Communication method and communication apparatus

By using the first network element to provide home network information to the DNS server in terminal roaming scenarios, and obtaining the application server address corresponding to the unauthorized domain name, the problem of limited service quality of the terminal in the visited network is solved, and the terminal can access services normally in the service network.

CN118740791BActive Publication Date: 2026-01-06HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310363701.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-31
Publication Date
2026-01-06
Estimated Expiration
2043-03-31

AI Technical Summary

Technical Problem

In terminal roaming scenarios, when the terminal's home network does not authorize the routing of services to the local data network of the visited network, the service quality is limited.

Method used

By using the first network element to provide the home network information to the DNS server in the visited network of the terminal, the address of the application server corresponding to the unauthorized domain name can be obtained, thereby enabling the terminal to access the application server in the service network and obtain the corresponding services.

Benefits of technology

This improves the quality of communication services for terminals within the service network and avoids the problem of being unable to access services due to unauthorized domain names.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118740791B_ABST
    Figure CN118740791B_ABST
Patent Text Reader

Abstract

The application provides a communication method and a communication device. The method comprises: a first network element receiving a first query message from a terminal, the first query message comprising information of a first domain name which is not authorized in a visited network of the terminal. The first network element is a network element in the visited network of the terminal. The first network element sends a second query message to a domain name system server according to the first query message, the second query message comprising information of the first domain name and information of a home network of the terminal, the information of the home network being used for determining an address of an application server used for providing a service corresponding to the first domain name for the terminal. The first network element receives the address of the application server from the DNS server. The terminal can access the service corresponding to the domain name, and the quality of the communication service of the terminal can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more specifically, to a communication method and a communication device. Background Technology

[0002] In mobile communication networks, different operators and different PLMNs (i.e., mobile communication networks) can be distinguished by their public land mobile network (PLMN) identifier (ID). The PLMN to which a terminal is subscribed is called the home PLMN (HPLMN). When a terminal leaves the coverage area of ​​the HPLMN due to movement or other reasons, if the terminal is currently within the coverage area of ​​another PLMN's wireless network, and that PLMN has a roaming agreement with the terminal's HPLMN, the terminal can access that PLMN through its wireless network. This PLMN can be called a visited PLMN (VPLMN), and the terminal's access to the VPLMN is called roaming. When the terminal's user plane terminates within an HPLMN, the terminal's roaming is called home routed (HR) roaming.

[0003] In HR roaming scenarios on the terminal, HPLMN can authorize certain domain name-related services to be offloaded to the local portion of the data network within the VPLMN. The visit-session management function (V-SMF) in the VPLMN allows the VPLMN network element to configure relevant network elements within the VPLMN based on authorization information from the HPLMN, including configuring edge application server discovery (EASDF). When a terminal queries the internet protocol (IP) address of the application server (AS) corresponding to a domain name authorized for offloading to the VPLMN network, the V-EASDF network element can interact with the domain name system server to obtain the AS IP address queried by the terminal, enabling that AS to provide the terminal with the services corresponding to that domain name.

[0004] However, when a terminal roams within a VPLMN, if the HPLMN does not authorize the diversion of services corresponding to one or more domain names to the VPLMN's local data network, the quality of services that the terminal can obtain may be limited. Summary of the Invention

[0005] This application provides a communication method and a communication device that enable a terminal to obtain the address of an application server corresponding to a domain name that is not authorized to divert corresponding services to the local data network within a service network. This allows the terminal to access the application server and obtain the services provided by the application server within the service network, thereby improving the quality of the terminal's communication services.

[0006] Firstly, a communication method is provided, which can be executed by a communication device, which may be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a first network element as an example.

[0007] The method includes: a first network element receiving a first query message from a terminal, the first network element being in the visited network of the terminal, the first query message including information about a first domain name, the first domain name being unauthorized in the visited network of the terminal; the first network element sending a second query message to a domain name system (DNS) server, the second query message including information about the first domain name and information about the home network of the terminal; and the first network element receiving the address of the application server from the DNS server.

[0008] In this second query message, the home network information is used to determine the address of the application server. Alternatively, the home network information in the second query message is used to obtain the address of the application server. This application server is used to provide the terminal with the services corresponding to the first domain name.

[0009] For example, the first domain name is not authorized in the network visited by the terminal, including: the service corresponding to the first domain name is not authorized by the terminal's home network to be diverted to the local data network.

[0010] According to the above scheme, when the first network element in the visited network of the terminal provides AS discovery service to the terminal, if the domain name provided by the terminal when querying the AS address is an unauthorized domain name in the visited network, the first network element provides the terminal's home network information to the DNS server. This allows the DNS server to find the AS address corresponding to the domain name that is not authorized to divert services to the local DN of the terminal's service network, and then provides it to the terminal through the first network element. This enables the terminal to obtain the address of the application server corresponding to the domain name that is not authorized to divert the corresponding services to the local data network in the service network, allowing the terminal to access the application server and obtain the services provided by the application server in the service network. This avoids the terminal being unable to access the services corresponding to the domain name due to unauthorized domain names, thus improving the quality of the terminal's communication services.

[0011] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the first network element receiving information from a second network element, the information being used to indicate a rule for a query message from the terminal for querying the address of an application server, the rule including: if the query message for querying the address of the application server includes an unauthorized domain name in the visited network of the terminal, the first network element providing the DNS server with information about the home network.

[0012] In one implementation, the rule specifically includes: if the query message used to query the address of the application server includes an unauthorized domain name in the visited network of the terminal, the first network element provides the DNS server with the home network information and the unauthorized domain name in a message.

[0013] According to the above scheme, the second network element can instruct the first network element on rules for processing DNS query messages. These rules include providing the home network information to the DNS server when the obtained query message contains an unauthorized domain name within the serving network. This allows the first network element to process the DNS query message according to these rules. The DNS server can then obtain the terminal's home network information and, based on the first domain name and the terminal's home network information, obtain the AS address corresponding to the first domain name based on address affinity and provide it to the terminal. This enables the terminal to access the application server within the serving network to obtain communication services, avoiding the inability to access services corresponding to a domain name due to unauthorized domain names, and improving the quality of the terminal's communication services.

[0014] In one implementation, the information is specifically used to indicate the rules adopted for the first query message, the rules including: the first network element provides the DNS server with information about the home network.

[0015] In conjunction with the first aspect, in some implementations of the first aspect, the first network element is a functional network element in the visited network of the terminal used to discover application servers, and the second network element is a functional network element in the visited network of the terminal used to manage the terminal's sessions.

[0016] In conjunction with the first aspect, in some implementations of the first aspect, the second query message includes an ECS option element that indicates information about the home network.

[0017] According to the above scheme, the ECS option cell in the DNS query message is reused to convey the home network information. Compared to modifying the format of the DNS query message to indicate the home network information, this reduces implementation complexity.

[0018] In conjunction with the first aspect, in certain implementations of the first aspect, the information of the home network includes one or more of the following:

[0019] The terminal's network protocol IP address, the IP address of the user plane function network element in the home network, or the dedicated address of the home network.

[0020] According to the above scheme, the home network information can be the terminal's IP address, the address of a network element in the home network, or the dedicated address of the home network used to obtain the AS address, which can improve the accuracy of the DNS server in obtaining the AS address based on the home network information.

[0021] In conjunction with the first aspect, in certain implementations of the first aspect, the first network element receiving the address of the application server from the DNS server includes: the first network element receiving a second response message from the DNS server in response to the second query message, the second response message including the address of the application server. Furthermore, the method further includes: the first network element sending a first response message to the terminal in response to the first query message, the first response message including the address of the application server.

[0022] According to the above scheme, the first network element obtains the address of the AS corresponding to the first domain name from the DNS server, and provides the terminal with the address of the AS corresponding to the first domain name in response to the terminal's query, so that the terminal can obtain the address of the AS corresponding to the domain name of the local DN that is not authorized to divert services to the visited network in the service network.

[0023] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the first network element acquiring authorized domain name information and / or unauthorized domain name information in the visited network of the terminal. Based on the domain name information, the first network element determines that the first domain name is unauthorized in the visited network of the terminal.

[0024] For example, the domain name information includes a first set of domain names and / or a second set of domain names. The first set of domain names includes one or more domain names that are authorized in the network visited by the terminal, and the first domain name does not belong to the first set of domain names. The domain name information also includes a second set of domain names that includes one or more domain names that are not authorized in the network visited by the terminal, and the first domain name belongs to the second set of domain names.

[0025] According to the above scheme, the first network element can determine, based on domain name information, that the first domain name is not authorized in the visited network of the terminal. This could be based on the first domain name not belonging to the first domain name set and / or based on the first domain name belonging to the second domain name set. This allows the first network element to provide the DNS server with home network information when querying the DNS server for the address of the AS corresponding to the first domain name, thus enabling the DNS server to accurately obtain the address of the AS corresponding to the first domain name and report it back to the terminal.

[0026] Secondly, a communication method is provided, which can be executed by a communication device, which can be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a second network element as an example.

[0027] The method includes: a second network element sending first information to a terminal, the first information instructing the first network element to discover an application server providing services to the terminal, wherein the first network element and the second network element are in the visited network of the terminal. The second network element then sends second information to the first network element, the second information instructing a rule for a query message from the terminal to query the address of the application server, the rule including: if the query message to query the address of the application server includes an unauthorized domain name in the visited network of the terminal, the first network element provides information about the home network of the terminal to a DNS server.

[0028] For example, the first domain name is not authorized in the network visited by the terminal, including: the service corresponding to the first domain name is not authorized by the terminal's home network to be diverted to the local data network.

[0029] According to the above scheme, the second network element can instruct the first network element on rules for processing DNS query messages. These rules include providing the home network information to the DNS server when the obtained query message contains an unauthorized domain name within the service network. This allows the first network element to process the DNS query message according to these rules. The DNS server can then obtain the terminal's home network information and, based on the first domain name and the terminal's home network information, obtain the address of the AS corresponding to the first domain name based on address affinity and provide it to the terminal. This enables the terminal to access the application server and obtain the services provided by the application server within the service network. It avoids situations where the terminal cannot access services corresponding to an unauthorized domain name, thus improving the quality of the terminal's communication services.

[0030] In conjunction with the second aspect, in some implementations of the second aspect, the rule specifically includes: when the query message used to query the address of the application server includes an unauthorized domain name in the visited network of the terminal, the first network element provides the DNS server with the home network information and the unauthorized domain name in a message.

[0031] For the solutions in the second aspect that correspond to those in the first aspect, the beneficial effects can be found in the description of the first aspect, and will not be repeated here.

[0032] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: the second network element receiving third information from a third network element, the third network element being in the home network of the terminal, the third information including information of the home network of the terminal, the information of the home network being used to query the application server corresponding to an unauthorized domain name in the visited network of the terminal.

[0033] In conjunction with the second aspect, in some implementations of the second aspect, the information of the home network includes the network protocol IP address of the terminal, the IP address of the user plane function network element in the home network, or the dedicated address of the home network.

[0034] In conjunction with the second aspect, in some implementations of the second aspect, the first network element is a functional network element in the visited network of the terminal used to discover application servers, and the second network element is a functional network element in the visited network of the terminal used to manage the terminal's sessions.

[0035] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: the second network element sending to the first network element the authorized domain name information and / or unauthorized domain name information in the visited network of the terminal.

[0036] In conjunction with the second aspect, in some implementations of the second aspect, the domain name information includes a first set of domain names, which includes one or more domain names authorized in the network visited by the terminal, and the first domain name does not belong to the first set of domain names; and / or, the domain name information includes a second set of domain names, which includes one or more domain names not authorized in the network visited by the terminal, and the first domain name belongs to the second set of domain names.

[0037] Thirdly, a communication method is provided, which can be executed by a communication device, which can be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a first network element as an example.

[0038] The method includes: a first network element receiving a first query message from a terminal, the first query message including information about a first domain name, which is not authorized in the network visited by the terminal. The first network element then sends a second query message to a second network element, the second query message including information about the first domain name, and the destination address of the second query message being the address of a Domain Name System (DNS) server. The DNS server is used to query the address of the application server corresponding to the unauthorized domain name in the network visited by the terminal, and the application server is used to provide the terminal with the service corresponding to the first domain name.

[0039] For example, the address of the DNS server is the address of the DNS server corresponding to the home network, or the address of the DNS server is the DNS server in the central data network.

[0040] For example, the first domain name is not authorized in the network visited by the terminal, including: the service corresponding to the first domain name is not authorized by the terminal's home network to be diverted to the local data network.

[0041] According to the above scheme, when the first network element in the visited network of the terminal provides AS discovery service to the terminal, if the first domain name provided by the terminal when querying the AS address is an unauthorized domain name in the visited network, the first network element provides a query message to the second network element containing the unauthorized domain name and with the destination address being the address of the aforementioned DNS server. This allows network elements in the network to forward the query message to a DNS server capable of finding the AS address corresponding to the unauthorized domain name in the terminal's visited network, based on the destination address of the query message. This enables the terminal to obtain the address of the application server corresponding to the unauthorized domain name in the service network, thus diverting the corresponding service to the local data network. This allows the terminal to access the application server and obtain the services provided by the application server within the service network. It avoids the terminal being unable to access the service corresponding to the domain name due to its unauthorized nature, thereby improving the quality of the terminal's communication services.

[0042] In conjunction with the third aspect, in some implementations of the third aspect, the first network element receives the address of the application server from the second network element.

[0043] According to the above scheme, when the DNS server finds the address of the AS corresponding to an unauthorized domain name in the visited network of the terminal, it can specifically send the address of the AS back to the terminal through the second network element and the first network element that transmit the query message to the terminal, so that the terminal can obtain the address of the AS.

[0044] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the first network element receiving information from the second network element, the information being used to indicate the rules adopted for a query message from the terminal for querying the address of an application server, the rules including: if the query message for querying the address of an application server includes an unauthorized domain name in the visited network of the terminal, the first network element sending a query message to the second network element containing the unauthorized domain name and the destination address being the address of the DNS server.

[0045] In one embodiment, the method further includes: the first network element receiving information from a second network element, the information indicating a rule to be adopted for the first query message, the rule including: the first network element providing the second network element with the second query message containing the first domain name and the destination address being the address of the DNS server.

[0046] According to the above scheme, the second network element can instruct the first network element on the rules for processing DNS query messages, so that the first network element can transmit the query message containing the unauthorized domain name and whose destination address is the address of the DNS server to the second network element, and finally to the DNS server.

[0047] In conjunction with the third aspect, in some implementations of the third aspect, the first network element is a functional network element in the visited network of the terminal used to discover application servers, and the second network element is a functional network element in the visited network of the terminal used to manage the terminal's sessions.

[0048] In conjunction with the third aspect, in certain implementations of the third aspect, the first network element receiving the address of the application server from the second network element includes: the first network element receiving a second response message from the second network element in response to the second query message, the second response message including the address of the application server. Furthermore, the method further includes: the first network element sending a first response message to the terminal in response to the first query message, the first response message including the address of the application server.

[0049] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the first network element acquiring authorized domain name information and / or unauthorized domain name information in the visited network of the terminal. Based on the domain name information, the first network element determines that the first domain name is unauthorized in the visited network of the terminal.

[0050] In conjunction with the third aspect, in certain implementations of the third aspect, the domain name information includes a first set of domain names and / or a second set of domain names, wherein the first set of domain names includes one or more domain names that are authorized in the network visited by the terminal, and the first domain name does not belong to the first set of domain names. The second set of domain names includes one or more domain names that are not authorized in the network visited by the terminal, and the first domain name belongs to the second set of domain names.

[0051] Fourthly, a communication method is provided, which can be executed by a communication device, which may be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a second network element as an example.

[0052] The method includes: a second network element receiving a second query message from a first network element, the second query message including information about a first domain name from a terminal, and the destination address of the second query message being the address of a Domain Name System (DNS) server, the first domain name being unauthorized in the visited network of the terminal, the DNS server being used to query for the terminal the address of the application server corresponding to the unauthorized domain name in the visited network of the terminal, the application server being used to provide the terminal with the service corresponding to the first domain name, the second query message being used to query the DNS server for the address of the application server corresponding to the first domain name for the terminal, the first network element being a functional network element in the visited network of the terminal used to manage the terminal's sessions, and the second network element being a functional network element in the visited network of the terminal used to discover application servers.

[0053] According to the above scheme, the second network element instructs the first network element on rules for processing DNS query messages. This allows the first network element to transmit query messages containing the unauthorized domain name and whose destination address is the address of the DNS server to the second network element, i.e., the control plane network element in the terminal's visited network used to manage terminal sessions. The terminal's transmission of the query message within the control plane network element of the visited network enables network elements to forward the query message to a DNS server capable of finding the address of the AS corresponding to the unauthorized domain name in the terminal's visited network, based on the destination address of the query message. Furthermore, even if the terminal encrypts the query message, the first network element used for AS discovery can still determine whether the domain name contained in the query message is an unauthorized domain name in the visited network. Based on the rules, it transmits the query message, allowing the terminal to obtain the address of the AS corresponding to the domain name. This enables the terminal to obtain the address of the application server corresponding to the unauthorized domain name that will be routed to the local data network within the service network, allowing the terminal to access the application server and obtain the services provided by it. This can prevent terminals from being unable to access services corresponding to a domain name due to unauthorized domain names, thereby improving the quality of terminal communication services.

[0054] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the second network element queries the DNS server for the terminal to obtain the address of the application server corresponding to the first domain name through network elements in the terminal's home network.

[0055] For example, the second network element sends a third query message to the third network element. The third query message is used to query the DNS server for the terminal to find the address of the application server corresponding to the first domain name. The third query message includes information about the first domain name. The third network element is a functional network element in the home network used to manage the terminal's session.

[0056] According to the above scheme, by transmitting the query message through the control plane network element of the visited network, the query message can be transmitted to the terminal's home network, and then through the home network to the DNS server that can find the address of the AS corresponding to the first domain name. This enables the terminal to obtain the address of the application server corresponding to the domain name that is not authorized to divert the corresponding business to the local data network within the serving network.

[0057] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes:

[0058] The second network element sends information to the first network element, the information being used to indicate the rules adopted for a query message from the terminal for querying the address of an application server. The rules include: if the query message for querying the address of an application server includes an unauthorized domain name in the network visited by the terminal, the first network element sends a query message to the second network element containing the unauthorized domain name and the destination address being the address of the DNS server.

[0059] In one embodiment, the second network element sends information to the first network element, the information being used to indicate the rules adopted for the first query message, the rules including: the first network element providing the second network element with the second query message containing the first domain name and the destination address being the address of the DNS server.

[0060] For the solutions in the fourth aspect that correspond to those in the third aspect, the beneficial effects can be found in the description of the third aspect, and will not be repeated here.

[0061] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the response message containing the address of the AS corresponding to the first domain name can be transmitted to the terminal through the first network element, the second network element, and the third network element that transmits the query message, that is, it can be transmitted to the terminal through the control plane network element that transmits the query message.

[0062] Specifically, the second network element receives a third response message from a third network element, the third response message including the address of the application server corresponding to the first domain name, and the third network element is a functional network element in the home network used to manage the terminal's session. Furthermore, the method further includes: the second network element sending a second response message to the first network element in response to the second query message, the second response message including the address of the application server corresponding to the first domain name.

[0063] In conjunction with the fourth aspect, in some implementations of the fourth aspect, a response message containing the address of the AS corresponding to the first domain name can be transmitted to the terminal through user plane network elements in the home network and user plane network elements in the visited network of the terminal.

[0064] Fifthly, a communication method is provided, which can be executed by a communication device, which may be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a second network element as an example.

[0065] The method includes: a second network element sending first information to a terminal, the first information instructing the first network element to discover an application server providing services to the terminal, the first network element being a functional network element in the visited network used to manage the terminal's session, and the second network element being a functional network element in the visited network used to discover the application server. The second network element then sends second information to the first network element, the second information instructing a rule for a first query message from the terminal to query the address of an application server. This rule includes: if the first query message includes an unauthorized domain name in the visited network, the first network element sends a second query message to the second network element containing the unauthorized domain name and with a destination address being the address of a DNS server, wherein the DNS server is used to query the address of the application server corresponding to the unauthorized domain name in the visited network for the terminal.

[0066] For the beneficial effects of the scheme in the fifth aspect, please refer to the descriptions of the beneficial effects of the corresponding schemes in the third and fourth aspects, which will not be repeated here.

[0067] Sixthly, a communication method is provided, which can be executed by a communication device, which may be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a first network element as an example.

[0068] The method includes: a fourth network element receiving a first query message, the first query message including information about a first domain name from a terminal, the first domain name being unauthorized in the network visited by the terminal; the fourth network element sending a fourth query message, the fourth query message including information about the first domain name, and the destination address of the fourth query message being the address of a Domain Name System (DNS) server, the DNS server being used to query for the terminal the address of the application server corresponding to the unauthorized domain name in the network visited by the terminal, the application server being used to provide the terminal with the service corresponding to the first domain name.

[0069] For example, the fourth network element is a functional network element in the visited network of the terminal used to manage the terminal's session, a functional network element in the home network used to manage the terminal's session, a user plane functional network element in the home network, or a functional network element in the home network used to discover application servers.

[0070] For example, the first domain name is not authorized in the network visited by the terminal, including: the service corresponding to the first domain name is not authorized by the home network to be diverted to the local data network.

[0071] According to the above scheme, when the fourth network element obtains an unauthorized domain name from the first terminal in the visited network, it transmits a query message containing the unauthorized domain name and with the destination address being the address of the aforementioned DNS server. Network elements in the network can then forward the query message to a DNS server capable of retrieving the address of the AS corresponding to the unauthorized domain name in the terminal's visited network, based on the destination address of the query message. This enables the terminal to obtain the address of the application server corresponding to the unauthorized domain name in the service network, thus diverting the corresponding services to the local data network. This allows the terminal to access the application server and obtain the services provided by it within the service network. It avoids the terminal being unable to access the services corresponding to an unauthorized domain name, thereby improving the quality of the terminal's communication services.

[0072] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the fourth network element receives the address of the application server.

[0073] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the fourth network element is a functional network element in the visited network of the terminal used to manage the terminal's session, and sending the fourth query message includes: sending the fourth query message to a functional network element in the home network used to manage the session therein.

[0074] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the fourth network element is a functional network element in the visited network of the terminal used to manage the terminal's sessions. The method further includes: the fourth network element sending information to a first network element, which is a network element in the visited network of the terminal used to discover application servers. This information is used to indicate the rules adopted for a query message from the terminal for querying the address of an application server. The rules include: if the query message for querying the address of an application server includes an unauthorized domain name in the visited network of the terminal, the first network element sends the query message for querying the address of the application server to the second network element.

[0075] In conjunction with the sixth aspect, in certain implementations of the sixth aspect, the fourth network element receiving the address of the application server includes: the fourth network element receiving a fourth response message in response to the fourth query message, the fourth response message including the address of the application server; and the fourth network element sending a first response message to the terminal in response to the first query message, the first response message including the address of the application server.

[0076] In a seventh aspect, a communication method is provided, which can be executed by a communication device, which may be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a terminal as an example.

[0077] The method includes: a terminal determining that a first domain name to be queried is not authorized in the visited network; the terminal determining a first message, the first message including a query message and indication information, the query message being used to query the address of the application server corresponding to the first domain name; the indication information being used to indicate that the query message is used to query the address of the Application Server (AS) corresponding to the domain name that is not authorized in the visited network, or the indication information being used to indicate that the query message includes a domain name that is not authorized in the visited network. The terminal sends the first message to the user plane function network element in the visited network.

[0078] According to the above scheme, the terminal notifies the user plane network element via an instruction message that the query message includes an unauthorized domain name in the visited network. Even if the terminal encrypts the query message (e.g., DHO, DOT), although the user plane network element cannot interpret the query message, it can determine, without interpreting the message itself, to pass the query message to the UPF network element in the home network through the instruction information in the first message. This allows the home network to retrieve the address of the AS corresponding to the unauthorized domain name in the visited network. This enables the terminal to access the address of the application server corresponding to the unauthorized domain name in the visited network and obtain the services provided by the application server. This avoids the terminal being unable to access the services corresponding to the domain name due to its unauthorized nature, thus improving the quality of terminal communication services.

[0079] Eighthly, a communication method is provided, which can be executed by a communication device, which may be a communication equipment or a component (such as a chip or chip system) configured in the communication equipment. The following description uses the execution of the method by a terminal as an example.

[0080] The method includes: a first user plane function network element receiving a first message from a terminal, the first message including a query message and indication information, the query message being used to query the address of the application server corresponding to a first domain name, and the indication information being used to indicate that the query message is used to query the address of an application server (AS) corresponding to an unauthorized domain name in the visited network, or the indication information being used to indicate that the query message includes an unauthorized domain name in the visited network. The first user plane function network element is located in the visited network of the terminal. The first user plane function network element sends the query message to a second user plane function network element, the second user plane function network element being located in the home network of the terminal.

[0081] For the beneficial effects of the scheme in aspect eight, please refer to the description of the beneficial effects of the scheme in aspect seven, which will not be repeated here.

[0082] Ninthly, a communication method is provided, which can be executed by a communication system, the communication system including a first network element and a second network element.

[0083] The method includes: a second network element sending first information to a terminal, the first information being used to instruct the first network element to discover an application server that provides services to the terminal, the first network element and the second network element being in the visited network of the terminal.

[0084] The second network element sends second information to the first network element, the second information being used to indicate the rules adopted for a query message from the terminal for querying the address of an application server, the rules including: if the query message for querying the address of an application server includes an unauthorized domain name in the visited network of the terminal, the first network element provides the DNS server with information about the home network of the terminal.

[0085] The first network element receives a first query message from the terminal, the first query message including information about a first domain name, which is not authorized in the network visited by the terminal.

[0086] The first network element sends a second query message to the Domain Name System (DNS) server. The second query message includes information about the first domain name and information about the home network of the terminal. The home network information is used to determine the address of the application server, which is used to provide the terminal with the services corresponding to the first domain name.

[0087] The first network element receives the address of the application server from the DNS server, and the first network element sends the address of the application server to the terminal.

[0088] In conjunction with aspect nine, in some implementations of aspect nine, the communication system also includes the aforementioned terminal.

[0089] In a tenth aspect, a communication method is provided, which can be executed by a communication system, the communication system including a first network element and a second network element.

[0090] The method includes: a first network element receiving a first query message from a terminal, the first query message including information about a first domain name, the first domain name being unauthorized in the network visited by the terminal;

[0091] The first network element sends a second query message to the second network element. The second query message includes information about the first domain name, and the destination address of the second query message is the address of a Domain Name System (DNS) server. The DNS server is used to query the address of the application server corresponding to an unauthorized domain name in the network visited by the terminal. The application server is used to provide the terminal with the service corresponding to the first domain name.

[0092] The second network element queries the DNS server for the address of the application server corresponding to the first domain name through the network element in the terminal's home network;

[0093] The first network element receives the address of the application server from the second network element;

[0094] The first network element sends the address of the application server to the terminal.

[0095] Eleventhly, a communication device is provided, which may include modules for performing the methods / operations / steps / actions described in the first to eighth aspects and any possible implementations of the first to eighth aspects. These modules may be hardware circuits, software, or a combination of hardware circuits and software implementations. For details, please refer to the detailed descriptions in the corresponding method examples above; further elaboration is not provided here.

[0096] In a twelfth aspect, a communication device is provided, including a processor. The processor is coupled to the memory and can be used to execute instructions in the memory to implement the methods of the first to eighth aspects and any possible implementation thereof.

[0097] Optionally, the communication device also includes the memory.

[0098] Optionally, the communication device further includes a communication interface, to which the processor is coupled. In this application, the communication interface can be a transceiver, pin, circuit, bus, module, or other type of communication interface, and is not limited thereto.

[0099] In one implementation, the communication device is a communication equipment. When the communication device is a communication equipment, the communication interface can be a transceiver, or the communication interface can be an input / output interface.

[0100] Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0101] In another implementation, the communication device is a chip configured within a communication device. When the communication device is a chip configured within a communication device, the communication interface can be an input / output interface.

[0102] In a thirteenth aspect, a processor is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive signals through the input circuit and transmit signals through the output circuit, causing the processor to execute the methods described in the first to eighth aspects and any possible implementation thereof.

[0103] In specific implementation, the processor can be one or more chips, the input circuit can be input pins, the output circuit can be output pins, and the processing circuit can be transistors, gate circuits, flip-flops, and various logic circuits. The input signal received by the input circuit can be received and input by, for example, but not limited to, a receiver, and the signal output by the output circuit can be, for example, but not limited to, output to and transmitted by a transmitter. Furthermore, the input circuit and the output circuit can be the same circuit, which is used as both the input circuit and the output circuit at different times. This application does not limit the specific implementation of the processor and various circuits.

[0104] In a fourteenth aspect, a computer program product is provided, comprising: a computer program (also referred to as code or instructions) that, when run, causes a computer to perform the methods described in the first to eighth aspects and any possible implementation thereof.

[0105] In a fifteenth aspect, a computer-readable storage medium is provided that stores a computer program (also referred to as code or instructions) that, when run on a computer, causes the computer to perform the methods described in the first to eighth aspects and any possible implementation thereof.

[0106] In a sixteenth aspect, this application provides a communication system comprising a first communication device and a second communication device. The first communication device is used to execute the method performed by a first network element in any of the first to eighth aspects and any possible implementations thereof. The second communication device is used to execute the method performed by a second network element in any of the first to eighth aspects and any possible implementations thereof.

[0107] In one embodiment, the communication system further includes a terminal for performing the methods described in the first to eighth aspects and any possible implementation thereof. Attached Figure Description

[0108] Figure 1 This is a schematic diagram of the communication system architecture provided in an embodiment of this application;

[0109] Figure 1A This is another schematic diagram of the communication system architecture provided in the embodiments of this application;

[0110] Figure 2 This is a schematic flowchart of a communication method provided in an embodiment of this application;

[0111] Figure 3This is a schematic flowchart illustrating the application of the communication method provided in this application to a terminal roaming scenario;

[0112] Figure 4 This is another schematic flowchart of the communication method provided in the embodiments of this application;

[0113] Figure 5 This is another illustrative flowchart illustrating the application of the communication method provided in this application embodiment to a terminal roaming scenario;

[0114] Figure 6 This is a schematic block diagram of a communication device provided in an embodiment of this application;

[0115] Figure 7 This is a schematic structural diagram of another communication device provided in the embodiments of this application. Detailed Implementation

[0116] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0117] In this application embodiment, " / " can indicate that the related objects are in an "or" relationship. For example, A / B can represent A or B. "And / or" can be used to describe three relationships between related objects. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. A and B can be singular or plural. To facilitate the description of the technical solutions in this application embodiment, the terms "first" and "second" can be used for distinction. These terms do not limit the quantity or execution order, and they are not necessarily different. In this application embodiment, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary" or "for example" should not be construed as being more preferred or advantageous than other embodiments or designs. The use of "exemplary" or "for example" is intended to present related concepts in a concrete manner for ease of understanding. In the embodiments of this application, at least one can also be described as one or more species, and more than one species can be two, three, four or more species, and this application does not impose any restrictions.

[0118] The technical solutions of the embodiments of this application can be applied to various communication systems, such as: long term evolution (LTE) systems, fifth generation (5G) communication systems, such as 5G new radio (NR) systems, sixth generation (6G) communication systems, and future communication systems, or systems that integrate multiple communication systems, etc. The embodiments of this application are not limited to these.

[0119] The terminal device involved in the embodiments of this application can also be referred to as a terminal. A terminal can be a device with wireless transceiver capabilities. Terminals can be deployed on land, including indoors, outdoors, handheld, and / or vehicle-mounted; they can also be deployed on water (such as ships); and they can also be deployed in the air (e.g., on airplanes, balloons, and satellites). Terminal devices can be user equipment (UE). UEs include handheld devices, vehicle-mounted devices, wearable devices, or computing devices with wireless communication capabilities. For example, a UE can be a mobile phone, a tablet computer, or a computer with wireless transceiver capabilities. Terminal devices can also be virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminals in industrial control, wireless terminals in autonomous driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in smart cities, and / or wireless terminals in smart homes, etc.

[0120] The radio access network (RAN) elements involved in the embodiments of this application can be RAN equipment, including base stations (BS), which can be devices deployed in the RAN capable of wireless communication with terminal devices. Base stations may take various forms, such as macro base stations, micro base stations, relay stations, or access points. The base stations involved in the embodiments of this application can be next-generation RAN (NG-RAN) equipment in 5G systems, base stations in long-term evolution (LTE) systems, or base stations in other systems, without limitation. NG-RAN equipment in 5G systems can also be called transmission reception points (TRP) or generation Node B (gNB or gNodeB). The base station can be an integrated base station or a base station separated into multiple network elements, without limitation. For example, a base station can be a base station with separate centralized units (CU) and distributed units (DU), i.e., the base station includes both CU and DU.

[0121] Figure 1 This is a schematic diagram of a network architecture applicable to embodiments of this application. For example... Figure 1 As shown, the network architecture may include UEs, access network elements (such as (R)AN) in the access network, and core network elements in the core network. The core network may include, for example, Figure 1 The network elements shown include the Access and Mobility Management (AMF) network element, Session Management (SMF) network element, User Plane Function (UPF) network element, Authentication Server Function (AUSF) network element, Policy Control Function (PCF) network element, Application Function (AF) network element, Unified Data Management (UDM) network element, and Network Slice Selection Function (NSSF) network element. Each functional network element will be described in detail below.

[0122] AMF network elements are mainly responsible for services such as mobility management and access management, including user location updates, user registration networks, and user handover.

[0123] The SMF (Service Provider Function) network element is primarily responsible for session management, terminal device address management and allocation, Dynamic Host Configuration Protocol (DHCP) functions, and the selection and control of user plane functions. It is mainly responsible for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating IP addresses to users and selecting the UPF (User Plane Function) that provides packet forwarding capabilities.

[0124] like Figure 1A A schematic diagram of an HR roaming network architecture applicable to embodiments of this application is shown. In an HR roaming scenario, the SMF network element in the terminal's home network can be denoted as an H-SMF network element, and the network element in the terminal's visited network can be denoted as a V-SMF network element. The V-SMF network element and the H-SMF network element can exchange information through interface 16 (denoted as N16).

[0125] UPF network elements are primarily responsible for packet routing and forwarding, packet filtering, and quality of service (QoS) control functions when connecting to the data network (DN) and user plane. In a session, a UPF network element directly connected to the DN via N6 is called a Protocol Data Unit (PDU) session anchor (PSA). Specifically, the core network may include UPF network elements connected to the DNS server (which can be called the central DNS server) in the central data network (Central DN), and this UPF network element can be specifically called a center PSA (C-PSA). The core network may also include UPF network elements connected to the DNS server in the local part of the DN, and this UPF network element can be specifically called a local PSA (L-PSA). A local data network refers to a group of network entities deployed locally within a data network, or a data network deployed locally.

[0126] In HR walkthrough scenarios, such as Figure 1A As shown, UPF network elements in the terminal's home network can be denoted as H-UPF network elements, and UPF network elements in the terminal's visited network can be denoted as V-UPF network elements. V-UPF network elements and H-UPF network elements can exchange information through interface 9 (denoted as N9).

[0127] UDM is primarily responsible for storing subscription data, credentials, and persistent identifiers (SUPI) for subscribed terminal devices in the network, and provides a service interface called Nudm. This data can be used for authentication and authorization of terminal devices accessing the operator's network.

[0128] AUSF is primarily responsible for authentication functions for terminal devices.

[0129] The PCF network element is mainly responsible for providing a unified policy framework for network behavior management, providing policy rules for control plane functions, and obtaining registration information related to policy decisions. The service interface it provides is Npcf.

[0130] In HR walkthrough scenarios, such as Figure 1A As shown, the PCF network element in the terminal's home network can be referred to as the H-PCF network element, and the UPF network element in the terminal's visited network can be referred to as the V-PCF network element. The V-PCF network element and the H-PCF network element can exchange information through interface 24 (denoted as N24).

[0131] The NSSF network element is mainly responsible for selecting a set of network slice instances to provide services to the UE through network slicing technology, dividing a physical network into multiple logical networks to achieve one network for multiple uses and provide personalized network services to users.

[0132] In HR roaming scenarios, NSSF network elements in the terminal's home network can be referred to as H-NSSF network elements, and network elements in the terminal's visited network can be referred to as V-NSSF network elements. V-NSSF network elements and H-NSSF network elements can exchange information through interface 58 (denoted as N31).

[0133] It should be noted that the above-mentioned functional networks can work independently or be combined to implement certain control functions, such as access control and mobility management functions for terminal devices, including access authentication, security encryption, and location registration, as well as session management functions such as the establishment, release, and modification of user plane transmission paths.

[0134] like Figure 1The functional network elements shown can communicate with each other through network interfaces. For example, the UE can transmit control plane messages with the AMF network element through interface 1 (denoted as N1); the RAN network element can establish a user plane data transmission channel with the UPF through interface 3 (denoted as N3); the RAN network element can establish a control plane signaling connection with the AMF network element through interface 2 (denoted as N2); the UPF can exchange information with the SMF network element through interface 4 (denoted as N4); the UPF can exchange user plane data with the data network DN through interface 6 (denoted as N6); different UPF network elements can exchange information with each other through interface N9; the AMF network element can exchange information with the SMF network element through interface 11 (denoted as N11); the SMF network element can exchange information with the PCF network element through interface 7 (denoted as N7); and the AMF network element can exchange information with the AUSF through interface 12 (denoted as N12). It should be noted that... Figure 1 This is merely an illustrative architecture diagram, except... Figure 1 In addition to the functional units shown, the network architecture may also include other functional units. This application does not limit this.

[0135] In edge computing (EC) deployment scenarios, some services may be provided by multiple edge application servers (EAS) deployed at the network edge. When a terminal needs to access these services, the EC scenario requires the terminal to access the nearest available EAS. Therefore, the terminal needs to obtain the appropriate EAS's internet protocol (IP) address. The terminal can discover EASDF network elements through edge application servers in the network that assist in terminal discovery of EAS. The EASDF network element mainly processes Domain Name System (DNS) messages according to the instructions of the SMF network element, including: receiving DNS query messages from the UE, including the full qualified domain name (FQDN), and reporting the FQDN in the DNS query message to the SMF network element. Additionally, the EASDF network element receives extended mechanisms for DNS-client-subnet (ECS) option establishment information (denoted as "info to build ECS option") from the SMF network element and adds ECS option information elements to the DNS query based on this ECS option establishment information. The EASDF network element sends the processed DNS query to the DNS server and receives the DNS response message from the DNS server to obtain the IP address of the EAS corresponding to the FQDN queried by the UE, and then sends it to the UE.

[0136] When a terminal roams within a VPLMN, the HPLMN can authorize one or more FQDNs to offload services to the VPLMN's local data network. However, for FQDNs for which the HPLMN has not authorized offloading services to the VPLMN's local data network, the quality of service available to the terminal may be limited. For example, a terminal roaming within a VPLMN may be unable to access services corresponding to domain names that are not authorized to be offloaded to the VPLMN's local data network.

[0137] To address the aforementioned issues, this application provides a corresponding solution. A functional network element for discovering the application server (AS) can obtain information about the terminal's home network. When providing AS discovery services to the terminal, this home network information is provided to the DNS server. This allows the DNS server to query the address of the AS corresponding to the domain name of the local DN of the service network that is not authorized to redirect traffic to the terminal. This information is then provided to the terminal through the functional network element for AS discovery. This enables the terminal to obtain the address of the AS corresponding to the domain name of the local DN of the service network that is not authorized to redirect traffic to the terminal. This allows the terminal to access the services it needs and improves the terminal's communication quality.

[0138] Figure 2 This is a schematic flowchart of the communication method 200 provided in this application embodiment. In this communication method 200, the terminal's service network can be a visited network, that is, the terminal roams in the visited network. Alternatively, the terminal's service network can be an intermediate network where the PLMN and the terminal's home network are the same. The intermediate network can be understood as a network composed of intermediate network elements providing services to the terminal, for example, an intermediate session management function network element (I-SMF) providing session management services to the terminal. This method 200 can enable the terminal to query the address of the AS corresponding to an unauthorized domain name in the visited network or service network, and to access the AS in the visited network or intermediate network. Alternatively, the service network can be the terminal's home network, for example, the terminal roams in the visited network where the service network and the PLMN of the terminal's home network are the same. Figure 2 In the illustrated embodiment, the terminal needs to query the address of an AS that does not cooperate with its home network, or in other words, the AS cooperates with a network of another operator besides the terminal's home network. Method 200 enables the terminal to query the address of the AS and access the AS that does not cooperate with its home network. The following description primarily uses the terminal's serving network as the visited network as an example; however, it should be understood that this application is not limited to this, and the serving network can also be the aforementioned intermediate network or home network.

[0139] The first network element is a functional network element used for AS discovery in the terminal's current serving network. For example, this first network element can be called an Edge Application Server Discovery Function (EASDF) network element or an Application Server Discovery Function (ASDF) network element. The method 200 includes, but is not limited to, the following steps:

[0140] S201, the terminal sends a first query message to the first network element, the first query message including information about the first domain name.

[0141] The first query message is used to query the address of the AS corresponding to the first domain name, which is used to provide services to the terminal.

[0142] The first network element receives the first query message from the terminal. The first network element determines the address of the AS corresponding to the first domain name queried by the terminal. The information of the first domain name in the first query message can be the first domain name itself, such as a full qualified domain name (FQDN). Alternatively, the information of the first domain name can be an identifier of the first domain name. The information of the first domain name is used to enable the first network element to determine the first domain name. This application does not limit the specific implementation form of the information of the first domain name. It should be understood that the first domain name can also be described as business information, that is, business information can be represented by a domain name, or business information can be represented by a uniform resource identifier (URI) / uniform resource locator (URL). Business information can also be represented by an application identifier. This application does not limit this; this application only uses a domain name as an example for illustration.

[0143] The first network element can determine that the first domain name is not authorized in the service network. In this application, the domain name not being authorized in the terminal's service network includes: the service corresponding to the domain name not being authorized by the terminal's home network to be routed to the local DN. The domain name being authorized in the terminal's service network includes: the service corresponding to the domain name being authorized by the terminal's home network to be routed to the local DN. Here, the local DN refers to a locally deployed and / or distributed DN. This local DN can be accessed by network elements in the visited network, or in other words, the terminal can access this local DN through the visited network. For example, the first domain name not being authorized in the terminal's service network includes: the service corresponding to the first domain name not being authorized by the terminal's home network to be routed to the local DN.

[0144] In one alternative implementation, the first network element may obtain domain name information that is authorized in the service network and / or domain name information that is not authorized in the service network. Based on this domain name information, the first network element determines that the first domain name is not authorized in the service network.

[0145] In one example, the first network element obtains domain name information that is authorized in the service network. This domain name information may include a first domain name set, which includes one or more domain names that are authorized in the service network. The first network element can determine that the first domain name is an unauthorized domain name in the service network if the first domain name does not belong to the first domain name set.

[0146] In another example, a first network element obtains information about unauthorized domain names within the service network. This domain name information may include a second set of domain names. The first network element also obtains information about authorized and unauthorized domain names within the service network. The first set of domain names includes one or more unauthorized domain names within the service network. The first network element can determine that a first domain name is an unauthorized domain name within the service network based on whether it belongs to the second set of domain names.

[0147] In another example, the domain name information may include the aforementioned first domain name set and the aforementioned second domain name set. The first network element determines that the first domain name is an unauthorized domain name in the service network based on the fact that the first domain name does not belong to the first domain name set and / or the first domain name belongs to the second domain name set.

[0148] FirstNetElement may obtain domain name information in the following ways, including but not limited to:

[0149] In one approach, the first network element obtains the domain name information from its configuration information (such as configuration information stored internally within the first network element). In other words, the domain name information is configured within the first network element.

[0150] For example, before the first network element receives the first query message, the second network element can send the domain name information to the first network element, and the first network element stores the domain name information in its configuration information. After receiving the first query message, the first network element retrieves the domain name information from its configuration information.

[0151] In another approach, after receiving the first query message, the first network element can send a request message to the second network element. This request message requests authorized domain name information and / or unauthorized domain name information within the service network. Upon receiving the request message, the second network element sends the requested domain name information to the first network element. Based on this domain name information, the first network element determines that the first domain name is unauthorized within the service network.

[0152] The aforementioned second network element can be a functional network element used to manage the terminal's sessions in the terminal's service network. The second network element can be called a Session Management Function (SMF) network element.

[0153] In one example, the terminal's serving network can be the terminal's visited network. The first network element is an EASDF network element (V-EASDF) in the visited network, and the second network element is an SMF network element (V-SMF) in the visited network. The V-SMF network element can send the domain name information to the V-EASDF network element. This domain name information can be included in the VPLMN offloading information sent by the V-SMF network element to the V-EASDF network element. For example, the domain name information can be authorized traffic for Home Routed with Session Breakout in VPLMN or non-authorized traffic for Home Routed with Session Breakout in VPLMN in the VPLMN offloading information. However, this application is not limited to this.

[0154] In another optional implementation, after receiving the first query message, the first network element sends the first domain name to the second network element. The second network element, based on the first domain name and authorized domain name information and / or unauthorized domain name information obtained from the service network, determines that the first domain name is unauthorized in the service network. The second network element then sends the terminal's home network information to the first network element. This home network information is used by the first network element to determine the second query message in S202.

[0155] In one approach, the first network element can determine that the first domain name is not authorized in the service network based on the information obtained about the home network of the terminal.

[0156] Alternatively, the first network element may not need to determine whether the first domain name is authorized in the serving network. After obtaining the home network information of the terminal from the second network element, the first network element determines the second query message in S202 based on the first query message and the home network information of the terminal. In S202, the first network element sends the second query message to the DNS server. This second query message includes the information of the first domain name and the home network information of the terminal. The home network information is used to determine the address of the AS corresponding to the first domain name.

[0157] The information about the terminal's home network in the second query message can be considered as information used to obtain the address of the AS corresponding to the first domain name.

[0158] In step S201, based on the first query message, the first network element determines the address of the AS corresponding to the first domain name that is not authorized in the serving network. Then, the first network element includes the terminal's home network information (obtained before receiving the first query message) and the first domain name information (obtained based on the first query message) in a second query message and sends it to the DNS server. Alternatively, after receiving the first query message, the first network element sends the first domain name to the second network element, obtains the home network information from the second network element, and then sends a second query message containing the first domain name and the terminal's home network information to the DNS server.

[0159] The first network element sends a second query message containing information about the terminal's home network to the DNS server, so that the DNS server can determine the address of the AS corresponding to the unauthorized first domain name in the terminal's service network based on the information about the terminal's home network in the second query message. This allows the terminal to obtain the address of the AS corresponding to the unauthorized first domain name in the service network (i.e., the visited network or intermediate network).

[0160] For example, the second query message includes an ECS option element, which is used to indicate information about the terminal's home network.

[0161] The home network information of the terminal can be information used to characterize the location of the home network, such as address information used to characterize the location of the home network. For example, the home network information of the terminal can be the terminal's Internet Protocol (IP) address, the IP address of a user plane function element in the terminal's home network, or the dedicated address of the terminal's home network. This allows the DNS server to obtain the terminal's home network information through the second query message and determine the address of the AS corresponding to the first domain name based on address affinity.

[0162] For example, the information about the terminal's home network could be the terminal's IP address 1. This IP address 1 can be used to obtain the address of the AS corresponding to an unauthorized domain name in the service network. The terminal's IP address 1 is anchored to a UPF network element in the terminal's home network. The second query message includes the terminal's IP address 1, and the DNS server can determine the address of the AS corresponding to the first domain name based on this IP address 1.

[0163] The terminal's home network may assign it two IP addresses. For example, in a multi-homed scenario, the network side assigns IP address 1 and IP address 2 to the terminal. If the source address in the first query message is the terminal's IP address 2 and the destination address is the IP address of the first network element, the first network element can determine that the first query message comes from the terminal based on the fact that the source address in the first query message is the terminal's IP address 2. However, this application is not limited to this; the IP address of the terminal used to obtain the address of the AS corresponding to the first domain name and the IP address of the terminal used to receive or send messages can be the same IP address of the terminal.

[0164] The information about the terminal's home network can also be the IP address of a UPF network element in the terminal's home network or a dedicated address of the home network. The dedicated address of the terminal's home network can be a dedicated address used to obtain the AS address corresponding to an unauthorized domain name in the terminal's service network, or it can be used for other purposes. This application does not limit this. For example, the dedicated address of the home network can be the terminal's IP address, where the terminal's IP address refers to the IP address after network address translation (NAT). As another example, the dedicated address of the home network can be the address of a specific network element in the home network, specifically the address of a home network session management function network element or the address of a home network edge application server discovery function.

[0165] In one alternative implementation, the first network element may provide the DNS server with the home network information of the terminal after receiving the first query message, based on the rules adopted for query messages from the terminal.

[0166] The second network element can send information to the first network element, which indicates the rules to be applied to query messages from the terminal. Accordingly, the first network element receives this information and indicates the rules to be applied to the query messages from the terminal.

[0167] Example 1: The rule includes the following: if a query message from a terminal includes a domain name that is not authorized in the visited network, the first network element provides the DNS server with information about the terminal's home network.

[0168] The second network element can obtain the terminal's home network information from network elements in its home network and then send it to the first network element. The terminal's home network information can be included in the information used to indicate the rules.

[0169] The rule that the second network element instructs the first network element specifically includes: if the query message from the terminal includes an unauthorized domain name in the visited network, the first network element provides the DNS server with the terminal's home network information and the unauthorized domain name in a single message.

[0170] For example, the second network element could be an SMF network element in the terminal's service network, and the first network element could be an EASDF network element in the terminal's service network. The SMF network element sends DNS context update information to the EASDF network element. This DNS context update information includes rules for query messages from the terminal. These rules include: if a query message from the terminal contains an unauthorized domain name in the visited network, the EASDF network element adds the terminal's home network information as an ECS option element to the query message and provides it to the DNS server. When the EASDF network element receives the first query message from the terminal, it adds the terminal's home network information as an ECS option element to the first query message to obtain a second query message, and sends the second query message to the DNS server so that the DNS server can determine the AS address corresponding to the first domain name based on the home network information as the ECS option element.

[0171] In Example 2, the rule includes: after receiving a query message from the terminal, providing the domain name in the query message to the second network element.

[0172] As described above, the first network element sends the first domain name to the second network element according to this rule. The second network element determines that the first domain name is not authorized in the service network and sends the terminal's home network information to the first network element. The first network element then provides the terminal's home network information to the DNS server.

[0173] For example, the first network element is an EASDF network element in the serving network, and the second network element is an SMF network element in the serving network. The SMF network element determines the ECS option corresponding to the first domain name reported by the EASDF network element (or, in other words, determines the information used to construct the ECS option for that domain name). The V-SMF network element sends the terminal's home network information to the EASDF network element. The EASDF network element can add the terminal's home network information as an ECS option to the second query message, making the second query message include the terminal's home network information. In this example, the EASDF network element does not need to determine whether the first domain name is authorized in the serving network.

[0174] The difference between Example 2 and Example 1 is that in Example 1, the first network element obtains the terminal's home network information before receiving the first query message, and determines that the second query message contains the terminal's home network information based on the fact that the first domain name is not authorized in the serving network. In Example 2, however, the second network element obtains the terminal's home network information after receiving the first query message and sending the first domain name to the second network element, thus determining that the second query message contains the terminal's home network information.

[0175] For example, both the first query message and the second query message can be referred to as DNS query messages.

[0176] S203, the DNS server sends the address of the AS corresponding to the first domain name to the first network element.

[0177] Accordingly, the first network element receives the address of the AS corresponding to the first domain name from the DNS server.

[0178] For example, the DNS server sends a second response message to the first network element in response to the second query message. This second response message includes the address of the AS corresponding to the first domain name. The first network element receives the second response message from the DNS server and determines the address of the AS corresponding to the first domain name based on the second response message.

[0179] S204, the first network element sends the address of the AS corresponding to the first domain name to the terminal.

[0180] Accordingly, the terminal receives the address of the AS corresponding to the first domain name from the first network element.

[0181] For example, a first network element sends a first response message to a terminal in response to a first query message. This second response message includes the address of the AS corresponding to the first domain name. The terminal receives the first response message from the first network element and determines the address of the AS corresponding to the first domain name based on the first response message.

[0182] According to the above scheme, when the first network element receives a query message from the terminal containing an unauthorized domain name in the serving network, the first network element can provide the DNS server with the terminal's home network information. This allows the DNS server to query the address of the AS corresponding to the first domain name based on the terminal's home network information and then return it to the terminal. This enables the terminal to obtain the address of the AS corresponding to an unauthorized domain name in the serving network (visited network or intermediate network), allowing the terminal to access the services provided by that AS and ensuring that the terminal device can access the services corresponding to unauthorized domain names. It also avoids the terminal being unable to access the services corresponding to a domain name due to its unauthorized nature.

[0183] Figure 3 This is a schematic flowchart of the communication method 300 provided in the embodiments of this application. Figure 3 The illustrated embodiment shows Figure 2 The illustrated embodiment is a specific implementation in a scenario where the serving network of the terminal (UE) is a visited network. The V-EASDF network element is an example of a first network element, used in the visited network to provide the UE with an AS discovery function. The V-SMF network element is an example of a second network element, used in the visited network to manage the UE's session. The AMF network element is used in the visited network for UE access management and / or mobility management. The H-SMF network element is used in the UE's home network to manage the UE's session. It should be understood that this application does not limit the names of the various network elements; in specific implementations, other network elements with corresponding functions can also be used to implement the communication method 300. The method 300 may include, but is not limited to, the following steps:

[0184] S301, the UE can send a NAS message to the AMF network element, which includes a session establishment / modification request message.

[0185] Session establishment / modification request messages refer to either session establishment request messages or session modification request messages.

[0186] When a UE visits a network, it sends a NAS message carrying session establishment / modification request information to an AMF network element to initiate a Home Router (HR) session establishment / modification procedure. Correspondingly, the AMF network element receives the NAS message from the UE and, based on the session establishment / modification request information in the NAS message, determines whether the UE has initiated an HR session establishment procedure.

[0187] S302, the AMF network element sends a Create / Update Session Management Context Request message to the V-SMF network element. This request message carries HR-SBO allowed indication information.

[0188] The HR-SBO authorization instruction information is used to indicate that the HR session is authorized (or permitted) to be offloaded locally (i.e., VPLMN). AMF network elements can determine the HR-SBO authorization instruction information based on the subscription information of the home network.

[0189] For example, the Create Session Management Context Request message can be denoted as N SMF Protocol Data Unit (PDU) Session - Create / Update Management Context Request (N SMF_PDUSession_Create / UpdateSMContext requeset) message.

[0190] S303, V-SMF network elements and V-EASDF network elements perform DNS context creation / update procedures.

[0191] After receiving a Create / Update Management Context Request message from an AMF network element, the V-SMF network element selects a V-EASDF network element to discover the AS for the UE, and the V-SMF network element and the V-EASDF network element perform the creation / update process of the DNS context of the V-EASDF network element.

[0192] The DNS context may include, but is not limited to, the UE's IP address, data network name (DNN), and single network slice selection assistance information (S-NSSAI) used to identify network slices. It should be understood that since the visited network has not yet exchanged information with the home network and has not yet obtained the IP address assigned to the UE by the home network, the UE's IP address contained in the DNS context at this time is a special value or special IP address that can be used to identify the UE.

[0193] The DNS context creation process can be achieved by a V-SMF network element sending a DNS context creation / update request message to a V-EASDF network element and receiving a DNS context creation / update response message from the V-EASDF network element, thereby realizing the DNS context creation / update of the V-EASDF network element. For example, the DNS context creation / update request message can be denoted as N. EASDF __DNS Context_Create / Update Request(N EASDF DNS context creation / update request messages. DNS context creation / update response messages can be denoted as N... EASDF DNS Context Creation / Update Response (N EASDF The message is "_DNSContext_Create / Update Response".

[0194] S304, the V-SMF network element sends a session creation / update request message to the H-SMF network element.

[0195] After the DNS context creation / update of the V-EASDF network element is completed, the V-SMF network element sends a session creation / update request message to the H-SMF network element. This session creation / update request message includes the HR-SBO authorization indication information obtained from the AMF network element in S302. After receiving the session creation / update request message from the V-SMF network element, the H-SMF network element determines, based on the HR-SBO authorization indication information in the session creation / update request message, that the UE's visited network request authorization session be locally offloaded in the visited network.

[0196] For example, this session creation request message can be denoted as N. SMF _PDU Session_ Creation / Update Request Message.

[0197] S305, the H-SMF network element sends a session creation / update response message to the V-SMF network element. This session creation / update response message carries VPLMN offloading information.

[0198] Accordingly, the V-SMF network element receives the session creation / update response message from the H-SMF network element and obtains the VPLMN traffic offloading information. For example, this session creation / update response message can be denoted as N. SMF _PDU Session_ Creation / Update Request Message.

[0199] The VPLMN routing information includes the domain name information described above, such as authorized domain name information in the visited network (which may include the first set of domain names mentioned above) and / or unauthorized domain name information in the visited network (which may include the second set of domain names mentioned above). For example, the domain names in the domain name set can be FQDNs or other domain names. The following explanation uses an FQDN domain name as an example.

[0200] The V-SMF network element can determine, based on the VPLMN routing information, that the corresponding service is authorized by the UE's home network to be routed to the domain name of the local data network in the visited network, and / or, based on the VPLMN routing information, that the corresponding service is not authorized by the UE's home network to be routed to the domain name of the local data network in the visited network.

[0201] In one optional implementation, the VPLMN offloading information may further include the addresses of authorized ASs in the visited network and / or the addresses of unauthorized ASs in the visited network, such as the AS's IP address. Based on the VPLMN offloading information, the V-SMF network element can determine that the corresponding service is authorized by the UE's home network to be offloaded to the address of an AS in the local data network of the visited network, and / or, based on the VPLMN offloading information, the V-SMF network element can determine that the corresponding service is not authorized by the UE's home network to be offloaded to the address of an AS in the local data network of the visited network.

[0202] In addition to VPLMN traffic offloading information, the session creation / update response message also includes the UE's IP address, i.e., the IP address assigned to the UE by the home network. In one optional implementation, the session creation / update response message includes two IP addresses assigned to the UE by the network side, such as IP address 1 and IP address 2. As described above, IP address 1 can be used to obtain the address of the AS corresponding to an unauthorized domain name in the visited network. IP address 1 is anchored to the UPF network element in the terminal's home network. IP address 2 is used to receive or send messages (or packets). However, this application is not limited to this; the session creation / update response message can also achieve the above two functions by including only one IP address assigned to the UE by the home network.

[0203] The session creation / update response message may also include tunnel information of the UPF element (i.e., H-UPF element) in the home network. This H-UPF element tunnel information is used to establish a tunnel connection between the UPF element (i.e., V-UPF element) in the visited network and the H-UPF element. This H-UPF element tunnel information can consist of the H-UPF element's IP address and tunnel endpoint identifier (TEID).

[0204] In Figure 3 In the illustrated embodiment, the session creation / update response message may further include information about the UE's home network. This home network information is provided by the V-SMF network element to the V-EASDF network element so that, upon receiving a query message from the UE containing an unauthorized domain name in the visited network, the V-EASDF network element can provide this home network information to the DNS server. In other words, the H-SMF network element can specifically send the UE's home network information to the V-SMF network element. However, this application is not limited to this; the H-SMF network element may also send the UE's home network information to the V-SMF network element via other messages or cells.

[0205] S306, V-SMF network elements and V-EASDF network elements perform DNS context update process.

[0206] V-SMF network elements update the DNS context of V-EASDF network elements, including the DNS message handling rules for V-SMF network elements.

[0207] In one optional implementation, the rule includes: upon receiving a query message from a terminal containing a domain name that is not authorized in the visited network, providing the UE's home network information to the DNS server. Exemplarily, the UE's home network information may include the UE's IP address, the IP address of the UE's H-UPF network element, or the dedicated address of the home network.

[0208] If the UE's home network information includes a dedicated address for the home network, that dedicated address can be obtained by the V-SMF network element from the H-SMF network element. However, this application is not limited to this.

[0209] Specifically, the rule may include: upon receiving a query message from a terminal containing a domain name that is not authorized in the visited network, adding the UE's home network information to the query message, and providing the processed query message to the DNS server.

[0210] In another alternative implementation, the rule includes: after receiving a query message from the terminal, providing the domain name in the query message to the second network element.

[0211] The DNS context update process may include a V-SMF network element sending a DNS context update request message to a V-EASDF network element and receiving a DNS context creation response message from the V-EASDF network element, thereby realizing the DNS context update of the V-EASDF network element. DNS processing rules may be carried in the DNS context update message. Optionally, the DNS context update request message may also carry one or more of the following information, but not limited to:

[0212] Information about the UE's home network, or the domain name information authorized in the visited network.

[0213] For example, a DNS context update request message can be denoted as N EASDF DNS Context Update Request (N EASDF The DNS context update response message can be denoted as N_DNSContext_Update Request. EASDF __DNS Context_Update Response(N EASDF The _DNSContext_Update Response message.

[0214] After a V-SMF network element completes the DNS context update for a V-EASDF network element, network elements in the visited network can continue to perform other steps for session creation / modification for that UE. Figure 3 (Not shown in the image), including: a V-SMF network element sending a session creation / modification accept message to the UE, the session creation / modification accept message carrying the address of the V-EASDF network element. After receiving the session creation / modification accept message, the UE can determine the address of the V-EASDF network element used to discover the AS for the UE.

[0215] When a UE needs to perform a service query, the UE initiates a service query process, which includes the following steps:

[0216] S307, the UE sends a first query message to the V-EASDF network element, which carries FQDN 1.

[0217] The source IP address of the first query message is the UE's IP address, and the destination IP address is the V-EASDF network element's address. Accordingly, the V-EASDF network element receives the first query message from the UE and determines the address of the AS corresponding to FQDN 1. Specifically, this first query message can be transmitted to the V-EASDF network element via the user plane. For example, the first query message can be transmitted to the V-EASDF via the RAN or V-UPF network element.

[0218] S308, the V-EASDF network element determines the second query message. This second query message includes FQDN 1 and information about the UE's home network.

[0219] In one optional implementation, the V-EASDF network element can obtain domain name information, such as obtaining domain name information in the DNS context. Based on the domain name information, it determines that FQDN 1 is an unauthorized domain name in the visited network. If the domain name information includes a first set of domain names, and the domain names contained in the first set of domain names are authorized domain names in the visited network, the V-EASDF network element determines that FQDN 1 does not belong to the first set of domain names, thereby determining that FQDN 1 is an unauthorized domain name in the visited network. And / or, if the domain name information includes a second set of domain names, and the domain names contained in the second set of domain names are unauthorized domain names in the home network, the V-EASDF network element determines that FQDN 1 belongs to the first set of domain names, thereby determining that FQDN 1 is an unauthorized domain name in the visited network.

[0220] If the V-EASDF network element determines that the FQDN 1 queried by the UE is an unauthorized domain name in the visited network, then the V-EASDF network element determines a second query message according to the DNS message processing rules. This second query message includes FQDN 1 and the UE's home network information. If the V-EASDF network element adds the UE's home network information to the first query message, the second query message is obtained.

[0221] The DNS processing rules specifically include: upon receiving a query message from a terminal containing an unauthorized domain name in the visited network, adding the UE's home network information as an ECS option to the query message, and then providing the query message to the DNS server. V-EASDF network elements can then add the UE's home network information as an ECS option to the first query message according to these processing rules, thus obtaining a second query message.

[0222] In another optional implementation, the V-EASDF network element, based on the DNS query message processing rules, provides the FQDN 1 to the V-SMF network element after receiving the first query message. The V-SMF network element determines the ECS option corresponding to FQDN 1 (or, in other words, determines the information used to construct the ECS option corresponding to FQDN 1) based on FQDN 1. The V-SMF network element sends the UE's home network information to the V-EASDF network element. The V-EASDF network element can then add the UE's home network information as an ECS option to the second query message, making the second query message include the terminal's home network information.

[0223] S309, the V-EASDF network element sends a second query message to the DNS server.

[0224] Accordingly, the DNS server receives the second query message from the V-EASDF network element. Based on address affinity, the DNS server can determine the address of the AS corresponding to FQDN 1.

[0225] S310, the DNS server sends the address of the AS corresponding to FQDN 1 to the V-EASDF network element.

[0226] For example, the DNS server sends a second response message to the V-EASDF network element in response to the second query message. This second response message includes the address of the AS corresponding to FQDN 1. The V-EASDF network element receives this second response message from the DNS server and determines the address of the AS corresponding to FQDN 1 based on the second response message.

[0227] S311, the V-EASDF network element sends the address of the AS corresponding to FQDN 1 to the UE.

[0228] Accordingly, the UE receives the address of the AS corresponding to FQDN 1 from the V-EASDF network element.

[0229] For example, the V-EASDF network element sends a first response message to the UE in response to the first query message. This second response message includes the address of the AS corresponding to FQDN 1. The UE receives the first response message from the V-EASDF network element and determines the address of the AS corresponding to FQDN 1 based on the first response message.

[0230] As described above, if the V-EASDF network element determines in S308 that FQDN 1 is an unauthorized domain name in the visited network, then S309 to S311 are executed. If the V-EASDF network element determines that FQDN 1 is an authorized domain name in the visited network, then the V-EASDF network element exchanges information with the V-SMF network element to trigger the V-SMF network element to insert / update VPLMNULCL / BP / L-PSA. The V-EASDF network element reports FQDN 1 to the V-SMF network element. Based on FQDN 1 and AS deployment information (including FQDN, data network access identifier (DNAI), etc.), the V-SMF network element determines the ECS option establishment instruction information and sends this ECS option establishment instruction information to the V-EASDF network element. The V-EASDF network element adds the ECS option to the first query message based on the ECS option establishment instruction information and sends the processed query message to the DNS server. The DNS server queries the address of the AS corresponding to FQDN 1 based on the received query message and sends it to the V-EASDF network element. The V-EASDF network element then reports the AS address corresponding to FQDN 1 to the V-SMF network element, triggering the V-SMF network element to insert / update ULCL / BP / L-PSA. The V-SMF network element instructs the V-EASDF network element to send a response message to the UE for the first query message, which carries the address of the AS corresponding to FQDN 1.

[0231] According to the above scheme, when a V-EASDF network element receives a query message from a UE containing an unauthorized domain name in the visited network, the V-EASDF network element can provide the DNS server with the UE's home network information. This allows the DNS server to query the address of the AS corresponding to FQDN 1 based on the UE's home network information and then relay it back to the terminal. This enables the terminal to obtain the address of the AS corresponding to an unauthorized domain name in the serving network within the visited network, allowing the terminal to access the services provided by that AS.

[0232] This application also provides a method in which, when a query message from a terminal contains a domain name that has not been authorized by the home network to be diverted to the local DN corresponding to the service network, the core network of the service network can transmit the query message to the home network via control plane network elements, thereby reaching the server in the local DN corresponding to the home network or reaching the central server, enabling the terminal to obtain the address of the AS corresponding to the domain name that has not been authorized in the service network.

[0233] Figure 4 This is a schematic flowchart of the communication method 400 provided in an embodiment of this application. Figure 4 As shown, the first network element is the network element in the terminal's serving network (such as the visited network or intermediate network) used for AS discovery; the second network element is the network element in the terminal's serving network used for managing the terminal's sessions; and the third network element is the network element in the terminal's home network. The DNS server is either the local server or the central server corresponding to the home network. Alternatively, Figure 4 The DNS server shown can be replaced by a network element in the home network used for AS discovery, which can be called a DNS resolver. The following explanation uses a DNS server as an example, and this method 400 includes, but is not limited to, the following steps:

[0234] S401, the terminal sends a first query message to the first network element, the first query message including information about the first domain name.

[0235] Accordingly, the first network element receives the first query message from the terminal. The first network element determines the address of the AS corresponding to the first domain name queried by the terminal, and the first network element can determine that the first domain name is not authorized in the service network. S401 can be implemented with reference to the description of S201 above, and will not be repeated here.

[0236] S402, the first network element sends a second query message to the second network element, the second query message including information about the first domain name.

[0237] In one optional implementation, the first network element may determine a second query message and send the second query message to the second network element based on the fact that the first domain name contained in the received first query message is an unauthorized domain name in the service network. Specifically, the first network element may determine the second query message and decide to send the second query message to the second network element according to the rules adopted for the query message.

[0238] For example, the second network element can send information to the first network element indicating the rules to be applied to a query message from a terminal for querying the address of an application server. Accordingly, the first network element receives this information from the second network element and determines the rules to be applied to the query message based on this information. Upon receiving a query message, the first network element processes the query message based on these rules. For instance, this information can be carried in a DNS context update message sent from the second network element to the first network element.

[0239] This rule may be implemented in ways including, but not limited to, the following.

[0240] Method 1, denoted as Rule 1, includes: if the query message used to query the address of the AS includes an unauthorized domain name in the visited network of the terminal, the first network element sends a query message containing the unauthorized domain name to the second network element.

[0241] After receiving a first query message containing an unauthorized first domain name in the service network, the first network element determines a second query message according to rule 1 and sends it to the second network element. The second query message includes information about the first domain name.

[0242] For example, a first network element can send the first query message to a second network element, where the second query message is the same as the first query message, and the source address of the first query message is the IP address of the terminal, and the destination address is the address of the first network element. However, this application is not limited to this; the second query message may differ from the first query message, such as by containing at least one different piece of information.

[0243] Method 2, referred to as Rule 2, includes: when the query message used to query the address of the application server includes an unauthorized domain name in the visited network of the terminal, the first network element sends a query message to the second network element containing the unauthorized domain name and the destination address being the address of the DNS server.

[0244] The information sent by the second network element to the first network element for indicating rules includes the address of a DNS server. This DNS server address can be the address of the DNS server corresponding to the terminal's home network or the address of the central DNS server. The first network element obtains the address of the DNS service from this information.

[0245] After receiving a first query message containing an unauthorized first domain name in the service network, the first network element determines a second query message according to rule 2 and sends it to the second network element. The second query message includes information about the first domain name, and the destination address of the second query message is the address of the DNS server.

[0246] For example, the source address of the first query message is the IP address of the terminal, and the destination address is the address of the first network element. The first network element modifies the destination address of the first query message to the address of the DNS server obtained from the second network element, obtains the second query message, and sends the second query message to the second network element. However, this application is not limited to this; the second query message may contain other different information than the first query message besides the different destination address.

[0247] In another optional implementation, the first network element does not determine whether the first domain name is authorized in the service network. For example, the second network element notifies the first network element of the processing rule for the query message as rule 3, which includes: upon receiving a query message from a terminal, providing the domain name in the query message to the second network element. After receiving the first query message, the first network element sends the first domain name to the second network element based on rule 3. The second network element, based on the first domain name and the authorized domain name information and / or unauthorized domain name information obtained by the second network element in the service network, determines that the first domain name is not authorized in the service network. The second network element then sends an instruction message to the first network element, which instructs the first network element to send a second query message to the second network element.

[0248] In one approach, the first network element sends the first query message to the second network element based on the instruction information, meaning the second query message is the first query message.

[0249] In another approach, the instruction specifically instructs the first network element to send a second query message to the second network element, wherein the destination address of the second query message is the address of a DNS server. This ensures that upon receiving the instruction, the first network element sends the second query message to the second network element, with the destination address of the second query message being the address of a DNS server.

[0250] In another embodiment, rule 3 further includes: after the first network element sends a domain name to the second network element and receives an instruction from the second network element instructing the first network element to send a query message, the first network element, in response to the instruction, sends a query message to the second network element with the destination address of a DNS server. Based on rule 3, the first network element can then send a second query message to the second network element with the destination address of a DNS server.

[0251] Optionally, the first network element may obtain the address of the DNS server or obtain the address of the DNS server from the indication information before receiving the first query message. The address of the DNS server may be the address of the DNS server corresponding to the terminal's home network or the address of the central DNS server. The first network element obtains the address of the DNS service from the information.

[0252] In this implementation, if the second network element determines that the domain name from the first network element is an authorized domain name in the service network, the second network element can determine the ECS option establishment instruction information based on the first domain name and AS deployment information (including FQDN, data network access identifier (DNAI) and other information), and send the ECS option establishment instruction information to the V-EASDF network element. The first network element adds the ECS option to the first query message based on the ECS option establishment instruction information, and sends the processed query message to the local DNS server in the visited network.

[0253] This application also provides a replacement for S402, meaning that after S401, the first network element can skip S402 and instead perform the following steps: The first network element sends a first domain name to the second network element. The second network element determines that the first domain name is an unauthorized domain name in the serving network. Then, the second network element determines (or generates) a third query message. This third query message includes the first domain name, and the destination address is the address of the DNS server. This third query message is used by the second network element in S403 to query the DNS server for the address of the AS corresponding to the first domain name through network elements in the home network as the terminal.

[0254] S403, the second network element queries the DNS server for the address of the AS corresponding to the first domain name for the terminal through the network elements in its home network.

[0255] The second network element queries the address of the AS corresponding to the first domain name from the local DNS server (hereinafter referred to as the DNS server corresponding to the home network) or the central server in the home network for the terminal through the network element in the home network. This includes: after receiving the second query message, the second network element obtains a third query message based on the second query message. The third query message includes the information of the first domain name. The second network element sends the third query message to the third network element.

[0256] The third network element is a network element in the terminal's home network. The second network element transmits the third query message to the terminal's home network so that the network elements in the home network can query the DNS server for the address of the AS corresponding to the first domain name.

[0257] If the second network element receives a second query message from the first network element that includes information about the first domain name, and the source address of the second query message is the IP address of the terminal and the destination address is the address of the first network element.

[0258] In one implementation, the third query message sent by the second network element to the third network element is the second query message. That is, after obtaining the second query message from the first network element, the second network element forwards the second query message to the third network element. For example, the third network element can modify the destination address in the second query message to the address of the DNS server corresponding to the home network or the address of the central server, so that the DNS server corresponding to the destination address can obtain the query message and thus query the address of the AS corresponding to the first domain name for the terminal.

[0259] In another implementation, the destination address of the third query message sent by the second network element to the third network element is the address of a DNS server. This DNS server address can be obtained by the second network element from network elements in its home network, and the second network element sets the destination address of the third query message to this DNS server address. For example, this DNS server address could be the address of the DNS server corresponding to the terminal's home network or the address of the central DNS server. This allows the DNS server corresponding to the destination address to obtain the query message and thus query the address of the AS corresponding to the first domain name for the terminal.

[0260] For example, the second network element modifies the destination address of the second query message to the address of the DNS server to obtain the third query message. However, this application is not limited to this; the third query message may contain other different information than the second query message besides the different destination address.

[0261] If the second network element receives a second query message from the first network element, and this second query message includes information about the first domain name, and the source address of the second query message is the terminal's IP address and the destination address is the DNS server's address, the third query message sent by the second network element to the third network element can be either the second query message or a second query message processed by the second network element. The source address of this third query message is the terminal's IP address, and the destination address is the DNS server's address. This is so that the DNS server corresponding to the destination address can obtain the query message and thus query the address of the AS corresponding to the first domain name for the terminal.

[0262] S404, The terminal obtains the address of the AS corresponding to the first domain name from the DNS server.

[0263] After the DNS server finds the address of the AS corresponding to the first domain name, it can pass the address of the AS to the network element in the serving network through the network element in the home network, and then to the terminal.

[0264] For example, the address of the AS can be passed from the DNS server to a third network element, then from the third network element to a second network element, and finally to a first network element. The terminal can then obtain the address of the AS from the first network element. That is, the address of the AS is returned to the terminal by the network element that transmits the query message. However, this application is not limited to this; the address of the AS can be passed to the terminal without passing through one or more network elements in the home network and the visited network that transmit the query message.

[0265] According to the above scheme, when the EASDF network element in the serving network receives a query message from the UE containing an unauthorized domain name in the visited network, the EASDF network element sends a query message to the SMF network element so that the message can be transmitted to the home network through the SMF network element. Through the transmission in the home network, the DNS server or central server corresponding to the home network can query the address of the AS corresponding to the first domain name for the terminal and feed it back to the terminal through the home network and the serving network, so that the terminal can access the services provided by the AS.

[0266] Figure 5 This is a schematic flowchart of the communication method 500 provided in the embodiments of this application. Figure 5 The illustrated embodiment shows Figure 4 The illustrated embodiment applies to a specific implementation in a visited network scenario where the service network of the terminal (UE) is used. It should be understood that prior to S501 of method 500, the UE and various network elements can perform actions such as... Figure 3 For details of S301 to S305 shown, please refer to [link / reference]. Figure 3 The description in the illustrated embodiment. Figure 5 In the illustrated embodiments, and Figure 3 The same parts in the illustrated embodiments can be referred to. Figure 3 The descriptions in the illustrated embodiments are omitted here for brevity. The method 500 may include, but is not limited to, the following steps:

[0267] S501, V-SMF network elements and V-EASDF network elements perform DNS context update process.

[0268] V-SMF network elements update the DNS context of V-EASDF network elements, including the V-SMF network element sending DNS message handling rules to the V-EASDF network element. These rules can be those described earlier. Figure 4 Rules 1 and 2 in the illustrated embodiment.

[0269] S502, the UE sends a first query message to the V-EASDF network element, which includes FQDN 1.

[0270] Accordingly, the V-EASDF network element receives the first query message from the UE, determines that the UE is querying the address of the AS corresponding to FQDN 1, and that FQDN 1 is an unauthorized domain name in the network visited by the UE.

[0271] S503, V-EASDF network element determines the second query message.

[0272] The source IP address of the first query message is the UE's IP address, and the destination IP address is the address of the V-EASDF network element. This V-EASDF network element then obtains the second query message based on the DNS message processing rules obtained in S501.

[0273] In one example, the rule is rule 1 above. The V-EASDF network element determines the second query message according to rule 1. The second query message includes FQDN 1, and the source address of the second query message is the IP address of the UE and the destination address is the address of the V-EASDF network element.

[0274] In another example, the rule is rule 2 mentioned above. The V-EASDF network element determines a second query message based on rule 2. This second query message includes FQDN 1, and the source address of the second query message is the UE's IP address, and the destination address is the DNS server address. The DNS server address can be the address of the DNS server corresponding to the home network or the address of the central server. The DNS server address can be obtained by the V-EASDF network element from the V-SMF network element in S501. The V-SMF network element can obtain the DNS server address from the home network; for example, the DNS server address can be included in the VPLMN routing information in the session creation / update response message.

[0275] In another example, the rule is rule 3 above. According to rule 3, the V-EASDF network element sends FQDN 1 to the V-SMF network element. After the V-SMF network element determines that FQDN 1 is an unauthorized domain name in the visited network, the V-SMF network element instructs the V-EASDF network element to send a query message to the V-SMF network element. The V-EASDF network element determines this second query message and sends it to the V-SMF network element. This second query message includes FQDN 1, and the destination address of the second query message is either the address of the V-EASDF network element or the address of the DNS server. For details on how the V-EASDF network element determines the second query message, please refer to the relevant description in S402, which will not be repeated here.

[0276] For example, the address of the DNS server can be the IP address of the DNS server.

[0277] S504, the V-EASDF network element sends a DNS context notification message to the V-SMF network element, which includes a second query message.

[0278] The V-EASDF network element sends a DNS context notification message containing the second query message to the V-SMF network element according to the DNS query message processing rules. Correspondingly, the SMF network element receives the DNS context update message from the V-EASDF network element, obtains the second query message, and determines the third query message based on the second query message. The specific method can be referred to the description in S403 above, and will not be repeated here.

[0279] For example, this DNS context notification message can be denoted as N EASDF DNS Context Notification (N EASDF The _DNSContext_Notify message.

[0280] S505, the V-SMF network element sends a session update request message to the H-SMF network element, which includes the third query message.

[0281] Accordingly, the H-SMF network element receives the session update request message from the V-SMF network element and obtains the third query message. For example, the session update request message can be denoted as N. SMF _PDU Session_ Update Request (N SMF The message is _PDUSession_Update Request.

[0282] S506, the H-SMF network element transmits the query message to the DNS server.

[0283] In one example, the source address of the third query message is the IP address of the UE, and the destination address is the address of the DNS server. The H-SMF network element can send the third query message to the H-UPF network element, which then sends it to the DNS server corresponding to the address of the DNS server.

[0284] In another example, the source address of the third query message is the UE's IP address, and the destination address is the V-EASDF address. The H-SMF network element can modify the destination address of the third query message to the DNS server address before sending it to the H-UPF network element. Alternatively, the H-SMF network element can pass the third query message to the H-UPF network element, which then modifies the destination address of the third query message and sends it to the DNS server corresponding to the destination address. Or, the H-UPF network element can send the third query message to the H-EASDF network element, which modifies the destination address of the third query message before passing it to the DNS server corresponding to that destination address. In this case, the H-EASDF's modification of the destination address of the third query message is based on the DNS processing rules issued by the H-SMF.

[0285] S507, the terminal obtains the address of the AS corresponding to FQDN 1 from the DNS server.

[0286] After determining the address of the AS corresponding to FQDN 1, the DNS server sends a DNS response message, which includes the address of the AS corresponding to FQDN 1. The source address of this DNS response message is the address of the DNS server.

[0287] In one example, the destination address of the DNS response message is the IP address of the UE. This DNS response message can be transmitted from the DNS server to the H-UPF network element, and then through the V-UPF network element to the UE. Alternatively, the path from the DNS server to the UE can be via the H-UPF network element, V-UPF network element, V-EASDF network element, and then back to the V-UPF network element.

[0288] In another example, the destination address of the DNS response message is the IP address of a V-EASDF network element. The path from the DNS server to the UE can be via H-UPF network element, H-SMF network element, V-SMF network element, V-EASDF network element, and V-UPF network element. Alternatively, the path from the DNS server to the UE can be via H-UPF network element, V-UPF network element, V-EASDF network element, and V-UPF network element.

[0289] According to the above scheme, when the V-EASDF network element receives a query message from the UE containing an unauthorized domain name in the visited network, the V-EASDF network element sends a query message to the V-SMF network element so that the message can be transmitted to the home network through the V-SMF network element. Through the transmission of the home network, the DNS server or central server corresponding to the home network can query the address of the AS corresponding to FQDN 1 for the terminal and feed it back to the terminal through the home network and the serving network, so that the terminal can access the services provided by the AS.

[0290] This application also provides another solution whereby the terminal queries the address of the AS corresponding to an unauthorized domain name in the service network through the user plane of the service network. This solution is described below.

[0291] The terminal determines that the first domain name to be queried is not authorized in the service network. The terminal determines a first message, which includes a query message and an indication message. The query message is used to query the address of the AS corresponding to the first domain name, and the indication message is used to indicate that the query message is used to query the address of the AS corresponding to the domain name that is not authorized in the service network, or the indication message is used to indicate that the query message contains a domain name that is not authorized in the service network.

[0292] In one approach, the terminal adds the indication information to the air interface protocol header and sends it to the access network element. For example, the indication information is added to the Service Data Adaptation Protocol (SDAP) header or the Packet Data Convergence Protocol (PDCP) header. The base station then adds the indication information to the core network user plane protocol header, such as the GPRS tunneling protocol-user plane (GTP-U) header.

[0293] The terminal sends the first message to a UPF element in the serving network. Based on the indication information in the first message, the UPF element determines that the query message is for querying the address of the AS corresponding to an unauthorized domain name in the serving network. Then, the UPF element sends the query message to the UPF element in the terminal's home network, so that the UPF in the home network can query the address of the AS corresponding to the unauthorized domain name in the serving network for the terminal. In this method, the UPF element in the serving network does not need to interpret the query message in the first message; it can determine to pass the query message to the UPF element in the home network based on the indication information in the first message.

[0294] Specifically, the first message may include a container containing the terminal's query message. Indication information from the first message is carried outside the container. After reading the indication information in the first message, the UPF element in the serving network sends the container to the UPF element in the home network. The UPF element in the serving network then transparently transmits (referred to as pass-through) the container to the UPF element in the home network.

[0295] In this scheme, even if the terminal encrypts the query message (e.g., using DOH or DOT encryption), the UPF network element in the serving network cannot decipher the query message. However, without deciphering the query message, the UPF network element can still determine, through the indication information in the first message, to pass the query message to the UPF network element in the home network. This allows the home network to retrieve the address of the AS corresponding to the unauthorized domain name in the serving network for the terminal. DOH is an abbreviation for DNS over HTTPS, a secure domain name resolution scheme that uses the encrypted HTTPS protocol for DNS resolution requests. HTTPS stands for Hypertext Transfer Protocol Secure. DOT is a DNS request that uses TLS for message encryption. TLS is an abbreviation for DNS over TLS.

[0296] It should be understood that, in the preceding text Figures 2 to 5 In this embodiment, the first network element and the second network element are capable of decrypting encrypted query messages from the terminal. Therefore, regardless of whether the query message is encrypted, Figures 2 to 5 All embodiments are capable of enabling terminals to query the address of the AS corresponding to an unauthorized domain name in the service network.

[0297] It is understood that, in order to achieve the functions in the above embodiments, each of the network elements and terminals includes corresponding hardware structures and / or software modules for performing each function. Those skilled in the art should readily recognize that, based on the units and method steps described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.

[0298] Figure 6 and Figure 7The diagram illustrates the possible structures of communication devices provided in embodiments of this application. These communication devices can be used to implement the functions of various network elements (such as the first network element, the second network element, the third network element, and the fourth network element) in the above-described method embodiments, and thus can also achieve the beneficial effects of the above-described method embodiments. In the embodiments of this application, the communication device can be as follows: Figure 1 The EASDF, SMF, or UPF network elements shown can also be modules (such as chips or chip systems) of communication devices that implement the functions of the above network elements.

[0299] The communication device 600 includes a transceiver unit 620, which can be used to receive or send information. The communication device 600 may also include a processing unit 610, which can be used to process instructions or data to achieve corresponding operations.

[0300] It should be understood that when the communication device 600 is a chip configured in (or used in) a communication device, the transceiver unit 620 in the communication device 600 can be the input / output interface or circuit of the chip, and the processing unit 610 in the communication device 600 can be the processor in the chip.

[0301] Optionally, the communication device 600 may further include a storage unit 630, which can be used to store instructions or data. The processing unit 610 can execute the instructions or data stored in the storage unit to enable the communication device to perform corresponding operations.

[0302] For a more detailed description of the processing unit 610 and the transceiver unit 620, please refer to [reference needed]. Figures 3 to 5 The relevant descriptions in the method embodiments shown.

[0303] It should be understood that the transceiver unit 620 in the communication device 600 can be implemented through a communication interface (such as a transceiver, transceiver circuit, input / output interface, or pins, etc.). When the communication interface is a transceiver, the transceiver can consist of a receiver and / or a transmitter. The processing unit 610 in the communication device 600 can be implemented through at least one processor, or it can be implemented through at least one logic circuit. Optionally, the communication device 600 also includes a storage unit, which can be implemented using a memory.

[0304] When the aforementioned communication device is a module applied to a network device, the network device module implements the functions of the network element in the above method embodiments. The network device module receives information from other modules within the network device, the information being received by the network device from other devices (such as other network devices or terminals); or, the network device module sends information to other modules within the network device, the information being sent by the network device to other devices (such as other network devices or terminals). Here, the network device module can be a chip within the network device.

[0305] like Figure 7 As shown, the communication device 700 includes a processor 710 and an interface circuit 720. The processor 710 and the interface circuit 720 are coupled to each other. It is understood that the interface circuit 720 can be a transceiver or an input / output interface. Optionally, the communication device 700 may also include a memory 730 for storing instructions executed by the processor 710, or storing input data required by the processor 710 to execute instructions, or storing data generated after the processor 710 executes instructions.

[0306] It is understood that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.

[0307] The method steps in the embodiments of this application can be implemented in hardware or in software instructions executable by a processor. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. The storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in an access network device or a terminal device. The processor and storage medium can also exist as discrete components in a communication device.

[0308] According to the method provided in the application embodiments, this application embodiment also provides a computer program product, the computer program product comprising: computer program code, which, when executed by one or more processors, causes a device including the processor to perform as described above. Figures 3 to 5 The method shown.

[0309] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device.

[0310] According to the method provided in the embodiments of this application, the embodiments of this application also provide a computer-readable storage medium that stores the aforementioned computer program or instructions. When the computer program or instructions are executed by one or more processors, they cause a device including the processor to perform actions such as... Figures 2 to 5 The method shown.

[0311] As described above, computer programs or instructions can be stored in or transferred from one computer-readable storage medium to another. For example, the computer programs or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or it can include both volatile and non-volatile types of storage media.

[0312] According to the method provided in the embodiments of this application, the embodiments of this application also provide a communication system, including one or more of the aforementioned first communication devices. The system may further include one or more of the aforementioned second communication devices.

[0313] In the various embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatuses described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the couplings or direct couplings or communication connections shown or discussed may be through some interfaces; indirect couplings or communication connections between apparatuses or units may be electrical, mechanical, or other forms.

[0314] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this solution according to actual needs.

[0315] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0316] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method characterized by comprising: Comprising: a first network element receives a first query message from a terminal, the first network element being in a visited network of the terminal, the first query message comprising information of a first domain name, the first domain name being unauthorized in the visited network of the terminal; the first network element sends a second query message to a domain name system (DNS) server, the second query message comprising information of the first domain name and information of a home network of the terminal, the information of the home network being used for determining an address of an application server, the application server being used for providing a service corresponding to the first domain name for the terminal; the first network element receives the address of the application server from the DNS server.

2. The method of claim 1, wherein, The method further comprises: the first network element receives information from a second network element, the information being used for indicating a rule adopted for a query message from the terminal for querying the address of the application server, the rule comprising: in a case that the query message for querying the address of the application server comprises a domain name unauthorized in the visited network of the terminal, the first network element provides the information of the home network to the DNS server.

3. The method of claim 1, wherein, The method further comprises: the first network element receives information from a second network element, the information being used for indicating a rule adopted for the first query message, the rule comprising: the first network element provides the information of the home network to the DNS server.

4. The method according to claim 2 or 3, characterized in that, The rule specifically comprises: in a case that the query message for querying the address of the application server comprises a domain name unauthorized in the visited network of the terminal, the first network element carries the information of the home network and the unauthorized domain name in one message and provides to the DNS server.

5. The method according to any one of claims 2 to 4, characterized in that, The first network element is a functional network element for discovering the application server in the visited network of the terminal, and the second network element is a functional network element for managing a session of the terminal in the visited network of the terminal.

6. The method according to any one of claims 1 to 5, characterized in that, The second query message comprises an ECS option information element, the ECS option information element indicating the information of the home network.

7. The method according to any one of claims 1 to 6, characterized in that, The information of the home network comprises one or more of: an Internet protocol (IP) address of the terminal, an IP address of a user plane functional network element in the home network, or a dedicated address of the home network.

8. The method according to any one of claims 1 to 7, characterized in that, The first network element receives the address of the application server from the DNS server, comprising: the first network element receives a second response message for the second query message from the DNS server, the second response message comprising the address of the application server; and the method further comprises: the first network element sends a first response message for the first query message to the terminal, the first response message comprising the address of the application server.

9. The method according to any one of claims 1 to 8, characterized in that, The method further comprises: the first network element acquires domain name information authorized in the visited network of the terminal and / or domain name information unauthorized in the visited network of the terminal; the first network element determines that the first domain name is unauthorized in the visited network of the terminal according to the domain name information.

10. The method of claim 9, wherein, The domain name information includes a first domain name set, the first domain name set including one or more domain names authorized in a visited network of the terminal, and the first domain name not belonging to the first domain name set; and / or The domain name information includes a second domain name set, the second domain name set including one or more domain names not authorized in the visited network of the terminal, and the first domain name belonging to the second domain name set.

11. The method according to any one of claims 1 to 10, characterized in that, The first domain name not being authorized in the visited network of the terminal includes that a service corresponding to the first domain name is not authorized by the home network to be offloaded to a local data network.

12. A communication method characterized by comprising: The method comprises: The second network element sends first information to the terminal, the first information being used to indicate that the first network element is used to discover an application server providing a service for the terminal, the first network element and the second network element being in a visited network of the terminal; The second network element sends second information to the first network element, the second information being used to indicate a rule adopted for a query message from the terminal for querying an address of an application server, the rule including that in a case where the query message for querying the address of the application server includes a domain name not authorized in the visited network of the terminal, the first network element provides information of a home network of the terminal to a DNS server.

13. The method of claim 12, wherein, The rule specifically includes that in a case where the query message for querying the address of the application server includes the domain name not authorized in the visited network of the terminal, the first network element carries the information of the home network and the domain name not authorized in one message and provides the information to the DNS server.

14. The method according to claim 12 or 13, characterized in that, The method further comprises: The second network element receives third information from a third network element, the third network element being in a home network of the terminal, the third information including information of the home network of the terminal, the information of the home network being used to query an application server corresponding to a domain name not authorized in the visited network of the terminal.

15. The method according to any one of claims 12 to 14, characterized in that, The information of the home network includes an IP address of the terminal, an IP address of a user plane function network element in the home network, or a special address of the home network.

16. The method according to any one of claims 12 to 15, characterized in that, The first network element is a function network element used to discover an application server in a visited network of the terminal, and the second network element is a function network element used to manage a session of the terminal in the visited network of the terminal.

17. The method according to any one of claims 12 to 16, characterized in that, The domain name not authorized in the visited network of the terminal includes that a service corresponding to the domain name is not authorized by the home network to be offloaded to a local data network.

18. A method of communication, comprising: The method comprises: A first network element receives a first query message from a terminal, the first query message including information of a first domain name, the first domain name not being authorized in a visited network of the terminal; The first network element sends a second query message to a second network element, the second query message comprising information of the first domain name, and a destination address of the second query message being an address of a Domain Name System (DNS) server, the DNS server being configured to query, for the terminal, an address of an application server corresponding to a domain name that is not authorized in a visited network of the terminal, the application server being configured to provide a service corresponding to the first domain name for the terminal; The first network element receives the address of the application server from the second network element.

19. The method of claim 18, wherein, The DNS server is a DNS server corresponding to a home network of the terminal, or the DNS server is a central DNS server in a central data network.

20. The method of claim 18 or 19, wherein, The method further comprises: The first network element receives information from the second network element, the information being configured to indicate a rule adopted for a query message from the terminal for querying an address of an application server, the rule comprising: in a case where the query message for querying an address of an application server comprises a domain name that is not authorized in a visited network of the terminal, the first network element sends a query message containing the domain name that is not authorized and having a destination address of the DNS server to the second network element.

21. The method of claim 18 or 19, wherein, The method further comprises: The first network element receives information from the second network element, the information being configured to indicate a rule adopted for the first query message, the rule comprising: the first network element provides the second query message containing the first domain name and having a destination address of the DNS server to the second network element.

22. The method of any one of claims 18-21, wherein, The first network element is a functional network element for discovering an application server in a visited network of the terminal, and the second network element is a functional network element for managing a session of the terminal in the visited network of the terminal.

23. The method of any one of claims 18-22, wherein, The first network element receives the address of the application server from the second network element, comprising: The first network element receives a second response message for the second query message from the second network element, the second response message comprising the address of the application server; And the method further comprises: The first network element sends a first response message for the first query message to the terminal, the first response message comprising the address of the application server.

24. The method of any one of claims 18-23, wherein, The method further comprises: The first network element acquires domain name information that is authorized in a visited network of the terminal and / or domain name information that is not authorized in the visited network of the terminal; The first network element determines, according to the domain name information, that the first domain name is not authorized in the visited network of the terminal.

25. The method of claim 24, wherein, The domain name information comprises a first domain name set, the first domain name set comprising one or more domain names that are authorized in the visited network of the terminal, and the first domain name not belonging to the first domain name set; and / or The domain name information comprises a second domain name set, the second domain name set comprising one or more domain names that are not authorized in the visited network of the terminal, and the first domain name belonging to the second domain name set.

26. The method of any one of claims 18-25, wherein, The first domain name is not authorized in a visited network of the terminal, including that a service corresponding to the first domain name is not authorized by a home network of the terminal to be offloaded to a local data network.

27. A method of communication, comprising: Including: The second network element receives a second query message from the first network element, the second query message including information of a first domain name from a terminal, and a destination address of the second query message being an address of a domain name system (DNS) server, the first domain name not being authorized in a visited network of the terminal, the DNS server being configured to query an address of an application server corresponding to the first domain name for the terminal in the visited network of the terminal, the application server being configured to provide a service corresponding to the first domain name for the terminal, the second query message being configured to query the address of the application server corresponding to the first domain name for the terminal from the DNS server, the first network element being a functional network element in the visited network of the terminal and configured to manage a session of the terminal, and the second network element being a functional network element in the visited network of the terminal and configured to discover the application server; The second network element queries, through a network element in a home network of the terminal, the address of the application server corresponding to the first domain name for the terminal from the DNS server.

28. The method of claim 27, wherein, The DNS server is a DNS server corresponding to the home network of the terminal, or the DNS server is a DNS server in a central data network.

29. The method of claim 27 or 28, wherein, The method further includes: The second network element sends information to the first network element, the information being configured to indicate a rule for a query message from the terminal and configured to query an address of an application server, the rule including that, in a case where the query message for querying the address of the application server includes a domain name not authorized in the visited network of the terminal, the first network element sends, to the second network element, a query message including the domain name not authorized and having an address of the DNS server as a destination address.

30. The method of any one of claims 27-29, wherein, The method further includes: The second network element receives a third response message from a third network element, the third response message including an address of an application server corresponding to the first domain name, the third network element being a functional network element in the home network and configured to manage a session of the terminal; And the method further includes: The second network element sends, to the first network element, a second response message for the second query message, the second response message including the address of the application server corresponding to the first domain name.

31. The method of any one of claims 27-30, wherein, The second network element queries, through a network element in a home network of the terminal, the address of the application server corresponding to the first domain name for the terminal from the DNS server, including: The second network element sends a third query message to a third network element, the third query message being configured to query the address of the application server corresponding to the first domain name for the terminal from the DNS server, and the third query message including information of the first domain name, wherein the third network element is a functional network element in the home network and configured to manage a session of the terminal.

32. The method of any one of claims 27-31, wherein, The first domain name is not authorized in a visited network of the terminal, including that a service corresponding to the first domain name is not authorized by the home network to be offloaded to a local data network.

33. A method of communication, comprising: Including: The second network element sends first information to the terminal, the first information being used for indicating that the first network element is used to discover an application server for providing a service for the terminal, the first network element and the second network element being in a visited network of the terminal, the first network element and the second network element being in a visited network of the terminal; The second network element sends second information to the first network element, the second information being used for indicating a rule adopted for a query message from the terminal for querying an address of an application server, the rule including that in a case where the query message for querying the address of the application server includes a domain name that is not authorized in a visited network of the terminal, the first network element provides information of a home network of the terminal to a DNS server; The first network element receives a first query message from the terminal, the first query message including information of a first domain name, the first domain name not being authorized in a visited network of the terminal; The first network element sends a second query message to a domain name system (DNS) server, the second query message including information of the first domain name and information of a home network of the terminal, the information of the home network being used for determination of an address of an application server, the application server being used to provide a service corresponding to the first domain name for the terminal; The first network element receives the address of the application server from the DNS server; The first network element sends the address of the application server to the terminal.

34. A method of communication, comprising: Including: The first network element receives a first query message from the terminal, the first query message including information of a first domain name, the first domain name not being authorized in a visited network of the terminal; The first network element sends a second query message to a second network element, the second query message including information of the first domain name, and a destination address of the second query message being an address of a domain name system (DNS) server, the DNS server being used to query, for the terminal, an address of an application server corresponding to a domain name that is not authorized in a visited network of the terminal, the application server being used to provide a service corresponding to the first domain name for the terminal; The second network element queries, for the terminal, the address of the application server corresponding to the first domain name from the DNS server through a network element in a home network of the terminal; The first network element receives the address of the application server from the second network element; The first network element sends the address of the application server to the terminal.

35. A communications device, characterized by The communication apparatus includes a processor coupled with a memory, the memory being used to store a computer program, and the processor being used to execute the computer program stored in the memory, so that the communication apparatus performs the method according to any one of claims 1 to 32.

36. A communications device, characterized by The communication apparatus includes modules for performing the method according to any one of claims 1 to 32.

37. A communication system, characterized by Including: a communication device for performing the method according to any one of claims 1 to 11 and a communication device for performing the method according to any one of claims 12 to 17; and / or, a communication device for performing the method according to any one of claims 18 to 26 and a communication device for performing the method according to any one of claims 27 to 32.

38. A computer readable storage medium comprising a computer program which, when executed on a computer, causes the computer to perform the method according to any one of claims 1 to 32.

39. A computer program product, characterised in that, The computer program product comprises a computer program which, when executed on a computer, causes the computer to perform the method according to any one of claims 1 to 32.

Citation Information

Patent Citations

  • A method, system, apparatus and control function entity for providing user information

    WO2007076722A1

  • Method, apparatus and system for discovering application

    WO2021168715A1