Transport proxy node, and methods therein in a communications network

The transport proxy node facilitates secure and efficient transport connection management by establishing an authenticated session and moving the endpoint to the target node, addressing mobility and signaling overhead issues in 5G networks.

WO2025147203A1PCT designated stage expired Publication Date: 2025-07-10TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050007
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-05
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing solutions for QUIC server-side mobility and transport protocol context transfer in 5G networks fail to handle unexpected system failures and do not optimize signaling overhead in connections between network functions, leading to inefficient and unreliable transport connections.

Method used

A transport proxy node establishes an authenticated transport connection session with a source node, obtains authorization for accessing resources at a target node, and moves the transport endpoint to the target node, allowing the source node to reuse the existing transport session for secure communication.

Benefits of technology

This approach reduces the number of secure channels required, enhances mobility and resilience in transport connections, and optimizes signaling overhead, improving communication efficiency between nodes in 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050007_10072025_PF_FP_ABST
    Figure SE2024050007_10072025_PF_FP_ABST
Patent Text Reader

Abstract

A method performed a transport proxy node. The method is for handling a transport connection between a source node and a target node in a communications network. The transport proxy node establishes (201) an authenticated transport connection session between the source node and the transport proxy node. The authenticated transport connection session comprises a transport context. The transport proxy node is a transport endpoint in the authenticated transport connection session. The transport proxy node receives (202) from the source node via the established authenticated transport connection session, a request for a transport connection session between the source node and the target node. The request requests resource discovery and authorization for accessing resources at the target node. The transport proxy node obtains (203) the requested authorization for accessing resources at the target node, for the source node to access the target node. The transport proxy node moves the transport endpoint to the target node by: sending (204) a copy of the transport context to the target node, and sending (205) to the source node a response to the request. The response comprises the obtained authorization for accessing resources at the target node. The obtained authorization enables the source node to access resources at the target node possessing the copy of the transport context, and to request for a communication between the source node and the target node via the transport session originally established between the source node and the transport proxy node.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] TRANSPORT PROXY NODE, AND METHODS THEREIN IN A COMMUNICATIONS

[0002] NETWORK

[0003] TECHNICAL FIELD

[0004] Embodiments herein relate to a transport proxy node and methods therein. In some aspects, embodiments relate to handling a transport connection between a source node and a target node in a communications network.

[0005] BACKGROUND

[0006] In a typical wireless communication network, wireless devices, also known as wireless communication devices, mobile stations, stations (STA) and / or User Equipment (UE), communicate via a Wide Area Network or a Local Area Network such as a Wi-Fi network or a cellular network comprising a Radio Access Network (RAN) part and a Core Network (CN) part. The RAN covers a geographical area which is divided into service areas or cell areas, which may also be referred to as a beam or a beam group, with each service area or cell area being served by a radio network node such as a radio access node e.g., a Wi-Fi access point, a Base Station (BS) or a radio base station (RBS), which in some networks may also be denoted, for example, a Base Station (BS), a NodeB, eNodeB (eNB), or gNodeB (gNB) as denoted in Fifth Generation (5G) telecommunications. A service area or cell area is a geographical area where radio coverage is provided by the radio network node. The radio network node communicates over an air interface operating on a radio frequency with the wireless devices within the range of the radio network node.

[0007] 3rd Generation Partnership Project (3GPP) is the standardization body for specifying the standards for the cellular system evolution, e.g., including 3G, 4G, 5G and the future evolutions. Specifications for Evolved Universal Terrestrial Radio Access (E- UTRA) and Evolved Packet System (EPS) have been completed within the 3GPP. In 4G also called a Fourth Generation (4G) network, EPS is core network and E-UTRA is radio access network. In 5G, 5G Core (5GC) is core network, NR is radio access network. As a continued network evolution, the new release of 3GPP specifies a 5G network also referred to as 5G New Radio (NR) and 5GC.

[0008] Frequency bands for 5G NR are being separated into two different frequency ranges, Frequency Range 1 (FR1) and Frequency Range 2 (FR2). FR1 comprises sub-6 GHz frequency bands. Some of these bands are bands traditionally used by legacy standards but have been extended to cover potential new spectrum offerings from 410 MHz to 7125 MHz. FR2 comprises frequency bands from 24.25 GHz to 52.6 GHz. Bands in this millimeter wave range have shorter range but higher available bandwidth than bands in the FR1.

[0009] Multi-antenna techniques may significantly increase the data rates and reliability of a wireless communication system. For a wireless connection between a single user, such as UE, and a base station (BS), the performance is in particular improved if both the transmitter and the receiver are equipped with multiple antennas, which results in a Multiple-Input Multiple-Output (MIMO) communication channel. This may be referred to as Single-User (SU)-MIMO. In the scenario where MIMO techniques is used for the wireless connection between multiple users and the base station, MIMO enables the users to communicate with the base station simultaneously using the same time-frequency resources by spatially separating the users, which increases further the cell capacity. This may be referred to as Multi-User (MU)-MIMO. Note that MU-MIMO may benefit when each UE only has one antenna. The cell capacity can be increased linearly with respect to the number of antennas at the BS side. Due to that, more and more antennas are employed in BS. Such systems and / or related techniques are commonly referred to as massive MIMO.

[0010] Transport layer i.e. , Layer four (L4) in a communications network comprises protocols such as e.g., QUIC, Transmission Control Protocol (TCP), Stream Control Transmission Protocol (SCTP) to control communication between a client and a server. A client may e.g., be a User Equipment (UE) or a Virtual Network Function (VNF). A server may e.g., be a web server, a database or another VNF.

[0011] Among the transport layer protocols, the usage of QUIC is increasing while the usage of Transmission Control Protocol (TCP) is decreasing in the Internet communication. QUIC is also replacing TCP in the 6G network design. From the protocol implementation perspective, this means that the transport protocol stack is moved from kernel as in TCP to user-space as in QUIC. This also means that modifications to the QUIC protocol stack are easier to make compared to TCP.

[0012] QUIC is a protocol running on top of a User Datagram Protocol (UDP). It utilizes a Transport Layer Security (TLS) 1.3 based handshake for authentication and key agreement, and then protects the payload carried by the UDP. QUIC provides client-side mobility where the topological location of the end-point changes in the network. QUIC achieves this by binding the QUIC protocol context comprising e.g., protocol parameters and cryptographic keys to a connection identifier carried by the QIIIC packets instead of IP addresses and ports. A connection identifier identifies a communication channel between a client and a server. This allows the server to keep associating the received traffic to the same context even if the client changes IP address.

[0013] 5GC architecture comprises a number of Network Functions (NF) such as Session Management Function (SMF), Access and Mobility Management Function (AMF), Authentication Server Function (ALISF), Policy Control Function (PCF), Unified Data Management (UDM), Network Repository Function (NRF), Application Function (AF), Network Exposure Function (NEF), just to mention some. 5G introduced the Service Based Architecture (SBA) defining how the NFs in the 5GC interact with each other. A source NF wanting to interact with a target NF first needs to get an authorization token for the intended interaction from the NRF. The NRF also helps to locate suitable NF instances such as e.g., SMF, AMF and UDM to be used. The source NF first mutually authenticates with the NRF using certificate-based TLS after which it indicates its request to access e.g., an NF type, a resource and / or a service. The NRF checks if the source NF has the authority to access the target NF. If authorized, the NRF issues an authorization token e.g., OAuth2.0 token to that effect and provides it to the source NF. The source NF then proceeds to connect to the indicated target NF learnt from NRF response. The source NF first does mutual authentication with certificate-based TLS and then presents the received authorization token e.g., OAuth2.0 token and requests service.

[0014] There is also an option for indirect communication in SBA, where a Service Communication Proxy (SCP) sits between the source and target NFs. An SCP may be used for load balancing between target NFs, moving connections from a failed target NF to another target NFs, monitoring traffic and / or interconnecting administrative domains. An SCP may be implemented as a virtual function in SBA. It can optionally even sit between the source NF and the NRF i.e. , the SCP does the discovery request of resources and requests the NRF for the authorization token on behalf of the source NF. When using SCP, the source NF does certificate and TLS based mutual authentication towards the SCP instead of towards the target NF and optionally NRF. The SCP can then modify the message before it completes the communication towards NRF and / or target NF. This means that there is a hop-by-hop chain of TLS connections between source NF and target NF, and possibly between source NF and NRF, with SCP sitting in-between.

[0015] When looking at the user plane communication, it has some similarities to the above. The user plane traffic is protected in a hop-by-hop manner, between UE and UPF, with the gNB taking a similar role from a security point of view as SCP as described above. There is first a set of security established between UE and gNB, after which gNB has a separate secure connection to the UPF, through which it forwards the traffic received over the UE-gNB secure connection. This type of connection may be referred to as hop-by-hop security.

[0016] SUMMARY

[0017] As part of developing embodiments herein, the inventors identified some problems that first will be described.

[0018] While QUIC does not have server-side mobility, it could still be considered to moving the server-side QUIC protocol state from one physical machine to another. The existing solutions for QUIC server-side migration to support protocol context transfer between containers however do not work if an unexpected system failure happens before or during the context transfer. This is also a problem when transferring the protocol context between network functions running in different administrative domains.

[0019] There are some connections in the 5G system e.g., SBA communication, security for user plane traffic between UE and UPF where communication can be optimized. In these cases, there are multiple security transport protocol contexts established to realize the connections. A reduction in the signalling overhead related to such connections is necessary. For example, in the case of connection between a source NF and a target NF via the NRF as described above, one security transport protocol context is needed for the connection between the source NF and the NRF, and another security context is needed when contacting the target NF that the NRF directs the source NF to connect to. The existing solutions do not allow moving the security transport protocol context from NRF to NF.

[0020] An object of embodiments herein is to improve the performance of communications network using transport connections between nodes.

[0021] According to an aspect of embodiments herein, the object is achieved by a method performed by a transport proxy node. The method is for handling a transport connection between a source node and a target node in a communications network. The transport proxy node establishes an authenticated transport connection session between the source node and the transport proxy node. The authenticated transport connection session comprises a transport context. The transport proxy node is a transport endpoint in the authenticated transport connection session. The transport proxy node receives from the source node via the established authenticated transport connection session, a request for a transport connection session between the source node and the target node. The request requests resource discovery and authorization for accessing resources at the target node. The transport proxy node obtains the requested authorization for accessing resources at the target node, for the source node to access the target node. The transport proxy node moves the transport endpoint to the target node by: sending a copy of the transport context to the target node, and sending to the source node a response to the request. The response comprises the obtained authorization for accessing resources at the target node. The obtained authorization enables the source node to access resources at the target node possessing the copy of the transport context, and to request for a communication between the source node and the target node via the transport session originally established between the source node and the transport proxy node.

[0022] According to another aspect of embodiments herein, the object is achieved by a transport proxy node. The transport proxy node is configured to handle a transport connection between a source node and a target node in a communications network. The transport proxy node is further being configured to establish an authenticated transport connection session between the source node and the transport proxy node, which authenticated transport connection session comprises a transport context, wherein the transport proxy node is adapted to be a transport endpoint in the authenticated transport connection session. The transport proxy node is configured to receive from the source node via the established authenticated transport connection session, a request for a transport connection session between the source node and the target node, which request requests resource discovery and authorization for accessing resources at the target node. Furthermore, the transport proxy node is configured to obtain the requested authorization for accessing resources at the target node, for the source node to access the target node. The transport proxy node further configured to move the transport endpoint to the target node by:

[0023] - Sending a copy of the transport context to the target node, and

[0024] - Sending to the source node, a response to the request, which comprises the obtained authorization for accessing resources at the target node. The obtained authorization enables the source node to access resources at the target node possessing the copy of the transport context, and to request for a communication between the source node and the target node, via the transport session originally established between the source node and the transport proxy node.

[0025] Thanks to that the transport proxy node moves the transport endpoint to the target node, it is possible for the source node to use the same transport session, originally established between the source node and the transport proxy node, to access resources at the target node. This results in an improved transport connection between the source node and the target node in the communications network as this eliminates the need for multiple secure channels to realize the connection between the source node and the target node.

[0026] Embodiments herein may provide one or more of the following advantages:

[0027] They optimize the number of secure channels that need to be established during communication between a source node and a target node.

[0028] They replace a hop-by-hop secure channel e.g., two separate TLS-based security associations with an end-to-end secure channel e.g., a single QIIIC connection with security from the source to the destination.

[0029] BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Examples of embodiments herein are described in more detail with reference to attached drawings in which:

[0031] Figure 1 is a schematic block diagram illustrating embodiments of a communications network.

[0032] Figure 2 is a flowchart depicting an embodiment of a method in a transport proxy node. Figure 3 is a combined signaling scheme and flowchart according to an example embodiment of a method herein.

[0033] Figure 4 is a combined signaling scheme and flowchart according to an example embodiment of a method herein.

[0034] Figure 5 is a combined signaling scheme and flowchart according to an example embodiment of a method herein.

[0035] Figure 6 is a combined signaling scheme and flowchart according to an example embodiment of a method herein.

[0036] Figure 7 is a schematic block diagram illustrating embodiments of a transport proxy node.

[0037] Figure 8 schematically illustrates embodiments of a communication system. Figure 9 is a generalized block diagram of embodiments of a UE.

[0038] Figure 10 is a generalized block diagram of embodiments of a network node.

[0039] Figure 11 is a generalized block diagram of embodiments of a host.

[0040] Figure 12 is a generalized block diagram of embodiments of a virtualization environment.

[0041] Figure 13 is a generalized block diagram of embodiments of a communication diagram of a host.

[0042] DETAILED DESCRIPTION

[0043] Embodiments herein provide a good server-side mobility and / or protocol state transfer mechanism which is useful in the 5G communications network.

[0044] Examples of embodiments herein provide a transport connection design that allows a source node to contact a transport proxy node in a secure fashion, and if the transport proxy node directs the source node to contact another node e.g., target node, then the transport endpoint may be changed to that target node. A source node may be e.g., a client in a QIIIC connection such as an NF, a UE, a base station. A transport proxy node may be e.g., an NRF, a SCP, a base station. A target node may e.g., be an NF, a UPF. From the perspective of the source node, it may be communicating with just the transport proxy node, and only one security transport protocol context needs to be established.

[0045] Examples of embodiments herein provide a resilient, secure, and scalable design for specific 3GPP / SBA use cases. A source node e.g., a client in a QUIC connection may communicate with a target node e.g., web / SBA service in a QUIC connection that may act conceptually both as a proxy and a service. In some example embodiments herein, the transport proxy node implements e.g., a server role towards the source node e.g., the client, while still having e.g., the web / SBA service as the transport endpoint. In example embodiments herein, the transport proxy node allows the transport end-point to change during the lifetime of the transport connection session.

[0046] According to example embodiments herein, the source node e.g., source NF first establishes a transport connection with the transport proxy node e.g., NRF, but instead of later establishing a separate secure transport connection session towards the target node e.g., target NF, the endpoint of the transport connection session is moved from transport proxy node to the target node and is re-used there. In some example embodiments, the transport proxy node first acts as an NRF, but at the same time may take on the role of a transport proxy for the target node. In some example embodiments herein, the transport communication between the target node and the source node may either go directly between the two or via the transport proxy node, which may also be acting as e.g., an SCP in some embodiments. In some example embodiments, there may be a load balancer serving the source node and forwarding traffic of the source node to the transport proxy node and the target node respectively thereby hiding the IP address difference between the transport proxy node and the target node.

[0047] Example embodiments herein may be useful for user plane security. According to some embodiments herein, the source node which e.g., may be a UE, first establishes a secure transport communication with a transport proxy node which e.g., may be a base station. The transport proxy node may then move the transport endpoint to a target node e.g., which may be a target NF such as e.g., a UPF. In these embodiments, since the transport proxy node e.g., the base station is on the transport path between the source node e.g., the UE and the target node e.g., the UPF, the transport proxy node may hide the change of IP address of the transport endpoint from the source node. The resulting transport channel replaces the hop-by-hop security channel between the source node e.g., UE, via the transport proxy node e.g., base station, to the target node e.g., UPF.

[0048] Figure 1 is a schematic overview depicting a communications network 100 wherein embodiments herein may be implemented. The wireless communications network 100 comprises one or more RANs, one or more CNs such as CN 106.

[0049] The communications network 100 may use 5G NR but may further use a number of other different technologies, such as, 6G, Wi-Fi, Long Term Evolution (LTE), LTE- Advanced, Wideband Code Division Multiple Access (WCDMA), Global System for Mobile communications / enhanced Data rate for GSM Evolution (GSM / EDGE), Worldwide Interoperability for Microwave Access (WiMax), or Ultra Mobile Broadband (UMB), just to mention a few possible implementations.

[0050] RAN nodes, such as a RAN node 110, operate in the RAN of the communications network 100. The RAN node 110 may be a transmission and reception point e.g. a radio access network node such as a base station, e.g. a radio base station such as a NodeB, an evolved Node B (eNB, eNode B), an NR Node B (gNB), a base transceiver station, a radio remote unit, an Access Point Base Station, a base station router, a transmission arrangement of a radio base station, a stand-alone access point, a Wireless Local Area Network (WLAN) access point or an Access Point Station (AP STA), an access controller, or any other network unit capable of communicating with UEs, such as a UE 121 that is used by a subscriber, within a cell, served by the RAN node 110. The RAN node 110 may be referred to as a serving radio network node and may communicate with the UE 121 with Downlink (DL) transmissions to the UE 121 and Uplink (UL) transmissions from the UE 121.

[0051] One or more UEs operate in the wireless communication network 100, such as e.g. the UE 121The UE 121 may e.g., be a wireless device, an NR device, a mobile station, a wireless terminal, an NB-loT device, an MTC device, an eMTC device, a CAT-M device, a WiFi device, an LTE device and a non-access point (non-AP) STA, a STA. It should be understood by the skilled in the art that “UE” is a non-limiting term which means any terminal, client, mobile client, IMS client, wireless communication terminal, user equipment, Device to Device (D2D) terminal, or node e.g., smart phone, laptop, mobile phone, sensor, relay, mobile tablets or even a car or any small base station communicating within a cell.

[0052] Network nodes, such as e.g., transport proxy node 130 may operate in the communications network 100, such as in the CN or the RAN. According to some embodiments herein, the transport proxy node 130 may e.g., be represented by an NRF or SCP.

[0053] CN nodes, such as e.g., CN node 131 operate in the CN 106 of the communications network 100. According to some embodiments herein, the source node may e.g., be represented by any NF in SBA.

[0054] CN nodes, such as e.g., target node 132 operate in the CN 106 of the communications network 100. The target node may e.g., be represented by any NF in SBA.

[0055] Methods herein is performed by a transport proxy node. The transport proxy node may e.g., be represented by any of the RAN node 110 or the CN node 130 and is therefore referred to as the transport proxy node 110, 130.

[0056] A source node is acting in methods herein, the source node may e.g., be represented by any of the UE 121 or the CN node 131 and is therefore referred to as the source node 121, 131.

[0057] A target node is acting in methods herein, the target node may e.g., be represented by the CN node 132 and is therefore referred to as the target node 132.

[0058] According to an example scenario, the RAN node 110 may act as a transport proxy node 130 connecting the source node e.g., the UE 121 with the target node e.g., the CN node 132. According to an example scenario, the UE 121 may represent the source node communicating with the target node e.g., CN node 132 via the transport proxy node e.g., RAN node 110 and / or CN node 130.

[0059] Methods according to embodiments herein are performed by the transport proxy node 110,130. This node may be Distributed Nodes (DN)s and functionality, e.g. comprised in a cloud 170 as shown in Figure 1.

[0060] According to some embodiments herein, the source node 121,131, e.g., source NF or UE, first establishes a secure transport channel to a transport proxy node 110,130 e.g., RAN node HO or NRF, and later moves the transport endpoint to another node i.e., a target node 132 e.g., target NF, without affecting the source node 121,131. This may reduce the number of secure channels that need to be established for communication between a source node 121 ,132 and a target node 132.

[0061] Examples of embodiments herein are also useful in non-3GPP scenarios where a source node 121,131 needs to interact with multiple other nodes e.g. web services or data-base instances from the same domain, where each node would establish a separate secure channel with the source node 121,131.

[0062] A number of embodiments will now be described, some of which may be seen as alternatives, while some may be used in combination.

[0063] A method according to embodiments will first be described as seen from the view of the transport proxy node 110,130 together with Figure 2.

[0064] Figure 2 shows exemplary embodiments of a method performed by the transport proxy node 110,130. The method is for handling a transport connection between the source node 121,131 and the target node 132 in the communications network 100. In some embodiments, the transport proxy node 110,130 is represented by any one or more out of: a Network Repository Function, NRF, a Service Communication Proxy, SCP, and a base station.

[0065] According to an example scenario, the source node 121 ,131 is required to access resources such as e.g., a service provided by an NF in SBA. The source node 121 ,131 may be unaware of the target node 132 which possess the required resources and the source node 121,131 may not possess an authorization to access the required resources at the target node 132.

[0066] The method comprises the following actions, which actions may be taken in any suitable order. Optional actions are referred to as dashed boxes in Figure 2. Action 201. The transport proxy node 110,130 establishes an authenticated transport connection session between the source node 121,131 and the transport proxy node 110,130. The authentication may be performed by e.g., QIIIC or TLS. The authenticated transport connection session comprises a transport context. The transport context may comprise information related to the transport connection between the source node 121,131 and the transport proxy node 110,130. The transport proxy node 110,130 is a transport endpoint in the authenticated transport connection session.

[0067] In some embodiments, the establishing of the transport connection session between the source node 121,131 and the transport proxy node 110, 130 is performed via a load balancer. In these embodiments, the load balancer may distribute the traffic from the source node 121 ,131 to e.g., the transport proxy node 110,130 and the target node 132. All signaling between the source node 121 ,131 and the transport proxy node 110,130 or the target node 132 may be via the load balancer.

[0068] Action 202. The transport proxy node 110,130 receives a request from the source node 121,131 via the established authenticated transport connection session. The request is for a transport connection session between the source node 121 ,131 and the target node 132. The request requests resource discovery and authorization for accessing resources at the target node 132. In some embodiments, this request by the source node 121 ,131 to access the target node 132 may implicitly imply a request for resource discovery and authorization e.g., when a UE 121 requests a base station 110 for connection to a target NF 132 such as e.g., UPF. In some other embodiments, the source node 121,131 explicitly requests for resource discovery and authorization using e.g., an authorization token.

[0069] According to the example scenario as described above, this request may be to access resources such as e.g., a service provided by an NF in SBA. The source node 121 ,131 may request the transport proxy node 110,130 to provide an identification of the target node 132 that can provide the resources required by the source node 121,131. The source node 121 ,131 may further request the transport proxy node 110,130 to provide an authorization in the form of e.g., a token to access the identified target node 132.

[0070] Action 203. The transport proxy node 110,130 obtains the requested authorization for accessing resources at the target node 132, for the source node 121 ,131 to access the target node 132. The authorization may be in the form of e.g., a token. The transport proxy node 110,130 may obtain the requested authorization after verifying that the source node 121,131 has the possibility to obtain authorization to access the target node 132. In some embodiments, the target proxy node 110,130 allocates the target node 132 to be used by the source node 121 ,131 before obtaining the authorization for the allocated target node 132.

[0071] Action 204. The transport proxy node 110,130 moves the transport endpoint to the target node 132 by sending a copy of the transport context to the target node 132. The transport context may be e.g., related to the transport connection session established between the source node 121 ,131 and the transport proxy node 110,130. The sending of the transport context to the target node 132 may signify that the target node 132 must create a new transport connection based on the transport context. In some embodiments, the copy of the transport context may be sent directly to the target node 132. In some other embodiments, the transport context may be continuously updated into a database from which the target node 132 may fetch the transport context.

[0072] Action 205. The transport proxy node 110,130 moves the transport endpoint to the target node 132 by sending to the source node 121,131, a response to the request. The response comprises the obtained authorization for accessing resources at the target node 132. In some embodiments, the response sent to the source node 121 ,131, further comprises one or more out of: an identification of the target node 132 and an indication indicating that the transport connection session between the source node 121,131 and the target node 132 is via said established 201 transport session. The obtained authorization enables the source node 121,131 to access resources at the target node 132 possessing the copy of the transport context. The obtained authorization enables the source node 121 ,131 to request for a communication between the source node 121,131 and the target node 132, via the transport session originally established between the source node 121 ,131 and the transport proxy node 110,130.

[0073] Action 206. The transport proxy node 110,130 may delete the transport context related to the transport connection session. This may be since the transport proxy node 110,130 has sent the transport context to the target node 132.

[0074] Action 207. The transport proxy node 110,130 may store the transport context to access the communication between the source node 121,131 and the target node 132. In these embodiments, the transport proxy node 110,130 may be represented by e.g., a SCP that may modify the communication sent by the source node 121 ,131 to the target node 132.

[0075] Action 208. The transport proxy node 110,130 may forward one or more packets in the communication from the source node 121,131 to the target node 132 using said established 201 transport connection session. In some embodiments, the packets from the source node 121,131 are sent to the target node 132 via the transport proxy node 110,130. In some other embodiments, the packets from the source node 121,131 are sent directly to the target node 132. In some embodiments where the transport connection session between the source node 121,131 and the target node 132 is via the load balancer, the packets from the source node 121 ,131 may be forwarded by the load balancer to the target node 132.

[0076] In this way by using the methods above, the transport proxy node 110,130 has enabled the source node 121 ,131 to communicate with the target node 132 by moving the transport endpoint of the same established transport connection, between the source node 121,131 and the transport proxy node 110,130, from the transport proxy node 110,130 to the target node 132. This way the number of transport connections required to be established for communication between the source node 121,131 and the target node 132 may be reduced thereby improving the transport connection.

[0077] Embodiments herein such as the embodiments mentioned above will now be further described and exemplified. The text below is applicable to and may be combined with any suitable embodiment described above.

[0078] As mentioned above, the transport proxy node 110, 130 may be represented by e.g., a RAN node 110 such as e.g., a base station and / or a CN node 130 such as e.g., an NRF and / or an SCP. As further mentioned above, the source node 121 ,131 may be represented by e.g., a UE 121 and / or a CN node 131 such as e.g., an NF. Also as mentioned above, the target node 132 may be represented by e.g., a CN node 132 such as e.g., an NF.

[0079] In some embodiments, the transport connection is between the source NF 131 and the target NF 132 via the NRF or SCP acting as the transport proxy node 130. In some other embodiments, the transport connection is between the UE 121 and the target NF 132 via the RAN node 110 acting as the transport proxy node 110.

[0080] The transport connection between the source node 121,131 and the target node 132 may be established using a transport protocol e.g., QUIC, TLS, TCP, security transport proxy node such as e.g., QUIC transport proxy node.

[0081] According to example embodiments herein, the source node 121 ,131 communicates directly or indirectly with one or more target nodes 132 using a secure channel. The target nodes 132 may be in parallel to each other, i.e. the source node 121 ,131 may connect to them individually e.g., source NF connects to NRF and to target NF, or one behind each other e.g. UE connects to gNB, which forwards UE traffic to UPF. In some first embodiments, the source node 121,131 may establish separate secure channels between itself and the target nodes 132, or the source nodes 121,131 may interconnect to each other with their own secure channels in the one target node 132 behind the other scenario.

[0082] According to example embodiments herein, the transport proxy node 110,130 e.g., server-side entity in QIIIC such as e.g., NRF first creates a transport connection session and a corresponding transport context when the source node 121,131 connects to it. Then instead of requiring the source node 121,131 to create a new transport connection session, the transport proxy node 110,130 moves the transport context to the target node 132 to which the source node 121,131 wants to connect to next. In these embodiments, the transport proxy node 110,130 first creating the transport context and then moving it to the target node 132, may selectively either delete the context after moving it out, or keep it depending on use case and policy. Examples of embodiments herein are best suited for moving the transport context between trusted parties i.e. , within one domain since there might not be a guarantee that the deletion of the transport context is done by the transport proxy node 110,130.

[0083] According to example embodiments herein, moving the transport context from the transport proxy node 110,130 to the target node 132 is done in different ways, e.g. via a database, or by direct communication with the new holder of the transport context e.g., the target node 132. In these embodiments, the transport context needs to be protected, which could e.g., be done by encrypting it with a public key of the receiver e.g., the target node 132 of the transport context. According to example embodiments herein, the transport context is practice cloned to a new entity / receiver, and then optionally depending on use case, the transport context in the originating node e.g., the transport proxy node 110,130 is deleted and the IP mobility signaling is used for signaling to the source node 121,131 the new IP address where the transport context is located. This new IP address may correspond to e.g., the target node 132.

[0084] Examples of embodiments herein focus on 3GPP / SBA use cases e.g., communication between two NFs and NRF and communication among UE, base station & UPF. Examples of embodiments herein are applicable in e.g. web traffic where a target service and / or domain has multiple services that the source node 121 ,131 wants to interact with. The use cases as described above may be parallelly connected e.g., communication between two NFs and NRF or serially connected e.g., communication among UE, base station and UPF are described in more detail according to embodiments herein. The source node 131 may be referred to as source NF or UE, the transport proxy node 130 may be referred to as NRF or base station and the target node 132 may be referred to as target NF or UPF in the below text. The transport connection in these cases may be referred to as QUIC connection and the corresponding transport context may be referred to as QUIC context.

[0085] Use Case 1 : NF-NF communication in SBA -parallel services of first embodiments.

[0086] In this use case, the source node 131 may be referred to as source NF, the transport proxy node 130 may be referred to as NRF and the target node 132 may be referred to as target NF. The transport connection in this case may be referred to as QUIC connection and the corresponding transport context may be referred to as QUIC context.

[0087] According to example embodiments herein, a source node 131 e.g., source NF first connects to the transport proxy node 130 e.g., NRF to get information about suitable target node 132 e.g., target NF to use as well as an authorization token to access the target node 132. Then, based on the obtained information, the source node 131 connects to the target node 132 and using the obtained token, the source node 131 requests service from the target node 132. In some embodiments, the source node 131 performs certificate-based TLS towards both the transport proxy node 130 and the target node 132. In these embodiments, while a move from TLS 1.2 to TLS 1.3 or QUIC i.e., TLS 1.3 handshake would significantly reduce the amount of connection setup signaling, due to TLS 1.3 being optimized in this regard, re-using the transport connection established towards the transport proxy node 130 and also towards the target node 132, according to embodiments herein, further halves what is left of the signaling done by the source node 131. Thus, the embodiments herein improve the transport connection between the source node 131 e.g., source NF and the target node 132 e.g., target NF thereby reducing the number of signaling and secure channel required for the communication. A communication between a source NF and a target NF may e.g., be between two network functions in the SBA architecture.

[0088] Security considerations:

[0089] In this use case, according to some embodiments herein, the transport proxy node 130 e.g., the NRF is a trusted party in the SBA architecture in that a requesting source node 131 e.g., source NF trusts the transport proxy node 130 to provide a pointer to the target node 132 e.g., target NF and a token for accessing the resources at the target node 132. In some embodiments, the target node 132 trusts the transport proxy node 130 to issue those tokens based on which the target node 132 provides service and / or resources to the source node 131. Thus, the transport proxy node 130 may be trusted by both the source node 131 and the target node 132. Examples of embodiments herein rely on the same trust and thereby allow the transport connection established to a trusted party e.g., the transport proxy node 130 to be reused towards another party e.g., the target node 132 to which the trusted party i.e. , the transport proxy node 130 points the originating node i.e., the source node 131.

[0090] According to example embodiments herein, the transport proxy node 130, once it has replied or even just before it replies to the discovery and authorization request of the source node 131 , clones the transport context to the target node 132. Depending on the use case, the transport proxy node 130 might later delete the local transport context. According to embodiments herein, the source node 131 continues to use the transport connection and sends its request to the target node 132 to access resources and / or services at the target node 131 via the same transport connection. This may be implemented in different ways and a few example use cases are described below:

[0091] 1.1. The transport proxy node 130 e.g., NRF may act as a QIIIC proxy for the target node 132 e.g., target NF taking the role of a web server, so that the source node e.g., source NF may send all requests via the transport proxy node 130 to the target node 132. In this use case, the transport proxy node 130 acts as transport endpoint during the transport proxy node 130 related operations e.g., resource discovery and token request, but later moves the transport context to the target node 132. The target node 132 then acts as a transport endpoint for the source node 131 to target node 132 communication e.g., NF-NF communication. The messages from the source node 131 are routed via the transport proxy node 130. The transport proxy node 130 may delete the transport context once it has moved it to the target node 132.

[0092] 1.2. The transport proxy node 130 e.g., NRF may also take on the role as SCP, and by that acts in a similar way as above. The difference to use case 1.1 above, is that now the transport proxy node 130 does not delete the transport context, and the transport proxy node 130 might modify the messages exchanged between the source node 131 and the target node 132 as an SCP would be able to do. 1.3. There may be a load balancer between the source node 131 and the transport proxy node 130 and / or the target node 132. The load balancer hides the transport endpoints i.e., the transport proxy node 130 and the target node 132 from the source node 131. In the case of a load balancer before the transport proxy node 130, the different transport proxy nodes 130 are seen as alternatives to each other as in a web service with multiple servers behind the load balancer, with the load balancer selecting where to forward each packet of the source node 131. Based on state, the load balancer first forwards traffic to the transport proxy node 130, where the transport connection session is established, and later based on the instruction from the transport proxy node 130 forwards the traffic of the transport connection towards the target node 132, which takes over the transport connection session from the transport proxy node 130.

[0093] 1.4. The transport connection e.g., QIIIC connection may implement server-side mobility and the server-side endpoint may be moved from the transport proxy node 130 e.g., NRF to the target node 132 e.g., target NF after the transport proxy node 130 has authorized the source node 131 e.g., the source NF to access the target node 132. Mobility signaling may inform the source node 131 about the new IP address that the source node 131 may use for the transport endpoint. This IP address may correspond to the target node 132 to which the endpoint of the transport connection has been moved.

[0094] The logic in the source node 131 may need to be changed from the current approach in which the source node 131 first connects to the transport proxy node 130 and then gets re-directed to the target node 132. According to embodiments herein, the source node 131 needs to understand that it uses just one transport connection to first indicate and / or request to the transport proxy node 130 about the resources it needs e.g., from the target node 132, and then uses the same transport connection to issue the request to the target node 132 to access resources at the target node 132. This may be achieved by e.g., by updating the implementation by enhancing the protocol statemachine in the source node 131. In QIIIC, this can be done as part of the application upgrade since the protocol is implemented on the application layer. In some embodiments, when the source node 131 has been authorized by the target node 132 to access resources at the target node 132, the source node 131 may continue to use the same transport connection to further communicate with the target node 132.

[0095] The above-mentioned use cases will be described in more detail below. Use Case 1.1: The transport proxy node 130 e.g., NRF acting as QUIC proxy

[0096] Figure 3 describes the use case in which the transport proxy node 130 e.g., NRF acts as QUIC proxy and forwards QUIC traffic between source node 131 e.g., source NF and target node 132 e.g., target NF. The source node 131 may be referred to as source NF, the transport proxy node 130 may be referred to as NRF and the target node 132 may be referred to as target NF in Figure 3. The transport connection in this case may be referred to as QUIC connection and the corresponding transport context may be referred to as QUIC context. The steps involved in the communication relating to this use case is as follows:

[0097] 301. In this step, the source node 131 connects to NRF and does resource discovery. This related to Actions 201, 202 and 203 as described above. The source node

[0098] 131 and the transport proxy node 130 may do transport based e.g., QUIC based mutual authentication after which the source node 131 may request the type of target node 132 it wishes to access. The transport proxy node 130 may then verify authorization of source node 131 to access target node 132 and may allocate the target node 132 for use by the source node 131. The transport proxy node 130 may create an authorization token for the source node 131 to access the target node 132.

[0099] 302. Before providing response with the authorization token to the source node 131 , the transport proxy node 130 clones the transport context to the selected target node

[0100] 132 as described in Action 204. The cloning may be performed by directly copying the context to the target node 132 or storing the context in a database from where the target node 132 may fetch it. The transport proxy node 130 indicates a packet number larger than the actual packet number to the target node 132, e.g. N larger than actual packet number. This way, the transport proxy node 130 may still send a few messages with the local copy of the context without exceeding the packet number told to the target node 132, which then may use the obtained packet number without causing packet number collisions.

[0101] 303. The transport proxy node 130 provides a response to the source node 131. This related to Action 205 as described above. The response carries the authorization token and optionally an indication that the target node 132 may be reached via the same transport connection session. According to example embodiments herein, the transport proxy node 130 provides an identification of the target node 132 possessing the resources requested by the source node 131. 304. The transport proxy node 130 deletes the transport context as described in Action 206. For a while before deletion, the transport context was duplicated at the target node 132 and the transport proxy node 130.

[0102] 305. The source node 131 starts to interact with the target node 132 by first providing the authorization token and then requesting service. The source node 131 sends communication via the same transport connection session it established with the transport proxy node 130. The traffic is addressed to and / or routed via the transport proxy node 130, which further routes it to the selected target node 132. Thus in this way, the target node 132 is hidden from the source node 131.

[0103] Use Case 2: The transport proxy node 130 e.q., NRF as SCP

[0104] Figure 4 describes the use case in which the transport proxy node 130 e.g., NRF acts as SCP and forwards QUIC traffic between source node 131 e.g., source NF and target node 132 e.g., target NF. The source node 131 may be referred to as source NF, the transport proxy node 130 may be referred to as NRF and the target node 132 may be referred to as target NF in Figure 4. The transport connection in this case may be referred to as QUIC connection and the corresponding transport context may be referred to as QUIC context. This use case is very similar to use case 1.1 as discussed above. The difference is in step 404 where in this case the transport proxy node 130 does not delete the transport context as described in step 304, but instead stores the transport context as described in Action 207 to use it in step 405 to modify messages from the source node 130 as shown in Figure 4.

[0105] Use Case 3: Using Load Balancer

[0106] Figure 5 describes the use case in which there is a load balancer between the source node 131 and the transport proxy node 130 and between the transport proxy node 130 and the target node 132. The load balancer is used to distribute the load among the different available transport proxy nodes 130 e.g., NRF and among different available target nodes 132 e.g., target NF. For example, if there are multiple transport proxy nodes 130 e.g., NRF instances, the load balancer may choose to forward the request from the source node 131 towards the transport proxy node 130 with least workload. The source node 131 may be referred to as source NF, the transport proxy node 130 may be referred to as NRF and the target node 132 may be referred to as target NF in Figure 5. The transport connection in this case may be referred to as QUIC connection and the corresponding transport context may be referred to as QIIIC context. The steps involved in the communication relating to this use case is as follows:

[0107] 501. In this step, the source node 131 connects to NRF and does resource discovery. This related to Actions 201 , 202 and 203 as described above. The connection passes through the load balancer which forwards the messages from the source node

[0108] 131 to a selected transport proxy node 130 with the least workload. The source node 131 and the transport proxy node 130 may do transport based e.g., QIIIC based mutual authentication through the load balancer after which the source node 131 may request the type of target node 132 it wishes to access. The transport proxy node 130 may then verify authorization of source node 131 to access target node 132 and may allocate the target node 132 for use by the source node 131. The transport proxy node 130 may create an authorization token for the source node 131 to access the target node 132.

[0109] 502. Before providing response with the authorization token to the source node 131 , the transport proxy node 130 clones the transport context to the selected target node

[0110] 132 as described in Action 204. The cloning may be performed by directly copying the context to the target node 132 or storing the context in a database from where the target node 132 may fetch it. The transport proxy node 130 indicates a packet number larger than the actual packet number to the target node 132, e.g. N larger than actual packet number. This way, the transport proxy node 130 may still send a few messages with the local copy of the context without exceeding the packet number told to the target node 132, which then may use the obtained packet number without causing packet number collisions.

[0111] 503. The transport proxy node 130 provides a response to the source node 131. This related to Action 205 as described above. The response carries the authorization token and optionally an indication that the target node 132 may be reached via the same transport connection session. According to example embodiments herein, the transport proxy node 130 provides an identification of the target node 132 possessing the resources requested by the source node 131.

[0112] 504. The transport proxy node 130 registers to the load balancer that the signaling and / or messages communicated over the current transport connection established between the source node 131 and the transport proxy node 130 should from then on be forwarded to the target node 132 instead of to the transport proxy node 130. In case the source node 131 is too fast and sends SBA signaling towards the target node 132 before the transport proxy node 130 has updated the load balancer, the SBA signaling will reach the transport proxy node 130 instead of the target node 132. The transport proxy node 130 may then forward messages to the target node 132.

[0113] 505. The transport proxy node 130 deletes the transport context as described in Action 206. For a while before deletion, the transport context was duplicated at the target node 132 and the transport proxy node 130.

[0114] 506. The source node 131 starts to interact with the target node 132 by first providing the authorization token and then requesting service. The source node 131 sends communication via the same transport connection session it established with the transport proxy node 130. The traffic is addressed to and / or routed via the load balancer, which further routes it to the selected target node 132 as instructed by the transport proxy node 130 in step 504. Thus in this way, the target node 132 is hidden from the source node 131.

[0115] Use Case 4: Server-side migration.

[0116] Figure 6 describes the last example use case in which the transport context is being moved from the transport proxy node 130 to the target node 132 in a form of server-side mobility operation in QUIC. However, it is only the transport context that is mobile, while the server node changes from the transport proxy node 130 to the target node 132. This means that there needs to be server-side mobility signaling done to inform the source node 131 that the server-side in this case, the transport context has moved. The source node 131 may be referred to as source NF, the transport proxy node 130 may be referred to as NRF and the target node 132 may be referred to as target NF in Figure 3. The transport connection in this case may be referred to as QUIC connection and the corresponding transport context may be referred to as QUIC context. The steps involved in the communication relating to this use case is as follows:

[0117] 601. In this step, the source node 131 connects to NRF and does resource discovery. This related to Actions 201 , 202 and 203 as described above. The source node 131 and the transport proxy node 130 may do transport based e.g., QUIC based mutual authentication through the load balancer after which the source node 131 may request the type of target node 132 it wishes to access. The transport proxy node 130 may then verify authorization of source node 131 to access target node 132 and may allocate the target node 132 for use by the source node 131. The transport proxy node 130 may create an authorization token for the source node 131 to access the target node 132. 602. Before providing response with the authorization token to the source node 131 , the transport proxy node 130 clones the transport context to the selected target node 132 as described in Action 204. The cloning may be performed by directly copying the context to the target node 132 or storing the context in a database from where the target node 132 may fetch it. The transport proxy node 130 indicates a packet number larger than the actual packet number to the target node 132, e.g. N larger than actual packet number. This way, the transport proxy node 130 may still send a few messages with the local copy of the context without exceeding the packet number told to the target node 132, which then may use the obtained packet number without causing packet number collisions.

[0118] 603. The transport proxy node 130 provides a response to the source node 131. This related to Action 205 as described above. The response carries the authorization token and optionally an indication that the target node 132 may be reached via the same transport connection session. According to example embodiments herein, the transport proxy node 130 provides an identification of the target node 132 possessing the resources requested by the source node 131.

[0119] 604. The transport proxy node 130 initiates QUIC server-side mobility, indicating to the source node 131 that the QUIC server has moved to the target node 132. The target node 132 might be part of the mobility signaling e.g. by proving that the server can indeed be reached at the new location. This may be performed by e.g., so-called address reachability test. The response sent to the source node 131 in step 603, could optionally also indicate to the source node 131 that IP mobility is about to take place and the source node 131 should wait for that i.e. step 604 before it proceeds with further SBA communication.

[0120] 605. The transport proxy node 130 deletes the transport context as described in Action 206. For a while before deletion, the transport context was duplicated at the target node 132 and the transport proxy node 130.

[0121] 606. The source node 131 starts to interact with the target node 132 by first providing the authorization token and then requesting service. The source node 131 sends communication directly to the target node 132, but still utilizing the same transport connection and the corresponding transport context as used for communication with the transport proxy node 130.

[0122] Use case 2: User plane security - serially connected services The difference in this use case compared to the use case 1 is that the transport endpoints are serially connected, i.e. the source node 121 only sees the closest one in the chain, which in turn forwards the traffic of the source node 121 up the chain to other endpoints taking part in the communication. An example would be a web server with a TLS proxy, where the client sends requests, addressed to the TLS proxy, to access the web server, which then mediates the traffic between the server and the client. According to the above example, the source node 121 may be referred to as the client, the transport proxy node 110 may be referred to as the TLS proxy and the target node 132 may be referred to as the web server.

[0123] The 3GPP use case considered here in example embodiments herein is the user plane security, which is split into UE-base station and base station-UPF secure channels. Further examples according to example embodiments herein may be e.g. control plane signalling of the UE sent to the AMF, which then forwards it to suitable NF in the 5GC. Example embodiments herein are used in some cases to have end-to-end security for the communication between UE and serving NF.

[0124] In this use case considering the user plane security, the source node 121 may be referred to as the UE 121 , the target proxy node 110 may be referred to as the RAN node 110 i.e., the base station, and the target node 132 may be referred to as the target NF 132 i.e., the UPF. According to example embodiments herein, the source node 121 e.g., the UE first establishes a transport connection session towards the transport proxy node 110 e.g., the base station as described in Action 201. This procedure replaces the currently standardized way of establishing user plane security between the source node 121 e.g., UE and the transport proxy node 110 e.g., the base station. This means that e.g., QUIC connection is used to establish the security association between a UE 121 and a RAN node 110. Then the transport proxy node 110 moves the transport endpoint by moving the transport context to the selected target node 132 e.g., the selected UPF, resulting in the transport connection session being between the source node 121 e.g., the UE and the target node 132 e.g., the UPF. The source node 121 still sends messages to the transport proxy node 110, which in turn forwards them as described in Action 208 in the transport connection session to the target node 132.

[0125] In some embodiments, the transport proxy node 110 removes the transport context from its own memory once it has moved the context to the the target node 132 e.g., UPF as mentioned in Action 206, except certain parameters needed for mapping the transport connection messages to a specific source node 121 and / or a specific transport context. As stated earlier, moving the transport context may be done in a secure way e.g. by encrypting it with the receiver's e.g., the target node’s 132 public key. The steps involved in communication relating to this use case may be similar to the steps in e.g., use case 1.1 and use case 1.2 presented earlier, where the transport proxy node 130 e.g., NRF remained on the path between the source node 131 and the target node 132. The difference in this use case is that the user plane data is always sent via the base station to the UPF, instead of for NF-NF communication the NFs today communicating directly with each other after NRF has helped with pairing the NFs to each other via authorization and NF allocation.

[0126] To perform the method actions above, the transport proxy node 110,130 is configured to handle a transport connection between a source node 121,131 and a target node 132 in a communications network 100.

[0127] The transport proxy node 110,130 may comprise an arrangement depicted in Figure 7. The transport proxy node 110,130 may comprise an input and output interface 700 configured to communicate in the communications network 100. The input and output interface 700 may comprise a wireless receiver not shown, and a wireless transmitter not shown.

[0128] The transport proxy node 110,130 is further being configured to establish an authenticated transport connection session between the source node 121 ,131 and the transport proxy node 110,130, which authenticated transport connection session comprises a transport context, wherein the transport proxy node 110,130 is adapted to be a transport endpoint in the transport connection session.

[0129] The transport proxy node 110,130 is further being configured to receive from the source node 121 ,131 via the established authenticated transport connection session, a request for a transport connection session between the source node 121,131 and the target node 132, which request requests resource discovery and authorization for accessing resources at the target node 132.

[0130] The transport proxy node 110,130 is further being configured to obtain the requested authorization for accessing resources at the target node 132, for the source node 121,131 to access the target node 132.

[0131] The transport proxy node 110,130 further being configured to move the transport endpoint to the target node 132 by:

[0132] - sending a copy of the transport context to the target node 132, and - sending to the source node 121,131 , a response to the request, which response comprises the obtained authorization for accessing resources at the target node 132, which obtained authorization enables the source node 121,131 to access resources at the target node 132 possessing the copy of the transport context, and request for a communication between the source node 121 ,131 and the target node 132, via the transport session originally established between the source node 121 ,131 and the transport proxy node 110,130.

[0133] In some embodiments, the response sent to the source node 121,131, is further adapted to comprise one or more out of: an identification of the target node 132 and an indication indicating that that the transport connection session between the source node 121 ,131 and the target node 132 is via said established 201 transport session.

[0134] In some embodiments, the transport proxy node 110,130 is further being configured to forward one or more packets in the communication from the source node 121 ,131 to the target node 132 using said established 201 transport connection session.

[0135] In some embodiments, the transport proxy node 110,130 is further being configured to any one out of: delete the transport context related to the transport connection session, or store the transport context to access the communication between the source node 121 ,131 and the target node 132.

[0136] In some embodiments, the transport proxy node 110,130 is further being configured to establish the transport connection session between the source node 121,131 and the transport proxy node 110,130 via a load balancer.

[0137] In some embodiments, the transport proxy node 110,130 is adapted to be represented by any one or more out of: a Network Repository Function, NRF, a Service Communication Proxy, SCP, and a base station.

[0138] Embodiments herein may be implemented through a respective processor or one or more processors, such as the respective processor 710 of a processing circuitry in the transport proxy node 110,130 depicted in Figure 7 together with respective computer program code for performing the functions and actions of the embodiments herein. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the respective transport proxy node 110,130. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the respective transport proxy node 110,130.

[0139] The transport proxy node 110,130 may further comprise a respective memory 720 comprising one or more memory units. The respective memory 720 comprises instructions executable by the processor in the respective transport proxy node 110,130. The respective memory 720 is arranged to be used to store e.g., media functions, indications, tags, information, data, configurations, communication data, and applications to perform the methods herein when being executed in the respective transport proxy node 110,130.

[0140] In some embodiments, a respective computer program 730 comprises instructions, which when executed by the respective at least one processor 710, cause the at least one processor of respective transport proxy node 110,130 to perform the actions above.

[0141] In some embodiments, a respective carrier 740 comprises the respective computer program 730, wherein the respective carrier 740 is one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or a computer-readable storage medium.

[0142] Those skilled in the art will appreciate that units in the respective transport proxy node 110,130 described above may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g. stored in the respective transport proxy node 110,130, that when executed by the respective one or more processors such as the processors described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application- Specific Integrated Circuitry ASIC, or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).

[0143] ADDITIONAL EXPLANATION

[0144] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0145] Figure 8 shows an example of a communication system QQ100 in accordance with some embodiments. In the example, the communication system QQ100 includes a telecommunication network QQ102 that includes an access network QQ104, such as a radio access network (RAN), and a core network QQ106, which includes one or more core network nodes QQ108. The access network QQ104 includes one or more access network nodes, such as network nodes QQ110a and QQ110b (one or more of which may be generally referred to as network nodes QQ110), or any other similar 3rd Generation Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network QQ102 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network QQ102 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network QQ102, including one or more network nodes QQ110 and / or core network nodes QQ108.

[0146] Examples of an ORAN network node include an open radio unit (0-Rll), an open distributed unit (0-Dll), an open central unit (O-CU), including an O-CU control plane (O- CLI-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an A1 , F1 , W1, E1 , E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the O-RAN Alliance or comparable technologies. The network nodes QQ110 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs 121, QQ112a, QQ112b, QQ112c, and QQ112d (one or more of which may be generally referred to as UEs QQ112) to the core network QQ106 over one or more wireless connections. Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system QQ100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system QQ100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0147] The UEs QQ112 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes QQ110 and other communication devices. Similarly, the network nodes QQ110 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs QQ112 and / or with other network nodes or equipment in the telecommunication network QQ102 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network QQ102.

[0148] In the depicted example, the core network QQ106 connects the network nodes QQ110 to one or more hosts, such as host QQ116. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network QQ106 includes one more core network nodes (e.g., core network node QQ108) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node QQ108. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier Deconcealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0149] The host QQ116 may be under the ownership or control of a service provider other than an operator or provider of the access network QQ104 and / or the telecommunication network QQ102, and may be operated by the service provider or on behalf of the service provider. The host QQ116 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0150] As a whole, the communication system QQ100 of Figure 8 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0151] In some examples, the telecommunication network QQ102 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network QQ102 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network QQ102. For example, the telecommunications network QQ102 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0152] In some examples, the UEs QQ112 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network QQ104 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network QQ104. Additionally, a UE may be configured for operating in single- or multi- RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC). In the example, the hub QQ114 communicates with the access network QQ104 to facilitate indirect communication between one or more UEs (e.g., UE QQ112c and / or QQ112d) and network nodes (e.g., network node QQ110b). In some examples, the hub QQ114 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub QQ114 may be a broadband router enabling access to the core network QQ106 for the UEs. As another example, the hub QQ114 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes QQ110, or by executable code, script, process, or other instructions in the hub QQ114. As another example, the hub QQ114 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub QQ114 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub QQ114 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub QQ114 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub QQ114 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0153] The hub QQ114 may have a constant / persistent or intermittent connection to the network node QQ110b. The hub QQ114 may also allow for a different communication scheme and / or schedule between the hub QQ114 and UEs (e.g., UE QQ112c and / or QQ112d), and between the hub QQ114 and the core network QQ106. In other examples, the hub QQ114 is connected to the core network QQ106 and / or one or more UEs via a wired connection. Moreover, the hub QQ114 may be configured to connect to an M2M service provider over the access network QQ104 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes QQ110 while still connected via the hub QQ114 via a wired or wireless connection. In some embodiments, the hub QQ114 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node QQ110b. In other embodiments, the hub QQ114 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node QQ110b, but which is additionally capable of operating as a communication start and / or end point for certain data channels. Figure 9 shows a UE QQ200 in accordance with some embodiments. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes such as e.g., transport proxy node 110,130, and target node 132 and / or other UEs, such as e.g., UE 121. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop- embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB-loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0154] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0155] The UE QQ200 includes processing circuitry QQ202 that is operatively coupled via a bus QQ204 to an input / output interface QQ206, a power source QQ208, a memory QQ210, a communication interface QQ212, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 9. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0156] The processing circuitry QQ202 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory QQ210. The processing circuitry QQ202 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry QQ202 may include multiple central processing units (CPUs).

[0157] In the example, the input / output interface QQ206 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE QQ200. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0158] In some embodiments, the power source QQ208 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source QQ208 may further include power circuitry for delivering power from the power source QQ208 itself, and / or an external power source, to the various parts of the UE QQ200 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source QQ208. Power circuitry may perform any formatting, converting, or other modification to the power from the power source QQ208 to make the power suitable for the respective components of the UE QQ200 to which power is supplied.

[0159] The memory QQ210 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory QQ210 includes one or more application programs QQ214, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data QQ216. The memory QQ210 may store, for use by the UE QQ200, any of a variety of various operating systems or combinations of operating systems.

[0160] The memory QQ210 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUlCC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory QQ210 may allow the UE QQ200 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory QQ210, which may be or comprise a device-readable storage medium.

[0161] The processing circuitry QQ202 may be configured to communicate with an access network or other network using the communication interface QQ212. The communication interface QQ212 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna QQ222. The communication interface QQ212 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter QQ218 and / or a receiver QQ220 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter QQ218 and receiver QQ220 may be coupled to one or more antennas (e.g., antenna QQ222) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0162] In the illustrated embodiment, communication functions of the communication interface QQ212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof.

[0163] Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0164] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface QQ212, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0165] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0166] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smartwatch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR), a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE QQ200 shown in Figure 9.

[0167] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-loT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0168] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0169] Figure 10 shows a network node QQ300 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), O- RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).

[0170] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0171] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi- cel l / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0172] The network node QQ300 includes a processing circuitry QQ302, a memory QQ304, a communication interface QQ306, and a power source QQ308. The network node QQ300 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node QQ300 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node QQ300 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory QQ304 for different RATs) and some components may be reused (e.g., a same antenna QQ310 may be shared by different RATs). The network node QQ300 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node QQ300, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node QQ300.

[0173] The processing circuitry QQ302 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node QQ300 components, such as the memory QQ304, to provide network node QQ300 functionality.

[0174] In some embodiments, the processing circuitry QQ302 includes a system on a chip (SOC). In some embodiments, the processing circuitry QQ302 includes one or more of radio frequency (RF) transceiver circuitry QQ312 and baseband processing circuitry QQ314. In some embodiments, the radio frequency (RF) transceiver circuitry QQ312 and the baseband processing circuitry QQ314 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry QQ312 and baseband processing circuitry QQ314 may be on the same chip or set of chips, boards, or units.

[0175] The memory QQ304 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device- readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry QQ302. The memory QQ304 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry QQ302 and utilized by the network node QQ300. The memory QQ304 may be used to store any calculations made by the processing circuitry QQ302 and / or any data received via the communication interface QQ306. In some embodiments, the processing circuitry QQ302 and memory QQ304 is integrated.

[0176] The communication interface QQ306 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface QQ306 comprises port(s) / terminal(s) QQ316 to send and receive data, for example to and from a network over a wired connection. The communication interface QQ306 also includes radio front-end circuitry QQ318 that may be coupled to, or in certain embodiments a part of, the antenna QQ310. Radio front-end circuitry QQ318 comprises filters QQ320 and amplifiers QQ322. The radio front-end circuitry QQ318 may be connected to an antenna QQ310 and processing circuitry QQ302. The radio front-end circuitry may be configured to condition signals communicated between antenna QQ310 and processing circuitry QQ302. The radio front-end circuitry QQ318 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry QQ318 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters QQ320 and / or amplifiers QQ322. The radio signal may then be transmitted via the antenna QQ310. Similarly, when receiving data, the antenna QQ310 may collect radio signals which are then converted into digital data by the radio front-end circuitry QQ318. The digital data may be passed to the processing circuitry QQ302. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0177] In certain alternative embodiments, the network node QQ300 does not include separate radio front-end circuitry QQ318, instead, the processing circuitry QQ302 includes radio front-end circuitry and is connected to the antenna QQ310. Similarly, in some embodiments, all or some of the RF transceiver circuitry QQ312 is part of the communication interface QQ306. In still other embodiments, the communication interface QQ306 includes one or more ports or terminals QQ316, the radio front-end circuitry QQ318, and the RF transceiver circuitry QQ312, as part of a radio unit (not shown), and the communication interface QQ306 communicates with the baseband processing circuitry QQ314, which is part of a digital unit (not shown).

[0178] The antenna QQ310 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna QQ310 may be coupled to the radio front-end circuitry QQ318 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna QQ310 is separate from the network node QQ300 and connectable to the network node QQ300 through an interface or port.

[0179] The antenna QQ310, communication interface QQ306, and / or the processing circuitry QQ302 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna QQ310, the communication interface QQ306, and / or the processing circuitry QQ302 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0180] The power source QQ308 provides power to the various components of network node QQ300 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source QQ308 may further comprise, or be coupled to, power management circuitry to supply the components of the network node QQ300 with power for performing the functionality described herein. For example, the network node QQ300 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source QQ308. As a further example, the power source QQ308 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0181] Embodiments of the network node QQ300 may include additional components beyond those shown in Figure 12 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node QQ300 may include user interface equipment to allow input of information into the network node QQ300 and to allow output of information from the network node QQ300. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node QQ300.

[0182] Figure 11 is a block diagram of a host QQ400, which may be an embodiment of the host QQ116 of Figure 8, in accordance with various aspects described herein. As used herein, the host QQ400 may be or comprise various combinations hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The host QQ400 may provide one or more services to one or more UEs.

[0183] The host QQ400 includes processing circuitry QQ402 that is operatively coupled via a bus QQ404 to an input / output interface QQ406, a network interface QQ408, a power source QQ410, and a memory QQ412. Other components may be included in other embodiments. Features of these components may be substantially similar to those described with respect to the devices of previous figures, such as Figures QQ2 and QQ3, such that the descriptions thereof are generally applicable to the corresponding components of host QQ400.

[0184] The memory QQ412 may include one or more computer programs including one or more host application programs QQ414 and data QQ416, which may include user data, e.g., data generated by a UE for the host QQ400 or data generated by the host QQ400 for a UE. Embodiments of the host QQ400 may utilize only a subset or all of the components shown. The host application programs QQ414 may be implemented in a container-based architecture and may provide support for video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAG, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UEs (e.g., handsets, desktop computers, wearable display systems, heads-up display systems). The host application programs QQ414 may also provide for user authentication and licensing checks and may periodically report health, routes, and content availability to a central node, such as a device in or on the edge of a core network. Accordingly, the host QQ400 may select and / or indicate a different host for over-the-top services for a UE. The host application programs QQ414 may support various protocols, such as the HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.

[0185] Figure 12 is a block diagram illustrating a virtualization environment QQ500 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments QQ500 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment QQ500 includes components defined by the O-RAN Alliance, such as an O- Cloud environment orchestrated by a Service Management and Orchestration Framework via an 0-2 interface.

[0186] Applications QQ502 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0187] Hardware QQ504 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers QQ506 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs QQ508a and QQ508b (one or more of which may be generally referred to as VMs QQ508), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer QQ506 may present a virtual operating platform that appears like networking hardware to the VMs QQ508.

[0188] The VMs QQ508 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer QQ506. Different embodiments of the instance of a virtual appliance QQ502 may be implemented on one or more of VMs QQ508, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0189] In the context of NFV, a VM QQ508 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs QQ508, and that part of hardware QQ504 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs QQ508 on top of the hardware QQ504 and corresponds to the application QQ502.

[0190] Hardware QQ504 may be implemented in a standalone network node with generic or specific components. Hardware QQ504 may implement some functions via virtualization. Alternatively, hardware QQ504 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration QQ510, which, among others, oversees lifecycle management of applications QQ502. In some embodiments, hardware QQ504 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system QQ512 which may alternatively be used for communication between hardware nodes and radio units.

[0191] Figure 13 shows a communication diagram of a host QQ602 communicating via a network node QQ604 with a UE QQ606 over a partially wireless connection in accordance with some embodiments. Example implementations, in accordance with various embodiments, of the UE (such as a UE QQ112a of Figure 8 and / or UE QQ200 of Figure 9), network node (such as network node QQ110a of Figure 8 and / or network node QQ300 of Figure 10), and host (such as host QQ116 of Figure 8 and / or host QQ400 of Figure 11) discussed in the preceding paragraphs will now be described with reference to Figure 13.

[0192] Like host QQ400, embodiments of host QQ602 include hardware, such as a communication interface, processing circuitry, and memory. The host QQ602 also includes software, which is stored in or accessible by the host QQ602 and executable by the processing circuitry. The software includes a host application that may be operable to provide a service to a remote user, such as the UE QQ606 connecting via an over-the-top (OTT) connection QQ650 extending between the UE QQ606 and host QQ602. In providing the service to the remote user, a host application may provide user data which is transmitted using the OTT connection QQ650.

[0193] The network node QQ604 includes hardware enabling it to communicate with the host QQ602 and UE QQ606. The connection QQ660 may be direct or pass through a core network (like core network QQ106 of Figure 8) and / or one or more other intermediate networks, such as one or more public, private, or hosted networks. For example, an intermediate network may be a backbone network or the Internet.

[0194] The UE QQ606 includes hardware and software, which is stored in or accessible by UE QQ606 and executable by the UE’s processing circuitry. The software includes a client application, such as a web browser or operator-specific “app” that may be operable to provide a service to a human or non-human user via UE QQ606 with the support of the host QQ602. In the host QQ602, an executing host application may communicate with the executing client application via the OTT connection QQ650 terminating at the UE QQ606 and host QQ602. In providing the service to the user, the UE's client application may receive request data from the host's host application and provide user data in response to the request data. The OTT connection QQ650 may transfer both the request data and the user data. The UE's client application may interact with the user to generate the user data that it provides to the host application through the OTT connection QQ650.

[0195] The OTT connection QQ650 may extend via a connection QQ660 between the host QQ602 and the network node QQ604 and via a wireless connection QQ670 between the network node QQ604 and the UE QQ606 to provide the connection between the host QQ602 and the UE QQ606. The connection QQ660 and wireless connection QQ670, over which the OTT connection QQ650 may be provided, have been drawn abstractly to illustrate the communication between the host QQ602 and the UE QQ606 via the network node QQ604, without explicit reference to any intermediary devices and the precise routing of messages via these devices.

[0196] As an example of transmitting data via the OTT connection QQ650, in step QQ608, the host QQ602 provides user data, which may be performed by executing a host application. In some embodiments, the user data is associated with a particular human user interacting with the UE QQ606. In other embodiments, the user data is associated with a UE QQ606 that shares data with the host QQ602 without explicit human interaction. In step QQ610, the host QQ602 initiates a transmission carrying the user data towards the UE QQ606. The host QQ602 may initiate the transmission responsive to a request transmitted by the UE QQ606. The request may be caused by human interaction with the UE QQ606 or by operation of the client application executing on the UE QQ606. The transmission may pass via the network node QQ604, in accordance with the teachings of the embodiments described throughout this disclosure. Accordingly, in step QQ612, the network node QQ604 transmits to the UE QQ606 the user data that was carried in the transmission that the host QQ602 initiated, in accordance with the teachings of the embodiments described throughout this disclosure. In step QQ614, the UE QQ606 receives the user data carried in the transmission, which may be performed by a client application executed on the UE QQ606 associated with the host application executed by the host QQ602.

[0197] In some examples, the UE QQ606 executes a client application which provides user data to the host QQ602. The user data may be provided in reaction or response to the data received from the host QQ602. Accordingly, in step QQ616, the UE QQ606 may provide user data, which may be performed by executing the client application. In providing the user data, the client application may further consider user input received from the user via an input / output interface of the UE QQ606. Regardless of the specific manner in which the user data was provided, the UE QQ606 initiates, in step QQ618, transmission of the user data towards the host QQ602 via the network node QQ604. In step QQ620, in accordance with the teachings of the embodiments described throughout this disclosure, the network node QQ604 receives user data from the UE QQ606 and initiates transmission of the received user data towards the host QQ602. In step QQ622, the host QQ602 receives the user data carried in the transmission initiated by the UE QQ606.

[0198] One or more of the various embodiments improve the performance of OTT services provided to the UE QQ606 using the OTT connection QQ650, in which the wireless connection QQ670 forms the last segment. More precisely, the teachings of these embodiments may improve the latency and thereby provide benefits such as reduced user waiting time.

[0199] In an example scenario, factory status information may be collected and analyzed by the host QQ602. As another example, the host QQ602 may process audio and video data which may have been retrieved from a UE for use in creating maps. As another example, the host QQ602 may collect and analyze real-time data to assist in controlling vehicle congestion (e.g., controlling traffic lights). As another example, the host QQ602 may store surveillance video uploaded by a UE. As another example, the host QQ602 may store or control access to media content such as video, audio, VR or AR which it can broadcast, multicast or unicast to UEs. As other examples, the host QQ602 may be used for energy pricing, remote control of non-time critical electrical load to balance power generation needs, location services, presentation services (such as compiling diagrams etc. from data collected from remote devices), or any other function of collecting, retrieving, storing, analyzing and / or transmitting data.

[0200] In some examples, a measurement procedure may be provided for the purpose of monitoring data rate, latency and other factors on which the one or more embodiments improve. There may further be an optional network functionality for reconfiguring the OTT connection QQ650 between the host QQ602 and UE QQ606, in response to variations in the measurement results. The measurement procedure and / or the network functionality for reconfiguring the OTT connection may be implemented in software and hardware of the host QQ602 and / or UE QQ606. In some embodiments, sensors (not shown) may be deployed in or in association with other devices through which the OTT connection QQ650 passes; the sensors may participate in the measurement procedure by supplying values of the monitored quantities exemplified above, or supplying values of other physical quantities from which software may compute or estimate the monitored quantities. The reconfiguring of the OTT connection QQ650 may include message format, retransmission settings, preferred routing etc.; the reconfiguring need not directly alter the operation of the network node QQ604. Such procedures and functionalities may be known and practiced in the art. In certain embodiments, measurements may involve proprietary UE signaling that facilitates measurements of throughput, propagation times, latency and the like, by the host QQ602. The measurements may be implemented in that software causes messages to be transmitted, in particular empty or ‘dummy’ messages, using the OTT connection QQ650 while monitoring propagation times, errors, etc.

[0201] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0202] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0203] When using the word "comprise" or “comprising” it shall be interpreted as nonlimiting, i.e. meaning "consist at least of".

[0204] The embodiments herein are not limited to the preferred embodiments described above. Various alternatives, modifications and equivalents may be used.

Claims

CLAIMS1 . A method performed by a transport proxy node (110, 130) for handling a transport connection between a source node (121 ,131) and a target node (132) in a communications network (100), the method comprising: establishing (201) an authenticated transport connection session between the source node (121 ,131) and the transport proxy node (110,130), which authenticated transport connection session comprises a transport context, wherein the transport proxy node (110,130) is a transport endpoint in the authenticated transport connection session, receiving (202) from the source node (121 ,131) via the established authenticated transport connection session, a request for a transport connection session between the source node (121 ,131) and the target node (132), which request is requesting resource discovery and authorization for the target node (132), obtaining (203) the requested authorization for accessing resources at the target node (132), for the source node (121 ,131) to access the target node (132), moving the transport endpoint to the target node (132) by:- sending (204) a copy of the transport context to the target node (132),- sending (205) to the source node (121 ,131), a response to the request, which response comprises the obtained authorization for accessing resources at the target node (132), which obtained authorization enables the source node (121 ,131) to access resources at the target node (132) possessing the copy of the transport context, and to request for a communication between the source node (121 ,131) and the target node (132), via the transport session originally established between the source node (121 ,131) and the transport proxy node (110,130).

2. The method according to claim 1 , wherein the response sent to the source node (121 ,131), further comprises one or more out of: an identification of the target node (132) and an indication indicating that the transport connection session between the source node (121 ,131) and the target node (132) is via said established (201) transport session.

3. The method according to any of the claims 1-2, further comprising:forwarding (208) one or more packets in the communication from the source node (121,131) to the target node (132) using said established (201) transport connection session.

4. The method according to any of the claims 1-3, further comprising any one out of: deleting (206) the transport context related to the transport connection session, or storing (207) the transport context to access the communication between the source node (121,131) and the target node (132).

5. The method according to any of the claims 1-4, wherein the establishing (201) of the transport connection session between the source node (121 ,131) and the transport proxy node (110,130) is performed via a load balancer.

6. The method according to any of the claim 1-5, wherein the transport proxy node (110,130) is represented by any one or more out of: a Network Repository Function, NRF, a Service Communication Proxy, SCP, and a base station.

7. A computer program (730) comprising instructions, which when executed by a processor (710), causes the processor (710) to perform actions according to any of the claims 1-6.

8. A carrier (740) comprising the computer program (730) of claim 7, wherein the carrier (740) is one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or a computer-readable storage medium.

9. A transport proxy node (110,130) configured to handle a transport connection between a source node (121,131) and a target node (132) in a communications network (100), the transport proxy node (110,130) further being configured to: establish an authenticated transport connection session between the source node (121 ,131) and the transport proxy node (110,130), which authenticated transport connection session comprises a transport context, wherein the transport proxy node (110,130) is adapted to be a transport endpoint in the authenticated transport connection session,receive from the source node (121,131) via the established authenticated transport connection session, a request for a transport connection session between the source node (121,131) and the target node (132), which request requests resource discovery and authorization for the target node (132), obtain the requested authorization for accessing resources at the target node (132), for the source node (121,131) to access the target node (132), the transport proxy node (110,130) further being configured to move the transport endpoint to the target node (132) by:- sending a copy of the transport context to the target node (132), and- sending to the source node (121,131), a response to the request, which response comprises the obtained authorization for accessing resources at the target node (132), which obtained authorization enables the source node (121 ,131) to access resources at the target node (132) possessing the copy of the transport context, and to request for a communication between the source node (121,131) and the target node (132), via the transport session originally established between the source node (121,131) and the transport proxy node (110,130).

10. The transport proxy node (110,130) according to claim 9, wherein the response sent to the source node (121,131), is further adapted to comprise one or more out of: an identification of the target node (132) and an indication indicating that that the transport connection session between the source node (121 ,131) and the target node (132) is via said established (201) transport session.

11. The transport proxy node (110,130) according to any of the claims 9-10, further being configured to: forward one or more packets in the communication from the source node (121 ,131) to the target node (132) using said established (201) transport connection session.

12. The transport proxy node (110,130) according to any of the claims 9-11, further being configured to any one out of: delete the transport context related to the transport connection session, or store the transport context to access the communication between the source node (121,131) and the target node (132).

13. The transport proxy node (110,130) according to any of the claims 9-12, further being configured to establish the transport connection session between the source node (121 ,131) and the transport proxy node (110,130) via a load balancer.

14. The transport proxy node (110,130) according to any of the claim 9-13, wherein the transport proxy node (110,130) is adapted to be represented by any one or more out of: a Network Repository Function, NRF, a Service Communication Proxy, SCP, and a base station.

Citation Information

Patent Citations

  • Packet acknowledgement techniques for improved network traffic management

    EP3994862A1

  • Controlling migration of a QUIC connection

    US11363671B2

  • Path Switching Method, Communication Apparatus, And Communication System

    US20220225211A1

  • QUIC and anycast proxy resiliency

    US20230085513A1

  • Packet transmission method, communication apparatus, and communication system

    US20230421642A1