Processing service requests
The method addresses the challenge of processing subsequent service requests by enabling the SCP node to acquire and use access tokens within the network, ensuring successful request processing and improved system performance.
Patent Information
- Application Number
- JP2024017969
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-07-31
- Filing Date
- 2024-02-08
- Publication Date
- 2025-05-19
- Estimated Expiration
- 2041-06-25
AI Technical Summary
Existing systems for processing service requests within a network face challenges in handling subsequent requests after the initial request for discovery parameters and access tokens, leading to failed subsequent request processing due to the inability to find or obtain valid access tokens.
A method where a first network function (NF) node of a service consumer initiates a first request to a service communication proxy (SCP) node, including discovery and access token request parameters. The SCP node then selects a second NF node of the service producer, acquires an access token, and transfers subsequent requests to the selected NF node using the stored or newly acquired access token.
This approach enables successful processing of subsequent service requests by ensuring the SCP node has the necessary access tokens, thereby improving system performance and reliability in handling service requests within the network.
Smart Images

Figure 0007679509000001 
Figure 0007679509000002 
Figure 0007679509000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to methods for processing service requests within a network and nodes configured to operate in accordance with those methods.
Background Art
[0002] There are various techniques for processing requests for services within a network. Service requests are generally from a consumer of the service ("service consumer") to a producer of the service ("service producer"). For example, a service request can be from a network function (NF) node of a service consumer to an NF node of a service producer. The NF node of the service consumer (NFc) and the NF node of the service producer (NFp) can communicate directly or indirectly. This is referred to as direct communication and indirect communication. In the case of indirect communication, the NF node of the service consumer and the NF node of the service producer can communicate via a service communication proxy (SCP) node.
[0003] Figures 1A-D show various existing systems for processing service requests as described in 3GPP TS 23.501 v16.5.0 (available at https: / / portal.3gpp.org / desktopmodules / Specification / SpecificationDetails.aspx?specificationId=3144 as of July 27, 2020). More specifically, Figures 1A and 1B show systems that use direct communication, and Figures 1C and 1D show systems that use indirect communication.
[0004] In the systems shown in FIGS. 1A and 1B, a service request is sent directly from the NF node of the service consumer to the NF node of the service producer. A response to the service request is sent directly from the NF node of the service producer to the NF node of the service consumer. Similarly, any subsequent service request is sent directly from the NF node of the service consumer to the NF node of the service producer. The system shown in FIG. 1B also has a Network Repository Function (NRF). Therefore, in the system shown in FIG. 1B, the consumer's NF node can query the NRF to find the appropriate NF node of the service producer to which the service request should be sent. In response to such a query, the consumer's NF node can receive NF profiles regarding one or more NF nodes of the service producer and can select the NF node of the service producer to which the service request should be sent based on the received one or more NF profiles. In the system shown in FIG. 1A, the NRF is not used. Instead, the consumer's NF node can be configured using one or more NF profiles of one or more NF nodes of the service producer.
[0005] In the systems shown in FIGS. 1C and 1D, a service request is sent indirectly from the NF node of the service consumer to the NF node of the service producer via a Service Communication Proxy (SCP) node. A response to the service request is sent indirectly from the NF node of the service producer to the NF node of the service consumer via the SCP. Similarly, any subsequent service request is sent indirectly from the NF node of the service consumer to the NF node of the service producer via the SCP. The systems shown in FIGS. 1C and 1D also have the NRF.
[0006] In the system shown in FIG. 1C, the consumer's NF node can query the NRF to find the appropriate NF node of the service producer to which the service request should be sent. In response to such an inquiry, the consumer NF node can receive an NF profile regarding one or more NF nodes of the service producer, and based on the one or more received NF profiles, can select the NF node of the service producer to which the service request should be sent. In this case, the service request sent from the consumer NF node to the SCP includes the address of the selected NF node of the service producer. The consumer NF node can forward the service request without performing further discovery or selection. If the selected NF node of the service producer is inaccessible for some reason, the consumer NF node may be able to find an alternative NF node. In other cases, the SCP may communicate with the NRF to obtain selection parameters (e.g., location, capacity, etc.), and the SCP can select the NF node of the service producer to which the service request should be sent.
[0007] In the system shown in Figure 1D, the consumer NF node (NFc) does not perform discovery or selection processing. Instead, the consumer NF node can add any necessary discovery and selection parameters (required to find the appropriate NF node (NFp) of the service producer) to the service request sent via the SCP. Then, the SCP can use the request address and the discovery and selection parameters within the service request to route the service request to the appropriate NF node of the service producer. The SCP can perform discovery using the NRF. The consumer NF node can also include in the service request a client credential assertion to be used by the SCP in the authorization process. The client credential assertion is a token signed by the consumer NF node, and the consumer NF node can authenticate against the receiving endpoints (NRF, producer's NF node) by including the signed token in the service request. The use of the client credential assertion is described in 3GPP TS 33.501 v16.3.0 (available at https: / / portal.3gpp.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3169 as of July 27, 2020), particularly in section 13.3.1.2.
[0008] In the case of the 5th Generation Core (5GC), since Release 16, the SCP is included as a network element that enables indirect communication between the service consumer's NF node and the service producer's NF node. The indirect communication used can be either of the two indirect communication options described earlier with reference to Figures 1C and 1D.
[0009] Figures 2A through 2C are signaling diagrams showing the exchange of signals in an existing system such as the system shown in FIG. 1D. The system shown in FIGS. 2A through 2C includes a first SCP node 10, a first NF node of a service consumer ("NFc") 20, a second NF node of a service producer ("NFp1") 30, and a third NF node of a service producer ("NFp2") 70. The first SCP node 10 is configured to operate as an SCP between the first NF node 20 and the second NF node 30. The second NF node 30 may be configured to execute a service 40, and the third NF node 70 may be configured to execute a service 80. The second NF node 30 and the third NF node 70 may be configured to execute the same service or different services. The second NF node 30 and the third NF node 70 may be part of a set 402 of NF nodes of a service producer. The system shown in FIGS. 2A through 2C also has a network repository function 60.
[0010] In FIGS. 2A through 2C, steps 600 through 630 are related to a first request regarding a user equipment (UE) / session context. As shown in block 500 of FIGS. 2A through 2C, the UE / session context may be stored. More specifically, as shown in block 600 of FIGS. 2A through 2C, the first NF node 20 determines which discovery and selection parameters to use. The parameters may be associated with a particular service within the received request, which is not shown in FIGS. 2A through 2C. As shown in blocks 502 and 602 of FIGS. 2A through 2C, the first NF node 20 stores the UE / session context for that request. This storage may be cached or stored externally.
[0011] As shown by arrow 604 in FIGS. 2A through 2C, the first NF node (NFc) 20 starts transmitting a discovery request to the first SCP node 10. The discovery request includes a client credential assertion that authenticates the client and provides information that can be used for the first SCP to obtain an access token on behalf of the first NF node 20. The first SCP node 10 uses the discovery request (see arrows 606 and 608) to obtain from the NRF 60 one or more NF profiles of one or more NF nodes (NFp) of the service producer regarding the service that needs to be executed. As shown in blocks 504 and 610 in FIGS. 2A through 2C, the first SCP node 10 can save the discovery result (the returned NF profile).
[0012] As shown by arrow 612, the first SCP node 10 sends an access token request to the NRF60. The access token request includes some parameters from the discovery parameters received in the request (see arrow 604), and may also include other information from the first SCP node 10, such as a scope (one or more services). Which discovery parameters need to be used to permit the access token can be configured in the first SCP node 10. The access token request parameters are discussed in more detail in 3GPP TS 33.501 cited above, particularly in section 13.4.1.1. The discovery parameters are discussed in more detail in GPP TS 29.510 V 16.4.0 available at https: / / portal.3gpp.org / desktopmodules / Specifications / SpecificationDetails.aspx?specificationId=3345 as of July 27, 2020, particularly in section 6.2.3.3.1. For example, tokens may need to be granted at different granularities, such as a service level + network slice level (using a single network slice selection assistance information, S-NSSAI; thus, in this example, an S-NSSAI may be required to grant an access token). Then, at arrow 614, the NRF grants an access token corresponding to the indicated granularity. The access token is then cached by the first SCP node 10, together with the criteria (scope and granularity) of the access token (see blocks 616 and 506). The access token may be valid for a predetermined period. The length of this period can be indicated by the NRF60, for example, when the NRF60 provides an access token response including the access token. After the predetermined period, the access token may expire.
[0013] As shown in block 618, the first SCP node 10 then selects, from among the (one or more) NF profiles obtained using discovery requests (at arrows 606 and 608), the NF node of the service producer, which in this example is the second NF node 30. The selected NF node of the service producer is the NF node corresponding to the granted access token received by the first SCP node at arrow 614. The determination of which of the obtained NF node profiles to select (assuming that two or more NF node profiles are received) depends on the specific configuration of the SCP node 10.
[0014] When an NF node (the second NF node 30 in this example) is selected, as shown in block 620, the first SCP node 10 changes the address within the request (received from the first NF node 20) from the address of the first SCP node 10 to the host address of the second NF node 30. The first SCP node 10 can perform additional tasks such as NF producer node monitoring as needed (see block 622). The first SCP node 10 then starts transmitting a service request at arrow 624 towards the selected second NF node 30. Note that the access token obtained by the first SCP node 10 is added to the service request. As shown by arrow 626 from FIGS. 2A to 2C, the first SCP node 10 receives a response containing the result from the second NF node 30. If the selected NF producer node supports the binding function, the result can include a client binding header with binding information intended to be used by the NFc in subsequent requests. The response also includes the NF instance ID and the set ID. As shown by arrow 628 from FIGS. 2A to 2C, the first SCP node 10 starts transmitting a response containing the result towards the first NF node 20. And as shown in blocks 508 and 630 from FIGS. 2A to 2C, the first NF node 20 can save the result.
[0015] In FIGS. 2A to 2C, steps 632 to 640 are related to subsequent service requests for an existing UE / session context. At block 632, the first NF node 20 identifies that the subsequent result corresponds to the same UE / session context. At block 634, since the communication between the first NF node 20 and the second NF node 30 is indirect (via the first SCP node 10) in this example, the first NF node 20 copies the client binding information received as a result from the second NF node 30 to the routing binding. Note that this step is unnecessary if bindings are not used. Next, the first NF node 20 sends a service request (with arrow 636) that includes the routing binding (bindings are not necessarily used as described above in this example) and also includes a client credential assertion. A client credential assertion may be required if a previously obtained token has expired.
[0016] At block 638, the first SCP node 10 attempts to find a valid access token from the stored results (see blocks 616 and 506 regarding access token storage). However, the information included in the subsequent request of arrow 636 does not provide a means to identify a valid token. The client credential assertion is included in the subsequent request, but other information that may have been provided in the discovery request in the first request (see arrow 604) is not included in the subsequent request at arrow 636. Therefore, the first SCP node 10 cannot find a valid stored access token and, moreover, cannot request an applicable token because the information required for the token request is not provided. In this example, the S-NSSAI is not provided. Thus, it is impossible for the first SCP node 10 to obtain a valid token, and the subsequent request procedure fails.
[0017] Therefore, in a system using indirect communication, after the first request to provide discovery parameters so that an SCP node can be selected, subsequent service requests cannot be processed by the SCP node. The SCP node cannot find a valid stored access token and does not have enough information to request a new access token. SUMMARY OF THE INVENTION
[0018] An object of the present disclosure is to alleviate or eliminate at least some of the above-mentioned problems related to the prior art.
[0019] Accordingly, according to one aspect of the present disclosure, a method for processing service requests within a network is provided, the method being performed by a first network function (NF) node of a service consumer to connect to a further NF node of a service producer via a first service communication proxy (SCP) node. The method includes initiating transmission of a first request regarding the provision of a first service by the further NF node to the first SCP node. The first request includes discovery parameters and access token request parameters. The access token request parameters facilitate the acquisition and storage of an access token by the first SCP node, and the discovery parameters facilitate the selection of a second NF node of the service producer as a further NF node for providing the first service by the first SCP node and the transfer of the request to the second NF node by the first SCP node. The method further includes receiving a response from the second NF node transferred by the first SCP node. The method also includes initiating transmission of a second request to the first SCP node, the second request being a subsequent request for the second NF node to supply the first service. The second request includes access token request parameters, and the first SCP node transfers the second request to the second NF node using the stored access token or the newly acquired access token included in the second request.
[0020] In some embodiments, the first request can include an encryption token to enable the first SCP node to obtain an access token on behalf of the first NF node, and the encryption token can be stored together with the access token request parameters. The second request can also include an encryption token. The encryption token can be an NF service consumer client credentials assertion.
[0021] In some embodiments, the second request can be for the second NF node to provide the first service in the same execution context as the first request.
[0022] In some embodiments, the access token request parameters can be stored in a user equipment (UE) data record.
[0023] In some embodiments, the access token request parameters can include a single network slice selection assistance information (S-NSSAI).
[0024] In some embodiments, the method can further include receiving, by the first SCP node, a first request for the provision of the first service by a further NF node. The method can further include obtaining a service producer NF node profile, obtaining an access token, and selecting a second NF node using the obtained service producer NF node profile. The method can also include starting to send a third request for the provision of the service to the second NF node, the third request including the obtained access token, receiving a response from the second NF node, and starting to send the response to the first NF node.
[0025] In some embodiments, the step of obtaining a service producer NF node profile may include starting to send, using discovery parameters from a first request for the service producer NF node profile, a fourth request to a network repository function (NRF) node, and receiving a first response from the NRF node or obtaining a stored service producer NF node profile. Also, the step of obtaining an access token may include starting to send, using access token request parameters from the first request, a fifth request for the access token to the NRF node, and receiving a second response from the NRF node or obtaining a stored access token. Further, the service producer NF node profile and / or the access token may be stored.
[0026] In some embodiments, the method may further include the first SCP node receiving a second request, which is a subsequent request for the provision of a first service to a second NF node. The method may further include obtaining a valid access token using access token request parameters from the second message. The method may also include starting to send a sixth request for service provision to the second NF node, the sixth request including a valid access token, receiving a response from the second NF node, and starting to send to the first NF node.
[0027] According to another aspect of the present disclosure, there is provided a first NF node having a processing circuit configured to operate according to the method described above with respect to the first NF node. In some embodiments, the first NF node may have at least one memory for storing instructions that, when executed by the processing circuit, cause the first NF node to operate according to the method described above with respect to the first NF node.
[0028] According to another aspect of the present disclosure, a method executed by a system is provided. The method may include the method described above with respect to the first SCP node and / or the method described above with respect to the first NF node.
[0029] According to another aspect of the present disclosure, a system is provided. The system may include at least one of the aforementioned first SCP nodes and / or at least one of the aforementioned first NF nodes.
[0030] According to another aspect of the present disclosure, when executed by a processing circuit, a computer program is provided that has instructions to cause the processing circuit to execute the method described above with respect to the first SCP node and / or the first NF node.
[0031] According to another aspect of the present disclosure, a computer program product implemented on a non-transitory machine-readable medium is provided that has instructions executable by a processing circuit to cause the processing circuit to execute the method described above with respect to the first SCP node and / or the first NF node.
[0032] Therefore, an improved approach for processing service requests within a network is provided.
Brief Description of the Drawings
[0033] To better understand the present technology and show how it can be implemented, as an example, reference is made to the accompanying drawings.
[0034]
Figure 1
Figure 2A
Figure 2B
Figure 2C
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7A
Figure 7B
Figure 7C
Figure 8
Figure 9
Mode for Carrying Out the Invention
[0035] Here, a method for processing service requests within a network will be described. A service request can also be referred to as a service invocation. Generally, a service is software that is intended to be managed with respect to a user. In this specification, a service can be any type of service, such as a communication service (e.g., a notification service or a callback service), a context management (e.g., user equipment context management (UECM)) service, a data management (DM) service, or any other type of service. The method described in this specification can be used with any communication or telecommunications network, such as a cellular network, for example. The network can be a fifth generation (5G) network or any other generation network. In some embodiments, the network can be a core network or a radio access network (RAN). The method described in this specification is implemented by a first network function (NF) node of a first service communication proxy (SCP) node and a service consumer node (NFc node). The SCP node can be configured to operate as an SCP between the NFc node and at least one NF node (NFp node) of a service producer within the network.
[0036] NF is a processing function within a network adopted or defined by the Third Generation Partnership Project (3GPP), and has defined functional operations and interfaces defined by 3GPP. NF can be implemented as a network element on dedicated hardware, as a software instance executed on dedicated hardware, or as a virtualized function instantiated on a suitable platform, such as on a cloud infrastructure, for example. It should be understood that the term "node" related to "NF node" in this specification encompasses each of these scenarios.
[0037] FIG. 3 shows a first SCP node 10 according to an embodiment. The first SCP node 10 is for processing service requests within a network. The first SCP node 10 is configured to operate as an SCP between a first network function (NF) node (20) of a service consumer and a second NF node (30) of a service producer in the network. In some embodiments, the first SCP node 10 can be, for example, a physical machine (e.g., a server) or a virtual machine (VM).
[0038] As shown in FIG. 3, the first SCP node 10 has a processing circuit (or logic) 12. The processing circuit 12 controls the operation of the first SCP node 10 and can implement the methods described herein with respect to the first SCP node 10. The processing circuit 12 can be configured or programmed to control the first SCP node 10 in the methods described herein. The processing circuit 12 can have one or more hardware components such as one or more processors, one or more processing units, one or more multi-core processors, and / or one or more modules. In certain embodiments, each of the one or more hardware components can be configured to execute, or be for executing, individual steps or multiple steps of the methods described herein with respect to the first SCP node 10. In some embodiments, the processing circuit 12 can be configured to execute software to implement the methods described herein with respect to the first SCP node 10. The software may be containerized according to some embodiments. Thus, in some embodiments, the processing circuit 12 can be configured to execute containers to implement the methods described herein with respect to the first SCP node 10.
[0039] That is, the processing circuit 12 of the first SCP node 10 is configured to receive a first request (from the first NF node 20, the consumer NF node) for the provision of a first service by a further NF node (provider NF node). The processing circuit 12 of the first SCP node 10 is further configured to obtain a service producer NF node profile and an access token, and to select a second NF node 30 using the obtained service producer NF node profile. The processing circuit 12 of the first SCP node 10 is also further configured to initiate transmission of a third request for the provision of a service to the second NF node, where the third request includes the obtained access token, to receive a response from the second NF node, and to initiate transmission of the response to the first NF node.
[0040] As shown in FIG. 3, in some embodiments, the first SCP node 10 may have a memory 14 as needed. The memory 14 of the first SCP node 10 may include volatile memory or non-volatile memory. In some embodiments, the memory 14 of the first SCP node 10 may include a non-transitory medium. Examples of the memory 14 of the first SCP node 10 include, but are not limited to, random access memory (RAM), read only memory (ROM), mass storage media such as hard disks, removable storage media such as compact discs (CDs) or digital video discs (DVDs), and / or any other memory.
[0041] The processing circuit 12 of the first SCP node 10 can be connected to the memory 14 of the first SCP node 10. In some embodiments, the memory 14 of the first SCP node 10 can be for storing program code or instructions that, when executed by the processing circuit 12 of the first SCP node 10, cause the first SCP node 10 to operate in the manner described herein with respect to the first SCP node 10. For example, in some embodiments, the memory 14 of the first SCP node 10 can be configured to store program code or instructions executable by the processing circuit 12 of the first SCP node 10 to operate the first SCP node 10 in accordance with the methods described herein with respect to the first SCP node 10. Alternatively or additionally, the memory 14 of the first SCP node 10 can be configured to store any of the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein. The processing circuit 12 of the first SCP node 10 can be configured to control the memory 14 of the first SCP node 10 to store the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein.
[0042] In some embodiments, as shown in FIG. 3, the first SCP node 10 may optionally have a communication interface 16. The communication interface 16 of the first SCP node 10 may be connected to the processing circuit 12 and / or the memory 14 of the first SCP node 10. The communication interface 16 of the first SCP node 10 may be operable to enable the processing circuit 12 of the first SCP node 10 to communicate with the memory 14 of the first SCP node 10 and / or vice versa. Similarly, the communication interface 16 of the first SCP node 10 may be operable to enable the processing circuit 12 of the first SCP node 10 to communicate with the first NF node and / or any other node. The communication interface 16 of the first SCP node 10 may be configured to transmit and / or receive the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein. In some embodiments, the processing circuit 12 of the first SCP node 10 may be configured to control the communication interface 16 of the first SCP node 10 to transmit and / or receive the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein.
[0043] Although the first SCP node 10 is shown in FIG. 3 as having a single memory 14, it will be understood that the first SCP node 10 may have at least one memory (i.e., a single memory or multiple memories) 14 that operates in the manner described herein. Similarly, although the first SCP node 10 is shown in FIG. 3 as having a single communication interface 16, it will be understood that the first SCP node 10 may have at least one communication interface (i.e., a single communication interface or multiple communication interfaces) 16 that operates in the manner described herein. Also, FIG. 3 shows only the components necessary to illustrate an embodiment of the first SCP node 10, and it will be understood that in an actual embodiment, the first SCP node 10 may have additional or alternative components to those shown.
[0044] FIG. 4 is a flowchart showing a method executed by the first SCP node 10 according to an embodiment. The first SCP node 10 is configured to operate as an SCP between a first NF node of a service consumer and a second NF node of a service producer in a network. The method is for processing service requests within the network. The first SCP node 10 described above with reference to FIG. 3 can be configured to operate according to the method of FIG. 4. The method can be executed by, or under the control of, the processing circuit 12 of the first SCP node 10.
[0045] The method of FIG. 4 is executed when a first request for a first service to be provided is received from the first NF node 20 (see block 102 of FIG. 4). The start of the transmission of the first request by the first NF node 20 will be described below with reference to FIG. 5. After receiving the first request, the first SCP node 10 obtains a service producer NF node (NFp) profile (see block 104). The NFp profile may be obtained from the NRF 60, and the first SCP node 10 can submit a discovery request to the NRF 60 and then receive a response including the NFp profile from the NRF 60. When a discovery request to the NRF 60 is used, this discovery request can use the discovery parameters included in the first request from the first NF node 20 and may include parameters from the first SCP node 10 based on the local configuration of the first SCP node 10. The obtained NFp profile can then be stored by the first SCP node 10. Alternatively, if a stored NFp profile is available, the first SCP node 10 can retrieve the stored NFp profile from a part of the first SCP node 10 or a connected storage device.
[0046] As shown in block 106, the first SCP node 10 also obtains one or more access tokens. The access tokens can be obtained from the NRF60 by submitting an access token request and receiving an access token response containing the access tokens. The access token request can include access token request parameters, and the access token request parameters can form part of the discovery parameters transmitted in a first request by the first NF node 20. The access token request parameters can include an encrypted token such as a client credential assertion from the first NF node 20. Using such an encrypted token, the first SCP node 10 may be able to obtain the access token on behalf of the first NF node 20. The obtained access token can then be stored by the first SCP node 10. The first SCP node 10 can also include in the access token request information not obtained from the discovery parameters, such as the range of one or more tokens requested, the granularity of the tokens requested, etc. Alternatively, if the stored access token is available, the first SCP node 10 can retrieve the access token stored from a storage device that is part of or connected to the first SCP node 10.
[0047] Next, the first SCP node 10 uses the obtained NFp profile and refers to the obtained access token to select one of the NFp nodes from which the profile has been obtained (see block 108). That is, the first SCP node 10 may prioritize the selection of the NFp node from which the access token has been obtained, or may select only the NFp nodes from which the access token has been obtained. Hereinafter, for ease of understanding, the selected NFp node may be referred to as the second NF node 30.
[0048] After selecting the NFp node (the second NF node 30), the first SCP node 10 starts transmitting to the second NF node 30 a request asking the second NF node 30 to provide the first service 40 to the first NF node 20, as shown in block 110 of FIG. 4. The request transmitted to the second NF node 30 is basically the same as the first request received by the first SCP node 10 from the first NF node 20, except that the SCP address is replaced with the address of the second NF node and the access token obtained by the first SCP node 10 is included in the request.
[0049] As used herein, the term "start" can mean, for example, causing or establishing. Thus, the processing circuit 12 of the first SCP node 10 can be configured to transmit information itself (e.g., via the communication interface 16 of the first SCP node 10) or to cause another node to transmit information. Similarly, when the first NF node 20 starts transmission, the first NF node 20 can be configured to transmit information itself (e.g., via the communication interface 26 of the first NF node 020) or to cause another node to transmit information.
[0050] Next, the first SCP node 10 receives a response to the request from the second NF node 30 (including the NF instance ID and potentially also the binding information if a binding is used) and starts transmitting this response to the first NF node 20 (see block 112). Upon receiving this response, the first NF node 20 can save information in an execution context, e.g., a UE / session context, as will be described in detail below.
[0051] The first SCP node 10 may be further configured to receive subsequent requests from the first NF node 20. The subsequent request is for the provision of a first service to the second NF node 30. As will be described in more detail below, the subsequent request may include access token request parameters that can be used by the first SCP node 10 to obtain a valid access token. If the first SCP node has a valid access token stored, this access token can be retrieved using the access token request parameters from the subsequent request. Alternatively, if the first SCP node does not have a stored valid access token (either because no valid token is stored or because a previously valid stored token has expired), the access token request parameters can be used, for example, to request a new access token from the NRF 60. If a valid access token has been obtained using the access token request parameters from the subsequent request, the first SCP node 10 can start transmitting the request for service provision to the second NF node 30. The request is basically the same as the subsequent request received by the first SCP node 10 from the first NF node 20, but the SCP address is replaced with the address of the second NF node 30 and the access token obtained by the first SCP node 10 is included in the request. When receiving a response from the second NF node 30, the first SCP node 10 can then start transmitting this response to the first NF node 20.
[0052] FIG. 5 shows a first NF node 20 according to an embodiment. The first NF node 20 is for processing service requests within a network. The first NF node 20 is configured to operate as a first NF node of a service consumer. In some embodiments, the first NF node 20 can be, for example, a physical machine (e.g., a server) or a virtual machine (VM). The first NF node 20 can be, for example, a user equipment (UE).
[0053] As shown in FIG. 5, the first NF node 20 has a processing circuit (or logic) 22. The processing circuit 22 controls the operation of the first NF node 20 and can implement the methods described herein with respect to the first NF node 20. The processing circuit 22 can be configured or programmed to control the first NF node 20 in the methods described herein. The processing circuit 22 can have one or more hardware components such as one or more processors, one or more processing units, one or more multi-core processors, and / or one or more modules. In certain embodiments, each of the one or more hardware components can be configured to perform, or be for performing, individual steps or multiple steps of the methods described herein with respect to the first NF node 20. In some embodiments, the processing circuit 22 can be configured to execute software to perform the methods described herein with respect to the first NF node 20. The software may be containerized according to some embodiments. Thus, in some embodiments, the processing circuit 22 can be configured to execute containers to perform the methods described herein with respect to the first NF node 20.
[0054] That is, the processing circuit 22 of the first NF node 20 is configured to start transmitting a first request to the first SCP node 10 for requesting the provision of a first service 40 by a further NF node (the further NF node is a service provider NF node). The first request has discovery parameters including an access token request parameter, and the discovery parameters facilitate the selection of a second NF node 30 as a service producer as a further NF node for providing the first service 40 by the first SCP node 10. In addition to including the access token request parameter in the discovery parameters, the access token request parameter may also be transmitted in a header separate from the discovery parameters, for example, an access token parameter header. In addition to starting the transmission of the first request, the processing circuit 22 of the first NF node 20 is configured to store the access token request parameter and also receive a response from the second NF node 30 (via the first SCP node 10). The processing circuit 22 of the first NF node 20 is also configured to start transmitting a second request to the first SCP node 10, and the second request is a subsequent request for the second NF node 30 to supply the first service 40. The second request has the stored access token request parameter that can be used to identify the stored access token or to request an access token (e.g., by the first SCP node 10).
[0055] As shown in FIG. 5, in some embodiments, the first NF node 20 may have a memory 24 as needed. The memory 24 of the first NF node 20 may have a volatile memory or a non-volatile memory. In some embodiments, the memory 24 of the first NF node 20 may have a non-transitory medium. Examples of the memory 24 of the first NF node 20 include, but are not limited to, random access memory (RAM), read-only memory (ROM), a mass storage medium such as a hard disk, a removable storage medium such as a compact disc (CD) or a digital video disc (DVD), and / or any other memory.
[0056] The processing circuit 22 of the first NF node 20 may be connected to the memory 24 of the first NF node 20. In some embodiments, the memory 24 of the first NF node 20 may be for storing program code or instructions that, when executed by the processing circuit 22 of the first NF node 20, cause the first NF node 20 to operate in the manner described herein with respect to the first NF node 20. For example, in some embodiments, the memory 24 of the first NF node 20 may be configured to store program code or instructions executable by the processing circuit 22 of the first NF node 20 to operate the first NF node 20 in accordance with the methods described herein with respect to the first NF node 20. Alternatively or additionally, the memory 24 of the first NF node 20 may be configured to store any of the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein. The processing circuit 22 of the first NF node 20 may be configured to control the memory 24 of the first NF node 20 to store the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein.
[0057] In some embodiments, as shown in FIG. 5, the first NF node 20 may optionally have a communication interface 26. The communication interface 26 of the first NF node 20 may be connected to the processing circuit 22 and / or the memory 24 of the first NF node 20. The communication interface 26 of the first NF node 20 may be operable to enable the processing circuit 22 of the first NF node 20 to communicate with the memory 24 of the first NF node 20 and / or vice versa. Similarly, the communication interface 26 of the first NF node 20 may be operable to enable the processing circuit 22 of the first NF node 20 to communicate with the first SCP node 10 and / or any other node. The communication interface 26 of the first NF node 20 may be configured to transmit and / or receive the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein. In some embodiments, the processing circuit 22 of the first NF node 20 may be configured to control the communication interface 26 of the first NF node 20 to transmit and / or receive the information, data, messages, requests, responses, instructions, notifications, signals, or the like described herein.
[0058] Although the first NF node 20 is shown in FIG. 5 as having a single memory 24, it will be understood that the first NF node 20 may have at least one memory (i.e., a single memory or multiple memories) 24 that operates in the manner described herein. Similarly, although the first NF node 20 is shown in FIG. 5 as having a single communication interface 26, it will be understood that the first NF node 20 may have at least one communication interface (i.e., a single communication interface or multiple communication interfaces) 26 that operates in the manner described herein. Also, FIG. 5 shows only the components necessary to illustrate an embodiment of the first NF node 20, and it will be understood that in an actual embodiment, the first NF node 20 may have additional or alternative components relative to what is shown.
[0059] FIG. 6 is a flowchart showing a method executed by a first NF node 20 according to an embodiment. The method of FIG. 6 is for processing service requests within a network. The first NF node 20 described above with reference to FIG. 5 is configured to operate according to the method of FIG. 6. The method can be executed by or under the control of the processing circuit 22 of the first NF node 20. The first SCP node 10 is configured to operate as an SCP between the first NF node 20 and a second NF node of a service producer within the network.
[0060] The method of FIG. 6 is executed to connect to a further NF node (such as a second NF node 40) of a service producer via the first SCP node 10. The first request relates to the provision of a first service (40) by the further NF node, and the transmission of this first request is initiated to the first SCP node 10 (see block 202). The first request has discovery parameters with access token request parameters, and the discovery parameters facilitate the selection of the second NF node 30 of the service producer as a further NF node for providing the first service 40 by the first SCP node 10. The access token request parameters are stored by the first NF node 10 (see block 204). The access token request parameters can have an encrypted token, such as a client credential assertion for the first NF node 20 (NF service consumer client credential assertion) or another type of encrypted token. Using such an encrypted token, the first SCP node 10 may be able to obtain an access token on behalf of the first NF node 20. If the first request includes an encrypted token, this can be stored as part of the access token request parameters.
[0061] The access token request parameters can be stored in the execution context of the first request, which can be the UE / session context, the protocol data unit (PDU) / session context, or another context. In particular, the access token request parameters can be stored in the UE data record. The access token request parameters can further have various other information such as a single network slice selection assistance information (S-NSSAI), a fully qualified domain name (FQDN). The discussion of the various parameters that can be included in the access token request is described in 3GPP TS 29.510 V 16.4.0, as cited above. In particular, section 6.3.5.2.2 of the cited document provides an overview of the relevant data types. The corresponding overview of the discovery data types is described in section 6.2.3.2.3.1 of the same cited document. When received by the first SCP node 10, the access token request parameters can potentially be used to obtain an access token in combination with further parameters such as range information that is not derived from the access token request parameters in the first request. The method further has receiving a response from the second NF node 30 via the first SCP node 10 (see block 206).
[0062] The method further comprises starting to send a second request to the first SCP node 10 (see block 208). The second request is a subsequent request for the provision of a first service, and the subsequent request relates to the first service provided by the second NF node 30. The second request includes at least a part of the stored access token request parameters included in the discovery parameters sent in the first request. The access token request parameters can be sent within a specific access token parameter header in the subsequent request. If the stored access token request parameters include an encrypted token (as described above), this encrypted token can be included in the second request. The access token request parameters in the second request can enable the first SCP node 10 to obtain a valid access token. A valid access token can be obtained by retrieving the stored access token or by requesting an access token (e.g., from the NRF 60). If the stored access token is retrieved, the access token parameters are used by the first SCP node 10 to find the stored access token. If a valid stored access token is not available because the stored access token is not available or the stored access token has expired (timed out), the access token parameters can be used to request a new access token from the NRF 60 using a process similar to the process used to obtain an access token for the first request. Using the obtained access token, the first SCP node 10 then sends a request to the second NF node 30 and receives a response passed to the first NF node 20. The rest is the same.
[0063] A system is also provided. The system can have at least one of the aforementioned first SCP nodes 10 and / or at least one of the aforementioned first NF nodes 20. The system can also have any one or more of the other nodes mentioned in this specification.
[0064] Figures 7A through 7C are signaling diagrams showing signal exchanges. The system shown in Figures 7A through 7C includes a first SCP node 10, a first NF node of a service consumer ("NFc") 20, a second NF node of a service producer ("NFp1") 30, and a third NF node of a service producer ("NFp2") 70. The first SCP node 10 is configured to operate as an SCP between the first NF node 20 and the second NF node 30. The second NF node 30 may be configured to provide (e.g., execute or perform) a service 40, and the third NF node 70 may be configured to provide (e.g., execute or perform) a service 80. The second NF node 30 and the third NF node 70 may be configured to provide (e.g., execute or perform) the same service or different services. The second NF node 30 and the third NF node 70 may be part of a set 402 of NF nodes of service producers. The system shown in Figures 2A through 2C also includes an NRF 60. In some embodiments, an entity may have the first SCP node 10 and the NRF 60. That is, in some embodiments, the first SCP node 10 may be integrated with the NRF 60 in a composite entity.
[0065] In some embodiments, the first SCP node 10 and the first NF node 20 may be arranged in independent placement units, and / or the first SCP node 10 and the second NF node 30 may be arranged in independent placement units. Thus, an SCP node based on an independent placement unit is possible, as described in 3GPP TS 23.501 v16.5.0 (cited above). In other embodiments, the first SCP node 10 may be arranged as a distributed network element. For example, in some embodiments, a part of the first SCP node 10 (e.g., a service agent) may be arranged in the same placement unit as the first NF node 20, and / or a part of the first SCP node 10 (e.g., a service agent) may be arranged in the same placement unit as the second NF node 30. Thus, an SCP node based on a service mesh is possible, as described in 3GPP TS 23.501 V16.5.0.
[0066] In some embodiments, at least one second SCP node may be configured to operate as an SCP between the first NF node 20 and the first SCP node 10, and / or at least one third SCP node may be configured to operate as an SCP between the first SCP node 10 and the second NF node 30. Thus, a multi-path of SCP nodes is possible. In some of these embodiments, the first SCP node 10 and one or both of at least one second SCP node and at least one third SCP node may be arranged in independent placement units. In some embodiments, at least one second SCP node and / or at least one third SCP node may be arranged as distributed network elements.
[0067] Steps 500, 504, 506, 508 from FIGS. 7A to 7C and 600 to 638 are as previously described with respect to FIGS. 2A to 2C. Some important differences between the example shown in FIGS. 2A to 2C and the embodiment of FIGS. 7A to 7C are as follows. In step 700, similar to step 602, the first NF node 20 saves a context (UE / session context, PDU / session context, etc.). Step 700 includes additionally saving access token request parameters that can be used by the first SCP node 10 to obtain an access token. As described above in the context of FIGS. 4 and 6, the access token request parameters can include an encrypted token, and if present, the encrypted token can also be saved in step 700. Next, in step 604, the access token request parameters can be sent (as part of the discovery parameters) to the first SCP node 10, and the processing of the first request proceeds as shown in FIGS. 2A to 2C. In step 632, the processing related to subsequent requests for the same service starts. The subsequent requests can be the second request, the third request, the fourth request, etc. In the embodiment shown in FIGS. 7A to 7C, binding is used, and thus, the client binding information provided to the first NF node 20 is included as routing binding information in step 634. As mentioned above, the use of binding is optional, and binding is not necessarily used. In step 702, subsequent service requests are sent to the first SCP node 10. However, since the access token request parameters are saved by the first NF node 20 in step 700, these parameters may also be included in the subsequent requests in step 702. In the embodiment shown in FIGS. 7A to 7C, an encrypted token (client credentials assertion in this example) is included as part of the access token request parameters.
[0068] The first SCP node 10 receives a subsequent request and, in step 638, attempts to find a valid access token. In the embodiments shown in FIGS. 2A through 2C, this attempt fails because the information contained in the subsequent request of arrow 636 does not provide a means to identify a valid token. The first SCP node in FIGS. 2A through 2C cannot even request an applicable token because the information required for the token request is not provided in the subsequent request of this example. In contrast, the access token request parameters contained in the subsequent request of the embodiment shown in FIGS. 7A through 7C enable the stored access token to be retrieved (e.g., from the memory of the first SCP node 10). In this embodiment, the S-NSSAI is required and is included in the access token request parameters. The stored access token is valid in this embodiment, but even if the stored access token is not valid (i.e., does not exist, has expired, or a different range of tokens is required), the access token request parameters contained in the subsequent request can be used by the first SCP node 10 to obtain a new access token from the NRF60. In some embodiments, the first SCP node 10 may be integrated with the NRF60, and thus the access token request parameters can be used to retrieve an access token from the NRF integrated with the first SCP node 10.
[0069] Since a valid access token can be obtained by the first SCP node 10, unlike the processes shown in FIGS. 2A to 2C, the subsequent request processing of the embodiments shown in FIGS. 7A to 7C does not fail. Instead, steps similar to those occurring in the first request are executed. As shown in block 704, the first SCP node 10 changes the address within the request (received from the first NF node 20) from the address of the first SCP node 10 to the host address of the second NF node 30. Next, as shown in step 706, any further tasks (such as monitoring) can be executed by the first SCP node 10. Next, in step 708, the first SCP node 10 begins transmitting a subsequent service request towards the selected second NF node 30. The service request has a valid access token obtained by the first SCP node 10 added to it. In step 710, the first SCP node 10 receives a response containing a result from the second NF node 30, and then, in step 712, this response is transmitted to the first NF node 20 and stored in the execution context (steps 714 and 716, in this embodiment the execution context is the UE / session context). Thus, as a result of including the access token request parameter in the subsequent service request, a valid access token, which is either the stored token or a new token, can be obtained and the request process will succeed.
[0070] FIG. 8 is a block diagram showing a first SCP node 10 according to an embodiment. The first SCP node 10 can process service requests within a network. The first SCP node 800 can operate as an SCP between a first NF node of a service consumer and a second NF node of a service producer within the network. The first SCP node 800 has a receiving module 802 configured to receive a first request requesting provision of a first service from the first NF node 20. The first SCP node 800 has an acquisition module 808 configured to acquire a service producer NF node profile and an access token. The first SCP node 800 also has a selection module 806 configured to select a producer NF node (such as the second NF node 30) using the acquired service producer NF node profile. The first SCP node 800 further has a transmission module 804 configured to start transmission of a request for service provision to the selected producer NF node. Here, the request includes the acquired access token. The receiving module is further configured to receive a response from the second NF node 30. The first SCP node 10 can operate as described herein with respect to any process executed by the first SCP node.
[0071] FIG. 9 is a block diagram showing a first NF node 20 of a service consumer according to an embodiment. The first NF node 20 can process service requests within the network and, in particular, can operate as the first NF node of the service consumer. The first NF node 20 has a transmission module 902 configured to initiate transmission of a first request for a first service provided by a further NF node, the first request being transmitted to the first SCP node 10. The first request has discovery parameters having an access token request parameter, the discovery parameters facilitating selection of a second NF node 30 of a service producer as a further NF node for providing the first service 40 by the first SCP node 10. The first NF node 20 also has a storage module 904 configured to store the access token request parameter, the access token request parameter being storable, for example, in an execution context. The first NF node 20 further has a reception module 906 configured to receive a response from the second NF node. The transmission module 902 is further configured to initiate transmission of a second request to the first SCP node 10, the second request being a subsequent request for the second NF node 30 to provide the first service 40, the second request having the stored access token request parameter usable to identify a stored access token or request an access token. The second request may request the second NF node 30 to provide the first service 40 in the same execution context as the first request (e.g., UE / session context or PDU / session context). The first NF node 20 can operate in the manner described herein with respect to any process executed by the first NF node.
[0072] When executed by a processing circuit (such as the processing circuit 12 of the aforementioned first SCP node 10 and / or the processing circuit 22 of the aforementioned first NF node 20), a computer program is also provided that has instructions for causing the processing circuit to execute at least a part of the method described herein. A computer program product embodied on a non-transitory machine-readable medium, which is executable by a processing circuit (such as the processing circuit 12 of the first SCP node 10 described above and / or the processing circuit 22 of the first NF node 20 described above), and has instructions for causing the processing circuit to execute at least a part of the method described herein, is provided. A computer program product having a medium that includes instructions for causing a processing circuit (such as the processing circuit 12 of the first SCP node 10 described above and / or the processing circuit 22 of the first NF node 20 described above) to execute at least a part of the method described herein is provided. In some embodiments, the medium may be any one of an electronic signal, an optical signal, an electromagnetic signal, an electrical signal, a wireless signal, a microwave signal, or a computer-readable storage medium.
[0073] Other embodiments include those defined by the following numbered descriptions.
[0074] A method for processing a service request within a network, the method being executed by a first network function (NF) node (20) of a service consumer to connect to a further NF node of a service producer via a first service communication proxy (SCP) node (10), the method comprising: starting (604) the transmission of a first request to the first SCP node (10) for a first service (40) provided by the further NF node, wherein the first request has discovery parameters having an access token request parameter, and the discovery parameters facilitate the selection by the first SCP node (10) of a second NF node (30) of the service producer as a further NF node for providing the first service (40), Storing the access token request parameters (700); Receiving a response from the second NF node (30) (628); Starting to send a second request to the first SCP node (10) (702), where the second request is a subsequent request for the second NF node (30) to provide the first service (40), and the second request has stored access token request parameters that can be used to identify the stored access token or request an access token.
[0075] Description 2 The method of Description 1, wherein the first request further has an encryption token for enabling the first SCP node (10) to obtain an access token on behalf of the first NF node (20); the encryption token is stored together with the access token request parameters; the second request has the encryption token.
[0076] Description 3 The method of Description 2, wherein the encryption token is an NF service consumer client credential assertion.
[0077] Description 4 The method of any of the preceding descriptions, wherein the second request requests the second NF node (30) to provide the first service (40) in the same execution context as the first request.
[0078] Description 5 The method of any of the preceding descriptions, wherein the storing of the access token request parameters is in a user equipment (UE) data record.
[0079] Description 6 The method of any of the preceding descriptions, wherein the access token request parameters have a single network slice selection assistance information (S-NSSAI).
[0080] A method according to any of the preceding descriptions, further comprising receiving, by the first SCP node (10), the first request (40) for requesting the provision of the first service (40) by the further NF node (604); obtaining a service producer NF node profile (606, 608); obtaining an access token using the access token parameter from the first request (612, 614); selecting the second NF node (30) using the obtained service producer NF node profile (618); starting to send a third request for requesting the provision of a service to the second NF node (30) to the second NF node (30) (624), where the third request includes the obtained access token; receiving a response from the second NF node (30) (626) and starting to send it to the first NF node (20) (628).
[0081] A method according to description 8, wherein the step of obtaining a service producer NF node profile comprises starting to send a fourth request using the discovery parameter from the first request for the service producer NF node profile to the network repository function (NRF) node (60) (606) and receiving a first response from the NRF node (608), or retrieving a stored service producer NF node profile.
[0082] A method according to any of descriptions 7 and 8, wherein the step of obtaining an access token comprises starting to send a fifth request using the access token request parameter from the first request for the access token to the NRF node (612) and receiving a second response from the NRF node (614), or retrieving the saved access token
[0083] Description 10 A method according to any one of Descriptions 7 to 9, further comprising, by the first SCP node (10), saving the service producer NF node profile (610), and / or saving the access token (616).
[0084] Description 11 A method according to any one of Descriptions 7 to 10, further comprising, by the first SCP node (10), receiving the second request, which is a subsequent request for providing the first service (40) to the second NF node (30) (702), obtaining a valid access token using the access token request parameter from the second message (638), starting to send a sixth request for providing a service to the second NF node (30), where the sixth request includes a valid access token (708), receiving a response from the second NF node (30) (710) and starting to send it to the first NF node (20) (712).
[0085] Description 12 A method according to any of the preceding descriptions, wherein the first SCP node (10) and the first NF node (20) are arranged in independent arrangement units, and / or wherein the first SCP node (10) and the second NF node (30) are arranged in independent arrangement units.
[0086] Description 13 A method according to any one of Descriptions 1 to 11, wherein the first SCP node (10) is arranged as a distributed network element.
[0087] Description 14 A method according to the method of Description 13, A part of the first SCP node (10) is arranged in the same arrangement unit as the first NF node (20), and / or A part of the first SCP node (10) is arranged in the same arrangement unit as the second NF node (30).
[0088] Description 15 The method according to any of the preceding descriptions, At least one second SCP node is configured to operate as an SCP between the first NF node (20) and the first SCP node (10), and / or At least one third SCP node is configured to operate as an SCP between the first SCP node (10) and the second NF node (30).
[0089] Description 16 The method according to Description 15, The first SCP node (10) and one or both of the at least one second SCP node and the at least one third SCP node are arranged in independent arrangement units.
[0090] Description 17 The method according to Description 15, The at least one second SCP node and / or the at least one third SCP node are arranged as distributed network elements.
[0091] Description 18 The method according to any of the preceding descriptions, An entity having the first SCP node (10) and the NRF node (60).
[0092] Description 19 The first NF node (20), having a processing circuit (22) configured to operate according to any of Descriptions 1 to 6.
[0093] Description 20 The first NF node (20) according to Description 19, wherein the first NF node (20) When executed by the processing circuit (22), it has at least one memory (24) for storing instructions that cause the first NF node (20) to operate according to any one of Descriptions 1 to 6.
[0094] Description 21 A system, having a first NF node (20) according to either of Descriptions 19 and 20, further having a first SCP node (10), the first SCP node (10) having a processing circuit (12) configured to operate according to any one of Descriptions 7 to 11.
[0095] Description 22 The system of Description 21, wherein the first SCP node (10) When executed by the processing circuit (12), it has at least one memory (14) for storing instructions that cause the first SCP node (10) to operate according to any one of Descriptions 7 to 11.
[0096] Description 23 A computer program having instructions that, when executed by a processing circuit, cause the processing circuit to execute a method according to any one of Descriptions 1 to 6 and / or any one of Descriptions 7 to 11.
[0097] Description 24 A computer program product embodied on a non - transitory machine - readable medium, the computer program product having instructions executable by the processing circuit to cause the processing circuit to execute a method according to any one of Descriptions 1 to 6 and / or any one of Descriptions 7 to 11.
[0098] In some embodiments, the first SCP node function and / or the first NF node function described herein may be executed by hardware. Accordingly, in some embodiments, any one or more of the first SCP node 10 and the first NF node 20 described herein may be a hardware node. However, it will also be understood that at least a part or all of the first SCP node function and / or the first NF node function described herein can be virtualized as necessary. For example, the functions executed by any one or more of the first SCP node 10 and the first NF node 20 described herein may be implemented by software executed on general-purpose hardware configured to compose the node functions. Accordingly, in some embodiments, any one or more of the first SCP node 10 and the first NF node 20 described herein may be a virtual node. In some embodiments, at least a part or all of the first SCP node function and / or the first NF node function described herein may be executed in a network-enabled cloud. The first SCP node function and / or the first NF node function described herein may all be in the same location, or at least a part of the node functions may be distributed.
[0099] It will be understood that at least some or all of the steps of the methods described herein may be automated in some embodiments. That is, in some embodiments, at least some or all of the steps of the methods described herein may be automatically executed. The methods described herein may be methods implemented by a computer.
[0100] Therefore, the method described in this specification advantageously provides an improved technique for processing service requests within a network. The first NF node 20 can store access token request parameters and include the stored parameters in subsequent service requests. Using the provided access token request parameters, the first SCP node 10 can retrieve a valid access token and proceed with subsequent service requests. Accordingly, system performance is improved.
[0101] Note that the above-described embodiments are illustrative rather than limiting ideas, and those skilled in the art can design many alternative embodiments within the scope of the appended claims. The term "comprising" does not exclude the existence of elements or steps other than those listed in the claims, "a" or "an" does not exclude a plurality, and a single processor or other unit can implement the functions of several units listed in the claims. Any reference signs in the claims should not be construed as limiting their scope.
Claims
1. A method for processing a service request in a network, the method being executed by a first Network Function (NF) node (20) of a service consumer to connect to a further NF node of a service producer via a first Service Communication Proxy (SCP) node (10), the method comprising the steps of: Initiating (604) the transmission of a first request to the first SCP node (10) for the provision of a first service (40) by the further NF node, where the first request includes discovery parameters and access token request parameters, the access token request parameters facilitating acquisition and storage of an access token by the first SCP node (10), and the discovery parameters facilitating selection by the first SCP node (10) of a second NF node (30) of a service producer as the further NF node for providing the first service (40) and forwarding of the first request by the first SCP node (10) to the second NF node (30); receiving (628) a response from the second NF node (30) forwarded by the first SCP node (10); and initiating (702) the transmission of a second request to the first SCP node (10); the second request is a subsequent request to the second NF node (30) to provide the first service (40), the second request having the access token request parameters, the access token request parameters being used by the first SCP node (10) to retrieve a stored access token or to obtain a new access token, and being included in the second request before the first SCP node (10) forwards the second request to the second NF node (30).
2. the first request further comprises a cryptographic token for enabling the first SCP node (10) to obtain an access token on behalf of the first NF node (20); The encrypted token is stored with the access token request parameters; The method of claim 1 , wherein the second request includes the encrypted token.
3. The method of claim 2 , wherein the cryptographic token is a NF service consumer client credential assertion.
4. 4. The method of claim 1, wherein the second request is for the second NF node (30) to provide the first service (40) in the same execution context as the first request.
5. The method according to any one of claims 1 to 4, wherein the access token request parameters are stored (700) in a user equipment (UE) data record.
6. The method according to claim 1 , wherein the access token request parameters include a single network slice selection assistance information (S-NSSAI).
7. Furthermore, the first SCP node (10) receiving (604) the first request (40) for provision of a first service (40) by the further NF node; Obtaining a service producer NF node profile (606, 608); obtaining an access token using the access token request parameters from the first request (612, 614); selecting (618) the second NF node (30) using the obtained service producer NF node profile; Initiating (624) the transmission of a third request to the second NF node (30) for the provision of a service from the second NF node (30), where the third request includes the obtained access token; receiving (626) a response from the second NF node (30); and initiating (628) a transmission to the first NF node (20); 7. The method according to claim 1 , comprising the steps of:
8. obtaining the service producer NF node profile, Initiating (606) the transmission of a fourth request using the discovery parameters from the first request to a Network Repository Function (NRF) node (60) for a service producer NF node profile and receiving (608) a first response from the NRF node (60); or Retrieving a stored service producer NF node profile; 8. The method of claim 7, comprising:
9. Obtaining the access token Initiating (612) a fifth request for an access token to an NRF node using the access token request parameters from the first request and receiving (614) a second response from the NRF node; or Retrieving a stored access token, 9. The method according to claim 7, wherein
10. Furthermore, the first SCP node (10) storing (610) the service producer NF node profile; and / or storing (616) the access token; and 10. The method according to claim 7, comprising the steps of:
11. Furthermore, the first SCP node (10) receiving (702) the second request, the second request being a subsequent request for the second NF node (30) to provide the first service (40); obtaining a valid access token using the access token request parameters from the second request (638); and initiating (708) the transmission of a sixth request for provision of service to the second NF node (30), where the sixth request includes a valid access token; receiving (710) a response from the second NF node (30) and initiating (712) a transmission to the first NF node (20); 11. The method according to claim 7, comprising the steps of:
12. 12. The method according to claim 1, further comprising, if the stored token has expired, obtaining, by the first SCP node (10), the new access token from a Network Repository Function (NRF) node.
13. A first NF node (20), A first NF node (20) having processing circuitry (22) configured to operate in accordance with the method of any one of claims 1 to 6.
14. The first NF node (20), 14. The first NF node (20) of claim 13, comprising at least one memory (24) for storing instructions that, when executed by the processing circuitry (22), cause the first NF node (20) to operate according to a method according to any one of claims 1 to 6.
15. 1. A system comprising: A first NF node (20) according to claim 13 or 14; a first SCP node (10), said first SCP node (10) having a processing circuit (12) configured to operate according to the method of any one of claims 7 to 12, system.
16. The first SCP node (10), 16. The system of claim 15, comprising at least one memory (14) for storing instructions that, when executed by the processing circuit (12), cause the first SCP node (10) to operate according to a method according to any one of claims 7 to 12.
17. A computer program comprising instructions which, when executed by a processing circuit, cause the processing circuit to carry out a method according to any one of claims 1 to 6 and / or any one of claims 7 to 12.
18. A machine-readable medium having stored thereon a computer program having instructions executable by a processing circuit to cause said processing circuit to perform a method according to any one of claims 1 to 6 and / or any one of claims 7 to 12.