First node, second node, third node, communications system and methods performed thereby for handling information
The method addresses the challenges of handling encrypted traffic by using a first node to determine the domain of an external node through DNS zone information and initiate appropriate traffic management, thereby improving network performance and user experience.
Patent Information
- Application Number
- PCT/EP2023/087569
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-27
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-05
AI Technical Summary
Existing methods for handling traffic in communications networks, particularly with encrypted traffic, lead to poor performance characterized by increased latency and low quality of experience due to challenges in traffic classification and management.
A computer-implemented method involving a first node that detects a flow of traffic between a device and another node, determines the domain of the external node using stored DNS zone information, and initiates traffic management based on this determination, thereby enabling effective classification and optimization of encrypted traffic.
This approach allows for improved traffic management in communications systems, enabling efficient classification of encrypted traffic and application of optimization techniques, such as Adaptive Bitrate Streaming, to enhance user experience and network performance.
Smart Images

Figure EP2023087569_05062025_PF_FP_ABST
Abstract
Description
[0001] FIRST NODE, SECOND NODE, THIRD NODE, COMMUNICATIONS SYSTEM AND METHODS PERFORMED THEREBY FOR HANDLING INFORMATION
[0002] TECHNICAL FIELD
[0003] The present disclosure relates generally to a first node and methods performed thereby for handling information. The present disclosure also relates generally to a second node, and methods performed thereby for handling the information. The present disclosure further relates generally to a third node, and methods performed thereby for handling the information. The present disclosure also relates generally to a communications system, and methods performed thereby for handling the information.
[0004] BACKGROUND
[0005] Computer systems in a communications network or communications system may comprise one or more nodes. A node may comprise a processing circuitry which, together with computer program code may perform different functions and actions, a memory, a receiving port, and a sending port. A node may be, for example, a server. Nodes may perform their functions entirely on the cloud.
[0006] The communications system may cover a geographical area which may be divided into cell areas, each cell area being served by a type of node, a network node in the Radio Access Network (RAN), radio network node or Transmission Point (TP), for example, an access node such as a Base Station (BS), e.g., a Radio Base Station (RBS), which sometimes may be referred to as e.g., gNB, evolved Node B (“eNB”), “eNodeB”, “NodeB”, “B node”, or Base Transceiver Station (BTS), depending on the technology and terminology used. The base stations may be of different classes such as e.g., Wide Area Base Stations, Medium Range Base Stations, Local Area Base Stations, and Home Base Stations, based on transmission power and thereby also cell size. A cell may be understood to be the geographical area where radio coverage may be provided by the base station at a base station site. One base station, situated on the base station site, may serve one or several cells. Further, each base station may support one or several communication technologies. The telecommunications network may also comprise network nodes which may serve receiving nodes, such as user equipments, with serving beams.
[0007] The standardization organization Third Generation Partnership Project (3GPP) is currently in the process of specifying a New Radio Interface called Next Generation Radio or New Radio (NR) or 5G-Universal Terrestrial Radio Access (UTRA), as well as a Fifth Generation (5G) Packet Core Network, which may be referred to as 5G Core Network (5GC), abbreviated as 5GC. Figure 1 is a schematic diagram depicting a particular example of a 5G reference architecture of a policy and charging control framework, as defined by 3GPP, which may be used as a reference for the present disclosure. An Application Function (AF) 1 may provide a service in the communications system and may interact with the 3GPP Core Network through a Network Exposure Function (NEF) 2. The AF 1 may allow external parties to use the Exposure Application Programming Interfaces (APIs) offered by the network operator. In case the AF 1 is trusted, e.g., internal to the network operator, the AF 1 may interact with the 3GPP Core Network directly, with no NEF 2 involved. The NEF 2 may support different functionality. Specifically, the NEF 2 may support different Exposure APIs, such as, for example, a NEF Application Programming Interface (API) for Packet Flow Description (PFD) Management. The NEF 2 may therefore be understood in such examples to comprise a PFD Function (PFDF). Management of Packet Flow Descriptions (PFDs) may be understood to refer to a capability to create, update or remove PFDs in the NEF 2 (PFDF), and the distribution from the NEF 2 (PFDF) to a Session Management Function (SMF) 3 and finally to a User Plane function (UPF) 4. This feature may be used when the UPF 4 may be configured to detect a particular application provided by an Application Service Provider (ASP). The SMF 3 may support different functionalities, e.g., the SMF 3 may receive Policy and Charging Control (PCC) rules from the Policy Control Function (PCF) 5 and may configure the UPF 4 accordingly. The UPF 4 may support handling of user plane traffic, including packet inspection, packet routing and forwarding, traffic usage reporting, and Quality of Service (QoS) handling for user plane, e.g., UL / DL rate enforcement, based on the rules received from the SMF 3. The User Plane may receive PFDs from the AF 1 through the NEF 2 and SMF 3. The SMF 3 may receive the PFD from the NEF 2, and convert it to applications and filters in Packet Detection Rules (PDRs) to be sent to the UPF 4. A Unified Data Repository (UDR) 6 may store data, grouped into distinct collections of subscription-related information: subscription data, policy data, structured data for exposure, and application data. Particularly relevant for this disclosure, stored data may comprise subscription policy data to be used by the PCF 5. The PCF 5 may support a unified policy framework to govern the network behavior.
[0008] Specifically, the PCF 5 may provide PCC rules to a Policy and Charging Enforcement Function (PCEF), that is, the SMF 3 and / or the UPF 4 that may enforce policy and charging decisions according to provisioned PCC rules. A Charging Function (CHF) 7 may support charging related functionality, specifically online and offline charging. The PCF 5 may provide policy rules to a User Equipment (UE) through an Access and Mobility Function (AMF) 8. The AMF 8 may manage access of the UE. For example, when the UE may be connected through different access networks, and mobility aspects of the UE. A Network Data Analytics Function (NWDAF) 9 may be understood to represent an operator managed network analytics logical function. The NWDAF 9 may be part of the 5GC architecture and may use the mechanisms and interfaces specified for 5GC and Operations, Administration and Maintenance (OAM). Each of the UDR 6, the NEF 2, the NWDAF 9, the AF 1 , the PCF 5, the CHF 7, the AMF 8, the SMF 3 and the UPF 4 may have an interface through which they may be accessed, which as depicted in the Figure, may be, respectively: Nudr 10, Nnef 11 , Nnwdaf 12, Naf 13, Npcf 14, Nchf 15, Namf 16, Nsmf 17 and N4 18.
[0009] Traffic encryption and network management
[0010] Traffic encryption is growing significantly in mobile networks and at the same time, the encryption mechanisms are growing in complexity. Most applications today are not based on HyperText Transfer Protocol (HTTP) cleartext, but instead they may be based on HTTP Secure (HTTPS) using Transport Layer Security (TLS), which may be understood to encrypt traffic. Additionally, a significant part of the traffic may now be based on Quick User Datagram Protocol Internet Connections (QUIC) transport, which may be have an encryption level higher than TLS. In the future, it is foreseen that most apps may be based on QUIC transport.
[0011] The Domain Name System (DNS) protocol may be understood as a naming system which may enable to locate and translate internet domain names into Internet Protocol (IP) addresses, so that humans may access resources on the internet. The DNS protocol today may be usually unencrypted, such as DNS over User Datagram Protocol (UDP) / Transmission Control Protocol (TCP). However, there are different Internet Engineering Task Force (IETF) Requests for Comments (RFCs) for DNS encryption, e.g., DNS over HTTPS (DOH), DNS over TLS (DoT), in order to prevent intermediary nodes or entities to detect DNS traffic. It is foreseen that in the 5G timeframe, that is, the 2020-2030 decade, most DNS traffic may be encrypted.
[0012] Server Name Indication (SNI) encryption
[0013] The SNI may be understood as an extension to the TLS computer networking protocol which may indicate to which hostname a client may be attempting to connect at the start of a handshaking process between the client and the host. The SNI may be indicated in an SNI field in a Client Hello message in QUIC protocol.
[0014] In QUIC, and for most QUIC protocol versions, the Client Hello message, which may include the SNI field, may be encrypted.
[0015] In TLS 1.3, a mechanism known as Encrypted Client Hello (ECH) and Encrypted SNI (ESNI) is defined to encrypt the Client Hello message, which may include the SNI field. This may be understood to apply to both, TLS and QUIC based applications.
[0016] Traffic differentiation by a Mobile Network Operator (MNO) may be based on different techniques. Today, the technique that may be most commonly used may be based on the inspection of the SNI field. An encrypted SNI field represents therefore a challenge for an MNO. DNS Zone transfer
[0017] DNS zone transfer may be understood to be a type of DNS transaction, that is, a DNS Zone transfer may be basically achieved by triggering a DNS query type Authoritative Transfer (AXFR). It may be understood as a mechanism to replicate DNS databases across a set of DNS servers.
[0018] A zone transfer may use TCP for transport and may take the form of a client-server transaction. The client requesting a zone transfer may be a secondary server requesting data from a primary server. DNS records may be usually stored in a primary or main server, and they may be replicated, that is, transferred, to a secondary server. The portion of the database that may be replicated may be understood to be a zone.
[0019] A zone transfer may comprise a preamble, followed by an actual data transfer. The preamble may be understood to be the initial procedure for the zone transfer. The preamble may comprise a lookup of a Start of Authority (SOA) resource record for a "zone apex". The SOA resource record may be understood as a type of resource record in DNS containing administrative information about the zone, especially regarding zone transfers. The zone apex may be understood as the node of the DNS namespace that may be at the top of the "zone". The fields of this SOA resource record, in particular the "serial number", may determine whether the actual data transfer may need to occur at all. The client may compare the serial number of the SOA resource record with the serial number in the last copy of that resource record that the client may have. If the serial number of the record being transferred is greater, the data in the zone may be deemed to have "changed" in some fashion, and the secondary server may proceed to request the actual zone data transfer. If the serial numbers are identical, the data in the zone may be deemed not to have "changed", and the client may continue to use the copy of the database that it already has, if it has one.
[0020] The actual data transfer process may begin by the client sending a query, operation code (opcode) 0, with the special query type AXFR, value 252, over the TCP connection to the server. Although DNS may be understood to technically support AXFR over UDP, it is considered not acceptable due to the risk of lost, or spoofed packets. The server may respond with a series of response messages, comprising all of the resource records for every domain name in the "zone". The first response may comprise the SOA resource record for the zone apex. The other data may follow in no specified order. The end of the data may be signaled by the server repeating the response containing the SOA resource record for the zone apex.
[0021] Some zone transfer clients may perform the SOA lookup of the preamble using the normal DNS query resolution mechanism of their system. These clients may be understood to not open a TCP connection to the server until they may have determined that they may need to perform the actual data transfer. However, since TCP may be used for normal DNS transactions, as well as for zone transfer, other zone transfer clients may perform the SOA lookup preamble over the same TCP connection as they may then perform the actual data transfer. These clients may open the TCP connection to the server before they may even perform the preamble, that is, before they may trigger the initial procedure for the zone transfer.
[0022] The preceding may be understood to describe a full zone transfer. An incremental zone transfer may differ from a full zone transfer in the following respects. In the incremental zone transfer, the client may use the special QTYPE IXFR, value 251 , instead of the AXFR QTYPE. In the incremental zone transfer, the client may send the SOA resource record for the zone apex that it may currently have, if any, in the IXFR message, letting the server know which version of the "zone" it may believe to be current.
[0023] Although the server may respond in the normal AXFR manner with the full data for the zone, it may also instead respond with an "incremental" data transfer. This latter may comprise a list of changes to the zone data, in zone serial number order, between the version of the zone that the client reported to the server as having, and the version of the zone that may be current at the server. The changes may comprise two lists, one of resource records that may be deleted, and one of resource records that may be inserted. A modification to a resource record may be represented as a deletion followed by an insertion.
[0024] Zone transfer may be understood to be entirely client-initiated. Although servers may send a NOTIFY message to clients, that they may have been informed about, whenever a change to the zone data may have been made, the scheduling of zone transfers may be entirely under the control of the clients. Clients may schedule zone transfers initially, when their databases may be empty, and thereafter at regular intervals, in a pattern controlled by the values in the "refresh", "retry", and "expire" fields in the SOA resource record of the zone apex.
[0025] Existing methods to handle traffic according to the mechanisms just described may lead to poor performance in a communications network, such as increased latency and low quality of experience.
[0026] SUMMARY
[0027] As part of the development of embodiments herein, one or more challenges with the existing technology will first be identified and discussed.
[0028] Traffic Management may be understood to be very important for mobile network operators (MNOs). MNOs have built their offerings on the network capability to apply service differentiated policy. Application of service differentiated policy may be understood to involve classification of traffic in order to determine what service may be applicable. For example, when congestion is detected, an MNO cannot apply traffic optimization techniques such as Adaptive Bitrate Streaming (ABR) shaping, which may be used to relieve congestion while keeping a Quality of Experience (QoE) of a user. ABR shaping may only be applied to video, e.g., streaming, traffic, not to other types of traffic, such as browsing.
[0029] Traffic Management based on traffic classification is now challenged due to the raise of traffic encryption, as exemplified above in HTTPS / TLS, QIIIC, ECH / ESNI, and / or DoH / DoT. Most applications today are encrypted, such as in HTTPS / TLS or QIIIC, and for those, traffic classification is becoming increasingly difficult. The latest encryption techniques, such as dual proxy deployments, which may be already deployed for commonly used browsers, do not allow a Mobile Network Operator (MNO) to identify traffic and apply traffic management actions.
[0030] MNOs may detect traffic by means of inspecting any of the following. In the case of HTTP plaintext traffic, MNOs may detect traffic by means of inspecting the hostname part of the URL. This is not valid today as most applications are encrypted with HTTPS / TLS or QUIC. In other cases, MNOs may detect traffic by means of inspecting domain names, specifically: the SNI field in the Client Hello for HTTPS / TLS traffic, the SNI field in the client Hello for QUIC traffic and / or the Query Name (QNAME) Fully Qualified Domain Name (FQDN) in the DNS query. However, regarding the SNI, there are now different mechanisms to encrypt the SNI field, e.g., in most QUIC protocol versions the SNI field is encrypted; in TLS 1.3 the SNI field may be encrypted using ECH / ESNI mechanism. This may be understood to mean that the MNO, may not be able to detect within a flow, e.g., via a 5-tuple, the corresponding domain, as it is already happening today with widely used applications.
[0031] Regarding DNS, DNS traffic may now be encrypted with DoH / DoT, so it is not possible for MNO to inspect the QNAME (FQDN) in the DNS query message.
[0032] According to the foregoing, it is an object of embodiments herein to improve the handling of information in a communications system.
[0033] According to a first aspect of embodiments herein, the object is achieved by a computer- implemented method, performed by a first node. The method is handling information. The first node operates in a communications system. The first node detects a flow of traffic between a device operating in the communications system and another node external to the communications system. The traffic comprises a first indication of a domain corresponding to the another node, and a second indication indicating an address of the another node. The first indication is encrypted and not decryptable by the first node. The second indication is unencrypted and lacking an explicit indication of the domain. The first node determines, responsive to the detected flow of traffic, the domain corresponding to the another node, as the domain corresponding to the second indication in stored DNS zone information previously obtained from the another node. The first node initiates managing the traffic based on the determined domain.
[0034] According to a second aspect of embodiments herein, the object is achieved by a computer-implemented method, performed by a second node. The method is for handling the information. The second node operates in the communications system. The second node receives an earlier message, from a third node operating in the communications system. The earlier message comprises a second request to store the DNS zone information, previously obtained from the another node external to the communications system. The DNS zone information comprises the second indication indicating the address of the another node. The second indication lacks an explicit indication of the domain corresponding to the another node. The DNS zone information further comprises a correspondence between the second indication and the domain. The second node stores the DNS zone information responsive to receiving the earlier message. The second node then receives, after having received the earlier message, a first message from the first node operating in the communications system 100. The first message comprises a first request for the stored DNS zone information. The second node then sends, responsive to the received first message, the second message to the first node. The second message comprises the requested stored DNS zone information.
[0035] According to a third aspect of embodiments herein, the object is achieved by a computer-implemented method, performed by the third node. The method is for handling the information. The third node operates in the communications system. The third node sends the earlier message to the second node operating in the communications system. The earlier message comprises the second request to store the DNS zone information, previously obtained from the another node 115 external to the communications system. The DNS zone information comprises the second indication indicating the address of the another node. The second indication lacks the explicit indication of the domain corresponding to the another node. The DNS zone information further comprises the correspondence between the second indication and the domain.
[0036] According to a fourth aspect of embodiments herein, the object is achieved by the first node, for handling the information. The first node is configured to operate in the communications system. The first node is configured to detect the flow of traffic between the device configured to operate in the communications system and the another node external to the communications system. The traffic is configured to comprise the first indication of the domain corresponding to the another node, and the second indication configured to indicate the address of the another node. The first indication is configured to be encrypted and not decryptable by the first node. The second indication is configured to be un-encrypted and lacking the explicit indication of the domain. The first node is also configured to determine, responsive to the detected flow of traffic, the domain configured to correspond to the another node, as the domain configured to correspond to the second indication in the stored DNS zone information configured to have been previously obtained from the another node. The first node is further configured to initiate managing the traffic based on the domain configured to be determined.
[0037] According to a fifth aspect of embodiments herein, the object is achieved by the second node, for handling the information. The second node is configured to operate in the communications system. The second node is configured to configured to receive the earlier message from the third node configured to operate in the communications system. The earlier message is configured to comprise the second request to store the DNS zone information, configured to have been previously obtained from the another node external to the communications system. The DNS zone information is configured to comprise the second indication configured to indicate the address of the another node. The second indication is configured to lack the explicit indication of the domain corresponding to the another node. The DNS zone information is further configured to comprise the correspondence between the second indication and the domain. The second node is also configured to store the DNS zone information responsive to receiving the earlier message. The second node 12 is further configured to receive, after having received the earlier message, the first message from the first node configured to operate in the communications system. The first message is configured to comprise the first request for the DNS zone information configured to be stored. The second node is additionally configured to send, responsive to the first message configured to be received, the second message to the first node. The second message is configured to comprise the stored DNS zone information configured to be requested.
[0038] According to a sixth aspect of embodiments herein, the object is achieved by the third node, for handling the information. The third node is configured to operate in the communications system. The third node is configured to send the earlier message to the second node configured to operate in the communications system. The earlier message is configured to comprise the second request to store the DNS zone information, configured to have been previously obtained from the another node external to the communications system. The DNS zone information is configured to comprise the second indication configured to indicate the address of the another node. The second indication is configured to lack the explicit indication of the domain configured to correspond to the another node. The DNS zone information is configured to further comprise the correspondence between the second indication and the domain.
[0039] According to a seventh aspect of embodiments herein, the object is achieved by the communications system, for handling the information. The communications system is configured to comprise one or more of: the first node, the second node and the third node.
[0040] By detecting the flow of traffic between the device and the another node external to the communications system, the flow comprising the first indication and the second indication, the first node may be then enabled to determine the domain corresponding to the another node. By determining the domain corresponding to the another node, the first node may then be enabled to initiate managing the traffic based on the determined domain. By the first node initiating managing the traffic based on the determined domain, the first node may improve the performance of the communications system, as for example, the first node may enable to classify the detected flow, e.g., may now differentiate video traffic from non-video traffic, and for example enable to apply traffic optimization. For example, if congestion is detected, the first node may enable to apply traffic optimization techniques, such as ABR shaping, only o video, e.g., streaming, traffic and not to other types of traffic, such as browsing, to relieve congestion while keeping a QoE of a user.
[0041] By the second node receiving the earlier message from the third node comprising the second request to store the DNS zone information comprising the second indication and the correspondence between the second indication and the domain, the second node may then be enabled to send, responsive to the received first message, the second message to the first node comprising the requested stored DNS zone information, thereby enabling that the first node may achieve the technical advantages described in the previous paragraph.
[0042] The third node may enable that a node external to the communications system may transfer information to the communications system, which information may then be used to determine the domain of the another node by the first node, when the domain of the another node may be encrypted in detected traffic.
[0043] Embodiments herein may be understood to allow a network operator of the communications system to apply traffic management actions in a simple an efficient way, especially when the traffic is encrypted, e.g., via DNS encryption, such as DoH / DoT, HTTPS, e.g., TLS, or QUID based applications, e.g., when SNI may be encrypted, either through QUID Client Hello encryption or through ECH / ESNI in TLS 1.3.
[0044] Embodiments herein may be understood to enable a very efficient procedure as a domain, e.g., videostreamingprovider, may usually have many subdomains, e.g., a popular video streaming provider domain has more than 20k subdomains. Hence, triggering individual queries would imply a very high number of DNS transactions, e.g., more than 20k. In contrast, with the proposed extension based on DNS Zone transfer, all the zone information from the another node may be available at the MNO.
[0045] Furthermore, embodiments herein may be understood to enable a seamless procedure in comparison with other collaborative approaches that may imply to create a new framework to send the detection rules, as embodiments herein may rely in an existing DNS technique present in all the DNS servers.
[0046] BRIEF DESCRIPTION OF THE DRAWINGS Examples of embodiments herein are described in more detail with reference to the accompanying drawings, according to the following description.
[0047] Figure 1 is a schematic diagram illustrating an example of a 5G Network Architecture, according to existing methods.
[0048] Figure 2 is a schematic diagram illustrating a non-limiting example of a communications system, according to embodiments herein.
[0049] Figure 3 is a flowchart depicting embodiments of a method in a first node, according to embodiments herein.
[0050] Figure 4 is a flowchart depicting embodiments of a method in a second node, according to embodiments herein.
[0051] Figure 5 is a flowchart depicting embodiments of a method in a third node, according to embodiments herein.
[0052] Figure 6 is a schematic diagram depicting a non-limiting example of signalling between nodes in a communications system, according to embodiments herein.
[0053] Figure 7 is a schematic diagram depicting another non-limiting example of signalling between nodes in a communications system, according to embodiments herein.
[0054] Figure 8 is a schematic block diagram illustrating two non-limiting examples, a) and b), of a first node, according to embodiments herein.
[0055] Figure 9 is a schematic block diagram illustrating two non-limiting examples, a) and b), of a second node, according to embodiments herein.
[0056] Figure 10 is a schematic block diagram illustrating two non-limiting examples, a) and b), of a third node, according to embodiments herein.
[0057] DETAILED DESCRIPTION
[0058] Certain aspects of the present disclosure and their embodiments address one or more of the challenges identified with the existing methods and provide solutions to the challenges discussed.
[0059] Embodiments herein may be understood to address the problems identified with the existing methods and may relate to encrypted traffic classification or detection based on DNS Zone Transfer. More particularly, embodiments herein may be understood to relate to a collaborative approach between an MNO and DNS server / s, e.g., authoritative server / s, which may be external, to the MNO, which approach may be based on allowing the MNO to perform DNS zone transfers from the (external) DNS (authoritative) servers.
[0060] Even further particularly, by exposing information from the (external) DNS (authoritative) server / s the MNO, for example, via a UPF, may be able to detect or classify encrypted application traffic. As DNS, e.g., authoritative, servers may be external to the MNO, the exposure may involve a NEF, e.g., via a new NEF service / API, which may allow DNS zone transfers from external DNS authoritative servers. The retrieved information may be stored by the MNO, e.g., in a UDR as part of a new data structure, e.g., as an extension to the existing Application Data, and distributed towards the different UPF / s in the network of the MNO, thereby enabling traffic management when traffic is encrypted.
[0061] The embodiments will now be described more fully hereinafter with reference to the accompanying drawings, in which examples are shown. In this section, embodiments herein are illustrated by exemplary embodiments. It should be noted that these embodiments are not mutually exclusive. Components from one embodiment or example may be tacitly assumed to be present in another embodiment or example and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. All possible combinations are not described to simplify the description.
[0062] Figure 2 depicts two non-limiting examples, in panels “a” and “b”, respectively, of a communications system 100, in which embodiments herein may be implemented. In some example implementations, such as that depicted in the non-limiting example of Figure 2a, the communications system 100 may be a computer network. In other example implementations, such as that depicted in the non-limiting example of Figure 2b, the communications system 100 may be implemented in a telecommunications system, sometimes also referred to as a telecommunications network, cellular radio system, cellular network, or wireless communications system. In some examples, the telecommunications system may comprise network nodes which may serve receiving nodes, such as wireless devices. The communications system 100 may for example be a network such as a 5G system, or a newer system supporting similar functionality. In some examples, the communications system 100 may be a Long-Term Evolution (LTE) network and may, alternatively or additionally, support other technologies such as a for example, e.g., LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), LTE Half-Duplex Frequency Division Duplex (HD-FDD), LTE operating in an unlicensed band. The telecommunications system may also support other technologies, such as Wideband Code Division Multiple Access (WCDMA), Universal Mobile Telecommunications System Terrestrial Radio Access (UTRA) TDD, Global System for Mobile communications (GSM) network, GSM / Enhanced Data Rate for GSM Evolution (EDGE) Radio Access Network (GERAN) network, Ultra-Mobile Broadband (UMB), EDGE network, network comprising any combination of Radio Access Technologies (RATs) such as e.g. MultiStandard Radio (MSR) base stations, multi-RAT base stations etc., any 2rd Generation Partnership Project (3GPP) cellular network, Wireless Local Area Network / s (WLAN) or WiFi network / s, Worldwide Interoperability for Microwave Access (WiMax), IEEE 802.15.4-based low-power short-range networks such as IPv6 over Low-Power Wireless Personal Area Networks (6LowPAN), Zigbee, Z-Wave, Bluetooth Low Energy (BLE), or any cellular network or system. The telecommunications system may for example support a Low Power Wide Area Network (LPWAN). LPWAN technologies may comprise Long Range physical layer protocol (LoRa), Haystack, SigFox, LTE-M, and Narrow-Band loT (NB-loT).
[0063] The communications system 100 may comprise a plurality of nodes, and / or operate in communication with other nodes, whereof a first node 111, a second node 112, a third node 113, a further node 114 or fourth node, and another node 115 or fifth node 115 are depicted in Figure 2. It may be understood that the communications system 100 may comprise and / or operate in communication with more nodes than those represented on Figure 2. For example, as will be depicted in other figures, the communications system 100 may comprise a sixth node 116, a seventh node 117, etc... The first node 111 , the second node 112, the third node 113 and the further node 114 may be comprised in, or be internal to, the communications system 100. The another node 115 is external to the communications system 100 but may operate via the communications system 100.
[0064] Any of the first node 111, the second node 112, the third node 113, the further node 114 and the another node 115 may be understood, respectively, as a first computer system, a second computer system, a third computer system, and fourth computer system and a fifth computer system. In some examples, any of the first node 111 , the second node 112, the third node 113, the further node 114 and the another node 115 may be implemented as a standalone server in e.g., a host computer in the cloud 120, as depicted in the non-limiting example depicted in panel b) of Figure 2 for the first node 111 , the second node 112, the third node 113 and the further node 114. Any of the first node 111, the second node 112, the third node 113, the further node 114 and the another node 115 may in some examples be a distributed node or distributed server, with some of their respective functions being implemented locally, e.g., by a client manager, and some of their functions implemented in the cloud 120, by e.g., a server manager. Yet in other examples, any of the first node 111 , the second node 112, the third node 113, the further node 114 and the another node 115 may also be implemented as processing resources in a server farm.
[0065] Any of the first node 111, the second node 112, the third node 113 and further node 114 may be co-localized. However, in typical embodiments, the first node 111 , the second node 112, the third node 113 and the another node 114 may be different nodes.
[0066] The first node 111 be understood to be a node that may have a capability to support handling of user plane traffic, including packet inspection, packet routing and forwarding, traffic usage reporting, and Quality of Service (QoS) handling for user plane, e.g., UL / DL rate enforcement, e.g., based on rules received from the further node 114. As depicted in Figure 2, a particular non-limiting example, wherein the communications system 100 may be a 5G network, the first node 111 may be UPF. In another non-limiting example of the first node 111 , wherein the communications system 100 may be a 4G network, the first node 111 may be a Packet Gateway User Plane (PGW-U), or a Traffic Detection Function User Plane (TDF- U).
[0067] The second node 112, in some examples may be a node having a capability to store data, grouped into distinct collections of subscription-related information, such as subscription data, policy data, structured data for exposure, and application data. As depicted in Figure 2, a particular non-limiting example, wherein the communications system 100 may be a 5G network, the second node 112 may, in such examples be a UDR. In such examples, wherein the communications system 100 may be a 4G network, the second node 112 may be Subscriber Profile Repository (SPR). In other examples, the second node 112 may be a node having a capability to support different functionalities and may configure the first node 111 accordingly. In such examples, wherein the communications system 100 may be a 5G network, the further node 114 may be an SMF. In such examples, wherein the communications system 100 may be a 4G network, the further node 114 may be , a Packet Gateway Control Plane (PGW-C), or a Traffic Detection Function Control Plane (TDF-C).
[0068] The third node 113 may be a node having a capability to support different functionality, e.g., different Exposure APIs, such as an API for PFD Management. As depicted in Figure 2, a particular non-limiting example, wherein the communications system 100 may be a 5G network, the third node 113 may be a NEF. In another non-limiting example of the third node 113, wherein the communications system 100 may be a 4G network, the third node 113 may be a Service Capability Exposure Function (SCEF).
[0069] The further node 114 may be a node having a capability to manage sessions of data communication between a device operating in the communications system 100, such as the device 130 described below, and the another node 115. The further node 114 may support different functionalities, such as receiving rules from a function controlling policy in the communications system 100, and configuring the first node 111 accordingly. As depicted in Figure 2, a particular non-limiting example, wherein the communications system 100 may be a 5G network, the further node 114 may be an SMF. In another non-limiting example of the further node 114, wherein the communications system 100 may be a 4G network, the further node 114 may be a PGW-C, or a TDF-C.
[0070] The another node 115 may be a node having a capability to manage service of an application to a device, such as the device 130 described below. The another node 115 may interact with the core network of the communications system 100 through the first node 111. The another node 115 may allow external parties to use the Exposure APIs offered by an operator of the communications system 100. As depicted in Figure 2, a particular non-limiting example, wherein the communications system 100 may be a 5G network, the another node 115 may be an AF / Application Server (AS). In another non-limiting example of the second node 112, wherein the communications system 100 may be a 4G network, the second node 112 may be a Services Capabilities Server (SCS), or an AS.
[0071] The communications system 100 may also comprise a device 130. The device 130 may be also known as a e.g., user equipment (UE), wireless device, mobile terminal, wireless terminal and / or mobile station, mobile telephone, cellular telephone, or laptop with wireless capability, an Internet of Things (loT) device, or a Customer Premises Equipment (CPE), just to mention some further examples. The device 130 in the present context may be, for example, portable, pocket-storable, hand-held, computer-comprised, or a vehicle-mounted mobile device, enabled to communicate voice and / or data, via a RAN, with another entity, such as a server, a laptop, a Personal Digital Assistant (PDA), or a tablet, a Machine-to- Machine (M2M) device, an Internet of Things (loT) device, e.g., a sensor or a camera, a device equipped with a wireless interface, such as a printer or a file storage device, modem, Laptop Embedded Equipped (LEE), Laptop Mounted Equipment (LME), USB dongles, CPE or any other radio network unit capable of communicating over a radio link in the communications system 100. The device 130 may be wireless, i.e. , it may be enabled to communicate wirelessly in the communications system 100 and, in some particular examples, may be able support beamforming transmission. The communication may be performed e.g., between two devices, between a device and a radio network node, and / or between a device and a server. The communication may be performed e.g., via a RAN and possibly one or more core networks, comprised, respectively, within the communications system 100.
[0072] The communications system 100 may comprise one or more radio network nodes, whereof a radio network node 140 is depicted in Figure 2b. The radio network node 140 may typically be a base station or Transmission Point (TP), or any other network unit capable to serve a wireless device or a machine type node in the communications system 100. The radio network node 140 may be e.g., a 5G gNB, a 4G eNB, or a radio network node in an alternative 5G radio access technology, e.g., fixed or WiFi. The radio network node 140 may be e.g., a Wide Area Base Station, Medium Range Base Station, Local Area Base Station, and Home Base Station, based on transmission power and thereby also coverage size. The radio network node 140 may be a stationary relay node or a mobile relay node. The radio network node 140 may support one or several communication technologies, and its name may depend on the technology and terminology used. The radio network node 140 may be directly connected to one or more networks and / or one or more core networks.
[0073] The communications system 100 covers a geographical area which may be divided into cell areas, wherein each cell area may be served by a radio network node, although, one radio network node may serve one or several cells.
[0074] The first node 111 may communicate with the second node 112 over a first link 151, e.g., a radio link or a wired link. The first node 111 may communicate with the further node 114 over a second link 152, e.g., a radio link or a wired link. The second node 112 may communicate with the third node 113 over a third link 153, e.g., a radio link or a wired link. The first node 111 may communicate with the another node 115 over a fourth link 154, e.g., a radio link or a wired link. The first node 111 may communicate with the device 130 over a fifth link 155, e.g., a radio link or a wired link. The third node 113 may communicate with the another node 115 over a sixth link 156, e.g., a radio link or a wired link. The first node 111 may communicate with the radio network node 140 over a seventh link 157, e.g., a radio link or a wired link. The radio network node 140 may communicate with the device 130 over an eighth link 158, e.g., a radio link or a wired link. The device 130 may communicate with the another node 115 over a ninth link 159, e.g., a radio link or a wired link.
[0075] Any of the first link 151 , the second link 152, the third link 153, the fourth link 154, the fifth link 155, the sixth link 156, the seventh link 157, the eighth link 158 and / or the ninth link 159 may be a direct link or it may go via one or more computer systems or one or more core networks in the communications system 100, or it may go via an optional intermediate network. The intermediate network may be one of, or a combination of more than one of, a public, private, or hosted network; the intermediate network, if any, may be a backbone network or the Internet, which is not shown in Figure 2.
[0076] Although terminology from Long Term Evolution (LTE) / 5G has been used in this disclosure to exemplify the embodiments herein, this should not be seen as limiting the scope of the embodiments herein to only the aforementioned system. Other wireless systems supporting similar or equivalent functionality may also benefit from exploiting the ideas covered within this disclosure.
[0077] As depicted in the non-limiting examples of Figure 2, in some embodiments wherein the communications system 100 may be a 5G system, the first node 111 may be a UPF, the second node 112 may be a UDR, the third node 113 may be NEF, the further node 114 may be an SMF and the another node 115 may be an AS / AF. AS explained earlier, embodiments herein may be understood to not only apply to 5G network architecture, but the same mechanisms may be applied to 4G, for example, just by replacing NEF by SCEF, UDR by SPR, PCF by PCRF, SMF by PGW-C or TDF-C and UPF by PGW-U or TDF-U.
[0078] In future telecommunication networks, e.g., in the sixth generation (6G), the terms used herein may need to be reinterpreted in view of possible terminology changes in future technologies. In general, the usage of “first”, “second”, “third”, “fourth”, “fifth”, “sixth”, “seventh”, “eighth” and / or “ninth” herein may be understood to be an arbitrary way to denote different elements or entities and may be understood to not confer a cumulative or chronological character to the nouns they modify.
[0079] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
[0080] Embodiments of a computer-implemented method, performed by the first node 111 , will now be described with reference to the flowchart depicted in Figure 3. The method may be understood to be for handling information. The first node 111 operates in the communications system 100.
[0081] In some embodiments, the communications system 100 may be one of the following. According to a first option, the communications system 100 may be a 5G network and the first node 111 may be a UPF. According to a second option, the communications system 100 may be a 4G network, and the first node 111 may be one of: a PGW-ll, and a TDF-ll.
[0082] Several embodiments are comprised herein. In some embodiments, all the actions may be performed. In some embodiments, some of the actions may be performed. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. A non-limiting example of the method performed by the first node 111 is depicted in Figure 3.
[0083] In Figure 3, optional actions are represented with dashed lines.
[0084] Action 301
[0085] Embodiments herein may be understood to aim at enabling to handle encrypted traffic by providing a method enabling to classify the traffic to, for example, apply any pertinent policy. This may be achieved by enabling to determine a domain corresponding to the node hosting the application managing the delivery of the content communicated by the encrypted traffic. In embodiments herein, this node may be understood to be the another node 115. The domain of the detected traffic may be encrypted and hence not readily identifiable by the first node 111. The encrypted traffic may, however, comprise another indication which may be unencrypted. While this other indication may not enable to classify the traffic bearing it, embodiments herein may provide a method that may enable to map the accessible indication of the another node 115 to its domain. This may be achieved in embodiments herein by retrieving this mapping from DNS zone information obtained from the another node 115 via a DNS zone transfer, as will be explained in the following actions. The another node 115 may have facilitated the DNS zone information via a DNS zone transfer in a previous onboarding procedure with the communications system 100, which will be described in relation to Figure 5, and later depicted with an example in Figure 6.
[0086] The node being able to perform the mapping between the unencrypted indication in the encrypted traffic and the domain corresponding to the another node 115 in embodiments herein may be understood to be the first node 111. In this Action 301 , the first node 111 may send a first previous indication to the further node 114 operating in the communications system 100. The first previous indication may indicate a capability of the first node 111 to determine a domain, based on stored DNS zone information. The capability may be understood as a new capability which may be referred to as of a capability of assisted traffic detection. However, it may be understood that a different name for this capability may be used.
[0087] The sending may be performed, e.g., via the second link 152.
[0088] In some embodiments, the communications system 100 may be one of the following. According to a first option, the communications system 100 may be a 5G network and the further node 114 may be an SMF. According to a second option, the communications system 100 may be a 4G network, and the further node 114 may be one of: a PGW-C, and a TDF-C.
[0089] The first previous indication may be a Packet Flow Control Protocol (PFCP) association request. In a non-limiting example, in the PFCP Association procedure, the first node 111, e.g., a UPF, may, in this Action 301 , report to the further node 114, e.g., an SMF, the new capability, e.g, of assisted traffic detection.
[0090] By sending the first previous indication in this Action 301 , the first node 111 may enable the further node 114, to select the first node 111, e.g., a UPF, as a type of node supporting this capability on a per PFCP session basis. The capability exchange procedure may be understood to have the technical advantage of efficiency. For example, if a consumer selects another first node, e.g., another UPF, for the session which does not have the capability, it may not be able to use the method disclosed herein. It may be able to re-select yet another first node, e.g., yet another UPF, which may support the capability, but this may be understood to imply extra processing.
[0091] Action 302
[0092] In this Action 302, the first node 111 may receive, responsive to the sent first previous indication, a second previous indication from the further node 114. The second previous indication may confirm receipt by the further node 114 of the first previous indication
[0093] The second previous indication may be a PFCP association response.
[0094] The receiving may be performed, e.g., via the second link 152. Action 303
[0095] The DNS zone information that may have been transferred from the another node 115 may be stored in the communications system 100 by the second node 112.
[0096] In this Action 303, the first node 111 may send a first message to the second node 112 operating in the communications system 100. The first message may comprise a first request for the stored DNS zone information from the second node 112. The first request may be understood to be for stored DNS zone information that may comprise the DNS zone information that may later be used by the first node 111 to determine the domain of the another node 115, as will be described in Action 305. This may be understood to mean that the first message may ask for the whole DNS zone database stored at the second node 112, or just a list of requested DNS Zones. For example, it may happen that the first node 111 may have been subject to a change, e.g., due to relocation or reselection, for one or several Protocol Data Unit (PDU) sessions, of the first node 111. In such change scenario, it may happen that the first node 111 may need to retrieve other zones, e.g., if the relocated PDU session / s may have or have had PCC rules for App-IDs for which the first node 111 may not have the corresponding DNS zone information previously stored. In that case, instead of retrieving a full copy of the DNS zone information, the first node 111 may request only the needed DNS zones information.
[0097] The sending in this Action 303 may be performed, e.g., via the first link 151.
[0098] In some embodiments, the requested stored DNS zone information may be based on one or more criteria. In some embodiments, the criteria may comprise at least one of application and domain related. According to the first option, the criteria for the first node 111 to select which may be the DNS zone information to request may be based on applications, for which the first node 111 may need to detect and apply traffic management actions. For example, if the first node 111 pertains to a Mobile BroadBand (MBB) slice and an MNO of the communications system 100 offers their MBB subscribers a subscription to gaming apps, the first node 111 may retrieve the zones corresponding to those gaming apps. If the first node 111 pertains to an Enterprise slice, the first node 111 may retrieve the zones corresponding to Enterprise apps, e.g., a video conferencing and chatting application, an application to share documents, etc.
[0099] According to the second option, the criteria for the first node 111 to select which may be the DNS zones to request may be based per domain, e.g., a domain of a browser, by querying the Zone of the browser.
[0100] The first message may be of different types, depending on the procedure that may be used by the first node 111 to retrieve the stored DNS zone information. In some embodiments, one of the following may apply. According to a first option, the first message may be a query request. According to a second option, the first message may be a subscription request.
[0101] According to the first option, the first node 111 may retrieve the stored DNS zone information via a pull procedure, that is, by sending a request and obtaining a response from the second node 112, enabling traffic management when traffic is encrypted.
[0102] According to the first option, the first node 111 may retrieve the stored DNS zone information via a push procedure, that is, by sending a subscribe request and obtaining a notification back from the second node 112.
[0103] In some embodiments, the communications system 100 one of the following. According to a first option, the communications system 100 may be a 5G network.
[0104] In some of such embodiments, as stated earlier, the first node 111 may be a UPF. In such embodiments, the first node 111 may send the first message in this Action 303 to the UDR. Other embodiments are possible, e.g. other 5GC NF such as the SMF may store the DNS zone information instead of the UDR. This may be advantageous considering multivendor deployments where the UDR may be from a different vendor, for addressing a UPF change scenario, e.g., UPF re-selection scenario due to mobility. According to the foregoing, in embodiments wherein the communications system 100 may be a 5G network, the second node 112 may be one of a UDR, and an SMF. In some examples of such embodiments, the first message may be a Nudr_Query Request message.
[0105] According to a second option, the communications system 100 may be a 4G network, and the second node 112 may be one of: an SPR, a PGW-C, and a TDF-C.
[0106] By sending the first message in this Action 303, the first node 111 may be enabled to retrieve the stored DNS zone information from the DNS zone database stored by the second node 112 and ultimately map encrypted traffic to a domain of the another 115 node involved in the traffic, thereby enabling classification of the encrypted traffic.
[0107] Action 304
[0108] In some embodiments, in this Action 304, the first node 111 may receive, responsive to the sent first message, a second message from the second node 112. The second message may comprise the requested stored DNS zone information.
[0109] As explained above, in some embodiments, one of the following may apply. According to a first option, the first message may be a query request, and the second message may be a query response. In some examples of such embodiments, the second message may be a Nudr_Query Response message, e.g., including the DNS Zones information.
[0110] According to a second option, the first message may be a subscription request, and the second message may be a notification response. By receiving the second message in this Action 304, the first node 111 may be enabled to retrieve the stored DNS zone information from the DNS zone database stored by the second node 112 and map encrypted traffic to a domain of the another 115 node involved in the traffic, as described in the next Action 305, thereby enabling classification of the encrypted traffic.
[0111] Action 305
[0112] At some point during the operation of the communications system 100, the device 130 may trigger a PDU Session Establishment procedure. This procedure may be as illustrated in the example depicted later in Figure 7. The PDU Session Establishment procedure may result in the further node 114, which may manage the session for the device 130, selecting the first node 111 based on the capability of the first node 111 for supporting the assisted traffic detection, as reported by the first node 111 in Action 301. The device 130 may, after the PDU Session may have been established, trigger application traffic for e.g., App-ID=example.com, which may include an encrypted QUIC / TLS Client Hello (CHLO).
[0113] In this Action 305, the first node 111 detects a flow of traffic between the device 130 operating in the communications system 100 and the another node 115 external to the communications system 100. The flow may be understood to be a new flow. As explained before, the traffic comprises a first indication of a domain corresponding to the another node 115, and a second indication indicating an address of the another node 115. The first indication is encrypted and not decryptable by the first node 111. The second indication is unencrypted and lacking an explicit indication of the domain.
[0114] The address of the another node 115 may be a Server IP address.
[0115] In some embodiments, at least one of the following may apply. According to a first option, the first indication may be one of a Uniform Resource Locator (URI), and an SNI. According to a second option, the second indication may be comprised in a 5-tuple. According to a third option, the second indication may be an IP address. According to a fourth option, the stored DNS zone information may have been previously obtained from the another node 115 based on a DNS zone transfer.
[0116] In some embodiments, the flow of traffic may be detected based on the confirmed receipt of the first previous indication. That is, the first node 111 may be the one detected the traffic as it may have been selected by the further node 114 based on the first node 111 having reported its capability to determine a domain based on stored DNS zone information in Action 301.
[0117] In some embodiments, the communications system 100 may be one of the following.
[0118] According to a first option, the communications system 100 may be a 5G network and the first node 111 may be a U PF and the another node 115 may be an Application Server. According to a second option, the communications system 100 may be a 4G network, and the first node 111 may be one of: a PGW-ll, and a TDF-ll and the another node 115 may be an Application Server.
[0119] By detecting the flow of traffic between the device 130 and the another node 115 external to the communications system 100 in this Action 305, the flow comprising the first indication and the second indication, the first node 111 may be then enabled to determine the domain corresponding to the another node 115 in the next Action 305, thereby ultimately enabling classification of the encrypted traffic and its handling accordingly.
[0120] Action 306
[0121] In this Action 306, the first node 111 determines, responsive to the detected flow of traffic, the domain corresponding to the another node 115, as the domain corresponding to the second indication in the stored DNS zone information previously obtained from the another node 115.
[0122] The first node 111 may have sent the first message to the second node 112 in Action 303 prior to the determining in this Action 306.
[0123] The determining in this Action 306 may be based on the received second message. That is, the first node 111 may perform the determining in this Action 306 by retrieving the domain corresponding to, e.g., the Server IP address indicated by the second indication through the DNS Zones database retrieved in Action 302 above.
[0124] The first node 111 may have sent the first previous indication in Action 301 prior to the determining in this Action 306.
[0125] By determining the domain corresponding to the another node 115 in this Action 306, the first node 111 may then be enabled to initiate managing the traffic based on the determined domain, as described in the next Action 307.
[0126] Action 307
[0127] In this Action 307, the first node 111 initiates managing the traffic based on the determined domain.
[0128] Initiating may be understood as triggering, enabling, facilitating, the enforcing by another node, or starting the managing itself.
[0129] The managing of the traffic may comprise at least one of: classifying the traffic and applying a traffic management rule. For example, based on the associated domain, the first node 111 may classify the packets in the detected flow into the PDR for App-ID=example.com and the corresponding traffic management actions may be executed, e.g., associated Forwarding Action Rule (FAR), Quality of Service (QoS) Enforcement Rule (QER) and / or Usage Reporting Rule (URR). By the first node 111 initiating managing the traffic based on the determined domain in this Action 307, the first node 111 may improve the performance of the communications system 100, as for example, the first node 111 may enable to classify the detected flow, e.g., may now differentiate video traffic from non-video traffic, and for example enable to apply traffic optimization. For example, when congestion is detected, the first node 111 may enable to apply traffic optimization techniques, such as ABR shaping, only o video, e.g., streaming, traffic and not to other types of traffic, such as browsing, to relieve congestion while keeping a QoE of a user.
[0130] Embodiments of a computer-implemented method performed by the second node 112, will now be described with reference to the flowchart depicted in Figure 4. The method may be understood to be for handling the information. The second node 112 operates in the communications system 100.
[0131] The method may comprise the following actions. Several embodiments are comprised herein. In some embodiments, the method may comprise all the actions. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. It should be noted that the examples herein are not mutually exclusive. Components from one example may be tacitly assumed to be present in another example and it will be obvious to a person skilled in the art how those components may be used in the other examples. In Figure 4, optional actions are depicted with dashed lines.
[0132] The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here to simplify the description. For example, in some examples, the address of the another node 115 may be a Server IP address.
[0133] Action 401
[0134] In this Action 401, the second node 112 receives a message, referred to herein as an earlier message, from the third node 113 operating in the communications system 100. The earlier message comprises a second request to store the DNS zone information, previously obtained from the another node 115 external to the communications system 100. The DNS zone information comprises the second indication indicating the address of the another node 115. The second indication lacks an explicit indication of the domain corresponding to the another node 115. The DNS zone information further comprises a correspondence between the second indication and the domain.
[0135] The receiving in this Action 401 may be performed, e.g., via the third link 153.
[0136] In some embodiments, at least one of the following may apply: a) the communications system 100 may be one of: i) a 5G network and: the second node 112 may be one of a UDR, and an SMF, the third node 113 may be a NEF, and an SMF, and the another node 115 may be an AS, and ii) a 4G network, and: the second node 112 may be one of: an SPR, a PGW-C, and a TDF-C, the third node 113 may be a SCEF, and the another node 115 may be an AS.
[0137] In some of the embodiments wherein the communications system 100 may be a 5G network, the second node 112 may be a UDR, and the third node 113 may be a NEF, the earlier message received in this Action 401 may be a Nudr_Store request message
[0138] In some embodiments, at least one of the following may apply: a) the second indication may be comprised in a 5-tuple, and b) the second indication may be an IP address, and c) the DNS zone information may have been previously obtained, e.g., retrieved, from the another node 115 based on a DNS zone transfer.
[0139] Action 402
[0140] In this Action 402, the second node 112 stores the DNS zone information responsive to receiving, in Action 401 , the earlier message. That is, the second node 112 may add the specific Zone information to its own database. The second node 112, e.g., the UDR, may support a new data structure relative to DNS information.
[0141] In some embodiments, at least one of the following may apply: a) the second indication may be comprised in a 5-tuple, b) the second indication may be an IP address, and c) the stored DNS zone information may have been previously obtained from the another node 115 based on a DNS zone transfer.
[0142] The second node 112 may optionally answer to the third node 113 indicating successful operation, e.g., by sending a Nudr_Store response message.
[0143] Action 403
[0144] In this Action 403, the second node 112 receives, after having received the earlier message, the first message from the first node 111 operating in the communications system 100. The first message comprises the first request for the stored DNS zone information.
[0145] In some embodiments, one of the following may apply: a) the first message may be the query request, and the second message may be a query response, and b) the first message may be the subscription request, and the second message may be the notification response.
[0146] In some embodiments, at least one of the following may apply: a) the requested stored DNS zone information may be based on the one or more criteria, b) the criteria may comprise at least one of application and domain related, c) the communications system 100 may be one of: i) a 5G network and: the first node 111 may be a UPF, the second node 112 may be one of a UDR, and an SMF, the third node 113 may be a NEF, and the another node 115 may be an AS, and ii) a 4G network, and: the first node 111 may be one of a PGW-U, and a TDF-U, the second node 112 may be one of: an SPR, a PGW-C, and a TDF-C, the third node 113 may be a SCEF, and the another node 115 may be an AS.
[0147] Action 404
[0148] In this Action 404, the second node 112 sends, responsive to the received first message, the second message to the first node 111. The second message comprises the requested stored DNS zone information.
[0149] Embodiments of a computer-implemented method performed by the third node 113, will now be described with reference to the flowchart depicted in Figure 5. The method may be understood to be for handling the information. The third node 113 is operating in the communications system 100.
[0150] The method may comprise the following actions. Several embodiments are comprised herein. In some embodiments, the method may comprise all the actions. In other embodiments, the method may comprise one or more actions. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. It should be noted that the examples herein are not mutually exclusive. Components from one example may be tacitly assumed to be present in another example and it will be obvious to a person skilled in the art how those components may be used in the other examples. In Figure 5, optional actions are depicted with dashed lines.
[0151] The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here to simplify the description. For example, in some examples, the address of the another node 115 may be a Server IP address.
[0152] Action 501
[0153] In this Action 501 , the third node 113 receives a request, referred to herein as a third request, from the another node 115.
[0154] The third request may indicate a first identifier of the another node 115, the address of the another node 115 and one or more DNS zones supported by the another node 115.
[0155] The receiving in this Action 501 may be performed, e.g., via the sixth link 156.
[0156] The another node 115 may be, e.g., a DNS Server, e.g., primary-server.com, acting as AF. The third node 113 may support a new service / API, which may allow DNS zone transfers from, e.g., external, DNS, authoritative, servers. The third node 113 may receive the third request in this Action 501 when the another node 115 may trigger an onboarding procedure to the network operator of the communications system 100. In some embodiments, at least one of the following may apply. According to a first option, the third request may be comprised in an Onboarding request message, e.g., Onboard_API_lnvoker.
[0157] According to a second option, the third request may be directed to a Common Application Programming Interface Framework (CAPIF) Core Function of the third node 113. In some embodiments, the communications system 100 may be it is assumed a deployment where the third node 113 may include the CAPIF Core Function. For details, please refer to 3GPP TS 23.222 Annex B (Figure B.2.2.2-1 “NEF implements the CAPIF architecture”).
[0158] According to a third option, the first identifier may be an application identifier, e.g., afID, such as primary-server.com. The first identifier may identify the AF.
[0159] According to a fourth option, the address may be an IP address of an application function (AF) , e.g., afIPAddress. The IP address of the AF may include the AF IP address.
[0160] According to a fifth option, the one or more DNS zones may be comprised in a list, e.g., List of Zone names. The list may include the list of Zones supported by the another node 115, e.g., the DNS Server.
[0161] In a particular non-limiting example, the third request may be an Onboarding Request (Onboard_API_lnvoker) comprising {afld=primary-server.com, afIPAddress, list of Zone names}.
[0162] After receiving the third request, the third node 113 may answer the another node 115 with an Onboarding response message indicating successful operation.
[0163] Action 502
[0164] The third node 113, in this Action 502, may send, responsive to the received third request, a third message to the another node 115. The third message may indicate to initiate a transfer procedure to obtain the DNS zone information. That is, in this Action 502, the third node 113 may trigger a DNS Zone transfer procedure. According to embodiments herein, the third node 113, e.g., a NEF, may support a new service, which may be implemented as an extension of a DNS client supporting AXFR type of queries. This may be in some non-limiting examples, e.g., a new NEF service which may allow DNS zone transfers from (external) DNS (authoritative) servers. In other non-limiting examples, this may be a new SCEF API which may allow DNS zone transfers from (external) DNS (authoritative) servers.
[0165] The sending in this Action 502 may be performed, e.g., via the sixth link 156.
[0166] In some embodiments, the third message may be a DNS query message. In other words, in this Action 502, the third node 113 may trigger a DNS query message.
[0167] In some embodiments, the third message may comprise a DNS query type, and one or more names of the requested one or more DNS zones. The DNS query type may be, for example, AXFR. This may indicate that the type of DNS query is AXFR. The one or more names of the requested one or more DNS zones may be a requested Zone name. The requested Zone name may indicate the requested zone name(s). The criteria for MNO, via the third node 113, to select which may be the zones to request may be based on applications, for which the MNO may need to detect and apply traffic management actions, e.g., based on subscription data and / or application data in the second node 112, if the MNO may offer their subscribers a subscription to gaming applications with low latency, the zones corresponding to those gaming applications may be requested. Other criteria may be per domain, e.g. *internetbrowser*, by querying a Zone of the internetbrowser of choice.
[0168] In a particular non-limiting example, the third message may be a DNS query comprising {DNS query type=AXFR, requested Zone name}
[0169] In some embodiments, at least one of the following may apply: a), the third request may be comprised in an Onboarding request message, b) the third request may be directed to a CAPIF Core Function of the third node 113, c) the first identifier may be an application identifier, d) the address may be an IP address of an AF, e) the one or more DNS zones may be comprised in a list, f) the third message may be a DNS query message, and g) the third message may comprise a DNS query type, and one or more names of the requested one or more DNS zones.
[0170] By sending the third message in this Action 502, the third node 113 may enable that an MNO of the communications system 100 may trigger a DNS Zone Transfer procedure and thereby obtain the DNS Zones database. The third node 113 may then trigger the another node 115 to look for the requested Zone data and return it in the next Action 503.
[0171] Action 503
[0172] In this Action 503, the third node 113 may receive, responsive to the sent third message, a fourth message from the another node 115. The fourth message may comprise the requested DNS zone information.
[0173] The fourth message may be a DNS answer message. In a particular non-limiting example, the fourth message may be a DNS answer comprising {requested Zone information}.
[0174] The receiving in this Action 503 may be performed, e.g., via the sixth link 156.
[0175] Action 504
[0176] In this Action 504, the third node 113 sends the earlier message to the second node 112 operating in the communications system 100. The earlier message comprises the second request to store the DNS zone information, previously obtained from the another node 115 external to the communications system 100. The DNS zone information comprises the second indication indicating the address of the another node 115. The second indication lacks the explicit indication of the domain corresponding to the another node 115. The DNS zone information further comprises the correspondence between the second indication and the domain.
[0177] The sending in this Action 504 may be performed, e.g., via the third link 153.
[0178] In some embodiments, at least one of the following may apply: a) the second indication may be comprised in the 5-tuple, b) the second indication may be an IP address, c) the stored DNS zone information may have been previously obtained from the another node 115 based on a DNS zone transfer, d) the DNS zone information requested to be stored may be based on the one or more criteria, e) the criteria may comprise at least one of application and domain related, and f) the communications system 100 may be one of: i) a 5G network and: the first node 111 may be a UPF, the another node 115 may be an AS, the second node 112 may be one of a UDR, and an SMF, and the third node 113 may be a NEF, and, and ii) a 4G network, and: the first node 111 may be one of a PGW-ll, and a TDF-ll, the another node 115 may be an AS, the second node 112 may be one of: an SPR, a PGW-C, and a TDF-C, and the third node 113 may be a SCEF.
[0179] In some embodiments, the sending in this Action 504 of the earlier message may be performed responsive to the receiving in Action 503 of the fourth message.
[0180] Figure 6 is a schematic diagram depicting a non-limiting example of signalling between nodes in the communications system 100, according to embodiments herein. Particularly, Figure 6 depicts an example of a method whereby an MNO may trigger a DNS Zone Transfer procedure. In Figure 6, the communications system 100 is a 5G network, the second node 112 is a UDR, the third node 113 is a NEF and the another node 115 is a DNS Server. It may be understood that in the following example depicted in Figure 6, any reference to the UDR may be understood to equally refer to the second node 112, any reference to the NEF may be understood to equally refer to the third node 113 and any reference to the DNS Server may be understood to equally refer to the another node 115. The sequence diagram of the nonlimiting example of embodiments herein based on DNS Zone Transfer, is shown in Figure 6, for the specific example of a NEF supporting the new NEF service / API, which may allow DNS zone transfers from (external) DNS (authoritative) servers, and the NEF storing the retrieved DNS Zone information in the UDR. Other examples may be possible, e.g., other 5GC NF such as the SMF storing the zone information instead of the UDR. In this example, for the sake of simplicity, it is assumed a deployment where the NEF may include the CAPIF Core Function. For details, please refer to 3GPP TS 23.222 Annex B (Figure B.2.2.2-1 “NEF implements the CAPIF architecture”). In Steps 1 and 2), the DNS Server, e.g., primary-server.com, acting as AF, may trigger an onboarding procedure to the network operator. To do so, the DNS Server may trigger an Onboarding request (Onboard_API_lnvoker) message to the CAPIF Core Function at the NEF, including the following information: a) afID = primary-server.com, which may identify the AF, b) afIPAddress, which may include the AF IP address, and c) List of Zone names, which may include the list of Zones supported by the DNS Server. The NEF may receive the Onboarding request message in agreement with Action 501. In Step 3) the NEF may answer the DNS Server with an Onboarding response message indicating successful operation. In Steps 4 and 5), the NEF, in agreement with Action 502, may trigger a DNS Zone transfer procedure. According to embodiments herein, the NEF may support a new service, which may be implemented as an extension of a DNS client supporting AXFR type of queries. The NEF may trigger a DNS query message including: a) DNS query type=AXFR , which may indicate AXFR type of DNS query, and b) requested Zone name, which may indicate the requested zone name(s). The criteria for the MNO, via the NEF, to select which may be the zones to request may be based on applications, for which the MNO may need to detect and apply traffic management actions, e.g., based on subscription data and / or application data in the UDR, if the MNO offers their subscribers a subscription to gaming applications with low latency, the zones corresponding to those gaming applications may be requested. Other criteria may be per domain. For simplicity, the SOA request is not shown in Figure 6. Usually, a SOA request precedes the AXFR request. In Steps 6 and 7), the DNS server may look for the requested Zone data and, in agreement with Action 503, may return it in DNS answer message comprising the requested Zone information. In Steps 8 and 9), the NEF, in agreement with Action 504 and Action 401 , may trigger towards the UDR a request to store the retrieved Zone information, by triggering a Nudr_Store request message comprising the Zone information. In Step 10), the UDR may store the Zone information in agreement with Action 402. According to embodiments herein, the UDR may support a new data structure relative to DNS information. In Step 11), the UDR may answer the NEF indicating successful operation by sending a Nudr_Store Response.
[0181] Figure 7 is a schematic diagram depicting another non-limiting example of signalling between nodes in the communications system 100, according to embodiments herein. Particularly, Figure 7 depicts an example of a method of assisted traffic detection. In Figure 7, the communications system 100 is a 5G network, the first node 111 is a U PF, the second node 112 is a UDR, the fourth node 114 is an SMF, the another node 115 is an Application Server, the sixth node 116 is a PCF, the seventh node 117 is an AMF and the device 130 is a UE. It may be understood that in the following example depicted in Figure 7, any reference to the UPF may be understood to equally refer to the first node 111, any reference to the UDR may be understood to equally refer to the second node 112, any reference to the SMF may be understood to equally refer to the fourth node 114, any reference to the Application Server may be understood to equally refer to the another node 115, any reference to the PCF may be understood to equally refer to the sixth node 116, any reference to the AMF may be understood to equally refer to the seventh node 117 and any reference to the UE may be understood to equally refer to the device 130. The sequence diagram of the non-limiting example of embodiments herein shown in Figure 3, may be understood to be for the specific embodiment of the UPF(s) retrieving, via pull procedure, that is, via a request / response, information from the UDR, enabling traffic management when traffic is encrypted. Other embodiments may be understood to be possible, such as UPF(s) retrieving via push procedure, that is, via a subscribe / notify, the information from the UDR, or from other 5GC NFs such as the SMF, as indicated above. Starting in panel a), in Steps 1 and 2), in the PFCP Association procedure, the UPF, in agreement with Action 301, may report to the SMF a new capability, of assisted traffic detection. The UPF may send a PFCP Association Request comprising the UPF capabilities of assisted traffic detection. This may allow the SMF to select a UPF supporting this capability on a per PFCP session basis. In Step 2, the SMF may send a PFCP Association Response, in agreement with Action 302. In Step 3), the UPF, may retrieve the DNS zone database from UDR. In order to do this, the UPF, in agreement with Action 303 and Action 403, may trigger a Nudr_Query Request message asking for the whole DNS zone database or just a list of requested DNS Zones. As indicated above, the criteria for UPF to select which may be the zones to request may be based on applications, for which the UPF may need to detect and apply traffic management actions. For example, if the UPF pertains to an MBB slice and, as indicated above, the MNO offers their MBB subscribers a subscription to gaming apps, the UPF may retrieve the zones corresponding to those gaming apps. If the UPF pertains to an Enterprise slice, the UPF may retrieve the zones corresponding to Enterprise apps. Other criteria may be per domain. In Step 4), the UDR, in agreement with Action 404 and Action 304, may answer the UPF with a Nudr_Query Response message including the DNS Zones information. In Steps 5 to 7), the UE may trigger a PDU Session Establishment procedure by sending a PDU Session Establishment Request to the AMF. The AMF may then send a Nsmf PDU Session Create to the SMF and the SMF may send a Npcf_SMPolicyControl_Create Request to the PCF. Only selected messages for embodiments herein may be understood to be shown in Figure 7 with respect to this procedure. Continuing in panel b), in Steps 8 and 9) The PCF may retrieve from UDR the subscriber data, e.g., based on the UE-ID, and / or application data, by sending a Nudr_Query Request with the UE-ID. The UDR may response by sending a Nudr_Query Response comprising the Subscriber data. In Step 10), the PCF may generate PCC rules, including a PCC rule for App-ID=example.com and send an Npcf_Policy Response comprising PCC rules including a PCC rule for App-ID (example.com). In Steps 11 to 13), the SMF may select a UPF supporting the assisted traffic detection capability. The SMF may trigger a PFCP Session Establishment procedure towards the UPF by sending a PFCP Session Establishment Request, to indicate the PDRs and the corresponding enforcement actions, e.g., FARs, QERs, URRs, etc, for the PDU session, specifically by including a PDR for App-ID=example.com and the corresponding traffic management actions, through an associated FAR, QER and / or URR. The UPF may the send a PFCP Session Establishment Response back to the SMF.
[0182] Continuing in panel c), in Steps 14 to 16), the UE may trigger application traffic, e.g., with App-ID=example.com, including an encrypted QUIC / TLS CHLO. The traffic may comprise a flow with a certain 5-tuple. The UPF may, in agreement with Action 305, detect a new flow, that is, the 5-tuple including a Server IP address, and, in agreement with Action 306, may, retrieve the domain corresponding to that Server IP address through the DNS Zones database retrieved in Step 4 above. Based on the associated domain, the UPF may then, in agreement with Action 307, classify the packets in this flow into the PDR for App-ID=example.com, and the corresponding traffic management actions may be executed, e.g., associated FAR, QER and / or URR. The UPF may then forward the application traffic including an encrypted QUIC / TLS CHLO, that is, the flow with the certain 5-tuple, towards the application server. As mentioned, other embodiments may be possible, e.g., the SMF may store the zone information, instead of the UDR, which the be advantageous considering multi-vendor deployments where the UDR may be from a different vendor, for addressing the UPF change scenario or, generally ,for more flexibility, e.g., update of required zone information, request of zone info, or even only reverse DNS query, by the UPF only when required. Regarding the UPF change scenario, such as UPF relocation or UPF reselection, for one or several PDU sessions, it may happen that the UPF may need to retrieve other zones, e.g., if the relocated PDU session / s has / have PCC rules for App-IDs for which the UPF may not have the corresponding zone information previously stored. In that case, instead of retrieving a full copy of the zone information, the UPF may request only the needed zones information.
[0183] Certain embodiments disclosed herein may provide one or more of the following technical advantage(s), which may be summarized as follows.
[0184] Embodiments herein may be understood to allow the network operator of the communications system 100 to apply traffic management actions in a simple an efficient way, especially when the traffic is encrypted, e.g., via DNS encryption, such as DoH / DoT, HTTPS, e.g., TLS, or QUIC based applications, when SNI is encrypted, either through QUIC Client Hello encryption or through ECH / ESNI in TLS 1.3.
[0185] Embodiments herein may be understood to enable a very efficient procedure as a domain, e.g., videostreamingprovider, may usually have many subdomains, e.g., a popular video streaming provider domain has more than 20k subdomains. Hence, triggering individual queries would imply a very high number of DNS transactions, e.g., more than 20k. In contrast, with the proposed extension based on DNS Zone transfer, all the zone information from the DNS Server may be available at the MNO. Furthermore, embodiments herein may be understood to enable a seamless procedure in comparison with other collaborative approaches that may imply to create a new framework to send the detection rules, as embodiments herein may rely in an existing DNS technique present in all the DNS servers.
[0186] Figure 8 depicts an example of the arrangement that the first node 111 may comprise to perform the method described in Figure 3 and / or Figure 7. The first node 111 may be understood to be for handling the information. The first node 111 is configured to operate in the communications system 100.
[0187] Several embodiments are comprised herein. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here. For example, in some examples, the address of the another node 115 may be configured to be a Server IP address.
[0188] The first node 111 is configured to detect the flow of traffic between the device 130 configured to operate in the communications system 100 and the another node 115 external to the communications system 100. The traffic is configured to comprise the first indication of the domain corresponding to the another node 115, and the second indication configured to indicate the address of the another node 115. The first indication is configured to be encrypted and not decryptable by the first node 111. The second indication is configured to be un-encrypted and lacking the explicit indication of the domain.
[0189] The first node 111 is also configured to determine, responsive to the detected flow of traffic, the domain configured to correspond to the another node 115, as the domain configured to correspond to the second indication in the stored DNS zone information configured to have been previously obtained from the another node 115.
[0190] The first node 111 is further configured to initiate managing the traffic based on the domain configured to be determined.
[0191] In some embodiments, at least one of the following may apply: a) the communications system 100 may be configured to be a 5G network and: i) the first node 111 may be configured to be a UPF, and ii) the another node 115 may be configured to be an AS, and b) the communications system 100 may be configured to be a 4G network, and: i) the first node 111 may be configured to be one of a PGW-ll and a TDF-ll, and ii) the another node 115 may be configured to be an AS. In some embodiments, the first node 111 may be further configured to send, prior to the determining, the first message to the second node 112 configured to operate in the communications system 100. The first message may be configured to comprise the first request for the stored DNS zone information from the second node 112.
[0192] In some embodiments, the first node 111 may be further configured to receive, responsive to the first message configured to be sent, the second message from the second node 112. The second message may be configured to comprise the requested stored DNS zone information, and the determining may be configured to be based on the second message configured to be received.
[0193] In some embodiments, at least one of the following may apply: i) the first message may be configured to be a query request, and the second message is configured to be a query response, and ii )the first message may be configured to be a subscription request, and the second message is configured to be a notification response.
[0194] In some embodiments, at least one of the following may apply: a) the requested stored DNS zone information may be configured to be based on one or more criteria, b) the criteria may be configured to comprise at least one of application and domain related, and c) the communications system 100 may be configured to be one of: i) a 5G network and the second node 112 may be configured to be one of a II DR and an SMF, and ii) a 4G network, and the second node 112 may be configured to be one of: an SPR, a PGW-C, and a TDF-C.
[0195] In some embodiments, the first node 111 may be further configured to send, prior to the determining, the first previous indication to the further node 114 configured to operate in the communications system 100. The first previous indication may be configured to indicate the capability of the first node 111 to determine a domain, based on stored DNS zone information.
[0196] In some embodiments, the first node 111 may be further configured to receive, responsive to the sent first previous indication, the second previous indication from the further node 114. The second previous indication may be configured to confirm receipt by the further node 114 of the first previous indication. The flow of traffic may be configured to be detected based on the receipt of the first previous indication configured to be confirmed.
[0197] In some embodiments, at least one of the following may apply: a) the first previous indication may be configured to be a PFCP association request, b) the second previous indication may be configured to be a PFCP association response, and c) the communications system 100 may be configured to be one of: i) a 5G network and the further node 114 may be configured to be an SMF, and ii) a 4G network, and the further node 114 may be configured to be one of: a PGW-C and a TDF-C.
[0198] In some embodiments, at least one of the following may apply: a) the first indication may be configured to be one of a URI and an SNI, b) the second indication may be configured to be comprised in a 5-tuple, c) the second indication may be configured to be an IP address, d) the stored DNS zone information may be configured to have been previously obtained from the another node 115 based on a DNS zone transfer and e) the managing of the traffic may be configured to comprise at least one of: classifying the traffic and applying a traffic management rule.
[0199] The embodiments herein in the first node 111 may be implemented through one or more processors, such as a processing circuitry 801 in the first node 111 depicted in Figure 8, together with computer program code for performing the functions and actions of the embodiments herein. A processor, as used herein, may be understood to be a hardware component. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the first node 111. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the first node 111.
[0200] The first node 111 may further comprise a memory 802 comprising one or more memory units. The memory 802 is arranged to be used to store obtained information, store data, configurations, schedulings, and applications etc. to perform the methods herein when being executed in the first node 111.
[0201] In some embodiments, the first node 111 may receive information from, e.g., the second node 112, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a receiving port 803. In some embodiments, the receiving port 803 may be, for example, connected to one or more antennas in first node 111. In other embodiments, the first node 111 may receive information from another structure in the communications system 100 through the receiving port 803. Since the receiving port 803 may be in communication with the processing circuitry 801 , the receiving port 803 may then send the received information to the processing circuitry 801. The receiving port 803 may also be configured to receive other information.
[0202] The processing circuitry 801 in the first node 111 may be further configured to transmit or send information to e.g., the second node 112, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a sending port 804, which may be in communication with the processing circuitry 801, and the memory 802.
[0203] Those skilled in the art will also appreciate that the units comprised within the first node 111 described above as being configured to perform different actions, may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g., stored in memory, that, when executed by the one or more processors such as the processing circuitry 801 , perform as described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuit (ASIC), or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).
[0204] The first node 111 may be configured to perform any of the Actions described in relation to Figure 3 and / or Figure 7, e.g., by means of the processing circuitry 801 within the first node 111 , configured to perform any of such actions.
[0205] Also, in some embodiments, different units comprised within the first node 111 may be configured to perform the different actions described above, implemented as one or more applications running on one or more processors such as the processing circuitry 801.
[0206] Thus, the methods according to the embodiments described herein for the first node 111 may be respectively implemented by means of a computer program 805 product, comprising instructions, i.e. , software code portions, which, when executed on at least one processing circuitry 801, cause the at least one processing circuitry 801 to carry out the actions described herein, as performed by the first node 111. The computer program 805 product may be stored on a computer-readable storage medium 806. The computer-readable storage medium 806, having stored thereon the computer program 805, may comprise instructions which, when executed on at least one processing circuitry 801 , cause the at least one processing circuitry 801 to carry out the actions described herein, as performed by the first node 111. In some embodiments, the computer-readable storage medium 806 may be a non-transitory computer- readable storage medium, such as a CD ROM disc, or a memory stick. In other embodiments, the computer program 805 product may be stored on a carrier containing the computer program 805 just described, wherein the carrier is one of an electronic signal, optical signal, radio signal, or the computer-readable storage medium 806, as described above.
[0207] The first node 111 may comprise a communication interface configured to facilitate, or an interface unit to facilitate, communications between the first node 111 and other nodes or devices, e.g., the second node 112, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. The interface may, for example, include a transceiver configured to transmit and receive radio signals over an air interface in accordance with a suitable standard.
[0208] In other embodiments, the first node 111 may comprise a radio circuitry 807, which may comprise e.g., the receiving port 803 and the sending port 804.
[0209] The radio circuitry 807 may be configured to set up and maintain at least a wireless connection with the second node 112, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. Circuitry may be understood herein as a hardware component.
[0210] Hence, embodiments herein also relate to the first node 111 operative to operate in the communications system 100. The first node 111 may comprise the processing circuitry 801 and the memory 802, said memory 802 containing instructions executable by said processing circuitry 801 , whereby the first node 111 is further operative to perform the actions described herein in relation to the first node 111 , e.g., in Figure 3 and / or Figure 7.
[0211] Figure 9 depicts an example of the arrangement that the second node 112 may comprise to perform the method described in Figure 4, Figure 6 and / or Figure 7. The second node 112 may be understood to be for handling the information. The second node 112 is configured to operate in the communications system 100.
[0212] Several embodiments are comprised herein. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the second node 111 and will thus not be repeated here. For example, in some examples, the address of the another node 115 may be configured to be a Server IP address.
[0213] The second node 112 is configured to receive the earlier message from the third node 113 configured to operate in the communications system 100. The earlier message is configured to comprise the second request to store the DNS zone information, configured to have been previously obtained from the another node 115 external to the communications system 100. The DNS zone information is configured to comprise the second indication configured to indicate the address of the another node 115. The second indication is configured to lack the explicit indication of the domain corresponding to the another node 115.- The DNS zone information is further configured to comprise the correspondence between the second indication and the domain.
[0214] The second node 112 is also configured to store the DNS zone information responsive to receiving the earlier message.
[0215] The second node 112 is further configured to receive, after having received the earlier message, the first message from the first node 111 configured to operate in the communications system 100. The first message is configured to comprise the first request for the DNS zone information configured to be stored. The second node 112 is additionally configured to send, responsive to the first message configured to be received, the second message to the first node 111. The second message is configured to comprise the stored DNS zone information configured to be requested.
[0216] In some embodiments, one of the following may apply: a) the first message may be configured to be a query request, and the second message may be configured to be a query response, and b) the first message may be configured to be a subscription request, and the second message may be configured to be a notification response.
[0217] In some embodiments, at least one of the following may apply: a) the requested stored DNS zone information may be configured to be based on the one or more criteria, b) the criteria may be configured to comprise at least one of application and domain related, and c) the communications system 100 may be configured to be one of: i) a 5G network and the first node 111 may be configured to be a UPF, the second node 112 may be configured to be one of a UDR, and an SMF, the third node 113 may be configured to be a NEF, and the another node 115 may be configured to be an AS, and ii) a 4G network, and the first node 111 may be configured to be one of a PGW-ll and a TDF-ll, the second node 112 may be configured to be one of: an SPR, a PGW-C, and a TDF-C, the third node 113 may be configured to be a SCEF, and the another node 115 may be configured to be an AS.
[0218] In some embodiments, at least one of the following may apply: a) the second indication may be configured to be comprised in the 5-tuple, b) the second indication may be configured to be the IP, address, and c) the stored DNS zone information may be configured to have been previously obtained from the another node 115 based on a DNS zone transfer.
[0219] In some embodiments, at least one of the following may apply: a) the application to which the traffic may be configured to belong may be configured to use one of dual proxy deployment and a virtual private network, b) the first node 111 may be configured to be one of: a NEF, and a BSS, c) the second node 112 may be configured to be one of an AF and an AS of the provider of the content, and d) the communications system 100 may be configured to be a 5G network.
[0220] The embodiments herein in the second node 112 may be implemented through one or more processors, such as a processing circuitry 901 in the second node 112 depicted in Figure 9, together with computer program code for performing the functions and actions of the embodiments herein. A processor, as used herein, may be understood to be a hardware component. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the second node 112. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the second node 112. The second node 112 may further comprise a memory 902 comprising one or more memory units. The memory 902 is arranged to be used to store obtained information, store data, configurations, schedulings, and applications etc. to perform the methods herein when being executed in the second node 112.
[0221] In some embodiments, the second node 112 may receive information from, e.g., the first node 111 , the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a receiving port 903. In some embodiments, the receiving port 903 may be, for example, connected to one or more antennas in second node 112. In other embodiments, the second node 112 may receive information from another structure in the communications system 100 through the receiving port 903. Since the receiving port 903 may be in communication with the processing circuitry 901 , the receiving port 903 may then send the received information to the processing circuitry 901. The receiving port 903 may also be configured to receive other information.
[0222] The processing circuitry 901 in the second node 112 may be further configured to transmit or send information to e.g., the first node 111, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a sending port 904, which may be in communication with the processing circuitry 901 , and the memory 902.
[0223] Those skilled in the art will also appreciate that the units comprised within the second node 112 described above as being configured to perform different actions, may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g., stored in memory, that, when executed by the one or more processors such as the processing circuitry 901 , perform as described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuit (ASIC), or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).
[0224] The second node 112 may be configured to perform any of the Actions described in relation to Figure 4, Figure 6 and / or Figure 7, e.g., by means of the processing circuitry 901 within the second node 112, configured to perform any of such actions.
[0225] Also, in some embodiments, different units comprised within the second node 112 may be configured to perform different actions described above, implemented as one or more applications running on one or more processors such as the processing circuitry 901.
[0226] Thus, the methods according to the embodiments described herein for the second node 112 may be respectively implemented by means of a computer program 905 product, comprising instructions, i.e., software code portions, which, when executed on at least one processing circuitry 901 , cause the at least one processing circuitry 901 to carry out the actions described herein, as performed by the second node 112. The computer program 905 product may be stored on a computer-readable storage medium 906. The computer- readable storage medium 906, having stored thereon the computer program 905, may comprise instructions which, when executed on at least one processing circuitry 901 , cause the at least one processing circuitry 901 to carry out the actions described herein, as performed by the second node 112. In some embodiments, the computer-readable storage medium 906 may be a non-transitory computer-readable storage medium, such as a CD ROM disc, or a memory stick. In other embodiments, the computer program 905 product may be stored on a carrier containing the computer program 905 just described, wherein the carrier is one of an electronic signal, optical signal, radio signal, or the computer-readable storage medium 906, as described above.
[0227] The second node 112 may comprise a communication interface configured to facilitate, or an interface unit to facilitate, communications between the second node 112 and other nodes or devices, e.g., the first node 111, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. The interface may, for example, include a transceiver configured to transmit and receive radio signals over an air interface in accordance with a suitable standard.
[0228] In other embodiments, the second node 112 may comprise a radio circuitry 907, which may comprise e.g., the receiving port 903 and the sending port 904.
[0229] The radio circuitry 907 may be configured to set up and maintain at least a wireless connection with the first node 111, the third node 113, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. Circuitry may be understood herein as a hardware component.
[0230] Hence, embodiments herein also relate to the second node 112, operative to operate in the communications system 100. The second node 112 may comprise the processing circuitry 901 and the memory 902, said memory 902 containing instructions executable by said processing circuitry 901, whereby the second node 112 is further operative to perform the actions described herein in relation to the second node 112, e.g., in Figure 4, Figure 6 and / or Figure 7.
[0231] Figure 10 depicts an example of the arrangement that the third node 113 may comprise to perform the method described in Figure 5 and / or Figure 6. The third node 113 may be understood to be for handling the information. The third node 113 is configured to operate in the communications system 100.
[0232] Several embodiments are comprised herein. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 101 and will thus not be repeated here. For example, in some examples, the address of the another node 115 may be configured to be a Server IP address.
[0233] The third node 113 is configured to send the earlier message to the second node 112 configured to operate in the communications system 100. The earlier message is configured to comprise the second request to store the DNS zone information, configured to have been previously obtained from the another node 115 external to the communications system 100. The DNS zone information is configured to comprise the second indication configured to indicate the address of the another node 115. The second indication is configured to lack the explicit indication of the domain configured to correspond to the another node 115. The DNS zone information is configured to further comprise the correspondence between the second indication and the domain.
[0234] The third node 113 may be further configured to receive the third request from the another node 115. The third request may be configured to indicate the first identifier of the another node 115, the address of the another node 115 and the one or more DNS zones configured to supported by the another node 115.
[0235] The third node 113 may be further configured to send, responsive to the received third request, the third message to the another node 115. The third message is configured to indicate to initiate the transfer procedure to obtain the DNS zone information.
[0236] The third node 113 may be further configured to receive, responsive to the third message configured to be sent, the fourth message from the another node 115. The fourth message may be configured to comprise the requested DNS zone information. The sending of the earlier message may be configured to be performed responsive to the receiving of the fourth message.
[0237] In some embodiments, at least one of the following may apply: a) the third request may be configured to be comprised in an Onboarding request message, b) the third request may be configured to be directed to a CAPIF Core Function of the third node 113, c) the first identifier may be configured to be an application identifier, d) the address may be configured to be an IP address of an application function, e) the one or more DNS zones may be configured to be comprised in the list, f) the third message may be configured to be a DNS query message, and g) the third message may be configured to be comprise the DNS query type, and the one or more names of the one or more DNS zones configured to be requested.
[0238] In some embodiments, at least one of the following may apply: a) the second indication may be configured to be comprised in a 5-tuple, b) the second indication may be configured to be the IP address, c) the stored DNS zone information may be configured to have been previously obtained from the another node 115 based on the DNS zone transfer, d) the DNS zone information requested to be stored may be configured to be based on the one or more criteria, e) the criteria may be configured to comprise at least one of application and domain related, and f) the communications system 100 may be configured to be one of: i) a 5G network and: the first node 111 may be configured to be a UPF, the another node 115 may be configured to be an AS, the second node 112 may be configured to be one of a II DR and an SMF, and the third node 113 may be configured to be a NEF, and ii ) a 4G network and: the first node 111 may be configured to be one of a PGW-ll and a TDF-ll, the another node 115 may be configured to be an AS, the second node 112 may be configured to be one of: an SPR a PGW-C and a TDF-C, and the third node 113 may be configured to be a SCEF.
[0239] The embodiments herein in the third node 113 may be implemented through one or more processors, such as a processing circuitry 1001 in the third node 113 depicted in Figure 10, together with computer program code for performing the functions and actions of the embodiments herein. A processor, as used herein, may be understood to be a hardware component. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the third node 113. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the third node 113.
[0240] The third node 113 may further comprise a memory 1002 comprising one or more memory units. The memory 1002 is arranged to be used to store obtained information, store data, configurations, schedulings, and applications etc. to perform the methods herein when being executed in the third node 113.
[0241] In some embodiments, the third node 113 may receive information from, e.g., the first node 111, the second node 112, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a receiving port 1003. In some embodiments, the receiving port 1003 may be, for example, connected to one or more antennas in third node 113. In other embodiments, the third node 113 may receive information from another structure in the communications system 100 through the receiving port 1003. Since the receiving port 1003 may be in communication with the processing circuitry 1001, the receiving port 1003 may then send the received information to the processing circuitry 1001. The receiving port 1003 may also be configured to receive other information.
[0242] The processing circuitry 1001 in the third node 113 may be further configured to transmit or send information to e.g., the first node 111 , the second node 112, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a sending port 1004, which may be in communication with the processing circuitry 1001, and the memory 1002.
[0243] Those skilled in the art will also appreciate that the units comprised within the third node 113 described above as being configured to perform different actions, may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g., stored in memory, that, when executed by the one or more processors such as the processing circuitry 1001 , perform as described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuit (ASIC), or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).
[0244] The third node 113 may be configured to perform any of the Actions described in relation to Figure 5 and / or Figure 7, e.g., by means of the processing circuitry 1001 within the third node 113, configured to perform any of such actions.
[0245] Also, in some embodiments, different units comprised within the third node 113 may be configured to perform the different actions described above, implemented as one or more applications running on one or more processors such as the processing circuitry 1001.
[0246] Thus, the methods according to the embodiments described herein for the third node 113 may be respectively implemented by means of a computer program 1005 product, comprising instructions, i.e., software code portions, which, when executed on at least one processing circuitry 1001, cause the at least one processing circuitry 1001 to carry out the actions described herein, as performed by the third node 113. The computer program 1005 product may be stored on a computer-readable storage medium 1006. The computer- readable storage medium 1006, having stored thereon the computer program 1005, may comprise instructions which, when executed on at least one processing circuitry 1001, cause the at least one processing circuitry 1001 to carry out the actions described herein, as performed by the third node 113. In some embodiments, the computer-readable storage medium 1006 may be a non-transitory computer-readable storage medium, such as a CD ROM disc, or a memory stick. In other embodiments, the computer program 1005 product may be stored on a carrier containing the computer program 1005 just described, wherein the carrier is one of an electronic signal, optical signal, radio signal, or the computer-readable storage medium 1006, as described above.
[0247] The third node 113 may comprise a communication interface configured to facilitate, or an interface unit to facilitate, communications between the third node 113 and other nodes or devices, e.g., the first node 111, the second node 112, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. The interface may, for example, include a transceiver configured to transmit and receive radio signals over an air interface in accordance with a suitable standard.
[0248] In other embodiments, the third node 113 may comprise a radio circuitry 1007, which may comprise e.g., the receiving port 1003 and the sending port 1004.
[0249] The radio circuitry 1007 may be configured to set up and maintain at least a wireless connection with the first node 111, the second node 112, the fourth node 114, the another node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. Circuitry may be understood herein as a hardware component.
[0250] Hence, embodiments herein also relate to the third node 113, operative to operate in the communications system 100. The third node 113 may comprise the processing circuitry 1001 and the memory 1002, said memory 1002 containing instructions executable by said processing circuitry 1001, whereby the third node 113 is further operative to perform the actions described herein in relation to the third node 113, e.g., in Figure 5 and / or Figure 6.
[0251] Embodiments herein may also comprise the communications system 100 comprising one or more of: the first node 111 configured as described in relation to Figure 8, the second node 112 configured as described in relation to Figure 9, and the third node 113 configured as described in relation to Figure 10.
[0252] When using the word "comprise" or “comprising”, it shall be interpreted as non- limiting, i.e. , meaning "consist at least of".
[0253] The embodiments herein are not limited to the above-described preferred embodiments. Various alternatives, modifications and equivalents may be used. Therefore, the above embodiments should not be taken as limiting the scope of the invention.
[0254] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features and advantages of the enclosed embodiments will be apparent from the following description.
[0255] As used herein, the expression “at least one of:” followed by a list of alternatives separated by commas, and wherein the last alternative is preceded by the “and” term, may be understood to mean that only one of the list of alternatives may apply, more than one of the list of alternatives may apply or all of the list of alternatives may apply. This expression may be understood to be equivalent to the expression “at least one of:” followed by a list of alternatives separated by commas, and wherein the last alternative is preceded by the “or” term.
[0256] Any of the terms processor and circuitry may be understood herein as a hardware component.
[0257] As used herein, the expression “in some embodiments” has been used to indicate that the features of the embodiment described may be combined with any other embodiment or example disclosed herein.
[0258] As used herein, the expression “in some examples” has been used to indicate that the features of the example described may be combined with any other embodiment or example disclosed herein.
[0259] REFERENCES
[0260] 1. RFC 5936 “DNS Zone Transfer Protocol”.
[0261] 2. 3GPP TS 29.522 v18.0.0 (Dec 2022) “5G System; Network Exposure Function Northbound APIs; Stage 3”.
[0262] 3. 3GPP TS 29.122 v18.0.0 (Dec 2022) “T8 reference point for Northbound APIs”.
Claims
CLAIMS:1 . A computer-implemented method, performed by a first node (111), for handling information, the first node (111) operating in a communications system (100), the method comprising:- detecting (305) a flow of traffic between a device (130) operating in the communications system (100) and another node (115) external to the communications system (100), wherein the traffic comprises a first indication of a domain corresponding to the another node (115), and a second indication indicating an address of the another node (115), wherein the first indication is encrypted and not decryptable by the first node (111), and wherein the second indication is un-encrypted and lacking an explicit indication of the domain,- determining (306), responsive to the detected flow of traffic, the domain corresponding to the another node (115), as the domain corresponding to the second indication in stored Domain Name System, DNS, zone information previously obtained from the another node (115), and- initiating (307) managing the traffic based on the determined domain.
2. The method according to claim 1 , wherein one of: a. the communications system (100) is a Fifth Generation, 5G, network and: i. the first node (111) is a User Plane Function, UPF, ii. the another node (115) is an Application Server, and b. the communications system (100) is a Fourth Generation, 4G, network, and: i. the first node (111) is one of a Packet Gateway User Plane, PGW-U, and a Traffic Detection Function User Plane, TDF-U, and ii. the another node (115) is an Application Server.
3. The method according to any of claims 1-2, further comprising:- sending (303), prior to the determining (306), a first message to a second node(112) operating in the communications system (100), the first message comprising a first request for the stored DNS zone information from the second node (112), and- receiving (304), responsive to the sent first message, a second message from the second node (112), the second message comprising the requested stored DNS zone information, and wherein the determining (306) is based on the received second message.
4. The method according to claim 3, wherein one of: a. the first message is a query request, and the second message is a query response, and b. the first message is a subscription request, and the second message is a notification response.
5. The method according to any of claims 3-4, wherein at least one of: a. the requested stored DNS zone information is based on one or more criteria, b. the criteria comprise at least one of application and domain related, and c. the communications system (100) is one of: i. a Fifth Generation, 5G, network and the second node (112) is one of a User Data Repository, UDR, and a Session Management Function, SMF, and ii. a Fourth Generation, 4G, network, and the second node (112) is one of: a Subscriber Profile Repository, SPR, a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF-C.
6. The method according to any of claims 1-2, further comprising:- sending (301), prior to the determining (306), a first previous indication to a further node (114) operating in the communications system (100), the first previous indication indicating a capability of the first node (111) to determine a domain, based on stored DNS zone information, and- receiving (302), responsive to the sent first previous indication, a second previous indication from the further node (114), the second previous indication confirming receipt by the further node (114) of the first previous indication, and wherein the flow of traffic is detected based on the confirmed receipt of the first previous indication.
7. The method according to claim 6, wherein at least one of one of: a. the first previous indication is a Packet Flow Control Protocol, PFCP, association request, b. the second previous indication is a PFCP association response, and c. the communications system (100) is one of: i. a Fifth Generation, 5G, network and the further node (114) is a Session Management Function, SMF, andii. a Fourth Generation, 4G, network, and the further node (114) is one of: a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF-C.
8. The method according to any of claims 1-7, wherein at least one of: a. the first indication is one of a Uniform Resource Locator, URI, and a Server Name Indication, SNI, b. the second indication is comprised in a 5-tuple, c. the second indication is an internet protocol, IP, address, d. the stored DNS zone information has been previously obtained from the another node (115) based on a DNS zone transfer, and e. the managing of the traffic comprises at least one of: classifying the traffic and applying a traffic management rule.
9. A computer-implemented method, performed by a second node (112), for handling information, the second node (112) operating in a communications system (100), the method comprising:- receiving (401) an earlier message from a third node (113) operating in the communications system (100), the earlier message comprising a second request to store Domain Name System, DNS, zone information, previously obtained from another node (115) external to the communications system (100), the DNS zone information comprising a second indication indicating an address of the another node (115), wherein the second indication lacks an explicit indication of a domain corresponding to the another node (115), and wherein the DNS zone information further comprises a correspondence between the second indication and the domain,- storing (402) the DNS zone information responsive to receiving (401) the earlier message,- receiving (403), after having received the earlier message, a first message from a first node (111) operating in the communications system (100), the first message comprising a first request for the stored DNS zone information, and- sending (404), responsive to the received first message, a second message to the first node (111), the second message comprising the requested stored DNS zone information.
10. The method according to claim 9, wherein one of:a. the first message is a query request, and the second message is a query response, and b. the first message is a subscription request, and the second message is a notification response.
11. The method according to any of claims 9-10, wherein at least one of: a. the requested stored DNS zone information is based on one or more criteria, b. the criteria comprise at least one of application and domain related, and c. the communications system (100) is one of: i. a Fifth Generation, 5G, network and: the first node (111) is a User Plane Function, UPF, the second node (112) is one of a User Data Repository, UDR, and a Session Management Function, SMF, the third node (113) is a Network Exposure Function, NEF, and the another node (115) is an Application Server, and ii. a Fourth Generation, 4G, network, and: the first node (111) is one of a Packet Gateway User Plane, PGW-U, and a Traffic Detection Function User Plane, TDF-U, the second node (112) is one of: a Subscriber Profile Repository, SPR, a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF-C, the third node (113) is a Service Capability Exposure Function, SCEF, and the another node (115) is an Application Server.
12. The method according to any of claims 9-11, wherein at least one of: a. the second indication is comprised in a 5-tuple, b. the second indication is an internet protocol, IP, address, and c. the stored DNS zone information has been previously obtained from the another node (115) based on a DNS zone transfer.
13. A computer-implemented method, performed by a third node (113), for handling information, the third node (113) operating in a communications system (100), the method comprising:- sending (504) an earlier message to a second node (112) operating in the communications system (100), the earlier message comprising a second requestto store Domain Name System, DNS, zone information, previously obtained from another node (115) external to the communications system (100), the DNS zone information comprising a second indication indicating an address of the another node (115), wherein the second indication lacks an explicit indication of a domain corresponding to the another node (115), and wherein the DNS zone information further comprises a correspondence between the second indication and the domain.
14. The method according to claim 13, further comprising:- receiving (501) a third request from the another node (115), the third request indicating a first identifier of the another node (115), the address of the another node (115) and one or more DNS zones supported by the another node (115),- sending (502), responsive to the received third request, a third message to the another node (115), the third message indicating to initiate a transfer procedure to obtain the DNS zone information, and- receiving (503), responsive to the sent third message, a fourth message from the another node (115), the fourth message comprising the requested DNS zone information, and wherein the sending (504) of the earlier message is performed responsive to the receiving (503) of the fourth message.
15. The method according to claim 14, wherein at least one of: a. the third request is comprised in an Onboarding request message, b. the third request is directed to a Common Application Programming Interface Framework, CAPIF, Core Function of the third node (113), c. the first identifier is an application identifier, d. the address is an internet protocol address of an application function, e. the one or more DNS zones are comprised in a list, f. the third message is a DNS query message, and g. the third message comprises a DNS query type, and one or more names of the requested one or more DNS zones.
16. The method according to any of claims 13-15, wherein at least one of: a. the second indication is comprised in a 5-tuple, b. the second indication is an internet protocol, IP, address, c. the stored DNS zone information has been previously obtained from the another node (115) based on a DNS zone transfer.d. the DNS zone information requested to be stored is based on one or more criteria, e. the criteria comprise at least one of application and domain related, and f. the communications system (100) is one of: i. a Fifth Generation, 5G, network and: the first node (111) is a User Plane Function, UPF, the another node (115) is an Application Server, the second node (112) is one of a User Data Repository, UDR, and a Session Management Function, SMF, and the third node (113) is a Network Exposure Function, NEF, and ii. a Fourth Generation, 4G, network, and: the first node (111) is one of a Packet Gateway User Plane, PGW-U, and a Traffic Detection Function User Plane, TDF-U, and the another node (115) is an Application Server, the second node (112) is one of: a Subscriber Profile Repository, SPR, a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF-C, and the third node (113) is a Service Capability Exposure Function, SCEF.
17. A first node (111), for handling information, the first node (111) being configured to operate in a communications system (100), the first node (111) being further configured to:- detect a flow of traffic between a device (130) configured to operate in the communications system (100) and another node (115) external to the communications system (100), wherein the traffic is configured to comprise a first indication of a domain corresponding to the another node (115), and a second indication configured to indicate an address of the another node (115), wherein the first indication is configured to be encrypted and not decryptable by the first node (111), and wherein the second indication is configured to be un-encrypted and lacking an explicit indication of the domain,- determine, responsive to the detected flow of traffic, the domain configured to correspond to the another node (115), as the domain configured to correspond to the second indication in stored Domain Name System, DNS, zone information configured to have been previously obtained from the another node (115), and- initiate managing the traffic based on the domain configured to be determined.
18. The first node (111) according to claim 17, wherein one of: a. the communications system (100) is configured to be a Fifth Generation, 5G, network and: i. the first node (111) is configured to be a User Plane Function, UPF, ii. the another node (115) is configured to be an Application Server, and b. the communications system (100) is configured to be a Fourth Generation, 4G, network, and: i. the first node (111) is configured to be one of a Packet Gateway User Plane, PGW-U, and a Traffic Detection Function User Plane, TDF-U, and ii. the another node (115) is configured to be an Application Server.
19. The first node (111) according to any of claims 17-18, being further configured to:- send, prior to the determining, a first message to a second node (112) configured to operate in the communications system (100), the first message being configured to comprise a first request for the stored DNS zone information from the second node (112), and- receive, responsive to the first message configured to be sent, a second message from the second node (112), the second message being configured to comprise the requested stored DNS zone information, and wherein the determining is configured to be based on the second message configured to be received.
20. The first node (111) according to claim 19, wherein one of: a. the first message is configured to be a query request, and the second message is configured to be a query response, and b. the first message is configured to be a subscription request, and the second message is configured to be a notification response.
21. The first node (111) according to any of claims 19-20, wherein at least one of: a. the requested stored DNS zone information is configured to be based on one or more criteria, b. the criteria are configured to comprise at least one of application and domain related, and c. the communications system (100) is configured to be one of:i. a Fifth Generation, 5G, network and the second node (112) is configured to be one of a User Data Repository, UDR, and a Session Management Function, SMF, and ii. a Fourth Generation, 4G, network, and the second node (112) is configured to be one of: a Subscriber Profile Repository, SPR, a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF-C.
22. The first node (111) according to any of claims 17-18, being further configured to:- send, prior to the determining, a first previous indication to a further node (114) configured to operate in the communications system (100), the first previous indication being configured to indicate a capability of the first node (111) to determine a domain, based on stored DNS zone information, and- receive, responsive to the sent first previous indication, a second previous indication from the further node (114), the second previous indication being configured to confirm receipt by the further node (114) of the first previous indication, and wherein the flow of traffic is configured to be detected based on the receipt of the first previous indication configured to be confirmed.
23. The first node (111) according to claim 22, wherein at least one of one of: a. the first previous indication is configured to be a Packet Flow Control Protocol, PFCP, association request, b. the second previous indication is configured to be a PFCP association response, and c. the communications system (100) is configured to be one of: i. a Fifth Generation, 5G, network and the further node (114) is configured to be a Session Management Function, SMF, and ii. a Fourth Generation, 4G, network, and the further node (114) is configured to be one of: a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF-C.
24. The first node (111) according to any of claims 17-23, wherein at least one of: a. the first indication is configured to be one of a Uniform Resource Locator, URI, and a Server Name Indication, SNI, b. the second indication is configured to be comprised in a 5-tuple, c. the second indication is configured to be an internet protocol, IP, address,d. the stored DNS zone information is configured to have been previously obtained from the another node (115) based on a DNS zone transfer, and e. the managing of the traffic is configured to comprise at least one of: classifying the traffic and applying a traffic management rule.
25. A second node (112), for handling information, the second node (112) being configured to operate in a communications system (100), the second node (112) being further configured to:- receive an earlier message from a third node (113) configured to operate in the communications system (100), the earlier message being configured to comprise a second request to store Domain Name System, DNS, zone information, configured to have been previously obtained from another node (115) external to the communications system (100), the DNS zone information being configured to comprise a second indication configured to indicate an address of the another node (115), wherein the second indication is configured to lack an explicit indication of a domain corresponding to the another node (115), and wherein the DNS zone information is further configured to comprise a correspondence between the second indication and the domain,- store (402) the DNS zone information responsive to receiving the earlier message,- receive, after having received the earlier message, a first message from a first node (111) configured to operate in the communications system (100), the first message being configured to comprise a first request for the DNS zone information configured to be stored, and- send (404), responsive to the first message configured to be received, a second message to the first node (111), the second message being configured to comprise the stored DNS zone information configured to be requested.
26. The second node (112) according to claim 25, wherein one of: a. the first message is configured to be a query request, and the second message is configured to be a query response, and b. the first message is configured to be a subscription request, and the second message is configured to be a notification response.
27. The second node (112) according to any of claims 25-26, wherein at least one of: a. the requested stored DNS zone information is configured to be based on one or more criteria,b. the criteria are configured to comprise at least one of application and domain related, and c. the communications system (100) is configured to be one of: i. a Fifth Generation, 5G, network and: the first node (111) is configured to be a User Plane Function, UPF, the second node (112) is configured to be one of a User Data Repository, UDR, and a Session Management Function, SMF, the third node (113) is configured to be a Network Exposure Function, NEF, and the another node (115) is configured to be an Application Server, and ii. a Fourth Generation, 4G, network, and: the first node (111) is configured to be one of a Packet Gateway User Plane, PGW-U, and a Traffic Detection Function User Plane, TDF-U, the second node (112) is configured to be one of: a Subscriber Profile Repository, SPR, a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF- C, the third node (113) is configured to be a Service Capability Exposure Function, SCEF, and the another node (115) is configured to be an Application Server.
28. The second node (112) according to any of claims 25-27, wherein at least one of: a. the second indication is configured to be comprised in a 5-tuple, b. the second indication is configured to be an internet protocol, IP, address, and c. the stored DNS zone information is configured to have been previously obtained from the another node (115) based on a DNS zone transfer.
29. A third node (113), for handling information, the third node (113) being configured to operate in a communications system (100), the third node (113) being further configured to:- send (504) an earlier message to a second node (112) configured to operate in the communications system (100), the earlier message being configured to comprise asecond request to store Domain Name System, DNS, zone information, configured to have been previously obtained from another node (115) external to the communications system (100), the DNS zone information being configured to comprise a second indication configured to indicate an address of the another node (115), wherein the second indication is configured to lack an explicit indication of a domain configured to correspond to the another node (115), and wherein the DNS zone information is configured to further comprise a correspondence between the second indication and the domain.
30. The third node (113) according to claim 29, being further configured to:- receive a third request from the another node (115), the third request being configured to indicate a first identifier of the another node (115), the address of the another node (115) and one or more DNS zones configured to supported by the another node (115),- send, responsive to the received third request, a third message to the another node (115), the third message being configured to indicate to initiate a transfer procedure to obtain the DNS zone information, and- receive, responsive to the third message configured to be sent, a fourth message from the another node (115), the fourth message being configured to comprise the requested DNS zone information, and wherein the sending of the earlier message is configured to be performed responsive to the receiving of the fourth message.
31. The third node (113) according to claim 30, wherein at least one of: a. the third request is configured to be comprised in an Onboarding request message, b. the third request is configured to be directed to a Common Application Programming Interface Framework, CAPIF, Core Function of the third node (113), c. the first identifier is configured to be an application identifier, d. the address is configured to be an internet protocol address of an application function, e. the one or more DNS zones are configured to be comprised in a list, f. the third message is configured to be a DNS query message, and g. the third message is configured to be comprise a DNS query type, and one or more names of the one or more DNS zones configured to be requested.
32. The third node (113) according to any of claims 29-31, wherein at least one of:a. the second indication is configured to be comprised in a 5-tuple, b. the second indication is configured to be an internet protocol, IP, address, c. the stored DNS zone information is configured to have been previously obtained from the another node (115) based on a DNS zone transfer. d. the DNS zone information requested to be stored is configured to be based on one or more criteria, e. the criteria are configured to comprise at least one of application and domain related, and f. the communications system (100) is configured to be one of: i. a Fifth Generation, 5G, network and: the first node (111) is configured to be a User Plane Function, UPF, the another node (115) is configured to be an Application Server, the second node (112) is configured to be one of a User Data Repository, UDR, and a Session Management Function, SMF, and the third node (113) is configured to be a NEF, and ii. a Fourth Generation, 4G, network, and: the first node (111) is configured to be one of a Packet Gateway User Plane, PGW-U, and a Traffic Detection Function User Plane, TDF-U, and the another node (115) is configured to be an Application Server, the second node (112) is configured to be one of: a Subscriber Profile Repository, SPR, a Packet Gateway Control Plane, PGW-C, and a Traffic Detection Function Control Plane, TDF- C, and the third node (113) is configured to be a Service Capability Exposure Function, SCEF.
33. A communications system (100) comprising one or more of: a first node (111) according to any of the claims 17-24, a second node (112) according to any of the claims 25-28, and a third node (113) according to any of the claims 29-32.
Citation Information
Patent Citations
Methods and systems for efficient encrypted SNI filtering for cybersecurity applications
CA3186011A1
User Data Traffic Handling
US20220086691A1
Cited By
Network supervision method and device and electronic equipment
CN121442342A