IP endpoint discovery without using DNS

By using the 3gpp-Sbi-IpEndpoints-Info header in the HTTP header, the problem of DNS search query dependency in the prior art is solved, and the ability to operate network without DNS is realized, and the request success rate is improved.

CN120165895APending Publication Date: 2025-06-17NOKIA NETWORKS OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411828966.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-14
Filing Date
2024-12-12
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing technology has dependence on DNS lookup queries during IP endpoint discovery, resulting in the inability to operate normally in some deployment environments, such as in operator deployments that do not use DNS servers, or in situations where multi-IP address support is required but DNS resolution cannot be used.

Method used

By using the 3gpp-Sbi-IpEndpoints-Info header in the HTTP header, containing multiple authorized IP endpoint information, DNS lookup queries are avoided and network operations are allowed without DNS.

Benefits of technology

The ability to operate network without DNS is realized, the request success rate in indirect communication is improved, and the limitation of DNS search query is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165895A_ABST
    Figure CN120165895A_ABST
Patent Text Reader

Abstract

The invention discloses IP endpoint discovery without using DNS. A method for communication includes receiving, at a second network function, an incoming message including information that a resource is created or updated or will be used for callback at a first network function, the resource is identified by each of a first uniform resource identifier and a second uniform resource identifier, the first uniform resource identifier comprising a scheme, a path, and a first authorization, and the second uniform resource identifier comprising a scheme, a path, and a second authorization different from the first authorization; an outgoing message related to the resource is sent from the second network function to the first network function, where the resource is identified by each of the first and second uniform resource identifiers in the outgoing message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various example embodiments of the present disclosure relate to discovery, and more specifically (but not exclusively) to IP endpoint discovery.

[0002] Abbreviation

[0003] 3GPP Third Generation Partnership Project

[0004] 5G / 6G / 7G Fifth Generation / Sixth Generation / Seventh Generation

[0005] 5GC Fifth Generation Core (Network)

[0006] AMF Access and Mobility Function

[0007] DDNS Dynamic DNS

[0008] DNS Domain Name Server

[0009] FQDN Fully Qualified Domain Name

[0010] HTTP Hypertext Transfer Protocol

[0011] IETF Internet Engineering Task Force

[0012] IP Internet Protocol

[0013] JSON JavaScript Object Notation

[0014] NF Network Function

[0015] NRF Network Repository Function

[0016] OWS Optional White Space

[0017] PDU Protocol Data Unit

[0018] RFC Request for Comments

[0019] RWS Required White Space

[0020] SBI Service-Based Interface

[0021] SCP Service Communication Proxy

[0022] SEPP Secure Edge Protection Proxy

[0023] SMF Session Management Function

[0024] SNI Server Name Indication

[0025] TLS Transport Layer Security

[0026] TS Technical Specification

[0027] UE User Equipment

[0028] URI Uniform Resource Identifier Background Art

[0029] A communication system can be regarded as a facility that enables a communication session between two or more entities (such as communication devices, base stations, and / or other nodes) by providing a carrier between various entities involved in the communication path.

[0030] The communication system can be a wireless communication system. Examples of wireless systems include PLMNs operating based on radio standards (such as the standards provided by 3GPP), satellite-based communication systems, and different wireless local area networks. For example, a wireless local area network can be implemented as a WLAN. Wireless systems can generally be divided into cells and are therefore often referred to as cellular systems.

[0031] Communication systems and related devices generally operate according to a given standard or specification that defines what the various entities associated with the system are allowed to do and how they should be implemented. Communication protocols and / or parameters that should be used for connections are also usually defined. An example of a set of standards is the so-called 5G standard. Summary of the Invention

[0032] Various example embodiments of the present disclosure are directed to solving at least some of the problems and / or issues and disadvantages explicitly described herein or otherwise apparent to those skilled in the relevant art, to provide methods, apparatuses, and computer programs that can be used to improve mechanisms and / or processes for discovery (such as IP endpoint discovery).

[0033] Various example embodiments will be described with respect to certain aspects. These aspects are not intended to indicate the key or fundamental features of the various example embodiments, nor are they intended to otherwise limit the scope of the present disclosure. Given the present disclosure, other features, aspects, and elements of the various example embodiments will be apparent to those skilled in the art.

[0034] According to a first aspect, there is provided an apparatus comprising:

[0035] One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the apparatus to perform at least:

[0036] Create or update a resource at a first network function, where each uniform resource identifier in a set of uniform resource identifiers identifies the resource, each uniform resource identifier in the set of uniform resource identifiers includes a scheme, a path, and a corresponding authorization, and for each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other uniform resource identifier in the corresponding pair;

[0037] Provide a message from the first network function to the second network function, the message including information that the resource has been created or updated, where in the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identify the resource, the first uniform resource identifier includes a first authorization, the message includes a second authorization different from the first authorization, and a second uniform resource identifier in the set of uniform resource identifiers that identify the resource includes the second authorization.

[0038] According to a second aspect, there is provided an apparatus, the apparatus comprising:

[0039] One or more processors, and a memory storing instructions that, when executed by the one or more processors, cause the apparatus to at least perform:

[0040] Provide a message from the first network function to the second network function, the message including information that a resource of the first network function will be used for a callback, where,

[0041] Each uniform resource identifier in a set of uniform resource identifiers identifies the resource,

[0042] Each uniform resource identifier in the set of uniform resource identifiers includes a scheme, a path, and a corresponding authorization,

[0043] For each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other uniform resource identifier in the corresponding pair;

[0044] In the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identify the resource,

[0045] The first uniform resource identifier includes a first authorization,

[0046] The message includes a second authorization different from the first authorization, and

[0047] A second uniform resource identifier in the set of uniform resource identifiers that identify the resource includes the second authorization.

[0048] According to a third aspect, there is provided an apparatus, the apparatus comprising:

[0049] one or more processors, and a memory storing instructions which, when executed by the one or more processors, cause the apparatus to at least perform:

[0050] receiving, at a second network function, an incoming message that includes information that a resource has been created or updated at a first network function or will be used for a callback, wherein, in the incoming message, the resource is identified by each of a first uniform resource identifier and a second uniform resource identifier, the first uniform resource identifier includes a scheme, a path, and a first authorization, and the second uniform resource identifier includes the scheme, the path, and a second authorization different from the first authorization;

[0051] sending, from the second network function to the first network function, an outgoing message related to the resource, wherein, in the outgoing message, the resource is identified by each of a first uniform resource identifier and a second uniform resource identifier.

[0052] According to a fourth aspect, there is provided a method, the method comprising:

[0053] creating or updating a resource at a first network function, wherein each uniform resource identifier in a set of uniform resource identifiers identifies the resource, each uniform resource identifier in the set of uniform resource identifiers includes a scheme, a path, and a corresponding authorization, and for each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other of the two uniform resource identifiers in the corresponding pair;

[0054] providing, from the first network function to a second network function, a message that includes information that the resource has been created or updated, wherein, in the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identifies the resource, the first uniform resource identifier includes a first authorization, the message includes a second authorization different from the first authorization, and a second uniform resource identifier in the set of uniform resource identifiers that identifies the resource includes the second authorization.

[0055] According to a fifth aspect, there is provided a method, the method comprising:

[0056] providing, from a first network function to a second network function, a message that includes information that a resource of the first network function will be used for a callback, wherein,

[0057] each uniform resource identifier in a set of uniform resource identifiers identifies the resource,

[0058] Each uniform resource identifier in the set of uniform resource identifiers includes a scheme, a path, and corresponding authorization,

[0059] For each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other uniform resource identifier in the corresponding pair;

[0060] In the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identifies the resource,

[0061] The first uniform resource identifier includes a first authorization,

[0062] The message includes a second authorization different from the first authorization, and

[0063] A second uniform resource identifier in the set of uniform resource identifiers that identifies the resource includes the second authorization.

[0064] According to a sixth aspect, a method is provided, the method comprising:

[0065] Receiving, at a second network function, an incoming message that includes information that a resource has been created or updated at a first network function or will be used for a callback, wherein in the incoming message, the resource is identified by each of a first uniform resource identifier and a second uniform resource identifier, the first uniform resource identifier includes a scheme, a path, and a first authorization, and the second uniform resource identifier includes a scheme, a path, and a second authorization different from the first authorization;

[0066] Sending, from the second network function to the first network function, an outgoing message related to the resource, wherein in the outgoing message, the resource is identified by each of the first uniform resource identifier and the second uniform resource identifier.

[0067] According to each of the first aspect, the second aspect, the fourth aspect, or the fifth aspect, the following items can be applied to:

[0068] Each authorization in the authorizations included by the uniform resource identifiers in the set of uniform resource identifiers that identify the resource may include a corresponding host part, and each host part in the host parts may include: a fully qualified domain name of the resource, or a corresponding Internet protocol address of the resource.

[0069] At least one authorization in the authorizations included by the uniform resource identifiers in the set of uniform resource identifiers that identify the resource may include a corresponding port of the resource.

[0070] One of the first authorization and the second authorization may have a host part that is an Internet Protocol version 4 address, and the other of the first authorization and the second authorization may have a host part that is an Internet Protocol version 6 address.

[0071] The first authorization and the second authorization may be included in the header of the message.

[0072] The message may include a header and a body. One of the first authorization and the second authorization may be included in the header of the message, and the other of the first authorization and the second authorization may be included in the body.

[0073] The message may be a Hypertext Transfer Protocol message.

[0074] In addition to the first authorization and the second authorization, the message may further include one or more alternative authorizations, and for each of the one or more alternative authorizations, the corresponding Uniform Resource Identifier in the set of Uniform Resource Identifiers identifying the resource may include the corresponding authorization.

[0075] According to each of the third aspect or the sixth aspect, the following may apply: Each of the first authorization and the second authorization may include a corresponding host part, and each of these host parts may include: the fully qualified domain name of the resource, or the corresponding Internet Protocol address of the resource.

[0076] At least one of the first authorization and the second authorization may include the corresponding port of the resource.

[0077] One of the first authorization and the second authorization may have a host part that includes an Internet Protocol version 4 address, and the other of the first authorization and the second authorization may have a host part that includes an Internet Protocol version 6 address.

[0078] The first authorization and the second authorization may be included in the header of the incoming message.

[0079] The incoming message may include a header and a body. One of the first authorization and the second authorization may be included in the header of the incoming message, and the other of the first authorization and the second authorization may be included in the body of the incoming message.

[0080] The incoming message may be received from a first network function.

[0081] The information may be a configuration file of the first network function, and the configuration file may include the first authorization and the second authorization.

[0082] The first authorization and the second authorization may be included in the header of the outgoing message.

[0083] The outgoing message may include a header and a body, one of the first authorization and the second authorization may be included in the header of the outgoing message, and the other authorization of the first authorization and the second authorization may be included in the body of the outgoing message.

[0084] In the header of the incoming message, the source uniform resource identifier may indicate the source of the incoming message; in the header of the outgoing message, the destination uniform resource identifier may indicate the destination of the outgoing message; the source uniform resource identifier may be one of the first uniform resource identifier and the second uniform resource identifier; the destination uniform resource identifier may be one of the first uniform resource identifier and the second uniform resource identifier.

[0085] The destination uniform resource identifier may be different from the source uniform resource identifier.

[0086] According to a third aspect, the authorization included by the source uniform resource identifier may be the fully qualified domain name of the resource; and when executed by the one or more processors, the instruction may further cause the device to at least perform:

[0087] Determine the destination uniform resource identifier based on the incoming message;

[0088] Prohibit the second network function from resolving the authorization of the source uniform resource identifier by querying the domain name server for obtaining the authorization included by the destination uniform resource identifier.

[0089] According to a sixth aspect, the authorization included by the source uniform resource identifier may be the fully qualified domain name of the resource; and the method may further include:

[0090] Determine the destination uniform resource identifier based on the incoming message;

[0091] Prohibit the second network function from resolving the authorization of the source uniform resource identifier by querying the domain name server for obtaining the authorization included by the destination uniform resource identifier.

[0092] · The incoming message may be a Hypertext Transfer Protocol message.

[0093] · The outgoing message may be a Hypertext Transfer Protocol message.

[0094] · The type of the incoming message may be the same as the type of the outgoing message.

[0095] · The type of the incoming message may be different from the type of the outgoing message.

[0096] · The type of the incoming message may be a request, and the type of the outgoing message may be a response.

[0097] · The type of the incoming message can be a response, and the type of the outgoing message can be a request.

[0098] · In addition to the first authorization and the second authorization, the incoming message can also include one or more alternative authorizations, and for each of the one or more alternative authorizations, in the incoming message, the resource is identified by a corresponding uniform resource identifier including a scheme, a path, and the corresponding alternative authorization.

[0099] According to each of the fourth to sixth aspects, the method can be a method for IP endpoint discovery.

[0100] According to the seventh aspect, there is provided a computer program product including an instruction set which, when executed by a device, is configured to cause the device to execute the method according to any one of the fourth aspect or the fifth aspect or the sixth aspect. The computer program product can be embodied as a computer-readable medium or directly loadable into a computer.

[0101] Above, various aspects have been described. It should be understood that other aspects can be provided by any combination of two or more of the above-described aspects.

[0102] Various other aspects are also described in the following detailed description and claims.

[0103] According to some aspects, the subject matter of the independent claims is provided. Some additional aspects are defined in the dependent claims. Example embodiments that do not fall within the scope of the claims, if any, will be construed as helpful in understanding the examples of the present disclosure.

[0104] According to some example embodiments, any one or more of the following advantages can be achieved: · DNS lookup queries can be avoided;

[0105] · The network can operate without DNS;

[0106] · The success rate of requests in indirect communication is higher.

[0107] Through the present disclosure, additional details, features, and advantages will be apparent to those skilled in the relevant art. BRIEF DESCRIPTION OF THE DRAWINGS

[0108] Some example embodiments will be described in more detail by way of non-limiting and illustrative examples with reference to the accompanying drawings, in which:

[0109] Figure 1 A message flow according to some example embodiments is shown;

[0110] Figure 2 A message flow according to some example embodiments is shown;

[0111] Figure 3 shows a message flow according to some example embodiments;

[0112] Figure 4 shows a message flow according to some example embodiments;

[0113] Figure 5 shows an apparatus according to an example embodiment;

[0114] Figure 6 shows a method according to some example embodiments;

[0115] Figure 7 shows an apparatus according to an example embodiment;

[0116] Figure 8 shows a method according to an example embodiment;

[0117] Figure 9 shows an apparatus according to an example embodiment;

[0118] Figure 10 shows a method according to an example embodiment; and

[0119] Figure 11 shows an apparatus according to an example embodiment. DETAILED DESCRIPTION

[0120] In the following, various example embodiments of the present disclosure are explained with reference to a mobile communication device capable of communicating via a wireless cellular system and a mobile communication system serving such a mobile communication device. Before explaining the various example embodiments in detail, certain general aspects of the wireless communication system and the mobile communication device are briefly explained for certain types of records and queries to help understand the various terms and technologies referred to in some example embodiments of the present disclosure.

[0121] A record or query may relate to a stored correlation between an IP name and an IPv4 address. For example, an A-query may be used to query a DNS for a domain name solution.

[0122] An AAAA record or AAAA query may relate to a stored correlation between an IP name and an IPv6 address. For example, an AAAA query may be used to query a DNS for a domain name solution.

[0123] An A / AAAA record and an A / AAAA query may relate to an A record and an A query and / or an AAAA record and an AAAA query, where in the respective context, it is irrelevant whether the record (query) is for an IPv4 or IPv6 address.

[0124] For example, the authorization of a URI that can be used in 5GC SBI can be an IP address or an FQDN address. Using an FQDN for authorization has certain benefits:

[0125] - An HTTP server (hereinafter sometimes only referred to as the "server") can have multiple IP addresses resolved to the same URI to improve redundancy (a form of "HTTP multi-homing"). - The server can be populated with a dual-stack IPv4 / IPv6 interface and allow peers to select the supported / preferred IP version.

[0126] - The FQDN is used as the Server Name Indication (SNI) for server authentication in TLS.

[0127] However, the FQDN must ultimately be resolved to its (multiple) IP. The NF consumer or SCP / SEPP can learn the IP associated with the FQDN in two ways:

[0128] - Resolve the IP via an A / AAAA DNS lookup query: This results in interacting with a DNS server for IP resolution, or a locally provided FQDN resolution file (e.g., a local DNS host file).

[0129] - Populate the FQDN and IP address within the NF profile registered in the NRF. Then, the NRF can learn the target URI via NFDiscovery.

[0130] Hereinafter, with reference to the accompanying drawings, various example embodiments will be described in more detail by non-limiting and illustrative examples.

[0131] If both the FQDN and one or more IP addresses for a peer are stored in the NRF, in several cases, another peer may not be able to learn the IP address if the URI includes the FQDN but not the IP address. Examples of such cases include:

[0132] · Via the HTTP Location header in an HTTP response,

[0133] · As a callback URI included in the JSON body of a subscription request, · A URI included in the JSON body for a service request / response (e.g., during UE mobility between AMFs or during PDU creation using an intermediate SMF), and · In the case of indirect communication, via the 3gpp-sbi-target-apiRoot HTTP header.

[0134]

[0135]

[0136] ​​More specifically, when the URI is provided by the NF in the HTTP location header or as a URI attribute in the JSON body, the sender must populate the authorization of the URI with the FQDN or IP.

[0137] Both of these approaches have limitations:

[0138] - To use the FQDN, the sender is configured with the logic for which the corresponding IP can be resolved by its peer. This may not be the case in deployments where the operator does not use a DNS server for IP resolution for non-roaming 5GC services. The main reasons for some operators to avoid using a DNS server are:

[0139] - Operational limitations: For example, using a new IP during horizontal scaling requires updating the DNS server entries (e.g., manually or via DDNS);

[0140] - Concerns that DNS failures / misconfigurations may cause a network-wide outage;

[0141] - The limitation that all IP endpoints must be provided with the same port (e.g., different ports cannot be used for different IPs).

[0142] - However, populating the authorization with an IP address is also problematic. In this case, alternative IPs cannot be populated to the peer. Therefore, since SNI requires an FQDN, TLS cannot be used.

[0143] Similar limitations also apply when using indirect communication via the SCP. In this case, the address of the final server (e.g., the owner of the authorization of the target URI address) is conveyed to the SCP via the 3gpp-sbi-target-apiRoot header. If the selected producer includes both an FQDN and an IP address in the NF profile registered in the NRF, the HTTP client must select an IP or an FQDN for the authorization of the 3gpp-sbi-target-apiRoot. This leads to problems similar to the above cases.

[0144] - If an FQDN is used, the last-hop SCP must resolve the IP via DNS, which may not always be feasible and may be the reason why the IP address appears in the NF profile in the first place.

[0145] - If an IP address is used, if the selected IP does not respond or operates with a different IP version (e.g., IPv4 vs. IPv6), the last-hop SCP cannot use alternative IP addresses that may be available. Additionally, this option is not compatible with TLS.

[0146] This problem is also related to the indirect communication (Model D) discovered by delegation. Although in this case, the SCP discovers / selects the producer in the initial request, in all subsequent requests, the consumer only sends the 3gpp-sbi-target-apiRoot to the SCP. Additionally, in a multi-hop SCP deployment, only the SCP that discovers the selected producer knows both the producer's FQDN and IP.

[0147] In some example embodiments, the HTTP header can include multiple authorizations (FQDN and / or IP address) for the same resource. For example, in addition to the source or destination address (which includes the authorization) included in the header, the header can also include an information element named 3gpp-Sbi-IpEndpoints-Info (as an example name), which can include additional authorizations. In an HTTP request or response, any authorization included in the header can be used to construct the URI. The URI can be located in the following:

[0148] - The Location HTTP header of the response;

[0149] - In the JSON body of a subscription request (e.g., the callback URI);

[0150] - In the JSON body of a service request or response;

[0151] - The 3gpp-sbi-target-apiRoot header in an indirect communication request or response.

[0152] This list of options is not exhaustive.

[0153] In addition to the authorization, the URI also includes at least the scheme and the path. The scheme and path of the resource are the same regardless of the selected authorization. The authorization includes the host part and can optionally include the port.

[0154] This information can be used by the HTTP client NF or the SCP to resolve the IP of the HTTP server without performing a DNS A / AAAA query.

[0155] In the absence of an FQDN, it is useful to use 3gpp-Sbi-IpEndpoints-Info to resolve an authorization that is already an IP, but the peer needs to provide both an IPv4 address and an IPv6 address or multiple IPv4 addresses, for example.

[0156] In some example embodiments, the 3gpp-Sbi-IpEndpoints-Info header can be implemented as follows:

[0157] 3gpp-Sbi-IpEndpoints-Info = "3gpp-Ip-Endpoints-Info:" OWSipEndpointsInfo *(";" OWS ipEndpointsInfo)

[0158] ipEndpointsInfo = authority "=" ipEndpoint "&" *(RWS "&" RWS ipEndpoint)

[0159] ipEndpoint = host [":" port]

[0160] (IP and optional port as defined in Section 3.2.2 of IETF RFC 3986)

[0161] authority = uri-host [":" port]

[0162] FQDN or IP with optional port as defined in Section 8.1.2.3 of IETF RFC 7540, excluding the [userinfo "@"] information defined in Section 3.2 of IETF RFC 3986. Example of FQDN authority resolved to two IP addresses and one IPv6 address: 3gpp-Sbi-IpEndpoints-Info:server1.example.com:80 = 10.10.1.1:80 & 20.20.2.2:80 & [2001:db8::1234:5678]:8080

[0163] Example of IPv4 authority with port resolved to an IPv6 address and port:

[0164] 3gpp-Sbi-IpEndpoints-Info:10.10.1.1:8080 = [2001:db8::1234:5678]:8080

[0165] Example of 3gpp-Sbi-IpEndpoints-Info with two authorities: 3gpp-Sbi-IpEndpoints-Info:server1.example.com:80 = 10.10.1.1:8080 & [2001:db8::1234:5678]:8080; callbackServer.host.com:8080 = 20.20.2.2:80

[0166] Note:

[0167] - According to the above implementation example, all alternative authorized IP endpoints (with optional ports) that can be used as URIs must be included as a single parameter. However, multiple parameters with different authorizations can exist in a single 3gpp-Sbi-IpEndpoints-Info header.

[0168] - According to the above implementation example, when the host part of the URI is an IP address (with optional port), it is not included again as one of the authorized values in the 3gpp-Sbi-IpEndpoints-Info header's authorized values, unless there are alternative authorizations with the same IP but different ports.

[0169] Alternative encoding

[0170] An alternative implementation is to populate this information as a new parameter in an existing information element of the HTTP header (e.g., as a new parameter in 3gpp-Sbi-Peer-Info).

[0171] Hereinafter, an HTTP header including additional authorizations as described above can be referred to as a 3gpp-Sbi-IpEndpoints-Info header, regardless of how the additional authorizations are encoded.

[0172] HTTP server NF behavior

[0173] HTTP response handling

[0174] In some example embodiments, the HTTP server can send a 3gpp-Sbi-IpEndpoints-Info header in 2xx success and 3xx redirect responses with a Location header. The Location header is a (standardized) HTTP header that provides a URI to a specific resource (e.g., see Section 7.1.2 of RFC 7231). The 3gpp-Sbi-IpEndpoints-Info header includes the (multiple) alternative IP endpoints authorized for the Location URI.

[0175] As another option according to some example embodiments, the HTTP server NF can send a 3gpp-Sbi-IpEndpoints-Info header in a 2xx success response where the JSON body includes a URI. The 3gpp-Sbi-IpEndpoints-Info includes the (multiple) alternative IP endpoints authorized for the relevant URI in the JSON body. If there are multiple URIs in the JSON body with different authorizations, only a subset of the information can be included.

[0176] HTTP request handling

[0177] In some example embodiments, the HTTP server NF may store the information of the 3gpp-Sbi-IpEndpoints-Info header included in the subscription request. This information can be used later to resolve the authorization of the callback URI when sending notifications.

[0178] As another option according to some example embodiments, the HTTP server NF may store the information of the 3gpp-Sbi-IpEndpoints-Info header included in a service request having a JSON body including a URI. This information can be used later to resolve the authorization of the URI referenced in the JSON body.

[0179] HTTP client NF behavior

[0180] HTTP response handling

[0181] In some example embodiments, the HTTP client NF may store the information of the 3gpp-Sbi-IpEndpoints-Info header included in 2xx and 3xx responses including a location header. This information can be used later to resolve the authorization of the URI of the NF peer server.

[0182] As another option according to some example embodiments, the HTTP client NF may store the information conveyed in the 3gpp-Sbi-IpEndpoints-Info header included in a service response having a JSON body including a URI. This information can be used later to resolve the authorization of the URI referenced in the JSON body.

[0183] HTTP request handling

[0184] In some example embodiments, the HTTP client NF may send the 3gpp-Sbi-IpEndpoints-Info header in a subscription request corresponding to the authorization of the related callback URI.

[0185] As another option according to some example embodiments, the HTTP client NF may send the 3gpp-Sbi-IpEndpoints-Info header in a service request having a JSON body including a URI. The gpp-Sbi-IpEndpoints-Info includes the (multiple) alternative IP endpoints resolved for the authorization of the related URI within the JSON body. If the JSON body has multiple URIs with different authorizations, the JSON body may include the information of all URIs or only the information of a subset of URIs.

[0186] URI authorization IP resolution

[0187] In some example embodiments, when the authorization of the target server is an FQDN, the HTTP client NF or SCP can use the previously stored 3gpp-Sbi-IpEndpoints-Info header to resolve the IP without performing DNS resolution. If the authorization in the URI is an IP, the HTTP client can use the 3gpp-Sbi-IpEndpoints-Info header to select an alternative IP of the same server (a form of HTTP multi-homing) before, for example, selecting an alternative server within the NF service set.

[0188] In the case of a request via indirect communication, the HTTP client NF can provide the 3gpp-Sbi-IpEndpoints-Info header and the 3gpp-sbi-target-apiRoot to allow the SCP to perform IP resolution / reselection and avoid DNS lookups.

[0189] Note: If the request is sent via indirect communication, the 3gpp-Sbi-IpEndpoints-Info can be included in the authorization referenced in the 3gpp-sbi-target-apiRoot and / or the JSON body.

[0190] For an initial request where no 3gpp-Sbi-IpEndpoints-Info is available, when both an FQDN and an IP or multiple IPs are included, the HTTP client can extract the IP address from the NF profile of the selected NF producer. In the case of indirect communication, the NF consumer can use this information to construct the 3gpp-Sbi-IpEndpoints-Info of the NF producer's address.

[0191] SCP Behavior

[0192] In the case of indirect communication, the SCP can use the 3gpp-Sbi-IpEndpoints-Info for IP resolution / reselection and avoid DNS lookups for the authorization included in the 3gpp-sbi-target-apiRoot.

[0193] In the case of indirect communication with delegated discovery, the SCP can construct the 3gpp-Sbi-IpEndpoints-Info based on the NF profile of the selected NF producer and send it to the next-hop SCP so that the last-hop SCP does not need to perform an NF profile lookup. If the received request already includes the 3gpp-Sbi-IpEndpoints-Info, the SCP can add this information as an additional authorization without removing the existing authorization.

[0194] Therefore, if the authorization in the location is the same and the server does not already include it, the SCP can construct 3gpp-Sbi-IpEndpoints-Info according to the NF profile of the selected producer and send it together with 3gpp-sbi-target-apiRoot in the response.

[0195] Figures 1 to 4 Some call flows are illustrated according to some example embodiments. Figure 1 The call flow in is as follows:

[0196] 1a + 1b: The consumer (via the SCP) sends a discovery request to the NRF.

[0197] 2a + 2b: In its response, the NRF (via the SCP) provides the NF profile to the consumer, and the NF profile includes both the FQDN and IP address as the authorization.

[0198] 3a: The consumer uses the FQDN in the service request ("POST") sent to the producer via the SCP. However, the consumer includes the IP address and port information (if available)

[0199] in 3gpp-Sbi-IpEndpoints-Info.

[0200]

[0201] 3b: The SCP can forward the request to the resource using any authorization indicated in the service request for the resource.

[0202] Figure 1 4a: According to the request, the producer can create another resource (or update an existing resource, not shown in ). The producer can reply to the SCP with a "201 Created" response, which includes the FQDN of the created resource and alternative IP endpoints.

[0203] 4b: The SCP forwards this information to the consumer.

[0204] 5a: The consumer sends a service request (e.g., "PATCH") related to the newly created resource to the producer via the SCP. The consumer includes the alternative IP address of the newly created resource in the HTTP header. Therefore, the SCP does not need to (and will not) perform DNS resolution.

[0205] 5b: The SCP forwards the service request from the consumer to the producer using one of the IP addresses in the IP address.

[0206] 5c: Due to a link failure, the producer does not receive the request from the consumer.

[0207] ​5d: Based on the 3gpp - Sbi - IpEndpoints - Info included in the service request from the consumer, the SCP selects another IP address to forward the service request. This time, the producer receives the service request.

[0208] 5e + 5f: The producer replies to the consumer via the SCP with a 204 response (e.g., the request was successfully processed; no content).

[0209] Except for not involving the SCP, Figure 2 the example call flow is Figure 1 corresponding to the call flow of Figure 2 The call flow in

[0210] 1. The consumer sends a discovery request to the NRF.

[0211] 2. In its response, the NRF provides the consumer with an NF profile, which includes both the authorized FQDN and two IP addresses (e.g., an IPv4 address and an IPv6 address).

[0212] 3. The consumer uses the IPv4 address in the service request ("POST") sent to the producer.

[0213] 4. According to the request, the producer can create another resource (or update an existing resource, Figure 2 not shown in

[0214] ). The producer can reply to the SCP with a "201 Created" response, which includes the FQDN of the created resource and an alternative IP endpoint.

[0215] 5a. The consumer sends a service request related to the newly created resource (e.g.,

[0216] "PATCH") to the producer using one of the alternative IP endpoints as the destination address.

[0217] 5b. Due to a link failure, the producer does not receive the request from the consumer.

[0218] 5c. The consumer sends a service request related to the newly created resource (e.g., "PATCH") to the producer again, this time using the other alternative IP endpoint as the destination address. The producer receives the request.

[0219] 6. The producer replies to the consumer with a 204 response (e.g., the request was successfully processed;

[0220] Figure 3The example call flow uses the 3gpp-Sbi-IpEndpoints-Info header in subscription / notification. These messages are as follows:

[0221] 1a: The consumer wishes to subscribe to the producer via the SCP through a subscription request. The consumer includes multiple callback URIs with different authorizations in the request.

[0222] 1b: The SCP forwards the request including multiple callback URIs to the producer.

[0223] 2a: The producer stores the callback URIs together with the alternative addresses indicated by the consumer,

[0224] and replies to the SCP with "201 Created".

[0225] 2b: The SCP forwards "201 Created" to the consumer.

[0226] 3a: When an event (the event subscribed by the consumer) occurs, the producer notifies the SCP and includes all URIs with different authorizations in the notification.

[0227] 3b: The SCP forwards the notification to the consumer using one of the URIs in the URI. The SCP does not need to (and will not) query DNS.

[0228] 3c: Due to a link failure, the forwarding of the notification fails.

[0229] 3d: The SCP selects another URI for forwarding. This time, the SCP successfully forwards the notification to the consumer.

[0230] 4a+4b: The consumer replies to the producer via the SCP with a 204 response (e.g., the request is successfully processed; no content).

[0231] Figure 4 The example call flow uses the 3gpp-Sbi-IpEndpoints-Info header in a service request, which includes a JSON body with a URI. These messages are as follows:

[0232] 1. The AMF ("old AMF") creates or updates the subscriber's PDU context at the SMF.

[0233] 2. The SMF replies with a 201 response that includes a PDU URI that includes the FQDN as authorization, and the SMF additionally provides other IP endpoints. This information is stored at the old AMF.

[0234] 3. When the UE moves to another AMF ("new AMF"), the new AMF requests the old AMF to transmit the information on the UE context location stored at the SMF.

[0235] 4. The old AMF transfers the information of the UE context location to the new AMF. This information includes the FQDN and IP address of the resources at the SMF (e.g., typically all URIs received in 2, but at least a subset thereof).

[0236] 5. The new AMF sends a request related to the UE context (a "publish") to the SMF. The new AMF can use any address it knows based on the transfer in 4 without a DNS query.

[0237] Figure 5 A device according to an example embodiment is shown. The device can be a (first) provider of 3gpp - Sbi - IpEndpoints - Info (such as an NF service producer or an NF service consumer) or an element thereof. Figure 6 A method according to an example embodiment is shown. According to Figure 5 the device of Figure 6 can execute Figure 6 the method of Figure 5 but is not limited to this method.

[0238] The device includes a component 110 for creating and a component 120 for providing. The component 110 for creating and the component 120 for providing can be a creating component and a providing component respectively. The component 110 for creating and the component 120 for providing can be a creator and a provider respectively. The component 110 for creating and the component 120 for providing can be a creating processor and a providing processor respectively.

[0239] The component 110 for creating creates a resource (S110) at a first network function. In some example embodiments, the component 110 for creating can be a component for updating the resource.

[0240] There is a set of URIs for identifying the resources. Each URI in the set of URIs identifies a resource. Each URI in the set of URIs includes a scheme, a path, and a corresponding authorization. For each pair of two URIs in the set of URIs, the authorization included by one URI in the corresponding pair is different from the authorization included by the other URI in the corresponding pair; in other words, the authorizations are different from each other.

[0241] Component 120 for provisioning provides a message from a first network function to a second network function, the message including information that a resource has been created (S120) (or information that a resource has been updated if the component for creation is a component for update). In the message, the resource is identified by a first URI in a set of URIs identifying the resource. The first URI includes a first authorization. The message includes a second authorization different from the first authorization. A second URI in the set of URIs identifying the resource includes the second authorization. That is, both the first URI including a scheme, the first authorization, and a path and the second URI including a scheme, the second authorization, and a path belong to the set of URIs for identifying the resource.

[0242] Figure 7 Shows an apparatus according to an example embodiment. The apparatus may be a (first) provider of 3gpp-Sbi-IpEndpoints-Info (such as an NF service producer or an NF service consumer) or an element thereof. Figure 8 Shows a method according to an example embodiment. According to Figure 7 The apparatus of Figure 8 may perform the method of Figure 8 The method of Figure 7 may be performed by the apparatus of

[0243] The device includes a component 210 for provisioning. The component 210 for provisioning may be a provisioning component. The provisioning component 210 may be a provider. The component 210 for provisioning may be a provisioning processor.

[0244] The component 210 for provisioning provides a message from a first network function to a second network function, the message including information that a resource of the first network function will be used for a callback (S210).

[0245] There is a set of URIs for identifying a resource. Each URI in the set of URIs identifies the resource. Each URI in the set of URIs includes a scheme, a path, and a corresponding authorization. For each pair of two URIs in the set of URIs, the authorization included by one URI in the corresponding pair is different from the authorization included by the other URI in the corresponding pair; in other words, the authorizations are different from each other.

[0246] In the message, the resource is identified by a first URI in a set of URIs identifying the resource. The first URI includes a first authorization. The message includes a second authorization different from the first authorization. A second URI in the set of URIs identifying the resource includes the second authorization. That is, both the first URI including a scheme, the first authorization, and a path and the second URI including a scheme, the second authorization, and a path belong to the set of URIs for identifying the resource.

[0247] Figure 9 Shows a device according to an example embodiment. The device can be a receiver of 3gpp-Sbi-IpEndpoints-Info (such as an NF service producer, an NF service consumer, or an SCP) or an element thereof. Figure 10 Shows a method according to an example embodiment. According to Figure 9 The device of Figure 10 can execute the Figure 10 method of Figure 9 but is not limited to this method.

[0248] The device includes a component 310 for receiving and a component 320 for transmitting. The component 310 for receiving and the component 320 for transmitting can be a receiving component and a transmitting component respectively. The component 310 for receiving and the component 320 for transmitting can be a receiver and a transmitter respectively. The component 310 for receiving and the component 320 for transmitting can be a receiving processor and a transmitting processor respectively.

[0249] The component 310 for receiving receives an incoming message (S310) at a second network function. The incoming message includes information that a resource is created or updated at a first network function or will be used for a callback. In the incoming message, the resource is identified by each of a first URI and a second URI. The first URI includes a scheme, a path, and a first authorization, and the second URI includes a scheme, a path, and a second authorization different from the first authorization. That is, the first URI and the second URI include the same scheme and path but include different authorizations. The incoming message can include more than two different authorizations for the resource.

[0250] The component 320 for transmitting sends an outgoing message related to the resource (S320) from the second network function to the first network function. In the outgoing message, the resource is identified by each of the first URI and the second URI. That is, the outgoing message includes at least a scheme, a path, a first authorization, and a second authorization. If the incoming message includes more than two different authorizations for the resource, the outgoing message can include all of these different authorizations or a subset thereof, where the subset includes multiple authorizations.

[0251] Figure 11 Shows a device according to an example embodiment. The device includes at least one processor 810 and at least one memory 820 storing instructions that, when executed by the at least one processor 810, cause the device to execute at least the method according to at least one of the following drawings and related descriptions: Figure 6 , Figure 8 or Figure 10 .

[0252] Some example embodiments are explained for 5G (NR). However, other example embodiments can be used for other 3GPP generations (such as 4G, 6G, 7G, etc.), for other wireless or wired communication devices, and for other systems that employ HTTP communication.

[0253] The UE is an example of a terminal. Other examples are MTC devices. Each terminal can be implemented as a smartphone, mobile phone, laptop, sensor device, etc. A terminal is typically a cellular communication device for communicating in a cellular network (such as a 3GPP network), but this is not mandatory.

[0254] A piece of information can be sent from one entity to another entity in one or more messages. Each of these messages can include other (different) pieces of information.

[0255] The names of network elements, network functions, protocols, and methods are based on certain standards. These names are not restrictive. For example, in other versions or other technologies, the names of these network elements and / or network functions and / or protocols and / or methods can be different as long as they provide the corresponding functions. This similarly applies to terminals.

[0256] Unless otherwise stated or clear from the context, different expressions of two entities mean that they perform different functions. This does not necessarily mean that they are based on different hardware. That is, each entity described herein can be based on different hardware, or some or all of the entities can be based on the same hardware. This does not necessarily mean that they are based on different software. That is, each entity described herein can be based on different software, or some or all of the entities can be based on the same software. Each entity described herein can be deployed in the cloud.

[0257] In view of the above description, it should thus be apparent that the example embodiments provide, for example, an HTTP client (such as a service consumer), or an element thereof, an apparatus embodying the client or the element thereof, a method for controlling and / or operating the client or the element thereof, one or more computer programs for controlling and / or operating the client or the element thereof, and a medium carrying such one or more computer programs and forming one or more computer program products. In view of the above description, it should thus be apparent that the example embodiments provide, for example, an HTTP server (such as a service producer), or an element thereof, an apparatus embodying the server or the element thereof, a method for controlling and / or operating the server or the element thereof, one or more computer programs for controlling and / or operating the server or the element thereof, and a medium carrying such one or more computer programs and forming one or more computer program products. In view of the above description, it should thus be apparent that the example embodiments provide, for example, a proxy (such as an SCP), or an element thereof, an apparatus embodying the proxy or the element thereof, a method for controlling and / or operating the proxy or the element thereof, one or more computer programs for controlling and / or operating the proxy or the element thereof, and a medium carrying such one or more computer programs and forming one or more computer program products.

[0258] As a non-limiting and illustrative example, the implementation of any of the above blocks, apparatuses, systems, techniques or methods includes implementation as hardware, software, firmware, special-purpose circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof. Each entity described in this specification may be at least partially (or fully) embodied in the cloud.

[0259] Furthermore, it should be understood that the apparatuses of the various example embodiments are configured to perform the corresponding methods, although in some cases only the apparatus or only the method is described.

[0260] In general, the various example embodiments may be implemented in hardware or special-purpose circuitry, software, logic, or any combination thereof. Some example embodiments of the present disclosure may be implemented in hardware, while other example embodiments may be implemented in firmware or software that may be executed by a controller, a microprocessor, or other computing devices, but the present disclosure is not limited thereto. Although the various example embodiments of the present disclosure may be illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it is well understood that, as a non-limiting and illustrative example, the blocks, apparatuses, systems, techniques or methods described herein may be implemented in hardware, software, firmware, special-purpose circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0261] As used herein, the term "circuitry" may refer to one or more or all of the following:

[0262] (a) Implementations solely in hardware circuitry (such as implementations solely in analog and / or digital circuitry) and

[0263] (b) Combinations of hardware circuitry and software, such as (where applicable):

[0264] (i) Combinations of (one or more) analog and / or digital hardware circuitry and software / firmware, and / or

[0265] (ii) Any portion of (one or more) hardware processors (including (one or more) digital signal processors) with software, software, and (one or more) memories that work together to cause a device (such as a mobile phone or a server) to perform various functions), and

[0266] (c) (One or more) hardware circuitry and / or (one or more) processors, such as (one or more) microprocessors or a portion of (one or more) microprocessors, which require software (e.g., firmware) to operate, but the software can be absent when not needed for operation.

[0267] This definition of "circuitry" applies to all uses of the term in this document, including in any claims. As another example, as used herein, the term "circuitry" also encompasses implementations of only hardware circuitry or a processor (or processors) or a portion of a hardware circuitry or a processor and its attendant software and / or firmware. For example, if applicable to a particular claim element, the term "circuitry" also encompasses a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit in a server, a cellular network device, or other computing or network devices.

[0268] Various example embodiments of the present disclosure can be implemented by computer software executable by a data processor of a mobile device (such as in a processor entity), or by hardware, or by a combination of software and hardware. Computer software or programs (also referred to as program products, including software routines, applets, and / or macros) can be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. A computer program product can include one or more computer-executable components that, when the program runs, are configured to perform any example embodiment described herein. One or more computer-executable components can be at least one software code or a portion thereof.

[0269] In addition, in this regard, it should be noted that any block of the logic flow shown in the figures can represent a program step, or interconnected logic circuits, blocks, and functions, or a combination of program steps and logic circuits, blocks, and functions. Software can be stored on physical media, such as memory chips or memory blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as DVDs and their data variants CDs. The physical media can be "non-transitory" media.

[0270] As used herein, the term "non-transitory" is a limitation on the medium itself (e.g., tangible, rather than a signal), rather than a limitation on the persistence of data storage (e.g., RAM vs. ROM).

[0271] The memory can be of any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor can be of any type suitable for the local technical environment and, by way of non-limiting example, can include one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), FPGAs, gate-level circuits, and processors based on multi-core processor architectures.

[0272] Various example embodiments of the present disclosure can be implemented in various components, such as integrated circuit modules. The design of integrated circuits is generally a highly automated process. Sophisticated and powerful software tools can be used to convert a logic-level design into a semiconductor circuit design for etching and formation on a semiconductor substrate.

[0273] The scope of protection sought by the various example embodiments of the present disclosure is defined by the independent claims. Example embodiments and their features (if any) described in the present disclosure that do not fall within the scope of the independent claims will be construed as examples to facilitate understanding of the various example embodiments of the present disclosure.

[0274] As used herein, unless otherwise specified, the terms "first X" and "second X" include the options where "first X" is the same as "second X" and where "first X" is different from "second X". Unless it is clear from the present disclosure, these terms are only used to distinguish one element from another and do not denote a temporal relationship.

[0275] As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrasings (where the list of two or more elements is joined by "and" or "or") mean at least any one of these elements, or at least any two or more of these elements, or at least all of these elements. Similarly, the expression "and / or" includes any and all combinations of two or more of the listed terms, including at least any one of these elements, or at least any two or more of these elements, or at least all of these elements.

[0276] As used herein, the term "or" means a non-exclusive "or" unless otherwise specified (e.g., by use of "otherwise" or "or alternatively").

[0277] As used herein, unless expressly stated otherwise, performing a step "in response to A" does not mean that the step is performed immediately after A occurs and may include one or more intermediate steps. Similarly, performing a step or function "based on A" does not mean that the step or function is performed only based on A, as one or more additional conditions may be included.

[0278] It should be understood that the foregoing are considered to be various example embodiments of the present disclosure. However, it should be noted that the description of any one of the various example embodiments of the present disclosure is provided only by way of non-limiting and illustrative examples and various modifications may be made without departing from the scope of the present disclosure. For example, additional example embodiments may be provided by a combination of any two or more of the foregoing various example embodiments.

Claims

1. A device for communication, comprising: one or more processors, and a memory storing instructions, which when executed by the one or more processors cause the apparatus to at least perform: creating or updating a resource at a first network function, wherein each uniform resource identifier in a set of uniform resource identifiers identifies the resource, each uniform resource identifier in the set of uniform resource identifiers includes a scheme, a path, and a corresponding authorization, and for each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other of the two uniform resource identifiers in the corresponding pair; A message is provided from the first network function to the second network function, the message including information that the resource is created or updated, wherein in the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identify the resource, the first uniform resource identifier includes a first authorization, the message includes a second authorization different from the first authorization, and the second uniform resource identifier in the set of uniform resource identifiers that identifies the resource includes the second authorization.

2. A device for communication, comprising: one or more processors, and a memory storing instructions, which when executed by the one or more processors cause the apparatus to at least perform: providing a message from a first network function to a second network function, the message including information that resources of the first network function are to be used for the call back, wherein: Each uniform resource identifier in the set of uniform resource identifiers identifies the resource, Each uniform resource identifier in the uniform resource identifier set includes a scheme, a path and a corresponding authority, for each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other of the two uniform resource identifiers in the corresponding pair; In the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identify the resource, The first uniform resource identifier includes a first authorization, The message includes a second authorization different from the first authorization, and A second uniform resource identifier in the set of uniform resource identifiers identifying the resource comprises the second authorization.

3. The apparatus according to any one of claims 1 to 2, wherein each of the authorizations included by the uniform resource identifier in the set of uniform resource identifiers identifying the resource includes a corresponding host part, and each of the host parts includes: The fully qualified domain name of the resource, or the corresponding Internet Protocol address of the resource. 4 . The apparatus of claim 3 , wherein at least one of the authorizations included by the uniform resource identifier in the set of uniform resource identifiers identifying the resource includes a corresponding port of the resource.

5. A device for communication, comprising: one or more processors, and a memory storing instructions, which when executed by the one or more processors cause the apparatus to at least perform: receiving, at the second network function, an incoming message, the incoming message including information that a resource is created or updated at the first network function or is to be used for a call back, wherein in the incoming message, the resource is identified by each of a first uniform resource identifier and a second uniform resource identifier, the first uniform resource identifier including a scheme, a path, and a first authorization, and the second uniform resource identifier including the scheme, the path, and a second authorization different from the first authorization; An outgoing message related to the resource is sent from the second network function to the first network function, wherein in the outgoing message, the resource is identified by each of the first and second uniform resource identifiers.

6. The apparatus of claim 5, wherein each of the first authorization and the second authorization comprises a respective host portion, and each of the host portions comprises: The fully qualified domain name of the resource, or the corresponding Internet Protocol address of the resource.

7. A method for communication, comprising: creating or updating a resource at a first network function, wherein each uniform resource identifier in a set of uniform resource identifiers identifies the resource, each uniform resource identifier in the set of uniform resource identifiers includes a scheme, a path, and a corresponding authorization, and for each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other of the two uniform resource identifiers in the corresponding pair; A message is provided from the first network function to the second network function, the message including information that the resource is created or updated, wherein in the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identify the resource, the first uniform resource identifier includes a first authorization, the message includes a second authorization different from the first authorization, and the second uniform resource identifier in the set of uniform resource identifiers that identifies the resource includes the second authorization.

8. A method for communication, comprising: providing a message from a first network function to a second network function, the message including information that resources of the first network function are to be used for the call back, wherein: Each uniform resource identifier in the set of uniform resource identifiers identifies the resource, Each uniform resource identifier in the uniform resource identifier set includes a scheme, a path and a corresponding authority, for each pair of two uniform resource identifiers in the set of uniform resource identifiers, the authorization included by one of the two uniform resource identifiers in the corresponding pair is different from the authorization included by the other of the two uniform resource identifiers in the corresponding pair; In the message, the resource is identified by a first uniform resource identifier in the set of uniform resource identifiers that identify the resource, The first uniform resource identifier includes a first authorization, The message includes a second authorization different from the first authorization, and A second uniform resource identifier in the set of uniform resource identifiers identifying the resource comprises the second authorization.

9. A method for communication, comprising: receiving, at the second network function, an incoming message, the incoming message including information that a resource is created or updated at the first network function or is to be used for a call back, wherein in the incoming message, the resource is identified by each of a first uniform resource identifier and a second uniform resource identifier, the first uniform resource identifier including a scheme, a path, and a first authorization, and the second uniform resource identifier including the scheme, the path, and a second authorization different from the first authorization; An outgoing message related to the resource is sent from the second network function to the first network function, wherein in the outgoing message, the resource is identified by each of the first and second uniform resource identifiers.

10. A computer program product comprising an instruction set, which, when executed by an apparatus, is configured to cause the apparatus to perform the method according to any one of claims 7 to 9.