Inter-PLMN communication

By exchanging domain name information in N32-c handshake signaling, the problem of secure connection between PLMNs is solved, and the flexibility and security improvement of inter-PLMN communication is achieved.

CN116095877BActive Publication Date: 2025-08-22NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211386732.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-11-05
Filing Date
2022-11-07
Publication Date
2025-08-22
Estimated Expiration
2042-11-07

AI Technical Summary

Technical Problem

There is a lack of an effective mechanism in the prior art to associate the N32-c transport layer secure connection between public land mobile networks (PLMNs) with the corresponding N32-f transport layer secure connection, resulting in the inability to effectively enable the renegotiation policy, terminate or identify the connection of a specific PLMN in inter-PLMN communication.

Method used

By exchanging domain name information during N32-c handshake signaling, using fully qualified domain name (FQDN) and server name indication (SNI) to establish and bind secure connection between N32-c and N32-f transport layer to achieve connection relevance.

Benefits of technology

It realizes effective binding of N32-c and N32-f transport layer secure connections between PLMNs, supports the application of renegotiation policies, can terminate or identify connections of specific PLMNs, and improves the flexibility and security of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116095877B_ABST
    Figure CN116095877B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to inter-PLMN communications. A device is disclosed. The device includes means for initiating establishment of an N32-c transport layer security connection with an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection toward the device; receiving a reply from the entity, the reply including domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity; and establishing the N32-f transport layer security connection toward the entity using the domain name information received in the reply.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to wireless communications, and more particularly, to wireless communications between public land mobile networks (PLMNs). Background Art

[0002] A communication system can be viewed as a facility that enables communication between two or more devices (such as user terminals, machine-type terminals, base stations, and / or other nodes) by providing a communication channel for carrying information between the communication devices. For example, a communication system can be provided by a communication network and one or more compatible communication devices. Communication can include, for example, data communication for carrying data for voice, electronic mail (email), text messaging, multimedia, and / or content data communication. Non-limiting examples of services provided include two-way or multi-way calls, data communication or multimedia services, and access to data network systems (such as the Internet).

[0003] In a wireless system, at least some of the communication occurs over a radio interface. Examples of wireless systems include public land mobile networks (PLMNs), satellite-based communication systems, and various wireless local area networks, such as wireless local area networks (WLANs). Local area wireless network technology that allows devices to connect to a data network is known as WiFi (or Wi-Fi). WiFi and WLAN are often used synonymously. Wireless systems can be divided into cells and are therefore often referred to as cellular systems. A base station provides at least one cell.

[0004] A user can access a communication system through an appropriate communication device or terminal capable of communicating with a base station. Therefore, a node such as a base station is often referred to as an access point. A user's communication device is often referred to as a user equipment (UE). The communication device is provided with appropriate signal reception and transmission means for enabling communication, such as communication with a base station and / or direct communication with other user equipment. The communication device can communicate on an appropriate channel, such as a channel on which a listening station (e.g., a cell's base station) transmits.

[0005] Communication systems and associated equipment typically operate according to a given standard or specification that specifies what the various entities associated with the system are allowed to do and how it should be achieved. Communication protocols and / or parameters that apply to the connection are also typically defined.

[0006] Since the introduction of fourth-generation (4G) services, there has been growing interest in the next-generation or fifth-generation (5G) standard. 5G may also be referred to as New Radio (NR) networks.

[0007] In some cases, communication between PLMNs is required, such as for communication between 5G Core (5GC) networks. For example, communication between PLMNs may be required in roaming and interconnection scenarios. Summary of the Invention

[0008] According to a first aspect, a device is provided, comprising components for performing the following operations: initiating establishment of an N32-c transport layer security connection with an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and establishing the N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0009] According to some examples, the domain name information of the device includes a fully qualified domain name, and the domain name information of the entity includes a fully qualified domain name.

[0010] According to some examples, the component is further configured to perform: using the reply from the entity to set a request uniform resource identifier for an N32-f HTTP secure message sent toward the entity.

[0011] According to some examples, the component is further configured to, in response to receiving a reply from the entity, establish an N32-f transport layer security connection towards the entity using a server name indication set to the domain name information received in the reply.

[0012] According to some examples, the component is further configured to: receive, from the entity, information about the N32-c transport layer security connection related to the N32-f transport layer security connection.

[0013] According to some examples, the component is further configured to perform sending, to the entity, an N32-c signaling request for terminating the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0014] According to some examples, the component is further configured to perform sending a request to the entity to renegotiate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0015] According to some examples, the component is further configured to: receive from the entity fully qualified domain name information for the N32-f transport layer security connection as one of: a wildcard transport layer security certificate; a transport layer security certificate applicable to a list of one or more valid fully qualified domain names.

[0016] According to some examples, the N32-c handshake signaling process corresponds to N32-c security capability negotiation.

[0017] According to some examples, the apparatus includes an initiating security edge protection agent, and the entity includes a responding security edge protection agent.

[0018] According to some examples, the component includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause execution of the apparatus.

[0019] According to a second aspect, a device is provided, comprising at least one processor; and at least one memory comprising computer program code; the at least one memory and the computer program code being configured to, together with the at least one processor, cause the device to at least perform: initiating establishment of an N32-c transport layer security connection with an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection toward the device; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity; and establishing an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0020] According to a third aspect, a device is provided, comprising: a circuit system for initiating establishment of an N32-c transport layer security connection with an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; a circuit system for sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection toward the device; a circuit system for receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity; and a circuit system for establishing an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0021] According to a fourth aspect, a method performed by a device is provided, comprising: initiating establishment of an N32-c transport layer security connection with an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection toward the device; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity; and establishing an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0022] According to some examples, the domain name information of the device includes a fully qualified domain name, and the domain name information of the entity includes a fully qualified domain name.

[0023] According to some examples, the method includes using a reply from the entity for setting a request uniform resource identifier for an N32-f HTTP secure message sent toward the entity.

[0024] According to some examples, the method includes, in response to receiving a reply from the entity, establishing an N32-f transport layer security connection towards the entity using a server name indication set to domain name information received in the reply.

[0025] According to some examples, the method includes receiving, from the entity, information of an N32-c transport layer security connection related to the N32-f transport layer security connection.

[0026] According to some examples, the method includes sending, to the entity, an N32-c signaling request to terminate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0027] According to some examples, the method includes sending a request to the entity to renegotiate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0028] According to some examples, the method includes receiving, from the entity, fully qualified domain name information for the N32-f transport layer security connection as one of: a wildcard transport layer security certificate; a transport layer security certificate applicable to a list of one or more valid fully qualified domain names.

[0029] According to some examples, the N32-c handshake signaling process corresponds to N32-c security capability negotiation.

[0030] According to some examples, the apparatus includes an initiating security edge protection agent, and the entity includes a responding security edge protection agent.

[0031] According to a fifth aspect, a computer program is provided, comprising instructions for causing an apparatus to at least perform the following operations: initiate establishment of an N32-c transport layer security connection with an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network; send an N32-c handshake signaling message from the apparatus to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the apparatus, the domain name information of the apparatus to be used by the entity for establishing an N32-f transport layer security connection toward the apparatus; receive a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection to the entity; and establish an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0032] According to a sixth aspect, a computer program is provided, comprising instructions stored thereon, the instructions being used to perform at least the following operations: initiate establishment of an N32-c transport layer security connection between an initiating device and an entity, the device being located in a first public land mobile network and the entity being located in a second public land mobile network; send an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device; receive a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and establish an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0033] According to a seventh aspect, a non-transitory computer-readable medium is provided, comprising program instructions for causing an apparatus to at least perform the following operations: initiate establishment of an N32-c transport layer security connection with an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network; send an N32-c handshake signaling message from the apparatus to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the apparatus, the domain name information of the apparatus to be used by the entity for establishing an N32-f transport layer security connection toward the apparatus; receive a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection toward the entity; and establish an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0034] According to an eighth aspect, a non-transitory computer-readable medium is provided, comprising program instructions stored thereon, the program instructions being used to perform at least the following: initiating establishment of an N32-c transport layer security connection between an apparatus and an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the apparatus to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the apparatus, the domain name information of the apparatus to be used by the entity for establishing an N32-f transport layer security connection toward the apparatus; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection toward the entity; and establishing an N32-f transport layer security connection toward the entity using the domain name information received in the reply.

[0035] According to a ninth aspect, a device is provided, comprising components for performing the following operations: receiving a message from an entity initiating establishment of an N32-c transport layer security connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and sending a reply to the entity, the reply including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device.

[0036] According to some examples, the domain name information of the device includes a fully qualified domain name, and the domain name information of the entity includes a fully qualified domain name.

[0037] According to some examples, the component is also configured to receive a request from the entity to establish an N32-f transport layer security connection to the device, the request including a server name indication, which is set to domain name information sent in a reply by the device to the N32-f transport layer security connection.

[0038] According to some examples, the request for an N32-f HTTP secure message received from the entity includes a uniform resource identifier set to domain name information sent in a reply by the device for the N32-f transport layer security connection.

[0039] According to some examples, the component is further configured to create a binding between the N32-f transport layer security connection and the related N32-c transport layer security connection using a server name indication or a uniform resource identifier.

[0040] According to some examples, the component is further configured to send information of the N32-c transport layer security connection related to the N32-f transport layer security connection to the entity.

[0041] According to some examples, the component is further configured to perform receiving a request from the entity to terminate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0042] According to some examples, the component is further configured to perform receiving, from the entity, a request to renegotiate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0043] According to some examples, the component is further configured to send to the entity fully qualified domain name information for the N32-f transport layer security connection as one of: a wildcard transport layer security certificate; a transport layer security certificate applicable to a list of one or more valid fully qualified domain names.

[0044] According to some examples, the N32-c handshake signaling process corresponds to N32-c security capability negotiation.

[0045] According to some examples, the apparatus includes a responding security edge protection agent, and the entity includes an initiating security edge protection agent.

[0046] According to some examples, the component includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause execution of the apparatus.

[0047] According to a tenth aspect, a device is provided, comprising at least one processor; and at least one memory comprising computer program code; the at least one memory and the computer program code are configured to, together with the at least one processor, cause the device to at least perform: receiving a message from an entity initiating establishment of an N32-c transport layer security connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and sending a reply to the entity, the reply including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device.

[0048] According to the eleventh aspect, a device is provided, comprising: a circuit system for receiving a message from an entity to initiate the establishment of an N32-c transport layer security connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; a circuit system for receiving an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and a circuit system for sending a reply to the entity, the reply including the domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device.

[0049] According to the twelfth aspect, a method performed by a device is provided, comprising: receiving a message from an entity to initiate establishment of an N32-c transport layer security connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity; and sending a reply to the entity, the reply including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection toward the device.

[0050] According to some examples, the domain name information of the device includes a fully qualified domain name, and the domain name information of the entity includes a fully qualified domain name.

[0051] According to some examples, the method includes receiving a request from the entity to establish an N32-f transport layer security connection toward the device, the request including a server indication that is set to domain name information to be sent in a reply by the device to the N32-f transport layer security connection.

[0052] According to some examples, the request for an N32-f HTTP secure message received from the entity includes a uniform resource identifier set to domain name information sent in a reply by the device for the N32-f transport layer security connection.

[0053] According to some examples, the method includes creating a binding between the N32-f transport layer security connection and a related N32-c transport layer security connection using a server name indication or a uniform resource identifier.

[0054] According to some examples, the method includes sending information of the N32-c transport layer security connection related to the N32-f transport layer security connection to the entity.

[0055] According to some examples, the method includes receiving, from the entity, a request to terminate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0056] According to some examples, the method includes receiving, from the entity, a request to renegotiate the N32-f transport layer security connection and the related N32-c transport layer security connection.

[0057] According to some examples, the method includes sending to the entity fully qualified domain name information for the N32-f transport layer security connection that is one of: a wildcard transport layer security certificate; a transport layer security certificate applicable to a list of one or more valid fully qualified domain names.

[0058] According to some examples, the N32-c handshake signaling process corresponds to N32-c security capability negotiation.

[0059] According to some examples, the apparatus includes a responding security edge protection agent, and the entity includes an initiating security edge protection agent.

[0060] According to a thirteenth aspect, a computer program is provided, comprising instructions for causing a device to at least perform the following operations: receive a message from an entity initiating establishment of an N32-c transport layer security connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receive an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and send a reply to the entity, the reply including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device.

[0061] According to a fourteenth aspect, a computer program is provided, comprising instructions stored thereon, the instructions being used to perform at least the following operations: receiving a message from an entity initiating establishment of an N32-c transport layer security connection with a device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and sending a reply to the entity, the reply including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device.

[0062] According to the fifteenth aspect, a non-transitory computer-readable medium is provided, comprising program instructions for causing an apparatus to at least perform the following operations: receive a message from an entity initiating establishment of an N32-c transport layer security connection with the apparatus, the entity being located in a first public land mobile network and the apparatus being located in a second public land mobile network; receive an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection toward the entity; and send a reply to the entity, the reply including domain name information of the apparatus, the domain name information of the apparatus to be used by the entity for establishing an N32-f transport layer security connection toward the apparatus.

[0063] According to the sixteenth aspect, a non-transitory computer-readable medium is provided, comprising program instructions stored thereon, the program instructions being used to perform at least the following operations: receiving a message from an entity initiating establishment of an N32-c transport layer security connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity on the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity being to be used by the device for establishing an N32-f transport layer security connection toward the entity; and sending a reply to the entity, the reply including domain name information of the device, the domain name information of the device being to be used by the entity for establishing an N32-f transport layer security connection toward the device. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] The invention will now be described in more detail with reference to the following examples and accompanying drawings, in which, by way of example only:

[0065] Figure 1 shows inter-PLMN communication according to an example;

[0066] Figure 2 is a signaling diagram according to an example;

[0067] Figure 3 is a signaling diagram according to an example;

[0068] Figure 4 is a signaling diagram according to an example;

[0069] Figure 5 Components of a control device according to an example are shown;

[0070] Figure 6 and 7 is a flow chart of a method according to an example;

[0071] Figure 8 A schematic diagram of a non-volatile storage medium storing instructions that, when executed by a processor, enable the processor to perform one or more steps of the method of some embodiments is shown. DETAILED DESCRIPTION

[0072] Before explaining the examples in detail, Figure 1 Some general principles of inter-network signaling are described.

[0073] Figure 1A communication system 100 is shown. The communication system 100 includes a first network 102 and a second network 104. In an example, the first network 102 can be a first 5GC network and the second network 104 can be a second, different 5GC network. In an example, the first network 102 can be considered to include a first PLMN and the second network 104 can be considered to include a second, different PLMN. Figure 1 In the example of FIG. 1 , network 102 includes a Security Edge Protection Proxy (SEPP) entity 106 , and network 104 includes a SEPP entity 108 .

[0074] Communication between SEPPs 106 and 108 occurs via a first interface 110 and a second interface 112. In an example, first interface 110 comprises an N32-c interface. The N32-c interface comprises a control plane interface between SEPPs, used to perform an initial handshake and negotiate parameters to be applied to actual N32 message forwarding. For example, the N32-c interface can be used to negotiate protection and security policies to be applied to HTTP messages exchanged between the two networks 102 and 104. In an example, second interface 112 comprises an N32-f interface. In an example, the N32-f interface is used to forward communications between SEPP entities 106 and 108. For example, the N32-f interface can be used to send JSON Web Encryption (JWE) and JSON Web Signature (JWS)-protected messages between SEPP 102 and SEPP 104. In an example, the N32-c and N32-f interfaces comprise transport layer security (TLS) connections.

[0075] In practice, an N32-c interface (e.g., first interface 110) has a corresponding N32-f interface (e.g., second interface 112). In practice, there may be multiple N32-c and N32-f interfaces within a system. As discussed in more detail below, there are issues in correlating an N32-c interface with its corresponding N32-f interface. Furthermore, the SEPP TLS profile is not defined; this is left to the GSMA.

[0076] When the "Protocol for N32 Interconnect Security" (PRINS) is used as the protocol for forwarding messages on an N32-f connection, a mechanism has been defined to associate an N32-c connection with an N32-f connection. In addition, when the N32-f connection is no longer needed, a mechanism has been defined for terminating the N32-f connection via the "N32-f Context Termination Procedure."

[0077] This disclosure identifies that there is currently no mechanism available in 3GPP to correlate an N32-f TLS connection with a corresponding N32-c TLS connection. This disclosure also identifies that correlation of these connections would be useful for several reasons, including:

[0078] - Enables any renegotiation policy used for N32-c TLS to apply to the associated N32f TLS connection.

[0079] -Be able to tear down or terminate the N32-f connection(s) associated with the N32-c connection;

[0080] - When a SEPP or Roaming Hub (RHUB) supports serving multiple PLMNs, it is possible to identify the N32-f connection(s) for a specific PLMN.

[0081] Thus, as will be described in greater detail below and in the accompanying figures, a mechanism is disclosed for correlating or associating one or more N32-c connections with corresponding one or more N32-f connections. In some examples, the correlation occurs between a particular N32-c connection and one or more corresponding N32-f connections. In some examples, this process occurs when TLS security is negotiated for N32-f during N32-c security negotiation. In some examples, an extension to N32-c signaling is proposed that supports signaling from a first SEPP (initiating SEPP) to a second SEPP (peer or receiving SEPP). In some examples, the extension includes the following to correlate N32-c and N32-f connections:

[0082] The TLS extension SNI (Server Name Indication) exchanged by N32-c is used for the establishment of the N32-f TLS connection. In some examples, the FQDN is encapsulated in the SNI field.

[0083] Hypertext Transfer Protocol (HTTP) Application Programming Interface Root (API Root) for N32-f connections

[0084] A wildcard certificate for N32-f connections, and / or

[0085] Subject Alternative Name (SAN) with one or more hostnames / FQDNs

[0086] According to an example, the mechanism allows correlation of N32-c connections with N32-f connections at both the TLS level (eg, SNI) and the HTTP level (eg, API root in request Uniform Resource Identifier (URI)).

[0087] Figure 2There is shown communication between an initiating (first) SEPP 206 and a responding (second) SEPP 208. As a non-limiting example, the initiating SEPP 206 is located in a visited PLMN and the responding SEPP 208 is located in a home PLMN.

[0088] At S1, a TLS connection is established for an N32-c connection between the initiating SEPP 206 and the responding SEPP 208. In some examples, S1 can be considered an N32-c "handshake" signaling procedure. See Section 5.2 "N32 Handshake Procedures (N32-c)" of 3GPP TS 29.573.

[0089] S2 and S3 show the security capability negotiation process over the established N32-c by the initiating SEPP 206 and the responding SEPP 208. The standard security capability negotiation process is defined in TS 29.573.

[0090] according to Figure 2 In the example of FIG. 2 , at S2 and as part of the security capability negotiation process on N32-c, the initiating SEPP 206 sends domain name information to the responding SEPP. The domain name information includes a server name indication to be used by the responding SEPP during the establishment of the N32-f TLS connection. According to some examples, the domain name information includes a fully qualified domain name (FQDN). Therefore, in the example, it can be considered that the initiating SEPP 206 sends the N32-f FQDN to the SEPP 208. In other words, the initiating SEPP 206 sends information about the N32-f connection FQDN to the responding SEPP 208, requesting that the responding SEPP 208 use this information when establishing the N32-f TLS connection. In the example, this assumes that TLS security is supported and that the initiating SEPP 206 supports correlating the N32-f and N32-c connections.

[0091] According to some examples, the FQDN includes a fixed portion and a "label" portion. The "label" portion may also be referred to as a dynamic portion or a non-fixed portion. According to some examples, the label portion precedes the dynamic portion.

[0092] For example, the fixed portion may be in the form of "sepp-n32f.5gc.mnc123.mcc012.3gppnetwork.org" or, more broadly, "sepp-n32f.operator.com." Here, "sepp" may include an identifier of the originating SEPP, and "operator" may include an identifier of the network operator that originates the SEPP. Therefore, it will be understood that "fixed" means a fixed format, and the content of the fixed portion may vary depending on the scenario (e.g., depending on the SEPP identity and the operator identity).

[0093] According to some examples, the tag portion includes a wildcard value or a wildcard FQDN. For example, the tag portion can be in the form of "N32c-123", where "123" is a dynamic value.

[0094] Thus, for example, the generated FQDN (i.e., fixed portion plus dynamic portion) may be of the form "n32c-123.sepp-n32f.5gc.mnc123.mcc012.3gppnetwork.org," or more broadly, "n32c-123.sepp-n32f.operator.com." In an example, the initiating SEPP 206 stores this FQDN information in its own memory / configuration.

[0095] At S3, responding SEPP 208 indicates the N32-f connection FQDN to initiating SEPP 206, and responding SEPP 208 requests that initiating SEPP 206 use the N32-f connection FQDN when setting up the N32-f TLS connection. In this example, this assumes that TLS security is supported and that responding SEPP 208 supports correlating N32-f and N32-c connections. In some examples, responding SEPP 208 sends the FQDN in a 200 OK message. The N32-f connection FQDN sent by responding SEPP 208 to initiating SEPP 206 may include a fixed portion and a dynamic portion, as described above for the initiating SEPP.

[0096] In this example, at S4, the responding SEPP 208 configures the generated FQDN as the "allowed SNI" for the N32-f TLS connection.

[0097] Thus, in some examples, the initiating SEPP 206 may be considered to have a list of fqdns configured as “AllowedSNI” that it shares with the responding SEPP 208. Similarly, the responding SEPP 208 may have a list of fqdns configured as “AllowedSNI” that it shares with the initiating SEPP 206.

[0098] It will be noted that during the N32-c handshake process, each N32-c connection may be assigned a different FQDN based on a wildcard value picked by the responding SEPP 208 , or selected from a list of FQDNs supported by the responding SEPP 208 .

[0099] According to some examples, an operator may provide a wildcard FQDN in its Domain Name System (DNS) so that all FQDNs of labels with the same fixed portion and any prefix resolve to the same SEPP entity. For example:

[0100] n32f-resp-fqdn=<n32c-123.sepp-n32f.operator.com>

[0101] Wildcard FQDN=<n32c-*.sepp-n32f.operator.com>

[0102] Where * is a wildcard value. Of course, the n32c-prefix and sepp-n32f.operator.com values ​​are given as examples only and may differ in practice.

[0103] Table 1 below shows in more detail Figure 2 Attributes that may be included in the SecNegotiateReqData message at S2.

[0104]

[0105] Table 1

[0106] Table 2 below shows in more detail Figure 2 The S3 SecNegotiateRspData message may include attributes.

[0107]

[0108] Table 2

[0109] Now refer to Figure 3 Describe in more detail Figure 2 The process after "Security Capability Negotiation Procedure over N32-c" shown in Figure 3 Communications between the initiating SEPP 206, DNS 220, and responding SEPP 208 are shown for establishing the N32-f connection and its correlation with the N32-c connection.

[0110] At S1 and S2, the initiating SEPP 206 parses the received N32f SEPP FQDN (i.e., Figure 2 To do this, the initiating SEPP 206 sends a query to the DNS at S1 and receives a reply from the DNS 220 at S2. To provide the reply at S2, in some examples, the DNS 220 is configured to use a wildcard FQDN, for example. An example lookup table is shown in Table 3 below, where * indicates a wildcard value.

[0111]

[0112] Table 3

[0113] In some examples, the trigger for the initiating SEPP to initiate establishment of the N32 - f interface is when the initiating SEPP 206 has traffic to send to the responding SEPP 208 .

[0114] It should be noted that in some examples, the operator provides a wildcard DNS entry that maps all requests for "*.sepp-n32f.operator.com" to the SEPP address.

[0115] At S3, as part of the N32-f TLS "handshake", the initiating SEPP 206 uses the FQDN value received as part of the N32-c security capability negotiation process (i.e., in Figure 2 In some examples, the FQDN value is included in the TLS SNI extension server_name attribute. In some examples, when this SNI is received at the initiating SEPP 206 from the responding SEPP 208, it is used during the establishment of the TLS connection for N32-f signaling, i.e., as part of the TLS handshake process for the N32-f connection. As shown in the figure, in some examples, this information is then included in the "Client Hello" message from the initiating SEPP 206 to the responding SEPP 208.

[0116] At S4, the responding SEPP 208 has allowed the SNI configured via N32-c. If the SNI value matches any allowed SNI value, the TLS handshake process proceeds. However, if the SNI value does not match, the TLS handshake is rejected (according to RFC 2818). In other words, the responding SEPP 208 selects the N32-c context based on the FQDN information received from the initiating SEPP 206.

[0117] When receiving a TLS Client Hello and an HTTP request, the receiving SEPP can bind the TLS connection and the HTTP request to the N32-c connection by using a specific SNI (TLS) and apiRoot (HTTP) (i.e., "n32c-123.sepp-n32f.operator.com"). According to the existing principle, the sending SEPP can set the SNI to the same value as the apiRoot of the HTTPS request. In other words, the responding SEPP 208 correlates (or associates, or binds) between the N32-c TLS connection and the related N32-f TLS connection.

[0118] S5 and S6 show two alternatives for how the responding SEPP 208 responds to the initiating SEPP 206 after the binding.

[0119] In the first option, as shown in S5, the responding SEPP 208 sends a list of supported FQDNs to the initiating SEPP 206. This response may be in the form of a certificate: Certificate <SNA = <list of supported FQDNs>. An example SNA certificate is as follows:

[0120]

[0121] In the second option shown in S6, the responding SEPP returns a wildcard TLS certificate, such as "*.sepp-n32f.5gc.mnc123.mcc012.3gppnetwork.org", or "*.sepp-n32f.operator.com". An example wildcard certificate is as follows.

[0122]

[0123] Figure 4 Shows an example process where the SEPP wishes to terminate the N32-c connection and the associated N32-f TLS connection.

[0124] At S1, the initiating SEPP 206 sends a N32-c signaling request to the responding SEPP 208 to terminate the N32-c connection and the (multiple) associated N32-f connections.

[0125] It will be noted that the responding SEPP 208 has received the N32-f FQDN of the previously sent initiating SEPP 206 (see for example Figure 2 and Figure 3 ). Using this information, at S2, the responding SEPP 208 identifies the TLS connection that it has originated towards the initiating SEPP 206.

[0126] The responsive SEPP 208 terminates these connections as indicated at S3.

[0127] Likewise, the initiating SEPP 206 may terminate all TLS connections it has initiated towards the responding SEPP 208, as indicated at S4.

[0128] For termination of connections, in some examples, the FQDN is removed from the allowed SNI list and the existing connection is drained and terminated. In some examples, new connections are not allowed.

[0129] In some examples, the renegotiation of the N32-c connection and the associated N32-f TLS connection may be similar to the termination process. For example, at S1, the request may be a request for renegotiation rather than a request for termination, and S3 and S4 may include renegotiation of the connection rather than termination of the connection.

[0130] A non-limiting working example is provided below to further aid in understanding these principles.

[0131] Initiating SEPP 206 supports both PLMN1 and PLMN2. To negotiate the security policy for PLMN1, initiating SEPP 206 invokes the security capability negotiation process. During this process, initiating SEPP 206 shares n32fFqdn="PLMN1.sepp-n32f.ABC.com" with responding SEPP 208. Responding SEPP 208 selects an available FQDN for N32f, such as n32fFqdn="PLMN2.sepp-n32f.XYZ.com," and shares the same with initiating SEPP 206. Initiating SEPP 206 now establishes an N32f TLS connection. To do so, initiating SEPP 206 sends a "Client Hello" message with SNI=PLMN2.sepp1-n32f.XYZ.com to responding SEPP 208. The responding SEPP 208 can correlate the N32f and N32c sessions via the SNI and reply with a "Server Hello" message including a wildcard certificate or an SNA with a list of fqdns.

[0132] If initiating SEPP 206 wishes to negotiate a security policy for PLMNx with PLMN2, it then invokes the security capability negotiation process again. During this process, initiating SEPP 206 shares n32fFqdn="PLMNx.sepp-n32f.ABC.com" with responding SEPP 208. Responding SEPP 208 selects an available FQDN for N32f, such as n32fFqdn="PLMN2a.sepp-n32f.XYZ.com," and shares the same with initiating SEPP 206. Initiating SEPP 206 now establishes an N32f TLS connection. Therefore, initiating SEPP 206 sends a Client Hello with SNI=PLMN2a.sepp1-n32f.XYZ.com. The responding SEPP 208 can correlate the N32f with the N32c session via the SNI and respond with a "Server Hello" message including a wildcard certificate or an SNA with a list of fqdns.

[0133] When the initiating SEPP 206 wishes to terminate the N32-c connection and associated N32-f TLS connection for PLMN1 and PLMN2, the SEPP 206 initiates a security capability negotiation process, where the initiating SEPP 206 shares supportedSecCapabilityList=NULL. Using the initiating SEPP's 206n32fFqdn (i.e., PLMN1.sepp-n32f.ABC.com) it received earlier during the N32-c handshake, the responding SEPP 208 identifies the TLS connections it has already initiated toward the initiating SEPP 206 and terminates all of these N32-f TLS connections. Similarly, the initiating SEPP 206 can terminate all N32-f TLS connections it has already originated toward the responding SEPP 208. Here, PLMN2a.sepp-n32f.XYZ.com is removed from the responding SEPP's 208 list of allowed SNIs, and the existing connections are drained and terminated. And, according to some examples, new connections are not allowed for the configured duration.Similarly, in the allowed SNI list of the response SEPP 206, PLMN1.sepp-n32f.ABC.com is removed, and the existing connection is drained and terminated.

[0134] Figure 5Examples of control devices for a communication system are shown, such as a station coupled to and / or for controlling an access system (such as a RAN node), such as a base station, gNB, a central unit of a cloud architecture or a node of a core network (such as an MME or S-GW), a scheduling entity (such as a spectrum management entity), or a server or host. Figure 5 The control device may, for example, include or host a SEPP or DNS. The control device may be integrated with a node or module of the core network or RAN, or external thereto. The control device 500 may be arranged to provide control of communications within the service area of ​​the system. The control device 500 includes at least one memory 501, at least one data processing unit 502, 503, and an input / output interface 504. Via this interface, the control device may be coupled to the receiver and transmitter of the base station. The receiver and / or transmitter may be implemented as a radio front end or a remote radio head. For example, the control device 500 or the processor 501 may be configured to execute appropriate software code to provide control functionality.

[0135] Figure 6 is a flow chart of a method according to an example. Figure 6 The flowchart is from the perspective of initiating SEPP 206.

[0136] At S1 , the method comprises initiating establishment of an N32-c transport layer secure connection with an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network.

[0137] At S2, the method includes sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity to establish an N32-f transport layer security connection toward the device.

[0138] At S3 , the method includes receiving a reply from the entity, the reply including domain name information of the entity to be used by the device for establishing an N32 -f transport layer security connection to the entity.

[0139] At S4 , the method includes establishing an N32 -f transport layer security connection towards the entity using the domain name information received in the reply.

[0140] Figure 7 is a flow chart of a method according to an example. Figure 7 The flowchart is from the perspective of responding to SEPP 208.

[0141] At S1 , the method includes receiving a message initiating setup of an N32-c transport layer secure connection with a device from an entity, the entity being located in a first public land mobile network and the device being located in a second public land mobile network.

[0142] At S2, the method includes receiving an N32-c handshake signaling message from an entity over an N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity to be used by the device for establishing an N32-f transport layer security connection toward the entity.

[0143] At S3 , the method includes sending a reply to the entity, the reply including domain name information of the device to be used by the entity for establishing an N32 - f transport layer security connection towards the device.

[0144] Figure 8 Schematic diagrams of non-volatile memory media 800a (e.g., a computer disk (CD) or digital versatile disk (DVD)) and 800b (e.g., a universal serial bus (USB) memory stick) storing instructions and / or parameters 802 that, when executed by a processor, allow the processor to perform Figures 6 to 7 In general, various embodiments may be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects of the present disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device, but the invention is not limited thereto. Although various aspects of the present invention may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that, as non-limiting examples, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or a controller or other computing device, or some combination thereof.

[0145] In general, various embodiments may be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects of the invention may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device, but the invention is not limited thereto. Although various aspects of the invention may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that, as non-limiting examples, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or a controller or other computing device, or some combination thereof.

[0146] As used in this application, the term "circuitry" may refer to one or more or all of the following: (a) hardware circuitry implementations only (such as implementations in analog and / or digital circuitry only) and (b) combinations of hardware circuitry and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuitry with software / firmware and (ii) any portion of hardware processor(s) (including digital signal processor(s)), software, and memory(s) with software that work together to enable a device (such as a mobile phone or server) to perform various functions, and (c) hardware circuitry and / or processor(s), such as microprocessors or portions of microprocessors that require software (e.g., firmware) to operate, but that software may not be present when such software is not required for operation. This definition of circuitry applies to all uses of the term in this application, including in any claims. As another example, as used in this application, the term circuitry also encompasses an implementation of only hardware circuitry or a processor (or processors) or a portion of a hardware circuitry or processor and their (or their) accompanying software and / or firmware. For example, the term circuitry would also encompass, if applicable to a particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or networking equipment.

[0147] Embodiments of the present invention may be implemented by computer software executable by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. Computer software or programs, also referred to as program products, include software routines, applets, and / or macros, and may be stored in any device-readable data storage medium and include program instructions for performing specific tasks. A computer program product may include one or more computer-executable components that are configured to perform the embodiments when the program is run. The one or more computer-executable components may be at least one software code or portion thereof.

[0148] Furthermore, in this regard, it should be noted that any block of the logic flow in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on physical media such as memory chips or memory blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as DVDs and their data variants, CDs. Physical media is a non-transitory medium.

[0149] The memory may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor may be of any type suitable for the local technical environment and may include, by way of non-limiting example, one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an FPGA, gate-level circuits based on a multi-core processor architecture, and a processor.

[0150] Embodiments of the present invention may be practiced in various components, such as integrated circuit modules. The design of integrated circuits is generally a highly automated process. Complex and powerful software tools are available to convert a logic-level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0151] The foregoing description has provided by way of non-limiting examples a complete and informative description of the exemplary embodiments of the present invention. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description when read in conjunction with the accompanying drawings and the appended claims. Nevertheless, all such and similar modifications of the teachings of this invention will still fall within the scope of the present invention as defined by the appended claims. Indeed, further embodiments exist comprising combinations of one or more embodiments with any of the other embodiments discussed above.

Claims

1. An apparatus for communication, comprising means for performing the following operations: initiating establishment of an N32-c transport layer security connection with an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection towards the device; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the device for establishing the N32-f transport layer security connection towards the entity; as well as The N32-f transport layer security connection is established towards the entity using the domain name information received in the reply. 2 . The apparatus of claim 1 , wherein the domain name information of the apparatus comprises a fully qualified domain name, and the domain name information of the entity comprises a fully qualified domain name.

3. The apparatus of claim 1 , wherein the component is further configured to perform: using the domain name information received in the reply from the entity to set a request uniform resource identifier for an N32-f Hypertext Transfer Protocol Secure message sent toward the entity.

4. The apparatus according to any one of claims 1 to 3, wherein the component is further configured to: in response to receiving the reply from the entity, establish the N32-f transport layer security connection towards the entity using a server name indication set to the domain name information received in the reply. 5 . The apparatus according to claim 1 , wherein the component is further configured to: receive, from the entity, information about an N32-c transport layer security connection related to the N32-f transport layer security connection.

6. The apparatus of claim 5, wherein the component is further configured to perform sending an N32-c signaling request to the entity for: terminating the N32-f transport layer security connection and the related N32-c transport layer security connection.

7. The apparatus of claim 5, wherein the component is further configured to perform sending a request to the entity to renegotiate the N32-f transport layer security connection and the related N32-c transport layer security connection.

8. The apparatus according to any one of claims 1 to 3, wherein the component is further configured to: receive from the entity fully qualified domain name information for the N32-f transport layer security connection as one of the following: a wildcard transport layer security certificate; a transport layer security certificate applicable to a list of one or more valid fully qualified domain names.

9. The apparatus according to any one of claims 1 to 3, wherein the N32-c handshake signaling process corresponds to N32-c security capability negotiation.

10. The apparatus of any one of claims 1 to 3, wherein the apparatus comprises an initiating security edge protection agent and the entity comprises a responding security edge protection agent.

11. An apparatus for communication, comprising means for performing the following operations: receiving a message from an entity initiating establishment of an N32-c transport layer secure connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection towards the entity; A reply is sent to the entity, the reply including domain name information of the device to be used by the entity for establishing the N32-f transport layer secure connection towards the device. 12 . The apparatus of claim 11 , wherein the domain name information of the apparatus comprises a fully qualified domain name, and the domain name information of the entity comprises a fully qualified domain name.

13. An apparatus according to claim 11, wherein the component is further configured to: receive a request from the entity to establish an N32-f transport layer security connection towards the apparatus, the request including a server indication, the server indication being set to the domain name information sent in the reply by the apparatus for the N32-f transport layer security connection.

14. An apparatus according to claim 13, wherein the request for an N32-f Hypertext Transfer Protocol Secure message received from the entity includes a uniform resource identifier, and the uniform resource identifier is set to the domain name information sent in the reply by the apparatus for the N32-f transport layer security connection.

15. The apparatus of claim 14, wherein the component is further configured to create a binding between the N32-f transport layer security connection and the related N32-c transport layer security connection using the server name indication or the uniform resource identifier.

16. The apparatus according to claim 15, wherein the component is further configured to: send information of the N32-c transport layer security connection related to the N32-f transport layer security connection to the entity.

17. The apparatus of claim 16, wherein the component is further configured to perform receiving a request from the entity to terminate the N32-f transport layer security connection and the related N32-c transport layer security connection.

18. The apparatus of claim 16, wherein the component is further configured to perform receiving a request from the entity to renegotiate the N32-f transport layer security connection and the related N32-c transport layer security connection.

19. The apparatus according to any one of claims 11 to 18, wherein the component is further configured to: send to the entity fully qualified domain name information for the N32-f transport layer security connection as one of the following: a wildcard transport layer security certificate; a transport layer security certificate applicable to a list of one or more valid fully qualified domain names.

20. The apparatus according to any one of claims 11 to 18, wherein the N32-c handshake signaling procedure corresponds to N32-c security capability negotiation.

21. The apparatus of any one of claims 11 to 20, wherein the apparatus comprises a responding security edge protection agent and the entity comprises an initiating security edge protection agent.

22. A method performed by an apparatus for communication, comprising: initiating establishment of an N32-c transport layer security connection with an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection towards the device; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the device for establishing the N32-f transport layer security connection towards the entity; as well as The N32-f transport layer security connection is established towards the entity using the domain name information received in the reply.

23. A method performed by an apparatus for communication, comprising: receiving a message from an entity initiating establishment of an N32-c transport layer secure connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection towards the entity; A reply is sent to the entity, the reply including domain name information of the device to be used by the entity for establishing the N32-f transport layer secure connection towards the device.

24. A computer-readable storage medium comprising program instructions, wherein the program instructions are configured to cause an apparatus to at least perform the following operations: initiating establishment of an N32-c transport layer security connection with an entity, the apparatus being located in a first public land mobile network and the entity being located in a second public land mobile network; sending an N32-c handshake signaling message from the device to the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the device, the domain name information of the device to be used by the entity for establishing an N32-f transport layer security connection towards the device; receiving a reply from the entity, the reply including domain name information of the entity, the domain name information of the entity to be used by the device for establishing the N32-f transport layer security connection towards the entity; as well as The N32-f transport layer security connection is established towards the entity using the domain name information received in the reply.

25. A computer-readable storage medium comprising program instructions, wherein the program instructions are configured to cause an apparatus to at least perform the following operations: receiving a message from an entity initiating establishment of an N32-c transport layer secure connection with the device, the entity being located in a first public land mobile network and the device being located in a second public land mobile network; receiving an N32-c handshake signaling message from the entity over the N32-c transport layer security connection, the N32-c handshake signaling message including domain name information of the entity, the domain name information of the entity to be used by the apparatus for establishing an N32-f transport layer security connection towards the entity; A reply is sent to the entity, the reply including domain name information of the device to be used by the entity for establishing the N32-f transport layer secure connection towards the device.

Citation Information

Patent Citations

  • Secure inter-mobile network communication

    US20210120416A1

  • Automated roaming service level agreements between network operators via security edge protection proxies in a communication system environment

    US20210321303A1