Method, apparatus, device and readable storage medium for supporting information obtaining
By sending a request containing configuration and association information to the network, obtaining the address of the first server, and prioritizing the processing of the latest information, the difficulty of obtaining certificates and subscriptions for terminals in standalone, non-public networks is solved, thus achieving accurate network access configuration.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- VIVO MOBILE COMM CO LTD
- Filing Date
- 2021-05-10
- Publication Date
- 2026-04-28
AI Technical Summary
When terminals temporarily access a network, they face difficulties in obtaining certificate and/or subscription configuration information, especially in standalone, non-public networks, where existing technologies cannot effectively provide the necessary information indexes and server addresses.
By sending a request to the first network, including first configuration information and associated information, the address of the first server is obtained, and the configuration information associated with it is confirmed according to the terminal's slice information and DN information. The latest configuration information is processed first to ensure accurate configuration of certificates and contracts.
This technology enables terminals to accurately obtain certificates and subscription information in independent, non-public networks, solving the problem of incomplete information indexing in existing technologies and ensuring smooth network access.
Smart Images

Figure CN114915960B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and specifically relates to a method, apparatus, device and readable storage medium that supports information acquisition. Background Technology
[0002] Terminals (e.g., user equipment, UE) may wish to temporarily access a first network to obtain certificates and / or subscriptions. However, how to obtain the configuration information from the first network for the terminal to obtain certificates and / or subscriptions is a problem that urgently needs to be solved. Summary of the Invention
[0003] This application provides a method, apparatus, device, and readable storage medium for supporting information acquisition, solving the problem of how to obtain configuration information from a first network for a terminal to obtain a certificate and / or sign up.
[0004] In a first aspect, a method for supporting information acquisition is provided, executed by a first communication device, comprising:
[0005] Send first information to a first network, the first information including: first configuration information and / or associated information of the first configuration information;
[0006] in,
[0007] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0008] The associated information of the first configuration information includes at least one of the following:
[0009] The identification information of the first object;
[0010] The group identifier information of the network group to which the first object belongs;
[0011] The slice information associated with the first object;
[0012] The DN information associated with the first object;
[0013] The identification information of the network to which the first server belongs;
[0014] The group identifier information of the network group to which the first server belongs;
[0015] The certificate and / or contract type information;
[0016] Indication information used to indicate the first access method;
[0017] The slice information associated with the first configuration information;
[0018] The first configuration information is associated with the DN information.
[0019] Secondly, a method for supporting information acquisition is provided, executed by a second communication device, including:
[0020] Obtain first information, which includes: first configuration information and / or associated information of the first configuration information;
[0021] Based on the first information, perform the first operation;
[0022] The first operation includes at least one of the following:
[0023] Save the first information;
[0024] Generate index information for the first configuration information, where the index information is one or more of the associated information of the first configuration information;
[0025] Generate index information for the address information of the first server, wherein the index information for the address information of the first server is one or more of the associated information of the first server;
[0026] Obtain the first request information, and based on the first request information, query or accept the order for the first configuration information;
[0027] Send the first configuration information that has been queried or ordered and / or the associated information of the first configuration information;
[0028] Obtain the terminal's slice information and / or the terminal's DN information, and based on the terminal's slice information and / or the terminal's DN information, confirm the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0029] Send first configuration information and / or associated information of the first configuration information, wherein the first configuration information is the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0030] Select the first target end and / or select the terminal's data channel;
[0031] Send the first information to the first target terminal and / or send the first information through relevant signaling of the terminal's data channel;
[0032] The priority of primary information is set higher than the priority of strategy information related to data operations;
[0033] in,
[0034] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0035] The associated information of the first configuration information includes at least one of the following:
[0036] The identification information of the first object;
[0037] The group identifier information of the network group to which the first object belongs;
[0038] The slice information associated with the first object;
[0039] The DN information associated with the first object;
[0040] The identification information of the network to which the first server belongs;
[0041] The group identifier information of the network group to which the first server belongs;
[0042] The certificate and / or contract type information;
[0043] The slice information associated with the first configuration information;
[0044] The first configuration information is associated with the DN information;
[0045] The indication information used to indicate the first access method indicates one of the following: the first configuration service information is used for terminals accessing the first network through the first access method, and the first server is able to configure the certificate and / or subscription of the first object for terminals accessing the first network through the first access method.
[0046] Thirdly, a method for supporting information acquisition is provided, executed by a third communication device, including:
[0047] Obtain second information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information;
[0048] Based on the second information, perform the second operation;
[0049] The second operation includes at least one of the following:
[0050] Select or query the target communication device based on the second information;
[0051] Send the first request information to the target communication device;
[0052] Send the second message;
[0053] The certificate and / or contract type information includes at least one of the following: a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization.
[0054] Fourthly, a method for supporting information acquisition is provided, executed by a fourth communication device, comprising:
[0055] Obtain network element query information and / or communication device index information;
[0056] The network element query information includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information, and DN information.
[0057] The third operation is performed based on the network element query information and / or the communication device index information;
[0058] The third operation includes at least one of the following:
[0059] Match the target communication device based on the network element query information;
[0060] Send information to the target communication device.
[0061] Fifthly, a method for supporting information acquisition is provided, executed by a fifth communication device, comprising:
[0062] The fourth acquisition module is used to acquire the first configuration information and / or the associated information of the first configuration information.
[0063] A sixth aspect provides a method for supporting information acquisition, executed by a sixth communication device, comprising:
[0064] Send network element registration information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the third object, group identification information of the network group to which the third object belongs, identification information of the third network, and group identification information of the third network group;
[0065] The third object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.
[0066] A seventh aspect provides an apparatus for supporting information acquisition, applied to a first communication device, comprising:
[0067] A first sending module is configured to send first information to a first network, the first information including: first configuration information and / or associated information of the first configuration information;
[0068] in,
[0069] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0070] The associated information of the first configuration information includes at least one of the following:
[0071] The identification information of the first object;
[0072] The group identifier information of the network group to which the first object belongs;
[0073] The slice information associated with the first object;
[0074] The DN information associated with the first object;
[0075] The identification information of the network to which the first server belongs;
[0076] The group identifier information of the network group to which the first server belongs;
[0077] The certificate and / or contract type information;
[0078] Indication information used to indicate the first access method;
[0079] The slice information associated with the first configuration information;
[0080] The first configuration information is associated with the DN information.
[0081] Eighthly, an apparatus for supporting information acquisition is provided, applied to a second communication device, comprising:
[0082] A first acquisition module is used to acquire first information, the first information including: first configuration information and / or associated information of the first configuration information;
[0083] The first execution module is used to perform a first operation based on the first information;
[0084] The first operation includes at least one of the following:
[0085] Save the first information;
[0086] Generate index information for the first configuration information, where the index information is one or more of the associated information of the first configuration information;
[0087] Generate index information for the address information of the first server, wherein the index information for the address information of the first server is one or more of the associated information of the first server;
[0088] Obtain the first request information, and based on the first request information, query or accept the order for the first configuration information;
[0089] Send the first configuration information that has been queried or ordered and / or the associated information of the first configuration information;
[0090] Obtain the terminal's slice information and / or the terminal's DN information, and based on the terminal's slice information and / or the terminal's DN information, confirm the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0091] Send first configuration information and / or associated information of the first configuration information, wherein the first configuration information is the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0092] Select the first target end and / or select the terminal's data channel;
[0093] Send the first information to the first target terminal and / or send the first information through relevant signaling of the terminal's data channel;
[0094] The priority of primary information is set higher than the priority of strategy information related to data operations;
[0095] in,
[0096] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0097] The associated information of the first configuration information includes at least one of the following:
[0098] The identification information of the first object;
[0099] The group identifier information of the network group to which the first object belongs;
[0100] The slice information associated with the first object;
[0101] The DN information associated with the first object;
[0102] The identification information of the network to which the first server belongs;
[0103] The group identifier information of the network group to which the first server belongs;
[0104] The certificate and / or contract type information;
[0105] The slice information associated with the first configuration information;
[0106] The first configuration information is associated with the DN information;
[0107] The indication information used to indicate the first access method indicates one of the following: the first configuration service information is used for terminals accessing the first network through the first access method, and the first server is able to configure the certificate and / or subscription of the first object for terminals accessing the first network through the first access method.
[0108] Ninth aspect, a device for supporting information acquisition is provided, applied to a third communication device, comprising:
[0109] The second acquisition module is used to acquire second information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information;
[0110] The second execution module is used to perform the second operation based on the second information;
[0111] The second operation includes at least one of the following:
[0112] Select or query the target communication device based on the second information;
[0113] Send the first request information to the target communication device;
[0114] Send the second message;
[0115] The certificate and / or contract type information includes at least one of the following: a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization.
[0116] Tenthly, an apparatus for supporting information acquisition is provided, applied to a fourth communication device, comprising:
[0117] The third acquisition module is used to acquire network element query information and / or communication device index information;
[0118] The network element query information includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information, and DN information.
[0119] The third execution module is used to perform a third operation based on the network element query information and / or the index information of the communication device;
[0120] The third operation includes at least one of the following:
[0121] Match the target communication device based on the network element query information;
[0122] Send information to the target communication device.
[0123] Eleventhly, an apparatus for supporting information acquisition is provided, applied to a fifth communication device, comprising:
[0124] The fourth acquisition module is used to acquire the first configuration information and / or the associated information of the first configuration information.
[0125] In a twelfth aspect, an apparatus for supporting information acquisition is provided, applied to a sixth communication device, comprising:
[0126] The third sending module is used to send network element registration information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the third object, group identification information of the network group to which the third object belongs, identification information of the third network, and group identification information of the third network group.
[0127] The third object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.
[0128] In a thirteenth aspect, a terminal is provided, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, performs the steps of the method described in the fifth aspect.
[0129] Fourteenth aspect, a network-side device is provided, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the methods described in the first, second, third, fourth, or sixth aspects.
[0130] In a fifteenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described above.
[0131] In a sixteenth aspect, a program product is provided, the program product being stored in a non-volatile storage medium, the program product being executed by at least one processor to implement the steps of the method described above.
[0132] In a seventeenth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being used to run a program or instructions to implement the steps of the method described above.
[0133] In this embodiment of the application, the terminal is supported in obtaining configuration information, which includes the address information of the first server. The terminal can obtain a certificate and / or a contract from the first server through the first network. Attached Figure Description
[0134] Figure 1 This is one of the schematic diagrams illustrating the method for obtaining supporting information provided in the embodiments of this application;
[0135] Figure 2 This is a second schematic diagram of the method for obtaining supporting information provided in the embodiments of this application;
[0136] Figure 3 This is the third schematic diagram of the method for obtaining supporting information provided in the embodiments of this application;
[0137] Figure 4 This is a fourth schematic diagram of the method for obtaining supporting information provided in the embodiments of this application;
[0138] Figure 5 This is the fifth schematic diagram of the method for obtaining supporting information provided in the embodiments of this application;
[0139] Figure 6 This is a schematic diagram of the method for obtaining supporting information provided in the embodiments of this application;
[0140] Figure 7-A and Figure 7-B This is a schematic diagram of the method for obtaining supporting information provided in the embodiments of this application;
[0141] Figure 8This is one of the schematic diagrams of the apparatus for obtaining supporting information provided in the embodiments of this application;
[0142] Figure 9 This is a second schematic diagram of the device for obtaining supporting information provided in the embodiments of this application;
[0143] Figure 10 This is the third schematic diagram of the device for obtaining supporting information provided in the embodiments of this application;
[0144] Figure 11 This is a fourth schematic diagram of the apparatus for obtaining supporting information provided in the embodiments of this application;
[0145] Figure 12 This is the fifth schematic diagram of the apparatus for obtaining supporting information provided in the embodiments of this application;
[0146] Figure 13 This is a schematic diagram of the apparatus for obtaining supporting information provided in the embodiments of this application;
[0147] Figure 14 This is a schematic diagram of the terminal provided in an embodiment of this application;
[0148] Figure 15 This is a schematic diagram of the network-side device provided in the embodiments of this application. Detailed Implementation
[0149] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0150] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects have an "and / or" relationship.
[0151] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. However, the following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description, although these technologies can also be applied to applications other than NR systems, such as 6th generation (6G) radio systems. th Generation 6G communication system.
[0152] In related technologies, a terminal (e.g., a user equipment (UE)) can access a Public Land Mobile Network (PLMN) or a Standalone Non-Public Network (SNPN)1 to download the SNPN2 certificate. When the UE does not have an SNPN1 certificate, if SNPN1 supports onboarding, then SNPN1 can be called an onboarding SNPN (O-SNPN for short). During onboarding SNPN, the UE does not have an O-SNPN certificate and uses the default credential to access the O-SNPN, and must provide an onboarding instruction to explain the special nature of the UE's registration type. Therefore, the O-SNPN scenario includes two functions:
[0153] (1) Default credential onboarding;
[0154] (2) Certificate and / or contract download.
[0155] For user plane certificate downloads, the UE may need to obtain the Provisioning Server (PS) address from SNPN1 or PLMN. The Application Function (AF) can configure the network to assign the PS address required for the UE.
[0156] Question 1: Since the UE only has a default credential, the AF cannot provide the associated Generic Public Subscription Identifier (GPSI) or UE Group Identifier (GroupID). Furthermore, an O-SNPN may serve multiple SO-SNPNs, and each SO-SNPN may have a different PS address. Therefore, simply providing the PS address is insufficient; the AF needs to provide the PS address and its associated information, such as the SO-SNPN ID and SO-SNPN Group ID.
[0157] One solution is for the UE to register with the Access and Mobility Management Function (AMF) of a first network (such as O-SNPN) to provide indication information (such as onboarding instructions) for the first access method. Since the AMF cannot index the O-SNPN's Unified Data Manager (UDM) or Unified Data Repository (UDR) based on the UE's UE identifier (e.g., Subscription Permanent Identifier (SUPI)), it can index the UDM or UDR used for onboarding based on the onboarding instructions and query or order the address information of the first server from the UDM or UDR. When multiple first servers exist, the UE can also provide the association information of the first configuration server during registration, such as the identification information of a second object (e.g., SO-SNPN), to request the address information of the corresponding SO-SNPN's first server.
[0158] Question 2: Existing information indexes (such as data keys) only support those based on terminal identifiers or terminal group identifiers. However, when the AF configures the address information of the first server to the first network, it cannot determine which terminals will access the first network to obtain it. Therefore, information indexes based on terminal identifiers or terminal group identifiers cannot index the address information of the first server.
[0159] One solution is to index the information by adding a new data key: SO-SNPN ID or onboarding indication.
[0160] Question 3: Core network elements, such as UDM, UDR, and Policy Control function (PCF), cannot be determined by the Subscription Permanent Identifier (SUPI) associated with the UE's default certificate.
[0161] One solution is to determine this through onboarding instructions, meaning that there is a core network element in the first network specifically for onboarding.
[0162] Another approach is to identify it through the SO-SNPN identifier, that is, in the first network, there is a core network element dedicated to SO-SNPN.
[0163] Question 4: When there are multiple configuration server addresses to be configured for the UE, additional information needs to be provided to the address of each configuration server; otherwise, the UE will not know how to select the configuration server address to use.
[0164] Question 5: In the existing definition, the priority of the PCC rule is higher than the priority of the first information stored locally in the SMF, or higher than the priority of data operation rules set based on the locally stored first information. Since the first information obtained externally is the most recent, it should have a higher priority. If the PCF still uses the locally configured first information to set the PCC rule, and the existing PCC rule has a higher priority than the first information stored locally in the SMF, this will cause errors when the SMF sets data operation rules based on the PCC rule. Therefore, one solution is to send the latest first information to the PCF or set the priority of the received first information to be higher than the priority of the PCC rule.
[0165] In one implementation, local storage and local configuration are sometimes used interchangeably.
[0166] In one optional embodiment of this application, obtaining or acquiring can be understood as obtaining from configuration, receiving, receiving after a request, acquiring through self-learning, inferring from unreceived information, or acquiring after processing received information. The specific method can be determined according to actual needs, and this embodiment does not limit this. For example, when a certain capability indication information sent by the device is not received, it can be inferred that the device does not support that capability.
[0167] In an optional embodiment of the invention, the transmission may include a broadcast, a system message broadcast, or a response to a request followed by a return.
[0168] In an optional embodiment of the invention, "capable" can mean at least one of the following: allow, support, prefer, or preferentially have capability. "Cannot" can mean at least one of the following: disallow, not support, disallow, not prefer, or lack capability.
[0169] In one optional embodiment of this application, the communication device may include at least one of the following: a communication network element and a terminal.
[0170] In one optional embodiment of this application, the communication network element may include at least one of the following: a core network element and a radio access network (RAN) element.
[0171] In one optional embodiment of this application, the core network element (CN element) may include, but is not limited to, at least one of the following: core network equipment, core network node, core network function, core network element, Mobility Management Entity (MME), Access Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Serving Gateway (SGW), PDN Gateway (PDN Gateway), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Serving GPRS Support Node (SGSN), Gateway GPRS Support Node (GGSN), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), and Application Function (AF).
[0172] In one optional embodiment of this application, the RAN network element may include, but is not limited to, at least one of the following: radio access network equipment, radio access network node, radio access network function, radio access network unit, 3GPP radio access network, non-3GPP radio access network, centralized unit (CU), distributed unit (DU), base station, evolved Node B (eNB), 5G base station (gNB), radio network controller (RNC), base station (NodeB), non-3GPP interworking function (N3IWF), access controller (AC) node, access point (AP) equipment, or wireless local area network (WLAN) node, N3IWF.
[0173] In one optional embodiment of this application, the first access method includes at least one of the following: an access method for accessing the network in order to obtain a certificate and / or a subscription, an access method using a restricted access network, and an access method using a default certificate to access the network;
[0174] In one implementation, the method of using a restricted network to download a certificate for accessing the first object, or the method of accessing a network to download a certificate for accessing the first object, can be referred to as onboarding. When the first object includes network A, the first network and network A can be the same network or different networks. The first network is the network accessed by the terminal, such as the currently accessed network.
[0175] In one optional embodiment of this application, the first server is used to configure the certificate and / or contracted server of the first object for the terminal.
[0176] In an optional embodiment of the present invention, the support for configuring certificates and / or contracts is used to further indicate at least one of the following: support for configuring certificates and / or contracts via the control plane, and support for configuring certificates and / or contracts via the user plane.
[0177] In an optional embodiment of the present invention, the statement "cannot configure certificates and / or contracts" is used to further indicate that configuring certificates and / or contracts via the control plane is not supported, and configuring certificates and / or contracts via the user plane is not supported.
[0178] In an optional embodiment of the present invention, the acquisition of the certificate and / or agreement is done remotely. For example, when a terminal accesses a first network to obtain the certificate and / or agreement, the provider of the certificate and / or agreement is a first entity. The first entity is an entity in a data network (DN) or an entity outside the network accessed by the terminal.
[0179] In an optional embodiment of the invention, the provider of the certificate and / or subscription is one of the following: an entity outside the first network, an entity outside the network accessed by the terminal, an entity in the data network (DN), or an entity in another network. The entity in the data network may be an application server, a certificate and / or subscription configuration server in the data network. The goal of the terminal accessing the network includes obtaining a certificate and / or subscription.
[0180] In an optional embodiment of the present invention, the certificate and / or agreement is a certificate and / or agreement for the network accessed by the terminal. The certificate and / or agreement for the network accessed by the terminal includes at least one of the following: a certificate and / or agreement for the terminal to use an unrestricted network, and a certificate and / or agreement for the terminal to use a restricted network.
[0181] In an optional embodiment of the present invention, the certificate and / or agreement includes at least one of the following: a certificate and / or agreement for unrestricted access, a certificate and / or agreement for restricted access, a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization. Primary authentication (such as Primary Authentication) may include: Authentication and Key Agreement (AKA), for example, 5G AKA, or Extensible Authentication Protocol (EAP) AKA.
[0182] Non-primary authentication and / or authorization includes at least one of the following: secondary authentication and / or authorization, and NSSAA Network Slice-Specific Authentication and Authorization. It is easy to understand that slice information associated with non-primary authentication and / or authorization includes slice information associated with "slice-related authentication and / or authorization," which can indicate whether the terminal is allowed to access the slice indicated by the slice information. Slice information associated with non-primary authentication and / or authorization and / or DN information associated with non-primary authentication and / or authorization includes slice information associated with secondary authentication and / or authorization and / or DN information, which can indicate whether the terminal is allowed to access the slice and / or DN.
[0183] In one implementation, the slice information may represent information about the slice.
[0184] In one embodiment, the slice information may include one of the following: S-NSSAI, NSSAI.
[0185] In one implementation, the DN information may represent information about a DN.
[0186] In one embodiment, the DN information may include at least one of the following: DNN (Data Network Name, also known as APN Access Point Name), and DN identification information.
[0187] In one implementation, the terminal may use a certificate (such as a default certificate) and / or subscription for restricted access to a first network, and then obtain a certificate and / or subscription for unrestricted access to a first object (including network A) through the first network. Network A may be the same as or different from the first network.
[0188] In an optional embodiment of the present invention, obtaining a certificate and / or a contract and / or configuring a certificate and / or a contract via the control plane includes at least one of the following: a first entity configures the certificate and / or a contract to the terminal via control plane signaling of the network accessed by the terminal; the terminal obtains the certificate and / or a contract from the first entity via control plane signaling of the network accessed by the terminal.
[0189] In an optional embodiment of the present invention, obtaining a certificate and / or a subscription and / or configuring a certificate and / or a subscription via the user plane includes at least one of the following: the terminal establishes a data channel in the accessed network and obtains the certificate and / or subscription from a first entity through the data channel; or the first entity configures the certificate and / or subscription to the terminal through the data channel established by the terminal in the accessed network.
[0190] In an optional embodiment of the present invention, the data channel includes at least one of the following: the data channel may include, but is not limited to, one of the following: PDU session, PDN connection, QoS stream, bearer, Internet Protocol Security (IPsec) channel, wherein the bearer may be an Evolved Radio Access Bearer (E-RAB), a Radio Access Bearer (RAB), a Data Radio Bearer (DRB), a Signaling Radio Bearer (SRB), etc.
[0191] In an optional embodiment of the present invention, the networks that are allowed to be accessed using a default certificate include those where the terminal accesses a network that can obtain limited connectivity using the terminal identifier corresponding to the default certificate.
[0192] In an optional embodiment of the invention, the default certificate includes a certificate for restricted access.
[0193] In an optional embodiment of the present invention, restricted access and restricted connection have the same meaning and can be used interchangeably.
[0194] In one implementation, the restricted access includes at least one of the following: only establishing a first data channel is permitted, and establishing data channels other than the first data channel is not permitted; only obtaining certificates and / or contracts is permitted, and obtaining services other than obtaining certificates and / or contracts is not permitted. The first data channel is used for obtaining certificates and / or contracts.
[0195] In one implementation, the certificate and / or contract of the first object can be obtained through the restricted access.
[0196] In an optional embodiment of the present invention, restricted access includes restricted control plane access and / or restricted user plane access.
[0197] In an optional embodiment of the invention, the restricted connection includes a restricted control plane connection and / or a restricted user plane connection. Certificates and / or contracts can be obtained through the restricted connection.
[0198] In an optional embodiment of the present invention, the network that can be accessed using the default certificate includes the network accessed using the terminal identifier corresponding to the default certificate and the network authentication and / or authorization that can be passed through the default certificate.
[0199] In an optional embodiment of the present invention, the subscription includes subscription data, such as slice information, data network name (DNN), etc.
[0200] In an optional embodiment of the present invention, the second communication device, the third communication device, the fourth communication device, and / or the sixth communication device are communication devices in the first network.
[0201] In an optional embodiment of the present invention, the object (e.g., a first object, a second object, a third object) includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, and non-primary authentication and / or authorization.
[0202] Wherein, network A may be the same as or different from the first network;
[0203] The A network may be the same as or different from the network accessed by the terminal.
[0204] In an optional embodiment of the present invention, the network type of the first network, the network accessed by the terminal, and / or the network type of network A include at least one of the following: public network, non-public network, public land mobile network (PLMN), public network integrated non-public network (PNI NPN), and standalone non-public network (SNPN).
[0205] In an optional embodiment of the present invention, the indication information for indicating the first access method can be embodied as a registration type for identifying the registration of the first access method type.
[0206] In an optional embodiment of the invention, the A network or the second network includes: a certificate and / or contract holder's SNPN network (such as SO-SNPN).
[0207] In one embodiment, the first server includes: a server that configures certificates and / or subscription information for terminals;
[0208] The certificate and / or contract information may be at least one of the following: certificate and / or contract information for accessing the first object, primary authentication and / or authorization certificate and / or contract, and non-primary authentication and / or authorization certificate and / or contract information.
[0209] Non-primary authentication and / or authorization includes at least one of the following: secondary authentication and / or authorization, slicing-related secondary authentication and / or authorization.
[0210] The first object includes: a slice of a network, a DN, and a network;
[0211] The network type includes at least one of the following: SNPN, PNI-NPN, PLMN.
[0212] In one embodiment, the segment information of the terminal includes at least one of the following: segment information requested by the terminal, segment information allowed by the terminal, segment information subscribed by the terminal, and segment information configured by the terminal.
[0213] In one embodiment, the slice information requested by the terminal includes at least one of the following: slice information requested when the terminal establishes a session; slice information requested when the terminal registers a network.
[0214] In one embodiment, the DN information of the terminal includes at least one of the following: DN information requested by the terminal, DN information allowed by the terminal, DN information of the terminal's subscription, and DN information configured by the terminal.
[0215] In one embodiment, the DN information requested by the terminal includes at least one of the following: DN information requested when the terminal establishes a session; DN information requested when the terminal registers with a network.
[0216] It's easy to understand that non-primary authentication (such as secondary authentication and segmented authentication) is associated with the terminal's segment and / or the terminal's DN information. When it's necessary to configure the location of the first server corresponding to the certificate download for non-primary authentication on the terminal, the terminal's segment information and / or the terminal's DN information can be used for association.
[0217] In one embodiment, the registration request information (including the registration request message) includes: the slice information requested by the terminal.
[0218] In one implementation, the data channel (e.g., PDU session) establishment request information (including data channel establishment request message) includes at least one of the following: slice information requested by the terminal, and DN information requested by the terminal.
[0219] In one implementation, the terminal establishes a connection with the network through connection establishment request information (such as connection establishment request message, service request message).
[0220] It's easy to understand that non-primary authentication (such as two-factor authentication and segmented authentication) is associated with the terminal's segment and / or DN information. When configuring a primary server for downloading non-primary authentication certificates for a terminal, the terminal's segment information and / or DN information can be used for association.
[0221] In one implementation, when the first configuration information includes the address information of multiple first servers, obtaining the first configuration information and its association information can help the terminal confirm which association information each first server is associated with. For example, first server A is associated with slice A, and second server B is associated with slice B.
[0222] The following description, in conjunction with the accompanying drawings, details a method, apparatus, device, and readable storage medium for supporting information acquisition provided by the embodiments of this application, through some examples and application scenarios.
[0223] See Figure 1 This application provides a method for supporting information acquisition, which is executed by a first communication device. The first communication device includes, but is not limited to, one of the following: AF, Network Exposure Function (NEF), Default Credentials Server (DCS), AUSF (such as AUSF in DCS), UDM (such as UDM in DCS), core network element; the specific steps include: step 101.
[0224] Step 101: Send first information to the first network, the first information including: first configuration information and / or associated information of the first configuration information;
[0225] In an optional embodiment of the present invention, the first configuration information may be referred to as configuration information for the first access method.
[0226] In an optional embodiment of the present invention, the first configuration information includes: the address information of a first server, wherein the first server is capable of configuring a certificate and / or subscription for a first object for a terminal (e.g., a terminal accessing a first network);
[0227] In an optional embodiment of the present invention, the associated information of the first configuration information includes at least one of the following:
[0228] (1) Identification information of the first object;
[0229] (2) The group identifier information of the network group to which the first object belongs;
[0230] (3) The slice information associated with the first object;
[0231] (4) The DN information associated with the first object;
[0232] (5) Identification information of the network to which the first server belongs;
[0233] (6) The group identifier information of the network group to which the first server belongs;
[0234] (7) Information on the type of certificate and / or contract;
[0235] (8) Indication information for indicating the first access method. In an optional embodiment of the present invention, the first object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization;
[0236] (9) Slice information associated with the first configuration information;
[0237] (10) DN information associated with the first configuration information;
[0238] Wherein, network A may be the same as or different from the first network;
[0239] And / or,
[0240] The certificate and / or agreement type information includes at least one of the following: a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization;
[0241] And / or,
[0242] Indication information used to indicate the first access method indicates one of the following: the first configuration service information is used for terminals accessing the first network through the first access method, and the first server is able to configure the certificate and / or subscription of the first object for the terminals accessing the first network through the first access method;
[0243] And / or,
[0244] Terminals accessing the first network access the first network via a first access method;
[0245] And / or,
[0246] The first server includes at least one of the following: a first server for primary authentication and / or authorization configuration, and a first server for non-primary authentication and / or authorization configuration;
[0247] Wherein, the first server for primary authentication and / or authorization configuration is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for primary authentication and / or authorization;
[0248] The first server configured for non-master authentication and / or authorization is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for non-master authentication and / or authorization.
[0249] In an optional embodiment of the present invention, the network type of the first network, the network accessed by the terminal, and / or the network type of network A include at least one of the following: public network, non-public network, public land mobile network (PLMN), public network integrated non-public network (PNI NPN), and standalone non-public network (SNPN).
[0250] In one embodiment, the slice information includes at least one of the following: slice information associated with primary authentication and / or authorization, and slice information associated with non-primary authentication and / or authorization.
[0251] In one embodiment, the DN information includes at least one of the following: DN information associated with primary authentication and / or authorization, and DN information associated with non-primary authentication and / or authorization.
[0252] In one implementation, the object associated with primary authentication and / or authorization may represent whether a terminal is allowed to access the object through a primary authentication and / or authorization process. The object associated with primary authentication and / or authorization includes at least one of the following: a slice (such as a slice specified in slice information), and a DN (such as a DN specified in DN information).
[0253] In one implementation, the object associated with non-primary authentication and / or authorization represents the determination of whether a terminal is allowed to access the object through a non-primary authentication and / or authorization process. The object associated with non-primary authentication and / or authorization includes at least one of the following: a slice (such as a slice specified in slice information), and a DN (such as a DN specified in DN information).
[0254] In an optional embodiment of the present invention, the address information of the first server includes at least one of the following: the Internet Protocol address of the first server, the Media Access Control address of the first server, the port number of the first server, the protocol version of the first server, and the index information of the address of the first server.
[0255] In an optional embodiment of the present invention, the index information of the first server address includes at least one of the following: the fully qualified domain name (FQDN) of the first server, and the Uniform Resource Locator (URL) of the first server.
[0256] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0257] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0258] Taking the first communication device as the AF as an example, the AF can provide onboarding configuration data to the O-SNPN or O-PLMN, including the PS address and the corresponding SO-SNPN identifier. This data is stored in the UDR and a new data key is generated, such as the SO-SNPN identifier, SO-SNPN group identifier, or onboarding identifier.
[0259] This application embodiment supports providing first configuration information to a first network. This allows the first network to configure the first configuration information for the terminal. The first configuration information includes the address information of a first server, and the terminal can obtain a certificate and / or subscription from the first server through the first network. Furthermore, the associated information of the first configuration can also support filtering of the first configuration information, allowing the terminal to obtain the truly desired first configuration information.
[0260] See Figure 2 This application provides a method for supporting information acquisition, executed by a second communication device, which includes, but is not limited to, one of the following: core network elements (such as UDM, UDR, AMF, SMF, PCF); the specific steps include:
[0261] Step 201: Obtain first information, the first information including: first configuration information and / or the associated information of the first configuration information;
[0262] Step 202: Based on the first information, perform the first operation;
[0263] In an optional embodiment of the present invention, the first operation includes at least one of the following:
[0264] (1) Save the first information;
[0265] (2) Generate index information (e.g., data key) for the first configuration information, and the index information of the first configuration information is one or more of the associated information of the first configuration information;
[0266] (3) Generate index information (e.g., data key) for the address information of the first server, and the index information of the address information of the first server is one or more of the associated information of the first server;
[0267] (4) Obtain the first request information, and query or accept the order for the first configuration information based on the first request information;
[0268] In one implementation, the first request information is used to request first configuration information (including the address information of the first server).
[0269] In one implementation, the first request is a first order request, used to order first configuration information (such as the address information of a first server).
[0270] (5) Send the first configuration information that has been queried or ordered and / or the associated information of the first configuration information;
[0271] Obtain the terminal's slice information and / or the terminal's DN information, and based on the terminal's slice information and / or the terminal's DN information, confirm the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0272] Send first configuration information and / or associated information of the first configuration information, wherein the first configuration information is the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0273] Select the first target end and / or select the terminal's data channel;
[0274] Send the first information to the first target terminal and / or send the first information through relevant signaling of the terminal's data channel;
[0275] The priority of setting primary information is higher than the priority of policy information related to data operations.
[0276] Optionally, when sending the first configuration information that has been queried or ordered, the associated information of the first configuration information is also sent.
[0277] In one implementation, if obtaining the first request information occurs before obtaining the first information, then the requested first configuration information is sent after obtaining the first information. In another implementation, the ordered first configuration information is sent when the first configuration information changes.
[0278] In one implementation, first configuration information that has been queried or ordered is sent to the communication device that sent the first request information. Optionally, association information of the first configuration information may also be sent to the communication device that sent the first request information.
[0279] In an optional embodiment of the present invention, the first configuration information includes: the address information of a first server, wherein the first server is capable of configuring a certificate and / or subscription for a first object for the terminal;
[0280] The associated information of the first configuration information includes at least one of the following:
[0281] (1) Identification information of the first object;
[0282] (2) The group identifier information of the network group to which the first object belongs;
[0283] (3) The slice information associated with the first object;
[0284] (4) The DN information associated with the first object;
[0285] (5) Identification information of the network to which the first server belongs;
[0286] (6) The group identifier information of the network group to which the first server belongs;
[0287] (7) Information on the type of certificate and / or contract;
[0288] (8) Indication information for indicating the first access method. In an optional embodiment of the present invention, the first object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization;
[0289] (9) Slice information associated with the first configuration information;
[0290] (10) DN information associated with the first configuration information;
[0291] Wherein, network A may be the same as or different from the first network;
[0292] And / or,
[0293] The certificate and / or agreement type information includes at least one of the following: a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization;
[0294] And / or,
[0295] Terminals accessing the first network access the first network through a first access method;
[0296] And / or,
[0297] The first server includes at least one of the following: a first server for primary authentication and / or authorization configuration, and a first server for non-primary authentication and / or authorization configuration;
[0298] Wherein, the first server for primary authentication and / or authorization configuration is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for primary authentication and / or authorization;
[0299] The first server configured for non-master authentication and / or authorization is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for non-master authentication and / or authorization.
[0300] In an optional embodiment of the present invention, the network type of the first network and / or the network type of network A includes at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
[0301] In one embodiment, the slice information includes the terminal's slice information;
[0302] In one embodiment, the DN information includes the DN information of the terminal;
[0303] In one embodiment, the segment information of the terminal includes at least one of the following: segment information requested by the terminal, segment information allowed by the terminal, segment information subscribed by the terminal, and segment information configured by the terminal.
[0304] In one embodiment, the slice information requested by the terminal includes at least one of the following: slice information requested when the terminal establishes a session; slice information requested when the terminal registers a network.
[0305] In one embodiment, the DN information of the terminal includes at least one of the following: DN information requested by the terminal, DN information allowed by the terminal, DN information of the terminal's subscription, and DN information configured by the terminal.
[0306] In one embodiment, the DN information requested by the terminal includes at least one of the following: DN information requested when the terminal establishes a session; DN information requested when the terminal registers with a network.
[0307] It's easy to understand that non-primary authentication (such as secondary authentication and segmented authentication) is associated with the terminal's segment and / or the terminal's DN information. When it's necessary to configure the location of the first server corresponding to the certificate download for non-primary authentication on the terminal, the terminal's segment information and / or the terminal's DN information can be used for association.
[0308] In one embodiment, sending the first configuration information and / or the associated information of the first configuration information includes: sending the first configuration information and / or the associated information of the first configuration information to the terminal.
[0309] In one implementation, a first request is obtained, and based on the first request, the user queries or accepts an order for first configuration information.
[0310] In another implementation, the terminal's slice information and / or the terminal's DN information (such as the terminal's subscribed slice information and / or the terminal's subscribed DN information) are obtained, and based on the terminal's slice information and / or the terminal's DN information, the first configuration information associated with the terminal's slice information and / or the terminal's DN information is confirmed.
[0311] In an optional embodiment of the present invention, the address information of the first server includes at least one of the following: the Internet Protocol address of the first server, the Media Access Control address of the first server, the port number of the first server, the protocol type used for the certificate and / or subscription configuration, the protocol version of the first server, and the index information of the first server address.
[0312] In an optional embodiment of the present invention, the index information of the first server address includes at least one of the following: the FQDN of the first server, and the URL of the first server.
[0313] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0314] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0315] In an optional embodiment of the present invention, the first request information includes at least one of the following:
[0316] (1) Indication information used to indicate the first access method;
[0317] (2) Information on the type of certificate and / or contract;
[0318] (3) Identification information of the second object;
[0319] (4) Group identifier information of the network group to which the second object belongs;
[0320] (5) Identification information of the second network;
[0321] In one embodiment, the identification information of the second network can be used to map the configuration information of the first access method corresponding to the second network (including the address information of the first server).
[0322] (6) Group identifier information of the second network group;
[0323] (7) Slice information associated with the second object;
[0324] (8) DN information associated with the second object;
[0325] (9) Terminal slice information;
[0326] (10) DN information of the terminal.
[0327] Wherein, the second network group is the network group to which the second network belongs;
[0328] In one embodiment, the second object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization.
[0329] The certificate and / or agreement type information includes at least one of the following: a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization.
[0330] In an optional embodiment of the present invention, where the first operation includes obtaining first request information and querying or accepting an order for first configuration information based on the first request information, the operation of querying or accepting an order for first configuration information based on the first request information includes at least one of the following:
[0331] The index information of the first configuration information queried or ordered contains the identification information of the first object, which matches the identification information of the second object in the first request information.
[0332] The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which the first object belongs, which matches the group identifier information of the second network group in the first request information.
[0333] The index information of the first configuration information queried or ordered contains slice information associated with the first object, which matches the slice information in the first request information;
[0334] The index information of the first configuration information queried or ordered contains the DN information associated with the first object, which matches the DN information in the first request information;
[0335] The index information of the first configuration information queried or ordered contains the identification information of network A, which matches the identification information of the second network in the first request information;
[0336] The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which network A belongs, which matches the identifier information of the second network in the first request information;
[0337] The index information of the first configuration information queried contains the identification information of the network to which the first server belongs, which matches the identification information of the second network in the first request information;
[0338] The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which the first server belongs, which matches the group identifier information of the second network group in the first request information.
[0339] The index information of the first configuration information queried includes the first access method, and the first request information includes indication information for indicating the first access method;
[0340] The index information of the first configuration information queried or ordered includes information for primary authentication and / or authorization, and the first request information includes information for primary authentication and / or authorization;
[0341] The index information of the first configuration information queried or ordered includes information for non-primary authentication and / or authorization, and the first request information includes information for non-primary authentication and / or authorization.
[0342] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0343] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0344] The step of sending the first configuration information and / or the associated information of the first configuration information includes: sending the first configuration information and / or the associated information of the first configuration information when the second condition is met.
[0345] The second condition includes at least one of the following:
[0346] Terminal registration or access to the first network;
[0347] The first configuration information and / or the associated information of the first configuration information are generated or updated.
[0348] Optionally, the operation of setting the priority of the first information to be higher than the priority of the data operation-related strategy information includes: if the third condition is met, setting the priority of the first information to be higher than the priority of the data operation-related strategy information;
[0349] The third condition includes at least one of the following:
[0350] The first information is the first information received.
[0351] The first information is not the first information configured locally.
[0352] In one embodiment, when the second communication device is a communication network element responsible for session management, the first information is received first information, including first information received from the communication network element responsible for mobility management.
[0353] In one embodiment, when the second communication device is a communication network element responsible for policy control, the first information is received information, including first information received from a communication network element responsible for session management or from a communication network element responsible for mobility management.
[0354] Optionally, the first target terminal includes at least one of the following: a communication network element responsible for session management, and a communication network element responsible for policy control.
[0355] In one embodiment, when the second communication device is a communication network element responsible for mobility management, the first target terminal includes a communication network element responsible for session management and / or a communication network element responsible for policy control.
[0356] In another embodiment, when the second communication device is a communication network element responsible for mobility management, the first target end includes a communication network element responsible for policy control.
[0357] Optionally, the step of sending the first information to the first target terminal and / or sending the first information through the terminal's data channel includes:
[0358] If the fourth condition is met, the first information is sent to the first target terminal and / or the first information is sent through the relevant signaling of the terminal's data channel;
[0359] The fourth condition includes at least one of the following:
[0360] The DN information of the terminal's data channel includes at least one of the following: DN information for the first access method, DN information associated with the first object, and DN information associated with the first configuration information;
[0361] The data channel slicing information of the terminal includes at least one of the following: slicing information for the first access method, slicing information associated with the first object, and slicing information associated with the first configuration information;
[0362] The DN information of the data channel of the terminal responsible for or associated with the first target end includes at least one of the following: DN information for the first access method, DN information associated with the first object, and DN information associated with the first configuration information.
[0363] The data channel slicing information of the terminal responsible for or associated with the first target end includes at least one of the following: slicing information for the first access method, slicing information associated with the first object, and slicing information associated with the first configuration information.
[0364] The terminal is the primary access method;
[0365] The first information is the first information received.
[0366] The first information is not the first information configured locally.
[0367] In one implementation, the communication network element (such as PCF) responsible for policy control sets data operation-related policy information (such as PCC rule) based on the first information.
[0368] In one implementation, the communication network element (such as SMF) responsible for session management performs at least one of the following actions based on the first information: setting data operation rules (such as N4 rules, such as PDR, FAR, etc.) and sending the first information to the terminal.
[0369] Optionally, the data operation rules and / or data operation-related policy information can be used to restrict data (such as data related to the first server and / or data related to DNS queries) or allow data (such as data related to the first server and / or data related to DNS queries) to pass through. Data related to the first server may include: data whose data source and / or data target is the first server.
[0370] Optionally, the data operations include at least one of the following: caching, discarding, passing, forwarding, and filtering.
[0371] In one implementation, the first target terminal and / or the terminal's data channel (such as a PDU session) can be selected based on the slice information associated with the first configuration information and / or the DN information associated with the first configuration information in the first information. It is easy to understand that in PNI SNPN or O-PLMN scenarios, the terminal is registering normally, not using the first access method. In this case, the terminal can have multiple data channels, each corresponding to multiple SMFs or multiple PCFs. Therefore, it is necessary to select the data channels and SMFs.
[0372] In one implementation, the terminal's data channel related signaling includes PDU Session related signaling (such as PDU Session Establishment) and session management related signaling (such as SM Policy Association Establishment).
[0373] It's easy to understand that, in the existing definition, the priority of the PCC rule is higher than the priority of the first information stored locally by the SMF, or higher than the priority of data operation rules set based on the locally stored first information. Since the first information obtained externally is the most recent, it should have a higher priority. If the PCF still uses the locally configured first information to set the PCC rule, and given that the existing PCC rule has a higher priority than the first information stored locally by the SMF, this will cause errors when the SMF sets data operation rules based on the PCC rule. Therefore, one solution is to send the latest first information to the PCF or set the priority of the received first information to be higher than the priority of the PCC rule.
[0374] In one implementation, the concepts of local storage and local configuration can be used interchangeably.
[0375] In this embodiment, querying or ordering of first configuration information is supported, enabling the first network to configure the first configuration information for the terminal. The first configuration information includes the address information of the first server, and the terminal can obtain a certificate and / or subscription from the first server through the first network. Furthermore, the associated information of the first configuration can also support filtering of the first configuration information, allowing the terminal to obtain the truly desired first configuration information.
[0376] See Figure 3 This application provides a method for supporting information acquisition, executed by a third communication device, which includes, but is not limited to, one of the following: a registration management network element (such as an AMF), a policy control network element (such as a PCF), a session management network element (such as a Session Management Function (SMF)), or a core network element; the specific steps include:
[0377] Step 301: Obtain second information, the second information including at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information;
[0378] Step 302: Based on the second information, perform the second operation;
[0379] The second operation includes at least one of the following:
[0380] (1) Select or query the target communication device based on the second information;
[0381] Optionally, the target communication device includes, but is not limited to, one of the following: PCF, UDM, UDR.
[0382] (2) Send a first request message to the target communication device;
[0383] (3) Send the second message;
[0384] The certificate and / or contract type information includes at least one of the following: a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization.
[0385] In one embodiment, the information of the target communication device conforming to one or more of the second information is configured on a third communication device. In another embodiment, the information of the target communication device is configured on a fourth communication device.
[0386] Optionally, sending the second information includes sending the second information to a session management network element (such as an SMF). In one embodiment, the second information can be sent when forwarding session management-related signaling sent by the terminal to the session management network element. In this case, the third communication device can be a registration management network element.
[0387] In an optional embodiment of the present invention, the step of querying the target communication device based on the second information includes:
[0388] Send network element query information to the fourth communication device, wherein the network element query information includes the second information;
[0389] Receive information about the target communication device sent by the fourth communication device.
[0390] Optionally, the fourth communication device is a Network Repository Function (NRF).
[0391] In an optional embodiment of the present invention, the first request information includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, identification information of the second network, group identification information of the second network group, slice information associated with the second object, DN information associated with the second object, slice information of the terminal, and DN information of the terminal.
[0392] In one embodiment, the second object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization.
[0393] In one embodiment, the segment information of the terminal includes at least one of the following: segment information requested by the terminal, segment information allowed by the terminal, segment information subscribed by the terminal, and segment information configured by the terminal.
[0394] In one embodiment, the slice information requested by the terminal includes at least one of the following: slice information requested when the terminal establishes a session; slice information requested when the terminal registers a network.
[0395] In one embodiment, the DN information of the terminal includes at least one of the following: DN information requested by the terminal, DN information allowed by the terminal, DN information of the terminal's subscription, and DN information configured by the terminal.
[0396] In one embodiment, the DN information requested by the terminal includes at least one of the following: DN information requested when the terminal establishes a session; DN information requested when the terminal registers with a network.
[0397] It's easy to understand that non-primary authentication (such as secondary authentication and segmented authentication) is associated with the terminal's segment and / or the terminal's DN information. When it's necessary to configure the location of the first server corresponding to the certificate download for non-primary authentication on the terminal, the terminal's segment information and / or the terminal's DN information can be used for association.
[0398] In one implementation, the terminal's slice information and / or DN information can be obtained from the terminal. For example, the terminal's slice information can be obtained from registration request information (including a registration request message). The registration request message may contain the slice information requested by the terminal. Alternatively, the terminal's slice information and / or DN information can be obtained from data channel establishment request information (including a data channel establishment request message).
[0399] In another implementation, the terminal's slice information and / or DN information can be obtained from the terminal's subscription data.
[0400] The data channel establishment request information (such as a PDU session) includes: the slice information requested by the terminal and the DN information requested by the terminal.
[0401] In one implementation, the terminal establishes a connection with the network via a connection establishment request message.
[0402] It's easy to understand that non-primary authentication (such as secondary authentication and segmented authentication) is associated with the terminal's segment and / or the terminal's DN information. When it's necessary to configure the location of the first server corresponding to the certificate download for non-primary authentication on the terminal, the terminal's segment information and / or the terminal's DN information can be used for association.
[0403] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0404] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0405] In this embodiment, the system supports obtaining second information sent by the terminal to determine first request information for the terminal, in order to query or order first configuration information, so that the first network can configure the first configuration information for the terminal. The first configuration information includes the address information of the first server, and the terminal can obtain a certificate and / or subscription from the first server through the first network. Simultaneously, the associated information of the first configuration can also support filtering of the first configuration information, so that the terminal can obtain the truly desired first configuration information.
[0406] See Figure 4 This application provides a method for supporting information acquisition, executed by a fourth communication device, which includes, but is not limited to, one of the following: NRF, core network element; the specific steps include:
[0407] Step 401: Obtain network element query information and / or communication device index information;
[0408] The network element query information includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information, and DN information.
[0409] Step 402: Perform the third operation based on the network element query information and / or the index information of the communication device;
[0410] The third operation includes at least one of the following:
[0411] (1) Match the target communication device based on the network element query information;
[0412] (2) Send information to the target communication device.
[0413] In one embodiment, the information of the target communication device is sent to the communication device that sends network element query information.
[0414] In an optional embodiment of the present invention, the index information of the target communication device matches the network element query information.
[0415] In an optional embodiment of the present invention, the index information of the target communication device matches the network element query information, including at least one of the following:
[0416] The index information of the target communication device includes: the indication information for indicating the first access method, and the network element query information includes the indication information for indicating the first access method;
[0417] The index information of the target communication device includes: the identification information of the second object, and the network element query information includes the identification information of the second object;
[0418] The index information of the target communication device includes: the group identifier information of the network group to which the second object belongs, and the network element query information includes the group identifier information of the network group to which the second object belongs;
[0419] The index information of the target communication device includes: information for master authentication and / or authorization; the network element query information includes information for master authentication and / or authorization.
[0420] The index information of the target communication device includes: information for non-master authentication and / or authorization; the network element query information includes information for non-master authentication and / or authorization.
[0421] The index information of the target communication device includes: the identification information of the second network, and the network element query information includes the identification information of the second network;
[0422] The index information of the target communication device includes: the group identifier information of the second network group, and the network element query information includes the group identifier information of the second network group;
[0423] The index information of the target communication device includes: slice information, and the network element query information includes the slice information;
[0424] The index information of the target communication device includes DN information, and the network element query information includes the DN information.
[0425] In an optional embodiment of the present invention, obtaining the index information of the communication device includes:
[0426] Obtain network element registration information;
[0427] Generate index information for communication devices based on network element registration information;
[0428] The network element registration information includes at least one of the following: indication information for indicating the first access method, certificate and / or contract type information, identification information of the third object, group identification information of the network group to which the third object belongs, identification information of the third network, and group identification information of the third network group.
[0429] The index information of the communication device includes one or more of the network element registration information.
[0430] Optionally, the third object refers to the network element or the communication device that sends the network element registration information serving the third object.
[0431] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0432] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0433] In this application embodiment, network element registration is supported for core network elements serving a third object and / or a first access method, so as to facilitate the selection of core network elements serving a third object and / or a first access method for the terminal.
[0434] See Figure 5 This application provides a method for supporting information acquisition, executed by a fifth communication device, which includes, but is not limited to, one of the following: a terminal; the specific steps include:
[0435] Step 501: Obtain the first configuration information and / or the associated information of the first configuration information.
[0436] Before the step of obtaining the first configuration information and / or the associated information of the first configuration information, the method further includes: sending second information, the second information including at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, identification information of the second network group, the second network group being the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information.
[0437] In one embodiment, the registration request information (including the registration request message) includes: the slice information requested by the terminal.
[0438] In one implementation, the data channel (e.g., PDU session) establishment request information (including data channel establishment request message) includes at least one of the following: slice information requested by the terminal, and DN information requested by the terminal.
[0439] In one implementation, the terminal establishes a connection with the network through connection establishment request information (such as connection establishment request message, service request message).
[0440] It's easy to understand that non-primary authentication (such as two-factor authentication and segmented authentication) is associated with the terminal's segment and / or DN information. When configuring a primary server for downloading non-primary authentication certificates for a terminal, the terminal's segment information and / or DN information can be used for association.
[0441] In one implementation, when the first configuration information includes the address information of multiple first servers, obtaining the first configuration information and its association information can help the terminal confirm which association information each first server is associated with. For example, first server A is associated with slice A, and second server B is associated with slice B.
[0442] In an optional embodiment of the present invention, the step of sending the second information includes:
[0443] If the first condition is met, send the second information;
[0444] The first condition includes at least one of the following:
[0445] (1) The terminal supports obtaining network subscriptions and / or certificates via the user plane;
[0446] (2) The terminal obtains the network subscription and / or certificate using the user plane method;
[0447] (3) The terminal needs to obtain a certificate and / or contract for master authentication and / or authorization;
[0448] (4) The terminal needs to obtain a certificate and / or contract for non-master authentication and / or authorization;
[0449] (5) The terminal needs to obtain a contract and / or certificate from a second network or a second object;
[0450] (6) The terminal does not have the address information of the first server corresponding to the second network or the second object.
[0451] In one embodiment, the second object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization.
[0452] Optionally, after obtaining the first configuration information and / or the association information of the first configuration information, the method further includes:
[0453] Based on the first configuration information and / or the associated information of the first configuration information, the terminal may perform at least one of the following:
[0454] Establish the first data channel;
[0455] Request a certificate and / or contract from the first server;
[0456] in,
[0457] The first data channel can be used for interaction between the terminal and the first server.
[0458] In one implementation, the certificate and / or agreement may be the certificate and / or agreement of the first object in the association information of the first configuration information.
[0459] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0460] and / or
[0461] The associated information of the first configuration information includes at least one of the following:
[0462] The identification information of the first object;
[0463] The group identifier information of the network group to which the first object belongs;
[0464] The slice information associated with the first object;
[0465] The DN information associated with the first object;
[0466] The identification information of the network to which the first server belongs;
[0467] The group identifier information of the network group to which the first server belongs;
[0468] The certificate and / or contract type information;
[0469] Indication information used to indicate the first access method;
[0470] The slice information associated with the first configuration information;
[0471] The first configuration information is associated with the DN information.
[0472] In one implementation, the second object is the same as the first object;
[0473] In another implementation, the second object is a subset of the first object;
[0474] In another implementation, the first object is a subset of the second object.
[0475] In this embodiment, the terminal can obtain first configuration information, including the address information of a first server. The terminal can obtain a certificate and / or subscription from the first server via a first network. Simultaneously, the terminal can also provide second information, enabling filtering of the first configuration information to ensure the terminal obtains the truly desired configuration information.
[0476] See Figure 6 This application provides a method for supporting information acquisition, executed by a sixth communication device, which includes, but is not limited to, one of the following: core network elements (such as UDR, UDM, PCF); the specific steps include:
[0477] Step 601: Send network element registration information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the third object, group identification information of the network group to which the third object belongs, identification information of the third network, and group identification information of the third network group.
[0478] In an optional embodiment of the present invention, the indication information for indicating the first access method indicates that the sixth communication device is a terminal used to access the network through the first access method or is used for the first access method.
[0479] And / or,
[0480] Certificate and / or contract type information indicates that the sixth communication device is used to provide at least one of the following: configuration information related to primary authentication and / or authorization, and configuration information related to non-primary authentication and / or authorization;
[0481] And / or,
[0482] The identification information of the third object indicates that the sixth communication device is used to serve the third object or to provide configuration information related to the third object;
[0483] And / or,
[0484] The group identifier information of the network group to which the third object belongs indicates that the sixth communication device is used to serve objects in the network group or to provide configuration information related to objects in the network group;
[0485] And / or,
[0486] The identification information of the third network indicates that the sixth communication device is used to serve the third network or to provide configuration information related to the third network;
[0487] And / or,
[0488] The group identifier information of the third network group indicates that the sixth communication device is used to serve the network in the network group or to provide network-related configuration information in the network group.
[0489] In this embodiment of the application, network element registration is supported for core network elements serving the first object and / or the first access method, so as to select core network elements serving the first object and / or the first access method for the terminal.
[0490] See Figure 7-A The specific steps are as follows:
[0491] Step 1: The UE sends a registration request to the AMF (optionally, including second information);
[0492] For a description of step 1, please refer to... Figure 5 The example shown.
[0493] Step 2: The AMF sends a policy association establishment request to the PCF (optionally, including second information);
[0494] Optionally, the PCF is a PCF that meets one or more of the second information. The AMF selects or queries the NRF based on the second information.
[0495] Step 3: PCF sends an information ordering request to UDR (optionally, including first request information);
[0496] Optionally, the UDR is a UDR that conforms to one or more of the second information. The AMF selects or queries the NRF for the UDR based on the second information.
[0497] For a description of steps 2 and 3, please refer to [link / reference]. Figure 3 The example shown.
[0498] Step 4: AF sends a service parameter configuration creation request / service parameter configuration modification request to NEF (optionally, including first information);
[0499] Step 5: NEF sends a service parameter configuration creation request / service parameter configuration modification request to UDR (optionally, including first information);
[0500] For a description of steps 4 and 5, please refer to [link / reference]. Figure 1 The example shown.
[0501] Step 6: The UDR sends a service parameter configuration creation response / service parameter configuration modification response (first information) to the AF via the NEF;
[0502] Step 7: UDR sends an information notification message (such as Nudr_DM_Notify) to PCF. The information notification message contains the first configuration information; the notification message may further contain the association information of the first configuration information.
[0503] For a description of steps 6 and 7, please refer to [link / reference]. Figure 2 The example shown.
[0504] Step 8: The PCF sends the UE Policy to the UE through the AMF (optionally, including first configuration information and / or associated information of the first configuration information).
[0505] For a description of step 8, please refer to [link / reference]. Figure 3 The example shown.
[0506] Step 9: Based on the first configuration information and / or the associated information of the first configuration information, the terminal may perform one of the following: establish a first data channel, or request a certificate and / or subscription from the first server. The first data channel can be used for interaction between the terminal and the first server. Step 9 can be referenced... Figure 5 As described in the examples.
[0507] It is understandable that there is no sequential relationship between steps 1 to 3 and steps 4 to 7; they can be parallel, or steps 4 to 7 can precede steps 1 to 3, or steps 1 to 3 can precede steps 4 to 5.
[0508] See Figure 7-B The specific steps are as follows:
[0509] Step 1: The UE sends a PDU session establishment request to the SMF through the AMF. The PDU session establishment request is included in the first message (such as the N1N2 transmission message) sent by the AMF to the SMF.
[0510] In one implementation, the PDU session request includes second information.
[0511] In another implementation, the first message contains second information. In this case, the AMF obtains the second information in the UE's registration request.
[0512] Step 2: The SMF sends a policy association establishment request to the AMF and then to the PCF (optionally, including second information);
[0513] Optionally, the PCF is a PCF that conforms to one or more of the second information. The AMF selects or queries the NRF based on the second information.
[0514] Step 3: The SMF sends an information subscription request to the UDR (optionally, including a first request message);
[0515] Optionally, the UDR is a UDR that conforms to one or more of the second information. The AMF selects or queries the NRF for the UDR based on the second information.
[0516] For a description of steps 1 to 3, please refer to [link / reference]. Figure 3 The example shown.
[0517] Steps 4 to 7 and Figure 7-A Steps 4 through 7 are the same, so they will not be repeated here.
[0518] Step 8: The SMF sends session management related signaling to the UE via the AMF (optionally, including first configuration information and / or associated information of the first configuration information). The first configuration information and / or associated information of the first configuration information can be sent via PCO information.
[0519] For a description of step 8, please refer to [link / reference]. Figure 3 The example shown.
[0520] Step 9: Based on the first configuration information, the terminal may perform one of the following: establish a first data channel, or request a certificate and / or subscription from the first server. The first data channel can be used for interaction between the terminal and the first server. Step 9 can be referenced... Figure 5 As described in the examples.
[0521] There is no sequential relationship between steps 1 to 3 and steps 4 to 7; they can be parallel, or steps 4 to 7 can precede steps 1 to 3, or steps 1 to 3 can precede steps 4 to 5.
[0522] See Figure 8 This application provides an apparatus for supporting information acquisition, applied to a first communication device. The apparatus 800 includes:
[0523] The first sending module 801 is used to send first information to the first network, the first information including: first configuration information and / or associated information of the first configuration information;
[0524] in,
[0525] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0526] The associated information of the first configuration information includes at least one of the following:
[0527] The identification information of the first object;
[0528] The group identifier information of the network group to which the first object belongs;
[0529] The slice information associated with the first object;
[0530] The DN information associated with the first object;
[0531] The identification information of the network to which the first server belongs;
[0532] The group identifier information of the network group to which the first server belongs;
[0533] The certificate and / or contract type information;
[0534] The slice information associated with the first configuration information;
[0535] The first configuration information is associated with the DN information;
[0536] Indication information used to indicate the first access method. In an optional embodiment of the present invention, the first object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization;
[0537] Wherein, network A may be the same as or different from the first network;
[0538] And / or,
[0539] The certificate and / or agreement type information includes at least one of the following: a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization;
[0540] And / or,
[0541] Indication information used to indicate the first access method indicates one of the following: the first configuration service information is used for terminals accessing the first network through the first access method, and the first server is able to configure the certificate and / or subscription of the first object for the terminals accessing the first network through the first access method;
[0542] And / or,
[0543] Terminals accessing the first network access the first network via a first access method;
[0544] And / or,
[0545] The first server includes at least one of the following: a first server for primary authentication and / or authorization configuration, and a first server for non-primary authentication and / or authorization configuration;
[0546] Wherein, the first server for primary authentication and / or authorization configuration is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for primary authentication and / or authorization;
[0547] The first server configured for non-master authentication and / or authorization is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for non-master authentication and / or authorization.
[0548] In an optional embodiment of the present invention, the network type of the first network, the network accessed by the terminal, and / or the network type of network A include at least one of the following: public network, non-public network, PLMN, PNI NPN, and stand-alone non-public network SNPN.
[0549] In an optional embodiment of the present invention, the address information of the first server includes at least one of the following: the Internet Protocol address of the first server, the Media Access Control address of the first server, the port number of the first server, the protocol version of the first server, and the index information of the address of the first server.
[0550] In an optional embodiment of the present invention, the index information of the first server address includes at least one of the following: the FQDN of the first server, and the URL of the first server.
[0551] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0552] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0553] The apparatus provided in this application embodiment can achieve... Figure 1 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0554] See Figure 9 This application provides an apparatus for supporting information acquisition, applied to a second communication device. The apparatus 900 includes:
[0555] The first acquisition module 901 is used to acquire first information, the first information including: first configuration information and / or associated information of the first configuration information;
[0556] The first execution module 902 is used to execute a first operation based on the first information;
[0557] The first operation includes at least one of the following:
[0558] Save the first information;
[0559] Generate index information (such as a data key) for the first configuration information, and the index information of the first configuration information is one or more of the associated information of the first configuration information;
[0560] Generate index information for the address information of the first server, wherein the index information for the address information of the first server is one or more of the associated information of the first server;
[0561] Obtain the first request information, and query or receive the first configuration information based on the first request information;
[0562] Send the first configuration information that has been queried or ordered and / or the associated information of the first configuration information;
[0563] Obtain the terminal's slice information and / or the terminal's DN information, and based on the terminal's slice information and / or the terminal's DN information, confirm the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0564] Send first configuration information and / or associated information of the first configuration information, wherein the first configuration information is the first configuration information associated with the terminal's slice information and / or the terminal's DN information;
[0565] Select the first target end and / or select the terminal's data channel;
[0566] Send the first information to the first target terminal and / or send the first information through relevant signaling of the terminal's data channel;
[0567] The priority of primary information is set higher than the priority of strategy information related to data operations;
[0568] in,
[0569] The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal;
[0570] The associated information of the first configuration information includes at least one of the following:
[0571] The identification information of the first object;
[0572] The group identifier information of the network group to which the first object belongs;
[0573] The slice information associated with the first object;
[0574] The DN information associated with the first object;
[0575] The identification information of the network to which the first server belongs;
[0576] The group identifier information of the network group to which the first server belongs;
[0577] The certificate and / or contract type information;
[0578] The slice information associated with the first configuration information;
[0579] The first configuration information is associated with the DN information;
[0580] Indication information used to indicate a first access method indicates one of the following: the first configuration service information is used for a terminal accessing the first network via the first access method, and the first server is capable of configuring the certificate and / or subscription of the first object for the terminal accessing the first network via the first access method. In an optional embodiment of the present invention, the first object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization;
[0581] Wherein, network A may be the same as or different from the first network;
[0582] And / or,
[0583] The certificate and / or agreement type information includes at least one of the following: a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization;
[0584] And / or,
[0585] Terminals accessing the first network access the first network through a first access method;
[0586] And / or,
[0587] The first server includes at least one of the following: a first server for primary authentication and / or authorization configuration, and a first server for non-primary authentication and / or authorization configuration;
[0588] Wherein, the first server for primary authentication and / or authorization configuration is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for primary authentication and / or authorization;
[0589] The first server configured for non-master authentication and / or authorization is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for non-master authentication and / or authorization.
[0590] In an optional embodiment of the present invention, the network type of the first network and / or the network type of network A includes at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
[0591] In an optional embodiment of the present invention, the address information of the first server includes at least one of the following: the Internet Protocol address of the first server, the Media Access Control address of the first server, the port number of the first server, the protocol type used for the certificate and / or subscription configuration, the protocol version of the first server, and the index information of the first server address.
[0592] In an optional embodiment of the present invention, the index information of the first server address includes at least one of the following: the FQDN of the first server, and the URL of the first server.
[0593] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0594] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0595] In an optional embodiment of the present invention, the first request information includes at least one of the following:
[0596] Indication information used to indicate the first access method;
[0597] Information on the type of certificate and / or contract;
[0598] The identification information of the second object;
[0599] The group identifier information of the network group to which the second object belongs;
[0600] The identification information of the second network;
[0601] Group identifier information for the second network group;
[0602] The second network group is the network group to which the second network belongs;
[0603] The slice information associated with the second object;
[0604] The DN information associated with the second object;
[0605] Terminal slice information;
[0606] The terminal's DN information.
[0607] The certificate and / or contract type information includes at least one of the following: a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization.
[0608] In one embodiment, the second object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization.
[0609] In an optional embodiment of the present invention, where the first operation includes obtaining first request information and querying first configuration information based on the first request information, the operation of querying or accepting an order for the first configuration information based on the first request information includes at least one of the following:
[0610] The index information of the first configuration information queried or ordered contains the identification information of the first object, which matches the identification information of the second object in the first request information.
[0611] The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which the first object belongs, which matches the group identifier information of the second network group in the first request information.
[0612] The index information of the first configuration information queried or ordered contains the identification information of network A, which matches the identification information of the second network in the first request information;
[0613] The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which network A belongs, which matches the identifier information of the second network in the first request information;
[0614] The index information of the first configuration information queried contains the identification information of the network to which the first server belongs, which matches the identification information of the second network in the first request information;
[0615] The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which the first server belongs, which matches the group identifier information of the second network group in the first request information.
[0616] The index information of the first configuration information queried includes the first access method, and the first request information includes indication information for indicating the first access method;
[0617] The index information of the first configuration information queried or ordered includes information for primary authentication and / or authorization, and the first request information includes information for primary authentication and / or authorization;
[0618] The index information of the first configuration information queried or ordered includes information for non-primary authentication and / or authorization, and the first request information includes information for non-primary authentication and / or authorization.
[0619] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0620] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0621] The step of sending the first configuration information and / or the associated information of the first configuration information includes: sending the first configuration information and / or the associated information of the first configuration information when the second condition is met.
[0622] The second condition includes at least one of the following:
[0623] Terminal registration or access to the first network;
[0624] The first configuration information and / or the associated information of the first configuration information are generated or updated.
[0625] Optionally, the operation of setting the priority of the first information to be higher than the priority of the data operation-related strategy information includes: if the third condition is met, setting the priority of the first information to be higher than the priority of the data operation-related strategy information;
[0626] The third condition includes at least one of the following:
[0627] The first information is the first information received.
[0628] The first information is not the first information configured locally.
[0629] In one embodiment, when the second communication device is a communication network element responsible for session management, the first information is received first information, including first information received from the communication network element responsible for mobility management.
[0630] In one embodiment, when the second communication device is a communication network element responsible for policy control, the first information is received information, including first information received from a communication network element responsible for session management or from a communication network element responsible for mobility management.
[0631] Optionally, the first target terminal includes at least one of the following: a communication network element responsible for session management, and a communication network element responsible for policy control.
[0632] In one embodiment, when the second communication device is a communication network element responsible for mobility management, the first target terminal includes a communication network element responsible for session management and / or a communication network element responsible for policy control.
[0633] In another embodiment, when the second communication device is a communication network element responsible for mobility management, the first target end includes a communication network element responsible for policy control.
[0634] Optionally, the step of sending the first information to the first target terminal and / or sending the first information through the terminal's data channel includes:
[0635] If the fourth condition is met, the first information is sent to the first target terminal and / or the first information is sent through the relevant signaling of the terminal's data channel;
[0636] The fourth condition includes at least one of the following:
[0637] The DN information of the terminal's data channel includes at least one of the following: DN information for the first access method, DN information associated with the first object, and DN information associated with the first configuration information;
[0638] The data channel slicing information of the terminal includes at least one of the following: slicing information for the first access method, slicing information associated with the first object, and slicing information associated with the first configuration information;
[0639] The DN information of the data channel of the terminal responsible for or associated with the first target end includes at least one of the following: DN information for the first access method, DN information associated with the first object, and DN information associated with the first configuration information.
[0640] The data channel slicing information of the terminal responsible for or associated with the first target end includes at least one of the following: slicing information for the first access method, slicing information associated with the first object, and slicing information associated with the first configuration information.
[0641] The terminal is the primary access method;
[0642] The first information is the first information received.
[0643] The first information is not the first information configured locally.
[0644] In one implementation, the communication network element (such as PCF) responsible for policy control sets data operation-related policy information (such as PCC rule) based on the first information.
[0645] In one implementation, the communication network element (such as SMF) responsible for session management performs at least one of the following actions based on the first information: setting data operation rules (such as N4 rules, such as PDR, FAR, etc.) and sending the first information to the terminal.
[0646] Optionally, the data operation rules and / or data operation-related policy information can be used to restrict data (such as data related to the first server and / or data related to DNS queries) or allow data (such as data related to the first server and / or data related to DNS queries) to pass through. Data related to the first server may include: data whose data source and / or data target is the first server.
[0647] Optionally, the data operations include at least one of the following: caching, discarding, passing, forwarding, and filtering.
[0648] In one implementation, the first target terminal and / or the terminal's data channel (such as a PDU session) can be selected based on the slice information associated with the first configuration information and / or the DN information associated with the first configuration information in the first information. It is easy to understand that in PNI SNPN or O-PLMN scenarios, the terminal is registering normally, not using the first access method. In this case, the terminal can have multiple data channels, each corresponding to multiple SMFs or multiple PCFs. Therefore, it is necessary to select the data channels and SMFs.
[0649] In one implementation, the terminal's data channel related signaling includes PDU Session related signaling (such as PDU Session Establishment) and session management related signaling (such as SM Policy Association Establishment).
[0650] It's easy to understand that, in the existing definition, the priority of the PCC rule is higher than the priority of the first information stored locally by the SMF, or higher than the priority of data operation rules set based on the locally stored first information. Since the first information obtained externally is the most recent, it should have a higher priority. If the PCF still uses the locally configured first information to set the PCC rule, and given that the existing PCC rule has a higher priority than the first information stored locally by the SMF, this will cause errors when the SMF sets data operation rules based on the PCC rule. Therefore, one solution is to send the latest first information to the PCF or set the priority of the received first information to be higher than the priority of the PCC rule.
[0651] In one implementation, the concepts of local storage and local configuration can be used interchangeably.
[0652] The apparatus provided in this application embodiment can achieve... Figure 2 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0653] See Figure 10 This application provides an apparatus for supporting information acquisition, applied to a third communication device, comprising:
[0654] The second acquisition module 1001 is used to acquire second information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information;
[0655] The second execution module 1002 is used to execute the second operation based on the second information;
[0656] The second operation includes at least one of the following:
[0657] Select or query the target communication device based on the second information;
[0658] Send the first request information to the target communication device;
[0659] Send the second information (e.g., send the second information to the session management network element);
[0660] The certificate and / or contract type information includes at least one of the following: a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization.
[0661] In an optional embodiment of the present invention, the second execution module 1002 is further configured to:
[0662] Send network element query information to the fourth communication device, wherein the network element query information includes the second information;
[0663] Receive information about the target communication device sent by the fourth communication device.
[0664] In an optional embodiment of the present invention, the first request information includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, identification information of the second network, group identification information of the second network group, slice information associated with the second object, DN information associated with the second object, slice information of the terminal, and DN information of the terminal.
[0665] In one embodiment, the second object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object associated with primary authentication and / or authorization, and an object associated with non-primary authentication and / or authorization.
[0666] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0667] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0668] The apparatus provided in this application embodiment can achieve... Figure 3 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0669] See Figure 11 This application provides an apparatus for supporting information acquisition, applied to a fourth communication device. The apparatus 1100 includes:
[0670] The third acquisition module 1101 is used to acquire network element query information and / or communication device index information;
[0671] The network element query information includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, identification information of the second network, group identification information of the second network group, the second network group being the network group to which the second network belongs, slice information, and DN information.
[0672] The third execution module 1102 is used to perform a third operation based on the network element query information and / or the index information of the communication device;
[0673] The third operation includes at least one of the following:
[0674] Match the target communication device based on the network element query information;
[0675] Send information to the target communication device.
[0676] In an optional embodiment of the present invention, the index information of the target communication device matches the network element query information.
[0677] In an optional embodiment of the present invention, the index information of the target communication device matches the network element query information, including at least one of the following:
[0678] The index information of the target communication device includes: the indication information for indicating the first access method, and the network element query information includes the indication information for indicating the first access method;
[0679] The index information of the target communication device includes: the identification information of the second object, and the network element query information includes the identification information of the second object;
[0680] The index information of the target communication device includes: the group identifier information of the network group to which the second object belongs, and the network element query information includes the group identifier information of the network group to which the second object belongs;
[0681] The index information of the target communication device includes: information for master authentication and / or authorization; the network element query information includes information for master authentication and / or authorization.
[0682] The index information of the target communication device includes: information for non-master authentication and / or authorization; the network element query information includes information for non-master authentication and / or authorization.
[0683] The index information of the target communication device includes: the identification information of the second network, and the network element query information includes the identification information of the second network;
[0684] The index information of the target communication device includes: the group identifier information of the second network group, and the network element query information includes the group identifier information of the second network group;
[0685] The index information of the target communication device includes: slice information, and the network element query information includes the slice information;
[0686] The index information of the target communication device includes DN information, and the network element query information includes the DN information.
[0687] In an optional embodiment of the present invention, obtaining the index information of the communication device includes:
[0688] Obtain network element registration information;
[0689] Generate index information for communication devices based on network element registration information;
[0690] The network element registration information includes at least one of the following: indication information for indicating the first access method, certificate and / or contract type information, identification information of the third object, group identification information of the network group to which the third object belongs, identification information of the third network, and group identification information of the third network group.
[0691] The index information of the communication device includes one or more of the network element registration information.
[0692] Optionally, the third object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, and non-primary authentication and / or authorization.
[0693] In an optional embodiment of the present invention, the first access method includes at least one of the following:
[0694] Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
[0695] The apparatus provided in this application embodiment can achieve... Figure 4 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0696] See Figure 12 This application provides an apparatus for supporting information acquisition, applied to a fifth communication device. The fifth communication device 1200 includes:
[0697] The fourth acquisition module 1201 is used to acquire the first configuration information and / or the associated information of the first configuration information.
[0698] In an optional embodiment of the present invention, before the step of obtaining the first configuration information and / or the associated information of the first configuration information, the fifth communication device 1200 further includes:
[0699] The second sending module 1202 is used to send second information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, identification information of the second network group, wherein the second network group is the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information.
[0700] In an optional embodiment of the present invention, the second sending module 1202 is further configured to:
[0701] If the first condition is met, send the second information;
[0702] The first condition includes at least one of the following:
[0703] The terminal supports obtaining network subscriptions and / or certificates via the user plane.
[0704] The terminal obtains network subscription and / or certificate via the user plane.
[0705] The terminal needs to obtain a certificate and / or contract for master authentication and / or authorization;
[0706] The terminal needs to obtain a certificate and / or contract for non-master authentication and / or authorization;
[0707] The terminal needs to obtain a contract and / or certificate from a second network or a second object;
[0708] The terminal does not have the address information of the first server corresponding to the second network or the second object.
[0709] In an optional embodiment of the present invention, after the step of obtaining the first configuration information and / or the associated information of the first configuration information, the fifth communication device 1200 further includes:
[0710] The fourth execution module is configured to, based on the first configuration information and / or the associated information of the first configuration information, have the terminal execute at least one of the following:
[0711] Establish the first data channel;
[0712] Request a certificate and / or contract from the first server;
[0713] in,
[0714] The first data channel is used for interaction between the terminal and the first server.
[0715] In one implementation, the certificate and / or agreement is the certificate and / or agreement of a first object in the association information of the first configuration information.
[0716] The apparatus provided in this application embodiment can achieve... Figure 5 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0717] See Figure 13 This application provides an apparatus for supporting information acquisition, applied to a sixth communication device. The apparatus 1300 includes:
[0718] The third sending module 1301 is used to send network element registration information, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the third object, group identification information of the network group to which the third object belongs, identification information of the third network, and group identification information of the third network group.
[0719] The third object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.
[0720] In an optional embodiment of the present invention, the indication information for indicating the first access method indicates that the sixth communication device is a terminal used to access the network through the first access method or is used for the first access method.
[0721] And / or,
[0722] The certificate and / or contract type information indicates that the sixth communication device is used to provide at least one of the following: configuration information related to primary authentication and / or authorization, and configuration information related to non-primary authentication and / or authorization;
[0723] And / or,
[0724] The identification information of the third object indicates that the sixth communication device is used to serve the third object or to provide configuration information related to the third object;
[0725] And / or,
[0726] The group identifier information of the network group to which the third object belongs indicates that the sixth communication device is used to serve objects in the network group or to provide configuration information related to objects in the network group;
[0727] And / or,
[0728] The identification information of the third network indicates that the sixth communication device is used to serve the third network or to provide configuration information related to the third network;
[0729] And / or,
[0730] The group identifier information of the third network group indicates that the sixth communication device is used to serve the network in the network group or to provide network-related configuration information in the network group.
[0731] The apparatus provided in this application embodiment can achieve... Figure 6 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0732] Figure 14 To realize the hardware structure diagram of a terminal according to an embodiment of this application, the terminal 1400 includes, but is not limited to, the following components: radio frequency unit 1401, network module 1402, audio output unit 1403, input unit 1404, sensor 1405, display unit 1406, user input unit 1407, interface unit 1408, memory 1409, and processor 1410.
[0733] Those skilled in the art will understand that the terminal 1400 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 1410 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 14 The terminal structure shown does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0734] It should be understood that, in this embodiment, the input unit 1404 may include a graphics processing unit (GPU) 14041 and a microphone 14042. The GPU 14041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1406 may include a display panel 14061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1407 includes a touch panel 14071 and other input devices 14072. The touch panel 14071 is also called a touch screen. The touch panel 14071 may include a touch detection device and a touch controller. Other input devices 14072 may include, but are not limited to, a physical keyboard, function keys (such as volume control buttons, power buttons, etc.), a trackball, a mouse, and a joystick, which will not be described in detail here.
[0735] In this embodiment, the radio frequency unit 1401 receives downlink data from the network-side device and processes it for the processor 1410; additionally, it sends uplink data to the network-side device. Typically, the radio frequency unit 1401 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc.
[0736] The memory 1409 can be used to store software programs or instructions and various data. The memory 1409 may primarily include a program or instruction storage area and a data storage area. The program or instruction storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1409 may include high-speed random access memory and non-volatile memory, which may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. For example, at least one disk storage device, flash memory device, or other non-volatile solid-state storage device.
[0737] Processor 1410 may include one or more processing units; optionally, processor 1410 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications or instructions, and the modem processor mainly handles wireless communication, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 1410.
[0738] The terminal provided in this application embodiment can achieve... Figure 5 The various processes implemented in the method embodiments shown achieve the same technical effects, and will not be described again here to avoid repetition.
[0739] This application also provides a network-side device. For example... Figure 15 As shown, the network-side device 1500 includes: an antenna 1501, a radio frequency (RF) device 1502, and a baseband device 1503. The antenna 1501 is connected to the RF device 1502. In the uplink direction, the RF device 1502 receives information through the antenna 1501 and transmits the received information to the baseband device 1503 for processing. In the downlink direction, the baseband device 1503 processes the information to be transmitted and sends it to the RF device 1502. The RF device 1502 processes the received information and transmits it through the antenna 1501.
[0740] The aforementioned frequency band processing device can be located in the baseband device 1503. The method executed by the network-side device in the above embodiments can be implemented in the baseband device 1503, which includes a processor 1504 and a memory 1505.
[0741] The baseband device 1503 may, for example, include at least one baseband board on which multiple chips are disposed, such as... Figure 15 As shown, one of the chips, for example, is a processor 1504, which is connected to a memory 1505 to call the program in the memory 1505 and execute the network device operation shown in the above method embodiment.
[0742] The baseband device 1503 may also include a network interface 1506 for exchanging information with the radio frequency device 1502, such as a common public radio interface (CPRI).
[0743] Specifically, the network-side device in this application embodiment further includes: instructions or programs stored in memory 1505 and executable on processor 1504, wherein processor 1504 calls the instructions or programs in memory 1505 to execute. Figures 10-13 The methods executed by each module shown achieve the same technical effect, and to avoid repetition, they will not be described in detail here.
[0744] This application also provides a program product, which is stored in a non-volatile storage medium and executed by at least one processor to implement the following: Figures 1-4 and Figure 6 The steps of the processing method described above.
[0745] This application embodiment also provides a readable storage medium storing a program or instructions that, when executed by a processor, implement the above-described functionality. Figures 1-6 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0746] The processor mentioned above is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0747] This application embodiment also provides a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run network-side device programs or instructions to achieve the above-mentioned... Figures 1-6 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0748] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0749] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0750] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0751] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A method for supporting information acquisition, characterized in that, Performed by a second communication device, including: Obtain first information, which includes: first configuration information associated with slice information and / or DN information; Based on the first information, perform the first operation; The first operation includes at least one of the following: Obtain the terminal's slice information and / or the terminal's DN information, and based on the terminal's slice information and / or the terminal's DN information, confirm the first configuration information associated with the terminal's slice information and / or the terminal's DN information; Send first configuration information to the terminal, wherein the first configuration information is the first configuration information associated with the terminal's slice information and / or the terminal's DN information; in, The first configuration information includes: the address information of the first server, and the first server is capable of configuring the certificate and / or contract of the first object for the terminal.
2. The method according to claim 1, characterized in that, in, The first information also includes the association information of the first configuration information; The associated information of the first configuration information includes at least one of the following: The slice information associated with the first configuration information; The first configuration information is associated with the DN information; The slice information associated with the first object; The DN information associated with the first object; The identification information of the first object; The group identifier information of the network group to which the first object belongs; The identification information of the network to which the first server belongs; The group identifier information of the network group to which the first server belongs; The certificate and / or contract type information; The indication information used to indicate the first access method indicates one of the following: the first configuration information is used for a terminal to access the first network through the first access method, and the first server is able to configure the certificate and / or subscription of the first object for the terminal to access the first network through the first access method.
3. The method according to claim 1, characterized in that, in, The first operation further includes at least one of the following: Save the first information; Generate index information for the first configuration information, where the index information is one or more of the associated information of the first configuration information; Generate index information for the address information of the first server, wherein the index information for the address information of the first server is one or more of the associated information of the first server; Send the first configuration information that has been queried or ordered and / or the associated information of the first configuration information; Select the first target end and / or select the terminal's data channel; Send the first information to the first target terminal and / or send the first information through relevant signaling of the terminal's data channel; The priority of primary information is set higher than the priority of strategy information related to data operations; Send the associated information of the first configuration information to the terminal.
4. The method according to any one of claims 1-3, characterized in that, The second communication device includes a Session Management Function (SMF).
5. The method according to claim 1, characterized in that, The first object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, objects associated with primary authentication and / or authorization, and objects associated with non-primary authentication and / or authorization; Wherein, network A may be the same as or different from the first network; And / or, The certificate and / or agreement type information includes at least one of the following: a certificate and / or agreement for primary authentication and / or authorization, and a certificate and / or agreement for non-primary authentication and / or authorization; And / or, Terminals accessing the first network access the first network via a first access method; And / or, The first server includes at least one of the following: a first server for primary authentication and / or authorization configuration, and a first server for non-primary authentication and / or authorization configuration; Wherein, the first server for primary authentication and / or authorization configuration is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for primary authentication and / or authorization; The first server configured for non-master authentication and / or authorization is capable of configuring a certificate and / or agreement for a first object for a terminal, and the certificate and / or agreement is used for non-master authentication and / or authorization.
6. The method according to claim 5, characterized in that, The network type of the first network, and / or the network type of the A network, includes at least one of the following: public network, non-public network, PLMN, PNI NPN, SNPN.
7. The method according to claim 1, characterized in that, The address information of the first server includes at least one of the following: the Internet Protocol address of the first server, the Media Access Control address of the first server, the port number of the first server, the protocol type used for the certificate and / or subscription configuration, the protocol version of the first server, and the index information of the address of the first server.
8. The method according to claim 7, characterized in that, The index information of the first server address includes at least one of the following: the FQDN of the first server, and the URL of the first server.
9. The method according to claim 2, characterized in that, The first access method includes at least one of the following: Access methods for obtaining certificates and / or contracts to access the network include restricted access networks and access methods using default certificates.
10. The method according to claim 1, characterized in that, The first operation further includes: obtaining first request information, and querying or accepting an order for first configuration information based on the first request information, wherein the first request information includes at least one of the following: Information on the type of certificate and / or contract; The identification information of the second object; The group identifier information of the network group to which the second object belongs; The identification information of the second network; Group identifier information for the second network group; The second network group is the network group to which the second network belongs; The slice information associated with the second object; The DN information associated with the second object; Terminal slice information; DN information of the terminal; The certificate and / or contract type information includes at least one of the following: a certificate and / or contract for primary authentication and / or authorization, and a certificate and / or contract for non-primary authentication and / or authorization; The second object includes at least one of the following: A network, an entity in a data network, an entity outside the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, objects associated with primary authentication and / or authorization, and objects associated with non-primary authentication and / or authorization.
11. The method according to claim 1, characterized in that, The first operation further includes obtaining first request information, and querying or accepting the order for first configuration information based on the first request information. In this case, the operation of querying or accepting the order for first configuration information based on the first request information includes at least one of the following: The index information of the first configuration information queried or ordered contains the identification information of the first object, which matches the identification information of the second object in the first request information. The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which the first object belongs, which matches the group identifier information of the second network group in the first request information. The index information of the first configuration information queried or ordered contains the identification information of network A, which matches the identification information of the second network in the first request information; The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which network A belongs, which matches the identifier information of the second network in the first request information; The index information of the first configuration information queried contains the identification information of the network to which the first server belongs, which matches the identification information of the second network in the first request information; The index information of the first configuration information queried or ordered contains the group identifier information of the network group to which the first server belongs, which matches the group identifier information of the second network group in the first request information. The index information of the first configuration information queried includes the first access method, and the first request information includes indication information for indicating the first access method; The index information of the first configuration information queried or ordered includes information for primary authentication and / or authorization, and the first request information includes information for primary authentication and / or authorization; The index information of the first configuration information queried or ordered includes information for non-primary authentication and / or authorization, and the first request information includes information for non-primary authentication and / or authorization.
12. The method according to claim 1, characterized in that, The step of sending the first configuration information and / or the associated information of the first configuration information includes: sending the first configuration information and / or the associated information of the first configuration information when the second condition is met; The second condition includes at least one of the following: Terminal registration or access to the first network; The first configuration information and / or the associated information of the first configuration information are generated or updated.
13. The method according to claim 3, characterized in that, The operation of setting the priority of the first information to be higher than the priority of the data operation-related strategy information includes: when the third condition is met, setting the priority of the first information to be higher than the priority of the data operation-related strategy information. The third condition includes at least one of the following: The first information is the first information received. The first information is not the first information configured locally.
14. The method according to claim 3, characterized in that, The first target terminal includes at least one of the following: a communication network element responsible for session management, and a communication network element responsible for policy control.
15. The method according to claim 14, characterized in that, When the second communication device is a communication network element responsible for mobility management, the first target end includes a communication network element responsible for session management and / or a communication network element responsible for policy control. and / or In the case where the second communication device is a communication network element responsible for mobility management, the first target end includes a communication network element responsible for policy control.
16. The method according to claim 14, characterized in that, The steps of sending the first information to the first target terminal and / or sending the first information through the terminal's data channel include: If the fourth condition is met, the first information is sent to the first target terminal and / or the first information is sent through the relevant signaling of the terminal's data channel; The fourth condition includes at least one of the following: The DN information of the terminal's data channel includes at least one of the following: DN information for the first access method, DN information associated with the first object, and DN information associated with the first configuration information; The data channel slicing information of the terminal includes at least one of the following: slicing information for the first access method, slicing information associated with the first object, and slicing information associated with the first configuration information; The DN information of the data channel of the terminal responsible for or associated with the first target end includes at least one of the following: DN information for the first access method, DN information associated with the first object, and DN information associated with the first configuration information. The data channel slicing information of the terminal responsible for or associated with the first target end includes at least one of the following: slicing information for the first access method, slicing information associated with the first object, and slicing information associated with the first configuration information. The terminal is the primary access method; The first information is the first information received. The first information is not the first information configured locally.
17. The method according to claim 1, characterized in that, The acquisition of the first information includes either locally configuring the first information or receiving the first information.
18. A method for supporting information acquisition, characterized in that, Performed by the fifth communication device, including: Receive first configuration information associated with slice information and / or DN information from the terminal of the second communication device; The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal; The fifth communication device includes a terminal; After receiving the first configuration information from the second communication device, the method further includes: Based on the first configuration information, the fifth communication device performs at least one of the following: Establish the first data channel; Request a certificate and / or contract from the first server; in, The first data channel is used for interaction between the terminal and the first server.
19. The method according to claim 18, characterized in that, The method further includes: Obtain the association information of the first configuration information; The associated information of the first configuration information includes at least one of the following: The slice information associated with the first configuration information; The first configuration information is associated with the DN information. The slice information associated with the first object; The DN information associated with the first object.
20. The method according to claim 18, characterized in that, Prior to the step of receiving first configuration information from the second communication device, the method further includes: Send a second message, which includes at least one of the following: indication information for indicating the first access method, certificate and / or subscription type information, identification information of the second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of the second network, identification information of the second network group (where the second network group is the network group to which the second network belongs), slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, or data channel establishment request information.
21. The method according to claim 20, characterized in that, The step of sending the second information includes: If the first condition is met, send the second information; The first condition includes at least one of the following: The terminal supports obtaining network subscriptions and / or certificates via the user plane. The terminal obtains network subscription and / or certificate via the user plane. The terminal needs to obtain a certificate and / or contract for master authentication and / or authorization; The terminal needs to obtain a certificate and / or contract for non-master authentication and / or authorization; The terminal needs to obtain a contract and / or certificate from a second network or a second object; The terminal does not have the address information of the first server corresponding to the second network or the second object.
22. The method according to claim 20, characterized in that, The data channel establishment request information includes at least one of the following: the slice information requested by the terminal, and the DN information requested by the terminal.
23. The method according to claim 19, characterized in that, The associated information of the first configuration information also includes at least one of the following: The identification information of the first object; The group identifier information of the network group to which the first object belongs; The identification information of the network to which the first server belongs; The group identifier information of the network group to which the first server belongs; The certificate and / or contract type information; Indication information used to indicate the first access method.
24. An apparatus for supporting information acquisition, characterized in that, Applied to a second communication device, including: The first acquisition module is used to acquire first information, the first information including: first configuration information associated with slice information and / or DN information; The first execution module is used to perform a first operation based on the first information; The first operation includes at least one of the following: Obtain the terminal's slice information and / or the terminal's DN information, and based on the terminal's slice information and / or the terminal's DN information, confirm the first configuration information associated with the terminal's slice information and / or the terminal's DN information; Send first configuration information to the terminal, wherein the first configuration information is the first configuration information associated with the terminal's slice information and / or the terminal's DN information; in, The first configuration information includes: the address information of the first server, and the first server is capable of configuring the certificate and / or contract of the first object for the terminal.
25. An apparatus for supporting information acquisition, characterized in that, Applied to fifth communication devices, including: The fourth acquisition module is used to receive the first configuration information associated with the slice information and / or DN information of the terminal from the second communication device. The first configuration information includes: the address information of the first server, which is capable of configuring the certificate and / or contract of the first object for the terminal; The fifth communication device includes a terminal; The fourth execution module is configured to, based on the first configuration information, have the fifth communication device perform at least one of the following: Establish the first data channel; Request a certificate and / or contract from the first server; in, The first data channel is used for interaction between the terminal and the first server.
26. The apparatus according to claim 25, characterized in that, The device further includes: a second sending module, used to send second information, the second information including at least one of the following: indication information for indicating a first access method, certificate and / or subscription type information, identification information of a second object, group identification information of the network group to which the second object belongs, slice information associated with the second object, DN information associated with the second object, identification information of a second network, identification information of a second network group, the second network group being the network group to which the second network belongs, slice information of a terminal, DN information of a terminal, connection establishment request information, registration request information, and data channel establishment request information.
27. A terminal, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the method for obtaining supporting information as claimed in any one of claims 18 to 23.
28. A network-side device, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the method as claimed in any one of claims 1 to 17.
29. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 23.