Method, device, apparatus and readable storage medium for supporting information acquisition

By transmitting detailed network configuration information and prioritizing external data, terminals can efficiently obtain certificates and subscriptions, addressing the challenges of onboarding to SNPNs without pre-existing certificates.

JP7723104B2Active Publication Date: 2025-08-13VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023545298
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-05-10
Filing Date
2022-02-08
Publication Date
2025-08-13
Estimated Expiration
2042-02-08

AI Technical Summary

Technical Problem

Terminals face challenges in obtaining configuration information from a first network for certificate and/or subscription, particularly in scenarios involving onboarding to a Standalone Non-Public Network (SNPN) without a pre-existing certificate, where conventional methods fail to provide sufficient address and related information for Unified Data Manager (UDM) indexing and prioritize local policy over external information.

Method used

The proposed solution involves transmitting specific information to a network, including address and configuration details of a first server, along with priority settings to ensure accurate indexing and configuration, enabling terminals to obtain certificates and subscriptions efficiently.

Benefits of technology

This approach allows terminals to effectively acquire necessary configuration information and certificates/subscriptions by ensuring correct indexing and prioritization of external information, overcoming limitations in conventional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007723104000001
    Figure 0007723104000001
  • Figure 0007723104000002
    Figure 0007723104000002
  • Figure 0007723104000003
    Figure 0007723104000003
Patent Text Reader

Abstract

The present application discloses a method, an apparatus, a device, and a readable storage medium for supporting information acquisition, the method including transmitting first information, including first configuration information and / or related information of the first configuration information, to a first network.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to Chinese Patent Application No. 202110185490.7 filed in China on February 10, 2021, claims priority to Chinese Patent Application No. 202110368840.3 filed in China on April 6, 2021, and claims priority to Chinese Patent Application No. 202110507934.4 filed in China on May 10, 2021, the entire contents of which are incorporated herein by reference.

[0002] The present application relates to the field of communications technology, and specifically to methods, apparatus, devices and readable storage media for supporting information acquisition. [Background technology]

[0003] A terminal (e.g., User Equipment (UE)) wants to temporarily access a first network to obtain a certificate and / or a subscription, but how the terminal obtains configuration information from the first network to obtain the certificate and / or the subscription is an urgent problem to be solved. Summary of the Invention [Problem to be solved by the invention]

[0004] Embodiments of the present application provide a method, an apparatus, a device, and a readable storage medium for supporting information acquisition that solve the problem of how a terminal obtains configuration information from a first network for obtaining a certificate and / or a subscription. [Means for solving the problem]

[0005] According to a first aspect, there is provided a method of supporting information acquisition performed by a first communications device, the method comprising: transmitting first information to a first network, the first information including first configuration information and / or information related to the first configuration information; where: the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; instruction information for instructing a first access method; slice information associated with the first placement information; and DN information related to the first configuration information.

[0006] According to a second aspect, there is provided a method of supporting information acquisition performed by a second communications device, the method comprising: Obtaining first information including first location information and / or information related to the first location information; performing a first operation based on the first information; Here, the first operation is: storing the first information; generating index information of the first configuration information, the index information being one or more of the related information of the first configuration information for the first configuration information; generating index information of a first server for address information of the first server, the index information being one or more of the related information of the first server; Obtaining first request information and querying or receiving first placement information based on the first request information; Transmitting the queried or ordered first location information and / or information related to the first location information; Acquire slice information and / or DN information of a terminal, and confirm first configuration information related to the slice information and / or DN information of the terminal based on the slice information and / or DN information of the terminal; Transmitting first configuration information and / or related information of the first configuration information related to slice information of the terminal and / or DN information of the terminal; Selecting a first target end and / or selecting a data channel for the terminal; transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal; setting a priority of the first information higher than a priority of policy information related to the data operation; where: the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; slice information associated with the first placement information; DN information related to the first placement information; and instruction information for instructing a first access method, the instruction information indicating one of that the first deployment service information is to be used for a terminal accessing the first network via the first access method, and that the first server is capable of deploying a certificate and / or a subscription of the first target for a terminal accessing the first network via the first access method.

[0007] According to a third aspect, there is provided a method of supporting information acquisition performed by a third communications device, the method comprising: Acquiring second information, wherein the second information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, slice information related to the second target, DN information related to the second target, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information of a terminal, DN information of a terminal, connection establishment request information, registration request information, and data channel establishment request information; performing a second operation based on the second information; wherein the second operation is: selecting or querying a target communication device based on the second information; Sending first request information to the target communication device; and transmitting the second information; Here, the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization.

[0008] According to a fourth aspect, there is provided a method of supporting information acquisition performed by a fourth communications device, the method comprising: Obtaining network element query information and / or communication device index information, wherein the network element query information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information, and DN information; performing a third operation based on the network element query information and / or the communication device index information; Here, the third operation is Matching a target communication device based on the network element query information; and transmitting information about the target communication device.

[0009] According to a fifth aspect, there is provided a method of supporting information acquisition performed by a fifth communications device, the method comprising: and a fourth acquiring module for acquiring the first configuration information and / or information related to the first configuration information.

[0010] According to a sixth aspect, there is provided a method of supporting information acquisition performed by a sixth communications device, the method comprising: sending network element registration information, the network element registration information including at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a third object, group identifier information of a network group to which the third object belongs, identifier information of a third network, and group identifier information of the third network group; Here, the third object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.

[0011] According to a seventh aspect, there is provided an apparatus for supporting information acquisition for use in a first communications device, the apparatus comprising: a first transmitting module for transmitting first information, including first configuration information and / or information related to the first configuration information, to a first network; where: the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; instruction information for instructing a first access method; slice information associated with the first placement information; and DN information related to the first configuration information.

[0012] According to an eighth aspect, there is provided an apparatus for supporting information acquisition for use in a second communication device, the apparatus comprising: a first acquiring module for acquiring first information including first location information and / or related information of the first location information; a first execution module for executing a first operation based on the first information; Here, the first operation is: storing the first information; generating index information of the first configuration information, the index information being one or more of the related information of the first configuration information for the first configuration information; generating index information of a first server for address information of the first server, the index information being one or more of the related information of the first server; Obtaining first request information and querying or receiving first placement information based on the first request information; Transmitting the queried or ordered first location information and / or information related to the first location information; Acquire slice information and / or DN information of a terminal, and confirm first configuration information related to the slice information and / or DN information of the terminal based on the slice information and / or DN information of the terminal; Transmitting first configuration information and / or related information of the first configuration information related to slice information of the terminal and / or DN information of the terminal; Selecting a first target end and / or selecting a data channel for the terminal; transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal; setting a priority of the first information higher than a priority of policy information related to the data operation; where: the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; slice information associated with the first placement information; DN information related to the first placement information; and instruction information for instructing a first access method, the instruction information indicating one of that the first deployment service information is to be used for a terminal accessing the first network via a first access method, and that the first server is capable of deploying a certificate and / or a subscription of the first target for a terminal accessing the first network via the first access method.

[0013] According to a ninth aspect, there is provided an apparatus for supporting information acquisition for use in a third communication device, the apparatus comprising: a second acquisition module for acquiring second information, the second information including at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, slice information related to the second target, DN information related to the second target, identifier information of a second network, group identifier information of a second network group, the second network group being a network group to which the second network belongs, slice information of a terminal, DN information of a terminal, connection establishment request information, registration request information, and data channel establishment request information; a second execution module for executing a second operation based on the second information; wherein the second operation is: selecting or querying a target communication device based on the second information; Sending first request information to the target communication device; and transmitting the second information; Here, the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization.

[0014] According to a tenth aspect, there is provided an apparatus for supporting information acquisition for use in a fourth communication device, the apparatus comprising: a third obtaining module for obtaining network element query information and / or communication device index information, wherein the network element query information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information, and DN information; and a third acquisition module; a third execution module for performing a third operation based on the network element query information and / or the communication device index information; Here, the third operation is Matching a target communication device based on the network element query information; and transmitting information about the target communication device.

[0015] According to an eleventh aspect, there is provided an apparatus for supporting information acquisition for use in a fifth communication device, the apparatus comprising: and a fourth acquiring module for acquiring the first configuration information and / or information related to the first configuration information.

[0016] According to a twelfth aspect, there is provided an apparatus for supporting information acquisition for use in a sixth communication device, the apparatus comprising: a third sending module for sending network element registration information, wherein the network element registration information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a third object, group identifier information of a network group to which the third object belongs, identifier information of a third network, and group identifier information of the third network group; Here, the third object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.

[0017] According to a thirteenth aspect, there is provided a terminal including a processor, a memory, and a program stored in the memory and operable to run on the processor, the program performing the steps of the method of the fifth aspect when executed by the processor.

[0018] According to a fourteenth aspect, there is provided a network side device, the network side device including a processor, a memory, and a program stored in the memory and operable to run on the processor, the program implementing the steps of the method according to the first, second, third, fourth or sixth aspect when executed by the processor.

[0019] According to a fifteenth aspect, there is provided a readable storage medium having stored thereon a program or instructions which, when executed by a processor, implement the steps of the method described above.

[0020] According to a sixteenth aspect, there is provided a computer program product, the computer program product being stored on a non-transitory storage medium, the computer program product being executed by at least one processor to implement the steps of the methods described above.

[0021] According to a seventeenth aspect, there is provided a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor running a program or instructions and used to implement the steps of the method described above. [Effects of the Invention]

[0022] An embodiment of the present application supports a terminal to obtain configuration information, the configuration information including address information of a first server, and the terminal can obtain a certificate and / or a subscription from the first server via a first network. [Brief explanation of the drawings]

[0023] [Figure 1] 1 is a schematic diagram of a method for supporting information acquisition according to an embodiment of the present application; [Figure 2] 2 is a second schematic diagram of a method for supporting information acquisition according to an embodiment of the present application; [Figure 3] 3 is a third schematic diagram of a method for supporting information acquisition according to an embodiment of the present application. [Figure 4] 4 is a fourth schematic diagram of a method for supporting information acquisition according to an embodiment of the present application. [Figure 5] 5 is a fifth schematic diagram of a method for supporting information acquisition according to an embodiment of the present application. [Figure 6] 6 is a sixth schematic diagram of a method for supporting information acquisition according to an embodiment of the present application. [Figure 7-A] 1 is a schematic diagram of a method for supporting information acquisition according to an embodiment of the present application; [Figure 7-B] 1 is a schematic diagram of a method for supporting information acquisition according to an embodiment of the present application; [Figure 8] 1 is a schematic diagram of an apparatus for supporting information acquisition according to an embodiment of the present application; [Figure 9] 2 is a second schematic diagram of an apparatus supporting information acquisition according to an embodiment of the present application; [Figure 10] 3 is a third schematic diagram of an apparatus for supporting information acquisition according to an embodiment of the present application. [Figure 11] 4 is a fourth schematic diagram of an apparatus for supporting information acquisition according to an embodiment of the present application. [Figure 12] 5 is a fifth schematic diagram of an apparatus for supporting information acquisition according to an embodiment of the present application. [Figure 13]6 is a sixth schematic diagram of an apparatus for supporting information acquisition according to an embodiment of the present application. [Figure 14] 1 is a schematic diagram of a terminal according to an embodiment of the present application; [Figure 15] FIG. 1 is a schematic diagram of a network-side device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0024] In order to more clearly explain the technical solutions of the embodiments of the present application, the above briefly introduces the drawings that need to be used in the description of the embodiments of the present application. It is obvious that the drawings in the above description are only some embodiments of the present application, and those skilled in the art can derive other drawings based on these drawings without any creative effort. The following clearly and completely describes the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. All other embodiments that can be obtained based on the embodiments of the present application without any creative effort by those skilled in the art fall within the scope of protection of the present application.

[0025] The terms "first," "second," etc., used in the specification and claims of this application are intended to distinguish between similar objects and are not intended to describe a particular order or sequence. It should be understood that terms used in this manner are interchangeable where appropriate, so that embodiments of this application may be performed in orders other than those illustrated or described herein, and that objects distinguished by "first" and "second" generally are of the same type and do not limit the number of objects; for example, a first object may be one or more. Furthermore, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / " generally indicates that the related objects are in an "and / or" relationship.

[0026] It should be noted that the techniques described in the embodiments of the present application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be applied to other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in the embodiments of the present application are always used interchangeably, and the described techniques may be used in the above-mentioned systems and radio technologies as well as other systems and radio technologies. However, although the following description describes New Radio (NR) systems for illustrative purposes and uses NR terminology in most of the following description, these technologies may also be used in applications other than NR system applications, such as sixth generation (6G) systems. th This may be applied to 6G (6th Generation) communication systems.

[0027] In the related art, a terminal (e.g., User Equipment (UE)) can access a Public Land Mobile Network (PLMN) or a Standalone Non-Public Network (SNPN) 1 to download a certificate for an SNPN 2. If the UE does not have a certificate for an SNPN 1, and the SNPN 1 supports an onboarding function, the SNPN 1 is called an onboarding SNPN, or may be abbreviated as an O-SNPN. In the case of an onboarding SNPN, the UE does not have a certificate for an O-SNPN and must access the O-SNPN using a default credential and provide an onboarding instruction to explain the particularity of the UE's registration type. Therefore, in an O-SNPN scenario, (1) Default credential onboarding and (2) Includes two functions: downloading certificates and / or subscriptions.

[0028] For user plane certificate download, the UE may need to obtain a Provisioning Server (PS) address from the SNPN1 or PLMN. The Application Function (AF) can configure the PS address that needs to be configured in the UE in the network.

[0029] Problem 1: Because the UE only has default credentials, the AF cannot provide the associated Generic Public Subscription Identifier (GPSI) or UE Group ID. An O-SNPN may serve multiple SO-SNPNs, and the PS addresses corresponding to each SO-SNPN may be different. Therefore, it is not enough for the AF to provide only the PS address; it must also provide the PS address and related information, such as the SO-SNPN ID and SO-SNPN Group ID.

[0030] One solution is for the UE to register with the Access and Mobility Management Function (AMF) of the first network (e.g., O-SNPN) and provide instruction information (e.g., an onboarding instruction) to indicate the first access method. The AMF cannot index the Unified Data Manager (UDM) or Unified Data Repository (UDR) of the O-SNPN based on the UE's UE identifier (ID) (e.g., a Subscriber Permanent Identifier (SUPI)). However, the AMF can index the UDM or UDR for onboarding based on the onboarding instruction and query or order the address information of the first server from the UDM or UDR. If there are multiple first servers, the UE can also provide related information of the first location server, such as the identifier information of the second target (e.g., SO-SNPN), during registration to request the acquisition of the address information of the first server corresponding to the SO-SNPN.

[0031] Problem 2: Conventional information indexes (such as data keys) only support terminal identifiers or terminal group identifiers. However, when the AF allocates the address information of the first server in the first network, it cannot determine which terminals access the first network to obtain it. Therefore, the information index based on the terminal identifier or terminal group identifier cannot index the address information of the first server.

[0032] One solution is to add a new data key: SO-SNPN ID or onboarding indication to index the information.

[0033] Problem 3: The decisions of core network elements, such as UDM, UDR and Policy Control function (PCF), cannot be determined by the Subscription Permanent Identifier (SUPI) associated with the UE's default certificate.

[0034] One solution is to determine by onboarding instruction, that is, there exists a core network element in the first network that is dedicated to the onboarding method.

[0035] Another solution concept is to determine by the SO-SNPN identifier, i.e., there is a core network element in the first network that is dedicated to the SO-SNPN.

[0036] Problem 4: If there are multiple configuration server addresses to be configured in the UE, additional information related to each configuration server address needs to be provided, otherwise the UE will not know how to select and use one of the configuration server addresses.

[0037] Problem 5: In the conventional definition, the priority of a policy and charging control rule (PCC rule) is higher than the priority of the first information stored locally in the SMF or higher than the priority of a data manipulation rule configured based on the locally stored first information. Because the externally acquired first information is the latest, it should have a higher priority. If the PCF still acquires the PCC rule based on the locally stored first information when configuring the PCC rule, an error occurs when the SMF configures the data manipulation rule based on the PCC rule because the priority according to the conventional PCC rule is higher than the priority of the first information stored locally in the SMF. Therefore, one solution is to send or receive the latest first information to the PCF and configure the priority of the acquired first information higher than the priority of the PCC rule.

[0038] In one embodiment, local storage and local placement may be mixed.

[0039] In one optional embodiment of the present application, selectively, acquisition or acquisition may be understood as acquisition from configuration, reception, reception after request, acquisition by self-learning, derivation and acquisition based on unreceived information, or acquisition after processing based on received information, and may be specifically determined according to actual needs, and the embodiment of the present application is not limited thereto. For example, if a certain capability indication information transmitted by a device is not received, it can be deduced that the device does not support this capability.

[0040] In one alternative embodiment of the present application, the sending may include broadcasting, broadcasting in a system message, or returning after responding to a request.

[0041] In one alternative embodiment of the present application, "to be able to" may refer to at least one of allowing, supporting, being inclined, and preferentially having the ability. "To not be able to" may refer to at least one of not allowing, not supporting, not being inclined, and not having the ability.

[0042] In one alternative embodiment of the present application, the communication equipment may include at least one of a communication network element and a terminal.

[0043] In one alternative embodiment of the present application, the communication network element may include at least one of a core network element and a Radio Access Network (RAN) network element.

[0044] In one alternative embodiment of the present application, the Core Network (CN) network elements include a Core Network Equipment, a Core Network Node, a Core Network Function, a Core Network Element, a Mobility Management Entity (MME), an Access Management Function (AMF), a Session Management Function (SMF), a User Plane Function (UPF), a Serving Gateway (SGW), a PDN Gateway (PDN Gateway), a Policy Control Function (PCF), a Policy and Charging Rules Function (PCRF), a Serving GPRS Support Node (SGSN), a Gateway GPRS Support Node (GGSN), a Unified Data Management (UDM), a Unified Data Repository (UDR), and a Home Subscriber Server (HSS). The HSS may include, but is not limited to, at least one of a Server (HSS) and an Application Function (AF).

[0045] In one alternative embodiment of the present application, the RAN network element may include at least one of, but is not limited to, a radio access network device, a radio access network node, a radio access network function, a radio access network unit, a 3rd Generation Partnership Project (3GPP®) radio access network, a non-3GPP® radio access network, a centralized unit (CU), a distributed unit (DU), a base station, an evolved base station (evolved Node B (eNB), a 5G base station (gNB), a radio network controller (RNC), a base station (NodeB), a non-3GPP® Inter Working Function (N3IWF), an access control (AC) node, an access point (AP) device or a wireless local area network (WLAN) node, and an N3IWF.

[0046] In one alternative embodiment of the present application, the first access method includes at least one of an access method for accessing a network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate; In one embodiment, the method of employing restricted network access to download a certificate for accessing a first target or the method of accessing a network to download a certificate for accessing a first target may be referred to as onboarding. When the first target includes an A network, the first network and the A network may be the same network or different networks. The first network is a network that the terminal accesses, for example, a currently accessed network.

[0047] In one alternative embodiment of the present application, the first server is used as a server that deploys the certificate and / or subscription of the first subject for the terminal.

[0048] In one alternative embodiment of the present application, supporting certificate and / or subscription deployment is further used to indicate at least one of supporting certificate and / or subscription deployment in a control plane manner and supporting certificate and / or subscription deployment in a user plane manner.

[0049] In one alternative embodiment of the present application, the above-mentioned not supporting certificate and / or subscription deployment is further used to indicate not supporting certificate and / or subscription deployment in a control plane manner and not supporting certificate and / or subscription deployment in a user plane manner.

[0050] In one alternative embodiment of the present application, obtaining the certificate and / or subscription is obtaining the certificate and / or subscription remotely, for example, when the terminal accesses a first network to obtain the certificate and / or subscription, the provider of the certificate and / or subscription is a first entity, which may be an entity in a data network (DN) or an entity other than the network accessed by the terminal.

[0051] In one alternative embodiment of the present application, the certificate and / or subscription provider is one of an entity other than the first network, an entity other than the network accessed by the terminal, an entity in a data network (DN), and an entity in another network. The entity in the data network may be an application server, a certificate and / or subscription deployment server in the data network. The goal of the terminal accessing the network includes obtaining a certificate and / or subscription.

[0052] In one alternative embodiment of the present application, the certificates and / or subscriptions are certificates and / or subscriptions of networks accessed by the terminal, including at least one of certificates and / or subscriptions of networks used for unrestricted access of the terminal and certificates and / or subscriptions of networks used for restricted access of the terminal.

[0053] In one alternative embodiment of the present application, the certificates and / or subscriptions include at least one of a certificate and / or subscription used for unrestricted access, a certificate and / or subscription used for restricted access, a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization. Primary authentication (e.g., Primary Authentication) may be performed using Authentication and Key Agreement (AKA), e.g., in 5G (5th Generation) communications technology (5G). th This may include 5G (5th Generation) AKA, and Extensible Authentication Protocol (EAP) AKA.

[0054] The non-primary authentication and / or authorization may include at least one of secondary authentication and / or authorization and slice-related authentication and / or authorization (NSSAA Network Slice-Specific Authentication and Authorization). For ease of understanding, slice information related to non-primary authentication and / or authorization may include slice information related to "slice-related authentication and / or authorization" and may represent authentication and / or authorization of whether to allow a terminal to access a slice indicated by the slice information. DN information related to non-primary authentication and / or authorization and / or slice information related to non-primary authentication and / or authorization may include slice information and / or DN information related to secondary authentication and / or authorization and may represent authentication and / or authorization of whether to allow a terminal to access the slice and / or DN.

[0055] In one embodiment, the slice information may represent information about a slice.

[0056] In one embodiment, the slice information may include one of Single Network Slice Selection Assistance Information (S-NSSAI) and Network Slice Selection Assistance Information (NSSAI).

[0057] In one embodiment, the DN information may represent information about a DN.

[0058] In one embodiment, the DN information may include at least one of a Data Network Name (DNN) (which may also be referred to as an Access Point Name (APN)) and DN identifier information.

[0059] In one embodiment, the terminal may access a first network using a credential (e.g., a default credential) and / or a subscription for restricted access to the network, and obtain a credential and / or a subscription for unrestricted access to a first target (including an A network) via the first network, where the A network may be the same as or different from the first network.

[0060] In one alternative embodiment of the present application, obtaining the certificate and / or the subscription in a control plane manner and / or configuring the certificate and / or the subscription in a control plane manner includes at least one of: a first entity configuring the certificate and / or the subscription to the terminal via control plane signaling of a network accessed by the terminal; and the terminal obtaining the certificate and / or the subscription from the first entity via control plane signaling of a network accessed by the terminal; In one alternative embodiment of the present application, obtaining the certificate and / or subscription in a user plane manner and / or deploying the certificate and / or subscription in a user plane manner includes at least one of the terminal establishing a data channel in a network to be accessed and obtaining the certificate and / or subscription from a first entity via the data channel, or the first entity deploying the certificate and / or subscription to the terminal via a data channel established in a network to be accessed by the terminal.

[0061] In one alternative embodiment of the present application, the data channel includes at least one of the following, which may include, but is not limited to, one of a Protocol Data Unit (PDU) session, a Public Data Network (PDN) connection, a Quality of Service (QoS) flow, a bearer, and an Internet Protocol Security (IPsec) channel, where the bearer may be an Evolved Radio Access Bearer (E-RAB), a Radio Access Bearer (RAB), a Data Radio Bearer (DRB), a Signaling Radio Bearer (SRB), etc.

[0062] In one alternative embodiment of the present application, allowing access to a network using a default certificate includes accessing a network to which a terminal can obtain restricted connectivity using a terminal identifier corresponding to the default certificate.

[0063] In one alternative embodiment of the present application, the default credentials include credentials used for restricted access schemes.

[0064] In one alternative embodiment of the present application, restricted access and restricted connectivity are synonymous and may be used interchangeably.

[0065] In one embodiment, the restricted access includes at least one of only allowing the establishment of a first data channel, not allowing the establishment of data channels other than the first data channel, only allowing the acquisition of certificates and / or subscriptions, and not allowing the acquisition of services other than certificates and / or subscriptions. The first data channel is used to acquire certificate and / or subscription data channels.

[0066] In one embodiment, the restricted access may allow for obtaining a certificate and / or subscription for the first subject.

[0067] In one alternative embodiment of the present application, the restricted access includes restricted control plane access and / or restricted user plane access.

[0068] In one alternative embodiment of the present application, the restricted connectivity includes a restricted control plane connection and / or a restricted user plane connection over which certificates and / or subscriptions can be obtained.

[0069] In one alternative embodiment of the present application, the network that can be accessed using the default certificate includes being able to access the network using a terminal identifier that corresponds to the default certificate and be authenticated and / or authorized by the network via the default certificate.

[0070] In one alternative embodiment of the present application, the subscription includes subscription data, such as slice information, Data Network Name (DNN), and the like.

[0071] In one alternative embodiment of the present application, the second communication device, the third communication device, the fourth communication device, and / or the sixth communication device are communication devices in the first network.

[0072] In one alternative embodiment of the present application, the objects (e.g., a first object, a second object, a third object) include at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization; wherein the A network is the same as or different from the first network; Here, the A network may be the same as or different from the network that the terminal accesses.

[0073] In one alternative embodiment of the present application, the network type of the first network, the network accessed by the terminal and / or the network A includes at least one of a public net, a non-public net, a Public Land Mobile Network (PLMN), a Public Network Integrated Non-Public Network (PNI NPN), and a Standalone Non-Public Network (SNPN).

[0074] In one alternative embodiment of the present application, the indication information for indicating the first access method may be embodied as a registration type for identifying a registration of the first access method type.

[0075] In one alternative embodiment of the present application, the A network or second network includes a certificate and / or subscription holder's SNPN network (eg, SO-SNPN).

[0076] In one embodiment, the first server comprises a server that configures certificates and / or subscription information for the terminal; The certificate and / or subscription information may be at least one of a certificate and / or subscription information for accessing a first subject, a primary authentication and / or authorization certificate and / or subscription, and a non-primary authentication and / or authorization certificate and / or subscription information.

[0077] The non-primary authentication and / or authorization may include at least one of a secondary authentication and / or authorization and a secondary authentication and / or authorization associated with a slice; the first object includes a slice of a network, a DN, and a network; The network type includes at least one of an SNPN, a PNI NPN, and a PLMN.

[0078] In one embodiment, the slice information of the terminal includes at least one of slice information requested by the terminal, slice information allowed for the terminal, slice information of the terminal's subscription, and slice information in which the terminal is located.

[0079] In one embodiment, the slice information requested by the terminal includes at least one of slice information requested by the terminal when establishing a session and slice information requested by the terminal when registering with the network.

[0080] In one embodiment, the DN information of the terminal includes at least one of DN information requested by the terminal, allowed DN information of the terminal, DN information of the terminal's subscription, and DN information where the terminal is located.

[0081] In one embodiment, the DN information requested by the terminal includes at least one of DN information requested by the terminal when establishing a session and DN information requested by the terminal when registering with the network.

[0082] For ease of understanding, non-primary authentication (e.g., secondary authentication and slice authentication) is associated with the slice of the terminal and / or the DN information of the terminal. When it is necessary to locate the address of the first server corresponding to the certificate download of the non-primary authentication for the terminal, the association may be performed using the slice information of the terminal and / or the DN information of the terminal.

[0083] In one embodiment, the registration request information (including the registration request message) includes slice information requested by the terminal.

[0084] In one embodiment, the data channel (e.g., PDU session) establishment request information (including a data channel establishment request message) includes at least one of slice information requested by the terminal and DN information requested by the terminal.

[0085] In one embodiment, the terminal establishes a connection with the network by means of connection establishment request information (eg, connection establishment request message, service request message).

[0086] For ease of understanding, non-primary authentication (e.g., secondary authentication and slice authentication) may be associated with the slice of the terminal and / or the DN information of the terminal. When it is necessary to locate the certificate of the non-primary authentication for the terminal and download the corresponding first server, the association may be made using the slice information of the terminal and / or the DN information of the terminal.

[0087] In one embodiment, when the first configuration information includes address information of multiple first servers, the terminal can obtain the first configuration information and associated information of the first configuration information to support determining which associated information each first server is associated with. For example, the first server A is associated with slice A, and the second server B is associated with slice B.

[0088] In the following, in conjunction with the drawings, a method, an apparatus, a device and a readable storage medium supporting information acquisition according to the embodiments of the present application will be described in detail through several embodiments and application scenarios thereof.

[0089] Referring to FIG. 1 , an embodiment of the present application provides a method for supporting information acquisition performed by a first communication device, where the first communication device includes, but is not limited to, one of an AF, a Network Exposure Function (NEF), a Default Credentials Server (DCS), an Authentication Server Function (AUSF) (e.g., AUSF in the DCS), a UDM (e.g., UDM in the DCS), and a core network element, and specific steps include step 101.

[0090] Step 101: Sending first information to a first network, the first information including first configuration information and / or information related to the first configuration information; In one alternative embodiment of the present application, the first configuration information may be referred to as configuration information used for a first access method.

[0091] In one alternative embodiment of the present application, the first configuration information includes address information of a first server, and the first server can configure a certificate and / or a subscription of a first subject for a terminal (e.g., a terminal accessing a first network); In one alternative embodiment of the present application, the related information of the first configuration information includes at least one of the following:

[0092] (1) Identifier information of the first subject; (2) group identifier information of the network group to which the first target belongs; (3) slice information associated with the first object; (4) DN information associated with the first subject; (5) Identifier information of the network to which the first server belongs; (6) group identifier information of the network group to which the first server belongs; (7) type information of the certificate and / or subscription; (8) Indication information for instructing a first access method, in one alternative embodiment of the present application, the first object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization; (9) slice information related to the first placement information; (10) DN information related to the first placement information; wherein the A network is the same as or different from the first network; and / or the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization; and / or The instruction information for instructing a first access method indicates one of: that the first configuration service information is used for a terminal accessing the first network via a first access method; and that the first server can configure a first target certificate and / or subscription for a terminal accessing the first network via the first access method; and / or a terminal accessing the first network accesses the first network using a first access method; and / or the first server includes at least one of a first server used for a primary authentication and / or authorization arrangement and a first server used for a non-primary authentication and / or authorization arrangement; wherein the first server used for the primary authentication and / or authorization configuration can configure a first target certificate and / or subscription for the terminal, and the certificate and / or subscription is used for the primary authentication and / or authorization; A first server used for the non-primary authentication and / or authorization configuration can configure a certificate and / or subscription of a first subject for the terminal, and the certificate and / or subscription is used for the non-primary authentication and / or authorization.

[0093] In one alternative embodiment of the present application, the network type of the first network, the network accessed by the terminal and / or the network A includes at least one of a public net, a non-public net, a Public Land Mobile Network (PLMN), a Public Network Integrated Non-Public Network (PNI NPN), and a Standalone Non-Public Network (SNPN).

[0094] In one embodiment, the slice information includes at least one of slice information associated with a primary authentication and / or authorization and slice information associated with a non-primary authentication and / or authorization.

[0095] In one embodiment, the DN information includes at least one of DN information associated with a primary authentication and / or authorization and DN information associated with a non-primary authentication and / or authorization.

[0096] In one embodiment, a primary authentication and / or authorization-related object may represent a primary authentication and / or authorization process that determines whether to allow a terminal to access the object. The primary authentication and / or authorization-related object may include at least one of a slice (e.g., a slice specified by the slice information) and a DN (e.g., a DN specified by the DN information).

[0097] In one embodiment, a non-primary authentication and / or authorization-related object represents a non-primary authentication and / or authorization process that determines whether to allow a terminal to access the object. The non-primary authentication and / or authorization-related object includes at least one of a slice (e.g., a slice specified by the slice information) and a DN (e.g., a DN specified by the DN information).

[0098] In one alternative embodiment of the present application, the address information of the first server includes at least one of an Internet Protocol address of the first server, a media access control address of the first server, a port number of the first server, a protocol version of the first server, and index information of the first server address.

[0099] In one alternative embodiment of the present application, the index information of the first server address includes at least one of a Fully Qualified Domain Name (FQDN) of the first server and a Uniform Resource Locator (URL) of the first server.

[0100] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0101] For example, if the first communication device is an AF, the AF can provide onboarding configuration data, including a PS address and a corresponding SO-SNPN identifier, to the O-SNPN or O-PLMN, store it in the UDR, and generate a new data key, such as a SO-SNPN identifier or a SO-SNPN group identifier or an onboarding identifier.

[0102] In an embodiment of the present application, first configuration information is supported for providing to a first network, thereby facilitating the first network to configure the first configuration information for a terminal. The first configuration information includes address information of a first server, and the terminal can obtain a certificate and / or a subscription from the first server via the first network. At the same time, the related information of the first configuration can also support filtering of the first configuration information, so as to facilitate the terminal to obtain the first configuration information that it actually wants.

[0103] Referring to Figure 2, an embodiment of the present application provides a method for supporting information acquisition performed by a second communication device, where the second communication device includes, but is not limited to, one of core network elements (e.g., UDM, UDR, AMF, SMF, PCF), and the specific steps include:

[0104] Step 201: Obtaining first information including first configuration information and / or information related to the first configuration information; Step 202: performing a first operation based on the first information; In one alternative embodiment of the present application, the first operation includes at least one of the following:

[0105] (1) storing the first information; (2) generating index information (e.g., data key) of the first configuration information, which is one or more pieces of related information of the first configuration information; (3) generating index information (e.g., data key) of the first server for the address information of the first server, the index information being one or more of the related information of the first server; (4) obtaining first request information, and querying or receiving first placement information based on the first request information; In one embodiment, the first request information is used to request first configuration information (including address information of the first server); In one embodiment, the first request is a first order request for ordering first configuration information (e.g., address information of a first server); (5) transmitting the queried or ordered first placement information and / or information related to the first placement information; Obtaining slice information and / or DN information of a terminal, and confirming first configuration information related to the slice information and / or DN information of the terminal based on the slice information and / or DN information of the terminal; Transmitting first configuration information and / or related information of the first configuration information related to slice information of the terminal and / or DN information of the terminal; Selecting a first target end and / or selecting a data channel of the terminal; Sending the first information to a first target end and / or sending the first information via associated signaling of a data channel of the terminal; The priority of the first information is set higher than the priority of the policy information related to the data operation.

[0106] Optionally, when transmitting the queried or ordered first location information, related information of the first location information is also transmitted at the same time.

[0107] In one embodiment, if acquisition of the first requested information occurs before acquisition of the first information, wait until after the first information is acquired before sending the requested first configuration information. In one embodiment, if the first configuration information has changed, send the ordered first configuration information.

[0108] In one embodiment, the queried or ordered first configuration information is sent to the communication device that sends the first request information, and optionally, related information of the first configuration information may be simultaneously sent to the communication device that sends the first request information.

[0109] In one alternative embodiment of the present application, the first configuration information includes address information of a first server, and the first server can configure a certificate and / or a subscription of a first subject for the terminal; The related information of the first location information includes at least one of the following:

[0110] (1) identifier information of the first object; (2) group identifier information of the network group to which the first target belongs; (3) slice information associated with the first object; (4) DN information associated with the first subject; (5) Identifier information of the network to which the first server belongs; (6) group identifier information of the network group to which the first server belongs; (7) type information of the certificate and / or subscription; (8) Indication information for instructing a first access method. In one alternative embodiment of the present application, the first object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization; (9) slice information related to the first placement information; (10) DN information related to the first placement information; wherein the A network is the same as or different from the first network; and / or the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization; and / or a terminal accessing the first network accesses the first network using a first access method; and / or the first server includes at least one of a first server used for a primary authentication and / or authorization arrangement and a first server used for a non-primary authentication and / or authorization arrangement; wherein the first server used for the primary authentication and / or authorization configuration can configure a first target certificate and / or subscription for the terminal, and the certificate and / or subscription is used for the primary authentication and / or authorization; A first server used for the non-primary authentication and / or authorization configuration can configure a certificate and / or subscription of a first subject for the terminal, and the certificate and / or subscription is used for the non-primary authentication and / or authorization.

[0111] In one alternative embodiment of the present application, the network type of the first network and / or the network type of the A network includes at least one of a public net, a non-public net, a PLMN, a PNI NPN, and an SNPN.

[0112] In one embodiment, the slice information includes slice information of a terminal; In one embodiment, the DN information includes DN information of a terminal; In one embodiment, the slice information of the terminal includes at least one of slice information requested by the terminal, slice information allowed for the terminal, slice information of the terminal's subscription, and slice information in which the terminal is located.

[0113] In one embodiment, the slice information requested by the terminal includes at least one of slice information requested by the terminal when establishing a session and slice information requested by the terminal when registering with the network.

[0114] In one embodiment, the DN information of the terminal includes at least one of DN information requested by the terminal, allowed DN information of the terminal, DN information of the terminal's subscription, and DN information where the terminal is located.

[0115] In one embodiment, the DN information requested by the terminal includes at least one of DN information requested by the terminal when establishing a session and DN information requested by the terminal when registering with the network.

[0116] For ease of understanding, non-primary authentication (e.g., secondary authentication and slice authentication) is associated with the slice of the terminal and / or the DN information of the terminal. When it is necessary to locate the address of the first server corresponding to the certificate download of the non-primary authentication for the terminal, the association may be performed using the slice information of the terminal and / or the DN information of the terminal.

[0117] In one embodiment, transmitting the first configuration information and / or the related information of the first configuration information comprises transmitting the first configuration information and / or the related information of the first configuration information to a terminal.

[0118] In one embodiment, obtaining first request information; and querying or receiving first placement information based on the first request information; In another embodiment, slice information of a terminal and / or DN information of a terminal (e.g., slice information of a terminal subscription and / or DN information of a terminal subscription) is obtained, and based on the slice information of the terminal and / or the DN information of the terminal, first configuration information related to the slice information of the terminal and / or the DN information of the terminal is confirmed.

[0119] In one alternative embodiment of the present application, the address information of the first server includes at least one of an Internet Protocol address of the first server, a Media Access Control address of the first server, a port number of the first server, a protocol type used for the certificate and / or subscription placement, a protocol version of the first server, and index information of the first server address.

[0120] In one alternative embodiment of the present application, the index information of the first server address includes at least one of an FQDN of the first server and a URL of the first server.

[0121] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0122] In one alternative embodiment of the present application, the first request information includes at least one of the following:

[0123] (1) instruction information for instructing a first access method; (2) Certificate and / or subscription type information; (3) Secondary subject identifier information; (4) Group identifier information of the network group to which the second target belongs; (5) second network identifier information; In one embodiment, the identifier information of the second network may be used to map configuration information (including address information of the first server) of the first access method corresponding to the second network; (6) group identifier information of the second network group; (7) slice information related to the second object; (8) DN information related to the second subject; (9) Terminal slice information, (10) Terminal DN information.

[0124] Here, the second network group is a network group to which the second network belongs, In one embodiment, the second object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization.

[0125] The certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization.

[0126] In one optional embodiment of the present application, when the first operation includes obtaining first request information and querying or receiving first location information based on the first request information, the operation of querying or receiving first location information based on the first request information includes: Identifier information of a first object included in index information of the queried or ordered first location information matches identifier information of a second object in first request information; The group identifier information of the network group to which the first target belongs, which is included in the index information of the queried or ordered first configuration information, matches the group identifier information of the second network group in the first request information; Slice information related to the first object included in the index information of the queried or ordered first location information matches slice information in the first request information; The DN information related to the first object included in the index information of the queried or ordered first location information matches the DN information in the first request information; The identifier information of the A network included in the index information of the queried or ordered first configuration information matches the identifier information of the second network in the first request information; The group identifier information of the network group to which the A network belongs, which is included in the index information of the queried or ordered first configuration information, matches the identifier information of the second network in the first request information; Identifier information of a network to which the first server belongs, which is included in index information of the queried first configuration information, matches identifier information of a second network in the first request information; The group identifier information of the network group to which the first server belongs, which is included in the index information of the queried or ordered first configuration information, matches the group identifier information of the second network group in the first request information; index information of the queried first location information includes a first access method, and first request information includes indication information for indicating the first access method; The index information of the queried or ordered first configuration information includes information used for primary authentication and / or authorization, and the first request information includes information used for primary authentication and / or authorization; The queried or ordered first configuration information includes index information used for non-primary authentication and / or authorization, and the first request information includes information used for non-primary authentication and / or authorization.

[0127] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0128] The step of transmitting the first configuration information and / or the related information of the first configuration information includes transmitting the first configuration information and / or the related information of the first configuration information when a second condition is satisfied.

[0129] The second condition is: a terminal registering with or accessing a first network; and generating or updating the first configuration information and / or information related to the first configuration information.

[0130] Optionally, the operation of setting the priority of the first information higher than the priority of the policy information related to the data operation includes setting the priority of the first information higher than the priority of the policy information related to the data operation when it is confirmed that a third condition is satisfied; Here, the third condition is: the first information is received and acquired first information; and the first information is not locally located first information.

[0131] In one embodiment, when the second communication device is a communication network element responsible for session management, the first information being first information received and obtained includes the first information being first information received and obtained from a communication network element responsible for mobility management.

[0132] In one embodiment, when the second communication device is a communication network element responsible for policy control, the first information being first information received and obtained includes the first information being first information received and obtained from a communication network element responsible for session management or a communication network element responsible for mobility management.

[0133] Optionally, the first target end includes at least one of a communication network element responsible for session management and a communication network element responsible for policy control.

[0134] In one embodiment, when the second communication device is a communication network element responsible for mobility management, the first target end comprises a communication network element responsible for session management and / or a communication network element responsible for policy control; In another embodiment, when the second communication device is a communication network element responsible for mobility management, the first target end comprises a communication network element responsible for policy control; Optionally, the step of transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal comprises: If a fourth condition is satisfied, transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal; Here, the fourth condition is: The DN information of the data channel of the terminal includes at least one of DN information used in a first access method, DN information associated with a first object, and DN information associated with first configuration information; The slice information of the data channel of the terminal includes at least one of slice information used for a first access method, slice information related to a first object, and slice information related to first configuration information; The DN information of the data channel of the terminal in charge of or associated with the first target end includes at least one of: DN information used in the first access method, DN information associated with the first target, and DN information associated with the first configuration information; The slice information of the data channel of the terminal in charge of or associated with the first target end includes at least one of slice information used in the first access method, slice information associated with the first target, and slice information associated with the first configuration information; the terminal is the primary access method; the first information is received and acquired first information; and the first information is not locally located first information.

[0135] In one embodiment, a communication network element (eg, PCF) responsible for policy control sets policy information (eg, PCC rule) related to data manipulation based on the first information.

[0136] In one embodiment, a communication network element (e.g., SMF) responsible for session management performs at least one of setting data manipulation rules (e.g., N4 rules, such as Packet Detection Rules (PDR), Forwarding Action Rules (FAR), etc.) based on the first information and transmitting the first information to the terminal.

[0137] Optionally, the data manipulation rules and / or policy information associated with data manipulation may be used to restrict or allow pass-through of data (e.g., excluding data associated with the first server and / or associated data queried by a Domain Name System (DNS)). Data associated with the first server may include data whose data source and / or data target is the first server.

[0138] Optionally, the data manipulation includes at least one of caching, discarding, pass-through, forwarding, filtering, and the like.

[0139] In one embodiment, the first target end may be selected and / or a data channel (e.g., a PDU session) for the terminal may be selected based on slice information associated with the first configuration information in the first information and / or DN information associated with the first configuration information. It is easy to understand that in a PNI SNPN or O-PLMN scenario, the terminal is not using the first access method but is successfully registered. At this time, multiple data channels may exist in the terminal, each corresponding to multiple SMFs or multiple PCFs. At this time, a data channel and an SMF need to be selected.

[0140] In one embodiment, the terminal's data channel-related signaling, such as PDU Session-related signaling (e.g., PDU Session Establishment), Session Management (SM)-related signaling (e.g., SM Policy Association Establishment), For ease of understanding, the conventional definition is that the priority of a PCC rule is higher than the priority of the first information stored locally in the SMF or higher than the priority of a data manipulation rule set based on the locally stored first information. Since the externally acquired first information is the latest, it should have a higher priority. If the PCF still acquires the PCC rule based on the locally stored first information when setting the PCC rule, an error occurs when the SMF sets the data manipulation rule based on the PCC rule because the priority according to the conventional PCC rule is higher than the priority of the first information stored locally in the SMF. Therefore, one solution is to send or receive the latest first information to the PCF and set the priority of the acquired first information higher than the priority of the PCC rule.

[0141] In one embodiment, the concepts of local storage and local placement may be mixed.

[0142] In an embodiment of the present application, a first network supports querying or ordering first configuration information to facilitate a terminal to configure first configuration information for the terminal. The first configuration information includes address information of a first server, and the terminal can obtain certificates and / or subscriptions from the first server via the first network. At the same time, the related information of the first configuration can also support filtering of the first configuration information to facilitate the terminal to obtain the first configuration information it actually wants.

[0143] Referring to Figure 3, an embodiment of the present application provides a method for supporting information acquisition performed by a third communication device, where the third communication device includes, but is not limited to, one of a registration management network element (e.g., AMF), a policy control network element (e.g., PCF), a session management network element (e.g., Session Management Function (SMF)), and a core network element, and the specific steps include:

[0144] Step 301: Obtain second information, the second information including at least one of: instruction information for indicating a first access method; certificate and / or subscription type information; identifier information of a second object; group identifier information of a network group to which the second object belongs; slice information related to the second object; DN information related to the second object; identifier information of a second network; group identifier information of a second network group; the second network group being the network group to which the second network belongs; slice information of a terminal; DN information of a terminal; connection establishment request information; registration request information; and data channel establishment request information; Step 302: performing a second operation based on the second information; Here, the second operation includes at least one of the following:

[0145] (1) selecting or querying a target communication device based on the second information; Optionally, the target communication device includes, but is not limited to, one of a PCF, a UDM, and a UDR.

[0146] (2) sending first request information to the target communication device; (3) transmitting the second information; Here, the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization.

[0147] In one embodiment, the target communication device information matching one or more of the second information is located on a third communication device, while in another embodiment the target communication device information is located on a fourth communication device.

[0148] Optionally, transmitting the second information includes transmitting the second information to a session management network element (e.g., SMF). In one embodiment, the second information may be transmitted when forwarding session management related signaling transmitted by the terminal to the session management network element. In this case, the third communication device may be the registration management network element.

[0149] In one alternative embodiment of the present application, the step of querying the target communication device based on the second information comprises: sending network element query information including the second information to a fourth communication device; and receiving information of the target communication device transmitted by a fourth communication device.

[0150] Optionally, the fourth communication device is a Network Repository Function (NRF).

[0151] In one alternative embodiment of the present application, the first request information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of the second network, group identifier information of the second network group, slice information related to the second target, DN information related to the second target, slice information of a terminal, and DN information of the terminal.

[0152] In one embodiment, the second object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization.

[0153] In one embodiment, the slice information of the terminal includes at least one of slice information requested by the terminal, slice information allowed for the terminal, slice information of the terminal's subscription, and slice information in which the terminal is located.

[0154] In one embodiment, the slice information requested by the terminal includes at least one of slice information requested by the terminal when establishing a session and slice information requested by the terminal when registering with the network.

[0155] In one embodiment, the DN information of the terminal includes at least one of DN information requested by the terminal, allowed DN information of the terminal, DN information of the terminal's subscription, and DN information where the terminal is located.

[0156] In one embodiment, the DN information requested by the terminal includes at least one of DN information requested by the terminal when establishing a session and DN information requested by the terminal when registering with the network.

[0157] For ease of understanding, non-primary authentication (e.g., secondary authentication and slice authentication) is associated with the slice of the terminal and / or the DN information of the terminal. When it is necessary to locate the address of the first server corresponding to the certificate download of the non-primary authentication for the terminal, the association may be performed using the slice information of the terminal and / or the DN information of the terminal.

[0158] In one embodiment, the slice information and / or DN information of the terminal may be acquired from the terminal. For example, the slice information of the terminal may be acquired from registration request information (including a registration request message). The registration request message may include slice information requested by the terminal. Also, for example, the slice information and / or DN information of the terminal may be acquired from data channel establishment request information (including a data channel establishment request message).

[0159] In another embodiment, the slice information of the terminal and / or the DN information of the terminal may be obtained from the subscription data of the terminal.

[0160] The data channel establishment request information (e.g., PDU session) includes slice information requested by the terminal and DN information requested by the terminal.

[0161] In one embodiment, the terminal establishes a connection with the network by means of a connection establishment request message.

[0162] For ease of understanding, non-primary authentication (e.g., secondary authentication and slice authentication) is associated with the slice of the terminal and / or the DN information of the terminal. When it is necessary to locate the address of the first server corresponding to the certificate download of the non-primary authentication for the terminal, the association may be performed using the slice information of the terminal and / or the DN information of the terminal.

[0163] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0164] In an embodiment of the present application, the first network supports obtaining second information sent by a terminal, determining first request information for the terminal, and querying or ordering first configuration information, thereby facilitating the first network to configure first configuration information for the terminal. The first configuration information includes address information of a first server, and the terminal can obtain a certificate and / or a subscription from the first server via the first network. At the same time, the related information of the first configuration can also support filtering of the first configuration information, so as to facilitate the terminal to obtain the first configuration information it actually wants.

[0165] Referring to FIG. 4, an embodiment of the present application provides a method for supporting information acquisition performed by a fourth communication device, where the fourth communication device includes, but is not limited to, one of an NRF and a core network element, and the specific steps include:

[0166] Step 401: Obtaining network element query information and / or communication device index information; Wherein, the network element query information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information, and DN information; Step 402: performing a third operation according to the network element query information and / or the communication device index information; Here, the third operation is (1) matching a target communication device based on network element query information; (2) transmitting information about the target communication device.

[0167] In one embodiment, the target communication device information is sent to the communication device that sends the network element query information.

[0168] In one alternative embodiment of the present application, the index information of the target communication device is consistent with the network element query information.

[0169] In one alternative embodiment of the present application, the matching of the index information of the target communication device with the network element query information is: The index information of the target communication device includes indication information for indicating the first access method, and the network element query information includes indication information for indicating the first access method; The index information of the target communication device includes the identifier information of the second object, and the network element query information includes the identifier information of the second object; The index information of the target communication device includes group identifier information of the network group to which the second target belongs, and the network element query information includes group identifier information of the network group to which the second target belongs; The index information of the target communication device includes information used for primary authentication and / or authorization, and the network element query information includes information used for primary authentication and / or authorization; The index information of the target communication device includes information used for non-primary authentication and / or authorization, and the network element query information includes information used for non-primary authentication and / or authorization; The index information of the target communication device includes identifier information of the second network, and the network element query information includes identifier information of the second network; The index information of the target communication device includes group identifier information of the second network group, and the network element query information includes group identifier information of the second network group; The index information of the target communication device includes slice information, and the network element query information includes the slice information; The index information of the target communication device includes DN information, and the network element query information includes the DN information.

[0170] In one alternative embodiment of the present application, obtaining index information of the communication device includes: Obtaining network element registration information; generating index information of the communication device based on the network element registration information; Wherein, the network element registration information includes at least one of instruction information for instructing a first access method, certificate and / or subscription type information, identifier information of a third object, group identifier information of a network group to which the third object belongs, identifier information of a third network, and group identifier information of a third network group; The index information of the communication device includes one or more of the network element registration information.

[0171] Optionally, the third target indicates that the network element or a communication device that transmits the network element registration information serves the third target.

[0172] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0173] In an embodiment of the present application, by supporting network element registration of a core network element serving a third target and / or a first access method, it is made easier to select a core network element serving a third target and / or a first access method for a terminal.

[0174] Referring to FIG. 5, an embodiment of the present application provides a method for supporting information acquisition performed by a fifth communication device, where the fifth communication device includes, but is not limited to, a terminal, and the specific steps include:

[0175] Step 501: Obtain first configuration information and / or information related to the first configuration information.

[0176] Before the step of obtaining the first configuration information and / or information related to the first configuration information, the method further includes sending second information, wherein the second information includes at least one of instruction information for indicating the first access method, certificate and / or subscription type information, identifier information of the second target, group identifier information of the network group to which the second target belongs, slice information related to the second target, DN information related to the second target, identifier information of the second network, second network group identifier information, information indicating that the second network group is the network group to which the second network belongs, slice information of the terminal, DN information of the terminal, connection establishment request information, registration request information, and data channel establishment request information.

[0177] In one embodiment, the registration request information (including the registration request message) includes slice information requested by the terminal.

[0178] In one embodiment, the data channel (e.g., PDU session) establishment request information (including a data channel establishment request message) includes at least one of slice information requested by the terminal and DN information requested by the terminal.

[0179] In one embodiment, the terminal establishes a connection with the network by means of connection establishment request information (eg, connection establishment request message, service request message).

[0180] For ease of understanding, non-primary authentication (e.g., secondary authentication and slice authentication) may be associated with the slice of the terminal and / or the DN information of the terminal. When it is necessary to locate the certificate of the non-primary authentication for the terminal and download the corresponding first server, the association may be made using the slice information of the terminal and / or the DN information of the terminal.

[0181] In one embodiment, when the first configuration information includes address information of multiple first servers, the terminal can obtain the first configuration information and associated information of the first configuration information to support determining which associated information each first server is associated with. For example, the first server A is associated with slice A, and the second server B is associated with slice B.

[0182] In one alternative embodiment of the present application, the step of transmitting the second information comprises: transmitting the second information when a first condition is satisfied; Here, the first condition is: (1) Supporting a terminal to obtain a network subscription and / or certificate in a user plane manner; (2) The terminal obtains a network subscription and / or certificate using a user plane method; and (3) the device must obtain a certificate and / or subscription for primary authentication and / or authorization; and (4) the device must obtain certificates and / or subscriptions used for non-primary authentication and / or authorization; and (5) the terminal is required to obtain a subscription and / or certificate for a second network or a second target; and (6) The terminal does not have address information of the first server corresponding to the second network or the second object.

[0183] In one embodiment, the second object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization.

[0184] Optionally, after obtaining the first configuration information and / or information related to the first configuration information, the method further comprises: The terminal, based on the first configuration information and / or information related to the first configuration information, establishing a first data channel; and requesting the first server to obtain a certificate and / or a subscription; where: The first data channel may be used for interaction between the terminal and the first server.

[0185] In one embodiment, the certificate and / or subscription may be a certificate and / or subscription of a first subject in the related information of the first configuration information.

[0186] the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; and / or The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; instruction information for instructing a first access method; slice information associated with the first placement information; and DN information related to the first configuration information.

[0187] In one embodiment, the second object is the same as the first object; In another embodiment, the second subject is a subset of the first subject; In another embodiment, the first subject is a subset of the second subject.

[0188] In an embodiment of the present application, the terminal is supported to obtain first configuration information including address information of the first server, so that the terminal can obtain a certificate and / or a subscription from the first server through the first network. At the same time, the terminal can further provide second information and support filtering of the first configuration information, facilitating the terminal to obtain the first configuration information that it actually wants.

[0189] Referring to Figure 6, an embodiment of the present application provides a method for supporting information acquisition performed by a sixth communication device, where the sixth communication device includes, but is not limited to, one of core network elements (e.g., UDR, UDM, PCF), and the specific steps include:

[0190] Step 601: Send network element registration information, where the network element registration information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a third object, group identifier information of a network group to which the third object belongs, identifier information of a third network, and group identifier information of a third network group.

[0191] In one alternative embodiment of the present application, the indication information for indicating the first access method indicates that the sixth communication device is used for a terminal accessing a network by the first access method or is used for the first access method; and / or the certificate and / or subscription type information indicates that the sixth communication device is used to provide at least one of configuration information related to a primary authentication and / or authorization and configuration information related to a non-primary authentication and / or authorization; and / or the identifier information of the third subject indicates that a sixth communication device is used to serve the third subject or to provide location information related to the third subject; and / or group identifier information of a network group to which a third object belongs indicates that a sixth communication device is used to serve the object in the network group or to provide configuration information related to the object in the network group; and / or the third network identifier information indicates that the sixth communication device is used to serve the third network or to provide configuration information related to the third network; and / or The group identifier information of the third network group indicates that the sixth communication device is used to serve a network in the network group or to provide configuration information relating to a network in the network group.

[0192] In an embodiment of the present application, by supporting network element registration of a core network element serving a first target and / or a first access method, it is made easier to select a core network element serving a first target and / or a first access method for a terminal.

[0193] Referring to FIG. 7-A, the specific steps are as follows:

[0194] Step 1: The UE sends a registration request (optionally including second information) to the AMF; For a description of step 1, please refer to the example shown in FIG.

[0195] Step 2: The AMF sends a policy association establishment request (optionally including second information) to the PCF; Optionally, the PCF is a PCF that matches one or more of the second information, and the AMF selects a PCF or queries the NRF based on the second information.

[0196] Step 3: The PCF sends an information order request (optionally including the first requested information) to the UDR; Optionally, the UDR is a UDR that matches one or more of the second information, and the AMF selects or queries the NRF for a UDR based on the second information.

[0197] For a description of steps 2 and 3, please refer to the example shown in FIG.

[0198] Step 4: The AF sends a business parameter configuration creation request / business parameter configuration modification request (optionally including the first information) to the NEF; Step 5: The NEF sends a business parameter configuration creation request / business parameter configuration modification request (optionally including the first information) to the UDR; For a description of steps 4 and 5, please refer to the example shown in FIG.

[0199] Step 6: The UDR sends a business parameter configuration creation response / business parameter configuration modification response (first information) to the AF via the NEF; Step 7: The UDR sends an information notification message (e.g., Nudr_DM_Notify) to the PCF, where the information notification message includes the first configuration information, and the notification message may further include related information of the first configuration information.

[0200] For a description of steps 6 and 7, please refer to the example shown in FIG.

[0201] Step 8: The PCF sends the UE Policy (optionally including the first configuration information and / or related information of the first configuration information) to the UE via the AMF.

[0202] For a description of step 8, please refer to the example shown in FIG.

[0203] In step 9, the terminal may perform one of establishing a first data channel and requesting the first server to obtain a certificate and / or a subscription based on the first configuration information and / or information related to the first configuration information. The first data channel may be used for interaction between the terminal and the first server. For step 9, please refer to the description of the embodiment in FIG. 5.

[0204] As can be understood, there is no chronological relationship between steps 1 to 3 and steps 4 to 7, and they may be parallel, or steps 4 to 7 may occur before steps 1 to 3, or steps 1 to 3 may occur before steps 4 to 5.

[0205] Referring to Figure 7-B, the specific steps are as follows:

[0206] Step 1: The UE sends a PDU session establishment request to the SMF via the AMF, where the PDU session establishment request is included in the first message (e.g., an N1N2 delivery message) sent by the AMF to the SMF.

[0207] In one embodiment, the PDU session request includes second information.

[0208] In another embodiment, the first message includes the second information, and the AMF obtains the second information in a registration request of the UE.

[0209] Step 2: The SMF sends a policy association establishment request (optionally including second information) to the PCF; Optionally, the PCF is a PCF that matches one or more of the second information, and the AMF selects a PCF or queries the NRF based on the second information.

[0210] Step 3: The SMF sends an information order request (optionally including the first requested information) to the UDR; Optionally, the UDR is a UDR that matches one or more of the second information, and the AMF selects or queries the NRF for a UDR based on the second information.

[0211] For a description of steps 1 to 3, please refer to the embodiment shown in FIG.

[0212] Steps 4 to 7 correspond to steps 4 to 7 in FIG. 7-A and will not be further described here.

[0213] Step 8: The SMF sends session management related signaling (optionally including the first configuration information and / or related information of the first configuration information) to the UE via the AMF. The first configuration information and / or related information of the first configuration information may be sent via information of a Protocol Configuration Option (PCO).

[0214] For a description of step 8, please refer to the example shown in FIG.

[0215] In step 9, the terminal may perform one of establishing a first data channel and requesting the first server to obtain a certificate and / or a subscription based on the first configuration information. The first data channel may be used for interaction between the terminal and the first server. For step 9, please refer to the description of the embodiment in FIG. 5.

[0216] Steps 1 to 3 and steps 4 to 7 may be performed in parallel without any order, or steps 4 to 7 may be performed before steps 1 to 3, or steps 1 to 3 may be performed before steps 4 to 5.

[0217] Referring to FIG. 8 , an embodiment of the present application provides an apparatus 800 for supporting information acquisition for use in a first communication device, the apparatus 800 comprising: a first sending module 801 for sending first information, including first configuration information and / or related information of the first configuration information, to a first network; where: the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; slice information associated with the first placement information; DN information related to the first placement information; and instruction information for instructing the first access method.

[0218] In one alternative embodiment of the present application, the first object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, a non-primary authentication and / or authorization, slice information, DN information, an object related to the primary authentication and / or authorization, and an object related to the non-primary authentication and / or authorization; wherein the A network is the same as or different from the first network; and / or the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization; and / or The instruction information for instructing a first access method indicates one of: that the first configuration service information is used for a terminal accessing the first network via a first access method; and that the first server can configure a first target certificate and / or subscription for a terminal accessing the first network via the first access method; and / or a terminal accessing the first network accesses the first network using a first access method; and / or the first server includes at least one of a first server used for a primary authentication and / or authorization arrangement and a first server used for a non-primary authentication and / or authorization arrangement; wherein the first server used for the primary authentication and / or authorization configuration can configure a first target certificate and / or subscription for the terminal, and the certificate and / or subscription is used for the primary authentication and / or authorization; A first server used for the non-primary authentication and / or authorization configuration can configure a certificate and / or subscription of a first subject for the terminal, and the certificate and / or subscription is used for the non-primary authentication and / or authorization.

[0219] In one alternative embodiment of the present application, the network type of the first network, the network accessed by the terminal, and / or the network type of the A network includes at least one of a public net, a non-public net, a PLMN, a PNI NPN, and a standalone non-public network SNPN.

[0220] In one alternative embodiment of the present application, the address information of the first server includes at least one of an Internet Protocol address of the first server, a media access control address of the first server, a port number of the first server, a protocol version of the first server, and index information of the first server address.

[0221] In one alternative embodiment of the present application, the index information of the first server address includes at least one of an FQDN of the first server and a URL of the first server.

[0222] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0223] The apparatus according to the embodiment of the present application can realize each process realized by the embodiment of the method shown in FIG. 1 and achieve the same technical effect, and will not be further described here to avoid repetition of description.

[0224] Referring to FIG. 9, an embodiment of the present application provides an apparatus 900 for supporting information acquisition for use in a second communication device, the apparatus 900 comprising: a first obtaining module 901 for obtaining first information including first location information and / or related information of the first location information; a first execution module 902 for executing a first operation based on the first information; Here, the first operation is: storing the first information; generating index information (e.g., data key) of the first configuration information, which is one or more pieces of related information of the first configuration information, for the first configuration information; generating index information of a first server for address information of the first server, the index information being one or more of the related information of the first server; Obtaining first request information and querying or receiving first placement information based on the first request information; Transmitting the queried or ordered first location information and / or information related to the first location information; Acquire slice information and / or DN information of a terminal, and confirm first configuration information related to the slice information and / or DN information of the terminal based on the slice information and / or DN information of the terminal; Transmitting first configuration information and / or related information of the first configuration information related to slice information of the terminal and / or DN information of the terminal; Selecting a first target end and / or selecting a data channel for the terminal; transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal; setting a priority of the first information higher than a priority of policy information related to the data operation; where: the first configuration information includes address information of a first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; slice information associated with the first placement information; DN information related to the first placement information; and instruction information for instructing a first access method, the instruction information indicating one of that the first deployment service information is to be used for a terminal accessing the first network via a first access method, and that the first server is capable of deploying a certificate and / or a subscription of the first target for a terminal accessing the first network via the first access method.

[0225] In one alternative embodiment of the present application, the first object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, a non-primary authentication and / or authorization, slice information, DN information, an object related to the primary authentication and / or authorization, and an object related to the non-primary authentication and / or authorization; wherein the A network is the same as or different from the first network; and / or the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization; and / or a terminal accessing the first network accesses the first network using a first access method; and / or the first server includes at least one of a first server used for a primary authentication and / or authorization arrangement and a first server used for a non-primary authentication and / or authorization arrangement; wherein the first server used for the primary authentication and / or authorization configuration can configure a first target certificate and / or subscription for the terminal, and the certificate and / or subscription is used for the primary authentication and / or authorization; A first server used for the non-primary authentication and / or authorization configuration can configure a certificate and / or subscription of a first subject for the terminal, and the certificate and / or subscription is used for the non-primary authentication and / or authorization.

[0226] In one alternative embodiment of the present application, the network type of the first network and / or the network type of the A network includes at least one of a public net, a non-public net, a PLMN, a PNI NPN, and an SNPN.

[0227] In one alternative embodiment of the present application, the address information of the first server includes at least one of an Internet Protocol address of the first server, a Media Access Control address of the first server, a port number of the first server, a protocol type used for the certificate and / or subscription placement, a protocol version of the first server, and index information of the first server address.

[0228] In one alternative embodiment of the present application, the index information of the first server address includes at least one of an FQDN of the first server and a URL of the first server.

[0229] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0230] In one alternative embodiment of the present application, the first request information comprises: instruction information for instructing a first access method; Certificate and / or subscription type information; second subject identifier information; Group identifier information of a network group to which the second target belongs; Identifier information of a second network; Group identifier information of a second network group; the second network group is a network group to which the second network belongs; slice information relating to a second object; and DN information associated with a second subject; The slice information of the device, and DN information of the terminal.

[0231] Here, the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization.

[0232] In one embodiment, the second object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization.

[0233] In one alternative embodiment of the present application, when the first operation includes obtaining first request information and querying first placement information based on the first request information, the operation of querying or receiving the first placement information based on the first request information may include: Identifier information of a first object included in index information of the queried or ordered first location information matches identifier information of a second object in first request information; The group identifier information of the network group to which the first target belongs, which is included in the index information of the queried or ordered first configuration information, matches the group identifier information of the second network group in the first request information; The identifier information of the A network included in the index information of the queried or ordered first configuration information matches the identifier information of the second network in the first request information; The group identifier information of the network group to which the A network belongs, which is included in the index information of the queried or ordered first configuration information, matches the identifier information of the second network in the first request information; Identifier information of a network to which the first server belongs, which is included in index information of the queried first configuration information, matches identifier information of a second network in the first request information; The group identifier information of the network group to which the first server belongs, which is included in the index information of the queried or ordered first configuration information, matches the group identifier information of the second network group in the first request information; index information of the queried first location information includes a first access method, and first request information includes indication information for indicating the first access method; The index information of the queried or ordered first configuration information includes information used for primary authentication and / or authorization, and the first request information includes information used for primary authentication and / or authorization; The queried or ordered first configuration information includes index information used for non-primary authentication and / or authorization, and the first request information includes information used for non-primary authentication and / or authorization.

[0234] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0235] The step of transmitting the first configuration information and / or the related information of the first configuration information includes transmitting the first configuration information and / or the related information of the first configuration information when a second condition is satisfied.

[0236] The second condition is: a terminal registering with or accessing a first network; and generating or updating the first configuration information and / or information related to the first configuration information.

[0237] Optionally, the operation of setting the priority of the first information higher than the priority of the policy information related to the data operation includes setting the priority of the first information higher than the priority of the policy information related to the data operation when it is confirmed that a third condition is satisfied; Here, the third condition is: the first information is received and acquired first information; and the first information is not locally located first information.

[0238] In one embodiment, when the second communication device is a communication network element responsible for session management, the first information being first information received and obtained includes the first information being first information received and obtained from a communication network element responsible for mobility management.

[0239] In one embodiment, when the second communication device is a communication network element responsible for policy control, the first information being first information received and obtained includes the first information being first information received and obtained from a communication network element responsible for session management or a communication network element responsible for mobility management.

[0240] Optionally, the first target end includes at least one of a communication network element responsible for session management and a communication network element responsible for policy control.

[0241] In one embodiment, when the second communication device is a communication network element responsible for mobility management, the first target end comprises a communication network element responsible for session management and / or a communication network element responsible for policy control; In another embodiment, when the second communication device is a communication network element responsible for mobility management, the first target end comprises a communication network element responsible for policy control; Optionally, the step of transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal comprises: If a fourth condition is satisfied, transmitting the first information to a first target end and / or transmitting the first information via associated signaling of a data channel of the terminal; Here, the fourth condition is: The DN information of the data channel of the terminal includes at least one of DN information used in a first access method, DN information associated with a first object, and DN information associated with first configuration information; The slice information of the data channel of the terminal includes at least one of slice information used for a first access method, slice information related to a first object, and slice information related to first configuration information; The DN information of the data channel of the terminal in charge of or associated with the first target end includes at least one of: DN information used in the first access method, DN information associated with the first target, and DN information associated with the first configuration information; The slice information of the data channel of the terminal in charge of or associated with the first target end includes at least one of slice information used in the first access method, slice information associated with the first target, and slice information associated with the first configuration information; the terminal is the primary access method; the first information is received and acquired first information; and the first information is not locally located first information.

[0242] In one embodiment, a communication network element (eg, PCF) responsible for policy control sets policy information (eg, PCC rule) related to data manipulation based on the first information.

[0243] In one embodiment, a communication network element (e.g., SMF) responsible for session management performs at least one of setting a data manipulation rule (e.g., N4 rule, e.g., PDR, FAR, etc.) based on the first information and transmitting the first information to the terminal.

[0244] Optionally, the data manipulation rules and / or policy information related to data manipulation may be used to restrict data (e.g., excluding data related to the first server and / or associated data queried by DNS) or allow data pass-through (e.g., excluding data related to the first server and / or associated data queried by DNS). Data related to the first server may include data whose data source and / or data target is the first server.

[0245] Optionally, the data manipulation includes at least one of caching, discarding, pass-through, forwarding, filtering, and the like.

[0246] In one embodiment, the first target end may be selected and / or a data channel (e.g., a PDU session) for the terminal may be selected based on slice information associated with the first configuration information in the first information and / or DN information associated with the first configuration information. It is easy to understand that in a PNI SNPN or O-PLMN scenario, the terminal is not using the first access method but is successfully registered. At this time, multiple data channels may exist in the terminal, each corresponding to multiple SMFs or multiple PCFs. At this time, a data channel and an SMF need to be selected.

[0247] In one embodiment, the terminal's data channel related signaling, such as PDU session related signaling (e.g., PDU session establishment), session management related signaling (e.g., SM policy association establishment), For ease of understanding, the conventional definition is that the priority of a PCC rule is higher than the priority of the first information stored locally in the SMF or higher than the priority of a data manipulation rule set based on the locally stored first information. Since the externally acquired first information is the latest, it should have a higher priority. If the PCF still acquires the PCC rule based on the locally stored first information when setting the PCC rule, an error occurs when the SMF sets the data manipulation rule based on the PCC rule because the priority according to the conventional PCC rule is higher than the priority of the first information stored locally in the SMF. Therefore, one solution is to send or receive the latest first information to the PCF and set the priority of the acquired first information higher than the priority of the PCC rule.

[0248] In one embodiment, the concepts of local storage and local placement may be mixed.

[0249] The apparatus according to the embodiment of the present application can realize each process realized by the embodiment of the method shown in FIG. 2 and achieve the same technical effect, and will not be further described here to avoid repetition.

[0250] Referring to FIG. 10 , an embodiment of the present application provides an apparatus for supporting information acquisition for use in a third communication device, comprising: a second acquisition module 1001 for acquiring second information, the second information including at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, slice information related to the second target, DN information related to the second target, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information of a terminal, DN information of a terminal, connection establishment request information, registration request information, and data channel establishment request information; a second execution module 1002 for executing a second operation based on the second information; wherein the second operation is: selecting or querying a target communication device based on the second information; Sending first request information to the target communication device; transmitting the second information (e.g., transmitting the second information to a session management network element); Here, the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization, and a certificate and / or subscription used for non-primary authentication and / or authorization.

[0251] In one alternative embodiment of the present application, the second execution module 1002 further comprises: sending network element query information including the second information to a fourth communication device; It is used to receive information about the target communication device sent by a fourth communication device.

[0252] In one alternative embodiment of the present application, the first request information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of the second network, group identifier information of the second network group, slice information related to the second target, DN information related to the second target, slice information of a terminal, and DN information of the terminal.

[0253] In one embodiment, the second object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, an object related to primary authentication and / or authorization, and an object related to non-primary authentication and / or authorization.

[0254] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0255] The apparatus according to the embodiment of the present application can realize each process realized by the embodiment of the method shown in FIG. 3 and achieve the same technical effect, and will not be further described here to avoid repetition of description.

[0256] Referring to FIG. 11, an embodiment of the present application provides an apparatus 1100 for supporting information acquisition used in a fourth communication device, the apparatus 1100 comprising: A third obtaining module 1101 for obtaining network element query information and / or communication device index information, wherein the network element query information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information, and DN information; a third acquisition module 1101; a third execution module 1102 for performing a third operation based on the network element query information and / or the communication device index information; Here, the third operation is Matching a target communication device based on the network element query information; and transmitting information about the target communication device.

[0257] In one alternative embodiment of the present application, the index information of the target communication device is consistent with the network element query information.

[0258] In one alternative embodiment of the present application, the matching of the index information of the target communication device with the network element query information is: The index information of the target communication device includes indication information for indicating the first access method, and the network element query information includes indication information for indicating the first access method; The index information of the target communication device includes the identifier information of the second object, and the network element query information includes the identifier information of the second object; The index information of the target communication device includes group identifier information of the network group to which the second target belongs, and the network element query information includes group identifier information of the network group to which the second target belongs; The index information of the target communication device includes information used for primary authentication and / or authorization, and the network element query information includes information used for primary authentication and / or authorization; The index information of the target communication device includes information used for non-primary authentication and / or authorization, and the network element query information includes information used for non-primary authentication and / or authorization; The index information of the target communication device includes identifier information of the second network, and the network element query information includes identifier information of the second network; The index information of the target communication device includes group identifier information of the second network group, and the network element query information includes group identifier information of the second network group; The index information of the target communication device includes slice information, and the network element query information includes the slice information; The index information of the target communication device includes DN information, and the network element query information includes the DN information.

[0259] In one alternative embodiment of the present application, obtaining index information of the communication device includes: Obtaining network element registration information; generating index information of the communication device based on the network element registration information; Wherein, the network element registration information includes at least one of instruction information for instructing a first access method, certificate and / or subscription type information, identifier information of a third object, group identifier information of a network group to which the third object belongs, identifier information of a third network, and group identifier information of a third network group; The index information of the communication device includes one or more of the network element registration information.

[0260] Optionally, the third object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.

[0261] In one alternative embodiment of the present application, the first access method is: The access method includes at least one of accessing the network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with a default certificate.

[0262] The apparatus according to the embodiment of the present application can realize each process realized by the embodiment of the method shown in FIG. 4 and achieve the same technical effect, and will not be further described here to avoid repetition of description.

[0263] Referring to FIG. 12, an embodiment of the present application provides an apparatus for supporting information acquisition used in a fifth communication device, wherein the fifth communication device 1200 includes: a fourth acquiring module 1201 for acquiring first configuration information and / or information related to the first configuration information;

[0264] In one alternative embodiment of the present application, before the step of obtaining first configuration information and / or related information of the first configuration information, the fifth communication device 1200: The second information further includes a second transmitting module 1202 for transmitting second information, wherein the second information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, slice information related to the second target, DN information related to the second target, identifier information of a second network, second network group identifier information, information indicating that the second network group is a network group to which the second network belongs, slice information of a terminal, DN information of a terminal, connection establishment request information, registration request information, and data channel establishment request information.

[0265] In one optional embodiment of the present application, the second transmitting module 1202 further comprises: used to transmit the second information when a first condition is met; Here, the first condition is: Supporting a terminal to obtain a network subscription and / or certificate in a user plane manner; The terminal obtains a network subscription and / or certificate using a user plane method; The terminal must obtain a certificate and / or subscription for primary authentication and / or authorization; The terminal needs to obtain certificates and / or subscriptions used for non-primary authentication and / or authorization; and The terminal needs to obtain a subscription and / or certificate for a second network or a second target; The terminal does not have address information of the first server corresponding to the second network or the second object.

[0266] In one alternative embodiment of the present application, after the step of obtaining first configuration information and / or related information of the first configuration information, the fifth communication device 1200: The terminal, based on the first configuration information and / or information related to the first configuration information, establishing a first data channel; and requesting the first server to obtain a certificate and / or a subscription; where: The first data channel is used for interaction between the terminal and the first server.

[0267] In one embodiment, the certificate and / or subscription is a certificate and / or subscription of a first subject in the related information of the first configuration information.

[0268] The apparatus according to the embodiment of the present application can realize each process realized by the embodiment of the method shown in FIG. 5 and achieve the same technical effect, and will not be further described here to avoid repetition of description.

[0269] Referring to FIG. 13, an embodiment of the present application provides an apparatus 1300 for supporting information acquisition used in a sixth communication device, the apparatus 1300 comprising: a third sending module 1301 for sending network element registration information, wherein the network element registration information includes at least one of: indication information for indicating a first access method; certificate and / or subscription type information; identifier information of a third object; group identifier information of a network group to which the third object belongs; identifier information of a third network; and group identifier information of a third network group; Here, the third object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, and a non-primary authentication and / or authorization.

[0270] In one alternative embodiment of the present application, the indication information for indicating the first access method indicates that the sixth communication device is used for a terminal accessing a network by the first access method or is used for the first access method; and / or the certificate and / or subscription type information indicates that the sixth communication device is used to provide at least one of configuration information related to a primary authentication and / or authorization and configuration information related to a non-primary authentication and / or authorization; and / or the identifier information of the third subject indicates that a sixth communication device is used to serve the third subject or to provide location information related to the third subject; and / or Group identifier information of the network group to which the third object belongs indicates that a sixth communication device is used to serve the object in the network group or to provide configuration information related to the object in the network group; and / or the third network identifier information indicates that a sixth communication device is used to serve the third network or to provide configuration information related to the third network; and / or The group identifier information of the third network group indicates that the sixth communication device is used to serve a network in the network group or to provide configuration information related to a network in the network group.

[0271] The apparatus according to the embodiment of the present application can realize each process realized by the embodiment of the method shown in FIG. 6 and achieve the same technical effect, and will not be further described here to avoid repetition of description.

[0272] FIG. 14 is a schematic diagram of the hardware structure of a terminal for implementing an embodiment of the present application, where the terminal 1400 includes components such as, but not limited to, a radio frequency unit 1401, a network module 1402, an audio output unit 1403, an input unit 1404, a sensor 1405, a display unit 1406, a user input unit 1407, an interface unit 1408, a memory 1409, and a processor 1410.

[0273] As will be understood by those skilled in the art, the terminal 1400 may further include a power source (e.g., a battery) for powering each component, and the power source may be logically connected to the processor 1410 by a power management system, thereby enabling the power management system to realize functions such as charge / discharge management and power consumption management. The terminal structure shown in Figure 14 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than those shown, or a combination of some components, or a different arrangement of components, which will not be further described here.

[0274] It should be understood that in the embodiment of the present application, the input unit 1404 may include a graphics processing unit (GPU) 14041 and a microphone 14042, and the graphics processor 14041 processes image data of still or video images captured by an image capture device (e.g., a camera) in a video capture mode or an image capture mode. The display unit 1406 may include a display panel 14061, and the display panel 14061 may be arranged in the form of a liquid crystal display, an organic light emitting diode, or the like. The user input unit 1407 includes a touch panel 14071 and other input devices 14072. The touch panel 14071 is also called a touch screen. The touch panel 14071 may include two parts: a touch detection device and a touch controller. The other input devices 14072 may include, but are not limited to, a physical keyboard, function keys (e.g., volume control buttons, switch buttons, etc.), a trackball, a mouse, and a control lever, which will not be further described herein.

[0275] In the embodiment of the present application, the radio frequency unit 1401 receives downlink data from the network side device, and then processes the data in the processor 1410, and transmits uplink data to the network side device. Generally, the radio frequency unit 1401 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc.

[0276] The memory 1409 may be used to store software programs or instructions and various data. The memory 1409 may primarily include a program or instruction storage area and a data storage area, where the program or instruction storage area can store an operating system, an application program or instructions required for at least one function (e.g., audio playback function, image playback function, etc.), etc. The memory 1409 may include high-speed random access memory or nonvolatile memory, where the nonvolatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. For example, the memory 1409 may be at least one magnetic disk memory device, flash memory device, or other nonvolatile solid-state memory device.

[0277] The processor 1410 may include one or more processing units. Optionally, the processor 1410 may integrate an application processor and a modem processor. Here, the application processor mainly processes an operating system, a user interface, and application programs or instructions, and the modem processor mainly processes wireless communication, such as a baseband processor. As can be appreciated, the modem processor does not have to be integrated into the processor 1410.

[0278] The terminal according to the embodiment of the present application can implement each process implemented by the embodiment of the method shown in Figure 5 and achieve the same technical effect, and will not be further described here to avoid repetition.

[0279] An embodiment of the present application further provides a network side device. As shown in Fig. 15, the network side device 1500 includes an antenna 1501, a radio frequency device 1502, and a baseband device 1503. The antenna 1501 and the radio frequency device 1502 are connected to each other. In the uplink direction, the radio frequency device 1502 receives information through the antenna 1501 and transmits the received information to the baseband device 1503 for processing. In the downlink direction, the baseband device 1503 processes the information to be transmitted and transmits it to the radio frequency device 1502, and the radio frequency device 1502 processes the received information and then transmits it through the antenna 1501.

[0280] The above frequency band processing device may be located in a baseband device 1503, and the method performed by the network side equipment in the above embodiments may be implemented in the baseband device 1503, which includes a processor 1504 and a memory 1505.

[0281] The baseband device 1503 may include, for example, at least one baseband board, on which multiple chips are installed, and as shown in FIG. 15 , one of the chips is, for example, a processor 1504, which is connected to a memory 1505, calls a program in the memory 1505, and performs the network side device operations shown in the above method embodiments.

[0282] The baseband device 1503 may further include a network interface 1506, which is used to exchange information with the radio frequency device 1502, and this interface may be, for example, a Common Public Radio Interface (CPRI).

[0283] Specifically, the network side device of the embodiment of the present application further includes instructions or programs stored in memory 1505 and capable of running on processor 1504, and processor 1504 can call the instructions or programs in memory 1505 to execute the methods performed by each module shown in Figures 10-13, and achieve the same technical effects, which will not be further described here to avoid repetition.

[0284] An embodiment of the present application further provides a computer program product, the computer program product being stored in a non-transitory readable storage medium, the computer program product being executed by at least one processor to realize the steps of the processing methods described in Figures 1-4 and 6.

[0285] The embodiments of the present application further provide a readable storage medium, which may be non-volatile or volatile, and stores a program or instruction on the readable storage medium, which, when executed by a processor, can realize each process of the method embodiments shown in Figures 1 to 6 and achieve the same technical effects. In order to avoid repetition, no further description will be given here.

[0286] The processor may be the processor in the terminal described in the above embodiment. The readable storage medium may include a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0287] The embodiments of the present application further provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor running a program or instruction of the network side device to realize each process of the method embodiments shown in Figures 1 to 6 above, and can achieve the same technical effects. In order to avoid repetition, no further description will be given here.

[0288] It should be understood that the chips referred to in the embodiments of this application may be referred to as system level chips, system chips, chip systems, or system-on-chips.

[0289] It should be noted that, in this specification, the terms "comprise," "include," "includes," or any other variations thereof are intended to cover the non-exclusive "comprise," whereby a process, method, article, or apparatus comprising a set of elements not only includes those elements, but also other elements not expressly listed or inherent in such process, method, article, or apparatus. Absent further limitations, an element defined by the phrase "comprises one of" does not preclude the presence of other identical elements in the process, method, article, or apparatus comprising that element. It should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may include performing functions in an essentially simultaneous manner or in the reverse order based on the functions involved. For example, the described method may be performed in a different order than described, and various steps may be added, omitted, or combined. Furthermore, features described with reference to some examples may be combined in other examples.

[0290] As will be apparent to those skilled in the art from the above description of the embodiments, the methods of the above embodiments can be realized in the form of software and a necessary general-purpose hardware platform. Of course, they can also be realized in hardware, but in many cases the former is a more preferred embodiment. Based on this understanding, the technical solution of the present application, in substance or in part contributing to the prior art, may be embodied in the form of a software product. This computer software product is stored in a storage medium (e.g., ROM / RAM, magnetic disk, optical disk) and includes some instructions for causing a terminal (which may be a mobile phone, computer, server, network device, etc.) to execute the methods described in each embodiment of the present application.

[0291] Although the embodiments of the present application have been described above in conjunction with the drawings, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not limiting. Those skilled in the art can take the teachings of the present application into account and implement many forms without departing from the spirit and scope of the claims, all of which fall within the scope of protection of the present application.

Claims

1. 1. A method of supporting information acquisition performed by a second communications device, comprising: Obtaining first information including first location information and / or information related to the first location information; performing a first operation based on the first information; Here, the first operation is: Acquire slice information and / or DN information of a terminal, and confirm first configuration information related to the slice information and / or DN information of the terminal based on the slice information and / or DN information of the terminal; Transmitting slice information of the terminal and / or first configuration information related to DN information of the terminal and / or related information of the first configuration information; the first configuration information includes address information of a first server, and the first server can configure a first subject certificate and / or subscription for the terminal; The related information of the first arrangement information is slice information associated with the first placement information; DN information related to the first placement information; slice information associated with the first object; and DN information associated with said first subject.

2. The first operation further comprises: transmitting said first information to a first target end and / or transmitting said first information via associated signaling of a data channel of a terminal; storing the first information; generating index information of the first configuration information, the index information being one or more of the related information of the first configuration information for the first configuration information; transmitting the queried or ordered first location information and / or information related to the first location information; The related information of the first arrangement information further includes: Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; and instruction information for instructing a first access method, wherein the instruction information indicates one of: that the first configuration information is to be used for a terminal accessing the first network via the first access method; and that the first server is capable of configuring the certificate and / or subscription of the first target for a terminal accessing the first network via the first access method.

3. The first object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, a non-primary authentication and / or authorization, slice information, DN information, an object related to the primary authentication and / or authorization, and an object related to the non-primary authentication and / or authorization; The method of claim 2 , wherein the A network is the same as or different from the first network.

4. 3. The method of claim 2, wherein the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization.

5. The method according to claim 2 , wherein a terminal accessing the first network accesses the first network using a first access method.

6. the first server includes at least one of a first server used for a primary authentication and / or authorization arrangement and a first server used for a non-primary authentication and / or authorization arrangement; wherein a first server used for the primary authentication and / or authorization configuration can configure a certificate and / or subscription of a first subject for a terminal, and the certificate and / or subscription is used for the primary authentication and / or authorization; 3. The method of claim 1, wherein a first server used for the non-primary authentication and / or authorization configuration is capable of configuring a certificate and / or subscription of a first subject for a terminal, and the certificate and / or subscription is used for the non-primary authentication and / or authorization.

7. The method of claim 3 , wherein the network type of the first network and / or the network type of the A network includes at least one of a public net, a non-public net, a PLMN, a PNI NPN, and a SNPN.

8. the address information of the first server includes at least one of an Internet Protocol address of the first server, a Media Access Control address of the first server, a port number of the first server, a protocol type used in the certificate and / or subscription placement, a protocol version of the first server, and index information of the address of the first server; The method of claim 1 , wherein the index information of the address of the first server includes at least one of an FQDN of the first server and a URL of the first server.

9. The first access method is 3. The method of claim 2, comprising at least one of an access method for accessing a network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with default credentials.

10. The first operation further comprises: obtaining first request information; and querying or receiving first placement information based on the first request information; The first request information is instruction information for instructing the first access method; Certificate and / or subscription type information; second subject identifier information; Group identifier information of a network group to which the second target belongs; Identifier information of a second network; Group identifier information of a second network group; the second network group is a network group to which the second network belongs; slice information relating to a second object; and DN information associated with a second subject; and The slice information of the device, and DN information of the terminal, wherein the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization; The method of claim 2, wherein the second object includes at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, non-primary authentication and / or authorization, slice information, DN information, objects related to primary authentication and / or authorization, and objects related to non-primary authentication and / or authorization.

11. The first operation further comprises: obtaining first request information; and querying or receiving first placement information based on the first request information; The operation of querying or receiving first placement information based on the first request information includes: Identifier information of a first object included in index information of the queried or ordered first location information matches identifier information of a second object in first request information; The group identifier information of the network group to which the first target belongs, which is included in the index information of the queried or ordered first configuration information, matches the group identifier information of the second network group in the first request information; The identifier information of the A network included in the index information of the queried or ordered first configuration information matches the identifier information of the second network in the first request information; The group identifier information of the network group to which the A network belongs, which is included in the index information of the queried or ordered first configuration information, matches the identifier information of the second network in the first request information; Identifier information of a network to which the first server belongs, which is included in index information of the queried first configuration information, matches identifier information of a second network in the first request information; The group identifier information of the network group to which the first server belongs, which is included in the index information of the queried or ordered first configuration information, matches the group identifier information of the second network group in the first request information; index information of the queried first location information includes a first access method, and the first request information includes indication information for indicating the first access method; The index information of the queried or ordered first configuration information includes information used for primary authentication and / or authorization, and the first request information includes information used for primary authentication and / or authorization; 3. The method of claim 2, wherein index information of the queried or ordered first configuration information includes information used for non-primary authentication and / or authorization, and the first request information includes information used for non-primary authentication and / or authorization.

12. 1. A method of supporting information acquisition performed by a first communications device, comprising: transmitting first information to a first network, the first information including first configuration information and / or information related to the first configuration information; where: the first configuration information includes address information of a first server, and the first server can configure a first subject certificate and / or subscription for the terminal; The related information of the first arrangement information is slice information associated with the first placement information; DN information related to the first placement information; Identifier information of the first object; and Group identifier information of a network group to which the first target belongs; slice information associated with the first object; DN information associated with the first subject; Identifier information of a network to which the first server belongs; Group identifier information of a network group to which the first server belongs; type information of the certificate and / or subscription; and instruction information for instructing the first access method.

13. The first object includes at least one of an A network, an entity in a data network, an entity other than the first network, a primary authentication and / or authorization, a non-primary authentication and / or authorization, slice information, DN information, an object related to the primary authentication and / or authorization, and an object related to the non-primary authentication and / or authorization; wherein the A network is the same as or different from the first network; the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization; The instruction information for instructing a first access method indicates one of: that the first configuration information is used for a terminal accessing the first network via a first access method; and that the first server can configure a first target certificate and / or subscription for a terminal accessing the first network via the first access method; a terminal accessing the first network accesses the first network using a first access method; the first server includes at least one of a first server used for a primary authentication and / or authorization arrangement and a first server used for a non-primary authentication and / or authorization arrangement; wherein a first server used for the primary authentication and / or authorization configuration can configure a certificate and / or subscription of a first subject for a terminal, and the certificate and / or subscription is used for the primary authentication and / or authorization; 13. The method of claim 12, wherein a first server used for the non-primary authentication and / or authorization configuration is capable of configuring a certificate and / or subscription of a first subject for a terminal, and the certificate and / or subscription is used for the non-primary authentication and / or authorization.

14. 14. The method of claim 13, wherein the network type of the first network, the network accessed by the terminal, and / or the network type of the A-network includes at least one of a public net, a non-public net, a public land mobile network PLMN, a public network integrated non-public network PNI NPN, and a standalone non-public network SNPN.

15. the address information of the first server includes at least one of an Internet Protocol address of the first server, a media access control address of the first server, a port number of the first server, a protocol version of the first server, and index information of the address of the first server; 13. The method of claim 12, wherein the index information of the address of the first server includes at least one of a fully qualified domain name FQDN of the first server and a uniform resource locator URL of the first server.

16. The first access method is 13. The method of claim 12, comprising at least one of an access method for accessing a network to obtain a certificate and / or a subscription, an access method employing restricted network access, and an access method employing network access with default credentials.

17. 1. A method of supporting information acquisition performed by a third communication device, comprising: Acquiring second information from a fifth communication device, wherein the second information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, slice information related to the second target, DN information related to the second target, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information of a terminal, and DN information of a terminal; performing a second operation based on the second information; wherein the second operation is: selecting or querying a target communication device based on the second information; Sending first request information to the target communication device; and transmitting the second information; Here, the method for supporting information acquisition, wherein the certificate and / or subscription type information includes at least one of a certificate and / or subscription used for primary authentication and / or authorization and a certificate and / or subscription used for non-primary authentication and / or authorization.

18. 1. A method of supporting information acquisition performed by a fourth communication device, comprising: obtaining network element query information from a third communication device; receiving network element registration information from the sixth communication device; and generating index information of the communication device based on the network element registration information; Wherein, the network element query information includes at least one of instruction information for indicating a first access method, certificate and / or subscription type information, identifier information of a second target, group identifier information of a network group to which the second target belongs, identifier information of a second network, group identifier information of a second network group, the second network group being the network group to which the second network belongs, slice information, and DN information; The method further comprises: performing a third operation based on the acquired network element query information and / or the generated index information of the communication device; Here, the third operation is Matching a target communication device based on the network element query information; and transmitting information about the target communication device.

19. A method of supporting information acquisition performed by a fifth communications device, comprising: acquiring first location information and / or information related to the first location information from a second communication device; Based on the first location information and / or related information of the first location information, performing at least one of establishing a first data channel used for interaction between the fifth communication device and a first server, and requesting the first server to obtain a certificate and / or a subscription; the first configuration information includes address information of the first server, and the first server can configure a first target certificate and / or subscription for the terminal; The related information of the first arrangement information is slice information associated with the first placement information; DN information related to the first placement information; slice information associated with the first object; and DN information associated with said first subject.

20. A method of supporting information acquisition performed by a sixth communication device, comprising: sending network element registration information to a fourth communication device, wherein the network element registration information includes at least one of instruction information for instructing a first access method, certificate and / or subscription type information, identifier information of a third object, group identifier information of a network group to which the third object belongs, identifier information of a third network, and group identifier information of the third network group; Here, the third object is a method for supporting information acquisition including at least one of an A network, an entity in a data network, an entity other than the first network, primary authentication and / or authorization, and non-primary authentication and / or authorization.

21. 1. A device for supporting information acquisition for use in a second communication device, comprising: a first acquisition module for acquiring first information including first location information and / or related information of the first location information; a first execution module for executing a first operation based on the first information; Here, the first operation is: Acquire slice information and / or DN information of a terminal, and confirm first configuration information related to the slice information and / or DN information of the terminal based on the slice information and / or DN information of the terminal; Transmitting slice information of the terminal and / or first configuration information related to DN information of the terminal and / or related information of the first configuration information; the first configuration information includes address information of a first server, and the first server can configure a first subject certificate and / or subscription for the terminal; The related information of the first arrangement information is slice information associated with the first placement information; DN information related to the first placement information; slice information associated with the first object; and DN information associated with the first subject.

22. A communications device configured to perform the steps of the method according to any one of claims 1 to 18, or to perform the steps of the method according to claim 19, or to perform the steps of the method according to claim 20.