Establishing a VPN connection with an external node

A VPN connection between a telecommunication provider’s NEF and an external node addresses security gaps in 3GPP specifications by providing secure and encrypted communication, enhancing data protection and preventing unauthorized access.

WO2025210640A1PCT designated stage Publication Date: 2025-10-09TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2024/050354
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-03
Publication Date
2025-10-09

Smart Images

  • Figure IN2024050354_09102025_PF_FP_ABST
    Figure IN2024050354_09102025_PF_FP_ABST
Patent Text Reader

Abstract

A first node (110) in a communication network (100) and an external node (120), methods (200; 300) performed by the first node and the external node, a computer program and a computer program product each for the first node and the external node is provided. The first node implements a Network Exposure Function. The first node receives, from an external node implementing an Application Function, a request for establishing a VPN connection between the first node and the external node. If the external node is permitted to utilize the VPN connection based on the request, the first node establishes the VPN connection with the external node. If the external node is not permitted to utilize the VPN connection based on the request, the first node denies the request for the VPN connection with the external node.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ESTABLISHING A VPN CONNECTION WITH AN EXTERNAL NODE

[0002] TECHNICAL FIELD

[0003] The disclosure herein relates to first node implementing a network exposure function and an external node implementing an application function, and provides a method performed by the first node, a method performed by the external node, a corresponding computer program and computer program product each for the first node and the external node.

[0004] BACKGROUND

[0005] A 3rdGeneration Partnership Project (3GPP) Network Exposure Function (NEF) is a node which is responsible for making available network capabilities, to authorized third-party applications and services, in a secure and controlled manner. The NEF enables the exposure, i.e. making available, of network functions, services, and capabilities in a standardized way, allowing external systems and applications to interact with a communication network such as a fifth generation (5G) network and / or a fourth generation (4G) network. The interaction between the NEF and the external systems and / or applications includes accessing data, requesting specific services and utilizing network capabilities securely.

[0006] By providing standardized interfaces, the NEF facilitates the development of applications and / or services that can leverage the functionalities and resources offered by the communication network. The NEF thus enables a more open and flexible environment for developers, allowing the developers to create a diverse range of applications that benefit from the characteristics of the communication network such as high throughput, low latency and high availability.

[0007] A 5G NEF can provide secure and developer-friendly access to 5G network services. The 5GNEF offers a set of application programming interfaces (APIs), comprising a Northbound API (found in 3GPP Technical Specification (TS) 29.522 vl 8.4.0) for external applications to interact with the communication network and a Southbound API (3 GPP TS 29.591 V18.4.0) for communication with various 5G network functions. The 5GNEF acts as a "border gateway" and facilitates communication between external Application Functions (AF) and 5G Network Functions (NFs), which allows third-party authorized applications and / or services to monitor and configure network behavior for different subscribers.

[0008] A Virtual Private Network (VPN) is a technology that establishes a secure and encrypted connection, often over the internet (insecure public network), to connect a device to a private network. The VPN enables protection of data from interception and ensuring online privacy and security. Most preferred way to configure a VPN is using VPN protocol: IP security (IPSec) and Internet Key Exchange (IKE). IPSec is a widely used VPN protocol that provides security through encryption and authentication.

[0009] IKE is a key establishment protocol used in conjunction with IPSec VPNs. IKE is responsible for the negotiation and establishment of security associations between the VPN client and server.

[0010] During IKE negotiation process, a VPN client and a VPN server authenticate each other and exchange cryptographic keys to establish a secure communication channel. The IKE negotiation process involves the use of digital signatures for authentication and the exchange of ephemeral Elliptic Curve Diffie-Hellman (ECDH) keys. Once the IKE negotiation process is successful and the security associations are established, data can be transmitted securely between the VPN client and the VPN server through a VPN tunnel using a protocol such as IPSec. IPSec is used for encryption and integrity checking, while IKE is used for key negotiation and authentication.

[0011] SUMMARY

[0012] A limitation of the current 3GPP technical specifications regarding network extension to partner networks include the lack of comprehensive functionality for securing and extending a telecommunication provider’s network to one or more partner networks. This limitation is particularly concerning when considering the increasing reliance on interworking architectures between 3 GPP cellular networks and other networks such as public Wireless Local Area Network (WLAN), where security measures such as authentication and key agreement need to be extended to ensure secure communication and data exchange. Security is crucial, particularly in scenarios involving sensitive applications like location-based services accessed by security agencies such as a law enforcement agency (LEA). Failing to secure communications between the telecommunication provider’s network to one or more partner networks may expose the telecommunication provider’s network to denial-of-service (DoS) attacks.

[0013] To overcome these limitations, the establishment of a VPN connection between a telecommunication provider’s NEF and an external node at the partner’s network (e.g. an Application Function (AF), a firewall) is advantageous for ensuring secure communication. By implementing a VPN between the telecommunication provider’s NEF and the external node, the telecommunication provider can create a secure and encrypted connection, protecting the data being transmitted. Moreover, for scenarios where the telecommunication provider’s services require interworking with multiple services to access one or more services within the same partner network, VPNs between the NEF and the external node enable seamless and secure network extension, promoting efficient application integration.

[0014] An object of the invention is to improve security in a communication network. This and other objects are met by means of different aspects of the invention, as defined by the independent claims.

[0015] According to a first aspect, a method performed by a first node in a communication network is provided. The first node implementing a Network Exposure Function (NEF). The method comprises receiving a request from an external node implementing an Application Function (AF). The request is for establishing a Virtual Private Network (VPN) connection between the first node and the external node. If the external node is permitted to utilize the VPN connection based on the request, the method comprises establishing the VPN connection with the external node. If the external node is not permitted to utilize the VPN connection based on the request, the method comprises denying the request for the VPN connection with the external node.

[0016] According to a second aspect, a method performed by an external node implementing an AF is provided. The method comprises transmitting a request to a first node in a communication network, wherein the first node implements a NEF. The request is for establishing a VPN connection between the first node and the external node.

[0017] According to a third aspect, a first node in a communication network and wherein the first node implements a NEF is provided. The first node is adapted to receive, from an external node implementing an AF, a request for establishing a VPN connection between the first node and the external node. If the external node is permitted to utilize the VPN connection based on the request, the first node is adapted to establish the VPN connection with the external node. If the external node is not permitted to utilize the VPN connection based on the request, the first node is adapted to deny the request for the VPN connection with the external node.

[0018] According to a fourth aspect, an external node implemented an AF is provided. The network node is adapted to transmit a request to a first node in a communication network. The first node implements a NEF. The request is for establishing a VPN connection between the first node and the external node.

[0019] According to a fifth aspect, a first node implementing a NEF is provided. The first node comprises at least one processing circuitry. The first node comprises at least one memory. The at least one memory is connected to the at least one processing circuitry. The at least one memory storing program code that is executed by the at least one processing circuitry to perform the method according to the first aspect.

[0020] According to a sixth aspect, an external node implementing an AF is provided. The external node comprises at least one processing circuitry. The external node comprises at least one memory. The at least one memory is connected to the at least one processing circuitry. The at least one memory storing program code that is executed by the at least one processing circuitry to perform the method according to the second aspect.

[0021] According to a seventh aspect, a computer program is provided. The computer program comprises instructions which, when executed by at least one processing circuitry of a first node causes the first node to carry out the method according to the first aspect and / or, when executed by at least one processing circuitry of an external node causes the external node to carry out the method according to the second aspect.

[0022] According to an eighth aspect, a computer program product stored on a non-transitory computer readable medium is provided. The computer program product comprises instructions that, when executed by at least one processing circuitry of a first node, causes the first node to perform the method according to the first aspect. Alternatively, or in addition, the computer program product comprises instructions that, when executed by at least one processing circuitry of an external node, causes the external node to perform the method according to the second aspect.

[0023] Advantageously, the disclosure herein provides enhanced confidentiality and integrity of data exchanged between the communication network and the external node. Hereby, enhanced privacy and / or anonymity for users accessing data from the first node is provided. The disclosure herein advantageously improves protection against cyber-attacks and enables improved secure communication. Furthermore, the disclosure herein may advantageously prevent unauthorized access and / or prevents eavesdropping on data (e.g. sensitive data, nonsensitive data) transmitted between the first node and the external node.

[0024] BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The above, as well as additional objects, features and advantages of the invention, will be better understood through the following illustrative and non-limiting detailed description of embodiments of the invention, with reference to the appended drawings, in which:

[0026] Fig. 1 illustrates an embodiment of a communication network and an external node of the invention. Fig. 2 illustrates an embodiment according to a method performed by a first node of the invention.

[0027] Fig. 3 illustrates an embodiment according to a method performed by an external node of the invention.

[0028] Fig. 4 illustrates an embodiment of a signaling diagram of the invention.

[0029] Fig. 5 shows an embodiment of a first node and / or one or more second nodes according to the invention.

[0030] Fig. 6 shows an embodiment of an external node according to the invention.

[0031] Fig. 7 illustrates an embodiment of a computer program product according to the invention.

[0032] All the figures are schematic, not necessarily to scale, and generally only show parts which are necessary in order to elucidate the invention, wherein other parts may be omitted or merely suggested.

[0033] DETAILED DESCRIPTION

[0034] The invention will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0035] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features and advantages of the enclosed embodiments will be apparent from the following description. Establishment of a Virtual Private Network (VPN) between a communication network and an external network increases the security between the two networks. A VPN is created by establishing a virtual point-to-point connection using a tunneling protocol over the two networks.

[0036] Fig. 1 illustrates an embodiment of a communication network 100 according to the invention. The communication network 100 comprises a first node 110 and optionally, one or more second nodes 115. The first node 110 implements a 3rdGeneration Partnership Project (3 GPP) Network Exposure Function (NEF). In an example, the one or more second nodes 115 may be capable of communicating with the first node 110. An external node 120 is placed outside of the communication network 110. The external node 120 may be configured to communicate with the first node 110. The external node 120 implements a 3GPP Application Function (AF). Examples of the first node 110 and / or the one or more second nodes 115 have been provided in relation to the description corresponding to Fig. 5. Examples of the external node 120 have been provided in relation to the description corresponding to Fig. 6.

[0037] The first node 110 is configured / adapted to receive a request from the external node 120 implementing the AF. The request is a request for establishing a VPN connection between the first node 110 and the external node 120. If the external node 120 is permitted to utilize the VPN connection based on the request, the first node 110 is adapted to establish the VPN connection with the external node 120. If the external node 120 is not permitted to utilize the VPN connection based on the request, the first node 110 is adapted to deny the request for the VPN connection with the external node 120.

[0038] In a case wherein the communication network 100 is a telecommunication network, the embodiments herein provide for communication between the first node 110 and the external node 120 (placed in a 3rdparty network such as a partner network) via VPN in combination with a firewall. The VPN connection establishment and the VPN policy and / or key exchange may be automated based upon the request from the 3rdparty network comprising the external node 120. If a 3rdparty network is no longer trusted or if the 3rdparty network is no longer authorized to use the VPN connection, the VPN connection is revoked.

[0039] In a case wherein the communication network 100 is a telecommunication network, the embodiments herein provide for secure communication, increased efficiency and ease of integration if the communication network 100 is to be extended to a 3rdparty network which hosts one or more applications or when access is to be provided to a 3rdparty network which hosts one or more applications. The embodiments herein also provide increased security to the 3rdparty network comprising the external node 120. Also, once the VPN connection is established, one or more applications hosted by the 3rdparty network can be easily, securely, and efficiently accessed by the communication network 100.

[0040] The embodiments herein provide enhanced security even in the case that an application is hosted by the 3rdparty network (e.g. in the external node 120) which uses public Internet since the established VPN connection provides an end-to-end secure connection between the communication network 100 and the 3rdparty network.

[0041] Fig. 2 illustrates an embodiment according to a method performed by a first node 110 of the invention. The method 200 is performed by the first node 110 in a communication network, such as the communication network 100 as described in relation to the description corresponding to Fig. 1.

[0042] The method 200 comprises receiving 205 a request from an external node 120 implementing an AF. The received request is for establishing a VPN connection between the first node and the external node.

[0043] If the external node 120 is permitted to utilize the VPN connection based on the request, the method 200 comprises establishing 215a the VPN connection with the external node 120.

[0044] If the external node 120 is not permitted to utilize the VPN connection based on the request, the method 200 comprises denying 215b the request for the VPN connection with the external node 120.

[0045] The method 200 optionally comprises verifying 210 if the external node 120 is permitted to utilize the VPN connection based on the request. The verification being performed by, for example, i) checking whether the external node 120 is permitted to utilize the VPN connection in a database within the first node 110 or any other node in the communication network 100, ii) checking whether the external node is trusted by the communication network 100 (e.g. if trusted, then the VPN connection may be established with the external node 120), iii) receiving an indication of a permission from another node about the external node (e.g. if another node in the communication network 100 has information about the external node 120 being trusted, the information may be sent to the first node 110).

[0046] Verifying whether the external node is permitted to utilize the VPN connection optionally comprises authenticating the request from the external node and / or authorizing the request from the external node. By authenticating the request, validation is performed about the identity of the external node 120, i.e., verifying credentials. Examples of authentication are using username and password pairs, one-time pins, authentication applications and biometrics. By authorizing the request, the external node is granted / denied permission to access a specific resource or function within the first node 120, i.e., authorization relates to access control. The verification may be performed based on a set of rules defined by 3 GPP, one or more use cases defined by a controller of the communication network (e.g. a controller node / an manual operator for a telecommunication provider) and / or network constraints (e.g. maximum requests allowed, latency, throughput) of the communication network and the external network.

[0047] Optionally, the request comprises one or more of: an identification (ID) of a network comprising the external node (e.g. a 3rdparty network which is a partner network for the communication network 100), an indication for requesting a VPN connection between the first node and the external node, a public Internet Protocol (IP) address of the external node and an external AF ID (e.g. an AF ID of the 3rdparty network’s AF).

[0048] The method 200 optionally comprises applying / configuring 220 a VPN policy for the VPN connection if the external node is permitted to utilize the VPN connection. The VPN policy may comprise at least one first parameter. The at least one first parameter may comprise one or more of an encryption algorithm, an authentication algorithm, a key group and a time-to-live (TTL) for the VPN connection. In some embodiments, the VPN connection may be configured using a VPN protocol such as IPSec, Transport layer security (TLS) and Datagram Transport Layer Security (DTLS). The VPN policy refers to the VPN protocol.

[0049] Examples of the encryption algorithm are Rivest-Shamir-Adleman (RSA), blowfish, Data Encryption Standard (DES), Advanced Encryption Standard (AES). Examples of the authentication algorithm are Hash-based message authentication code (HMAC), Secure Hash Algorithms (SHA; e.g. SHA-128, SHA-256, SHA-1024) and Message-Digest algorithms (MD algorithms; .g. MD4, MD5, MD6). Examples of key groups are Diffie-Hellman (DH) groups (e g. MODP groups: DH Group 2, DH Group 5, DH Group 14; ECP groups: DH Group 19, DH Group 20, DH group 21), Elliptic-curve Diffie-Hellman (ECDH) groups and Triple Diffie-Hellman (3-DH). The TTL may be in the order of a few nanoseconds to a few hours. The TTL provides an indication about how long (in time) a particular VPN session is to be established and / or maintained.

[0050] The method 200 optionally comprises generating 225 an encryption key for the VPN connection if the external node is permitted to utilize the VPN connection. The encryption key may be a private or a public key depending upon the requirements of the communication network 100.

[0051] The method 200 optionally comprises establishing 230 a key exchange policy for the VPN connection if the verification establishes that the external node is permitted to utilize the VPN connection. The method 200 optionally comprises generating 235 an encryption key for the VPN connection if the external node is permitted to utilize the VPN connection, wherein the key exchange policy comprises exchanging the generated encryption key (i.e., transmitting the generated encryption key to the external node 120). The key exchange policy may comprise at least one second parameter. The at least one second parameter comprises at least one of a local gateway IP address (e.g. a local wide area network (WAN) ID), a remote gateway IP address (e.g. a remote WAN ID), an encryption algorithm, an authentication algorithm, a key group and a TTL for the VPN connection.

[0052] Examples of the encryption algorithm, the authentication algorithm, the key group and the TTL have been provided above in the description relating to configuring 220. The key exchange policy may be an Internet Key Exchange (IKE) policy such as IKEvl and IKEv2.

[0053] Preferably, the first node 110 and the external node 120 communicate via a northbound NEF interface. In some embodiments, the AF comprises a firewall. Thus, some embodiments herein provide a mechanism for setting up of a VPN connection between the communication network and the external network by the implementing a Northbound interface (NBI) and providing a means to use the NBI.

[0054] In some embodiments, configuration settings of the VPN connection may be saved at the first node 110 and / or the external node 120 by known security procedures once it has been determined that the external node is permitted to utilize a VPN connection. Once the VPN connection configuration at the communication network 100 is completed (e.g. at the first node 110) and communicated with an external network (e.g. at the external node 120), a VPN association between the communication network 100 and the external network is created.

[0055] Figs. 3 illustrates an embodiment according to a method 300 performed by an external node 120 of the invention. The method 300 is performed by the external node 120 in a communication network, such as the communication network 100 as described in relation to the description corresponding to Fig. 1. The external node 120 implements an AF. The method 300 comprises transmitting 305 a request to the first node 110 implementing a NEF. The request is a request for establishing a VPN connection between the first node 110 and the external node 120.

[0056] The request optionally comprises one or more of an ID of a network comprising the external node 120, an indication for requesting a VPN connection between the first node 110 and the external node 120, a public IP address of the external node 120 and an external AF ID.

[0057] The method 300 optionally comprises obtaining 310 a VPN policy configuration for the VPN connection if the external node is permitted to utilize the VPN connection. The VPN policy may comprise at least one first parameter comprising at least one of an encryption algorithm, an authentication algorithm, a key group and a TTL for the VPN connection. The examples for the encryption algorithm, the authentication algorithm, the TTL and key group have been provided in the description corresponding to Fig. 2.

[0058] The method 300 optionally comprises obtaining 315 a key exchange policy for the VPN connection if the external node 120 is permitted to utilize the VPN connection. Optionally, obtaining the key exchange policy comprises receiving an encryption key for the VPN connection from the first node 110. The encryption key may be generated by the first node 110.

[0059] The key exchange policy optionally comprises at least one second parameter comprising at least one of a local gateway IP address, a remote gateway IP address, an encryption algorithm, an authentication algorithm, a key group and a TTL for the VPN connection.

[0060] In some embodiments, the first node 110 and the external node 120 may communicate with each other via a northbound NEF interface. In some embodiments, the AF may comprise a firewall.

[0061] Fig. 4 shows an example of a signaling diagram in accordance with some embodiments. In this example, the communication network 100 is a telecommunication provider’s network, the first node 110 implements an NEF, the external node 120 implements an AF and the external node 120 is part of a partner network. The first node 110 and the external node 120 may be configured to communicate on a northbound NEF interface.

[0062] The first node 110 is configured to receive 205, 305 a request for establishing a VPN connection between the first node 110 and the external node 120. If the external node 120 is permitted to utilize the VPN connection based on the request, the first node 110 is configured to establish 215a the VPN connection with the external node 120. If the external node is not permitted to utilize the VPN connection based on the request, the first node is configured to deny 215b the request for the VPN connection with the external node 120.

[0063] The first node 110 is optionally configured to verify 210 if the external node is permitted to utilize the VPN connection based on the request by authenticating the request from the external node and / or authorizing the request from the external node. In some embodiments, the communication network 100 may comprise one or more second nodes 115. The one or more second nodes 115 may be configured to verify 210 if the external node is permitted to utilize the VPN connection based on the request. The request may be a request as described in relation to Figs. 2 and 3.

[0064] The first node 110 is optionally configured to apply / configure 220 a VPN policy for the VPN connection if the external node 120 is permitted to utilize the VPN connected based on the request. The VPN policy may be a VPN protocols as described in relation to the description of Figs. 2 and 3. The VPN policy comprises at least one first parameter as described in relation to the description of Figs. 2 and 3. The external node 120 is optionally configured to obtain 310 the VPN policy configuration for the VPN connection.

[0065] The first node 110 is optionally configured to generate 225 an encryption key for the VPN connection if the external node 120 is permitted to utilize the VPN connection. The one or more second nodes 115 may be configured to generate 225 an encryption key for the VPN connection if the external node 120 is permitted to utilize the VPN connection.

[0066] The first node 110 is optionally configured to establish 230 a key exchange policy for the VPN connection if the external node 120 is permitted to utilize the VPN connection. The key exchange policy may be a key exchange policy as described in relation to the description of Figs. 2 and 3. The external node 120 is optionally configured to obtain 315 (e.g. retrieve, receive) the key exchange policy for the VPN connection from the first node 110.

[0067] The first node 110 is optionally configured to generate 235 an encryption key for the VPN connection if the external node 120 is permitted to utilize the VPN connection, wherein the key exchange policy comprises exchanging the generated encryption key. The key exchange policy comprises at least one second parameter as described in relation to the description of Figs. 2 and 3. As mentioned above, the one or more second nodes 115 may be configured to generate 225 the encryption key for the VPN connection. Fig. 5 shows the first node 110 in accordance with some embodiments. As used herein, first node 110 refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), routers, base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), RAN nodes, 0-RAN nodes or components of an 0-RAN node (e.g., 0-RU, 0-DU, O-CU), and / or any 6G network nodes. The one or more second nodes 115 may also be implemented and illustrated as the first node 110 in Fig. 5.

[0068] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an 0-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0069] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi -standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0070] The first node 110 includes a processing circuitry 502, a memory 504, a communication interface 506, and a power source 508. The first node 110 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the first node 110 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the first node 110 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 504 for different RATs) and some components may be reused (e.g., a same antenna 510 may be shared by different RATs). The first node 110 may also include multiple sets of the various illustrated components for different wireless technologies integrated into the first node 110, for example GSM, WCDMA, LTE, NR, 6G, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within the first node 110.

[0071] The processing circuitry 502 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other first node 110 components, such as the memory 504, to provide the first node 110 functionality.

[0072] In some embodiments, the processing circuitry 502 includes a system on a chip (SOC). In some embodiments, the processing circuitry 502 includes one or more of radio frequency (RF) transceiver circuitry 512 and baseband processing circuitry 514. In some embodiments, the radio frequency (RF) transceiver circuitry 512 and the baseband processing circuitry 514 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 512 and baseband processing circuitry 514 may be on the same chip or set of chips, boards, or units.

[0073] The memory 504 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 502. The memory 504 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 502 and utilized by the first node 110. The memory 504 may be used to store any calculations made by the processing circuitry 502 and / or any data received via the communication interface 506. In some embodiments, the processing circuitry 502 and memory 504 is integrated.

[0074] The communication interface 506 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 506 comprises port(s) / terminal(s) 516 to transmit and receive data, for example to and from a network over a wired connection. The communication interface 506 also includes radio front-end circuitry 518 that may be coupled to, or in certain embodiments a part of, the antenna 510. Radio front-end circuitry 518 comprises filters 520 and amplifiers 522. The radio front-end circuitry 518 may be connected to an antenna 510 and processing circuitry 502. The radio front-end circuitry may be configured to condition signals communicated between antenna 510 and processing circuitry 502. The radio front-end circuitry 518 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 518 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 520 and / or amplifiers 522. The radio signal may then be transmitted via the antenna 510. Similarly, when receiving data, the antenna 510 may collect radio signals which are then converted into digital data by the radio front-end circuitry 518. The digital data may be passed to the processing circuitry 502. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0075] In certain alternative embodiments, the first node 110 does not include separate radio front-end circuitry 518, instead, the processing circuitry 502 includes radio front-end circuitry and is connected to the antenna 510. Similarly, in some embodiments, all or some of the RF transceiver circuitry 512 is part of the communication interface 506. In still other embodiments, the communication interface 506 includes one or more ports or terminals 516, the radio frontend circuitry 518, and the RF transceiver circuitry 512, as part of a radio unit (not shown), and the communication interface 506 communicates with the baseband processing circuitry 514, which is part of a digital unit (not shown).

[0076] The antenna 510 may include one or more antennas, or antenna arrays, configured to transmit and / or receive wireless signals. The antenna 510 may be coupled to the radio frontend circuitry 518 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 510 is separate from the first node 110 and connectable to the first node 110 through an interface or port.

[0077] The antenna 510, communication interface 506, and / or the processing circuitry 502 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 510, the communication interface 506, and / or the processing circuitry 502 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0078] The power source 508 provides power to the various components of first node 110 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 508 may further comprise, or be coupled to, power management circuitry to supply the components of the first node 110 with power for performing the functionality described herein. For example, the first node 110 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 508. As a further example, the power source 508 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0079] Embodiments of the first node 110 may include additional components beyond those shown in Fig. 5 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the first node 110 may include user interface equipment to allow input of information into the first node 110 and to allow output of information from the first node 110. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the first node 110. The first node 110 is configured to perform the operations according to any of the methods disclosed herein in relation to the first node 110, including the method shown in Fig. 2 and the signaling diagram of Fig. 4.

[0080] Fig. 6 shows the external node 120 in accordance with some embodiments. As used herein, external node 120 refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), routers, base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), RAN nodes, O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU), and / or any 6G network nodes. Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an 0-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0081] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi -standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0082] The external node 120 includes a processing circuitry 602, a memory 604, a communication interface 606, and a power source 608. The external node 120 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the external node 120 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeB s. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the external node 120 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 604 for different RATs) and some components may be reused (e.g., a same antenna 610 may be shared by different RATs). The external node 120 may also include multiple sets of the various illustrated components for different wireless technologies integrated into the external node 120, for example GSM, WCDMA, LTE, NR, 6G, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within the external node 120.

[0083] The processing circuitry 602 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other external node 120 components, such as the memory 604, to provide the external node 120 functionality.

[0084] In some embodiments, the processing circuitry 602 includes a system on a chip (SOC). In some embodiments, the processing circuitry 602 includes one or more of radio frequency (RF) transceiver circuitry 612 and baseband processing circuitry 614. In some embodiments, the radio frequency (RF) transceiver circuitry 612 and the baseband processing circuitry 614 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 612 and baseband processing circuitry 614 may be on the same chip or set of chips, boards, or units.

[0085] The memory 604 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 602. The memory 604 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 602 and utilized by the external node 120. The memory 604 may be used to store any calculations made by the processing circuitry 602 and / or any data received via the communication interface 606. In some embodiments, the processing circuitry 602 and memory 604 is integrated.

[0086] The communication interface 606 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 606 comprises port(s) / terminal(s) 616 to transmit and receive data, for example to and from a network over a wired connection. The communication interface 606 also includes radio front-end circuitry 618 that may be coupled to, or in certain embodiments a part of, the antenna 610. Radio front-end circuitry 618 comprises filters 620 and amplifiers 622. The radio front-end circuitry 618 may be connected to an antenna 610 and processing circuitry 602. The radio front-end circuitry may be configured to condition signals communicated between antenna 610 and processing circuitry 602. The radio front-end circuitry 618 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 618 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 620 and / or amplifiers 622. The radio signal may then be transmitted via the antenna 610. Similarly, when receiving data, the antenna 610 may collect radio signals which are then converted into digital data by the radio front-end circuitry 618. The digital data may be passed to the processing circuitry 602. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0087] In certain alternative embodiments, the external node 120 does not include separate radio front-end circuitry 618, instead, the processing circuitry 602 includes radio front-end circuitry and is connected to the antenna 610. Similarly, in some embodiments, all or some of the RF transceiver circuitry 612 is part of the communication interface 606. In still other embodiments, the communication interface 606 includes one or more ports or terminals 616, the radio front-end circuitry 618, and the RF transceiver circuitry 612, as part of a radio unit (not shown), and the communication interface 606 communicates with the baseband processing circuitry 614, which is part of a digital unit (not shown).

[0088] The antenna 610 may include one or more antennas, or antenna arrays, configured to transmit and / or receive wireless signals. The antenna 610 may be coupled to the radio frontend circuitry 618 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 610 is separate from the external node 120 and connectable to the external node 120 through an interface or port.

[0089] The antenna 610, communication interface 606, and / or the processing circuitry 602 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 610, the communication interface 606, and / or the processing circuitry 602 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment. The power source 608 provides power to the various components of external node 120 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 608 may further comprise, or be coupled to, power management circuitry to supply the components of the external node 120 with power for performing the functionality described herein. For example, the external node 120 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 608. As a further example, the power source 608 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0090] Embodiments of the external node 120 may include additional components beyond those shown in Fig. 6 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the external node 120 may include user interface equipment to allow input of information into the external node 120 and to allow output of information from the external node 120. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the external node 120. The external node 120 is configured to perform the operations according to any of the methods disclosed herein in relation to the external node 120, including the method shown in Fig. 3 and the signaling diagram of Fig. 4.

[0091] Fig. 7 illustrates an embodiment of a computer program product 710 according to the invention. The computer program product 710 of the first node 110, the one or more second nodes 115 and / or the external node 120 includes a computer readable storage medium (storage or recording medium) storing a computer program 720 comprising computer readable instructions. The computer readable medium of the first node 110, the one or more second nodes 115 and / or the external node 120, may be a non-transitory computer readable medium, such as, magnetic media (e.g., a hard disk), optical media, memory devices (e.g., random access memory, flash memory), and the like. In some embodiments, the computer readable instructions of the computer program 720 are configured such that when executed by processing circuitry 502 and / or the processing circuitry 602, the computer readable instructions cause the first node 110, the one or more second nodes 115 and / or the external node 120 to perform steps described herein (e.g., method 200, method 300, signaling diagram 400). In other embodiments, the first node 110, the one or more second nodes 115 and / or the external node 120 may be configured / operable to perform steps described herein without the need for code. That is, for example, the processing circuity 502 and / or the processing circuitry 602 may consist merely of one or more ASICs. Hence, the features of the embodiments described herein may be implemented in hardware and / or software.

[0092] The computer program code mentioned above may also be provided, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the hardware. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on the first node 110, the one or more second nodes 115 and / or the external node 120, and downloaded to the hardware at production, and / or during software updates.

Claims

CLAIMS1. A method (200) performed by a first node (110) in a communication network (100), the first node implementing a Network Exposure Function, NEF, the method comprising: receiving (205), from an external node (120) implementing an Application Function, AF, a request for establishing a Virtual Private Network, VPN, connection between the first node and the external node; if the external node is permitted to utilize the VPN connection based on the request: establishing (215a) the VPN connection with the external node; and if the external node is not permitted to utilize the VPN connection based on the request: denying (215b) the request for the VPN connection with the external node.

2. The method according to claim 1, the method further comprising: verifying (210) if the external node is permitted to utilize the VPN connection based on the request.

3. The method according to claim 2, wherein verifying (210) whether the external node is permitted to utilize the VPN connection comprises: authenticating the request from the external node; and / or authorizing the request from the external node.

4. The method according to any one of claims 1 to 3, wherein the request comprises one or more of: an identification, ID, of a network comprising the external node; an indication for requesting a VPN connection between the first node and the external node; a public Internet Protocol, IP, address of the external node; and an external AF ID.

5. The method according to any one of claims 1 to 4, comprising: configuring (220) a VPN policy for the VPN connection if the external node is permitted to utilize the VPN connection.

6. The method according to claim 5, wherein the VPN policy comprises at least one first parameter comprising at least one of: an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

7. The method according to any one of claims 1 to 6, comprising: generating (225) an encryption key for the VPN connection if the external node is permitted to utilize the VPN connection.

8. The method according to any one of claims 1 to 7, comprising: establishing (230) a key exchange policy for the VPN connection if the verification that the external node is permitted to utilize the VPN connection.

9. The method according to claim 8, comprising: generating (235) an encryption key for the VPN connection if the external node is permitted to utilize the VPN connection; and wherein the key exchange policy comprises exchanging the generated encryption key.

10. The method according to claim 8 or 9, wherein the key exchange policy comprises at least one second parameter comprising at least one of: a local gateway IP address; a remote gateway IP address; an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

11. The method according to any one of claims 1 to 10, wherein the first node and the external node communicate via a northbound NEF interface.

12. The method according to any one of claims 1 to 11, wherein the AF comprises a firewall.

13. A first node (110) in a communication network (100), the first node implementing a Network Exposure Function, NEF, the first node adapted to: receive (205), from an external node (120) implementing an Application Function, AF, a request for establishing a Virtual Private Network, VPN, connection between the first node and the external node; if the external node is permitted to utilize the VPN connection based on the request: establish (215a) the VPN connection with the external node; and if the external node is not permitted to utilize the VPN connection based on the request: deny (215b) the request for the VPN connection with the external node.

14. The first node according to claim 13, adapted to: verify (210) if the external node is permitted to utilize the VPN connection based on the request.

15. The first node according to claim 14, wherein verifying (210) whether the external node is permitted to utilize the VPN connection comprises: authenticating the request from the external node; and / or authorizing the request from the external node.

16. The first node according to any one of claims 13 to 15, wherein the request comprises one or more of: an identification, ID, of a network comprising the external node; an indication for requesting a VPN connection between the first node and the external node; a public Internet Protocol, IP, address of the external node; and an external AF ID.

17. The first node according to any one of claims 13 to 16, adapted to: configure (220) a VPN policy for the VPN connection if the external node is permitted to utilize the VPN connection.

18. The first node according to claim 17, wherein the VPN policy comprises at least one first parameter comprising at least one of: an encryption algorithm;an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

19. The first node according to any one of claims 13 to 18, adapted to: generate (225) an encryption key for the VPN connection if the external node is permitted to utilize the VPN connection.

20. The first node according to any one of claims 13 to 19, adapted to: establish (230) a key exchange policy for the VPN connection if the verification that the external node is permitted to utilize the VPN connection.

21. The first node according to claim 20, adapted to: generate (235) an encryption key for the VPN connection if the external node is permitted to utilize the VPN connection; and wherein the key exchange policy comprises exchanging the generated encryption key.

22. The first node according to claim 20 or 21, wherein the key exchange policy comprises at least one second parameter comprising at least one of: a local gateway IP address; a remote gateway IP address; an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

23. The first node according to any one of claims 12 to 22, wherein the first node and the external node communicate via a northbound NEF interface.

24. A method (300) performed by an external node (120) implementing an Application Function, AF, the method comprising: transmitting (305), to a first node (110) implementing a Network Exposure Function, NEF, in a communication network (100), a request for establishing a Virtual Private Network, VPN, connection between the first node and the external node.

25. The method according to claim 24, wherein the request comprises one or more of: an identification, ID, of a network comprising the external node; an indication for requesting a VPN connection between the first node and the external node; a public Internet Protocol, IP, address of the external node; and an external AF ID.

26. The method according to claims 24 or 25, comprising: obtaining (310) a VPN policy configuration for the VPN connection if the external node is permitted to utilize the VPN connection.

27. The method according to claim 26, wherein the VPN policy comprises at least one first parameter comprising at least one of: an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

28. The method according to any one of claims 24 to 27, comprising: obtaining (315) a key exchange policy for the VPN connection if the external node is permitted to utilize the VPN connection.

29. The method according to claim 28, wherein obtaining the key exchange policy comprises receiving an encryption key generated by the first node for the VPN connection.

30. The method according to claim 28 or 29, wherein the key exchange policy comprises at least one second parameter comprising at least one of: a local gateway IP address; a remote gateway IP address; an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

31. The method according to any one of claims 24 to 30, wherein the first node and the external node communicate via a northbound NEF interface.

32. The method according to any one of claims 24 to 31, wherein the AF comprises a firewall.

33. An external node (120) implementing an Application Function, AF, the external node adapted to: transmit (305), to a first node (110) implementing a Network Exposure Function, NEF, in a communication network (100), a request for establishing a Virtual Private Network, VPN, connection between the first node and the external node.

34. The external node according to claim 33, wherein the request comprises one or more of: an identification, ID, of a network comprising the external node; an indication for requesting a VPN connection between the first node and the external node; a public Internet Protocol, IP, address of the external node; and an external AF ID.

35. The external node according to claims 33 or 34, adapted to: obtain (310) a VPN policy configuration for the VPN connection if the external node is permitted to utilize the VPN connection.

36. The external node according to claim 35, wherein the VPN policy comprises at least one first parameter comprising at least one of: an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

37. The external node according to any one of claims 33 to 36, adapted to: obtain (315) a key exchange policy for the VPN connection if the external node is permitted to utilize the VPN connection.

38. The external node according to claim 37, wherein obtaining the key exchange policy comprises receiving an encryption key generated by the first node for the VPN connection.

39. The external node according to claim 37 or 38, wherein the key exchange policy comprises at least one second parameter comprising at least one of a local gateway IP address; a remote gateway IP address; an encryption algorithm; an authentication algorithm; a key group; and a time-to-live, TTL, for the VPN connection.

40. The external node according to any one of claims 33 to 39, wherein the first node and the external node communicate via a northbound NEF interface.

41. The external node according to any one of claims 33 to 40, wherein the AF comprises a firewall.

42. A first node (110) in a communication network (100), the first node implementing a Network Exposure Function, NEF, the first node comprising: at least one processing circuitry (502); and at least one memory (504) connected to the at least one processing circuitry (502) and storing program code that is executed by the at least one processing circuitry to perform the method according to any one of claims 1 to 12.

43. An external node (120), the external node implementing an Application Function, AF, the external node comprising: at least one processing circuitry (602); and at least one memory (604) connected to the at least one processing circuitry (602) and storing program code that is executed by the at least one processing circuitry to perform the method according to any one of claims 24 to 32.

44. A computer program (720) comprising instructions which, when executed by at least one processing circuitry (602; 502) of: a first node (110), causes the first node to carry out the method according to any one of claims 1 to 12; and / or an external node (120), causes the external node to carry out the method according to any one of claims 24 to 32.

45. A computer program product (710) stored on a non-transitory computer readable medium and comprising instructions that, when executed by at least one processing circuitry (602; 502) of: a first node (110), causes the first node to perform the method according to any one of claims 1 to 12; and / or an external node (120), causes the external node to perform the method according to any one of claims 24 to 32.

Citation Information

Patent Citations

  • Data communication service over a virtual private network gateway, application function, and network exposure function

    US20220345882A1

  • Network information exposure method and apparatus, electronic device, and storage medium

    US20230309002A1