Shared resource content filters
By enabling NFps to discover and reference registered resource content filters with consumer information derivation rules, the system addresses configuration challenges and inefficient resource retrieval, achieving optimized and efficient resource access in telecommunications systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2025-10-29
- Publication Date
- 2026-05-15
AI Technical Summary
Existing solutions for filtering resources in telecommunications systems face issues such as cumbersome and error-prone configuration of resource content filters at individual network function producers (NFps), reliance on consumer information not explicitly provided in access tokens, and complex NFc requests leading to inefficient resource retrieval.
Implementing a system where network function service producers (NFps) discover and reference resource content filters registered by other NFps, with consumer information derivation rules at the network repository function (NRF) to determine applicable filters, and NFcs requesting filter IDs rather than detailed specifications, reducing misalignment and optimizing resource retrieval.
This approach reduces the need for individual NFp configuration, minimizes misalignment, and enhances efficient resource retrieval by allowing NFcs to request specific filters, thereby optimizing processing and network resources.
Smart Images

Figure IMGF000012_0001_TABLE 
Figure IMGF000015_0001_TABLE 
Figure 00000033_0000
Abstract
Description
SHARED RESOURCE CONTENT FILTERSTECHNOLOGICAL FIELD
[0001] The present disclosure relates generally to telecommunications and, in particular, to filtering the content of resources requested from a network function in a telecommunications system.BACKGROUND
[0002] A telecommunications system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications path. A telecommunications system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.
[0003] In a wireless telecommunications system, at least a part of a communication session between at least two stations occurs over a wireless link. Examples of wireless telecommunications systems comprise public land mobile networks (PLMN), satellite based communication systems and different wireless local networks, for example wireless local area networks (WLAN). Some wireless systems can be divided into cells, and are therefore often referred to as cellular systems.
[0004] A user can access the telecommunications system by means of an appropriate communication device or terminal. A communication device of a user may be referred to as user equipment (UE) or user device. A communication device is provided with an appropriate signal receiving and transmitting apparatus for enabling communications, for example enabling access to a communication network or communications directly with other users. The communication device may access a carrier provided by a station, for example a base station of a cell, and transmit and / or receive communications on the carrier.
[0005] The telecommunications system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the communication system are permitted to do and how operations should be achieved. Communication protocols and / or parameters which shall be used for connection of the various entities are also typically defined. One example of a telecommunications system is the Universal Mobile Telecommunications System (UMTS). Other examples of telecommunications systems are Long-Term Evolution (LTE), LTE Advanced and the so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP).BRIEF SUMMARY
[0006] Example implementations of the present disclosure are directed to telecommunications and, in particular, to filtering the content of resources requested from a network function in a telecommunications system. The present disclosure includes, without limitation, the following example implementations.
[0007] Some example implementations provide an apparatus to implement a network function service producer (NFp), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: at least one of register with a network repository function (NRF) one or more resource content filters associated with the NFp, or discover another one or more resource content filters registered with the NRF by at least one other NFp; and register a network function profile for the NFp with the NRF, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters.
[0008] Some example implementations provide a method performed by a network function service producer (NFp), the method comprising: at least one of registering with a network repository function (NRF) one or more resource content filters associated with the NFp, or discovering another one or more resource content filters registered with the NRF by at least one other NFp; and registering a network function profile for the NFp with the NRF, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters.
[0009] Some example implementations provide an apparatus to implement a network repository function (NRF), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: receive an access token request from a network function service consumer (NFc) for an authorization to access a resource or service of a network function service producer (NFp); apply one or more consumer information derivation rules to determine consumer information used by at least one applicable resource content filter associated with the NFp; generate an access token that contains at least one resource content filter identifier (ID) of the at least one applicable resource content filter, and the consumer information; and send an access token response including the access token to the NFc.
[0010] Some example implementations provide a method performed by a network repository function (NRF), the method comprising: receiving an access token request from a network function service consumer (NFc) for an authorization to access a resource or service of a network function service producer (NFp); applying one or more consumer information derivation rules to determine consumer information used by at least one applicable resource content filter associated with the NFp; generating an access token that contains at least one resource content filter identifier (ID) of the at least one applicable resourcecontent filter, and the consumer information; and sending an access token response including the access token to the NFc.
[0011] Some example implementations provide an apparatus to implement a network function service consumer (NFc), the apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least: discover from a network repository function (NRF) one or more usable resource content filters associated with a network function service producer (NFp); send a request for a resource of the NFp, the request including at least one resource content filter identifier (ID) of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; and receive a response to the request from the NFp that includes a representation of the resource constructed by the NFp during which the at least one resource content filter is applied.
[0012] Some example implementations provide a method performed by a network function service consumer (NFc), the method comprising: discovering from a network repository function (NRF) one or more usable resource content filters associated with a network function service producer (NFp); sending a request for a resource of the NFp, the request including at least one resource content filter identifier (ID) of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; and receiving a response to the request from the NFp that includes a representation of the resource constructed by the NFp during which the at least one resource content filter is applied.
[0013] These and other features, aspects, and advantages of the present disclosure will be apparent from a reading of the following detailed description together with the accompanying figures, which are briefly described below. The present disclosure includes any combination of two, three, four or more features or elements set forth in this disclosure, regardless of whether such features or elements are expressly combined or otherwise recited in a specific example implementation described herein. The present disclosure is intended to be read holistically such that any separable features or elements of the disclosure, in any of its aspects and example implementations, should be viewed as combinable unless the context of the disclosure clearly dictates otherwise.
[0014] It will therefore be appreciated that this Brief Summary is provided merely for purposes of summarizing some example implementations so as to provide a basic understanding of some aspects of the disclosure. Accordingly, it will be appreciated that the above described example implementations are merely examples and should not be construed to narrow the scope or spirit of the disclosure in any way. Other example implementations, aspects and advantages will become apparent from the following detailed description taken in conjunction with the accompanying figures which illustrate, by way of example, the principles of some described example implementations.BRIEF DESCRIPTION OF THE FIGURE(S)
[0015] Having thus described example implementations of the disclosure in general terms, reference will now be made to the accompanying figures, which are not necessarily drawn to scale, and wherein:
[0016] FIG. 1 illustrates a telecommunications system that includes one or more public land mobile networks (PLMNs) coupled to one or more external data networks, according to some example implementations of the present disclosure;
[0017] FIG. 2 illustrates a telecommunications system that includes two PLMNs, in accordance with some example implementations;
[0018] FIG. 3 is a signaling chart of one or more procedures involving use of configurable resource content filters;
[0019] FIG. 4 is a signaling chart of one or more procedures involving use of configurable resource content filters, according to various example implementations;
[0001] FIGS. 5Aand 5B are flowcharts illustrating various steps in a method performed by a network function service producer (NFp), according to some example implementations;
[0002] FIGS. 6Aand 6B are flowcharts illustrating various steps in a method performed by a network repository function (NRF), according to some example implementations;
[0003] FIG. 7 is a flowchart illustrating various steps in a method performed by a network function service consumer (NFc), according to various example implementations;
[0004] FIG. 8 illustrates an apparatus according to some example implementations.DETAILED DESCRIPTION
[0005] Some implementations of the present disclosure will now be described more fully hereinafter with reference to the accompanying figures, in which some, but not all implementations of the disclosure are shown. Indeed, various implementations of the disclosure may be embodied in many different forms and should not be construed as limited to the implementations set forth herein; rather, these example implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Like reference numerals refer to like elements throughout.
[0006] Unless specified otherwise or clear from context, references to first, second or the like should not be construed to imply a particular order. A feature described as being above another feature (unless specified otherwise or clear from context) may instead be below, and vice versa; and similarly, features described as being to the left of another feature else may instead be to the right, and vice versa. Also, while reference may be made herein to quantitative measures, values, geometric relationships or the like, unless otherwisestated, any one or more if not all of these may be absolute or approximate to account for acceptable variations that may occur, such as those due to engineering tolerances or the like.
[0007] As used herein, unless specified otherwise or clear from context, the "or” of a set of operands is the "inclusive or” and thereby true if and only if one or more of the operands is true, as opposed to the "exclusive or” which is false when all of the operands are true. Thus, for example, "[A] or [B]” is true if [A] is true, or if [B] is true, or if both [A] and [B] are true. Further, the articles "a” and "an” mean "one or more,” unless specified otherwise or clear from context to be directed to a singular form. Furthermore, it should be understood that unless otherwise specified, the terms "data,” "content,” "digital content,” "information,” and similar terms may be at times used interchangeably. The term "network” may refer to a group of interconnected computers including clients and servers; and within a network, these computers may be interconnected directly or indirectly by various means including via one or more switches, routers, gateways, access points or the like.
[0008] The present disclosure discusses systems and architectures that, while specific terms may be used, are broadly applicable across various technologies. For instance, while the present disclosure may reference technologies from 3GPP such as Global System for Mobile Communications (GSM), UMTS, LTE, LTE Advanced, 5G NR, 5G Advanced, and 6G, the present disclosure is equally relevant to non-3GPP technologies like IEEE 802, Bluetooth, and Bluetooth Low Energy. Example implementations of the present disclosure described herein also mention public land mobile networks (PLMNs) and mobile network operators (MNOs), but example implementations are similarly applicable to standalone non-public networks (SNPNs) and the private entities operating these networks. Furthermore, although some examples and figures focus on radio access networks (RANs) and 3GPP access, example implementations are applicable to any type of network access. This includes not only 5G or 6G 3GPP access but also non-3GPP access, such as wireline access, untrusted non-3GPP access, and trusted non-3GPP access using wireless access gateway function (W-AGF), non-3GPP interworking function (N3IWF), or trusted non-3GPP gateway function (TNGF) to connect to a 5G or 6G core network.
[0009] Further, as used in this application, the term "circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry); (b) combinations of hardware circuits and software, such as (as applicable): (I) a combination of analog and / or digital hardware circuit(s) with software / firmware and (II) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); or (c) hardware circuit(s) and / or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0010] The above definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0011] FIG. 1 illustrates a telecommunications system 100 according to various example implementations of the present disclosure. The telecommunications system generally includes one or more telecommunications networks. As shown, for example, the system includes one or morePLMNs 102 coupled to one or more other external data networks 104 - notably including a wide area network (WAN) such as the Internet. As will be appreciated, a PLMN may be deployed in a number of different manners. Some deployments of 4G LTE and 5G NR in particular are considered standalone (SA) deployments. Other deployments combine 4G LTE and 5G technologies, and are referred to as non-standalone (NSA) deployments.
[0012] Each of the PLMNs 102 includes a core network (CN) 106 backbone, such as the Evolved Packet Core (EPC) of 4G LTE, and the 5G core network (5GC) (at times referred to as the NGC) of 5G NR; and each of the core networks and the Internet are coupled to one or more RANs 108, air interfaces or the like that implement one or more radio access technologies (RATs). Examples of these RANs include the evolved UMTS terrestrial radio access network (E-UTRAN) of 4G LTE, and the next generation (NG) radio access network (NG-RAN) of 5G NR. As used herein, a "network device” refers to any suitable device at a network side of a telecommunications network. Examples of suitable network devices are described in greater detail below.
[0013] Examples of radio access technologies include 3GPP radio access technologies such as GSM, UMTS, LTE, LTE Advanced, 5G NR, 5G Advanced, and 6G. Other examples of radio access technologies include IEEE 802 technologies such as IEEE 802.11 (Wi-Fi), IEEE 802.15 (including 802.15.1 (WPAN / Bluetooth), 802.15.4 (Zigbee) and 802.15.6 (WBAN)), Bluetooth, Bluetooth Low Energy (BLE), ultra wideband (UWB), and the like. Generally, a radio access technology may refer to any 2G, 3G, 4G, 5G, 6G or higher generation mobile communication technology and their different versions, as well as to any other wireless radio access technology that may be arranged to interwork with such a mobile communication technology to provide access to the CN 106 of a MNO.
[0014] The telecommunications system 100 also includes one or more radio units that may be varyingly known as user equipment (UE) 110, terminal device, terminal equipment, mobile station or the like. The UE is generally a device configured to communicate with a network device or a further UE in a telecommunications network. The UE may be a portable computer (e.g., laptop, notebook, tabletcomputer), mobile phone (e.g., cell phone, smartphone), wearable computer (e.g., smartwatch), or the like. In other examples, the UE may be an Internet of things (IoT) device, an industrial IoT (IIoT device), a vehicle equipped with a vehicle-to-everything (V2X) communication technology, or the like. In some examples, as referenced by 3GPP, the UE may be a narrowband IoT (NB-IoT) device, an enhanced machine-type communication (eMTC) device, a reduced capability (RedCap) device, an ambient loT device, or the like.
[0015] In operation, these UEs 110 may connect to one or more of the RANs 108 according to their particular radio access technologies to thereby access a particular CN 106 of a PLMN 102, or to access one or more of the external data networks 104 (e.g., the Internet). The external data network may provide Internet access, operator services, 3rd party services, etc. For example, the International Telecommunication Union (ITU) has classified 5G mobile network services into three categories: enhanced mobile broadband (eMBB), ultra-reliable and low-latency communications (URLLC), and massive machine type communications (mMTC) or massive internet of things (MIoT).
[0016] In various examples, a RAN 108 may be configured as one or more macrocells, microcells, picocells, femtocells or the like. The RAN may generally include one or more radio access nodes that interact with UEs 110. In various examples, a radio access node may be referred to as a base station (BS), access point (AP), base transceiver station (BTS), Node B (NB), evolved NB (eNB), macro BS, NB (MNB) or eNB (MeNB), home BS, NB (HNB) or eNB (HeNB), next generation NB (gNB), enhanced gNB (en-gNB), next generation eNB (ng-eNB), or the like. The term 'gNB' in 5G NR may correspond to the eNB in 4G LTE. Also, a NG-RAN node may refer to a gNB or a ng-eNB.
[0017] The RAN 108 may include some type of network controlling / governing entity responsible for control of the radio access nodes. The network controlling / governing entity and radio access node may be separate or integrated into a single apparatus. The network controlling / governing entity may include processing circuity configured to carry out various management functions, etc. The processing circuity may be associated with a memory, computer-readable storage medium or database for maintaining information required in the management functions.
[0018] FIG. 2 illustrates a telecommunications system 200 that includes two PLMNs 102A, 102B, in accordance with some example implementations of the present disclosure. As shown, each of the PLMNs is equipped with a number of network functions (NFs), two of which are shown as respectively a NF service consumer (NFc) 202 and a NF service producer (NFp) 204. A network function may refer to an operational and / or a physical entity. A network function may be a specific network node or element, or a specific function or set of functions carried out by one or more entities, such as virtualized network elements (VNFs). One physical node may be configured to perform plural NFs. A network function can be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g., on a cloudinfrastructure. Examples of such network functions include a resource control or management function, session management or control function, interworking, data management or storage function, authentication function or a combination of one or more of these functions.
[0019] In the context of a 3GPP 5G service based architecture (SBA), core network NFs may communicate with each other using service-based interfaces (SBIs). These core network NFs may include, for example, an access and mobility management function (AMF), a session management function (SMF), a network slice selection function (NSSF), a network exposure function (NEF), a network repository function (NRF) 206, 208, a unified data management (UDM), an authentication server function (AUSF), a policy control function (PCF), an application function (AF), or the like. The PLMNs may each further include a security edge protection proxy (SEPP) 210, 212 configured to operate as a security edge node or gateway.
[0020] In some examples, the NFs may communicate with each other using representational state transfer application programming interfaces (APIs), which may be known as Restful APIs. Further examples of NFs include NFs related to gaming, streaming or industrial process control. The telecommunications system may also include nodes from 3G or 4G node systems, such as home subscriber server (HSS), and a suitable interworking function for protocol translations between, e.g., diameter and REST API JSON (JavaScript Object Notation). While described herein primarily using terminology of 5G systems, example implementations of the present disclosure may be applicable also to other communication networks using proxies as described herein, such as 4G networks and non-3GPP networks.
[0021] Although the telecommunications system 200 is illustrated with two PLMNs 102A, 102B, in general at least some example implementations may be practiced in a single PLMN, which need not necessarily have SEPPs. In an inter-PLMN case, the SEPP 210, 212 is a network node at the boundary of a MNO's network that may be configured to receive a message, such as a Hypertext Transfer Protocol (HTTP) request message or HTTP response message from an NF, to apply protection for sending and to forward the reformatted message through a chain of intermediate nodes, such as IP exchanges (IPXs) 214, 216, towards a receiving SEPP. The receiving SEPP receives a message sent by the sending SEPP and forwards the message towards an NF within its MNO's network (e.g., the AUSF).
[0022] In the example of FIG. 2, an NF service may be provided to a NFc 202 by a NFp 204. As noted, the NFc and NFp may reside in different PLMNs 102A, 102B or the NFc and NFp may reside in the same PLMN.
[0023] In some examples, a service communication proxy (SCP) 218, 220 may be deployed for indirect communication between NFs. An SCP is an intermediate network entity to assist in indirect communication between an NFc 202 and an NFp 204, including routing messages, such as control plane messages between the NFs. The SCP may discover and select NFp on behalf of NFc. The SCP may request an access token (at times referred to as an authorization token) from the NRF 206, 208 or an authorization server on behalf of NFc to access the service of NFp.
[0024] Direct communication may be applied between NFc 202 and NFp 204 for an NF service, or NF service communication may be performed indirectly via SCP(s) 218, 220. In direct communication, the NFc performs discovery of the target NFp by local configuration or via local NRF 206 (this NRF may be referred to as a NRFc). In indirect communication, the NFc may delegate the discovery of the target NFp to the SCP 218. In the latter case, the SCP may use the parameters provided by NFc to perform discovery and / or selection of the target NFp, such as with reference to one or more NRFs 206, 208.
[0025] NF discovery and NF service discovery enable entities, such as NFc 202 or SCP 218, to discover a set of NF instance(s) and NF service instance(s) for a specific NF service or an NFp type. The NFc and / or the SCP may be core network entities. The NRF may include a function that is used to support the functionality of NF and NF service registration, discovery, authorization and status notification. Additionally or alternatively, the NRF 206, 208 may be configured to act as an authorization server. The NRF may maintain an NF profile of available NFp entities and their supported services. The NRF may notify about newly registered, updated, or deregistered NFp entities along with its NF services to a subscribed NFc or SCP. An NRF may thus advise NFc entities or SCP concerning where, that is, from which NFp entities, they may obtain services they need. In general, an NRF is a terminological example of a network support node, and an SCP is a terminological example of a proxy entity. An NRF may be separate from or co-located with an SCP, or even hosted by a service provider.
[0026] In order for the NFc 202 or SCP 218 to obtain information about the NFp 204 and / or NF service(s) registered or configured in a PLMN I slice, the NFc or SCP may initiate, based on local configuration, a discovery procedure with an NRF, such as NRF 206. The discovery procedure may be initiated by providing the type of the NFp 204 and optionally a list of the specific service(s) it is attempting to discover.The NFc or SCP may additionally or alternatively provide other service parameters, such as information relating to network slicing.
[0027] It is to be noted that at least some of the entities or nodes, such as NFc 202, NFp 204, NRF 206, 208, may act in both service-consuming and service-providing roles and that their physical structure may be similar or identical, while their role in the present examples in delivery of a particular message or service is identified by use of the prefix / suffix “c” or “p” indicating whether they are acting as the service-consuming or service-producing NF. It is to be noted that instead of “c” and “p”, “v” for visited and “h” for home can be used to refer to at least some respective entities in the visited and home PLMNs. In some example implementations, a telecommunications system includes parts from multiple generations of mobile communication technology.
[0028] In some example implementations, OAuth or another authorization framework for service authorization and / or token exchange is applied between NFc 202 and NFp 204 for the purpose of authorizing an NFc to access the service of an NFp. In some of these example implementations, an NRF 206, 208 or another network entity may be or perform as an authorization server, such asan OAuth authorization server. The NFc may be an OAuth client and the NFp may operateas OAuth resource server, and they may be configured to support OAuth authorization framework.
[0029] In general, a network support function such as NRF 206 may be further configured to act as an authorization server, and provide the NFc 202 (or SCP 218 acting on behalf of the NFc) with a cryptographic access token authorizing the NFc to use the service provided by the NFp 204. In this regard, the access token is a credential that can be used by the NFc to access the service. One example of a suitable access token is an OAuth access token, which in some further examples may be formatted as a JSON Web Token (JWT). The access token may assert some number of claims that include information for the NFp to identify the NFc, scope of access, expiry, etc. The access token may include a unique token identifier, and a cryptographic signature produced using a private key of the NRF.
[0030] The NFc 202 (or SCP 218) may include the access token in a service request for access to a service provided by the NFp 204, such as in an "authorization bearer” header. In this regard, the purpose of the access token is to inform the NFp that the bearer of the token has been authorized to access the service and perform specific actions (as specified by a scope of access that has been granted). The access token may be used as a Bearer credential (and therefore at times referred to as a bearer access token), and transmitted in an HTTP Authorization header of an HTTP request message.
[0031] The NFp 204 may receive the service request and perform a validation of the access token before allowing access to the service. The NFp may verify validity of the cryptographic signature using the corresponding public key of the NRF 206, which the NFp may obtain in connection with registering the service(s) it provides with the NRF. The NFp may also validate the claims asserted in the access token (the information for the NFp to identify the NFc, scope of access, expiry, etc.). In some examples, this validation may include verifying the access token has not expired based on its expiry, which may be sufficient to enable the NFc to reuse the access token.
[0032] In 3GPP, reducing information exposure over SBI has been studied, including mechanisms to prevent excessive data exposure over SBI, and access to disallowed resource segments. One proposed solution addresses the issue through configurable resource content filters. The proposed solution addresses in particular aspects of how to restrict information provided by an NFp 204 to different NFcs 202, and how to differentiate among NFcs who possess same scope of authorization to a resource. According to the proposed solution, NFps may apply configurable resource content filters in specific use cases as determined by the NRF 206, using rules that may take input of NFc characteristics, NFp characteristics and other information. The resource content filters may be implemented by the NFp when presenting a resource to the NFc.
[0033] Resource content filter definitions may be decided by each NFp 204. This may include specifying a list of resource attributes that are either allowed or restricted. These attributes may be identified by JSON pointers, which may also include variable values to allow or restrict specific instances of an attribute.Variable values may be fixed or use patterns such as regular expressions, ranges, or wildcards, and may be derived from parameters in a request from an NFc 202, such as uniform resource identifier (URI), payload, or OAuth token content. The variable values in at least some of the resource content filters may be based on consumer characteristics, information or the like (generally consumer information) related to the NFc.
[0034] FIG. 3 is a signaling chart 300 of one or more procedures involving use of configurable resource content filters, according to the proposed solution. Operators can define resource content filters that apply to any resource representation defined in an API of an NFp 204. One or more NFp instances may configure these resource content filters, which may be stored or cached in the NFp instances so the resource content filters can be applied when a resource is presented. Each resource content filter has a unique resource content filter identifier (ID) within the operator network, which may be registered with the NRF 206 by the NFps 204 using the resource content filters.
[0035] The NRF 206 may at step 302 be configured with filter applicability information with authorization mappings that consider consumer information and NF service profiles. This may allow the NRF to generate a list of applicable resource content filter IDs to apply when a NFc 202 accesses a resource. In addition to deciding if the NFc is authorized to access a resource, the NRF may use configuration data to determine which resource content filters to be applied by the NFp 204. Additional configuration that the NRF may use to determine applicable filters for authorizing NFc access may take various forms and may be based on any relevant information available to the NRF about the NFc or the NFp's resources.
[0036] As shown at step 303, a NFc 202 may send the NRF 206 an access token request for authorization to access a resource or service of the NFp 204. When the NFc requests the access token, the NRF 206 may at step 304 determine applicable resource content filters based on the filter applicability information, and include the relevant filter IDs in the token. When variable values in the applicable resource content filters are based on consumer information, the NRF may also determine the consumer information to include in the token. The NRF can maintain multiple such lists for different filters, ensuring that only the necessary consumer information is included in the token.
[0037] The NRF 206 may at step 305 send an access token response to the NFc 202, including the access token that contains the relevant filter IDs and consumer information. The NFc may then at step 306 send the NFp 204 a resource request with the access token. The NFp, upon receiving a request with the access token, may at step 307 apply the appropriate filters before sending data from the requested resource to the NFc at step 308.
[0038] Below is a table that shows some example filters configured at an NFp 204, e.g., determining that "when filter 8703 is applied upon returning resource ResA to an NFc X, attributeAbc shall be included only if its value is 1 and subAttrXyz in attributeAbc shall be excluded.” Note that whether the filter 8703 shall be applied to requests of NFc X may be configured at the NRF 206 (and may depend on the NFc type etc.).
[0039] As explained in greater detail below, the proposed solution suffers from a number of problems, such as A) individual configuration of too many NFps 204 with resource content filters, B) filtering rules that are based on consumer information that is not explicit / inherent in the access token provided in the request from the NFc, and C) complex NFc requests that contain many API-specified filtering parameters that result in the same filtering as the NFp-configured filters. These technical problems may lead to a failure of the proposed solution to achieve its desired goals.
[0040] Again, the proposed solution may be subject to heavy and error-prone NFp configuration. NFps 204 of the same NF type are expected to often serve the same use cases and therefore may need to use also the same or similar filters. In solutions with numerous NFps requiring the same filters, the proposed solution requires those filters to be separately configured in each NFp. This can be cumbersome and error-prone, thus discouraging the adoption of the resource content filters. Even more importantly, it increases the risk of misalignment between the configuration at the NRF about the "filter applicability” and the configuration at the NFps about the filter contents (and existence / validity), e.g., the NRF configuration might refer to filters that are applicable for an NFp that does not have these filters (anymore).
[0041] Filtering rules, which are defined in the content of the resource content filters and currently stored only at the NFp 204, may depend on values of consumer information parameters. In the example given above, for example, resource content filters may depend on the NFc PLMN id ("consumerPImnld”). Other examples may use a NFc "tenant id”, the "subscriber category” associated with the resources to be accessed by the NFc, or other consumer-related information. These resource content filters cannot work properly if the NFp does not receive (or cannot derive itself) the required consumer information. For example, a resource content filter that specifies the return a certain part of a requested resource only if the resource is associated with the "GOLD” category will not work if the consumer categories (including "GOLD”) are maintained by the operator elsewhere than at the NFp, and are not provided securely and explicitly in the request (which would be the case for most APIs).
[0042] Another problem with the proposed solution involves NFc requests that include a complex filter specification. When a NFc 202 uses a SBI to request a resource provided by a NFp 204, the defaultbehavior of the NFp is to send the entire content of the requested resource, with the format defined in the API. In some use cases, the NFc may only need part of the resource, To retrieve the entire content may waste processing and network resources by the NFp retrieving the resource content, constructing a full representation, sending the representation across the network to the NFc (potentially through intermediate NFs / SCPs), and by the NFc decoding the entire resource.
[0043] The NFc 202 may be able to request the specific parts of the resource required for a particular use case. This may depend on the API allowing access to the resource specifying the method of filtering and which types of filtering can be requested (which attributes can be used for filtering), and the NFc including in its request a list of filter terms (for example as query parameters). But APIs do not always allow complete flexibility on what filtering may be requested by a NFc. If the NFc implementation would benefit from using an unsupported filter, the API has to be modified in the standards. Additionally, NFc requests including filter terms can be quite large. This can result in larger message sizes and increased processing resource required, potentially negating the benefit of retrieving a partial resource that satisfies the use case requirements.
[0044] In view of the foregoing, example implementations of the present disclosure provide solutions to the aforementioned problems described above. According to some example implementations, NFps 204 may discover and reference resource content filters registered by other NFps. This may reduce the need for NFps to be configured with resource content filters, as well as the risk of misalignment between NRF and NFp configuration, and between configuration of different NFps (which could lead to different filter behavior for the same use case on different NFps, for example).
[0045] In some example implementations, consumer information to be derived at the NRF 206 may be based on derivation rules that are either configured at the NRF or registered by any authorized NF (which is not necessarily the only NF for which these derivation rules will apply).
[0046] In some example implementations, NFcs 202 may request that the NFp 204 apply one or more resource content filters. In some of these examples, the NFc may include filter IDs in a request sent to the NFp, rather than needing to include a potentially large, detailed specification of the filtering that the NFc wants to be applied. Also in some of these examples, the NFc may be able to discover which resource content filters are available at the NFps, so the NFc does not need to be configured or coded with the resource content filters it wants to use.
[0047] FIG. 4 is a signaling chart 400 of one or more procedures involving use of configurable resource content filters, according to various example implementations. As shown at step 401a, an NRF 204 may be configured with resource content filter applicability rules. These rules may apply to one or more registered resource content filters and may be used to instruct the NRF on how to decide which resource content filters must be applied by the NFp(s) 204A, 204B in specific cases. Alternatively, these rules may beregistered at the NRF by the NFp or by an NF (or Operations, Administration, and Maintenance (OAM)) which has the related authority.
[0048] The configuration of filter applicability rules may be performed in a number of different manners. As described, the filter applicability rules may be configured by either configuration on the NRF 206, or by registration at the NRF by a NFp 204. In some examples, the registration at the NRF by the NFp may extend the existing NF profile resource to allow inclusion of the applicability rules related to each resource content filter the NFp registers. This extension may re-use the allowedRuleSet attribute already in place in the NF profile data type definition, or alternatively use a new attribute that provides a similar concept. It may also be possible to include the allowedRuleSet attribute (or any other new attribute introduced to define filter applicability rules - in an NF profile in a shared data resource. This would allow a set of filter applicability rules to be associated with multiple NFps without the need for each of the NFps to individually register their rule sets.
[0049] In some examples, the association of resource content filters and / or consumer information derivation rules with NFps 204 may be achieved by the NFps registering references to the resource content filters or rule sets, such as the IDs of the resource content filters or rule sets. The references so registered may be stored in an extension to the NF profile resource that is already used by NFps to register their profiles at the NRF 206. Use of the shared profile mechanism already supported by NRF may also allow the references to be included in shared profile data, and a shared profile data containing such references may be associated with multiple NFps. This may enable, for example, a list of filter IDs to be associated with multiple NFps without the need for each of the NFps to individually register their list of resource content filters at NRF.
[0050] As shown at steps 401b, 401c, 402a, 402b, NFp(s) 204A, 204B may be configured with and register resource content filters (content of resource content filters) and consumer information derivation rules. In this regard, the NFp(s) may be configured with resource content filters that may be applied when constructing resource representations in specific use cases, such as according to the aforementioned proposed solution.
[0051] In some examples, the NRF 206 may be additionally configured with the consumer information derivation rules. These rules apply to one or more of the configured resource content filters and may be used to instruct the NRF on how to derive the required filter input information for a NFc 202 making a request to which the resource content filter applies. Alternatively, these rules may be registered at the NRF by the NFp 204 or by an NF (or OAM) which has the related authority. Notably, these rules may then apply to any NFc-NFp interaction. The following table shows example consumer information derivation rules that derive the NFc tenant id based on NFc instance id patterns and the NFc category based on the NFc type.
[0052] The NFp(s) 204A, 204B may register at NRF 206 the content of their configured resource content filters. In some examples, the number of the NFp's configured resource content filters are registered at the NRF may be up to NFp local policy or configuration. The content of the resource content filters registered at the NRF may be the same as or similar to that of the proposed solution described above. In some examples, the content of the resource content filters may include a list of attributes within a resource that is allowed to be presented, and / or a list of attributes within the resource that are not allowed to be presented. For configured resource content filters that are registered at the NRF that use the consumer information derivation rules, the consumer information derivation rules may also be registered at NRF, unless configured at NRF by other means.
[0053] The registration of resource content filters at the NRF 206 may be performed in a number of different manners. In some examples, new resources used to store resource content filters may be defined as part of the Nnrf_NFManagement service. These resources may contain filter details and be identified by a filter ID. NFps 204 may create, update and delete the resources, and other NFs (NFcs 202 and NFps) may read the resources and subscribe to notifications of data change on them.
[0054] In some other examples, a new NRF service may be created to manage the resource content filter resources. These resources may be managed and accessed in a manner similar to that described above.
[0055] Like the registration of resource content filters, the registration of consumer information derivation rules at the NRF 206 may be performed in a number of different manners. In some examples, new resources used to store consumer information derivation rules may be defined as part of the Nnrf_NFManagement service. These resources may contain rule details and be identified by a ruleset ID. The rule sets may be linked to resource content filters using a ruleset ID attribute inside the resource content filter resource. The NFps 204 may create, update and delete the resources, and other NFs (NFcs 202 and NFps) may read the resources and subscribe to notifications of data change on them.
[0056] In some other examples, a new NRF service may be created to manage the consumer information derivation rules resources. These resources may be managed and accessed in a manner similar to that described above. The new service may be the same service as is used to manage the resource content filter resources as described above.
[0057] As shown at step 403, an NFp 204A may discover one or more resource content filters (content of resource content filters) registered by other NFps(s) (e.g., NFp 204B). In this regard, a NFp may request that the NRF 206 send resource content filters that have been registered by other NFps. In some examples, the requested resource content filters may be filtered by the NFp's request so that only appropriate resource content filters are retrieved by the NFp, such as those that apply to resources held by the requesting NFp.
[0058] The NRF 206 may send details of registered resource content filters to the NFp 204 in response to the request, and the NFp may store the registered resource content filters for future use when the NFp receives a request from a NFc 202 requiring application of the resource content filters. This filter discovery may be useful in a number of cases, such as those involving an NF set in which only one of the NF instances is configured with the resource content filters, one or more of which the other NF instances may discover for their use.
[0059] The NFp(s) 204A, 204B may at step 404 register with the NRF 206 their NF profile(s) which may include the IDs of resource content filters that are usable by the NFp(s). For an NFp, the NF profile of the NFp may include resource content filter ID(s) of usable resource content filters selected from resource content filter(s) registered by the NFp and / or other resource content filter(s) registered by other NFp(s) and discovered by the NFp.
[0060] An NFc 202 may at step 405 discover resource content filters (content of resource content filters) registered by NFp(s) 204A, 204B. In this regard, the NFc may request that the NRF 206 send resource content filters that have been registered by NFps. In some examples, the requested resource content filters may be filtered by the NFc's request so that only appropriate resource content filters are retrieved, such as those that apply to resources used by the requesting NFc. The NRF may send the details of registered resource content filters to the NFc, and the NFc may store the resource content filters for future application, such as for issuing service requests towards the NFp with resource content filters as described below.
[0061] The discovery of resource content filters or consumer information derivation rules may be done by NFcs 202 or NFps 204 in a number of different manners. In some examples, the discovery of resource content filters or consumer information derivation rules may be done by accessing the service(s) at the NRF 206 that manage these resources. The NFcs of this NRF service may perform filtered reads or searches, or they may read specific resources using the resource ID.
[0062] As shown at steps 406, 407 and 408, the NFc 202 may request that the NRF 206 generate an access token with a specific scope. The NRF may check the authorization of the NFc for the requested scope, and make an authorization decision. If authorized, the NRF may checks the filter applicability rules and determine which resource content filter(s) to be applied when the NFc requests a resource within the scope of the access token, such as according to the proposed solution described above. The NRF mayalso check the registered consumer information derivation rules and determine consumer information to be used as input to the applicable resource content filters.
[0063] The NRF 206 may generate the access token that contains a list of IDs of applicable resource content filters, and the consumer information used by the applicable resource content filters. The NRF may then send the access token to the NFc 202.
[0064] As shown at steps 409, 410 and 411, the NFc 202 may request a resource of a NFp (e.g., NFp 204A). In this regard, the NFc may request that the NFp send a representation of a resource. The request includes the access token (containing the list of filter IDs and consumer information). In some examples, the request includes additional filter IDs that the NFc wants the NFp to apply. The NFp may apply the resource content filters specified in the access token and in the NFc's request when constructing the representation of the resource, and send a response including the filtered resource representation to the NFc.
[0065] As described above, the solutions provided by example implementations of the present disclosure provide a number of advantages. Registration at the NRF 206 of the content of resource content filters configured in a NFp 204 may reduce the overhead of configuring multiple resource content filters in multiple NFp instances. Instead, a NFp can discover some or all of the resource content filters that it can apply by querying NRF.
[0066] Registration at the NRF 206 of the content of resource content filters configured in a NFp 204 also allows NFcs 202 to discover resource content filters that may be requested by the NFc to be applied by a NFp. Without this discovery, the NFc can still request application of resource content filters, but the NFc needs to obtain information about the available resource content filters using other means, such as local configuration. Notably, decisions about which resource content filters the NFc should request to be used may be based on the content of the resource content filters and NFc logic and / or configuration.
[0067] Allowing the NFps 204 to register consumer information derivation rules at the NRF 206, in addition to registering filter content, may avoid the need in some cases for the NRF to obtain the derivation rules by other means, such as local configuration. The registration of consumer information derivation rules may also allow exposure of the derivation rules to other NFps and NFcs 202, which may allow these NFs to make decisions about when and how to use the resource content filters and what consumer information may be required in NFc requests that request these resource content filters to be applied.
[0068] Even further, the ability of a NFc 202 to specify, in a request sent to a NFp 204, resource content filters to be applied by the NFp using only a filter ID may greatly reduce the size of the request message sent to the NFp. It may also reduce the amount of processing required by the NFp in interpreting a filtering request to determine how the resource representation is to be filtered.
[0069] The solutions and behaviors described above may be applicable to 3GPP core network standards, but may also be applicable outside the core network.
[0070] In some examples, NFcs 202 may be allowed to specify filter IDs in the access token generation request sent to the NRF 206 (see steps 406 - 408). This may allow the NRF to generate an access token that contains a list of filter IDs that the NFc 202 wants to be applied whenever that access token is used. The complexity of generating requests the NFc sends to the NFp may also be reduced to include the list of IDs of resource content filters to be applied, but without a change in the size of the request as the list of filter IDs is still present in the access token. The NFc may also not be able to use that access token without all the resource content filters listed being applied, but may instead request a new access token.
[0071] FIGS. 5A and 5B are flowcharts illustrating various steps in a method 500 performed by a network function service producer (NFp), according to various example implementations. The method includes at least one of registering with a network repository function (NRF) one or more resource content filters associated with the NFp, or discovering another one or more resource content filters registered with the NRF by at least one other NFp, as shown at blocks 502 and 504 of FIG. 5A. And the method includes registering a network function profile for the NFp with the NRF, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters, as shown at block 506.
[0072] In some examples, the method 500 further includes registering with the NRF one or more consumer information derivation rules to be applied by the NRF to determine consumer information for at least one network function service consumer (NFc) that requests an authorization to access a resource of the NFp.
[0073] In some examples, the method 500 further includes receiving a request from a network function service consumer (NFc) for a resource of the NFp, the request including at least one resource content filter ID of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc, as shown at block 508 of FIG. 5B. In some of these examples, the method also includes applying the at least one resource content filter when a representation of the resource is constructed, as shown at block 510. And the method includes sending a response to the request to the NFc that includes the representation of the resource, as shown at block 512.
[0074] In some examples, the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters. In some of these examples, the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter. Also in some of these examples, applying the at least one resource content filter at block 510 includes applying the at least one applicable resource content filter and the at least one additional resource content filter.
[0075] FIGS. 6A and 6B are flowcharts illustrating various steps in a method 600 performed by a network repository function (NRF), according to various example implementations. The method includes receivingan access token request from a network function service consumer (NFc) for an authorization to access a resource or service of a network function service producer (NFp), as shown at block 602 of FIG. 6A. The method includes applying one or more consumer information derivation rules to determine consumer information used by at least one applicable resource content filter associated with the NFp, as shown at block 604. The method includes generating an access token that contains at least one resource content filter identifier (ID) of the at least one applicable resource content filter, and the consumer information, as shown at block 606. And the method includes sending an access token response including the access token to the NFc, as shown at block 608.
[0076] In some examples, the one or more consumer information derivation rules are registered with the NRF by the NFp or another network function.
[0077] In some examples, one or more resource content filter applicability rules are registered with the NRF by the NFp or another network function. In some of these examples, the method 600 further includes applying the one or more resource content filter applicability rules to determine the at least one applicable resource content filter associated with the NFp that are applicable to the NFc.
[0078] In some examples, one or more resource content filters associated with the NFp are registered with the NRF. In some of these examples, the method 600 further includes sending to the NFp another one or more resource content filters registered with the NRF by at least one other NFp, as shown at block 610 of FIG. 6B. Also in some of these examples, the method includes registering a network function profile for the NFp, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters, as shown at block 612. And the at least one applicable resource content filter is determined from the one or more usable resource content filters.
[0079] In some examples, the at least one applicable resource content filter is determined from one or more usable resource content filters that are usable by the NFp. In some of these examples, the method 600 further includes sending the one or more usable resource content filters to the NFc.
[0080] FIG. 7 is a flowchart illustrating various steps in a method 700 performed by a network function service consumer (NFc), according to various example implementations. The method includes discovering from a network repository function (NRF) one or more usable resource content filters associated with a network function service producer (NFp), as shown at block 702. The method includes sending a request for a resource of the NFp, the request including at least one resource content filter identifier (ID) of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc, as shown at block 704. And the method includes receiving a response to the request from the NFp that includes a representation of the resource constructed by the NFp during which the at least one resource content filter is applied, as shown at block 706.
[0081] In some examples, the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters. In some of these examples, the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter.
[0082] In some examples, the access token also contains consumer information used by the at least one applicable resource content filter. In some of these examples, the consumer information is determined by the NRF by application of one or more consumer information derivation rules registered with the NRF by the NFp or another network function.
[0083] According to example implementations of the present disclosure, a telecommunications system 100 or PLMN 102, and its components such as NFc 202, NFp 204, NRFc 218 and / or NRFp 220, may be implemented by various means. Means for implementing the system and its components may include hardware, firmware, software, or combinations thereof. In some examples, one or more apparatuses may be configured to function as or otherwise implement the system and its components shown and described herein. In examples involving more than one apparatus, the respective apparatuses may be connected to or otherwise in communication with one another in a number of different manners, such as directly or indirectly via a wired or wireless network or the like.
[0084] According to some example implementations, at least some of the method 500 described with respect to FIGS. 5A and 5B may be carried out by an apparatus comprising means for performing functions corresponding steps of the method. Similarly, at least some of the method 600 described with respect to FIGS. 6A and 6B may be carried out by an apparatus comprising means for performing functions corresponding steps of the method. And at least some of the method 700 described with respect to FIG. 7 may be carried out by an apparatus comprising means for performing functions corresponding steps of the method. Examples of a suitable apparatus may include a network function or any suitable apparatus, such as a server, host or node.
[0085] FIG. 8 illustrates an apparatus 800 in which means for performing various functions includes hardware, alone or under direction of one or more computer programs from a computer-readable storage medium or other memory, such as computer memory, according to some example implementations of the present disclosure. The apparatus may include one or more of each of a number of components such as, for example, processing circuitry 802 connected to computer-readable storage medium or other memory 804.
[0086] The processing circuitry 802 may be composed of one or more processors alone or in combination with one or more computer-readable storage media. The processing circuitry is generally any piece of computer hardware that is capable of processing information such as, for example, data, computer programs and / or other suitable electronic information. The processing circuitry is composed of a collectionof electronic circuits some of which may be packaged as an integrated circuit or multiple interconnected integrated circuits (an integrated circuit at times more commonly referred to as a "chip”). The processing circuitry may be configured to execute computer programs, which may be stored onboard the processing circuitry or otherwise stored in the memory 804 (of the same or another apparatus).
[0087] The processing circuitry 802 may be a number of processors, a multi-core processor or some other type of processor, depending on the particular implementation. Further, the processing circuitry may be implemented using a number of heterogeneous processor systems in which a main processor is present with one or more secondary processors on a single chip. As another illustrative example, the processing circuitry may be a symmetric multi-processor system containing multiple processors of the same type. In yet another example, the processing circuitry may be embodied as or otherwise include one or more ASICs, FPGAs or the like. Thus, although the processing circuitry may be capable of executing a computer program to perform one or more functions, the processing circuitry of various examples may be capable of performing one or more functions without the aid of a computer program. In either instance, the processing circuitry may be appropriately programmed to perform functions or operations according to example implementations of the present disclosure.
[0088] The memory 804 is generally any piece of computer hardware that is capable of storing information such as, for example, data, computer programs, instructions 806 (e.g., computer-readable program code) and / or other suitable information either on a temporary basis and / or a permanent basis. The memory may include volatile and / or non-volatile memory, and may be fixed or removable. Examples of suitable memory include recording media, random access memory (RAM), read-only memory (ROM), a hard drive, a flash memory, a thumb drive, a removable computer diskette, an optical disk or some combination thereof.
[0089] The memory 804 is a non-transitory device capable of storing information. One example of a suitable memory is a computer-readable storage medium, which is distinguishable from a computer-readable transmission medium capable of carrying information from one location to another. Examples of suitable computer-readable transmission media comprise electronic carrier signals, telecommunications signals, or some combination thereof. As used herein, the term "non-transitory” is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM versus ROM). A computer-readable medium as described herein generally refers to a computer-readable storage medium or computer-readable transmission medium. A computer-readable medium is any entity or device capable in which information, such as one or more computer programs or portions thereof, may be stored and carried.
[0090] In addition to the memory 804 (e.g., computer-readable storage medium), the processing circuitry 802 may also be connected to one or more interfaces for displaying, transmitting and / or receiving information. The interfaces may include a communications interface 808 and / or one or more user interfaces (e.g., display, user input interface). The communications interface may be configured to transmit and / orreceive information, such as to and / or from other apparatus(es), network(s) or the like. The communications interface may be configured to transmit and / or receive information by physical (wired) and / or wireless communications links. Examples of suitable communication interfaces include a network interface controller (NIC), wireless NIC (WNIC) or the like.
[0091] Execution of the instructions 806 by the processing circuitry 802, or storage of the instructions in the memory 804, supports combinations of operations for implementing example implementations of the present disclosure. In this manner, an apparatus 800 may comprise at least one processing circuitry and at least one memory coupled to the at least one processing circuitry, where the at least one processing circuitry is configured to execute instructions stored in the at least one memory. It will also be understood that one or more functions, and combinations of functions, may be implemented by special purpose hardware-based computer systems and / or processing circuitry which perform the specified functions, or combinations of special purpose hardware and program code instructions.
[0092] Some example implementations of the present disclosure may also be carried out in the form of a computer process defined by one or more computer programs or portions thereof. Example implementations of the present disclosure may be carried out by executing at least one portion of a computer program comprising instructions. The computer program may be in source code form, object code form, or in some intermediate form. The computer program may be stored in a computer-readable medium that is readable by a computer, processing circuitry or other suitable apparatus. As indicated above, for example, the computer program may be stored in a memory, such as a computer-readable storage medium. Additionally or alternatively, for example, the computer program may be stored in a computer-readable transmission medium. The coding of software for carrying out example implementations of the present disclosure is well within the scope of a person of ordinary skill in the art.
[0093] As will be appreciated, any suitable instructions may be loaded onto a computer, a processing circuitry or other programmable apparatus from a memory or a computer-readable medium (e.g., computer-readable storage medium, computer-readable transmission medium) to produce a particular machine, such that the particular machine becomes a means for implementing the functions specified herein. The instructions may also be stored in a computer-readable medium that can direct a computer, a processing circuitry or other programmable apparatus to function in a particular manner to thereby generate a particular machine or particular article of manufacture. In some examples, the instructions stored in the computer-readable medium may produce an article of manufacture, where the article of manufacture becomes a means for implementing functions described herein. The instructions may be retrieved from a computer-readable medium and loaded into a computer, processing circuitry or other programmable apparatus to configure the computer, processing circuitry or other programmable apparatus to execute operations to be performed on or by the computer, processing circuitry or other programmable apparatus.
[0094] Retrieval, loading and execution of instructions comprising program code instructions may be performed sequentially such that one instruction is retrieved, loaded and executed at a time. In some example implementations, retrieval, loading and / or execution may be performed in parallel such that multiple instructions are retrieved, loaded, and / or executed together. Execution of the program code instructions may produce a computer-implemented process such that the instructions executed by the computer, processing circuitry or other programmable apparatus provide operations for implementing functions described herein.
[0095] As explained above and reiterated below, the present disclosure includes, without limitation, the following example implementations.
[0096] Clause 1. A method performed by a network function service producer (NFp), the method comprising: at least one of registering with a network repository function (NRF) one or more resource content filters associated with the NFp, or discovering another one or more resource content filters registered with the NRF by at least one other NFp; and registering a network function profile for the NFp with the NRF, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters.
[0097] Clause 2. The method of clause 1, wherein the method further comprises registering with the NRF one or more consumer information derivation rules to be applied by the NRF to determine consumer information for at least one network function service consumer (NFc) that requests an authorization to access a resource of the NFp.
[0098] Clause 3. The method of clause 1 or clause 2, wherein the method further comprises: receiving a request from a network function service consumer (NFc) for a resource of the NFp, the request including at least one resource content filter ID of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; applying the at least one resource content filter when a representation of the resource is constructed; and sending a response to the request to the NFc that includes the representation of the resource.
[0099] Clause 4. The method of clause 3, wherein the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters, and the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter, and wherein applying the at least one resource content filter includes applying the at least one applicable resource content filter and the at least one additional resource content filter.
[0100] Clause 5. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 1 to 4.
[0101] Clause 6. An apparatus comprising means for performing the method of any of clauses 1 to 4.
[0102] Clause 7. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 1 to 4.
[0103] Clause 8. A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 1 to 4.
[0104] Clause 9. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 1 to 4.
[0105] Clause 10. A method performed by a network repository function (NRF), the method comprising: receiving an access token request from a network function service consumer (NFc) for an authorization to access a resource or service of a network function service producer (NFp); applying one or more consumer information derivation rules to determine consumer information used by at least one applicable resource content filter associated with the NFp; generating an access token that contains at least one resource content filter identifier (ID) of the at least one applicable resource content filter, and the consumer information; and sending an access token response including the access token to the NFc.
[0106] Clause 11. The method of clause 10, wherein the one or more consumer information derivation rules are registered with the NRF by the NFp or another network function.
[0107] Clause 12. The method of clause 10 or clause 11, wherein one or more resource content filter applicability rules are registered with the NRF by the NFp or another network function, and wherein the method further comprises applying the one or more resource content filter applicability rules to determine the at least one applicable resource content filter associated with the NFp that are applicable to the NFc.
[0106] Clause 13. The method of any of clauses 10 to 12, wherein one or more resource content filters associated with the NFp are registered with the NRF, and the method further comprises: sending to the NFp another one or more resource content filters registered with the NRF by at least one other NFp: and registering a network function profile for the NFp, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters, and wherein the at least one applicable resource content filter is determined from the one or more usable resource content filters.
[0109] Clause 1. The method of any of clauses 10 to 13, wherein the at least one applicable resource content filter is determined from one or more usable resource content filters that are usable by the NFp, and wherein the method further comprises sending the one or more usable resource content filters to the NFc.
[0110] Clause 15, An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 10 to 14.
[0111] Clause 16. An apparatus comprising means for performing the method of any of clauses 10 to 14,
[0112] Clause 17. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 10 to 14.
[0113] Clause 18, A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 10 to 14.
[0114] Clause 19. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 10 to 14.
[0115] Clause 20. A method performed by a network function service consumer (NFc), the method comprising: discovering from a network repository function (NRF) one or more usable resource content filters associated with a network function service producer (NFp); sending a request for a resource of the NFp, the request including at least one resource content filter identifier (ID) of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; and receiving a response to the request from the NFp that includes a representation of the resource constructed by the NFp during which the at least one resource content filter is applied.
[0116] Clause 21, The method of clause 20, wherein the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters, and the request further includes the at least one resource content, filter ID of the at least one resource content filter as at least one additional resource content filter.
[0117] Clause 22. The method of clause 21, wherein the access token also contains consumer information used by the at least one applicable resource content filter, the consumer information determined by the NRF by application of one or more consumer information derivation rules registered with the NRF by the NFp or another network function.
[0118] Clause 23. An apparatus comprising: at least one memory configured to store instructions; and at least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to perform the method of any of clauses 20 to 22.
[0119] Clause 24, An apparatus comprising means for performing the method of any of clauses 20 to 22.
[0120] Clause 25. A computer-readable medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 20 to 22.
[0121] Clause 26, A computer-readable storage medium comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 20 to 22.
[0122] Clause 27. A computer program comprising instructions that, in response to execution by at least one processing circuitry, causes an apparatus to perform the method of any of clauses 20 to 22.
[0123] Many modifications and other implementations of the disclosure set forth herein will come to mind to one skilled in the art to which the disclosure pertains having the benefit of the teachings presented in the foregoing description and the associated figures. Therefore, it is to be understood that the disclosure is not to be limited to the specific implementations disclosed and that modifications and other implementations are intended to be included within the scope of the appended claims. Moreover, although the foregoing description and the associated figures describe example implementations in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative implementations without departing from the scope of the appended claims, in this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as may be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.
Claims
WHAT IS CLAIMED IS:
1. An apparatus to implement a network function service producer (NFp), the apparatus comprising: at least one memory configured to store instructions; andat least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least:at least one of register with a network repository function (NRF) one or more resource content filters associated with the NFp, or discover another one or more resource content filters registered with the NRF by at least one other NFp; andregister a network function profile for the NFp with the NRF, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters.
2. The apparatus of claim 1, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further register with the NRF one or more consumer information derivation rules to be applied by the NRF to determine consumer information for at least one network function service consumer (NFc) that requests an authorization to access a resource of the NFp.
3. The apparatus of claim 1, wherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further at least:receive a request from a network function service consumer (NFc) for a resource of the NFp, the request including at least one resource content filter ID of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; apply the at least one resource content filter when a representation of the resource is constructed; andsend a response to the request to the NFc that includes the representation of the resource.
4. The apparatus of claim 3, wherein the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters, and the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter, andwherein applying the at least one resource content filter includes applying the at least one applicable resource content filter and the at least one additional resource content filter.
5. A method performed by a network function service producer (NFp), the method comprising:at least one of registering with a network repository function (NRF) one or more resource content filters associated with the NFp, or discovering another one or more resource content filters registered with the NRF by at least one other NFp; andregistering a network function profile for the NFp with the NRF, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters.
6. The method of claim 5, wherein the method further comprises registering with the NRF one or more consumer information derivation rules to be applied by the NRF to determine consumer information for at least one network function service consumer (NFc) that requests an authorization to access a resource of the NFp.
7. The method of claim 5, wherein the method further comprises:receiving a request from a network function service consumer (NFc) for a resource of the NFp, the request including at least one resource content filter ID of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; applying the at least one resource content filter when a representation of the resource is constructed; andsending a response to the request to the NFc that includes the representation of the resource.
8. The method of claim 7, wherein the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters, and the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter, and wherein applying the at least one resource content filter includes applying the at least one applicable resource content filter and the at least one additional resource content filter.
9. An apparatus to implement a network repository function (NRF), the apparatus comprising:at least one memory configured to store instructions; andat least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least:receive an access token request from a network function service consumer (NFc) for an authorization to access a resource or service of a network function service producer (NFp);apply one or more consumer information derivation rules to determine consumer information used by at least one applicable resource content filter associated with the NFp;generate an access token that contains at least one resource content filter identifier (ID) of the at least one applicable resource content filter, and the consumer information; andsend an access token response including the access token to the NFc.
10. The apparatus of claim 9, wherein the one or more consumer information derivation rules are registered with the NRF by the NFp or another network function.
11. The apparatus of claim 9, wherein one or more resource content filter applicability rules are registered with the NRF by the NFp or another network function, andwherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further apply the one or more resource content filter applicability rules to determine the at least one applicable resource content filter associated with the NFp that are applicable to the NFc.
12. The apparatus of claim 9, wherein one or more resource content filters associated with the NFp are registered with the NRF, and the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further at least:send to the NFp another one or more resource content filters registered with the NRF by at least one other NFp; andregister a network function profile for the NFp, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters, and wherein the at least one applicable resource content filter is determined from the one or more usable resource content filters.
13. The apparatus of claim 9, wherein the at least one applicable resource content filter is determined from one or more usable resource content filters that are usable by the NFp, andwherein the at least one processing circuitry is configured to execute the instructions to cause the apparatus to further send the one or more usable resource content filters to the NFc.
14. A method performed by a network repository function (NRF), the method comprising:receiving an access token request from a network function service consumer (NFc) for an authorization to access a resource or service of a network function service producer (NFp);applying one or more consumer information derivation rules to determine consumer information used by at least one applicable resource content filter associated with the NFp;generating an access token that contains at least one resource content filter identifier (ID) of the at least one applicable resource content filter, and the consumer information; andsending an access token response including the access token to the NFc.
15. The method of claim 14, wherein the one or more consumer information derivation rules are registered with the NRF by the NFp or another network function.
16. The method of claim 14, wherein one or more resource content filter applicability rules are registered with the NRF by the NFp or another network function, andwherein the method further comprises applying the one or more resource content filter applicability rules to determine the at least one applicable resource content filter associated with the NFp that are applicable to the NFc.
17. The method of claim 14, wherein one or more resource content filters associated with the NFp are registered with the NRF, and the method further comprises:sending to the NFp another one or more resource content filters registered with the NRF by at least one other NFp; andregistering a network function profile for the NFp, the network function profile including one or more resource content filter identifiers (IDs) of one or more usable resource content filters selected from at least one of the one or more resource content filters or the other one or more resource content filters, and wherein the at least one applicable resource content filter is determined from the one or more usable resource content filters.
18. The method of claim 14, wherein the at least one applicable resource content filter is determined from one or more usable resource content filters that are usable by the NFp, andwherein the method further comprises sending the one or more usable resource content filters to the NFc.
19. An apparatus to implement a network function service consumer (NFc), the apparatus comprising: at least one memory configured to store instructions; andat least one processing circuitry configured to access the at least one memory, and execute the instructions to cause the apparatus to at least:discover from a network repository function (NRF) one or more usable resource content filters associated with a network function service producer (NFp);send a request for a resource of the NFp, the request including at least one resource content filter identifier (ID) of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; andreceive a response to the request from the NFp that includes a representation of the resource constructed by the NFp during which the at least one resource content filter is applied.
20. The apparatus of claim 19, wherein the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters, and the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter.
21. The apparatus of claim 20, wherein the access token also contains consumer information used by the at least one applicable resource content filter, the consumer information determined by the NRF by application of one or more consumer information derivation rules registered with the NRF by the NFp or another network function.
22. A method performed by a network function service consumer (NFc), the method comprising:discovering from a network repository function (NRF) one or more usable resource content filters associated with a network function service producer (NFp);sending a request for a resource of the NFp, the request including at least one resource content filter identifier (ID) of at least one resource content filter of the one or more usable resource content filters, the at least one resource content filter ID specified by the NFc; andreceiving a response to the request from the NFp that includes a representation of the resource constructed by the NFp during which the at least one resource content filter is applied.
23. The method of claim 22, wherein the request includes an access token that contains at least one resource content filter ID of at least one applicable resource content filter determined by the NRF from the one or more usable resource content filters, and the request further includes the at least one resource content filter ID of the at least one resource content filter as at least one additional resource content filter.
24. The method of claim 23, wherein the access token also contains consumer information used by the at least one applicable resource content filter, the consumer information determined by the NRF by application of one or more consumer information derivation rules registered with the NRF by the NFp or another network function.