Methods, communication devices, media, and chips for online signing

By coordinating the control of core network equipment and access network equipment, terminal equipment is restricted from accessing cells that support online subscription. This solves the problems of increased load and security caused by cell selection and reselection mechanisms in 5G NR systems, and achieves improved load balancing and network security.

CN115348582BActive Publication Date: 2026-04-03HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-14
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In 5G NR communication systems, when terminal devices access the target network, existing technologies struggle to effectively control cell selection and reselection mechanisms, leading to increased load on ordinary cells and impacting network security. This is especially true in standalone non-public networks (SNPN) and public network integrated non-public networks (PNI-NPN), where terminal devices may increase the load on intermediate networks and affect traditional services when obtaining subscription information or credentials.

Method used

Core network equipment and access network equipment control the access process of terminal equipment by receiving cell capability information and online subscription capability instructions, restricting it to access only in cells that support online subscription. Core network equipment controls access by sending rejection or redirection instructions, and terminal equipment selects appropriate cells for access and handover based on online subscription capabilities.

Benefits of technology

It effectively reduces cell load, improves network performance and security, and ensures that terminal devices obtain signing or credential information only through networks that support online signing during the access process, thus avoiding changes to the existing cell selection mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115348582B_ABST
    Figure CN115348582B_ABST
Patent Text Reader

Abstract

This disclosure provides embodiments of a method, communication apparatus, medium, and chip for online subscription. In these embodiments, a core network device receives a first message from an access network device. The first message includes a cell identifier of a first cell of the access network device to which the terminal device intends to access. The core network device determines, based on the cell identifier of the first cell, that the first cell does not support online subscription. The core network device controls the terminal device's access to the first cell. By considering the cell's online subscription capability, restrictions on cell access can be implemented on the core network side without changing the cell selection mechanism on the terminal device side. In this way, the load on ordinary cells can be effectively reduced, and network performance and security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communications, and more specifically, to methods, communication devices, media, and chips for online boarding of terminal devices. Background Technology

[0002] In 5G New Radio (NR) communication systems, two types of non-public networks (NPNs) are defined: Standalone NPNs (SNPNs) and Public Network Integrated-NPNs (PNI-NPNs). SNPNs have independent Radio Access Networks (RANs) and core networks (5G Cores, 5GCs) and can operate without relying on the network functions of public networks such as Public Land Mobile Networks (PLMNs). PNI-NPNs, on the other hand, can partially rely on the network functions of public networks. PNI-NPNs can be further divided into Closed Access Groups (CAGs) and network slicing. CAGs provide services tailored to specific services or users, while Slicing utilizes the slicing features defined by 5G to provide services to specific services or users using dedicated slices.

[0003] An NPN can act as the target network for a terminal device to access, or as an intermediate network to assist the terminal device in accessing the target network. For example, a terminal device (e.g., a UE) may not have credentials for accessing the target network. In this case, the terminal device can temporarily establish a connection with the intermediate network to obtain subscription information or credentials for accessing the target network. Then, the terminal device can deregister from the intermediate network and register with the target network using the subscription information or credentials to complete access to the target network. The current process for obtaining subscription information or credentials should meet the following requirements: (1) the intermediate network provides instructions on whether online subscription is supported; and (2) providing online subscription services to the terminal device does not affect the intermediate network's own traditional services and network security. To meet the above requirements, it is necessary to further improve the cell selection and / or cell reselection mechanism of the terminal device. Summary of the Invention

[0004] The exemplary embodiments disclosed herein provide a scheme for controlling terminal equipment to access a cell in a communication system.

[0005] In a first aspect of this disclosure, a method for communication is provided. In this method, a core network device receives a first message from an access network device. The first message includes a cell identifier of a first cell of the access network device to which a terminal device intends to access. The core network device determines, based on the cell identifier of the first cell, that the first cell does not support online subscription. The core network device controls the terminal device's access to the first cell. In this manner, the core network device can control the terminal device's access to a cell based on whether the cell of the access network device supports online subscription, thereby effectively reducing the load on ordinary cells and improving network performance and security.

[0006] In some embodiments, the method further includes the core network device receiving cell capability information from the access network device. The cell capability information includes a cell identifier and corresponding online subscription capability for at least one cell of the access network device, and the at least one cell includes a first cell. The core network device determines, based on the cell capability information and the cell identifier of the first cell, that the first cell does not support online subscription.

[0007] In some embodiments, the method further includes the core network device receiving an update message from the access network device. The update message indicates an update to cell capability information. Thus, the core network device can control terminal device access to a cell based on dynamic changes in the cell capabilities of the access network device.

[0008] In some embodiments, the first message also indicates the online subscription capability of the first cell. The method further includes the core network device determining, based on the cell identifier of the first cell and the online subscription capability of the first cell, that the first cell does not support online subscription.

[0009] In some embodiments, controlling access to the first cell includes: the core network equipment restricting terminal equipment from accessing the first cell.

[0010] In some embodiments, the core network device restricting a terminal device's access to the first cell includes: the core network device sending a second message to the terminal device. The second message includes at least one of a denial indication, a denial reason value, or a redirection indication.

[0011] In some embodiments, the determination to restrict a terminal device's access to the first cell is based on at least one of the following: the first message includes an online subscription instruction; the credential server fails to authorize the terminal device; or there is no user plane context for the terminal device.

[0012] In some embodiments, the method further includes the core network device determining that the terminal device's access to the first cell is in a remote configuration phase. Controlling access to the first cell includes the core network device determining that it does not restrict the terminal device's access to the first cell.

[0013] In some embodiments, the method further includes the core network device determining that the terminal device's access to the first cell is in a remote configuration phase. Controlling access to the first cell includes the core network device restricting the terminal device's access to the first cell.

[0014] In some embodiments, the core network device determines that access is in the online signing phase based on at least one of the following: Access is in the online signing phase if the first message includes an online signing indication; Access is in the online signing phase if the credential server fails to authorize the terminal device; Access is in the online signing phase if no user plane context exists for the terminal device.

[0015] In some embodiments, the core network device determines that access is in the remote configuration phase based on at least one of the following: Access is in the remote configuration phase if the first message does not include an online subscription indication; Access is in the remote configuration phase if the credential server successfully authorizes the terminal device; or Access is in the remote configuration phase if a user plane context exists.

[0016] In a second aspect of this disclosure, a method for communication is provided. In this method, an access network device sends a first message to a core network device. The first message includes a cell identifier of a first cell of the access network device to which a terminal device intends to access. The access network device receives first indication information from the core network device regarding access to the first cell. The access network device determines that the first cell does not support online subscription. Based on the first indication information, the access network device controls the terminal device's access to the first cell. This allows the terminal device to obtain subscription or credential information only through cells supporting online subscription services without changing the cell selection or cell handover mechanism on the terminal device side. This scheme also allows for flexible configuration of whether the same access restrictions apply to subsequent access procedures. In this way, cell load can be reduced, network security can be ensured, and the performance of the communication system can be improved.

[0017] In some embodiments, the first indication information indicates that access to the first cell by the terminal device should be restricted. Controlling access to the first cell includes the access network equipment restricting the terminal device's access to the first cell.

[0018] In some embodiments, restricting a terminal device's access to a first cell by the access network device sending a third message to the terminal device. The third message includes at least one of the following: a rejection indication, a rejection reason value, or a redirection indication for the terminal device.

[0019] In some embodiments, the method further includes: the access network device receiving second indication information from the core network device. The second indication information indicates the removal of the restriction on access to the first cell.

[0020] In a third aspect of this disclosure, a method for communication is provided. In this method, a terminal device receives an online subscription capability indication from an access network device. The online subscription capability information for at least one cell includes a cell identifier and corresponding online subscription capability for at least one cell of the access network device. The online subscription capability indication includes the online subscription capability information for at least one cell of the access network device. Based on the online subscription capability information, the terminal device selects a second cell from the at least one cell, the second cell supporting online subscription. The terminal device sends an online subscription request for the second cell to the access network device. Through this mechanism, the terminal device can dynamically consider the online subscription capability of cells when performing cell selection or cell reselection. For example, when the terminal device requests access to the network to obtain subscription or credential information, it can select a cell supporting online subscription services based on the online subscription capability of each cell, thereby effectively reducing the load on ordinary cells. After online subscription is completed, the terminal device can consider whether to apply cell access restrictions. In this way, cell load balancing can be achieved, while ensuring network security and improving the performance of the communication system.

[0021] In some embodiments, the terminal device determines candidate cells that support online subscription based on online subscription capability information. The terminal device then selects a second cell from the candidate cells for camping. The determination of candidate cells is implemented at the access layer of the terminal device.

[0022] In some embodiments, a fourth message is received from the core network equipment. The fourth message indicates that the online subscription has been completed. The terminal equipment performs cell reselection or cell handover for at least one cell. Cell reselection or cell handover may not be based on online subscription capability information.

[0023] In some embodiments, the terminal device performs cell reselection or cell handover for at least one cell based on online subscription capability information.

[0024] In a fourth aspect of this disclosure, a core network device is provided. The core network device includes: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the core network device to implement the methods according to the possible implementations of the first aspect described above.

[0025] In a fifth aspect of this disclosure, an access network device is provided. The access network device includes: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the access network device to implement the method in a possible implementation of the second aspect described above.

[0026] In a sixth aspect of this disclosure, a terminal device is provided. The terminal device includes: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the terminal device to implement the methods in the possible implementations of the third aspect described above.

[0027] In a seventh aspect of this disclosure, a computer program product is provided. The computer program product is tangibly stored on a computer-readable medium and includes computer-executable instructions that, when executed, cause a device to perform operations according to any possible implementation of the methods in the first to third aspects described above.

[0028] In an eighth aspect of this disclosure, a communication device is provided. The communication device includes components for implementing the method according to any one of the possible implementations of the first to third aspects described above.

[0029] In a ninth aspect of this disclosure, a chip is provided. The chip is configured to perform operations according to any one of the possible implementations of the first to third aspects described above.

[0030] In a tenth aspect of this disclosure, a communication system is provided, including one or more of the aforementioned core network equipment and access network equipment.

[0031] In some embodiments, the communication system also includes other communication devices involved in the embodiments. Attached Figure Description

[0032] The features, advantages, and other aspects of various implementations of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Several implementations of this disclosure are illustrated herein by way of example, not limitation, in the accompanying drawings:

[0033] Figure 1 A schematic block diagram of the online signing process for terminal devices is shown;

[0034] Figure 2 A schematic block diagram of a communication environment in which embodiments of the present disclosure may be shown;

[0035] Figure 3 An interactive signaling diagram of a communication process according to some embodiments of the present disclosure is shown;

[0036] Figure 4 Interactive signaling diagrams of communication processes according to other embodiments of this disclosure are shown;

[0037] Figure 5An interactive signaling diagram of a communication process according to yet another embodiment of the present disclosure is shown;

[0038] Figure 6 A flowchart is shown illustrating a method implemented at a core network device according to some embodiments of the present disclosure;

[0039] Figure 7 A flowchart is shown illustrating a method implemented at an access network device according to other embodiments of the present disclosure;

[0040] Figure 8 A flowchart illustrating a method implemented at a terminal device according to yet another embodiment of the present disclosure is shown;

[0041] Figure 9 A schematic block diagram of a communication device according to some embodiments of the present disclosure is shown; and

[0042] Figure 10 A simplified block diagram of an example device suitable for implementing embodiments of the present disclosure is shown.

[0043] In the various figures, the same or similar reference numerals represent the same or similar elements. Detailed Implementation

[0044] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0045] In the description of the embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "an embodiment" or "the embodiment" should be understood as "at least one embodiment". In the description of this application, unless otherwise stated, " / " indicates that the related objects are in an "or" relationship, for example, A / B can represent A or B; "and / or" in this application is merely a description of the relationship between related objects, indicating that three relationships can exist, for example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of this application, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. Furthermore, to facilitate a clear description of the technical solutions in the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that the terms "first" and "second" are not necessarily different.

[0046] The embodiments of this disclosure can be implemented according to any suitable communication protocol, including but not limited to cellular communication protocols such as fourth generation (4G) and fifth generation (5G), wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocols currently known or to be developed in the future. The technical solutions of the embodiments of this disclosure are applicable to any suitable communication system, such as: General Packet Radio Service (GPRS), Long Term Evolution (LTE) systems, Frequency Division Duplex (FDD) systems, Time Division Duplex (TDD) systems, Universal Mobile Telecommunications Service (UMTS), Narrowband Internet of Things (NB-IoT) communication systems, future fifth generation (5G) systems, or New Radio (NR), etc.

[0047] For illustrative purposes, the following text will refer to the 3rd Generation Partnership Project (3GPP) for 5G. rd The embodiments of this disclosure are described in the context of a Generation Partnership Project (3GPP) communication system. However, it should be understood that the embodiments of this disclosure are not limited to applications to 5G 3GPP communication systems, but can be applied to any communication system with similar problems, such as LTE communication systems, Wireless Local Area Networks (WLANs), wired communication systems, or other communication systems developed in the future.

[0048] As used in this disclosure, the term "terminal device" refers to any terminal device capable of wireless communication with network devices or with each other via a wired or air interface. A terminal device may sometimes be referred to as user equipment (UE). A terminal device can be any type of mobile terminal, fixed terminal, or portable terminal. As an example, terminal devices may include cellular phones, cordless phones, smartphones, sites, user units, handheld terminals, mobile terminals (MT), subscriber stations (SS), portable subscriber stations (PSS), internet nodes, communicators, desktop computers, laptop computers, notebook computers, tablet computers, wireless data cards, wireless modems, personal communication system (PCS) devices, personal navigation devices, personal digital assistants (PDAs), positioning devices, radio receivers, e-book devices, gaming devices, Internet of Things (IoT) devices, wireless local loop (WLL) stations, machine type communication (MTC) terminals, in-vehicle devices, aircraft, virtual reality (VR) devices, augmented reality (AR) devices, wearable devices, terminal devices in 5G networks, or any terminal devices in future evolved Public Land Mobile Networks (PLMNs), other devices that can be used for communication, or any combination of the above. Embodiments of this disclosure are not limited in this regard.

[0049] As used in this disclosure, the term "access network equipment" refers to an entity or node that can communicate with terminal equipment. For example, it can be a Radio Access Network (RAN) network device that provides functions such as radio resource management, quality of service (QoS) management, data compression, and encryption on the air interface side. Access network equipment can include various types of base stations. As examples, access network equipment can include various forms of macro base stations, micro base stations, pico base stations, femtobase stations, relay stations, access points, remote radio units (RRUs), radio heads (RHs), remote radio heads (RRHs), etc. In systems employing different radio access technologies, the name of the access network equipment may differ; for example, it may be called NodeB in 3G networks, evolved NodeB (eNB or eNodeB) in LTE networks, and gNodeB (gNB) or NRNodeB (NR NB) in 5G networks, etc. The embodiments of this disclosure do not limit this. As used herein, the term "entity" refers to a network element that can perform a specific function.

[0050] The exemplary embodiments of this disclosure may involve the following network elements:

[0051] 1. Radio Access Network ((R)AN) element: Used to provide network access functionality for authorized terminal devices in a specific area, and capable of using transmission tunnels of different quality according to the terminal device's level and service requirements. The (R)AN element manages radio resources, provides access services to terminal devices, and thus completes the forwarding of control signals and terminal device data between the terminal device and the core network. The (R)AN element can also be understood as a base station in a traditional network.

[0052] 2. User plane network element: Used for packet routing and forwarding, as well as quality of service (QoS) processing of user plane data. In 5G communication systems, this user plane network element can be a user plane function (UPF) network element. In future communication systems, the user plane network element can still be a UPF network element, or it can have other names; this application does not limit this.

[0053] 3. Data Network: A network used to provide data transmission. In a 5G communication system, this data network can be a data network (DN). In future communication systems, the data network may still be a DN, or it may have other names; this application does not limit this.

[0054] 4. Access Management Network Element: Primarily used for mobility management and access management, it can implement functions of the Mobility Management Entity (MME) other than session management, such as lawful interception and access authorization / authentication. In 5G communication systems, this access management network element can be an access and mobility management function (AMF) network element. In future communication systems, the access management network element can still be an AMF network element, or it can have other names; this application does not limit its scope.

[0055] 5. Session Management Network Element: Primarily used for session management, allocation and management of Internet Protocol (IP) addresses for terminal devices, selection of manageable user plane functions, policy control and charging function interface endpoints, and downlink data notification. In 5G communication systems, this session management network element can be a session management function (SMF) network element. In future communication systems, the session management network element can still be an SMF network element, or it can have other names; this application does not limit its scope.

[0056] 6. Network Open Element: Used to securely expose services and capabilities provided by 3GPP network function elements to the outside world.

[0057] In 5G communication systems, this network open element can be a network exposure function (NEF) element. In future communication systems, the network open element can still be a NEF element, or it can have other names; this application does not limit this.

[0058] 7. Unified data management network element: used to handle user identification, access authentication, registration, and mobility management, etc.

[0059] In 5G communication systems, this unified data management network element can be a unified data management (UDM) network element. In future communication systems, the unified data management network element can still be a UDM network element, or it can have other names; this application does not limit this.

[0060] 8. Authentication Service Network Element: This element performs primary authentication, i.e., authentication between the terminal device and the operator's network. After receiving an authentication request from a subscribed user, the Authentication Service Network Element can authenticate and / or authorize the subscribed user using authentication and / or authorization information stored in the Unified Data Management Network Element, or generate the subscribed user's authentication and / or authorization information using the Unified Data Management Network Element. The Authentication Service Network Element can then send the authentication and / or authorization information back to the subscribed user. In one implementation, the Authentication Service Network Element can also be co-located with the Unified Data Management Network Element.

[0061] In 5G communication systems, this authentication service network element can be an authentication server function (AUSF) network element. In future communication systems, unified data management can still be an AUSF network element, or it can have other names; this application does not limit this.

[0062] 9. Application Network Element: Used for data routing affected by applications, accessing network open function network elements, and interacting with the policy framework for policy control, etc. In 5G communication systems, this application network element can be an application function (AF) network element. In future communication systems, the application network element can still be an AF network element, or it can have other names; this application does not limit this.

[0063] 10. Terminal equipment: This can include various handheld devices, vehicle-mounted devices, wearable devices, computing devices or other processing devices connected to a wireless modem with wireless communication capabilities, as well as various forms of terminals, such as mobile stations (MS), terminals, user equipment (UE), soft terminals, etc., such as water meters, electricity meters, sensors, etc.

[0064] In the network architecture, Namf is the service-based interface presented by the AMF network element, Nsmf is the service-based interface presented by the SMF network element, Nnef is the service-based interface presented by the NEF network element, Nudm is the service-based interface presented by the UDM network element, and Naf is the service-based interface presented by the AF network element. N1 is the reference point between terminal device 111 and the AMF network element; N2 is the reference point between the (R)AN network element and the AMF network element, used for sending non-access stratum (NAS) messages, etc.; N3 is the reference point between the (R)AN network element and the UPF network element, used for transmitting user plane data, etc.; N4 is the reference point between the SMF network element and the UPF network element, used for transmitting information such as tunnel identification information of the N3 connection, data cache attribute information, and downlink data notification messages, etc.; the N6 interface is the reference point between the UPF network element and the DN, used for transmitting user plane data, etc.

[0065] It should be noted that the names of various network elements (e.g., UPF network elements, UDM network elements, etc.) included in the network architecture are merely names and do not limit the function of the network element itself. In 5G networks and other future networks, the aforementioned network elements may also have other names, and this application embodiment does not specifically limit this. For example, in 6G networks, some or all of the aforementioned network elements may use the terminology from 5G, or they may have other names, etc. This is explained uniformly here and will not be repeated below. In addition, it is understood that the aforementioned network elements or functions can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., cloud platform). The aforementioned network elements or functions can be divided into one or more services, and furthermore, services that exist independently of network functions may also exist. In this application, instances of the aforementioned functions, instances of services included in the aforementioned functions, or instances of services that exist independently of network functions can all be referred to as service instances. The term "cell selection" used herein refers to the process by which a terminal device selects a cell to camp on based on certain criteria and uses that cell as the serving cell. In the context of this disclosure, "cell selection" can refer to initial cell selection, i.e., the process by which a terminal device selects an initial serving cell after completing PLMN selection, or it can refer to "cell reselection," i.e., the process by which a terminal device switches from the current cell to another cell. In some embodiments of this disclosure, the term "cell selection" may also include both "initial cell selection" and "cell reselection."

[0066] The current 5G 3GPP system architecture mainly includes the following network functions and entities: terminal equipment (e.g., UE), (R)AN, UPF, DN, AMF, SMF, PCF, AF, Network Slice Selection Function (NSSF), AUSF, and UDM. These network functions and entities interact through corresponding interfaces; for example, the UE and AMF can interact using the N1 interface. Some interfaces can be implemented using service-oriented interfaces. Additionally, the Network Data Analytics Function (NWDAF) can interact with other network functions through the service-oriented interface Nnwdaf. The term "entity" used in this paper refers to a network element that can implement a specific function.

[0067] UE, (R)AN, UPF, and DN are generally referred to as user layer network function entities. User data traffic can be transmitted via (R)AN and UPF through the PDU session established between the UE and DN. Other parts are generally referred to as control layer network functions and entities, which can be used for functions such as authentication and authorization, registration management, session management, mobility management, and policy control, thereby achieving reliable and stable transmission of user layer traffic.

[0068] As discussed above, current communication systems allow terminal devices to obtain subscription information or credentials for accessing the target network through an intermediate network, enabling the terminal device to subsequently access the target network and establish a PDU session. Figure 1 A schematic block diagram of an online signing process 100 for a terminal device is shown. Figure 1 In the SNPN scenario shown, terminal device 130 expects to access SNPN 140 and can obtain subscription or credential information for accessing SNPN 140 by establishing a connection with O-SNPN 120.

[0069] exist Figure 1In the example, SNPN 140 acts as the target network, while O-SNPN 120 acts as an intermediate network. Specifically, O-SNPN 120 can broadcast an online subscription capability indication. Based on this indication, terminal device 130 determines that O-SNPN 120 supports online subscription and establishes a connection with O-SNPN 120 using default subscription or credential information. The terminal device's online subscription request for O-SNPN 120 needs to be authenticated by the Default Credential Server (DCS) 112. Only after successful authentication can terminal device 130 obtain subscription or credential information for the target network from the Provisioning Server (PS) 114 using a restricted User Plane (UP) or Control Plane (CP) transport channel.

[0070] PS 114 has a protocol with SNPN 140 and can store or retrieve subscription or credential information of SNPN 140. PS 114 sends the subscription or credential information for SNPN 140 to terminal device 130 through a restricted UP or CP transmission channel. Terminal device 130 can then de-register from O-SNPN 120 and register with SNPN 140 using the retrieved subscription or credential information.

[0071] In process 100, the process by which terminal device 130 selects a network that supports online signing and obtains authorization from DCS 112 can be called the online signing stage. The subsequent process of establishing a CP or UP transmission channel and obtaining signing or credential information for the target network can be called the remote provisioning stage.

[0072] In conventional communication systems, networks providing online subscription services also offer other traditional services. If access network equipment supporting online subscription services broadcasts online subscription capability indications in all its cells, a large number of terminal devices requesting online subscription may increase the cell load, affecting the access network equipment's traditional services, and these online subscription requests may contain malicious requests. Therefore, access network equipment supports broadcasting online subscription capability indications at the cell level; that is, access network equipment can broadcast online subscription capability indications in specific cells to restrict the access of terminal devices requesting online subscription services.

[0073] According to the cell selection or reselection mechanism, when the Access Stratum (AS) of a terminal device receives information broadcast by the access network device, including parameters such as network identifier and online subscription capability indication, it will send it to the Non-Access Stratum (NAS) of the terminal device. The NAS of the terminal device selects a network that supports online subscription based on the online subscription capability indication and instructs the AS layer to select a cell within that network. Since the cell selection at this time references information such as cell frequency, signal strength, and parameters contained in system messages, the AS of the terminal device does not consider the cell's online subscription capability indication. In other words, the cell selected by the AS of the terminal device may be a regular cell that does not provide online subscription services, and currently, there is no verification process on the RAN side and core network side to restrict the UE to access only from cells that support online subscription.

[0074] Furthermore, cell reselection or handover processes caused by the mobility of terminal devices should not affect the remote configuration phase of the terminal devices. That is, only the online subscription phase of the terminal devices should be restricted. After obtaining online subscription authorization, there should be no restriction on which cells the terminal devices can perform the remote configuration process in. Existing cell reselection or handover mechanisms cannot flexibly restrict terminal devices' access to cells based on phases.

[0075] To address the aforementioned issues and other potential problems, embodiments of this disclosure provide an online subscription scheme. This scheme considers the online subscription capabilities of access network equipment within a cell and controls the access process of the terminal equipment to that cell. The scheme can also apply restrictions to the access process based on whether it is in the online subscription phase, and choose whether to apply restrictions based on whether the access process is in the remote configuration phase. When this scheme is implemented on the core network or access network side, it does not require changes to the cell selection or cell handover mechanism of the terminal equipment. Furthermore, this scheme can also be used to enhance existing cell selection or cell handover mechanisms without altering the operation on the core network or access network side. In this way, cell load can be effectively reduced, and network performance and security can be improved.

[0076] Figure 2A schematic diagram of a communication environment 200 in which embodiments of the present disclosure may be implemented is shown. The communication environment 200 includes a core network device 210, an access network device 220, and a terminal device 230. The access network device provides a first cell 221, a second cell 222, and a third cell 223. The core network device 210, the access network device 220, and the terminal device 230 can communicate with each other. It should be understood that the network environment 200 is for illustrative purposes only and does not imply any limitation on the scope of the present disclosure. Embodiments of the present disclosure may also be embodied in other network environments or architectures. Furthermore, it should be understood that the network environment 200 may also include other elements or entities for implementing communication connections, data transmission, control, etc. For the sake of simplicity, Figure 2 These elements or entities are not shown in the figures, but this does not mean that the embodiments of this disclosure do not include them.

[0077] Access network device 220 can broadcast messages to terminal devices 230 within its coverage area. These messages may include, for example, network identifiers, online subscription capability indications, scheduling information, configuration parameters, cell access-related information, etc. Terminal device 230 can determine, based on the broadcast message, that the network provided by access network device 220 supports online subscription services and select a cell (e.g., first cell 221) to access access network device 220. For example, terminal device 230 can select first cell 221 for camping and send a registration request to core network device 210 through access network device 220. This registration request includes indication information for online subscription. As terminal device 230 moves, it can switch to other cells of access network device 220 besides first cell 221, such as cells 222 or 223, through cell reselection or cell handover mechanisms. For illustrative purposes only, in the following description, access network device 220 refers to an intermediate network that provides terminal device 230 with subscription or credential information for accessing a target network (not shown).

[0078] Access network device 220 can communicate with core network device 210. Access network device 220 can send cell capability information to core network device 210 via Next Generation Application Protocol (NGAP) messages. As an example, cell capability information may include overall capability information for cells 221 to 223, such as cell identifiers (e.g., Cell Global Identifier (CGI)), online subscription capability information, service support capability information, etc. As another example, cell capability information may only include the cell identifier and online subscription capability information of the first cell 221 to which terminal device 230 intends to access. Furthermore, access network device 220 can send a message to core network device 210 indicating the cell identifier of the first cell 221 to which terminal device 230 intends to access. Access network device 220 can also send instruction information for online subscription to core network device 210, which core network device 210 can use to determine whether the access process of terminal device 230 to the first cell 221 is in the online subscription stage or the remote configuration stage.

[0079] The core network device 210 can be implemented as an AMF, DCS, UDM, PCF, SMF, or any other suitable network element on the core network side. For example, if the core network device 210 is implemented as an AMF, it can provide control plane storage resources for the sessions of the terminal device 230, storing session identifiers, SMF network element identifiers associated with the session identifiers, etc.

[0080] When the core network device 210 is implemented as a DCS, it can authenticate the terminal device 230 and determine the authorization result. If the core network device 210 successfully authorizes the terminal device 230, the terminal device 230 can obtain online subscription services.

[0081] When core network device 210 is implemented as a UDM (User Device Manager), it can be responsible for subscription management and authentication, and store subscription information for terminal devices in the network. Furthermore, the subscription information can further indicate the device type and / or capability information of the terminal devices. In this case, regardless of whether core network device 210 is the UDM itself or another network element different from the UDM, core network device 210 can determine whether to restrict access to the cell for terminal devices in the online subscription phase based on the device type and / or capability information indicated by the subscription information.

[0082] When core network device 210 is implemented as a PCF (Polymobility Component Provider), it can provide policy information related to mobility, access selection, and PDU sessions. Furthermore, the policy information can further indicate the device type and / or capability information of the terminal devices. In this case, regardless of whether core network device 210 is the PCF itself or another network element different from the PCF, core network device 210 can determine whether to restrict access to the cell for terminal devices in the online subscription phase based on the device type and / or capability information indicated by the policy information.

[0083] When the core network device 210 is implemented as an SMF (Software Context Provider), it can be responsible for user plane element selection, user plane element redirection, IP address allocation, bearer establishment, modification and release, and QoS control. After the core network device 210 establishes a user plane transmission channel for the terminal device 230, a user plane context for the terminal device 230 exists in the network.

[0084] Furthermore, core network device 210 can also communicate with other network entities or functions in communication environment 200. For example, if core network device 210 is not implemented as a DCS, it can obtain authorization results from the DCS. As mentioned earlier, if terminal device 230 completes DCS authentication in the intermediate network, it can obtain online subscription services and execute subsequent remote configuration procedures. Therefore, core network device 210 can determine whether the access process of terminal device 230 to the first cell 221 is in the online subscription stage or the remote configuration stage based on the authorization result of the DCS, and further choose whether to restrict the access of terminal device 230 to the first cell 221.

[0085] If core network device 210 is not implemented as an SMF (Service Provider Function), it can communicate with the SMF to obtain the verification result regarding the user plane context. If no user plane context exists for terminal device 230, it indicates that the online subscription process has not yet been completed, and core network device 210 can determine that it is necessary to restrict terminal device 230's access to the first cell 221. If a user plane context exists for terminal device 230, it indicates that the online subscription process has been completed, that is, the access process is in the remote configuration phase. In this case, core network device 210 can further choose whether to restrict terminal device 230's access to the first cell 221.

[0086] It should be understood that Figure 2 The number of various devices and their connections shown are for illustrative purposes only and no limitations are imposed. Communication environment 200 may include any suitable number of devices and networks appropriate for implementing embodiments of this disclosure. In communication environment 200, core network device 210, access network device 220, and terminal device 230 may transmit data and control information to each other.

[0087] Communication in the communication environment 200 can be implemented according to any appropriate communication protocol, including but not limited to wireless local area network communication protocols such as first-generation cellular communication protocol (1G), second-generation cellular communication protocol (2G), third-generation cellular communication protocol (3G), fourth-generation cellular communication protocol (4G) and fifth-generation cellular communication protocol (5G), such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other current protocol known or to be developed in the future. Furthermore, communications may utilize any suitable wireless communication technology, including but not limited to: Narrow Band-Internet of Things (NB-IoT), Global System for Mobile Communications (GSM), Enhanced Data Rate for GSM Evolution (EDGE), Wideband Code Division Multiple Access (WCDMA), Code Division Multiple Access 2000 (CDMA2000), Time Division-Synchronization Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), the three major application scenarios of 5G mobile communication systems (eMBB, URLLC, and eMTC), and / or any other technologies currently known or to be developed therein.

[0088] The following will refer to Figures 3 to 9 The following will specifically discuss exemplary embodiments of this disclosure. For ease of discussion, reference will be made to... Figure 2 The example communication environment described herein is used to illustrate signaling interactions between communication entities according to example embodiments of this disclosure. It should be understood that example embodiments of this disclosure can be applied in a similar manner to other communication environments.

[0089] According to some embodiments of this disclosure, access restrictions for online-subscribed cells can be implemented on the core network side, thereby avoiding changes to the cell selection mechanism used by terminal devices. For example, Figure 3 The diagram illustrates the interactive signaling of the specific communication process 300 according to the above scheme. For example... Figure 3 As shown, the communication process 300 involves core network equipment 210, access network equipment 220, and terminal equipment 230. It should be understood that... Figure 3The communication processes illustrated herein are merely exemplary and not limiting. Embodiments of this disclosure may include... Figure 3 Interactive signaling not shown in the diagram, or omitted. Figure 3 Some of the signaling is shown in the diagram.

[0090] 305. Terminal device 230 and access network device 220 perform the 305 cell selection procedure. For example, access network device 220 may broadcast system messages in its cells 221 to 223. System messages may include, for example, network identifiers, online subscription capability indications, scheduling information, configuration parameters, cell access-related information, etc. Terminal device 230 may determine, based on the system messages, that the network provided by access network device 220 supports online subscription services, and select one of the cells of access network device 220 (e.g., first cell 221) for camping. Terminal device 230 may send a registration request to access network device 220 for the first cell 221, the registration request including indication information for online subscription.

[0091] 310. After receiving the registration request, the access network device 220 sends a first message to the core network device 210, including the cell identifier of the first cell 221 selected by the terminal device 230. The first message may be an NGAP message, such as an Initial UE Message. In some embodiments, the first message may also indicate the online subscription capability of the first cell 221.

[0092] In other example embodiments, core network device 210 may obtain cell capability information from access network device 220, including but not limited to cell identifiers of cells 221 to 223 and corresponding online subscription capability information, service support capability information, etc. This cell capability information may be included in messages such as NG setup request messages and RAN configuration update messages. Core network device 210 may also receive update information from access network device 220, indicating updates to the cell capability information.

[0093] 315. Based on the first message, core network device 210 can determine whether the cell to which terminal device 230 wants to access supports online contract signing services. For example, based on the cell identifier of the first cell 221, core network device 210 determines 315 that the first cell 221 does not support online contract signing. Then, core network device 210 can control the access of terminal device 230 to the first cell 221.

[0094] 320. Core network device 210 can determine whether the access process is in the online signing stage or the remote configuration stage, and based on the stage of the access process and the online signing capability of the cell to be accessed, determine whether to restrict the terminal device 230's access to the cell. For example, core network device 210 can determine 320 that the terminal device 230's access to the first cell 221 is in the online signing stage. Based on the judgments on the access process in 315 and 320, core network device 210 determines that the terminal device 230 is restricted from accessing the first cell 221.

[0095] 325. Core network device 210 sends a 325 indication message to access network device to restrict access to the first cell 221.

[0096] 330. Core network device 210 sends a second message 330 to terminal device 230. The second message may include a rejection indication, a rejection reason value, or a redirection indication.

[0097] 335. Upon receiving the second message, terminal device 230 and access network device 220 perform the cell reselection procedure 335. Access network device 220 may send a message instructing the cell reselection procedure to core network device 210. This message may include other messages different from the first message, such as uplink NAS transport messages, etc., and this disclosure is not limited in this respect.

[0098] As mentioned earlier, once the online signing process is completed, subsequent access procedures for terminal device 230 and access network device 220 (such as remote configuration, cell reselection / cell handover triggered due to mobility) are not affected by the cell's online signing capability, and therefore access restrictions can be waived. Of course, the same access restrictions can also be applied to subsequent access procedures.

[0099] 340. As an example, after 315, core network device 210 determines that 340 terminal device 230's access to the first cell 221 is in the remote configuration phase. Although in the context of this disclosure, the process by which terminal device 230 obtains authorization from DCS112 through an intermediate network is referred to as the online signing phase, and the subsequent process of establishing a CP or UP transmission channel and obtaining signing or credential information for the target network can be referred to as the remote configuration phase, the naming of "online signing phase" and "remote configuration phase" corresponds to the current standard, but the embodiments of this disclosure are also applicable to equivalent or equivalent concepts in future or subsequent standards. Therefore, the scope of this disclosure is not limited in this respect.

[0100] In some example embodiments, core network device 210 may determine the stage of the access process of terminal device 230, or whether to restrict terminal device 230's access to the first cell 221, based on one or more criteria. For example, if the first message includes an online subscription instruction, core network device 210 may determine that the access process is in the online subscription stage and that it is necessary to restrict terminal device 230's access to the first cell 221. If the first message does not include an online subscription instruction, core network device 210 may determine that the access process is in the remote configuration stage, and core network device 210 may further select whether to restrict terminal device 230's access to the first cell 221.

[0101] As another example, core network device 210 can be based on, for example Figure 1 The authorization result of DCS 112 to terminal device 230 is used to determine the access status. If DCS 112 fails to authorize terminal device 230, it indicates that the online subscription process has not yet been completed, and core network device 210 can determine that terminal device 230's access to the first cell 221 needs to be restricted. If DCS 112 successfully authorizes terminal device 230, it indicates that the online subscription process has been completed, that is, the access process is in the remote configuration phase. In this case, core network device 210 can further choose whether to restrict terminal device 230's access to the first cell 221.

[0102] It should be understood that determining the stage of the access process based on the authorization result of the DCS to the terminal device 230 is given for illustrative purposes only. The embodiments of this disclosure are not limited to DCS authentication and can also be applied to other authorization authentication methods. For example, the core network device 210 can make a determination based on the authorization result of the UDM network element to the terminal device 230. If the UDM network element fails to authorize the terminal device 230, it indicates that the online subscription process of the terminal device 230 has not yet been completed, and the core network device 210 can determine that the access process of the terminal device 230 is in the online subscription stage. For the terminal device 230 in the online subscription stage, the core network device 210 can determine that it is necessary to restrict the terminal device 230's access to the first cell 221. If the UDM network element successfully authorizes the terminal device 230, it indicates that the online subscription process has been completed, that is, the access process is in the remote configuration stage. In this case, the core network device 210 can further choose whether to restrict the terminal device 230's access to the first cell 221.

[0103] Since a user plane transmission channel for transmitting signing or credential information will be established during the online signing phase, core network device 210 can also determine whether a user plane context for terminal device 230 exists in the network. For example, core network device 210 can communicate with SMF network elements to verify the existence of user plane context information. If no user plane context for terminal device 230 exists, it indicates that the online signing process has not yet been completed, and core network device 210 can determine that access to the first cell 221 by terminal device 230 needs to be restricted. If a user plane context for terminal device 230 exists, it indicates that the online signing process has been completed, that is, the access process is in the remote configuration phase. In this case, core network device 210 can further choose whether to restrict access to the first cell 221 by terminal device 230.

[0104] 345. Core network device 210 can determine whether to restrict terminal device 230's access to the first cell 221. If it is determined that access is not restricted, then terminal device 230 is allowed to access the first cell 221. Further,

[0105] 350. Alternatively, if access to the first cell 221 is restricted in 345, then, similar to 330, the core network device 210 may send the second message 350 to the terminal device 230.

[0106] 355. In response to the second message, terminal device 230 may perform a cell reselection procedure with access network device 220. The cell reselection procedure may be based on existing criteria or mechanisms to be developed in the future, and therefore will not be described in detail here. The scope of this disclosure is not limited in this respect.

[0107] Although in process 300, the core network device 210 is described as executing 315 first, followed by 320 or 340—that is, first determining the online subscription capability of the first cell 221, and then determining the stage of the access process of the terminal device 230—the execution of process 300 does not depend on the order of 315, 320, or 340. For example, in some alternative embodiments, the core network device 210 may first determine the stage of the access process of the terminal device 230, i.e., execute 320 or 340 first, and then determine the online subscription capability of the first cell 221, i.e., execute 315. In other example embodiments, the determination of the stage of the access process and the determination of the online subscription capability of the first cell 221 may also be executed in parallel. The scope of this disclosure is not limited in this respect.

[0108] Based on the example embodiments described above, a scheme for controlling terminal device access to the network is provided. This scheme is implemented on the core network side and can ensure that the terminal device can only obtain subscription or credential information through cells supporting online subscription services without changing the cell selection or cell handover mechanism on the terminal device side. This scheme also allows for flexible configuration of whether the same access restrictions apply to subsequent access processes. In this way, cell load conditions can be adjusted, network security can be ensured, and the performance of the communication system can be improved.

[0109] According to other embodiments of this disclosure, access restrictions for online-subscribed cells can be implemented on the access network side, thereby avoiding changes to the cell selection mechanism used by the terminal device. For example, Figure 4 The diagram illustrates the interactive signaling of the specific communication process 400 according to the above scheme. (See diagram for example.) Figure 4 As shown, the communication process 400 involves core network equipment 210, access network equipment 220, and terminal equipment 230. It should be understood that... Figure 4 The communication processes illustrated herein are merely exemplary and not limiting. Embodiments of this disclosure may include... Figure 4 Interactive signaling not shown in the diagram, or omitted. Figure 4 Some of the signaling is shown in the diagram.

[0110] 405. Terminal device 230 and access network device 220 execute the 405 cell selection procedure, and send a registration request to core network device 210 through access network device 220. The cell selection procedure in 405 is similar to... Figure 3 Similar to the 305, it will not be described in detail here.

[0111] 410. Upon receiving the registration request, the access network device 220 sends a first message to the core network device 210, including the cell identifier of the first cell 221 selected by the terminal device 230. For example, the access network device 220 can forward the registration request from the terminal device 230 through the first message. The first message can be an NGAP message, such as an Initial UE Message.

[0112] Upon receiving the first message, core network device 210 can determine whether the access procedure is in the online signing phase or the remote configuration phase. Core network device 210 and access network device 220 can establish a connection (e.g., NGAP Association) for each terminal device in the network. This connection can be uniquely identified at access network device 220 using an identifier such as the RAN UE NGAP ID. Similarly, the connection can be uniquely identified at core network device 210 using an identifier such as the AMF UE NGAP ID. After the NGAP connection is established, core network device 210 can verify the phase of terminal device 230 at any time. Core network device 210 can determine the phase of the access procedure based on one or more criteria described in process 300. Therefore, further details are omitted here. Then, core network device 210 can send indication information to access network device 220 to indicate the phase of the access procedure.

[0113] In some example embodiments, core network device 210 may be a core network element in the network selected by access network device 220 that supports online subscription. In this case, core network device 210 may determine whether access to the first cell 221 by terminal device 230 needs to be controlled based on pre-configured rules or policies. For example, core network device 210 may determine whether to restrict access to terminal device 230 based on the device type and / or device capabilities indicated by the pre-configured rules or policies of terminal device 230. In such embodiments, the pre-configured rules or policies may be stored locally on core network device 210. The scope of this disclosure is not limited in this respect.

[0114] 415. As an example, core network device 210 can determine that the 415 access process is in the online signing stage.

[0115] 420. Then, the core network device 210 sends a first indication message 420 to the access network device 220 to indicate that the terminal device 230's access to the first cell 221 is restricted. The access network device 220 may store the first indication message. If the core network device 210 has previously sent another indication message, the access network device 220 may use the first indication message to update the stored other indication message.

[0116] 425. Based on the online subscription capability information of the first cell 221, the access network device 220 can determine that the first cell 221 does not support online subscription services. The access network device 220 can control the access of the terminal device 230 to the first cell 221 based on the first indication information and the online subscription capability of the first cell 221.

[0117] In the above embodiment, access network device 220 may determine that access to the first cell 221 by terminal device 230 should be restricted. 430. In this case, access network device 220 sends a third message to terminal device 230, the third message may include at least one of a denial indication, a denial reason value, or a redirection indication for the terminal device.

[0118] 435. Upon receiving the third message, terminal device 230 and access network device 220 execute the cell reselection procedure 435. The cell reselection procedure may be based on existing criteria or mechanisms to be developed in the future, and therefore will not be described in detail here. The scope of this disclosure is not limited in this respect.

[0119] 440. As another example, core network device 210 can determine that the access process is in the remote configuration phase. If core network device 210 previously sent a first indication message to access network device 220 to indicate restriction of terminal device 230's access to the first cell 221, core network device 210 can send a second indication message to access network device 220 to indicate the removal of the access restriction on the first cell 221. In this case, access network device 220 can use the second indication message to update the previously stored first indication message.

[0120] As yet another example, if core network device 210 determines that access procedure 440 is in the remote configuration phase, core network device 210 may also send a first indication message to access network device 220 indicating a restriction on access to the first cell 221. In this case, access network device 220 and terminal device 230 may perform operations similar to those in 430 and 435. The scope of this disclosure is not limited in this respect.

[0121] Although in process 400, the access network device 220 is described as executing 415 before 420—that is, determining the stage of the access process before determining the online subscription capability of the first cell 221—the execution of process 400 does not depend on the order of 415 and 420. For example, in some alternative embodiments, the core network device 210 may first determine the online subscription capability of the first cell 221 before determining the stage of the access process of the terminal device 230, i.e., executing 420 before 415. In other example embodiments, the determination of the stage of the access process and the online subscription capability of the first cell 221 may also be executed in parallel. The scope of this disclosure is not limited in this respect.

[0122] Based on the example embodiments described above, a scheme for controlling terminal device access to a network is provided. This scheme is implemented on the access network side and, without changing the cell selection or cell handover mechanism on the terminal device side, allows the terminal device to obtain subscription or credential information only through cells supporting online subscription services. This scheme also allows for flexible configuration of whether the same access restrictions apply to subsequent access procedures. In this way, cell load can be reduced, network security can be ensured, and the performance of the communication system can be improved.

[0123] According to further embodiments of this disclosure, enhanced cell selection or cell reselection mechanisms can be implemented at the terminal device. For example, Figure 5 The diagram illustrates the interactive signaling of the specific communication process 500 according to the above scheme. For example... Figure 5 As shown, the communication process 500 involves core network equipment 210, access network equipment 220, and terminal equipment 230. It should be understood that... Figure 5 The communication processes illustrated herein are merely exemplary and not limiting. Embodiments of this disclosure may include... Figure 5 Interactive signaling not shown in the diagram, or omitted. Figure 5 Some of the signaling is shown in the diagram.

[0124] 505. Access network device 220 sends an online subscription capability indication (505) to terminal device 230. The online subscription capability indication may include online subscription capability information for cells 221 to 223 of access network device 220. For example, access network device 220 may broadcast a message including the online subscription capability indication to terminal devices within its coverage area. This message may be a system message, and in addition to the online subscription capability indication, it may also include network identifiers, scheduling information, configuration parameters, cell access-related information, etc.

[0125] In some example embodiments, after the AS of terminal device 230 receives messages broadcast from multiple access network devices, it transmits the relevant parameters and indication information in the messages to the NAS layer. The NAS layer of terminal device 230 can select access network devices that support online subscription services based on the online subscription capability indication, and instruct the AS layer to select a cell that supports online subscription provided by the access network device for camping based on the online subscription capability indication.

[0126] 510. For example, the NAS layer of terminal device 230 determines that the network provided by access network device 220 supports online subscription services, and thus instructs the AS layer to determine, based on the online subscription capability information, candidate cells 510 that support online subscription from cells 221 to 223 of access network device 220, such as second cell 222 and third cell 223.

[0127] 515. The AS layer of terminal device 230 may select 515 a second cell 222 for camping from candidate cells 222 and 223, and send 520 an online subscription request for the second cell 222 to access network device 220. It should be understood that terminal device 230 may determine the cell for camping from the candidate cells based on any existing or future-to-be-developed criteria, and therefore will not be elaborated here. The scope of this disclosure is not limited in this respect.

[0128] 525. Upon receiving an online signing request, access network device 220 and core network device 210 can execute the 525 online signing process with terminal device 230.

[0129] 530. After the online signing process is completed, the core network device 210 sends a fourth message (530) to the terminal device 230 to indicate that the online signing is complete. Upon receiving the fourth message, the terminal device 230 can store it.

[0130] As mentioned earlier, once the online signing process is completed, subsequent access procedures for terminal device 230 and access network device 220 (such as remote configuration, cell reselection triggered by mobility, or cell handover) are not affected by the cell's online signing capability, and therefore access restrictions can be waived. Of course, the same access restrictions can also be applied to subsequent access procedures.

[0131] 535. As an example, after receiving the fourth message, terminal device 230 can determine that cell reselection 535 requires online subscription capability information. In this case, the AS layer of terminal device 230 still considers the online subscription capability information during the cell reselection process. In this case, terminal device 230 can reselect the cell 545 for camping from cells 222 and 223 of access network device 220 that support online subscription.

[0132] 540. As another example, after receiving the fourth message, terminal device 230 can determine that cell reselection does not need to be based on online subscription capability information. The NAS layer of terminal device 230 can instruct the AS layer to remove the restriction on cell selection.

[0133] 545. In this case, terminal device 230 can reselect the cell for camping from all cells of access network device 220.

[0134] It should be understood that other steps in the re-election of communities can be based on any existing or future guidelines, and therefore will not be elaborated upon here. The scope of this disclosure is not limited in this respect.

[0135] Based on the example embodiments described above, an enhanced cell selection mechanism is provided. This mechanism allows terminal devices to dynamically consider the online subscription capabilities of cells during cell selection or cell reselection. For example, when a terminal device requests network access to obtain subscription or credential information, it can select cells that support online subscription services based on the online subscription capabilities of each cell, thereby effectively reducing the load on ordinary cells. After online subscription is completed, the terminal device can consider whether to apply cell access restrictions. In this way, cell load balancing can be achieved, while network security can be ensured, and the performance of the communication system can be improved.

[0136] The following will refer to Figure 6 Combination Figure 3 The communication process in the example embodiments described is explained in detail. Figure 6 A flowchart of a method 600 according to some embodiments of the present disclosure is shown. Method 600 can be implemented at a core network device. For example, method 600 can be implemented at core network device 210. For ease of discussion, the following will be combined with... Figure 2 This describes method 600. It should be understood that method 600 is also applicable to other communication scenarios and devices.

[0137] At box 610, core network device 210 receives a first message from access network device 220. The first message may include the cell identifier of the first cell 221 of the access network device 220 to which terminal device 230 wants to access. For example, the first message may be an NGAP message.

[0138] At frame 620, core network device 210 determines that the first cell 221 does not support online contract signing based on the cell identifier of the first cell 221.

[0139] In some example embodiments, core network device 210 may receive cell capability information from access network device 220. The cell capability information may include a cell identifier for at least one cell of access network device 220 and online subscription capabilities corresponding to the at least one cell, wherein the at least one cell includes a first cell 221. In such an embodiment, core network device 210 may determine, based on the cell capability information and the cell identifier of the first cell 221 obtained from a first message, that the first cell 221 does not support online subscription.

[0140] In some example embodiments, core network device 210 may receive update messages from access network device 220. These update messages may indicate updates to previously received cell capability information.

[0141] In some example embodiments, the first message may also indicate the online signing capability of the first cell 221, and the core network device 210 may determine that the first cell 221 does not support online signing based on the cell identifier of the first cell 221 and the online signing capability of the first cell 221.

[0142] At frame 630, core network device 210 controls the access of terminal device 230 to the first cell 221.

[0143] In some example embodiments, core network device 210 may restrict terminal device 230's access to the first cell 221. In such embodiments, core network device 210 may send a second message to terminal device 230. The second message may include at least one of the following: a denial indication, a denial reason value, or a redirection indication.

[0144] In some example embodiments, core network device 210 may determine to restrict terminal device 230's access to the first cell 221 based on at least one of the following: the first message includes an online subscription instruction, the credential server fails to authorize terminal device 230, or there is no user plane context for terminal device 230 in the network.

[0145] In some example embodiments, core network device 210 can determine that terminal device 230's access to the first cell 221 is in the online subscription stage. Based on the above determination, core network device 210 can restrict terminal device 230's access to the first cell 221 and send a second message to terminal device 230. The second message includes at least one of the following: a rejection indication, a rejection reason value, or a redirection indication.

[0146] In other example embodiments, core network device 210 may determine that the terminal device 230's access to the first cell 221 is in the remote configuration phase. Based on the above determination, core network device 210 may determine that it does not restrict the terminal device 230's access to the first cell 221.

[0147] Alternatively, if it is determined that the terminal device 230's access to the first cell 221 is in the remote configuration phase, the core network device 210 may restrict the terminal device 230's access to the first cell 221.

[0148] Core network device 210 can determine the access stage based on whether the first message includes an online subscription instruction. For example, if the first message includes an online subscription instruction, the access is in the online subscription stage. If the first message does not include an online subscription instruction, the access is in the remote configuration stage.

[0149] Core network device 210 can determine the access stage based on the authorization result of the credential server for terminal device 230. For example, if the credential server fails to authorize terminal device 230, the access is in the online signing stage. If the credential server successfully authorizes terminal device 230, the access is in the remote configuration stage.

[0150] Core network device 210 can determine the access phase based on whether a user plane context for terminal device 230 exists in the network. For example, if no user plane context for terminal device 230 exists in the network, the access is in the online subscription phase. If a user plane context for terminal device 230 exists in the network, the access is in the remote configuration phase.

[0151] The following will refer to Figure 7 Combination Figure 4 The communication process in the example embodiments described is explained in detail. Figure 7 A flowchart of a method 700 according to some embodiments of the present disclosure is shown. Method 700 can be implemented at an access network device. For example, method 700 can be implemented at access network device 220. For ease of discussion, the following will be combined with... Figure 2 This describes method 700. It should be understood that method 700 is also applicable to other communication scenarios and devices.

[0152] At frame 710, access network device 220 sends a first message to core network device 210. The first message may include the cell identifier of the first cell 221 of the access network device 220 to which terminal device 230 wants to access.

[0153] At frame 720, access network device 220 receives first indication information from core network device 210 regarding access to first cell 221. The first indication information may indicate whether to restrict terminal device 230's access to first cell 221.

[0154] At frame 730, access network device 220 determines that the first cell 221 does not support online contract signing.

[0155] At block 740, access network device 220 controls access to first cell 221 by terminal device 230 based on first indication information. In embodiments where the first indication information indicates restriction of terminal device 230's access to first cell 221, access network device 220 may send a third message to terminal device 230. The third message may include at least one of the following: a rejection indication, a rejection reason value, or a redirection indication for terminal device 230.

[0156] In some example embodiments, access network device 220 receives second indication information from core network device. The second indication information indicates the removal of access restrictions on first cell 221. In such example embodiments, the second indication information may indicate the removal of access restrictions on first cell 2210.

[0157] The following will refer to Figure 8 Combination Figure 5 The communication process in the described example embodiments is explained in detail. Figure 8 A flowchart of a method 800 according to some embodiments of the present disclosure is shown. Method 800 can be implemented at a terminal device. For example, method 800 can be implemented at terminal device 230. For ease of discussion, the following will be combined with... Figure 2 This describes method 800. It should be understood that method 800 is also applicable to other communication scenarios and devices.

[0158] At box 810, terminal device 230 receives an online subscription capability indication from access network device 220. The online subscription capability indication may include online subscription capability information for at least one cell of access network device 220 (e.g., first cell 221, second cell 222, and third cell 223).

[0159] At frame 820, terminal device 230 selects a second cell 222 that supports online signing from at least one cell based on online signing capability information.

[0160] In some example embodiments, terminal device 230 can determine candidate cells among at least one of cells 221 to 223 that support online subscription, such as second cell 222 and third cell 223, based on online subscription capability information. Then, terminal device 230 can select second cell 222 from candidate cells 222 and 223 for camping. In the above embodiments, the determination of candidate cells 222 and 223 is implemented at the AS layer of terminal device 230.

[0161] At frame 830, terminal device 230 sends an online subscription request for the second cell 222 to access network device 220.

[0162] In some example embodiments, terminal device 230 may receive a fourth message from core network device 210. The fourth message may indicate that online subscription has been completed. In response to the fourth message, terminal device 230 may perform cell reselection or cell handover for at least one cell 221 to 223. For example, cell reselection or cell handover may not be based on online subscription capability information.

[0163] In other example embodiments, terminal device 230 may also perform cell reselection or cell handover for at least one cell 221 to 223 based on online subscription capability information.

[0164] The above, combined with Figures 3 to 8 The communication method provided in the embodiments of this application is described in detail below. Figures 9 to 10 The communication device provided in the embodiments of this application is described in detail.

[0165] Figure 9 This is a schematic block diagram of a communication device provided in an embodiment of this application. Figure 9 As shown, the device 900 may include a processing unit 910 and a transceiver unit 920. The processing unit 910 is used to control and manage the operation of the communication device, for example, the processing unit 910 is used to execute steps for information / data processing in the communication device. The transceiver unit 920 is used to support the communication device in sending or receiving information / data.

[0166] In one possible embodiment, the transceiver unit 920 can be further divided into a transmitting unit and a receiving unit.

[0167] In one possible embodiment, the communication device may further include a storage module for storing program code and data that the communication device can store.

[0168] (i) In one possible design, the device 900 can be the core network device in the above method embodiments, or it can be a module (such as a chip) applied to the core network device. The device 900 can be used to execute the various steps or processes corresponding to the core network device in methods 300-800 described above. Specifically,

[0169] The transceiver unit 920 is configured to: receive a first message from the access network device, the first message including the cell identifier of the first cell of the access network device to which the terminal device wants to access;

[0170] The processing unit 910 is configured to: determine, based on the cell identifier of the first cell, that the first cell does not support online subscription; and control the access of the terminal device to the first cell.

[0171] Optionally, the transceiver unit 920 is further configured to: receive cell capability information from the access network device, the cell capability information including a cell identifier and corresponding online subscription capability for at least one cell of the access network device, the at least one cell including the first cell; and

[0172] The processing unit 910 is further configured to: determine, based on the cell capability information and the cell identifier of the first cell, that the first cell does not support the online subscription.

[0173] Optionally, the transceiver unit 920 is further configured to: receive an update message from the access network device, the update message indicating an update to the cell capability information.

[0174] Optionally, the processing unit 910 is further configured to: determine, based on the cell identifier of the first cell and the online signing capability of the first cell, that the first cell does not support the online signing.

[0175] Optionally, the processing unit 910 is further configured to: restrict the terminal device's access to the first cell.

[0176] Optionally, the restriction on the terminal device's access to the first cell is determined based on at least one of the following:

[0177] The first message includes instructions for online signing;

[0178] The credential server failed to authorize the terminal device; or

[0179] There is no user plane context for the terminal device.

[0180] Optionally, the processing unit 910 is further configured to: determine that the terminal device's access to the first cell is in the online subscription stage, and wherein controlling the access to the first cell includes:

[0181] The processing unit 910 is also configured to: restrict the terminal device's access to the first cell.

[0182] Optionally, the transceiver unit 920 is further configured to: send a second message to the terminal device, the second message including at least one of the following: a rejection indication, a rejection reason value, or a redirection indication.

[0183] Optionally, the processing unit 910 is further configured to: determine that the terminal device's access to the first cell is in the remote configuration phase, and determine that the terminal device's access to the first cell is not restricted.

[0184] Optionally, the processing unit 910 determines that the terminal device's access to the first cell is in the remote configuration stage and restricts the terminal device's access to the first cell.

[0185] Optionally, the processing unit 910 determines that the access is in the online signing stage based on at least one of the following:

[0186] If the first message includes an online signing instruction, then the access is in the online signing stage;

[0187] If the credential server fails to authorize the terminal device, the access is in the online signing stage; or

[0188] If no user plane context exists for the terminal device, the access is in the online signing phase.

[0189] Optionally, the processing unit 910 determines that the access is in the remote configuration phase based on at least one of the following:

[0190] If the first message does not include the online signing instruction, then the access is in the remote configuration phase;

[0191] If the credential server successfully authorizes the terminal device, the access is in the remote configuration phase; or

[0192] If the user plane context exists, the access is in the remote configuration phase.

[0193] (ii) In one possible design, the device 900 can be the access network device in the above method embodiments, or it can be a module (such as a chip) applied to the access network device. The device 900 can be used to execute the various steps or processes corresponding to the access network device in methods 300-800 described above. Specifically,

[0194] The transceiver unit 920 is configured to: send a first message to the core network device, the first message including the cell identifier of a first cell of the access network device to which the terminal device wants to access; and receive first indication information about access to the first cell from the core network device;

[0195] The processing unit 910 is configured to: determine that the first cell does not support online subscription; and, based on the first indication information, control the access of the terminal device to the first cell.

[0196] Optionally, the first indication information indicates restriction of the terminal device's access to the first cell, and wherein controlling access to the first cell includes:

[0197] The processing unit 910 is also configured to: restrict the terminal device's access to the first cell.

[0198] Optionally, restricting the terminal device's access to the first cell includes:

[0199] Processing unit 910 is further configured to: send a third message to the terminal device via transceiver unit 920, the third message including at least one of the following: a rejection indication, a rejection reason value, or a redirection indication for the terminal device.

[0200] Optionally, the transceiver unit 920 is further configured to: receive second indication information from the core network equipment, the second indication information indicating the cancellation of the access restriction on the first cell.

[0201] (III) In one possible design, the device 900 can be the terminal device in the above method embodiments, or it can be a module (such as a chip) applied to the terminal device. The device 900 can be used to execute the various steps or processes corresponding to the terminal device in methods 300-800 described above. Specifically,

[0202] The transceiver unit 920 is configured to: receive an online subscription capability indication from an access network device, the online subscription capability indication including online subscription capability information of at least one cell of the access network device, wherein the online subscription capability information of the at least one cell includes a cell identifier and a corresponding online subscription capability for at least one cell of the access network device;

[0203] Processing unit 910 is configured to: select a second cell from the at least one cell, the second cell supporting online subscription, based on the online subscription capability information of the at least one cell; and

[0204] The transceiver unit 920 is also used to send an online subscription request for the second cell to the access network device.

[0205] Optionally, the processing unit 910 is further configured to: determine candidate cells among the at least one cell that support online signing based on the online signing capability information of the at least one cell; and select a second cell from the candidate cells for camping.

[0206] The determination of the candidate cells is implemented at the access layer of the terminal device.

[0207] Optionally, the transceiver unit 920 is further configured to receive a fourth message from the core network equipment, the fourth message indicating that the online contract signing is complete; and

[0208] The processing unit 910 is also configured to: perform cell reselection or cell handover for the at least one cell, wherein the cell reselection or cell handover does not require online subscription capability information of the at least one cell.

[0209] Optionally, the processing unit 910 is further configured to: perform cell reselection or cell handover for the at least one cell based on the online subscription capability information of the at least one cell.

[0210] It should be understood that device 900 here is embodied in the form of a functional unit. The term "unit" here can refer to application-specific integrated circuits (ASICs), electronic circuits, processors (e.g., shared processors, proprietary processors, or group processors, etc.) and memories for executing one or more software or firmware programs, combined logic circuits, and / or other suitable components supporting the described functions. In an alternative example, those skilled in the art will understand that device 900 can be specifically a core network device in the above embodiments, used to execute the various processes and / or steps corresponding to the core network device in the above method embodiments; or, device 900 can be specifically a terminal device in the above embodiments, used to execute the various processes and / or steps corresponding to the terminal device in the above method embodiments; or, device 900 can be specifically an access network device in the above embodiments, used to execute the various processes and / or steps corresponding to the access network device in the above method embodiments. To avoid repetition, further details are omitted here.

[0211] The apparatus 900 in each of the above-described schemes has the function of implementing the corresponding steps performed by the core network equipment in the above-described method; or, the apparatus 900 in each of the above-described schemes has the function of implementing the corresponding steps performed by the terminal equipment in the above-described method; or, the apparatus 900 in each of the above-described schemes has the function of implementing the corresponding steps performed by the access network equipment in the above-described method. The functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions; for example, a communication unit can be replaced by a transceiver (e.g., the transmitting unit in the communication unit can be replaced by a transmitter, and the receiving unit in the communication unit can be replaced by a receiver), and other units, such as processing units, can be replaced by a processor, respectively executing the transmission and reception operations and related processing operations in each method embodiment.

[0212] In addition, the aforementioned communication unit can also be a transceiver circuit (for example, it may include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit.

[0213] Figure 10 A communication device 1000 provided in an embodiment of this application is shown. The device 1000 includes a processor 1010 and a transceiver 1020. The processor 1010 and the transceiver 1020 communicate with each other through an internal connection path. The processor 1010 is used to execute instructions to control the transceiver 1020 to send and / or receive signals.

[0214] Optionally, the device 1000 may further include a memory 1030, which communicates with the processor 1010 and the transceiver 1020 via an internal connection path. The memory 1030 stores instructions, and the processor 1010 can execute the instructions stored in the memory 1030. In one possible implementation, the device 1000 is used to implement the various processes and steps corresponding to the core network device in the above method embodiments. In another possible implementation, the device 1000 is used to implement the various processes and steps corresponding to the access network device in the above method embodiments. In yet another possible implementation, the device 1000 is used to implement the various processes and steps corresponding to the terminal device in the above method embodiments.

[0215] It should be understood that the device 1000 can specifically be a core network device, access network device, or terminal device in the above embodiments, or it can be a chip or chip system. Correspondingly, the transceiver 1020 can be the transceiver circuit of the chip, which is not limited here. Specifically, the device 1000 can be used to execute the various steps and / or processes corresponding to the core network device, access network device, or terminal device in the above method embodiments. Optionally, the memory 1030 may include read-only memory and random access memory, and provide instructions and data to the processor. A portion of the memory may also include non-volatile random access memory. For example, the memory may also store device type information. The processor 1010 can be used to execute the instructions stored in the memory, and when the processor 1010 executes the instructions stored in the memory, the processor 1010 is used to execute the various steps and / or processes of the above method embodiments corresponding to the core network device, access network device, or terminal device. In the implementation process, the various steps of the above method can be completed by the integrated logic circuits in the processor or by instructions in the form of software. The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are not provided here.

[0216] It should be noted that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuitry in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above methods.

[0217] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0218] According to the method provided in the embodiments of this application, this application also provides a computer program product, which includes: computer program code, which, when run on a computer, causes the computer to execute... Figures 3 to 8 The embodiments shown are core network equipment, access network equipment, or terminal equipment.

[0219] According to the method provided in the embodiments of this application, this application also provides a computer-readable storage medium storing program code, which, when executed on a computer, causes the computer to perform... Figures 3 to 8 The embodiments shown are core network equipment, access network equipment, or terminal equipment.

[0220] According to the method provided in the embodiments of this application, this application also provides a communication system, which may include core network equipment, access network equipment, and... Figures 3 to 8 Other network elements in the illustrated embodiment.

[0221] In the above-described embodiments of the apparatus and methods Figures 3 to 8 The illustrated embodiments are completely corresponding, with each module or unit performing its respective steps. For example, the communication unit (transceiver) performs the receiving or sending steps in the method embodiments, while other steps besides sending and receiving can be performed by the processing unit (processor). The function of a specific unit can be based on the corresponding method embodiments. There can be one or more processors.

[0222] In the embodiments of this application, the terms and English abbreviations are exemplary examples given for ease of description and should not be construed as limiting the application in any way. This application does not preclude the possibility of defining other terms that can achieve the same or similar functions in existing or future agreements.

[0223] In the embodiments of this application, the terms "first," "second," and various numerical designations are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. For example, they may be used to distinguish different core network devices or different attribute information.

[0224] As used in this specification, the terms "component," "module," "system," etc., are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. As illustrated, applications running on computing devices and computing devices can both be components. One or more components may reside in a process and / or an execution thread, and components may be located on a single computer and / or distributed among two or more computers. Furthermore, these components can be executed from various computer-readable storage media on which various data structures are stored. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component between a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).

[0225] Those skilled in the art will recognize that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0226] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be based on the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0227] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0228] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0229] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0230] In the above embodiments, the functions of each functional unit can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs), etc.

[0231] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0232] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for communication, characterized in that, The method includes: The core network device receives a first message from the access network device. The first message includes the cell identifier of the first cell of the access network device to which the terminal device wants to access, and the first message also indicates the online subscription capability of the first cell. The core network equipment determines that the first cell does not support online signing based on the cell identifier and the online signing capability of the first cell; and The core network equipment controls the access of the terminal equipment to the first cell.

2. The method according to claim 1, characterized in that, The method further includes: The core network device receives cell capability information from the access network device. The cell capability information includes a cell identifier and corresponding online subscription capability for at least one cell of the access network device, wherein the at least one cell includes the first cell; and Based on the cell capability information and the cell identifier of the first cell, the core network equipment determines that the first cell does not support the online subscription.

3. The method according to claim 2, characterized in that, The method further includes: The core network device receives an update message from the access network device, the update message indicating an update to the cell capability information.

4. The method according to claim 1, characterized in that, Controlling access to the first cell includes: The core network equipment restricts the terminal equipment from accessing the first cell.

5. The method according to claim 4, characterized in that, The restriction on the terminal device's access to the first cell is determined based on at least one of the following: The first message includes instructions for online signing; The credential server failed to authorize the terminal device; or There is no user plane context for the terminal device.

6. The method according to claim 4, characterized in that, The method further includes: The core network equipment determines that the terminal equipment's access to the first cell is in the online subscription stage, and the control of access to the first cell includes: The core network equipment restricts the terminal equipment from accessing the first cell.

7. The method according to claim 4 or 6, characterized in that, The core network equipment restricts the terminal device's access to the first cell by including: The core network device sends a second message to the terminal device, the second message including at least one of the following: a rejection indication, a rejection reason value, or a redirection indication.

8. The method according to claim 1, characterized in that, The method further includes: The core network equipment determines that the terminal device is in the remote configuration phase for access to the first cell, and the control of access to the first cell includes: The core network equipment determines that it will not restrict the terminal device's access to the first cell.

9. The method according to claim 1, characterized in that, The method further includes: The core network equipment determines that the terminal device's access to the first cell is in the remote configuration phase, and The control of access to the first cell includes: The core network equipment restricts the terminal equipment from accessing the first cell.

10. The method according to claim 6, characterized in that, The core network equipment determines that the access is in the online subscription stage based on at least one of the following: If the first message includes an online signing instruction, then the access is in the online signing stage; If the credential server fails to authorize the terminal device, the access is in the online signing stage; or If no user plane context exists for the terminal device, the access is in the online signing phase.

11. The method according to claim 8 or 9, characterized in that, The core network device determines that the access is in the remote configuration phase based on at least one of the following: If the first message does not include the online signing instruction, then the access is in the remote configuration phase; If the credential server successfully authorizes the terminal device, the access is in the remote configuration phase; or If a user plane context exists for the terminal device, the access is in the remote configuration phase.

12. A method for communication, characterized in that, The method includes: The access network device sends a first message to the core network device. The first message includes the cell identifier of the first cell of the access network device to which the terminal device wants to access. The first message also indicates the online subscription capability of the first cell. The cell identifier and the online subscription capability of the first cell are used to determine that the first cell does not support online subscription. The access network device receives first indication information about access to the first cell from the core network device; The access network device determines that the first cell does not support online subscription; and The access network device controls the terminal device's access to the first cell based on the first indication information.

13. The method according to claim 12, characterized in that, The first indication information indicates that the terminal device's access to the first cell is restricted, and wherein controlling access to the first cell includes: The access network device restricts the terminal device's access to the first cell.

14. The method according to claim 12, characterized in that, The access network device restricts the terminal device's access to the first cell by including: The access network device sends a third message to the terminal device, the third message including at least one of the following: a rejection indication, a rejection reason value, or a redirection indication for the terminal device.

15. The method according to claim 13, characterized in that, The method further includes: The access network device receives a second indication information from the core network device, the second indication information indicating that the restriction on access to the first cell is lifted.

16. A core network device, characterized in that, The core network equipment includes: At least one processing unit; and At least one memory is coupled to the at least one processing unit and stores instructions for execution by the at least one processing unit, which, when executed by the at least one processing unit, cause the core network device to implement the method according to any one of claims 1 to 11.

17. An access network device, characterized in that, The access network includes: At least one processing unit; and At least one memory, coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, which, when executed by the at least one processing unit, cause the access network to implement the method according to any one of claims 12 to 15.

18. A computer-readable storage medium having a computer program stored thereon, the computer program, when executed by a processor, implementing the method according to any one of claims 1 to 11 or any one of claims 12 to 15.

19. A chip configured to perform the method according to any one of claims 1 to 11 or any one of claims 12 to 15.