Message routing methods, devices, systems, storage media, and electronic devices
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2023-05-12
- Publication Date
- 2026-08-04
Smart Images

Figure 0007900529000001 
Figure 0007900529000002 
Figure 0007900529000003
Abstract
Description
Cross-reference to Related Applications
[0001] This disclosure claims the priority of Chinese Patent Application No. CN202210760237.4, titled "Message Routing Method, Apparatus, and System", filed on June 29, 2022, and all of its content is incorporated herein by reference.
Technical Field
[0002] This disclosure relates to the field of communications, and more specifically, to a message routing method 、 apparatus, and system , storage media and electronic devices thereof.
Background Art
[0003] In some cases, a network that roams between 5G SA (Standalone) defined by 3GPP (registered trademark) and a PLMN (Public Land Mobile Network) includes a SEPP (Security Edge Protection Proxy), an AMF (Access and Mobility Management Function), a UDM (Unified Data Management), an NRF (NF Repository Function), etc.
[0004] In some cases, SEPP acts as a security edge protection proxy for PLMNs, responsible for forwarding control plane signaling for interactions between PLMNs. As an example, consider a typical VPLMN (Visited Public Land Mobile Network) AMF network element accessing a UDM network element in an HPLMN (Home Public Land Mobile Network). Figure 1 shows an interactive flowchart between PLMNs in the relevant technology of this disclosure. As can be seen from the interactive process in Figure 1, in some cases, there is a technical issue of signaling bypass from the VPLMN to the HPLMN. [Overview of the Initiative] [Problems that the invention aims to solve]
[0005] This disclosure provides a message routing method, apparatus, and system that at least solves the technical problem of signaling bypass when PLMNs interact with each other.
[0006] According to one embodiment of the present disclosure, a method for routing messages applied to a security edge protected proxy VSEPP of a visited public land mobile network is provided, the method comprising: receiving a service request message and first routing parameters transmitted by a first network function NF, wherein the first routing parameters carry network repository function NRF discovery parameters and a user identifier, and the first NF resides within the visited public land mobile network VPLMN; and routing the service request message and NRF discovery parameters to a security edge protected proxy HSEPP of a local public land mobile network according to the user identifier, wherein the HSEPP routes the service request message to a second NF based on the NRF discovery parameters, and the second NF resides within the local public land mobile network HPLMN.
[0007] According to one embodiment of the present disclosure, an alternative message routing method is provided that applies to a security edge protected proxy HSEPP of a local public land mobile network, the method comprising: receiving a service request message and a second routing parameter to be routed by a security edge protected proxy VSEPP of a destination public land mobile network; routing the service request message to a second network function NF according to the second routing parameter, the second NF staying within HPLMN; receiving a response message returned by the second NF based on the service request message; and sending the response message to VSEPP.
[0008] Another embodiment of the present disclosure provides a message routing device applied to a security edge protected proxy VSEPP of a visited public land mobile network, the device comprising: a first receiving module configured to receive a service request message and first routing parameters transmitted by a first network function NF, wherein the first routing parameters carry a network repository function NRF discovery parameter and a user identifier, and the first receiving module resides in a visited public land mobile network VPLMN; and a routing module configured to route the service request message and NRF discovery parameter to a security edge protected proxy HSEPP of a local public land mobile network according to the user identifier, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameter, the routing module resides in a local public land mobile network HPLMN.
[0009] Another embodiment of the present disclosure provides a message routing device applicable to a local public land mobile network security edge protected proxy HSEPP, the device comprising: a first receiving module configured to receive a request for service message and a second routing parameter routed by a destination public land mobile network security edge protected proxy VSEPP; a routing module configured to route the request for service message to a second network function NF according to the second routing parameter, wherein the second NF resides within HPLMN; a second receiving module configured to receive a response message returned by the second NF based on the request for service message; and a transmitting module configured to send the response message to VSEPP.
[0010] Another embodiment of this disclosure further provides a message routing system that includes a destination public land mobile network security edge protection proxy VSEPP, which includes the device described in the above embodiment, and a local public land mobile network security edge protection proxy HSEPP, which includes the device described in the above embodiment.
[0011] Another embodiment of the present disclosure further provides a computer-readable storage medium in which a computer program is stored, and the computer program is configured, when executed, to perform the steps in any one embodiment of the method described above.
[0012] Another embodiment of the present disclosure further provides an electronic device including a memory and a processor, wherein a computer program is stored in the memory and the processor is configured to execute the computer program to perform the steps in any one embodiment of the method described above.
[0013] The drawings described herein are provided for further understanding of the Disclosure and constitute part of the Disclosure. The exemplary embodiments and descriptions thereof are used to illustrate the Disclosure and do not unduly limit the Disclosure. [Brief explanation of the drawing]
[0014] [Figure 1] This is an interactive flowchart between PLMNs in the technology related to this disclosure. [Figure 2] This is a block diagram of the hardware structure of the message routing server as disclosed in this document. [Figure 3] This is a flowchart illustrating the message routing method described in this disclosure. [Figure 4] This is a network architecture diagram applicable to this disclosure. [Figure 5] This is a network architecture diagram of PLMN in this disclosure. [Figure 6] This is a flowchart illustrating the routing method for another message as described in this disclosure. [Figure 7] This is a UDM interactive diagram showing how the AMF of the VPLMN in this disclosure accesses the HPLMN. [Figure 8] This is a structural block diagram of the message routing device described in this disclosure. [Figure 9] This is a structural block diagram of a routing device for another message as disclosed in this disclosure. [Figure 10] This is a block diagram of the message routing system structure as disclosed in this document. [Modes for carrying out the invention]
[0015] The present invention will be described in detail below with reference to the attached drawings and in conjunction with embodiments. The embodiments and features described herein may be combined in any way that does not contradict each other.
[0016] Note that terms such as "first", "second", etc. in the specification, claims, and the above-mentioned drawings of the present disclosure are used to distinguish similar objects, but are not necessarily used to explain a specific order or sequence.
[0017] In some cases, the SEPP transfers control plane signaling for interaction between PLMNs as a security edge protection proxy of the PLMN. As an example, consider that an AMF network element of a typical VPLMN (Visited Public Land Mobile Network) accesses a UDM network element in an HPLMN (Home Public Land Mobile Network). FIG. 1 is an interactive flowchart between PLMNs in the related art of the present disclosure. As can be seen from the interactive process in FIG. 1, in some cases, there is a signaling detour from the VPLMN to the HPLMN, resulting in a significant delay in service processing. All response messages for service discovery are relatively large, and a large amount of bandwidth resources are required between the VPLMN and the HPLMN. The AMF of the VPLMN needs to subscribe to the state of the UDM of the HPLMN, and a UDM state change notification needs to be sent between the VPLMNs. There is a high possibility that the notification cannot be reached and it will affect the service.
[0018] Example 1 The embodiments of the method according to Embodiment 1 of the present disclosure may be executed by a base station, a server, a base station controller, or a similar network element. Taking execution on a server as an example, FIG. 2 is a hardware structure block diagram of a message routing server according to the present disclosure. FIG. 2 As shown in FIG., the server has one or more (FIG. 2It may include only one processor 102 (the processor 102 may include a processing device such as a microprocessor MCU or a programmable logic device FPGA, but is not limited thereto), and a memory 104 for storing data. In an exemplary embodiment, the above server may further include a transmitter 106 and an input / output device 108 for communication functions. Those skilled in the art can understand that the structure shown in FIG. 2 is merely an example, and it is not intended to limit the structure of the above server. For example, the server may have more or fewer components than those shown in FIG. 2 , or may further include a configuration different from that shown in FIG. 2 .
[0019] The memory 104 may be used to store software programs and modules of application software, such as a computer program corresponding to the message routing method in the present disclosure. The processor 102 may execute various functional applications and data processing by executing the computer program stored in the memory 104, that is, implement the above method. The memory 104 may include high-speed random access memory, and may further include non-volatile memory such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some examples, the memory 104 may further include a memory remotely located with respect to the processor 102, and these remote memories may be connected to the server via a network. Examples of the above network include, but are not limited to, the Internet, intranet, local area network, mobile communication network, and combinations thereof.
[0020] The transmitting device 106 is used to send and receive data over a network. Specific examples of the network described above may include a wireless network provided by the server's telecommunications carrier. In one example, the transmitting device 106 includes a network interface controller (NIC) that can connect to other network devices via the server to communicate with the Internet. In another example, the transmitting device 106 may be a radio frequency (RF) module for wirelessly communicating with the Internet.
[0021] In this embodiment, a message routing method is provided, and Figure 3 is a flowchart of the message routing method according to this disclosure, which is applied to VSEPP (Visited Public Land Mobile Network Security Edge Protection Proxy) as shown in Figure 3, and the process includes the following steps.
[0022] In step S302, the service request message and first routing parameters sent by the first network function NF are received, where the first routing parameters carry network repository function NRF discovery parameters and a user identifier, and the first NF resides within the destination public land mobile communication network VPLMN.
[0023] In an exemplary embodiment, the user identifier may be a SUPI (SUbs cription Permanent Identifier), and the first NF is connected to the user equipment (UE), and the UE uses its own SUPI when initiating a service request to the first NF.
[0024] Figure 4 is a network architecture diagram applicable to this disclosure. Messages are roamed between two networks, VPLMN and HPLMN. VPLMN includes network elements such as AMF, SMF (Session Management Function), (R)AN (Access Network, or Radio Access Network), UPF (User Plan Function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (NF Repository Function), PCF (Policy Control Function), and VSEPP. HPLMN includes network elements such as UDM, NRF, NEF, NSSF, HSEPP, SMF, AUSF (Authentication Server Function), PCF, AF (Application Function), NSSAAF (Network Slice-Specific Authentication and Authorization Function), UPF, and DN (Data Network, e.g., Operator Services, Internet Access, Third-Party Services).
[0025] In step S304, the service request message and NRF discovery parameters are routed to the local public land mobile network security edge protection proxy HSEPP according to the user identifier, so that the HSEPP routes the service request message to a second NF according to the NRF discovery parameters, where the second NF resides within the HPLMN.
[0026] In this embodiment, the first NF is a network element of the VPLMN other than VSEEP that can initiate a service request, such as an AMF, and the second NF is a network element of the HPLMN other than HSEEP that can process a service request, such as a UDM. Figure 5 is a network architecture diagram of the PLMN in this disclosure, which includes the first NF and the second NF, which are the network element that initiates service access and the network element that responds to service access in the VPLMN, respectively, vSEPP is the SEPP network element of the VPLMN network, and hSEPP is the SEPP network element of the HPLMN network.
[0027] The above steps involve receiving a service request message and first routing parameters transmitted by the first network function (NF), the first routing parameters carrying the network repository function (NRF discovery parameters) and user identifier, the first NF staying within the destination public land mobile network (VPLMN), and routing the service request message and NRF discovery parameters to the local public land mobile network's security edge protection proxy (HSEPP) according to the user identifier, the HSEPP routing the service request message to the second NF according to the NRF discovery parameters, the second NF staying within the HPLMN, the VSEPP no longer executing the discovery request for the second NF, and directly routing the NRF discovery parameters carrying the network repository function to the HSEPP, the HSEPP executing the discovery request and routing the service request message, thereby reducing message detours between PLMNs, solving the technical problem in related technologies of interactive signaling detours between PLMNs, reducing the number of signaling interactions during service processing, and reducing processing delay and network resource overhead.
[0028] In this embodiment, the service request message and NRF discovery parameters are routed to the security edge protection proxy HSEPP of the local public land mobile network according to the user identifier, and then a response message is received from a second NF returned by HSEPP, wherein the response message is a response message generated by the second NF after receiving the service request message and completing the service processing, and the response message is sent to the first NF.
[0029] In an exemplary embodiment, when routing a message between PLMNs, the first NF directly sends an HTTP2 Service Request message carrying NRF Discovery parameters to the VPLMN SEPP in the VPLMN network. Receiving the service request message and first routing parameters sent by the first NF includes receiving the HTTP2 Service Request message sent by the first NF, the service request message including the HTTP2 Service Request message carrying the first routing parameters.
[0030] In one example, an HTTP2 Service Request message carries a first set of routing parameters: a user permanent identifier (SUPI) for accessing the UE, an authorization identifier, and an NRF discovery identifier. Here, the authorization identifier is used to indicate the Fully Qualified Domain Name (FQDN) or IP address of the VSEPP that interacts with the HPLMN to which the user permanent identifier (SUPI) belongs, and the NRF discovery identifier is used to indicate the discovery parameters necessary for the first NF to discover the second NF.
[0031] The first NF requires the second NF to interact, the first NF determines that the user belongs to an HPLMN based on the user's SUPI identifier, and the first NF encapsulates an HTTP request message that includes at least the FQDN or IP address of the SEPP to interact with the HPLMN to which the user's SUPI belongs in the VPLMN, and routing parameters such as 3gpp-Sbi-Discovery-*=* (NRF discovery identifier), where * is a general term that carries discovery parameters necessary for the AMF to discover the UDM.
[0032] In this embodiment, an alternative message routing method is provided, and Figure 6 is a flowchart of the alternative message routing method according to this disclosure, which is applied to HSEPP, and as shown in Figure 6, the process includes the following steps S602 to S608.
[0033] In step S602, the service request message and second routing parameters are received, which are routed by the security edge protection proxy VSEPP of the visited public land mobile communication network.
[0034] In one example, the second routing parameter includes the HSEPP's FQDN or IP address and the network repository function NRF discovery parameter carried by the first routing parameter.
[0035] In step S604, the service request message is routed to the second network function NF according to the second routing parameter, where the second NF resides within HPLMN.
[0036] In step S606, the response message returned by the second NF based on the service request message is received.
[0037] Step S608: Send a response message to VSEPP.
[0038] In one embodiment of this embodiment, routing a service request message to a second network function NF according to a second routing parameter includes S11, creating a discovery request message using a network repository function NRF discovery parameter and a second routing parameter carrying the fully qualified domain name (FQDN) or IP address of the NRF in HPLMN; S12, sending the request message to the NRF in HPLMN; and S13, routing the service request message to the second NF according to the discovery result returned by the NRF.
[0039] In one example, routing a service request message to a second NF according to the discovery results returned by the NRF includes receiving several second NF identifiers returned by the NRF based on the request message, selecting the target second NF from among the several second NF identifiers, and sending the service request message to the target second NF.
[0040] Let the first NF be the AMF and the second NF be the UDM. The solution of this embodiment will be interpreted and described in detail, and Figure 7 is a UDM interactive diagram in which the AMF of the VPLMN accesses the HPLMN in this disclosure, and includes the following steps.
[0041] Step 1, the AMF needs to interact with the UDM. The AMF determines that the user belongs to an HPLMN based on the user's SUPI identifier. The AMF encapsulates an HTTP2 request message, which includes at least the FQDN or IP address of the VSEPP for interacting with the HPLMN to which the user's SUPI belongs in the VPLMN, and routing parameters 3gpp-Sbi-Discovery-*=*, where * is a general term for the discovery parameters that the AMF needs to discover the UDM. The AMF then sends the message to the SEPP (VSEPP, i.e., VPLMN SEPP) for interacting with the HPLMN to which the user's SUPI belongs in the pre-configured VPLMN.
[0042] Step 2, the VPLMN SEPP receives the HTTP2 request message sent by the AMF, reads the user identifier, retrieves the SEPP information for the HPLMN to which user SUPI belongs based on the routing policy information, encapsulates the HTTP2 request message, and forwards the parameters carried by the AMF as is, including at least:authority=FQDN or IP address of the SEPP in the HPLMN, and 3gpp-Sbi-Discovery-*=*, where * is a general term.
[0043] Step 3, hSEPP receives the service request sent from vSEPP, extracts the 3gpp-Sbi-Discovery-* related parameters from the request, encapsulates an NRF discovery request that includes the parameter :authority=FQDN or IP address of the NRF in HPLMN, populates the service discovery related parameters according to the 3gpp-Sbi-Discovery-* parameters carried to vSEPP, and sends the NRF discovery request to the NRF in HPLMN.
[0044] Step 4, HPLMN NRF returns the UDM discovery results, which include at least the FQDN or IP address of the available UDMNF.
[0045] Step 5, hSEPP receives the UDM discovery results returned by the NRF, selects a UDM from one or more UDM NFs, and sends the service request received in Step 3 to the selected UDM, including the parameter :authority=UDM's FQDN or IP address, instructing it to remove the associated 3gpp-Sbi-Discovery-* parameters.
[0046] Step 6, the UDM receives the request message, completes the service processing, and returns a response message to hSEPP via the original route.
[0047] Step 7, hSEPP returns the response message to vSEPP via the original route.
[0048] Step 8, vSEPP returns the response message to AMF via the original route.
[0049] Step 9, finish.
[0050] Using this embodiment, the VPLMN NF directly sends a signaling message carrying NRF Discovery parameters to the SEPP without performing discovery between PLMNs. The VPLMN routes the message to the HPLMN SEPP according to the user identifier in the signaling. The HPLMN retrieves the NRF Discovery parameters from the signaling and sends them to the NRF to perform service discovery. From the service discovery results, it retrieves the target NF and forwards the message to the target NF.
[0051] The solution in this embodiment optimizes the process in the related technology, reduces the number of signaling interactions, changes the number of signaling interactions between PLMNs from two to one, improves network efficiency, eliminates signaling bypass in the signaling interactions between PLMNs, has low latency, eliminates the need to transmit NRF service discovery results between PLMNs, and since the NRF service discovery result message is relatively large, the solution in this embodiment reduces the bandwidth requirements.
[0052] Through the description of the embodiments above, those skilled in the art will clearly understand that the methods according to the embodiments may be implemented by software and a necessary general hardware platform, or by hardware, and that in many cases the former is a better embodiment. Based on this understanding, the technical solutions of the present disclosure can essentially implement the parts that contribute to the prior art in the form of a software product, which is stored in a storage medium (e.g., ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing terminal equipment (such as a mobile phone, computer, server, or network equipment) to perform the methods of the various embodiments of the present disclosure.
[0053] Example 2 In this embodiment, a message routing device and system are further provided, which are used to implement the above-described embodiment and preferred embodiment, and the descriptions already provided will not be repeated. As used below, the term “module” may be implemented as a combination of software and / or hardware with a predetermined function. The devices described in the following embodiments are preferably implemented in software, but can also be implemented in hardware, or as a combination of software and hardware.
[0054] Figure 8 is a structural block diagram of a message routing device according to this disclosure, which is applied to a security edge protection proxy VSEPP of a destination public land mobile communication network as shown in Figure 8, and the device includes a first receiving module 80 and a routing module 82.
[0055] The first receiving module 80 is configured to receive a service request message and first routing parameters transmitted by the first network function NF. Here, the first routing parameters carry network repository function NRF discovery parameters and a user identifier, and the first NF resides within the destination public land mobile communication network VPLMN.
[0056] The routing module 82 is configured to route service request messages and NRF discovery parameters to the local public land mobile network security edge protection proxy HSEPP according to the user identifier, so that the HSEPP routes the service request messages to the second NF according to the NRF discovery parameters, and the second NF resides within the HPLMN.
[0057] In an exemplary embodiment, the device further includes a second receiving module configured to route a service request message and NRF discovery parameters to a security edge protected proxy HSEPP of a local public land mobile network according to a user identifier, and then receive a response message from a second NF returned by HSEPP, wherein the response message is a response message generated by the second NF after receiving the service request message and completing service processing; and a transmitting module configured to transmit the response message to a first NF.
[0058] In an exemplary embodiment, the first receiving module includes a receiving unit configured to receive an HTTP2 Service Request message sent by a first NF, wherein the service request message includes an HTTP2 Service Request message carrying first routing parameters.
[0059] In an exemplary embodiment, an HTTP2 Service Request message carries a first routing parameter consisting of a user permanent identifier (SUPI) accessing the UE, an authorization identifier, and an NRF discovery identifier, where the authorization identifier is used to indicate the fully qualified domain name (FQDN) or IP address of the VSEPP interacting with the HPLMN to which the user permanent identifier (SUPI) belongs, and the NRF discovery identifier is used to indicate the discovery parameters necessary for the first NF to discover the second NF.
[0060] Figure 9 is a structural block diagram of a routing device for another message according to the present disclosure, which is applied to a security edge protection proxy HSEPP of a local public land mobile network as shown in Figure 9, and the device includes a first receiving module 90, a routing module 92, a second receiving module 94, and a transmitting module 96.
[0061] The first receiving module 90 is configured to receive a service request message and second routing parameters routed by the security edge protection proxy VSEPP of the visited public land mobile communication network, the routing module 92 is configured to route the service request message to a second network function NF according to the second routing parameters, where the second NF resides within the HPLMN, the second receiving module is configured to receive a response message returned by the second NF based on the service request message, and the transmitting module 96 is configured to send the response message to VSEPP.
[0062] In an exemplary embodiment, the routing module includes a creation unit configured to create a discovery request message using network repository function NRF discovery parameters and a second routing parameter carrying the fully qualified domain name (FQDN) or IP address of the NRF in the HPLMN; a transmission unit configured to send the request message to the NRF in the HPLMN; and a routing unit configured to route the service request message to the second NF according to the discovery result returned by the NRF.
[0063] In an exemplary embodiment, the routing unit includes a receiving subunit configured to receive several second NF identifiers returned by the NRF based on a request message, and a transmitting subunit configured to select a target's second NF from among several second NF identifiers and send a service request message to the target's second NF.
[0064] Another embodiment of the present disclosure further provides a message routing system that includes a destination public land mobile network security edge protection proxy VSEPP, which includes the device described in the above embodiment, and a local public land mobile network security edge protection proxy HSEPP, which includes the device described in the above embodiment.
[0065] Figure 10 is a structural block diagram of the message routing system according to this disclosure. As shown in Figure 10, the system includes VSEPP100, which includes the apparatus of the embodiment described above, and HSEPP102, which includes the apparatus of the embodiment described above.
[0066] Each of the above modules may be implemented through software or hardware, and in the latter case, all of the above modules may be placed in the same processor, or they may be implemented in any combination on different processors, and are not limited to these.
[0067] Example 3 Embodiments of the present disclosure further provide a computer-readable storage medium in which a computer program is stored, the computer program being configured, when executed, to perform the steps of any one embodiment of the method described above.
[0068] In an exemplary embodiment, the computer-readable storage medium described above may be configured to store a computer program for performing the following steps: S1, receive a service request message and first routing parameters transmitted by a first network function NF, where the first routing parameters carry network repository function NRF discovery parameters and a user identifier, and the first NF stays within the destination public land mobile network VPLMN; S2, route the service request message and NRF discovery parameters to a security edge protected proxy HSEPP of the local public land mobile network according to the user identifier, so that the HSEPP routes the service request message to a second NF based on the NRF discovery parameters, and the second NF stays within the local public land mobile network HPLMN.
[0069] In exemplary embodiments, the computer-readable storage medium described above includes, but is not limited to, various media capable of storing computer programs, such as U disks, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical disks.
[0070] Embodiments of the present disclosure further provide an electronic device including a memory and a processor, wherein a computer program is stored in the memory and the processor is configured to execute the computer program and perform the steps in any one embodiment of the method described above.
[0071] In the exemplary embodiment, the electronic device may further include a transmitting device connected to the processor and an input / output device connected to the processor.
[0072] In an exemplary embodiment, the processor may be configured to perform the following steps via a computer program: S1, receive a service request message and first routing parameters transmitted by a first network function NF, the first routing parameters including network repository function NRF discovery parameters and a user identifier, the first NF resides in the destination public land mobile network VPLMN; S2, route the service request message and NRF discovery parameters to the local public land mobile network security edge protection proxy HSEPP according to the user identifier, the HSEPP then routes the service request message to a second NF based on the NRF discovery parameters, the second NF resides in the HPLMN.
[0073] In the exemplary embodiments, specific examples in these embodiments can be found by referring to the examples described in the above embodiments and the optional embodiments, and will not be described again in these embodiments.
[0074] This disclosure provides a solution in which a first network function (NF) receives a service request message and first routing parameters, where the first routing parameters carry network repository function (NRF) discovery parameters and a user identifier. The first NF resides within the destination public land mobile network (VPLMN) and routes the service request message and NRF discovery parameters to the local public land mobile network's security edge protection proxy (HSEPP) according to the user identifier. The HSEPP then routes the service request message to a second NF based on the NRF discovery parameters. The second NF resides within the HPLMN, and the VSEPP no longer executes the discovery request for the second NF. Instead, it directly routes the NRF discovery parameters carrying the network repository function to the HSEPP, which executes the discovery request and routes the service request message. This reduces message detours between PLMNs, solves the technical problem in related technologies of inter-PLMN interactive signaling detours, reduces the number of signaling interactions during service processing, and reduces processing delay and network resource overhead.
[0075] Clearly, those skilled in the art will understand that each module or step of the present disclosure described above can be implemented using a general-purpose computing device, which may be centralized in a single computing device or distributed across a network of multiple computing devices, which in exemplary implementations may be implemented in program code executable by the computing device, which may be stored in a memory device and executed by the computing device, which may, in some cases, be implemented by executing the illustrated or described steps in a different order than specified herein, or by manufacturing them individually in separate integrated circuit modules, or by manufacturing multiple modules or steps among them in a single integrated circuit module. Thus, the present disclosure is not limited to any particular combination of hardware and software.
[0076] The foregoing are merely preferred embodiments of the Disclosure and are not intended to limit the Disclosure. Those skilled in the art can modify and alter the Disclosure in various ways. Any modifications, equivalent substitutions, improvements, etc., made within the principles of the Disclosure shall be within the scope of the Disclosure.
Claims
1. A method for routing messages applied to a security edge protected proxy VSEPP of a visited public land mobile communication network, The process involves receiving a service request message and first routing parameters transmitted by a first network function NF, wherein the first routing parameters carry network repository function NRF discovery parameters and a user identifier, and the first NF remains within the visited public land mobile network VPLMN. The service request message and the NRF discovery parameters are routed to a security edge protection proxy HSEPP of the local public land mobile network according to the user identifier, the HSEPP then routes the service request message to a second NF according to the NRF discovery parameters, the second NF resides within the local public land mobile network HPLMN. How to route messages.
2. After routing the service request message and the NRF discovery parameters to the local public land mobile network security edge protection proxy HSEPP according to the user identifier, the method then: Receiving a response message from the second NF returned by the HSEPP, wherein the response message is a response message generated by the second NF after receiving the service request message and completing the service processing. The further includes sending the response message to the first NF, The method according to claim 1.
3. Receiving the service request message and first routing parameters sent by the first NF means that This includes receiving an HTTP2 Service Request message transmitted by the first NF, wherein the service request message includes the HTTP2 Service Request message carrying the first routing parameters. The method according to claim 1.
4. The HTTP2 Service Request message carries first routing parameters: a user permanent identifier (SUPI) for accessing the UE, an authorization identifier, and an NRF discovery identifier, wherein the authorization identifier is used to indicate the fully qualified domain name (FQDN) or IP address of the VSEPP interacting with the HPLMN to which the user permanent identifier (SUPI) belongs, and the NRF discovery identifier is used to indicate the discovery parameters necessary for the first NF to discover the second NF. The method according to claim 3.
5. A method for routing messages applicable to a security edge protected proxy HSEPP of a local public land mobile communications network, The system receives a service request message and a second routing parameter routed by the security edge protection proxy VSEPP of the visited public land mobile communication network, The service request message is routed to the second network function NF according to the second routing parameters, wherein the second NF resides within HPLMN. Receiving a response message returned by the second NF based on the service request message, Further comprising sending the response message to the VSEPP, How to route messages.
6. Routing the service request message to the second network function NF according to the second routing parameter is: A discovery request message is created using the NRF discovery parameters of the network repository function and the second routing parameters that carry the fully qualified domain name (FQDN) or IP address of the NRF in the HPLMN. Sending the request message to the NRF in the HPLMN, This includes routing the service request message to a second NF according to the discovery result returned by the aforementioned NRF, The method according to claim 5.
7. Routing the service request message to the second NF according to the discovery result returned by the aforementioned NRF is: Based on the aforementioned request message, receive several second NF identifiers returned by the NRF, This includes selecting the target's second NF from among several second NF identifiers and sending the service request message to the target's second NF, The method according to claim 6.
8. A message routing device applied to the VSEPP security edge protection proxy of a visited public land mobile communication network, A first receiving module for receiving a service request message and first routing parameters transmitted by a first network function NF, wherein the first routing parameters carry network repository function NRF discovery parameters and a user identifier, and the first NF is located within a visited public land mobile communication network VPLMN, A routing module for routing the service request message and the NRF discovery parameters to a security edge protection proxy HSEPP of a local public land mobile network according to the user identifier, the HSEPP routing the service request message to a second NF according to the NRF discovery parameters, the second NF including a routing module residing within the local public land mobile network HPLMN, A message routing device.
9. A message routing device applicable to a security edge protection proxy HSEPP of a local public land mobile communications network, A first receiving module for receiving service request messages and second routing parameters routed by the security edge protection proxy VSEPP of the visited public land mobile communication network, A routing module for routing the service request message to a second network function NF according to the second routing parameters, wherein the second NF is a routing module located within HPLMN, A second receiving module for receiving a response message returned by the second NF based on the service request message, Includes a transmission module for sending the response message to the VSEPP, A message routing device.
10. A security edge protection proxy VSEPP for a visited public land mobile network, including the device described in claim 8, and a security edge protection proxy HSEPP for a local public land mobile network, including the device described in claim 9, A message routing system.
11. A computer-readable storage medium in which a computer program is stored, wherein the computer program is configured to perform the method described in any one of claims 1 to 4 when executed. A computer-readable storage medium.
12. A computer-readable storage medium storing a computer program, wherein the computer program is configured to perform the method described in any one of claims 5 to 7 when executed. A computer-readable storage medium.
13. An electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the computer program and to perform the method according to any one of claims 1 to 4. electronic equipment.
14. An electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the computer program and to perform the method according to any one of claims 5 to 7. electronic equipment.