Method, apparatus and computer program
The apparatus and method for session management in communication systems address the lack of end-to-end security for DNS messages by managing address lists and security mechanisms, ensuring secure and efficient transmission in edge computing environments.
Patent Information
- Application Number
- GB2024004906
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-05
- Publication Date
- 2025-10-15
AI Technical Summary
Existing communication systems lack effective mechanisms to ensure end-to-end security for Domain Name System (DNS) messages, which are crucial for secure communication sessions, particularly in edge computing environments.
An apparatus and method for a session management function that determines the application of an end-to-end security mechanism on DNS messages, providing instructions to transmit queries and responses based on security notifications, and managing address lists to ensure secure communication.
Ensures secure and efficient transmission of DNS messages by verifying and managing address lists, enhancing security and reliability in edge computing environments.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
FIELD [1] The present application relates to apparatus, method(s) and computer program(s) for providing notifications indicating whether an end-to-end security mechanism is applied on domain name system (DNS) messages associated with a DNS query. BACKGROUND [2] A communication system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications session. A communication system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet. [3] The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. One example of a communications system is UTRAN (Universal Mobile Telecommunications Service terrestrial radio access network (e.g., 3G radio)). Other examples of communication systems are the longterm evolution (LTE) of the Universal Mobile Telecommunications System (UMTS) radio-access technology and so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP). SUMMARY [4] According to a first aspect, there is provided an apparatus for a session management function, the apparatus comprising means for performing: obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query; in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing: providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service; obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response; determining whether the ordered list of addresses comprises at least two addresses; based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / or based on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of: causing the ordered list of addresses to be provided to the EASDF; and transmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; or determining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; and transmitting, to the EASDF, a fourth instruction to perform: transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query. [5] According to a second aspect, there is provided a method for an apparatus for a session management function, the method comprising: obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query; in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing: providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service; obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response; determining whether the ordered list of addresses comprises at least two addresses; based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / or based on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of: causing the ordered list of addresses to be provided to the EASDF; and transmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; or determining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; and transmitting, to the EASDF, a fourth instruction to perform: transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query. [6] According to a third aspect, there is provided an apparatus for a session management function, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query; in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing: providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service; obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response; determining whether the ordered list of addresses comprises at least two addresses; based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / or based on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of: causing the ordered list of addresses to be provided to the EASDF; and transmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; or determining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; and transmitting, to the EASDF, a fourth instruction to perform: transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query. [7] According to a fourth aspect, there is provided an apparatus for a session management function, the apparatus comprising respective circuitry for performing: obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query; in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing: providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service; obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response; determining whether the ordered list of addresses comprises at least two addresses; based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / or based on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of: causing the ordered list of addresses to be provided to the EASDF; and [8] transmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; or determining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; and transmitting, to the EASDF, a fourth instruction to perform: transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query. [9] The following may apply to any (e.g., one or more, including all) of the above first to fourth aspects.
[10] The apparatus may further be caused to perform, in response to the determination based on the third notification that the end-to-end security mechanism is not applied on the DNS messages associated with the first DNS response: performing at least one of: causing a reordering of the ordered list of addresses to form a reordered list of addresses, causing the removal of at least one address from the ordered list of addresses to form at least one reduced address list, or determining to keep the ordered list of addresses unchanged; causing the reordered list of addresses, the at least one reduced address list, and / or the ordered list of addresses to be provided to the EASDF; and transmitting, to the EASDF, a fifth instruction to perform: transmitting, to the user equipment transmitting the first DNS query, a third DNS response that comprises the provided reordered list of addresses, the at least one reduced address, or the ordered list of addresses.
[11] The apparatus may further be caused to perform, in response to the determination based on the second notification that the end-to-end security mechanism is not applied on the DNS messages associated with the first DNS response, performing: said providing, to the EASDF, at least one of the indication of packet data unit session Anchor user plane function, PSA UPF, address, the indication of a location of a user equipment transmitting the first DNS query, the predicted address of the edge computing service, the predicted subnet of the edge computing service, or the predicted subnet of the edge computing service; said providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, the predicted subnet of the edge computing service, or the predicted subnet of the edge computing service; said obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; and transmitting, to the EASDF, a sixth instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query.
[12] Each address in the ordered list of addresses may indicate a respective edge application server.
[13] The apparatus may further be caused to perform: providing, to the EASDF, a seventh instruction to report to the apparatus whether the end-to-end security mechanism is applied on DNS messages associated with a DNS query.
[14] The apparatus may further be caused to perform, receiving, from a network entity, the predicted address of the edge computing service or the predicted subnet of the edge computing service.
[15] The network entity may comprise at least one of a NetWork Data Analytics Function or Application Data Analytics Enabler Server.
[16] According to a fifth aspect, there is provided an apparatus for an edge application server discovery function, EASDF, the apparatus comprising means for performing: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a first address determined from the ordered list of addresses; receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; and transmitting, based on the second instruction, the third DNS query to the ADNS server.
[17] According to a sixth aspect, there is provided a method for an apparatus for an edge application server discovery function, EASDF, the method comprising: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a first address determined from the ordered list of addresses; receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; and transmitting, based on the second instruction, the third DNS query to the ADNS server.
[18] According to a seventh aspect, there is provided an apparatus for an edge application server discovery function, EASDF, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a first address determined from the ordered list of addresses; receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; and transmitting, based on the second instruction, the third DNS query to the ADNS server.
[19] According to an eighth aspect, there is provided an apparatus for an edge application server discovery function, EASDF, the apparatus comprising respective circuitry for performing: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a first address determined from the ordered list of addresses; receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; and transmitting, based on the second instruction, the third DNS query to the ADNS server.
[20] According to a ninth aspect, there is provided an apparatus for an edge application server discovery function, EASDF, the apparatus comprising means for performing: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; and receiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.
[21] According to a tenth aspect, there is provided a method for an apparatus for an edge application server discovery function, EASDF, the method comprising: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; and receiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.
[22] According to an eleventh aspect, there is provided an apparatus for an edge application server discovery function, EASDF, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; and receiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.
[23] According to a twelfth aspect, there is provided an apparatus for an edge application server discovery function, EASDF, the apparatus comprising respective circuitry for for performing: providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query; receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service; receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service; transmitting, based on the first instruction, the second DNS query to the ADNS; receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification; receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; and receiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.
[24] The following may apply in respect of any (e.g., one or more, including all) of the above fifth to twelfth aspects.
[25] Each address in the ordered list of addresses may indicate a respective edge application server.
[26] The apparatus may further be caused to perform: receiving, from the SMF, a third instruction to report whether the end-to-end security mechanism is applied on DNS messages associated with a DNS query.
[27] The apparatus may further be caused to perform: establishing an association with an analytics function; and providing, to the analytics function, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended DNS Client Subnet, a timestamp, or an EAS address.
[28] According to a thirteenth aspect, there is provided an apparatus for an analytics function, comprising means for performing: establishing an association with or a subscription to an edge application server discovery function, EASDF; obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; and providing a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.
[29] According to a fourteenth aspect, there is provided a method for an apparatus for an analytics function, the method comprising: establishing an association with or a subscription to an edge application server discovery function, EASDF; obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; and providing a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.
[30] According to a fifteenth aspect, there is provided an apparatus for an analytics function, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: establishing an association with or a subscription to an edge application server discovery function, EASDF; obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; and providing a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.
[31] According to a sixteenth aspect, there is provided an apparatus for an analytics function, comprising respective circuitry for performing: establishing an association with or a subscription to an edge application server discovery function, EASDF; obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; and providing a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.
[32] The following may apply in respect of any (e.g., one or more, including all), of the above thirteenth to sixteenth aspects.
[33] The predicted address of the edge computing service or the predicted subnet of the edge computing service may be determined based on Edge Application Server popularity or on Edge Application Server load, or on both.
[34] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.
[35] In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above. DESCRIPTION OF FIGURES
[36] Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which:
[37] Figure 1 shows a representation of a network system according to some example embodiments;
[38] Figure 2 shows a representation of a control apparatus according to some example embodiments;
[39] Figure 3 shows a representation of an apparatus according to some example embodiments;
[40] Figures 4 and 5 illustrates example network features;
[41] Figures 6 to 8 illustrate example signalling that may be performed by apparatus described herein; and
[42] Figures 9 to 11 illustrate operations that may be performed by apparatus performed herein. DETAILED DESCRIPTION
[43] The following relates to at least one method for edge computing (EC).
[44] Edge computing is a distributed computing model that brings computation and data storage closer to the sources of data, so that a client requesting a service (e.g., processing) is closer to the producer that is performing the service. This is meant to make applications faster.
[45] EC was introduced into 5G networks for a plurality of different reasons. For example, moving cloud resources closer to a user may reduce end-to-end (E2E) latency for receiving a service, which may better support time-sensitive applications. Further, the use of an edge computing architecture may enable bandwidth pressure on the mobile backhaul to be relieved, which may be useful in scenarios in which there are a high density of high-bandwidth-demanding devices, such as in dense urban areas. Edge computing is further seen as advantageous as it may enhance the privacy of data being processed, as there is a smaller likelihood of it being intercepted.
[46] 3GPP’s current integration of edge computing methods and apparatus with entities in the 5G architecture is reflected in the 3GPP specification 3GPP TS 23.548. In some embodiments, the 3GPP specification 3GPP TS 23.548 may refer to 3GPP TS 23.548 V18.4.0 (2013-12).
[47] Figure 1 provides an example overview of the current edge computing architecture as it relates to 5G. It is understood that this is merely an example, and that other architecture configurations may exist for edge computing devices, particularly as 3GPP moves to 6G and beyond. Figure 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented.
[48] Figure 1 illustrates a user equipment (UE) 101 that communicates with a 5G architecture 102 that is connected to an edge computing architecture and / or an edge hosting environment architecture 103. The terms “edge computing” and “edge hosting environment” will be used synonymously in the following, as it is understood that the presently described techniques and methods can apply in respect of either (and / or both) of such architectures. It is also understood in the following that although a UE is described as being a client apparatus, the functionality of a client apparatus may be performed by any entity, including a network function of the 5G network.
[49] The 5G architecture 102 is illustrated as comprising a radio network access entity 111 (also referred to herein as a network access node or network device) and a plurality of network functions, such as a Network Data Analytics Function (NWDAF) 112, a session management function (SMF) 113, a policy control function (PCF) 114, a network exposure function (NEF) 115, a protocol data unit session anchor user plane function (PSA UPF) 116, and an edge application server discovery function (EASDF) 117.
[50] Each of these network functions may have a plurality of different functions. Some of these functions are discussed below.
[51] The NWDAF 112 is a network function that provides network analytics information to other network functions and application functions upon request. The network analytics information may provide at least one value corresponding to at least one metric that can be used for determining a state of a communication network. The receiving entity may use the received network analytics information to make at least one decision about communicating within the network.
[52] The SMF 113 may be configured to determine session information for a user equipment based on policy received from the PCF 114, and configure this session information at other entities (e.g., at the PSA UPF 116 and / or the EASDF 117). The session information may be used for managing sessions.
[53] The network exposure function 115 may act as a type of interworking function between a 5G core network and an application function (AF) of another data network. In the present example, the NEF 115 is illustrated as interfacing with an application function 121 located in the edge computing architecture 103.
[54] The PSA UPF 116 may be configured to handle user plane traffic transmitted between the user equipment 101 and a data network via the 5G network 102. With respect to the PSA UPF’s functionality for edge computing purposes, the PSA UPF 116 is illustrated as providing an interface (e.g., an N6 interface) to a data network in which edge applications servers are available (such as an interface to the edge computing architecture 103. It is possible for the UE to steer user traffic flows to specific edge application server (EAS) internet protocol (IP) addresses via specific PSA UPFs.
[55] The EASDF 117 may be configured to discover or assist in the discovery of edge application servers. The Edge Application Server Discovery Function (EASDF) acts as a Domain Name System (DNS) resolver to the UE 101 and can augment the DNS queries with UE location-related information by inserting, for instance, an Extended DNS (EDNS) Client Subnet (ECS) information as instructed by the SMF. This ECS information is also referred to as an “ECS option”. The ECS option may comprise an indication of a topological location of a UE by comprising a precise address of the UE (e.g., an exact IP address of the UE), a less precise address of the UE (e.g., a prefix or subnetwork part of the exact IP address of the UE), an address (or part thereof) of a network access node (e.g., gNB) to which the UE is connected or a network node which can serve UE traffic to a data network (e.g., a PSA UPF).
[56] In an embodiment, the ECS is an option of a DNS query message. The EASDF inserts a subnet to indicate a UE location to the ADNS.
[57] The UE may also be referred to as a “user device”, a “terminal”, and / or a “terminal device”. The network access node and the UE can communicate with each other. The network access node may serve a coverage area, called a cell. The UE may have access to a communication network via the cell. In some example embodiments, both the UE and the network access node may be configured to implement a beamforming technique and communicate with each other via a plurality of beams.
[58] The term “terminal device” refers to any end device that may be capable of wireless communication. Byway of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a mobile device, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), a machine-type communications (MTC) device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user device”, “user equipment” and “UE” may be used interchangeably.
[59] As used herein, the term “network device" is used interchangeably with “network access node”, and refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or nonground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[60] In some example embodiments, a link from the network access node to the UE is referred to as a downlink (DL), while a link from the UE to the network access node is referred to as an uplink (UL). Links are also referred to herein as “channels”. In DL, the network access node is a transmitting device (or a transmitter), and the UE is a receiving device (or a receiver). In UL, the UE is a transmitting device (or a transmitter), and the network access node is a receiving device (or a receiver). A link between the UE and another user device (not shown) is referred to as a sidelink (SL). In SL, one of the user devices is a transmitting device (or a transmitter), and the other of the user devices is a receiving device (or a receiver).
[61] Communications between the UE and the network access node may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols of the first generation (1G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[62] The EC control plane is represented in 3GPP by an Application Function (AF) and the EC data plane (also called the EC user plane) is represented in 3GPP by an Edge Application Server (EAS).
[63] The edge computing architecture 103 may comprise an application function 121 (e.g.. an application function having interface(s) with the NEF 115), at least one edge application server 122 (e.g., an edge application server having interface(s) with the PSA UPF 116), and an authoritative domain name system server (ADNS) 123.
[64] The Authoritative DNS Server (ADNS) (which is also referred to as an Authoritative Name Server (ANS)) belongs to the EC / EHE and has been configured with the list of candidate EAS IP addresses for a fully qualified domain name (FQDN).
[65] The ADNS 123 may have an interface with the EASDF 117 and be queried by the EASDF 117 for names of candidate edge application servers for providing at least one service to the UE 101. The ADNS may be configured with a list of candidate EAS IP addresses for a Fully Qualified Domain Name (FQDN). The ADNS may also be able to access information regarding the load of the EAS instances present in the edge computing architecture 103 for the purpose of selecting at least one candidate EAS to be provided to the EASDF 117 in response to a discovery request received from the EASDF 117.
[66] A lot of mobile EC applications (e.g., augmented reality (AR), virtual reality (VR), etc.) comprise off-loading a processing-intensive task onto an EAS or to the Edge Computing in general, in order to reduce the User Equipment (UE) processing cost and / or to increase the UE battery autonomy.
[67] For example, in the case of wireless mobile VR, an end-to-end (E2E) latency comprises: sensor detection and action capture; computing process, rendering and encoding; framing and streaming; network transport; terminal decoding; and screen refresh. The latency partitioning for this application can be grouped to the latency causing by the UE, the latency from the 5G network, and the latency from the EC network. Computing process latency and communication latency may be the latency bottlenecks in VR methods. As these applications do not always need longterm storage of their transactions, at least part of their computation tasks may be offloaded to external elements with processing capabilities such as ECs, in-network, Base Station, etc.
[68] Figure 2 illustrates an example of a control apparatus 200 for causing a network device (such as the network device 111 and / or any of the network functions described in Figure 1) to perform its operations. The control apparatus may comprise at least one random access memory (RAM) 211a, at least on read only memory (ROM) 211b, at least one processor 212, 213 and an input / output interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211b. The at least one processor 212, 213 may be configured to execute an appropriate software code 215. The software code 215 may for example allow to perform one or more steps to perform one or more of the present aspects. The software code 215 may be stored in the ROM 211 b. The control apparatus 200 may be interconnected with another control apparatus 200 controlling another function of the network device. In some embodiments, each function of the network device comprises a control apparatus 200. In some exemplary embodiments, the apparatus 200 may be implemented at the network device 111 or may be the network device 111.
[69] Figure 3 illustrates an example of a terminal 300, such as the user device 101, illustrated on Figure 1. The terminal 300 may be provided by any device capable of sending and receiving radio signals, such as the user device described herein. The terminal 300 may provide, for example, communication of data for carrying communications. The communications may be one or more of voice, electronic mail (email), text message, multimedia, data, machine data and so on.
[70] The terminal 300 may receive signals over an air or radio interface 307 via appropriate apparatus for receiving and may transmit signals via appropriate apparatus for transmitting radio signals. In Figure 3 transceiver apparatus is designated schematically by block 306. The transceiver apparatus 306 may be provided for example by means of a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device.
[71] The terminal 300 may be provided with at least one processor 301, at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access systems (such as a network access system provided by the network device described above in relation to Figures 1 and 2) and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one 5 processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more of the present aspects. The software code 308 may be stored in the ROM 302a.
[72] The processor, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by io reference 304. The device may optionally have a user interface such as keypad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the device.
[73] In some exemplary embodiments, the terminal 300 may be an apparatus 15 comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause a user device 101 to perform examples or embodiments described in this document.
[74] In some embodiments, there are at least two options for exchanging information between 5G systems (5GS) and EC systems for performing an EAS 20 discovery procedure using an EASF. The first option is labelled as an EC-centric approach, while the second option is labelled as a 5G-centric approach. These are outlined below.
[75] In the EC-centric approach, the EASDF adds, into a DNS request to be sent to an authoritative DNS server, metrics relating to the 5GS, such as, for example, a 25 5GS latency, a 5GS cost, a 5GS resource availability, a 5GS resource utilisation, and / or a 5GS performance index. This may be sent in addition to the ECS option related to the client and / or a fully qualified domain name queried by the client.
[76] The ADNS may, based on the received information and preconfigured policies configured at the ADNS , select an E2E path that fulfils those policies 30 according to the received metrics, and obtain a unique EAS IP address corresponding to that end-to-end path. The ADNS may respond to the DNS request by providing an indication of the unique EAS IP address. This may be used by the UE for requesting a service from the edge application server identified by the unique EAS IP address.
[77] In the 5G-centric approach, the DNS request is provided to the ADNS without the 5GS metrics mentioned above. However, in the DNS response, the ADNS comprises indications corresponding to, for each EAS IP address indicated in the DNS reply, respective EC metrics, such as, for example, an EC latency, an EC cost, an EC resource availability, an EC resource utilisation, and / or an EC performance index.
[78] The 5GS (e.g., an SMF in the 5GS and / or some other network function in the 5GS) uses the received EC metrics with corresponding 5GS metrics to help an EASDF select an end-to-end path for the UE’s requested EC services. This may be performed based on analogous policies to those described above in relation to EC-centric approach. A unique EAS IP address corresponding to the selected end-to-end path may be provided to the UE client for use by the UE client to request a service from the edge application server identified by the unique EAS IP address.
[79] Both of these options consider E2E latency requirements, which can be calculated using E2E service level agreement parameters.
[80] The E2E service level agreement (SLA) parameters include processing SLA-related factors within the external compute elements (e.g., within the EC). SLA parameters can be related to reliability, cost, latency, etc. This is illustrated below with reference to Figure 4.
[81] Figure 4 illustrates a UE 401, a 5G network 410 that comprises a network access node 411 and a plurality of user plane functions (UPFs) 412, and an edge computing system 420. The edge computing system 420 is illustrated as comprising an internet gateway (IGW) 421, a Top of Rack (ToR) switch or router 422, a hypervisor 423, an operating system 424, and an EAS 425.
[82] As shown in Figure 4, the total E2E network latency is represented by the round trip time for transmitting between the UE 401 and the EAS 425, while the processing latency is represented by the time spent in the EAS 425 to perform the requested computational task. The sum of the total E2E network latency is referred to herein as the E2E application latency. The time in which a signal is in the 5G network 410 is referred to a 5G system latency. The time in which the signal is in the edge computing system 420 is referred to the EC latency. The EC latency comprises the processing patency and an EC network latency that represents a round trip time between entry of the signal into the EC system and arrival of the signal at the EAS 425.
[83] Thus, the E2E application latency includes both an E2E network round-trip delay (e.g., overall data communication delay) and a processing latency (e.g., data processing delay) within the EC.
[84] To guarantee the E2E SLA, an “appropriate" EAS should be discovered and selected for serving a UE. As discussed above, the Edge Application Server Discovery Function (EASDF) in 5G acts as a Domain Name System (DNS) resolver for the UE after receiving the UE DNS queries. Afterwards, the EASDF contacts the ADNS to provide the appropriate EAS. Currently, the method of EAS selection in edge / cloud is introduced with a policy set by a service provider in the ADNS. There are several policies used by existing ADNSs in the edge / cloud based on UE geolocation or historical latency between UE’s access network and the EAS instances.
[85] In the case where the different devices or UEs are to connect to different EASs (e.g., for optimal E2E latency purposes), the same Fully Qualified Domain Name (FQDN) corresponding to a service to be provided to UE may link with different IP addresses. The ADNS may thus return different IP addresses depending on the UE in question and the applied routing policy already set for the special requested edge application. This is illustrated with respect to Figure 5.
[86] Figure 5 illustrates a first UE 501 located in a first city, and a second UE 502 located in a second city (the first and second cities being different).
[87] The first UE 501 issues a first discovery request for an internet protocol (IP) address of “example.com”. In response to this request, an ADNS 503 is configured to identify a first EAS 504 for the first UE’s current location, and to provide an address for this first EAS 504 to the first UE 501 (e.g., address aaa.aaa.aaa.aaa).
[88] The second UE 502 issues a second discovery request for an IP address of “example.com”. In response to this request, the ADNS 503 is configured to identify a second EAS 505 for the second UE’s current location, and to provide an address for this second EAS 505 to the second UE 502 (e.g., address bbb.bbb.bbb.bbb).
[89] When a UE connects to an EC architecture through cellular networks (e.g., 5G), in order to select an EAS having an optimal E2E application latency, the 5GS and the EC should exchange latency information related to an application service, and the appropriate policy for selecting an EAS should be set in the ADNS.
[90] Depending on the entity acting as the decision maker for EAS selection, there may be different limitations to respect.
[91] For example, one of the limitations to be considered in designing the solutions is the impact of features such as DNS Security Extensions (DNSSEC). The DNS resolver is not allowed to modify this list because the modification may cause issues. It is understood that similar issues may arise in respect to other E2E security mechanisms, and that references in the following to DNSSEC may refer to any end-to-end security mechanism used for resolving DNS addresses corresponding to an edge application server.
[92] In more detail, when / if an EASDF selects an EAS instance from an authoritative DNS server response, and as the SMF managing the session and / or the EASDF are aware of the FQDN / domain, the EASDF and / or the SMF can map the FQDN to a set of EAS candidates and their processing and E2E metrics.
[93] However, as the authoritative DNS server includes all valid EAS IP addresses in the response, the EASDF and / or SMF applying the metrics may select a “best” EAS IP address and modify the DNS response to be provided to the client. The EASDF could even remove IP address(es) included by the authoritative DNS server. Note that the IP address removal may not be allowed by DNSSEC specifications.
[94] In other words, the above-mentioned EC-centric and 5GS-centric approaches, which both enable selecting an optimal E2E path and require exchanges of sensitive information between the two domains (5GS and EC), may be inconsistent with the requirements of the DNSSEC specifications. This is because these two approaches utilize an extension in the DNS specification, and more precisely the extension detailed in IETF RFC 6891. As DNS protocol is largely deployed across today’s networks, it is difficult to introduce additional fields with especially new behaviours (normal procedures, error cases, caching, etc). Extending the DNS protocol in a standardized way also requires IETF consensus, which may be hard to reach for an extension for a very specific purpose.
[95] The following aims to address at least one of the above-mentioned issues.
[96] In particular, the following aims to provide a 5GS entity (such as an SMF) information indicating whether DNSSEC is to be used when looking up a specific service. The 5GS entity may use this information when an EAS IP address is being selected.
[97] For example, assuming a UE client issues a DNS query to an EASDF for an edge computing service (e.g., based on a FQDN), when / if an SMF is subsequently provided with a plurality of EAS IP addresses from an EASDF (e.g., as part of selecting an “optimal” EAS IP address based on E2E latency requirements), the SMF may also be provided with an indication of whether DNSSEC is applied in respect of DNS queries corresponding to those EAS IP addresses.
[98] When / lf the DNSSEC is applied, the SMF may determine whether to obtain a reduced plurality of addresses by causing the EASDF to perform a new discovery operation with the ADNS referring to a selected EAS IP address, or whether to instead cause the EASDF to reorder the plurality of EAS IP addresses into an ordered list based on an expected latency between the client / UE and the EASs associated with the different EAS IP addresses. In the former example, the SMF may select the “optimal” EAS IP address, and cause the EASDF to re-perform a discovery operation by inserting the selected “optimal” EAS IP address into an ECS option (described further below).
[99] When / lf the DNSSEC is not applied, the SMF may obtain a reduced plurality of addresses by removing EAS IP addresses from the plurality of addresses received from the EASDF (e.g., to a single EAS IP address), and cause the reduced plurality of addresses to be provided to the UE client. In this case, no security signature need be obtained for the reduced plurality of addresses as the DNSSEC is not applied.
[100] In a more detailed example, an EASDF may report DNSSEC specific information (e.g., DNSSEC indication) to an SMF, based on which the SMF may determine how to instruct the EASDF to react to DNS messages in order to support selecting the best E2E user plane path.
[101] Further, on receipt of the DNSSEC specific information sent by the EASDF, the SMF may cause the EASDF to perform differently based on whether DNSSEC is indicated as being applied or not. For example, when there is no DNSSEC applied, the SMF may select one best EAS IP address because, in this case, the removal of EAS IP address is allowed. Conversely, when DNSSEC is confirmed: the SMF may only either cause the EASDF to reorder obtained EAS IP addresses, or the SMF may instruct the EASDF to additionally query the ADNS with a DNS query based on an EAS IP address selected by the SMF. This may be performed by the SMF using a new ECS option set to the selected EAS IP address. In this latter case, based on this new ECS option, the ADNS determines the selected the EAS IP address and inserts the corresponding DNSSEC signature into a DNS response, which is then sent transparently to UE via the EASDF with the selected EAS IP address.
[102] Also described in the following is an example in which the SMF may additionally use network analytics information provided by a network analytics function to determine whether the SMF may act as an authoritative DNS server instead of the ADNS comprised in the edge computing architecture. For example, the network analytics function may be configured to provide the SMF with indications of load and / or latency associated with respective edge computing servers within the edge computing architecture at different, future, times. This may be used by the SMF to determine whether there is a clear choice for EAS IP address selection (e.g., because the difference in latency and / or load for the edge computing server associated with that EAS IP address is more than and / or equal to a threshold amount relative to the latency and / or load of any other edge computing server of which the SMF is aware. This is described further below in relation to Figure 8.
[103] Figures 6 to 8 illustrate example signalling operations that may be used for achieving the presently described functionality.
[104] For both of the examples of Figures 6 and 7, it is assumed that an SMF has received, from an EASDF, an indication that the EASDF has received a discovery request for an EC from a UE.
[105] Figure 6 illustrates signalling that may be performed between a UE 601, an EASDF 602, an SMF 603, and an ADNS 604.
[106] During 6001, the SMF 603 signals the EASDF 602. This signalling may comprise an instruction to include, in a DNS request, an ECS that comprises an indication of a location of the UE 601.
[107] For example, the ECS may comprise an identifier of the IP subnet for the UE 601 (e.g., that comprises at least part of the address and / or location of the UE 601). The address comprised in the DNS request may be less than the UE’s full IP address to avoid potential privacy issues.
[108] As another example, the ECS may comprise an address of a network access node (e.g., a gNB) to which the UE is connected.
[109] The format (e.g., the semantic, and / or form and contents) of the ECS should be agreed between the 5GS and the EC according to at least one of the abovementioned behavioral parameters.
[110] During 6002, the EASDF 602 signals the ADNS 604. This signalling may comprise an ECS comprising the indication of the location of the UE 601 according to the instructions of 6001.
[111] During 6003, the ADNS 604 selects one or more “appropriate” EC sites based on the received ECS. An appropriate EC site may be considered to be an EC system.
[112] During 6004, the ADNS 604 orders the selected appropriate EC sites into a list that reflects relative priorities of use of the plurality of appropriate EC sites (e.g., such that a most preferred appropriate EC site is located at one end of the list, and a least preferred appropriate EC site is located at the opposite end of the list). The ordering may be performed based on at least one EC metric. The at least one EC metric may comprise, for example, a computing processing unit (CPU) load, a processing delay, or a network delay. Each of these EC sites may comprise one or more EAS.
[113] From 6004, the ADNS 604 may perform 6005a or 6005b.
[114] 6005a is performed when / if (the ADNS 604 determines that) there is a large difference (based on at least one predetermined parameter) between the first EAS and the remainder EASs in the EASs corresponding to the appropriate EC sites. In this example, during 6005a, the ADNS 604 signals a single EAS IP address to the EASDF 602. From 6005a, the method proceeds to 6006.
[115] 6005b is performed when / if (the ADNS 604 determines) that there is not a large difference (based on at least one predetermined parameter) between the first EAS and the remainder EASs in the EASs corresponding to the appropriate EC sites. In this example, during 6005b, the ADNS 604 signals to the EASDF 602 an ordered list of EAS IP addresses with regards to a metric set agreed between the two entities. From 6005b, the method proceeds to 6006.
[116] During 6006, the EASDF 602 signals a DNS response to the SMF 603. This signalling may comprise the address(es) received during at least one of 6005a or 6005b. This signalling may comprise an indication of whether those address(es) use DNSSEC for resolving addresses.
[117] During 6007, the SMF 602 utilizes the SMF’s knowledge of the 5GS topology and knowledge of current and / or predicted future metrics for making a final selection of an E2E path (including the EAS processing delay).
[118] When / if the received indication indicates that DNSSEC is not applicable,, the EASDF sends to the UE a single unique EAS IP address ora subset (e.g., less than all) of the received list of EAS IP addresses.
[119] When the received indication indicates that DNSSEC is applicable, the SMF may determine to instruct the EASDF to reorder the list of EAS addresses according to a predetermined metric (e.g., as described in section 6.3 of IETF RFC 4034), or the SMF may determine to instruct the EASDF to additionally query the ADNS with a DNS query with a new ECS option set to the selected EAS IP address(es). An ECS option is an option in the Extension Mechanisms for DNS that allows a recursive DNS resolver (such as, for example, the EASDF in the present example) to specify the subnetwork for the host or client on whose behalf it is making a DNS query. This is generally intended to help speed up the delivery of data by allowing better use of DNS-based load balancing to select a service address near the client when the client computes.
[120] Although not shown, this may proceed as described in relation to 6001 to 6007, except the ECS sent to the ADNS comprises the selected EAS IP address. Based on this the ADNS selects the EAS IP address and may insert a corresponding security signature, which is then sent transparently to the UE via the EASDF in the DNS response.
[121] In the example of Figure 6, the indication of the location (e.g., the UE IP subnet address) set during 6001 may be relatively wide. For example, a single UE IP subnet address may indicate a region that covers a plurality of N6 interfaces, where an N6 interface is an interface between a user plane function and a data network outside of the 5GS, such as the EC system.
[122] Figure 7 illustrates an option in which a location of a UE is scaled down so that only a single N6 interface is covered by the UE location indicated by the SMF. This may be useful when the 5GS latency budget is expected to be more significant than the EC latency.
[123] Figure 7 illustrates signalling that may be performed between a UE 701, an EASDF 702, an SMF 703, and an ADNS 704.
[124] During 7001, the SMF 703 selects an N6 interface. The selected N6 interface may be selected as being the N6 interface that provides a lowest UE-UPF latency for the UE. When / if the SMF 703 is able to determine an N6 delay, the SMF 703 may (be able to) calculate / acknowledge a value that represents the N6 delay.
[125] During 7002, the SMF 703 signals the EASDF 702. This signalling may comprise an instruction to include, in a DNS request, an ECS that comprises the N6 IP address.
[126] During 7003, the ADNS 704 selects one or more “appropriate” EC sites based on the received ECS. An appropriate EC site may be considered to be an EC system.
[127] During 7004, the ADNS 704 orders the selected appropriate EC sites into a list that reflects relative priorities of use of the plurality of appropriate EC sites (e.g., such that a most preferred appropriate EC site is located at one end of the list, and a least preferred appropriate EC site is located at the opposite end of the list). The ordering may be performed based on at least one EC metric. The at least one EC metric may comprise, for example, a computing processing unit (CPU) load, a processing delay, or a network delay. Each of these EC sites may comprise one or more EAS.
[128] From 7004, the ADNS 704 may perform 7005a or 7005b.
[129] 7005a is performed when / if (the ADNS 704 determines that) there is a large difference (based on at least one predetermined parameter) between the first EAS and the remainder EASs in the EASs corresponding to the appropriate EC sites. In this example, during 7005a, the ADNS 704 signals a single EAS IP address to the EASDF 702. From 7005a, the method proceeds to 7006.
[130] 7005b is performed when / if (the ADNS 704 determines that) there is not a large difference (based on at least one predetermined parameter) between the first EAS and the remainder EASs in the EASs corresponding to the appropriate EC sites. In this example, during 7005b, the ADNS 704 signals to the EASDF 702 an ordered list of EAS IP addresses with regards to a metric set agreed between the two entities. From 7005b, the method proceeds to 7006.
[131] During 7006, the EASDF 702 signals a DNS response to the SMF 703. This signalling may comprise the address(es) received during at least one of 7005a or 7005b. This signalling may comprise an indication of whether those address(es) use DNSSEC for resolving addresses.
[132] During 7007, the SMF 703 utilizes the SMF’s knowledge of the 5GS topology and knowledge of current and / or predicted future metrics for making a final selection of an E2E path (including the EAS processing delay).
[133] When / lf the received indication indicates that DNSSEC is not applicable,, the EASDF sends to the UE a single unique EAS IP address ora subset (e.g., less than all) of the received list of EAS IP addresses.
[134] When / if the received indication indicates that DNSSEC is applicable, the SMF may determine to instruct the EASDF to reorder the list of EAS addresses according to a predetermined metric (e.g., as described in section 6.3 of IETF RFC 4034), or the SMF may determine to instruct the EASDF to additionally query the ADNS with a DNS query with a new ECS option set to the selected EAS IP address. Although not shown, this may proceed as described in relation to 7001 to 7007, except the ECS sent to the ADNS comprises the selected EAS IP address. Based on this the ADNS selects the EAS IP address and may insert a corresponding security signature, which is then sent transparently to the UE via the EASDF in the DNS response.
[135] In the previous examples of Figures 6 and 7, the ordered list of EAS IP addresses is an abstraction that allows the EC to avoid providing the 5GS with detailed sensitive information about the internal operations of the EC system, such as CPU load. Due to this abstraction, the 5GS selection of the E2E path may not be optimal. Worst, the final result of the sequential selection may not be compliant to the E2E SLA. We observe in this case a failure of the sequential selection process.
[136] In order to avoid such failure, the example of Figure 8 illustrates an example in which an analytics function provides the SMF with information about the EC network for use by the SMF in determining whether the SMF may act as an authoritative DNS server by itself, based on historical information, or whether to outsource EAS IP address selection to an ADNS.
[137] For example, the EASDF (via the SMF) could have assistance from the NetWork Data Analytics Function (NWDAF) and / or Application Data Analytics Enabler Server (ADAES) which is deployed in the 5GC to predict, for instance, network function load. Similarly, the NWDAF and / or Application Data Analytics Enabler Server (ADAES) could be used, in the present context, to predict an EC site load with regards to a given FQDN requested (i.e., type of application) and a time instant.
[138] It is to be noted that NWDAF and ADAES can distinct between short time and long time sessions based on the FQDN / EAS ID Endpoint and EAS ID respectively (where “short” and “long” are currently defined in TS 23.558).
[139] The EASDF may provide statistical data to the NWDAF. For instance, the EASDF may provide at least one of: a timestamp, a FQDN, a UE IP subnet address (or some other UE location indication), an indication of whether a selected end-to-end path is compliant or not with the end-to-end (E2E) service level agreement, etc.
[140] Based on this statistical data, the NWDAF and / or Application Data Analytics Enabler Server (ADAES) could provide the SMF / EASDF with recommendation in terms of EC site load with regards to a given FQDN and time instant.
[141] For example, the ECS in the example of Figure 6 comprises a UE IP subnet (e.g. with a 24-bit IPv4 prefix) which points to a 5GC region. This 5GC region corresponds, in turn, to a given EC site (e.g. site 1). Unfortunately, the EC site in question (e.g. site 1) may be usually observed to be overloaded during a given period of the day (e.g. between 20:00 PM and 23:20 PM). For a given time-sensitive application (e.g. example.com), this results in a very excessive processing latency during this period of time. Thus, the sequential selection (during this period of time) may result in the selection of an E2E solution which is not compliant to the E2E applicative latency even though the 5GS network latency is observed to be good.
[142] In such a situation, the NWDAF and / or Application Data Analytics Enabler Server (ADAES) could recommend that the SMF and / or the EASDF extends the UE IP subnet in the DNS request sent to the ADNS (e.g. replacing the previous 24-bit mask by a 20-bit mask) and to broaden the UE location region so that it includes at least one other EC site (e.g. site 2) that is observed (by the NWDAF) to not be in overload state.
[143] Figure 8 illustrates signalling that may be performed between a UE 801, an NWDAF 802, and EASDF 803, an SMF 804, and an ADNS 805. It is understood that although the NWDAF is mentioned here, that any analytics function may be configured to provide the functionality mentioned below in relation to the NWDAF 802. For example, the functionality mentioned below in relation to the NWDAF 802 may be provided by an Application Data Analytics Enabler Server (ADAES) without any loss of generality.
[144] During 8001, the EASDF 803 and NWDAF 802 exchange signalling for creating an association. The association may indicate that the EASDF 803 and the NWDAF 802 are to exchange DNS related parameters (such as, for example, FQDN, ECS options, service area, EAS IP address, time stamps, etc.)
[145] Based on the timestamp for sending the DNS query from the EASDF to the ADNS and the timestamp when receiving the DNS response, the NWDAF may recognize that for that particular service area, ECS option and FQDN certain EAS IP addresses are likely to be used or unused at particular times. Stated differently, in a certain daily / weekly time period, the NWDAF 802 may determine which ECS servers have the best capacity for serving a client UE within that certain time period.
[146] During 8002, the SMF subscribes to the NWDAF 802 to be notified about suggested data network access identifier (DNAI) (or EAS option) and EAS IP pairs based on a predicted load of EASs during specific time periods.
[147] During 8003, the UE 801 sends a DNS query to the EASDF 803. This signalling may be as described in relation to 3GPP TS 23.548.
[148] During 8004, the EASDF 803 signals the SMF 804. This signalling may comprise an indication notifying the SMF that the DNS query has been received. This signalling may comprise an indication notifying the SMF whether DNSSEC is to be applied in respect of that DNS query.
[149] During 8005, the SMF 804 determines from the information comprised in the received signalling whether the SMF 804 is able to act as an authoritative DNS server for this DNS query.
[150] When / lf (the SMF 804 determines that) the SMF 804 is able to act as the authoritative DNS server, the method proceeds to 8006a.
[151] During 8006a, the SMF 804 selects a suggested EAS IP address (or an list of EAS IP addresses) based on the information provided by the NWDAF 802 during 8002. From 8006a, the method proceeds
[152] During 8007a, the SMF 804 signals the EASDF 802. This signalling may instruct the EASDF 802 to provide the suggested EAS IP address (or the list of EAS IP addresses) to the UE client 801 in response to the DNS query. From 8007a, the method proceeds to 8008a.
[153] During 8008a, the EASDF 803 signals the UE 801. This signalling may comprise the suggested EAS IP address (or the list of EAS IP addresses) in response to the DNS query of 8001.
[154] When / lf (the SMF 804 determines that) the SMF 804 is unable to act as the authoritative DNS server, the method proceeds to 8006b.
[155] During 8006b, the SMF 804 determines a predicted ECS option (e.g., the SMF 804 determines an address to be used for the EAS IP address for serving the UE 801). From 8006b, the method proceeds to 8007b.
[156] During 8007b, the SMF 804 instructs the EASDF 803 to send a DNS request to the ADNS 805 for determining a DNS address using the predicted ECS option. From 8007b, the method proceeds to 8008b.
[157] During 8008b, the EASDF 803 sends a DNS request to the ADNS 805. This DNS request may comprise the predicted ECS option. From 8008b, the method proceeds to 8009b.
[158] During 8009b, the ADNS 805 responds to the DNS request of 8008b. This signalling may comprise an indication of a list of EAS IP addresses. The signalling may further comprise an indication of whether DNSSEC is supported or not. From 8009b, the method proceeds to 8010b.
[159] During 8010b, the EASDF 805 reports the provided list of EAS IP addresses to the SMF 803. The SMF may proceed as per 6007 or 7007.
[160] In a slight variance to 8007b, the SMF may instruct the EASDF to continue to send the DNS query with the NWDAF-recommended ECS option even when / if the UE indicated support for DNSSEC. In such a case, the SMF may instruct the EASDF to notify the SMF whether or not the DNS response carries DNSSEC Resource Records (RRs). In case ADNS does not support the DNSSEC, the SMF may select one IP address only or may shorten the list of IP addresses. In case of the DNSSEC supported by the ADNS, the SMF may instruct the EASDF to reorder the RR’s. When the ADNS does not support DNSSEC in the DNS response, the SMF may shorten the list of IP addresses.
[161] Figures 9 to 10 illustrate at least some features that may be performed by apparatus described above in reference to at least one of Figures 6 to 8. It is therefore understood that features described above in relation to these Figures may be used to provide further understanding how at least one of the following features may be implemented in an example. The apparatus of any (e.g., one or more, including all) of Figures 9 to 10 may be implemented using an apparatus according to at least Figure 2. It is further understood in the following that “providing" is used interchangeably with “transmitting”, and “obtaining” is used interchangeably with “receiving”.
[162] Figure 9 illustrates operations that may be performed by an apparatus for a session management function, SMF. As mentioned above, the apparatus of Figure 9 may be as described above in relation to Figure 2.
[163] During 901, the apparatus obtains, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service. The apparatus may further obtain a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query.
[164] During 902, the apparatus may determine, based on the second notification indicating whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query. Stated differently, the apparatus may determine that the end-to-end security mechanism is applied based on a value comprised in the second notification, or the apparatus may determine that the end-to-end security mechanism is not applied based on a different value comprised in the second notification, where only one of the value or the different value may be comprised in the second notification at any one time.
[165] During 903, in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, the apparatus provides, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service.
[166] The PSA UPF address indication may comprise an identification of a user plane function such as an N6 interface identifier and / or a user plane function identifier.
[167] The indication of a iocation of a user equipment transmitting the first DNS query may comprise a precise address for the user equipment, and / or a more abstracted version of the address of the user equipment (e.g. a subdomain address of the precise address of the user equipment).
[168] The “predicted address” may be as described above in relation to the “suggested address” of Figure 8. For example, the predicted address may comprise an address of an edge computing application server address and / or a list of EAS addresses corresponding to a server based on information previously provided to the apparatus by an analytics function. The apparatus may receive, from a network entity, the predicted address of the edge computing service. The network entity may comprise at least one of a NetWork Data Analytics Function or Application Data Analytics Enabler Server. Stated differently, the network entity may comprise an analytics function. The apparatus may further subscribe to receive information related to the predicted address, such as described above in relation to the “suggested address” of Figure 8.
[169] During 904, the apparatus provides, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or a predicted subnet of the edge computing service (e.g., to at least one of the addresses signalled during 903). Stated differently, the EASDF may be instructed to perform a DNS query with an ADNS using address information supplied by the SMF during 903. 903 and 904 may be performed as part of the same transmission. Alternatively, 903 and 904 may be performed as part of separate (e.g., different) transmissions (e.g., transmissions made using different transmission opportunities).
[170] During 905, the apparatus obtains, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query. The apparatus may further receive a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response.
[171] During 906, the apparatus determines, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response. Stated differently, the apparatus may determine that the end-to-end security mechanism is applied based on a value comprised in the second notification, or the apparatus may determine that the end-to-end security mechanism is not applied based on a different value comprised in the second notification, where only one of the value or the different value may be comprised in the second notification at any one time.
[172] During 907, the apparatus may determine whether the ordered list of addresses comprises at least two addresses.
[173] During 908, the apparatus may select and transmit at least one instruction to be provided to the EASDF based on the results of at least one of the determinations of 906 and 907.
[174] For example, when it is determined, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and when it is determined that the ordered list of addresses comprises at least two addresses, the apparatus may: determine one (e.g., a single) address from the ordered list of addresses, and cause the determined address to be provided to the EASDF with a second instruction to perform a new DNS query with the ADNS server. This causing may comprise transmitting, to the EASDF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet (e.g., an ECS option) of the third DNS query as the determined address). The second instruction may further cause (e.g., result in) the EASDF performing, in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query.
[175] As another example, when it is determined, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and when it is determined that the ordered list of addresses comprises at least two addresses, the apparatus may cause the ordered list of addresses to be provided to the EASDF, and transmit, to the EASDF a third instruction to perform transmitting the first DNS response to the user equipment transmitting the first DNS query. Whether the SMF performs these actions or the actions of the previous paragraph may be set based on a local policy configured at the SMF.
[176] As another example, in response to the determination that the ordered list of addresses does not comprise at least two addresses (e.g., in response to the indication that the ordered list of addresses comprises a single address), the SMF may transmit, to the EASDF, a fourth instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query. For this example, it does not matter whether the end-to-end security mechanism is applied or not, as the SMF cannot remove any addresses from the ordered list of addresses or reorder the addresses.
[177] As another example, in response to the determination based on the third notification that the end-to-end security mechanism is not applied on the DNS messages associated with the first DNS response (e.g., and that the ordered list comprises two or more addresses), the apparatus may cause the ordered list of addresses to be reordered to form the reordered plurality of addresses, and / or the apparatus may form at least one reduced address list by removing at least one address from the plurality of addresses. The reordered plurality of addresses and / or the at least one reduced address list may subsequently be provided to the EASDF. The apparatus may further transmit, to the EASDF, a fourth instruction that causes the SMF to perform: transmitting, to the user equipment transmitting the first DNS query, a third DNS response that comprises the reordered plurality of addresses and / or at least one reduced address.
[178] These four examples thus correspond to the cases where: 1) there are multiple addresses in the original DNS response provided to the SMF when the end-to-end security mechanism is applied: In this example, the SMF decides that a new DNS query should be performed to obtain DNS response related to only a subset (e.g., one) of these ordered list of addresses such that the DNS response subsequently provided to the querying UE does not include at least one EAS excluded by the SMF based on latency and / or considerations, or the SMF decides that the current DNS response is sufficient (and instructs the EASDF to return the first DNS response accordingly); 2) there is a single address in the original DNS response (and the end-to-end security mechanism may be indicated as being applied or the end-to-end security mechanism may be indicated as not being applied): In this case, the SMF cannot perform any additional selection among the ordered list of addresses (as there is only one address), and so no additional DNS search need be performed for obtaining a new DNS response. Instead, the EASDF may be instructed to simply provide the first DNS response to the UE in response to the UE’s DNS query. However, it is understood that when the end-to-end security mechanism is applied, the SMF may further instruct the EASDF to obtain a security signature corresponding to that single address when no security signature has previously been provided. When no security signature has previously been provided to the EASDF and the end-to-end security mechanism is applied, the EASDF may obtain this by signalling the ADNS (or any other authorisation server) a request for the security signature, and receiving the security signature in response. The first DNS response may subsequently be provided to the UE with the security signature in response to the UE’s DNS query. Conversely, when a security signature has previously been provided to the EASDF and the end-to-end security mechanism has been applied, the instruction to the EASDF may simply cause the EASDF to provide the first DNS response to the UE with the previously provided security signature (e.g., without performing any further DNS query with the ADNS). Further, when the end-to-end security mechanism is not applied, the SMF may simply instruct the EASDF to provide the first DNS response to the UE without any security signature (e.g., without performing any further DNS query with the ADNS); and 3) there are multiple addresses in the original DNS response provided to the SMF when the end-to-end security mechanism is not applied: in this example, the SMF is authorised to remove and / or reorder addresses itself as the end-to-end security mechanism is not applied. Consequently, the SMF does not need to instruct that a new (e.g., additional) DNS search should be performed. Instead, the SMF may simply be instructed to provide the reordered list of addresses and / or a reduced version of the list of addresses to the UE in response to the UE’s DNS query.
[179] Each address in the ordered list of addresses may indicate a respective edge application server.
[180] The apparatus may provide, to the EASDF, a fifth instruction to report to the apparatus whether the end-to-end security mechanism is applied on DNS messages associated with a DNS query. This may be performed prior to the signalling of 901. This signalling may be performed during 904.
[181] It is understood that the providing, providing, and obtaining features of 903 to 905 may alternatively be performed based on the second notification indicating that the end-to-end security mechanism is not applied on the DNS messages associated with the first DNS response (as opposed to when it is indicated that the end-to-end security mechanism is applied). In this case, instead of proceeding to 906, the apparatus may instead be caused to transmit, to the EASDF, a sixth instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query. This may be performed regardless of whether the third notification is received, and / or regardless of what a received third notification indicates. It is understood that the apparatus may instead perform operation 3) mentioned above when the second notification (and / or the third notification) indicates that that end-to-end security mechanism is not applied on the DNS message. The actual operation of the apparatus may depend on a local policy configured at the apparatus.
[182] It is further understood that as the actions of 903 to 905 are not dependent on what the second notification actually indicates, that these steps may be performed in examples in which the second notification is not received (e.g., these steps may be performed without being based on what the second notification indicates, and / or without being based on the second notification being received).
[183] Figure 10 illustrates operations that may be performed by an apparatus for an EASDF. The apparatus may be as described above in relation to Figure 2. The EASDF may correspond to the EASDF described in relation to Figure 9.
[184] During 1001, the apparatus provides, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query. This may be as described in relation to 901.
[185] During 1002, the apparatus receives, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service. This may be as described in relation to 903.
[186] During 1003, the apparatus receives, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet (e.g., an ECS option) of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service. This may be as described above in relation to 904.
[187] During 1004, the apparatus transmits, based on the first instruction, the second DNS query to the ADNS.
[188] During 1005, the apparatus receives, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response.
[189] During 1006, the apparatus transmits, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification. This may be as described above in relation to 905.
[190] During 1007, the apparatus may receive from the SMF, an instruction that causes the SMF to either perform a new DNS query with the ADNS server to obtain a DNS response for transmission to the user equipment, or that causes the SMF to provide a DNS response to the user equipment without performing a new DNS query with the ADNS. Stated differently, the apparatus may receive from the SMF an instruction that instructs the SMF regarding how to the respond to the UE’s DNS query. The apparatus may subsequently respond to the UE’s DNS query in accordance with the instruction from the SMF. This signalling of 1007 may correspond to at least one of the three examples described above in relation to Figure 9.
[191] For example, the apparatus may receive from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query. This may correspond to example 1) mentioned above in which there were originally multiple addresses comprised in the first DNS response and the end-to-end security mechanism applied. Consequently, based on this instruction, the apparatus may transmit, based on the second instruction, the third DNS query to the ADNS server. For example, the apparatus may transmit a third DNS query to the ADNS server that comprises a single address from the ordered list of addresses and a request for a security signature corresponding to that single address. The address may receive a second DNS response in response to this third DNS query. The second DNS response may comprise the requested security signature and a DNS response corresponding to that single address. The apparatus may provide the second DNS response to the user equipment.
[192] As another example, the apparatus may receive the instruction to simply provide the address of the first DNS response to the user equipment when the first DNS response comprises only a single EAS address. It is understood that the SMF may determine whether or not a security signature should be requested based on whether the end-to-end security mechanism is applied, as described above. Wien a security signature is to be requested, the apparatus may transmit a third DNS query to the ADNS server that comprises the single address from the ordered list of addresses and a request for a security signature corresponding to that single address. The address may receive a second DNS response in response to this third DNS query. The second DNS response may comprise the requested security signature and a DNS response corresponding to that single address. The apparatus may provide the second DNS response to the user equipment. This example corresponds to example 2) discussed above in relation to Figure 9.
[193] As another example, the apparatus may receive a reordered list of the ordered list of addresses and / or a reduced list of the ordered list of addresses from the SMF (as described above). This may correspond to the example 3) discussed above in relation to Figure 9. In this example, the SMF may provide the reduced list and / or reordered list to the user equipment without performing a new DNS query to the ADNS. As the end-to-end security mechanism is not applied in this case, no security signature needs to be requested. Stated differently, in this third example, the apparatus may receive, from the SMF, a reordered plurality of addresses or at least one reduced address, and receive, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses or at least one reduced address.
[194] Each address in the ordered list of addresses may indicate a respective edge application server.
[195] The apparatus may further receive, from the SMF, a third instruction to report whether the end-to-end security mechanism is applied on DNS messages associated with a DNS query. This may be received before the signalling of 1001.
[196] It is further noted that, as described in relation to the example of Figure 8, the EASDF may be configured to provide an analytics function with information that may be used by the analytics function for suggesting EAS addresses (e.g., the “predicted” and / or “suggested” addresses mentioned above) to the SMF for use at different times.
[197] Figure 11 illustrates operations that may be performed by an apparatus for an analytics function. The analytics function of Figure 11 may be as described above in relation to any of Figures 9 to 10.
[198] During 1101, the analytics function may establish an association with, or a subscription to an EASDF function (such as an EASDF described above in relation to Figure 10). This association and / or subscription may cause the EASDF to provide the analytics function with information corresponding to at least one edge computing service.
[199] Consequently, during 1102, the analytics function obtains, from the EASDF, information indicating, for an edge computing service, at least one of: a FQDN (e.g., a FQDN of the edge computing service), a service area covered by the edge computing service, a timestamp such as described above, an Extended domain network system client subnet, or an edge application server address of an edge application server that can provide the edge computing service.
[200] It is understood that multiple edge application server addresses may be provided during 1102 (e.g., corresponding to different edge application servers that can provide the edge computing service). It is understood that the obtaining may be performed periodically, or aperiodic-ally (e.g., in respond to a one-off request from the analytics function, and / or in response to a trigger event being identified by the EASDF, such as a load of an edge application server that can provide the edge computing service reaching a threshold level).
[201] During 1103, the analytics function may provide an SMF (such as the SMF in Figure 9) with a predicted address to use for the edge computing service or a predicted subnet of the edge computing service. It is understood that “predicted” and “estimated” are used interchangeably throughout this application. The predicted address and / or predicted subnet may correspond to (e.g., may identify) one or more edge application servers that can provide the edge computing service.
[202] The analytics function may predict (e.g., estimate) such information based on load of the different edge application servers at different times. For example, the predicted address of the edge computing service or the predicted subnet of the edge computing service may be determined based on Edge Application Server popularity or on Edge Application Server load, or on both.
[203] As an aside, it is further noted that although the above examples indicate examples in which an SMF performs a preselection process (e.g., by indicating at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service), or a predicted subnet of the edge computing service, that this may not be performed in some examples. In such a case, the SMF may simply perform an initial DNS search based on addressing information received in the DNS query received from the UE, and provide the results of this search (in the form of an ordered list) to the SMF as per 1006). Stated differently, 1001 to 1003 and / or 901 to 904 may be omitted in operations performed by some example apparatus.
[204] As a further aside, in some examples, when only a single address is comprised in the ordered list of addresses, instead of providing this single address to the SMF, the EASDF may simply return this single address to the user equipment as a response to the UE’s DNS query (e.g., without informing the SMF). When the SMF is configured in such a way, the EASDF may be configured to only perform examples 1) and 3) mentioned above.
[205] There are a plurality of advantages associated with the above-described techniques.
[206] For example, the presently described methods do not result in any additional extension to the DNS protocol. Further, privacy between the 5GS and EC may be maintained as information exchange between the two networks may be minimized. This has particular relevance when 5GS and EC are part of two different organizations. The use of artificial intelligence (Al) assistance may further avoid and / or reduce sequential selection failures by providing good-enough E2E solutions.
[207] In addition, there is already multi-value routing policy in AWS Route53 ADNS which responds to DNS query with up to 8 values at a randomized weight. Therefore, the DNS system is already ready and adapted to such type of responses. Implementation of this type of policy can be easily adapted to be used as an enabler for the presently described methods.
[208] Although the above examples of Figures 9 to 11 illustrate methods that may be performed and / or features in relation to the example of Figure 8 (and, by extension, in relation to the examples of Figures 6 and 7, which may be at least partly comprised in the example of Figure 8), it is understood that the presently disclosed example may be illustrated through some key features performed by the SMF and EASDF.
[209] For example, the presently described advantages may be achieved by the following steps being performed by the SMF, where the “addresses” mentioned in the following correspond to addresses of edge application servers for providing an edge computing service requested by a client: a) the SMF receives, from an EASDF, an ordered plurality of addresses corresponding to a DNS response to a DNS request issued by a client for the edge computing service (e.g., a UE or some other requesting apparatus) and a notification that indicates whether DNS messages corresponding to the DNS request have an end-to-end DNS security mechanism applied (such as DNSSec). The notification may be received separately from the ordered plurality of addresses (e.g., a different times). The notification may be received at the same time as the ordered plurality of addresses. b) The SMF decides how to instruct the EASDF based on whether the end-to-end security mechanism is indicated as being applied or not. i) For example, when the end-to-end security mechanism is indicated as being applied, the SMF may reorder the ordered plurality of addresses to form a reordered plurality of addresses and / or select a single address from the ordered plurality of addresses, provide the EASDF with the reordered plurality of addresses or provide the EASDF to perform a new DNS query based on the single address (depending on what action is taken). For this first case, the EASDF may provide the client with the reordered plurality of addresses. For this second case, the EASDF may perform a new DNS query (e.g., with the ADNS) based on the single address, and provide the results of the new DNS query to the client. ii) As another example, when the end-to-end security mechanism is not indicated as being applied, the SMF may simply select a single address from the ordered plurality of addresses and provide this single address to the EASDF with either an instruction to provide the single address to the client, or with an instruction to provide the results of a new DNS query (e.g., with the ADNS) based on the single address to the client. For this first case, the EASDF may provide the client with the single address. For this second case, the EASDF may perform a new DNS query (e.g., with the ADNS) based on the single address, and provide the results of the new DNS query to the client.
[210] The selection and reordering performed in any of the above examples of Figures 9 to 11 (and in the preceding example comprising a) and b)) may be performed in a variety of ways. For example, the SMF may perform this based on a knowledge of the 5G topology and / or load requirements of various entities comprised therein so as to select an address for minimizing latency for the edge computing service to be provided. Stated differently, the SMF may perform the reordering and / or selecting based on latency comprised in the network entities in the 5G core through which the client may obtain the edge computing service. As another example, the SMF may perform this based on information indicating latency comprised in the edge computing domain that has been received from an analytics function. As another example, the SMF may perform this based on information indicating latency in both the edge computing domain and based on information indicating latency in the 5G core (e.g., based on a combination of the preceding two examples).
[211] it is further understood that at least one of the additional features of any of Figures 9 to 11 may be performed in relation to these simple features of a) and b).
[212] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.
[213] It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.
[214] It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.
[215] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[216] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[217] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (c) a combination of analog and / or digital hardware circuit(s) with software / firmware and (d) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (e) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[218] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[219] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.
[220] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.
[221] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[222] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.
[223] Embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.
[224] The scope of protection sought for various embodiments of the disclosure is set out by the independent claims. The embodiments and features, if any, described in this specification that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various embodiments of the disclosure.
[225] The foregoing description has provided by way of non-limiting examples a full and informative description of the exemplary embodiment of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings of this disclosure will still fall within the scope of this invention as defined in the appended claims. Indeed, there is a further embodiment comprising a combination of one or more embodiments with any of the other embodiments previously discussed.
Claims
1) An apparatus for a session management function, the apparatus comprising means for performing:obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query;in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing:providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service;providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service;obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response;determining whether the ordered list of addresses comprises at least two addresses;based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / orbased on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of:causing the ordered list of addresses to be provided to theEASDF; andtransmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query;ordetermining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; andtransmitting, to the EASDF, a fourth instruction to perform:transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; andin response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query.2) An apparatus according to claim 1, further comprising means for performing:in response to the determination based on the third notification that the end-to-end security mechanism is not applied on the DNS messages associated with the first DNS response:performing at least one of: causing a reordering of the ordered list of addresses to form a reordered list of addresses, causing the removal of at least one address from the ordered list of addresses to form at least one reduced address list, or determining to keep the ordered list of addresses unchanged;causing the reordered list of addresses, the at least one reduced address list, and / or the ordered list of addresses to be provided to the EASDF; andtransmitting, to the EASDF, a fifth instruction to perform: transmitting, to the user equipment transmitting the first DNS query, a third DNS response that comprises the provided reordered list of addresses, the at least one reduced address, or the ordered list of addresses.3) An apparatus as claimed in any preceding claim, further comprising means for performing:in response to the determination based on the second notification that the end-to-end security mechanism is not applied on the DNS messages associated with the first DNS response, performing:said providing, to the EASDF, at least one of the indication of packet data unit session Anchor user plane function, PSA UPF, address, the indication of a location of a user equipment transmitting the first DNS query, the predicted address of the edge computing service, the predicted subnet of the edge computing service, or the predicted subnet of the edge computing service;said providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predictedaddress of the edge computing service, the predicted subnet of the edge computing service, or the predicted subnet of the edge computing service;said obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response; andtransmitting, to the EASDF, a sixth instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query.4) An apparatus as claimed in any preceding claim, wherein each address in the ordered list of addresses indicates a respective edge application server.5) An apparatus as claimed in any preceding claim, further comprising means for performing: providing, to the EASDF, a seventh instruction to report to the apparatus whether the end-to-end security mechanism is applied on DNS messages associated with a DNS query.6) An apparatus as claimed in any preceding claim, further comprising means for performing:receiving, from a network entity, the predicted address of the edge computing service or the predicted subnet of the edge computing service.7) An apparatus as claimed in claim 6, wherein the network entity comprises at least one of a NetWork Data Analytics Function or Application Data Analytics Enabler Server.8) An apparatus for an edge application server discovery function, EASDF, the apparatus comprising means for performing:providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service;receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service;transmitting, based on the first instruction, the second DNS query to the ADNS;receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification;receiving, from the SMF, a first address determined from the ordered list of addresses;receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; andtransmitting, based on the second instruction, the third DNS query to the ADNS server.9) An apparatus for an edge application server discovery function, EASDF, the apparatus comprising means for performing:providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service;receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service;transmitting, based on the first instruction, the second DNS query to the ADNS;receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification;receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; andreceiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.10) An apparatus as claimed in any of claims 8 to 9, wherein each address in the ordered list of addresses indicates a respective edge application server.11) An apparatus as claimed in any of claims 8 to 10, further comprising means for performing: receiving, from the SMF, a third instruction to report whether the end-to-end security mechanism is applied on DNS messages associated with a DNS query.12) An apparatus as claimed in any of claims 8 to 11, further comprising means for performing:establishing an association with an analytics function; and providing, to the analytics function, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended DNS Client Subnet, a timestamp, or an EAS address.13) An apparatus for an analytics function, comprising means for performing: establishing an association with or a subscription to an edge application server discovery function, EASDF;obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; andproviding a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.14) An apparatus as claimed in claim 13, wherein the predicted address of the edge computing service or the predicted subnet of the edge computing service is determined based on Edge Application Server popularity or on Edge Application Server load, or on both.15) A method for an apparatus for a session management function, the method comprising:obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query;in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing:providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service;providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service;obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response;determining whether the ordered list of addresses comprises at least two addresses;based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / orbased on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of:causing the ordered list of addresses to be provided to theEASDF; andtransmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query;ordetermining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; andtransmitting, to the EASDF, a fourth instruction to perform:transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; andin response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query; and16) A method for an apparatus for an edge application server discovery function, EASDF, the method comprising:providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service;receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service;transmitting, based on the first instruction, the second DNS query to the ADNS;receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification;receiving, from the SMF, a first address determined from the ordered list of addresses;receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature forthe first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; andtransmitting, based on the second instruction, the third DNS query to the ADNS server.17) A method for an apparatus for an edge application server discovery function, EASDF, the method comprising:providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service;receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service;transmitting, based on the first instruction, the second DNS query to the ADNS;receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification;receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; andreceiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.18) A method for an apparatus for an analytics function, the method comprising: establishing an association with or a subscription to an edge application server discovery function, EASDF;obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; andproviding a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.19) A computer program comprising instructions which, when the program is executed by a computer for a session management function, SMF, cause the computer to perform:obtaining, from an edge application server discovery function, EASDF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification that indicates whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;determining, based on the second notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query;in response to the determination, based on the second notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS query, performing:providing, to the EASDF, at least one of an indication of packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNSquery, a predicted address of the edge computing service, or a predicted subnet of the edge computing service;providing, to the EASDF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS by setting an Extended DNS Client Subnet of the second DNS query as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service or the predicted subnet of the edge computing service;obtaining, from the EASDF, an ordered list of addresses corresponding to the edge computing service in a first DNS response of the second DNS query, and a third notification that indicates whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;determining, based on the third notification, whether the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response;determining whether the ordered list of addresses comprises at least two addresses;based on a determination that the ordered list of addresses does not comprise at least two addresses performing: transmitting, to the EASDF, a second instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query; and / orbased on a determination, based on the third notification, that the end-to-end security mechanism is applied on the DNS messages associated with the first DNS response and a determination that the ordered list of addresses comprises at least two addresses, performing at least one of:causing the ordered list of addresses to be provided to theEASDF; andtransmitting, to the EASDF, a third instruction to perform: transmitting the first DNS response to the user equipment transmitting the first DNS query;ordetermining one address from the ordered list of addresses; causing the determined address to be provided to the EASDF; andtransmitting, to the EASDF, a fourth instruction to perform:transmitting, to the ADNS server, a third DNS query that sets an Extended DNS Client Subnet as the determined address; andin response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the determined address, transmitting the second DNS response to a user equipment that transmitted the first DNS query; and20) A computer program comprising instructions which, when the program is executed by a computer for an edge application server discovery function, EASDF cause the computer to perform:providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;receiving, from the SMF, at least one of: an indication of a packet data unit session Anchor user plane function, PSA UPF, address, an indication of a location of a user equipment transmitting the first DNS query, an indication of a predicted address of the edge computing service, or a predicted subnet of the edge computing service;receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service;transmitting, based on the first instruction, the second DNS query to the ADNS;receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification;receiving, from the SMF, a first address determined from the ordered list of addresses;receiving, from the SMF, a second instruction to perform: transmitting, to the ADNS server, a third DNS query having an Extended DNS Client Subnet set as the first address; and in response to receiving, from the ADNS, a second DNS response of the third DNS query and a security signature for the first address, transmitting the second DNS response to the user equipment transmitting the first DNS query; andtransmitting, based on the second instruction, the third DNS query to the ADNS server.21) A computer program comprising instructions which, when the program is executed by a computer for an edge application server discovery function, EASDF cause the computer to perform:providing, to a session management function, SMF, a first notification of a first domain name system, DNS, query for an edge computing service and a second notification of whether an end-to-end security mechanism is applied on DNS messages associated with the first DNS query;receiving, from the SMF, an indication of at least one of: a packet data unit session Anchor user plane function, PSA UPF, address or an indication of a location of a user equipment transmitting the first DNS query, a predicted address of the edge computing service, or a predicted subnet of the edge computing service;receiving, from the SMF, a first instruction to transmit a second DNS query to an Authoritative DNS Server, ADNS, wherein an Extended DNS Client Subnet of the second DNS query is set as the at least one of: the PSA UPF address, the indication of the location of the user equipment, the predicted address of the edge computing service, or the predicted subnet of the edge computing service;transmitting, based on the first instruction, the second DNS query to the ADNS;receiving, from the ADNS, a first DNS response to the second DNS query, wherein the first DNS response comprises an ordered list of addresses corresponding to the edge computing service and a third notification of whether the end-to-end security mechanism is applied on DNS messages associated with the first DNS response;transmitting, to the SMF, the ordered list of addresses corresponding to the edge computing service and the third notification;receiving, from the SMF, a reordered plurality of addresses or at least one reduced address; andreceiving, from the SMF, a second instruction to perform: transmitting, to the user equipment, a third DNS response comprising an indication of at least one of the reordered plurality of addresses, or at least one reduced address.22) A computer program comprising instructions which, when the program is executed by a computer for an analytics function cause the computer to perform:establishing an association with or a subscription to an edge application server discovery function, EASDF;obtaining, from the EASDF, information indicating, for an edge computing service, at least one of: a Fully Qualified Domain Name, Service Area, an Extended domain network system Client Subnet, a timestamp, or an edge application server address; andproviding a session management function with a predicted address of the edge computing service or a predicted subnet of the edge computing service.
Citation Information
Patent Citations
Method and communication apparatus for secure communication
EP4376458A1
Method and communication apparatus for secure communication
WO2023016395A1