SECURE COMMUNICATION METHOD AND APPARATUS - Patent application
The method of obtaining an access token for the second session management function using the NF instance ID provided by the AMF addresses the challenge of accessing services in 5G networks, enabling secure and efficient communication by allowing the first session management function to perform authorized operations.
Patent Information
- Application Number
- JP2023508547
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-08-10
- Filing Date
- 2021-08-10
- Publication Date
- 2025-05-14
- Estimated Expiration
- 2041-08-10
AI Technical Summary
In 5G communication networks, there is a lack of mechanism for the Access and Mobility Management Function (AMF) to provide the Network Function Instance ID (NF instance ID) of the Session Management Function (SMF) to the new Interim or Visiting SMF during session context creation, leading to challenges in obtaining access tokens and performing SM context retrieval or PDU session operations.
A method is introduced where the first session management function sends a request to the network repository function to obtain an access token for the second session management function, using the NF instance ID provided by the AMF. This allows the first session management function to authorize and perform various operations such as SM context retrieval or PDU session creation.
This solution enables the first session management function to obtain the necessary access tokens and perform authorized operations with the second session management function, thereby overcoming the limitations of the current system and ensuring secure and efficient communication in 5G networks.
Smart Images

Figure 0007676534000020 
Figure 0007676534000021 
Figure 0007676534000022
Abstract
Description
[Technical field]
[0001] TECHNICAL FIELD Non-limiting and exemplary embodiments of the present disclosure relate generally to the field of communications, and specifically to secure communication methods and apparatus. [Background technology]
[0002] This section introduces aspects that may facilitate a better understanding of the present disclosure. As such, statements in this section are to be read in this light and are not to be understood as admissions about what is or is not in the prior art.
[0003] Deployment topology according to specific SMF service area In communication networks such as Third Generation Partnership Project (3GPP) networks, a new feature called "Deployment Topology with SMF Serving Area (DTSSA)" is introduced in 5GC, which enables an Access and Mobility Management Function (AMF) to insert / change an Intermediate Session Management Function (I-SMF) when a User Equipment (UE) moves out of the serving area of a current Serving Session Management Function (SMF) in order to continue a session of a Protocol Data Unit (PDU) served by an old SMF.
[0004] Clause 4.23 of 3GPP TS 23.502 V16.4.0, the entire disclosure of which is incorporated herein by reference, describes support for deployment topologies by specific SMF service areas.
[0005] Figure 1 shows the UE Triggered Service Request with I-SMF Insertion / Modification / Deletion procedure. Figure 1 is a copy of Figure 4.23.4.3-1 of 3GPP TS 23.502 V16.4.0. The steps shown in Figure 1 are described in clause 4.23.4.3 of 3GPP TS 23.502 V16.4.0. If an I-SMF is inserted or modified, during the UE Triggered Service Request with I-SMF / V-SMF Change procedure, the new I-SMF fetches the SM context of the PDU session from the A-SMF (Anchor SMF) or the old I-SMF.
[0006] In step 4a, the new I-SMF derives the SM (Session Management) context from the old I-SMF (in case of I-SMF change) or SMF (in case of I-SMF insertion) by invoking the Nsmf_PDUSession_Context request (SM context type, SM context ID (identifier)). The new I-SMF uses the SM context ID received from the AMF for this service operation. The SM context ID is used by the recipient of the Nsmf_PDUSession_Context request to determine the target PDU session. The SM context type indicates that all the requested information is SM context, i.e. PDN (Packet Data Network) connection context and 5G (5th Generation) SM context.
[0007] In step 4b, the old I-SMF in case of an I-SMF change or the SMF in case of an I-SMF insertion responds with the SM context of the indicated PDU session. If extended buffering is applied and the extended buffering timer is still running in the old SMF or old I-UPF (Intermediate User Plane Function (UPF)) or the service request is triggered by downlink data, the old I-SMF or SMF includes in the response a forwarding indication indicating that a forwarding tunnel is required for sending out the buffered downlink packets. For an I-SMF insertion, if an I-UPF controlled by the SMF was available for the PDU session, the SMF includes a forwarding indication.
[0008] Similar mechanisms are implemented during all UE mobility procedures as described in 3GPP TS 23.502 V16.4.0, including mobility registration, N2 / Xn based handover, etc.
[0009] Section 4.23.5.1 of 3GPP TS 23.502 V16.4.0 describes the PDU session establishment procedure. In the DTSSA, when a PDU session is established, the following cases are included for non-roaming or LBO (local breakout) roaming: -If the service area of the selected SMF includes the location where the UE is camped, the UE request PDU session establishment procedure is the same as described in clause 4.3.2.2.1 of 3GPP TS 23.502 V16.4.0. -If the service area of the selected SMF does not include the location where the UE is camped, the AMF selects an I-SMF serving the area where the UE is camped. The UE Request PDU Session Establishment procedure for home routed roaming specified in clause 4.3.2.2.2 of 3GPP TS 23.502 V16.4.0 is used to establish the PDU session. Compared with the procedure specified in clause 4.3.2.2.2 of 3GPP TS 23.502 V16.4.0, the V-SMF and V-UPF (Visited User Plane Function (UPF)) are replaced by the I-SMF and I-UPF (Intermediate UPF), and the H-SMF (Home SMF) and H-UPF (Home UPF) are replaced by the SMF and UPF (PSA (PDU Session Anchor)), respectively. Also, only the S-NSSAI (Single Network Slice Selection Assistance Information) with a value specified by the serving PLMN (Public Land Mobile Network) is sent to the SMF. The I-SMF provides the SMF with a list of supported DNAIs (Data Network Access Identifiers), and the SMF provides the I-SMF with the DNAIs of interest for this PDU session based on the DNAI list information received from the I-SMF as specified in 3GPP TS 23.502 V16.4.0 Figure 4.23.9.1-1 step 1. When delegated discovery is used, the SCP (Service Communication Proxy) selects the SMF described in Annex E of 3GPP TS 23.502 V16.4.0.
[0010] Figure 2 shows the establishment of a UE request PDU session for a home routed roaming scenario. Figure 2 is a copy of Figure 4.3.2.2.2-1 of 3GPP TS 23.502 V16.4.0. The steps in Figure 2 are described in section 4.3.2.2.2 of 3GPP TS 23.502 V16.4.0.
[0011] In step 3a as in step 3 of clause 4.3.2.2.1 of 3GPP TS 23.502 V16.4.0, the following is added: The AMF also provides the identity of the H-SMF selected in step 2 of Figure 4.3.2.2.2-1 of 3GPP TS 23.502 V16.4.0, as well as both the VPLMN S-NSSAI from the allowed NSSAI and the corresponding S-NSSAI of the HPLMN (Home PLMN) that is the VPLMN (Visited PLMN) S-NSSAI from the allowed NSSAI in the mapping. The H-SMF is provided when the PDU session is home routed. The AMF may also provide the identity of the alternative H-SMF if received in step 2 of Figure 4.3.2.2.2-1 of 3GPP TS 23.502 V16.4.0. -The V-SMF does not use the DNN selection mode received from the AMF, but relays this information to the H-SMF.
[0012] The AMF may include the H-PCF ID in this step, which the V-SMF will pass to the H-SMF in step 6. This allows the H-SMF to select the same H-PCF in step 9a.
[0013] If control plane CIoT 5GS optimization is used for the PDU session and the "Calling NEF indication" in the subscription data is set to the S-NSSAI / DNN combination, the AMF includes the "Calling NEF" flag in the Nsmf_PDUSession_CreateSMContext request.
[0014] In step 6, from the V-SMF to the H-SMF: Nsmf_PDUSession_Create request (Subscription Persistent Identifier (SUPI), Generic Public Subscription Identifier (GPSI) (if available), V-SMF SM Context ID, Data Network Name (DNN), S-NSSAI whose value is specified by the HPLMN, PDU Session ID, V-SMF ID, V-CN-Tunnel-Info, PDU Session Type, Protocol Configuration Option (PCO), Number of Packet Filters, User Location Information, Access Type, Radio Access Technology (RAT) Type, Policy Control Function (PCF) ID, [Low Data Rate Control State], SM PDU DN Request Container, DNN Selection Mode, Control Plane CIoT (Cellular Internet of Things) 5GS (Fifth Generation System) Optimization Indication, [Request for Always-On PDU Session], AMF ID, Serving Network). The protocol configuration options may include information that the H-SMF may need to correctly establish a PDU session (e.g., SSC (Session and Service Continuity) mode or SM PDU DN Request Container used to authenticate the UE by DN-AAA (Authentication, Authorization, and Accounting) as specified in section 4.3.2.3 of 3GPP TS 23.502 V16.4.0). The H-SMF may use the DNN selection mode when deciding whether to accept or reject the UE request. If the V-SMF does not receive any response from the H-SMF due to a communication failure on the N16 interface, depending on the operator policy, the V-SMF may create a PDU session to one of the alternative H-SMFs if additional H-SMF information is provided in step 3a, as detailed in 3GPP TS 29.502 V16.4.0, the entire disclosure of which is incorporated herein by reference. The low data rate control status is included if received from the AMF. If the PDU session is targeted for control plane CIoT 5GS optimization, the control plane CIoT 5GS optimization indication is set by the V-SMF.
[0015] The V-SMF SM Context ID contains the addressing information assigned to the service operation associated with this PDU session. The H-SMF stores the PDU session and the association of the V-SMF Context ID of this PDU session to this UE.
[0016] If the H-SMF needs to use V-SMF services for this PDU session before step 13 (invoking the Nsmf_PDUSession_Update request), in the first invocation of the Nsmf_PDUSession_Update request the H-SMF provides the V-SMF with the H-SMF SM context ID it has assigned for the service operation associated with this PDU session.
[0017] If a RAT type is included in the message, the H-SMF stores the RAT type in the SM context.
[0018] Nnrf Access Token Service In 3GPP 5GC (5G Core Network), OAuth is introduced to enforce access control for NF service consumers consuming services at NF (Network Function) service producers, i.e., the NF consumer needs to obtain an access token from an authorization server (i.e., NRF (Network Repository Function)) and attach the token in a service request towards the NF producer. To gain access to a particular NF producer, the NF consumer provides the NF instance ID of the NF producer to the authorization server, which then checks the NF profile of the producer and authorizes the access accordingly.
[0019] After authorization of "Client Credentials" as defined in 3GPP TS 33.501 V16.3.0, the entire disclosure of which is incorporated herein by reference, the NRF presents the Nnrf_AccessToken service (used for OAuth2 authorization, see IETF RFC 6749 (October 2012), the entire disclosure of which is incorporated herein by reference), which reveals a "Token Endpoint" where an Access Token Request Service can be requested by the NF Service Consumer.
[0020] Figure 3 shows the procedure by which an NF service consumer obtains an access token before NF service access. Figure 3 is a copy of Figure 13.4.1.1-1 of 3GPP TS 33.501 V16.3.0. The steps in Figure 3 are described in Section 13.4.1.1 of 3GPP TS 33.501 V16.3.0.
[0021] The NF service consumer may send an HTTP POST request to the "token endpoint" as described in IETF Request for Comments 6749 (October 2012), section 3.2. The URI of the "token endpoint" is: {nrfApiRoot} / oauth2 / token
[0022] In this case, {nrfApiRoot} represents the concatenation of the NRF's "scheme" and "authority" components, as defined in IETF RFC 3986 (January 2005), the entire disclosure of which is incorporated herein by reference.
[0023] The OAuth 2.0 access token request consists of a POST request in the body of an HTTP (HyperText Transfer Protocol), and the POST request contains the following: - Oauth2 grant type set in "client_credentials" - A "scope" parameter indicating the name of the NF service that the NF service consumer wishes to access (i.e., the expected NF service name) - The NF instance Id of the NF service consumer requesting an OAuth2.0 access token, if this is an access token request for a specific NF service producer - NF type of NF service consumer, if this is an access token request not for a specific NF service producer - The NF type of the expected NF service producer, if this is an access token request for a specific NF service producer - The NF instance Id of the expected NF service producer, if this is an access token request for a specific NF service producer - Home and Serving PLMN IDs, if this is an access token request for use in a roaming scenario (see 3GPP TS 33.501 V16.3.0, section 13.4.1.2) Summary of the Invention
[0024] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0025] There are some problems with security communication between some NFs such as SMFs. Usually, NF consumers explicitly discover and select NF producers via NRF discovery, and thus are aware of the NF instance ID from the search results. However, in some scenarios, the NF producer is not selected by the NF consumer itself, e.g., the AMF discovers and selects the H-SMF / SMF for the V-SMF / I-SMF during PDU session establishment, or the new I-SMF derives the SM context from the old I-SMF or SMF. In order to successfully serve home-routed PDU session establishment and UE mobility, the DTSSA feature supported by both V-SMF and I-SMF is required. In order to successfully access services in the H-SMF / SMF / old I-SMF, the new I-SMF / V-SMF needs the NF instance ID of the peer SMF (as a service producer) since it needs to obtain an access token. However, currently, the AMF has no means to provide the new V-SMF / I-SMF with the corresponding SMF ID during the SM context creation procedure.
[0026] When a V-SMF or I-SMF is inserted or changed during UE mobility, the AMF provides "smContextRef" that the V-SMF or I-SMF can use to retrieve the SM context from the H-AMF or A-SMF or old I-SMF, but it is necessary to perform the retrieval operation before the V-SMF or I-SMF to obtain an access token, otherwise the H-AMF or A-SMF or old I-SMF may reject the SM context retrieval request. The AMF does not provide the NF instance ID of the H-AMF or A-SMF or old I-SMF that provides the "smContextRef" operation.
[0027] When a V-SMF or I-SMF is removed during UE mobility, the AMF provides a "smContextRef" that the H-AMF or A-SMF can use to retrieve the SM context from the I-SMF, but it is necessary to obtain an access token before the H-SMF or A-SMF performs the retrieval operation, otherwise the I-SMF may reject the SM context retrieval request. The AMF does not provide the NF instance ID of the I-SMF that provides the "smContextRef" operation.
[0028] When a V-SMF or I-SMF is inserted during PDU session establishment, the AMF provides the H-SMF or A-SMF with a "hSmfUri" or "smfUri" that the V-SMF or I-SMF can use to create a PDU session, but the V-SMF or I-SMF must obtain an access token before performing the PDU session operation, otherwise the H-SMF or A-SMF may reject the SM context retrieval request. The AMF does not provide the NF instance ID of the H-AMF or A-SMF that provides the "hSmfUri" or "smfUri" operation.
[0029] To overcome or mitigate at least one of the above problems or other problems, an improved security communication solution is proposed in an embodiment of the present disclosure.
[0030] In a first aspect of the present disclosure, a method is provided that is performed by a first session management function, the method including sending a first request to a network repository function to obtain an access token for a second session management function, the method further including receiving a first response from the network repository function that contains the access token for the second session management function or error information.
[0031] In one embodiment, the method may further include sending a second request to the second session management function containing an access token for the second session management function.
[0032] In one embodiment, the second request may include at least one of a request to establish a forwarding tunnel between the first session management function and the second session management function, a request to retrieve a session management context from the second session management function, a request to create a new protocol data unit (PDU) session in the second session management function or create an association with an existing packet data network (PDN) connection in the second session management function, a request to update an established PDU session in the second session management function, a request to release resources associated with a PDU session in the second session management function, or a request to push a session management context to the second session management function.
[0033] In one embodiment, the second request may include at least one of a Nsmf_PDUSession_UpdateSMContext request, a Nsmf_PDUSession_Context request, a Nsmf_PDUSession_Create request, a Nsmf_PDUSession_Update, a Nsmf_PDUSession_Release request, or a Nsmf_PDUSession_ContextPush request.
[0034] In one embodiment, the first request may be a Nnrf_AccessToken_Get request.
[0035] In one embodiment, the first request may contain a network function instance identifier of the second session management function.
[0036] In one embodiment, the network function instance identifier of the second session management function may include one of a network function instance identifier of a session management function hosting the session management (SM) context, a network function instance identifier of a home session management function, a network function instance identifier of a session management function, at least one network function instance identifier of at least one additional home session management function, or at least one network function instance identifier of at least one additional session management function.
[0037] In one embodiment, the error information may indicate that the first session management function is not enabled to access the services provided by the next hop network function producer.
[0038] In one embodiment, the second session management function may be a home session management function or a session management function or an old intermediate session management function or an old visited session management function.
[0039] In one embodiment, the first session management function may be a new intermediate session management function or a visited session management function.
[0040] In one embodiment, the network repository function may be an OAuth 2.0 authorization server, the first session management function is an OAuth 2.0 client, and the second session management function is an OAuth 2.0 resource server.
[0041] In one embodiment, the method may further include receiving a third request from the network function service consumer containing the network function instance identifier of the second session management function.
[0042] In one embodiment, the method may further include the first session management function sending a third response to the network function service consumer including an application error indicating that the network function service consumer is not authorized to access the service provided by the second session management function.
[0043] In one embodiment, the network function service consumer is an access and mobility management function.
[0044] In one embodiment, the first request is sent to the network repository function when OAuth is enabled for the second session management function.
[0045] In a second aspect of the present disclosure, a method is provided that is performed by a network repository function, the method including receiving a first request to obtain an access token for a second session management function from a first session management function, the method further including sending a first response to the first session management function that contains the access token for the second session management function or error information.
[0046] In one embodiment, the access token is used by the first session management function to send the second request to the second session management function.
[0047] In one embodiment, the first request is received from a first session management function when OAuth is enabled for a second session management function.
[0048] In a third aspect of the present disclosure, a method is provided that is performed by a second session management function. The method includes receiving a second request from the first session management function, the second request including an access token for the second session management function. The method further includes processing the second request.
[0049] In one embodiment, the method further includes the first session management function receiving a third response from the first session management function including an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0050] In a fourth aspect of the present disclosure, a method is provided that is performed by a network function service consumer, the method including sending a third request to a first session management function that contains a network function instance identifier of the second session management function.
[0051] In one embodiment, the network function service consumer is an access and mobility management function.
[0052] In a fifth aspect of the present disclosure, a first session management function is provided. The first session management function includes a processor and a memory coupled to the processor. The memory contains instructions executable by the processor. The first session management function operates to send a first request to a network repository function to obtain an access token for a second session management function. The first session management function further operates to receive a first response from the network repository function containing the access token for the second session management function or error information.
[0053] In a sixth aspect of the present disclosure, a network repository function is provided. The network repository function includes a processor and a memory coupled to the processor. The memory contains instructions executable by the processor. The network repository function is operative to receive a first request from a first session management function to obtain an access token for a second session management function. The network repository function is further operative to send a first response to the first session management function containing the access token for the second session management function or error information.
[0054] In a seventh aspect of the present disclosure, a second session management function is provided. The second session management function includes a processor and a memory coupled to the processor. The memory contains instructions executable by the processor. The second session management function is operative to receive a second request from the first session management function, the second request containing an access token for the second session management function. The second session management function is further operative to process the second request.
[0055] In an eighth aspect of the present disclosure, a network function service consumer is provided, the network function service consumer including a processor and a memory coupled to the processor, the memory containing instructions executable by the processor, the network function service consumer operative to send a third request to a first session management function, the third request containing a network function instance identifier of a second session management function.
[0056] In another aspect of the present disclosure, a first session management function is provided. The first session management function includes a first sending module and a first receiving module. The first sending module may be configured to send a first request to obtain an access token for the second session management function to a network repository function. The first receiving module may be configured to receive a first response from the network repository function containing the access token for the second session management function or error information.
[0057] In one embodiment, the first session management function may further include a second sending module. The second sending module may be configured to send a second request to the second session management function containing the access token for the second session management function. In one embodiment, the first session management function may further include a second receiving module. The second receiving module may be configured to receive a third request from the network function service consumer containing a network function instance identifier of the second session management function.
[0058] In one embodiment, the first session management function may further include a third sending module that may be configured to send a third response to the network function service consumer including an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0059] In another aspect of the disclosure, a network repository function is provided. The network repository function includes a receiving module and a sending module. The receiving module may be configured to receive a first request to obtain an access token for a second session management function from a first session management function. The sending module may be configured to send a first response to the first session management function containing the access token for the second session management function or error information.
[0060] In another aspect of the present disclosure, a second session management function is provided. The second session management function includes a receiving module and a processing module. The receiving module may be configured to receive a second request containing an access token for the second session management function from the first session management function. The processing module may be configured to process the second request.
[0061] In another aspect of the present disclosure, a network function service consumer is provided, the network function service consumer including a sending module, the sending module may be configured to send a third request to the first session management function, the third request including a network function instance identifier of the second session management function.
[0062] In one embodiment, the network function service consumer may further include a receiving module that may be configured to receive a third response from the first session management function that includes an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0063] In another aspect of the present disclosure, there is provided a computer program product comprising instructions that, when executed on at least one processor, cause the at least one processor to perform any of the methods according to the first, second, third and fourth aspects of the present disclosure.
[0064] In another aspect of the present disclosure, a computer-readable storage medium is provided storing instructions that, when executed by at least one processor, cause the at least one processor to perform any of the methods according to the first, second, third, and fourth aspects of the present disclosure.
[0065] The embodiments herein, of which the following is a non-exhaustive list of examples, provide many advantages. Some embodiments herein may enable a first session management function to obtain an access token (such as an OAuth2 token) for a second session management function based on an access and mobility management function (such as an AMF) providing an NF instance ID, thereby allowing the first session management function to authorize the second session management function to perform various options (such as an SM context retrieval operation or a PDU session creation operation). The embodiments herein are not limited to the above features and advantages. Those skilled in the art will recognize additional features and advantages upon reading the following detailed description.
[0066] The above and other aspects, features, and advantages of various embodiments of the present disclosure will become more fully apparent from the following detailed description, taken in conjunction with the accompanying drawings, in which, by way of example, like reference numbers or letters are used to designate like or equivalent elements, and in which: The drawings are presented to facilitate a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale. [Brief description of the drawings]
[0067] [Figure 1] A diagram showing the UE trigger service request procedure due to I-SMF insertion / modification / deletion. [Diagram 2] A diagram showing UE request PDU session establishment for a home routed roaming scenario. [Diagram 3] A diagram showing the procedure by which an NF service consumer obtains an access token before accessing an NF service. [Figure 4] FIG. 1 illustrates a schematic diagram of a high-level architecture in a 5G network in which embodiments of the present disclosure can be implemented. [Diagram 5] 1 is a flowchart of a method according to one embodiment of the present disclosure. [Figure 6]4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 7] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 8] 4 is a flowchart of a method according to another embodiment of the present disclosure. [Figure 9] 13 is a flowchart of a UE triggered service request by I-SMF insertion / modification / deletion according to one embodiment of the present disclosure; [Figure 10] 1 is a flowchart of a UE request PDU session establishment for a home routed roaming scenario according to one embodiment of the present disclosure. [Figure 11] 1 is a flowchart of SM context creation according to one embodiment of the present disclosure. [Figure 12] 1 is a flowchart of a service request by I-SMF insertion / modification / deletion or V-SMF modification according to one embodiment of the present disclosure. [Figure 13] FIG. 1 is a block diagram illustrating an apparatus suitable for practicing some embodiments of the present disclosure. [Figure 14] FIG. 2 is a block diagram illustrating a first session management function according to an embodiment of the present disclosure. [Figure 15] FIG. 2 is a block diagram illustrating a network repository function according to one embodiment of the present disclosure. [Figure 16] FIG. 2 is a block diagram illustrating a second session management function according to an embodiment of the present disclosure. [Figure 17] FIG. 2 is a block diagram illustrating a network function service consumer according to one embodiment of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0068] The embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only to enable those skilled in the art to better understand and practice the present disclosure, rather than to suggest any limitations on the scope of the present disclosure. References to features, advantages, or similar words throughout this specification do not imply that all of the features and advantages that may be realized in the present disclosure are to be or are in any single embodiment of the present disclosure. Rather, words referring to features and advantages should be understood to mean that the specific features, advantages, or characteristics described in connection with an embodiment are included in at least one embodiment of the present disclosure. Furthermore, the described features, advantages, and characteristics of the present disclosure may be combined in any suitable manner in one or more embodiments. Those skilled in the art will recognize that the present disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other examples, additional features and advantages that may not be present in all embodiments of the present disclosure may be recognized in a particular embodiment.
[0069] As used herein, the term "network" refers to a network conforming to any suitable (wireless or wired) communication standard. For example, wireless communication standards may include New Radio (NR), long-term evolution (LTE), LTE-Advanced, wideband code division multiple access (WCDMA), high speed packet access (HSPA), code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal frequency division multiple access (OFDMA), single carrier frequency division multiple access (SC-FDMA), and other wireless networks. A CDMA network may implement a non-segregated technology such as Universal Terrestrial Radio Access (UTRA). UTRA includes WCDMA and other variants of CDMA. A TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network may implement wireless technologies such as Enhanced UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash OFDMA, ad-hoc networks, wireless sensor networks, etc. In the following description, the terms "network" and "system" may be used interchangeably. Furthermore, communication between two devices in a network may be performed according to any suitable communication protocol, including but not limited to wireless communication protocols defined by a standards body such as the 3rd Generation Partnership Project (3GPP), or wired communication protocols. For example, wireless communication protocols may include first generation (1G), 2G, 3G, 4G, 4.5G, 5G communication protocols, and / or any other protocols now known or developed in the future.
[0070] The term "entity" as used herein refers to a network device or a network node or a network function in a communication network. For example, in a wireless communication network, such as a 3GPP-type cellular network, a core network device may provide multiple services to customers interconnected by access network devices. Each access network device may be connected to the core network device by a wired or wireless connection.
[0071] The term "Network Function" refers to any suitable function that can be implemented in a network entity (physical or virtual) of a communication network. For example, a Network Function can be implemented as a network element on dedicated hardware, as a software instance running on dedicated hardware, or as a virtualized function instantiated on a suitable platform, e.g., a cloud infrastructure. For example, a 5G system (5GS) may include multiple NFs, such as AMF (Access and Mobility Function), SMF (Session Management Function), AUSF (Authentication Service Function), UDM (Unified Data Management), PCF (Policy Control Function), AF (Application Function), NEF (Network Publishing Function), UPF (User Plane Function), and NRF (Network Repository Function), RAN (Radio Access Network), SCP (Service Communication Proxy), NWDAF (Network Data Analysis Function).
[0072] The term "terminal device" refers to any terminal device capable of accessing and receiving services from a communications network. By way of example and not limitation, terminal device refers to a mobile terminal, user equipment (UE), or other suitable device. A UE may be, for example, a subscriber station (SS), a mobile subscriber station, a mobile station (MS), or an access terminal (AT). Terminal devices may include, but are not limited to, portable computers, image capture terminals such as digital cameras, gaming terminals, music storage and playback devices, mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable devices, personal digital assistants (PDAs), portable computers, desktop computers, wearable terminals, vehicle mounted wireless terminals, wireless endpoints, mobile stations, laptop embedded equipment (LEE), laptop mounted equipment (LME), USB dongles, smart devices, and wireless customer premises equipment (CPE). In the following description, the terms "terminal device", "terminal", "user equipment", and "UE" may be used interchangeably. As one example, a terminal device may represent a UE configured to communicate according to one or more communication standards promulgated by 3GPP, such as the 3GPP LTE or NR standards. As used herein, "user equipment" or "UE" may not necessarily have a "user" in the sense of a human user who owns and / or operates the associated equipment. In some embodiments, a terminal device may be configured to transmit and / or receive information without direct human interaction. For example, a terminal device may be designed to transmit information to a network on a predefined schedule, when triggered by an internal or external event, or in response to a request from the communication network. Instead, a UE may represent a device that is intended for sale to or operation by a human user, but may not initially be associated with a unique human user.
[0073] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements and transmits results of such monitoring and / or measurements to another terminal device and / or network equipment. In this case, the terminal device may be a machine-to-machine (M2M) device, which may be referred to as a machine-type communication (MTC) device in the 3GPP context. As one particular example, the terminal device may be a UE that implements the 3GPP Narrowband Internet of Things (NB-IoT) standard. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machines, or home or personal appliances, e.g., personal wearables such as refrigerators, televisions, clocks, etc. In other scenarios, the terminal device may represent a vehicle or other equipment that can monitor and / or report its operating state or other functions associated with its operation.
[0074] References herein to "one embodiment," "one embodiment," "exemplary embodiment," and the like indicate that the described embodiment may include a particular feature, structure, or characteristic, but not all embodiments need include the particular feature, structure, or characteristic. Also, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with one embodiment, it is submitted that it is within the knowledge of one of ordinary skill in the art to affect such feature, structure, or characteristic in connection with other embodiments, whether or not explicitly stated.
[0075] In this specification, terms such as "first" and "second" may be used to describe various elements, but it should be understood that these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, a first element can be referred to as a second element, and similarly, a second element can be referred to as a first element, without departing from the scope of the exemplary embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0076] As used herein, the phrase "at least one of A and B" should be understood to mean "A only, B only, or both A and B." The phrase "A and / or B" should be understood to mean "A only, B only, or both A and B."
[0077] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise. It will be further understood that the terms "comprise", "comprising", "has", "having", "includes", and / or "including" as used herein specify the presence of stated features, elements, and / or components, etc., but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0078] Please note that these terms used in this document are used only for ease of description or distinction between nodes, devices, or networks, etc. As technology develops, other terms with similar / same meanings may also be used.
[0079] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0080] It should be noted that some embodiments of the present disclosure are primarily described in relation to cellular networks defined by 3GPP, which are used as non-limiting examples of certain exemplary network configurations and system deployments. As such, the description of the exemplary embodiments given herein specifically refers to terminology directly related thereto. Such terminology is used only in the context of the presented non-limiting examples and embodiments, and is not intended to limit the present disclosure in any way. Rather, any other system configuration or wireless technology, such as wireless sensor networks, may be equally utilized as long as the exemplary embodiments described herein are applicable.
[0081] Figure 4 illustrates a schematic high-level architecture in a 5G network in which embodiments of the present disclosure can be implemented. The architecture is the same as Figure 4.2.3-1 in 3GPP TS 23.501 V16.4.0, the entire disclosure of which is incorporated herein by reference. The system architecture in Figure 4 includes AMF, SMF, AUSF, UDM, PCF, AF, NEF, UPF and NRF, (R)AN, SCP, 4 may include some example elements such as: The network elements, reference points, and interfaces as shown in FIG. 4 may be the same as the corresponding network elements, reference points, and interfaces described in 3GPP TS 23.501 V16.4.0.
[0082] For simplicity, the system architecture of Figure 4 illustrates only a few example elements. In practice, the communication system may further include any additional elements suitable for supporting communications between terminal devices or between a wireless device and another communication device, such as a landline telephone, a service provider, or any other network node or terminal device. The communication system may provide communications and various types of services to one or more terminal devices to facilitate the terminal device's access to and / or use of services provided by or through the communication system.
[0083] FIG. 5 shows a flowchart of a method 500 according to an embodiment of the present disclosure. The flowchart may be executed by an apparatus implemented in or as a first session management function (e.g., I-SMF, V-SMF, new SMF, etc.) or communicatively coupled to the first session management function. As such, the apparatus may provide means or modules for accomplishing various parts of the method 500, as well as means or modules for accomplishing other processes in conjunction with other components. The first session management function may provide the same or similar functions as those of the SMF described in section 6.2.2 of 3GPP TS 23.501 V16.4.0. In an embodiment, the first session management function may be a new intermediate session management function (e.g., I-SMF) or a visited session management function (e.g., V-SMF).
[0084] In block 502, optionally, the first session management function receives a third request containing a network function instance identifier of the second session management function from a network function service consumer. The network function service consumer may be, for example, any suitable NF in 5GS (such as an AMF). In one embodiment, the network function service consumer may be an access and mobility management function. The access and mobility management function may provide the same or similar functionality as that of the AMF described in section 6.2.1 of 3GPP TS 23.501 V16.4.0. The second session management function may provide the same or similar functionality as that of the SMF described in section 6.2.2 of 3GPP TS 23.501 V16.4.0. In one embodiment, the second session management function may be a home session management function (such as an H-SMF) or a session management function (such as an SMF) or an old intermediate session management function (such as an I-SMF) or an old visited session management function (such as a V-SMF). The third request may be any suitable request that can be sent from the network function service consumer to the first session management function, such as a modified existing request or a new message. In one embodiment, the third request may be any suitable message that can be sent from the AMF to the SMF as described in 3GPP TS 23.502 V16.4.0. In one embodiment, the third request may be a Nsmf_PDUSession_CreateSMContext request as described in 3GPP TS 23.502 V16.4.0. In one embodiment, the third request may contain at least one network function instance identifier of the at least one second session management function.
[0085] In one embodiment, the network function instance identifier of the second session management function includes at least one of a network function instance identifier of a session management function hosting the session management (SM) context, a network function instance identifier of a home session management function, a network function instance identifier of a session management function, at least one network function instance identifier of at least one additional home session management function, or at least one network function instance identifier of at least one additional session management function.
[0086] In block 504, the first session management function sends a first request to a network repository function to obtain an access token for the second session management function. The network repository function may provide the same or similar functionality as that of an NRF as described in section 6.2.2 of 3GPP TS 23.501 V16.4.0. In one embodiment, the network repository function may be an NRF. The first request may be any suitable message, such as an existing message or a new message. In one embodiment, the first request may be an Nnrf_AccessToken_Get request as described in section 13.4.1.1 of 3GPP TS 33.501 V16.3.0.
[0087] In one embodiment, the first request is sent to the network repository function when OAuth is valid for the second session management function.
[0088] In one embodiment, a first session management function may send a first request to a network repository function to obtain at least one access token for at least one second session management function.
[0089] In one embodiment, the first request contains at least one network function instance identifier of the at least one second session management function. The at least one network function instance identifier of the at least one second session management function may be obtained in various manners. For example, the first session management function may obtain the at least one network function instance identifier of the at least one second session management function when it receives a third request from the network function service consumer that contains the at least one network function instance identifier of the at least one second session management function.
[0090] In block 506, the first session management function receives a first response from the network repository function containing the access token or error information for the second session management function. The first response may be any suitable message, such as an existing message or a new message. In one embodiment, the first response may be an Nnrf_AccessToken_Get response as described in section 13.4.1.1 of 3GPP TS 33.501 V16.3.0.
[0091] In one embodiment, the first response may contain at least one access token for the at least one second session management function.
[0092] The error information may be any suitable error information. For example, the error information may be an OAuth 2.0 error response as defined in RFC 6749. In one embodiment, the error information indicates that the first session management function is not enabled to access a service provided by a next hop network function producer (e.g., a second session management function).
[0093] For example, an NF service consumer (e.g., a first session management function) shall request an access token from a network repository function (e.g., an NRF) in the same PLMN using the Nnrf_AccessToken_Get request operation. The message shall include the NF instance Id of the NF service consumer, the requested "scope" including the expected NF service name and optionally "additional scope" information (i.e., the requested resource and the requested action on that resource (service operation)), the NF type of the expected NF producer instance and the NF consumer. The service consumer may also include a list of NSSAIs or a list of NSI (Network Slice Instance) IDs for the expected NF producer instance (e.g., a second session management function). The message may include the NF set IDs of the expected NF service producer instance. The NRF may optionally authorize the NF service consumer. The NRF shall further generate an access token with the appropriate claims included. The NRF shall digitally sign the generated access token based on a shared secret or private key as described in RFC 7515. The claims in the token shall include the NF instance Id of the NRF (issuer), the NF instance Id of the NF service consumer (subject), the NF type of the NF service producer (intended user), the expected service name, scope, expiration time and optionally "additional scope" information (authorized resources and authorized actions (service operations) on those resources). The claims may include a list of NSSAI or NSI IDs for the expected NF producer instances. The claims may include the NF Set IDs of the expected NF service producer instances.If authorization is successful, the NRF shall send the access token to the NF service consumer in an Nnrf_AccessToken_Get response operation, otherwise it shall reply based on the OAuth 2.0 error response as specified in RFC 6749. Other parameters sent by the NRF in addition to the access token (e.g. expiry time, allowed scope) are described in 3GPP TS 29.510 V16.4.0. The NF service consumer may store the received token. The stored tokens may be reused during their validity period to access services from the NF types of producers listed in the claims (scope, target user).
[0094] In one embodiment, the network repository function is an OAuth 2.0 authorization server, the first session management function is an OAuth 2.0 client, and the second session management function is an OAuth 2.0 resource server.
[0095] In block 508, optionally, the first session management function sends a second request to the second session management function containing the access token for the second session management function. The second request may be any suitable request that can be sent from the first session management function to the second session management function, such as a modified existing request or a new message. In an embodiment, the second request may be any suitable message that can be sent from one SMF to another SMF as described in 3GPP TS 23.502 V16.4.0.
[0096] In one embodiment, the second request may include at least one of a request to establish a forwarding tunnel between the first session management function and the second session management function, a request to retrieve a session management context from the second session management function, a request to create a new protocol data unit (PDU) session in the second session management function or create an association with an existing packet data network (PDN) connection in the second session management function, a request to update an established PDU session in the second session management function, a request to release resources associated with a PDU session in the second session management function, or a request to push a session management context to the second session management function.
[0097] In one embodiment, the second request includes at least one of a Nsmf_PDUSession_UpdateSMContext request, a Nsmf_PDUSession_Context request, a Nsmf_PDUSession_Create request, a Nsmf_PDUSession_Update, a Nsmf_PDUSession_Release request, or a Nsmf_PDUSession_ContextPush request, as described in 3GPP TS 23.502 V16.4.0.
[0098] In block 510, optionally, the first session management function may send a third response to the network function service consumer including an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0099] 6 shows a flowchart of a method 600 according to another embodiment of the present disclosure. This flowchart may be executed by an apparatus implemented in or as a network repository function (such as an NRF) or communicatively coupled to a network repository function. As such, the apparatus may provide means or modules for achieving various parts of the method 600, and means or modules for achieving other processes in conjunction with other components. For some parts described in the above embodiments, the detailed description thereof is omitted here for brevity.
[0100] In block 602, the network repository function receives a first request from the first session management function to obtain an access token for the second session management function. For example, the first session management function may send the first request in block 502 of Figure 5, after which the network repository function may receive the first request. In one embodiment, the first request is received from the first session management function when OAuth is valid for the second session management function.
[0101] A network repository function such as the NRF may optionally authorize the NF service consumer (i.e., the first session management function). The network repository function shall also generate an access token in which the appropriate claims are included. The NRF shall digitally sign the generated access token based on a shared secret or private key as described in RFC 7515. The claims in the token shall include the NF instance Id of the NRF (issuer), the NF instance Id of the NF service consumer (subject), the NF type of the NF service producer (target user), the expected service name, scope, expiration time and optionally "additional scope" information (authorized resources and authorized actions on those resources (service operations)). The claims may include a list of NSSAI or NSI IDs for the expected NF producer instances. The claims may include the NF Set ID of the expected NF service producer instance.
[0102] In block 604, the network repository function sends a first response to the first session management function containing the access token or error information for the second session management function.
[0103] In one embodiment, the access token is used by the first session management function to send a second request to the second session management function, as described above.
[0104] 7 shows a flowchart of a method 700 according to another embodiment of the present disclosure. This flowchart may be executed by an apparatus implemented in or as a second session management function (such as an SMF) or communicatively coupled to a second session management function. As such, the apparatus may provide means or modules for achieving various parts of the method 700, and means or modules for achieving other processes in conjunction with other components. For some parts described in the above embodiments, the detailed description thereof is omitted here for brevity.
[0105] In block 702, the second session management function receives a second request from the first session management function containing an access token for the second session management function. For example, the first session management function may send the second request in block 508 of FIG. 5, after which the second session management function may receive the second request.
[0106] In block 704, the second session management function processes the second request. For example, depending on the particular type of the second request, the second session management function may process the second request differently. For example, when the second request includes at least one of an Nsmf_PDUSession_UpdateSMContext request, an Nsmf_PDUSession_Context request, an Nsmf_PDUSession_Create request, an Nsmf_PDUSession_Update, an Nsmf_PDUSession_Release request, or an Nsmf_PDUSession_ContextPush request, the second session management function may process the second request as described in 3GPP TS 23.502 V16.4.0.
[0107] 8 shows a flowchart of a method 800 according to another embodiment of the present disclosure. This flowchart may be executed by an apparatus implemented in or as a network function service consumer (such as an AMF) or communicatively coupled to the network function service consumer. As such, the apparatus may provide means or modules for achieving various parts of the method 800, and means or modules for achieving other processes in conjunction with other components. For some parts described in the above embodiments, the detailed description thereof is omitted here for brevity.
[0108] In block 802, the network function service consumer sends a third request to the first session management function containing the network function instance identifier of the second session management function. The third request may be any suitable message, such as a modified existing message or a new message. In one embodiment, the third message may be an Nsmf_PDUSession_CreateSMContext request, as described in 3GPP TS 23.502 V16.4.0.
[0109] In block 804, optionally, the network function service consumer receives a third response from the first session management function including an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0110] In one embodiment, the network function service consumer may be an access and mobility management function, such as an AMF.
[0111] FIG. 9 illustrates a flowchart of a UE triggered service request by I-SMF insertion / modification / deletion according to one embodiment of the present disclosure.
[0112] The procedures in this subclause are used when an I-SMF is to be inserted, modified or deleted as part of a UE triggered service request. These procedures include the following cases: - the UE moves from an SMF service area to a new I-SMF service area and a new I-SMF is inserted (i.e., I-SMF insertion), or - the UE moves from an old I-SMF service area to a new I-SMF service area and the I-SMF is changed (i.e., I-SMF change); or - The UE moves from the old I-SMF service area to the SMF service area, and the old I-SMF is deleted (i.e., I-SMF deleted).
[0113] When a service request is triggered by the network by downlink data and a new I-UPF is selected, a forwarding tunnel is established between the old I-UPF (if the old I-UPF is different from the PSA) and the new I-UPF to forward the buffered data.
[0114] In the home routed roaming case, the (old and new) I-SMF and (old and new) I-UPF are located in the visited PLMN, and the SMF and UPF (PSA) are located in the home PLMN. In this HR roaming case, only the I-SMF change case applies (there is always a V-SMF for the PDU session).
[0115] In step 3, if the AMF has selected a new I-SMF, the AMF sends a Nsmf_PDUSession_CreateSMContext request (PDU session ID, SM context ID, UE location information, access type, RAT type, operation type) to the new I-SMF. The SM context ID points to the old I-SMF in case of an I-SMF change or to the SMF in case of an I-SMF insertion.
[0116] The AMF sets the operation type to "UP Activated" to indicate the establishment of N3 tunnel user plane resources for the PDU session. The AMF determines the access type and RAT type based on the global RAN node ID associated with the N2 interface.
[0117] If the UE time zone has changed compared to the last reported UE time zone, the AMF shall include the UE time zone IE in this message.
[0118] In one embodiment, the AMF provides the NF instance ID of the SMF corresponding to "SmContextRef." For example, the Nsmf_PDUSession_CreateSMContext request may further include the NF instance ID of the SMF corresponding to "SmContextRef."
[0119] In one embodiment, the AMF provides an NF instance ID of the SMF corresponding to the “smfUri” or “hSmfUri.” For example, the Nsmf_PDUSession_CreateSMContext request may further include an NF instance ID of the SMF corresponding to the “smfUri” or “hSmfUri.”
[0120] In step 3a, the new I-SMF invokes a Nnrf_AccessToken_GetRequest(targetNfType, targetNfInstanceId) to the NRF to obtain an access token for the old I-SMF (in case of I-SMF change) or SMF (in case of I-SMF insertion).
[0121] In step 4a, the new I-SMF retrieves the SM context from the old I-SMF (in case of I-SMF change) or SMF (in case of I-SMF insertion) by invoking the Nsmf_PDUSession_Context request (SM context type, SM context ID). The new I-SMF uses the SM context ID received from the AMF for this service operation. The SM context ID is used by the recipient of the Nsmf_PDUSession_Context request to determine the target PDU session. The SM context type indicates that the requested information is all SM context, i.e., PDN connection context and 5G SM context.
[0122] In one embodiment, the Nsmf_PDUSession_Context request may further include an access token for the old I-SMF (in case of an I-SMF change) or SMF (in case of an I-SMF insertion).
[0123] In step 7a, if a tunnel endpoint for buffered DL data has been allocated, the new I-SMF invokes a Nsmf_PDUSession_UpdateSMContext request (tunnel endpoint for buffered DL data) to the old I-SMF in case of I-SMF change to establish a forwarding tunnel. The new I-SMF uses the SM context ID received from the AMF for this service operation.
[0124] In one embodiment, the Nsmf_PDUSession_UpdateSMContext request may further include an access token for the old I-SMF.
[0125] Other steps in Figure 9 are the same as the corresponding steps in Figure 4.23.4.3-1 of 3GPP TS 23.502 V16.4.0. Messages other than the Nnrf_AccessToken_Get request as shown in Figure 9 are the same as the corresponding messages in Figure 4.23.4.3-1 of 3GPP TS 23.502 V16.4.0.
[0126] In one embodiment, similar mechanisms of FIG. 9 may be performed during all UE mobility procedures as described in 3GPP TS 23.502 V16.4.0, including mobility registration, N2 / Xn based handover, etc.
[0127] FIG. 10 illustrates a flow chart of UE request PDU session establishment for a home routed roaming scenario according to one embodiment of the present disclosure.
[0128] In step 3a as in step 3 of clause 4.3.2.2.1 of 3GPP TS 23.502 V16.4.0, the following is added: - The AMF also provides the identity of the H-SMF selected in step 2 of Figure 10, as well as both the VPLMN S-NSSAI from the allowed NSSAI and the corresponding S-NSSAI of the HPLMN that is the VPLMN S-NSSAI from the allowed NSSAI in the mapping. The H-SMF is provided when the PDU session is home routed. The AMF may also provide the identity of the alternative H-SMF if received in step 2 of Figure 10. -The V-SMF does not use the DNN selection mode received from the AMF, but relays this information to the H-SMF.
[0129] The AMF may include the H-PCF ID in this step, which the V-SMF will pass to the H-SMF in step 6. This enables the H-SMF to select the same H-PCF in step 9a of Figure 10.
[0130] If control plane CIoT 5GS optimization is used for the PDU session and the "invoking NEF indication" in the subscription data is set for the S-NSSAI / DNN combination, the AMF includes the "invoking NEF" flag in the Nsmf_PDUSession_CreateSMContext request.
[0131] In one embodiment, the AMF provides the NF instance ID of the SMF corresponding to "SmContextRef." For example, the Nsmf_PDUSession_CreateSMContext request may further include the NF instance ID of the SMF corresponding to "SmContextRef."
[0132] In one embodiment, the AMF provides an NF instance ID of the SMF corresponding to the “smfUri” or “hSmfUri.” For example, the Nsmf_PDUSession_CreateSMContext request may further include an NF instance ID of the SMF corresponding to the “smfUri” or “hSmfUri.”
[0133] In step 5, the V-SMF initiates the N4 session establishment procedure with the selected V-UPF.
[0134] In step 5a, the V-SMF sends an N4 session establishment request to the V-UPF.
[0135] In step 5b, the V-UPF acknowledges by sending an N4 session establishment response. The CN tunnel information is provided to the V-SMF in this step.
[0136] In step 5c, the V-SMF invokes a Nnrf_AccessToken_GetRequest(targetNfType, targetNfInstanceId) to the NRF to obtain an access token for the H-SMF.
[0137] In step 6, V-SMF to H-SMF: Nsmf_PDUSession_Create Request (SUPI, GPSI (if available), V-SMF SM Context ID, DNN, S-NSSAI whose value is specified by HPLMN, PDU Session ID, V-SMF ID, V-CN-Tunnel-Info, PDU Session Type, PCO, Number of Packet Filters, User Location Information, Access Type, RAT Type, PCF ID, [Low Data Rate Control State], SM PDU DN Request Container, DNN Selection Mode, Control Plane CIoT 5GS Optimization Indication, [Request Always-On PDU Session], AMF ID, Serving Network). The protocol configuration options may include information that the H-SMF may need to correctly establish the PDU session (e.g. SSC Mode or SM PDU DN Request Container used to authenticate the UE by DN-AAA as specified in subclause 4.3.2.3). The H-SMF may use the DNN selection mode when deciding whether to accept or reject the UE request. If the V-SMF does not receive any response from the H-SMF due to a communication failure on the N16 interface, depending on the operator policy, as detailed in 3GPP TS 29.502 V16.4.0, the V-SMF may create a PDU session to one of the alternative H-SMFs if additional H-SMF information is provided in step 3a. The low data rate control status is included if received from the AMF. If the PDU session is targeted for control plane CIoT 5GS optimization, the control plane CIoT 5GS optimization indication is set by the V-SMF.
[0138] The V-SMF SM Context ID contains the addressing information assigned to the service operation associated with this PDU session. The H-SMF stores the PDU session and the association of the V-SMF Context ID of this PDU session to this UE.
[0139] If the H-SMF needs to use V-SMF services for this PDU session before step 13 (invoking the Nsmf_PDUSession_Update request), in the first invocation of the Nsmf_PDUSession_Update request the H-SMF provides the V-SMF with the H-SMF SM context ID it has assigned for the service operation associated with this PDU session.
[0140] If a RAT type is included in the message, the H-SMF stores the RAT type in the SM context.
[0141] In one embodiment, the Nsmf_PDUSession_Create request may further include an access token for the H-SMF.
[0142] Other steps in Fig. 10 are the same as the corresponding steps in Fig. 4.3.2.2.2-1 of 3GPP TS 23.502 V16.4.0. Messages other than the Nnrf_AccessToken_Get request shown in Fig. 10 are the same as the corresponding messages in Fig. 4.3.2.2.2-1 of 3GPP TS 23.502 V16.4.0.
[0143] In one embodiment, 3GPP TS 29.502 V16.4.0 may be modified as follows: First change 5.2.2.2.1 Overview The Create SM Context service operation shall be used to create an individual SM context for a given PDU session in the SMF, in the V-SMF for HR roaming scenarios or in the I-SMF for a PDU session by an I-SMF. It is used in the following steps: -UE Request PDU Session Establishment (see clauses 4.3.2 and 4.23.5.1 of 3GPP TS 23.502 [3]) -EPS to 5GS idle mode mobility, EPS to 5GS idle mode mobility with data forwarding or handover using the N26 interface (see clauses 4.11.1, 4.23.12.3, 4.23.12.5, and 4.23.12.7 of 3GPP TS 23.502 [3]) - EPS to 5GS mobility without N26 interface (see clause 4.11.2.3 of 3GPP TS 23.502[3]) - handover of PDU sessions between 3GPP and non-3GPP accesses when the target AMF does not know the SMF resource identifier of the SM context used by the source AMF, e.g. when the target AMF is not in the PLMN of the N3IWF (see clause 4.9.2.3.2 of 3GPP TS 23.502 [3]) or when the UE is roaming and the selected N3IWF is in the HPLMN (see clause 4.9.2.4.2 of 3GPP TS 23.502 [3]) - Handover from EPS to 5GC-N3IWF (see clause 4.11.3.1 of 3GPP TS 23.502 [3]) -EPC / ePDG to 5GS handover (see clause 4.11.4.1 of 3GPP TS 23.502[3]) - Xn-based or N2-based handover with I-SMF or V-SMF insertion and modification (see clauses 4.23.7.3, 4.23.11, and 4.23.12 of 3GPP TS 23.502 [3]) - UE triggered service requests due to I-SMF insertion / modification / deletion or V-SMF modification (see clause 4.23.4.3 of 3GPP TS 23.502 [3]) - Registration procedures for UE PDU sessions with I-SMF or V-SMF insertion, modification and deletion (see clause 4.23.3 of 3GPP TS 23.502 [3]) - EPC / ePDG to 5GS handover with I-SMF insertion (see clause 4.23 of 3GPP TS 23.502 [3]) -SMF context transfer procedure, no LBO or roaming, no I-SMF (see clause 4.26.5.3 of 3GPP TS 23.502 [3]) -I-SMF context transfer procedure (see clause 4.26.5.2 of 3GPP TS 23.502 [3]) - 5G-RG request PDU session establishment by W-5GAN (see section 7.3.1 of 3GPP TS 23.316
[36] ) - FN-RG related PDU session establishment by W-5GAN (see section 7.3.4 of 3GPP TS 23.316
[36] ) -Non-5G capable devices that support 5G-CRG and FN-CRG request PDU session establishment by W-5GAN (see clause 4.10a of 3GPP TS 23.316
[36] ) -Handover from 3GPP Access / EPS to W-5GAN / 5GC (see clause 7.6.4.1 of 3GPP TS 23.316
[36] ). There shall be only one individual SM context per PDU session. An NF service consumer (e.g., AMF) shall create an SM context by using the HTTP POST method as shown in Figure 11. Figure 11 shows a flowchart of SM context creation according to one embodiment of the present disclosure. 1. The NF service consumer shall send a POST request to a resource representing the SMF SM context collection resource. The payload body of the POST request shall contain: -View the individual SM context resources that are created A request type IE when received from a UE for a single access PDU session and when the request refers to an existing PDU session or an existing emergency PDU session, where the request type IE shall not be included for an MA-PDU session establishment request and may be included in other cases. - Old PDU Session ID (i.e. for PDU session establishment for SSC mode 3 operation) when received from the UE -If the DNN corresponds to a LADN (Local Area Data Network), an indication that the UE is inside or outside the LADN service area Indication that an MA-PDU session is requested when an MA-PDU session is requested to be established by the UE, or indication that a PDU session is enabled to be upgraded to an MA-PDU session when indicated by the UE -anType Additional AnType when the UE is registered for both 3GPP and non-3GPP access -cpCiotEnabled IE with the value 'true' if the NF service consumer (e.g., AMF) verifies that the CIOt feature is supported by the SMF (and for home-routed sessions, also by the H-SMF) and control plane CIoT 5GS optimization is enabled for this PDU session - cpOnlyInd IE with the value 'true' if the PDU session shall use only control plane CIoT 5GS optimizations - Invoke NEF indication with value 'true' for a home-routed PDU session when the cpCiotEnabled IE is set to 'true' and data delivery via the NEF is selected for the PDU session - Subscription for SM context state notifications -servingNfId to identify the serving AMF - trace control and configuration parameters if trace is activated (see 3GPP TS 32.422
[22] ); -Identifier of the N3 termination in the W-AGF, TNGF or TWIF, if available (i.e. FQDN or IP address) -Subscription for DDN failure notifications if availability following a DDN failure event has been subscribed to by the UDM For the UE request PDU session establishment procedure in a home routed roaming scenario (see clause 4.3.2.2.2 of 3GPP TS 23.502 [3]), the NF service consumer shall provide the URI of the Nsmf_PDUSession service of the H-SMF in the hSmfUri IE and optionally the corresponding SMF ID, and may provide the URI of the Nsmf_PDUSession service of additional H-SMFs with corresponding SMF IDs. The V-SMF shall attempt to create a PDU session using the hSmfUri IE. If the V-SMF does not receive any response from the H-SMF due to a communication failure on the N16 interface, Depending on operator policy, the V-SMF may attempt to reach the hSmfUri via an alternative path, or - If additional H-SMF URIs are provided, the V-SMF may attempt to create a PDU session in one of the additional H-SMFs provided. For PDU session establishment by the I-SMF (see clause 4.23.5.1 of 3GPP TS 23.502 [3]), the NF service consumer shall provide the URI of the Nsmf_PDUSession service of the SMF in the SmfUri IE and optionally the corresponding SMF ID, and may provide the URI of the Nsmf_PDUSession service of additional SMFs with the corresponding SMF ID. The I-SMF shall attempt to create the PDU session using the smfUri IE. If the I-SMF does not receive any response from the SMF due to a communication failure on the N16a interface, Depending on operator policy, the I-SMF may attempt to reach the smfUri via an alternative path, or -If additional SMF URIs are provided, the I-SMF may attempt to create a PDU session in one of the additional SMFs provided. For the UE request PDU session establishment procedure, if the AMF determines that the RAT type is NB-IoT and the UE already has two PDU sessions with user plane resources activated, the AMF may continue the PDU session establishment as specified in clause 4.3.2.2.1 of 3GPP TS 23.502 [3] and may include a cpCiotEnabled IE or cpOnlyInd IE with a value of “TRUE” for the SMF. The payload body of a POST request may further contain: - The AMF service name for which the SM context state notification is sent, encoded in the serviceName attribute (see clause 6.5.2.2 of 3GPP TS 29.500 [4]). On success, "201 Created" SHALL be returned, the POST response payload body SHALL contain a representation describing the status of the request, and the "Location" header SHALL be present and SHALL contain the URI of the created resource. The authority and / or disposition-specific string of the apiRoot of the created resource URI may differ from the authority and / or disposition-specific string of the apiRoot of the request URI received in the POST request. If the request type is received in the request and is set to EXISTING_PDU_SESSION or EXISTING_EMERGENCY_PDU_SESSION (i.e. indicating that this is a request for an existing PDU Session or an existing Emergency PDU Session), the SMF shall identify the existing PDU Session or Emergency PDU Session based on the PDU Session ID, in this case the SMF shall not create a new SM context but instead update the existing SM context and provide a representation of the updated SM context in the "201 Create" response to the NF service consumer. The POST request is: - containing the same SUPI or PEI for an emergency registered UE without a UICC or without an authenticated SUPI and the same PDU Session ID as for the existing SM context, -This is a request to establish a new PDU session, i.e. The RequestType IE is present in the request and is set to INITIAL_REQUEST or INITIAL_EMERGENCY_REQUEST (e.g., a single access PDU session establishment request); -The RequestType IE and the maRequestInd IE are both absent in the request (e.g., EPS to 5GS mobility), or - the maRequestInd IE is present in the request (i.e., an MA-PDU session establishment request) and the access type indicated in the request corresponds to the access type of an existing SM context In such a case, it shall be considered as a collision with an existing SM context. A POST request that conflicts with an existing SM context shall be treated as a request for a new SM context. Before creating a new SM context, the SMF shall clear the existing SM context locally and any associated resources in the UPF and PCF. See also section 5.2.3.3.1 for handling of requests that conflict with an existing SM context. If the smContextStatusUri of the existing SM context is different from the smContextStatusUri received in the POST request, the SMF shall also send an SM context status notification (see section 5.2.2.5) targeting the smContextStatusUri of the existing SM context to notify the release of the existing SM context. For HR PDU sessions, if the H-SMF URI in the request is different from the H-SMF URI of the existing PDU session, the V-SMF shall also clear the existing PDU session in the H-SMF by invoking the Release service operation (see section 5.2.2.9). For a PDU session with I-SMF, if the SMF URI in the request is different from the SMF URI of an existing PDU session, the I-SMF shall also clear the existing PDU session in the SMF by invoking the Release service operation (see section 5.2.2.9). If a request type is received in the request indicating that it is a request for a new PDU session (i.e. INITIAL_REQUEST) and if an old PDU session ID was also included in the request, the SMF shall identify, based on the old PDU session ID, the existing PDU session which should be released and to which the new PDU session establishment relates. If the GPSI IE is not provided in the request, e.g. because the PDU session has been moved from another access or another system, and the SMF knows that a GPSI is already associated with the PDU session (or a GPSI has been received from the h-SMF for an HR PDU session), the SMF shall include the GPSI in the response. If the request does not contain the "UE presence in LADN service area" indication and the SMF determines that the DNN corresponds to a LADN, the SMF shall consider the UE to be outside the LADN service area. The SMF shall reject the request if the UE is outside the LADN service area. On failure or redirection during UE request PDU session establishment, one of the HTTP status codes listed in Table 6.1.3.2.3.1-3 shall be returned. For 4xx / 5xx responses, the message body shall contain an SmContextCreateError structure containing: -A ProblemDetails structure with the "Cause" attribute set to one of the application errors listed in Table 6.1.3.2.3.1-3 - N1 SM information (PDU Session Reject) if the request contained N1 SM information, except in cases where an error prevents the SMF from generating a response to the UE (e.g. invalid request format). Next Change 5.2.2.2.4 I-SMF insertion, modification, or removal during Xn-based handover An NF service consumer (e.g., AMF) shall request the I-SMF (for I-SMF insertion or modification) or the SMF (for I-SMF deletion) to create an SM context during an Xn-based handover as follows: 1. The NF service consumer shall send a POST request with the following additional information: -N2 SM information received from the target 5G-AN (see Path Switch Request Forwarding IE in clause 9.3.4.8 of 3GPP TS 38.413 [9]) - Additional N2 SM information received from the source 5G-AN, if any (see Secondary RAT Data Usage Report Forwarding IE in clause 9.3.4.23 of 3GPP TS 38.413 [9]) - an identifier of the SM context resource in the SMF during an I-SMF insertion or in the source I-SMF during an I-SMF modification or deletion, and optionally an smContextRef attribute set to the NF instance identifier of the SMF hosting the SM context resource 2a. On success, the SMF shall return a 201 Create response. The "Location" header shall be present in the POST response and shall contain the URI of the SM context resource that was created. The NF service consumer (e.g., AMF) shall store the association of the PDU session ID and the SMF ID. 2b. Same as step 2b in Figure 5.2.2.2.1-1. If the Path Switch Request Forwarding IE is included in the N2 SM information in the request message but the path switch is unsuccessful, the message body shall contain an SmContextCreateError structure containing the following: -N2 SM information (path switching request transfer failure) Next Change 5.2.2.2.5 I-SMF insertion, modification, or deletion during N2-based handover An NF service consumer (e.g., AMF) shall request the I-SMF (for I-SMF insertion or modification) or the SMF (for I-SMF deletion) to create an SM context during an N2-based handover as follows: 1. The NF service consumer shall send a POST request with the following additional information: - N2 SM information received from the source NG-RAN (see Handover Mandatory Forwarding IE in clause 9.3.4.14 of 3GPP TS 38.413 [9]) The hoState attribute set to -PREPARING (see Section 5.2.2.3.4.1) - an identifier of the SM context resource in the SMF during an I-SMF insertion or in the source I-SMF during an I-SMF modification or deletion, and optionally an smContextRef attribute set to the NF instance identifier of the SMF hosting the SM context resource 2a. If successful, the SMF shall return a 201 Create response containing the following information: - hoState attribute set to PREPARING, as defined in step 2 of Figure 5.2.2.3.4.2-1, and N2 SM information to request the target 5G-AN to allocate resources to the PDU session The "Location" header shall be present in the POST response and shall contain the URI of the SM context resource that was created. The NF service consumer (e.g., AMF) shall store the association of the PDU session ID and the SMF ID. 2b. Same as step 2b in Figure 5.2.2.2.1-1. Next Change 5.2.2.2.6 Service request with I-SMF insertion / change / deletion or V-SMF change An NF service consumer (e.g., AMF) shall request a new I-SMF or a new V-SMF to create an SM context during a service request with I-SMF insertion / modification or V-SMF modification, or shall request an SMF to create an SM context during a service request with I-SMF deletion. Figure 12 shows a flowchart of a service request with I-SMF insertion / modification / deletion or V-SMF modification according to one embodiment of the present disclosure. 1. The NF service consumer SHALL send a POST request as specified in section 5.2.2.2.1 with the following additional information: - an identifier of the SM context resource in the SMF (for a service request due to an I-SMF insertion) or old I-SMF (for a service request due to an I-SMF modification or deletion) or old V-SMF (for a service request due to a V-SMF modification) and, optionally, an smContextRef attribute set to the NF instance identifier of the SMF hosting the SM context resource - the upCnxState attribute set to ACTIVATING (see Section 5.2.2.3.2.1) to indicate the establishment of N3 tunnel user plane resources for the PDU session 2a. If successful, the SMF SHALL return a 201 Create response as specified in Section 5.2.2.2.1 with the following additional information: -upCnxState attribute set to ACTIVATING N2 SM information to request the 5G-AN to allocate resources to the PDU session, including the transport layer address of the uplink endpoint and the tunnel endpoint (i.e., the GTP-U F-TEID of the UPF for uplink traffic) for the user plane data for this PDU session (see PDU Session Resource Setup Request Forwarding IE in clause 9.3.4.1 of 3GPP TS 38.413 [9]) 2b. Same as step 2b in Figure 5.2.2.2.1-1. Steps 3-4 are skipped in this case. Next Change 5.2.2.2.7 Registration procedures for UE PDU sessions with I-SMF insertion, modification and deletion The NF service consumer (e.g., AMF) shall request the SMF to create an SM context during the UE registration procedure for a PDU session with I-SMF insertion, modification, and deletion as follows: Similar to step 1 in 1.5.2.2.2.1-1, the NF service consumer shall send a POST request with the following additional information: - an identifier of the SM context resource in the SMF during an I-SMF insertion, or in the I-SMF during an I-SMF removal, or in the old I-SMF during an I-SMF change, and optionally an smContextRef attribute set to the NF instance identifier of the SMF hosting the SM context resource - upCnxState attribute set to ACTIVATING (see clause 5.2.2.3.2.1) to indicate establishment of N3 tunnel user plane resources for the PDU session if the UE has requested to activate the PDU session 2a. On success, the SMF shall return a 201 Create response. If the SMF establishes N3 tunnel user plane resources for the PDU session, e.g. due to an NF service consumer requesting it or due to buffered DL data in the old I-SMF / I-UPF (see clause 4.23.3 of 3GPP TS 23.502 [3]), the 201 Create response shall contain the following additional information: -upCnxState attribute set to ACTIVATING N2 SM information to request the 5G-AN to allocate resources to the PDU session, including the transport layer address and tunnel endpoint (i.e., the GTP-UF-TEID of the UPF for uplink traffic) of the uplink termination point for user plane data for this PDU session (see PDU Session Resource Setup Request Transport IE in clause 9.3.4.1 of 3GPP TS 38.413 [9]) The "Location" header shall be present in the POST response and shall contain the URI of the SM context resource that was created. The NF service consumer (e.g., AMF) shall store the association of the PDU session ID and the SMF ID. 2b. Same as step 2b in Figure 5.2.2.2.1-1. Next Change 6.1.3.2.3.1 POST This method creates individual SM context resources in the SMF or V-SMF in an HR roaming scenario. This method SHALL support the URI query parameters defined in Table 6.1.3.2.3.1-1. JPEG0007676534000001.jpg25170 This method shall support the request data structure specified in Table 6.1.3.2.3.1-2, and the response data structure and response codes specified in Table 6.1.3.2.3.1-3. JPEG0007676534000002.jpg28170JPEG0007676534000003.jpg255170Next change 6.1.6.2.2 Type: SmContextCreateData JPEG0007676534000004.jpg255170JPEG0007676534000005.jpg255170JPEG0007676534000006.jpg255170JPEG0007676534000007.jpg255170JPEG0007676534000008.jpg255170JPEG0007676534000009.jpg255170JPEG0007676534000010.jpg255170JPEG0007676534000011.jpg255170JPEG0007676534000012.jpg106170Next change 6.1.7.3 Application Errors The general application errors specified in Table 5.2.7.2-1 of 3GPP TS 29.500 [4] may be used for the Nsmf PduSession service. The following application errors, listed in Table 6.1.7.3-1, are specific to the Nsmf_PDUSession service. JPEG0007676534000013.jpg255170JPEG0007676534000014.jpg255170JPEG0007676534000015.jpg169170Next change A.2 Nsmf_PDUSession API openapi:3.0.0 information: Version: '1.1.0' Title: 'Nsmf_PDUSession' Description: | SMF PDU Session Service (C) 2020,3GPP Organizational Partners (ARIB,ATIS,CCSA,ETSI,TSDSI,TTA,TTC) Unauthorized reproduction prohibited. externalDocs: Description: 3GPP TS 29.502 V16.4.0; 5G Systems; Session Management Services; Stage 3 url:http: / / www.3gpp.org / ftp / Specs / archive / 29_series / 29.502 / server: - url:'{apiRoot} / nsmf-pdusession / v1' variable: apiRoot: Default: https: / / example.com Description: apiRoot as specified in 3GPP TS 29.501, clause 4.4. sm-context and pdu-session resources can be distributed on different processing instances or hosts. Hence, the authority and / or location specific string of the apiRoot in the URI of each created sm-context and pdu-session resource may differ from the authority and / or location specific string of the apiRoot in the URI of the collection of sm-contexts and pdu-sessions. Text skipped for clarity TIFF0007676534000016.tif255170TIFF0007676534000017.tif255170TIFF0007676534000018.tif255170TIFF0007676534000019.tif177170Text skipped for clarity End of change
[0144] The various blocks / steps illustrated in Figures 5-12 may be considered as multiple coupled logic circuit elements configured to perform method steps and / or operations resulting from computer program code operations and / or related functions. The schematic flow chart diagrams described above are generally illustrated as logic flow chart diagrams. As such, the illustrated order and labeled steps illustrate particular embodiments of the presented method. Other steps and methods may be considered equivalent in function, logic, or effect to one or more steps or portions thereof of the illustrated method. Furthermore, the order in which a particular method is performed may or may not strictly follow the order of the corresponding steps shown.
[0145] In one embodiment, the SMF IDs corresponding to the SMF service URI and the SM context URI may be added to the SmContextCreateData type.
[0146] In one embodiment, a new application error is defined for service authorization failure when the V-SMF / I-SMF is not authorized to access the service in the H-SMF / SMF / old V- / I-SMF.
[0147] In one embodiment, the service procedure for the AMF to provide the corresponding SMF ID is updatable.
[0148] The embodiments herein provide many advantages, of which a non-exhaustive list of examples is provided below. Some embodiments herein may enable a first session management function to obtain an access token (e.g., an OAuth2 token) for a second session management function based on an access and mobility management function (e.g., AMF) providing an NF instance ID, such that the first session management function can authorize the second session management function to perform various options (e.g., SM context retrieval operation or PDU session creation operation). The embodiments herein are not limited to the above features and advantages. Those skilled in the art will recognize additional features and advantages from reading the following detailed description.
[0149] 13 is a block diagram illustrating an apparatus suitable for implementing some embodiments of the present disclosure. For example, any one of the first session management function, the network repository function, the second session management function, and the network function service consumer described above may be implemented as or by the apparatus 1300.
[0150] The apparatus 1300 includes at least one processor 1321, such as a digital processor (DP), and at least one memory (MEM) 1322 coupled to the processor 1321. The apparatus 1320 may further include a transmitter TX and a receiver RX 1323 coupled to the processor 1321. The MEM 1322 stores a program (PROG) 1324. The PROG 1324 may include instructions that, when executed on the associated processor 1321, enable the apparatus 1320 to operate according to embodiments of the present disclosure. The combination of the at least one processor 1321 and the at least one MEM 1322 may form a processing means 1325 adapted to perform various embodiments of the present disclosure.
[0151] Various embodiments of the present disclosure may be implemented by a computer program executable by the processor 1321, one or more of software, firmware, hardware, or a combination thereof.
[0152] The MEM1322 may be of any type suitable for the local technology environment and may be implemented using any suitable data storage technology, such as, by way of non-limiting examples, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed and removable memory.
[0153] The processor 1321 may be of any type suitable for the local technology environment and may include, by way of non-limiting examples, one or more of a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture.
[0154] In one embodiment in which the apparatus is implemented as or in a first session management function, the memory 1322 contains instructions executable by the processor 1321 to cause the first session management function to operate according to any step of any method associated with the first session management function described above.
[0155] In one embodiment in which the device is implemented as or in a network repository function, the memory 1322 contains instructions executable by the processor 1321 to cause the network repository function to operate according to any step of the method associated with the network repository function described above.
[0156] In one embodiment in which the apparatus is implemented as or in a second session management function, the memory 1322 contains instructions executable by the processor 1321 to cause the second session management function to operate according to any step of the method associated with the second session management function described above.
[0157] In one embodiment in which the device is implemented as or in a network function service consumer, memory 1322 contains instructions executable by processor 1321 to cause the network function service consumer to operate according to any step of the method associated with the network function service consumer described above.
[0158] 14 is a block diagram illustrating a first session management function according to an embodiment of the present disclosure. As shown, the first session management function 1400 includes a first sending module 1402 and a first receiving module 1404. The first sending module 1402 may be configured to send a first request to obtain an access token for the second session management function to a network repository function. The first receiving module 1404 may be configured to receive a first response from the network repository function containing the access token for the second session management function or error information.
[0159] In one embodiment, the first session management function 1400 may further include a second sending module 1406. The second sending module 1406 may be configured to send a second request to the second session management function containing an access token for the second session management function. In one embodiment, the first session management function 1400 may further include a second receiving module 1408. The second receiving module 1408 may be configured to receive a third request from the network function service consumer containing a network function instance identifier of the second session management function.
[0160] In one embodiment, the first session management function may further include a third sending module 1410. The third sending module 1410 may be configured to send a third response to the network function service consumer including an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0161] 15 is a block diagram illustrating a network repository function according to one embodiment of the present disclosure. As shown, the network repository function 1500 includes a receiving module 1502 and a sending module 1504. The receiving module 1502 may be configured to receive a first request to obtain an access token for a second session management function from a first session management function. The sending module 1504 may be configured to send a first response to the first session management function containing the access token for the second session management function or error information.
[0162] 16 is a block diagram illustrating a second session management function according to one embodiment of the present disclosure. As shown, the second session management function 1600 includes a receiving module 1602 and a processing module 1604. The receiving module 1602 may be configured to receive a second request containing an access token for the second session management function from the first session management function. The processing module 1604 may be configured to process the second request.
[0163] 17 is a block diagram illustrating a network function service consumer according to one embodiment of the present disclosure. As shown, network function service consumer 1700 includes a sending module 1702. Sending module 1702 may be configured to send a third request to the first session management function, the third request including the network function instance identifier of the second session management function.
[0164] In one embodiment, the network function service consumer may further include a receiving module 1704. The receiving module may be configured to receive a third response from the first session management function including an application error indicating that the first session management function is not authorized to access the service provided by the second session management function.
[0165] The term unit or module may have its conventional meaning in the field of electronic equipment, electrical devices, and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for performing respective tasks, procedures, calculations, outputs, and / or display functions, etc., such as those described herein.
[0166] Depending on the functional unit, the first session management function, the network repository function, the second session management function, or the network function service consumer may not require a fixed processor or memory, and any computing resource and storage resource may be allocated from the first session management function, the network repository function, the second session management function, or the network function service consumer in the communication system. The introduction of virtualization technology and network computing technology may improve the utilization efficiency of network resources and the flexibility of the network.
[0167] According to one aspect of the present disclosure, a computer program product is provided that includes instructions tangibly stored on a computer-readable storage medium and that, when executed on at least one processor, cause the at least one processor to perform any of the methods described above.
[0168] According to one aspect of the present disclosure, a computer-readable storage medium is provided that stores instructions that, when executed by at least one processor, cause the at least one processor to perform any of the methods described above.
[0169] Furthermore, the present disclosure can also provide a carrier that contains the computer program as described above.The carrier is one of electronic signal, optical signal, radio signal, or computer readable storage medium.Computer readable storage medium can be, for example, RAM (random access memory), ROM (read only memory), flash memory, magnetic tape, optical compact disk such as CD-ROM, DVD, and Blu-ray disk, or electronic memory device.
[0170] The techniques described herein may be implemented by various means, such that an apparatus implementing one or more functions of a corresponding apparatus described by an embodiment may include not only prior art means, but also means for implementing one or more functions of a corresponding apparatus described by an embodiment, and may include separate means for each separate function, or means that can be configured to perform one or more functions. For example, these techniques may be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules), or a combination thereof. For firmware or software, implementation may be made by modules (e.g., procedures and functions, etc.) that perform the functions described herein.
[0171] Exemplary embodiments herein are described with reference to block diagrams and flowchart illustrations of methods and apparatus. It will be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, respectively, can be implemented by various means including computer program instructions. These computer program instructions may be loaded onto a general purpose computer, a special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute on the computer or other programmable data processing apparatus, provide means for performing the functions specified in the flowchart block(s).
[0172] Furthermore, although operations are illustrated in a particular order, this should not be understood as requiring that such operations be performed in the particular order or sequence shown, or that all of the illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be construed as limitations on the scope of the subject matter described herein, but rather as descriptions of features that may be specific to certain embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable subcombination.
[0173] Although this specification contains many specific implementation details, these should not be interpreted as limitations on the scope of any implementation or on the scope that may be claimed, but rather as descriptions of features that may be specific to a particular embodiment of a particular implementation. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable subcombination. Also, although features may be described above as acting in a certain combination and even initially claimed as such, one or more features from a claimed combination may, in some cases, be deleted from the combination, and the claimed combination may be directed to a subcombination or a variation of the subcombination.
[0174] It will be obvious to those skilled in the art that with the advancement of technology, the concept of the present invention can be implemented in various ways. The above-mentioned embodiments are shown to illustrate, not to limit, the present disclosure, and it should be understood that modifications and variations may be used without departing from the spirit and scope of the present disclosure, as easily understood by those skilled in the art. Such modifications and variations are considered to be within the scope of the present disclosure and the appended claims. The scope of protection of the present disclosure is defined by the appended claims.
Claims
1. A method (500) performed by a first session management function, comprising: Receiving a third request from an Access and Mobility Management Function (AMF) containing a network function instance identifier of a second session management function (502); sending (504) a first request to a network repository function to obtain an access token for the second session management function, the first request including the network function instance identifier of the second session management function; receiving (506) a first response from the network repository function containing the access token or error information for the second session management function; sending a second request to the second session management function containing the access token for the second session management function (508); A method comprising:
2. The second request is a request to establish a forwarding tunnel between the first session management function and the second session management function; a request to retrieve a session management context from the second session management function; a request to create a new protocol data unit (PDU) session in the second session management function or to create an association with an existing packet data network (PDN) connection in the second session management function; A request to update the established PDU session in the second Session Management Function; A request to release resources associated with the PDU session in the second Session Management Function; or The method of claim 1 , further comprising at least one of: a request to push a session management context to the second session management function.
3. The second request is Nsmf_PDUSession_UpdateSMContext request, Nsmf_PDUSession_Context request, Nsmf_PDUSession_Create request, Nsmf_PDUSession_Update, Nsmf_PDUSession_Release request, or The method of claim 2 , further comprising at least one of a Nsmf_PDUSession_ContextPush request.
4. The method of claim 1 , wherein the first request is an Nnrf_AccessToken_Get request.
5. The network function instance identifier of the second session management function the network function instance identifier of a session management function that hosts a session management (SM) context; said network function instance identifier of a home session management function; said network function instance identifier of a session management function; At least one network function instance identifier of at least one additional home session management function; or The method of claim 1 , further comprising at least one of the at least one network function instance identifier of the at least one additional session management function.
6. 6. The method of claim 1, wherein the error information indicates that the first session management function is not enabled to access a service provided by a next-hop network function producer.
7. The method according to any one of claims 1 to 6, wherein the second session management function is a home session management function or a session management function or an old intermediate session management function or an old visited session management function.
8. The method according to claim 1 , wherein the first session management function is a new intermediate session management function or a visited session management function.
9. 9. The method of claim 1, wherein the network repository function is an OAuth 2.0 authorization server, the first session management function is an OAuth 2.0 client, and the second session management function is an OAuth 2.0 resource server.
10. 2. The method of claim 1, further comprising: the first session management function sending (510) a third response to the network function service consumer including an application error indicating that the network function service consumer is not authorized to access a service provided by the second session management function.
11. 11. The method of claim 1, wherein the first request is sent to the network repository function when OAuth is enabled for the second session management function.
12. A first session management function (1300), A processor (1321); a memory (1322) coupled to the processor (1321), the memory (1322) containing instructions executable by the processor (1321) such that the first session management function (1300) receiving a third request from an access and mobility management function (AMF) containing a network function instance identifier of the second session management function; sending a first request to a network repository function to obtain an access token for the second session management function, the first request including the network function instance identifier of the second session management function; receiving a first response from the network repository function containing the access token or error information for the second session management function; and and sending a second request to the second session management function containing the access token for the second session management function.
13. A first session management facility according to claim 12, wherein the first session management facility is further operative to perform a method according to any one of claims 2 to 11.