Communication methods and communication devices
By providing information about the home network to a DNS server, the communication method and device enable terminals to access application servers in a visited network, enhancing communication service quality despite unauthorized domain names.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-03-26
- Publication Date
- 2026-04-16
AI Technical Summary
When a device roams within a visited public land mobile network (VPLMN) and the home PLMN (HPLMN) does not authorize the offloading of services corresponding to certain domain names to the local data network, the quality of services the device can obtain is limited.
A communication method and device that enable a terminal to obtain the address of an application server corresponding to a domain name not authorized for offloading by providing information about the home network to a DNS server, allowing the DNS server to find the AS address and provide it to the terminal, thereby enabling access to the application server in the serving network.
This solution allows the terminal to access and obtain services from application servers in the serving network, improving the quality of communication services by overcoming the limitation of unauthorized domain names.
Smart Images

Figure 2026512420000001_ABST
Abstract
Description
[Technical Field]
[0001] This application claims priority to Chinese Patent Application No. 202310363701.0, titled "COMMUNICATION METHOD AND COMMUNICATION APPARATUS," filed with the State Intellectual Property Administration of China on 31 March 2023, which is incorporated herein by reference in its entirety.
[0002] This application relates to the field of communications, and more specifically to communication methods and communication devices. [Background technology]
[0003] In mobile communication networks, identifiers (IDs) for public land mobile networks (PLMNs) may be used to distinguish between mobile communication networks (i.e., PLMNs) of different operators and different standards. The PLMN that a terminal subscribes to is the home PLMN (HPLMN). When a terminal leaves the coverage of an HPLMN's wireless network due to movement or other reasons, if the terminal is currently within the coverage of another PLMN's wireless network and that PLMN is the PLMN with which the terminal has a roaming agreement with its HPLMN, the terminal may access the PLMN via that PLMN's wireless network. That PLMN may be referred to as a visited PLMN (VPLMN), and access to the VPLMN by the terminal may be referred to as roaming. When the terminal's user plane terminates on an HPLMN, the terminal's roaming may be referred to as home-roaming (HR) roaming.
[0004] In a terminal's HR roaming scenario, HPLMN may authorize the offloading of services corresponding to certain domain names to the local portion of the data network within VPLMN. The visited session management function (V-SMF) network element within VPLMN may configure the relevant network elements within VPLMN based on authorization information from HPLMN, including configuring edge application server discovery (EASDF). When a terminal queries the Internet Protocol (IP) address of an application server (AS) corresponding to a domain name authorized to be offloaded to VPLMN, the V-EASDF network element may communicate with a domain name system server to obtain the AS IP address queried by the terminal, thereby enabling the AS to provide the service corresponding to the domain name to the terminal.
[0005] However, when a device roams within a VPLMN, if the HPLMN does not authorize the offloading of services corresponding to one or more domain names to the local data network within the VPLMN, the quality of services the device can obtain may be limited. [Overview of the Initiative]
[0006] Embodiments of this application provide a communication method and a communication device that enable a terminal to obtain the address of an application server corresponding to a domain name that is not authorized to offload the corresponding service to the local data network in a serving network. In this way, the terminal can access the application server in the serving network and obtain the service provided by the application server, thereby improving the quality of the terminal's communication service.
[0007] According to the first embodiment, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. Below, an example in which a first network element performs the method will be used for illustrative purposes.
[0008] The method includes: a first network element receiving a first query message from a terminal, the first network element being located within the terminal's visited network, the first query message containing information about a first domain name, the first domain name being unauthorized within the terminal's visited network; the first network element sending a second query message to a domain name system (DNS) server, the second query message containing information about the first domain name and information about the terminal's home network; and the first network element receiving the address of an application server from the DNS server.
[0009] The information about the home network in the second query message is used to determine the address of the application server. In other words, the information about the home network in the second query message is used to obtain the address of the application server. The application server is configured to provide the service corresponding to the first domain name to the terminal.
[0010] For example, the fact that the first domain name is not authorized on the terminal's visited network includes the fact that the service corresponding to the first domain name is not authorized by the terminal's home network to be offloaded to the local data network.
[0011] According to the above solution, when a first network element in the terminal's visited network provides an AS discovery service to the terminal, if the domain name provided when the terminal queries for an AS address is an unauthorized domain name in the terminal's visited network, the first network element provides information about the terminal's home network to the DNS server, thereby allowing the DNS server to find the AS address corresponding to the domain name that is not authorized to offload services to the local DN of the terminal's serving network, and provide the AS address to the terminal via the first network element. In this way, the terminal can obtain the address of the application server corresponding to the domain name that is not authorized to offload the corresponding service to the local data network in the serving network, thereby allowing the terminal to access the application server in the serving network and obtain the services provided by the application server. In addition, this avoids the problem where the terminal cannot access the service corresponding to the domain name because the domain name is unauthorized, and improves the quality of the terminal's communication services.
[0012] In relation to the first aspect, in some implementations of the first aspect, the method further includes a first network element receiving information from a second network element, the information being from a terminal and indicating rules used in a query message used to query the address of an application server, the rules including the first network element providing information about its home network to a DNS server when the query message used to query the address of an application server contains a domain name that is not authorized in the network visited by the terminal.
[0013] In one implementation, the rule specifically includes, when a query message used to query the address of an application server contains an unauthorized domain name on the terminal's visited network, the first network element includes information about the home network and the unauthorized domain name in a single message and provides that message to the DNS server.
[0014] According to the above solution, the second network element may provide the first network element with rules to be used to handle DNS query messages. These rules include providing the DNS server with information about the home network when the retrieved query message contains a domain name that is not authorized in the serving network, thereby enabling the first network element to process the DNS query message according to those rules. In this way, the DNS server can retrieve information about the terminal's home network, and based on the first domain name, the information about the terminal's home network, and address affinity, retrieve the AS address corresponding to the first domain name, and provide the AS address corresponding to the first domain name to the terminal, thereby enabling the terminal to access application servers in the serving network and obtain communication services. This avoids the problem where the terminal cannot access services corresponding to a domain name because the domain name is not authorized, and improves the quality of communication services for the terminal.
[0015] In one implementation, the information specifically indicates a rule used in the first query message, the rule including that the first network element provides information about the home network to the DNS server.
[0016] In relation to the first aspect, in some implementations of the first aspect, the first network element is a functional network element located within the terminal's visited network and configured to discover application servers, and the second network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session.
[0017] In relation to the first aspect, in some implementations of the first aspect, the second query message includes an ECS option information element, which indicates information about the home network.
[0018] According to the above solution, the ECS option information element within the DNS query message is reused to send information about the home network. This solution reduces implementation complexity compared to a method where the DNS query message format is modified to indicate information about the home network.
[0019] In relation to the first aspect, in some implementations of the first aspect, information about the home network includes one or more of the following: the Internet Protocol IP address of the terminal, the IP addresses of user plane functional network elements within the home network, or the dedicated address of the home network.
[0020] According to the above solution, the information about the home network may be the IP address of the terminal, the address of a network element within the home network, or a dedicated address of the home network used to obtain the AS address, thereby improving the accuracy of obtaining the AS address by the DNS server based on the information about the home network.
[0021] In relation to the first aspect, in some implementations of the first aspect, the first network element receiving the address of an application server from a DNS server includes the first network element receiving a second response message from the DNS server for a second query message, the second response message including the address of an application server. The method further includes the first network element sending a first response message for a first query message to a terminal, the first response message including the address of an application server.
[0022] According to the above solution, the first network element obtains the address of the AS corresponding to the first domain name from the DNS server, responds to the query of the terminal, and provides the address of the AS corresponding to the first domain name to the terminal. Thereby, the terminal obtains the address of the AS corresponding to the domain name for which offloading services to the local DN of the destination network in the serving network is not approved.
[0023] Related to the first aspect, in some implementations of the first aspect, the method further includes the first network element obtaining information about domain names approved in the destination network of the terminal and / or information about domain names not approved in the destination network of the terminal, and the first network element determining, based on the information about the domain name, that the first domain name is not approved in the destination network of the terminal.
[0024] For example, the information about the domain name includes a first set of domain names and / or a second set of domain names. The first set of domain names includes one or more domain names approved in the destination network of the terminal, and the first domain name does not belong to the first set of domain names. The information about the domain name includes the second set of domain names, and the second set of domain names includes one or more domain names not approved in the destination network of the terminal, and the first domain name belongs to the second set of domain names.
[0025] According to the above solution, the first network element may determine, based on the information about the domain name, that the first domain name is not approved in the destination network of the terminal. For example, based on the case where the first domain name does not belong to the first set of domain names and / or based on the case where the first domain name belongs to the second set of domain names, the first domain name may be determined not to be approved in the destination network of the terminal. Thus, when querying the DNS server for the address of the AS corresponding to the first domain name, the first network element provides the information about the home network to the DNS server. In this way, the DNS server can accurately obtain the address of the AS corresponding to the first domain name and feedback the address to the terminal.
[0026] According to a second aspect, a communication method is provided. The method may be executed by a communication device, which may be a communication device or a component (such as a chip or a chip system) configured within the communication device. Hereinafter, an example where the second network element executes the method is used for explanation.
[0027] The method includes that the second network element sends the first information to the terminal, where the first information indicates that the first network element is configured to discover an application server that provides services to the terminal, and the first network element and the second network element are within the destination network of the terminal, and that the second network element sends the second information to the first network element, where the second information is from the terminal and indicates the rules used in the query message for querying the address of the application server, and the rules include that when the query message used for querying the address of the application server includes a domain name not approved in the destination network of the terminal, the first network element provides the information about the home network of the terminal to the DNS server.
[0028] For example, the fact that the first domain name is not authorized on the terminal's visited network includes the fact that the service corresponding to the first domain name is not authorized by the terminal's home network to be offloaded to the local data network.
[0029] According to the above solution, the second network element may provide the first network element with rules to be used to process DNS query messages, and the rules include providing the DNS server with information about the home network when the retrieved query message contains a domain name that is not authorized in the serving network, thereby enabling the first network element to process the DNS query message according to those rules. In this way, the DNS server may obtain information about the terminal's home network, obtain the AS address corresponding to the first domain name based on the first domain name, the information about the terminal's home network, and address affinity, and provide the AS address corresponding to the first domain name to the terminal, thereby enabling the terminal to access application servers in the serving network and obtain services provided by the application servers. In addition, this avoids the problem where the terminal cannot access services corresponding to a domain name because the domain name is not authorized, and improves the quality of communication services for the terminal.
[0030] In relation to the second aspect, in some implementations of the second aspect, the rule specifically includes, when a query message used to query the address of an application server contains an unauthorized domain name in the network visited by the terminal, the first network element includes information about the home network and the unauthorized domain name in a single message and provides that message to the DNS server.
[0031] For the advantages of the solution in the second aspect, which corresponds to the solution in the first aspect, please refer to the description of the first aspect. Further details will not be explained again here.
[0032] In relation to the second aspect, in some implementations of the second aspect, the method further includes a second network element receiving third information from a third network element, the third network element being within the terminal's home network, the third information including information about the terminal's home network, and the information about the home network being used to query an application server corresponding to an unauthorized domain name in the terminal's visited network.
[0033] In relation to the second aspect, in some implementations of the second aspect, information about the home network includes the Internet Protocol IP address of the terminal, the IP address of a user plane functional network element within the home network, or the dedicated address of the home network.
[0034] In relation to the second aspect, in some implementations of the second aspect, the first network element is a functional network element located within the terminal's visited network and configured to discover application servers, and the second network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session.
[0035] In relation to the second aspect, in some implementations of the second aspect, the method further includes the second network element transmitting to the first network element information about domain names that are authorized in the terminal's visited network, and / or information about domain names that are not authorized in the terminal's visited network.
[0036] In relation to the second aspect, in some implementations of the second aspect, the information about a domain name includes a first set of domain names, the first set of domain names includes one or more domain names that are authorized in the terminal's visited network, the first domain name does not belong to the first set of domain names, and / or the information about a domain name includes a second set of domain names, the second set of domain names includes one or more domain names that are not authorized in the terminal's visited network, and the first domain name belongs to the second set of domain names.
[0037] According to a third aspect, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. Below, an example in which a first network element performs the method will be used for illustrative purposes.
[0038] The method includes: a first network element receiving a first query message from a terminal, the first query message containing information about a first domain name, the first domain name being unauthorized in the terminal's visited network; and the first network element sending a second query message to a second network element, the second query message containing information about a first domain name, the destination address of the second query message being the address of a Domain Name System DNS server, the DNS server being configured to query for the terminal the address of an application server corresponding to an unauthorized domain name in the terminal's visited network, and the application server being configured to provide the terminal with a service corresponding to the first domain name.
[0039] For example, the DNS server address is either the address of the DNS server corresponding to the home network, or the DNS server address is a DNS server within the central data network. The address That is the case.
[0040] For example, the fact that the first domain name is not authorized on the terminal's visited network includes the fact that the service corresponding to the first domain name is not authorized by the terminal's home network to be offloaded to the local data network.
[0041] According to the above solution, when a first network element in the terminal's visited network provides an AS discovery service to the terminal, if the first domain name provided when the terminal queries for an AS address is an unauthorized domain name in the visited network, the first network element provides a query message to a second network element that includes the unauthorized domain name and whose destination address is the address of a DNS server. The second network element forwards the query message, thereby allowing network elements in the network to forward the query message to a DNS server that can find the AS address corresponding to the unauthorized domain name in the terminal's visited network based on the destination address of the query message. In this way, the terminal can obtain the address of the application server corresponding to the domain name that is not authorized to offload the corresponding service to the local data network in the serving network, thereby allowing the terminal to access the application server in the serving network and obtain the services provided by the application server. In addition, this avoids the problem where the terminal cannot access the service corresponding to the domain name because the domain name is unauthorized, and improves the quality of the terminal's communication services.
[0042] In relation to the third aspect, in some implementations of the third aspect, the first network element receives the address of the application server from the second network element.
[0043] According to the above solution, after finding the AS address corresponding to an unauthorized domain name in the network visited by the terminal, the DNS server may feed back the AS address to the terminal, in particular, via a second network element and a first network element that forward the query message to the terminal, thereby allowing the terminal to obtain the AS address.
[0044] In relation to the third aspect, in some implementations of the third aspect, the method further includes a first network element receiving information from a second network element, the information being from a terminal and indicating a rule used in a query message used to query the address of an application server, the rule including, when the query message used to query the address of an application server includes an unauthorized domain name in the network visited by the terminal, the first network element sending a query message to the second network element that includes an unauthorized domain name and whose destination address is the address of a DNS server.
[0045] In one implementation, the method further includes a first network element receiving information from a second network element, the information indicating a rule to be used in a first query message, the rule including the first network element providing the second network element with a second query message which includes a first domain name and whose destination address is the address of a DNS server.
[0046] According to the above solution, the second network element may provide the first network element with rules to be used to process DNS query messages, thereby allowing the first network element to forward query messages containing unauthorized domain names and whose destination address is the address of a DNS server to the second network element according to those rules, and the query messages are ultimately forwarded to the DNS server.
[0047] In relation to the third aspect, in some implementations of the third aspect, the first network element is a functional network element located within the terminal's visited network and configured to discover application servers, and the second network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session.
[0048] In relation to the third aspect, in some implementations of the third aspect, the receiving of the application server address by a first network element from a second network element includes the receiving of a second response message for a second query message by the first network element from the second network element, the second response message including the application server address, and the method further includes the sending of a first response message for a first query message to a terminal, the first response message including the application server address.
[0049] In relation to the third aspect, in some implementations of the third aspect, the method further includes the first network element obtaining information about domain names that are authorized in the terminal's visited network and / or information about domain names that are not authorized in the terminal's visited network, and the first network element determining, based on the information about domain names, that the first domain name is not authorized in the terminal's visited network.
[0050] In relation to the third aspect, in some implementations of the third aspect, information about domain names includes a first set of domain names and / or a second set of domain names, the first set of domain names includes one or more domain names that are authorized in the terminal's visited network, the first domain names do not belong to the first set of domain names, and / or the second set of domain names includes one or more domain names that are not authorized in the terminal's visited network, the first domain names belong to the second set of domain names.
[0051] According to a fourth aspect, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. Below, an example in which a second network element performs the method will be used for illustrative purposes.
[0052] The method includes a second network element receiving a second query message from a first network element, the second query message containing information about a first domain name which originates from a terminal, the destination address of the second query message being the address of a Domain Name System DNS server, the first domain name which is not authorized in the terminal's visited network, the DNS server being configured to query for the terminal the address of an application server corresponding to a domain name which is not authorized in the terminal's visited network, the application server being configured to provide the terminal with a service corresponding to the first domain name, the second query message being used to query the DNS server for the terminal the address of an application server corresponding to the first domain name, the first network element being a functional network element located in the terminal's visited network and configured to manage the terminal's session, and the second network element being a functional network element located in the terminal's visited network and configured to discover application servers.
[0053] According to the above solution, the second network element provides the first network element with rules to be used to process DNS query messages, so that the first network element can forward query messages containing an unauthorized domain name and whose destination address is the address of a DNS server to the second network element, i.e., a control plane network element, located within the terminal's visited network and configured to manage the terminal's session, according to those rules. The control plane network element within the terminal's visited network then forwards the query message. In this way, the network elements within the network can forward the query message to a DNS server that can find the AS address corresponding to the unauthorized domain name in the terminal's visited network, based on the destination address of the query message. In addition, in this solution, even if the terminal implements cryptographic protection for the query message, the first network element configured to discover the AS can determine whether the domain name contained in the query message is an unauthorized domain name in the visited network, and the first network element forwards the query message according to its rules, thereby allowing the terminal to obtain the AS address corresponding to the domain name. In this way, the terminal can obtain the address of an application server corresponding to a domain name that is not authorized to offload the corresponding service to the local data network within the serving network. This allows the terminal to access the application server within the serving network and obtain the services provided by the application server. In addition, this avoids the problem where the terminal cannot access the service corresponding to a domain name because the domain name is not authorized, thereby improving the quality of the terminal's communication services.
[0054] In relation to the fourth aspect, in some implementations of the fourth aspect, the second network element queries a DNS server for the address of the application server corresponding to the first domain name, via a network element in the terminal's home network.
[0055] For example, a second network element sends a third query message to a third network element, which is used to query a DNS server for the address of an application server corresponding to a first domain name on behalf of a terminal, which contains information about the first domain name, and the third network element is a functional network element located in a home network and configured to manage terminal sessions.
[0056] According to the above solution, a control plane network element within the terminal's visited network forwards the query message, thereby forwarding it to the terminal's home network, and through the home network, it can be forwarded to a DNS server that can find the AS address corresponding to the first domain name. In this way, the terminal can obtain the address of the application server corresponding to a domain name that is not authorized to offload the corresponding service to the local data network in the serving network.
[0057] In relation to the fourth aspect, in some implementations of the fourth aspect, the method further includes the following:
[0058] A second network element transmits information to a first network element, the information being from a terminal and indicating rules used in query messages used to query the address of an application server, the rules including that if the query message used to query the address of an application server contains an unauthorized domain name in the network visited by the terminal, the first network element transmits a query message to the second network element that contains the unauthorized domain name and whose destination address is the address of a DNS server.
[0059] In one implementation, a second network element sends information to a first network element, the information indicates a rule to be used in a first query message, the rule to provide the second network element with a second query message which includes a first domain name and whose destination address is the address of a DNS server.
[0060] For the advantages of the solution in the fourth aspect, which corresponds to the solution in the third aspect, please refer to the description of the third aspect. Further details will not be explained again here.
[0061] In relation to the fourth aspect, in some implementations of the fourth aspect, a response message containing the address of the AS corresponding to the first domain name may be forwarded to the terminal via a first network element, a second network element, and a third network element that forward the query message, i.e., it may be forwarded to the terminal via a control plane network element that forwards the query message.
[0062] Specifically, the method further comprises the second network element receiving a third response message from the third network element, the third response message including the address of an application server corresponding to a first domain name, the third network element being a functional network element located in a home network and configured to manage terminal sessions, the second network element sending a second response message to the first network element for a second query message, the second response message including the address of an application server corresponding to a first domain name.
[0063] In relation to the fourth aspect, in some implementations of the fourth aspect, a response message containing the AS address corresponding to the first domain name may be forwarded to the terminal via user plane network elements in the home network and user plane network elements in the terminal's visited network.
[0064] According to the fifth aspect, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. Below, an example in which a second network element performs the method will be used for illustrative purposes.
[0065] The method includes a second network element sending first information to a terminal, the first information indicating that the first network element is configured to discover application servers that provide services to the terminal, the first network element being a functional network element located in the terminal's visited network and configured to manage the terminal's session, and the second network element being a functional network element located in the visited network and configured to discover application servers, and the second network element sending second information to the first network element, the second information indicating a rule from the terminal and used in a first query message used to query the address of an application server, the rule including, when the first query message includes a domain name not authorized in the visited network, the first network element sending a second query message to the second network element that includes the domain name not authorized and whose destination address is the address of a DNS server, the DNS server being configured to query for the terminal the address of an application server corresponding to the domain name not authorized in the visited network.
[0066] For the advantages of the solution in the fifth aspect, please refer to the descriptions of the advantages of the corresponding solutions in the third and fourth aspects. Further details will not be explained again here.
[0067] According to the sixth aspect, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. Hereafter, 4th An example of a network element performing the method will be used for illustrative purposes.
[0068] The method includes: a fourth network element receiving a first query message, the first query message containing information about a first domain name which is from a terminal and is not authorized in the terminal's visited network; and the fourth network element sending a fourth query message, the fourth query message containing information about a first domain name, the destination address of the fourth query message being the address of a Domain Name System DNS server, the DNS server being configured to query for the terminal the address of an application server corresponding to a domain name not authorized in the terminal's visited network, and the application server being configured to provide the terminal with a service corresponding to the first domain name.
[0069] For example, the fourth network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session, a functional network element located within the home network and configured to manage the terminal's session, a user plane functional network element within the home network, or a functional network element located within the home network and configured to discover application servers.
[0070] For example, the fact that the first domain name is not authorized on the terminal's visited network includes the fact that the service corresponding to the first domain name is not authorized by the home network to be offloaded to the local data network.
[0071] According to the above solution, when a fourth network element obtains an unauthorized domain name from the first terminal in the visited network, the fourth network element forwards a query message that includes the unauthorized domain name and whose destination address is the address of a DNS server. In this way, network elements in the network can forward the query message to a DNS server that can find the address of the AS corresponding to the unauthorized domain name in the terminal's visited network, based on the destination address of the query message. In this way, the terminal can obtain the address of the application server corresponding to the unauthorized domain name in the serving network, thereby enabling the terminal to access the application server in the serving network and obtain the services provided by the application server. In addition, this avoids the problem where the terminal cannot access the service corresponding to the domain name because the domain name is unauthorized, and improves the quality of the terminal's communication services.
[0072] In relation to the sixth aspect, in some implementations of the sixth aspect, the fourth network element receives the address of the application server.
[0073] In relation to the sixth aspect, in some implementations of the sixth aspect, the fourth network element is a functional network element located in the terminal's visited network and configured to manage the terminal's session, and sending the fourth query message includes sending the fourth query message to a functional network element located in the home network and configured to manage the terminal's session.
[0074] In relation to the sixth aspect, in some implementations of the sixth aspect, the fourth network element is a functional network element located in the terminal's visited network and configured to manage the terminal's session, the method being that the fourth network element transmits information to a first network element, the first network element being located in the terminal's visited network and configured to discover application servers, the information being from the terminal and indicating rules used in query messages used to query the address of application servers, the rules further comprising the first network element transmitting a query message used to query the address of application servers to a second network element when the query message used to query the address of application servers contains a domain name not authorized in the terminal's visited network.
[0075] In relation to the sixth aspect, in some implementations of the sixth aspect, the fourth network element receiving the address of an application server includes the fourth network element receiving a fourth response message for a fourth query message, the fourth response message including the address of an application server, and the fourth network element sending a first response message for a first query message to a terminal, the first response message including the address of an application server.
[0076] According to the seventh aspect, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. For illustrative purposes, an example in which a terminal performs the method will be used below.
[0077] The method includes the terminal determining that a first domain name to be queried is not authorized in the visited network, the terminal determining a first message, the first message comprising a query message and indication information, the query message being used to query the address of an application server corresponding to the first domain name, the indication information indicating that the query message is used to query the address of an AS corresponding to a domain name not authorized in the visited network, or the indication information indicating that the query message contains a domain name not authorized in the visited network, and the terminal sending the first message to a user plane functional network element in the visited network.
[0078] According to the above solution, the terminal notifies the user plane network element, based on the indication information, that the query message contains a domain name that is not authorized in the visited network. As a result, even if the terminal has applied cryptographic protection (such as DHO and DOT) to the query message, the user plane functional network element cannot interpret the query message. However, based on the indication information in the first message, the user plane functional network element can decide to forward the query message to the UPF network element in the home network without interpreting it. This allows the UPF network element in the home network to find the AS address corresponding to the unauthorized domain name in the visited network for the terminal. In this way, the terminal can access the address of the application server corresponding to the unauthorized domain name in the visited network and obtain the services provided by the application server. In addition, this avoids the problem where the terminal cannot access the service corresponding to the domain name because the domain name is not authorized, and improves the quality of the terminal's communication services.
[0079] According to the eighth aspect, a communication method is provided. The method may be performed by a communication device, which may be a communication device or a component (such as a chip or chip system) configured within a communication device. Hereafter, First User Plane Functional Network Element An example of how the method is implemented will be used for explanation.
[0080] The method includes a first user plane functional network element receiving a first message from a terminal, the first message comprising a query message and indication information, the query message being used to query the address of an application server corresponding to a first domain name, the indication information indicating that the query message is used to query the address of an AS corresponding to a domain name not authorized in the visited network, or the indication information indicating that the query message contains a domain name not authorized in the visited network, the first user plane functional network element being located in the terminal's visited network, and the first user plane functional network element sending the query message to a second user plane functional network element being located in the terminal's home network.
[0081] For the advantageous effects of the solution in the eighth aspect, please refer to the explanation of the advantageous effects of the solution in the seventh aspect. Further details will not be explained again here.
[0082] According to the ninth aspect, a communication method is provided. The method may be performed by a communication system, which includes a first network element and a second network element.
[0083] The method involves a second network element transmitting first information to a terminal, the first information being configured to discover an application server that provides services to the terminal, and the first and second network elements being within the terminal's visited network. ru , including.
[0084] A second network element transmits second information to a first network element, the second information being from a terminal and indicating rules used in query messages used to query the address of an application server, the rules including that if the query message used to query the address of an application server contains a domain name not authorized in the network visited by the terminal, the first network element provides information about the terminal's home network to the DNS server.
[0085] The first network element receives a first query message from the terminal, the first query message contains information about a first domain name, and the first domain name is not authorized in the terminal's visited network.
[0086] The first network element sends a second query message to a Domain Name System (DNS) server, which includes information about the first domain name and information about the terminal's home network. The information about the home network is used to determine the address of the application server, which is configured to provide the terminal with the service corresponding to the first domain name.
[0087] The first network element receives the application server's address from the DNS server, and then sends the application server's address to the terminal.
[0088] In relation to the ninth aspect, in some implementations of the ninth aspect, the communication system further includes the above-mentioned terminal.
[0089] According to a tenth aspect, a communication method is provided. The method may be performed by a communication system, which includes a first network element and a second network element.
[0090] The method includes a first network element receiving a first query message from a terminal, the first query message containing information about a first domain name, the first domain name being unauthorized in the terminal's visited network.
[0091] The first network element sends a second query message to the second network element, the second query message containing information about the first domain name, the destination address of the second query message being the address of a Domain Name System (DNS) server, the DNS server being configured to query for the terminal the address of an application server corresponding to an unauthorized domain name in the network visited by the terminal, and the application server being configured to provide the terminal with a service corresponding to the first domain name.
[0092] The second network element queries the DNS server for the address of the application server corresponding to the first domain name, via the network element within the terminal's home network, on behalf of the terminal.
[0093] The first network element receives the application server's address from the second network element.
[0094] The first network element sends the application server's address to the terminal.
[0095] According to the eleventh aspect, a communication device is provided. The device may include a module configured to perform, in one-to-one correspondence, the methods / operations / steps / actions described in any one of the first to eighth aspects and any possible implementations of the first to eighth aspects. The module may be hardware circuitry or software, or may be implemented by hardware circuitry in combination with software. For further details, see the detailed description in the corresponding method examples above. Further details are not described again here.
[0096] According to the twelfth aspect, a communication device including a processor is provided. The processor may be coupled to memory and configured to execute instructions in memory to carry out a method in any one of the first to eighth aspects and possible implementations of the first to eighth aspects.
[0097] Optionally, the communication device may further include memory.
[0098] Optionally, the communication device further includes a communication interface, and a processor is coupled to the communication interface. In this application, the communication interface may be a transceiver, pins, circuit, bus, module, or other type of communication interface; however, it is not limited thereto.
[0099] In a given implementation, a communication device is a communication interface. When a communication device is a communication interface, the communication interface may be a transceiver, or it may be an input / output interface.
[0100] Optionally, a transceiver may be a transceiver circuit. Optionally, an input / output interface may be an input / output circuit.
[0101] In other implementations, the communication device is a chip configured within the communication device. When the communication device is a chip configured within the communication device, the communication interface may be an input / output interface.
[0102] According to the thirteenth aspect, a processor is provided which includes an input circuit, an output circuit, and a processing circuit. The processing circuit receives a signal through the input circuit and transmits a signal through the output circuit, thereby the processor is configured to perform a method in any one of the first to eighth aspects and possible implementations of the first to eighth aspects.
[0103] In a specific implementation process, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or any logic circuit. The input signal received by the input circuit may be received and input by a receiver, for example, but not limited to this, and the signal output by the output circuit may be output to a transmitter, for example, but not limited to this, and transmitted by the transmitter, and the input circuit and the output circuit may be the same circuit, which is used as an input circuit and an output circuit at different times. The specific implementation of the processor and various circuits is not limited in this application.
[0104] According to the 14th aspect, a computer program product is provided. The computer program product includes a computer program (sometimes referred to as code or instructions). When the computer program is executed, the computer becomes capable of performing any one of the methods in the first to eighth aspects and any possible implementations of the first to eighth aspects.
[0105] According to the 15th aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (sometimes referred to as code or instructions). When the computer program is executed on a computer, the computer becomes capable of performing any one of the methods in the first to eighth aspects and any possible implementations of the first to eighth aspects.
[0106] According to the sixteenth aspect, the application provides a communication system comprising a first communication device and a second communication device, the first communication device being configured to perform a method performed by a first network element in any one of the possible implementations of the first to eighth aspects and the first to eighth aspects, and the second communication device being configured to perform a method performed by a second network element in any one of the possible implementations of the first to eighth aspects and the first to eighth aspects.
[0107] In one implementation, the communication system further includes a terminal configured to perform a method in any one of the first to eighth embodiments and possible implementations of the first to eighth embodiments. [Brief explanation of the drawing]
[0108] [Figure 1] This is a diagram showing the architecture of a communication system according to an embodiment of this application. [Figure 1A] Another diagram of the architecture of the communication system according to the embodiment of this application. [Figure 2] This is a schematic flowchart of the communication method according to the embodiment of this application. [Figure 3] This is a schematic flowchart of a communication method applied to a terminal roaming scenario according to an embodiment of this application. [Figure 4] This is another schematic flowchart of the communication method according to the embodiment of this application. [Figure 5]This is another schematic flowchart of a communication method applied to a terminal roaming scenario according to an embodiment of this application. [Figure 6] This is a block diagram of a communication device according to an embodiment of this application. [Figure 7] This is another diagram showing the structure of a communication device according to an embodiment of this application. [Modes for carrying out the invention]
[0109] The technical solution of this application will be described below with reference to the attached diagrams.
[0110] In embodiments of this application, “ / ” may represent an “or” relationship between related objects, for example A / B may represent A or B, and “and / or” may represent three relationships between related objects, for example A and / or B may represent the following three cases: that only A exists, that both A and B exist, and that only B exists, where A and B may be singular or plural. In order to facilitate the description of the technical solutions in embodiments of this application, terms such as “first” and “second” may be used in embodiments of this application for distinction. Terms such as “first” and “second” do not limit the quantity or order of execution, and do not limit the definitive differences. In embodiments of this application, terms such as “example” or “for example” represent an example, illustration, or explanation. Any embodiment or design solution described as “example” or “for example” should not be construed as having any advantages over other embodiments or design solutions. Words such as “example” or “for example” are used to provide relevant concepts in a concrete manner for ease of understanding. In embodiments of this application, “at least one (type)” may be alternatively described as “one (type) or more (types),” and “more (types)” may be two (types), three (types), four (types), or more (types). This is not limited to embodiments of this application.
[0111] The technical solutions in the embodiments of this application may be applied to various communication systems, such as long-term evolution (LTE) systems, fifth-generation (5G) communication systems, such as 5G new radio (NR) systems, sixth-generation (6G) communication systems, future communication systems, or systems integrating multiple communication systems. This is not limited to the embodiments of this application.
[0112] In embodiments of this application, terminal devices may also be referred to as terminals. A terminal may be a device having wireless transceiver functionality. A terminal may be located on the ground, on water (e.g., on a ship), or in the air (e.g., on an airplane, balloon, or satellite), including being located indoors, outdoors, handheld, and / or in a vehicle. A terminal device may be user equipment (UE). UE includes handheld devices, vehicle-mounted devices, wearable devices, or computing devices with wireless communication capabilities. For example, UE may be a mobile phone, a tablet computer, or a computer with wireless transceiver functionality. The terminal device may alternatively be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in autonomous driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in a smart city, and / or a wireless terminal in a smart home.
[0113] In embodiments of this application, a radio access network (RAN) network element may be a RAN device including a base station (BS), or a device located within a radio access network and capable of wireless communication with terminal devices. A base station may take multiple forms. For example, a base station may be a macro base station, a micro base station, a relay station, or an access point. In embodiments of this application, a base station may be a next-generation-RAN (NG-RAN) device in a 5G system, a base station in a long-term evolution (LTE) system, or a base station in another system, but is not limited thereto. An NG-RAN device in a 5G system may also be referred to as a transmission reception point (TRP) or a next-generation network element B (generation NodeB, gNB, or gNodeB). A base station may be an integrated base station or a base station divided into multiple network elements, but is not limited thereto. For example, a base station is one in which a central unit (CU) and a distributed unit (DU) are separated; that is, the base station includes both a CU and a DU.
[0114] Figure 1 is a diagram of a network architecture to which embodiments of this application can be applied. As shown in Figure 1, the network architecture may include a UE, access network elements within the access network (e.g., (R)AN), and core network elements within the core network. The core network may include several functional units shown in Figure 1, such as an access and mobility management function (AMF) network element, a session management function (SMF) network element, a user plane function (UPF) network element, an authentication server function (AUSF) network element, a policy control function (PCF) network element, an application function (AF) network element, a unified data management (UDM) network element, and a network slice selection function (NSSF) network element. The functional network elements will be described individually below.
[0115] The AMF network element is primarily responsible for services such as mobility management and access management, including user location updates, user network registration, and user switching.
[0116] SMF network elements are primarily responsible for session management, terminal device address management and assignment, dynamic host configuration protocol functions, and selection and control of user plane functions. SMF network elements are mainly responsible for session management within mobile networks, such as session establishment, modification, and release. Specific functions of SMF network elements include, for example, assigning IP addresses to users or selecting a UPF to provide packet forwarding functionality.
[0117] Figure 1A shows a diagram of an HR roaming network architecture to which embodiments of this application are applicable. In an HR roaming scenario, SMF network elements in the terminal's home network may be denoted as H-SMF network elements, and SMF network elements in the terminal's visited network may be denoted as V-SMF network elements. V-SMF network elements and H-SMF network elements can exchange information through interface 16 (denoted as N16).
[0118] UPF network elements are primarily responsible for performing functions related to external connectivity to the data network (DN), user plane data packet routing and forwarding, packet filtering, and quality of service (QoS) control. UPF network elements that are directly connected to the DN via N6 in a session are called protocol data unit (PDU) session anchors (PSAs). Specifically, the core network may include UPF network elements connected to DNS servers (sometimes called central DNS servers) within the central data network (Central DN), and these UPF network elements are sometimes specifically called center PSAs (C-PSAs). The core network may also include UPF network elements connected to DNS servers within the local data network (Local part of DN), and these UPF network elements are sometimes specifically called local PSAs (L-PSAs). A local data network is a group of network entities located within a local data network, or it means that a data network is located locally.
[0119] In an HR roaming scenario, as shown in Figure 1A, UPF network elements within the terminal's home network may be referred to as H-UPF network elements, and UPF network elements within the terminal's visited network may be referred to as V-UPF network elements. V-UPF network elements and H-UPF network elements can exchange information through interface 9 (referred to as N9).
[0120] The UDM network element is primarily responsible for storing subscription data, credentials, and Subscriber Permanent Identifiers (SUPIs) of subscribed terminal devices within the network. The service-based interface represented by the UDM network element is the Nudm. This data can be used for authentication and authorization for terminal devices to access the operator network.
[0121] The AUSF network element is primarily responsible for authenticating terminal devices.
[0122] The PCF network element is primarily responsible for providing a centralized policy framework for network behavior management, providing policy rules for control plane functions, and obtaining registration information related to policy decisions. The service-based interface represented by the PCF network element is Npcf.
[0123] In an HR roaming scenario, as shown in Figure 1A, the PCF network elements within the terminal's home network may be referred to as H-PCF network elements, and the UPF network elements within the terminal's visited network may be referred to as V-PCF network elements. The V-PCF network elements and H-PCF network elements can exchange information through interface 24 (referred to as N24).
[0124] NSSF network elements are primarily responsible for selecting a set of network slice instances to serve the UE using network slicing technology, and for providing personalized network services to users by slicing a single physical network into multiple logical networks for multiple purposes.
[0125] In HR roaming scenarios, NSSF network elements within the terminal's home network may be referred to as H-NSSF network elements, and NSSF network elements within the terminal's visited network may be referred to as V-NSSF network elements. V-NSSF network elements and H-NSSF network elements are interfaces (referred to as N31). 31 Information can be exchanged through this.
[0126] It should be noted that the above functional networks may operate independently or may be combined to implement several control functions, such as access control and mobility management functions including access authentication, security encryption, and location registration for terminal devices, as well as session management functions such as establishing, releasing, and modifying user plane transmission paths.
[0127] The functional network elements shown in Figure 1 can communicate with each other through network interfaces. For example, a UE may send control plane messages to an AMF network element through interface 1 (denoted as N1), a RAN network element may establish a user plane data transmission channel with a UPF network element through interface 3 (denoted as N3), a RAN network element may establish a control plane signaling connection to an AMF network element through interface 2 (denoted as N2), a UPF may exchange information with an SMF network element through interface 4 (denoted as N4), a UPF network element may exchange user plane data with a data network DN through interface 6 (denoted as N6), different UPF network elements may exchange information with each other through interface N9, an AMF network element may exchange information with an SMF network element through interface 11 (denoted as N11), an SMF network element may exchange information with a PCF network element through interface 7 (denoted as N7), and an AMF network element may exchange information with an AUSF network element through interface 12 (denoted as N12). It should be noted that Figure 1 is merely an illustrative architectural diagram, and the network architecture may include other functional units in addition to those shown in Figure 1. This is not limited to the present invention.
[0128] In edge computing (EC) deployment scenarios, several services may be provided by multiple edge application servers (EAS) located at the network edge. When a terminal needs to access these services, in an EC scenario, the terminal is required to access the nearest available EAS. Therefore, the terminal needs to obtain the network protocol (IP) address of the appropriate EAS. The terminal can obtain the network protocol address via an edge application server discovery function (EASDF) network element that is located in the network and configured to assist the terminal in discovering the EAS. The EASDF network element primarily handles Domain Name System (DNS) messages based on the indication of the SMF network element, and its handling operations include receiving DNS query messages containing a fully qualified domain name (FQDN) and originating from the UE, and reporting the FQDN in the DNS query message to the SMF network element. In addition, the EASDF network element receives information from the SMF network element to construct an extended mechanism for the DNS-client-subnet (ECS) option (referred to as information for constructing the ECS option), and adds an ECS option information element to the DNS query based on the information for constructing the ECS option. The EASDF network element sends the processed DNS query to the DNS server, receives a DNS response message from the DNS server to obtain the IP address of the EAS corresponding to the FQDN queried by the UE, and sends that IP address to the UE.
[0129] When a device roams within a VPLMN, the HPLMN may authorize the offloading of services corresponding to one or more FQDNs to the VPLMN's local data network. However, for FQDNs that the HPLMN has not authorized to offload services to the VPLMN's local data network, the quality of services obtainable from the FQDN by the device may be limited. For example, when roaming within a VPLMN, a device may fail to access services corresponding to domain names that are not authorized to be offloaded to the VPLMN's local data network.
[0130] To address the above problem, embodiments of this application provide a corresponding solution. A functional network element used to discover an application server (AS) may obtain information about the terminal's home network and, when providing the AS discovery service to the terminal, provide this information to a DNS server, thereby enabling the DNS server to find the address of an AS corresponding to a domain name that is not authorized to offload services to the local DN of the terminal's serving network. The functional network element used to discover the AS then provides that address to the terminal. In this way, the terminal can obtain the address of an AS corresponding to a domain name in the serving network that is not authorized to offload services to the local DN of the terminal's serving network, and the terminal can access the services requested by the terminal. This improves the communication quality of the terminal.
[0131] Figure 2 is a schematic flowchart of communication method 200 according to an embodiment of this application. In communication method 200, the terminal's serving network may be a visited network, i.e., the terminal roams within the visited network. Alternatively, the terminal's serving network may be an intermediate network where the PLMN is the same as the terminal's home network PLMN. The intermediate network may be understood as a network containing intermediate network elements that provide services to the terminal. For example, an Intermediate SMF (I-SMF) network element provides session management services to the terminal. According to method 200, the terminal can access an AS within the visited network or intermediate network by finding the address of an AS corresponding to an unauthorized domain name in the visited network or serving network. Alternatively, the serving network may be the terminal's home network. For example, in the embodiment shown in Figure 2, the terminal needs to query the address of an AS that does not cooperate with the terminal's home network, or in other words, the AS cooperates with other operator networks other than the terminal's home network. According to Method 200, a terminal can discover the address of an AS and access an AS that does not cooperate with the home network. Hereinafter, we will primarily use an example where the terminal's serving network is the terminal's visited network for illustrative purposes. This application is not limited thereto, and the serving network may alternatively be the intermediate network or home network described above.
[0132] The first network element is a functional network element located within the terminal's current serving network and configured to discover ASs. For example, the first network element may be referred to as an edge application server discovery functional EASDF network element, or an application server discovery functional ASDF network element. Method 200 includes, but is not limited to, the following steps:
[0133] S201: The terminal sends a first query message to a first network element, the first query message containing information about a first domain name.
[0134] The first query message is used to query the address of the AS corresponding to the first domain name, and the AS is configured to provide services to the terminal.
[0135] The first network element receives a first query message from a terminal. The first network element determines that the terminal queries the address of the AS corresponding to the first domain name. The information about the first domain name in the first query message may be the first domain name itself. For example, the first domain name may be a fully qualified domain name (FQDN). Alternatively, the information about the first domain name may be an identifier for the first domain name. The information about the first domain name is used by the first network element to determine the first domain name. The specific implementation of the information about the first domain name is not limited in this application. The first domain name may also be described as service information; that is, service information may be expressed using a domain name, or using a uniform resource identifier (URI) / uniform resource locator (URL), or using an application identifier. This is not limited in this application, and the domain name is used only as an example for illustrative purposes.
[0136] A first network element may determine that a first domain name is not authorized in the serving network. In this application, a domain name being not authorized in the terminal's serving network includes the fact that the offloading of services corresponding to the domain name to a local DN is not authorized by the terminal's home network, and a domain name being authorized in the terminal's serving network includes the fact that the offloading of services corresponding to the domain name to a local DN is authorized by the terminal's home network. A local DN is a locally located and / or distributed DN. A local DN may be accessed by network elements in a visited network, or in other words, a terminal may access a local DN via a visited network. For example, a first domain name being not authorized in the terminal's serving network includes the fact that the offloading of services corresponding to the first domain name to a local DN is not authorized by the terminal's home network.
[0137] In any implementation, the first network element may obtain information about domain names that are authorized by the serving network and / or information about domain names that are not authorized by the serving network, and the first network element may determine, based on the information about domain names, that the first domain name is not authorized by the serving network.
[0138] In one example, a first network element obtains information about domain names that are accepted in the serving network, and this information may include a first set of domain names, the first set of domain names includes one or more domain names that are accepted in the serving network, and the first network element may determine that a first domain name is not accepted in the serving network based on cases where the first domain name does not belong to the first set of domain names.
[0139] In another example, the first network element obtains information about domain names not authorized in the serving network, and this information may include a second set of domain names, and the first network element obtains information about domain names authorized in the serving network and information about domain names not authorized in the serving network. The first set of domain names includes one or more domain names not authorized in the serving network. The first network element may determine that the first domain name is not authorized in the serving network based on the cases in which the first domain name belongs to the second set of domain names.
[0140] In further examples, information about a domain name may include both a first set of domain names and a second set of domain names. In this case, the first network element determines that the first domain name is not an authorized domain name in the serving network based on the cases where the first domain name does not belong to the first set of domain names and / or where the first domain name belongs to the second set of domain names.
[0141] The method by which the first network element obtains information about a domain name is not limited to the following methods:
[0142] In one scheme, the first network element obtains information about the domain name from the configuration information of the first network element (for example, configuration information stored within the first network element). In other words, the information about the domain name is configured within the first network element.
[0143] For example, before the first network element receives the first query message, the second network element sends information about the domain name to the first network element, and the first network element stores the information about the domain name in its configuration information. After receiving the first query message, the first network element retrieves the information about the domain name from the configuration information.
[0144] In another configuration, after the first network element receives the first query message, the first network element may send a request message to the second network element, which is used to request information about domain names that are authorized in the serving network and / or about domain names that are not authorized in the serving network. After receiving the request message, the second network element sends the information about the domain names requested by the request message to the first network element. Based on the information about the domain names, the first network element determines that the first domain name is not authorized in the serving network.
[0145] The second network element may be a functional network element located within the terminal's serving network and configured to manage the terminal's session; the second network element may be referred to as a session management functional SMF network element.
[0146] In one example, the terminal's serving network may be the terminal's destination network, where the first network element is an EASDF network element within the destination network, i.e., a V-EASDF network element, and the second network element is an SMF network element within the destination network, i.e., a V-SMF network element. The V-SMF network element may transmit information about a domain name to the V-EASDF network element. The information about a domain name may be included in VPLMN offloading info transmitted by the V-SMF network element to the V-EASDF network element. For example, the information about a domain name may be service information that is in the VPLMN offloading info and is authorized to be offloaded in the destination network (authorized traffic for Home Routed with Session Breakout in VPLMN), or it may be service information that is in the VPLMN offloading info and is not authorized to be offloaded in the destination network (unauthorized traffic for Home Routed with Session Breakout in VPLMN). However, this application is not limited thereto.
[0147] In any other implementation, after receiving the first query message, the first network element sends the first domain name to the second network element, and the second network element determines that the first domain name is not authorized on the serving network based on the first domain name, information about domain names authorized on the serving network and obtained by the second network element, and / or information about domain names not authorized on the serving network and obtained by the second network element, and the second network element sends information about the terminal's home network to the first network element. The information about the home network is used by the first network element to determine the second query message in S202.
[0148] In one system, a first network element may determine, based on information about the acquired terminal's home network, that the first domain name is not authorized on the serving network.
[0149] In other schemes, the first network element does not need to determine whether the first domain name is authorized in the serving network. After obtaining information about the terminal's home network from the second network element, the first network element determines the second query message in S202 based on the first query message and the information about the terminal's home network. S202: The first network element sends the second query message to the DNS server, which includes information about the first domain name and information about the terminal's home network, the home network information being used to determine the AS address corresponding to the first domain name.
[0150] The information about the terminal's home network in the second query message can be considered as information used to obtain the AS address corresponding to the first domain name.
[0151] In S201, the first network element decides, based on the first query message, that the terminal queries the AS address corresponding to a first domain name that is not authorized in the serving network. In this case, the first network element adds information about the terminal's home network, obtained before the first network element receives the first query message, and information about the first domain name, obtained based on the first query message, to the second query message and sends the second query message to the DNS server. Alternatively, after receiving the first query message, the first network element sends the first domain name to the second network element, obtains information about the home network from the second network element, and sends a second query message to the DNS server containing the first domain name and information about the terminal's home network.
[0152] The first network element sends a second query message to a DNS server containing information about the terminal's home network, which the DNS server may determine, based on the information about the terminal's home network in the second query message, the address of the AS corresponding to the first domain name that is not authorized in the terminal's serving network, and the terminal can obtain the address of the AS corresponding to the first domain name that is not authorized in the serving network in the serving network (i.e., the visited network or intermediate network).
[0153] For example, the second query message includes an ECS option information element, and the ESC option information element indicates information about the terminal's home network.
[0154] Information about the terminal's home network may be information representing the location of the home network. For example, information about the terminal's home network may be address information representing the location of the home network. For example, information about the terminal's home network may be the terminal's Internet Protocol (IP) address, the IP address of a user plane functional network element within the terminal's home network, or the dedicated address of the terminal's home network. After obtaining information about the terminal's home network through the second query message, the DNS server may determine the AS address corresponding to the first domain name based on address affinity.
[0155] For example, information about a terminal's home network might be the terminal's IP address 1. IP address 1 can be used to obtain the AS address corresponding to an unauthorized domain name in the serving network. Terminal's IP address 1 is anchored to a UPF network element within the terminal's home network. A second query message includes terminal's IP address 1, and the DNS server can determine the AS address corresponding to the first domain name based on IP address 1.
[0156] A terminal's home network may assign two IP addresses to the terminal. For example, in a multi-homed scenario, the network assigns IP address 1 and IP address 2 to the terminal. For instance, the source address of the first query message is the terminal's IP address 2, and the destination address of the first query message is the IP address of the first network element. In this case, the first network element may determine that the first query message originated from the terminal based on the case where the source address of the first query message is the terminal's IP address 2. However, this application is not limited thereto. The IP address belonging to the terminal and used to obtain the AS address corresponding to the first domain name, and the IP address belonging to the terminal and used by the terminal to receive or send messages, may be the same IP address of the terminal.
[0157] Alternatively, information about the terminal's home network may be the IP address of a UPF network element within the terminal's home network, or a dedicated address of the home network. The dedicated address of the terminal's home network may be a dedicated address used in the terminal's serving network to obtain the AS address corresponding to an unauthorized domain name, or the dedicated address of the home network may be used for other purposes, but is not limited to this application. For example, the dedicated address of the home network may be the terminal's IP address, which is an IP address obtained through network address translation (NAT). In another example, the dedicated address of the home network may be the address of a specific network element within the home network. Specifically, the dedicated address of the home network may be the address of a session management function network element within the home network, or an edge application server discovery function within the home network. Network elements The address is also acceptable.
[0158] In any implementation, after receiving a first query message, the first network element may provide the DNS server with information about the terminal's home network, according to the rules used for query messages from the terminal.
[0159] The second network element may send information to the first network element, which indicates rules to be used in query messages from the terminal. In response, the first network element receives information indicating rules to be used in query messages from the terminal.
[0160] Example 1: The rule includes a first network element providing information about the terminal's home network to the DNS server when a query message from the terminal contains a domain name that is not authorized on the visited network.
[0161] The second network element may obtain information about the terminal's home network from network elements within the home network and then transmit this information to the first network element. The information about the terminal's home network may be included in the above-mentioned information that defines the rules.
[0162] The rules indicated to the first network element by the second network element include, in particular, that if a query message from a terminal contains a domain name that is not authorized in the visited network, the first network element shall include information about the terminal's home network and the unauthorized domain name in a single message and provide that message to the DNS server.
[0163] For example, the second network element may be an SMF network element in the terminal's serving network, and the first network element may be an EASDF network element in the terminal's serving network. In this case, the SMF network element sends DNS context update information to the EASDF network element, which includes rules used in query messages from the terminal, and the rules include that when a query message received from the terminal contains a domain name not authorized in the visited network, the EASDF network element adds information about the terminal's home network as an ECS option information element to the query message and provides the query message to the DNS server. After the EASDF network element receives the first query message from the terminal, the EASDF network element adds information about the terminal's home network as an ECS option information element to the first query message to obtain a second query message, and sends the second query message to the DNS server, whereupon the DNS server determines the AS address corresponding to the first domain name based on the information about the home network used as an ECS option information element.
[0164] In Example 2, the rule includes receiving a query message from a terminal and then providing the domain name in the query message to a second network element.
[0165] As described above, the second network element transmits the first domain name to the second network element according to the rules, the second network element determines that the first domain name is not authorized on the serving network, transmits information about the terminal's home network to the first network element, and the first network element provides information about the terminal's home network to the DNS server.
[0166] For example, the first network element is an EASDF network element in the serving network, and the second network element is an SMF network element in the serving network. In this case, the SMF network element determines the ECS options corresponding to the first domain name (or, in other words, determines the information that corresponds to the domain name and is used to construct the ECS options) based on the first domain name reported by the EASDF network element. The V-SMF network element sends information about the terminal's home network to the EASDF network element. The EASDF network element may add information about the terminal's home network as an ECS option to the second query message, so that the second query message includes information about the terminal's home network. In this example, the EASDF network element does not need to determine whether the first domain name is authorized in the serving network.
[0167] The difference between Example 2 and Example 1 is that in Example 1, the first network element obtains information about the terminal's home network before receiving the first query message and, based on the case where the first domain name is not authorized on the serving network, decides that the second query message should include information about the terminal's home network. However, in Example 2, after receiving the first query message and sending the first domain name to the second network element, the first network element obtains information about the terminal's home network and decides that the second query message should include information about the terminal's home network.
[0168] For example, both the first and second query messages are sometimes referred to as DNS query messages.
[0169] S203: The DNS server sends the AS address corresponding to the first domain name to the first network element.
[0170] In response, the first network element receives the AS address corresponding to the first domain name from the DNS server.
[0171] For example, a DNS server sends a second response message to a first network element in response to a second query message, and the second response message contains the address of the AS corresponding to the first domain name. The first network element receives the second response message from the DNS server and, based on the second response message, determines the address of the AS corresponding to the first domain name.
[0172] S204: The first network element sends the AS address corresponding to the first domain name to the terminal.
[0173] In response, the terminal receives the AS address corresponding to the first domain name from the first network element.
[0174] For example, a first network element sends a first response message to a terminal in response to a first query message, the first response message containing the address of the AS corresponding to the first domain name. The terminal receives the first response message from the first network element and, based on the first response message, determines the address of the AS corresponding to the first domain name.
[0175] According to the above solution, when a first network element receives a query message from a terminal that contains a domain name not authorized in the serving network, the first network element may provide information about the terminal's home network to the DNS server, thereby allowing the DNS server to find the AS address corresponding to the first domain name based on the information about the terminal's home network and feed that address back to the terminal. In this way, the terminal can obtain the AS address corresponding to the domain name not authorized in the serving network in the serving network (visited network or intermediate network), thereby allowing the terminal to access services provided by the AS. This ensures that the terminal device can access services corresponding to the unauthorized domain name and avoids the situation where the terminal cannot access services corresponding to a domain name because the domain name is not authorized.
[0176] Figure 3 is a schematic flowchart of the communication method 300 according to an embodiment of this application. The embodiment shown in Figure 3 shows a specific implementation of the embodiment shown in Figure 2 applied to a scenario in which the serving network of a terminal (a UE is used as an example) is a visited network. The V-EASDF network element is an example of a first network element, and in the visited network, the V-EASDF network element is a functional network element configured to provide AS discovery functionality to the UE. The V-SMF network element is an example of a second network element, and in the visited network, the V-SMF network element is a functional network element configured to manage the UE's session. The AMF network element is a functional network element located in the visited network and configured for access management and / or mobility management to the UE. The H-SMF network element is a functional network element located in the UE's home network and configured to manage the UE's session. The names of the network elements should be understood to be not limited in this application. In specific implementations, the communication method 300 may be carried out by network elements having other names and corresponding functions. Method 300 includes, but is not limited to, the following steps:
[0177] S301:UE may send a NAS message to an AMF network element, which may include a session establishment / modification request message.
[0178] A session establishment / modification request message is either a session establishment request message or a session modification request message.
[0179] The UE initiates the home root HR session establishment / correction procedure by sending a NAS message carrying session establishment / correction request information to an AMF network element in the visited network. In response, the AMF network element receives the NAS message from the UE and, based on the session establishment / correction request information in the NAS message, decides that the UE should initiate the HR session establishment procedure.
[0180] S302: The AMF network element sends a Create / Update Session Management Context Request message to the V-SMF network element, and the request message carries HR-SBO allowed indication information.
[0181] HR-SBO authorization indication information indicates that the service in the HR session is authorized (or authorized) to be offloaded locally (i.e., VPLMN). An AMF network element may determine HR-SBO authorization indication information based on the home network subscription information.
[0182] For example, the request message to create a session management context is N SMF Protocol Data Unit (PDU) Session Creation / Update Management Context Request (N SMF This message is sometimes referred to as the _PDUSession_Create / UpdateSMContext request.
[0183] S303: V-SMF network elements and V-EASDF network elements perform the DNS context creation / update process.
[0184] After a V-SMF network element receives a create / update session management context request message from an AMF network element, the V-SMF network element selects a V-EASDF network element to be used to discover the AS for the terminal, and the V-SMF and V-EASDF network elements then execute the DNS context creation / update process for the V-EASDF network element.
[0185] The DNS context may include, but is not limited to, the UE's IP address, data network name (DNN), and single network slice selection assistance information (S-NSSAI) used to identify network slices. In this case, since the visited network does not exchange information with the home network and does not obtain an IP address that has not been assigned to the UE by the home network, the IP address belonging to the UE and included in the DNS context should be understood as a special value or special IP address that can be used to identify the UE.
[0186] The DNS context creation process may include a V-SMF network element calling a DNS context creation / update request message, sending the message to a V-EASDF network element, and receiving a DNS context creation / update response message from the V-EASDF network element. This creates / updates the DNS context of the V-EASDF network element. For example, the DNS context creation / update request message is N EASDF DNS context creation / update request (N EASDF This is sometimes referred to as the _DNSContext_Create / Update Request) message. The DNS context creation / update response message is N EASDF DNS context creation / update response (NEASDF This message is sometimes referred to as the _DNSContext_Create / Update Response) message.
[0187] S304: The V-SMF network element sends a session creation / renewal request message to the H-SMF network element.
[0188] After completing the creation / update of the DNS context for the V-EASDF network element, the V-SMF network element sends a session creation / update request message to the H-SMF network element, which includes HR-SBO authorization indication information obtained from the AMF network element in S302. After receiving the session creation / update request message from the V-SMF network element, the H-SMF network element determines, based on the HR-SBO authorization indication information in the session creation / update request message, that the UE's visited network is requesting authorization for the service in the session to be offloaded locally to the visited network.
[0189] For example, the session creation request message is N SMF This message is sometimes referred to as a PDU session creation / update request message.
[0190] S305: The H-SMF network element sends a session creation / update response message to the V-SMF network element, and the session creation / update response message carries VPLMN offload information.
[0191] In response, the V-SMF network element receives a session creation / update response message from the H-SMF network element and obtains VPLMN offload information. For example, the session creation / update response message is N SMF PDU session creation / update response It is sometimes referred to as a message.
[0192] The VPLMN offload information includes information about the domain names described above, for example, information about domain names that are authorized in the visited network (this information may include a first set of domain names), and / or information about domain names that are not authorized in the visited network (this information may include a second set of domain names). For example, the domain names in the set of domain names may be FQDNs or other domain names. The following explanation uses an example where the domain names are FQDNs.
[0193] A V-SMF network element may determine, based on VPLMN offload information, that the UE's home network has authorized the offloading of the corresponding service to the domain name of the local data network of the visited network, and / or, based on VPLMN offload information, that the UE's home network has not authorized the offloading of the corresponding service to the domain name of the local data network of the visited network.
[0194] In any implementation, the VPLMN offload information may further include addresses of ASes authorized in the visited network and / or addresses of ASes not authorized in the visited network. For example, the AS addresses may specifically be the IP addresses of the ASes. Based on the VPLMN offload information, a V-SMF network element may determine the addresses of ASes authorized by the UE's home network to offload the corresponding services to the local data network of the visited network, and / or, based on the VPLMN offload information, a V-SMF network element may determine the addresses of ASes not authorized by the UE's home network to offload the corresponding services to the local data network of the visited network.
[0195] In addition to VPLMN offload information, the session creation / update response message further includes the UE's IP address, i.e., the IP address assigned to the UE by the home network. In any implementation, the session creation / update response message includes two IP addresses assigned to the UE by the network, e.g., IP address 1 and IP address 2. As described above, IP address 1 may be used to obtain the AS address corresponding to an unapproved domain name in the visited network, and IP address 1 is fixed in the UPF network element within the terminal's home network. IP address 2 is used to receive or send messages (or packets). However, this application is not limited thereto. Alternatively, the session creation / update response message may include only one IP address assigned to the UE by the home network to accomplish the two functions described above.
[0196] The session creation / renewal response message may further include tunnel information for a UPF network element (i.e., an H-UPF network element) within the home network. The tunnel information for the H-UPF network element is used to establish a tunnel connection between the H-UPF network element and a UPF network element (i.e., a V-UPF network element) within the visited network. The tunnel information for the H-UPF network element may consist of the IP address of the H-UPF network element and a tunnel endpoint identifier (TEID).
[0197] In the embodiment shown in Figure 3, the session creation / renewal response message may further include information about the UE's home network, which is provided by the V-SMF network element to the V-EASDF network element, so that when a query message received from the UE includes a domain name that is not authorized on the visited network, the V-EASDF network element provides the home network information to the DNS server. In other words, the H-SMF network element transmits information about the UE's home network to the V-SMF network element. However, this application is not limited thereto. Alternatively, the H-SMF network element may add information about the UE's home network to another message or information element and transmit that information to the V-SMF network element.
[0198] S306: V-SMF network elements and V-EASDF network elements perform the DNS context update process.
[0199] A V-SMF network element updates the DNS context of a V-EASDF network element, which involves the V-SMF network element sending DNS message handling rules.
[0200] In any implementation, the rule includes providing the DNS server with information about the UE's home network when a query message is received from a terminal and contains a domain name that is not authorized on the visited network. For example, the information about the UE's home network may include the UE's IP address, the IP address of the UE's H-UPF network element, or the home network's dedicated address.
[0201] If the information about the UE's home network includes the dedicated address of the home network, the dedicated address of the home network can be obtained by the V-SMF network element from the H-SMF network element. However, this application is not limited thereto.
[0202] Specifically, the rule can include that when a query message containing a domain name that is from the terminal and not approved in the destination network is received, information about the UE's home network is added to the query message, and the processed query message is provided to the DNS server.
[0203] In any other implementation, the rule can include providing the domain name in the query message to a second network element after receiving the query message from the terminal.
[0204] The DNS context update process can include that the V-SMF network element invokes a DNS context update request message, sends the DNS context update request message to the V-EASDF network element, and receives a DNS context creation response message from the V-EASDF network element. Thereby, the DNS context of the V-EASDF network element is updated. For example, the DNS context update message can carry DNS handling rules. Optionally, the DNS context update request message can further carry, but is not limited to, one or more of the following information: information about the UE's home network, information about the domain names approved in the destination network, or information about the domain names not approved in the destination network.
[0205] For example, the DNS context update request message can be N EASDF DNS context update (N EASDF _DNSContext_Update Request) message may be denoted. The DNS context update response message is NEASDF DNS context update response (N EASDF This message is sometimes referred to as the _DNSContext_Update Response) message.
[0206] After the V-SMF network element has finished updating the DNS context of the V-EASDF network element, the network element in the visited network may continue to perform other steps of the UE's session creation / modification (not shown in Figure 3), which include the V-SMF network element sending a session creation / modification accept message to the UE, the session creation / modification accept message carrying the address of the V-EASDF network element. After receiving the session creation / modification accept message, the UE may determine the address of the V-EASDF network element to be used to discover the AS for the UE.
[0207] When a UE needs to query a service, it initiates a service query process, which specifically includes the following steps:
[0208] S307:UE sends the first query message to the V-EASDF network element, and the first query message carries the FQDN1.
[0209] The source IP address of the first query message is the IP address of the UE, and the destination IP address of the first query message is the address of the V-EASDF network element. Accordingly, the V-EASDF network element receives the first query message from the UE and decides that the UE queries the AS address corresponding to FQDN1. Specifically, the first query message may be forwarded to the V-EASDF network element via the user plane. For example, the first query message may be forwarded to the V-EASDF network element via the RAN and V-UPF network elements.
[0210] S308: The V-EASDF network element determines the second query message. The second query message includes the FQDN1 and information about the UE's home network.
[0211] In any implementation, a V-EASDF network element may retrieve information about a domain name. For example, a V-EASDF network element may retrieve information about a domain name from a DNS context and, based on that information, determine that FQDN1 is an unauthorized domain name in the visited network. For example, if the information about a domain name includes a first set of domain names, and the domain names included in the first set are authorized domain names in the visited network, then the V-EASDF network element determines that FQDN1 does not belong to the first set of domain names and therefore determines that FQDN1 is an unauthorized domain name in the visited network. Alternatively, for example, if the information about a domain name includes a second set of domain names, and the domain names included in the second set are unauthorized domain names in the home network, then the V-EASDF network element determines that FQDN1 belongs to the second set of domain names and therefore determines that FQDN1 is an unauthorized domain name in the visited network.
[0212] If the V-EASDF network element determines that the FQDN1 queried by the UE is an unauthorized domain name in the visited network, the V-EASDF network element determines a second query message according to DNS message handling rules, and the second query message includes the FQDN1 and information about the UE's home network. For example, the V-EASDF network element obtains the second query message by adding information about the UE's home network to the first query message.
[0213] The DNS message handling rule specifically includes, when a query message is received from a terminal and contains a domain name not authorized on the visited network, adding information about the UE's home network to the query message as an ECS option and providing the query message to the DNS server. The V-EASDF network element may, in accordance with the handling rule, add information about the UE's home network to the first query message as an ECS option and obtain a second query message.
[0214] In any other implementation, after receiving the first query message, the V-EASDF network element provides the FQDN1 to the V-SMF network element according to the DNS query message handling rules. The V-SMF network element determines the ECS options corresponding to the FQDN1 based on the FQDN1 (or, in other words, determines the information that corresponds to the FQDN1 and is used to construct the ECS options). The V-SMF network element sends information about the UE's home network to the V-EASDF network element. The V-EASDF network element may add the information about the UE's home network as an ECS option to the second query message, so that the second query message includes information about the terminal's home network.
[0215] S309:V-EASDF network element sends a second query message to the DNS server.
[0216] In response, the DNS server receives a second query message from the V-EASDF network element. Based on the FQDN1, information about the UE's home network, and address affinity, the DNS server can determine the AS address corresponding to the FQDN1.
[0217] S310: The DNS server sends the AS address corresponding to FQDN1 to the V-EASDF network element.
[0218] For example, a DNS server sends a second response message to a V-EASDF network element for a second query message, and the second response message contains the address of the AS corresponding to FQDN1. The V-EASDF network element receives the second response message from the DNS server and determines the address of the AS corresponding to FQDN1 based on the second response message.
[0219] S311: The V-EASDF network element sends the AS address corresponding to FQDN1 to the UE.
[0220] In response, the UE receives the AS address corresponding to FQDN1 from the V-EASDF network element.
[0221] For example, a V-EASDF network element sends a first response message to a first query message, and the first response message contains the address of the AS corresponding to FQDN1. The UE receives the first response message from the V-EASDF network element and determines the address of the AS corresponding to FQDN1 based on the first response message.
[0222] As described above, in S308, if the V-EASDF network element can determine that FQDN1 is a domain name not authorized in the visited network, S309 to S311 are executed. If the V-EASDF network element determines that FQDN1 is a domain name not authorized in the visited network, the V-EASDF network element exchanges information with the V-SMF network element and triggers the V-SMF network element to insert / update the VPLMN ULCL / BP / L-PSA. The V-EASDF network element reports FQDN1 to the V-SMF network element. The V-SMF network element determines the ECS option establishment indication information based on FQDN1 and AS placement information (including information such as FQDN and data network access identifier (DNAI)), and sends the ECS option establishment indication information to the V-EASDF network element. The V-EASDF network element then adds the ECS option to the first query message based on the ECS option establishment indication information and sends the processed query message to the DNS server. The DNS server queries the AS address corresponding to FQDN1 based on the received query message and sends that address to the V-EASDF network element. The V-EASDF network element then reports the AS address corresponding to FQDN1 to the V-SMF network element, triggering V-SMF to insert or update ULCL / BP / L-PSA. The V-SMF network element instructs the V-EASDF network element to send a response message to the UE for the first query message, and the response message carries the AS address corresponding to FQDN1.
[0223] According to the above solution, when a V-EASDF network element receives a query message from a UE that contains a domain name not authorized in the visited network, the V-EASDF network element may provide information about the UE's home network to the DNS server, which can then find the AS address corresponding to FQDN1 based on the information about the UE's home network and feed that address back to the terminal. In this way, the terminal can obtain the AS address corresponding to the domain name not authorized in the serving network in the visited network, thereby enabling the terminal to access services provided by the AS.
[0224] Embodiments of this application further provide a method in which, when a query message from a terminal includes a domain name that is not authorized by the home network to offload service to a local DN corresponding to the serving network, the core network of the serving network may forward the query message to the home network via a control plane network element, and the query message is then forwarded to a server in the local DN corresponding to the home network or a central server. In this way, the terminal can obtain the address of an AS corresponding to a domain name that is not authorized in the serving network.
[0225] Figure 4 is a schematic flowchart of the communication method 400 according to an embodiment of this application. As shown in Figure 4, the first network element is a network element located in the terminal's serving network (e.g., a visited network or intermediate network) and configured to discover AS; the second network element is a network element located in the terminal's serving network and configured to manage the terminal's session; the third network element is a network element in the terminal's home network, and the DNS server is a local server or a central server corresponding to the home network. Alternatively, the DNS server shown in Figure 4 may be replaced with a network element located in the home network and configured to discover AS, which is sometimes referred to as a DNS resolver. Hereafter, a DNS server will be used as an example for explanation. Method 400 includes, but is not limited to, the following steps.
[0226] S401: The terminal sends a first query message to a first network element, and the first query message contains information about a first domain name.
[0227] In response, the first network element receives the first query message from the terminal. The first network element determines that the terminal is querying the AS address corresponding to the first domain name, and may determine that the first domain name is not authorized in the serving network. S401 may be implemented with reference to the above description of S201. Further details are not described again here.
[0228] S402: The first network element sends a second query message to the second network element, the second query message containing information about the first domain name.
[0229] In any implementation, the first network element may determine a second query message based on the case where the first domain name contained in the received first query message is a domain name not authorized in the serving network, and may send the second query message to the second network element. Specifically, the first network element may determine a second query message according to the rules used for the query message, and may decide to send the second query message to the second network element.
[0230] For example, a second network element may send information to a first network element, which may originate from a terminal and indicate rules to be used in a query message used to query the address of an application server. In response, the first network element receives the information from the second network element and determines the rules to be used in the query message based on that information. When the first network element receives the query message, it processes (handles) the query message according to those rules. For example, the information may be carried in a DNS context update message sent to the first network element by the second network element.
[0231] The rules are not limited, but may include the following implementations:
[0232] Method 1 is denoted as Rule 1, and Rule 1 includes the first network element sending a query message containing an unauthorized domain name to a second network element when the query message used to query the address of an AS contains an unauthorized domain name in the network visited by the terminal.
[0233] After receiving a first query message containing a first domain name that is not authorized in the serving network, the first network element determines a second query message according to Rule 1, sends the second query message to the second network element, and the second query message contains information about the first domain name.
[0234] For example, a first network element may send a first query message to a second network element, the second query message being the first query message, the source address of the first query message being the IP address of the terminal, and the destination address of the first query message being the address of the first network element. However, this application is not limited thereto. The second query message may be different from the first query message. For example, at least some of the information contained in the second query message may be different from that contained in the first query message.
[0235] Method 2 is denoted as Rule 2, and Rule 2 includes the first network element sending a query message to the second network element that contains an unauthorized domain name and whose destination address is the address of a DNS server when a query message used to query the address of an application server contains an unauthorized domain name in the network visited by the terminal.
[0236] The information that specifies the rules and is transmitted from the second network element to the first network element includes the address of a DNS server, which may be the address of the DNS server corresponding to the terminal's home network or the address of a central DNS server. The first network element is DNS server The address is obtained from that information.
[0237] After receiving a first query message containing a first domain name that is not authorized in the serving network, the first network element determines a second query message according to Rule 2, sends the second query message to the second network element, the second query message contains information about the first domain name, and the destination address of the second query message is the address of the DNS server.
[0238] For example, the source address of the first query message is the IP address of the terminal, and the destination address of the first query message is the address of the first network element. After changing the destination address of the first query message to an address belonging to a DNS server and obtained from the second network element, the first network element obtains the second query message and sends the second query message to the second network element. However, this application is not limited thereto. The second query message and the first query message may further include other different information in addition to different destination addresses.
[0239] In any other implementation, the first network element does not determine whether the first domain name is authorized in the serving network. For example, Rule 3 is a handling rule used in query messages and notified to the first network element by the second network element, which includes providing the domain name in the query message to the second network element when it receives the query message from a terminal. After receiving the first query message, the first network element sends the first domain name to the second network element according to Rule 3. Based on the first domain name and information obtained by the second network element about domain names authorized in the serving network and / or domain names not authorized in the serving network, the second network element determines that the first domain name is not authorized in the serving network, and the second network element sends indication information to the first network element, which indicates to the first network element that it should send the second query message to the second network element.
[0240] In one method, the first network element sends a first query message to the second network element based on the indication information; that is, the second query message is the first query message.
[0241] In another method, the indication information specifically tells the first network element to send a second query message to the second network element, and the destination address of the second query message is the address of the DNS server. In this way, after the first network element receives the indication information, it sends the second query message to the second network element, and the destination address of the second query message is the address of the DNS server.
[0242] In another configuration, Rule 3 further includes the fact that, after the first network element sends a domain name to the second network element and receives indication information that the second network element will send a query message, the destination address of the query message sent by the first network element to the second network element in response to the indication information is the address of a DNS server. The first network element may send a second query message, whose destination address is a DNS server, to the second network element in accordance with Rule 3.
[0243] Optionally, the first network element may obtain the DNS server address in particular before receiving the first query message, or may obtain the DNS server address from the indication information. The DNS server address may be the address of the DNS server corresponding to the terminal's home network, or the address of a central DNS server. The first network element is DNS server Obtain the address from the information.
[0244] In this implementation, if the second network element determines that the domain name from the first network element is a domain name recognized in the serving network, the second network element may determine ECS option establishment indication information based on the first domain name and AS placement information (including information such as the FQDN and data network access identifier (DNAI)), and send that ECS option establishment indication information to the V-EASDF network element, and the first network element adds the ECS option to the first query message based on the ECS option establishment indication information and sends the processed query message to the local DNS server in the destination network.
[0245] This application further provides a mechanism to replace S402. In other words, after S401, the first network element may, instead of performing S402, perform the following steps: the first network element transmits a first domain name to the second network element, and if the second network element determines that the first domain name is an unauthorized domain name in the serving network, the second network element determines (or generates) a third query message, the third query message containing the first domain name, and the destination address of the third query address being the address of a DNS server. The third query message is used in S403 by the second network element to query a DNS server for the address of the AS corresponding to the first domain name via a network element in the home network for a terminal.
[0246] S403: The second network element, for the terminal, uses network elements within the home network to query the DNS server for the AS address corresponding to the first domain name.
[0247] For a second network element to query a local DNS server within the home network (hereinafter referred to as the DNS server corresponding to the home network) or a central server for the address of the AS corresponding to the first domain name, using network elements within the home network for a terminal, includes the second network element receiving the second query message and then obtaining a third query message based on the second query message, wherein the third query message contains information about the first domain name, and the second network element sending the third query message to the third network element.
[0248] The third network element is a network element within the terminal's home network. The second network element forwards the third query message to the terminal's home network, thereby the second network element, on behalf of the terminal, uses the network elements within the home network to query the DNS server for the AS address corresponding to the first domain name.
[0249] The second query message received by the second network element from the first network element contains information about the first domain name, the source address of the second query message is the IP address of the terminal, and the destination address of the second query message is the address of the first network element.
[0250] In this case, in a certain implementation, the third query message sent by the second network element to the third network element is the second query message; that is, after obtaining the second query message from the first network element, the second network element forwards the second query message to the third network element. For example, the third network element may change the destination address of the second query message to the address of the DNS server corresponding to the home network or the address of the central server, so that the DNS server corresponding to the destination address can obtain the query message, and the DNS server can query the AS address corresponding to the first domain name for the terminal.
[0251] In this case, in other implementations, the destination address of the third query message sent by the second network element to the third network element is the address of a DNS server. The DNS server address may be obtained by the second network element from a network element within the home network, and the second network element sets the destination address of the third query message to the DNS server address. For example, the DNS server address may be the address of the DNS server corresponding to the terminal's home network, or it may be the address of a central server, so that the DNS server corresponding to the destination address can obtain the query message, and the DNS server queries for the terminal for the AS address corresponding to the first domain name.
[0252] For example, a second network element obtains a third query message by changing the destination address of the second query message to the address of a DNS server. However, this application is not limited thereto. The third and second query messages may further include other different information in addition to different destination addresses.
[0253] When a second network element receives a second query message from a first network element, the second query message contains information about the first domain name, the source address of the second query message is the terminal's IP address, and the destination address of the second query message is the DNS server's address. The third query message sent by the second network element to the third network element may be the second query message, or it may be obtained after the second query message has been processed by the second network element. The source address of the third query message is the terminal's IP address, and the destination address of the third query message is the DNS server's address, so that the DNS server corresponding to the destination address can obtain the query message, and the DNS server queries the terminal for the AS address corresponding to the first domain name.
[0254] S404: The terminal obtains the AS address corresponding to the first domain name from the DNS server.
[0255] After finding the AS address corresponding to the first domain name, the DNS server forwards the AS address to the network element in the serving network via the network element in the home network, and then forwards the AS address to the terminal.
[0256] For example, the AS address may be forwarded by a DNS server to a third network element, which then forwards it to a second network element, and then to a first network element, thereby allowing the terminal to obtain the AS address from the first network element. That is, the AS address is returned to the terminal via a network element that forwards query messages. However, this application is not limited thereto. The AS address may be forwarded to the terminal without using one or more network elements in the home network and the visited network that forward query messages.
[0257] According to the above solution, when an EASDF network element in the serving network receives a query message from a UE containing a domain name not authorized in the visited network, the EASDF network element sends the query message to an SMF network element, thereby the message can be forwarded to the home network via the SMF network element. The message is then forwarded through the home network, thereby allowing the DNS server or central server corresponding to the home network to find the AS address corresponding to the first domain name for the terminal, and to feed back the AS address corresponding to the first domain name to the terminal via the home network and the serving network. In this way, the terminal can access the services provided by the AS.
[0258] Figure 5 is a schematic flowchart of the communication method 500 according to an embodiment of this application. The embodiment shown in Figure 5 shows a specific implementation of the embodiment shown in Figure 4, applied to a scenario in which the serving network of a terminal (a UE is used as an example) is a visited network.
[0259] It should be understood that, prior to S501 in Method 500, S301 to S305 shown in Figure 3 may be performed between the UE and the network element. For details, please refer to the description in the embodiment shown in Figure 3. For parts of the embodiment shown in Figure 5 that are the same as those in the embodiment shown in Figure 3, please refer to the description in the embodiment shown in Figure 3. For brevity, details will not be described again here. Method 500 may include, but is not limited to, the following steps:
[0260] S501: V-SMF network elements and V-EASDF network elements execute the DNS context update process.
[0261] The V-SMF network element updates the DNS context of the V-EASDF network element, which includes the V-SMF network element sending DNS message handling rules to the V-EASDF network element. These rules may be rules 1 and 2 in the embodiment shown in Figure 4 above.
[0262] S502:UE sends a first query message to the V-EASDF network element, and the first query message includes the FQDN1.
[0263] In response, the V-EASDF network element receives the UE's first query message and determines that the UE is querying the AS address corresponding to FQDN1, and that FQDN1 is an unauthorized domain name in the UE's visited network.
[0264] S503: The V-EASDF network element determines the second query message.
[0265] The source IP address of the first query message is the UE's IP address, and the destination IP address of the first query message is the address of the V-EASDF network element. The V-EASDF network element obtains the second query message according to the DNS message handling rules obtained in S501.
[0266] In one example, the rule is Rule 1 above. In this case, the V-EASDF network element determines the second query message according to Rule 1, the second query message includes the FQDN1, the source address of the second query message is the UE's IP address, and the destination address of the second query message is the address of the V-EASDF network element.
[0267] In other examples, the rule is Rule 2 above. In this case, the V-EASDF network element determines the second query message according to Rule 2, the second query message includes the FQDN1, the source address of the second query message is the UE's IP address, and the destination address of the second query message is the DNS server address. The DNS server address may be the address of the DNS server corresponding to the home network or the address of the central server. The DNS server address may be obtained from the V-SMF network element by the V-EASDF network element in S501. The V-SMF network element may obtain the DNS server address from the home network. For example, the DNS server address may be included in the VPLMN offload information in the session creation / update response message.
[0268] In other examples, the rule is Rule 3. In this case, the V-EASDF network element sends FQDN1 to the V-SMF network element according to Rule 3. After the V-SMF network element determines that FQDN1 is an unauthorized domain name in the visited network, the V-SMF network element instructs the V-EASDF network element to send a query message to the V-SMF network element. The V-EASDF network element determines a second query message and sends it to the V-SMF network element, the second query message containing FQDN1, and the destination address of the second query message is either the address of the V-EASDF network element or the address of a DNS server. For the specific method by which the V-EASDF network element determines the second query message, see the relevant explanation in S402. Further details are not provided here.
[0269] For example, the address of a DNS server can be the IP address of the DNS server.
[0270] S504: The V-EASDF network element sends a DNS context notification message to the V-SMF network element, and the DNS context notification The message includes a second query message.
[0271] The V-EASDF network element sends a DNS context notification message containing a second query message to the V-SMF network element, in accordance with the DNS query message handling rules. In response, the SMF network element sends a DNS context notification message to the V-SMF network element. notification The system receives a message from the V-EASDF network element, obtains a second query message, and determines a third query message based on the second query message. For specific details, please refer to the explanation in S403 above. Further details will not be explained again here.
[0272] For example, a DNS context notification message is N EASDF DNS context notification (N EASDF This message is sometimes referred to as the _DNSContext_Notify) message.
[0273] S505: The V-SMF network element sends a session update request message to the H-SMF network element, and the session update request message includes a third query message.
[0274] In response, the H-SMF network element receives a session update request message from the V-SMF network element and obtains a third query message. For example, the session update request message is N SMF PDU session update request (N SMF This message is sometimes referred to as a _PDUSession_Update Request.
[0275] S506: The H-SMF network element forwards query messages to the DNS server.
[0276] In one example, the source address of the third query message is the IP address of the UE, and the destination address of the third query message is the address of the DNS server. In this case, the H-SMF network element may send the third query message to the H-UPF network element, which will send the third query message to the DNS server corresponding to the DNS server's address.
[0277] In other examples, the source address of the third query message is the UE's IP address, and the destination address of the third query message is V-EASDF. Network elementsThis is the address. In this case, the H-SMF network element can change the destination address of the third query message to the DNS server address and then send the third query message to the H-UPF network element. Alternatively, the H-SMF network element forwards the third query message to the H-UPF network element, and the H-UPF network element corrects the destination address of the third query message. Then the H-UPF network element sends the query message to the DNS server corresponding to the destination address. Alternatively, the H-UPF network element sends the third query message to the H-EASDF network element, and H-EASDF Network elements After correcting the destination address of the third query message, H-EASDF Network elements H-EASDF forwards the query message to the DNS server corresponding to the destination address. Network elements This modifies the destination address of the third query message according to the DNS handling rules delivered by the H-SMF network element.
[0278] S507: The terminal obtains the AS address corresponding to FQDN1 from the DNS server.
[0279] After determining the AS address corresponding to FQDN1, the DNS server sends a DNS response message. This DNS response message contains the AS address corresponding to FQDN1, and the source address of the DNS response message is the DNS server's address.
[0280] In one example, the destination address of the DNS response message is the IP address of the UE. The DNS response message may be forwarded by the DNS server to an H-UPF network element, and then forwarded to the UE via a V-UPF network element. Alternatively, the path by which the DNS response message is forwarded by the DNS server to the UE may be, in order, through an H-UPF network element, a V-UPF network element, a V-EASDF network element, and then another V-UPF network element, before the DNS response message is forwarded to the UE.
[0281] In other examples, the destination address of the DNS response message is the IP address of the V-EASDF network element, and the path through which the DNS response message is forwarded by the DNS server to the UE can, in sequence, pass through the H-UPF network element, the H-SMF network element, the V-SMF network element, the V-EASDF network element, and the V-UPF network element, and then the DNS response message is forwarded to the UE. Alternatively, the path through which the DNS response message is forwarded by the DNS server to the UE can, in sequence, pass through the H-UPF network element, the V-UPF network element, the V-EASDF network element, and the V-UPF network element, and then the DNS response message is forwarded to the UE.
[0282] According to the above solution, when the V-EASDF network element receives a query message containing an unapproved domain name in the visited network from the UE, the V-EASDF network element sends the query message to the V-SMF network element, whereby the message can be forwarded to the home network via the V-SMF network element. Then, the message is forwarded via the home network, whereby the DNS server or the central server corresponding to the home network can find the address of the AS corresponding to FQDN1 for the terminal and can feedback the address to the terminal via the home network and the serving network. In this way, the terminal can access the service provided by the AS.
[0283] This application further provides another solution in which the terminal queries the address of the AS corresponding to an unapproved domain name in the serving network by using the user plane of the serving network. The solution will be described below.
[0284] The terminal determines that the first domain name to be queried is not authorized in the serving network, and the terminal determines a first message, which includes a query message and indication information, the query message being used to query the AS address corresponding to the first domain name, and the indication information indicating that the query message is used to query the AS address corresponding to a domain name not authorized in the serving network, or the indication information indicating that the query message contains a domain name not authorized in the serving network.
[0285] In one configuration, the terminal adds indication information to the air interface protocol packet header and transmits that air interface protocol packet header to the access network element. For example, the indication information is added to the service data adaptation protocol (SDAP) header or the packet data convergence protocol (PDCP) header. The base station then adds the indication information to the core network user plane protocol packet header, for example, the general packet radio service (GPRS) tunneling protocol-user plane (GTP-U) header.
[0286] The terminal sends the first message to a UPF network element in the serving network. The UPF network element receives the first message. messageBased on the indication information within the first message, the UPF network element decides that the query message will be used to query the AS address corresponding to a domain name not authorized in the serving network, and sends the query message to the UPF network element in the terminal's home network, thereby enabling the UPF network element in the home network to find the AS address corresponding to the domain name not authorized in the serving network for the terminal. In this scheme, the UPF network element in the serving network does not need to interpret the query message in the first message and can decide to forward the query message to the UPF network element in the home network based on the indication information within the first message.
[0287] Specifically, the first message may include a container that carries the terminal's query message. Indication information within the first message is carried outside the container. After reading the indication information from the first message, the UPF network element in the serving network sends the container to the UPF network element in the home network. The UPF network element in the serving network transparently sends (or simply transmits) the container to the UPF network element in the home network.
[0288] In this solution, even if the terminal performs encryption protection on the query message (e.g., the query message is encrypted using the DOH or DOT encryption method), the UPF network element in the serving network cannot interpret the query message, and the UPF network element can still decide to forward the query message to the UPF network element in the home network without interpreting it, based on the indication information in the first message, thereby allowing the UPF network element in the home network to find the AS address corresponding to the domain name not authorized in the serving network for the terminal. DOH is an abbreviation for DNS over HTTPS, and DOH is a secure domain name resolution solution that performs DNS resolution using the encrypted HTTPS protocol. HTTPS stands for hypertext transfer protocol secure. DOT is a TLS-based packet encryption DNS request, and is an abbreviation for DNS over TLS, where TLS is... Transport Layer Security It refers to.
[0289] In the embodiments shown in Figures 2 to 5, it should be understood that the first and second network elements have the ability to decrypt encrypted query messages from the terminal. Therefore, regardless of whether the query message is encrypted or not, in the embodiments shown in Figures 2 to 5, the terminal can query the AS address corresponding to an unauthorized domain name in the serving network.
[0290] To implement the functions in the embodiments described above, the network elements and terminals may be understood to include corresponding hardware structures and / or software modules for performing those functions. Those skilled in the art will readily notice that the units and method steps in the examples described in relation to the embodiments disclosed herein can be implemented in hardware or in combination with hardware and computer software. Whether the functions are performed using hardware or using hardware driven by computer software depends on the specific application scenario and the design constraints of the technical solution.
[0291] Figures 6 and 7 show the structures of possible communication devices according to embodiments of this application, respectively. These communication devices may be configured to implement the functions of the network elements (e.g., the first network element, the second network element, the third network element, and the fourth network element) in the method embodiment described above. Therefore, these communication devices can also implement the advantageous effects of the method embodiment described above. In this embodiment of this application, the communication device may be the EASDF network element, SMF network element, or UPF network element shown in Figure 1, or it may be a communication device module (e.g., a chip or chip system) that implements the functions of the above network elements.
[0292] The communication device 600 includes a transceiver unit 620, which may be configured to receive or transmit information. The communication device 600 may further include a processing unit 610, which may be configured to process commands or data to perform corresponding operations.
[0293] When the communication device 600 is a chip configured within (or used within) a communication device, the transceiver unit 620 within the communication device 600 may be an input / output interface or a chip circuit, and the processing unit 610 within the communication device 600 may be a processor within the chip.
[0294] Optionally, the communication device 600 may further include a storage unit 630. The storage unit 630 may be configured to store instructions or data. The processing unit 610 may execute the instructions or data stored in the storage unit, enabling the communication device to perform the corresponding operation.
[0295] For a more detailed description of the processing unit 610 and the transceiver unit 620, please refer to the relevant descriptions in the method embodiments shown in Figures 3 to 5.
[0296] The transceiver unit 620 within the communication device 600 may be implemented through a communication interface (e.g., a transceiver, a transceiver circuit, an input / output interface, or pins), and when the communication interface is a transceiver, the transceiver should be understood to include a receiver and / or transmitter. The processing unit 610 within the communication device 600 may be implemented using at least one processor, or the processing unit 610 within the communication device 600 may be implemented using at least one logic circuit. Optionally, the communication device 600 further includes a storage unit, which may be implemented using memory.
[0297] When the above communication device is a module used in a network device, the network device module implements the functions of the network element in the above embodiment of the method. The network device module receives information from other modules in the network device, where the information is received by the network device from other devices (e.g., other network devices or terminals), or the network device module transmits information to other modules in the network device, where the information is transmitted by the network device to other devices (e.g., other network devices or terminals). The network device module may, in this case, be a chip in a network device.
[0298] As shown in Figure 7, the communication device 700 includes a processor 710 and an interface circuit 720. The processor 710 and the interface circuit 720 are coupled to each other. The interface circuit 720 may be understood to be a transceiver or an input / output interface. Optionally, the communication device 700 may further include a memory 730 configured to store instructions executed by the processor 710, input data required by the processor 710 to execute the instructions, or data generated after the processor 710 has executed the instructions.
[0299] The processor in this embodiment of this application may be understood to be a Central Processing Unit (CPU), or another general-purpose processor, a Digital Signal Processor (DSP), an Application-Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or another programmable logic device, a transistor logic device, a hardware component, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0300] The method steps in this embodiment of this application may be implemented in hardware or in software instructions that can be executed by a processor. The software instructions may include corresponding software modules. The software modules may be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, removable hard disks, CD-ROMs, or any other form of storage medium well known in the art. For example, the storage medium may be coupled to a processor so that the processor can read information from and write information to the storage medium. Alternatively, the storage medium may be a component of the processor. The processor and storage medium may be located within an ASIC. In addition, the ASIC may be located within an access network device or a terminal device. Alternatively, the processor and storage medium may exist as separate components within a communication device.
[0301] According to the method provided in the embodiments of this application, the embodiments of this application further provide a computer program product. The computer program product includes computer program code. When the computer program code is executed by one or more processors, the device including the processors can execute the methods shown in FIGS. 3 to 5.
[0302] All or part of the above embodiments can be implemented using software, hardware, firmware, or any combination thereof. When the above embodiments are implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the procedures or functions in the embodiments of this application are executed in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, a network device, a user device, or other programmable devices.
[0303] According to the method provided in the embodiments of this application, the embodiments of this application further provide a computer-readable storage medium. The computer-readable storage medium stores the above computer program or instructions. When the computer program or instructions are executed by one or more processors, the device including the processors can execute the methods shown in FIGS. 2 to 5.
[0304] Computer programs or instructions may be stored in computer-readable storage media, or transmitted from one computer-readable storage medium to another. For example, computer programs or instructions may be transmitted by wire or wireless means from one website, computer, server, or data center to another. Computer-readable storage media may be any available medium accessible by a computer, or a data storage device such as a server or data center that integrates one or more available media. Available media may be magnetic media, such as floppy disks, hard disks, or magnetic tapes; optical media, such as digital video discs; or semiconductor media, such as solid-state drives. Computer-readable storage media may be volatile or non-volatile storage media, or may include two types of storage media: volatile storage media and non-volatile storage media.
[0305] According to the method provided in the embodiments of this application, embodiments of this application further provide a communication system comprising one or more first communication devices as described above. The system may further include one or more second communication devices as described above.
[0306] In some embodiments provided in this application, the disclosed systems, apparatus, and methods should be understood to be implementable in other ways. For example, the described apparatus is merely an example. For example, the division into units is merely a logical functional division, and actual implementations may involve other divisions. For example, multiple units or components may be combined or integrated into other systems, and some functions may be omitted or not performed. In addition, the mutual coupling, direct coupling, or communication connection shown or discussed may be implemented through some interfaces. Indirect coupling or communication connection between apparatus or units may be implemented electrically, mechanically, or in other forms.
[0307] Units described as separate parts may or may not be physically separate, and parts shown as units may or may not be physical units, and may be located in one place or distributed across multiple network units. Some or all units may be selected based on actual requirements to achieve the objectives of the solution of the embodiment.
[0308] In the various embodiments of this application, unless otherwise noted or unless there is a logical inconsistency, the terminology and / or descriptions in different embodiments are consistent and may be referenced to one another, and the technical features in different embodiments may be combined based on their internal logical relationships to form new embodiments.
[0309] The above description is merely a specific implementation of this application and is not intended to limit the scope of protection of this application. Any modifications or substitutions that are readily understood by those skilled in the art within the scope of the technical knowledge disclosed in this application should fall within the scope of protection of this application. Accordingly, the scope of protection of this application should cover the scope of protection of the claims.
Claims
1. A step of receiving a first query message from a terminal by a first network element, wherein the first network element is located within the terminal's visited network, the first query message includes information about a first domain name, and the first domain name is not authorized in the terminal's visited network. The first network element sends a second query message to a Domain Name System (DNS) server, wherein the second query message includes the information about the first domain name and the information about the terminal's home network, and the information about the home network is used to determine the address of the application server. The first network element receives the address of the application server from the DNS server. A communication method that includes this.
2. The aforementioned method, A step of receiving information from a second network element by the first network element, wherein the information is from the terminal and indicates a rule used in a query message used to query the address of the application server, the rule includes providing the first network element with the DNS server the information about the home network when the query message used to query the address of the application server includes a domain name that is not authorized in the terminal's visited network. Further including, The method according to claim 1.
3. The aforementioned method, A step of receiving information from a second network element by the first network element, wherein the information indicates a rule to be used in the first query message, and the rule includes the first network element providing the information about the home network to the DNS server. Further including, The method according to claim 1.
4. The aforementioned rule is, When the query message used to query the address of the application server includes the domain name which is not authorized on the terminal's visited network, the first network element includes the information about the home network and the unauthorized domain name in a single message and provides the message to the DNS server. This includes in particular The method according to claim 2 or 3.
5. The first network element is a functional network element located within the terminal's visited network and configured to discover application servers, and the second network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session. The method according to any one of claims 2 to 4.
6. The second query message includes an ECS option information element, the ECS option information element indicating the information about the home network. The method according to any one of claims 1 to 5.
7. The information regarding the aforementioned home network is as follows: The Internet Protocol IP address of the terminal, the IP address of the user plane function network element within the home network, or the dedicated address of the home network. Including one or more of the following: The method according to any one of claims 1 to 6.
8. The step of receiving the address of the application server from the DNS server using the first network element is: The first network element receives a second response message from the DNS server for the second query message, the second response message includes the address of the application server, The aforementioned method, A step of sending a first response message to the terminal for the first query message via the first network element, the first response message including the address of the application server, further comprising: The method according to any one of claims 1 to 7.
9. The aforementioned method, The first network element obtains information about domain names that are authorized in the destination network of the terminal, and / or information about domain names that are not authorized in the destination network of the terminal. The first network element determines, based on the information regarding the domain name, that the first domain name is not authorized in the destination network of the terminal. Further including, The method according to any one of claims 1 to 8.
10. The information relating to the domain name includes a first set of domain names, the first set of domain names includes one or more domain names approved in the visited network of the terminal, the first domain name does not belong to the first set of domain names, and / or The information relating to the domain name includes a second set of domain names, the second set of domain names includes one or more domain names that are not authorized in the destination network of the terminal, and the first domain name belongs to the second set of domain names. The method according to claim 9.
11. The fact that the first domain name is not authorized in the destination network of the terminal includes the fact that the home network does not authorize the offloading of the service corresponding to the first domain name to the local data network. The method according to any one of claims 1 to 10.
12. The application server is configured to provide the service corresponding to the first domain name to the terminal. The method according to any one of claims 1 to 11.
13. A step of transmitting first information to a terminal via a second network element, wherein the first information indicates that the first network element is configured to discover an application server that provides services to the terminal, and the first and second network elements are located within the terminal's destination network. A step of transmitting second information to the first network element by the second network element, wherein the second information is from the terminal and indicates a rule used in a query message used to query the address of the application server, the rule includes providing the first network element with information about the terminal's home network to the DNS server when the query message used to query the address of the application server includes a domain name that is not authorized in the terminal's visited network. A communication method that includes this.
14. The aforementioned rule is, When the query message used to query the address of the application server includes the domain name which is not authorized on the terminal's visited network, the first network element includes the information about the home network and the unauthorized domain name in a single message and provides the message to the DNS server. This includes in particular The method according to claim 13.
15. The aforementioned method, The step of receiving third information from the second network element, wherein the third network element is located within the terminal's home network, the third information includes information about the terminal's home network, and the information about the home network is used to query an application server corresponding to an unauthorized domain name in the terminal's visited network. Further including, The method according to claim 13 or 14.
16. The information regarding the aforementioned home network is as follows: The Internet Protocol IP address of the terminal, the IP address of the user plane function network element within the home network, or the dedicated address of the home network. Including one or more of the following: The method according to any one of claims 13 to 15.
17. The first network element is a functional network element located within the terminal's visited network and configured to discover application servers, and the second network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session. The method according to any one of claims 13 to 16.
18. The domain name that is not authorized in the visited network of the terminal includes the fact that the service corresponding to the domain name is not authorized by the home network to be offloaded to the local data network. The method according to any one of claims 13 to 17.
19. A first network element receives a first query message from a terminal, wherein the first query message includes information about a first domain name, and the first domain name is not authorized in the terminal's visited network. The steps include: sending a second query message from the first network element to the second network element, wherein the second query message includes the information about the first domain name, the destination address of the second query message is the address of a Domain Name System DNS server, the DNS server is configured to query for the terminal the address of an application server corresponding to an unauthorized domain name in the terminal's visited network, and the application server is configured to provide the terminal with a service corresponding to the first domain name; The first network element receives the address of the application server from the second network element. A communication method that includes this.
20. The DNS server is either a DNS server corresponding to the terminal's home network, or a central DNS server within a central data network. The method according to claim 19.
21. The aforementioned method, A step of receiving information from a second network element by the first network element, wherein the information is from the terminal and indicates a rule used in a query message used to query the address of an application server, the rule includes the first network element sending the query message to the second network element, which includes the unauthorized domain name and whose destination address is the address of the DNS server, when the query message used to query the address of the application server includes an unauthorized domain name in the destination network of the terminal. Further including, The method according to claim 19 or 20.
22. The aforementioned method, A step of receiving information from a second network element by the first network element, wherein the information indicates a rule to be used in the first query message, and the rule includes the first network element providing the second network element with the second query message which includes the first domain name and whose destination address is the address of the DNS server. Further including, The method according to claim 19 or 20.
23. The first network element is a functional network element located within the terminal's visited network and configured to discover application servers, and the second network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session. The method according to any one of claims 19 to 22.
24. The step of receiving the address of the application server from the second network element by the first network element is: The first network element receives a second response message from the second network element for the second query message, the second response message includes the address of the application server, the step of The aforementioned method, A step of sending a first response message to the terminal for the first query message via the first network element, the first response message including the address of the application server, further comprising: The method according to any one of claims 19 to 23.
25. The aforementioned method, The first network element obtains information about domain names that are authorized in the destination network of the terminal, and / or information about domain names that are not authorized in the destination network of the terminal. The first network element determines, based on the information regarding the domain name, that the first domain name is not authorized in the destination network of the terminal. Further including, The method according to any one of claims 19 to 24.
26. The information relating to the domain name includes a first set of domain names, the first set of domain names includes one or more domain names approved in the visited network of the terminal, the first domain name does not belong to the first set of domain names, and / or The information relating to the domain name includes a second set of domain names, the second set of domain names includes one or more domain names that are not authorized in the destination network of the terminal, and the first domain name belongs to the second set of domain names. The method according to claim 25.
27. The fact that the first domain name is not authorized on the terminal's visited network includes the fact that the service corresponding to the first domain name is not authorized by the terminal's home network to be offloaded to the local data network. The method according to any one of claims 19 to 26.
28. A step of receiving a second query message from a first network element via a second network element, wherein the second query message includes information about a first domain name originating from a terminal, the destination address of the second query message is the address of a Domain Name System DNS server, the first domain name is not authorized in the terminal's visited network, the DNS server is configured to query for the terminal the address of an application server corresponding to the unauthorized domain name in the terminal's visited network, the application server is configured to provide the terminal with a service corresponding to the first domain name, the second query message is used to query the DNS server for the terminal the address of the application server corresponding to the first domain name, the first network element is a functional network element located within the terminal's visited network and configured to manage the terminal's session, and the second network element is a functional network element located within the terminal's visited network and configured to discover application servers. The second network element queries the DNS server for the address of the application server corresponding to the first domain name, via a network element within the terminal's home network, for the terminal. A communication method that includes this.
29. The DNS server is either a DNS server corresponding to the terminal's home network, or a DNS server within a central data network. The method according to claim 28.
30. The aforementioned method, A step of transmitting information to the first network element by the second network element, wherein the information is from the terminal and indicates a rule used in a query message used to query the address of the application server, and the rule includes, when the query message used to query the address of the application server includes an unauthorized domain name in the terminal's visited network, the first network element transmits the query message to the second network element, which includes the unauthorized domain name and whose destination address is the address of the DNS server. Further including, The method according to claim 28 or 29.
31. The aforementioned method, The step of receiving a third response message from the third network element by the second network element, wherein the third response message includes the address of the application server corresponding to the first domain name, and the third network element is a functional network element located in the home network and configured to manage the session of the terminal, further comprising the step of receiving a third response message from the third network element by the second network element, the second network element including the address of the application server corresponding to the first domain name, and the third network element being a functional network element located in the home network and configured to manage the session of the terminal, The aforementioned method, The second network element transmits a second response message to the first network element for the second query message, the second response message includes the address of the application server corresponding to the first domain name, further comprising the steps of: The method according to any one of claims 28 to 30.
32. The step of querying the DNS server for the address of the application server corresponding to the first domain name via a network element in the terminal's home network using the second network element is: The step of sending a third query message to the third network element via the second network element, wherein the third query message is used for the terminal to query the DNS server for the address of the application server corresponding to the first domain name, the third query message includes the information about the first domain name, and the third network element is a functional network element located in the home network and configured to manage the session of the terminal. The method according to any one of claims 28 to 31.
33. The fact that the first domain name is not authorized on the terminal's visited network includes the fact that the service corresponding to the first domain name is not authorized by the terminal's home network to be offloaded to the local data network. The method according to any one of claims 28 to 32.
34. A step of transmitting first information to a terminal via a second network element, wherein the first information indicates that the first network element is configured to discover an application server that provides services to the terminal, and the first and second network elements are located within the terminal's destination network, and the first and second network elements are located within the terminal's destination network, A step of transmitting second information to the first network element by the second network element, wherein the second information is from the terminal and indicates a rule used in a query message used to query the address of the application server, the rule includes providing the first network element with information about the terminal's home network to the DNS server when the query message used to query the address of the application server includes a domain name that is not authorized in the terminal's visited network. The first network element receives a first query message from the terminal, wherein the first query message includes information about a first domain name, and the first domain name is not authorized in the terminal's visited network. The first network element sends a second query message to the domain name system DNS server, wherein the second query message includes the information about the first domain name and the information about the terminal's home network, the information about the home network being used to determine the address of the application server, and the application server being configured to provide the terminal with a service corresponding to the first domain name. The first network element receives the address of the application server from the DNS server, The first network element transmits the address of the application server to the terminal. A communication method that includes this.
35. A first network element receives a first query message from a terminal, wherein the first query message includes information about a first domain name, and the first domain name is not authorized in the terminal's visited network. The steps include: sending a second query message from the first network element to the second network element, wherein the second query message includes the information about the first domain name, the destination address of the second query message is the address of a Domain Name System DNS server, the DNS server is configured to query for the terminal the address of an application server corresponding to an unauthorized domain name in the terminal's visited network, and the application server is configured to provide the terminal with a service corresponding to the first domain name; The second network element queries the DNS server for the address of the application server corresponding to the first domain name via the network element in the terminal's home network. The first network element receives the address of the application server from the second network element, The first network element transmits the address of the application server to the terminal. A communication method that includes this.
36. A communication device including a processor, wherein the processor is coupled to a memory, the memory is configured to store a computer program, and the processor is configured to execute the computer program stored in the memory so that the communication device can perform the method according to any one of claims 1 to 33.
37. A communication device comprising a module configured to perform the method described in any one of claims 1 to 33.
38. A communication device configured to perform the method described in any one of claims 1 to 12, and a communication device configured to perform the method described in any one of claims 13 to 18, and / or A communication device configured to perform the method described in any one of claims 19 to 27 and a communication device configured to perform the method described in any one of claims 28 to 33 A communication system, including
39. A computer-readable storage medium containing a computer program, wherein when the computer program is executed on a computer, the computer is able to perform the method described in any one of claims 1 to 33.
40. A computer program product, wherein the computer program product includes a computer program, and when the computer program is executed, the computer becomes capable of performing the method described in any one of claims 1 to 33.
41. A step of receiving a first query message from a terminal by a first network element, wherein the first network element is located within the terminal's visited network, the first query message includes information about a first domain name, and the first domain name is not authorized in the terminal's visited network. The first network element sends a second query message to a Domain Name System (DNS) server, wherein the second query message includes the information about the first domain name and the information about the terminal's home network, and the information about the home network is used to determine the address of the application server. The first network element receives the address of the application server from the DNS server. A communication method including, The method further includes the steps of receiving the second query message by the DNS server and transmitting the address of the application server.