Method for obtaining and using an identifier for a user device hosting the client in an edge computing client

The method allows the EEC to obtain and use a UE ID for authentication and authorization in 5G networks, addressing the lack of clarity in UE ID acquisition and enhancing security in Edge Computing applications.

JP2025514598APending Publication Date: 2025-05-09TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024553703
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-16
Filing Date
2023-05-12
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The challenge in 5G networks is that the Edge Computing Service (ECS) and Edge Enabler Server (EES) authentication in Edge Computing (EC) lacks clarity on how the Edge Execution Client (EEC) obtains the User Equipment Identifier (UE ID), preventing the EEC from receiving necessary services.

Method used

A method for the EEC to receive a UE ID during authentication, either in an access token or a service provisioning response, from a first server, enabling the EEC to authenticate and authorize with a second server using the UE ID, which can be obtained through AKMA, GBA, or IP address to GPSI translation.

Benefits of technology

This method provides a clear and unambiguous way for the EEC to obtain and use the UE ID for authentication and authorization, enhancing security and enabling secure EC applications over 3GPP networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025514598000001_ABST
    Figure 2025514598000001_ABST
Patent Text Reader

Abstract

An embodiment includes a method for a client (e.g., EEC) of an edge data network. Such a method includes receiving, from a first server (e.g., ECS) of the edge data network, an identifier of a user equipment hosting the client (UE ID) during or after authentication and / or authorization of the client by the first server. Such a method includes transmitting the UE ID to a second server (e.g., EES) of the edge data network during authentication and / or authorization of the client by the second server. Other embodiments include complementary methods for the first and second servers, and complementary methods for a client (or a UE hosting the same) and server configured to perform such methods.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present application relates generally to the field of wireless communication networks, and more specifically to "edge computing" technologies that facilitate secure execution environments closer to users and / or devices rather than in a centralized public network cloud. [Background technology]

[0002] Currently, the 3rd Generation Partnership Project (3GPP) is standardizing the fifth generation (5G) of cellular systems. 5G is being developed for maximum flexibility to support several substantially different use cases. These include enhanced Mobile Broadband (eMBB), Machine Type Communications (MTC), Ultra-Reliable Low Latency Communications (URLLC), Sidelink Device-to-Device (D2D) and several other use cases.

[0003] FIG. 1 illustrates a high-level view of an exemplary 5G network architecture including a Next Generation Radio Access Network (NG-RAN 199) and a 5G Core (5GC 198). The NG-RAN may include one or more gNodeBs (gNBs) connected to the 5GC via one or more NG interfaces, such as gNBs (100, 150) connected via respective interfaces (102, 152). More specifically, the gNBs may be connected to one or more Access and Mobility Management Functions (AMFs) in the 5GC via respective NG-C interfaces and to one or more User Plane Functions (UPFs) in the 5GC via respective NG-U interfaces. The 5GC may include various other Network Functions (NFs), as described in more detail below.

[0004] Further, gNBs may be interconnected via one or more Xn interfaces, such as Xn interface 140 between gNBs (100, 150). The radio technology of NG-RAN is often referred to as "New Radio" (NR). With respect to the NR interface to the UE, each gNB may support Frequency Division Duplex (FDD), Time Division Duplex (TDD), or a combination thereof. Each of the gNBs may provide a geographic coverage area that includes one or more cells, and in some cases may use various directional beams to provide coverage in the respective cells. In general, a DL "beam" is a coverage area of ​​a network transmitted reference signal (RS) that may be measured or monitored by the UE.

[0005] The NG-RAN is layered into the Radio Network Layer (RNL) and the Transport Network Layer (TNL). The NG-RAN architecture, i.e., the NG-RAN logical nodes and the interfaces between them, are defined as part of the RNL. Each NG-RAN interface Face For (NG, Xn, F1), the relevant TNL protocols and functions are specified. The TNL provides user plane transport and signalling transport services.

[0006] The NG RAN logical node shown in Figure 1 includes a central unit (CU or gNB-CU, e.g., 110) and one or more distributed units (DU or gNB-DU, e.g., 120, 130). The CU is a logical node that hosts higher layer protocols and performs various gNB functions such as controlling the operation of the DU. The DU is a distributed logical node that hosts lower layer protocols and may include various subsets of gNB functions depending on the functional partitioning option.

[0007] A gNB-CU connects to one or more gNB-DUs via respective F1 logical interfaces (e.g., 122 and 132 shown in FIG. 1). However, a gNB-DU can only connect to a single gNB-CU. A gNB-CU and its connected gNB-DUs communicate with other gNBs and 5 From G.C. As gNB In other words, the F1 interface is not visible beyond the gNB-CU.

[0008] Another change in 5G networks (e.g., 5GC) is that the traditional peer-to-peer interfaces and protocols found in previous generations of networks are modified and / or replaced by a service-based architecture (SBA), where a network function (NF) offers one or more services to one or more service consumers. This can be achieved, for example, through HTTP / REST (Hyper Text Transfer Protocol / Representational State Transfer) application programming interfaces. tough This can be done through APIs. Generally, the various services are self-contained functions that can be changed and modified in an isolated way without affecting other services. This SBA model also embraces principles such as modularity, reusability, and self-containment of NFs, allowing for deployment leveraging the latest virtualization and software technologies.

[0009] In addition, a service is composed of various "service operations", which are finer divisions of the overall service functionality. The interaction between service consumers and producers is of the "request / response" or "subscribe / notify" type. Get it In the 5G SBA, the Network Repository Function (NRF) enables each network function to discover services offered by other network functions, and the Data Storage Function (DSF) enables each network function to store its context.

[0010] 3GPP Rel-16 introduced a feature called 3GPP User Credential-based Authentication and Key Management for Applications (AKMA) for 5G, including Internet of Things (IoT) use cases. Specifically, AKMA leverages the user's Authentication and Key Agreement (AKA) credentials to bootstrap security between the UE and an Application Function (AF), allowing the UE to securely exchange data with an application server. The AKMA architecture is considered an evolution of the Generic Bootstrapping Architecture (GBA) specified for 5GC in 3GPP Rel-15. profit , and is further specified in 3GPP TS33.535 (v16.0.0).

[0011] 5GC is expected to support Edge Computing (EC) to enable operators and third-party services to be hosted closer to the UE's access point. This will reduce end-to-end latency and reduce the load on the transport network, enabling more efficient service delivery. 5GC can select a User Plane Function (UPF) closer to the UE and perform traffic steering from the UPF to the local data network over the N6 interface. UPF and N6 are explained in more detail below.

[0012] 3GPP TR23.748 (v17.0.0) requires EC support for 5GC Can beIn addition, 3GPP TR33.839 (v0.7.0) discusses the security considerations to support EC in 5GC in Rel-17. The main issues discussed in 3GPP TR33.839 include authentication, authorization and transport security solutions for the interfaces between clients and servers and between different servers in the edge data network. These servers include the Edge Configuration Server (ECS), Edge Enabler Server (EES) and Edge Application Server (EAS). The relevant clients are considered as applications running on the UE and communicating with the ECS and EES. profit 3GPP TS23.558 (v17.3.0) specifies the architecture for enabling edge applications, including these clients and servers. Summary of the Invention [Problem to be solved by the invention]

[0013] To use the services provided by the ECS and EES, the EEC provides an identifier (e.g., UE ID) of the UE hosting the EEC. However, it is currently unclear how the EEC can obtain the UE ID. and / or Not specified. If the EEC does not have a UE ID, the EEC may be prevented from receiving services provided by the ECS or EES, which is undesirable.

[0014] Accordingly, embodiments of the present disclosure address these and other issues, challenges and / or difficulties, thereby enabling otherwise advantageous deployment of EC solutions in connection with 5G networks. [Means for solving the problem]

[0015] Some embodiments of the present disclosure include a method (e.g., a procedure) for a client (e.g., an EEC) of an edge data network (e.g., a 5G network).

[0016] The example methods include receiving, during or after authentication and / or authorization of the client by a first server of the edge data network, a user equipment identifier (UE ID) hosting the client from a first server. The example methods also include transmitting, during authentication and / or authorization of the client by a second server of the edge data network, the UE ID to a second server.

[0017] In some embodiments, the UE ID is included in an access token received from the first server, and the access token including the UE ID is sent to the second server. In some of these embodiments, one or more of the following apply: The access token is sent to the second server along with an indication that the access token includes the UE ID. · An access token is received from the first server along with an indication that the access token includes the UE identity.

[0018] In other embodiments, the UE ID is received from the first server in a service provisioning response that does not include an access token for the second server, and / or the UE ID is sent to the second server in a request that does not include an access token for the second server.

[0019] Other embodiments include complementary methods (e.g., procedures) for a first server (e.g., ECS) of an edge data network (e.g., a 5G network).

[0020] These example methods may include obtaining, during or after authentication and / or authorization of a client of the edge data network by a first server, an identifier of a user equipment (UE ID) hosting the client. The example methods may include the operation of block 1020, where the first server may transmit the UE ID to the client for authentication and / or authorization of the client by a second server of the edge data network.

[0021] In some embodiments, the UE ID is a Universal Public Subscription Identifier (GPSI) and is obtained based on any of the following: · Authentication and Key Management (AKMA) procedures for applications with communication networks connected to edge data networks; Generic Bootstrap Architecture (GBA) procedures with a communications network; or -IP address to GPS conversion.

[0022] In some embodiments, the UE ID is sent to the client in an access token for the second server. In some of these embodiments, the access token is included in a service provisioning response to the client. In some of these embodiments, the access token is sent to the client along with an indication that the access token includes the UE ID.

[0023] In another embodiment, the UE ID is sent to the client in the service provisioning response, but the response does not include an access token for the second server.

[0024] Other embodiments include complementary methods (e.g., procedures) for a second server (e.g., EES) in an edge data network (e.g., a 5G network).

[0025] The example methods include receiving, from a client of the edge data network, a user equipment identifier (UE ID) hosting the client, the UE ID having been provided to the client by a first server of the edge data network. The example methods also include performing authentication and / or authorization of the client based on the received UE ID.

[0026] In some embodiments, the UE identity is received from the client in an access token for the second server, the access token being generated by the first server, and authentication and / or authorization of the client is performed based on the access token. In some of these embodiments, the access token is received from the client along with an indication that the access token includes the UE identity.

[0027] In another embodiment, the UE ID is received from the client in a request that does not include an access token for the second server.

[0028] In various embodiments, the client is an EEC, the first server is an ECS, and the second server is an EES. In various embodiments, the UE ID is a GPSI.

[0029] Other embodiments include clients and servers in or associated with an edge data network (or UEs, network nodes, or computing systems hosting same) configured to perform operations corresponding to any of the example methods described herein. Other embodiments also include non-transitory computer-readable media storing computer-executable instructions that, when executed by processing circuitry, configure such clients and servers to perform operations corresponding to any of the example methods described herein.

[0030] These and other embodiments described herein can provide a clear and unambiguous way for an EEC to obtain and use a UE ID (of the UE hosting the EEC) for authentication and / or authorization purposes, thereby promoting security of EC applications over 3GPP networks (e.g., 5GC and NG-RAN).

[0031] These and other objects, features and advantages of the present disclosure will become apparent from the following detailed description taken in conjunction with the drawings, which are briefly described below. [Brief description of the drawings]

[0032] [Figure 1] FIG. 1 illustrates various aspects of an example 5G network architecture. [Diagram 2] FIG. 1 illustrates various aspects of an example 5G network architecture. [Diagram 3] FIG. 1 illustrates an example application layer architecture supporting edge computing (EC) applications in a 5G network. [Figure 4] FIG. 1 is a signaling diagram of a token-based procedure for authentication of an EEC by an ECS and an EES. [Diagram 5] Signal flow diagram of various token-based procedures for authentication of EEC. [Figure 6] Signal flow diagram of various token-based procedures for authentication of EEC. [Figure 7] FIG. 1 is a signaling diagram of a procedure between an EEC, an ECS, and an EES, according to various embodiments of the present disclosure. [Figure 8] FIG. 1 is a signaling diagram of a procedure between an EEC, an ECS, and an EES, according to various embodiments of the present disclosure. [Figure 9] FIG. 1 illustrates an example method (e.g., procedure) for a client of an edge data network, in accordance with various embodiments of the present disclosure. [Figure 10] FIG. 1 illustrates an example method (e.g., procedure) for a first server of an edge data network, in accordance with various embodiments of the present disclosure. [Figure 11] FIG. 1 illustrates an example method (e.g., procedure) for a second server of an edge data network, in accordance with various embodiments of the present disclosure. [Figure 12] 1 illustrates a communication system in accordance with various embodiments of the present disclosure. [Figure 13] 1 illustrates a UE in accordance with various embodiments of the present disclosure. [Figure 14] FIG. 2 illustrates a network node in accordance with various embodiments of the present disclosure. [Figure 15] FIG. 1 illustrates a host computing system in accordance with various embodiments of the present disclosure. [Figure 16] FIG. 1 is a block diagram of a virtualization environment in which functionality implemented by some embodiments of the present disclosure may be virtualized. [Figure 17] FIG. 2 illustrates communication between a host computing system, a network node, and a UE over multiple connections, at least one of which is wireless, in accordance with various embodiments of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0033] The above briefly summarized embodiments will now be described in more detail with reference to the accompanying drawings. These descriptions are provided as examples to explain the subject matter to those skilled in the art, and should not be construed as limiting the scope of the subject matter to only the embodiments described herein. More specifically, examples are provided below to illustrate the operation of various embodiments in accordance with the advantages described above.

[0034] Generally, all terms used herein should be interpreted according to their ordinary meaning in the relevant technical field unless a different meaning is clearly given and / or a different meaning is suggested from the context of use. All references to an element, apparatus, component, means, step, etc. should be openly interpreted as a reference to at least one instance of that element, apparatus, component, means, step, etc., unless expressly stated otherwise. The steps of any method and / or procedure disclosed herein do not have to be performed in the exact order disclosed, unless a step is clearly described as following or preceding another step and / or is implicitly indicated as having to precede or follow another step. Any feature of the embodiments disclosed herein may be applied to other embodiments, as appropriate. Similarly, any advantage of an embodiment may be applied to other embodiments, and vice versa. Other objects, features, and advantages of the accompanying embodiments will become apparent from the following description.

[0035] Additionally, the following terminology is used throughout the following description:

[0036] Radio Access Node: As used herein, a "radio access node" (or "radio network node", "radio access network node" or "RAN node") may be any node in a radio access network (RAN) that operates to transmit and / or receive signals wirelessly. Some examples of radio access nodes are base stations (e.g., gNB in ​​a 3GPP 5G / NR network or eNB in ​​a 3GPP LTE network), base station distributed components (such as CU and DU), high power or macro base stations, low power base stations (e.g., macro, pico, femto or home base stations), integrated access backhaul (IAB) nodes, transmission points (TP), transmit / receive points (TRP), remote radio units (RRU or RRH), and relay This includes, but is not limited to, nodes.

[0037] Core Network Node: As used herein, a "core network node" is any type of node in a core network. Some examples of core network nodes include, for example, a Mobility Management Entity (MME), a Serving Gateway (SGW), a PDN Gateway (P-GW), a Policy and Charging Rules Function (PCRF), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a User Plane Function (UPF), a Charging Function (CHF), a Policy Control Function (PCF), an Authentication Server Function (AUSF), a Location Management Function (LMF), etc.

[0038] Wireless Device: As used herein, a "wireless device" (abbreviated WD) is a device that communicates wirelessly with network nodes and / or other wireless devices. in A wireless device is any type of device capable of communicating and configured, arranged, and / or operable to do so. Wireless communication may include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared, and / or other types of signals suitable for carrying information over the air. Unless otherwise noted, the term "wireless device" in this disclosure is used interchangeably with the term "user equipment" (abbreviated "UE"), both of which have a different meaning than the term "network node."

[0039] Wireless Node: As used herein, a "wireless node" is either a "wireless access node" (or an equivalent term) or a "wireless device."

[0040] Network Node: As used herein, a "network node" is any node that is part of either the radio access network (e.g., radio access node or equivalent names as described above) or the core network (e.g., core network node as described above) of a cellular communications network. Functionally, a network node refers to a device that is configured, arranged and / or operable to communicate directly or indirectly with wireless devices and / or to communicate with other network nodes or equipment in the cellular communications network to enable and / or provide wireless access for wireless devices and / or to perform other functions (e.g., management) in the cellular communications network.

[0041] Node: As used herein, the term "node" (without any prefix) may be any type of node in or with a wireless network (including a RAN and / or a core network), including a radio access node (or equivalent term), a core network node, or a wireless device. However, the term "node" may be limited to a particular type (e.g., a radio access node) based on certain characteristics in any context.

[0042] It should be noted that the description herein focuses on 3GPP cellular communication systems, and as such, 3GPP terminology or terminology similar to 3GPP terminology is often used. However, the concepts disclosed herein are not limited to 3GPP systems. Other wireless systems, including but not limited to Wideband Code Division Multiple Access (WCDMA), Worldwide Interoperability for Microwave Access (WiMax), Ultra Mobile Broadband (UMB), and Global System for Mobile Communications (GSM), may also benefit from the concepts, principles, and / or embodiments described herein.

[0043] Additionally, functions and / or operations described herein as being performed by a wireless device or network node may be distributed across multiple wireless devices and / or network nodes. Additionally, although the term "cell" is used herein, it is understood that (particularly with respect to 5G NR) a beam may be used in place of a cell. profit , therefore, it should be understood that the concepts described herein apply equally to both cells and beams.

[0044] Figure 2 illustrates an example non-roaming 5G reference architecture with service-based interfaces and various 3GPP-defined NFs in the control plane (CP). These include the following NFs, with more detailed descriptions provided for the NFs most relevant to this disclosure:

[0045] Application functions (AF, Naf In tough The 5GC and 5G networks will work together to provide information to network operators and subscribe to certain events that occur in the operator's network. Interaction The AF provides control of flow resources according to what has been negotiated with the network to applications where services are provided at a different layer (the transport layer) than the layer where the service was requested (the signaling layer). The AF communicates dynamic session information to the PCF (through the N5 interface), including a description of the media delivered from the transport layer.

[0046] · The Policy Control Function (PCF, with Npcf interface) supports a unified policy framework to control the network behavior by providing PCC rules (e.g. treatment of each service data flow under PCC control) to the SMF via the N7 reference point. The PCF provides policy control decisions and flow-based charging control to the SMF, including service data flow discovery, gating, QoS and flow-based charging (except credit control). The PCF receives session and media related information from the AF and notifies the AF of traffic (or user) plane events.

[0047] · User Plane Function (UPF) - Supports user plane traffic processing including packet inspection and various enforcement actions (e.g. event detection and reporting) based on rules received from the SMF. The UPF communicates with the RAN (e.g. NG-RNA) over the N3 reference point, with the SMF (described below) over the N4 reference point, and with the external Packet Data Network (PDN) over the N6 reference point. The N9 reference point is for communication between two UPFs.

[0048] The Session Management Function (SMF, with Nsmf interface) manages the separate traffic (or user) plane, including creating, updating, and deleting Protocol Data Unit (PDU) sessions and managing session context with the User Plane Function (UPF) (e.g. for event reporting). Interaction For example, the SMF performs data flow detection, online and offline charging (based on the filter definitions contained in the PCC rules). Interaction , and performs policy enforcement.

[0049] The Charging Function (CHF, with Nchf interface) is responsible for integrating the online and offline charging functions. The CHF provides quota management (for online charging), re-authorization triggers, rating conditions, etc., and is notified of usage reports from the SMF. Quota management involves granting a specific number of units (bytes, seconds, etc.) for a service. The CHF is also known as the charging system. Interaction do.

[0050] · The Access and Mobility Management Function (AMF, with Namf interface) terminates the RAN CP interface and is responsible for all mobility and connection management for the UE (similar to MME in EPC). The AMF communicates with the UE via the N1 reference point and with the RAN (e.g. NG-RAN) via the N2 reference point.

[0051] Network Exposure Function (NEF) with Nnef Interface - acts as an entry point into the operator's network by securely exposing network capabilities and events offered by 3GPP NFs to the AF and providing a way for the AF to securely provide information to the 3GPP network. For example, the NEF provides a service that allows the AF to provide specific subscription data for various UEs (such as expected UE behavior).

[0052] · Network Repository Function (NRF) with Nnrf interface - provides service registration and discovery, allowing NFs to identify suitable services available from other NFs.

[0053] Network Slice Selection Function (NSSF) with Nnssf interface - A "network slice" is a logical partition of the 5G network that provides certain network capabilities and characteristics, e.g. to support a certain service. A network slice instance is a set of NF instances and required network resources (e.g. compute, storage, communication) that provide the network slice capabilities and characteristics. The NSSF enables other NFs (e.g. AMF) to identify the network slice instance suitable for the UE's desired service.

[0054] · Authentication Server Function with Nausf Interface (AUSF) - performs user authentication based on the user's home network (HPLMN) and calculates security keying material for various purposes.

[0055] Location Management Function (LMF) with Nlmf interface - supports various UE location related functions including determining the UE's position and obtaining either DL position measurements or estimates from the UE, UL position measurements from the NG RAN, or non-UE related assistance data from the NG RAN.

[0056] Unified Data Management (UDM) functionality with Nudm interface - 3GPP certified credentials Le It supports the creation, user identification, access authorization based on subscription data, and other subscriber-related functions. To provide this functionality, the UDM is stored in the 5GC Unified Data Repository (UDR). Subscription Using data (including authentication data), the UDR also supports the storage and retrieval of policy data by the PCF, and the storage and retrieval of application data by the NEF.

[0057] The communication link between the UE and the 5G network (AN and CN) can be classified into two different hierarchies. The UE communicates with the CN via the Non-Access Stratum (NAS) and with the AN via the Access Stratum (AS). All NAS communication is performed between the UE and the AMF via the NAS protocol (N1 interface in Figure 2). Security of the communication over these strata is provided by the NAS protocol (for NAS) and the PDCP protocol (for AS).

[0058] 3GPP Rel-16 introduced a feature called Authentication and Key Management (AKMA) for 3GPP User Credential-based Applications in 5G, including Internet of Things (IoT) use cases. Specifically, AKMA leverages the user's Authentication and Key Agreement (AKA) credentials to bootstrap security between the UE and the Application Function (AF) so that the UE can securely exchange data with the application server. The AKMA architecture is an evolution of the Generic Bootstrapping Architecture (GBA) specified for 5GC in 3GPP Rel-15 and is further specified in 3GPP TS 33.535 (v16.1.0).

[0059] In addition to the NEF, AUSF, and AF shown in Figure 2 and described above, the Rel-16 AKMA also utilizes an Anchor Function for Application Authentication and Key Management (AAnF). This function is shown in Figure 2 with the Naanf interface. In general, the AAnF is Interaction It maintains the UE AKMA context which is used for subsequent bootstrapping requests by application functions etc. At a high level, the AAnF is similar to the Bootstrapping Server Function (BSF) defined in the GBA of Rel-15.

[0060] In general, the security mechanisms of the various 5GS protocols rely on multiple security keys. 3GPP TS33.501 (v16.4.0) specifies these keys in an organized hierarchical structure. At the top is the long-term key part of the authentication credentials, stored in the SIM card on the UE side and in the UDM / ARPF in the user's HPLMN.

[0061] Once the primary authentication is successful between the UE and the AUSF in the HPLMN, the second level key in the hierarchy, K AUSFThis key is not intended to leave the HPLMN and is used to protect information exchanges between the UE and the HPLMN, such as the provisioning of parameters from the UDM in the HPLMN to the UE. More precisely, K AUSF is used for integrity protection of messages delivered from the HPLMN to the UE. As described in 3GPP TS 33.501, such new features include the Steering of Roaming (SoR) and UDM parameter delivery procedures.

[0062] K AUSF is another key K SEAF This key is then used by the serving PLMN to derive subsequent NAS and AS protection keys. These lower level keys, together with other security parameters (such as cryptographic algorithms, UE security capabilities, and counter values ​​used for replay protection of various protocols), constitute the 5G security context as defined in 3GPP TS 33.501. However, K AUSF is not part of the UE's 5G security context that exists in the UE's serving PLMN.

[0063] 3GPP TR33.839 (v17.1.0) discusses the study of security aspects for enhancing support of Edge Computing (EC) in 5GC for 3GPP Rel-17. The main issues discussed in 3GPP TR33.839 include authentication, authorization, and transport security solutions for the interfaces between clients and servers, and between different servers in the edge data network. These servers include Edge Configuration Servers (ECS), Edge Enabler Servers (EES), and Edge Application Servers (EAS). Can be seen The relevant clients include an edge enabler client (EEC), which can be considered as an application that runs on the UE and communicates with the ECS and EES.

[0064] 3GPP TS 23.558 (v17.3.0) specifies various client / server and server / server interfaces in the Rel-17 EC architecture. Figure 3 illustrates an exemplary application layer architecture supporting EC applications. In addition to the ECS (330), EES (340), EAS (350) and EEC (310) discussed above, Figure 3 also illustrates one or more application clients running on the UE (300) and communicating application data traffic with the EAS in the edge data network (320). Additionally, Figure 3 illustrates the following client / server and server / server interfaces defined in 3GPP TS 23.558: EDGE-1: Between EEC and EES EDGE-2: Between EES and CN (5GC, etc.) EDGE-3: Between EAS and EES EDGE-4: Between EEC and ECS EDGE-5: Between the EEC and the application client EDGE-6: Between ECS and EES EDGE-7: Between EAS and CN EDGE-8: Between ECS and CN EDGE-9: Between EES and EES

[0065] 3 shows the ECS (330) outside of the edge data network (300), it should be noted that this is an exemplary representation: Due to its functionality, the ECS, like the other servers shown, may be considered part of the edge data network.

[0066] In the architecture shown in Figure 3, the EEC running on the UE needs to authenticate itself to the EES / ECS. The EEC provides an Identifier (ID) of the UE for this purpose, as specified in 3GPP TS 23.558 clause 7.2.6. One example of a UE ID is the Generic Public Subscription Identifier (GPSI), which can be used inside and outside the 5G network, as further specified in 3GPP TS 23.501 (v17.2.0) and 23.003 (v17.3.0). 3GPP TS 23.558 also specifies an edge enabler layer that includes the EEC of the UE. In this case, the UE uses the EEC ID as a client identifier of the edge enabler layer.

[0067] 3GPP TS33.558 (v17.0.0) specifies the security and privacy mechanisms for the edge enabler layer defined in 3GPP TS23.558. One of the security mechanisms is the authorization of the EEC by the EES using an access token. Specifically, the ECS issues an access token that the EEC uses to the EES, and the E E S authorizes the EEC by verifying and checking the access token.

[0068] 4 is an example signal flow diagram of an AKMA-based solution for EEC authentication by an ECS that provides the EEC with a token to use for authentication in the EES. A detailed description of this proposal (referred to as "Solution #3") is provided in Section 6.3.2 of 3GPP TR 33.839 (v17.1.0), which is incorporated by reference in its entirety. Section 6.4 of 3GPP TR 33.839 describes a similar proposal (referred to as "Solution #4") that uses secondary authentication to support EEC authentication by an ECS that provides the EEC with a token to use for authentication in the EES.

[0069] 3GPP TR33.839 describes another proposal (called "Solution #17") that uses a token provided by an Edge Computing Service Provider (ECSP) associated with the EEC. At the EDGE-4 interface, authentication of the ECS and transport security of the interface are achieved using TLS with the server using a server certificate issued by a CA in the PKI. The first authentication of the EEC by the ECS uses a token containing an EEC ID that the EEC's ECSP or a trusted new entity (which may or may not be affiliated with the ECSP) provides to the EEC. In the case of token provision by the ECSP, it is assumed that there is a business relationship between the EEC's ECSP and the ECS, so that the EEC's ECSP provides the EEC with an initial access token, which the ECS can validate. After authenticating the EEC, the ECS provides the EEC with a token to be used to establish the next communication between them at the first access. At the access after the first access, the ECS considers information such as the token's expiration date and determines whether a new access token is required.

[0070] In solution #17, for the EDGE-1 interface, authentication of the EES and transport security of the interface is achieved using TLS with server authentication based on a server certificate issued by a CA in the PKI. To authenticate the EEC by the EES, the EEC first obtains a token from the ECS and sends the token to the EES. It is assumed that there is a business relationship between the ECSP of the ECS and the EES so that the EES can validate the token.

[0071] Figure 5 is an example signal flow diagram of another proposal for authentication and authorization between the EEC and the EES. In summary, the EEC uses the EES's TLS certificate to authenticate the EES. The EEC uses a token provided by the ECS for its authentication to the EES. The token can be an access token (OAuth 2.0) for implicit authentication of the EEC, or an identity token (OpenID Connect 1.0) for explicit authentication. The EES can validate the token because there is a business relationship between the EEC's ECSP and the ECS.

[0072] In act 1, the ECS issues the EEC a token that the EES uses to authenticate the EEC. In act 2, the EEC and the EES establish a TLS session using the EES's TLS certificate. In act 3, the EEC sends the token provided by the ECS during the established TLS session. In act 4, the EES validates the token.

[0073] Another solution for authentication of the EEC to the EES / ECS involves the EEC's service provider (i.e., ECSP) providing the EEC with a token that is used to authenticate the EEC by the EES / ECS. Figure 6 is an example signal flow diagram of one of these solutions for authentication at the EDGE-1 interface between the EEC and the EES. In this solution, authentication of the EES and transport security of the interface is achieved by using server-authenticated TLS using the server's (i.e., EES's) certificate issued by a CA in a PKI. As shown in Figure 13, the ECS first provides the token to the EEC. After setting up a server-authenticated TLS connection using the EES certificate, the EEC uses the access token provided by the ECS to authenticate the EEC with the EES.

[0074] As mentioned before, the EEC provides the UE ID to the EES / ECS in addition to the EEC ID for authentication purposes. The manner in which the EEC obtains the UE ID is not defined in 3GPP TS23.558 or other specifications. One possible solution (called "Solution 23") is described in 3GPP TR23.700-98 (v0.6.0). In Solution 23, the EEC invokes the EDGE UE ID service provided by the EES.

[0075] Furthermore, it is not specified how the UE identity information is transmitted to the EES. For example, 3GPP TS 23.558 states that it is up to 3GPP Group SA3 to include the EES identity and UE identity as part of the security credentials in requests for EDGE-1 and EDGE-4 interactions, but 3GPP Group SA3 has not yet defined or specified these requirements or details.

[0076] Embodiments of the present disclosure address these and other problems, issues, and / or difficulties by providing a technique in which the ECS provides a UE identity to the EEC during authentication and authorization procedures between the EEC and the ECS. This information may be inserted into an access token if the EES uses access token-based authorization, or this information may be sent in a response from the ECS to the EEC. The EEC then sends the UE identity received in this manner to the EES during authentication and authorization procedures between the EEC and the EES. Thus, embodiments provide a clear and unambiguous way for the EEC to obtain and use a UE identity (i.e., of the UE hosting the EEC) for authentication and authorization purposes, thereby facilitating security of EC applications over 3GPP networks (such as 5GC and NG-RAN).

[0077] Figure 7 is a signaling diagram between an EEC (710), an ECS (720), and an EEC (730) in accordance with some embodiments of the present disclosure. In particular, the procedure shown in Figure 7 is for a scenario in which the EES supports EEC authorization based on access tokens. Although the operations in Figure 7 are numerically labeled, this is done for ease of explanation and not to imply or require an order of operations, unless stated to the contrary.

[0078] In operation 1, the EEC and ECS perform a procedure for authentication and (optionally) authorization. During or after this procedure, the ECS obtains the UE ID (e.g., GPSI) of the UE hosting the EEC from the network using the AKMA, GBA, or IP address to GPSI translation. Alternatively, the ECS can obtain the UE ID from a local configuration.

[0079] After the procedure in act 1 is successful, in act 2, the ECS prepares an access token that includes the UE identity. For example, the access token can be an OAuth 2.0 token, and the UE identity can be included in a subject claim of the token. Document RFC 7519 published by the Internet Engineering Task Force (IETF) describes an exemplary token with a subject claim field in which the UE identity can be inserted.

[0080] In operation 3, the ECS sends the access token including the UE identity as a response to the EEC. For example, the response may be a service provisioning response as defined in 3GPP TS 23.558 section 8.3.3.3. In some embodiments, the EEC may implicitly recognize that the access token received in the response from the ECS includes the UE identity. In other embodiments, the ECS may also include an explicit indication in the response that the UE identity is included in the access token. In either case, the EEC does not need to use other mechanisms to obtain the UE identity, such as the mechanisms described in 3GPP TR 23.700-98 (v0.6.0) section 7.23.

[0081] In operation 4, the EEC sends the token including the UE ID to the EES for authentication and authorization. In operation 5, the EES verifies the access token and obtains the UE ID of the UE hosting the EEC from the access token.

[0082] Figure 8 is a signaling diagram between an EEC (810), an ECS (820), and an EEC (830) in accordance with another embodiment of the present disclosure. In particular, the procedure shown in Figure 8 is for a scenario in which the EES does not support EEC authorization based on access tokens. Although the operations in Figure 8 are numerically labeled, this is done for ease of explanation and does not imply or require an order of operations, unless stated to the contrary.

[0083] In operation 1, the EEC and ECS perform a procedure for authentication and (optionally) authorization. During or after this procedure, the ECS obtains the UE ID (e.g., GPSI) of the UE hosting the EEC from the network using the AKMA, GBA, or IP address to GPSI translation. Alternatively, the ECS can obtain the UE ID from a local configuration.

[0084] After the procedure in operation 1 is successful, in operation 2, the ECS prepares a response including the UE ID. In operation 3, the ECS sends the response including the UE ID to the EEC. For example, the response may be a service provisioning response as defined in 3GPP TS23.558 section 8.3.3.3. In operation 4, the EEC sends an authentication and authorization request including the UE ID to the EES. In operation 5, the EES retrieves the UE ID from the received request and uses it during authentication and authorization of the EEC.

[0085] The above-described embodiments may be further described with reference to FIGS. 9-11, which illustrate example methods (e.g., procedures) performed by a client, a first server, and a second server, respectively, of an edge data network. In other words, various features of the operations described below correspond to the various embodiments described above. The example methods illustrated in FIGS. 9-11 may be complementary to one another such that they may be used cooperatively to provide benefits, advantages, and / or solutions to problems described herein. Although the example methods are illustrated in FIGS. 9-11 by certain blocks in a particular order, the operations corresponding to the blocks may be performed in a different order than illustrated and may be combined and / or separated into operations having different functionality than illustrated. Optional blocks or operations are indicated with dashed lines.

[0086] More specifically, Figure 9 illustrates an example method (e.g., procedure) for a client of an edge data network (e.g., a 5G network) in accordance with various embodiments of the present disclosure. The example method illustrated in Figure 9 may be performed by a client hosted by a UE (e.g., a wireless device), such as an EEC described elsewhere herein.

[0087] The exemplary method may include the operation of block 910, where during or after authentication and / or authorization of the client by a first server of the edge data network, the client may receive from the first server a user equipment identifier (UE ID) of the client hosting the client. The exemplary method may also include the operation of block 920. Can be , where the client may send the UE ID to the second server during authentication and / or authorization of the client by the second server of the edge data network.

[0088] In some embodiments, the UE ID is included in an access token received from the first server (e.g., at block 910), and the access token including the UE ID is sent to the second server (e.g., at block 920). Figure 7 shows examples of these embodiments. In some of these embodiments, one or more of the following apply: The access token is sent to the second server along with an indication that the access token includes the UE ID. · An access token is received from the first server along with an indication that the access token includes the UE identity.

[0089] In other embodiments, the UE identity is received from the first server in a service provisioning response that does not include an access token for the second server, and / or the UE identity is sent to the second server in a request that does not include an access token for the second server. Figure 8 shows examples of these embodiments.

[0090] In some embodiments, the client is an EEC, the first server is an ECS, and the second server is an EES. In some embodiments, the UE ID is a GPSI.

[0091] Additionally, Figure 10 illustrates an example method (e.g., procedure) for a first server of an edge data network (e.g., a 5G network) according to various embodiments of the present disclosure. The example method illustrated in Figure 10 may be performed by any suitable server (e.g., an ECS, etc.) as described elsewhere herein.

[0092] An example method can include the operations of block 1010, where during or after authentication and / or authorization of a client of the edge data network by a first server, the first server can obtain a user equipment identifier (UE ID) hosting the client. An example method can include the operations of block 1020, where the first server can transmit the UE ID to the client for authentication and / or authorization of the client by a second server of the edge data network.

[0093] In some embodiments, the UE ID is a GPSI and is obtained (e.g., in block 1010) based on one of the following: · Authentication and Key Management (AKMA) procedures for applications with communication networks connected to edge data networks; Generic Bootstrap Architecture (GBA) procedures with a communications network; or -IP address to GPS conversion.

[0094] In some embodiments, the UE ID is sent to the client as an access token for the second server. Figure 7 shows examples of these embodiments. In some of these embodiments, the access token is included in a service provisioning response to the client. In some of these embodiments, the access token is sent to the client along with an indication that the access token includes the UE ID.

[0095] In other embodiments, the UE ID is sent to the client in the service provisioning response, but this response does not include an access token for the second server. Figure 8 shows examples of these embodiments.

[0096] In some embodiments, the client is an EEC, the first server is an ECS, and the second server is an EES.

[0097] Additionally, Figure 11 illustrates an example method (e.g., procedure) for a second server of an edge data network (e.g., a 5G network) according to various embodiments of the present disclosure. The example method illustrated in Figure 11 may be performed by any suitable server (e.g., EES, etc.) as described elsewhere herein.

[0098] The example method can include the operation of block 1110, where the second server can receive, from the client of the edge data network, a user equipment identifier (UE ID) hosting the client. The UE ID has been provided to the client by the first server of the edge data network. The example method can also include the operation of block 1120, where the second server can perform authentication and / or authorization of the client based on the received UE ID.

[0099] In some embodiments, the UE ID is received from the client in an access token for the second server, the access token being generated by the first server, and authentication and / or authorization of the client is performed based on the access token. Figure 7 shows an example of these embodiments. In some of these embodiments, the access token is received from the client along with an indication that the access token includes the UE ID.

[0100] In other embodiments, the UE ID is received from the client in a request that does not include an access token for the second server. Figure 8 shows examples of these embodiments.

[0101] In some embodiments, the client is an EEC and the second server is an EES. In some embodiments, the UE ID is a GPSI.

[0102] While various embodiments are described above in terms of methods, techniques and / or procedures, those skilled in the art will readily appreciate that such methods, techniques and / or procedures may be embodied in various combinations of hardware and software in a variety of systems, communication devices, computing devices, control devices, apparatus, non-transitory computer readable media, computer program products, and the like.

[0103] 12 illustrates an example of a communications system 1200 according to some embodiments. In this example, the communications system 1200 includes a telecommunications network 1202 including an access network 1204 (e.g., a RAN) and a core network 1206 including one or more core network nodes 1208. The access network 1204 includes one or more access network nodes, such as network nodes 1210a-b (one or more of which may be generally referred to as network nodes 1210), or any other similar 3GPP access node or non-3GPP access point. The network nodes 1210 facilitate direct or indirect connectivity of user equipment (UE), such as by connecting UEs 1212a-d (one or more of which may be generally referred to as UEs 1212) to the core network 1206 over one or more disconnected connections.

[0104] Exemplary wireless communications over wireless connections include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for carrying information without the use of wires, cables, or other material conductors. Moreover, in various embodiments, communications system 1200 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in communication of data and / or signals, whether via wired or wireless connections. Communications system 1200 may include and / or interface with any type of communications, telecommunications, data, cellular, wireless networks, and / or other similar types of systems.

[0105] The UE 1212 may be any of a wide variety of communication devices, including wireless devices, that are arranged, configured, and / or operable to wirelessly communicate with the network node 1210 and other communication devices. Similarly, the network node 1210 is arranged, capable, configured, and / or operable to communicate, directly or indirectly, with the UE 1212 and / or with other network nodes or equipment within the telecommunications network 1202 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as management within the telecommunications network 1202.

[0106] In the illustrated example, the core network 1206 connects the network node 1210 to one or more hosts, such as a host 1216. The connections may be direct or indirect through one or more intermediate networks or devices. In other examples, the network nodes may be directly coupled to the hosts. The core network 1206 includes one or more core network nodes (e.g., 1208) that are structured with hardware and software components. The functionality of those components may be substantially similar to those described with respect to UEs, network nodes, and / or hosts, and thus those descriptions are generally applicable to the corresponding components of the core network node 1208. Exemplary core network nodes include one or more of the following functions: a Mobile Switching Center (MSC), a Mobility Management Entity (MME), a Home Subscriber Server (HSS), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Subscription Identifier Deciphering Function (SIDF), a Unified Data Management (UDM), a Security Edge Protection Proxy (SEPP), a Network Publication Function (NEF), and / or a User Plane Function (UPF).

[0107] The host 1216 may be owned or controlled by, and operated by or on behalf of, a non-operator service provider or a provider of the access network 1204 and / or the telecommunications network 1202. The host 1216 may host a variety of applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services such as acquiring and compiling data regarding various ambient conditions sensed by multiple UEs, analytics functionality, social media, functionality for controlling or otherwise interacting with remote devices, functionality for alarm and monitoring centers, or any other such functionality performed by a server.

[0108] Overall, the communication system 1200 of Figure 12 enables connectivity between UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as a particular standard, including, but not limited to, Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G), wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (WiFi), and / or any other suitable wireless communication standard, such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC), ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards, such as LoRa and Sigfox.

[0109] In some examples, the telecommunications network 1202 is a cellular network implementing functions standardized by 3GPP. Thus, the telecommunications network 1202 may support network slicing to provide different logical networks to different devices connected to the telecommunications network 1202. For example, the telecommunications network 1202 may provide Ultra-Reliable Low Latency Communication (URLLC) services to some UEs, while providing enhanced Mobile Broadband (eMBB) services to other UEs, and massive machine type communication (mMTC) / massive IoT services to additional UEs.

[0110] As another example, the communications system 1200 may include an edge data network. In that case, various servers of the edge data network may be part of the telecommunications network 1202, e.g., hosted or implemented by one or more core network nodes 1208 and / or one or more network nodes 1210. Additionally, the UE 1212 may implement or host one or more clients for the edge data network. In this manner, the clients and servers hosted by the communications system 1200 may perform the operations attributed to these entities in the above descriptions of the various methods or procedures.

[0111] In some examples, the UE 1212 is configured to transmit and / or receive information without direct human interaction. For example, the UE may be designed to transmit information to the access network 1204 on a predetermined schedule, when triggered by an internal or external event, or upon a request from the access network 1204. Additionally, the UE may be configured to operate in a single or multi-RAT or multi-standard mode. For example, the UE may be configured and operate in any one or combination of Wi-Fi, NR (New Radio), and LTE, i.e., Multi-Radio Dual Connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio-Dual Connectivity (EN-DC).

[0112] In the above examples, the hub 1214 communicates with the access network 1204 to facilitate indirect communication between one or more UEs (e.g., 1212c and / or 1212d) and a network node (e.g., 1210b). In some examples, the hub 1214 may be a controller, a router, a content source, and analytics, or any of the other communication devices described herein with respect to a UE. For example, the hub 1214 may be a broadband router that allows access to the core network 1206 for the UE. As another example, the hub 1214 may be a controller that sends commands or instructions to one or more actuators in the UE. The commands or instructions may be received from the UE or the network node 1210 or may be accepted by executable code, scripts, processes, or other instructions in the hub 1214. As another example, the hub 1214 may be a data collector that acts as a temporary storage for data for the UE and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 1214 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker, or other media delivery device, the hub 1214 may obtain media or data related to VR assets, video, audio, or other sensory information via a network node, which the hub 1214 then provides to the UE, either directly, after performing local processing, and / or after adding additional local content. In yet another example, the hub 1214 acts as a proxy server or orchestrator for the UEs, especially if one or more of the UEs are low energy IoT devices.

[0113] The hub 1214 may have a constant / permanent or intermittent connection to the network node 1210b. The hub 1214 may also enable different communication schemes and / or schedules between the hub 1214 and the UEs (UEs 1212c and / or 1212d) and between the hub 1214 and the core network 1206. In other examples, the hub 1214 is connected to the core network 1206 and / or one or more UEs via a wired connection. Moreover, the hub 1214 may be configured to connect to an M2M service provider over the access network 1204 and / or to other UEs over a direct connection. In some scenarios, a UE may establish a wireless connection with the network node 1210 while still being connected via the hub 1214 via a wired or wireless connection. In some embodiments, the hub 1214 may be a dedicated hub, i.e., a hub whose primary function is to route communications between the UEs and the network node 1210b. In other embodiments, the hub 1214 may be a non-dedicated hub, i.e., a device that is operable to route communications between the UE and the network node 1210b, but that additionally can act as an origination and / or termination point for communications for any data channel.

[0114] 13 illustrates a UE 1300, according to some embodiments. Examples of UEs include, but are not limited to, smartphones, mobile phones, cell phones, Voice over IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, gaming consoles or devices, music storage devices, playback appliances, wearable terminal devices, wireless endpoints, mobile stations, tablets, laptops, laptop embedded equipment (LEE), laptop mounted equipment (LME), smart devices, wireless customer premises equipment (CPE), vehicles, vehicle mounted or vehicle embedded / integrated wireless devices, etc. Other examples include any UE identified by 3GPP, including Narrowband Internet of Things (NB-IoT) UEs, Machine Type Communication (MTC) UEs, and / or enhanced MTC (eMTC) UEs.

[0115] A UE may support device-to-device (D2D) communications, for example, by implementing 3GPP standards for sidelink communications, dedicated short-range communications (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2E). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the associated device. Instead, a UE may represent a device (e.g., a smart sprinkler controller) that is intended for sale to or operation by a human user, but may not be associated with a particular human user, at least initially. Alternatively, a UE may represent a device (e.g., a smart power meter) that is not intended for sale to or operation by an end user, but may be associated with or operated for the benefit of a user.

[0116] The UE 1300 includes a processing circuit 1302 operably coupled via a bus 1304 to an input / output interface 1306, a power source 1308, a memory 1310, a communication interface 1312, and / or any other components, or any combination thereof. A given UE may utilize all or a subset of the components shown in FIG. 13. The level of integration between components may vary from one UE to another. Additionally, a given UE may include multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0117] The processing circuitry 1302 is configured to process instructions and data and may be configured to implement any sequential state machine operable to execute instructions stored in memory 1310 as a machine-readable computer program. The processing circuitry 1302 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc.), programmable logic with appropriate firmware, one or more stored computer programs, a general-purpose processor such as a microprocessor or digital signal processor (DSP) with appropriate software, or any combination of the above. For example, the processing circuitry 1302 may be implemented as one or more centrally-implemented state machines. Processing Unit (CPU).

[0118] In the above examples, the input / output interface 1306 may be configured to provide one or more interfaces to an input device, an output device, or one or more input / output devices. Examples of output devices include speakers, sound cards, video cards, displays, monitors, printers, actuators, emitters, smart cards, other output devices, or any combination thereof. An input device may enable a user to capture information for the UE 1300. Examples of input devices include touch-sensitive or presence-sensitive displays, cameras (e.g., digital cameras, digital video cameras, webcams, etc.), microphones, sensors, mice, trackballs, directional pads, trackpads, scroll wheels, and smart cards, etc. A presence-sensitive display may include a capacitive or resistive touch sensor for sensing input from a user. The sensors may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetic sensor, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as the input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0119] In some embodiments, the power source 1308 is structured as a battery or battery pack. Other types of power sources may also be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a battery. The power source 1308 may include a power supply for transmitting power from the power source itself and / or the external power source to various portions of the UE 1300 via interfaces such as input circuits or power cables. source The power transfer may be for example for charging the power source 1308. The power circuitry may perform any formatting, conversion, or other modification of the power from the power source 1308 to generate power suitable for each component of the UE 1300 being powered.

[0120] The memory 1310 may be or may be configured to include random access memory (RAM), read only memory (ROM), programmable read only memory (PROM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), magnetic disk, optical disk, hard disk, removable cartridge, flash drive, etc. In one example, the memory 1310 includes one or more application programs 1314, such as an operating system, a web browser application, widgets, gadget engine, or other applications, and corresponding data 1316. The storage medium 1310 may store various operating systems or combinations of operating systems for use by the UE 1300.

[0121] The memory 1310 may be configured to include multiple physical drive units such as a Redundant Array of Independent Disks (RAID), flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a High-Density Digital Versatile Disc (HD-DVD), an optical disk drive, an internal hard disk drive, a Blu-Ray optical disk drive, a Holographic Digital Data Storage (HDDS) optical disk drive, an external Mini-DIMM (Dual In-Line Memory Module), a Synchronous Dynamic Random Access Memory (SDRAM), an external Micro-DIMM SDRAM, a smart card memory such as a tamper-resistant module in the form of a universal integrated circuit card (UICC) that includes one or more subscriber identity modules (SIMs) such as a USIM and / or an ISIM, other memory, or any combination thereof. The UICC may be, for example, an embedded UICC (eUICC), an integrated UICC (iUICC), or a commonly known "SIM card." Removable The memory 1310 may be a UICC. The memory 1310 may enable the UE 1300 to access instructions, application programs, and the like stored on a temporary or non-transitory storage medium to offload data or upload data. An article of manufacture, such as one that utilizes a communication system, may be tangibly embodied as or within the memory 1310, which may be or include a device-readable storage medium.

[0122] The processing circuit 1302 may be configured to communicate with an access network or other networks using a communication interface 1312. The communication interface 1312 may include one or more communication subsystems and may include or be communicatively coupled to an antenna 1322. The communication interface 1312 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of other wirelessly enabled devices (e.g., other UEs or network nodes in the access network). Each transceiver may include a transmitter 1318 and / or a receiver 1320 appropriate for providing network communications (e.g., optical, electrical, frequency-allocated, etc.). Moreover, the transmitter 1318 and receiver 1320 may be coupled to one or more antennas (e.g., antenna 1322), which may share circuit components, software, or firmware, or may alternatively be implemented separately.

[0123] In the illustrated embodiment, the communication capabilities of communication interface 212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication such as using the Global Positioning System (GPS) for determining location, other similar communication capabilities, or any combination thereof. Communications may be implemented according to one or more communication protocols and / or standards, such as, for example, IEEE 802.11, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP), Synchronous Optical Networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), etc.

[0124] Regardless of the type of sensor, the UE may provide an output of data captured by its sensors to a network node via a wireless connection through its communications interface 1312. Data captured by the UE's sensors may be communicated via other UEs to the network node via a wireless connection. The output may be periodic (e.g., once every 15 minutes when reporting sensed temperature), random (e.g., to balance the load of notifications from multiple sensors), in response to a triggering event (e.g., moisture is detected and an alert is sent), on request (e.g., a user initiated request), or as a continuous stream (e.g., a live video feed of a patient).

[0125] As another example, the UE may include an actuator, motor, or switch associated with a communications interface configured to receive wireless input from a network node over a wireless connection. In response to the received wireless input, the actuator, motor, or switch may change state. For example, the UE may include a motor that adjusts a control surface or rotor of a drone in flight in accordance with the received input, or a robotic arm that performs a medical procedure in accordance with the received input.

[0126] When the UE is in the form of an Internet of Things (IoT) device, it may be a device for use in one or more application domains, including but not limited to wearable technology in the city, extended industrial applications, and healthcare. Non-limiting examples of such IoT devices are or are incorporated into devices such as connected refrigerators or freezers, TVs, connected lighting fixtures, electric meters, robot vacuums, voice-controlled smart speakers, home security cameras, motion detectors, thermostats, smoke detectors, door / window sensors, flood / moisture sensors, electric door locks, connected doorbells, air conditioning systems such as heat pumps, autonomous vehicles, surveillance systems, weather monitors, vehicle parking monitors, electric vehicle charging stations, smart watches, fitness trackers, head mounted displays for augmented reality (AR) or virtual reality (VR), wearables for haptic augmentation or sensory enhancement, water sprinklers, animal or object trackers, sensors for monitoring plants or animals, industrial robots, unmanned aerial vehicles (UAVs), and any type of medical device such as a heart rate monitor or a remote controlled surgical robot. A UE in the form of an IoT device comprises other components as described in connection with the UE 1300 shown in FIG. 13, in addition to circuitry and / or software depending on the intended application of the IoT device.

[0127] As yet another specific example, in an IoT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements and transmits results of such monitoring and / or measurements to other UEs and / or network nodes. The UE in this case may be an M2M device, which may be referred to as an MTC device in the 3GPP context. As one example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, the UE may represent a car, truck, ship or aircraft, or other equipment that can monitor and / or report on its operating status or other functions associated with its operation.

[0128] As another example, the UE 1300 may implement or host one or more clients for an edge data network, such as an EEC, and in such a case, the UE 1300 may perform operations ascribed to such clients in the various methods or procedures described above.

[0129] In practice, any number of UEs may be used together for a single use case. For example, a first UE may be a drone or be integrated into a drone and provide drone speed information (obtained through a speed sensor) to a second UE that is a remote controller that operates the drone. When a user makes changes from the remote controller, the first UE may adjust the drone's throttle (e.g., by controlling an actuator) to increase or decrease the drone's speed. The first and / or second UE may also include more than one of the above-mentioned functionalities. For example, a UE may be equipped with sensors and actuators and handle communication of data for both the speed sensor and the actuator.

[0130] 14 illustrates a network node 1400 according to some embodiments. Examples of network nodes include, but are not limited to, access points (e.g., wireless access points), base stations (e.g., wireless base stations, Node Bs, eNBs, and gNBs).

[0131] Base stations may be categorized based on the amount of coverage they provide (or, alternatively, their transmit power levels), and may therefore be referred to as femto, pico, micro, or macro base stations, depending on the amount of coverage provided. A base station may also be a relay donor node that controls a relay node or a relay. A network node may include one or more (or all) parts of a distributed radio base station, also referred to as a centralized digital unit and / or a remote radio unit (RRU), such as a remote radio head (RRH). Such remote radio units may or may not be integrated with an antenna, such as an antenna-integrated radio. Some of the distributed radio base stations may also be referred to as nodes in a distributed antenna system (DAS).

[0132] Other examples of network nodes include multi-transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BS, network controllers such as radio network controllers (RNC) or base station controllers (BSC), base transceiver stations (BTS), transmission points, transmitting nodes, multi-cell / multicast coordination entities (MCE), operations and maintenance (O&M) nodes, operations support system (OSS) nodes, self-organizing network (SON) nodes, positioning nodes (e.g., evolved serving mobile location center (E-SMLC) and / or minimization drive test (MDT).

[0133] As another example, various servers (e.g., ECS and / or EES) of an edge data network may be implemented or hosted by one or more network nodes 1400. Each of these network nodes 1400 may then perform the operations ascribed to such servers in the various manners or procedures described above.

[0134] The network node 1400 includes a processing circuit 1402, a memory 1404, a communication interface 1406, and a power source 1408. The network node 1400 may be comprised of multiple physically separate components, each of which may have its own respective components (e.g., a Node B component and an RNC component, or a BTS component and a BSC component, etc.). In certain scenarios where the network node 1400 comprises multiple separate components (e.g., a BTS and a BSC component), one or more separate components may be shared between several network nodes. For example, a single RNC may control several Node Bs. In such scenarios, each unique pair of Node B and RNC may be considered as a single separate network node in some examples. In some embodiments, the network node 1400 may be configured to support several radio access technologies (RATs). In such embodiments, some components may be redundant (e.g., separate memories 1404 for different RATs) and some components may be reused (e.g., the same antenna 1410 may be shared by several different RATs). Network node 1400 may include multiple sets of the various illustrated components for various wireless technologies, such as GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID), or Bluetooth wireless technologies, that are integrated into network node 1400. These wireless technologies may be integrated on the same or different chips or sets of chips and other components within network node 1400.

[0135] The processing circuitry 1402 may include a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application specific integrated circuit, field programmable gate array, or any other suitable computing device, resource or combination of one or more of hardware, software and / or encoded logic operable alone or in combination with other network node 1400 components, such as memory 1404, to provide the functionality of the network node 1400.

[0136] In some embodiments, the processing circuitry 1402 may include a system on a chip (SOC). In some embodiments, the processing circuitry 1402 may include one or more of a radio frequency (RF) transceiver circuitry 1412 and a baseband processing circuitry 1414. In some embodiments, the RF transceiver circuitry 1412 and the baseband processing circuitry 1414 may be on separate chips (or sets of chips), boards, or units, such as a radio unit and a digital unit. In alternative embodiments, some or all of the RF transceiver circuitry 1412 and the baseband processing circuitry 1414 may be on the same chip or chipset, board, or unit.

[0137] The memory 1404 may include, but is not limited to, persistent storage, solid-state memory, remote mounted memory, magnetic media, optical media, random access memory (RAM), or other storage devices that store information, data, and / or instructions that may be used by the processing circuit 1402. Read-only Memory (ROM), large-scale storage media (e.g., hard disk), the law of natureThe memory 1404 may include any type of volatile or non-volatile computer readable memory, including removable storage media (e.g., flash drives, compact discs (CDs) or digital video discs (DVDs)) and / or any other volatile or non-volatile non-transitory device readable and / or computer executable memory devices. The memory 1404 may store any suitable instructions, data, or information, including applications (collectively computer programs 1404a, which may be in the form of a computer program product) that may be executed by the processing circuit 1402 and utilized by the network node 1400, including one or more of computer programs, software, logic, rules, codes, tables, and / or other instructions. The memory 1404 may be used to store any calculations performed by the processing circuit 1402 and / or any data received via the communications interface 1406. In some embodiments, the processing circuit 1402 and the memory 1404 are integrated.

[0138] The communication interface 1406 is used for wired or wireless communication of signaling and / or data between network nodes, access networks, and / or UEs. As shown, the communication interface 1406 includes a port / terminal 1416 for transmitting and receiving data to and from a network over a wired connection, for example. The interface 1406 also includes a radio front-end circuit 1418 that is connected to an antenna 1410 and may be part of the antenna 1410 in certain embodiments. The radio front-end circuit 1418 includes a filter 1420 and an amplifier 1422. The radio front-end circuit 1418 may be connected to the antenna 1410 and the processing circuit 1402. The radio front-end circuit may be configured to condition signals communicated between the antenna 1410 and the processing circuit 1402. The radio front-end circuit 1418 may receive digital data to be sent to another network node or UE over a wireless connection. The radio front-end circuitry 1418 may convert the digital data into a radio signal having appropriate channel and bandwidth parameters using a combination of filters 1420 and / or amplifiers 1422. The radio signal may then be transmitted via the antenna 1410. Similarly, when receiving data, the antenna 1410 collects the radio signal, which is converted into digital data by the radio front-end circuitry 1418. The digital data may be output to the processing circuitry 1402. In other embodiments, the communication interface may include different components and / or different combinations of components.

[0139] In certain alternative embodiments, the network node 1400 may not include a separate radio front-end circuit 1418; rather, the processing circuit 1402 includes the radio front-end circuitry and is connected to the antenna 1410. Similarly, in some embodiments, all or some of the RF transceiver circuitry 1412 is part of the communications interface 1406. In yet other embodiments, the communications interface 1406 may include one or more ports or terminals 1416, the radio front-end circuitry 1418, and the RF transceiver circuitry 1412 as part of a radio unit (not shown), and the communications interface 1406 may communicate with baseband processing circuitry 1414 that is part of a digital unit (not shown).

[0140] The antenna 1410 may include one or more antennas or an antenna array configured to transmit and / or receive wireless signals. The antenna 1410 is coupled to the radio front-end circuitry 1418 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In certain embodiments, the antenna 1410 may be separate from the network node 1400 and connectable to the network node 1400 via an interface or port.

[0141] The antenna 1410, the communication interface 1406 and / or the processing circuit 1402 may be configured to perform any receiving operation and / or certain acquisition operations described herein as being performed by a network node. Any information, data and / or signals may be received from a UE, other network nodes and / or any other network equipment. Similarly, the antenna 1410, the communication interface 1406 and / or the processing circuit 1402 may be configured to perform any transmitting operation described herein as being performed by a network node. Any information, data and / or signals may be transmitted to a UE, other network nodes and / or any other network equipment.

[0142] The power source 1408 provides power to the various components of the network node 1400 in a format appropriate for each component (e.g., at the voltage and current levels required for each respective component). The power source 1408 may include or be coupled to power management circuitry for providing power to the components of the network node 1400 to perform the functionality described herein. For example, the network node 1400 may be connectable to an external power source (e.g., a power grid, an electrical outlet) via an input circuit or interface, such as an electrical cable, such that the external power source provides power to the power source 1408. source As yet another example, power source 1408 may include a power source in the form of a battery or battery pack that is connected to or included in the power circuit. The battery may provide backup power in the event of failure of the external power source.

[0143] Embodiments of network node 1400 may include additional components beyond those shown in FIG. 14 to provide certain aspects of the functionality of the network node, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, network node 1400 may include a user interface that allows for the input of information into network node 1400 and the output of information from network node 1400. Face The network node 1400 may include equipment that may enable a user to perform diagnostics, maintenance, repair, and other administrative functions on the network node 1400.

[0144] 15 is a block diagram of a host 1500, which may be an embodiment of the host 1216 of FIG. 12, in accordance with various aspects described herein. As used herein, the host 1500 may refer to a hardware device in any combination, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, a container, or processing resources within a server farm. DouThe host 1500 may be or may include software and / or hardware. The host 1500 may provide one or more services to one or more UEs. As a specific example, the host 1600 may implement one or more servers of an edge data network (e.g., an ECS and / or an EES), including execution of various example methods resulting in such servers in the discussion above.

[0145] The host 1500 includes a processing circuit 1502 operably coupled via a bus 1504 to an input / output interface 1506, a network interface 1508, a power supply 1510, and a memory 1512. In other embodiments, other components may be included, the functionality of which may be substantially similar to those described with respect to the devices in previous figures, such as Figures 13 and 14, and therefore those descriptions are generally applicable to the corresponding components of the host 1500.

[0146] Memory 1512 may include one or more computer programs 1514 including one or more host application programs 1514 and data 1516 which may include user data, e.g., data generated by a UE for host 1500 or data generated by host 1500 for a UE. An embodiment of host 1500 may utilize all or only a subset of the components shown. Host application programs 1514 may be implemented in a container-based architecture and may provide support for video codecs (Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for different UE classes, types or implementations (e.g., handsets, desktop computers, wearable display systems, heads-up display systems). The host application program 1514 may also provide user authentication and license checks, and may periodically report health, route, and content availability to a central node, such as a device in or at the edge of the core network. Thus, the host 1500 may select and / or point to different hosts for over-the-top services for the UE. The host application program 1514 may support a variety of protocols, such as HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.

[0147] FIG. 16 is a block diagram illustrating a virtualization environment 1600 in which functionality implemented by some embodiments may be virtualized. In this context, virtualization means for generating a virtual version of an apparatus or device may include a virtualized hardware platform, storage devices, and networking resources. As used herein, virtualization may be applied to any device or component thereof described herein and refers to an implementation in which at least a portion of its functionality is implemented as one or more virtual components. Some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1600 hosted by one or more hardware nodes, such as a network node, a UE, a core network node, or a hardware computing device acting as a host. Furthermore, in embodiments in which a virtual node does not require wireless connectivity (e.g., a core network node or a host), the node may be virtualized in its entirety.

[0148] Applications 1602 (which may alternatively be referred to as software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) run in the virtualization environment 1600 to implement some of the features, functionality and / or benefits of embodiments disclosed herein. As a specific example, various servers (e.g., ECS and / or EES) of the edge data network described above may be implemented in the virtualization environment 1600 as applications, software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.

[0149] The hardware 1604 includes processing circuitry, memory for storing software and / or instructions executable by the hardware processing circuitry (collectively referred to as computer programs 1604a, which may be in the form of a computer program product), and / or other hardware devices described herein, such as network interfaces, input / output interfaces, etc. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1606 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1608a-b (one or more of which may be generally referred to as VMs 1608), and / or perform any of the functions, features, and / or advantages described in connection with some embodiments described herein. The virtualization layer 1606 may present a virtual operating platform that appears to be networking hardware to the virtual machines 1608.

[0150] The VMs 1608 may include virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and may be executed by a corresponding virtualization layer 1606. Various embodiments of instances of virtual appliances 1602 may be implemented in one or more of the VMs 1608, and the implementation may be done in various ways. Hardware virtualization is referred to in some contexts as network function virtualization (NFV). NFV may be used to consolidate many network equipment types into industry-standard, high-capacity server hardware, physical switches, and physical storage that may be located in data centers and customer premises equipment.

[0151] In the context of NFV, a VM 1608 may be a software implementation of a physical machine that runs programs as if they were running on a physical, non-virtualized machine. Each VM 1608 and the portion of the hardware 1604 on which it runs, whether the hardware is dedicated to that VM and / or shared by that VM with other VMs, forms a separate virtual network element. Also in the context of NFV, a virtual network function is responsible for handling specific network functions running in one or more VMs 1608 on top of the hardware 1604 and corresponds to the applications 1602.

[0152] The hardware 1604 may be implemented in a standalone network node with generic or proprietary components. The hardware 1604 may implement some functions via virtualization. Alternatively, the hardware 1604 may be part of a larger hardware cluster (such as in a data center or CPE) where multiple hardware nodes work together and are managed via management and orchestration 1610, which oversees, among other things, the lifecycle management of the application 1602. In some embodiments, the hardware 1604 is coupled to one or more radio units, each including one or more transmitters and one or more receivers, which may be coupled to one or more antennas. The radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces, or may be used in combination with virtual components to provide wireless capabilities to virtual nodes, such as radio access nodes or base stations. In some embodiments, some signaling may be provided with the use of a control system 1612, which may alternatively be used for communication between the hardware nodes and the radio units.

[0153] 17 illustrates a communication diagram of a host 1702 communicating with a UE 1706 via a network node 1704 over a partially wireless connection according to some embodiments. Exemplary implementations according to various embodiments of the UE (UE 1212a of FIG. 12 and / or UE 1300 of FIG. 13), network node (network node 1210a of FIG. 12 and / or network node 1400 of FIG. 14), and host (host 1216 of FIG. 12 and / or host 1500 of FIG. 15) discussed in the previous paragraphs will now be described with reference to FIG. 17.

[0154] Similar to the host 1500, an embodiment of the host 1702 includes hardware such as communications interfaces, processing circuitry, and memory. The host 1702 further includes software stored within or accessible by the host 1702 and executable by the processing circuitry. The software includes a host application that may be operable to provide services to a remote user, such as a UE 1706 connecting via an over-the-top (OTT) connection 1750 extending between the UE 1706 and the host 1702. During the provision of services to the remote user, the host application may provide user data that is transmitted using the OTT connection 1750.

[0155] The network node 1704 includes hardware that enables communication with the host 1702 and the UE 1706. The connection 1760 may be direct or may pass through one or more other intermediate networks, such as a core network (such as the core network 1206 of FIG. 12) and / or one or more public, private, or hosted networks. For example, the intermediate network may be a backbone network or the Internet.

[0156] The UE 1706 also includes software stored in or accessible by the UE 1706 and executable by the UE's processing circuitry. The software includes a client application, such as a web browser or an operator-specific "app," that may be operable to provide services to a human or non-human user via the UE 1702 with the support of the host 1706. A host application running in the host 1702 may communicate with the client application running in the UE 1706 through an OTT connection 1750 that terminates in the host 1702. During the provision of services to a user, the client application in the UE may receive request data from the host application in the host and provide user data in response to the request data. The OTT connection 1750 may transport both request data and user data. The client application in the UE may interact with the user to generate user data that it provides to the host application through the OTT connection 1750.

[0157] The OTT connection 1750 may extend through a connection 1760 between the host 1702 and a network node 1704, and through a wireless connection 1770 between the network node 1704 and the UE 1706, providing a connection between the host 1702 and the UE 1706. The connection 1760 and the wireless connection 1770 over which the OTT connection 1750 may be provided are depicted abstractly to illustrate communication between the host 1702 and the UE 1706 through the network node 1704, without explicit reference to any intermediate devices and the exact routing of messages through those devices.

[0158] As an example of transmitting data over the OTT connection 1750, in step 1708, the host 1702 provides user data, which may be done by executing a host application. In some embodiments, the user data is associated with a particular human user interacting with the UE 1706. In other embodiments, the user data is associated with the UE 1706 sharing data with the host 1702 without explicit human interaction. In step 1710, the host 1702 initiates a transmission to the UE 1706 carrying user data. The host 1702 may initiate the transmission in response to a request transmitted by the UE 1706. The request may be triggered by human interaction with the UE 1706 or by operation of a client application running on the UE 1706. In accordance with the teachings of the embodiments described throughout this disclosure, the transmission may pass through the network node 1704. In response, at step 1712, the network node 1704 transmits the user data carried in the transmission initiated by the host 1702 to the UE 1706 in accordance with the teachings of the embodiments described throughout this disclosure. At step 1714, the UE 1706 receives the user data carried in the transmission, which may be performed by a client application executing on the UE 1706 that is associated with the host application executed by the host 1702.

[0159] In some examples, the UE 1706 executes a client application, which provides user data destined for the host 1702. The user data may be provided in reaction or response to receiving the data from the host 1702. In response, the UE 1706 may provide the user data, which may be done by executing the client application, at step 1716. During the provision of the user data, the client application may further take into account user input received from the user via an input / output interface of the UE 1706. Regardless of the specific manner in which the user data is provided, the UE QQ 1706 initiates transmission of the user data to the host QQ 1702 via the network node 1704 at step 1718. At step 1720, the network node 1704 receives the user data from the UE 1706 and initiates transmission of the received user data to the host 1702, in accordance with the teachings of the embodiments described throughout this disclosure. At step 1722, the host 1702 receives the user data carried in the transmission initiated by the UE 1706.

[0160] One or more various embodiments improve the performance of OTT services provided to the UE 1706 using the OTT connection 1750, of which the radio connection 1770 forms the final segment. These and other embodiments described herein can provide a clear and unambiguous way for the EEC to obtain and use a UE ID (i.e., of the UE hosting the EEC) for authentication and / or authorization purposes, thereby facilitating security of EC applications over 3GPP networks (e.g., 5GC and NG-RAN). When edge computing is deployed in this way to provide and support OTT data services, it increases the value of such services to end users and service providers.

[0161] In an example scenario, factory status information may be collected and analyzed by the host 1702. As another example, the host 1702 may process audio and video data, which may have been obtained from UEs, for use in generating maps. As another example, the host 1702 may collect and analyze real-time data to assist in controlling vehicle congestion (e.g., controlling traffic lights). As another example, the host 1702 may store surveillance video uploaded by UEs. As another example, the host 1702 may store or control access to media content, such as video, audio, VR or AR, that may be broadcast, multicast or unicast to UEs. As another example, the host 1702 may be used for energy pricing, remote control of non-time-critical power loads for balancing power generation needs, location services, presentation services (e.g., compiling diagrams from data collected from remote devices), or any other function that collects, acquires, stores, analyzes and / or transmits data.

[0162] In some examples, measurement procedures may be provided to monitor data rates, latency, and other factors that are improved by one or more embodiments. Additionally, there may be optional network functionality to reconfigure the OTT connection 1750 between the host 1702 and the UE 1706 in response to variations in the measurements. The measurement procedures and / or network functionality to reconfigure the OTT connection may be implemented in software and hardware of the host 1702 and / or the UE 1706. In some embodiments, sensors (not shown) may be deployed in or associated with other devices through which the OTT connection 1750 passes, and these sensors may participate in the measurement procedures by providing values ​​for the monitored quantities exemplified above or providing values ​​for other physical quantities from which the monitored quantities may be calculated or estimated by the software. The reconfiguration of the OTT connection 1750 may include message formats, retransmission settings, preferred routing, etc., and the reconfiguration need not directly change the operation of the network node 1704. Such procedures and functionality may be known or practiced in the art. In one embodiment, the measurements may include proprietary UE signaling to facilitate measurements of throughput, propagation time, delay, etc. by the host 1702. The measurements may be implemented by software sending messages over the OTT connection 1750, specifically empty or "dummy" messages, while monitoring propagation time, errors, etc.

[0163] The foregoing merely illustrates the principles of the present disclosure. Various modifications and alterations to the described embodiments will be apparent to those skilled in the art in view of the teachings herein. Thus, it will be appreciated that those skilled in the art can devise numerous systems, arrangements and procedures that, although not explicitly shown or described herein, embody the principles of the present disclosure and thus are within the spirit and scope of the present disclosure. As should be understood by those skilled in the art, the various exemplary embodiments can be used together and interchangeably with one another.

[0164] The term unit has its conventional meaning in the art of electricity, electrical devices, and / or electronic devices and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logical solid state and / or discrete devices, computer programs or instructions described herein for performing respective tasks, procedures, computations, output, and / or display functions, etc.

[0165] Any suitable steps, methods, features, functions, or advantages disclosed herein may be performed through one or more functional units or modules of one or more virtual devices. Each virtual device may include multiple such functional units. These functional units may include processing circuitry, which may include one or more microprocessors or microcontrollers, and other digital hardware, which may include digital signal processors (DSPs), dedicated digital logic, and the like. The processing circuitry is configured to execute program code stored in memory, which may include one or more types of memory, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, and the like. The program code stored in memory includes program instructions for implementing one or more communication and / or data communication protocols and, in some embodiments, program instructions for performing one or more of the techniques described herein. In some embodiments, the processing circuitry may be used to cause each functional unit to perform a function corresponding to the respective functional unit in accordance with one or more embodiments.

[0166] As described herein, a device and / or an apparatus may be represented by a semiconductor chip, a chipset, or a (hardware) module including such a chip or chipset, but this does not exclude the possibility that the functionality of the device or apparatus is not implemented in hardware but is implemented as a software module, such as a computer program or computer program product including executable software code portions executed or performed by a processor. Furthermore, the functionality of a device or an apparatus may be implemented by any combination of hardware and software. A device or an apparatus may also be considered as an assembly of multiple devices and / or apparatus, whether functionally cooperating with each other or independent of each other. Furthermore, devices and apparatus may be implemented distributed throughout a system, as long as the functionality of the device or apparatus is maintained. Such similar principles are deemed to be known to those skilled in the art.

[0167] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which this disclosure belongs. Furthermore, terms used herein should be interpreted to have a meaning consistent with their meaning in the context of this specification and related art, and should not be interpreted in an ideal or overly formal sense unless expressly defined herein.

[0168] Additionally, certain terms used in this disclosure, including the specification and drawings, may be used synonymously in certain instances (e.g., "data" and "information"). Although these terms (and / or other terms that may be synonymous with each other) may be used synonymously herein, it is to be understood that there may be instances where such terms are not intended to be used synonymously.

Claims

1. 1. A method for an edge data network client, comprising: receiving (910) from a first server of the edge data network a user equipment identifier (UE ID) hosting the client during or after authentication and / or authorization of the client by the first server; During authentication and / or authorization of the client by a second server of the edge data network, transmitting (920) the UE ID to the second server; The method includes:

2. 2. The method of claim 1 , the UE ID is included in an access token received from the first server; The access token, including the UE ID, is sent to the second server.

3. 3. The method of claim 2, The access token is included in a service provisioning response from the first server.

4. 4. The method according to claim 2 or 3, sending the access token to the second server along with an indication that the access token includes the UE ID; receiving the access token from the first server along with an indication that the access token includes the UE ID; The method according to claim 1, wherein one or more of the following is applied:

5. 2. The method of claim 1 , the UE ID is received from the first server in a service provisioning response that does not include an access token for the second server; the UE ID is sent to the second server in a request that does not include an access token for the second server; The method according to claim 1, wherein one or more of the following is applied:

6. 6. The method according to any one of claims 1 to 5, The method, wherein the client is an edge enabler client (EEC), the first server is an edge configuration server (ECS), and the second server is an edge enabler server (EES).

7. 7. The method according to any one of claims 1 to 6, comprising: The method, wherein the UE ID is a Universal Public Subscriber Identifier (GPSI).

8. 1. A method for a first server of an edge data network, comprising: - obtaining (1010) during or after authentication and / or authorization of a client of the edge data network by the first server, an identifier of a user equipment (UE ID) hosting said client; sending (1020) the UE ID to the client for authentication and / or authorization of the client by a second server of the edge data network; The method includes:

9. 9. The method of claim 8, The UE ID is a Universal Public Subscriber Identifier (GPSI); an authentication and key management (AKMA) procedure for applications with a communication network connected to the edge data network; a Generic Bootstrap Architecture (GBA) procedure with said communication network; IP address to GPS conversion, The method is obtained based on any one of the following:

10. 10. The method according to claim 8 or 9, The UE ID is sent to the client in an access token for the second server.

11. 11. The method of claim 10, The access token is included in a service provisioning response to the client.

12. 12. The method according to claim 10 or 11, The access token is sent to the client along with an indication that the access token includes the UE ID.

13. 10. The method according to claim 8 or 9, The UE ID is sent to the client in a service provisioning response that does not include an access token for the second server.

14. 14. The method according to any one of claims 8 to 13, comprising: The method, wherein the client is an edge enabler client (EEC), the first server is an edge configuration server (ECS), and the second server is an edge enabler server (EES).

15. 1. A method for a second server of an edge data network, comprising: receiving (1110) from a client of the edge data network a user equipment identifier (UE ID) hosting the client, the UE ID having been provided to the client by a first server of the edge data network; performing (1120) authentication and / or authorization of the client based on the received UE ID; The method includes:

16. 16. The method of claim 15, the UE ID is received within an access token for the second server from the client; The access token is generated by the first server; A method, wherein authentication and / or authorization of the client is performed based on the access token.

17. 17. The method of claim 16, The method of claim 1, wherein the access token is received from the client along with an indication that the access token includes the UE ID.

18. 16. The method of claim 15, The UE ID is received from the client in a request that does not include an access token for the second server.

19. 19. The method according to any one of claims 15 to 18, comprising: The method, wherein the client is an edge enabler client (EEC), the first server is an edge configuration server (ECS), and the second server is an edge enabler server (EES).

20. 20. The method according to any one of claims 15 to 19, comprising: The method, wherein the UE ID is a Universal Public Subscriber Identifier (GPSI).

21. A user equipment (UE) (300, 1212, 1300, 1706) configured to host a client (310, 710, 810) of an edge data network (320), comprising: a communications interface circuit (1312) configured to facilitate communications between the client and a first server and a second server (330, 340, 720, 730, 820, 830, 1216, 1500, 1602, 1702) of the edge data network; a processing circuit (1302) operably connected to said communication interface circuit; Equipped with The processing circuit and the communication interface circuit include receiving an identifier (UE ID) of the UE from a first server of the edge data network during or after authentication and / or authorization of the client by the first server; during authentication and / or authorization of the client by a second server of the edge data network, transmitting the UE ID to the second server; The UE is configured to:

22. 22. The UE of claim 21, A UE, wherein the processing circuitry and the communications interface circuitry are further configured to perform operations corresponding to a method according to any one of claims 2 to 7.

23. A user equipment (UE) (300, 1212, 1300, 1706) configured to host a client (310, 710, 810) of an edge data network (320), comprising: receiving an identifier (UE ID) of the UE from a first server (330, 720, 820, 1216, 1500, 1602, 1702) of the edge data network during or after authentication and / or authorization of the client by the first server; During authentication and / or authorization of the client by a second server of the edge data network, transmitting the UE ID to the second server (340, 730, 830, 1216, 1500, 1602, 1702); The UE is configured to:

24. 24. The UE of claim 23, The client, UE, is further configured to perform operations corresponding to the method of any one of claims 2 to 7.

25. A non-transitory computer-readable medium (1310) storing computer-executable instructions that, when executed by a processing circuit (1302) associated with a client (310, 710, 810) of an edge data network (320), configures the client to perform operations corresponding to the methods described in any one of claims 1 to 7.

26. A computer program product (1314) including computer-executable instructions that, when executed by a processing circuit (1302) associated with a client (310, 710, 810) of an edge data network (320), configures the client to perform operations corresponding to the methods recited in any one of claims 1 to 7.

27. a first server (330, 720, 820, 1216, 1500, 1602, 1702) configured to operate in an edge data network (320), a communications interface circuit (1508, 1604) configured to communicate with one or more clients (310, 710, 810) of the edge data network; a processing circuit (1502, 1604) operably connected to said interface circuit; Equipped with The processing circuit and the communication interface circuit include - obtaining, during or after authentication and / or authorization of a client of the edge data network by the first server, an identifier (UE ID) of a user equipment (300, 1212, 1300, 1706) hosting said client; sending the UE ID to the client for authentication and / or authorization of the client by a second server (340, 730, 830, 1216, 1500, 1602, 1702) of the edge data network; A first server configured to:

28. 28. A first server according to claim 27, 15. A first server, wherein the processing circuitry and the communications interface circuitry are further configured to perform operations corresponding to a method according to any one of claims 9 to 14.

29. a first server (330, 720, 820, 1216, 1500, 1602, 1702) configured to operate in an edge data network (320), - obtaining, during or after authentication and / or authorization of a client (310, 710, 810) of the edge data network by the first server, an identifier (UE ID) of a user equipment (300, 1212, 1300, 1706) hosting said client; sending the UE ID to the client for authentication and / or authorization of the client by a second server (340, 730, 830, 1216, 1500, 1602, 1702) of the edge data network; A first server configured to:

30. 30. A first server according to claim 29, A first server configured to perform operations corresponding to the method of any one of claims 9 to 14.

31. A non-transitory computer-readable medium (1512, 1604) storing computer-executable instructions that, when executed by a processing circuit (1502, 1604) associated with a first server (330, 720, 820, 1216, 1500, 1602, 1702) configured to operate in an edge data network (320), configures the first server to perform operations corresponding to the methods described in any one of claims 8 to 14.

32. A computer program product (1514, 1604) including computer-executable instructions that, when executed by a processing circuit (1502, 1604) associated with a first server (330, 720, 820, 1216, 1500, 1602, 1702) configured to operate in an edge data network (320), configures the first server to perform operations corresponding to the methods described in any one of claims 8 to 14.

33. a second server (340, 730, 830, 1216, 1500, 1602, 1702) configured to operate in the edge data network (320), a communications interface circuit (1508, 1604) configured to communicate with one or more clients (310, 710, 810) of the edge data network; a processing circuit (1502, 1604) operably connected to said interface circuit; Equipped with The processing circuit and the communication interface circuit include receiving, from a client of the edge data network, an identifier (UE ID) of a user equipment (300, 1212, 1300, 1706) hosting the client, the UE ID having been provided to the client by a first server (330, 720, 820, 1216, 1500, 1602, 1702) of the edge data network; performing authentication and / or authorization of the client based on the received UE ID; a second server configured to:

34. 34. A second server according to claim 33, A second server, wherein the processing circuitry and the communications interface circuitry are further configured to perform operations corresponding to a method according to any one of claims 16 to 20.

35. a second server (340, 730, 830, 1216, 1500, 1602, 1702) configured to operate in the edge data network (320), receiving, from a client of the edge data network, an identifier (UE ID) of a user equipment (300, 1212, 1300, 1706) hosting said client, said UE ID being provided to said client by a first server (330, 720, 820, 1216, 1500, 1602, 1702) of the edge data network; performing authentication and / or authorization of the client based on the received UE ID; a second server configured to:

36. A second server according to claim 35, configured to perform operations corresponding to the method according to any one of claims 16 to 20.

37. A non-transitory computer-readable medium (1512, 1604) storing computer-executable instructions that, when executed by a processing circuit (1512, 1604) associated with a second server (340, 730, 830, 1216, 1500, 1602, 1702) configured to operate in an edge data network (320), configures the second server to perform operations corresponding to the methods described in any one of claims 15 to 20.

38. A computer program product (1514, 1604) of computer-executable instructions that, when executed by a processing circuit (1512, 1604) associated with a second server (340, 730, 830, 1216, 1500, 1602, 1702) configured to operate in an edge data network (320), configures the second server to perform operations corresponding to the methods described in any one of claims 15 to 20.

Citation Information

Patent Citations

  • Authorization method and device

    CN114268943A