Authorization of edge enabler client (EEC) context transfer
By using a token mechanism to generate OAuth 2.0 access tokens in the edge computing system, the security threat of EEC context information during application context relocation is resolved, enabling secure information transfer and authorization control under unreliable communication conditions, thus enhancing system security.
Patent Information
- Application Number
- CN202480030523.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-04-07
- Filing Date
- 2024-04-05
- Publication Date
- 2025-12-09
AI Technical Summary
In edge computing, EEC context information is subject to security threats and potential malicious behavior during application context relocation, which may lead to functional impairment or attack risks. Existing technologies are unable to effectively guarantee the security and authorization control of information transmission.
By employing a token mechanism, an OAuth 2.0 access token is generated through negotiation between the EEC and the token server. This limits the granularity and timing of context information transfer, enabling authorization and control of the EEC context and ensuring the secure transfer of information between the source EES and the target EES.
It enables secure transfer of EEC context information under unreliable communication conditions, enhances the security and authorization control of edge computing systems, and reduces the risk of malicious behavior.
Smart Images

Figure CN121100511A_ABST
Abstract
Description
[0001] Related applications This application claims the benefit and priority of U.S. Provisional Patent Application No. 63 / 458,015, filed April 7, 2023, entitled “Authorization of Edge Enabler Client (EEC) Context Transfer,” the entire contents of which are incorporated herein by reference. Background Technology
[0002] Edge computing enables services to be hosted near user devices or other client devices, providing low-latency and high-bandwidth services while reducing traffic across the network backbone. These services can offer a wide range of capabilities, including virtual and augmented reality, real-time video games, teleconferencing, autonomous driving, and AI-enhanced applications.
[0003] In many embodiments, the Edge Enabler Client (EEC) can be executed by a client device, such as a Wireless Transmitter Receiver Unit (WTRU), User Equipment (UE), or other computing device, to communicate with an Edge Configuration Server (ECS) and / or an Edge Enabler Server (EES). The EES can provide EEC context information, such as WTRU or UE identity information, location information, Application Client (AC) profiles, service session context information, and / or other information. During the Application Context Relocation (ACR) process, this context information can be transmitted from the source EES (S-EES) to the target EES (T-EES). However, this information can be sensitive, and infiltration or interception by malicious actors could lead to security threats, functional impairment, or the addition of attack vectors. Summary of the Invention
[0004] This document describes embodiments of systems and methods for EEC context transfer security and authorization. In some embodiments, an EEC may authorize and / or consent to the transfer of EEC context information from the S-EES to the T-EES. According to embodiments, authorization may have different levels of granularity, including authorizing the transfer of EEC context to a specific T-EES, authorizing specific transfer operations, authorizing the transfer of specific information, etc. In some embodiments, an EEC may authorize specific transfer operations as part of a specific ACR process. For example, in some such embodiments, for each ACR process, each EEC context transfer from the S-EES to the T-EES for an EEC may be authorized individually or solely by that EEC, even if the EEC does not participate in the selection of the T-EES.
[0005] In various embodiments, the EEC context can be relocated from the S-EES to the T-EES via push (S-EES initiated) or pull (T-EES initiated) approaches. In some ACR procedures, the EEC context can be transferred even when communication between the EEC and the S-EES is not possible or unreliable. Thus, in some embodiments, the EEC context transfer mechanism can allow the EEC to authorize the context transfer even when communication between the EEC and the T-EES is not possible or unreliable during the context transfer. BRIEF DESCRIPTION OF DRAWINGS
[0006] A more detailed understanding can be had from the following description, given by way of example in conjunction with the accompanying drawings wherein: FIG. 1A is a system diagram illustrating an example communications system in which one or more disclosed embodiments can be implemented; FIG. 1B is a system diagram illustrating an example wireless transmit / receive unit (WTRU) that can be used within the communications system FIG. 1A illustrated in FIG. 1A; FIG. 1C is a system diagram illustrating an example radio access network (RAN) and an example core network (CN) that can be used within the communications system FIG. 1A illustrated in FIG. 1A; FIG. 1D is a system diagram illustrating a further example RAN and a further example CN that can be used within the communications system FIG. 1A illustrated in FIG. 1A; FIG. 2 is a block diagram of an embodiment of a system for enabling edge applications; FIG. 3 is a flow diagram of an embodiment of a method for application context relocation; FIG. 4 is a flow diagram of an embodiment of a method of EEC authorization for EEC context transfer in the case where the EEC initiates and the EEC context is pulled from the S-EES to the T-EES; FIG. 5 is a flow diagram of an embodiment of a method of EEC authorization for EEC context transfer in the case where there is no EEC initiation and the EEC context is pushed from the S-EES to the T-EES; FIG. 6 is a flow diagram of an embodiment of a method of EEC authorization for EEC context transfer in the case where the EEC initiates and the EEC context is pushed from the S-EES to the T-EES; FIG. 7A andFIG. 7B is a flow diagram of an embodiment of a method of EEC authorization for EEC context transfer; and FIG. 8 is a flow diagram of an embodiment of a method of EEC authorization for EEC context transfer. DETAILED DESCRIPTION
[0007] Edge computing enables services to be hosted near user equipment or other client devices, and can provide low latency and high bandwidth services while reducing traffic across a network backbone. Such services can provide a large number of capabilities, including virtual and augmented reality, real-time video games, teleconferencing, autonomous driving, and artificial intelligence enhanced applications.
[0008] In many embodiments, an edge enabler client (EEC) can be executed by a client device, such as a wireless transmit receive unit (WTRU), user equipment (UE), or other computing device, to communicate with an edge configuration server (ECS) and / or an edge enabler server (EES). The EES can provide EEC context information, such as WTRU or UE identity information, location information, application client (AC) profiles, service session context information, and / or other information. During an application context relocation (ACR) procedure, context information can be sent from a source EES (S-EES) to a target EES (T-EES). However, this information can be sensitive, and penetration or interception by a malicious actor can result in security threats, impaired functionality, or additional attack vectors.
[0009] Embodiments of systems and methods for EEC context transfer security and authorization are described herein. In some embodiments, an EEC can authorize and / or consent to the transfer of EEC context information from an S-EES to a T-EES. According to embodiments, the authorization can have different levels of granularity, including authorization to transfer EEC context to a particular T-EES, authorization of a particular transfer operation, authorization of particular information being transferred, and / or the like. In some embodiments, an EEC can authorize a particular transfer operation as part of a particular ACR procedure. For example, in some such embodiments, each EEC context transfer from an S-EES to a T-EES by an EEC can be individually or independently authorized by that EEC for each ACR procedure, even if the EEC did not participate in the selection of the T-EES.
[0010] In a first aspect, the present disclosure relates to embodiments of methods and systems for EEC authorization for EEC context transfer in scenarios where the ACR procedure is initiated by the EEC and the EEC context is pulled from the S-EES to the T-EES. In these embodiments, the EEC can obtain a token prior to any entity in the edge enablement layer (EEL) determining to initiate the ACR procedure. The EEC can negotiate with the token server to limit which entities can use the token and / or other restrictions (e.g., time, date, specific application, etc.). The EEC can provide the token to the S-EES. The S-EES can then use the token when authorizing a request from the T-EES to retrieve the EEC context. In some such embodiments, the EEC can be able to exert some degree of control over where its context can be transferred to even if the S-EES cannot communicate with the EEC when context transfer is needed.
[0011] In another aspect, the present disclosure relates to embodiments of methods and systems for EEC authorization for EEC context transfer in scenarios where the ACR procedure is not initiated by the EEC and the EEC context is pushed from the S-EES to the T-EES. In these embodiments, the EEC can obtain a token prior to any entity in the EEL determining to initiate the ACR procedure. The EEC can negotiate with the token server to limit which entities can use the token and / or other restrictions (e.g., time, date, specific application, etc.). The EEC can provide the token to the S-EES. The S-EES can then use the token when transferring context to the T-EES. In some such embodiments, the EEC can be able to exert some degree of control over where its context can be transferred to even if the S-EES cannot communicate with the EEC when context transfer is needed.
[0012] In still another aspect, the present disclosure relates to embodiments of methods and systems for EEC authorization for EEC context transfer in scenarios where the ACR procedure is initiated by the EEC and the EEC context is pushed from the S-EES to the T-EES. In these embodiments, the EEC determines to perform the ACR procedure, obtains a token, and sends the token to the S-EES. The S-EES can then provide the token to the T-EES so that the T-EES can authenticate that it is permitted to receive the EEC's context.
[0013] Various embodiments of these systems and methods use a token to authorize EEC context transfer from an S-EES to a T-EES. In some embodiments, the token can be an OAuth 2.0 access token, and can be generated by a server (e.g., a token server, an edge configuration server (ECS)) or another device. In some embodiments, the server that generates the token can be referred to as an authorization server. In various embodiments, an EEC can authorize the transfer of context information from an S-EES to a T-EES. The authorization can be a type of consent, and thus, in such embodiments, the EEC can consent to the transfer of context information from an S-EES to a T-EES. The EEC can operate on behalf of or by a user, and thus, this type of consent can be referred to as user consent. The context information transferred from a first EES to a second EES can include information related to one or more application layer sessions.
[0014] For reference, various abbreviations and acronyms are used herein, such as the following: 3GPP Third Generation Partnership Project 5G Fifth Generation AC Application Client ACR Application Context Relocation ACT Application Context Transfer DNN Data Network Name EAS Edge Application Server ECS Edge Configuration Server ECSP Edge Computing Service Provider EDN Edge Data Network EEC Edge Enabler Client EEL Edge Enabler Layer EES Edge Enabler Server FQDN Fully Qualified Domain Name KI Key Issue KPI Key Performance Indicator MNO Mobile Network Operator NMC Notification Management Client NMS Notification Management Server QoS Quality of Service SCP Service Continuity Planning S-EAS Source Edge Application Server S-EES Source Edge Enabler Server TR Technical Report TS Technical Specification T-EAS Target Edge Application Server T-EES Target Edge Enabler Server UID User Identifier URI Universal Resource Identifier UE User Equipment WLAN Wireless Local Area Network and related technologies (IEEE 802.1 domain) WTRU Wireless Transmit Receive Unit.
[0015] Before discussing embodiments of the systems and methods discussed herein, it can be helpful to discuss embodiments of communication systems and devices that can be used with the systems and methods.
[0016] FIG. 1A is a system diagram illustrating an example communications system 100 in which one or more disclosed embodiments can be implemented. The communications system 100 can be a multiple access system that provides content, such as voice, data, video, messaging, broadcast, etc., to multiple wireless users. The communications system 100 can enable multiple wireless users to access such content through the sharing of system resources, including wireless bandwidth. For example, the communications systems 100 can employ one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), zero-tail unique-word discrete Fourier transform spread OFDM (ZT-UW-DTS-S-OFDM), unique word OFDM (UW-OFDM), resource block-filtered OFDM, filter bank multicarrier (FBMC), and the like.
[0017] As FIG. 1AAs shown, the communication system 100 can include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104, a core network (CN) 106, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, though it will be appreciated that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of the WTRUs 102a, 102b, 102c, 102d can be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which can be referred to as a station (STA), can be configured to transmit and / or receive wireless signals, and can include a user equipment (UE), a mobile station, a fixed or mobile subscriber unit, a subscription-based unit, a pager, a cellular telephone, a personal digital assistant (PDA), a smartphone, a laptop, a netbook, a personal computer, a wireless sensor, a hotspot or Mi-Fi device, an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot or other wireless devices operating in an industrial and / or
[0018] The communication system 100 can also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b can be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d to facilitate access to one or more communication networks, such as the CN 106, the Internet 110, and / or the other networks 112. By way of example, the base stations 114a, 114b can be a base transceiver station (BTS), a Node-B, an eNode B (eNB), a Home Node B, a Home eNode B, a next generation Node-B (such as gNode Bs (gNB), a new radio (NR) Node B, a site controller, an access point (AP), a wireless router, and so on. While the base stations 114a, 114b are each depicted as a single element, it will be appreciated that the base stations 114a, 114b can include any number of interconnected base stations and / or network elements.
[0019] The base stations 114a can be part of the RAN 104, which can also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, etc. The base stations 114a and / or the base stations 114b can be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which can be referred to as a cell (not shown). The frequencies can be in the licensed spectrum, the unlicensed spectrum, or a combination of the licensed and unlicensed spectrums. A cell can provide coverage for a wireless service to a particular geographic area, which can be relatively fixed or can change over time. The cell can further be split into cell sectors, which can each be associated with a base station. For example, the cell associated with the base station 114a can be split into three sectors. Thus, in one embodiment, the base station 114a can include three transceivers, one for each sector of the cell. In an embodiment, the base station 114a can employ multiple-input multiple-output (MIMO) techniques, and can utilize multiple transceivers for each sector of the cell. For example, beamforming can be used to transmit and / or receive signals in a desired spatial direction.
[0020] The base stations 114a, 114b can communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which can be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 can be established using any suitable radio access technology (RAT).
[0021] More specifically, as noted above, the communications system 100 can be a multiple access system and can employ one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, and the like. For example, the base station 114a in the RAN 104 and the WTRUs 102a, 102b, 102c can implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which can establish the air interface 116 using wideband CDMA (WCDMA). WCDMA can include communication protocols such as High-Speed Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA can include High-Speed Downlink (DL) Packet Access (HSDPA) and / or High-Speed Uplink (UL) Packet Access (HSUPA).
[0022] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c can implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which can establish the air interface 116 using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).
[0023] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c can implement a radio technology such as NR Radio Access, which can establish the air interface 116 using NR.
[0024] In an embodiment, the base station 114a and the WTRUs 102a, 102b, 102c can implement multiple radio access technologies. For example, the base station 114a and WTRUs 102a, 102b, 102c can implement LTE wireless access and NR wireless access together, for instance using dual connectivity (DC) principles. Thus, the air interface utilized by WTRUs 102a, 102b, 102c can be characterized by multiple types of radio access technologies and / or transmissions sent to / from multiple types of base stations (e.g., a eNB and a gNB), including in the case of dual connectivity.
[0025] In other embodiments, the base station 114a and the WTRUs 102a, 102b, 102c can implement radio technologies such as IEEE 802.11 (i.e., Wireless Fidelity (WiFi), IEEE 802.16 (i.e., Worldwide Interoperability for Microwave Access (WiMAX)), CDMA2000, CDMA2000 IX, CDMA2000 EV-DO, Interim Standard 2000 (IS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), GSM EDGE (GERAN), and the like.
[0026] For example, FIG. 1AThe base station 114b in the embodiment can be a wireless router, Home Node B, Home eNode B, or access point, and can utilize any suitable RAT for facilitating wireless connectivity access to the Internet, such as IEEE 802.11, Bluetooth, code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), Global System for Mobile communications (GSM), Voice over Internet Protocol (VoIP), Voice FIG. 1A The base station 114b in the embodiment can be a wireless router, Home Node B, Home eNode B, or access point, and can utilize any suitable RAT for facilitating wireless connectivity access to the Internet, such as IEEE 802.11, Bluetooth, code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), Global System for Mobile communications (GSM), Voice over Internet Protocol (VoIP), Voice
[0027] The RAN 104 can be in communication with the CN 106, which can be any type of network configured to provide voice, data, applications, and / or voice over internet protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data can have varying quality of service (QoS) requirements, such as differing throughput requirements, latency requirements, error tolerance requirements, reliability requirements, data throughput requirements, mobility requirements, and the like. The CN 106 can provide call control, billing services, mobile location-based services, pre-paid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions, such as user authentication. Although not shown in the FIG. 1A Although not shown in the FIG. 1, it will be appreciated that the RAN 104 and / or the CN 106 can be in direct or indirect communication with other RANs that employ the same RAT as the RAN 104 or a different RAT. For example, in addition to being connected to the RAN 104, which can employ a NR radio technology, the CN 106 can also be in communication with another RAN (not shown) employing a GSM, UMTS, CDMA 2000, WiMAX, E-UTRA, or WiFi radio technology.
[0028] CN 106 can also act as a gateway for WTRUs 102a, 102b, 102c, and 102d to access PSTN 108, the Internet 110, and / or other networks 112. PSTN 108 may include a circuit-switched telephone network providing Common Old-Style Telephone Service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices using common communication protocols such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and / or Internet Protocol (IP) from the TCP / IP Internet Protocol suite. Network 112 may include wired and / or wireless communication networks owned and / or operated by other service providers. For example, network 112 may include another CN connected to one or more RANs, which may use the same RAT as RAN 104 or a different RAT.
[0029] Some or all of the WTRUs 102a, 102b, 102c, and 102d in the communication system 100 may include multi-mode capabilities (e.g., WTRUs 102a, 102b, 102c, and 102d may include multiple transceivers for communicating with different wireless networks via different wireless links). For example, FIG. 1A The WTRU 102c shown can be configured to communicate with base stations 114a and 114b, where base station 114a can use cellular-based radio technology and base station 114b can use IEEE 802 radio technology.
[0030] FIG. 1B This is a system diagram illustrating example WTRU 102. (Example:) FIG. 1B As shown, WTRU 102 may include a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keyboard 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power supply 134, a Global Positioning System (GPS) chipset 136, and / or other peripheral devices 138, etc. It will be appreciated that WTRU 102 may include any sub-combination of the above-described elements while remaining consistent with the embodiments.
[0031] The processor 118 can be a general purpose processor, a special purpose processor, a conventional processor, a digital signal processor (DSP), a plurality of microprocessors, one or more microprocessors in association with a DSP core, a controller, a microcontroller, Application Specific Integrated Circuits (ASICs), Field Programmable Gate Array (FPGAs), any other type of integrated circuit (IC), a state machine, and the like. The processor 118 can perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 can be coupled to the transceiver 120, which can be coupled to the transmit / receive element 122. While FIG. 1B The processor 118 and the transceiver 120 are depicted as separate components, it will be appreciated that the processor 118 and the transceiver 120 can be integrated together in an electronic package or chip.
[0032] The transmit / receive element 122 can be configured to transmit signals to, or receive signals from, a base station (e.g., the base station 114a) over the air interface 116. For example, in one embodiment, the transmit / receive element 122 can be an antenna configured to transmit and / or receive RF signals. In an embodiment, the transmit / receive element 122 can be an emitter / detector configured to transmit and / or receive IR, UV, or visible light signals, for example. In yet another embodiment, the transmit / receive element 122 can be configured to transmit and / or receive both RF and light signals. It will be appreciated that the transmit / receive element 122 can be configured to transmit and / or receive any combination of wireless signals.
[0033] Although the transmit / receive element 122 is depicted in the WTRU 102 FIG. 1B In one embodiment, the WTRU 102 can include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.
[0034] The transceiver 120 can be configured to modulate information to be transmitted by the transmit / receive element 122 and to demodulate information received by the transmit / receive element 122. As noted above, the WTRU 102 can have multi-mode capabilities. Thus, the transceiver 120 can include multiple transceivers for enabling the WTRU 102 to communicate via multiple RATs, such as NR and IEEE 802.11, for example.
[0035] The processor 118 of the WTRU 102 can be coupled to, and can receive user input data from, the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or organic light-emitting diode (OLED) display unit). The processor 118 can also output user data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. In addition, the processor 118 can access information from, and store data in, any type of suitable memory, such as the non-removable memory 130 and / or the removable memory 132. The non-removable memory 130 can include random-access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 can include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, and the like. In other embodiments, the processor 118 can access information from, and store data in, memory that is not physically located on the WTRU 102, such as on a server or a home computer (not shown).
[0036] The processor 118 can receive power from the power source 134 and can be configured to distribute and / or control the power to the other components in the WTRU 102. The power source 134 can be any suitable device for powering the WTRU 102. For example, the power source 134 can include one or more dry cell batteries (e.g., nickel-cadmium (NiCd), nickel-zinc (NiZn), nickel metal hydride (NiMH), lithium-ion (Li-ion), etc.), solar cells, fuel cells, and the like.
[0037] The processor 118 can also be coupled to the GPS chipset 136, which can be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or in lieu of, the information from the GPS chipset 136, the WTRU 102 can receive location information over the air interface 116 from a base station (e.g., base stations 114a, 114b) and / or determine its location based on the timing of the signals being received from two or more nearby base stations. It will be appreciated that the WTRU 102 can acquire location information by way of any suitable location-determination method while remaining consistent with an embodiment.
[0038] The processor 118 can further be coupled to other peripherals 138 that can include one or more software and / or hardware modules that provide additional features, functionality and / or wired or wireless connectivity. For example, the peripherals 138 can include an accelerometer, an e-compass, a satellite transceiver, a digital camera (e.g., for photographs or video), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands -free headset, a Bluetooth® module, a frequency modulated (FM) radio unit, a digital music player, a media player, a video game player module, an Internet browser, a virtual reality and / or an augmented reality (VR / A R) device, an activity tracker, and the like. The peripherals 138 can include one or more sensors. The sensors can be one or more of a gyroscope, an accelerometer, a hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor, a geolocation sensor, an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, a humidity sensor, and the like.
[0039] The WTRU 102 can include a full duplex radio for which transmission and reception of some or all signals (e.g., associated with particular subframes for both the UL (e.g., for transmission) and DL (e.g., for reception) can be concurrent and / or simultaneous. The full duplex radio can include an interference management unit 139 to reduce and / or substantially eliminate self-interference and / or cross- interference due to concurrent transmission and reception. In an embodiment, the WTRU 102 can include a half duplex radio for which transmission and reception of some or all signals (e.g., associated with particular subframes for either the UL (e.g., for transmission) or the DL (e.g., for reception)).
[0040] FIG. 1C is a system diagram illustrating the RAN 104 and the CN 106 according to an embodiment. As described above, the RAN 104 can employ an E-UTRA radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 can also be in communication with the CN 106.
[0041] The RAN 104 can include eNode-Bs 160a, 160b, 160c, though it will be appreciated that the RAN 104 can include any number of eNode-Bs while remaining consistent with an embodiment. The eNode-Bs 160a, 160b, 160c can each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the eNode-Bs 160a, 160b, 160c can implement MIMO technology. Thus, the eNode-B 160a, for example, can use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a.
[0042] Each of the eNode-Bs 160a, 160b, 160c can be associated with a particular cell (not shown) and can be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, and the like. As shown, the eNode-Bs 160a, 160b, 160c can communicate with one another over an X2 interface. FIG. 1C
[0043] FIG. 1C The CN 106 can include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (PGW) 166, as shown. While the foregoing elements are depicted as part of the CN 106, it will be appreciated that any of these elements can be owned and / or operated by an entity other than the CN operator.
[0044] The MME 162 can be connected to each of the eNode-Bs 162a, 162b, 162c in the RAN 104 via an S1 interface and can serve as a control node. For example, the MME 162 can be responsible for authenticating users of the WTRUs 102a, 102b, 102c, bearer activation / deactivation, selecting a particular serving gateway during an initial attach of the WTRUs 102a, 102b, 102c, and the like. The MME 162 can provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as GSM and / or WCDMA.
[0045] The SGW 164 can be connected to each of the eNode Bs 160a, 160b, 160c in the RAN 104 via the S1 interface. The SGW 164 can generally route and forward user data packets to / from the WTRUs 102a, 102b, 102c. The SGW 164 can perform other functions, such as anchoring user planes during inter-eNode B handovers, triggering paging when DL data is available for the WTRUs 102a, 102b, 102c, managing and storing contexts of the WTRUs 102a, 102b, 102c, and the like.
[0046] The SGW 164 can be connected to the PGW 166, which can provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.
[0047] The CN 106 can also serve as a gateway for the WTRUs 102a, 102b, 102c to access the PSTN 108, the Internet 110, and / or the other networks 112. The PSTN 108 can include circuit-switched telephone networks that provide infrastructure for the provision of voice, video, and / or data services to users. The CN 106 can include IP gateways, such as an IP multimedia subsystem (IMS), that serve as an interface between the CN 106 and the PSTN 108. The other networks 112 can include other wired and / or wireless networks that are owned and / or operated by other service providers.
[0048] Although WTRUs are described in FIG. 1A to FIG. 1D representative embodiments as wireless terminals, it is contemplated that in certain representative embodiments such terminals can use, e.g., temporarily or permanently, a wired communication interface to a communication network.
[0049] In representative embodiments, the other networks 112 can be a WLAN.
[0050] A WLAN in Infrastructure Basic Service Set (BSS) mode can have an Access Point (AP) which can be used by one or more stations (STAs) associated with the AP to obtain connectivity to each other or to external networks outside the BSS. The AP can have an interface to a Distribution System (DS) or another type of wired / wireless network that can carry traffic in both directions between STAs and / or between STAs and the external network. Traffic between STAs can pass through the AP and / or another STA acting as a relay. A WLAN operating in an Independent BSS (IBSS) mode can not have an AP, and the STAs in the IBSS can communicate directly with each other through a wireless link.
[0051] When using an 802.11 ac infrastructure mode of operation or similar, an AP can transmit beacons on a fixed channel, such as a primary channel. The primary channel can be a fixed width (e.g., 20 MHz wide bandwidth) or a dynamically set width. The primary channel can be the operating channel of the BSS and can be used by STAs to establish a connection with the AP. In certain representative embodiments, Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA) with collision avoidance can be implemented, for example, in 802.11 systems. For CSMA / CA, a STA including the AP (e.g., each STA) can sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a particular STA, the particular STA can back off. One STA (e.g., only one station) can transmit at any given time in a given BSS.
[0052] High Throughput (HT) STAs can use 40 MHz wide channels for communication, for example, via a combination of the primary 20 MHz channel with an adjacent or nonadjacent 20 MHz channel to form a 40 MHz wide channel.
[0053] Very High Throughput (VHT) STAs can support 20 MHz, 40 MHz, 80 MHz, and / or 160 MHz wide channels. The 40 MHz and / or 80 MHz channels can be formed by combining contiguous 20 MHz channels. A 160 MHz channel can be formed by combining 8 contiguous 20 MHz channels, or by combining two non-contiguous 80 MHz channels, which can be referred to as an 80+80 configuration. For the 80+80 configuration, after channel coding, the data can be passed through a segment parser that can divide the data into two streams. Inverse Fast Fourier Transform (IFFT) processing and time domain processing can be done on each stream separately. The streams can be mapped on to the two 80 MHz channels, and the data can be transmitted by a transmitting STA. At the receiver of the receiving STA, the above operations for the 80+80 configuration can be reversed, and the combined data can be sent to the Medium Access Control (MAC) layer.
[0054] Sub-1 GHz modes of operation are supported by 802.11af and 802.11ah. The channel operating bandwidths and carriers in 802.11af and 802.11ah are reduced relative to those used in 802.11η and 802.11ac. 802.11af supports 5 MHz, 10 MHz, and 20 MHz bandwidths in the TV White Space (TVWS) spectrum, and 802.11ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non-TVWS spectrum. According to a representative embodiment, 802.11ah can support metering / control / machine-type communications, such as MTC devices in a macro coverage area. MTC devices can have certain capabilities, e.g., limited capabilities, including support (e.g., only support) for certain and / or limited bandwidths. MTC devices can include a battery with a battery life above a threshold (e.g., to maintain a very long battery life).
[0055] WLAN systems that can support multiple channels and channel bandwidths (such as 802.11η, 802.11ac, 802.11af, and 802.11ah) include a channel that can be designated as the primary channel. The primary channel can have a bandwidth equal to the largest common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel can be set and / or limited by the STA that supports the smallest bandwidth operating mode among all STAs operating in the BSS. In the example of 802.11ah, for STAs that support (e.g., only support) 1 MHz mode, the primary channel can be 1 MHz wide, even if the AP and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or network allocation vector (NAV) settings can depend on the status of the primary channel. If the primary channel is busy with transmissions to the AP, for example, due to a STA that only supports 1 MHz operating mode, all available frequency bands can be considered busy, even if most of the available frequency bands are still idle.
[0056] In the United States, the available frequency bands that 802.11ah can use are from 902 MHz to 928 MHz. In Korea, the available frequency bands are from 917.5 MHz to 923.5 MHz. In Japan, the available frequency bands are from 916.5 MHz to 927.5 MHz. Depending on the country code, the total bandwidth available for 802.11ah is 6 MHz to 26 MHz.
[0057] FIG. 1D is a system diagram illustrating the RAN 104 and the CN 106 according to an embodiment. As described above, the RAN 104 can employ an NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 can also be in communication with the CN 106.
[0058] The RAN 104 can include gNBs 180a, 180b, 180c, although it will be appreciated that the RAN 104 can include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, 180c can each include one or more transceivers for communicating with the WTRUs 102a, 102b, 102c over the air interface 116. In one embodiment, the gNBs 180a, 180b, 180c can implement MIMO technology. For example, gNBs 180a, 180b can utilize beamforming to transmit signals to and / or receive signals from the gNBs 180a, 180b, 180c. Thus, the gNB 180a, for example, can use multiple antennas to transmit wireless signals to, and / or receive wireless signals from, the WTRU 102a. In an embodiment, the gNBs 180a, 180b, 180c can implement carrier aggregation technology. For example, the gNB 180a can transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers can be on unlicensed spectrum while the remaining component carriers can be on licensed spectrum. In an embodiment, the gNBs 180a, 180b, 180c can implement Coordinated Multi-Point (CoMP) technology. For example, WTRU 102a can receive coordinated transmissions from gNB 180a and gNB 180b (and / or gNB 180c).
[0059] The WTRUs 102a, 102b, 102c can communicate with gNBs 180a, 180b, 180c using transmissions associated with scalable numerology. For example, the OFDM symbol spacing and / or the OFDM subcarrier spacing can vary from transmission to transmission, from different cells, and / or for different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c can communicate with gNBs 180a, 180b, 180c using subframes or transmission time intervals (TTIs) of various or scalable lengths (e.g., containing different numbers of OFDM symbols and / or lasting different lengths of absolute time).
[0060] The gNBs 180a, 180b, 180c can be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In the standalone configuration, the WTRUs 102a, 102b, 102c can communicate with gNBs 180a, 180b, 180c without also accessing other RANs (e.g., such as eNode-Bs 160a, 160b, 160c). In the standalone configuration, the WTRUs 102a, 102b, 102c can utilize one or more of gNBs 180a, 180b, 180c as a mobility anchor point. In the standalone configuration, the WTRUs 102a, 102b, 102c can use signals
[0061] Each of the gNBs 180a, 180b, 180c can be associated with a particular cell (not shown) and can be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support of network slicing, DC, networking between NR and E-UTRA, routing of user plane data towards user plane functions (UPFs) 184a, 184b, routing of control plane information towards access and mobility management functions (AMFs) 182a, 182b, and / or the like. As shown, the gNBs 180a, 180b, 180c can communicate with one another over an Xn interface. FIG. 1D As shown, the gNBs 180a, 180b, 180c can be in communication with the AN 180a, 180b, 180c over an Xn interface.
[0062] FIG. 1DThe illustrated CN 106 can include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b, and possibly a Data Network (DN) 185a, 185b. While the foregoing elements are depicted as part of the CN 106, it will be appreciated that any of these elements can be owned and / or operated by an entity other than the CN operator.
[0063] The AMF 182a, 182b can be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 104 via an N2 interface and can serve as the control node. For example, the AMF 182a, 182b can be responsible for authenticating WTRUs 102a, 102b, 102c, supporting network slicing (e.g., handling different Protocol Data Unit (PDU) sessions in accordance with different requirements), selecting a particular SMF 183a, 183b, managing the WTRU 102a, 102b, 102c registration area, terminating non-access stratum (NAS) signaling, mobility management, and the like. Network slicing can be used by the AMF 182a, 182b to customize CN support for WTRUs 102a, 102b, 102c based on the type of service being accessed by the WTRU 102a, 102b, 102c. For example, different network slices can be established for different use cases such as services relying on ultra-reliable low latency (URLLC) access, services relying on enhanced massive mobile broadband (eMBB) access, services for MTC access, and the like. The AMF 182a, 182b can provide control plane functions to access the RAN 104 and other RANs (not shown) using other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies such as WiFi.
[0064] The SMF 183a, 183b can be connected to AMF 182a, 182b in the CN 106 via an N11 interface. The SMF 183a, 183b can also be connected to UPF 184a, 184b in the CN 106 via an N4 interface. The SMF 183a, 183b can select and control the UPF 184a, 184b and configure the routing of traffic through the UPF 184a, 182b. The SMF 183a, 183b can perform other functions, such as managing and allocating WTRU IP address, managing PDU sessions, controlling policy enforcement and QoS, providing DL data notifications, and the like. PDU session types can be IP-based, non-IP based, Ethernet-based, and the like.
[0065] The UPF 184a, 184b can be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 104 via an N3 interface, which can provide the WTRUs 102a, 102b, 102c with access to packet- switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPF 184a, 184b can perform other functions, such as routing and forwarding packets, enforcing user plane policies, supporting multi-homed PDU sessions, handling user plane QoS, buffering DL packets, providing mobility anchoring, and the like.
[0066] The CN 106 can facilitate communications with other networks. For example, the CN 106 can include, or can communicate with, an IP gateway for facilitating communications between the CN 106 and the PSTN 108, with other CNs, and / or with other networks 112. Additionally, the CN 106 can provide the WTRUs 102a, 102b, 102c with access to the other networks 112, which can include other wired and / or wireless networks that are owned and / or operated by other service providers. In one embodiment, the WTRUs 102a, 102b, 102c can be connected to a local DN 185a, 185b via the UPF 184a, 184b, as shown by the dashed line in FIG. 1 A. In another embodiment, the WTRUs 102a, 102b, 102c can be connected to the local DN 185a, 185b via the UPF 184a, 184b, as shown by the dashed line in FIG. 1 A.
[0067] In view of FIG. 1A to FIG. 1D And FIG. 1A to FIG. 1D In view of the corresponding description as provided herein, one or more functions or all of the functions described herein in relation to one or more of the WTRUs 102a-102d, the base stations 114a-114b, the eNode-Bs 160a-160c, the MME 162, the SGW 164, the PGW 166, the gNBs 180a-180c, the AMF 182a-182b, the UPF 184a-184b, the SMF 183a-183b, the DN 185a-185b, and / or any other device(s) described herein can be performed by one or more emulation devices (not shown). The emulation devices can be one or more devices configured to emulate one or more functions or all of the functions described herein. For example, the emulation devices can be used to test other devices and / or to simulate a network and / or WTRU functionality.
[0068] The simulation devices can be designed to implement one or more tests of other devices in a laboratory environment and / or in an operator network environment. For example, one or more simulation devices can perform one or more, or all, of the functions while implemented and / or deployed, entirely or in part, as part of a wired and / or wireless communication network to test other devices within the communication network. One or more simulation devices can perform one or more, or all, of the functions while implemented / deployed temporarily as part of a wired and / or wireless communication network. Simulation devices can be coupled directly to another device for testing purposes and / or can perform tests using over-the-air, wireless communication.
[0069] One or more simulation devices can perform one or more, including all, of the functions while not implemented / deployed as part of a wired and / or wireless communication network. For example, simulation devices can be utilized in a testing scenario in a test laboratory and / or a non-deployed (e.g., testing) wired and / or wireless communication network in order to implement tests of one or more components. The one or more simulation devices can be test equipment. Direct RF coupling and / or wireless communication, via RF circuitry (which can include one or more antennas, for example) can be used by the simulation devices to transmit and / or receive data.
[0070] FIG. 2 is a block diagram of an embodiment of a system 200 for enabling edge applications. In brief overview, the system can include a UE or WTRU 202 or other device (referred to variously as a UE, WTRU, mobile device, smartphone, mobile computing device, remote device, wearable device, or any other similar terminology) in communication with an edge data network 212, an edge configuration server 218, and / or a notification management server 220 via a network 210 (e.g., a 3GPP core network or any other type and form of network).
[0071] As shown, in some implementations, the WTRU 202 can include or execute one or more application clients 204. In some embodiments, the application client (AC) 204 is a user application that resides on the UE in communication with an edge application server (EAS) 214. The UE or WTRU 202 can use several ACs 204 concurrently. For example, the WTRU 202 can include one or more processors that execute one or more ACs 204 stored in memory of the WTRU 202. For example, in some implementations, the AC 204 can include a web browsing application, a social media application, a video game application, a productivity application, a remote desktop application, or any other type and form of application. In many implementations, the AC 204 can include a web application that communicates with an application server, such as the EAS 214, or an application executed in a web browser or similar local application.
[0072] In some embodiments, the edge application server (EAS) 214 is an application server that resides in the edge data network (EDN) 212. The EAS can include hardware, software, or a combination of hardware and software. For example, in some implementations, the EAS can include one or more software servers that execute on general-purpose hardware (e.g., a cloud server, a cluster, or a virtual farm) located at the edge data network 212 and provide services to the AC 202. For example, the EAS 214 can include a web server that provides a web application (e.g., a mail application, a productivity application, etc.) to one or more WTRUs 202 and ACs 204.
[0073] In some implementations, a WTRU can be relocated geographically and / or logically. For example, as a WTRU 202 moves within an area, it can become geographically closer to various EASs 214. Physically proximate EASs 214 can have lower latency connections to the WTRU, and thus, it can be desirable to switch the WTRU and AC 204 from a first EAS (referred to as a source EAS or S-EAS) that provides an application to a second EAS (referred to as a target EAS or T-EAS) that can provide the same application. In some implementations, the second EAS or target EAS can not necessarily be geographically closer to the S-EAS, but can be logically closer - that is, network speed, bandwidth, or congestion can make the connection from the WTRU 202 to the T-EAS faster or have lower latency than the connection to the S-EAS, regardless of physical proximity. Thus, in various implementations, it can be desirable to switch the WTRU from services provided by the S-EAS to services provided by the T-EAS based on location, latency, throughput, congestion, or any other physical and / or network characteristics. This switch can be referred to as relocation, although as discussed above, in some implementations, the WTRU can not physically change location. As discussed in more detail below, relocating the WTRU from the S-EAS to the T-EAS can include transferring configuration and / or state information (commonly referred to as context) from the S-EAS to the T-EAS. For example, if the S-EAS is providing a stateful web application to the AC 204, switching the AC to the T-EAS without transferring the context can cause the web application to crash or lose its state and be unable to fulfill requests until it is reloaded. This can impair functionality, cause data loss, etc. In contrast, implementations of the systems and methods discussed herein can provide seamless context transfer between the S-EAS and the T-EAS, allowing continued use by the relocated AC.
[0074] In the context of the mobile / relocation use case, a source EAS (S-EAS) can be an instance of an EAS that serves an AC in an initial location before the mobile / relocation has occurred, and a target EAS (T-EAS) can be an instance of an EAS that serves the AC in a destination location after the mobile / relocation has occurred. Each EDN 212 can have multiple EAS instances 214. Each EDN 212 can contain different groups of EAS instances 214 of different types (e.g., different EAS IDs); the EASs 214 can serve one or more AC instances 204, which can reside on different UEs 202.
[0075] In some embodiments, an edge enabler client (EEC) 206 provides edge support to an AC 202 instance on a UE / WTRU 202. Each UE 202 can have one or more EECs 206. In some embodiments, each AC 204 uses only one EEC 206. For example, the EEC 206 can comprise a plug-in or subroutine of the AC 204, or can be executed as a handler dedicated to the AC 204, and is configured to hook or intercept calls to and from the AC 204. Thus, in various implementations, the EEC 206 can comprise an application, service, server, daemon, routine, or other executable logic for communicating on behalf of the AC 204 with the edge enabler server(s) 216 and the edge configuration server(s) 218, including for managing context switching or relocation.
[0076] In some embodiments, an edge enabler server (EES) 216 provides the support functionality required by the EASs 214 and EECs 206. The EES 216 can comprise an application, server, service, daemon, routine, or other executable logic for transferring state and / or configuration information or other context information between the EASs 214 and communicating with the EECs 206 on behalf of the ACs 204. The EES 216 can be executed by one or more physical computing devices (e.g., servers, workstations, etc.) or by one or more virtual computing devices executed by one or more physical computing devices (e.g., as a cloud service, virtual server farm, etc.). The EES 216 can be executed by the same devices as the EASs 214, or can be executed by different devices. As discussed above, in the context of the mobile / relocation use case, a source EES (S-EES) is the EES used before the mobile / relocation has occurred, and a target EES (T-EES) is the EES used after the mobile / relocation has occurred. Each EDN 212 (or each data network name (DNN)) can have one or more EES instances 216. There can be multiple EDN instances 212 in the network 210.
[0077] In some embodiments, an edge configuration server (ECS) 218 can include an application, server, service, daemon, routine, or other executable logic that provides support functions for EECs 206 or EESs 216 to discover EES instances 216 that provide a particular EAS 214. For example, the ECS can include a configuration database, a user database, an application database, or other such database for identifying EASs 214 and / or EECs 206 or ACs 204. The ECS 218 can be provided by one or more computing devices, including physical or virtual computing devices (e.g., cloud servers) as discussed above. There can be one or more ECSs 218 for a network.
[0078] In some embodiments, a notification management client (NMC) 208 provides support functions for EECs 206 to create a notification channel (NM-UU) between the NMC 208 and a notification management server (NMS) 220 to receive notifications from ECSs or EESs. In some embodiments, each EEC uses only one NMC. The NMC 208 can be an application, service, server, daemon, routine, or other executable logic executed by and / or in communication with the processors of the UE / WTRU 202. For example, in some implementations, the NMC 208 can include an application provided by the EAS 214. In other implementations, the NMC 208 can include a service executed by an application or operating system of the WTRU, such as a listener service or other routine for periodically pulling and / or receiving notifications from the NMS 220. As shown, the NMC 208 can be provided as a service enabler architecture layer (SEAL) service. The NMC 208 can support notification management functions for EECs 206 and ACs 204, sometimes referred to as vertical application layer (VAL) client(s) over the NM-C reference point.
[0079] In some embodiments, a notification management server (NMS) 220 provides support functions for ECSs or EESs to send notifications to EECs via a notification channel created between the NMC and the NMS. The NMS 220 can be an application, service, server, daemon, routine, or other executable logic executed by one or more physical computing devices and / or virtual computing devices executed by physical computing devices. There can be one or more NMSs 220 for a network. The NMS 220 can communicate with the NMC 208 via the NM-UU reference point (e.g., via a point-to-point interface of the network 210 or another network) or via a PUSH server for indirect delivery, and can provide notification management functions to EECs 218 and EESs 216 via the NM-S reference point (e.g., via a point-to-point interface of the network 210 or another network).
[0080] 3GPP TS 23.558 V18.1.0, “Architecture for enabling Edge Applications,” which is incorporated herein by reference, describes some embodiments of service continuity procedures in the Edge Enabler Layer (EEL) for transferring application context from S-EAS to T-EAS. As discussed above, context transfer can be triggered, for example, by UE mobility and non-mobility events such as, for example, EAS server maintenance, overload, etc. The purpose of service continuity is to minimize edge service interruption to AC 204 executing on UE 202.
[0081] The EEL specifies service continuity for applications requiring context relocation in five different Application Context Relocation (ACR) scenarios. Each scenario can include 4 different phases: detection, decision, execution, and post-execution. The ACR scenarios can specify different EEL entities (e.g., EEC, EES, EAS) for the detection and decision phases (e.g., detection entity and decision entity) and different sets of interactions between EEL entities for the execution phase.
[0082] FIG. 3is a flowchart of an embodiment of a method for application context relocation. Briefly, in various implementations, a detection entity, which can be executed by or on a UE or WTRU or on an external server or another computing device, monitors UE or WTRU location, movement, or other physical or network characteristics (e.g., noise, latency, congestion, velocity or acceleration, location coordinates, received beacon signal strength, etc.) and informs a decision entity (step 305). In various implementations, the decision entity, which can similarly be executed by or on a UE or WTRU or on an external server or another computing device, then determines whether ACR is needed and commands an execution entity to perform ACR (step 310). In various implementations, the execution entity, which can similarly be executed by or on a UE or WTRU or on an external server or another computing device, then runs the ACR procedure defined in the service continuity scenario to transfer the application context from the S-EAS to the T-EAS (step 315). When the ACR execution is completed, the ACR cleanup is performed (step 320). For example, a WTRU executing a detection entity, which can include the EEC 206, can monitor network or device characteristics. In some implementations, a decision entity of the WTRU, which can similarly include the EEC 206, can determine that ACR is necessary based on the measurements and can communicate with the EES 216 and / or ECS 218 to initiate the transfer. Conversely, in some implementations, the WTRU detection entity can report the measurements to a decision entity on the EES 216, which can determine that ACR is necessary and can communicate with the EEC 206 and / or ECS 218.
[0083] Various methods can be used for EEC authorization, including pulling or pushing context transfer pre-configuration tokens for future EECs. Briefly, in a first aspect, to pre-configure tokens for future EEC pull context transfer, in some embodiments, the EEC can perform one or more of the following steps.
[0084] First, in some embodiments, an EEC (e.g., EEC 206) can send a request for a token to a server. The request can identify an instance of an EEC context. In some embodiments, the request can also indicate a request for authorization restrictions. In some embodiments, the EEC context can be identified by an EEC context ID or a session context, which can be identified by a combination of some or all of an application client identifier (ACID), an EEC identifier (EEC ID), a user equipment identifier (UE ID), an S-EAS endpoint, and / or a T-EAS endpoint. In some embodiments, the authorization restrictions can indicate specific T-EES(s) that can be authorized with the token. In some embodiments, the authorization restrictions can indicate that only certain types of T-EES(s) can be authorized with the token. In some embodiments, the authorization restrictions can indicate that only T-EES(s) associated with a particular service provider can be authorized with the token. In some embodiments, the authorization restrictions can indicate that only T-EES(s) at a particular location can be authorized with the token. In some embodiments, the authorization restrictions can indicate that only T-EES(s) in a certain EDN(s) can be authorized with the token. In various embodiments, any of the above authorization restrictions can indicate which T-EES(s) cannot be authorized with the token. The request can also include a requested token validity time. In some embodiments, the token server can be the ECS 218 and / or EES 216, or can be an application or server executed by the ECS 218 or similar hardware server.
[0085] In many implementations, the authorization restrictions can identify characteristics of EESs rather than specific EESs. For example, rather than identifying a specific server, the authorization restrictions can specify that a server can be authorized if it has an uptime greater than a threshold, or a resource utilization less than a threshold, or is within a threshold number of miles from a geographic location, or has a latency to an EEC or ECS less than a threshold, or has a specific application service capability (e.g., the server can host artificial intelligence / machine learning applications, or can provide a web interface to web applications, or can provide remote data storage capabilities, etc.), or has a specified operating system version (e.g., indicating that a particular patch is up to date), or has other specialized hardware or access to such hardware (e.g., satellite uplinks, or light-tracing GPUs, etc.). In some such implementations, the set of potential EESs that can satisfy the authorization restrictions can be referred to as candidate target EESs or similar terminology. In general, not all EESs can satisfy the requirements, and thus the candidate target EESs can be a subset of the EESs in the system. In many implementations, the authorization restrictions can be agnostic to any particular EES, or can not include an identification of a particular EES, but can include only the characteristics required for authorization or validity of the token.
[0086] Second, in some implementations, the EEC 206 can receive a response from the server. In some embodiments, the response can include the token, and in some cases, the authorization restrictions applied to the token. The response can also include a token validity duration.
[0087] Third, in some implementations, the EEC 206 can send a message to a first EES (S-EES 216A). In some embodiments, the message can include the token and the authorization restrictions (e.g., if they are included in the token). In some embodiments, the message can also include the token validity duration. The message can be used to control which other EES(s) (T-EES) can receive the context information associated with the EEC 206. For example, in some implementations, a T-EES can transmit a request for the context information to the S-EES, and the S-EES can determine whether the T-EES is authorized to receive the context information based on the authorization restrictions.
[0088] Fourth, in some implementations, the EEC 206 can decide to perform an ACR procedure and select a T-EES (e.g., T-EES 216B). Selecting a T-EES can include identifying a T-EES from among candidate T-EESs that has characteristics that satisfy the authorization restrictions requirements associated with the token. For example, the EEC can select a T-EES that has a location within a required region, or a latency below a required threshold, or has a capability to provide a specific application service, etc.
[0089] Fifth, in some embodiments, the EEC 206 can send an ACR request to the selected T-EES 216B. In some embodiments, the request can include the token. In such embodiments, the T-EES can use the token to retrieve the EEC context information from the S-EES 216A (if the token authorization restrictions do not prevent the T-EES from receiving the context information).
[0090] Sixth, in some embodiments, the EEC 206 can receive a message from the T-EES 216B (e.g., if the token authorization restrictions do not prevent the T-EES from receiving the context information). In some embodiments, the message includes an indication that the token was used to authorize the context transfer to the T-EES. In some embodiments, the message can trigger the EEC 206 to consider the token invalid and reinitiate the process in order to obtain a new token for future ACR processes. For example, the T-EES 216B can indicate that it was prevented by authorization restrictions, or the T-EES 216B can provide an indication that the context transfer was authorized, but that the token can have expired in the meantime. The message provided by the T-EES 216B can be an ACR information notification or any other suitable type and format of notification message.
[0091] In another aspect, to preconfigure a token for future EEC push context transfers, the EEC can perform one or more of the following steps: First, in some embodiments, the EEC 206 can send a request for a token to a server. In some embodiments, the request identifies an instance of an EEC context. In some embodiments, the request also indicates a request for authorization restrictions.
[0092] In some embodiments, the EEC context is identified by an EEC context ID or a session context, which can be identified by a combination of ACID, EEC ID (or UE ID), S-EAS endpoint, and T-EAS endpoint. In some embodiments, the authorization restriction can indicate a specific T-EES(s) that can be authorized with the token. In some embodiments, the authorization restriction can indicate that only certain types of T-EES(s) can be authorized with the token. In some embodiments, the authorization restriction can indicate that only T-EES(s) associated with a particular service provider can be authorized with the token. In some embodiments, the authorization restriction can indicate that only T-EES(s) in a particular location can be authorized with the token. In some embodiments, the authorization restriction can indicate that only T-EES(s) in a certain EDN(s) can be authorized with the token. In some embodiments, any of the above authorization restrictions can indicate which T-EES(s) cannot be authorized with the token. As discussed above, the authorization restriction can refer to required properties or characteristics that some EESs can satisfy and corresponding thresholds, for which the token correspondingly indicates authorization for context transfer.
[0093] In some embodiments, the request can also include a requested token validity time. In many implementations, the token server can be the ECS 218.
[0094] Second, in some implementations, the EEC 206 can receive a response from the server. In some embodiments, the response includes a token and an authorization restriction that applies to the token. The response can also include a token validity duration.
[0095] Third, in some implementations, the EEC 206 sends a message to a first EES (S-EES 216A). In some embodiments, the message includes the token and the authorization restriction. The message can also include the token validity duration. The purpose of the message can be to control which other EES(s) (T-EES 216B) can receive context information associated with the EEC.
[0096] Fourth, in some implementations, the EEC 206 receives a message from the first EES (S-EES 216A). In some embodiments, the message includes an indication that the token was used to authorize a context transfer to a T-EES 216B. In some embodiments, the message can include a T-EES identity (e.g., the S-EES 216A can select the T-EES to which the context is being transferred from multiple potential EES(s) 216). The message can trigger the EEC to consider the token invalid and re-initiate the process in order to obtain a new token for future ACR processes. In some embodiments, the message can be an ACR information notification.
[0097] Aspects of these embodiments are discussed in more detail below.
[0098] FIG. 4 Figure illustrates an embodiment of a process 400 for EEC authorization for EEC context transfer in a scenario where an ACR procedure is initiated by the EEC 206 and the procedure requires pulling the EEC context from the S-EES 216A to the T-EES 216B. In such embodiments, the EEC 206 can obtain a token prior to any entity in the EEL determining to initiate the ACR procedure. In some embodiments, the EEC 206 negotiates with a token server 402 (which can be provided by the ECS 218) to set limits in which entities can use the token. In some embodiments, the EEC 206 then provides the token to the S-EES 216A. The S-EES 216A later uses the token in authorizing a request from the T-EES 216B to retrieve the EEC context. Advantageously, in these embodiments, the EEC 206 can be able to exert some degree of control over where its context can be transferred even if the S-EES 216A is unable to communicate with the EEC when context transfer needs to occur (e.g., due to network conditions changing, because the EEC has moved out of range of the S-EES, etc.).
[0099] In step 1, in some embodiments, the EEC 206 sends a request to the server 402 to obtain an authorization token. The authorization token will be used to authorize transfer of the EEC's context from the source EES (S-EES 216A) to the T-EES 216B. The request to the server can include the identity of the S-EES 216A. Since the T-EES 216B can not yet have been determined or selected, the request can not identify a T-EES or can indicate that no T-EES has been selected. In some embodiments, the request also identifies the context to be transferred. The context is identified by the EEC context ID or by a combination of identities including the ACID, the EEC ID (or UE ID), the S-EAS endpoint, and the T-EAS endpoint. In some embodiments, the session context needs to be identified because multiple ACR procedures for the same EEC (UE), S-EES, and T-EES can occur simultaneously. In some embodiments, the request can also include a requested token validity duration, which indicates to the server that it should consider the token valid for only the indicated duration. In some embodiments, the request also indicates requested authorization limits. The requested authorization limits can indicate limits on which T-EESes can be authorized with the token. The limits can indicate specific T-EESes that can be authorized with the token. The limits can indicate that only T-EESes of a particular type, associated with a particular service provider, or in a particular location can be authorized with the token. Alternatively, the limits can indicate which T-EES(es) cannot be authorized with the token.
[0100] In some embodiments, the server 402 can be the ECS 218. The request can be integrated with a service provisioning process.
[0101] In step 2, in some embodiments, the server 402 responds to the EEC 206 with an authorization token. In some embodiments, the response includes a token validity duration, which indicates how long the server considers the token to be valid. In some embodiments, the response also indicates authorization restrictions that apply to the token. Note that the EEC 206 can choose to request a token after determining to perform an ACR.
[0102] In step 3, in some embodiments, the EEC 206 sends a token delegation message to the S-EES 216A. In some embodiments, the request includes the authorization token, the token validity duration, and the authorization restrictions that apply to the token. In these embodiments, the word delegation refers to the EEC 206 delegating the work of token validation to the S-EES 216A. The S-EES can subsequently perform token validation (e.g., as part of step 9 in the transfer EEC context).
[0103] In step 4, in some embodiments, the EEC 206 determines to perform an ACR process. For example, the EEC 206 can be triggered to perform an ACR process based on detecting a change in UE location. In some embodiments, the EEC 206 can also be triggered to perform an ACR process based on a notification request from the ECS 218.
[0104] In step 5, in some embodiments, the EEC 206 selects one or more EES to act as a target EES (T-EES 216B) in the ACR process.
[0105] In step 6, in some embodiments, the EEC 206 initiates an ACR initiation process by sending an ACR request to the T-EES 216B. The request can include the authorization token and the identity of the S-EES 216A. In some embodiments, the request also includes information (e.g., an EEC context ID or ACID, an EEC ID (or UE ID), an S-EAS endpoint, and a T-EAS endpoint) that will be used by the T-EES 216B to identify an EEC context that will need to be transferred as part of the ACR process. In some embodiments, the T-EES 216B can determine whether an authorization token is required to perform a context transfer. The determination of whether an authorization token is required can be based on a local policy or an indication previously received from the EEC 206 (e.g., during a registration process).
[0106] In step 7, in some embodiments, T-EES 216B sends an ACR response message to EEC 206. If T-EES 216B determines that the authorization token was not included in the ACR request, that the token was not properly formatted (e.g., not associated with the identified S-EES 216A), that the token is expired, or that the token is not associated with the context that will need to be transferred, T-EES 216B can indicate that the request is denied and include a reason code identifying the reason for the denial.
[0107] In step 8, in some embodiments, if an authorization token is included in the ACR request, T-EES 216B can determine that it is authorized to pull the EEC context from S-EES; if T-EES is authorized, T-EES 216B can initiate an EEC context pull relocation procedure with the identified S-EES by sending a pull EEC context request to S-EES 216A. The EEC context pull can include the authorization token.
[0108] In step 9, in some embodiments, S-EES 216A can verify that the token is applicable to the context being requested to be transferred and verify the token (e.g., S-EES 216A can check that the token is the same token provided to S-EES by EES in step 3, can validate the signature of the token, and / or can transmit the token to token server 402 for verification or validation). S-EES 216A can first determine whether the token is valid to authorize S-EES 216A to transfer the EEC context to T-EES 216B; if the pull request included an authorization token in step 8, S-EES can verify whether the token received in the pull EEC context request is valid to authorize S-EES 216A to transfer the EEC context to T-EES 216B. S-EES 216A can send a pull EEC context response message to T-EES and indicate success or failure. If the failure is due to an invalid token, S-EES can notify T-EES that the token is invalid and S-EES can include the reason for its invalidity (e.g., that the token is expired).
[0109] In step 10, in some embodiments, T-EES 216B can send an ACR information notification to EEC 206. In some embodiments, the ACR information notification can include an indication of which authorization token was used to authorize the context transfer to T-EES 216B, and whether the token was invalid or valid, and whether the transfer was successful or unsuccessful. This message can trigger EEC to consider the token invalid and re-initiate the process at step 1 in order to obtain a new token for S-EES for future ACR processes. Note that when re-initiating the process, in some implementations, S-EES can be the EES that was considered the T-EES in the process (e.g., the process can be re-initiated with the T-EES as the new S-EES).
[0110] FIG. 5 Figure illustrates an example process 500 for EEC authorization for EEC context transfer in a scenario where the ACR process is not initiated by EEC 206 and the process requires pushing the EEC context from S-EES 216A to T-EES 216B. In embodiments of the process, EEC 206 can obtain a token before any entity in the EEL determines to initiate an ACR process. In some embodiments, EEC 206 negotiates with token server 402 to set the limitations on which entities can use the token. EEC 206 then provides the token to S-EES 216A. S-EES 216A later uses the token when transferring context to T-EES 216B. In addition, in some implementations, the token can be transferred to T-EES 216B, so T-EES can verify that it is allowed to accept the EEC context. Advantageously, in some embodiments, EEC 206 is able to exert some degree of control over where its context can be transferred, even if S-EES 216A is unable to communicate with EEC when context transfer needs to occur (e.g., due to EEC being out of range, network conditions changing, etc.).
[0111] In step 1, in some embodiments, the EEC 206 sends a request to the server 402 to obtain an authorization token. In some implementations, the token server 402 can be provided by the ECS 218. The authorization token can be used to authorize the transfer of the EEC's context from the source EES (S-EES) to the T-EES. In some embodiments, the request to the server includes the identity of the S-EES 216A. Since the T-EES is not determined in these implementations, the request can indicate that there is no T-EES 216B, or can be agnostic or blank with respect to the T-EES. In some implementations, the request can indicate a plurality of candidate T-EES 216B (e.g., a subset of all T-EES), with the assumption that one of them can be selected later. In some embodiments, the request can identify the context to be transferred. In some embodiments, the session context is identified by the EEC context ID or by a combination of identities including the ACID, the EEC ID (or UE ID), the S-EAS endpoint, and the T-EAS endpoint. In some embodiments, the session context can be identified such that multiple ACR procedures for the same EEC (UE), S-EES, and T-EES can occur simultaneously. In some embodiments, the request can also include a requested token validity duration, which indicates to the server that it should consider the token valid for only the indicated duration. In some embodiments, the request also indicates a requested authorization restriction. The requested authorization restriction can indicate a restriction on what T-EES 216B can be authorized with the token. The restriction can indicate a particular T-EES(s) that can be authorized with the token. The restriction can indicate that only T-EES(s) of a particular type, associated with a particular service provider, or in a particular location can be authorized with the token. Alternatively, the restriction can indicate which T-EES(s) cannot be authorized with the token. The request can be integrated with the service provisioning procedure.
[0112] In step 2, in some embodiments, the server 402 can respond to the EEC 206 with an authorization token. In some embodiments, the response includes the token and a token validity duration, which indicates how long the server considers the token valid. In some embodiments, the response also indicates an authorization restriction that applies to the token.
[0113] In step 3, in some embodiments, the EEC 206 sends a token delegation message to the S-EES 216A. In some embodiments, the request includes the authorization token, the token validity duration, and the authorization restriction that applies to the token. In some embodiments, the information sent in the token delegation message can be carried in an EAS information provisioning message.
[0114] In step 4, in some embodiments, the S-EES 216A determines to perform an ACR procedure. For example, the S-EES 216A can be triggered to perform an ACR procedure based on detecting a change in UE location.
[0115] In step 5, in some embodiments, the S-EES 216A selects an EES to act as a target EES (T-EES 216B) in the ACR procedure. In some embodiments, the S-EES 216A will select a T-EES 216B that can use the authorization token (e.g., a T-EES 216B that is authorized by the authorization limits of the token). In other words, the S-EES 216A can apply a filter to the EES(s) (e.g., candidate T-EES(s)) that are considered for T-EES selection, such that EES(s) for which the token cannot be applied are not considered.
[0116] In step 6, in some embodiments, the S-EES 216A will initiate an EEC context push relocation procedure with the identified T-EES 216B by sending a push EEC context request to the T-EES. The EEC context push can include the authorization token.
[0117] In step 7, in some embodiments, the T-EES 216B can send a request to the token server 402 and / or the ECS 218 to verify that the token is applicable to the context being requested to be transferred, and to validate that the token is valid. For example, the T-EES can send the token, a hash of the token, an identifier of the token, a signed version of the token, or any other type and form of notification.
[0118] In step 8, in some embodiments, the server 402 can reply to the T-EES 216B. In some embodiments, the server 402 can inform the T-EES 216B whether the token is valid or invalid. If the server 402 informs the T-EES 216B that the token is invalid, it can include the reason for its invalidity (e.g., the token is expired).
[0119] In step 9, in some embodiments, the T-EES 216B will send a push EEC context response message to the S-EES 216A and indicate success or failure. If the failure is due to an invalid token, in some embodiments, the T-EES 216B will inform the S-EES 216A that the token is invalid, and the T-EES can include the reason for its invalidity (e.g., the token is expired).
[0120] In step 10, in some embodiments, S-EES 216A will send an ACR information notification to EEC 206. In some embodiments, the ACR information notification will include the T-EES identity, and an indication of which authorization token was used to authorize the context transfer to T-EES 216B. This message can trigger EEC 206 to consider the token invalid, and re-initiate the process at step 1 in order to obtain a new token for S-EES 216A for future ACR processes. Note that when re-initiating the process, in some embodiments, the S-EES can be the EES that was considered the T-EES in the process (e.g., the context is transferred back to the S-EES).
[0121] In some embodiments, process 500 can start at steps 4 and 5. Then, S-EES 216A can perform step 10 to send the T-EES 216B identity to EEC 206. Then, EEC 206 can perform steps 1, 2, and 3 to obtain a token associated specifically with T-EES 216B. Then, the delegation token message can include the token associated specifically with T-EES 216B. The process can then proceed to steps 6, 7, 8, and 9.
[0122] FIG. 6 FIG. 6 illustrates an example process 600 for EEC authorization for EEC context transfer in a scenario where an ACR process is initiated by EEC 206 and the process requires pushing the EEC context from S-EES 216A to T-EES 216B. In some such embodiments, EEC 206 can determine to perform an ACR process, obtain a token, and send the token to S-EES 216A. S-EES 216A can use the token to verify whether it is allowed to transfer the EEC context to T-EES 216B. S-EES 216A can provide the token to T-EES 216B so that T-EES 216B can verify that it is permitted to receive the context of the EEC.
[0123] In step 1, in some embodiments, EEC 206 determines to perform an ACR process. For example, in some embodiments, EEC 206 can be triggered to perform an ACR process based on detecting a change in UE location, network conditions, etc. In other embodiments, EEC 206 can be triggered to perform an ACR process based on a notification request from ECS 218.
[0124] In step 2, in some embodiments, the EEC 206 performs a service provisioning procedure with the ECS 218. As part of the service provisioning procedure, in some embodiments, the EEC 206 receives information about the EEC(s) 206 available in the EDN. The received information can include the identity of the EES(s) 216. In some embodiments, the information can include the coverage area(s) of the EES(s) 216, allowing the EEC 206 to select a T-EES 216B based on the location of the UE / WTRU.
[0125] In step 3, in some embodiments, the EEC 206 selects one of the EES(s) 216 to act as the target EES (T-EES 216B) in the ACR procedure. In some embodiments, the EEC 206 also performs T-EAS discovery to determine the identity of the T-EAS 214B. For example, the EEC 206 can broadcast a query to available T-EAS servers, can communicate with the EES 216, can communicate with a management server, etc.
[0126] In step 4, in some embodiments, the EEC 206 sends a request to the server 402 and / or the ECS 218 to obtain an authorization token. In some embodiments, the authorization token can be used to authorize the transfer of the EEC's context from the source EES (S-EES 216A) to the T-EES 218B. In some embodiments, the request to the server 402 can include the identities of the S-EES 216A and the T-EES 218B. In some embodiments, the request also identifies the context to be transferred. In some embodiments, the session context is identified by the EEC context ID or by a combination of identities including the ACID, the EEC ID (or UE ID), the S-EAS endpoint, and the T-EAS endpoint. In some embodiments, the session context can be identified such that multiple ACR procedures for the same EEC (UE), S-EES, and T-EES can occur simultaneously. In some embodiments, the request can also include a requested token validity duration, which indicates to the server that it should consider the token valid for only the indicated duration. The request can be integrated with the service provisioning procedure.
[0127] In step 5, in some embodiments, the server 400 and / or the ECS 218 responds to the EEC 206 with an authorization token. In some embodiments, the response includes a token validity duration, which indicates how long the server will consider the token valid.
[0128] In step 6, in some embodiments, the EEC 206 initiates the ACR initiation process by sending an ACR request to the S-EES 216A. In some embodiments, the request includes an authorization token and the identity of the selected T-EES 216B. In some embodiments, the request also includes information (e.g., EEC Context ID or ACID, EEC ID (or UE ID), S-EAS endpoint, and T-EAS endpoint) that will be used by the S-EES 216A to identify the EEC context that will need to be transferred as part of the ACR process. In some embodiments, the S-EES 216A can determine whether an authorization token is required to perform the context transfer. The determination of whether an authorization token is required can be based on a local policy or an indication previously received from the EEC 206 (i.e., during the registration process).
[0129] In step 7, in some embodiments, the S-EES 216A sends an ACR response message to the EEC 206. If the S-EES determines that an authorization token was not included in the ACR request, that the token was not properly formatted (e.g., not associated with the identified T-EES 216B), that the token is expired, or that the token is not associated with the context that will need to be transferred, in some embodiments, the S-EES 216A can indicate that the request was denied and include a reason code identifying the reason for the denial.
[0130] In step 8, in some embodiments, the S-EES 216A can validate that it is authorized to transfer the EEC context to the T-EES 216B by validating the token, the S-EES 216A can interact with a token server (not shown in the figure). If authorized, the S-EES 216A can initiate an EEC context push relocation process with the identified T-EES 216B by sending a push EEC context request to the T-EES 216B. The EEC context push can include the authorization token.
[0131] In step 9, if a token is included, in some embodiments, the T-EES 216B can send a request to a server to validate that the token is applicable to the context being transferred and to validate that the token is valid.
[0132] In step 10, in some embodiments, the server 400 and / or ECS 218 will reply to the T-EES 216B. The server 400 and / or ECS 218 can inform the T-EES 216B whether the token is valid or invalid. If the server informs the T-EES 216B that the token is invalid, it can include the reason why it is invalid (e.g., it has expired).
[0133] In step 11, in some embodiments, T-EES 216B will send a push EEC context response message to S-EES 216A and indicate success or failure. If the failure is due to an invalid token, T-EES 216B can inform S-EES 216A that the token is invalid and T-EES 216B can include the reason for its invalidity (e.g., it has expired, not allowed to transfer to T-EES instance).
[0134] In step 12a or 12b, in some embodiments, S-EES 216A or T-EES 216B can inform EEC 206 whether the EEC 206 context push operation was successful or not successful, respectively. If the push was not successful, in some embodiments, S-EES 216A or T-EES 216B can indicate the reason for the operation not being successful. In some embodiments, if the operation was successful, T-EES 216B can inform EEC 206 and / or if the operation was not successful, S-EES 216A can inform EEC 206.
[0135] In step 13, in some embodiments, EEC 206 will send a request to AC 204 to start application context transfer. In some embodiments, the notification from S-EES 216A or T-EES 216B can trigger EEC 206 to send the request.
[0136] FIG. 7A and FIG. 7B is a flow diagram of an embodiment of a method 700 of EEC authorization for EEC context transfer. At 702, in some implementations, EEC 206 can request an authorization token from token server 400 702. The request can be transmitted via any suitable method or communication format, such as via a Uu wireless interface, via a management frame, etc. The request can include an identification of the EEC and / or associated one or more ACs, a UE ID or WTRU ID, or any other such information. In some implementations, the request can include an identification of the source EES and / or target EES.
[0137] At 704, in some embodiments, the token server can determine whether the EEC is authorized to request a token. For example, the token server can validate the cryptographic signature (e.g., the EEC's public key), the user ID, or any other such information. If not, the request can be denied, either explicitly or by not returning a token. If so, at 706, the token server 400 can generate a token and provide the token to the EEC. The token can be of any type and format, and can include a cryptographic hash or signature, a UE or WTRU ID, a source and / or target EES identifier, or any other such information. For example, in some embodiments, the token can include authorization restrictions, such as an expiration time, a location, an application type or category, a user identifier, a T-EES identifier, or any other type and form of restriction. At 708, the EEC can receive the token.
[0138] As discussed above, in some embodiments, the application context can be "pushed" from the source EES to the target EES, while in other embodiments, the application context can be "pulled" by the target EES from the source EES. As used herein, push and pull can indicate which of the EESs initiates the transfer of context from the other of the EESs (e.g., pulled by the T-EES or pushed by the S-EES), respectively.
[0139] If the device is configured for "pull" mode at 710, at 712, in some embodiments, the EEC 206 can determine whether to relocate the application context. This can be based on any type and form of information or measurements, such as the location of the device, measurements of network characteristics including latency, throughput, bandwidth, and congestion, geographic proximity to EESs, and the like.
[0140] In some embodiments, in response to determining to relocate the application context, at 714, the EEC 206 can provide an authorization token to a target server (e.g., T-EES 216B). In some embodiments, providing the authorization token can include selecting a T-EES from among a plurality of EESs that is suitable to receive the application context and provide the application service after relocation. The T-EES can be selected based on its location, its network connection or characteristics of the network connection between the EEC and the T-EES, and the like. For example, as discussed above, the T-EES can be selected based on characteristics (e.g., physical, logical, functional, or other such characteristics) that match, comply with, or correspond to the authorization restrictions associated with the token. At 716, the T-EES 216B can receive the token. As discussed above, the token can include authorization restrictions, such as an expiration time, a location, an application type or category, a user identifier, a T-EES identifier, or any other type and form of restriction.
[0141] At 718, the T-EES 216B can attempt to validate or verify the token. Validating the token can include checking a hash or cryptographic signature of the token, or transmitting a message to the token server 400 or other authorization server to obtain information to verify the token. For example, in some embodiments, the T-EES can provide a user identifier, location, or any other such information to the token server. In some embodiments, the token can be signed with a private key of the token server, and the T-EES can verify the origin of the token via a public key of the token server and verification of the information payload of the token. At 720, the token server can verify the token (e.g., compare the token to a user or EEC database, etc.) and / or validate the authorization limits of the token (e.g., that the T-EES 216B is authorized to use the token for context transfer, that the token is not expired, that the token is associated with an application provided by the T-EES or associated EAS, that the characteristics of the T-EES correspond to or comply with the authorization limits associated with the token, etc.). The token server can reply to the T-EES with an authorization identifier or an error (or other message indicating that the token is invalid or lacks authorization to use the token).
[0142] At 722, if the token is valid, the T-EES can transmit a request for context information of the application client (e.g., a context "pull" request) from the S-EES that is providing service to the AC. The request for context information can include the token, and / or can include an identification of the authorization or validity of the token, an identification of the AC or EEC or UE / WTRU or device user, or any other type and form of information. At 724, the S-EES can provide the context to the target server. The context can be in any suitable format, such as a flat file, a database, parameter-value pairs, a data string or array, a bitmap, XML data, compressed data, or any other type and format for providing state or context information of the application client and / or application server.
[0143] At 726, the T-EES can provide application context relocation (ACR) information to the EEC 206 to complete the transfer, such as synchronization or handshake information with the T-EES, state information or other identifiers, or any other type and form of information to enable the EEC and / or AC to resume use of the application provided by the EAS. At 728, the EEC 206 can receive the ACR information, and can use it to continue communication of the AC with the corresponding EAS (e.g., continue access to a web application, etc.).
[0144] Turning to FIG. 7BIn implementations in which a context push request is used, at 730, the EEC 206 can transmit an authorization token to the EES-S. As discussed above, this can be performed some time before communication is lost or compromised or before physical movement of the UE / WTRU, and thus, the transmission of the token can not indicate that a context transfer is performed.
[0145] At 732, the EES-S 216A can determine whether relocation is required. For example, the EES-S 216A can monitor communications with the EEC 206 to determine whether the UE / WTRU has traveled beyond a specified region, whether communications have been compromised or slowed (e.g., due to interference or congestion, etc.). If not, the EES-S can wait (and continue to provide application services to the AC). If so, at 734, the EES-S can select a target server. Selection of the T-EES 216B can include identifying a T-EES associated with a new location of the WTRU / UE; identifying a T-EES having sufficient bandwidth or processing resources, etc. In some implementations, selection of the T-EES can include determining characteristics of the T-EES that match, comply with, or correspond to authorization limits associated with the token. At 736, the EES-S can transmit a context transfer request to the T-EES. The request can include the token or an identifier of the token (e.g., a hash or other cryptographic function); an identifier of the application client, the EEC, the user identifier, the UE or WTRU, or any other such information. In some implementations, the request can include authorization limits or other such information.
[0146] At 738, the T-EES can attempt to validate the token. Validating the token can include transmitting the token, a hash of the token, a signed version of the token, or any other type and form of information to the token server 400. In some implementations, validating the token can include determining that the token is not expired, and / or that the T-EES is authorized to use the token (if it is valid). At 740, the token server can determine whether the token is valid, and can provide token information or similar information to the T-EES, respectively, or can transmit an error message to the T-EES (e.g., indicating that the token is invalid, expired, that the T-EES lacks authorization or permission to use the token, etc.).
[0147] At 742, if the token is valid and the T-EES is authorized, the T-EES can transmit a response to the initial transfer request. In some implementations, the response can request that context information be provided to the T-EES. At 744, in response to receiving the response to the context transfer request, the S-EES can provide ACR information and / or any other type and form of information (e.g., an identification of the selected target server or T-EES, etc.) to the EEC. At 746, the EEC can receive confirmation via any suitable means (e.g., a UU interface or other such interface).
[0148] FIG. 8 is a flowchart of an embodiment of the method 802 of EEC authorization for EEC context transfer from the perspective of a token server or ECS. In some implementations, at 802, the server can receive a request for an authorization token. The request can be received from a UE / WTRU, from an AC or EAC executed by or on behalf of a UE / WTRU, or the like. The request can include an identification of the UE / WTRU, the AC and / or EAC, the S-EES and / or T-EES for context transfer, or any other type and format of information.
[0149] At 804, in some implementations, the server can provide the token to the requesting entity (e.g., UE / WTRU, AC or EAC executed by or on behalf of a UE / WTRU, or the like). The token can include one or more authorization restrictions, including an expiration time or date, an identification of the application and / or EES(s) that can provide the application service, or the like.
[0150] Subsequently (e.g., during a context transfer procedure) at 808, the token server can receive a request to validate the token from the S-EES or T-EES. The request can include any type and format of supporting information, including an identifier of the AC, EAC, or EES(s), a time or validity time of the token, a user identifier, or the like. In some implementations, the token can be signed via a cryptographic key pair, and the token server can include the signed data to the original token data to ensure that it is still valid.
[0151] If the token is invalid or expired, or the T-EES does not have authorization for context transfer (e.g., does not have characteristics that match or comply with the authorization restrictions associated with the token), at 810, the token server can reject the token and can provide an identification of the rejection reason(s) (e.g., expiration of a validity time, a restriction on which EES is authorized or eligible to use the token, or the like). If the T-EES does have authorization and / or if the token is valid, at 812, the token server can provide an authorization confirmation to the requesting device or entity. For example, if the T-EES requests to validate the token, the token server can provide a confirmation or other notification of the token or authorization validity to perform a context transfer to the T-EES. If the S-EES requests to validate the token, the token server can provide a confirmation or other notification of the token or authorization validity to perform a context transfer to the S-EES.
[0152] Accordingly, the present disclosure relates to embodiments of methods and systems for authorizing a transfer of a specific context instance from an S-EES to a T-EES. Embodiments of these methods and systems can ensure that context information associated with an EEC is only sent to a T-EES that is authorized to receive the context.
[0153] In a first aspect, the present disclosure relates to a method for authorizing edge enabler client (EEC) context transfer. The method includes an edge enabler client (EEC) determining, by a wireless transmit receive unit (WTRU), to relocate an application context from a first edge enabler server. The method further includes, in response to the determination, requesting, by the edge enabler client (EEC), an authorization token from a token server, the request including an identification of the application context and an identification of one or more authorization restrictions corresponding to characteristics of edge enabler servers required for authorization. The method further includes receiving, by the EEC from the token server, an authorization token for the application context, and in some embodiments, the identification of the one or more authorization restrictions. The method further includes transmitting, by the EEC, the authorization token to the first edge enabler server. The method further includes receiving, by the EEC from one of the first edge enabler server and a second edge enabler server, an indication that the authorization token is used to authorize a context transfer from the first edge enabler server to the second edge enabler server in response to the second edge enabler server having characteristics matching the one or more authorization restrictions.
[0154] In some embodiments, the indication is received from the second edge enabler server, the second edge enabler server transmitting the indication to the EEC in response to successfully retrieving the EEC context information from the first edge enabler server. In further embodiments, the method includes selecting, by the EEC, the second edge enabler server from a plurality of edge enabler servers. In another further embodiment, the method includes transmitting, by the EEC, an application context relocation request to the second edge enabler server, the application context relocation request including the authorization token.
[0155] In some embodiments, the indication is received from the first edge enabler server, the first edge enabler server transmitting the indication to the EEC in response to successfully pushing the EEC context information to the second edge enabler server. In further embodiments, the first edge enabler server selects the second edge enabler server from a plurality of edge enabler servers.
[0156] In some embodiments, the method includes determining to relocate the application context from the first edge enabler server by monitoring a physical location or movement of the WTRU. In some embodiments, the method includes transmitting, by the EEC, a request including an identification of one or more authorization restrictions. In further embodiments, the one or more authorization restrictions include an identification of a target edge enabler server authorized to use the authorization token to receive the relocated application context.
[0157] In some embodiments, the one or more authorization restrictions do not identify a specific edge enabler server. In some embodiments, the one or more authorization restrictions include an identification of a valid duration of the authorization token, a location or region, a minimum communication latency, an application capability, or a maximum utilization level.
[0158] In another aspect, the disclosure relates to a method. The method includes receiving, by an authorization token server from an edge enabler client (EEC) executed by a wireless transmit receive unit (WTRU), a request for an authorization token, the request including an identification of an application context associated with a first edge enabler server and an identification of a first one or more authorization restrictions corresponding to characteristics of edge enabler servers required for authorization. The method further includes providing, by the authorization token server, the authorization token to the EEC. The method further includes subsequently receiving, by the authorization token server from a second edge enabler server, the authorization token. The method further includes determining, by the authorization token server, that the authorization token is valid based on a match of the one or more authorization restrictions to characteristics of the second edge enabler server, and that the application context is authorized to be relocated to the second edge enabler server. The method further includes, in response to the determination, transmitting, by the authorization token server to one or more of the EEC, the first edge enabler server, and the second edge enabler server, an authorization of the relocation of the application context.
[0159] In some embodiments, the one or more authorization restrictions do not identify a specific edge enabler server. In some embodiments, the one or more authorization restrictions include an identification of a specific target edge enabler server authorized to use the authorization token to receive the relocated application context. In some embodiments, the one or more authorization restrictions include a location or region, a minimum communication latency, an application capability, or a maximum utilization level. In some embodiments, the one or more authorization restrictions include a valid duration of the authorization token. In some embodiments, the application context includes WTRU or user equipment (UE) identity information, location information, application client (AC) profile, or service session context information.
[0160] In another aspect, the present disclosure relates to a wireless transmit receive unit (WTRU) configured to perform an embodiment of the above-described method. In another aspect, the present disclosure relates to a user equipment (UE) configured to perform an embodiment of the above-described method. In another aspect, the present disclosure relates to a network device configured to perform an embodiment of the above-described method. In another aspect, the present disclosure relates to a computing device configured to perform an embodiment of the above-described method. In another aspect, the present disclosure relates to an integrated circuit configured to perform an embodiment of the above-described method. In another aspect, the present disclosure relates to a non-transitory computer-readable medium comprising instructions that, when executed by a processing device, cause the processing device to perform an embodiment of the above-described method. While features and elements are described above in particular combinations, one of ordinary skill in the art will appreciate that each feature or element can be used alone or in any combination with the other features and elements. In addition, the methods described herein can be implemented in a computer program, software, or firmware incorporated in a computer- readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (through wired or wireless connections) and computer- readable storage media. Examples of computer-readable storage media include, but are not limited to, read only memory (ROM), random access memory (RAM), register, cache memory, semiconductor memory devices, magnetic media such as internal hard disks and removable disks, magneto-optical media, and optical media such as CD-ROM disks, and digital versatile disks (DVDs). The processor associated with a software can be used to implement a radio frequency transceiver used in a WTRU, UE, terminal, base station, RNC, or any host computer.
Claims
1. A method for context transfer of an Authorized Edge Enabler Client (EEC), comprising: The application context is determined from the first edge enabler server by the edge enabler client (EEC) performed by the wireless transmit / receive unit (WTRU). In response to the determination, the EEC requests an authorization token from the token server. The request includes an identifier of the application context and an identifier of one or more authorization restrictions, the one or more authorization restrictions corresponding to the characteristics of the edge enabler server required for authorization. The EEC receives the authorization token for the application context from the token server; The EEC transmits the authorization token and the identifier of one or more authorization restrictions to the first edge enabler server; as well as In response to the second edge enabler server having characteristics that match the one or more authorization restrictions, the EEC receives the authorization token from one of the first and second edge enabler servers as an indication to authorize a context transfer from the first edge enabler server to the second edge enabler server.
2. The method of claim 1, wherein the indication is received from a second edge enabler server, the second edge enabler server transmitting the indication to the EEC in response to successfully retrieving EEC context information from a first edge enabler server.
3. The method of claim 2, further comprising the EEC selecting a second edge enabler server from a plurality of edge enabler servers.
4. The method according to claim 2 or claim 3, further comprising transmitting an application context relocation request from the EEC to a second edge enabler server, the application context relocation request including an authorization token.
5. The method of claim 1, wherein upon receiving the indication from a first edge enabler server, the first edge enabler server transmits the indication to the EEC in response to the first edge enabler server successfully pushing EEC context information to a second edge enabler server.
6. The method of claim 5, wherein the first edge enabler server selects the second edge enabler server from a plurality of edge enabler servers.
7. The method according to any of the preceding claims, wherein determining the relocation of the application context from the first edge enabler server further includes monitoring the physical location or movement of the WTRU.
8. The method according to any of the preceding claims, wherein the one or more authorization restrictions do not identify a specific edge enabler server.
9. The method according to any of the preceding claims, wherein the one or more authorization restrictions include an identifier of the validity duration of the authorization token, location or region, minimum communication latency, application capability, or maximum utilization level.
10. A method comprising: The authorization token server receives a request for an authorization token from the edge enabler client (EEC) executed by the wireless transmit / receive unit (WTRU). The request includes an identifier of the application context associated with a first edge enabler server and an identifier of one or more authorization restrictions, which correspond to the characteristics of the edge enabler server required for authorization. The authorization token is provided to the EEC by the authorization token server; The authorization token is then received by the authorization token server from the second edge enabler server; The authorization token server determines that the authorization token is valid by matching one or more authorization restrictions based on the characteristics of the second edge enabler server, and authorizes the application context to be relocated to the second edge enabler server; as well as In response to the determination, the authorization token server transmits the authorization for the relocation of the application context to one or more of the EEC, the first edge enabler server, and the second edge enabler server.
11. The method of claim 10, wherein the one or more authorization restrictions do not identify a specific edge enabler server.
12. The method of claim 10 or 11, wherein the one or more authorization restrictions include location or region, minimum communication latency, application capability, or maximum utilization level.
13. The method according to any one of claims 10 to 12, wherein the one or more authorization restrictions include the effective duration of the authorization token.
14. The method according to any one of claims 10 to 13, wherein the application context includes WTRU or user equipment (UE) identity information, location information, application client (AC) profile, or service session context information.
15. A wireless transmit / receive unit (WTRU) configured to perform the method as described in any one of claims 1-14.
16. A user equipment (UE) configured to perform the method as described in any one of claims 1-14.
17. A network device configured to perform the method as claimed in any one of claims 1-14.
18. A computing device configured to perform the method as claimed in any one of claims 1-14.
19. An integrated circuit configured to perform the method as described in any one of claims 1-14.
20. A non-transitory computer-readable medium comprising instructions that, when executed by a processing device, cause the processing device to perform the method as claimed in any one of claims 1-14.