Methods and apparatuses for implementing roaming service

By mapping and forwarding messages through network proxies, the method establishes N32 interfaces between SEPPs in different networks, allowing subscription-based routing to a target core network without requiring a direct roaming agreement, thus overcoming the SEPP communication barrier.

WO2026103925A1PCT designated stage Publication Date: 2026-05-21TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2025-11-18
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

The security edge protection proxy (SEPP) in the visited network cannot establish a N32 interface with the SEPP in the target network due to the lack of roaming agreement, preventing the functionality of subscription-based routing to a target core network.

Method used

A method involving network nodes in the home, visited, and target networks to establish communication paths by mapping and forwarding messages through proxies, enabling the establishment of N32 interfaces without requiring a direct roaming agreement between the networks.

Benefits of technology

Enables the functionality of subscription-based routing to a target core network without impacting network function consumers in the visited network, even in the absence of a roaming agreement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025135684_21052026_PF_FP_ABST
    Figure CN2025135684_21052026_PF_FP_ABST
Patent Text Reader

Abstract

Methods and apparatuses for implementing roaming service are disclosed. According to an embodiment, a first network node implementing a proxy in a home network for a terminal device receives, from a second network node implementing a proxy in a visited network for the terminal device, a first message related to the terminal device. The first message comprises information for an address of the home network mapped from an address of a fourth network node in a target network for the terminal device. The first network node sends a second message to a third network node implementing a proxy in the target network, based on the information for the address of the home network.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND APPARATUSES FOR IMPLEMENTING ROAMING SERVICETechnical Field

[0001] Embodiments of the disclosure generally relate to communication, and, more particularly, to methods and apparatuses for implementing roaming service.Background

[0002] This section introduces aspects that may facilitate better understanding of the present disclosure. Accordingly, the statements of this section are to be read in this light and are not to be understood as admissions about what is in the prior art or what is not in the prior art.

[0003] The roaming value-added service (RVAS) functionality is introduced in Release 19. As mentioned in 3rd generation partnership project (3GPP) technical specification (TS) 22.877 V19.0.0, the RVAS functionality may include welcome short messaging service (SMS) , steering of roaming (SoR) during the registration, and subscription-based routing to a target core network.

[0004] For the functionality of subscription-based routing to a target core network, chapter 4.2.3 of 3GPP TS 23.501 V19.2.1 describes the following content. Subscription-based routing to a particular core network as specified in clause 6.44 of TS 22.261 [2] enables forwarding of the signalling and user traffic of certain UEs to a target PLMN that may be neither the serving PLMN nor the HPLMN of the UE. This is achieved by selecting NFs residing in the target PLMN. The NRF of the HPLMN, with optional support of the NRF in that target PLMN as specified in clause 4.17.5 of TS 23.502 [3] , is responsible to provide proper network function instance information during network function discovery and selection.Summary

[0005] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0006] One of the objects of the disclosure is to provide an improved solution for implementing roaming service. In particular, one of the problems to be solved by the disclosure is that for the functionality of subscription-based routing to a target core network, the security edge protection proxy (SEPP) in the visited network could not establish a N32 interface with the SEPP in the target network in some cases so that such functionality could not work.

[0007] According to a first aspect of the disclosure, a method at a first network node implementing a proxy in a home network for a terminal device is provided. The method may comprise receiving, from a second network node implementing a proxy in a visited network for the terminal device, a first message related to the terminal device. The first message may comprise information for an address of the home network mapped from an address of a fourth network node in a target network for the terminal device. The method may further comprise sending a second message to a third network node implementing a proxy in the target network, based on the information for the address of the home network.

[0008] According to a second aspect of the disclosure, a method at a second network node implementing a proxy in a visited network for a terminal device is provided. The method may comprise receiving, from a fifth network node in the visited network, a fourth message related to the terminal device. The fourth message may comprise information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device. The method may further comprise sending a first message to a first network node implementing a proxy in the home network, based on the information for the address of the home network.

[0009] According to a third aspect of the disclosure, a method at a third network node implementing a proxy in a target network for a terminal device is provided. The method may comprise receiving, from a first network node implementing a proxy in a home network for the terminal device, a second message related to the terminal device. The second message may comprise an address of a fourth network node in the target network. The method may further comprise sending a third message to the fourth network node, based on the address of the fourth network node.

[0010] According to a fourth aspect of the disclosure, a method at a fourth network node in a target network for a terminal device is provided. The method may comprise receiving, from a third network node implementing a proxy in the target network, a third message related to the terminal device.

[0011] According to a fifth aspect of the disclosure, a method at a fifth network node in a visited network for a terminal device is provided. The method may comprise sending, to a second network node implementing a proxy in the visited network, a fourth message related to the terminal device. The fourth message may comprise information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device.

[0012] According to a sixth aspect of the disclosure, a method at a sixth network node implementing a network repository function (NRF) in a home network for a terminal device is provided. The method may comprise receiving, from a seventh network node implementing a NRF in a target network for the terminal device, an address of a fourth network node in the target network. The method may further comprise determining information for an address of the home network mapped from the address of the fourth network node. The method may further comprise sending the information for the address of the home network to an eighth network node implementing a NRF in a visited network for the terminal device.

[0013] According to a seventh aspect of the disclosure, a first network node implementing a proxy in a home network for a terminal device is provided. The first network node may comprise processing circuitry and a memory. The processing circuitry may be configured to receive, from a second network node implementing a proxy in a visited network for the terminal device, a first message related to the terminal device. The first message may comprise information for an address of the home network mapped from an address of a fourth network node in a target network for the terminal device. The processing circuitry may be further configured to send a second message to a third network node implementing a proxy in the target network, based on the information for the address of the home network.

[0014] According to an eighth aspect of the disclosure, a second network node implementing a proxy in a visited network for a terminal device is provided. The second network node may comprise processing circuitry and a memory. The processing circuitry may be configured to receive, from a fifth network node in the visited network, a fourth message related to the terminal device. The fourth message may comprise information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device. The processing circuitry may be further configured to send a first message to a first network node implementing a proxy in the home network, based on the information for the address of the home network.

[0015] According to a ninth aspect of the disclosure, a third network node implementing a proxy in a target network for a terminal device is provided. The third network node may comprise processing circuitry and a memory. The processing circuitry may be configured to receive, from a first network node implementing a proxy in a home network for the terminal device, a second message related to the terminal device. The second message may comprise an address of a fourth network node in the target network. The processing circuitry may be further configured to send a third message to the fourth network node, based on the address of the fourth network node.

[0016] According to a tenth aspect of the disclosure, a fourth network node in a target network for a terminal device is provided. The fourth network node may comprise processing circuitry and a memory. The processing circuitry may be configured to receive, from a third network node implementing a proxy in the target network, a third message related to the terminal device.

[0017] According to an eleventh aspect of the disclosure, a fifth network node in a visited network for a terminal device is provided. The fifth network node may comprise processing circuitry and a memory. The processing circuitry may be configured to send, to a second network node implementing a proxy in the visited network, a fourth message related to the terminal device. The fourth message may comprise information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device.

[0018] According to a twelfth aspect of the disclosure, a sixth network node implementing a NRF in a home network for a terminal device is provided. The sixth network node may comprise processing circuitry and a memory. The processing circuitry may be configured to receive, from a seventh network node implementing a NRF in a target network for the terminal device, an address of a fourth network node in the target network. The processing circuitry may be further configured to determine information for an address of the home network mapped from the address of the fourth network node. The processing circuitry may be further configured to send the information for the address of the home network to an eighth network node implementing a NRF in a visited network for the terminal device.

[0019] According to a thirteenth aspect of the disclosure, a computer program is provided. The computer program may comprise instructions that, when executed by processing circuitry, cause the processing circuitry to carry out the method according to any of the above first to sixth aspects.

[0020] According to a fourteenth aspect of the disclosure, a computer program product is provided. The computer program product may comprise instructions that, when executed by processing circuitry, cause the processing circuitry to carry out the method according to any of the above first to sixth aspects.

[0021] According to a fifteenth aspect of the disclosure, a computer-readable medium is provided. The computer-readable medium may comprise instructions that, when executed by processing circuitry, cause the processing circuitry to carry out the method according to any of the above first to sixth aspects.

[0022] According to a sixteenth aspect of the disclosure, a carrier is provided. The carrier may contain the computer program according to the above thirteenth aspect. The carrier may be one of an electronic signal, optical signal, radio signal, or computer-readable medium.

[0023] According to a seventeenth aspect of the disclosure, a method implemented in a communication system is provided. The communication system may include any two or more of: a first network node implementing a proxy in a home network for a terminal device, a second network node implementing a proxy in a visited network for a terminal device, a third network node implementing a proxy in a target network for a terminal device, a fourth network node in a target network for a terminal device, a fifth network node in a visited network for a terminal device, and a sixth network node implementing a NRF in a home network for a terminal device. The method may comprise any two or more of: steps of the method according to the above first aspect; steps of the method according to the above second aspect; steps of the method according to the above third aspect; steps of the method according to the above fourth aspect; steps of the method according to the above fifth aspect; and steps of the method according to the above sixth aspect.

[0024] According to an eighteenth aspect of the disclosure, a communication system is provided. The communication system may include any two or more of: a first network node according to the above seventh aspect, a second network node according to the above eighth aspect, a third network node according to the above ninth aspect, a fourth network node according to the above tenth aspect, a fifth network node according to the above eleventh aspect, and a sixth network node according to the above twelfth aspect.

[0025] With any one of the above first to eighth aspects, the feature subscription-based routing to a target core network can work without any further impact to a network function consumer in the visited network, even if there is no roaming agreement between the visited network and the target network.Brief Description of the Drawings

[0026] These and other objects, features and advantages of the disclosure will become apparent from the following detailed description of illustrative embodiments thereof, which are to be read in connection with the accompanying drawings.

[0027] FIG. 1 is a diagram illustrating the existing network architecture for subscription-based routing to a target core network;

[0028] FIG. 2 is a diagram illustrating control plane and user plane for subscription-based routing to a target core network;

[0029] FIG. 3 is a diagram illustrating a scenario in which subscription-based routing to a target core network could not work;

[0030] FIG. 4 is a diagram illustrating an exemplary communication system into which an embodiment of the disclosure can be applicable;

[0031] FIG. 5 and FIG. 6 are flowcharts each illustrating a process according to an embodiment of the disclosure;

[0032] FIG. 7 to FIG. 9 are flowcharts each illustrating a method performed by a first network node according to an embodiment of the disclosure;

[0033] FIG. 10 is a flowchart illustrating a method performed by a second network node according to an embodiment of the disclosure;

[0034] FIG. 11 and FIG. 12 are flowcharts each illustrating a method performed by a third network node according to an embodiment of the disclosure;

[0035] FIG. 13 to FIG. 15 are flowcharts each illustrating a method performed by a fourth network node according to an embodiment of the disclosure;

[0036] FIG. 16 is a flowchart illustrating a method performed by a fifth network node according to an embodiment of the disclosure;

[0037] FIG. 17 is a flowchart illustrating a method performed by a sixth network node according to an embodiment of the disclosure;

[0038] FIG. 18 is a diagram illustrating an exemplary network architecture according to an embodiment of the disclosure;

[0039] FIG. 19A and FIG. 19B are flowcharts illustrating an exemplary process according to an embodiment of the disclosure; and

[0040] FIG. 20 is a block diagram illustrating an apparatus suitable for use in practicing some embodiments of the disclosure.Detailed Description

[0041] For the purpose of explanation, details are set forth in the following description in order to provide a thorough understanding of the embodiments disclosed. It is apparent, however, to those skilled in the art that the embodiments may be implemented without these specific details or with an equivalent arrangement.

[0042] With respect to the functionality of subscription-based routing to a target core network, the access and mobility management function (AMF) will receive the target public land mobile network (PLMN) information in the session management function (SMF) Selection Subscription Data from the unified data management (UDM) , and use it as Operator Identity in the data network name (DNN) included in the network function (NF) Discovery request to find the SMF for non-roaming scenario or home SMF (H-SMF) for home routed (HR) roaming scenario.

[0043] Chapters 5.3.2.2.2 and 5.3.2.2.3 of 3GPP TS 29.510 V19.2.0 describe the following content on the behavior of network repository function (NRF) . If the NRF supports the “subscription-based routing to a target core network” feature as specified in clause 5.48 of 3GPP TS 23.501 [2] and if it receives a service discovery request for a SMF where the query parameter DNN contains an Operator Identifier set to a PLMN Id other than its PLMN Id, the NRF may further query another appropriate NRF, e.g., a NRF in a target PLMN (identified by the OI) , to discover the SMF (s) in that target PLMN. See also clause 4.17.4 of 3GPP TS 23.502 [3] .

[0044] The network architecture for the subscription-based routing to a target core network will look like as shown in FIG. 1. The visited NRF (V-NRF) interacts with the home NRF (H-NRF) and the H-NRF interacts with the target NRF (T-NRF) . The AMF uses the services provided by the UDM and authentication server function (AUSF) in the target PLMN. Also the visited SMF (V-SMF) uses the services provided by the target SMF (T-SMF) in the Target PLMN. Note that the UDM / AUSF might be located in the home PLMN (HPLMN) .

[0045] The control plane and user plane for this feature will look like as shown in FIG. 2. The V-SMF communicates with the T-SMF via a security edge protection proxy (SEPP) in the visited PLMN (VPLMN) and a SEPP in the target PLMN. Note that there might be a kind of intermediate gateway between the user plane function (UPF) in the VPLMN and the UPF in the target PLMN.

[0046] Source and destination network verification may be performed at a SEPP. TS 33.501 V19.2.0 describes the following content. 5.9.3.2 Requirements for Security Edge Protection Proxy (SEPP) The SEPP shall implement anti-spoofing mechanisms that enable cross-layer validation of source and destination address and identifiers (e.g. FQDNs or PLMN IDs) . NOTE 2: An example for such an anti-spoofing mechanism is the following: If there is a mismatch between different layers of the message or the destination address does not belong to the SEPP’s own PLMN (or SNPN) , the message is discarded. … Sending SEPP behavior for the 3gpp-Sbi-Originating-Network-Id header: - If the sending NF or the SCP has inserted the 3gpp-Sbi-Originating-Network-Id header in the signaling message (service / subscription request or notification message) , the sending SEPP shall compare the PLMN ID or SNPN ID in the 3gpp-Sbi-Originating-Network-Id header in the received signaling message with the PLMN ID (s) or SNPN ID (s) that the sending SEPP represents by its certificate. … Receiving SEPP behavior for the 3gpp-Sbi-Originating-Network-Id header: - The receiving SEPP shall check whether the 3gpp-Sbi-Originating-Network-Id header included in the signalling message belongs to the sending SEPP’s own PLMN or SNPN. It does this by verifying that the asserted PLMN ID in the 3gpp-Sbi-Originating-Network-Id header matches one of the sending SEPP's own PLMN ID (s) or SNPN ID (s) either in the N32-f context, the sending SEPP's certificate, or a locally configured list of PLMN IDs or SNPN-IDs that the sending SEPP represents.

[0047] Serving network name verification may be performed at an AUSF. TS 33.501 V19.2.0 describes the following content. 6.1.2 Initiation of authentication and selection of authentication method Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF shall check that the requesting SEAF in the serving network identified by the 3gpp-Sbi-Originating-Network-Id header specified in TS 29.500

[0074] is entitled to use the serving network name in the Nausf_UEAuthentication_Authenticate Request.

[0048] For some deployments, there is no roaming agreement between the VPLMN and the target PLMN. For such a case, subscription-based routing to a target core network feature does not work.

[0049] For control plane service based interface (SBI) signaling, it needs to go through N32 interface between SEPPs of two PLMNs. Since there is no roaming agreement between the VPLMN and the target PLMN, it is not possible for the SEPP in the VPLMN to establish a N32 interface with the SEPP in the target PLMN. As a result, the SBI signaling from the network function consumer (NFc) (e.g. the V-SMF) in the VPLMN cannot be directly sent to the network function producer (NFp) (e.g. the T-SMF) in the target PLMN.

[0050] Assume that a SEPP in the HPLMN can be used to forward the control plane signaling as shown in FIG. 3. Then, how to select a peer SEPP by the SEPP in the VPLMN is a problem. Since there is no roaming agreement between the VPLMN and the target PLMN, the identity of the target PLMN is not aware by the SEPP in the VPLMN, and thus, it is not possible for the SEPP in the VPLMN to know which peer SEPP should be selected. Similar problem applies to the user plane traffic as well.

[0051] The present disclosure proposes an improved solution for implementing roaming service. Hereinafter, the solution will be described in detail with reference to FIG. 4 to FIG. 20.

[0052] FIG. 4 is a diagram illustrating an exemplary communication system into which an embodiment of the disclosure can be applicable. As shown, the communication system may comprise a user equipment (UE) 401, a (radio) access network ( (R) AN) 402, a user plane function (UPF) 403, a data network (DN) 404, a network slice-specific and SNPN authentication and authorization function (NSSAAF) 405 (where SNPN refers to standalone non-public network) , an authentication server function (AUSF) 406, an access and mobility management function (AMF) 407, a session management function (SMF) 408, a service communication proxy (SCP) 409, a network slice admission control function (NSACF) 410, a network slice selection function (NSSF) 411, a network exposure function (NEF) 412, a network repository function (NRF) 413, a policy control function (PCF) 414, a unified data management (UDM) 415, an application function (AF) 416, and an edge application server discovery function (EASDF) 417. The functional description of the above entities can be found from clause 6 of 3GPP TS 23.501 V19.3.0.

[0053] Within the context of this disclosure, the term UE or terminal device may also be referred to as, for example, device, access terminal, mobile station, mobile unit, subscriber station, or the like. It may refer to any end device that can access a wireless communication network and receive services therefrom. By way of example and not limitation, the UE or terminal device may include a portable computer, an image capture terminal device such as a digital camera, a gaming terminal device, a music storage and playback appliance, a mobile phone, a cellular phone, a smart phone, a tablet, a wearable device, a personal digital assistant (PDA) , or the like.

[0054] In an Internet of things (IoT) scenario, a UE or terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE or terminal device and / or a network equipment. In this case, the UE or terminal device may be a machine-to-machine (M2M) device, which may, in a 3GPP context, be referred to as a machine-type communication (MTC) device. Particular examples of such machines or devices may include sensors, metering devices such as power meters, industrial machineries, bikes, vehicles, or home or personal appliances, e.g. refrigerators, televisions, personal wearables such as watches, and so on.

[0055] As used herein, the term “communication system” refers to a system following any suitable communication standards, such as the first generation (1G) , 2G, 2.5G, 2.75G, 3G, 4G, 4.5G, 5G communication protocols, and / or any other protocols either currently known or to be developed in the future. The specific terms used herein do not limit the present disclosure only to the communication system related to the specific terms, which however can be more generally applied to other communication systems. Note that the network node (or network function) mentioned in this document may be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g. on a cloud infrastructure.

[0056] FIG. 5 is a flowchart illustrating a process according to an embodiment of the disclosure. As shown, the process involves the following entities: a fifth network node in a visited network for a terminal device, a sixth network node implementing a NRF in a home network for the terminal device, a seventh network node implementing a NRF in a target network for the terminal device, and an eighth network node implementing a NRF in the visited network for the terminal device. The terminal device may be in home routed roaming. There may be an agreement between the operator of the home network and the operator of the target network so that for some terminal devices (e.g. those terminal devices whose subscription permanent identifiers (SUPIs) are within a specific SUPI range) , their traffic should be forwarded to the target network. This feature may be referred to as subscription-based routing to a target core network. Suppose this feature is applicable to the terminal device or the terminal device is subscribed to this feature (e.g. the SUPI of the terminal device belongs to the specific SUPI range) . The traffic herein may include signaling and user traffic. The target network for the terminal device may refer to a network to which traffic (e.g. signalling and user traffic) of the terminal device is forwarded. The fifth network node may implement a control plane network function (e.g. an AMF, an SMF, etc. ) in the visited network. For example, the fifth network node may be a network function consumer which needs to use a service provided by a network function producer in the target network. The term “use” here may cover an indirect use case where the network function consumer provides information related to the network function producer to another network node which may then directly use the service provided by the network function producer. The process of FIG. 5 relates to such indirect use case. However, it should be noted that the principle described with respect to FIG. 5 can also be similarly applicable to the direct use case. Also note that only those blocks relevant to the present disclosure are shown in FIG. 5, and some blocks may be omitted so as not to obscure the principle of the present disclosure.

[0057] At block 501, the fifth network node (e.g. an AMF) in the visited network sends, to the eighth network node (e.g. an NRF) in the visited network, a discovery request for discovering a network node (e.g. an SMF) in the home network e.g. for the purpose of protocol data unit (PDU) establishment for the terminal device. The discovery request may comprise a network identifier (ID) identifying the home network, so as to discover a network node (e.g. an SMF) in the home network. Since the terminal device is subscribed to the feature subscription-based routing to a target core network, the discovery request also comprises a data network name (DNN) which contains an operator identity of the target network.

[0058] Based on the network ID identifying the home network, the eighth network node (e.g. an NRF) in the visited network sends, to the sixth network node (e.g. an NRF) in the home network, a further discovery request for discovering the network node (e.g. an SMF) in the home network at block 502. The further discovery request sent at block 502 may be substantially same as the discovery request sent at block 501.

[0059] Since the further discovery request also comprises the DNN which contains the operator identity of the target network, the sixth network node (e.g. an NRF) in the home network sends, to the seventh network node (e.g. an NRF) in the target network, a yet further discovery request for discovering a network node (e.g. an SMF) in the target network at block 503.

[0060] Then, the seventh network node (e.g. an NRF) in the target network sends a discovery response to the sixth network node (e.g. an NRF) in the home network at block 504. The discovery response may comprise an address of the network node (e.g. an SMF) in the target network. The network node (e.g. an SMF) in the target network may also be called a fourth network node hereinafter.

[0061] At block 505, the sixth network node (e.g. an NRF) in the home network determines information for an address of the home network mapped from the address of the fourth network node. The information for the address of the home network mapped from the address of the fourth network node may refer to address information of the home network from which the address of the fourth network node can be derived. For example, the address of the fourth network node may comprise a fully qualified domain name (FQDN) of the fourth network node. The information for the address of the home network may comprise the address (e.g. a domain name) of the home network and information explicitly or implicitly indicating the address (e.g. the FQDN) of the fourth network node. As an exemplary example, The information for the address of the home network may take the form of a concatenation of the information explicitly or implicitly indicating the address (e.g. the FQDN) of the fourth network node and the address (e.g. the domain name) of the home network, which are arranged in this order.

[0062] As a first option, the information explicitly indicates the address (e.g. the FQDN) of the fourth network node. For this option, the address of the fourth network node may be extracted from the information. As a second option, the information implicitly indicating the address of the fourth network node may be an index (or a key) for the address of the fourth network node. For this option, the address of the fourth network node may be stored in a database and be retrieved from the database by using the corresponding index. As a third option, the information implicitly indicating the address of the fourth network node may be information transformed by an algorithm from the address of the fourth network node. For this option, the address of the fourth network node may be transformed back by the algorithm from the information implicitly indicating the address of the fourth network node. For example, Base64 encoding may be performed on the address of the fourth network node to obtain the information implicitly indicating the address of the fourth network node. Then, Base64 decoding may be performed on the information to obtain the address of the fourth network node.

[0063] At block 506, the sixth network node (e.g. an NRF) in the home network sends, to the eighth network node (e.g. an NRF) in the visited network, a further discovery response comprising the information for the address of the home network. At block 507, the eighth network node (e.g. an NRF) in the visited network sends, to the fifth network node (e.g. an AMF) in the visited network, a yet further discovery response comprising the information for the address of the home network. The fifth network node (e.g. an AMF) may then provide the information to a network function consumer (e.g. an SMF ) in the visited network. By using the information for the address of the home network, a signaling message for the terminal device can be sent from the network function consumer (e.g. an SMF) in the visited network to the fourth network node (e.g. an SMF) in the target network, which will be described later with reference to FIG. 6.

[0064] FIG. 6 is a flowchart illustrating a process according to an embodiment of the disclosure. As shown, the process involves the following entities: a first network node implementing a proxy in a home network for a terminal device, a second network node implementing a proxy in a visited network for the terminal device, a third network node implementing a proxy in a target network for the terminal device, a fourth network node in the target network for the terminal device, and a fifth network node in the visited network for the terminal device. As described above with respect to FIG. 5, the terminal device may be in home routed roaming. Suppose the feature subscription-based routing to a target core network is applicable to the terminal device or the terminal device is subscribed to this feature (e.g. the SUPI of the terminal device belongs to the specific SUPI range) . The target network for the terminal device may refer to a network to which traffic (e.g. signalling and user traffic) of the terminal device is forwarded. The proxy may be e.g. a proxy connecting different networks. As an exemplary example, the proxy may be a SEPP. The fourth network node may implement a control plane network function (e.g. an SMF, an AUSF, etc. ) in the target network. For example, the fourth network node may be a network function producer. As described above, the fifth network node may implement a control plane network function (e.g. an AMF, an SMF, etc. ) in the visited network. For example, the fifth network node may be a network function consumer. Note that only those blocks relevant to the present disclosure are shown in FIG. 6, and some blocks may be omitted so as not to obscure the principle of the present disclosure.

[0065] At block 601, the fifth network node (e.g. an SMF) in the visited network sends, to the second network node (e.g. a proxy such as a SEPP) in the visited network, a fourth message related to the terminal device, e.g. for the purpose of PDU session establishment. The fourth message comprises the information for the address of the home network which is mapped from an address of the fourth network node in the target network for the terminal device. The information for the address of the home network has been described above with respect to block 505 of FIG. 5 and can be received from e.g. an AMF in the visited network as described above.

[0066] As an exemplary example, the fifth network node (e.g. an SMF) in the visited network may receive, from an AMF in the visited network, a request message for creating a session management (SM) context for the terminal device, e.g. a Nsmf_PDUSession_CreateSMContext request. The request message comprises the information for the address of the home network. Since the information for the address of the home network is essentially an address information of the home network, the fifth network node (e.g. an SMF) can correctly interpret this information as normal. Based on this information, the fifth network node (e.g. an SMF) in the visited network may determine that the fourth message (which may be a request message for establishment of a PDU session in this case, e.g. a Nsmf_PDUSession_Create request) needs to be firstly sent to the second network node (e.g. a proxy such as a SEPP) in the visited network. Note that this determination can also be made based on a PLMN ID in the SUPI of the terminal device. Then, the fourth message is sent at block 601. The information for the address of the home network may be contained in the message body of the fourth message in an information element (IE) (e.g. “hSmfUri” IE defined in TS 29.502 V19.2.0, clause 6.1.6.2.2) identifying a SMF in the home network. The information for the address of the home network may also be contained in a message header (e.g. a custom header such as 3gpp-Sbi-target-ApiRoot header) of the fourth message.

[0067] At block 602, the second network node (e.g. a proxy such as a SEPP) in the visited network sends, to the first network node (e.g. a proxy such as a SEPP) in the home network, a first message related to the terminal device. The first message comprises the information for the address of the home network mapped from the address of the fourth network node in the target network for the terminal device. The first message may comprise a message body eof the fourth message.

[0068] As an option, the message body may be reformatted. For the example of SEPP, according to technical specification (TS) 29.573 V19.3.0, the N32-f interface may be used between two SEPPs for forwarding of JavaScript Object Notation (JSON) Object Signing and Encryption (JOSE) protected HTTP / 2 messages between a NF service consumer and a NF service producer across two PLMNs, when PRotocol for N32 INterconnect Security (PRINS) is the negotiated security policy. The message forwarding on N32-f shall be based on the negotiated security capability and the exchanged security parameters between the two SEPPs. A SEPP on the sending side PLMN may apply message reformatting in the following cases: 1) when it receives a HTTP / 2 request message from an NF service consumer to a an NF service producer in another PLMN; 2) when it receives a response HTTP / 2 response message from an NF service producer to an NF service consumer in another PLMN; 3) when it receives a HTTP / 2 notification request message from an NF service producer to an NF service consumer in another PLMN; 4) when it receives a HTTP / 2 notification response message from an NF service consumer to an NF service producer in another PLMN. The SEPP shall reformat the HTTP / 2 message by encapsulating the whole message into the body of a new HTTP POST message. The body of the HTTP POST request / response message shall contain the reformatted original HTTP / 2 request / response message respectively. The HTTP POST request / response body shall be encoded as the “N32fReformattedReqMsg”  / ” N32fReformattedRspMsg” JSON bodies respectively, as specified in clause 6.2.5 of TS 29.573 V19.3.0 .

[0069] As another option, the message body may be unreformatted. For the example of SEPP, according to TS 29.573 V19.3.0, the N32-f interface may also be used between two SEPPs for forwarding of HTTP / 2 messages between a NF service consumer and a NF service producer without any reformatting and application layer protection, when Transport Layer Security (TLS) is the negotiated security policy.

[0070] For both the above options, the message bodies of the two messages can achieve the same basic function. For instance, for the example of Nsmf_PDUSession_Create request, the message bodies of the fourth message and the first message can achieve the same basic function of requesting establishment of a PDU session. It is possible that certain attribute (s) in the message bodies of the two messages may be different due to certain minor purpose. For example, the attribute vsmfPduSessionUri attribute in the message body of the fourth message (e.g. Nsmf_PDUSession_Create request) may be updated by the second network node to conceal internal network topology so that this attribute is different between the two messages.

[0071] In the above exemplary example of Nsmf_PDUSession_Create request, since the information for the address of the home network (which may be contained in the message header of the fourth message) is essentially an address information of the home network, the second network node (e.g. a proxy such as a SEPP) can correctly interpret this information as normal. Based on this information, the second network node (e.g. a proxy such as a SEPP) in the visited network can determine that the fourth message needs to be forwarded to the first network node (e.g. a proxy such as a SEPP) in the home network. The address of the first network node (e.g. a proxy such as a SEPP) in the home network may be obtained by performing domain name system (DNS) query by using e.g. the domain name of the home network. Note that the address of the first network node can also be obtained from a local configuration at the second network node.

[0072] As an example, supppose the information for the address of the home network is inst1. smf. 5gc. mnc456. mcc123.3gppnetwork. org. 5gc. mnc789. mcc123.3gppnetwork. org, where inst1. smf. 5gc. mnc456. mcc123.3gppnetwork. org is the FQDN of the fourth network node (e.g. an SMF) and 5gc. mnc789. mcc123.3gppnetwork. org is the domain name of the home network. As another example, suppose the information for the address of the home network is 1126374. forwarding. 5gc. mnc789. mcc123.3gppnetwork. org, where 1126374 is a key stored in a database which corresponds to inst1. smf. 5gc. mnc456. mcc123.3gppnetwork. org, and the “forwarding” is a mark indicating that it is a forwarding scenario. In both examples, according to the latter 5gc. mnc789. mcc123.3gppnetwork. org, the second network node (e.g. a proxy such as a SEPP) in the visited network can know that the first network node (e.g. a proxy such as a SEPP) in the home network has a mobile network code (MNC) of 789 and a mobile country code (MCC) of 123, and thus, can obtain the address thereof.

[0073] Then, a connection between e.g. N32 interfaces of the second network node and the first network node may be established to send the first message at block 602. The information for the address of the home network may be contained in a message header (e.g. a custom header such as 3gpp-Sbi-target-ApiRoot header) of the first message.

[0074] After receiving the first message, the first network node may derive, from the information for the address of the home network, the address of the fourth network node. Then, the first network node may include the address of the fourth network node in a second message used for forwarding the first message. As described above, the information for the address of the home network may comprise the address (e.g. a domain name) of the home network and information explicitly or implicitly indicating the address (e.g. the FQDN) of the fourth network node. To derive the address of the fourth network node, the first network node may remove, from the information for the address of the home network, the address (e.g. the domain name) of the home network. The first network node may then determine the address of the fourth network node based on a remaining portion of the information for the address of the home network.

[0075] In the case of the information explicitly indicating the address (e.g. the FQDN) of the fourth network node, the first nework node may determine, as the address of the fourth network node, the remaining portion of the information for the address of the home network. In the case of the information implicitly indicating the address (e.g. the FQDN) of the fourth network node, as an option, the first network node may retrieve, from a database, the address of the fourth network node which corresponds to the remaining portion of the information for the address of the home network. Alternatively, as another option, the first network node may transform the remaining portion of the information for the address of the home network to the address of the fourth network node. This can be done by using the algorithm mentioned above.

[0076] Then, the first network node (e.g. a proxy such as a SEPP) in the home network sends a second message to the third network node (e.g. a proxy such as a SEPP) in the target network at block 603. The second message may comprise the message body of the first message. The message body may be reformatted or unreformatted, as described above.

[0077] In the above exemplary example of Nsmf_PDUSession_Create request, suppose the information for the address of the home network is inst1. smf. 5gc. mnc456. mcc123.3gppnetwork. org. 5gc. mnc789. mcc123.3gppnetwork. org or 1126374. forwarding. 5gc. mnc789. mcc123. 3gppnetwork. org. Then, according to the fact that there are two domain names in the information or according to the mark “forwarding” in the information, the first network node (e.g. a proxy such as a SEPP) in the home network can know it is a forwarding scenario (i.e. the first message needs to be forwarded to the third network node (e.g. a proxy such as a SEPP) in the target network) . Consequently, the first network node may remove the domain name of the home network (5gc. mnc789. mcc123.3gppnetwork. org) to either directly get the FQDN of the fourth network node (e.g. an SMF) in the target network or retrieve it from the database by using the key “1126374” . The address of the third network node (e.g. a proxy such as a SEPP) in the target network may be obtained by performing DNS query by using e.g. the domain name of the target network which is contained in the FQDN of the fourth network node. Note that the address of the third network node can also be obtained from a local configuration at the first network node. Then, a connection between e.g. N32 interfaces of the first network node and the third network node may be established to send the second message at block 603. The address of the fourth network node may be contained in a message header (e.g. a custom header such as 3gpp-Sbi-target-ApiRoot header) of the second message.

[0078] Optionally, the second message may comprise one or more of: an ID identifying a network for forwarding traffic of the terminal device; and at least one indicator indicating a purpose for which the second message is sent. The ID identifying the network for forwarding traffic of the terminal device may also be called a forwarding network ID or any other suitable name having similar meaning. The at least one indicator may comprise one or more of: a first indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network; and a second indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network and only for a test. The first indicator may have a name “RVAS_FORWARD” or any other suitable name having similar meaning. The second indicator may have a name “RVAS_FORWARD_TEST” or any other suitable name having similar meaning. The ID and / or the at least one indicator may be contained in the message header of the second message.

[0079] Then, at block 604, the third network node (e.g. a proxy such as a SEPP) in the target network sends a third message to the fourth network node (e.g. an SMF) in the target network, based on the address of the fourth network node. The third message may comprise a message body of the second message. The message body may be reformatted or unreformatted, as described above. Third message may comprise an ID identifying a network for forwarding traffic of the terminal device; and / or at least one indicator indicating a purpose for which the third message is sent. The ID identifying the network for forwarding traffic of the terminal device may be the forwarding network ID as mentioned above. The at least one indicator may comprise one or more of: a first indicator indicating that the third message is sent for forwarding traffic of the terminal device to the target network; and a second indicator indicating that the third message is sent for forwarding traffic of the terminal device to the target network and only for a test. The ID and / or the at least one indicator may be contained in the message header of the third message.

[0080] Optionally, after receiving the second message, the third network node may verify whether the ID in the second message identifying a network for forwarding traffic of the terminal device matches an ID identifying a network supported by the first network node. The ID identifying the network for forwarding traffic of the terminal device may be the forwarding network ID as mentioned above. The ID identifying a network supported by the first network node (e.g. a proxy such as a SEPP) may comprise, but not limited to, the first network node’s PLMN ID (s) or SNPN ID (s) either in N32-f context, the first network node’s certificate, or a locally configured list of PLMN IDs or SNPN-IDs that the first network node represents. It may be obtained by the third network node when a N32 connection is established between the third network node and the first network node. The third message may be sent at block 604 when the verification is successful.

[0081] Optionally, after receiving the third message, the fourth network node may perform authorization on the third message based on the ID in the third message identifying a network for forwarding traffic of the terminal device. The authorization may be performed based on an authorization policy which may be a local configuration at the fourth network node. The authorization policy may comprise a list of network IDs allowed or authorized for the fourth network node. Then, the authorization may be performed by checking whether the ID identifying the network for forwarding traffic of the terminal device is in the list of network IDs allowed or authorized for the fourth network node. The fourth network node may perform further operations when the authorization is successful. Alternatively or additionally, the fourth network node may verify whether an ID in a message header of the third message identifying a visited network for the terminal device matches an ID in a message body of the third message identifying a network serving the terminal device. The ID identifying a visited network for the terminal device may be e.g. the 3gpp-Sbi-Originating-Network-Id. The ID identifying a network serving the terminal device may be e.g. the serving network name defined in TS 33.501 V19.2.0. The fourth network node may perform further operations when either one or both of the authorization and the verification is successful.

[0082] With the process of FIG. 6, the feature subscription-based routing to a target core network can work without any further impact to a network function consumer in the visited network, even if there is no roaming agreement between the visited network and the target network.

[0083] FIG. 7 is a flowchart illustrating a method performed by a first network node according to an embodiment of the disclosure. The first network node may implement a proxy in a home network for a terminal device. The proxy may be a proxy connecting different networks, such as a SEPP. At block 702, the first network node receives, from a second network node implementing a proxy in a visited network for the terminal device, a first message related to the terminal device. The first message comprises information for an address of the home network mapped from an address of a fourth network node in a target network for the terminal device. For example, the address of the fourth network node may comprise a FQDN of the fourth network node. The information for the address of the home network may comprise a domain name of the home network and information explicitly or implicitly indicating the FQDN of the fourth network node. The fourth network node may implement a control plane network function in the target network.

[0084] At block 704, the first network node sends a second message to a third network node implementing a proxy in the target network, based on the information for the address of the home network. The second message may comprise a message body of the first message and the message body may be reformatted or unreformatted. For example, each of the first message and the second message may be a hypertext transfer protocol (HTTP) request message. The HTTP request message may conform to HTTP2 protocol, or HTTP3 / QuickUDPInternet Connections (QUIC) protocol. The information for the address of the home network may be contained in a custom header of the HTTP request message. With the method of FIG. 7, the same effect as the process of FIG. 6 can be achieved.

[0085] Optionally, the second message may comprise one or more of: an ID identifying a network for forwarding traffic of the terminal device; and at least one indicator indicating a purpose for which the second message is sent. The at least one indicator may comprise one or more of: a first indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network; and a second indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network and only for a test.

[0086] FIG. 8 is a flowchart illustrating a method performed by a first network node according to an embodiment of the disclosure. The first network node may implement a proxy in a home network for a terminal device. The proxy may be a proxy connecting different networks, such as a SEPP. At block 702, the first network node receives, from a second network node implementing a proxy in a visited network for the terminal device, a first message related to the terminal device. The first message comprises information for an address of the home network mapped from an address of a fourth network node in a target network for the terminal device. At block 806, after receiving the first message, the first network node derives, from the information for the address of the home network, the address of the fourth network node. For example, block 806 may be implemented as blocks 910 and 912 of FIG. 9. At block 910, the first network node removes, from the information for the address of the home network, the address of the home network. At block 912, the first network node determines the address of the fourth network node based on a remaining portion of the information for the address of the home network. For example, block 912 may be implemented as any one of blocks 9122-9126 of FIG. 9. At block 9122, the first network node determines, as the address of the fourth network node, the remaining portion of the information for the address of the home network. At block 9124, the first network node retrieves, from a database, the address of the fourth network node which corresponds to the remaining portion of the information for the address of the home network. At block 9126, the first network node transforms the remaining portion of the information for the address of the home network to the address of the fourth network node. At block 806, the first network node includes, in the second message, the address of the fourth network node. At block 704, the first network node sends a second message to a third network node implementing a proxy in the target network, based on the information for the address of the home network. The second message may comprise a message body of the first message and the message body may be reformatted or unreformatted.

[0087] FIG. 10 is a flowchart illustrating a method performed by a second network node according to an embodiment of the disclosure. The second network node may implement a proxy in a visited network for a terminal device. At block 1002, the second network node receives, from a fifth network node in the visited network, a fourth message related to the terminal device. The fourth message comprises information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device. The fourth network node may implement a control plane network function in the target network. The fifth network node may implement a control plane network function in the visited network. At block 1004, the second network node sends a first message to a first network node implementing a proxy in the home network, based on the information for the address of the home network. The first message may comprise a message body of the fourth message and the message body may be reformatted or unreformatted. Each of the fourth message and the first message may be a HTTP request message. The information for the address of the home network may be contained in a custom header of the HTTP request message. With the method of FIG. 10, the same effect as the process of FIG. 6 can be achieved.

[0088] FIG. 11 is a flowchart illustrating a method performed by a third network node according to an embodiment of the disclosure. The third network node may implement a proxy in a target network for a terminal device. At block 1102, the third network node receives, from a first network node implementing a proxy in a home network for the terminal device, a second message related to the terminal device. The second message comprises an address of a fourth network node in the target network. The fourth network node may implement a control plane network function in the target network. At block 1104, the third network node sends a third message to the fourth network node, based on the address of the fourth network node. The third message may comprise a message body of the second message and the message body may be reformatted or unreformatted. Each of the second message and the third message may be a HTTP request message. The address of the fourth network node may be contained in a custom header of the HTTP request message. With the method of FIG. 11, the same effect as the process of FIG. 6 can be achieved.

[0089] FIG. 12 is a flowchart illustrating a method performed by a third network node according to an embodiment of the disclosure. The third network node may implement a proxy in a target network for a terminal device. At block 1102, the third network node receives, from a first network node implementing a proxy in a home network for the terminal device, a second message related to the terminal device. The second message comprises an address of a fourth network node in the target network. At block 1206, after receiving the second message, the third network node verifies whether the ID in the second message identifying a network for forwarding traffic of the terminal device matches an ID identifying a network supported by the first network node. At block 1104, when the verification is successful, the third network node sends, to the fourth network node, a third message comprising a same message body as a message body of the second message, based on the address of the fourth network node.

[0090] FIG. 13 is a flowchart illustrating a method performed by a fourth network node in a target network for a terminal device according to an embodiment of the disclosure. The fourth network node may implement a control plane network function in the target network. At block 1302, the fourth network node receives, from a third network node implementing a proxy in the target network, a third message related to the terminal device. With the method of FIG. 13, the same effect as the process of FIG. 6 can be achieved.

[0091] FIG. 14 is a flowchart illustrating a method performed by a fourth network node in a target network for a terminal device according to an embodiment of the disclosure. The fourth network node may implement a control plane network function in the target network. At block 1302, the fourth network node receives, from a third network node implementing a proxy in the target network, a third message related to the terminal device. The third message may be a HTTP request message. At block 1404, after receiving the third message, the fourth network node performs authorization on the third message based on an ID in the third message identifying a network for forwarding traffic of the terminal device. The fourth network node may perform further operations when the authorization is successful.

[0092] FIG. 15 is a flowchart illustrating a method performed by a fourth network node in a target network for a terminal device according to an embodiment of the disclosure. The fourth network node may implement a SMF in the target network. At block 1508, the fourth network node sends, to a UPF in the target network, a first request for establishing a PDU session for the terminal device. At block 1510, the fourth network node receives, from the UPF in the target network, a first response to the first request. The first response comprises tunnel information of a general packet radio service (GPRS) tunneling protocol (GTP) proxy. The GTP proxy is used for forwarding traffic of the terminal device between the UPF in the target network and a UPF in a visited network for the terminal device. At block 1512, the fourth network node sends the tunnel information of the GTP proxy to the UPF in the visited network via a SMF in the visited network. With the method of FIG. 15, the same effect as the process of FIG. 6 can be achieved for user traffic of the terminal device.

[0093] FIG. 16 is a flowchart illustrating a method performed by a fifth network node in a visited network for a terminal device according to an embodiment of the disclosure. The fifth network node may implement a control plane network function in the visited network. At block 1602, the fifth network node sends, to a second network node implementing a proxy in the visited network, a fourth message related to the terminal device. The fourth message comprises information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device. The fourth network node may implement a control plane network function in the target network. The fourth message may be a HTTP request message. The information for the address of the home network may be contained in a custom header of the HTTP request message. With the method of FIG. 16, the same effect as the process of FIG. 6 can be achieved.

[0094] FIG. 17 is a flowchart illustrating a method performed by a sixth network node according to an embodiment of the disclosure. The sixth network node may implement a NRF in a home network for a terminal device. At block 1702, the sixth network node receives, from a seventh network node implementing a NRF in a target network for the terminal device, an address of a fourth network node in the target network. The fourth network node may implement a control plane network function in the target network. At block 1704, the sixth network node determines information for an address of the home network mapped from the address of the fourth network node. At block 1706, the sixth network node sends the information for the address of the home network to an eighth network node implementing a NRF in a visited network for the terminal device. With the method of FIG. 17, the same effect as the process of FIG. 6 can be achieved.

[0095] FIG. 18 is a diagram illustrating an exemplary network architecture according to an embodiment of the disclosure. As shown, the SEPP in the HPLMN is introduced to forward the control plane signaling. The signaling from the NFc in the VPLMN can be sent to the SEPP in the HPLMN indicated by a mapped HPLMN FQDN. This FQDN has two purposes. One is for the SEPP in the VPLMN to find the peer SEPP (i.e. the SEPP in the HPLMN) . Another is for the SEPP in the HPLMN to find the SEPP in the target PLMN. This FQDN may be provided by the NRF in the HPLMN based on the NFProfile of NFp returned by the NRF in the target PLMN in the Inter PLMN Discovery procedure.

[0096] The mapped HPLMN FQDN might be in the following format: <Label representing FQDN from target PLMN>. <Home Domain Name of Home PLMN>. The Label representing FQDN from target PLMN can be the one (i.e. interPlmnFqdn) registered by the NFp into the NRF in the target PLMN. For example, if the interPlmnFqdn of NFp in the target PLMN is inst1. smf. 5gc. mnc456. mcc123.3gppnetwork. org, and the Home Domain Name of Home PLMN is 5gc. mnc789. mcc123.3gppnetwork. org, then the mapped HPLMN will be inst1. smf. 5gc. mnc456. mcc123.3gppnetwork. org. 5gc. mnc789. mcc123.3gppnetwork. org. Note that the label representing FQDN from target PLMN might be restructured into another format algorithmically or stored outside (e.g. in a database) for the SEPP in the HPLMN to easily identity and forward the request.

[0097] When the SEPP in the HPLMN receives the request originally from the NFc in the VPLMN, it will forward it to the SEPP in the target PLMN based on the FQDN above. Additionally, the SEPP in the HPLMN may include a new 3gpp customer header that identifies forwarding network (i.e., HPLMN PLMN ID or SNPN ID) , and / or a new N32 purpose that indicates the network forwarding scenario. Note that in the present disclosure, the “forwarding network” can also be named as “relaying network” or “intermediate network” , i.e., an intermediate network in the communication path that forwards or relays or re-directs the signaling message towards the target network. To simplify the description, the terms of “forwarding network” , “3gpp-Sbi-Forward-Network-Id” and “RVAS_FORWARD” are used as exemplary examples.

[0098] In addition, a GTP Proxy is introduced in the HPLMN for the User Plane. The tunnel information of this GTP proxy will be provided by the T-SMF in the target PLMN (e.g. based on the local configuration) to the V-SMF in the VPLMN.

[0099] FIG. 19A and FIG. 19B are flowcharts illustrating an exemplary process according to an embodiment of the disclosure. The process relates to a PDU Session Establishment procedure. As shown, the process involves the following entities: a UE, an AMF, a SMF, a NRF, a UPF and a SEPP in a VPLMN; a SEPP, a NRF and a GTP proxy in a HPLMN; and a SEPP, a NRF, a UPF and a H-SMF in a target PLMN. Note that the H-SMF refers to a home SMF in the target PLMN, but does not refer to a SMF in the HPLMN. Thus, the H-SMF may also be referred to as a T-SMF. Although only the PDU Session Establishment procedure is described, it should be noted that the principle of the present disclosure could be applied to other procedures as well.

[0100] At step 1, the UE registers to the 5th generation (5G) system (5GS) from the VPLMN, and the target PLMN information is included in the SmfSelectionSubscriptionData from the UDM. Then, a PDU Session Establishment procedure is triggered by the UE. At step 2, the UE sends a PDU Session Establishment request to the AMF. At step 3, the AMF performs the V-SMF discovery and selection. At step 4, the AMF also performs the H-SMF Discovery and Selection. Specifically, the AMF sends a Nnrf_NFDiscovery_Request request to the NRF in the VPLMN, which includes the target PLMN (i.e. HPLMN ID) , DNN, and other information. At step 5, the NRF in the VPLMN derives NRF in the Home PLMN based on the target PLMN information in the Discovery request, and forwards the request to the NRF in the HPLMN. At step 6, the NRF in the HPLMN finds the Operator Identity of DNN is another PLMN, so the NRF forwards this request to the NRF in the target PLMN, as described in TS 29.510 V19.2.0. At step 7, the NRF in the target PLMN returns the H-SMF profile to the NRF in the HPLMN.

[0101] At step 8, the NRF in the HPLMN maps the FQDN of H-SMF into a HPMN specified FQDN. The format might be like <Label representing FQDN from target PLMN>. <Home Domain Name of Home PLMN>. At step 9, the NRF in the HPLMN forwards the response to the NRF in the VPLMN. At step 10, the NRF in the VPLMN forwards the response to the AMF.

[0102] At step 11, the AMF sends a Nsmf_PDUSession_CreateSMContext request to the V-SMF (i.e. the SMF in the VPLMN) selected in the Step 3, by including the H-SMF (i.e. the SMF in the target PLMN) information. At step 12, steps 3b-5b of Figure 4.3.2.2.2-1 in TS 23.502 V19.3.0 are performed. At step 13, the V-SMF sends a Nsmf_PDUSession_Create request to the H-SMF. The V-SMF will include the mapped HPLMN FQDN of H-SMF to the SEPP in the VPLMN. Note that some legacy headers (e.g. 3gpp-Sbi-Originating-Network-Id) might be included as well. At step 14, the SEPP in the HPLMN verifies the request. Note that the SEPP instance receiving the request from the VPLMN and the SEPP instance forwarding the request to the NFp in the target PLMN might be the same instance, or different instance. If verification is successful, the SEPP in the HPLMN forwards the request to the SEPP in the target PLMN based on the unmapped FQDN of H-SMF at step 15. It may additionally include the 3gpp-Sbi-Forward-Network-Id header, and update the 3gpp-Sbi-target-ApiRoot header by using the original FQDN of H-SMF.

[0103] At step 16, the SEPP in the Target PLMN verifies the request (e.g. source and forwarding network verification) . For source and forwarding network verification at receiving SEPP in the target PLMN, if the 3gpp-Sbi-Interplmn-Purpose and / or 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers are presented in the signaling message, and if the value of 3gpp-Sbi-Interplmn-Purpose header equals to “RVAS_FORWARD” or “RVAS_FORWARD_TEST” , optionally based on local configured policy, the receiving SEPP may check whether the 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers included in the signaling message belong to the sending SEPP’s own PLMN or SNPN. The receiving SEPP does the source and forwarding network ID matching check by verifying that the asserted PLMN ID (s) or SNPN ID (s) in the 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers match one of the sending SEPP’s own PLMN ID (s) or SNPN ID (s) either in the N32-f context, the sending SEPP’s certificate, or a locally configured list of PLMN IDs or SNPN-IDs that the peer sending SEPP represents. If verification is successful, the SEPP in the target PLMN forwards the request to the H-SMF at step 17.

[0104] At step 18, steps 7-11 of Figure 4.3.2.2.2-1 in TS 23.502 V19.3.0 are performed. At step 19, the H-SMF sends a N4 PDU Session Establishment Request to the UPF in the target PLMN. At step 20, the UPF in the target PLMN creates a GTP Tunnel for this PDU Session. At step 21, the UPF in the target PLMN sends a N4 PDU Session Establishment Response with the tunnel information allocated by the GTP Proxy. This tunnel information will be sent to the UPF in the VPLMN via the H-SMF and the V-SMF. At step 22, steps 12c-24 of Figure 4.3.2.2.2-1 in TS 23.502 V19.3.0 are performed. Note that the control plane signaling from the H-SMF to the V-SMF can utilize the new customer header as well for the security.

[0105] [Rectified under Rule 91, 03.02.2026]In the process of FIG. 19A and FIG. 19B, if a NF consumer in the VPLMN wants to use a service provided by a NF producer in the target PLMN, the NF consumer sends a discovery request to the NRF in the VPLMN. Then, the NRF in the VPLMN sends a further discovery request to the NRF in the HPLMN. Then, the NRF in the HPLMN sends a yet further discovery request to the NRF in the target PLMN. When the NRF in the target PLMN discovers the desired NF producer, the NRF in the target PLMN returns a NF profile including the FQDN of the desired NF producer to the NRF in the HPLMN. Then the NRF in the HPLMN maps the FQDN of the desired NF producer to the domain name of the HPLMN and returns the mapped domain name of the HPLMN to the NF consumer via the NRF in the VPLMN.

[0106] When the NF consumer requests the service from the NF producer, the mapped domain name of the HPLMN may be contained in the request to be sent to the SEPP in the VPLMN. The SEPP in the VPLMN may obtain the domain name of the HPLMN as normal and forward the request to the SEPP in the HPLMN. Then the SEPP in the HPLMN may recover the FQDN of the desired NF producer from the mapped domain name of the HPLMN and forward the request to the desired NF producer in the target PLMN.

[0107] [Rectified under Rule 91, 03.02.2026]With the process of FIG. 19A and FIG. 19B, the feature subscription-based routing to a target core network can work completely for the control plane signaling and without any further impact to the NFc in the VPLMN, and user plane as well.

[0108] Based on the above description, updates may be proposed to be introduced in the corresponding technical specifications. As an example, a new 3gpp customer header indicating the PLMN forwarding the HTTP request may be proposed to be introduced into TS 29.500 V19.3.0 as shown below, where the newly added contents relative to TS 29.500 V19.3.0 are highlighted with underlines. 5.2.3.3.1 General 5.2.3.2. x 3gpp-Sbi-Forward-Network-Id The header contains the PLMN Identity (MCC-MNC) of the PLMN or the SNPN ID (MCC-MNC-NID) of the source SNPN to forward the received HTTP messages. The encoding of the header follows the ABNF as defined in IETF RFC 9110

[0011] . Sbi-Forward-Network-Id-Header = "3gpp-Sbi-Forward-Network-Id: " OWS 3DIGIT "-" 2*3DIGIT [ "-" 11HEXDIG ]

[0109] Alternatively or additionally, a corresponding new value may be proposed to be introduced in the 3gpp-Sbi-Interplmn-Purpose TS 29.500 V19.3.0 to indicate the purpose of this message, where the newly added contents relative to TS 29.500 V19.3.0 are highlighted with underlines. 5.2.3.3.11 3gpp-Sbi-Interplmn-Purpose

[0110] In addition, with respect to source and forwarding network verification at receiving SEPP: if the 3gpp-Sbi-Interplmn-Purpose and / or 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers are presented in the signaling message, and if the value of 3gpp-Sbi-Interplmn-Purpose header equals to "RVAS_FORWARD" or "RVAS_FORWARD_TEST" , maybe based on local configured policy, the receiving SEPP may check whether the 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers included in the signaling message belongs to the sending SEPP’s own PLMN or SNPN. The receiving SEPP does the source and forwarding network ID matching check by verifying that the asserted PLMN ID (s) or SNPN ID (s) in the 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers match one of the sending SEPP's own PLMN ID (s) or SNPN ID (s) either in the N32-f context, the sending SEPP's certificate, or a locally configured list of PLMN IDs or SNPN-IDs that the sending SEPP represents.

[0111] With respect to source network verification at NFp, if the 3gpp-Sbi-Interplmn-Purpose and / or 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers are presented in the signaling message, and if the value of 3gpp-Sbi-Interplmn-Purpose header equals to "RVAS_FORWARD" or "RVAS_FORWARD_TEST" , the NFp in the target network may perform the source network verification and authorization based on 3gpp-Sbi-Originating-Network-Id and / or 3gpp-Sbi-Forward-Network-Id headers.

[0112] FIG. 20 is a block diagram illustrating an apparatus suitable for use in practicing some embodiments of the disclosure. For example, any one of the first network node to the sixth network node described above may be implemented through the apparatus 2000. As shown, the apparatus 2000 may include processing circuitry 2010 and a memory 2020. The processing circuitry 2010 may be configured to operate in accordance with the embodiments of the present disclosure, as discussed above. The processing circuitry 2010 may include a processor and / or integrated circuitry for processing and / or control. The processor may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multi-core processor architectures, as non-limiting examples. The integrated circuitry may include, but not limited to, field programmable gate array (FPGA) , application specific integrated circuitry (ASIC) , etc.

[0113] The memory 2020 may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, flash memories, magnetic memory devices and systems, optical memory devices and systems, fixed memories and removable memories. The memory 2020 may be configured to store data, instructions and / or other information described herein. In some embodiments, the instructions are executable by the processor, whereby the apparatus 2000 is operative to or configured to operate in accordance with the embodiments of the present disclosure, as discussed above. That is, the embodiments of the present disclosure may be implemented at least in part by computer program executable by the processor, or by hardware, or by a combination of computer program and hardware.

[0114] As such, it should be appreciated that at least some aspects of the exemplary embodiments of the disclosure may be practiced in various components such as integrated circuit chips and modules. It should thus be appreciated that the exemplary embodiments of this disclosure may be realized in an apparatus that is embodied as an integrated circuit, where the integrated circuit may comprise circuitry (as well as possibly firmware) for embodying at least one or more of a data processor, a digital signal processor, baseband circuitry and radio frequency circuitry that are configurable so as to operate in accordance with the exemplary embodiments of this disclosure.

[0115] It should be appreciated that at least some aspects of the exemplary embodiments of the disclosure may be embodied in computer-executable instructions, such as in one or more program modules, executed by one or more computers or other devices. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types when executed by a processor in a computer or other device. The computer executable instructions may be stored on a computer readable medium such as a hard disk, optical disk, removable storage media, solid state memory, RAM, etc. As will be appreciated by one skilled in the art, the function of the program modules may be combined or distributed as desired in various embodiments. In addition, the function may be embodied in whole or in part in firmware or hardware equivalents such as integrated circuits, field programmable gate arrays (FPGA) , and the like.

[0116] References in the present disclosure to “one embodiment” , “an embodiment” and so on, indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to implement such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0117] It should be understood that, although the terms “first” , “second” and so on may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of the disclosure. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.

[0118] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the present disclosure. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components, but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof. The terms “connect” , “connects” , “connecting” and / or “connected” used herein cover the direct and / or indirect connection between two elements. It should be noted that two blocks shown in succession in the above figures may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved.

[0119] The present disclosure includes any novel feature or combination of features disclosed herein either explicitly or any generalization thereof. Various modifications and adaptations to the foregoing exemplary embodiments of this disclosure may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings. However, any and all modifications will still fall within the scope of the non-Limiting and exemplary embodiments of this disclosure.

Claims

1.A method at a first network node implementing a proxy in a home network for a terminal device, comprising:receiving (702) , from a second network node implementing a proxy in a visited network for the terminal device, a first message related to the terminal device, wherein the first message comprises information for an address of the home network mapped from an address of a fourth network node in a target network for the terminal device; andsending (704) a second message to a third network node implementing a proxy in the target network, based on the information for the address of the home network.2.The method according to claim 1, wherein the second message comprises a message body of the first message and the message body is reformatted or unreformatted.3.The method according to claim 1 or 2, after receiving (702) the first message, further comprising:deriving (806) , from the information for the address of the home network, the address of the fourth network node; andincluding (808) , in the second message, the address of the fourth network node.4.The method according to claim 3, wherein deriving (806) the address of the fourth network node comprises:removing (910) , from the information for the address of the home network, the address of the home network; anddetermining (912) the address of the fourth network node based on a remaining portion of the information for the address of the home network.5.The method according to claim 4, wherein determining (912) the address of the fourth network node based on a remaining portion of the information for the address of the home network comprises one of:determining (9122) , as the address of the fourth network node, the remaining portion of the information for the address of the home network;retrieving (9124) , from a database, the address of the fourth network node which corresponds to the remaining portion of the information for the address of the home network; andtransforming (9126) the remaining portion of the information for the address of the home network to the address of the fourth network node.6.The method according to any of claims 1 to 5, wherein the second message comprises one or more of:an identifier, ID, identifying a network for forwarding traffic of the terminal device; andat least one indicator indicating a purpose for which the second message is sent.7.The method according to claim 6, wherein the at least one indicator comprises one or more of:a first indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network; anda second indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network and only for a test.8.The method according to any of claims 1 to 7, wherein the address of the fourth network node comprises a fully qualified domain name, FQDN, of the fourth network node; and / orwherein the information for the address of the home network comprises a domain name of the home network and information explicitly or implicitly indicating the FQDN of the fourth network node.9.The method according to any of claims 1 to 8, wherein each of the first message and the second message is a hypertext transfer protocol, HTTP, request message.10.The method according to claim 9, wherein the information for the address of the home network is contained in a custom header of the HTTP request message.11.The method according to any of claims 1 to 10, wherein the proxy is a proxy connecting different networks.12.The method according to any of claims 1 to 11, wherein the fourth network node implements a control plane network function in the target network.13.A method at a second network node implementing a proxy in a visited network for a terminal device, the method comprising:receiving (1002) , from a fifth network node in the visited network, a fourth message related to the terminal device, wherein the fourth message comprises information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device; andsending (1004) a first message to a first network node implementing a proxy in the home network, based on the information for the address of the home network.14.The method according to claim 13, wherein the first message comprises a message body of the fourth message and the message body is reformatted or unreformatted.15.The method according to claim 13 or 14, wherein the address of the fourth network node comprises a fully qualified domain name, FQDN, of the fourth network node; and / orwherein the information for the address of the home network comprises a domain name of the home network and information explicitly or implicitly indicating the FQDN of the fourth network node.16.The method according to any of claims 13 to 15, wherein each of the fourth message and the first message is a hypertext transfer protocol, HTTP, request message.17.The method according to claim 16, wherein the information for the address of the home network is contained in a custom header of the HTTP request message.18.The method according to any of claims 13 to 17, wherein the proxy is a proxy connecting different networks.19.The method according to any of claims 13 to 18, wherein the fourth network node implements a control plane network function in the target network; and / orwherein the fifth network node implements a control plane network function in the visited network.20.A method at a third network node implementing a proxy in a target network for a terminal device, the method comprising:receiving (1102) , from a first network node implementing a proxy in a home network for the terminal device, a second message related to the terminal device, wherein the second message comprises an address of a fourth network node in the target network; andsending (1104) a third message to the fourth network node, based on the address of the fourth network node.21.The method according to claim 20, wherein the third message comprises a message body of the second message and the message body is reformatted or unreformatted.22.The method according to claim 20 or 21, wherein the second message comprises one or more of:an identifier, ID, identifying a network for forwarding traffic of the terminal device; andat least one indicator indicating a purpose for which the second message is sent.23.The method according to claim 22, wherein the at least one indicator comprises one or more of:a first indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network; anda second indicator indicating that the second message is sent for forwarding traffic of the terminal device to the target network and only for a test.24.The method according to any of claims 22 to 23, after receiving (1102) the second message, further comprising:verifying (1206) whether the ID in the second message identifying a network for forwarding traffic of the terminal device matches an ID identifying a network supported by the first network node.25.The method according to any of claims 20 to 24, wherein the address of the fourth network node comprises a fully qualified domain name, FQDN, of the fourth network node.26.The method according to any of claims 20 to 25, wherein each of the second message and the third message is a hypertext transfer protocol, HTTP, request message.27.The method according to claim 26, wherein the address of the fourth network node is contained in a custom header of the HTTP request message.28.The method according to any of claims 20 to 27, wherein the proxy is a proxy connecting different networks.29.The method according to any of claims 20 to 28, wherein the fourth network node implements a control plane network function in the target network.30.A method at a fourth network node in a target network for a terminal device, the method comprising:receiving (1302) , from a third network node implementing a proxy in the target network, a third message related to the terminal device.31.The method according to claim 30, after receiving (1302) the third message, further comprising:performing (1404) authorization on the third message based on an identifier, ID, in the third message identifying a network for forwarding traffic of the terminal device.32.The method according to claim 30 or 31, wherein the third message is a hypertext transfer protocol, HTTP, request message.33.The method according to any of claims 30 to 32, wherein the proxy is a proxy connecting different networks.34.The method according to any of claims 30 to 33, wherein the fourth network node implements a control plane network function in the target network.35.The method according to any of claims 30 to 34, wherein the fourth network node implements a session management function, SMF, in the target network; andwherein the method further comprises:sending (1508) , to a user plane function, UPF, in the target network, a first request for establishing a protocol data unit, PDU, session for the terminal device;receiving (1510) , from the UPF in the target network, a first response to the first request, wherein the first response comprises tunnel information of a GPRS tunneling protocol, GTP, proxy, the GTP proxy being used for forwarding traffic of the terminal device between the UPF in the target network and a UPF in a visited network for the terminal device; andsending (1512) the tunnel information of the GTP proxy to the UPF in the visited network via a SMF in the visited network.36.A method at a fifth network node in a visited network for a terminal device, the method comprising:sending (1602) , to a second network node implementing a proxy in the visited network, a fourth message related to the terminal device, wherein the fourth message comprises information for an address of a home network for the terminal device which is mapped from an address of a fourth network node in a target network for the terminal device.37.The method according to claim 36, wherein the address of the fourth network node comprises a fully qualified domain name, FQDN, of the fourth network node; and / orwherein the information for the address of the home network comprises a domain name of the home network and information explicitly or implicitly indicating the FQDN of the fourth network node.38.The method according to claim 36 or 37, wherein the fourth message is a hypertext transfer protocol, HTTP, request message.39.The method according to claim 38, wherein the information for the address of the home network is contained in a custom header of the HTTP request message.40.The method according to any of claims 36 to 39, wherein the proxy is a proxy connecting different networks.41.The method according to any of claims 36 to 40, wherein the fourth network node implements a control plane network function in the target network; and / orwherein the fifth network node implements a control plane network function in the visited network.42.A method at a sixth network node implementing a network repository function, NRF, in a home network for a terminal device, the method comprising:receiving (1702) , from a seventh network node implementing a NRF in a target network for the terminal device, an address of a fourth network node in the target network;determining (1704) information for an address of the home network mapped from the address of the fourth network node; andsending (1706) the information for the address of the home network to an eighth network node implementing a NRF in a visited network for the terminal device.43.The method according to claim 42, wherein the address of the fourth network node comprises a fully qualified domain name, FQDN, of the fourth network node; and / orwherein the information for the address of the home network comprises a domain name of the home network and information explicitly or implicitly indicating the FQDN of the fourth network node.44.The method according to claim 42 or 43, wherein the fourth network node implements a control plane network function in the target network.45.A network node (2000) , comprising:processing circuitry (2010) ; anda memory (2020) , the memory (2020) containing instructions executable by the processing circuitry (2010) , whereby the network node is operative to perform the method according to any one of claims 1 to 44.46.A computer program comprising instructions that, when executed by processing circuitry, cause the processing circuitry to carry out the method according to any of claims 1 to 44.47.A computer program product comprising instructions that, when executed by processing circuitry, cause the processing circuitry to carry out the method according to any of claims 1 to 44.48.A computer-readable medium comprising instructions that, when executed by processing circuitry, cause the processing circuitry to carry out the method according to any of claims 1 to 44.49.A carrier containing the computer program according to claim 46, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer-readable medium.