User equipment and core network apparatus
By processing the S-NSSAI and reason value in the login rejection message by the UE and core network devices in the 5G system, the information management problem of the network slice in the pending state is solved, the support of network slice specific authentication and authorization is achieved, and the flexibility and efficiency of the system are improved.
Patent Information
- Application Number
- CN202080066547.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-27
- Filing Date
- 2020-09-24
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2040-09-24
AI Technical Summary
In the 5G system, the existing technology does not clearly define the specific scheme and method for managing information related to pending network slices based on UE and network in the pending state of network slices, resulting in unclear network slice specific authentication and authorization processes.
During the login process, user equipment (UE) and core network devices receive and process login rejection messages including S-NSSAI and reason values, ignoring or not passing unusable network slice information to support network slice specific authentication and authorization.
It supports network slice-specific authentication and authorization in the 5G system, ensuring that the UE can log in to the core network that supports this function, and improving the flexibility and efficiency of network slice management.
Smart Images

Figure CN114521336B_ABST
Abstract
Description
Technical Field
[0001] The present application claims the benefit of priority from Japanese Patent Application No. 2019-176833, filed on September 27, 2019, the entire contents of which are incorporated herein by reference. Background Art
[0002] In 3GPP (3rd Generation Partnership Project), which has been conducting standardization activities for mobile communication systems in recent years, SAE (System Architecture Evolution) is being studied as a system architecture for LTE (Long Term Evolution).
[0003] Furthermore, in recent years, 3GPP has also been conducting research on the next-generation communication technology and system architecture of the 5G (5th Generation) mobile communication system, specifically the 5GS (5G System) standardization as a system for implementing the 5G mobile communication system (see Non-Patent Documents 1 and 2). 5GS identifies the technical issues involved in connecting various terminals to cellular networks and specifies solutions.
[0004] Prior art literature
[0005] Non-patent literature
[0006] Non-patent document 1: 3GPP TS 23.501V16.1.0 (2019-06); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; SystemArchitecture for the 5G System; Stage 2 (Release 16)
[0007] Non-patent document 2: 3GPP TS 23.502V16.1.1(2019-06); 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2 (Release 16)
[0008] Non-patent document 3: 3GPP TS 24.501V16.1.0 (2019-06); 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3 (Release 16) Summary of the Invention
[0009] Problems to be solved by the invention
[0010] In 5GS (5G System), research is being conducted on 5GCN (5G Core Network), a new core network, to provide various services.
[0011] Furthermore, 5G defines network slices, which are logical networks that provide specific network functions and characteristics for specific service types and groups. For example, a network slice could be a logical network for low-latency terminals or sensor terminals used in the IoT (Internet of Things).
[0012] 3GPP is studying eNS (Enhancement of Network Slicing) to develop further network slicing-related functions. Furthermore, within eNS, research is underway on Network Slice-specific Authentication and Authorization, which moves beyond the existing per-UE authentication process to a per-network slice authentication process.
[0013] The following is studied: in a case where the UE requests permission to connect to a network slice that requires network slice-specific authentication and authorization in a registration request, the network responds to the UE while pending notification of whether the network slice requested by the UE is an allowed slice or a rejected slice.
[0014] However, the specific scheme and method for managing information related to pending network slices based on UE and network in the pending state of network slices are not clear.
[0015] The present invention has been made in view of the above-mentioned circumstances, and provides a method for realizing the functions of eNS in 5GS.
[0016] Technical Solution
[0017] A UE according to one embodiment of the present invention is characterized in that the UE includes a transceiver and a control unit. During the login process for initial login, the transceiver receives a login rejection message including a first rejection NSSAI from the core network via the first access. The first rejection NSSAI includes a first S-NSSAI and a first reason value. When the control unit has not logged in to the second access, if the first reason value indicates that it is not available in the current PLMN (Public Land Mobile Network), the control unit ignores the first S-NSSAI.
[0018] A UE according to one embodiment of the present invention is characterized in that the UE comprises a transceiver and a control unit, wherein the transceiver receives a login rejection message including a first rejection NSSAI from a core network via a first access during a login process for initial login, wherein the first rejection NSSAI includes a first S-NSSAI and a first reason value, and the control unit ignores the first S-NSSAI when the first reason value indicates that the UE is not available in the current PLMN, if the UE has not logged in to the second access.
[0019] A core network device according to one embodiment of the present invention is characterized in that the core network device comprises a transceiver unit and a control unit, wherein the transceiver unit sends a login rejection message including a first rejection NSSAI to the UE during the login process for initial login, wherein the first rejection NSSAI includes a first S-NSSAI and a first reason value, and the control unit does not include a value indicating that the value is not available in the current login area in the first reason value.
[0020] A core network device according to an embodiment of the present invention is characterized in that the core network device includes a transceiver and a control unit. During the login process for initial login, the transceiver sends a login rejection message including a first rejection NSSAI to the UE via the first access. The first rejection NSSAI includes a first S-NSSAI and a first reason value. When the UE has not logged in to the second access, the control unit does not include a value indicating that it is not available in the current PLMN in the first reason value.
[0021] A UE according to one embodiment of the present invention is characterized in that the UE comprises a transceiver unit and a control unit, the transceiver unit receiving a non-login request including a first rejection NSSAI from a core network, the first rejection NSSAI including a first S-NSSAI and a first reason value, and the control unit ignoring the first S-NSSAI when the first reason value indicates that it is not available in the current login area.
[0022] A UE according to one embodiment of the present invention is characterized in that the UE comprises a transceiver unit and a control unit, wherein the transceiver unit receives a non-login request including a first S-NSSAI, a first reason value, and information indicating a first access from a core network, and the control unit ignores the first S-NSSAI when the first reason value indicates that the second access is not available in the current PLMN if the control unit is not logged in to the second access.
[0023] A core network device according to one embodiment of the present invention is characterized in that the core network device comprises a transceiver unit and a control unit, wherein the transceiver unit sends a non-login request including a first rejection NSSAI to the UE, wherein the first rejection NSSAI includes a first S-NSSAI and a first reason value, and the control unit does not include a value that is unavailable in the current login area in the first reason value.
[0024] A core network device according to one embodiment of the present invention is characterized in that the core network device comprises a transceiver unit and a control unit, wherein the transceiver unit sends a non-login request including a first S-NSSAI, a first reason value, and information indicating a first access to a UE, and when the UE is not logged in to a second access, the control unit does not include a value indicating that it is not available in the current PLMN in the first reason value.
[0025] Beneficial effects
[0026] According to one solution of the present invention, in 5GS, eNS can be supported, network slice specific authentication and authorization can be supported, and UEs supporting network slice specific authentication and authorization can log in to a core network supporting network slice specific authentication and authorization. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1This is a diagram illustrating an outline of a mobile communication system (EPS / 5GS).
[0028] Figure 2 This is a diagram illustrating the detailed structure of the mobile communication system (EPS / 5GS).
[0029] Figure 3 This is a diagram illustrating the device structure of UE.
[0030] Figure 4 This is a diagram illustrating the structure of the access network device (gNB) in 5GS.
[0031] Figure 5 This is a diagram illustrating the structure of the core network device (AMF / SMF / UPF) in 5GS.
[0032] Figure 6 This is a diagram illustrating the login process.
[0033] Figure 7 is a diagram illustrating the network slice specific authentication and authorization process.
[0034] Figure 8 This is a diagram illustrating the process of changing / updating the UE settings.
[0035] Figure 9 This is a diagram illustrating a non-login process initiated by a network. DETAILED DESCRIPTION
[0036] Hereinafter, the best mode for carrying out the present invention will be described with reference to the accompanying drawings. Note that, in this embodiment, an embodiment of a mobile communication system to which the present invention is applied will be described as an example.
[0037] [1. System Overview]
[0038] first, Figure 1 is a diagram for explaining an outline of a mobile communication system 1 used in each embodiment. Figure 2 It is a diagram for explaining the detailed configuration of the mobile communication system 1 .
[0039] exist Figure 1 It is recorded that the mobile communication system 1 is composed of UE_A10, access network_A80, core network_A90, PDN (Packet Data Network)_A5, access network_B120, core network_B190 and DN (Data Network)_A6.
[0040] In the following, symbols are sometimes omitted to record these devices and functions, for example, UE, access network_A, core network_A, PDN, access network_B, core network_B, DN, etc.
[0041] In addition, Figure 2 It records devices and functions such as UE_A10, E-UTRAN80, MME40, SGW35, PGW-U30, PGW-C32, PCRF60, HSS50, 5G AN120, AMF140, UPF130, SMF132, PCF160, UDM150, N3IWF170, and the interfaces that connect these devices and functions.
[0042] In the following, symbols are sometimes omitted to record these devices and functions, for example, UE, E-UTRAN, MME, SGW, PGW-U, PGW-C, PCRF, HSS, 5G AN, AMF, UPF, SMF, PCF, UDM, N3IWF, etc.
[0043] It should be noted that the EPS (Evolved Packet System) of the 4G system consists of an access network_A and a core network_A, but may further include a UE and / or a PDN. Furthermore, the 5GS (5G System) of the 5G system consists of a UE, an access network_B, and a core network_B, but may further include a DN.
[0044] UE is a device that can connect to network services via 3GPP access (also known as 3GPP access network, 3GPP AN) and / or non-3GPP access (non-3GPP access, also known as non-3GPP access network, non-3GPP AN). UE can be a terminal device that can perform wireless communication, such as a portable phone or a smartphone, or a terminal device that can connect to EPS or 5GS. UE can have a UICC (Universal Integrated Circuit Card) or an eUICC (Embedded UICC). It should be noted that the UE can be expressed as a user device or as a terminal device.
[0045] Access Network_A corresponds to E-UTRAN (Evolved Universal Terrestrial Radio Access Network) and / or a wireless LAN access network. E-UTRAN includes one or more eNBs (evolved Node Bs) 45. Note that, below, reference to eNBs 45 may be omitted, for example, by simply referring to them as "eNB." When multiple eNBs exist, they are interconnected, for example, via an X2 interface. Furthermore, a wireless LAN access network includes one or more access points.
[0046] In addition, access network_B corresponds to the 5G access network (5G AN). 5G AN is composed of NG-RAN (NG Radio Access Network: NG radio access network) and / or non-3GPP access network. One or more gNB (NRNodeB: NR node B) 122 are configured in NG-RAN. It should be noted that, below, the symbols for gNB122 are sometimes omitted, such as eNB. gNB is a node that provides NR (New Radio: New Radio) user plane and control plane to UE, and is a node connected to 5GCN via NG interface (including N2 interface or N3 interface). That is, gNB is a base station device newly designed for 5GS, and has different functions from the base station device (eNB) used in EPS as a 4G system. In addition, when there are multiple gNBs, each gNB is connected to each other, for example, via an Xn interface.
[0047] In addition, the non-3GPP access network can be an untrusted non-3GPP access network or a trusted non-3GPP access network. Here, the untrusted non-3GPP access network can be, for example, a non-3GPP access network such as a public wireless LAN that does not perform security management within the access network. On the other hand, the trusted non-3GPP access network can be an access network specified by 3GPP, and can also have a TNAP (trusted non-3GPP access point) and a TNGF (trusted non-3GPP Gateway function).
[0048] In the following, E-UTRAN and NG-RAN are referred to as 3GPP access. Wireless LAN access networks and non-3GPP ANs are also referred to as non-3GPP access. Nodes deployed in access network_B are also collectively referred to as NG-RAN nodes.
[0049] In addition, below, access network_A and / or access network_B and / or the device included in access network_A and / or the device included in access network_B are sometimes referred to as access network or access network device.
[0050] Furthermore, Core Network_A corresponds to the Evolved Packet Core (EPC). The EPC includes, for example, the Mobility Management Entity (MME), Serving Gateway (SGW), Packet Data Network Gateway (PGW)-U, PGW-C, Policy and Charging Rules Function (PCRF), and Home Subscriber Server (HSS).
[0051] Furthermore, Core Network_B corresponds to 5GCN (5G Core Network). 5GCN includes, for example, AMF (Access and Mobility Management Function), UPF (User Plane Function), SMF (Session Management Function), PCF (Policy Control Function), and UDM (Unified Data Management). Here, 5GCN can be represented as 5GC.
[0052] In addition, below, core network_A and / or core network_B, the devices included in core network_A and / or the devices included in core network_B are sometimes referred to as core networks or core network devices or devices within the core network.
[0053] The core network (core network_A and / or core network_B) can be an IP mobile communication network operated by a mobile communication operator (Mobile Network Operator; MNO) that connects the access network (access network_A and / or access network_B) with the PDN and / or DN, or it can be a core network used by a mobile communication operator that operates and manages the mobile communication system 1, or it can be a core network used by virtual mobile communication operators and virtual mobile communication service providers such as MVNO (Mobile Virtual Network Operator) and MVNE (Mobile Virtual Network Enabler).
[0054] In addition, Figure 1 The case where PDN and DN are the same is recorded in the text, but they can also be different. PDN can be a DN (Data Network) that provides communication services to UE. It should be noted that DN can be constructed as a packet data service network, or it can be constructed for each service. Moreover, PDN can include connected communication terminals. Therefore, connection with PDN can be connection with a communication terminal or server device configured for PDN. Moreover, sending and receiving user data with PDN can be sending and receiving user data with a communication terminal or server device configured for PDN. It should be noted that PDN can be expressed as DN, and DN can also be expressed as PDN.
[0055] In addition, below, at least a portion of the access network_A, core network_A, PDN, access network_B, core network_B, and DN, and / or one or more devices included therein, may be referred to as a network or network device. In other words, the network and / or network device transmitting and receiving messages and / or executing a process refers to at least a portion of the access network_A, core network_A, PDN, access network_B, core network_B, and DN, and / or one or more devices included therein, transmitting and receiving messages and / or executing a process.
[0056] Furthermore, the UE can connect to an access network. Furthermore, the UE can connect to a core network via the access network. Furthermore, the UE can connect to a PDN or DN via the access network and the core network. In other words, the UE can send and receive (communicate) user data with the PDN or DN. This can be done using not only Internet Protocol (IP) communication but also non-IP communication.
[0057] Here, IP communication refers to data communication using IP, in which data is sent and received through IP packets. An IP packet consists of an IP header and a payload portion. The payload portion may include data sent and received by the devices and functions included in the EPS, and the devices and functions included in the 5GS. In addition, non-IP communication refers to data communication that does not use IP, in which data is sent and received in a form different from the structure of IP packets. For example, non-IP communication can be data communication achieved by sending and receiving application data that is not assigned an IP header, or it can be assigned other headers such as a MAC header and an Ethernet (registered trademark) frame header to send and receive user data sent and received by the UE.
[0058] In addition, access network_A, core network_A, access network_B, core network_B, PDN_A, and DN_A can be configured with Figure 2 For example, the core network_A and / or the core network_B may include an AUSF (Authentication Server Function) and an AAA (Authentication, Authorization, and Accounting) server (AAA-S).
[0059] Here, the AUSF is a core network device that has authentication functions for 3GPP access and non-3GPP access. Specifically, it is a network function unit that receives a request for authentication for 3GPP access and / or non-3GPP access from a UE and performs the authentication process.
[0060] In addition, the AAA server is a device with authentication, authorization, and billing functions that is directly connected to the AUSF or indirectly connected via other network devices. The AAA server can be a network device within the core network. It should be noted that the AAA server may not be included in the core network_A and / or core network_B, but included in the PLMN. In other words, the AAA server can be a core network device or a device outside the core network. For example, the AAA server can be a server device within the PLMN managed by a 3rd party.
[0061] It should be noted that in Figure 2In the figure, each device and function is shown as one for simplicity, but multiple identical devices and functions may be configured in the mobile communication system 1. Specifically, multiple devices and functions such as UE_A 10, E-UTRAN 80, MME 40, SGW 35, PGW-U 30, PGW-C 32, PCRF 60, HSS 50, 5G AN 120, AMF 140, UPF 130, SMF 132, PCF 160, and / or UDM 150 may be configured in the mobile communication system 1.
[0062] [2. Configuration of Each Device]
[0063] Next, the configuration of each device (UE and / or access network device and / or core network device) used in each embodiment is described using the accompanying drawings. It should be noted that each device can be configured as physical hardware, as logical (virtual) hardware configured on general-purpose hardware, or as software. In addition, at least part (including all) of the functions of each device can also be configured as physical hardware, logical hardware, or software.
[0064] It should be noted that the storage units (storage_A340, storage_A440, storage_B540, storage_A640, storage_B740) within each device and function described below are composed of, for example, semiconductor memories, SSDs (Solid State Drives), HDDs (Hard Disk Drives), etc. In addition, each storage unit can store not only the information originally set at the factory stage, but also various information sent and received between the device itself and devices and functions other than the function (such as UEs and / or access network devices and / or core network devices and / or PDNs and / or DNs). In addition, each storage unit can store identification information, control information, flags, parameters, etc. included in control messages sent and received within the various communication processes described below. In addition, each storage unit can store this information in each UE. In addition, when intercommunication between 5GS and EPS is performed, each storage unit can store control messages and user data sent and received between the devices and functions included in the 5GS and / or EPS. At this time, not only data sent and received via the N26 interface can be stored, but also data not sent and received via the N26 interface can be stored.
[0065] [2.1. UE Device Configuration]
[0066] First, use Figure 3An example of the configuration of a UE (User Equipment) is described. The UE is composed of a control unit A300, an antenna 310, a transceiver A320, and a storage unit A340. The control unit A300, the transceiver A320, and the storage unit A340 are connected via a bus. The transceiver A320 is connected to the antenna 310.
[0067] The control unit A300 is a functional unit that controls the overall operation and functions of the UE. The control unit A300 reads and executes various programs stored in the storage unit A340 as needed to implement various processes in the UE.
[0068] The transceiver_A320 is a functional unit for wireless communication with a base station (eNB or gNB) within the access network via an antenna. Specifically, the UE uses the transceiver_A320 to transmit and receive user data and / or control information with the access network, core network, PDN, and / or DN.
[0069] Reference Figure 2 To explain in detail, the UE can communicate with the base station device (eNB) within the E-UTRAN via the LTE-Uu interface using the transceiver_A320. Furthermore, the UE can communicate with the base station device (gNB) within the 5G AN using the transceiver_A320. Furthermore, the UE can send and receive NAS (Non-Access-Stratum) messages with the AMF via the N1 interface using the transceiver_A320. However, the N1 interface is a logical interface, so in practice, communication between the UE and the AMF is carried out via the 5G AN.
[0070] The storage unit_A340 is a functional unit for storing programs, user data, control information, etc. required for various actions of the UE.
[0071] [2.2. gNB Device Configuration]
[0072] Next, use Figure 4 An example of a gNB configuration is described below. The gNB consists of a control unit B500, an antenna 510, a network connection unit B520, a transceiver B530, and a storage unit B540. The control unit B500, the network connection unit B520, the transceiver B530, and the storage unit B540 are connected via a bus. The transceiver B530 is connected to the antenna 510.
[0073] The control unit B500 controls the overall operation and functions of the gNB. It implements various processes within the gNB by reading and executing various programs stored in the storage unit B540 as needed.
[0074] The Network Connection Unit_B520 is a functional unit for communication between the gNB and the AMF and / or UPF. Specifically, the gNB can use the Network Connection Unit_B520 to send and receive user data and / or control information with the AMF and / or UPF.
[0075] The transceiver_B 530 is a functional unit for wirelessly communicating with the UE via the antenna 510. Specifically, the gNB can use the transceiver_B 530 to transmit and receive user data and / or control information to and from the UE.
[0076] Reference Figure 2 To elaborate, the gNB within the 5G AN can communicate with the AMF via the N2 interface using the network connection unit_B520 and with the UPF via the N3 interface. Furthermore, the gNB can communicate with the UE using the transceiver unit_B530.
[0077] Storage unit_B540 is a functional unit used to store programs, user data, control information, etc. required for various actions of gNB.
[0078] [2.3.AMF Device Configuration]
[0079] Next, use Figure 5 The following describes an example of the AMF device configuration. The AMF consists of a control unit B700, a network connection unit B720, and a storage unit B740. The control unit B700, the network connection unit B720, and the storage unit B740 are connected via a bus. The AMF can be a node that processes the control plane.
[0080] The control unit B700 is a functional unit that controls the overall operation and functions of the AMF. The control unit B700 reads and executes various programs stored in the storage unit B740 as needed to implement various processes in the AMF.
[0081] The Network Connection Unit_B720 is a functional unit for connecting the AMF to a base station device (gNB), SMF, PCF, UDM, and / or SCEF within the 5G AN. Specifically, the AMF can use the Network Connection Unit_B720 to transmit and receive user data and / or control information with a base station device (gNB), SMF, PCF, UDM, and / or SCEF within the 5G AN.
[0082] Reference Figure 2To be more specific, the AMF within the 5GCN can communicate with the gNB via the N2 interface by using the network connection section_A 620, can communicate with the UDM via the N8 interface, can communicate with the SMF via the N11 interface, and can communicate with the PCF via the N15 interface. Further, the AMF can perform transmission and reception of NAS messages with the UE via the N1 interface by using the network connection section_A 620. Note that the N1 interface is a logical interface, and thus, in reality, communication between the UE and the AMF is performed via the 5G AN. Further, the AMF can communicate with the MME via the N26 interface by using the network connection section_A 620 in a case where the N26 interface is supported.
[0083] The storage section_B 740 is a functional section for storing programs, user data, control information, and the like required for each action of the AMF.
[0084] Note that the AMF has a function of exchanging control messages with a RAN using the N2 interface, a function of exchanging NAS messages with a UE using the N1 interface, a function of performing encryption and integrity protection of NAS messages, a Registration management (RM) function, a Connection management (CM) function, a Reachability management function, a Mobility management function of a UE or the like, a function of transferring SM (Session Management) messages between a UE and an SMF, an Access Authentication function, a Security Anchor function (SEA), a Security Context management (SCM) function, a function of supporting an N2 interface for an N3IWF (Non-3GPP Interworking Function), a function of supporting transmission and reception of NAS signals with a UE via an N3IWF, a function of authenticating a UE connected via an N3IWF, and the like.
[0085] In addition, the RM state of each UE is managed in the login management. The RM state can be synchronized between the UE and the AMF. As RM states, there are non-login states (RM-DEREGISTERED state) and login states (RM-REGISTERED state). In the non-login state, the UE is not logged in to the network. Therefore, the UE context in the AMF does not have valid location information and routing information for the UE, so the AMF is in a state where the UE cannot be reached. In addition, in the login state, the UE is logged in to the network. Therefore, the UE can receive services that require logging in to the network. It should be noted that the RM state can also be expressed as a 5GMM state (5GMMstate). In this case, the non-login state can also be expressed as a 5GMM-DEREGISTERED state, and the login state can also be expressed as a 5GMM-REGISTERED state.
[0086] In other words, 5GMM-REGISTERED can be a state where each device has established a 5GMM context, or a state where a PDU session context has been established. It should be noted that when each device is in the 5GMM-REGISTERED state, UE_A10 can start sending and receiving user data and control messages, and can also respond to paging. It should also be noted that when each device is in the 5GMM-REGISTERED state, UE_A10 can perform login procedures and / or service request procedures other than the login procedure for initial login.
[0087] Furthermore, 5GMM-DEREGISTERED can mean that each device has not established a 5GMM context, that the network does not have the location information of UE_A10, or that the network cannot reach UE_A10. It should be noted that when each device is in the 5GMM-DEREGISTERED state, UE_A10 can either initiate a login process or establish a 5GMM context by executing the login process.
[0088] In addition, the CM state of each UE is managed in the connection management. The CM state can be synchronized between the UE and the AMF. As CM states, there are a non-connected state (CM-IDLE state) and a connected state (CM-CONNECTED state). In the non-connected state, the UE is in a logged-in state, but does not have a NAS signaling connection (NAS signaling connection) established with the AMF via the N1 interface. In addition, in the non-connected state, the UE does not have a connection (N2 connection) of the N2 interface and a connection (N3 connection) of the N3 interface. On the other hand, in the connected state, it has a NAS signaling connection (NAS signaling connection) established with the AMF via the N1 interface. In addition, in the connected state, the UE may also have a connection (N2 connection) of the N2 interface and / or a connection (N3 connection) of the N3 interface.
[0089] Moreover, in connection management, it can also be divided into CM states in 3GPP access and CM states in non-3GPP access for management. In this case, as the CM state in 3GPP access, there can be a non-connected state in 3GPP access (CM-IDLE state over 3GPP access) and a connected state in 3GPP access (CM-CONNECTED state over3GPP access). Moreover, as the CM state in non-3GPP access, there can be a non-connected state in non-3GPP access (CM-IDLE state over non-3GPP access) and a connected state in non-3GPP access (CM-CONNECTEDstate over non-3GPP access). It should be noted that the non-connected state can be expressed as an idle mode, and the connected state mode can be expressed as a connected mode.
[0090] It should be noted that the CM state can also be expressed as 5GMM mode (5GMM mode). In this case, the non-connected state can also be expressed as 5GMM non-connected mode (5GMM-IDLE mode), and the connected state can also be expressed as 5GMM connected mode (5GMM-CONNECTED mode). Moreover, the non-connected state in 3GPP access can also be expressed as 5GMM non-connected mode in 3GPP access (5GMM-IDLE mode over 3GPP access), and the connected state in 3GPP access can also be expressed as 5GMM connected mode in 3GPP access (5GMM-CONNECTED mode over 3GPP access). Moreover, the non-connected state in non-3GPP access can also be expressed as 5GMM non-connected mode in non-3GPP access (5GMM-IDLE modeover non-3GPP access), and the connected state in non-3GPP access can also be expressed as 5GMM connected mode in non-3GPP access (5GMM-CONNECTED mode over non-3GPP access). It should be noted that the 5GMM non-connected mode can be expressed as an idle mode, and the 5GMM connected mode can be expressed as a connected mode.
[0091] In addition, more than one AMF can be configured in the core network_B. In addition, the AMF can be an NF that manages more than one NSI (Network Slice Instance). In addition, the AMF can also be a shared CP function (CCNF; Common CPNF (Control Plane Network Function)) shared among multiple NSIs.
[0092] It should be noted that N3IWF is a device and / or function configured between non-3GPP access and 5GCN when the UE is connected to 5GS via non-3GPP access.
[0093] [2.4.SMF device configuration]
[0094] Next, use Figure 5 An example of the SMF device configuration is described below. The SMF consists of a control unit B700, a network connection unit B720, and a storage unit B740. The control unit B700, the network connection unit B720, and the storage unit B740 are connected via a bus. The SMF can be a node that processes the control plane.
[0095] The control unit_B700 is a functional unit that controls the entire operation and functions of the SMF. The control unit_B700 realizes various processes in the SMF by reading and executing various programs stored in the storage unit_B740 as needed.
[0096] The network connection unit_B720 is a functional unit for connecting the SMF with the AMF and / or UPF and / or PCF and / or UDM. In other words, the SMF can use the network connection unit_B720 to send and receive user data and / or control information between the AMF and / or UPF and / or PCF and / or UDM.
[0097] Reference Figure 2 To explain in detail, the SMF in 5GCN can communicate with AMF via the N11 interface by using the network connection part _A620, can communicate with UPF via the N4 interface, can communicate with PCF via the N7 interface, and can communicate with UDM via the N10 interface.
[0098] The storage unit_B740 is a functional unit for storing programs, user data, control information, etc. required for various actions of the SMF.
[0099] SMF has the following functions: session management (SessionManagement) function such as establishment, modification, and release of PDU sessions, IP address allocation (IP address allocation) and its management function for UE, UPF selection and control function, UPF setting function for routing services to the appropriate destination (sending destination), function of sending and receiving the SM part of NAS messages, function of notifying that downlink data has arrived (Downlink Data Notification), function of providing AN-specific (each AN's) SM information sent to AN via AMF through the N2 interface, function of determining the SSC mode (Session and Service Continuity mode) for the session, and roaming function, etc.
[0100] [2.5. UPF device configuration]
[0101] Next, use Figure 5 The following describes an example of a UPF configuration. The UPF consists of a control unit B700, a network connection unit B720, and a storage unit B740. The control unit B700, the network connection unit B720, and the storage unit B740 are connected via a bus. The UPF can be a node that processes the control plane.
[0102] The control unit_B700 is a functional unit that controls the overall operation and functions of the UPF. The control unit_B700 reads and executes various programs stored in the storage unit_B740 as needed to implement various processes in the UPF.
[0103] The Network Connection Unit_B720 is a functional unit for connecting the UPF to a base station (gNB) and / or SMF and / or DN within the 5G AN. Specifically, the UPF can use the Network Connection Unit_B720 to transmit and receive user data and / or control information with a base station (gNB) and / or SMF and / or DN within the 5G AN.
[0104] Reference Figure 2 To provide a detailed explanation, the UPF in the 5GCN can communicate with the gNB via the N3 interface by using the network connection part _A620, can communicate with the SMF via the N4 interface, can communicate with the DN via the N6 interface, and can communicate with other UPFs via the N9 interface.
[0105] Storage unit_B740 is a functional unit for storing programs, user data, control information, etc. required for various actions of UPF.
[0106] UPF has the following functions: serving as an anchor point for intra-RAT mobility or inter-RAT mobility, serving as an external PDU session point for interconnecting with DN (that is, serving as a gateway between DN and core network_B to transmit user data), routing and transmitting packets, UL CL (Uplink Classifier) function that supports routing of multiple service flows for one DN, branching point function that supports multi-homed PDU sessions, QoS (Quality of Service) processing function for user plane, verification function of uplink services, triggering buffering of downlink packets, downlink data notification function, etc.
[0107] Furthermore, the UPF can be a gateway for IP and / or non-IP communications. Furthermore, the UPF can function as both a transport for IP communications and a converter for non-IP and IP communications. Furthermore, the multiple gateways configured can be gateways connecting the core network B and a single DN. It should be noted that the UPF can have connectivity with other NFs and can also connect to various devices via other NFs.
[0108] It should be noted that the user plane is user data sent and received between the UE and the network. The user plane can be sent and received using a PDN connection or a PDU session. In the case of EPS, the user plane can also be sent and received using the LTE-Uu interface and / or the S1-U interface and / or the S5 interface and / or the S8 interface and / or the SGi interface. In the case of 5GS, the user plane can also be sent and received via the interface between the UE and the NG RAN and / or the N3 interface and / or the N9 interface and / or the N6 interface. Hereinafter, the user plane may also be represented as U-Plane.
[0109] The control plane is responsible for sending and receiving control messages for purposes such as UE communication control. This control plane can use the NAS (Non-Access-Stratum) signaling connection between the UE and the MME for transmission and reception. Furthermore, in the case of EPS, the control plane can also use the LTE-Uu interface and the S1-MME interface for transmission and reception. Furthermore, in the case of 5GS, the control plane can also use the interface between the UE and the NG RAN and the N2 interface for transmission and reception. Hereinafter, the control plane may also be referred to as the Control Plane or the C-Plane.
[0110] Furthermore, the user plane (U-Plane, User Plane; UP) can be a communication path for sending and receiving user data and can be composed of multiple bearers. Furthermore, the control plane (C-Plane, Control Plane; CP) can be a communication path for sending and receiving control messages and can be composed of multiple bearers. [2.6. Description of Other Devices and / or Functions and / or Identification Information in This Embodiment]
[0111] Next, other devices, functions, and / or identification information will be described.
[0112] The term "network" refers to at least a portion of the access network B, core network B, and DN. Furthermore, one or more devices included in at least a portion of the access network B, core network B, and DN may also be referred to as a network or network device. Specifically, "the network performs message transmission, reception, and / or processing" may mean that a device within the network (a network device and / or a control device) performs message transmission, reception, and / or processing. Conversely, "a device within the network performs message transmission, reception, and / or processing" may mean that the network performs message transmission, reception, and / or processing.
[0113] In addition, SM (Session Management) messages (also known as NAS (Non-Access-Stratum) SM messages) can be NAS messages used in the SM process, or they can be control messages sent and received between UE_A10 and SMF_A230 via AMF_A240. Furthermore, SM messages can include PDU session establishment request messages, PDU session establishment accept messages, PDU session complete messages, PDU session reject messages, PDU session change request messages, PDU session change accept messages, and PDU session change response messages. Furthermore, the SM process can include the PDU session establishment process.
[0114] Furthermore, MM (Mobility Management) messages (also known as NAS MM messages) can be NAS messages used in MM processes, or they can be control messages sent and received between UE_A10 and SMF_A230 via AMF_A240. MM messages can include login request messages, login acceptance messages, login rejection messages, deregistration request messages, deregistration acceptance messages, UE configuration update request messages, and UE configuration update acceptance messages. Furthermore, MM processes can include login processes, deregistration processes, UE configuration update processes, authentication, and authorization processes.
[0115] Furthermore, 5GS (5G System) services may be connection services provided using the core network B190. Furthermore, 5GS services may be different from EPS services or the same as EPS services.
[0116] In addition, non-5GS services may be services other than 5GS services, and may also include EPS services and / or non-EPS services.
[0117] The PDN (Packet Data Network) type indicates the type of PDN connection, including IPv4, IPv6, IPv4v6, and non-IP. If IPv4 is specified, data is sent and received using IPv4. If IPv6 is specified, data is sent and received using IPv6. If IPv4v6 is specified, data is sent and received using either IPv4 or IPv6. If non-IP is specified, communication is not performed using IP, but rather using a communication method other than IP.
[0118] A PDU (Protocol Data Unit / Packet Data Unit) session can be defined as an association between a DN providing PDU connectivity services and a UE, but can also be connectivity established between a UE and an external gateway. The UE can use a PDU session to send and receive user data with the DN by establishing a PDU session in the 5GS via the access network B and the core network B. Here, the external gateway can be a UPF, SCEF, or similar device. The UE can use a PDU session to send and receive user data with devices such as application servers deployed in the DN.
[0119] It should be noted that each device (UE and / or access network device and / or core network device) can also manage one or more identification information corresponding to the PDU session establishment. It should be noted that these identification information may include one or more of DNN, QoS rules, PDU session type, application identification information, NSI identification information, access network identification information and SSC mode, and may further include other information. Moreover, in the case of establishing multiple PDU sessions, the identification information corresponding to the PDU session establishment can be the same content or different content.
[0120] Furthermore, the DNN (Data Network Name) can be identification information for external networks such as the core network and / or DN. Furthermore, the DNN can be used to select gateways such as PGW_A30 / UPF_A235 that connect to the core network B190. Furthermore, the DNN can be equivalent to the APN (Access Point Name).
[0121] In addition, the PDU (Protocol Data Unit / Packet Data Unit) session type indicates the type of PDU session, which includes IPv4, IPv6, Ethernet, and Unstructured. When IPv4 is specified, it indicates that IPv4 is used to send and receive data. When IPv6 is specified, it indicates that IPv6 is used to send and receive data. When Ethernet is specified, it indicates that Ethernet frames are sent and received. In addition, Ethernet can indicate that communication without using IP is performed. When Unstructured is specified, it indicates that Point-to-Point (P2P) tunneling technology is used to send and receive data to an application server or the like in the DN. As a P2P tunneling technology, for example, UDP / IP encapsulation technology can also be used. It should be noted that IP can be included in the above-mentioned others in the PDU session type. IP can be specified when the UE can use both IPv4 and IPv6.
[0122] In addition, a network slice (NS) refers to a logical network that provides specific network capabilities and network characteristics. UE and / or network can support network slicing (NW slicing; NS) in 5GS.
[0123] In addition, a network slice instance (NSI) refers to a network slice formed and configured by a collection of instances (entities) of network functions (NFs) and required resources. Here, NF refers to a processing function in a network, which is adopted or defined in 3GPP. NSI is an entity that constitutes one or more NSs within the core network_B. In addition, NSI can be composed of a virtual NF (Network Function) generated using NST (Network Slice Template). Here, NST refers to a logical expression of one or more NFs associated with a resource request for providing the requested communication service or capability. That is, NSI can refer to an aggregate within the core network_B190 composed of multiple NFs. In addition, NSI can be a logical network configured to divide the user data sent according to services, etc. There can be more than one NF in the NS. The NF constituted in the NS may be a device shared with other NSs, or may not be a device shared with other NSs. The UE and / or devices within the network can be assigned to one or more NSs based on registration information such as NSSAI and / or S-NSSAI and / or UE usage type and / or one or more NSI IDs and / or APN. It should be noted that the UE usage type is a parameter value included in the UE's registration information for identifying the NSI. The UE usage type can be stored in the HSS. The AMF can select the SMF and UPF based on the UE usage type.
[0124] In addition, S-NSSAI (Single Network Slice Selection Assistance information) is information used to identify NS. S-NSSAI can be composed of only SST (Slice / Servicetype: Slice / Service type), or it can be composed of both SST and SD (Slice Differentiator: Slice Differentiator). Here, SST refers to information indicating the expected actions of NS in terms of functions and services. In addition, SD can be information that interpolates SST when selecting an NSI from multiple NSIs shown in SST. S-NSSAI can be information specific to each PLMN, or it can be standard information common between PLMNs. In addition, the network can store more than one S-NSSAI in the UE's login information as the default S-NSSAI. It should be noted that when the S-NSSAI is the default S-NSSAI, the network can provide the NS related to the UE when the UE does not send a valid S-NSSAI to the network in the login request message.
[0125] In addition, NSSAI (Network Slice Selection Assistance Information) is a collection of S-NSSAI. Each S-NSSAI included in NSSAI is information that assists the access network or core network in selecting NSI. The UE can store the NSSAI allowed by the network for each PLMN. In addition, NSSAI can be information used to select the AMF.
[0126] In addition, the configured NSSAI is the NSSAI provided and stored in the UE. The UE can store the configured NSSAI for each PLMN. The configured NSSAI can be information set by the network (or PLMN).
[0127] Further, a requested NSSAI (requested NSSAI) is an NSSAI provided from a UE to a network in a registration procedure. The requested NSSAI can be an allowed NSSAI (allowed NSSAI) or a configured NSSAI stored by the UE. Specifically, the requested NSSAI can be information indicating network slices that the UE desires to access. The S-NSSAI included in the requested NSSAI can be referred to as a requested S-NSSAI (requested S-NSSAI). For example, the requested NSSAI is transmitted in a NAS message or an RRC (Radio Resource Control) message including a NAS (Non-Access-Stratum) message transmitted from the UE to the network, such as a registration request message or a PDU session establishment request message.
[0128] Further, an allowed NSSAI is information indicating one or more network slices that a UE is allowed. In other words, the allowed NSSAI is information identifying network slices to which the network is allowed to connect the UE. The UE and the network respectively store and manage the allowed NSSAI as information of the UE per access (3GPP access or non-3GPP access). The S-NSSAI included in the allowed NSSAI can be referred to as an allowed S-NSSAI (allowed S-NSSAI).
[0129] Further, a rejected NSSAI is information indicating one or more network slices that a UE is not allowed. In other words, the rejected NSSAI is information identifying network slices to which the network is not allowed to connect the UE. The rejected NSSAI can be information including one or more S-NSSAIs in combination with a reason value. It is noted that the reason value is information indicating a reason why the network rejects the corresponding S-NSSAI. The UE and the network can respectively appropriately store and manage the rejected NSSAI based on establishing a corresponding reason value for each S-NSSAI. Also, the rejected NSSAI can be included in a NAS message or an RRC message including a NAS message transmitted from the network to the UE, such as a registration accept message, a configuration update command, a registration reject message, etc. The S-NSSAI included in the rejected NSSAI can be referred to as a rejected S-NSSAI (rejected S-NSSAI). The rejected NSSAI can be any one of a first to fourth rejected NSSAI, or a combination of the first to fourth rejected NSSAI.
[0130] Here, the first rejected NSSAI is a set of one or more S-NSSAIs that are not available in the current PLMN among the S-NSSAIs included in the requested NSSAI by the UE. The first rejected NSSAI can be the rejected NSSAI for the current PLMN of the 5GS. The first rejected NSSAI can be the rejected NSSAI stored by the UE or NW, or the rejected NSSAI sent from the NW to the UE. In the case where the first rejected NSSAI is the rejected NSSAI sent from the NW to the UE, the first rejected NSSAI can be information including a combination of one or more S-NSSAIs and a reason value. The reason value at this time can be "S-NSSAI not available in the current PLMN" or information indicating that the S-NSSAI corresponding to the reason value is not available in the current PLMN.
[0131] The first rejected NSSAI is valid for the entire registered PLMN. In other words, the UE and / or NW can process the first rejected NSSAI and the S-NSSAI included in the first rejected NSSAI as information independent of the access type. In other words, the first rejected NSSAI can be information valid for both 3GPP access and non-3GPP access.
[0132] The UE may delete the first rejected NSSAI from storage when the UE transitions to a non-registered state for the current PLMN via both 3GPP access and non-3GPP access. In other words, when the UE transitions to a non-registered state for the current PLMN via a certain access, successfully registers to a new PLMN via a certain access, or fails to register to a new PLMN via a certain access and transitions to a non-registered state, and when the UE is in a non-registered state (non-registered state) via another access, the UE deletes the first rejected NSSAI.
[0133] The second rejected NSSAI is a set of one or more S-NSSAIs that are not available in the current registration area among the S-NSSAIs included in the requested NSSAI by the UE. The second rejected NSSAI can be the rejected NSSAI for the current registration area of the 5GS. The second rejected NSSAI can be the rejected NSSAI stored by the UE or NW, or it can be the rejected NSSAI sent from the NW to the UE. In the case where the second rejected NSSAI is the rejected NSSAI sent from the NW to the UE, the second rejected NSSAI can be information including a combination of one or more S-NSSAIs and a reason value. The reason value at this time can be "S-NSSAI not available in the current registration area", or it can be information indicating that the S-NSSAI corresponding to the reason value is not available in the current registration area.
[0134] The second rejected NSSAI is valid within the current login area. That is, the UE and / or NW can process the second rejected NSSAI and the S-NSSAI included in the second rejected NSSAI as information for each access type. That is, the second rejected NSSAI can be information valid for 3GPP access or non-3GPP access, respectively. That is, upon transitioning to the non-logged state for a particular access, the UE can delete the second rejected NSSAI from storage.
[0135] The third rejected NSSAI is the S-NSSAI for which the network requires network slice specific authentication and authorization, and is a collection of one or more S-NSSAIs for which network slice specific authentication and authorization are not completed and are not available in the current PLMN. The third rejected NSSAI may be the NSSAI rejected by the 5GS due to network slice specific authentication and authorization (Rejected NSSAI due to network slice specific authentication and authorization). The third rejected NSSAI may be the rejected NSSAI stored by the UE or NW, or the rejected NSSAI sent from the NW to the UE. In the case where the third rejected NSSAI is the NSSAI sent from the NW to the UE, the third rejected NSSAI may be information including a combination of one or more S-NSSAIs and a reason value. The reason value at this time can be "Network slice-specific authentication and authorization pending for the S-NSSAI", or it can be information indicating that the S-NSSAI corresponding to the reason value is prohibited or pending until the network slice-specific authentication and authorization for the S-NSSAI is completed.
[0136] The third rejected NSSAI is valid for the entire registered PLMN. In other words, the UE and / or NW can process the third rejected NSSAI and the S-NSSAI included in the third rejected NSSAI as information independent of the access type. That is, the third rejected NSSAI can be information valid for both 3GPP access and non-3GPP access. The third rejected NSSAI can be an NSSAI different from the rejected NSSAI. The third rejected NSSAI can also be the first rejected NSSAI.
[0137] The third rejected NSSAI is an NSSAI composed of one or more S-NSSAIs that identify the slice for which the UE is pending a procedure. Specifically, while storing the third rejected NSSAI, the UE does not initiate a login request procedure for the S-NSSAI included in the third rejected NSSAI. In other words, the UE does not use the S-NSSAI included in the third rejected NSSAI in the login procedure until network slice-specific authentication and authorization for the S-NSSAI included in the third rejected NSSAI are completed. The third rejected NSSAI is identification information including one or more S-NSSAIs received from the core network in correspondence with a pending reason value indicating network slice-specific authentication and authorization. The third rejected NSSAI is information that is independent of the access type. Specifically, if the UE stores the third rejected NSSAI, the UE does not attempt to send a login request message including the S-NSSAI included in the third rejected NSSAI to both the 3GPP access and non-3GPP access parties.
[0138] The fourth rejected NSSAI is the S-NSSAI for which the network requires network slice specific authentication and authorization, and is a collection of one or more S-NSSAIs for which the network slice specific authentication and authorization results in failure. The fourth rejected NSSAI may be the NSSAI stored by the UE or NW, or it may be the NSSAI sent from the NW to the UE. In the case where the fourth rejected NSSAI is the NSSAI sent from the NW to the UE, the fourth rejected NSSAI may be information including a combination of one or more S-NSSAIs and a reason value. The reason value at this time may be "Network slice specific authentication and authorization failure S-NSSAI (Networkslice-specific authentication and authorization failure for the S-NSSAI)", or it may be information indicating the failure of network slice specific authentication and authorization for the S-NSSAI corresponding to the reason value.
[0139] The fourth rejected NSSAI is valid for the entire registered PLMN. In other words, the UE and / or NW may process the fourth rejected NSSAI and the S-NSSAI included therein as information independent of the access type. That is, the fourth rejected NSSAI may be information valid for both 3GPP access and non-3GPP access. The fourth rejected NSSAI may be an NSSAI different from the rejected NSSAI. The fourth rejected NSSAI may also be the first rejected NSSAI.
[0140] The fourth rejected NSSAI identifies a slice that was rejected due to a failure of network slice-specific authentication and authorization by the UE from the core network. Specifically, while storing the fourth rejected NSSAI, the UE does not initiate a login request procedure for the S-NSSAI included in the fourth rejected NSSAI. The fourth rejected NSSAI includes one or more identification information of an S-NSSAI received from the core network in correspondence with a reason value indicating a failure of network slice-specific authentication and authorization. The fourth rejected NSSAI is access type-independent information. Specifically, if the UE stores the fourth rejected NSSAI, the UE may not attempt to send a login request message including the S-NSSAI included in the fourth rejected NSSAI to both the 3GPP access and the non-3GPP access. Alternatively, the UE may send a login request message including the S-NSSAI included in the fourth rejected NSSAI based on UE policy. Alternatively, the UE may delete the fourth rejected NSSAI based on UE policy and transition to a state where it can send a login request message including the S-NSSAI included in the fourth rejected NSSAI.
[0141] The tracking area is a single or multiple ranges managed by the core network that can be represented by the location information of UE_A10. The tracking area can be composed of multiple cells. Moreover, the tracking area can be the range of control messages such as broadcast paging, or the range in which UE_A10 can move without performing a switching process. Moreover, the tracking area can be a routing area or a location area, as long as it is the same area as these areas. Hereinafter, the tracking area may also be TA (Tracking Area). The tracking area can be identified by TAI (Tracking Area Identity) composed of TAC (Tracking area code) and PLMN.
[0142] The registration area (or registration area) is a set of one or more TAs assigned to the UE by the AMF. It should be noted that while UE_A10 is moving within one or more TAs included in the registration area, it can move without sending or receiving signals for tracking area updates. In other words, the registration area can be an information group indicating the area in which UE_A10 can move without performing the tracking area update process. The registration area can be identified by a TAIlist consisting of one or more TAIs.
[0143] UE ID refers to information used to identify the UE. Specifically, for example, the UE ID can be SUCI (SUbscription Concealed Identifier), SUPI (Subscription Permanent Identifier), GUTI (Globally Unique Temporary Identifier), IMEI (International Mobile Subscriber Identity), IMEISV (IMEI Software Version), or TMSI (Temporary Mobile Subscriber Identity). Alternatively, the UE ID can be other information set within an application or network. Furthermore, the UE ID can be information used to identify a user.
[0144] The network slice specific authentication and authorization function refers to the function used to implement the authentication and authorization specific to the network slice. In the network slice specific authentication and authorization, the authentication and authorization of the UE can be performed outside the core network such as the 3rd party. The PLMN and network devices equipped with the network slice specific authentication and authorization function can perform the network slice specific authentication and authorization process for a certain S-NSSAI based on the login information of the UE. In addition, the UE equipped with the network slice specific authentication and authorization function can manage and store the pending rejected NSSAI for the network slice specific authentication and authorization and / or the rejected NSSAI for the failure of the network slice specific authentication and authorization. In this specification, the network slice specific authentication and authorization is sometimes referred to as the network slice specific authentication and authorization process, the authentication and authorization process.
[0145] The S-NSSAI requiring network slice specific authentication and authorization is an S-NSSAI requiring network slice specific authentication and authorization managed by the core network and / or the core network device. The core network and / or the core network device may store the S-NSSAI requiring network slice specific authentication and authorization by establishing a correspondence between the S-NSSAI and information indicating whether network slice specific authentication and authorization are required. The core network and / or the core network device may further establish a correspondence between the S-NSSAI requiring network slice specific authentication and authorization and information indicating whether the network slice specific authentication and authorization are completed, or information indicating that the network slice specific authentication and authorization are completed and are in an allowed or successful state. The core network and / or the core network device may manage the S-NSSAI requiring network slice specific authentication and authorization as information that is independent of the access network.
[0146] Next, in this embodiment, the identification information sent, received, stored, and managed by each device is described. The first identification information may be information indicating that the UE supports network slice-specific authentication and authorization functions. Alternatively, the first identification information may be information indicating whether the network slice-specific authentication and authorization functions are supported. The first identification information may be 5G MM capability information. The first identification information may be information indicating that the UE can store the first rejected NSSAI and / or the second rejected NSSAI.
[0147] The second identification information is information identifying the slice requested by the UE. Specifically, the second identification information may be the requested NSSAI, which may be configured to include one or more S-NSSAIs. The S-NSSAI included in the second identification information may be the S-NSSAI included in the configured NSSAI stored by the UE or the S-NSSAI included in the allowed NSSAI. Furthermore, the UE does not include the S-NSSAI included in the rejected NSSAI stored by the UE in the second identification information.
[0148] Specifically, when storing a rejected NSSAI corresponding to the PLMN of the second identification information, the UE determines whether to include the S-NSSAI in the second identification information based on the reason value corresponding to each S-NSSAI included in the rejected NSSAI. For example, the UE does not include the S-NSSAI corresponding to the reason value indicating pending for network slice specific authentication and authorization in the second identification information.
[0149] The third identification information is information indicating a user ID and / or UE ID used in network slice-specific authentication and authorization for the slice requested by the UE. Specifically, the third identification information may be a user ID and / or UE ID used for network slice-specific authentication and authorization corresponding to the S-NSSAI, or may be a GPSI. The third identification information may be associated with the second identification information.
[0150] The eleventh identification information is information indicating that the core network and / or the core network device supports the network slice specific authentication and authorization function. The eleventh identification information may be 5GMM NW capability information. The eleventh identification information may be information notifying the core network to enable the UE to be in a state capable of performing the network slice specific authentication and authorization process based on the network slice specific authentication and authorization function.
[0151] The twelfth identification information is information identifying the slices allowed by the core network. Specifically, the twelfth identification information may be the allowed NSSAI, which may include one or more S-NSSAIs. The twelfth identification information may be information for each access. In addition, if the core network does not store the allowed NSSAI that can be sent to the UE, and if the allowed NSSAI may be allocated in the future, the twelfth identification information may be empty information.
[0152] The thirteenth identification information is information identifying a set of one or more S-NSSAIs rejected by the core network in the S-NSSAI included in the second identification information. In other words, it is information identifying a set of S-NSSAIs not permitted by the core network. The thirteenth identification information may be the rejected NSSAI of the 5GS. Specifically, the thirteenth identification information may be information including one or more S-NSSAIs and each reason value associated with each S-NSSAI. The thirteenth identification information may be a rejected NSSAI consisting of at least one of the first to fourth rejected NSSAIs.
[0153] The fourteenth identification information is a timer value indicating the pending time for network slice specific authentication and authorization. In other words, the fourteenth identification information may be information indicating the start of a timer count using the timer value indicated by the fourteenth identification information. The fourteenth identification information may be associated with the thirteenth identification information or may be combined with the thirteenth identification information and transmitted and received as a single message.
[0154] The fifteenth identification information is information indicating that the AMF of the UE's login destination has changed from the AMF of the previous login destination. The fifteenth identification information may be a flag or identification information. The fifteenth identification information may be information that identifies the AMF, for example, it may be a GUTI (Globally Unique Temporary Identifier), or it may be an AMF Region ID or AMF Set ID included in the GUTI, or it may be an AMF Pointer. The fifteenth identification information may be a login area.
[0155] The sixteenth identification information may be information indicating whether to delete the third rejected NSSAI stored by the UE. Alternatively, the sixteenth identification information may be information indicating that the UE deletes the third rejected NSSAI.
[0156] The sixteenth identification may include information indicating to the UE that one or more S-NSSAIs are deleted from the third rejected NSSAI. Specifically, if the NW sends the sixteenth identification information to the UE, the UE may delete the one or more S-NSSAIs included in the sixteenth identification information from the third rejected NSSAI.
[0157] The twenty-first identification information is information identifying a slice that the network allows the UE to use. The twenty-first identification information may be an allowed NSSAI. The twenty-first identification information may be a newly allocated allowed NSSAI. The twenty-first identification information may include an S-NSSAI included in a rejected NSSAI due to pending Slice Specific Authentication.
[0158] The 22nd identification information is information identifying a slice rejected by the core network, in other words, information identifying a slice not permitted by the core network. The 22nd identification information may be a rejected NSSAI of the 5GS. Specifically, the 22nd identification information may be information including one or more S-NSSAIs and reason values associated with each S-NSSAI. The 22nd identification information may be a rejected NSSAI consisting of at least one of the first to fourth rejected NSSAIs.
[0159] The twenty-fifth identification information may be information indicating that the UE is requested to start the login procedure again. The twenty-fifth identification information may be information indicated by a Configuration update indication IE (information element).
[0160] The thirty-first identification information is information identifying a slice rejected by the core network, in other words, information identifying a slice not permitted by the core network. The thirty-first identification information may be a rejected NSSAI of the 5GS. Specifically, the thirty-first identification information may be information including one or more S-NSSAIs and each rejection reason value associated with each S-NSSAI. The thirty-first identification information may be a rejected NSSAI consisting of at least one of the first to fourth rejected NSSAIs.
[0161] The 32nd identification information is information indicating that the core network currently does not have an allowed NSSAI for the UE. The 32nd identification information may be the 5G MM reason of 5G, which is no available network slices (cause No network slices available).
[0162] It should be noted that each device can exchange and / or obtain various capability information and / or various request information of each device during the broadcast information and / or RRC process and / or the login process to the core network and / or the service request process for emergency calls.
[0163] In addition, each device involved in this process can send and receive each control message described in this process, send and receive one or more identification information included in each control message, and store the sent and received identification information as a context.
[0164] [3.1. Description of the process used in each embodiment]
[0165] Next, the procedures used in each embodiment are described. It should be noted that the procedures used in each embodiment include a registration procedure, a network slice-specific authentication and authorization procedure, a generic UE configuration update procedure, and a network-initiated de-registration procedure. Each procedure is described below.
[0166] It should be noted that, in each embodiment, Figure 2As described in
[15] , the following description takes as an example the case where the HSS and UDM, the PCF and PCRF, the SMF and PGW-C, and the UPF and PGW-U are configured as the same device (that is, the same physical hardware, the same logical hardware, or the same software). However, the contents described in this embodiment can also be applied to the case where they are configured as different devices (that is, different physical hardware, different logical hardware, or different software). For example, data can be sent and received directly between them, data can be sent and received via the N26 interface between the AMF and MME, or data can be sent and received via the UE.
[0167] [3.2. Login process]
[0168] First, use Figure 6 The registration procedure is described. Hereinafter, this process refers to the registration procedure. The registration procedure is a process led by the UE to log in to the access network_B and / or core network_B and / or DN. If it is in a state of not logging in to the network, the UE can perform this process at any timing, such as when the power is turned on. In other words, if it is in a non-logged-in state (5GMM-DEREGISTERED state), the UE can start this process at any timing. In addition, each device (especially the UE and AMF) can transition to a registered state (5GMM-REGISTEDEDstate) based on the completion of the registration process. It should be noted that each registration state can be managed in each device for each access. Specifically, each device can independently manage the registration state for 3GPP access (logged-in state or non-logged-in state) and the registration state for non-3GPP access.
[0169] Also, the registration procedure may be a procedure for updating location registration information of the UE in the network and / or periodically notifying the network of the UE's status and / or updating specific parameters related to the UE in the network.
[0170] The UE can start the registration procedure when moving across TAs. In other words, the UE can start the registration procedure when moving to a TA different from the TA indicated by the maintained TA list. Also, the UE can start the procedure when a timer being executed expires. Also, the UE can start the registration procedure when the context of each device needs to be updated because the PDU session is disconnected, disabled. Also, the UE can start the registration procedure when capability information and / or preferences related to PDU session establishment of the UE change. Also, the UE can start the registration procedure periodically. Also, the UE can start the registration procedure based on completion of the update procedure set by the UE or based on completion of the registration procedure or based on completion of the PDU session establishment procedure or based on completion of the PDU session management procedure or based on information received from the network in each procedure. Note that the UE can execute the registration procedure at any timing, and is not limited thereto.
[0171] Note that the procedure for changing the state of the UE from the state of not being registered to the state of being registered to the network described above can be set as an initial registration procedure or a registration procedure for initial registration, and the registration procedure executed in the state of the UE being registered to the network can be set as a registration procedure for mobility and periodic registration update or a mobility and periodic registration procedure.
[0172] Figure 6 The new AMF refers to an AMF that registers the UE by the present procedure, and the old AMF refers to an AMF that registers the UE by a procedure prior to the present procedure. In the present procedure, in the case where no change of the AMF occurs, no interface between the old AMF and the new AMF and no procedure between the old AMF and the new AMF are generated, and the new AMF can be the same device as the old AMF. In the present embodiment, in the case where the AMF is described, it can refer to the new AMF, or it can refer to the old AMF, and in addition, it can refer to both.
[0173] First, the UE starts the registration process by sending a registration request message (S600)(S602)(S604) to the new AMF. Specifically, the UE sends an RRC message including the registration request message to the 5G AN (or gNB) (S600). It should be noted that the registration request message is a NAS message sent and received on the N1 interface. In addition, the RRC message can be a control message sent and received between the UE and the 5G AN (or gNB). In addition, NAS messages are processed in the NAS layer, and RRC messages are processed in the RRC layer. It should be noted that the NAS layer is a higher layer than the RRC layer.
[0174] Here, the UE can include at least one or more of the first to third identification information in the login request message and / or RRC message and send it. Moreover, the UE can include identification information indicating the type of this process in the login request message and / or RRC message and send it. Here, the identification information indicating the type of this process can be a 5GS registration type IE (5GS registration type IE), or it can be information indicating that this process is used for initial login or for login information update accompanying movement or for regular login information update or for login in emergency.
[0175] The UE can include these identification information in control messages different from these, for example, control messages of layers lower than the RRC layer (for example, the MAC layer, the RLC layer, the PDCP layer) and send them. It should be noted that the UE can send these identification information to indicate that the UE supports each function, or to indicate the UE's request, or to indicate both. Moreover, in the case of sending and receiving multiple identification information, two or more identification information of these identification information can constitute one or more identification information. It should be noted that the information indicating support for each function and the information indicating a request for the use of each function can be sent and received as the same identification information, or can be sent and received as different identification information.
[0176] It should be noted that the UE can select and determine whether to send the first to third identification information to the network based on the UE's capability information and / or UE policy and / or UE status and / or user login information and / or context maintained by the UE.
[0177] The UE may send the first identification information when it has a network slice specific authentication and authorization function or when it requests at least one S-NSSAI identifying a slice requiring network slice specific authentication and authorization. The UE may request that the network treat the UE as a UE with a network slice specific authentication and authorization function and request that an authentication and authorization process based on the network slice specific authentication and authorization function be performed in a process related to the UE by sending the first identification information.
[0178] The UE may transmit the second identification information when storing the allowed NSSAI for the requested access of the requested PLMN and / or when maintaining the configured NSSAI. The UE may select one or more S-NSSAI1s from the stored allowed NSSAIs and / or configured NSSAIs, include them in the second identification information, and transmit the information. Furthermore, when storing the rejected NSSAI, the UE may exclude the S-NSSAI included in the rejected NSSAI from the second identification information and transmit the information.
[0179] In the case where the S-NSSAI requested by the UE is information identifying a slice requiring network slice specific authentication and authorization and / or the UE stores identification information (e.g., EAP (Extensible Authentication Protocol) ID) used in establishing a correspondence between the S-NSSAI requested by the UE, the UE may send the third identification information. The UE may request to start the network slice specific authentication and authorization process, or may request the network for the result of the network slice specific authentication and authorization by sending the third identification information.
[0180] The UE may include identification information other than the first to third identification information in a login request message and / or an RRC message including a login request message, for example, including UE ID and / or PLMN ID and / or AMF identification information and send it. Here, the AMF identification information may be information for identifying the AMF or a set of AMFs, for example, 5G-S-TMSI (5G S-Temporary Mobile Subscription Identifier: 5G S-Temporary Mobile User Identity), GUAMI (Globally Unique AMF Identifier: Globally Unique AMF Identifier).
[0181] In addition, the UE can start the PDU session establishment process during the login process by including an SM message (e.g., a PDU session establishment request message) in the login request message and sending it, or by sending an SM message (e.g., a PDU session establishment request message) together with the login request message.
[0182] Upon receiving an RRC message including a Login Request message, the 5G AN (or gNB) selects an AMF to which to transmit the Login Request message (S602). It should be noted that the 5G AN (or gNB) can select an AMF based on one or more identification information included in the Login Request message and / or the RRC message including the Login Request message. Specifically, the 5G AN (or gNB) can select a new AMF as the destination for the Login Request message based on at least one of the first to third identification information.
[0183] For example, the 5G AN (or gNB) may select an AMF with network slice specific authentication and authorization capabilities and / or an AMF with connectivity to a network with network slice specific authentication and authorization capabilities based on the first identification information.
[0184] Furthermore, the 5G AN (or gNB) may select an AMF based on the second identification information. Specifically, the 5G AN (or gNB) may select an AMF included in the network slice identified by the S-NSSAI included in the second identification information or having connectivity to the network slice.
[0185] It should be noted that the AMF selection method is not limited to this. The 5G AN (or gNB) may also select an AMF based on conditions other than these. The 5G AN (or gNB) extracts the Login Request message from the received RRC message and transmits the Login Request message to the selected new AMF (S604). It should be noted that if at least one of the first to third identification information is not included in the Login Request message but is included in the RRC message, the identification information included in the RRC message may be transmitted to the selected AMF together with the Login Request message (S604).
[0186] Upon receiving the Login Request message, the new AMF can perform a first conditional check. The first conditional check is used to determine whether the network (or the new AMF) accepts the UE's request. If the first conditional check is true, the new AMF begins the process from S606 onwards and executes process (A). On the other hand, if the first conditional check is false, the new AMF may skip processes S606 to S612 and execute process (B) instead.
[0187] Alternatively, the new AMF may perform the first condition determination after receiving the UE context from the old AMF (S608). In this case, if the first condition determination is true, the new AMF executes procedure (A). On the other hand, if the first condition determination is false, the new AMF may not execute procedure (A) but execute procedure (B).
[0188] It should be noted that the first condition judgment can be performed based on the receipt of the login request message and / or the identification information and / or subscriber information and / or network capability information and / or operator policy and / or network status and / or user login information and / or context maintained by the AMF included in the login request message.
[0189] For example, the first condition may be true if the network permits the UE's request, and false if the network does not permit the UE's request. Alternatively, the first condition may be true if the UE's login destination network and / or devices within the network support the function requested by the UE, and false if they do not. Furthermore, the first condition may be true if the identification information being sent and received is permitted, and false if the identification information being sent and received is not permitted.
[0190] In addition, the first condition may be judged to be true when the S-NSSAI included in the requested NSSAI received by the AMF from the UE is information identifying a slice requiring a slice specific authentication and authorization process, and further when the result of the slice specific authentication and authorization process stored by the AMF as the S-NSSAI corresponding to the UE is successful. Alternatively, the first condition may be judged to be false when there is no S-NSSAI allowed for the UE and there is no reservation to allocate an allowed NSSAI to the UE in the future.
[0191] First, the case where the first condition is true is described. If the new AMF is different from the AMF indicated by the AMF identification information included in the message received from the UE, the new AMF executes procedures S606 and S608. If the new AMF is the same as the AMF indicated by the AMF identification information included in the message received from the UE, procedures S606 and S608 are not executed. In other words, if a change of AMF occurs through this procedure, procedures S606 and S608 are executed. If no change of AMF occurs, procedures S606 and S608 are skipped.
[0192] The UE context transmission process (S606, S608) is described. The new AMF identifies the AMF indicated by the AMF identification information as the old AMF and sends a UE context request message to the old AMF (S606). Based on the received UE context request message, the old AMF sends the UE context to the new AMF. Based on the received UE context, the new AMF generates a UE context.
[0193] Here, the UE context sent from the new AMF to the old AMF may include the UE ID and the allowed NSSAI. In addition, the UE context may include the configured NSSAI and / or rejected NSSAI. In addition, the allowed NSSAI and / or configured AMF (configured AMF) and / or rejected NSSAI included in the UE context may be associated with information on whether the notification to the UE is complete.
[0194] In addition, the UE context may include information of the S-NSSAI requiring a network slice specific authentication and authorization process, information indicating successful authentication of the UE to complete the network slice specific authentication and authorization process, and / or information indicating authentication failure.
[0195] Next, the process (A) of this process is described. In the case where the new AMF determines to accept the UE's registration request, based on the determination and / or based on receiving the UE context from the old AMF, the new AMF sends a Registration Accept message to the UE (S610).
[0196] The new AMF may include at least one or more identification information from the eleventh to sixteenth identification information in the login acceptance message and send it. It should be noted that the AMF can indicate that the network supports each function by sending these identification information and / or login acceptance messages, or indicate that the UE's request is accepted, or indicate that part of the request from the UE is not allowed, or indicate a combination of these information. Moreover, in the case of sending and receiving multiple identification information, two or more identification information of these identification information may constitute one or more identification information. It should be noted that the information indicating support for each function and the information indicating a request for use of each function may be sent and received as the same identification information, or may be sent and received as different identification information.
[0197] The AMF may send at least one of the eleventh to sixteenth identification information when at least any one of the first to third identification information is received from the UE and / or when the UE's setting information is updated since the previous login process.
[0198] The AMF may send the eleventh identification information if the first identification information is received from the UE and / or if the network slice specific authentication and authorization process is started and / or if the network supports network slice specific authentication and authorization.
[0199] The AMF may not allow the UE's S-NSSAI (allowed NSSAI) when sending the login acceptance message, but after this process is completed or there is a reservation to perform a network slice specific authentication and authorization process in parallel with this process, an empty value will be included in the twelfth identification information and sent.
[0200] Based on the reception of the eleventh identification information, the UE can identify that the network has network slice specific authentication and authorization functions, and can store the UE login as a UE with network slice specific authentication and authorization functions.
[0201] The UE may identify the slices allowed by the network based on the reception of the twelfth identification information, and may store the S-NSSAI included in the twelfth identification information as the allowed NSSAI. Then, the UE may store the allowed NSSAI until the twelfth identification information is received. The UE may store the allowed NSSAI until it moves out of the login area. If the allowed NSSAI has already been stored, the UE may update the stored information to the allowed NSSAI indicated by the twelfth identification information. Moreover, if the rejected S-NSSAI stored by the UE is included in the new allowed NSSAI, the UE may delete the S-NSSAI from the rejected NSSAI.
[0202] Furthermore, upon receiving the empty twelfth identification information, the UE may transition to a state where login is permitted but establishment of a PDU session is not permitted. Specifically, upon receiving the empty twelfth identification information, the UE may store the received login area as a non-permitted area, or may transition to a state where mobility restriction is executed.
[0203] The UE can identify and store the slices rejected by the network and the reasons for rejection based on the reception of the thirteenth identification information.
[0204] For example, upon receiving the thirteenth identification information, the UE may appropriately store the S-NSSAI included in the thirteenth identification information in the rejected NSSAI based on the reason value associated with the S-NSSAI included in the thirteenth identification information. Furthermore, if the S-NSSAI included in the stored rejected NSSAI is included in the allowed NSSAI, the UE may delete the S-NSSAI from the allowed NSSAI.
[0205] Furthermore, for example, if the thirteenth identification information includes a first rejected NSSAI, in other words, if the thirteenth identification information includes at least one set of S-NSSAI and a rejection reason value indicating that the PLMN cannot be used, the UE may include the S-NSSAI in the first rejected NSSAI based on the rejection reason value and store the S-NSSAI. Furthermore, if the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE may delete the rejected NSSAI from the allowed NSSAI.
[0206] Moreover, for example, in the case where the second rejected NSSAI is included in the thirteenth identification information, in other words, in the case where the thirteenth identification information contains at least one set of S-NSSAI and a rejection reason value indicating that it is not available within the current login area, the UE can include the S-NSSAI in the second rejected NSSAI based on the rejection reason value and store it.
[0207] Moreover, for example, in the case where the third rejected NSSAI is included in the thirteenth identification information, in other words, in the case where the thirteenth identification information comprises at least one set of S-NSSAI and a rejection reason value representing the S-NSSAI pending for network slice specific authentication and authorization, the UE may include the S-NSSAI in the third rejected NSSAI based on the rejection reason value and store it.
[0208] Moreover, for example, in the case where the fourth rejected NSSAI is included in the thirteenth identification information, in other words, in the case where the thirteenth identification information constitutes at least one set of S-NSSAI and a rejection reason value of S-NSSAI indicating network slice specific authentication and authorization failure, the UE can delete the S-NSSAI from the third rejected NSSAI based on the rejection reason value, and can include the S-NSSAI in the fourth rejected NSSAI and store it.
[0209] Moreover, when the UE receives the thirteenth identification information including at least one S-NSSAI, if the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE can delete the rejected NSSAI from the allowed NSSAI.
[0210] The UE may also store the S-NSSAI associated with other reason values in the same manner. It should be noted that the storage method of the NSSAI based on the UE's rejection is not limited to this, as long as the S-NSSAI is stored in a state where it is associated with the reason value.
[0211] The UE can start counting of the timer or the timer based on reception of the thirteenth identification information including the third rejected NSSAI and / or the rejection reason value included in the thirteenth identification information and / or the fourteenth identification information. Here, the value of the timer can be a value pre-stored by the UE or a value of the timer indicated by the fourteenth identification information.
[0212] The UE stops the timer in a case where the counting of the timer, a case where the UE receives a set-up update command or a log-in accept message including an allowed NSSAI and / or a rejected NSSAI indicating a notification of a result of network slice specific authentication and authorization for a rejected NSSAI by the network pending or a case where the UE receives the result in the network slice specific authentication and authorization.
[0213] In a case where the counting of the timer expires, that is, in a case where the UE does not receive a set-up update command or a log-in accept message including an allowed NSSAI and / or a rejected NSSAI indicating a notification of a result of network slice specific authentication and authorization for a rejected NSSAI by the network pending or a case where the UE does not receive the result in the network slice specific authentication and authorization in the counting of the timer, the UE can delete the third rejected NSSAI or can also delete the corresponding rejected S-NSSAI from the third rejected NSSAI.
[0214] The UE can identify that the change of the AMF has occurred based on reception of the fifteenth identification information. The UE can delete the third rejected NSSAI based on reception of the sixteenth identification information in a case where the UE has stored the third rejected NSSAI before receiving the log-in accept message.
[0215] In a case where the fifteenth identification information is information indicating a log-in area, the UE can delete the third rejected NSSAI as the log-in area is changed.
[0216] The UE can delete the third rejected NSSAI based on reception of the sixteenth identification information. Specifically, in a case where the sixteenth identification information is information indicating deletion of the third rejected NSSAI, the UE can delete the third rejected NSSAI.
[0217] Note that each process performed by the UE based on reception of each identification information as described above can be performed in or after the process is completed, or can be performed based on completion of the process after the process is completed.
[0218] Note that the AMF can select, determine which one of the eleventh to sixteenth identification information is included in the login acceptance message, based on the received respective identification information and / or subscriber information and / or network capability information and / or operator policy and / or network status and / or user's login information and / or context held by the AMF, and the like.
[0219] Further, the AMF can include and transmit the SM message (e.g., PDU session establishment acceptance message) in the login acceptance message or transmit the SM message (e.g., PDU session establishment acceptance message) together with the login acceptance message. However, this transmission method can be performed in a case where the SM message (e.g., PDU session establishment request message) is included in the login request message. Further, this transmission method can also be performed in a case where the SM message (e.g., PDU session establishment request message) is included together with the login request message. The AMF can indicate that the procedure for the SM is accepted in the login procedure by performing such a transmission method.
[0220] Further, the AMF can indicate that the UE's request is accepted by transmitting the login acceptance message based on the received respective identification information and / or subscriber information and / or network capability information and / or operator policy and / or network status and / or user's login information and / or context held by the AMF, and the like.
[0221] The UE receives the login acceptance message via the 5G AN (gNB) (S608). The UE can recognize that the UE's request based on the login request message is accepted and the content of the respective identification information included in the login acceptance message by receiving the login acceptance message.
[0222] Further, the UE can transmit the login completion message to the AMF via the 5G AN (gNB) as a response message to the login acceptance message (S610). Note that the UE can include and transmit the SM message (e.g., PDU session establishment completion message) in the login completion message in a case where the SM message (e.g., PDU session establishment acceptance message) is received, and can indicate the completion of the procedure for the SM by including the SM message. Here, the login completion message is a NAS message transmitted / received on the N1 interface, but is included in and transmitted / received in the RRC message between the UE and the 5G AN (gNB).
[0223] The AMF receives the login completion message via the 5G AN (gNB) (S612). Further, the respective devices complete the procedure of (A) in the present procedure and the login procedure based on the transmission / reception of the login acceptance message and / or the login completion message.
[0224] Next, the case where the first condition is determined to be false is described. The AMF sends a Registration Reject message to the UE via the 5G AN (gNB) as a response message to the Registration Request message (S614). Here, the Registration Reject message is a NAS message sent and received over the N1 interface, but is included in the RRC message and sent and received between the UE and the 5G AN (gNB).
[0225] The new AMF may include at least one of the thirty-first to thirty-second identification information in the login rejection message and send it. The new AMF may also include a reason value in the login rejection message and send it. Here, the reason value may be a 5GMM cause. It should be noted that the AMF may indicate that the network does not support various functions by sending these identification information and / or login rejection messages, or may indicate that the UE's request is rejected or not accepted, or may indicate the reason why the request from the UE is not allowed, or may indicate a combination of these information. Moreover, in the case of sending and receiving multiple identification information, two or more identification information of these identification information may constitute one or more identification information. It should be noted that the information indicating support for various functions and the information indicating request for use of various functions may be sent and received as the same identification information, or may be sent and received as different identification information.
[0226] The AMF may send at least one of the thirty-first to thirty-second identification information when at least any one of the first to third identification information is received from the UE and / or when the UE's setting information is updated since the previous login process.
[0227] The AMF may send the thirty-second identification information and the login rejection message if the UE's S-NSSAI is not allowed and there is no reservation to add the S-NSSAI to the allowed NSSAI through other procedures (such as network slice specific authentication and authorization procedures) in the future.
[0228] The UE may appropriately identify and store the rejected S-NSSAI and the reason for rejection based on the reception of the thirty-first identification information and / or the type of this procedure (registration type) and / or the status of the UE.
[0229] First, the case where this procedure is a login procedure for initial login will be described. Specifically, the case where the UE includes information indicating that this procedure is a login procedure for initial login in the login request message will be described.
[0230] For example, when the UE receives the thirty-first identification information included in the login rejection message during the login process for the initial login, it may include the S-NSSAI in the appropriate rejected NSSAI and store it based on the rejection reason value corresponding to the S-NSSAI included in the thirty-first identification information and / or the status of the UE, or it may ignore the S-NSSAI.
[0231] Specifically, if the first rejected NSSAI is included in the 31st identification information, in other words, if the 31st identification information includes at least one set of S-NSSAI and a rejection reason value indicating that the UE cannot be used in the current PLMN, and further, if the UE is logged into an access different from the access requested by the UE for the current PLMN, the UE may include the S-NSSAI in the first rejected NSSAI based on the rejection reason value and store the S-NSSAI. Furthermore, if the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE may delete the rejected NSSAI from the allowed NSSAI.
[0232] In addition, in the case where the thirty-first identification information includes the first rejected NSSAI, in other words, in the case where the thirty-first identification information consists of at least one set of S-NSSAI and a rejection reason value indicating that it cannot be used in the current PLMN, and further in the case where the UE is in a state of not logging into an access different from the access requested by the UE, the UE may ignore the S-NSSAI.
[0233] Moreover, for example, in the case where the second rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating that it is not usable within the current login area, the UE can ignore the S-NSSAI.
[0234] In addition, when the third rejected NSSAI is included in the thirty-first identification information, in other words, when the thirty-first identification information includes at least one set of S-NSSAI and a rejection reason value indicating the S-NSSAI pending for network slice specific authentication and authorization, and thus when the UE is in a state of logging into an access different from the access requested by the UE, the UE may include the S-NSSAI in the third rejected NSSAI based on the rejection reason value and store it. Furthermore, when the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE may delete the rejected NSSAI from the allowed NSSAI.
[0235] In addition, in the case where the third rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating the S-NSSAI pending for network slice specific authentication and authorization, and thus in the case where the UE is in a state of not logging into an access different from the access requested by the UE, the UE may ignore the S-NSSAI.
[0236] In addition, in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value of S-NSSAI indicating failure of network slice specific authentication and authorization, and then in the case where the UE is in a state of logging into an access different from the access requested by the UE, the UE can include the S-NSSAI in the fourth rejected NSSAI based on the rejection reason value and store it, and, in the case where the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE can delete the rejected NSSAI from the allowed NSSAI.
[0237] Or in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value of S-NSSAI indicating failure of network slice specific authentication and authorization, and then in the case where the UE is in a state of logging into an access different from the access requested by the UE, the UE can delete the S-NSSAI from the third rejected NSSAI based on the rejection reason value.
[0238] In addition, in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating the S-NSSAI pending for network slice specific authentication and authorization, and thus in the case where the UE is in a state of not logging into an access different from the access requested by the UE, the UE may ignore the S-NSSAI.
[0239] Next, the case where this process is a registration process for mobile and periodic registration updates will be described.
[0240] For example, when the UE receives the 31st identification information during a registration procedure for mobility and periodic registration updates, the UE may store the S-NSSAI included in the 31st identification information in an appropriate rejected NSSAI based on a reason value associated with the S-NSSAI included in the 31st identification information. Furthermore, if the S-NSSAI included in the stored rejected NSSAI is included in the allowed NSSAI, the S-NSSAI may be deleted from the allowed NSSAI.
[0241] Furthermore, for example, if the first rejected NSSAI is included in the 31st identification information, in other words, if the 31st identification information includes at least one set of S-NSSAI and a rejection reason value indicating that the PLMN cannot be used, the UE may include the S-NSSAI in the first rejected NSSAI based on the rejection reason value and store the S-NSSAI. Furthermore, if the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE may delete the rejected NSSAI from the allowed NSSAI.
[0242] Moreover, for example, in the case where the second rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating that it is not usable within the current login area, the UE can include the S-NSSAI in the second rejected NSSAI based on the rejection reason value and store it.
[0243] Moreover, for example, in the case where the third rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information consists of at least one set of S-NSSAI and a rejection reason value representing the S-NSSAI pending for network slice specific authentication and authorization, the UE can include the S-NSSAI in the third rejected NSSAI based on the rejection reason value and store it.
[0244] Moreover, for example, in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information constitutes at least one set of S-NSSAI and a rejection reason value of S-NSSAI indicating failure of network slice specific authentication and authorization, the UE can delete the S-NSSAI from the third rejected NSSAI based on the rejection reason value, and can also include the S-NSSAI in the fourth rejected NSSAI and store it.
[0245] Moreover, when the UE receives the thirty-first identification information including at least one S-NSSAI, when the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE can delete the rejected NSSAI from the allowed NSSAI.
[0246] That is, when the UE receives a login rejection message including the thirty-first identification information from the core network during the initial login process, and when the thirty-first identification information includes the S-NSSAI and a rejection reason value indicating that it is not available in the current login area, the UE can ignore the S-NSSAI.
[0247] Moreover, when the UE receives a login rejection message including the thirty-first identification information from the core network during the login process for the initial login for a certain access, and when the UE is in a non-logged-in state for the access of the other party, and when the thirty-first identification information includes an S-NSSAI and a rejection reason value indicating that the S-NSSAI for establishing the association is not available in the current PLMN and / or indicates that the S-NSSAI is pending for network slice specific authentication and authorization and / or indicates that the network slice specific authentication and authorization has failed, the UE may ignore the S-NSSAI.
[0248] Moreover, during the login process for initial login, in other cases, the UE may append to the corresponding rejected NSSAI based on the rejection reason and store it. If it exists, the S-NSSAI included in the rejected NSSAI stored by the UE may be deleted from the allowed NSSAI stored by the UE.
[0249] In addition, when the UE receives the thirty-first identification information during the login process for mobility and periodic login updates, regardless of the rejection reason value corresponding to the S-NSSAI included in the thirty-first identification information and the status of the UE, the UE can add the S-NSSAI included in the thirty-first identification information to the appropriate rejected NSSAI based on the rejection reason for establishing the association and store it. If it exists, the S-NSSAI included in the rejected NSSAI stored by the UE can be deleted from the allowed NSSAI stored by the UE.
[0250] When the UE receives the thirty-second identification information, the UE may delete the allowed NSSAI for the access (3GPP access or non-3GPP access) requested by the UE.
[0251] The UE may also store the S-NSSAI associated with other reason values in the same manner. It should be noted that the storage method of the NSSAI based on the UE's rejection is not limited to this, as long as the S-NSSAI is stored in a state where it is associated with the reason value.
[0252] It should be noted that the various processes performed by the UE based on the reception of various identification information as described above can be performed during this process or after the completion of this process, or can be performed after the completion of this process based on the completion of this process.
[0253] It should be noted that the AMF can select and determine whether to include at least one of the thirty-first to thirty-second identification information in the login rejection message based on the received identification information and / or subscriber information and / or network capability information and / or operator policy and / or network status and / or user login information and / or context maintained by the AMF.
[0254] Specifically, AMF may not send a login rejection message having the thirty-first identification information including a rejection reason value indicating that the login is not available in the current login area during the login process for the initial login, or may control it in that way.
[0255] Moreover, the AMF may control in the same way as above by sending a login rejection message having the thirty-first identification information including a rejection reason value indicating that the UE is not available in the current PLMN and / or a rejection reason value indicating that the S-NSSAI is pending for network slice specific authentication and authorization and / or a rejection reason value indicating that the network slice specific authentication and authorization has failed, without sending the login rejection message via a certain access when the UE is not logged in through the access of another party during the login process for the initial login of a certain access.
[0256] The UE receives a Login Reject message via the 5G AN (gNB). By receiving the Login Reject message, the UE can identify that its request based on the Login Request message was rejected and the various identification information included in the Login Reject message. Furthermore, the UE can also identify that its request was rejected if it does not receive a Login Accept message or a Login Reject message within a specified period after sending the Login Request message. Each device can complete the login process based on the transmission and reception of the Login Reject message.
[0257] It should be noted that each device can transition to or maintain a state in which the UE is logged into the network (RM_REGISTERED state or 5GMM-REGISTERED state) based on the transmission and reception of a login acceptance message and / or a login completion message, and can also transition to or maintain a state in which the UE is not logged into the network (RM_DEREGISTERED state or 5GMM-DEREGISTERED state) based on the transmission and reception of a login rejection message. In addition, the transition of each device to each state can be based on the completion of the login process.
[0258] Furthermore, upon completion of the login process, each device may perform processing based on the information sent and received during the login process. For example, when information indicating that a portion of the UE's request was rejected is sent or received, the reason for the UE's request rejection can be identified. Furthermore, each device may re-implement this process based on the reason for the UE's request rejection, or may perform the login process for Core Network_A or other cells.
[0259] Furthermore, the UE may store the identification information received together with the registration accept message and / or the registration reject message upon completion of the registration procedure, and may also identify the determination of the network.
[0260] Furthermore, each device may initiate a network slice specific authentication and authorization process and a UE setting update process based on the completion of the login process. It should be noted that the details of the network slice specific authentication and authorization process and the UE setting update process are described later.
[0261] [3.3. Network Slice Specific Authentication and Authorization Process]
[0262] Next, use Figure 7 The network slice specific authentication and authorization process is described. Hereinafter, the network slice specific authentication and authorization process is also referred to as this process. This process can be a process for the core network to enable the UE to perform authentication and authorization processes for slices that require network slice specific authentication and authorization processes.
[0263] This procedure may be initiated by the AMF. For example, the AMF may initiate this procedure based on receipt of a Login Request message from the UE. The AMF may initiate this procedure without storing the results of the network slice specific authentication and authorization for the at least one S-NSSAI requested by the UE.
[0264] Alternatively, the AMF may initiate this procedure based on a request from the AAA-S. For example, if, as a result of executing network slice specific authentication and authorization for an S-NSSAI that has already been executed at least once, the AMF is managing the S-NSSAI as an allowed NSSAI, and the AAA-S requests execution of network slice specific authentication and authorization for the S-NSSAI again, the AMF may initiate this procedure based on a request from the AAA-S. In this case, this procedure may be a network slice specific authentication and authorization procedure initiated by the AAA-S.
[0265] This process is described below. The AMF sends an EAP ID Request message to the UE via the 5G AN (or gNB or non-3GPP access) (S700). The EAP ID Request message may be included in an Authentication Request message (Authentication Request message) as a NAS message and sent. The AMF may include one or more S-NSSAIs corresponding to the requested EAP ID in the EAP ID Request message or the Authentication Request message including the EAP ID Request message and send it.
[0266] Based on the sending of the EAP ID request message, the AMF requests one or more EAP IDs for one or more S-NSSAIs from the UE as the identification information of the UE for performing network slice specific authentication and authorization.
[0267] Based on the reception of the EAP ID request message and / or the reception of the S-NSSAI, the UE sends an EAP ID response message (S702). The EAP ID response message may be included in an authentication response message (Authentication response message) as a NAS message and sent. The UE includes the S-NSSAI received from the AMF in the EAP ID response message or the authentication request message including the EAP ID response message and sends it. The UE includes the EAP ID as the identification information of the UE corresponding to the S-NSSAI received from the AMF in the EAP ID response message and sends it. It should be noted that the UE may include multiple EAP IDs and multiple S-NSSAIs in the EAP ID response message, or may associate each EAP ID with each S-NSSAI and send it.
[0268] The AMF sends an authentication request message to the AAA-S via the AUSF based on the reception of the EAP ID response message from the UE and / or the EAP ID (S704, S706). The AMF can include the EAP ID response message received from the UE in the authentication request message and send to the AUSF and / or the AAA-S, or include the EAP ID and / or the S-NSSAI included in the EAP ID response message received from the UE in the authentication request message and send to the AUSF and / or the AAA-S.
[0269] Note that the authentication request message sent from the AMF to the AUSF and the authentication request message sent from the AUSF to the AAA-S can be the same message or different messages. Specifically, the AUSF can transfer the authentication request message received from the AMF to the AAA-S, or include the EAP ID and / or the S-NSSAI included in the authentication request message received from the AMF in the authentication request message and send to the AAA-S.
[0270] The AAA-S can start a procedure of an exchange of messages required for authentication between the UE and the AAA-S based on the reception of the authentication request message (S708). Note that the messages for the exchange procedure of messages between the AAA-S and the UE can be EAP messages.
[0271] The AAA-S performs an authentication procedure based on the reception of the authentication request message received from the AMF via the AUSF. The AAA-S sends an authentication response message to the AMF via the AUSF as a response to the authentication request message received from the AMF (S710, S712). The AUSF includes the authentication result and the S-NSSAI in the authentication response message and sends. Here, the authentication result can be information indicating success or failure.
[0272] The AMF sends an authentication result message to the UE based on the reception of the authentication response message (S714). The AMF can include the authentication result and the S-NSSAI included in the authentication response message in the authentication response message or send.
[0273] Each device can complete this process based on the sending and receiving of the authentication result message. Each device can update the stored information based on the completion of this process and the information sent and received in this process. Specifically, the AMF can store the authentication result of each S-NSSAI based on the sending and receiving of the authentication result. For example, when sending and receiving "success" as the authentication result, the AMF can establish an association with the S-NSSAI sent and received together with the authentication result, and store it as the UE's information as the status of "success" of the network slice specific authentication and authorization. Similarly, when sending and receiving "failure" as the authentication result, the AMF can establish an association with the S-NSSAI sent and received together with the authentication result, and store it as the UE's information as the status of "failure" of the network slice specific authentication and authorization.
[0274] In addition, when this process is initiated based on the receipt of a login request message from the UE, the AMF may update the allowed NSSAI and / or rejected NSSAI for the UE based on the sending and receiving of the authentication result. Specifically, for example, when sending and receiving "success" as the authentication result, the AMF may store the S-NSSAI sent and received along with the authentication result as the allowed NSSAI, or may associate "allowed" with the S-NSSAI and store them. Similarly, when sending and receiving "failure" as the authentication result, the AMF may store the S-NSSAI sent and received along with the authentication result as the rejected NSSAI, or associate "rejected" with the S-NSSAI and store them. Moreover, when the AMF sends and receives "failure" as the authentication result, and further when the UE includes the S-NSSAI sent and received along with the authentication result in the third rejected NSSAI and stores it, the UE may delete the S-NSSAI from the third rejected NSSAI.
[0275] In addition, the UE may store the authentication result of each S-NSSAI based on the authentication result sent and received. Specifically, for example, when the UE sends and receives "success" as the authentication result, the UE may establish an association with the S-NSSAI sent and received along with the authentication result, and store it as the UE's information as the "success" status of the network slice specific authentication and authorization. Similarly, when the UE sends and receives "failure" as the authentication result, the UE may establish an association with the S-NSSAI sent and received along with the authentication result, and store it as the UE's information as the "failure" status of the network slice specific authentication and authorization.
[0276] In addition, each device may implement an update process based on stored information based on the completion of this procedure. For example, the AFM may initiate a UE configuration update procedure based on the completion of this procedure if the S-NSSAI included in the allowed NSSAI and / or rejected NSSAI for the UE has changed. The AMF may use the UE configuration update procedure to notify the UE of the new allowed NSSAI and the new rejected NSSAI.
[0277] [3.4.UE Setting Update Procedure]
[0278] Next, use Figure 8 The Generic UE Configuration Update Procedure is described. Hereinafter, the UE Configuration Update Procedure is also referred to as this procedure. This procedure is used by the core network to update UE configuration information. This procedure can also be used to perform network-led mobility management for UEs logged into the network.
[0279] Moreover, the devices in the core network such as AMF can start this process based on the update of the network settings and / or the update of the operator's policy. It should be noted that the trigger of this process can be the detection of the UE's mobility, the detection of the status change of the UE and / or the access network and / or the core network, or the status change of the network slice. Moreover, the trigger of this process can be the reception of a request from the DN and / or the application server of the DN, the change of the network settings, or the change of the operator's policy. Moreover, the trigger of this process can also be the expiration of the executing timer. It should be noted that the triggers for the devices in the core network to start this process are not limited to these. In other words, this process can be executed at any timing after the above-mentioned login process and / or PDU session establishment process are completed. Moreover, if each device is in a state where a 5GMM context has been established and / or each device is in a state as a 5GMM connection mode, this process can be executed at any timing.
[0280] Furthermore, during this process, each device may send and receive messages including identification information for changing UE configuration information and / or identification information for stopping or changing functions performed by the UE. Furthermore, upon completion of this process, each device may update configuration information for the network-directed configuration or initiate actions directed by the network.
[0281] The UE can update the setting information of the UE based on the control information transmitted / received through the present procedure. Also, the UE can stop a function in execution and can start a new function along with the update of the setting information of the UE. In other words, the apparatus in the core network can use the control information by leading the present procedure and transmitting the control message and the control information of the present procedure to the UE to cause the UE to update the setting information of the UE which can be identified. Also, the apparatus in the core network can cause the UE to stop a function in execution and can cause the UE to start a new function by updating the setting information of the UE.
[0282] First, the AMF starts a UE setting update procedure by transmitting a configuration update command message (S800) to the UE via the 5G AN (or gNB).
[0283] The AMF can include and transmit one or more of the twenty-first to twenty-fifth identification information in the configuration update command message. Note that the AMF can indicate new setting information of the UE and can request an update of the setting information of the UE by transmitting one or more of the twenty-first to twenty-fifth identification information. Note that the information indicating support of each function and the information indicating a request for use of each function can be transmitted / received as the same identification information or can be transmitted / received as different identification information.
[0284] Also, in a case where a plurality of identification information is transmitted / received, two or more of the plurality of identification information can be configured as one or more identification information. Note that the information indicating support of each function and the information indicating a request for use of each function can be transmitted / received as the same identification information or can be transmitted / received as different identification information.
[0285] Note that the AMF can select / determine whether to include the twenty-first to twenty-fifth identification information in the configuration update command message based on each of the received identification information and / or subscriber information and / or capability information of the network and / or operator policy and / or state of the network and / or login information of the user and / or context maintained by the AMF, etc.
[0286] Further, the AMF can transmit the configuration update command message based on each of the received identification information and / or subscriber information and / or capability information of the network and / or operator policy and / or state of the network and / or login information of the user and / or context maintained by the AMF, etc., thereby indicating a request for an update of the setting information of the UE.
[0287] The UE receives a configuration update command message via a 5G AN (or gNB) (S800). The UE may update the UE's configuration information based on the configuration update command message and / or the identification information included in the configuration update command message.
[0288] The UE may update the allowed NSSAI stored in the UE by receiving the twenty-first identification information. Specifically, the UE may use the received twenty-first identification information as the new allowed NSSAI and replace the stored information.
[0289] The UE may update the rejected NSSAI stored by the UE by receiving the twenty-second identification information. Specifically, upon receiving the twenty-second identification information, the UE may append the rejected NSSAI included in the twenty-second identification information to the rejected NSSAI stored by the UE, or may update the rejected NSSAI stored by the UE to the rejected NSSAI included in the twenty-second identification information.
[0290] For example, if the twenty-second identification information includes at least the S-NSSAI and the reason value, and if the UE already manages a rejected NSSAI, the UE may not delete the stored rejected NSSAI, but may append the S-NSSAI included in the twenty-second identification information to the rejected NSSAI already stored by the UE and store the result. Alternatively, the UE may delete the stored rejected NSSAI and store the S-NSSAI included in the twenty-second identification information as the rejected NSSAI.
[0291] The UE may start a login process after completing this process based on the reception of the twenty-fifth identification information. The login process started by the UE may be the login process described in Chapter 3.
[0292] It should be noted that the various processes performed by the UE based on the reception of each identification information as described above may be performed during this procedure or after completion of this procedure, or may be performed based on completion of this procedure after completion of this procedure. Furthermore, the UE may send a Configuration Update Complete message to the AMF via the 5G AN (gNB) as a response message to the Configuration Update Command message based on the identification information included in the Configuration Update Command message (S802).
[0293] When the UE sends a setting update complete command message, the AMF receives the setting update complete message via the 5G AN (gNB) (S802). In addition, each device completes this process based on the transmission and reception of the setting update command message and / or the setting update complete message.
[0294] Furthermore, upon completion of this procedure, each device may perform processing based on the information received and sent during this procedure. For example, if update information regarding configuration information is received and sent, each device may update the configuration information. Furthermore, if information indicating the need to perform a login procedure is received and sent, the UE may initiate the login procedure upon completion of this procedure.
[0295] Furthermore, upon completion of this procedure, the UE may store the identification information received along with the configuration information command message, and may also identify the network's determination. Furthermore, upon completion of this procedure, the UE may perform various procedures based on the stored information.
[0296] In the above process, the device in the core network can instruct the UE to update the setting information that the UE has applied by sending and receiving the setting update command message, and can instruct the UE to stop or change the function being executed.
[0297] [3.5. Non-login process initiated by the network]
[0298] Next, use Figure 9 This section describes the network-initiated de-registration procedure. Hereinafter, this procedure refers to the network-initiated de-registration procedure. The network-initiated de-registration procedure is used by the network to manually deregister from access network A and / or core network A, access network B and / or core network B, and / or DN and / or PDN. This procedure can be used to perform network-initiated mobility management for a UE that is logged into the network.
[0299] If the UE is in a state where it is logged in to the network (RM-REGISTERED state or 5GMM-REGISTEDED state), the AMF can perform this procedure at any timing. For example, the AMF can start this procedure as the UE's login information is updated. In addition, specifically, the AMF can start this procedure when there is no allowed NSSAI in the UE's login information based on the completion of the network slice specific authentication and authorization process. In other words, the AMF can start this procedure when there is no allowed S-NSSAI for the UE and no reservation of S-NSSAI is added to the allowed NSSAI in the future through other procedures (such as network slice specific authentication and authorization procedures).
[0300] First, the AMF can start this process by sending a De-registration Request message to the UE (S900). Here, the De-registration Request message is a NAS message sent and received on the N1 interface, but is included in the RRC message and sent and received between the UE and the 5G AN (gNB).
[0301] The AMF may include at least one of the thirty-first and thirty-second identification information in the non-login request message and send it. The AMF may further include a reason value and / or information indicating the access type for deregistration in the non-login request message and send it. Here, the reason value may be a 5GMM cause. In addition, the information indicating the access type for deregistration may be the Accesstype information included in the De-registration type IE (non-login type IE) of the 5GS, or may be information indicating 3GPP access or non-3GPP access or both.
[0302] It should be noted that the AMF can send these identification information and / or non-login messages to indicate that the network does not support each function, request a transition to a non-login state, notify the AMF of changes, instruct to continue the login process, or indicate a combination of these information. Moreover, when sending and receiving multiple identification information, two or more identification information of these identification information can constitute one or more identification information. It should be noted that the information indicating support for each function and the information indicating a request for use of each function can be sent and received as the same identification information or as different identification information.
[0303] The UE may identify and store the rejected S-NSSAI and the reason for rejection based on reception of at least one of the thirty-first to thirty-second identification information and / or the state of the UE.
[0304] When receiving the thirty-first identification information included in the non-login request message, the UE may include the S-NSSAI in the appropriate rejected NSSAI and store it based on the reason value corresponding to the S-NSSAI included in the thirty-first identification information and / or the status of the UE, or may ignore the S-NSSAI.
[0305] Specifically, when the 31st identification information includes the first rejected NSSAI, in other words, when the 31st identification information includes at least one set of S-NSSAI and a rejection reason value indicating that the access cannot be used in the current PLMN, and further, when the non-registration request message includes information indicating 3GPP access or non-3GPP access as the access type indicating deregistration, and further, when the access to the other party is in a registered state, the UE may include the S-NSSAI in the first rejected NSSAI and store it. Furthermore, when the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE may delete the rejected NSSAI from the allowed NSSAI.
[0306] In addition, in the case where the thirty-first identification information includes the first rejected NSSAI, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating that it cannot be used in the current PLMN, and further in the case where the UE transitions to the non-login state for all accesses based on the reception of the non-login request message, the UE may ignore the S-NSSAI.
[0307] It should be noted that the situation where the UE transitions to a non-login state for all accesses based on the reception of a non-login request message may refer to a situation where the information indicating the access type for de-login in the non-login request message includes information indicating the access of both parties, or the information indicating the access type for de-login in the non-login request message includes information indicating 3GPP access or non-3GPP access, and the UE is in a non-login state for the access of the other party.
[0308] Moreover, for example, in the case where the second rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating that it is not usable within the current login area, the UE can ignore the S-NSSAI.
[0309] In addition, when the third rejected NSSAI is included in the 31st identification information, in other words, when the 31st identification information includes at least one set of S-NSSAI and a rejection reason value indicating the S-NSSAI pending for network slice specific authentication and authorization, and further, when the non-login request message includes information indicating 3GPP access or non-3GPP access as information indicating the access type for deregistration, and further, when the access to the other party is in a logged-in state, the UE may include the S-NSSAI in the third rejected NSSAI and store it. Moreover, when the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE may delete the rejected NSSAI from the allowed NSSAI.
[0310] In addition, in the case where the thirty-first identification information includes a third rejected NSSAI, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating the S-NSSAI pending for network slice specific authentication and authorization, and further in the case where the UE transitions to a non-login state for all accesses based on reception of a non-login request message, the UE may ignore the S-NSSAI.
[0311] In addition, in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information constitutes at least one set of S-NSSAI and a rejection reason value of S-NSSAI indicating failure of network slice specific authentication and authorization, and further in the case where the information indicating the access type for de-login is included in the non-login request message including information indicating 3GPP access or non-3GPP access, and further in the case where the access to the other party is in a logged-in state, the UE can include the S-NSSAI in the fourth rejected NSSAI and store it, and, in the case where the S-NSSAI included in the new rejected NSSAI is included in the allowed NSSAI stored by the UE, the UE can delete the rejected NSSAI from the allowed NSSAI.
[0312] Or in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value of S-NSSAI indicating failure of network slice specific authentication and authorization, and then in the case where the UE transitions to a non-login state for all accesses based on reception of a non-login request message, the UE may delete the S-NSSAI from the third rejected NSSAI.
[0313] In addition, in the case where the fourth rejected NSSAI is included in the thirty-first identification information, in other words, in the case where the thirty-first identification information contains at least one set of S-NSSAI and a rejection reason value indicating the S-NSSAI pending for network slice specific authentication and authorization, and further in the case where the UE transitions to the non-login state for all accesses based on the reception of the non-login request message, the UE may ignore the S-NSSAI.
[0314] That is, in the non-login process initiated by the network, when a non-login request message including the thirty-first identification information is received from the core network, and the thirty-first identification information includes S-NSSAI and a rejection reason value indicating that it is not available in the current login area, the S-NSSAI can be ignored.
[0315] Moreover, in a non-login process initiated by the network, in the case of receiving a non-login request message including the thirty-first identification information from the core network, and further in the case of the UE transitioning to the non-login state for all accesses based on the reception of the non-login request message, and further in the case of the thirty-first identification information including an S-NSSAI and a rejection reason value indicating that the S-NSSAI for establishing the association is not available in the current PLMN and / or indicating that the S-NSSAI for network slice specific authentication and authorization is pending and / or indicating that the network slice specific authentication and authorization has failed, the UE may ignore the S-NSSAI.
[0316] Moreover, in the non-login process initiated by the network, in other cases, the UE can add and store the S-NSSAI corresponding to the appropriate rejected NSSAI based on the rejection reason included in the thirty-first identification information, and if it exists, the S-NSSAI included in the rejected NSSAI stored by the UE can be deleted from the allowed NSSAI stored by the UE.
[0317] In addition, in the case where the UE receives the thirty-first identification information during the non-login process initiated by the network, and in the case where the UE has not transitioned to the non-login state for all accesses based on the reception of the non-login request message, and regardless of the rejection reason value corresponding to the S-NSSAI included in the thirty-first identification information, the UE can add the S-NSSAI included in the thirty-first identification information to the appropriate rejected NSSAI based on the rejection reason for establishing the association and store it, and if it exists, the S-NSSAI included in the rejected NSSAI stored by the UE can be deleted from the allowed NSSAI stored by the UE.
[0318] When the UE receives the 32nd identification information, the UE may delete the allowed NSSAI for access that transitions to the non-logged-in state. Specifically, when the UE includes the 32nd identification information and information indicating 3GPP access in a non-logged-in request message and receives it, the UE may delete the allowed NSSAI for 3GPP access from storage. When the UE includes the 32nd identification information and information indicating non-3GPP access in a non-logged-in request message and receives it, the UE may delete the allowed NSSAI for non-3GPP access from storage. When the UE includes the 32nd identification information and information indicating access of both parties in a non-logged-in request message and receives it, the UE may delete the stored allowed NSSAI from storage. The UE may also store the S-NSSAI that corresponds to other reason values in the same way. It should be noted that the storage method of the NSSAI based on the UE's rejection is not limited to this, as long as it is stored in a state where the S-NSSAI corresponds to the reason value.
[0319] It should be noted that the AMF can select and determine whether to include at least one of the thirty-first to thirty-second identification information in the non-login request message based on subscriber information and / or network capability information and / or operator policy and / or network status and / or user login information and / or context maintained by the AMF.
[0320] Specifically, the AMF may not include the thirty-first identification information including the rejection reason value indicating that it is not available in the current login area in the login request message, or may control it in that way.
[0321] Moreover, the AMF may include information indicating access of both parties in the non-login request message as identification information indicating the access type for de-login, without including a rejection reason value indicating unavailable in the current PLMN and / or a rejection reason value of S-NSSAI pending for indicating network slice specific authentication and authorization and / or a rejection reason value of S-NSSAI indicating failure of network slice specific authentication and authorization in the login reject message, and may also perform control in that way.
[0322] The UE receives the non-login request message via the 5G AN (gNB). By receiving the non-login request message, the UE can identify the content of various identification information included in the non-login request message.
[0323] Upon receiving the Non-Login Request message, the UE may send a Non-Login Accept message (DEREGISTRAION ACCEPT message) to the AMF via the 5G AN (or gNB). It should be noted that the Non-Login Accept message is a NAS message sent and received over the N1 interface. Furthermore, the RRC message may be a control message sent and received between the UE and the 5G AN (or gNB).
[0324] Each device can transition to a state where the UE is not logged into the network (RM_DEREGISTERED state or 5GMM-DEREGISTERED state) based on the sending and receiving of the login acceptance message. In addition, the transition of each device to each state can also be based on the completion of this process.
[0325] Furthermore, each device may perform processing based on the information sent and received during the non-login process upon completion of the non-login process. For example, the UE may start the login process upon completion of the non-login process.
[0326] [4. Embodiments of the present invention]
[0327] The embodiment of the present invention may be a combination of one or more processes described in Chapter 3. That is, in the embodiment of the present invention, each process in Chapter 3 may be executed independently of other processes, or each device may start an appropriate process after each process is completed.
[0328] [5. Improvement example]
[0329] The program running in the apparatus of the present invention may be a program that controls a central processing unit (CPU) or other computer system to implement the functions of the embodiments of the present invention. The program or the information processed by the program is temporarily stored in volatile memory such as random access memory (RAM), non-volatile memory such as flash memory, a hard disk drive (HDD), or other storage device system.
[0330] It should be noted that the program for implementing the functions of the embodiments involved in the present invention can also be recorded in a computer-readable recording medium. This can be achieved by reading the program recorded in the recording medium into a computer system and executing it. The "computer system" mentioned here refers to a computer system built into a device, and includes a computer system with hardware such as an operating system and peripherals. In addition, the "computer-readable recording medium" can be a semiconductor recording medium, an optical recording medium, a magnetic recording medium, a medium that dynamically stores a program for a short period of time, or other computer-readable recording medium.
[0331] Furthermore, each functional block or each feature of the device used in the above-described embodiments can be mounted or implemented by an electronic circuit such as an integrated circuit or a plurality of integrated circuits. A circuit designed in such a manner as to execute the functions described in this specification can include a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or a combination thereof. The general-purpose processor can be a microprocessor, or can be a processor of a type other than a microprocessor, a controller, a microcontroller, or a state machine. The above-described electronic circuit can be constituted by a digital circuit, or can be constituted by an analog circuit. Furthermore, in the case where an integrated circuit technology replacing the current integrated circuit technology emerges as a result of advancement of semiconductor technology, one or more aspects of the present application can also use a new integrated circuit based on this technology.
[0332] Note that the present application is not limited to the above-described embodiments. In the embodiments, one example of the device is described, but the present application is not limited thereto, and can be applied to a stationary or non-portable electronic device, such as a terminal device or a communication device, provided indoors or outdoors, such as an AV device, a kitchen device, a cleaning / washing device, an air conditioning device, an office device, a vending machine, or other living device.
[0333] The embodiments of the present application have been described in detail above with reference to the accompanying drawings, but the specific configuration is not limited to the present embodiments, and design changes and the like within a range not deviating from the gist of the present application are included. Furthermore, the present application can be variously changed within the scope of the technical idea recited in the technical scope, and embodiments obtained by appropriately combining the technical ideas disclosed in the different embodiments in an appropriate manner are also included in the technical scope of the present application. Furthermore, a configuration obtained by replacing elements that have the same or similar functions to the elements described in the above-described embodiments with each other is also included.
[0334] Explanation of Reference Signs
[0335] 1 mobile communication system
[0336] 10 UE_A
[0337] 30 PGW-U
[0338] 32 PGW-C
[0339] 35 SGW
[0340] 40 MME
[0341] 45 eNB
[0342] 50 HSS
[0343] 60 PCRF
[0344] 80 Access Network_A(E-UTRAN)
[0345] 90 Core Network_A
[0346] 120 Access Network_B (5G AN)
[0347] 122 gNB
[0348] 130 UPF
[0349] 132 SMF
[0350] 140 AMF
[0351] 150 UDM
[0352] 160 PCF
[0353] 190 Core Network_B
Claims
1. A user equipment (UE), characterized in that: The UE includes a transceiver unit, a storage unit, and a control unit. The transceiver receives a non-login request message from a core network, where the non-login request message includes first rejection network slice selection assistance information NSSAI, where the first rejection NSSAI includes first single network slice selection assistance information S-NSSAI and a first reason value associated with the first S-NSSAI. The control unit stores the first S-NSSAI in the rejection NSSAI stored in the storage unit based on the first reason value, and Based on the receipt of the non-login request message, the UE is transitioned to the 5GMM-DEREGISTERED state.
2. The UE according to claim 1, wherein The first reason value indicates: The first S-NSSAI is not available in the current PLMN, the first S-NSSAI is not available in the current login area, or the first S-NSSAI is not available due to network slice specific authentication and authorization failure.
Citation Information
Patent Citations
Rare earth species separation recovery fusion protein and use thereof
JP2019176833A
Slice information updating method and device
CN109951877A
A mechanism to enable interworking between network slicing and evolved packet core connectivity
TW201924400A
Methods and apparatuses for reconfiguring a data connection
WO2018206080A1