via a user plane includes at least one of the following: the terminal establishes a data channel in the accessed network, and obtains the certificate and / or contract from the first entity through the data channel; or the first entity configures the certificate and / or contract to the terminal through the data channel established by the terminal in the accessed network.

[0156] In an optional embodiment of the present invention, the data channel includes at least one of the following: the data channel may include but is not limited to one of the following: PDU session, PDN connection, QoS flow, bearer, Internet Protocol Security (IPsec) channel, wherein the bearer may be an evolved radio access bearer (Evolved Radio Access Bearer, E-RAB), a radio access bearer (Evolved Radio Access Bearer, RAB), a data radio bearer (Data Radio Bearer, DRB), a signaling radio bearer (signalling radio bearers, SRB), etc.

[0157] In an optional embodiment of the present invention, the network that is allowed to be accessed using the default certificate includes the terminal using the terminal identifier corresponding to the default certificate to access the network that can obtain a restricted connection.

[0158] In an optional embodiment of the present invention, the default certificate includes a certificate for a restricted access mode.

[0159] In an optional embodiment of the present invention, restricted access and restricted connection have the same meaning and can be used interchangeably.

[0160] In one embodiment, the restricted access includes at least one of the following: only allowing the establishment of the first data channel, not allowing the establishment of data channels other than the first data channel, only allowing the acquisition of certificates and / or contracts, not allowing the acquisition of services other than certificates and / or contracts. The first data channel is a data channel for acquiring certificates and / or contracts.

[0161] In one implementation, a certificate and / or a subscription of the first object may be obtained through the restricted access.

[0162] In an optional embodiment of the present invention, the restricted access includes restricted control plane access and / or restricted user plane access.

[0163] In an optional embodiment of the present invention, the restricted connection includes a restricted control plane connection and / or a restricted user plane connection. A certificate and / or a subscription may be obtained through the restricted connection.

[0164] In an optional embodiment of the present invention, the network accessible by using the default certificate includes accessing the network by using the terminal identifier corresponding to the default certificate and passing the authentication and / or authorization of the network by using the default certificate.

[0165] In an optional embodiment of the present invention, the networks in the first list include networks mapped by the network group in the first list. A network group can be mapped to one or more networks.

[0166] In an optional embodiment of the present invention, the networks in the list of networks capable of configuring certificates and / or subscriptions include networks to which the first communication device can have limited access and which enable the first communication device to obtain certificates and / or subscriptions.

[0167] In an optional embodiment of the present invention, characteristics of the networks in the first list include networks to which the first communication device can have limited access and to which the first communication device can obtain a certificate and / or a contract.

[0168] In an optional embodiment of the present invention, the suscription includes subscription data, such as slice information, DNN, etc.

[0169] In an optional embodiment of the present invention, A network is used to generally refer to a network, or is used to specifically refer to one or more networks.

[0170] In an optional embodiment of the present invention, the certificate and / or contract of the first object includes a certificate and / or contract for accessing the first object. The certificate and / or contract for accessing the first object includes at least one of the following: a certificate and / or contract for unrestricted access to the first object, and a certificate and / or contract for restricted access to the first object.

[0171] In an optional embodiment of the present invention, the certificate and / or contract of the A network includes a certificate and / or contract for accessing the A network. The certificate and / or contract for accessing the A network includes at least one of the following: a certificate and / or contract for unrestricted access to the A network, and a certificate and / or contract for restricted access to the A network.

[0172] In an optional embodiment of the present invention, configuring a certificate and / or a subscription for the first communication device includes enabling the first communication device to obtain a certificate and / or a subscription.

[0173] In an optional embodiment of the present invention,

[0174] (1) Optionally, enabling the first communication device to obtain a certificate and / or a contract includes: configuring a certificate and / or a contract for the first communication device.

[0175] (2) Optionally, enabling the first communication device to obtain a certificate and / or a contract via a control plane includes: configuring a certificate and / or a contract for the first communication device via a control plane.

[0176] (3) Optionally, enabling the first communication device to obtain a certificate and / or a contract via a user plane includes: configuring a certificate and / or a contract for the first communication device via a user plane.

[0177] (4) Optionally, enabling the first communication device to obtain the certificate and / or the contract of the first object through the control plane includes: configuring the certificate and / or the contract of the first object for the first communication device through the control plane.

[0178] and / or

[0179] (5) Optionally, enabling the first communication device to obtain a certificate and / or a contract of the first object in a user plane manner includes: configuring a certificate and / or a contract of the first object for the first communication device in a user plane manner.

[0180] In an optional embodiment of the present invention,

[0181] (1) Optionally, configuring a certificate and / or signing a contract for the first communication device includes: enabling the first communication device to obtain a certificate and / or signing a contract includes:.

[0182] (2) Optionally, configuring a certificate and / or signing a contract for the first communication device via a control plane includes: enabling the first communication device to obtain a certificate and / or signing a contract via a control plane includes:.

[0183] (3) Optionally, configuring a certificate and / or signing a contract for the first communication device via a user plane includes: enabling the first communication device to obtain a certificate and / or signing a contract via a user plane includes:.

[0184] (4) Optionally, configuring the certificate and / or subscription of the first object for the first communication device through the control plane includes enabling the first communication device to obtain the certificate and / or subscription of the first object through the control plane.

[0185] and / or

[0186] (5) Optionally, configuring the certificate and / or contract of the first object for the first communication device in a user plane manner includes: enabling the first communication device to obtain the certificate and / or contract of the first object in a user plane manner. It is not difficult to understand that when the certificate and / or contract of the first network is provided by an entity outside the network accessed by the terminal, configuring the certificate and / or contract for the first communication device can be understood as enabling the first communication device to obtain the certificate and / or contract of the first object in a user plane manner.

[0187] In conjunction with the accompanying drawings, a method, apparatus, device and readable storage medium for supporting network selection provided by an embodiment of the present application are described in detail below through some embodiments and their application scenarios.

[0188] See also Figure 2 An embodiment of the present application provides a method for supporting network selection, which is performed by a first communication device, and the first communication device includes but is not limited to a terminal (UE). The specific steps include: step 201 and step 202.

[0189] Step 201: Obtain first information, where the first information includes: a first list, a second list and / or first indication information;

[0190] Step 202: Select a network according to the first information;

[0191] In an optional embodiment of the present invention, the first list includes one of the following:

[0192] (1) one or more network objects;

[0193] (2) identification information of one or more network objects;

[0194] In an optional embodiment of the present invention, the characteristics of the networks in the first list include at least one of the following:

[0195] (1) The first communication device can be accessed in a restricted manner;

[0196] (2) enabling the first communication device to obtain a certificate and / or sign a contract;

[0197] (3) The first communication device can access using the default certificate;

[0198] In one implementation manner, characteristics of the networks in the first list include networks to which the first communication device can have limited access and to which the first communication device can obtain a certificate and / or a contract.

[0199] In one implementation, the default certificate includes a certificate for a restricted access mode.

[0200] In another optional embodiment of the present invention, the first list includes at least one of the following:

[0201] (1) A list of networks that can be restricted from access;

[0202] (2) Ability to configure a list of certificates and / or signed networks;

[0203] (3) A list of networks that can be accessed using the default credentials;

[0204] In one implementation, the characteristics of the networks in the list of networks capable of configuring certificates and / or contracts include one of the following: the first communication device can have limited access, the first communication device can obtain a certificate and / or a contract, and the first communication device can access using a default certificate.

[0205] In an optional embodiment of the present invention, the second list includes:

[0206] (1) one or more network objects;

[0207] (2) identification information of one or more network objects;

[0208] In an optional embodiment of the present invention, the characteristics of the networks in the second list include at least one of the following:

[0209] (1) The first communication device cannot be accessed;

[0210] (2) the first communication device cannot obtain a certificate and / or sign a contract;

[0211] (3) The first communication device cannot be accessed using the default certificate;

[0212] In another optional embodiment of the present invention, the second list includes at least one of the following:

[0213] (1) A list of networks that cannot be restricted from access;

[0214] (2) Unable to configure certificates and / or contracted network lists;

[0215] (3) A list of networks that cannot be accessed using the default credentials;

[0216] The network list includes:

[0217] (1) one or more network objects;

[0218] (2) identification information of one or more network objects;

[0219] Wherein, the network object includes a network and / or a network group;

[0220] The first indication information is used to indicate at least one of the following:

[0221] (1) Support or not support configuration of certificates and / or signing;

[0222] (2) Support or not support configuration of certificates and / or contracts through the control plane;

[0223] (3) Support or not support configuration of certificates and / or contracts via the user plane;

[0224] (4) Support or not support configuration of certificates and / or contracts based on restricted access;

[0225] (5) Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0226] (6) Support or not support configuration of certificates and / or contracts through the user plane based on restricted access;

[0227] (7) Support or not support configuration of certificates and / or contracts based on unrestricted access;

[0228] (8) Support or not support configuration of certificates and / or contracts through the control plane based on unrestricted access;

[0229] (9) Support or not support configuration of certificates and / or contracts through the user plane based on unrestricted access.

[0230] In one embodiment, the first communication device obtains the first list and / or the second list through preconfiguration. In another embodiment, the first communication device obtains the first list and / or the second list from an accessed network or a first server. The first server is a server that configures a certificate and / or a contract for the first communication device.

[0231] In an optional embodiment of the present invention, the certificate and / or contract includes at least one of the following: a certificate and / or contract of the first object; a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization;

[0232] In one embodiment, the non-primary authentication and / or authorization includes at least one of the following: secondary authentication and / or authorization (Secondary authentication / authorization), slice-related authentication and / or authorization (NSSAA Network Slice-Specific Authentication and Authorization).

[0233] in,

[0234] The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and / or authorization, and non-primary authentication and / or authorization;

[0235] The first entity includes one of the following: an entity in a data network, an entity outside a network accessed by the first communication device;

[0236] in,

[0237] The A network is the same as or different from the network in the first list;

[0238] and / or,

[0239] The A network is the same as or different from the network in the second list;

[0240] and / or,

[0241] The A network is the same as or different from the network accessed by the first communication device; and / or,

[0242] The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through a control plane, obtaining the certificate and / or the contract through a user plane;

[0243] and / or,

[0244] The network list capable of configuring certificates and / or contracts includes at least one of the following: a network list capable of configuring certificates and / or contracts via a control plane, and a network list capable of configuring certificates and / or contracts via a user plane;

[0245] In one embodiment, the characteristics of the network in the network list that can be configured with certificates and / or contracts via the control plane include one of the following: the first communication device can have limited access, the first communication device can obtain a certificate and / or a contract via the control plane, and the first communication device can access using a default certificate.

[0246] In one embodiment, the characteristics of the network in the network list that can be configured with certificates and / or contracts via the user plane include the following: the first communication device can have limited access, the first communication device can obtain a certificate and / or a contract via the user plane, and the first communication device can access using a default certificate.

[0247] In an optional embodiment of the present invention, enabling the first communication device to obtain a certificate and / or a contract includes at least one of the following: enabling the first communication device to obtain a certificate and / or a contract via a control plane, and enabling the first communication device to obtain a certificate and / or a contract via a user plane.

[0248] In an optional embodiment of the present invention, the certificate and / or subscription of the first object includes a certificate and / or subscription for accessing the first object.

[0249] In an optional embodiment of the present invention, the first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;

[0250] and / or,

[0251] The second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;

[0252] and / or,

[0253] The list of networks capable of configuring certificates and / or contracts includes: a list of networks capable of configuring certificates and / or contracts for the first object;

[0254] and / or,

[0255] The list of networks that cannot be configured with certificates and / or contracts includes: a list of networks that cannot be configured with certificates and / or contracts of the first object;

[0256] and / or,

[0257] Enabling the first communication device to obtain a certificate and / or a contract includes: enabling the first communication device to obtain a certificate and / or a contract of the first object;

[0258] and / or,

[0259] Not enabling the first communication device to obtain a certificate and / or a contract includes: not enabling the first communication device to obtain a certificate and / or a contract of a first object.

[0260] In an optional embodiment of the present invention, the first list corresponding to the first object includes: a first list corresponding to the first object in a control plane manner, and a first list corresponding to the first object in a user plane manner;

[0261] in,

[0262] The first list in a control plane manner corresponding to the first object and the first list in a user plane manner corresponding to the first object are the same as or different from each other;

[0263] The networks in the first list corresponding to the first object in a control plane manner include networks that enable the first communication device to obtain a certificate and / or a contract of the first object in a control plane manner;

[0264] The networks in the first list corresponding to the first object in a user plane manner include networks that enable the first communication device to obtain a certificate and / or a contract for the first object in a user plane manner;

[0265] and / or,

[0266] The second list corresponding to the first object includes: a second list corresponding to the first object in a control plane manner, and a second list corresponding to the first object in a user plane manner;

[0267] in,

[0268] The second list in a control plane manner corresponding to the first object is the same as or different from the second list in a user plane manner corresponding to the first object;

[0269] The networks in the second list corresponding to the first object in a control plane manner include networks that cannot enable the first communication device to obtain a certificate and / or a contract of the first object in a control plane manner;

[0270] The networks in the second list corresponding to the first object in a user plane manner include networks that do not enable the first communication device to obtain a certificate and / or a contract for the first object in a user plane manner;

[0271] and / or,

[0272] The certificate and / or the subscribed network list capable of configuring the first object includes at least one of the following: the certificate and / or the subscribed network list capable of configuring the first object in a control plane manner, and the certificate and / or the subscribed network list capable of configuring the first object in a user plane manner;

[0273] and / or,

[0274] The inability to configure the certificate and / or the subscribed network list of the first object includes at least one of the following: the inability to configure the certificate and / or the subscribed network list of the first object through the control plane mode, and the inability to configure the certificate and / or the subscribed network list of the first object through the user plane mode;

[0275] and / or,

[0276] The enabling of the first communication device to obtain the certificate and / or contract of the A object includes at least one of the following: enabling the first communication device to obtain the certificate and / or contract of the first object through a control plane method, and enabling the first communication device to obtain the certificate and / or contract of the first object through a user plane method;

[0277] and / or,

[0278] The inability of the first communication device to obtain the certificate and / or contract of object A includes at least one of the following: the inability of the first communication device to obtain the certificate and / or contract of the first object via the control plane, and the inability of the first communication device to obtain the certificate and / or contract of the first object via the user plane.

[0279] In an optional embodiment of the present invention, the network type of the network in the first list, the network type of the network in the second list, and / or the network type of network A includes at least one of the following: public network, non-public network, PLMN, non-independent non-public network (Public Network Integrated Non-Public Network, PNI-NPN), SNPN.

[0280] In an optional embodiment of the present invention, obtaining the first indication information includes:

[0281] The first indication information is broadcast from the cell or received from the second communication device.

[0282] In an optional embodiment of the present invention, the method further includes:

[0283] By accessing the network in the first list, at least one of the following is obtained:

[0284] (1) a certificate and / or a contract with the first party,

[0285] (2) identification information of the first object;

[0286] (3) a first list corresponding to the first object;

[0287] (4) a second list corresponding to the first object;

[0288] In an optional embodiment of the present invention, selecting a network according to the first information includes: selecting a first network when a first condition is met;

[0289] The first condition includes at least one of the following:

[0290] The first network is a network in the first list;

[0291] Obtaining first indication information from the first network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0292] The terminal needs to obtain a certificate and / or a contract with the first object;

[0293] The first list includes at least one of the following: a list of networks capable of configuring the certificate and / or contract of the first object; a first list corresponding to the first object; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object; a list of allowed networks corresponding to the certificate and / or contract of the first object;

[0294] The first network has the highest priority in the first list;

[0295] The first communication device is within the coverage of the first network or the first communication device can detect a signal of the first network.

[0296] In an optional embodiment of the present invention, selecting a network according to the first information includes:

[0297] When the second condition is met, selecting the second network;

[0298] The second condition includes at least one of the following:

[0299] The second network is not a network in the second list;

[0300] The first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0301] The terminal needs to obtain a certificate and / or a contract with the first object;

[0302] The second list includes at least one of the following: a list of networks that cannot configure the certificate and / or contract of the first object; a second list corresponding to the first object; networks in the second list cannot enable the first communication device to obtain the certificate and / or contract of the first object; a list of disallowed networks corresponding to the certificate and / or contract of the first object;

[0303] The first communication device is outside the coverage of any network in the first list or the first communication device cannot detect a signal of any network in the first list.

[0304] In an optional embodiment of the present invention, the networks in the first list are sorted by priority.

[0305] In an optional embodiment of the present invention, selecting a network according to the first information includes:

[0306] When the third condition is met, the third network is selected;

[0307] The third condition includes at least one of the following:

[0308] The third network is a network in the first list;

[0309] Obtaining first indication information from the third network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0310] The terminal needs to obtain a certificate and / or a contract with the first object;

[0311] The first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, a list of networks capable of configuring the certificate and / or contract of the first object in a control plane manner; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object in a control plane manner; the first communication device is within the coverage of a third network or the first communication device can monitor a signal of the third network;

[0312] and / or,

[0313] When the fourth condition is met, selecting the fourth network;

[0314] The fourth condition includes at least one of the following:

[0315] The fourth network is a network in the first list;

[0316] The first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane, supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0317] The terminal needs to obtain a certificate and / or a contract with the first object;

[0318] The first list includes at least one of the following: a first list corresponding to the first object in a user plane manner, a list of networks capable of configuring the certificate and / or contract of the first object in a user plane manner; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object in a user plane manner;

[0319] The first communication device is within the coverage of the fourth network or the first communication device can monitor a signal of the fourth network.

[0320] In the embodiment of the present application, the first indication information is used to instruct the first communication device to select a network for downloading a certificate and / or signing a contract.

[0321] In the embodiment of the present application, the first communication device may select a network for downloading a certificate and / or signing a contract according to the first information.

[0322] See also Figure 3 The embodiment of the present application provides a method for supporting network selection, which is performed by a second communication device, and the second communication device includes but is not limited to one of the following: a RAN network element, a CN network element (such as an access and mobility management function (Access and Mobility Management Function, AMF), a session management function (Session Management Function, SMF)), and the specific steps include:

[0323] Step 301: Sending first indication information;

[0324] The first indication information is used to indicate at least one of the following:

[0325] (1) Support or not support configuration of certificates and / or signing;

[0326] (3) Support or not support configuration of certificates and / or contracts through the control plane;

[0327] (4) Support or not support configuration of certificates and / or contracts via the user plane;

[0328] (5) Support or not support configuration of certificates and / or contracts based on restricted access;

[0329] (6) Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0330] (7) Support or not support configuration of certificates and / or contracts through the user plane based on restricted access;

[0331] (8) Support or not support configuration of certificates and / or contracts based on unrestricted access;

[0332] (9) Support or not support configuration of certificates and / or contracts through the control plane based on unrestricted access;

[0333] (10) Support or not support configuration of certificates and / or contracts through the user plane based on unrestricted access.

[0334] In one implementation, the first indication information is broadcast via a cell system message.

[0335] In one embodiment, the second communication device is a communication device in the first network or the second network.

[0336] In the embodiment of the present application, the first indication information is used to instruct the first communication device to select a network for downloading a certificate and / or signing a contract.

[0337] See also Figure 4The embodiment of the present application provides a method for supporting network selection, which is performed by a third communication device, and the third communication device includes but is not limited to one of the following: a RAN network element, a CN network element (such as AMF, SMF), a first server, and a first entity. The specific steps include:

[0338] Step 401: Send the first list and / or the second list;

[0339] In an optional embodiment of the present invention, the first list includes:

[0340] (1) one or more network objects;

[0341] (2) identification information of one or more network objects;

[0342] The characteristics of the network in the first list include at least one of the following:

[0343] (1) The first communication device can be accessed in a restricted manner;

[0344] (2) enabling the first communication device to obtain a certificate and / or sign a contract;

[0345] (3) The first communication device can access using the default certificate;

[0346] In one implementation manner, the networks in the first list include networks to which the first communication device can have limited access and to which the first communication device can obtain a certificate and / or a contract.

[0347] In another optional embodiment of the present invention, the first list includes at least one of the following:

[0348] (1) A list of networks that can be restricted from access,

[0349] (2) Ability to configure certificates and / or signed network lists,

[0350] (3) A list of networks that can be accessed using the default credentials;

[0351] In one implementation, the characteristics of the networks in the list of networks capable of configuring certificates and / or contracts include one of the following: the first communication device can have limited access, the first communication device can obtain a certificate and / or a contract, and the first communication device can access using a default certificate.

[0352] In an optional embodiment of the present invention, the second list includes:

[0353] (1) one or more network objects;

[0354] (2) identification information of one or more network objects;

[0355] The characteristics of the network in the second list include at least one of the following:

[0356] (1) The first communication device cannot be accessed;

[0357] (2) the first communication device cannot obtain a certificate and / or sign a contract;

[0358] (3) The first communication device cannot be accessed using the default certificate;

[0359] In another optional embodiment of the present invention, the second list includes at least one of the following:

[0360] (1) A list of networks that cannot be restricted from access;

[0361] (2) Unable to configure certificates and / or contracted network lists;

[0362] (3) A list of networks that cannot be accessed using the default credentials;

[0363] The network list includes one or more network objects, or identification information of one or more network objects, and the network objects include networks and / or network groups.

[0364] In another optional embodiment of the present invention, the certificate and / or contract includes at least one of the following: a certificate and / or contract of the first object; a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization;

[0365] in,

[0366] The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and / or authorization, and non-primary authentication and / or authorization;

[0367] The first entity includes one of the following: an entity in a data network, an entity outside a network accessed by the first communication device;

[0368] The A network is the same as or different from the network in the first list;

[0369] and / or,

[0370] The A network is the same as or different from the networks in the second list.

[0371] and / or,

[0372] The A network is the same as or different from the network accessed by the first communication device;

[0373] and / or,

[0374] The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through a control plane, obtaining the certificate and / or the contract through a user plane;

[0375] and / or,

[0376] The network list capable of configuring certificates and / or contracts includes at least one of the following: a network list capable of configuring certificates and / or contracts via a control plane, and a network list capable of configuring certificates and / or contracts via a user plane;

[0377] In one embodiment, the characteristics of the network in the network list that can be configured with certificates and / or contracts via the control plane include one of the following: the first communication device can have limited access, the first communication device can obtain a certificate and / or a contract via the control plane, and the first communication device can access using a default certificate.

[0378] In one embodiment, the characteristics of the network in the network list that can be configured with certificates and / or contracts via the user plane include the following: the first communication device can have limited access, the first communication device can obtain a certificate and / or a contract via the user plane, and the first communication device can access using a default certificate.

[0379] In one implementation, enabling the first communication device to obtain a certificate and / or a contract includes at least one of the following: enabling the first communication device to obtain a certificate and / or a contract via a control plane, and enabling the first communication device to obtain a certificate and / or a contract via a user plane.

[0380] In an optional embodiment of the present invention, the network type of the network in the first list, the network type of the network in the second list, and / or the network type of network A includes at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.

[0381] In an optional embodiment of the present invention, the networks in the first list are sorted by priority.

[0382] In the embodiment of the present application, the first list and / or the second list are used to instruct the first communication device to select a network for downloading a certificate and / or signing a contract.

[0383] See also Figure 5 , the specific steps are as follows

[0384] Step 1: Configure the terminal to obtain the first object (such as SNPN2) certificate and / or the first list corresponding to the contract (such as a mixed network list of SNPN and PLMN).

[0385] Step 2: receiving first indication information sent by a second communication device (such as a RAN network element or a CN network element);

[0386] Step 3: Select a network according to the first list and the first indication information.

[0387] It is understood that the implementation of step 3 can refer to Figure 2 Description of the illustrated embodiment.

[0388] See also Figure 6 The embodiment of the present application provides a device for supporting network selection, which is applied to a first communication device. The device 600 includes:

[0389] A first acquisition module 601 is used to obtain first information, where the first information includes: a first list, a second list and / or first indication information;

[0390] A selection module 602, configured to select a network according to the first information;

[0391] In an optional embodiment of the present invention, the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be accessed with limited access, the first communication device can obtain a certificate and / or sign a contract, and the first communication device can access using a default certificate;

[0392] In another optional embodiment of the present invention, the first list includes at least one of the following:

[0393] List of networks that can be restricted from access;

[0394] Ability to configure certificates and / or signed network lists;

[0395] List of networks that can be accessed using default credentials;

[0396] In one implementation, the networks in the list of networks capable of configuring certificates and / or contracts include networks to which the first communication device can have limited access and to which the first communication device can obtain certificates and / or contracts.

[0397] In an optional embodiment of the present invention, the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access, the first communication device cannot obtain a certificate and / or sign a contract, and the first communication device cannot access using a default certificate;

[0398] In another optional embodiment of the present invention, the second list includes at least one of the following:

[0399] List of networks that cannot be restricted from access;

[0400] Inability to configure certificates and / or signed network lists;

[0401] List of networks that cannot be accessed using default certificates;

[0402] Wherein, the network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and / or network groups;

[0403] The first indication information is used to indicate at least one of the following:

[0404] Support or not support provisioning certificates and / or signing;

[0405] Support or not support configuration of certificates and / or contracts via the control plane;

[0406] Support or not support configuration of certificates and / or signing via user plane;

[0407] Support or not support configuration of certificates and / or contracts based on restricted access;

[0408] Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0409] Support or not support configuration of certificates and / or contracts through user plane based on restricted access;

[0410] Support or not support provisioning of certificates and / or contracts based on unrestricted access;

[0411] Support or not support configuration of certificates and / or contracts via control plane based on unrestricted access;

[0412] Support or not support configuration of certificates and / or subscriptions through the user plane based on unrestricted access.

[0413] In one implementation, the first communication device obtains the first list and / or the second list through preconfiguration.

[0414] The certificate and / or subscription of the first object includes a certificate and / or subscription for accessing the first object.

[0415] In one implementation, the first communication device obtains the first list and / or the second list through preconfiguration.

[0416] The certificate and / or subscription of the first object includes a certificate and / or subscription for accessing the first object.

[0417] In an optional embodiment of the present invention, the certificate and / or contract includes at least one of the following: a certificate and / or contract of the first object; a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization;

[0418] in,

[0419] The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and / or authorization, and non-primary authentication and / or authorization;

[0420] The first entity includes one of the following: an entity in a data network, an entity outside a network accessed by the first communication device;

[0421] Wherein, the A network is the same as or different from the network in the first list;

[0422] and / or,

[0423] The A network is the same as or different from the network in the second list;

[0424] and / or,

[0425] The A network is the same as or different from the network accessed by the first communication device;

[0426] and / or,

[0427] The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through a control plane, obtaining the certificate and / or the contract through a user plane;

[0428] and / or,

[0429] The network list capable of configuring certificates and / or contracts includes at least one of the following: a network list capable of configuring certificates and / or contracts via a control plane, and a network list capable of configuring certificates and / or contracts via a user plane;

[0430] and / or,

[0431] Enabling the first communication device to obtain a certificate and / or a contract includes at least one of the following: enabling the first communication device to obtain a certificate and / or a contract via a control plane, and enabling the first communication device to obtain a certificate and / or a contract via a user plane.

[0432] In an optional embodiment of the present invention, the first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different;

[0433] and / or,

[0434] The second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different;

[0435] and / or,

[0436] The list of networks capable of configuring certificates and / or contracts includes: a list of networks capable of configuring certificates and / or contracts for the first object;

[0437] and / or,

[0438] The list of networks that cannot be configured with certificates and / or contracts includes: a list of networks that cannot be configured with certificates and / or contracts of the first object;

[0439] and / or,

[0440] Enabling the first communication device to obtain a certificate and / or a contract includes: enabling the first communication device to obtain a certificate and / or a contract of the first object;

[0441] and / or,

[0442] Not enabling the first communication device to obtain a certificate and / or a contract includes: not enabling the first communication device to obtain a certificate and / or a contract of the first object.

[0443] In an optional embodiment of the present invention, the first list corresponding to the first object includes: a first list corresponding to the first object in a control plane manner, and a first list corresponding to the first object in a user plane manner;

[0444] in,

[0445] The first list in a control plane manner corresponding to the first object and the first list in a user plane manner corresponding to the first object are the same as or different from each other;

[0446] The networks in the first list corresponding to the first object in a control plane manner include: networks that enable the first communication device to obtain a certificate and / or a contract of the first object in a control plane manner;

[0447] The networks in the first list corresponding to the first object in a user plane manner include: networks that enable the first communication device to obtain a certificate and / or a contract of the first object in a user plane manner;

[0448] and / or,

[0449] The second list corresponding to the first object includes: a second list corresponding to the first object in a control plane manner, and a second list corresponding to the first object in a user plane manner;

[0450] in,

[0451] The second list in a control plane manner corresponding to the first object is the same as or different from the second list in a user plane manner corresponding to the first object;

[0452] The networks in the second list corresponding to the first object in a control plane manner include networks that cannot enable the first communication device to obtain a certificate and / or a contract of the first object in a control plane manner;

[0453] The networks in the second list corresponding to the first object in a user plane manner include networks that do not enable the first communication device to obtain a certificate and / or a contract for the first object in a user plane manner;

[0454] and / or,

[0455] The certificate and / or the subscribed network list capable of configuring the first object includes at least one of the following: the certificate and / or the subscribed network list capable of configuring the first object in a control plane manner, and the certificate and / or the subscribed network list capable of configuring the first object in a user plane manner;

[0456] and / or,

[0457] The certificate and / or the subscribed network list of the first object cannot be configured, including at least one of the following: the certificate and / or the subscribed network list of the first object cannot be configured through the control plane, and the certificate and / or the subscribed network list of the first object cannot be configured through the user plane;

[0458] and / or,

[0459] The enabling of the first communication device to obtain the certificate and / or the contract of the first object includes at least one of the following: enabling the first communication device to obtain the certificate and / or the contract of the first object through a control plane, and enabling the first communication device to obtain the certificate and / or the contract of the first object through a user plane;

[0460] and / or,

[0461] The inability of the first communication device to obtain the certificate and / or contract of the first object includes at least one of the following: the inability of the first communication device to obtain the certificate and / or contract of the first object via the control plane, and the inability of the first communication device to obtain the certificate and / or contract of the first object via the user plane.

[0462] In an optional embodiment of the present invention, the network types of the networks in the first list, the networks in the second list, and / or the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.

[0463] In an optional embodiment of the present invention, the first acquisition module 601 is further used to: receive the first indication information from a cell broadcast or from a second communication device.

[0464] In an optional embodiment of the present invention, the device 600 further includes:

[0465] A second acquisition module is configured to obtain at least one of the following by accessing a network in the first list:

[0466] a certificate and / or a contract of said first object,

[0467] identification information of the first object;

[0468] a first list corresponding to the first object;

[0469] a second list corresponding to the first object;

[0470] In an optional embodiment of the present invention, the selection module 602 is further used for:

[0471] When the first condition is met, the first network is selected;

[0472] The first condition includes at least one of the following:

[0473] The first network is a network in the first list;

[0474] Obtaining first indication information from the first network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0475] The terminal needs to obtain a certificate and / or a contract with the first object;

[0476] The first list includes at least one of the following: a list of networks capable of configuring the certificate and / or contract of the first object; a first list corresponding to the first object; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object; a list of allowed networks corresponding to the certificate and / or contract of the first object;

[0477] The first network has the highest priority in the first list;

[0478] The first communication device is within the coverage of the first network or the first communication device can detect a signal of the first network.

[0479] In an optional embodiment of the present invention, the selection module 602 is further used for:

[0480] When the second condition is met, selecting the second network;

[0481] The second condition includes at least one of the following:

[0482] The second network is not a network in the second list;

[0483] The first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0484] The terminal needs to obtain a certificate and / or a contract with the first object;

[0485] The second list includes at least one of the following: a list of networks that cannot configure the certificate and / or contract of the first object; a second list corresponding to the first object; networks in the second list cannot enable the first communication device to obtain the certificate and / or contract of the first object; a list of disallowed networks corresponding to the certificate and / or contract of the first object;

[0486] The first communication device is outside the coverage of any network in the first list or the first communication device cannot detect a signal of any network in the first list.

[0487] In an optional embodiment of the present invention, the networks in the first list are sorted by priority.

[0488] In an optional embodiment of the present invention, the selection module 602 is further used for:

[0489] When the third condition is met, the third network is selected;

[0490] The third condition includes at least one of the following:

[0491] The third network is a network in the first list;

[0492] Obtaining first indication information from the third network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0493] The terminal needs to obtain a certificate and / or a contract with the first object;

[0494] The first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, a list of networks capable of configuring the certificate and / or contract of the first object in a control plane manner; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object in a control plane manner; the first communication device is within the coverage of a third network or the first communication device can monitor a signal of the third network;

[0495] and / or,

[0496] When the fourth condition is met, selecting the fourth network;

[0497] The fourth condition includes at least one of the following:

[0498] The fourth network is a network in the first list;

[0499] The first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane, supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access;

[0500] The terminal needs to obtain a certificate and / or a contract with the first object;

[0501] The first list includes at least one of the following: a first list corresponding to the first object in a user plane manner, a list of networks capable of configuring the certificate and / or contract of the first object in a user plane manner; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object in a user plane manner;

[0502] The first communication device is within the coverage of the fourth network or the first communication device can monitor a signal of the fourth network.

[0503] The device provided in the embodiment of the present application can achieve Figure 2 The various processes implemented by the method embodiment shown achieve the same technical effect and will not be described again here to avoid repetition.

[0504] See also Figure 7 The embodiment of the present application provides a device for supporting network selection, which is applied to a second communication device. The device 700 includes:

[0505] A first sending module 701, configured to send first indication information;

[0506] The first indication information is used to indicate at least one of the following:

[0507] Support or not support provisioning certificates and / or signing;

[0508] Support or not support configuration of certificates and / or contracts via the control plane;

[0509] Support or not support configuration of certificates and / or signing via user plane;

[0510] Support or not support configuration of certificates and / or contracts based on restricted access;

[0511] Support or not support configuration of certificates and / or contracts through the control plane based on restricted access;

[0512] Support or not support configuration of certificates and / or contracts through user plane based on restricted access;

[0513] Support or not support provisioning of certificates and / or contracts based on unrestricted access;

[0514] Support or not support configuration of certificates and / or contracts via control plane based on unrestricted access;

[0515] Support or not support configuration of certificates and / or subscriptions through the user plane based on unrestricted access.

[0516] The device provided in the embodiment of the present application can achieve Figure 3 The various processes implemented by the method embodiment shown achieve the same technical effect and will not be described again here to avoid repetition.

[0517] See also Figure 8 The embodiment of the present application provides a device for supporting network selection, which is applied to a third communication device. The device 800 includes:

[0518] The second sending module 801 is used to send the first list and / or the second list;

[0519] In an optional embodiment of the present invention, the first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include at least one of the following: the first communication device can be accessed with limited access, the first communication device can obtain a certificate and / or sign a contract, and the first communication device can access using a default certificate;

[0520] In one implementation manner, the networks in the first list include networks to which the first communication device can have limited access and to which the first communication device can obtain a certificate and / or a contract.

[0521] In another optional embodiment of the present invention, the first list includes at least one of the following:

[0522] A list of networks that can be restricted from access.

[0523] Ability to configure certificates and / or signed network lists,

[0524] List of networks that can be accessed using default credentials;

[0525] In one implementation, the networks in the list of networks capable of configuring certificates and / or contracts include networks to which the first communication device can have limited access and to which the first communication device can obtain certificates and / or contracts.

[0526] In an optional embodiment of the present invention, the second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include at least one of the following: the first communication device cannot access, the first communication device cannot obtain a certificate and / or sign a contract, and the first communication device cannot access using a default certificate;

[0527] In another optional embodiment of the present invention, the second list includes at least one of the following:

[0528] List of networks that cannot be restricted from access;

[0529] Inability to configure certificates and / or signed network lists;

[0530] List of networks that cannot be accessed using default certificates;

[0531] The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and / or network groups.

[0532] In an optional embodiment of the present invention, the certificate and / or contract includes at least one of the following: a certificate and / or contract of the first object; a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization;

[0533] in,

[0534] The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and / or authorization, and non-primary authentication and / or authorization;

[0535] The first entity includes one of the following: an entity in a data network, an entity outside a network accessed by the first communication device;

[0536] The A network is the same as or different from the network in the first list;

[0537] and / or,

[0538] The A network is the same as or different from the networks in the second list.

[0539] and / or,

[0540] The A network is the same as or different from the network accessed by the first communication device;

[0541] and / or,

[0542] The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through a control plane, obtaining the certificate and / or the contract through a user plane;

[0543] and / or,

[0544] The network list capable of configuring certificates and / or contracts includes at least one of the following: a network list capable of configuring certificates and / or contracts via a control plane, and a network list capable of configuring certificates and / or contracts via a user plane;

[0545] and / or,

[0546] Enabling the first communication device to obtain a certificate and / or a contract includes at least one of the following: enabling the first communication device to obtain a certificate and / or a contract via a control plane, and enabling the first communication device to obtain a certificate and / or a contract via a user plane.

[0547] In an optional embodiment of the present invention, the network type of the network in the first list, the network type of the network in the second list, and / or the network type of the A network includes at least one of the following: public network, non-public network, PLMN, PNINPN, SNPN.

[0548] In an optional embodiment of the present invention, the networks in the first list are sorted by priority.

[0549] The device provided in the embodiment of the present application can achieve Figure 4 The various processes implemented by the method embodiment shown achieve the same technical effect and will not be described again here to avoid repetition.

[0550] The device provided in the embodiment of the present application can achieve Figure 4 The various processes implemented by the method embodiment shown achieve the same technical effect and will not be described again here to avoid repetition.

[0551] Fig. 9 To implement a hardware structure diagram of a terminal in an embodiment of the present application, the terminal 900 includes but is not limited to: a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user input unit 907, an interface unit 908, a memory 909, and a processor 910 and other components.

[0552] Those skilled in the art will appreciate that the terminal 900 may also include a power source (such as a battery) for supplying power to various components, and the power source may be logically connected to the processor 910 through a power management system, thereby implementing functions such as managing charging, discharging, and power consumption management through the power management system. Fig. 9 The terminal structure shown in the figure does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently, which will not be described in detail here.

[0553] It should be understood that in the embodiment of the present application, the input unit 904 may include a graphics processor (Graphics Processing Unit, GPU) 9041 and a microphone 9042, and the graphics processor 9041 processes the image data of the static picture or video obtained by the image capture device (such as a camera) in the video capture mode or the image capture mode. The display unit 906 may include a display panel 9061, and the display panel 9061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 907 includes a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 may include two parts: a touch detection device and a touch controller. Other input devices 9072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.

[0554] In the embodiment of the present application, the radio frequency unit 901 receives downlink data from the network side device and sends it to the processor 910 for processing; in addition, the uplink data is sent to the network side device. Generally, the radio frequency unit 901 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.

[0555] The memory 909 can be used to store software programs or instructions and various data. The memory 909 can mainly include a program or instruction storage area and a data storage area, wherein the program or instruction storage area can store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.), etc. In addition, the memory 909 can include a high-speed random access memory, and can also include a non-volatile memory, wherein the non-volatile memory can be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM, PROM), an erasable programmable read-only memory (Erasable PROM, EPROM), an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or a flash memory. For example, at least one disk storage device, a flash memory device, or other non-volatile solid-state storage devices.

[0556] The processor 910 may include one or more processing units; optionally, the processor 910 may integrate an application processor and a modem processor, wherein the application processor mainly processes an operating system, a user interface, and application programs or instructions, etc., and the modem processor mainly processes wireless communications, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 910.

[0557] The terminal provided in the embodiment of the present application can achieve Figure 2 The various processes implemented by the method embodiment shown achieve the same technical effect and will not be described again here to avoid repetition.

[0558] The present application embodiment also provides a network side device. Fig.10 As shown, the network side device 1000 includes: an antenna 1001, a radio frequency device 1002, and a baseband device 1003. The antenna 1001 is connected to the radio frequency device 1002. In the uplink direction, the radio frequency device 1002 receives information through the antenna 1001 and sends the received information to the baseband device 1003 for processing. In the downlink direction, the baseband device 1003 processes the information to be sent and sends it to the radio frequency device 1002. The radio frequency device 1002 processes the received information and sends it out through the antenna 1001.

[0559] The frequency band processing device may be located in the baseband device 1003 . The method performed by the network-side device in the above embodiment may be implemented in the baseband device 1003 . The baseband device 1003 includes a processor 1004 and a memory 1005 .

[0560] The baseband device 1003 may include, for example, at least one baseband board on which a plurality of chips are arranged. Fig.10 As shown, one of the chips is, for example, a processor 1004, which is connected to a memory 1005 to call a program in the memory 1005 to execute the network device operations shown in the above method embodiment.

[0561] The baseband device 1003 may further include a network interface 1006 for exchanging information with the radio frequency device 1002 . The interface may be, for example, a common public radio interface (CPRI).

[0562] Specifically, the network side device of the embodiment of the present application further includes: instructions or programs stored in the memory 1005 and executable on the processor 1004, and the processor 1004 calls the instructions or programs in the memory 1005 to execute Figure 7-Figure 8 The methods executed by the modules shown achieve the same technical effects, and therefore will not be described here in detail to avoid repetition.

[0563] The embodiment of the present application also provides a program product, which is stored in a non-volatile storage medium and is executed by at least one processor to implement the following Figure 2-Figure 4 The steps of the processing method.

[0564] The embodiment of the present application also provides a readable storage medium on which a program or instruction is stored. When the program or instruction is executed by a processor, the above Figure 2-Figure 4 The various processes of the method embodiment shown can achieve the same technical effect, and will not be described again here to avoid repetition.

[0565] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0566] The present application also provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run a network side device program or instruction to implement the above Figure 2-Figure 4 The various processes of the method embodiment shown can achieve the same technical effect, and will not be described again here to avoid repetition.

[0567] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0568] It should be noted that, in this article, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0569] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a disk, or an optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application.

[0570] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims

1. A method for supporting network selection, It is characterized in that The method is performed by a first communication device, wherein the first communication device includes a terminal, including: Obtaining first information, wherein the first information includes: a first list and / or a second list; selecting a network according to the first information; in, The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include: enabling the first communication device to obtain a certificate and / or a contract; or the first list includes: a list of networks capable of configuring a certificate and / or a contract; The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include: being unable to enable the first communication device to obtain a certificate and / or a contract; or the second list includes: a list of networks that cannot configure a certificate and / or a contract; The network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and / or network groups.

2. The method according to claim 1, It is characterized in that The first information also includes first indication information, where the first indication information is used to indicate whether configuration of certificates and / or signing is supported or not.

3. The method according to claim 1, It is characterized in that The certificate and / or contract includes at least one of the following: a certificate and / or contract of the first object; a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization; in, The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and / or authorization, and non-primary authentication and / or authorization; The first entity includes one of the following: an entity in a data network, an entity outside a network accessed by the first communication device; in, The A network is the same as or different from the network in the first list; and / or, The A network is the same as or different from the network in the second list; and / or, The A network is the same as or different from the network accessed by the first communication device; and / or, The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through a control plane, obtaining the certificate and / or the contract through a user plane; and / or, The network list capable of configuring certificates and / or contracts includes at least one of the following: a network list capable of configuring certificates and / or contracts via a control plane, and a network list capable of configuring certificates and / or contracts via a user plane; and / or, Enabling the first communication device to obtain a certificate and / or a contract includes at least one of the following: enabling the first communication device to obtain a certificate and / or a contract via a control plane, and enabling the first communication device to obtain a certificate and / or a contract via a user plane.

4. The method according to claim 3, It is characterized in that The first list is a first list corresponding to the first object, and the first lists corresponding to different first objects are the same or different; and / or, The second list is a second list corresponding to the first object, and the second lists corresponding to different first objects are the same or different; and / or, The list of networks capable of configuring certificates and / or contracts includes: a list of networks capable of configuring certificates and / or contracts for the first object; and / or, The list of networks that cannot be configured with certificates and / or contracts includes: a list of networks that cannot be configured with certificates and / or contracts of the first object; and / or, Enabling the first communication device to obtain a certificate and / or a contract includes: enabling the first communication device to obtain a certificate and / or a contract of the first object; and / or, Not enabling the first communication device to obtain a certificate and / or a contract includes: not enabling the first communication device to obtain a certificate and / or a contract of the first object.

5. The method according to claim 4, It is characterized in that The first list corresponding to the first object includes: a first list corresponding to the first object in a control plane manner, and a first list corresponding to the first object in a user plane manner; in, The first list in a control plane manner corresponding to the first object and the first list in a user plane manner corresponding to the first object are the same as or different from each other; The networks in the first list corresponding to the first object in a control plane manner include: networks that enable the first communication device to obtain a certificate and / or a contract of the first object in a control plane manner; The networks in the first list corresponding to the first object in a user plane manner include: networks that enable the first communication device to obtain a certificate and / or a contract of the first object in a user plane manner; and / or, The second list corresponding to the first object includes: a second list corresponding to the first object in a control plane manner, and a second list corresponding to the first object in a user plane manner; in, The second list in a control plane manner corresponding to the first object is the same as or different from the second list in a user plane manner corresponding to the first object; The networks in the second list corresponding to the first object in a control plane manner include networks that cannot enable the first communication device to obtain a certificate and / or a contract of the first object in a control plane manner; The networks in the second list corresponding to the first object in a user plane manner include networks that do not enable the first communication device to obtain a certificate and / or a contract for the first object in a user plane manner; and / or, The certificate and / or the subscribed network list capable of configuring the first object includes at least one of the following: the certificate and / or the subscribed network list capable of configuring the first object in a control plane manner, and the certificate and / or the subscribed network list capable of configuring the first object in a user plane manner; and / or, The certificate and / or the subscribed network list of the first object cannot be configured, including at least one of the following: the certificate and / or the subscribed network list of the first object cannot be configured through the control plane, and the certificate and / or the subscribed network list of the first object cannot be configured through the user plane; and / or, The enabling of the first communication device to obtain the certificate and / or the contract of the first object includes at least one of the following: enabling the first communication device to obtain the certificate and / or the contract of the first object through a control plane, and enabling the first communication device to obtain the certificate and / or the contract of the first object through a user plane; and / or, The inability of the first communication device to obtain the certificate and / or contract of the first object includes at least one of the following: the inability of the first communication device to obtain the certificate and / or contract of the first object via the control plane, and the inability of the first communication device to obtain the certificate and / or contract of the first object via the user plane.

6. The method according to claim 1 or 3, It is characterized in that The network types of the networks in the first list, the networks in the second list, and / or the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.

7. The method according to claim 2, It is characterized in that Obtaining first indication information, including: The first indication information is broadcast from the cell or received from the second communication device.

8. The method according to claim 1, It is characterized in that The method further comprises: By accessing the network in the first list, at least one of the following is obtained: the certificate and / or contract of the first subject, identification information of the first object; a first list corresponding to the first object; A second list corresponding to the first object.

9. The method according to any one of claims 1 to 4, It is characterized in that The selecting a network according to the first information includes: When the first condition is met, the first network is selected; The first condition includes at least one of the following: The first network is a network in the first list; Obtaining first indication information from the first network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access; The terminal needs to obtain a certificate and / or a contract with the first object; The first list includes at least one of the following: a list of networks capable of configuring the certificate and / or contract of the first object; a first list corresponding to the first object; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object; a list of allowed networks corresponding to the certificate and / or contract of the first object; The first network has the highest priority in the first list; The first communication device is within the coverage of the first network or the first communication device can detect a signal of the first network.

10. The method according to any one of claims 1 to 5, It is characterized in that The selecting a network according to the first information includes: When the second condition is met, selecting the second network; The second condition includes at least one of the following: The second network is not a network in the second list; The first indication information is obtained from the second network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access; The terminal needs to obtain a certificate and / or a contract with the first object; The second list includes at least one of the following: a list of networks that cannot configure the certificate and / or contract of the first object; a second list corresponding to the first object; networks in the second list cannot enable the first communication device to obtain the certificate and / or contract of the first object; a list of disallowed networks corresponding to the certificate and / or contract of the first object; The first communication device is outside the coverage of any network in the first list or the first communication device cannot detect a signal of any network in the first list.

11. The method according to claim 1, It is characterized in that The networks in the first list are sorted by priority.

12. The method according to any one of claims 3 to 5, It is characterized in that The selecting a network according to the first information includes: When the third condition is met, the third network is selected; The third condition includes at least one of the following: The third network is a network in the first list; Obtaining first indication information from the third network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane; supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access; The terminal needs to obtain a certificate and / or a contract with the first object; The first list includes at least one of the following: a first list corresponding to the first object in a control plane manner, a list of networks capable of configuring the certificate and / or contract of the first object in a control plane manner; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object in a control plane manner; the first communication device is within the coverage of a third network or the first communication device can monitor a signal of the third network; and / or, When the fourth condition is met, selecting the fourth network; The fourth condition includes at least one of the following: The fourth network is a network in the first list; The first indication information is obtained from the fourth network, and the first indication information indicates at least one of the following: supporting configuration of certificates and / or contracts; supporting configuration of certificates and / or contracts through a control plane; supporting configuration of certificates and / or contracts through a user plane, supporting configuration of certificates and / or contracts based on restricted access; supporting configuration of certificates and / or contracts through a control plane based on restricted access; supporting configuration of certificates and / or contracts through a user plane based on restricted access; supporting configuration of certificates and / or contracts based on unrestricted access; supporting configuration of certificates and / or contracts through a control plane based on unrestricted access; supporting configuration of certificates and / or contracts through a user plane based on unrestricted access; The terminal needs to obtain a certificate and / or a contract with the first object; The first list includes at least one of the following: a first list corresponding to the first object in a user plane manner, a list of networks capable of configuring the certificate and / or contract of the first object in a user plane manner; a network in the first list capable of enabling the first communication device to obtain the certificate and / or contract of the first object in a user plane manner; The first communication device is within the coverage of the fourth network or the first communication device can monitor a signal of the fourth network.

13. A method for supporting network selection, It is characterized in that The method is executed by a third communication device and includes: Sending a first list and / or a second list to a terminal, where the first list and / or the second list is used by the terminal to select a network; The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include: enabling the first communication device to obtain a certificate and / or a contract; or the first list includes at least one of the following: a list of networks capable of configuring a certificate and / or a contract, The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include: being unable to enable the first communication device to obtain a certificate and / or a contract; or, the second list includes at least one of the following: a list of networks that cannot configure a certificate and / or a contract; The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and / or network groups.

14. The method according to claim 13, It is characterized in that The certificate and / or contract includes at least one of the following: a certificate and / or contract of the first object; a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization; in, The first object includes at least one of the following: A network, a first entity, a network accessed by the first communication device, primary authentication and / or authorization, and non-primary authentication and / or authorization; The first entity includes one of the following: an entity in a data network, an entity outside a network accessed by the first communication device; The A network is the same as or different from the network in the first list; and / or, The A network is the same as or different from the network in the second list; and / or, The A network is the same as or different from the network accessed by the first communication device; and / or, The obtaining of the certificate and / or the contract includes at least one of the following: obtaining the certificate and / or the contract through a control plane, obtaining the certificate and / or the contract through a user plane; and / or, The network list capable of configuring certificates and / or contracts includes at least one of the following: a network list capable of configuring certificates and / or contracts via a control plane, and a network list capable of configuring certificates and / or contracts via a user plane; and / or, Enabling the first communication device to obtain a certificate and / or a contract includes at least one of the following: enabling the first communication device to obtain a certificate and / or a contract via a control plane, and enabling the first communication device to obtain a certificate and / or a contract via a user plane.

15. The method according to claim 13 or 14, It is characterized in that The network types of the networks in the first list, the network types of the networks in the second list, and / or the network type of the A network include at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.

16. The method according to claim 13, It is characterized in that The networks in the first list are sorted by priority.

17. A device for supporting network selection, It is characterized in that A first communication device is used, wherein the first communication device includes a terminal, including: A first acquisition module, configured to obtain first information, wherein the first information includes: a first list and / or a second list; A selection module, configured to select a network according to the first information; in, The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include: enabling the first communication device to obtain a certificate and / or a contract; or, the first list includes: a list of networks capable of configuring a certificate and / or a contract; The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include: being unable to enable the first communication device to obtain a certificate and / or a contract; or the second list includes: a list of networks that cannot configure a certificate and / or a contract; The network list includes one or more network objects, or identification information of one or more network objects; the network objects include networks and / or network groups.

18. A device for supporting network selection, It is characterized in that Applicable to a third communication device, comprising: A second sending module, used for sending the first list and / or the second list to the terminal, where the first list and / or the second list is used by the terminal to select a network; The first list includes: one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the first list include: enabling the first communication device to obtain a certificate and / or a contract; or the first list includes: a list of networks capable of configuring a certificate and / or a contract, The second list includes one or more network objects, or identification information of one or more network objects, and the characteristics of the networks in the second list include: being unable to enable the first communication device to obtain a certificate and / or a contract; or, the second list includes: a list of networks that cannot configure a certificate and / or a contract; The network list includes one or more network objects, or the network list includes identification information of one or more network objects, and the network objects include networks and / or network groups.

19. A terminal, It is characterized in that include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program implements the steps of the method according to any one of claims 1 to 12 when executed by the processor.

20. A network side device, It is characterized in that include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the method according to any one of claims 13 to 16 are implemented.

21. A readable storage medium, It is characterized in that The readable storage medium stores a program or an instruction, and when the program or the instruction is executed by a processor, the steps of the method according to any one of claims 1 to 16 are implemented.

Citation Information

Patent Citations

  • Communication method, device and system

    CN111510923A