[go: up one dir, main page]

CN114071465B - Access control method, device and communication equipment - Google Patents

Access control method, device and communication equipment Download PDF

Info

Publication number
CN114071465B
CN114071465B CN202110369540.7A CN202110369540A CN114071465B CN 114071465 B CN114071465 B CN 114071465B CN 202110369540 A CN202110369540 A CN 202110369540A CN 114071465 B CN114071465 B CN 114071465B
Authority
CN
China
Prior art keywords
network
information
terminal
access
accessing
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202110369540.7A
Other languages
Chinese (zh)
Other versions
CN114071465A (en
Inventor
柯小婉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Vivo Mobile Communication Co Ltd
Original Assignee
Vivo Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vivo Mobile Communication Co Ltd filed Critical Vivo Mobile Communication Co Ltd
Priority to JP2023503412A priority Critical patent/JP7509991B2/en
Priority to EP21851111.1A priority patent/EP4192064A4/en
Priority to PCT/CN2021/110015 priority patent/WO2022022739A1/en
Priority to KR1020237006765A priority patent/KR20230043969A/en
Priority to PH1/2023/550256A priority patent/PH12023550256A1/en
Publication of CN114071465A publication Critical patent/CN114071465A/en
Priority to US18/104,061 priority patent/US20230179597A1/en
Application granted granted Critical
Publication of CN114071465B publication Critical patent/CN114071465B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The embodiment of the application provides an access control method, an access control device and communication equipment, and relates to the technical field of communication. The access control method comprises the following steps: acquiring first information and/or second information; the first information includes at least one of: indication information of a first access mode, routing indication of a first type and network identification of the first type; the second information includes at least one of: a first type of network identification, a first type of routing indication, a first type of group identification, and identification information of a terminal; performing a first operation according to the first information and/or the second information; the first operation includes at least one of: selecting a first authentication service network element; a first type of group identity is determined, a first type of routing indication is determined or a first type of network identity is determined. By using the method of the embodiment of the application, the selection of the authentication service network element can be supported under the scene that the terminal accesses the first network in the first access mode.

Description

接入控制方法、装置及通信设备Access control method, device and communication equipment

技术领域Technical Field

本申请实施例涉及通信技术领域,尤其涉及一种接入控制方法、装置及通信设备。The embodiments of the present application relate to the field of communication technology, and in particular, to an access control method, apparatus, and communication device.

背景技术Background technique

目前,终端为了下载用于接入独立非公用网络(Standalone Non-publicNetwork,SNPN)的证书而接入另一网络(此方式可称为onboarding)的过程中,需要通过默认证书鉴权服务器的认证。然而,此时该另一网络的鉴权服务功能(AuthenticationServer Function,AUSF)可能与终端无关,与终端的签约永久标识无关。此情况下,如何选择鉴权服务网元是急需要解决的问题。At present, in order to download the certificate for accessing the Standalone Non-public Network (SNPN) and access another network (this method can be called onboarding), the terminal needs to pass the authentication of the default certificate authentication server. However, at this time, the authentication service function (AUSF) of the other network may be irrelevant to the terminal and the contracted permanent identification of the terminal. In this case, how to select the authentication service network element is an urgent problem to be solved.

发明内容Summary of the invention

本申请实施例提供一种接入控制方法、装置及通信设备,用于解决如何选择鉴权服务网元的问题。The embodiments of the present application provide an access control method, apparatus and communication device for solving the problem of how to select an authentication service network element.

为了解决上述技术问题,本申请是这样实现的:In order to solve the above technical problems, this application is implemented as follows:

第一方面,本申请实施例提供了一种接入控制方法,应用于第一通信设备,包括:In a first aspect, an embodiment of the present application provides an access control method, applied to a first communication device, including:

获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;Acquire first information and/or second information; wherein the first information includes at least one of the following: indication information of a first access mode, a first type of routing indication, and a first type of network identification; the second information includes at least one of the following: a first type of network identification, a first type of routing indication, a first type of group identification, and identification information of a terminal;

根据所述第一信息和/或所述第二信息,执行第一操作;Perform a first operation according to the first information and/or the second information;

其中,所述第一操作包括以下至少一项:The first operation includes at least one of the following:

选择第一鉴权服务网元;Select the first authentication service network element;

确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;Determining a first type of group identifier, a first type of routing indication, information of a service provider, and/or a first type of network identifier;

根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;Requesting to discover an authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, information of the service provider and/or indication information of the first access method;

其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或者不同的网络;The first network and the second network are the same network or different networks;

其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;The first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals of the first access mode, and an authentication service network element for providing authentication services to terminals with default certificates;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

第二方面,本申请实施例提供了一种接入控制方法,应用于第二通信设备,包括:In a second aspect, an embodiment of the present application provides an access control method, applied to a second communication device, including:

发送第一信息;Sending the first message;

其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;The first information includes at least one of the following: indication information of the first access mode, a first type of routing indication, a first type of network identification, and identification information of the terminal;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或不同的网络;The first network and the second network are the same network or different networks;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

第三方面,本申请实施例提供了一种接入控制方法,应用于第三通信设备,包括:In a third aspect, an embodiment of the present application provides an access control method, which is applied to a third communication device, including:

获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、认证提供方的信息、第一类型的路由指示、第一类型的网络标识、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;Acquire third information and/or fourth information; wherein the third information includes at least one of the following: a first type of group identifier, information of an authentication provider, a first type of routing indication, a first type of network identifier, and indication information of a first access method; the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, a network identifier of a network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access method supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate;

根据所述第三信息和/或所述第四信息,执行第三操作;Perform a third operation according to the third information and/or the fourth information;

其中,所述第三操作包括以下至少一项:The third operation includes at least one of the following:

发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;finding an authentication service network element matching the third information, wherein the fourth information of the authentication service network element matches the third information;

发送所述发现的鉴权服务网元;Sending the discovered authentication service network element;

其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;The authentication service type supported by the authentication service network element includes supporting authentication services for terminals with default certificates;

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或不同的网络;The first network and the second network are the same network or different networks;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

第四方面,本申请实施例提供了一种接入控制方法,应用于第四通信设备,包括:In a fourth aspect, an embodiment of the present application provides an access control method, which is applied to a fourth communication device, including:

发送第四信息;Sending the fourth message;

其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;The fourth information is used to indicate the attribution information of the authentication service network element; the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access mode supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate;

其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;The routing indication supported by the authentication service network element is a first type of routing indication;

所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;The network identifier of the network to which the authentication service network element belongs is a network identifier of the first type;

所述鉴权服务网元所属的组标识为第一类型的组标识;The group identifier to which the authentication service network element belongs is a group identifier of the first type;

所述鉴权服务网元支持的接入方式包括第一接入方式;The access mode supported by the authentication service network element includes a first access mode;

所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;The authentication service type supported by the authentication service network element includes supporting the provision of authentication services to terminals with default certificates;

所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式;The first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, and an access mode capable of using only restricted services;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

第五方面,本申请实施例提供了一种接入控制装置,应用于第一通信设备,包括:In a fifth aspect, an embodiment of the present application provides an access control apparatus, applied to a first communication device, including:

第一获取模块,用于获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;A first acquisition module, configured to acquire first information and/or second information; wherein the first information includes at least one of the following: indication information of a first access mode, a first type of routing indication, and a first type of network identification; the second information includes at least one of the following: a first type of network identification, a first type of routing indication, a first type of group identification, and identification information of a terminal;

第一执行模块,用于根据所述第一信息和/或所述第二信息,执行第一操作;A first execution module, configured to execute a first operation according to the first information and/or the second information;

其中,所述第一操作包括以下至少一项:The first operation includes at least one of the following:

选择第一鉴权服务网元;Select the first authentication service network element;

确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;Determining a first type of group identifier, a first type of routing indication, information of a service provider, and/or a first type of network identifier;

根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;Requesting to discover an authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, information of the service provider and/or indication information of the first access method;

其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或者不同的网络;The first network and the second network are the same network or different networks;

其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;The first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals of the first access mode, and an authentication service network element for providing authentication services to terminals with default certificates;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

第六方面,本申请实施例提供了一种接入控制装置,应用于第二通信设备,包括:In a sixth aspect, an embodiment of the present application provides an access control device, applied to a second communication device, including:

第一发送模块,用于发送第一信息;A first sending module, used for sending first information;

其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;The first information includes at least one of the following: indication information of the first access mode, a first type of routing indication, a first type of network identification, and identification information of the terminal;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或不同的网络;The first network and the second network are the same network or different networks;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

第七方面,本申请实施例提供了一种接入控制装置,应用于第三通信设备,包括:In a seventh aspect, an embodiment of the present application provides an access control apparatus, applied to a third communication device, including:

第二获取模块,用于获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;A second acquisition module is used to acquire third information and/or fourth information; wherein the third information includes at least one of the following: a first type of group identifier, a first type of routing indication, a first type of network identifier, information of an authentication provider, and indication information of a first access method; the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, a network identifier of a network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access method supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate;

第二执行模块,用于根据所述第三信息和/或所述第四信息,执行第三操作;A second execution module, configured to execute a third operation according to the third information and/or the fourth information;

其中,所述第三操作包括以下至少一项:The third operation includes at least one of the following:

发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;finding an authentication service network element matching the third information, wherein the fourth information of the authentication service network element matches the third information;

发送所述发现的鉴权服务网元;Sending the discovered authentication service network element;

其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;The authentication service type supported by the authentication service network element includes supporting authentication services for terminals with default certificates;

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或不同的网络;The first network and the second network are the same network or different networks;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

第八方面,本申请实施例提供了一种接入控制装置,应用于第四通信设备,包括:In an eighth aspect, an embodiment of the present application provides an access control device, applied to a fourth communication device, including:

第二发送模块,用于发送第四信息;A second sending module, used for sending fourth information;

其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;The fourth information is used to indicate the attribution information of the authentication service network element; the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access mode supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate;

其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;The routing indication supported by the authentication service network element is a first type of routing indication;

所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;The network identifier of the network to which the authentication service network element belongs is a network identifier of the first type;

所述鉴权服务网元所属的组标识为第一类型的组标识;The group identifier to which the authentication service network element belongs is a group identifier of the first type;

所述鉴权服务网元支持的接入方式包括第一接入方式;The access mode supported by the authentication service network element includes a first access mode;

所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;The authentication service type supported by the authentication service network element includes supporting the provision of authentication services to terminals with default certificates;

所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式;The first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, and an access mode capable of using only restricted services;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

第九方面,本申请实施例提供了一种接入控制方法,应用于第五通信设备,包括:In a ninth aspect, an embodiment of the present application provides an access control method, applied to a fifth communication device, including:

在满足第五条件的情况下,执行第五操作;When the fifth condition is met, performing a fifth operation;

所述第五操作包括以下至少一项:The fifth operation includes at least one of the following:

不使用第五信息为终端选择网元;not using the fifth information to select a network element for the terminal;

其中,in,

所述第五条件包括以下至少一项:所述终端为第一接入方式;The fifth condition includes at least one of the following: the terminal is in the first access mode;

所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中MNC,终端用户标识中MCC,终端用户标识中realm中的信息,终端用户标识中第一网络标识NID,终端用户标识中网络标识。The fifth information includes at least one of the following: a user identifier of the terminal, an MNC in the user identifier of the terminal, an MCC in the user identifier of the terminal, information in a realm in the user identifier of the terminal, a first network identifier NID in the user identifier of the terminal, and a network identifier in the user identifier of the terminal.

第十方面,本申请实施例提供了一种接入控制装置,应用于第二通信设备,包括:In a tenth aspect, an embodiment of the present application provides an access control device, applied to a second communication device, including:

第三执行模块,用于在满足第五条件的情况下,执行第五操作;A third execution module, configured to execute a fifth operation when a fifth condition is met;

所述第五操作包括以下至少一项:The fifth operation includes at least one of the following:

不使用第五信息为终端选择网元;not using the fifth information to select a network element for the terminal;

其中,in,

所述第五条件包括以下至少一项:所述终端为第一接入方式;The fifth condition includes at least one of the following: the terminal is in the first access mode;

所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。The fifth information includes at least one of the following: a user identifier of the terminal, network identifier information in the user identifier of the terminal, and realm information in the user identifier of the terminal.

第十方面,本申请实施例提供了一种通信设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时可实现第一方面提供的接入控制方法的步骤,或者,实现第二方面提供的接入控制方法的步骤,或者,实现第三方面提供的接入控制方法的步骤,或者,实现第四方面提供的接入控制方法的步骤,或者,实现第九方面提供的接入控制方法的步骤。In the tenth aspect, an embodiment of the present application provides a communication device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor; the computer program, when executed by the processor, can implement the steps of the access control method provided in the first aspect, or the steps of the access control method provided in the second aspect, or the steps of the access control method provided in the third aspect, or the steps of the access control method provided in the fourth aspect, or the steps of the access control method provided in the ninth aspect.

第一方面,本申请实施例提供了一种可读存储介质,所述可读存储介质上存储有程序或指令,所述程序或指令被处理器执行时实现如可实现第一方面提供的接入控制方法的步骤,或者,实现第二方面提供的接入控制方法的步骤,或者,实现第三方面提供的接入控制方法的步骤,或者,实现第四方面提供的接入控制方法的步骤,或者,实现第九方面提供的接入控制方法的步骤。In a first aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the access control method provided in the first aspect are implemented, or the steps of the access control method provided in the second aspect are implemented, or the steps of the access control method provided in the third aspect are implemented, or the steps of the access control method provided in the fourth aspect are implemented, or the steps of the access control method provided in the ninth aspect are implemented.

不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。It is not difficult to understand that, through this embodiment, in the scenario where the terminal accesses the first network in the first access mode, selection of the authentication service network element can be supported.

附图说明BRIEF DESCRIPTION OF THE DRAWINGS

通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本申请的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present application. Also, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

图1A为本申请实施例提供的一种无线通信系统的架构示意图;FIG1A is a schematic diagram of the architecture of a wireless communication system provided in an embodiment of the present application;

图1B为本申请中第一接入方式下网元间的关系示意图;FIG1B is a schematic diagram of the relationship between network elements under the first access mode in this application;

图2为本申请一实施例的接入控制方法的流程示意图;FIG2 is a schematic diagram of a flow chart of an access control method according to an embodiment of the present application;

图3为本申请另一实施例的接入控制方法的流程示意图;FIG3 is a schematic diagram of a flow chart of an access control method according to another embodiment of the present application;

图4为本申请又一实施例的接入控制方法的流程示意图;FIG4 is a schematic diagram of a flow chart of an access control method according to another embodiment of the present application;

图5为本申请又一实施例的接入控制方法的流程示意图;FIG5 is a schematic diagram of a flow chart of an access control method according to another embodiment of the present application;

图6为本申请实施例的应用场景1的服务鉴权的指示过程的流程图;6 is a flowchart of the indication process of service authentication in application scenario 1 of an embodiment of the present application;

图7为本申请实施例的应用场景2的服务选择过程的流程图;FIG7 is a flowchart of a service selection process for application scenario 2 of an embodiment of the present application;

图8为本申请实施例的应用场景3的服务选择过程的流程图;FIG8 is a flowchart of a service selection process for application scenario 3 of an embodiment of the present application;

图9为本申请实施例的一种接入控制装置的结构图;FIG9 is a structural diagram of an access control device according to an embodiment of the present application;

图10为本申请实施例的另一种接入控制装置的结构图;FIG10 is a structural diagram of another access control device according to an embodiment of the present application;

图11为本申请实施例的另一种接入控制装置的结构图;FIG11 is a structural diagram of another access control device according to an embodiment of the present application;

图12为本申请实施例的另一种接入控制装置的结构图;FIG12 is a structural diagram of another access control device according to an embodiment of the present application;

图13为本申请实施例的一种通信设备的结构图。FIG13 is a structural diagram of a communication device according to an embodiment of the present application.

具体实施方式Detailed ways

下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first" and "second" are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and/or" in the specification and claims represents at least one of the connected objects, and the character "/" generally represents that the objects associated with each other are in an "or" relationship.

图1A示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以包括支持终端功能的中继和/或支持中继功能的终端,终端11也可以称作终端设备或者用户终端(User Equipment,UE),终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、移动上网装置(Mobile InternetDevice,MID)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personalcomputer,UMPC)、移动上网装置(Mobile Internet Device,MID)、可穿戴式设备(WearableDevice)或车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian UserEquipment,PUE)等终端侧设备,可穿戴式设备包括:手环、耳机、眼镜等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以是基站或核心网,其中,基站可被称为节点B、演进节点B、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(ExtendedService Set,ESS)、B节点、演进型B节点(eNB)、家用B节点、家用演进型B节点、WLAN接入点、WiFi节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例,但是并不限定基站的具体类型。FIG1A shows a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 11 and a network side device 12. Among them, the terminal 11 may include a relay supporting terminal functions and/or a terminal supporting relay functions. The terminal 11 may also be referred to as a terminal device or a user terminal (User Equipment, UE). The terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a mobile Internet device (Mobile Internet Device, MID), a handheld computer, a netbook, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a mobile Internet device (Mobile Internet Device, MID), a wearable device (Wearable Device) or a vehicle-mounted device (Vehicle User Equipment, VUE), a pedestrian terminal (Pedestrian User Equipment, PUE) and other terminal side devices, and the wearable device includes: a bracelet, a headset, glasses, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 can be a base station or a core network, wherein the base station can be referred to as a node B, an evolved node B, an access point, a base transceiver station (Base Transceiver Station, BTS), a radio base station, a radio transceiver, a basic service set (Basic Service Set, BSS), an extended service set (Extended Service Set, ESS), a B node, an evolved B node (eNB), a home B node, a home evolved B node, a WLAN access point, a WiFi node, a transmitting and receiving point (Transmitting Receiving Point, TRP) or some other suitable term in the field. As long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is taken as an example, but the specific type of the base station is not limited.

在一些通信场景中,存在通信设备没有网络的证书却需要接入网络的场景,例如:在独立非公用网络(Standalone Non-public Network,SNPN)部署时,UE可能还没有能够用于接入SNPN的证书和UE标识。比如工厂部署的SNPN和刚在市场上采购的终端,或者在演唱会现场部署的SNPN和观众的终端。In some communication scenarios, there are scenarios where the communication device does not have a network certificate but needs to access the network, for example: when a standalone non-public network (SNPN) is deployed, the UE may not have a certificate and UE identity that can be used to access the SNPN. For example, the SNPN deployed in the factory and the terminal just purchased on the market, or the SNPN deployed at the concert site and the audience's terminal.

为了让这种类型的UE获取用于接入SNPN的证书和UE标识,UE可以接入某个网络(后续称为第一网络),下载用于接入SNPN的证书。比如UE接入第一网络,建立一条数据通道,并通过所述数据通道连接配置服务器,从配置服务器下载SNPN的证书或者UE接入第一网络,第一网络的控制网元代替UE向配置服务器下载SNPN的证书。In order for this type of UE to obtain the certificate and UE identity for accessing the SNPN, the UE can access a certain network (hereinafter referred to as the first network) and download the certificate for accessing the SNPN. For example, the UE accesses the first network, establishes a data channel, and connects to the configuration server through the data channel, downloads the SNPN certificate from the configuration server, or the UE accesses the first network, and the control network element of the first network downloads the SNPN certificate from the configuration server on behalf of the UE.

为了下载用于接入第二网络的证书而接入第一网络的方式可以称为onboarding。第一网络和第二网络可以是同一个网络。Accessing the first network in order to download a certificate for accessing the second network may be called onboarding. The first network and the second network may be the same network.

当UE没有第一网络的证书的情况下,第一网络需要对UE进行认证才可以为UE下载证书或者是建立用于下载证书的数据通道。UE上可能具有默认证书,此时,第一网络可以请求默认证书鉴权服务器(DCS Default Credential Server)对具有默认证书的UE进行认证。DCS可以直接认证UE或者或请求其他实体对UE进行认证。When the UE does not have the certificate of the first network, the first network needs to authenticate the UE before downloading the certificate for the UE or establishing a data channel for downloading the certificate. The UE may have a default certificate. In this case, the first network can request the default certificate authentication server (DCS Default Credential Server) to authenticate the UE with the default certificate. The DCS can directly authenticate the UE or request other entities to authenticate the UE.

这种类型的认证类比UE在漫游接入其他网络的认证但又不同于UE漫游认证。This type of authentication is similar to the authentication of UE when roaming to other networks, but is different from UE roaming authentication.

-在漫游的情况下,UE访问的网络的AMF为UE选择UE归属网络的鉴权服务器(Home-Authentication Server Function,归属AUSF),并请求归属AUSF对UE进行认证。-In the case of roaming, the AMF of the network visited by the UE selects the Home-Authentication Server Function (AUSF) of the UE's home network for the UE and requests the home AUSF to authenticate the UE.

-在onboarding方式下,如图1B所示,第一网络的AMF可以为UE选择UE访问的第一网络下的认证代理服务器(比如,鉴权服务器功能(Authentication Server Function,AUSF),或者AAA(Authentication Authorization Accounting Server)服务器代理),并由认证代理服务器来请求另一网络中默认鉴权服务器(Default Credential Server,DCS)对UE进行认证。当UE具有的默认证书是通信网络(如3GPP的网络)的证书时,DCS可以是UE归属网络的归属AUSF。NRF保存有网元的关系,可以被调用进行网元的查询。-In the onboarding mode, as shown in Figure 1B, the AMF of the first network can select an authentication proxy server (for example, an authentication server function (AUSF) or an AAA (Authentication Authorization Accounting Server) server agent) under the first network accessed by the UE for the UE, and the authentication proxy server requests the default authentication server (DCS) in another network to authenticate the UE. When the default certificate of the UE is a certificate of a communication network (such as a 3GPP network), the DCS can be the AUSF of the UE's home network. The NRF stores the relationship between network elements and can be called to query network elements.

具有公共陆地移动网(Public Land Mobile Network,PLMN)证书的UE可以:1)通过PLMN证书漫游接入其他PLMN网络,2)通过PLMN证书接入SNPN,3)还可以onboarding到第一网络进行默认证书认证。其中,对于方式1),UE接入网络的AMF与UE归属网络的AUSF联系。对于方式3),UE接入网络的AMF与接入网络的认证代理服务器(如AUSF,或AAA服务器代理)联系,所述认证代理服务器与UE归属AUSF联系。对于方式2),可能采用方式1)的认证结构也可能采用方式3)的认证结构。A UE with a Public Land Mobile Network (PLMN) certificate can: 1) roam and access other PLMN networks through the PLMN certificate, 2) access the SNPN through the PLMN certificate, and 3) onboard to the first network for default certificate authentication. For method 1), the AMF of the UE access network contacts the AUSF of the UE's home network. For method 3), the AMF of the UE access network contacts the authentication proxy server (such as AUSF, or AAA server agent) of the access network, and the authentication proxy server contacts the AUSF of the UE's home network. For method 2), the authentication structure of method 1) may be used, and the authentication structure of method 3) may be used.

为了支持方式3)的认证结构,还要解决如下问题:In order to support the authentication structure of method 3), the following problems must be solved:

问题1:目前的AMF连接的AUSF选择是,AMF根据UE提供的签约永久标识(Subscription Permanent Identifier,SUPI)中的归属网络标识(Home NetworkIdentifier)或者SUPI关联的AUSF组标识(Group ID)进行选择的。但是在onboarding的架构中,第一网络的AMF需为UE选择第一网络中的AUSF,AUSF再为UE选择UE归属地的AUSF。第一网络的AUSF与UE无关,与UE的SUPI无关。如何区分不同接入类型的UE选择不同的AUSF成为一个需要解决的问题。Question 1: The current AUSF selection for the AMF connection is that the AMF selects the Home Network Identifier (Home Network Identifier) in the Subscription Permanent Identifier (SUPI) provided by the UE or the AUSF group ID (Group ID) associated with the SUPI. However, in the onboarding architecture, the AMF of the first network needs to select the AUSF in the first network for the UE, and the AUSF then selects the AUSF in the UE's home area for the UE. The AUSF of the first network has nothing to do with the UE and has nothing to do with the UE's SUPI. How to distinguish UEs of different access types and select different AUSFs has become a problem that needs to be solved.

本申请实施例中,可选的,获取可以理解为从配置获得、接收、通过请求后接收、通过自学习获取、根据未收到的信息推导获取或者是根据接收的信息处理后获得,具体可根据实际需要确定,本申请实施例对此不作限定。比如当未收到设备发送的某个能力指示信息时可推导出该设备不支持该能力。In the embodiments of the present application, optionally, acquisition can be understood as acquisition from configuration, reception, reception after request, acquisition through self-learning, acquisition by deduction based on information not received, or acquisition after processing of received information, which can be determined according to actual needs and is not limited in the embodiments of the present application. For example, when a certain capability indication information sent by a device is not received, it can be deduced that the device does not support the capability.

可选的,发送可以包含广播,系统消息中广播,响应请求后返回。Optionally, the sending may include broadcasting, broadcasting in system messages, and returning after responding to requests.

在本申请一种实施例中,非公网是非公众网络的简称。非公众网络可以称为以下之一:非公众通信网络。非公网可以包括以下至少一种部署方式:物理的非公网、虚拟的非公网、实现在公网上的非公网。一种实施方式中,非公网为封闭访问组(Closed AccessGroup,CAG)。一个CAG可以由一组终端组成。In one embodiment of the present application, non-public network is short for non-public network. Non-public network can be referred to as one of the following: non-public communication network. Non-public network can include at least one of the following deployment modes: physical non-public network, virtual non-public network, non-public network implemented on the public network. In one implementation mode, non-public network is a closed access group (Closed Access Group, CAG). A CAG can be composed of a group of terminals.

在本申请一种实施例中,非公网服务是非公众网络服务的简称。非公众网络服务也可以称为以下之一:非公众网络的网络服务、非公众通信服务、非公众网络通信服务、非公网的网络服务或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。一种实施方式中,非公网为封闭访问组,此时,非公网服务为封闭的访问组的网络服务。In one embodiment of the present application, non-public network service is the abbreviation of non-public network service. Non-public network service can also be referred to as one of the following: network service of non-public network, non-public communication service, non-public network communication service, network service of non-public network or other naming. It should be noted that in the embodiment of the present invention, there is no specific limitation on the naming method. In one implementation mode, the non-public network is a closed access group. In this case, the non-public network service is a network service of the closed access group.

在本申请一种实施例中,非公众网络可以包含或称为私有网络。私有网络可以称为以下之一:私有通信网络、私网、本地区域网络(LAN)、私有虚拟网络(PVN)、隔离的通信网络、专用的通信网络或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。In one embodiment of the present application, a non-public network may include or be referred to as a private network. A private network may be referred to as one of the following: a private communication network, a private network, a local area network (LAN), a private virtual network (PVN), an isolated communication network, a dedicated communication network, or other names. It should be noted that the naming method is not specifically limited in the embodiments of the present invention.

在本申请一种实施例中,公网是公众网络的简称。公众网络可以称为以下之一:公众通信网络或其他命名。需要说明的是,在本发明实施例中对于命名方式不做具体限定。In one embodiment of the present application, the public network is the abbreviation of the public network. The public network can be called one of the following: a public communication network or other names. It should be noted that the naming method is not specifically limited in the embodiment of the present invention.

本申请一种可选实施例中,鉴权服务包括向鉴权服务器(如DCS,或归属AUSF)发起对终端的鉴权请求。鉴权服务网元可以是为终端提供鉴权服务的鉴权代理。可选的,所述鉴权服务网元可以包括但不限于以下之一:AUSF、AAA代理。In an optional embodiment of the present application, the authentication service includes initiating an authentication request for the terminal to an authentication server (such as a DCS or a home AUSF). The authentication service network element may be an authentication agent that provides authentication services for the terminal. Optionally, the authentication service network element may include but is not limited to one of the following: AUSF, AAA agent.

本申请一种可选实施例中,第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。In an optional embodiment of the present application, the indication information of the first access method is used to indicate at least one of the following: an access method for accessing the first network in order to download a certificate for accessing the second network, an access method for accessing the first network without a certificate capable of accessing the first network, an access method capable of using only restricted services, and the certificate for the terminal to access the first network is a default certificate.

本申请一种可选实施例中,所述终端接入第一网络的证书为默认证书是指终端接入第一网络时,向第一网络提供的终端的标识对应的证书为默认证书。一种实施方式中,所述默认证书不是第一网络的证书。In an optional embodiment of the present application, the certificate for the terminal to access the first network is a default certificate, which means that when the terminal accesses the first network, the certificate corresponding to the terminal identifier provided to the first network is the default certificate. In one implementation, the default certificate is not a certificate of the first network.

可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。Optionally, the first network and the second network are the same network or different networks.

本申请一种可选实施例中,所述第一网络的网络类型可以包括但不限于以下之一:公网(如PLMN),独立非公网(如NPN),公网集成的非公网(如PNI NPN)。In an optional embodiment of the present application, the network type of the first network may include but is not limited to one of the following: a public network (such as PLMN), an independent non-public network (such as NPN), and a non-public network integrated with a public network (such as PNI NPN).

本申请一种可选实施例中,不具有能够能够接入第一网络的证书包括不具有能够访问第一网络的非受限服务的证书。In an optional embodiment of the present application, not having a certificate capable of accessing the first network includes not having a certificate capable of accessing a non-restricted service of the first network.

1)一种实施方式中,终端直接具有B网络的证书,可以认为终端具有能够接入B网络的证书。1) In one implementation, the terminal directly has a certificate of the B network, and it can be considered that the terminal has a certificate that can access the B network.

2)另一种实施方式中,服务提供方A(包括A网络)与B网络间存在允许A的终端接入B网络享受网络服务的协议(如漫游协议),此时,可以认为A的终端具有能够接入B网络的证书,即A的证书。此中,服务提供方A的终端和B网络的终端接入B网络,可以认为访问的是非受限服务。2) In another implementation, there is an agreement (such as a roaming agreement) between service provider A (including A network) and B network that allows A's terminal to access B network and enjoy network services. In this case, it can be considered that A's terminal has a certificate that can access B network, that is, A's certificate. Here, the terminal of service provider A and the terminal of B network access B network, and it can be considered that the access is non-restricted service.

3)另一种实施方式中,服务提供方C(包括C网络)的终端为了下载接入B网络的证书而接入B网络的方式中,终端具有的C的证书能够帮助B网络请求C中的鉴权服务器验证终端。此时终端具有的C的证书并不是能够接入B网络的证书,而是B网络能够验证终端的证书,一般称为默认证书。此中,服务提供方C的终端接入B网络,可以认为访问的是受限服务。3) In another implementation, when a terminal of service provider C (including C network) accesses B network in order to download a certificate for accessing B network, the certificate of C possessed by the terminal can help B network request the authentication server in C to verify the terminal. In this case, the certificate of C possessed by the terminal is not a certificate that can access B network, but a certificate that B network can verify the terminal, which is generally called a default certificate. Here, when the terminal of service provider C accesses B network, it can be considered that the access is a restricted service.

本申请一种可选实施例中,认证提供方为能够对具有默认证书的终端进行验证的提供方。一种实施方式中,所述认证提供方不包括漫游场景中的终端归属网络。In an optional embodiment of the present application, the authentication provider is a provider that can verify a terminal with a default certificate. In one implementation, the authentication provider does not include the home network of the terminal in a roaming scenario.

本申请一种可选实施例中,所述终端的认证提供方的信息包括以下至少一项:终端的默认证书对应网络的网络标识,终端的默认证书对应的终端的标识中的网络标识,终端的归属网络的网络标识,默认证书验证提供方的索引信息,DCS的索引信息。不难理解。终端的证书与终端的标识对应。所述终端的认证提供方的信息可以包含在终端的标识中。In an optional embodiment of the present application, the information of the authentication provider of the terminal includes at least one of the following: the network identifier of the network corresponding to the default certificate of the terminal, the network identifier in the identifier of the terminal corresponding to the default certificate of the terminal, the network identifier of the home network of the terminal, the index information of the default certificate verification provider, and the index information of the DCS. It is not difficult to understand. The certificate of the terminal corresponds to the identifier of the terminal. The information of the authentication provider of the terminal can be included in the identifier of the terminal.

本申请一种可选实施例中,所述终端的第一标识包括以下之一:终端的默认证书对应的终端标识,或者终端在DCS中的终端标识。In an optional embodiment of the present application, the first identifier of the terminal includes one of the following: a terminal identifier corresponding to a default certificate of the terminal, or a terminal identifier of the terminal in a DCS.

一种实施方式中,所述终端的归属网络的标识为终端的默认证书对应的终端的标识中的网络的标识。另一种实施方式中,所述终端的归属网络标识为验证提供方网络的标识。In one implementation, the identifier of the home network of the terminal is the identifier of the network in the identifier of the terminal corresponding to the default certificate of the terminal. In another implementation, the identifier of the home network of the terminal is the identifier of the verification provider network.

可选的,DCS是终端的认证提供方中的设备。当DCS包括终端归属的AUSF时,所述终端的第一标识为终端在归属网络中的终端标识。此时,默认证书验证方的索引信息或DCS的索引信息为终端的归属网络的标识。Optionally, the DCS is a device in the authentication provider of the terminal. When the DCS includes the AUSF to which the terminal belongs, the first identifier of the terminal is the terminal identifier of the terminal in the home network. At this time, the index information of the default certificate verifier or the index information of the DCS is the identifier of the home network of the terminal.

本申请一种可选实施例中,所述归属网络可以为终端的默认证书对应的网络。一种实施方式中,归属AUSF为归属网络中的AUSF。归属NRF为归属网络中的NRF。其他归属网元为归属网络中的网元。In an optional embodiment of the present application, the home network may be a network corresponding to a default certificate of the terminal. In one implementation, the home AUSF is an AUSF in the home network. The home NRF is an NRF in the home network. Other home network elements are network elements in the home network.

本申请一种可选实施例中,第一类型的网络标识包括第一类型的归属网络标识。用于第一接入方式的归属网络标识包括用于第一接入方式的归属网络标识。第一类型的归属网络标识包括:用于第一接入方式的归属网络标识。In an optional embodiment of the present application, the first type of network identifier includes a first type of home network identifier. The home network identifier used for the first access mode includes a home network identifier used for the first access mode. The first type of home network identifier includes: a home network identifier used for the first access mode.

本申请一种另可选实施例中,第一类型的网络标识可以是以下之一:认证提供方的网络标识,终端的默认证书对应的网络标识,终端的默认证书对应的终端的标识中的网络标识。In another optional embodiment of the present application, the first type of network identifier may be one of the following: a network identifier of an authentication provider, a network identifier corresponding to a default certificate of a terminal, and a network identifier in an identifier of a terminal corresponding to a default certificate of a terminal.

本申请一种可选实施例中,通信设备可以包括以下至少一项:通信网元和终端。In an optional embodiment of the present application, the communication device may include at least one of the following: a communication network element and a terminal.

本申请一种实施例中,通信网元可以包括以下至少一项:核心网网元和无线接入网网元。In one embodiment of the present application, the communication network element may include at least one of the following: a core network element and a wireless access network element.

本申请实施例中,核心网网元(CN网元)可以包含但不限于如下至少一项:核心网设备、核心网节点、核心网功能、核心网网元、移动管理实体(Mobility ManagementEntity,MME)、接入移动管理功能(Access Management Function,AMF)、网络存储功能(Network Repository Function,NRF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、服务网关(serving GW,SGW)、PDN网关(PDN Gate Way,PDN网关)、策略控制功能(Policy Control Function、PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、GPRS服务支持节点(ServingGPRS Support Node,SGSN)、网关GPRS支持节点(Gateway GPRS Support Node,GGSN)、统一数据管理(Unified Data Management,UDM),统一数据存储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)和应用功能(ApplicationFunction,AF)。In the embodiment of the present application, the core network element (CN element) may include but is not limited to at least one of the following: core network equipment, core network node, core network function, core network element, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access Management Function, AMF), network storage function (Network Repository Function, NRF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), serving gateway (serving GW, SGW), PDN gateway (PDN Gate Way, PDN Gateway), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), GPRS service support node (Serving GPRS Support Node, SGSN), gateway GPRS support node (Gateway GPRS Support Node, GGSN), unified data management (Unified Data Management, UDM), unified data storage (Unified Data Repository, UDR), home subscriber server (Home Subscriber Server, HSS) and application function (Application Function, AF).

以下对本申请实施例的接入控制方法进行说明。The access control method of the embodiment of the present application is described below.

请参考图2,本申请实施例提供了一种接入控制方法,应用于第一通信设备;该第一通信设备包括AMF。可选的,该第一通信设备为第一网络中的通信设备。如图2所示,所述方法包括:Referring to FIG. 2 , an embodiment of the present application provides an access control method, which is applied to a first communication device; the first communication device includes an AMF. Optionally, the first communication device is a communication device in a first network. As shown in FIG. 2 , the method includes:

步骤21:获取第一信息和/或第二信息。Step 21: Obtain the first information and/or the second information.

其中,所述第一信息包括但不限于以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识。所述第二信息包括但不限于以下至少一项:第一类型的路由指示、第一类型的网络标识、第一类型的组标识、终端的标识信息。The first information includes but is not limited to at least one of the following: indication information of the first access mode, a first type of routing indication, and a first type of network identification. The second information includes but is not limited to at least one of the following: a first type of routing indication, a first type of network identification, a first type of group identification, and identification information of the terminal.

可选的,所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识。Optionally, the first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to terminals of the first access mode.

可选的,所述第一类型的网络标识包括:用于第一接入方式的网络标识。Optionally, the first type of network identifier includes: a network identifier used for a first access mode.

可选的,所述第一类型的路由指示包括:用于第一接入方式的路由指示。Optionally, the first type of routing indication includes: a routing indication for a first access mode.

一种实施方式中,可以从终端接收获取第一信息。上述的第一信息可以包含在终端的标识(如SUCI,或SUPI等)中进行发送。In one implementation, the first information may be received from the terminal. The first information may be included in an identifier of the terminal (such as SUCI or SUPI, etc.) and sent.

另一种实施方式中,可以第一通信设备本地配置获取第二信息。In another implementation, the second information may be acquired by local configuration of the first communication device.

所述终端的标识信息可以包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识。The identification information of the terminal may include at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal.

1)所述终端的第一标识包含终端的认证提供方的信息。所述认证提供方为能够对具有默认证书的终端进行验证的提供方,或者是能够认证终端的提供方(如终端的归属网络,终端的默认证书对应的网络)。一种实施方式中,所述认证提供方不包括漫游场景中的终端归属网络1) The first identification of the terminal includes information of the authentication provider of the terminal. The authentication provider is a provider that can verify the terminal with the default certificate, or a provider that can authenticate the terminal (such as the home network of the terminal, the network corresponding to the default certificate of the terminal). In one embodiment, the authentication provider does not include the home network of the terminal in the roaming scenario.

所述终端的认证提供方的信息包括以下至少一项:终端的默认证书对应网络的网络标识,终端的默认证书对应的终端的标识中的网络标识,终端的归属网络的网络标识,默认证书验证提供方的索引信息,DCS的索引信息。不难理解。终端的证书与终端的标识对应。所述终端的认证提供方的信息可以包含在终端的标识中。The information of the authentication provider of the terminal includes at least one of the following: the network identifier of the network corresponding to the default certificate of the terminal, the network identifier in the identifier of the terminal corresponding to the default certificate of the terminal, the network identifier of the home network of the terminal, the index information of the default certificate verification provider, and the index information of the DCS. It is not difficult to understand. The certificate of the terminal corresponds to the identifier of the terminal. The information of the authentication provider of the terminal can be included in the identifier of the terminal.

所述终端的第一标识包括以下之一:终端的默认证书对应的终端标识,或者终端在DCS中的终端标识。The first identifier of the terminal includes one of the following: a terminal identifier corresponding to a default certificate of the terminal, or a terminal identifier of the terminal in the DCS.

可选的,DCS是终端的认证提供方中的设备。当DCS包括终端归属的AUSF时,所述终端的第一标识为终端在归属网络中的终端标识。此时,默认证书验证方的索引信息或DCS的索引信息为终端的归属网络的标识。Optionally, the DCS is a device in the authentication provider of the terminal. When the DCS includes the AUSF to which the terminal belongs, the first identifier of the terminal is the terminal identifier of the terminal in the home network. At this time, the index information of the default certificate verifier or the index information of the DCS is the identifier of the home network of the terminal.

2)所述终端的第二标识包含第一类型的网络标识和/或第一类型的路由指示;2) The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

3)所述终端的第三标识中包含终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。3) The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

不难理解,根据终端的第二标识或根据终端的第三标识,可以确定第一类型的网络标识和/或第一类型的路由指示。It is not difficult to understand that the first type of network identifier and/or the first type of routing indication can be determined according to the second identifier of the terminal or according to the third identifier of the terminal.

1)一种实施方式中,可发送终端的第一标识和第一类型的网络标识。1) In one implementation, a first identifier of the terminal and a first type of network identifier may be sent.

2)另一种实施方式中,可发送终端的第一标识和第一类型的路由指示。2) In another implementation, a first identifier of the terminal and a first type of routing indication may be sent.

3)另一种实施方式中,可发送终端的第一标识和终端的第二标识。3) In another implementation, the first identifier of the terminal and the second identifier of the terminal may be sent.

4)另一种实施方式中,可发送终端的第三标识。4) In another implementation, a third identifier of the terminal may be sent.

步骤22:根据第一信息和/或第二信息,执行第一操作。Step 22: Execute a first operation according to the first information and/or the second information.

其中,所述第一操作可以包括以下至少一项:The first operation may include at least one of the following:

选择第一鉴权服务网元;Select the first authentication service network element;

确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;Determining a first type of group identifier, a first type of routing indication, information of a service provider, and/or a first type of network identifier;

根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元。A request is made to discover an authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, information of a service provider and/or indication information of a first access method.

可选的,所述第一接入方式的指示信息可用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。Optionally, the indication information of the first access method can be used to indicate at least one of the following: an access method for accessing the first network in order to download a certificate for accessing the second network, an access method for accessing the first network without a certificate capable of accessing the first network, an access method capable of using only restricted services, and the certificate for the terminal to access the first network is the default certificate.

可选的,所述第一网络和所述第二网络是同一个网络或者不同的网络。Optionally, the first network and the second network are the same network or different networks.

一种实施方式中,第一接入方式的指示信息包括第一注册类型。而第一注册类型可以用于指示以下至少一项:为了下载用于接入第二网络的证书而注册接入第一网络的注册方式、不具有能够接入第一网络的证书而注册第一网络的注册方式。In one implementation, the indication information of the first access method includes a first registration type. The first registration type may be used to indicate at least one of the following: a registration method for registering to access the first network in order to download a certificate for accessing the second network, and a registration method for registering the first network without having a certificate capable of accessing the first network.

可选的,上述能够接入第一网络的证书包括能够访问第一网络的非受限服务的证书。上述不具有能够能够接入第一网络的证书包括不具有能够访问第一网络的非受限服务的证书。Optionally, the certificate capable of accessing the first network includes a certificate capable of accessing unrestricted services of the first network. The certificate not capable of accessing the first network includes a certificate not capable of accessing unrestricted services of the first network.

1)一种实施方式中,终端直接具有B网络的证书,可以认为终端具有能够接入B网络的证书。1) In one implementation, the terminal directly has a certificate of the B network, and it can be considered that the terminal has a certificate that can access the B network.

2)另一种实施方式中,服务提供方A(包括A网络)与B网络间存在允许A的终端接入B网络享受网络服务的协议(如漫游协议),此时,可以认为A的终端具有能够接入B网络的证书,即A的证书。此中,服务提供方A的终端和B网络的终端接入B网络,可以认为访问的是非受限服务。2) In another implementation, there is an agreement (such as a roaming agreement) between service provider A (including A network) and B network that allows A's terminal to access B network and enjoy network services. In this case, it can be considered that A's terminal has a certificate that can access B network, that is, A's certificate. Here, the terminal of service provider A and the terminal of B network access B network, and it can be considered that the access is non-restricted service.

3)另一种实施方式中,服务提供方C(包括C网络)的终端为了下载接入B网络的证书而接入B网络的方式中,终端具有的C的证书能够帮助B网络请求C中的鉴权服务器验证终端。此时终端具有的C的证书并不是能够接入B网络的证书,而是B网络能够验证终端的证书,一般称为默认证书。此中,服务提供方C的终端接入B网络,可以认为访问的是受限服务。3) In another implementation, when a terminal of service provider C (including C network) accesses B network in order to download a certificate for accessing B network, the certificate of C possessed by the terminal can help B network request the authentication server in C to verify the terminal. In this case, the certificate of C possessed by the terminal is not a certificate that can access B network, but a certificate that B network can verify the terminal, which is generally called a default certificate. Here, when the terminal of service provider C accesses B network, it can be considered that the access is a restricted service.

可选的,上述的第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元。Optionally, the above-mentioned first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals of the first access mode, and an authentication service network element for providing authentication services to terminals with default certificates.

一种实施方式中,所述鉴权服务包括向鉴权服务器(如DCS,或归属AUSF)发起对终端的鉴权请求。In one implementation, the authentication service includes initiating an authentication request for the terminal to an authentication server (such as a DCS or a home AUSF).

本申请实施例中,上述根据第一类型的组标识、第一类型的路由指示、第一类型的网络标识或第一接入方式的指示信息,请求发现鉴权服务网元可包括以下至少一项:In the embodiment of the present application, the request to discover the authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, or the indication information of the first access method may include at least one of the following:

向第一目标端发送所述第一类型的组标识,所述第一类型的组标识用于所述第一目标端发现匹配所述第一类型的组标识的鉴权服务网元;Sending the first type of group identifier to a first target end, where the first type of group identifier is used by the first target end to discover an authentication service network element matching the first type of group identifier;

向第一目标端发送所述第一接入方式的指示信息,所述第一接入方式的指示信息用于所述第一目标端发现匹配所述第一接入方式的指示信息的鉴权服务网元;Sending indication information of the first access method to a first target end, where the indication information of the first access method is used by the first target end to find an authentication service network element matching the indication information of the first access method;

向第一目标端发送所述第一类型的路由指示,所述第一类型的路由指示用于所述第一目标端发现匹配所述第一类型的路由指示的鉴权服务网元。The first type of routing indication is sent to a first target end, where the first type of routing indication is used by the first target end to discover an authentication service network element matching the first type of routing indication.

向第一目标端发送所述第一类型的网络标识,所述第一类型的网络标识用于所述第一目标端发现匹配所述第一类型的网络标识的鉴权服务网元。The first type of network identifier is sent to a first target end, where the first type of network identifier is used by the first target end to discover an authentication service network element matching the first type of network identifier.

可选的,所述第一目标端可以包括:负责查询网络中网元的网元设备,比如网络存储库功能(Network Repository Function,NRF)。Optionally, the first target end may include: a network element device responsible for querying network elements in the network, such as a network repository function (Network Repository Function, NRF).

可选的,所述鉴权服务网元可以包括但不限于以下之一:AUSF、AAA代理。一种实施方式中,鉴权服务网元可以是为终端提供鉴权服务的鉴权代理。Optionally, the authentication service network element may include but is not limited to one of the following: AUSF, AAA proxy. In one implementation, the authentication service network element may be an authentication proxy that provides authentication services for the terminal.

一种实施方式中,可以通过专用于第一接入方式的AUSF组标识向NRF请求发现AUSF。In one implementation, the AUSF discovery may be requested from the NRF via an AUSF group identifier dedicated to the first access method.

可选的,上述获取第一信息可包括:从终端获取第一信息。和/或,上述获取第二信息可包括:根据第一通信设备上的配置,获取第二信息。Optionally, the acquiring of the first information may include: acquiring the first information from a terminal. And/or, the acquiring of the second information may include: acquiring the second information according to a configuration on the first communication device.

可选的,上述获取第一信息和/或第二信息可以包括以下至少一项:Optionally, the obtaining of the first information and/or the second information may include at least one of the following:

从终端获取第一接入方式的指示信息;Acquire indication information of a first access mode from a terminal;

根据第一通信设备上的配置,获取第一类型的组标识、第一类型的路由指示或者第一类型的网络标识。According to the configuration on the first communication device, a first type of group identifier, a first type of routing indication or a first type of network identifier is acquired.

进一步的,上述根据第一信息和/或第二信息,执行第一操作可以包括:Further, performing the first operation according to the first information and/or the second information may include:

根据所述第一接入方式的指示信息,确定第一类型的组标识、第一类型的路由指示或第一类型的网络标识;Determine, according to the indication information of the first access mode, a first type of group identifier, a first type of routing indication, or a first type of network identifier;

根据所述第一类型的组标识、第一类型的路由指示和/或第一类型的网络标识,请求发现鉴权服务网元。A request is made to discover an authentication service network element according to the first type of group identifier, the first type of routing indication and/or the first type of network identifier.

可选的,上述获取第一信息和/或第二信息可以包括以下至少一项:Optionally, the obtaining of the first information and/or the second information may include at least one of the following:

从终端获取第一类型的网络标识和/或第一类型的路由指示,acquiring a first type of network identification and/or a first type of routing indication from the terminal,

根据第一通信设备上的配置,获取第一类型的组标识;Acquire a first type of group identifier according to a configuration on the first communication device;

进一步的,上述根据第一信息和/或第二信息,执行第一操作可以包括:Further, performing the first operation according to the first information and/or the second information may include:

根据所述第一类型的网络标识和/或第一类型的路由指示,确定第一类型的组标识;Determining a first type of group identifier according to the first type of network identifier and/or the first type of routing indication;

根据所述第一类型的组标识,请求发现鉴权服务网元。According to the group identifier of the first type, a request is made to discover an authentication service network element.

可选的,上述的第一操作还包括以下至少一项:Optionally, the first operation further includes at least one of the following:

接收请求发现的鉴权服务网元;receiving an authentication service network element requested for discovery;

根据终端的第二标识或终端的第三标识导出第一类型的网络标识和/或第一类型的路由指示;Deriving a first type of network identifier and/or a first type of routing indication according to the second identifier of the terminal or the third identifier of the terminal;

不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;Not sending the second identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

根据终端的第三标识,导出终端的第一标识;deriving the first identifier of the terminal according to the third identifier of the terminal;

向第一鉴权服务网元或或所述发现的鉴权服务网元发送终端的第一标识。Sending the first identifier of the terminal to the first authentication service network element or the discovered authentication service network element.

不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。It is not difficult to understand that, through this embodiment, in the scenario where the terminal accesses the first network in the first access mode, selection of the authentication service network element can be supported.

请参考图3,本申请实施例提供了一种接入控制方法,应用于第二通信设备;该第二通信设备包括UE。如图3所示,所述方法包括:Referring to FIG3 , an embodiment of the present application provides an access control method, which is applied to a second communication device; the second communication device includes a UE. As shown in FIG3 , the method includes:

步骤31:发送第一信息。Step 31: Send the first message.

其中,所述第一信息包可以括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息。The first information packet may include at least one of the following: indication information of a first access mode, a first type of routing indication, a first type of network identification, and identification information of a terminal.

所述第一类型的路由指示包括:用于第一接入方式的路由指示。The first type of routing indication includes: a routing indication used for a first access mode.

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。The indication information of the first access method is used to indicate at least one of the following: an access method for accessing the first network in order to download a certificate for accessing the second network, an access method for accessing the first network without a certificate capable of accessing the first network, an access method capable of using only restricted services, and the certificate for the terminal to access the first network is a default certificate.

所述第一网络和所述第二网络是同一个网络或不同的网络。The first network and the second network are the same network or different networks.

可选的,向终端接入的第一网络发送所述第一信息。终端接入第一网络的方式为第一接入方式。上述的第一信息可以包含在终端的标识(如SUCI,或SUPI等)中进行发送。Optionally, the first information is sent to a first network accessed by the terminal. The way in which the terminal accesses the first network is the first access way. The above-mentioned first information may be included in an identifier of the terminal (such as SUCI, or SUPI, etc.) and sent.

可选的,上述发送第一信息可以包括:在满足第一条件的情况下,发送所述第一信息。其中,所述第一条件可以包括以下至少一项:Optionally, sending the first information may include: sending the first information when a first condition is met. The first condition may include at least one of the following:

第二通信设备接入第一网络的目是为了下载用于接入第二网络的证书;The purpose of the second communication device accessing the first network is to download a certificate for accessing the second network;

第二通信设备不具有能够接入第一网络的证书;The second communication device does not have a certificate capable of accessing the first network;

第二通信设备接入第一网络仅能够使用受限服务。The second communication device can only use restricted services when accessing the first network.

所述第一网络和所述第二网络是同一个网络或不同的网络。The first network and the second network are the same network or different networks.

一种实施方式中,所述用于第一接入方式的网络标识是通过终端的用户永久标识SUPI发送的。In one implementation, the network identifier used for the first access mode is sent via a user permanent identifier SUPI of the terminal.

需指出的,所述第二通信设备不具有能够接入第一网络的证书包括:第二通信设备不具有第一网络的证书或者第二通信设备不具有能够接入第一网络的服务提供方的证书。It should be noted that the second communication device does not have a certificate capable of accessing the first network includes: the second communication device does not have a certificate for the first network or the second communication device does not have a certificate for a service provider capable of accessing the first network.

上述能够接入第一网络的证书可以包括能够访问第一网络的非受限服务的证书。上述不具有能够能够接入第一网络的证书包括不具有能够访问第一网络的非受限服务的证书。The certificate capable of accessing the first network may include a certificate capable of accessing unrestricted services of the first network. The certificate not capable of accessing the first network may include a certificate not capable of accessing unrestricted services of the first network.

1)一种实施方式中,终端直接具有B网络的证书,可以认为终端具有能够接入B网络的证书。1) In one implementation, the terminal directly has a certificate of the B network, and it can be considered that the terminal has a certificate that can access the B network.

2)另一种实施方式中,服务提供方A(包括A网络)与B网络间存在允许A的终端接入B网络享受网络服务的协议(如漫游协议),此时,可以认为A的终端具有能够接入B网络的证书,即A的证书。此中,服务提供方A的终端和B网络的终端接入B网络,可以认为访问的是非受限服务。2) In another implementation, there is an agreement (such as a roaming agreement) between service provider A (including A network) and B network that allows A's terminal to access B network and enjoy network services. In this case, it can be considered that A's terminal has a certificate that can access B network, that is, A's certificate. Here, the terminal of service provider A and the terminal of B network access B network, and it can be considered that the access is non-restricted service.

3)另一种实施方式中,服务提供方C(包括C网络)的终端为了下载接入B网络的证书而接入B网络的方式中,终端具有的C的证书能够帮助B网络请求C中的鉴权服务器验证终端。此时终端具有的C的证书并不是能够接入B网络的证书,而是B网络能够验证终端的证书,一般称为默认证书。此中,服务提供方C的终端接入B网络,可以认为访问的是受限服务。3) In another implementation, when a terminal of service provider C (including C network) accesses B network in order to download a certificate for accessing B network, the certificate of C possessed by the terminal can help B network request the authentication server in C to verify the terminal. In this case, the certificate of C possessed by the terminal is not a certificate that can access B network, but a certificate that B network can verify the terminal, which is generally called a default certificate. Here, when the terminal of service provider C accesses B network, it can be considered that the access is a restricted service.

可选的,所述终端的标识信息可以包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识。Optionally, the identification information of the terminal may include at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal.

1)所述终端的第一标识包含终端的认证提供方的信息。所述认证提供方为能够对具有默认证书的终端进行验证的提供方,或者是能够认证终端的提供方(如终端的归属网络)。1) The first identification of the terminal includes information of an authentication provider of the terminal. The authentication provider is a provider that can verify a terminal with a default certificate, or a provider that can authenticate the terminal (such as the home network of the terminal).

所述终端的认证提供方的信息包括以下至少一项:终端的默认证书对应网络的网络标识,终端的默认证书对应的终端的标识中的网络标识,终端的归属网络的网络标识,默认证书验证提供方的索引信息,DCS的索引信息。所述终端的认证提供方的信息可以包含在终端的标识中。The information of the authentication provider of the terminal includes at least one of the following: the network identifier of the network corresponding to the default certificate of the terminal, the network identifier in the identifier of the terminal corresponding to the default certificate of the terminal, the network identifier of the home network of the terminal, the index information of the default certificate verification provider, and the index information of the DCS. The information of the authentication provider of the terminal may be included in the identifier of the terminal.

不难理解。终端的证书与终端的标识对应。所述终端的第一标识包括以下之一:终端的默认证书对应的终端标识,或者终端在DCS中的终端标识。It is not difficult to understand that the certificate of the terminal corresponds to the identifier of the terminal. The first identifier of the terminal includes one of the following: the terminal identifier corresponding to the default certificate of the terminal, or the terminal identifier of the terminal in the DCS.

可选的,DCS是终端的认证提供方中的设备。当DCS包括终端归属的AUSF时,所述终端的第一标识为终端在归属网络中的终端标识。此时,默认证书验证方的索引信息或DCS的索引信息为终端的归属网络的标识。Optionally, the DCS is a device in the authentication provider of the terminal. When the DCS includes the AUSF to which the terminal belongs, the first identifier of the terminal is the terminal identifier of the terminal in the home network. At this time, the index information of the default certificate verifier or the index information of the DCS is the identifier of the home network of the terminal.

2)所述终端的第二标识包含第一类型的网络标识和/或第一类型的路由指示;2) The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

3)所述终端的第三标识中包含终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。3) The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

不难理解,根据终端的第二标识或根据终端的第三标识,可以确定第一类型的网络标识和/或第一类型的路由指示。It is not difficult to understand that the first type of network identifier and/or the first type of routing indication can be determined according to the second identifier of the terminal or according to the third identifier of the terminal.

1)一种实施方式中,可发送终端的第一标识和第一类型的网络标识。1) In one implementation, a first identifier of the terminal and a first type of network identifier may be sent.

2)另一种实施方式中,可以发送终端的第一标识和第一类型的路由指示。2) In another implementation, the first identifier of the terminal and the first type of routing indication may be sent.

3)另一种实施方式中,可以发送终端终端的第一标识和终端的第二标识。3) In another implementation, the first identifier of the terminal and the second identifier of the terminal may be sent.

4)另一种实施方式中,可以发送终端的第三标识。4) In another implementation, a third identifier of the terminal may be sent.

可选的,在发送第一信息的步骤之前,所述方法还可包括以下至少一项:Optionally, before the step of sending the first information, the method may further include at least one of the following:

生成终端的第二标识,即将终端的标识中的路由指示设置为第一类型的路由指示和/或将终端的标识中的归属网络标识设置为第一类型的网络标识;Generate a second identifier of the terminal, that is, set the routing indication in the identifier of the terminal to the routing indication of the first type and/or set the home network identifier in the identifier of the terminal to the network identifier of the first type;

生成终端的第三标识,即将第一类型的网络标识添加到终端的标识中和/或将第一类型的路由指示添加到终端的标识中。The third identifier of the terminal is generated, that is, the first type of network identifier is added to the identifier of the terminal and/or the first type of routing indication is added to the identifier of the terminal.

一种实施方式中,所述生成终端的第二标识和/或生成终端的第三标识的操作是在满足第一条件的情况下执行的。第一条件如上所述,此处不再赘述。In one implementation, the operation of generating the second identifier of the terminal and/or generating the third identifier of the terminal is performed when a first condition is satisfied. The first condition is as described above and will not be described in detail herein.

不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,,支持对鉴权服务网元的选择。It is not difficult to understand that, through this embodiment, in the scenario where the terminal accesses the first network in the first access mode, selection of the authentication service network element can be supported.

请参考图4,本申请实施例提供了一种接入控制方法,应用于第三通信设备;该第三通信设备包括NRF。可选地,该第三通信设备为第一网络中的通信设备。如图4所示,所述方法包括:Please refer to FIG4 , an embodiment of the present application provides an access control method, which is applied to a third communication device; the third communication device includes an NRF. Optionally, the third communication device is a communication device in the first network. As shown in FIG4 , the method includes:

步骤41:获取第三信息和/或第四信息。Step 41: Obtain third information and/or fourth information.

可选的,所述第三信息可以包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息。Optionally, the third information may include at least one of the following: a first type of group identifier, a first type of routing indication, a first type of network identifier, information of an authentication provider, and indication information of a first access method.

可选的,所述第四信息用于指示鉴权服务网元的归属信息。所述第四信息可以包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证。Optionally, the fourth information is used to indicate the attribution information of the authentication service network element. The fourth information may include at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access mode supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate.

可选的,所述第一接入方式的指示信息可用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。Optionally, the indication information of the first access method can be used to indicate at least one of the following: an access method for accessing the first network in order to download a certificate for accessing the second network, an access method for accessing the first network without a certificate capable of accessing the first network, an access method capable of using only restricted services, and the certificate for the terminal to access the first network is the default certificate.

可选的,所述第一网络和所述第二网络是同一个网络或不同的网络。Optionally, the first network and the second network are the same network or different networks.

可选的,所述第一类型的路由指示包括:用于第一接入方式的路由指示。Optionally, the first type of routing indication includes: a routing indication for a first access mode.

一种实施方式中,所述受限服务包括下载能够接入网络的证书的服务。In one implementation, the restricted service includes a service for downloading a certificate for accessing a network.

可选的,所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识。Optionally, the first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to terminals of the first access mode.

一种实施方式中,可以从AMF获取第三信息。In one implementation, the third information may be obtained from the AMF.

另一种实施方式中,可以从鉴权服务网元(如AUSF或AAA代理)获取第四信息,即鉴权服务网元的归属信息。In another implementation, the fourth information, ie, the attribution information of the authentication service network element, may be obtained from an authentication service network element (such as an AUSF or an AAA agent).

步骤42:根据第三信息和/或第四信息,执行第三操作。Step 42: Perform a third operation according to the third information and/or the fourth information.

其中,所述第三操作可以包括以下至少一项:The third operation may include at least one of the following:

发现匹配所述第三信息的鉴权服务网元,即所述鉴权服务网元的第四信息与所述第三信息相匹配;finding an authentication service network element that matches the third information, that is, the fourth information of the authentication service network element matches the third information;

发送所述发现的鉴权服务网元。Send the discovered authentication service network element.

其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务。The authentication service type supported by the authentication service network element includes supporting authentication service for terminals with default certificates.

一种实施方式中,向第二目标端发送所述发现的鉴权服务网元。所述的第二目标端包括:AMF。一种实施方式中,从第二目标端接收所述第三信息。In one implementation, the discovered authentication service network element is sent to the second target end. The second target end includes: AMF. In one implementation, the third information is received from the second target end.

可选的,鉴权服务网元可以包括以下之一:AUSF,AAA代理。Optionally, the authentication service network element may include one of the following: AUSF, AAA proxy.

一种实施方式中,匹配第三信息的鉴权服务网元为第一鉴权服务网元。所述第一鉴权服务网元包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。In one implementation, the authentication service network element matching the third information is a first authentication service network element. The first authentication service network element includes: an authentication service network element configured to provide authentication services to a terminal of a first access mode.

一种实施方式中,所述第一类型的组标识包括以下之一:AUSF Group ID、AAA代理group ID。In one implementation, the first type of group identifier includes one of the following: AUSF Group ID, AAA proxy group ID.

一种实施方式中,可以向NRF请求发现AUSF。In one implementation, a request may be made to the NRF to discover the AUSF.

可选的,在发现匹配所述第三信息的鉴权服务网元的操作中,当所述第三信息包括第一接入方式的指示信息的情况下,所述发现的鉴权服务网元支持的接入方式为第一接入方式;或者,当所述第三信息包括第一类型的路由指示的情况下,所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;或者,当所述第三信息包括第一类型的网络标识的情况下,所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;或者,当所述第三信息包括第一类型的组标识的情况下,所述发现的鉴权服务网元所属的组标识为第一类型的组标识;或者,当所述第三信息包括认证提供方的信息,所述发现的鉴权服务网元支持的认证提供方信息包括所述第三信息中的认证提供方的信息。Optionally, in the operation of discovering an authentication service network element that matches the third information, when the third information includes indication information of a first access method, the access method supported by the discovered authentication service network element is the first access method; or, when the third information includes a first type of routing indication, the routing indication supported by the discovered authentication service network element is a first type of routing indication; or, when the third information includes a first type of network identifier, the network identifier of the network to which the discovered authentication service network element belongs is a first type of network identifier; or, when the third information includes a first type of group identifier, the group identifier to which the discovered authentication service network element belongs is a first type of group identifier; or, when the third information includes information of an authentication provider, the authentication provider information supported by the discovered authentication service network element includes the authentication provider information in the third information.

或者,所述发现的鉴权服务网元满足至少以下一项:Alternatively, the discovered authentication service network element satisfies at least one of the following:

所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;The routing indication supported by the discovered authentication service network element is a first type of routing indication;

所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;The network identifier of the network to which the discovered authentication service network element belongs is a network identifier of the first type;

所述发现的鉴权服务网元所属的组标识为第一类型的组标识;The group identifier to which the discovered authentication service network element belongs is a group identifier of the first type;

所述发现的鉴权服务网元支持的接入方式为第一接入方式;The access mode supported by the discovered authentication service network element is the first access mode;

所述发现的鉴权服务网元支持的鉴权服务类型为支持对具有默认证书的终端提供鉴权服务。The authentication service type supported by the discovered authentication service network element is supporting the provision of authentication services to terminals with default certificates.

不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。It is not difficult to understand that, through this embodiment, in the scenario where the terminal accesses the first network in the first access mode, selection of the authentication service network element can be supported.

请参考图5,本申请实施例提供了一种接入控制方法,应用于第四通信设备;该第四通信设备包括AUSF。可选地,该第四通信设备为第一网络中的通信设备。如图5所示,所述方法包括:Referring to FIG5 , an embodiment of the present application provides an access control method, which is applied to a fourth communication device; the fourth communication device includes an AUSF. Optionally, the fourth communication device is a communication device in the first network. As shown in FIG5 , the method includes:

步骤51:发送第四信息。Step 51: Send the fourth message.

其中,所述第四信息用于指示鉴权服务网元的归属信息。所述第四信息可以包括以下至少一项:鉴权服务网元支持的路由指示,鉴权服务网元所属网络的网络标识,鉴权服务网元所属的组标识,鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证。The fourth information is used to indicate the ownership information of the authentication service network element. The fourth information may include at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access mode supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate.

其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示。The routing indication supported by the authentication service network element is a first type of routing indication.

所述鉴权服务网元所属网络的网络标识为第一类型的网络标识。The network identifier of the network to which the authentication service network element belongs is a first type of network identifier.

所述鉴权服务网元所属的组标识为第一类型的组标识。The group identifier to which the authentication service network element belongs is a first type of group identifier.

所述鉴权服务网元支持的接入方式包括第一接入方式。The access methods supported by the authentication service network element include a first access method.

所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务(比如作为鉴权代理)。The authentication service types supported by the authentication service network element include supporting the provision of authentication services to terminals with default certificates (such as serving as an authentication agent).

所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书。The first access method includes at least one of the following: an access method for accessing the first network in order to download a certificate for accessing the second network, an access method for accessing the first network without a certificate capable of accessing the first network, an access method capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate.

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识。The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of a first access mode.

所述第一类型的第一类型的路由指示包括:用于第一接入方式的路由指示。The first type of routing indication of the first type includes: a routing indication used for a first access mode.

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

可选的,上述发送第四信息可以包括:在满足第二条件的情况下,发送所述第四信息;其中,所述第二条件包括:所述鉴权服务网元为用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。Optionally, the sending of the fourth information may include: sending the fourth information when a second condition is met; wherein the second condition includes: the authentication service network element is an authentication service network element for providing authentication services to terminals of the first access mode.

不难理解,通过本实施例,能够在上述的终端以第一接入方式接入第一网络的场景下,支持对鉴权服务网元的选择。It is not difficult to understand that, through this embodiment, in the scenario where the terminal accesses the first network in the first access mode, selection of the authentication service network element can be supported.

本申请实施例提供了一种接入控制方法,应用于第五通信设备;该第四通信设备包括以下至少一项:AMF,AUSF,UDM。可选地,该第五通信设备为第一网络中的通信设备。所述方法包括:The embodiment of the present application provides an access control method, which is applied to a fifth communication device; the fourth communication device includes at least one of the following: AMF, AUSF, UDM. Optionally, the fifth communication device is a communication device in the first network. The method includes:

在满足第五条件的情况下,执行第五操作;When the fifth condition is met, performing a fifth operation;

所述第五操作包括以下至少一项:The fifth operation includes at least one of the following:

不使用第五信息为终端选择网元;not using the fifth information to select a network element for the terminal;

其中,in,

所述第五条件包括以下至少一项:所述终端为第一接入方式;The fifth condition includes at least one of the following: the terminal is in the first access mode;

所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。The fifth information includes at least one of the following: a user identifier of the terminal, network identifier information in the user identifier of the terminal, and realm information in the user identifier of the terminal.

一种实施方式中,对通过非第一接入方式接入网络的终端,根据终端的用户标识中的信息来为终端选择网络设备是默认操作。因此对通过非第一接入方式接入网络的终端,需要执行例外操作。In one implementation, for a terminal that accesses the network through a non-first access method, selecting a network device for the terminal based on information in the terminal's user identifier is a default operation. Therefore, for a terminal that accesses the network through a non-first access method, an exception operation needs to be performed.

其中,所述终端用户标识中网络标识信息包括以下至少一项;终端用户标识中MNC,终端用户标识中MCC,终端用户标识中网络标识NID。The network identification information in the terminal user identification includes at least one of the following: MNC in the terminal user identification, MCC in the terminal user identification, and network identification NID in the terminal user identification.

可选地,所述在满足第五条件的情况下,执行第五操作的步骤之前,所述方法还包括:获得第一信息,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;其中,Optionally, before the step of performing the fifth operation when the fifth condition is met, the method further includes: obtaining first information, the first information including at least one of the following: indication information of the first access mode, a first type of routing indication, and a first type of network identification; the second information includes at least one of the following: a first type of network identification, a first type of routing indication, a first type of group identification, and identification information of the terminal; wherein,

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

可选地,所述获得第一信息的步骤之后,根据第一信息确定满足第五条件。Optionally, after the step of obtaining the first information, it is determined based on the first information whether a fifth condition is satisfied.

可选地,所述网元包括以下至少一项:核心网网元,鉴权服务功能AUSF,统一数据管理UDM,统一数据存储UDR。Optionally, the network element includes at least one of the following: a core network element, an authentication service function AUSF, a unified data management UDM, and a unified data storage UDR.

一种实施方式中,所述网元可以是网络设备。In one implementation, the network element may be a network device.

下面结合具体应用场景对本申请实施例提供的方法进行描述。The method provided in the embodiment of the present application is described below in conjunction with specific application scenarios.

应用场景一Application scenario 1

本应用场景一中,如图6所示,服务鉴权的指示过程可包括:In this application scenario 1, as shown in FIG6 , the service authentication indication process may include:

步骤61:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元(后续以AUSF作为实例说明)向NRF发起注册请求,比如Nnrf_NF Management_NF Register。Step 61: The authentication service network element (hereinafter referred to as AUSF as an example) used to provide authentication services to the terminal of the first access mode initiates a registration request to the NRF, such as Nnrf_NF Management_NF Register.

可选的,该注册请求中包括第四信息,该第四信息用于指示鉴权服务网元的归属信息,该第四信息可以包括以下至少一项:鉴权服务网元所属网络的网络标识,鉴权服务网元所属的组标识,鉴权服务网元支持的接入方式。Optionally, the registration request includes fourth information, and the fourth information is used to indicate the attribution information of the authentication service network element. The fourth information may include at least one of the following: the network identifier of the network to which the authentication service network element belongs, the group identifier to which the authentication service network element belongs, and the access method supported by the authentication service network element.

一种实施方式中,通过鉴权服务网元所属网络的网络标识是第一类型的归属的网络标识的情况下,可说明鉴权服务网元用于对第一接入方式的终端提供鉴权服务。In one implementation, when the network identifier of the network to which the authentication service network element belongs is a first type of belonging network identifier, it can be indicated that the authentication service network element is used to provide authentication services to the terminal of the first access mode.

另一种实施方式中,通过鉴权服务网元所属的组标识是第一类型的组标识的情况下,可说明鉴权服务网元用于对第一接入方式的终端提供鉴权服务。In another implementation manner, when the group identifier to which the authentication service network element belongs is a group identifier of the first type, it can be indicated that the authentication service network element is used to provide authentication services to the terminal of the first access mode.

应用场景二Application scenario 2

本应用场景二中,UE注册第一网络,所述注册类型是第一接入方式。第一网络需要请求DCS对UE进行认证。AMF,NRF,AUSF为第一网络中的通信设备,归属NRF和归属AUSF为UE归属网络中的设备,所述归属AUSF为DCS的一种实施例。如图7所示,选择AUSF的过程可包括:In this application scenario 2, the UE registers the first network, and the registration type is the first access mode. The first network needs to request the DCS to authenticate the UE. AMF, NRF, and AUSF are communication devices in the first network, and the home NRF and home AUSF are devices in the UE's home network, and the home AUSF is an embodiment of the DCS. As shown in Figure 7, the process of selecting the AUSF may include:

步骤71:UE向AMF发起注册请求,其中,该注册请求的注册类型为第一接入方式的指示信息(如第一注册类型)。Step 71: The UE initiates a registration request to the AMF, wherein the registration type of the registration request is indication information of the first access method (such as the first registration type).

步骤72:AMF根据UE提供的第一接入方式的指示信息(如第一注册类型),执行AUSF的选择操作,包括以下至少一项:Step 72: The AMF performs an AUSF selection operation according to the indication information of the first access mode provided by the UE (such as the first registration type), including at least one of the following:

(1)选择本地配置的用于第一接入方式的AUSF;(1) selecting a locally configured AUSF for the first access mode;

(2)选择本地配置的用于第一接入方式的AUSF的组标识(AUSF Group ID),并根据该AUSF组标识向NRF请求发现AUSF;(2) Selecting a locally configured AUSF group ID for the first access mode, and requesting the NRF to discover the AUSF according to the AUSF group ID;

(3)通过网络功能发现请求,比如Nnrf_NF Discovery_Request,向NRF发送第一接入方式的指示信息,用于请求发现支持第一接入方式的AUSF;(3) Sending indication information of the first access method to the NRF through a network function discovery request, such as Nnrf_NF Discovery_Request, to request discovery of an AUSF that supports the first access method;

不难理解,在此之前,AUSF注册NRF时要对应提供其支持的接入方式,如第一接入方式。It is not difficult to understand that before this, AUSF must provide the access methods it supports when registering NRF, such as the first access method.

(4)通过网络功能发现请求,比如Nnrf_NF Discovery_Request,向NRF发送第一类型的网络标识(Home Network ID);(4) Sending a first type of network identifier (Home Network ID) to the NRF through a network function discovery request, such as Nnrf_NF Discovery_Request;

不难理解,在此之前,支持第一接入方式的AUSF注册NRF时要对应提供鉴权服务网元所属网络的网络标识为第一接入方式的网络标识。比如专用于第一接入方式的网络标识。It is not difficult to understand that before this, when the AUSF supporting the first access mode registers the NRF, the network identifier of the network to which the network element providing the authentication service belongs must be the network identifier of the first access mode, for example, a network identifier dedicated to the first access mode.

(5)通过网络功能发现请求,比如Nnrf_NF Discovery_Request,向NRF发送第一类型的组标识;(5) Sending a first type of group identifier to the NRF through a network function discovery request, such as Nnrf_NF Discovery_Request;

不难理解,在此之前,支持第一接入方式的AUSF注册NRF时要对应提供鉴权网元所属的组标识为第一接入方式的网络标识。比如专用于第一接入方式的鉴权服务网元的组标识。It is not difficult to understand that before this, when the AUSF supporting the first access mode registers with the NRF, it needs to provide the group identifier of the authentication network element as the network identifier of the first access mode, such as the group identifier of the authentication service network element dedicated to the first access mode.

步骤73:NRF根据获取的第三信息和/或第四信息,执行第三操作。Step 73: The NRF performs a third operation according to the acquired third information and/or fourth information.

其中,所述第三信息可包括以下至少一项:第一类型的组标识、第一类型的网络标识、第一接入方式的指示信息。所述第四信息用于指示鉴权服务网元的归属信息。所述第四信息可包括以下至少一项:鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式。The third information may include at least one of the following: a first type of group identifier, a first type of network identifier, and indication information of a first access method. The fourth information is used to indicate the attribution information of the authentication service network element. The fourth information may include at least one of the following: a network identifier of a network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, and an access method supported by the authentication service network element.

其中,所述第三操作包括以下至少一项:The third operation includes at least one of the following:

发现匹配所述第三信息的鉴权服务网元(后续以AUSF示例说明);Finding an authentication service network element matching the third information (hereinafter described using AUSF as an example);

向AMF发送所述发现的鉴权服务网元。Send the discovered authentication service network element to AMF.

步骤74:AMF向AUSF发送UE认证请求,比如Nausf_UEAuthentication_Authenticate Request。其中,该请求中可包括终端的第一标识(UE真实的第一SUCI或者第一SUPI)。Step 74: AMF sends a UE authentication request to AUSF, such as Nausf_UEAuthentication_Authenticate Request, where the request may include the first identifier of the terminal (the real first SUCI or first SUPI of the UE).

步骤75至步骤78:AUSF根据终端的第一标识、或第一UE标识中的归属网络标识,或第一UE标识对应AUSF组标识等,通过NRF和归属NRF发现归属AUSF。Step 75 to step 78: AUSF discovers the belonging AUSF through NRF and the belonging NRF based on the first identifier of the terminal, the belonging network identifier in the first UE identifier, or the AUSF group identifier corresponding to the first UE identifier.

具体的,步骤75中,AUSF向NRF发送网络功能发现请求,比如Nnrf_NF Discovery_Request。其中,该发现请求中可包括以下之一:终端的第一标识、终端的归属网络标识HomeNetwork ID、与终端的第一标识相关的AUSF组标识等。Specifically, in step 75, the AUSF sends a network function discovery request, such as Nnrf_NF Discovery_Request, to the NRF, wherein the discovery request may include one of the following: the first identifier of the terminal, the home network identifier HomeNetwork ID of the terminal, the AUSF group identifier related to the first identifier of the terminal, and the like.

步骤76中,NRF向归属NRF发送网络功能发现请求,比如Nnrf_NF Discovery_Request。其中,该发现请求中可包括终端的第一标识、或第一UE标识中的归属网络标识,或第一UE标识对应AUSF组标识AUSF组标识等。In step 76, the NRF sends a network function discovery request, such as Nnrf_NF Discovery_Request, to the home NRF, wherein the discovery request may include the first identifier of the terminal, or the home network identifier in the first UE identifier, or the AUSF group identifier corresponding to the first UE identifier, etc.

步骤77中,归属NRF向NRF返回网络功能发现响应,比如Nnrf_NF Discovery_Response。In step 77, the home NRF returns a network function discovery response, such as Nnrf_NF Discovery_Response, to the NRF.

步骤78中,NRF向AUSF返回网络功能发现响应,比如Nnrf_NF Discovery_Response。In step 78, the NRF returns a network function discovery response, such as Nnrf_NF Discovery_Response, to the AUSF.

步骤79:AUSF向归属AUSF发起UE认证请求,比如Nausf_UE Authentication_Authenticate Request。其中,该请求中包括生成的第二SUCI或者第一SUPI、SN-name、第一接入方式的指示信息等。Step 79: The AUSF initiates a UE authentication request to the home AUSF, such as Nausf_UE Authentication_Authenticate Request, wherein the request includes the generated second SUCI or first SUPI, SN-name, indication information of the first access mode, etc.

之后,归属AUSF可以向UE发起认证过程。Afterwards, the home AUSF may initiate an authentication process towards the UE.

应用场景三Application scenario three

本应用场景三中,UE注册第一网络,提供终端的标识信息。第一网络需要请求DCS对UE进行认证。AMF,NRF,AUSF为第一网络中的通信设备,归属NRF和归属AUSF为UE归属网络中的设备,所述归属AUSF为DCS的一种实施例。如图8所示,选择AUSF的过程可包括:In this application scenario three, the UE registers the first network and provides the terminal's identification information. The first network needs to request the DCS to authenticate the UE. AMF, NRF, and AUSF are communication devices in the first network, and the home NRF and home AUSF are devices in the UE's home network, and the home AUSF is an embodiment of the DCS. As shown in Figure 8, the process of selecting the AUSF may include:

步骤81:UE向AMF发起注册请求。可选地,该注册请求中包含第一信息。示例性地,比如终端的标识信息。Step 81: The UE initiates a registration request to the AMF. Optionally, the registration request includes first information, such as identification information of the terminal.

所述终端的标识信息可以包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal may include at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包含终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包含第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包含终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

AMF可以执行:根据终端的第二标识或终端的第三标识,导出第一类型的网络标识和/或第一类型的路由指示;The AMF may execute: deriving a first type of network identifier and/or a first type of routing indication according to the second identifier of the terminal or the third identifier of the terminal;

所述第一类型的网络标识是专用于第一接入方式的特定取值,如111。The first type of network identifier is a specific value dedicated to the first access mode, such as 111.

所述第一类型的路由指示是专用于第一接入方式的特定取值。The first type of routing indication is a specific value dedicated to the first access mode.

1)一种实施方式中,所述注册请求中包含终端的第一标识和第一类型的网络标识。1) In one implementation, the registration request includes a first identifier of the terminal and a first type of network identifier.

2)另一种实施方式中,所述注册请求中包含终端的第一标识和终端的第二标识。2) In another implementation manner, the registration request includes a first identifier of the terminal and a second identifier of the terminal.

3)另一种实施方式中,所述注册请求中包含终端的第三标识。3) In another implementation manner, the registration request includes a third identifier of the terminal.

当终端的第一标识(SUPI或SUPI)指示的是PLMN或SNPN的签约时,所述DCS索引信息中包含UE的SUPI真正的Home Network ID。When the first identifier (SUPI or SUPI) of the terminal indicates a subscription to a PLMN or SNPN, the DCS index information includes the real Home Network ID of the SUPI of the UE.

步骤82:AMF向NRF发送网络功能发现请求比如Nnrf_NF Discovery_Request,即根据第一接入方式的归属网络标识向NRF请求查询AUSF,获取AUSF。Step 82: AMF sends a network function discovery request such as Nnrf_NF Discovery_Request to NRF, that is, requests NRF to query AUSF according to the home network identifier of the first access method to obtain AUSF.

可选地,该请求中包含AUSF的Home Network ID和/或Group ID。Optionally, the request includes the Home Network ID and/or Group ID of the AUSF.

步骤83:NRF向AMF返回发送的发现的鉴权服务网元即AUSF。Step 83: NRF returns the discovered authentication service network element, i.e. AUSF, to AMF.

步骤84:AMF向AUSF发送UE认证请求,比如Nausf_UEAuthentication_Authenticate Request。Step 84: AMF sends a UE authentication request to AUSF, such as Nausf_UEAuthentication_Authenticate Request.

可选的,AMF可以执行以下至少一项:Optionally, the AMF may perform at least one of the following:

不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;Not sending the second identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

根据终端的第三标识导出终端的第一标识;deriving a first identifier of the terminal according to a third identifier of the terminal;

向第一鉴权服务网元或或所述发现的鉴权服务网元发送终端的第一标识。Sending the first identifier of the terminal to the first authentication service network element or the discovered authentication service network element.

步骤85至步骤89:同应用场景二中的步骤75至79,此处不再赘述。Steps 85 to 89 are the same as steps 75 to 79 in application scenario 2 and will not be repeated here.

请参考图9,本申请实施例提供了一种接入控制装置,应用于第一通信设备,如图9所示,该接入控制装置90包括:Referring to FIG. 9 , an embodiment of the present application provides an access control device, which is applied to a first communication device. As shown in FIG. 9 , the access control device 90 includes:

第一获取模块91,用于获取第一信息和/或第二信息;其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;The first acquisition module 91 is used to acquire the first information and/or the second information; wherein the first information includes at least one of the following: indication information of the first access mode, a first type of routing indication, and a first type of network identification; the second information includes at least one of the following: a first type of network identification, a first type of routing indication, a first type of group identification, and identification information of the terminal;

第一执行模块92,用于根据所述第一信息和/或所述第二信息,执行第一操作;A first execution module 92, configured to execute a first operation according to the first information and/or the second information;

其中,所述第一操作包括以下至少一项:The first operation includes at least one of the following:

选择第一鉴权服务网元;Select the first authentication service network element;

确定第一类型的组标识,第一类型的路由指示、服务提供方的信息和/或第一类型的网络标识;Determining a first type of group identifier, a first type of routing indication, information of a service provider, and/or a first type of network identifier;

根据所述第一类型的组标识、第一类型的路由指示、第一类型的网络标识、服务提供方的信息和/或第一接入方式的指示信息,请求发现鉴权服务网元;Requesting to discover an authentication service network element according to the first type of group identifier, the first type of routing indication, the first type of network identifier, information of the service provider and/or indication information of the first access method;

其中,所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或者不同的网络;The first network and the second network are the same network or different networks;

其中,所述第一鉴权服务网元包括以下至少一项:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元、为具有默认证书的终端提供鉴权服务的鉴权服务网元;The first authentication service network element includes at least one of the following: an authentication service network element for providing authentication services to terminals of the first access mode, and an authentication service network element for providing authentication services to terminals with default certificates;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

可选的,所述第一执行模块92还用于执行以下至少一项:Optionally, the first execution module 92 is further configured to execute at least one of the following:

向第一目标端发送所述第一类型的组标识,所述第一类型的组标识用于所述第一目标端发现匹配所述第一类型的组标识的鉴权服务网元;Sending the first type of group identifier to a first target end, where the first type of group identifier is used by the first target end to discover an authentication service network element matching the first type of group identifier;

向第一目标端发送所述第一接入方式的指示信息,所述第一接入方式的指示信息用于所述第一目标端发现匹配所述第一接入方式的指示信息的鉴权服务网元;Sending indication information of the first access method to a first target end, where the indication information of the first access method is used by the first target end to find an authentication service network element matching the indication information of the first access method;

向第一目标端发送所述第一类型的路由指示,所述第一类型的路由指示用于所述第一目标端发现匹配所述第一类型的路由指示的鉴权服务网元。The first type of routing indication is sent to a first target end, where the first type of routing indication is used by the first target end to discover an authentication service network element matching the first type of routing indication.

向第一目标端发送所述第一类型的网络标识,所述第一类型的网络标识用于所述第一目标端发现匹配所述第一类型的网络标识的鉴权服务网元。The first type of network identifier is sent to a first target end, where the first type of network identifier is used by the first target end to discover an authentication service network element matching the first type of network identifier.

可选的,所述第一获取模块91具体用于:从终端获取第一信息。Optionally, the first acquisition module 91 is specifically used to: acquire first information from a terminal.

可选的,所述第一获取模块91具体用于:根据第一通信设备上的配置,获取第二信息。Optionally, the first acquisition module 91 is specifically used to: acquire the second information according to the configuration on the first communication device.

可选的,所述第一获取模块91具体用于以下至少一项:Optionally, the first acquisition module 91 is specifically used for at least one of the following:

从终端获取第一接入方式的指示信息;Acquire indication information of a first access mode from a terminal;

根据第一通信设备上的配置,获取第一类型的组标识、第一类型的路由指示或者第一类型的网络标识;Acquire a first type of group identifier, a first type of routing indication, or a first type of network identifier according to a configuration on the first communication device;

其中,所述根据所述第一信息和/或所述第二信息,执行第一操作包括以下至少一项:The performing of the first operation according to the first information and/or the second information includes at least one of the following:

根据所述第一接入方式的指示信息,确定第一类型的组标识、第一类型的路由指示或第一类型的网络标识;Determine, according to the indication information of the first access mode, a first type of group identifier, a first type of routing indication, or a first type of network identifier;

根据所述第一类型的组标识、第一类型的路由指示和/或第一类型的网络标识,请求发现鉴权服务网元。A request is made to discover an authentication service network element according to the first type of group identifier, the first type of routing indication and/or the first type of network identifier.

可选的,所述第一获取模块91具体用于以下至少一项:Optionally, the first acquisition module 91 is specifically used for at least one of the following:

从终端获取第一类型的网络标识和/或第一类型的路由指示,acquiring a first type of network identification and/or a first type of routing indication from the terminal,

根据第一通信设备上的配置,获取第一类型的组标识;Acquire a first type of group identifier according to a configuration on the first communication device;

其中,所述根据所述第一信息和/或所述第二信息,执行第一操作包括以下至少一项:The performing of the first operation according to the first information and/or the second information includes at least one of the following:

根据所述第一类型的网络标识和/或第一类型的路由指示,确定第一类型的组标识;Determining a first type of group identifier according to the first type of network identifier and/or the first type of routing indication;

根据所述第一类型的组标识,请求发现鉴权服务网元。According to the group identifier of the first type, a request is made to discover an authentication service network element.

可选的,所述第一操作还包括以下至少一项:Optionally, the first operation further includes at least one of the following:

接收请求发现的鉴权服务网元;receiving an authentication service network element requested for discovery;

根据所述终端的第二标识或终端的第三标识,导出第一类型的网络标识和/或第一类型的路由指示;deriving a first type of network identifier and/or a first type of routing indication according to the second identifier of the terminal or the third identifier of the terminal;

不向第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第二标识;Not sending the second identifier of the terminal to the first authentication service network element or the discovered authentication service network element;

根据所述终端的第三标识,导出终端的第一标识;deriving the first identifier of the terminal according to the third identifier of the terminal;

向所述第一鉴权服务网元或所述发现的鉴权服务网元发送终端的第一标识。Sending a first identifier of the terminal to the first authentication service network element or the discovered authentication service network element.

本实施例中,接入控制装置90能够实现本申请图2所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。In this embodiment, the access control device 90 can implement each process implemented in the method embodiment shown in FIG. 2 of the present application, and achieve the same beneficial effects, which will not be described again here to avoid repetition.

请参考图10,本申请实施例提供了一种接入控制装置,应用于第二通信设备,如图10所示,该接入控制装置100包括:Referring to FIG. 10 , an embodiment of the present application provides an access control device, which is applied to a second communication device. As shown in FIG. 10 , the access control device 100 includes:

第一发送模块101,用于发送第一信息;A first sending module 101, configured to send first information;

其中,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识、终端的标识信息;The first information includes at least one of the following: indication information of the first access mode, a first type of routing indication, a first type of network identification, and identification information of the terminal;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或不同的网络;The first network and the second network are the same network or different networks;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

可选的,所述第一发送模块101具体用于:在满足第一条件的情况下,发送所述第一信息;Optionally, the first sending module 101 is specifically configured to: send the first information when a first condition is met;

其中,所述第一条件包括以下至少一项:The first condition includes at least one of the following:

第二通信设备接入第一网络的目是为了下载用于接入第二网络的证书;The purpose of the second communication device accessing the first network is to download a certificate for accessing the second network;

第二通信设备不具有能够接入第一网络的证书;The second communication device does not have a certificate capable of accessing the first network;

第二通信设备接入第一网络仅能够使用受限服务。The second communication device can only use restricted services when accessing the first network.

可选的,该接入控制装置100还包括:Optionally, the access control device 100 further includes:

生成模块,用于生成终端的第二标识,将终端的标识中的路由指示设置为第一类型的路由指示和/或将终端的标识中的归属网络标识设置为第一类型的网络标识;和/或a generating module, configured to generate a second identifier of the terminal, set a routing indication in the identifier of the terminal to a routing indication of the first type and/or set a home network identifier in the identifier of the terminal to a network identifier of the first type; and/or

生成终端的第三标识,将第一类型的网络标识添加到终端的标识中和/或将第一类型的路由指示添加到终端的标识中。A third identifier of the terminal is generated, and a first type of network identifier is added to the identifier of the terminal and/or a first type of routing indication is added to the identifier of the terminal.

本实施例中,接入控制装置100能够实现本申请图3所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。In this embodiment, the access control device 100 can implement each process implemented in the method embodiment shown in FIG. 3 of the present application, and achieve the same beneficial effects, which will not be described again here to avoid repetition.

请参考图11,本申请实施例提供了一种接入控制装置,应用于第二通信设备,如图11所示,该接入控制装置110包括:Please refer to FIG. 11 , an embodiment of the present application provides an access control device, which is applied to a second communication device. As shown in FIG. 11 , the access control device 110 includes:

第二获取模块111,用于获取第三信息和/或第四信息;其中,所述第三信息包括以下至少一项:第一类型的组标识、第一类型的路由指示、第一类型的网络标识、认证提供方的信息、第一接入方式的指示信息;所述第四信息用于指示鉴权服务网元的归属信息,所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;The second acquisition module 111 is used to acquire third information and/or fourth information; wherein the third information includes at least one of the following: a first type of group identifier, a first type of routing indication, a first type of network identifier, information of an authentication provider, and indication information of a first access method; the fourth information is used to indicate the attribution information of the authentication service network element, and the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access method supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate;

第二执行模块112,用于根据所述第三信息和/或所述第四信息,执行第三操作;A second execution module 112, configured to execute a third operation according to the third information and/or the fourth information;

其中,所述第三操作包括以下至少一项:The third operation includes at least one of the following:

发现匹配所述第三信息的鉴权服务网元,所述鉴权服务网元的第四信息与所述第三信息相匹配;finding an authentication service network element matching the third information, wherein the fourth information of the authentication service network element matches the third information;

发送所述发现的鉴权服务网元;Sending the discovered authentication service network element;

其中,所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;The authentication service type supported by the authentication service network element includes supporting authentication services for terminals with default certificates;

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一网络和所述第二网络是同一个网络或不同的网络;The first network and the second network are the same network or different networks;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

可选的,在发现匹配所述第三信息的鉴权服务网元的操作中,Optionally, in the operation of finding an authentication service network element matching the third information,

当所述第三信息包括第一接入方式的指示信息的情况下,所述发现的鉴权服务网元支持的接入方式为第一接入方式;When the third information includes indication information of the first access method, the access method supported by the discovered authentication service network element is the first access method;

或者,当所述第三信息包括第一类型的路由指示的情况下,所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;Alternatively, when the third information includes a first type of routing indication, the routing indication supported by the discovered authentication service network element is a first type of routing indication;

或者,当所述第三信息包括第一类型的网络标识的情况下,所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;Alternatively, when the third information includes a first type of network identifier, the network identifier of the network to which the discovered authentication service network element belongs is a first type of network identifier;

或者,当所述第三信息包括第一类型的组标识的情况下,所述发现的鉴权服务网元所属的组标识为第一类型的组标识。Alternatively, when the third information includes a first type of group identifier, the group identifier to which the discovered authentication service network element belongs is a first type of group identifier.

或者,当所述第三信息包括认证提供方的信息,所述发现的鉴权服务网元支持的认证提供方信息包括所述第三信息中的认证提供方的信息;Alternatively, when the third information includes information of an authentication provider, the authentication provider information supported by the discovered authentication service network element includes the authentication provider information in the third information;

或者,所述发现的鉴权服务网元满足至少以下一项:Alternatively, the discovered authentication service network element satisfies at least one of the following:

所述发现的鉴权服务网元支持的路由指示为第一类型的路由指示;The routing indication supported by the discovered authentication service network element is a first type of routing indication;

所述发现的鉴权服务网元所属网络的网络标识为第一类型的网络标识;The network identifier of the network to which the discovered authentication service network element belongs is a network identifier of the first type;

所述发现的鉴权服务网元所属的组标识为第一类型的组标识;The group identifier to which the discovered authentication service network element belongs is a group identifier of the first type;

所述发现的鉴权服务网元支持的接入方式为第一接入方式;The access mode supported by the discovered authentication service network element is the first access mode;

所述发现的鉴权服务网元支持的鉴权服务类型为支持对具有默认证书的终端提供鉴权服务。The authentication service type supported by the discovered authentication service network element is supporting the provision of authentication services to terminals with default certificates.

本实施例中,接入控制装置110能够实现本申请图4所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。In this embodiment, the access control device 110 can implement each process implemented in the method embodiment shown in FIG. 4 of the present application, and achieve the same beneficial effects, which will not be described again here to avoid repetition.

请参考图12,本申请实施例提供了一种接入控制装置,应用于第二通信设备,如图12所示,该接入控制装置120包括:Please refer to FIG. 12 , an embodiment of the present application provides an access control device, which is applied to a second communication device. As shown in FIG. 12 , the access control device 120 includes:

第二发送模块121,用于发送第四信息;The second sending module 121 is used to send fourth information;

其中,所述第四信息用于指示鉴权服务网元的归属信息;所述第四信息包括以下至少一项:鉴权服务网元支持的路由指示、鉴权服务网元所属网络的网络标识、鉴权服务网元所属的组标识、鉴权服务网元支持的接入方式、鉴权服务网元支持的鉴权服务类型、鉴权服务网元支持的认证提供方的信息且所述认证提供方能够对具有默认证书的终端进行认证;The fourth information is used to indicate the attribution information of the authentication service network element; the fourth information includes at least one of the following: a routing indication supported by the authentication service network element, a network identifier of the network to which the authentication service network element belongs, a group identifier to which the authentication service network element belongs, an access mode supported by the authentication service network element, an authentication service type supported by the authentication service network element, and information of an authentication provider supported by the authentication service network element, and the authentication provider can authenticate a terminal with a default certificate;

其中,所述鉴权服务网元支持的路由指示为第一类型的路由指示;The routing indication supported by the authentication service network element is a first type of routing indication;

所述鉴权服务网元所属网络的网络标识为第一类型的网络标识;The network identifier of the network to which the authentication service network element belongs is a network identifier of the first type;

所述鉴权服务网元所属的组标识为第一类型的组标识;The group identifier to which the authentication service network element belongs is a group identifier of the first type;

所述鉴权服务网元支持的接入方式包括第一接入方式;The access mode supported by the authentication service network element includes a first access mode;

所述鉴权服务网元支持的鉴权服务类型包括支持对具有默认证书的终端提供鉴权服务;The authentication service type supported by the authentication service network element includes supporting the provision of authentication services to terminals with default certificates;

所述第一接入方式包括以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The first access mode includes at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识。The first type of network identifier includes: a network identifier used for a first access mode.

可选的,所述第二发送模块121还用于:在满足第二条件的情况下,发送所述第四信息;Optionally, the second sending module 121 is further used to: send the fourth information when the second condition is met;

其中,所述第二条件包括:所述鉴权服务网元为用于对第一接入方式的终端提供鉴权服务的鉴权服务网元。The second condition includes: the authentication service network element is an authentication service network element used to provide authentication services to terminals of the first access mode.

本实施例中,接入控制装置120能够实现本申请图5所示方法实施例中实现的各个过程,以及达到相同的有益效果,为避免重复,这里不再赘述。In this embodiment, the access control device 120 can implement each process implemented in the method embodiment shown in FIG. 5 of the present application, and achieve the same beneficial effects, which will not be described again here to avoid repetition.

本申请还提供一种接入控制装置,应用于第五通信设备,包括:The present application also provides an access control device, applied to a fifth communication device, including:

第三执行模块,用于在满足第五条件的情况下,执行第五操作;A third execution module, configured to execute a fifth operation when a fifth condition is met;

所述第五操作包括以下至少一项:The fifth operation includes at least one of the following:

不使用第五信息为终端选择网元;not using the fifth information to select a network element for the terminal;

其中,in,

所述第五条件包括以下至少一项:所述终端为第一接入方式;The fifth condition includes at least one of the following: the terminal is in the first access mode;

所述第五信息包括以下至少一项:终端的用户标识,终端用户标识中网络标识信息,终端用户标识中realm中的信息。The fifth information includes at least one of the following: a user identifier of the terminal, network identifier information in the user identifier of the terminal, and realm information in the user identifier of the terminal.

一种实施方式中,对通过非第一接入方式接入网络的终端,根据终端的用户标识中的信息来为终端选择网络设备是默认操作。因此对通过非第一接入方式接入网络的终端,需要执行例外操作。In one implementation, for a terminal that accesses the network through a non-first access method, selecting a network device for the terminal based on information in the terminal's user identifier is a default operation. Therefore, for a terminal that accesses the network through a non-first access method, an exception operation needs to be performed.

其中,所述终端用户标识中网络标识信息包括以下至少一项;终端用户标识中MNC,终端用户标识中MCC,终端用户标识中网络标识NID。The network identification information in the terminal user identification includes at least one of the following: MNC in the terminal user identification, MCC in the terminal user identification, and network identification NID in the terminal user identification.

可选地,所述装置还包括:Optionally, the device further comprises:

第三获取模块,用于获得第一信息,所述第一信息包括以下至少一项:第一接入方式的指示信息、第一类型的路由指示、第一类型的网络标识;所述第二信息包括以下至少一项:第一类型的网络标识、第一类型的路由指示、第一类型的组标识、终端的标识信息;其中,The third acquisition module is used to obtain first information, wherein the first information includes at least one of the following: indication information of the first access mode, a first type of routing indication, and a first type of network identification; the second information includes at least one of the following: a first type of network identification, a first type of routing indication, a first type of group identification, and identification information of the terminal; wherein,

所述第一接入方式的指示信息用于指示以下至少一项:为了下载用于接入第二网络的证书而接入第一网络的接入方式、不具有能够接入第一网络的证书而接入第一网络的接入方式、仅能够使用受限服务的接入方式、终端接入第一网络的证书为默认证书;The indication information of the first access mode is used to indicate at least one of the following: an access mode for accessing the first network in order to download a certificate for accessing the second network, an access mode for accessing the first network without a certificate capable of accessing the first network, an access mode capable of using only restricted services, and a certificate for the terminal to access the first network is a default certificate;

所述第一类型的组标识包括:用于对第一接入方式的终端提供鉴权服务的鉴权服务网元的组标识;The first type of group identifier includes: a group identifier of an authentication service network element used to provide authentication services to a terminal of the first access mode;

所述第一类型的网络标识包括:用于第一接入方式的网络标识;The first type of network identifier includes: a network identifier used for a first access mode;

所述第一类型的路由指示包括:用于第一接入方式的路由指示;The first type of routing indication includes: a routing indication for a first access mode;

所述终端的标识信息包括以下至少一项:终端的第一标识、终端的第二标识、终端的第三标识;The identification information of the terminal includes at least one of the following: a first identification of the terminal, a second identification of the terminal, and a third identification of the terminal;

所述终端的第一标识包括终端的认证提供方的信息;The first identification of the terminal includes information of an authentication provider of the terminal;

所述终端的第二标识包括第一类型的网络标识和/或第一类型的路由指示;The second identifier of the terminal includes a first type of network identifier and/or a first type of routing indication;

所述终端的第三标识中包括终端的认证提供方的信息、第一类型的网络标识和/或第一类型的路由指示。The third identifier of the terminal includes information of an authentication provider of the terminal, a first type of network identifier and/or a first type of routing indication.

可选地,所述装置还包括:Optionally, the device further comprises:

确定模块,用于根据第一信息确定满足第五条件。A determination module is used to determine whether a fifth condition is satisfied according to the first information.

可选地,所述网元包括以下至少一项:核心网网元,AUSF,UDM和UDR。Optionally, the network element includes at least one of the following: a core network element, an AUSF, a UDM and a UDR.

一种实施方式中,所述网元可以是网络设备。In one implementation, the network element may be a network device.

参见图13,图13是本申请实施例提供的另一种通信设备的结构示意图,如图13所示,通信设备130包括:处理器131、存储器132及存储在所述存储器132上并可在所述处理器上运行的计算机程序,通信设备130中的各个组件通过总线接口133耦合在一起,所述计算机程序被所述处理器131执行时可实现上述图2所示方法实施例中实现的各个过程,或者,实现上述图3所示方法实施例中实现的各个过程,或者,实现上述图4所示方法实施例中实现的各个过程,或者,实现上述图5所示方法实施例中实现的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。Refer to Figure 13, which is a structural diagram of another communication device provided in an embodiment of the present application. As shown in Figure 13, the communication device 130 includes: a processor 131, a memory 132, and a computer program stored in the memory 132 and executable on the processor. The various components in the communication device 130 are coupled together through a bus interface 133. When the computer program is executed by the processor 131, it can implement the various processes implemented in the method embodiment shown in Figure 2 above, or implement the various processes implemented in the method embodiment shown in Figure 3 above, or implement the various processes implemented in the method embodiment shown in Figure 4 above, or implement the various processes implemented in the method embodiment shown in Figure 5 above, and can achieve the same technical effect. In order to avoid repetition, it will not be repeated here.

本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质上存储计算机程序,所述计算机程序被处理器执行时实现上述图2所示方法实施例中实现的各个过程,或者,实现上述图3所示方法实施例中实现的各个过程,或者,实现上述图4所示方法实施例中实现的各个过程,或者,实现上述图5所示方法实施例中实现的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。其中,所述的计算机可读存储介质,如只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the various processes implemented in the method embodiment shown in FIG. 2, or the various processes implemented in the method embodiment shown in FIG. 3, or the various processes implemented in the method embodiment shown in FIG. 4, or the various processes implemented in the method embodiment shown in FIG. 5, and can achieve the same technical effect. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM/RAM, a disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.

上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims (21)

1. An access control method applied to a first communication device, comprising:
acquiring first information; the first information comprises identification information of a terminal, the identification information of the terminal comprises a third identification of the terminal, and the third identification of the terminal comprises a routing indication for a first access mode and index information of DCS;
Executing a first operation according to the first information;
wherein the first operation comprises:
selecting a first authentication service network element;
Wherein the first authentication service network element comprises at least one of: an authentication service network element for providing authentication service for the terminal of the first access mode, and an authentication service network element for providing authentication service for the terminal with the default certificate;
wherein the first access manner includes at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
2. The method of claim 1, wherein the first information further comprises: indication information of a first access mode;
the indication information of the first access mode is used for indicating at least one of the following: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates;
The first network and the second network are the same network or different networks.
3. The method according to claim 1 or 2, wherein the method further comprises:
obtaining second information, wherein the second information comprises: a group identification of a first type;
The group identification of the first type includes: and the authentication service network element group identification is used for providing authentication service for the terminal of the first access mode.
4. The method of claim 3, wherein the step of,
The acquiring the first information includes: acquiring first information from a terminal;
And/or the number of the groups of groups,
The acquiring the second information includes: and acquiring second information according to the configuration on the first communication equipment.
5. A method according to claim 3, wherein the acquiring the first information:
Acquiring the indication information of the first access mode from a terminal;
And/or the number of the groups of groups,
The acquiring the second information includes:
And acquiring the group identifier of the first type according to the configuration on the first communication equipment.
6. A method according to claim 3, wherein the obtaining the first information comprises:
Acquiring a network identifier for a first access mode and the routing indication for the first access mode from a terminal;
And/or
The acquiring the second information includes:
a group identity of a first type is obtained according to a configuration on a first communication device.
7. The method of claim 1, wherein the first operation further comprises:
And according to the third identification of the terminal, deriving a network identification for the first access mode and a routing indication for the first access mode.
8. An access control method applied to a second communication device, comprising:
transmitting first information;
The first information comprises identification information of a terminal, wherein the identification information of the terminal comprises a third identification of the terminal, and the third identification of the terminal comprises a routing indication for a first access mode and index information of DCS;
wherein the first access manner includes at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
9. The method of claim 8, wherein the first information further comprises: indication information of a first access mode;
the indication information of the first access mode is used for indicating at least one of the following: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates;
The first network and the second network are the same network or different networks.
10. The method of claim 8, wherein the transmitting the first information comprises:
transmitting the first information when a first condition is satisfied;
wherein the first condition includes at least one of:
The purpose of the second communication device accessing the first network is to download credentials for accessing the second network;
the second communication device does not have a certificate capable of accessing the first network;
the second communication device accessing the first network is only able to use the restricted service.
11. The method of claim 8, wherein prior to the step of transmitting the first information, the method further comprises at least one of:
generating a third identifier of the terminal, adding the network identifier for the first access mode to the identifier of the terminal and/or adding the routing indication for the first access mode to the identifier of the terminal.
12. An access control method applied to a third communication device, comprising:
acquiring third information and fourth information; wherein the third information includes a routing indication for the first access mode and at least one of: a group identifier of a first type, a network identifier for a first access mode, information of an authentication provider, and indication information of the first access mode; the fourth information includes: an access mode supported by the authentication service network element;
Performing a third operation according to the third information and the fourth information;
Wherein the third operation includes:
Finding an authentication service network element matched with the third information, wherein fourth information of the authentication service network element is matched with the third information;
transmitting the discovered authentication service network element;
wherein the first access manner includes at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
13. The method of claim 12, wherein the indication information of the first access manner is used to indicate at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates;
the first network and the second network are the same network or different networks;
The group identification of the first type includes: and the authentication service network element group identification is used for providing authentication service for the terminal of the first access mode.
14. The method according to claim 13, wherein, in the operation of discovering an authentication service network element matching the third information,
When the third information includes the indication information of the first access mode, the found access mode supported by the authentication service network element is the first access mode;
Or when the third information includes a routing instruction for the first access mode, the routing instruction supported by the discovered authentication service network element is the routing instruction for the first access mode;
or when the third information includes a network identifier for the first access mode, the network identifier of the network to which the discovered authentication service network element belongs is the network identifier for the first access mode;
Or when the third information includes a group identifier of the first type, the group identifier to which the discovered authentication service network element belongs is the group identifier of the first type;
Or when the third information comprises information of an authentication provider, the information of the authentication provider supported by the discovered authentication service network element comprises information of the authentication provider in the third information;
Or the discovered authentication service network element satisfies at least one of the following:
the routing indication supported by the discovered authentication service network element is the routing indication for the first access mode;
The network identifier of the network to which the discovered authentication service network element belongs is a network identifier for a first access mode;
the group identifier to which the discovered authentication service network element belongs is a first type group identifier;
the found access mode supported by the authentication service network element is a first access mode;
the authentication service type supported by the discovered authentication service network element is used for supporting the authentication service provided for the terminal with the default certificate.
15. An access control method applied to a fourth communication device, comprising:
sending a registration request to a third communication device, the registration request including fourth information;
wherein the fourth information includes: an access mode supported by the authentication service network element; the access modes supported by the authentication service network element comprise a first access mode;
The first access mode comprises at least one of the following: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
16. An access control apparatus for use with a first communication device, comprising:
The first acquisition module is used for acquiring first information; wherein the first information includes: the method comprises the steps that identification information of a terminal comprises a third identification of the terminal, and the third identification of the terminal comprises a route indication and index information of DCS (distributed control system) for a first access mode;
the first execution module is used for executing a first operation according to the first information;
wherein the first operation comprises:
selecting a first authentication service network element;
Wherein the first authentication service network element comprises at least one of: an authentication service network element for providing authentication service for the terminal of the first access mode, and an authentication service network element for providing authentication service for the terminal with the default certificate;
wherein the first access manner includes at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
17. An access control apparatus applied to a second communication device, comprising:
the first sending module is used for sending the first information;
wherein the first information includes: the terminal identification information comprises a third identification of the terminal, wherein the third identification of the terminal comprises a routing indication for a first access mode and index information of DCS;
wherein the first access manner includes at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
18. An access control apparatus applied to a third communication device, comprising:
The second acquisition module is used for acquiring third information and fourth information; wherein the third information includes a routing indication for the first access mode and at least one of: a group identifier of a first type, a network identifier for a first access mode, information of an authentication provider, and indication information of the first access mode; the fourth information includes: an access mode supported by the authentication service network element;
The second execution module is used for executing a third operation according to the third information and the fourth information;
Wherein the third operation includes:
Finding an authentication service network element matched with the third information, wherein fourth information of the authentication service network element is matched with the third information;
transmitting the discovered authentication service network element;
wherein the first access manner includes at least one of: an access method for accessing the first network for downloading a certificate for accessing the second network, an access method for accessing the first network without having a certificate capable of accessing the first network, an access method capable of using only limited services, and a certificate for accessing the first network by the terminal are default certificates.
19. An access control apparatus applied to a fourth communication device, comprising:
The second sending module is used for sending a registration request to the third communication equipment, wherein the registration request comprises fourth information;
wherein the fourth information includes: an access mode supported by the authentication service network element;
the access modes supported by the authentication service network element comprise a first access mode;
The first access mode comprises at least one of the following: an access method for accessing the first network in order to download a certificate for accessing the second network, an access method for accessing the first network without a certificate capable of accessing the first network, and an access method capable of using only limited services.
20. A communication device comprising a processor, a memory and a computer program stored on the memory and executable on the processor, which when executed by the processor performs the steps of the access control method according to any one of claims 1 to 7, or the steps of the access control method according to any one of claims 8 to 11, or the steps of the access control method according to claims 12-14, or the steps of the access control method according to claim 15.
21. A readable storage medium, characterized in that the readable storage medium has stored thereon a program or instructions which, when executed by a processor, implement the steps of the access control method according to any one of claims 1 to 7, or the steps of the access control method according to any one of claims 8 to 11, or the steps of the access control method according to claims 12-14, or the steps of the access control method according to claim 15.
CN202110369540.7A 2020-07-31 2021-04-06 Access control method, device and communication equipment Active CN114071465B (en)

Priority Applications (6)

Application Number Priority Date Filing Date Title
JP2023503412A JP7509991B2 (en) 2020-07-31 2021-08-02 Access control method, device and communication device
EP21851111.1A EP4192064A4 (en) 2020-07-31 2021-08-02 Access control method and apparatus, and communication device
PCT/CN2021/110015 WO2022022739A1 (en) 2020-07-31 2021-08-02 Access control method and apparatus, and communication device
KR1020237006765A KR20230043969A (en) 2020-07-31 2021-08-02 Access control method, device and communication device
PH1/2023/550256A PH12023550256A1 (en) 2020-07-31 2021-08-02 Access control method and apparatus, and communication device
US18/104,061 US20230179597A1 (en) 2020-07-31 2023-01-31 Access control method, access control apparatus, and communications device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN2020107621963 2020-07-31
CN202010762196 2020-07-31

Publications (2)

Publication Number Publication Date
CN114071465A CN114071465A (en) 2022-02-18
CN114071465B true CN114071465B (en) 2024-08-06

Family

ID=80233267

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202110369540.7A Active CN114071465B (en) 2020-07-31 2021-04-06 Access control method, device and communication equipment

Country Status (1)

Country Link
CN (1) CN114071465B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115314841B (en) * 2021-05-06 2024-07-30 华为技术有限公司 Communication method and communication device

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020098974A1 (en) * 2018-11-14 2020-05-22 Telefonaktiebolaget Lm Ericsson (Publ) Methods and apparatuses for network function selection in 5g for a user

Family Cites Families (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101227712B (en) * 2007-01-15 2012-06-06 华为技术有限公司 System and method for implementing multi-type communication network integration
CN102638797B (en) * 2012-04-24 2016-08-03 华为技术有限公司 Access the method for wireless network, terminal, access network node and authentication server
US9167427B2 (en) * 2013-03-15 2015-10-20 Alcatel Lucent Method of providing user equipment with access to a network and a network configured to provide access to the user equipment
EP3219131A1 (en) * 2014-11-12 2017-09-20 Nokia Solutions and Networks Oy Method, apparatus and system
US11006274B2 (en) * 2015-11-30 2021-05-11 Qualcomm Incorporated Service-based network selection
CN109413646B (en) * 2017-08-16 2020-10-16 华为技术有限公司 Secure access method, device and system
US9998896B1 (en) * 2017-08-18 2018-06-12 Verizon Patent And Licensing Inc. Dedicated APN access using default network access key for profile download
CN109688586B (en) * 2017-10-19 2021-12-07 中兴通讯股份有限公司 Network function authentication method and device and computer readable storage medium
CN110167013B (en) * 2018-02-13 2020-10-27 华为技术有限公司 A communication method and device
CN110636506A (en) * 2018-06-22 2019-12-31 维沃移动通信有限公司 Network access method, terminal and network-side network element
CN110881184B (en) * 2018-09-05 2021-05-18 华为技术有限公司 Communication method and device
CN110086652B (en) * 2019-03-25 2023-04-18 北京天地互连信息技术有限公司 Management system and method for service network element in 5G core network
CN111356157B (en) * 2020-03-15 2024-10-25 腾讯科技(深圳)有限公司 Method and related equipment for realizing network capability opening
CN111416827B (en) * 2020-03-25 2021-09-21 广州爱浦路网络技术有限公司 Method for discovering network function NF according to security level

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020098974A1 (en) * 2018-11-14 2020-05-22 Telefonaktiebolaget Lm Ericsson (Publ) Methods and apparatuses for network function selection in 5g for a user

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3GPP TR 23.700-07 V0.4.0 Technical Specification Group Services and System Aspects *
Study on enhanced support of non-public networks(Release 17)".3GPP specs\archive.2020,第102-110页. *

Also Published As

Publication number Publication date
CN114071465A (en) 2022-02-18

Similar Documents

Publication Publication Date Title
US9526119B2 (en) Methods and apparatus for multiple data packet connections
CN108574969B (en) Connection processing method and device in multi-access scenario
JP4944118B2 (en) System and method for distributing wireless network access parameters
US10595187B2 (en) System and method of selective packet data network gateway discovery
CN111277997B (en) Method for supporting UE association and communication equipment
US20230179597A1 (en) Access control method, access control apparatus, and communications device
US20090305674A1 (en) Device management in visited network
CN106664558B (en) Method and device for establishing a connection
CN108243631B (en) A method and device for accessing a network
WO2022022738A1 (en) Information configuration method and apparatus, and communication device
JP3854148B2 (en) Method and apparatus for selecting identification confirmation information
WO2023124991A1 (en) Communication method and apparatus
CN116471705A (en) User equipment routing strategy processing method and user equipment
CN114071465B (en) Access control method, device and communication equipment
CN111200857A (en) A user routing update method and device
CN114173333A (en) Access network, network selection method, device and communication equipment
CN113556746B (en) Access control method and communication device
JP7572568B2 (en) Information processing method, device, communication device, and readable storage medium
WO2021208857A1 (en) Access control method and communication device
WO2024212793A1 (en) Communication method and communication apparatus
WO2022037611A1 (en) Network access method and apparatus, network selection method and apparatus, and communication device
CN119383597A (en) Device, method and computer program
CN119729483A (en) Communication method, device and system
CN119300106A (en) Network switching method, device, equipment and storage medium
CN120455984A (en) Registration method and device of dual-boot equipment, communication device and storage medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant