Method and apparatus for user plane security for virtual network groups

By enhancing parameters to provide interfaces and shared data, allowing open functions to provide the same user-side security configuration for virtual network groups, solving the problem that external applications are difficult to configure consistent user-side security, and achieving simplified security management and consistent configuration.

CN120077687APending Publication Date: 2025-05-30TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202380073949.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-21
Filing Date
2023-10-17
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the prior art, external application functions or vertical applications are difficult to configure the same user surface security for virtual network groups, and configuring user surface security in large groups is cumbersome and prone to errors, and there is a lack of a method to resolve user surface security inconsistent conflicts.

Method used

By providing interfaces and shared virtual network group data with enhanced parameters, the open function allows the virtual network group to provide the same user-plane security configuration, and the coordinated work of the data management node and the data repository node can achieve unified user-plane security management of the virtual network group.

Benefits of technology

It realizes the configuration of the same user-plane security for virtual network groups by external applications or vertical applications, simplifies the security configuration management of large groups, and ensures the consistency and manageability of user-plane security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120077687A_ABST
    Figure CN120077687A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method and device for user plane security of a VN group. A method performed by an open function includes receiving a first message from an application node, the first message including at least one parameter to be created or updated. The at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group. The method may also include sending a second message including the at least one parameter to be created or updated to the data management node or the data repository node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The non - limiting and exemplary embodiments of the present disclosure generally relate to the field of communication technologies, and more particularly to methods and apparatuses for user plane security of virtual network (VN) groups. Background Art

[0002] This section introduces aspects that may help to better understand the present disclosure. Therefore, the statements in this section should be read from this perspective and should not be construed as an admission of what is in the prior art or what is not in the prior art.

[0003] VN groups can be supported in various networks. For example, in a communication network such as New Radio (NR) defined by the 3rd Generation Partnership Project (3GPP), it supports 5th Generation (5G) VN group communication.

[0004] As described in clause 4.15.6.2 of 3GPP TS23.502 V17.5.0, the disclosure of which is incorporated herein by reference in its entirety, information on 5G VN groups can be provided by an Application Function (AF) to a Network Exposure Function (NEF) and stored in a Unified Data Repository (UDR) through the NEF service operation information flow process.

[0005] Clause 4.4.15 of 3GPP TS29.522 V17.7.0, the disclosure of which is incorporated herein by reference in its entirety, describes the NEF 5G Local Area Network (LAN) parameter provisioning as follows.

[0006] 4.4.15.1 Overview

[0007] These procedures are used by the AF to provide 5G LAN type service - related parameters to the NEF. The following procedures are supported:

[0008] - Management of 5G virtual network membership; and / or

[0009] - Management of 5G virtual network group data

[0010] 4.4.15.2 Creation of a new subscription for 5G LAN parameter provisioning

[0011] To create a new subscription to provide 5G LAN - related parameters, the AF shall initiate an HTTP POST request to the NEF for the "5G LAN parameter provisioning subscription" resource. The body of the HTTP POST message shall contain 5G LAN service - related parameters within the "5gLanParams" attribute.

[0012] After receiving the corresponding HTTP POST message, if the AF is authorized by the NEF to provide the parameter, the NEF shall interact with the UDM by using the Nudm_ParameterProvision service defined in 3GPP TS 29.503

[17] to create a subscription at the UDM. If the UDM accepts the request and the UDM notifies the NEF of a successful response, the NEF shall create a new subscription and allocate a subscription identifier for the "Individual 5G LAN Parameter Provision Subscription" resource. Then, the NEF shall send an HTTP "201 Created" response that has the 5GLanParametersProvision data structure as the response body and a Location header field containing the URI of the created individual subscription resource.

[0013] 4.4.15.3 Modification of an existing subscription for 5G LAN parameter provision

[0014] To modify an existing subscription for 5G LAN parameter provision, the AF shall initiate an HTTP PUT / PATCH request to the NEF for the "Individual 5G LAN Parameter Provision Subscription" resource. The body of the HTTP PUT message shall include the 5GLanParametersProvision data type defined in clause 5.7.2.3.2. The external group identifier, DNN, S-NSSAI, and one or more PDU session types shall remain the same as the previous values. The body of the HTTP PATCH message shall include the 5G LanParametersProvisionPatch data defined in clause 5.7.2.3.5.

[0015] After receiving the corresponding HTTP PUT / PATCH message, if the AF is authorized by the NEF to provide the parameter, the NEF shall interact with the UDM by using the Nudm_ParameterProvision service defined in 3GPP TS 29.503

[17] to modify the existing subscription at the UDM. If the UDM accepts the modification request and the UDM notifies the NEF of a successful response, the NEF shall update the existing subscription for the "Individual 5G LAN Parameter Provision Subscription" resource. Then, the NEF shall send an HTTP response that includes a "200 OK" status code with the 5G LanParametersProvision data structure or a "204 No Content" status code.

[0016] 4.4.15.4 Deletion of an existing subscription for 5G LAN parameter provision

[0017] To delete an existing subscription that provides parameters for 5G LAN, the AF shall initiate an HTTP DELETE request to the NEF for the "Individual 5G LAN Parameter Provision Subscription" resource.

[0018] After receiving the corresponding HTTP DELETE message, if the AF is authorized, the NEF shall interact with the UDM to delete the existing parameter provision subscription at the UDM by using the Nudm_ParameterProvision service as defined in 3GPP TS 29.503

[17] . If the UDM accepts the request and notifies the NEF of a successful response, the NEF shall delete the existing subscription for the "Individual 5G LAN Parameter Provision Subscription" resource. Then the NEF shall send an HTTP "204 No Content" response.

[0019] Clause 5.7.2.3.3 of 3GPP TS 29.522 V17.7.0 describes the type: 5GLanParameters as follows.

[0020] 5.7.2.3.3 Type: 5G LanParameters

[0021] This type represents the 5G LAN service-related parameters that need to be provided. Table 5.7.2.3.3-1: Definition of Type 5GLanParameters

[0022] Article 5.6.2.1 of 3GPP TS 29.503 V17.8.0 (the disclosure of which is incorporated herein by reference in its entirety) describes the NEF 5G LAN parameter provision as follows.

[0023] 5.6.2.1 Introduction

[0024] For the Nudm_ParameterProvision service, the following service operations are defined:

[0025] - Update

[0026] - Create

[0027] - Delete

[0028] - Retrieve

[0029] The Nudm_ParameterProvision service is used by the consuming NF (e.g., NEF) to update the subscription data of a UE or a group of UEs by using the update service operation.

[0030] For detailed information, please refer to Clause 4.15.6.2 of 3GPP TS23.502 [3].

[0031] The NF service consumer (e.g., SOR-AF) can also use the Nudm_ParameterProvision service to send updated roaming guidance information for the UE to the UDM at any time, as specified in Appendix C.3 of 3GPP TS23.122

[20] .

[0032] 5G-VN-Group Creation

[0033] Figure 1a A scenario where the NF service consumer sends a request to the UDM to create a 5G VN group is shown. This figure is the same as Figure 5 .6.2.3.2-1 of 3GPP TS29.503 V17.8.0.

[0034] The request contains the external identifier of the group and the group configuration.

[0035] Clause 5.6.2.3.2 of 3GPP TS29.503 V17.8.0 describes the following steps.

[0036] 1. The NF service consumer sends a PUT request to the resource... / 5g-vn-groups / {extGroupId} to create the 5G VN group as present in the message body.

[0037] If MTC provider information and / or AF ID are received in the request, the UDM shall check whether the MTC provider and / or AF are allowed to perform this operation for the UE; otherwise, the UDM shall skip the MTC provider and / or AF authorization check.

[0038] 2a. On success, the UDM responds with "201 Created".

[0039] 2b. If the creation cannot be accepted (e.g., the MTC provider or AF is not allowed to perform this operation for the UE), an HTTP status code "403 Forbidden" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0040] On failure, an appropriate HTTP status code indicating the error shall be returned, and appropriate additional error information shall be returned in the PUT response body.

[0041] Figure 1b A scenario where the NF service consumer sends a request to the UDM to modify the group data of the external group id is shown. This figure is the same as Figure 5.6.2.2.3-1 is the same.

[0042] The request contains the external group identifier of the group and modification instructions.

[0043] Clause 5.6.2.2.3 of 3GPP TS29.503 V17.8.0 describes the following steps.

[0044] 1. The NF service consumer sends a PATCH request to the resources representing the 5G VN group.

[0045] If MTC provider information and / or AF ID are received in the request, the UDM shall check whether the MTC provider and / or AF are allowed to perform this operation for the UE; otherwise, the UDM shall skip the MTC provider and / or AF authorization check.

[0046] 2a. On success, the UDM responds with "204 No Content".

[0047] 2b. If the external group id does not exist in the UDM, an HTTP status code "404 Not Found" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0048] 2c. If the MTC provider or AF is not allowed to perform this operation for the UE, an HTTP status code "403 Forbidden" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0049] On failure, an appropriate HTTP status code indicating the error shall be returned, and appropriate additional error information shall be returned in the PATCH response body.

[0050] Figure 1c The figure shows the scenario where the NF service consumer sends a request to the UDM to delete a 5G VN group, and this figure is the same as that of 3GPP TS29.503 V17.8.0's Figure 5 .6.2.4.2-1.

[0051] The request contains the external identifier of the group.

[0052] Clause 5.6.2.4.2 of 3GPP TS29.503 V17.8.0 describes the following steps.

[0053] 1. The NF service consumer sends a DELETE request to the resource... / 5g-vn-groups / {extGroupId} to delete the 5G VN group identified by the external group id.

[0054] If the MTC provider information and / or AF ID are received in the request, the UDM shall check whether the MTC provider and / or AF are allowed to perform this operation for the UE; otherwise, the UDM shall skip the MTC provider and / or AF authorization check.

[0055] 2a. On success, the UDM responds with "204 No Content".

[0056] 2b. If the external group ID does not exist in the UDM, the HTTP status code "404 Not Found" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0057] 2c. If the MTC provider or AF is not allowed to perform this operation for the UE, the HTTP status code "403 Forbidden" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0058] On failure, an appropriate HTTP status code indicating the error shall be returned, and appropriate additional error information shall be returned in the delete response body.

[0059] Figure 1d The figure shows a scenario where the NF service consumer sends a request to the UDM to obtain a 5G VN group. This figure is the same as that in 3GPP TS 29.503 V17.8.0 Figure 5 .6.2.5.2-1.

[0060] The request contains the external identifier of the group.

[0061] Clause 5.6.2.5.2 of 3GPP TS 29.503 V17.8.0 describes the following steps.

[0062] 1. The NF service consumer sends a get request to the resource... / 5g-vn-groups / {extGroupId} to obtain the 5G VN group identified by the external group ID.

[0063] 2a. On success, the UDM responds with "200 Ok" with the VPN group information.

[0064] 2b. If the external group ID does not exist in the UDM, the HTTP status code "404 Not Found" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0065] 2c. If the original AF is not allowed to obtain this information, an HTTP status code "403 Forbidden" shall be returned, and additional error information shall be included in the response body (in the "ProblemDetails" element).

[0066] On failure, an appropriate HTTP status code indicating the error shall be returned, and appropriate additional error information shall be returned in the fetch response body.

[0067] Clause 6.5.6.2.6 of 3GPP TS29.503 V17.8.0 describes the definition of type 5GVnGroupConfiguration as follows. Table 6.5.6.2.6-1: Definition of type 5GVnGroupConfiguration

[0068] Clause 6.5.6.2.7 of 3GPP TS29.503 V17.8.0 describes the definition of type 5GVnGroupData as follows. Table 6.5.6.2.7-1: Definition of type 5GVnGroupData

[0069] Clause 6.1.6.2.39 of 3GPP TS29.503 V17.8.0 describes the definition of type VnGroupData as follows. Table 6.1.6.2.39-1: Definition of type VnGroupData Summary of the Invention

[0070] The Summary of the Invention is provided in simplified form to introduce selected concepts, which are further described below in the Detailed Description. The Summary of the Invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0071] For example, to reduce the incremental complexity added by security, all PDU sessions associated with a specific VN (e.g., 5G LAN) group should have the same user plane security policy. However, there is a lack of functionality to configure the same user plane security for VN groups on the existing parameter provisioning interface. Additionally, in the shared VN group data, user plane security is not available in the existing data model. Some of the problems with existing solutions for user plane security for VN groups are as follows.

[0072] Problem 1: External application functions, external enterprise applications, or external vertical applications in a non-trusted environment cannot configure the same user plane security for a VN group because there is no service-based interface opened by an open function such as NEF for this purpose.

[0073] Problem 2: User plane security can only be configured at the individual level in a trusted environment. This means that when it comes to a VN group with a large group size, it must be configured for each member of the group, which is error-prone and time-consuming, especially when the size of the group is not small (e.g., hundreds or thousands of group members).

[0074] Problem 3: If the user plane security is configured inconsistently, there is no way to resolve conflicts. For example, member A is configured with user plane security profile 1, while member B is configured with user plane security profile 2 that is not equal to user plane security profile 1 at the individual level. It is uncertain how to implement the same user plane security for the VN group, and it may break the user plane security consistency for the entire VN group.

[0075] To overcome or mitigate at least one of the above problems or other problems, embodiments of the present disclosure propose an improved solution for user plane security of a VN group.

[0076] In an embodiment, an enhanced parameter provision interface is proposed for providing the same user plane security for a VN (e.g., 5G LAN) group.

[0077] In an embodiment, enhanced shared VN group data is proposed to enable the VN group to have the same user plane security.

[0078] In a first aspect of the present disclosure, a method performed by an open function is proposed. The method may include receiving, from an application node, a first message including at least one parameter to be created or updated. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The method may further include sending, to a data management node or a data repository node, a second message including the at least one parameter to be created or updated.

[0079] In an embodiment, the VN group may include a fifth-generation VN group.

[0080] In an embodiment, the UP security information for the VN group indicates applying the same UP security to the VN group.

[0081] In an embodiment, the user plane (UP) security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0082] In an embodiment, the first message may include at least one of a parameter provisioning creation request or a parameter provisioning update request.

[0083] In an embodiment, the second message may include at least one of a parameter provisioning creation request or a parameter provisioning update request.

[0084] In an embodiment, the application node may include at least one of an application function (AF), a service capability server (SCS), or an application server (AS).

[0085] In an embodiment, the data management node may include a unified data management (UDM) and / or the data repository node may include a home subscriber server (HSS) or a home location register (HLR).

[0086] In an embodiment, the open function may include at least one of a service capability exposure function (SCEF), a network exposure function (NEF), or an SCEF combined with the NEF.

[0087] In a second aspect of the present disclosure, a method performed by a data management node is provided. The method may include receiving, from an open function or an application function (AF), a second message that includes at least one parameter to be created or updated. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The method may further include sending, to a data repository node, a third message that includes the at least one parameter to be created or updated.

[0088] In an embodiment, the VN group may include a 5G VN group.

[0089] In an embodiment, the UP security information for a VN group indicates that the same UP security is applied to the VN group.

[0090] In an embodiment, the user plane (UP) security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0091] In an embodiment, the second message may include at least one of a parameter provisioning creation request or a parameter provisioning update request.

[0092] In an embodiment, the third message may include at least one of a data management creation request or a data management update request.

[0093] In an embodiment, the data repository node may include a Unified Data Repository (UDR).

[0094] In an embodiment, the data management node may include Unified Data Management (UDM).

[0095] In an embodiment, the open function may include a Network Exposure Function (NEF).

[0096] In an embodiment, the method may further include receiving, from a session management function, a first request for retrieving shared data for a VN group. The method may further include sending, to the data repository node, a second request for retrieving shared data for a VN group. The method may further include receiving, from the data repository node, a second response including the shared data for the VN group. The method may further include sending, to the session management function, a first response including the shared data for the VN group. The shared data for the VN group may include UP security information for the VN group.

[0097] In an embodiment, the method may further include receiving, from a session management function, a third request for subscribing to data change notifications for a VN group. The method may further include sending, to the data repository node, a fourth request for subscribing to data change notifications for a VN group. The method may further include receiving, from the data repository node, a first data change notification message including UP security information for the VN group. The method may further include sending, to the session management function, a second data change notification message including UP security information for the VN group.

[0098] In a third aspect of the present disclosure, a method performed by an application node is provided. The method may include sending a first message including at least one parameter to be created or updated to an open function or a data management node or a data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0099] In an embodiment, the VN group may include a 5G VN group.

[0100] In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0101] In an embodiment, the UP security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0102] In an embodiment, the first message may include at least one of a parameter provision creation request or a parameter provision update request.

[0103] In an embodiment, the application node may include at least one of an application function (AF), a service capability server (SCS), or an application server (AS).

[0104] In an embodiment, the open function may include at least one of a service capability exposure function (SCEF), a network exposure function (NEF), or an SCEF combined with the NEF.

[0105] In an embodiment, the data repository node may include at least one of a home subscriber server (HSS) or a home location register (HLR).

[0106] In an embodiment, the data management node may include a unified data management (UDM).

[0107] In a fourth aspect of the present disclosure, a method performed by a network management node is provided. The method may include sending a fourth message including at least one parameter to be created or updated to a data repository node. The at least one parameter to be created or updated may include UP security information for a virtual network (VN) group.

[0108] In an embodiment, the VN group may include a 5G VN group.

[0109] In an embodiment, the UP security information of the VN group indicates that the same UP security is applied to the VN group.

[0110] In an embodiment, the UP security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0111] In an embodiment, the fourth message may include at least one of the following: a parameter provision creation request, or a parameter provision update request.

[0112] In an embodiment, the network management node may include a communication service provider (CSP) provisioning system.

[0113] In an embodiment, the data repository node may include a Unified Data Repository (UDR), a Home Subscriber Server (HSS), or a Home Location Register (HLR).

[0114] In a fifth aspect of the present disclosure, a method performed by a data repository node is provided. The method includes receiving, from a data management node, an open function, an application node, or a network management node, a message including at least one parameter to be created or updated. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The method may further include storing the at least one parameter to be created or updated.

[0115] In an embodiment, the VN group may include a fifth-generation VN group.

[0116] In an embodiment, the UP security information of the VN group indicates that the same UP security is applied to the VN group.

[0117] In an embodiment, the UP security information of the VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0118] In an embodiment, the message may include at least one of a data management creation request or a data management update request.

[0119] In an embodiment, the data repository node may include at least one of a Home Subscriber Server (HSS), a Home Location Register (HLR), or a Unified Data Repository (UDR).

[0120] In an embodiment, the data management node may include a Unified Data Management (UDM).

[0121] In an embodiment, the open function may include at least one of a Service Capability Exposure Function (SCEF), a Network Exposure Function (NEF), or an SCEF combined with the NEF.

[0122] In an embodiment, the application node may include at least one of an Application Function (AF), a Service Capability Server (SCS), or an Application Server (AS).

[0123] In an embodiment, the network management node may include a CSP-provided system.

[0124] In an embodiment, the method may further include: if no internal group identifier is assigned to the VN group identified by the external group ID, assign an internal group identifier (ID). The method may further include: storing a mapping between the internal group ID and the external group ID. The method may further include: assigning a shared data ID to the VN group data. The method may further include: for each member of the VN group, associating the session management data with the internal group ID and the shared data ID.

[0125] In an embodiment, the method may further include: receiving, from a data management node or a session management function, a request for retrieving shared data for a VN group. The method may further include sending, to the data management node or the session management function, a response including the shared data for the VN group. The shared data for the VN group may include UP security information for the VN group.

[0126] In an embodiment, the method may further include receiving, from a data management node or a session management function, a request for subscribing to data change notifications for a VN group. The method may further include sending, to the data management node or the session management function, a data change notification message. The data change notification message may include UP security information for the VN group.

[0127] In a sixth aspect of the present disclosure, a method performed by a session management function is provided. The method may include sending, to a data management node or a data repository node, a request for retrieving shared data for a VN group. The method may further include receiving, from the data management node or the data repository node, a response including the shared data for the VN group. The shared data for the VN group may include UP security information for the VN group.

[0128] In an embodiment, the method may further include sending, to a data management node or a data repository node, a request for subscribing to data change notifications for a VN group. The method may further include receiving, from the data management node or the data repository node, a data change notification message. The data change notification message may include UP security information for the VN group.

[0129] In an embodiment, the method may further include determining whether a protocol data unit (PDU) session establishment is for individual-level communication or for group-level communication. When the PDU session establishment is for group-level communication, the method may further include, via an access and mobility management function, setting the same user plane security data from the UP security information for the VN group into the PDU session request going to the radio access network.

[0130] In an embodiment, the VN group may include a fifth-generation VN group.

[0131] In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0132] In an embodiment, the UP security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0133] In an embodiment, the data repository node may include at least one of a home subscriber server (HSS) or a home location register (HLR).

[0134] In an embodiment, the data management node may include a unified data management (UDM).

[0135] In a seventh aspect of the present disclosure, an open function is proposed. The open function may include a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The open function is operable to receive a first message including at least one parameter to be created or updated from an application node. The at least one parameter to be created or updated may include UP security information for a virtual network (VN) group. The open function is further operable to send a second message including the at least one parameter to be created or updated to a data management node or a data repository node.

[0136] In an eighth aspect of the present disclosure, a data management node is proposed. The data management node may include a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The data management node is operable to receive a second message including at least one parameter to be created or updated from an open function or an application function (AF). The at least one parameter to be created or updated may include UP security information for a virtual network (VN) group. The data management node is further operable to send a third message including the at least one parameter to be created or updated to a data repository node.

[0137] In a ninth aspect of the present disclosure, an application node is proposed. The application node may include a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The application node is operable to send a first message including at least one parameter to be created or updated to an open function or a data management node or a data repository node. The at least one parameter to be created or updated may include UP security information for a virtual network (VN) group.

[0138] In a tenth aspect of the present disclosure, a network management node is provided. The network management node may include a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The network management node is operable to send a fourth message including at least one parameter to be created or updated to a data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0139] In an eleventh aspect of the present disclosure, a data repository node is provided. The data repository node may include a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The data repository node is operable to receive a message including at least one parameter to be created or updated from a data management node, an open function, an application node, or a network management node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The data repository node is further operable to store the at least one parameter to be created or updated.

[0140] In a twelfth aspect of the present disclosure, a session management function is provided. The session management function may include a processor and a memory coupled to the processor. The memory stores instructions executable by the processor. The session management function is operable to send a request for retrieving shared data for a VN group to a data management node or a data repository node. The session management function is further operable to receive a response including the shared data for the VN group from the data management node or the data repository node. The shared data for the VN group may include UP security information for the VN group.

[0141] In another aspect of the present disclosure, an open function is provided. The open function may include a receiving module configured to receive a first message including at least one parameter to be created or updated from an application node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The open function may further include a sending module configured to send a second message including the at least one parameter to be created or updated to a data management node or a data repository node.

[0142] In another aspect of the present disclosure, a data management node is provided. The data management node may include a first receiving module configured to receive a second message including at least one parameter to be created or updated from an open function or an application function (AF). The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The data management node may further include a first sending module configured to send a third message including at least one parameter to be created or updated to a data repository node.

[0143] In an embodiment, the data management node may further include a second receiving module configured to receive a first request from a session management function for retrieving shared data for a VN group.

[0144] In an embodiment, the data management node may further include a second sending module configured to send a second request for retrieving shared data for a VN group to a data repository node.

[0145] In an embodiment, the data management node may further include a third receiving module configured to receive a second response including shared data for a VN group from a data repository node.

[0146] In an embodiment, the data management node may further include a third sending module configured to send a first response including shared data for a VN group to a session management function. The shared data for a VN group may include UP security information for a VN group.

[0147] In an embodiment, the data management node may further include a fourth receiving module configured to receive a third request from a session management function for subscribing to data change notifications for a VN group.

[0148] In an embodiment, the data management node may further include a fourth sending module configured to send a fourth request for subscribing to data change notifications for a VN group to a data repository node.

[0149] In an embodiment, the data management node may further include a fifth receiving module configured to receive a first data change notification message including UP security information for a VN group from a data repository node.

[0150] In an embodiment, the data management node may further include a fifth sending module configured to send a second data change notification message including UP security information for a VN group to a session management function.

[0151] In another aspect of the present disclosure, an application node is proposed. The application node may include a sending module configured to send a first message including at least one parameter to be created or updated to an open function or a data management node or a data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0152] In another aspect of the present disclosure, a network management node is proposed. The network management node may include a sending module configured to send a fourth message including at least one parameter to be created or updated to a data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0153] In another aspect of the present disclosure, a data repository node is proposed. The data repository node may include a first receiving module configured to receive a message including at least one parameter to be created or updated from a data management node or an open function or an application node or a network management node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The data repository node may further include a first storage module configured to store the at least one parameter to be created or updated.

[0154] In an embodiment, the data repository node may further include a first allocation module configured to allocate an internal group identifier (ID) if no internal group identifier is allocated for the VN group identified by the external group ID.

[0155] In an embodiment, the data repository node may further include a second storage module configured to store a mapping between the internal group ID and the external group ID.

[0156] In an embodiment, the data repository node may further include a second allocation module configured to allocate a shared data ID for the VN group data.

[0157] In an embodiment, the data repository node may further include an association module configured to associate session management data with the internal group ID and the shared data ID for each member of the VN group.

[0158] In an embodiment, the data repository node may further include a second receiving module configured to receive a request for retrieving the shared data for the VN group from a data management node or a session management function.

[0159] In an embodiment, the data repository node may further include a first sending module configured to send a response including shared data for a VN group to the data management node or the session management function. The shared data for the VN group may include UP security information for the VN group.

[0160] In an embodiment, the data repository node may further include a third receiving module configured to receive from the data management node or the session management function a request for subscribing to data change notifications for a VN group.

[0161] In an embodiment, the data repository node may further include a second sending module configured to send a data change notification message to the data management node or the session management function. The data change notification message may include UP security information for the VN group.

[0162] In another aspect of the present disclosure, a session management function is proposed. The session management function may include a first sending module configured to send a request for retrieving shared data for a VN group to the data management node or the data repository node. The session management function may further include a first receiving module configured to receive from the data management node or the data repository node a response including shared data for the VN group. The shared data for the VN group may include UP security information for the VN group.

[0163] In an embodiment, the session management function may further include a second sending module configured to send a request for subscribing to data change notifications for a VN group to the data management node or the data repository node.

[0164] In an embodiment, the session management function may further include a second receiving module configured to receive from the data management node or the data repository node a data change notification message. The data change notification message may include UP security information for the VN group.

[0165] In an embodiment, the session management function may further include a determination module configured to determine whether a protocol data unit (PDU) session establishment is for individual-level communication or for group-level communication.

[0166] In an embodiment, the session management function may further include a second sending module configured to, when the PDU session establishment is for group-level communication, set the same user plane security data from the UP security information for the VN group into the PDU session request to the radio access network through the access and mobility management function.

[0167] In another aspect of the present disclosure, there is provided a computer program product including instructions which, when executed by at least one processor, cause the at least one processor to perform the method according to any one of the first, second, third, fourth, fifth or sixth aspects.

[0168] In another aspect of the present disclosure, there is provided a computer-readable storage medium storing instructions which, when executed by at least one processor, cause the at least one processor to perform the method according to any one of the first, second, third, fourth, fifth or sixth aspects.

[0169] The embodiments herein can provide many advantages, and the following is a non-exhaustive list of examples of advantages. In some embodiments herein, the proposed solution can enable the possibility of the same user-plane security for external applications or external enterprise applications or vertical application configurations of VN groups, which enhances the openness of communication service providers to monetize diverse services carried by the network and enables more use cases for the network, especially for vertical industries with requirements for the same user-plane security. In some embodiments herein, the proposed solution can enhance the manageability of the same user-plane security for VN groups, supporting new configuration operations for the creation, update, and deletion of the same user-plane security for VN groups in a unified service-based interface. It reduces the deficiencies in the management of VN groups with the same user-plane security and OPEX (operational expenditure). In some embodiments herein, by using the recommended user-plane security conflict resolution mechanism, the flexibility to configure user-plane security simultaneously at the individual level and the group level can be achieved, and different user-plane security can be set for the PDU sessions established for group communication and the PDU sessions established for individual communication. In some embodiments herein, in order to reduce the incremental complexity added by security, all PDU sessions associated with a specific LAN group should have the same user-plane security configuration. This can be easily ensured by the proposed new method for enhancing user-plane security for VN groups. Otherwise, relying solely on manual work to ensure that all PDU sessions associated with a specific VN (such as 5G LAN) group have the same user-plane security configuration would be time-consuming and laborious. The embodiments herein are not limited to the above features and advantages. Those skilled in the art will recognize additional features and advantages after reading the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0170] From the following detailed description with reference to the accompanying drawings, by way of example, the above and other aspects, features and benefits of the various embodiments of the present disclosure will become more fully apparent, in which like reference numerals or letters are used to refer to like or equivalent elements. The drawings are shown for facilitating a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale, where:

[0171] Figure 1a Illustrates a scenario where an NF service consumer sends a request to the UDM to create a 5G VN group;

[0172] Figure 1b Illustrates a scenario where an NF service consumer sends a request to the UDM to modify the group data of an external group id;

[0173] Figure 1c Illustrates a scenario where an NF service consumer sends a request to the UDM to delete a 5G VN group;

[0174] Figure 1d Illustrates a scenario where an NF service consumer sends a request to the UDM to obtain a 5G VN group;

[0175] Figure 2a Schematically illustrates an advanced architecture in a fifth-generation network according to an embodiment of the present disclosure;

[0176] Figure 2b Schematically illustrates a system architecture in a 4G network according to an embodiment of the present disclosure;

[0177] Figure 2c Illustrates a non-roaming architecture of a network exposure function in a reference point representation;

[0178] Figure 2d Illustrates a non-roaming service exposure architecture for EPC-5GC interworking;

[0179] Figure 3 Illustrates a flowchart of a method according to an embodiment of the present disclosure;

[0180] Figure 4a Illustrates a flowchart of a method according to another embodiment of the present disclosure;

[0181] Figure 4b Illustrates a flowchart of a method according to another embodiment of the present disclosure;

[0182] Figure 4c Illustrates a flowchart of a method according to another embodiment of the present disclosure;

[0183] Figure 5 Illustrates a flowchart of a method according to another embodiment of the present disclosure;

[0184] Figure 6a Illustrates a flowchart of a method according to another embodiment of the present disclosure;

[0185] Figure 6b Illustrates a flowchart of a method according to another embodiment of the present disclosure;

[0186] Figure 6c The flowchart of a method according to another embodiment of the present disclosure is shown;

[0187] Figure 6d The flowchart of a method according to another embodiment of the present disclosure is shown;

[0188] Figure 6e The flowchart of a method according to another embodiment of the present disclosure is shown;

[0189] Figure 6f The flowchart of a method according to another embodiment of the present disclosure is shown;

[0190] Figure 6g The flowchart of a method according to another embodiment of the present disclosure is shown;

[0191] Figure 6h The flowchart of a method according to another embodiment of the present disclosure is shown;

[0192] Figure 7a The flowchart of a method in which AF provides user plane configuration data for a VN group according to an embodiment of the present disclosure;

[0193] Figure 7b The flowchart of a method in which CSP provides user plane security data for a VN group according to an embodiment of the present disclosure;

[0194] Figure 7c The flowchart of a PDU session establishment process according to an embodiment of the present disclosure;

[0195] Figure 8a It is a block diagram showing a device suitable for practicing some embodiments of the present disclosure;

[0196] Figure 8b An open function block diagram provided for an embodiment of the present disclosure;

[0197] Figure 8c A data management node block diagram provided for an embodiment of the present disclosure;

[0198] Figure 8d An application node block diagram provided for an embodiment of the present disclosure;

[0199] Figure 8e A network management node block diagram provided for an embodiment of the present disclosure;

[0200] Figure 8f A data repository node block diagram provided for an embodiment of the present disclosure;

[0201] Figure 9 A session management function block diagram provided for an embodiment of the present disclosure. Detailed implementation manners

[0202] Embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for the purpose of enabling those skilled in the art to better understand and thus implement the present disclosure, rather than suggesting any limitation on the scope of the present disclosure. Throughout the specification, references to features, advantages, or similar language do not imply that all features and advantages achievable with the present disclosure should be present in or in any single embodiment of the present disclosure. Instead, language referring to features and advantages should be understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. In addition, the features, advantages, and characteristics described in the present disclosure may be combined in any suitable manner in one or more embodiments. Those skilled in the relevant art will recognize that the present disclosure may be practiced without one or more specific features or advantages of a particular embodiment. In other cases, additional features and advantages may be recognized in certain embodiments, and the additional features and advantages may not be present in all embodiments of the present disclosure.

[0203] As used herein, the term "network" refers to a network that follows any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-Carrier Frequency Division Multiple Access (SC-FDMA), and other wireless networks. CDMA networks may implement radio technologies such as Universal Terrestrial Radio Access (UTRA). UTRA includes WCDMA and other variants of CDMA. TDMA networks may implement radio technologies such as Global System for Mobile Communications (GSM). OFDMA networks may implement radio technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, Ad-hoc networks, wireless sensor networks, etc. In the following description, the terms "network" and "system" may be used interchangeably. In addition, communication between two devices in a network may be performed according to any suitable communication protocol, including but not limited to communication protocols defined by standard organizations such as 3GPP. For example, the communication protocol may include first-generation (1G), 2G, 3G, 4G, 4.5G, 5G communication protocols and / or any other protocol known currently or developed in the future.

[0204] The term "network device" or "network node" refers to any suitable network function (NF) that can be implemented in a (physical or virtual) network entity of a communication network. For example, a network function can be implemented as a network element on dedicated hardware, as a software instance running on dedicated hardware, or as a virtualized function instantiated on a suitable platform (e.g., on a cloud infrastructure). For example, a 5G system (5GS) can include multiple NFs such as an access and mobility function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management (UDM), a policy control function (PCF), an application function (AF), a network exposure function (NEF), a user plane function (UPF), and a network repository function (NRF), a radio access network (RAN), a service communication proxy (SCP), a network data analytics function (NWDAF), a network slice selection function (NSSF), a network slice specific authentication and authorization function (NSSAAF), etc. For example, a 4G system (e.g., LTE (Long Term Evolution)) can include a mobility management entity (MME), a home subscriber server (HSS), a PCRF (policy and charging rules function), a packet data network gateway (PGW), a PGW control plane (PGW-C), a serving gateway (SGW), an SGW control plane (SGW-C), an E-UTRAN node B (eNB), etc. In other embodiments, for example, depending on the specific network, the network functions can include different types of NFs.

[0205] The term "terminal device" refers to any terminal device that can access a communication network and receive services therefrom. By way of example and not limitation, terminal devices refer to mobile terminals, user equipment (UE), or other suitable devices. A UE may be, for example, a user station (SS), a portable user station, a mobile station (MS), or an access terminal (AT). Terminal devices may include, but are not limited to, portable computers, image capture terminal devices such as digital cameras, game terminal devices, music storage and playback devices, mobile phones, cellular phones, smart phones, IP voice (VoIP) phones, wireless local loop phones, tablet computers, wearable devices, personal digital assistants (PDA), portable computers, desktop computers, wearable terminal devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), USB dongles, smart devices, wireless customer premise equipment (CPE), etc. In the following description, the terms "terminal device", "terminal", "user equipment", and "UE" may be used interchangeably. As an example, a terminal device may represent a UE configured to communicate according to one or more communication standards (such as the LTE standard or the NR standard of 3GPP) released by 3GPP (Third Generation Partnership Project). As used herein, a "user equipment" or "UE" may not necessarily have a "user" in terms of a human user who owns and / or operates the relevant device. In some embodiments, a terminal device may be configured to send and / or receive information without direct human interaction. For example, when triggered by an internal or external event, or in response to a request from a communication network, a terminal device may be designed to send information to the network according to a predetermined schedule. Alternatively, a UE may represent a device intended for sale to or operation by a human user but initially may not be associated with a specific human user.

[0206] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. In this case, the terminal device may be a machine-to-machine (M2M) device, which may be referred to as a machine type communication (MTC) device in the 3GPP context. As a specific example, a terminal device may be a UE that implements the 3GPP narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (such as electricity meters), industrial machinery, or household or personal appliances such as refrigerators, televisions, personal wearable devices (such as watches), etc. In other scenarios, a terminal device may represent a vehicle or other device capable of monitoring and / or reporting its operating status or other functions related to its operation.

[0207] References to "one embodiment", "an embodiment", "an exemplary embodiment", etc. in the specification indicate that the described embodiments may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. Moreover, these phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that, whether or not explicitly described, the influence of that feature, structure, or characteristic in combination with other embodiments is within the knowledge of those skilled in the art.

[0208] It should be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, the first element may be referred to as the second element, and similarly, the second element may be referred to as the first element. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.

[0209] As used herein, the phrase "at least one of A and B" or "at least one of A or B" should be understood to mean "only A, only B, or both A and B". The phrase "A and / or B" should be understood to mean "only A, only B, or both A and B".

[0210] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the exemplary embodiments. Unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" as used herein are also intended to include the plural forms. It will be further understood that when used herein, the terms "comprises", "comprising", "has", "owns", "contains", and / or "covers" specify the presence of the described features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0211] Note that these terms used herein are only for convenience of description and for distinction between nodes, devices, or networks, etc. As technology develops, other terms with similar / same meanings may also be used.

[0212] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0213] Although the subject matter described herein may be implemented in any suitable type of system using any suitable components, the embodiments disclosed herein are described with respect to Figures 2a to 2d a communication system conforming to theFigures 2a to 2d The system architecture only depicts some exemplary elements. In practice, a communication system may further include any additional elements suitable for supporting communication between terminal devices or between a wireless device and another communication device (such as a landline telephone, a service provider, or any other network node or terminal device). The communication system may provide communication and various types of services to one or more terminal devices to facilitate the access and / or use of services provided by or via the communication system by the terminal devices.

[0214] Figure 2a Schematically shows an advanced architecture in a fifth-generation network according to an embodiment of the present disclosure. For example, the fifth-generation network may be 5GS. Figure 2a The architecture is the same as that shown in Figure 4.2.3-1 described in 3GPP TS23.501 V17.5.0, the disclosure of which is incorporated herein by reference in its entirety. Figure 2a The system architecture may include some exemplary elements, such as AUSF, AMF, DN (data network), NEF, NRF, NSSF, PCF, SMF, UDM, UPF, AF, UE, (R)AN, SCP (service communication proxy), NSSAAF (network slice specific authentication and authorization function), NSACF (network slice admission control function), edge application server discovery function (EASDF), etc.

[0215] According to an exemplary embodiment, as Figure 2a shown, the UE may establish a signaling connection with the AMF via reference point N1. This signaling connection may enable NAS (non-access stratum) signaling exchange between the UE and the core network, including the signaling connection between the UE and the (R)AN and the N2 connection for this UE between the (R)AN and the AMF. The (R)AN may communicate with the UPF via reference point N3. The UE may establish a protocol data unit (PDU) session to the DN (data network, such as an operator network or the Internet) via the UPF via reference point N6.

[0216] As Figure 2a further shown, the exemplary system architecture also includes service-based interfaces presented by NFs such as NRF, NEF, AUSF, UDM, PCF, AMF, NSACF, EASDF, and SMF, such as Nnrf, Nnef, Nausf, Nudm, Npcf, Namf, Nnsacf, Neasdf, and Nsmf. In addition, Figure 2aSome reference points are also shown, such as N1, N2, N3, N4, N6, and N9, which can support the interaction between NF services in the NF. For example, these reference points can be implemented through the corresponding NF service-based interfaces and by specifying some NF service consumers and providers and their interactions to perform specific system processes.

[0217] Figure 2a The various NFs shown in can be responsible for functions such as session management, mobility management, authentication, security, etc. AUSF, AMF, DN, NEF, NRF, NSSF, PCF, SMF, UDM, UPF, AF, UE, (R)AN, SCP, NSACF, EASDF can include, for example, the functions defined in Clause 6.2 of 3GPP TS 23.501 V17.5.0.

[0218] Figure 2b Schematically shown is the system architecture in a 4G network according to an embodiment of the present disclosure, which is the same as Figure 4.2-1a of 3GPP TS 23.682 V17.3.0, the disclosure of which is incorporated herein by reference in its entirety. Figure 2b The system architecture may include some exemplary elements, such as a Service Capability Server (SCS), an Application Server (AS), SCEF (Service Capability Exposure Function), HSS, UE, RAN (Radio Access Network), SGSN (Serving GPRS (General Packet Radio Service) Support Node), MME, MSC (Mobile Switching Center), S-GW (Serving Gateway), GGSN / P-GW (Gateway GPRS Support Node / PDN (Packet Data Network) Gateway), MTC-IWF (Machine-Type Communication - Interworking Function), CDF / CGF (Charging Data Function / Charging Gateway Function), MTC-AAA (Machine-Type Communication - Authentication, Authorization, and Accounting), SMS-SC / GMSC / IWMSC (Short Message Service - Service Center / Gateway MSC / Interworking MSC), IP-SM-GW (Internet Protocol Short Message Gateway). As Figure 2b The network elements and interfaces shown in may be the same as the corresponding network elements and interfaces described in 3GPP TS 23.682 V17.2.0.

[0219] The system architecture shows an architecture where a UE for MTC is connected to a 3GPP network (UTRAN (Universal Terrestrial Radio Access Network), E-UTRAN (Evolved UTRAN), GERAN (GSM EDGE (Enhanced GSM Evolution Data Rate) Radio Access Network), etc.) via the Um / Uu / LTE-Uu interfaces. The system architecture also shows the 3GPP network service capability exposure to the SCS and AS.

[0220] AsFigure 2b As further shown, the exemplary system architecture also includes various reference points.

[0221] Tsms: A reference point used by an entity outside the 3GPP network to communicate with a UE for MTC via SMS (Short Message Service).

[0222] Tsp: A reference point used by the SCS to communicate with the control plane signaling related to the MTC-IWF.

[0223] T4: A reference point used between the MTC-IWF and the SMS-SC in the HPLMN.

[0224] T6a: A reference point used between the SCEF and the serving MME.

[0225] T6b: A reference point used between the SCEF and the serving SGSN.

[0226] T8: A reference point used between the SCEF and the SCS / AS.

[0227] S6m: A reference point used by the MTC-IWF to query the HSS / HLR (Home Location Register).

[0228] S6n: A reference point used by the MTC-AAA to query the HSS / HLR.

[0229] S6t: A reference point used between the SCEF and the HSS.

[0230] SGs: A reference point used between the MSC and the MME.

[0231] Gi / SGi: A reference point used between the GGSN / P-GW and the application server and between the GGSN / P-GW and the SCS.

[0232] Rf / Ga: A reference point used between the MTC-IWF and the CDF / CGF.

[0233] Gd: A reference point used between the SMS-SC / GMSC / IWMSC and the SGSN.

[0234] SGd: A reference point used between the SMS-SC / GMSC / IWMSC and the MME.

[0235] E: A reference point used between the SMS-SC / GMSC / IWMSC and the MSC.

[0236] End-to-end communication between MTC applications in the UE and MTC applications in the external network uses services provided by the 3GPP system and optionally uses services provided by the Service Capability Server (SCS).

[0237] MTC applications in the external network are typically hosted by an Application Server (AS) and can use the SCS for additional value-added services. The 3GPP system provides transport, subscriber management, and other communication services, including various architecture enhancements triggered by, but not limited to, MTC (e.g., control plane device triggering).

[0238] For communication between the AS and the 3GPP system and based on the SCS provider, different models are foreseen for machine type services. Different architecture models supported by the architecture reference model include the direct model, the indirect model, and the hybrid model, as described in 3GPP TS23.682 V17.3.0.

[0239] Figure 2c The non-roaming architecture of the network exposure function in the reference point representation is shown, which is the same as Figure 4.2.3-5 of 3GPP TS23.501 V17.5.0.

[0240] Note 1: The trust domain for the NEF is the same as the trust domain for the SCEF defined in 3GPP TS23.682 V17.3.0.

[0241] Note 2: The 3GPP interface represents the southbound interface between the NEF and the 5GC network functions, such as the N29 interface between the NEF and the SMF, the N30 interface between the NEF and the PCF, etc. For simplicity, not all southbound interfaces from the NEF are shown.

[0242] N33 is the reference point between the NEF and the AF. API represents the Application Programming Interface.

[0243] Figure 2d The non-roaming service exposure architecture for EPC (Evolved Packet Core)-5GC interworking is shown, which is the same as Figure 4.3.5.11 of 3GPP TS23.501 V17.5.0. If the UE is capable of moving between EPS and 5GS, the network is expected to associate the UE with an SCEF+NEF (SCEF combined with the NEF) node for service capability exposure.

[0244] Note 1: The trust domain for the SCEF+NEF is the same as the trust domain for the SCEF defined in 3GPP TS23.682 V17.3.0.

[0245] Note 2: The EPC interface represents the southbound interface between the SCEF and the EPC nodes, such as the S6t interface between the SCEF and the HSS, the T6a interface between the SCEF and the MME, etc. All southbound interfaces from the SCEF are defined in 3GPP TS23.682 V17.3.0 and are not shown for simplicity.

[0246] Note 3: The 5GC interface represents the southbound interface between the NEF and the 5GC network functions, such as the N29 interface between the NEF and the SMF, the N30 interface between the NEF and the PCF, etc. For simplicity, not all southbound interfaces from the NEF are shown.

[0247] Note 4: Interaction between the SCEF and the NEF within the combined SCEF+NEF is required. For example, when the SCEF+NEF supports the monitoring API, if the UE moves between the EPC and the 5GC, the SCEF and the NEF need to share the context and status information of the monitoring events regarding the UE's configuration.

[0248] Note 5: The northbound APIs that the EPC or 5GC network can support are discovered by the SCEF+NEF node via the CAPIF (Common API Framework for 3GPP northbound APIs) function and / or via the local configuration of the SCEF+NEF node. Different API sets can be supported by both network types.

[0249] Figure 3 A flowchart of a method according to an embodiment of the present disclosure is shown, and the method can be executed by a device implemented in an open function, or a device implemented at an open function, or a device implemented as an open function, or a device communicatively coupled to an open function. Therefore, the device can provide components or modules for implementing various parts of method 300, as well as components or modules for implementing other processes in combination with other components.

[0250] The open function can be any suitable network device or node or entity or function. For example, the open function can provide components for securely opening services, events, and capabilities provided by a network interface. The open function can provide components for discovering the opened services and capabilities. The open function can provide access to network capabilities through a homogeneous network application programming interface (e.g., a network API). The open function can abstract services from underlying network interfaces and protocols. In an embodiment, the network function can include at least one of a Service Capability Exposure Function (SCEF), a Network Exposure Function (NEF), and an SCEF combined with the NEF.

[0251] At block 302, the open function can receive a first message from an application node, and the first message includes at least one parameter to be created or updated. The at least one parameter to be created or updated can include user plane (UP) security information for a virtual network (VN) group.

[0252] The application node can be any suitable network device or node or entity or function. In an embodiment, the application node can include at least one of an Application Function (AF), a Service Capability Server (SCS), or an Application Server (AS).

[0253] The first message can be any suitable message, such as an existing message or a new message. In an embodiment, the first message can include at least one of a parameter provision create request or a parameter provision update request. For example, the first message can be an Nnef_ParameterProvision_Create request or an Nnef_ParameterProvision_Update request as described in 3GPP TS23.502 V17.5.0.

[0254] The at least one parameter to be created or updated can also include any suitable parameter. For example, when the first message is a parameter provision create request, it can include at least one of the following: AF identifier, transaction reference ID (identifier), GPSI (Generic Public Subscription Identifier) or UE addressing information, external group ID for 5G VN group creation or for multicast MBS (Multicast / Broadcast Service) group creation, external group ID, 5G VN group related information (such as 5G VN group data, 5G VN membership management), MTC provider information, multicast MBS group related information (such as multicast MBS group membership management), etc.

[0255] For example, when the first message is a parameter provision update request, it can include at least one of the following: AF identifier, transaction reference ID, GPSI or UE addressing information, external group ID, at least one of expected UE behavior parameters or at least one of network configuration parameters or 5G VN related information or ECS (Edge Configuration Server) address configuration information, validity time or location privacy indication parameter, MTC provider information or multicast MBS group related information.

[0256] A VN group can be a group of UEs using private communication for LAN type services. In an embodiment, the VN group can include a fifth generation VN group.

[0257] The UP security information for the VN group can provide the same user plane security configuration data for the VN group. In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0258] The UP security information for the VN group can include any suitable user plane security configuration data. In an embodiment, the UP security information for the VN group can include at least one of the following: an information element indicating whether UP integrity protection is required, preferred or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred or not required for traffic on a PDU session.

[0259] At block 304, the open function can send a second message including at least one parameter to be created or updated to a data management node or a data repository node.

[0260] The data management node can be any suitable network device or node or entity or function. In an embodiment, the data management node can include Unified Data Management (UDM).

[0261] The data repository node can be any suitable network device or node or entity or function. In an embodiment, the data repository node can include a Home Subscriber Server (HSS) or a Home Location Register (HLR).

[0262] The second message can be any suitable message, such as an existing message or a new message. In an embodiment, the second message can include at least one of a parameter provision create request or a parameter provision update request. For example, the second message can be a Nudm_ParameterProvision_Create request or a Nudm_ParameterProvision_Update request as described in 3GPP TS23.502 V17.5.0.

[0263] Figure 4a A flowchart of a method according to another embodiment of the present disclosure is shown, which can be executed by a device implemented in a data management node, or a device implemented at a data management node, or a device implemented as a data management node, or a device communicatively coupled to a data management node. Thus, the device can provide components or modules for implementing various parts of method 400, and components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, descriptions thereof are omitted here for the sake of brevity.

[0264] At block 402, the data management node can receive a second message including at least one parameter to be created or updated from an open function or an Application Function (AF). The at least one parameter to be created or updated can include User Plane (UP) security information for a Virtual Network (VN) group.

[0265] In an embodiment, the data management node can include Unified Data Management (UDM).

[0266] In an embodiment, the open function can include a Network Exposure Function (NEF).

[0267] In an embodiment, the VN group can include a 5G VN group.

[0268] In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0269] In an embodiment, the UP security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0270] In an embodiment, the second message may include at least one of a parameter provision creation request or a parameter provision update request.

[0271] At block 404, the data management node may send a third message to the data repository node, the third message including at least one parameter to be created or updated.

[0272] The third message may be any suitable message, such as an existing message or a new message. In an embodiment, the third message may include at least one of a data management creation request or a data management update request. For example, the second message may be a Nudr_DM_Create request or a Nudr_DM_Update request as described in 3GPP TS23.502 V17.5.0.

[0273] In an embodiment, the data repository node may include a Unified Data Repository (UDR).

[0274] Figure 4b A flowchart of a method according to another embodiment of the present disclosure is shown, the method being executable by an apparatus implemented in a data management node, or an apparatus implemented at a data management node, or an apparatus implemented as a data management node, or an apparatus communicatively coupled to a data management node. Thus, the apparatus may provide components or modules for implementing various parts of method 410, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, descriptions thereof are omitted here for the sake of brevity.

[0275] At block 412, the data management node may receive a first request from the session management function for retrieving shared data for a VN group.

[0276] The session management function may be any suitable network device or node or entity or function. In an embodiment, the session management function may be an SMF.

[0277] The first request may be any suitable message, such as an existing message or a new message. In an embodiment, the first request may be a Nudm_SDM_GET request as described in 3GPP TS23.502 V17.5.0.

[0278] At block 414, the data management node may send a second request to the data repository node to retrieve shared data for the VN group.

[0279] The second request may be any suitable message, such as an existing message or a new message. In an embodiment, the second request may be a Nudr_DM_Query request as described in 3GPP TS23.502 V17.5.0.

[0280] At block 416, the data management node may receive a second response from the data repository node that includes the shared data for the VN group.

[0281] In an embodiment, the shared data for the VN group may include UP security information for the VN group.

[0282] The second response may be any suitable message, such as an existing message or a new message. In an embodiment, the second response may be a Nudr_DM_Query response as described in 3GPP TS23.502 V17.5.0.

[0283] At block 418, the data management node may send a first response that includes the shared data for the VN group to the session management function.

[0284] The first response may be any suitable message, such as an existing message or a new message. In an embodiment, the first response may be a Nudm_SDM_GET response as described in 3GPP TS23.502 V17.5.0.

[0285] Figure 4c A flowchart of a method according to another embodiment of the present disclosure is shown, which may be performed by an apparatus implemented in a data management node, or an apparatus implemented at a data management node, or an apparatus implemented as a data management node, or an apparatus communicatively coupled to the data management node. Thus, the apparatus may provide components or modules for implementing various parts of method 420, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, the description thereof is omitted here for the sake of brevity.

[0286] At block 422, the data management node may receive a third request from the session management function to subscribe to data change notifications for the VN group.

[0287] The third request may be any suitable message, such as an existing message or a new message. In an embodiment, the third request may be a Nudm_SDM_Subscribe request as described in 3GPP TS23.502 V17.5.0.

[0288] At block 424, the data management node may send a fourth request to the data repository node for subscribing to data change notifications for a VN group.

[0289] The fourth request may be any suitable message, such as an existing message or a new message. In an embodiment, the fourth request may be a Nudr_DM_Subscribe request as described in 3GPP TS23.502 V17.5.0.

[0290] At block 426, the data management node may receive a first data change notification message from the data repository node, including UP security information for the VN group.

[0291] The first data change notification message may be any suitable message, such as an existing message or a new message. In an embodiment, the first data change notification message may be a Nudr_DM_Notify message as described in 3GPP TS23.502 V17.5.0.

[0292] At block 428, the data management node may send a second data change notification message including UP security information for the VN group to the session management function.

[0293] The second data change notification message may be any suitable message, such as an existing message or a new message. In an embodiment, the second data change notification message may be a Nudm_SDM_Notification message as described in 3GPP TS23.502 V17.5.0.

[0294] Figure 5 A flowchart of a method according to another embodiment of the present disclosure is shown, which may be executed by a device implemented in an application node, or a device implemented at an application node, or a device implemented as an application node, or a device communicatively coupled to an application node. Thus, the device may provide components or modules for implementing various parts of method 500, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0295] At block 502, the application node may send a first message including at least one parameter to be created or updated to an open function, or a data management node, or a data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0296] For example, when the application node is a trusted application node, the application node may send the first message to the data management node or the data repository node. When the application node is a non-trusted application node, the application node may send the first message to the open function.

[0297] In an embodiment, the VN group may include a fifth-generation VN group.

[0298] In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0299] In an embodiment, the UP security information for the VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on the PDU session.

[0300] In an embodiment, the first message may include at least one of the following: a parameter provision creation request, or a parameter provision update request.

[0301] In an embodiment, the application node may include at least one of an application function (AF), a service capability server (SCS), or an application server (AS).

[0302] In an embodiment, the open function may include at least one of a service capability exposure function (SCEF), a network exposure function (NEF), or an SCEF combined with the NEF.

[0303] In an embodiment, the data repository node may include at least one of a home subscriber server (HSS) or a home location register (HLR).

[0304] In an embodiment, the data management node may include a unified data management (UDM).

[0305] Figure 6a A flowchart of a method according to another embodiment of the present disclosure is shown, and the method may be executed by a device implemented in a network management node, or a device implemented at a network management node, or a device implemented as a network management node, or a device communicatively coupled to the network management node. Therefore, the device may provide components or modules for implementing various parts of method 600, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0306] At block 602, the network management node may send a fourth message including at least one parameter to be created or updated to the data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0307] A network management node can be any suitable network device or node or entity or function. In an embodiment, the network management node can include a communication service provider (CSP) providing system.

[0308] The fourth message can be any suitable message, such as an existing message or a new message. In an embodiment, the fourth message can be a parameter provision creation request or a parameter provision update request. For example, the fourth message can be a Nudr_DM_Create request or a Nudr_DM_Update request as described in 3GPP TS 23.502 V17.5.0.

[0309] In an embodiment, the VN group can include a fifth-generation VN group.

[0310] In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0311] In an embodiment, the UP security information for the VN group can include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0312] In an embodiment, the data repository node can include a unified data repository (UDR) or a home subscriber server (HSS) or a home location register (HLR).

[0313] Figure 6b A flowchart of a method according to another embodiment of the present disclosure is shown, which can be executed by a device implemented in a data repository node, or a device implemented at a data repository node, or a device implemented as a data repository node, or a device communicatively coupled to a data repository node. Thus, the device can provide components or modules for implementing various parts of method 610, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0314] At block 612, the data repository node can receive a message including at least one parameter to be created or updated from a data management node or an open function or an application node or a network management node. The at least one parameter to be created or updated can include user plane (UP) security information for a virtual network (VN) group.

[0315] At block 614, the data repository node can store the at least one parameter to be created or updated.

[0316] In an embodiment, the VN group may include a fifth-generation VN group.

[0317] In an embodiment, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

[0318] In an embodiment, the UP security information for the VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on the PDU session.

[0319] In an embodiment, the message may include at least one of a data management creation request or a data management update request.

[0320] In an embodiment, the data repository node may include at least one of a home subscriber server (HSS), a home location register (HLR), or a unified data repository (UDR).

[0321] In an embodiment, the data management node may include unified data management (UDM).

[0322] In an embodiment, the open function may include at least one of a service capability exposure function (SCEF), a network exposure function (NEF), or an SCEF combined with the NEF.

[0323] In an embodiment, the application node may include at least one of an application function (AF), a service capability server (SCS), or an application server (AS).

[0324] In an embodiment, the network management node may include a CSP-provided system.

[0325] Figure 6c A flowchart of a method according to another embodiment of the present disclosure is shown, and the method may be executed by a device implemented in a data repository node, or a device implemented at a data repository node, or a device implemented as a data repository node, or a device communicatively coupled to the data repository node. Therefore, the device may provide components or modules for implementing various parts of method 620, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, descriptions thereof are omitted here for the sake of brevity.

[0326] At block 622, if no internal group identifier is assigned to the VN group identified by the external group ID, the data repository node may assign an internal group identifier (ID).

[0327] At block 624, the data repository node may store a mapping between an internal group ID and an external group ID.

[0328] At block 626, the data repository node may assign a shared data ID for the VN group data.

[0329] At block 628, for each member of the VN group, the data repository node may associate session management data with the internal group ID and the shared data ID.

[0330] Figure 6d A flowchart of a method according to another embodiment of the present disclosure is shown. The method may be executed by a device implemented in a data repository node, or a device implemented at a data repository node, or a device implemented as a data repository node, or a device communicatively coupled to the data repository node. Thus, the device may provide components or modules for implementing various parts of method 630, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0331] At block 632, the data repository node may receive a request for retrieving shared data for a VN group from a data management node or a session management function.

[0332] At block 634, the data repository node may send a response including the shared data for the VN group to the data management node or the session management function.

[0333] In an embodiment, the shared data for the VN group may include UP security information for the VN group.

[0334] Figure 6e A flowchart of a method according to another embodiment of the present disclosure is shown. The method may be executed by a device implemented in a data repository node, or a device implemented at a data repository node, or a device implemented as a data repository node, or a device communicatively coupled to the data repository node. Thus, the device may provide components or modules for implementing various parts of method 640, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0335] At block 642, the data repository node may receive a request for subscribing to data change notifications for a VN group from a data management node or a session management function.

[0336] At block 644, the data repository node may send a data change notification message to the data management node or the session management function.

[0337] In an embodiment, the data change notification message may include UP security information for a VN group.

[0338] Figure 6f A flowchart of a method according to another embodiment of the present disclosure is shown, and the method may be executed by a device implemented in a session management function, or a device implemented at a session management function, or a device implemented as a session management function, or a device communicatively coupled to a session management function. Thus, the device may provide components or modules for implementing various parts of method 650, as well as components or modules for implementing other processes in combination with other components. For some parts already described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0339] At block 652, the session management function may send a request to a data management node or a data repository node to retrieve shared data for a VN group.

[0340] At block 654, the session management function may receive a response including shared data for a VN group from the data management node or the data repository node.

[0341] In an embodiment, the shared data for a VN group may include UP security information for the VN group.

[0342] In an embodiment, the VN group may include a fifth-generation VN group.

[0343] In an embodiment, the UP security information for a VN group indicates that the same UP security is applied to the VN group.

[0344] In an embodiment, the UP security information for a VN group may include at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

[0345] In an embodiment, the data repository node may include at least one of a home subscriber server (HSS) or a home location register (HLR).

[0346] In an embodiment, the data management node may include a unified data management (UDM).

[0347] Figure 6gA flowchart of a method according to another embodiment of the present disclosure is shown, and the method may be executed by a device implemented in a session management function, or a device implemented at a session management function, or a device implemented as a session management function, or a device communicatively coupled to a session management function. Thus, the device may provide components or modules for implementing various parts of method 660, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0348] At block 662, the session management function may send a request to subscribe to data change notifications for a VN group to a data management node or a data repository node.

[0349] At block 664, the session management function may receive a data change notification message from a data management node or a data repository node.

[0350] In an embodiment, the data change notification message may include UP security information for the VN group.

[0351] Figure 6h A flowchart of a method according to another embodiment of the present disclosure is shown, and the method may be executed by a device implemented in a session management function, or a device implemented at a session management function, or a device implemented as a session management function, or a device communicatively coupled to a session management function. Thus, the device may provide components or modules for implementing various parts of method 670, as well as components or modules for implementing other processes in combination with other components. For some parts that have been described in the above embodiments, for the sake of brevity, the description thereof is omitted here.

[0352] At block 672, the session management function may determine whether a protocol data unit (PDU) session establishment is for individual-level communication or for group-level communication.

[0353] The session management function may determine whether a PDU session establishment is for individual-level communication or for group-level communication in various ways. For example, the SMF may receive an Nsmf_PDUSession_CreateSMContext request as described in 3GPP TS23.502 V17.5.0 from the AMF, and the Nsmf_PDUSession_CreateSMContext request may include information indicating whether the PDU session establishment is for individual-level communication or for group-level communication. The session management function may determine whether a PDU session establishment is for individual-level communication or for group-level communication based on subscription information or any other suitable information.

[0354] For example, the SMF can determine whether the PDU session establishment is for individual-level communication or for group-level communication, for example, based on DNN (Data Network Name) and S-NSSAI (Single Network Slice Selection Assistance Information) information, and further determine the user plane security to be used.

[0355] At block 674, when the PDU session establishment is for group-level communication, the session management function can set the same user plane security data from the UP security information for the VN group into the PDU session request going to the radio access network through the access and mobility management function.

[0356] In an embodiment, the user plane security implementation information for the user plane of the PDU session can be determined based on at least one of the following:

[0357] - The subscribed user plane security configuration, which is part of the SM subscription information received from the UDM; and

[0358] - When the UDM does not provide the user plane security configuration information, use the user plane security configuration locally configured in the SMF according to (DNN, S-NSSAI).

[0359] Once determined at the time of establishing the PDU session, the user plane security implementation information is applied to the life cycle of the PDU session.

[0360] In an embodiment, the user plane security configuration from the UDM takes precedence over the locally configured user plane security configuration. The NG-RAN is responsible for implementing that the maximum UP integrity protection data rate transmitted to the UE in the downlink does not exceed the maximum supported data rate for integrity protection.

[0361] In an embodiment, the user plane security information (annotated as the UpSecurity data type in a later protocol extension) provides the user plane (UP) security policy for the PDU session to the NG-RAN.

[0362] In an embodiment, the user plane security information indicates whether UP integrity protection is (annotated as the UpIntegrity data type in a later protocol extension):

[0363] - Required: For all traffic on the PDU session, UP integrity protection should be applied.

[0364] - Preferred: For all traffic on the PDU session, UP integrity protection should be applied.

[0365] - Not required: UP integrity protection should not be applied on the PDU session.

[0366] In an embodiment, the user plane security information indicates whether UP confidentiality protection is (annotated as the UpConfidentiality data type in a later protocol extension):

[0367] - Required: For all traffic on the PDU session, UP confidentiality protection shall be applied.

[0368] - Preferred: For all traffic on the PDU session, UP confidentiality protection shall be applied.

[0369] - Not required: UP confidentiality shall not be applied on the PDU session.

[0370] Figure 7a A flowchart showing an AF providing user plane configuration data for a VN group according to an embodiment of the present disclosure is presented.

[0371] This flowchart depicts a call flow for an AF to provide user plane security information for a VN group. Two scenarios are included.

[0372] For Scenario 1, the AF is from an external application function or from an external enterprise application or from an external vertical industry application, so the AF is not trusted by the CSP's network. The steps can be as follows.

[0373] In step 1. The AF can initiate an HTTP (HyperText Transfer Protocol) POST request to the NEF for the "5GLAN parameter provision subscription" resource. The body of the HTTP POST message shall contain 5GLAN service-related parameters within the "5gLanParams" attribute. The novel part here is that 5GLanParameters is extended with new attributes to provide the same user plane security configuration data.

[0374] An embodiment of the 5GLanParameters protocol payload extended with user plane security (the highlighted part is the extension) is shown in Table 1 below. Table 1: Definition of type 5GlanParameters extended with the new upSecurity attribute

[0375] Table 1 is the same as Table 5.7.2.3.3-1 of 3GPP TS29.522 V17.7.0, except for the new attribute "upSecurity".

[0376] In an embodiment, A.5 of 3GPP TS29.522 V17.7.0 can be modified as follows. A.5 5G LAN Parameter Provision API

[0377] The UpSecurity data type is further defined as in Table 2: Table 2: Definition of UpSecurity type

[0378] The enumeration UpIntegrity indicates whether UP integrity protection is required, preferred, or not required for all traffic on the PDU session. It can comply with the provisions defined in Table 3. Table 3: Enumeration UpIntegrity

[0379] The enumeration UpConfidentiality indicates whether UP confidentiality protection is required, preferred, or not required for all traffic on the PDU session. It can comply with the provisions defined in Table 4. Table 4: Enumeration UpConfidentiality

[0380] In step 2. After receiving the corresponding HTTP POST message, if the AF is authorized by the NEF to provide the parameter, the NEF can interact with the UDM by using the Nudm_ParameterProvision service to create a subscription at the UDM. The NEF can send a request to the UDM to create a 5G VN group. The request contains the external identifier of the group and the group configuration. 5GVnGroupData is extended with new attributes to provide the same user plane security information. For the description of this attribute, please refer to the description in step 1.

[0381] An example of the 5GVnGroupData protocol payload extended with user plane security (the highlighted part is the extension) is shown in Table 5 below: Table 5: Definition of type 5GVnGroupData with new extended upSecurity attribute

[0382] Table 5 is the same as Table 6.5.6.2.7-1 of 3GPP TS 29.503 V17.8.0 except for the new attribute "upSecurity".

[0383] In step 3, the UDM may send a request to the UDR to create a 5G VN group. The request may contain the external identifier of the group and the group configuration. Similarly, the 5GVnGroupConfiguration on the Nudr interface is extended with new attributes to provide user plane security information. An example of the 5GVnGroupData protocol payload extended with user plane security configuration is depicted in step 2.

[0384] In step 4. After receiving the corresponding message from the UDM for creating a 5G VN group, as an example method, the UDR may perform the following specific logic:

[0385] (1) Store the 5GVnGroupConfiguration data with the above new extended attributes for the same user plane security configuration

[0386] (2) If the UDM has not yet assigned an internal group Id to the group identified by the external group identifier, assign an internal group Id and store the mapping between the internal group id and the external group Id

[0387] (3) Assign a shared data ID for the VN group data

[0388] (4) For each member indicated in the 5GVnGroupConfiguration for the VN group: Associate the session management data with the internal group id and the shared data id pointing to the VN group data

[0389] In step 5. The UDR may notify the UDM of a successful response. The internal group identifier may be returned in this response.

[0390] In step 6. The UDM may notify the NEF of a successful response.

[0391] In step 7. The NEF may notify the AF of a successful response.

[0392] For scenario 2, where the AF is trusted, the steps may be as follows.

[0393] In step 1. The AF may send a request to the UDM to create a 5G VN group. The request may contain the external identifier of the group and the group configuration. The 5GVnGroupConfiguration is extended with new attributes to provide the same user plane configuration data: UpIntegrity and UpConfidentiality. For the description of these attributes, please refer to the description in step 1 of scenario 1.

[0394] In step 2, the UDM can send a request to the UDR to create a 5G VN group. The request can include the external identifier of the group and the group configuration. Similarly, the 5GVnGroupConfiguration on the Nudr interface is extended with new attributes to provide the same user plane security configuration data: UpIntegrity and UpConfidentiality. For the descriptions of these attributes, please refer to the description in step 1 of scenario 1.

[0395] In step 3, after receiving the corresponding message from the UDM for creating a 5G VN group, the UDR can execute specific logic:

[0396] (1) If the UDM has not yet assigned an internal group Id to the group identified by the external group identifier, assign an internal group Id and store the mapping between the internal group id and the external group Id

[0397] (2) Assign a shared data ID to the 5G VN group data

[0398] (3) Store the 5GVnGroupConfiguration data with the above new extended attributes for the same user plane security configuration

[0399] (4) For each member indicated in the 5GVnGroupConfiguration for the VN group: associate the session management data with the internal group id and the shared data id pointing to the VN group data

[0400] In step 4, the UDR can notify the UDM of a successful response. The internal group identifier can be returned in this response.

[0401] In step 5, the UDM can notify the AF of a successful response.

[0402] Figure 7b The flowchart shows the process by which the CSP provides user plane security data for a VN group according to an embodiment of the present disclosure.

[0403] This flowchart depicts the flowchart of the call flow for the CSP to provide user plane security through OAM and the providing system. The steps can be as follows.

[0404] In step 1, the CSP OAM (Operation Administration and Maintenance) management side can send a parameter providing request to the providing system to create a 5G VN group. The request can include the external identifier of the group and the group configuration. The 5GVnGroupConfiguration is extended with new attributes to provide the same user plane security configuration data: UpIntegrity and UpConfidentiality. For the descriptions of these attributes, please refer to Figure 7aDescription in Step 1 of Medium Scenario 1.

[0405] In Step 2. The providing system can send a request to the UDR to create a 5G VN group. The request can include the external identifier of the group and the group configuration. Similarly, the 5GVnGroupConfiguration on the Nudr interface is extended with new attributes to provide the same user plane configuration data: UpIntegrity and UpConfidentiality. For the descriptions of these attributes, please refer to Figure 7a the description in Step 1 of Scenario 1.

[0406] In Step 3. After receiving the corresponding message from the providing system for creating a 5G VN group, the UDR can execute specific logic:

[0407] (1) Allocate an internal group Id for the group identified by the external group identifier and store the mapping between the internal group id and the external group Id

[0408] (2) Allocate a shared data Id for the 5G VN group data

[0409] (3) Store the 5GVnGroupConfiguration data with the above newly extended attributes for the same user plane security configuration

[0410] (4) For each member indicated in the 5GVnGroupConfiguration for the VN group: Associate the session management data with the internal group id and the shared data id pointing to the VN group data

[0411] In Step 4. The UDR can notify the providing system of a successful response.

[0412] In Step 5. The providing system can notify the OAM administrator of a successful response.

[0413] Figure 7c A flowchart showing the PDU session establishment process according to an embodiment of the present disclosure.

[0414] This flowchart depicts the PDU session establishment / modification process. For group-level PDU sessions, the provided shared VN group data can be retrieved from the UDM. Based on the embodiments of the present disclosure, the VN group data is extended with user plane security data. The steps are as follows.

[0415] In step 1. The UE initiates the PDU session establishment procedure requested by the UE by sending a NAS message containing a PDU session establishment request (the PDU session establishment request is within the N1 SM (session management) container). The PDU session establishment request includes the PDU session ID, the requested PDU session type, the requested SSC (session and service continuity) mode, 5GSM capabilities, PCO (protocol configuration options), SM PDU DN request container, [number of packet filters], [header compression configuration], UE integrity protection maximum data rate, [request for always-on PDU session], [RSN (redundancy sequence number)], and [PDU session pair ID].

[0416] In step 2. The AMF selects an SMF.

[0417] In step 3. If the AMF has no association with the SMF for the PDU session ID provided by the UE (e.g., when the request type indicates "initial request"), the AMF invokes the Nsmf_PDUSession_CreateSMContext request, but if the AMF already has an association with the SMF for the PDU session ID provided by the UE (e.g., when the request type indicates "existing PDU session"), the AMF invokes the Nsmf_PDUSession_UpdateSMContext request.

[0418] In step 4. If the session management subscription data for the S-NSSAI of the corresponding SUPI, DNN, and HPLMN is not available, the SMF uses Nudm_SDM_Get (SUPI, session management subscription data, the selected DNN, S-NSSAI of the HPLMN, serving PLMN ID, [NID]) to retrieve the session management subscription data.

[0419] The UDR sends the session management subscription data for the UE to the UDM. The internal group Id assigned by the UDR to which the UE belongs is returned, and at the same time, the shared data id pointing to the VN group data is also returned. The UDM further sends the session management data to the SMF.

[0420] In step 5. The SMF uses Nudm_SDM_Subscribe (SUPI, session management subscription data, the selected DNN, S-NSSAI of the HPLMN, serving PLMN ID, [NID]) to subscribe to be notified when this subscription data is modified. The UDM can obtain this information from the UDR through Nudr_DM_Query (SUPI, subscription data, session management subscription data, the selected DNN, S-NSSAI of the HPLMN, serving PLMN ID, [NID]), and can subscribe to notifications from the UDR for the same data through Nudr_DM_subscribe.

[0421] The SMF supports the processing of VN group data and can indicate to the UDM that it supports the SharedData feature.

[0422] In step 6, the SMF sends an Nsmf_PDUSession_CreateSMContext response to the AMF.

[0423] In step 7, the SMF determines, for example based on DNN and S-NSSAI information, whether the PDU session establishment is for individual-level communication or for group-level communication, and further determines that user plane security should be used.

[0424] The user plane security implementation information for the user plane of the PDU session is based on the following:

[0425] The subscribed user plane security configuration, which is part of the SM subscription information received from the UDM; and

[0426] When the UDM does not provide user plane security configuration information, the user plane security configuration locally configured in the SMF according to (DNN, S-NSSAI) is used.

[0427] Once determined at the establishment of the PDU session, the user plane security implementation information is applied throughout the life cycle of the PDU session.

[0428] The user plane security configuration from the UDM takes precedence over the locally configured user plane security configuration. The NG-RAN is responsible for ensuring that the maximum UP integrity protection data rate transmitted to the UE in the downlink does not exceed the maximum supported data rate for integrity protection.

[0429] It is expected that the UP integrity protection data rate applied by the UE in the uplink will generally not exceed the indicated maximum supported data rate, but the UE is not required to enforce strict rate implementation.

[0430] At handover, the source NG-RAN node transfers the user plane security implementation information for integrity protection and the maximum supported data rate according to the UE to the target NG-RAN node. If the target RAN node cannot support the requirements in the user plane security implementation information, the target RAN node rejects the request to set up resources for the PDU session. In this case, the PDU session is not handed over to the target RAN node and the PDU session is released.

[0431] Alternative #1: If the PDU session establishment is for individual communication

[0432] In step 8, the SMF checks the per-user plane security information of the session management data received from step 4, and if the PDU session establishment is for individual communication, in steps 14 and 15, the SMF sets the user plane security data from the individual session management data into the PDU session request to the RAN via the AMF.

[0433] Alternative #2: If the PDU session establishment is for group communication

[0434] In step 9, the SMF checks the received session management data and finds that the UE belongs to the group identified by the internal group ID and the associated shared data ID for VN group data. The SMF retrieves the shared data for the VN group from the UDM via the shared data ID, and the UDM further retrieves it from the UDR.

[0435] In step 10, the UDR sends the shared data for the VN group to the UDM. As mentioned above, the user plane security configuration for the VN group is also returned in the VN group data. The UDM further sends the VN group data with the included user plane security configuration to the SMF.

[0436] An example of the shared VnGroupData extended with the user plane security configuration (the underlined part is the extension) is shown in Table 6. Table 6: Definition of the type VnGroupData with the new extended upSecurity attribute

[0437] Except for the new attribute " upSecurity ", Table 6 is the same as Table 6.1.6.2.39-1 of 3GPP TS29.503 V17.8.0.

[0438] In the embodiment, A.2 of 3GPP TS29.503 V17.8.0 can be modified as follows. A.2 NUDM_SDM API

[0439] In the embodiment, A.6 of 3GPP TS29.503 V17.8.0 can be modified as follows. A.6 NUDM_PP API

[0440] Note: UpSecurity is defined in Table 2-4.

[0441] In step 11, the SMF can subscribe to the UDR via the UDM for data change notifications for the VN group data. If there is a user plane security change, the changed user plane security will be notified to the SMF. Therefore, the SMF can be notified at any time of the user plane security configuration change for the VN group.

[0442] In step 12, the SMF checks the group-level user plane security information from the VN group data received in step 10. And if the PDU session establishment is for group-level communication, in steps 14 and 15, the same user plane security data from the VN group data is set into the PDU session request to the RAN via the AMF.

[0443] In step 13, the SMF sends an N4 / PFCP session establishment / modification message to the UPF. This message includes the PDR, FAR, and other rules for the PDU session. The UPF processes the session establishment / modification request and creates the rules provided by the SMF.

[0444] In step 14, SMF to AMF: Namf_Communication_N1N2MessageTransfer (PDU session ID, N2SM information (PDU session ID, one or more QFIs, one or more QoS profiles, CN tunnel information, S-NSSAI from the allowed NSSAI, session-AMBR, PDU session type, user plane security implementation information, UE integrity protection maximum data rate, RSN, PDU session pair ID), N1 SM container (PDU session establishment acceptance ([one or more QoS rules, and if needed, QoS flow level QoS parameters for one or more QoS flows associated with one or more QoS rules], selected SSC mode, one or more S-NSSAIs, UE-requested DNN, allocated IPv4 address, interface identifier, session-AMBR, selected PDU session type, [reflected QoS timer] (if available), [one or more P-CSCF addresses], [control plane only indicator], [header compression configuration], [permitted always-on PDU session], [small data rate control parameter], [small data rate control status], [service PLMN rate control], [one or more PVS FQDNs and / or one or more PVS IP addresses]))). If multiple UPFs are used for the PDU session, the CN tunnel information contains the tunnel information related to the UPF terminating N3.

[0445] The N2 SM information carries the information that the AMF should forward to the (R)AN, which includes the user plane security implementation information determined by the SMF as described in step 8 or step 12.

[0446] At step 15. AMF to (R)AN: N2 PDU session request (N2 SM information, NAS message (PDU session ID, N1 SM container (PDU session establishment acceptance)), [CN-assisted RAN parameter adjustment]). The N2 SM information carries information including the user plane security implementation information determined by the SMF as described in step 8 or step 12.

[0447] At step 16. (R)AN to UE: The (R)AN may exchange AN-specific signaling with the UE related to the information received from the SMF. For example, in the case of NG-RAN, an RRC connection reconfiguration may occur with the UE to establish the necessary NG-RAN resources related to the QoS rules for the PDU session request received in step 15. The gNB / ng-eNB shall send an RRC connection reconfiguration message to the UE for UP security activation, which contains an indication of the activation of UP integrity protection and encryption for each DRB according to the security configuration from step 15.

[0448] At step 17. (R)AN to AMF: N2 PDU session response (PDU session ID, cause, N2 SM information (PDU session ID, AN tunnel information, list of one or more accepted / rejected QFIs, user plane implementation policy notification)). When the NG-RAN cannot meet the user plane security implementation information with a value of Required, it rejects the establishment of UP resources for the PDU session. When the NG-RAN cannot meet the user plane security implementation with a value of Preferred, the NG-RAN notifies the SMF.

[0449] At step 18. AMF to SMF: Nsmf_PDUSession_UpdateSMContext request (SM context ID, N2SM information, request type). The AMF forwards the N2 SM information received from the (R)AN to the SMF.

[0450] At step 19. The SMF initiates an N4 session modification procedure with the UPF. The SMF provides the AN tunnel information and the corresponding forwarding rules to the UPF. The UPF provides an N4 session modification response to the SMF.

[0451] At step 20. The SMF registers for the PDU session in the UDM.

[0452] At step 21. SMF to AMF: Nsmf_PDUSession_UpdateSMContext response (cause).

[0453] Some steps such as steps 7, 10, and 12 are new steps according to embodiments of the present disclosure. Some steps may be the same as the corresponding steps described in 3GPP TS23.502 V17.5.0.

[0454] In an embodiment, to solve Problem 1, the NEF 5G LAN parameter provisioning interface is improved such that an external application function or an external enterprise application or an external vertical application can configure the same user plane security for a certain 5G VN group. In addition, the UDM parameter provisioning interface is improved to allow the NEF to provide the same user plane security for a certain 5G VN group into the UDM.

[0455] In an embodiment, to solve Problem 2, the UDM parameter provisioning interface is improved to allow the NEF to provide the same user plane security for a certain 5G VN group into the UDM. The UDR group management data interface is improved to provide the same user plane security for a certain 5G VN group into the UDR through the provisioning system of the UDM or the communication service provider.

[0456] In an embodiment, to solve Problem 3, a conflict resolution mechanism is recommended, that is, if a PDU session is established for group communication, the same user plane security of the 5G VN group is implemented. If a PDU session is established for non-group-level communication, the user plane security configured at the individual level should be used.

[0457] In an embodiment, the NEF opens a new method for configuring the same user plane security of a certain 5G VN group that should be implemented during group-level communication to an external application function or an external enterprise application or a vertical application. The mentioned configuration also includes operations of creation, update, and deletion.

[0458] In an embodiment, the UDM opens a new method for configuring the same user plane security of a certain 5G VN group that should be implemented during group-level communication. The mentioned configuration also includes operations of creation, update, and deletion. One of the consumers of this service is the NEF. When the NEF accepts a request from an external application or an external enterprise application or an external vertical application, the NEF configures the same user plane security of a certain 5G VN group managed by the corresponding UDM.

[0459] In an embodiment, the UDR opens a new method for configuring the same user plane security of a certain 5G VN group that should be implemented during group-level communication. One of the consumers of this service is the UDM. When the UDM accepts a request from the NEF, the UDM configures the same user plane security of a certain VN group managed by the corresponding UDR.

[0460] In an embodiment, the new method in the SMF determines which user plane security configuration should be used. If a PDU session is established for group-level communication, the user plane security configured at the group level shall take precedence. If an individual PDU session is established for non-group-level communication, the user plane security at the individual level shall take precedence.

[0461] The embodiments herein can provide many advantages. The following is a non-exhaustive list of examples of advantages. In some embodiments herein, the proposed solution can enable the possibility for external applications or external enterprise applications or vertical applications to configure the same user plane security for a VN group, which enhances the openness of the communication service provider to monetize the diverse services carried by the network and enables more use cases for the network, especially for vertical industries that have requirements for the same user plane security. In some embodiments herein, the proposed solution can enhance the manageability of the same user plane security for a VN group, supporting new configuration operations for the creation, update, and deletion of the same user plane security for a VN group in a unified service-based interface. It reduces the deficiencies in the management of VN groups with the same user plane security and OPEX (operational expenditure). In some embodiments herein, by using the recommended user plane security conflict resolution mechanism, the flexibility to configure user plane security at both the individual level and the group level can be achieved, and different user plane security can be set for the PDU sessions established for group communication and the PDU sessions established for individual communication. In some embodiments herein, to reduce the incremental complexity added by security, all PDU sessions associated with a specific LAN group should have the same user plane security configuration. This can be easily ensured by the proposed new method for enhancing user plane security for VN groups. Otherwise, relying solely on manual work to ensure that all PDU sessions associated with a specific VN (such as 5G LAN) group have the same user plane security configuration would be time-consuming and laborious. The embodiments herein are not limited to the above features and advantages. Those skilled in the art will recognize additional features and advantages after reading the following detailed description.

[0462] Figure 8a is a block diagram showing an apparatus suitable for practicing some embodiments of the present disclosure. For example, any one of the above open functions, data management nodes, application nodes, network management nodes, data repository nodes, or session management functions can be implemented as or by apparatus 800.

[0463] The apparatus 800 includes at least one processor 821, such as a digital processor (DP), and at least one memory (MEM) 822 coupled to the processor 821. The apparatus 800 may further include a transmitter TX and a receiver RX 823 coupled to the processor 821. The MEM 822 stores a program (PROG) 824. The PROG 824 may include instructions that, when executed on the relevant processor 821, cause the apparatus 800 to operate in accordance with embodiments of the present disclosure. The combination of the at least one processor 821 and the at least one MEM 822 may form a processing device 825 adapted to implement various embodiments of the present disclosure.

[0464] Various embodiments of the present disclosure may be implemented by a computer program executable by the processor 821, software, firmware, hardware, or a combination of one or more of them.

[0465] The MEM 822 may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory, as non-limiting examples.

[0466] The processor 821 may be of any type suitable for the local technical environment and may include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture, as non-limiting examples.

[0467] In embodiments where the apparatus is implemented as an open function or at an open function, the memory 822 stores instructions executable by the processor 821, whereby the open function operates in accordance with any method related to the open function as described above.

[0468] In embodiments where the apparatus is implemented as a data management node or at a data management node, the memory 822 stores instructions executable by the processor 821, whereby the data management node operates in accordance with any method related to the data management node as described above.

[0469] In embodiments where the apparatus is implemented as an application node or at an application node, the memory 822 stores instructions executable by the processor 821, whereby the application node operates in accordance with any method related to the application node as described above.

[0470] In embodiments where the apparatus is implemented as a network management node or at a network management node, the memory 822 stores instructions executable by the processor 821, whereby the network management node operates in accordance with any method related to the network management node as described above.

[0471] In an embodiment where the apparatus is implemented as a data repository node or is implemented at a data repository node, the memory 822 stores instructions that can be executed by the processor 821, whereby the data repository node operates according to any of the methods related to the data repository node as described above.

[0472] In an embodiment where the apparatus is implemented as a session management function or is implemented at a session management function, the memory 822 stores instructions that can be executed by the processor 821, whereby the session management function operates according to any of the methods related to the session management function as described above.

[0473] Figure 8b is a block diagram showing an open function according to an embodiment of the present disclosure. As shown, the open function 830 may include a receiving module 831 configured to receive a first message including at least one parameter to be created or updated from an application node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The open function 830 may further include a sending module 832 configured to send a second message including at least one parameter to be created or updated to a data management node or a data repository node.

[0474] Figure 8c is a block diagram showing a data management node according to an embodiment of the present disclosure. As shown, the data management node 840 may include a first receiving module 841 configured to receive a second message including at least one parameter to be created or updated from an open function or an application function (AF). The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The data management node 840 may further include a first sending module 842 configured to send a third message including at least one parameter to be created or updated to a data repository node.

[0475] In an embodiment, the data management node 840 may further include a second receiving module 843 configured to receive a first request for retrieving shared data for a VN group from a session management function.

[0476] In an embodiment, the data management node 840 may further include a second sending module 844 configured to send a second request for retrieving shared data for a VN group to a data repository node.

[0477] In an embodiment, the data management node 840 may further include a third receiving module 845 configured to receive a second response including shared data for a VN group from a data repository node.

[0478] In an embodiment, the data management node 840 may further include a third sending module 846, which is configured to send a first response including shared data for the VN group to the session management function. The shared data for the VN group may include UP security information for the VN group.

[0479] In an embodiment, the data management node 840 may further include a fourth receiving module 847, which is configured to receive a third request from the session management function for subscribing to data change notifications for the VN group.

[0480] In an embodiment, the data management node 840 may further include a fourth sending module 848, which is configured to send a fourth request for subscribing to data change notifications for the VN group to the data repository node.

[0481] In an embodiment, the data management node 840 may further include a fifth receiving module 849-1, which is configured to receive a first data change notification message including UP security information for the VN group from the data repository node.

[0482] In an embodiment, the data management node 840 may further include a fifth sending module 849-2, which is configured to send a second data change notification message including UP security information for the VN group to the session management function.

[0483] Figure 8d is a block diagram showing an application node according to an embodiment of the present disclosure. As shown, the application node 850 may include a sending module 851, which is configured to send a first message including at least one parameter to be created or updated to an open function or a data management node or a data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0484] Figure 8e is a block diagram showing a network management node according to an embodiment of the present disclosure. As shown, the network management node 860 may include a sending module 861, which is configured to send a fourth message including at least one parameter to be created or updated to the data repository node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group.

[0485] Figure 8fIt is a block diagram showing a data repository node according to an embodiment of the present disclosure. As shown, the data repository node 870 may include a first receiving module 871 configured to receive a message including at least one parameter to be created or updated from a data management node, an open function or application node, or a network management node. The at least one parameter to be created or updated may include user plane (UP) security information for a virtual network (VN) group. The data repository node 870 may also include a first storage module 872 configured to store the at least one parameter to be created or updated.

[0486] In an embodiment, the data repository node 870 may also include a first allocation module 873 configured to allocate an internal group identifier (ID) if no internal group identifier is allocated for the VN group identified by an external group ID.

[0487] In an embodiment, the data repository node 870 may also include a second storage module 874 configured to store a mapping between the internal group ID and the external group ID.

[0488] In an embodiment, the data repository node 870 may also include a second allocation module 875 configured to allocate a shared data ID for the VN group data.

[0489] In an embodiment, the data repository node 870 may also include an association module 876 configured to associate session management data with the internal group ID and the shared data ID for each member of the VN group.

[0490] In an embodiment, the data repository node 870 may also include a second receiving module 877 configured to receive a request for retrieving shared data for the VN group from a data management node or a session management function.

[0491] In an embodiment, the data repository node 870 may also include a first sending module 878 configured to send a response including the shared data for the VN group to a data management node or a session management function. The shared data for the VN group may include UP security information for the VN group.

[0492] In an embodiment, the data repository node 870 may also include a third receiving module 879-1 configured to receive a request for subscribing to data change notifications for the VN group from a data management node or a session management function.

[0493] In an embodiment, the data repository node 870 may also include a second sending module 879-2 configured to send a data change notification message to a data management node or a session management function. The data change notification message may include UP security information for the VN group.

[0494] Figure 9 is a block diagram showing a session management function according to an embodiment of the present disclosure. As shown, the session management function 900 may include a first sending module 901 configured to send a request for retrieving shared data for a VN group to a data management node or a data repository node. The session management function 900 may also include a first receiving module 902 configured to receive a response including shared data for the VN group from the data management node or the data repository node. The shared data for the VN group may include UP security information for the VN group.

[0495] In an embodiment, the session management function 900 may also include a second sending module 903 configured to send a request for subscribing to data change notifications for a VN group to the data management node or the data repository node.

[0496] In an embodiment, the session management function 900 may also include a second receiving module 904 configured to receive a data change notification message from the data management node or the data repository node. The data change notification message may include UP security information for the VN group.

[0497] In an embodiment, the session management function 900 may also include a determination module 905 configured to determine whether a protocol data unit (PDU) session establishment is for individual-level communication or for group-level communication.

[0498] In an embodiment, the session management function 900 may also include a second sending module 906 configured to, when the PDU session establishment is for group-level communication, set the same user plane security data from the UP security information for the VN group into a PDU session request to a radio access network through an access and mobility management function.

[0499] The terms unit or module may have a conventional meaning in the field of electronics, electrical equipment, and / or electronic devices and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, outputs, and / or display functions, and the like, such as those described herein.

[0500] Using functional units, an open function, a data management node, an application node, a network management node, a data storage node, or a session management function may not require a fixed processor or memory, and any computing resources and storage resources may be arranged from the open function, the data management node, the application node, the network management node, the data storage node, or the session management function in a communication system. The introduction of virtualization technology and network computing technology can improve the use efficiency of network resources and the flexibility of the network.

[0501] According to one aspect of the present disclosure, there is provided a computer program product tangibly stored on a computer-readable storage medium and including instructions that, when executed on at least one processor, cause the at least one processor to perform any of the above methods.

[0502] According to one aspect of the present disclosure, there is provided a computer-readable storage medium storing instructions that, when executed on at least one processor, cause the at least one processor to perform any of the above methods.

[0503] In addition, the present disclosure may also provide a carrier containing the above computer program, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer-readable storage medium. The computer-readable storage medium may be, for example, an optical disc or an electronic storage device such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, magnetic tape, CD-ROM, DVD, Blu-ray disc, etc.

[0504] The techniques described herein may be implemented in various ways such that an apparatus that implements one or more functions of the corresponding apparatus described by the embodiments includes not only components of the prior art but also components for implementing one or more functions of the corresponding apparatus described by the embodiments, and it may include separate components for each individual function or may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses), firmware (one or more apparatuses), software (one or more modules), or a combination thereof. For firmware or software, the implementation may be accomplished by modules (e.g., procedures, functions, etc.) that perform the functions described herein.

[0505] The exemplary embodiments herein have been described with reference to block diagrams and flowcharts of methods and apparatuses. It will be understood that each block of the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented by various components including computer program instructions. These computer program instructions can be loaded onto a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, so that the instructions executed on the computer or other programmable data processing device create components for implementing the functions specified in the flowchart block or blocks.

[0506] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order, or that all of the illustrated operations be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Also, although several specific implementation details are included in the above discussion, these should not be construed as limitations on the scope of the subject matter described herein, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination.

[0507] Although this specification contains many specific implementation details, these should not be construed as limitations on the scope of any implementation or of what may be claimed, but rather as descriptions of features that may be specific to particular embodiments of a particular implementation. Certain features that are described in the context of separate embodiments in this specification may also be implemented in combination in a single embodiment. Conversely, the various features that are described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although the above features may be described as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination may in some cases be excluded from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.

[0508] It will be apparent to those skilled in the art that, as technology advances, the inventive concept can be implemented in various ways. The above embodiments are given for purposes of illustration and not limitation, and it should be understood that modifications and variations can be made without departing from the spirit and scope of the present disclosure, as will be readily understood by those skilled in the art. Such modifications and variations are considered to be within the scope of the present disclosure and the appended claims. The scope of protection of the present disclosure is defined by the appended claims.

Claims

1. A method (300) performed by an open function, comprising: receiving (302) a first message from an application node, the first message including at least one parameter to be created or updated, wherein the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group; and sending (304) a second message including the at least one parameter to be created or updated to a data management node or a data repository node.

2. The method according to claim 1, wherein, the VN group includes a fifth-generation VN group.

3. The method according to claim 1 or 2, wherein, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

4. The method according to any one of claims 1 - 3, wherein, the UP security information for the VN group includes at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

5. The method according to any one of claims 1 - 4, wherein, the first message includes at least one of the following: a parameter provision creation request, or a parameter provision update request.

6. The method according to any one of claims 1 - 5, wherein, the second message includes at least one of the following: a parameter provision creation request, or a parameter provision update request.

7. The method according to any one of claims 1 - 6, wherein, the application node includes at least one of the following: an application function (AF), a service capability server (SCS), or an application server (AS).

8. The method according to any one of claims 1 - 7, wherein, the data management node includes a unified data management (UDM), and / or the data repository node includes a home subscriber server (HSS) or a home location register (HLR).

9. The method according to any one of claims 1 - 8, wherein, the open function includes at least one of the following: a service capability exposure function (SCEF), a network exposure function (NEF), or an SCEF combined with an NEF.

10. A method (400) performed by a data management node, comprising: receiving (402) a second message from an open function or an application function (AF), the second message including at least one parameter to be created or updated, wherein the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group; and sending (404) a third message including the at least one parameter to be created or updated to a data repository node.

11. The method according to claim 10, wherein, the VN group includes a fifth-generation VN group.

12. The method according to claim 10 or 11, wherein, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

13. The method according to any one of claims 10 - 12, wherein, The UP security information for the VN group includes at least one of the following: An information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or An information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

14. The method according to any one of claims 10-13, wherein, The second message includes at least one of the following: A parameter provision creation request, or A parameter provision update request.

15. The method according to any one of claims 10-14, wherein, The third message includes at least one of the following: A data management creation request, or A data management update request.

16. The method according to any one of claims 10-15, wherein, The data repository node includes a Unified Data Repository (UDR).

17. The method according to any one of claims 10-16, wherein, The data management node includes a Unified Data Management (UDM).

18. The method according to any one of claims 10-17, wherein, The open function includes a Network Exposure Function (NEF).

19. The method according to any one of claims 10-18, further comprising: Receiving (412) a first request from a session management function to retrieve shared data for the VN group; Sending (414) a second request to the data repository node to retrieve shared data for the VN group; Receiving (416) a second response from the data repository node including the shared data for the VN group; and Sending (418) a first response including the shared data for the VN group to the session management function, wherein the shared data for the VN group includes the UP security information for the VN group.

20. The method according to any one of claims 10-19, further comprising: Receiving (422) a third request from a session management function to subscribe to data change notifications for the VN group; Sending (424) a fourth request to the data repository node to subscribe to data change notifications for the VN group; Receiving (426) a first data change notification message including the UP security information for the VN group from the data repository node; and Sending (428) a second data change notification message including the UP security information for the VN group to the session management function.

21. A method (500) performed by an application node, comprising: Sending (502) a first message including at least one parameter to be created or updated to an open function or a data management node or a data repository node, wherein the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group.

22. The method according to claim 21, wherein, The VN group includes a 5G VN group.

23. The method according to claim 21 or 22, wherein, The UP security information for the VN group indicates that the same UP security is applied to the VN group.

24. The method according to any one of claims 21 - 23, wherein, the UP security information for the VN group includes at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

25. The method according to any one of claims 21 - 24, wherein, the first message includes at least one of the following: a parameter providing a creation request, or a parameter providing an update request.

26. The method according to any one of claims 21 - 25, wherein, the application node includes at least one of the following: an application function (AF), a service capability server (SCS), or an application server (AS).

27. The method according to any one of claims 21 - 26, wherein, the open function includes at least one of the following: a service capability exposure function (SCEF), a network exposure function (NEF), or an SCEF combined with the NEF.

28. The method according to any one of claims 21 - 27, wherein, the data repository node includes at least one of the following: a home subscriber server (HSS), or a home location register (HLR).

29. The method according to any one of claims 21 - 28, wherein, the data management node includes a unified data management (UDM).

30. A method (600) performed by a network management node, comprising: sending (602) a fourth message including at least one parameter to be created or updated to a data repository node, wherein the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group.

31. The method according to claim 30, wherein, the VN group includes a 5G VN group.

32. The method according to claim 30 or 31, wherein, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

33. The method according to any one of claims 30 - 32, wherein, the UP security information for the VN group includes at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

34. The method according to any one of claims 30 - 33, wherein, the fourth message includes at least one of the following: a parameter providing a creation request, or a parameter providing an update request.

35. The method according to any one of claims 30 - 34, wherein, the network management node includes a communication service provider (CSP) providing system.

36. The method according to any one of claims 30 - 35, wherein, The data repository node includes a Unified Data Repository (UDR), a Home Subscriber Server (HSS), or a Home Location Register (HLR).

37. A method (610) performed by a data repository node, comprising: receiving (612) from a data management node, an open function, an application node, or a network management node, a message including at least one parameter to be created or updated, wherein the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group; and storing (614) the at least one parameter to be created or updated.

38. The method according to claim 37, wherein, the VN group includes a 5G VN group.

39. The method according to claim 37 or 38, wherein, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

40. The method according to any one of claims 37 - 39, wherein, the UP security information for the VN group includes at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit (PDU) session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on a PDU session.

41. The method according to any one of claims 37 - 40, wherein, the message includes at least one of the following: a data management create request, or a data management update request.

42. The method according to any one of claims 37 - 41, wherein, the data repository node includes at least one of the following: a Home Subscriber Server (HSS), a Home Location Register (HLR), or a Unified Data Repository (UDR).

43. The method according to any one of claims 37 - 42, wherein, the data management node includes a Unified Data Management (UDM).

44. The method according to any one of claims 37 - 43, wherein, the open function includes at least one of the following: a Service Capability Exposure Function (SCEF), a Network Exposure Function (NEF), or an SCEF combined with an NEF.

45. The method according to any one of claims 37 - 44, wherein, the application node includes at least one of the following: an Application Function (AF), a Service Capability Server (SCS), or an Application Server (AS).

46. The method according to any one of claims 37 - 45, wherein, the network management node includes a CSP-provided system.

47. The method according to any one of claims 37 - 46, further comprising: allocating (622) an internal group identifier if no internal group identifier is assigned to the VN group identified by an external group identifier ID; storing (624) a mapping between the internal group ID and the external group ID; allocating (626) a shared data ID for the VN group data; and associating (628) session management data with the internal group ID and the shared data ID for each member of the VN group.

48. The method according to any one of claims 37 - 47, further comprises: receiving (632) from a data management node or a session management function a request for retrieving shared data for the VN group; and sending (634) to the data management node or the session management function a response including the shared data for the VN group, wherein the shared data for the VN group includes the UP security information for the VN group.

49. The method according to any one of claims 37 - 48, further comprises: receiving (642) from a data management node or a session management function a request for subscribing to data change notifications for the VN group; and sending (644) to the data management node or the session management function a data change notification message, wherein the data change notification message includes the UP security information for the VN group.

50. A method (650) performed by a session management function, comprises: sending (652) to a data management node or a data repository node a request for retrieving shared data for a VN group; and receiving (654) from the data management node or the data repository node a response including the shared data for the VN group; wherein the shared data for the VN group includes the UP security information for the VN group.

51. The method according to claim 50, further comprises: sending (662) to the data management node or the data repository node a request for subscribing to data change notifications for the VN group; and receiving (664) from the data management node or the data repository node a data change notification message, wherein the data change notification message includes the UP security information for the VN group.

52. The method according to claim 50 or 51, further comprises: determining (672) whether a protocol data unit PDU session establishment is for individual - level communication or for group - level communication; and when the PDU session establishment is for the group - level communication, setting (674) the same user plane security data from the UP security information for the VN group into a PDU session request to a radio access network.

53. The method according to any one of claims 50 - 52, wherein, the VN group includes a fifth - generation VN group.

54. The method according to any one of claims 50 - 53, wherein, the UP security information for the VN group indicates that the same UP security is applied to the VN group.

55. The method according to any one of claims 50 - 54, wherein, the UP security information for the VN group includes at least one of the following: an information element indicating whether UP integrity protection is required, preferred, or not required for traffic on a protocol data unit PDU session, or an information element indicating whether UP confidentiality protection is required, preferred, or not required for traffic on the PDU session.

56. The method according to any one of claims 50 - 55, wherein, The data repository node includes at least one of the following: a home subscriber server HSS, or a home location register HLR.

57. The method according to any one of claims 50-56, wherein, the data management node includes a unified data management UDM.

58. An open function (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the open function (800) is operable to: receive, from an application node, a first message including at least one parameter to be created or updated, wherein the at least one parameter to be created or updated includes user plane UP security information for a virtual network VN group; and send, to a data management node or a data repository node, a second message including the at least one parameter to be created or updated.

59. The open function according to claim 58, wherein, the open function is further operable to perform the method according to any one of claims 2 to 9.

60. A data management node (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the data management node (800) is operable to: receive, from an open function or an application function AF, a second message including at least one parameter to be created or updated, wherein the at least one parameter to be created or updated includes user plane UP security information for a virtual network VN group; and send, to a data repository node, a third message including the at least one parameter to be created or updated.

61. The data management node according to claim 60, wherein, the data management node is further operable to perform the method according to any one of claims 11 to 20.

62. An application node (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the application node (800) is operable to: send, to an open function or a data management node or a data repository node, a first message including at least one parameter to be created or updated, wherein the at least one parameter to be created or updated includes user plane UP security information for a virtual network VN group.

63. The application node according to claim 62, wherein, the application node is further operable to perform the method according to any one of claims 22 to 29.

64. A network management node (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the network management node (800) is operable to: Send a fourth message including at least one parameter to be created or updated to a data repository node, where the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group.

65. The network management node according to claim 64, wherein the network management node is further operable to perform the method according to any one of claims 31 to 36.

66. A data repository node (800) comprising: a processor (821) ; and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the data repository node (800) is operable to: receive a message including at least one parameter to be created or updated from a data management node, or an open function or application node, or a network management node, where the at least one parameter to be created or updated includes user plane (UP) security information for a virtual network (VN) group; and store the at least one parameter to be created or updated.

67. The data repository node according to claim 66, wherein the data repository node is further operable to perform the method according to any one of claims 38 to 49.

68. A session management function (800), comprising: a processor (821); and a memory (822) coupled to the processor (821), the memory (822) storing instructions executable by the processor (821), whereby the session management function (800) is operable to: send a request for retrieving shared data for a VN group to a data management node or a data repository node; and receive a response including the shared data for the VN group from the data management node or the data repository node; where the shared data for the VN group includes UP security information for the VN group.

69. The session management function according to claim 68, wherein the session management function is further operable to perform the method according to any one of claims 51 to 57.

70. A computer-readable storage medium storing instructions that, when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 57.

71. A computer program product comprising instructions that, when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 57.

Citation Information

Cited By

  • Virtual network group control management method and system based on 6G mobile communication

    CN120499028A