Method, apparatus and computer program

The described method and apparatus enable secure and efficient inter-public-land-mobile-network signaling by using HTTP/TCP connections through roaming intermediaries, addressing challenges in network interoperability and security within public land mobile networks.

WO2025168418A1PCT designated stage Publication Date: 2025-08-14NOKIA TECHNOLOGIES OY

Patent Information

Application Number
PCT/EP2025/052279
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-05
Filing Date
2025-01-29
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing communication systems face challenges in establishing efficient and secure inter-public-land-mobile-network signaling connections, particularly in scenarios involving roaming user equipment, due to complexities in contractual agreements and connectivity issues between different networks.

Method used

The implementation of a method and apparatus that utilize Hypertext Transfer Protocol (HTTP) connect requests and responses to establish Transmission Control Protocol (TCP) connections through roaming intermediaries, enabling secure and controlled signaling connections between Security Edge Protection Proxies in different public land mobile networks, with mechanisms for verifying identities and negotiating security protocols.

Benefits of technology

Facilitates secure and efficient establishment of inter-public-land-mobile-network signaling connections, ensuring compliance with contractual agreements and managing message forwarding policies, thereby enhancing network interoperability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025052279_14082025_PF_FP_ABST
    Figure EP2025052279_14082025_PF_FP_ABST
Patent Text Reader

Abstract

There is provided an apparatus, method, and computer program for transmitting, to a first roaming intermediary, a hypertext transfer protocol connect request of establishing a transmission control protocol connection between the first roaming intermediary and a peer apparatus, wherein the transmission control protocol connection is used for establishing an inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary; and receiving, from the first roaming intermediary, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection towards the peer apparatus is established; wherein the hypertext transfer protocol connect request comprises information indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public- land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, APPARATUS AND COMPUTER PROGRAM FIELD

[0001] The present application relates to a method, apparatus, system and computer program and in particular but not exclusively to apparatus for establishing an inter-public-land-mobile-network signaling connection. BACKGROUND

[0002] A communication system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entitiesinvolved in the communications path. A communication system can be provided, forexample, by means of a communication network and one or more compatiblecommunication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.

[0003] In a wireless communication system at least a part of a communicationsession between at least two stations occurs over a wireless link. Examples of wireless systems comprise public land mobile networks (PLMN), satellite based communication systems and different wireless local networks, for example wireless local area networks (WLAN). Some wireless systems can be divided into cells, and are therefore often referred to as cellular systems.

[0004] A user can access the communication system by means of an appropriate communication device or terminal. A communication device of a user may be referred to as user equipment (UE) or user device. A communication device isprovided with an appropriate signal receiving and transmitting apparatus forenabling communications, for example enabling access to a communication network or communications directly with other users. The communication devicemay access a carrier provided by a station, for example a base station of a cell, and transmit and / or receive communications on the carrier.

[0005] The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. One example of a communications system is UTRAN (3G radio). Other examples of communication systems are the long-term evolution (LTE) of the Universal Mobile Telecommunications System (UMTS) radio-access technology and so-called 5G or New Radio (NR) networks. NR is beingstandardized by the 3rd Generation Partnership Project (3GPP). SUMMARY

[0006] According to a first aspect, there is provided an apparatus comprising means for performing: transmitting, to a first roaming intermediary, a hypertext transfer protocol connect request of establishing a transmission control protocol connection between the first roaming intermediary and a peer apparatus, wherein the transmission control protocol connection is used for establishing an inter-public- land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary; and receiving, from the first roaming intermediary, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection towards the peer apparatus is established; wherein the hypertext transfer protocol connect request comprises information indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0007] Information describing the purpose of establishing the transmission controlprotocol connection may comprise information identifying the hypertext transferprotocol connect request is to be used to establish the inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary.

[0008] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying at least oneintended purpose of the inter-public-land-mobile-network signaling connection beingestablished.

[0009] The at least one intended purpose of the inter-public-land-mobile-networksignaling connection being established may be at least one of: a roaming intendedpurpose; a disaster roaming purpose; an inter-public-land-mobile-network mobilityintended purpose; or an SMS interconnection intended purpose.

[0010] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying a securityprotocol intended to be negotiated over the inter-public-land-mobile-network signaling connection.

[0011] The security protocol intended to be negotiated over the inter-public-land- mobile-network signaling connection may comprise one of: a protocol for N32interconnect security, PRINS, protocol; a security profiles for PRINS; and a transportlayer security, TLS, protocol.

[0012] Information controlling the forwarding or origination of messages by the firstroaming intermediary may comprise information of at least one policy indicatingwhether the first roaming intermediary is permitted to at least one of: accept or rejecta service request exchanged between Network Functions of the two Public Land Mobile Networks; accept or reject a request from one visited Public Land Mobile Network to register an in-bound roaming user equipment to a home Public LandMobile Network of the user equipment; deregister a user equipment; or terminate apacket data unit session.

[0013] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise a correlation identifier configured tocorrelate communication messages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile- network messages forwarding connection between the apparatus and the peer apparatus.The header may comprise: a single header ; or two or more headers,each of the two or more headers comprising one of: information indicating theapparatus; information describing a purpose of establishing the transmission controlprotocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocolconnection; or information controlling forwarding or origination of messages by thefirst roaming intermediary towards the apparatus or the peer apparatus.

[0014] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the peer apparatus is established and may comprise information identifying at least one acceptable intended purpose of establishing the inter-public-land-mobile-network signaling communication via the first roaming intermediary.

[0015] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the peer apparatus is established and may comprise information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile-network communication via the first roaming intermediatory.

[0016] Information which indicates whether the transmission control protocolconnection towards the peer apparatus is established may be information indicatingthe transmission control protocol connection is not established and the informationmay further comprise a reason of the transmission control protocol connection is notestablished.

[0017] The reason of the transmission control protocol connection is not establishedmay comprise at least one of: no contractual roaming agreement; peer apparatus cannot be reached due to connectivity issues; or an unallowed N32 purpose; and an unallowed security protocol.

[0018] The hypertext transfer protocol connect response may indicate whether thefirst roaming intermediary or a further roaming intermediary rejected theestablishment of the transmission control protocol connection towards the peer apparatus.

[0019] The hypertext transfer protocol connect response may contain a Serverheader identifying the roaming intermediary which rejected the establishment of thetransmission control protocol connection towards the peer apparatus.

[0020] The apparatus may be a consumer Security Edge Protection Proxy in a publicland mobile network and the peer apparatus may be a producer Security EdgeProtection Proxy in a peer public land mobile network.

[0021] Information indicating the apparatus may comprise at least one of thefollowing: information identifying the apparatus; or information indicating a public land mobile network of the apparatus.

[0022] Information indicating the apparatus may comprise a Fully Qualified DomainName of the apparatus.

[0023] The information indicating the peer apparatus may comprise at least one of the following: information identifying the peer apparatus; or information indicating a peer public land mobile network of the peer apparatus.

[0024] The means may be further for performing signing the information prior to transmitting, the signing the information providing at least one of: verification of theapparatus at the first roaming intermediary; or verification of the information at thefirst roaming intermediary.

[0025] The inter-public-land-mobile-network signaling connection may be used bythe apparatus and the peer apparatus to determine the security to apply for the forwarding of messages between the two Public Land Mobile Networks.

[0026] According to a second aspect there is provided an apparatus, the apparatus being a roaming intermediary, the apparatus comprising means for performing: receiving, from a further apparatus, a hypertext transfer protocol connect request of establishing a transmission control protocol connection towards a target Security Edge Protection Proxy of a target Public Land Mobile Network, wherein the transmission control protocol connection is used for establishing an inter-public- land-mobile-network signaling connection between the target Security Edge Protection Proxy and a consumer Security Edge Protection Proxy via the apparatus, wherein the hypertext transfer protocol connect request comprises informationindicating the producer Security Edge Protection Proxy, and wherein the hypertexttransfer protocol connect request comprises a header comprising at least one of:information indicating the further apparatus; information describing a purpose ofestablishing the transmission control protocol connection; information describing theinter-public-land-mobile-network signaling connection being established by usingthe transmission control protocol connection; or information controlling forwardingor origination of messages by the apparatus towards the producer Security EdgeProtection Proxy or the further apparatus; and determining whether the transmissioncontrol protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information; andtransmitting at least one of: to the further apparatus, a hypertext transfer protocolconnect response comprising response information which indicates whether thetransmission control protocol connection is established; or to a further roamingintermediary, a further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network for establishing the inter- public-land-mobile-network signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the apparatus and also through the further roaming intermediary.

[0027] The further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security EdgeProtection Proxy of the target Public Land Mobile Network may comprise informationindicating the target Security Edge Protection Proxy, and wherein the further hypertext transfer protocol connect request comprises a header comprising at leastone of: information indicating the further apparatus; information indicating theapparatus; information describing a purpose of establishing the transmission controlprotocol connection; information describing the inter-public-land-mobile-networksignaling connection being established by using the transmission control protocolconnection; or information controlling forwarding or origination of messages by thefurther roaming intermediary towards the target Security Edge Protection Proxy orthe consumer Security Edge Protection Proxy.

[0028] Information describing the purpose of establishing the transmission controlprotocol connection may comprise information identifying the hypertext transfer protocol connect request is to be used to establish a signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the roaming intermediary.

[0029] The information describing the inter-public-land-mobile-network signaling connection being established may comprise information identifying at least oneintended purpose of the inter-public-land-mobile-network signaling connection beingestablished.

[0030] The at least one intended purpose of the inter-public-land-mobile-networksignaling connection being established may be at least one of: a roaming intendedpurpose; a disaster roaming purpose; an inter-public-land-mobile-network mobilityintended purpose; or an SMS interconnection intended purpose.

[0031] The information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying a securityprotocol intended to be negotiated over the inter-public-land-mobile-network signaling connection.

[0032] The security protocol intended to be negotiated over the inter-public-land-mobile-network signaling connection may comprise one of: a protocol for N32interconnect security, PRINS, protocol; a security profiles for PRINS; and a transportlayer security, TLS, protocol.

[0033] Information controlling the forwarding or origination of messages by theroaming intermediary may comprise information of at least one policy indicatingwhether the roaming intermediary is permitted to at least one of: accept or reject aservice request exchanged between Network Functions of the two Public LandMobile Networks; accept or reject a request from one visited Public Land MobileNetwork to register an in-bound roaming user equipment to a home Public LandMobile Network of the user equipment; deregister a user equipment; and terminatea packet data unit session.

[0034] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise a correlation identifier configured tocorrelate communication messages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile- network messages forwarding connection between the consumer Security Edge Protection Proxy and the target Security Edge Protection Proxy.

[0035] The header may comprise: a single header; or two or more headers, each of the two or more headers comprising one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection;or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0036] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the target Security Edge Protection Proxy is established and may comprise information identifying at least one acceptable intended purpose of establishing the inter-public-land-mobile- network signaling communication via the roaming intermediary.

[0037] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the target Security Edge Protection Proxy is established and may comprise information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile- network communication via the roaming intermediary.

[0038] The information which indicates whether the transmission control protocol connection towards the target Security Edge Protection Proxy is established maybe information indicating the transmission control protocol connection is notestablished and the information may further comprise a reason of the transmissioncontrol protocol connection is not established.

[0039] The reason of the transmission control protocol connection is not establishedmay comprise at least one of: no contractual roaming agreement; peer apparatuscannot be reached due to connectivity issues; an unallowed N32 purposes; or anunallowed security protocol.

[0040] The hypertext transfer protocol connect response may indicate that the apparatus rejected the establishment of the transmission control protocol connection towards the further apparatus.

[0041] The hypertext transfer protocol connect response may contain a Server header identifying the apparatus.

[0042] The further apparatus may be one of: an originating Security Edge ProtectionProxy in an originating public land mobile network; and a consumer Security EdgeProtection Proxy in a public land mobile network; and a preceding connection linkroaming intermediary.

[0043] The information indicating the producer Security Edge Protection Proxy maycomprise at least one of the following: information identifying a succeedingconnection link roaming intermediary; information indicating a public land mobilenetwork of the producer Security Edge Protection Proxy; or information indicating apublic land mobile network of the target Security Edge Protection Proxy.

[0044] Information indicating the apparatus may comprise a Fully Qualified DomainName of the further apparatus.

[0045] The means may be further for performing at least one of: verification of thefurther apparatus at the apparatus based on a signing of the information at thefurther apparatus; or verification of the information based on a signing of theinformation at the further apparatus.

[0046] The means for performing determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the targetPublic Land Mobile Network is established based on the information may be furtherfor determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network maybe established based on at least one of: a contractual roaming agreement betweenthe roaming intermediary and the Public Land Mobile Network of the furtherapparatus; or a contractual roaming agreement between the roaming intermediaryand the target Public Land Mobile Network; or at least one of the intended purposesallowed by the contractual agreement between the roaming intermediary and thePublic Land Mobile Network of the further apparatus; or at least one of the intendedpurposes allowed by the contractual agreement between the roaming intermediary and the target Public Land Mobile Network.

[0047] According to a third aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: transmitting, to a first roaming intermediary, a hypertext transfer protocol connect request of establishing a transmission control protocol connection between the first roaming intermediary and a peer apparatus, wherein the transmission control protocol connection is used for establishing an inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary; and receiving, from the first roaming intermediary, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection towards the peer apparatus is established; wherein the hypertext transfer protocol connect requestcomprises information indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0048] Information describing the purpose of establishing the transmission controlprotocol connection may comprise information identifying the hypertext transferprotocol connect request is to be used to establish the inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary.

[0049] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying at least oneintended purpose of the inter-public-land-mobile-network signaling connection beingestablished.

[0050] The at least one intended purpose of the inter-public-land-mobile-networksignaling connection being established may be at least one of: a roaming intendedpurpose; a disaster roaming purpose; an inter-public-land-mobile-network mobilityintended purpose; or an SMS interconnection intended purpose.

[0051] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying a securityprotocol intended to be negotiated over the inter-public-land-mobile-network signaling connection.

[0052] The security protocol intended to be negotiated over the inter-public-land- mobile-network signaling connection may comprise one of: a protocol for N32interconnect security, PRINS, protocol; a security profiles for PRINS; and a transportlayer security, TLS, protocol.

[0053] Information controlling the forwarding or origination of messages by the firstroaming intermediary may comprise information of at least one policy indicatingwhether the first roaming intermediary is permitted to at least one of: accept or rejecta service request exchanged between Network Functions of the two Public LandMobile Networks; accept or reject a request from one visited Public Land Mobile Network to register an in-bound roaming user equipment to a home Public Land Mobile Network of the user equipment; deregister a user equipment; and terminatea packet data unit session.

[0054] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise a correlation identifier configured tocorrelate communication messages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile- network messages forwarding connection between the apparatus and the peer apparatus.

[0055] The header may comprise: a single header; or two or more headers, each of the two or more headers comprising one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0056] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the peer apparatus is established and may comprise information identifying at least one acceptable intended purpose of establishing the inter-public-land-mobile-network signaling communication via the first roaming intermediary.

[0057] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the peer apparatus is established and may comprise information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile-network communication via the first roaming intermediary.

[0058] Information which indicates whether the transmission control protocolconnection towards the peer apparatus is established may be information indicatingthe transmission control protocol connection is not established and the informationmay further comprise a reason of the transmission control protocol connection is notestablished.

[0059] The reason of the transmission control protocol connection is not establishedmay comprise at least one of: no contractual roaming agreement; peer apparatuscannot be reached due to connectivity issues; an unallowed N32 purpose; or anunallowed security protocol.

[0060] The hypertext transfer protocol connect response may indicate whether thefirst roaming intermediary or a further roaming intermediary rejected theestablishment of the transmission control protocol connection towards the peer apparatus.

[0061] The hypertext transfer protocol connect response may contain a Serverheader identifying the roaming intermediary which rejected the establishment of thetransmission control protocol connection towards the peer apparatus.

[0062] The apparatus may be a consumer Security Edge Protection Proxy in a publicland mobile network and the peer apparatus may be a producer Security EdgeProtection Proxy in a peer public land mobile network.

[0063] Information indicating the apparatus may comprise at least one of thefollowing: information identifying the apparatus; or information indicating a public land mobile network of the apparatus.

[0064] Information indicating the apparatus may comprise a Fully Qualified DomainName of the apparatus.

[0065] The information indicating the peer apparatus may comprise at least one of the following: information identifying the peer apparatus; or information indicating a peer public land mobile network of the peer apparatus.

[0066] The apparatus may be further caused for performing signing the information prior to transmitting, the signing the information providing at least one of: verificationof the apparatus at the first roaming intermediary; or verification of the informationat the first roaming intermediary.

[0067] The inter-public-land-mobile-network signaling connection may be used bythe apparatus and the peer apparatus to determine the security to apply for the forwarding of messages between the two Public Land Mobile Networks.

[0068] According to a fourth aspect there is provided an apparatus, the apparatusbeing a roaming intermediary, the apparatus comprising at least one processor andat least one memory storing instructions that, when executed by the at least oneprocessor, cause the apparatus at least to perform: receiving, from a furtherapparatus, a hypertext transfer protocol connect request of establishing a transmission control protocol connection towards a target Security Edge Protection Proxy of a target Public Land Mobile Network, wherein the transmission controlprotocol connection is used for establishing an inter-public-land-mobile-networksignaling connection between the target Security Edge Protection Proxy and a consumer Security Edge Protection Proxy via the apparatus, wherein the hypertext transfer protocol connect request comprises information indicating the producer Security Edge Protection Proxy, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the further apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile- network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the apparatus towards the producer Security Edge Protection Proxy or the further apparatus; and determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information; and transmitting at least one of: to the further apparatus, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection is established; or to a further roaming intermediary, a further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network for establishing the inter-public-land-mobile-network signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the apparatus and also through the further roaming intermediary.

[0069] The further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network may comprise information indicating the target Security Edge Protection Proxy, and wherein the further hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the further apparatus; information indicating the apparatus; information describing a purpose of establishing the transmission controlprotocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by thefurther roaming intermediary towards the target Security Edge Protection Proxy orthe consumer Security Edge Protection Proxy.

[0070] Information describing the purpose of establishing the transmission controlprotocol connection may comprise information identifying the hypertext transfer protocol connect request is to be used to establish a signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the roaming intermediary.

[0071] The information describing the inter-public-land-mobile-network signaling connection being established may comprise information identifying at least oneintended purpose of the inter-public-land-mobile-network signaling connection beingestablished.

[0072] The at least one intended purpose of the inter-public-land-mobile-networksignaling connection being established may be at least one of: a roaming intendedpurpose; a disaster roaming purpose; an inter-public-land-mobile-network mobilityintended purpose; or an SMS interconnection intended purpose.

[0073] The information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying a securityprotocol intended to be negotiated over the inter-public-land-mobile-network signaling connection.

[0074] The security protocol intended to be negotiated over the inter-public-land- mobile-network signaling connection may comprise one of: a protocol for N32interconnect security, PRINS, protocol; a security profiles for PRINS; and a transportlayer security, TLS, protocol.

[0075] Information controlling the forwarding or origination of messages by theroaming intermediary may comprise information of at least one policy indicatingwhether the roaming intermediary is permitted to at least one of: accept or reject aservice request exchanged between Network Functions of the two Public Land Mobile Networks; accept or reject a request from one visited Public Land Mobile Network to register an in-bound roaming user equipment to a home Public LandMobile Network of the user equipment; deregister a user equipment; and terminate a packet data unit session.

[0076] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise a correlation identifier configured tocorrelate communication messages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile- network messages forwarding connection between the consumer Security Edge Protection Proxy and the target Security Edge Protection Proxy.

[0077] The header may comprise: a single header; or two or more headers, each of the two or more headers comprising one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0078] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the target Security Edge Protection Proxy is established and may comprise information identifying at least one acceptable intended purpose of establishing the inter-public-land-mobile- network signaling communication via the roaming intermediary.

[0079] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the target Security Edge Protection Proxy is established and may comprise information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile- network communication via the roaming intermediary.

[0080] The information which indicates whether the transmission control protocol connection towards the target Security Edge Protection Proxy is established maybe information indicating the transmission control protocol connection is notestablished and the information may further comprise a reason of the transmissioncontrol protocol connection is not established.

[0081] The reason of the transmission control protocol connection is not establishedmay comprise at least one of: no contractual roaming agreement; peer apparatuscannot be reached due to connectivity issues; an unallowed N32 purposes; or anunallowed security protocol.

[0082] The hypertext transfer protocol connect response may indicate that the apparatus rejected the establishment of the transmission control protocol connection towards the further apparatus.

[0083] The hypertext transfer protocol connect response may contain a Server header identifying the apparatus.

[0084] The further apparatus may be one of: an originating Security Edge ProtectionProxy in an originating public land mobile network; and a consumer Security EdgeProtection Proxy in a public land mobile network; and a preceding connection link roaming intermediary.

[0085] The information indicating the producer Security Edge Protection Proxy maycomprise at least one of the following: information identifying a succeeding connection link roaming intermediary; information indicating a public land mobile network of the producer Security Edge Protection Proxy; or information indicating a public land mobile network of the target Security Edge Protection Proxy.

[0086] Information indicating the apparatus may comprise a Fully Qualified DomainName of the further apparatus.

[0087] The apparatus may be further caused to perform at least one of: verificationof the further apparatus at the apparatus based on a signing of the information atthe further apparatus; or verification of the information based on a signing of theinformation at the further apparatus.

[0088] The apparatus caused to perform determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information may befurther caused to perform determining whether the transmission control protocolconnection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network may be established based on at least one of: a contractualroaming agreement between the roaming intermediary and the Public Land MobileNetwork of the further apparatus; or a contractual roaming agreement between theroaming intermediary and the target Public Land Mobile Network; or at least one ofthe intended purposes allowed by the contractual agreement between the roamingintermediary and the Public Land Mobile Network of the further apparatus; or at leastone of the intended purposes allowed by the contractual agreement between theroaming intermediary and the target Public Land Mobile Network.

[0089] According to a fifth aspect, there is provided a method for an apparatus, the method comprising: transmitting, to a first roaming intermediary, a hypertext transfer protocol connect request of establishing a transmission control protocol connection between the first roaming intermediary and a peer apparatus, wherein the transmission control protocol connection is used for establishing an inter-public- land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary; and receiving, from the first roaming intermediary, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection towards the peer apparatus is established; wherein the hypertext transfer protocol connect request comprises information indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controllingforwarding or origination of messages by the first roaming intermediary towards theapparatus or the peer apparatus.

[0090] Information describing the purpose of establishing the transmission controlprotocol connection may comprise information identifying the hypertext transferprotocol connect request is to be used to establish the inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary.

[0091] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying at least oneintended purpose of the inter-public-land-mobile-network signaling connection beingestablished.

[0092] The at least one intended purpose of the inter-public-land-mobile-networksignaling connection being established may be at least one of: a roaming intendedpurpose; a disaster roaming purpose; an inter-public-land-mobile-network mobilityintended purpose; or an SMS interconnection intended purpose.

[0093] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying a securityprotocol intended to be negotiated over the inter-public-land-mobile-network signaling connection.

[0094] The security protocol intended to be negotiated over the inter-public-land- mobile-network signaling connection may comprise one of: a protocol for N32interconnect security, PRINS, protocol; a security profiles for PRINS; and a transportlayer security, TLS, protocol.

[0095] Information controlling the forwarding or origination of messages by the firstroaming intermediary may comprise information of at least one policy indicatingwhether the first roaming intermediary is permitted to at least one of: accept or rejecta service request exchanged between Network Functions of the two Public Land Mobile Networks; accept or reject a request from one visited Public Land Mobile Network to register an in-bound roaming user equipment to a home Public Land Mobile Network of the user equipment; deregister a user equipment; and terminate a packet data unit session.

[0096] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise a correlation identifier configured tocorrelate communication messages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile- network messages forwarding connection between the apparatus and the peer apparatus.

[0097] The header may comprise: a single header; or two or more headers, each of the two or more headers comprising one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0098] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the peer apparatus is established and may comprise information identifying at least one acceptable intended purposeof establishing the inter-public-land-mobile-network signaling communication via the first roaming intermediary.

[0099] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the peer apparatus is established and may comprise information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile-network communication via the first roaming intermediary.

[0100] Information which indicates whether the transmission control protocolconnection towards the peer apparatus is established may be information indicatingthe transmission control protocol connection is not established and the informationmay further comprise a reason of the transmission control protocol connection is notestablished.

[0101] The reason of the transmission control protocol connection is not establishedmay comprise at least one of: no contractual roaming agreement; peer apparatuscannot be reached due to connectivity issues; an unallowed N32 purpose; or anunallowed security protocol.

[0102] The hypertext transfer protocol connect response may indicate whether thefirst roaming intermediary or a further roaming intermediary rejected theestablishment of the transmission control protocol connection towards the peer apparatus.

[0103] The hypertext transfer protocol connect response may contain a Serverheader identifying the roaming intermediary which rejected the establishment of thetransmission control protocol connection towards the peer apparatus.

[0104] The apparatus may be a consumer Security Edge Protection Proxy in a publicland mobile network and the peer apparatus may be a producer Security EdgeProtection Proxy in a peer public land mobile network.

[0105] Information indicating the apparatus may comprise at least one of thefollowing: information identifying the apparatus; or information indicating a public land mobile network of the apparatus.

[0106] Information indicating the apparatus may comprise a Fully Qualified DomainName of the apparatus.

[0107] The information indicating the peer apparatus may comprise at least one of the following: information identifying the peer apparatus; or information indicating a peer public land mobile network of the peer apparatus.

[0108] The method may further comprise signing the information prior totransmitting, the signing the information providing at least one of: verification of theapparatus at the first roaming intermediary; or verification of the information at thefirst roaming intermediary.

[0109] The inter-public-land-mobile-network signaling connection may be used bythe apparatus and the peer apparatus to determine the security to apply for the forwarding of messages between the two Public Land Mobile Networks.

[0110] According to a there is provided according to a sixth aspect a method for anapparatus, the apparatus being a roaming intermediary, the method comprising:receiving, from a further apparatus, a hypertext transfer protocol connect request of establishing a transmission control protocol connection towards a target Security Edge Protection Proxy of a target Public Land Mobile Network, wherein the transmission control protocol connection is used for establishing an inter-public- land-mobile-network signaling connection between the target Security Edge Protection Proxy and a consumer Security Edge Protection Proxy via the apparatus, wherein the hypertext transfer protocol connect request comprises information indicating the producer Security Edge Protection Proxy, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of:information indicating the further apparatus; information describing a purpose ofestablishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the apparatus towards the producer Security Edge Protection Proxy or the further apparatus; and determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information; and transmitting at least one of: to the further apparatus, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection is established; or to a further roaming intermediary, a further hypertext transfer protocol connect request of establishing afurther transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network for establishing the inter- public-land-mobile-network signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the apparatus and also through the further roaming intermediary.

[0111] The further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network may comprise information indicating the target Security Edge Protection Proxy, and wherein the further hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the further apparatus; information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-networksignaling connection being established by using the transmission control protocolconnection; or information controlling forwarding or origination of messages by thefurther roaming intermediary towards the target Security Edge Protection Proxy orthe consumer Security Edge Protection Proxy.

[0112] Information describing the purpose of establishing the transmission controlprotocol connection may comprise information identifying the hypertext transfer protocol connect request is to be used to establish a signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the roaming intermediary.

[0113] The information describing the inter-public-land-mobile-network signaling connection being established may comprise information identifying at least oneintended purpose of the inter-public-land-mobile-network signaling connection beingestablished.

[0114] The at least one intended purpose of the inter-public-land-mobile-networksignaling connection being established may be at least one of: a roaming intendedpurpose; a disaster roaming purpose; an inter-public-land-mobile-network mobilityintended purpose; or an SMS interconnection intended purpose.

[0115] The information describing the inter-public-land-mobile-network signalingconnection being established may comprise information identifying a securityprotocol intended to be negotiated over the inter-public-land-mobile-network signaling connection.

[0116] The security protocol intended to be negotiated over the inter-public-land- mobile-network signaling connection may comprise one of: a protocol for N32interconnect security, PRINS, protocol; a security profiles for PRINS; and a transportlayer security, TLS, protocol.

[0117] Information controlling the forwarding or origination of messages by theroaming intermediary may comprise information of at least one policy indicatingwhether the roaming intermediary is permitted to at least one of: accept or reject aservice request exchanged between Network Functions of the two Public Land Mobile Networks; accept or reject a request from one visited Public Land Mobile Network to register an in-bound roaming user equipment to a home Public Land Mobile Network of the user equipment; deregister a user equipment; and terminatea packet data unit session.

[0118] Information describing the inter-public-land-mobile-network signalingconnection being established may comprise a correlation identifier configured tocorrelate communication messages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile- network messages forwarding connection between the consumer Security Edge Protection Proxy and the target Security Edge Protection Proxy.

[0119] The header may comprise: a single header; or two or more headers, each of the two or more headers comprising one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0120] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the target Security Edge Protection Proxy is established and may comprise information identifying at least one acceptable intended purpose of establishing the inter-public-land-mobile- network signaling communication via the roaming intermediary.

[0121] The hypertext transfer protocol connect response may indicate that the transmission control protocol connection towards the target Security Edge Protection Proxy is established and may comprise information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile- network communication via the roaming intermediary.

[0122] The information which indicates whether the transmission control protocol connection towards the target Security Edge Protection Proxy is established maybe information indicating the transmission control protocol connection is notestablished and the information may further comprise a reason of the transmissioncontrol protocol connection is not established.

[0123] The reason of the transmission control protocol connection is not establishedmay comprise at least one of: no contractual roaming agreement; peer apparatuscannot be reached due to connectivity issues; an unallowed N32 purposes; or anunallowed security protocol.

[0124] The hypertext transfer protocol connect response may indicate that the apparatus rejected the establishment of the transmission control protocol connection towards the further apparatus.

[0125] The hypertext transfer protocol connect response may contain a Server header identifying the apparatus.

[0126] The further apparatus may be one of: an originating Security Edge Protection Proxy in a originating public land mobile network; and a consumer Security Edge Protection Proxy in a public land mobile network; and a preceding connection link roaming intermediary.

[0127] The information indicating the producer Security Edge Protection Proxy maycomprise at least one of the following: information identifying a succeeding connection link roaming intermediary; information indicating a public land mobile network of the producer Security Edge Protection Proxy; or information indicating a public land mobile network of the target Security Edge Protection Proxy.

[0128] Information indicating the apparatus may comprise a Fully Qualified DomainName of the further apparatus.

[0129] The method may further comprise at least one of: verification of the furtherapparatus at the apparatus based on a signing of the information at the furtherapparatus; or verification of the information based on a signing of the information atthe further apparatus.

[0130] The method may further comprise determining whether the transmissioncontrol protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information may befurther caused to perform determining whether the transmission control protocolconnection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network may be established based on at least one of: a contractualroaming agreement between the roaming intermediary and the Public Land MobileNetwork of the further apparatus; or a contractual roaming agreement between theroaming intermediary and the target Public Land Mobile Network; or at least one ofthe intended purposes allowed by the contractual agreement between the roamingintermediary and the Public Land Mobile Network of the further apparatus; or at leastone of the intended purposes allowed by the contractual agreement between theroaming intermediary and the target Public Land Mobile Network.

[0131] According to a seventh aspect, there is provided a computer readablemedium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: transmitting, to a first roaming intermediary, a hypertext transfer protocol connect request of establishing a transmission control protocol connection between the first roaming intermediary and a peer apparatus, wherein the transmission control protocol connection is used for establishing an inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary; and receiving, from the first roaming intermediary, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection towards the peer apparatus is established; wherein the hypertext transfer protocol connect request comprises information indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection;or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0132] According to an eighth aspect, there is provided a computer readablemedium comprising instructions which, when executed by an apparatus, the apparatus being a roaming intermediary, cause the apparatus to perform at leastthe following: receiving, from a further apparatus, a hypertext transfer protocolconnect request of establishing a transmission control protocol connection towards a target Security Edge Protection Proxy of a target Public Land Mobile Network, wherein the transmission control protocol connection is used for establishing an inter-public-land-mobile-network signaling connection between the target Security Edge Protection Proxy and a consumer Security Edge Protection Proxy via the apparatus, wherein the hypertext transfer protocol connect request comprises information indicating the producer Security Edge Protection Proxy, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the further apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the apparatus towards the producer Security Edge Protection Proxy or the further apparatus; and determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information; and transmitting at least one of: to the further apparatus, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection is established; or to a further roaming intermediary, a further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network for establishing the inter-public-land-mobile-network signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the apparatus and also through the further roaming intermediary.

[0133] In all of the above aspects, the apparatus of user equipment may be causedto provide to the apparatus of the network access node at least one of the first time duration, second time duration, or third time duration. Alternatively or in addition, at least one of the first time duration, or third time duration may be configured by a communication standard.

[0134] According to an aspect, there is an apparatus comprising: circuitry configuredto perform: transmitting, to a first roaming intermediary, a hypertext transfer protocolconnect request of establishing a transmission control protocol connection between the first roaming intermediary and a peer apparatus, wherein the transmission control protocol connection is used for establishing an inter-public-land-mobile- network signaling connection between the apparatus and the peer apparatus via the first roaming intermediary; and receiving, from the first roaming intermediary, a hypertext transfer protocol connect response comprising response informationwhich indicates whether the transmission control protocol connection towards thepeer apparatus is established; wherein the hypertext transfer protocol connect request comprises information indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus.

[0135] According to an aspect, there is an apparatus comprising: circuitry configuredto perform: receiving, from a further apparatus, a hypertext transfer protocol connectrequest of establishing a transmission control protocol connection towards a target Security Edge Protection Proxy of a target Public Land Mobile Network, wherein the transmission control protocol connection is used for establishing an inter-public- land-mobile-network signaling connection between the target Security Edge Protection Proxy and a consumer Security Edge Protection Proxy via the apparatus, wherein the hypertext transfer protocol connect request comprises information indicating the producer Security Edge Protection Proxy, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of:information indicating the further apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the apparatus towards the producer Security Edge Protection Proxy or the further apparatus; and determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information; and transmitting at least one of: to the further apparatus, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection is established; or to a further roaming intermediary, a further hypertext transfer protocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network for establishing the inter- public-land-mobile-network signaling connection between the target Security Edge Protection Proxy and the consumer Security Edge Protection Proxy via the apparatus and also through the further roaming intermediary.

[0136] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.

[0137] In the above, many different embodiments have been described. It should beappreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above. DESCRIPTION OF FIGURES

[0138] Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which:

[0139] Fig.1 shows a representation of an inter-network communications systemaccording to some example embodiments;

[0140] Fig.2 shows a signal flow diagram representation of an example, successful,single roaming-intermediary implementation for establishing a N32-c connectionaccording to some embodiments;

[0141] Fig.3 shows a signal flow diagram representation of an example, successful,multiple roaming-intermediary implementation for establishing a N32-c connectionaccording to some embodiments;

[0142] Fig. 4 shows a signal flow diagram representation of an example, failed,single roaming-intermediary implementation for establishing a N32-c connectionaccording to some embodiments;

[0143] Fig. 5 shows a signal flow diagram representation of an example, failed,multiple roaming-intermediary implementation for establishing a N32-c connectionaccording to some embodiments;

[0144] Fig. 6 shows a representation of an example control apparatus suitable forimplementing some embodiments;

[0145] Fig 7a shows a flow diagram of the operation of an example consumer Security Edge Protection Proxy in a public land mobile network according to some embodiments; and

[0146] Fig. 7b shows a flow diagram of the operation of an example originatingSecurity Edge Protection Proxy in an originating public land mobile network or aconsumer Security Edge Protection Proxy in a public land mobile network or a preceding connection link roaming intermediary according to some embodiments. DETAILED DESCRIPTION

[0147] The following relates to apparatus, methods and computer programs for establishing an inter-public-land-mobile-network signaling connection, for example between 5G or NR networks. In the following certain embodiments are explainedwith reference to wireless cellular systems and mobile communication systemsserving such mobile communication devices. Before explaining in detail the exemplifying embodiments, certain general principles of establishing an inter-public- land-mobile-network signaling connection are briefly explained with reference to Fig. 1 to assist in understanding the technology underlying the described examples. It is understood that the following description is not limited to 5G systems and may be expanded to later developed systems (e.g., 6G and beyond).

[0148] Fig. 1 shows a schematic representation of two public-land-mobile-networksrepresented by 5G systems (5GS) 100 and 102 and the internetwork interconnectimplemented by one or more roaming intermediary (RI).

[0149] The 5GS 100, 102 may, though not explicitly shown in Fig.1, be comprisedby a terminal or user equipment (UE), a 5G radio access network (5G-RAN) or next generation radio access network (NG-RAN), a 5G core network (5GC), one or moreapplication functions (Afs) and one or more data networks (DN).

[0150] The 5GC may comprise the following (network function) entities: Network Slice Selection Function (NSSF); Network Exposure Function; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM); Application Function (AF); Authentication Server Function (AUSF); Access and Mobility Management Function (AMF); and Session Management Function (SMF).

[0151] The 5G-RAN may provide at least one area of coverage to the terminal. This area of coverage is referred to as a cell.

[0152] The internetwork interconnect allows secure communication between a service-consuming network function (cNF) 101 and a service-producing networkfunction (pNF) 161 located in the different PLMNs (5GS 100, 102 respectively).

[0153] Security can be enabled by a Security Edge Protection Proxy (SEPP) in bothnetworks. Thus, for example, FIG. 1 shows a service-consuming PLMN SEPP, c-SEPP 111, located at the edge of the first 5GS 100 and a service-producing PLMNSEPP, p-SEPP 151, located at the edge of the second 5GS 102. The SEPPs 111and 151 are configured to enforce protection policies regarding application layer security thereby ensuring integrity and confidentiality protection for those elements to be protected.

[0154] In addition, there can comprise one or more interconnect providers, orroaming intermediary (RI) between c-SEPP 111 and p-SEPP 151. The termRoaming Intermediary (RI) refers to “An entity that provides roaming relatedservices” (see 3GPP TS 33.501). This may refer, e.g., to a Roaming Hub, a RVAS(Roaming Value Added Service server), or an IPX.

[0155] In some embodiments, the interconnect providers are associated with orhave specific business or access relationships with the operators of the variousPLMNs. For example, an operation of the c-SEPP can have a business relationshipwith a first roaming intermediary (RI-A 131), while the p-SEPP’s operator can havea business relationship with a second roaming intermediary (RI-B 141). Theinterconnect providers can further have suitable access or business relationships.

[0156] Although Fig.1 shows two roaming intermediaries (RI-A 131, RI-B 141) it would be appreciated that the interconnect can employ a single roamingintermediary or more than two roaming intermediaries implementing theinterconnection. In the following examples they can be assumed to be transparent and simply forward the communication.

[0157] In some embodiments, the SEPPs 111 and 151 can employ JSON WebEncryption (JWE, specified in RFC 7516) for protecting messages on the N32 interface, and the IPX providers use JSON Web Signatures (JWS, specified in RFC 7515) for signing their modifications needed for their mediation services.

[0158] For example, consider the case where a cNF 101 sends a message to a pNF161. If this communication is across PLMN operators over the N32 interface, as shown in Fig.1, the c-SEPP 111 receives the message and applies a symmetric key based application layer protection, for example in a manner similar to thatdefined in clause 13.2 of TS 33.501. The resulting JWE object is forwarded to theroaming intermediaries 131, 141. In other words, the object is communicated via aseries of N32-c connections from the c-SEPP 111 to the RI-A 131 via a first N32-cconnection 122, from the RI-A 131 to the RI-B 141 via a second N32-c connection123 and from the RI-B 141 to the p-SEPP 151 via a third N32-c connection 124.

[0159] Additionally, as shown in Fig. 1, the N32-c connections 122, 123, and 124can be employed to negotiate the N32-f 125 specific associated security configuration parameters requested to enforce Application Layer Security on HTTP messages exchanged between the SEPPs 141, 151.

[0160] In other words two security solutions have been defined by 3GPP (asindicated in TS 33.501) for protecting inter-PLMN signaling between the PLMNs. The first is Application layer security (which is known as Protocol for N32Interconnect Security- PRINS). The second of which is the end-to-end (e2e)transport layer security (TLS) security.

[0161] The N32 interface furthermore, as shown by Fig.1 consists of:

[0162] N32-c 122, 123, 124 connection, for management of the N32 interface (e.g. negotiation of the security solution to apply for protecting the inter-PLMN signaling over N32-f), and

[0163] N32-f 125 connection, for sending of JWE and JWS protected messages (when using PRINS security) or e2e TLS protected messages (when using TLS security) between the SEPPs (when using PRINS security).

[0164] The establishment of the one or more N32-c connections at the roamingintermediaries (RIs) is a field currently being researched. Specifically and asdiscussed in further detail herein is the ability for RIs to be enhanced to enable,among other aspects, to accept or reject the establishment of N32-c connectionsbetween SEPPs.

[0165] A N32-connection establishment procedure can employ a Hypertext Transfer Protocol (HTTP) CONNECT method to establish a transport control protocol (TCP)connection between the SEPPs via the one or more roaming Intermediaries. TheHTTP Connect method for example is described in IETF RFC 9110, where the CONNECT method requests that the recipient establishes a tunnel to the destination origin server identified by the request target, and if successful restrict its behaviour to blind forwarding of data in both directions until the tunnel is closed. The tunnel can be used to create the end-to-end virtual connection through one or more proxies (the RIs) which can then be secured using TLS as indicated above.

[0166] Additionally in a manner similar to IETF RFC 9113, the embodiments can be configured to specify that the CONNECT method can be used with the RIs configured to support an establish a TCP connection to the host and the port identified in the “authority” pseudo-header field. Once the connection is successfully established, the RI can be configured to send a HEADERS frame containing a 2xx- series status code to the client or sender of the request.

[0167] Furthermore, following the initial HEADERS frame sent by each peerestablishing the connection, all subsequent DATA frames correspond to data sent on the TCP connection. The frame payload of any DATA frame sent by the client, such as the c-SEPP, is transmitted by the RI onwards to the p-SEPP, similarly data sent by the p-SEPP to the RI can be transmitted onwards to the c-SEPP.

[0168] The embodiments as described herein define how the RIs determine whetherto allow or disallow a N32-c connection establishment, and which information(beyond the identity of source and target PLMNs) should be exchanged betweenthe SEPP and the RI for the above determination.

[0169] Additionally in some embodiments the connection establishment can beextended for other purposes, such as troubleshooting and / or for controlling the N32-f message forwarding / origination by the RI.

[0170] The HTTP connect method is a hop-by-hop method. The client (c-SEPP 111)requests an HTTP Proxy (RI-A 131) server to establish a TCP connection / tunnel tothe desired destination (p-SEPP 151). The RI-A 131 (operating as a HTTP proxyserver) then proceeds to make the connection on behalf of the C-SEPP 111(operating as the client). Once the connection has been established by the RI-A131, the RI-A 131 continues to proxy the TCP stream to and from the client.

[0171] Hence, the RI, such as RI-A 131 or RI-B 141 can be configured to determinewhether or not it agrees with establishment of the communication between the 2SEPPs and therefore can be provided with the ability to terminate a N32-cestablishment process. (Note, once TLS is established, the RI cannot see, what is negotiated among the SEPPs in N32-c).

[0172] The embodiments, as discussed herein, provides additional information within the HTTP CONNECT request / response messages in preparation of the N32- c connection establishment, from the SEPP to the RI, vice versa or between two RIs.

[0173] This additional information can be used by the RI to determine whether to allow or disallow the establishment of the N32-c connection. Also as discussedabove the information can be employed in trouble-shooting and and / or for controllingthe N32-f message forwarding / origination by the RI.

[0174] Furthermore, in some embodiments, to assure that no unauthorizedmodification of the information happens, the information can be signed and verifiedduring the HTTP connect setup.

[0175] In some embodiments the RI can be configured to generate and transmit (orforward) to the origin of the request (the c-SEPP) error messages comprisinginformation identifying the reason for the rejection or disallowed establishment ofthe connection. The error message information can therefore be employed by the c-SEPP 111 to determine whether to re-attempt an establishment of the connection, or to attempt an establishment of the connection via a different RI or for which reason not to use the same RI anymore.

[0176] Therefore, in summary, the embodiments propose additional information tobe included in HTTP CONNECT request / response messages for the establishment of connections such as the N32-c connection establishment procedure.

[0177] This additional information can be, for example, from a c-SEPP 111 to a RI-A 131, in the HTTP CONNECT request, for at least one of: enabling RI-A to(dis)allow the establishment the N32-c connection between SEPPs, debugging & trouble-shooting, or controlling the N32-f message forwarding / origination by RI.

[0178] The additional information, furthermore, from a RI-A 131 to a c-SEPP 111,can be in the HTTP CONNECT response.

[0179] The additional information can be exchanged from RI-A 131 to RI-B 141 andvice-versa (in examples where there are two or more RIs between the SEPPs).

[0180] The additional information in the HTTP CONNECT request can comprise atleast one of: -an indication that the HTTP CONNECT request message is used to setupa N32-c connection; -the target PLMN ID or SNPN ID or some suitable identifier configured toidentify the target network; or- the source PLMN ID and / or SNPN ID or some suitable identifierconfigured to identify the source network.

[0181] In some embodiments the identifier can be signalled elsewise.

[0182] The additional information in the HTTP CONNECT request message can furthermore comprise an intended N32 purpose(s) of the N32 connection. Thisinformation can be employed by the RI in determining whether to allow theestablishment of an N32-c connection between 2 PLMNs / SNPNs for specific ordefined N32 purposes only. For example, the RI can be configured to allow aconnection to be established based on whether the information intended purpose isat least one of: a roaming intended purpose; a disaster roaming purpose; an inter-public-land-mobile-network mobility intended purpose; or an SMS interconnectionintended purpose. For example, the request can be accepted when the intendedpurpose is for disaster roaming between 2 PLMNs without other roamingagreements.

[0183] Additional information in the HTTP CONNECT request message can be the requested N32-f security solution (in other words whether the N32-f security solution if either PRINS or TLS; and if PRINS optionally the intended PRINS security profile).For example, if the SEPP’s intention is to use the contracted RI for only proxying (IPlevel routing) with TLS, or if the RI may have the option to modify or include owninformation. The intention of continuing for N32-f with TLS or PRINS or whichsecurity profile, may influence the decision or determination at the RI whether or notto establish N32-c. In other words, the RI may determine to establish the inter-public-land-mobile-network signaling connection based on whether the requestedsecurity solution is implemented at the RI or not.

[0184] The HTTP CONNECT request message additional information can be the c-SEPP’s FQDN identifying the source SEPP. For example, this information can beuseful for debugging or trouble-shooting purposes should the connectionestablishment fail or the connection fail at some future point.

[0185] Additional information in the HTTP CONNECT request message can be c-SEPP policies regarding N32-f message origination by the RI. For example, theadditional information can indicate whether the RI is allowed to reject a registrationrequest, to deregister a UE, to terminate PDU sessions.

[0186] The additional information in the HTTP CONNECT request message can furthermore comprise N32 correlation ID (N32 handshake ID) that the SEPPs isconfigured to employ at a later point to correlate N32-c and N32-f. This informationcan for example be helpful for providing error information back to the SEPP. In some embodiments if different correlation IDs are used in N32-f messages for different directions, passing the N32 correlation ID in the HTTP CONNECT request can only be used for enabling correlation on the N32-f interface with N32-c connections forthe initiating direction (for example c-SEPP initiating the requestp-SEPPreceiving the request).

[0187] In some embodiments since the HTTP CONNECT request message cannotencode contents (i.e., a payload body), the additional information is encoded in theHTTP headers. This can be either within a custom header definition or by using the3GPP defined header where one or more field in the defined header repurposedwith the additional information.

[0188] In other words, the information may be incorporated within a new HTTPheader or to existing 3GPP custom HTTP header that has not been previously usedin the context of an N32-c connection establishment. For example, the informationcan be incorporated within the fields 3gpp-Sbi-Originating-Network-Id, 3gpp-Sbi-Interplmn-Purpose, 3gpp-Sbi-NF-Peer-Info.

[0189] An example of this can be shown in the following: Example 1: CONNECT sepp.5gc.mnc203.mcc422.3gppnetwork.org:443 3gpp-Sbi-Connect-Info: connect-purpose=N32C; security=PRINS; n32- correlation-id=0600AD1855BD6007 3gpp-Sbi-Originating-Network-Id: 123-45 3gpp-Sbi-Interplmn-Purpose: ROAMING 3gpp-Sbi-NF-Peer-Info: srcsepp=sepp12.5gc.mnc155.mcc400.3gppnetwork; dstri=ri3.operator.com 3gpp-Sbi-RI-Policies: allow=REJECT_UE_REGISTRATION, DEREGISTER_UE; disallow=TERMINATE_PDU_SESSION

[0190] In this example the information in the line 3gpp-Sbi-Connect-Info: connect-purpose=N32C; security=PRINS; n32-correlation-id=0600AD1855BD6007 definesthe connection is a N32C and that the security policy to be used is PRINS and further defines a correlation identifier.

[0191] Additionally a connection purpose is defined in the information ROAMINGby 3gpp-Sbi-Interplmn-Purpose: ROAMING.

[0192] The allowed and disallowed policies for the RI are furthermore defined in theinformation from line 3gpp-Sbi-RI-Policies: allow=REJECT_UE_REGISTRATION,DEREGISTER_UE; disallow=TERMINATE_PDU_SESSION.

[0193] A second example is as followsExample 2: CONNECT sepp.5gc.mnc203.mcc422.3gppnetwork.org:443 3gpp-Sbi-Connect-Info: connect-purpose=N32C; security=PRINS; n32- correlation-id=0600AD1855BD6007; originating-Network-Id: 123-45; N32- purpose: ROAMING; srcsepp=sepp12.5gc.mnc155.mcc400.3gppnetwork;policies-allow=REJECT_UE_REGISTRATION, DEREGISTER_UE; policies- disallow=TERMINATE_PDU_SESSION

[0194] In the above examples: sepp.5gc.mnc203.mcc422.3gppnetwork.orgrepresents the FQDN of the p-SEPP andsepp12.5gc.mnc155.mcc400.3gppnetwork represents the FQDN of the c-SEPP.

[0195] Upon receipt of the HTTP CONNECT request from c-SEPP, the RI is configured to determine whether the transmission control protocol connection (N32- c) establishment towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on the information.

[0196] In other words, the determination of whether to establish the connection(towards the p-SEPP 151) can be based on the source PLMN ID or SNPN-ID or thetarget PLMN ID or SNPN ID. This determination can be similar to known mechanisms for determining whether to establish a connection based on the source or target PLMNs.

[0197] Furthermore, the determination whether to establish the connection can bebased on the operator / network identity of the previous hop’s RI based on knownsignalling of RHUB ID (from RI-A 131 to RI-B 141).

[0198] As discussed earlier the determination at the RI whether to establish theconnection can be based on the HTTP CONNECT purpose. For example, an RI canbe configured to only accept an HTTP CONNECT request for the purpose of establishing a N32-c connection.

[0199] Furthermore, in some embodiments the determination at the RI is configuredto establish whether the requested N32-f security solution matches a solutionaccepted by the RI. For example, a RI determination can be configured to onlyaccept the HTTP CONNECT request if the request is for setting up PRINS security over N32-f.

[0200] Also, in some embodiments, the determination at the RI whether to establishthe connection can be based on the N32 intended purpose. Thus, for example, the RI is configured to accept only requests between two PLMNs for one or more specific or defined intended purposes, such as Disaster Roaming.

[0201] In some embodiments, systems with multiple RIs between the c-SEPP andp-SEPP can be configured to, based on determining that the connection is to beestablished, to propagate part of, or all the additional information received in theHTTP CONNECT request in a further HTTP CONNECT request sent towards thesecond or further RI (RI-B 141). Additionally, in some embodiments, the first RI (RI-A 131) is configured to add their own RI operator / network ID in the HTTP CONNECTrequest forwarded to the second or further RI.

[0202] In some embodiments, the RI determination can be configured to use theadditional information received in the HTTP CONNECT for trouble-shooting orresponding to a suitable request.

[0203] For example, the RI can, in some embodiments, generate a suitableresponse to the SEPP (or an earlier RI in the chain) and within the response provideinformation suitable for assisting the establishment or trouble-shooting of theattempt for establishment.

[0204] For example, the information can be within a HTTP CONNECT response inthe manner discussed as follows.

[0205] When / if the response indicates a successful determination for theestablishment of a connection between the SEPPs then the response can be an ‘200 OK’ response.

[0206] The ‘200 OK’ response can further comprise information which identifies allowed N32 purposes for the N32 connection. These allowed N32 purposes can be a subset of the N32 purposes signaled to the RI in the request. This information can then be used by the SEPP (or earlier or preceding RI in the chain) to identify whether to send any future requests to the RI and thus prevent the SEPP (or earlier RI)sending a request to the specific RI for a connection purpose that would not beallowed.

[0207] The ‘200 OK’ response can further comprise information which identifies allowed N32-f security solutions. These allowed N32-f security solutions can beused by the SEPP to enforce a specific security solution. For example, when therequest indicated both TLS and PRINS are acceptable but the RI wants to enforcea specific security solution, such as PRINS then the SEPP can be configured toemploy the N32-f security solution indicated by the information in the response.

[0208] In some embodiments the information can specify other aspects associatedwith the security solution. For example, the RI can specify that it requires PRINSsecurity, and further may provide a security profile indicating which informationelements (IEs) shall be encrypted, which IEs need to be available in the clear, suchthat the RI can operate between the SEPPs.

[0209] The ‘200 OK’ response can further comprise information which identifies thep-SEPP FQDN. Thus, even when the RI has overwritten the p-SEPP FQDN with atarget MNO’s specific p-SEPP FQDN (based on local configuration at the RI and / orcontractual agreements between the RI and the target MNO), this information canbe used in future trouble-shooting or debugging.

[0210] The information in the ‘200 OK’ response can further comprise an indication of whether the same HTTP connection between c-SEPP and RI may be used by the c-SEPP for establishing other tunnels for other N32-c connections. In other words the information can indicate whether a c-SEPP may initiate new HTTP CONNECTrequests on the HTTP connection (using different HTTP / 2 stream identifiers), to setup TCP tunnels towards the same or different SEPPs.

[0211] In an unsuccessful determination for the establishment of a connectionbetween the SEPPs then the response can be an ‘4xx / 5xx’ response. The ‘4xx / 5xx’response can further comprise information identifying the reason for the unsuccessful determination. This information can be incorporating in “newapplication errors”, for example, “Roaming not allowed for the requested N32purposes”, or alternatively, a generic “HTTP CONNECT rejected” response cancomprise one or more additional parameters indicating which parameters of the HTTP CONNECT caused the failure.

[0212] In some embodiments, in order to assure that no modification of theinformation has occurred between the c-SEPP and RI, the information can be signedby the initiating SEPP and then the RI is configured to verify the signature.

[0213] This is useful in examples when no secure channel is established between the c-SEPP and RI prior to the sending of the HTTP CONNECT request message. To assure that the RI can prove the sender origin and that the message is integrity protected, this enhancement can be used.

[0214] Therefore, in some embodiments, upon / after receiving of the HTTPCONNECT response, the c-SEPP is configured to employ the response informationreceived in the response. For example, to limit the N32 purposes or the securitysolutions and / or profiles the c-SEPP may negotiate with the peer SEPP during the N32-c handshake service requests.

[0215] If the 200 OK response includes the p-SEPP FQDN, the c-SEPP can beconfigured to establish the N32-c TLS connection and for send a N32-c service request (instead of using a known p-SEPP FQDN).

[0216] In such embodiments there is no need for the p-SEPP TLS certificate tocontain an SAN entry containing the well-known p-SEPP FQDN.

[0217] If an error response was received, the c-SEPP logs the error and may restartthe full procedure considering the received error information to avoid the error to occur again.

[0218] Further example HTTP custom headers, according to some embodiments can be as follows.

[0219] 3gpp-Connect-Req-Info

[0220] The header enables to convey information in the HTTP CONNECT request to the Roaming Intermediary, that may be used by the Roaming Intermediary to determine whether to allow the establishment of the N32-c connection and / or for trouble-shooting.

[0221] The encoding of the header follows the ABNF as defined in IETF RFC 9110. Connect-Info-Req-Header = "3gpp-Connect-Req-Info:" OWS "connect-purpose:" OWS connect-purpose-value ";" OWS orig-network-id ";" OWS sender-fqdnOWS intended- n32-purposes] *( ";" OWS req-param ) connect-purpose-value = "n32c" / token orig-network-id = "originating-network-id:" OWS 3DIGIT "-" 2*3DIGIT [ "-" 11HEXDIGIT ] sender-fqdn = "sender-fqdn:" OWS 4*( ALPHA / DIGIT / "-" / "." ) intended-n32-purposes = 1# ( "intended-n32-purpose: " OWS n32-purpose-value) n32-purpose-value = "ROAMING" / "INTER_PLMN_MOBILITY" / "SMS_INTERCONNECT" / "ROAMING_TEST" / "INTER_PLMN_MOBILITY_TEST" / "SMS_INTERCONNECT_TEST" / "SNPN_INTERCONNECT" / "SNPN_INTERCONNECT_TEST" / "DISASTER_ROAMING" / "DISASTER_ROAMING_TEST" / token req-param = req-param-name ":" OWS req-param-value req-param-name = token req-param-value = token

[0222] EXAMPLE 1: For an HTTP CONNECT request message from the c-SEPP tothe RI-A to request establishing the TCP connection towards the p-SEPP 3gpp-Connect-Req-Info: connect-purpose: n32c; originating-network-id: 123-45; sender-fqdn: sepp12.5gc.mnc155.mcc400.3gppnetwork; intended-n32-purpose: ROAMING; intended-32-purpose: SMS_INTERCONNECT

[0223] EXAMPLE 2: For an HTTP CONNECT request message from the RI-A to theRI-B to request establishing the TCP connection towards p-SEPP 3gpp-Connect-Req-Info: connect-purpose; n32c; originating-network-id: 123-45; sender-fqdn: ri234.rioperator.com; intended-n32-purpose: ROAMING;; intended- n32-purpose: SMS_INTERCONNECT

[0224] 3gpp-Connect-Resp-Info

[0225] The header enables to convey information in the HTTP CONNECT response towards the c-SEPP.

[0226] The encoding of the header follows the ABNF as defined in IETF RFC 9110. Connect-Info-Resp-Header = "3gpp-Connect-Resp-Info:" OWS [allowed-n32- purposes OWS] [";" p-sepp-fqdn] *( ";" OWS resp-param )allowed-n32-purposes = 1# ( "allowed-n32-purpose=" n32-purpose) p-sepp-fqdn = "p-sepp-resp-param = resp-param-name ":" OWS resp-param-value resp-param-name = token resp-param-value = token

[0227] EXAMPLE: 3gpp-Connect-Resp-Info: allowed-n32-purpose: ROAMING; p-sepp-fqdn: sepp2.5gc.mnc203.mcc422.3gppnetwork.org

[0228] With respect to Figs. 2 to 5 are shown a series of signal flow diagramsshowing successful and unsuccessful establishment of connections based on someembodiments. For example, Figs. 2 and 3 show successful establishment ofconnections in a single and multiple RI connection chain configuration respectfully according to some embodiments. Figs. 4 and 5 show unsuccessful attempts at establishment of connections in a single and multiple RI connection chain configuration respectively according to some embodiments.

[0229] The initial operation of all of the signal flow diagrams Figs 2 to 5 is the TCP connection establishment 201 between the c-SEPP 111 and the RI-A 131.Then the c-SEPP 111 is configured to send to the RI-A 131 a HTTP CONNECT request asshown by 203. The HTTP CONNECT request comprises information identifying thepeer apparatus (the p-SEPP). In this example the information is the p-SEPP hostand port. Furthermore, the request comprises additional information as indicatedabove.

[0230] The RI-A 131 receives the HTTP CONNECT request and based on theinformation identifying the peer apparatus (the target SEPP or p-SEPP) andadditional information as indicated above is configured to determine, as shown by205, whether the transmission control protocol connection towards the target SEPP of the target Public Land Mobile Network is to be established.

[0231] With respect to Fig. 2, the RI-A is configured to determine, based on theinformation, that the request is to be accepted and the transmission control protocolconnection towards the target SEPP of the target Public Land Mobile Network is to be established.

[0232] Then, as shown by 207, the RI-A is configured to establish a TCP connectionbetween RI-A 131 and p-SEPP 151.

[0233] Following the establishment of the TCP connection the RI-A is configured to generate a HTTP CONNECT response, the response comprising a ‘200 OK’ response and further including response information such as described above. The ‘200 OK’ response is transmitted back to the c-SEPP 111 as shown by 209.

[0234] The RI-A 131 can then be configured to blind forward information as shown by 211.

[0235] Following this an end-to-end (e2e) N32-c TLS connection establishment iscompleted as shown by 213.

[0236] Additionally, an end-to-end (e2e) N32-c handshake servicerequests / responses is completed as shown by 215.

[0237] With respect to Fig.3 is shown a successful establishment of connections in a multiple RI connection chain configuration.

[0238] Following a successful determination that the request is to be accepted at the RI-A 131, the RI-A 131 is configured to establish a TCP connection between the RI- A 131 and the RI-B 141 as shown by 301.

[0239] Then the RI-A 131 is configured to send to the RI-B 141 a HTTP CONNECTrequest as shown by 303. The HTTP CONNECT request comprises information identifying the peer apparatus (the p-SEPP). In this example the information is thep-SEPP host and port. Furthermore, the request comprises additional informationas indicated above. The additional information can as also indicated above furtherinformation associated with the RI-A 131.

[0240] The RI-B 141 is configured to receive the HTTP CONNECT request andbased on the information identifying the peer apparatus (the target SEPP or p- SEPP) and additional information as indicated above is configured to determine, as shown by 305, whether the transmission control protocol connection towards the target SEPP of the target Public Land Mobile Network is to be established.

[0241] With respect to Fig. 3, the RI-B is configured to determine, based on the information, that the request is to be accepted and the transmission control protocol connection towards the target SEPP of the target Public Land Mobile Network is to be established.

[0242] Then, as shown by 307, the RI-B is configured to establish a TCP connectionbetween RI-B 141 and p-SEPP 151.

[0243] Following the establishment of the TCP connection the RI-B is configured togenerate a HTTP CONNECT response, the response comprising a ‘200 OK’ response and further including response information such as described above. The‘200 OK’ response is transmitted back to the RI-A 131 as shown by 309.

[0244] The response comprising a ‘200 OK’ response and further including response information is received by the RI-A 131 and then forwarded to the c-SEPP 111 such as described above. The ‘200 OK’ response is transmitted back to the c-SEPP 111 as shown by 311.

[0245] The RI-B 131 can then be configured to blind forward information as shownby 315 and the RI-A 121 can then be configured to blind forward information as shown by 313.

[0246] Following this an end-to-end (e2e) N32-c TLS connection establishment iscompleted as shown by 317.

[0247] Additionally an end-to-end (e2e) N32-c handshake service requests / responses is completed as shown by 319.

[0248] With respect to Fig. 4, an unsuccessful request is shown with respect to asingle RI configuration. The RI-A is configured to determine, based on theinformation, that the request is to be rejected.

[0249] Then, as shown by 207, the RI-A is configured to generate and transmit backto the c-SEPP 111 a suitable response, the response comprising responseinformation. In this example as shown by 401, a ‘403 Forbidden’ responsecomprising error information is transmitted back to the c-SEPP 111.

[0250] With respect to Fig.3 is shown an unsuccessful establishment of connectionsin a multiple RI connection chain configuration.

[0251] Following a successful determination that the request is to be accepted at the RI-A 131, the RI-A 131 is configured to establish a TCP connection between the RI- A 131 and the RI-B 141 as shown by 301.

[0252] Then the RI-A 131 is configured to send to the RI-B 141 a HTTP CONNECTrequest as shown by 303. The HTTP CONNECT request comprises information identifying the peer apparatus (the p-SEPP). In this example the information is thep-SEPP host and port. Furthermore, the request comprises additional informationas indicated above. The additional information can as also indicated above furtherinformation associated with the RI-A 131.

[0253] The RI-B 141 is configured to receive the HTTP CONNECT request andbased on the information identifying the peer apparatus (the target SEPP or p- SEPP) and additional information as indicated above is configured to determine, as shown by 305, whether the transmission control protocol connection towards the target SEPP of the target Public Land Mobile Network is to be established.

[0254] With respect to Fig. 5, the RI-B is configured to determine, based on the information, that the request is to be rejected.

[0255] Then, as shown by 501, the RI-B is configured to generate and transmit backto the RI-A 131 a suitable response, the response comprising response information. In this example a ‘403 Forbidden’ response comprising error information istransmitted back to the RI-A 131.

[0256] The response is received by the RI-A 131 and then forwarded to the c-SEPP 111 such as described above. The ‘403 Forbidden’ response is transmitted back to the c-SEPP 111 as shown by 503.

[0257] Fig. 6 illustrates an example of a control apparatus 600 for controlling afunction such as the SEPP or RI as illustrated in Figure 1. The control apparatusmay comprise at least one random access memory (RAM) 611a, at least on read only memory (ROM) 611b, at least one processor 612, 613 and an input / output interface 614. The at least one processor 612, 613 may be coupled to the RAM 611a and the ROM 611b. The at least one processor 612, 613 may be configured to execute an appropriate software code 615. The software code 615 may for example allow to perform one or more steps to perform one or more of the present aspects. The software code 615 may be stored in the ROM 611b. The control apparatus 600 may be interconnected with another control apparatus 600 controlling another function of the 5GRAN or the 5GC. In some embodiments, each function of the 5GRAN or the 5GC comprises a control apparatus 600. In alternative embodiments, two or more functions of the 5GRAN or the 5GC may share a control apparatus.

[0258] As shown in Fig. 7a is shown a flow diagram of a method according to anembodiment of the present disclosure. The method may be used in and / orperformed by an apparatus (e.g., a consumer Security Edge Protection Proxy (c-SEPP) or a device comprising the c-SEPP) in a public land mobile network. Notethat the device comprising the c-SEPP refers to a device performing at least part of the functionalities of the c-SEPP.

[0259] As shown by 701, the method comprises transmitting, to a first roamingintermediary, a HTTP CONNECT request of establishing a TCP connection between the first RI and a peer apparatus.

[0260] Furthermore is shown, by 703, receiving, from the first roaming intermediary,an hypertext transfer protocol connect response comprising response informationwhich indicates whether the transmission control protocol connection towards the peer apparatus is established.

[0261] Specifically, the apparatus transmits, to a first roaming intermediary (RI), anHTTP CONNECT request of establishing a TCP connection between the first RI and a peer apparatus. In an embodiment, the TCP connection is used for establishingan inter-public-land-mobile-network signaling connection (e.g., N32-c or a signalingconnection on N32 interface) between the apparatus and the peer apparatus (e.g.,p-SEPP, an apparatus / device comprising p-SEPP) via the first RI. The apparatusreceives a hypertext transfer protocol connect response from the first RI. In anembodiment, the hypertext transfer protocol connect response indicatestransmission control protocol connection towards the peer apparatus is established.

[0262] In an embodiment, the HTTP CONNECT request may be for establishing aUDP (User Datagram Protocol) connection (e.g., a tunnel for UDP communications) between the first RI and the peer apparatus, wherein the UDP connection is used for establishing the inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus. In this embodiment, the security protocol intended to be negotiated over the inter-public-land-mobile-network signaling connection may further comprise a Quick UDP Internet Connections (QUIC) protocol.

[0263] In an embodiment, the HTTP CONNECT request comprises at least one of:- information indicating the peer apparatus;- information indicating / identifying the peer apparatus;- information indicating / identifying the apparatus;- information describing / indicating a purpose of establishing thetransmission control protocol connection; -information describing / indicating the inter-public-land-mobile-networksignaling connection being established by using the transmission control protocol connection; or -information controlling forwarding or origination of messages by thefirst roaming intermediary towards the apparatus or the peer apparatus.

[0264] In an embodiment, at least one of the information indicating / identifying thepeer apparatus; information indicating / identifying the apparatus; information describing / indicating a purpose of establishing the transmission control protocol connection; information describing / indicating the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by thefirst roaming intermediary towards the apparatus or the peer apparatus arecomprised in one or more headers of the HTTP CONNECT request.

[0265] In an embodiment, if these information are in the HTTP CONNECTIONrequest, at least one of the information indicating / identifying the peer apparatus; information indicating / identifying the apparatus; information describing / indicating a purpose of establishing the transmission control protocol connection; information describing / indicating the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roaming intermediary towards the apparatus or the peer apparatus are (comprised) in one or more headers of the HTTP CONNECT request.

[0266] Fig.7b shows a flow diagram of a method according to an embodiment of thepresent disclosure. The method may be used in and / or performed by anapparatus / device.

[0267] In an embodiment, the apparatus / device comprises a preceding connectionlink roaming intermediary (e.g., first RI or RI). Note that the apparatus / devicecomprising the preceding connection link roaming intermediary refers to anapparatus / device performing at least part of the functionalities of the preceding connection link roaming intermediary.

[0268] Thus, as shown by 751, is receiving at an apparatus, an HTTP CONNECTrequest of establishing a TCP connection towards a target SEPP of a target PLMN.

[0269] Furthermore, as shown by 753, is transmitting at least one of: to the furtherapparatus, an HTTP CONNECT response comprising response information whichindicates whether the TCP connection is established; or to a further roaming intermediary, a further HTTP CONNECT request of establishing a further TCP connection towards the target SEPP of the target PLMN for establishing the inter- PLMN signaling connection between the target SEPP and the consumer SEPP via the apparatus and also through the further roaming intermediary.

[0270] Specifically, the apparatus (e.g., first RI or RI) receives, from anotherapparatus (e.g., c-SEPP, an apparatus / device comprising c-SEPP), an HTTPCONNECT request of establishing a TCP connection between the first RI and a peerapparatus (e.g., p-SEPP, an apparatus / device comprising p-SEPP). In anembodiment, the TCP connection is used for establishing an inter-public-land-mobile-network signaling connection (e.g., N32-c or a signaling connection on N32interface) between the another apparatus (c-SEPP) and the peer apparatus (e.g.,p-SEPP, an apparatus / device comprising p-SEPP) via the apparatus (e.g., first RIor RI). In an embodiment, the peer apparatus is also called target apparatus / SEPPin a target PLMN.

[0271] In response to the HTTP CONNECT request, the apparatus may transmit atleast one: -to the further apparatus, a HTTP CONNECT response comprising responseinformation which indicates whether the TCP connection is established; or -to a further roaming intermediary (e.g., second RI), a further HTTPCONNECT request of establishing a further TCP connection towards the target SEPP of the target PLMN for establishing the inter-PLMN signaling connection between the target SEPP and the consumer SEPP via the apparatus and also through the further roaming intermediary.

[0272] For example, the RI receiving the HTTP CONNECT request may determinewhether to accept the request and / or to establish the TCP connection based on theHTTP CONNECT request. If determining not to accept the request and / or not toestablish the TCP connection, the RI transmits the HTTP CONNECT response to the apparatus transmitting the HTTP CONNECT request (i.e., c-SEPP or anotherRI), wherein the HTTP CONNECT response (or information comprised in the HTTPCONNECT response) indicates that the TCP connection is not established or theHTTP CONNECT request is rejected.

[0273] If determining to accept the request and / or to establish the TCP connection,the RI transmits the HTTP CONNECT response to the apparatus transmitting the HTTP CONNECT request (i.e., c-SEPP or another RI), wherein the HTTP CONNECT response (or information comprised in the HTTP CONNECT response)indicates that that the TCP connection is established or the HTTP CONNECTrequest is accepted.

[0274] As an alternative or in addition, If determining to accept the request and / or to establish the TCP connection, the RI transmits the HTTP CONNECT request to another RI (e.g., second RI), to establish the TCP connection to the p-SEPP. Based on the HTTP CONNECT response from the another RI, the RI transmits an HTTP CONNECT response to the apparatus transmitting the HTTP CONNECT request (i.e., c-SEPP or another RI), wherein (the information of) the HTTP CONNECTresponse indicates whether the TCP connection is established or the HTTPCONNECT request is accepted / rejected.

[0275] In an embodiment, the HTTP CONNECT request comprises at least one of:- information indicating the peer apparatus;- information indicating / identifying the peer apparatus;- information indicating / identifying the apparatus;- information describing / indicating a purpose of establishing thetransmission control protocol connection; -information describing / indicating the inter-public-land-mobile-networksignaling connection being established by using the transmission control protocol connection; or -information controlling forwarding or origination of messages by thefirst roaming intermediary towards the apparatus or the peer apparatus.

[0276] In an embodiment, at least one of the information indicating / identifying thepeer apparatus; information indicating / identifying the apparatus; information describing / indicating a purpose of establishing the transmission control protocol connection; information describing / indicating the inter-public-land-mobile-network signaling connection being established by using the transmission control protocolconnection; or information controlling forwarding or origination of messages by thefirst roaming intermediary towards the apparatus or the peer apparatus arecomprised in one or more headers of the HTTP CONNECT request.

[0277] In an embodiment, if these information are in the HTTP CONNECTIONrequest, at least one of the information indicating / identifying the peer apparatus; information indicating / identifying the apparatus; information describing / indicating a purpose of establishing the transmission control protocol connection; information describing / indicating the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the first roamingintermediary towards the apparatus or the peer apparatus are (comprised) in one ormore headers of the HTTP CONNECT request.

[0278] In the present disclosure, the apparatus being / having / comprising a networkfunction (e.g., SEPP) refers to an apparatus which performs or is configured to perform at least part of functionalities of the network function. For example, the apparatus comprises means for performing at least part of functionalities of the network function.

[0279] It should be understood that the apparatuses may comprise or be coupled toother units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.

[0280] It is noted that whilst some embodiments have been described in relation to5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.

[0281] It is also noted herein that while the above describes example embodiments,there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.

[0282] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0283] In general, the various embodiments may be implemented in hardware orspecial purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0284] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations inonly analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (asapplicable): (c) a combination of analog and / or digital hardware circuit(s) withsoftware / firmware and (i) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); and(ii) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portionof a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0285] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (ormultiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0286] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.

[0287] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as DVD and the data variants thereof, CD. The physical media is a non-transitory media.

[0288] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0289] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specificintegrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

[0290] Embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0291] The scope of protection sought for various embodiments of the disclosure is set out by the independent claims. The embodiments and features, if any, described in this specification that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various embodiments of the disclosure.

[0292] The foregoing description has provided by way of non-limiting examples a full and informative description of the exemplary embodiment of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings of this disclosure will still fall within the scope of this invention as defined in the appended claims. Indeed, there is a further embodiment comprising a combination of one or more embodiments with any of the other embodiments previously discussed.

Claims

CLAIMS1. An apparatus comprising means for performing:transmitting, to a first roaming intermediary, a hypertext transfer protocolconnect request of establishing a transmission control protocol connection betweenthe first roaming intermediary and a peer apparatus, wherein the transmissioncontrol protocol connection is used for establishing an inter-public-land-mobile-network signaling connection between the apparatus and the peer apparatus via thefirst roaming intermediary; andreceiving, from the first roaming intermediary, a hypertext transfer protocolconnect response comprising response information which indicates whether thetransmission control protocol connection towards the peer apparatus is established;wherein the hypertext transfer protocol connect request comprisesinformation indicating the peer apparatus, and wherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the apparatus; information describing a purpose of establishing the transmission controlprotocol connection; information describing the inter-public-land-mobile-network signalingconnection being established by using the transmission control protocolconnection; orinformation controlling forwarding or origination of messages by the firstroaming intermediary towards the apparatus or the peer apparatus.

2. The apparatus as claimed claim 1, wherein the information describing thepurpose of establishing the transmission control protocol connection comprises information identifying the hypertext transfer protocol connect request is to be usedto establish the inter-public-land-mobile-network signaling connection between theapparatus and the peer apparatus via the first roaming intermediary.

3. The apparatus as claimed in any preceding claims, wherein the informationdescribing the inter-public-land-mobile-network signaling connection beingestablished comprises information identifying at least one intended purpose of theinter-public-land-mobile-network signaling connection being established.

4. The apparatus as claimed in any preceding claims, wherein the informationdescribing the inter-public-land-mobile-network signaling connection beingestablished comprises information identifying a security protocol intended to benegotiated over the inter-public-land-mobile-network signaling connection.

5. The apparatus as claimed in claim 4, wherein the security protocol intendedto be negotiated over the inter-public-land-mobile-network signaling connectioncomprises one of: a protocol for N32 interconnect security, PRINS, protocol; a security profiles for PRINS; and a transport layer security, TLS, protocol.

6. The apparatus as claimed in any preceding claims, wherein the informationdescribing the inter-public-land-mobile-network signaling connection beingestablished comprises a correlation identifier configured to correlate communicationmessages on the inter-public-land-mobile-network signaling connection andcommunication messages on an inter-public-land-mobile-network messagesforwarding connection between the apparatus and the peer apparatus.

7. The apparatus as claimed in any preceding claims, wherein the hypertexttransfer protocol connect response indicates that the transmission control protocolconnection towards the peer apparatus is established and comprises informationidentifying at least one acceptable intended purpose of establishing the inter-public-land-mobile-network signaling communication via the first roaming intermediary.

8. The apparatus as claimed in any preceding claims, wherein the hypertexttransfer protocol connect response indicates that the transmission control protocolconnection towards the peer apparatus is established and comprises informationidentifying at least one acceptable security protocol for establishing the inter-public-land-mobile-network communication via the first roaming intermediary.

9. The apparatus as claimed in any preceding claims, wherein the informationwhich indicates whether the transmission control protocol connection towards thepeer apparatus is established is information indicating the transmission controlprotocol connection is not established and the information further comprises areason of the transmission control protocol connection is not established.

10. The apparatus as claimed in any preceding claims, wherein the apparatus isa consumer Security Edge Protection Proxy in a public land mobile network and thepeer apparatus is a producer Security Edge Protection Proxy in a peer public landmobile network.

11. The apparatus as claimed in any preceding claims, wherein the informationindicating the apparatus comprises at least one of the following: information identifying the apparatus; or information indicating a public land mobile network of the apparatus.

12. The apparatus as claimed in any preceding claims, wherein the inter-public-land-mobile-network signaling connection is used by the apparatus and the peerapparatus to determine the security to apply for the forwarding of messagesbetween the two Public Land Mobile Networks.

13. An apparatus, the apparatus being a roaming intermediary, the apparatuscomprising means for performing: receiving, from a further apparatus, a hypertext transfer protocol connectrequest of establishing a transmission control protocol connection towards a target Security Edge Protection Proxy of a target Public Land Mobile Network, wherein the transmission control protocol connection is used for establishing an inter-public-land-mobile-network signaling connection between the target Security EdgeProtection Proxy and a consumer Security Edge Protection Proxy via the apparatus,wherein the hypertext transfer protocol connect request comprises informationindicating the producer Security Edge Protection Proxy, andwherein the hypertext transfer protocol connect request comprises a header comprising at least one of: information indicating the further apparatus; information describing a purpose of establishing the transmission control protocol connection; information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by theapparatus towards the producer Security Edge Protection Proxy or the furtherapparatus; and determining whether the transmission control protocol connection towardsthe target Security Edge Protection Proxy of the target Public Land Mobile Networkis established based on the information; andtransmitting at least one of: to the further apparatus, a hypertext transfer protocol connect response comprising response information which indicates whether the transmission control protocol connection is established; or to a further roaming intermediary, a further hypertext transfer protocolconnect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the targetPublic Land Mobile Network for establishing the inter-public-land-mobile-network signaling connection between the target Security Edge ProtectionProxy and the consumer Security Edge Protection Proxy via the apparatusand also through the further roaming intermediary.

14. The apparatus as claimed in claim 13, wherein the further hypertext transferprotocol connect request of establishing a further transmission control protocol connection towards the target Security Edge Protection Proxy of the target PublicLand Mobile Network comprises information indicating the target Security EdgeProtection Proxy, and wherein the further hypertext transfer protocol connectrequest comprises a header comprising at least one of: information indicating the further apparatus; information indicating the apparatus; information describing a purpose of establishing the transmission control protocol connection; or information describing the inter-public-land-mobile-network signaling connection being established by using the transmission control protocol connection; or information controlling forwarding or origination of messages by the furtherroaming intermediary towards the target Security Edge Protection Proxy or theconsumer Security Edge Protection Proxy.

15. The apparatus as claimed in any of claims 13 or 14, wherein the informationdescribing the purpose of establishing the transmission control protocol connection comprises information identifying the hypertext transfer protocol connect request isto be used to establish a signaling connection between the target Security EdgeProtection Proxy and the consumer Security Edge Protection Proxy via the roaming intermediary.

16. The apparatus as claimed in any of claims 13 to 15, wherein the informationdescribing the inter-public-land-mobile-network signaling connection being established comprises information identifying at least one intended purpose of theinter-public-land-mobile-network signaling connection being established.

17. The apparatus as claimed in any of claims 13 to 16, wherein the informationdescribing the inter-public-land-mobile-network signaling connection beingestablished comprises information identifying a security protocol intended to benegotiated over the inter-public-land-mobile-network signaling connection.

18. The apparatus as claimed in claim 17, wherein the security protocol intendedto be negotiated over the inter-public-land-mobile-network signaling connectioncomprises one of: a protocol for N32 interconnect security, PRINS, protocol; asecurity profiles for PRINS; anda transport layer security, TLS, protocol.

19. The apparatus as claimed in any of claims 13 to 18, wherein the informationdescribing the inter-public-land-mobile-network signaling connection beingestablished comprises a correlation identifier configured to correlate communicationmessages on the inter-public-land-mobile-network signaling connection and communication messages on an inter-public-land-mobile-network messagesforwarding connection between the consumer Security Edge Protection Proxy andthe target Security Edge Protection Proxy.

20. The apparatus as claimed in any of claims 13 to 19, wherein the hypertexttransfer protocol connect response indicates that the transmission control protocolconnection towards the target Security Edge Protection Proxy is established andcomprises information identifying at least one acceptable intended purpose of establishing the inter-public-land-mobile-network signaling communication via the roaming intermediary.

21. The apparatus as claimed in any of claims 13 to 20, wherein the hypertexttransfer protocol connect response indicates that the transmission control protocolconnection towards the target Security Edge Protection Proxy is established andcomprises information identifying at least one acceptable security protocol for establishing the inter-public-land-mobile-network communication via the roaming intermediary.

22. The apparatus as claimed in any of claims 13 to 21, wherein the informationwhich indicates whether the transmission control protocol connection towards thetarget Security Edge Protection Proxy is established is information indicating thetransmission control protocol connection is not established and the informationfurther comprises a reason of the transmission control protocol connection is notestablished.

23. The apparatus as claimed in any of claims 13 to 22, wherein the furtherapparatus is one of: an originating Security Edge Protection Proxy in an originating public landmobile network; anda consumer Security Edge Protection Proxy in a public land mobile network; and a preceding connection link roaming intermediary.

24. The apparatus as claimed in any of claims 13 to 23, wherein the means forperforming determining whether the transmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land MobileNetwork is established based on the information is further determining whether thetransmission control protocol connection towards the target Security Edge Protection Proxy of the target Public Land Mobile Network is established based on at least one of: acontractual roaming agreement between the roaming intermediary and thePublic Land Mobile Network of the further apparatus; ora contractual roaming agreement between the roaming intermediary and thetarget Public Land Mobile Network; orat least one of the intended purposes allowed by the contractual agreementbetween the roaming intermediary and the Public Land Mobile Network of the furtherapparatus; or at least one of the intended purposes allowed by the contractual agreementbetween the roaming intermediary and the target Public Land Mobile Network.

25. A method for implementing the means for performing as claimed in any ofclaims 1 to 24.

Citation Information

Patent Citations

  • A method of implementing 5g core roaming routing in an IPX network

    EP4050968A1

Cited By

  • Systems and methods for transferring state of connections and packets between mesh nodes in a mesh network

    US20260032750A1