Communication method, communication device, communication system and storage medium

CN121100540APending Publication Date: 2025-12-09BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480013948.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-07
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

There is a mutual distrust problem between PLMN and NPN, which affects communication security.

Method used

The network function service consumer sends a discovery request to the network storage function NRF through the service communication proxy SCP, and the NRF receives and processes the request to improve communication security.

Benefits of technology

By using this method, the communication security between PLMN and NPN is improved, attackers are prevented from collecting topology information and sending messages of wrong NF type, and illegal service and information exchange are restricted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121100540A_ABST
    Figure CN121100540A_ABST
Patent Text Reader

Abstract

The invention relates to a communication method, communication equipment, a communication system and a storage medium. The method comprises the following steps: a network function service consumer sends a first discovery request to a network storage function (NRF) through a service communication proxy (SCP); through the embodiment of the invention, the communication security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, communication device, communication system, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, a communication device, a communication system and a storage medium. BACKGROUND

[0002] A Non-Public Network (NPN) can be carried by a Public Land Mobile Network (PLMN). For performance and privacy reasons, NPN users can request to deploy one or more PLMN network functions (NFs) at customer premises. Then, these customer premises PLMN NFs can be considered as NPN NFs. Among them, deploying dedicated NFs at customer premises, for example, can be sinking NFs to the customer's (for example, enterprise A) machine room, etc. For example, the customer premises can deploy dedicated User Plane Function (UPF) and part of Control Plane (CP) functions.

[0003] However, there is a problem of mutual distrust between the PLMN and the NPN, which affects the communication security.

[0004] SUMMARY

[0005] How to improve the security of communication between network devices located in different networks is a technical problem to be solved.

[0006] Embodiments of the present disclosure provide a communication method, a communication device, a communication system and a storage medium.

[0007] According to a first aspect of embodiments of the present disclosure, a communication method is provided, and the method comprises: sending, by a network function service consumer, a first discovery request to a network repository function (NRF) through a service communication proxy (SCP).

[0008] According to a second aspect of embodiments of the present disclosure, a communication method is provided, and the method comprises: receiving, by a network repository function (NRF), a first discovery request sent by a network function service consumer through a service communication proxy (SCP).

[0009] According to a third aspect of embodiments of the present disclosure, a communication method is provided, and the method comprises: receiving, by a service communication proxy (SCP), a first discovery request sent by a network function service consumer, and sending the first discovery request to a network repository function (NRF).

[0010] According to a fourth aspect of the embodiments of the present disclosure, a network function service consumer is provided, including: a transceiver configured to send a first discovery request to a network storage function (NRF) via a service communication proxy (SCP).

[0011] According to a fifth aspect of the embodiments of the present disclosure, a NRF is provided, including: a transceiver configured to receive a first discovery request sent by a network function service consumer via a service communication proxy (SCP).

[0012] According to a sixth aspect of the embodiments of the present disclosure, a SCP is provided, including: a transceiver configured to receive a first discovery request sent by a network function service consumer, and send the first discovery request to a network storage function (NRF).

[0013] According to a seventh aspect of the embodiments of the present disclosure, a network function service consumer is provided, including: one or more processors; and wherein the processor is configured to execute the communication method of the first aspect.

[0014] According to an eighth aspect of the embodiments of the present disclosure, a NRF is provided, including: one or more processors; and wherein the processor is configured to execute the communication method of the second aspect.

[0015] According to a ninth aspect of the embodiments of the present disclosure, a SCP is provided, including: one or more processors; and wherein the processor is configured to execute the communication method of the third aspect.

[0016] According to a tenth aspect of the embodiments of the present disclosure, a communication system is provided, including a network function service consumer, a NRF and a SCP, wherein the network function service consumer is configured to implement the communication method of the first aspect, the NRF is configured to implement the communication method of the second aspect, and the SCP is configured to implement the communication method of the third aspect.

[0017] According to an eleventh aspect of the embodiments of the present disclosure, a storage medium is provided, which stores instructions, when the instructions are executed on a communication device, causing the communication device to execute any of the above communication methods.

[0018] According to a twelfth aspect of the embodiments of the present disclosure, a computer program is provided, which, when executed by a communication device, causes the communication device to execute any of the above communication methods.

[0019] According to the embodiments of the present disclosure, the network function service consumer sends a discovery request to the NRF via the SCP, which can improve the communication security. BRIEF DESCRIPTION OF DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0021] FIG. 1A is a schematic diagram of an architecture of a PNI-NPN in which a customer-side deployment is dedicated to a UPF and part of CP functions.

[0022] FIG. 1B is a schematic diagram of a communication system architecture, according to an embodiment of the present disclosure.

[0023] FIG. 2A is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0024] FIG. 2B is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0025] FIG. 2C is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0026] FIG. 2D is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0027] FIG. 3A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0028] FIG. 3B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0029] FIG. 4A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0030] FIG. 4B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0031] FIG. 5A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0032] FIG. 5B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0033] FIG. 6 is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0034] FIG. 7A is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0035] FIG. 7B is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0036] FIG. 7C is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0037] FIG. 7D is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0038] FIG. 8A is a structural diagram of a network function service consumer according to an embodiment of the present disclosure.

[0039] FIG. 8B is a structural diagram of an NRF according to an embodiment of the present disclosure.

[0040] FIG. 8C is a structural diagram of an SCP according to an embodiment of the present disclosure.

[0041] FIG. 9A is a structural diagram of a communication device according to an embodiment of the present disclosure.

[0042] FIG. 9B is a structural diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0043] The present disclosure provides a communication method, a communication device, a communication system, and a storage medium.

[0044] In a first aspect, a communication method is provided. The method includes: sending, by a network function service consumer, a first discovery request to a network repository function (NRF) via a service communication proxy (SCP).

[0045] In the above embodiments, the network function service consumer sends a discovery request to the NRF via the SCP, which can improve communication security.

[0046] In some embodiments of the first aspect, the method further includes: sending, by the network function service consumer, a second discovery request to the NRF, the NRF being configured to reject the second discovery request when a first policy is met; and in response to the NRF rejecting the second discovery request, receiving, by the network function service consumer, indication information sent by the NRF, the indication information being used to instruct the network function service consumer to send the first discovery request to the NRF via the SCP.

[0047] In some embodiments of the first aspect, the method further includes: in response to the network function service consumer determining that the first policy is met based on a predefined rule, determining to send the first discovery request to the NRF via the SCP.

[0048] In some embodiments of the first aspect, the first discovery request is used to discover a network function service provider, and the first policy includes at least one of the following: the network function service consumer is located in a first network, and the network function service provider is located in a second network; the network function service consumer is located in the second network, and the network function service provider is located in the first network; the network function service consumer is located in a third network, and the network function service provider is located in a fourth network, wherein the network types of the third network and the fourth network are the same as that of the second network.

[0049] In some embodiments of the first aspect, in some embodiments, the SCP is configured to determine whether to authorize the network function service consumer to send the first discovery request to the NRF based on a predefined rule; in response to the SCP authorizing the network function service consumer to send the first discovery request to the NRF, the network function service consumer sends the first discovery request to a network storage function (NRF) through the SCP.

[0050] In some embodiments of the first aspect, in some embodiments, the predefined rule comprises at least one of: whether a network function service consumer in a first network is allowed to request content of a network function service provider in a second network; whether a network function service consumer of a first network function type in the first network is allowed to request content of a network function service provider in the second network; the content comprises at least one of a service, a resource, and information.

[0051] In some embodiments of the first aspect, in some embodiments, the method further comprises: in response to the NRF authorizing the first discovery request based on the first information of the network function service provider, the network function service consumer communicates with the network function service provider through the SCP.

[0052] In some embodiments of the first aspect, in some embodiments, the NRF authorizing the first discovery request based on the first information of the network function service provider comprises at least one of: the NRF passing the authentication of the network function service consumer and obtaining information of a network to which the network function service consumer is associated; the NRF determining, based on the first information of the network function service provider, that the network function service provider allows a predetermined type of network function service consumer to request content of the network function service provider, and / or that the network function service provider allows a network to which the network function service consumer is associated to request content of the network function service provider; and / or that the network function service provider allows a network function in the network to which the network function service consumer is associated to request content of the network function service provider, the content comprising at least one of a service, a resource, and information.

[0053] In some embodiments of the first aspect, in some embodiments, the first information of the network function service provider is configured to indicate at least one of: whether a network function service consumer of a first network function type in a first network is allowed to request content of a network function service provider in a second network; whether a network function service consumer of a first network function type in the second network is allowed to request content of a network function service provider in the first network; wherein the content comprises at least one of a service, a resource, and information.

[0054] In some embodiments of the first aspect, in some embodiments, the network function service consumer is located in a NPN supported by a visited network, and the first discovery request is used to discover a network function service provider located in a home network; the network function service consumer sends the first discovery request to a network repository function (NRF) through a service communication proxy (SCP), including that the network function service consumer sends the first discovery request to a visited NRF through the SCP, and the visited NRF is used to send the first discovery request to a home NRF through a first security edge protection proxy (SEPP) and a second SEPP.

[0055] In some embodiments of the first aspect, in some embodiments, the first discovery request includes fourth information of the network service consumer, and the first SEPP is used to process the fourth information to obtain fifth information and send the fifth information to the second SEPP, and the second SEPP is used to process the fifth information to obtain sixth information.

[0056] In some embodiments of the first aspect, in some embodiments, the method further includes that the network function service consumer receives a first message sent by the SCP, and the first message includes second information of the network function service provider, and the second information is information obtained by the SCP by processing third information of the network function service provider.

[0057] In some embodiments of the first aspect, in some embodiments, the first discovery request includes fourth information of the network function service consumer, and the SCP is used to process the fourth information of the network function service consumer to obtain fifth information.

[0058] In some embodiments of the first aspect, in some embodiments, the method further includes that the network function service consumer sends a subscriber permanent identifier (SUPI) to the SCP, and the SCP is used to send the SUPI to a user data management (UDM) to obtain a generic public subscriber identifier (GPSI).

[0059] In some embodiments of the first aspect, in some embodiments, the method further includes that the network function service consumer sends a subscriber permanent identifier (SUPI) to a user data management (UDM) to obtain a generic public subscriber identifier (GPSI), and the network function service consumer sends the GPSI to the SCP.

[0060] In a second aspect, the embodiments of the present disclosure provide a communication method, including that a network repository function (NRF) receives a first discovery request sent by a network function service consumer through a service communication proxy (SCP).

[0061] In the above embodiment, in the above embodiment, the NRF receives a discovery request sent by a network function service consumer through the SCP, and communication security can be improved.

[0062] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: receiving, by the NRF, a second discovery request sent by the network function service consumer; and rejecting, by the NRF, the second discovery request when the first policy is met.

[0063] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: in response to the NRF rejecting the second discovery request, sending, by the NRF, indication information to the network function service consumer, the indication information being used to instruct the network function service consumer to send a first discovery request to the NRF through the SCP.

[0064] In combination with some embodiments of the second aspect, in some embodiments, the first discovery request is used to discover a network function service provider, and the first policy includes at least one of the following: the network function service consumer is located in a first network, and the network function service provider is located in a second network; the network function service consumer is located in the second network, and the network function service provider is located in the first network; the network function service consumer is located in a third network, and the network function service provider is located in a fourth network, wherein the network types of the third network and the fourth network are the same as the network type of the second network.

[0065] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: authorizing, by the NRF, the first discovery request based on first information of a network function service provider.

[0066] In combination with some embodiments of the second aspect, in some embodiments, the NRF authorizes the first discovery request based on first information of a network function service provider, including at least one of the following: the NRF passes authentication of the network function service consumer and obtains information of a network associated with the network function service consumer; the NRF determines, based on the first information of the network function service provider, that the network function service provider allows a predetermined type of network function service consumer to request content of the network function service provider, and / or the network function service provider allows a network associated with the network function service consumer to request content of the network function service provider; and / or the network function service provider allows a network function in the network associated with the network function service consumer to request content of the network function service provider, the content including at least one of a service, a resource, and information.

[0067] In some embodiments of the second aspect, in some embodiments, the first information of the network function service provider is used to indicate at least one of: whether a network function service consumer of a first network function type located in the first network is allowed to request content of the network function service provider located in the second network; whether a network function service consumer of the first network function type located in the second network is allowed to request content of the network function service provider located in the first network; wherein the content comprises at least one of a service, a resource, and information.

[0068] In some embodiments of the second aspect, in some embodiments, the network function service consumer is located in a NPN supported by a visited network, and the first discovery request is used to discover a network function service provider located in a home network; the NRF receives the first discovery request sent by the network function service consumer through the SCP, comprising: a visited NRF receiving the first discovery request sent by the network function service consumer through the SCP; and the visited NRF sends the first discovery request to a home NRF through a first SEPP and a second SEPP.

[0069] In some embodiments of the second aspect, in some embodiments, the first discovery request comprises fourth information of the network service consumer, the first SEPP is used to process the fourth information to obtain fifth information and send the fifth information to the second SEPP, and the second SEPP is used to process the fifth information to obtain sixth information.

[0070] In a third aspect, the embodiments of the present disclosure provide a communication method, comprising: receiving, by a service communication proxy SCP, a first discovery request sent by a network function service consumer, and sending the first discovery request to a NRF.

[0071] In some embodiments of the third aspect, in some embodiments, the SCP determines whether to authorize the network function service consumer to send the first discovery request to the NRF based on a predefined rule, and the method further comprises: determining that the SCP authorizes the network function service consumer to send the first discovery request to the NRF.

[0072] In some embodiments of the third aspect, in some embodiments, the predefined rule comprises at least one of: whether a network function service consumer in a first network is allowed to request content of a network function service provider in a second network; whether a network function service consumer of a first network function type located in the first network is allowed to request content of the network function service provider located in the second network; the content comprises at least one of a service, a resource, and information.

[0073] In some embodiments of the third aspect, in some embodiments, the method further includes: sending, by the SCP, a first message to the network function service consumer, the first message including second information of the network function service provider, the second information being information obtained by processing the third information of the network function service provider.

[0074] In some embodiments of the third aspect, in some embodiments, the first discovery request includes fourth information of the network function service consumer, and the method further includes: processing, by the SCP, the fourth information of the network function service consumer to obtain fifth information.

[0075] In some embodiments of the third aspect, in some embodiments, the method further includes: sending, by the SCP, the fifth information to the network function service provider.

[0076] In a fourth aspect, the embodiments of the present disclosure provide a network function service consumer, including: a transceiver module, configured to send a first discovery request to a network storage function NRF through a service communication proxy SCP.

[0077] In a fifth aspect, the embodiments of the present disclosure provide a NRF, including: a transceiver module, configured to receive a first discovery request sent by a network function service consumer through a service communication proxy SCP.

[0078] In a sixth aspect, the embodiments of the present disclosure provide a SCP, including: a transceiver module, configured to receive a first discovery request sent by a network function service consumer, and send the first discovery request to a network storage function NRF.

[0079] In a seventh aspect, the embodiments of the present disclosure provide a network function service consumer, including: one or more processors; wherein the processor is configured to execute the communication method of the first aspect.

[0080] In an eighth aspect, the embodiments of the present disclosure provide a NRF, including: one or more processors; wherein the processor is configured to execute the communication method of the second aspect.

[0081] In a ninth aspect, the embodiments of the present disclosure provide a SCP, including: one or more processors; wherein the processor is configured to execute the communication method of the third aspect.

[0082] In a tenth aspect, the embodiments of the present disclosure provide a communication system, including a network function service consumer, a NRF and a SCP, wherein the network function service consumer is configured to implement the communication method of the first aspect, the NRF is configured to implement the communication method of the second aspect, and the SCP is configured to implement the communication method of the third aspect.

[0083] In a eleventh aspect, the embodiments of the present disclosure provide a storage medium, the storage medium storing instructions, and the instructions, when executed on a communication device, cause the communication device to perform any of the methods described above.

[0084] In a twelfth aspect, the embodiments of the present disclosure provide a program product, comprising: a computer program, the computer program, when executed on a communication device, causing the communication device to perform the method described in any of the optional implementation manners of the first aspect to the fifth aspect.

[0085] In a thirteenth aspect, the embodiments of the present disclosure provide a computer program, when executed on a computer, causing the computer to perform the method described in any of the optional implementation manners described above.

[0086] In a fourteenth aspect, the embodiments of the present disclosure provide a chip or chip system. The chip or chip system comprises processing circuitry configured to perform the method described in any of the optional implementation manners described above.

[0087] It can be understood that the network device, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, which will not be described here.

[0088] The embodiments of the present disclosure propose a communication method, a network function service consumer, a network function, a network function service provider, a communication system and a storage medium. In some embodiments, the terms of the communication method, the information transmission method, the information reporting method, the information receiving method and the like can be replaced with each other.

[0089] The communication device in the embodiments of the present disclosure can include but is not limited to: a network function service consumer, an NRF and an SCP.

[0090] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or all the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.

[0091] In the embodiments of the present disclosure, the terms and / or descriptions among the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0092] The terms used in the embodiments of the present disclosure are only for the purpose of describing particular embodiments and are not used as limitations of the present disclosure.

[0093] In the embodiments of the present disclosure, unless otherwise specified and logically conflicted, the elements expressed in singular form, such as "one", "one kind", "the", "the above", "the", "the above", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.

[0094] In the embodiments of the present disclosure, "plurality" refers to two or more.

[0095] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple" and the like can be replaced with each other.

[0096] In some embodiments, the writing manner of "at least one of A, B", "A and / or B", "A in one case and B in another case", "A in response to one case and B in response to another case" and the like can include the following technical solutions according to the case: A is executed in some embodiments (A is executed regardless of B); B is executed in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected from A and B); A and B are executed in some embodiments (A and B are executed). When there are more branches such as A, B, C, the above is similar.

[0097] In some embodiments, the writing manner of "A or B" and the like can include the following technical solutions according to the case: A is executed in some embodiments (A is executed regardless of B); B is executed in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected from A and B). When there are more branches such as A, B, C, the above is similar.

[0098] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the contents thereof can be the same or different.

[0099] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0100] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0101] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0102] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0103] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0104] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like can be replaced with each other.

[0105] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0106] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.

[0107] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.

[0108] In some embodiments, data, information, etc. can be obtained in compliance with laws and regulations of the country in which the location is situated.

[0109] In some embodiments, data, information, etc. can be obtained after obtaining consent from the user.

[0110] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0111] A Non-Public Network (NPN) can be carried by a Public Land Mobile Network (PLMN). For performance and privacy reasons, NPN users can request to deploy one or more network functions (NFs) dedicated at customer premises. Among them, deploying dedicated NFs at customer premises, for example, can be to sink NFs to the customer's (for example, enterprise A) machine room, etc. For example, the customer premises can deploy a dedicated User Plane Function (UPF) and part of the Control Plane (CP) functions.

[0112] FIG. 1A is a schematic diagram of an architecture of a Public Network Integrated NPN (PNI-NPN) in which dedicated UPF and part of CP functions are deployed at customer premises.

[0113] As shown in FIG. 1A, one or more of a network slice selection function (NSSF), a network exposure function (NEF), a network repository function (NRF), a policy control function (PCF), a unified data management (UDM) function, an application function (AF), an edge application server discovery function (EASDF), the network slice specific authentication and authorization function (NSSAAF), an authentication server function (AUSF), an access and mobility management function (AMF), a session management function (SMF), a Service Control Point (SCP), a Network Slice Admission Control function (NSACF) can be included in the PLMN network, and one or more of an AMF, an SMF, a user plane function (UPF), and a Data Network (DN) deployed at the customer side B can also be included.

[0114] It can be understood that “Nnssf”, “Nnef”, “Nnrf”, “Npcf”, “Nudm”, “Naf”, “Nnssaaf”, “Nausf”, “Namf”, “Nsmf”, “N4”, “N6”, and “N9” in FIG. 1A represent the names of service interfaces, and specific descriptions can be referred to in the related description in the 3GPP standard protocol, which will not be described here.

[0115] The above communication scenario can have the following security problems.

[0116] First, the PLMN does not trust the NPN. Specifically, compared with the PLMN operator, the resources used by the NPN customer for network security protection can be limited, for example, the physical security on the customer side can be weaker than the core network of the PLMN operator. If the network function deployed on the NPN customer side is compromised, it is possible to exploit the NPN-end NFs to attack the PLMN.

[0117] Furthermore, the NPN does not trust the PLMN. The NPN part can be used for very sensitive tasks (for example, an NPN used to support a smart factory full of commercial secrets). In this case, the NPN must deal with the threat brought by the PLMN network function (that is, the NPN cannot trust the PLMN).

[0118] When the NPN and the PLMN do not trust each other (that is, the NPN and the PLMN can both be attackers of each other), the communication system needs to meet the following security requirements.

[0119] Attackers can collect the topology information of the PLMN or the NPN, and use this information to further attack the PLMN or the NPN. Therefore, the communication system should support mutual hiding of the topology information of the PLMN and the customer-side network (NPN).

[0120] When the NPN and the PLMN do not trust each other (that is, the NPN and the PLMN can both be attackers of each other), the communication system needs to meet the following security requirements.

[0121] Attackers can collect the topology information of the PLMN or the NPN, and use this information to further attack the PLMN or the NPN. Therefore, the communication system should support mutual hiding of the topology information of the PLMN and the customer-side network (NPN).

[0122] Attackers can send messages of incorrect NF types to the NFs of the opposite domain according to the 3GPP specification. Therefore, according to the 3GPP specification, the communication system should support blocking messages with incorrect NF types sent from the NFs on the customer side or the operator side on the trust boundary.

[0123] The customer-side compromised NFs can request the NFs in the PLMN to use services not allowed on the customer side, and vice versa. Moreover, the communication system should support limiting the ways of exchanging services and information between the customer side and the operator side, and vice versa.

[0124] However, the communication system in the related art does not support bidirectional topology hiding between the PLMN and the PLMN carrying the NPN; the communication system in the related art does not support blocking messages with incorrect NF types sent from the NFs on the customer side or the operator side on the trust boundary; the communication system in the related art cannot support limiting the ways of exchanging services and information between the customer side and the operator side, and vice versa.

[0125] The embodiment of the present disclosure provides a communication method, a network function service consumer sends a discovery request to an NRF through an SCP, and communication security can be improved.

[0126] FIG. 1B is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.

[0127] As shown in FIG. 1B, the communication system 100 includes a network function service consumer 101, an NRF 102, and an SCP 103. The network function service consumer 101 can be a network device using a service, the NRF 102 can be used for service discovery, and the network function service consumer 101 can send a discovery request to the NRF 102 through the SCP 103. Of course, the network function service consumer 101, the NRF 102, and the SCP 103 can also be other types of nodes in the communication system, and the present disclosure does not limit the same.

[0128] In some embodiments, a network node can include at least one of an access network device and a core network device.

[0129] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5th generation mobile communication technology (5G) communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0130] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0131] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers are controlled by the CU, and the rest or all of the protocol layers are distributed in the DU and controlled by the CU, but not limited thereto.

[0132] In some embodiments, the core network device can be one device including one or more network elements, or can be multiple devices or device groups including all or part of the one or more network elements described above. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next-generation core (NGC), for example.

[0133] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be understood by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.

[0134] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1B or part of the subject, but are not limited thereto. The subjects shown in FIG. 1B are exemplary, and the communication system can include all or part of the subjects in FIG. 1B, or include other subjects other than those in FIG. 1B. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, and the connection can be in any manner, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0135] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. In addition, a plurality of systems can be combined (for example, combination of LTE or LTE-A and 5G, and the like).

[0136] FIG. 2A is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2A, the embodiment of the present disclosure relates to a communication method, the method comprising:

[0137] In step S2101, a Network function (NF) service producer sends first information to the NRF.

[0138] In some embodiments, the NRF receives the first information sent by the network function service producer.

[0139] In some embodiments, the first information is used to represent information related to the network function service producer.

[0140] In some embodiments, the first information can be registration information of the network function service producer.

[0141] In some embodiments, the name of the first information is not limited, for example, it is “registration information”, “configuration information”, “configuration file”, “network function profile”, etc. The first information can also be included in the configuration file of the network function service producer.

[0142] In some embodiments, the network function service producer can register with the NRF.

[0143] In an example, the configuration data of the NF profile of the network function service producer in the network function service producer registration process can contain “additional scope”. The “additional scope” information indicates resources and operations (service operations) allowed to be performed by the network function (NF) service consumer on these resources. These resources can be the network function (NF) type of each network function service consumer, or the NF instance of each network function service consumer. The terminal list associated with the NPN served by the network function service consumer can also be configured in the NF profile.

[0144] In some embodiments, the network function service producer can send NPN related information to the NRF. The NPN information includes at least one of the following: a Closed Access Group (CAG) identifier associated with the NPN; location information; an NPN identifier.

[0145] In some embodiments, the NPN information sent by the network function service producer is used to indicate that the network function in the NPN can obtain content related to the network function service producer. The content includes at least one of services, resources, and information.

[0146] In some embodiments, the NPN information sent by the network function service provider is used to indicate that a specific network function type in the NPN can acquire the content related to the network function service provider. The content includes at least one of service, resource, and information.

[0147] In some embodiments, the NPN information sent by the network function service provider is used to indicate that the NPN can acquire the content related to the network function service provider. The content includes at least one of service, resource, and information.

[0148] In some embodiments, the first information is used to authorize the network function service consumer to determine whether the network function service consumer is allowed to request the content of the network service provider. The content of the network function service provider includes at least one of service, resource, and information.

[0149] In some embodiments, the first information is used to indicate at least one of A and B below:

[0150] A. Whether the network function service consumer of the first network function type located in the first network is allowed to request the content of the network function service provider located in the second network. For example, whether the network function service consumer (e.g., AMF) of a specific NF type located in a specific PLMN is allowed to request the service / resource / information (e.g., specific data) of a specific network function service provider located on the NPN side. For example, whether the network function service consumer (e.g., AMF) of a specific NF type located in a specific NPN is allowed to request the service / resource / information (e.g., specific data) of a specific network function service provider located on the PLMN side.

[0151] B. Whether the network function service consumer of the first network function type located in the second network is allowed to request the content of the network function service provider located in the first network. For example, whether the network function service consumer (e.g., AMF) of a specific NF type located in a specific NPN is allowed to request the service / resource / information (e.g., specific data) of a specific network function service provider located on the PLMN side. For example, whether the network function service consumer (e.g., AMF) of a specific NF type located in a specific PLMN is allowed to request the service / resource / information (e.g., specific data) of a specific network function service provider located on the NPN side.

[0152] In some embodiments, the network function service provider is any one of network devices for providing services.

[0153] In some embodiments, the network function service provider can send a certificate of the network function service provider to the NRF. The certificate can be, for example, a Transport Layer Security (TLS) or the like.

[0154] In some embodiments, the network function service provider and the NRF can be mutually authenticated based on a certificate. In an example, the NRF can determine the NPN information associated with the network function service provider based on the first information (e.g., a profile) of the network function service provider or a certificate of the network function service provider. The NPN information associated with the network function service provider can also be referred to as the information of the NPN served by the network function service provider.

[0155] In some embodiments, the NRF can store the first information.

[0156] In some embodiments, the NRF can send a message to the network function service provider, through which the network function service provider sends a registration request is responded.

[0157] In step S2102, the network function service consumer sends seventh information to the NRF.

[0158] In some embodiments, the NRF receives the seventh information sent by the network function service consumer.

[0159] In some embodiments, the name of the seventh information is not limited, which is, for example, “registration information”, “configuration information”, “configuration file”, “network function profile” and the like. Among them, the seventh information can also be included in the profile of the network function service provider.

[0160] In some embodiments, the network function service consumer can register with the NFR. In an example, the network function service consumer can send the seventh information when it is first run. For example, the seventh information can be sent through “registration request information (Nnrf_NFManagement_NFRegister Request)”.

[0161] In some embodiments, the seventh information includes the NPN information associated with the network function service consumer, which includes at least one of the following: a closed access group (CAG) identifier associated with the NPN; location information; NPN identifier.

[0162] In some embodiments, the seventh information is configured by an operation maintenance management (OAM) system.

[0163] In some embodiments, the network function service consumer can send a certificate of the network function service consumer to the NRF. The certificate can be, for example, a Transport Layer Security (TLS) or the like.

[0164] In some embodiments, the network function service consumer and the NRF can be mutually authenticated based on the certificate. In an example, the NRF can determine the NPN information associated with the network function service consumer based on the seventh information (e.g., a profile) of the network function service consumer or the certificate of the network function service consumer. The NPN information associated with the network function service consumer can also be referred to as the information of the NPN served by the network function service consumer.

[0165] In some embodiments, the network function service consumer can be authenticated by the NRF based on a Client Credentials Assertion (CCA). In some embodiments, the NRF can determine the NPN information associated with the network function service consumer based on the seventh information (e.g., a profile) of the network function service consumer or the certificate of the network function service consumer or the CCA of the network function service consumer. The NPN information associated with the network function service consumer can also be referred to as the information of the NPN served by the network function service consumer.

[0166] In some embodiments, the NRF can store the seventh information.

[0167] In some embodiments, the NRF can send a message to the network function service consumer, and the message is used to respond to the registration request sent by the network function service consumer.

[0168] In step S2103, the network function service consumer sends a second discovery request to the NRF.

[0169] In some embodiments, the second discovery request is used to request to discover devices available in the network. For example, the second discovery request is used to request to discover network function service providers.

[0170] In some embodiments, the network function service consumer discovers services available in the network according to the name and type of the network function service. The network function service consumer invokes the second discovery request from the NRF appropriately configured in the same PLMN, and the second discovery request includes the expected NF service name, the NF type of the expected NF instance, and the NF type of the network function service consumer.

[0171] In an example, the second discovery request can be a network function service discovery request (Nnrf_NFDiscovery_Request) invoked in the NRF.

[0172] In addition, the NPN indication information is included in the second discovery request for discovering the service provided by the NPN. The NPN indication information may be, for example, a CAG identifier related to the NPN, location information (for example, a geographic location, a data center) that can identify a specific NPN, or an NPN identifier.

[0173] At step S2104, the NRF rejects the second discovery request.

[0174] In some embodiments, the NRF determines whether to authorize the second discovery request.

[0175] In some embodiments, the NRF passes the authentication of the network function service consumer and obtains the NPN information provided by the network function service consumer. For example, the seventh information is obtained.

[0176] In some embodiments, the NRF determines the first policy for determining whether to authorize the second discovery request based on the seventh information.

[0177] In an example, the NRF determines whether to authorize the second discovery request according to the NPN indication (optional), the profile of the expected NF / NF service, and the type of the network function service consumer, to determine whether to allow the network function service consumer to discover the expected NF instance.

[0178] In some embodiments, the first policy is used by the network function service consumer to determine whether to authorize the second discovery request.

[0179] In some embodiments, the first policy is used to determine whether the network in which the service requested by the network function service consumer is located and the network of the network function service consumer belong to the same network. Alternatively, it can also be understood that the first policy is used to determine whether the network in which the network function service provider requested to be discovered by the network function service consumer is located and the network of the network function service consumer belong to the same network. In an example, whether to belong to the same network can be understood as whether to cross domains.

[0180] In some embodiments, the first policy is a policy for determining not to authorize the second discovery request. Wherein, not to authorize can also be understood as rejecting the second discovery request. Of course, it can be understood that the first policy can also be a policy for determining to authorize the second discovery request.

[0181] In the embodiments of the present disclosure, the first policy is a policy for rejecting the second discovery request. For the implementation of the first policy being a policy for authorizing the second discovery request, it is opposite to the above.

[0182] In an example, the first policy includes at least one of the following A, B, and C:

[0183] A. The network function service consumer is located in a first network, and the network function service provider is located in a second network.

[0184] B. The network function service consumer is located in a second network, and the network function service provider is located in a first network.

[0185] C. The network function service consumer is located in a third network, and the network function service provider is located in a fourth network, wherein the network types of the third network and the fourth network are the same as the network type of the second network.

[0186] In some embodiments, the first network is a PLMN, and the second network is a NPN.

[0187] In some embodiments, the first network is a NPN, and the second network is a PLMN. In some embodiments, the third network is a first NPN, and the fourth network is a second NPN.

[0188] In some embodiments, the NRF determines whether to authorize the second discovery request based on the first policy.

[0189] In an example, the NRF determines whether to authorize the second discovery request based on Table 1 as follows.

[0190] Table 1

[0191] In some embodiments, the NRF determines to authorize the second discovery request in a case where the NRF determines that the first policy is not satisfied. The NRF allows discovery of the network function service consumer based on the NRF. The network function service consumer discovers the network function service consumer based on the NRF.

[0192] In some embodiments, the NRF rejects the second discovery request in a case where the NRF determines that the first policy is satisfied, to avoid information leakage between the network function service consumer and the network function service provider.

[0193] In step S2105, the NRF sends indication information to the network function service consumer.

[0194] In some embodiments, the NRF sends the indication information in response to the NRF rejecting the second discovery request.

[0195] In some embodiments, the indication information is used to indicate that the network function service consumer sends the first discovery request to the NRF through the SCP. Alternatively, the indication information is used to indicate that the NRF rejects the second discovery request. Alternatively, the indication information is used to indicate that the service discovery request to the NRF fails / error.

[0196] In some embodiments, the indication information is used to indicate that the network function service consumer sends the first discovery request to the NRF through multiple SCPs.

[0197] In some embodiments, the network function service consumer receives the indication information sent by the NRF.

[0198] At step S2106, the network function service consumer sends a first discovery request to the NRF through a service communication proxy (SCP).

[0199] In some embodiments, the first discovery request is used to discover a network function service provider.

[0200] In some embodiments, the network function service consumer sends the first discovery request to the NRF through one service communication proxy (SCP).

[0201] In some embodiments, the network function service consumer sends the first discovery request to the NRF through multiple (e.g., 2) service communication proxies (SCPs).

[0202] In some embodiments, the first discovery request includes discovery parameters required for discovering a network function service provider. In an example, the discovery parameters can include parameters in the second discovery request. For example, including an NPN indication.

[0203] In some embodiments, if the network function service consumer is located in a PLMN but expects the requested service / network function service provider to be in an NPN, the network function service consumer should send a second discovery request to the SCP to perform the subsequent discovery process of the network function service provider through the SCP, avoiding information leakage between the network function service consumer and the network function service provider.

[0204] In some embodiments, if the network function service consumer is located in an NPN but expects the requested service / network function service provider to be in a PLMN, the network function service consumer should send a second discovery request to the SCP to perform the subsequent discovery process of the network function service provider through the SCP, avoiding information leakage between the network function service consumer and the network function service provider.

[0205] At step S2107, the NRF authorizes the first discovery request.

[0206] In some embodiments, the SCP can perform the first discovery request by interacting with the NRF using a network function discovery service.

[0207] In some embodiments, the NRF authorizes the first discovery request based on the first information of the network function service provider. For example, the NRF authorizes the first discovery request based on information collected during the registration interaction between the network function service consumer, the network function service provider and the NRF (through the Nnrf_NFDiscovery service or the Nnrf_NFManagement_NFStatusNotify service operation). Wherein, the SCP interacts with the NRF to authorize the first discovery request, so that the SCP selects the network function service provider requested by the network function service consumer.

[0208] In some embodiments, the NRF authorizes the first discovery request based on the first information of the network function service provider, including at least one of the following A and B:

[0209] A. The NRF is authenticated by the network function service consumer and obtains the information of the network associated with the network function service consumer.

[0210] B. The NRF determines, based on the first information of the network function service provider, that the network function service provider allows the type of network function service consumer to request the content of the network function service provider of a predetermined type; and / or, the network function service provider allows the network associated with the network function service consumer to request the content of the network function service provider; and / or, the network function service provider allows the network function in the network associated with the network function service consumer to request the content of the network function service provider. Wherein, the content includes at least one of service, resource, and information.

[0211] In some embodiments, the first information (profile of the network function service provider) indicates that a specific NF type (e.g. AMF) in a specific NPN can / cannot discover / access / use the services / resources (e.g. specific data) of a specific NF provider on the PLMN side. And / or the first information (profile of the network function service provider) indicates that a specific NF type (e.g. AMF) in a specific PLMN can / cannot discover / access / use the services / resources (e.g. specific data) of a specific NF provider on the NPN side. In an example, the NRF authorizes the first discovery request based on the manner of Table 2 below to determine whether to authorize the first discovery request.

[0212] Table 2

[0213] Step S2108, the SCP sends a first request to the network function service provider.

[0214] In some embodiments, the first request may, for example, be a service request or a subscription request.

[0215] In some embodiments, the network function service consumer receives the first request sent by the SCP.

[0216] In some embodiments, in response to the first discovery request being authorized by the NRF, the network function service consumer is authorized to communicate with the network function service provider through the SCP. The SCP selects the network function service provider. In one example, the SCP forwards the first request to the discovered network function service provider according to the configuration of the network slice. For example, the SCP sends the first request corresponding to the network function expected to be sent to the corresponding network function service provider through the same network slice.

[0217] In some embodiments, the fourth information of the network function service consumer is included in the first request. The SCP processes the fourth information to obtain the fifth information.

[0218] In some embodiments, the fourth information of the network function service consumer is included in the first request, and the fourth information is address information (e.g., IP address, FQDN, etc.) of the network function service consumer. The SCP processes the fourth information to obtain the fifth information, and the processing is topology hiding.

[0219] Step S2109, the SCP sends the fifth information to the network function service provider.

[0220] In some embodiments, the network function service provider receives the fifth information sent by the SCP.

[0221] Step S2110, the network function service provider sends a second message to the SCP.

[0222] In some embodiments, the SCP receives the second message sent by the network function service provider.

[0223] In some embodiments, the second message is used to respond to the first discovery request sent by the SCP.

[0224] In some embodiments, the second message can also be referred to as a response message. Or it can also be referred to as a discovery response.

[0225] In some embodiments, if the first discovery request creates a resource in the network function service provider, the network function service provider will return resource information for identifying the created resource.

[0226] Step S2111, the SCP sends the first message to the network function service consumer.

[0227] In some embodiments, the network function service consumer receives the first message sent by the SCP.

[0228] In some embodiments, the SCP sending the first message to the network function service consumer can be understood as the SCP routing the second message to the network function service consumer.

[0229] In some embodiments, the second information in the first message is information related to the network function service provider.

[0230] In some embodiments, the second information is information obtained by the SCP processing the third information of the network function service provider.

[0231] In some embodiments, the third information of the network function service provider may, for example, be address information (e.g., IP address, FQDN, etc.) of the network function service provider.

[0232] In some embodiments, the SCP performs topology hiding on the third information (e.g., IP address, FQDN, etc.) of the network function service provider to obtain the second information.

[0233] In some embodiments, the network function service consumer receives the second information processed from the third information (e.g., address information of the network function service provider), and the network function service consumer can perform subsequent communication processing based on the second information. For example, subsequent operations on the created resource. For example, requesting the corresponding created resource.

[0234] In some embodiments, if the network function service consumer does not receive the second information, the communication process based on the first discovery request can end here.

[0235] Step S2112, the network function service consumer sends a second request to the SCP.

[0236] In some embodiments, the second request may, for example, be a service request or a subscription request.

[0237] In some embodiments, the second request is used to request the network function service of the network function service provider. For example, requesting subsequent operations on the created resource.

[0238] In some embodiments, the second request includes the second information of the network function service provider.

[0239] In some embodiments, the SCP receives the second request sent by the network function service consumer.

[0240] In some embodiments, the SCP resolves the second information included in the second request (e.g., resolves the address information of the network function service provider) to obtain third information of the network function service provider that needs to be selected. In an example, the SCP resolves the third information of the network function service provider, and selects the network function service provider based on the third information.

[0241] At step S2113, the SCP sends a second request to the network function service provider.

[0242] In some embodiments, the second request can be a service request or a subscription request.

[0243] In some embodiments, the network function service provider receives the second request sent by the SCP.

[0244] In some embodiments, the second request includes address information (e.g., IP address, FQDN, etc.) of the network function service consumer. The SCP performs topology hiding on the address information of the network function service consumer. The second request sent by the SCP to the network function service provider includes the topology-hidden address information of the network function service consumer.

[0245] At step S2114, the network function service provider sends a third message to the SCP.

[0246] In some embodiments, the third message is a response to the second request.

[0247] In some embodiments, the network function service provider can use the updated resource information to send the third message in response. The third message is different from the second message.

[0248] In some embodiments, the SCP receives the third message sent by the network function service provider.

[0249] At step S2115, the SCP sends a third message to the network function service consumer.

[0250] In some embodiments, the network function service consumer receives the third message sent by the SCP.

[0251] In some embodiments, the SCP performs replacement processing on the third information of the network function service provider to obtain second information, and sends the third message including the second information to the network function service consumer.

[0252] In some embodiments, if the resource information on the network function service provider side is updated, the network function service consumer uses the received updated resource information to perform subsequent operations on the resource.

[0253] Step S2116, the network function service consumer sends a Subscription Permanent Identifier (SUPI) to the SCP, or the network function service consumer sends a Generic Public Subscription Identifier (GPSI) to the SCP.

[0254] In some embodiments, if the network function service consumer includes a SUPI in a message (e.g., the first discovery request, the second discovery request, the first request, the second request, etc.) sent from one network to another network, the network function service consumer needs to convert the SUPI to a GPSI before sending the message, and send the converted GPSI. Alternatively, the network function service consumer sends the SUPI to a corresponding entity (e.g., the SCP) before sending the message, and the corresponding entity converts the SUPI to a GPSI before sending to another network, and sends the converted GPSI. The sending of the message from one network to another network can be sending from a PLMN to a NPN. The sending of the message from one network to another network can also be sending from a NPN to a PLMN.

[0255] In some embodiments, the network function service consumer can send a SUPI to a User Data Management (UDM) to obtain a GPSI, and send the obtained GPSI to the SCP.

[0256] In some embodiments, the network function service consumer can send a SUPI to the SCP, and the SCP sends the SUPI to a UDM to obtain a GPSI. The SCP sends the converted GPSI before sending to another network.

[0257] In some embodiments, if the SCP includes a SUPI in a message sent from one network to another network, the SCP needs to convert the SUPI to a GPSI before sending the message, and send the converted GPSI. The sending of the message from one network to another network can be sending from a PLMN to a NPN. The sending of the message from one network to another network can also be sending from a NPN to a PLMN.

[0258] In some embodiments, the SCP sends a SUPI to a UDM to obtain a GPSI.

[0259] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101-S2116. For example, step S2106 can be implemented as an independent embodiment, step S2107 can be implemented as an independent embodiment, and steps S2104+S2105+S2106 can be implemented as an independent embodiment, but are not limited thereto.

[0260] In some embodiments, steps S2101 and S2102 can be exchanged in order or performed simultaneously, and steps S2106 and S2116 can be exchanged in order or performed simultaneously.

[0261] In some embodiments, steps S2101, S2102, S2103, and S2107-S2116 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0262] FIG. 2B is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2B, the embodiments of the present disclosure relate to a communication method, and the method includes:

[0263] In step S2201, the network function service provider sends first information to the home NRF.

[0264] Optional implementation of step S2201 can refer to optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0265] In step S2202, the network function service consumer sends seventh information to the visited NRF.

[0266] Optional implementation of step S2202 can refer to optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0267] In step S2203, the network function service consumer sends a second discovery request to the visited NRF.

[0268] Optional implementation of step S2203 can refer to optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0269] In step S2204, the visited NRF rejects the second discovery request.

[0270] Optional implementation of step S2204 can refer to optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0271] At step S2205, the visited NRF sends indication information.

[0272] In some embodiments, in response to the NRF rejecting the second discovery request, the NRF sends indication information.

[0273] In some embodiments, the indication information is used to instruct the network function service consumer to send the first discovery request to the NRF through the SCP. Alternatively, the indication information is used to instruct the NRF to reject the second discovery request. Alternatively, the indication information is used to instruct that the service discovery request to the NRF fails / error. Alternatively, in the case that the network function service consumer is located in an NPN supported by the visited network, the indication information is used to instruct to send the first discovery request to the visited NRF through the SCP.

[0274] In some embodiments, the network function service consumer receives the indication information sent by the NRF.

[0275] At step S2206, the network function service consumer sends a first discovery request to the visited NRF.

[0276] In some embodiments, the first discovery request may, for example, be a discovery request (Nnrf_NFDiscovery_Request) of the visited NRF invoked by the network function service consumer located in the visited place.

[0277] In some embodiments, the first discovery request includes, for example, an expected service name, an NF type of an expected NF, a home PLMN ID, a service PLMN ID, an NF type of an NF service consumer, and the like.

[0278] In some embodiments, if the expected service / network function service consumer is in an NPN in the home place (PLMN-1), the network function service consumer sends the first discovery request to the visited NRF for service discovery. In the first discovery request, the NPN indication in the optional implementation shown in FIG. 2A is included.

[0279] In some embodiments, the optional implementation regarding the first discovery request can refer to the optional implementation regarding the first discovery request in step S2106 of FIG. 2A and other related parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0280] In some embodiments, the visited NRF sends the first discovery request to the home NRF.

[0281] In some embodiments, the visited NRF sends the first discovery request to the home NRF through the first SEPP and the second SEPP.

[0282] In some embodiments, the home NRF receives the first discovery request sent by the visited NRF.

[0283] In some embodiments, if the NPN indication is included in the first discovery request, the home NRF performs service discovery based on the NPN indication. In an example, if the NF profile of the network function service provider does not allow the network function to be discovered in the NPN, the home NRF shall reject the first discovery request, such as rejecting the discovery request. A failure / error message can also be sent. In an example, if the NF profile of the network function service provider allows the network function to be discovered in the NPN, the home NRF will continue to perform service discovery according to the NPN indication.

[0284] In step S2207, the visited NRF sends the first discovery request to the first SEEP.

[0285] In some embodiments, the fourth information of the network function service consumer is included in the first discovery request. The first SEEP of the visited location processes the fourth information to obtain the fifth information.

[0286] In step S2208, the first SEEP sends the fifth information to the second SEEP.

[0287] In some embodiments, the first SEEP is the SEEP of the visited location, and the second SEEP is the SEEP of the home location.

[0288] In step S2209, the second SEEP sends the fifth information or the sixth information to the home NRF.

[0289] In some embodiments, the second SEEP of the home location sends the fifth information to the home NRF.

[0290] In some embodiments, the second SEEP of the home location processes the fifth information to obtain the sixth information.

[0291] In some embodiments, the second SEEP of the home location sends the sixth information to the home NRF.

[0292] In some embodiments, the fourth information includes address information (such as a Fully qualified domain name (FQDN), an Internet Protocol (IP) address, etc.) of the network function service consumer, and the fifth information and / or the sixth information can be an address identifier (such as a character "A") generated based on the address information (such as the FQDN, the IP address, etc.) of the network function service consumer.

[0293] In step S2210, the home NRF sends the fifth information or the sixth information to the network function service provider.

[0294] In some embodiments, the first SEEP and / or the second SEEP determines whether to authorize the network function service consumer to send the first discovery request based on a predefined rule.

[0295] In some embodiments, the predefined rule comprises at least one of the following A and B:

[0296] A. whether the network function service consumer in the first network is allowed to request the content of the network function service provider in the second network.

[0297] wherein the content comprises at least one of a service, a resource, and information.

[0298] B. whether the network function service consumer of the first network function type located in the first network is allowed to request the content of the network function service provider located in the second network.

[0299] wherein the content comprises at least one of a service, a resource, and information.

[0300] In some embodiments, in response to the first SEEP and / or the second SEEP authorizing the network function service consumer to send the first discovery request, the network function service consumer sends the first discovery request.

[0301] In some embodiments, in response to the first SEEP and / or the second SEEP not authorizing (rejecting) the network function service consumer to send the first discovery request, subsequent sending of the first discovery request to the home NRF is stopped.

[0302] Step S2211, the network function service consumer sends a second request to the first SEEP.

[0303] In some embodiments, the network function service consumer sends the second request, and the second request comprises address information (e.g., IP address, FQDN) of the network function service consumer. The first SEEP performs topology hiding on the address information (e.g., IP address, FQDN) of the network function service consumer. In some embodiments, the optional implementation of the second request can refer to the optional implementation of the second request in step S2112 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be described here.

[0304] Step S2212, the first SEEP sends the second request to the second SEEP.

[0305] Step S2213, the second SEEP sends the second request to the network function service provider.

[0306] In some embodiments, the first SEEP receives the second request sent by the network function service consumer and forwards the second request to the second SEEP, which sends the second request to the network function service provider.

[0307] In some embodiments, the network function service provider receives the second request.

[0308] In some embodiments, the network function service provider sends a third message. In some embodiments, optional implementations of the third message can refer to optional implementations of the first discovery request in step S2114 of FIG. 2A and other associated parts of the embodiments involved in FIG. 2A, which will not be repeated here.

[0309] In some embodiments, the second SEEP receives the third message sent by the network function service provider and forwards the third message to the first SEEP, which sends the third message to the network function service consumer.

[0310] In some embodiments, in some embodiments, if the network function service consumer includes the SUPI in the message (e.g., the first discovery request, the second discovery request, the first request, the second request, etc.) sent from one network to another network, the network function service consumer needs to convert the SUPI to the GPSI before sending the message, and send the converted GPSI. Alternatively, the network function service consumer sends the SUPI to the corresponding entity (e.g., the first SEEP and / or the second SEEP) before sending the message, and the corresponding entity converts the SUPI to the GPSI before sending to another network, and sends the converted GPSI. The message sent from one network to another network can be a message sent from one PLMN to another PLMN.

[0311] In some embodiments, the network function service consumer can send the SUPI to the User Data Management (UDM) to obtain the GPSI, and send the obtained GPSI to the first SEEP and / or the second SEEP.

[0312] In some embodiments, the network function service consumer can send the SUPI to the first SEEP and / or the second SEEP, and the first SEEP and / or the second SEEP send the SUPI to the UDM to obtain the GPSI. The first SEEP and / or the second SEEP send the converted GPSI before sending to another network.

[0313] The communication method related to the embodiments of the present disclosure can include at least one of steps S2201-S2207. For example, steps S2206 and S2207 can be implemented as independent embodiments, but are not limited thereto.

[0314] In some embodiments, steps S2201 and S2202 can be exchanged in order or performed simultaneously.

[0315] In some embodiments, steps S2201, S2202, S2203, S2204-S2205 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0316] FIG. 2C is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2C, the embodiments of the present disclosure relate to a communication method, and the method includes:

[0317] In step S2301, the network function service provider sends first information to the NRF.

[0318] The optional implementation of step S2301 can refer to the optional implementation of step S2101 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be described here.

[0319] In step S2302, the network function service consumer sends seventh information to the NRF.

[0320] The optional implementation of step S2302 can refer to the optional implementation of step S2102 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be described here.

[0321] In step S2303, the network function service consumer determines that the first policy is met.

[0322] In some embodiments, the first policy is used to determine whether to send the first discovery request to the NRF through the SCP.

[0323] In some embodiments, the first policy includes at least one of the following: the network function service consumer is located in a first network, and the network function service provider is located in a second network; the network function service consumer is located in the second network, and the network function service provider is located in the first network; the network function service consumer is located in a third network, and the network function service provider is located in a fourth network, wherein the network types of the third network and the fourth network are the same as the network type of the second network.

[0324] In some embodiments, the network function service consumer determines whether to send the first discovery request to the NRF through the SCP through the first policy. In some embodiments, the network function service consumer determines whether to send the first discovery request to the NRF through the SCP through the first policy.

[0325] In some embodiments, the network function service consumer is located in a first network, the network function service provider is located in a second network, and the network function service consumer determines to send the first discovery request to the NRF via the SCP.

[0326] In some embodiments, the network function service consumer is located in a second network, the network function service provider is located in a first network, and the network function service consumer determines to send the first discovery request to the NRF via the SCP.

[0327] In some embodiments, the network function service consumer is located in a third network, the network function service provider is located in a fourth network, and the network function service consumer determines to send the first discovery request to the NRF via the SCP.

[0328] In some embodiments, the first network is an NPN network, and the second network is a PLMN network.

[0329] In some embodiments, the first network is a PLMN network, and the second network is an NPN network.

[0330] In some embodiments, the third network is one NPN, and the fourth network is another NPN.

[0331] The optional implementation of the first policy can refer to the optional implementation of the first policy in step S2104 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0332] In some embodiments, in response to the network function service consumer determining that the first policy is met based on the predefined rule, it is determined to send the first discovery request to the NRF via the SCP.

[0333] In some embodiments, in response to the network function service consumer determining that the first policy is not met based on the predefined rule, it is determined that the content of accessing the other network is not met, and the content includes at least one of a service, a resource, and information.

[0334] In step S2304, the network function service consumer sends the first discovery request to the NRF via the SCP.

[0335] The optional implementation of step S2304 can refer to the optional implementation of step S2106 of FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0336] Optional implementation of step S2304 can be referred to optional implementation of step S2206, step S2207 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2B. Details are not described here.

[0337] In some embodiments, the communication method related to FIG. 2C can further include at least one of step S2107, step S2108, step S2109, step S2110, step S2111, step S2112, step S2113, step S2114, step S2115, and step S2116 in FIG. 2A. Details can be referred to other associated parts in the embodiments related to FIG. 2A. Details are not described here.

[0338] FIG. 2D is an interaction diagram of a communication method according to embodiments of the present disclosure. As shown in FIG. 2D, the embodiments of the present disclosure relate to a communication method, and the method includes:

[0339] In step S2401, the network function service provider sends first information to the NRF.

[0340] Optional implementation of step S2401 can be referred to optional implementation of step S2101 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A. Details are not described here.

[0341] In step S2402, the network function service consumer sends sixth information to the NRF.

[0342] Optional implementation of step S2402 can be referred to optional implementation of step S2101 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A. Details are not described here.

[0343] In step S2403, the network function service consumer sends a first discovery request to the SCP.

[0344] In some embodiments, the first discovery request is used to discover the network function service provider.

[0345] In some embodiments, the network function service consumer requests the SCP to send the first discovery request to the NRF.

[0346] In some embodiments, optional implementation of the first discovery request can be referred to optional implementation of the first discovery request in step S2106 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A. Details are not described here.

[0347] In some embodiments, the SCP receives the first discovery request sent by the network function service consumer.

[0348] At step S2404, the SCP authorizes the network function service consumer to send the first discovery request to the NRF.

[0349] In some embodiments, the SCP determines whether to authorize the network function service consumer to send the first discovery request to the NRF based on a predefined rule.

[0350] In some embodiments, the predefined rule comprises at least one of the following A and B:

[0351] C. whether the network function service consumer in the first network is allowed to request content of the network function service provider in the second network. Wherein, the content comprises at least one of service, resource, and information.

[0352] D. whether the network function service consumer of the first network function type located in the first network is allowed to request content of the network function service provider located in the second network. Wherein, the content comprises at least one of service, resource, and information.

[0353] In some embodiments, in response to the SCP authorizing the network function service consumer to send the first discovery request to the NRF, the network function service consumer sends the first discovery request to the network storage function NRF through the SCP.

[0354] In some embodiments, in response to the SCP not authorizing (rejecting) the network function service consumer to send the first discovery request to the NRF, the network function service consumer stops sending the first discovery request to the network storage function NRF.

[0355] In some embodiments, the first network is an NPN network, and the second network is a PLMN network.

[0356] In some embodiments, the first network is a PLMN network, and the second network is an NPN network.

[0357] In some embodiments, the communication method related to FIG. 2D can further comprise at least one of steps S2106, S2107, S2108, S2109, S2110, S2111, S2112, S2113, S2114, S2115, and S2116 of FIG. 2A. For details, refer to other associated parts in the embodiments related to FIG. 2A.

[0358] In some embodiments, the communication method related to FIG. 2D further comprises steps S2405 and S2406. For details of the implementation of steps S2405 and S2406, refer to the optional implementation of steps S2206 and S2207 of FIG. 2B and other associated parts in the embodiments related to FIG. 2B.

[0359] In some embodiments, the name of information and the like is not limited to the name described in the embodiments, and the terms of "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", "chip", and the like can be replaced with each other.

[0360] In some embodiments, the terms of "time", "time point", "time", "time position", and the like can be replaced with each other, and the terms of "time length", "time period", "time window", "window", "time", and the like can be replaced with each other.

[0361] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive", and the like can be replaced with each other, and can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like.

[0362] In some embodiments, the terms of "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive", and the like can be replaced with each other.

[0363] In some embodiments, the terms of "certain", "preset", "pre-set", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced with each other, and "certain A", "preset A", "pre-set A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, can be interpreted as A obtained by setting, configuring, or indicating, and the like, and can be interpreted as certain A, certain A, arbitrary A, or first A, but is not limited thereto.

[0364] In some embodiments, the determining or judging can be performed by a value represented by 1 bit (0 or 1), a true or false value (Boolean value) represented by true or false, or a comparison of numerical values (for example, a comparison with a predetermined value), but is not limited thereto.

[0365] In some embodiments, "not expecting to receive" can be interpreted as not receiving on the time domain resource and / or the frequency domain resource, or as not performing subsequent processing on the data, etc. after receiving the data, etc.; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the receiver to respond to the content of the sending.

[0366] FIG. 3A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiment of the present disclosure relates to a communication method, and the method comprises:

[0367] Step S3101: transmitting seventh information.

[0368] The optional implementation of step S3101 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0369] In some embodiments, the network function service consumer sends the seventh information to the NRF.

[0370] Step S3102: transmitting a second discovery request.

[0371] The optional implementation of step S3102 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0372] In some embodiments, the network function service consumer sends the second discovery request to the NRF.

[0373] Step S3103: obtaining indication information.

[0374] The optional implementation of step S3103 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0375] In some embodiments, the NRF sends the indication information to the network function service consumer.

[0376] Step S3104: transmitting a first discovery request.

[0377] The optional implementation of step S3104 can refer to the optional implementation of step S2106 in FIG. 2A, step S2206 in FIG. 2B, step S2304 in FIG. 2C, the optional implementation of step S2403 in FIG. 2D, and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C, and 2D, which are not described here again.

[0378] In some embodiments, the network function service consumer sends the first discovery request to the NRF through the SCP, or the network function service consumer sends the first discovery request to the visited NRF through the SCP, or the network function service consumer sends the first discovery request to the SCP.

[0379] Step S3105: obtaining the first message.

[0380] The optional implementation of step S3105 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which are not described here again.

[0381] In some embodiments, the network function service consumer receives the first message sent by the SCP.

[0382] Step S3106: sending a second request.

[0383] The optional implementation of step S3106 can refer to the optional implementation of step S2112 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which are not described here again.

[0384] In some embodiments, the network function service consumer sends the second request to the SCP.

[0385] Step S3107: obtaining a third message.

[0386] The optional implementation of step S3107 can refer to the optional implementation of step S2115 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which are not described here again.

[0387] In some embodiments, the network function service consumer receives the third message sent by the SCP.

[0388] Step S3108: sending a SUPI or a GPSI.

[0389] The optional implementation of step S3108 can refer to the optional implementation of step S2115 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which are not described here again.

[0390] In some embodiments, the network function service consumer sends the SUPI or the GPSI to the SCP.

[0391] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101-S3108. For example, step S3102 can be implemented as an independent embodiment, and step S3104 can be implemented as an independent embodiment, but is not limited thereto.

[0392] In some embodiments, steps S3101, S3102, and S3103 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0393] In some embodiments, steps S3105, S3106, S3107, and S3108 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0394] FIG. 3B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to a communication method, and the above method includes:

[0395] Step S3201, a first discovery request is sent.

[0396] The optional implementation of step S3201 can refer to the optional implementation of step S2106 in FIG. 2A, step S2206 in FIG. 2B, step S2304 in FIG. 2C, step S2403 in FIG. 2D, and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C, and 2D, which will not be repeated here.

[0397] In some embodiments, the network function service consumer sends the first discovery request to the NRF through the SCP, or the network function service consumer sends the first discovery request to the visited NRF through the SCP, or the network function service consumer sends the first discovery request to the SCP.

[0398] FIG. 4A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 4A, the embodiments of the present disclosure relate to a communication method, and the above method includes:

[0399] Step S4101, first information is obtained.

[0400] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0401] In some embodiments, the NRF receives the first information sent by the network function service provider.

[0402] Step S4102, seventh information is obtained.

[0403] The optional implementation of step S4102 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0404] In some embodiments, the NRF receives the seventh information sent by the network function service consumer.

[0405] Step S4103, obtaining the second discovery request.

[0406] The optional implementation of step S4103 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0407] In some embodiments, the NRF receives the second discovery request sent by the network function service consumer.

[0408] Step S4104, rejecting the second discovery request.

[0409] The optional implementation of step S4104 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0410] In some embodiments, the NRF rejects the second discovery request.

[0411] Step S4105, sending the indication information.

[0412] The optional implementation of step S4105 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0413] In some embodiments, the NRF sends the indication information to the network function service consumer.

[0414] Step S4106, obtaining the first discovery request.

[0415] The optional implementation of step S4106 can refer to the optional implementation of step S2106 in FIG. 2A, step S2206 in FIG. 2B, step S2207 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.

[0416] In some embodiments, the NRF receives the first discovery request sent by the network function service consumer through the SCP.

[0417] In some embodiments, the visited NRF can receive the first discovery request sent by the network function service consumer, and the visited NRF sends the first discovery request to the home NRF. In some embodiments, the visited NRF can receive the first discovery request sent by the network function service consumer, and the visited NRF sends the first discovery request to the home NRF.

[0418] Step S4107, authorizing the first discovery request.

[0419] The optional implementation of step S4107 can refer to the optional implementation of step S2107 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which are not described herein again.

[0420] In some embodiments, the NRF authorizes the first discovery request.

[0421] In some embodiments, the home NRF authorizes the first discovery request.

[0422] The communication method related to the embodiments of the present disclosure can include at least one of steps S4101-S4107. For example, step S4106 can be implemented as an independent embodiment, but is not limited thereto.

[0423] In some embodiments, steps S4101 and S4102 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0424] In some embodiments, steps S4103, S4104 and S4105 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0425] FIG. 4B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to a communication method, and the above method includes:

[0426] Step S4201, obtaining a first discovery request.

[0427] The optional implementation of step S4201 can refer to the optional implementation of step S2106 in FIG. 2A, step S2206 in FIG. 2B, step S2207 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which are not described herein again.

[0428] In some embodiments, the NRF receives the first discovery request sent by the network function service consumer through the SCP.

[0429] FIG. 5A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5A, the embodiments of the present disclosure relate to a communication method, and the above method includes:

[0430] Step S5101, obtaining a first discovery request.

[0431] The optional implementation of step S5101 can refer to the optional implementation of step S2106 in FIG. 2A, step S2403 in FIG. 2D, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described here again.

[0432] In some embodiments, the SCP receives the first discovery request sent by the network function service consumer.

[0433] In step S5102, the SCP authorizes the network function service consumer to send the first discovery request to the NRF.

[0434] The optional implementation of step S5102 can refer to the optional implementation of step S2404 in FIG. 2D, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described here again.

[0435] In some embodiments, the SCP authorizes the network function service consumer to send the first discovery request to the NRF.

[0436] In step S5103, the first discovery request is sent.

[0437] The optional implementation of step S5102 can refer to the optional implementation of step S2106 in FIG. 2A, step S2206 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described here again.

[0438] In some embodiments, the SCP sends the first discovery request to the NRF, or the SCP sends the first discovery request to the NRF in the visited place.

[0439] The communication method related to the embodiments of the present disclosure can include at least one of steps S5101-S5103. For example, step S5101 can be implemented as an independent embodiment, and step S5103 can be implemented as an independent embodiment, but is not limited thereto.

[0440] In some embodiments, step S5102 is optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0441] FIG. 5B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5B, the embodiments of the present disclosure relate to a communication method, and the above method includes:

[0442] In step S5201, a first request is sent.

[0443] The optional implementation of step S5201 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C and 2D. Details are not described herein again.

[0444] In some embodiments, the SCP sends the first request to a network function service provider.

[0445] Step S5202, sending the fifth information.

[0446] The optional implementation of step S5202 can refer to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C and 2D. Details are not described herein again.

[0447] In some embodiments, the SCP sends the fifth information to a network function service provider.

[0448] Step S5203, obtaining the second message.

[0449] The optional implementation of step S5203 can refer to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C and 2D. Details are not described herein again.

[0450] In some embodiments, the SCP receives the second message sent by a network function service provider.

[0451] Step S5204, sending the first message.

[0452] The optional implementation of step S5204 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C and 2D. Details are not described herein again.

[0453] In some embodiments, the SCP sends the first message to a network function service consumer.

[0454] Step S5205, obtaining the second request.

[0455] The optional implementation of step S5205 can refer to the optional implementation of step S2112 in FIG. 2A and other associated parts in the embodiments related to FIGS. 2A, 2B, 2C and 2D. Details are not described herein again.

[0456] In some embodiments, the SCP obtains the second request sent by a network function service consumer.

[0457] Step S5206, sending the second request.

[0458] The optional implementation of step S5206 can refer to the optional implementation of step S2113 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described herein again.

[0459] In some embodiments, the SCP sends the second request to a network function service provider.

[0460] Step S5207, obtaining the third message.

[0461] The optional implementation of step S5207 can refer to the optional implementation of step S2114 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described herein again.

[0462] In some embodiments, the SCP receives the third message sent by the network function service provider.

[0463] Step S5208, sending the third message.

[0464] The optional implementation of step S5208 can refer to the optional implementation of step S2115 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described herein again.

[0465] In some embodiments, the SCP sends the third message to a network function service consumer.

[0466] Step S5209, obtaining the SUPI or GPSI.

[0467] The optional implementation of step S5209 can refer to the optional implementation of step S2116 in FIG. 2A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which are not described herein again.

[0468] In some embodiments, the SCP receives the SUPI or GPSI sent by the network function service consumer.

[0469] The communication method related to the embodiments of the present disclosure can include at least one of steps S5201-S5209. For example, step S5201 can be implemented as an independent embodiment, but is not limited thereto.

[0470] In some embodiments, steps S5202, S5203, S5204, S5205, S5206, S5207, S5208, and S5209 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0471] FIG. 6 is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 6, the embodiment of the present disclosure relates to a communication method, and the method comprises the following steps.

[0472] In step S6101, the network function service consumer sends a first discovery request to the SCP.

[0473] The optional implementation of step S6101 can refer to step S2106 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which will not be repeated here.

[0474] In step S6102, the SCP sends the first discovery request to the NRF.

[0475] The optional implementation of step S6102 can refer to step S2106 in FIG. 2A, step S2211 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A, FIG. 2B, FIG. 2C, and FIG. 2D, which will not be repeated here.

[0476] In some embodiments, the above method can include the method of the above embodiments of the communication system side, network device side, etc., which will not be repeated here.

[0477] The embodiment of the present disclosure provides a communication method, and the NRF authorizes the service request of the network function service consumer through the NPN information of the network function service consumer and the NPN related policy of the network function service provider, which can prevent the message of the wrong NF type sent by the customer side or the operator side NF from crossing the trust boundary, limit the exchange of services and information between the customer side and the operator side, and improve the security of communication.

[0478] In the embodiment of the present disclosure, the service request across domains is rejected by the NRF, which can avoid exposing the topology information (such as FQDN, IP address, etc.) of the NF service provider to the NF service consumer in the service discovery process, and improve the security of communication.

[0479] In the embodiment of the present disclosure, for service discovery in the same PLMN, the SCP initiated proxy service discovery can be used, so that the topology information can be hidden.

[0480] In the embodiment of the present disclosure, for service discovery between PLMNs, the SEPP can be used to hide the topology information.

[0481] FIG. 7A is an interaction diagram of a communication method according to an embodiment of the present disclosure.

[0482] In step S7101, the NF service consumer sends a registration request to the NRF.

[0483] In some embodiments, the NRF is deployed by the PLMN, and the address of the NRF can be configured to the NF service consumer side, assuming that the address of the NRF can only be configured to the network function that trusts the NRF.

[0484] In some embodiments, when the NF service consumer is first running, the NF service consumer can send a registration request to the NRF, for example, the NF service consumer can send an Nnrf_NFManagement_NFRegister Request message to the NRF.

[0485] In some embodiments, the NF profile of the NF service consumer can be included in the registration request.

[0486] In some embodiments, the NF profile can include NPN information served by the NF service consumer, wherein the NPN served by the NF service consumer can also be referred to as the NPN to which the NF service consumer belongs, and can also be referred to as the NPN associated with the NF service consumer.

[0487] In some embodiments, the NPN information can include at least one of the following:

[0488] CAG identifier of the NPN;

[0489] Location information (for example, geographical location or data center where the NF is located);

[0490] NPN identifier.

[0491] In some embodiments, the above-mentioned location information can be location information capable of identifying a specific NPN. For example, the NPN corresponding to the geographical location or data center where the NF is located can be determined according to the geographical location or data center where the NF is located.

[0492] In some embodiments, the NF profile of the NF service consumer can be configured by an operation maintenance management (OAM) system.

[0493] In step S7102, the NRF stores the NF profile of the NF service consumer.

[0494] In some embodiments, the NRF stores the NF profile of the NF service consumer and marks that the NF service consumer is available.

[0495] In some embodiments, the NF profile sent by the NF service consumer to the NRF needs to be integrity protected by the NF service consumer and verified by the NRF.

[0496] At step S7103, the NRF sends a registration response to the NF service consumer.

[0497] In some embodiments, the NRF can confirm acceptance of the NF registration by the Nnrf_NFManagement_NFRegister response.

[0498] In some embodiments, the NRF can send the Nnrf_NFManagement_NFRegister_Response to the NF service consumer.

[0499] The communication method related to the embodiments of the present disclosure can include at least one of steps S7101-S7103. In the embodiments of the present disclosure, any one of steps S7101-S7103 can be implemented independently. For example, step S7101 can be implemented as an independent embodiment, step S7102 can be implemented as an independent embodiment, and step S7103 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0500] In some embodiments, steps S7101-S7103 can be exchanged in order or executed simultaneously. Without contradiction, each step can be combined arbitrarily, and the order of each step can be exchanged arbitrarily, and the present disclosure does not limit this.

[0501] In some embodiments, the NF service provider can register with the NRF. For example, the NF service provider can send a registration request to the NRF, which can include the configuration file of the NF service provider.

[0502] In some embodiments, in the NF service registration process, the configuration data of the NF configuration file of the NF service provider can include an "additional scope". The "additional scope" information indicates resources and operations (such as service operations) allowed to be performed by the NF service consumer on these resources. These resources can be the NF type of each NF service consumer, or the NF instance ID of each NF service consumer.

[0503] In some embodiments, the terminal list associated with the NPN served by the NF service consumer can also be configured in the NF configuration file.

[0504] The NF configuration file can also indicate that a specific NF type (such as AMF) in a specific NPN can / may not discover / access / use the services / resources (such as specific data) of a specific NF provider on the PLMN side.

[0505] The NF profile can also indicate that a specific NF type (e.g. AMF) in a specific PLMN can / may not discover / access / use the services / resources (e.g. specific data) of a specific NF provider at the end of a NPN.

[0506] When using the NF profile for NF service consumer authorization, the rules as shown in Table 2 can be used.

[0507] In some embodiments, the NFs and the NRF can authenticate each other.

[0508] In some embodiments, the NFs including NF service consumers / providers and the NRF shall support TLS with mutual authentication and use the identity in the end entity certificate for identity verification and policy check. The network function shall support both server-side and client-side certificates. The certificate shall include information about NPNs provided by the NF. Thus, after authentication, the NRF can obtain the NPN information served by the NF.

[0509] In some embodiments, the NRF authenticates the NF service consumer based on a Client Credentials Assertion (CCA). The CCA includes the NPN information served by the NF service consumer. Thus, after authentication, the NRF can obtain the NPN information served by the NF.

[0510] FIG. 7B is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 7B, the embodiment of the present disclosure relates to a communication method, and the method comprises:

[0511] In step S7201, the NF service consumer sends a discovery request to the NRF.

[0512] In some embodiments, the discovery request can be an NF discovery request.

[0513] In some embodiments, the NRF passes the authentication of the NF service consumer and obtains the NPN information provided by the NF service consumer.

[0514] In some embodiments, the NF service consumer wants to discover the available services in the network according to the service name and target NF type. The NF service consumer invokes a discovery request from the NRF properly configured in the same PLMN, the discovery request can be Nnrf_NFDiscovery_Request, the discovery request can include at least one of the following: expected NF service name, NF type of expected NF instance, NF type of NF consumer. In addition, in order to discover the services provided by NPN, Nnrf_NFDiscovery_Request should include NPN indication (for example, CAG identification related to NPN, location information (for example, geographic location, data center) that can identify a specific NPN, NPN identification).

[0515] Step S7202, the NRF authorizes the discovery request.

[0516] In some embodiments, the NRF authorizes Nnrf_NFDiscovery_Request. The NRF decides whether to allow the NF service consumer to discover the expected NF instance according to the NPN indication (optional), the profile of the expected NF / NF service, and the type of the NF service consumer.

[0517] In some embodiments, in the scenario of PLMN carrying NPN, if the NRF receives the NPN indication, the discovery request can be authorized according to the authorization rules as shown in Table 1.

[0518] Step S7203, the NRF sends a discovery response to the NF service consumer.

[0519] In some embodiments, if the authorization is passed, the NRF will determine a set of NF instances that meet the Nnrf_NFDiscovery_Request and the internal policy of the NRF, and send the NF profile of these instances.

[0520] The communication method related to the embodiments of the present disclosure can include at least one of steps S7201-S7203.

[0521] In some embodiments, steps S7201-S7203 can be exchanged in order or executed simultaneously. Without contradiction, each step can be arbitrarily combined, and the order of each step can be arbitrarily exchanged, and the present disclosure does not limit this.

[0522] FIG. 7C is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 7C, the embodiments of the present disclosure relate to a communication method, and the above method includes:

[0523] Step S7301, the NF service consumer sends a request to the SCP.

[0524] In some embodiments, when the NF service consumer and the NF service provider are in the same PLMN, the SCP can delegate the discovery of the NF service.

[0525] In some embodiments, the NF service consumer sends a service request to the SCP. The request can include discovery and selection parameters required to discover and select the NF service provider instance.

[0526] In some embodiments, if the NF service consumer is in a PLMN and the desired service / NF service provider is in an NPN, the NF service consumer shall send a service request to the SCP in order to perform delegated service discovery. The service request shall include an NPN indication.

[0527] Step S7302, the SCP performs the discovery procedure.

[0528] In some embodiments, the SCP can perform the discovery request by interacting with the NRF using the Nnrf_NFDiscovery service or can use information collected earlier during interactions with the NRF, e.g. through the Nnrf_NFDiscovery service or the Nnrf_NFManagement_NFStatusNotify service operation. The SCP authorizes the request with the NRF. The SCP can select the target NF service provider.

[0529] Step S7303, the SCP sends the request to the NF service provider.

[0530] In some embodiments, if the NF service consumer is authorized to communicate with the NF service provider, the SCP shall forward the request to the selected NF service provider according to the configuration of the network slice, e.g. the desired NF instance is only reachable through NFs within the same network slice.

[0531] In some embodiments, the SCP can request the service from the NF service provider on behalf of the NF service consumer.

[0532] Step S7304, the NF service provider sends a response to the SCP.

[0533] In some embodiments, the NF service provider sends a response to the SCP. If the request in step S7303 created a resource in the NF service producer, the NF service producer returns resource information identifying the created resource.

[0534] Step S7305, the SCP sends a response to the NF service consumer.

[0535] In some embodiments, the SCP routes the response to the NF service consumer.

[0536] In some embodiments, if the NF service consumer receives one resource address, it uses it for subsequent requests about that resource. Otherwise, the process ends here.

[0537] In some embodiments, if the response in step S7304 contains the address (e.g. IP address, FQDN) of the NF service provider, the SCP can perform topology hiding for the address of the NF service provider.

[0538] In some embodiments, the topology can thus generate an address identifier (e.g. character “A”) for the address of the NF service provider. The SCP replaces the resource address with the newly generated address identifier. The SCP forwards the modified resource address to the NF consumer.

[0539] Step S7306, the NF service consumer sends a request to the SCP.

[0540] In some embodiments, the NF service consumer can send a service request to the SCP.

[0541] In some embodiments, the NF service consumer sends the received resource address to the SCP.

[0542] Step S7307, the SCP performs discovery and selection.

[0543] In some embodiments, the SCP resolves the address of the NF service provider and selects a target NF service provider instance. Specifically, the SCP identifies the address of the NF service provider using the address identifier. Then, the SCP routes the request to the selected NF service provider instance.

[0544] Step S7308, the SCP sends a request to the NF service provider.

[0545] In some embodiments, the SCP sends a service request to the NF service provider.

[0546] In some embodiments, if the response in step S7306 contains the address (e.g. IP address, FQDN) of the NF service consumer, the SCP can perform topology hiding for the address of the NF service consumer.

[0547] Step S7309, the NF service provider sends a response to the SCP.

[0548] In some embodiments, the NF service provider sends a response to the SCP. The NF service provider can respond using updated resource information that is different from the previously received response.

[0549] Step S7310, the SCP sends a response to the NF service consumer.

[0550] In some embodiments, the SCP sends a response to the NF service consumer after the same NF service producer instance address replacement process defined in step S7305. If the resource information is updated, the NF service consumer uses the received resource information for subsequent operations (requests) on the resource.

[0551] The communication method related to the embodiments of the present disclosure can include at least one of steps S7301-S7310.

[0552] In some embodiments, steps S7301-S7310 can be exchanged in order or performed simultaneously. Without contradiction, each step can be arbitrarily combined and the order of each step can be arbitrarily exchanged, and the present disclosure does not limit this.

[0553] FIG. 7D is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 7D, the embodiments of the present disclosure relate to a communication method, and the method includes:

[0554] Step S7401, the NF service consumer sends a discovery request to the NRF in the serving PLMN.

[0555] In some embodiments, the serving PLMN can be a visited PLMN.

[0556] In some embodiments, if the NF service consumer wants to discover NF / NF service in the NPN of the home PLMN, the NRF of the visited PLMN needs to request the "NF discovery" service from the NRF of the home PLMN.

[0557] It can be understood that the NRF in the home PLMN communicates with the NRF and the NF consumer in the serving PLMN through the SEPP in the respective PLMN. For the sake of clarity, the SEPP is not shown in the figure.

[0558] In some embodiments, the NF service consumer in the serving PLMN calls Nnrf_NFDiscovery_Request (expected service name, NF type of expected NF, home PLMN ID, serving PLMN ID, NF type of NF service consumer) to the appropriately configured NRF in the serving PLMN. If the expected service / NF service provider is in the NPN of the home PLMN, the NF service consumer should send a service request to the NRF for service discovery, and the service request should include the NPN indication.

[0559] Step S7402: The NRF in the serving PLMN and the NRF in the home PLMN transmit a discovery request / response.

[0560] In some embodiments, the NRF of the serving PLMN identifies the NRF in the home PLMN (hNRF) based on the home PLMN ID and requests NF discovery service from the NRF in the home PLMN to obtain the expected NF profile of the NF instance deployed in the home PLMN. Since the NRF in the serving PLMN triggers NF discovery on behalf of the NF service consumer, the NRF in the serving PLMN cannot replace the information of the service consumer NF, i.e., the NF consumer ID, i.e., the NPN indication in the discovery request message it sends to the hNRF.

[0561] In some embodiments, the hNRF may further query the appropriate Home NRF in the Home PLMN based on the input information received from the NRF in the Serving PLMN. The FQDN of the Home NRF or the endpoint address of the NF Discovery Service of the Home NRF in the Primary PLMN may be configured in the hNRF or may need to be discovered based on the input information.

[0562] In some embodiments, if an NPN indication is received, the NRF in the home PLMN performs service discovery by considering the NPN indication. If the NF profile of the target NF does not allow it to be discovered by NFs in the NPN, the NRF in the home network should reject the discovery request and / or send a failure / error message. Otherwise, the NRF in the home PLMN will continue to perform discovery based on the NPN indication.

[0563] Step S7403: The NRF in the serving PLMN sends a response to the NF service consumer.

[0564] In some embodiments, if allowed, the NRF in the serving PLMN will determine a set of NF instances that comply with the Nnrf_NFDiscovery_Request and NRF internal policies and send the NF profiles of these instances.

[0565] In some embodiments, if the message sent by PLMN-1 to PLMN-2 contains an address related to PLMN-1 (such as FQDN, IP address), the SEPP in PLMN-1 is used as the topology for the address related to PLMN-1.

[0566] In some embodiments, the address transformation includes generating an address identifier (e.g., character 'A') with a PLMN-1 related address (e.g., FQDN, IP address). The SEPP in PLMN-1 replaces the resource address with the newly generated address identifier. The modified message is then forwarded by the SEPP of PLMN-1 to PLMN-2. Here, PLMN-1 can be a serving PLMN or a home PLMN; and PLMN-2 can be a serving PLMN or a home PLMN.

[0567] The communication method according to the embodiments of the present disclosure can include at least one of steps S7401-S7403.

[0568] In some embodiments, steps S7401-S7403 can be performed in any order or simultaneously. Without contradiction, each step can be combined arbitrarily, and the order of each step can be exchanged arbitrarily, which is not limited by the present disclosure.

[0569] In the embodiments of the present disclosure, part or all of the steps and their optional implementation manners can be combined with part or all of the steps in other embodiments, or combined with the optional implementation manners of other embodiments.

[0570] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device including units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another device is proposed, including units or modules for implementing each step performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0571] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize the functions of any of the above methods or the units or modules of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.

[0572] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), or the like.

[0573] FIG. 8A is a structural schematic diagram of a network function service consumer according to an embodiment of the present disclosure. As shown in FIG. 8A, the network function service consumer 8100 can include a transceiver module 8101. In some embodiments, the transceiver module 8101 is configured to send the first discovery request. Optionally, the transceiver module is configured to perform at least one of the steps (for example, step S2106, but not limited thereto) in the processing performed by the network function service consumer in any of the above methods.

[0574] FIG. 8B is a structural schematic diagram of an NRF according to an embodiment of the present disclosure. As shown in FIG. 8B, the NRF 8200 can include a transceiver module 8201. In some embodiments, the transceiver module 8201 is configured to receive the first discovery request. Optionally, the transceiver module is configured to perform at least one of the steps (for example, step S2106, but not limited thereto) in the processing performed by the NRF in any of the above methods, which will not be described herein again.

[0575] FIG. 8C is a structural schematic diagram of the SCP according to an embodiment of the present disclosure. As shown in FIG. 8C, the SCP 8300 can include a transceiver module 8301. In some embodiments, the transceiver module 8301 is configured to receive the first discovery request sent by the network function service consumer, and send the first discovery request to the network storage function (NRF). Optionally, the transceiver module is configured to perform at least one of the steps (for example, step S2106, but not limited thereto) in the processing performed by the SCP in any of the above methods, and details are not described herein.

[0576] In some embodiments, the processing module can be one module, or can include a plurality of sub-modules. Optionally, the plurality of sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Optionally, the processing module can be mutually replaced by the processor.

[0577] FIG. 9A is a structural schematic diagram of a communication device 9100 according to an embodiment of the present disclosure. The communication device 9100 can be a network device (for example, an access network device, a core network device, etc.), a terminal (for example, a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 9100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0578] As shown in FIG. 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (for example, a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 9100 is configured to perform any of the above methods. Optionally, the one or more processors 9101 are configured to invoke instructions to cause the communication device 9100 to perform any of the above methods.

[0579] In some embodiments, the communication device 9100 further includes one or more transceivers 9102. When the communication device 9100 includes one or more transceivers 9102, the transceiver 9102 performs at least one of the communication steps (e.g., steps S2101, S2102, S2103, S2105, S2106, S2107, S2108, S2109, S2110, S2111, S2112, S2113, S2114, S2115, S2116, but not limited to) of transmitting and / or receiving in the above-described methods, and the processor 9101 performs at least one of the other steps (e.g., steps S2104, S2107, but not limited to). In alternative embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Alternatively, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced with each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.

[0580] In some embodiments, the communication device 9100 further includes one or more memories 9103 for storing data. Alternatively, all or part of the memory 9103 can also be outside the communication device 9100. In alternative embodiments, the communication device 9100 can include one or more interface circuits 9104. Alternatively, the interface circuit 9104 is connected with the memory 9103, and the interface circuit 9104 can be used to receive data from the memory 9103 or other devices, and can be used to send data to the memory 9103 or other devices. For example, the interface circuit 9104 can read the data stored in the memory 9103 and send the data to the processor 9101.

[0581] The communication device 9100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0582] FIG. 9B is a structural schematic diagram of the chip 9200 according to an embodiment of the present disclosure. For the case that the communication device 9100 can be a chip or a chip system, the structural schematic diagram of the chip 9200 shown in FIG. 9B can be referred to, but is not limited thereto.

[0583] The chip 9200 comprises one or more processors 9201. The chip 9200 is configured to execute any of the above methods.

[0584] In some embodiments, the chip 9200 further comprises one or more interface circuits 9202. Optionally, the terms of interface circuit, interface, transceiver pin, etc. can be replaced by each other. In some embodiments, the chip 9200 further comprises one or more memories 9203 for storing data. Optionally, all or part of the memory 9203 can be outside the chip 9200. Optionally, the interface circuit 9202 is connected with the memory 9203, the interface circuit 9202 can be configured to receive data from the memory 9203 or other devices, and the interface circuit 9202 can be configured to send data to the memory 9203 or other devices. For example, the interface circuit 9202 can read the data stored in the memory 9203 and send the data to the processor 9201.

[0585] In some embodiments, the interface circuit 9202 performs at least one of the communication steps (such as steps S2101, S2102, S2103, S2105, S2106, S2107, S2108, S2109, S2110, S2111, S2112, S2113, S2114, S2115, S2116, but not limited thereto) of transmitting and / or receiving in the above methods. The interface circuit 9202 performing the communication steps such as transmitting and / or receiving in the above methods means that the interface circuit 9202 performs data interaction between the processor 9201, the chip 9200, the memory 9203 or the transceiver device. In some embodiments, the processor 9201 performs at least one of the other steps (such as steps S2104, S2107, but not limited thereto).

[0586] The modules and / or devices described in each of the embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated as appropriate. Optionally, part or all of the steps can also be performed by a plurality of modules and / or devices in cooperation, which is not limited herein.

[0587] The present disclosure further provides a storage medium having stored instructions which, when executed on the communication device 9100, cause the communication device 9100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and can also be a storage medium readable by other apparatuses. Optionally, the storage medium can be a non-transitory storage medium, but is not limited thereto and can also be a transitory storage medium.

[0588] The present disclosure further provides a program product which, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0589] The present disclosure further provides a computer program which, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method, characterized in that: The method comprises: The network function service consumer sends a first discovery request to the network storage function NRF through the service communication proxy SCP.

2. The method according to claim 1, characterized in that The method further comprises: The network function service consumer sends a second discovery request to the NRF, and the NRF is configured to reject the second discovery request when the first policy is met; In response to the NRF rejecting the second discovery request, the network function service consumer receives indication information sent by the NRF, where the indication information is used to instruct the network function service consumer to send a first discovery request to the NRF through the SCP.

3. The method according to claim 1, characterized in that The method further comprises: In response to the network function service consumer determining that the first policy is satisfied based on the predefined rule, it is determined to send a first discovery request to the NRF through the SCP.

4. The method according to claim 2 or 3, characterized in that The first discovery request is used to discover a network function service provider, and the first strategy includes at least one of the following: The network function service consumer is located in the first network, and the network function service provider is located in the second network; The network function service consumer is located in the second network, and the network function service provider is located in the first network; The network function service consumer is located in a third network, and the network function service provider is located in a fourth network, wherein the network types of the third network and the fourth network are the same as the network type of the second network.

5. The method according to claim 1, wherein The SCP is configured to determine, based on a predefined rule, whether to authorize the network function service consumer to send the first discovery request to the NRF; In response to the SCP authorizing the network function service consumer to send the first discovery request to the NRF, the network function service consumer sends the first discovery request to the network storage function NRF through the SCP.

6. The method according to claim 5, characterized in that The predefined rules include at least one of the following: Whether the network function service consumer in the first network is allowed to request content from the network function service provider in the second network; Whether a network function service consumer of the first network function type located on the first network is allowed to request content from a network function service provider located on the second network; The content includes at least one of services, resources, and information.

7. The method according to claim 1, characterized in that The method further comprises: In response to the NRF authorizing the first discovery request based on the first information of the network function service provider, the network function service consumer communicates with the network function service provider through the SCP.

8. The method according to claim 7, characterized in that The NRF authorizes the first discovery request based on the first information of the network function service provider, including at least one of the following: The NRF authenticates the network function service consumer and obtains information about the network associated with the network function service consumer; The NRF determines, based on the first information of the network function service provider, that the network function service provider allows a predetermined type of network function service consumer to request content of the network function service provider, and / or that the network function service provider allows a network associated with the network function service consumer to request content of the network function service provider; And / or, the network function service provider allows the network function in the network associated with the network function service consumer to request content from the network function service provider, where the content includes at least one of services, resources, and information.

9. The method according to claim 7 or 8, characterized in that The first information of the network function service provider is used to indicate at least one of the following: Whether a network function service consumer of the first network function type located on the first network is allowed to request content from a network function service provider located on the second network; whether a network function service consumer of the first network function type located on the second network is allowed to request content from a network function service provider located on the first network; The content includes at least one of services, resources, and information.

10. The method according to claim 1, characterized in that The network function service consumer is located in an NPN supported by a visited network, and the first discovery request is used to discover a network function service provider located in a home network; The network function service consumer sends a first discovery request to the network storage function NRF through the service communication proxy SCP, including: The network function service consumer sends a first discovery request to the visited NRF through the SCP, and the visited NRF is configured to send the first discovery request to the home NRF through a first security edge protection proxy SEPP and a second SEPP.

11. The method according to claim 10, characterized in that The first discovery request includes fourth information of the network service consumer. The first SEPP is configured to process the fourth information to obtain fifth information and send the fifth information to the second SEPP. The second SEPP is configured to process the fifth information to obtain sixth information.

12. The method according to any one of claims 1 to 10, characterized in that The method further comprises: The network function service consumer receives a first message sent by the SCP, where the first message includes second information of the network function service provider, and the second information is information obtained by the SCP processing third information of the network function service provider.

13. The method according to any one of claims 1 to 10, characterized in that The first discovery request includes fourth information of the network function service consumer, and the SCP is used to process the fourth information of the network function service consumer to obtain fifth information.

14. The method according to claim 1, wherein The method further comprises: The network function service consumer sends a user permanent identifier SUPI to the SCP, and the SCP is used to send the SUPI to a user data manager UDM to obtain a general public user identifier GPSI.

15. The method according to claim 1, wherein The method further comprises: The network function service consumer sends a user permanent identifier SUPI to the user data manager UDM to obtain a general public user identifier GPSI; The network function service consumer sends the GPSI to the SCP.

16. A communication method, characterized in that: The method comprises: The network storage function NRF receives a first discovery request sent by the network function service consumer through the SCP.

17. The method according to claim 16, characterized in that The method further comprises: The NRF receives a second discovery request sent by the network function service consumer; The NRF rejects the second discovery request when the first policy is satisfied.

18. The method according to claim 17, characterized in that The method further comprises: In response to the NRF rejecting the second discovery request, the NRF sends indication information to the network function service consumer, where the indication information is used to instruct the network function service consumer to send a first discovery request to the NRF through the SCP.

19. The method according to claim 17, wherein The first discovery request is used to discover a network function service provider, and the first strategy includes at least one of the following: The network function service consumer is located in the first network, and the network function service provider is located in the second network; The network function service consumer is located in the second network, and the network function service provider is located in the first network; The network function service consumer is located in a third network, and the network function service provider is located in a fourth network, wherein the network types of the third network and the fourth network are the same as the network type of the second network.

20. The method according to claim 16, wherein The method further comprises: The NRF authorizes the first discovery request based on first information of the network function service provider.

21. The method according to claim 20, characterized in that The NRF authorizes the first discovery request based on the first information of the network function service provider, including at least one of the following: The NRF authenticates the network function service consumer and obtains information about the network associated with the network function service consumer; The NRF determines, based on the first information of the network function service provider, that the network function service provider allows a predetermined type of network function service consumer to request content of the network function service provider, and / or that the network function service provider allows a network associated with the network function service consumer to request content of the network function service provider; And / or, the network function service provider allows the network function in the network associated with the network function service consumer to request content from the network function service provider, where the content includes at least one of services, resources, and information.

22. The method according to claim 21, characterized in that The first information of the network function service provider is used to indicate at least one of the following: Whether a network function service consumer of the first network function type located on the first network is allowed to request content from a network function service provider located on the second network; whether a network function service consumer of the first network function type located on the second network is allowed to request content from a network function service provider located on the first network; The content includes at least one of services, resources, and information.

23. The method according to claim 16, wherein The network function service consumer is located in an NPN supported by a visited network, and the first discovery request is used to discover a network function service provider located in a home network; The NRF receives a first discovery request sent by a network function service consumer through an SCP, including: The visited NRF receives the first discovery request sent by the network function service consumer through the SCP; The visited NRF sends a first discovery request to the home NRF through the first SEPP and the second SEPP.

24. The method according to claim 23, wherein The first discovery request includes fourth information of the network service consumer. The first SEPP is configured to process the fourth information to obtain fifth information and send the fifth information to the second SEPP. The second SEPP is configured to process the fifth information to obtain sixth information.

25. A communication method, characterized in that: The method comprises: The service communication proxy SCP receives a first discovery request sent by a network function service consumer, and sends the first discovery request to the NRF.

26. The method according to claim 25, characterized in that The SCP determines, based on a predefined rule, whether to authorize the network function service consumer to send the first discovery request to the NRF, and the method further includes: Determine that the SCP authorizes the network function service consumer to send the first discovery request to the NRF.

27. The method according to claim 26, characterized in that The predefined rules include at least one of the following: Whether the network function service consumer in the first network is allowed to request content from the network function service provider in the second network; Whether a network function service consumer of the first network function type located on the first network is allowed to request content from a network function service provider located on the second network; The content includes at least one of services, resources, and information.

28. The method according to claim 25, characterized in that The method further comprises: The SCP sends a first message to the network function service consumer, where the first message includes second information of the network function service provider, and the second information is information obtained by processing the third information of the network function service provider.

29. The method according to claim 25, characterized in that The first discovery request includes fourth information of the network function service consumer, and the method further includes: The SCP processes the fourth information of the network function service consumer to obtain fifth information.

30. The method according to claim 29, wherein The method further comprises: The SCP sends the fifth information to the network function service provider.

31. A network function service consumer, characterized in that: include: The transceiver module is used to send a first discovery request to the network storage function NRF through the service communication agent SCP.

32. An NRF, characterized in that include: The transceiver module is used to receive a first discovery request sent by a network function service consumer through a service communication agent SCP.

33. An SCP, characterized in that: include: The transceiver module is used to receive a first discovery request sent by a network function service consumer and send the first discovery request to the network storage function NRF.

34. A network function service consumer, characterized in that: include: one or more processors; The network function service consumer is configured to execute the method according to any one of claims 1 to 15.

35. An NRF, characterized in that include: one or more processors; The NRF is used to perform the method according to any one of claims 16 to 24.

36. An SCP, characterized in that: include: one or more processors; The SCP is configured to perform the method according to any one of claims 25 to 30.

37. A communication system, characterized in that: The invention comprises a network function service consumer, an NRF and an SCP, wherein the network function service consumer is configured to implement the method according to any one of claims 1 to 15, the NRF is configured to implement the method according to any one of claims 16 to 24, and the SCP is configured to implement the method according to any one of claims 25 to 30.

38. A storage medium storing instructions, characterized in that: When the instructions are executed on a communication device, the communication device executes the method according to any one of claims 1 to 15, the NRF is configured to implement the method according to any one of claims 16 to 24, and the SCP is configured to implement the method according to any one of claims 25 to 30.

39. A program product, characterized in that include: A computer program, which, when executed by a communication device, causes the communication device to perform the method according to any one of claims 1 to 15, the NRF being configured to implement the method according to any one of claims 16 to 24, and the SCP being configured to implement the method according to any one of claims 25 to 30.