Method, apparatus and computer program

A UDP proxy in 5G networks manages encrypted media streams by transmitting Application Metadata, addressing the challenge of suboptimal QoS handling and UE power management for encrypted media streams.

WO2025176720A1PCT designated stage Publication Date: 2025-08-28NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/054438
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-23
Filing Date
2025-02-19
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

In 5G networks, the inability to detect and manage PDU Sets and End of Data Burst indicators for encrypted media streams, such as those using QUIC, due to the encryption of relevant header information, results in suboptimal Quality of Service (QoS) handling and UE power management.

Method used

Implementing a UDP proxy within the network to facilitate the transmission of Application Metadata, allowing the network to identify PDU Sets and End of Data Bursts by leveraging Application Metadata Semantics, even in end-to-end encrypted channels.

Benefits of technology

Enables optimized PDU Set-based QoS handling and End of Data Burst detection, ensuring efficient delivery of media streams and effective UE power management even in encrypted environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025054438_28082025_PF_FP_ABST
    Figure EP2025054438_28082025_PF_FP_ABST
Patent Text Reader

Abstract

An apparatus comprising: means for controlling an application to send application data over an encrypted channel to a user equipment; means for sending Application Metadata that can be understood by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; means for generating a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading the Application Metadata; means for sending the message to a core network entity.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD, APPARATUS AND COMPUTER PROGRAM

[0002] TECHNICAL FIELD

[0003] This disclosure relates to methods, an apparatus and computer programs, and in particular - but not exclusively - to methods, apparatus and computer programs relating to providing metadata for application data.

[0004] BACKGROUND

[0005] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0006] Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 4G (4thGeneration), 5G (5th Generation) standards provided by 3GPP.

[0007] SUMMARY

[0008] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.

[0009] According to a first aspect, there is provided a method comprising: controlling an application to send application data over an encrypted channel to a user equipment; sending Application Metadata that can be understood by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; generating a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading the Application Metadata; sending the message to a core network entity. According to some examples, Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

[0010] According to some examples, the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

[0011] According to some examples, the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

[0012] According to some examples, the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.

[0013] According to some examples, the information indicative of a type of transport used indicates that UDP proxy is used as the intermediate proxy.

[0014] According to some examples, the application data sent over the encrypted channel to the user equipment comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more real-time media streams and each application data unit is associated with the Application Metadata for their delivery to the user equipment.

[0015] According to some examples, the intermediate proxy comprises a UDP proxy and the application data is sent over the encrypted channel to the user equipment via the UDP proxy

[0016] The method may be performed by an apparatus.

[0017] The apparatus may comprise means for implementing the method.

[0018] The apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods discussed in relation to the first aspect. The apparatus may implement an Application Function and / or Application Server.

[0019] According to a second aspect, there is provided a method comprising: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; determining, based on operator policy, that the network entity is authorized to provide the Application Metadata semantics information; generating a message comprising at least one of the Application Access Rule and the Application Metadata semantics information for reading the Application Metadata; sending the message to a core network entity.

[0020] According to some examples, the core network entity comprises a Unified Data Repository, UDR.

[0021] According to some examples, the method comprises: receiving, from a Session Management Function, SMF, a subscription request for the Application Access Rule and / or Application Metadata semantics information; sending the Application Metadata semantics information to the SMF.

[0022] According to some examples, the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

[0023] According to some examples, the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

[0024] According to some examples, the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

[0025] According to some examples, the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier. According to some examples, the information indicative of a type of transport used indicates that UDP proxy is used.

[0026] According to some examples, the application data, sent over the encrypted channel, comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more realtime media streams and each application data unit is associated with the Application Metadata for their delivery to a user equipment.

[0027] According to some examples, the application data is sent over the encrypted channel via a UDP proxy.

[0028] The method may be performed by an apparatus.

[0029] The apparatus may comprise means for implementing the method.

[0030] The apparatus may implement a Network Exposure Function.

[0031] The apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods discussed in relation to the second aspect.

[0032] According to a third aspect, there is provided a method comprising: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; generating a request that a User Datagram Protocol, UDP, proxy is used for the application data sent over the encrypted channel, wherein the request is generated based on the Application Access Rule and / or the Application Metadata semantics information; sending the request to a User Plane Function, UPF.

[0033] According to some examples, the method comprises: receiving, from the UPF, parameters for the UDP proxy; sending the Application Access Rule and the parameters for the UDP proxy to a User Equipment, wherein the User Equipment is configured to connect to the UDP proxy to receive the application data when a filter condition in the Application Access Rule is met.

[0034] According to some examples, the core network entity comprises a Network Exposure Function NEF, or a Policy Control Function, PCF.

[0035] According to some examples, the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

[0036] According to some examples, the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

[0037] According to some examples, the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

[0038] According to some examples, the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.

[0039] According to some examples, the information indicative of a type of transport used indicates that UDP proxy is used.

[0040] According to some examples, the application data sent over the encrypted channel comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more realtime media streams and each application data unit is associated with the Application Metadata for their delivery to a user equipment.

[0041] The method may be performed by an apparatus.

[0042] The apparatus may comprise means for implementing the method.

[0043] The apparatus may implement a Session Management Function. The apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods discussed in relation to the third aspect.

[0044] According to a fourth aspect, there is provided a method comprising: for receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; allocating resources for a User Datagram Protocol, UDP, proxy to be used as the intermediate proxy; sending, to the network entity, parameters for the UDP proxy.

[0045] According to some examples, the method comprises: using the metadata semantics information to negotiate how the Application Metadata is to be received from an application server; sending the application data to a user equipment, wherein the Application Metadata is used to map the application data to a specific Quality of Service, QoS, treatment in a network and to determine metadata to be sent along the application data to an Access Network, wherein the application data is mapped to the QoS treatment by applying a specific QoS threshold level or selecting a specific QoS Enforcement Rule.

[0046] According to some examples, the network entity comprises an SMF.

[0047] According to some examples, the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

[0048] According to some examples, the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

[0049] According to some examples, the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata. According to some examples, the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.

[0050] According to some examples, the information indicative of a type of transport used indicates that UDP proxy is used.

[0051] According to some examples, the application data sent over the encrypted channel comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more realtime media streams and each application data unit is associated with the Application Metadata for their delivery to a user equipment.

[0052] The method may be performed by an apparatus.

[0053] The apparatus may comprise means for implementing the method.

[0054] The apparatus may implement a User Plane Function.

[0055] The apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods discussed in relation to the fourth aspect.

[0056] According to a fifth aspect, there is provided a method comprising: receiving, from a core network entity, an Application Access Rule and information for a UDP proxy; determining whether a condition in the Application Access Rule is met; connecting to the UDP proxy when the condition in the Application Access Rule is met; for receiving, using the UDP proxy, application data.

[0057] According to some examples, the Application Access Rule and UDP information are received in a Non-Access Stratum, NAS, Protocol Data Unit, PDU, session establishment accept or in NAS PDU session modification request.

[0058] According to some examples, determining whether the condition in the Application Access Rule is met comprises determining whether uplink data to be sent from the user equipment matches a description in the Application Access Rule . According to some examples, the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

[0059] According to some examples, the Application Access Rule indicates that the UDP proxy is to be used.

[0060] According to some examples, the application data comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more real-time media streams and each application data unit is associated with Application Metadata for their delivery to the user equipment.

[0061] According to some examples, the method comprises communicating with an application server via the UDP proxy.

[0062] The method may be performed by an apparatus.

[0063] The apparatus may comprise means for implementing the method.

[0064] The apparatus may comprise a User Equipment.

[0065] The apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any of the methods discussed in relation to the fifth aspect.

[0066] According to an aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.

[0067] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.

[0068] According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods. In the above, many different aspects have been described. It should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above.

[0069] Various other aspects are also described in the following detailed description and in the attached claims.

[0070] In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above.

[0071] DESCRIPTION OF FIGURES

[0072] Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying Figures in which:

[0073] FIG. 1 shows a representation of a communication network comprising a 5thgeneration communication network;

[0074] FIG. 2 shows an example network architecture;

[0075] FIG. 3A shows an example datagram payload;

[0076] FIG. 3B shows an example datagram payload;

[0077] FIG. 4 shows an example message flow;

[0078] FIG. 5 shows an example message flow;

[0079] FIG. 6 shows an example message flow;

[0080] FIG. 7 shows an example message flow;

[0081] FIG. 8 shows an example method performed by an Application Function or Application Server;

[0082] FIG. 9 shows an example method performed by a Network Exposure Function;

[0083] FIG. 10 shows an example method performed by a Session Management Function;

[0084] FIG. 11 shows an example method performed by a User Plane Function;

[0085] FIG. 12 shows an example method performed by a User Equipment;

[0086] FIG. 13 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments;

[0087] FIG. 14 shows a representation of an apparatus according to some example embodiments; and

[0088] FIG. 15 shows a schematic representation of a non-volatile memory medium storing instructions which when executed by a processor allow a processor to perform one or more of the steps of the methods disclosed herein. DETAILED DESCRIPTION

[0089] When sending application data between application endpoints over an encrypted channel (e.g., an end-to-end (E2E) encrypted channel) the network in the middle is not able to read the application data., However, an application endpoint can share metadata about the application data with the network allowing the network to better manage the delivery of the application data (e.g., to apply a specific Quality of Service treatment for it).

[0090] An example of data that could be sent over an encrypted channel is video traffic, which is a significant portion of overall Internet traffic. Video encoders generate a set of different types of frames (such as l-frames or P-frames) or slices that are sent over a network using a media transport protocol (for example, Real-time Transport Protocol, RTP). For Extended Reality and Media Services, XRM, 3GPP, Rel-18 has specified a mechanism to handle video (or other similar) traffic called Application aware QoS. Typically, frames or slices are large such that they are sent over the network fragmented into many Internet Protocol (IP) packets which in the 5G System are treated as PDUs (Protocol Data Units). Instead of handling just individual PDUs, the PDUs carrying the same frame or slice can be identified as a PDU Set.

[0091] With this approach, the 5G System (Core and especially Access Network) can provide PDU Set based Quality of Service (QoS) handling for the traffic. This can be based on PDU Set specific QoS parameters (e.g., PDU Set Delay Budget, PSDB, PDU Set Error Rate, PSER, PDU Set Integrated Handling Indication, PSI HI) which are provided to the Access Network (e.g. Radio Access Network RAN) via the control plane upon a request by an Application Function or Application Server. Handling the traffic can also be based on other PDU Set Information such as PDU Set Importance or Size which are carried as metadata over the User Plane along with the PDUs themselves. For downlink traffic, the User Plane Function (UPF) detects the set of IP packets belonging to a PDU Set and provides the corresponding information over 3GPP user plane protocol (GTP-u) to the 3GPP access network (e.g. RAN) that can then apply PDU Set based QoS, accordingly.

[0092] The PDU Set detection is possible with RTP based on specific RTP headers used in the media stream between AS (Application Server) and UE which include PDU Set related information. However, this will be challenged when media is sent over a transport protocol that encrypts all the relevant header information. For example, with Quick UDP Internet Connections, QUIC, where the QUIC payloads are end-to-end encrypted, the UPF cannot detect or read the PDU Set information. When the application endpoints use an E2E encrypted channel through the network, it is advantageous (e.g., in some use cases necessary) to develop an architecture, protocol, and mechanism to allow, enable or otherwise facilitate a system (e.g., a 5G system) to receive metadata (e.g., identification metadata) from the application to apply the PDU Set concept in the system. Examples provide a system (e.g., a system that is part of a 5G System) that does not access the end-to-end secured application data and keeps the metadata for the application data secured between the application and the 5G System. As such application data can be secured between a UE and an AF / AS via a UDP proxy in a UPF.

[0093] In addition to PDU Set based QoS handling of the traffic, a similar issue applies to the detection of the end of a data burst (the last packet within a burst of packets), which the UPF is supposed to perform for downlink (DL) direction to provide an End of Data Burst indicator to the RAN. This detection also relies on reading information from packet headers such as RTP.

[0094] In the following various example embodiments are explained with reference to communication devices (e.g., UEs) that are capable of communication with a communications network. Before explaining in detail the embodiments of the methods and apparatuses of the present disclosure, a communications network comprising a 5thgeneration communication system (5GS), a radio access network and a core network (5GC) thereof, are briefly explained with reference to FIG. 1.

[0095] FIG. 1 shows a schematic representation of a communications network comprising a cellular or mobile communication system (e.g., a 5G communication system (5GS), and data network. The 5GS may comprise a radio access network such as a 5G radio access network (5G-RAN) or next generation radio access network (NG-RAN), a 5G core network (5GC). An application function may be deployed in the 5GS as trusted application function or may be deployed or hosted on one or more application servers of the data network. Such application functions are untrusted application functions. The 5GS connects a UE to a data network via the access network and the 5GC (e.g., a UPF of the 5GC).

[0096] The 5GC may comprise the following network functions: Network Slice Selection Function (NSSF); Network Exposure Function; Network Repository Function (NRF); Policy Control Function (PCF); UDM; Application Function (AF); Authentication Server Function (AUSF); an AMF; and Session Management Function (SMF), and a user plane function (UPF). FIG. 1 also shows the various interfaces (N1 , N2 etc.) that may be implemented between the various elements of the system. Some examples described herein provide a method for an AF or AS to request a proxy to be instantiated in certain UPF(s) to serve traffic to specific services. Further, some examples provide a method for one or more UEs in the system to be configured to use the proxy when connecting to the specific services. Some examples provide a method for providing configuration information in the system to the relevant UPF(s) and / or UE(s). Some examples provide information to the UE to instruct when to use the proxy and for which service the proxy should be used for.

[0097] Some examples also provide a method for a UPF and AF / AS to negotiate what metadata each end supports and how metadata can be carried in a HTTP tunnel.

[0098] When media and related protocol header information usable for PDU Set identification are end-to-end encrypted, (for example, information within QUIC protocol payload), any on path transit nodes in the network cannot access the PDU Set information. Considering a 5G network as an example, this would mean that the UPF is not able to detect the PDU Set information or end of data burst indication. Consequently, XRM application would not receive optimized handling from the network, as the network will not be able to apply PDU Set based QoS or End of Data Burst based UE power saving for the media traffic.

[0099] XRM traffic may including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units. Each media stream of the one or more real-time media streams and each application data unit is associated with Application Metadata for their delivery in a network (e.g., to delivery to a user equipment).

[0100] Application Metadata is a generic container that provides useful information about application data (for example, UDP payload). This information is useful to UPF to detect a UDP payload and treat accordingly. Application Metadata can be used to manage application data, for example for detecting application data and applying QoS thresholds to the detected application data.

[0101] In the XRM context, Application Metadata can contain PDU Set Information and End of Data burst Information. The semantics and encoding are specified as 3GPP TS 26.522. In some examples, a total size of the Application Metadata is 64 bits. However, Application Metadata can be any number of data and encoding, and this can be decided by an implementor of an AS and / or UPF to decide. Application Metadata Semantics information specifies header fields and encoding that is used to create Application Metadata by AS. This information can be provided to a UPF by AS / AF via in-band signalling or control plane approach. The Application Metadata semantics information may comprises instructions for how applications controlled by an AS / AF can send Application Metadata to the intermediate proxy. The Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata. The information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier. The information indicative of a type of transport used may indicate that a UDP proxy is used.

[0102] Application Metadata Semantic Identifier is defined to give identification of specific Application Metadata Semantics. This identifier is provided along with Contextld when Context ID is registered with AS. For example, Application Metadata Semantic Identifier can be like this [3gpp-defined-ts26.522-v18], In this case, 3GPP TS26.522 specified PDU Set Information and End of Data burst information along with encoding will be respected when AS sends Application Metadata.

[0103] An Application Access Rule (AAR) can be provided to a system (e.g., 5GS) to create a User Datagram Protocol, UDP, proxy and for the UE to use the UDP proxy. The AAR may be provided to one or more core network entities of a 5GS. The AAR may be provided by an AF or AS. An AAR may comprise at least one of: application Identifier; application addressing information; and proxying information to reach the application. An example skeleton for an AAR may correspond to:

[0104] • Application identifier for UE e.g. Application identifier for OS X = xrm.app.example.com, Application identifier for OS Y = xrm.Osy-app.example.com, [if different UE OS would use different application identifiers] 5GX application identifier: xyz [if 5G0 e.g. for PCF, CHF would use different application identifier than UE(s)]

[0105] • Protocol: UDP

[0106] • Transport Descriptor: UDP proxy

[0107] According to some examples, when an SMF receives the AAR, the SMF requests the UPF (e.g., over N4 interface) to provision UDP proxy with connect-UDP option (for example in Packet Forwarding Control Protocol (PFCP) Session Modification request message or in in PFCP Session establishment request message). The user data can be sent using UPF as UDP proxy using UDP protocol. The UPF can send to the SMF the UDP proxy IP address and port number to use for this application and the PDU Session. This can be done over N4 in PFCP Session Establishment / Modification Response message(s). Based on this information, the S F may provide the updated AAR to the UE via NAS message. The updated AAR may have the following example skeleton:

[0108] • Application identifier for UE e.g. Application identifier xrm.app.example.com, Application identifier

[0109] • Protocol: UDP

[0110] • Transport Descriptor: UDP proxy

[0111] • UDP proxy IP address and Port number

[0112] The AAR may be provided by the SMF to the UE e.g. in NAS PDU Session establishment accept message or in NAS PDU Session modification request message.

[0113] As discussed above, when application endpoints use an E2E encrypted channel such as a QUIC connection for their communication through the network, it is useful to provide PDU set, end of data burst identification related metadata or other metadata from the application to the UPF. In the following, in case of XRM, Application Metadata Semantics may include PDU set Information and End of Data Burst but can also contain the type of PDU (to distinguish e.g. Real-time Transport Protocol (RTP) from RTP Control Protocol (RTCP) from Session Traversal Utilities for NAT (STUN) flows). The PDU Set detection is possible with RTP based on specific RTP headers used in the media stream between AS (Application Server) and UE which include PDU Set related information. However, this will be challenged when media is sent over a transport protocol that encrypts all the relevant header information. For example, with QUIC, where the QUIC payloads are end-to-end encrypted, the UPF cannot detect or read the PDU Set information. Currently, IETF is working on standardizing two approaches for real-time media over QUIC: Media over QUIC (MoQ) and RTP over QUIC, where both protocols would utilize special solution(s) to provide the PDU Set information to the UPF.

[0114] Some examples described herein allow, enable, or otherwise fcailitate the instantiation of a proxy in certain UPF(s) to serve one or more services, requested by their associated AFs, and to configure UE(s) to use the instantiated proxy. This can be performed by:

[0115] • AF providing AAR (Application Access Rule) information to 5G system (e.g., to one or more core network entities of a 5G system), via extending existing API or via new API, as described in procedure alternatives below. Alternatively, the information indicating the AAR information is provided to the 5G System by another method.

[0116] • Information indicating the AAR provided by AF or by other means can be further provided to the SMF. Based on the AAR information, the SMF may:

[0117] Request UPF to instantiate a (UDP) proxy for one or more requested services, start to perform proxying UE traffic to any Application Servers (AS’s) of those services and to report back to SMF the addressing information of the (UDP) proxy;

[0118] Provide AAR rule to the UE over NAS, where AAR rule is generated based on AAR information received from AF and (UDP) proxy addressing information provided by the UPF hosting the (UDP) proxy;

[0119] AAR rules sent to the UE over NAS ensure that the UE will use UDP proxy in the network where relevant, i.e., only when contacting the services identified in the rule (and will not use it when not relevant, i.e., when contacting a service not included in any rule).

[0120] Some examples describe a proxy operation with HTTP connect method for negotiating where metadata each end (UPF / proxy at one end and AS at the other end) supports, and how metadata is carried in the HHTP tunnel. A first example mechanism is Application Programming Interface (API) based, where an AF provides “Application Metadata Semantics” that could be used by UPF eventually to properly read metadata sent in-band from AS to the proxy in UPF. This information may be in scope of entire service (applies to all proxied UE connections to all AS’s of the service) or be limited to a specific UE-to-AS proxied connection. A second example mechanism may comprise in-band negotiation. AS / AF can negotiate, using a HTTP header, with UPF Application Metadata Semantic ID, where the ID is used to identify a particular semantics when multiple of the metadata semantic is available, in-band.

[0121] FIG. 2 shows an example method for providing a UDP proxy. A UDP payload may be augmented with additional data, as discussed in RFC 9298. A Context ID value of zero (0) is reserved for the UDP payload. Non-zero Context IDs can be generated dynamically and registered between peers. The Context ID registration process can be performed using HTTP headers fields or capsule protocol [RFC 9297], This context ID can be used to extend the CONNECT-UDP as defined by RFC 9298.

[0122] Using the flexibility provided by RFC 9298, at 201 UE 202 sends a request to initiate a tunnel with “connect-udp” upgrade token to UPF 204 (i.e. a UDP proxy) and specify the targeted AS 206 information in the “target_host” and “target_port”. DNS resolution of the request sent at 201 may be performed at 203, to address AS 206 (e.g., if required). UPF 204 understands the request received at 201 for session establishment (e.g., XRM media session establishment) and at 205 sends a http request to AS 206 with the “connect-udp” upgrade token, and the target_port is the desired port number (which is by default 443). When AS receives the tunnel request from the UPF with “target_host” corresponding to a localhost, it understands the request aims to create a tunnel to reach a local application.

[0123] FIG. 2 shows (at 201) UE 202 initiating a HTTP / 3 tunnel towards AS 206 via UPF 204. UE 202 may act as a HTTP client. UPF 204 behaves as a UDP proxy and AS 206 acts as a HTTP server.

[0124] When UE 202 sends the CONNECT request to UPF 204 at 201 , UPF 204 will consequently create another HTTP tunnel towards AS 206 to forward UE 202’s UDP payload. UPF 204 selects a non-zero Context ID for this tunnel towards AS 206 and registers that via a HTTP header field (or via capsule protocol). This context ID can be dynamically selected.

[0125] UPF 204 uses the HTTP header (‘Application Metadata’) to register the selected Context ID. The HTTP header is an Item structured Field [as discussed in RFC8941], Presence of “Application-metadata” HTTP header in the request will indicate the support of Application Metadata by UPF 204. The HTTP header value will contain the selected Context ID. An example of “Application-metadata” HTTP header could be as following if the selected Context ID 20 -

[0126] Application-metadata : 20;

[0127] Upon receiving the connect request from UPF 204 with “Application-metadata” HTTP header, AS 206 understands the request to use this proposed method and in its response at 207 AS 206 replies with the context ID it selects for this communication. For example, it can respond with:

[0128] Application-metadata : 20;

[0129] Upon receiving this response from AS 206, UPF 204 understands the usage of the proposed HTTP datagram payload with metadata in this context is complete and agreed. From this point, AS 206 tunnels the UDP payload in the HTTP datagram to UPF 204. The response from AS 206 sent at 207 can be forwarded from UPF 204 to UE 202 at 209. Application Metadata can be included within a HTTP datagram and sent to UPF 204 at 211. Two options for including metadata in a UDP Proxying HTTP datagram payload with metadata are shown in FIG. 3A and 3B.

[0130] In a first option, shown in FIG. 3A, the UDP-proxying HTTP datagram payload comprises a Context ID, the metadata and a UDP proxying payload. In this example, the content of the metadata and the length of the metadata may be known in advance between UPF 204 and AS 206.

[0131] In a second option, shown in FIG. 3B, the metadata length is provided as a separate structure element in the HTTP datagram and the Application layer metadata is encoded in the tunnelled UDP payload (for example, at the beginning or end of the UDP payload). UPF 204 then reads the information form the tunnelled UDP payload according to the length specified. This extension can be extended, as the Application layer metadata length can determine how much metadata is encoded.

[0132] Returning to FIG. 2, whether the first option (FIG. 3A) or second option (FIG. 3B) is used, at 211 the metadata is sent with the UDP proxying HTTP datagram from AS 206 to UPF 204. At 213, the UDP Proxying HTTP datagram Payload is then sent without the metadata from UPF 204 to UE 202.

[0133] Where there are multiple encoding formats or different versions of Application Metadata defined, a HTTP header sent from UPF to AS may be used to indicate which Application Metadata encoding version and / or format is used to a data session. An example of such a HTTP header is:

[0134] Application-metadata : context-id=42; encoding=Application Layer Semantic Identifier; r;

[0135] As such, in-band signalling can be used to indicates which Application Metadata encoding version and / or format is used to a data session.

[0136] Another approach is to use a control plane approach, where informing what type of Application Metadata is used is supported in user plane traffic (i.e; HTTP datagram tunnel from AS to UPF) and is performed by AF to 5G system via NEF. The Name (like 3gpp-defined-encoding- number explained in in-band signaling) can be shared from AF. This information finally is delivered to UPF. Therefore, the UPF can understand what type of Application Metadata presents in the HTTP datagram.

[0137] FIG. 4 and FIG. 5 show a first example method for providing rules, such as AAR discussed above, to an SMF. The first example method can also be used to sync User Plane entities to use the UPF proxy. FIG. 6 shows a second example method for show a second example method for providing rules, such as AAR discussed above, to a PCF (which can then provide the rules to an SMF as shown in FIG. 7). The second example method can also be used to sync User Plane entities to use the UPF proxy.

[0138] Note that while the provisioning of Application Metadata Semantics from AF to the 5GS could be generic to any application-aware case, however in the following the special case of XRM applications is considered as an example, i.e. XRM semantics or XRM metadata semantics (used interchangeably) and their provision are considered.

[0139] In the first example method shown in FIG. 4 and FIG. 5 , XRM Semantics along with AAR are provided independently of QoS information and before PDU sessions are established. A dedicated (not QoS related) API is used for AF to provide 5GS with AAR and XRM metadata semantics.

[0140] In the second example method shown in FIG. 6, XRM Semantics along with AAR are provided along with QoS information before PDU sessions are established.

[0141] FIG. 7 then shows how the first example method and the second example method into a PDU session establishment procedure as well as the modifications used to allow, enable, or otherwise facilitate the instantiation of a proxy in certain UPF(s) to serve one or more services, requested by their associated AFs, and to configure UE(s) to use the instantiated proxy.

[0142] Note that it is possible for AS and UPF to communicate XRM semantics over the HTTP connection as described above.

[0143] In the first example method shown in FIG. 4 and 5, a dedicated (not QoS related) API is used for AF to provide 5GS with AAR and XDRM metadata semantics.

[0144] At 417, AF 412 uses a service to send AAR and XRM metadata semantics to NEF 410. The service may comprise a Create / Update / Delete request message. The service may comprise Nnef_AARManagement_Create / Update / Delete service. This information can then be updated to SMF(s) that hace subscribed to an AAR management service using Nnef_AARManagement_Subscribe service operation (discussed below with respect to FIG. 5).

[0145] The AAR and XRM metadata semantics provided by AF 412 may correspond to:

[0146] • Application identifier for OS X e.g. xrm.app.example.com, Application identifier for OS Y e.g. xrm.OSY-app.example.com;

[0147] • 5GX application identifier: xyz [if 5GC e.g. for PCF, CHF would use different application identifier than UE(s)];

[0148] • Protocol: UDP;

[0149] • Transport Descriptor: UDP proxy.

[0150] At 417, AF 412 invokes the Nnef_AARManagement_Create / Update / Delete service.

[0151] At 419, NEF 410 may check that AF 412 is authorized to perform this request and NEF 410 checks if AF 412 is authorised to provision this AAR data based on the operator policies. Besides the information from the AF 412, NEF 410 may determine the sets (set of) impacted Data Network Name (DNN) and Single Network Slice Selection Assistance information (S- NSSAI).

[0152] At 421 , NEF 410 stores the information received at 417 in UDR 408. This may be performed by the Nudr_DM_Create / Update / Delete (DNN+S-NSSAI, one or more sets of AARs) to the UDR to store the corresponding information in the UDR.

[0153] At 423, UDR 408 updates its data storage.

[0154] At 425, UDR 408 sends a response to NEF 410 to confirm that the data has been stored. This may be sent as a Nudr_DM_Create / Update / Delete Response message.

[0155] At 427, NEF 410 sends a response to AF 412 to confirm that the data has been stored. This may be sent as a Nnef_AARManagement_Create / Update / Delete Response message.

[0156] FIG. 5 shows an example method for providing, modifying or removing AAR and / or Application Metadata semantics information for reading Application Metadata to SMF 508. NEF 510 may correspond to NEF 410. At 529, SMF 508 subscribes to NEF 510 for receiving AAR and / or XRM metadata semantics notifications. This may be performed by sending Nnef_AARManagement_Subscribe message with subscription filtering information corresponding to the sets (or set of) DNN+S- NSSAI SMF 508 supports.

[0157] At 531 , a procedure for AAR d / or XRM metadata semantics management is triggered by AF (e.g., AF 412).

[0158] At 533, for impacted DNN+S-NSSAI which have subscribed to the information, NEF 510 sends AAR and / or XRM metadata semantics information. NEF 510 may invoke Nnef_AAR_Management_Notify (AARs, impacted DNN+S-NSSAI) to the SMF(s) 508 which have subscribed to the information. NEF 510 may decide to delay the distribution of AARs or XRM semantics to the SMF(s) 508 for some time to optimize the signalling load.

[0159] At 535, SMF 508 stores the information received to use it for impacted PDU sessions.

[0160] A second example method for providing ARM semantics and / or AAR is shown in FIG. 6. In this example, XRM metadata semantics and / or AAR are provided before PDU sessions are established along with QoS information.

[0161] A NEF API forAF requested QoS fora fora UE or group of UEs not identified by a UE address, (e.g., the 3GPPP-defined Nnef_AF_Request_for_QoS.) may be used. As the UE or group of UEs can be identified without an IP address it implies that the impacted UEs have not yet established a PDU Session to the AF.

[0162] In this example, Nnef_AF_Request_for_QoS refers to all UEs for a specific DNN / S-NSSAI combination. AAR and XRM metadata semantics are passed to 5GC / UE via the Nnef_AF_Request_for_QoS.

[0163] At 637, PCF 614 subscribes to Application data from UDR 608.

[0164] At 639, AF 612 sends a request to reserve resources to NEF 610 (e.g., in a Nnef_AF_Request_QoS_Create request message). The request may comprise at least one of: Flow description(s) or External Application Identifier; QoS reference or individual QoS parameters; Alternative Service Requirements (as described in clause 6.1.3.22 of TS 23.503); all UEs accessing the DNN / S-NSSAI, XRM metadata semantics; Application Access Rule. At 641 , NEF 610 authorizes the AF request with the new content.

[0165] At 643, NEF 610 stores the received information in UDR 608. NEF 610 uses the Nudr_DM service to store the information in UDR 608. The information is stored as Application Data in UDR 608 properly extended. If the AF 612 requested for notifications of Resource allocation status or other events, the NEF 610 includes the information (e.g., required information )for reporting the event, including the Notification Target Address pointing to the NEF 610 or AF 612 and the Notification Correlation ID containing the AF Transaction Internal ID.

[0166] At 645, UDR 608 notifies the PCF(s) 614 that have subscribed with the data received at 643.

[0167] At 647,. NEF 610 replies to AF 612.

[0168] At 639, the PCF(s) 614 identify the active PDU sessions associated with the data received from UDR 608.

[0169] FIG. 7 shows a modified PDU session establishment procedure. XRM metadata semantics and AAR are provided per PDU session once the PDU session is established.

[0170] At 751 , UE 702 request a PDU session to be established.

[0171] At 753, the standard PDU session establishment steps may be performed as described in 3GPP TS 23.502 4.3.2.2.

[0172] At 755, PCF 714 generates a Policy and Charging Control (PCC) and sends to SMF 708. If the first example method described above with respect to FIG. 4 and 5 is used, the PCC rules need not contain the AAR and / or XRM semantics because SMF 708 already has this information based on its subscription with the NEF. If the second example method (at 757) described above with respect to FIG. 6 is used, the PCC rules include the Application Access Rule and / or XRM metadata semantics.

[0173] At 759, steps 8 and 9 of the PDU Session Establishment Procedure described in TS 23.502 - sec 4.3.2.2 are performed.

[0174] 767 shows the establishment of a UDP proxy. At 761 , based on AAR from PCC, or locally available information, SMF 708 instructs the UPF 704 to activate the UDP Proxying functionality for this PFCP session using U DP-Proxying control information. It also sends XRM metadata semantics to UPF in the PFCP Session Establishment Request.

[0175] At 763, UPF 704 allocates resources for UDP proxy and ay 765 returns the corresponding UDP Proxy Parameters (of the UDP proxy - i.e. IP address and Port number) to SMF 708 in a response message (e.g., PFCP Session Establishment Response).

[0176] At 769 and 771 , SMF 708 may send the AAR with the newly received UDP proxy server info from UPF 704 to UE 702 e.g. in NAS PDU Session establishment accept or in NAS PDU Session modification request.

[0177] At 773, when a filter condition received in the AAR matches, UE 702 issues n UDP connect to the U DP-proxy in UPF 704 based on application access rule received from SMF 708. The connection terminates in the established UDP proxy at 775. At 777, UPF 704 issues an UDP connect to AS 706 . UE can now send uplink data using UDP proxying technique towards UDP proxy in UPF 704. At 777, UDP proxy in UPF sends the UL user plane data to AS 706 (which many comprise a media server, for example).

[0178] At 779, AS 706 sends downlink data (e.g., application data) to the UDP proxy in UPF 704. AS 706 sends PDU along with XRM metadata (e.g., in HTTP datagram). The downlink data may be sent via an encrypted channel. The downlink data may be sent over an encrypted channel to the user equipment via the UDP proxy in UPF 704.

[0179] At 781, UPF 704 receives UDP proxying payload and XRM metadata container. The UDP proxy in UPF 704 can understand the Application Metadata by using the AAR and Application Metadata semantics information. Then, UPF 704 extracts the PDU-set information from the XRM metadata container that is encapsulated in HTTP datagram according to the provisioned XRM metadata semantics, and generates GTP-U header based on the received PDU set information, before forwarding UDP proxying payload to UE 702 through an access network 718 (e.g,, 5G AN / RAN that utilize the PDU set information at 785 to provide proper QoS to the PDU.

[0180] FIG. 8 shows an example method flow. The method may be performed by an AF such as AF 412 or AF 612, or may be performed by an AS such as AS 706 or AS 206.

[0181] At 800, the method comprises controlling an application to send application data over an encrypted channel to a user equipment. At 802, the method comprises sending Application Metadata that can be understood by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel.

[0182] At 804, the method comprises generating a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading the Application Metadata.

[0183] At 806, the method comprises sending the message to a core network entity

[0184] FIG. 9 shows an example method flow. The method may be performed by an NEF such as NEF 410, 510 or 610, for example.

[0185] At 900, the method comprises receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel.

[0186] At 902, the method comprises determining, based on operator policy, that the network entity is authorized to provide the Application Metadata semantics information.

[0187] At 904, the method comprises generating a message comprising at least one of the Application Access Rule and the Application Metadata semantics information for reading the Application Metadata.

[0188] At 906, the method comprises sending the message to a core network entity.

[0189] FIG. 10 shows an example method flow. The method may be performed by an SMF such as SMF 508 or SMF 708, for example.

[0190] At 1000, the method comprises receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel.

[0191] At 1000, the method comprises generating a request that a User Datagram Protocol, UDP, proxy is used for the application data sent over the encrypted channel, wherein the request is generated based on the Application Access Rule and / or the Application Metadata semantics information.

[0192] At 1000, the method comprises sending the request to a User Plane Function, UPF

[0193] FIG. 11 shows an example method flow. The method may be performed by UPF such as UPF 204 or 704, for example.

[0194] At 1100, the method comprises receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel.

[0195] At 1100, the method comprises allocating resources for a User Datagram Protocol, UDP, proxy to be used as the intermediate proxy.

[0196] At 1100, the method comprises sending, to the network entity, parameters for the UDP proxy.

[0197] FIG. 12 shows an example method flow. The method may be performed by UE such as UE 202 or 702, for example.

[0198] At 1200, the method comprises receiving, from a core network entity, an Application Access Rule and information for a UDP proxy.

[0199] At 1202, the method comprises determining whether a condition in the Application Access Rule is met.

[0200] At 1204, the method comprises connecting to the UDP proxy when the condition in the Application Access Rule is met. At 1206, the method comprises receiving, using the UDP proxy, application data.

[0201] FIG. 13 illustrates an example of an apparatus 1300 implementing or comprising at least the session management of the core network of the communication network illustrated on FIG. 1. The apparatus 1300 may comprise at least one random access memory (RAM) 1311 a, at least on read only memory (ROM) 1311b, at least one processor 1312, 1313 and a network interface 1314. The at least one processor 1312, 1313 may be coupled to the RAM 1311a and the ROM 1311 b. The at least one processor 1312, 1313 may be configured to execute an appropriate software code 1315 of the network entities described herein. Execution of the software code 1315 of the network entities described herein (or execution of instructions of the software code 1315) may for example may cause the apparatus to perform method shown in FIG. 8 to 12. The software code 1315 may be stored in the ROM 1311b. The apparatus 1300 may be interconnected with another apparatus 1300 for controlling other network functions of the 5GC. In some embodiments, one or more network functions of the 5GC is deployed or hosted on an apparatus 1300. In alternative embodiments, the apparatus may include software code of additional network functions of the core network of the communication network. The apparatus 1300 may comprise a computing device (e.g., a server), a computing system, such as a distributed computing system, or a virtual machine provided by a cloud computing system. In some examples, the apparatus 1300 may comprise a cloud computing system (e.g., a cloud core network) that comprises the session management function, and other network functions of the core network shown in FIG. 1.

[0202] FIG. 14 illustrates an example of a communication device 1400, such as the terminal illustrated on FIG. 1. The communication device 1400 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 1400 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 1400 may comprise a transceiver for transmitting and / or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.

[0203] The communication device 1400 may receive wireless signals (e.g., radio signals) over an air or radio interface 1407 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In FIG. 14 transceiver is designated schematically by block 1406. The transceiver 1406 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi output (MIMO) antenna.

[0204] The communication device 1400 may be provided with at least one processor 1301, at least one memory ROM 1402a, at least one RAM 1402b and other possible components 1403 for use in software and hardware aided execution of tasks it is configured to perform, including control of access to and communications with radio access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices. The at least one processor 1401 is coupled to the RAM 1402b and the ROM 1402a. The at least one processor 1401 may be configured to execute an appropriate software code 1408 (e.g., the at least one processor may execute instructions of the software code 1408). The execution of the software code 1408 may for example allow the communication device to perform one or more operations, including the operations described herein. The software code 1408 may be stored in the ROM 1402a.

[0205] The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. The circuit board, chipsets or system on chip is denoted by reference 1404. The communication device 1400 may optionally have a user interface such as key pad 1405, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of communication device.

[0206] FIG. 15 shows a schematic representation of non-volatile memory media 1500a (e.g. computer disc (CD) or digital versatile disc (DVD)) and 1500b (e.g. universal serial bus (USB) memory stick) storing instructions and / or parameters 1502 which when executed by a processor allow the processor to perform one or more of the steps of any method flow described herein.

[0207] It is understood that references in the above to various network functions (e.g., to an AMF, an AF, a PCF etc.) may comprise apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus comprising a network function may comprise a virtual network function instance of that network function. It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.

[0208] It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.

[0209] It is also noted herein that while the above describes various example embodiments, there are several variations and modifications which may be made to the various example embodiments without departing from the scope of this disclosure.

[0210] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0211] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0212] As used herein, the term “circuitry” may refer to one or more or all of the following:

[0213] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0214] (b) combinations of hardware circuits and software, such as (as applicable):

[0215] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0216] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.”

[0217] This definition of circuitry applies to all uses of the term “means” herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0218] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computerexecutable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.

[0219] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.

[0220] The term “non-transitory,” as used herein, is a limitation of the medium itself (i. e. , tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0221] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

[0222] Various example embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0223] The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments and features thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.

[0224] The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of the disclosure as set forth in the claims. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.

Claims

Claims1. An apparatus comprising: means for controlling an application to send application data over an encrypted channel to a user equipment; means for sending Application Metadata that can be understood by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; means for generating a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading the Application Metadata; means for sending the message to a core network entity.

2. The apparatus according to claim 1, wherein the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

3. The apparatus according to claim 1 or claim 2, wherein the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

4. The apparatus according to any preceding claim, wherein the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

5. The apparatus according to claim 4, wherein the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.

6. The apparatus according to claim 4 or claim 5, wherein: the information indicative of a type of transport used indicates that UDP proxy is used as the intermediate proxy.

7. The apparatus according to any preceding claim, wherein the application data sent over the encrypted channel to the user equipment comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series ofapplication data units, and each media stream of the one or more real-time media streams and each application data unit is associated with the Application Metadata for their delivery to the user equipment.

8. The apparatus according to any preceding claim, wherein the intermediate proxy comprises a UDP proxy and the application data is sent over the encrypted channel to the user equipment via the UDP proxy.

9. A method comprising: controlling an application to send application data over an encrypted channel to a user equipment; sending Application Metadata that can be understood by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; generating a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading the Application Metadata; sending the message to a core network entity.

10. A computer program comprising instructions, which when executed by the at least one processor of an apparatus, cause the apparatus to perform: controlling an application to send application data over an encrypted channel to a user equipment; sending Application Metadata that can be understood by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; generating a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading the Application Metadata; sending the message to a core network entity.

11. An apparatus comprising: means for receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel;means for determining, based on operator policy, that the network entity is authorized to provide the Application Metadata semantics information; means for generating a message comprising at least one of the Application Access Rule and the Application Metadata semantics information for reading the Application Metadata; means for sending the message to a core network entity.

12. The apparatus according to claim 11 , wherein the core network entity comprises a Unified Data Repository, UDR.

13. The apparatus according to claim 11 or claim 12, comprising: means for receiving, from a Session Management Function, SMF, a subscription request for the Application Access Rule and / or Application Metadata semantics information; means for sending the Application Metadata semantics information to the SMF.

14. The apparatus according to any of claims 11 to 13, wherein the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

15. The apparatus according to any of claims 11 to 14, wherein the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

16. The apparatus according to any of claims 11 to 15, wherein the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

17. The apparatus according to claim 16, wherein the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.

18. The apparatus according to claim 16 or claim 17, wherein: the information indicative of a type of transport used indicates that UDP proxy is used.

19. The apparatus according to any of claims 16 to 18, wherein the application data, sent over the encrypted channel, comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more real-time media streams and each application data unit is associated with the Application Metadata for their delivery to a user equipment.

20. The apparatus according to any of claims 16 to 19, wherein the application data is sent over the encrypted channel via a UDP proxy.21 . A method comprising: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; determining, based on operator policy, that the network entity is authorized to provide the Application Metadata semantics information; generating a message comprising at least one of the Application Access Rule and the Application Metadata semantics information for reading the Application Metadata; sending the message to a core network entity.

22. A computer program comprising instructions, which when executed by the at least one processor of an apparatus, cause the apparatus to perform: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; determining, based on operator policy, that the network entity is authorized to provide the Application Metadata semantics information; generating a message comprising at least one of the Application Access Rule and the Application Metadata semantics information for reading the Application Metadata; sending the message to a core network entity.

23. An apparatus comprising: means for receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; means for generating a request that a User Datagram Protocol, UDP, proxy is used for the application data sent over the encrypted channel, wherein the request is generated based on the Application Access Rule and / or the Application Metadata semantics information; means for sending the request to a User Plane Function, UPF.

24. The apparatus according to claim 23, the apparatus comprising: means for receiving, from the UPF, parameters for the UDP proxy; means for sending the Application Access Rule and the parameters for the UDP proxy to a User Equipment, wherein the User Equipment is configured to connect to the UDP proxy to receive the application data when a filter condition in the Application Access Rule is met.

25. The apparatus according to claim 23 or claim 24, wherein the core network entity comprises a Network Exposure Function NEF, or a Policy Control Function, PCF.

26. The apparatus according to any of claims 23 to 25, wherein the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

27. The apparatus according to any of claims 23 to 26, wherein the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

28. The apparatus according to any of claims 23 to 27, wherein the Application Metadata semantics information comprises at least one of: an application identifier; information indicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

29. The apparatus according to claim 28, wherein the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.

30. The apparatus according to claim 28 or claim 29, wherein: the information indicative of a type of transport used indicates that UDP proxy is used.31 . The apparatus according to any of claims 24 to 30, wherein the application data sent over the encrypted channel comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more real-time media streams and each application data unit is associated with the Application Metadata for their delivery to a user equipment.

32. A method comprising: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; generating a request that a User Datagram Protocol, UDP, proxy is used for the application data sent over the encrypted channel, wherein the request is generated based on the Application Access Rule and / or the Application Metadata semantics information; sending the request to a User Plane Function, UPF.

33. A computer program comprising instructions, which when executed by the at least one processor of an apparatus, cause the apparatus to perform: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel;generating a request that a User Datagram Protocol, UDP, proxy is used for the application data sent over the encrypted channel, wherein the request is generated based on the Application Access Rule and / or the Application Metadata semantics information; sending the request to a User Plane Function, UPF.

34. An apparatus comprising: means for receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; means for allocating resources for a User Datagram Protocol, UDP, proxy to be used as the intermediate proxy; means for sending, to the network entity, parameters for the UDP proxy.

35. The apparatus of claim 34, wherein the apparatus comprises: means for using the metadata semantics information to negotiate how the Application Metadata is to be received from an application server; means for sending the application data to a user equipment, wherein the Application Metadata is used to map the application data to a specific Quality of Service, QoS, treatment in a network and to determine metadata to be sent along the application data to an Access Network, wherein the application data is mapped to the QoS treatment by applying a specific QoS threshold level or selecting a specific QoS Enforcement Rule.

36. The apparatus of claim 34 or claim 35, wherein the network entity comprises an SMF.

37. The apparatus according to any of claims 34 to 36, wherein the Application Metadata semantics information comprises instructions for how applications controlled by the apparatus can send Application Metadata to the intermediate proxy.

38. The apparatus according to any of claims 34 to 37, wherein the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

39. The apparatus according to any of claims 34 to 38, wherein the Application Metadata semantics information comprises at least one of: an application identifier; informationindicative of at least one protocol that can be used to provide the Application Metadata; information indicative of a type of transport used for the Application Metadata.

40. The apparatus according to claim 39, wherein the information indicative of at least one protocol that can be used to provide the Application Metadata is associated with a context identifier.41 . The apparatus according to claim 39 or claim 40, wherein: the information indicative of a type of transport used indicates that UDP proxy is used.

42. The apparatus according to any of claims 37 to 41, wherein the application data sent over the encrypted channel comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more real-time media streams and each application data unit is associated with the Application Metadata for their delivery to a user equipment.

43. A method comprising: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel; allocating resources for a User Datagram Protocol, UDP, proxy to be used as the intermediate proxy; sending, to the network entity, parameters for the UDP proxy.

44. A computer program comprising instructions, which when executed by the at least one processor of an apparatus, cause the apparatus to perform: receiving, from a network entity, a message comprising at least one of an Application Access Rule and Application Metadata semantics information for reading Application Metadata, wherein the application data is sent over an encrypted channel with the Application Metadata such that the Application Metadata can be understood only by an intermediate proxy, wherein the Application Metadata can be used to manage the application data sent over the encrypted channel;allocating resources for a User Datagram Protocol, UDP, proxy to be used as the intermediate proxy; sending, to the network entity, parameters for the UDP proxy.

45. A user equipment comprising: means for receiving, from a core network entity, an Application Access Rule and information for a UDP proxy; means for determining whether a condition in the Application Access Rule is met; means for connecting to the UDP proxy when the condition in the Application Access Rule is met; means for receiving, using the UDP proxy, application data.

46. A user equipment according to claim 45, wherein the Application Access Rule and UDP information are received in a Non-Access Stratum, NAS, Protocol Data Unit, PDU, session establishment accept or in NAS PDU session modification request.

47. A user equipment according to claim 45 or claim 46, wherein determining whether the condition in the Application Access Rule is met comprises determining whether uplink data to be sent from the user equipment matches a description in the Application Access Rule .

48. The user equipment according to any of claims 45 to 47, wherein the Application Access Rule comprises at least one of an application Identifier, application addressing information and proxying information to reach the application.

49. The user equipment according to claim 48, wherein: the Application Access Rule indicates that the UDP proxy is to be used.

50. The user equipment according to any of claims 45 to 49, wherein the application data comprises Extended Reality and Media Services, XRM, data including one or more real-time media streams for video, audio, sensory and / or haptic information, wherein the media streams comprises a series of application data units, and each media stream of the one or more real-time media streams and each application data unit is associated with Application Metadata for their delivery to the user equipment.

51. The user equipment according to any of claim 49, comprising:means for communicating with an application server via the UDP proxy.

52. A method comprising: receiving, from a core network entity, an Application Access Rule and information for a UDP proxy; determining whether a condition in the Application Access Rule is met; connecting to the UDP proxy when the condition in the Application Access Rule is met; receiving, using the UDP proxy, application data.

53. A computer program comprising instructions, which when executed by the at least one processor of an apparatus, cause the apparatus to perform: receiving, from a core network entity, an Application Access Rule and information for a UDP proxy; determining whether a condition in the Application Access Rule is met; connecting to the UDP proxy when the condition in the Application Access Rule is met; receiving, using the UDP proxy, application data.