Discovery of masque endpoints in a communications network

The DDR protocol extension facilitates the discovery and usage of MASQUE endpoints in 5G networks, addressing exposure challenges and improving network performance and application support by enabling MASQUE proxy utilization.

WO2025153427A1PCT designated stage expired Publication Date: 2025-07-24TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/050651
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-16
Filing Date
2025-01-13
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Mobile Network Operators (MNOs) face challenges in exposing supported MASQUE endpoints to User Equipment (UEs), limiting the UEs' ability to use MASQUE endpoints for applications, and service providers struggle to deploy MASQUE endpoints effectively in collaboration with MNOs, leading to suboptimal network performance and application support.

Method used

An extension of the Discovery of Designated Resolvers (DDR) protocol is used to enable the discovery and usage of MASQUE endpoints by transmitting register requests, DDR queries, and responses to terminal devices, allowing for the establishment of MASQUE connections, with support for parameters like svcpriority, targetName, alpn, authority, targetipv4, targetipv6, and port, and enabling/disabling the MASQUE Discovery Service on a per subscriber or network basis.

Benefits of technology

Enables the discovery and usage of MASQUE proxies in 5G networks, improving network performance and allowing network operators to provide MASQUE endpoints for service providers, enhancing network efficiency and application support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025050651_24072025_PF_FP_ABST
    Figure EP2025050651_24072025_PF_FP_ABST
Patent Text Reader

Abstract

This disclosure provides a method for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The method comprises transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile; transmitting from a second network node to a terminal device network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node; transmitting from the terminal device to the first network node a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DISCOVERY OF MASQUE ENDPOINTS IN A COMMUNICATIONS NETWORK

[0002] TECHNICAL FIELD

[0003] The present invention generally relates to MASQUE (Multiplexed Application Substrate over Quick User Datagram Protocol Internet Connections Encryption) in communications or mobile networks, and more specifically, the invention relates to discovering and using MASQUE endpoints.

[0004] BACKGROUND

[0005] MASQUE (Multiplexed Application Substrate over QUIC Encryption) is a set of protocols and extensions to HTTP (Hypertext Transfer Protocol) to allow proxying Internet traffic over HTTP. MASQUE can be used for example in relay services for applications, using MASQUE proxies for this purpose.

[0006] Discovery of Designated Resolvers (DDR) protocol enables clients to query designated resolvers for endpoint services using DNS (Domain Name Services). Either an application or the underlying platform can make use of DDR to locate an endpoint (e.g., a MASQUE endpoint) by querying for a list of endpoints using a Service Binding (SVCB) DNS record. SVCB works similarly to the service (SRV) record, but also allows for additional application parameters, such as Application-Layer Protocol Negotiation (ALPN) or information for transport layer security. DDR also includes methods for authenticating endpoints and DDR servers, e.g., based on requiring that a certificate contain an IP address, requiring that the IP address of the DDR-discovered resolver has the same IP address as the unauthenticated resolver, or based on a name rather than an IP address. DDR may be used to discover encrypted DNS resolvers.

[0007] A problematic aspect of the current solutions, regarding the integration of MASQUE proxies within 5G networks, is that Mobile Network Operators (MNOs) may face challenges in exposing supported MASQUE endpoints to User Equipment (UEs), limiting the UEs' ability to use MASQUE endpoints for applications. A further problematic aspect is that service providers may also face challenges when deploying MASQUE endpoints in collaboration with MNOs, since they cannot adequately expose these endpoints to UEs for application use.

[0008] These problematic aspects may lead to suboptimal network performance, application support and service delivery.

[0009] SUMMARY

[0010] The invention is set out in the appended set of claims.

[0011] An object of the invention is to enable the discovery and usage of MASQUE (Multiplexed Application Substrate over QUIC Encryption) endpoints in a communications network, particularly when the endpoints relate to MASQUE proxies deployed in a 5G network, by means of an extension of the DDR protocol.

[0012] This disclosure provides a method for discovering Multiplexed Application Substrate over QUIC (Quick UDP Internet Connections) Encryption, MASQUE, endpoints in a communications network. The method comprises transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile; transmitting from a second network node to a terminal device network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node; transmitting from the terminal device to the first network node a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection. In some embodiments, the method further comprises selecting by the second network node the first network node based on the support of the MASQUE Discovery Service, particularly based on the support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile. In some embodiments, the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function (UPF). In some embodiments, the method further comprises detecting traffic at the Ingress Proxy and applying traffic management actions. In some embodiments, the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality. In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0013] - svcpriority, indicating the priority of the record,

[0014] - targetName, indicating the domain name of an endpoint,

[0015] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0016] - alpn, indicating Application Layer Protocol Negotiation,

[0017] - authority, indicating a policy for MASQUE flows,

[0018] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0019] - port, indicating the endpoint port.

[0020] In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found. In some embodiments, the Ingress Proxy is a User Plane Function (UPF) and the method further comprises indicating by the UPF to the second network node a UP function feature for MASQUE Discovery Service during a PFCP Association procedure. In some embodiments, the method further comprises transmitting from the third network node to the second network node a list of Network Functions supporting DDR service extension with MASQUE profile. In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information. In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0021] An aspect of the invention relates to a method performed by a first network node for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The method comprises transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile; receiving at the first network node from a terminal device a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; and transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records. In some embodiments, the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality. In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0022] - svcpriority, indicating the priority of the record,

[0023] - targetName, indicating the domain name of an endpoint,

[0024] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0025] - alpn, indicating Application Layer Protocol Negotiation,

[0026] - authority, indicating a policy for MASQUE flows,

[0027] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0028] - port, indicating the endpoint port.

[0029] In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found. In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information. In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0030] An aspect of the invention relates to a method performed by a terminal device for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The method comprises receiving at a terminal device from a second network node network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node, particularly wherein the first network node supports a MASQUE Discovery Service; transmitting from the terminal device to a first network node a Discovery of Designated Resolvers (DDR) query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; receiving at the terminal device from the first network node a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection. In some embodiments, the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function (UPF). In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0031] - svcpriority, indicating the priority of the record,

[0032] - targetName, indicating the domain name of an endpoint,

[0033] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0034] - alpn, indicating Application Layer Protocol Negotiation,

[0035] - authority, indicating a policy for MASQUE flows,

[0036] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0037] - port, indicating the endpoint port.

[0038] In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found. In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information. In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE). Other aspects of the invention relate to mobile network nodes, particularly a terminal device (101 , 600), a third network node (110), a first network node (115, 500), a second network node (115) configured to perform the respective methods as described herein. Other aspects of the invention relate to computer program and computer program products.

[0039] In some embodiments, the terminal device is a User Equipment (UE). In some embodiments, the third network node is a Network Repository Function (NRF). In some embodiments, the first network node is a Network Function (NF). In some embodiments, the second network node is a Network Function (NF). In some embodiments, the first network node and / or the second network node are a NF supporting a DDR service.

[0040] Advantageously, the solution disclosed herein enables the discovery and usage of MASQUE proxies in 5G networks. Thus, improving the network performance in MASQUE deployments.

[0041] Further advantageously, the solution disclosed herein enables network operators to provide a discovery method for MASQUE endpoints.

[0042] Further advantageously, the solution disclosed herein enables network operators to provide MASQUE endpoints for service providers.

[0043] Additional objectives, features and advantages of the concepts disclosed herein will be apparent from the following description, claims and drawings, or may be learned by practice of the described technologies and concepts as set forth herein.

[0044] BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to best describe the manner in which the disclosed concepts may be implemented, as well as define other objects, advantages and features of the disclosure, a more particular description is provided below and is illustrated in the appended drawings. Understanding that these drawings depict only exemplary embodiments of the invention and are not therefore to be considered to be limiting in scope, the examples will be described and explained with additional specificity and detail through the use of the accompanying drawings.

[0046] Figure 1 illustrates an example networked system in accordance with particular embodiments of the solution described herein. Figures 2A-2C illustrate an example signaling diagram showing a procedure according to particular embodiments of the solution described herein.

[0047] Figure 3 illustrates an example flowchart showing a method performed by a mobile network node according to particular embodiments of the solution described herein.

[0048] Figure 4 illustrates an example flowchart showing a method performed by a User Equipment (UE) according to particular embodiments of the solution described herein.

[0049] Figure 5 illustrates an example block diagram of a mobile network node configured in accordance with particular embodiments of the solution described herein.

[0050] Figure 6 illustrates an example block diagram of a UE configured in accordance with particular embodiments of the solution described herein.

[0051] Figure 7 illustrates an example block diagram of a virtualized environment.

[0052] DETAILED DESCRIPTION

[0053] The invention will now be described in detail hereinafter with reference to the accompanying drawings, in which examples of embodiments or implementations of the invention are shown. The invention may, however, be embodied or implemented in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of present invention to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be tacitly assumed to be present / used in another embodiment. These embodiments of the disclosed subject matter are presented as teaching examples and are not to be construed as limiting the scope of the disclosed subject matter. For example, certain details of the described embodiments may be modified, omitted, or expanded upon without departing from the scope of the described subject matter.

[0054] The example embodiments described herein arise in the context of a telecommunications network, including but not limited to a telecommunications network that conforms to and / or otherwise incorporates aspects of a fifth generation (5G) architecture. Figure 1 is an example networked system 100 in accordance with example embodiments of the present disclosure. Figure 1 specifically illustrates User Equipment (UE) 101 , which may be in communication with a (Radio) Access Network (RAN) 102 and Access and Mobility Management Function (AMF) 106 and User Plane Function (UPF) 103. The AMF 106 may, in turn, be in communication with core network services including Session Management Function (SMF) 107 and Policy Control Function (PCF) 111. The core network services may also be in communication with an Application Server / Application Function (AS / AF) 113. Other networked services also include Network Slice Selection Function (NSSF) 108, Authentication Server Function (AUSF) 105, User Data Management (UDM) 112, Network Exposure Function (NEF) 109, Network Repository Function (NRF) 110, Unified Data Repository (UDR) 114, Network Data Analytics Function (NWDAF) 115 and Data Network (DN) 104. In some example implementations of embodiments of the present disclosure, each one of the entities in the networked system 100 are considered to be a Network Function (NF). One or more additional instances of the NFs may be incorporated into the networked system.

[0055] The solution described herein aims to enable the discovery and usage of MASQUE endpoints in a communications network, particularly when the endpoints relate to MASQUE proxies deployed in a 5G network, by means of an extension of the DDR protocol.

[0056] This disclosure provides a method for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The method comprises transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile; transmitting from a second network node to a terminal device network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node; transmitting from the terminal device to the first network node a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection. In some embodiments, the method further comprises selecting by the second network node the first network node based on the support of the MASQUE Discovery Service, particularly based on the support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile. In some embodiments, the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function (UPF). In some embodiments, the method further comprises detecting traffic at the Ingress Proxy and applying traffic management actions. In some embodiments, the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality. In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0057] - svcpriority, indicating the priority of the record,

[0058] - targetName, indicating the domain name of an endpoint,

[0059] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0060] - alpn, indicating Application Layer Protocol Negotiation,

[0061] - authority, indicating a policy for MASQUE flows,

[0062] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0063] - port, indicating the endpoint port. In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found. In some embodiments, the Ingress Proxy is a User Plane Function (UPF) and the method further comprises indicating by the UPF to the second network node a UP function feature for MASQUE Discovery Service during a PFCP Association procedure. In some embodiments, the method further comprises transmitting from the third network node to the second network node a list of Network Functions supporting DDR service extension with MASQUE profile. In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information. In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0064] An aspect of the invention relates to a method performed by a first network node for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The method comprises transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile; receiving at the first network node from a terminal device a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; and transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records. In some embodiments, the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality. In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0065] - svcpriority, indicating the priority of the record,

[0066] - targetName, indicating the domain name of an endpoint,

[0067] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0068] - alpn, indicating Application Layer Protocol Negotiation,

[0069] - authority, indicating a policy for MASQUE flows,

[0070] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0071] - port, indicating the endpoint port. In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found. In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information. In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0072] An aspect of the invention relates to a method performed by a terminal device for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The method comprises receiving at a terminal device from a second network node network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node, particularly wherein the first network node supports a MASQUE Discovery Service; transmitting from the terminal device to a first network node a Discovery of Designated Resolvers (DDR) query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; receiving at the terminal device from the first network node a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection. In some embodiments, the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function (UPF). In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0073] - svcpriority, indicating the priority of the record,

[0074] - targetName, indicating the domain name of an endpoint,

[0075] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0076] - alpn, indicating Application Layer Protocol Negotiation,

[0077] - authority, indicating a policy for MASQUE flows,

[0078] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0079] - port, indicating the endpoint port. In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found. In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information. In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0080] Other aspects of the invention relate to mobile network nodes, particularly a terminal device (101 , 600), a third network node (110), a first network node (115, 500), a second network node (115) configured to perform the respective methods as described herein. Other aspects of the invention relate to computer program and computer program products. In some embodiments, the terminal device is a User Equipment (UE). In some embodiments, the third network node is a Network Repository Function (NRF). In some embodiments, the first network node is a Network Function (NF). In some embodiments, the second network node is a Network Function (NF). In some embodiments, the first network node and / or the second network node are a NF supporting a DDR service.

[0081] Advantageously, the solution disclosed herein enables the discovery and usage of MASQUE proxies in 5G networks. Thus, improving the network performance in MASQUE deployments.

[0082] Further advantageously, the solution disclosed herein enables network operators to provide a discovery method for MASQUE endpoints.

[0083] Further advantageously, the solution disclosed herein enables network operators to provide MASQUE endpoints for service providers.

[0084] This disclosure also provides mobile network nodes, particularly a terminal device (101 , 600), a third network node (110), a first network node (115, 500), a second network node (115) configured to perform the respective methods as described herein. In some embodiments, the terminal device is a User Equipment (UE) 101. In some embodiments, the third network node is a Network Repository Function (NRF) 110. In some embodiments, the first network node is a Network Function (NF) 115. In some embodiments, the second network node is a Network Function (NF) 115.

[0085] This disclosure also provides the corresponding computer program and computer program products comprising code, for example in the form of a computer program, that when run on processing circuitry of the mobile network nodes causes the mobile network nodes to perform the disclosed methods.

[0086] The solution and the features comprised therein are further described in what follows.

[0087] This solution disclosed herein enables to use an enhanced Discovery of Designated Resolvers (DDR) service, tailored for finding MASQUE (Multiplexed Application Substrate over QUIC Encryption) proxies. This service sends necessary discovery information to User Equipment (UE) through NAS signaling. The UE, either through its operating system or application clients, requests MASQUE endpoints from designated resolvers via this DDR service. The 5G Core (5GC) DDR service then provides responses based on the user's subscription and the application's capabilities, enabling the UE to connect to the identified MASQUE endpoints, such as those in the User Plane Function (UPF). The proposed solution comprises the following aspects:

[0088] • At operator's network, a feature “MASQUE Discovery Service based on DDR extensions” can be enabled / disabled on a per subscriber, on a per group of subscribers, on a per global (network) basis or on a per DNN basis. • Any 5GC (5G Core) NF (e.g., UPF or MNO's DNS Resolver) supporting the

[0089] “MASQUE Discovery Service based on DDR extensions” registers the support of the service in NRF.

[0090] • For the specific case the MASQUE discovery service is supported by the UPF, in the PFCP Association procedure, UPF reports to SMF a UP function feature (MADISE, MASQUE Discovery Service). This allows SMF to select a UPF supporting this capability on a per PFCP session basis. See Table 1 .

[0091] Table 1 : UP Function Features • DDR protocol is extended to support a schema for MASQUE endpoints. The schema contaisn at least the basic parameters that the UE needs to establish a connection with the MASQUE endpoint: schema: _masque svcpriority: Priority of the record that shall be considered by the UE targetName: The domain name of an endpoint

[0092] SvcParams (optional): A list of key=value pairs describing the alternative endpoint at TargetName alpn: Application Layer Protocol Negotiation authority: MNO policy for MASQUE flows targetipv4: Endpoint Ip targetipv6: Endpoint Ip port: Endpoint Port

[0093] • UE OS or application client queries for endpoints by using the reserved schema template by following DDR syntaxis. E.g.:

[0094] _masque.service_provider.com, IN SVCB

[0095] • The MNO 5G core replies to the type of DDR query by providing the endpoint records or a resolution error if not found. One query can reference to more than one record. For example, for the query above, the MNO 5G core will reply as following:

[0096] 300 IN SVCB 1 service_provider.com. alpn="h3" port="80" ipv4hint="1.1.1.1 ,1.0.0.1" ipv6hint="2606:4700:4700::1111 ,2606:4700:4700::1001 "

[0097] 300 IN SVCB 2 service_provider.com. alpn="h3" port="8080" ipv4hint="1 .1.1.1 ,1 .0.0.1 " ipv6hint="2606:4700:4700::1111 ,2606:4700:4700::1001 "

[0098] • The UE OS or application client uses type of DDR reply to select the MASQUE endpoint to establish the connection.

[0099] Hereinafter, drawings showing examples of embodiments of the solution are described in detail. Figure 2 is a signaling diagram illustrating a procedure for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network. The procedure is performed by a terminal device (101 , 600), a third network node (110), a first network node (115, 500), a second network node (115). In some embodiments, the terminal device is a User Equipment (UE). In some embodiments, the third network node is a Network Repository Function (NRF). In some embodiments, the first network node is a Network Function (NF). In some embodiments, the second network node is a Network Function (NF).

[0100] The steps of the procedure, in the scenario of a dual proxy deployment, are the following.

[0101] Steps 1 and 2) A 5GC NF (e.g., UPF or MNO's DNS Resolver) supporting extended DDR service, registers in NRF by triggering a Nnrf_NFManagement_NFRegister Request message including the following information:

[0102] • NFProfile including support for DDR service extension with MASQUE profile.

[0103] Alternatively, for the specific case the DDR service extension with MASQUE profile is supported by the UPF, at PFCP Association procedure between UPF and SMF entities, it is proposed to extend the existing mechanism to report UPF capabilities with a UP function feature (MADISE, MASQUE Discovery Service). This would allow SMF to know which UPFs support this capability and thus can influence on UPF selection.

[0104] Step 3) UE triggers PDU session establishment, by means of sending a PDU Session Establishment Request to AMF. Note the sequence diagram in Figure 2 does not include all the signaling messages involved in the PDU Session Establishment procedure. The relevant signaling messages for the IvD are described in subsequent steps.

[0105] Steps 4) AMF selects an SMF to manage the PDU session and triggers Nsmf PDU Session Create message.

[0106] Step 5) SMF selects a PCF and triggers a Npcf_SMPolicyControl_Create Request message.

[0107] Steps 6 and 7) PCF retrieves the subscriber policy data from UDR by triggering a Nudr Query request message including the SUPI and UDR answers including the following information:

[0108] Indication of MASQUE support, optionally including a list of application identifiers. Steps 8 and 9) PCF generates the corresponding PCC rule / s (based on Subscriber Policy Data) and triggers a Npcf_SMPolicyControl_Create Response message including the following information:

[0109] • Indication of MASQUE support, optionally including a list of application identifiers.

[0110] Step 10) SMF selects a UPF supporting MASQUE Ingress Proxy and triggers a PFCP Session Establishment Request message.

[0111] Steps 11 and 12) UPF enables MASQUE Ingress Proxy and answers the message in Step 10 indicating successful operation.

[0112] Steps 13 and 14) SMF triggers discovery procedure (via NRF) for extended DDR service by triggering a Nnrf NFDiscovery Request message including the following information:

[0113] • Indication of requested support for DDR service extension with MASQUE profile

[0114] Step 15) NRF answers with the following information:

[0115] • List of NFs supporting DDR service extension with MASQUE profile.

[0116] Steps 16 and 17) SMF triggers the Nsmf PDU Session Create Response message including the following information:

[0117] • Information relative to DDR service extended with MASQUE profile, (Optional) list of App-ID

[0118] Step 18) AMF triggers a PDU Session Establishment Response message including the following information:

[0119] • Information relative to DDR service extended with MASQUE profile, (Optional) list of App-ID

[0120] Step 19) UE stores the received information.

[0121] Steps 20 and 21) User at UE opens an application (e.g., example.com) which requires Dual Proxy support. DDR procedure is triggered (towards the discovered 5GC entity supporting DDR service extended with MASQUE profile) to query for designated resolvers, e.g:

[0122] _masque.example.com, IN SVCB

[0123] Steps 22 and 23) The 5GC entity supporting DDR service extended with MASQUE profile replies to the type of DDR query by providing the endpoint records, e.g.: 300 IN SVCB 1 example_masque.com. alpn="h3" port="80" ipv4hint="1.1.1.1 ,1.0.0.1” ipv6hint="2606:4700:4700::1111 ,2606:4700:4700::1001 " authority-’ No Charging”"

[0124] Steps 24 and 25) UE stores the received information and establishes a QUIC connection with the MASQUE Ingress proxy by triggering a HTTP CONNECT method including the following information:

[0125] • :protocol=connect-udp [6]

[0126] • :scheme=https

[0127] • :path= / egressproxyinstance.com / 443 / . This indicates the egress proxy instance

[0128] • stream ld=0

[0129] Step 26) UPF authorizes the request.

[0130] Step 27) UPF answers indicating successful operation.

[0131] Step 28) Through the tunnel of the Ingress Proxy connection, UE triggers a CONNECT request to the Egress proxy, i.e. UE sends a HTTP CONNECT method including the following information:

[0132] • :protocol=connect-udp [6]

[0133] • :scheme=https

[0134] • :path= / example.com / 443 / . This indicates the target host (application server).

[0135] • :authority=egressproxyinstance.com. This indicates the domain of the egress proxy instance.

[0136] • streamld=0.

[0137] The solution also works with other HTTP methods, such as connect-ip or even regular HTTP connect.

[0138] Step 29) UPF forwards to the CONNECT message to the Egress Proxy. Note the target domain (example.com) is not visible to UPF so the user privacy provided by the dual-proxy deployment is respected.

[0139] Step 30) Egress Proxy answers indicating successful operation. Step 31 ) UE sends HTTP3 datagrams towards the Application Server. End-to-end data is relayed via the Ingress Proxy to the Egress Proxy and onwards to the target server. The MNO is unaware of the target application, the provider of the Egress Proxy and target server are unaware of the subscriber address.

[0140] Step 32) UPF detects traffic through the tunnel with Ingress / Egress Proxy and applies the corresponding traffic management actions (e.g., zero rating, QoS).

[0141] Hereinafter, flowcharts showing examples of embodiments of the solution are described in detail.

[0142] The embodiments correspond to methods performed by and involving a terminal device (101 , 600), a third network node (110), a first network node (115, 500), a second network node (115).

[0143] Figure 3 is a flowchart illustrating a method performed by the first network node for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network.

[0144] In step S-301 , the first network node transmits to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers (DDR) service extension with MASQUE profile.

[0145] In step S-302, the first network node receives from a terminal device a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension.

[0146] In step S-303, the first network node transmits to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records.

[0147] In some embodiments, the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality.

[0148] In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0149] - svcpriority, indicating the priority of the record,

[0150] - targetName, indicating the domain name of an endpoint, - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0151] - alpn, indicating Application Layer Protocol Negotiation,

[0152] - authority, indicating a policy for MASQUE flows,

[0153] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0154] - port, indicating the endpoint port.

[0155] In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found.

[0156] In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information.

[0157] In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0158] Figure 4 is a flowchart illustrating a method performed by the terminal device for discovering Multiplexed Application Substrate over QUIC Encryption, MASQUE, endpoints in a communications network.

[0159] In step S-401 , the terminal device receives from a second network node network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node, particularly wherein the first network node supports a MASQUE Discovery Service.

[0160] In step S-402, the terminal device transmits to a first network node a Discovery of Designated Resolvers (DDR) query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension.

[0161] In step S-403, the terminal device receives from the first network node a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records.

[0162] In step S-404, the terminal device initiates a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection. In some embodiments, the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function (UPF).

[0163] In some embodiments, the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:

[0164] - svcpriority, indicating the priority of the record,

[0165] - targetName, indicating the domain name of an endpoint,

[0166] - SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.

[0167] - alpn, indicating Application Layer Protocol Negotiation,

[0168] - authority, indicating a policy for MASQUE flows,

[0169] - targetipv4 and / or targetipv6, indicating the endpoint IP addresses,

[0170] - port, indicating the endpoint port.

[0171] In some embodiments, the response to the DDR query includes a resolution error if endpoints are not found.

[0172] In some embodiments, the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information.

[0173] In some embodiments, the first network node is a Network Function (NF), the second network node is a Session Management Function (SMF) the third network node is a Network Repository Function (NRF) and the terminal device is a User Equipment (UE).

[0174] Figure 5 is a block diagram illustrating elements of a mobile network node 500 of a mobile communications network. In some embodiments, the mobile network node 500 is a Network Function (NF) 115. As shown, the mobile network node may include network interface circuitry 501 (also referred to as a network interface) configured to provide communications with other nodes of the core network and / or the network. The mobile network node may also include a processing circuitry 502 (also referred to as a processor) coupled to the network interface circuitry, and memory circuitry 503 (also referred to as memory) coupled to the processing circuitry. The memory circuitry 503 may include computer readable program code that when executed by the processing circuitry 502 causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, processing circuitry 502 may be defined to include memory so that a separate memory circuitry is not required. As discussed herein, operations of the mobile network node may be performed by processing circuitry 502 and / or network interface circuitry 501 . For example, processing circuitry 502 may control network interface circuitry 501 to transmit communications through network interface circuitry 501 to one or more other network nodes and / or to receive communications through network interface circuitry from one or more other network nodes. Moreover, modules may be stored in memory 503, and these modules may provide instructions so that when instructions of a module are executed by processing circuitry 502, processing circuitry 502 performs respective operations (e.g., operations discussed below with respect to Example Embodiments relating to core network nodes).

[0175] Figure 6 is a block diagram illustrating elements of a User Equipment (UE) 600 (also referred to as a communication device, a mobile terminal, a mobile communication terminal, a wireless device, a wireless communication device, a wireless terminal, mobile device, a wireless communication terminal, a user equipment node / terminal / device, etc.) configured to provide wireless communication according to embodiments of the disclosure. As shown, communication device UE may include an antenna 607, and transceiver circuitry 601 (also referred to as a transceiver) including a transmitter and a receiver configured to provide uplink and downlink radio communications with a base station(s) (also referred to as a RAN node) of a radio access network. The UE may also include processing circuitry 603 (also referred to as a processor) coupled to the transceiver circuitry, and memory circuitry 605 (also referred to as memory, e.g., corresponding to device readable medium) coupled to the processing circuitry. The memory circuitry 605 may include computer readable program code, such as application client 609, that when executed by the processing circuitry 603 causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, processing circuitry 603 may be defined to include memory so that separate memory circuitry is not required. The UE 600 may also include an interface (such as a user interface) coupled with processing circuitry 603, and / or the UE may be incorporated in a vehicle. As discussed herein, operations of the UE may be performed by processing circuitry 603 and / or transceiver circuitry 601 . For example, processing circuitry 603 may control transceiver circuitry 601 to transmit communications through transceiver circuitry 601 over a radio interface to a radio access network node (also referred to as a base station) and / or to receive communications through transceiver circuitry 601 from a RAN node over a radio interface. Moreover, modules may be stored in memory circuitry 605, and these modules may provide instructions so that when instructions of a module are executed by processing circuitry 603, processing circuitry 603 performs respective operations (e.g., the operations disclosed herein with respect to the example embodiments relating to the UE).

[0176] Figure 7 is a block diagram illustrating a virtualization environment 700 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 700 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 700 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an 0-2 interface.

[0177] Applications 702 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0178] Hardware 704 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 706 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 708a and 708b (one or more of which may be generally referred to as VMs 708), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 706 may present a virtual operating platform that appears like networking hardware to the VMs 708.

[0179] The VMs 708 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 706. Different embodiments of the instance of a virtual appliance 702 may be implemented on one or more of VMs 708, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0180] In the context of NFV, a VM 708 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 708, and that part of hardware 704 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 708 on top of the hardware 704 and corresponds to the application 702.

[0181] Hardware 704 may be implemented in a standalone network node with generic or specific components. Hardware 704 may implement some functions via virtualization. Alternatively, hardware 704 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 710, which, among others, oversees lifecycle management of applications 702. In some embodiments, hardware 704 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 712 which may alternatively be used for communication between hardware nodes and radio units.

[0182] Embodiments within the scope of the present invention may also include computer-readable media for carrying or having computer-executable instructions or data structures stored thereon. Such computer-readable media can be any available media that can be accessed by a general purpose or special purpose computer. By way of example, and not limitation, such tangible computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to carry or store desired program code means in the form of computer-executable instructions or data structures. When information is transferred or provided over a network or another communications connection (either hardwired, wireless, or combination thereof) to a computer, the computer properly views the connection as a computer-readable medium. Thus, any such connection is properly termed a computer- readable medium. Combinations of the above should also be included within the scope of the tangible computer-readable media.

[0183] Computer-executable instructions include, for example, instructions and data which cause a general purpose computer, special purpose computer, or special purpose processing device to perform a certain function or group of functions. Computer-executable instructions also include program modules that are executed by computers in standalone or network environments. Generally, program modules include routines, programs, objects, components, and data structures that perform particular tasks or implement particular abstract data types. Computer executable instructions, associated data structures, and program modules represent examples of the program code means for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represent examples of corresponding acts for implementing the functions described in such steps.

[0184] Those of skill in the art will appreciate that other embodiments of the invention may be practiced in network computing environments with many types of computer system configurations, including personal computers, hand-held devices, multi-processor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, mainframe computers, and the like. Embodiments may also be practiced in distributed computing environments where tasks are performed by local and remote processing devices that are linked (either by hardwired links, wireless links, or by a combination thereof) through a communications network. In a distributed computing environment, program modules may be located in both local and remote memory storage devices.

[0185] Communication at various stages of the described system can be performed through a local area network, a token ring network, the Internet, a corporate intranet, 802.11 series wireless signals, fiber-optic network, radio or microwave transmission, etc. Although the underlying communication technology may change, the fundamental principles described herein are still applicable.

[0186] The various embodiments described above are provided by way of illustration only and should not be construed to limit the invention. For example, the principles herein may be applied to any remotely controlled device. Further, those of skill in the art will recognize that communication between the remote the remotely controlled device need not be limited to communication over a local area network but can include communication over infrared channels, Bluetooth or any other suitable communication interface. Those skilled in the art will readily recognize various modifications and changes that may be made to the present invention without following the example embodiments and applications illustrated and described herein, and without departing from the scope of the present disclosure.

[0187] The terminology used herein is for the purpose of describing various embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "includes," "including," "comprises," and "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, or components, and combinations thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, or components, and combinations thereof. Further, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to ""a / an / the element, apparatus, component, means, module, step, etc."" are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, module, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.

[0188] ABBREVIATIONS

[0189] ALPN - Application-Layer Protocol Negotiation

[0190] AMF - Access and Mobility Management Function

[0191] AS / AF - Application Server / Application Function

[0192] ALISF - Authentication Server Function

[0193] DDR - Discovery of Designated Resolvers

[0194] DN - Data Network

[0195] DNS - Domain Name Services

[0196] DNN - Data Network Name

[0197] HTTP - Hypertext Transfer Protocol MASQUE - Multiplexed Application Substrate over QUIC Encryption

[0198] MNO - Mobile Network Operator

[0199] MPQUIC - Multipath Quick UDP Internet Connections

[0200] NAS - Non-Access Stratum

[0201] NEF - Network Exposure Function

[0202] NF - Network Function

[0203] NRF - Network Repository Function

[0204] NWDAF - Network Data Analytics Function

[0205] PCF - Policy Control Function

[0206] PFCP - Packet Forwarding Control Protocol

[0207] PDU - Protocol Data Unit

[0208] QoS - Quality of Service

[0209] QUIC - Quick UDP Internet Connections

[0210] RAN - Radio Access Network

[0211] SVCB - Service Binding (DNS Resource Record)

[0212] SMF - Session Management Function

[0213] UDM - User Data Management

[0214] UDP - User Datagram Protocol

[0215] UDR - Unified Data Repository

[0216] UE - User Equipment

[0217] UPF - User Plane Function

Claims

CLAIMS1 . A method for discovering Multiplexed Application Substrate over Quick User Datagram Protocol Internet Connections Encryption, MASQUE, endpoints in a communications network, the method comprising: transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers, DDR, service extension; transmitting from a second network node to a terminal device network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node; transmitting from the terminal device to the first network node a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection.

2. The method of claim 1 , wherein the method further comprises selecting by the second network node the first network node based on the support of the MASQUE Discovery Service, particularly based on the support for Discovery of Designated Resolvers, DDR, service extension with MASQUE profile.

3. The method of any one of claims from claim 1 to claim 2, wherein the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function, UPF.

4. The method of any one of claims from claim 1 to claim 3, wherein the method further comprises detecting traffic at the Ingress Proxy and applying traffic management actions.

5. The method of any one of claims from claim 1 to claim 4, wherein the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality.

6. The method of any one of claims from claim 1 to claim 5, wherein the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:- svcpriority, indicating the priority of the record,- targetName, indicating the domain name of an endpoint,- SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.- alpn, indicating Application Layer Protocol Negotiation,- authority, indicating a policy for MASQUE flows,- targetipv4 and / or targetipv6, indicating the endpoint IP addresses,- port, indicating the endpoint port.

7. The method of any one of claims from claim 1 to claim 6, wherein the response to the DDR query includes a resolution error if endpoints are not found.

8. The method of any one of claims from claim 1 to claim 7, wherein the Ingress Proxy is a User Plane Function, UPF, and the method further comprises indicating by the UPF to the second network node a UP function feature for MASQUE Discovery Service during a PFCP Association procedure.

9. The method of any one of claims from claim 1 to claim 8, wherein the method further comprises transmitting from the third network node to the second network node a list of Network Functions supporting DDR service extension with MASQUE profile.

10. The method of any one of claims from claim 1 to claim 9, wherein the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information.11 . The method of any one of claims from claim 1 to claim 10, wherein the first network node is a Network Function, NF, the second network node is a Session ManagementFunction, SMF, the third network node is a Network Repository Function, NRF, and the terminal device is a User Equipment, UE.

12. A method performed by a first network node for discovering Multiplexed Application Substrate over Quick User Datagram Protocol Internet Connections Encryption, MASQUE, endpoints in a communications network, the method comprising: transmitting from a first network node to a third network node a register request, wherein the first network node supports a MASQUE Discovery Service, wherein the register request includes an indication of support for Discovery of Designated Resolvers, DDR, service extension; receiving at the first network node from a terminal device a DDR query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; and transmitting from the first network node to the terminal device a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records.

13. The method of claim 12, wherein the MASQUE Discovery Service is enabled or disabled on a per subscriber, group of subscribers, global network or per DNN basis, and wherein the Ingress Proxy receives an indication to enable or disable the MASQUE ingress proxy functionality.

14. The method of any one of claims from claim 12 to claim 13, wherein the DDR service extension supports a schema for MASQUE endpoints containing parameters for establishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:- svcpriority, indicating the priority of the record,- targetName, indicating the domain name of an endpoint,- SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.- alpn, indicating Application Layer Protocol Negotiation,- authority, indicating a policy for MASQUE flows,- targetipv4 and / or targetipv6, indicating the endpoint IP addresses,- port, indicating the endpoint port.

15. The method of any one of claims from claim 12 to claim 14, wherein the response to the DDR query includes a resolution error if endpoints are not found.

16. The method of any one of claims from claim 12 to claim 15, wherein the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information.

17. The method of any one of claims from claim 12 to claim 16, wherein the first network node is a Network Function, NF, the second network node is a Session Management Function, SMF, the third network node is a Network Repository Function, NRF, and the terminal device is a User Equipment, UE.

18. A method performed by a terminal device for discovering Multiplexed Application Substrate over Quick User Datagram Protocol Internet Connections Encryption, MASQUE, endpoints in a communications network, the method comprising: receiving at a terminal device from a second network node network address information relative to the first network node, particularly wherein the second network node previously discovered the first network node by querying the third network node, particularly wherein the first network node supports a MASQUE Discovery Service; transmitting from the terminal device to a first network node a Discovery of Designated Resolvers, DDR, query for MASQUE endpoints, particularly wherein the request uses a DDR protocol extension; receiving at the terminal device from the first network node a response to the DDR query including MASQUE endpoint information, particularly wherein the MASQUE endpoint information comprises endpoint records; and initiating at the terminal device a network connection based on the received MASQUE endpoint information, particularly wherein the network connection is a MASQUE connection.

19. The method of claim 18, wherein the method further comprises triggering a CONNECT request at the terminal device to an Ingress Proxy based on the MASQUE endpoint information, particularly wherein the Ingress Proxy is a User Plane Function, UPF.

20. The method of any one of claims from claim 18 to claim 19, wherein the DDR service extension supports a schema for MASQUE endpoints containing parameters forestablishing a connection with the MASQUE endpoint, wherein the parameters comprise any one of:- svcpriority, indicating the priority of the record,- targetName, indicating the domain name of an endpoint,- SvcParams, indicating a list of key-value pairs describing the alternative endpoint at targetName.- alpn, indicating Application Layer Protocol Negotiation,- authority, indicating a policy for MASQUE flows,- targetipv4 and / or targetipv6, indicating the endpoint IP addresses,- port, indicating the endpoint port.21 . The method of any one of claims from claim 18 to claim 20, wherein the response to the DDR query includes a resolution error if endpoints are not found.

22. The method of any one of claims from claim 18 to claim 21 , wherein the method further comprises establishing a QUIC connection with the MASQUE Ingress Proxy based on the MASQUE endpoint information.

23. The method of any one of claims from claim 18 to claim 22, wherein the first network node is a Network Function, NF, the second network node is a Session Management Function, SMF, the third network node is a Network Repository Function, NRF, and the terminal device is a User Equipment, UE.

24. Apparatus for discovering Multiplexed Application Substrate over Quick User Datagram Protocol Internet Connections Encryption, MASQUE, endpoints in a communications network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor such that the apparatus is operable to perform the method of any one of claims from claim 12 to claim 17.

25. Apparatus for discovering Multiplexed Application Substrate over Quick User Datagram Protocol Internet Connections Encryption, MASQUE, endpoints in a communications network, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor such that the apparatus is operable to perform the method of any one of claims from claim 18 to claim 23.

26. A system comprising an apparatus as claimed in claim 24, and an apparatus as claimed in claim 25.

27. A computer-implemented system comprising one or more processors and one or more computer storage media storing computer-usable instructions that, when used by the one or more processors, cause the one or more processors to perform a method according to any one of claims from claim 12 to claim 23.

28. A computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to perform a method according to any of claims from claim 12 to claim 23.

29. A computer program product, embodied on a non-transitory machine-readable medium, comprising instructions which are executable by a processor, causing the processor to perform the method according to any of claims from claim 12 to claim 23.

Citation Information

Patent Citations

  • Enhanced service continuity

    WO2023187203A1