Mechanism to expose reverse NAT information

By requesting a Session Management Function (SMF) to obtain and relay the NATed public IP address and port from a User Plane Function (UPF) using UE identifiers, the challenge of identifying unique IP addresses and ports for User Equipment (UE) in 3GPP systems is resolved, enabling effective data correlation and analysis.

WO2025172951A1PCT designated stage Publication Date: 2025-08-21TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051651
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-16
Filing Date
2025-02-14
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

In 3GPP systems, obtaining a Network Address Translated (NATed) public IP address and port for a User Equipment (UE) is challenging when the Network Function (NF) consumer knows only the Subscriber Permanent Identifier (SUPI), as existing methods fail to uniquely identify the UE's IP address and port due to multiple PDU sessions and shared IP addresses.

Method used

A method where a Network Function (NF) or Application Function (AF) sends a request to a Session Management Function (SMF) with the UE's identifier, which then obtains the UE's IP address and sends a request to a User Plane Function (UPF) to retrieve the NATed public IP address and port, allowing the UPF to filter and provide the correct information based on a list of candidate traffic destination IP addresses.

Benefits of technology

Enables the NF or AF to obtain a unique public IP address and port for the UE, facilitating data collection and analysis by correlating IP flows with the UE, even when multiple PDU sessions and IP flows are present.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051651_21082025_PF_FP_ABST
    Figure IB2025051651_21082025_PF_FP_ABST
Patent Text Reader

Abstract

Systems and methods are disclosed herein that enable a Network Function (NF) consumer or Application Function (AF) to obtain a public Internet Protocol (IP) address and port for a User Equipment (UE) after Network Address Translation (NAT), when the NF consumer or AF has only the Subscription Permanent Identifier (SUPI) (or GPSI) of the UE.
Need to check novelty before this filing date? Find Prior Art

Description

MECHANISM TO EXPOSE REVERSE NA TIN FORMA HONRelated Applications

[0001] This application claims the benefit of European patent application serial number 24382155.0, filed February 16, 2024, the disclosure of which is hereby incorporated herein by reference in its entirety.Technical Field

[0002] The present disclosure relates to a 3rdGeneration Partnership Project system and, more specifically, to a service in the 3GPP system for obtaining a Network Address Translated (NATed) Internet Protocol (IP) address and port of a User Equipment (UE).Background

[0003] Currently in the 3rdGeneration Partnership Project (3GPP) specifications, a Network Function (NF) consumer can get the private Internet Protocol (IP) address for a User Equipment (UE) from a User Plane Function (UPF) supporting Network Address Translation (NAT) by including a public IP address via service Nupf_GetUEPrivateIPaddrAndIdentifiers. However, there are use cases where the NF consumer knows the Subscriber Permanent Identifier (SUPI), and the NF consumer wants to get the public address and port after NAT for a UE. This is especially the case when Network Data Analytics Function (NWDAF) wants to get information related to a UE via an Application Function (AF). See 3GPP 23.288 V18.3.0, clause 6.2.8.2.4 and related subclauses.

[0004] In 3GPP SA2 Working Group (WG) meeting number 158, and later on in meeting number 160, there were proposals to solve this issue in S2-2313383, which is a Change Request (CR) to 3GPP TS 23.288 V18.3.0.Summary

[0005] Systems and methods for obtaining a Network Address Translated (NATed) public Internet Protocol (IP) address and port of a User Equipment (UE) are disclosed. In one embodiment, a method comprises, at a Session Management Function (SMF), receiving, from a Network Function (NF) or Application Function (AF) (NF / AF), a first request for a public IP address and port of a UE, wherein the first request comprises anidentifier of the UE. The method further comprises, at the SMF, obtaining a UE IP address of the UE based on the identifier of the UE and sending a second request for the public IP address and port of the UE to a User Plane Function (UPF), wherein the second request comprises the UE IP address of the UE. The method further comprises, at the UPF, receiving the second request from the SMF, obtaining a NATed public IP address and port (e.g., TCP / UDP port) of the UE based on the UE IP address comprised in the second request, and sending, to the SMF, a response to the second request that comprises the NATed public IP address and port of the UE. The method further comprises, at the SMF, receiving the response to the second request from the UPF and sending, to the NF / AF, a response to the first request comprising the NATed public IP address and port of the UE.

[0006] In one embodiment, a method performed by an NF or an AF comprises sending, to a core network node, a request for a public IP address and port of a UE having one or more packet data unit (PDU) sessions established over a telecommunication system, wherein the request comprises an identifier of the UE. The method further comprises receiving, from the core network node, a response comprising either a NATed public IP address and port of the UE or all NAT mappings related to an IP address of the UE assigned by the telecommunication system for the one or more PDU sessions. Corresponding embodiments of a network node for implementing an NF or AF are also disclosed.

[0007] In another embodiment, a method performed in a core network of a telecommunications system comprises, at a Session Management Function (SMF). receiving, from an NF or AF (NF / AF), a first request for a public IP address and port of a UE, wherein the first request comprises an identifier of the UE. The method further comprises, at the SMF, obtaining a UE IP address assigned for a PDU session of the UE based on the identifier of the UE and sending a second request for the public IP address and port of the UE to a User Plane Function (UPF), wherein the second request comprises the UE IP address of the UE. The method further comprises, at the UPF, receiving the second request from the SMF, obtaining a NATed public IP address and port of the UE based on the received UE IP address of the UE or all NAT mappings related to the received UE IP address, and sending, to the SMF, a response to the second request that comprises either the NATed public IP address and port of the UE or all NAT mappings related to the received UE IP address. The method further comprises,at the SMF, receiving the response to the second request from the UPF and sending, to the NF / AF, a response to the first request comprising either the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address. Corresponding embodiments of an SMF and UPF and methods of operation thereof are also disclosed herein.Brief Description of the Drawings

[0008] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.

[0009] Figure 1 illustrates a procedure in accordance with an embodiment of the present disclosure;

[0010] Figure 2 illustrates one example of a cellular communications system in which embodiments of the present disclosure may be implemented;

[0011] Figure 3 illustrates a 5G network architecture using service-based interfaces between the NFs in the Control Plane (CP);

[0012] Figure 4 is a schematic block diagram of a network node according to some embodiments of the present disclosure;

[0013] Figure 5 is a schematic block diagram that illustrates a virtualized embodiment of the network node according to some embodiments of the present disclosure; and

[0014] Figure 6 is a schematic block diagram of the network node according to some other embodiments of the present disclosure.Detailed

[0015] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0016] Radio Access Node: As used herein, a "radio access node" or "radio network node" or "radio access network node" is any node in a Radio Access Network(RAN) of a cellular communications network that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., a New Radio (NR) base station (gNB) in a Third Generation Partnership Project (3GPP) Fifth Generation (5G) NR network or an enhanced or evolved Node B (eNB) in a 3GPP Long Term Evolution (LTE) network), a high-power or macro base station, a low-power base station (e.g., a micro base station, a pico base station, a home eNB, or the like), a relay node, a network node that implements part of the functionality of a base station (e.g., a network node that implements a gNB Central Unit (gNB-CU) or a network node that implements a gNB Distributed Unit (gNB-DU)) or a network node that implements part of the functionality of some other type of radio access node.

[0017] Core Network Node: As used herein, a "core network node" is any type of node in a core network or any node that implements a core network function. Some examples of a core network node include, e.g., a Mobility Management Entity (MME), a Packet Data Network Gateway (P-GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), or the like. Some other examples of a core network node include a node implementing an Access and Mobility Management Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like.

[0018] Network Node: As used herein, a "network node" is any node that is either part of the RAN or the core network of a cellular communications network / system.

[0019] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.

[0020] Note that, in the description herein, reference may be made to the term "cell"; however, particularly with respect to 5G NR concepts, beams may be used instead of cells and, as such, it is important to note that the concepts described herein are equally applicable to both cells and beams.

[0021] There currently exist certain challenge(s). The main idea of the solution in S2-2313383 is to let the Session Management Function (SMF) identify the Protocol DataUnit (PDU) session related to the Subscription Permanent Identifier (SUPI) and Data Network Name (DNN) and Single Network Slice Selection Assistance Information (S- NSSAI). However, there are problems with this, namely:1. SUPI, DNN, and S-NSSAI do not uniquely identify a PDU session, since there can be several User PDU sessions for this combination.2. There may be many UEs sharing the same public Internet Protocol (IP) address, and thus the port is needed. However, the UE may have several IP sessions ongoing, thus a unique port using the solution in S2-2313383 cannot be identified.

[0022] Certain aspects of the present disclosure and their embodiments may provide solutions to the aforementioned or other challenges. Embodiments of the present disclosure let a Network Function (NF) consumer provide a list of candidate traffic destination IP addresses in a new service (referred to herein by the exemplary, nonlimiting name "Nsmf_GetPublicIPaddressAndPort") so that the User Plane Function (UPF) can filter out the wanted User Equipment (UE) IP flow(s) and provide only for those the user IP address and port after Network Address Translation (NAT).

[0023] Certain embodiments may provide one or more of the following technical advantage(s). Embodiments of the present disclosure enable a unique IP address and port to be identified.

[0024] Systems and methods are disclosed herein that enable a NF consumer or Application Function (AF) to obtain a public IP address and port for a UE after NAT, when the NF consumer or AF has only the SUPI (or GPSI) of the UE.

[0025] In one example use case, a Network Data Analytics Function (NWDAF) can subscribe to an AF in order for the AF to collect data from a UE which can be used by the NWDAF for analytics to the UE. In the subscription, the NWDAF can provide the SUPI / GPSI of the UE to the AF, and the AF then needs to be able to correlate an IP flow between itself and the UE with the received SUPI / GPSI. The NWDAF can also by itself provide the IP address to the AF, i.e. NWDAF translates SUPI to UE IP address.

[0026] One solution to this correlation is for the AF to query the User Plane Function (UPF), or cause a Network Exposure Function (NEF) to query the UPF, for this mapping e.g. via the Session Management Function (SMF). Since a UE can have many PDU sessions for a DNN and S-NSSAI each with its own NAT address and since the UE can also have many ongoing IP flows on a PDU session where only one of these is towardsthe AF, there must be a way to distinguish the IP flow between the UE and the AF from all other IP flows of the UE. Embodiments of the present disclosure provide a mechanism by which the AF provides a list of its IP addresses that the AF uses for its communication with the UEs, or if the AF uses an NEF, the NEF is configured with the list of IP address the AF uses for its communication with UEs.

[0027] In this regard, Figure 1 illustrates the operation of a NF or AF (NF / AF) 100, an SMF 102, and a UPF 104, in accordance with an embodiment of the present disclosure. While not explicitly shown in Figure 1, as an initial condition for the procedure, a PDU session(s) for a UE has been established over a telecommunications system (e.g., a 5G system). If a Generic Public Subscription Identifier (GPSI) is known, the NF (e.g. NEF or NWDAF) / AF 100 has translated the GPSI to a SUPI. The NF / AF 100 has discovered the SMF(s) 102 handling one or more PDU session(s) for the combination of SUPI and DNN and S-NSSAI. The NF needs to know the endpoint addresses of the remote end (that is, all possible destination IP addresses of the UE IP flows e.g. the AF endpoints) if it is the NF and not AF that is to execute the procedure of Figure 1. In this case, the NF may obtain the endpoint addresses of the remote end (i.e., all possible destination IP addresses of the UE IP flows, e.g., the AF endpoints) via signaling from the AF or via configuration.

[0028] Step 1: The NF / AF 100 sends an Nsmf_GetPublicIPaddressAndPort request including the SUPI, DNN, S-NSSAI, and optionally a list of public IP addresses for the remote endpoints, e.g. the AF endpoints) to the SMF 102. Note that if the UE has several PDU sessions for the DNN and S-NSSAI and these PDU sessions are served by different SMFs, the NF / AF 100 sends a Nsmf_GetPublicIPaddressAndPort request to each of those SMFs.

[0029] Step 2: The SMF 102 translates the SUPI, DNN, and S-NSSAI to UE IP address(es) and sends, to the UPF 104, a Nupf_GetPublicIPaddressAndPort request including the UE IP address, the DNN, the S-NSSAI, and if received the list of public IP addresses for the remote endpoints. Note that if the UE has more than one PDU session for the DNN and S-NSSAI, then, if the SMF 102 includes UE IP address(es) in the request to the UPF 104, the SMF 100 sends several requests to UPF 104 (e.g., a separate request for each UE IP address).

[0030] Step 3: The UPF 104 finds all related NAT mappings for the received UE IP address (or SUPI). Further, if a list of public addresses was received in step 2, the UPF104 selects the NAT mapping of the UE flow with a destination IP address within the received list of public IP addresses for the remote endpoints. The UPF 104 responds to the SMF 102 with a Nupf_GetPublicIPaddressAndPort response including the UE's NATed Public IP address and port (e.g., TCP / UDP Port). If the UPF 104 did not receive a list of public IP addresses for the remote endpoints, the UPF 104 responds with all NAT mappings related to UE IP address (assigned by the telecommunication system for the PDU session(s) of the UE) in Nupf_GetPublicIPaddressAndPort response.

[0031] Step 4: The SMF 102 forwards the received information in step 3 to the NF / AF 100. If AF requested the public IP address via NEF, and if NEF receives the full mapping NAT mapping table (i.e., UPF did not receive a list of public IP addresses for the remote end), NEF only provides the public IP address and port that is relevant for the AF.

[0032] The following provides one example embodiment of a service definition of the Nupf_GetPublicIPaddressAndPort service:• Service operation name: Nupf_GetPublicIPaddressAndPort_Get• Description: NF service consumer gets the NATed UE public IP address and Port, for the IP flow between the UE and a remote end, e.g. an AF.• Inputs, Required: IP address (UE IP address assigned by 5GC for the PDU session)• Inputs, Optional: DNN, S-NSSAI, IP domain, list of public IP addresses of the remote end.• Outputs, Required: if list of public IP addresses was in Inputs: a public IP address and source TCP / UDP port (or non, if no NAT mapping was found). If no list of public IP addressees was in Inputs: the full NAT mapping table for the UE IP address• Outputs, Optional: None

[0033] One example of an extension to the proposed solution above is as follows:• A list of IP addresses can be provided in the proposed new service / primitive, so that the UPF 104 will reply (e.g., in step 3) with only the NATed results for the UE IP flows which are relevant for that NF consumer.

[0034] Some example variants of the embodiment described above with respect toFigure 1 are:• The request to UPF 104 (e.g., in step 2) may identify the UE with another identifier, e.g. SUPI, instead of the UE IP address.• The request to the SMF 102 (e.g., in step 1) and / or the request to the UPF 104 (e.g., in step 2) may include, instead of an explicit list of public IP addresses, an identifier (e.g. App ID) where and the corresponding public IP addresses are configured in the UPF 104.

[0035] Figure 2 illustrates one example of a cellular communications system 200 in which embodiments of the present disclosure may be implemented. In the embodiments described herein, the cellular communications system 200 is a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC); however, the embodiments of the present disclosure may be used in other types of wireless communications systems (e.g., a 6thGeneration (6G) system). In this example, the RAN includes base stations 202-1 and 202-2, which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs), controlling corresponding (macro) cells 204-1 and 204-2. The base stations 202-1 and 202-2 are generally referred to herein collectively as base stations 202 and individually as base station 202. Likewise, the (macro) cells 204-1 and 204-2 are generally referred to herein collectively as (macro) cells 204 and individually as (macro) cell 204. The RAN may also include a number of low power nodes 206-1 through 206-4 controlling corresponding small cells 208-1 through 208-4. The low power nodes 206-1 through 206-4 can be small base stations (such as pico or femto base stations) or RRHs, or the like. Notably, while not illustrated, one or more of the small cells 208-1 through 208-4 may alternatively be provided by the base stations 202. The low power nodes 206-1 through 206-4 are generally referred to herein collectively as low power nodes 206 and individually as low power node 206. Likewise, the small cells 208-1 through 208-4 are generally referred to herein collectively as small cells 208 and individually as small cell 208. The cellular communications system 200 also includes a core network 210, which in the 5G System (5GS) is referred to as the 5GC. The base stations 202 (and optionally the low power nodes 206) are connected to the core network 210.

[0036] The base stations 202 and the low power nodes 206 provide service to wireless communication devices 212-1 through 212-5 in the corresponding cells 204 and 208. The wireless communication devices 212-1 through 212-5 are generally referred to herein collectively as wireless communication devices 212 and individually as wirelesscommunication device 212. In the following description, the wireless communication devices 212 are oftentimes UEs, but the present disclosure is not limited thereto.

[0037] Figure 3 illustrates a 5G network architecture using service-based interfaces between the NFs in the CP. Figure 3 can be viewed as one particular implementation of the system 200 of Figure 2. Seen from the access side, the 5G network architecture shown in Figure 3 comprises a plurality of UEs 212 connected to either a RAN 202 or an Access Network (AN) as well as an Access and Mobility Management Function (AMF) 300. Typically, the R(AN) 202 comprises base stations, e.g. such as eNBs or gNBs or similar. Seen from the core network side, the 5GC NFs shown in Figure 3 include a Network Slice Selection Function (NSSF) 302, a Network Exposure Function (NEF) 304, a Network Repository Function (NRF) 306, a Policy and Control Function (PCF) 308, a Unified Data Management function (UDM) 310, an Application Function (AF) 312, an Edge Application Server Discovery Function (EASDF) 314, a Network Slice-specific and SNPN Authentication and Authorization Function (NSSAAF) 316, an Authentication Server Function (AUSF) 318, the AMF 300, Session Management Function (SMF) 320, Service Communication Proxy (SCP) 322, Network Slice Admission Control Function (NSACF) 324, and a User Plane Function (UPF) 326 The service(s) etc. that a NF provides to other authorized NFs can be exposed to the authorized NFs through the service-based interface. In Figure 3, the service based interfaces are indicated by the letter "N" followed by the name of the NF, e.g. Namf for the service based interface of the AMF 300 and Nsmf for the service based interface of the SMF 320, etc. The functionality of the various NFs shown in Figure 3 are defined in 3GPP specifications. To the extent that their functionality is related to embodiments of the present disclosure, their functionality is a defined in existing 3GPP specifications or as described herein.

[0038] An NF may be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g., a cloud infrastructure.

[0039] Figure 4 is a schematic block diagram of a network node 400 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 400 may be, for example, a base station 202 or 206, a network node that implements all or part of the functionality of the base station 202 or gNB, or a network node that implements the functionality of an NF or AF, asdescribed herein. As illustrated, the network node 400 includes a control system 402 that includes one or more processors 404 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 406, and a network interface 408. The one or more processors 404 are also referred to herein as processing circuitry. In addition, if the network node 400 is a radio access node (e.g., a base station 202, gNB, or network node that implements at least some of the functionality of the base station 202 or gNB), the network node 400 may include one or more radio units 410 that each includes one or more transmitters 412 and one or more receivers 414 coupled to one or more antennas 416. The radio units 410 may be referred to or be part of radio interface circuitry. In some embodiments, the radio unit(s) 410 is external to the control system 402 and connected to the control system 402 via, e.g., a wired connection (e.g., an optical cable). However, in some other embodiments, the radio unit(s) 410 and potentially the antenna(s) 416 are integrated together with the control system 402. The one or more processors 404 operate to provide one or more functions of the network node 400 as described herein (e.g., one or more functions of a consumer NF, an AF, an NEF, an SMF, or a UPF, as described herein). In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 406 and executed by the one or more processors 404.

[0040] Figure 5 is a schematic block diagram that illustrates a virtualized embodiment of the network node 400 according to some embodiments of the present disclosure. Again, optional features are represented by dashed boxes. As used herein, a "virtualized" network node is an implementation of the network node 400 in which at least a portion of the functionality of the network node 400 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated, in this example, if the network node 400 is a radio access node, the network node 400 may include the control system 402 and / or the one or more radio units 410, as described above. The control system 402 may be connected to the radio unit(s) 410 via, for example, an optical cable or the like. The network node 400 includes one or more processing nodes 500 coupled to or included as part of a network(s) 502. If present, the control system 402 or the radio unit(s) are connected to the processing node(s) 500 via the network 502. Each processing node500 includes one or more processors 504 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 506, and a network interface 508.

[0041] In this example, functions 510 of the network node 400 described herein (e.g., one or more functions of a consumer NF, an AF, an NEF, an SMF, or a UPF, as described herein) are implemented at the one or more processing nodes 500 or distributed across the one or more processing nodes 500 and the control system 402 and / or the radio unit(s) 410 in any desired manner. In some particular embodiments, some or all of the functions 510 of the network node 400 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environ ment(s) hosted by the processing node(s) 500. As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) 500 and the control system 402 is used in order to carry out at least some of the desired functions 510. Notably, in some embodiments, the control system 402 may not be included, in which case the radio unit(s) 410 communicate directly with the processing node(s) 500 via an appropriate network interface(s).

[0042] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the network node 400 or a node (e.g., a processing node 500) implementing one or more of the functions 510 of the network node 400 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).

[0043] Figure 6 is a schematic block diagram of the network node 400 according to some other embodiments of the present disclosure. The network node 400 includes one or more modules 600, each of which is implemented in software. The module(s) 600 provides the functionality of the network node 400 described herein. This discussion is equally applicable to the processing node 500 of Figure 5 where the modules 600 may be implemented at one of the processing nodes 500 or distributed across multiple processing nodes 500 and / or distributed across the processing node(s) 500 and the control system 402.

[0044] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processor (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0045] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).

Claims

Claims1. A method performed by a Network Function, NF, or Application Function, AF, (NF or AF), the method comprising: sending (Fig. 1, step 1), to a core network node, a request for a public Internet Protocol, IP, address and port of a User Equipment, UE, having one or more packet data unit (PDU) sessions established over a telecommunication system, wherein the request comprises an identifier of the UE; receiving (Fig. 1, step 4), from the core network node, a response comprising either a Network Address Translated, NATed, public IP address and port of the UE or all NAT mappings related to an IP address of the UE assigned by the telecommunication system for the one or more PDU sessions.

2. The method of claim 1, wherein the request further comprises information indicative of one or more public IP addresses for one or more remote endpoints.

3. The method of claim 2, wherein the one or more remote endpoints are one or more AF endpoints.

4. The method of claim 2 or 3, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises an identifier associated to the one or more public IP addresses for the one or more remote end points.

5. The method of claim 2 or 3, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises a list of the one or more public IP addresses for the one or more remote endpoints.

6. The method of any of claims 2 to 3, wherein the response comprises the NATed public IP address and port of the UE.

7. The method of claim 6, wherein the NATed public IP address and port of the UE comprised in the response is a NATed public IP address and port of the UE associatedto a UE flow with a destination IP address within a list consisting of the one or more public IP addresses for the one or more remote endpoints.

8. The method of claim 1, wherein the response comprises all NAT mappings related to an IP address of the UE assigned by the telecommunication system for the one or more PDU sessions.

9. The method of any of claims 1 to 8, wherein the request further comprises a data network name.

10. The method of claim 9, wherein the request further comprises a network slice identifier.

11. The method of claim 10, wherein the network slice identifier is a Single Network Slice Selection Assistance Information, S-NSSAI.

12. The method of any of claims 1 to 11, wherein identifier of the UE is a Subscription Permanent Identifier, SUPI, of the UE or Generic Public Subscription Identifier, GPSI, of the UE.

13. The method of any of claims 1 to 12, wherein the core network node is a Session Management Function, SMF.

14. The method of any of claims 1 to 13, wherein the AF sends the request directly to the core network node or via a Network Exposure Function, NEF.

15. The method of any of claims 1 to 13, wherein the NF is an NF in the core network of the telecommunication system16. The method of any of claims 1 to 15, wherein the port is a Transmission Control Protocol, TCP, / User Datagram Protocol, UDP, port.

17. A network node for implementing a Network Function, NF, or Application Function, AF, adapted to: send (Fig. 1, step 1), to a core network node, a request for a public Internet Protocol, IP, address and port of a User Equipment, UE, having one or more packet data unit (PDU) sessions established over a telecommunication system, wherein the request comprises an identifier of the UE; receive (Fig. 1, step 4), from the core network node, a response comprising either a Network Address Translated, NATed, public IP address and port of the UE or all NAT mappings related to an IP address of the UE assigned by the telecommunication system for the one or more PDU sessions.

18. The network node of claim 17, further adapted to perform the method of any of claims 2 to 16.

19. A network node for implementing a Network Function, NF, or Application Function, AF, comprising processing circuitry (404; 504) configured to cause the network node to: send (Fig. 1, step 1), to a core network node, a request for a public Internet Protocol, IP, address and port of a User Equipment, UE, having one or more packet data unit (PDU) sessions established over a telecommunication system, wherein the request comprises an identifier of the UE; receive (Fig. 1, step 4), from the core network node, a response comprising either a Network Address Translated, NATed, public IP address and port of the UE or all NAT mappings related to an IP address of the UE assigned by the telecommunication system for the one or more PDU sessions.

20. The network node of claim 19, wherein the processing circuitry is further configured to cause the network node to perform the method of any of claims 2 to 16.

21. A method comprising:• at a Session Management Function, SMF: o receiving (Fig. 1, step 1), from a Network Function, NF, or Application Function, AF, (NF / AF), a first request for a public Internet Protocol, IP,address and port of a User Equipment, UE, wherein the first request comprises an identifier of the UE; o obtaining (Fig. 1, step 2) a UE IP address assigned for a packet data unit (PDU) session of the UE based on the identifier of the UE; and o sending (Fig. 1, step 2) a second request for the public IP address and port of the UE to a User Plane Function, UPF, wherein the second request comprises the UE IP address of the UE;• at the UPF: o receiving (Fig. 1, step 2) the second request from the SMF; o obtaining (Fig. 1, step 3) a Network Address Translated, NATed, public IP address and port of the UE based on the received UE IP address of the UE or all NAT mappings related to the received UE IP address; o sending (Fig. 1, step 3), to the SMF, a response to the second request that comprises either the NATed public IP address and port of the UE or all NAT mappings related to the received UE IP address;• at the SMF: o receiving (Fig. 1, step 3) the response to the second request from the UPF; and o sending (Fig. 1, step 4), to the NF / AF, a response to the first request comprising either the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address.

22. The method of claim 20, wherein both the first request and the second request further comprise information indicative of one or more public IP addresses for one or more remote endpoints.

23. The method according to claim 22, wherein the response to the second request and the response to the first request comprise the NATed public IP address and port of the UE when the first request and the second request further comprise information indicative of one or more public IP addresses for one or more remote endpoints.

24. The method of claim 22 or 23, wherein the one or more remote endpoints are one or more AF endpoints.

25. The method of any of claims 22 to 24, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises an identifier associated to the one or more public IP addresses for the one or more remote end points.

26. The method of any of claims 22 to 24, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises a list of the one or more public IP addresses for the one or more remote endpoints.

27. The method of any of claims 22 to 26, wherein, at the UPF, obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE comprises obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE that are mapped to a destination IP address that corresponds to one of the one or more public IP addresses for the one or more remote endpoints.

28. The method of claim 21, wherein, at the UPF, obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE or all NAT mappings related to the received UE IP address comprises obtaining (Fig. 1, step 3) all NAT mappings related to the received UE IP address, and the response sent by the UPF to the SMF comprises the NAT mappings related to the received UE IP address.

29. The method of any of claims 21 to 28, wherein the first request further comprises a data network name.

30. The method of claim 29, wherein the first request further comprises a network slice identifier.

31. The method of any of claims 21 to 30, wherein the second request further comprises the data network name.

32. The method of claim 31, wherein the second request further comprises the network slice identifier.

33. The method of any of claims 21 to 32, wherein identifier of the UE comprised in the first request is a Subscription Permanent Identifier, SUPI, of the UE or Generic Public Subscription Identifier, GPSI, of the UE.

34. A method performed by a Session Management Function, SMF, the method comprising: receiving (Fig. 1, step 1), from a Network Function, NF, or Application Function, AF, (NF / AF), a first request for a public Internet Protocol, IP, address and port of a User Equipment, UE, wherein the first request comprises an identifier of the UE; obtaining (Fig. 1, step 2) a UE IP address assigned for a packet data unit (PDU) session of the UE based on the identifier of the UE; sending (Fig. 1, step 2) a second request for the public IP address and port of the UE to a User Plane Function, UPF, wherein the second request comprises the UE IP address of the UE; receiving (Fig. 1, step 3), from the UPF, a response to the second request that comprises either a NATed public IP address and port of the UE or all NAT mappings related to the UE IP address; and sending (Fig. 1, step 4), to the NF / AF, a response to the first request comprising either the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address.

35. The method of claim 34, wherein both the first request and the second request further comprise information indicative of one or more public IP addresses for one or more remote endpoints.

36. The method according to claim 35, wherein the response to the second request and the response to the first request comprise the NATed public IP address and port of the UE when the first request and the second request further comprise information indicative of one or more public IP addresses for one or more remote endpoints.

37. The method of claim 35 or 36, wherein the one or more remote endpoints are one or more AF endpoints.

38. The method of any of claims 35 to 37, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises an identifier associated to the one or more public IP addresses for the one or more remote end points.

39. The method of any of claims 35 to 37, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises a list of the one or more public IP addresses for the one or more remote endpoints.

40. The method of any of claims 36 to 38, wherein, at the UPF, obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE comprises obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE that are mapped to a destination IP address that corresponds to one of the one or more public IP addresses for the one or more remote endpoints.

41. The method of claim 34, wherein the response received from the UPF comprises all NAT mappings related to the received UE IP address, and the response sent to the NF / AF comprises the NAT mappings related to the received UE IP address.

42. The method of any of claims 24 to 41, wherein the first request further comprises a data network name.

43. The method of claim 42, wherein the first request further comprises a network slice identifier.

44. The method of claim 42 or 43, wherein the second request further comprises the data network name.

45. The method of claim 44, wherein the second request further comprises the network slice identifier.

46. The method of any of claims 34 to 45, wherein identifier of the UE comprised in the first request is a Subscription Permanent Identifier, SUPI, of the UE or Generic Public Subscription Identifier, GPSI, of the UE.

47. A network node adapted to: receive (Fig. 1, step 1), from a Network Function, NF, or Application Function, AF, (NF / AF), a first request for a public Internet Protocol, IP, address and port of a User Equipment, UE, wherein the first request comprises an identifier of the UE; obtain (Fig. 1, step 2) a UE IP address assigned for a packet data unit (PDU) session of the UE based on the identifier of the UE; send (Fig. 1, step 2) a second request for the public IP address and port of the UE to a User Plane Function, UPF, wherein the second request comprises the UE IP address of the UE; receive (Fig. 1, step 3), from the UPF, a response to the second request that comprises either a NATed public IP address and port of the UE or all NAT mappings related to the UE IP address; and send (Fig. 1, step 4), to the NF / AF, a response to the first request comprising either the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address.

48. The network node of claim 47, further adapted to perform the method of any of claims 35 to 46.

49. A network node comprising processing circuitry (404; 504) configured to cause the network node to: receive (Fig. 1, step 1), from a Network Function, NF, or Application Function, AF, (NF / AF), a first request for a public Internet Protocol, IP, address and port of a User Equipment, UE, wherein the first request comprises an identifier of the UE; obtain (Fig. 1, step 2) a UE IP address assigned for a packet data unit (PDU) session of the UE based on the identifier of the UE; send (Fig. 1, step 2) a second request for the public IP address and port of the UE to a User Plane Function, UPF, wherein the second request comprises the UE IP address of the UE;receive (Fig. 1, step 3), from the UPF, a response to the second request that comprises either a NATed public IP address and port of the UE or all NAT mappings related to the UE IP address; and send (Fig. 1, step 4), to the NF / AF, a response to the first request comprising either the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address.

50. The network node of claim 49, wherein the processing circuitry is further configured to cause the network node to perform the method of any of claims 35 to 46.

51. A method performed by a User Plane Function, UPF, the method comprising: receiving (Fig. 1, step 2), from a network node, a request for either a public IP address and port of a UE or all Network Address Translated, NAT, mappings related to the UE IP address, wherein the request comprises a UE IP address of the UE; obtaining (Fig. 1, step 3) a NATed public IP address and port based on the received UE IP address of the UE or all NAT mappings related to the received UE IP address; and sending (Fig. 1, step 3), to the network node, a response to the request that comprises either the NATed public IP address and port of the UE or the NAT mappings related to the UE IP address.

52. The method of claim 51, wherein the request further comprises information indicative of one or more public IP addresses for one or more remote endpoints.

53. The method according to claim 52, wherein the UPF obtains the NATed public IP address and port of the UE and the response to the request comprises the NATed public IP address and port of the UE when the request further comprises information indicative of one or more public IP addresses for the one or more remote endpoints.

54. The method of claim 52 or 53, wherein the one or more remote endpoints are one or more AF endpoints.

55. The method of any of claims 52 to 54, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises an identifier associated to the one or more public IP addresses for the one or more remote end points.

56. The method of any of claims 52 to 54, wherein the information indicative of the one or more public IP addresses for the one or more remote endpoints comprises a list of the one or more public IP addresses for the one or more remote endpoints.

57. The method of any of claims 52 to 54, wherein obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address comprises obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE that are mapped to a destination IP address that corresponds to one of the one or more public IP addresses for the one or more remote endpoints.

58. The method of claim 51, wherein obtaining (Fig. 1, step 3) the NATed public IP address and port of the UE or all NAT mappings related to the UE IP address comprises obtaining (Fig. 1, step 3) all NAT mappings related to the UE IP address, and the response sent to the network node comprises the NAT mappings related to the UE IP address.

59. The method of any of claims 51 to 58, wherein the request further comprises a data network name.

60. The method of claim 59, wherein the request further comprises a network slice identifier.

61. A network node adapted to: receive (Fig. 1, step 2), from a network node, a request for either a public IP address and port of a UE or all Network Address Translated, NAT, mappings related to the UE IP address, wherein the request comprises a UE IP address of the UE; obtain (Fig. 1, step 3) a NATed public IP address and port based on the received UE IP address or all NAT mappings related to the received UE IP address; andsend (Fig. 1, step 3), to the network node, a response to the request that comprises either the NATed public IP address and port of the UE or the NAT mappings related to the received UE IP address.

62. The network node of claim 61, further adapted to perform the method of any of claims 52 to 60.

63. A network node comprising processing circuitry (404; f504) configured to cause the network node to: receive (Fig. 1, step 2), from a network node, a request for either a public IP address and port of a UE or all Network Address Translated, NAT, mappings related to the UE IP address, wherein the request comprises a UE IP address of the UE; obtain (Fig. 1, step 3) a NATed public IP address and port based on the received UE IP address or all NAT mappings related to the received UE IP address; and send (Fig. 1, step 3), to the network node, a response to the request that comprises either the NATed public IP address and port of the UE or the NAT mappings related to the received UE IP address.

64. The network node of claim 63, wherein the processing circuitry is further configured to cause the network node to perform the method of any of claims 52 to 60.

Citation Information

Patent Citations

  • UE identification using its source IP address

    WO2022039835A1