Apparatus, method and computer program
By introducing the Service Communication Agent (SCP) to directly acquire and store the complete configuration files of the network function service producers in local storage, the problem of inefficiency found in the communication system is solved, and the performance and communication delay of the network function repository function (NRF) is optimized.
Patent Information
- Application Number
- CN202380082191.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-12
- Filing Date
- 2023-10-10
- Publication Date
- 2025-07-04
AI Technical Summary
In communication systems, when network function service consumers discover network function service producers, the prior art has inefficiency and performance bottlenecks. Especially in indirect communication mode, network function repository function (NRF) needs to handle a large number of duplicate discovery requests, resulting in performance degradation and delays.
By introducing a Service Communication Agent (SCP), the agent can send requests to the Network Function Repository Function (NRF) on behalf of the network function service consumers, directly obtain the complete configuration files of the network function service producers including authorized attributes, and store and reuse these configuration files locally, reducing duplicate requests to the NRF, and optimizing the discovery process.
Improve the efficiency of network function service consumers discover network function service producers, reduce NRF load and request times, optimize SCP performance, and reduce communication delay and storage requirements.
Smart Images

Figure CN120266439A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an apparatus, method, and computer program for discovering a network function service producer in a communication system. Background Art
[0002] A communication system can be regarded as a facility that enables a communication session between two or more entities (such as communication devices, base stations, and / or other nodes) by providing a carrier between various entities involved in a communication path.
[0003] The communication system can be a wireless communication system. Examples of wireless systems include public land mobile networks (PLMNs) operating based on radio standards (such as those provided by 3GPP), satellite-based communication systems, and different wireless local area networks, such as wireless local area networks (WLANs). Wireless systems are typically divided into cells and are therefore often referred to as cellular systems.
[0004] Communication systems and associated devices typically operate according to a given standard or specification that defines what the various entities associated with the system are allowed to do and how they should be implemented. Communication protocols and / or parameters to be used for connections are also typically defined. An example of a standard is the so-called 5G standard. Summary of the Invention
[0005] According to one aspect, there is provided an apparatus including components for: receiving, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details; sending a request to a network function repository function to discover a profile of the network function service producer including authorization attributes; receiving, from the network function repository function, a profile of the network function service producer including authorization attributes; and determining, based on the authorization attributes and the network function service consumer details, whether the network function service consumer is allowed to consume the service from the network function service producer.
[0006] The apparatus can be a service communication proxy.
[0007] The apparatus can include components for: determining, based on the authorization attributes and the network function service consumer details, that the network function service consumer is allowed to consume the service from the network function service producer; and sending a service request to the network function service producer to consume the service from the network function service producer.
[0008] The apparatus may include components for: receiving, from another network function service consumer, a request to consume a service from a network function service producer, the request including other network function service consumer details; and determining, based on authorization attributes and the other network function service consumer details, whether the other network function service consumer is permitted to consume the service from the network function service producer.
[0009] The apparatus may include components for: storing a configuration file of a network function service producer including authorization attributes.
[0010] A request from the apparatus to discover a configuration file of a network function service producer including authorization attributes includes: an indication to discover a complete configuration file of a network function service producer including authorization attributes.
[0011] According to one aspect, there is provided an apparatus including at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured to, with the at least one processor, cause the apparatus to at least: receive, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details; send a request to a network function repository function to discover a configuration file of a network function service producer including authorization attributes; receive, from the network function repository function, the configuration file of the network function service producer including authorization attributes; and determine, based on the authorization attributes and the network function service consumer details, whether the network function service consumer is permitted to consume the service from the network function service producer.
[0012] The apparatus may be a service communication proxy.
[0013] The at least one memory and the computer code, together with the at least one memory, are configured to cause the apparatus to at least: determine, based on the authorization attributes and the network function service consumer details, that the network function service consumer is permitted to consume the service from the network function service producer; and send a service request to the network function service producer to consume the service from the network function service producer.
[0014] The at least one memory and the computer code, together with the at least one processor, are configured to cause the apparatus to at least: receive, from another network function service consumer, a request to consume a service from a network function service producer, the request including other network function service consumer details; and determine, based on the authorization attributes and the other network function service consumer details, whether the other network function service consumer is permitted to consume the service from the network function service producer.
[0015] At least one memory and computer code, together with at least one processor, are configured to cause the apparatus to at least: store a profile of a network function service producer that includes authorization attributes.
[0016] A request from the apparatus to discover a profile of a network function service producer that includes authorization attributes includes: an indication to discover a complete profile of a network function service producer that includes authorization attributes.
[0017] According to one aspect, there is provided an apparatus including circuitry configured to: receive, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details; send a request to a network function repository function to discover a profile of a network function service producer that includes authorization attributes; receive, from the network function repository function, a profile of a network function service producer that includes authorization attributes; and determine, based on the authorization attributes and the network function service consumer details, whether the network function service consumer is permitted to consume the service from the network function service producer.
[0018] The apparatus may be a service communication proxy.
[0019] The apparatus may include circuitry configured to: determine, based on the authorization attributes and the network function service consumer details, that the network function service consumer is permitted to consume the service from the network function service producer; and send a service request to the network function service producer to consume the service from the network function service producer.
[0020] The apparatus may include circuitry configured to: receive, from another network function service consumer, a request to consume a service from a network function service producer, the request including other network function service consumer details; and determine, based on the authorization attributes and the other network function service consumer details, whether the other network function service consumer is permitted to consume the service from the network function service producer.
[0021] The apparatus may include circuitry configured to: store a profile of a network function service producer that includes authorization attributes.
[0022] A request from the apparatus to discover a profile of a network function service producer that includes authorization attributes includes: an indication to discover a complete profile of a network function service producer that includes authorization attributes.
[0023] According to one aspect, a method is provided, including: receiving, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details; sending a request to a network function repository function, the request for discovering a profile of the network function service producer including authorization attributes; receiving, from the network function repository function, the profile of the network function service producer including authorization attributes; and determining, based on the authorization attributes and the network function service consumer details, whether the network function service consumer is permitted to consume the service from the network function service producer.
[0024] The method may be performed by an apparatus.
[0025] The apparatus may be a service communication proxy.
[0026] The method may include: determining, based on the authorization attributes and the network function service consumer details, that the network function service consumer is permitted to consume the service from the network function service producer; and sending a service request to the network function service producer to consume the service from the network function service producer.
[0027] The method may include: receiving, from another network function service consumer, a request to consume a service from the network function service producer, the request including other network function service consumer details; and determining, based on the authorization attributes and the other network function service consumer details, whether the other network function service consumer is permitted to consume the service from the network function service producer.
[0028] The method may include: storing the profile of the network function service producer including authorization attributes.
[0029] The request from the apparatus for discovering the profile of the network function service producer including authorization attributes includes: an indication for discovering a complete profile of the network function service producer including authorization attributes.
[0030] According to one aspect, a computer program including computer-executable code is provided, which when running on at least one processor is configured to: receive, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details; send a request to a network function repository function, the request for discovering a profile of the network function service producer including authorization attributes; receive, from the network function repository function, the profile of the network function service producer including authorization attributes; and determine, based on the authorization attributes and the network function service consumer details, whether the network function service consumer is permitted to consume the service from the network function service producer.
[0031] The at least one processor may be part of the apparatus.
[0032] The apparatus may be a service communication proxy.
[0033] The computer program may include computer-executable code that, when run on at least one processor, is configured to: determine that a network function service consumer is permitted to consume a service from a network function service producer based on authorization attributes and network function service consumer details; and send a service request to the network function service producer to consume the service from the network function service producer.
[0034] The computer program may include computer-executable code that, when run on at least one processor, is configured to: receive, from another network function service consumer, a request to consume a service from a network function service producer, the request including other network function service consumer details; and determine whether the other network function service consumer is permitted to consume the service from the network function service producer based on authorization attributes and the other network function service consumer details.
[0035] The computer program may include computer-executable code that, when run on at least one processor, is configured to: store a configuration file of a network function service producer that includes authorization attributes.
[0036] A request from the apparatus to discover a configuration file of a network function service producer that includes authorization attributes includes: an indication to discover a complete configuration file of a network function service producer that includes authorization attributes.
[0037] According to one aspect, there is provided an apparatus that includes components for: receiving, from another apparatus, a request to discover a configuration file of a network function service producer that includes authorization attributes; determining that the other apparatus is permitted to discover the configuration file of the network function service producer that includes authorization attributes; and sending to the other apparatus the configuration file of the network function service producer that includes authorization attributes.
[0038] The apparatus may be a network function repository function.
[0039] Another apparatus may be a service communication proxy.
[0040] The apparatus may include components for: receiving, from another apparatus, a request to discover a configuration file of another network function service producer that includes authorization attributes; determining that the other apparatus is not permitted to discover the configuration file of the other network function service producer that includes authorization attributes; and rejecting the request or sending to the other apparatus a configuration file of a network function service producer that does not include authorization attributes.
[0041] The apparatus may include components for: determining, based on static authorization configured in the apparatus indicating whether another apparatus is permitted to discover a profile of a network function service producer including authorization attributes, or an access token received in a request received from another apparatus, which request is for discovering a profile of a network function service producer including authorization attributes, that another apparatus is permitted to discover the profile of the network function service producer including authorization attributes.
[0042] A request from another apparatus for discovering a profile of a network function service producer including authorization attributes includes an indication for receiving an original profile or a complete profile of the network function service producer including authorization attributes.
[0043] The authorization attributes may include at least one of the following: the type of network function service consumer permitted to consume the service of the network function service producer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0044] The network function service consumer details may include at least one of the following: the type of network function service consumer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0045] According to one aspect, there is provided an apparatus including at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured to, with the at least one processor, cause the apparatus to at least: receive from another apparatus a request for discovering a profile of a network function service producer including authorization attributes; determine that the other apparatus is permitted to discover the profile of the network function service producer including authorization attributes; and send to the other apparatus the profile of the network function service producer including authorization attributes.
[0046] The apparatus may be a network function repository function.
[0047] The other apparatus may be a service communication proxy.
[0048] The at least one memory and the computer code may be configured to, with the at least one processor, cause the apparatus to at least: receive from another apparatus a request for discovering a profile of another network function service producer including authorization attributes; determine that the other apparatus is not permitted to discover the profile of the other network function service producer including authorization attributes; and reject the request or send to the other apparatus a profile of a network function service producer not including authorization attributes.
[0049] At least one memory and computer code can be configured to, with at least one processor, cause the apparatus to at least: determine that another apparatus is permitted to discover a profile of a network function service producer including authorization attributes based on: static authorization configured in the apparatus indicating whether another apparatus is permitted to discover the profile of the network function service producer; or an access token received in a request received from another apparatus, the request for discovering the profile of the network function service producer including authorization attributes.
[0050] A request from another apparatus for discovering a profile of a network function service producer including authorization attributes includes: an indication for receiving an original profile or a complete profile of the network function service producer including authorization attributes.
[0051] The authorization attributes can include at least one of the following: the type of a network function service consumer permitted to consume the services of the network function service producer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0052] The network function service consumer details can include at least one of the following: the type of a network function service consumer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0053] According to one aspect, there is provided an apparatus including circuitry configured to: receive a request from another apparatus for discovering a profile of a network function service producer including authorization attributes; determine that another apparatus is permitted to discover the profile of the network function service producer including authorization attributes; and send to the another apparatus the profile of the network function service producer including authorization attributes.
[0054] The apparatus can be a network function repository function.
[0055] The another apparatus can be a service communication proxy.
[0056] The apparatus can include circuitry configured to: receive a request from another apparatus for discovering a profile of another network function service producer including authorization attributes; determine that another apparatus is not permitted to discover the profile of the other network function service producer including authorization attributes; and reject the request, or send to the another apparatus the profile of the network function service producer not including authorization attributes.
[0057] The apparatus may include circuitry configured to determine that another apparatus is permitted to discover a profile of a network function service producer including authorization attributes based on: static authorization configured in the apparatus indicating whether another apparatus is permitted to discover the profile of the network function service producer; or an access token received in a request received from another apparatus, the request being for discovering a profile of a network function service producer including authorization attributes.
[0058] A request from another apparatus for discovering a profile of a network function service producer including authorization attributes includes an indication for receiving an original profile or a complete profile of the network function service producer including authorization attributes.
[0059] The authorization attributes may include at least one of the following: a type of a network function service consumer permitted to consume services of the network function service producer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0060] The network function service consumer details may include at least one of the following: a type of a network function service consumer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0061] According to one aspect, a method is provided that includes: receiving, from another apparatus, a request for discovering a profile of a network function service producer including authorization attributes; determining that the other apparatus is permitted to discover the profile of the network function service producer including authorization attributes; and sending, to the other apparatus, the profile of the network function service producer including authorization attributes.
[0062] The method may be performed by an apparatus.
[0063] The apparatus may be a network function repository function.
[0064] The other apparatus may be a service communication proxy.
[0065] The method may include: receiving, from another apparatus, a request for discovering a profile of another network function service producer including authorization attributes; determining that the other apparatus is not permitted to discover the profile of the other network function service producer including authorization attributes; and rejecting the request or sending, to the other apparatus, a profile of a network function service producer not including authorization attributes.
[0066] The method may include: determining, based on static authorization configured in the device, which indicates whether another device is allowed to discover the profile of a network function service producer including authorization attributes; or an access token received in a request received from another device, the request being for discovering the profile of a network function service producer including authorization attributes.
[0067] A request from another device for discovering the profile of a network function service producer including authorization attributes includes: an indication for receiving an original profile or a complete profile of the network function service producer including authorization attributes.
[0068] The authorization attributes may include at least one of the following: the type of network function service consumer allowed to consume the services of the network function service producer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0069] The network function service consumer details may include at least one of the following: the type of network function service consumer, a public land mobile network, a standalone non-public network, a network slice, or a domain name.
[0070] According to one aspect, there is provided a computer program including computer-executable code which, when run on at least one processor, is configured to: receive a request from another device for discovering the profile of a network function service producer including authorization attributes; determine that the other device is allowed to discover the profile of the network function service producer including authorization attributes; and send to the other device the profile of the network function service producer including authorization attributes.
[0071] The at least one processor may be part of the device.
[0072] The device may be a network function repository function.
[0073] The other device may be a service communication proxy.
[0074] The computer program may include computer-executable code which, when run on at least one processor, is configured to: receive a request from another device for discovering the profile of another network function service producer including authorization attributes; determine that the other device is not allowed to discover the profile of the other network function service producer including authorization attributes; and reject the request, or send to the other device the profile of the network function service producer not including authorization attributes.
[0075] A computer program may include computer-executable code that, when run on at least one processor, is configured to: determine, based on static authorization configured in the device, indicating whether another device is allowed to discover a profile of a network function service producer including authorization attributes; or an access token received in a request received from another device, the request being for discovering a profile of a network function service producer including authorization attributes, that another device is allowed to discover the profile of the network function service producer.
[0076] A request from another device for discovering a profile of a network function service producer including authorization attributes includes an indication for receiving an original profile or a complete profile of the network function service producer including authorization attributes.
[0077] The authorization attributes may include at least one of the following: the type of a network function service consumer allowed to consume the service of the network function service producer, a public land mobile network, a stand-alone non-public network, a network slice, or a domain name.
[0078] The network function service consumer details may include at least one of the following: the type of a network function service consumer, a public land mobile network, a stand-alone non-public network, a network slice, or a domain name.
[0079] According to one aspect, there is provided a computer-readable medium including program instructions stored thereon for performing at least one of the above methods.
[0080] According to one aspect, there is provided a non-transitory computer-readable medium including program instructions stored thereon for performing at least one of the above methods.
[0081] According to one aspect, there is provided a non-volatile tangible memory medium including program instructions stored thereon for performing at least one of the above methods.
[0082] In the foregoing, many different aspects have been described. It should be understood that other aspects may be provided by a combination of any two or more of the above aspects.
[0083] Various other aspects are also described in the following detailed description and the appended claims.
[0084] List of Abbreviations
[0085] AF: Application Function
[0086] AMF: Access and Mobility Management Function
[0087] API: Application Programming Interface
[0088] BS: Base Station
[0089] CU: Centralized Unit
[0090] DL: Downlink
[0091] DU: Distributed Unit
[0092] gNB: gNodeB
[0093] GSM: Global System for Mobile Communications
[0094] HSS: Home Subscriber Server
[0095] IoT: Internet of Things
[0096] LTE: Long Term Evolution
[0097] MAC: Media Access Control
[0098] MS: Mobile Station
[0099] MTC: Machine Type Communication
[0100] NEF: Network Exposure Function
[0101] NF: Network Function
[0102] NR: New Radio
[0103] NRF: Network Function Repository Function
[0104] OAM: Operation, Administration and Maintenance
[0105] PDU: Packet Data Unit
[0106] RAM: Random Access Memory
[0107] (R)AN: (Radio) Access Network
[0108] ROM: Read Only Memory
[0109] SMF: Session Management Function
[0110] TR: Technical Report
[0111] TS: Technical Specification
[0112] UE: User Equipment
[0113] UMTS: Universal Mobile Telecommunications System
[0114] 3GPP: Third Generation Partnership Project
[0115] 5G: Fifth Generation
[0116] 5GC: 5G Core Network
[0117] 5GS: 5G System BRIEF DESCRIPTION OF THE DRAWINGS
[0118] Embodiments will now be described by way of example only with reference to the accompanying drawings, in which:
[0119] Figure 1 shows a schematic representation of a 5G system;
[0120] Figure 2 shows a schematic representation of a control device;
[0121] Figure 3 shows a schematic representation of a user equipment;
[0122] Figure 4a and Figure 4b shows a signaling diagram of a process for discovering a network function service producer in a communication system;
[0123] Figure 5a and Figure 5b shows a signaling diagram of another process for discovering a network function service producer in a communication system;
[0124] Figure 6 shows a block diagram of a method for discovering a network function service producer in a communication system, for example, performed by a service communication proxy;
[0125] Figure 7 shows a block diagram of a method for discovering a network function service producer in a communication system, for example, performed by a network function repository function; and
[0126] Figure 8 shows a schematic representation of a non - volatile storage medium storing instructions which, when executed by a processor, allow the processor to execute Figure 6 and Figure 7 one or more steps of the method. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0127] In the following, certain embodiments are explained with reference to a mobile communication device capable of communicating via a wireless cellular system and a mobile communication system serving such a mobile communication device. Before explaining exemplary embodiments in detail, reference is made to Figure 1 , Figure 2 and Figure 3 to briefly explain some general principles of wireless communication systems, their access systems, and mobile communication devices to assist in understanding the technology behind the described examples.
[0128] Figure 1Shows a schematic representation of a 5G system (5GS). The 5GS may include a User Equipment (UE), a (Radio) Access Network ((R)AN), a 5G Core Network (5GC), one or more Application Functions (AF), and one or more Data Networks (DN).
[0129] The 5G (R)AN may include one or more gNodeB (gNB) Distributed Unit functions connected to one or more gNodeB (gNB) Centralized Unit functions.
[0130] The 5GC may include an Access and Mobility Management Function (AMF), a Session Management Function (SMF), an Authentication Server Function (AUSF), User Data Management (UDM), a User Plane Function (UPF), a Network Exposure Function (NEF), a Network Function Repository Function (NRF), a Service Communication Proxy (SCP), and / or other network functions (NF) or proxies not shown.
[0131] Figure 2 Shows an example of a control device 200 for controlling the functions of the (R)AN or 5GC as Figure 1 shown. The control device may include at least one Random Access Memory (RAM) 211a, at least one Read Only Memory (ROM) 211b, at least one processor 212, 213, and an Input / Output interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211b. The at least one processor 212, 213 may be configured to execute appropriate software code 215. The software code 215 may, for example, allow the execution of one or more steps to perform one or more of the aspects herein. The software code 215 may be stored in the ROM 211b. The control device 200 may be interconnected with another control device 200 that controls another function of the 5G (R)AN or 5GC. In some embodiments, each function of the (R)AN or 5GC includes a control device 200. In alternative embodiments, two or more functions of the (R)AN or 5GC may share a control device.
[0132] Figure 3 Illustrates an example of a UE 300, such as Figure 1The UE shown in
[0133] UE 300 can receive signals via an appropriate receiving device over the air or radio interface 307, and can send signals via an appropriate device for transmitting radio signals. In Figure 3 this case, the transceiver device is schematically designated by block 306. The transceiver device 306 can be provided, for example, by means of a radio part and an associated antenna arrangement. The antenna arrangement can be arranged inside or outside the mobile device.
[0134] UE 300 can be equipped with at least one processor 301, at least one memory ROM 302a, at least one RAM 302b, and other possible components 303, which are used for software and hardware assisted task execution. The tasks are designed to perform access control to the access system and other communication devices, and communication with the access system and other communication devices. At least one processor 301 is coupled to RAM 302b and ROM 302a. At least one processor 301 can be configured to execute appropriate software code 308. The software code 308 can, for example, allow the execution of one or more of the present aspects. The software code 308 can be stored in ROM 302a.
[0135] The processor, memory, and other related control devices can be provided on a suitable circuit board and / or chipset. This feature is represented by reference numeral 304. The device can optionally have a user interface, such as a keypad 305, a touch-sensitive screen or keyboard, a combination thereof, etc. Optionally, one or more of a display, a speaker, and a microphone can be provided according to the device type.
[0136] 3GPP TS29.510 stipulates that in the 5GC, NF service producers can register with the NRF. NF service producers can use the Nnrf_NFManagement service application programming interface (API). NF service consumers can discover NF service producers via the NRF. NF service consumers can use the Nnrf_NFDiscovery service API.
[0137] The NRF may store (i.e., cache) the complete (i.e., original) profile of an NF service producer. The complete (i.e., original) profile of an NF service producer may include authorization attributes that specify which NF service consumers are allowed to discover and consume the services produced by the NF service producer. The authorization attributes may specify which NF service consumers from which public land mobile network (PLMN), from which standalone non-public network (SNPN), with which NF type, from which domain, or with which network slice selection assistance information are allowed to discover and consume the services produced by the NF service producer. The authorization attributes may be named "allowedxxx". For example, the authorization attributes may include "allowedPlmns", "allowedSnpns", "allowedNfTypes", "allowedNfDomains", or "allowedNssais".
[0138] In direct communication, an NF service consumer may send a discovery request to the NRF to discover a partial profile of the NF service producer other than the "allowedxxx" attributes, rather than the complete (i.e., original) profile of the NF service producer that includes the "allowedxxx" attributes. The discovery request may include discovery query parameters. The discovery query parameters may include NF service consumer details.
[0139] Section 6.2.3.2.3.1 of 3GPP TS29510 specifies that the discovery request may include NF service consumer details. For example, the NF service consumer details may include requester-nf-instance-fqdn, requester-snpn-list, or requester-snssais.
[0140] The NRF may determine whether an NF service consumer is allowed to consume (i.e., access) the services of the NF service producer, and thus discover a partial profile of the NF service producer, based on the NF service consumer details and the "allowedxxx" attributes included in the complete (i.e., original) profile of the NF service producer. If the NF service consumer is allowed to consume (i.e., access) the services of the NF service producer, and thus discover a partial profile of the NF service producer, the NRF may return the partial profile of the NF service producer to the NF service consumer in a discovery response to the discovery request.
[0141] It should be understood that the NRF may not return the complete (i.e., original) profile of the NF service producer to the NF service consumer. The NRF may modify the attributes included in the profile of the NF service producer (e.g., the fully qualified domain name (fqdn) attribute). The NFR may remove the attributes included in the profile of the NF service producer (e.g., the "allowedxxx" attribute).
[0142] The NF service consumer may store (i.e., cache) a partial profile of the NF service producer. The NF service consumer may use the partial profile of the NF service producer to determine whether to send a service request to the NF service producer.
[0143] The partial profile of the NF service producer included in the discovery response received by the NF service consumer from the NRF may vary based on the NF service consumer details included in the discovery request sent by the NF service consumer to the NRF. That is, the partial profile of the NF service producer included in the discovery response is customized for the NF service consumer (i.e., customized for the services that the NF service consumer is allowed to consume from the NF service producer). The NF service consumer may use the partial profile of the NF service producer included in the discovery response to determine whether to send a service request to the NF service producer.
[0144] Section 6.1.6.2.2 of 3GPP TS 29.510 correspondingly specifies the data model of the complete (i.e., original) profile of the NF service producer in the NRF registration API, and Section 6.2.6.2.3 specifies the data model of the partial profile of the NF service producer in the NRF discovery response.
[0145] In indirect communication with delegated discovery (also known as communication model D), the NF service consumer may send a service request to the SCP. The service request may include NF service consumer details. 3GPP TS 29.500 specifies that the NF service consumer may use the 3gpp-Sbi-Discovery header to indicate the NF service consumer details in the service request. The service request may include the 3gpp-Sbi-Discovery header that conveys discovery query parameters. The discovery query parameters may include NF service consumer details.
[0146] Then, the SCP may send a discovery request to the NRF on behalf of the NF service consumer. The discovery request may include discovery query parameters. The discovery query parameters may include NF service consumer details. The NRF may process the discovery request sent by the SCP (in indirect communication) in the same manner as the discovery request issued by the NF service consumer (in direct communication).
[0147] The NRF can determine whether an NF service consumer is allowed to consume services from an NF service producer based on the NF service consumer details included in the discovery request from the SCP and the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the NRF, and thus discover a partial profile of the NF service producer. If the NF service consumer is allowed to consume services from the NF service producer and thus discovers a partial profile of the NF service producer, the NRF can return the partial profile of the NF service producer to the SCP in the discovery response.
[0148] It should be understood that the NRF may not return the complete (i.e., original) profile of the NF service producer to the SCP. The NRF can modify the attributes (e.g., fully qualified domain name (fqdn) attribute) included in the profile of the NF service producer. The NFR can remove the attributes (e.g., authorization attribute) included in the profile of the NF service producer.
[0149] The SCP can store (i.e., cache) the partial profile of the NF service producer. The SCP can use the partial profile of the NF service producer to determine whether an NF service consumer is allowed to consume services from the NF service producer and thus determine whether to send a service request to the NF service producer on behalf of the NF service consumer.
[0150] It should be understood that the partial profile of the NF service producer included in the discovery response received by the SCP from the NRF may vary based on the NF service consumer details included in the discovery request sent by the SCP to the NRF. The partial profile of the NF service producer included in the discovery response is customized for the NF service consumer.
[0151] The SCP can use the profile of the NF service producer included in the discovery response with the NF service consumer to determine whether to send a service request to the NF service producer on behalf of the NF service consumer, but may not reuse the profile of the NF service producer included in the discovery response to determine whether to send a service request to the NF service producer on behalf of another NF service consumer.
[0152] For example, AMF 1 may send a service request to the SCP with the requester-nf-instance-fqdn set to fqdn 1, and subsequently AMF 2 may send a service request to the SCP with the requester-nf-instance-fqdn set to fqdn 2. The SCP may use a partial profile of the NF service producer customized for AMF 1 to determine whether to send a service request to the NF service producer on behalf of AMF 1. However, the SCP may not reuse the partial profile of the NF service producer customized for AMF 1 to determine whether to send a service request to the NF service producer on behalf of AMF 2.
[0153] It should be understood that in the above example, the service request originating from AMF 1 and the service request originating from AMF 2 include discovery headers with different requester-nf-instance-fqdn, and as a result, the partial profile of the NF service producer customized for AMF 1 is different from the partial profile of the NF service producer customized for AMF 2 (e.g., AMF1 may be allowed to consume services provided by the NF service producer rather than by AMF 2). However, the same applies if the service request originating from AMF 1 and the service request originating from AMF 2 include discovery headers with different requester-snssai or different requester-snpn-list.
[0154] More generally, any time the SCP receives a service request from an NF service consumer that includes a discovery header with new NF service consumer details, the SCP must send a discovery request to the NRF. This results in a large amount of discovery traffic towards the NRF. This affects the performance of both the NRF and the SCP and increases the additional latency. In addition, the SCP must store (i.e., cache) the partial profile of the NF service producer for each discovery header with NF service consumer details received from the NRF to avoid sending a service request that includes a discovery header with the same service consumer details twice. This requires a large amount of memory at the SCP.
[0155] One or more aspects of the present disclosure provide a mechanism for processing discovery requests in a more efficient manner, particularly for indirect communication.
[0156] The NF service consumer may send a service request to the SCP. The service request may include discovery query parameters. The discovery query parameters may include NF service consumer details.
[0157] The SCP may send a discovery request to the NRF on behalf of the NF service consumer. The discovery request may include discovery query parameters. The discovery query parameters may or may not include NF service consumer details. The discovery query parameters may include an indication to discover the complete (i.e., original) profile of NF service producers including the "allowedxxx" attribute, rather than a partial profile of NF service producers that do not include the "allowedxxx" attribute. The discovery query parameters may include an "original-profile" indication or a "complete-profile" indication.
[0158] The NRF may determine whether the SCP is authorized to discover the complete (i.e., original) profile of NF service producers including the "allowedxxx" attribute. The NRF may determine whether the SCP is authorized to discover the complete (i.e., original) profile of NF service producers including the "allowedxxx" attribute based on static authorization configured in the NRF indicating which network entities are allowed to execute such requests (e.g., all SCPs or a specific SCP). The NRF may determine whether the SCP is authorized to discover the complete (i.e., original) profile of NF service producers including the "allowedxxx" attribute based on a specific authorization (i.e., a specific access token) using the Oauth2 framework (when the NRF API supports OAuth2). For example, a new additional scope may be defined in the NRF NF discovery API as follows to authorize the SCP to discover the complete (i.e., original) profile of NF service producers including the "allowedxxx" attribute.
[0159]
[0160] Table 6.2.8-1 of 3GPP TS29.510: Oauth2 scopes defined in the Nnrf_NFDiscovery API
[0161]
[0162]
[0163] If the SCP is not authorized to discover the complete (i.e., original) profile of NF service producers including the "allowedxxx" attribute, the NRF may send a discovery response including a partial profile of the NF service producer (excluding the "allowedxxx" attribute). Alternatively, the NRF may send a discovery error response (i.e., the NRF may reject the discovery request).
[0164] If the SCP is authorized to discover the complete (i.e., original) profile of an NF service producer including the "allowedxxx" attribute, the NRF may send a discovery response including the complete (i.e., original) profile of the NF service producer (including the "allowedxxx" attribute).
[0165] The SCP may store (i.e., cache) the complete (i.e., original) profile of the NF service producer including the "allowedxxx" attribute. This storage (i.e., caching) may be done without storing any NF service consumer details in the cache key (i.e., the request does not include query parameters of the URI with NF service consumer details). The SCP may use the complete (i.e., original) profile of the NF service producer including the "allowedxxx" attribute to determine whether to send a service request to the NF service producer on behalf of the NF service consumer. The SCP may reuse the complete (i.e., original) profile of the NF service producer including the "allowedxxx" attribute to determine whether to send a service request to the NF service producer on behalf of the NF service consumer and / or on behalf of another NF service consumer (regardless of whether the NF service consumer details and other NF service consumer details are different). In one variant, the SCP may not include any NF service consumer details in the NF discovery request to discover the complete NF profile of the NF service producer.
[0166] More specifically, the SCP may determine whether the NF service consumer is allowed to consume the service from the NF service producer based on the NF service consumer details included in the service request from the NF service consumer and the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the SCP. If the NF service consumer is allowed to consume the service from the NF service producer, the SCP may send a service request to the NF service producer on behalf of the NF service consumer.
[0167] That is, the operation of determining whether the NF service consumer is allowed to consume the service from the NF service producer based on the NF service consumer details included in the service request from the NF service consumer and the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer is delegated by the NRF to the SCP.
[0168] Subsequently, another NF service consumer may send a service request to the SCP. The service request may include other discovery query parameters (including other NF service consumer details). Alternatively, the service request may include the same discovery query parameters as those in the service request previously sent by the NF service consumer to the SCP.
[0169] The SCP may send a discovery request to the NRF without representing other NF service consumers.
[0170] The SCP may determine whether other NF service consumers are allowed to consume services from the NF service producer based on other NF service consumer details included in a service request from other NF service consumers and the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the SCP. If other NF service consumers are allowed to consume services from the NF service producer, the SCP may send a service request to the NF service producer on behalf of other NF service consumers.
[0171] The SCP may send a subscription request to the NRF to receive updated "allowedxxx" attributes for updating the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the SCP. The subscription request may include an originalProfile boolean set to "true". The SCP may use the NFStatusSubscribe service operation.
[0172] The NRF may update the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the NRF. The NRF may determine that the SCP is allowed to receive the updated "allowedxxx" attribute for updating the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the SCP based on the originalProfile boolean set to "true" in the subscription request. The NRF may send the updated "allowedxxx" attribute for updating the "allowedxxx" attribute included in the complete (i.e., original) profile of the NF service producer stored by the SCP. The NRF may use the NFStatusNotify service operation. The SCP may update the complete (i.e., original) profile of the NF service producer stored by the SCP.
[0173] An advantage of one or more aspects of the present disclosure is that NRF performance may be optimized due to reduced discovery request traffic between the SCP and the NRF.
[0174] Advantages of one or more aspects of the present disclosure are that, as opposed to caching multiple partial profiles of an NF service producer for different NF service consumers, SCP performance can be optimized by caching the complete (i.e., original) profile of the NF service producer and reusing the complete (i.e., original) profile of the NF service producer regardless of the requester NF service consumer details.
[0175] An advantage of one or more aspects of the present disclosure is that, as a result of reducing the number of discovery requests sent from the SCP to the NRF, the latency for sending a service request from the SCP to the NRF can be reduced.
[0176] It should be understood that the above concepts are not limited to the SCP. The SCP can be replaced by another network entity, such as a 5GC NF or an operation administration and maintenance (OAM) entity.
[0177] Figure 4a and Figure 4b A signaling diagram illustrating a process for discovering an NF service producer in a communication system is shown.
[0178] The UDM 1 can be configured to provide services to an NF service consumer from domain fqdn 1.
[0179] In step 1, the UDM 1 can send a registration request to the NRF. The registration request can include the complete (i.e., original) profile of the UDM 1 (including the allowedNFDomains attribute set to fqdn 1).
[0180] The UDM 2 can be configured to provide services to an NF service consumer from domain fqdn 2.
[0181] In step 2, the UDM 2 can send a registration request to the NRF. The registration request can include the complete (i.e., original) profile of the UDM 2 (including the allowedNFDomains attribute set to fqdn 2).
[0182] In step 3, the AMF 1 can send a service request to the SCP. The service request can include a discovery header (e.g., target-nf-type: UDM, requester-nf-type: AMF, and requester-nf-instance-fqdn: fqdn 1) that conveys discovery query parameters. The discovery query parameters can include AMF 1 details (e.g., requester-nf-type: AMF and requester-nf-instance-fqdn: fqdn 1).
[0183] In step 4, the SCP may send a discovery request to the NRF. The discovery request may include discovery query parameters (e.g., target-nf-type: UDM, requester-nf-type: AMF, and requester-nf-instance-fqdn: fqdn 1).
[0184] The NRF may determine, based on the AMF 1 details and the "allowedXXX" attribute of the complete (i.e., original) profile of UDM 1 stored by the NRF, that AMF 1 is authorized to consume services from UDM 1 and is thus allowed to discover the partial profile of UDM 1 that does not include the "allowedXXX" attribute.
[0185] In step 5, the NRF may send a discovery response to the SCP that includes the partial profile of UDM 1 (excluding the "allowedXXX" attribute).
[0186] In step 6, the SCP may send a service request to UDM 1 on behalf of AMF 1.
[0187] In step 7, AMF 2 may send a service request to the SCP. The service request may include a discovery header that conveys query parameters (e.g., target-nf-type: UDM, requester-nf-type: AMF, and requester-nf-instance-fqdn: fqdn 2). The discovery query parameters may include AMF 2 details (e.g., requester-nf-type: AMF and requester-nf-instance-fqdn: fqdn 2).
[0188] In step 8, the SCP may send a discovery request to the NRF. The discovery request may include discovery query parameters (e.g., target-nf-type: UDM, requester-nf-type: AMF, and requester-nf-instance-fqdn: fqdn 2).
[0189] The NRF may determine, based on the AMF 1 details and the "allowedXXX" attribute of the complete (i.e., original) profile of UDM 2 stored by the NRF, that AMF 2 is authorized to consume services from UDM 2 and is thus allowed to discover the partial profile of UDM 2 that does not include the "allowedXXX" attribute.
[0190] In step 9, the NRF may send a discovery response to the SCP that includes the partial profile of UDM 2 (excluding the "allowedXXX" attribute).
[0191] In step 10, the SCP may send a service request on behalf of AMF 2 to UDM 2.
[0192] Figure 5a And Figure 5b Fig. 5 shows a signaling diagram of another process for discovering an NF service producer in a communication system. Steps 1 to 3 in Fig. 5 are the same as steps 1 to 3 in Fig. 4 and are thus not shown.
[0193] UDM 1 may be configured to provide services to an NF service consumer from domain fqdn 1.
[0194] In step 1, UDM 1 may send a registration request to the NRF. The registration request may include the complete (i.e., original) profile of UDM 1 (including the allowedNFDomains attribute set to fqdn 1).
[0195] UDM 2 may be configured to provide services to an NF service consumer from domain fqdn 2.
[0196] In step 2, UDM 2 may send a registration request to the NRF. The registration request may include the complete (i.e., original) profile of UDM 2 (including the allowedNFDomains attribute set to fqdn 2).
[0197] In step 3, AMF 1 may send a service request to the SCP. The service request may include discovery query parameters (e.g., target-nf-type: UDM, requester-nf-type: AMF, and requester-nf-instance-fqdn: fqdn1). The discovery query parameters may include AMF 1 details (e.g., requester-nf-type: AMF and requester-nf-instance-fqdn: fqdn 1).
[0198] In step 4, the SCP may send a discovery request to the NRF. The discovery request may include discovery query parameters (e.g., target-nf-type: UDM, requester-nf-type: AMF, requester-nf-instance-fqdn: fqdn 1). In addition, the discovery request includes new discovery query parameters to request discovery of the complete (i.e., original) profile of the UDM (i.e., original-profile: true).
[0199] The NRF can determine that the SCP is allowed to discover the complete (i.e., original) profile of the UDM profile that matches the discovery query parameters including the "allowedXXX" attribute (except for the parameters for transmitting NF service consumer details if any).
[0200] In step 5, the SCP can send the complete (i.e., original) profile of UDM 1 including the "allowedXXX" attribute. The SCP can also send the complete (i.e., original) profile of UDM 2 including the "allowedXXX" attribute.
[0201] The SCP can determine that AMF 1 is authorized to consume services from UDM 1 based on the "allowedXXX" attribute of the complete (i.e., original) profile of UDM 1 stored by the SCP.
[0202] In step 6, the SCP can send a service request to UDM 1 on behalf of AMF 1.
[0203] In step 7, AMF 2 can send a service request to the SCP. The service request can include discovery query parameters (e.g., target-nf-type: UDM, requester-nf-type: AMF, and requester-nf-instance-fqdn: fqdn2). The discovery query parameters can include AMF 2 details (e.g., requester-nf-type: AMF and requester-nf-instance-fqdn: fqdn 2).
[0204] The SCP can not send a new discovery request to the NRF and can not receive a new discovery response. The SCP can reuse the previous discovery response. The SCP can determine that AMF 2 is authorized to consume services from UDM 2 based on the "allowedXXX" attribute of the complete (i.e., original) profile of UDM 2 stored by the SCP.
[0205] In step 8, the SCP can send a service request to UDM 2 on behalf of AMF 2.
[0206] Figure 6 A block diagram showing a method for discovering an NF service producer in a communication system (e.g., performed by the SCP) is shown.
[0207] In step 600, the SCP can receive a request from an NF service consumer to consume services from an NF service producer, the request including NF service consumer details.
[0208] In step 602, the SCP may send a request to the NRF, which is used to discover the profile of the NF service producer including the authorization attributes;
[0209] In step 604, the SCP may receive from the NRF the profile of the NF service producer including the authorization attributes.
[0210] In step 606, based on the authorization attributes and the NF service consumer details, the SCP may determine whether the NF service consumer is allowed to consume the service from the network function service producer.
[0211] The SCP may determine, based on the authorization attributes and the NF service consumer details, that the NF service consumer is allowed to consume the service from the NF service producer. The SCP may send a service request to the NF service producer to consume the service from the NF service producer.
[0212] The SCP may receive from another NF service consumer a request to consume the service from the NF service producer, and the request includes other NF service consumer details. The SCP may determine, based on the authorization attributes and the other NF service consumer details, whether the other NF service consumer is allowed to consume the service from the NF service producer.
[0213] The SCP may store the profile of the NF service producer including the authorization attributes.
[0214] The request from the SCP to discover the profile of the NF service producer including the authorization attributes includes: an indication to discover the complete profile of the NF service producer including the authorization attributes.
[0215] The SCP may send a request to the NRF, which is used to discover the profile of the NF service producer including the authorization attributes and another profile of another NF service producer including other authorization attributes, where the NF service producer and the other NF service producer have the same network function type. The SCP may receive from the NRF the profile of the NF service producer including the authorization attributes and another profile of another NF service producer including other authorization attributes. The SCP may determine, based on the authorization attributes and the NF service consumer details, whether the NF service consumer is allowed to consume the service from the NF service producer. The SCP may determine, based on the other authorization attributes and the other NF service consumer details, whether another NF service consumer is allowed to consume the service from another NF service producer.
[0216] Figure 7 A block diagram showing a method for discovering an NF service producer in a communication system (e.g., performed by the NRF) is shown.
[0217] In step 700, the NRF may receive a request from the SCP to discover a profile of an NF service producer including authorized attributes.
[0218] In step 702, the NRF may determine that the SCP is allowed to discover a profile of an NF service producer including authorized attributes.
[0219] In step 704, the NRF may send to the SCP a profile of an NF service producer including authorized attributes.
[0220] The NRF may receive from the SCP a request to discover a profile of another NF service producer including authorized attributes. The NRF may determine that the SCP is not allowed to discover profiles of other NF service producers including authorized attributes. The NRF may reject the request or send to the SCP a profile of an NF service producer that does not include authorized attributes.
[0221] The NRF may indicate whether the SCP is allowed to discover a profile of a network function service producer based on static authorization configured in the device, and determine that the SCP is allowed to discover a profile of an NF service producer including authorized attributes. The NRF may determine that the SCP is allowed to discover a profile of an NF service producer including authorized attributes based on an access token received in a request received from the SCP, the request being to discover a profile of an NF service producer including authorized attributes.
[0222] A request from the SCP to discover a profile of a network function service producer including authorized attributes includes an indication to receive an original or complete profile of an NF service producer including authorized attributes.
[0223] Authorized attributes may include at least one of the following: the type of network function service consumer allowed to consume the services of the NF service producer, PLMN, standalone non-public network, network slice, or domain name.
[0224] NF service consumer details may include at least one of the following: the type of NF service consumer, PLMN, standalone non-public network, network slice, or domain name.
[0225] Figure 8 A schematic representation of a non-volatile storage medium storing instructions and / or parameters 8000 is shown, which when executed by a processor allows the processor to execute Figure 6 and Figure 7 one or more steps in the method of
[0226] Note that while example embodiments are described above, several variations and modifications may be made to the solution of the present disclosure without departing from the scope of the present invention.
[0227] It should be understood that although the above concepts have been discussed in the context of 5GS, one or more of these concepts may be applicable to other cellular systems.
[0228] Accordingly, embodiments may vary within the scope of the appended claims. In general, some embodiments may be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software executed by a controller, microprocessor, or other computing device, but the embodiments are not limited thereto. Although various embodiments may be shown or described as block diagrams, flowcharts, or using some other graphical representation, it is well understood that the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general purpose hardware or controllers or other computing devices, or some combination thereof, as non-limiting examples.
[0229] Embodiments may be implemented by computer software stored in a memory and may be executed by at least one data processor of the entities involved, or by hardware, or by a combination of software and hardware. Additionally, in this regard, it should be noted that, for example Figure 6 and Figure 7 any process in may represent program steps, or interconnected logic circuits, blocks, and functions, or a combination of program steps and logic circuits, blocks, and functions. The software may be stored on a physical medium, such as a memory chip or a memory block implemented within a processor, a magnetic medium such as a hard disk or a floppy disk, and an optical medium such as, for example, a DVD and its data variant CD.
[0230] The memory may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor may be of any type suitable for the local technical environment and may include, as non-limiting examples, one or more of the following: general purpose computers, dedicated computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASICs), gate-level circuits, and processors based on multi-core processor architectures.
[0231] Alternatively or additionally, some embodiments may be implemented using circuitry. The circuitry may be configured to perform one or more of the previously described functions and / or method steps. The circuitry may be incorporated in a base station and / or a communication device.
[0232] As used in this application, the term "circuitry" may refer to one or more or all of the following:
[0233] (a) Implementation only by hardware circuits (such as implementation only in analog and / or digital circuitry);
[0234] (b) A combination of hardware circuits and software, such as:
[0235] (i) A combination of (multiple) analog and / or digital hardware circuits with software / firmware, and
[0236] (ii) Any part of (multiple) hardware processors with software (including (multiple) digital signal processors), software, and (multiple) memories, which work together to enable a device (such as a communication device or a base station) to perform the various functions described previously; and
[0237] (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a part of (multiple) microprocessors, whose operation requires software (such as firmware), but the software can be absent when not needed.
[0238] This definition of circuitry applies to all uses of the term in this application, including in any claims. As another example, as used in this application, the term circuitry also encompasses implementations of only hardware circuits or processors (or multiple processors) or parts of hardware circuits or processors and their accompanying software and / or firmware. The term circuitry also encompasses, for example, integrated devices.
[0239] The above description provides a complete and informative description of some embodiments by way of exemplary and non - limiting examples. However, when the above description is read in conjunction with the accompanying drawings and the appended claims, various modifications and adaptations will become apparent to those skilled in the relevant art. However, all such and similar teachings of modifications will still fall within the scope defined by the appended claims.
Claims
1. An apparatus, comprising: At least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured to, with the at least one processor, cause the apparatus to at least: Receive, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details; Send a request to a network function repository function, the request for discovering a profile of the network function service producer including authorization attributes; Receive, from the network function repository function, the profile of the network function service producer including the authorization attributes; And Based on the authorization attributes and the network function service consumer details, determine whether the network function service consumer is permitted to consume the service from the network function service producer.
2. The apparatus according to claim 1, wherein the apparatus is a service communication proxy.
3. The apparatus according to claim 1 or claim 2, wherein the at least one memory and the computer code are configured to, with the at least one processor, cause the apparatus to at least: Based on the authorization attributes and the network function service consumer details, determine that the network function service consumer is permitted to consume the service from the network function service producer; and Send the service request to the network function service producer to consume the service from the network function service producer.
4. The apparatus according to any one of claims 1 to 3, wherein the at least one memory and the computer code are configured to, with the at least one processor, cause the apparatus to at least: Receive, from another network function service consumer, a request to consume a service from the network function service producer, the request including other network function service consumer details; Based on the authorization attributes and the other network function service consumer details, determine whether the other network function service consumer is permitted to consume the service from the network function service producer.
5. The apparatus according to any one of claims 1 to 4, wherein the at least one memory and the computer code are configured to, with the at least one processor, cause the apparatus to at least: Store the profile of the network function service producer including the authorization attributes.
6. The apparatus according to any one of claims 1 to 5, wherein the request from the apparatus for discovering the profile of the network function service producer including the authorized attribute comprises: An indication for discovering a complete profile of the network function service producer including the authorization attributes.
7. The apparatus according to any one of claims 1 to 6, wherein the at least one memory and the computer code are configured to, with the at least one processor, cause the apparatus to at least: Send a request to a network function repository function, the request for discovering a profile of a network function service producer including authorization attributes and another profile of another network function service producer including other authorization attributes, wherein the network function service producer and the other network function service producer have the same network function type; Receive the profile of the network function service producer including the authorization attribute and the other profile of the other network function service producer including the other authorization attribute from the network function repository function; And Based on the authorized attributes and network function service consumer details, determine whether the network function service consumer is allowed to consume the service from the network function service producer; and Based on the other authorized attributes and other network function service consumer details, determine whether another network function service consumer is allowed to consume the service from the other network function service producer.
8. An apparatus, comprising: At least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured to, together with the at least one processor, cause the device to at least: Receive, from another device, a request to discover a profile of a network function service producer including authorized attributes; Determine that the other device is allowed to discover the profile of the network function service producer including the authorized attributes; and Send to the other device the profile of the network function service producer including the authorized attributes.
9. The device according to claim 8, wherein the device is a network function repository function.
10. The device according to claim 8 or claim 9, wherein the other device is a service communication proxy.
11. The device according to any one of claims 8 to 10, wherein the at least one memory and the computer code are configured to, together with the at least one processor, cause the device to at least: Receive, from the other device, a request to discover a profile of another network function service producer including authorized attributes; Determine that the other device is not allowed to discover the profile of the other network function service producer including the authorized attributes; and Deny the request or send to the other device the profile of the network function service producer that does not include the authorized attributes.
12. The device according to any one of claims 8 to 11, wherein the at least one memory and the computer code are configured to, together with the at least one processor, cause the device to at least: Based on the following, determine that the other device is allowed to discover the profile of the network function service producer including the authorized attributes: Static authorization configured in the device, indicating whether the other device is allowed to discover the profile of the network function service producer; or An access token received in the request received from the other device, the request being to discover the profile of the network function service producer including the authorized attributes.
13. The apparatus according to any one of claims 9 to 12, wherein the request from the other apparatus to discover the profile of the network function service producer including the authorized attribute comprises: An indication to receive the original profile or the complete profile of the network function service producer including the authorized attributes.
14. The device according to any one of claims 1 to 13, wherein the authorized attributes include at least one of the following: the type of network function service consumer allowed to consume the service of the network function service producer, a public land mobile network, a stand-alone non-public network, a network slice, or a domain name.
15. The apparatus according to any one of claims 1 to 14, wherein the network function service consumer details include at least one of the following: the type of the network function service consumer, a public land mobile network, a stand-alone non-public network, a network slice, or a domain name.
16. A method, comprising: Receiving, from a network function service consumer, a request to consume a service from a network function service producer, the request including network function service consumer details. Sending a request to a network function repository function, the request for discovering a profile of the network function service producer including authorization attributes. Receiving, from the network function repository function, the profile of the network function service producer including the authorization attributes. And Determining, based on the authorization attributes and the network function service consumer details, whether the network function service consumer is permitted to consume the service from the network function service producer.
17. A method, comprising: Receiving, from another apparatus, a request to discover a profile of a network function service producer including authorization attributes. Determining that the other apparatus is permitted to discover the profile of the network function service producer including the authorization attributes. And Sending to the other apparatus the profile of the network function service producer including the authorization attributes.
18. A computer program comprising computer-executable instructions that, when run on one or more processors, perform the steps of the method according to claim 16 or claim 17.