Service providing method and apparatus, computer device and storage medium

CN119789060BActive Publication Date: 2026-06-23CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2024-12-31
Publication Date
2026-06-23

Smart Images

  • Figure CN119789060B_ABST
    Figure CN119789060B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of wireless communication, in particular to a service providing method and device, a computer device and a storage medium. The method comprises the following steps: receiving an initial service request sent by a service demander; performing address inverse transformation on a target FQDN to obtain a service network address; replacing the target FQDN in the initial service request with the service network address to obtain a target service request; and sending the target service request to a service provider, so that the service provider provides services to the service demander according to a functional network element corresponding to the service network address. The application realizes the sending of the service network address under the condition that only the SEPP network element performs address inverse transformation on the target FQDN to obtain the service network address, without the functional adjustment of other network elements, so that the communication mechanism does not need to additionally construct a DNS or a database, the management and maintenance cost of maintaining the mapping relationship between the domain network FQDN and the service network address is reduced, and the risk of service transmission interruption is also reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technology, and in particular to a service provision method, apparatus, computer equipment, and storage medium. Background Technology

[0002] In the 5G SA (5G Standalone) international roaming network architecture, operators interconnect through SEPP (Security Edge Protection Proxy) for signaling forwarding. In the signaling request message received by the home SEPP from the serving SEPP, the address format of the service provider is FQDN (Fully Qualified Domain Name). In direct routing mode, the home SEPP needs to obtain the service network address corresponding to the FQDN within the domain before it can forward the message to the corresponding service provider within the domain.

[0003] Therefore, communication agencies need to additionally maintain the mapping relationship between the entire network FQDN and service network addresses within the domain by building a DNS (Domain Name System) or database, which also leads to an increase in management and maintenance costs. Summary of the Invention

[0004] Therefore, it is necessary to provide a service delivery method, apparatus, computer equipment, and storage medium that can reduce management and maintenance costs in response to the above-mentioned technical problems.

[0005] Firstly, this application provides a service provision method. The method includes:

[0006] Receive an initial service request sent by a service requester; wherein the initial service request carries a target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response after receiving a service discovery response for the service requester sent by the Network Repository Function (NRF) network element.

[0007] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0008] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address.

[0009] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0010] In one embodiment, generating the target FQDN based on the service network address carried in the service discovery response includes:

[0011] Extract the service network address of the service provider carried in the service discovery response;

[0012] The service network address is encrypted to determine the target FQDN.

[0013] In one embodiment, determining the target FQDN based on address encryption of the serving network address includes:

[0014] The service network address is encrypted to obtain an encrypted string;

[0015] The domain name information of the communication organization is added to the suffix of the encrypted string, and the encrypted string with the domain name information of the communication organization added to the suffix is ​​used as the target FQDN.

[0016] In one embodiment, the service discovery response is a response sent by the NRF network element to the SEPP network element after receiving the service discovery request sent by the service requester.

[0017] In one embodiment, the step of performing inverse address transformation on the target FQDN to obtain the serving network address includes:

[0018] The target FQDN is decrypted to obtain the service network address.

[0019] In one embodiment, the step of decrypting the target FQDN to obtain the serving network address includes:

[0020] The encrypted string contained in the target FQDN is decrypted to obtain the service network address.

[0021] Secondly, this application also provides a service providing apparatus. The apparatus includes:

[0022] The receiving module is used to receive an initial service request sent by a service requester; wherein the initial service request carries a target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response after receiving the service discovery response sent by the Network Repository Function (NRF) network element for the service requester.

[0023] The transformation module is used to perform inverse address transformation on the target FQDN to obtain the serving network address;

[0024] The replacement module is used to replace the target FQDN in the initial service request with the service network address to obtain the target service request;

[0025] The sending module is used to send the target service request to the service producer, so that the service producer can provide services to the service demander according to the functional network element corresponding to the service network address.

[0026] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0027] Receive an initial service request sent by a service requester; wherein the initial service request carries a target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response after receiving a service discovery response for the service requester sent by the Network Repository Function (NRF) network element.

[0028] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0029] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address.

[0030] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0031] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0032] Receive an initial service request sent by a service requester; wherein the initial service request carries a target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response after receiving a service discovery response for the service requester sent by the Network Repository Function (NRF) network element.

[0033] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0034] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address.

[0035] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0036] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:

[0037] Receive an initial service request sent by a service requester; wherein the initial service request carries a target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response after receiving a service discovery response for the service requester sent by the Network Repository Function (NRF) network element.

[0038] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0039] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address.

[0040] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0041] The aforementioned service provision method, apparatus, computer equipment, and storage medium receive an initial service request carrying a target FQDN from a service requester, perform inverse address transformation on the target FQDN to obtain a service network address, and replace the target FQDN in the initial service request with the service network address to obtain a target service request. Then, the target service request is sent to a service provider, enabling the service provider to provide services to the service requester based on the functional network element corresponding to the service network address. As can be seen from the above, this application, by receiving an initial service request from a service requester and replacing the target FQDN in the initial service request with a service network address, achieves the transmission of the service network address by performing inverse address transformation on the target FQDN using only the SEPP network element, without requiring functional adjustments to other network elements. This eliminates the need for communication institutions to build additional DNS or databases, reducing the management and maintenance costs of maintaining the mapping relationship between FQDNs and service network addresses across the entire domain, reducing the risk of service transmission interruptions, and eliminating potential service interruption risks caused by untimely updates to the mapping relationship data between FQDNs and service network addresses. Attached Figure Description

[0042] Figure 1An application environment diagram for a service provision method provided in an embodiment of this application;

[0043] Figure 2 A flowchart illustrating the first service provision method provided in this application embodiment;

[0044] Figure 3 A flowchart illustrating the second service provision method provided in this application embodiment;

[0045] Figure 4 A flowchart illustrating the third service provision method provided in this application embodiment;

[0046] Figure 5 A schematic diagram illustrating the process of a SEPP network element generating a target FQDN, provided for an embodiment of this application;

[0047] Figure 6 This is a schematic diagram illustrating a process by which S sends a target service request to a service provider, as provided in an embodiment of this application.

[0048] Figure 7 A structural block diagram of a service providing apparatus provided in an embodiment of this application;

[0049] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0051] The service provision method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, SEPP network element 102 communicates with NRF (Network Repository Function) network element 104 via the network. The data storage system can store the data that server 104 needs to process. The data storage system can be integrated on server 104 or placed in the cloud or on other network servers. By receiving an initial service request carrying a target FQDN sent by the service requester, the system performs inverse address transformation on the target FQDN to obtain the service network address; then, it replaces the target FQDN in the initial service request with the service network address to obtain the target service request; subsequently, it sends the target service request to the service producer, enabling the service producer to provide services to the service requester according to the functional network element corresponding to the service network address.

[0052] In one embodiment, such as Figure 2 As shown, a service provision method is provided, which is applied to Figure 1 Taking the SEPP network element in the example, the explanation includes the following steps:

[0053] S201, Receive the initial service request sent by the service requester.

[0054] The initial service request carries the target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element after receiving the service discovery response for the service requester sent by the network repository function (NRF) network element, based on the service network address carried in the service discovery response.

[0055] In one embodiment of this application, the service requester sends an initial service request to the Serving SEPP network element of the Serving PLMN (Serving Public Land Mobile Network); the Serving SEPP network element forwards the initial service request to the Home SEPP network element of the Home PLMN (Home Public Land Mobile Network), the execution subject of the service provision method, thereby realizing the operation of receiving the initial service request sent by the service requester.

[0056] The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving a service discovery request from the service requester.

[0057] S202, perform inverse address transformation on the target FQDN to obtain the serving network address.

[0058] It should be noted that since the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response sent by the Network Repository Function (NRF) network element after receiving the service discovery response for the service requester, the service network address can be obtained by performing an inverse transformation on the target FQDN.

[0059] In one embodiment of this application, if the target FQDN is obtained by encrypting the service network address, then when it is necessary to obtain the service network address, the target FQDN can be decrypted to obtain the service network address.

[0060] In another embodiment of this application, when it is necessary to perform inverse address transformation on the target FQDN, the mapping relationship between the target FQDN and the service network address can be obtained in advance. The mapping relationship records at least one candidate FQDN and different candidate network addresses corresponding to each candidate FQDN. Then, according to the mapping relationship, the operation of performing inverse address transformation on the target FQDN to obtain the service network address can be realized.

[0061] Specifically, after determining the target FQDN, the similarity between the target FQDN and at least one candidate FQDN recorded in the mapping relationship is compared. The candidate FQDN that is the same as the target FQDN is used as the reference FQDN. Then, the candidate network address corresponding to the reference FQDN in the mapping relationship is used as the service network address.

[0062] S203, replace the target FQDN in the initial service request with the service network address to obtain the target service request.

[0063] In one embodiment of this application, the data location of the target FQDN in the initial service request is determined. Then, after determining the service network address, the service network address is replaced with the target FQDN at the data location to obtain the target service request.

[0064] S204, the target service request is sent to the service provider so that the service provider can provide services to the service requester according to the functional network element corresponding to the service network address.

[0065] The aforementioned service provision method involves receiving an initial service request carrying a target FQDN from a service requester, performing an inverse address transformation on the target FQDN to obtain a service network address, and replacing the target FQDN in the initial service request with the service network address to obtain a target service request. The target service request is then sent to the service provider, enabling the service provider to provide services to the service requester based on the functional network element corresponding to the service network address. As can be seen from the above, this application, by receiving an initial service request from a service requester and replacing the target FQDN in the initial service request with a service network address, achieves the transmission of the service network address by performing an inverse address transformation on the target FQDN using only the SEPP network element. This eliminates the need for functional adjustments to other network elements, reducing the management and maintenance costs of maintaining the mapping relationship between FQDNs and service network addresses across the entire network, lowering the risk of service transmission interruptions, and eliminating potential service interruption risks caused by untimely updates to the mapping relationship data between FQDNs and service network addresses.

[0066] In one embodiment, such as Figure 3 As shown, when it is necessary to generate a target FQDN based on the service network address carried in the service discovery response, the following can be included:

[0067] S301, Extract the service network address of the service producer carried in the service discovery response.

[0068] Specifically, network address identification is performed on the service discovery response to locate the data location corresponding to the service network address in the service discovery response. Then, based on the data location corresponding to the service network address, the service network address of the service producer carried in the service discovery response is extracted.

[0069] The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving a service discovery request from the service requester.

[0070] In one embodiment of this application, after the Serving SEPP network element forwards the initial service request to the Home SEPP network element of the Home PLMN, the execution entity of the service provision method, the Home SEPP network element forwards the initial service request to the Home NRF network element, and the Home NRF network element then...

[0071] S302, encrypt the service network address and determine the target FQDN.

[0072] It should be noted that when it is necessary to encrypt the service network address, the following can be included: encrypt the service network address to obtain an encrypted string; add the communication institution's domain name information to the suffix of the encrypted string, and use the encrypted string with the communication institution's domain name information added to the suffix as the target FQDN.

[0073] As an example, if the service network address is 10.1.1.1, the encrypted string djg640jfdsk is generated after encryption using the local algorithm; the communication agency domain name information 5gc.mnc012.mcc345.3gppnetwork.org is added to the suffix of the encrypted string, resulting in the target FQDN: djg640jfdsk.5gc.mnc012.mcc345.3gppnetwork.org.

[0074] To further explain, since the target FQDN is an encrypted string with the domain name information of the communication organization appended to the suffix, the following method can be used when performing inverse address transformation on the target FQDN to obtain the service network address: decrypt the target FQDN to obtain the service network address.

[0075] Specifically, since the target FQDN contains not only encrypted strings but also communication organization domain name information, only the encrypted strings contained in the target FQDN are decrypted to obtain the service network address.

[0076] As an example, if the target FQDN information is djg640jfdsk.5gc.mnc012.mcc345.3gppnetwork.org, then the SEPP network element decrypts the encrypted string contained in the target FQDN to obtain the service network address 10.1.1.1. The SEPP network element then replaces the target FQDN in the initial service request with the service network address to obtain the target service request.

[0077] The aforementioned service provision method encrypts the service network address, adding the communication organization's domain name information to the suffix of the encrypted string to obtain the target FQDN. This achieves the goal of obtaining the service network address by decrypting the encrypted string contained in the target FQDN. It enables the transmission of the service network address by performing inverse address transformation on the target FQDN using only SEPP network elements, without requiring functional adjustments to other network elements. This eliminates the need for communication organizations to build additional DNS or databases, reducing the management and maintenance costs of maintaining the mapping relationship between FQDNs and service network addresses across the entire domain, and also reducing the risk of service transmission interruptions.

[0078] In one embodiment, such as Figure 4 As shown, when it is necessary to send a target service request to the service provider, the following can be included:

[0079] S401, Receive the initial service request sent by the service requester.

[0080] S402, decrypt the encrypted string contained in the target FQDN to obtain the service network address.

[0081] S403, replace the target FQDN in the initial service request with the service network address to obtain the target service request.

[0082] S404 sends the target service request to the service provider, so that the service provider can provide services to the service requester according to the functional network element corresponding to the service network address.

[0083] In one embodiment of this application, the process by which the SEPP network element generates the target FQDN is as follows: Figure 5As shown, the service requester sends a service discovery request to the Serving NRF network element of the Serving PLMN (Serving Public Land Mobile Network); the Serving NRF network element forwards the service discovery request to the Serving SEPP network element; the Serving SEPP network element forwards the service discovery request to the Home SEPP network element of the Home PLMN (Home Public Land Mobile Network), the entity executing the service provision method; the Home SEPP network element forwards the service discovery request to the Home NRF network element; the Home NRF network element generates a service discovery response for the service discovery request and sends the service discovery response to the Home SEPP network element; after receiving the service discovery response for the service requester from the Home NRF network element, the Home SEPP network element generates a target FQDN based on the service network address carried in the service discovery response and sends a service discovery response carrying the target FQDN to the Serving SEPP network element; the Serving SEPP network element sends a service discovery response to the Serving NRF network element; and the Serving NRF network element sends a service discovery response to the service requester.

[0084] Furthermore, service discovery requests may include, but are not limited to, service discovery requests and network element state subscription requests, etc. The request type of service discovery requests is not limited here.

[0085] In one embodiment of this application, the process of sending a target service request to the service provider is as follows: Figure 6 As shown, the service requester sends the initial service request to the Serving SEPP network element; the Serving SEPP network element sends the initial service request to the Home SEPP network element; the Home SEPP network element performs inverse address transformation on the target FQDN to obtain the service network address, and then sends the target service request to the service producer.

[0086] The above-described service provision method involves receiving an initial service request carrying a target FQDN from a service requester, performing inverse address transformation on the target FQDN to obtain a service network address, replacing the target FQDN in the initial service request with the service network address to obtain a target service request, and then sending the target service request to the service producer so that the service producer can provide services to the service requester based on the functional network element corresponding to the service network address.

[0087] As described above, this application achieves service network address replacement for the target FQDN in the initial service request by receiving the initial service request from the service requester. This enables the transmission of the service network address by performing inverse address transformation on the target FQDN using only the SEPP network element, without requiring functional adjustments to other network elements. This eliminates the need for communication institutions to build additional DNS or databases, reducing the management and maintenance costs of maintaining the mapping relationship between FQDNs and service network addresses across the entire network. It also reduces the risk of service transmission interruption and eliminates the potential service interruption caused by untimely updates to the mapping relationship data between FQDNs and service network addresses.

[0088] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0089] Based on the same inventive concept, this application also provides a service providing apparatus for implementing the service providing method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more service providing apparatus embodiments provided below can be found in the limitations of the service providing method described above, and will not be repeated here.

[0090] In one embodiment, such as Figure 7 As shown, a service providing apparatus is provided, comprising: a receiving module 10, a transformation module 20, a replacement module 30, and a sending module 40, wherein:

[0091] The receiving module 10 is used to receive an initial service request sent by a service requester; wherein the initial service request carries a target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element based on the service network address carried in the service discovery response after receiving the service discovery response for the service requester sent by the Network Repository Function (NRF) network element.

[0092] The transformation module 20 is used to perform inverse address transformation on the target FQDN to obtain the service network address.

[0093] Replacement module 30 is used to replace the target FQDN in the initial service request with the service network address to obtain the target service request.

[0094] The sending module 40 is used to send the target service request to the service producer, so that the service producer can provide services to the service demander according to the functional network element corresponding to the service network address.

[0095] In one embodiment, the service network address of the service producer carried in the service discovery response is extracted;

[0096] Encrypt the service network address to determine the target FQDN.

[0097] In one embodiment, the service network address is encrypted to obtain an encrypted string;

[0098] Add the communication organization's domain name information to the suffix of the encrypted string, and use the encrypted string with the communication organization's domain name information appended to it as the target FQDN.

[0099] The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving a service discovery request from a service requester.

[0100] The target FQDN is decrypted to obtain the service network address.

[0101] The encrypted string contained in the target FQDN is decrypted to obtain the service network address.

[0102] The aforementioned service providing device receives an initial service request carrying a target FQDN from a service requester, performs inverse address transformation on the target FQDN to obtain a service network address, replaces the target FQDN in the initial service request with the service network address, and obtains a target service request. Then, it sends the target service request to the service provider, enabling the service provider to provide services to the service requester based on the functional network element corresponding to the service network address. As can be seen from the above, this application, by receiving an initial service request from a service requester and replacing the target FQDN in the initial service request with a service network address, achieves the transmission of the service network address by performing inverse address transformation on the target FQDN using only the SEPP network element. This eliminates the need for functional adjustments to other network elements, reducing the management and maintenance costs of maintaining the mapping relationship between FQDNs and service network addresses across the entire network, lowering the risk of service transmission interruptions, and eliminating potential service interruption risks caused by untimely updates to the mapping relationship data between FQDNs and service network addresses.

[0103] Each module in the aforementioned service providing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can invoke and execute the operations corresponding to each module.

[0104] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 8 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a service provision method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0105] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0106] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0107] Receive the initial service request sent by the service requester; wherein the initial service request carries the target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element after receiving the service discovery response sent by the network repository function (NRF) network element for the service requester, based on the service network address carried in the service discovery response.

[0108] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0109] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address;

[0110] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0111] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0112] Extract the service network address of the service provider carried in the service discovery response;

[0113] Encrypt the service network address to determine the target FQDN.

[0114] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0115] Encrypt the service network address to obtain an encrypted string;

[0116] Add the communication organization's domain name information to the suffix of the encrypted string, and use the encrypted string with the communication organization's domain name information appended to it as the target FQDN.

[0117] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0118] The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving a service discovery request from a service requester.

[0119] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0120] The target FQDN is decrypted to obtain the service network address.

[0121] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0122] The encrypted string contained in the target FQDN is decrypted to obtain the service network address.

[0123] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0124] Receive the initial service request sent by the service requester; wherein the initial service request carries the target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element after receiving the service discovery response sent by the network repository function (NRF) network element for the service requester, based on the service network address carried in the service discovery response.

[0125] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0126] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address;

[0127] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0128] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0129] Extract the service network address of the service provider carried in the service discovery response;

[0130] Encrypt the service network address to determine the target FQDN.

[0131] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0132] Encrypt the service network address to obtain an encrypted string;

[0133] Add the communication organization's domain name information to the suffix of the encrypted string, and use the encrypted string with the communication organization's domain name information appended to it as the target FQDN.

[0134] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0135] The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving a service discovery request from a service requester.

[0136] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0137] The target FQDN is decrypted to obtain the service network address.

[0138] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0139] The encrypted string contained in the target FQDN is decrypted to obtain the service network address.

[0140] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:

[0141] Receive the initial service request sent by the service requester; wherein the initial service request carries the target fully qualified domain name (FQDN); the target FQDN is generated by the SEPP network element after receiving the service discovery response sent by the network repository function (NRF) network element for the service requester, based on the service network address carried in the service discovery response.

[0142] Perform inverse address transformation on the target FQDN to obtain the serving network address;

[0143] The target service request is obtained by replacing the target FQDN in the initial service request with the service network address;

[0144] The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

[0145] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0146] Extract the service network address of the service provider carried in the service discovery response;

[0147] Encrypt the service network address to determine the target FQDN.

[0148] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0149] Encrypt the service network address to obtain an encrypted string;

[0150] Add the communication organization's domain name information to the suffix of the encrypted string, and use the encrypted string with the communication organization's domain name information appended to it as the target FQDN.

[0151] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0152] The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving a service discovery request from a service requester.

[0153] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0154] The target FQDN is decrypted to obtain the service network address.

[0155] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0156] The encrypted string contained in the target FQDN is decrypted to obtain the service network address.

[0157] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0158] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0159] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0160] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A service provision method, characterized in that, The method, applied to a Security Edge Protection Agent (SEPP) network element, includes: Receives a service discovery response for the service requester from the NRF network element that is the network repository function; The service network address carried in the service discovery response is encrypted using a local algorithm to obtain an encrypted string. The communication organization domain name information is added to the suffix of the encrypted string to generate the target fully qualified domain name (FQDN). The service discovery response carrying the target FQDN is sent to the service requester via the NRF network element; Receive an initial service request sent by the service requester; wherein the initial service request carries the target FQDN; The encrypted string contained in the target FQDN is decrypted to obtain the service network address; wherein, the process of obtaining the service network address does not require access to the Domain Name System (DNS) and database used to store the mapping relationship between FQDN and service network address; The target service request is obtained by replacing the target FQDN in the initial service request with the service network address. The target service request is sent to the service provider, so that the service provider can provide services to the service requester based on the functional network element corresponding to the service network address.

2. The method according to claim 1, characterized in that, The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving the service discovery request sent by the service requester.

3. The method according to claim 2, characterized in that, The service discovery request types include network element status subscription requests.

4. The method according to claim 1, characterized in that, The step of replacing the target FQDN in the initial service request with the service network address to obtain the target service request includes: Determine the data location of the target FQDN in the initial service request; Replace the service network address with the target FQDN at the data location to obtain the target service request.

5. A service providing device, characterized in that, Applied to the Security Edge Protection Agent (SEPP) network element, the device is used for: Receives a service discovery response for the service requester from the NRF network element that is the network repository function; The service network address carried in the service discovery response is encrypted using a local algorithm to obtain an encrypted string. The communication organization domain name information is added to the suffix of the encrypted string to generate the target fully qualified domain name (FQDN). The service discovery response carrying the target FQDN is sent to the service requester via the NRF network element; The device includes: A receiving module is configured to receive an initial service request sent by the service requester; wherein the initial service request carries the target FQDN; The transformation module is used to decrypt the encrypted string contained in the target FQDN to obtain the service network address; wherein, the process of obtaining the service network address does not require accessing the Domain Name System (DNS) and database used to store the mapping relationship between FQDN and service network address; The replacement module is used to replace the target FQDN in the initial service request with the service network address to obtain the target service request; The sending module is used to send the target service request to the service producer, so that the service producer can provide services to the service demander according to the functional network element corresponding to the service network address.

6. The apparatus according to claim 5, characterized in that, The service discovery response is the response sent by the NRF network element to the SEPP network element after receiving the service discovery request sent by the service requester.

7. The apparatus according to claim 5, characterized in that, The replacement module is also used for: Determine the data location of the target FQDN in the initial service request; Replace the service network address with the target FQDN at the data location to obtain the target service request.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.