Originating network edge node, terminating network edge node, first internet protocol multimedia subsystem (IMS) node and methods in a wireless communications network

A centralized PASSporT signing and verification mechanism at the network edge addresses the challenge of multiple entities adding PASSporTs, enabling efficient and coordinated data validation across trust domains in wireless communication networks.

WO2025252298A1PCT designated stage Publication Date: 2025-12-11TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/065224
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-03
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing wireless communication networks face challenges in efficiently centralizing the signing and verification of Personal Assertion Tokens (PASSporTs) containing rich call data across different trust domains and networks, leading to multiple entities adding signed PASSporTs without a unified verification mechanism.

Method used

A centralized signing and verification mechanism is implemented at the network edge, where an originating network edge node constructs a PASSporT based on selected parameters marked as trusted by multiple server nodes, and a terminating network edge node verifies and routes the PASSporT to execute services, ensuring only verified data is marked as trusted.

Benefits of technology

This approach enables coordinated signing and verification, allowing a single node to validate data for all server nodes involved, facilitating multi-vendor deployments without specific configuration, and ensuring trusted data is marked for execution in the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024065224_11122025_PF_FP_ABST
    Figure EP2024065224_11122025_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by an originating network edge node The method is for centralising a construction of a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network is provided. The originating network edge node receives (301) an Invite Message IM12 from a first Internet Protocol Multimedia Subsystem, IMS, node in an originating network. The IM12 comprises a first addition and a second addition. The IM12 relates to a call to a second User Equipment, UE, initiated by a first UE. The IM12 comprises a caller identity of the first UE, and a verification parameter, indicating that the caller identity is trusted. The first addition comprises a first data related to the call marked by a first server node with a specific parameter indicating that the first data is trusted. The second addition comprises a second data related to the call marked by a second server node with the same specific parameter, indicating that the second data is trusted. The originating network edge node selects (302) which parameters or headers comprising parameters comprised in IM12 to be signed based on the IM12 marked with the specific parameter. The originating network edge node constructs (303) a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM12. The originating network edge node then sends (304) the constructed PASSporT to a first network node and requests centralized signing to be valid for server nodes related to the call. The originating network edge node receives (305) the centralized signed PASSporT from the first network node. The originating network edge node then sends (306) the IM12 together with the centralized signed PASSporT to a terminating network edge node in a terminating network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ORIGINATING NETWORK EDGE NODE, TERMINATING NETWORK EDGE NODE, FIRST INTERNET PROTOCOL MULTIMEDIA SUBSYSTEM (IMS) NODE AND METHODS IN A WIRELESS COMMUNICATIONS NETWORK

[0002] TECHNICAL FIELD

[0003] Embodiments herein relate to an originating network edge node, a terminating network edge node, a first Internet Protocol Multimedia Subsystem (IMS) network node, and methods therein. In some aspects, they relate to centralising a construction of a Personal Assertion Token (PASSporT) for signing of verified data of a call in a wireless communications network.

[0004] BACKGROUND

[0005] In a typical wireless communication network, wireless devices, also known as wireless communication devices, mobile stations, stations (STA) and / or User Equipment (UE), communicate via a Wide Area Network or a Local Area Network such as a Wi-Fi network or a cellular network comprising a Radio Access Network (RAN) part and a Core Network (CN) part. The RAN covers a geographical area which is divided into service areas or cell areas, which may also be referred to as a beam or a beam group, with each service area or cell area being served by a radio network node such as a radio access node e.g., a Wi-Fi access point, a Base Station (BS) or a radio base station (RBS), which in some networks may also be denoted, for example, a Base Station (BS), a NodeB, eNodeB (eNB), or gNodeB (gNB) as denoted in Fifth Generation (5G) telecommunications. A service area or cell area is a geographical area where radio coverage is provided by the radio network node. The radio network node communicates over an air interface operating on a radio frequency with the wireless devices within the range of the radio network node.

[0006] 3rd Generation Partnership Project (3GPP) is the standardization body for specifying the standards for the cellular system evolution, e.g., including 3G, 4G, 5G and the future evolutions. Specifications for Evolved Universal Terrestrial Radio Access (E- UTRA) and Evolved Packet System (EPS) have been completed within the 3GPP. In 4G also called a Fourth Generation (4G) network, EPS is core network and E-UTRA is radio access network. In 5G, 5G Core (5GC) is core network, NR is radio access network. As a continued network evolution, the new release of 3GPP specifies a 5G network also referred to as 5G New Radio (NR) and 5GC.

[0007] Frequency bands for 5G NR are being separated into two different frequency ranges, Frequency Range 1 (FR1) and Frequency Range 2 (FR2). FR1 comprises sub-6 GHz frequency bands. Some of these bands are bands traditionally used by legacy standards but have been extended to cover potential new spectrum offerings from 410 MHz to 7125 MHz. FR2 comprises frequency bands from 24.25 GHz to 52.6 GHz. Bands in this millimeter wave range have shorter range but higher available bandwidth than bands in the FR1.

[0008] Multi-antenna techniques may significantly increase the data rates and reliability of a wireless communication system. For a wireless connection between a single user, such as UE, and a base station (BS), the performance is in particular improved if both the transmitter and the receiver are equipped with multiple antennas, which results in a Multiple-Input Multiple-Output (MIMO) communication channel. This may be referred to as Single-User (SU)-MIMO. In the scenario where MIMO techniques is used for the wireless connection between multiple users and the base station, MIMO enables the users to communicate with the base station simultaneously using the same time-frequency resources by spatially separating the users, which increases further the cell capacity. This may be referred to as Multi-User (MU)-MIMO. Note that MU-MIMO may benefit when each UE only has one antenna. The cell capacity can be increased linearly with respect to the number of antennas at the BS side. Due to that, more and more antennas are employed in BS. Such systems and / or related techniques are commonly referred to as massive MIMO.

[0009] The Alliance for Telecommunications Industry Solutions (ATIS) has defied a framework, referred to as Signature-based Handling of Asserted information using toKENs (SHAKEN), which establishes an end-to-end architecture that allows a telephone service provider to authenticate and assert a telephone identity and provides for the verification of this telephone identity by a terminating service provider. The SHAKEN framework defines a profile, using protocols standardized in the Internet Engineering Task Force (IETF) Secure Telephone Identity Revisited (STIR), providing recommendations and requirements for implementing these IETF specifications - RFC 8225, Personal Assertion Token (PASSporT) & RFC 8224, Authenticated Identity Management in the Session Initiation Protocol and RFC 8226, Secure Telephone Identity Credentials Certificates, to support management of Service Provider-level certificates within the SHAKEN framework.

[0010] 3GPP have adopted this framework and defined an architecture and procedures as outlined in Annex V in 3. 3GPP TS 24.229 v18.

[0011] ATIS have expanded the original framework by introducing mechanisms for authentication, verification, transport of calling name and other enhanced caller identity information, e.g., images, logos sometimes referred to as RCD-Rich Call Data, and call reason and describing how they are handled in various call origination and termination scenarios. See Signature-based Handling of Asserted information using toKENs (SHAKEN): Calling Name and Rich Call Data Handling Procedures - ATI S-1000094.

[0012] 3GPP has not as yet adopted the updated procedures (for RCD etc.).

[0013] The current architecture for signing and verifying (s&v) a Personal Assertion Token (See RFC 8588, Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN) supports interaction both from Application Servers (AS) as well as at the network edge, Interconnect Border Control Function (IBCF), see Figure 1 depicting the Usage of a Mobile Station (MS) reference point of 3GPP TS 24.229 Annex V. This procedure is today primarily used for the conveying of verified caller party phone number in the STIR / SHAKEN architecture.

[0014] SUMMARY

[0015] As part of developing embodiments herein, the inventors identified some problems that first will be described.

[0016] When supporting s&v for passports containing only a Telephone Number (TN), this may be easily orchestrated between AS and IBCF, but when adding more information to the PASSporT than phone numbers, such as e.g., Rich Call Data, which may be added by many different entities such as e.g., AS, resulting in that multiple entities have to add signed PASSporTs. it would be beneficial to centralize the s&v, e.g., to the network edge, such as the IBCF, for calls between different trust domains and / or networks.

[0017] An object of embodiments herein is to improve the way of signing of verified data of a call in a wireless communications network. According to an aspect of embodiments herein, the object is achieved by a method performed by an originating network edge node. The method is for centralising a construction of a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network. The originating network edge node receives an Invite Message IM 12 from a first Internet Protocol Multimedia Subsystem, IMS, node in an originating network. The I M 12 comprises a first addition and a second addition. The IM 12 relates to a call to a second User Equipment, UE, initiated by a first UE. The IM 12 comprises a caller identity of the first UE, and a verification parameter, indicating that the caller identity is trusted. The first addition comprises a first data related to the call marked by a first server node with a specific parameter indicating that the first data is trusted. The second addition comprises a second data related to the call marked by a second server node with the same specific parameter, indicating that the second data is trusted. The originating network edge node selects which parameters or headers comprising parameters comprised in IM 12 to be signed based on the IM 12 marked with the specific parameter. The originating network edge node constructs a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM 12. The originating network edge node then sends the constructed PASSporT to a first network node and requests centralized signing to be valid for server nodes related to the call. The originating network edge node receives the centralized signed PASSporT from the first network node. The originating network edge node then sends the IM 12 together with the centralized signed PASSporT to a terminating network edge node in a terminating network.

[0018] According to an aspect of embodiments herein, the object is achieved by a method performed by a terminating network edge node in a terminating network. The method is for handling a Personal Assertion Token, PASSporT, related to a call in a wireless communications network. The terminating network edge node receives an Invite Message, IM12, from an originating network edge node of an originating network. The IM12 is received together with a centralized signed PASSporT. The IM 12 comprises a first addition and a second addition. The IM 12 relates to a call to a second User Equipment, UE, initiated by a first UE. The IM12 comprises a caller identity of the first UE, and a verification parameter indicating that the caller identity is trusted. The first addition comprises a first data related to the call. The second addition comprises a second data related to the call. The terminating network edge node routes the centralized signed PASSporT to a second network node and requests assertion and verification of the first data and the second data in IM 12. When the terminating network edge node receives verified first and / or second data and assertion result from the second network node, it marks a header of the IM 12 as verified by the verification parameter. It also marks with a specific parameter, the first and / or second data in the IM 12 that has been verified by the PASSporT in the I M 12. The terminating network edge node routes the marked I M 12 towards a third server node for executing services related to the first and / or second data marked with the specific parameter indicating that the first and / or second data is trusted.

[0019] According to an aspect of embodiments herein, the object is achieved by a method performed by a first Internet Protocol Multimedia Subsystem, IMS, node in an originating network. The method is for assisting an originating network edge node in a centralisation of constructing a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network. The first IMS node receives an Invite Message, IM, from a second IMS node. The IM relates to a call to a second User Equipment, UE, initiated by a first UE. The IM comprises a caller identity of the first UE, and a verification parameter, indicating that the caller identity is trusted. The first IMS node routes the IM to a first server node. The first IMS node receives the IM from the first server node. The IM includes a first addition, IMl .The first addition comprises a first data related to the call marked with a specific parameter indicating that the first data is trusted. After routing the IM1 to a second server node the first IMS node receives from the second server node, the IM1 including a second addition, IM 12. The second addition comprises a second data related to the call, e.g., a call info header, marked with the same specific parameter indicating that the second data is trusted. The first IMS node routes the I M 12 to the originating network edge node. The IM 12 enables the originating network edge node to construct a centralized signed PASSporT to be valid for the first data and the second data on behalf of server nodes related to the call in the originating network and send the centralized signed PASSporT to a terminating network edge node.

[0020] According to another aspect of embodiments herein, the object is achieved by an originating network edge node. The originating network edge node is configured to centralise a construction of a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network. The originating network edge node is further configured to:

[0021] - Receive from a first Internet Protocol Multimedia Subsystem, IMS, node in the originating network, an Invite Message IM 12. The IM 12 is adapted to comprise a first addition and a second addition. The IM 12 is adapted to relate to a call to a second User Equipment, UE, initiated by a first UE. The IM 12 is adapted to comprise a caller identity of the first UE, and a verification parameter, indicating that the caller identity is trusted. The first addition is adapted to comprise a first data related to the call marked by a first server node with a specific parameter, indicating that the first data is trusted. The second addition is adapted to comprise a second data related to the call, marked by a second server node with the same specific parameter, indicating that the second data is trusted.

[0022] - Select which parameters or headers comprising parameters comprised in IM12 to be signed based on the IM 12 marked with the specific parameter.

[0023] - Construct a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM 12.

[0024] - Send the constructed PASSporT to a first network node for centralized signing to be valid for server nodes related to the call.

[0025] - Receive the centralized signed PASSporT from the first network node, and

[0026] - send the IM 12 together with the centralized signed PASSporT to a terminating network edge node in a terminating network.

[0027] According to another aspect of embodiments herein, the object is achieved by a terminating network edge node in a terminating network. The terminating network edge node is configured to handle a Personal Assertion Token, PASSporT, related to a call in a wireless communications network. The terminating network edge node is further configured to:

[0028] - Receive from an originating network edge node of an originating network, an Invite Message, IM 12, together with a centralized signed PASSporT. The IM 12 is adapted to comprise a first addition and a second addition. The IM 12 is relating to a call to a second User Equipment, UE, initiated by a first UE. The IM 12 is adapted to comprise a caller identity of the first UE, and a verification parameter indicating that the caller identity is trusted. The first addition is adapted to comprise a first data related to the call, and the second addition is adapted to comprise a second data related to the call.

[0029] - Route the centralized signed PASSporT to a second network node 112, requesting assertion and verification of the first data and the second data in IM 12.

[0030] - When receiving verified first and / or second data, and assertion result from the second network node 112, mark a header of the IM12 as verified by the verification parameter, and mark with a specific parameter, the first and / or second data in the IM12 that has been verified by the PASSporT in the I M 12, and route the marked IM 12 towards a third server node for executing services related to the first and / or second data marked with the specific parameter indicating that the first and / or second data is trusted.

[0031] According to an aspect of embodiments herein, the object is achieved by a first Internet Protocol Multimedia Subsystem, IMS, node in an originating network. The first IMS node is configured to assist an originating network edge node in a centralization of constructing a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network. The first IMS node is further configured to:

[0032] - Receive an Invite Message, IM, from a second IMS node. The IM is adapted to relate to a call to a second User Equipment, UE, initiated by a first UE. The IM is adapted to comprise a caller identity of the first UE, and a verification parameter, indicating that the caller identity is trusted.

[0033] - After routing the IM to a first server node, receive from the first server node, the IM including a first addition, IM. The first addition is adapted to comprise a first data related to the call, marked with a specific parameter indicating that the first data is trusted.

[0034] - After routing the IM 1 to a second server node, receive from the second server node, the IM1 including a second addition, IM 12. The second addition is adapted to comprise a second data related to the call, marked with the same specific parameter, indicating that the second data is trusted, and

[0035] - Route the IM 12 to the originating network edge node. The IM 12 is adapted to enable the originating network edge node to construct a centralized signed PASSporT to be valid for the first data and the second data on behalf of server nodes related to the call in the originating network. Send the centralized signed PASSporT to a terminating network edge node.

[0036] Embodiments herein may provide one or more of the following advantages:

[0037] Embodiments herein enable:

[0038] - A coordination of signing and verification information making it possible for a single node or entity to perform all the signing and / or all the verifications to be valid for server nodes related to a call.

[0039] - A multi-vendor deployment to avail of a centralized Signing & Verification mechanism without the need for deployment of any specific configuration. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Examples of embodiments herein are described in more detail with reference to attached drawings in which:

[0041] Figure 1 is a schematic block diagram illustrating prior art.

[0042] Figure 2 is a schematic overview illustrating embodiments of a communications network.

[0043] Figure 3 is a flowchart depicting an embodiment of a method in an originating network edge node.

[0044] Figure 4 is a flowchart depicting an embodiment of a method in a terminating network edge node.

[0045] Figure 5 is a flowchart depicting an embodiment of a method in a first IMS node.

[0046] Figure 6 is a sequence diagram illustrating an example embodiment of a method performed in an originating network.

[0047] Figure 7 is a sequence diagram illustrating an example embodiment of a method performed in a terminating network.

[0048] Figure 8 is a schematic block diagram illustrating embodiments of an originating network node.

[0049] Figure 9 is a schematic block diagram illustrating embodiments of a terminating network node.

[0050] Figure 10 is a schematic block diagram illustrating embodiments of a first IMS node.

[0051] Figure 11 schematically illustrates embodiments of a communication system.

[0052] Figure 12 is a generalized block diagram of embodiments of a UE.

[0053] Figure 13 is a generalized block diagram of embodiments of a network node.

[0054] Figure 14 is a generalized block diagram of embodiments of a virtualization environment.

[0055] DETAILED DESCRIPTION

[0056] Example embodiments herein provide a mechanism for instructing a network edge node such as e.g. an IBCF, how to construct a PASSporT for signing any verified data in SIP signalling. In an example of embodiments herein a specific parameter, e.g., a SIP signalling parameter is provided, which indicates that a SIP header or part of a SIP header needs to be signed or has been verified.

[0057] Some examples of embodiments herein enable IMS domain nodes to convey in SIP signaling, verification and signing needs of different parts of the SIP headers.

[0058] Figure 2 is a schematic overview depicting a wireless communications network 100 wherein embodiments herein may be implemented. The communications network 100 comprises one or more RANs, and one or more CNs. Embodiments herein relate to a call that is sent from a first UE 121 via an originating network 101 and a terminating network 102 towards a second UE 122 in the communications network 100. The communications network 100 may use 5G NR but may further use a number of other different technologies, such as, 6G, Wi-Fi, Long Term Evolution (LTE), LTE-Advanced, Wideband Code Division Multiple Access (WCDMA), Global System for Mobile communications / enhanced Data rate for GSM Evolution (GSM / EDGE), Worldwide Interoperability for Microwave Access (WiMax), or Ultra Mobile Broadband (UMB), just to mention a few possible implementations.

[0059] Base stations operate in the RAN the wireless communications network 100, such as an originating base station 110-o serving an originating network 101 , and a terminating base station 110-t serving a terminating network 102. Embodiments herein relate to a call to a second UE 122 in the terminating network 102, initiated by a first UE 121 in the originating network 101. The respective base station 110 o / t may be a transmission and reception point e.g. a radio access network node such as a base station, e.g. a radio base station such as a NodeB, an evolved Node B (eNB, eNode B), an NR Node B (gNB), a base transceiver station, a radio remote unit, an Access Point Base Station, a base station router, a transmission arrangement of a radio base station, a stand-alone access point, a Wireless Local Area Network (WLAN) access point or an Access Point Station (AP STA), an access controller, or any other network unit capable of communicating with UEs, such as the first UE 121 or the second UE 122, within radio coverage of the respective base station 110 o / t. The respective base station 110 o / t may be referred to as a serving base station and communicates with a UE 121 , 122 with Downlink (DL) transmissions to the UE 121 , 122 and Uplink (UL) transmissions from the UE 121 , 122. A first network node 111, e.g., an Secure Telephone Identity - Authentication Service (STI-AS), is operating in the originating network 101, and a second network node 112, e.g., an Secure Telephone Identity - Verification Service (STI-VS), is operating in the terminating network 102.

[0060] One or more UEs operate in the communication network 100, such as e.g. the first UE 121 and the second UE 122. Each UE 121, 122 may e.g. be 5G-RG, an a 5G device, such as e.g. the UE 121 , that is enhanced with AR capability, a remote UE, a wireless device, an NR device, a mobile station, a wireless terminal, an NB-loT device, an MTC device, an eMTC device, a CAT-M device, a WiFi device, an LTE device and an a non- access point (non-AP) STA, a STA, that communicates via a base station such as e.g. a base station 105, one or more Access Networks (AN), e.g. a RAN, to one or more core network (CN) nodes, in one or more CNs, one or more IMS nodes, such as e.g. the IMS control node 130 in the IMS network 105. The UEs 121 , 122 may communicate with one or more CN nodes such as the first CN node 151 and second CN node 152, or IMS nodes, such as the IMS control node 130. It should be understood by the skilled in the art that “UE” is a non-limiting term which means any terminal, client, mobile client, IMS client, wireless communication terminal, user equipment, Device to Device (D2D) terminal, or node e.g. smart phone, laptop, mobile phone, sensor, relay, mobile tablets or even a car or any small base station communicating within a cell.

[0061] A first IMS node 131 e.g., an Interrogating (I) or Serving (S) Call Session Control Function (CSCF), and a second IMS node 132, e.g., a proxy (P) -CFCS, are operating in the originating network 101. A third IMS node 133 e.g., an l / S-CSCF, is operating in the terminating network 102.

[0062] A first server node 141 e.g., Application Server (AS)1, and a second server node 142, e.g., AS2, are operating in the originating network 101. A third server node 143 e.g., AS3, is operating in the terminating network 102.

[0063] An originating network edge node 151 , e.g., an IBCF, operates in the originating network 101, and a terminating network edge node 152, e.g., an IBCF, operates in the terminating network 102. A P-CSCF 161 may operate in the originating network 101 and a P-CSCF 162 may operate in the terminating network 102.

[0064] Methods according to embodiments herein are performed by the originating network edge node 151 , the terminating network edge node 152, and the first IMS node 131. These nodes may be Distributed Nodes (DN)s and functionality, e.g. comprised in a cloud 170 as shown in Figure 4.

[0065] Example embodiments herein introduces a mechanism to allow any IMS node in the IMS domain to mark a message such as e.g., a SIP header as being verified via a specific parameter attached to the header. This parameter instructs a network edge node, such as e.g., an IBCF, to include the header, or parts thereof, into a signed PASSporT added to a message in the SIP signaling.

[0066] This allows for a concerted and centralized signing of a single PASSporT rather than having multiple entities adding signed PASSporTs to the SIP message as in prior art.

[0067] A number of embodiments will now be described, some of which may be seen as alternatives, while some may be used in combination.

[0068] A method according to embodiments herein will first be described as seen from the view of the originating network edge node 151 together with Figure 3, then as seen from the view of the terminating network edge node 152 together with Figure 4, and then as seen from the view of the first IMS node 131 together with Figure 5.

[0069] Figure 3 shows exemplary embodiments of a method performed by the originating network edge node 151, e.g., an IBCF. The method is for centralizing a construction of a PASSporT for signing of verified data of a call in the wireless communications network 100.

[0070] The method comprises the following actions, which actions may be taken in any suitable order.

[0071] Action 301. The originating network edge node 151 receives an Invite Message (IM12) from the first IMS node 131. As mentioned above, the first IMS node 131 may e.g. be an l / S-CSCF. The first IMS node 131 is operating in the originating network 101. An Invite Message may be referred to as INVITE herein. The IM12 relates to a call to the second UE 122 initiated by the first UE 121. The I M 12 comprises a caller identity of the first UE 121 , and a verification parameter, indicating that the caller identity is trusted.

[0072] The I M 12 further comprises a first addition and a second addition.

[0073] The first addition comprises a first data related to the call. The first data related to the call may e.g., comprise any data that is related to the call, such as e.g., a display name. The first data is marked by the first server node 141 with a specific parameter. The specific parameter indicates that the first data is trusted. The specific parameter may e.g., be referred to as rich call data - network provided (rcd-np).

[0074] The second addition comprises a second data related to the call, marked by the second server node 142 with the same specific parameter. The specific parameter indicates that the second data is trusted. The second data related to the call may e.g., comprise any data that is related to the call, such as e.g., a call info header.

[0075] Thus, the first server node 141 has marked the first data with the same specific parameter as the second server node 142 has marked the second data.

[0076] In some embodiments, the specific parameter marking in the first addition and the second addition, is represented by a Session Initiation Protocol (SIP) signaling parameter attached to a respective SIP header or part of a SIP header of the IM 12, which in this example have been received in SIP signaling.

[0077] Action 302. The originating network edge node 151 selects which parameters or headers comprising parameters comprised in IM 12 to be signed. The selection is based on the IM 12 marked with the specific parameter.

[0078] In some embodiments, the constructing of the PASSporT comprises including a SIP header or parts of a SIP header in the PASSporT, and sending the PASSporT as added to SIP signaling to the first network node 111 for a centralized signing.

[0079] Action 303. The originating network edge node 151 constructs a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM 12.

[0080] Action 304. The originating network edge node 151 sends the constructed PASSporT to the first network node 111 , e.g., an STI-AS, requesting centralized signing to be valid for server nodes related to the call. Action 305. The originating network edge node 151 receives the centralized signed PASSporT from the first network node 111.

[0081] Action 306. The originating network edge node 151 sends the IM 12 together with the centralized signed PASSporT to the terminating network edge node 152 e.g., IBCF, in a terminating network 102.

[0082] Figure 4 shows exemplary embodiments of a method performed by the terminating network edge node 152 operating in the terminating network 102. The method is for handling a PASSporT related to a call in the wireless communications network 100.

[0083] The method comprises the following actions, which actions may be taken in any suitable order.

[0084] Action 401. The terminating network edge node 152 receives the IM 12 together with the centralized signed PASSporT from the originating network edge node 151 of the originating network 101. The IM 12 comprises the first addition and the second addition. The IM 12 relates to the call to the second UE 122 initiated by the first UE 121. The IM 12 comprises the caller identity of the first UE 121, and the verification parameter indicating that the caller identity is trusted. The first addition comprises the first data related to the call. The second addition comprises the second data related to the call.

[0085] Action 402. The terminating network edge node 152 routes the centralized signed PASSporT to the second network node 112, e.g., STI-VS, requesting assertion and verification of the first data and the second data in I M 12.

[0086] Action 403. The terminating network edge node 152 receives verified first and / or second data and assertion result from the second network node 112.

[0087] Action 404. The terminating network edge node 152 marks a header of the IM12 as verified by the verification parameter. It also marks with a specific parameter, the first and / or second data in the I M 12 that has been verified by the PASSporT in the I M 12. In this way, only the data in the I M 12 that has been verified by the PASSporT in the I M 12 is marked with the specific parameter. Which in this example may be only the first data, only the second data or both the first and second data. Action 405 The terminating network edge node 152 routes the marked IM 12 towards the third server node 143. The third sever node thereafter executes services related to the first and / or second data marked with the specific parameter indicating that the first and / or second data is trusted.

[0088] Figure 5 shows exemplary embodiments of a method performed by the first IMS node 131 e.g., an S / I-CSCF, operating in the originating network 101. The method is for assisting the originating network edge node 151, e.g., an IBCF, in a centralisation of constructing a PASSporT for signing of verified data of a call in the wireless communications network 100.

[0089] The method comprises the following actions, which actions may be taken in any suitable order.

[0090] Action 501. The first IMS node 131 receives an IM from the second IMS node 132, e.g., a P-CFCS. The IM relates to the call to the second UE 122 initiated by the first UE 121. The IM comprises a caller identity of the first UE 121 and a verification parameter indicating that the caller identity is trusted.

[0091] Action 502. The first IMS node 131 routes the IM to the first server node 141 , e.g., AS1.

[0092] According to some embodiments, the first server node 141 adds a first addition to the IM. The first addition comprises a first data related to the call, e.g., a display name. The first data is marked by the first server node 141, with the specific parameter.

[0093] Action 503. The first IMS node 131 receives the IM from the first server node 141. The IM is including a first addition. The IM including the first addition is referred to as IM1. The first addition comprises a first data related to the call, e.g., a display name. The first data is marked, e.g., by the first server node 141 , with a specific parameter, e.g., referred to as rcd-np. The specific parameter is indicating that the first data is trusted.

[0094] Action 504. The first IMS node 131 routes the IM 1 to a second server node 142, e.g., AS2. According to some embodiments, the second server node 142 adds a second addition to the IM1. The second addition comprises a second data related to the call, e.g., a display name. The second data is marked by the second server node 141 , with the specific parameter.

[0095] Action 505. The first IMS node 131 receives from the second server node 142, the IM1 including a second addition. The IM including the first addition and the second addition is referred to as IM 12. The second addition comprises a second data related to the call, e.g., a call info header. It is marked with the same specific parameter, e.g., rcd- np2, indicating that the second data is trusted.

[0096] In some embodiments, the specific parameter marking in the first addition and the second addition, is represented by a SIP signaling parameter attached to a respective SIP header or part of a SIP header of the corresponding IM1 and / or I M 12, which have been received in SIP signaling.

[0097] Action 506. The first IMS node 131 routes the IM 12 to the originating network edge node 151, e.g., IBCF. The IM12 enables the originating network edge node 151 to construct a centralized signed PASSporT to be valid for the first data and the second data. This is on behalf of server nodes related to the call in the originating network 102. The originating network edge node 151 is thereby able to send the centralized signed PASSporT to a terminating network edge node 152. e.g., a IBCF2.

[0098] Embodiments herein such as the embodiments mentioned above will now be further described and exemplified. The text below is applicable to and may be combined with any suitable embodiment described above.

[0099] A call flow for an example of originating network 101 procedures is shown in a sequence diagram of Figure 6. It should be noted that not all interactions are shown for simplicity.

[0100] 601. The originating UE, such as the first UE 121, initiates a call and sends an IM, referred to as INVITE in Figure 6, to the P-CSCF 161. The P-CSCF 161 adds an asserted caller identity of the first UE 121 in a P-Asserted Identity header (PAI). The first UE 121 also adds a verification parameter, e.g., a STIR / SHAKEN verification parameter referred to as verstat in Figure 6. This is to indicate that the caller id is trusted.

[0101] 602. The P-CSCF 161 routes the call to the first IMS node 131 such as the l / S- CSCF.

[0102] 603. The first IMS node 131 such as the l / S-CSCF routes the INVITE comprising the PAI header and the verstat to the first server node 141 such as the AS1.

[0103] 604. The first server node 141, such as the AS1, decides to add a first addition comprising the first data such as e.g., a network asserted “display-name”, to the PAI header. According to embodiments herein, the first server node 141 also marks the header with the specific parameter, referred to as rcd-np in the example of Figure 6. This is e.g., to mark the display name as network provided and hence trusted. The first server node 141 , routes the IM1 comprising the INVITE including the first addition, the PAI header, the verstat and the rcd-np to the first IMS node 131 such as the l / S-CSCF.

[0104] 605. The first IMS node 131 such as the l / S-CSCF routes the call comprising IM1 to the second server node 142 such as the AS2.

[0105] 606. The second server node 142 decides to add a second addition comprising the second data such as e.g., an asserted Call-Info header to the INVITE, in this example to the IM1. According to embodiments herein, second server node 142 also marks the header with the same specific parameter, “rcd-np”, to mark the Call-Info header as network provided and hence trusted. The second server node 142, routes the IM 12 comprising the INVITE including the first and second addition, the PAI header, the verstat and the rcd-np to the first IMS node 131 such as the l / S-CSCF.

[0106] 607. The first IMS node 131 such as the l / S-CSCF routes the call comprising IM 12 to the originating network edge node 151, e.g., an IBCF.

[0107] 608. The originating network edge node 151 will collect all network provided and trusted data indicated by the specific rcd-np parameter from the INVITE that may be used in the supported PASSporT formats. Next, the originating network edge node 151 sends the PASSporT for centralized signing to the first network node 111 e.g., an STI-AS.

[0108] 609. The first network node 111 will e.g., create an Identity header containing the signed PASSporT and return it to the originating network edge node 151.

[0109] 610. The originating network edge node 151 may e.g., remove all “rcd-np” markings from the headers. Next, the originating network edge node 151 forwards the IM 12 comprising the INVITE with the signed PASSporT to the terminating network 102. A call flow for an example of terminating network 102 procedures is shown in a sequence diagram of Figure 7. It should be noted that not all interactions are shown for simplicity.

[0110] 701. The terminating network edge node 152, e.g. a IBCF, receives from the originating network 101, the IM12 comprising the INVITE with the signed PASSporT, e.g., in the Identity header.

[0111] 702. The terminating network edge node 152 sends containing the signed PASSporT e.g., comprised in the Identity header, for verification to the second network node 112, e.g., an STI-VS.

[0112] 703. The second network node 112, returns the with the verified data and an assertion result.

[0113] 704. The terminating network edge node 152 will mark the header of IM 12 such as e.g., the PAI header, as verified using the verification parameter, e.g., the verstat parameter. According to embodiments herein, the terminating network edge node 152 also marks all other verified data, e.g. first and / or the second data, in the INVITE that is verified by the PASSporT. This other verified data is marked with the specific parameter e.g., rcd-np. Next, the IM12 is sent to the third IMS node 133, e.g., an l / S-CSCF.

[0114] 705. The call is routed to the third server node 143, e.g., AS3. The third server node 143 may then execute any services using the network asserted data such as the first and / or second data marked with the specific para meter such as the rcd-np, knowing that the data can be trusted. The third server node 143 may also decide to remove untrusted data, parameters and headers from the INVITE that are not marked with the specific parameter. This step may involve several AS invocations.

[0115] 706. The call is routed to the third IMS node 133, e.g., an l / S-CSCF.

[0116] 707. The call is then routed to P-CSCF (Prior art).

[0117] 708. The P-CSCF 162 will remove all specific parameter, e.g., rcd-np, markings from headers that may carry this parameter. It may also remove untrusted data from the INVITE. The verification parameter, e.g., the verstat parameter, will notify the second UE 122 that all conveyed data can be trusted.

[0118] Technical Specification Impact of 3GPP TS 24.229:

[0119] - Update to chapter 5.7 (Procedures at the Application Server (AS))

[0120] - Update to chapter 5.10 (Procedures at the IBCF)

[0121] - Update to chapter 5.7.1.25 (Assertion verification) To perform the method actions above, the originating network edge node 151 is configured to centralise a construction of a PASSporT for signing of verified data of a call in a wireless communications network 100.

[0122] The originating network edge node 151 may comprise an arrangement depicted in Figure 8. The originating network edge node 151 may comprise an input and output interface 800 configured to communicate in the communications network 100, e.g., with the first IMS node 131 and the terminating network edge node 152. The input and output interface 800 may comprise a wireless receiver not shown, and a wireless transmitter not shown.

[0123] The originating network edge node 151 is further being configured to receive an Invite Message IM12 from the first IMS node 131 in the originating network 101. The IM12 is adapted to comprise a first addition and a second addition.

[0124] The IM 12 is adapted to relate to a call to the second UE 122 initiated by the first UE 121. The IM 12 is adapted to comprise a caller identity of the first UE 121 , and a verification parameter, indicating that the caller identity is trusted.

[0125] The first addition is adapted to comprise a first data related to the call marked by a first server node 141 with a specific parameter, indicating that the first data is trusted.

[0126] The second addition is adapted to comprise a second data related to the call, marked by a second server node 142 with the same specific parameter, indicating that the second data is trusted.

[0127] The originating network edge node 151 is further configured to select which parameters or headers comprising parameters comprised in IM 12 to be signed based on the IM 12 marked with the specific parameter.

[0128] The originating network edge node 151 is further configured to construct a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM 12.

[0129] The originating network edge node 151 is further configured to send the constructed PASSporT to a first network node 111 for centralized signing to be valid for server nodes related to the call.

[0130] The originating network edge node 151 is further configured to receive the centralized signed PASSporT from the first network node 111, and send the IM 12 together with the centralized signed PASSporT to a terminating network edge node 152 in a terminating network 102. To perform the method actions above, the terminating network edge node 152 is configured to handle a PASSporT related to a call in a wireless communications network 100.

[0131] The terminating network edge node 152 may comprise an arrangement depicted in Figure 9. The terminating network edge node 152 may comprise an input and output interface 900 configured to communicate in the communications network 100, e.g., with the originating network edge node 151. The input and output interface 900 may comprise a wireless receiver not shown, and a wireless transmitter not shown.

[0132] The terminating network edge node 152 is further being configured to receive from an originating network edge node 151 of an originating network 101 , an Invite Message, IM12, together with a centralized signed PASSporT.

[0133] The IM 12 is adapted to comprise a first addition and a second addition. The IM 12 is relating to a call to a second UE 122 initiated by a first UE 121. The IM12 is adapted to comprise a caller identity of the first UE 121 , and a verification parameter indicating that the caller identity is trusted.

[0134] The first addition is adapted to comprise a first data related to the call, and the second addition is adapted to comprise a second data related to the call.

[0135] The terminating network edge node 152 is further configured to route the centralized signed PASSporT to a second network node 112, requesting assertion and verification of the first data and the second data in IM 12.

[0136] When receiving verified first and / or second data, and assertion result from the second network node 112, the terminating network edge node 152 is further configured to mark a header of the IM 12 as verified by the verification parameter and mark with a specific parameter, the first and / or second data in the IM 12 that has been verified by the PASSporT in the IM 12.

[0137] The terminating network edge node 152 is further configured to route the marked I M 12 towards a third server node 143 for executing services related to the first and / or second data marked with the specific parameter indicating that the first and / or second data is trusted.

[0138] To perform the method actions above, the first IMS node 131 is configured to assist an originating network edge node 151 in a centralisation of constructing a PASSporT for signing of verified data of a call in a wireless communications network 100.

[0139] The first IMS node 131 may comprise an arrangement depicted in Figure 10. The first IMS node 131 may comprise an input and output interface 1000 configured to communicate in the communications network 100, e.g., with the originating network edge node 151 and the terminating network edge node 152. The input and output interface 1000 may comprise a wireless receiver not shown, and a wireless transmitter not shown.

[0140] The first IMS node 131 is further configured to receive an Invite Message (IM) from the second IMS node 132. The IM is adapted to relate to a call to the second UE 122 initiated by the first UE 121. The IM is adapted to comprise a caller identity of the first UE 121 , and a verification parameter, indicating that the caller identity is trusted.

[0141] The first IMS node 131 is further configured to, after routing the IM to a first server node 141 , receive the IM including a first addition, IM1 from the first server node 141 . The first addition is adapted to comprise a first data related to the call, marked with a specific parameter indicating that the first data is trusted.

[0142] The first IMS node 131 is further configured to, after routing the IM1 to a second server node 142, receive the IM1 including a second addition, IM 12 from the second server node 142. The second addition is adapted to comprise a second data related to the call, marked with the same specific parameter, indicating that the second data is trusted.

[0143] The first IMS node 131 is further configured to route the IM 12 to the originating network edge node 151. The IM 12 is adapted to enable the originating network edge node 151 to construct a centralized signed PASSporT to be valid for the first data and the second data on behalf of server nodes related to the call in the originating network 102 and send the centralized signed PASSporT to a terminating network edge node 152.

[0144] Embodiments herein may be implemented through a respective processor or one or more processors, such as the respective processor 810 of a processing circuitry in the originating network edge node 151 depicted in Figure 8, processor 910 of a processing circuitry in the terminating network edge node 152 depicted in Figure 9, and processor 1010 of a processing circuitry in the first IMS node 131 depicted in Figure 10 together with respective computer program code for performing the functions and actions of the embodiments herein. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the respective originating network edge node 151 , terminating network edge node 152 and first IMS node 131. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the respective originating network edge node 151, terminating network edge node 152 and first IMS node 131.

[0145] The originating network edge node 151 , terminating network edge node 152 and first IMS node 131 may further comprise a respective memory 820, memory 920 and memory 1020 comprising one or more memory units. The respective memory 820 and memory 920 and memory 1020 comprises instructions executable by the processor in the respective originating network edge node 151, terminating network edge node 152 and first IMS node 131. The respective memory 820 and memory 920 and memory 1020 are arranged to be used to store e.g., media functions, indications, tags, information, data, configurations, communication data, and applications to perform the methods herein when being executed in the respective originating network edge node 151, terminating network edge node 152 and first IMS node 131.

[0146] In some embodiments, a respective computer program 830, computer program 930 and computer program 1030 comprises instructions, which when executed by the respective at least one processor 810, processor 910 and processor 1010, cause the at least one processor of respective originating network edge node 151 , terminating network edge node 152 and first IMS node 131 to perform the actions above.

[0147] In some embodiments, a respective carrier 840, carrier 940 and carrier 1040 comprises the respective computer program 830 and computer program 930 and computer program 1030, wherein the respective carrier 840, carrier 940 and carrier 1040 is one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or a computer-readable storage medium.

[0148] Those skilled in the art will appreciate that units in the respective originating network edge node 151, terminating network edge node 152 and first IMS node 131 described above may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g. stored in the respective originating network edge node 151, terminating network edge node 152 and first IMS node 131 , that when executed by the respective one or more processors such as the processors described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuitry ASIC, or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a- Chip (SoC). Figure 11 shows an example of a communication system QQ100 in accordance with some embodiments.

[0149] In the example, the communication system QQ100 includes a telecommunication network QQ102 that includes an access network QQ104, such as a radio access network (RAN), and a core network QQ106, which includes one or more core network nodes QQ108. The access network QQ104 includes one or more access network nodes, such as network nodes QQ110a and QQ110b (one or more of which may be generally referred to as network nodes QQ110), or any other similar 3rd Generation Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network QQ102 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network QQ102 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network QQ102, including one or more network nodes QQ110 and / or core network nodes QQ108.

[0150] Examples of an ORAN network node include an open radio unit (0-Rll), an open distributed unit (0-Dll), an open central unit (O-CU), including an O-CU control plane (O- CLI-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an A1, F1, W1 , E1, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies. The network nodes QQ110 facilitate direct or indirect connection of user equipment (UE), such as by connecting UEs QQ112a, QQ112b, QQ112c, and QQ112d (one or more of which may be generally referred to as UEs QQ112) to the core network QQ106 over one or more wireless connections.

[0151] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system QQ100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system QQ100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0152] The UEs QQ112 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes QQ110 and other communication devices. Similarly, the network nodes QQ110 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs QQ112 and / or with other network nodes or equipment in the telecommunication network QQ102 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network QQ102.

[0153] In the depicted example, the core network QQ106 connects the network nodes QQ110 to one or more host computing systems, such as host QQ116. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network QQ106 includes one more core network nodes (e.g., core network node QQ108) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node QQ108. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0154] The host QQ116 may be under the ownership or control of a service provider other than an operator or provider of the access network QQ104 and / or the telecommunication network QQ102. The host QQ116 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0155] As a whole, the communication system QQ100 of 9 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0156] In some examples, the telecommunication network QQ102 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network QQ102 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network QQ102. For example, the telecommunications network QQ102 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0157] In some examples, the UEs QQ112 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network QQ104 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network QQ104. Additionally, a UE may be configured for operating in single- or multi- RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0158] In the example, the hub QQ114 communicates with the access network QQ104 to facilitate indirect communication between one or more UEs (e.g., UE QQ112c and / or QQ112d) and network nodes (e.g., network node QQ110b). In some examples, the hub QQ114 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub QQ114 may be a broadband router enabling access to the core network QQ106 for the UEs. As another example, the hub QQ114 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes QQ110, or by executable code, script, process, or other instructions in the hub QQ114. As another example, the hub QQ114 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub QQ114 may be a content source. For example, for a UE that is a VR device, display, loudspeaker, or other media delivery device, the hub QQ114 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub QQ114 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub QQ114 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0159] The hub QQ114 may have a constant / persistent or intermittent connection to the network node QQ110b. The hub QQ114 may also allow for a different communication scheme and / or schedule between the hub QQ114 and UEs (e.g., UE QQ112c and / or QQ112d), and between the hub QQ114 and the core network QQ106. In other examples, the hub QQ114 is connected to the core network QQ106 and / or one or more UEs via a wired connection. Moreover, the hub QQ114 may be configured to connect to an M2M service provider over the access network QQ104 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes QQ110 while still connected via the hub QQ114 via a wired or wireless connection. In some embodiments, the hub QQ114 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node QQ110b. In other embodiments, the hub QQ114 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node QQ110b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0160] Figure 12 shows a UE QQ200 in accordance with some embodiments. The UE QQ200 presents additional details of some embodiments of the UE QQ112 of Figure 9. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes such as e.g. the originating base station 110- o, the terminating base station 110-t and / or other UEs such as e.g. the first and second UEs 121 , 122. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage / playback device, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), an Augmented Reality (AR) or Virtual Reality (VR) device, wireless customerpremise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including a narrow band internet of things (NB-loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0161] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0162] The UE QQ200 includes processing circuitry QQ202 that is operatively coupled via a bus QQ204 to an input / output interface QQ206, a power source QQ208, a memory QQ210, a communication interface QQ212, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in 10. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0163] The processing circuitry QQ202 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory QQ210. The processing circuitry QQ202 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry QQ202 may include multiple central processing units (CPUs).

[0164] In the example, the input / output interface QQ206 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE QQ200. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0165] In some embodiments, the power source QQ208 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source QQ208 may further include power circuitry for delivering power from the power source QQ208 itself, and / or an external power source, to the various parts of the UE QQ200 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source QQ208. Power circuitry may perform any formatting, converting, or other modification to the power from the power source QQ208 to make the power suitable for the respective components of the UE QQ200 to which power is supplied.

[0166] The memory QQ210 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory QQ210 includes one or more application programs QQ214, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data QQ216. The memory QQ210 may store, for use by the UE QQ200, any of a variety of various operating systems or combinations of operating systems.

[0167] The memory QQ210 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUlCC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory QQ210 may allow the UE QQ200 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory QQ210, which may be or comprise a device-readable storage medium.

[0168] The processing circuitry QQ202 may be configured to communicate with an access network or other network using the communication interface QQ212. The communication interface QQ212 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna QQ222. The communication interface QQ212 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter QQ218 and / or a receiver QQ220 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter QQ218 and receiver QQ220 may be coupled to one or more antennas (e.g., antenna QQ222) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0169] In the illustrated embodiment, communication functions of the communication interface QQ212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0170] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface QQ212, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0171] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0172] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE QQ200 shown in Figure 12.

[0173] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-loT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0174] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0175] Figure 13 shows a network node QQ300 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), O- RAN nodes or components of an O-RAN node (e.g., 0-Rll, 0-Dll, O-CU).

[0176] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0177] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi- cel l / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0178] The network node QQ300 includes a processing circuitry QQ302, a memory QQ304, a communication interface QQ306, and a power source QQ308. The network node QQ300 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node QQ300 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node QQ300 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory QQ304 for different RATs) and some components may be reused (e.g., a same antenna QQ310 may be shared by different RATs). The network node QQ300 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node QQ300, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node QQ300.

[0179] The processing circuitry QQ302 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node QQ300 components, such as the memory QQ304, to provide network node QQ300 functionality.

[0180] In some embodiments, the processing circuitry QQ302 includes a system on a chip (SOC). In some embodiments, the processing circuitry QQ302 includes one or more of radio frequency (RF) transceiver circuitry QQ312 and baseband processing circuitry QQ314. In some embodiments, the radio frequency (RF) transceiver circuitry QQ312 and the baseband processing circuitry QQ314 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry QQ312 and baseband processing circuitry QQ314 may be on the same chip or set of chips, boards, or units.

[0181] The memory QQ304 may comprise any form of volatile or non-volatile computer- readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device- readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry QQ302. The memory QQ304 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry QQ302 and utilized by the network node QQ300. The memory QQ304 may be used to store any calculations made by the processing circuitry QQ302 and / or any data received via the communication interface QQ306. In some embodiments, the processing circuitry QQ302 and memory QQ304 is integrated. The communication interface QQ306 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface QQ306 comprises port(s) / terminal(s) QQ316 to send and receive data, for example to and from a network over a wired connection. The communication interface QQ306 also includes radio front-end circuitry QQ318 that may be coupled to, or in certain embodiments a part of, the antenna QQ310. Radio front-end circuitry QQ318 comprises filters QQ320 and amplifiers QQ322. The radio front-end circuitry QQ318 may be connected to an antenna QQ310 and processing circuitry QQ302. The radio front-end circuitry may be configured to condition signals communicated between antenna QQ310 and processing circuitry QQ302. The radio front-end circuitry QQ318 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry QQ318 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters QQ320 and / or amplifiers QQ322. The radio signal may then be transmitted via the antenna QQ310. Similarly, when receiving data, the antenna QQ310 may collect radio signals which are then converted into digital data by the radio front-end circuitry QQ318. The digital data may be passed to the processing circuitry QQ302. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0182] In certain alternative embodiments, the network node QQ300 does not include separate radio front-end circuitry QQ318, instead, the processing circuitry QQ302 includes radio front-end circuitry and is connected to the antenna QQ310. Similarly, in some embodiments, all or some of the RF transceiver circuitry QQ312 is part of the communication interface QQ306. In still other embodiments, the communication interface QQ306 includes one or more ports or terminals QQ316, the radio front-end circuitry QQ318, and the RF transceiver circuitry QQ312, as part of a radio unit (not shown), and the communication interface QQ306 communicates with the baseband processing circuitry QQ314, which is part of a digital unit (not shown).

[0183] The antenna QQ310 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna QQ310 may be coupled to the radio front-end circuitry QQ318 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna QQ310 is separate from the network node QQ300 and connectable to the network node QQ300 through an interface or port. The antenna QQ310, communication interface QQ306, and / or the processing circuitry QQ302 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna QQ310, the communication interface QQ306, and / or the processing circuitry QQ302 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0184] The power source QQ308 provides power to the various components of network node QQ300 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source QQ308 may further comprise, or be coupled to, power management circuitry to supply the components of the network node QQ300 with power for performing the functionality described herein. For example, the network node QQ300 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source QQ308. As a further example, the power source QQ308 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0185] Embodiments of the network node QQ300 may include additional components beyond those shown in Figure 11 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node QQ300 may include user interface equipment to allow input of information into the network node QQ300 and to allow output of information from the network node QQ300. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node QQ300. In some embodiments providing a core network node, such as core network node 108 of FIG. QQ1, some components, such as the radio front-end circuitry QQ318 and the RF transceiver circuitry QQ312 may be omitted.

[0186] Figure 14 is a block diagram illustrating a virtualization environment QQ400 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments QQ400 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment QQ400 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an 0-2 interface. Virtualization may facilitate distributed implementations of a network node, UE, core network node, or host.

[0187] Applications QQ402 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0188] Hardware QQ404 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers QQ406 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs QQ408a and QQ408b (one or more of which may be generally referred to as VMs QQ408), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer QQ406 may present a virtual operating platform that appears like networking hardware to the VMs QQ408.

[0189] The VMs QQ408 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer QQ406. Different embodiments of the instance of a virtual appliance QQ402 may be implemented on one or more of VMs QQ408, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0190] In the context of NFV, a VM QQ408 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs QQ408, and that part of hardware QQ404 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs QQ408 on top of the hardware QQ404 and corresponds to the application QQ402.

[0191] Hardware QQ404 may be implemented in a standalone network node with generic or specific components. Hardware QQ404 may implement some functions via virtualization. Alternatively, hardware QQ404 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration QQ410, which, among others, oversees lifecycle management of applications QQ402. In some embodiments, hardware QQ404 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system QQ412 which may alternatively be used for communication between hardware nodes and radio units.

[0192] Although the computing devices described herein (e.g., UEs, network nodes) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0193] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0194] When using the word "comprise" or “comprising” it shall be interpreted as nonlimiting, i.e. meaning "consist at least of".

[0195] The embodiments herein are not limited to the preferred embodiments described above. Various alternatives, modifications and equivalents may be used.

Claims

CLAIMS1. A method performed by an originating network edge node (151) for centralising a construction of a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network (100), the method comprising: receiving (301) from a first Internet Protocol Multimedia Subsystem, IMS, node (131) in an originating network (101), an Invite Message IM12, which IM12 comprises a first addition and a second addition, which IM 12 relates to a call to a second User Equipment, UE, (122) initiated by a first UE (121), and which I M 12 comprises a caller identity of the first UE (121), and a verification parameter, indicating that the caller identity is trusted and which first addition comprises a first data related to the call marked by a first server node (141) with a specific parameter indicating that the first data is trusted, and which second addition comprises a second data related to the call, marked by a second server node (142) with the same specific parameter, indicating that the second data is trusted, selecting (302) which parameters or headers comprising parameters comprised in IM 12 to be signed based on the IM12 marked with the specific parameter, constructing (303) a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM 12, sending (304) the constructed PASSporT to a first network node (111) requesting centralized signing to be valid for server nodes related to the call, receiving (305) the centralized signed PASSporT from the first network node (111), sending (306) the IM12 together with the centralized signed PASSporT to a terminating network edge node (152) in a terminating network (102).

2. The method according to claim 1, wherein the specific parameter marking in the first addition and the second addition, is represented by a Session Initiation Protocol, SIP, signalling parameter attached to a respective SIP header or part of a SIP header of the IM12, which have been received in SIP signalling.

3. The method according to any of claims 1-2, wherein the constructing (302) of the PASSporT comprises including a SIP header or parts of a SIP header in the PASSporT, and sending the PASSporT as added to SIP signalling to the first network node (111) for a centralized signing.

4. A method performed by terminating network edge node (152) in a terminating network (102), for handling a Personal Assertion Token, PASSporT, related to a call in a wireless communications network (100), the method comprising: receiving (401) from an originating network edge node (151) of an originating network (101), an Invite Message, IM12, together with a centralized signed PASSporT, which IM 12 comprises a first addition and a second addition, which IM 12 is relating to a call to a second User Equipment, UE, (122) initiated by a first UE (121), which IM 12 comprises a caller identity of the first UE (121), and a verification parameter indicating that the caller identity is trusted, wherein the first addition comprises a first data related to the call and which second addition comprises a second data related to the call, routing (402) the centralized signed PASSporT to a second network node (112) requesting assertion and verification of the first data and the second data in IM12, when receiving (403) verified first and / or second data and assertion result from the second network node (112), marking (404) a header of the I M 12 as verified by the verification parameter and marking with a specific parameter, the first and / or second data in the IM 12 that has been verified by the PASSporT in the IM12, routing (405) the marked IM 12 towards a third server node (143) for executing services related to the first and / or second data marked with the specific parameter indicating that the first and / or second data is trusted.

5. A method performed by a first Internet Protocol Multimedia Subsystem, IMS, node (131) in an originating network (101), for assisting an originating network edge node (151) in a centralisation of constructing a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network (100), the method comprising:receiving (501) an Invite Message, IM, from a second IMS node (132), which IM relates to a call to a second User Equipment, UE, (122) initiated by a first UE (121), and which IM comprises a caller identity of the first UE (121), and a verification parameter, indicating that the caller identity is trusted, after routing (502) the IM to a first server node (141), receiving (503) from the first server node (141), the IM including a first addition, IM1 , wherein the first addition comprises a first data related to the call marked with a specific parameter indicating that the first data is trusted, after routing (504) the IM 1 to a second server node (142), receiving (505) from the second server node (142), the IM1 including a second addition, IM 12, wherein the second addition comprises a second data related to the call, marked with the same specific parameter indicating that the second data is trusted, and routing (506) the IM 12 to the originating network edge node (151), which IM 12 enables the originating network edge node (151) to construct a centralized signed PASSporT to be valid for the first data and the second data on behalf of server nodes related to the call in the originating network (102), and send the centralized signed PASSporT to a terminating network edge node (152).

6. The method according to claim 5, wherein the specific parameter marking in the first addition and the second addition, are Session Initiation Protocol, SIP, signalling parameters attached to a respective SIP header or part of a SIP header of the corresponding IM1 and / or IM 12, which have been received in SIP signalling.

7. The method according to any of claims 5-6, wherein construct the PASSporT comprises including a SIP header or parts of a SIP header in the PASSporT, and sending the PASSporT as added to SIP signalling to the first network node (111) for a centralized signing.

8. A computer program (830) comprising respective instructions, which when executed by a respective processor (810), causes the processor (810) to perform actions according to any of the claims 1-3.

9. A computer program (930) comprising respective instructions, which when executed by a respective processor (910), causes the processor (910) to perform actions according to claim 4.

10. A computer program (1030) comprising respective instructions, which when executed by a respective processor (1010), causes the processor (1010) to perform actions according to any of the claims 5-7.11 . One or more carriers (840, 940, 1040) comprising the respective computer program (830, 930, 1030) of any of claims 8-10, wherein the respective carrier (840, 940, 1040) is one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or a computer-readable storage medium.

12. An originating network edge node (151) configured to centralise a construction of a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network (100), the originating network edge node (151) further being configured to: receive from a first Internet Protocol Multimedia Subsystem, IMS, node (131) in the originating network (101), an Invite Message IM 12, which IM 12 is adapted to comprise a first addition and a second addition, which IM 12 is adapted to relate to a call to a second User Equipment, UE, (122) initiated by a first UE (121), and which IM 12 is adapted to comprise a caller identity of the first UE (121), and a verification parameter, indicating that the caller identity is trusted and which first addition is adapted to comprise a first data related to the call marked by a first server node (141) with a specific parameter, indicating that the first data is trusted, and which second addition is adapted to comprise a second data related to the call, marked by a second server node (142) with the same specific parameter, indicating that the second data is trusted, select which parameters or headers comprising parameters comprised in IM 12 to be signed based on the IM 12 marked with the specific parameter, construct a PASSporT based on the selected parameters or headers comprising parameters, and the verification parameter in IM 12, send the constructed PASSporT to a first network node (111) for centralized signing to be valid for server nodes related to the call,receive the centralized signed PASSporT from the first network node (111), and send the IM12 together with the centralized signed PASSporT to a terminating network edge node (152) in a terminating network (102).

13. The originating network edge node (151) according to claim 12, wherein the specific parameter marking in the first addition and the second addition, is adapted to be represented by a Session Initiation Protocol, SIP, signalling parameter attached to a respective SIP header or part of a SIP header of the IM 12, which have been received in SIP signalling.

14. The originating network edge node (151) according to any of claims 12-13, further being configured to construct the PASSporT by including a SIP header or parts of a SIP header in the PASSporT, and send the PASSporT as added to SIP signalling to the first network node (111) for a centralized signing.

15. A terminating network edge node (152) in a terminating network (102), configured to handle a Personal Assertion Token, PASSporT, related to a call in a wireless communications network (100), the terminating network edge node (152) further being configured to: receive from an originating network edge node (151) of an originating network (101), an Invite Message, IM12, together with a centralized signed PASSporT, which I M 12 is adapted to comprise a first addition and a second addition, which IM 12 is relating to a call to a second User Equipment, UE, (122) initiated by a first UE (121), which IM12 is adapted to comprise a caller identity of the first UE (121), and a verification parameter indicating that the caller identity is trusted, wherein the first addition is adapted to comprise a first data related to the call, and which second addition is adapted to comprise a second data related to the call, route the centralized signed PASSporT to a second network node (112), requesting assertion and verification of the first data and the second data in IM 12, when receiving verified first and / or second data, and assertion result from the second network node (112), mark a header of the IM 12 as verified by theverification parameter and mark with a specific parameter, the first and / or second data in the IM 12 that has been verified by the PASSporT in the IM 12, and route the marked IM 12 towards a third server node (143) for executing services related to the first and / or second data marked with the specific parameter indicating that the first and / or second data is trusted.

16. A first Internet Protocol Multimedia Subsystem, IMS, node (131) in an originating network (101), configured to assist an originating network edge node (151) in a centralisation of constructing a Personal Assertion Token, PASSporT, for signing of verified data of a call in a wireless communications network (100), the first IMS, node (131) further being configured to: receive an Invite Message, IM, from a second IMS node (132), which IM is adapted to relate to a call to a second User Equipment, UE, (122) initiated by a first UE (121), and which IM is adapted to comprise a caller identity of the first UE (121), and a verification parameter, indicating that the caller identity is trusted, after routing the IM to a first server node (141), receive from the first server node (141), the IM including a first addition, IM1 , wherein the first addition is adapted to comprise a first data related to the call, marked with a specific parameter indicating that the first data is trusted, after routing the IM 1 to a second server node (142), receive from the second server node (142), the IM1 including a second addition, IM 12, wherein the second addition is adapted to comprise a second data related to the call, marked with the same specific parameter, indicating that the second data is trusted, and route the IM 12 to the originating network edge node (151), which IM 12 is adapted to enable the originating network edge node (151) to construct a centralized signed PASSporT to be valid for the first data and the second data on behalf of server nodes related to the call in the originating network (102), and send the centralized signed PASSporT to a terminating network edge node (152).

17. The first IMS, node (131) according to claim 16, wherein the specific parameter marking in the first addition and the second addition, is adapted to be represented by a Session Initiation Protocol, SIP, signalling parameter attached to a respective SIP header or part of a SIP header of the corresponding IM1 and / or IM 12, which have been received in SIP signalling.

18. The first IMS node (131) according to any of claims 16-17, wherein construct the PASSporT is adapted to comprise include a SIP header or parts of a SIP header in the PASSporT, and sending the PASSporT as added to SIP signalling to the first network node (111) for a centralized signing.