Message Routing Method, Apparatus, System, Storage Medium, and Electronic Device
The method and apparatus optimize message routing by directly routing service requests to HPLMN NFs using user identifiers and NRF discovery parameters, addressing signaling detours and improving network efficiency.
Patent Information
- Application Number
- JP2024577341
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-29
- Filing Date
- 2023-05-12
- Publication Date
- 2025-07-10
- Estimated Expiration
- 2043-05-12
AI Technical Summary
Signaling detour occurs between Visited Public Land Mobile Networks (VPLMN) and Home Public Land Mobile Networks (HPLMN), leading to increased processing delays and resource overhead in network interactions.
A method and apparatus for routing messages through a security edge protection proxy (SEPP) that directly routes service request messages to the appropriate network function (NF) within the HPLMN using user identifiers and NRF discovery parameters, reducing the need for inter-PLMN discovery and signaling interactions.
Reduces processing delays and network resource overhead by minimizing signaling detours and interactions between PLMNs, optimizing network efficiency and bandwidth usage.
Smart Images

Figure 2025521850000001_ABST
Abstract
Description
Cross-reference to Related Applications
[0001] This disclosure claims the priority of Chinese Patent Application No. CN202210760237.4, titled "Message Routing Method, Apparatus, and System", filed on June 29, 2022, and all of its content is incorporated herein by reference in its entirety.
Technical Field
[0002] This disclosure relates to the field of communications, and more specifically, to a message routing method, apparatus, and system.
Background Art
[0003] In some cases, a network that roams between 5G SA (Standalone) defined by 3GPP (registered trademark) and a PLMN (Public Land Mobile Network) includes a SEPP (Security Edge Protection Proxy), an AMF (Access and Mobility Management Function), a UDM (Unified Data Management), an NRF (NF Repository Function), and the like.
[0004] In some cases, SEPP is responsible for transferring control plane signaling for interactions between PLMNs as a security edge protection proxy for the PLMN. As an example, consider a typical Visited Public Land Mobile Network (VPLMN) AMF network element accessing a UDM network element in a Home Public Land Mobile Network (HPLMN). FIG. 1 is an interactive flowchart between PLMNs in the related art of the present disclosure. As can be seen from the interactive process in FIG. 1, in some cases, there is a technical problem of signaling detour from the VPLMN to the HPLMN.
Summary of the Invention
Problems to be Solved by the Invention
[0005] The present disclosure provides a method, apparatus, and system for routing messages to at least solve the technical problem of signaling detour when interacting between PLMNs in some cases.
[0006] According to an embodiment of the present disclosure, a method for routing a message applied to a security edge protection proxy VSEPP of a visited public land mobile network is provided. The method includes receiving a service request message and a first routing parameter transmitted by a first network function NF, where the first routing parameter carries a network repository function NRF discovery parameter and a user identifier, the first NF stays within the visited public land mobile network VPLMN, and routing the service request message and the NRF discovery parameter to a security edge protection proxy HSEPP of the home public land mobile network according to the user identifier, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameter, where the second NF stays within the home public land mobile network HPLMN.
[0007] According to an embodiment of the present disclosure, there is provided a routing method for another message applied to a security edge protection proxy HSEPP of a local public land mobile communication network. This method includes receiving a service request message and a second routing parameter routed by a security edge protection proxy VSEPP of a visited public land mobile communication network, and routing the service request message to a second network function NF according to the second routing parameter, where the second NF stays within the HPLMN, receiving a response message returned by the second NF based on the service request message, and sending the response message to the VSEPP.
[0008] According to another embodiment of the present disclosure, there is provided a message routing apparatus applied to a security edge protection proxy VSEPP of a visited public land mobile communication network. This apparatus includes a first receiving module configured to receive a service request message and a first routing parameter sent by a first network function NF, where the first routing parameter carries network repository function NRF discovery parameters and a user identifier, and the first NF stays within the visited public land mobile communication network VPLMN, and a routing module configured to route the service request message and the NRF discovery parameters to a security edge protection proxy HSEPP of a local public land mobile communication network according to the user identifier, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameters, where the second NF stays within the local public land mobile communication network HPLMN.
[0009] According to another embodiment of the present disclosure, there is provided a routing device for another message applied to a security edge protection proxy HSEPP of a local public land mobile communication network. This device includes a first receiving module configured to receive a service request message routed by a security edge protection proxy VSEPP of a visited public land mobile communication network and a second routing parameter, and a routing module configured to route the service request message to a second network function NF according to the second routing parameter, where the second NF stays within the HPLMN, a second receiving module configured to receive a response message returned by the second NF based on the service request message, and a transmitting module configured to transmit the response message to the VSEPP.
[0010] According to still another embodiment of the present disclosure, there is further provided a message routing system including a security edge protection proxy VSEPP of a visited public land mobile communication network including the device described in the above embodiment and a security edge protection proxy HSEPP of a local public land mobile communication network including the device described in the above embodiment.
[0011] According to still another embodiment of the present disclosure, there is further provided a computer-readable storage medium storing a computer program, where the computer program is configured to execute the steps in the method embodiment of any one of the above when executed.
[0012] According to still another embodiment of the present disclosure, there is further provided an electronic device including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to execute the computer program to execute the steps in the method embodiment of any one of the above.
[0013] The drawings described herein are provided for a further understanding of the present disclosure, are constituted as a part of the present disclosure, and the exemplary embodiments and the description thereof of the present disclosure are used to explain the present disclosure and are not intended to unduly limit the present disclosure.
Brief Description of the Drawings
[0014]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Modes for Carrying Out the Invention
[0015] Hereinafter, the present invention will be described in detail in conjunction with embodiments with reference to the accompanying drawings. It should be noted that the embodiments of the present disclosure and the features in the embodiments may be combined without conflict.
[0016] Note that terms such as "first", "second", etc. in the specification, claims, and the above-mentioned drawings of the present disclosure are used to distinguish similar objects, but are not necessarily used to describe a specific order or sequence.
[0017] In some cases, the SEPP transfers control plane signaling for interaction between PLMNs as a security edge protection proxy for the PLMN. As an example, it is taken that an AMF network element of a typical VPLMN (Visited Public Land Mobile Network) accesses a UDM network element in an HPLMN (Home Public Land Mobile Network). FIG. 1 is an interactive flowchart between PLMNs of the related art of the present disclosure. As can be seen from the interactive process in FIG. 1, in some cases, there is a signaling detour from the VPLMN to the HPLMN, resulting in a large delay in service processing. All response messages for service discovery are relatively large, a large amount of bandwidth resources are required between the VPLMN and the HPLMN, the AMF of the VPLMN needs to subscribe to the state of the UDM of the HPLMN, and a UDM state change notification needs to be sent between the VPLMNs, and there is a high possibility that the notification cannot be reached and affects the service.
[0018] Example 1 Examples of the method according to Example 1 of the present disclosure may be executed on a base station, a server, a base station controller, or a similar network element. Taking execution on a server as an example, FIG. 1 is a hardware structure block diagram of a message routing server according to the present disclosure. As shown in FIG. 1, the server may include one or more (only one is shown in FIG. 1) processors 102 (the processor 102 may include a processing device such as a microprocessor MCU or a programmable logic device FPGA, but is not limited thereto), and a memory 104 for storing data. In an exemplary embodiment, the above-mentioned server may further include a transmitting device 106 and an input / output device 108 for communication functions. Those skilled in the art can understand that the structure shown in FIG. 1 is merely an example and does not limit the structure of the above-mentioned server. For example, the server may further include more or fewer components than those shown in FIG. 1, or a configuration different from that shown in FIG. 1.
[0019] The memory 104 may be used to store computer programs, such as software programs and modules of application software, such as a computer program corresponding to the message routing method in the present disclosure. The processor 102 executes the computer program stored in the memory 104 to execute various functional applications and data processing, that is, to implement the above method. The memory 104 may include high-speed random access memory, and may further include one or more magnetic storage devices, flash memory, or other non-volatile solid memories. In some examples, the memory 104 may further include a memory disposed remotely from the processor 102, and these remote memories may be connected to the server via a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0020] The transmitting device 106 is used to transmit and receive data via a network. Specific examples of the above-described network may include a wireless network provided by a server communication carrier, etc. In one example, the transmitting device 106 includes a Network Interface Controller (abbreviated as NIC) that can be connected to other network devices via a server to communicate with the Internet. In one example, the transmitting device 106 may be a Radio Frequency (RF) module for wirelessly communicating with the Internet.
[0021] In this embodiment, a method for routing messages is provided. FIG. 3 is a flowchart of the message routing method according to the present disclosure. As shown in FIG. 3, it is applied to a Visited Public Land Mobile Network Security Edge Protection Proxy (VSEPP), and the process includes the following steps.
[0022] Step S302: Receive a service request message and a first routing parameter transmitted by a first Network Function (NF), where the first routing parameter carries a Network Repository Function (NRF) discovery parameter and a user identifier, and the first NF stays within a visited Public Land Mobile Network (VPLMN).
[0023] In an exemplary embodiment, the user identifier may be a SUPI (SUbs cription Permanent Identifier), and the first NF is connected to a User Equipment (UE). When the UE initiates a service request to the first NF, it uses its own SUPI.
[0024] FIG. 4 is a network architecture diagram applied to the present disclosure. Messages are roamed between two networks, a VPLMN and an HPLMN. The VPLMN includes network elements such as an AMF, an SMF (Session Management Function), an (R)AN (Access Network or Radio Access Network), a UPF (User plan Function), an NSSF (Network Slice Selection Function), an NEF (Network Exposure Function), an NRF (NF Repository Function), a PCF (Policy Control function), a VSEPP, etc. The HPLMN includes network elements such as a UDM, an NRF, an NEF, an NSSF, an HSEPP, an SMF, an AUSF (Authentication Server Function), a PCF, an AF (Application Function), an NSSAAF (Network Slice-Specific Authentication and Authorization Function), a UPF, a DN (Data network, such as operator services, Internet access, third-party services), etc.
[0025] Step S304: Route the service request message and the NRF discovery parameter according to the user identifier to the security edge protection proxy HSEPP of the local public land mobile network, so that the HSEPP routes the service request message to a second NF according to the NRF discovery parameter, where the second NF stays within the HPLMN.
[0026] The first NF in this embodiment is another network element in the VPLMN that can initiate a service request, excluding VSEEP, such as the AMF. The second NF is another network element in the HPLMN that can process a service request, excluding HSEEP, such as the UDM. FIG. 5 is a network architecture diagram of the PLMN in the present disclosure, including the first NF and the second NF, which are respectively a network element that initiates service access in the VPLMN and a network element that responds to service access. vSEPP is the SEPP network element of the VPLMN network, and hSEPP is the SEPP network element of the HPLMN network.
[0027] By the above steps, a service request message and a first routing parameter transmitted by the first network function NF are received. The first routing parameter carries a network repository function NRF discovery parameter and a user identifier. The first NF stays within the visited public land mobile network VPLMN. According to the user identifier, the service request message and the NRF discovery parameter are routed to the home security edge protection proxy HSEPP of the local public land mobile network. Then, HSEPP routes the service request message to the second NF according to the NRF discovery parameter. The second NF stays within the HPLMN. VSEPP no longer executes the discovery request for the second NF, and directly routes the NRF discovery parameter carrying the network repository function to HSEPP. HSEPP executes the discovery request and routes the service request message, reducing the detour of messages between PLMNs, solving the technical problem in the related art of the detour of interactive signaling between PLMNs, reducing the number of signaling interactions during service processing, and reducing the processing delay and network resource overhead.
[0028] In this embodiment, according to the user identifier, after routing the service request message and the NRF discovery parameters to the security edge protection proxy HSEPP of the local public land mobile network, receiving a response message from the second NF returned by the HSEPP, where the response message is a response message generated by the second NF after receiving the service request message and completing the service processing, and further including transmitting the response message to the first NF.
[0029] In an exemplary embodiment, when routing a message between PLMNs, the first NF directly sends an HTTP2 Service Request message carrying the NRF Discovery (NRF discovery) parameters to the VPLMN SEPP in the VPLMN network. Receiving the service request message and the first routing parameters sent by the first NF includes receiving the HTTP2 Service Request message sent by the first NF, and the service request message includes the HTTP2 Service Request message carrying the first routing parameters.
[0030] In one example, the HTTP2 Service Request message carries the first routing parameters, namely the user permanent identifier SUPI for accessing the UE, the authorization identifier, and the NRF discovery identifier. Here, the authorization identifier is used to indicate the FQDN (Fully Qualified Domain Name) or IP address of the VSEPP that interacts with the HPLMN to which the user permanent identifier SUPI belongs, and the NRF discovery identifier is used to indicate the discovery parameters required for the first NF to discover the second NF.
[0031] The first NF requires the second NF to perform an interaction. The first NF determines that the user belongs to the HPLMN based on the user's SUPI identifier. The first NF encapsulates an HTTP request message that includes at least the FQDN or IP address of the SEPP for interacting with the HPLMN to which the user SUPI belongs in Authority (authorization identifier) = VPLMN, and the routing parameter 3gpp-Sbi-Discovery-*=*(NRF discovery identifier), where * is a general term carrying the discovery parameters required for the AMF to discover the UDM.
[0032] In this embodiment, a routing method for another message is provided. FIG. 6 is a flowchart of a routing method for another message according to the present disclosure applied to the HSEPP. As shown in FIG. 6, the process includes the following steps S602 to S608.
[0033] Step S602: Receive a service request message routed by the security edge protection proxy VSEPP of the visited public land mobile network and a second routing parameter.
[0034] In one example, the second routing parameter includes the FQDN or IP address of the HSEPP and the network repository function NRF discovery parameter carried by the first routing parameter.
[0035] Step S604: Route the service request message to a second network function NF according to the second routing parameter, where the second NF stays within the HPLMN.
[0036] Step S606: Receive a response message returned by the second NF based on the service request message.
[0037] Step S608: Send the response message to the VSEPP.
[0038] In one embodiment of this embodiment, routing the service request message to the second network function NF according to the second routing parameter includes: S11, creating a discovery request message using the second routing parameter carrying the network repository function NRF discovery parameter and the fully qualified domain name FQDN or IP address of the NRF in the HPLMN; S12, sending a request message to the NRF in the HPLMN; and S13, routing the service request message to the second NF according to the discovery result returned by the NRF.
[0039] In an example, routing the service request message to the second NF according to the discovery result returned by the NRF includes receiving several second NF identifiers returned by the NRF based on the request message, and among the several second NF identifiers, selecting the target second NF and sending the service request message to the target second NF.
[0040] Interpret and explain the solution of this embodiment in detail with the first NF being the AMF and the second NF being the UDM. FIG. 7 is an interactive diagram of the UDM accessed by the AMF of the VPLMN in the present disclosure and includes the following steps.
[0041] Step 1, the AMF needs to interact with the UDM. The AMF determines that the user belongs to the HPLMN according to the user's SUPI identifier. The AMF encapsulates an HTTP2 request message. The HTTP request message contains at least the FQDN or IP address of the VSEPP for interacting with the HPLMN to which the user SUPI belongs in :authority=VPLMN, and the routing parameter 3gpp-Sbi-Discovery-*=*, where * is a general term carrying the discovery parameters required for the AMF to discover the UDM. The AMF sends the message to the SEPP (VSEPP, i.e., VPLMN SEPP) in the pre-configured VPLMN for interacting with the HPLMN to which the user SUPI belongs.
[0042] Step 2, the VPLMN SEPP receives the HTTP2 request message sent by the AMF, reads the user identifier, obtains the SEPP information of the HPLMN to which the user SUPI belongs based on the routing policy information, encapsulates the HTTP2 request message. The HTTP2 request message contains at least the FQDN or IP address of the SEPP in :authority=HPLMN, and the routing parameter 3gpp-Sbi-Discovery-*=*, where * is a general term, and directly transfers the parameters carried by the AMF.
[0043] Step 3, the hSEPP receives the service request sent from the vSEPP, obtains the 3gpp-Sbi-Discovery-* related parameters from the request, encapsulates an NRF discovery request containing the parameter of the FQDN or IP address of the NRF in :authority=HPLMN, inputs the service discovery related parameters according to the 3gpp-Sbi-Discovery-* parameters carried by the vSEPP, and the hSEPP sends the NRF discovery request to the NRF in the HPLMN.
[0044] Step 4, the HPLMN NRF returns the discovery result of the UDM including at least the FQDN or IP address of the available UDMNFs.
[0045] Step 5, the hSEPP receives the discovery result of the UDM returned by the NRF, selects a UDM from one or more UDM NFs, and sends the service request received in Step 3, which includes the parameter :authority=FQDN or IP address of the UDM, to the selected UDM, and instructs to delete the relevant 3gpp-Sbi-Discovery-* parameters.
[0046] Step 6, the UDM receives the request message, completes the service processing, and returns the response message to the hSEPP via the original route.
[0047] Step 7, the hSEPP returns the response message to the vSEPP via the original route.
[0048] Step 8, the vSEPP returns the response message to the AMF via the original route.
[0049] Step 9, end.
[0050] Using the solution of this embodiment, the VPLMN NF directly sends the signaling carrying the NRF Discovery parameter to the SEPP without performing discovery between PLMNs. The VPLMN routes the message to the HPLMN SEPP according to the user identifier in the signaling. The HPLMN obtains the NRF Discovery parameter from the signaling and sends it to the NRF to perform service discovery. The target NF is obtained from the service discovery result, and the message is transferred to the target NF.
[0051] The solution means of this embodiment optimizes the process in the related art, reduces the number of signaling interactions, changes the number of signaling interactions between PLMNs from two to one, improves network efficiency, there is no detour of signaling in the signaling interaction between PLMNs, the delay is small, and there is no need to transmit the NRF service discovery result between PLMNs. Since the message of the NRF service discovery result is relatively large, the solution means of this embodiment reduces the bandwidth requirement.
[0052] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments may be implemented by software and a general hardware platform required, and of course, may also be implemented by hardware. In many cases, the former is a better embodiment. Based on such an understanding, the technical solution of the present disclosure can essentially implement the part that contributes to the prior art in the form of a software product. The computer software product is stored in a storage medium (for example, ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (such as a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present disclosure.
[0053] Embodiment 2 In this embodiment, a message routing device and system are further provided. The device is used to implement the above embodiments and preferred embodiments, and the content already described will not be repeated. As used below, the term "module" may be implemented as a combination of software and / or hardware with a predetermined function. The device described in the following embodiments is preferably implemented by software, but implementation by hardware or a combination of software and hardware is also possible and conceivable.
[0054] FIG. 8 is a structural block diagram of a message routing apparatus according to the present disclosure. As shown in FIG. 8, it is applied to a security edge protection proxy VSEPP of a visited public land mobile communication network. The apparatus includes a first receiving module 80 and a routing module 82.
[0055] The first receiving module 80 is configured to receive a service request message and a first routing parameter transmitted by a first network function NF. Here, the first routing parameter carries a network repository function NRF discovery parameter and a user identifier, and the first NF stays within a visited public land mobile communication network VPLMN.
[0056] The routing module 82 is configured to route the service request message and the NRF discovery parameter to a security edge protection proxy HSEPP of a home public land mobile communication network according to the user identifier, so that the HSEPP routes the service request message to a second NF according to the NRF discovery parameter, and the second NF stays within the HPLMN.
[0057] In an exemplary embodiment, the apparatus further includes a second receiving module configured to receive, according to the user identifier, a response message from the second NF returned by the HSEPP after routing the service request message and the NRF discovery parameter to the security edge protection proxy HSEPP of the home public land mobile communication network, where the response message is a response message generated by the second NF after receiving the service request message and completing service processing, and a transmitting module configured to transmit the response message to the first NF.
[0058] In an exemplary embodiment, the first receiving module includes a receiving unit configured to receive an HTTP2 Service Request message sent by a first NF, where the service request message includes an HTTP2 Service Request message carrying a first routing parameter.
[0059] In an exemplary embodiment, the HTTP2 Service Request message carries a first routing parameter including a user permanent identifier SUPI for accessing the UE, an authorization identifier, and an NRF discovery identifier, where the authorization identifier is used to indicate a fully qualified domain name FQDN or an IP address of a VSEPP that interacts with the HPLMN to which the user permanent identifier SUPI belongs, and the NRF discovery identifier is used to indicate discovery parameters required for the first NF to discover a second NF.
[0060] FIG. 9 is a structural block diagram of a routing device for another message according to the present disclosure. As shown in FIG. 9, it is applied to a security edge protection proxy HSEPP of a local public land mobile network. The device includes a first receiving module 90, a routing module 92, a second receiving module 94, and a transmitting module 96.
[0061] The first receiving module 90 is configured to receive a service request message and a second routing parameter routed by a security edge protection proxy VSEPP of a visited public land mobile network. The routing module 92 is configured to route the service request message to a second network function NF according to the second routing parameter, where the second NF stays within the HPLMN. The second receiving module is configured to receive a response message returned by the second NF based on the service request message, and the transmitting module 96 is configured to transmit the response message to the VSEPP.
[0062] In an exemplary embodiment, the routing module is configured to create a discovery request message using second routing parameters carrying network repository function NRF discovery parameters and the fully qualified domain name FQDN or IP address of the NRF in the HPLMN, a creation unit; a transmission unit configured to transmit a request message to the NRF in the HPLMN; and a routing unit configured to route a service request message to a second NF according to the discovery result returned by the NRF.
[0063] In an exemplary embodiment, the routing unit includes a receiving subunit configured to receive several second NF identifiers returned by the NRF based on a request message, and a transmitting subunit configured to select a target second NF from the several second NF identifiers and transmit a service request message to the target second NF.
[0064] According to another embodiment of the present disclosure, there is further provided a message routing system including a security edge protection proxy VSEPP of a visited public land mobile network including the device described in the above embodiment, and a security edge protection proxy HSEPP of a local public land mobile network including the device described in the above embodiment.
[0065] FIG. 10 is a structural block diagram of a message routing system according to the present disclosure. As shown in FIG. 10, the system includes a VSEPP 100 including the device of the above embodiment, and an HSEPP 102 including the device described in the above embodiment.
[0066] It should be noted that each of the above modules may be implemented through software or hardware. In the latter case, all of the above modules may be arranged in the same processor, or the above modules may be arranged in different processors in any combination, and the present disclosure is not limited thereto.
[0067] Embodiment 3 Embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program, which is configured to execute the steps in the method embodiment of any one of the above when executed.
[0068] In an exemplary embodiment, in this embodiment, the above computer-readable storage medium may be configured to store a computer program for performing the following steps. S1. Receive a service request message and a first routing parameter sent by a first network function NF, where the first routing parameter carries a network repository function NRF discovery parameter and a user identifier, and the first NF stays within a visited public land mobile network VPLMN. S2. Route the service request message and the NRF discovery parameter to a security edge protection proxy HSEPP of a local public land mobile network according to the user identifier, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameter, and the second NF stays within a local public land mobile network HPLMN.
[0069] In an exemplary embodiment, in this embodiment, the above computer-readable storage medium includes, but is not limited to, various media capable of storing a computer program, such as a USB disk, a read-only memory (abbreviated as ROM), a random access memory (abbreviated as RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0070] Embodiments of the present disclosure further provide an electronic device including a memory and a processor, where the memory stores a computer program, and the processor is configured to execute the computer program to execute the steps in the method embodiment of any one of the above.
[0071] In an exemplary embodiment, the electronic device may further include a transmitter connected to the processor and an input / output device connected to the processor.
[0072] In an exemplary embodiment, in this embodiment, the above-mentioned processor may be configured to execute the following steps via a computer program. S1, receive a service request message and a first routing parameter transmitted by a first network function NF, where the first routing parameter includes a network repository function NRF discovery parameter and a user identifier, and the first NF stays within a visited public land mobile network VPLMN; S2, route the service request message and the NRF discovery parameter to a security edge protection proxy HSEPP of the local public land mobile network according to the user identifier, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameter, where the second NF stays within the HPLMN.
[0073] In an exemplary embodiment, for specific examples in this embodiment, reference may be made to the examples described in the above embodiments and selectable embodiments, and they will not be repeatedly described in this embodiment.
[0074] According to the present disclosure, a service request message and a first routing parameter transmitted by a first network function NF are received, where the first routing parameter carries a network repository function NRF discovery parameter and a user identifier, the first NF stays within a visited public land mobile network VPLMN, and according to the user identifier, the service request message and the NRF discovery parameter are routed to a security edge protection proxy HSEPP of a local public land mobile network, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameter, the second NF stays within an HPLMN, the VSEPP no longer executes a discovery request for the second NF, directly routes the NRF discovery parameter carrying the network repository function to the HSEPP, and executes the discovery request by the HSEPP and routes the service request message, thereby reducing the detour of messages between PLMNs, solving the technical problem in the related art of the detour of interactive signaling between PLMNs, reducing the number of signaling interactions during service processing, and reducing the processing delay and network resource overhead.
[0075] Obviously, those skilled in the art can implement each module or each step of the present disclosure described above using a general-purpose computing device, and they may be concentrated on a single computing device or dispersed in a network composed of multiple computing devices. In an exemplary implementation, they may also be implemented with program codes executable by a computing device. As a result, they may be stored in a storage device and executed by a computing device. In some cases, the steps illustrated or described may be executed in an order different from that in this specification, or they may be individually manufactured into separate integrated circuit modules, or multiple of them or steps may be manufactured into a single integrated circuit module for implementation. Therefore, the present disclosure is not limited to any specific combination of hardware and software.
[0076] The above are only preferred embodiments of the present disclosure and are not intended to limit the present disclosure. For those skilled in the art, various modifications and changes can be made to the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the principle of the present disclosure shall be included in the protection scope of the present disclosure.
Claims
1. A method for routing a message applied to a security edge protection proxy VSEP of a visited public land mobile communication network, comprising: Receiving a service request message and a first routing parameter transmitted by a first network function NF, wherein the first routing parameter carries a network repository function NRF discovery parameter and a user identifier, and the first NF stays within a visited public land mobile communication network VPLMN; Routing the service request message and the NRF discovery parameter to a security edge protection proxy HSEP of a home public land mobile communication network according to the user identifier, so that the HSEP routes the service request message to a second NF according to the NRF discovery parameter, and the second NF stays within a home public land mobile communication network HPLMN; A method for routing a message.
2. After routing the service request message and the NRF discovery parameter to a security edge protection proxy HSEP of a home public land mobile communication network according to the user identifier, the method further comprises: Receiving a response message from the second NF returned by the HSEP, wherein the response message is a response message generated by the second NF after receiving the service request message and completing service processing; Further comprising transmitting the response message to the first NF. The method according to claim 1.
3. Receiving a service request message and a first routing parameter transmitted by a first NF comprises: Receiving an HTTP2 Service Request message transmitted by the first NF, wherein the service request message comprises the HTTP2 Service Request message carrying the first routing parameter. The method according to claim 1.
4. The HTTP2 Service Request message carries first routing parameters including a user permanent identifier SUPI for accessing the UE, an authorization identifier, and an NRF discovery identifier. The authorization identifier is used to indicate the fully qualified domain name FQDN or IP address of the VSEPP that interacts with the HPLMN to which the user permanent identifier SUPI belongs. The NRF discovery identifier is used to indicate the discovery parameters required for the first NF to discover the second NF. The method according to claim 3.
5. A message routing method applied to a security edge protection proxy HSEPP of a local public land mobile network, comprising: Receiving a service request message and second routing parameters routed by a security edge protection proxy VSEPP of a visited public land mobile network; Routing the service request message to a second network function NF according to the second routing parameters, where the second NF stays within the HPLMN; Receiving a response message returned by the second NF based on the service request message; Further comprising transmitting the response message to the VSEPP. A message routing method.
6. Routing the service request message to a second network function NF according to the second routing parameters includes: Creating a discovery request message using the second routing parameters carrying the NRF discovery parameters of the network repository function and the fully qualified domain name FQDN or IP address of the NRF in the HPLMN; Transmitting the request message to the NRF in the HPLMN; Routing the service request message to a second NF according to the discovery result returned by the NRF. The method according to claim 5.
7. Routing the service request message to a second network function NF according to the discovery result returned by the NRF includes: Receiving several second NF identifiers returned by the NRF based on the request message. selecting a target second NF from among the several second NF identifiers and sending the service request message to the target second NF The method according to claim 6.
8. A message routing device applied to a security edge protection proxy VSEP of a visited public land mobile network, a first receiving module for receiving a service request message and a first routing parameter transmitted by a first network function NF, wherein the first routing parameter carries a network repository function NRF discovery parameter and a user identifier, and the first NF is a first receiving module staying within a visited public land mobile network VPLMN; a routing module for routing the service request message and the NRF discovery parameter to a security edge protection proxy HSEP of a home public land mobile network according to the user identifier, so that the HSEP routes the service request message to a second NF according to the NRF discovery parameter, and the second NF stays within a home public land mobile network HPLMN A message routing device.
9. A message routing device applied to a security edge protection proxy HSEP of a home public land mobile network, a first receiving module for receiving a service request message and a second routing parameter routed by a security edge protection proxy VSEP of a visited public land mobile network; a routing module for routing the service request message to a second network function NF according to the second routing parameter, and the second NF stays within an HPLMN; a second receiving module for receiving a response message returned by the second NF based on the service request message; and a transmission module for transmitting the response message to the VSEP. A message routing device.
10. A message routing system including a security edge protection proxy VSIPP for a visited public land mobile communication network including the apparatus according to claim 8 and a home security edge protection proxy HSIPP for a local public land mobile communication network including the apparatus according to claim 9. A message routing system.
11. A computer-readable storage medium storing a computer program, wherein the computer program, when executed, is configured to execute the method according to any one of claims 1 to 7. A computer-readable storage medium.
12. An electronic device including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the computer program to execute the method according to any one of claims 1 to 7. An electronic device.
Citation Information
Patent Citations
Method and solution for avoiding issues with inter PLMN routing and TLS in 5G service based architecture
CN111819874A
SEPP registration, discovery and inter-PLMN connectivity policies
US20200036754A1
Network node
WO2020208913A1