Method and apparatus for handling non-integrity protected reject messages in non-public networks

By generating random latency for user equipment (UE) in a standalone non-public network (SNPN) and managing a list of banned networks, the problem of DoS attacks in 5G networks is solved, improving access security and robustness and preventing malicious connections.

CN114556994BActive Publication Date: 2026-05-01NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2020-07-24
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

There is a lack of effective methods to prevent denial-of-service (DoS) attacks in existing 5G networks, especially in standalone non-public networks (SNPNs). When malicious networks attack with denial messages that are not protected by integrity, user equipment (UE) is misled into connecting to fake base stations, endangering data security.

Method used

By generating a waiting time for the user equipment (UE) that is randomly selected from a pre-approved waiting time range, and dynamically managing the list of blocked networks based on whether the counter value is between zero and the randomly selected maximum value, malicious rejection message repeat attacks are prevented.

Benefits of technology

It effectively reduces the risk of DoS attacks, improves the security and robustness of UEs when accessing SNPN, prevents malicious connections, and protects the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114556994B_ABST
    Figure CN114556994B_ABST
Patent Text Reader

Abstract

Methods and apparatus, including computer program products, are provided for handling an unprotected reject message in a non-public network. In some example embodiments, an apparatus can be provided that includes at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to receive a reject message from a network function in a standalone non-public network (SNPN), wherein information in the reject message indicates that the apparatus is not allowed to access the SNPN by subscription, and add an identification of the SNPN to a forbidden SNPN list associated with access via which the apparatus sent a request and subsequently received the reject message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The topics described in this article relate to wireless telecommunications. Background Technology

[0002] Telecommunications networks such as fifth-generation mobile networks (5G networks) are expected to represent the next major phase of mobile telecommunications standards and bring numerous improvements to the mobile network user experience. For example, 5G networks should offer new technological solutions that allow for greater throughput, lower latency, higher reliability, greater connectivity, and greater mobility.

[0003] In addition to these performance improvements, 5G networks are also expected to expand the flexibility of network use and allow for a wider range of use cases and business models for users.

[0004] However, as 5G systems support an increasing number of devices and services (including applications with a wide range of use cases and different requirements in terms of bandwidth, latency, and reliability), user equipment operating on and communicating through cellular systems is increasingly vulnerable to malicious communications such as denial-of-service (DoS) attacks. Summary of the Invention

[0005] Methods, apparatus, and computer program products are provided for processing rejection messages that are not protected by integrity in non-public networks.

[0006] In some example embodiments, an apparatus may be provided comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: receive a rejection message from a network function in a Standalone Non-Public Network (SNPN), wherein information in the rejection message indicates that the apparatus is not permitted to access the SNPN by subscription; and add the identifier of the SNPN to a list of banned SNPNs, wherein the apparatus sends a request for access by subscription for the banned SNPN and subsequently receives the rejection message. In some embodiments, the information in the rejection message includes a 5G Mobility Management (5GMM) reason value #72, #74, or #75. In some embodiments, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus to at least: set a 5G System (5GS) update state to 5U3 ROAMING NOTALLOWED; store the 5GS update state; and delete each of the 5G Globally Unique Temporary Identifier (5G-GUTI), the Last Access Registration Identifier (TAI), the TAI list, and the Key Set Identifier (ngKSI). In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: enter a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and to cause the device to perform SNPN selection. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: determine whether the Non-Access Stratum (NAS) has successfully performed an integrity check on the rejection message; and if the NAS has successfully performed an integrity check on the rejection message, set an SNPN-specific attempt counter for non-3GPP (non-3GPP) access for the SNPN to a specific maximum value for the user equipment. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0007] In other example embodiments, a method, such as a computer-implemented method, may be provided, which may be implemented using, for example, an apparatus such as those described herein. In some embodiments, the method may include: receiving a rejection message from a network function in a Standalone Non-Public Network (SNPN), wherein information in the rejection message indicates that the device is not permitted to access the network via subscription; and adding the identifier of the SNPN to a list of banned SNPNs, wherein the device sends a request for access via subscription to the banned SNPN and subsequently receives the rejection message. In some embodiments, the information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the method further includes: setting the 5GS update state to 5U3 ROAMING NOT ALLOWED; storing the 5GS update state; and deleting each of the 5G-GUTI, the last access registration TAI, the TAI list, and the ngKSI. In some embodiments, the method further includes: causing the device to enter a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and causing the device to perform SNPN selection. In some embodiments, the method further includes: determining whether the NAS has successfully performed an integrity check on the rejection message; and if the NAS has successfully performed an integrity check on the rejection message, setting an SNPN-specific attempt counter for non-3GPP access for the SNPN to a specific maximum value for the user equipment. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0008] In other example embodiments, an apparatus, such as an apparatus including at least one processor and at least one memory storing computer program code, may be provided, which may be configured to implement methods such as those described herein. In some embodiments, the apparatus may include: a component for receiving a rejection message from a network function in an Independent Non-Public Network (SNPN), wherein information in the rejection message indicates that the apparatus is not permitted to access the SNPN by subscription. In some embodiments, the apparatus may include a component for adding the identifier of the SNPN to a list of banned SNPNs, wherein the apparatus sends a request for access by subscription to a banned SNPN and subsequently receives the rejection message. In some embodiments, information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the apparatus may further include: a component for setting the 5GS update status to 5U3 ROAMING NOT ALLOWED; a component for storing the 5GS update status; and a component for deleting each of the 5G-GUTI, the last access registration TAI, the TAI list, and the ngKSI. In some embodiments, the apparatus may further include: components for causing the apparatus to enter a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and components for causing the apparatus to perform SNPN selection. In some embodiments, the apparatus may further include: components for determining whether the NAS has successfully performed an integrity check on the rejection message; and components for setting an SNPN-specific attempt counter for non-3GPP access for the user equipment to a specific maximum value if the NAS has successfully performed an integrity check on the rejection message. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0009] In other example embodiments, a computer program product may be provided, such as a non-transitory computer-readable medium including program code that, when executed, causes operations including: receiving a rejection message from a network function in an Independent Non-Public Network (SNPN), wherein information in the rejection message indicates that a device is not permitted to access the SNPN by subscription; and adding an identifier of the SNPN to a list of banned SNPNs, wherein the device sends a request for access by subscription for the banned SNPN and subsequently receives the rejection message. In some embodiments, the information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the program code causes further operations including: setting the 5GS update state to 5U3 ROAMING NOT ALLOWED; storing the 5GS update state; and deleting each of the 5G-GUTI, the last access registered TAI, the TAI list, and the ngKSI. In some embodiments, the program code causes further operations including: putting the device into a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and causing the device to perform SNPN selection. In some embodiments, the program code causes further operations including: determining whether the NAS has successfully performed an integrity check on the rejection message; and if the NAS has successfully performed an integrity check on the rejection message, setting the SNPN-specific attempt counter for non-3GPP access for the SNPN to a specific maximum value for the user equipment. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0010] According to yet another embodiment, an apparatus is provided, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: store a user data list, wherein each entry in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); maintain one or more banned SNPN lists and one or more SNPN-specific attempt counters; and, in the event that an entry in the user data list is reconfigured or removed, determine, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list for non-3GPP access. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0011] According to yet another embodiment, a method is provided, the method comprising: storing a user data list, wherein each entry in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters; and, in the event that an entry in the user data list is reconfigured or removed, determining, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0012] According to another embodiment, an apparatus is provided, such as an apparatus including one or more processors and one or more memories storing computer program code. Such an apparatus can be configured to perform any of the methods described herein, such as executing computer-implemented instructions stored on one or more memories using one or more processors. In some embodiments, the apparatus may include: components for storing a user data list, wherein each entry in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); components for maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters; and components for determining, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with a reconfigured or removed entry should be removed from the one or more banned SNPN lists in the event that an entry in the user data list is reconfigured or removed. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list for non-3GPP access. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0013] In another example embodiment, a computer program product including a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program code that, when executed, causes operations including: storing a user data list, wherein each entry in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters; and, in the event that an entry in the user data list is reconfigured or removed, determining, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list for non-3GPP access. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0014] According to another embodiment, an apparatus is provided, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: store a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); receive an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; upon receiving the rejection message, determine whether the entry for accessing the SNPN is invalid for access via which the apparatus sends a request message and / or receives the rejection message, and initiate T3247; and maintain one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an Authentication Reject message. In some embodiments, the rejection message is a registration rejection message or a service rejection message. In some embodiments, one or more counters include: a counter for events where an entry for the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry for the current SNPN is considered invalid for non-3GPP access.

[0015] In another embodiment, a method is provided that: stores a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); receives an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; upon receiving the rejection message, determines whether the entry for accessing the SNPN is invalid for access via which the device sends a request message and / or receives the rejection message, and initiates T3247; and maintains one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an AUTHENITCATION REJECT message. In some embodiments, the rejection message is a REGISTRATION REJECT message or a SERVICE REJECT message. In some embodiments, one or more counters include: a counter for events where an entry in the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry in the current SNPN is considered invalid for non-3GPP access.

[0016] According to another embodiment, an apparatus is provided, such as an apparatus including one or more processors and one or more memories storing computer program code. Such an apparatus can be configured to perform any of the methods described herein, such as executing computer-implemented instructions stored on one or more memories using one or more processors. In some embodiments, the apparatus may include: components for storing a list of user data, wherein each of a plurality of entries in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); components for receiving a rejection message that is not protected by integrity from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; components for determining, upon receiving the rejection message, whether the entry for accessing the SNPN is invalid for access via which the apparatus sends a request message and / or receives the rejection message, and initiating T3247; and components for maintaining one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an AUTHENITCATION REJECT message. In some embodiments, the rejection message is a REGISTRATION REJECT message or a SERVICE REJECT message. In some embodiments, one or more counters include: a counter for events where an entry in the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry in the current SNPN is considered invalid for non-3GPP access.

[0017] According to yet another embodiment, a computer program product including a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program code that, when executed, causes operations including: storing a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); receiving an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; upon receiving the rejection message, determining whether the entry for accessing the SNPN is invalid for access via which the device sends a request message and / or receives the rejection message, and initiating T3247; and maintaining one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an AUTHENITCATION REJECT message. In some embodiments, the rejection message is a REGISTRATION REJECT message or a SERVICE REJECT message. In some embodiments, one or more counters include: a counter for events where an entry in the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry in the current SNPN is considered invalid for non-3GPP access.

[0018] According to another example embodiment, an apparatus is provided, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: receive a rejection message from a network function in an Independent Non-Public Network (SNPN); initiate one or more timers configured to monitor time elapsed since the rejection message was received; randomly determine a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network function; determine, via the one or more timers, whether the time elapsed since the rejection message corresponds to a randomly selected duration value; and, if it is determined that the elapsed time corresponds to the randomly selected duration value, send the subsequent registration request to the network entity. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the apparatus. In some embodiments, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus to at least: determine, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: immediately send a subsequent registration request to a network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: send an initial registration request to a network entity, the initial registration request including at least identification information for the user equipment. In some embodiments, one or more counters are associated with entries in a user data list maintained by the device, the one or more counters including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a temporary or permanent banned network list, wherein at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: remove entries for private networks from the temporary or permanent banned network list if the value of a second counter is greater than zero but less than a randomly selected duration value when the second counter expires.

[0019] According to another embodiment, a method is provided, the method comprising: receiving a registration rejection message from a network entity in response to sending an initial registration request; starting one or more timers configured to monitor time elapsed since receiving the registration rejection message; randomly determining a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network entity; determining, via the one or more timers, whether the time elapsed since receiving the registration rejection message corresponds to a randomly selected duration value; and, if it is determined that the elapsed time corresponds to the randomly selected duration value, sending the subsequent registration request to the network entity. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the device. In some embodiments, the method further includes: determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, the method further includes: immediately sending a subsequent registration request to the network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, the method further includes: sending an initial registration request to the network entity, the initial registration request including at least identification information for a user device. In some embodiments, one or more counters are associated with entries in a user data list maintained by the device, the one or more counters comprising: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a temporary or permanent banned network list, and the method further comprises: removing entries in the user data list for private networks from the temporary or permanent banned network list if the value of the second counter is greater than zero but less than a randomly selected duration value when the second counter expires.

[0020] According to another embodiment, an apparatus is provided, such as an apparatus including one or more processors and one or more memories storing computer program code. This apparatus can be configured to perform any of the methods described herein, such as executing computer-implemented instructions stored on one or more memories using one or more processors. In some embodiments, the apparatus may include: means for receiving a registration rejection message from a network entity in response to sending an initial registration request; means for starting one or more timers, wherein the one or more timers are configured to monitor time elapsed since receiving the registration rejection message; means for randomly determining a duration value within a predetermined range between a minimum and a maximum value, wherein the minimum value corresponds to a minimum secure duration for sending a subsequent registration request to the network entity; means for determining, based on the one or more timers, whether the time elapsed since receiving the registration rejection message corresponds to a randomly selected duration value; and means for sending the subsequent registration request to the network entity if it is determined that the elapsed time corresponds to the randomly selected duration value. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the apparatus. In some embodiments, the apparatus further includes: means for determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, the apparatus further includes: means for immediately sending a subsequent registration request to a network entity when the registration rejection message is determined to be an integrity-protected message. In some embodiments, the apparatus further includes: means for sending an initial registration request to a network entity, wherein the initial registration request includes at least identification information for a user equipment. In some embodiments, one or more counters are associated with entries in a user data list maintained by the apparatus, the one or more counters including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a temporary or permanent banned network list, and the apparatus further includes: means for removing entries in the user data list for private networks from the temporary or permanent banned network list when the value of the second counter is greater than zero but less than a randomly selected duration value when the second counter expires.

[0021] According to another embodiment, a computer program product including a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program code that, when executed, causes operations including: receiving a registration rejection message from a network entity in response to sending an initial registration request; starting one or more timers configured to monitor time elapsed since receiving the registration rejection message; randomly determining a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network entity; determining, based on the one or more timers, whether the time elapsed since receiving the registration rejection message corresponds to a randomly selected duration value; and, if it is determined that the elapsed time corresponds to the randomly selected duration value, sending the subsequent registration request to the network entity. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the device. In some embodiments, the program code causes further operations including: determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, the program code causes further operations including: immediately sending a subsequent registration request to the network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, the program code causes further operations including sending an initial registration request to a network entity, the initial registration request including at least identification information for the user equipment. In some embodiments, one or more counters are associated with entries in a user data list maintained by the device, the one or more counters including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a list of temporarily or permanently banned networks, and the program code causes further operations including removing entries for private networks from the list of temporarily or permanently banned networks when the value of the second counter is greater than zero but less than a randomly selected duration value upon the expiration of the second counter.

[0022] The above aspects and features can be implemented in systems, apparatus, methods, and / or products according to desired configurations. Details of one or more variations of the subject matter described herein are set forth in the accompanying drawings and the following description. The features and advantages of the subject matter described herein will become apparent from the description and drawings and from the claims. Attached Figure Description

[0023] In the attached diagram:

[0024] Figure 1 An example depicting a portion of a 5G wireless network according to some example embodiments;

[0025] Figure 2 Examples depicting apparatuses according to some exemplary embodiments;

[0026] Figure 3 Examples of processing flows for a UE to request registration with the network, according to some example embodiments;

[0027] Figure 4 Examples of processing flows for a UE to request services from a network, according to some example embodiments;

[0028] Figure 5 Examples of methods for processing rejection messages that are not protected by integrity in a non-public network, according to some example embodiments;

[0029] Figure 6 Another example of a method for processing rejection messages that are not protected by integrity in a non-public network, according to some example embodiments;

[0030] Figure 7 Further example of a method for processing rejection messages that are not protected by integrity in a non-public network, according to some example embodiments;

[0031] ] Figure 8 Further example of a method for processing rejection messages that are not protected by integrity in a non-public network, according to some example embodiments; Figure 9 Another example of a method for processing rejection messages that are not protected by integrity in a non-public network, according to some example embodiments, is described.

[0032] The same markings are used to refer to the same or similar items in the accompanying drawings. Detailed Implementation

[0033] In many cellular systems and telecommunications networks, such as fifth-generation (5G) networks, user equipment (UE) can be configured to access public terrestrial mobile networks (PLMNs), standalone non-public networks (SNPNs), etc., through interaction. In this process, the UE requests registration with the network; the network registers or rejects the UE; the network sends a registration message or rejection message back to the UE; and if the UE receives a registration message, it performs the procedures for connecting to and authenticating with the network. However, frequently and for various reasons, the network will send a rejection message to the UE, indicating that the network cannot register the UE with the network.

[0034] One of the key issues that next-generation telecommunications systems (e.g., 5G networks) need to address is how to provide a robust method to prevent DoS attacks for UEs attempting to connect to a network (e.g., SNPN). When the network is not a PLMN (e.g., when the network is an SNPN) and / or when the expected or initial connection protocol sought between the UE and the network is non-3GPP, a suspicious DoS attacker (e.g., a malicious network) may know the predetermined waiting time and simply intercept the control messages sent from the UE at some point outside the predetermined waiting time used to send another control message, in situations where the network cannot be trusted to provide the UE with a waiting time to respond to control messages.

[0035] Currently, 3GPP standard TS 24.501 (the entire contents of which are incorporated herein by reference for all purposes) does not provide a robust method for reducing or preventing denial-of-service (DoS) attacks against such cellular systems and networks. A specific vulnerability exists when a UE sends a request to register with the network. Instead of the expected network responding to the UE's registration request, a malicious or fake network responds with an unsolicited or actively provided registration rejection message. In this situation, under current standards and network protocols, the UE can receive the request and immediately respond by sending the same request a second time, or it can respond with a second request for connection via a different protocol. In this case, the malicious or fake network is prepared and waiting for a repeated or second request from the UE and can deploy a malicious or fake base station to intercept the registration request. Once the malicious or fake base station receives the repeated or second registration request from the UE, it can send a message indicating acceptance of the registration request, authentication information, connection protocol information, etc., back to the UE. Furthermore, the UE may determine that the malicious or fake base station is actually part of a real, approved network and will connect to the malicious or fake network via the malicious or fake base station, thereby endangering the UE and any data or information stored on or sent from / to the UE.

[0036] Other approaches to preventing such DoS attacks and subsequent vulnerabilities at the UE level have been discussed, such as those in International Patent Application No. 2019 / 004901 (hereinafter referred to as “901 Publication”) and Amendment Request C1-193912 (hereinafter referred to as “912CR”), which was agreed upon at the 117th meeting of 3GPP TSG-CT WG1 held in Reno, NV, USA, from May 13-17, 2019. The entire contents of each article are incorporated herein by reference.

[0037] According to "901 Announcement," the network provides optional control signaling that instructs a wireless communication device to wait a certain amount of time before sending a control message to the network device. The UE can then accept or reject this waiting time before sending a control message and send the control message to the network device after this waiting time. Alternatively, the UE can reject the network-prescribed waiting time and instead use the default waiting time or trigger an error handline procedure in response to a suspected DoS attack. However, because the network provides a certain waiting time, and because this waiting time is static and predetermined by the network as a safe time (after which control messages are sent), malicious networks or fake access points (e.g., base stations, gNodeBs, etc.) can easily send a proactively offered rejection message to the UE, waiting for the network-standardized time, thereby intercepting duplicate or new control messages and continuously launching DoS attacks or attempting to establish a malicious connection with the UE by registering it with the fake access point, as well as other possible malicious activities. Furthermore, since the network provides a certain waiting time, a malicious or fake network could be the network providing that waiting time. This malicious or fake network could then simply wait for that known waiting time, intercept delayed control messages, and continuously launch DoS attacks, attempting to establish a malicious connection with the UE by registering it with a fake access point. Therefore, the systems, methods, and devices described in "901 Disclosure" do not propose a robust method for reducing or eliminating DoS attacks based on vulnerabilities associated with malicious rejection messages sent in response to a UE's registration request.

[0038] Regarding "912CR", the described method explicitly applies only to PLMNs and effectively indicates that "UEs may request the use of Mobile-Initiated Connection (MICO) mode during the registration process (see 3GPP TS 23.501 and 3GPP TS 23.502)" and "UEs should not request the use of MICO mode on non-3GPP access." In other words, "912CR" indicates that MICO mode can only be used with public networks and not with non-public networks, which imposes limitations on network access and UE security if a connection to a non-public (e.g., non-3GPP) network is desired or required. As stated in "912CR", a UE can use a single counter for the "SIM / USIM is deemed invalid for GPRS service" event and a single counter for the "SIM / USIM is deemed invalid for 5GS service on non-3GPP access" event. For each PLMN-specific counter whose value is greater than zero and less than the UE's specific maximum value, the UE should remove the corresponding PLMN from the list of banned PLMNs. For each PLMN-specific attempt counter for non-3GPP access whose value is greater than zero and less than the UE's specific maximum value, the UE should remove the corresponding PLMN from the list of banned PLMNs for non-3GPP access.

[0039] As described herein, by providing the UE with a randomly selected waiting time from a pre-approved waiting time range, and then removing network identifiers or entries from a temporary or permanent banned network list based on whether a counter value is between zero and a randomly selected UE achieving a specific maximum value (e.g., a randomly selected UE achieving a specific maximum value associated with that specific network and that specific control message attempt), at least some example embodiments of the methods, apparatus, and computer program products address this problem, as well as other problems and limitations of conventional methods.

[0040] Some embodiments will now be described more fully below with reference to the accompanying drawings, which illustrate some, but not all, of the embodiments of this disclosure. In fact, various embodiments of this disclosure may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will satisfy applicable legal requirements. The same reference numerals throughout refer to the same elements. As used herein, the terms “data,” “content,” “information,” and similar terms are used interchangeably to refer to data that can be transmitted, received, and / or stored according to embodiments of this disclosure. Therefore, the use of any such terms should not be construed as limiting the spirit and scope of the embodiments of this disclosure.

[0041] Furthermore, as used herein, the term "circuit" means: (a) a hardware circuit implementation (e.g., an implementation of analog and / or digital circuitry); (b) a combination of a circuit and a computer program product comprising software and / or firmware instructions stored on one or more computer-readable storage media, which work together to enable a device to perform one or more functions described herein; and (c) a circuit, such as a microprocessor or a portion thereof, which requires software or firmware to operate, even if such software or firmware is not physically present. This definition of "circuit" applies to all uses of the term herein, including its use in any claim. As another example, as used herein, the term "circuit" also covers implementations comprising one or more processors and / or portions thereof and their accompanying software and / or firmware. As yet another example, the term "circuit" as used herein also includes, for example, baseband integrated circuits or application processor integrated circuits for mobile phones, or similar integrated circuits in servers, cellular network devices, other network devices, field-programmable gate arrays, and / or other computing devices.

[0042] As defined herein, “computer-readable storage medium” refers to a physical storage medium (e.g., a volatile or non-volatile storage device), which may differ from “computer-readable transmission medium”, which refers to an electromagnetic signal.

[0043] Now for reference Figure 1 This illustrates an example system supporting communication between a UE and one or more access points, each of which can communicate with one or more stations. These access points can then communicate with one or more networks. While access points can communicate via Long Term Evolution (LTE) or LTE-Advanced (LTE-A) networks, other networks can also support communication between access points, including those configured according to Wideband Code Division Multiple Access (W-CDMA), CDMA2000, Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), IEEE 802.11 standards (e.g., including IEEE 802.11ah or 802.11ac standards or other updated modifications of that standard), Wireless Local Area Networks (WLAN), Global Microwave Access Interoperability (WiMAX) protocol, Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (UTRAN), etc.

[0044] Access points and UEs can communicate via wired communication, but most commonly via wireless communication. For example, access points and UEs can communicate in a frequency band below 1 GHz as defined by the IEEE 802.11ah standard or in a frequency band of 5 GHz as defined by the IEEE 802.11ac standard. Access points can be represented by any of various network entities, such as access points, base stations, Node Bs, gNodeBs (gNBs), Radio Network Controllers (RNCs), mobile devices / stations (e.g., mobile phones, smartphones, portable digital assistants (PDAs), pagers, laptops, tablets, or any and many other handheld or portable communication devices, computing devices, content generation devices, content consumption devices, or combinations thereof), etc. UEs can also be represented by various devices, such as sensors, meters, etc. Sensors and meters can be deployed in a variety of applications, including in practical applications as gas meters, water meters, electricity meters, etc., in environmental and / or agricultural monitoring applications, in industrial process automation applications, in healthcare and fitness applications, in building automation and control applications, and / or in temperature sensing applications. In some embodiments, a station embodied by sensors or instruments may be used to transmit sensor and instrument data back. Alternatively, the UE may be embodied by a mobile terminal, such as a mobile communication device, for example, any one or a combination of a mobile phone, smartphone, portable digital assistant (PDA), pager, laptop computer, tablet computer, or many other handheld or portable communication device, computing device, content generation device, content consumption device. In embodiments where the UE is embodied by a mobile terminal, communication between the access point and the UE may be used for purposes such as extending the range of Wi-Fi or another wireless local area network (WLAN) by extending the range of a hotspot, and may be used to offload traffic that would otherwise be carried by a cellular or other network.

[0045] The access point and / or UE may be embodied in or otherwise include device 202, such as Figure 2 frame Figure 1 As generally understood, device 202 is specifically configured to perform the functions of a corresponding device. While this device may be used, for example, by an access point or a UE, it should be noted that the components, devices, or elements described below are not mandatory and may therefore be omitted in some embodiments. Furthermore, in addition to those shown and described herein, some embodiments may include further or different components, devices, or elements.

[0046] A method for processing unprotected rejection messages in non-public networks is disclosed. In some embodiments, the method typically includes: generating a randomly selected wait time from a pre-approved wait time range; removing a network identifier or entry from a temporary or permanent blocked network list based on whether a counter value is between zero and a specific maximum value achieved by the UE (e.g., a specific maximum value achieved by the UE associated with the specific network and the specific control message attempt); and / or sending a control message after the randomly selected wait time if the counter value is below the specific maximum value achieved by the UE. References are provided below. Figure 1 Example implementations are provided.

[0047] Figure 1 An example of a portion of a 5G wireless network 100 according to some example embodiments is depicted.

[0048] The 5G wireless network 100 may include user equipment (UE) 102, which is configured to be wirelessly coupled to a radio access network (RAN) 104 (also referred to as core network 104) served by wireless access points 106 (such as wireless base stations, wireless LAN access points, home base stations, and / or other types of wireless access points).

[0049] Network 100 may include core network 104, which may include features not shown, such as Access and Mobility Management Function (AMF), Access Session Management Function (V-SMF), Access Policy Control Function (v-PCF), Access Network Slice Selection Function (v-NSSF), and / or Access User Plane Function (V-UPF). In some embodiments, these devices may be associated with a Standalone Non-Public Network (SNPN).

[0050] In some embodiments, network 100 and / or core network 104 may include devices having functions supporting a Home Public Land Mobile Network (HPLMN) and corresponding functions for “home” radio local area network (WLAN) access, offloading, and / or non-3GPP access. These devices may include features not shown, such as a local SMF, a local PCF, a local NSSF, unified data management, authentication server function (AUSF), application function (AF), local user plane function (H-UPF), and a data network (DN).

[0051] Figure 1A pseudo-access point 108, unrelated to the core network 104, is also depicted. Much like the wireless access point 106, the pseudo-access point 108 is configured to communicate with the UE 102 via a set of architectures, via nodes, or via other service interfaces. While there are reasons why the pseudo-access point 108 could be placed near the real access point 106 or near a suspected location of the UE 102, the pseudo-access point 108 can be located anywhere as long as the UE 102 has wireless access to it for purposes such as sending and receiving communications, control messages, and service requests.

[0052] Figure 1 Service interfaces such as 110, 112, and 116 are also described. The architecture, nodes (e.g., AMF, V-PCF, H-PCF, H-SMF, and V-SMF, as well as other devices), and service interfaces can be defined according to standards such as 3GPP TS 23.501 or 3GPP TS 24.501, however, other standards and proprietary interfaces can be used.

[0053] Network slicing refers to a logical network that provides specific network capabilities and characteristics. A network slice can be considered a dynamically created logical end-to-end network, allowing a given UE to access different network slices through the same radio access network (e.g., through the same radio interface). Network slices can provide different services and / or have different QoS requirements. 3GPP TS 23.501 – System Architecture for 5G Systems describes an example of network slicing.

[0054] The UE's subscription information may specify configuration information related to the number of network slices, QoS type, and / or identifier. The UE's configuration information (provided by the network when registering in a network such as SNPN or PLMN) may include one or more network slice identifiers, such as one or more individual NSSAIs (S-NSSAIs).

[0055] When UE 102 sends registration request 110, registration request 110 can be received or intercepted by both the real access point 106 and the pseudo access point 108. In some embodiments, registration request 110 may include an unencrypted registration request. Since UE 102 is searching for a specific network (e.g., core network 104), UE 102 will expect a response message from core network 104 or an entity of core network 104 (such as the real access point 106). In some embodiments, UE 102 may expect to accept the message requesting registration with network 104, or alternatively, reject the message requesting registration with network 104. There are many reasons why network 104 may reject registration request 110, among which non-limiting options include network 104 not being ready or able to accept new user equipment at this time, access point 106 not operating correctly or having sufficient bandwidth to manage the registration process or relay such a request, and the authentication or identification information provided by UE 102 with registration request 110 being incorrect or unverifiable at this time, etc. However, while UE 102 may be anticipating a response from network 104 or its network devices (e.g., true access point 106), UE 102 may alternatively respond by receiving an actively offered rejection message 112 from pseudo access point 108 in response to sending registration request 110. In some embodiments, the actively offered rejection message 112 may include a non-access stratum (NAS) rejection message, such as a NAS rejection message involving 5GMM rejection reason value #7 (which refers to the reason "5GS service is not permitted"). As described herein, the NAS is the highest layer of the control plane between the UE and the Mobility Management Entity (MME) and can be used to support UE mobility and support session management procedures for establishing and maintaining IP connectivity between the UE and, for example, a Packet Data Network Gateway (PDNGW). In some embodiments, as described in, for example, the behavior of UE 102 under 3GPP TS 24.501, such a registration rejection message should be processed by the receiving 5GMM entity in UE 102. UE 102 then deletes the 5GMM context (e.g., network information and access credentials) and considers the Universal Subscriber Identity Module (USIM) invalid for 5GS services until it is turned off or the Universal Integrated Circuit Card (UICC) containing the USIM is removed from UE 102. Under 3GPP TS 24.501, an alternative is to silently discard proactively offered NAS rejection messages (e.g., rejection message 112), which would mean that UE 102 cannot verify whether the NAS rejection message was sent by a genuine or forged / malicious network or access point.

[0056] Typically, under current 3GPP standards, to prevent spoofed networks from controlling the validity of the USIM and the list of banned PLMNs for the UE, the UE can maintain a counter and a timer (e.g., the T3247 timer) with a random value uniformly drawn from a predetermined range between 30 and 60 minutes. Furthermore, under current 3GPP standards, when the UE receives a rejection message without integrity protection, the UE can start a timer (e.g., T3247) and immediately attempt to register to the same network via another access type (e.g., 3GPP access or non-3GPP access, depending on the access type first attempted before receiving the rejection message). Under current 3GPP standards, after the timer expires, the UE can attempt to register to the same network unless the counter prevents the UE from attempting registration.

[0057] While this approach under the current 3GPP standard may be useful for PLMNs, there is currently no method that can provide such protection for non-public networks such as SNPNs. For example, the method described in 3GPP TS 24.501 and all other current methods are insufficient for use with non-public networks because the way user information is stored is fundamentally different.

[0058] Regarding how user data is stored together with PLMN identifiers relative to non-public network entities (e.g., SNPN entities), for PLMNs, a single SUPI and associated credentials are stored in the USIM and used for registration to all PLMNs, while for non-public networks such as SNPNs, a single SUPI and associated credentials (entries in the "User Data List" that can be stored in the UE via any suitable storage medium) are used for registration to the non-public network, where a different set of "SUPI and associated credentials" is used for each non-public network 102 (also referred to below as "SNPN 102").

[0059] For example, the methods described in 3GPP TS 24.501 and all other current methods are insufficient for use with non-public networks because UE 102 can communicate with the PLMN in MICO mode to enable a quasi-secure channel for communication regarding registration requests, and UE 102 will receive "integrity-verified" rejection messages on this channel, which can be received and trusted for the purpose of 5GS service and registration with the PLMN to make the USIM valid or invalid, but this is not the case for non-public network 104. While there are issues with the UE's stance of rejecting all networks from which it receives rejection messages, there is currently no way to trust rejection messages from non-public network 104 (e.g., SNPN 104) in order to manage the validity / invalidation of USIMs and to list / remove networks from the temporary / permanent list of banned networks managed by UE 102. Due to these and other differences between public networks (e.g., PLMN) and non-public networks 104 (e.g., SNPN 104), current 3GPP standards and other currently available protocols and methods are insufficient to reduce or prevent DoS attacks stemming from the following: In response to sending a registration request 110 to non-public network 104, UE 102 receives a malicious rejection message 112 and re-attempts the registration request 110 to a malicious network or spoofed access point 108, resulting in repeated DoS attacks or successful registration and / or connection of UE 102 with the spoofed access point 108. If the malicious network or spoofed access point 108 can impersonate a Basic Service Set Identifier (BSSID) or Radio Message Authentication Code (MAC) address, or other credentials that can be "verified" relative to a list of authorized or trusted non-public networks stored at UE 102, UE 102 will trust the malicious network or spoofed access point 108 and will be vulnerable to further attacks, loss of UE user data, damage to UE 102, etc.

[0060] Therefore, this document describes and illustrates systems, apparatus, methods, and computer programs for preventing DoS attacks against UE 102 that receives a denial message 112 without integrity protection from a pseudo access point 108. In some embodiments, when UE 102 receives a denial message 112 without integrity protection, UE 102 starts a timer and operates based on a corresponding counter value, the received 5GMM denial reason value, and the access type (e.g., 3GPP or non-3GPP access). In some embodiments, an existing timer T3247 can be reused for this purpose.

[0061] In some embodiments, contrary to the method used to verify the USIM for a non-public network 104 (e.g., SNPN 104), for each entry in the "User Data List" stored at UE 102, UE 102 maintains one counter for the event "the entry for the current SNPN is considered invalid for 3GPP access" and one counter for the event "the entry for the current SNPN is considered invalid for non-3GPP access". Therefore, in some embodiments, the validity of subscription information is managed separately for each non-public network 104 (e.g., SNPN 104). In the case of PLMNs and conventional methods for preventing such DoS attacks on UE 102 attempting to register with a PLMN, UE 102 is configured to use only a single counter for the event "SIM / USIM is considered invalid for GPRS service" and a single counter for the event "SIM / USIM is considered invalid for 5GS service on non-3GPP access". Thus, according to conventional practice for PLMNs, once subscription information in the USIM is considered invalid for one PLMN, then subscription information in the USIM is also considered invalid for other PLMNs. Conversely, according to the method described herein and in the claims, UE 102 can invalidate the USIM for a specific non-public network 104 (e.g., SNPN 104) without invalidating the USIM for other non-public networks.

[0062] In some embodiments, when an entry in the "User Data List" is reconfigured or removed, if the value of the SNPN 104 used for the SNPN corresponding to that entry for 3GPP access is greater than zero and less than a specific maximum value implemented by the UE, then the UE 102 should remove the SNPN identifier corresponding to that entry from the "Permanently Banned SNPN" list. In some embodiments, if the value of the SNPN 104 used for the SNPN corresponding to that entry for non-3GPP access is greater than zero and less than a specific maximum value implemented by the UE, then the UE 102 should remove the SNPN identifier corresponding to that entry from the "Permanently Banned SNPN" list for non-3GPP access.

[0063] In the conventional method for preventing DoS attacks against UEs attempting to connect to a PLMN, when the USIM is removed or otherwise reset, for each PLMN-specific attempt counter whose value is greater than zero and less than a specific maximum value implemented by the UE, the UE 102 should remove the corresponding PLMN from the list of banned PLMNs, and for each PLMN-specific attempt counter whose value is greater than zero and less than a specific maximum value implemented by the UE, the UE should remove the corresponding PLMN from the list of banned PLMNs for non-3GPP access.

[0064] Furthermore, as discussed in more detail below, UE 102, upon receiving rejection message 112, determines that rejection message 112 is not integrity protected because no NAS security, such as encryption of NAS signaling messages that can serve as security parameters for authentication, is provided. Under the 3GPP protocol, integrity protection and encryption can be bound together in the EPS security context (established between UE 102 and MME) and identified by a key set identifier. Therefore, it is generally not possible to establish an EPS security context between UE 102 and SNPN 104. In the context of the PLMN, UE 102 can communicate with the PLMN in MICO mode, meaning that rejection message 112 received from the PLMN is likely to be integrity protected and encrypted upon reception. Conversely, since authentication and identification information are different for each SNPN 104, UE 102 cannot form a secure or quasi-secure communication channel with SNPN 104 so that SNPN 104 can send rejection message 112 with integrity protection and encryption.

[0065] Therefore, UE 102 can be configured to comply with a protocol that selects a random value from a pre-approved range of values ​​associated with waiting time 114, by which UE 102 should wait for the duration of waiting time 114 before sending another control message to SNPN 104 or its access point 106. If, after waiting timer 114, UE 102 determines that the counter is not higher than the UE-approved thresholds for the specific network type (e.g., public vs. non-public) and connection type (e.g., 3GPP vs. non-3GPP) for which UE 102 is requesting registration, the control message is resent to access point 106 to request registration with network 104.

[0066] Once UE 102 determines that network 104 and / or genuine access point 106 are unlikely to be spoofed access point 108, UE 102 can resend control messages. Once network 104 approves UE 102's registration with network 104, UE 102 can begin operating in connected mode, receiving services from service providers according to network 104's service-based architecture (SBA) (e.g., 5GSBA), and utilizing network 104 to communicate with network 104 and with the Internet 118 and / or other resources and services.

[0067] Now for reference Figure 2 It provides a block diagram of apparatus 202 according to some example embodiments. Apparatus 202 may represent user equipment, such as user equipment 102. Apparatus 202 or a portion thereof may be implemented in other network nodes, including base station access point 106 / WLAN access point and other network devices, or other parts of SNPN 104 itself.

[0068] As shown, device 202 may include processor 204, which communicates with memory 206 and is configured to provide and receive signals to and from communication interface 208. In some embodiments, communication interface 208 may include a transmitter and a receiver. In some embodiments, processor 204 may be configured to at least partially control the functions of device 202. In some embodiments, processor 204 may be configured to control the functions of a transmitter and receiver by influencing control signaling via electrical leads to the transmitter and receiver. Similarly, processor 204 may be configured to control other elements of device 10 by influencing control signaling via electrical leads connecting processor 204 to other elements (such as a display or memory 206). Processor 204 may be embodied in various ways, including circuitry, at least one processing core, one or more microprocessors with an accompanying digital signal processor, one or more processors without an accompanying digital signal processor, one or more coprocessors, one or more multi-core processors, one or more controllers, processing circuitry, one or more computers, various other processing units including integrated circuits (e.g., application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc.), or certain combinations thereof. Therefore, although in Figure 2 The processor 20 is illustrated as a single processor; however, in some example embodiments, processor 20 may include multiple processors or processing cores.

[0069] Device 202 may operate using one or more air interface standards, communication protocols, modulation types, access types, etc. Signals transmitted and received by processor 204 may include signaling information according to the applicable cellular system air interface standard and / or any number of different wired or wireless network technologies (including but not limited to Wi-Fi, Wireless Local Access Network (WLAN) technologies such as IEEE 802.11, 802.16, 802.3, ADSL, DOCSIS, etc.). Additionally, these signals may include voice data, user-generated data, user-requested data, etc.

[0070] For example, the cellular modem in device 202 and / or therein can operate according to various first-generation (1G) communication protocols, second-generation (2G or 2.5G) communication protocols, third-generation (3G) operating communication protocols, fourth-generation (4G) communication protocols, fifth-generation (5G) communication protocols, and Internet Protocol Multimedia Subsystem (IMS) communication protocols (e.g., Session Initiation Protocol (SIP), etc.). For example, device 10 can operate according to 2G wireless communication protocols such as IS-136, Time Division Multiple Access (TDMA), Global System for Mobile Communications (GSM), IS-95, and Code Division Multiple Access (CDMA). Additionally, for example, device 10 can operate according to 2.5G wireless communication protocols such as General Packet Radio Service (GPRS) and Enhanced Data GSM Environment (EDGE). Furthermore, for example, device 202 can operate according to 3G wireless communication protocols, such as Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), Wideband Code Division Multiple Access (WCDMA), and Time Division Synchronous Code Division Multiple Access (TD-SCDMA). Additionally, device 202 can operate according to 3.9G wireless communication protocols, such as Long Term Evolution (LTE) and Evolved Universal Terrestrial Radio Access Network (E-UTRAN). Furthermore, for example, device 202 can operate according to 4G wireless communication protocols (such as Advanced LTE, 5G, etc.) and similar wireless communication protocols that may be developed subsequently.

[0071] It should be understood that processor 204 may include circuitry for implementing the audio / video and logic functions of device 202. For example, processor 204 may include a digital signal processor device, a microprocessor device, an analog-to-digital converter, a digital-to-analog converter, etc. The control and signal processing functions of device 202 can be distributed among these devices according to their respective capabilities. Additionally, processor 204 may include an internal voice encoder (VC) 20a, an internal data modem (DM) 20b, etc. Furthermore, processor 204 may include the ability to operate one or more software programs, which may be stored in memory 206. Typically, the software instructions stored in processor 204 and memory 206 can be configured to cause device 202 to perform actions. For example, processor 204 may be able to operate a connectivity program such as a web browser. This connectivity program may allow device 202 to send and receive web content (such as location-based content) according to protocols (such as Wireless Application Protocol, WAP, Hypertext Transfer Protocol, HTTP, etc.).

[0072] Device 202 may also include a user interface, such as headphones or speakers, a ringer, a microphone, a display, a user input interface, etc., which may be operatively coupled to processor 204. As described above, the display may include a touch-sensitive display, wherein a user can touch and / or gesture to make selections, input values, etc. Processor 204 may also include user interface circuitry configured to control at least some functions of one or more elements of the user interface, such as speakers, ringers, microphones, displays, etc. Processor 204 and / or the user interface circuitry including processor 204 may be configured to control one or more functions of one or more elements of the user interface via computer program instructions (e.g., software and / or firmware) accessible to processor 204 stored on memory 206 (e.g., volatile memory, non-volatile memory, devices including them, etc.). Device 202 may include a battery for powering various circuitry associated with the mobile terminal (e.g., circuitry providing mechanical vibration as a detectable output). The user input interface may include a device that allows device 202 to receive data, such as a keypad (e.g., a virtual keyboard displayed on a display or an externally coupled keyboard).

[0073] like Figure 2 As shown, device 202 may also include one or more mechanisms for sharing and / or obtaining data, illustrated as communication interface 208. For example, communication interface 208 of device 202 may include a short-range radio frequency (RF) transceiver and / or interrogator, thus enabling data sharing with and / or data acquisition from electronic devices based on RF technology. Device 202 may include other short-range transceivers, such as infrared (IR) transceivers, using Bluetooth... TM Bluetooth operated by wireless technology TM (BT) transceivers, wireless universal serial bus (USB) transceivers, Bluetooth TM Low-power transceivers, ZigBee transceivers, ANT transceivers, cellular device-to-device transceivers, wireless LAN link transceivers, and / or any other short-range radio technologies. Device 202 (particularly a short-range transceiver) can be able to send and / or receive data from electronic devices in their vicinity (e.g., within approximately 10 meters). Device 202, including Wi-Fi or wireless LAN modems, can also be able to send and / or receive data to / from electronic devices according to various wireless network technologies (including 6LoWpan, Wi-Fi, Wi-Fi Low Power, WLAN technologies such as IEEE 802.11, IEEE 802.15, IEEE 802.16, etc.).

[0074] Device 202 may include other memories, such as a Subscriber Identity Module (SIM), a Removable Subscriber Identity Module (R-UIM), an eUICC, a UICC, etc., which may store information elements related to the mobile user. In addition to the SIM, device 202 may include other removable and / or fixed memories. Device 202 may include volatile and / or non-volatile memories, which may include some or all of memory 206, or alternatively may be separate memories within or connected to device 202. For example, volatile memories may include random access memory (RAM) (including dynamic and / or static RAM), on-chip or off-chip cache memory, etc. Non-volatile memories that can be embedded and / or removable may include, for example, read-only memory, flash memory, magnetic storage devices (e.g., hard disks, floppy disk drives, magnetic tapes), optical disk drives and / or optical media, non-volatile random access memory (NVRAM), etc. Like volatile memories, non-volatile memories may include cache areas for temporary data storage. At least a portion of the volatile and / or non-volatile memories may be embedded in processor 204. The memory may store one or more software programs, instructions, information fragments, data, etc., that can be used by the device to perform the operations disclosed herein. Alternatively or additionally, device 202 may be configured to cause the operations disclosed herein with respect to base station 106 / WLAN access point 106 and network nodes including UE 102.

[0075] The memory may include an identifier capable of uniquely identifying device 202, such as an International Mobile Equipment Identity (IMEI) code. In the example embodiment, computer code stored in the memory may be used to configure processor 204, and / or processor 204 may be configured to provide the operations disclosed herein with respect to base station 106 / WLAN access point 106 and network nodes including UE 102. Similarly, device 202 may be configured as any other component or network device from SNPN 104.

[0076] Some embodiments disclosed herein can be implemented in software, hardware, application logic, or a combination of software, hardware, and application logic. For example, the software, application logic, and / or hardware may reside on memory 206, control device 204, or electronic components. In some example embodiments, the application logic, software, or instruction set is maintained on any of a variety of conventional computer-readable media. In the context of this document, [the following is used to describe the implementation of software, hardware, and application logic]. Figure 2As illustrated in the example, "computer-readable medium" can be any non-transitory medium that can contain, store, communicate, propagate or transmit instructions for use by or in connection with an instruction execution system, apparatus or device (such as a computer or data processor circuit). Computer-readable medium can include non-transitory computer-readable storage medium, which can be any medium that can contain or store instructions for use by or in connection with an instruction execution system, apparatus or device (such as a computer).

[0077] Without limiting the scope, interpretation, or application of the claims appearing below in any way, the technical effects of one or more exemplary embodiments disclosed herein can be improved UE configurations. The reference to “UE 102” below is to be understood as applicable and also refers to “apparatus 202”. Therefore, any embodiment of the method, system, means, device, apparatus, or computer program described or illustrated herein is to be understood to include any or all components, functions, elements, or steps of any other embodiment, such that any method can be performed by UE 102, by apparatus 202, or by any other suitable system or apparatus, and likewise, can be performed according to computer program code contemplated within the scope of this disclosure.

[0078] In some embodiments, UE 102 can be configured to operate in SNPN access mode, wherein UE 102 is configured to request, establish and maintain access, connection, communication channel, and means for service provision with network devices and network entities.

[0079] In some embodiments, if UE 102 operates in SNPN access mode, UE 102 shall maintain at least one of the following counters for each entry in the "User Data List":

[0080] a) An SNPN-specific attempt counter for 3GPP-type access, configured to count only access attempts via 3GPP access;

[0081] b) An SNPN-specific attempt counter for non-3GPP type access, which is configured to count only access attempts via non-3GPP access;

[0082] c) A counter for the event "The current SNPN entry is considered invalid for 3GPP access", and

[0083] d) A counter for the event “The current SNPN entry is considered invalid for non-3GPP access”.

[0084] In some embodiments, UE 102 may or should store the aforementioned counters in its non-volatile memory. In some embodiments, when an entry with the corresponding SNPN identifier in the "User Data List" is reconfigured or removed, UE 102 should erase the attempt counter and reset the event counter to "zero". In some embodiments, the counter value should not be affected by the activation or deactivation of MICO mode or power-saving mode (e.g., see 3GPP TS 24.301).

[0085] In some embodiments, the UE-specific maximum value for any of the above counters should not exceed 10. In some embodiments, different counters may be implemented using different UEs to achieve the specific maximum value. In other words, in some embodiments, the UE-specific maximum value may differ between different network types (e.g., PLMN, SNPN) and / or between different access protocols (e.g., 3GPP, non-3GPP).

[0086] In some embodiments, if UE 102 receives a rejection message (sometimes referred to as a rejection message) from the network after sending a registration request or a request to provide services to UE 102, UE 102 may evaluate the rejection message to determine whether it believes the message comes from a reputable network, determine the reason for receiving the rejection message, and / or determine whether it may send another similar and / or different message to the network regarding the registration or service request. For example, in the context of a 5G network, if UE 102 receives a registration rejection or service rejection message without integrity protection due to the selection of one or more of the 5GMM reason values ​​(e.g., #3, #6, #12, #15, #72, #74, or #75), then before network 104 has established a secure exchange of NAS messages for the N1 NAS signaling connection, if the timer has not run, UE 102 will start timer T3247 (e.g., see 3GPP TS24.008), which has a random value uniformly drawn from a range between two predetermined waiting time values ​​(e.g., 30 minutes and 60 minutes), and take the following actions:

[0087] A) If the received 5GMM reason value is #3 or #6:

[0088] a. If a 5GMM cause value is received via 3GPP access, and:

[0089] i. If the value of the counter used for the "Entry of the current SNPN is considered invalid for 3GPP access" event is less than the maximum value implemented by the UE, then UE 102 may or should:

[0090] • Set the 5GS update status to 5U3 ROAMING NOT ALLOWED (and store it), and delete the 5G Globally Unique Temporary Identifier (5G-GUTI), the Last Accessed Registration Tracking Area Identifier (TAI), the TAI list, and the Key Set Identifier (ngKSI) used for 3GPP access.

[0091] • Increment the counter used for the event "The current SNPN entry is considered invalid for 3GPP access";

[0092] • Reset the registration attempt counter in the event of a registration rejection message;

[0093] • Store the current TAI in the "5GS Tracking-Prohibited Zones for Roaming" list for the current SNPN and enter the 5GMM-DEREGISTERED.LIMITED-SERVICE state; and

[0094] • According to 3GPP TS 38.304 or 3GPP TS 36.304, search for a suitable cell in another tracking area. As a UE implementation option, if non-3GPP access is available, the UE has not yet registered to the current SNPN via non-3GPP access, and the entry in the "User Data List" with the SNPN identifier of the current SNPN is not considered invalid for non-3GPP access, then the UE can attempt to register via non-3GPP access; or

[0095] ii. Otherwise, UE 102 may or should continue operating as if the message were protected by integrity;

[0096] b. If a 5GMM cause value is received via a non-3GPP access, and:

[0097] i. If the value of the counter used for the "Entry for the current SNPN is considered invalid for non-3GPP access" event is less than the maximum value specified by the UE, then UE 102 should:

[0098] • Set the 5GS update status to 5U3 ROAMING NOT ALLOWED (and store it), and delete the 5G-GUTI used for non-3GPP access, the last accessed registered TAI, the TAI list, and ngKSI;

[0099] • Enter 5GMM-DEREGISTERED LIMITED-SERVICE state; and

[0100] • Increment the counter used for the event "The entry for the current SNPN is considered invalid for non-3GPP access" by 1. As a UE implementation option:

[0101] a. If another access point for non-3GPP access is available, the UE can attempt to register to that other access point via non-3GPP access (the UE can choose another non-3GPP access point based on specific UE implementation methods); or

[0102] b. If 3GPP access is available, the UE has not yet registered to the current SNPN via 3GPP access, and the entry in the current "User Data List" with the SNPN identifier of the current SNPN is not considered invalid for 3GPP access, then the UE can attempt to register to the same network where non-3GPP access is not permitted via 3GPP access; or

[0103] ii. Otherwise, UE 102 should continue operating as if the message were protected by integrity;

[0104] B) If the received 5GMM reason value is #12 or #15, UE 102 should continue operating as if the message were protected by integrity. Additionally:

[0105] 1) If a 5GMM cause value is received via 3GPP access, non-3GPP access is available, the UE has not yet registered with the current SNPN via non-3GPP access, and the entry in the "User Data List" with the SNPN identifier of the current SNPN is not considered invalid for non-3GPP access, then UE 102 can attempt to register with the current SNPN via non-3GPP access; or

[0106] 2) If a 5GMM cause value is received through non-3GPP access, 3GPP access is available, UE 102 has not yet registered to the current SNPN through 3GPP access, and the entry in the "User Data List" with the SNPN identifier of the current SNPN is not considered invalid for 3GPP access, then UE 102 can attempt to register to the current SNPN through 3GPP access.

[0107] C) If the received 5GMM reason value is #72, the UE should continue operating as if the message were protected by integrity. Additionally, if the value of the SNPN-specific attempt counter used for non-3GPP access for the current SNPN is less than the maximum value implemented by the UE, the UE should increment the counter; and

[0108] D) If the received 5GMM reason value is #74 or #75:

[0109] 1) If a 5GMM cause value is received via 3GPP access, then UE 102 should:

[0110] a. Set the 5GS update status to 5U3 ROAMING NOT ALLOWED (and store it), and delete the 5G-GUTI used for 3GPP access, the last accessed registered TAI, the TAI list, and ngKSI;

[0111] b. Reset the registration attempt counter in the event of a registration rejection message;

[0112] c. Store the current TAI in the "5GS Tracking-Prohibited Zones for Roaming" list for the current SNPN and enter the 5GMM-DEREGISTERED LIMITED-SERVICE state; and

[0113] d. Search for a suitable cell in another tracking area according to 3GPP TS38.304 or 3GPP TS36.304. As a UE implementation option, if non-3GPP access is available, UE 102 has not yet registered to the current SNPN via non-3GPP access, and the entry in the "User Data List" with the SNPN identifier of the current SNPN is not considered invalid for non-3GPP access, then UE 102 may attempt to register to the current SNPN via non-3GPP access; and

[0114] 2) If a 5GMM cause value is received via a non-3GPP access, then UE 102 should:

[0115] a. Set the 5GS update status to 5U3 ROAMING NOT ALLOWED (and store it), and delete the 5G-GUTI used for non-3GPP access, the last accessed registered TAI, the TAI list, and ngKSI;

[0116] b. Reset the registration attempt counter in the event of a registration rejection message; and

[0117] c. Enter the 5GMM-DEREGISTERED LIMITED-SERVICE state. As a UE implementation option, if another access point for non-3GPP access is available, UE 102 can attempt to register via non-3GPP access (UE 102 can choose another non-3GPP access point based on UE implementation-specific means), or if 3GPP access is available, UE 102 has not yet registered to the current SNPN via 3GPP access, and the entry in the "User Data List" with the SNPN identifier of the current SNPN is not considered invalid for 3GPP access, then UE 102 can attempt to register via 3GPP access.

[0118] In some embodiments, when timer T3247 expires, UE 102 may or should:

[0119] a. For the current SNPN, erase the "5GS no-tracking zones for regional services" list and the "5GS no-tracking zones for roaming" list;

[0120] b. If the value of the counter used for the "Entry of the current SNPN is considered invalid for 3GPP access" event is less than the maximum value implemented by the UE, then the entry in the "User Data List" with the SNPN identifier of the current SNPN is set to be valid for 3GPP access;

[0121] c. If the value of the counter used for the "Entry of the current SNPN is considered invalid for non-3GPP access" event is less than the maximum value implemented by the UE, then the entry in the "User Data List" with the SNPN identifier of the current SNPN is set to be valid for non-3GPP access.

[0122] d. If the value of the SNPN-specific attempt counter used for 3GPP access for the current SNPN is greater than zero and less than the maximum value that the UE implements, and the SNPN identifier of the current SNPN is included in either the "Permanently Banned SNPN" list and / or the "Temporarily Banned SNPN" list, then remove the SNPN identifier of the current SNPN from the "Permanently Banned SNPN" list and / or the "Temporarily Banned SNPN" list.

[0123] e. If the value of the attempt counter specific to the SNPN for non-3GPP access is greater than zero but less than the maximum value for the UE to achieve, and the SNPN identifier of the current SNPN is included in either the "Permanently Banned SNPN" list for non-3GPP access and / or the "Temporarily Banned SNPN" list for non-3GPP access, then remove the SNPN identifier of the current SNPN from the "Permanently Banned SNPN" list for non-3GPP access and / or the "Temporarily Banned SNPN" list for non-3GPP access.

[0124] f. If still necessary, initiate the registration process based on the 5GMM status and 5GS update status, or perform an SNPN selection, for example, see 3GPP TS 23.122. When UE 102 is turned off:

[0125] a. For each SNPN-specific attempt counter for 3GPP access whose value is greater than zero and less than the maximum value required for UE implementation, UE 102 should remove the corresponding SNPN identifier (if any) from the "Permanently Banned SNPNs" list and / or the "Temporarily Banned SNPNs" list; and

[0126] b. For each SNPN-specific attempt counter for non-3GPP access whose value is greater than zero and less than the maximum value to be achieved by the UE, the UE 102 shall remove the corresponding SNPN identifier (if any) from the "Permanently Banned SNPN" list and / or the "Temporarily Banned SNPN" list.

[0127] When entries in the "User Data List" are reconfigured or removed:

[0128] a. If the value of the SNPN-specific attempt counter used for 3GPP access for the SNPN corresponding to this entry is greater than zero and less than the maximum value specified by the UE, then the UE should remove the SNPN identifier corresponding to this entry from the "Permanently Banned SNPNs" list and / or the "Temporarily Banned SNPNs" list (if any); and

[0129] b. If the value of the attempt counter for the SNPN corresponding to the entry is greater than zero and less than the maximum value that the UE implements, then the UE should remove the SNPN identifier corresponding to the entry (if any) from the "Permanently Banned SNPNs" list and / or the "Temporarily Banned SNPNs" list for non-3GPP access.

[0130] Now for reference Figure 3 , Figure 3A specific embodiment of this disclosure illustrates a message protocol diagram of UE 102 issuing a registration request to the Access Mobility Function (AMF) of network 104, wherein the AMF may be a component of base station 106 or accessible through base station 106. When UE 102 sends the registration request message to the AMF, UE 102 starts a timer T3510. Subsequently, the AMF receives the registration request message and determines whether UE 102 can register with network 104 based on the registration request. If the AMF can register UE 102 with network 104, the AMF performs authorization for UE 102 using network 104. If the AMF has assigned a TempID for the request, the AMF starts a timer T3550 upon receiving the registration request and sends a registration acceptance message back to UE 102. When UE 102 receives the REGISTRATION ACCEPT message, UE 102 stops the T3510 timer. If the AMF has assigned a TempID, UE 102 sends a REGISTRATION COMPLETE message back to the AMF. Upon receiving the REGISTRATION COMPLETE message, the AMF then stops the T3550 timer. Conversely, as shown at the bottom of the message diagram, if the AMF determines that UE 102 cannot register with network 104, the AMF does not start a timer but simply responds to the REGISTRATION REQUES message by sending a REGISTRATION REJECT message back to UE 102. Upon receiving the REGISTRATION REJECT message from the AMF, UE 102 stops the T3510 timer and increments the counter by 1 based on the network type and access protocol.

[0131] In some embodiments, if UE 102 receives a REGISTRATION ACCEPT message from SNPN 104, UE 102 should reset the SNPN-specific attempt counter for the specific access type for which the message was received. If the message was received via 3GPP access, UE 102 should reset the counter for the "entry of the current SNPN is considered invalid for 3GPP access" event. If the message was received via non-3GPP access, UE 102 should reset the counter for the "entry of the current SNPN is considered invalid for non-3GPP access" event.

[0132] In some embodiments, UE 102 may or should take the following actions based on the 5GMM cause value received in the REGISTRATION REJECT message:

[0133] #3 (illegal UE) or #6 (illegal ME):

[0134] a. UE 102 should set the 5GS update state to 5U3 ROAMING NOT ALLOWED (and should store it), and should delete any 5G-GUTI, last accessed registered TAI, TAI list, and ngKSI. UE 102 should consider entries in the "User Data List" with the SNPN identifier of the current SNPN 104 as invalid until UE 102 is turned off or the entry is reconfigured or removed. UE 102 should enter the 5GMM-DEREGISTERED state. If the NAS has successfully performed an integrity check on the message, UE 102 should set a counter for the "Entry of the current SNPN is considered invalid for 3GPP access" event and set it to a UE-specific maximum value for that specific counter, and set a counter for the "Entry of the current SNPN is considered invalid for non-3GPP access" event to a UE-specific maximum value for that specific counter.

[0135] #72 (Non-3GPP access to 5GCN is not permitted)

[0136] a. When this reason value is provided in a REGISTRATION REJECT message received via non-3GPP access, UE 102 should set the 5GS update state to 5U3 ROAMING NOT ALLOWED (and should store it), and should delete the 5G-GUTI, the last accessed registered TAI, the TAI list, and the ngKSI. Additionally, UE 102 should reset the registration attempt counter and enter the 5GMM-DEREGISTERED state. If the NAS has successfully performed an integrity check on the message, UE 102 should set the SNPN-specific attempt counter for non-3GPP access for that SNPN to the maximum value specific to the UE implementation for that specific counter.

[0137] #74 (SNPN has not yet granted authorization for this)

[0138] a. 5GMM Reason #74 applies only when received from a cell belonging to an SNPN. 5GMM Reason #74 received from a cell not belonging to an SNPN is considered an anomalous situation. In some embodiments, UE 102 should set the 5GS update state to 5U3ROAMING NOT ALLOWED (and should store it), and should delete any 5G-GUTI, the last accessed registered TAI, the TAI list, and ngKSI. UE 102 should reset the registration attempt counter and store the SNPN identifier in a "temporarily banned SNPN" list for the specific access type that received the message. UE 102 should enter the 5GMM-DEREGISTERED PLMN-SEARCH state and perform SNPM selection (e.g., according to 3GPP TS 23.122). If the NAS has successfully performed an integrity check on the message, UE 102 should set the SNPN-specific attempt counter for 3GPP access for that SNPN to a UE-specific maximum value for that specific counter, and set the SNPN-specific attempt counter for non-3GPP access for that SNPN to the same UE-specific maximum value for that specific counter. If the NAS has successfully performed an integrity check on the message, and UE 102 also supports the registration process to the same SNPN via other access, UE 102 should additionally process the 5GMM parameters and 5GMM status for this access, as described for this 5GMM cause value.

[0139] #75 (No SNPN license ever granted for this)

[0140] a. 5GMM Reason #75 applies only when received from a cell belonging to an SNPN. 5GMM Reason #75 received from a cell not belonging to an SNPN is considered an anomalous case. UE 102 should set the 5GS update state to 5U3 ROAMING NOTALLOWED (and should store it), and should delete any 5G-GUTI, the last accessed registration TAI, the TAI list, and the ngKSI. UE 102 should reset the registration attempt counter and store the SNPN identifier in the "Permanently Banned SNPN" list for the specific access type that received the message. UE 102 should enter the 5GMM-DEREGISTERED.PLMN-SEARCH state and perform an SNPN selection (e.g., according to 3GPP TS 23.122). If the NAS has successfully performed an integrity check on the message, UE 102 should set the SNPN-specific attempt counter for 3GPP access for that SNPN to the maximum value required for that specific UE implementation, and set the SNPN-specific attempt counter for non-3GPP access for that SNPN to the maximum value required for that specific UE implementation. If the NAS has successfully performed an integrity check on the message, and UE 102 also supports the registration process to the same SNPN 104 via other access, UE 102 should additionally process the 5GMM parameters and 5GMM status for this access, as described for this 5GMM cause value.

[0141] Now for reference Figure 4 , Figure 4A specific embodiment of this disclosure illustrates a message protocol diagram in which UE 102 sends a service request (SERVICE REQUEST) to the AMF of network 104 via Access Layer (AS) signaling, wherein the AMF may be a component of base station 106 or accessible through base station 106. When UE 102 sends the SERVICE REQUEST message to the AMF, UE 102 starts a T3517 timer. Subsequently, the AMF receives the SERVICE REQUEST message and determines whether it can provide service to UE 102 based on the SERVICE REQUEST. If the AMF can provide service to UE 102 from network 104, the AMF performs authorization for UE 102 using network 104 and relays the service to network 104. If the AMF can provide service to UE 102 from network 104, the AMF sends a service acceptance (SERVICE ACCEPT) message to UE 102 via AS signaling, and UE 102 stops the T3517 timer. Conversely, if UE 102 sends a SERVICE REQUEST message for emergency service rollback, network 104 or AMF can return an AS indication, and UE 102 can stop the T3517 timer. Alternatively, if UE 102 sends a SERVICE REQUEST message to the AMF via AS signaling, and the AMF determines that network 104 cannot provide the requested service to UE 102, the AMF sends a SERVICE REJECT message to UE 102, and UE 102 stops the T3517 timer.

[0142] In some embodiments, UE 102 may or should take the following actions based on the 5GMM cause value received in the SERVICE REJECT message:

[0143] #3 (illegal UE) and #6 (illegal ME):

[0144] a. UE 102 should set the 5GS update state to 5U3 ROAMING NOT ALLOWED (and should store it), and should delete any 5G-GUTI, last accessed registered TAI, TAI list, and ngKSI. The UE should consider entries in the "User Data List" with the SNPN identifier of the current SNPN invalid until the UE is turned off or the entry is reconfigured or removed. The UE should enter the 5GMM-DEREGISTERED state. If the NAS has successfully performed an integrity check on the message, the UE should set the counters for the "Entry of the current SNPN is considered invalid for 3GPP access" event and the counters for the "Entry of the current SNPN is considered invalid for non-3GPP access" event to the UE-specific maximum values.

[0145] #72 (Non-3GPP access to 5GCN is not allowed):

[0146] a. If the UE initiates a service request procedure via non-3GPP access, the UE should set the 5GS update state to 5U3ROAMING NOT ALLOWED (and should store it), and should delete the 5G-GUTI used for non-3GPP access, the last access registered TAI, the TAI list, and the ngKSI. Additionally, for non-3GPP access, the UE should reset the registration attempt counter and enter the 5GMM-DEREGISTERED state. If the NAS has successfully performed an integrity check on the message, the UE should set the SNPN-specific attempt counter used for non-3GPP access for that SNPN to the maximum value required by the UE.

[0147] #74 (SNPN authorization is not currently available for this):

[0148] a. 5GMM Reason #74 applies only when received from a cell belonging to an SNPN. 5GMM Reason #74 received from a cell not belonging to an SNPN is considered an anomalous case. The UE should set the 5GS Update state to 5U3 ROAMING NOTALLOWED (and should store it), and should delete any 5G-GUTI, the last accessed registered TAI, the TAI list, and ngKSI. The UE should reset the registration attempt counter and store the SNPN identifier in the "Temporarily Forbidden SNPNs" list for the specific access type that received the message. The UE should enter the 5GMM-DEREGISTERED.PLMN-SEARCH state and perform SNPN selection according to 3GPP TS 23.122. If the NAS has successfully performed an integrity check on the message, the UE should set the SNPN-specific attempt counters for 3GPP access for this SNPN and the SNPN-specific attempt counters for non-3GPP access to the UE-specific maximum values. If the NAS has successfully performed an integrity check on the message, and the UE also supports the registration process with the same SNPN through other access points, then the UE should handle the 5GMM parameters and 5GMM status for this access point separately, as described for this 5GMM cause value.

[0149] #75 (Permanently not licensed for this SNPN):

[0150] a. 5GMM Reason #75 applies only when received from a cell belonging to an SNPN. 5GMM Reason #75 received from a cell not belonging to an SNPN is considered an anomalous case. The UE should set the 5GS Update state to 5U3 ROAMING NOTALLOWED (and should store it), and should delete any 5G-GUTI, the last accessed registered TAI, the TAI list, and ngKSI. The UE should reset the registration attempt counter and store the SNPN identifier in the "Permanently Banned SNPN" list for the specific access type that received the message. The UE should enter the 5GMM-DEREGISTERED.PLMN-SEARCH state and perform SNPN selection according to 3GPP TS 23.122. If the NAS has successfully performed an integrity check on the message, the UE should set the SNPN-specific attempt counter for 3GPP access for this SNPN and the SNPN-specific attempt counter for non-3GPP access to the UE-specific maximum values. If the NAS has successfully performed an integrity check on the message, and the UE also supports the registration process with the same SNPN through other access points, then the UE should handle the 5GMM parameters and 5GMM status for this access point separately, as described for this 5GMM cause value.

[0151] In some embodiments, if an EAP failure message is received in the AUTHENTICATION REJECT message:

[0152] 1) If the NAS has successfully performed an integrity check on the message:

[0153] a. The UE should set the update status to 5U3 ROAMING NOT ALLOWED, and delete the stored 5G-GUTI, TAI list, last accessed registered TAI, and ngKSI. Entries in the "User Data List" with the SNPN identifier of the current SNPN should be considered invalid until the UE is turned off or the entry is reconfigured or removed; and

[0154] b. The UE should set the counters used for the "Entry for the current SNPN is considered invalid for 3GPP access" event and the counters used for the "Entry for the current SNPN is considered invalid for non-3GPP access" event to specific maximum values ​​for the UE implementation; and

[0155] 2) If this message is received without integrity protection, and if the timer is not running, the UE should start timer T3247, which has a randomly drawn value uniformly within a range of 30 to 60 minutes. Additionally, the UE should:

[0156] a. If the message is received via 3GPP access and the value of the counter used for the “the current SNPN entry is considered invalid for 3GPP access” event is less than the maximum value that the UE implements, then for the case where the received 5GMM cause value is #3, the operation shall be performed as specified in item A)-a of paragraph

[73] above (if the UE is operating in SNPN access mode).

[0157] b. If the message is received via non-3GPP access and the value of the counter used for the “the current SNPN entry is considered invalid for non-3GPP access” event is less than the maximum value specified by the UE, then for the case where the received 5GMM cause value is #3, the operation shall be performed as specified in item A)-b of paragraph

[73] above (if the UE is operating in SNPN access mode).

[0158] c. Otherwise:

[0159] i. If a 5GMM cause value is received via 3GPP access, the UE should:

[0160] 1. Set the update status for 3GPP access to 5U3 ROAMING NOT ALLOWED. For 3GPP access, only delete the stored 5G-GUTI, TAI list, last accessed registered TAI, and ngKSI. Entries in the "User Data List" with the SNPN identifier of the current SNPN should be considered invalid for 3GPP access until the UE is turned off or the entry is reconfigured or removed.

[0161] 2. The UE should set the counter used for the "Entry of the current SNPN is considered invalid for 3GPP access" event to a specific maximum value implemented by the UE; and

[0162] ii. If a 5GMM cause value is received via non-3GPP access, the UE should:

[0163] 1. Set the update status for non-3GPP access to 5U3 ROAMING NOT ALLOWED. For non-3GPP access, only delete the stored 5G-GUTI, TAI list, last accessed registered TAI, and ngKSI. Entries in the "User Data List" with the SNPN identifier of the current SNPN should be considered invalid for non-3GPP access until the UE is turned off or the entry is reconfigured or removed. The UE should set the counter used for the "Entry of the current SNPN is considered invalid for non-3GPP access" event to a specific maximum value implemented by the UE.

[0164] In some embodiments, upon receiving an AUTHENTICATION REJECT message: a. If the NAS has successfully performed an integrity check on the message, the UE should set the update status to 5U3 ROAMING NOT ALLOWED, and delete the stored 5G-GUTI, TAI list, last accessed registered TAI, and ngKSI. Entries in the "User Data List" with the SNPN identifier of the current SNPN should be considered invalid until the UE is turned off or the entry is reconfigured or removed.

[0165] i. The UE should set the counters for the "Entry of the current SNPN is considered invalid for 3GPP access" event and the counters for the "Entry of the current SNPN is considered invalid for non-3GPP access" event to specific maximum values ​​for the UE.

[0166] b. If the message is received without integrity protection, and if the timer is not running, the UE should start timer T3247, which has a randomly drawn value uniformly within a range of 30 to 60 minutes. Additionally, the UE should:

[0167] i. If the message is received via 3GPP access and the value of the counter used for the “the current SNPN entry is considered invalid for 3GPP access” event is less than the maximum value that the UE implements, then for the case where the received 5GMM cause value is #3, the operation shall be performed as specified in item A)-a of the list in paragraph

[73] above (if the UE is operating in SNPN access mode);

[0168] ii. If the message is received via non-3GPP access and the value of the counter used for the “the current SNPN entry is considered invalid for non-3GPP access” event is less than the maximum value specified by the UE, then for the case where the received 5GMM cause value is #3, the operation shall be performed as specified in items A)-b of paragraph

[73] above (if the UE is operating in SNPN access mode).

[0169] iii. Otherwise:

[0170] If a 5GMM cause value is received via 3GPP access, then UE 102 should:

[0171] a. Set the update status for 3GPP access to 5U3 ROAMING NOT ALLOWED. For 3GPP access, only delete the stored 5G-GUTI, TAI list, last accessed registered TAI, and ngKSI. Entries in the "User Data List" with the SNPN identifier of the current SNPN should be considered invalid for 3GPP access until the UE is turned off or the entry is reconfigured or removed.

[0172] b. The UE should set the counter used for the "entry in the current SNPN is considered invalid for 3GPP access" event to a specific maximum value for the UE implementation; and

[0173] • If a 5GMM cause value is received via non-3GPP access, the UE should:

[0174] a. Set the update status for non-3GPP access to 5U3 ROAMING NOT ALLOWED. For non-3GPP access, only delete the stored 5G-GUTI, TAI list, last accessed registered TAI, and ngKSI. Entries in the "User Data List" with the SNPN identifier of the current SNPN should be considered invalid until the UE is turned off or the entry is reconfigured or removed.

[0175] b. The UE should set the counter used for the "entry of the current SNPN is considered invalid for non-3GPP access" event to a specific maximum value for the UE.

[0176] While many of the embodiments described herein relate to 5G systems, it should be understood that other embodiments are also contemplated and included within the scope of this disclosure, including or configured to operate in other system types such as 4G systems.

[0177] Now for reference Figure 5 This provides a method 10 for processing unprotected rejection messages in a non-public network. Method 10 can be performed partially or entirely by a UE 102, device 202, or any other suitable component. In some embodiments, the method may include: at 11, receiving a registration rejection message from a network entity in response to sending an initial registration request. Method 10 may further include: at 12, starting one or more timers configured to monitor the time elapsed since the registration rejection message was received. Method 10 may further include: at 13, randomly determining a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network entity. Method 10 may further include: at 14, determining, via the one or more timers, whether the time elapsed since the registration rejection message corresponds to a randomly selected duration value. Method 10 may further include: at 15, if it is determined that the elapsed time corresponds to the randomly selected duration value, sending the subsequent registration request to the network entity.

[0178] In some embodiments, a registration rejection message may include a reason code indicating why a network entity cannot register the device. In some embodiments, the method may further include: determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, method 10 may further include: immediately sending a subsequent registration request to the network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, the method may further include: sending an initial registration request to the network entity, the initial registration request including at least identification information for the user equipment. In some embodiments, one or more counters may be associated with entries in a user data list maintained by the device. In some embodiments, one or more counters may include: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events.

[0179] In some embodiments, the user data list is a list of temporarily or permanently banned networks. In some embodiments, the method may further include: removing the entry for private networks from the list of temporarily or permanently banned networks when the value of the second counter is greater than zero but less than a randomly selected duration value upon the expiration of the second counter.

[0180] Now for reference Figure 6 The method 20 provides a method 20 for processing unprotected rejection messages in non-public networks. Method 20 can be performed partially or entirely by UE 102, device 202, or any other suitable component. In some embodiments, method 20 may include: at 21, receiving a registration rejection message from a network entity in response to sending an initial registration request. In some embodiments, method 20 may further include: at 22, starting one or more timers configured to monitor the elapsed time since receiving the registration rejection message, wherein the one or more timers are associated with entries in a user data list maintained by the device, the one or more timers including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, method 20 may further include: at 23, randomly determining a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to the minimum secure duration for sending a subsequent registration request to the network entity. In some embodiments, method 20 may further include: at 24, determining, via the one or more timers, whether the elapsed time since receiving the registration rejection message corresponds to a randomly selected duration value. In some embodiments, method 20 may further include: at 25, if the value of the second counter is greater than zero but less than the randomly selected duration value when the second counter expires, removing the entry for the private network from the temporary or permanent banned network list. In some embodiments, method 20 may further include: at 26, if it is determined that the elapsed time corresponds to the randomly selected duration value, sending the subsequent registration request to the network entity.

[0181] Now for reference Figure 7The method 30 provides a method 30 for handling rejection messages that are not protected by integrity in a non-public network. Method 30 can be performed partially or entirely by UE 102, device 202, or any other suitable component. In some embodiments, method 30 may include: at 31, receiving a rejection message from a network function in an Independent Non-Public Network (SNPN), wherein information in the rejection message indicates that the device is not permitted to access the SNPN by subscription. In some embodiments, method 30 may further include: at 32, adding the identifier of the SNPN to a list of banned SNPNs associated with access, wherein the device sends a request via the access and subsequently receives the rejection message. Method 30 may optionally further include: at 33, setting the 5GS update state to 5U3 ROAMING NOT ALLOWED, storing the 5GS update state; and deleting each of the 5G-GUTI, the last accessed registered TAI, the TAI list, and the ngKSI. In some embodiments, method 30 may optionally further include: at 34, if it is determined that the elapsed time corresponds to a randomly selected duration value, sending the subsequent registration request to the network entity, and causing the device to perform SNPN selection. In some embodiments, method 30 may optionally further include: at 35, determining whether the NAS has successfully performed an integrity check on the rejection message; if the NAS has successfully performed an integrity check on the rejection message, setting the SNPN-specific attempt counter for non-3GPP access for the SNPN to a specific maximum value for the user equipment.

[0182] Now for reference Figure 8 This provides a method 40 for processing unprotected rejection messages in a non-public network. Method 40 can be performed partially or entirely by UE 102, device 202, or any other suitable component. In some embodiments, method 40 may include: at 41, storing a list of user data, wherein each entry in the user data list includes user data for accessing an Independent Non-Public Network (SNPN). In some embodiments, method 40 may further include: at 42, maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters. In some embodiments, method 40 may further include: at 43, in the event that an entry in the user data list is reconfigured or removed, determining, based on the one or more SNPN-specific attempt counters, whether the identifier of the SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists.

[0183] Now for reference Figure 9The method 50 provides a method 50 for processing unprotected rejection messages in a non-public network. Method 50 can be performed partially or entirely by UE 102, device 202, or any other suitable component. In some embodiments, method 50 may include: at 51, storing a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing an Independent Non-Public Network (SNPN). In an embodiment, method 50 may further include: at 52, receiving an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid. In an embodiment, method 50 may further include: at 53, upon receiving the rejection message, determining whether the entry for accessing the SNPN is invalid for access by the device via which it sends a request message and / or receives the rejection message, and initiating T3247. In some embodiments, method 50 may further include: at 54, maintaining one or more counters for the SNPN, wherein the one or more counters are used to determine whether an entry for accessing the SNPN should be set to valid when T3247 expires.

[0184] As described herein, at least some embodiments of methods, apparatuses, and computer program products for processing unprotected rejection messages in non-public networks are provided.

[0185] In some example embodiments, an apparatus may be provided comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: receive a rejection message from a network function in an Independent Non-Public Network (SNPN), wherein information in the rejection message indicates that the apparatus is not permitted to access the SNPN by subscription; and add an identifier of the SNPN to a list of banned SNPNs, wherein the apparatus sends a request for access by subscription for the banned SNPN and subsequently receives the rejection message. In some embodiments, the information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus to at least: set a 5GS update state to 5U3 ROAMING NOT ALLOWED; store the 5GS update state; and delete each of the 5G-GUTI, the last access registration TAI, the TAI list, and the ngKSI. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: enter a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and to cause the device to perform SNPN selection. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: determine whether the NAS has successfully performed an integrity check on the rejection message; and if the NAS has successfully performed an integrity check on the rejection message, set an SNPN-specific attempt counter for non-3GPP access for the SNPN to a specific maximum value for the user equipment. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0186] In other example embodiments, a method, such as a computer-implemented method, may be provided, which may be implemented using, for example, an apparatus such as those described herein. In some embodiments, the method may include: receiving a rejection message from a network function in a Standalone Non-Public Network (SNPN), wherein information in the rejection message indicates that the device is not permitted to access the network via subscription; and adding the identifier of the SNPN to a list of banned SNPNs, wherein the device sends a request for access via subscription to the banned SNPN and subsequently receives the rejection message. In some embodiments, the information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the method further includes: setting the 5GS update state to 5U3 ROAMING NOT ALLOWED; storing the 5GS update state; and deleting each of the 5G-GUTI, the last access registration TAI, the TAI list, and the ngKSI. In some embodiments, the method further includes: causing the device to enter a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and causing the device to perform SNPN selection. In some embodiments, the method further includes: determining whether the NAS has successfully performed an integrity check on the rejection message; and if the NAS has successfully performed an integrity check on the rejection message, setting an SNPN-specific attempt counter for non-3GPP access for the SNPN to a specific maximum value for the user equipment. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0187] In other example embodiments, an apparatus, such as an apparatus including at least one processor and at least one memory storing computer program code, may be provided, which may be configured to implement methods such as those described herein. In some embodiments, the apparatus may include: a component for receiving a rejection message from a network function in an Independent Non-Public Network (SNPN), wherein information in the rejection message indicates that the apparatus is not permitted to access the SNPN by subscription. In some embodiments, the apparatus may include a component for adding the identifier of the SNPN to a list of banned SNPNs, wherein the apparatus sends a request for access by subscription to a banned SNPN and subsequently receives the rejection message. In some embodiments, information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the apparatus may further include: a component for setting the 5GS update status to 5U3 ROAMING NOT ALLOWED; a component for storing the 5GS update status; and a component for deleting each of the 5G-GUTI, the last access registration TAI, the TAI list, and the ngKSI. In some embodiments, the apparatus may further include: components for causing the apparatus to enter a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and components for causing the apparatus to perform SNPN selection. In some embodiments, the apparatus may further include: components for determining whether the NAS has successfully performed an integrity check on the rejection message; and components for setting an SNPN-specific attempt counter for non-3GPP access for the user equipment to a specific maximum value if the NAS has successfully performed an integrity check on the rejection message. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0188] In other example embodiments, a computer program product may be provided, such as a non-transitory computer-readable medium including program code that, when executed, causes operations including: receiving a rejection message from a network function in an Independent Non-Public Network (SNPN), wherein information in the rejection message indicates that a device is not permitted to access the SNPN by subscription; and adding an identifier of the SNPN to a list of banned SNPNs, wherein the device sends a request for access by subscription for the banned SNPN and subsequently receives the rejection message. In some embodiments, the information in the rejection message includes 5GMM reason values ​​#72, #74, or #75. In some embodiments, the program code causes further operations including: setting the 5GS update state to 5U3 ROAMING NOT ALLOWED; storing the 5GS update state; and deleting each of the 5G-GUTI, the last access registered TAI, the TAI list, and the ngKSI. In some embodiments, the program code causes further operations including: putting the device into a 5GMM-DEREGISTERED state or a 5GMM-DEREGISTERED.PLMN-SEARCH state; and causing the device to perform SNPN selection. In some embodiments, the program code causes further operations including: determining whether the NAS has successfully performed an integrity check on the rejection message; and if the NAS has successfully performed an integrity check on the rejection message, setting the SNPN-specific attempt counter for non-3GPP access for the SNPN to a specific maximum value for the user equipment. In some embodiments, the banned SNPN list is a permanently banned SNPN list. In some embodiments, the banned SNPN list is a temporarily banned SNPN list. In some embodiments, the banned SNPN list is a permanently banned SNPN list for non-3GPP access. In some embodiments, the banned SNPN list is a temporarily banned SNPN list for non-3GPP access.

[0189] According to yet another embodiment, an apparatus is provided, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: store a user data list, wherein each entry in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); maintain one or more banned SNPN lists and one or more SNPN-specific attempt counters; and, in the event that an entry in the user data list is reconfigured or removed, determine, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list for non-3GPP access. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0190] According to yet another embodiment, a method is provided, the method comprising: storing a user data list, wherein each entry in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters; and, in the event that an entry in the user data list is reconfigured or removed, determining, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0191] According to another embodiment, an apparatus is provided, such as an apparatus including one or more processors and one or more memories storing computer program code. Such an apparatus can be configured to perform any of the methods described herein, such as executing computer-implemented instructions stored on one or more memories using one or more processors. In some embodiments, the apparatus may include: components for storing a user data list, wherein each entry in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); components for maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters; and components for determining, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with a reconfigured or removed entry should be removed from the one or more banned SNPN lists in the event that an entry in the user data list is reconfigured or removed. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list for non-3GPP access. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0192] In another example embodiment, a computer program product including a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program code that, when executed, causes operations including: storing a user data list, wherein each entry in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); maintaining one or more banned SNPN lists and one or more SNPN-specific attempt counters; and, in the event that an entry in the user data list is reconfigured or removed, determining, based on the one or more SNPN-specific attempt counters, whether an identifier of an SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list. In some embodiments, the one or more banned SNPN lists include a permanently banned SNPN list for non-3GPP access. In some embodiments, the one or more banned SNPN lists include a temporarily banned SNPN list for non-3GPP access. In some embodiments, the one or more SNPN-specific attempt counters include SNPN-specific attempt counters for 3GPP access. In some embodiments, one or more SNPN-specific attempt counters include SNPN-specific attempt counters for non-3GPP access.

[0193] According to another embodiment, an apparatus is provided, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: store a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); receive an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; upon receiving the rejection message, determine whether the entry for accessing the SNPN is invalid for access via which the apparatus sends a request message and / or receives the rejection message, and initiate T3247; and maintain one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an Authentication Reject message. In some embodiments, the rejection message is a registration rejection message or a service rejection message. In some embodiments, one or more counters include: a counter for events where an entry for the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry for the current SNPN is considered invalid for non-3GPP access.

[0194] In another embodiment, a method is provided that: stores a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); receives an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; upon receiving the rejection message, determines whether the entry for accessing the SNPN is invalid for access via which the device sends a request message and / or receives the rejection message, and initiates T3247; and maintains one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an AUTHENITCATION REJECT message. In some embodiments, the rejection message is a REGISTRATION REJECT message or a SERVICE REJECT message. In some embodiments, one or more counters include: a counter for events where an entry in the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry in the current SNPN is considered invalid for non-3GPP access.

[0195] According to another embodiment, an apparatus is provided, such as an apparatus including one or more processors and one or more memories storing computer program code. Such an apparatus can be configured to perform any of the methods described herein, such as executing computer-implemented instructions stored on one or more memories using one or more processors. In some embodiments, the apparatus may include: components for storing a list of user data, wherein each of a plurality of entries in the user data list includes user data for accessing a Standalone Non-Public Network (SNPN); components for receiving a rejection message that is not protected by integrity from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; components for determining, upon receiving the rejection message, whether the entry for accessing the SNPN is invalid for access via which the apparatus sends a request message and / or receives the rejection message, and initiating T3247; and components for maintaining one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an AUTHENITCATION REJECT message. In some embodiments, the rejection message is a REGISTRATION REJECT message or a SERVICE REJECT message. In some embodiments, one or more counters include: a counter for events where an entry in the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry in the current SNPN is considered invalid for non-3GPP access.

[0196] According to yet another embodiment, a computer program product including a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program code that, when executed, causes operations including: storing a user data list, wherein each of a plurality of entries in the user data list includes user data for accessing an Independent Non-Public Network (SNPN); receiving an unprotected rejection message from a network function in the SNPN, wherein information in the rejection message indicates that the entry for accessing the SNPN is invalid; upon receiving the rejection message, determining whether the entry for accessing the SNPN is invalid for access via which the device sends a request message and / or receives the rejection message, and initiating T3247; and maintaining one or more counters for the SNPN, wherein the one or more counters are used to determine whether the entry for accessing the SNPN should be set to valid when T3247 expires. In some embodiments, the information in the rejection message includes a 5GMM cause value #3 or #6. In some embodiments, the information in the rejection message includes an AUTHENITCATION REJECT message. In some embodiments, the rejection message is a REGISTRATION REJECT message or a SERVICE REJECT message. In some embodiments, one or more counters include: a counter for events where an entry in the current SNPN is considered invalid for 3GPP access; and a counter for events where an entry in the current SNPN is considered invalid for non-3GPP access.

[0197] According to another example embodiment, an apparatus is provided, comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code being configured, together with the at least one processor, to cause the apparatus to at least: receive a rejection message from a network function in an Independent Non-Public Network (SNPN); initiate one or more timers configured to monitor time elapsed since the rejection message was received; randomly determine a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network function; determine, via the one or more timers, whether the time elapsed since the rejection message corresponds to a randomly selected duration value; and, if it is determined that the elapsed time corresponds to the randomly selected duration value, send the subsequent registration request to the network entity. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the apparatus. In some embodiments, the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus to at least: determine, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: immediately send a subsequent registration request to a network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: send an initial registration request to a network entity, the initial registration request including at least identification information for the user equipment. In some embodiments, one or more counters are associated with entries in a user data list maintained by the device, the one or more counters including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a temporary or permanent banned network list, wherein at least one memory and computer program code are further configured, together with at least one processor, to cause the device to at least: remove entries for private networks from the temporary or permanent banned network list if the value of a second counter is greater than zero but less than a randomly selected duration value when the second counter expires.

[0198] According to another embodiment, a method is provided, the method comprising: receiving a registration rejection message from a network entity in response to sending an initial registration request; starting one or more timers configured to monitor time elapsed since receiving the registration rejection message; randomly determining a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network entity; determining, via the one or more timers, whether the time elapsed since receiving the registration rejection message corresponds to a randomly selected duration value; and, if it is determined that the elapsed time corresponds to the randomly selected duration value, sending the subsequent registration request to the network entity. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the device. In some embodiments, the method further includes: determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, the method further includes: immediately sending a subsequent registration request to the network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, the method further includes: sending an initial registration request to the network entity, the initial registration request including at least identification information for a user device. In some embodiments, one or more counters are associated with entries in a user data list maintained by the device, the one or more counters comprising: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a temporary or permanent banned network list, and the method further comprises: removing entries in the user data list for private networks from the temporary or permanent banned network list if the value of the second counter is greater than zero but less than a randomly selected duration value when the second counter expires.

[0199] According to another embodiment, an apparatus is provided, such as an apparatus including one or more processors and one or more memories storing computer program code. This apparatus can be configured to perform any of the methods described herein, such as executing computer-implemented instructions stored on one or more memories using one or more processors. In some embodiments, the apparatus may include: means for receiving a registration rejection message from a network entity in response to sending an initial registration request; means for starting one or more timers, wherein the one or more timers are configured to monitor time elapsed since receiving the registration rejection message; means for randomly determining a duration value within a predetermined range between a minimum and a maximum value, wherein the minimum value corresponds to a minimum secure duration for sending a subsequent registration request to the network entity; means for determining, based on the one or more timers, whether the time elapsed since receiving the registration rejection message corresponds to a randomly selected duration value; and means for sending the subsequent registration request to the network entity if it is determined that the elapsed time corresponds to the randomly selected duration value. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the apparatus. In some embodiments, the apparatus further includes: means for determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, the apparatus further includes: means for immediately sending a subsequent registration request to a network entity when the registration rejection message is determined to be an integrity-protected message. In some embodiments, the apparatus further includes: means for sending an initial registration request to a network entity, wherein the initial registration request includes at least identification information for a user equipment. In some embodiments, one or more counters are associated with entries in a user data list maintained by the apparatus, the one or more counters including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a temporary or permanent banned network list, and the apparatus further includes: means for removing entries in the user data list for private networks from the temporary or permanent banned network list when the value of the second counter is greater than zero but less than a randomly selected duration value when the second counter expires.

[0200] According to another embodiment, a computer program product including a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including program code that, when executed, causes operations including: receiving a registration rejection message from a network entity in response to sending an initial registration request; starting one or more timers configured to monitor time elapsed since receiving the registration rejection message; randomly determining a duration value within a predetermined range between a minimum and a maximum value, the minimum value corresponding to a minimum secure duration for sending a subsequent registration request to the network entity; determining, based on the one or more timers, whether the time elapsed since receiving the registration rejection message corresponds to a randomly selected duration value; and, if it is determined that the elapsed time corresponds to the randomly selected duration value, sending the subsequent registration request to the network entity. In some embodiments, the registration rejection message includes a reason code indicating why the network entity cannot register the device. In some embodiments, the program code causes further operations including: determining, at least based on the reason code, whether the registration rejection message is an integrity-protected message. In some embodiments, the program code causes further operations including: immediately sending a subsequent registration request to the network entity if the registration rejection message is determined to be an integrity-protected message. In some embodiments, the program code causes further operations including sending an initial registration request to a network entity, the initial registration request including at least identification information for the user equipment. In some embodiments, one or more counters are associated with entries in a user data list maintained by the device, the one or more counters including: a first counter associated with entries in the user data list for non-private networks considered for network access events; and a second counter associated with entries in the user data list for private networks considered for network access events. In some embodiments, the user data list is a list of temporarily or permanently banned networks, and the program code causes further operations including removing entries for private networks from the list of temporarily or permanently banned networks when the value of the second counter is greater than zero but less than a randomly selected duration value upon the expiration of the second counter.

[0201] The above aspects and features can be implemented in systems, apparatus, methods, and / or products according to desired configurations. Details of one or more variations of the subject matter described herein are set forth in the accompanying drawings and detailed embodiments. The features and advantages of the subject matter described herein will become apparent from the description and drawings and from the claims.

[0202] The subject matter disclosed herein can be embodied in systems, apparatus, methods, and / or products according to desired configurations. For example, the base stations and user equipment (or one or more components thereof) and / or processes described herein can be implemented using one or more of the following: a processor executing program code, an application-specific integrated circuit (ASIC), a digital signal processor (DSP), an embedded processor, a field-programmable gate array (FPGA), and / or combinations thereof. These various implementations can include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, at least one input device, and at least one output device. The programmable processor can be dedicated or general-purpose for receiving / sending data and instructions from / to a storage system. These computer programs (also referred to as programs, software, software applications, applications, components, program code, or code) can include machine instructions for the programmable processor and can be implemented using high-level programming languages, and / or object-oriented programming languages, and / or assembly / machine languages. As used herein, the term "computer-readable medium" means any computer program product, computer-readable medium, machine-readable medium, computer-readable storage medium, or means and / or apparatus (e.g., magnetic disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor (including a machine-readable medium that receives machine instructions). Similarly, systems also described herein may include a processor and memory coupled to the processor. The memory may include one or more programs that cause the processor to perform one or more of the operations described herein.

[0203] Although some variations have been described in detail above, other modifications or additions are possible. In particular, further features and / or variations may be provided in addition to those set forth herein. Furthermore, the implementations described above can be various combinations and sub-combinations of the disclosed features and / or combinations and sub-combinations of some of the further features disclosed above. Other embodiments may fall within the scope of the appended claims.

[0204] If desired, the different functions discussed herein may be performed in different orders and / or simultaneously with each other. Furthermore, if desired, one or more of the aforementioned functions may be optional or may be combined. Although various aspects of some embodiments are set forth in the independent claims, other aspects of some embodiments include other combinations of features from the described embodiments and / or dependent claims with features of the independent claims, not just those expressly listed in the claims. It should also be noted herein that while exemplary embodiments have been described above, these descriptions should not be considered limiting. Rather, several variations and modifications may be made without departing from the scope of some embodiments as defined in the appended claims. Other embodiments may fall within the scope of the appended claims. The term “based on” includes “at least based on”. Unless otherwise stated, the phrase “such as” means “such as, for example”.

[0205] It should be understood that the term "user equipment" is intended to cover any suitable type of wireless user equipment, such as mobile phones, portable data processing devices, or portable web browsers. It should also be understood that the term "user equipment" is intended to cover any suitable type of non-portable user equipment, such as television receivers, desktop data processing devices, or set-top boxes.

[0206] Generally, various embodiments of the present invention can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects may be implemented in hardware, while others may be implemented in firmware or software executable by a controller, microprocessor, or other computing device, but the invention is not limited thereto. Although various aspects of the invention may be illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be well understood that, by way of non-limiting example, the blocks, apparatuses, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or certain combinations thereof.

[0207] Embodiments of the present invention can be implemented by computer software executable by a data processor of a mobile device (such as in a processor entity), or by hardware, or by a combination of software and hardware. Furthermore, it should be noted in this regard that any block of the logical flow as shown in the figures may represent a program step, or interconnected logic circuits, blocks, and functions, or a combination of program steps and logic circuits, blocks, and functions. Software can be stored on a physical medium, such as a memory chip, or a block of memory implemented within the processor, a magnetic medium such as a hard disk or floppy disk, and an optical medium such as a DVD and its data variant CD. The memory can be of any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor can be of any type suitable for the local technical environment and, by way of non-limiting example, may include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture.

[0208] The foregoing description has provided a complete and detailed description of exemplary embodiments of the invention by way of exemplary and non-limiting examples. However, various modifications and alterations will become apparent to those skilled in the art when read in conjunction with the accompanying drawings and claims, in view of the foregoing description. Nevertheless, all such modifications and alterations taught in this invention will still fall within the scope of this invention.

Claims

1. A communication apparatus (202), comprising: At least one processor (204); as well as At least one memory (206) including computer program code, said at least one memory and said computer program code being configured together with said at least one processor to cause the device to at least: This enables the storage of (41) a user data list, wherein the entries in the user data list include user data for accessing the Independent Non-Public Network (SNPN); Maintain (42) one or more banned SNPN lists and one or more SNPN-specific attempt counters; and In the event that an entry in the user data list is reconfigured or removed, based on the one or more SNPN-specific attempt counters, determine (43) whether the identifier of the SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists.

2. The apparatus according to claim 1, wherein, The one or more banned SNPN lists include one or more of the following: Permanently banned SNPN list Temporarily banned SNPN list For those permanently banned from SNPN lists that are not part of the 3GPP (Generation 3 Partner Program) or non-3GPP access, or Temporary SNPN list for non-3GPP access.

3. The apparatus according to claim 1, wherein, The one or more SNPN-specific attempt counters include one or more of the following: An attempt counter specific to SNPN for 3GPP access under the 3rd Generation Partnership Project (3GPP), or an attempt counter specific to SNPN for non-3GPP access.

4. The apparatus of claim 1, wherein the at least one memory and the computer program code are further configured, together with the at least one processor, to cause the apparatus to at least: Receive a rejection message from a network function in the SNPN that is not protected by integrity, the rejection message indicating that the entry used to access the SNPN is invalid; Upon receiving the rejection message, a timer is started; and When the timer expires, it is determined whether the entry used to access the SNPN should be set to valid.

5. The apparatus of claim 4, wherein the timer is a 3GPP Timer T3247.

6. A method for communication, comprising: This enables (41) to store a list of user data, wherein the entries in the list of user data include user data for accessing the Independent Non-Public Network (SNPN); Maintain (42) one or more banned SNPN lists and one or more SNPN-specific attempt counters; and In the event that an entry in the user data list is reconfigured or removed, based on the one or more SNPN-specific attempt counters, determine (43) whether the identifier of the SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists.

7. The method according to claim 6, wherein, The one or more banned SNPN lists include one or more of the following: Permanently banned SNPN list Temporarily banned SNPN list For those permanently banned from SNPN lists that are not part of the 3GPP (Generation 3 Partner Program) or non-3GPP access, or Temporary SNPN list for non-3GPP access.

8. The method according to claim 6, wherein, The one or more SNPN-specific attempt counters include one or more of the following: An attempt counter specific to SNPN for 3GPP access, or an attempt counter specific to SNPN for non-3GPP access.

9. The method according to claim 6, further comprising: Receive a rejection message from a network function in the SNPN that is not protected by integrity, the rejection message indicating that the entry used to access the SNPN is invalid; Upon receiving the rejection message, a timer is started; and When the timer expires, it is determined whether the entry used to access the SNPN should be set to valid.

10. The method of claim 9, wherein the timer is a 3GPP Timer T3247.

11. A computer-readable medium comprising instructions that, when executed by a computer, cause the computer to: This enables the storage of a list of user data (41), where, The entries in the user data list include user data used for accessing the Independent Non-Public Network (SNPN); Maintain (42) one or more banned SNPN lists and one or more SNPN-specific attempt counters; as well as In the event that an entry in the user data list is reconfigured or removed, based on the one or more SNPN-specific attempt counters, determine (43) whether the identifier of the SNPN associated with the reconfigured or removed entry should be removed from the one or more banned SNPN lists.

12. The computer-readable medium of claim 11, wherein, The one or more banned SNPN lists include one or more of the following: Permanently banned SNPN list Temporarily banned SNPN list For those permanently banned from SNPN lists that are not part of the 3GPP (Generation 3 Partner Program) or non-3GPP access, or Temporary SNPN list for non-3GPP access.

13. The computer-readable medium of claim 11, wherein, The one or more SNPN-specific attempt counters include one or more of the following: An attempt counter specific to SNPN for 3GPP access, or an attempt counter specific to SNPN for non-3GPP access.

14. The computer-readable medium of claim 11, wherein, When the instruction is executed by the computer, it also causes the computer to: Receive a rejection message that is not protected by integrity from the network functions in the SNPN, the rejection message indicating that the entry used to access the SNPN is invalid; Upon receiving the rejection message, a timer is started; and When the timer expires, it is determined whether the entry used to access the SNPN should be set to valid.

15. The computer-readable medium of claim 14, wherein the timer is a 3GPP Timer T3247.

Citation Information

Patent Citations

  • Control signaling in a wireless communication system for preventing attacks depending on integrity protection and timer rules

    WO2019004901A1