Handling user equipment identification information
The method dynamically provisions AF-specific external user and group identifiers by extending UDM subscription data and using NEF, SMF, and BSF services to overcome NAT challenges, ensuring accurate AF interactions in 5G systems.
Patent Information
- Application Number
- JP2024506946
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-06
- Filing Date
- 2022-07-29
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-07-29
AI Technical Summary
Existing 5G communication systems face challenges in dynamically provisioning application function (AF)-specific external user and user group identifiers due to network address translation (NAT) affecting the accuracy of AF interactions with the 5G core network, particularly when identifying specific subscribers or groups, and existing solutions do not adequately address this issue.
A method and apparatus are provided to dynamically provision AF-specific external user and user group identifiers by extending the UDM subscription data to include external UE IDs and group identifiers, leveraging the NEF to convert addresses pre- and post-NAT, and using the SMF or BSF services to obtain SUPIs, even in scenarios without PCF/BSF deployment, ensuring AFs receive accurate identifiers.
Enables accurate identification of subscribers and groups by AFs, supporting scenarios with and without PCF/BSF deployment, and addressing network address translation, thereby enhancing AF interactions with the 5G core network.
Smart Images

Figure 0007710601000011 
Figure 0007710601000012 
Figure 0007710601000013
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to wireless communication. More particularly, aspects of the present disclosure relate to, in particular, the dynamic provisioning of application function specific external user and user group identifiers for public services. These aspects may be implemented as methods, computer program products, apparatuses, and systems, and in particular, may be implemented in 4th generation (4G) and 5th generation (5G) networks.
Background Art
[0002] The 3rd Generation Partnership Project (3GPP) is developing technical specifications (TS) for 5G communication systems. 3GPP TS23.501 V17.1.1 (2021-06) defines the architectural aspects of the 5G service-based architecture (SBA), and the procedures are described in TS23.502 V17.1.0 (2021-06). According to this SBA, network functions (NFs) use service-based interactions to consume services from other NFs. The discovery of services and the NFs that create those services are provided by the Network Repository Function (NRF).
[0003] A 5G architecture with service-based interfaces can be referenced in FIG. 1.
[0004] FIG. 1 shows a block diagram of a wireless communication network 100 according to an example described herein. In this example, the 5G network architecture may relate to a non-roaming architecture.
[0005] Having service-based interfaces in the 5G core control plane (CP) implies that NFs in the 5G core CP provide services consumed by other NFs in the 5G core CP.
[0006] Part of the 5G reference architecture is defined by 3GPP. Some architecture core network entities (network functions (NFs)) and core network interfaces for examples of the present disclosure may include the following. 1) User Equipment (UE) 102 as an exemplary terminal device. UE 102 constitutes an endpoint of a Voice over IP call or an endpoint of a video or audio streaming session that extends through an Access Network Domain (AND), for example, via a (Radio) Access Network ((R)AN) 104. 2) Application Function (AF) 126, located outside the Core Network Domain (CND) and generally operated by a dedicated service provisioning entity (e.g., an Over The Top (OTT) entity) or implemented on such an application server. AF 126 is configured to interact with the CND via the Naf interface. Generally, the AF interacts with the 3GPP core network to provide or consume services. The functions and purposes of the AF are defined only in the specifications regarding the interaction of the AF with the 3GPP core network. As an example, the AF can be part of an application server or interact with the core network on behalf of an (one or more) application server. 3) The Network Exposure Function (NEF) 118 has an Nnef interface and supports different functions. Specifically, in the context of some of the examples outlined in this specification, the NEF 118 can act as an entry point to the CND for the AF 126. Thus, the AF 126 interacts with the CND through the NEF 118. The NEF is also an entry point for an Application Service Provider (ASP) to a Mobile Network Operator (MNO), also known as a Connectivity Service Provider (CSP). The NEF exposes mobile network capabilities and events to the ASP as a service on the Service Based Interface (SBI). In particular, the NEF complements information provided by external Application Functions (AFs), permits AF requests, and converts internal-external information. The AF can be deployed by either the operator or a third party. 4) The Session Management Function (SMF) 114 has an N4 interface and an Nsmf interface. The SMF 114 supports procedures such as session establishment, modification, and release, as well as policy-related functions. In particular, the SMF 114 configures the User Plane Function (UPF) 106 (for example, for event reporting). Generally, the SMF serves, among other things, to select and control UPF entities. Moreover, in some examples, the SMF 114 thus uses Packet Forwarding Control Protocol (PFCP) procedures to configure the UPF 106 through the N4 interface. 5) The Binding Support Function (BSF) is used to find the PCF responsible for the user protocol data unit (PDU) session policy session in scenarios involving two or more Policy Control Functions (PCF). 6) The User Plane Function (UPF) 106 has an N4 interface to the SMF 114 and an N3 interface to the (R)AN 104. The UPF 106 supports handling user plane traffic on the user plane (UP) based on rules received from the SMF 114 in the control plane (CP). In particular, in the example outlined herein, the UPF 106 thus supports packet inspection and different enforcement actions (such as event detection and reporting). 7) The Policy Control Function (PCF) 122 supports an integrated policy framework for governing (core) network (domain) behavior via the Npcf interface. Specifically, the PCF 122 provides policy and charging control (PCC) rules to the SMF 114 and / or the UPF 106, for example, to detect service traffic and perform policy and charging decisions according to the PCC rules. The PCF is an optional entity in the 5G core. 8) The Unified Data Management (UDM) entity 124 centrally stores data (such as subscriber information) in the core network domain. The UDM particularly performs subscription management and user identification information handling. To provide this function, the UDM uses subscription data (including authentication data) that can be stored in a user data repository, in which case the UDM implements application logic and does not require an internal user data storage area. 9) The Access and Mobility Management Function (AMF) 112 handles access and mobility for the UE 102. 10) The Network Repository Function (NRF) 120 is provided in the radio communication network 100. The NRF particularly supports the following functions. - The NRF supports a service discovery function. The NRF can receive NF discovery requests from NF instances and provide information on the discovered NF instances. - Further, the NRF may maintain an NF profile of available NF instances and the services supported by those NF instances. 11) The Network Slice Selection Function (NSSF) 116 may support selecting a set of network slice instances serving the UE 102. Further, the NSSF 116 may determine a set of AMF 112 to be used for serving the UE 102, possibly by querying the NRF 120, or determine a list of candidate AMFs based on a configuration. 12) The Authentication Server Function (AUSF) 110 supports authentication for 3GPP access and non-trusted non-3GPP access as specified in TS 33.501. The AUSF 110 may further support network slice specific authentication and authorization as specified in TS 23.502. 13) The Data Network (DN) 108 is coupled to the UPF 106 via the interface N6. The DN 108 may be related to, for example, operator services, Internet access, or third-party services.
[0007] The PCF and BSF are conditional 5GC NFs that may or may not be deployed, conditional on the services supported by the network. As an example, Voice over Long-Term Evolution (VoLTE) requires the PCF and BSF to be deployed.
[0008] In the establishment of a user PDU session, when the SMF that manages the user PDU session establishes a policy association with the PCF, the PCF registers the PDU session at the BSF. For this purpose, the PCF uses the service operation Nbsf_Management_Register, which requires a UE address, which may be an IP address / prefix or a MAC address as defined in TS23.501 V17.1.1 (2021-06) in that case. A Subscription Permanent Identifier (SUPI) may also be included (see TS23.502 referred to above for details).
[0009] Further functions and associations between entities provided in the radio communication network 100 can be found, for example, in 3GPP TS23.501 V17.1.1 (2021-06).
[0010] Application Service Provider (ASP)-Connectivity Service Provider (CSP) joint solution 3GPP has specified services for exposing different network capabilities to applications. The AF is an NF that interacts with the 3GPP core network to consume these services. The AF is not made possible by the operator to directly access the NF that provides those services. The AF shall use an external exposure framework (see section 7.3 in 3GPP TS23.501 V17.1.1 (2021-06)) and interact with the relevant NF via the NEF.
[0011] A complete list of services for which the AF and the NEF interact can be found in 3GPP TS23.501 V17.1.1 (2021-06) and TS23.502 V17.1.0 (2021-06).
[0012] AF requests the NEF for a specific user PDU session service flow or application, user, or group of users. Alternatively, it may not be related to one or more specific users but may be applicable to a certain DN, slice, or all CSP users. Service specifications specify the input parameters for each service operation (see TS23.502 V17.1.0 (2021-06)). The identifiers that can be used to specify the target of the request may vary during the service operation. Examples of identifiers used are the user Internet Protocol (IP) or Media Access Control (MAC) address (e.g., when it refers to a certain PDU session), the Globally Public Subscription Identifier (GPSI) (e.g., for referring to a subscriber), or an external group identifier (for referring to a group of subscribers).
[0013] The assumption is that the AF has visibility of the user service connection and thus the IP / MAC addresses and can include them as identifiers when the AF is related to the PDU session in which the request is in progress.
[0014] 5G System (5GS) Identifiers TS23.502 V17.1.0 (2021-06) and TS23.003 V17.2.0 (2021-06) specify some of the identifiers used in the 5GS, among which the following are specified. - The SUPI is the Global Unique 5G Subscription Permanent Identifier (SUPI), which is assigned to each subscriber in the 5G system and is to be provisioned in the UDM / UDR. The SUPI is used only within the 3GPP system. - GPSI is required to handle 3GPP subscriptions in different data networks external to the 3GPP system. The 3GPP system stores the association between the GPSI and the corresponding SUPI in the subscription data. The GPSI is a public identifier used both inside and outside the 3GPP system. The GPSI is either a Mobile Station Integrated Services Digital Network Number (MSISDN) or an external identifier, see TS23.003 V17.2.0 (2021-06). - The external identifier identifies a subscription associated with the International Mobile Subscriber Identity (IMSI). A subscription associated with an IMSI may have one or several external identifiers. The identifier is globally unique. - The internal group identifier is network-internal globally unique identification information that identifies a set of SUPIs from a given network (e.g., Machine-Type Communication (MTC) devices). The subscription data for a UE in the UDR may associate the subscriber with a group. If a UE can belong to a limited number of groups, the exact number is specified in the stage 3 specifications. - The external group identifier identifies a group consisting of one or more subscriptions associated with a group of IMSIs. The identifier is globally unique.
[0015] Network Address Translation Network Address Translation (NAT) is a way to remap one IP address space to another by modifying the network address information in the IP header of a packet while the packet is passing through a traffic routing device. NAT has become a prevalent and essential tool in preserving the global address space despite IPv4 address exhaustion.
[0016] Most of the Internet traffic uses the Transmission Control Protocol (TCP) or the User Datagram Protocol (UDP). In these protocols, the port numbers are changed so that the combination of the IP address and port information for the returned packets can be clearly mapped to the corresponding mobile core network destination. RFC2663 uses the term Network Address and Port Translation (NAPT) for this type of NAT. This is the most common type of NAT and is synonymous with the term "NAT" in common usage.
[0017] NAT is deployed on the N6 interface. Therefore, the source addresses and ports of the packets moving from the 5G Core (5GC) to the DN will be modified, and the destination addresses and ports of the packets moving from the DN and back will be modified. In that scenario, the source IP address extracted by the application server from the user data packets is not the same as the source IP address known to the mobile core, which affects the AF interaction with the 5GC.
[0018] This problem has been recognized in the 3GPP specifications and is being addressed, for example, as outlined in US Patent Application Publication No. 2014 / 0325091 (A1). In these solutions, the information on the IP address and port translation implemented by the NAT function is shared directly, upon request, via some other node, with the Policy Controller (PCF, or Policy and Charging Rules Function (PCRF)) and the BSF. The relationship between the address / port after NAT and the address / port before NAT can be used to resolve the first one to the second one when it is included during the service request by the AF.
[0019] The most advanced NAT supports mechanisms such as Internet Protocol Flow Information Export (IPFIX) to export data. Internet Protocol Flow Information Export, also known as IPFIX, is an extended version of NetFlow v9 standardized by the Internet Engineering Task Force (IETF). It supports variable-length fields such as Hypertext Transfer Protocol (HTTP) host names or HTTP Uniform Resource Locators (URLs), as well as enterprise-defined fields. IPFIX enables the collection and analysis of flow data from Layer 3 devices and firewalls using an IPFIX collector and an IPFIX analyzer.
[0020] When the AF consumes a service that requires identifying a specific subscriber or group of subscribers in the interaction between the AF and the NEF, the AF needs to be provisioned with identifiers that can be used externally, which are the GPSI and the external group identifier.
[0021] Several solutions have been discussed in 3GPP as part of the SA Working Group (WG) 2 meeting #143e regarding how the AF should define a service to obtain an identifier for a subscription from the user IP address, i.e., it has been proposed to update the existing NEF API and a BSF-centric solution has been proposed. At that time, no decision was made, but questions regarding that topic were sent to SA WG3 (Security). SA WG3 states that using the MSISDN as the GPSI causes security issues and that it is not a valid option.
Summary of the Invention
[0022] Therefore, it is necessary to address the above.
[0023] According to a first aspect, a method is provided that is executed by a first network entity in a core network domain (CND) of a wireless communication network. The method includes receiving, by the first network entity, a request from a second entity to obtain user equipment (UE) identification information. In response to the request, the first network entity sends a request to a third network entity in the CND to obtain from the third network entity UE identification information that is specific to the second entity. The first network entity receives, from the third network entity, UE identification information that is specific to the second entity. The first network entity sends the UE identification information that is specific to the second entity to the second entity.
[0024] In a second aspect of the present disclosure, a method in a wireless communication network is provided that includes a first network entity in a CND of the wireless communication network and a second entity. The method is executed by the second entity. The method includes sending, by the second entity, a request to the first network entity to obtain user equipment (UE) identification information that is specific to the second entity. The second entity receives, from the first network entity, UE identification information that is specific to the second entity.
[0025] In a third aspect of the present disclosure, a method is provided that is performed by a network entity in a core network domain (CND) of a wireless communication network. The method includes generating a modified version of one or both of external user equipment (UE) identification information and an external group identifier using an application service provider identifier, wherein the external UE identification information identifies a subscription for the UE and the external group identifier refers to one or more subscriptions. The method further includes generating a token for the modified version of one or both of the external UE identification information and the external group identifier.
[0026] A computer program product is also provided that includes a program code portion for configuring a processor to perform the method according to any one of the first to third aspects when executed on at least one processor. The computer program product can be stored on a computer-readable recording medium or encoded in a data signal.
[0027] Further, an apparatus adapted to operate in a CND of a wireless communication network is provided. The apparatus is configured to receive a request from a second entity to obtain user equipment (UE) identification information. In response to the request, the apparatus is configured to send a request to a third network entity in the CND to obtain UE identification information specific to the second entity from the third network entity. The apparatus is further configured to receive, from the third network entity, UE identification information specific to the second entity. The apparatus is further configured to send, to the second entity, UE identification information specific to the second entity.
[0028] The apparatus described above can be configured to implement the method of the first method aspect and any (preferred) exemplary implementation thereof outlined throughout the present disclosure.
[0029] A further apparatus adapted to operate in a wireless communication network is provided. The apparatus is configured to send a request to a first network entity in the CND of the wireless communication network to obtain user equipment (UE) identification information that is unique to the apparatus. The apparatus is further configured to receive, from the first network entity, UE identification information that is unique to the apparatus. The apparatus may be configured to implement the method of the second method aspect and any (preferred) exemplary implementation thereof as outlined throughout the present disclosure.
[0030] A further apparatus adapted to operate in a wireless communication network is provided. The apparatus is configured to use an application service provider identifier to generate a modified version of one or both of external user equipment (UE) identification information and an external group identifier. The external UE identification information identifies a subscription for the UE, and the external group identifier refers to one or more subscriptions. The apparatus is further configured to generate a token for the modified version of one or both of the external UE identification information and the external group identifier. The apparatus may be configured to implement the method of the third method aspect and any (preferred) exemplary implementation thereof as outlined throughout the present disclosure.
[0031] The system presented herein comprises any two or more of the apparatuses described above.
[0032] Further aspects, details and advantages of the present disclosure will become apparent from the following detailed description of the exemplary embodiments and from the drawings.
Brief Description of the Drawings
[0033]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
DETAILED DESCRIPTION OF THE INVENTION
[0034] In the following description, for purposes of illustration and not limitation, specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be apparent to those skilled in the art that the present disclosure may be practiced in other embodiments that depart from these specific details.
[0035] For example, the following description focuses on an exemplary network configuration according to 5G specifications, but the present disclosure is not limited thereto throughout. The present disclosure may also be implemented in other cellular or non-cellular wireless communication networks, for example, those compliant with 4th generation (4G) specifications (e.g., according to the Long Term Evolution (LTE) specifications standardized by the 3rd Generation Partnership Project (3GPP)).
[0036] Furthermore, those skilled in the art will appreciate that the steps, services, and functions described herein can be implemented using individual hardware circuits, software operating in conjunction with a programmed microprocessor or general-purpose computer, one or more application-specific integrated circuits (ASICs), and / or one or more digital signal processors (DSPs). When the present disclosure is described in terms of a method, it can also be embodied in one or more processors and one or more memories coupled to the one or more processors, where the one or more memories store one or more computer programs that, when executed by the one or more processors, implement the steps, services, and functions disclosed herein.
[0037] In the following description of exemplary implementations, the same reference numerals denote the same or similar components.
[0038] The following is a detailed description of a solution for the dynamic provisioning of AF-specific external user and user group identifiers for public services. The solution enables the AF to be provisioned with a specific UE ID represented by an external identifier defined in TS23.003 V17.2.0 (2021-06) and, if required, an external group identifier for the UE, also AF-specific, defined in TS23.003 V17.2.0 (2021-06).
[0039] Note that after obtaining the AF-specific UE ID or external group identifier, the AF can invoke NEF-provided services (such as location monitoring).
[0040] FIG. 2 shows a flowchart of method 200 for obtaining an AF-specific UE ID.
[0041] In step S201 (step 1), AF 126 requests to obtain the UE ID via the Nnef_UeId_Get service operation. The request message may include a UE address, which may be a UE IP address and / or a MAC address. The request may include an AF identifier, which is an AF service identifier and / or may include MTC provider information. The request includes, in this example, an application port ID (client and server) and an IP domain.
[0042] Note that MTC provider information can be used by any type of service provider (MTC or non-MTC) or company or external party, for example, to distinguish their different customers.
[0043] In this example, NEF 118 receives NAT information. For example, NEF 118 incorporates an IPFIX collector, obtains NAT export data, and NEF 118 uses that data to convert the UE IP address and application port (client side) after NAT (input parameters in the AF request) to the UE IP address before NAT. The NEF uses the converted address in requests to 5GC NFs.
[0044] The AF request may include an indicator for requesting an external group identifier for the UE.
[0045] In step S202 (step 2), NEF 118 permits the AF request. If permission is not granted, NEF 118 replies to AF 126 with a result value indicating permission failure. In other cases, NEF 118 proceeds to the following steps.
[0046] NEF 118 adds the AF service ID or MTC provider ID if it is missing.
[0047] Step S203a (Step 3a) and Step 204a (Step 4a) relate to an example where the PCF 122 / BSF 202 is deployed. In this case, the NEF 118 uses the UE address and IP domain in the Nbsf_Management_Discovery service operation to obtain the UE's session binding information. If the SUPI is not received in the session binding information from the BSF, the NEF 118 returns to the AF 126 a result value indicating that the UE ID is not available.
[0048] Step S203b (Step 3b) and Step 204b (Step 4b) relate to an example where the PCF 122 / BSF 202 is not deployed. In this case, the NEF 118 identifies the SMF 114 that owns the IP address based on the configuration and uses a new service operation, for example, called Nsmf_PDUSession_Get, to obtain the subscriber's SUPI from the SMF 114.
[0049] The Nsmf_PDUSession_Get input parameters include, in this example, the UE address (IP address and / or MAC address), the IP domain, the DNN, and the S-NSSAI, and the output parameter includes the SUPI.
[0050] In Step S205 (Step 5), the NEF 118 interacts with the UDM 124 to obtain the AF-specific UE ID via the Nudm_SDM_Get service operation. The request message includes the SUPI.
[0051] The request to the UDM 124 includes, in this example, at least one of the application port ID, the MTC provider information, and the AF service identifier as input parameters.
[0052] The request to the UDM 124 may include a UE group ID indication to indicate that the AF-specific UE group ID is also requested as an input parameter.
[0053] It should be noted that NEF118 can check the provided MTC provider information and override it to the NEF selection MTC provider information based on the settings. If NEF118 does not exist, how to determine the MTC provider information can be left to the implementation form in some examples (for example, based on the requesting AF).
[0054] In step S206 (step 6), UDM124 responds to NEF118 with the external identifier for the UE associated with the application port ID and / or MTC provider information and / or AF service identifier and (if required) the external group identifier.
[0055] Tables 1 and 2 shown below describe possible implementations of extensions for providing the data required in the Nudm_SDM_Get service operation. - The identifier conversion subscription data type field can be extended to include an optional external group identifier (Table 1). - MTC provider information and / or AF service identifier are added as data sub-keys for identifier conversion (Table 2). TIFF0007710601000001.tif255165TIFF0007710601000002.tif255164TIFF0007710601000003.tif255165TIFF0007710601000004.tif255164TIFF0007710601000005.tif255164TIFF0007710601000006.tif255164TIFF0007710601000007.tif255165TIFF0007710601000008.tif255165TIFF0007710601000009.tif152170 TIFF0007710601000010.tif166170
[0056] In step S207 (step 7), NEF118 further responds to AF126 with the information received from UDM124.
[0057] The solution needs to extend the UDM data management for subscribers and groups to support external UE IDs and external group identifiers that may be specific to an application, AF service, or MTC provider according to the selected granularity level. The granularity of these identifiers needs to be agreed upon with the Application Service Provider (ASP), for example, when a new MTC provider is onboarded.
[0058] The external UE IDs and group identifiers are then provisioned in the UDM for all subscribers and subscriber groups that may need them, and with the granularity agreed upon with each ASP. - In onboarding (depending on the granularity, when an application, AF service, or MTC provider is onboarded): for all subscribers and groups defined in the UDM, and whenever a new subscriber or subscriber group id is added in the UDM that may need them. - When a permitted request for external identification information about the SUPI is received in the UDM, in response to the requirements for subscribers and groups when associated with that SUPI. The external UE IDs and group identifiers can be generated at that instant and stored for future requests (i.e., the external UE IDs and group identifiers can be provisioned dynamically in the UDM).
[0059] There may be logic in the UDM or in a support function to generate the external UE IDs and group identifiers that need to be provisioned in the UDM, such that those external UE IDs and group identifiers are unique within the 5GC and may not be correlatable to one SUPI by different applications, AF services, or MTC providers.
[0060] Figure 3 shows a flowchart of method 300 according to some examples of the present disclosure.
[0061] (which may correspond to step S201) In step S302, the first network entity receives a request from the second entity to obtain UE identification information.
[0062] (which may correspond to step S205) In step S304, the first network entity sends a request to the third network entity in the CND to obtain from the third network entity the UE identification information unique to the second entity in response to the request.
[0063] (which may correspond to step S206) In step S306, the first network entity receives from the third network entity the UE identification information unique to the second entity.
[0064] (which may correspond to step S207) In step S308, the first network entity sends to the second entity the UE identification information unique to the second entity.
[0065] Figure 4 shows a flowchart of method 400 according to some examples of the present disclosure.
[0066] (which may correspond to step S201) In step S402, the second entity sends a request to the first network entity to obtain the UE identification information unique to the second entity.
[0067] (which may correspond to step S207) In step S404, the second entity receives from the first network entity the UE identification information unique to the second entity.
[0068] FIG. 5 shows a flowchart of a method 500 according to some examples of the present disclosure. In some examples, the method 500 may be implemented in the method 200 and may be performed by the UDM 124.
[0069] In step S502, the network entity generates a modified version of one or both of the external user equipment (UE) identification information and the external group identifier using the application service provider identifier. The external UE identification information identifies a subscription for the UE, and the external group identifier refers to one or more subscriptions. The modified version may be generated, for example, by a pre-set mapping, an automatic or algorithmic modification, etc.
[0070] In step S504, the network entity generates a token for the modified version of one or both of the external UE identification information and the external group identifier. The token may be generated by any tokenization technique, such as those used for data security, or by any other means for generating non-sensitive elements (tokens).
[0071] In some examples, the mapping between the SUPI and the external identifier is stored in an entity (such as the UDM). In some examples, the format of the sensitive data and the format of the tokenized data may be aligned, and the definition of the external identifier may still be reused even when they are tokenized to be application function specific.
[0072] In some examples, for the subscriber SUPI, a decorated (modified) version of the SUPI is generated using the ASP identifier that can still fit within the SUPI format, and then a token for that version is generated using a tokenization algorithm.
[0073] FIG. 6 is a block diagram of a system 600 according to some examples of the present disclosure.
[0074] In this example, the system includes device 602, device 612, and device 622.
[0075] In this example, device 602 includes processor 604, memory 606, input interface 608, and output interface 610.
[0076] Device 602 is adapted to operate in the CND of the wireless communication network 100. Device 602 is configured to receive a request from a second entity to obtain user equipment (UE) identification information. Further, device 602 is configured to send a request to a third network entity in the CND to obtain UE identification information unique to the second entity from the third network entity in response to the request. Device 602 is further configured to receive UE identification information unique to the second entity from the third network entity and send the UE identification information unique to the second entity to the second entity.
[0077] In this example, device 612 includes processor 614, memory 616, input interface 618, and output interface 620.
[0078] Device 612 is adapted to operate in the wireless communication network 100. The device is configured to send a request to a first network entity in the CND of the wireless communication network to obtain user equipment (UE) identification information unique to device 612. Device 612 is further configured to receive the UE identification information unique to this device from the first network entity.
[0079] In this example, device 622 includes processor 624, memory 626, input interface 628, and output interface 630.
[0080] The apparatus 622 is adapted to operate in the wireless communication network 100. The apparatus 622 is configured to use an application service provider identifier to generate a modified version of one or both of external user equipment (UE) identification information and an external group identifier. The external UE identification information identifies a subscription for the UE, and the external group identifier refers to one or more subscriptions. The apparatus 622 is further configured to generate a token for a modified version of one or both of the external UE identification information and the external group identifier.
[0081] In the prior art, a solution for provisioning an external identifier compliant with 3GPP TSG-WG SA2 meeting #143E e-meeting, S2-2101307 to the AF has not been described. The prior art claims to address the NAT scenario, but neither specifies how nor prepares for it.
[0082] The present disclosure addresses, among other things, non-IP PDU sessions (i.e., when the AF provides a MAC address and does not provide a UE IP address). The present disclosure may also solve scenarios where the AF needs to be provisioned with an external group identifier. The present disclosure further provides a BSF-based solution taking into account that the PCF / BSF is an optional NF in the network and may not be deployed. The present disclosure further does not assume that the BSF has returned a GPSI and solves the provisioning of an external identifier that should be AF-specific.
[0083] According to an example of the present disclosure, the NEF provides a new service for the AF to be provisioned with external subscriber and / or subscriber group identifiers that the AF may need in its interaction with the 3GPP core network in many services.
[0084] The AF may provide, as input, the following. - Type of request: Whether GPSI is requested, whether an external group identifier is requested, or both are requested - UE IP address and port on both the client side and the server side for an IP type PDU session, and UE MAC address for a non-IP Ethernet type PDU session - ASP identifiers with different granularity levels such that the 5GC can provide an external identifier unique to the requesting side. Those ASP identifiers may include one or more of an application port ID, an AF service identifier, and MTC provider information
[0085] To provide the above services by the 5GC network, the solutions presented in this document may do the following - Extend the UDM subscription data using the AF service identifier, application port ID, and subscriber GPSI for each MTC provider, and extend the UDM subscriber group data using the AF service identifier, application port ID, and external group identifier for each MTC provider - Enhance the UDM service so that the NEF can request the GPSI for a certain SUPI applicable to an application, AF service, or MTC from the UDM, and also enhance the UDM service so that the NEF can request the (one or more) external group identifiers for the group to which the subscriber identified by the SUPI belongs - As an alternative to network deployment with a PCF and a BSF (PCF / BSF are optional NFs), the NEF uses the existing BSF service to obtain the SUPI corresponding to a certain UE address - As an alternative to network deployment when the PCF and BSF are not deployed, the SMF provides a new service that the NEF uses to obtain the SUPI corresponding to the UE address from the SMF
[0086] In some examples, scenarios involving Network Address Translation (NAT) can be supported by defining the UE address and application port (client - side and server - side) for an IP - type PDU session as input parameters. The solution may, in some examples, require the NEF to obtain from the NAT information of the transformation being performed. The NEF can then convert the UE IP address and port after NAT (provided by the AF) to the UE IP address and port before NAT and interact with the BSF or SMF using the UE IP address they understand.
[0087] The examples described herein enable the extension of UDM subscriber and subscriber group management to include the handling of the GPSI specific to an application, AF service, or MTC provider and the (one or more) external group identifiers. Further, service operation can be extended to obtain subscriber data from the UDM based on the SUPI in order to also support the retrieval of external group identifiers. A new service can be defined for the AF to obtain a valid external identifier for a subscriber or subscriber group from the UE address, where as the UE address, (i) the AF provides the UE IP address and port (client - side and server - side) that enable it to support some scenarios where NAT is deployed for an IP - type PDU session, and / or (ii) the AF provides the MAC address when a non - IP Ethernet PDU session is being performed. The NEF can be extended to receive information from the NAT (e.g., acting as an IPFIX collector) and convert the UE IP address and port after NAT (provided by the AF) to the UE IP address and port before NAT (as described in the NAT report). Further, a new SMF service can be defined to obtain the SUPI corresponding to the UE address (in a scenario without PCF and BSF). The solution leverages the existing BSF service to obtain the SUPI corresponding to the UE address (only in a scenario with PCF and BSF).
[0088] Compared with the solutions in the prior art, the examples according to the present disclosure enable the provision of application / AF service / MTC provider specific external identifiers. By including this information as input in new services provided to AF and involving UDM, the examples outlined herein are enhanced to provide customized external identifiers. The UDM, which is responsible for identity handling, can handle the same number of user and group external identifiers as desired (compared to solutions where the BSF directly provides information).
[0089] Furthermore, the examples described herein support network address translation scenarios. When the AF provides the UE address and port (client side and server side), the NEF can derive the address before NAT from the UE address and port after NAT if it receives the NAT information from the network address translation service connection.
[0090] The examples according to the present disclosure further solve the problem of provisioning external identifiers for groups of users by having the UDM store those external identifiers and providing them for the SUPI. This case has not been addressed before. The case is solved by enabling the explicit request for external group identifiers in the subscriber data request to the UDM for the UE address owner and then also for the SUPI owner.
[0091] Furthermore, the examples outlined herein also support scenarios where the PCF / BSF is not deployed. This has not been addressed before. It is solved by defining a new service for the SMF to provide the SUPI corresponding to a certain UE address.
[0092] To avoid corrections between AFs, the AF specific identifier can be used according to the examples described herein.
[0093] It should be understood that the present disclosure has been described with reference to exemplary embodiments that can be modified in many aspects. Therefore, the present invention is limited only by the following claims.
Claims
1. A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: receiving (S302), by the first network entity, from a second entity, a request for obtaining user equipment (UE) identification information; sending (S304), in response to the request, by the first network entity, to a third network entity in the CND, a request for obtaining, from the third network entity, the UE identification information unique to the second entity; receiving (S306), by the first network entity, from the third network entity, the UE identification information unique to the second entity; sending (S308), by the first network entity, to the second entity, the UE identification information unique to the second entity; and wherein the first network entity is a network exposure function (NEF), the second entity is an application function (AF), and the third network entity is a unified data management (UDM), the method (300).
2. A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: receiving (S302), by the first network entity, from a second entity, a request for obtaining user equipment (UE) identification information; sending (S304), in response to the request, by the first network entity, to a third network entity in the CND, a request for obtaining, from the third network entity, the UE identification information unique to the second entity; receiving (S306), by the first network entity, from the third network entity, the UE identification information unique to the second entity; sending (S308), by the first network entity, to the second entity, the UE identification information unique to the second entity; and wherein the second entity is an application function; A method in which the request for obtaining UE identification information received from the second entity by the first network entity includes an indicator for requesting an external group identifier that refers to one or more subscriptions for the UE. **Claim 3** A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: Receiving (S302) by the first network entity from a second entity a request for obtaining user equipment (UE) identification information; In response to the request, sending (S304) by the first network entity to a third network entity in the CND a request for obtaining from the third network entity the UE identification information specific to the second entity; Receiving (S306) by the first network entity from the third network entity the UE identification information specific to the second entity; Sending (S308) by the first network entity to the second entity the UE identification information specific to the second entity; Comprising: The second entity being an application function; The request for obtaining from the third network entity the UE identification information specific to the second entity, which is sent by the first network entity to the third network entity, includes one or more of an application port identifier, machine type communication (MTC) provider information, and a service identifier related to the second entity. **Claim 4** A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: Receiving (S302) by the first network entity from a second entity a request for obtaining user equipment (UE) identification information; In response to the request, sending, by the first network entity, a request to the third network entity in the CND to obtain, from the third network entity, the UE identification information unique to the second entity (S304); Receiving, by the first network entity, from the third network entity, the UE identification information unique to the second entity (S306); Sending, by the first network entity, to the second entity, the UE identification information unique to the second entity (S308); comprising; the second entity being an application function; wherein the request sent by the first network entity to the third network entity to obtain, from the third network entity, the UE identification information unique to the second entity includes a UE group indication for instructing that UE group identification information unique to the second entity is requested, a method. **Claim 5** A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: Receiving, by the first network entity, from a second entity, a request to obtain user equipment (UE) identification information (S302); In response to the request, sending, by the first network entity, a request to the third network entity in the CND to obtain, from the third network entity, the UE identification information unique to the second entity (S304); Receiving, by the first network entity, from the third network entity, the UE identification information unique to the second entity (S306); Sending, by the first network entity, to the second entity, the UE identification information unique to the second entity (S308); comprising; the second entity being an application function; A method, including receiving, by the first network entity from the third network entity, an external identifier that identifies a subscription for the UE, the external identifier including the UE identification information unique to the second entity. **Claim 6** A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: Receiving (S302), by the first network entity from a second entity, a request for obtaining user equipment (UE) identification information; Sending (S304), in response to the request, by the first network entity to a third network entity in the CND, a request for obtaining, from the third network entity, the UE identification information unique to the second entity; Receiving (S306), by the first network entity from the third network entity, the UE identification information unique to the second entity; Sending (S308), by the first network entity to the second entity, the UE identification information unique to the second entity; Including The second entity being an application function; A method, wherein receiving, by the first network entity from the third network entity, the UE identification information unique to the second entity includes receiving, by the first network entity from the third network entity, an external group identifier that refers to one or more subscriptions for the UE. **Claim 7** A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: Receiving (S302), by the first network entity from a second entity, a request for obtaining user equipment (UE) identification information; Sending (S304), in response to the request, by the first network entity to a third network entity in the CND, a request for obtaining, from the third network entity, the UE identification information unique to the second entity; Receiving, by the first network entity, the UE identification information unique to the second entity from the third network entity (S306); Sending, by the first network entity, the UE identification information unique to the second entity to the second entity (S308); comprising; wherein the second entity is an application function; The sending, by the first network entity, of the request to the third network entity to obtain the UE identification information unique to the second entity from the third network entity is based on the identifier conversion subscription data type field in the request being extended to include an optional external group identifier, a method. **Claim 8** A method (300) performed by a first network entity in a core network domain (CND) of a wireless communication network, the method comprising: Receiving, by the first network entity, a request from a second entity to obtain user equipment (UE) identification information (S302); In response to the request, sending, by the first network entity, a request to a third network entity in the CND to obtain the UE identification information unique to the second entity from the third network entity (S304); Receiving, by the first network entity, the UE identification information unique to the second entity from the third network entity (S306); Sending, by the first network entity, the UE identification information unique to the second entity to the second entity (S308); comprising; wherein the second entity is an application function; The sending, by the first network entity, of the request to the third network entity to obtain the UE identification information unique to the second entity from the third network entity is based on machine type communication (MTC) provider information and / or service identifiers related to the second entity being added as data sub-keys for identifier conversion, a method.
9. The method according to any one of claims 1 to 8, wherein the request for obtaining UE identification information received from the second entity by the first network entity includes a UE Internet Protocol (IP) address and application port identification information in an application client in the UE.
10. The method according to claim 9, further comprising converting, by the first network entity, the UE IP address and the application port identification information after network address translation (NAT) into a UE IP address and application port identification information before NAT.
11. A method (400) in a wireless communication network, wherein the wireless communication network comprises a first network entity in a core network domain (CND) of the wireless communication network and a second entity, and the method is executed by the second entity, sending (S402), by the second entity, a request for obtaining user equipment (UE) identification information unique to the second entity to the first network entity; receiving (S404), by the second entity, from the first network entity, the UE identification information unique to the second entity; and including the UE identification information unique to the second entity is received based on a request for obtaining the UE identification information unique to the second entity sent by the first network entity from a third network entity in the CND by the first network entity; wherein the first network entity is a network exposure function (NEF), the second entity is an application function (AF), and the third network entity is an unified data management (UDM), the method (400).
12. A method (400) in a wireless communication network, wherein the wireless communication network comprises a first network entity in a core network domain (CND) of the wireless communication network and a second entity, and the method is executed by the second entity, sending, by the second entity, a request to the first network entity to obtain user equipment (UE) identification information unique to the second entity (S402); receiving, by the second entity, from the first network entity, the UE identification information unique to the second entity (S404); including; wherein the second entity is an application function; wherein the request sent by the second entity to the first network entity to obtain UE identification information includes an indicator for requesting an external group identifier that refers to one or more subscriptions for the UE.
13. The method according to claim 11 or 12, wherein the request sent by the second entity to the first network entity to obtain UE identification information includes a UE Internet Protocol (IP) address and application port identification information in an application client in the UE.
14. A method (500) performed by a network entity in a core network domain (CND) of a wireless communication network, the method comprising: generating, using an application service provider identifier, a modified version of one or both of external user equipment (UE) identification information and an external group identifier, wherein the external UE identification information identifies a subscription for the UE and the external group identifier refers to one or more subscriptions (S502); generating a token for the modified version of one or both of the external UE identification information and the external group identifier (S504); including.
15. The method according to claim 14, wherein the network entity is an Unified Data Management (UDM).
16. The method according to claim 14, wherein the modified version of one or both of the external UE identification information and the external group identifier is unique to an entity in or coupled to the wireless communication network.
17. An apparatus (502) adapted to operate in a core network domain (CND) of a wireless communication network (100), the apparatus (502) being configured to execute the method according to any one of claims 1 to 8.
18. An apparatus (512) adapted to operate in a wireless communication network (100), the apparatus being configured to execute the method according to claim 11 or 12.
19. An apparatus (522) adapted to operate in a wireless communication network (100), the apparatus being configured to execute the method according to any one of claims 14 to 16.