Service request handling

By initiating a service request that includes discovery and access token request parameters in the SCP node, the problem of the SCP node being unable to handle subsequent requests in the prior art is solved, ensuring the smooth transmission and processing of service requests.

CN116097691BActive Publication Date: 2026-02-03TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202180058406.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-07-31
Filing Date
2021-06-25
Publication Date
2026-02-03
Estimated Expiration
2041-06-25

AI Technical Summary

Technical Problem

In existing indirect communication systems, subsequent requests for services cannot be made through the Service Communication Agent (SCP) node because the SCP node cannot find a valid storage access token and lacks the information to request a new access token.

Method used

The first SCP node initiates a request to the service producer, including discovery parameters and access token request parameters, to obtain and store the access token, and forwards the request to the service producer node; subsequent requests include the stored or newly obtained access token to ensure smooth communication.

Benefits of technology

It enables efficient processing of service requests in indirect communication systems, ensuring that subsequent requests can be successfully processed and avoiding communication failures caused by invalid access tokens.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116097691B_ABST
    Figure CN116097691B_ABST
Patent Text Reader

Abstract

Methods for handling service requests are provided. One method allows a service consumer's network function node to connect to a service producer's NF node via a service communication proxy node. The method includes initiating transmission of a first request to a SCP node (202). The first request includes a discovery parameter and an access token request parameter that facilitates obtaining and storing an access token by the SCP node. The discovery parameter facilitates selecting a second NF node of a service producer that provides a first service and forwarding the request to the second NF node. The method includes receiving a response from the second NF node (206) and initiating transmission of a second request to the SCP node (208), the second request being a subsequent request for the second NF node to provide the first service. The second request includes the access token request parameter.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to methods for handling service requests in a network and nodes configured to operate according to those methods. Background Technology

[0002] Various technologies exist for handling requests for services within a network. Service requests typically originate from a service consumer (“service consumer”) to a service producer (“service producer”). For example, a service request may originate from a service consumer’s network function (NF) node to a service producer’s NF node. The service consumer’s NF node (NFc) and the service producer’s NF node (NFp) may communicate directly or indirectly. These are referred to as direct communication and indirect communication, respectively. In the case of indirect communication, the service consumer’s NF node and the service producer’s NF node may communicate via a service communication broker (SCP) node.

[0003] Figure 1 The AD diagram illustrates the different existing systems used to handle service requests, such as those described in 3GPP TS 23.501 v16.5.0 (available at https: / / portal.3gpp.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3144 (as of July 27, 2020)). In more detail, Figure 1 Figures A and 1B illustrate systems using direct communication, while Figure 1 Figures C and 1D illustrate a system that uses indirect communication.

[0004] exist Figure 1 In the systems shown in A and 1B, service requests are sent directly from the service consumer's NF node to the service producer's NF node. Responses to service requests are sent directly from the service producer's NF node to the service consumer's NF node. Similarly, any subsequent service requests are sent directly from the service consumer's NF node to the service producer's NF node. Figure 1 The system shown in B also includes Network Repository Functionality (NRF). Therefore, in Figure 1 In the system shown in B, a consumer's NF node can query the NRF to discover the appropriate NF node of the service producer sending service requests to it. In response to such a query, the consumer's NF node can receive NF profiles of one or more NF nodes of the service producer, and based on the received NF profile(s), can select the NF node of the service producer to send service requests to it. Figure 1In the system shown in A, instead of using NRF, the consumer's NF node can be configured with one or more NF profiles of the service producer's (one or more) NF nodes.

[0005] exist Figure 1 In the systems shown in C and 1D, service requests are indirectly sent from the service consumer's NF node to the service producer's NF node via a Service Communication Broker (SCP) node. Responses to service requests are indirectly sent from the service producer's NF node to the service consumer's NF node via the SCP. Similarly, any subsequent service requests are indirectly sent from the service consumer's NF node to the service producer's NF node via the SCP. Figure 1 The systems shown in C and 1D also include NRF.

[0006] exist Figure 1 In the system shown in C, a consumer's NF node can query the NRF to discover a suitable NF node of the service producer sending a service request to it. In response to such a query, the consumer's NF node can receive NF profiles of one or more NF nodes of the service producer, and based on the received NF profile(s), can select the NF node of the service producer to which it should send the service request. In this case, the service request sent from the service consumer's NF node to the SCP includes the address of the selected NF node of the service producer. The service consumer's NF node can forward the service request without performing any further discovery or selection. If the selected NF node of the service producer is inaccessible for any reason, an alternative can be found based on the service consumer's NF node. In other cases, the SCP can communicate with the NRF to obtain selection parameters (e.g., location, capacity, etc.), and the SCP can select the NF node of the service producer to which it should send the service request.

[0007] exist Figure 1In the system shown in D, the consumer's NF node (NFc) does not perform a discovery or selection process. Instead, the consumer's NF node can add any necessary discovery and selection parameters (the parameters required to find the appropriate NF node NFp of the service producer) to its service request sent via the SCP. The SCP can then use the requested address in the service request, along with the discovery and selection parameters, to route the service request to the appropriate NF node of the service producer. The SCP can perform discovery in conjunction with the NRF. The consumer's NF node can also include a client credential assertion in the service request for use by the SCP during the authorization process. The client credential assertion is a token signed by the consumer's NF node, which enables the consumer's NF node to authenticate to the receiving endpoint (NRF, producer's NF node) by including the signed token in the service request. The use of client credential assertions is discussed in 3GPP TS 33.501v 16.3.0 (available at https: / / portal.3gpp.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3169 (since July 27, 2020)), particularly in Section 13.3.1.2.

[0008] For the fifth-generation core (5GC), starting with version 16, SCP is included as a network element to allow indirect communication between NF nodes serving consumers and NF nodes serving producers. The indirect communication used can be referenced in earlier versions. Figure 1 Either of the two indirect communication options described in C and 1D.

[0009] Figure 2A -C is used to illustrate existing systems (such as...) Figure 1 Signaling diagram of signal exchange in the system shown in D. Figure 2A The system shown in -C includes a first SCP node 10, a first NF node 20 (“NFc”) for a service consumer, a second NF node 30 (“NFp1”) for a service producer, and a third NF node 70 (“NFp2”) for a service producer. The first SCP node 10 is configured to operate as an SCP between the first NF node 20 and the second NF node 30. The second NF node 30 may be configured to run service 40, and the third NF node 70 may be configured to run service 80. The second NF node 30 and the third NF node 70 may be configured to run the same service or different services. The second NF node 30 and the third NF node 70 may be part of a set of NF nodes 402 for the service producer. Figure 2A The system shown in -C also includes network repository functionality 60.

[0010] exist Figure 2A In -C, steps 600-630 involve a first request for the User Equipment (UE) / session context. (As per...) Figure 2A Box 500 (-C) is used to store the UE / session context. More details are available from... Figure 2A As shown in box 600 of the -C section, the first NF node 20 determines which discovery and selection parameters to use. These parameters can be associated with a specific service in the received request, which... Figure 2A -C is not shown. (As per...) Figure 2A As shown in boxes 502 and 602 of -C, the first NF node 20 stores the UE / session context of the request. This storage device can be cached or stored externally.

[0011] As by Figure 2A As indicated by arrow 604 (-C), the first NF node (NFc) 20 initiates a discovery request transmission to the first SCP node 10. The discovery request includes a client credential assertion that provides information to verify the client and can be used by the first SCP to obtain an access token on behalf of the first NF node 20. The first SCP node 10 uses the discovery request to obtain from NRF 60 the NF profiles (see arrows 606 and 608) of one or more NF nodes (NFp) of the service producer for the service to be performed. Figure 2A As shown in boxes 504 and 610 of -C, the first SCP node 10 can store discovery results (returned (one or more) NF profiles).

[0012] As indicated by arrow 612, the first SCP node 10 sends an access token request to NRF 60. The access token request includes some parameters from the discovery parameters received in the request (see arrow 604), and may also include other information from the first SCP node 10, such as the scope (one or more services). The first SCP node 10 can be configured to specify which discovery parameters should be used to grant the access token. Access token request parameters are discussed in more detail in 3GPP TS 33.501 (as described above), particularly in section 13.4.1.1. Discovery parameters are discussed in more detail in 3GPP TS 29.510V 16.4.0 (available at https: / / portal.3gpp.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3345 (from July 27, 2020)), particularly in section 6.2.3.2.3.1. Tokens may need to be granted at different granularities; for example, they may be required to be at the service level plus the network slice level (using Single-Network-Slice Selection Auxiliary Information S-NSSAI, so in this example it may be required to grant the access token). Then, at arrow 614, the NRF grants the access token for the indicated granularity. The access token is then cached by the first SCP node 10 in conjunction with the criteria (scope and granularity) of the access token (see boxes 616 and 506). The access token may be valid for a predetermined period of time; for example, the duration of this period may be indicated by NRF 60 when NRF 60 provides an access token response that includes the access token. After the predetermined period of time, the access token may expire.

[0013] As shown by box 618, the first SCP node 10 then selects the NF node of the service producer from the NF profile(s) obtained using the discovery request (in arrows 606 and 608), which in this example is the second NF node 30. The selected NF node of the service producer is the NF node corresponding to the granted access token received by the first SCP node in arrow 614. Determining which of the obtained NF node profile(s) to select (assuming more than one NF node profile has been received) depends on the specific configuration of SCP node 10.

[0014] Once an NF node has been selected (in this example, the second NF node 30), the first SCP node 10 modifies the address in the request (received from the first NF node 20) from its own address to the host address of the second NF node 30, as shown in box 620. The first SCP node 10 may optionally perform further tasks, such as NF producer node monitoring (see box 622). Then, at arrow 624, the first SCP node 10 initiates a service request transmission toward the selected second NF node 30; the access token obtained by the first SCP node 10 has been added to the service request. Figure 2A As indicated by arrow 626 (-C), the first SCP node 10 receives a response including the results from the second NF node 30. If the selected NF producer node supports binding functionality, the results may include a client binding header with binding information, intended for use by NFc in subsequent requests. The response also includes the NF instance ID and collection ID. Figure 2A As indicated by arrow 628 (-C), the first SCP node 10 initiates a transmission, including a response, towards the first NF node 20. (As shown by...) Figure 2A As shown in boxes 508 and 630 of -C, the first NF node 20 can then store the result.

[0015] exist Figure 2A In -C, steps 632-640 involve a follow-up service request for an existing UE / session context. In box 632, the first NF node 20 identifies that the follow-up result corresponds to the same UE / session context. In box 634, the first NF node 20 copies the client binding information received from the result from the second NF node 30 to the routing binding, since communication between the first NF node 10 and the second NF node 30 is indirect in this example (via the first SCP node 10); this step is not necessary if binding is not used. The first NF node 20 then sends a service request that includes the routing binding (in this example; binding is not necessarily used as mentioned above) and also includes a client credential assertion (at arrow 636). A client credential assertion may be requested if a previously obtained token has expired.

[0016] In box 638, the first SCP node 10 attempts to locate a valid access token from the stored results (see boxes 616 and 506 for access token storage). However, the information included in the subsequent request in arrow 636 does not provide a means of identifying a valid token. Although a client credential assertion is included in the subsequent request, it does not include other information that may have been provided in the discovery request in the first request (see arrow 604). The first SCP node 10 is therefore unable to locate a valid stored access token and cannot request an applicable token because the information required for a token request is not provided. In this example, S-NSSAI is not provided. Consequently, the first SCP node 10 cannot obtain a valid token, and the subsequent request process fails.

[0017] Therefore, in systems using indirect communication, after the initial request to provide discovery parameters to the SCP node to allow selection, subsequent requests for the service cannot be made by the SCP node. The SCP node cannot find a valid stored access token and does not have sufficient information to request a new access token. Summary of the Invention

[0018] One object of this disclosure is to exclude or eliminate at least some of the aforementioned disadvantages associated with the prior art.

[0019] Therefore, according to one aspect of this disclosure, a method for handling service requests in a network is provided, wherein the method is performed by a first network function NF node for a service consumer connecting to an additional NF node of a service producer via a first service communication agent (SCP) node. The method includes transmitting to the first SCP node a first request for a first service to be provided by the additional NF node. The first request includes discovery parameters and access token request parameters. The access token request parameters facilitate the first SCP node in acquiring and storing an access token, and the discovery parameters facilitate the first SCP node in selecting a second NF node of the service producer as the additional NF node to provide the first service, and the first SCP node forwards the request to the second NF node. The method further includes receiving a response forwarded by the first SCP node from the second NF node. The method also includes transmitting to the first SCP node a second request, wherein the second request is a follow-up request for the second NF node to provide the first service. The second request includes access token request parameters, and the first SCP node forwards the second request to the second NF node, wherein the second request includes a stored access token or a newly acquired access token.

[0020] In some embodiments, the first request may include a cryptographic token to enable the first SCP node to obtain an access token on behalf of the first NF node, wherein the cryptographic token may be stored together with the access token request parameters. The second request may also include a cryptographic token. The cryptographic token may be an NF service consumer client credential assertion.

[0021] In some embodiments, the second request may be to have a second NF node provide the first service in the same execution context as the first request.

[0022] In some embodiments, access token request parameters may be stored in the user equipment (UE) data record.

[0023] In some embodiments, the access token request parameters may include Single-Network Slice Selection Auxiliary Information (S-NSSAI).

[0024] In some embodiments, the method may further include a first SCP node receiving a first request for a first service to be provided by another NF node. The method may further include: obtaining a service producer NF node profile, obtaining an access token, and using the obtained service producer NF node profile to select a second NF node. The method may also include: transmitting a third request to the second NF node to allow the second NF node to provide services, the third request including the obtained access token; receiving a response from the second NF node and transmitting a response to the first NF node.

[0025] In some embodiments, the step of obtaining a service producer NF node profile may include initiating a transmission of a fourth request for the service producer NF node profile to a Network Repository Function (NRF) node using discovery parameters from the first request, and receiving a first response from the NRF node, or retrieving a stored service producer NF node profile. Furthermore, the step of obtaining an access token may include initiating a transmission of a fifth request for an access token to the NRF node using access token request parameters from the first request, and receiving a second response from the NRF node, or retrieving a stored access token. Additionally, the service producer NF node profile and / or access token may be stored.

[0026] In some embodiments, the method may further include a first SCP node receiving a second request, which is a follow-up request to a second NF node to provide a first service. The method may further include obtaining a valid access token using an access token request parameter from a second message. The method may also include: initiating a sixth request for service provision to the second NF node, the sixth request including the valid access token; receiving a response from the second NF node; and initiating a transmission to the first NF node.

[0027] According to another aspect of this disclosure, a first NF node is provided, which includes processing circuitry configured to operate according to the methods previously described with respect to the first NF node. In some embodiments, the first NF node may include at least one memory for storing instructions that, when executed by the processing circuitry, cause the first NF node to operate according to the methods previously described with respect to the first NF node.

[0028] According to another aspect of this disclosure, a method performed by a system is provided. This method may include the methods previously described with respect to a first SCP node and / or the methods previously described with respect to a first NF node.

[0029] According to another aspect of this disclosure, a system is provided. This system may include at least one first SCP node as previously described and / or at least one first NF node as previously described.

[0030] According to another aspect of this disclosure, a computer program including instructions, when executed by processing circuitry, causes the processing circuitry to perform the methods previously described with respect to the first SCP node and / or the first NF node.

[0031] According to another aspect of this disclosure, a computer program product embodied on a non-transitory machine-readable medium is provided, which includes instructions executable by processing circuitry to cause the processing circuitry to perform methods as previously described with respect to a first SCP node and / or a first NF node.

[0032] Therefore, an improved technique for handling service requests in a network is provided. Attached Figure Description

[0033] To better understand the technology and demonstrate how it can be made effective, reference will now be made to the accompanying drawings by way of example, in which:

[0034] Figure 1 AD is a block diagram illustrating different existing systems;

[0035] Figure 2A -C is a signaling diagram illustrating signal exchange in the existing system;

[0036] Figure 3 This is a block diagram illustrating a first service communication proxy (SCP) node according to an embodiment;

[0037] Figure 4 This is a flowchart illustrating a method performed by a first SCP node according to an embodiment;

[0038] Figure 5 This is a block diagram illustrating a first network function (NF) node according to an embodiment;

[0039] Figure 6 This is a flowchart illustrating a method executed by a first NF node according to an embodiment;

[0040] Figure 7A -C is a signaling diagram illustrating signal exchange in a system according to an embodiment;

[0041] Figure 8 This is a block diagram illustrating the first SCP node according to an embodiment; and

[0042] Figure 9 This is a block diagram illustrating the first NF node according to an embodiment. Detailed Implementation

[0043] This document describes techniques for handling service requests in a network. A service request may also be referred to as a request for a service. Generally, a service is software designed for management by a user. In this document, a service can be any type of service, such as a communication service (e.g., a notification service or a callback service), a context management service (e.g., a User Equipment Context Management (UECM)) service, a data management (DM) service, or any other type of service. The techniques described herein can be used with respect to any network, such as any communications or telecommunications network, such as a cellular network. The network can be a fifth-generation (5G) network or any other generation of network. In some embodiments, the network can be a core network or a radio access network (RAN). The techniques described herein are implemented by a first service communication agent (SCP) node and a first network function (NF) node (NFc node) of the service consumer. The SCP node can be configured to operate as an SCP between the NFc node and at least one NF node (NFp node) of the service producer in the network.

[0044] An NF (Network Function) is a processing function adopted or defined by the 3GPP (3rd Generation Partnership Project) in a network, possessing defined functional behavior and 3GPP-defined interfaces. An NF can be implemented as a network element on dedicated hardware, a software instance running on dedicated hardware, or a virtualized function instantiated on a suitable platform (e.g., on cloud infrastructure). In this document, the term "node" in relation to "NF node" will be understood to encompass each of these scenarios.

[0045] Figure 3 The illustration shows a first SCP node 10 according to an embodiment. The first SCP node 10 is used to handle service requests in the network. The first SCP node 10 is configured to operate as an SCP between a first network function NF node (20) that is a service consumer in the network and a second NF node (30) that is a service producer. In some embodiments, the first SCP node 10 may be, for example, a physical machine (e.g., a server) or a virtual machine (VM).

[0046] like Figure 3 As shown, the first SCP node 10 includes processing circuitry (or logic) 12. Processing circuitry 12 controls the operation of the first SCP node 10 and can implement the methods described herein with respect to the first SCP node 10. Processing circuitry 12 may be configured or programmed to control the first SCP node 10 in the manner described herein. Processing circuitry 12 may include one or more hardware components, such as one or more processors, one or more processing units, one or more multi-core processors, and / or one or more modules. In a particular implementation, each of the one or more hardware components may be configured to perform or be used to perform individual or multiple steps of the methods described herein with respect to the first SCP node 10. In some embodiments, processing circuitry 12 may be configured to run software to perform the methods described herein with respect to the first SCP node 10. According to some embodiments, the software may be containerized. Thus, in some embodiments, processing circuitry 12 may be configured to run a container to perform the methods described herein with respect to the first SCP node 10.

[0047] In short, the processing circuitry 12 of the first SCP node 10 is configured to receive (from the first NF node 20, the consumer NF node) a first request for a first service to be provided by another NF node (which is a provider NF node). The processing circuitry 12 of the first SCP node 10 is further configured to acquire the service producer NF node profile and access token, and use the acquired service producer NF node profile to select a second NF node 30. The processing circuitry 12 of the first SCP node 10 is also configured to: initiate a transmission to the second NF node 30 of a third request for the second NF node 30 to provide services, the third request including the acquired access token; receive a response from the second NF node 30; and initiate a response transmission to the first NF node 20.

[0048] like Figure 3 As shown, in some embodiments, the first SCP node 10 may optionally include memory 14. The memory 14 of the first SCP node 10 may include volatile memory or non-volatile memory. In some embodiments, the memory 14 of the first SCP node 10 may include non-transitory media. Examples of the memory 14 of the first SCP node 10 include, but are not limited to, random access memory (RAM), read-only memory (ROM), mass storage media such as hard disks, removable storage media such as CDs or DVDs, and / or any other memory.

[0049] The processing circuitry 12 of the first SCP node 10 may be connected to the memory 14 of the first SCP node 10. In some embodiments, the memory 14 of the first SCP node 10 may be used to store program code or instructions that, when executed by the processing circuitry 12 of the first SCP node 10, cause the first SCP node 10 to operate in the manner described herein with respect to the first SCP node 10. For example, in some embodiments, the memory 14 of the first SCP node 10 may be configured to store program code or instructions executable by the processing circuitry 12 of the first SCP node 10 to cause the first SCP node 10 to operate according to the methods described herein with respect to the first SCP node 10. Alternatively or additionally, the memory 14 of the first SCP node 10 may be configured to store any information, data, messages, requests, responses, indications, notifications, signals, or the like described herein. The processing circuitry 12 of the first SCP node 10 may be configured to control the memory 14 of the first SCP node 10 to store the information, data, messages, requests, responses, indications, notifications, signals, or the like described herein.

[0050] In some embodiments, such as Figure 3 As shown, the first SCP node 10 may optionally include a communication interface 16. The communication interface 16 of the first SCP node 10 may be connected to the processing circuitry 12 of the first SCP node 10 and / or the memory 14 of the first SCP node 10. The communication interface 16 of the first SCP node 10 may be operable to allow the processing circuitry 12 of the first SCP node 10 to communicate with the memory 14 of the first SCP node 10, and / or vice versa. Similarly, the communication interface 16 of the first SCP node 10 may be operable to allow the processing circuitry 12 of the first SCP node 10 to communicate with the first NF node and / or any other node. The communication interface 16 of the first SCP node 10 may be configured to transmit and / or receive information, data, messages, requests, responses, indications, notifications, signals, or the like described herein. In some embodiments, the processing circuitry 12 of the first SCP node 10 may be configured to control the communication interface 16 of the first SCP node 10 to transmit and / or receive information, data, messages, requests, responses, indications, notifications, signals, or the like described herein.

[0051] Despite the fact that the first SCP node 10 is in Figure 3 While shown as including a single memory 14, it will be appreciated that the first SCP node 10 may include at least one memory (i.e., a single memory or multiple memories) 14 operating in the manner described herein. Similarly, although the first SCP node 10 is shown as including a single memory 14, it may also include at least one memory (i.e., a single memory or multiple memories) 14 operating in the manner described herein. Figure 3The diagram is illustrated to include a single communication interface 16, but it will be appreciated that the first SCP node 10 may include at least one communication interface (i.e., a single communication interface or multiple communication interfaces) 16 operating in the manner described herein. It will also be appreciated that... Figure 3 Only the components required to illustrate the embodiment of the first SCP node 10 are shown, and in actual implementation, the first SCP node 10 may include additional or alternative components to those shown.

[0052] Figure 4 This is a flowchart illustrating a method performed by a first SCP node 10 according to an embodiment. The first SCP node 10 is configured to operate as an SCP between a first NF node (service consumer) and a second NF node (service producer) in the network. The method is used to handle service requests in the network. (Previous Reference) Figure 3 The first SCP node 10 described can be configured according to Figure 4 The method of operation can be executed by or under the control of the processing circuitry 12 of the first SCP node 10.

[0053] When a first request for the first service to be provided is received from the first NF node 20, the execution is performed. Figure 4 The method (see) Figure 4 (Box 102). See below for reference. Figure 5 The initiation of the first request transmission by the first NF node 20 is discussed. Upon receiving the first request, the first SCP node 10 acquires a service producer NF node (NFp) profile (see box 104). The NFp profile can be acquired from NRF 60; the first SCP node 10 can submit a discovery request to NRF 60 and then receive a response from NRF 60 including the NFp profile. In the case of a discovery request using NRF 60, the discovery request may use discovery parameters included in the first request from the first NF node 20, and may also include parameters from the first SCP node 10 based on its local configuration. The acquired NFp profile can then be stored by the first SCP node 10. Alternatively, if the stored NFp profile is available, the first SCP node 10 can retrieve the stored NFp profile from a storage device that is part of or connected to the first SCP node 10.

[0054] As shown in box 106, the first SCP node 10 also acquires one or more access tokens. Access tokens can be acquired from the NRF 60 by submitting an access token request and receiving an access token response including one or more access tokens. The access token request may include access token request parameters, which may form part of the discovery parameters sent by the first SCP node 20 in a first request. The access token request parameters may include cryptographic tokens, such as client credential assertions from the first SCP node 20. Using such cryptographic tokens, the first SCP node 10 may be able to acquire access tokens on behalf of the first SCP node 20. The acquired access tokens (one or more) may then be stored by the first SCP node 10. The first SCP node 10 may also include information in the access token request that is not obtained from the discovery parameters, such as the range of the requested tokens (one or more), the granularity of the requested tokens (one or more), etc. Alternatively, if stored access tokens are available, the first SCP node 10 may retrieve the stored access tokens from a storage device that is part of or connected to the first SCP node 10.

[0055] Then, the first SCP node 10 uses the acquired NFp profile and, referring to the acquired access token, selects one of the NFp nodes for which a profile has already been obtained (see box 108). That is, the first SCP node 10 may preferentially select an NFp node for which an access token has already been obtained, or may select only NFp nodes for which an access token has already been obtained. In the following text, for ease of understanding, the selected NFp node may be referred to as the second NF node 30.

[0056] The first SCP node 10 has already selected an NFp node (second NF node 30). Then, the first SCP node 10 initiates a transmission to the second NF node 30 requesting that the second NF node 30 provide the first service 40 to the first NF node 20, as if... Figure 4 As shown in box 110. The request sent to the second NF node 30 is essentially the same as the first request received by the first SCP node 10 from the first NF node 20, but the SCP address is replaced by the address of the second NF node and the access token obtained by the first SCP node 10 is included in the request.

[0057] In this document, the term "initiate" may mean, for example, causing or establishing. Thus, the processing circuitry 12 of the first SCP node 10 may be configured to transmit information itself (e.g., via the communication interface 16 of the first SCP node 10), or may be configured to cause another node to transmit information. Similarly, in the case where the first NF node 20 initiates a transmission, the first NF node 20 may be configured to transmit information itself (e.g., via the communication interface 26 of the first NF node 020), or may be configured to cause another node to transmit information.

[0058] Then, the first SCP node 10 receives a response to the request from the second NF node 30 (including the NF instance ID, and potentially binding information if binding is used), and initiates the transmission of the response to the first NF node 20 (see box 112). Upon receiving the response, the first NF node 20 may store the information in the execution context, such as the UE / session context, as discussed in detail below.

[0059] The first SCP node 10 may be further configured to receive a follow-up request from the first NF node 20, which requests the second NF node 30 to provide the first service. As discussed in more detail below, the follow-up request may include access token request parameters, which the first SCP node 10 may use to obtain a valid access token. If the first SCP node already stores a valid access token, the access token request parameters from the follow-up request can be used to retrieve that access token. Alternatively, if the first SCP node does not store a valid access token (either because no valid token is stored, or because a previously valid stored token has expired), the access token request parameters may be used, for example, to request a new access token from NRF 60. Once a valid access token has been obtained using the access token request parameters from the follow-up request, the first SCP node 10 may then initiate a transmission to the second NF node 30 requesting the provision of services; this request may be substantially the same as the follow-up request received by the first SCP node 10 from the first NF node 20, but in which the SCP address is replaced by the address of the second NF node 30 and the access token obtained by the first SCP node 10 is included in the request. Upon receiving a response from the second NF node 30, the first SCP node 10 may then initiate the transmission of that response to the first NF node 20.

[0060] Figure 5 The illustration shows a first NF node 20 according to an embodiment. The first NF node 20 is used to handle service requests in the network. The first NF node 20 is configured to operate as a first NF node serving a service. In some embodiments, the first NF node 20 may be, for example, a physical machine (e.g., a server) or a virtual machine (VM). The first NF node 20 may be, for example, a user equipment (UE).

[0061] like Figure 5 As shown, the first NF node 20 includes processing circuitry (or logic) 22. Processing circuitry 22 controls the operation of the first NF node 20 and can implement the methods described herein with respect to the first NF node 20. Processing circuitry 22 may be configured or programmed to control the first NF node 20 in the manner described herein. Processing circuitry 22 may include one or more hardware components, such as one or more processors, one or more processing units, one or more multi-core processors, and / or one or more modules. In a particular implementation, each of the one or more hardware components may be configured to perform or be used to perform individual or multiple steps of the methods described herein with respect to the first NF node 20. In some embodiments, processing circuitry 22 may be configured to run software to perform the methods described herein with respect to the first NF node 20. According to some embodiments, the software may be containerized. Thus, in some embodiments, processing circuitry 22 may be configured to run a container to perform the methods described herein with respect to the first NF node 20.

[0062] In short, the processing circuitry 22 of the first NF node 20 is configured to initiate a transmission to the first SCP node 10 of a first request for the provision of a first service 40 by another NF node (which is a service provider NF node). The first request includes discovery parameters, which include access token request parameters, wherein the discovery parameters facilitate the selection by the first SCP node 10 of a second NF node 30 as the other NF node providing the first service 40. In addition to including the access token request parameters in the discovery parameters, the access token request parameters may also be sent in a separate header of the discovery parameters (e.g., an access token parameter header). Besides initiating the transmission of the first request, the processing circuitry 22 of the first NF node 20 is also configured to store the access token request parameters and (via the first SCP node 10) receive a response from the second NF node 30. The processing circuitry 22 of the first NF node 20 is also configured to initiate a transmission of a second request to the first SCP node 10, wherein the second request is a subsequent request for the second NF node 30 to provide the first service 40. The second request includes stored access token request parameters, which can be used (e.g., by the first SCP node 10) to identify the stored access token or request an access token.

[0063] like Figure 5As shown, in some embodiments, the first NF node 20 may optionally include memory 24. The memory 24 of the first NF node 20 may include volatile memory or non-volatile memory. In some embodiments, the memory 24 of the first NF node 20 may include non-transitory media. Examples of the memory 24 of the first NF node 20 include, but are not limited to, random access memory (RAM), read-only memory (ROM), mass storage media such as hard disks, removable storage media such as CDs or DVDs, and / or any other memory.

[0064] The processing circuitry 22 of the first NF node 20 may be connected to the memory 24 of the first NF node 20. In some embodiments, the memory 24 of the first NF node 20 may be used to store program code or instructions that, when executed by the processing circuitry 22 of the first NF node 20, cause the first NF node 20 to operate in the manner described herein with respect to the first NF node 20. For example, in some embodiments, the memory 24 of the first NF node 20 may be configured to store program code or instructions executable by the processing circuitry 22 of the first NF node 20 to cause the first NF node 20 to operate according to the methods described herein with respect to the first NF node 20. Alternatively or additionally, the memory 24 of the first NF node 20 may be configured to store any information, data, messages, requests, responses, indications, notifications, signals, or the like described herein. The processing circuitry 22 of the first NF node 20 may be configured to control the memory 24 of the first NF node 20 to store the information, data, messages, requests, responses, indications, notifications, signals, or the like described herein.

[0065] In some embodiments, such as Figure 5 As shown, the first NF node 20 may optionally include a communication interface 26. The communication interface 26 of the first NF node 20 may be connected to the processing circuitry 22 of the first NF node 20 and / or the memory 24 of the first NF node 20. The communication interface 26 of the first NF node 20 may be operable to allow the processing circuitry 22 of the first NF node 20 to communicate with the memory 24 of the first NF node 20, and / or vice versa. Similarly, the communication interface 26 of the first NF node 20 may be operable to allow the processing circuitry 22 of the first NF node 20 to communicate with the first SCP node 10 and / or any other node. The communication interface 26 of the first NF node 20 may be configured to transmit and / or receive information, data, messages, requests, responses, indications, notifications, signals, or the like described herein. In some embodiments, the processing circuitry 22 of the first NF node 20 may be configured to control the communication interface 26 of the first NF node 20 to transmit and / or receive information, data, messages, requests, responses, indications, notifications, signals, or the like described herein.

[0066] Although the first NF node 20 is in Figure 5 While shown as including a single memory 24, it will be appreciated that the first NF node 20 may include at least one memory (i.e., a single memory or multiple memories) 24 operating in the manner described herein. Similarly, although the first NF node 20 is shown as including a single memory 24, it may also include at least one memory (i.e., a single memory or multiple memories) 24 operating in the manner described herein. Figure 5 The diagram is illustrated to include a single communication interface 26, but it will be appreciated that the first NF node 20 may include at least one communication interface (i.e., a single communication interface or multiple communication interfaces) 26 operating in the manner described herein. It will also be appreciated that... Figure 5 Only the components required to illustrate the embodiment of the first NF node 20 are shown, and in actual implementation, the first NF node 20 may include additional or alternative components to those shown.

[0067] Figure 6 This is a flowchart illustrating a method performed by the first NF node 20 according to an embodiment. Figure 6 This method is used to handle service requests in the network. (Previous reference) Figure 5 The first NF node 20 described is configured according to Figure 6 The method of operation can be executed by or under the control of the processing circuitry 22 of the first NF node 20. The first SCP node 10 is configured to operate as an SCP between the first NF node 20 and the second NF node of the service producer in the network.

[0068] implement Figure 6 The method is used to connect to an additional NF node (such as a second NF node 40) of the service producer via a first SCP node 10. A first request is made for the second NF node to provide the first service (40), and a transmission of the first request is initiated to the first SCP node 10 (see box 202). The first request includes discovery parameters, which include access token request parameters, wherein the discovery parameters facilitate the selection by the first SCP node 10 of the second NF node 30 of the service producer as the second NF node to provide the first service 40. The access token request parameters are stored by the first NF node 10 (see box 204). The access token request parameters may include, for example, an encrypted token, such as a client credential assertion of the first NF node 20 (NF service consumer client credential assertion) or another type of encrypted token. Using such an encrypted token, the first SCP node 10 may be able to obtain an access token on behalf of the first NF node 20. In the case where the first request includes an encrypted token, this may be stored as part of the access token request parameters.

[0069] Access token request parameters may be stored in the execution context of the first request, which may be a UE / session context, a Protocol Data Unit (PDU) / session context, or another context. Specifically, access token request parameters may be stored in a UE data record. Access token request parameters may further include various other information, such as Single-Network Slice Selection Auxiliary Information (S-NSSAI), Fully Qualified Domain Name (FQDN), etc. A discussion of various parameters that can be included in the access token request can be found in 3GPP TS29.510V 16.4.0, as cited above. In particular, section 6.3.5.2.2 of the cited document provides an overview of the relevant data types. A corresponding overview of the discovered data types can be found in section 6.2.3.2.3.1 of the same cited document. Once received by the first SCP node 10, the access token request parameters may potentially be used in conjunction with other parameters (such as range information not derived from the access token request parameters in the first request) to obtain an access token. The method further includes receiving a response from the second NF node 30 via the first SCP node 10 (see box 206).

[0070] The method further includes transmitting a second request to the first SCP node 10 (see box 208). The second request is a follow-up request to the provision of the first service; this follow-up request is for the first service to be provided by the second NF node 30. The second request includes at least a portion of the stored access token request parameters included in the discovery parameters sent in the first request. The access token request parameters may be sent in a specific access token parameter header in the follow-up request. If the stored access token request parameters include an encrypted token (as discussed above), the encrypted token may be included in the second request. The access token request parameters in the second request allow the first SCP node 10 to obtain a valid access token; a valid access token may be obtained by retrieving a stored access token or by requesting an access token (e.g., from NRF 60). In the case of retrieving a stored access token, the first SCP node 10 uses the access token parameters to locate the stored access token. If no valid stored access token is available, either because no stored access token is available or because the stored access token has expired (timed out), a new access token can be requested from NRF 60 using the access token parameter, following a process similar to that used to obtain an access token for the first request. Using the obtained access token, the first SCP node 10 can then send a request to the second NF node 30, receive a response passed to the first NF node 20, and so on.

[0071] A system is also provided. This system may include at least one first SCP node 10 as described herein and / or at least one first NF node 20 as described herein. The system may also include any one or more of the other nodes mentioned herein.

[0072] Figure 7A -C is a signaling diagram illustrating signal exchange. Figure 7A The system shown in -C includes a first SCP node 10, a first NF node 20 (“NFc”) for a service consumer, a second NF node 30 (“NFp1”) for a service producer, and a third NF node 70 (“NFp2”) for a service producer. The first SCP node 10 is configured to operate as an SCP between the first NF node 20 and the second NF node 30. The second NF node 30 may be configured to provide (e.g., perform or run) service 40, and the third NF node 70 may be configured to provide (e.g., perform or run) service 80. The second NF node 30 and the third NF node 70 may be configured to provide (e.g., perform or run) the same service or different services. The second NF node 30 and the third NF node 70 may be part of a set of NF nodes 402 for the service producer. Figure 2A The system shown in -C also includes NRF 60. In some embodiments, the entity may include the first SCP node 10 and NRF 60. That is, in some embodiments, the first SCP node 10 may be combined with NRF 60 in a single combined entity.

[0073] In some embodiments, the first SCP node 10 and the first NF node 20 may be deployed in separate deployment units, and / or the first SCP node 10 and the second NF node 30 may be deployed in separate deployment units. Thus, SCP nodes based on separate deployment units are possible, as described in 3GPP TS 23.501v16.5.0 (as cited above). In other embodiments, the first SCP node 10 may be deployed as a distributed network element. For example, in some embodiments, a portion of the first SCP node 10 (e.g., a service proxy) may be deployed in the same deployment unit as the first NF node 20, and / or a portion of the first SCP node 10 (e.g., a service proxy) may be deployed in the same deployment unit as the second NF node 30. Thus, SCP nodes based on service meshes are possible, as described in 3GPP TS 23.501v16.5.0.

[0074] In some embodiments, at least one second SCP node may be configured as an SCP operation between the first NF node 20 and the first SCP node 10, and / or at least one third SCP node may be configured as an SCP operation between the first SCP node 10 and the second NF node 30. Thus, multipathing of the SCP nodes is possible. In some embodiments of these embodiments, one or both of the at least second SCP node and the at least third SCP node, as well as the first SCP node 10, may be deployed in separate deployment units. In some embodiments, at least one second SCP node and / or at least one third SCP node may be deployed as distributed network elements.

[0075] Figure 7A -C steps 500, 504, 506, and 508, as well as 600-638, are as previously referenced. Figure 2A As described by -C. Figure 2A The example shown in -C and Figure 7A Some key differences between the -C implementations are as follows. In step 700, similar to step 602, the first NF node 20 stores the context (UE / session context, PDU / session context, etc.). Step 700 includes additionally storing access token request parameters that can be used by the first SCP node 10 to obtain an access token. As mentioned above... Figure 4 and Figure 6 As discussed in the context, the access token request parameters may include an encrypted token, which, if present, may also be stored in step 700. Then, in step 604, the access token request parameters may be sent (as part of the discovery parameters) to the first SCP node 10, and the process of the first request is as follows: Figure 2A -C is indicated. In step 632, the process related to subsequent requests for the same service begins. Subsequent requests can be a second request, a third request, a fourth request, and so on. Figure 7A In the embodiment shown in -C, binding has been used, and therefore, in step 634, the client binding information provided to the first NF node 20 is included as routing binding information; as mentioned earlier, the use of binding is optional and not mandatory. In step 702, a subsequent service request is sent to the first SCP node 10. However, since the access token request parameters were stored by the first NF node 20 in step 700, these parameters can also be included in the subsequent request in step 702. Figure 7A In the embodiment shown in -C, the cryptographic token (in this example, the client credential assertion) is included as part of the access token request parameters.

[0076] The first SCP node 10 receives subsequent requests and, in step 638, attempts to locate a valid access token. Figure 2A In the example shown by -C, the attempt failed because the information included in the subsequent request of arrow 636 did not provide a means of identifying a valid token. Figure 2A The first SCP node in -C also cannot request an applicable token because the information required for a token request is not provided in subsequent requests in this example. In contrast, including Figure 7A The access token request parameter in the subsequent request of the embodiment shown in -C allows (e.g., from the memory of the first SCP node 10) to retrieve a stored access token. In this embodiment, S-NSSAI is required and is included in the access token request parameter. In this embodiment, the stored access token is valid; however, even if the stored access token is invalid (i.e., does not exist or has expired, or requires a token of a different range), the access token request parameter included in the subsequent request can still be used by the first SCP node 10 to obtain a new access token from NRF 60. In some embodiments, the first SCP node 10 may be combined with NRF 60, and the access token request parameter can therefore be used to retrieve an access token from the NRF combined with the first SCP node 10.

[0077] Because the first SCP node 10 can obtain a valid access token, unlike Figure 2A The process shown in -C is... Figure 7A The subsequent request process in the embodiment shown in -C will not fail. Instead, steps similar to those that occurred in the first request are performed. SCP node 10 modifies the address in the request (received from first NF node 20) from the address of first SCP node 10 to the address of the host of second NF node 30, as shown in box 704. Then, optional additional tasks (such as monitoring) can be performed by first SCP node 10, as shown in step 706. Then, in step 708, first SCP node 10 initiates a transmission of a subsequent service request toward the selected second NF node 30; a valid access token obtained by first SCP node 10 has been added to the service request. In step 710, first SCP node 10 receives a response including the result from second NF node 30, and then in step 712, the response is sent to first NF node 20 and stored in the execution context (steps 714 and 716, in this embodiment, the execution context is the UE / session context). Therefore, as a result of including the access token request parameter in the subsequent service request, a valid access token is obtained, which is either a stored token or a new token, and the request process can succeed.

[0078] Figure 8This is a block diagram illustrating a first SCP node 10 according to an embodiment. The first SCP node 10 can handle service requests in the network. The first SCP node 800 can operate as an SCP between a first NF node (service consumer) and a second NF node (service producer) in the network. The first SCP node 800 includes: a receiving module 802 configured to receive a first request from the first NF node 20 requesting the provision of a first service. The first SCP node 800 includes: an acquisition module 808 configured to acquire a service producer NF node profile and an access token. The first SCP node 800 also includes: a selection module 806 configured to select a producer NF node (such as the second NF node 30) using the acquired service producer NF node profile. The first SCP node 800 additionally includes: a transmission module 804 configured to initiate the transmission of a request to provide service to the selected producer NF node, the request including the acquired access token. The receiving module is further configured to receive a response from the second NF node 30. The first SCP node 10 can operate in the manner described herein with respect to any process performed by the first SCP node.

[0079] Figure 9 This is a block diagram illustrating a first NF node 20 of a service consumer according to an embodiment. The first NF node 20 can handle service requests in the network, and in particular, can operate as a first NF node of a service consumer. The first NF node 20 includes: a transmission module 902 configured to initiate the transmission of a first request for a first service to be provided by another NF node, the first request being transmitted to a first SCP node 10. The first request includes discovery parameters, the discovery parameters including access token request parameters, wherein the discovery parameters facilitate the selection by the first SCP node 10 of a second NF node 30 as another NF node providing the first service 40. The first NF node 20 also includes: a storage module 904 configured to store the access token request parameters, wherein the access token request parameters may be stored, for example, in an execution context. The first NF node 20 further includes: a receiving module 906 configured to receive a response from the second NF node. The transmission module 902 is further configured to transmit a second request to the first SCP node 10, which is a follow-up request to the second NF node 30 to provide the first service 40, wherein the second request includes access token request parameters that can be used to identify the stored access token or request the stored access token. The second request may be to allow the second NF node 30 to provide the first service 40 in the same execution context as the first request (e.g., UE / session context or PDU / session context). The first NF node 20 may operate in the manner described herein with respect to any procedures performed by the first NF node.

[0080] A computer program including instructions, when executed by processing circuitry (such as processing circuitry 12 of the previously described first SCP node 10 and / or processing circuitry 22 of the previously described first NF node 20), is provided to cause the processing circuitry to perform at least a portion of the methods described herein. A computer program product embodied on a non-transitory machine-readable medium is provided, comprising instructions executable by processing circuitry (such as processing circuitry 12 of the previously described first SCP node 10 and / or processing circuitry 22 of the previously described first NF node 20) to cause the processing circuitry to perform at least a portion of the methods described herein. A computer program product including a carrier containing instructions for causing processing circuitry (such as processing circuitry 12 of the previously described first SCP node 10 and / or processing circuitry 22 of the previously described first NF node 20) to perform at least a portion of the methods described herein. In some embodiments, the carrier may be any of an electronic signal, optical signal, electromagnetic signal, electrical signal, radio signal, microwave signal, or computer-readable storage medium.

[0081] Other embodiments include those defined in the following numbered statements:

[0082] Statement 1. A method for handling service requests in a network, wherein the method is performed by a first network function NF node (20) for a service consumer to connect to an additional NF node of a service producer via a first service communication proxy SCP node (10), the method comprising:

[0083] Transmission (604) is initiated to the first SCP node (10) for a first request to be provided by the other NF node for a first service (40), wherein the first request includes discovery parameters, the discovery parameters include access token request parameters, wherein the discovery parameters facilitate the selection by the first SCP node (10) of a second NF node (30) as the other NF node providing the first service (40);

[0084] Store (700) the access token request parameters;

[0085] Receive (628) a response from the second NF node (30); and

[0086] Transmission (702) of a second request is initiated to the first SCP node (10), the second request being a follow-up request to the second NF node (30) to provide the first service (40), wherein the second request includes access token request parameters of the storage that can be used to identify the storage access token or request the storage access token.

[0087] Declaration 2. The method of Declaration 1, wherein:

[0088] The first request further includes an encrypted token to enable the first SCP node (10) to obtain an access token on behalf of the first NF node (20);

[0089] The encryption token is stored together with the access token request parameters; and

[0090] The second request includes the cryptographic token.

[0091] Statement 3. The method of Statement 2, wherein the cryptographic token is an NF service consumer client credential assertion.

[0092] Statement 4. Any of the methods stated above, wherein the second request is to have the second NF node (30) provide the first service (40) in the same execution context as the first request.

[0093] Statement 5. Any of the methods stated above, wherein the access token request parameters are stored in the user equipment (UE) data record.

[0094] Statement 6. Any of the methods stated above, wherein the access token request parameter includes Single-Network Slice Selection Auxiliary Information (S-NSSAI).

[0095] Statement 7. Any of the methods stated above further includes: by the first SCP node (10):

[0096] Receive (604) the first request for the first service (40) provided by the other NF node;

[0097] Obtain the (606, 608) service producer NF node profile;

[0098] Obtain access tokens (612, 614) using the access token parameters from the first request;

[0099] Use the obtained service producer NF node profile to select (618) the second NF node (30);

[0100] Transmission (624) of a third request to the second NF node (30) to provide services, the third request including the acquired access token;

[0101] Receive (626) the response from the second NF node (30) and initiate transmission (628) to the first NF node (20).

[0102] Statement 8. The method of Statement 7, wherein the steps for obtaining the NF node profile of the service producer include:

[0103] Initiate a transmission (606) to the Network Repository Function (NRF) node (60) of a fourth request for the service producer NF node profile using the discovery parameters from the first request, and receive (608) a first response from the NRF node (60); or

[0104] Retrieve storage service generator NF node profile.

[0105] Statement 9. Any of the methods stated in Statements 7 and 8, wherein the step of obtaining an access token comprises: initiating (612) a transmission of a fifth request for an access token to the NRF node using the access token request parameters from the first request, and receiving (614) a second response from the NRF node; or

[0106] Retrieve the stored access token.

[0107] Statement 10. Any of the methods stated in Statements 7 to 9, further comprising: by the first SCP node (10): storing (610) the service producer NF node profile; and / or

[0108] Store the access token (616).

[0109] Statement 11. Any of the methods stated in Statements 7 to 10, further comprising: by the first SCP node (10): receiving (702) the second request, the second request being a subsequent request for the second NF node (30) to provide the first service (40);

[0110] A valid access token (638) is obtained using the access token request parameters from the second message;

[0111] Transmit (708) a sixth request for service provision to the second NF node (30), the sixth request including a valid access token;

[0112] Receive (710) the response from the second NF node (30) and initiate transmission (712) to the first NF node (20).

[0113] Statement 12. Any of the methods stated in the foregoing, wherein:

[0114] The first SCP node (10) and the first NF node (20) are deployed in separate deployment units; and / or the first SCP node (10) and the second NF node (30) are deployed in separate deployment units.

[0115] Declaration 13. Any of the methods declared in Declarations 1 through 11, wherein:

[0116] The first SCP node (10) is deployed as a distributed network element.

[0117] Declaration 14. The method of Declaration 13, wherein:

[0118] A portion of the first SCP node (10) is deployed in the same deployment unit as the first NF node (20); and / or

[0119] A portion of the first SCP node (10) was deployed in the same deployment unit as the second NF node (30).

[0120] Statement 15. Any of the methods stated in the foregoing, wherein:

[0121] At least one second SCP node is configured to operate as an SCP between the first NF node (20) and the first SCP node (10); and / or

[0122] At least one third SCP node is configured to operate as an SCP between the first SCP node (10) and the second NF node (30).

[0123] Declaration 16. The method of Declaration 15, wherein:

[0124] At least one or both of the second SCP node and at least one third SCP node, along with the first SCP node (10), are deployed in a separate deployment unit.

[0125] Declaration 17. The method of Declaration 15, wherein:

[0126] At least one second SCP node and / or at least one third SCP node are deployed as distributed network elements.

[0127] Statement 18. Any of the methods stated in the foregoing, wherein:

[0128] The entities include the first SCP node (10) and the NRF node (60).

[0129] Declaration 19. A first NF node (20), comprising:

[0130] Processing circuit (22) is configured to operate according to any of the statements 1 to 6.

[0131] Declaration 20. The first node (20) of Declaration 19, where:

[0132] The first NF node (20) includes:

[0133] At least one memory (24) is used to store instructions that, when executed by the processing circuit (22), cause the first NF node (20) to operate according to any of the statements 1 to 6.

[0134] Statement 21. A system comprising:

[0135] The first NF node (20) of any of the statements in statements 19 and 20;

[0136] It further includes a first SCP node (10) which includes processing circuitry (12) configured to operate in accordance with any of the statements 7 to 11.

[0137] Declaration 22. The system of Declaration 21, wherein:

[0138] The first SCP node (10) includes:

[0139] At least one memory (14) for storing instructions that, when executed by the processing circuit (12), cause the first SCP node (10) to operate according to any of the statements 7 to 11.

[0140] Statement 23. A computer program comprising instructions that, when executed by processing circuitry, cause the processing circuitry to perform a method according to any one of statements 1 to 6 and / or a method according to any one of statements 7 to 11.

[0141] Statement 24. A computer program product embodied on a non-transitory machine-readable medium, comprising instructions executable by processing circuitry to cause the processing circuitry to perform a method according to any of statements 1 to 6 and / or any of statements 7 to 11.

[0142] In some embodiments, the first SCP node functionality and / or the first NF node functionality described herein may be executed by hardware. Thus, in some embodiments, any one or more of the first SCP node 10 and the first NF node 20 described herein may be hardware nodes. However, it will also be understood that, optionally, at least some or all of the first SCP node functionality and / or the first NF node functionality described herein may be virtualized. For example, the functionality performed by any one or more of the first SCP node 10 and the first NF node 20 described herein may be implemented using software running on general-purpose hardware configured to orchestrate node functionality. Thus, in some embodiments, any one or more of the first SCP node 10 and the first NF node 20 described herein may be virtual nodes. In some embodiments, at least some or all of the first SCP node functionality and / or the first NF node functionality described herein may be executed in a network-enabled cloud. The first SCP node functionality and / or the first NF node functionality described herein may all be in the same location, or at least some of the node functionalities may be distributed.

[0143] It will be understood that, in some embodiments, at least some or all of the method steps described herein can be automated. That is, in some embodiments, at least some or all of the method steps described herein can be performed automatically. The methods described herein can be computer-implemented methods.

[0144] Therefore, an improved technique for handling service requests in a network is advantageously provided in the manner described herein. The first NF node 20 can store access token request parameters and include the stored parameters in subsequent service requests. Using the provided access token request parameters, the first SCP node 10 can retrieve a valid access token and make the subsequent service request. This correspondingly improves system performance.

[0145] It should be noted that the embodiments mentioned above are illustrative and not limiting, and those skilled in the art will be able to devise many alternative embodiments without departing from the scope of the appended claims. The word "comprising" does not exclude the presence of elements or steps different from those listed in the claims, "a (or an)" does not exclude multiple, and a single processor or other unit may perform the functions of several units recited in the claims. No reference numerals in the claims should be construed as limiting their scope.

Claims

1. A method for handling service requests in a network, wherein, The method is performed by a first network function NF node (20) of a service consumer for connecting to an additional NF node of a service producer via a first service communication proxy SCP node (10), the method comprising: Transmission (604) is initiated to the first SCP node (10) for a first request to be provided by the other NF node for a first service (40), wherein the first request includes discovery parameters and access token request parameters, wherein: the access token request parameters facilitate the first SCP node (10) to obtain and store an access token; and the discovery parameters facilitate the first SCP node (10) to select a second NF node (30) as the other NF node to provide the first service (40), and the first SCP node (10) forwards the first request to the second NF node (30); Receive (628) a response forwarded by the first SCP node (10) from the second NF node (30); and Transmission (702) of a second request is initiated to the first SCP node (10), the second request being a follow-up request to the second NF node (30) to provide the first service (40), wherein the second request includes the access token request parameters, and wherein the first SCP node (10) forwards the second request to the second NF node (30), wherein the second request includes a stored access token or a newly acquired access token.

2. The method of claim 1, wherein: The first request further includes an encrypted token to enable the first SCP node (10) to obtain an access token on behalf of the first NF node (20); The encryption token is stored together with the access token request parameters; as well as The second request includes the cryptographic token.

3. The method as described in claim 2, wherein, The encrypted token is an NF service consumer client credential assertion.

4. The method as claimed in any of the preceding claims, wherein, The second request is to have the second NF node (30) provide the first service (40) in the same execution context as the first request.

5. The method as claimed in any of the preceding claims, wherein, The access token request parameters are stored (700) in the user equipment (UE) data record.

6. The method as claimed in any of the preceding claims, wherein, The access token request parameters include Single Network Slice Selection Auxiliary Information (S-NSSAI).

7. The method of any of the preceding claims, further comprising: From the first SCP node (10): Receive (604) the first request for the first service (40) provided by the other NF node; Obtain the (606, 608) service producer NF node profile; Obtain access tokens (612, 614) using the access token request parameters from the first request; Use the obtained service producer NF node profile to select (618) the second NF node (30); Transmission (624) of a third request to the second NF node (30) to provide services, the third request including the acquired access token; Receive (626) the response from the second NF node (30) and initiate transmission (628) to the first NF node (20).

8. The method of claim 7, wherein, The profile of the NF node for obtaining the service producer includes: Initiate a transmission (606) to the Network Repository Function (NRF) node (60) of a fourth request for the service producer NF node profile using the discovery parameters from the first request, and receive (608) a first response from the NRF node (60); or Retrieve storage service generator NF node profile.

9. The method of any one of claims 7 and 8, wherein, The process of obtaining the access token includes: Initiate a transmission (612) to the NRF node of a fifth request for an access token using the access token request parameters from the first request, and receive (614) a second response from the NRF node; or Retrieve the stored access token.

10. The method of any one of claims 7 to 9, further comprising: The first SCP node (10): storage (610) of the service producer NF node profile; and / or Store the access token (616).

11. The method of any one of claims 7 to 10, further comprising: The first SCP node (10) receives (702) the second request, which is a subsequent request for the second NF node (30) to provide the first service (40); Obtain (638) a valid access token using the access token request parameters from the second request; Transmit (708) a sixth request for service provision to the second NF node (30), the sixth request including a valid access token; Receive (710) the response from the second NF node (30) and initiate transmission (712) to the first NF node (20).

12. A first NF node (20), comprising: The processing circuit (22) is configured to operate according to the method of any one of claims 1 to 6.

13. The first node (20) as claimed in claim 12, wherein: The first NF node (20) includes: At least one memory (24) for storing instructions that, when executed by the processing circuit (22), cause the first NF node (20) to operate according to any one of claims 1 to 6.

14. A system comprising: The first NF node (20) as described in any one of claims 12 and 13; It further includes a first SCP node (10), which includes a processing circuit (12) configured to operate according to any one of claims 7 to 11.

15. The system of claim 14, wherein: The first SCP node (10) includes: At least one memory (14) for storing instructions that, when executed by the processing circuit (12), cause the first SCP node (10) to operate according to any one of claims 7 to 11.

16. An apparatus comprising corresponding components for performing the method according to any one of claims 1 to 6 and / or the method according to any one of claims 7 to 11.

17. A machine-readable medium storing a computer program, comprising instructions executable by processing circuitry to cause the processing circuitry to perform the method according to any one of claims 1 to 6 and / or the method according to any one of claims 7 to 11.