Propagating congestion information from a service communication proxy

A service communication proxy in telecommunications systems addresses abnormal signaling behavior by subscribing to NWDAF analytics and taking mitigation actions, improving network stability and performance by reducing congestion.

WO2026032984A1PCT designated stage Publication Date: 2026-02-12NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/072515
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2025-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing telecommunications systems face challenges in effectively managing and mitigating abnormal signaling behavior in network functions, leading to congestion and signaling storms, which can impact network performance and efficiency.

Method used

Implementing a service communication proxy (SCP) that subscribes to network data analytics function (NWDAF) for abnormal signaling behavior analytics, receives notifications, and takes actions such as sending information to affected network functions or updating NF profiles to manage and mitigate the abnormal behavior.

Benefits of technology

The SCP effectively mitigates abnormal signaling behavior by enabling network functions to take proactive measures, reducing congestion and enhancing network stability and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025072515_12022026_PF_FP_ABST
    Figure EP2025072515_12022026_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by a service communication proxy (SCP) is provided. The method includes subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior. The method includes receiving a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with an affected network function (NF). The method includes receiving a service request from a NF service consumer for a NF service producer. And the method includes sending information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is the affected NF, where the information so sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior.
Need to check novelty before this filing date? Find Prior Art

Description

PROPAGATING CONGESTION INFORMATION FROM A SERVICE COMMUNICATION PROXYTECHNOLOGICAL FIELD

[0001] The present disclosure relates generally to telecommunications and, in particular, to congestion control in a telecommunications system.BACKGROUND

[0002] A telecommunications system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications path. A telecommunications system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.

[0003] In a wireless telecommunications system at least a part of a communication session between at least two stations occurs over a wireless link. Examples of wireless systems comprise public land mobile networks (PLMN), satellite based communication systems and different wireless local networks, for example wireless local area networks (WLAN). Some wireless systems can be divided into cells, and are therefore often referred to as cellular systems.

[0004] A user can access the telecommunications system by means of an appropriate communication device or terminal. A communication device of a user may be referred to as user equipment (UE) or user device. A communication device is provided with an appropriate signal receiving and transmitting apparatus for enabling communications, for example enabling access to a communication network or communications directly with other users. The communication device may access a carrier provided by a station, for example a base station of a cell, and transmit and / or receive communications on the carrier.

[0005] The telecommunications system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. One example of a telecommunications system is the Universal Mobile Telecommunications System (UMTS). Other examples of telecommunications systems are Long-Term Evolution (LTE), LTE Advanced and the so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP).BRIEF SUMMARY

[0006] Example implementations of the present disclosure are directed to telecommunications and, in particular, to congestion control in a telecommunications system. The present disclosure includes, without limitation, the following example implementations.

[0007] Some example implementations provide an apparatus to implement a service communication proxy (SCP), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: subscribe at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receive a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); receive a service request from a NF service consumer for a NF service producer; and at least one of: send information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or update a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0008] Some example implementations provide an apparatus implemented by a service communication proxy (SCP), the apparatus comprising: means for subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; meansfor receiving a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); means for receiving a service request from a NF service consumer for a NF service producer; and at least one of: means for sending information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or means for updating a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0009] Some example implementations provide a method performed by a service communication proxy (SCP), the method comprising: subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receiving a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); receiving a service request from a NF service consumer for a NF service producer; and at least one of: sending information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or updating a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0010] Some example implementations provide a computer-readable storage medium that is non-transitory and has instructions stored therein that, in response to execution by at least one processing circuitry, causes a service communication proxy (SCP) to at least: subscribe at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receive a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); receive a service request from a NF service consumer for a NF service producer; and at least one of:send information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or update a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0011] Some example implementations provide an apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause a network function (NF) to at least: receive information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); identify one or more application sessions involving the affected NF; and take one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0012] Some example implementations provide an apparatus implemented by a network function (NF), the apparatus comprising: means for receiving information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); means for identifying one or more application sessions involving the affected NF; and means for taking one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0013] Some example implementations provide a method performed by a network function (NF), the method comprising: receiving information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); identifying one or more application sessions involving the affected NF; and taking one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0014] Some example implementations provide a computer-readable storage medium comprising: at least one memory configured to store instructions; and at least one processingcircuitry configured to access the at least one memory, and execute the instructions to cause a network function (NF) to at least: receive information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); identify one or more application sessions involving the affected NF; and take one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0015] These and other features, aspects, and advantages of the present disclosure will be apparent from a reading of the following detailed description together with the accompanying figures, which are briefly described below. The present disclosure includes any combination of two, three, four or more features or elements set forth in this disclosure, regardless of whether such features or elements are expressly combined or otherwise recited in a specific example implementation described herein. This disclosure is intended to be read holistically such that any separable features or elements of the disclosure, in any of its aspects and example implementations, should be viewed as combinable unless the context of the disclosure clearly dictates otherwise.

[0016] It will therefore be appreciated that this Brief Summary is provided merely for purposes of summarizing some example implementations so as to provide a basic understanding of some aspects of the disclosure. Accordingly, it will be appreciated that the above described example implementations are merely examples and should not be construed to narrow the scope or spirit of the disclosure in any way. Other example implementations, aspects and advantages will become apparent from the following detailed description taken in conjunction with the accompanying figures which illustrate, by way of example, the principles of some described example implementations.BRIEF DESCRIPTION OF THE FIGURE(S)

[0017] Having thus described example implementations of the disclosure in general terms, reference will now be made to the accompanying figures, which are not necessarily drawn to scale, and wherein:

[0018] FIG. 1 illustrates a telecommunications system that includes one or more public land mobile networks (PLMNs) coupled to one or more external data networks, according to some example implementations of the present disclosure;

[0019] FIG. 2 illustrates a deployment of a PLMN, according to some example implementations;

[0020] FIG. 3 more particularly depicts aspects of the deployment of FIG. 2, according to some example implementations;

[0021] FIG. 4 illustrates a signaling chart of a procedure to handle abnormal signaling behavior of a network function (NF) service consumer (NFc), according to some example implementations;

[0022] FIG. 5 illustrates a signaling chart of a procedure to handle abnormal signaling behavior of a NF service producer (NFp), according to some example implementations;

[0023] FIG. 6 illustrates a signaling chart of a procedure to handle abnormal signaling behavior of a NFp NF set, according to some example implementations.

[0024] FIG. 7 illustrates a signaling chart of a procedure to handle abnormal signaling behavior of a NFp service communication proxy (SCP) domain, according to some example implementations;

[0025] FIG. 8 illustrates a signaling chart of a procedure for delegated service discovery, according to some example implementations;

[0026] FIGS. 9A, 9B and 9C are flowcharts illustrating various steps in a method performed by a SCP, according to various example implementations;

[0027] FIG. 10 is a flowchart illustrating various steps in a method performed by a NF, according to various example implementations; and

[0028] FIG. 11 illustrates an apparatus according to some example implementations.DETAILED DESCRIPTION

[0029] Some implementations of the present disclosure will now be described more fully hereinafter with reference to the accompanying figures, in which some, but not all implementations of the disclosure are shown. Indeed, various implementations of the disclosure may be embodied in many different forms and should not be construed as limited to the implementations set forth herein; rather, these example implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Like reference numerals refer to like elements throughout.

[0030] Unless specified otherwise or clear from context, references to first, second or the like should not be construed to imply a particular order. A feature described as being above another feature (unless specified otherwise or clear from context) may instead be below, and vice versa; and similarly, features described as being to the left of another feature else may instead be to the right, and vice versa. Also, while reference may be made herein to quantitative measures, values, geometric relationships or the like, unless otherwise stated, any one or more if not all of these may be absolute or approximate to account for acceptable variations that may occur, such as those due to engineering tolerances or the like.

[0031] As used herein, unless specified otherwise or clear from context, the “or” of a set of operands is the “inclusive or” and thereby true if and only if one or more of the operands is true, as opposed to the “exclusive or” which is false when all of the operands are true. Thus, for example, “[A] or [B]” is true if [A] is true, or if [B] is true, or if both [A] and [B] are true. Further, the articles “a” and “an” mean “one or more,” unless specified otherwise or clear from context to be directed to a singular form. Furthermore, it should be understood that unless otherwise specified, the terms “data,” “content,” “digital content,” “information,” and similar terms may be at times used interchangeably. The term “network” may refer to a group of interconnected computers including clients and servers; and within a network, these computers may be interconnected directly or indirectly by various means including via one or more switches, routers, gateways, access points or the like.

[0032] Reference may be made herein to terms specific to a particular system, architecture or the like, but it should be understood that example implementations of the present disclosure may be equally applicable to any of a number of systems, architectures and the like. For example, reference may be made to 3 GPP technologies such as Global System for Mobile Communications (GSM), UMTS, LTE, LTE Advanced, 5GNR, 5G Advanced and 6G; however, it should be understood that example implementations of the present disclosure may be equally applicable to non-3GPP technologies such as IEEE 802, Bluetooth and Bluetooth Low Energy.

[0033] Further, as used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry); (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) withsoftware / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); or (c) hardware circuit(s) and / or processor(s), such as a microprocessor(s) or a portion of a microprocessor s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0034] The above definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0035] FIG. 1 illustrates a telecommunications system 100 according to various example implementations of the present disclosure. The telecommunications system generally includes one or more telecommunications networks. As shown, for example, the system includes one or more public land mobile networks (PLMNs) 102 coupled to one or more other external data networks 104 - notably including a wide area network (WAN) such as the Internet. Each of the PLMNs includes a core network (CN) 106 backbone such as the Evolved Packet Core (EPC) of LTE, the 5G core network (5GC) or the like; and each of the core networks and the Internet are coupled to one or more radio access networks (RANs) 108, air interfaces or the like that implement one or more radio access technologies (RATs). As used herein, a “network device” refers to any suitable device at a network side of a telecommunications network. Examples of suitable network devices are described in greater detail below.

[0036] In addition, the system includes one or more radio units that may be varyingly known as user equipment (UE) 110, terminal device, terminal equipment, mobile station or the like. The UE is generally a device configured to communicate with a network device or a further UE in a telecommunication network. The UE may be a portable computer (e.g., laptop, notebook, tablet computer), mobile phone (e.g., cell phone, smartphone), wearable computer (e.g., smartwatch), or the like. In other examples, the UE may be an Internet of Things (loT)device, an industrial loT (IIoT device), a vehicle equipped with a vehicle-to-everything (V2X) communication technology, or the like. In some examples, as referenced by 3 GPP, the UE may be a narrowband loT (NB-IoT) device, an enhanced machine-type communication (eMTC) device, a reduced capability (RedCap) device, an ambient loT device, or the like.

[0037] In operation, these UEs may be configured to connect to one or more of the RANs 108 according to their particular radio access technologies to thereby access a particular CN 106 of a PLMN 102, or to access one or more of the external data networks 104 (e.g., the Internet). The external data network may be configured to provide Internet access, operator services, 3rd party services, etc. For example, the International Telecommunication Union (ITU) has classified 5G mobile network services into three categories: enhanced mobile broadband (eMBB), ultra-reliable and low-latency communications (URLLC), and massive machine type communications (mMTC) or massive internet of things (MIoT).

[0038] Examples of radio access technologies include 3 GPP radio access technologies such as GSM, UMTS, LTE, LTE Advanced, 5GNR, 5G Advanced, and 6G. Other examples of radio access technologies include IEEE 802 technologies such as IEEE 802.11 (Wi-Fi), IEEE 802.15 (including 802.15.1 (WPAN / Bluetooth), 802.15.4 (Zigbee) and 802.15.6 (WBAN)), Bluetooth, Bluetooth Low Energy (BLE), ultra wideband (UWB), and the like. Generally, a radio access technology may refer to any 2G, 3G, 4G, 5G, 6G or higher generation mobile communication technology and their different versions, as well as to any other wireless radio access technology that may be arranged to interwork with such a mobile communication technology to provide access to the CN 106 of a mobile network operator (MNO).

[0039] In various examples, a RAN 108 may be configured as one or more macrocells, microcells, picocells, femtocells or the like. The RAN may generally include one or more radio access nodes that are configured to interact with UEs 110. In various examples, a radio access node may be referred to as a base station (BS), access point (AP), base transceiver station (BTS), Node B (NB), evolved NB (eNB), macro BS, NB (MNB) or eNB (MeNB), home BS, NB (HNB) or eNB (HeNB), next generation NB (gNB), enhanced gNB (en-gNB), next generation eNB (ng-eNB), or the like. The RAN may include some type of network controlling / governing entity responsible for control of the radio access nodes. The network controlling / governing entity and radio access node may be separate or integrated into a single apparatus. The network controlling / governing entity may include processing circuityconfigured to carry out various management functions, etc. The processing circuity may be associated with a memory, computer-readable storage medium or database for maintaining information required in the management functions.

[0040] ARAN 108 may be centralized or distributed. In various examples, components of a RAN may be interconnected by Ethernet, Gigabit Ethernet, Asynchronous Transfer Mode (ATM), optical fiber, dark fiber, passive wavelength division multiplexing (WDM), WDM passive optical network (WDM-PON), optical transport network (OTN), time sensitive networking (TSN) and / or any other data link layer network, possibly including radio links.The RAN may be connected to a CN 106 through one or more gateways, network functions or the like.

[0041] As will be appreciated, a PLMN 102 may be deployed in a number of different manners. In a 4GLTE deployment, the EPC is the CN 106, and the evolved UMTS terrestrial radio access network (E-UTRAN) is the RAN 108; and the E-UTRAN includes one or more eNBs (radio access nodes) configured to connect UEs 110 to the E-UTRAN to thereby access the EPC. FIG. 2 illustrates a deployment 200, such as a 5G or 6G deployment. As shown, the 5GC 202 is the CN, and the next generation (NG) radio access network (NG-RAN) 204 is the RAN; and the NG-RAN includes one or more gNBs 206 (radio access nodes) configured to connect UEs 110 to the NG-RAN to thereby access the 5GC. The term ‘gNB’ in 5G may correspond to the eNB in 4G LTE.

[0042] Some 4G LTE and 5G deployments are considered standalone (SA) deployments.Other deployments combine 4G LTE and 5 G technologies, and are referred to as non- standalone (NSA) deployments. In some deployments, the E-UTRAN includes one or more ng-eNBs that are configured to communicate with the 5GC, and that may also be configured to communicate with one or more gNBs. Similarly, in another deployment, the NG-RAN may include one or more en-gNBs that are configured to communicate with the EPC, and that may also be configured to communicate with one or more eNBs. In various instances, a single UE 110, a dual-mode or multimode UE, may support multiple (two or more) RANs — thereby being configured to connect to multiple RANs, such as 4G LTE and 5G.

[0043] In some deployments, such as deployment 200, operations of the gNB 206 or other radio access node may be carried out, at least partly, in a central / centralized unit (CU), such as a server, host or node, operationally coupled to a distributed unit (DU), such as a radiohead / node. It is also possible that node operations may be distributed among a plurality of servers, hosts or nodes. It should also be understood that the distribution of work between 5GC 202 (or other CN) operations and gNB (or other radio access node) operations may vary depending on implementation.

[0044] A 5G network architecture may be based on a so-called CU-DU split. One gNB- CU (central node) may control one or more gNB-DUs. The gNB-CU may control a plurality of spatially separated gNB-DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some example implementations, however, the gNB-DUs (also called DU) may include, for example, a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the gNB-CU (also called a CU) may include the layers above the RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC), and an internet protocol (IP) layer. Other functional splits are also possible. It is considered that a skilled person is familiar with the open systems interconnection (OSI) model and the functionalities within each layer.

[0045] In some example implementations, the server or CU may generate a virtual network through which the server communicates with the radio node. In general, virtual networking may involve a process of combining hardware and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Such virtual network may provide flexible distribution of operations between the server and the radio head / node. In practice, any digital signal processing task may be performed in either the CU or the DU, and the boundary where the responsibility is shifted between the CU and the DU may be selected according to implementation.

[0046] FIG. 3 more particularly depicts aspects of the deployment 200 for a MNO, according to some example implementations. As shown, the deployment includes the 5GC 202, and NG-RAN 204 with one or more gNBs 206 configured to connect UEs 110 to the NG- RAN to thereby access the 5GC. The 5GC may include a number of network functions (NFs) divided between the control plane and the user plane. In particular, the 5GC may include, for example, an access and mobility management function (AMF) 302, a session management function (SMF) 304, a user plane function (UPF) 306, a network exposure function (NEF) 308, a network data analytics function (NWDAF) 310, and / or an application function (AF) 312. Other examples of suitable NFs include a network repository function (NRF) 314, anetwork slice selection function (NSSF), a policy control function (PCF), a unified data management (UDM) 316, a service communication proxy (SCP) 318, or the like.

[0047] In the control plane, the AMF 302 is configured to provide UE-based authentication, authorization, mobility management, etc. The SMF 304 is configured to provide various functionality including session management (SM), UE Internet Protocol (IP) address allocation and management, selection and control of UPF(s) 306, control part of policy enforcement and Quality of Service (QoS), lawful intercept, termination of SM parts of NAS messages, Downlink Data Notification (DNN), roaming functionality, handle local enforcement to apply QoS for Service Level Agreements (SLAs), charging data collection and charging interface, etc. If the UE 110 has multiple sessions, different SMFs may be allocated to each session to manage them individually and possibly provide different functionalities per session.

[0048] The UPF 306 supports various user plane operations and functionalities, such as packet routing and forwarding, traffic handling (e.g., QoS enforcement), an anchor point for intra-RAT / inter-RAT mobility (when applicable), packet inspection and policy rule enforcement, lawful intercept (UP collection), traffic accounting and reporting, etc. The UPF is the point of interconnect between the 5GC and at least one external data network (DN) 318 (i.e., point of ingress or egress for a DN), and routes packets to and from the DN. The DN may be configured to provide Internet access, operator services, 3rd party services, etc.

[0049] The NWDAF 310 collects and analyzes network data to provide insights into the performance, optimization, and overall health of the 5GC 202. This information may be used for network management, optimization, and decision-making processes to enhance the network’s efficiency.

[0050] The AF 312 may interact with the 5GC 202 to enable the deployment of specific services and applications. The AF communicates with other NFs to request and manage network resources, ensuring that the network adapts to the requirements of different applications and services. The NEF 308 allows authorized third-party applications and services to access specific network functions and services in a controlled manner. The NEF enables the exposure of network capabilities to external entities, fostering innovation and the development of new services.

[0051] In some examples, one or more SCPs 318 may be deployed for indirect communication between NFs. An SCP is an intermediate network entity to assist in indirect communication between one NF referred to as an NF service consumer (NFc), and another NF referred to as an NF service producer (NFp). In this regard, the SCP may assist in routing messages, such as control plane messages between the NFs. The SCP may discover and select NFp on behalf of NFc. The SCP may also support load balancing, monitoring, and / or overload control functionality.

[0052] Direct communication may be applied between an NFc and an NFp for an NF service, or NF service communication may be performed indirectly via SCP(s) 318. In direct communication, the NFc performs discovery of the target NFp by local configuration or via local NRF 314 (this NRF may be referred to as a NRFc). In indirect communication, the NFc may delegate the discovery of the target NFp to the SCP . In the latter case, the SCP may use the parameters provided by NFc to perform discovery and / or selection of the target NFp , such as with reference to one or more NRFs.

[0053] NF discovery and NF service discovery enable entities, such as an NFc or SCP 318, to discover a set of NF instance(s) and NF service instance(s) for a specific NF service or an NFp type. The NFc and / or the SCP may be core network entities. The NRF may include a function that is used to support the functionality of NF and NF service registration, discovery, authorization and status notification. Additionally or alternatively, the NRF 314 may be configured to act as an authorization server. The NRF may maintain an NF profile of available NFp entities and their supported services. The NRF may notify about newly registered, updated, or deregistered NFp entities along with its NF services to a subscribed NFc or SCP. An NRF may thus advise NFc entities or SCP concerning where, that is, from which NFp entities, they may obtain services they need. In general, an NRF is a terminological example of a network support node, and an SCP is a terminological example of a proxy entity. An NRF may be separate from or co-located with an SCP, or even hosted by a service provider.

[0054] In order for the NFc or SCP 318 to obtain information about the NFp and / or NF service(s) registered or configured in a PLMN / slice, the NFc or SCP may initiate, based on local configuration, a discovery procedure with an NRF, such as NRF 314. The discovery procedure may be initiated by providing the type of the NFp and optionally a list of thespecific service(s) it is attempting to discover. The NFc or SCP may additionally or alternatively provide other service parameters, such as information relating to network slicing.

[0055] In some deployments, SCPs 318 may be organized in SCP domains that are stored in the NRF 314 by the SCP as part of an NF profile of the SCP (an SCP profile), and that may be retrieved by other NFs (e.g., SCPs) to decide how to route messages. The SCP profile of an SCP may include information including, for example, NF sets of NFs served by the SCP, and the SCP domain that the SCP belongs to. If an SCP belongs to more than one SCP domain, the SCP may be able to bridge these domains, i.e., send messages between these domains.

[0056] For Release 19, 3 GPP has studied a number of artificial intelligence (Al) / machine learning (ML) enhancements for the core network, including enhancements related to mitigating signaling storms caused by massive signaling of UEs 110 and / or caused by NFs signaling. It has been agreed that by means of statistics and predictions, the NWDAF 310 supports assistance to signaling storm mitigation and prevention by statistically learning the expected normal level of signaling and identifying a significant deviation indicating a signaling storm. A new analytics identity (ID) to support signaling storm mitigation and prevention caused by NFs signaling may also be defined. In one current proposal, entities that may subscribe to this new analytics ID (e.g., “control plane signaling abnormality”) include the SCP 318 (in the case of using SCP for service communication between NFs).

[0057] An agreement has also been made on output data from the NWDAF 310 to support storm mitigation and prevention. The output data may include statistics analytics, such as target NF ID, cause of the signaling storm (e.g., signaling storm caused by UEs 110 and signaling storm caused by NF), NF lists or a group of UEs, statistics corresponding to the input data, and the like. The output data may also include prediction analytics, such as target NF ID, cause of the signaling storm, NF lists or a group of UEs 110, prediction corresponding to the input data, confidence level of the prediction, and the like.

[0058] Examples of mitigation or prevention for NFs are currently under discussion, and a final mitigation or prevention operations may be based on MNO policy / configuration and NF implementation. The mitigation and prevention may be based on factors such as UE-related configurations (back-off timers, thresholds, slice or priority based overload control, etc.), and / or NF-related configuration ((re)discovery / selection, prioritizations, threshold, etc.). Existing mechanisms to mitigate and prevent a signaling storm caused by NF abnormalsignaling include, for example, the source NF / SCP 318 configures to (re)select other NFs instead of the NF with abnormal signaling, and may unsubscribes the NF with abnormal signaling. In another example, the source NF / SCP may configure to deprioritize the NFs / services with abnormal signaling from being selected.

[0059] In some examples, an SCP 318 may request throttling, back-pressure, connection pooling, or the like; and as indicated above, an SCP may support load balancing, monitoring, and / or overload control functionality. In the context of load balancing or control, for example, the SCP may signal load control information (LCI) or overload control information (OCI) to manage and optimize network traffic by providing dynamic load status information. The SCP may convey LCI through a “3gpp-Sbi-Lci” HTTP (hypertext transfer protocol) header that includes information such as a timestamp and load metric, which helps other NFs make informed routing decisions to evenly distribute traffic. The SCP may convey OCI through a “3gpp-Sbi-Oci” HTTP header that includes information such as a timestamp and an overload reduction metric, which helps other NFs adjust their signaling traffic to mitigate overload.

[0060] The SCP 318 should be enabled to take actions to mitigate an observed or expected signaling storm caused by another NF when the SCP is informed about the signaling storm via analytics, such as from the NWDAF 310. The SCP itself may be able to select an NFp other than the NF diagnosed with an observed (current) or expected (predicted) future abnormal signaling, or to throttle or block signaling sent by the NF. The NFp and NFc, however, have more far-reaching possibilities for mitigation actions. For example, the SCP is hardly able to select message exchanges or users to handle with priority based on application logic. It would be beneficial that not all NFs in a network need to subscribe to analytics about a signaling storm but that the SCP as central entity involved in all communication does so.

[0061] In view of the foregoing, example implementations provide a solution in which an SCP 318 may be informed via a subscription for analytics that some NF is causing or expected to cause a signaling storm. When forwarding signaling that originates from that signaling- storm-causing NF (either a request sent by that NF as a NFc or a response sent by that NF as an NFp) towards some peer NF, the SCP may add information about the observed (current) or expected signaling storm based on the related information received from the NWDAF 310.

[0062] The information about a observed or expected signaling storm may be signaled by the SCP 318 to a NFp or NFc in a number of different manners. In some examples, theinformation may be signaled in a custom HTTP header (e.g., an abnormality indication header) or via extensions of the existing LCI header (3gpp-Sbi-Lci) or the existing OCI header (3gpp-Sbi-Oci). This information about the observed or expected signaling storm may include, for example, type of signaling storm, expected time or period for the signaling storm, intensity, affected services, or the like.

[0063] In some examples, the SCP 318 may also reject a request sent toward the signaling- storm-causing NF and, in a message to reject the request, include information about the observed or expected signaling storm (e.g., type of signaling storm, expected time, intensity, affected services).

[0064] In some examples, if the signaling storm impacts an entire NF set, the SCP 318 may also update its SCP profile at the NRF 314 to indicate the NF set of the NF that is causing or expected to cause a signaling storm is no longer reachable via the SCP.

[0065] When the peer NF receives the added information about the observed or expected signaling storm, the peer NF may identify application sessions involving the signaling-storm- causing NF, which for an expected (predicted) signaling storm, may include application sessions expected to last until the expected time of the signaling storm. The peer NF may also possibly selects application sessions with lower priority among the application sessions involving the signaling-storm-causing NF.

[0066] The peer NF may then take one or more actions to mitigate the signaling storm for one or more of the identified application sessions. For example, the peer NF may terminate one or more of the identified application sessions, and possibly re-establishing the application session(s) via another NF (e.g., before the expected time of the signaling storm). The peer NF may reduce the amount of requests sent within the application session(s), rejecting incoming request(s) within the application session(s) with an error code and / or back-off timer to prevent that the incoming request(s) are repeated.

[0067] In some examples, an analytics ID for the NF causing or expected to cause a signaling storm may also indicate an SCP domain as a target for reporting. The NWDAF 310 may then report signaling storm(s) impacting particular NFs in the SCP domain, as well as signaling storm(s) impacting all NFs in the SCP domain. In the latter case, the SCP may handle any requests directed towards an NF in that SCP domain as described above, and theSCP may in addition update its SCP profile at the NRF 314 to indicate the SCP domain that is causing or expected to cause a signaling storm is no longer reachable via the SCP.

[0068] According to some example implementations, an application session may be a packet data unit (PDU) session. If an AMF 302 is informed that an SMF 304 handling a PDU session for a UE 110 is expected to cause problems, the AMF may trigger the UE to release and re-establish its PDU session and select a new SMF for the PDU session established afterwards. In another example, if the SMF is part of an SMF set and other SMFs of the SMF set are not expected to cause problems, the AMF may seamlessly reselect other SMF(s) in the same SMF set for PDU sessions served by the SMF expected to cause problems.

[0069] FIG. 4 illustrates a signaling chart 400 of a procedure to handle abnormal signaling behavior of a NFc 412, according to some example implementations. As shown, the SCP 318 at step 401 subscribes at the NWDAF 310 for analytics related to abnormal network behavior or signaling storm. The subscription may, for example, indicate one of several target NFs of a particular type (e.g., typel). In some examples, the SCP requests the analytics, or subscribes to the analytics when receiving a request from that target NF type (as the request in step 403), or a request targeting that NF type.

[0070] The NWDAF 310 at step 402 notifies the SCP 318 about an observed or expected abnormal NF behavior that affects an NFc 412. The NWDAF may indicate the affected NFc via NF type, set, instance ID (in this example NF type A, Setl, instance i), an identifier describing the type of the abnormal behavior (e.g., overload, erroneous behavior), expected intensity, expected abnormality time window, affected services, or the like.

[0071] The SCP 318 at step 403 receives an HTTP request originating from the affected NFc 412 identified in step 402, where the HTTP request is targeted towards a NFp 414. The request may be received via another intermediate node (e.g., an HTTP proxy, another SCP or a security edge protection proxy (SEPP)).

[0072] The SCP 318 at step 404 forwards the HTTP request towards the target NFp 414 or another intermediate node (e.g., an HTTP proxy, another SCP or a SEPP). The SCP includes information that indicates that the NFc 412 that sent the HTTP request is displaying or is expected to display abnormal behavior and may include any of the related parameters described in step 402. In some examples, this information is conveyed in an extended 3gpp-Sbi-Lci HTTP header (the extensions may for example include information about a time window when the abnormal behavior is expected).

[0073] The target NFp 414 at step 405 sends a reply to the HTTP request.

[0074] The SCP 318 at step 406 forwards the reply to the HTTP request to the affected NFc 412. In some examples, the SCP includes information that indicates the NFc that sent the HTTP request is displaying or is expected to display abnormal behavior and may include any of the related parameters described in step 402.

[0075] The target NFp 414 at step 407 takes one or more actions to mitigate the abnormal behavior. The target NFp may for example identify application sessions (e.g., PDU sessions) involving affected NFc 412 (for predicted future signaling storms, e.g., application sessions expected to last until the expected time of the signaling storm). The target NFp may also possibly select application sessions with lower priority among them. The target NFp takes action(s) to mitigate the signaling storm such as terminating related application sessions and possibly re-establishing the application session via another NF (e.g., before the expected time of the signaling storm), reducing the amount of requests sent within the application session, rejecting incoming requests within the application session with an error code and / or back-off timer preventing that they are repeated.

[0076] The affected NFc 412 at step 408 takes one or more actions to mitigate the abnormal behavior. The NFc may for example identify application sessions (e.g., PDU sessions) (for predicted future signaling storms, e.g., application sessions expected to last until the expected time of the signaling storm), and possibly select application sessions with lower priority among them. The affected NFc may take action(s) to mitigate the signaling storm such as terminating related application sessions and possibly re-establishing the application session via another NFc (e.g., before the expected time of the signaling storm), reducing the amount of requests sent within the application session, rejecting incoming requests within the application session with an error code and / or back-off timer preventing that they are repeated.

[0077] FIG. 5 illustrates a signaling chart 500 of a procedure to handle abnormal signaling behavior of a NFp 414, according to some example implementations. As shown, the SCP 318 at step 501 subscribes at the NWDAF 310 for analytics related to abnormal network behavior or signaling storm. The subscription may include, for example, information that indicates one of several target NFs of a particular type (e.g., typel). In some examples, the SCP requests theanalytics, or subscribes to the analytics when receiving a request from that target NF type, or a request targeting that NF type (as the request in step 503).

[0078] The NWDAF 310 at step 502 notifies the SCP 318 about an observed or expected abnormal NF behavior that affects an NFp 414. The NWDAF may include information that indicates the affected NFp via NF type, set, instance ID (in this example NF type B, Set2, instance ii), an identifier describing the type of the abnormal behavior (e.g., overload, erroneous behavior), expected intensity, expected abnormality time window, affected services, or the like.

[0079] The SCP 318 at step 503 receives an HTTP request targeting the affected NFp 414 identified in step 502. The request may be received via another intermediate node (e.g., an HTTP proxy, another SCP or a SEPP).

[0080] The SCP 318 at step 504 forwards the HTTP request towards the target (affected) NFp 414 or another intermediate node (e.g., an HTTP proxy, another SCP or a SEPP). In some examples, it includes information that indicates the target NFp is displaying or is expected to display abnormal behavior and may include any of the related parameters described in step 502. In some examples, this information is conveyed in an extended 3gpp-Sbi-Lci HTTP header (the extensions may for example include information about a time window when the abnormal behavior is expected).

[0081] The target (affected) NFp 414 at step 505 sends a reply to the HTTP request.

[0082] The SCP 318 at step 506 forwards the reply to the HTTP request to the NFc 412 (possibly via intermediate nodes). The reply includes information that indicates the NFp 414 that sent the HTTP reply is displaying or is expected to display abnormal behavior and may include any of the related parameters described in step 502. In some examples, this information is conveyed in an extended 3gpp-Sbi-Lci HTTP header (the extensions may for example include information about a time window when the abnormal behavior is expected).

[0083] The NFc 412 at step 507 takes one or more actions to mitigate the abnormal behavior. The NFc may for example identify application sessions (e.g., PDU sessions) involving that signaling-storm-causing NF for predicted future signaling storms, e.g., application sessions expected to last until the expected time of the signaling storm), and possibly select application sessions with lower priority among them. The NFc takes action(s) to mitigate the signaling storm such as terminating related application sessions and possiblyre-establishing the application session via another NF (e.g., before the expected time of the signaling storm), reducing the amount of requests sent within the application session, rejecting incoming requests within the application session with an error code and / or back-off timer preventing that they are repeated.

[0084] The target (affected) NFp 414 at step 508 takes one or more actions to mitigate the abnormal behavior. The target NFp may for example identify application sessions (e.g., PDU sessions) for predicted future signaling storms, e.g., application sessions expected to last until the expected time of the signaling storm), and possibly select application sessions with lower priority among them. The target NFp takes action(s) to mitigate the signaling storm such as terminating related application sessions and possibly re-establishing the application session via another NF (e.g., before the expected time of the signaling storm), reducing the amount of requests sent within the application session, rejecting incoming requests within the application session with an error code and / or back-off timer preventing that they are repeated.

[0085] FIG. 6 illustrates a signaling chart 600 of a procedure to handle abnormal signaling behavior of a NFp NF set, according to some example implementations. As shown, the SCP 318 at step 601 subscribes at the NWDAF 310 for analytics related to abnormal network behavior or signaling storm. The subscription may include, for example, information that indicates one of several target NF sets. In some examples, the SCP requests the analytics, or subscribes to the analytics when receiving a request from that target set, or a request targeting that set (as the request in step 604).

[0086] The NWDAF 310 at step 602 notifies the SCP 318 about an observed or expected abnormal NF behavior that affects an entire NF set including an affected NFp 414. The NWDAF may include, for example, information that indicates the affected NF set (in this example set 2), an identifier describing the type of the abnormal behavior (e.g., overload, erroneous behavior), expected intensity, expected abnormality time window, affected services, or the like.

[0087] The SCP 318 at step 603 decides, based on the information received in step 602 (e.g., abnormality type, intensity and time window), that the NF set should no longer be targeted by HTTP requests. The SCP thus updates its SCP profile at the NRF 314 to remove the corresponding NF set ID from the list of NF sets reachable through the SCP.

[0088] The SCP 318 at step 604 receives an HTTP request from an NFc 412 that targets the affected NFp 414 within the affected NF set identified in step 602. The request may be received via or another intermediate node (e.g., an HTTP proxy, another SCP or a SEPP).

[0089] The SCP 318 at step 605 rejects the HTTP request by sending an error response towards the NFc 412 (possibly via the intermediate nodes in step 604). The error response includes information that indicates the NF set of the target (affected) NFp 414 is displaying or is expected to display abnormal behavior and may include any of the related parameters described in step 602. In some examples, this information is conveyed in an extended 3gpp- Sbi-Lci HTTP header (the extensions may for example include information about a time window when the abnormal behavior is expected).

[0090] The NFc 412 at step 606 takes one or more actions to mitigate the abnormal behavior. The NFc may for example identify application sessions (e.g., PDU sessions) involving that signaling-storm-causing NF for predicted future signaling storms, e.g., application sessions expected to last until the expected time of the signaling storm), and possibly select application sessions with lower priority among them. The NFc takes action(s) to mitigate the signaling storm such as terminating related application sessions and possibly re-establishing the application session via another NF (e.g., before the expected time of the signaling storm), reducing the amount of requests sent within the application session, rejecting incoming requests within the application session with an error code and / or back-off timer preventing that they are repeated.

[0091] FIG. 7 illustrates a signaling chart 700 of a procedure to handle abnormal signaling behavior of a NFp SCP domain, according to some example implementations. The SCP 318 at step 701 subscribes at the NWDAF 310 for analytics related to abnormal network behavior or signaling storm. The subscription may include, for example, information that indicates one of several target SCP domains. The SCP domain describes that an SCP is used as entry node for all requests towards NFs in that SCP domain, for example all nodes in a server farm. In some examples, the SCP requests the analytics, or subscribes to the analytics when receiving a request targeting that SCP domain (as the request in step 704).

[0092] The NWDAF 310 at step 702 notifies the SCP 318 about an observed or expected abnormal NF behavior that affects all NFs in an SCP domain, including an affected NFp 414. The NWDAF may include information that indicates the affected SCP domain (in thisexample SCP domain b), an identifier describing the type of the abnormal behavior (e.g., overload, erroneous behavior), expected intensity, expected abnormality time window, affected services, or the like.

[0093] The SCP 318 at step 703 decides, based on the information received in step 702 (e.g., abnormality type, intensity and time window), that the SCP domain should no longer be targeted by HTTP request. The SCP thus updates its SCP profile at the NRF 314 to remove the corresponding SCP domain ID from the list of SCP domains reachable through the SCP.

[0094] The SCP 318 at step 704 receives an HTTP request from an NFc 412 that targets the affected NFp 414 within the affected SCP domain identified in step 702. The request may be received via or another intermediate node (e.g., an HTTP proxy, another SCP or a SEPP).

[0095] The SCP 318 at step 705 rejects the HTTP request by sending an error response towards the NFc 412 (possibly via the intermediate nodes in step 704). The error response includes information that indicates the SCP domain of the target (affected) NFp 414 is displaying or is expected to display abnormal behavior and may include any of the related parameters described in step 702. In some examples, this information is conveyed in an extended 3gpp-Sbi-Lci HTTP header (the extensions may for example include information about the SCP domain, and a time window when the abnormal behavior is expected).

[0096] The NFc 412 at step 706 takes one or more actions to mitigate the abnormal behavior. The NFc may for example route the HTTP requests to the target NFp 414 via a different SCP domain. In other examples, the NFc may identify application sessions (e.g., PDU sessions) involving that signaling-storm-causing NF for predicted future signaling storms, e.g., application sessions expected to last until the expected time of the signaling storm), and possibly select application sessions with lower priority among them. In some of these other examples, the NFc takes action(s) to mitigate the signaling storm such as terminating related application sessions and possibly re-establishing the application session via another NF (e.g., before the expected time of the signaling storm), reducing the amount of requests sent within the application session, rejecting incoming requests within the application session with an error code and / or back-off timer preventing that they are repeated.

[0097] Notably, communication between an NFc 412 and NFp 414 may involve multiple SCP domains. When an SCP 318 updates its SCP profile at step 703, other SCPs may be updated about the changes of the SCP domain routing information and update their routingdecisions accordingly. This may result in the SCPs no longer sending their requests through an SCP domain that experiences or is foreseen to experience abnormal behaviors / signaling storms / signaling latencies. In some examples, the SCP profile of the SCP at the NRF 314 may include information that indicates period(s) of time during which an SCP domain is reachable or is not reachable through the SCP. In some of these examples, the SCP domain routing information that is sent by the NRF to other SCPs may also include information that indicates the same, such as to let the other SCPs know that during certain periods of time, an SCP domain is reachable or not reachable via a particular SCP.

[0098] FIG. 8 illustrates a signaling chart 800 of a delegated service discovery procedure, according to some example implementations. As shown, the NFc 412 at step 801 intends to communicate with an NFp 414. The NFc sends a service request to an SCP 318. The request may include discovery and selection parameters necessary to discover and select a NFp instance. The discovery and selection parameters may be included in the request by the NFc in a way that the SCP does not need to parse the request body.

[0099] The SCP 318 may at step 802 perform discovery upon the request either by interacting with an NRF 314 using Nnrf_NFDiscovery service NRF or may use information collected during the previous interactions with an NRF (by the Nnrf_NFDiscovery service or Nnrf_NFManagement_NFStatusNotify service operation). The SCP together with the NRF authorizes the request.

[0100] In accordance with some example implementations of the present disclosure, the SCP 318 may subscribe at the NWDAF 310 for analytics related to abnormal network behavior / signaling storm, or NF load, and then obtain related information from the NWD AF. This subscription and related notifications may already have occurred before step 801, and the SCP may cache such information. The SCP selects the target NFp 414 and may take the analytics information obtained from the NWDAF into consideration for that selection. In this regard, the SCP may select target NFps displaying no abnormal behavior or reject request targeting NFps displaying abnormal behavior with appropriate error information about the abnormal behavior. The SCP may therefore enable NFcs 412 to take mitigation actions. The SCP may also update its SCP profile at the NRF 314 to indicate that certain NF sets or SCP domains are no longer reachable through the SCP.

[0101] As shown at step 803, if the NFc 412 is authorized to communicate with the NFp 414, the SCP 318 forwards the request to the selected NFp. The SCP may include information related to observed or expected abnormal network behavior of the NFc to enable the NFp to take mitigation actions.

[0102] The NFp 414 at step 804 sends a response to the SCP 318. If the request in step 803 creates a resource in the NFp, the NFp responds with resource information identifying the created resource.

[0103] The SCP 318 at step 805 routes the response to the NFc 412. The SCP may include information related to observed or expected abnormal network behavior of the NFp 414 to enable the NFc to take mitigation action(s).

[0104] If the NFc 412 receives a resource address, it uses it for subsequent requests regarding the concerned resource. Otherwise, the procedure ends here.

[0105] On a subsequent operation on the created resource, the NFc 412 at step 806 addresses the resource via the resource address returned by the NFp 414 at step 804. The SCP 318 at step 807 resolves the NFp address and selects a target NFp instance. The SCP then at step 808 routes the request to the selected NFp instance. The NFp at step 809 sends a response to the SCP 318. The NFp may respond with an updated resource information different to the one received in the previous response. And the SCP at step 810 sends a response to the NFc. If the resource information was updated, the NFc uses the received resource information for subsequent operations (requests) on the resource.

[0106] FIGS. 9A - 9C are flowcharts illustrating various steps in a method 900 performed by a service communication proxy (SCP), according to various example implementations. The method includes subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior, as shown at block 902 of FIG. 9A. The method includes receiving a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF), as shown at block 904. The method includes receiving at block 906 a service request from a NF service consumer for a NF service producer. The method includes at least one of the following. The method includes sending information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at leastone of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior, as shown at block 908. Aditionally or alternatively, the method includes updating a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable through the SCP, as shown at block 910.

[0107] In some examples, the notification from the NWDAF is about at least one of: an overload; an erroneous behavior; an expected intensity; an expected abnormality time window; one or more affected application services; or at least one of the one or more affected NFs, one or more types of the one or more affected NFs, or one or more SCPs.

[0108] In some examples, subscribing for the analytics includes subscribing for analytics related to abnormal signaling behavior of one or more types of NF that include a type of the affected NF. In some of these examples, the notification is about the observed or expected abnormal signaling behavior affecting the one or more affected network functions of any of the one or more types of the NF.

[0109] In some examples, the information about the observed or expected abnormal signaling behavior is sent to at least one of the NF service consumer or the NF service producer.

[0110] In some examples, the information about the observed or expected abnormal signaling behavior is sent to at least the NF service producer. In some of these examples, sending the information at block 908 includes adding the information to the service request from the NF service consumer, and forwarding the service request including the information to the NF service producer, as shown at blocks 912 and 914 of FIG. 9B.

[0111] In some examples, the method 900 further includes receiving a service response from the NF service producer in response to the service request, as shown at block 916 of FIG. 9C. In some of these examples, the information about the observed or expected abnormal signaling behavior is sent to at least the NF service consumer, and sending the information at block 908 includes adding the information to the service response from the NF service producer, and forwarding the service response including the information to the NF service consumer, as shown at blocks 918 and 920.

[0112] In some examples, the information about the observed or expected abnormal signaling behavior is sent to the NF service consumer, and the information is sent by a service error response to the service request.

[0113] In some examples, subscribing for the analytics includes subscribing for analytics related to abnormal signaling behavior of one or more sets of NFs that include at least one affected set of NFs to which the one or more affected NFs belong. In some of these examples, the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected set of NFs.

[0114] In some examples, the method comprises updating the NF profile of the SCP at the NRF to indicate the at least one affected set of NFs is no longer reachable via the SCP.

[0115] In some examples, the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the at least one affected set of NFs.

[0116] In some examples, subscribing for the analytics includes subscribing for analytics related to abnormal signaling behavior of one or more SCP domains that include at least one affected SCP domain to which the one or more affected NFs belong. In some of these examples, the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected SCP domain.

[0117] In some examples, the method comprises updating the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

[0118] In some examples, the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the affected at least one SCP domain.

[0119] FIG. 10 is a flowchart illustrating various steps in a method 1000 performed by a network function (NF), according to various example implementations. The method includes receiving information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF), as shown at block 1002. The method includes identifying one or more application sessions involving the affected NF, as shown at block 1004. And the method includes taking one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions, as shown at block 1006.

[0120] In some examples, the NF is a NF service producer, and the information about the observed or expected abnormal signaling behavior is received in a service request forwarded by the SCP from a NF service consumer, and the service request includes the information added to the service request by the SCP.

[0121] In some examples, the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service response forwarded by the SCP from a NF service producer, and the service response includes the information added to the service response by the SCP.

[0122] In some examples, the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service error response to a service request from the NF service consumer.

[0123] In some examples, taking the one or more actions at block 1008 includes at least one of: taking one or more actions are taken to mitigate the observed or expected abnormal signaling behavior for the at least one lower priority application session; reducing an amount of requests sent within the one or more application sessions; rejecting incoming requests within the one or more application sessions with at least one of an error code or a back-off timer to prevent the incoming requests from repeating; terminating the one or more application sessions; or reestablishing or moving the one or more application sessions via another NF different from the affected NF.

[0124] According to example implementations of the present disclosure, a telecommunications system 100 or PLMN 102, and its components such as a UE 110, CN 106, RAN 108, 5GC 202, NG-RAN 204, gNB 206, AMF 302, SMF 304, UPF 306, NEF 308, NWDAF 310, AF 312, NRF 314, UDM 316, SCP 318, NFc 412, and / or NFp 414 may be implemented by various means. Means for implementing the system and its components may include hardware, firmware, software, or combinations thereof. In some examples, one or more apparatuses may be configured to function as or otherwise implement the system and its components shown and described herein. In examples involving more than one apparatus, the respective apparatuses may be connected to or otherwise in communication with one another in a number of different manners, such as directly or indirectly via a wired or wireless network or the like.

[0125] According to some example implementations, at least some of the method 900 described with respect to FIGS. 9A-9C may be carried out by an apparatus comprising means for performing functions corresponding steps of the method. Similarly, at least some of the method 1000 described with respect to FIG. 10 may be carried out by an apparatus comprising means for performing functions corresponding steps of the method. Examples of a suitable apparatus may include an NF (e g., AMF, SMF, UPF, NEF, NWDAF, AF, NRF, UDM, SCP, NFc, NFp), or any suitable apparatus, such as a server, host or node.

[0126] FIG. 11 illustrates an apparatus 1100 in which means for performing various functions includes hardware, alone or under direction of one or more computer programs from a computer-readable storage medium or other memory, such as computer memory, according to some example implementations of the present disclosure. The apparatus may include one or more of each of a number of components such as, for example, processing circuitry 1102 connected to computer-readable storage medium or other memory 1104.

[0127] The processing circuitry 1102 may be composed of one or more processors alone or in combination with one or more computer-readable storage media. The processing circuitry is generally any piece of computer hardware that is capable of processing information such as, for example, data, computer programs and / or other suitable electronic information. The processing circuitry is composed of a collection of electronic circuits some of which may be packaged as an integrated circuit or multiple interconnected integrated circuits (an integrated circuit at times more commonly referred to as a “chip”). The processing circuitry may be configured to execute computer programs, which may be stored onboard the processing circuitry or otherwise stored in the memory 1104 (of the same or another apparatus).

[0128] The processing circuitry 1102 may be a number of processors, a multi-core processor or some other type of processor, depending on the particular implementation. Further, the processing circuitry may be implemented using a number of heterogeneous processor systems in which a main processor is present with one or more secondary processors on a single chip. As another illustrative example, the processing circuitry may be a symmetric multi-processor system containing multiple processors of the same type. In yet another example, the processing circuitry may be embodied as or otherwise include one or more ASICs, FPGAs or the like. Thus, although the processing circuitry may be capable ofexecuting a computer program to perform one or more functions, the processing circuitry of various examples may be capable of performing one or more functions without the aid of a computer program. In either instance, the processing circuitry may be appropriately programmed to perform functions or operations according to example implementations of the present disclosure.

[0129] The memory 1104 is generally any piece of computer hardware that is capable of storing information such as, for example, data, computer programs, instructions 1106 (e.g., computer-readable program code) and / or other suitable information either on a temporary basis and / or a permanent basis. The memory may include volatile and / or non-volatile memory, and may be fixed or removable. Examples of suitable memory include recording media, random access memory (RAM), read-only memory (ROM), a hard drive, a flash memory, a thumb drive, a removable computer diskette, an optical disk or some combination thereof.

[0130] The memory 1104 is a non-transitory device capable of storing information. One example of a suitable memory is a computer-readable storage medium, which is distinguishable from a computer-readable transmission medium capable of carrying information from one location to another. Examples of suitable computer-readable transmission media comprise electronic carrier signals, telecommunications signals, software distribution packages, or some combination thereof. As used herein, the term “non-transitory” is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM versus ROM). A computer-readable medium as described herein generally refers to a computer-readable storage medium or computer-readable transmission medium. A computer-readable medium is any entity or device capable in which information, such as one or more computer programs or portions thereof, may be stored and carried.

[0131] In addition to the memory 1104 (e.g., computer-readable storage medium), the processing circuitry 1102 may also be connected to one or more interfaces for displaying, transmitting and / or receiving information. The interfaces may include a communications interface 1108 and / or one or more user interfaces (e.g., display, user input interface). The communications interface may be configured to transmit and / or receive information, such as to and / or from other apparatus(es), network(s) or the like. The communications interface may be configured to transmit and / or receive information by physical (wired) and / or wirelesscommunications links. Examples of suitable communication interfaces include a network interface controller (NIC), wireless NIC (WNIC) or the like.

[0132] Execution of the instructions 1106 by the processing circuitry 1102, or storage of the instructions in the memory 1104, supports combinations of operations for implementing example implementations of the present disclosure. In this manner, an apparatus 1100 may comprise at least one processing circuitry and at least one memory coupled to the at least one processing circuitry, where the at least one processing circuitry is configured to execute instructions stored in the at least one memory. It will also be understood that one or more functions, and combinations of functions, may be implemented by special purpose hardwarebased computer systems and / or processing circuitry which perform the specified functions, or combinations of special purpose hardware and program code instructions.

[0133] Some example implementations of the present disclosure may also be carried out in the form of a computer process defined by one or more computer programs or portions thereof. Example implementations of the present disclosure may be carried out by executing at least one portion of a computer program comprising instructions. The computer program may be in source code form, object code form, or in some intermediate form. The computer program may be stored in a computer-readable medium that is readable by a computer, processing circuitry or other suitable apparatus. As indicated above, for example, the computer program may be stored in a memory, such as a computer-readable storage medium. Additionally or alternatively, for example, the computer program may be stored in a computer-readable transmission medium. The coding of software for carrying out example implementations of the present disclosure is well within the scope of a person of ordinary skill in the art.

[0134] As will be appreciated, any suitable instructions may be loaded onto a computer, a processing circuitry or other programmable apparatus from a memory or a computer-readable medium (e.g., computer-readable storage medium, computer-readable transmission medium) to produce a particular machine, such that the particular machine becomes a means for implementing the functions specified herein. The instructions may also be stored in a computer-readable medium that can direct a computer, a processing circuitry or other programmable apparatus to function in a particular manner to thereby generate a particular machine or particular article of manufacture. In some examples, the instructions stored in thecomputer-readable medium may produce an article of manufacture, where the article of manufacture becomes a means for implementing functions described herein. The instructions may be retrieved from a computer-readable medium and loaded into a computer, processing circuitry or other programmable apparatus to configure the computer, processing circuitry or other programmable apparatus to execute operations to be performed on or by the computer, processing circuitry or other programmable apparatus.

[0135] Retrieval, loading and execution of instructions comprising program code instructions may be performed sequentially such that one instruction is retrieved, loaded and executed at a time. In some example implementations, retrieval, loading and / or execution may be performed in parallel such that multiple instructions are retrieved, loaded, and / or executed together. Execution of the program code instructions may produce a computer-implemented process such that the instructions executed by the computer, processing circuitry or other programmable apparatus provide operations for implementing functions described herein.

[0136] As explained above and reiterated below, the present disclosure includes, without limitation, the following example implementations.

[0137] Clause 1. An apparatus to implement a service communication proxy (SCP), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: subscribe at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receive a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); receive a service request from a NF service consumer for a NF service producer; and at least one of: send information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or update a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0138] Clause 2. The apparatus of clause 1 , wherein the information about the observed or expected abnormal signaling behavior comprises at least one of: an overload indication; an erroneous behavior indication; an expected intensity; an expected abnormality time window; one or more affected NF services; or at least one of the one or more affected NFs, one or more types of the one or more affected NFs, or one or more SCPs, or one or more SCP domains.

[0139] Clause 3. The apparatus of clause 1 or clause 2, wherein the apparatus caused to subscribe for the analytics includes the apparatus caused to subscribe for analytics related to abnormal signaling behavior of one or more types of NF that include a type of the affected NF, and the notification is about the observed or expected abnormal signaling behavior affecting the one or more affected network functions of any of the one or more types of the NF.

[0140] Clause 4. The apparatus of any of clauses 1 to 3, wherein the information about the observed or expected abnormal signaling behavior is sent to at least one of the NF service consumer or the NF service producer.

[0141] Clause 5. The apparatus of any of clauses 1 to 4, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service producer, and the apparatus caused to send the information includes the apparatus caused to: add the information to the service request from the NF service consumer; and forward the service request including the information to the NF service producer.

[0142] Clause 6. The apparatus of any of clauses 1 to 5, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further receive a service response from the NF service producer in response to the service request, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service consumer, and the apparatus caused to send the information includes the apparatus caused to: add the information to the service response from the NF service producer; and forward the service response including the information to the NF service consumer.

[0143] Clause 7. The apparatus of any of clauses 1 to 6, wherein the information about the observed or expected abnormal signaling behavior is sent to the NF service consumer, and the information is sent by a service error response to the service request.

[0144] Clause 8. The apparatus of any of clauses 1 to 7, wherein the apparatus caused to subscribe for the analytics includes the apparatus caused to subscribe for analytics related toabnormal signaling behavior of one or more sets of NFs that include at least one affected set of NFs to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected set of NFs.

[0145] Clause 9. The apparatus of clause 8, wherein the apparatus is caused to update the NF profile of the SCP at the NRF to indicate the at least one affected set of NFs is no longer reachable via the SCP.

[0146] Clause 10. The apparatus of clause 8 or clause 9, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the at least one affected set of NFs.

[0147] Clause 11. The apparatus of any of clauses 1 to 10, wherein the apparatus caused to subscribe for the analytics includes the apparatus caused to subscribe for analytics related to abnormal signaling behavior of one or more SCP domains that include at least one affected SCP domain to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected SCP domain.

[0148] Clause 12. The apparatus of clause 11, wherein the apparatus is caused to update the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

[0149] Clause 13. The apparatus of clause 11 or clause 12, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the affected at least one SCP domain.

[0150] Clause 14. An apparatus implemented by a service communication proxy (SCP), the apparatus comprising: means for subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; means for receiving a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); means for receiving a service request from a NF service consumer for a NF service producer; and at least one of: means for sending information about the observed or expected abnormal signaling behavior to at leastone of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or means for updating a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0151] Clause 15. The apparatus of clause 14, wherein the information about the observed or expected abnormal signaling behavior comprises at least one of: an overload indication; an erroneous behavior indication; an expected intensity; an expected abnormality time window; one or more affected NF services; or at least one of the one or more affected NFs, one or more types of the one or more affected NFs, or one or more SCPs, or one or more SCP domains.

[0152] Clause 16. The apparatus of clause 14 or clause 15, wherein the means for subscribing for the analytics includes means for subscribing for analytics related to abnormal signaling behavior of one or more types of NF that include a type of the affected NF, and the notification is about the observed or expected abnormal signaling behavior affecting the one or more affected network functions of any of the one or more types of the NF.

[0153] Clause 17. The apparatus of any of clauses 14 to 16, wherein the information about the observed or expected abnormal signaling behavior is sent to at least one of the NF service consumer or the NF service producer.

[0154] Clause 18. The apparatus of any of clauses 14 to 17, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service producer, and the means for sending the information: means for adding the information to the service request from the NF service consumer; and means for forwarding the service request including the information to the NF service producer.

[0155] Clause 19. The apparatus of any of clauses 14 to 18, wherein the apparatus further comprises means for receiving a service response from the NF service producer in response to the service request, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service consumer, and the means for sending the information includes: means for adding the information to the service response from the NFservice producer; and means for forwarding the service response including the information to the NF service consumer.

[0156] Clause 20. The apparatus of any of clauses 14 to 19, wherein the information about the observed or expected abnormal signaling behavior is sent to the NF service consumer, and the information is sent by a service error response to the service request.

[0157] Clause 21. The apparatus of any of clauses 14 to 20, wherein the means for subscribing for the analytics includes means for subscribing for analytics related to abnormal signaling behavior of one or more sets of NFs that include at least one affected set of NFs to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected set of NFs.

[0158] Clause 22. The apparatus of clause 21, wherein the apparatus comprises the means for updating the NF profile of the SCP at the NRF to indicate the at least one affected set of NFs is no longer reachable via the SCP.

[0159] Clause 23. The apparatus of clause 21 or clause 22, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the at least one affected set of NFs.

[0160] Clause 24. The apparatus of any of clauses 14 to 23, wherein the means for subscribing for the analytics includes means for subscribing for analytics related to abnormal signaling behavior of one or more SCP domains that include at least one affected SCP domain to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected SCP domain.

[0161] Clause 25. The apparatus of clause 24, wherein the apparatus comprises the means for updating the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

[0162] Clause 26. The apparatus of clause 24 or clause 25, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF servi ce consumer or the NF service producer comprises information that indicates the affected at least one SCP domain.

[0163] Clause 27. A method performed by a service communication proxy (SCP), the method comprising: subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receiving a notification from the NWDAF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); receiving a service request from a NF service consumer for a NF service producer; and at least one of: sending information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or updating a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0164] Clause 28. The method of clause 27, wherein the information about the observed or expected abnormal signaling behavior comprises at least one of: an overload indication; an erroneous behavior indication; an expected intensity; an expected abnormality time window; one or more affected NF services; or at least one of the one or more affected NFs, one or more types of the one or more affected NFs, or one or more SCPs, or one or more SCP domains.

[0165] Clause 29. The method of clause 27 or clause 28, wherein subscribing for the analytics includes subscribing for analytics related to abnormal signaling behavior of one or more types of NF that include a type of the affected NF, and the notification is about the observed or expected abnormal signaling behavior affecting the one or more affected network functions of any of the one or more types of the NF.

[0166] Clause 30. The method of any of clauses 27 to 29, wherein the information about the observed or expected abnormal signal ing behavior is sent to at least one of the NF service consumer or the NF service producer.

[0167] Clause 31. The method of any of clauses 27 to 30, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service producer, and sending the information includes: adding the information to the service request from the NF service consumer; and forwarding the service request including the information to the NF service producer.

[0168] Clause 32. The method of any of clauses 27 to 31, wherein the method further comprises receiving a service response from the NF service producer in response to the service request, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service consumer, and sending the information includes: adding the information to the service response from the NF service producer; and forwarding the service response including the information to the NF service consumer.

[0169] Clause 33. The method of any of clauses 27 to 32, wherein the information about the observed or expected abnormal signaling behavior is sent to the NF service consumer, and the information is sent by a service error response to the service request.

[0170] Clause 34. The method of any of clauses 27 to 33, wherein subscribing for the analytics includes subscribing for analytics related to abnormal signaling behavior of one or more sets of NFs that include at least one affected set of NFs to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected set of NFs.

[0171] Clause 35. The method of clause 34, wherein the method comprises updating the NF profile of the SCP at the NRF to indicate the at least one affected set of NFs is no longer reachable via the SCP.

[0172] Clause 36. The method of clause 34 or clause 35, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the at least one affected set of NFs.

[0173] Clause 37. The method of any of clauses 27 to 36, wherein subscribing for the analytics includes subscribing for analytics related to abnormal signaling behavior of one or more SCP domains that include at least one affected SCP domain to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected SCP domain.

[0174] Clause 38. The method of clause 37, wherein the method comprises updating the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

[0175] Clause 39. The method of clause 37 or clause 38, wherein the information about the observed or expected abnormal signal ing behavior sent to at least one of the NF serviceconsumer or the NF service producer comprises information that indicates the affected at least one SCP domain.

[0176] Clause 40. A computer-readable storage medium that is non-transitory and has instructions stored therein that, in response to execution by at least one processing circuitry, causes a service communication proxy (SCP) to at least: subscribe at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receive a notification from the NWD AF about an observed or expected abnormal signaling behavior associated with one or more affected network functions (NF); receive a service request from a NF service consumer for a NF service producer; and at least one of: send information about the observed or expected abnormal signaling behavior to at least one of the NF service consumer or the NF service producer, one of which is an affected NF of the one or more affected NFs, the information sent to enable the at least one of the NF service consumer or the NF service producer to perform one or more mitigation actions for the observed or expected abnormal signaling behavior; or update a NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable, or are expected to become no longer reachable during a certain time period, through the SCP.

[0177] Clause 41. The computer-readable storage medium of clause 40, wherein the information about the observed or expected abnormal signaling behavior comprises at least one of: an overload indication; an erroneous behavior indication; an expected intensity; an expected abnormality time window; one or more affected NF services; or at least one of the one or more affected NFs, one or more types of the one or more affected NFs, or one or more SCPs, or one or more SCP domains.

[0178] Clause 42. The computer-readable storage medium of clause 40 or clause 41, wherein the SCP caused to subscribe for the analytics includes the SCP caused to subscribe for analytics related to abnormal signaling behavior of one or more types of NF that include a type of the affected NF, and the notification is about the observed or expected abnormal signaling behavior affecting the one or more affected network functions of any of the one or more types of the NF.

[0179] Clause 43. The computer-readable storage medium of any of clauses 40 to 42, wherein the information about the observed or expected abnormal signaling behavior is sent to at least one of the NF service consumer or the NF service producer.

[0180] Clause 44. The computer-readable storage medium of any of clauses 40 to 43, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service producer, and the SCP caused to send the information includes the SCP caused to: add the information to the service request from the NF service consumer; and forward the service request including the information to the NF service producer.

[0181] Clause 45. The computer-readable storage medium of any of clauses 40 to 44, wherein the computer-readable storage medium has further instructions stored therein that, in response to execution by the at least one processing circuitry, causes the SCP to further receive a service response from the NF service producer in response to the service request, wherein the information about the observed or expected abnormal signaling behavior is sent to at least the NF service consumer, and the SCP caused to send the information includes the SCP caused to: add the information to the service response from the NF service producer; and forward the service response including the information to the NF service consumer.

[0182] Clause 46. The computer-readable storage medium of any of clauses 40 to 45, wherein the information about the observed or expected abnormal signaling behavior is sent to the NF service consumer, and the information is sent by a service error response to the service request.

[0183] Clause 47. The computer-readable storage medium of any of clauses 40 to 46, wherein the SCP caused to subscribe for the analytics includes the SCP caused to subscribe for analytics related to abnormal signaling behavior of one or more sets of NFs that include at least one affected set of NFs to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected set of NFs.

[0184] Clause 48. The computer-readable storage medium of clause 47, wherein the SCP is caused to update the NF profile of the SCP at the NRF to indicate the at least one affected set of NFs is no longer reachable via the SCP.

[0185] Clause 49. The computer-readable storage medium of clause 47 or clause 48, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the at least one affected set of NFs.

[0186] Clause 50. The computer-readable storage medium of any of clauses 40 to 49, wherein the SCP caused to subscribe for the analytics includes the SCP caused to subscribe for analytics related to abnormal signaling behavior of one or more SCP domains that include at least one affected SCP domain to which the one or more affected NFs belong, and wherein the notification is about the observed or expected abnormal signaling behavior associated with the at least one affected SCP domain.

[0187] Clause 51. The computer-readable storage medium of clause 50, wherein the SCP is caused to update the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

[0188] Clause 52. The computer-readable storage medium of clause 50 or clause 51, wherein the information about the observed or expected abnormal signaling behavior sent to at least one of the NF service consumer or the NF service producer comprises information that indicates the affected at least one SCP domain.

[0189] Clause 53. An apparatus comprising means for performing the method of any of clauses 27 to 39.

[0190] Clause 54. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 27 to 39.

[0191] Clause 55. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 27 to 39.

[0192] Clause 56. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 27 to 39.

[0193] Clause 57. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause a network function (NF) to at least: receive information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); identify one or more application sessions involving the affected NF; and take one or more actions tomitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0194] Clause 58. The apparatus of clause 57, wherein the NF is a NF service producer, and the information about the observed or expected abnormal signaling behavior is received in a service request forwarded by the SCP from a NF service consumer, and the service request includes the information added to the service request by the SCP.

[0195] Clause 59. The apparatus of clause 57 or clause 58, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service response forwarded by the SCP from a NF service producer, and the service response includes the information added to the service response by the SCP.

[0196] Clause 60. The apparatus of any of clauses 57 to 59, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service error response to a service request from the NF service consumer.

[0197] Clause 61. The apparatus of any of clauses 57 to 60, wherein the NF caused to take the one or more actions includes the NF caused to at least one of: take one or more actions are taken to mitigate the observed or expected abnormal signaling behavior for the at least one lower priority application session; reduce an amount of requests sent within the one or more application sessions; reject incoming requests within the one or more application sessions with at least one of an error code or a back-off timer to prevent the incoming requests from repeating; terminate the one or more application sessions; or reestablish or moving the one or more application sessions via another NF different from the affected NF.

[0198] Clause 62. An apparatus implemented by a network function (NF), the apparatus comprising: means for receiving information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); means for identifying one or more application sessions involving the affected NF; and means for taking one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0199] Clause 63. The apparatus of clause 62, wherein the NF is a NF service producer, and the information about the observed or expected abnormal signaling behavior is received ina service request forwarded by the SCP from a NF service consumer, and the service request includes the information added to the service request by the SCP.

[0200] Clause 64. The apparatus of clause 62 or clause 63, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service response forwarded by the SCP from a NF service producer, and the service response includes the information added to the service response by the SCP.

[0201] Clause 65. The apparatus of any of clauses 62 to 64, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service error response to a service request from the NF service consumer.

[0202] Clause 66. The apparatus of any of clauses 62 to 65, wherein the means for taking the one or more actions includes at least one of: means for taking one or more actions are taken to mitigate the observed or expected abnormal signaling behavior for the at least one lower priority application session; means for reducing an amount of requests sent within the one or more application sessions; means for rejecting incoming requests within the one or more application sessions with at least one of an error code or a back-off timer to prevent the incoming requests from repeating; means for terminating the one or more application sessions; or means for reestablishing or moving the one or more application sessions via another NF different from the affected NF.

[0203] Clause 67. A method performed by a network function (NF), the method comprising: receiving information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); identifying one or more application sessions involving the affected NF; and taking one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0204] Clause 68. The method of clause 67, wherein the NF is a NF service producer, and the information about the observed or expected abnormal signaling behavior is received in a service request forwarded by the SCP from a NF service consumer, and the service request includes the information added to the service request by the SCP.

[0205] Clause 69. The method of clause 67 or clause 68, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior isreceived in a service response forwarded by the SCP from a NF service producer, and the service response includes the information added to the service response by the SCP.

[0206] Clause 70. The method of any of clauses 67 to 69, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service error response to a service request from the NF service consumer.

[0207] Clause 71. The method of any of clauses 67 to 70, wherein taking the one or more actions includes at least one of: taking one or more actions are taken to mitigate the observed or expected abnormal signaling behavior for the at least one lower priority application session; reducing an amount of requests sent within the one or more application sessions; rejecting incoming requests within the one or more application sessions with at least one of an error code or a back-off timer to prevent the incoming requests from repeating; terminating the one or more application sessions; or reestablishing or moving the one or more application sessions via another NF different from the affected NF.

[0208] Clause 72. A computer-readable storage medium comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause a network function (NF) to at least: receive information from a service communication proxy (SCP) about an observed or expected abnormal signaling behavior associated with an affected network function (NF); identify one or more application sessions involving the affected NF; and take one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

[0209] Clause 73. The computer-readable storage medium of clause 72, wherein the NF is a NF service producer, and the information about the observed or expected abnormal signaling behavior is received in a service request forwarded by the SCP from a NF service consumer, and the service request includes the information added to the service request by the SCP.

[0210] Clause 74. The computer-readable storage medium of clause 72 or clause 73, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service response forwarded by the SCP from a NF service producer, and the service response includes the information added to the service response by the SCP.

[0211] Clause 75. The computer-readable storage medium of any of clauses 72 to 74, wherein the NF is a NF service consumer, and the information about the observed or expected abnormal signaling behavior is received in a service error response to a service request from the NF service consumer.

[0212] Clause 76. The computer-readable storage medium of any of clauses 72 to 75, wherein the NF caused to take the one or more actions includes the NF caused to at least one of: take one or more actions are taken to mitigate the observed or expected abnormal signaling behavior for the at least one lower priority application session; reduce an amount of requests sent within the one or more application sessions; reject incoming requests within the one or more application sessions with at least one of an error code or a back-off timer to prevent the incoming requests from repeating; terminate the one or more application sessions; or reestablish or moving the one or more application sessions via another NF different from the affected NF.

[0213] Clause 77. An apparatus comprising means for performing the method of any of clauses 67 to 71.

[0214] Clause 78. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 67 to 71

[0215] Clause 79. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 67 to 71.

[0216] Clause 80. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 67 to 71.

[0217] Many modifications and other implementations of the disclosure set forth herein will come to mind to one skilled in the art to which the disclosure pertains having the benefit of the teachings presented in the foregoing description and the associated figures. Therefore, it is to be understood that the disclosure is not to be limited to the specific implementations disclosed and that modifications and other implementations are intended to be included within the scope of the appended claims. Moreover, although the foregoing description and the associated figures describe example implementations in the context of certain examplecombinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative implementations without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as may be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

CLAIMS1. A method performed by a service communication proxy (SCP), the method comprising: subscribing at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receiving a notification from the NWDAF about the abnormal signaling behavior associated with one or more affected network functions (NFs); receiving a service request from an NF service consumer for an NF service producer; rejecting the service request with information about the abnormal signaling behavior, wherein the NF service producer is one of the one or more affected NFs; and updating an NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable through the SCP.

2. The method of claim 1 , wherein the information about the abnormal signaling behavior comprises an erroneous behavior indication.

3. The method of claim 1, wherein the information is about the abnormal signaling behavior of the NF service producer, and the information is sent by a service error response to the service request.

4. The method of claim 1, wherein the notification is about the abnormal signaling behavior associated with the one or more affected network functions in at least one affected SCP domain.

5. The method of claim 4, wherein the method comprises updating the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

466. The method of claim 4, wherein the information about the abnormal signaling behavior comprises information that indicates the affected at least one SCP domain.

7. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to: subscribe at a network data analytics function (NWDAF) for analytics related to abnormal signaling behavior; receive a notification from the NWDAF about the abnormal signaling behavior associated with one or more affected network functions (NFs); receive a service request from an NF service consumer for an NF service producer; reject the service request with information about the abnormal signaling behavior, wherein the NF service producer is one of the one or more affected NFs; and update an NF profile of the SCP at a network repository function (NRF) to indicate that the one or more affected NFs are no longer reachable through the SCP.

8. The apparatus of claim 7, wherein the information about the abnormal signaling behavior comprises an erroneous behavior indication.

9. The apparatus of claim 7, wherein the apparatus is caused to reject the service request by sending the information about the abnormal signaling behavior of the NF service producer, and the information is sent by a service error response to the service request.

10. The apparatus of claim 7, wherein the notification is about the abnormal signaling behavior associated with the one or more affected network functions in at least one affected SCP domain.

11. The apparatus of claim 10, wherein the apparatus is caused to update the NF profile of the SCP at the NRF to indicate the at least one affected SCP domain is no longer reachable via the SCP.

12. The method of claim 10, wherein the information about the abnormal signaling behavior comprises information that indicates the affected at least one SCP domain.

13. A method performed by a network function (NF), the method comprising: receiving information from a service communication proxy (SCP) about an abnormal signaling behavior associated with an affected network function (NF); identifying one or more application sessions involving the affected NF; and taking one or more actions to mitigate the observed or expected abnormal signaling behavior for the one or more application sessions.

14. The method of claim 13, wherein the NF is an NF service consumer, and the information about the abnormal signaling behavior is received in a service error response to a service request from the NF service consumer.48

Citation Information

Patent Citations

  • Migration to Indirect Communication Mode in a Service-Based Architecture

    US20230006888A1

  • METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR REDUCING THE LIKELIHOOD OF SUCCESSFUL DENIAL OF SERVICE (DoS) ATTACKS BY VALIDATING OVERLOAD CONTROL INFORMATION (OCI) SCOPE AGAINST NETWORK FUNCTION (NF) PROFILE INFORMATION OBTAINED USING TARGET RESOURCE IDENTIFICATION INFORMATION

    US20230072290A1