Mechanism for service detection in encrypted services
Through collaboration between network operators and content providers, SNI encryption is activated using SLA and DNS resolution/source server redirection mechanisms, solving the challenges of service detection and management under encrypted services and achieving effective execution of QoS and service optimization.
Patent Information
- Application Number
- CN202080105038.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-09-15
- Filing Date
- 2020-11-13
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2040-11-13
AI Technical Summary
Existing technologies make it difficult to effectively distinguish between encrypted TLS 1.3 and higher versions and QUIC protocol application services, resulting in challenges for network operators in service management, such as difficulties in QoS and service optimization.
Through collaboration between network operators and content providers, a service level agreement (SLA) is adopted to deactivate SNI encryption for a specific set of applications, and DNS resolution and source server redirection mechanisms are used to ensure that UPF can detect and classify encrypted services.
It realizes the service detection and management of specific application sets in an encrypted service environment, ensuring the normal operation of QoS and service optimization functions.
Smart Images

Figure CN116076097B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to wireless communication systems, and more particularly to a mechanism for traffic detection in the context of encrypted traffic. Background Art
[0002] Figure 1 An example of a fifth generation (“5G”) network (also known as a new radio (“NR”) network) is shown that includes a network node 120 (e.g., a 5G base station (“gNB”)), a plurality of communication devices 110 (also known as user equipment (“UE”)).
[0003] Figure 2 An example of a 5G reference architecture defined by the 3rd Generation Partnership Project ("3GPP") is shown. The 5G network architecture includes a network slice selection function ("NSSF"), a network exposure function ("NEF"), a network repository function ("NRF"), a policy control function ("PCF"), a unified data management ("UDM"), an application function ("AF"), an authentication server function ("AUSF"), an access and mobility management function ("AMF"), a session management function ("SMF"), UEs, radio access network ("RAN") nodes, a user plane function ("UPF"), and a data network ("DN"). The 5G architecture allows the UDM, PCF, and NEF to store data in a unified data repository ("UDR"). The data may include subscription data and policy data for the UDM and PCF. The data may also include structured data for exposure, application data for the NEF (including packet flow descriptions ("PFDs") for application detection and AF request information for multiple UEs).
[0004] PCF can support a unified policy framework to manage network behavior. For example, PCF can provide policy and charging control ("PCC") rules to SMF.
[0005] The SMF may support different functions (e.g., session establishment, modification / release, and policy-related functions such as terminating interfaces to the PCF, charging data collection, supporting charging interfaces, and controlling and coordinating charging data collection at the UPF). In some examples, the SMF may manage the UE Internet Protocol ("IP") address allocation process (allocation may be performed by the SMF or the UPF), receive PCC rules from the PCF, and configure the UPF accordingly over the N4 reference point (e.g., the Packet Forwarding Control Protocol ("PFCP")). The SMF may control packet processing in the UPF by establishing, modifying, or deleting PFCP sessions and by providing (e.g., adding, modifying, or deleting) packet detection rules ("PDRs"), forwarding action rules ("FARs"), quality of service ("QoS") enforcement rules ("QERs"), and / or usage reporting rules ("URRs") for each PFCP session. A PFCP session may correspond to a separate protocol data unit ("PDU") session or an independent PFCP session that is not bound to any PDU session.
[0006] Each PDR may include Packet Detection Information ("PDI") that specifies service filters or signatures to match incoming packets. Each PDR is associated with rules that provide a set of instructions to be applied to packets that match the PDI. These rules may include a FAR that includes instructions related to the processing of packets, specifically, forwarding, copying, dropping, or buffering packets with or without notifying the control plane ("CP") functions about the arrival of DL packets. These rules may also include zero, one, or more QERs that include instructions related to QoS enforcement for the service. These rules may also include zero, one, or more URRs that include instructions related to service measurement and reporting.
[0007] The UPF may support processing of user plane ("UP") traffic based on rules received from the SMF, such as packet inspection (via PDR) and different enforcement measures (e.g., traffic control, QoS, charging / reporting (via FAR, QER, URR)).
[0008] Traffic encryption has grown significantly in mobile networks, and at the same time, the complexity of encryption mechanisms has also grown.
[0009] The network provider may use service filters (which may be configured locally or received from the content provider / AF via the Nnef interface) to detect services and apply corresponding management / enforcement actions (eg, billing and QoS).
[0010] In some examples, the information that a content provider can convey to a network operator so that the network operator can properly distinguish and classify the content provider's traffic is information included in a standardized PFD. The standardized PFD includes a set of information that can detect application traffic, the information set including: a PFD id; a triple (including a protocol, a server-side IP address, and a port number); an important portion of a universal resource locator ("URL") to match (e.g., a host name); or a domain name matching criteria (referring to the Transport Layer Security ("TLS") protocol, particularly to the TLS Client Hello Server Name Indication).
[0011] There may be significant use of encrypted SNI in the near future, but existing methods have difficulty performing traffic differentiation, which may negatively impact existing network operator traffic management use cases (e.g., sponsored data, QoS, and traffic optimization) for both TLS (version 1.3 and higher) and / or QUIC-based applications. At the same time, using only unencrypted SNI may not provide sufficient security. Summary of the Invention
[0012] According to some embodiments, a method of operating a first network node in a first communication network is provided. The method may include receiving (1110) a first message from a second network node operating in a second communication network. The method may also include: in response to receiving the first message, the first network node may also determine that the second network node is associated with a network operator that has a service level agreement (SLA) with a content operator, and the content operator is associated with the first network node. The method may also include sending a second message to the second network node. The second message may include information based on the second node being associated with the network operator that has the SLA with the content operator. The information is associated with whether subsequent messages from a communication device associated with the second network node are sent to a source server using an unencrypted server name indication (SNI).
[0013] According to other embodiments, a method for operating a network node in a communications network is provided. The method may include receiving a request message for resources associated with an application from a communications device. The method may also include determining whether a subscriber policy is associated with the communications device. The method may also include determining a uniform resource locator (URL) based on whether the subscriber policy is associated with the communications device. The method may also include sending a response message including the URL to the communications device.
[0014] According to other embodiments, a network node, a computer program and / or a computer program product is provided for performing one or more of the above methods.
[0015] The various embodiments described herein allow network operators to provide existing traffic management functionality to their subscribers when the traffic is encrypted, including when DNS traffic is also encrypted. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The accompanying drawings illustrate certain non-limiting embodiments of the inventive concept, and are included to provide a further understanding of the present disclosure, and are incorporated into and constitute a part of this application. In the drawings:
[0017] Figure 1 is an example schematic diagram illustrating a 5th generation ("5G") network;
[0018] Figure 2 is an example block diagram illustrating a 5G network architecture;
[0019] Figure 3 is an example signal flow diagram illustrating a DNS-based mechanism for deactivating SNI encryption of an application according to some embodiments;
[0020] Figures 4 to 7 is an example signal flow diagram illustrating an origin server-based mechanism for deactivating SNI encryption of an application in accordance with some embodiments;
[0021] Figure 8 is an example block diagram illustrating a communication device according to some embodiments;
[0022] Figure 9 is an example block diagram illustrating a radio access network ("RAN") node according to some embodiments;
[0023] Figure 10 is an example block diagram illustrating a core network ("CN") node according to some embodiments;
[0024] Figure 11 is an example flow chart illustrating operations performed by a network node according to some embodiments;
[0025] Figure 12 is an example flow chart illustrating operations performed by a communication device according to some embodiments;
[0026] Figure 13 is a block diagram of a wireless network according to some embodiments;
[0027] Figure 14 is a block diagram of a user equipment according to some embodiments;
[0028] Figure 15 is a block diagram of a virtualization environment according to some embodiments;
[0029] Figure 16is a block diagram of a telecommunications network connected to a host computer via an intermediary network according to some embodiments;
[0030] Figure 17 is a block diagram of a host computer communicating with a user device via a base station over a partially wireless connection according to some embodiments;
[0031] Figure 18 is a block diagram of a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments;
[0032] Figure 19 is a block diagram of a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments;
[0033] Figure 20 is a block diagram of a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments;
[0034] Figure 21 is a block diagram of a method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments. DETAILED DESCRIPTION
[0035] Hereinafter, the present invention will be described more fully with reference to the accompanying drawings, in which examples of embodiments of the present invention are shown. However, the present invention can be embodied in a variety of different forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided so that this disclosure will be comprehensive and complete, and the scope of the present invention will be fully conveyed to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. A component from one embodiment can be assumed to be present in / used in another embodiment by default.
[0036] The Transport Layer Security ("TLS") protocol may specify an extension called Server Name Indication ("SNI"). A content server may host multiple sources behind a single IP address. In order to route an application stream to the correct server without having to decrypt the entire stream, the SNI extension may be used. The SNI extension may be sent by the client in the Client Hello message and includes a plaintext string of the domain name of the server to which the client is attempting to connect. Because the SNI field is sent in plaintext, network elements along the path can use it to classify the stream.
[0037] In some examples, including TLS 1.3, the SNI extension can be encrypted. In an additional or alternative example, Quick User Datagram Protocol ("UDP") Internet Connections ("QUIC"), a stream-multiplexing encrypted transport protocol based on UDP, is used as an alternative to the Transmission Control Protocol ("TCP"). QUIC can rely on TLS 1.3, so that QUIC-based applications will cause the SNI extension to be encrypted.
[0038] Domain Name System ("DNS") encryption is a fundamental component of the Internet. DNS is used every time you visit a website, send an email, have an instant messaging ("IM") conversation, or perform a variety of other online actions. When a user opens an application, the DNS protocol is used to retrieve the server Internet Protocol ("IP") address for the target application domain. The DNS protocol can be unencrypted (for example, DNS over UDP / TCP), but DNS encryption can be used to prevent middleboxes from inspecting DNS traffic. It is likely that within the 5G timeframe, most DNS traffic will be encrypted.
[0039] In some examples, TLS 1.3 will cause the TLS SNI to be encrypted / obfuscated. Packet Forwarding Description ("PFD") rules as defined by the 3rd Generation Partnership Project ("3GPP") can make it more difficult to distinguish between traffic for TLS (1.3 and higher) and / or QUIC-based applications because network elements along the path typically use SNI to classify flows. Traffic can still be distinguished based on lists of IP addresses, but this can have a number of disadvantages. For example, lists of IP addresses can be difficult to keep updated, can expose over-the-top ("OTT") topologies, and can result in more information being exchanged (e.g., lists of IP addresses can be large).
[0040] Encrypted SNI may result in a lack of service differentiation, which may have relevant impacts on existing network operator service management use cases (e.g., sponsored data, Quality of Service (“QoS”), and service optimization) for both TLS (1.3 and higher) and / or QUIC-based applications.
[0041] Various embodiments described herein provide a mechanism for collaborating between content providers and network operators to deactivate SNI encryption for a specific set of applications. In some embodiments, SNI encryption may be deactivated for a specific set of applications even if DNS traffic is encrypted.
[0042] In some embodiments, DNS-based operations allow for deactivation of SNI encryption for a specific set of applications. A network operator and a content provider may have a service level agreement ("SLA") that includes deactivation of SNI encryption in the network operator's network for a certain set of applications of the content provider. In some examples, subscribers of a network operator are pre-provisioned with the addresses of the network operator's DNS servers. When the authoritative DNS detects that a DNS request is coming from a user of a certain mobile network (e.g., via a mobile network operator ("MNO") DNS), it does not provide encrypted SNI ("eSNI") keys.
[0043] In additional or alternative embodiments, the authoritative DNS can differentiate DNS queries from users of a certain MNO based on the IP address of the DNS resolver (e.g., the MNO DNS IP address) and differentiate responses accordingly (e.g., providing / not providing an eSNI key). In some examples, the network operator provides the IP address of its DNS resolver to the content provider as part of an "offline" SLA or exposes the IP address of the MNO DNS resolver involved in SNI deactivation to the content provider through an "online" mechanism.
[0044] In additional or alternative embodiments, to allow the MNO to authorize this process (e.g., allowing user consent), a mechanism for MNO DNS partitioning may be used such that only DNS queries for subscribers who have been provided with authorization for this process are sent to DNS resolvers covered by the SLA (e.g., user DNS is bootstrapped using the Encrypted Protocol Configuration Option (“ePCO”) at PDU session establishment).
[0045] In some embodiments, operation based on the origin server allows for deactivation of SNI encryption for a specific set of applications. The network operator and the content provider may have a service level agreement ("SLA") that includes deactivation of SNI encryption in the network operator's network for a certain set of applications of the content provider. In some examples, based on the agreement between the network operator and the content provider, eSNI deactivation may be performed by an application ("App") redirection to a domain that does not have an eSNI key. This redirection may be performed by the origin server when the origin server identifies a user whose traffic is coming from a given MNO (under the SLA) based on the user's IP address. In an additional or alternative example, the MNO provides a public IP range to the OTT as part of an "offline" SLA or exposes the MNO's public IP range to the content provider through an "online" mechanism.
[0046] The various embodiments described herein allow network operators to provide existing traffic management functionality to their subscribers when the traffic is encrypted, including when DNS traffic is also encrypted.
[0047] Figure 8 is a block diagram illustrating elements of a communication device 800 (also referred to as a mobile terminal, mobile communication terminal, wireless device, wireless communication device, wireless terminal, mobile device, wireless communication terminal, user equipment UE, user equipment node / terminal / device, etc.) configured to provide wireless communication according to an embodiment of the present inventive concept. (The communication device 800 may be provided, for example, as described below with respect to Figure 13 As shown, the communication device 800 may include an antenna 807 (e.g., corresponding to Figure 13 antenna 4111) and transceiver circuit 801 (also referred to as a transceiver, for example, corresponding to Figure 13 The transceiver circuit 801 includes a transmitter and a receiver configured to provide communication with a base station of a radio access network (eg, corresponding to a base station of a radio access network). Figure 13 The communication device 800 may further include: a processing circuit 803 (also referred to as a processor, for example, corresponding to Figure 13 Processing circuit 4120), coupled to the transceiver circuit; and memory circuit 805 (also referred to as memory, for example, corresponding to Figure 13 The device readable medium 4130 is coupled to the processing circuit. The memory circuit 805 may include computer-readable program code that, when executed by the processing circuit 803, causes the processing circuit to perform operations according to the embodiments disclosed herein. According to other embodiments, the processing circuit 803 may be defined to include a memory, thereby eliminating the need for a separate memory circuit. The communication device 800 may also include an interface (e.g., a user interface) coupled to the processing circuit 803, and / or the communication device UE may be incorporated into a vehicle.
[0048] As discussed herein, the operations of the communication device 800 may be performed by the processing circuitry 803 and / or the transceiver circuitry 801. For example, the processing circuitry 803 may control the transceiver circuitry 801 to transmit communications to a radio access network node (also referred to as a base station) via a radio interface through the transceiver circuitry 801 and / or to receive communications from a RAN node via a radio interface through the transceiver circuitry 801. In addition, modules may be stored in the memory circuitry 805, and these modules may provide instructions such that when the instructions of the modules are executed by the processing circuitry 803, the processing circuitry 803 performs corresponding operations.
[0049] In some embodiments, the term radio network node or network node refers to any type of network node that serves a UE and / or is connected to another network node, network element, or any radio node from which a UE receives signals. In some examples, a radio network node includes: a Node B, a base station ("BS"), a multi-standard radio ("MSR") node (e.g., an MSRBS, a gNodeB, a network controller, a radio network controller ("RNC"), a base station controller ("BSC"), a relay, a donor node that controls a relay, a base transceiver station ("BTS"), an access point ("AP"), a transmission point, a transmission node, a remote radio unit ("RRU"), a remote radio head ("RRH"), or a node in a distributed antenna system ("DAS").
[0050] Figure 9 is a block diagram illustrating elements of a radio access network (RAN) node 900 (also referred to as a network node, base station, eNodeB / eNB, gNodeB / gNB, etc.) of a radio access network (RAN) configured to provide cellular communications according to an embodiment of the present inventive concept. (The RAN node 900 may be provided, for example, as described below with respect to Figure 13 As shown in the figure, the RAN node 900 may include a transceiver circuit 901 (also referred to as a transceiver, such as a Figure 13 The transceiver circuit 901 includes a transmitter and a receiver configured to provide uplink radio communication and downlink radio communication with the mobile terminal. The RAN node 900 may include a network interface circuit 907 (also referred to as a network interface, for example, corresponding to Figure 13 The network interface circuit 907 is configured to provide communication with other nodes of the RAN and / or core network CN (e.g., with other base stations). The RAN node 900 may further include: a processing circuit 903 (also referred to as a processor, e.g., corresponding to the processing circuit 4170), coupled to the transceiver circuit; and a memory circuit 905 (also referred to as a memory, e.g., corresponding to the memory). Figure 13 4180) is coupled to the processing circuit. Memory circuit 905 may include computer-readable program code that, when executed by processing circuit 903, causes the processing circuit to perform operations according to the embodiments disclosed herein. According to other embodiments, processing circuit 903 may be defined to include memory, thereby eliminating the need for a separate memory circuit.
[0051] As discussed herein, the operations of the RAN node 900 may be performed by the processing circuitry 903, the network interface 907, and / or the transceiver 901. For example, the processing circuitry 903 may control the transceiver 901 to transmit downlink communications to one or more mobile terminals UE via the radio interface via the transceiver 901 and / or to receive uplink communications from one or more mobile terminals UE via the radio interface via the transceiver 901. Similarly, the processing circuitry 903 may control the network interface 907 to transmit communications to one or more other network nodes via the network interface 907 and / or to receive communications from one or more other network nodes via the network interface. In addition, modules may be stored in the memory 905, and these modules may provide instructions such that when the instructions of the modules are executed by the processing circuitry 903, the processing circuitry 903 performs corresponding operations (e.g., the operations discussed below with respect to example embodiments related to network nodes).
[0052] According to some other embodiments, the network node may be implemented as a core network (CN) node without a transceiver. In such embodiments, transmissions to the wireless communication device (UE) may be initiated by the network node, such that transmissions to the wireless communication device (UE) are provided by the network node (e.g., by a base station or RAN node) including a transceiver. According to embodiments in which the network node is a RAN node including a transceiver, initiating the transmission may include sending via the transceiver.
[0053] Figure 10 is a block diagram illustrating elements of a core network ("CN") node 1000 (e.g., an SMF node, an AMF node, an AUSF node, a UDM node, etc.) of a communication network configured to provide cellular communications according to an embodiment of the present inventive concept. As shown, the CN node 1000 may include a network interface circuit 1007 (also referred to as a network interface) configured to provide communications with other nodes of the core network and / or RAN. The CN node 1000 may also include a processing circuit 1003 (also referred to as a processor) coupled to the network interface circuit and a memory circuit 1005 (also referred to as a memory) coupled to the processing circuit. The memory circuit 1005 may include computer-readable program code that, when executed by the processing circuit 1003, causes the processing circuit to perform operations according to the embodiments disclosed herein. According to other embodiments, the processing circuit 1003 may be defined to include a memory, thereby eliminating the need for a separate memory circuit.
[0054] As discussed herein, operations of the CN node 1000 may be performed by the processing circuitry 1003 and / or the network interface circuitry 1007. For example, the processing circuitry 1003 may control the network interface circuitry 1007 to send communications to one or more other network nodes via the network interface circuitry 1007 and / or to receive communications from one or more other network nodes via the network interface circuitry 1007. Furthermore, modules may be stored in the memory 1005, and these modules may provide instructions such that, when the instructions of the modules are executed by the processing circuitry 1003, the processing circuitry 1003 performs corresponding operations.
[0055] Figure 3 An example of an SNI-encrypted DNS-based mechanism for deactivating an application is shown. Figure 3 In the example, the application is shown as example.com, but the DNS-based mechanism can be used for any service type as long as some prerequisites are met.
[0056] In some embodiments, the precondition includes: the network operator and the content provider have an SLA that includes deactivating SNI encryption in the network operator's network for the content provider's application (e.g., example.com). As part of this agreement, the content provider can obtain the IP address of the DNS resolver of the user in the operator's network who should deactivate SNI encryption. In additional or alternative embodiments, the precondition includes: the network operator's subscribers are pre-provisioned with the address of the network operator's DNS server and the user accepts to use the network operator's pre-provisioned information. For example, this information can be provided to the UE as part of the session establishment process.
[0057] At operation 310, client 302 (e.g., a UE or a network node associated with the UE) attempts to resolve the original domain (example.com) by communicating with MNO DNS 305. At operation 320, MNO DNS attempts to resolve the original domain (example.com) by communicating with authoritative DNS 308. At operation 330, the authoritative DNS detects that the request comes from an IP address of a DNS resolver known as operator X (associated with MNO DNS 306), for which an SLA agreement exists for deactivating eSNI for the requested domain (example.com). At operation 340, authoritative DNS 308 resolves the hostname (without an associated eSNI key) and sends an AA record (without an eSNI key) to MNO DNS 306. At operation 340, MNO DNS 306 forwards the AA record (without an eSNI key) to client 302.
[0058] Since the eSNI key is not provided to the UE (client 302), subsequent requests will be sent using the plaintext SNI. At operations 360, 370, and 380, client 302 sends a message with the plaintext SNI to origin server 309, and the UPF 304 detection filter is able to detect and classify the application traffic. At operation 390, origin server 309 sends a response to client 302 using PDR based on the classification of the application traffic.
[0059] Figures 4 to 7 An example of an origin server-based mechanism for deactivating SNI encryption for an application is shown. In some embodiments, the origin-based mechanism is specific to Hypertext Transfer Protocol ("HTTP") based services, but may have fewer prerequisites than a DNS-based mechanism. In additional or alternative embodiments, the prerequisites may include: the network operator and the content provider having an SLA that includes deactivating SNI encryption in the network operator's network for the content provider's application (e.g., example.com). As part of the agreement, the content provider may obtain a public IP range assigned to the user by the network operator. In additional or alternative embodiments, the ability of the MNO to implement its own DNS resolver (a prerequisite for some DNS-based embodiments) may be challenged by some HTTP browsers.
[0060] Figure 4 An example of an SNI-encrypted origin-based mechanism for deactivating an application (example.com) is shown.
[0061] At operation 405, client 302 (including or associated with a UE) sends a message for resolving the original domain (example.com) to authoritative DNS 308. At operation 410, authoritative DNS 308 replies to client 302 by sending a message including an AA (or AAAA) record with an eSNI key.
[0062] At operation 415, client 302 sends a request message to origin server 309. The request message may request a resource and include a TLS Client Hello message protected by eSNI. At operation 420, origin server 309 detects that the request comes from an IP address known to belong to operator X (for which it holds an SLA agreement). At operation 425, origin server 309 redirects the request to a URL served by operator X by sending a response to client 302, including a URL with a hostname that will not be resolved using the eSNI key. In this example, a 307 Temporary redirect code is used, but other redirect codes can be used to achieve the same result.
[0063] At operations 430 and 435 , the client 302 communicates with the MNO HTTPS server IP address 305 using the Carrier X URL (Carrier X may deactivate eSNI in the resolution) and establishes a TCP and TLS connection.
[0064] At operation 440, the UPF 304 detects the message based on the destination IP address or TLS SNI and checks the subscriber policy (both for user consent and operator verification) based on the PCC rules pre-installed and pre-configured for the service.
[0065] At operation 445 , after TCP and TLS are established, the client 302 triggers an HTTPS GET to the operator X URL, appending the URL with the hostname that is not resolved using the eSNI key.
[0066] At operation 450, the MNO HTTP server 305 redirects to the host name that will not be resolved using the eSNI key. In this example, a 308 permanent redirect code is used, but other redirect codes can be used to achieve the same result.
[0067] At operations 455 and 460 , client 302 communicates with authoritative DNS 308 and resolves the new hostname (without receiving the associated eSNI key).
[0068] At operations 465, 470, and 475, client 302 will send a request with a clear text SNI to origin server 309 and UPF 304 detects the application service. In some embodiments, a token or user id is sent by UPF 304 to origin server 309 to indicate that a particular service is activated.
[0069] At operation 480 , the origin server 309 sends a response to the client 302 applying the PDR based on the classification of the application traffic.
[0070] Figures 5 and 6 An additional example of an SNI-encrypted source-based mechanism for deactivating an application (example.com) is shown. Operations 405, 410, 415, 420, 430, 435, 440, 455, 460, and 470 are similar to those described above with respect to Figure 4 405, 410, 415, 420, 430, 435, 440, 455, 460 and 470 described.
[0071] exist Figures 5 to 6In the figure, at operation 525, origin server 309 redirects the request to a URL served by operator X by sending a response to client 302. The response includes two separate query parameters, which contain two redirection URLs. One URL's hostname (nk.example.com) will not be resolved using the eSNI key when the policy applies, while the other URL's hostname (example.com) will be resolved using the eSNI key when the policy does not apply. In this example, a 307 Temporary Redirection code is used, but other redirection codes can be used to achieve the same result.
[0072] exist Figures 5 and 6 In operation 545 , after TCP and TLS are established, the client 302 triggers an HTTPS GET to the operator X URL, thereby appending two URLs (one selected based on the MNO HTTPS server and one selected based on whether the policy applies).
[0073] exist Figure 5 In the example, the policy applies, so at operation 550, the MNO HTTP server 305 redirects to the hostname (nk.example.com) based on the policy application. In this example, the policy-related data (QSBzdXBlciBpbXBvcnRhbnQgcG9sa) is added as a query parameter to the redirect URL (encrypted in base64, although other encryption methods can be used). The 308 permanent redirect code is used, but other redirect codes can be used to achieve the same result. At operations 565 and 575, the request message includes the policy-related data (provided by the MNO HTTPS server 305) as a query parameter. At operation 580, the origin server 309 sends a response to the client 302 that applied the PDR based on the classification of the application service and / or the policy-related data.
[0074] exist Figure 6 , the policy does not apply, so at operation 650, the MNO HTTP server 305 redirects to the host name (example.com) based on the policy not applying. In this example, the policy-related data (Tm8gcG9saWN5) is added as a query parameter to the redirect URL (encrypted in base64, although other encryption methods can be used). The 308 permanent redirect code is used, but other redirect codes can be used to achieve the same result. At operation 665, the request message includes the policy-related data (provided by the MNO HTTPS server 305) as a query parameter. At operation 675, the origin server 309 determines that the policy data indicates that a new redirect is not required. At operation 680, the origin server 309 sends a response to the client 302 based on the policy-related data.
[0075] In additional or alternative embodiments, instead of policy-related data, the URL provided by the MNO HTTPS server 305 may be a no-policy URL (eg, no-policy.example.com) that is different from the original URL (example.com).
[0076] Figure 7 Another origin server-based mechanism for deactivating SNI encryption of an application (example.com) is shown.
[0077] At operation 705, client 302 (including or associated with a UE) sends a message for resolving the original domain (example.com) to authoritative DNS 308. At operation 710, authoritative DNS 308 replies to client 302 by sending a message including an AA (or AAAA) record with an eSNI key.
[0078] At operation 715, client 302 sends a request message to origin server 309. The request message may request a resource and include a TLS Client Hello message protected by eSNI. At operation 720, origin server 309 detects that the request comes from an IP address known to belong to operator X (for which it holds an SLA agreement). At operation 425, origin server 309 redirects the request to a URL served by operator X by sending a response to client 302, including a URL with a hostname that will not be resolved using the eSNI key. In this example, a 308 Permanent redirect code is used, but other redirect codes can be used to achieve the same result.
[0079] At operation 730, client 302 sends a message to authoritative DNS 308 to resolve the new hostname (nk.example.com). At operation 735, authoritative DNS 308 replies to client 302 by sending a message including an AA (or AAAA) record without an associated eSNI key.
[0080] Subsequent requests from the UE will be sent using the plaintext SNI, allowing the UPF 304 detection filter to detect the application traffic.
[0081] At operations 740, 745, and 750, client 302 sends a request with a clear text SNI to origin server 309 and UPF 304 detects the application service. In some embodiments, a token or user id is sent by UPF 304 to origin server 309 to indicate that a particular service is activated.
[0082] At operation 755 , the origin server 309 sends a response to the client 302 applying the PDR based on the classification of the application traffic.
[0083] exist Figure 7 In the example shown, the selection of users to whom this process applies is controlled by using specific IP pools / ranges (e.g., on a per-subscriber category basis) from operator X for users to whom eSNI deactivation applies. This assumes that the network operator assigns UE IP addresses from these IP pools / ranges if eSNI deactivation applies to the subscriber, and that these IP pools / ranges are the IP address / ranges that the content provider obtains as part of the agreement.
[0084] Although various embodiments have been described in terms of a 5G network architecture, the same mechanisms can be applied to other radio access technologies. For example, the same mechanisms can be used for 4G by replacing the PCF with a policy and charging rules function ("PCRF"); replacing the SMF with a PDN gateway CP function ("PGW-C") or a traffic detection function CP function ("TDF-C"); and replacing the UPF with a PDN gateway UP function ("PGW-U") or a traffic detection function UP function ("TDF-U").
[0085] Reference will now be made to some embodiments of the present invention Figure 11 The operation of network nodes is discussed with the help of the flowchart. Figure 11 The following will be described as being performed by the network node 1000 (using Figure 10 For example, the module can be stored in Figure 10 The modules may be stored in the memory 1005 and these modules may provide instructions such that when the instructions of the modules are executed by the corresponding processing circuit 1003, the processing circuit 1003 performs the corresponding operations of the flowchart. Figure 11 The operations in may be performed by any suitable network node.
[0086] Figure 11 An example of operations performed by a network node associated with a content provider to deactivate SNI encryption for an application is shown.
[0087] At block 1110 , the processing circuit 1003 receives a first message from a second network node operating in a second communication network via the network interface 1007 .
[0088] At block 1120, processing circuit 1003 determines that the second network node is associated with a network operator that has an SLA with a content operator that is associated with the first network node. In some embodiments, determining that the second network node is associated with the network operator that has an SLA with the content operator includes: determining an IP address of the second network node; determining that the IP address of the second network node is in a predetermined list of IP addresses provided by the network operator; and determining that the second network node is associated with the network operator that has an SLA with the content operator based on the IP address being in the predetermined list of IP addresses.
[0089] At block 1130, processing circuit 1003 sends a second message to the second network via network interface 1007. The second message includes information based on the network node being associated with a network operator that has an SLA with the content operator. The information may be associated with whether a subsequent message from the communication device associated with the second network node is sent to the origin server using an unencrypted server name indication (SNI).
[0090] In some embodiments, the first network node is an authoritative DNS node and the second network node is an MNO DNS node. The first message may be a DNS query. In additional or alternative embodiments, sending the second message to the second network node includes sending a DNS query response to the second network node, the DNS query response indicating that subsequent messages from the communication device associated with the second network node are to be sent to the source server using unencrypted SNI. In additional or alternative embodiments, sending the DNS query response includes sending the DNS query response without a DNS record required for SNI encryption.
[0091] In an additional or alternative embodiment, the first network node is an origin server and the second network node is a communication device. The first message may be a request message using eSNI. In an additional or alternative embodiment, sending the second message to the second network node includes: sending a response message including a URL based on the second network node being associated with a network operator that has an SLA with the content operator. In some examples, the response message includes the first URL, an indication of a subscriber policy, and a second URL, and indicates that: in response to the subscriber policy being associated with the communication device, the communication device should use the first URL for subsequent resource requests; and in response to the subscriber policy not being associated with the communication device, the communication device should use the second URL for subsequent resource requests. In an additional or alternative example, the first URL can be resolved so that the communication device sends subsequent resource requests using unencrypted SNI, and the second URL can be resolved so that the communication device sends subsequent resource requests using eSNI.
[0092] In an additional or alternative embodiment, the first communication network or the second communication network is a fifth generation 5G network. In an additional or alternative embodiment, the first communication network or the second communication network is a long term evolution LTE network. In an additional or alternative embodiment, the first communication network or the second communication network is any suitable radio access technology.
[0093] For some embodiments of network nodes and related methods, Figure 11 Various operations may be optional.
[0094] Reference will now be made to some embodiments of the present invention Figure 12 The operation of network nodes is discussed with the help of the flowchart. Figure 12 The following will be described as being performed by the network node 1000 (using Figure 10 For example, the module can be stored in Figure 10 The modules may be stored in the memory 1005 and these modules may provide instructions such that when the instructions of the modules are executed by the corresponding processing circuit 1003, the processing circuit 1003 performs the corresponding operations of the flowchart. Figure 12 The operations in may be performed by any suitable network node.
[0095] Figure 12 An example of operations performed by a network node associated with a network operator to deactivate SNI encryption for an application is shown.
[0096] At block 1210 , the processing circuit 1003 receives a request message for resources associated with an application from a communication device via the network interface 1007 .
[0097] At block 1220 , the processing circuit 1003 determines whether a subscriber policy is associated with the communication device.
[0098] At block 1230, processing circuit 1003 determines a URL based on whether a subscriber policy is associated with the communication device. In some embodiments, determining the URL includes determining whether subsequent communications from the communication device should use an eSNI based on whether a subscriber policy is associated with the communication device. The URL may be determined based on whether subsequent communications from the communication device should use an eSNI.
[0099] In some embodiments, determining whether a subscriber policy is associated with the communication device includes determining that a subscriber policy is associated with the communication device.The URL may be selected from the plurality of URLs based on the URL being resolvable such that the communication device sends a subsequent message using an unencrypted SNI.
[0100] In some embodiments, determining whether a subscriber policy is associated with the communication device includes determining that a subscriber policy is not associated with the communication device.The URL may be selected from the plurality of URLs based on the URL being resolvable such that the communication device sends a subsequent message using the eSNI.
[0101] In additional or alternative embodiments, the request message further includes the first URL, an indication of a subscriber policy, and the second URL.Determining the URL may include selecting a URL from the first URL and the second URL based on whether a subscriber policy is associated with the communication device.
[0102] At block 1240, the processing circuit 1003 sends a response message including the URL to the communication device via the network interface 1007. In some embodiments, the response message also includes information associated with the subscriber policy.
[0103] In additional or alternative embodiments, the first communication network or the second communication network is a fifth generation (5G) network. In some examples, the network node is a CN node including a UPF and an MNO DNS server. In additional or alternative embodiments, the first communication network or the second communication network is a Long Term Evolution (LTE) network. In additional or alternative embodiments, the first communication network or the second communication network is any suitable radio access technology.
[0104] For some embodiments of network nodes and related methods, Figure 12 Various operations may be optional.
[0105] Some of the abbreviations used above are described below.
[0106] Explanation of abbreviations
[0107] 3GPP Third Generation Partnership Project
[0108] AF application function
[0109] AMF Access and Mobility Management Function
[0110] CHLO Client Greetings
[0111] DNS domain name service
[0112] DNSSEC DNS Security
[0113] DOH DNS over HTTP / 2
[0114] DPI Deep Packet Inspection
[0115] EDNS DNS extension mechanism
[0116] ESNI Encrypted Server Name Indication
[0117] FAR forwarding action rules
[0118] FQDN Fully Qualified Domain Name
[0119] HTTP Hypertext Transfer Protocol
[0120] HTTPS Super Transmission Text Protocol Security
[0121] IE Information Element
[0122] PCF Policy Control Function
[0123] PCRF policy control rule function
[0124] PDR Group Detection Rules
[0125] PDU Protocol Data Unit
[0126] PFCP Packet Flow Control Protocol
[0127] PGW Packet Gateway
[0128] PGW-C PDN gateway control plane function
[0129] PGW-U PDN gateway user plane function
[0130] QER QoS Enforcement Rules
[0131] QoS Quality of Service
[0132] QUIC fast UDP internet connection
[0133] SMF session management functions
[0134] SNI Server Name Indication
[0135] TCP Transmission Control Protocol
[0136] TLS Transport Layer Security
[0137] UDP User Datagram Protocol
[0138] UDM Unified Data Repository
[0139] UE User Equipment
[0140] UPF User Plane Function
[0141] URL Uniform Resource Locator
[0142] URR Usage Reporting Rules
[0143] Additional references include:
[0144] TLS 1.3draft-ietf-tls-esni-06 Encrypted Server Name Indication
[0145] Additional instructions are provided below.
[0146] Generally, unless clearly given and / or different meanings are suggested from the context, all terms used in this article will be interpreted according to their ordinary meaning in the relevant technical field. Unless otherwise clearly stated, all references to "one / an / element, equipment, component, device, step, etc." should be openly interpreted as referring to at least one instance in an element, equipment, component, device, step, etc. Unless a step must be clearly described as being after or before another step and / or a step must be after or before another step implicitly, the steps of any method disclosed herein need not be performed in the exact order disclosed. Where appropriate, any feature of any embodiment disclosed herein may be applied to any other embodiment. Similarly, any advantage of any embodiment may be applicable to any other embodiment, and vice versa. By the description below, other purposes, features and advantages of the attached embodiments will be apparent.
[0147] Some embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. However, other embodiments are within the scope of the subject matter disclosed herein, and the disclosed subject matter should not be construed as being limited to only the embodiments set forth herein; rather, these embodiments are provided merely as examples to convey the scope of the subject matter to those skilled in the art.
[0148] Figure 13 A wireless network in accordance with some embodiments is shown.
[0149] Although the subject matter described herein may be implemented in any suitable type of system using any suitable components, the embodiments disclosed herein are directed to wireless networks (e.g., Figure 13 For simplicity, Figure 13 The wireless network shown in FIG. 4 only depicts network 4106, network nodes 4160 and 4160b, and WDs 4110, 4110b, and 4110c (also referred to as mobile terminals). In practice, a wireless network may also include any additional components suitable for supporting communication between wireless devices or between a wireless device and another communication device (e.g., a landline phone, a service provider, or any other network node or terminal device). Of the components shown, network node 4160 and wireless device (WD) 4110 are depicted with additional details. A wireless network may provide communication and other types of services to one or more wireless devices, facilitating the wireless devices to access and / or use services provided by or via the wireless network.
[0150] A wireless network may include and / or interface with any type of communication, telecommunication, data, cellular, and / or radio network or other similar type of system. In some embodiments, a wireless network may be configured to operate according to a particular standard or other type of predefined rules or procedures. Thus, particular embodiments of a wireless network may implement communication standards such as Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, or 5G standards; wireless local area network (WLAN) standards (e.g., IEEE 802.11 standards); and / or any other suitable wireless communication standards, such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, and / or ZigBee standards.
[0151] Network 4106 may include one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTNs), packet data networks, optical networks, wide area networks (WANs), local area networks (LANs), wireless local area networks (WLANs), wired networks, wireless networks, metropolitan area networks, and other networks to enable communication between devices.
[0152] The network node 4160 and the WD 4110 include various components described in more detail below. These components work together to provide network node and / or wireless device functionality, such as providing wireless connectivity in a wireless network. In various embodiments, a wireless network may include any number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, relay stations, and / or any other components that may facilitate or participate in the communication of data and / or signals (whether via a wired or wireless connection).
[0153] As used herein, a network node refers to a device that is capable of, configured, arranged and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or devices in a wireless network to enable and / or provide wireless access to the wireless device and / or perform other functions in the wireless network (e.g., management). Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, NodeBs, evolved NodeBs (eNBs), and NR NodeBs (gNBs)). Base stations can be classified based on the amount of coverage they provide (or in other words, based on their transmit power levels), so they can also be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station can be a relay node or a relay donor node that controls a relay. A network node can also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), sometimes referred to as a remote radio head (RRH). These remote radio units may be integrated with an antenna as an antenna-integrated radio, or may not be integrated with an antenna as an antenna-integrated radio. Part of a distributed radio base station may also be referred to as a node in a distributed antenna system (DAS). Still other examples of network nodes include multi-standard radio (MSR) equipment (e.g., MSRBS), a network controller (e.g., a radio network controller (RNC) or a base station controller (BSC)), a base transceiver station (BTS), a transmission point, a transmission node, a multi-cell / multicast coordination entity (MCE), a core network node (e.g., MSC, MME), an O&M node, an OSS node, a SON node, a positioning node (e.g., E-SMLC) and / or an MDT. As another example, a network node may be a virtual network node, as described in more detail below. However, more generally, a network node may represent any suitable device (or group of devices) that is capable of, configured, arranged and / or operable to implement and / or provide access to a wireless communication network for a wireless device, or to provide a service to a wireless device that has accessed the wireless network.
[0154] exist Figure 13 In FIG. 4 , the network node 4160 includes a processing circuit 4170, a device-readable medium 4180, an interface 4190, an auxiliary device 4184, a power supply 4186, a power supply circuit 4187, and an antenna 4162. Figure 13The network node 4160 shown in the exemplary wireless network of the present invention can represent a device that includes a combination of the hardware components shown, but other embodiments can include network nodes with different combinations of components. It should be understood that the network node includes any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. In addition, although the components of the network node 4160 are depicted as a single box within a larger box, or nested within multiple boxes, in reality, the network node can include multiple different physical components that make up a single illustrated component (for example, the device readable medium 4180 can include multiple separate hard drives and multiple RAM modules).
[0155] Similarly, network node 4160 may be comprised of multiple physically separate components (e.g., a Node B component and an RNC component, a BTS component and a BSC component, etc.), each of which may have its own corresponding components. In certain scenarios where network node 4160 includes multiple separate components (e.g., a BTS and a BSC component), one or more of the separate components may be shared across multiple network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair may be considered a single, separate network node in some cases. In some embodiments, network node 4160 may be configured to support multiple radio access technologies (RATs). In such an embodiment, some components may be replicated (e.g., separate device-readable media 4180 for different RATs), and some components may be reused (e.g., the same antenna 4162 may be shared by all RATs). Network node 4160 may also include multiple sets of the various components shown for different wireless technologies (e.g., GSM, WCDMA, LTE, NR, WiFi, or Bluetooth wireless technologies) integrated into network node 4160. These wireless technologies may be integrated into the same or different chips or chipsets and other components within network node 4160 .
[0156] The processing circuitry 4170 is configured to perform any determinations, calculations, or similar operations (e.g., certain obtaining operations) described herein as being provided by the network node. These operations performed by the processing circuitry 4170 may include processing information obtained by the processing circuitry 4170, for example, by converting the obtained information into other information, comparing the obtained information or the converted information with information stored in the network node, and / or performing one or more operations based on the obtained information or the converted information and making a determination based on the results of the processing.
[0157] Processor circuit 4170 may include one or more combinations of the following: a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or encoded logic, which is operable to provide network node 4160 functionality, either alone or in conjunction with other network node 4160 components (e.g., device-readable medium 4180). For example, processing circuit 4170 may execute instructions stored in device-readable medium 4180 or in memory within processing circuit 4170. Such functionality may include providing any of the various wireless features, functions, or benefits discussed herein. In some embodiments, processing circuit 4170 may include a system on a chip (SOC).
[0158] In some embodiments, processing circuitry 4170 may include one or more of radio frequency (RF) transceiver circuitry 4172 and baseband processing circuitry 4174. In some embodiments, radio frequency (RF) transceiver circuitry 4172 and baseband processing circuitry 4174 may be on separate chips (or chipsets), boards, or units (e.g., a radio unit and a digital unit). In alternative embodiments, some or all of RF transceiver circuitry 4172 and baseband processing circuitry 4174 may be on the same chip, chipset, board, or unit.
[0159] In certain embodiments, some or all of the functionality described herein as being provided by a network node, base station, eNB, or other such network device may be performed by processing circuitry 4170 executing instructions stored on device-readable medium 4180 or memory within processing circuitry 4170. In alternative embodiments, some or all of the functionality may be provided by processing circuitry 4170, for example, in a hardwired manner, without executing instructions stored on a separate or discrete device-readable medium. In any of these embodiments, processing circuitry 4170 may be configured to perform the described functionality, regardless of whether or not executing instructions stored on a device-readable storage medium. The benefits provided by such functionality are not limited to processing circuitry 4170 or to other components of network node 4160, but are enjoyed by network node 4160 as a whole and / or generally by end users and the wireless network.
[0160] Device-readable medium 4180 may include any form of volatile or non-volatile computer-readable memory, including, but not limited to, permanent storage devices, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., a hard disk), removable storage media (e.g., a flash drive, a compact disk (CD), or a digital video disk (DVD)), and / or any other volatile memory or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that can be used by processing circuitry 4170. Device-readable medium 4180 may store any suitable instructions, data, or information, including computer programs, software, applications including one or more of logic, rules, code, tables, and / or other instructions that can be executed by processing circuitry 4170 and used by network node 4160. Device-readable medium 4180 may be used to store any computations performed by processing circuitry 4170 and / or any data received via interface 4190. In some embodiments, the processing circuitry 4170 and the device-readable medium 4180 may be considered integrated.
[0161] Interface 4190 is used for wired or wireless communication of signaling and / or data between network node 4160, network 4106, and / or WD 4110. As shown, interface 4190 includes port / terminal 4194 for sending and receiving data to and from network 4106, for example, via a wired connection. Interface 4190 also includes radio front-end circuitry 4192, which can be coupled to antenna 4162 or, in some embodiments, be part of antenna 4162. Radio front-end circuitry 4192 includes filter 4198 and amplifier 4196. Radio front-end circuitry 4192 can be connected to antenna 4162 and processing circuitry 4170. Radio front-end circuitry can be configured to condition signals communicated between antenna 4162 and processing circuitry 4170. Radio front-end circuitry 4192 can receive digital data, which is then transmitted to other network nodes or WDs via a wireless connection. Radio front-end circuitry 4192 can use a combination of filters 4198 and / or amplifiers 4196 to convert digital data into a radio signal with appropriate channel and bandwidth parameters. The radio signal can then be transmitted via antenna 4162. Similarly, when receiving data, antenna 4162 can collect the radio signal, which is then converted into digital data by radio front-end circuitry 4192. The digital data can be passed to processing circuitry 4170. In other embodiments, the interface may include different components and / or different combinations of components.
[0162] In certain alternative embodiments, the network node 4160 may not include a separate radio front end circuitry 4192, and alternatively, the processing circuitry 4170 may include the radio front end circuitry and may be connected to the antenna 4162 without the need for a separate radio front end circuitry 4192. Similarly, in some embodiments, all or some of the RF transceiver circuitry 4172 may be considered part of the interface 4190. In other embodiments, the interface 4190 may include one or more ports or terminals 4194, the radio front end circuitry 4192, and the RF transceiver circuitry 4172 as part of a radio unit (not shown), and the interface 4190 may communicate with the baseband processing circuitry 4174, which is part of a digital unit (not shown).
[0163] Antenna 4162 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals. Antenna 4162 may be coupled to radio front-end circuitry 4192 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, antenna 4162 may include one or more omnidirectional, sectored, or planar antennas operable to transmit / receive radio signals between, for example, 2 GHz and 66 GHz. Omnidirectional antennas may be used to transmit / receive radio signals in any direction, sectored antennas may be used to transmit / receive radio signals relative to devices within a specific area, and panel antennas may be line-of-sight antennas for transmitting / receiving radio signals in a relatively straight line. In some cases, using more than one antenna may be referred to as MIMO. In some embodiments, antenna 4162 may be separate from network node 4160 and may be connected to network node 4160 via an interface or port.
[0164] Antenna 4162, interface 4190 and / or processing circuit 4170 can be configured to perform any receiving operation and / or certain obtaining operations described herein as being performed by a network node. Any information, data and / or signal can be received from a wireless device, another network node and / or any other network device. Similarly, antenna 4162, interface 4190 and / or processing circuit 4170 can be configured to perform any transmitting operation described herein as being performed by a network node. Any information, data and / or signal can be sent to a wireless device, another network node and / or any other network device.
[0165] Power circuit 4187 may include or be coupled to power management circuitry and is configured to provide power to the components of network node 4160 for performing the functions described herein. Power circuit 4187 may receive power from power source 4186. Power source 4186 and / or power circuit 4187 may be configured to provide power to the various components of network node 4160 in a form appropriate for each component (e.g., at the voltage and current levels required by each respective component). Power source 4186 may be included in power circuit 4187 and / or network node 4160 or external to it. For example, network node 4160 may be connected to an external power source (e.g., a power outlet) via an input circuit or interface such as a cable, where the external power source provides power to power circuit 4187. As another example, power supply 4186 may include a power source in the form of a battery or battery pack connected to or integrated into power circuit 4187. The battery may provide backup power if the external power source fails. Other types of power sources, such as photovoltaic devices, may also be used.
[0166] Alternative embodiments of network node 4160 may include beyond Figure 13 , which additional components may be responsible for providing certain aspects of the functionality of the network node (including any of the functionality described herein and / or any functionality required to support the subject matter described herein). For example, the network node 4160 may include a user interface device to allow information to be input into the network node 4160 and to allow information to be output from the network node 4160. This may allow a user to perform diagnostic, maintenance, repair, and other management functions with respect to the network node 4160.
[0167] As used herein, a wireless device (WD) refers to a device that is capable of, configured, arranged, and / or operable to communicate wirelessly with a network node and / or other wireless devices. Unless otherwise specified, the term WD is used interchangeably with user equipment (UE) in this article. Wireless communication can include using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for sending information through the air to send and / or receive wireless signals. In some embodiments, a WD can be configured to send and / or receive information without direct human interaction. For example, a WD can be designed to send information to the network in a predetermined schedule when triggered by an internal or external event, or in response to a request from the network. Examples of WD include, but are not limited to, smartphones, mobile phones, cellular phones, voice over IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, game consoles or devices, music storage devices, playback devices, wearable terminal devices, wireless endpoints, mobile stations, tablet computers, laptop computers, laptop embedded devices (LEEs), laptop mounted devices (LMEs), smart devices, wireless client equipment (CPEs), vehicle-mounted wireless terminal devices, etc. A WD can, for example, support device-to-device (D2D) communication, vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, and vehicle-to-everything (V2X) communication by implementing 3GPP standards for sidelink communication, and in this case can be referred to as a D2D communication device. As another specific example, in an Internet of Things (IoT) scenario, a UE can represent a machine or other device that performs monitoring and / or measurement and transmits the results of such monitoring and / or measurement to another UE and / or network node. In this case, the WD can be a machine-to-machine (M2M) device, which in the 3GPP context can be referred to as an MTC device. As a specific example, a WD can be a UE that implements the 3GPP Narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (e.g., power meters), industrial machines, or household or personal appliances (e.g., refrigerators, televisions, etc.), personal wearable devices (e.g., watches, fitness trackers, etc.). In other scenarios, a UE can represent a vehicle or other device capable of monitoring and / or reporting its operating status or other functions associated with its operation. As described above, WD may represent an endpoint of a wireless connection, in which case the device may be referred to as a wireless terminal. In addition, as described above, UE may be mobile, in which case it may also be referred to as a mobile device or mobile terminal.
[0168] As shown, wireless device 4110 includes antenna 4111, interface 4114, processing circuitry 4120, device-readable medium 4130, user interface device 4132, auxiliary device 4134, power supply 4136, and power supply circuitry 4137. WD 4110 may include multiple sets of one or more of the components shown for different wireless technologies supported by WD 4110 (e.g., GSM, WCDMA, LTE, NR, WiFi, WiMAX, or Bluetooth wireless technologies, to name a few). These wireless technologies may be integrated into the same or different chips or chipsets as the other components within WD 4110.
[0169] Antenna 4111 may include one or more antennas or antenna arrays configured to send and / or receive wireless signals and connected to interface 4114. In certain alternative embodiments, antenna 4111 may be separate from WD 4110 and may be connected to WD 4110 via an interface or port. Antenna 4111, interface 4114, and / or processing circuit 4120 may be configured to perform any receive or transmit operation described herein as being performed by a WD. Any information, data, and / or signal may be received from a network node and / or another WD. In some embodiments, the radio front-end circuit and / or antenna 4111 may be considered an interface.
[0170] As shown, interface 4114 includes radio front-end circuitry 4112 and antenna 4111. Radio front-end circuitry 4112 includes one or more filters 4118 and amplifier 4116. Radio front-end circuitry 4112 is connected to antenna 4111 and processing circuitry 4120 and is configured to condition signals communicated between antenna 4111 and processing circuitry 4120. Radio front-end circuitry 4112 may be coupled to antenna 4111 or be part of antenna 4111. In some embodiments, WD 4110 may not include a separate radio front-end circuitry 4112; instead, processing circuitry 4120 may include the radio front-end circuitry and be connected to antenna 4111. Similarly, in some embodiments, some or all of RF transceiver circuitry 4122 may be considered part of interface 4114. Radio front-end circuitry 4112 may receive digital data, which will be transmitted over a wireless connection to other network nodes or WDs. The radio front-end circuit 4112 can use a combination of filters 4118 and / or amplifiers 4116 to convert the digital data into a radio signal with appropriate channel and bandwidth parameters. The radio signal can then be transmitted via antenna 4111. Similarly, when receiving data, the antenna 4111 can collect the radio signal, which is then converted into digital data by the radio front-end circuit 4112. The digital data can be passed to the processing circuit 4120. In other embodiments, the interface may include different components and / or different combinations of components.
[0171] The processor circuit 4120 may include a combination of one or more of the following: a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or encoded logic that is operable to provide WD 4110 functionality alone or in conjunction with other WD 4110 components (e.g., device-readable medium 4130). Such functionality may include providing any of the various wireless features or benefits discussed herein. For example, the processing circuit 4120 may execute instructions stored in the device-readable medium 4130 or in a memory within the processing circuit 4120 to provide the functionality disclosed herein.
[0172] As shown, processing circuitry 4120 includes one or more of RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126. In other embodiments, the processing circuitry may include different components and / or different combinations of components. In some embodiments, processing circuitry 4120 of WD 4110 may include an SOC. In some embodiments, RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126 may be on separate chips or chipsets. In alternative embodiments, part or all of baseband processing circuitry 4124 and application processing circuitry 4126 may be combined into one chip or chipset, and RF transceiver circuitry 4122 may be on a separate chip or chipset. In yet another alternative embodiment, part or all of RF transceiver circuitry 4122 and baseband processing circuitry 4124 may be on the same chip or chipset, and application processing circuitry 4126 may be on a separate chip or chipset. In other alternative embodiments, part or all of RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126 may be combined in the same chip or chipset. In some embodiments, RF transceiver circuitry 4122 may be part of interface 4114. RF transceiver circuitry 4122 may condition RF signals for processing circuitry 4120.
[0173] In some embodiments, some or all of the functions described herein as being performed by the WD may be provided by a processing circuit 4120 executing instructions stored on a device-readable medium 4130, which in some embodiments may be a computer-readable storage medium. In alternative embodiments, some or all of the functions may be provided by the processing circuit 4120, for example, in a hardwired manner, without executing instructions stored on a separate or discrete device-readable storage medium. In any of those specific embodiments, the processing circuit 4120 may be configured to perform the described functions regardless of whether instructions stored on a device-readable storage medium are executed. The benefits provided by such functionality are not limited to the processing circuit 4120 or to other components of the WD 4110, but are enjoyed by the WD 4110 as a whole and / or generally by the end user and the wireless network.
[0174] The processing circuitry 4120 may be configured to perform any determinations, calculations, or similar operations (e.g., certain obtaining operations) described herein as being performed by the WD. These operations performed by the processing circuitry 4120 may include information obtained by the processing circuitry 4120 through, for example, processing the obtained information into other information, comparing the obtained information or the converted information with information stored by the WD 4110, and / or performing one or more operations based on the obtained information or the converted information and making determinations based on the results of the processing.
[0175] The device-readable medium 4130 is operable to store computer programs, software, applications including one or more of logic, rules, code, tables, etc., and / or other instructions that can be executed by the processing circuit 4120. The device-readable medium 4130 may include computer memory (e.g., random access memory (RAM) or read-only memory (ROM)), mass storage media (e.g., a hard disk), removable storage media (e.g., a compact disk (CD) or digital video disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data and / or instructions that can be used by the processing circuit 4120. In some embodiments, the processing circuit 4120 and the device-readable medium 4130 may be considered to be integrated.
[0176] User interface device 4132 may provide components that allow a human user to interact with WD 4110. This interaction can take various forms, such as visual, auditory, tactile, and the like. User interface device 4132 is operable to generate output to the user and allow the user to provide input to WD 4110. The type of interaction may vary depending on the type of user interface device 4132 installed in WD 4110. For example, if WD 4110 is a smartphone, interaction may occur via a touchscreen; if WD 4110 is a smart meter, interaction may occur via a screen that displays usage information (e.g., the number of gallons used) or a speaker that provides an audible alarm (e.g., if smoke is detected). User interface device 4132 may include input interfaces, devices, and circuitry, as well as output interfaces, devices, and circuitry. User interface device 4132 is configured to allow information to be input into WD 4110 and is connected to processing circuitry 4120 to allow processing circuitry 4120 to process the input information. User interface device 4132 may include, for example, a microphone, proximity or other sensors, keys / buttons, a touch display, one or more cameras, a USB port, or other input circuitry. The user interface device 4132 is also configured to allow information to be output from the WD 4110 and to allow the processing circuit 4120 to output information from the WD 4110. The user interface device 4132 may include, for example, a speaker, a display, a vibration circuit, a USB port, a headphone jack, or other output circuitry. By using one or more input and output interfaces, devices, and circuits of the user interface device 4132, the WD 4110 may communicate with an end user and / or wireless network and allow them to benefit from the functionality described herein.
[0177] Auxiliary device 4134 is operable to provide more specific functionality that might not typically be performed by a WD. This may include specialized sensors for taking measurements for various purposes, interfaces for additional types of communication such as wired communication, etc. The inclusion and types of components of auxiliary device 4134 may vary depending on the embodiment and / or scenario.
[0178] In some embodiments, power source 4136 may be in the form of a battery or battery pack. Other types of power sources may also be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a battery cell. WD 4110 may also include power circuitry 4137 for delivering power from power source 4136 to various components of WD 4110. WD 4110 requires power from power source 4136 to perform any functions described or indicated herein. In some embodiments, power circuitry 4137 may include power management circuitry. Power circuitry 4137 may additionally or alternatively be operable to receive power from an external power source; in this case, WD 4110 may be connected to the external power source (e.g., an electrical outlet) via input circuitry or an interface such as a power cable. In some embodiments, power circuitry 4137 may also be operable to deliver power from the external power source to power source 4136. This may be used, for example, to charge power source 4136. Power circuitry 4137 may perform any formatting, conversion, or other modifications to the power from power source 4136 to make it suitable for the various components of WD 4110 being powered.
[0179] Figure 14 A user equipment according to some embodiments is shown.
[0180] Figure 14 An embodiment of a UE according to various aspects described herein is shown. As used herein, a "user equipment" or "UE" may not necessarily have a "user" in the sense of a human user who owns and / or operates the associated equipment. Alternatively, a UE may represent a device that is intended to be sold to or operated by a human user but may not be, or may not initially be, associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended to be sold to or operated by an end user but may be associated with or operated for the benefit of a user (e.g., a smart power meter). UE 4200 may be any UE identified by the 3rd Generation Partnership Project (3GPP), including an NB-IoT UE, a Machine Type Communication (MTC) UE, and / or an enhanced MTC (eMTC) UE. As Figure 14 As shown, UE 4200 is an example of a WD configured for communication according to one or more communication standards promulgated by the Third Generation Partnership Project (3GPP), such as 3GPP's GSM, UMTS, LTE, and / or 5G standards. As previously mentioned, the terms WD and UE may be used interchangeably. Therefore, although Figure 14 It is UE, but the components discussed in this article are also applicable to WD and vice versa.
[0181] exist Figure 14In the embodiment, UE 4200 includes a processing circuit 4201, which is operatively coupled to an input / output interface 4205, a radio frequency (RF) interface 4209, a network connection interface 4211, a memory 4215 including a random access memory (RAM) 4217, a read-only memory (ROM) 4219, and a storage medium 4221, a communication subsystem 4231, a power supply 4213, and / or any other components, or any combination thereof. The storage medium 4221 includes an operating system 4223, an application 4225, and data 4227. In other embodiments, the storage medium 4221 may include other similar types of information. Some UEs may use Figure 14 All of the components shown in the , or only a subset of the components may be used. The level of integration between components may vary from one UE to another. In addition, some UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0182] exist Figure 14 , processing circuitry 4201 may be configured to process computer instructions and data. Processor 4201 may be configured to execute any sequential state machine of machine instructions stored as a machine-readable computer program in memory, such as one or more hardware-implemented state machines (e.g., in discrete logic, FPGAs, ASICs, etc.); programmable logic and suitable firmware; one or more stored programs, general-purpose processors (such as microprocessors or digital signal processors (DSPs)) and suitable software; or any combination thereof. For example, processing circuitry 4201 may include two central processing units (CPUs). Data may be information in a form suitable for use by a computer.
[0183] In the depicted embodiment, the input / output interface 4205 can be configured to provide a communication interface to an input device, an output device, or both. The UE 4200 can be configured to use an output device via the input / output interface 4205. The output device can use the same type of interface port as the input device. For example, a USB port can be used to provide input to and output from the UE 4200. The output device can be a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, a transmitter, a smart card, another output device, or any combination thereof. The UE 4200 can be configured to use an input device via the input / output interface 4205 to allow a user to capture information into the UE 4200. The input device can include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a webcam, etc.), a microphone, a sensor, a mouse, a trackball, a directional keyboard, a trackpad, a scroll wheel, a smart card, etc. The presence-sensitive display can include a capacitive or resistive touch sensor to sense input from the user. The sensor can be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, another type of sensor, or any combination thereof. For example, the input device can be an accelerometer, a magnetometer, a digital camera, a microphone, and an optical sensor.
[0184] exist Figure 14 In the embodiment of the present invention, the RF interface 4209 can be configured to provide a communication interface to RF components such as transmitters, receivers and antennas. The network connection port 4211 can be configured to provide a communication interface to the network 4243a. The network 4243a can include a wired and / or wireless network, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network or any combination thereof. For example, the network 4243a can include a Wi-Fi network. The network connection interface 4211 can be configured to include a receiver and a transmitter interface for communicating with one or more other devices through a communication network according to one or more communication protocols (e.g., Ethernet, TCP / IP, SONET, ATM, etc.). The network connection interface 4211 can implement receiver and transmitter functions suitable for a communication network link (e.g., optical, electrical, etc.). The transmitter and receiver functions can share circuit components, software, or alternatively can be implemented separately.
[0185] RAM 4217 can be configured to interface with processing circuit 4201 via bus 4202 to provide storage or caching of data or computer instructions during the execution of software programs such as operating systems, applications, and device drivers. ROM 4219 can be configured to provide computer instructions or data to processing circuit 4201. For example, ROM 4219 can be configured to store unchanged low-level system code or data for basic system functions, such as basic input and output (I / O) stored in non-volatile memory, booting, or receiving keystrokes from a keyboard. Storage medium 4221 can be configured to include memory, such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, floppy disk, hard disk, removable tape, or flash drive. In an example, storage medium 4221 can be configured to include an operating system 4223, an application 4225 such as a web browser application, a widget or gadget engine or another application, and data files 4227. The storage medium 4221 may store any one or a combination of various operating systems for use by the UE 4200 .
[0186] Storage medium 4221 can be configured to include multiple physical drive units, such as a redundant array of independent disks (RAID), a floppy disk drive, a flash memory, a USB flash drive, an external hard drive, a thumb drive, a pen drive, a key drive, a high-density digital versatile disc (HD-DVD) optical drive, an internal hard drive, a Blu-ray disc drive, a holographic digital data storage (HDDS) optical drive, an external mini dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), an external micro-DIMM SDRAM, a smart card memory such as a subscriber identity module or a removable user identity (SIM / RUIM) module, other memory, or any combination thereof. Storage medium 4221 can allow UE 4200 to access computer-executable instructions, applications, etc. stored on a temporary or non-temporary storage medium to download or upload data. An article of manufacture, such as an article utilizing a communication system, can be tangibly embodied in storage medium 4221, which can include device-readable media.
[0187] exist Figure 14In the embodiment, the processing circuit 4201 can be configured to communicate with the network 4243b using the communication subsystem 4231. The network 4243a and the network 4243b can be one or more identical networks or one or more different networks. The communication subsystem 4231 can be configured to include one or more transceivers for communicating with the network 4243b. For example, the communication subsystem 4231 can be configured to include one or more transceivers for communicating with another device (e.g., another WD, UE) capable of wireless communication or one or more remote transceivers of a base station of a radio access network (RAN) according to one or more communication protocols (e.g., IEEE 802.11, CDMA, WCDMA, GSM, LTE, UTRAN, WiMax, etc.). Each transceiver can include a transmitter 4233 and / or a receiver 4235 to respectively implement transmitter or receiver functions suitable for a RAN link (e.g., frequency allocation, etc.). In addition, the transmitter 4233 and receiver 4235 of each transceiver can share circuit components, software, or firmware, or can be implemented separately.
[0188] In the illustrated embodiment, the communication functions of the communication subsystem 4231 may include data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication (such as use of a global positioning system (GPS) for determining location), another type of communication function, or any combination thereof. For example, the communication subsystem 4231 may include cellular communication, Wi-Fi communication, Bluetooth communication, and GPS communication. The network 4243b may include a wired and / or wireless network, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network, or any combination thereof. For example, the network 4243b may be a cellular network, a Wi-Fi network, and / or a near-field network. The power supply 4213 may be configured to provide alternating current (AC) or direct current (DC) power to the components of the UE 4200.
[0189] The features, benefits, and / or functionality described herein may be implemented in one of the components of UE 4200, or divided among multiple components of UE 4200. Furthermore, the features, benefits, and / or functionality described herein may be implemented in any combination of hardware, software, or firmware. In one example, the communication subsystem 4231 may be configured to include any of the components described herein. Furthermore, the processing circuit 4201 may be configured to communicate with any such component via bus 4202. In another example, any such component may be represented by program instructions stored in a memory that, when executed by the processing circuit 4201, perform the corresponding functions described herein. In another example, the functionality of any such component may be divided between the processing circuit 4201 and the communication subsystem 4231. In another example, the non-computationally intensive functions of any such component may be implemented in software or firmware, and the computationally intensive functions may be implemented in hardware.
[0190] Figure 15 A virtualized environment is shown in accordance with some embodiments.
[0191] Figure 15 is a schematic block diagram illustrating a virtualization environment 4300 in which functionality implemented by some embodiments may be virtualized. In this context, virtualization means creating a virtual version of an apparatus or device that may include virtualized hardware platforms, storage devices, and network resources. As used herein, virtualization may be applied to a node (e.g., a virtualized base station or a virtualized radio access node) or a device (e.g., a UE, a wireless device, or any other type of communication device) or a component thereof, and relates to an implementation in which at least some portion of functionality is implemented as one or more virtual components (e.g., via one or more applications, components, functions, virtual machines, or containers executing on one or more physical processing nodes in one or more networks).
[0192] In some embodiments, some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines implemented in one or more virtual environments 4300 hosted by one or more hardware nodes 4330. Furthermore, in embodiments where the virtual nodes are not radio access nodes or do not require radio connectivity (e.g., core network nodes), the network nodes may then be fully virtualized.
[0193] These functions may be implemented by one or more applications 4320 (which may alternatively be referred to as software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.), which are operable to implement some of the features, functions, and / or benefits of some embodiments disclosed herein. Applications 4320 operate in a virtualized environment 4300, which provides hardware 4330 including processing circuitry 4360 and memory 4390. Memory 4390 contains instructions 4395 executable by processing circuitry 4360, whereby applications 4320 are operable to provide one or more of the features, benefits, and / or functions disclosed herein.
[0194] The virtualized environment 4300 includes general-purpose or specialized network hardware devices 4330, which include a set of one or more processors or processing circuits 4360, which can be commercial off-the-shelf (COTS) processors, application-specific integrated circuits (ASICs), or any other type of processing circuitry including digital or analog hardware components or specialized processors. Each hardware device can include memory 4390-1, which can be non-persistent memory for temporarily storing instructions 4395 or software executed by the processing circuits 4360. Each hardware device can include one or more network interface controllers (NICs) 4370 (also known as network interface cards), which include physical network interfaces 4380. Each hardware device can also include non-transitory, permanent, machine-readable storage media 4390-2 having stored therein software 4395 and / or instructions executable by the processing circuits 4360. The software 4395 can include any type of software, including software for instantiating one or more virtualization layers 4350 (also known as hypervisors), software for executing virtual machines 4340, and software that enables them to perform the functions, features, and / or benefits described in connection with some embodiments described herein.
[0195] The virtual machines 4340 include virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and can be run by corresponding virtualization layers 4350 or hypervisors. Different embodiments of instances of the virtual devices 4320 can be implemented on one or more of the virtual machines 4340, and the implementation can be done in different ways.
[0196] During operation, processing circuitry 4360 executes software 4395 to instantiate a hypervisor or virtualization layer 4350 , which may sometimes be referred to as a virtual machine monitor (VMM). Virtualization layer 4350 may present a virtual operating platform that appears to the networked hardware of virtual machine 4340 .
[0197] like Figure 15As shown, hardware 4330 can be a standalone network node with common or specific components. Hardware 4330 can include antenna 43225 and can implement some functions via virtualization. Alternatively, hardware 4330 can be part of a larger hardware cluster (e.g., in a data center or customer premises equipment (CPE)), where many hardware nodes work together and are managed by management and coordination (MANO) 43100, which oversees, among other things, the lifecycle management of application 4320.
[0198] In some contexts, hardware virtualization is referred to as network function virtualization (NFV). NFV can be used to unify numerous network device types onto industry-standard high-capacity server hardware, physical switches, and physical storage that can be located in data centers and customer premises equipment (CPE).
[0199] In the context of NFV, a virtual machine 4340 can be a software implementation of a physical machine that runs programs as if they were executed on a physical, non-virtualized machine. Each virtual machine 4340 and the portion of hardware 4330 that executes it (whether dedicated to that virtual machine and / or shared with other virtual machines in virtual machines 4340) form a separate virtual network element (VNE).
[0200] Still in the context of NFV, a virtual network function (VNF) is responsible for handling operations in one or more virtual machines 4340 on top of the hardware network infrastructure 4330 and corresponds to Figure 15 Specific network functionality of application 4320.
[0201] In some embodiments, one or more radio units 43200, each including one or more transmitters 43220 and one or more receivers 43210, may be coupled to one or more antennas 43225. The radio units 43200 may communicate directly with the hardware nodes 4330 via one or more suitable network interfaces, and may be used in conjunction with virtual components to provide radio capabilities to virtual nodes, such as radio access nodes or base stations.
[0202] In some embodiments, some signaling may be implemented using a control system 43230 , which may alternatively be used for communications between the hardware node 4330 and the radio unit 43200 .
[0203] Figure 16 shows a telecommunications network connected to a host computer via an intermediary network according to some embodiments;
[0204] refer to Figure 16According to an embodiment, a communication system includes a telecommunications network 4410 (e.g., a 3GPP-type cellular network), which includes an access network 4411 (e.g., a wireless access network) and a core network 4414. The access network 4411 includes a plurality of base stations 4412a, 4412b, 4412c, such as NBs, eNBs, gNBs, or other types of wireless access points, each of which defines a corresponding coverage area 4413a, 4413b, 4413c. Each base station 4412a, 4412b, 4412c can be connected to the core network 4414 via a wired or wireless connection 4415. A first UE 4491 located in the coverage area 4413c is configured to wirelessly connect to or be paged by the corresponding base station 4412c. A second UE 4492 in the coverage area 4413a can wirelessly connect to the corresponding base station 4412a. Although multiple UEs 4491, 4492 are shown in this example, the disclosed embodiments are equally applicable to situations where only one UE is located in the coverage area or only one UE is connected to the corresponding base station 4412.
[0205] Telecommunications network 4410 itself is connected to a host computer 4430, which can be embodied in the hardware and / or software of a standalone server, a cloud-enabled server, a distributed server, or as processing resources in a server farm. Host computer 4430 can be owned or controlled by a service provider, or operated by or on behalf of a service provider. Connections 4421, 4422 between telecommunications network 4410 and host computer 4430 can extend directly from core network 4414 to host computer 4430, or can pass through an optional intermediate network 4420. Intermediate network 4420 can be one or a combination of public, private, or managed networks; if present, intermediate network 4420 can be a backbone network or the Internet; specifically, intermediate network 4420 can include two or more subnetworks (not shown).
[0206] Figure 16The communication system in FIG. 44 as a whole enables connectivity between connected UEs 4491, 4492 and a host computer 4430. This connection can be described as an over-the-top (OTT) connection 4450. The host computer 4430 and the connected UEs 4491, 4492 are configured to communicate data and / or signaling via the OTT connection 4450 using the access network 4411, the core network 4414, any intermediate networks 4420, and possibly other intermediate infrastructure (not shown). The OTT connection 4450 can be transparent in the sense that the participating communication devices through which it passes are unaware of the routing of uplink and downlink communications. For example, the base station 4412 may not be informed or need not be informed of the past routing of incoming downlink communications having data originating from the host computer 4430 and to be forwarded (e.g., handed over) to the connected UE 4491. Similarly, the base station 4412 does not need to be aware of the future routing of outgoing uplink communications originating from the UE 4491 and destined for the host computer 4430.
[0207] Figure 17 A host computer is shown communicating with a user device via a base station over a partially wireless connection in accordance with some embodiments.
[0208] Now refer to Figure 17 Describe the example implementation of the UE, base station and host computer according to the embodiment discussed in the previous paragraph. In the communication system 4500, the host computer 4510 includes hardware 4515, which includes a communication interface 4516, which is configured to establish and maintain a wired or wireless connection with the interface of different communication devices of the communication system 4500. The host computer 4510 also includes a processing circuit 4518, which may have storage and / or processing capabilities. Specifically, the processing circuit 4518 may include one or more programmable processors, application-specific integrated circuits, field programmable gate arrays, or a combination of such devices (not shown) suitable for executing instructions. The host computer 4510 also includes software 4511, which is stored in or accessible by the host computer 4510 and can be executed by the processing circuit 4518. The software 4511 includes a host application 4512. The host application 4512 may be operated to provide services to a remote user, such as a UE 4530 connected via an OTT connection 4550 that terminates at the UE 4530 and the host computer 4510. In providing services to the remote user, the host application 4512 may provide user data sent using the OTT connection 4550.
[0209] The communication system 4500 also includes a base station 4520 provided in the telecommunication system, the base station 4520 including hardware 4525 that enables it to communicate with the host computer 4510 and the UE 4530. The hardware 4525 may include: a communication interface 4526 for establishing and maintaining a wired or wireless connection between interfaces of different communication devices of the communication system 4500; and a radio interface 4527 for establishing and maintaining communication with other devices located in the coverage area served by the base station 4520 (in the area covered by the network). Figure 17 The communication interface 4526 may be configured to facilitate a connection 4560 with the host computer 4510. The connection 4560 may be direct, or it may be through a core network (e.g., a telecommunications system) of the telecommunications system. Figure 17 The base station 4520 may also include software 4521, which may be stored internally or accessible via an external connection.
[0210] The communication system 4500 also includes the UE 4530 mentioned above. The hardware 4535 of the UE 4530 may include a radio interface 4537, which is configured to establish and maintain a wireless connection 4570 with a base station serving the coverage area in which the UE 4530 is currently located. The hardware 4535 of the UE 4530 also includes processing circuitry 4538, which may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or a combination of such devices (not shown) adapted to execute instructions. The UE 4530 also includes software 4531, which is stored in or accessible by the UE 4530 and can be executed by the processing circuitry 4538. The software 4531 includes a client application 4532. The client application 4532 can be operated to provide services to human or non-human users via the UE 4530 with the support of the host computer 4510. In host computer 4510, executing host application 4512 can communicate with executing client application 4532 via OTT connection 4550, which terminates at UE 4530 and host computer 4510. When providing services to users, client application 4532 can receive request data from host application 4512 and provide user data in response to the request data. OTT connection 4550 can transmit both the request data and the user data. Client application 4532 can interact with the user to generate the user data it provides.
[0211] Notice, Figure 17The host computer 4510, base station 4520 and UE 4530 shown in FIG can be respectively Figure 16 The host computer 4430, one of the base stations 4412a, 4412b, 4412c, and one of the UEs 4491, 4492 in FIG. 4430 are similar or identical. That is, the internal workings of these entities may be similar to or identical to those of FIG. Figure 17 shown, and independently, the surrounding network topology can be Figure 16 network topology.
[0212] exist Figure 17 In FIG4 , an OTT connection 4550 is abstractly depicted to illustrate communication between a host computer 4510 and a UE 4530 via a base station 4520, without explicitly mentioning any intermediate devices or the precise routing of messages through these devices. The network infrastructure can determine the routing, which can be configured to be hidden from the UE 4530, the service provider operating the host computer 4510, or both. While the OTT connection 4550 is active, the network infrastructure can also make decisions to dynamically change the routing (e.g., based on load balancing considerations or network reconfiguration).
[0213] The wireless connection 4570 between the UE 4530 and the base station 4520 is consistent with the teachings of the embodiments described throughout this disclosure. One or more of the various embodiments can improve the performance of an OTT service provided to the UE 4530 using the OTT connection 4550, of which the wireless connection 4570 forms the final component. More specifically, the teachings of these embodiments can improve random access speeds and / or reduce random access failure rates, thereby providing benefits such as faster and / or more reliable random access.
[0214] A measurement process may be provided for monitoring data rate, latency, and other factors that may be improved in accordance with one or more embodiments. Optional network functionality may also be provided for reconfiguring the OTT connection 4550 between the host computer 4510 and the UE 4530 in response to changes in measurement results. The measurement process and / or network functionality for reconfiguring the OTT connection 4550 may be implemented in the software 4511 and hardware 4515 of the host computer 4510, or in the software 4531 and hardware 4535 of the UE 4530, or in both. In an embodiment, sensors (not shown) may be deployed in or associated with the communication devices through which the OTT connection 4550 passes; the sensors may participate in the measurement process by providing values of the monitored quantities exemplified above, or by providing values of other physical quantities from which the software 4511, 4531 may calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 4550 may include: message format, retransmission settings, preferred routing, etc.; the reconfiguration does not need to affect the base station 4520 and can be unknown or imperceptible to the base station 4520. Such processes and functions may be known and practiced in the art. In certain embodiments, the measurement may involve proprietary UE signaling that facilitates the host computer 4510 to measure throughput, propagation time, latency, etc. The measurement can be achieved by the software 4511 and 4531 using the OTT connection 4550 to send messages (particularly empty messages or "dummy" messages) while monitoring propagation time, errors, etc.
[0215] Figure 18 A method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments is shown.
[0216] Figure 18 The communication system includes a host computer, a base station and a UE, which can be a reference Figures 16 and 17 To simplify this disclosure, only the host computer, base station and UE are described. Figure 18 The reference numerals will be included in this section. In step 4610, the host computer provides user data. In sub-step 4611 of step 4610 (which may be optional), the host computer provides the user data by executing a host application. In step 4620, the host computer initiates a transmission to the UE, which carries the user data. In step 4630 (which may be optional), in accordance with the teachings of the embodiments described throughout this disclosure, the base station sends the user data carried in the transmission initiated by the host computer to the UE. In step 4640 (which may also be optional), the UE executes a client application associated with the host application executed by the host computer.
[0217] Figure 19 A method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments is shown.
[0218] Figure 19 The communication system includes a host computer, a base station and a UE, which can be a reference Figures 16 and 17 To simplify this disclosure, only the host computer, base station and UE are described. Figure 19 The reference numerals will be included in this section. In step 4710 of the method, the host computer provides user data. In an optional sub-step (not shown), the host computer provides the user data by executing a host application. In step 4720, the host computer initiates a transmission to the UE, which carries the user data. According to the teachings of the embodiments described throughout this disclosure, the transmission can be delivered via a base station. In step 4730 (which may be optional), the UE receives the user data carried in the transmission.
[0219] Figure 20 A method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments is shown.
[0220] Figure 20 The communication system includes a host computer, a base station and a UE, which can be a reference Figures 16 and 17 To simplify this disclosure, only the host computer, base station and UE are described. Figure 20 The reference numerals will be included in this section. In step 4810 (which may be optional), the UE receives input data provided by the host computer. Additionally or alternatively, in step 4820, the UE provides user data. In sub-step 4821 of step 4820 (which may be optional), the UE provides user data by executing a client application. In sub-step 4811 of step 4810 (which may be optional), the UE executes a client application that provides user data in response to the received input data provided by the host computer. When providing user data, the executed client application may also take into account user input received from the user. Regardless of the specific manner in which the user data is provided, the UE initiates transmission of the user data to the host computer in sub-step 4830 (which may be optional). In step 4840 of the method, in accordance with the teachings of the embodiments described throughout this disclosure, the host computer receives user data sent from the UE.
[0221] Figure 21 A method implemented in a communication system including a host computer, a base station, and a user equipment according to some embodiments is shown.
[0222] Figure 21 The communication system includes a host computer, a base station and a UE, which can be a reference Figures 16 and 17 To simplify this disclosure, only the host computer, base station and UE are described. Figure 21 Reference numerals will be included in this section. In step 4910 (which may be optional), in accordance with the teachings of the embodiments described throughout this disclosure, the base station receives user data from the UE. In step 4920 (which may be optional), the base station initiates a transmission of the received user data to the host computer. In step 4930 (which may be optional), the host computer receives the user data carried in the transmission initiated by the base station.
[0223] Any suitable steps, methods, features, functions or benefits disclosed herein may be performed by one or more functional units or modules of one or more virtual devices. Each virtual device may include a plurality of these functional units. These functional units may be implemented by processing circuits, which may include one or more microprocessors or microcontrollers and other digital hardware (which may include digital signal processors (DSPs), dedicated digital logic, etc.). The processing circuit may be configured to execute program code stored in a memory, which may include one or more types of memory, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory device, optical storage device, etc. The program code stored in the memory includes program instructions for executing one or more telecommunications and / or data communication protocols and instructions for executing one or more technologies described herein. In some implementations, the processing circuit may be used to cause the corresponding functional unit to perform a corresponding function according to one or an embodiment of the present disclosure.
[0224] The term unit may have a conventional meaning in the field of electronics, electrical devices and / or electronic equipment, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logical solid-state and / or discrete devices, computer programs or instructions for performing various tasks, processes, calculations, output and / or display functions, etc., such as those described herein.
[0225] abbreviation
[0226] At least some of the following abbreviations may be used in this disclosure. If there is an inconsistency between abbreviations, the abbreviation used above shall take precedence. If listed multiple times below, the first listing shall take precedence over any subsequent listings.
[0227] 1x RTT CDMA2000 1x Radio Transmission Technology
[0228] 3GPP Third Generation Partnership Project
[0229] 5G fifth generation
[0230] ABS Almost Blank Subframe
[0231] ARQ Automatic Repeat Request
[0232] AWGN Additive White Gaussian Noise
[0233] BCCH Broadcast Control Channel
[0234] BCH Broadcast Channel
[0235] Carrier Aggregation (CA)
[0236] CC carrier component
[0237] CCCHSDU Common Control Channel SDU
[0238] CDMA Code Division Multiple Access
[0239] CGI Cell Global Identifier
[0240] CIR Channel Impulse Response
[0241] CP Cyclic Prefix
[0242] CPICH Common Pilot Channel
[0243] CPICH Ec / No The energy received by each CPICH chip divided by the power density in the frequency band
[0244] CQI Channel Quality Information
[0245] C-RNTI Cell RNTI
[0246] CSI Channel State Information
[0247] DCCH Dedicated Control Channel
[0248] DL Downlink
[0249] DM demodulation
[0250] DMRS Demodulation Reference Signal
[0251] DRX Discontinuous Reception
[0252] DTX Discontinuous Transmission
[0253] DTCH Dedicated Traffic Channel
[0254] DUT Device Under Test
[0255] E-CID Enhanced Cell ID (positioning method)
[0256] E-SMLC Evolved Service Mobile Location Center ECGI Evolved CGI eNB E-UTRAN Node B EPDCCH Enhanced Physical Downlink Control Channel E-SMLC Evolved Service Mobile Location Center E-UTRA Evolved UTRA E-UTRAN Evolved UTRAN FDD Frequency Division Duplex
[0257] Further research on FFS
[0258] GERN GSM EDGE Radio Access Network Base stations in gNB NR
[0259] GNSS Global Navigation Satellite System GSM Global System for Mobile Communications HARQ Hybrid Automatic Repeat Request HO Handover
[0260] HSPA High Speed Packet Access HRPD High Rate Packet Data LOS line of sight
[0261] LPP LTE Positioning Protocol LTE Long Term Evolution
[0262] MAC Media Access Control MBMS Multimedia Broadcast / Multicast Service MBSFN Multimedia Broadcast Multicast Service Single Frequency Network MBSFN ABS MBSFN Almost Blank Subframe MDT Minimized Drive Test
[0263] MIB Master Information Block
[0264] MME Mobility Management Entity MSC Mobile Switching Center PDCCH Narrowband Physical Downlink Control Channel NR New Radio
[0265] OCNG OFDMA channel noise generator
[0266] OFDM Orthogonal Frequency Division Multiplexing
[0267] OFDMA Orthogonal Frequency Division Multiple Access
[0268] OSS Operation Support System
[0269] OTDOA Observed Time Difference of Arrival
[0270] O&M Operations and Maintenance
[0271] PBCH Physical Broadcast Channel
[0272] P-CCPCH Primary Common Control Physical Channel
[0273] Pcell primary cell
[0274] PCFICH Physical Control Format Indicator Channel
[0275] PDCCH Physical Downlink Control Channel
[0276] PDP Power Delay Profile
[0277] PDSCH Physical Downlink Shared Channel
[0278] PGW Packet Gateway
[0279] PHICH Physical Hybrid ARQ Indicator Channel
[0280] PLMN Public Land Mobile Network
[0281] PMI Precoding Matrix Indicator
[0282] PRACH Physical Random Access Channel
[0283] PRS Positioning Reference Signal
[0284] PSS Primary Synchronization Signal
[0285] PUCCH Physical Uplink Control Channel
[0286] PUSCH Physical Uplink Shared Channel
[0287] PACH Random Access Channel
[0288] QAM Quadrature Amplitude Modulation
[0289] RAN Radio Access Network
[0290] RAT Radio Access Technology
[0291] RLM Radio Link Management
[0292] RNC Radio Network Controller
[0293] RNTI Radio Network Temporary Identifier
[0294] RRC Radio Resource Control
[0295] RRM Radio Resource Management
[0296] RS reference signal
[0297] RSCP Received Signal Code Power
[0298] RSRP Reference Symbol Received Power or Reference Signal Received Power
[0299] RSRQ Reference Signal Received Quality or Reference Symbol Received Quality
[0300] RSSI Received Signal Strength Indicator
[0301] RSTD Reference Signal Time Difference
[0302] SCH Synchronization Channel
[0303] Scell secondary cell
[0304] SDU Service Data Unit
[0305] SFN System Frame Number
[0306] SGW Service Gateway
[0307] SI System Information
[0308] SIB System Information Block
[0309] SNR signal-to-noise ratio
[0310] SON self-optimizing network
[0311] SS synchronization signal
[0312] SSS Secondary synchronization signal
[0313] TDD Time Division Duplex
[0314] TDOA Time Difference of Arrival
[0315] TOA (Time of Arrival)
[0316] TSS three-level synchronization signal
[0317] TTI Transmission Time Interval
[0318] UE User Equipment
[0319] UL Uplink
[0320] UMTS Universal Mobile Telecommunications System
[0321] USIM Universal Subscriber Identity Module
[0322] UTDOA Uplink Time Difference of Arrival
[0323] UTRA Universal Terrestrial Radio Access
[0324] UTRAN Universal Terrestrial Radio Access Network
[0325] WCDMA Wide CDMA
[0326] WLAN Wireless Local Area Network
[0327] Further definitions and examples are discussed below.
[0328] In the above description of various embodiments of the inventive concept, it is to be understood that the terms used herein are only used for the purpose of describing specific embodiments and are not intended to limit the inventive concept. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those of ordinary skill in the art to which the inventive concept belongs. It should also be understood that terms such as those defined in general dictionaries should be interpreted as having a meaning consistent with their meaning in the context of this specification and the relevant art, and not as an ideal or overly superficial meaning, unless so explicitly defined herein.
[0329] When an element is referred to as being "connected," "coupled," "responsive" or variations thereof relative to another element, it may be directly connected, coupled to or responsive to the other element, or there may be intermediate elements. In contrast, when an element is referred to as being "directly connected," "directly coupled," "directly responsive" or variations thereof relative to another element, there are no intermediate elements. Throughout the text, similar reference numerals represent similar elements. In addition, "coupled," "connected," "responsive" or variations thereof used herein may include wireless coupling, connection or response. As used herein, the singular forms "a," "an," and "said" are intended to also include the plural forms, unless the context clearly indicates otherwise. For the sake of brevity and / or clarity, well-known functions or structures may not be described in detail. The term "and / or" (abbreviated as " / ") includes any and all combinations of one or more of the relevant listed items.
[0330] It will be understood that although the terms first, second, third, etc. can be used herein to describe each element / operation, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another element / operation. Therefore, the first element / operation in some embodiments can be referred to as the second element / operation in other embodiments without departing from the teachings of the present invention. Throughout the specification, the same reference numerals or the same reference signs represent the same or similar elements.
[0331] As used herein, the terms "comprise, comprising, comprises, including, includes," "have, has, having," or variations thereof, are open ended and include one or more stated features, integers, elements, steps, components, or functions, but do not preclude the presence or addition of one or more other features, integers, elements, steps, components, functions, or combinations thereof. Furthermore, as used herein, the commonly used abbreviation "eg," derived from the Latin phrase "exempligratia," may be used to introduce or specify a general example of a previously mentioned item without intending to be limiting of that item. The commonly used abbreviation "ie," derived from the Latin phrase "idest," may be used to specify a specific item of a more general recitation.
[0332] Example embodiments are described herein with reference to block diagrams and / or flowchart illustrations of computer-implemented methods, devices (systems and / or equipment), and / or computer program products. It should be understood that the blocks of the block diagrams and / or flowchart illustrations and combinations of blocks in the block diagrams and / or flowchart illustrations can be implemented by computer program instructions executed by one or more computer circuits. These computer program instructions can be provided to a processor circuit of a general-purpose computer circuit, a special-purpose computer circuit, and / or other programmable data processing circuit to produce a machine so that instructions executed by a processor of a computer and / or other programmable data processing device convert and control transistors, values stored in memory locations, and other hardware components within such circuits to implement the functions / actions specified in the block diagrams and / or flowchart illustrations, and thereby create a device (functional body) and / or structure for implementing the functions / actions specified in the block diagrams and / or flowchart illustrations.
[0333] These computer program instructions may also be stored in a tangible computer-readable medium that can direct a computer or other programmable data processing apparatus to function in a specific manner such that the instructions stored in the computer-readable medium produce an article of manufacture comprising instructions for implementing the functions / actions specified in the blocks of the block diagrams and / or flowcharts. Thus, embodiments of the present inventive concept may be implemented in hardware and / or software (including firmware, stored software, microcode, etc.) running on a processor such as a digital signal processor, which may be collectively referred to as a "circuit," "module," or variations thereof.
[0334] It should also be noted that in some alternative implementations, the function / action marked in the frame may not occur in the order marked in the flow chart. For example, depending on the function / action involved, the two frames shown in succession can actually be performed simultaneously, or frames can sometimes be performed in the opposite order. In addition, the function of a given frame of a flow chart and / or block diagram can be divided into multiple frames and / or the function of two or more frames of a flow chart and / or block diagram can be integrated at least in part. Finally, without departing from the scope of the inventive concept, other frames can be added / inserted between the frames shown, and / or frames / operations can be omitted. In addition, although some frames include arrows about the communication path for indicating the main direction of communication, it should be understood that communication can occur in the direction opposite to the arrows represented.
[0335] Without departing substantially from the principles of the present invention, many changes and modifications may be made to the embodiments. All of these changes and modifications are intended to be included within the scope of the present invention herein. Therefore, the above-mentioned subject matter should be understood as illustrative rather than restrictive, and the examples of the embodiments are intended to cover all of these modifications, improvements, and other embodiments that fall within the spirit and scope of the present invention. Therefore, to the maximum extent permitted by law, the scope of the present invention should be determined by the widest permissible interpretation of the present disclosure including the examples of the embodiments and their equivalents, and should not be limited to or restricted to the specific embodiments previously described.
Claims
1. A method of operating a first network node in a first communication network, the method comprising: receiving (1110) a first message from a second network node operating in a second communication network; In response to receiving the first message, determining ( 1120 ) that the second network node is associated with a network operator having a service level agreement (SLA) with a content operator, wherein the content operator is associated with the first network node; as well as A second message is sent (1130) to the second network node, the second message including information related to whether subsequent messages from the communication device associated with the second network node are to be sent to the origin server using an unencrypted Server Name Indication (SNI) according to the Transport Layer Security (TLS) protocol based on the second network node being associated with the network operator having the SLA with the content operator.
2. The method according to claim 1, wherein Determining that the second network node is associated with a network operator having the SLA with the content operator includes: determining an Internet Protocol (IP) address of the second network node; determining that the IP address of the second network node is in a predetermined IP address list provided by the network operator; and Based on the IP address being in the predetermined IP address list, it is determined that the second network node is associated with a network operator having the SLA with the content operator.
3. The method according to any one of claims 1 to 2, wherein The first network node is an authoritative domain name system DNS node, The second network node is a mobile network operator MNO DNS node, wherein the first message is a DNS query, and Sending the second message to the second network node includes sending a DNS query response to the second network node, where the DNS query response indicates that subsequent messages from the communication device associated with the second network node are sent to the source server using unencrypted SNI.
4. The method according to claim 3, wherein: Sending the DNS query response includes sending the DNS query response without a DNS record required for SNI encryption.
5. The method according to any one of claims 1 to 2, wherein The first network node is the source server, wherein the second network node is the communication device, The first message is a request message using an encrypted server name indication (eSNI) according to the Transport Layer Security (TLS) protocol. The sending of the second message to the second network node includes: sending a response message including a uniform resource locator (URL) based on that the second network node is associated with the network operator having the SLA with the content operator.
6. The method according to claim 5, wherein: The URL is a first URL, The response message includes the first URL, an indication of a subscriber policy, and a second URL, and indicates that: in response to the subscriber policy being associated with the communication device, the communication device should use the first URL for subsequent resource requests; and in response to the subscriber policy not being associated with the communication device, the communication device should use the second URL for the subsequent resource requests.
7. The method according to claim 6, wherein: The first URL can be resolved to enable the communication device to send the subsequent resource request using the unencrypted SNI, The second URL can be resolved so that the communication device sends the subsequent resource request using the eSNI.
8. The method according to any one of claims 1 to 2, wherein The first communication network or the second communication network is a fifth generation 5G network.
9. The method according to any one of claims 1 to 2, wherein: The first communication network or the second communication network is a Long Term Evolution (LTE) network.
10. A method of operating a network node in a communication network, the method comprising: receiving ( 1210 ) a request message for a resource associated with an application from a communication device; determining (1220) whether a subscriber policy is associated with the communication device; determining (1230) a uniform resource locator (URL) based on whether the subscriber policy is associated with the communication device; as well as sending (1240) a response message including the URL to the communication device, Wherein, determining the URL includes: determining whether subsequent communications from the communication device should use an encrypted server name indication (eSNI) according to a Transport Layer Security (TLS) protocol based on whether the subscriber policy is associated with the communication device; and The URL is determined based on whether subsequent communications from the communication device should use the eSNI.
11. The method according to claim 10, wherein: Determining whether the subscriber policy is associated with the communication device includes: determining that the subscriber policy is associated with the communication device, The determining of the URL comprises: selecting the URL from a plurality of URLs based on the URL being resolvable so that the communication device sends a subsequent message using an unencrypted SNI.
12. The method according to claim 10, wherein: Determining whether the subscriber policy is associated with the communication device includes: determining that the subscriber policy is not associated with the communication device, The determining of the URL comprises: selecting the URL from a plurality of URLs based on the fact that the URL can be resolved so that the communication device sends a subsequent message using the eSNI.
13. The method according to any one of claims 10 to 12, wherein The request message also includes a first URL, an indication of a subscriber policy, and a second URL, Wherein, determining the URL comprises: selecting the URL from the first URL and the second URL based on whether the subscriber policy is associated with the communication device.
14. The method according to any one of claims 10 to 12, wherein The response message also includes information associated with the subscriber policy.
15. The method according to any one of claims 10 to 12, wherein The communication network is the fifth generation 5G network, The network node is a core network CN node, and the core network CN node includes a user plane function UPF and a mobile network operator MNO domain name system DNS server.
16. The method according to any one of claims 10 to 12, wherein The communication network is a Long Term Evolution (LTE) network.
17. A first network node (900, 1000) in a first communication network, comprising: Processing circuit (903, 1003); as well as A memory (905, 1005) is coupled to the processing circuit and stores instructions, wherein the instructions are executable by the processing circuit to enable the first network node to perform any one of the methods of claims 1-9.
18. A computer program product comprising program code to be executed by a processing circuit (903, 1003) of a first network node (900, 1000) operating in a communication network, whereby execution of the program code causes the first network node to perform any of the methods of claims 1-9.
19. A non-transitory storage medium comprising program code to be executed by a processing circuit (903, 1003) of a first network node (900, 1000) operating in a communication network, whereby execution of the program code causes the first network node to perform any of the methods of claims 1-9.
20. A network node (1000) in a communication network, comprising: Processing circuit (1003); as well as A memory (1005) is coupled to the processing circuit and stores instructions, wherein the instructions are executable by the processing circuit to cause the network node to perform any one of the methods of claims 10-16.
21. A computer program product comprising program code to be executed by a processing circuit (1003) of a network node (1000) operating in a communication network, whereby execution of the program code causes the network node to perform any of the methods of claims 10-16.
22. A non-transitory storage medium comprising program code to be executed by a processing circuit (1003) of a network node (1000) operating in a communication network, whereby execution of the program code causes the network node to perform any of the methods of claims 10-16.
Citation Information
Patent Citations
Identifying a network node to which data will be replicated
CN109496414A
Dynamic resource partitioning for multi-carrier access for 5G or other next generation network
US10425829B1