Bidirectional communication protocol for private networks
The proposed communication protocol between SEPPs in 5G networks addresses registration challenges and firewall traversal issues, ensuring efficient and timely bidirectional communication for seamless roaming.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- CISCO TECHNOLOGY INC
- Filing Date
- 2023-01-30
- Publication Date
- 2026-04-17
AI Technical Summary
Existing methods for roaming between private networks in 5G systems face challenges with cumbersome boundary node registration and the inability of traditional firewalls to allow inbound connections, leading to delays in message delivery and inefficient communication across enterprise firewalls.
A communication protocol, such as WebSocket, is established between security edge protection proxies (SEPPs) of home and visited networks to enable bidirectional communication, allowing seamless exchange of roaming signals and automatic termination when the user device leaves the visited network.
Facilitates timely and efficient bidirectional communication between private networks, ensuring seamless roaming experiences and reducing delays by enabling interactive communication across enterprise firewalls.
Smart Images

Figure 0007847654000001 
Figure 0007847654000002 
Figure 0007847654000003
Abstract
Description
Technical Field
[0001] Cross - reference to Related Applications
[0001] This application claims the benefit of priority of U.S. Non - Provisional Patent Application No. 17 / 846,582, entitled "BI - DIRECTIONAL COMMUNICATION PROTOCOL FOR PRIVATE NETWORKS", filed on June 22, 2022, and U.S. Provisional Patent Application No. 63 / 305,502, entitled "EDGE PROXY TO EDGE PROXY COMMUNICATIONS ACROSS ENTERPRISE FIREWALLS", filed on February 1, 2022, the disclosures of which are hereby incorporated by reference in their entirety.
[0002] Technical Field
[0002] The subject matter of this disclosure generally relates to the field of computer networking, and more specifically, to facilitating two - way communication between private networks across enterprise firewalls.
Background Art
[0003] Background
[0003] Current mobile and wireless communication systems widely adopt 5G, which is a next - generation wireless communication system that provides much higher data rates and less latency. Many communication service providers (e.g., mobile network operators) deploying 5G systems have developed roaming services to extend the coverage of the home operator's services, enabling their mobile users to use those services within the networks of other operators. In 5G systems, for roaming services, the SBA (Service - Based Architecture) and security functions that protect the network edge are newly supported by a new NF (network function) called SEPP (Security Edge Protection Proxy).
[0004] Brief explanation of the drawing
[0004] In order to illustrate how the above and other advantages and features of this disclosure can be obtained, a more specific explanation of the principles briefly described above is provided by reference to specific embodiments shown in the accompanying drawings. With understanding that these drawings only illustrate exemplary embodiments of this disclosure and are therefore not to be considered limiting its scope, the principles herein are described and explained in more detail with further specificity by using the accompanying drawings. [Brief explanation of the drawing]
[0005] [Figure 1]
[0005] An illustrative schematic diagram of a 5G network environment in which one or more aspects of the present disclosure may operate is shown. [Figure 2]
[0006] This disclosure provides several examples illustrating exemplary network environments for establishing bidirectional communication protocols in 5G service-based architectures. [Figure 3A]
[0007] This disclosure illustrates some examples of an enhanced roaming system that supports bidirectional communication between 5G networks. [Figure 3B]
[0007] The following are illustrative diagrams of an enhanced roaming system that supports bidirectional communication between 5G networks, according to some examples of the present disclosure. [Figure 3C]
[0007] The following are illustrative diagrams of an enhanced roaming system that supports bidirectional communication between 5G networks, according to some examples of the present disclosure. [Figure 3D]
[0007] The following are illustrative diagrams of an enhanced roaming system that supports bidirectional communication between 5G networks, according to some examples of the present disclosure. [Figure 4A]
[0008] This disclosure illustrates some examples of an enhanced roaming system that supports bidirectional communication between 4G and 5G networks. [Figure 4B]
[0008] The present disclosure illustrates some examples of an enhanced roaming system that supports bidirectional communication between a 4G network and a 5G network. [Figure 4C]
[0008] The present disclosure illustrates some examples of an enhanced roaming system that supports bidirectional communication between a 4G network and a 5G network. [Figure 4D]
[0008] The present disclosure illustrates some examples of an enhanced roaming system that supports bidirectional communication between a 4G network and a 5G network. [Figure 5]
[0009] This disclosure provides flowcharts illustrating methods for enabling bidirectional communication between networks, using several examples. [Figure 6]
[0010] The following are exemplary network devices according to several aspects of this disclosure. [Figure 7]
[0011] For example, an exemplary computing system is shown, which can be any computing device on which the system's components can be implemented. [Modes for carrying out the invention]
[0006] Detailed explanation
[0012] Various embodiments of this disclosure are described in detail below. Specific implementations are described, but it should be understood that these are for illustrative purposes only. Those skilled in the art will recognize that other components and configurations may be used without departing from the spirit and scope of this disclosure. Therefore, the following descriptions and drawings are illustrative and should not be construed as limiting. Numerous specific details are provided to provide a full understanding of this disclosure. However, in some cases, well-known or prior art details are omitted to avoid complicating the description. References to one embodiment or a particular embodiment in this disclosure may refer to the same embodiment or any of the embodiments, and such references mean at least one of the embodiments.
[0007]
[0013] References to “one embodiment” or “a particular embodiment” mean that certain features, structures, or characteristics described in relation to that embodiment are included in at least one embodiment of this disclosure. While the phrase “in one embodiment” appears in various places throughout this specification, not all of them necessarily refer to the same embodiment, nor are different or alternative embodiments mutually exclusive with other embodiments. Furthermore, various features are described that may be shown in some embodiments but not in others.
[0008]
[0014] The terms used herein generally have the common meanings in the art within the context of this disclosure and in the specific context in which each term is used. Substitute words and synonyms may be used for any one or more terms described herein, and it is not particularly important whether or not a term is detailed or described herein. In some cases, synonyms for certain terms are provided. The detailing of one or more synonyms does not preclude the use of other synonyms. The use of examples anywhere in this specification, including examples of terms described herein, is illustrative only and is not intended to further limit the scope and meaning of this disclosure or the exemplary terms. Similarly, this disclosure is not limited to the various embodiments provided herein.
[0009]
[0015] Without any intention to limit the scope of this disclosure, examples of equipment, apparatus, methods, and related results according to embodiments of this disclosure are given below. For the convenience of the reader, titles or subtitles may be used in the examples, but please note that this does not limit the scope of this disclosure. Unless otherwise defined, technical and scientific terms used herein have the meanings generally understood by those skilled in the art to which this disclosure belongs. In the event of any conflict, this specification, including the definitions, shall prevail.
[0010]
[0016] Further features and advantages of the present disclosure are described in the following description, some of which will be apparent from the description or can be learned by practicing the principles disclosed herein. The features and advantages of the present disclosure can be realized and obtained by the devices and combinations particularly pointed out in the appended claims. These and other features of the present disclosure will become more fully apparent from the following description and appended claims, or can be learned by practicing the principles described herein.
[0011]
[0017]
[0012]
[0018] Overview
[0019] Aspects of the present invention are described in the independent claims, and the preferred features are described in the dependent claims. The features of one aspect can be applied alone to each aspect or in combination with other aspects.
[0013]
[0020] Disclosed herein are a system, a method, and a computer-readable medium for supporting two-way communication between private networks across an enterprise firewall of a private network.
[0014]
[0021] In one aspect, the method includes receiving, from a user device, a subscription request for operating on a destination private network, determining that the user device is associated with a home network, and establishing a communication protocol between a security edge protection proxy of the destination private network and a security edge protection proxy of the home network, the communication protocol enabling an exchange of two-way roaming signals between the destination private network and the home network while the user device is operating on the destination private network.
[0015]
[0022] In another aspect, the method further includes rewriting a callback URI (Uniform Resource Identifier) that is signaled by a network function of a visited private network and received by a security edge protection proxy of a home network to a URI that resolves to the security edge protection proxy of the home network.
[0016]
[0023] In another aspect, the method further includes enabling routing of a server-initiated message originated within a home network towards a visited private network by restoring a Diameter origin host and origin information from a subscription request and updating routing information within the home network.
[0017]
[0024] In another aspect, the method further includes determining that a subscription of a user device to a visited private network has ended and terminating a communication protocol between a security edge protection proxy of the home network and a security edge protection proxy of the visited private network.
[0018]
[0025] In another aspect, the method further includes determining that a timer has expired, where the timer defines a period of a communication protocol, and terminating the communication protocol between the home network and the visited private network when it is determined that the timer has expired.
[0019]
[0026] In another aspect, when the visited private network is a private 5G network, a bidirectional N32 interface is used to transfer signals between the visited private network and the home network via a communication protocol.
[0020]
[0027] In another embodiment, if the visited private network is a private LTE network, the S6a interface is used to transfer signals between the visited private network and the home network using a communication protocol.
[0021]
[0028] In another embodiment, the method further includes determining that there is at least one outstanding subscription to a visited private network, and that the outstanding subscription relates to a second user device associated with the home network, and maintaining a communication protocol between the home network's security edge protected proxy and the visited private network's security edge protected proxy while the at least one outstanding subscription is valid.
[0022]
[0029] In one embodiment, the network component includes one or more memories storing computer-readable instructions, and one or more processors. The one or more processors are configured to execute computer-readable instructions to receive a subscription request from a user device to operate on a visited private network, to determine that the user device is associated with a home network, and to establish a communication protocol between a security edge protected proxy of the visited private network and a security edge protected proxy of the home network, wherein the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network.
[0023]
[0030] In one embodiment, one or more non-transient computer-readable media, when executed by one or more processors of a network component, include computer-readable instructions causing the network component to: receive a subscription request from a user device to operate on a visited private network; determine that the user device is associated with a home network; and establish a communication protocol between a security edge protected proxy of the visited private network and a security edge protected proxy of the home network, wherein the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network.
[0024]
[0031]
[0025]
[0032] Description of Embodiments
[0033] Throughout this disclosure, for convenience, the following abbreviations will be used: 5GNF: 5G network function AAA: Authentication, Authorization, and Billing ANP or AP: Access Network Provider or Access Provider DEA: Diameter Edge Agent DNS: Domain Name System DRA: Diameter Routing Agent HPLMN:Home Public Land Mobile Network IDP: Identity Provider NAS: Non-Access Stratum PLMN:Public Land Mobile Network SBA: Service-Based Architecture SCP:Service Communication Proxy SEPP:Security Edgy Protection Proxy TCP:Transmission Control Protocol TLS: Transport Layer Security UE: User Equipment VPLMN: Visited Public Land Mobile Network
[0026]
[0034] As mentioned earlier, SEPP is a new network feature of the 5G system that supports the 5G service-based architecture and security features (i.e., protecting the network edge). The 5G service-based architecture allows any third-party application to interact with the 5G NF in a secure manner. The 5G service-based architecture requires the ability to support any inbound connections from the initiating SEPP to the responding SEPP, as follows: For example, the GSM Association (GSMA) requires that the IP addresses of the initiating SEPP be registered and shared among operators to reduce the risks of accepting inbound connections from third-party networks.
[0027]
[0035] However, existing methods for roaming between private networks can be problematic when there are many networks, as registering boundary nodes can be cumbersome. Furthermore, the increasing diversity of networks necessitates enabling traditional firewall traversal for inter-SEPP communication. However, traditional firewalls prioritize policy control for outbound connections and do not allow inbound connections. In addition, 5G network architectures require the timely delivery of messages from HPLMN to VPLMN. For example, delays in the delivery of information after a UE has registered with a neighboring PLMN (e.g., Nudm_UECM_DeregistrationNotify) can cause problems when the UE subsequently returns to its original PLMN.
[0028]
[0036] Therefore, in 5G service-based architectures, there is a need for a communication protocol that can support bidirectional communication between networks across enterprise firewalls. This technology includes, among other things, systems, methods, and computer-readable media for resolving the aforementioned problems and contradictions. In some examples, systems, methods, and computer-readable media are provided for enabling bidirectional communication between a home network provider and a visited network provider (e.g., inter-SEPP communication in a 5G service-based architecture). In particular, the proposed solution relates to establishing a communication protocol for bidirectional communication between a home network provider and a visited network provider when a user device from the home network enters the visited private network. Furthermore, the proposed solution relates to automatically terminating the communication protocol when the user device leaves the visited network. The term “WebSocket” is understood to be used to refer to the communication protocol of this disclosure that supports bidirectional communication between private networks, more specifically, inter-SEPP communication across enterprise firewalls.
[0029]
[0037] Figure 1 shows an exemplary schematic diagram of a 5G network environment 100 in which one or more aspects of the present disclosure may operate. As shown, the network environment 100 is divided into four domains, each described in more detail below: a user equipment (UE) domain 110, for example, one or more enterprises, where multiple user mobile phones or other connected devices 112 reside; a radio access network (RAN) domain 120, where multiple radio cells, base stations, towers, or other radio infrastructure 122 reside; a core network 130, where multiple network functions (NFs) 131, 132, ..., n reside; and a data network 140, where one or more data communications networks, such as the Internet 142, reside. Furthermore, the data network 140 may support a SaaS provider configured to provide SaaS to enterprises, for example, users within the UE domain 110.
[0030]
[0018] The core network 130 includes a plurality of network functions (NFs), which are herein referred to as NF131, NF132, ..., NFn. In some examples, the core network 130 is a 5GC according to one or more accepted 5G core network (5GC) architectures or designs. In some cases, the core network 130 is an Evolved Packet Core (EPC) network that combines an embodiment of a 5GC with an existing 4G network. Regardless of the specific design of the core network 130, the plurality of NFs typically run in the control plane of the core network 130 and provide a service-based architecture in which a given NF allows any other authorized NF to access its services. For example, a Session Management Function (SMF) controls the establishment, modification, release, etc., of sessions and, in the process of doing so, provides other NFs with access to these configuration SMF services.
[0031]
[0019] In some examples, the multiple NFs of the core network 130 may include one or more AMFs (Access and Mobility Management Functions) (usually used when the core network 130 is a 5GC network) and MMEs (Mobility Management Entities) (usually used when the core network 130 is an EPC network) (for simplicity and clarity, they are collectively referred to as AMF / MME in this specification). In some examples, the AMF / MME may be common to multiple slices of the multiple network slices 152, or otherwise shared by multiple slices of the multiple network slices 152, and in some examples, the AMF / MME may be specific to a single slice of the multiple network slices 152.
[0032]
[0020] The same applies to the remaining NFs of the core network 130, which may be shared among one or more network slices or provided as unique instances specific to a single slice among multiple network slices 152. In addition to the NFs including the AMF / MME described above, the multiple NFs of the core network 130 may further include one or more of the following: UPE (User Plane Function); PCF (Policy Control Function); AUSF (Authentication Server Function); UDM (Unified Data Management function); AF (Application Function); NEF (Network Exposure Function); NRF (NF Repository Function); and NSSF (Network Slice Selection Function). As those skilled in the art will understand, various other NFs can be provided without departing from the scope of this disclosure.
[0033]
[0021] An overall operator network domain 150 is defined across these four domains of the 5G network environment 100. The operator network domain 150 is, in some examples, a PLMN (Public Land Mobile Network) and can be thought of as a telecommunications carrier or entity that provides mobile phone services to end users within the UE domain 110. Within the operator network domain 150, multiple network slices 152 are created, defined, or otherwise provisioned to deliver a defined set of features and functions, such as a desired set of SaaS, for a specific use case or to meet other requirements or specifications. Note that the network slicing of the multiple network slices 152 is implemented in an end-to-end manner across multiple different technology and management domains, including management and orchestration planes (not shown). In other words, network slicing takes place at least from the enterprise or subscriber edge in the UE domain 110, through the RAN 120, through the 5G access edge and 5G core network 130, and down to the data network 140. Furthermore, it should be noted that this network slicing may extend to multiple different 5G providers.
[0034]
[0022] For example, as shown herein, the multiple network slices 152 include slice 1 corresponding to smartphone subscribers of a 5G provider that also operates the network domain, and slice 2 corresponding to smartphone subscribers of a virtual 5G provider that leases capacity from the actual operator of the network domain 150. Also shown are slice 3 which can be provided to a fleet of connected vehicles, and slice 4 which can be provided to an IoT product or container tracking system across a factory network or supply chain. Note that these network slices 152 are provided for illustrative purposes and in accordance with this disclosure, and the operator network domain 150 may implement any number of network slices as needed, and may implement these network slices for user and user equipment purposes, use cases, or subsets in addition to those listed above. Specifically, the operator network domain 150 may implement any number of network slices to provision SaaS from a SaaS provider to one or more companies.
[0035]
[0023] 5G mobile and wireless networks are intended to provide improved mobile broadband communication and deliver a wider range of services and applications compared to all previous generation mobile and wireless networks. Compared to previous generation mobile and wireless networks, the 5G architecture is service-based, which means that, where appropriate, architectural elements are defined as network functions that serve other network functions through a common framework interface. To support such a wide range of services and network functions across the ever-growing base of user equipment (UE), 5G networks incorporate the concept of network slicing, which was used in previous generation architectures.
[0036]
[0038] Within the scope of 5G mobile and wireless network architecture, a network slice includes a defined set of features and functions that together form a complete Public Land Mobile Network (PLMN) to serve a UE. This network slicing enables the controlled configuration of PLMNs with specific network functions and services required for a particular usage scenario. In other words, network slicing allows 5G network operators to deploy multiple independent PLMNs, each customized by instantiating only the features, capabilities, and services required to meet a given subset of UEs or related business customer needs.
[0037]
[0039] Figure 2 shows an exemplary network environment 200 for establishing a bidirectional communication protocol, according to several examples of the present disclosure. In some examples, the network environment 200 includes a UE 202, a visited network provider 210, and a home network provider 230. The UE 202, initially connected to the home network provider 230, roams to an area covered by the visited network provider 210.
[0038]
[0040] In some implementations, the visited network provider 210 includes V-SEPP212 and multiple network functions 221, 222, 223, etc. (similar to, for example, the network functions 131, 132, ..., n of the core network 130 as shown in Figure 1). The home network provider 230 also includes H-SEPP232 and multiple network functions 241, 242, 243, etc. (similar to, for example, the network functions 131, 132, ..., n of the core network 130 as shown in Figure 1). In some cases, the N32 interface is used as the interface between the V-SEPP212 of the visited network provider 210 and the H-SEPP232 of the home network provider 230, thereby enabling bidirectional communication between V-SEPP212 and H-SEPP232.
[0039]
[0041] In some examples, UE202 appears in an area covered by the visited network provider 210. The visited network provider 210 needs to authenticate UE202 (e.g., by an HTTP / 2 request). An inbound user device on the network (e.g., UE202 on the visited network provider 210) can trigger the establishment of a WebSocket with the network, which holds the credentials necessary to authenticate a particular user device. In some cases, while UE202 is being serviced by the network, the WebSocket may exist to allow a bidirectional flow of information between the visited network provider 210 and the home network provider 230 (i.e., exchange of roaming signals). When UE202 leaves the area covered by the visited network provider 210, the WebSocket can terminate as roaming is no longer required.
[0040]
[0042] In some cases, if a second UE from the same home network joins the same destination network, the second UE can use the same WebSocket. The WebSocket is maintained as long as at least one UE remains on the destination network. That is, the WebSocket can only be terminated when the last UE from home provider 230 leaves the network of destination network provider 210. In some examples, a UE's home network can be identified based on the UE's network code.
[0041]
[0043] Figures 3A–3D illustrate exemplary extended roaming systems 300 having data flows to support bidirectional communication between 5G networks, according to several examples of the present disclosure. The exemplary network environments in Figures 3A–3D include a 5G ANP (Access Network Provider) 302 (i.e., a visited network provider), a 5G IDP (Identity Provider) 304 (i.e., a home network provider), and a DNS (Domain Name System) 306 between the 5G ANP 302 and the 5G IDP 304. In some examples, the 5G ANP 302 includes a 5GNF 308, an SCP 310, a V-SEPP 312, and a firewall 314. The 5G IDP 304 also includes a 5GNF 316 and 318, an SCP 320, and a H-SEPP 322.
[0042]
[0044] In some examples, the 5G ANP302 and 5G IDP304 may be the HPLMN and VPLMN (or vice versa). The VPLMN is the PLMN that the mobile subscriber roamed to when leaving the HPLMN.
[0043]
[0045] According to some examples, V-SEPP312 and H-SEPP322 can be deployed at the edge of each network (e.g., 5G ANP302 and 5G IDP304, respectively) to provide perimeter protection in the mobile core infrastructure network. Furthermore, V-SEPP312 and H-SEPP322 may be configured to proxy messages from network functions within 5G ANP302 (e.g., 5GNF308) to network functions within 5G IDP304 (e.g., 5GNF316 and 318), or vice versa. Information can be exchanged between both NFs in 5G ANP302 and 5G IDP304 as follows:
[0044]
[0046] As shown in Figure 3A, the 5G IDP304 can configure a record to point to the SEPP in step 324. The 5G ANP302 also allows outbound ports from the SEPP in step 326. In some examples, the 5GNP308 sends an HTTP / 2 request to the SCP310 in step 328, which then forwards it to the V-SEPP312 in step 332. The SCP310 also establishes a routing policy for all initiation requests directed to a particular SEPP instance in step 330. In step 334, the V-SEPP312 sends a DNS query to the DNS306, which then sends a DNS response back in step 336. In step 338, a TLS is established between the V-SEPP312 and the H-SEPP322, for example, using the WBA (Wireless Broadband Alliance) Public Key Infrastructure (PKI).
[0045]
[0047] Figure 3B is a continuation of Figure 3A. More specifically, Figure 3B shows the setup process for a WebSocket-based N32-f. N32-f is an inter-SEPP forwarding interface that can be used, for example, to forward communication between the network functions of an access provider (e.g., 5GNF308 of 5G ANP302) and the network functions of an ID provider (e.g., 5GNF316 and 318 of 5G IDP304). In some examples, the WebSocket of this disclosure can provide a communication channel over a single TCP connection and is therefore a communication protocol that can enable two-way interactive communication (i.e., bidirectional communication) between the 5GNF221, 222, and 223 of a visited network provider 210 and the 5GNF241, 242, and 243 of a home network provider 230 via two SEPPs (e.g., V-SEPP312 and H-SEPP322).
[0046]
[0048] In step 340, V-SEPP312 sends an HTTPget request to H-SEPP322, and H-SEPP322 then sends an HTTP101 response. In step 342, a WebSocket is established between V-SEPP312 and H-SEPP322 as follows. In step 344, V-SEPP312 may send a subscription request to H-SEPP322 via the N32-f service. If the subscription request is rejected, in step 346, H-SEPP322 sends a subscription rejection message to V-SEPP312 via the N32-f service. In some cases, the subscription rejection message may include details of the problem. If the subscription request is accepted, in step 348, H-SEPP322 sends a subscription acceptance message to V-SEPP312 via the N-32-f service, and in step 350, the routing information for 5G ANP302 is updated on SCP320. As described below, in step 352, a bidirectional N-32-f service can be established between V-SEPP312 and H-SEPP322.
[0047]
[0049] Figure 3C is a continuation of Figure 3B. More specifically, Figure 3C shows the process of a WebSocket-based N32-f service. In step 354, 5GNF308 of 5G ANP302 sends an http / 2 request to SCP310, which then forwards the http / 2 request to V-SEPP312. Upon receiving the http / 2 request, V-SEPP can encode it in JSON (JavaScript Object Notation) in step 354. In step 356, V-SEPP312 sends an N32-f message request to H-SEPP322. Upon receiving the request, H-SEPP322 can reconstruct the JSON http / 2 request in step 358 and send the http / 2 request to SCP320, which then forwards the http / 2 request to 5GNF318. Subsequently, 5GNF318 sends the HTTP / 2 response to SCP320, which forwards the HTTP / 2 response to H-SEPP322. H-SEPP322 encodes the HTTP / 2 response in JSON and, in step 360, sends an N32-f message response to V-SEPP312. In step 368, V-SEPP312 tracks the response from the other network. In step 370, V-SEPP312 restores the JSON HTTP / 2 response and forwards the response to SCP310, which then forwards the response to 5GNF308.
[0048]
[0050] Similar to steps 354-370, 5G IDP304 can utilize the same WebSocket-based N32-f because it supports bidirectional communication between SEPPs. 5GNF316 of 5G IDP304 can send an http / 2 request to SCP320. In step 372, 5G IDP304 can select a SEPP instance using a routing policy and forward the http / 2 request to H-SEPP322, which then encodes the http / 2 request in JSON. In step 374, H-SEPP322 can send an N32-f message request to V-SEPP312, which then, in step 376, V-SEPP312 restores the http / 2 request in JSON. V-SEPP312 can forward the restored http / 2 request to SCP310, which then forwards that http / 2 request to 5GNF308. Upon receiving the request, 5GNF308 can send an HTTP / 2 response to SCP310, which then forwards the HTTP / 2 response to V-SEPP312. V-SEPP312 can encode the HTTP / 2 response in JSON. In step 378, V-SEPP312 sends an N32-f message response to H-SEPP322. In step 380, H-SEPP322 restores the JSON HTTP / 2 response and forwards the HTTP / 2 response to SCP320, which then forwards the HTTP / 2 response to 5GNF316, the device that initially requested the HTTP / 2 request.
[0049]
[0051] Figure 3D is a continuation from Figure 3C. More specifically, Figure 3D shows the process of terminating a WebSocket-based N32-f. In step 382, V-SEPP312 can check two conditions to determine whether it can terminate the WebSocket-based N32-f. First, V-SEPP312 determines that there are no outstanding subscriptions for 5GNF on 5G ANP302. Also, V-SEPP312 determines that the timer has expired since the last transaction. If both conditions are met, in step 384, V-SEPP312 can send a termination request to H-SEPP322. Upon receiving the termination request, in step 386, H-SEPP322 can send a termination acceptance message to V-SEPP312. Also, in step 388, H-SEPP322 requests SCP320 to remove the routing information for 5G ANP302. As described below, in step 390, the outbound TLS connection between V-SEPP312 and H-SEPP322 can be terminated.
[0050]
[0052] Figures 4A–4D illustrate an exemplary enhanced roaming system 400 having data flows to support bidirectional communication between a 4G network and a 5G network, as shown in several examples of the present disclosure. The exemplary network environment in Figures 4A–4D includes a 4G ANP 402 (i.e., a visited network provider), a 5G IDP 404 (i.e., a home network provider), and a DNS 406 between the 4G ANP 402 and the 5G IDP 404. In some examples, the 4G ANP includes a NAS 408, a DRA 410, a V-DEA 412, and a firewall 414. The 5G IDP 404 also includes an H-DEA 416, a DRA 418, and an AAA server 420. Compared to the exemplary flows in Figures 3A–D, the exemplary flows of the enhanced roaming system 400 shown in Figures 4A–4D utilize the use of S6a services. In some examples, S6a is a diameter-based authentication application used by Mobility Management Entity (MME) nodes to retrieve authentication credentials from the Home Subscriber Server (HSS).
[0051]
[0053] In some cases, the 4G ANP402 and 5G IDP404 may be HPLMN and VPLMN (or vice versa). VPLMN is the PLMN that the mobile subscriber roamed to when leaving the HPLMN.
[0052]
[0054] As shown in Figure 4A, in step 422, the 5G IDP404 can configure a record to point to the DEA. Also, in step 424, the 4G ANP402 allows outbound ports from the DEA. In step 426, the NAS408 sends a Diameter request to the DRA410, which then forwards the Diameter request to the V-DEA412. In step 428, the V-DEA412 sends a DNS query to the DNS406. Then, in step 430, the DNS406 sends a DNS response to the V-DEA412. In step 432, TLS is established between the V-DEA412 and the H-DEA416, for example, using the WBA's PKI.
[0053]
[0055] Figure 4B is a continuation of Figure 4A. More specifically, Figure 4B shows the setup process for WebSocket-based S6a-f. More specifically, procedure 400 includes the establishment of a WebSocket between the 4G ANP and the 5G IDP. S6a-f is an interface that supports end-to-end diameter-based signaling between network functions (e.g., NAS408 of 4G ANP402 and AAA server420 of 5G IDP404). As previously mentioned, WebSocket is a computer communication protocol that provides a communication channel over a single TCP connection and thus enables two-way interactive communication (i.e., bidirectional communication) between two DEAs (e.g., V-DEA412 and H-DEA416).
[0054]
[0056] In step 434, V-DEA412 sends an HTTP GET request to H-DEA416, and then in step 436, H-DEA416 returns an HTTP 101 response. In step 438, a WebSocket is established between V-DEA412 and H-DEA416 as follows.
[0055]
[0057] In step 440, V-DEA412 can send a subscription request to H-DEA416 via the S6a service. The subscription request includes the Diameter origin host and realm identifier for the NAS408 of the 4G ANP402. If the subscription request is rejected, in step 442, H-DEA416 sends a subscription rejection message to V-DEA412 via the S6a service. In some cases, the subscription rejection message may include details of the problem. If the subscription request is accepted, in step 444, H-DEA416 sends a subscription acceptance message to V-DEA412 via the S6a service. Also, in step 446, H-DEA416 updates the routing information for the Diameter origin host and realm identifier of the NAS408 of the 4G ANP402 in DRA418. In step 448, a bidirectional S6a-f service is established between V-DEA412 and H-DEA416, as follows:
[0056]
[0058] Figure 4B further illustrates the capability exchange process for a WebSocket-based S6a service. In step 450, V-DEA can generate a diameter capability exchange request. In step 452, V-DEA412 can send an S6a message request to H-DEA416, which then decodes the diameter capability exchange request and generates an answer in step 454. In step 456, H-DEA416 sends the diameter capability exchange answer to V-DEA412. In step 458, V-DEA decodes the diameter capability exchange answer.
[0057]
[0059] Figure 4C is a continuation of Figure 4B. Specifically, Figure 4C shows the process of a WebSocket-based S6a forwarding service. In step 460, NAS408 sends a diameter authentication information request to DRA410, which then forwards the diameter authentication information request to V-DEA412. V-DEA412 encodes the diameter authentication information request in JSON. In step 462, V-DEA412 sends an N32f message request to H-DEA416. In step 464, H-DEA416 recovers the diameter request from the JSON and sends the diameter authentication information request to DRA418, which then forwards the diameter authentication information request to AAA server 420. Upon receiving the request, AAA server 420 sends a diameter authentication information answer to DRA418, which then forwards the diameter authentication information answer to H-DEA416. H-DEA416 then encodes the diameter authentication information answer in JSON. In step 466, H-DEA416 sends an S6a message response to V-DEA412. In step 468, V-DEA412 recovers the diameter authentication information answer from the JSON and sends it to DRA410, which then forwards the diameter authentication information answer to NAS408. In step 470, the UE is authenticated as follows.
[0058]
[0060] Furthermore, in step 472, NAS408 can send a diameter location update request to DRA410, which then forwards the diameter location update request to V-DEA412. V-DEA412 sends an N32f message request to H-DEA416. The diameter location request is distributed from H-DEA416 to DRA418 and then to AAA server 420. Upon receiving the request, AAA server 420 sends a diameter location update answer to DRA418, which then forwards the diameter location update answer to H-DEA416. H-DEA416 sends an S6a message response to V-DEA412. In step 474, V-DEA412 can track the location update procedure "per UE". In step 476, V-DEA412 can send a diameter location update answer to DRA410, which then forwards the diameter location update answer to NAS408.
[0059]
[0061] In some implementations, in step 478, the AAA server 420 of the 5G IDP 404 can send a diameter location cancellation request to the DRA 418. In step 480, the 5G IDP 404 selects a DEA instance using a routing policy. In step 482, the DRA 418 sends a diameter location cancellation request to the H-DEA 416. The H-DEA 416 sends an S6a message request to the V-DEA 412. The V-DEA 412 then sends the diameter location cancellation request to the DRA 410, which then forwards the diameter location cancellation request to the NAS 408. The NAS 408 sends a diameter location cancellation answer to the DRA 410, which then forwards the diameter location cancellation answer to the V-DEA 412. In step 484, the V-DEA 412 removes the UE from tracking. In step 486, V-DEA412 sends an S6a message response to H-DEA416. H-DEA416 sends a diameter position cancellation answer to DRA418, which then forwards the diameter position cancellation answer to AAA server 420.
[0060]
[0062] Figure 4D is a continuation from Figure 4C. Specifically, Figure 4D shows the termination process for WebSocket-based S6a-f. In step 488, V-DEA412 can check two conditions to determine whether it can terminate WebSocket-based S6a-f. First, V-DEA412 determines that there are no active UEs from HPLMN (e.g., PLMN for 5G IDP404) (e.g., no pending registrations). Also, V-DEA412 determines that the timer has expired since the last transaction. If both conditions are met, in step 490, V-DEA412 can send a termination request to H-DEA416 via the S6a service. Upon receiving the termination request, in step 492, H-DEA416 sends a termination acceptance message to V-DEA412 via the S6a service. In step 494, H-DEA416 removes the routing information for 4G ANP402. In step 496, the outbound TLS connection between V-DEA412 and H-DEA416 can be terminated as follows:
[0061]
[0063] Figure 5 shows a flowchart of Method 500 supporting bidirectional SEPP-to-SEPP communication in several examples of the present disclosure. While the exemplary Method 500 shows a specific sequence of operations, this sequence can be modified without departing from the scope of the present disclosure. For example, some of the illustrated operations may be performed in parallel or in a different order that does not substantially affect the functionality of Method 500. In other examples, different components of the exemplary device or system implementing Method 500 may function substantially simultaneously or in a specific order.
[0062]
[0064] In step 510, method 500 includes receiving a subscription request from the user device to operate on (register with) the visited private network. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can register with a visited private network (e.g., a 5G ANP 302 as shown in Figure 3, or a 4G ANP 402 as shown in Figure 4) and receive a subscription request from the user device to operate on that visited private network.
[0063]
[0065] In some cases, the visited private network may include edge protection providers such as SEPP or DEA (for example, V-SEPP312 as shown in Figure 3, or V-DEA412 as shown in Figure 4).
[0064]
[0066] In step 520, method 500 includes determining that the user device is from a home network (e.g., a home private network). For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can determine that the user device is from a home network (e.g., a 5G IDP 304 as shown in Figure 3, or a 5G IDP 404 as shown in Figure 4).
[0065]
[0067] In step 530, method 500 includes establishing a communication protocol between the home network and the visited network (e.g., the visited private network). The communication protocol can enable bidirectional exchange of roaming signals between the visited private network and the home network during the subscription of a user device to the visited private network across a firewall such as firewall 314 and / or firewall 414. In some cases, the term “WebSocket” is used to describe the communication protocol that enables bidirectional exchange of roaming signals.
[0066]
[0068] For example, the extended roaming systems 300 and 400 shown in Figures 3 and 4, respectively, can establish communication protocols between a 5G ANP 302 and a 5G IDP 304, as shown in Figure 3, or between a 4G ANP 402 and a 5G IDP 404, as shown in Figure 4.
[0067]
[0069] In some cases, once a bidirectional forwarding service is established with the visited private network, the enhanced roaming system can signal the network functions of the visited private network to ensure that PLMN-based routing decisions for home network outbound requests destined for the visited private network are routed via SEPP or DEA. For example, the enhanced roaming system can rewrite the callback URI (Uniform Resource Identifier), which is signaled by the network functions of the visited private network and received in the signaling message by the home network's security edge protected proxy, to a URI that returns to the home network's security edge protected proxy. Furthermore, the enhanced roaming system can recover Diameter origin host and origin region information from the subscription request and update the routing information within the home network to enable routing of server startup messages originating within the home network destined for the visited private network.
[0068]
[0070] In some cases, once a bidirectional forwarding service with the home network is established, the extended roaming system can operate to intercept OK messages in response to subscribe and unsubscribe request messages via the home network.
[0069]
[0071] In step 540, method 500 includes determining whether there are any outstanding subscriptions. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can determine whether there are any outstanding subscriptions to a visited private network (e.g., a 5G ANP 302 as shown in Figure 3, or a 4G ANP 402 as shown in Figure 4).
[0070]
[0072] In some examples, an extended roaming system may have a counter for outstanding subscriptions between VPLMNs and HPLMNs (e.g., 5G ANP302 and 5G IDP304 as shown in Figures 3A-3D, or 4G ANP402 and 5G IDP404 as shown in Figures 4A-4D). For example, extended roaming systems 300 and 400, as shown in Figures 3-4 respectively, may refer to a counter to determine whether outstanding subscriptions exist between networks before terminating the bidirectional communication protocol between the networks. More specifically, a V-SEPP312 as shown in Figures 3A-3D or a V-DEA412 as shown in Figures 4A-4D may be extended with functionality to record the number of outstanding subscriptions for the 5G ANP302 or 4G ANP402 service, respectively, and to trigger disconnection / termination if no outstanding subscriptions exist.
[0071]
[0073] If there are unprocessed subscriptions, method 500 includes maintaining a bidirectional communication protocol in step 550. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can maintain a bidirectional communication protocol between a 5G ANP 302 and a 5G IDP 304, as shown in Figure 3, or between a 4G ANP 402 and a 5G IDP 404, as shown in Figure 4.
[0072]
[0074] If there are no outstanding subscriptions, method 500 includes determining in step 560 whether the timer has expired. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can determine whether the timer has expired since the last transaction with a 5G ANP 302, as shown in Figure 3, or a 4G ANP 402, as shown in Figure 4.
[0073]
[0075] If the timer has not expired, method 500 includes maintaining a bidirectional communication protocol in step 550. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can maintain a bidirectional communication protocol between a 5G ANP 302 and a 5G IDP 304, as shown in Figure 3, or between a 4G ANP 402 and a 5G IDP 404, as shown in Figure 4.
[0074]
[0076] If the timer has expired, method 500 includes terminating the bidirectional communication protocol in step 570. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, terminate the bidirectional communication protocol between a 5G ANP 302 and a 5G IDP 304, as shown in Figure 3, or between a 4G ANP 402 and a 5G IDP 404, as shown in Figure 4.
[0075]
[0077] More specifically, if there are no outstanding subscriptions and the timer has expired since the last transaction (e.g., the last response received by the visited private network or home network), the extended roaming system can terminate the bidirectional communication protocol. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can terminate the bidirectional communication protocol between the 5G ANP 302 and 5G IDP 304, as shown in Figure 3, or between the 4G ANP 402 and 5G IDP 404, as shown in Figure 4, if there are no outstanding subscriptions and the timer has expired.
[0076]
[0078] Furthermore, method 500 includes signaling to the SCP of the home network to update routing information when the bidirectional communication protocol terminates. For example, extended roaming systems 300 and 400, as shown in Figures 3 and 4 respectively, can signal to the SCP 310 of the 5G ANP 302, as shown in Figures 3A and 3D, to update routing information when the bidirectional forwarding instance with the 5G IDP 304 terminates.
[0077]
[0079] According to some implementations, the information exchanged via WebSocket can mimic information exchanged using established N32-c signaling, as defined in 3GPP 29.573. However, instead of establishing a unidirectional N32-f instance, the extended roaming system of this disclosure establishes a bidirectional N32-f forwarding instance.
[0078]
[0080] Figure 6 shows an exemplary network device 600 suitable for performing switching, routing, load balancing, and other networking operations. The network device 600 includes a central processing unit (CPU) 604, an interface 602, and a bus 610 (e.g., a PCI bus). When operating under the control of appropriate software or firmware, the CPU 604 is responsible for performing packet management, error detection, and / or routing functions. The CPU 604 preferably achieves all these functions under the control of software, including an operating system and any appropriate application software. The CPU 604 may include one or more processors 608, such as processors from the INTEL X86 family of microprocessors. In some cases, the processor 608 may be hardware specifically designed to control the operation of the network device 600. In some cases, memory 606 (e.g., non-volatile RAM, ROM, etc.) also forms part of the CPU 604. However, there are many different ways in which memory can be coupled to the system.
[0079]
[0081] Interface 602 is typically provided as modular interface cards (sometimes called "line cards"). Generally, they control the transmission and reception of data packets on the network and, at times, support other peripherals used with the network device 600. Possible interfaces include Ethernet interfaces, Frame Relay interfaces, cable interfaces, DSL interfaces, and Token Ring interfaces. Furthermore, various ultra-high-speed interfaces such as High Speed Token Ring interfaces, wireless interfaces, Ethernet interfaces, Gigabit Ethernet interfaces, ATM interfaces, HSSI interfaces, POS interfaces, FDDI interfaces, WIFI interfaces, 3G / 4G / 5G cellular interfaces, CAN BUS, and LoRA may be provided. Generally, these interfaces may include ports suitable for communication with the appropriate medium. In some cases, they may also include a separate processor and, possibly, volatile RAM. The separate processor can control communication-intensive tasks such as packet switching, medium control, signal processing, cryptography, and management. By providing a separate processor for communication-intensive tasks, these interfaces enable the master CPU 604 to efficiently perform routing calculations, network diagnostics, security functions, and more.
[0080]
[0082] The system shown in Figure 6 is one specific network device of this technology, but it is by no means the only network device architecture capable of implementing this technology. For example, architectures with a single processor that handles communication and routing calculations are often used. Furthermore, other types of interfaces and media may also be used in the network device 600.
[0081]
[0083] Regardless of the network device configuration, it may use one or more memories or memory modules (including memory 606) configured to store program instructions for general network operations and mechanisms for roaming, route optimization, and routing functions as described herein. These program instructions may, for example, control the operation of the operating system and / or one or more applications. One or more memories may also be configured to store tables such as mobility binding, registration, and association tables. Memory 606 may also hold various software containers and virtualization execution environments and data.
[0082]
[0084] The network device 600 may also include an application-specific integrated circuit (ASIC) which may be configured to perform routing and / or switching operations. The ASIC can communicate with other components within the network device 600 via the bus 610 to exchange data and signals, and can coordinate various types of operations performed by the network device 600, such as routing, switching, and / or data storage operations.
[0083]
[0085] Figure 7 shows an exemplary computing system 700 that includes components that communicate electrically with one another using a connection 705, in which one or more aspects of the present disclosure may be implemented. The connection 705 may be a physical connection via a bus, or a direct connection to a processor 710, such as in a chipset architecture. The connection 705 may also be a virtual connection, a networked connection, or a logical connection.
[0084]
[0086] In some embodiments, the computing system 700 is a distributed system in which the functions described herein may be distributed across a data center, a group of data centers, a peer network, and the like. In some embodiments, one or more of the system components described represent a number of such components, each performing some or all of the functions described. In some embodiments, the components may be physical or virtual devices.
[0085]
[0087] An exemplary system 700 includes at least one processing unit (CPU or processor) 710 and connections 705 that connect various system components to the processor 710, including system memory 715 such as read-only memory (ROM) 720 and random access memory (RAM) 725. The computing system 700 may include a high-speed memory cache 712 that is connected directly to the processor 710, in close proximity to the processor 710, or incorporated as part of the processor 710.
[0086]
[0088] The processor 710 may include an arbitrary general-purpose processor, hardware or software services such as services 732, 734, and 736 stored in a storage device 730, and a dedicated processor in which software instructions are incorporated into the actual processor design, configured to control the processor 710. The processor 710 may be a fully self-contained computing system that includes multiple cores or processors, buses, memory controllers, caches, etc. A multicore processor may be symmetrical or asymmetrical.
[0087]
[0089] To enable user interaction, the computing system 700 includes an input device 745, which may represent any number of input mechanisms such as a microphone for conversation, a touchscreen for gesture or graphical input, a keyboard, a mouse, motion input, or conversation. The computing system 700 may also include an output device 735, which may be one or more of a number of output mechanisms known to those skilled in the art. In some cases, a multimodal system may allow a user to provide multiple types of input / output for communication with the computing system 700. The computing system 700 may also include a communication interface 740, which can generally control and manage user inputs and system outputs. There are no restrictions on operation with specific hardware configurations, and therefore the basic features described herein can be easily replaced as improved hardware or firmware configurations are developed.
[0088]
[0090] The storage device 730 may be a non-volatile memory device, or it may be a hard disk, or any other type of computer-readable medium capable of storing computer-accessible data, such as a magnetic cassette, flash memory card, solid-state memory device, digital versatile disk, cartridge, random access memory (RAM), read-only memory (ROM), and / or any combination thereof.
[0089]
[0091] The storage device 730 may include software services, servers, and the like, and when code defining such software is executed by the processor 710, the code causes the system to perform functions. In some embodiments, a hardware service that performs a particular function may include software components stored on a computer-readable medium in relation to necessary hardware components such as the processor 710, connection 705, and output device 735 in order to perform the function.
[0090]
[0092] To clarify the explanation, in some cases, this technology may be presented as including individual functional blocks that include steps or routines in a way embodied in a device, device component, or software, or functional blocks that include a combination of hardware and software.
[0091]
[0093] In summary, a system, method, and computer-readable medium are disclosed for facilitating bidirectional edge proxy-to-edge communication across an enterprise firewall in a 5G service-based architecture. In one embodiment, the method includes receiving a subscription request from a user device to operate on a visited private network, determining that the user device is associated with a home network, and establishing a communication protocol between a security edge protected proxy on the visited private network and a security edge protected proxy on the home network, wherein the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network.
[0092]
[0094] Any of the steps, operations, functions, or processes described herein may be performed or implemented by hardware and software services or a combination of services, either alone or in combination with other devices. In some embodiments, a service may be software that resides in the memory of one or more servers of a client device and / or content management system, and performs one or more functions when a processor executes the software associated with the service. In some embodiments, a service may be a program or group of programs that perform a specific function. In some embodiments, a service may be considered a server. Memory may be a non-temporary computer-readable medium.
[0093]
[0095] In some embodiments, computer-readable storage devices, media, and memory may include cable signals or wireless signals, such as bitstreams. However, non-transient computer-readable storage media, as referred to, explicitly exclude media such as energy, carrier signals, electromagnetic waves, and the signals themselves.
[0094]
[0096] The method according to the above example can be implemented using computer-executable instructions stored on a computer-readable medium or otherwise available. Such instructions may include, for example, instructions and data that cause a general-purpose computer, a dedicated computer, or a dedicated processing device to perform a specific function or set of functions, or otherwise configure a general-purpose computer, a dedicated computer, or a dedicated processing device to perform a specific function or set of functions. Some of the computer resources used may be accessible over a network. Computer-executable instructions may be, for example, binaries, intermediate format instructions such as assembly language, firmware, or source code. Examples of computer-readable media that may be used to store instructions, information used, and / or information created in the method according to the described example include magnetic disks or optical disks, solid-state memory devices, flash memory, USB devices with non-volatile memory, and networked storage devices.
[0095]
[0097] Devices implementing the methods described herein may include hardware, firmware, and / or software, and may adopt any form factor from a variety of form factors. Typical examples of such form factors include servers, laptops, smartphones, small form factor personal computers, and personal digital assistants. The functionalities described herein may also be embodied in peripheral devices or add-in cards. Such functionalities may, as a further example, be implemented on a circuit board across different chips or different processes running in a single device.
[0096]
[0098] Instructions, a medium for carrying such instructions, computing resources for executing them, and other structures for supporting such computing resources are means for providing the functions described in these disclosures.
[0097]
[0099] While various examples and other information have been used to illustrate aspects of the claims, those skilled in the art will be able to derive a wide range of implementations from these examples, and therefore, it should not be suggested that the claims are limited based on any particular features or arrangement in such examples. Furthermore, while some subject matter may have been described in language specific to the examples of structural features and / or method steps, it should be understood that the subject matter defined in the claims is not necessarily limited to these described features or actions. For example, such functionality may be distributed or performed differently in components other than those identified herein. More precisely, the described features and steps are disclosed as examples of components of the systems and methods in the claims.
[0098]
[0100] Claim language or other language that uses the phrases "at least one of the sets" and / or "one or more of the sets" indicates that one member of the set or multiple members of the set (in any combination) satisfy the claim. For example, claim language that uses the phrases "at least one of A and B" or "at least one of A or B" means A, B, or A and B. In another example, claim language that uses the phrases "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, or A and B and C. The phrases "at least one of the sets" and / or "one or more of the sets" do not limit the set to the items listed in the set. For example, claim language that uses the phrases "at least one of A and B" or "at least one of A or B" may mean A, B, or A and B, and may include further items not listed in the set A and B.
Claims
1. A method performed by one or more processors, Receiving a subscription request from the user's device to operate on the visited private network, The determination that the user device is associated with the home network, Establishing a communication protocol between the security edge protected proxy of the visited private network and the security edge protected proxy of the home network, wherein the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network. It is determined that there is at least one outstanding subscription to the aforementioned private network of the visited location, While the at least one pending subscription is active, the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network is maintained. Methods that include...
2. The method according to claim 1, further comprising rewriting a callback URI (Uniform Resource Identifier) signaled by the network function of the visited private network and received by the security edge protected proxy of the home network to a URI that returns to the security edge protected proxy of the home network.
3. The method according to claim 1 or 2, further comprising restoring the Diameter origin host and origin information from the subscription request, and updating the routing information within the home network, thereby enabling the routing of server startup messages originating within the home network to the visited private network.
4. It is determined that the subscription of the user device to the aforementioned private network has ended, Terminate the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network. The method according to claim 1 or 2, further comprising:
5. The determination that the timer has expired, and that the timer defines or determines the duration of the communication protocol. When it is determined that the timer has expired, the communication protocol between the home network and the private network of the visited location is terminated. The method according to claim 1 or 2, further comprising:
6. The method according to claim 1 or 2, wherein, if the visited private network is a private 5G network, a signal is transferred between the visited private network and the home network using the communication protocol with a bidirectional N32 interface.
7. The method according to claim 1 or 2, wherein, if the visited private network is a private LTE network, the S6a interface is used to transfer signals between the visited private network and the home network using the communication protocol.
8. To determine that the unprocessed subscription relates to a second user device associated with the home network, The method according to claim 1 or 2, further comprising:
9. One or more memories storing computer-readable instructions, Executing the aforementioned computer-readable instruction, Receiving a subscription request from the user's device to operate on the visited private network, The determination that the user device is associated with the home network, Establishing a communication protocol between the security edge protected proxy of the visited private network and the security edge protected proxy of the home network, wherein the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network. It is determined that there is at least one outstanding subscription to the aforementioned private network of the visited location, While the at least one pending subscription is active, the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network is maintained. One or more processors configured to perform the following: Network components, including
10. The network component according to claim 9, wherein the one or more processors are further configured to execute computer-readable instructions to rewrite a callback URI (Uniform Resource Identifier) signaled by the network function of the visited private network and received by the security edge protected proxy of the home network to a URI that returns to the security edge protected proxy of the home network.
11. The one or more processors execute the computer-readable instructions to restore the Diameter origin host and origin information from the subscription request. The network component according to claim 9 or 10, further configured to enable routing of server startup messages originating within the home network to the visited private network by updating routing information within the home network.
12. The one or more processors execute the computer-readable instructions, It is determined that the subscription of the user device to the aforementioned private network has ended, Terminate the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network. The network component according to claim 9 or 10, further configured to perform the following:
13. The one or more processors execute the computer-readable instructions, The determination that the timer has expired, and that the timer defines or determines the duration of the communication protocol. When it is determined that the timer has expired, the communication protocol between the home network and the private network of the visited location is terminated. The network component according to claim 9 or 10, further configured to perform the following:
14. If the visited private network is a private 5G network, a bidirectional N32 interface is used to transfer signals between the visited private network and the home network using the communication protocol. The network component according to claim 9 or 10, wherein, if the visited private network is a private LTE network, it uses the S6a interface to transfer signals between the visited private network and the home network using the communication protocol.
15. One or more non-temporary computer-readable media containing computer-readable instructions, wherein when the computer-readable instructions are executed by one or more processors of a network component, the network component is configured to: Receiving a subscription request from the user's device to operate on the visited private network, The determination that the user device is associated with the home network, Establishing a communication protocol between the security edge protected proxy of the visited private network and the security edge protected proxy of the home network, wherein the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network. It is determined that there is at least one outstanding subscription to the aforementioned private network of the visited location, While the at least one pending subscription is active, the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network is maintained. One or more non-temporary computer-readable media that perform the following actions.
16. The one or more non-temporary computer-readable media according to claim 15, wherein the execution of the computer-readable instructions by the one or more processors is signaled by the network function of the visited private network and received by the security edge protected proxy of the home network, and the one or more processors are further caused to rewrite the callback URI (Uniform Resource Identifier) to a URI that returns to the security edge protected proxy of the home network.
17. The execution of the computer-readable instructions by the one or more processors further causes the one or more processors to enable the routing of server startup messages originating within the home network to the visited private network by restoring the Diameter origin host and origin information from the subscription request and updating the routing information within the home network.
18. The execution of the computer-readable instruction by the one or more processors is It is determined that the subscription of the user device to the aforementioned private network has ended, Terminate the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network. The one or more non-temporary computer-readable media according to claim 15 or 16, further comprising having one or more processors perform the same operation.
19. The execution of the computer-readable instruction by the one or more processors is The determination that the timer has expired, and that the timer defines or determines the duration of the communication protocol. When it is determined that the timer has expired, the communication protocol between the home network and the private network of the visited location is terminated. The one or more non-temporary computer-readable media according to claim 15 or 16, further comprising having one or more processors perform the same operation.
20. If the visited private network is a private 5G network, a bidirectional N32 interface is used to transfer signals between the visited private network and the home network using the communication protocol. If the visited private network is a private LTE network, one or more non-temporary computer-readable media according to claim 15 or 16, which use the S6a interface to transfer signals between the visited private network and the home network using the communication protocol.
21. A means for receiving subscription requests from user devices to operate on the visited private network, Means for determining that the user device is associated with a home network, Means for establishing a communication protocol between the security edge protected proxy of the visited private network and the security edge protected proxy of the home network, A means for determining that there is at least one outstanding subscription to the aforementioned private network of the visited location, Means for maintaining the communication protocol between the security edge protected proxy of the home network and the security edge protected proxy of the visited private network while the at least one pending subscription is active, Includes, A device in which the communication protocol enables the exchange of bidirectional roaming signals between the visited private network and the home network while the user device is operating on the visited private network.
22. The apparatus according to claim 21, further comprising means for carrying out the method described in claim 2.
23. A computer program, a computer program product, or a computer-readable medium that, when executed by a computer, includes instructions causing the computer to perform the steps of the method described in claim 1.
Citation Information
Patent Citations
Re-authentication procedure for security key (KAUSF) generation and steering of roaming (SOR) data delivery
US20200344606A1
Network node
WO2020208913A1