N32-F connection and / or N32-F context termination or re-establishment by roaming intermediary of communication network

The apparatus and method address the inefficiencies in managing N32-f contexts and connections by determining and directing the termination or re-establishment based on network criteria, enhancing network efficiency and security in inter-PLMN communication.

GB2640212APending Publication Date: 2025-10-15NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
GB2024004864
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-05
Publication Date
2025-10-15

AI Technical Summary

Technical Problem

Existing systems lack efficient mechanisms for managing the termination and re-establishment of N32-f contexts and connections involving Security Edge Protection Proxies (SEPPs) in inter-PLMN communication networks, which can lead to inefficiencies and security vulnerabilities.

Method used

An apparatus and method are provided to determine whether an N32-f context and/or connection should be terminated or re-established, generating instructions to direct the SEPP entity to perform these actions, and sending messages to facilitate the process, based on various criteria such as network maintenance, resource availability, contractual changes, and connectivity issues.

Benefits of technology

This solution enhances network management by optimizing resource utilization and ensuring secure communication by terminating or re-establishing N32-f contexts and connections as needed, thereby improving network efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A roaming intermediary entity, comprising: means for: determining whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or reestablished; based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generating a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection; and / or based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generating a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection; generating a message comprising at least one of the first instruction and / or the second instruction; and sending the message to the SEPP entity. The roaming intermediary entity may comprise an entity that provides roaming related services and wherein the entity that provides roaming related services comprises a Roaming Hub or an IP exchange service (IPX) provider entity deployed between two PLMNs or deployed between a PLMN and a Standalone Private Network (SNPN) or deployed between two SNPNs.
Need to check novelty before this filing date? Find Prior Art

Description

[0002] A Security Edge Protection Proxy (SEPP) entity is an entity that is deployed at a perimeter of a Public Land Mobile Network (PLMN) and is configured for protecting control plane messages that are signaled (e.g., sent) to another SEPP deployed at a perimeter of another PLMN via an inter-PLMN Service Based Interface (e.g., a N32-interface). In other words, the SEPP encrypts the control plane messages to enforce inter-PLMN security on an N32 interface and thus securing communication between the PLMNs. Application layer security may be used for protecting inter-PLMN signaling (e.g. for protecting control plane messages that are sent between two PLMNs), also called PRotocol for N32 INterconnect Security (PRINS). In other situations, end-to-end (e2e) Transport Layer Security (TLS) protocol may be used for protecting inter-PLMN signaling.

[0003] An N32-c interface is a control plane interface between SEPPS for performing an initial handshake and negotiating security keys to use for protecting inter-PLMN signaling (e.g., for protecting control plane message sent via a N32-f connection).

[0004] An N32-f interface is a forwarding interface for forwarding communication between a network function (NF) service consumer and a NF service producer after applying application level security protection. For example, an N32-f connection may be used for sending JavaScript Object Notation (JSON) web encryption (JWE) and web signature (JWS) protocol messages between two SEPPs (when using PRINS security protocol) or e2e TLS protected messages (when using TLS security protocol). BRIEF SUMMARY

[0005] In one or more aspects, an apparatus is provided including at least one processor and at least one memory storing instructions of a roaming intermediary entity, wherein execution of the instructions of the roaming intermediary entity cause the apparatus to determine whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or re-established. The apparatus is further caused to, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generate a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the apparatus is further caused to, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be reestablished, generate a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection. The apparatus is further caused to generate a message including at least one of the first instruction and / or the second instruction. The apparatus is further caused to send the message to the SEPP entity.

[0006] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0007] In one or more aspects, the determining whether at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message includes an N32-f message forwarding error response message.

[0008] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0009] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one N32-f context and / or the N32-f connection.

[0010] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0011] In one or more aspects, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, the message that is generated further includes an indication of an alternative roaming intermediary for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0012] In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of network maintenance at the network including the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient resources at the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of a business determination. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of a change of contractual agreements between the roaming intermediary entity and another roaming intermediary entity, the SEPP entity, or another SEPP entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicating that the determination that a N32-f connection is inactive. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative a switch to the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient connectivity with the another roaming intermediary entity, the SEPP entity, or the another SEPP entity.

[0013] In one or more aspects, the roaming intermediary entity includes an entity that provides roaming related services and wherein the entity that provides roaming related services includes a Roaming Hub or an internet protocol (IP) exchange service (IPX) provider entity deployed between two Public Land Mobile Networks (PLMNs), or deployed between a PLMN and a Standalone Private Network (SNPN), or deployed between two SNPNs.

[0014] In one or more aspects, an apparatus is provided including at least one processor and at least one memory storing instructions of a security edge protection proxy (SEPP) entity, wherein execution of the instructions of the SEPP entity cause the apparatus to receive, from a roaming intermediary entity, a message including at least one of a first instruction or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to reestablish the at least one of the N32-f context and / or the N32-f connection. The apparatus is further caused to, based on the message including the first instruction, terminate the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the apparatus is further caused to, based on the message including the second instruction, re-establish the at least one of the N32-f context and / or the N32-f connection.

[0015] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0016] In one or more aspects, the message includes a N32-f message forwarding error response message, and wherein the message is received subsequent to the SEPP entity providing, to the roaming intermediary entity, an N32-f message forwarding request.

[0017] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0018] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0019] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0020] In one or more aspects, the message further includes an indication of an alternative roaming intermediary entity for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0021] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to terminate the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN).

[0022] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to re-establish the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN), and then initiates establishment of a new N32-f context towards the peer SEPP entity of the peer Public Land Mobile Network (PLMN) or the peer Standalone Private Network (SNPN).

[0023] In one or more aspects, the SEPP entity is deployed by one PLMN or one SNPN to support and protect the communication with the peer SEPP entity deployed by the peer PLMN or the peer SNPN, and wherein the communication between the SEPP entity and the peer SEPP entity takes place via one or more roaming intermediaries including the roaming intermediary entity.

[0024] In one or more aspects, the N32-f connection includes an HTTP connection established between the SEPP entity and the roaming intermediary entity, wherein the N32-f connection enables exchange of messages between the PLMN or the SNPN and the peer PLMN or the peer SNPN.

[0025] In one or more aspects, the N32-f context includes a context established at the SEPP entity and the peer SEPP entity, wherein the N32-f context stores security and protection policies agreed between the SEPP entity and the peer SEPP entity for protecting communication over the N32-f connection.

[0026] In one or more aspects, a computer-implemented method is provided that is performed by a roaming intermediary entity and includes determining whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or re-established. The method further includes, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generating a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the method further includes, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generating a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection. The method further includes generating a message including at least one of the first instruction and / or the second instruction. The method further includes sending the message to the SEPP entity.

[0027] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0028] In one or more aspects, the determining whether at least one of the N32-f context or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message includes an N32-f message forwarding error response message.

[0029] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0030] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one N32-f context and / or the N32-f connection.

[0031] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0032] In one or more aspects, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, the message that is generated further includes an indication of an alternative roaming intermediary for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0033] In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of network maintenance at the network including the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient resources at the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of a business determination. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of a change of contractual agreements between the roaming intermediary entity and another roaming intermediary entity, the SEPP entity, or another SEPP entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicating that the determination that a N32-f connection is inactive. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative a switch to the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient connectivity with the another roaming intermediary entity, the SEPP entity, or the another SEPP entity.

[0034] In one or more aspects, the roaming intermediary entity includes an entity that provides roaming related services and wherein the entity that provides roaming related services includes a Roaming Hub or an internet protocol (IP) exchange service (IPX) provider entity deployed between two Public Land Mobile Networks (PLMNs), or deployed between a PLMN and a Standalone Private Network (SNPN), or deployed between two SNPNs.

[0035] In one or more aspects, a computer-implemented method is provided that is performed by a security edge protection proxy (SEPP) entity and includes receiving, from a roaming intermediary entity, a message including at least one of a first instruction or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to reestablish the at least one of the N32-f context and / or the N32-f connection. The method further includes, based on the message including the first instruction, terminating the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the method further includes, based on the message including the second instruction, re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0036] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0037] In one or more aspects, the message includes a N32-f message forwarding error response message, and wherein the message is received subsequent to the SEPP entity providing, to the roaming intermediary entity, an N32-f message forwarding request.

[0038] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0039] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0040] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0041] In one or more aspects, the message further includes an indication of an alternative roaming intermediary entity for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0042] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to terminate the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN).

[0043] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to re-establish the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN), and then initiates establishment of a new N32-f context towards the peer SEPP entity of the peer Public Land Mobile Network (PLMN) or the peer Standalone Private Network (SNPN).

[0044] In one or more aspects, the SEPP entity is deployed by one PLMN or one SNPN to support and protect the communication with the peer SEPP entity deployed by the peer PLMN or the peer SNPN, and wherein the communication between the SEPP entity and the peer SEPP entity takes place via one or more roaming intermediaries including the roaming intermediary entity.

[0045] In one or more aspects, the N32-f connection includes an HTTP connection established between the SEPP entity and the roaming intermediary entity, wherein the N32-f connection enables exchange of messages between the PLMN or the SNPN and the peer PLMN or the peer SNPN.

[0046] In one or more aspects, the N32-f context includes a context established at the SEPP entity and the peer SEPP entity, wherein the N32-f context stores security and protection policies agreed between the SEPP entity and the peer SEPP entity for protecting communication over the N32-f connection.

[0047] In one or more aspects, a non-transitory computer readable storage medium is provided including computer instructions that, when executed by a roaming intermediary, cause the roaming intermediary to determine whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or re-established. The roaming intermediary entity is further caused to, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generate a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the roaming intermediary entity is further caused to, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generate a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection. The roaming intermediary entity is further caused to generate a message including at least one of the first instruction and / or the second instruction. The roaming intermediary entity is further caused to send the message to the SEPP entity.

[0048] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0049] In one or more aspects, the determining whether at least one of the N32-f context or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message includes an N32-f message forwarding error response message.

[0050] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0051] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one N32-f context and / or the N32-f connection.

[0052] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0053] In one or more aspects, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, the message that is generated further includes an indication of an alternative roaming intermediary for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0054] In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of network maintenance at the network including the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient resources at the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of a business determination. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of a change of contractual agreements between the roaming intermediary entity and another roaming intermediary entity, the SEPP entity, or another SEPP entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicating that the determination that a N32-f connection is inactive. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative a switch to the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient connectivity with the another roaming intermediary entity, the SEPP entity, or the another SEPP entity.

[0055] In one or more aspects, the roaming intermediary entity includes an entity that provides roaming related services and wherein the entity that provides roaming related services includes a Roaming Hub or an internet protocol (IP) exchange service (IPX) provider entity deployed between two Public Land Mobile Networks (PLMNs), or deployed between a PLMN and a Standalone Private Network (SNPN), or deployed between two SNPNs.

[0056] In one or more aspects, a non-transitory computer readable storage medium is provided including computer instructions that, when executed by a security edge protection proxy (SEPP) entity, cause the SEPP entity to receive, from a roaming intermediary entity, a message including at least one of a first instruction or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection. The SEPP entity is further caused to, based on the message including the first instruction, terminate the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the SEPP entity is further caused to, based on the message including the second instruction, re-establish the at least one of the N32-f context and / or the N32-f connection.

[0057] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0058] In one or more aspects, the message includes a N32-f message forwarding error response message, and wherein the message is received subsequent to the SEPP entity providing, to the roaming intermediary entity, an N32-f message forwarding request.

[0059] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0060] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0061] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0062] In one or more aspects, the message further includes an indication of an alternative roaming intermediary entity for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0063] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to terminate the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN).

[0064] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to re-establish the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN), and then initiates establishment of a new N32-f context towards the peer SEPP entity of the peer Public Land Mobile Network (PLMN) or the peer Standalone Private Network (SNPN).

[0065] In one or more aspects, the SEPP entity is deployed by one PLMN or one SNPN to support and protect the communication with the peer SEPP entity deployed by the peer PLMN or the peer SNPN, and wherein the communication between the SEPP entity and the peer SEPP entity takes place via one or more roaming intermediaries including the roaming intermediary entity.

[0066] In one or more aspects, the N32-f connection includes an HTTP connection established between the SEPP entity and the roaming intermediary entity, wherein the N32-f connection enables exchange of messages between the PLMN or the SNPN and the peer PLMN or the peer SNPN.

[0067] In one or more aspects, the N32-f context includes a context established at the SEPP entity and the peer SEPP entity, wherein the N32-f context stores security and protection policies agreed between the SEPP entity and the peer SEPP entity for protecting communication over the N32-f connection.

[0068] In one or more aspects, a roaming intermediary entity is provided that includes means for determining whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or re-established. The roaming intermediary entity further includes means for, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generating a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the roaming intermediary entity further includes means for, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generating a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection. The roaming intermediary entity further includes means for generating a message including at least one of the first instruction and / or the second instruction. The roaming intermediary entity is further caused to send the message to the SEPP entity.

[0069] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0070] In one or more aspects, the determining whether at least one of the N32-f context or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message includes an N32-f message forwarding error response message.

[0071] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0072] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one N32-f context and / or the N32-f connection.

[0073] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0074] In one or more aspects, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, the message that is generated further includes an indication of an alternative roaming intermediary for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0075] In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of network maintenance at the network including the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient resources at the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of a business determination. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of a change of contractual agreements between the roaming intermediary entity and another roaming intermediary entity, the SEPP entity, or another SEPP entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicating that the determination that a N32-f connection is inactive. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative a switch to the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient connectivity with the another roaming intermediary entity, the SEPP entity, or the another SEPP entity.

[0076] In one or more aspects, the roaming intermediary entity includes an entity that provides roaming related services and wherein the entity that provides roaming related services includes a Roaming Hub or an internet protocol (IP) exchange service (IPX) provider entity deployed between two Public Land Mobile Networks (PLMNs), or deployed between a PLMN and a Standalone Private Network (SNPN), or deployed between two SNPNs.

[0077] In one or more aspects, a security edge protection proxy (SEPP) entity is provided that includes means for receiving, from a roaming intermediary entity, a message including at least one of a first instruction or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection. The SEPP entity further includes means for, based on the message including the first instruction, terminating the at least one of the N32-f context and / or the N32-f connection. Additionally or alternatively, the SEPP entity further includes means for, based on the message including the second instruction, re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0078] In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0079] In one or more aspects, the message includes a N32-f message forwarding error response message, and wherein the message is received subsequent to the SEPP entity providing, to the roaming intermediary entity, an N32-f message forwarding request.

[0080] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0081] In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0082] In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

[0083] In one or more aspects, the message further includes an indication of an alternative roaming intermediary entity for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0084] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to terminate the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN).

[0085] In one or more aspects, when the message comprises an instruction that directs the SEPP entity to re-establish the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN), and then initiates establishment of a new N32-f context towards the peer SEPP entity of the peer Public Land Mobile Network (PLMN) or the peer Standalone Private Network (SNPN).

[0086] In one or more aspects, the SEPP entity is deployed by one PLMN or one SNPN to support and protect the communication with the peer SEPP entity deployed by the peer PLMN or the peer SNPN, and wherein the communication between the SEPP entity and the peer SEPP entity takes place via one or more roaming intermediaries including the roaming intermediary entity.

[0087] In one or more aspects, the N32-f connection includes an HTTP connection established between the SEPP entity and the roaming intermediary entity, wherein the N32-f connection enables exchange of messages between the PLMN or the SNPN and the peer PLMN or the peer SNPN.

[0088] In one or more aspects, the N32-f context includes a context established at the SEPP entity and the peer SEPP entity, wherein the N32-f context stores security and protection policies agreed between the SEPP entity and the peer SEPP entity for protecting communication over the N32-f connection. BRIEF DESCRIPTION OF THE DRAWINGS

[0089] Having thus described certain example aspects of the present disclosure in general terms, reference will hereinafter be made to the accompanying drawings, which are not necessarily drawn to scale, and where:

[0090] FIG. 1A is simplified block diagram of two communication networks that are interconnected by two security edge protection proxies which provide secure communications between the communication networks in accordance with an example embodiment of the present disclosure;

[0091] FIG. IB is an example apparatus in accordance with an example embodiment of the present disclosure;

[0092] FIG. 2 illustrates a protocol for N32 Interconnect Security (PRINS) used for secure signaling of control plane message between two communication networks in accordance with previous aspects;

[0093] FIG. 3 illustrates a procedure in which a roaming intermediary entity detects an error in a response in accordance with previous aspects;

[0094] FIG. 4 is an example signaling diagram of a roaming intermediary instructing a SEPP to terminate an N32-f context by originating an N32-f request encapsulating an N32-c message in accordance with an example aspect of the present disclosure;

[0095] FIG. 5 is an example signaling diagram of a roaming intermediary instructing a SEPP to terminate an N32-f context by sending a 4xx / 5xx response in accordance with an example aspect of the present disclosure;

[0096] FIG. 6 is an example signaling diagram of a roaming intermediary instructing a SEPP to terminate an N32-f context with a callback URI of an HTTP Connect request in accordance with an example aspect of the present disclosure;

[0097] FIG. 7 is a flowchart illustrating operations performed by a roaming intermediary in order to provide a message instructing a SEPP to terminate or re-establish an N32-f context and / or an N32-f connection in accordance with an example aspect of the present disclosure; and

[0098] FIG. 8 is a flowchart illustrating operations performed by a SEPP in order to terminate or re-establish an N32-f context and / or an N32-f connection in accordance with an example aspect of the present disclosure. DETAILED DESCRIPTION

[0099] Some aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which some, but not all, aspects are shown. Indeed, various aspects may be embodied in many different forms and should not be construed as limited to the aspects set forth herein; rather, these aspects are provided so that this disclosure will satisfy applicable legal requirements. Like reference numerals refer to like elements throughout. As used herein, the terms “data,” “content,” “information,” and similar terms may be used interchangeably to refer to data capable of being transmitted, received and / or stored in accordance with aspects of the present disclosure. Thus, use of any such terms should not be taken to limit the spirit and scope of aspects of the present disclosure.

[0100] Additionally, as used herein, the term “circuitry” refers to (a) hardware-only circuit implementations (e.g., implementations in analog circuitry and / or digital circuitry); (b) combinations of circuits and computer program product(s) including software and / or firmware instructions stored on one or more computer readable memories that work together to cause an apparatus to perform one or more functions described herein; and (c) circuits, such as, for example, a microprocessor(s) or a portion of a microprocessor(s), that require software or firmware for operation even if the software or firmware is not physically present. This definition of “circuitry” applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term “circuitry” also includes an implementation including one or more processors and / or portion(s) thereof and accompanying software and / or firmware. As another example, the term “circuitry” as used herein also includes, for example, a baseband integrated circuit or applications processor integrated circuit for a mobile phone or a similar integrated circuit in a server, a cellular network device, other network device (such as a core network apparatus), field programmable gate array, and / or other computing device.

[0101] As used herein, the term “computer-readable medium” refers to non-transitory storage hardware, non-transitory storage device or non-transitory computer system memory that may be accessed by a controller, a microcontroller, a computational system or a module of a computational system to encored thereon computer-executable instructions or software programs. A non-transitory “computer readable medium” may be accessed by a computational system or a module of a computational system to retrieve and / or execute the computerexecutable instructions or software programs encoded on the medium. Examples of non-transitory computer-readable media may include, but are not limited to, one or more types of hardware memory, non-transitory tangible media (for example, one or more magnetic storage disks, one or more optical disks, one or more universal synchronous bus (USB) flash drives), computer system memory or random-access memory (such as dynamic random access memory (DRAM), static random access memory (SRAM), extended data out random access memory (EDO RAM), and the like.

[0102] FIG. 1A shows two public land mobile networks (PLMNs) A and B comprising two security edge protection proxies (SEPPs) 102 and 104 that provide secure communications of control plane messages between two PLMNs A and B in accordance with an example embodiment of the present disclosure. In one or more aspects, the SEPPS 102 and 104 perform authentication of each other prior to communication of control plane messages between communication networks A and B. In some aspects, PLMN A is a home PLMN (i.e., a PLMN with a relationship to a subscriber) and PLMN B is a visiting PLMN (i.e., a PLMN to which the same subscriber has roamed).

[0103] In some aspects, at phase 100a, an N32-c interface connection is created between the SEPP 102 and the SEPP 104. In some aspects, an initial HPPT / 2 handshake procedure is performed between SEPP 102 and SEPP 104 over the N32-c connection 106. In some aspects, parameters are negotiated over the N32-c connection 106 to be applied to N32 message forwarding between SEPP 102 and SEPP 104. In an example aspect, once the HTTP / 2 handshake procedure is completed, the N32-c connection 106 is torn down. In some examples, the N32-c connection 106 is end-to-end between SEPPs 102 and 104 and does not involve an internet protocol exchange (IPX) intercepting the HTTP / 2 connection. In some examples, an IPX is involved for internet protocol level routing.

[0104] In one or more aspects, at phase 100b, an N32-f context is established between SEPPs 102 and 104, which allows an N32-f connection 108. In some aspects, the N32-f connection is a forwarding interface between SEPPs 102 and 104 that is used for forwarding communication between a network function (NF) service consumer and a NF service producer after applying application level security protection. In some aspects, N32-f connection 108 can provide application level security between SEPPS 102 and 104. In some aspects, if negotiated over N32-c connection 106, application level security can protect (i.e., secure) messages exchanged between the NF service consumer and the NF service producer and forward application layer protected messages from a SEPP 102 in PLMN Ato PLMN B by using IPXs 110 and 112 (also referred to as roaming intermediary entities). IPXs 110 and 112 may insert content modification instructions which SEPP 104 applies after verifying the integrity of the modification instructions.

[0105] In some aspects, N32-f connection 108 is long lived. In some embodiments, N32-f connection 108 is an HTTP / 2 connection which protects confidentiality of information elements in messages forwarded between SEPPs. In some examples, information elements may be modified in HTTP / 2 request and response messages via IPX 110 and / or 112. In some examples, the N32-f connection 108 may be terminated while the N32-f context may remain. In some aspects, the N32-f connection 108 may be re-established with the same N32-f context. In some aspects, when the N32-f context is terminated, the N32-f connection 108 is terminated.

[0106] FIG. IB depicts an example apparatus 120 that may comprise or implement a roaming intermediary or a SEPP. As shown in FIG. 1, the apparatus 120 includes, is associated with, or is in communications with processing circuitry 122, a memory device 124, and a communication interface 126. The processing circuitry 122 may be in communication with the memory device 124 via a bus configured for passing information among the memory 124, the processing circuitry 122, and the communication interface 126 of the apparatus. The memory 124 may be non-transitory and may include, for example, one or more volatile and / or non-volatile memories. In other words, for example, the memory device 124 may be an electronic storage device (e.g.. a computer readable storage medium) including gates configured to store data (e.g., bits) that may be retrievable by a machine (e.g., a computing device like the processing circuitry). The memory device 124 may be configured to store information, data, content, applications, instructions, or the like. For example, the memory device 124 may be configured to buffer input data for processing by the processing circuitry 122. The memory device 124 may be configured to store instructions of a roaming intermediary and / or SEEP for execution by the processing circuitry, wherein execution of the instructions of the roaming intermediary and / or SEEP which causes the apparatus to carry out various operations in accordance with an example aspect of the present disclosure.

[0107] The apparatus 120 may, in some aspects, be embodied as a general purpose computer (e.g., a single physical computer), a virtual machine, a distributed computer system, a cloud computing system that provides a cloud core network, and / or various other computing devices. However, in some aspects, the apparatus 120 may be embodied as a chip or chip set. In other words, the apparatus may include one or more physical packages (e.g., chips) including materials, components and / or wires on a structural assembly (e.g., a baseboard). The structural assembly may provide physical strength, conservation of size, and / or limitation of electrical interaction for component circuitry included thereon. The apparatus may therefore, in some cases, be configured to implement an aspect on a single chip or as a single “system on a chip.” As such, in some cases, a chip or chipset may constitute means for performing one or more operations for providing the functionalities described herein.

[0108] The processing circuitry 122, also referenced as a processor, may be embodied in a number of different ways. For example, the processing circuitry 122 may be embodied as one or more of various hardware processing means such as a coprocessor, a microprocessor, a controller, a digital signal processor (DSP), a processing element with or without an accompanying DSP, or various other circuitry including integrated circuits such as, for example, an ASIC (application specific integrated circuit), an FPGA (field programmable gate array), a central processing unit, a graphics processing unit, a tensor processing unit, a microcontroller unit (MCU), a hardware accelerator, a special-purpose computer chip, or the like. As such, in some aspects, the processing circuitry may include one or more processing cores configured to perform independently. A multi-core processing circuitry may enable multiprocessing within a single physical package. Additionally or alternatively, the processing circuitry 122 may include one or more processors configured in tandem via the bus to enable independent execution of instructions, pipelining, and / or multithreading.

[0109] In an example aspect, the processing circuitry 122 may be configured to execute instructions stored in the memory device 124 or otherwise accessible to the processing circuitry 122. Alternatively or additionally, the processing circuitry 122 may be configured to execute hardcoded functionality. As such, whether configured by hardware or software methods, or by a combination thereof, the processing circuitry may represent an entity (e.g., physically embodied in circuitry) capable of performing operations according to an aspect of the present disclosure while configured accordingly. Thus, for example, when the processing circuitry 122 is embodied as an ASIC, FPGA or the like, the processing circuitry 122 may be specifically configured hardware for conducting the operations described herein. Alternatively, as another example, when the processing circuitry is embodied as an executor of instructions, the instructions may specifically configure the processor to perform the algorithms and / or operations described herein when the instructions are executed. However, in some cases, the processing circuitry 122 may be a processor of a specific device (e.g., an image or video processing system) configured to employ an aspect by further configuration of the processing circuitry by instructions for performing the algorithms and / or operations described herein. The processing circuitry may include, among other things, a clock, an arithmetic logic unit (ALU) and logic gates configured to support operation of the processing circuitry.

[0110] The communication interface 126 may be any means such as a device or circuitry embodied in either hardware or a combination of hardware and software that is configured to receive and / or transmit data including media content in the form of video or image files, one or more audio tracks or the like. In this regard, the communication interface may include, for example, an antenna (or multiple antennas) and supporting hardware and / or software for enabling communications with a wireless communication network. Additionally or alternatively, the communication interface may include the circuitry for interacting with the antenna(s) to cause transmission of signals via the antenna(s) or to handle receipt of signals received via the antenna(s). In some environments, the communications interface may alternatively or also support wired communication. As such, for example, the communication interface may include a communication modem and / or other hardware / software for supporting communication via cable, digital subscriber line (DSL), universal serial bus (USB) or other mechanisms.

[0111] Turning now to FIG. 2, protocol for N32 Interconnect Security (PRINS) used for secure signaling of control plane message between two communication networks in accordance with previous aspects. The PRINS secures signaling between two network functions 202 and 212 each connected to a SEPP. In this case, network function 202 is a service consumer connected to consumer SEPP 204 (i.e., a SEPP on the network function consumer side) and network function 212 is a service producer connected to producer SEPP 210 (i.e., a SEPP on the network function producer side).

[0112] An N32-f context has a unique N32-f context identifier that is created at both the consumer SEPP 202 and the producer SEPP 210 at the N32-c 216 handshake. The N32-f context identifier stores security and protection policies negotiated to be used to protect messages exchanged between two PLMNs over the N32-f connections 214 in both directions. The N32-f context identifier is also signaled in N32-f messages to allow correlating the N32-f messages with the corresponding N32-f context resulting from an N32-c 216 handshake. The N32-f context identifier is generated by the producer SEPP 210 and is included in N32-c 216 messages and N32-f messages. The consumer SEPP 204 uses the N32-f context identifier to identify the N32-f connection 214 and apply the appropriate security protection and verification.

[0113] A producer roaming intermediary 208 and a consumer roaming intermediary 206 are provided in system 200. The roaming intermediaries 206 and 2208 may provide roaming related services. The roaming intermediaries may be roaming hubs, roaming value-added service servers, internet protocol exchanges (illustrated), and / or the like.

[0114] A roaming intermediary 206 or 208 may originate error messages to adjacent PLMN SEPPs 204 or 210, such as when a roaming intermediary 206 or 208 detects an error in an incoming N32-f response such as an indication that an information element was encrypted when it was expected to be clear.

[0115] The N32-c 216 connection may be set up via roaming intermediary 206 or 208 using a Hypertext Transfer Protocol (HTTP) connect method. N32-f related errors, N32-f applicative (service based interface) errors, and N32-f applicative (service based interface) requests may be originated. [0H6] If a roaming intermediary 206 or 208 detects an error an error in an incoming N32-f request or response, it needs to generate an N32-c 216 related error message upon reception of an N32-f response. For example, this may be due to encrypted information in the N32-f response message when it was expected to be clear. The roaming intermediary 208 sends an N32-f request message encapsulating an N32-c 216 message towards producer SEPP 210 to report the error.

[0117] If a roaming intermediary 206 OR 208 needs to generate an N32-f related error message upon receiving an N32-f response, the roaming intermediary constructs a new N32-f request for a SEPP with several modifications. For example, the modifications may include the DataToIntegrityProtectBlock containing only the MetaData with the N32-f context identifier and message identifier of the N32-f response message for which an error was detected. The modificationBlock contains patch instructions based on a DataToIntegrityProtectBlock only containing the MetaData with the N32-f context identifier and message identifier. The patch instructions in the modificationBlock result m encoding an N32-c request for N32-f error reporting. Adding the requestLine to form an HTTP POST request {n32c-apiRoot} / n32c-handshake / vl / n32f-error. The {n32c-apiRoot} is set to a dummy N32-c apiRoot defined as the N32-f apiRoot with the authority part prepended with label n32c. Headers will be added if applicable. A payload will be added that is the content of the N32-f Error Reporting Request (N32fErrorInfo). The modificationBlock contains the JWS signature of the roaming intermediary. The roaming intermediary then sends its N32-f request (i.e., the N32-f related error message) towards the producer SEPP using the same N32-f apiRoot as the one that was used in the original N32-f request sent to the producer SEPP. The request may be sent via another roaming intermediary.

[0118] The dummy N32-c apiRoot in the N32-c message encapsulated in the N32-f request need not contain addressing information of any actual N32-c service instance of the producer SEPP. Instead, this indicates to the receiving N32-f service instance of the producer SEPP that it needs to look up for an N32-c service instance and route the request towards that N32-c service instance.

[0119] A roaming intermediary does not have a current way to instruct the SEPP to terminate the N32-f connection and / or N32-f context (e.g., when the roaming intermediary would need to shut down and a new roaming intermediary should be used for inter-PLMN communication). Terminating an N32-f connection means releasing the N32-f HTTP connection. Terminating an N32-f context means releasing the N32 context that was established during the N32-c handshake, including all security and protection policies that were negotiated for use over the related N32-f connections. A new handshake would then be required to establish a new N32-f context to allow the resumption of message exchanges communication of control plane messages between the two PLMNs over a N32-f connection.

[0120] Turning now to FIG. 3, a procedure 300 is provided in which a roaming intermediary detects an error in a response in accordance with previous aspects.

[0121] At operation 302, the consumer network function 292 sends a service request message to the consumer SEPP 204. The service request message is an HTTP request message.

[0122] At operation 304, the consumer SEPP 204 sends an N32-f request using PRINS security to forward the service request message to the producer SEPP 210. The N32-f request is sent using a JSON object signing and encryption message.

[0123] At operation 306, the producer SEPP 210 sends the service request to the producer network function 212.

[0124] At operation 308, the producer network function 212 returns a service response to the producer SEPP 210. The service response may be a 200 OK response.

[0125] At operation 310, the producer SEPP 210 encapsulates the service response in an N32-f response and forwards the message to the consumer SEPP 204 via roaming intermediary 208. The N32-f message is a JSON object signing and encryption message.

[0126] At operation 312, roaming intermediary 208 detects an N32-f related error. For example, an information element may have been received encrypted when it should have been clear. Depending on the policy of roaming intermediary 208, the roaming intermediary may forward the response message (i.e., the 200 OK response) encapsulating the service response to the consumer SEPP 204 via roaming intermediary 206. In examples where roaming intermediary 208 decides not to forward the response message to the consumer SEPP 204, network function consumers and network function producers may end up with de-synchronized status in case of a non-safe or idempotent operation. A 5GC service based interface may be used for handling these situations, such as to detect the re-transmitted request. In other examples, roaming intermediary 206 may detect an error, and the same procedure 300 would apply.

[0127] At operation 314, roaming intermediary 206 forwards the service response from the roaming intermediary 208 to the consumer SEPP 204.

[0128] At operation 316, consumer SEPP 204 forwards the service response to the consumer network function 202.

[0129] At operation 318, the roaming intermediary 208 sends a new N32-f request encapsulating an N32-c “N32 Error Reporting request” message. The message is sent towards a producer SEPP 210 to report the error. Upon receipt of an N32-f request encapsulating an N32-c message with a dummy N32-c apiRoot, the receiving N32-f service instance of the producer SEPP 210 looks up for an N32-c instance that can support the N32-f connection identified by the N32-f context identifier received in the N32-f request. The producer SEPP 210 substitutes the dummy N32-c apiRoot of the N32-c message with the apiRoot of that N32-c service instance and forwards the N32-c message towards that N32-c service instance.

[0130] At operation 320, the producer SEPP 210 returns “204 No Content” to the roaming intermediary 208.

[0131] At operation 322, the producer SEPP 210 logs the error and, if possible and allowed by local policies, considers it for further N32-f messages that the producer SEPP 210 sends towards the consumer SEPP 204. The producer SEPP 210 may send the reported information element in clear in further messages it forwards towards the consumer SEPP 204.

[0132] At operation 324, the consumer network function 202 may repeat its service request in case no response is being received from the consumer SEPP 204.

[0133] At operation 326, the consumer SEPP 204 forwards the repeated service request form the consumer network function 202 if any. Alternatively, the consumer SEPP 204 may resend its N32-f request to the producer SEPP 210 due to no response being received from the producer SEPP 210.

[0134] At operation 328, the producer SEPP 210 forwards the service request towards the producer network function 212.

[0135] At operation 330, the producer network 212 returns the service response. The service response may be a 200 OK response.

[0136] At operation 332, the producer SEPP 210 encapsulates the service response in an N32-f response. The response may be a JSON object signing and encrypted protected message. The producer SEPP 210 forwards the message to the consumer SEPP 204. The producer SEPP 210 takes into account any error information earlier received from the consumer SEPP 204 or the roaming intermediary 208 if possible and allowed by local policies. For example, the producer SEPP 204 may have earlier received an information element reporting an error in clear.

[0137] At operation 334, the consumer SEPP 204 sends a service response to the consumer network function 202.

[0138] Turning now to FIG. 4, an example signaling diagram 400 of a roaming intermediary instructing a SEPP to terminate an N32-f context by originating an N32-f request encapsulating an N32-c message is provided in accordance with an example aspect of the present disclosure. In one or more aspects, the signaling diagram 400 illustrates communications between a consumer SEPP 420, roaming intermediaries 422 and 424, and producer SEPP 426. In some aspects, the producer SEPP 426 includes an N32-f instance 426a and an N32-c instance 426b. In some examples, there is an N32 interface between the consumer SEPP 420 and the producer SEPP 426. In some examples, roaming intermediaries 422 and 424 manage communications between SEPPs 420 and 426, each associated with a different PLMN. In some examples, the N32-f context serves as a logical link for secure communication, thus enabling 5G roaming services.

[0139] In one or more aspects, at operation 402, the roaming intermediary 424 decides to terminate the N32-f context. Roaming intermediary 424 may decide to terminate the N32-f context for different reasons in different aspects. For example, the roaming intermediary 414 may terminate the N32-f context based on business decisions, security violations, resource constraints, network maintenance, user requests, error reporting, and / or the like. In some aspects, the roaming intermediary 424 may decide to terminate the N32-f context and / or the N32-f connection. In some aspects, the roaming intermediary 424 may decide to re-establish the N32-f context and / or the N32-f connection.

[0140] In one or aspects, at operation 404, the roaming intermediary 414 may send an N32-f HTTP request message encapsulating an N32-c message. For example, the N32-c message may be an N32-f error reporting request or an N32-f termination request towards the producer SEPP 426 to report the error (in other examples, the message may be sent to consumer SEPP 420). In some examples, the N32-f error reporting request or N32-f termination request includes error information indicating instructions for the SEPP 426 and / or reasons for the instructions. In some examples, the error message comprises an instruction that directs producer SEPP 426 terminate the N32-f context and / or the N32-f connection not re-establish the N32-f context and / or the N32- f connection in the future. In some examples, the error message comprises an instruction that directs producer SEPP 426 to terminate the N32-f context and / or the N32-f connection allow the N32-f context and / or the N32-f connection to be re-established in the future. In some examples, the error message comprises an instruction that directs producer SEPP 426 to release and reestablish the N32-f context and / or N32-f connection. In some examples, the error message comprises an instruction that directs to producer SEPP 426 an identity of an alternative roaming intermediary with which to re-establish the N32-f context and / or the N-32-f connection. In some examples, the roaming intermediary 424 generates an error message towards each of consumer SEPP 420 and producer SEPP 426, and each SEPP tears down its N32-f context locally.

[0141] In some examples, the error message may indicate the reason for the N32-f context and / or N32-f connection termination or re-establishment. In some examples, the reason for the N32-f context and / or N32-f connection termination or re-establishment serves as the instruction when the SEPP would react differently to different scenarios. In some examples where the roaming intermediary 424 decides to no longer facilitate communications with a PLMN for business reasons (e.g., contract termination or fraudulent behavior), the message comprises an instruction that directs the SEPP 426 to terminate the N32-f connection and not try to reconnect with that PLMN. In some examples, previously negotiated credentials become invalid. In some examples where the roaming intermediary 424 observes no traffic on an N32-f connection for a configurable time, the message comprises an instruction that directs the SEPP 426 to maintain the N32-f context and re-establish connection if there is demand, with negotiated credentials remaining applicable. In some examples where the roaming intermediary 424 determines that it should power down and another roaming intermediary should be used, the message comprises an instruction that directs the SEPP 426 to re-establish the N32-f connection via another roaming intermediary and maintain the N32-f context, with negotiated credentials remaining applicable. In some examples where the roaming intermediary 424 observes connectivity issues on a transmission control protocol connection with SEPP 426, the message comprises an instruction that directs the SEPP 426 to re-establish the N32-f connection towards roaming intermediary 424 and maintain the N32-f context, with negotiated credentials remaining applicable. In some examples, the error message may indicate that the producer SEPP 426 has become temporarily unavailable, and the error message may instruct the consumer SEPP 420 to terminate the N32-f context until SEPP availability is restored. In some examples, the error message comprises an instruction that directs a SEPP to terminate an N32-f context before a maintenance operation. In some examples, the error message may instruct a SEPP to terminate an N32-f context due to an unauthorized access attempt, and the error message may instruct a SEPP to log the intrusion attempt. In some examples, the error message may instruct a SEPP to terminate an N32-f context due to resource exhaustion. In some examples, a roaming intermediary 424 may want a specific SEPP not to re-establish an N32-f connection, and that SEPP can either maintain or terminate the N32-f context based on roaming intermediary 424 preference, while negotiated credentials remain applicable.

[0142] In some examples, the error message includes information element n32fConnectionRel!nd which provides instructions to terminate the N32-f connection, and an indication whether the N32-f connection may be re-established, and / or an alternative roaming intermediary entity through which to re-establish the N32-f connection.

[0143] In some examples, the error message includes information element n32fContextRelInd which provides instructions to terminate the N32-f context (and by extension the N32-f connection), and an indication whether the N32-f context may be re-established, and / or an alternative roaming intermediary entity through which to re-establish the N32-f context.

[0144] In some examples, this solution provides a straightforward way for the roaming intermediary 424 to signal termination to a SEPP 426. In some examples, inclusion of an N32-c related cause is allowed. In some examples, the N32-f connection and / or N32-f context to be terminated or re-established is explicitly identified.

[0145] In one or more aspects, at operation 406, a producer SEPP N32-f instance 426a replaces the dummy apiRoot with the N32-c apiRoot corresponding to the N32-f context identifier received in the N32-f message at operation 404. In some aspects, the producer SEPP N32-f instance proceeds to send a source identity of roaming intermediary 424 to the N32-c instance 426b.

[0146] In one or more aspects, at operation 408, the producer SEPP N32-f service instance 426a sends the N32-c request message towards the target N32-c service instance 426b. In some aspects, the message includes the identity of the sending roaming intermediary 424 so that the SEPP N32-c instance 426b can determine the roaming intermediary 424 that originated the error and take a proper decision based on the contract or the agreement between the agreement between SEPP 426 and roaming intermediary 424. In some examples, the message is an HTTP POST N32-f error reporting message. In some examples, the message includes the application error to terminate or re-establish the N32-f context and / or connection.

[0147] In one or more aspects, at operation 410, the producer SEPP N32-f service instance 426b identifies the request from the roaming intermediary 424 to terminate the N32-f context and / or the N32-f connection.

[0148] In one or more aspects, at operation 412, the producer SEPP N32-c instance 426b logs the error. In some examples, producer SEPPN32-C instance 426b checks the sender identity of the message (e.g., roaming intermediary 424). In some examples, the producer SEPP N32-c instance 426b returns “204 No Content” to the producer SEPP N32-f instance 426a.

[0149] In one or more aspects, at operation 414, the producer SEPP N32-f instance 426a provides, to roaming intermediary 424, the response message. In some examples, the response message is a “200 OK response” encapsulating the response message.

[0150] In some aspects at operation 416, the producer SEPP 426 terminates the N32-f connection and / or the N32-f context. In some aspects, the producer SEPP 426 re-establishes the N32-f connection and / or the N32-f context again using a different roaming intermediary or the same roaming intermediary 424. In some examples, this may occur immediately or after a delay.

[0151] In some aspects, at operation 418, the producer SEPP N32-c instance starts an N32-f context termination procedure. In some examples, the SEPP N32-c instance sends an N32-f context termination request message towards the consumer SEPP 420 based on the received cause from the roaming intermediary application error. In some examples, the N32-f context termination request is extended with a new cause information indicating that the N32-f context is released upon roaming intermediary request.

[0152] Turning now to FIG. 5, an example signaling diagram 500 of a roaming intermediary instructing a SEPP to terminate an N32-f context by responding to an incoming N32-f request message with a 4xx or 4xx response message is provided in accordance with an example aspect of the present disclosure. In one or more aspects, the signaling diagram 500 illustrates communications between the consumer SEPP 420, roaming intermediaries 422 and 424, and producer SEPP 426. In some aspects, the producer SEPP 426 includes an N32-f instance 426a and an N32-c instance 426b. In some examples, there is an N32 interface between the consumer SEPP 420 and the producer SEPP 426. In some examples, roaming intermediaries 422 and 424 manage communications between SEPPs 420 and 426, each associated with a different PLMN. In some examples, the N32-f context serves as a logical link for secure communication, thus enabling 5G roaming services.

[0153] In one or more aspects, at operation 502, producer SEPP N32-f instance 426a sends an N32-f request message to roaming intermediary 424. In some examples, the message is an N 3 2ReformattedReqMsg.

[0154] In one or more aspects, at operation 402, the roaming intermediary 424 decides to terminate the N32-f context. Roaming intermediary 424 may decide to terminate the N32-f context for different reasons in different aspects. For example, the roaming intermediary 414 may terminate the N32-f context based on business decisions, security violations, resource constraints, network maintenance, user requests, error reporting, and / or the like. In some aspects, the roaming intermediary 424 may decide to terminate the N32-f connection. In some aspects, the roaming intermediary 424 may decide to re-establish the N32-f context and / or the N32-f connection.

[0155] In one or aspects, at operation 504, the roaming intermediary 414 responds to the producer SEPP 426 with an N32-f error response message such as a 4xx or 5xx response that includes error information. In other examples, the roaming intermediary 414 may respond to a consumer SEPP with an N32-f error response message. In some examples, the error response message includes error information indicating instructions for the SEPP 426 and / or reasons for the instructions. In some examples, the error response message comprises an instruction that directs producer SEPP 426 terminate the N32-f context and / or the N32-f connection not reestablish the N32-f context and / or the N32-f connection in the future. In some examples, the error response message comprises an instruction that directs producer SEPP 426 to terminate the N32-f context and / or the N32-f connection allow the N32-f context and / or the N32-f connection to be re-established in the future. In some examples, the error response message comprises an instruction that directs producer SEPP 426 to release and re-establish the N32-f context and / or N32-f connection. In some examples, the error response message comprises an instruction that directs to producer SEPP 426 an identity of an alternative roaming intermediary with which to re-establish the N32-f context and / or the N-32-f connection. In some examples, the roaming intermediary 424 generates an error response message towards each of consumer SEPP 420 and producer SEPP 426, and each SEPP tears down its N32-f context locally.

[0156] In some examples, the error response message may indicate the reason for the N32-f context and / or N32-f connection termination or re-establishment. In some examples, the reason for the N32-f context and / or N32-f connection termination or re-establishment serves as the instruction when the SEPP would react differently to different scenarios. In some examples where the roaming intermediary 424 decides to no longer facilitate communications with a PLMN for business reasons (e.g., contract termination or fraudulent behavior), the response message comprises an instruction that directs the SEPP 426 to terminate the N32-f connection and not try to reconnect with that PLMN. In some examples, previously negotiated credentials become invalid. In some examples where the roaming intermediary 424 observes no traffic on an N32-f connection for a configurable time, the response message comprises an instruction that directs the SEPP 426 to maintain the N32-f context and re-establish connection if there is demand, with negotiated credentials remaining applicable. In some examples where the roaming intermediary 424 determines that it should power down and another roaming intermediary should be used, the response message comprises an instruction that directs the SEPP 426 to re-establish the N32-f connection via another roaming intermediary and maintain the N32-f context, with negotiated credentials remaining applicable. In some examples where the roaming intermediary 424 observes connectivity issues on a transmission control protocol connection with SEPP 426, the response message comprises an instruction that directs the SEPP 426 to re-establish the N32-f connection towards roaming intermediary 424 and maintain the N32-f context, with negotiated credentials remaining applicable. In some examples, the error response message may indicate that the producer SEPP 426 has become temporarily unavailable, and the error response message may instruct the consumer SEPP 420 to terminate the N32-f context until SEPP availability is restored. In some examples, the error response message comprises an instruction that directs a SEPP to terminate an N32-f context before a maintenance operation. In some examples, the error response message may instruct a SEPP to terminate an N32-f context due to an unauthorized access attempt, and the error response message may instruct a SEPP to log the intrusion attempt. In some examples, the error response message may instruct a SEPP to terminate an N32-f context due to resource exhaustion. In some examples, a roaming intermediary 424 may want a specific SEPP not to re-establish an N32-f connection, and that SEPP can either maintain or terminate the N32-f context based on roaming intermediary 424 preference, while negotiated credentials remain applicable.

[0157] In some examples, the error response message includes information element n32fConnectionRelInd which provides instructions to terminate the N32-f connection, and an indication whether the N32-f connection may be re-established, and / or an alternative roaming intermediary entity through which to re-establish the N32-f connection.

[0158] In some examples, the error response message includes information element n32fContextRelInd which provides instructions to terminate the N32-f context (and by extension the N32-f connection), and an indication whether the N32-f context may be re-established, and / or an alternative roaming intermediary entity through which to re-establish the N32-f context.

[0159] In some examples, this solution provides a straightforward way for the roaming intermediary 424 to signal termination to a SEPP 426. In some examples, inclusion of an N32-c related cause is allowed. In some examples, the N32-f connection and / or N32-f context to be terminated or re-established is explicitly identified.

[0160] In one or more aspects, at operation 408, the producer SEPP N32-f service instance 426a sends the error response message towards the target N32-c service instance 426b. In some aspects, the response message includes the identity of the sending roaming intermediary 424 so that the SEPP N32-c instance 426b can determine the roaming intermediary 424 that originated the error and take a proper decision based on the contract or the agreement between the agreement between SEPP 426 and roaming intermediary 424. In some examples, the response message is an HTTP POST N32-f error reporting message. In some examples, the response message includes the application error to terminate or re-establish the N32-f context and / or connection.

[0161] In one or more aspects, at operation 410, the producer SEPPN32-f service instance 426b identifies the request from the roaming intermediary 424 to terminate the N32-f context and / or the N32-f connection.

[0162] In one or more aspects, at operation 412, the producer SEPP N32-c instance 426b logs the error. In some examples, producer SEPPN32-C instance 426b checks the sender identity of the response message (e.g., roaming intermediary 424). In some examples, the producer SEPPN32-C instance 426b returns “204 No Content” to the producer SEPP N32-f instance 426a.

[0163] In some aspects at operation 416, the producer SEPP 426 terminates the N32-f connection and / or the N32-f context. In some aspects, the producer SEPP 426 re-establishes the N32-f connection and / or the N32-f context again using a different roaming intermediary or the same roaming intermediary 424. In some examples, this may occur immediately or after a delay.

[0164] In some aspects, at operation 418, the producer SEPP N32-c instance starts an N32-f context termination procedure. In some examples, the SEPP N32-c instance sends an N32-f context termination request message towards the consumer SEPP 420 based on the received cause from the roaming intermediary application error. In some examples, the N32-f context termination request is extended with a new cause information indicating that the N32-f context is released upon roaming intermediary request.

[0165] Turning now to FIG. 6, an example signaling diagram 600 of a roaming intermediary instructing a SEPP to terminate and / or re-establish an N32-f context with a callback URI of an HTTP Connect request is provided in accordance with an example aspect of the present disclosure. In some aspects, the producer SEPP 427, the roaming intermediary 424, and the consumer SEPP 420 are in illustrated.

[0166] In one or more aspects, at operation 602, the producer SEPP 426 and the roaming intermediary 424 establish a transmission control protocol connection.

[0167] In one or more aspects, at operation 604, the producer SEPP 427 transmits an HTTP connect request to roaming intermediary 424. In some examples, the HTTP connect request contains a header with an N32-c callback uniform resource identifier (URI). In some examples, a callback URI is defined for the SEPP 424.

[0168] In one or more aspects, at operation 606, the roaming intermediary 424 determines whether to establish an N32-c connection. In some examples, the roaming intermediary 424 stores the N32-c callback URI of the SEPP 424.

[0169] In one or more aspects, at operation 608, the consumer SEPP 420 and the roaming intermediary 424 establish a transmission control protocol connection.

[0170] In one or more aspects, at operation 610, the roaming intermediary 424 transmits a 200 OK response to the producer SEPP 424. In some examples, blind forwarding of data then takes place.

[0171] In one or more aspects, at operation 612, an e2e N32-c transport layer security connection is established between the producer SEPP 426 and the consumer SEPP 420.

[0172] In one or more aspects, at operation 614, producer SEPP 426 and consumer SEPP 420 perform an e2e N32-c handshake procedure. In some examples, the procedure includes exchanging N32-c requests and responses.

[0173] In one or more aspects, at operation 616, N32-f connections are established between SEPP 426, roaming intermediary 424, and SEPP 420. In some aspects, N32-f connections are established based on N32-f context.

[0174] In one or more aspects, at operation 618, N32-f messages are exchanged. For example, roaming intermediary 424 forwards N32-f messages between producer SEPP 426 and consumer SEPP 420.

[0175] In one or more aspects, at operation 620, roaming intermediary 424 determines to terminate the N32-f connection and / or the N32-f context. In some examples, roaming intermediary 424 retrieves the callback URI stored in operation 606 and received in operation 604 in order to send an instruction to terminate the N32-f context and / or the N32-f connection towards the callback URI.

[0176] In one or more aspects, at operation 622, roaming intermediary entity 424 sends an HTTP request (e.g., a notification request) towards the callback URI stored in operation 606 and received in operation 604. In some examples, the HTTP request includes instructions that direct the producer SEPP 424 to terminate the N32-f context and / or the N32-f connection. In some examples, the HTTP request includes an information indicating whether the producer SEPP 424 may re-establish the N32-f context and / or N32-f connection. In some examples, the HTTP request includes information indicative of an alternative roaming intermediary by which to reestablish the N32-f context and / or N32-f connection. In some examples, N32-f connections are identified via identifier or implicitly via an N32-c connection used to negotiate credentials for the N32-f context. In some examples, the roaming intermediary receives “204 No Content” from the producer SEPP 424.

[0177] In one or more aspects, at operation 624, the producer SEPP 426 determines to terminate the N32-f context and / or N32-f connection. In one or more aspects, at 626, producer SEPP 426 sends to consumer SEPP 420 a message comprising an instruction that directs the consumer SEPP 420 to terminate the N32-f context and / or the N32-f connection. In one or more aspects, the message may be a n32fTerminate message, and the n32fTerminate message may include a parameter called N32fContextInfo (generally referred toa a N32FContextInfo parameter) and another parameter called TerminationCause (generally referred to as TerminationCause parameter. The N32FContextInfo parameter indicates to terminate the N32-f context and / or tN32-f connection and the TerminationCause parameter indicates a cause of the termination of the N32-f context and / or N32-f connection.

[0178] Turning now to FIG. 7, an example flowchart is illustrated for a process 700 performed by a roaming intermediary entity (e.g., roaming intermediary entity 424) in order to send a control plane message to a SEPP. In one or more aspects, the roaming intermediary entity is configured to provide roaming related services. The roaming intermediary entity may be a Roaming Hub or an internet protocol (IP) exchange service (IPX) provider entity and a roaming intermediary entity may be deployed between two communication networks to enable secure communication of control plane messages between the two communication networks. For example, a roaming intermediary entity may be deployed between two Public Land Mobile Networks (PLMNs), deployed between a PLMN and a Standalone Private Network (SNPN) or deployed between two SNPNs.

[0179] As shown in block 702 of FIG. 7, the apparatus embodied by the roaming intermediary entity 424 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for determining whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or re-established. In one or more aspects, the determining whether at least one of the N32-f context or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message includes an N32-f message forwarding error response message. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of network maintenance at the network including the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of insufficient resources at the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or reestablished is based on information indicative of a business determination. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of a change of contractual agreements between the roaming intermediary entity and another roaming intermediary entity, the SEPP entity, or another SEPP entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicating that the determination that a N32-f connection is inactive. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative a switch to the roaming intermediary entity. In one or more aspects, the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on information indicative of insufficient connectivity with the another roaming intermediary entity, the SEPP entity, or the another SEPP entity.

[0180] As shown in block 704 of FIG. 7, the apparatus embodied by the roaming intermediary entity 424 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generating a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection.

[0181] As shown in block 706 of FIG. 7, the apparatus embodied by the roaming intermediary entity 424 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generating a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection. In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before reestablishing the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, the message that is generated further includes an indication of an alternative roaming intermediary for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

[0182] As shown in block 708 of FIG. 7, the apparatus embodied by the roaming intermediary entity 424 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for generating a message including at least one of the first instruction and / or the second instruction. In one or more aspects, the message includes an N32-f error reporting request, and the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

[0183] As shown in block 710 of FIG. 7, the apparatus embodied by the roaming intermediary entity 424 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for sending the message to the SEPP entity. In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and the second instruction for the SEPP entity to reestablish the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one N32-f context and / or the N32-f connection.

[0184] Turning now to FIG. 8, an example flowchart is illustrated for a process 800 performed by a security edge protection proxy (SEPP) entity (e.g., SEPP 420 / 426) in order to apply an instruction received from a roaming intermediary entity. In one or more aspects, the SEPP entity is deployed by one PLMN or one SNPN to support and protect the communication with the peer SEPP entity deployed by the peer PLMN or the peer SNPN, and wherein the communication between the SEPP entity and the peer SEPP entity takes place via one or more roaming intermediaries including the roaming intermediary entity.

[0185] As shown m block 802 of FIG. 8, the apparatus embodied by the SEPP entity 420 / 426 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for receiving, from a roaming intermediary entity, a message including at least one of a first instruction or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, the message includes an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message. In one or more aspects, the message includes a N32-f message forwarding error response message, and the message is received subsequent to the SEPP entity providing, to the roaming intermediary entity, an N32-f message forwarding request. In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection and the second instruction for the SEPP entity to reestablish the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, the message includes the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not include the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before reestablishing the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, the message further includes an indication of an alternative roaming intermediary entity for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, the N32-f connection includes an HTTP connection established between the SEPP entity and the roaming intermediary entity, wherein the N32-f connection enables exchange of messages between the PLMN or the SNPN and the peer PLMN or the peer SNPN. In one or more aspects, the N32-f context includes a context established at the SEPP entity and the peer SEPP entity, wherein the N32-f context stores security and protection policies agreed between the SEPP entity and the peer SEPP entity for protecting communication over the N32-f connection.

[0186] As shown in block 804 of FIG. 8, the apparatus embodied by the SEPP entity 420 / 426 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for, based on the message including the first instruction, terminating the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, when the message comprises an instruction that directs the SEPP entity to terminate the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN).

[0187] As shown in block 806 of FIG. 8, the apparatus embodied by the SEPP entity 420 / 426 includes means, such as the processing circuitry 122, the communication interface 126, or the like, for, based on the message including the second instruction, re-establishing the at least one of the N32-f context and / or the N32-f connection. In one or more aspects, when the message comprises an instruction that directs the SEPP entity to re-establish the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN), and then initiates establishment of a new N32-f context towards the peer SEPP entity of the peer Public Land Mobile Network (PLMN) or the peer Standalone Private Network (SNPN).

[0188] FIGS. 7-8 illustrate flowcharts depicting methods according to an example aspect of the present disclosure. It will be understood that each block of the flowcharts and combination of blocks in the flowcharts may be implemented by various means, such as hardware, firmware, processor, circuitry, and / or other communication devices associated with execution of software including one or more computer program instructions. For example, one or more of the procedures described above may be embodied by computer program instructions. In this regard, the computer program instructions which embody the procedures described above may be stored by a memory device 240 of an apparatus employing an aspect and executed by a processor 220. As will be appreciated, any such computer program instructions may be loaded into a computer or other programmable apparatus (for example, hardware) to produce a machine, such that the resulting computer or other programmable apparatus implements the functions specified in the flowchart blocks. These computer program instructions may also be stored in a computer-readable memory that may direct a computer or other programmable apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture the execution of which implements the function specified in the flowchart blocks. The computer program instructions may also be loaded into a computer or other programmable apparatus to cause a series of operations to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide operations for implementing the functions specified in the flowchart blocks.

[0189] Accordingly, blocks of the flowcharts support combinations of means for performing the specified functions and combinations of operations for performing the specified functions for performing the specified functions. It will also be understood that one or more blocks of the flowcharts, and combinations of blocks in the flowcharts, may be implemented by special purpose hardware-based computer systems which perform the specified functions, or combinations of special purpose hardware and computer instructions. 5

[0190] Many modifications and other aspects set forth herein will come to mind to one skilled in the art to which this disclosure pertains having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the disclosure is not to be limited to the specific aspects disclosed and that modifications and other aspects are intended to be included within the scope of the appended claims. 10

[0191] Moreover, although the foregoing descriptions and the associated drawings describe example aspects in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative aspects without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described 15 above are also contemplated as may be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

1. A roaming intermediary entity, comprising:means for:determining whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or reestablished;based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generating a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection; and / orbased on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generating a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection;generating a message comprising at least one of the first instruction and / or the second instruction; andsending the message to the SEPP entity.

2. The roaming intermediary entity of claim 1, wherein the message comprises an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

3. The roaming intermediary entity of claim 1, wherein the determining whether at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message comprises an N32-f message forwarding error response message.

4. The roaming intermediary entity of any one of claims 1-3, wherein the message comprises the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and the second instruction for the SEPP entity to reestablish the at least one of the N32-f context and / or the N32-f connection.

5. The roaming intermediary entity of any one of claims 1, wherein the message comprises the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not comprise the second instruction for the SEPP entity to re-establish the at least one N32-f context and / or the N32-f connection.

6. The roaming intermediary entity of any one of claims 1-3, wherein the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

7. The roaming intermediary entity of claim 6, wherein, based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, the message that is generated further comprises an indication of an alternative roaming intermediary for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

8. The roaming intermediary entity of any one of claims 1-7, wherein the determining whether the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is based on at least one of information indicative of network maintenance at the network comprising the roaming intermediary entity;information indicative of insufficient resources at the roaming intermediary entity; information indicative of a business determination;information indicative of a change of contractual agreements between the roaming intermediary entity and another roaming intermediary entity, the SEPP entity, and / or another SEPP entity;information indicating that the determination that a N32-f connection is inactive; information indicative a switch to the roaming intermediary entity; and / or information indicative of insufficient connectivity with the another roaming intermediary entity, the SEPP entity, and / or the another SEPP entity.

9. The roaming intermediary of any one of claims 1 -8, wherein the roaming intermediary entity comprises an entity that provides roaming related services and wherein the entity that provides roaming related services comprises a Roaming Hub or an internet protocol (IP) exchange service (IPX) provider entity deployed between two Public Land Mobile Networks (PLMNs), or deployed between a PLMN and a Standalone Private Network (SNPN), or deployed between two SNPNs.

10. A security edge protection proxy (SEPP) entity, comprising:means for:receiving, from a roaming intermediary entity, a message comprising at least one of a first instruction and / or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection; and at least one of:based on the message comprising the first instruction, terminating the at least one of the N32-f context and / or the N32-f connection; orbased on the message comprising the second instruction, re-establishing the at least one of the N32-f context and / or the N32-f connection.

11. The SEPP entity of claim 10, wherein the message comprises an N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

12. The SEPP entity of claim 10, wherein the message comprises a N32-f message forwarding error response message, and wherein the message is received subsequent to the SEPP entity providing, to the roaming intermediary entity, an N32-f message forwarding request.

13. The SEPP entity of any one of claims 10-12, wherein the message comprises thefirst instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection and the second instruction for the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection.

14. The SEPP entity of any one of claims 10-12, wherein the message comprises the first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection, and does not comprise the second instruction for the SEPP entity to reestablish the at least one of the N32-f context and / or the N32-f connection.

15. The SEPP entity of any one of claims 10-12, wherein the second instruction further directs the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection before re-establishing the at least one of the N32-f context and / or the N32-f connection.

16. The SEPP entity of claim 15, wherein the message further comprises an indication of an alternative roaming intermediary entity for the SEPP entity to use to re-establish the at least one of the N32-f context and / or the N32-f connection.

17. The SEPP entity according to any one of claims 10-16, wherein when the message comprises an instruction that directs the SEPP entity to terminate the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN).

18. The SEPP entity according to any one of claims 10-16, wherein when the message comprises an instruction that directs the SEPP entity to re-establish the N32-f context, the SEPP entity initiates an N32-f context termination procedure towards a peer SEPP entity of a peer Public Land Mobile Network (PLMN) or a peer Standalone Private Network (SNPN), and then initiates establishment of a new N32-f context towards the peer SEPP entity of the peer Public Land Mobile Network (PLMN) or the peer Standalone Private Network (SNPN).

19. The SEPP entity of any claims 10 to 18, wherein the SEPP entity is deployed by one PLMN or one SNPN to support and protect the communication with the peer SEPP entity deployed by the peer PLMN or the peer SNPN, and wherein the communication between the SEPP entity and the peer SEPP entity takes place via one or more roaming intermediaries comprising the roaming intermediary entity.

20. The N32-f connection of any one of claims 10-19, wherein the N32-f connection comprises an HTTP connection established between the SEPP entity and the roaming intermediary entity, wherein the N32-f connection enables exchange of messages between the PLMN or the SNPN and the peer PLMN or the peer SNPN.

21. The N32-f context of any one of claims 10-20, wherein the N32-f context comprises a context established at the SEPP entity and the peer SEPP entity, wherein the N32-f context stores security and protection policies agreed between the SEPP entity and the peer SEPP entity for protecting communication over the N32-f connection.

22. A computer-implemented method, comprising performing by a roaming intermediary entity:determining whether at least one of an N32-f context and / or an N32-f connection involving a security edge protection proxy (SEPP) entity should be terminated and / or reestablished;based on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated, generating a first instruction directing the SEPP entity to terminate the at least one of the N32-f context and / or the N32-f connection; and / orbased on determining that the at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be re-established, generating a second instruction directing the SEPP entity to re-establish the least one of the N32-f context and / or the N32-f connection;generating a message comprising at least one of the first instruction and / or the second instruction; andsending the message to the SEPP entity.

23. The computer-implemented method of claim 22, wherein the message comprisesan N32-f error reporting request, and wherein the N32-f error reporting request is encapsulated in an N32-f message forwarding request message.

24. The computer-implemented method of claim 22, wherein the determining whether at least one of the N32-f context and / or the N32-f connection involving the SEPP entity should be terminated and / or re-established is in response to receiving, from the SEPP entity, an N32-f message forwarding request and wherein the message comprises an N32-f message forwarding 5 error response message.

25. A computer-implemented method, comprising performing by a security edgeprotection proxy (SEPP) entity:receiving, from a roaming intermediary entity, a message comprising at least one of a first 10 instruction and / or a second instruction, wherein the first instruction directs the SEPP entity to terminate at least one of an N32-f context and / or an N32-f connection, and wherein the second instruction directs the SEPP entity to re-establish the at least one of the N32-f context and / or the N32-f connection; and at least one ofbased on the message comprising the first instruction, terminating the at least one 15 of the N32-f context and / or the N32-f connection; orbased on the message comprising the second instruction, re-establishing the at least one of the N32-f context and / or the N32-f connection.

Citation Information

Patent Citations

  • Termination of connections over a forwarding interface between networks

    US20220248229A1