Mobile Termination (MT) Early Data Transfer (EDT) in Control Plane and User Plane Solutions

By generating and transmitting RRC paging messages containing MT EDT indications in a wireless communication system, the problem that existing systems do not support MT EDT is solved, which improves downlink data transmission efficiency and reduces UE power consumption.

CN114026931BActive Publication Date: 2025-06-17APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202080046570.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-05-01
Filing Date
2020-05-01
Publication Date
2025-06-17
Estimated Expiration
2040-05-01

AI Technical Summary

Technical Problem

Existing wireless communication systems do not support mobile termination (MT) early data transmission (EDT), resulting in low downlink data transmission efficiency and high UE power consumption.

Method used

After receiving the MT EDT indication at the RAN node, an RRC paging message including an MT EDT indication, a contention-free (CF) physical random access channel (PRACH) resource indication, and an EDT-Radio Network Temporary Identifier (EDT-RNTI) indication is generated, and the message is transmitted to the user equipment (UE) to realize MT EDT.

Benefits of technology

The downlink data transmission efficiency is improved, the power consumption of the UE is reduced, and DL data transmission in Msg4 is supported without first transmitting uplink data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114026931B_ABST
    Figure CN114026931B_ABST
Patent Text Reader

Abstract

The present disclosure describes methods, systems, and devices for mobile terminated (MT) early data transmission (EDT). In one example, a method involves a node of the RAN receiving an MT EDT indication and information indicating downlink data for transmission to a user equipment (UE) served by the RAN. The method further involves determining to initiate MT EDT to transmit the downlink data to the UE based on the information indicating the downlink data. The method further involves generating a radio resource control (RRC) paging message that includes: (i) the MT EDT indication, (ii) an indication of contention-free (CF) physical random access channel (PRACH) resources, and (iii) an indication of an EDT-radio network temporary identifier (EDT-RNTI). Additionally, the method involves transmitting the RRC paging message to the UE.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This disclosure claims the benefit of priority of U.S. Provisional Patent Application No. 62 / 841,696, filed on May 1, 2019, entitled "MOBILE-TERMINATED (MT) EARLY DATA TRANSMISSION (EDT) IN CONTROL PLANE AND USER PLANE SOLUTIONS". The entire patent application described above is incorporated herein by reference. Technical Field

[0003] This disclosure generally relates to signaling in a wireless communication system. Background Art

[0004] A user equipment (UE) may wirelessly transmit data using a wireless communication network. To wirelessly transmit data, the UE connects to a node of a radio access network (RAN) and synchronizes with the network. Summary of the Invention

[0005] This disclosure describes methods, systems, and devices for mobile-terminated (MT) early data transmission (EDT).

[0006] According to one aspect of the disclosure, a method involves a node of the RAN receiving an MT EDT indication and information indicating downlink data for transmission to a user equipment (UE) served by the RAN. The method further involves determining, based on the information indicating the downlink data, to initiate MT EDT to transmit the downlink data to the UE. The method further involves generating a radio resource control (RRC) paging message that includes: (i) the MT EDT indication, (ii) an indication of contention-free (CF) physical random access channel (PRACH) resources, and (iii) an indication of an EDT-radio network temporary identifier (EDT-RNTI). Additionally, the method involves transmitting the RRC paging message to the UE.

[0007] Other versions include corresponding systems, apparatuses, and computer programs for performing the actions of the methods defined by instructions encoded on a computer-readable storage device. These versions and other versions may optionally include one or more of the following features.

[0008] In some embodiments, the information indicating the downlink data includes the size of the downlink data, and determining to initiate MT EDT is further based on the number of required transmission repetitions.

[0009] In some specific embodiments, a contention-free (CF) preamble is generated using a modulo function of a UE identifier (ID) and a PRACH preamble index.

[0010] In some specific embodiments, the EDT-RNTI is defined as EDT-RNTI = paging-RNTI (P-RNTI) - constant * offset, and where the constant is the PRACH preamble index.

[0011] In some specific embodiments, the method further includes receiving, from the UE, an RRC response message for an RRC paging message, the RRC response message including a CF preamble; identifying the UE based on the CF preamble in the RRC response message; sending, via an S1 application protocol (S1-AP) initial message, a request for downlink data to a mobility management entity (MME); and receiving, from the MME and via an S1-AP response message, a downlink non-access stratum (NAS) protocol data unit (PDU).

[0012] In some specific embodiments, the downlink data is user plane data, and where the method further includes: retrieving the UE context and encrypting the downlink NAS PDU using the UE context; and transmitting the downlink NAS PDU to the UE in a downlink RRC message.

[0013] In some specific embodiments, the downlink RRC message further includes a suspension indication and a new resume ID multiplexed with the downlink NAS PDU.

[0014] In some specific embodiments, the downlink data is control plane data, and the method further includes transmitting a DL PDU to the UE in a downlink RRC message.

[0015] In some specific embodiments, the downlink RRC message further includes a timing advance (TA) for the UE and an uplink grant. In some specific embodiments, the received downlink NAS PDU is encrypted using NAS security. In some specific embodiments, an MT EDT indication and information indicating downlink data are received from the mobility management entity (MME) via an S1 application protocol (S1-AP) paging message.

[0016] According to another aspect of the present disclosure, a method involves generating a paging message that includes an indication of a contention-free (CF) physical random access channel (PRACH) resource and an early data transmission - radio network temporary identifier (EDT-RNTI) offset. The method further involves encoding the paging message for transmission to a user equipment (UE). BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1Illustrates an exemplary messaging diagram 100 of a Msg2-based technique for transmitting downlink (DL) control plane data (CP) to a user equipment (UE) according to some specific implementations of the present disclosure.

[0018] Figure 2 Illustrates an exemplary messaging diagram 200 of a Msg4-based technique for transmitting downlink (DL) control plane data (CP) to a device according to some specific implementations of the present disclosure.

[0019] Figure 3 Illustrates an exemplary messaging diagram 300 of a Msg4-based technique for transmitting downlink (DL) user plane (UP) data to a device according to some specific implementations of the present disclosure.

[0020] Figure 4 Illustrates an exemplary messaging diagram 400 of a Msg2-based technique for transmitting downlink (DL) user plane (UP) data to a device according to some specific implementations of the present disclosure.

[0021] Figure 5 Illustrates an exemplary messaging diagram 500 of a hybrid technique for transmitting downlink (DL) user plane (UP) data to a device according to some specific implementations of the present disclosure.

[0022] Figure 6A and Figure 6B Each illustrates a flowchart of an exemplary method according to some specific implementations of the present disclosure.

[0023] Figure 7 Illustrates an exemplary architecture of a system 700 of a network according to some specific implementations of the present disclosure.

[0024] Figure 8 Illustrates an exemplary architecture of a system including a core network according to some specific implementations of the present disclosure.

[0025] Figure 9 Illustrates another exemplary architecture of a system including a core network according to some specific implementations of the present disclosure.

[0026] Figure 10 Illustrates an example of infrastructure equipment according to some specific implementations of the present disclosure.

[0027] Figure 11 Illustrates an example of a platform or device according to some specific implementations of the present disclosure.

[0028] Figure 12 Illustrates exemplary components of a baseband circuit and a radio front-end circuit according to some specific implementations of the present disclosure.

[0029] Figure 13 Illustrates exemplary protocol functions that can be implemented in a wireless communication system according to some specific implementations of the present disclosure.

[0030] Figure 14 Illustrates an example of a computer system according to some specific implementations of the present disclosure.

[0031] Like reference symbols in the various figures indicate like elements. Detailed Description

[0032] Narrowband Internet of Things (NB-IoT) is a technology designed to address specific cellular IoT (CIoT) constraints. NB-IoT can provide improved indoor coverage, support for a relatively large number of low-throughput devices, low latency sensitivity, low device cost, low device power consumption, and an improved network architecture. NB-IoT can be deployed in the Global System for Mobile Communications (GSM) spectrum or the Long-Term Evolution (LTE) spectrum. NB-IoT can also be deployed in fifth-generation (5G) or New Radio (NR) technologies.

[0033] NB-IoT also supports control plane (CP) and user plane (UP) optimization solutions. The CP solution (referred to as CPCIoT evolved packet system (EPS) optimization) enables the efficient transmission of user data (e.g., Internet Protocol (IP) data or non-IP data) or short message service (SMS) messages over the control plane via the Mobility Management Entity (MME) without establishing a data radio bearer. CP CIoT EPS optimization can do this by transmitting CP data that is transmitted over the non-access stratum (NAS). The UP solution (referred to as UP CIoT EPS optimization) enables a user equipment (UE) to resume a previously stored Radio Resource Control (RRC) connection. The UP solution does this by storing the UE access stratum (AS) context in an access node (e.g., an eNodeB (eNB)) and storing the UE AS context in the UE. The UP solution enables a change from EPS mobility management (EMM) idle mode to EMM connected mode without using a service request procedure.

[0034] In addition, NB-IoT can provide support for early data transmission (EDT), which is beneficial for infrequent small data packet transmissions. Specifically, EDT can be beneficial for data transmission from and / or to a UE in an idle or suspended state without causing the UE to transition to a connected state. Thus, EDT enables data transmission without resuming an RRC connection. In some specific implementations, if the data does not exceed a predetermined threshold, small data transmissions can be applicable to EDT transmissions, e.g., transmissions less than N bytes, where N is a predetermined value (e.g., 100, 128, 256, 512, and 1024). Other values of N are possible.

[0035] In implementation, there is a Mobile Originated (MO) EDT solution. This solution enables uplink (UL) data to be transmitted in Msg3 and enables downlink (DL) data to be transmitted in Msg4. However, existing systems do not support the transmission of DL data in Msg4 without first transmitting UL data in Msg3. That is, existing systems do not support Mobile Terminated (MT) EDT. However, such solutions can have many advantages, including improved DL transmission efficiency and / or UE power consumption. Therefore, there is a need to develop an MT EDT solution.

[0036] This disclosure describes systems and methods for implementing an MT EDT solution for a UE that can be optimized using CP and / or UP C-IoT EPS. Specifically, this disclosure describes Msg2-based techniques and Msg4-based techniques for DL transmission of CP and UP data. This disclosure also describes hybrid techniques for transmitting DL UP data. Note that although this disclosure describes these techniques in the context of an LTE system, these techniques can also be used in a 5G / NR system.

[0037] I. Control Plane Data MT EDT

[0038] a. Msg2-based techniques

[0039] Figure 1 FIG. 100 shows an exemplary messaging diagram of a Msg2-based technique for transmitting downlink (DL) control plane data (CP) to a user equipment (UE) according to some specific implementations. In one implementation, a wireless communication system can use a Msg2-based technique (also referred to as a “Msg2-based solution”) to implement MT EDT. As Figure 1 shown, the wireless communication system includes an MME 130, an S-GW 140, and an eNB 150. The eNB 150 is an access point (AP) of a radio access network (RAN) that serves the UE 160. In this example, the UE 160 can be configured to use CP CIoT EPS optimization. Additionally, in this example, the S-GW 140 provides DL CP data, but in other examples, the SCEF can provide DL CP data (e.g., provided to the MME 130). Note that although Figure 1A single eNB and a single UE are shown, but the wireless communication system may include multiple eNBs and / or multiple UEs. Additionally, although the Msg2-based technique is described in the context of an LTE system, the technique may also be used in a 5G / NR system, which may include an NG-RAN (e.g., gNB), an access and mobility management function (AMF), a session management function (SMF), and / or a user plane function (UPF).

[0040] The Msg2-based technique begins at step 102 of the messaging diagram 100. At step 102, the S-GW 140 (or SCEF) sends CP data information to the MME 130. The CP data information may include an indication of the arrival of DL CP data and / or size information of the DL data. In one example, the DL CP data may arrive at the S-GW 140, which may generate the CP data information and send the CP data information to the MME 130. At step 104, and after receiving the CP data information, the MME 130 determines whether to use MT EDT to transfer data to the UE 160. In one example, the MME 130 may make the determination based on: (i) the size information of the DL data, (ii) the subscription information of the UE 160, (iii) whether additional DL data is expected to be transferred to the UE 160, and / or (iv) a release assistance indication (RAI), where the RAI indicates whether an acknowledgement or response is expected after the data transfer (e.g., whether an uplink (UL) acknowledgement (ACK) is required). In some examples, when the CP DL data arrives at the S-GW 140, the data may be made available to the MME 130 by forwarding the data to the MME 130.

[0041] The MME 130 determines to initiate an MT EDT to send CP DL data to the UE 160. The MME 130 then generates an S1-AP paging message including an MT EDT indication and CP data information. Then, at step 106, the MME 130 transmits the S1-AP paging message to the eNB 150. At step 108, and after receiving the S1-AP paging message, the eNB 150 determines whether to use the MT EDT to transmit DL data to the UE 160. The eNB 150 may make the determination based on the number of required transmission repetitions and / or the size information of the DL data. If the eNB 150 decides to use the MT EDT, the eNB 150 determines a contention-free (CF) physical random access channel (PRACH) resource index, a PRACH preamble index, and / or EDT-radio network temporary identifier (EDT-RNTI) information. This information may be collectively referred to as MT EDT information. As described herein, this information enables the UE 160 to transmit Msg1 and determine the EDT-RNTI to be used to receive Msg2. In addition, the EDT-RNTI information may be a specific EDT-RNTI (e.g., a reserved EDT-RNTI) or an offset value of the EDT-RNTI.

[0042] At step 110, the eNB 150 sends a paging message (e.g., an RRC message) to the UE 160. Among other things, the paging message includes an MT EDT indication, a CF PRACH resource, and / or EDT-RNTI information. At step 112, and after the UE 160 receives the paging message, the non-access stratum (NAS) of the UE 160 may temporarily exit the suspended state. Then, the UE 160 uses the received CF PRACH resource to respond to the paging message. As Figure 1 shown, the UE 160 responds with Msg1, which may include a CF preamble (for receiving the RRC message) and / or a NAS protocol data unit (PDU).

[0043] At step 114, and after receiving Msg1, the eNB 150 may identify the UE 160 based on the CF preamble included in Msg1. The eNB 150 also generates an S1-AP initial message to be sent to the MME 130. The initial message may include a request to send DL CP data. In an example where the UE 160 sends a NAS PDU, the eNB 150 may include the NAS PDU in the S1-AP initial message. And in an example where the UE 160 does not send a NAS PDU, the eNB 150 may generate the initial message without a NAS PDU or may include a dummy NAS PDU in the message.

[0044] At step 116, the eNB 150 sends an S1-AP initial message to the MME 130. In response to receiving the initial message, the MME 130 may perform signaling with the S-GW 140 (e.g., establish a bearer) to receive DL data from the S-GW 140. At step 118, and in response to receiving the S1-AP initial message, the MME 130 sends DL CP data (e.g., NAS PDU) to the eNB 150. At step 120, the eNB 150 sends an RRC message (Msg2) to the UE 160. Msg2 may include the DL CP data in a dedicatedinfoNAS information element (IE). In this technique, since the CP DL data is sent in the NAS PDU, the data can be protected by NAS security. The UE 160 may use the EDT-RNTI information to monitor the physical downlink control channel (PDCCH) to receive the DL CP data. In one example, the UE 160 determines a specific EDT-RNTI resource to monitor based on the EDT-RNTI information included in the paging message. Then, the UE 160 may receive Msg2 via the monitored resource. In some examples, the eNB150 may also send a random access response (RAR) containing a timing advance (TA) and UL grant to the UE 160, and the UE 160 may use the RAR for UL ACK transmission. The UE 160 may receive the RAR in the same Msg2 or in a separate message.

[0045] At step 122, the UE 160 uses the UL grant provided in the RAR to transmit an RRC message (Msg3) including a NAS PDU. The NAS PDU may be a NAS ACK or UL ACK for the received CP DL data. To process and generate the RRC message (and associated data), a gap 128 between Msg2 and Msg3 may be scheduled. The scheduling gap is described in further detail below. After successful UL data transmission, from the perspective of the UE 160, MT EDT is completed. Therefore, the UE NAS pauses again, and the UE 160 remains in the idle mode. At step 124, the eNB 150 forwards the NAS PDU to the MME 130, which may forward the NAS PDU to the S-GW 140 at step 126. This technique is completed when the S-GW 140 receives the NAS PDU.

[0046] In one embodiment, a new message format can be used to implement at least some of the messaging for Msg2-based techniques. For example, the S1-AP message of step 102 can be a new S1-AP message that includes an "MT-CP-EDT indication" field and an integer field "DL data bit size". As another example, the S1-AP initial UE message of step 116 can be a new S1-AP message that includes an "MO EDT session" field and an "MT EDT session" field. This message can be sent by the eNB to transfer an initial layer 3 message to the MME over the S1 interface. As yet another example, the S1-AP message of step 124 can be a new S1-AP message.

[0047] Within the example, the message UERadioPagingInformation or UEPagingCoverageInformation can be extended for this purpose. If the UP solution requires a recovery ID, the recovery ID can also be included. In the example of UEPagingCoverageInformation, the message can be used to transfer UE paging coverage information, covering both upload to and download from the evolved packet core (EPC) / 5G core (5GC). The direction of the message is from the eNB to / from the EPC / 5GC. In the example of UERadioPagingInformation, the message can be used to transfer radio paging information, covering both upload to and download from the EPC / 5GC. The direction of the message is from the eNB to / from the EPC / 5GC. In some examples, the S1-AP message of step 124 can be an existing message, such as UPLINK NAS TRANSPORT (which is used to carry NAS data over the S1 interface).

[0048] As previously mentioned, in order for the UE 160 to receive Msg2, the eNB 150 provides the UE 160 with MT EDT information (e.g., CF PRACH resources, number of preamble repetitions, and EDT-RNTI information). However, this information can amount to an overhead of up to 28 bits in the broadcast paging message. It is desirable to reduce the overhead in the paging message to minimize the impact on paging capacity and the power consumption of other UEs (since a large number of UEs may be receiving the same broadcast paging message).

[0049] In one embodiment, the wireless network may define the value of the MT-EDT information based on existing information or information available to the UE in order to reduce the overhead of paging messages. In one example, the EDT-RNTI may be based on the paging-RNTI (P-RNTI) or a fixed hexadecimal value (e.g., FFF3) in order to reduce the 16-bit overhead of the EDT-RNTI. In this example, an x-bit (e.g., 3-bit) offset from the P-RNTI (or fixed hexadecimal value) may be used to define the EDT-RNTI. The x-bit offset may be included in the paging message. Thus, the overhead of the DT-RNTI is reduced from 16 bits to 3 bits. For example, the EDT-RNTI may be defined as:

[0050] EDT-RNTI = P-RNTI - constant * offset. Formula (1)

[0051] In another example, the CF preamble is derived based on the UE ID provided in the paging message (which is used for paging occasion (PO) calculation) and an x-bit value (e.g., 3 bits with 8 values). The x-bit value may be the preamble index. In one specific implementation, for enhanced machine type communication (eMTC), the CF preamble is calculated as:

[0052] CF preamble = numberOfRA-Preambles + UE ID mod preambleIndex.

[0053] Formula (2)

[0054] Or

[0055] CF preamble = numberOfRA-Preambles + (UE ID mod preambleIndex) mod

[0056] (64 - numberOfRA-Preambles). Formula (3)

[0057] In another specific implementation, for NB-IoT, the preambleIndex may be used to calculate the carrier to be used as the preamble. For example, the carrier to be used as the preamble may be calculated as:

[0058] CF preamble = nprach-SubcarrierOffset + nprach-NumCBRA-StartSubcarriers

[0059] +(UE ID mod preambleIndex) mod (nprach-NumSubcarriers - nprach -

[0060] (NumCBRA-StartSubcarriers). Equation (4)

[0061] In equations (2), (3), and (4), mod represents the modulo function.

[0062] As previously described, after transmitting the preamble, the UE can monitor the EDT-RNTI for DL data. For example, DL common control channel (CCCH) messages can be used to send CP DL data in dedicatedInfoNAS. In one example, if the eNB wants the UE to transition to the connected mode, RRCConnectionSetup can be extended for this purpose. In another example, if the eNB wants the UE to remain in the idle mode, RRCEarlyDataComplete can be used.

[0063] In addition, in Msg2-based techniques, the eNB may not be able to guarantee that the preamble and / or CP DL data it receives from a legitimate UE are sent to the legitimate UE (e.g., a fake UE can send the same preamble). Therefore, a secure ULACK from the UE may be required. In one implementation, the eNB can schedule a UL grant for the UE to send a UL NAS PDU with a NAS acknowledgment. In this case, the UE transmits a UL ACK for the received DL data, and the UL NAS PDU can contain application UL ACK data. Thus, the UE can also expect to receive a random access response (RAR) to receive the timing advance (TA) and a UL grant. In this way, in some examples, the RAR can be multiplexed with the RRC message in Msg2. However, in other examples, due to channel conditions, the RAR message and the RRC message may not be scheduled in the same Msg2. Therefore, the eNB can also schedule the RRC message (with DL data) and the RAR separately.

[0064] In one embodiment, to transmit NAS PDUs for NAS ACK or UL ACK, a new UL CCCH message class extension is used. In one example, the spare field in messageClassExtensionFuture-r13 is used to define an RRC message (e.g., rrcMT-EDT-ACK-r16) to carry the NAS PDU in Msg3. However, as previously mentioned, to generate the UL ACK and the RRC message, a gap between Msg2 and Msg3 can be scheduled. In one embodiment, when UL authorization is provided in Msg2 for transmitting any ACK or UL data in Msg3, a sufficient gap is scheduled such that the UE can process the DL data in Msg2 and prepare the UL ACK to be transmitted in Msg3. In another embodiment, UL authorization is not provided in Msg2, but instead information indicating when the UE should monitor the PDCCH to receive the UL authorization for Msg3 is provided. It should be understood that the RRC processing time is considered when determining when the UE should start monitoring the PDCCH to receive the UL authorization. After successful transmission of UL data in Msg3, no further messaging exchange is required, and the UE can remain in the idle mode.

[0065] As previously mentioned, the S-GW provides DL data to the MME. However, when the S-GW provides the DL data can depend on the size and / or quantity of the DL data packets. In one embodiment, if the DL data is a single packet and / or smaller than a predetermined threshold, the S-GW can provide the DL data to the MME when the DL data is received. For example, in the Figure 1 example, the S-GW can provide the DL data to the MME in step 102. However, if the DL data is more than one packet and / or larger than the predetermined threshold, the S-GW cannot simply forward the DL data to the MME. Instead, a bearer must be established between the MME and the S-GW to transfer the data (e.g., between Figure 1 steps 116 and 118). This concept also applies to other techniques disclosed herein.

[0066] b. Techniques Based on Msg4

[0067] In some networks, RAN paging (which may include MT EDT information) can be broadcast by each cell in the tracking area. However, some cells may have paging capacity limitations. Other cells may not have CF PRACH resources or unique EDT-RNTIs available for paging.

[0068] In one embodiment, the MO EDT solution can be used to overcome these limitations. In one example, the eNB may broadcast a paging message including only the MT EDT indication in only some cells. If the UE receives the paging message when it is in one of the cells where the message is broadcast, the UE can initiate the MO EDT procedure by responding to the paging using the EDT preamble. Thus, if the UE is in RRC_IDLE and using CP CIoT EPS optimization and receives a paging message including only the MT EDT indication, the MO EDT can be triggered. Note that in this scenario, the MT EDT or MO EDT is triggered by the eNB in the paging message.

[0069] In another embodiment, the MO EDT solution can be used even if the UE is using UP CIoT EPS optimization. In this case, the S-GW determines that MT EDT can be used to send DL data. Thus, the DL data is forwarded to the MME even if the UE is in a suspended state. The UE NAS can temporarily exit the suspended state when it receives the MT EDT indication so that it can transmit or receive NAS PDUs. Once the AS layer indicates that the MT EDT has been completed (or has failed), the UE NAS can return to its previous suspended state.

[0070] Figure 2 An exemplary messaging diagram 200 of a Msg4-based technique for transmitting downlink (DL) control plane data (CP) to a device according to some specific implementations is shown. In this example, with respect to Figure 1 The described wireless communication system uses a Msg4-based technique (also referred to as "Msg4-based solution") to implement MT EDT.

[0071] The Msg4-based technique starts at step 202 of the messaging diagram 200. At step 202, the S-GW 140 (or SCEF) determines whether to initiate the MT EDT. In one example, the S-GW 140 makes the determination regardless of whether the DL data is CP or UP data. Additionally, the S-GW 140 makes the determination based on whether there is a single instance or multiple instances of the DL data.

[0072] At step 204, the S-GW 140 (or SCEF) sends the CP data information to the MME 130. In some examples, when the CP DL data arrives at the S-GW 140, the data may be made available to the MME 130 by forwarding the data to the MME 130. At step 206, and after receiving the DL data, the MME 130 determines whether to use MT EDT to transmit the data to the UE160. The MME 130 may make the determination based on: (i) UE capabilities, (ii) transport block size (TBS), and / or (iii) RAI. The MME130 then determines to initiate MT EDT to send the CP DL data to the UE 160. The MME 130 also generates an S1-AP paging message including the MT EDT indication and the DL data information.

[0073] At step 208, the MME 130 transmits the S1-AP paging message to the eNB 150. At step 210, and after receiving the S1-AP paging message, the eNB 150 determines whether to use MT EDT to transmit the CP DL data to the UE 160. The eNB150 may make the determination based on the number of required transmission repetitions and / or the size information of the DL data (e.g., maximum data size). If the eNB 150 decides to use MT EDT, the eNB 150 generates a paging message including the MT EDT indication.

[0074] At step 212, the eNB 150 sends a paging message (e.g., an RRC message) to the UE 160. At step 214, and after the UE 160 receives the paging message, the non-access stratum (NAS) of the UE 160 may temporarily exit the suspended state (if it is in that state). Then, at step 216, the UE 160 uses Msg1 including the MO EDT preamble to respond to the paging message. At step 218, the eNB 150 sends Msg2 including an RAR containing the UL authorization size to the UE 160. At step 220, the UE 160 transmits an RRC message (Msg3) including a NAS service request or an MT access indication. At step 222, and after receiving Msg3, the eNB 150 generates an S1-AP initial message to send to the MME 130. The initial message may include a request to send the DL data and the UE NAS PDU. In response to receiving the initial message, the MME 130 may perform signaling with the S-GW 140 (e.g., establish a bearer) to receive the DL data from the S-GW.

[0075] At step 224, the MME 130 may use a DL NAS transport message to send DL data (e.g., NAS PDU) to the eNB 150. At step 226, the eNB 150 sends an RRC message (Msg4) to the UE 160 that may include the DL data in dedicatedInfoNAS. At step 228, the UE 160 may optionally transmit an RRC message (Msg5) to the eNB that includes UL ACK data. At step 230, the eNB 150 forwards the UE ACK and / or UL data to the MME 130, which may forward the NAS PDU to the S-GW 140 at step 232. As shown at step 234, after successful transmission of the UL data, from the perspective of the UE 160, the MT EDT is complete. Accordingly, the UE NAS pauses again (e.g., if it was in a paused state prior to the MT EDT), and the UE 160 remains in the idle mode.

[0076] II. MT EDT for Transmitting User Plane Data

[0077] a. Msg4-based techniques

[0078] In one embodiment, Msg-4-based techniques may be used to transport user plane data. As with the prior art, if the MME and / or eNB determine to initiate an MT EDT to send DL UP data, an MT EDT indication is provided in a paging message. In this technique, the DL data is encrypted and transmitted via a dedicated traffic channel (DTCH). In order to receive the DL data via the DTCH, the UE may need to derive a new key to decrypt the DL data. Accordingly, the UE may receive a next-hop link counter (NCC) during the UE's prior connection suspension procedure.

[0079] Figure 3 An exemplary messaging diagram 300 of Msg4-based techniques for transmitting downlink (DL) user plane (UP) data to a device in accordance with some specific implementations is shown. In this example, relative to Figure 1 the wireless communication system described uses Msg4-based techniques (also referred to as "Msg4-based solutions") to implement the MT EDT. Note that in this example, a UL ACK for the DL data is not required, but a UL ACK may still be sent.

[0080] At step 302, if the UE 160 is using UP C-IoT EPS optimization, the S-GW 140 (or SCEF) may send an indication of the arrival of DL data and DL data size information to the MME 130. At step 304, the MME 130 determines whether to initiate MT EDT (e.g., by including MT EDT information in the S1-AP paging). The MME 130 may make the determination based on: (i) the Dl data size information, (ii) the subscription information of the UE 160, (iii) whether additional DL data is expected to be transmitted to the UE 160 and / or (iv) the Release Assistance Indication (RAI). If the MME 130 decides to initiate MT EDT, the technique proceeds. At step 306, the MME 130 then generates an MT EDT indication (e.g., a 1-bit indication) and adds the MT EDT indication in the S1-AP paging message sent to the eNB 150.

[0081] At step 308, the eNB 150 sends a paging message with the MT EDT indication to the UE 160. At step 310, if the UE 160 receives the paging and recognizes the MT EDT indication, the UE 160 resumes the UE context and activates AS security. As shown in block 312, the UE 160 may access the old AS keys (K RRCint_0 , K eNB_0 ) from the previous connection. Additionally, the UE may have an NCC in the suspension message of the previous connection of the UE 160.

[0082] At step 314, the UE 160 sends Msg1 via the PRACH in response to the paging. At step 316, the eNB 150 sends an RAR to the UE 160 in Msg2. The RAR may include the UL grant size. At step 318, the UE 160 responds with Msg3 including RRCConnectionResumeRequest, where the establishment cause is "mt-Access" (i.e., no UL data to transmit). The RRCConnectionResumeRequest also includes the old key K RRCint_0 . At step 320, the eNB150 initiates an S1-AP context recovery procedure to resume the S1 connection and reactivate the S1-U bearer. At step 322, the MME130 requests the S-GW 140 to reactivate the S1-U bearer for the UE 160. At step 324, the MME 130 confirms the UE context recovery to the eNB 150. At step 326, the S-GW 140 sends the DL data to the eNB 150.

[0083] At step 328, eNB 150 determines whether to use MT EDT based on the UE coverage enhancement (CE) level, the maximum TBS, the establishment cause, whether the UE has received the NCC in the UE's previous connection, the UE capabilities, and / or whether additional UL / DL data is expected according to S-GW 140. At step 330, if eNB 150 determines to use MT EDT, eNB 150 may initiate a suspension of the S1 connection. Additionally, at step 332, eNB 150 initiates the deactivation of the S1-U bearer. At step 334, eNB 150 sends Msg4 including RRCConnectionRelease to keep UE 160 in RRC_IDLE. The message includes a ReleaseCause set to "rrc-Suspend", a resumeID multiplexed with DL data, a NextHopChainingCount (i.e., the new NCC), and drb-ContinueROHC, which is stored by UE 160 upon reception. Alternatively, if UE 160 is not ready to receive the DL data in Msg4, eNB 150 sends an RRCConnectionResume message without encryption.

[0084] As previously described, after receiving a paging message with an MT EDT indication, the UE may activate the AS security unit and respond to the paging message. However, the UE must indicate to the eNB in Msg3 that the UE has activated AS security and is ready to receive an encrypted RRC message with DL data in Msg4. In one embodiment, spare bits in the RRCConnectionResumeRequest message may be used for this purpose. Alternatively, in another embodiment, the eNB may be configured to determine the MT EDT capability of the UE to default activate AS security when receiving an MT EDT indication in paging if one or more conditions are met. The first condition is that the UE can be identified as the paging UE according to Msg3. The second condition is that the UE is capable of MT EDT. The third condition is that the UE responds to a paging message including an MT-EDT indication. For example, the eNB may make this determination based on whether the resume reason is "mt-Access". The fourth condition is that the UE has received the NCC in a previous suspension message. Specifically, when the target eNB retrieves the UE context from the source eNB, the source eNB may indicate to the target eNB whether the UE can receive DL data in Msg4 (e.g., by indicating whether the NCC was delivered to the UE in the last suspension procedure).

[0085] In one embodiment, the UE may use one or more of the above conditions to determine whether to activate AS security before responding to a paging message. If the UE determines based on the conditions that it cannot receive DL data in Msg4, the UE does not activate AS security.

[0086] In some scenarios, the UE may have UL data to transmit (e.g., an application acknowledgment of received DL data), but when the UE receives a paging message including an MT-EDT indication, it cannot initiate MO EDT. In such scenarios, if the UE uses the resume cause "mt-Access", the eNB may release the UE in Msg4 (as described above). Alternatively, if the UE uses the resume cause "mo-Data", DL data cannot be sent in Msg4. Therefore, the UE may not be able to transmit the UL data.

[0087] In one embodiment, an alternative value in the ResumeCause field of the RRCConnectionResumeRequest message may be used to introduce a new resume cause "mo-mt-Access". This new resume cause indicates that the UE is ready to receive any encrypted DL data in Msg4 (e.g., the MT EDT capability and NCC received in a previous suspension message), and also has UL data to send (e.g., UL data or an application ACK for DL data).

[0088] In another embodiment, if the existing resume cause (mt-Access) is used, it is assumed that Msg4 is not encrypted or the UE has not activated AS security and the legacy procedure proceeds. But when the UE uses the new resume cause (e.g., mt-Access-EDT), the UE indicates to the eNB that the UE has activated AS security and is ready to receive encrypted RRC messages and / or DL data in Msg4. In this case, the DL data may be sent together with the RRC connection release message in Msg4. Optionally, if ULACK is desired, the eNB may provide a UL grant. Then, the release procedure is delayed until the ULACK data is transmitted in the provided UL grant in Msg5. When Msg5 is successfully completed, the UE release procedure is executed.

[0089] In another embodiment, when a UL CCCH message extension (e.g., RRCConnectionResumeRequest-r16) is used for the RRC message in Msg3, the additional 3 bits required for the extension can be freed by removing the 3-bit release cause field in the RRC message. In one example, the remaining 1 spare bit can be used for the purpose of releasing the auxiliary information (RAI), which indicates whether the UE expects to transmit UL data in response to DL data. In another example, the remaining 1 spare bit can be used for the new resume reasons "mt-Access-EDT" or "mo-mt-Access". The new resume reason "mo-mt-Access" indicates that the UE is responding to paging and the UE has UL data to transmit.

[0090] In one embodiment, if the eNB determines to use MT EDT (e.g., based on UE CE level, maximum TBS size, UE capabilities, and no further UL / DL data is expected from the S-GW / UE), the eNB may send an RRCConnectionRelease message with DL data. If the eNB determines that the UE is ready to receive DL data in Msg4, but the eNB cannot send the DL data in Msg4 due to TBS limitations (e.g., the UE is at a worse coverage level), the eNB may segment the DL data and transmit it in Msg4.

[0091] In some examples, the eNB may send an encrypted RRCConnectionResume message in Msg4. However, if the eNB determines that the UE cannot receive encrypted data in Msg4 (e.g., the UE does not respond to paging, the UE does not have MT EDT capabilities, or the UE did not receive the NCC in the previous suspension message), the RRCConnectionResume message in Msg4 is not encrypted.

[0092] b. Msg2-based techniques

[0093] Figure 4 Exemplary messaging diagram 400 shows Msg2-based techniques for transmitting downlink (DL) user plane (UP) data to a device according to some specific implementations. In this example, with respect to Figure 1 The described wireless communication system uses Msg2-based techniques (also referred to as "Msg2-based solutions") to implement MT EDT.

[0094] The Msg2-based technique starts at step 402 of the message transfer graph 400. At step 402, the S-GW 140 determines whether to initiate MT EDT. In one example, the S-GW 140 makes the determination regardless of whether the DL data is CP or UP data. Additionally, the S-GW 140 may make the determination based on whether there is a single instance or multiple instances of DL data. At step 404, the S-GW 140 (or SCEF) sends an indication of the DL data to the MME 130. At step 406, and after receiving the DL data, the MME130 determines whether to use MT EDT to transfer the data to the UE 160. The MME 130 may make the determination based on: (i) UE capabilities, (ii) TBS, and / or (iii) RAI.

[0095] At step 408, the MME 130 determines to initiate MT EDT to send the DL UP data to the UE 160. The MME 130 then generates an S1-AP paging message including the MT EDT indication, DL data information, and a recovery ID. The MME 130 then transmits the S1-AP paging message to the eNB 150. At step 410, and after receiving the S1-AP paging message, the eNB 150 may determine the PRACH resources of the UE 160. At step 412, the eNB 150 sends a paging message (e.g., an RRC message) to the UE 160. At step 414, if the UE 160 receives the paging and recognizes the MT EDT indication, the UE 160 restores the UE context and activates AS security. As shown in block 416, the UE 160 may access the old AS keys (K RRCint_0 , K eNB_0 ) from the previous connection. Additionally, the UE may have received an NCC (e.g., NCC_1) in the suspension message of the previous connection of the UE160.

[0096] At step 418, the UE 160 responds to the eNB150 using Msg1 including a CF preamble derived from the paging message. At step 418, and after receiving Msg1, the eNB 150 may identify the UE 160 based on the CF preamble included in Msg1. Additionally, the eNB 150 generates an S1-AP initial message to be sent to the MME 130. The initial message may include a request to send the DLUP data and the recovery ID. At step 420, the eNB 150 sends the S1-AP initial message to the MME 130. In response to receiving the initial message, the MME 130 may perform signaling with the S-GW 140 (e.g., establish a bearer) to receive the DL data from the S-GW 140. At step 422, the MME 130 sends the DL UP data to the eNB 150. The MME 130 may also send the recovery ID and a new NAS count.

[0097] At step 424, eNB 150 retrieves the UE context and encrypts the data received from MME 130. At step 426, eNB 150 sends Msg2 to UE 160, where Msg2 includes a suspension indication, a new NAS count, a new resume ID, and DL data. At step 428, UE 160 transmits an RRC message (Msg3) including an RRC ACK message with optional UL data. At step 430, eNB 150 may send a suspension completion message including the new resume ID to MME 130. Additionally, eNB 150 may send optional UL data to MME 130. At step 432, MME 130 may forward the UL data to S-GW 140.

[0098] In this embodiment, although an S1 bearer is not established between eNB 150 and S-GW 140, eNB 150 can still derive a new key to protect Msg2 and Msg3. However, when sending an RRCConnectionRelease message in Msg2, eNB 150 must provide the same NCC value for the next resume procedure. This is because there will be no S1-AP suspension procedure in this scenario, and thus eNB 150 will not be able to receive any new NCC from MME 130. In this embodiment, Msg2 may also include a UL grant that enables the UE to send an encrypted RRC message as an acknowledgement in Msg3. Additionally, the UE NAS receives a NAS PDU including user data. In this case, when a NAS PDU is received for MT EDT, the AS sends an indication not to initiate any NAS signaling. In some examples, the MME may send user data without NAS security (e.g., NAS integrity protection or encryption) when the UE is in a suspended state and may use AS security.

[0099] c. Hybrid UP and CP Technologies

[0100] In one embodiment, a UP solution is used between UE 160 and eNB 150, and a CP solution is used between UE 160 and MME 130 (or S-GW 140).

[0101] Figure 5 Exemplary message flow diagram 500 of a hybrid technology for transmitting downlink (DL) user plane (UP) data to a device according to some specific implementations is shown. In this example, with respect to Figure 1 the described wireless communication system implements MT EDT using hybrid technology.

[0102] The hybrid technique starts at step 502 of the messaging diagram 500. At step 502, the S-GW 140 determines whether to initiate MT EDT. In one example, the S-GW 140 makes the determination regardless of whether the DL data is CP or UP data. Additionally, the S-GW 140 may make the determination based on whether there is a single instance or multiple instances of DL data. At step 504, the S-GW 140 sends an indication of the DL data to the MME 130. At step 506, and after receiving the DL data, the MME 130 determines whether to use MT EDT to transfer the data to the UE 160. The MME 130 may make the determination based on: (i) UE capabilities, (ii) TBS, and / or (iii) RAI.

[0103] At step 508, the MME 130 determines to initiate MT EDT to send the DL UP data to the UE 160. The MME 130 then generates an S1-AP paging message including the MT EDT indication, DL data information, and a recovery ID. The MME 130 then transmits the S1-AP paging message to the eNB 150. At step 510, and after receiving the S1-AP paging message, the eNB 150 may send a paging message (e.g., an RRC message) including the MT EDT indication to the UE 160. At step 512, if the UE 160 receives the paging and recognizes the MT EDT indication, the UE 160 restores the UE context and activates AS security. As shown in block 514, the UE 160 may access the old AS keys (K RRCint_0 , K eNB_0 ) from the previous connection. Additionally, the UE may have received an NCC (e.g., NCC_1) in the suspend message of the previous connection of the UE 160.

[0104] At step 516, the UE 160 sends Msg1 via the PRACH in response to the paging. At step 518, the eNB 150 sends an RAR to the UE 160 in Msg2. The RAR may include the legacy UL grant size. At step 520, the UE 160 responds with Msg3 including an RRCConnectionResumeRequest, where the release cause is "mt-Access" or "mo-Data". The RRCConnectionResumeRequest also includes the old key K RRCint_0 . At step 522, the eNB 150 initiates an S1-AP UE context recovery procedure to restore the S1 connection. The request sent to the MME 130 may include a request to send MT data. At step 524, the MME 130 may use a DL NAS transport message to send the DL data to the eNB 150.

[0105] At step 526, eNB 150 determines whether to use MT EDT based on conditions such as the establishment cause, MT EDT capability, and / or whether the UE has received the NCC in the UE's previous connection. At step 528, eNB 150 sends Msg4 including RRCConnectionRelease to keep the UE in RRC_IDLE. The message includes a suspension indication, a resumeID multiplexed with DL data, and the same NCC, which is stored by UE 160 when received. At step 532, eNB 150 may confirm the transmission to MME130.

[0106] Figure 6A and Figure 6B FIG. shows a flowchart of an exemplary process according to some specific embodiments. For clarity of presentation, the following description generally describes the process in the context of other figures in this specification. For example, processes 600 and 610 may be performed by Figure 1 the base station shown (e.g., eNB 150). However, it should be understood that these processes may be performed, as appropriate, by any suitable system, environment, software, and hardware, or a combination of system, environment, software, and hardware. In some specific embodiments, the various steps of the process may be run in parallel, combined, looped, or run in any order.

[0107] Figure 6A FIG. is a flowchart of an exemplary method 600 for mobile terminated (MT) early data transmission (EDT). At step 602, the method involves a node in the RAN receiving an MT EDT indication and information indicating downlink data for transmission to a user equipment (UE) served by the RAN. At step 604, the method involves determining to initiate MT EDT to transmit the downlink data to the UE based on the information indicating the downlink data. At step 606, the method involves generating a radio resource control (RRC) paging message that includes: (i) an MT EDT indication, (ii) an indication of a contention-free (CF) physical random access channel (PRACH) resource, and (iii) an indication of an EDT - radio network temporary identifier (EDT-RNTI). At step 608, the method involves transmitting the RRC paging message to the UE.

[0108] In some specific embodiments, the information indicating the downlink data includes the size of the downlink data, and determining to initiate MT EDT is further based on the number of required transmission repetitions.

[0109] In some specific implementations, a contention-free (CF) preamble is generated using a modulo function of a UE identifier (ID) and a PRACH preamble index. In some specific implementations, the EDT-RNTI is defined as EDT-RNTI = paging-RNTI (P-RNTI) - constant * offset, and where the constant is the PRACH preamble index. In some specific implementations, the method further includes receiving, from the UE, an RRC response message for an RRC paging message, the RRC response message including the CF preamble; identifying the UE based on the CF preamble in the RRC response message; sending a request for downlink data to a mobility management entity (MME) via an S1 application protocol (S1-AP) initial message; and receiving a downlink non-access stratum (NAS) protocol data unit (PDU) from the MME and via an S1-AP response message.

[0110] In some specific implementations, the downlink data is user plane data, and where the method further includes: retrieving the UE context and encrypting the downlink NAS PDU using the UE context; and transmitting the downlink NAS PDU to the UE in a downlink RRC message.

[0111] In some specific implementations, the downlink RRC message further includes a suspension indication and a new resume ID multiplexed with the downlink NAS PDU.

[0112] In some specific implementations, the downlink data is control plane data, and the method further includes transmitting a DL PDU to the UE in a downlink RRC message.

[0113] In some specific implementations, the downlink RRC message further includes a timing advance (TA) for the UE and an uplink grant. In some specific implementations, the received downlink NAS PDU is encrypted using NAS security. In some specific implementations, an MT EDT indication and information indicating the downlink data are received from a mobility management entity (MME) via an S1 application protocol (S1-AP) paging message.

[0114] Figure 6B is a flowchart of an exemplary method 610 for mobile-terminated (MT) early data transmission (EDT). At step 612, the method involves generating a paging message that includes an indication of a contention-free (CF) physical random access channel (PRACH) resource and an early data transmission - radio network temporary identifier (EDT-RNTI) offset. At step 614, the method further includes encoding the paging message for transmission to a user equipment (UE).

[0115] Figure 6A and Figure 6BThe exemplary processes shown may be modified or reconfigured to include additional, fewer, or different steps ( Figure 6A and Figure 6B not shown), which may be performed in the order shown or in a different order.

[0116] Figure 7 FIG. shows an exemplary architecture of a system 700 of a network according to various embodiments. The following description is provided for an example system 700 that operates in conjunction with the LTE system standard and the 5G or NR system standard provided in the 3GPP technical specifications. However, the exemplary embodiments are not limited in this regard, and the embodiments may be applied to other networks that benefit from the principles described herein, such as future 3GPP systems (e.g., sixth generation (6G) systems), IEEE 802.16 protocols (e.g., WMAN, WiMAX, etc.), and the like.

[0117] As Figure 7 shown, the system 700 includes UEs 701a and 701b (collectively referred to as "multiple UEs 701" or "UE 701"). In this example, the multiple UEs 701 are shown as smart phones (e.g., handheld touchscreen mobile computing devices that can connect to one or more cellular networks), but may also include any mobile or non-mobile computing device, such as consumer electronic devices, mobile phones, smart phones, feature phones, tablets, wearable computer devices, personal digital assistants (PDAs), pagers, wireless handheld devices, desktop computers, laptop computers, in-vehicle infotainment (IVI), in-vehicle entertainment (ICE) devices, instrument clusters (IC), head-up display (HUD) devices, on-board diagnostic (OBD) devices, dashtop mobile equipment (DME), mobile data terminals (MDT), electronic engine management systems (EEMS), electronic / engine electronic control units (ECU), electronic / engine electronic control modules (ECM), embedded systems, microcontrollers, control modules, engine management systems (EMS), networked or "smart" home appliances, MTC devices, M2M, IoT devices, and the like.

[0118] In some embodiments, any one of the plurality of UEs 701 may be an IoT UE, which may include a network access layer designed for low-power IoT applications that utilize short-term UE connections. The IoT UE may utilize technologies such as M2M or MTC to exchange data with an MTC server or device via a PLMN, ProSe, or D2D communication, a sensor network, or an IoT network. The M2M or MTC data exchange may be machine-initiated data exchange. The IoT network describes interconnected IoT UEs, which may include uniquely identifiable embedded computing devices (within the Internet infrastructure) with short-lived connections. The IoT UE may execute background applications (e.g., keep-alive messages, status updates, etc.) to facilitate connections to the IoT network.

[0119] The plurality of UEs 701 may be configured to be communicatively coupled to, for example, the RAN 710. In an embodiment, the RAN 710 may be an NG RAN or 5G RAN, an E-UTRAN, or a legacy RAN such as a UTRAN or GERAN. As used herein, the term "NG RAN" etc. may refer to the RAN 710 operating in an NR or 5G system 700, while the term "E-UTRAN" etc. may refer to the RAN 710 operating in an LTE or 4G system 700. The plurality of UEs 701 respectively utilize connections (or channels) 703 and 704, each connection including a physical communication interface or layer (discussed further below in detail).

[0120] In this example, the connections 703 and 704 are shown as air interfaces to enable communicative coupling and may be consistent with a cellular communication protocol, such as a GSM protocol, a CDMA network protocol, a PTT protocol, a POC protocol, a UMTS protocol, a 3GPP LTE protocol, a 5G protocol, an NR protocol, and / or any other communication protocol discussed herein. In an embodiment, the plurality of UEs 701 may directly exchange communication data via the ProSe interface 705. The ProSe interface 705 may alternatively be referred to as the SL interface 705 and may include one or more logical channels, including but not limited to PSCCH, PSSCH, PSDCH, and PSBCH.

[0121] UE 701b is shown as being configured to access an AP 706 (also referred to as a "WLAN node 706", "WLAN 706", "WLAN terminal 706", "WT 706", etc.) via a connection 707. The connection 707 may include a local wireless connection, such as a connection consistent with any IEEE 802.11 protocol, where the AP 706 will include Wi-Fi Router. In this example, it is shown that AP 706 is connected to the Internet without being connected to the core network of the wireless system (described in further detail below). In various embodiments, UE 701b, RAN 710, and AP 706 may be configured to utilize LWA operations and / or LWIP operations. LWA operations may involve UE 701b in the RRC_CONNECTED state configured by RAN nodes 711a - 711b to utilize the radio resources of LTE and WLAN. LWIP operations may involve UE 701b using the WLAN radio resources (e.g., connection 707) via an IPsec protocol tunnel to authenticate and encrypt the packets (e.g., IP packets) sent through connection 707. IPsec tunneling may include encapsulating the entire original IP packet and adding a new packet header, thus protecting the original header of the IP packet.

[0122] RAN 710 may include one or more AN nodes or RAN nodes 711a and 711b (collectively referred to as "multiple RAN nodes 711" or "RAN nodes 711") that enable connections 703 and 704. As used herein, terms such as "access node", "access point", etc. may describe equipment that provides radio baseband functionality for data and / or voice connections between a network and one or more users. These access nodes may be referred to as BS, gNB, RAN node, eNB, NodeB, RSU, TRxP, or TRP, etc., and may include terrestrial stations (e.g., land access points) or satellite stations that provide coverage within a geographical area (e.g., a cell). As used herein, terms such as "NG RAN node", etc. may refer to RAN node 711 (e.g., gNB) operating in an NR or 5G system 700, while terms such as "E - UTRAN node", etc. may refer to RAN node 711 (e.g., eNB) operating in an LTE or 4G system 700. According to various embodiments, multiple RAN nodes 711 may be implemented as one or more dedicated physical devices such as macrocell base stations and / or low - power (LP) base stations for providing femtocells, picocells, or other similar cells with a smaller coverage area, smaller user capacity, or higher bandwidth compared to macrocells.

[0123] In some embodiments, all or part of the plurality of RAN nodes 711 may be implemented as one or more software entities running on a server computer, as part of a virtual network that may be referred to as a Cloud RAN (CRAN) and / or a virtual baseband unit pool (vBBUP). In these embodiments, the CRAN or vBBUP may implement RAN function splitting, such as PDCP splitting, where the RRC and PDCP layers are operated by the CRAN / vBBUP, and the other L2 protocol entities are operated by the respective RAN nodes 711; MAC / PHY splitting, where the RRC, PDCP, RLC, and MAC layers are operated by the CRAN / vBBUP, and the PHY layer is operated by the respective RAN nodes 711; or "lower PHY" splitting, where the RRC, PDCP, RLC, MAC layers, and the upper part of the PHY layer are operated by the CRAN / vBBUP, and the lower part of the PHY layer is operated by the respective RAN nodes 711. This virtualization framework allows the idle processor cores of the plurality of RAN nodes 711 to execute other virtualized applications. In some specific implementations, a separate RAN node 711 may represent a separate gNB-DU connected to the gNB-CU via a separate F1 interface ( Figure 7 not shown). In these specific implementations, the gNB-DU may include one or more remote radio heads or RFEMs (see, for example, Figure 10 ), and the gNB-CU may be operated by a server (not shown) located in the RAN 710 or by a pool of servers in a manner similar to the CRAN / vBBUP. In addition or alternatively, one or more of the plurality of RAN nodes 711 may be a next-generation eNB (ng-eNB), which is a RAN node that provides E-UTRA user plane and control plane protocol terminations to a plurality of UEs 701 and is connected to a 5GC (e.g., Figure 9 the CN 920) via an NG interface (discussed below).

[0124] In a V2X scenario, one or more of the multiple RAN nodes 711 can be or act as an RSU. The term "road side unit" or "RSU" can refer to any traffic infrastructure entity for V2X communication. The RSU can be implemented in or by a suitable RAN node or a stationary (or relatively stationary) UE, where the RSU implemented in or by a UE can be referred to as a "UE-type RSU", the RSU implemented in or by an eNB can be referred to as an "eNB-type RSU", the RSU implemented in or by a gNB can be referred to as a "gNB-type RSU", and so on. In one example, the RSU is a computing device coupled to a radio frequency circuit located on the road side, and the computing device provides connectivity support to passing vehicle UEs 701 (vUE 701). The RSU can also include an internal data storage circuit for storing intersection map geometries, traffic statistics, media, and applications / software for sensing and controlling ongoing vehicle and pedestrian traffic. The RSU can operate on the 5.9 GHz direct short range communication (DSRC) frequency band to provide extremely low latency communication required for high-speed events, such as collision avoidance, traffic warnings, etc. In addition or alternatively, the RSU can operate on a cellular V2X frequency band to provide the aforementioned low latency communication and other cellular communication services. In addition or alternatively, the RSU can operate as a Wi-Fi hotspot (2.4 GHz frequency band) and / or provide connectivity to one or more cellular networks to provide uplink and downlink communication. Some or all of the computing device and the radio frequency circuit of the RSU can be encapsulated in a weather-resistant package suitable for outdoor installation, and can include a network interface controller to provide a wired connection (e.g., Ethernet) to a traffic signal controller and / or a backhaul network.

[0125] Any one of the multiple RAN nodes 711 can serve as an end point of the air interface protocol and can be the first point of contact for multiple UEs 701. In some embodiments, any one of the multiple RAN nodes 711 can perform various logical functions of the RAN 710, including but not limited to the functions of a radio network controller (RNC), such as radio bearer management, uplink and downlink dynamic radio resource management and data packet scheduling, and mobility management.

[0126] In an embodiment, multiple UEs 701 can be configured to communicate with each other or with any one of the multiple RAN nodes 711 over a multi-carrier communication channel using OFDM communication signals according to various communication technologies, such as but not limited to OFDMA communication technology (e.g., for downlink communication) or SC-FDMA communication technology (e.g., for uplink and ProSe or sidelink communication), although the scope of the embodiment is not limited in this regard. The OFDM signal can include multiple orthogonal subcarriers.

[0127] In some embodiments, a downlink resource grid can be used for downlink transmissions from any one of a plurality of RAN nodes 711 to a plurality of UEs 701, and uplink transmissions can utilize similar techniques. The grid can be a time-frequency grid, referred to as a resource grid or a time-frequency resource grid, which is the physical resources in the downlink in each time slot. For an OFDM system, such a time-frequency plane representation is a common practice, which makes radio resource allocation intuitive. Each column and each row of the resource grid corresponds to an OFDM symbol and an OFDM subcarrier, respectively. The duration of the resource grid in the time domain corresponds to one time slot in a radio frame. The smallest time-frequency unit in the resource grid is represented as a resource element. Each resource grid includes a plurality of resource blocks, which describe the mapping of certain physical channels to resource elements. Each resource block includes a set of resource elements; in the frequency domain, this can represent the smallest amount of resources that can be currently allocated. Such resource blocks are used to transmit several different physical downlink channels.

[0128] According to various embodiments, a plurality of UEs 701 and a plurality of RAN nodes 711 transmit data (e.g., send data and receive data) via a licensed medium (also referred to as "licensed spectrum" and / or "licensed band") and an unlicensed shared medium (also referred to as "unlicensed spectrum" and / or "unlicensed band"). The licensed spectrum can include channels operating in a frequency range of approximately 400 MHz to approximately 3.8 GHz, while the unlicensed spectrum can include the 5 GHz band.

[0129] To operate in the unlicensed spectrum, a plurality of UEs 701 and a plurality of RAN nodes 711 can use LAA, eLAA, and / or feLAA mechanisms to operate. In these specific implementations, a plurality of UEs 701 and a plurality of RAN nodes 711 can perform one or more known medium sensing operations and / or carrier sensing operations to determine whether one or more channels in the unlicensed spectrum are unavailable or otherwise occupied before transmitting in the unlicensed spectrum. The medium / carrier sensing operations can be performed according to the listen-before-talk (LBT) protocol.

[0130] LBT is a mechanism by which devices (e.g., multiple UEs 701, multiple RAN nodes 711, etc.) sense the medium (e.g., a channel or carrier frequency) and transmit when the medium is sensed as idle (or when a specific channel in the medium is sensed as unoccupied). The medium sensing operation may include CCA, which uses at least ED to determine whether there are other signals on the channel to determine whether the channel is occupied or idle. The LBT mechanism allows cellular / LAA networks to coexist with existing systems in the unlicensed spectrum and with other LAA networks. ED may include sensing RF energy on the expected transmission band over a period of time and comparing the sensed RF energy with a predefined or configured threshold.

[0131] Generally, existing systems in the 5GHz band are WLANs based on IEEE 802.11 technology. WLANs adopt a contention-based channel access mechanism called CSMA / CA. Here, when a WLAN node (e.g., a mobile station (MS) such as a UE 701, an AP 706, etc.) intends to transmit, the WLAN node may first perform CCA before transmission. Additionally, in the case where more than one WLAN node senses the channel as idle and transmits simultaneously, a backoff mechanism is used to avoid collisions. The backoff mechanism may be a counter randomly introduced within the CWS, which exponentially increases in case of a collision and is reset to the minimum value upon successful transmission. The LBT mechanism designed for LAA is somewhat similar to the CSMA / CA of WLANs. In some specific implementations, the LBT process for DL or UL transmission bursts (including PDSCH or PUSCH transmissions) may have a variable-length LAA contention window between X and Y ECCA time slots, where X and Y are the minimum and maximum values of the LAA's CWS. In one example, the minimum CWS for LAA transmission may be 9 microseconds (ms); however, the size of the CWS and the MCOT (e.g., the transmission burst) may be based on government regulatory requirements.

[0132] The LAA mechanism is built on the CA technology of the LTE-Advanced system. In CA, each aggregated carrier is called a CC. A CC may have a bandwidth of 1.4MHz, 3MHz, 5MHz, 10MHz, 15MHz, or 20MHz, and up to five CCs can be aggregated, so the maximum aggregated bandwidth is 100MHz. In an FDD system, for DL and UL, the number of aggregated carriers may be different, where the number of UL CCs is equal to or lower than the number of DL component carriers. In some cases, each CC may have a different bandwidth from other CCs. In a TDD system, the number of CCs and the bandwidth of each CC are generally the same for DL and UL.

[0133] CA also includes respective serving cells to provide respective CCs. The coverage of the serving cells may vary, e.g., because the CCs on different frequency bands will experience different path losses. The primary serving cell or PCell may provide the PCC for both UL and DL and may handle activities related to RRC and NAS. The other serving cells are called SCell, and each SCell may provide respective SCCs for both UL and DL. SCCs can be added and removed as needed, while changing the PCC may require the UE 701 to undergo a handover. In LAA, eLAA, and feLAA, some or all of the SCell may operate in the unlicensed spectrum (referred to as "LAA SCell"), and the LAA SCell is assisted by the PCell operating in the licensed spectrum. When the UE is configured with more than one LAA SCell, the UE may receive UL grants on the configured LAA SCell indicating different PUSCH starting positions within the same subframe.

[0134] The PDSCH carries user data and higher layer signaling to multiple UEs 701. Among other information, the PDCCH carries information about the transport format and resource allocation related to the PDSCH channel. It can also notify multiple UEs 701 about the transport format, resource allocation, and HARQ information related to the uplink shared channel. Generally, downlink scheduling (allocating control and shared channel resource blocks to the UEs 701b within the cell) can be performed on any of the multiple RAN nodes 711 based on the channel quality information fed back from any of the multiple UEs 701. Downlink resource allocation information can be sent on the PDCCH for each of the multiple UEs 701 (e.g., allocated to).

[0135] The PDCCH uses CCEs to convey control information. Before being mapped to resource elements, the PDCCH complex-valued symbols can first be organized into quadruples and then arranged using a sub-block interleaver for rate matching. One or more of these CCEs can be used to transmit each PDCCH, where each CCE can correspond to nine sets of four physical resource elements each, called REGs. Four quadrature phase shift keying (QPSK) symbols can be mapped to each REG. Depending on the size of the DCI and the channel conditions, one or more CCEs can be used to transmit the PDCCH. There can be four or more different PDCCH formats defined in LTE with different numbers of CCEs (e.g., aggregation levels, L = 1, 2, 4, or 8).

[0136] Some embodiments may use the concept of resource allocation for controlling channel information, which is an extension of the above concept. For example, some embodiments may utilize the EPDCCH that uses PDSCH resources for control information transmission. One or more ECCEs may be used to transmit the EPDCCH. Similar to the above, each ECCE may correspond to nine sets each including four physical resource elements, referred to as EREG. In some cases, an ECCE may have other numbers of EREG.

[0137] A plurality of RAN nodes 711 may be configured to communicate with each other via an interface 712. In an embodiment where the system 700 is an LTE system (e.g., when the CN 720 is an EPC 820 as in Figure 8 ), the interface 712 may be an X2 interface 712. The X2 interface may be defined between two or more RAN nodes 711 (e.g., two or more eNBs, etc.) connected to the EPC 720, and / or between two eNBs connected to the EPC 720. In some specific implementations, the X2 interface may include an X2 user plane interface (X2-U) and an X2 control plane interface (X2-C). The X2-U may provide a flow control mechanism for user packets transmitted through the X2 interface, and may be used to convey information about the delivery of user data between eNBs. For example, the X2-U may provide specific sequence number information about user data transmitted from the MeNB to the SeNB; information about the successful in-sequence delivery of PDCP PDUs from the SeNB to the UE 701 for user data; information about PDCP PDUs not delivered to the UE 701; information about the current minimum desired buffer size at the SeNB for transmitting user data to the UE; and so on. The X2-C may provide access mobility functions within LTE, including context transfer from the source eNB to the target eNB, user plane transmission control, etc.; load management functions; and inter-cell interference coordination functions.

[0138] In an embodiment where the system 700 is a 5G or NR system (e.g., when the CN 720 is Figure 9When it comes to the 5GC 920, the interface 712 can be the Xn interface 712. The Xn interface is defined between two or more RAN nodes 711 (such as two or more gNBs, etc.) connected to the 5GC 720, between a RAN node 711 (such as a gNB) connected to the 5GC 720 and an eNB, and / or between two eNBs connected to the 5GC 720. In some specific embodiments, the Xn interface may include an Xn user plane (Xn-U) interface and an Xn control plane (Xn-C) interface. The Xn-U can provide non-guaranteed delivery of user plane PDUs and support / provide data forwarding and traffic control functions. The Xn-C can provide management and error handling functions for managing the functions of the Xn-C interface; the mobility support for the UE 701 in the connected mode (such as CM connection) includes functions for managing the UE mobility in the connected mode between one or more RAN nodes 711. This mobility support may include context transfer from an old (source) serving RAN node 711 to a new (target) serving RAN node 711; and control of the user plane tunnel between the old (source) serving RAN node 711 and the new (target) serving RAN node 711. The protocol stack of the Xn-U may include a transport network layer built on the Internet Protocol (IP) transport layer, and a GTP-U layer for carrying user plane PDUs on top of the UDP and / or IP layer. The Xn-C protocol stack may include an application layer signaling protocol (referred to as the Xn application protocol (Xn-AP)) and a transport network layer built on SCTP. SCTP can be on top of the IP layer and can provide guaranteed delivery of application layer messages. In the transport IP layer, point-to-point transmission is used to deliver signaling PDUs. In other specific embodiments, the Xn-U protocol stack and / or the Xn-C protocol stack may be the same as or similar to the user plane and / or control plane protocol stacks shown and described herein.

[0139] RAN 710 is shown as communicatively coupled to a core network - in this embodiment, communicatively coupled to core network (CN) 720. The CN 720 may include a plurality of network elements 722 that are configured to provide various data and telecommunications services to customers / users (e.g., users of a plurality of UEs 701) connected to the CN 720 via the RAN 710. Components of the CN 720 may be implemented in one physical node or separate physical nodes and include components for reading and executing instructions from a machine-readable or computer-readable medium (e.g., a non-transitory machine-readable storage medium). In some embodiments, NFV may be used to virtualize any or all of the above network node functions via executable instructions stored in one or more computer-readable storage media (described in further detail below). A logical instance of the CN720 may be referred to as a network slice, and a logical instance of a portion of the CN 720 may be referred to as a network sub-slice. The NFV architecture and infrastructure may be used to virtualize one or more network functions onto physical resources that include a combination of industry-standard server hardware, storage hardware, or switches (alternatively performed by proprietary hardware). In other words, the NFV system may be used to perform a virtual or reconfigurable implementation of one or more EPC components / functions.

[0140] Generally, application server 730 may be an element that provides an application that uses IP bearer resources with the core network (e.g., UMTS PS domain, LTE PS data services, etc.). Application server 730 may also be configured to support one or more communication services (e.g., VoIP sessions, PTT sessions, group communication sessions, social network services, etc.) for a plurality of UEs 701 via the EPC 720.

[0141] In an embodiment, the CN 720 may be a 5GC (referred to as "5GC 720", etc.), and the RAN 710 may be connected to the CN 720 via an NG interface 713. In an embodiment, the NG interface 713 may be divided into two parts: an NG user plane (NG-U) interface 714 that carries traffic data between a RAN node 711 and a UPF; and an S1 control plane (NG-C) interface 715 that is a signaling interface between a plurality of RAN nodes 711 and a plurality of AMFs. Refer to Figure 9 Embodiments where the CN 720 is a 5GC 720 are discussed in more detail.

[0142] In an embodiment, CN 720 can be a 5G CN (referred to as "5GC 720", etc.), while in other embodiments, CN 720 can be an EPC. In the case where CN 720 is an EPC (referred to as "EPC 720", etc.), RAN 710 can be connected to CN 720 via the S1 interface 713. In an embodiment, the S1 interface 713 can be divided into two parts: the S1 user plane (S1-U) interface 714, which carries traffic data between the RAN node 711 and the S-GW; and the S1-MME interface 715, which is a signaling interface between multiple RAN nodes 711 and multiple MMEs.

[0143] Figure 8 An exemplary architecture of a system 800 including a first CN 820 according to various embodiments is shown. In this example, the system 800 can implement the LTE standard, where CN 820 is an EPC 820 corresponding to Figure 7 CN 720. Additionally, UE 801 can be the same as or similar to Figure 7 UE 701, and E-UTRAN 810 can be a RAN that is the same as or similar to Figure 7 RAN 710, and it can include the previously discussed RAN node 711. CN 820 can include an MME 821, an S-GW 822, a P-GW 823, an HSS 824, and an SGSN 825.

[0144] Functionally, MME 821 can be similar to the control plane of a traditional SGSN and can implement MM functions to keep track of the current location of UE 801. MME 821 can perform various MM procedures to manage aspects of mobility during access, such as gateway selection and tracking area list management. MM (also referred to as "EPS MM" or "EMM" in the E-UTRAN system) can refer to all applicable procedures, methods, data storage, etc. for maintaining knowledge of the current location of UE 801, providing user identity confidentiality to the user / subscriber, and / or performing other similar services. Each UE 801 and MME 821 can include an MM or EMM sublayer, and when the attachment process is successfully completed, an MM context can be established in UE 801 and MME 821. The MM context can be a data structure or database object that stores MM-related information of UE 801. MME 821 can be coupled to HSS 824 via the S6a reference point, to SGSN 825 via the S3 reference point, and to S-GW 822 via the S11 reference point.

[0145] The SGSN 825 can be a node that serves the UE 801 by tracking the location of the individual UE 801 and performing security functions. In addition, the SGSN 825 can perform inter-EPC node signaling for mobility between 2G / 3G and E-UTRAN 3GPP access networks; PDN and S-GW selection as specified by the MME 821; handling of the UE 801 time zone function as specified by the MME 821; and MME selection for handover to the E-UTRAN 3GPP access network. The S3 reference point between the MME 821 and the SGSN 825 can be enabled for user and bearer information exchange for 3GPP inter-access network mobility in the idle state and / or the active state.

[0146] The HSS 824 can include a database for network users, which includes subscription-related information for supporting network entity handling of communication sessions. The EPC 820 can include one or several HSS 824s, depending on the number of mobile subscribers, the capacity of the equipment, the organization of the network, etc. For example, the HSS 824 can provide support for routing / roaming, authentication, authorization, naming / addressing solutions, location dependence, etc. The S6a reference point between the HSS 824 and the MME 821 can enable the transfer of subscription and authentication data for authenticating / authorizing user access to the EPC 820 between the HSS 824 and the MME 821.

[0147] The S-GW 822 can terminate the S1 interface 713 ( Figure 8 the “S1-U” in ) towards the RAN 810, and route data packets between the RAN 810 and the EPC 820. Additionally, the S-GW 822 can be a local mobility anchor for inter-RAN node handover, and can also provide an anchor for 3GPP inter-mobility. Other responsibilities can include lawful interception, charging, and enforcement of certain policies. The S11 reference point between the S-GW822 and the MME 821 can provide a control plane between the MME 821 and the S-GW 822. The S-GW 822 can be coupled to the P-GW 823 via the S5 reference point.

[0148] The P-GW 823 can terminate the SGi interface towards the PDN 830. The P-GW 823 can route data packets between the EPC 820 and an external network such as a network including an application server 730 (alternatively referred to as “AF”) via the IP interface 725 (see for example Figure 7 ). In an embodiment, the P-GW 823 can be communicatively coupled to the application server ( Figure 7 ) via the IP communication interface 725 (see for example, Figure 7 the application server 730 of or Figure 8in the PDN 830). The S5 reference point between the P-GW 823 and the S-GW 822 can provide user plane tunneling and tunnel management between the P-GW 823 and the S-GW 822. Due to the mobility of the UE 801 and whether the S-GW 822 needs to connect to a non-collocated P-GW 823 for the required PDN connectivity, the S5 reference point can also be used for S-GW 822 relocation. The P-GW 823 may also include a node for policy enforcement and charging data collection (such as a PCEF (not shown)). Additionally, the SGi reference point between the P-GW 823 and the packet data network (PDN) 830 can be an external public, private PDN of the operator or an internal operator packet data network, for example, to provide IMS services. The P-GW 823 can be coupled to the PCRF 826 via the Gx reference point.

[0149] The PCRF 826 is the policy and charging control element of the EPC 820. In a non-roaming scenario, there may be a single PCRF 826 in the home public land mobile network (HPLMN) associated with the Internet protocol connectivity access network (IP-CAN) session of the UE 801. In a roaming scenario with local traffic breakout, there may be two PCRFs associated with the IP-CAN session of the UE 801: the home PCRF (H-PCRF) in the HPLMN and the visited PCRF (V-PCRF) in the visited public land mobile network (VPLMN). The PCRF 826 can be communicatively coupled to the application server 830 via the P-GW 823. The application server 830 can signal the PCRF 826 to indicate a new service flow and select appropriate QoS and charging parameters. The PCRF 826 can configure the rule to a PCEF (not shown) with appropriate TFT and QCI, and start QoS and charging as specified by the application server 830. The Gx reference point between the PCRF 826 and the P-GW 823 can allow the transmission of QoS policies and charging rules from the PCRF 826 to the PCEF in the P-GW 823. The Rx reference point can reside between the PDN 830 (or "AF 830") and the PCRF 826.

[0150] Figure 9Shows the architecture of a system 900 including a second CN 920 according to various embodiments. System 900 is shown to include a UE 901, which may be the same as or similar to the previously discussed UE 701 and UE 801; a (R)AN 910, which may be the same as or similar to the previously discussed RAN 710 and RAN 810, and which may include the previously discussed RAN node 711; and a DN 903, which may be, for example, a carrier service, Internet access, or a third-party service; and a 5GC 920. 5GC 920 may include an AUSF 922; an AMF 921; an SMF 924; a NEF 923; a PCF 926; an NRF 925; a UDM 927; an AF 928; a UPF 902; and an NSSF 929.

[0151] UPF 902 may act as an anchor point for mobility within and between RATs, an external PDU session point for interconnecting with DN 903, and a branching point for supporting multi-homed PDU sessions. UPF 902 may also perform packet routing and forwarding, perform packet inspection, perform the user plane part of policy rules, legally intercept packets (UP collection), perform traffic usage reporting, perform QoS handling for the user plane (e.g., packet filtering, gating, UL / DL rate enforcement), perform uplink traffic verification (e.g., SDF to QoS flow mapping), perform transport-level packet marking in the uplink and downlink, and perform downlink packet buffering and downlink data notification triggering. UPF 902 may include an uplink classifier to support routing traffic to data networks. DN 903 may represent various network operator services, Internet access, or third-party services. DN 903 may include or be similar to the previously discussed application server 730. UPF 902 may interact with SMF 924 via the N4 reference point between SMF 924 and UPF 902.

[0152] AUSF 922 may store data for the authentication of UE 901 and handle authentication-related functions. AUSF 922 may facilitate a common authentication framework for various access types. AUSF 922 may communicate with AMF 921 via the N12 reference point between AMF 921 and AUSF 922; and may communicate with UDM 927 via the N13 reference point between UDM 927 and AUSF 922. Additionally, AUSF 922 may present an interface based on the Nausf service.

[0153] The AMF 921 can be responsible for registration management (e.g., responsible for registering the UE 901, etc.), connection management, reachability management, mobility management, and lawful interception of AMF-related events, and access authentication and authorization. The AMF 921 can be the termination point of the N11 reference point between the AMF 921 and the SMF 924. The AMF 921 can provide transmission for SM messages between the UE 901 and the SMF 924 and act as a transparent proxy for routing SM messages. The AMF 921 can also provide transmission for SMS messages between the UE 901 and the SMSF ( Figure 9 not shown in the figure). The AMF 921 can act as the SEAF, which can include interactions with the AUSF 922 and the UE 901 and receive the intermediate key established due to the UE 901 authentication process. In the case of using USIM-based authentication, the AMF 921 can retrieve security materials from the AUSF 922. The AMF 921 can also include the SCM function, which receives the key for deriving the access network-specific key from the SEA. In addition, the AMF 921 can be the termination point of the RAN CP interface, which can include or be the N2 reference point between the (R)AN 910 and the AMF 921; and the AMF 921 can be the termination point of the NAS (N1) signaling and perform NAS encryption and integrity protection.

[0154] The AMF 921 can also support NAS signaling with the UE 901 through the N3 IWF interface. The N3IWF can be used to provide access to untrusted entities. The N3IWF can be the termination point of the N2 interface between the (R)AN 910 of the control plane and the AMF 921, and can be the termination point of the N3 reference point between the (R)AN 910 of the user plane and the UPF 902. Therefore, the AMF 921 can process the N2 signaling for PDU sessions and QoS from the SMF 924 and the AMF 921, encapsulate / decapsulate packets for IPSec and N3 tunnels, mark the N3 user plane packets on the uplink, and perform QoS corresponding to the N3 packet marking, taking into account the QoS requirements associated with such markings received through N2. The N3IWF can also relay the uplink and downlink control plane NAS signaling between the UE 901 and the AMF 921 via the N1 reference point between the UE 901 and the AMF 921, and relay the uplink and downlink user plane packets between the UE 901 and the UPF 902. The N3IWF also provides a mechanism for establishing an IPsec tunnel with the UE 901. The AMF 921 can present an interface based on the Namf service and can be the termination point of the N14 reference point between two AMF 921s and the N17 reference point between the AMF 921 and the 5G-EIR ( Figure 9 not shown).

[0155] UE 901 may need to register with the AMF 921 in order to receive network services. The RM is used to register or deregister the UE 901 with the network (e.g., the AMF 921), and to establish a UE context in the network (e.g., the AMF 921). The UE 901 may operate in the RM-REGISTERED state or the RM-DEREGISTERED state. In the RM DEREGISTERED state, the UE 901 is not registered with the network, and the UE context in the AMF 921 does not hold the valid location or routing information of the UE 901, so the AMF 921 cannot reach the UE 901. In the RM REGISTERED state, the UE 901 is registered with the network, and the UE context in the AMF 921 may hold the valid location or routing information of the UE 901, so the AMF 921 can reach the UE 901. In the RM-REGISTERED state, the UE 901 may perform a mobility registration update procedure, perform a periodic registration update procedure triggered by the expiration of a periodic update timer (e.g., to notify the network that the UE 901 is still active), and perform a registration update procedure to update UE capability information or renegotiate protocol parameters with the network, etc.

[0156] The AMF 921 may store one or more RM contexts for the UE 901, where each RM context is associated with a specific access to the network. The RM context may be a data structure, a database object, etc., which indicates or stores, in particular, the registration status and the periodic update timer for each access type. The AMF 921 may also store a 5GC MM context that may be the same as or similar to the previously discussed (E)MM context. In various embodiments, the AMF 921 may store the CE mode B restriction parameters of the UE 901 in the associated MM context or RM context. The AMF 921 may also derive values from the UE usage setting parameters that have been stored in the UE context (and / or MM / RM context) when needed.

[0157] CM can be used to establish and release a signaling connection between UE 901 and AMF 921 via the N1 interface. The signaling connection is used to enable NAS signaling exchange between UE 901 and CN 920, and includes a signaling connection between the UE and the AN (e.g., an RRC connection for non-3GPP access or a UE-N3IWF connection) and an N2 connection of UE 901 between the AN (e.g., RAN 910) and AMF 921. UE 901 can operate in one of two CM states (CM-IDLE mode or CM-CONNECTED mode). When UE 901 operates in the CM-IDLE state / mode, UE 901 may not have a NAS signaling connection established with AMF 921 via the N1 interface, and there may be an (R)AN 910 signaling connection for UE 901 (e.g., N2 and / or N3 connections). When UE 901 operates in the CM-CONNECTED state / mode, UE 901 may have a NAS signaling connection established with AMF 921 via the N1 interface, and there may be an (R)AN 910 signaling connection for UE 901 (e.g., N2 and / or N3 connections). Establishing an N2 connection between (R)AN 910 and AMF 921 may cause UE 901 to transition from the CM-IDLE mode to the CM-CONNECTED mode, and when the N2 signaling between (R)AN 910 and AMF 921 is released, UE 901 may transition from the CM-CONNECTED mode to the CM-IDLE mode.

[0158] The SMF 924 may be responsible for SM (e.g., session establishment, modification, and release, including tunnel maintenance between the UPF and the AN node); UE IP address allocation and management (including optional authorization); selection and control of the UPF function; configuring the traffic steering of the UPF to route traffic to the correct destination; terminating the interface towards the policy control function; the policy enforcement and the control part of QoS; lawful interception (for SM events and the interface with the LI system); terminating the SM part of the NAS message; downlink data notification; initiating AN-specific SM information sent to the AN via the AMF over N2; and determining the SSC mode of the session. SM may refer to the management of the PDU session, and the PDU session or "session" may refer to the PDU connectivity service that provides or enables the PDU exchange between the UE 901 identified by the data network name (DNN) and the data network (DN) 903. The PDU session can be established upon request by the UE 901 using the NAS SM signaling exchanged between the UE 901 and the SMF 924 over the N1 reference point, modified upon request by the UE 901 and the 5GC 920, and released upon request by the UE 901 and the 5GC 920. When requested from the application server, the 5GC 920 may trigger a specific application in the UE 901. In response to receiving the trigger message, the UE 901 may pass the trigger message (or the relevant part / information of the trigger message) to one or more identified applications in the UE 901. The identified applications in the UE 901 may establish a PDU session to a specific DNN. The SMF 924 may check whether the UE 901 request complies with the user subscription information associated with the UE 901. In this regard, the SMF 924 may retrieve and / or request to receive an update notification on the subscription data at the SMF 924 level from the UDM 927.

[0159] The SMF 924 may include the following roaming functions: handling local enforcement to apply the QoS SLA (VPLMN); charging data collection and charging interface (VPLMN); lawful interception (for SM events and the interface with the LI system, in the VPLMN); and supporting the interaction with the external DN to transmit the signaling for PDU session authorization / authentication via the external DN. In the roaming scenario, the N16 reference point between two SMF 924s may be included in the system 900, which may be between the SMF 924 in the visited network and another SMF 924 in the home network. Additionally, the SMF 924 may present an interface based on the Nsmf service.

[0160] The NEF 923 can provide components for securely exposing the services and capabilities provided by 3GPP network functions to third parties, internal exposure / re - exposure, application functions (e.g., AF 928), edge computing or fog computing systems, etc. In such embodiments, the NEF 923 can authenticate, authorize, and / or restrict the AF. The NEF 923 can also transform the information exchanged with the AF 928 and the information exchanged with internal network functions. For example, the NEF 923 can transform between AF service identifiers and internal 5GC information. The NEF 923 can also receive information from other network functions (NFs) based on the exposure capabilities of the other NFs. This information can be stored at the NEF 923 as structured data, or stored at a data - storing NF using a standardized interface. Then, the stored information can be re - exposed by the NEF 923 to other NFs and AFs, and / or used for other purposes such as analysis. Additionally, the NEF 923 can present an interface based on the Nnef service.

[0161] The NRF 925 can support the service discovery function, receive NF discovery requests from NF instances, and provide information about the discovered NF instances to NF instances. The NRF 925 also maintains information about available NF instances and the services they support. As used herein, terms such as "instantiation" can refer to the creation of an instance, and an "instance" can refer to a specific occurrence of an object, which can occur, for example, during the execution of program code. Additionally, the NRF 925 can present an interface based on the Nnrf service.

[0162] The PCF 926 can provide control - plane functions for executing their policy rules and can also support a unified policy framework for managing network behavior. The PCF 926 can also implement an FE to access subscription information related to policy decisions in the UDR of the UDM 927. The PCF 926 can communicate with the AMF 921 via the N15 reference point between the PCF 926 and the AMF 921, which can include the PCF 926 in the visited network and the AMF 921 in a roaming scenario. The PCF 926 can communicate with the AF 928 via the N5 reference point between the PCF 926 and the AF 928; and communicate with the SMF 924 via the N7 reference point between the PCF 926 and the SMF 924. The system 900 and / or the CN 920 can also include an N24 reference point between the PCF 926 (in the home network) and the PCF 926 (in the visited network). Additionally, the PCF 926 can present an interface based on the Npcf service.

[0163] The UDM 927 can process subscription-related information to support the handling of communication sessions by network entities and can store the subscription data of the UE 901. For example, subscription data can be transmitted between the UDM 927 and the AMF 921 via the N8 reference point between the UDM 927 and the AMF. The UDM 927 can include two parts: the Application FE and the UDR( Figure 9 (the FE and the UDR are not shown). The UDR can store the subscription data and policy data of the UDM 927 and the PCF 926, and / or the structured data for exposure and application data of the NEF 923 (including the PFD for application detection, the application request information of multiple UEs 901). The Nudr service-based interface can be presented by the UDR 221 to allow the UDM 927, the PCF 926, and the NEF 923 to access a specific set of stored data, as well as read, update (e.g., add, modify), delete, and subscribe to notifications of relevant data changes in the UDR. The UDM can include the UDM-FE, which is responsible for handling credentials, location management, subscription management, etc. In different transactions, several different front-ends can serve the same user. The UDM-FE accesses the subscription information stored in the UDR and performs authentication credential processing, user identification processing, access authorization, registration / mobility management, and subscription management. The UDR can interact with the SMF 924 via the N10 reference point between the UDM 927 and the SMF 924. The UDM 927 can also support SMS management, where the SMS-FE implements similar application logic as described above. Additionally, the UDM 927 can present a Nudm service-based interface.

[0164] The AF 928 can provide the influence of the application on traffic routing, provide access to the NCE, and interact with the policy framework for policy control. The NCE can be a mechanism that allows the 5GC 920 and the AF 928 to provide information to each other via the NEF 923, which can be used for edge computing implementations. In such implementations, network operators and third-party services can be hosted near the attachment UE 901 access point to achieve effective service delivery with reduced end-to-end latency and load on the transport network. For edge computing implementations, the 5GC can select the UPF 902 near the UE 901 and perform traffic steering from the UPF 902 to the DN 903 via the N6 interface. This can be based on the UE subscription data, the UE location, and the information provided by the AF 928. In this way, the AF 928 can affect the UPF (re)selection and traffic routing. Based on the operator deployment, when the AF 928 is considered a trusted entity, the network operator can allow the AF 928 to directly interact with the relevant NF. Additionally, the AF 928 can present a Naf service-based interface.

[0165] The NSSF 929 selects a set of network slice instances that can serve the UE 901. If needed, the NSSF 929 can also determine the allowed NSSAI and the mapping to the subscribed S-NSSAI. The NSSF 929 can also determine, based on appropriate configuration and possibly by querying the NRF 925, the set of AMFs, or a list of candidate AMFs 921, for serving the UE 901. The selection of a set of network slice instances for the UE 901 can be triggered by the AMF 921, where the UE 901 registers by interacting with the NSSF 929, which can cause the AMF 921 to change. The NSSF 929 can interact with the AMF 921 via the N22 reference point between the AMF 921 and the NSSF 929; and can communicate with another NSSF 929 in the visited network via the N31 reference point ( Figure 9 not shown). Additionally, the NSSF 929 can expose an interface based on the Nnssf service.

[0166] As previously discussed, the CN 920 can include an SMSF, which can be responsible for SMS subscription checking and verification, and relaying SM messages to / from the UE 901 to / from other entities such as the SMS-GMSC / IWMSC / SMS router. The SMS can also interact with the AMF 921 and the UDM 927 for a notification procedure for which the UE 901 can be used for SMS transmission (e.g., setting the UE unreachable flag and notifying the UDM 927 when the UE 901 is available for SMS).

[0167] The CN 120 can also include Figure 9 other elements not shown, such as a data storage system / architecture, 5G-EIR, SEPP, etc. The data storage system can include SDSF, UDSF, etc. Any NF can store unstructured data into the UDSF (e.g., UE context) or retrieve it from the UDSF via the N18 reference point between any NF and the UDSF ( Figure 9 not shown). A single NF can share the UDSF for storing its respective unstructured data, or each NF can have its own UDSF located at or near the single NF. Additionally, the UDSF can expose an interface based on the Nudsf service ( Figure 9 not shown). The 5G-EIR can be an NF that checks the status of the PEI to determine whether to blacklist a specific piece of equipment / entity from the network; and the SEPP can be a non-transparent proxy that performs topology hiding, message filtering, and policing on the inter-PLMN control plane interface.

[0168] Additionally, there can be more reference points and / or service-based interfaces between NF services in the NF; however, for clarity, Figure 9These interfaces and reference points are omitted. In one embodiment, CN 920 may include an Nx interface, which is an inter-CN interface between the MME (e.g., MME 821) and the AMF 921 to enable interoperability between CN 920 and CN 820. Other example interfaces / reference points may include an interface based on N5g-EIR services presented by the 5G-EIR, an N27 reference point between the NRF in the visited network and the NRF in the home network; and an N31 reference point between the NSSF in the visited network and the NSSF in the home network.

[0169] Figure 10 An example of infrastructure equipment 1000 according to various embodiments is shown. Infrastructure equipment 1000 (or "system 1000") may be implemented as a base station, a radio headend, a RAN node (such as the RAN nodes 711 and / or the AP 706 shown and described previously), an application server 730, and / or any other element / device discussed herein. In other examples, system 1000 may be implemented in or by a UE.

[0170] System 1000 includes: an application circuit 1005, a baseband circuit 1010, one or more radio frequency front-end modules (RFEMs) 1015, a memory circuit 1020, a power management integrated circuit (PMIC) 1025, a power splitter circuit 1030, a network controller circuit 1035, a network interface connector 1040, a satellite positioning circuit 1045, and a user interface 1050. In some embodiments, device 1000 may include additional elements, such as, for example, a memory / storage device, a display, a camera, a sensor, or an input / output (I / O) interface. In other embodiments, these components may be included in more than one device. For example, the circuits may be separately included in more than one device for CRAN, vBBU, or other similar implementations.

[0171] The application circuit 1005 may include circuitry such as, but not limited to, one or more processors (or processor cores), cache memory, and one or more of the following: a low-dropout regulator (LDO), an interrupt controller, a serial interface such as SPI, I2C, or a general-purpose programmable serial interface module, a real-time clock (RTC), a timer-counter including an interval timer and a watchdog timer, general-purpose input / output (I / O or IO), a memory card controller such as a Secure Digital (SD) Multimedia Card (MMC) or the like, a Universal Serial Bus (USB) interface, a Mobile Industry Processor Interface (MIPI) interface, and a Joint Test Action Group (JTAG) test access port. The processor (or core) of the application circuit 1005 may be coupled to or may include memory / storage elements and may be configured to execute instructions stored in the memory / storage device to enable various applications or operating systems to run on the system 1000. In some embodiments, the memory / storage elements may be on-chip memory circuitry that may include any suitable volatile and / or non-volatile memory such as DRAM, SRAM, EPROM, EEPROM, flash memory, solid-state memory, and / or any other type of memory device technology such as those discussed herein.

[0172] The processor of the application circuit 1005 may include, for example, one or more processor cores (CPUs), one or more application processors, one or more graphics processing units (GPUs), one or more reduced instruction set computing (RISC) processors, one or more Acorn RISC Machine (ARM) processors, one or more complex instruction set computing (CISC) processors, one or more digital signal processors (DSPs), one or more FPGAs, one or more PLDs, one or more ASICs, one or more microprocessors or controllers, or any suitable combination thereof. In some embodiments, the application circuit 1005 may include or may be a dedicated processor / controller for operating in accordance with the various embodiments herein. As an example, the processor of the application circuit 1005 may include one or more Apple A-series processors, Intel or processors; Advanced Micro Devices (AMD) processors, accelerated processing units (APUs), or processors; ARM-based processors licensed by ARM Holdings, Ltd., such as the ARM Cortex-A series processors provided by Cavium(TM), Inc., and MIPS-based designs from MIPS Technologies, Inc., such as MIPS Warrior P-class processors; and so on. In some embodiments, system 1000 may not utilize application circuitry 1005 and, instead, may include a dedicated processor / controller to process, for example, IP data received from the EPC or 5GC.

[0173] In some implementations, application circuitry 1005 may include one or more hardware accelerators, which may be microprocessors, programmable processing devices, and so on. The one or more hardware accelerators may include, for example, computer vision (CV) and / or deep learning (DL) accelerators. For example, the programmable processing device may be one or more field programmable devices (FPDs), such as field programmable gate arrays (FPGAs), and so on; programmable logic devices (PLDs), such as complex PLDs (CPLDs), high-capacity PLDs (HCPLDs), and so on; ASICs, such as structured ASICs, and so on; programmable system-on-chips (PSoCs); and so on. In such embodiments, the circuitry of application circuitry 1005 may include logic blocks or logic architectures, as well as other interconnected resources that may be programmed to perform various functions, such as the processes, methods, functions, and so on, of the various embodiments discussed herein. In such embodiments, the circuitry of application circuitry 1005 may include memory units (e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, static memory (e.g., static random access memory (SRAM), antifuse, and so on)) for storing logic blocks, logic architectures, data, and so on in look-up tables (LUTs), and so on.

[0174] Baseband circuitry 1010 may be implemented as, for example, a soldered-in substrate that includes one or more integrated circuits, a single-packaged integrated circuit soldered to the main circuit board, or a multi-chip module that includes two or more integrated circuits. Various hardware electronic components of baseband circuitry 1010 are discussed below with reference to Figure 12 discussed the various hardware electronic components of baseband circuitry 1010.

[0175] User interface circuitry 1050 may include one or more user interfaces designed to enable a user to interact with system 1000 or a peripheral component interface designed to enable peripheral components to interact with system 1000. The user interface may include, but is not limited to, one or more physical or virtual buttons (e.g., reset buttons), one or more indicators (e.g., light-emitting diodes (LEDs)), a physical keyboard or keypad, a mouse, a touchpad, a touch screen, a speaker or other audio-emitting device, a microphone, a printer, a scanner, a headset, a display screen or display device, and so on. The peripheral component interface may include, but is not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, a power interface, and so on.

[0176] The radio front end module (RFEM) 1015 may include a millimeter wave (mmWave) RFEM and one or more sub-millimeter wave radio frequency integrated circuits (RFICs). In some implementations, the one or more sub-millimeter wave RFICs may be physically separated from the mmWave RFEM. The RFIC may include one or more antennas or antenna arrays (see, e.g., below). Figure 12 The antenna array 1211 is a connector and the RFEM can be connected to multiple antennas. In an alternative implementation, both millimeter wave and sub-millimeter wave radio functions can be implemented in the same physical RFEM 1015 incorporating both millimeter wave antennas and sub-millimeter waves.

[0177] The memory circuit 1020 may include one or more of the following: a volatile memory including a dynamic random access memory (DRAM) and / or a synchronous dynamic random access memory (SDRAM), a non-volatile memory (NVM) including a high-speed electrically erasable memory (commonly referred to as a "flash memory"), a phase change random access memory (PRAM), a magnetoresistive random access memory (MRAM), etc., and may be combined with a memory device obtained from and The memory circuit 1020 may be implemented as one or more of the following: a solder-in package integrated circuit, a socket memory module, and a plug-in memory card.

[0178] The PMIC 1025 may include a voltage regulator, a surge protector, a power alarm detection circuit, and one or more backup power sources, such as a battery or capacitor. The power alarm detection circuit may detect one or more of a brownout (undervoltage) and a surge (overvoltage) condition. The power tee circuit 1030 may provide power extracted from a network cable to provide both power and data connections for the infrastructure equipment 1000 using a single cable.

[0179] The network controller circuit 1035 may provide connectivity to the network using a standard network interface protocol such as Ethernet, Ethernet based on a GRE tunnel, Ethernet based on a multi-protocol label switching (MPLS), or some other suitable protocol. A physical connection may be used to provide a network connection to / from the infrastructure equipment 1000 via a network interface connector 1040, which may be an electrical connection (commonly referred to as a "copper interconnect"), an optical connection, or a wireless connection. The network controller circuit 1035 may include one or more dedicated processors and / or FPGAs for communicating using one or more of the aforementioned protocols. In some implementations, the network controller circuit 1035 may include multiple controllers for providing connectivity to other networks using the same or different protocols.

[0180] The positioning circuit 1045 includes circuitry for receiving and decoding signals transmitted / broadcast by a positioning network of a Global Navigation Satellite System (or GNSS). Examples of navigation satellite constellations (or GNSS) include the Global Positioning System (GPS) of the United States, the Global Navigation Satellite System (GLONASS) of Russia, the Galileo system of the European Union, the Beidou Navigation Satellite System of China, regional navigation systems, or GNSS augmentation systems (e.g., navigation using the Indian Constellation (NAVIC), the Quasi-Zenith Satellite System (QZSS) of Japan, the Doppler Orbitography and Radio-positioning Integrated by Satellite (DORIS) of France, etc.). The positioning circuit 1045 includes various hardware elements (e.g., including hardware devices for facilitating OTA communication such as switches, filters, amplifiers, antenna elements, etc.) to communicate with components of the positioning network such as navigation satellite constellation nodes. In some embodiments, the positioning circuit 1045 may include a Microtechnology for Positioning, Navigation, and Timing (Micro-PNT) IC that uses a primary timing clock to perform position tracking / estimation without GNSS assistance. The positioning circuit 1045 may also be part of or interact with the baseband circuit 1010 and / or the RFEM 1015 to communicate with nodes and components of the positioning network. The positioning circuit 1045 may also provide position data and / or time data to the application circuit 1005, which may use this data to synchronize operations with various infrastructure (e.g., RAN node 711, etc.).

[0181] Figure 10 The components shown may communicate with each other using an interface circuit, which may include any number of bus and / or interconnect (IX) technologies such as Industry Standard Architecture (ISA), Extended ISA (EISA), Peripheral Component Interconnect (PCI), Peripheral Component Interconnect Extended (PCIx), PCI Express (PCIe), or any number of other technologies. The bus / IX may be a proprietary bus, e.g., used in an SoC-based system. Other bus / IX systems may be included, such as I2C interface, SPI interface, point-to-point interface, and power bus, etc.

[0182] Figure 11 An example of a platform 1100 (or “device 1100”) is shown according to various embodiments. In an embodiment, the computer platform 1100 may be adapted to be used as a UE 701, 801, 901, an application server 730, and / or any other element / device discussed herein. The platform 1100 may include any combination of the components shown in the example. The components of the platform 1100 may be implemented as an integrated circuit (IC), a portion of an IC, discrete electronic devices, or other modules, logic, hardware, software, firmware, or combinations thereof adapted within the computer platform 1100, or as components otherwise incorporated within the chassis of a larger system. Figure 11The block diagram is intended to show a high-level view of the components of computer platform 1100. However, some of the components shown may be omitted, additional components may be present, and different arrangements of the components shown may occur in other specific implementations.

[0183] Application circuitry 1105 includes circuitry such as, but not limited to, one or more processors (or processor cores), cache memory, and one or more of an LDO, an interrupt controller, a serial interface (such as SPI), I2C or a general-purpose programmable serial interface module, an RTC, timers (including interval timers and watchdog timers), general-purpose I / O, a memory card controller (such as an SD MMC or similar controller), a USB interface, a MIPI interface, and a JTAG test access port. The processor (or core) of application circuitry 1105 may be coupled to or may include memory / storage elements and may be configured to execute instructions stored in the memory / storage device to enable various applications or operating systems to run on system 1100. In some specific implementations, the memory / storage elements may be on-chip memory circuitry that may include any suitable volatile and / or non-volatile memory, such as DRAM, SRAM, EPROM, EEPROM, flash memory, solid-state memory, and / or any other type of memory device technology, such as those discussed herein.

[0184] The processor of application circuitry 1005 may include, for example, one or more processor cores, one or more application processors, one or more GPUs, one or more RISC processors, one or more ARM processors, one or more CISC processors, one or more DSPs, one or more FPGAs, one or more PLDs, one or more ASICs, one or more microprocessors or controllers, a multi-threaded processor, an ultra-low voltage processor, an embedded processor, some other known processing elements, or any suitable combination thereof. In some embodiments, application circuitry 1005 may include or may be a dedicated processor / controller for operating in accordance with the various embodiments herein.

[0185] As an example, the processor of application circuitry 1105 may include an Apple A-series processor. The processor of application circuitry 1105 may also be one or more of the following: a processor based on Architecture Core TM such as Quark TM 、Atom TM 、i3, i5, i7 or MCU-class processors, or may be available from Another such processor from Corporation, Santa Clara, CA; Advanced Micro Devices (AMD) A processor or an accelerated processing unit (APU); from Snapdragon from Technologies, Inc. TM Processors, Texas Instruments, Open Multimedia Applications Platform (OMAP) TM Processors; MIPS-based designs from MIPS Technologies, Inc., such as MIPS Warrior M-class, Warrior I-class, and Warrior P-class processors; ARM-based designs licensed from ARM Holdings, Ltd., such as ARM Cortex-A, Cortex-R, and Cortex-M series processors; etc. In some specific embodiments, the application circuitry 1105 may be part of a system-on-chip (SoC), where the application circuitry 1105 and other components are formed as a single integrated circuit.

[0186] In addition or alternatively, the application circuitry 1105 may include circuitry such as, but not limited to, one or more field programmable devices (FPDs) such as FPGAs, etc.; programmable logic devices (PLDs), such as complex PLDs (CPLDs), high-capacity PLDs (HCPLDs), etc.; ASICs, such as structured ASICs, etc.; programmable SoCs (PSoCs); and so on. In such embodiments, the circuitry of the application circuitry 1105 may include logic blocks or logic architectures, as well as other interconnect resources that can be programmed to perform various functions such as the processes, methods, functions, etc. of the various embodiments discussed herein. In such embodiments, the circuitry of the application circuitry 1105 may include memory units (e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, static memory (e.g., static random access memory (SRAM), antifuse, etc.)) for storing logic blocks, logic architectures, data, etc. in look-up tables (LUTs), etc.

[0187] The baseband circuitry 1110 may be implemented as, for example, a soldered-in substrate that includes one or more integrated circuits, a single packaged integrated circuit soldered to the main circuit board, or a multi-chip module that includes two or more integrated circuits. The various hardware electronic components of the baseband circuitry 1110 are discussed below with reference to Figure 12 discussed the various hardware electronic components of the baseband circuitry 1110.

[0188] The RFEM 1115 may include a millimeter-wave (mmWave) RFEM and one or more sub-millimeter-wave radio frequency integrated circuits (RFICs). In some embodiments, the one or more sub-millimeter-wave RFICs may be physically separated from the millimeter-wave RFEM. The RFIC may include connections to one or more antennas or antenna arrays (see, for example, antenna array 1211 below Figure 12 ), and the RFEM may be connected to multiple antennas. In an alternative embodiment, the radio functions of both millimeter-wave and sub-millimeter-wave may be implemented in the same physical RFEM 1115 that combines millimeter-wave antennas and sub-millimeter-waves.

[0189] The memory circuit 1120 may include any number and type of memory devices for providing a given amount of system memory. For example, the memory circuit 1120 may include one or more of the following: volatile memory, which includes random access memory (RAM), dynamic RAM (DRAM), and / or synchronous dynamic RAM (SDRAM); and non-volatile memory (NVM), which includes high-speed electrically erasable memory (commonly known as flash memory), phase change random access memory (PRAM), magnetoresistive random access memory (MRAM), etc. The memory circuit 1120 may be developed according to Joint Electron Device Engineering Council (JEDEC) low-power double data rate (LPDDR)-based designs such as LPDDR2, LPDDR3, LPDDR4, etc. The memory circuit 1120 may be implemented as one or more of the following: a soldered-in package integrated circuit, a single-die package (SDP), a dual-die package (DDP), or a quad-die package (Q17P), a socketed memory module, a dual in-line memory module (DIMM) including a micro DIMM or a mini DIMM, and / or soldered to a motherboard via a ball grid array (BGA). In a low-power embodiment, the memory circuit 1120 may be an on-chip memory or register associated with the application circuit 1105. To provide persistent storage of information such as data, applications, operating systems, etc., the memory circuit 1120 may include one or more mass storage devices, which may particularly include solid-state disk drives (SSDDs), hard disk drives (HDDs), micro-HDDs, resistive change memories, phase change memories, holographic memories, or chemical memories, etc. For example, the computer platform 1100 may incorporate 3D cross-point (XPOINT) memory obtained from and .

[0190] The removable memory circuit 1123 may include devices, circuits, enclosures / casings, ports, or sockets, etc. for coupling a portable data storage device to the platform 1100. These portable data storage devices can be used for mass storage and may include, for example, flash memory cards (e.g., Secure Digital (SD) cards, micro SD cards, xD Picture cards, etc.), as well as USB flash drives, optical discs, external HDDs, etc.

[0191] The platform 1100 may also include interface circuitry (not shown) for connecting external devices to the platform 1100. External devices connected to the platform 1100 via this interface circuitry include sensor circuit 1121 and electromechanical components (EMC) 1122, as well as a removable memory device coupled to the removable memory circuit 1123.

[0192] The sensor circuit 1121 includes devices, modules, or subsystems aimed at detecting events or changes in its environment and sending information (sensor data) about the detected events to some other device, module, subsystem, etc. Examples of such sensors particularly include: inertial measurement units (IMUs) including accelerometers, gyroscopes, and / or magnetometers; microelectromechanical systems (MEMS) or nanoelectromechanical systems (NEMS) including three-axis accelerometers, three-axis gyroscopes, and / or magnetometers; level sensors; flow sensors; temperature sensors (e.g., thermistors); pressure sensors; barometric pressure sensors; gravimeters; altimeters; image capture devices (e.g., cameras or lensless apertures); light detection and ranging (LiDAR) sensors; proximity sensors (e.g., infrared radiation detectors, etc.), depth sensors, ambient light sensors, ultrasonic transceivers; microphones or other similar audio capture devices; etc.

[0193] The EMC 1122 includes devices, modules, or subsystems aimed at enabling the platform 1100 to change its state, position, and / or orientation or move or control mechanisms or (sub)systems. Additionally, the EMC 1122 may be configured to generate messages / signaling and send messages / signaling to other components of the platform 1100 to indicate the current state of the EMC 1122. The EMC 1122 includes one or more power switches, relays (including electromechanical relays (EMRs) and / or solid-state relays (SSRs)), actuators (e.g., valve actuators, etc.), audible sound generators, visual warning devices, motors (e.g., DC motors, stepper motors, etc.), wheels, thrusters, propellers, claws, clamps, hooks, and / or other similar electromechanical components. In an embodiment, the platform 1100 is configured to operate one or more EMC 1122 based on one or more capture events and / or instructions or control signals received from a service provider and / or various clients.

[0194] In some specific implementations, the interface circuit can connect the platform 1100 to the positioning circuit 1145. The positioning circuit 1145 includes circuitry for receiving and decoding signals transmitted / broadcast by the positioning network of GNSS. Examples of navigation satellite constellations (or GNSS) can include GPS in the United States, GLONASS in Russia, the Galileo system in the European Union, the Beidou Navigation Satellite System in China, regional navigation systems, or GNSS augmentation systems (e.g., NAVIC, QZSS in Japan, DORIS in France, etc.). The positioning circuit 1145 includes various hardware components (e.g., including hardware devices for facilitating OTA communication such as switches, filters, amplifiers, antenna elements, etc.) to communicate with components of the positioning network such as navigation satellite constellation nodes. In some embodiments, the positioning circuit 1145 can include a micro PNT IC that uses a primary timing clock to perform position tracking / estimation without GNSS assistance. The positioning circuit 1145 can also be part of or interact with the baseband circuit 1010 and / or the RFEM 1115 to communicate with nodes and components of the positioning network. The positioning circuit 1145 can also provide position data and / or time data to the application circuit 1105, which can use this data to synchronize operations with various infrastructures (e.g., radio base stations) for turn-by-turn navigation applications, etc.

[0195] In some specific implementations, the interface circuit can connect the platform 1100 to the near field communication (NFC) circuit 1140. The NFC circuit 1140 is configured to provide non-contact short-range communication based on the radio frequency identification (RFID) standard, where magnetic field sensing is used to enable communication between the NFC circuit 1140 and NFC-enabled devices external to the platform 1100 (e.g., "NFC contact points"). The NFC circuit 1140 includes an NFC controller coupled to an antenna element and a processor coupled to the NFC controller. The NFC controller can be a chip / IC that provides NFC functionality to the NFC circuit 1140 by executing NFC controller firmware and an NFC stack. The NFC stack can be executed by the processor to control the NFC controller, and the NFC controller firmware can be executed by the NFC controller to control the antenna element to transmit short-range RF signals. The RF signals can power a passive NFC tag (e.g., a microchip embedded in a sticker or wristband) to transfer stored data to the NFC circuit 1140, or initiate data transfer between the NFC circuit 1140 and another active NFC device (e.g., a smart phone or an NFC-enabled POS terminal) close to the platform 1100.

[0196] The drive circuit 1146 may include software elements and hardware elements for controlling specific devices embedded in, attached to, or otherwise communicatively coupled with the platform 1100. The drive circuit 1146 may include respective drivers, allowing other components of the platform 1100 to interact with or control various input / output (I / O) devices that may be present within or connected to the platform 1100. For example, the drive circuit 1146 may include: a display driver for controlling and allowing access to a display device, a touchscreen driver for controlling and allowing access to the touchscreen interface of the platform 1100, a sensor driver for obtaining sensor readings from the sensor circuit 1121 and controlling and allowing access to the sensor circuit 1121, an EMC driver for obtaining the actuator position of the EMC 1122 and / or controlling and allowing access to the EMC 1122, a camera driver for controlling and allowing access to an embedded image capture device, and an audio driver for controlling and allowing access to one or more audio devices.

[0197] A power management integrated circuit (PMIC) 1125 (also referred to as “power management circuit 1125”) may manage the power provided to the various components of the platform 1100. Specifically, relative to the baseband circuit 1110, the PMIC 1125 may control power selection, voltage scaling, battery charging, or DC-DC conversion. When the platform 1100 is capable of being powered by a battery 1130, e.g., when the device is included in the UE701, 801, 901, the PMIC 1125 is typically included.

[0198] In some embodiments, the PMIC 1125 can control or otherwise be part of various power saving mechanisms of the platform 1100. For example, if the platform 1100 is in the RRC_Connected state, in which the platform remains connected to the RAN node because it expects to receive traffic soon, after a period of inactivity, the platform can enter a state called Discontinuous Reception mode (DRX). During this state, the platform 1100 can power down for short intervals, thus saving power. If there is no data traffic activity for an extended period, the platform 1100 can transition to the RRC_Idle state, in which the device is disconnected from the network and does not perform operations such as channel quality feedback, handover, etc. The platform 1100 enters a very low power state and performs paging, in which the device wakes up periodically again to listen for the network and then powers down again. The platform 1100 may not receive data while in this state; to receive data, the platform must transition back to the RRC_Connected state. Additional power saving modes can make the device unavailable to the network for longer than the paging interval (ranging from seconds to hours). During this time, the device is completely unable to connect to the network and can be completely powered down. Any data sent during this time will incur a significant delay, and it is assumed that the delay is acceptable.

[0199] The battery 1130 can power the platform 1100, but in some examples, the platform 1100 can be installed in a fixed location and can have a power source coupled to the power grid. The battery 1130 can be a lithium-ion battery, a metal-air battery such as a zinc-air battery, an aluminum-air battery, a lithium-air battery, etc. In some specific implementations, such as in V2X applications, the battery 1130 can be a typical lead-acid automotive battery.

[0200] In some specific implementations, the battery 1130 can be a "smart battery" that includes or is coupled to a battery management system (BMS) or a battery monitoring integrated circuit. The BMS can be included in the platform 1100 to track the state of charge (SoCh) of the battery 1130. The BMS can be used to monitor other parameters of the battery 1130, such as the state of health (SoH) and state of function (SoF) of the battery 1130 to provide fault prediction. The BMS can communicate information about the battery 1130 to the application circuit 1105 or other components of the platform 1100. The BMS can also include an analog-to-digital (ADC) converter that allows the application circuit 1105 to directly monitor the voltage of the battery 1130 or the current from the battery 1130. Battery parameters can be used to determine actions that the platform 1100 can perform, such as transmission frequency, network operation, sensing frequency, etc.

[0201] A power block or other power source coupled to the power grid can be coupled to the BMS to charge the battery 1130. In some examples, the power block XS30 can be replaced with a wireless power receiver to wirelessly obtain power, for example, through a loop antenna in the computer platform 1100. In these examples, the wireless battery charging circuit can be included in the BMS. The specific charging circuit selected can depend on the size of the battery 1130 and thus on the required current. Charging can be performed using the aviation fuel standards published by the Aviation Fuel Alliance, the Qi wireless charging standards published by the Wireless Power Consortium, or the Rezence charging standards published by the Wireless Power Consortium.

[0202] The user interface circuit 1150 includes various input / output (I / O) devices present within or connected to the platform 1100 and includes one or more user interfaces designed to enable user interaction with the platform 1100 and / or a peripheral component interface designed to enable interaction with peripheral components of the platform 1100. The user interface circuit 1150 includes an input device circuit and an output device circuit. The input device circuit includes any physical or virtual device for accepting input, particularly including one or more physical or virtual buttons (e.g., a reset button), a physical keyboard, a keypad, a mouse, a touchpad, a touchscreen, a microphone, a scanner, a headset, etc. The output device circuit includes any physical or virtual device for displaying information or otherwise communicating information (such as sensor readings, actuator positions, or other similar information). The output device circuit can include any number and / or combination of audio or visual displays, particularly including one or more simple visual outputs / indicators (e.g., binary state indicators (e.g., light-emitting diodes (LEDs)) and multi-character visual outputs, or more complex outputs such as a display device or a touchscreen (e.g., a liquid crystal display (LCD), an LED display, a quantum dot display, a projector, etc.), where the output of characters, graphics, multimedia objects, etc. is generated or produced by the operation of the platform 1100. The output device circuit can also include a speaker or other audio emitting device, a printer, etc. In some embodiments, the sensor circuit 1121 can be used as an input device circuit (e.g., an image capture device, a motion capture device, etc.) and one or more EMCs can be used as an output device circuit (e.g., an actuator for providing haptic feedback, etc.). In another example, an NFC circuit can be included to read an electronic tag and / or connect to another NFC-enabled device, and the NFC circuit includes an NFC controller and a processing device coupled to an antenna element. The peripheral component interface can include, but is not limited to, a non-volatile memory port, a USB port, an audio jack, a power interface, etc.

[0203] Although not shown, the components of platform 1100 may communicate with each other using suitable bus or interconnect (IX) technologies, which may include any number of technologies, including ISA, EISA, PCI, PCIx, PCIe, Time-Triggered Protocol (TTP) systems, FlexRay systems, or any number of other technologies. The bus / IX may be a proprietary bus / IX, for example, used in an SoC-based system. Other bus / IX systems may be included, such as I2C interfaces, SPI interfaces, point-to-point interfaces, and power buses, among others.

[0204] Figure 12 Exemplary components of baseband circuit 1210 and radio front-end module (RFEM) 1215 are shown in accordance with various embodiments. Baseband circuit 1210 corresponds respectively to Figure 10 baseband circuit 1010 and Figure 11 baseband circuit 1110. RFEM 1215 corresponds respectively to Figure 10 RFEM 1015 and Figure 11 RFEM 1115. As shown, RFEM 1215 may include radio frequency (RF) circuit 1206, front-end module (FEM) circuit 1208, and antenna array 1211 coupled together at least as shown.

[0205] Baseband circuit 1210 includes circuits and / or control logic components that are configured to perform various radio / network protocols and radio control functions that enable communication with one or more radio networks via RF circuit 1206. The radio control functions may include, but are not limited to, signal modulation / demodulation, encoding / decoding, radio frequency shifting, etc. In some embodiments, the modulation / demodulation circuit of baseband circuit 1210 may include fast Fourier transform (FFT), precoding, or constellation mapping / demapping functions. In some embodiments, the encoding / decoding circuit of baseband circuit 1210 may include convolutional, tail-biting convolutional, turbo, Viterbi, or low-density parity-check (LDPC) encoder / decoder functions. Embodiments of the modulation / demodulation and encoder / decoder functions are not limited to these examples and may include other suitable functions in other embodiments. Baseband circuit 1210 is configured to process baseband signals received from the receive signal path of RF circuit 1206 and generate baseband signals for the transmit signal path of RF circuit 1206. Baseband circuit 1210 is configured to connect to application circuits 1005 / 1105 (see Figure 10 and Figure 11 ) to generate and process baseband signals and control the operation of RF circuit 1206. Baseband circuit 1210 may handle various radio control functions.

[0206] The foregoing circuitry and / or control logic of the baseband circuit 1210 may include one or more single-core or multi-core processors. For example, the one or more processors may include a 3G baseband processor 1204A, a 4G / LTE baseband processor 1204B, a 5G / NR baseband processor 1204C, or some other baseband processor 1204D for other existing generations, generations under development, or generations to be developed in the future (e.g., sixth generation (6G), etc.). In other embodiments, some or all of the functions of the baseband processors 1204A - 1204D may be included in modules stored in the memory 1204G and may be executed via a central processing unit (CPU) 1204E. In other embodiments, some or all of the functions of the baseband processors 1204A - 1204D may be provided as hardware accelerators (e.g., FPGA, ASIC, etc.) loaded with appropriate bitstreams or logic blocks stored in corresponding memory units. In various embodiments, the memory 1204G may store program code of a real-time operating system (RTOS) that, when executed by the CPU 1204E (or other baseband processor), will cause the CPU 1204E (or other baseband processor) to manage the resources of the baseband circuit 1210, schedule tasks, etc. Examples of RTOSs may include Operating System Embedded (OSE) provided by Nucleus RTOS provided by Mentor TM ,by Mentor Nucleus RTOS provided by TM Mentor Versatile Real-Time Executive (VRTX) provided by Mentor, ThreadX provided by Express ThreadX provided by Express TM ,by FreeRTOS, REX OS provided by, OKL4 provided by Open Kernel (OK) OKL4 provided by Open Kernel (OK), or any other suitable RTOS, such as those discussed herein. Additionally, the baseband circuit 1210 includes one or more audio digital signal processors (DSPs) 1204F. The audio DSP 1204F includes elements for compression / decompression and echo cancellation and may include other suitable processing elements in other embodiments.

[0207] In some embodiments, each of processors 1204A - 1204E includes a respective memory interface to send data to / from memory 1204G. Baseband circuitry 1210 may also include one or more interfaces for communicatively coupling to other circuits / devices, such as an interface for sending data to / receiving data from a memory external to baseband circuitry 1210; an application circuit interface for sending data to / receiving data from application circuits 1005 / 1105 of Figures 10 to X T; an RF circuit interface for sending data to / receiving data from RF circuit 1206 of Figure 12 ; a wireless hardware connection interface for sending data to / receiving data from one or more wireless hardware elements (e.g., near field communication (NFC) components, low power components, components, etc.); and a power management interface for sending power or control signals to / receiving power or control signals from PMIC 1125.

[0208] In an alternative embodiment (which may be combined with the above embodiments), baseband circuitry 1210 includes one or more digital baseband systems that are coupled to each other via an interconnect subsystem and to a CPU subsystem, an audio subsystem, and an interface subsystem. The digital baseband subsystems may also be coupled to a digital baseband interface and a mixed - signal baseband subsystem via another interconnect subsystem. Each of the interconnect subsystems may include a bus system, point - to - point connections, a network - on - chip (NOC) fabric, and / or some other suitable bus or interconnect technology, such as those discussed herein. The audio subsystem may include DSP circuitry, buffer memory, program memory, a voice processing accelerator circuit, data converter circuits such as analog - to - digital converter circuits and digital - to - analog converter circuits, analog circuitry including one or more of amplifiers and filters, and / or other similar components. In one aspect of the present disclosure, baseband circuitry 1210 may include protocol processing circuitry having one or more control circuit instances (not shown) to provide control functions for the digital baseband circuitry and / or the radio frequency circuitry (e.g., radio front - end module 1215).

[0209] Although Figure 12Not shown, but in some embodiments, baseband circuit 1210 includes respective processing devices (e.g., a "multi-protocol baseband processor" or "protocol processing circuitry") for operating one or more wireless communication protocols and respective processing devices for implementing PHY layer functions. In these embodiments, the PHY layer functions include the aforementioned radio control functions. In these embodiments, the protocol processing circuitry operates or implements various protocol layers / entities of one or more wireless communication protocols. In a first example, when baseband circuit 1210 and / or RF circuit 1206 is part of a millimeter wave communication circuit or some other suitable cellular communication circuit, the protocol processing circuitry may operate LTE protocol entities and / or 5G / NR protocol entities. In the first example, the protocol processing circuitry will operate MAC, RLC, PDCP, SDAP, RRC, and NAS functions. In a second example, when baseband circuit 1210 and / or RF circuit 1206 is part of a Wi-Fi communication system, the protocol processing circuitry may operate one or more IEEE-based protocols. In the second example, the protocol processing circuitry will operate Wi-Fi MAC and logical link control (LLC) functions. The protocol processing circuitry may include one or more memory structures (e.g., 1204G) for storing program code and data for operating the protocol functions, and one or more processing cores for executing the program code and performing various operations using the data. Baseband circuit 1210 may also support radio communication for more than one wireless protocol.

[0210] The various hardware elements of baseband circuit 1210 discussed herein may be implemented as, for example, a soldered-in substrate that includes one or more integrated circuits (ICs), a single-packaged integrated circuit soldered to a main circuit board, or a multi-chip module that includes two or more ICs. In one example, the components of baseband circuit 1210 may be appropriately combined in a single chip or single chipset, or disposed on the same circuit board. In another example, some or all of the constituent components of baseband circuit 1210 and RF circuit 1206 may be implemented together, such as, for example, a system-on-chip (SoC) or a system-in-package (SiP). In another example, some or all of the constituent components of baseband circuit 1210 may be implemented as a separate SoC communicatively coupled to RF circuit 1206 (or multiple instances of RF circuit 1206). In yet another example, some or all of the constituent components of baseband circuit 1210 and application circuit 1005 / 1105 may be implemented together as separate SoCs (e.g., a "multi-chip package") mounted to the same circuit board.

[0211] In some embodiments, the baseband circuit 1210 may provide communications compatible with one or more radio technologies. For example, in some embodiments, the baseband circuit 1210 may support communications with E-UTRAN or other WMAN, WLAN, WPAN. Embodiments in which the baseband circuit 1210 is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuits.

[0212] The RF circuit 1206 may enable communication with a wireless network using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuit 1206 may include switches, filters, amplifiers, etc. to facilitate communication with the wireless network. The RF circuit 1206 may include a receive signal path that may include circuitry for downconverting an RF signal received from the FEM circuit 1208 and providing a baseband signal to the baseband circuit 1210. The RF circuit 1206 may also include a transmit signal path that may include circuitry for upconverting a baseband signal provided by the baseband circuit 1210 and providing an RF output signal for transmission to the FEM circuit 1208.

[0213] In some embodiments, the receive signal path of the RF circuit 1206 may include a mixer circuit 1206a, an amplifier circuit 1206b, and a filter circuit 1206c. In some embodiments, the transmit signal path of the RF circuit 1206 may include a filter circuit 1206c and a mixer circuit 1206a. The RF circuit 1206 may also include a synthesizer circuit 1206d for synthesizing the frequencies used by the mixer circuits 1206a of the receive signal path and the transmit signal path. In some embodiments, the mixer circuit 1206a of the receive signal path may be configured to downconvert an RF signal received from the FEM circuit 1208 based on the synthesized frequency provided by the synthesizer circuit 1206d. The amplifier circuit 1206b may be configured to amplify the downconverted signal, and the filter circuit 1206c may be a low-pass filter (LPF) or a band-pass filter (BPF) configured to remove unwanted signals from the downconverted signal to generate an output baseband signal. The output baseband signal may be provided to the baseband circuit 1210 for further processing. In some embodiments, although not required, the output baseband signal may be a zero-frequency baseband signal. In some embodiments, the mixer circuit 1206a of the receive signal path may include a passive mixer, but the scope of the embodiments is not limited in this regard.

[0214] In some embodiments, the mixer circuit 1206a of the transmit signal path can be configured to up-convert an input baseband signal based on a synthesized frequency provided by the synthesizer circuit 1206d to generate an RF output signal for the FEM circuit 1208. The baseband signal can be provided by the baseband circuit 1210 and can be filtered by the filter circuit 1206c.

[0215] In some embodiments, the mixer circuit 1206a of the receive signal path and the mixer circuit 1206a of the transmit signal path can include two or more mixers and can be arranged for quadrature down-conversion and quadrature up-conversion, respectively. In some embodiments, the mixer circuit 1206a of the receive signal path and the mixer circuit 1206a of the transmit signal path can include two or more mixers and can be arranged for image rejection (e.g., Hartley image rejection). In some embodiments, the mixer circuit 1206a of the receive signal path and the mixer circuit 1206a of the transmit signal path can be arranged for direct down-conversion and direct up-conversion, respectively. In some embodiments, the mixer circuit 1206a of the receive signal path and the mixer circuit 1206a of the transmit signal path can be configured for superheterodyne operation.

[0216] In some embodiments, the output baseband signal and the input baseband signal can be analog baseband signals, although the scope of the embodiments is not limited in this regard. In some alternative embodiments, the output baseband signal and the input baseband signal can be digital baseband signals. In these alternative embodiments, the RF circuit 1206 can include an analog-to-digital converter (ADC) and a digital-to-analog converter (DAC) circuit, and the baseband circuit 1210 can include a digital baseband interface to communicate with the RF circuit 1206.

[0217] In some dual-mode embodiments, a separate radio IC circuit can be provided to process signals of each spectrum, but the scope of the embodiments is not limited in this regard.

[0218] In some embodiments, the synthesizer circuit 1206d can be a fractional-N synthesizer or a fractional N / N+1 synthesizer, but the scope of the embodiments is not limited in this regard because other types of frequency synthesizers can also be suitable. For example, the synthesizer circuit 1206d can be a delta-sigma synthesizer, a frequency multiplier, or a synthesizer including a phase-locked loop with a frequency divider.

[0219] The synthesizer circuit 1206d can be configured to synthesize an output frequency based on a frequency input and a frequency divider control input for use by the mixer circuit 1206a of the RF circuit 1206. In some embodiments, the synthesizer circuit 1206d can be a fractional N / N+1 synthesizer.

[0220] In some embodiments, the frequency input may be provided by a voltage controlled oscillator (VCO), although this is not required. The divider control input may be provided by the baseband circuit 1210 or the application circuit 1005 / 1105 according to the desired output frequency. In some embodiments, the divider control input (e.g., N) may be determined from a look-up table based on the channel indicated by the application circuit 1005 / 1105.

[0221] The synthesizer circuit 1206d of the RF circuit 1206 may include a divider, a delay locked loop (DLL), a multiplexer, and a phase accumulator. In some embodiments, the divider may be a dual modulus divider (DMD), and the phase accumulator may be a digital phase accumulator (DPA). In some embodiments, the DMD may be configured to divide an input signal by N or N + 1 (e.g., based on a carry) to provide a fractional division ratio. In some example embodiments, the DLL may include a cascade of tunable delay elements, a phase detector, a charge pump, and a set of D-type flip-flops. In these embodiments, the delay elements may be configured to divide the VCO period into Nd equal phase bins, where Nd is the number of delay elements in the delay line. In this way, the DLL provides negative feedback to help ensure that the total delay through the delay line is one VCO period.

[0222] In some embodiments, the synthesizer circuit 1206d may be configured to generate a carrier frequency as the output frequency, while in other embodiments, the output frequency may be a multiple of the carrier frequency (e.g., twice the carrier frequency, four times the carrier frequency), and may be used with an in-phase / quadrature (IQ) generator and a divider circuit to generate multiple signals having multiple different phases relative to each other at the carrier frequency. In some embodiments, the output frequency may be the local oscillator frequency (fLO). In some embodiments, the RF circuit 1206 may include an IQ / polarity converter.

[0223] The FEM circuit 1208 may include a receive signal path that may include circuitry configured to operate on an RF signal received from the antenna array 1211, amplify the received signal, and provide an amplified version of the received signal to the RF circuit 1206 for further processing. The FEM circuit 1208 may also include a transmit signal path that may include circuitry configured to amplify a transmit signal provided by the RF circuit 1206 for transmission by one or more antenna elements in the antenna array 1211. In various embodiments, amplification through the transmit or receive signal path may be accomplished only in the RF circuit 1206, only in the FEM circuit 1208, or in both the RF circuit 1206 and the FEM circuit 1208.

[0224] In some embodiments, the FEM circuit 1208 may include a TX / RX switch to switch between transmit mode and receive mode operations. The FEM circuit 1208 may include a receive signal path and a transmit signal path. The receive signal path of the FEM circuit 1208 may include an LNA to amplify the received RF signal and provide the amplified received RF signal as an output (e.g., to the RF circuit 1206). The transmit signal path of the FEM circuit 1208 may include a power amplifier (PA) for amplifying an input RF signal (e.g., provided by the RF circuit 1206), and one or more filters for generating an RF signal for subsequent transmission by one or more antenna elements of the antenna array 1211.

[0225] The antenna array 1211 includes one or more antenna elements, each antenna element being configured to convert an electrical signal into a radio wave to travel through the air and convert the received radio wave into an electrical signal. For example, a digital baseband signal provided by the baseband circuit 1210 is converted into an analog RF signal (e.g., a modulated waveform), which will be amplified and transmitted via the antenna elements of the antenna array 1211 including one or more antenna elements (not shown). The antenna elements may be omnidirectional, directional, or a combination thereof. The antenna elements may form various arrangements as known and / or discussed herein. The antenna array 1211 may include a microstrip antenna or a printed antenna fabricated on the surface of one or more printed circuit boards. The antenna array 1211 may be formed as a patch of metal foil in various shapes (e.g., a patch antenna), and may be coupled to the RF circuit 1206 and / or the FEM circuit 1208 using metal transmission lines and the like.

[0226] The processors of the application circuit 1005 / 1105 and the baseband circuit 1210 may be used to execute elements of one or more instances of a protocol stack. For example, the processor of the baseband circuit 1210 may be used to execute layer 3, layer 2, or layer 1 functions, either alone or in combination, while the processor of the application circuit 1005 / 1105 may utilize the data received from these layers (e.g., packet data) and further execute layer 4 functions (e.g., TCP and UDP layers). As mentioned herein, layer 3 may include the RRC layer, which will be described in further detail below. As mentioned herein, layer 2 may include the MAC layer, the RLC layer, and the PDCP layer, which will be described in further detail below. As mentioned herein, layer 1 may include the PHY layer of the UE / RAN node, which will be described in further detail below.

[0227] Figure 13 Various protocol functions that may be implemented in a wireless communication device are shown. Specifically, Figure 13An arrangement 1300 is included that shows the interconnection between various protocol layers / entities. The following description is provided for various protocol layers / entities operating in conjunction with 5G / NR system standards and LTE system standards, Figure 13 but Figure 13 some or all aspects of which may also be applicable to other wireless communication network systems.

[0228] In addition to other higher layer functions not shown, the protocol layers of arrangement 1300 may include one or more of PHY 1310, MAC 1320, RLC 1330, PDCP 1340, SDAP 1347, RRC 1355, and NAS layer 1357. These protocol layers may include one or more service access points capable of providing communication between two or more protocol layers (e.g., Figure 13 items 1359, 1356, 1350, 1349, 1345, 1335, 1325, and 1315 in).

[0229] PHY 1310 may transmit and receive physical layer signals 1305, which may be received from or transmitted to one or more other communication devices. Physical layer signals 1305 may include one or more physical channels, such as those discussed herein. PHY 1310 may also perform link adaptation or adaptive modulation and coding (AMC), power control, cell search (e.g., for initial synchronization and handover purposes), and other measurements used by higher layers (e.g., RRC 1355). PHY 1310 may further perform error detection on transport channels, forward error correction (FEC) encoding / decoding of transport channels, modulation / demodulation of physical channels, interleaving, rate matching, mapping to physical channels, and MIMO antenna processing. In an embodiment, an instance of PHY 1310 may process requests from an instance of MAC 1320 via one or more PHY-SAPs 1315 and provide indications thereto. According to some embodiments, requests and indications transmitted via PHY-SAP 1315 may include one or more transport channels.

[0230] An instance of MAC 1320 can process requests from an instance of RLC 1330 and provide indications thereto via one or more MAC-SAPs 1325. These requests and indications transmitted via MAC-SAP 1325 can include one or more logical channels. MAC 1320 can perform mapping between logical channels and transport channels, multiplex MAC SDUs from one or more logical channels onto a TB to be delivered to PHY 1310 via a transport channel, demultiplex MAC SDUs from a TB delivered from PHY 1310 via a transport channel onto one or more logical channels, multiplex MAC SDUs onto a TB, schedule information reporting, perform error correction via HARQ, and perform logical channel prioritization.

[0231] An instance of RLC 1330 can process requests from an instance of PDCP 1340 and provide indications thereto via one or more radio link control service access points (RLC-SAPs) 1335. These requests and indications transmitted via RLC-SAP 1335 can include one or more logical channels. RLC 1330 can operate in multiple operation modes, including: transparent mode (TM), unacknowledged mode (UM), and acknowledged mode (AM). RLC 1330 can perform transmission of upper layer protocol data units (PDUs), error correction via automatic repeat request (ARQ) for AM data transmission, and concatenation, segmentation, and reassembly of RLC SDUs for UM and AM data transmission. RLC 1330 can also perform resegmentation of RLC data PDUs for AM data transmission, reordering of RLC data PDUs for UM and AM data transmission, detection of duplicate data for UM and AM data transmission, discarding of RLC SDUs for UM and AM data transmission, detection of protocol errors for AM data transmission, and perform RLC reestablishment.

[0232] An instance of PDCP 1340 can process requests from an instance of RRC 1355 and / or an instance of SDAP 1347 and provide indications thereto via one or more packet data convergence protocol service access points (PDCP-SAPs) 1345. These requests and indications transmitted via PDCP-SAP 1345 can include one or more radio bearers. PDCP 1340 can perform header compression and decompression of IP data, maintain a PDCP sequence number (SN), perform sequential delivery of upper layer PDUs upon lower layer reestablishment, eliminate duplication of lower layer SDUs upon reestablishment of the lower layer for radio bearers mapped to RLC AM, encrypt and decrypt control plane data, perform integrity protection and integrity verification on control plane data, control timer-based data discarding, and perform security operations (e.g., encryption, decryption, integrity protection, integrity verification, etc.).

[0233] Instances of SDAP 1347 can process requests from one or more higher layer protocol entities via one or more SDAP - SAPs 1349 and provide indications thereto. These requests and indications transmitted via SDAP - SAP 1349 can include one or more QoS flows. SDAP 1347 can map QoS flows to DRBs and vice versa, and can also mark the QFI in DL packets and UL packets. A single SDAP entity 1347 can be configured for a separate PDU session. In the UL direction, NG - RAN 710 can control the mapping of QoS flows to DRBs in two different ways (reflection mapping or explicit mapping). For reflection mapping, the SDAP 1347 of UE 701 can monitor the QFI of DL packets of each DRB, and can apply the same mapping to the packets flowing in the UL direction. For a DRB, the SDAP 1347 of UE 701 can map UL packets belonging to a QoS flow that corresponds to the QoS flow ID and PDU session observed in the DL packets of that DRB. To implement reflection mapping, NG - RAN 910 can mark DL packets with the QoS flow ID via the Uu interface. Explicit mapping can involve RRC 1355 configuring SDAP 1347 with an explicit mapping rule of QoS flows to DRBs, which can be stored and followed by SDAP 1347. In an embodiment, SDAP 1347 can be used only in NR implementations and not in LTE implementations.

[0234] RRC 1355 can configure aspects of one or more protocol layers via one or more management service access points (M - SAPs), and the one or more protocol layers can include one or more instances of PHY 1310, MAC 1320, RLC 1330, PDCP 1340, and SDAP 1347. In an embodiment, an instance of RRC 1355 can process requests from one or more NAS entities 1357 and provide indications thereto via one or more RRC - SAPs 1356. The main services and functions of RRC 1355 can include broadcasting of system information (e.g., included in the MIB or SIB related to NAS), broadcasting of system information related to the access stratum (AS), paging, establishment, maintenance, and release of the RRC connection between UE 701 and RAN 710 (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), establishment, configuration, maintenance, and release of point - to - point radio bearers, security functions including key management, mobility between RATs, and measurement configuration for UE measurement reports. These MIBs and SIBs can include one or more IEs, each of which can include separate data fields or data structures.

[0235] NAS 1357 can form the top layer of the control plane between the UE 701 and the AMF 921. NAS 1357 can support the mobility and session management procedures of the UE 701 to establish and maintain an IP connection between the UE 701 and the P-GW in the LTE system.

[0236] According to various embodiments, one or more protocol entities of the arrangement 1300 can be implemented in the UE 701, the RAN node 711, the AMF 921 in the NR implementation or the MME 821 in the LTE implementation, the UPF 902 in the NR implementation or the S-GW 822 and the P-GW 823 in the LTE implementation, etc., for the control plane or user plane communication protocol stacks between the aforementioned devices. In such embodiments, one or more protocol entities that can be implemented in one or more of the UE 701, the gNB 711, the AMF 921, etc., can communicate with the corresponding peer protocol entities that can be implemented in another device or on another device (using the services of the corresponding lower layer protocol entities to perform such communication). In some embodiments, the gNB-CU of the gNB 711 can host the RRC 1355, the SDAP 1347, and the PDCP 1340 that control the operation of one or more gNB-DUs of the gNB, and each gNB-DU of the gNB 711 can host the RLC 1330, the MAC 1320, and the PHY 1310 of the gNB 711.

[0237] In a first example, the control plane protocol stack can include, in order from the top layer to the bottom layer, NAS 1357, RRC 1355, PDCP 1340, RLC 1330, MAC 1320, and PHY 1310. In this example, the upper layer 1360 can be built on top of the NAS 1357, which includes an IP layer 1361, an SCTP 1362, and an application layer signaling protocol (AP) 1363.

[0238] In the NR implementation, the AP 1363 can be the NG application protocol layer (NGAP or NG-AP) 1363 for the NG interface 713 defined between the NG-RAN node 711 and the AMF 921, or the AP 1363 can be the Xn application protocol layer (XnAP or Xn-AP) 1363 for the Xn interface 712 defined between two or more RAN nodes 711.

[0239] The NG-AP 1363 can support the functions of the NG interface 713 and may include an elementary procedure (EP). The NG-AP EP can be an interaction unit between the NG-RAN node 711 and the AMF 921. The NG-AP 1363 services can include two groups: UE-associated services (e.g., services related to the UE 701) and non-UE-associated services (e.g., services related to the entire NG interface instance between the NG-RAN node 711 and the AMF 921). These services can include functions, including but not limited to: a paging function for sending a paging request to the NG-RAN node 711 involved in a specific paging area; a UE context management function for allowing the AMF 921 to establish, modify, and / or release the UE context in the AMF 921 and the NG-RAN node 711; a mobility function for the UE 701 in the ECM-CONNECTED mode, for supporting mobility within the system HO in the NG-RAN, and for supporting mobility between systems HO from / to the EPS system; a NAS signaling transmission function for transmitting or rerouting NAS messages between the UE 701 and the AMF 921; a NAS node selection function for determining the association between the AMF 921 and the UE 701; an NG interface management function for setting up the NG interface and monitoring errors through the NG interface; a warning message sending function for providing a means to transmit a warning message via the NG interface or cancel the ongoing broadcast of a warning message; a configuration transmission function for requesting and transmitting RAN configuration information (e.g., SON information, performance measurement (PM) data, etc.) between two RAN nodes 711 via the CN 720; and / or other similar functions.

[0240] The XnAP 1363 can support the functions of the Xn interface 712 and may include XnAP basic mobility procedures and XnAP global procedures. The XnAP basic mobility procedures can include procedures for handling UE mobility within the NG RAN 711 (or E-UTRAN 810), such as handover preparation and cancellation procedures, SN status transmission procedures, UE context retrieval and UE context release procedures, RAN paging procedures, procedures related to dual connectivity, etc. The XnAP global procedures can include procedures that are not related to a specific UE 701, such as Xn interface setup and reset procedures, NG-RAN update procedures, cell activation procedures, etc.

[0241] In the LTE specific implementation, the AP 1363 can be the S1 application protocol layer (S1-AP) 1363 for the S1 interface 713 defined between the E-UTRAN node 711 and the MME, or the AP 1363 can be the X2 application protocol layer (X2AP or X2-AP) 1363 for the X2 interface 712 defined between two or more E-UTRAN nodes 711.

[0242] The S1 Application Protocol Layer (S1-AP) 1363 can support the functions of the S1 interface, and similar to the previously discussed NG-AP, the S1-AP can include S1-AP EPs. The S1-AP EP can be an interaction unit between the E-UTRAN node 711 and the MME 821 within the LTE CN 720. The S1-AP 1363 services can include two groups: UE-associated services and non-UE-associated services. The functions performed by these services include, but are not limited to: E-UTRAN Radio Access Bearer (E-RAB) management, UE capability indication, mobility, NAS signaling transport, RAN Information Management (RIM), and configuration transport.

[0243] The X2AP 1363 can support the functions of the X2 interface 712, and can include X2AP basic mobility procedures and X2AP global procedures. The X2AP basic mobility procedures can include procedures for handling UE mobility within the E-UTRAN 720, such as handover preparation and cancellation procedures, SN status transfer procedures, UE context retrieval and UE context release procedures, RAN paging procedures, procedures related to dual connectivity, etc. The X2AP global procedures can include procedures that are not related to a specific UE 701, such as X2 interface setup and reset procedures, load indication procedures, error indication procedures, cell activation procedures, etc.

[0244] The SCTP layer (alternatively referred to as the SCTP / IP layer) 1362 can provide guaranteed delivery of application layer messages (e.g., NGAP or XnAP messages in an NR implementation, or S1-AP or X2AP messages in an LTE implementation). The SCTP 1362 can ensure reliable delivery of signaling messages between the RAN node 711 and the AMF 921 / MME 821, partially based on the IP protocol supported by the IP 1361. The Internet Protocol layer (IP) 1361 can be used to perform packet addressing and routing functions. In some implementations, the IP layer 1361 can use point-to-point transmission to deliver and transfer PDUs. In this regard, the RAN node 711 can include communication links (e.g., wired or wireless) with the L2 and L1 layers of the MME / AMF to exchange information.

[0245] In a second example, the user plane protocol stack may include, in order from the highest layer to the lowest layer, SDAP 1347, PDCP 1340, RLC 1330, MAC 1320, and PHY 1310. The user plane protocol stack may be used for communication between UE 701, RAN node 711, and UPF 902 in an NR implementation, or between S-GW 822 and P-GW 823 in an LTE implementation. In this example, upper layer 1351 may be built on top of SDAP 1347 and may include User Datagram Protocol (UDP) and IP Security layer (UDP / IP) 1352, General Packet Radio Service (GPRS) Tunneling Protocol for the user plane layer (GTP-U) 1353, and User Plane PDU layer (UP PDU) 1363.

[0246] The transport network layer 1354 (also referred to as the "transport layer") may be built on top of IP transport, and GTP-U 1353 may be used on top of the UDP / IP layer 1352 (including the UDP layer and the IP layer) to carry user plane PDUs (UP-PDUs). The IP layer (also referred to as the "Internet layer") may be used to perform packet addressing and routing functions. The IP layer may assign IP addresses to user data packets in any one of, for example, IPv4, IPv6, or PPP formats.

[0247] GTP-U 1353 may be used to carry user data within the GPRS core network and between the radio access network and the core network. For example, the user data being transmitted may be packets in any one of IPv4, IPv6, or PPP formats. UDP / IP 1352 may provide a checksum for data integrity, port numbers for addressing different functions at the source and destination, and encryption and authentication for selected data flows. RAN node 711 and S-GW 822 may exchange user plane data via a protocol stack including L1 layer (e.g., PHY 1310), L2 layer (e.g., MAC 1320, RLC 1330, PDCP 1340, and / or SDAP 1347), UDP / IP layer 1352, and GTP-U 1353 using the S1-U interface. S-GW 822 and P-GW 823 may exchange user plane data via a protocol stack including L1 layer, L2 layer, UDP / IP layer 1352, and GTP-U 1353 using the S5 / S8a interface. As previously discussed, the NAS protocol may support the mobility and session management processes of UE 701 to establish and maintain an IP connection between UE 701 and P-GW 823.

[0248] In addition, although Figure 13Not shown, but the application layer may exist above the AP 1363 and / or the transport network layer 1354. The application layer may be a layer in which users of the UE 701, RAN node 711, or other network elements interact with software applications executed, for example, by the application circuit 1005 or the application circuit 1105, respectively. The application layer may also provide one or more interfaces for the software application to interact with the communication system (such as the baseband circuit 1210) of the UE 701 or the RAN node 711. In some specific embodiments, the IP layer and / or the application layer may provide the same or similar functions as the layers 5 to 7 or parts thereof of the Open Systems Interconnection (OSI) model (e.g., OSI layer 7 - application layer, OSI layer 6 - presentation layer, and OSI layer 5 - session layer).

[0249] Figure 14 is a block diagram showing components that can read instructions from a machine-readable or computer-readable medium (e.g., a non-transitory machine-readable storage medium) and can perform any one or more of the methods discussed herein. Specifically, Figure 14 shows a schematic diagram of the hardware resources 1400, including one or more processors (or processor cores) 1410, one or more memory / storage devices 1420, and one or more communication resources 1430, each of which can be communicatively coupled via a bus 1440. For embodiments in which node virtualization (e.g., NFV) is utilized, a hypervisor 1402 may be executed to provide an execution environment for one or more network slices / sub-slices to utilize the hardware resources 1400.

[0250] The processor 1410 may include, for example, a processor 1412 and a processor 1414. The processor 1410 may be, for example, a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a DSP such as a baseband processor, an ASIC, an FPGA, a radio frequency integrated circuit (RFIC), another processor (including those discussed herein), or any suitable combination thereof.

[0251] The memory / storage device 1420 may include main memory, disk memory, or any suitable combination thereof. The memory / storage device 1420 may include, but is not limited to, any type of volatile or non-volatile memory, such as dynamic random access memory (DRAM), static random access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, solid-state storage devices, etc.

[0252] The communication resource 1430 may include an interconnect or network interface component or other suitable device to communicate with one or more peripheral devices 1404 or one or more databases 1406 via the network 1408. For example, the communication resource 1430 may include a wired communication component (e.g., for coupling via USB), a cellular communication component, an NFC component, (or low-power) component, component, and other communication components.

[0253] The instructions 1450 may include software, programs, applications, applets, applications, or other executable code for causing at least any one of the processors 1410 to execute any one or more of the method sets discussed herein. The instructions 1450 may reside, in whole or in part, in at least one of the processors 1410 (e.g., within the cache memory of the processor), the memory / storage device 1420, or any suitable combination thereof. Additionally, any portion of the instructions 1450 may be transmitted from any combination of the peripheral devices 1404 or the databases 1406 to the hardware resource 1400. Accordingly, the memory of the processor 1410, the memory / storage device 1420, the peripheral devices 1404, and the databases 1406 are examples of computer-readable and machine-readable media.

Claims

1. A method for mobile terminated (MT) early data transmission (EDT) in a wireless communication system, the method comprising: A node of a radio access network (RAN) receives information indicating downlink data to be transmitted to a user equipment (UE) served by the RAN; Determine to initiate the MT EDT to transmit the downlink data to the UE, at least in part based on the information indicating the downlink data; Generate a radio resource control (RRC) paging message for transmission to the UE, the RRC paging message including an indication of the MT EDT, an indication of a contention-free (CF) physical random access channel (PRACH) preamble (CF PRACH preamble), and an indication of an EDT-radio network temporary identifier (EDT-RNTI), where the EDT-RNTI is defined as EDT-RNTI = paging-RNTI (P-RNTI) - constant * offset, and where the constant is the PRACH preamble index and the offset is an x-bit offset from the P-RNTI, where x is an integer; and Transmit the RRC paging message to the UE.

2. The method according to claim 1, wherein the information indicating the downlink data comprises the size of the downlink data.

3. The method according to claim 1, further comprising: Receive a preamble from the UE for the MT EDT.

4. The method according to claim 1, the method further comprising: Receive a response message from the UE in response to the RRC paging message; Send a request for the downlink data to a mobility management entity (MME) via an S1 application protocol (S1-AP) initial message; And Receive a downlink non-access stratum (NAS) protocol data unit (PDU) from the MME via an S1-AP response message.

5. The method according to claim 4, wherein control plane cellular Internet of Things (CP CIoT) optimization is used to transmit the downlink data, and wherein the method further comprises: Transmit the downlink NAS PDU to the UE in a downlink RRC message.

6. The method according to claim 4, wherein the received downlink NAS PDU is encrypted using NAS security.

7. The method according to claim 1, wherein the information indicating the downlink data is received from a mobility management entity (MME) via an S1 application protocol (S1-AP) paging message.

8. The method according to claim 1, wherein, Generate a CF preamble using a modulo function of a UE identifier (ID) and a PRACH preamble index.

9. A non-transitory computer-readable storage device storing instructions, which when executed by a data processing device, cause the data processing device to perform operations for mobile terminated (MT) early data transmission (EDT), the operations comprising: A node of a radio access network (RAN) receives information indicating downlink data to be transmitted to a user equipment (UE) served by the RAN; Determine to initiate the MT EDT to transmit the downlink data to the UE, at least in part based on the information indicating the downlink data; Generate a radio resource control (RRC) paging message for transmission to the UE, the RRC paging message including an indication of the MT EDT, an indication of a contention-free (CF) physical random access channel (PRACH) preamble (CF PRACH preamble), and an indication of an EDT-radio network temporary identifier (EDT-RNTI), where the EDT-RNTI is defined as EDT-RNTI = paging-RNTI (P-RNTI) - constant * offset, and where the constant is the PRACH preamble index and the offset is an x-bit offset from the P-RNTI, where x is an integer; and Transmit the RRC paging message to the UE.

10. The non-transitory computer-readable storage device according to claim 9, wherein the information indicating the downlink data comprises the size of the downlink data.

11. The non-transitory computer-readable storage device according to claim 9, the operations further comprising: Receive a preamble from the UE for the MT EDT.

12. The non-transitory computer-readable storage device according to claim 9, wherein the operation further comprises: Receive a response message from the UE in response to the RRC paging message; Send a request for the downlink data to a mobility management entity (MME) via an S1 application protocol (S1-AP) initial message; And Receive a downlink non-access stratum (NAS) protocol data unit (PDU) from the MME via an S1-AP response message.

13. The non-transitory computer-readable storage device according to claim 12, wherein control plane cellular Internet of Things (CP CIoT) optimization is used to transmit the downlink data, and wherein the operation further comprises: Transmit the downlink NAS PDU to the UE in a downlink RRC message.

14. The non-transitory computer-readable storage device according to claim 12, wherein the received downlink NAS PDU is encrypted using NAS security.

15. The non-transitory computer-readable storage device according to claim 9, wherein the information indicating the downlink data is received from a Mobility Management Entity (MME) via an S1 Application Protocol (S1-AP) paging message.

16. The non-transitory computer-readable storage device according to claim 9, wherein Generate a CF preamble using a modulo function of a UE identifier ID and a PRACH preamble index.

17. An apparatus, comprising: One or more processors and one or more storage devices storing instructions that, when executed by the one or more processors, are operable to cause the one or more processors to perform operations for mobile-terminated MT early data transfer EDT, the operations including: Receiving, at a node of a radio access network RAN, information indicating downlink data for transmission to a user equipment UE served by the RAN; Determining, at least in part based on the information indicating the downlink data, to initiate the MT EDT to transmit the downlink data to the UE; Generating a radio resource control RRC paging message for transmission to the UE, the RRC paging message including an indication of the MT EDT, an indication of a contention-free CF physical random access channel PRACH preamble CF PRACH preamble, and an indication of an EDT-radio network temporary identifier EDT-RNTI, where the EDT-RNTI is defined as EDT-RNTI = paging-RNTI (P-RNTI) - constant * offset, and where the constant is a PRACH preamble index and the offset is an x-bit offset from the P-RNTI, where x is an integer; and Transmitting the RRC paging message to the UE.

18. The apparatus according to claim 17, wherein the information indicating the downlink data includes the size of the downlink data.

19. The apparatus according to claim 17, wherein the operation further comprises: Receiving, from the UE, a preamble for the MT EDT.

20. The apparatus according to claim 17, wherein the operation further comprises: Receiving, in response to the RRC paging message, a response message from the UE; Sending a request for the downlink data to a mobility management entity MME via an S1 application protocol S1-AP initial message; And Receiving a downlink non-access stratum NAS protocol data unit PDU from the MME and via an S1-AP response message.

21. The apparatus according to claim 20, wherein control plane cellular Internet of Things (CP CIoT) optimization is used to transmit the downlink data, and wherein the operation further comprises: Transmit the downlink NAS PDU to the UE in a downlink RRC message.

22. The apparatus according to claim 20, wherein the received downlink NAS PDU is encrypted using NAS security.

23. The apparatus according to claim 17, wherein the information indicating the downlink data is received from a mobility management entity MME via an S1 application protocol S1-AP paging message.

24. The apparatus according to claim 17, wherein Generate a CF preamble using a modulo function of a UE identifier ID and a PRACH preamble index.